43 Commits

Author SHA1 Message Date
Tom Alexander
1deb7a84e5 Add install of instawow. 2026-09-27 20:46:26 -04:00
Tom Alexander
ffbd3847e7 Fix lexical binding issue loading python language server. 2026-09-13 23:47:20 -04:00
Tom Alexander
4a6cbfad67 Use lexical binding in elisp files.
This silences a warning for each of these files. Lexical binding will become the default in a future version of emacs.
2026-09-12 21:00:26 -04:00
Tom Alexander
450478cff4 I changed bhyverc to use pci slot 10 for network, so update the network interface. 2026-09-12 17:27:33 -04:00
Tom Alexander
82d460e08e Update packages. 2026-09-12 17:27:33 -04:00
Tom Alexander
24853ba6a2 Add secret for private images pulled in tekton steps. 2026-09-12 17:26:41 -04:00
Tom Alexander
f2bde9ffea Disable installing documentation. 2026-09-07 15:41:38 -04:00
Tom Alexander
0d6001d655 Add parted to debugging role on kubernetes.
This is to support expanding the storage.
2026-09-07 13:24:39 -04:00
Tom Alexander
a0e8a74906 Update packages. 2026-09-05 19:07:41 -04:00
Tom Alexander
e719948a3e Switch to quad9 for DNS.
Mullvad is shutting down their public DNS.

ref: https://mullvad.net/en/blog/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead
2026-09-05 09:46:36 -04:00
Tom Alexander
3f281f1980 Clean up nix_builder directories at the start of a build. 2026-09-03 22:21:07 -04:00
Tom Alexander
6ed4aa08f6 Add a role for mitmproxy. 2026-08-29 09:40:21 -04:00
Tom Alexander
9bfa21368b Update to Linux 7.2.
This is to pull in the drivers for the mt7927 wireless chipset in my desktop. Normally, I would keep the rest of my machines on LTS but since Linux 7 significantly changed the kernel preemption, maintaining two configs would be more trouble than it is worth.
2026-08-29 06:50:47 -04:00
Tom Alexander
4eb7749967 Update persist directory for the latest firefox. 2026-08-29 06:50:45 -04:00
Tom Alexander
d0504bf98f Update rpcs3. 2026-08-28 09:02:47 -04:00
Tom Alexander
f1d6ae3f1b Merge branch 'update' into nix 2026-08-28 06:55:11 -04:00
Tom Alexander
85815fddfd Update deprecated podman settings. 2026-08-28 06:53:56 -04:00
Tom Alexander
5680e566bc Update packages. 2026-08-28 06:53:56 -04:00
Tom Alexander
3bbaeaf2af Install Arial font with rpcs3. 2026-08-26 17:16:22 -04:00
Tom Alexander
1845b1ac30 Increase thresholds for automatic garbage collection. 2026-08-10 22:38:26 -04:00
Tom Alexander
4a772b7276 Disable ca-derivations for the kubernetes cluster also. 2026-08-10 18:30:58 -04:00
Tom Alexander
0e231428df Disable ca-derivations.
Seeing if this is what is causing all my issues with files/directories in the nix store going missing.
2026-08-10 15:27:18 -04:00
Tom Alexander
27b5c0c9ab Disable build of sm64ex. 2026-08-09 17:18:26 -04:00
Tom Alexander
54e97da71d Enable building on quark. 2026-08-09 16:23:47 -04:00
Tom Alexander
58c78c50e6 Add The Lord of the Rings The War in the North to RPCS3. 2026-08-09 16:23:47 -04:00
Tom Alexander
e2ed4013c5 Add support for exfat. 2026-08-09 16:23:47 -04:00
Tom Alexander
3aefe7c0b5 Update nix builder to gracefully handle errors during setup. 2026-08-09 00:45:41 -04:00
Tom Alexander
a2485dcfe0 Update NixBSD build target to my repo and add a wip branch build target. 2026-08-08 18:36:06 -04:00
Tom Alexander
d4dc7e1f59 Trust garak's signing key. 2026-08-07 15:48:09 -04:00
Tom Alexander
3c17d56664 Separate enabling distributed build vs substituters. 2026-08-05 17:54:38 -04:00
Tom Alexander
adff9fcd29 Update nix_builder to support tar in the flake lockfile. 2026-08-04 21:39:54 -04:00
Tom Alexander
649e4033fd Update nix_builder to record the revisions of the flake inputs. 2026-07-28 10:20:18 -04:00
Tom Alexander
1b38004e03 Add more hosts to /etc/hosts. 2026-07-28 08:22:47 -04:00
Tom Alexander
d8ef4356a0 Enable some more builds in nix_builder. 2026-07-23 20:25:42 -04:00
Tom Alexander
5dd5f2e4e0 Fix docker credential generation. 2026-07-23 20:08:40 -04:00
Tom Alexander
84e8983974 Update nix_builder. 2026-07-18 23:30:39 -04:00
Tom Alexander
24f4a8c2d9 Tweak the containerd garbage collect threshold on kubelets.
Pods were getting evicted due to disk pressure, so this causes garbage collection to trigger sooner.
2026-07-18 13:59:56 -04:00
Tom Alexander
a3cdaa9128 Increase subuid/subgid range to support running buildkit inside podman. 2026-07-18 08:42:02 -04:00
Tom Alexander
51295a23dc Enable the build VM as a substituter.
This should enable me to have local build jobs without rebuilding stuff that already exists on the build VM server.
2026-07-18 08:41:11 -04:00
Tom Alexander
11d8b93551 Add an /etc/hosts entry for google's metadata server.
gcloud was reaching out to this address which was causing delays. Pointing it to localhost to speed the failure up.
2026-07-14 11:53:38 -04:00
Tom Alexander
40b8742a80 Add nix pull-through cache secrets. 2026-07-13 20:35:11 -04:00
Tom Alexander
32080e0e01 Add chown for nix pull through cache database. 2026-07-12 17:25:12 -04:00
Tom Alexander
41668506cd Retire the kubernetes branch now that it is merged into nix. 2026-07-06 18:28:58 -04:00
69 changed files with 441 additions and 190 deletions

View File

@@ -36,6 +36,7 @@ in
./roles/emacs
./roles/emulate_isa
./roles/esim
./roles/exfat
./roles/firefox
./roles/firewall
./roles/flux
@@ -50,6 +51,7 @@ in
./roles/graphviz
./roles/hydra
./roles/image_based_appliance
./roles/instawow
./roles/iso
./roles/iso_mount
./roles/jujutsu
@@ -63,6 +65,7 @@ in
./roles/media
./roles/memtest86
./roles/minimal_base
./roles/mitmproxy
./roles/network
./roles/nix_index
./roles/nix_repl
@@ -117,14 +120,14 @@ in
nix.settings.experimental-features = [
"nix-command"
"flakes"
"ca-derivations"
# "ca-derivations"
# "blake3-hashes"
# "git-hashing"
];
nix.settings.trusted-users = [ "@wheel" ];
nix.settings.connect-timeout = 5;
nix.settings.min-free = 128000000;
nix.settings.max-free = 1000000000;
nix.settings.min-free = 5 * 1024 * 1024 * 1024; # Kick off garbage collect if space for nix store is less than 5 GiB
nix.settings.max-free = 10 * 1024 * 1024 * 1024; # Run that garbage collect until at least 10 GiB are free.
nix.settings.fallback = true;
nix.settings.warn-dirty = false;
nix.settings.fsync-metadata = true;
@@ -246,31 +249,32 @@ in
glew = (final.glew.override { enableEGL = false; });
};
})
(disableTests "onetbb") # oneTBB tests hang forever on machines with a single core (like my build virtual machine) https://github.com/uxlfoundation/oneTBB/issues/1557
(disableTests "aws-c-common") # aws-c-common tests time out on my build virtual machine but run fine on my laptop.
(disableOptimizations "onnxruntime") # QuantizeLinearOpTest test failing.
(final: prev: {
fwupd = prev.fwupd.overrideAttrs (
rpcs3 = prev.rpcs3.overrideAttrs (
finalAttrs: prevAttrs: {
version = "2.1.5";
version = "0.0.42-19843";
src = final.fetchFromGitHub {
owner = "fwupd";
repo = "fwupd";
tag = finalAttrs.version;
hash = "sha256-DzQ+N99ZmFRqZc2rN6PSqmoIMXUyrE8Kkn+KnT/AWPc=";
owner = "RPCS3";
repo = "rpcs3";
rev = "6567a5a2f8ab47a89db395d6b47a7b59b23d6960";
postCheckout = ''
cd $out/3rdparty
git submodule update --init \
fusion/fusion asmjit/asmjit yaml-cpp/yaml-cpp SoundTouch/soundtouch stblib/stb \
feralinteractive/feralinteractive wolfssl/wolfssl
'';
hash = "sha256-a1c1+Ui7XyHFTGEZAgRuJasCzQqr2PZNTlwaDUWVb18=";
};
patches = [ ];
}
);
})
(disableTests "onetbb") # oneTBB tests hang forever on machines with a single core (like my build virtual machine) https://github.com/uxlfoundation/oneTBB/issues/1557
(disableTests "aws-c-common") # aws-c-common tests time out on my build virtual machine but run fine on my laptop.
# Works but probably sets python2's scipy to be python3:
#
# (final: prev: {
# pythonPackagesExtensions = prev.pythonPackagesExtensions ++ [
# (python-final: python-prev: {
# scipy = final.unoptimized.python3Packages.scipy;
# })
# ];
# })
(disableTests "ada") # test failing with http url is not idempotent.
];
# This option defines the first version of NixOS you have installed on this particular machine,

View File

@@ -22,11 +22,11 @@
]
},
"locked": {
"lastModified": 1780894562,
"narHash": "sha256-c3430xwxwhHipl3jigUGMMBfpaMylDqytW/kdmB3ZGs=",
"lastModified": 1781152676,
"narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=",
"owner": "nix-community",
"repo": "disko",
"rev": "24fed06cac83bcc44ac8efbb57cab1a82fa0bedc",
"rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1",
"type": "github"
},
"original": {
@@ -170,11 +170,11 @@
"rust-overlay": "rust-overlay_2"
},
"locked": {
"lastModified": 1783278211,
"narHash": "sha256-/1u+MIQIge+cNPukQoK4Jp8nLuFZRbx4U+MyyxG0RpM=",
"lastModified": 1788488145,
"narHash": "sha256-s1UY+kbLtb+5ye4GnE/HKh0idUQ0iiIkMMtGI7cDRHk=",
"ref": "refs/heads/main",
"rev": "9281ba7e10d362d4edb489d0df0e78936dfe7b58",
"revCount": 32,
"rev": "8b28dfb583e094f52fd6ab70c709cc1981d8853d",
"revCount": 46,
"type": "git",
"url": "https://code.fizz.buzz/talexander/nix_builder.git"
},
@@ -185,11 +185,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1780749050,
"narHash": "sha256-3av0pIjlOWQ6rDbNOmpUSvbNnJkGORQKKjb4LtCZsIY=",
"lastModified": 1788752844,
"narHash": "sha256-VaWGJ6+cIYN2erfSecbRV+4ljI185Ty2wUrXyvQbgOw=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "a799d3e3886da994fa307f817a6bc705ae538eeb",
"rev": "dc5d91f840324650bac8c379428c7037a416959a",
"type": "github"
},
"original": {
@@ -199,22 +199,6 @@
"type": "github"
}
},
"nixpkgs-google": {
"locked": {
"lastModified": 1779893571,
"narHash": "sha256-wiwMyVCtmjRjlFCe2zaumCE6LRV9GzzN0ZH25NQkbAU=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "45f6cfaa4605b706c870e75bd74bdb5e97eee11e",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "45f6cfaa4605b706c870e75bd74bdb5e97eee11e",
"type": "github"
}
},
"nixpkgs-stable": {
"locked": {
"lastModified": 1730741070,
@@ -264,8 +248,7 @@
"impermanence": "impermanence",
"lanzaboote": "lanzaboote",
"nix_builder": "nix_builder",
"nixpkgs": "nixpkgs",
"nixpkgs-google": "nixpkgs-google"
"nixpkgs": "nixpkgs"
}
},
"rust-overlay": {

View File

@@ -20,7 +20,6 @@
inputs.nixpkgs.follows = "nixpkgs";
};
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
nixpkgs-google.url = "github:NixOS/nixpkgs/45f6cfaa4605b706c870e75bd74bdb5e97eee11e";
lanzaboote = {
url = "github:nix-community/lanzaboote/v0.4.2";
inputs.nixpkgs.follows = "nixpkgs";
@@ -39,7 +38,6 @@
{
self,
nixpkgs,
nixpkgs-google,
disko,
impermanence,
lanzaboote,
@@ -99,9 +97,6 @@
hostPlatform.gcc.arch = "default";
hostPlatform.gcc.tune = "default";
};
google = import nixpkgs-google {
system = prev.stdenv.hostPlatform.system;
};
})
];
};

View File

@@ -4,16 +4,19 @@
config = {
me.distributed_build.enable = true;
me.distributed_build.machines.quark = {
enable = false;
enable_build = false;
enable_substituter = false;
additional_config = {
speedFactor = 2;
};
};
me.distributed_build.machines.hydra = {
enable = true;
enable_build = false;
enable_substituter = true;
additional_config = {
speedFactor = 2;
};
substituter_url = "ssh-ng://nixworker@ns1.fizz.buzz:65122?compress=true&ssh-key=/persist/manual/ssh/root/keys/id_ed25519&remote-store=local?root=/.disk/root";
};
};
}

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`
@@ -129,6 +129,8 @@
# systemd.user.extraConfig = "DefaultLimitNOFILE=8192";
# systemd.services."user@11400".serviceConfig.LimitNOFILE = "8192";
nix.settings.secret-key-files = [ "/persist/manual/nix/nix-cache-key.sec" ];
me.build_in_ram.enable = true;
me.dont_use_substituters.enable = true;
me.hydra.enable = true;

View File

@@ -4,10 +4,19 @@
config = {
me.distributed_build.enable = true;
me.distributed_build.machines.quark = {
enable = true;
enable_build = false;
enable_substituter = false;
additional_config = {
speedFactor = 2;
};
};
me.distributed_build.machines.hydra = {
enable_build = false;
enable_substituter = true;
additional_config = {
speedFactor = 2;
};
substituter_url = "ssh-ng://nixworker@ns1.fizz.buzz:65122?compress=true&ssh-key=/persist/manual/ssh/root/keys/id_ed25519&remote-store=local?root=/.disk/root";
};
};
}

View File

@@ -94,6 +94,7 @@
me.emacs_flavor = "full";
me.emulate_isa.enable = true;
me.esim.enable = true;
me.exfat.enable = true;
me.firefox.enable = true;
me.firewall.enable = true;
me.flux.enable = true;
@@ -106,6 +107,7 @@
me.graphical = true;
me.graphics_card_type = "amd";
me.graphviz.enable = true;
me.instawow.enable = true;
me.iso_mount.enable = true;
me.jujutsu.config = ../../roles/jujutsu/files/jujutsu_config_home.toml;
me.jujutsu.enable = true;
@@ -117,6 +119,7 @@
me.lvfs.enable = true;
me.media.enable = true;
me.memtest.enable = true;
me.mitmproxy.enable = true;
me.network.enable = true;
me.nix_index.enable = true;
me.nix_repl.enable = true;
@@ -164,7 +167,7 @@
me.zrepl.enable = true;
me.zsh.enable = true;
me.sm64ex.enable = true;
me.sm64ex.enable = false;
me.shipwright.enable = false;
me.ship2harkinian.enable = true;
};

View File

@@ -4,16 +4,19 @@
config = {
me.distributed_build.enable = true;
me.distributed_build.machines.quark = {
enable = false;
enable_build = true;
enable_substituter = false;
additional_config = {
speedFactor = 2;
};
};
me.distributed_build.machines.hydra = {
enable = true;
enable_build = false;
enable_substituter = true;
additional_config = {
speedFactor = 2;
};
substituter_url = "ssh-ng://nixworker@ns1.fizz.buzz:65122?compress=true&ssh-key=/persist/manual/ssh/root/keys/id_ed25519&remote-store=local?root=/.disk/root";
};
};
}

View File

@@ -4,16 +4,19 @@
config = {
me.distributed_build.enable = true;
me.distributed_build.machines.quark = {
enable = false;
enable_build = false;
enable_substituter = false;
additional_config = {
speedFactor = 2;
};
};
me.distributed_build.machines.hydra = {
enable = true;
enable_build = false;
enable_substituter = true;
additional_config = {
speedFactor = 2;
};
substituter_url = "ssh-ng://nixworker@ns1.fizz.buzz:65122?compress=true&ssh-key=/persist/manual/ssh/root/keys/id_ed25519&remote-store=local?root=/.disk/root";
};
};
}

View File

@@ -100,6 +100,7 @@
me.graphical = true;
me.graphics_card_type = "amd";
me.graphviz.enable = true;
me.instawow.enable = true;
me.iso_mount.enable = true;
me.jujutsu.config = ../../roles/jujutsu/files/jujutsu_config_home.toml;
me.jujutsu.enable = true;
@@ -111,6 +112,7 @@
me.lvfs.enable = true;
me.media.enable = true;
me.memtest.enable = true;
me.mitmproxy.enable = true;
me.network.enable = true;
me.nix_index.enable = true;
me.nix_repl.enable = true;
@@ -159,7 +161,7 @@
me.zrepl.enable = true;
me.zsh.enable = true;
me.sm64ex.enable = true;
me.sm64ex.enable = false;
me.shipwright.enable = false;
me.ship2harkinian.enable = true;
};

View File

@@ -3,11 +3,20 @@
config = {
me.distributed_build.enable = true;
me.distributed_build.machines.hydra = {
enable = true;
me.distributed_build.machines.quark = {
enable_build = false;
enable_substituter = false;
additional_config = {
speedFactor = 2;
};
};
me.distributed_build.machines.hydra = {
enable_build = false;
enable_substituter = true;
additional_config = {
speedFactor = 2;
};
substituter_url = "ssh-ng://nixworker@ns1.fizz.buzz:65122?compress=true&ssh-key=/persist/manual/ssh/root/keys/id_ed25519&remote-store=local?root=/.disk/root";
};
};
}

View File

@@ -4,10 +4,19 @@
config = {
me.distributed_build.enable = true;
me.distributed_build.machines.quark = {
enable = true;
enable_build = false;
enable_substituter = false;
additional_config = {
speedFactor = 2;
};
};
me.distributed_build.machines.hydra = {
enable_build = false;
enable_substituter = true;
additional_config = {
speedFactor = 2;
};
substituter_url = "ssh-ng://nixworker@ns1.fizz.buzz:65122?compress=true&ssh-key=/persist/manual/ssh/root/keys/id_ed25519&remote-store=local?root=/.disk/root";
};
};
}

View File

@@ -72,5 +72,9 @@ in
git_fix_author
rsync_clone
];
# Disable installing documentation.
documentation.doc.enable = false;
documentation.nixos.enable = false;
};
}

View File

@@ -10,7 +10,14 @@
let
make_machine_config = name: {
enable = lib.mkOption {
enable_build = lib.mkOption {
type = lib.types.bool;
default = false;
example = true;
description = "Whether we want to use the ${name} machine during distributed builds.";
};
enable_substituter = lib.mkOption {
type = lib.types.bool;
default = false;
example = true;
@@ -59,25 +66,35 @@ let
hostName = lib.mkForce "hydra?remote-store=local?root=/.disk/root";
};
};
joined_configs =
lib.genAttrs
(builtins.filter (hostname: config.me.distributed_build.machines."${hostname}".enable) (
builtins.attrNames all_nixos_configs
))
(
hostname:
(lib.mkMerge [
build_machine_list = (
map (
hostname:
(lib.mkIf config.me.distributed_build.machines."${hostname}".enable_build (
lib.mkMerge [
{
hostName = hostname;
sshUser = "nixworker";
sshKey = "/persist/manual/ssh/root/keys/id_ed25519";
maxJobs = 1;
supportedFeatures = all_nixos_configs."${hostname}".config.me.optimizations.system_features;
protocol = "ssh-ng";
}
static_host_configs."${hostname}"
config.me.distributed_build.machines."${hostname}".additional_config
])
);
]
))
) (builtins.attrNames all_nixos_configs)
);
substituters_list = (
map (
hostname:
(lib.mkIf (
config.me.distributed_build.machines."${hostname}".enable_substituter
&& config.me.distributed_build.machines."${hostname}".substituter_url != null
) (config.me.distributed_build.machines."${hostname}".substituter_url))
) (builtins.attrNames all_nixos_configs)
);
has_any_substituters = substituters_list != [ ];
in
{
imports = [ ];
@@ -117,35 +134,17 @@ in
"odo:0S/XKSFjjIrihQ7lbHEIebXk/c/xuoodhm0Gz26YhjA="
"odowork:zg3UKBAyLy3xtZkL0hMtbxHjxgn5A2QY8NNAgyRT6Yo="
"quark:Eb6ygkIiVlcUqb5hOjEVIQcfYLpCz40YVYA3/rxrgBc="
"hydra:1s4Cy9YJLgw4jWx5jdSCfJmIm0hfya7WEy/EwJYI5Ys="
"garak:8nUS6/aHl+FmF518WZlG4DzDToQ3fSNnpHR+aFQmkqc="
];
}
{
nix.buildMachines = (
map (
hostname:
(lib.mkIf config.me.distributed_build.machines."${hostname}".enable (
lib.mkMerge [
{
hostName = hostname;
sshUser = "nixworker";
sshKey = "/persist/manual/ssh/root/keys/id_ed25519";
maxJobs = 1;
supportedFeatures = all_nixos_configs."${hostname}".config.me.optimizations.system_features;
protocol = "ssh-ng";
}
static_host_configs."${hostname}"
config.me.distributed_build.machines."${hostname}".additional_config
]
))
) (builtins.attrNames all_nixos_configs)
);
nix.buildMachines = build_machine_list;
}
# {
# nix.settings.substitute = lib.mkForce true;
# nix.settings.substituters = lib.mkForce (
# lib.mapAttrsToList (hostname: joined_config: "ssh-ng://${joined_config.hostName}") joined_configs
# );
# }
(lib.mkIf has_any_substituters {
nix.settings.substitute = lib.mkForce true;
nix.settings.substituters = lib.mkForce substituters_list;
})
]
);
}

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(setq gc-cons-threshold (* 128 1024 1024)) ;; 128MiB Increase garbage collection threshold for performance (default 800000)
;; Increase amount of data read from processes, default 4k
(when (version<= "27.0" emacs-version)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package diminish)
;; Eglot recommends pulling the latest of the standard libraries it

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
;; ========== Function to reload current file =================
(defun reload-file ()
@@ -11,10 +12,9 @@
"Run a command using the current buffer as stdin and replacing its contents if the command succeeds with the stdout from the command. This is useful for code formatters."
(let (
(stdout-buffer (generate-new-buffer "tmp-stdout" t))
(full-cmd (append '(call-process-region nil nil cmd nil stdout-buffer nil) args))
)
(unwind-protect
(let ((exit-status (eval full-cmd)))
(let ((exit-status (apply #'call-process-region nil nil cmd nil (list stdout-buffer nil) nil args)))
(if (eq exit-status 0)
(save-excursion
(replace-buffer-contents stdout-buffer)
@@ -31,10 +31,9 @@
"Run a command using the current buffer as stdin and replacing its contents if the command succeeds with the stdout from the command. This is useful for code formatters. This version only replaces the buffer contents if the command output some text."
(let (
(stdout-buffer (generate-new-buffer "tmp-stdout" t))
(full-cmd (append '(call-process-region nil nil cmd nil stdout-buffer nil) args))
)
(unwind-protect
(let ((exit-status (eval full-cmd)))
(let ((exit-status (apply #'call-process-region nil nil cmd nil (list stdout-buffer nil) nil args)))
(if (eq exit-status 0)
(if (> (buffer-size stdout-buffer) 0)
(save-excursion
@@ -55,10 +54,9 @@
(let (
(default-directory (or dir default-directory))
(stdout-buffer (generate-new-buffer "tmp-stdout" t))
(full-cmd (append '(call-process cmd nil (list stdout-buffer nil) nil) args))
)
(unwind-protect
(let ((exit-status (condition-case nil (eval full-cmd) (file-missing nil))))
(let ((exit-status (condition-case nil (apply #'call-process cmd nil (list stdout-buffer nil) nil args) (file-missing nil))))
(if (eq exit-status 0)
(progn
(with-current-buffer stdout-buffer

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
;; Add your keys here, as such
;; Disable the suspend frame hotkeys

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
;; Set theme
(load-theme 'tango-dark t)
(set-face-attribute 'default nil :background "black")

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(package-initialize)
(use-package use-package
:custom

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package eglot
;; This is an emacs built-in but we're pulling the latest version
:pin gnu

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'util-tree-sitter)
(use-package bash-ts-mode

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(use-package cmake-mode

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(defun d2-format-buffer ()
"Run prettier."
(interactive)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package dockerfile-ts-mode
:pin manual
:mode (

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(defun lua-format-buffer ()
"Run stylua."
(interactive)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package markdown-mode
:ensure t
:commands (markdown-mode gfm-mode)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package nftables-mode
:commands nftables-mode
)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'color)
(let ((bg (face-attribute 'default :background)))
(use-package org

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(defun xml-fmt ()
"Run xmllint --format."
(run-command-on-buffer "xmllint" "--format" "-")

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(defun yaml-format-buffer ()
"Run prettier."
(interactive)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package flymake
:pin manual
:ensure nil

View File

@@ -1,3 +1,5 @@
;; -*- lexical-binding: t; -*-
;; (add-to-list 'major-mode-remap-alist '(c-mode . c-ts-mode))
(use-package treesit
@@ -13,6 +15,8 @@
;; :custom
;; (treesit-font-lock-level 3)
(setq treesit-font-lock-level 4)
;; (setq treesit-auto-install-grammar t)
;; (setq treesit-enabled-modes t)
)
(provide 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(defun my/minibuffer-delete (arg)
"When looking for files, go up an entire directory with the backspace button if theres no text after the directory."
(interactive "p")

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(add-to-list 'load-path (concat user-emacs-directory "elisp"))
(require 'base)

View File

@@ -0,0 +1,26 @@
{
config,
lib,
pkgs,
...
}:
{
imports = [ ];
options.me = {
exfat.enable = lib.mkOption {
type = lib.types.bool;
default = false;
example = true;
description = "Whether we want to install exfat.";
};
};
config = lib.mkIf config.me.exfat.enable {
# boot.supportedFilesystems = [ "exfat" ];
environment.systemPackages = with pkgs; [
exfatprogs
];
};
}

View File

@@ -20,7 +20,7 @@
config = lib.mkIf (config.me.firefox.enable && config.me.graphical) {
programs.firefox = {
enable = true;
package = (pkgs.wrapFirefox (pkgs.firefox-unwrapped.override { pipewireSupport = true; }) { });
package = (pkgs.wrapFirefox (pkgs.firefox-unwrapped.override { withPipewire = true; }) { });
languagePacks = [ "en-US" ];
preferences = {
# "identity.sync.tokenserver.uri": "https://ffsync.fizz.buzz/token/1.0/sync/1.5";
@@ -134,7 +134,7 @@
users.talexander = {
directories = [
{
directory = ".mozilla";
directory = ".config/mozilla";
user = "talexander";
group = "talexander";
mode = "0700";

View File

@@ -18,7 +18,7 @@
};
config = lib.mkIf config.me.gcloud.enable {
environment.systemPackages = with pkgs.google; [
environment.systemPackages = with pkgs; [
(google-cloud-sdk.withExtraComponents [ google-cloud-sdk.components.gke-gcloud-auth-plugin ])
];

View File

@@ -61,6 +61,7 @@
systemd.services."build-cache" =
let
enabled_targets = [
"wip"
"odo"
"odo_update"
"odowork"
@@ -83,7 +84,10 @@
"worker2_update"
"family_disks"
"family_disks_update"
# "nixbsd" # Disabled due to onetbb tests hanging on one-cpu machines.
"nixbsd"
"nix_builder_develop"
"organic_develop"
"natter_develop"
];
build_flags = lib.concatMap (target: [
"--target"
@@ -96,6 +100,7 @@
IFS=$'\n\t'
DIR="$( cd "$( dirname "''${BASH_SOURCE[0]}" )" && pwd )"
NIX_REMOTE='local?root=/.disk/root' RUST_BACKTRACE=1 RUST_LOG=nix_builder=DEBUG ${nix_builder.packages.x86_64-linux.default}/bin/nix-builder clean --config ${./files/nix_builder.toml}
NIX_REMOTE='local?root=/.disk/root' RUST_BACKTRACE=1 RUST_LOG=nix_builder=DEBUG ${nix_builder.packages.x86_64-linux.default}/bin/nix-builder build --config ${./files/nix_builder.toml} ${builtins.concatStringsSep " " build_flags}
'';
restartIfChanged = false;

View File

@@ -1,5 +1,12 @@
output_directory = "/home/nixworker/persist/nix_builder"
[[targets]]
name = "wip"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "wip"
path = "nix/configuration"
attr = "nixosConfigurations.odo.config.system.build.toplevel"
[[targets]]
name = "odo"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
@@ -67,98 +74,98 @@ output_directory = "/home/nixworker/persist/nix_builder"
[[targets]]
name = "controller0"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "controller0.vm_iso"
[[targets]]
name = "controller0_update"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "controller0.vm_iso"
update = true
update_branch = "kubernetes_update"
update_branch = "nix_update"
[[targets]]
name = "controller1"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "controller1.vm_iso"
[[targets]]
name = "controller1_update"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "controller1.vm_iso"
update = true
update_branch = "kubernetes_update"
update_branch = "nix_update"
[[targets]]
name = "controller2"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "controller2.vm_iso"
[[targets]]
name = "controller2_update"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "controller2.vm_iso"
update = true
update_branch = "kubernetes_update"
update_branch = "nix_update"
[[targets]]
name = "worker0"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "worker0.vm_iso"
[[targets]]
name = "worker0_update"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "worker0.vm_iso"
update = true
update_branch = "kubernetes_update"
update_branch = "nix_update"
[[targets]]
name = "worker1"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "worker1.vm_iso"
[[targets]]
name = "worker1_update"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "worker1.vm_iso"
update = true
update_branch = "kubernetes_update"
update_branch = "nix_update"
[[targets]]
name = "worker2"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "worker2.vm_iso"
[[targets]]
name = "worker2_update"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "kubernetes"
branch = "nix"
path = "nix/kubernetes"
attr = "worker2.vm_iso"
update = true
update_branch = "kubernetes_update"
update_branch = "nix_update"
# TODO: Add steam deck
@@ -178,9 +185,30 @@ output_directory = "/home/nixworker/persist/nix_builder"
update = true
update_branch = "nix_update"
# [[targets]]
# name = "nixbsd"
# repo = "https://github.com/nixos-bsd/nixbsd.git"
# revision = "828ff7a3c4ee91f548de65a963fca40eaedb171c"
# path = "."
# attr = "base.vmClosureInfo"
[[targets]]
name = "nixbsd"
repo = "https://code.fizz.buzz/talexander/machine_setup.git"
branch = "nixbsd"
path = "nix/nixbsd"
attr = "computer.vm"
[[targets]]
name = "nix_builder_develop"
repo = "https://code.fizz.buzz/talexander/nix_builder.git"
branch = "main"
path = "."
attr = "devShells.x86_64-linux.default"
[[targets]]
name = "organic_develop"
repo = "https://code.fizz.buzz/talexander/organic.git"
branch = "main"
path = "."
attr = "devShells.x86_64-linux.default"
[[targets]]
name = "natter_develop"
repo = "https://code.fizz.buzz/talexander/natter.git"
branch = "main"
path = "."
attr = "devShells.x86_64-linux.default"

View File

@@ -0,0 +1,25 @@
{
config,
lib,
pkgs,
...
}:
{
imports = [ ];
options.me = {
instawow.enable = lib.mkOption {
type = lib.types.bool;
default = false;
example = true;
description = "Whether we want to install instawow.";
};
};
config = lib.mkIf config.me.instawow.enable {
environment.systemPackages = with pkgs; [
instawow
];
};
}

View File

@@ -14,30 +14,12 @@ let
full = {
PREEMPT_DYNAMIC = yes;
PREEMPT = yes;
PREEMPT_VOLUNTARY = lib.mkForce no;
PREEMPT_LAZY = lib.mkForce no;
PREEMPT_NONE = no;
};
lazy = {
PREEMPT_DYNAMIC = yes;
PREEMPT = no;
PREEMPT_VOLUNTARY = lib.mkForce no;
PREEMPT_LAZY = yes;
PREEMPT_NONE = no;
};
voluntary = {
PREEMPT_DYNAMIC = no;
PREEMPT = no;
PREEMPT_VOLUNTARY = yes;
PREEMPT_LAZY = lib.mkForce no;
PREEMPT_NONE = no;
};
none = {
PREEMPT_DYNAMIC = no;
PREEMPT = no;
PREEMPT_VOLUNTARY = lib.mkForce no;
PREEMPT_LAZY = lib.mkForce no;
PREEMPT_NONE = yes;
};
};
tick_hz =
@@ -99,16 +81,14 @@ let
TRANSPARENT_HUGEPAGE_MADVISE = yes;
};
};
common_config =
with lib.kernel;
{
# Google's BBRv3 TCP congestion Control
TCP_CONG_BBR = yes;
DEFAULT_BBR = yes;
};
common_config = with lib.kernel; {
# Google's BBRv3 TCP congestion Control
TCP_CONG_BBR = yes;
DEFAULT_BBR = yes;
};
flavors = {
server = lib.mkMerge [
preemption_type.none
preemption_type.lazy
tick_hz."300"
performance_governor.default
tick_rate.tickless
@@ -142,7 +122,8 @@ in
kernel.version = lib.mkOption {
type = lib.types.str;
default = "linux"; # LTS
# default = "linux"; # LTS
default = "linux_7_2"; # LTS
example = "linux_6_18";
description = "What version of the kernl should we use.";
};

View File

@@ -25,8 +25,8 @@
nixpkgs.overlays = [
(final: prev: {
tex = (
pkgs.texlive.combine {
inherit (pkgs.texlive)
pkgs.texliveSmall.withPackages (
ps: with ps; [
scheme-basic
dvisvgm
dvipng # for preview and export as html in org-mode
@@ -44,8 +44,8 @@
upquote # emacs org-mode pdf export
lineno # emacs org-mode pdf export
beamer # emacs org-mode presentation pdf export
;
}
]
)
);
})
];

View File

@@ -0,0 +1,25 @@
{
config,
lib,
pkgs,
...
}:
{
imports = [ ];
options.me = {
mitmproxy.enable = lib.mkOption {
type = lib.types.bool;
default = false;
example = true;
description = "Whether we want to install mitmproxy.";
};
};
config = lib.mkIf config.me.mitmproxy.enable {
environment.systemPackages = with pkgs; [
mitmproxy
];
};
}

View File

@@ -6,6 +6,8 @@
}:
# Alternative DNS servers:
# "194.242.2.2#doh.mullvad.net"
# "2a07:e340::2#doh.mullvad.net"
# "1.0.0.1#cloudflare-dns.com"
# "1.1.1.1#cloudflare-dns.com"
# "2606:4700:4700::1001#cloudflare-dns.com"
@@ -14,6 +16,10 @@
# "8.8.8.8#dns.google"
# "2001:4860:4860::8844#dns.google"
# "2001:4860:4860::8888#dns.google"
# "9.9.9.10#dns10.quad9.net"
# "149.112.112.10#dns10.quad9.net"
# "2620:fe::10#dns10.quad9.net"
# "2620:fe::fe:10#dns10.quad9.net"
let
patchScriptBin =
@@ -39,8 +45,10 @@ in
networking.dhcpcd.enable = lib.mkDefault false;
networking.useDHCP = lib.mkDefault false;
networking.nameservers = [
"194.242.2.2#doh.mullvad.net"
"2a07:e340::2#doh.mullvad.net"
"9.9.9.10#dns10.quad9.net"
"149.112.112.10#dns10.quad9.net"
"2620:fe::10#dns10.quad9.net"
"2620:fe::fe:10#dns10.quad9.net"
];
services.resolved = {
enable = true;
@@ -56,6 +64,7 @@ in
# TODO: The 127.0.0.1 address should probably be moved to a host-specific file.
networking.extraHosts = ''
127.0.0.1 ${config.networking.hostName}.home.arpa
127.0.0.3 metadata.google.internal
10.216.1.32 homeserver
fdfd:5e8a:ee2d::1:32 homeserver
10.216.1.6 media
@@ -67,7 +76,15 @@ in
10.217.1.1 drmario
10.217.2.1 mrmanager
fdfd:5e8a:ee2d::2:2 mrmanager
172.16.16.1 unifi
172.16.16.231 plug1
172.16.16.232 plug2
172.16.16.233 plug3
172.16.16.234 plug4
172.16.16.235 temperature1
172.16.16.236 temperature2
172.16.16.245 turtle
172.16.16.250 sauna
172.16.16.251 stream
'';

View File

@@ -34,7 +34,9 @@
# Write config files in /etc/containers
virtualisation.containers.enable = true;
# By default this includes "quay.io" which leads to prompting for which registry to download from.
virtualisation.containers.registries.search = [ "docker.io" ];
virtualisation.containers.registries.settings = {
unqualified-search-registries = [ "docker.io" ];
};
virtualisation = {
podman = {
enable = true;
@@ -50,6 +52,23 @@
DOCKER_HOST = "unix://$XDG_RUNTIME_DIR/podman/podman.sock";
};
# Increase subuid / subgid to support running buildkit-rootless
# ref: https://github.com/moby/buildkit/issues/3297
users.users.talexander = {
subUidRanges = [
{
startUid = 100000;
count = 262144; # default = 65536
}
];
subGidRanges = [
{
startGid = 100000;
count = 262144; # default = 65536
}
];
};
environment.persistence."/state" = lib.mkIf (config.me.mountPersistence) {
hideMounts = true;
directories = [

View File

@@ -38,7 +38,7 @@ in
};
};
Miscellaneous = {
"Pause emulation on RPCS3 focus loss" = true;
"Pause emulation on RPCS3 focus loss" = false;
"Start games in fullscreen mode" = true;
"Pause Emulation During Home Menu" = false; # true makes the home menu slow
};
@@ -53,7 +53,10 @@ in
rpcs3
];
allowedUnfree = [ "rpcs3" ];
allowedUnfree = [
"rpcs3"
"corefonts"
];
security.pam.loginLimits = [
{
@@ -70,6 +73,10 @@ in
}
];
fonts.packages = with pkgs; [
corefonts # Needed for Arial, otherwise launching games fails.
];
me.install.user.talexander.file = {
".config/rpcs3/config.yml" = lib.mkIf (config.me.rpcs3.config != null) {
source = rpcs3_config_yaml;
@@ -81,6 +88,10 @@ in
# Demon's Souls per-game config.
source = ./files/config_BLUS30443.yml;
};
".config/rpcs3/custom_configs/config_BLUS30421.yml" = {
# The Lord of the Rings The War in the North per-game config.
source = ./files/config_BLUS30421.yml;
};
".config/rpcs3/patches/patch.yml" = {
# All of the available patches.
source = ./files/patch.yml;

View File

@@ -0,0 +1,14 @@
Core:
SPU Block Size: Safe
Video:
Write Color Buffers: true
Minimum Scalable Dimension: 640
Net:
Internet enabled: Connected
IP address: 0.0.0.0
Bind address: 0.0.0.0
DNS address: 8.8.8.8
IP swap list: ""
UPNP Enabled: false
PSN status: RPCN
PSN Country: us

View File

@@ -20,8 +20,9 @@
config = lib.mkIf (config.me.wine.enable && config.me.graphical) {
environment.systemPackages = with pkgs; [
# wineWowPackages.stable # supports 32 + 64 bit
wineWowPackages.waylandFull # Supports 32 + 64 bit with native wayland support.
wineWow64Packages.waylandFull # Supports 32 + 64 bit with native wayland support.
# winetricks
# lutris
];
};
}

View File

@@ -41,7 +41,7 @@
nix.settings.experimental-features = [
"nix-command"
"flakes"
"ca-derivations"
# "ca-derivations"
# "blake3-hashes"
# "git-hashing"
];
@@ -64,6 +64,10 @@
};
nix.settings.auto-optimise-store = !config.me.buildingPortable;
# Disable installing documentation.
documentation.doc.enable = false;
documentation.nixos.enable = false;
environment.persistence."/persist" = lib.mkIf (config.me.mountPersistence) {
hideMounts = true;
directories = [

View File

@@ -22,11 +22,11 @@
]
},
"locked": {
"lastModified": 1780290312,
"narHash": "sha256-eTAlX0CwgB84Ts3GaBd944A3DRXVMzgA0EqroZBISUo=",
"lastModified": 1781152676,
"narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=",
"owner": "nix-community",
"repo": "disko",
"rev": "115e5211780054d8a890b41f0b7734cafad54dfe",
"rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1",
"type": "github"
},
"original": {
@@ -164,11 +164,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1780749050,
"narHash": "sha256-3av0pIjlOWQ6rDbNOmpUSvbNnJkGORQKKjb4LtCZsIY=",
"lastModified": 1788752844,
"narHash": "sha256-VaWGJ6+cIYN2erfSecbRV+4ljI185Ty2wUrXyvQbgOw=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "a799d3e3886da994fa307f817a6bc705ae538eeb",
"rev": "dc5d91f840324650bac8c379428c7037a416959a",
"type": "github"
},
"original": {

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -66,6 +66,12 @@ let
group = "26";
mode = "0755";
}
{
path = "manual-pv/ncps-psql";
owner = "26";
group = "26";
mode = "0755";
}
# {
# path = "manual-pv/gitea";
# owner = "1000";

View File

@@ -63,6 +63,7 @@ let
username = builtins.readFile "${./secrets/flux-system/registry-credentials/username}";
password = builtins.readFile "${./secrets/flux-system/registry-credentials/password}";
email = builtins.readFile "${./secrets/flux-system/registry-credentials/email}";
address = builtins.readFile "${./secrets/flux-system/registry-credentials/address}";
})
// {
# "__annotations" = {
@@ -103,6 +104,11 @@ let
"homepage-staging" = {
"oauth2-env" = oauth2_env { dex_id = "homepage-staging"; };
};
"nix-pull-through-cache" = {
"auth" = {
"CACHE_GET_TOKEN" = (builtins.readFile "${./secrets/nix-pull-through-cache/auth/CACHE_GET_TOKEN}");
};
};
"tekton-gateway" = {
"oauth2-env" = oauth2_env { dex_id = "tekton"; };
};
@@ -125,6 +131,21 @@ let
"harbor-plain" = {
"config.json" = (builtins.readFile "${./secrets/webhook-bridge/harbor-plain/config.json}");
};
"nix-pull-through-cache" = {
"CACHE_GET_TOKEN" = (builtins.readFile "${./secrets/nix-pull-through-cache/auth/CACHE_GET_TOKEN}");
};
"registry-credentials" =
(generate_docker_secret {
username = builtins.readFile "${./secrets/flux-system/registry-credentials/username}";
password = builtins.readFile "${./secrets/flux-system/registry-credentials/password}";
email = builtins.readFile "${./secrets/flux-system/registry-credentials/email}";
address = builtins.readFile "${./secrets/flux-system/registry-credentials/address}";
})
// {
# "__annotations" = {
# "tekton.dev/docker-0" = "https://harbor.fizz.buzz";
# };
};
};
};
encrypted_secrets = (
@@ -199,14 +220,19 @@ let
username,
password,
email,
address,
}:
let
in
{
"__type" = "kubernetes.io/dockerconfigjson";
".dockerconfigjson" = builtins.toJSON {
inherit username password email;
"auth" = toBase64 "${username}:${password}";
auths = {
"${address}" = {
inherit username password email;
"auth" = toBase64 "${username}:${password}";
};
};
};
};
## dex

View File

@@ -25,6 +25,7 @@
gptfdisk # cgdisk
arp-scan # To find devices on the network
ldns # for drill
parted
];
# This can make debugging easier by rejecting packets instead of dropping them:

View File

@@ -48,6 +48,12 @@ let
"fd00:3e42:e349::10"
];
imageMaximumGCAge = "24h"; # Delete unused images after 1 day.
imageGCHighThresholdPercent = 80;
imageGCLowThresholdPercent = 70;
evictionHard = {
"nodefs.available" = "5%";
"imagefs.available" = "10%";
};
};
kubelet_config_file = (to_yaml_file "kubelet-config.yaml" kubelet_config);
in

View File

@@ -21,7 +21,7 @@
assertions = [
{
# Kubernetes should only upgrade 1 minor version at a time, so this assert is here to prevent unwittingly jumping versions.
assertion = lib.hasPrefix "1.36." pkgs.kubernetes.version;
assertion = lib.hasPrefix "1.37." pkgs.kubernetes.version;
message = "Unexpected Kubernetes package version: ${pkgs.kubernetes.version}";
}
];