Home

infra @main - refs - log -
-
https://git.jolheiser.com/infra.git
dragonwell flake
tree log patch
all: refactor to mirror dragonwell setup Signed-off-by: jolheiser <git@jolheiser.com>
Signature
-----BEGIN SSH SIGNATURE----- U1NIU0lHAAAAAQAAADMAAAALc3NoLWVkMjU1MTkAAAAgBTEvCQk6VqUAdN2RuH6bj1dNkY oOpbPWj+jw4ua1B1cAAAADZ2l0AAAAAAAAAAZzaGE1MTIAAABTAAAAC3NzaC1lZDI1NTE5 AAAAQCZp0cpDjC6qTaIHGi/eAhJBxEQYuuRaN3OZC/Kfj84Jxy0buT9YuYjYyfSYjvJZM6 IoOQfyR/kdcbxfDEMapAU= -----END SSH SIGNATURE-----
jolheiser <git@jolheiser.com>
1 day ago
23 changed files, 205 additions(+), 136 deletions(-)
config.nixdragonwell/default.nixgunpowder/services/beszel.nixgunpowder/default.nixgunpowder/services/bazarr.nixgunpowder/services/jellyfin.nixgunpowder/services/prowlarr.nixgunpowder/services/radarr.nixgunpowder/services/sonarr.nixjasmine/beszel.nixjasmine/services/cifs.nixjasmine/default.nixjasmine/homeassistant.nixjasmine/services/beszel.nixjasmine/services/homeassistant.nixjasmine/services/slideshow.nixshincha/services/beszel.nixshincha/services/cfg.nixshincha/default.nixshincha/services/golink.nixshincha/services/mazanoke.nixshincha/services/oidc.nixshincha/services/tclip.nix
M config.nix -> config.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
diff --git a/config.nix b/config.nix
index 05104fdac163f686a3c899a9a4af626b5bccd45b..3978417c411e65f0c880733198f34ef5b547fc11 100644
--- a/config.nix
+++ b/config.nix
@@ -3,6 +3,5 @@   pkgs ? import <nixpkgs> { },
 }:
 {
   username = "jolheiser";
-  sshKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL+uhnfFLhlyfGGsksSxh5IIY6gnIMryeQ2EiM979kZa";
   domain = "jolheiser.com";
 }
M dragonwell/default.nix -> dragonwell/default.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
diff --git a/dragonwell/default.nix b/dragonwell/default.nix
index 738e174071e819dbcb9ab4563e9e4a907c3cc7ff..8480926ea43d7a4c0098c7433cbbf11e2010369e 100644
--- a/dragonwell/default.nix
+++ b/dragonwell/default.nix
@@ -1,4 +1,7 @@
 { jolheiser, ... }:
+let
+  key = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL+uhnfFLhlyfGGsksSxh5IIY6gnIMryeQ2EiM979kZa";
+in
 {
   imports =
     (map (name: ./services + "/${name}") (builtins.attrNames (builtins.readDir ./services)))
@@ -36,9 +39,9 @@         "docker"
         "storage"
       ];
       isNormalUser = true;
-      openssh.authorizedKeys.keys = [ jolheiser.sshKey ];
+      openssh.authorizedKeys.keys = [ key ];
     };
-    "root".openssh.authorizedKeys.keys = [ jolheiser.sshKey ];
+    "root".openssh.authorizedKeys.keys = [ key ];
   };
 
   nix = {
M gunpowder/beszel.nix -> gunpowder/services/beszel.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
diff --git a/gunpowder/beszel.nix b/gunpowder/services/beszel.nix
rename from gunpowder/beszel.nix
rename to gunpowder/services/beszel.nix
index d6e2596e5936819d7be2ab24125c526b879098f0..ff157f647a0f75d2d98c9307aa2e5cfba2cab0e5 100644
--- a/gunpowder/beszel.nix
+++ b/gunpowder/services/beszel.nix
@@ -1,6 +1,9 @@
-{ config, ... }:
-{
-  age.secrets.beszel-gunpowder.file = ../secrets/beszel-gunpowder.age;
+{ lib, config, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
+  age.secrets.beszel-gunpowder.file = ../../secrets/beszel-gunpowder.age;
   services.beszel.agent = {
     enable = true;
     environment = {
M gunpowder/default.nix -> gunpowder/default.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
diff --git a/gunpowder/default.nix b/gunpowder/default.nix
index ef70ac02f632e38dbdd9ec733db6097aaf9648c6..00dd9604e462031a376fdea59aeff4336fa25b3c 100644
--- a/gunpowder/default.nix
+++ b/gunpowder/default.nix
@@ -1,13 +1,11 @@
-{ pkgs, ... }:
+{ jolheiser, pkgs, ... }:
 let
-  username = "jolheiser";
   key = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJh5aUDN/KN28+4tbayXRQliLyKFZaCZtUMEBNaJfHYj";
 in
 {
-  imports = [
-    ./beszel.nix
-    ./hardware.nix
-  ];
+  imports =
+    (map (name: ./services + "/${name}") (builtins.attrNames (builtins.readDir ./services)))
+    ++ [ ./hardware.nix ];
 
   boot = {
     kernelPackages = pkgs.linuxPackages_latest;
@@ -54,63 +52,11 @@       enable = true;
       package = pkgs.mullvad-vpn;
     };
     resolved.enable = true;
-
-    # media
-    jellyfin = {
-      enable = true;
-      openFirewall = true;
-    };
-    tailproxy.jellyfin = {
-      enable = true;
-      hostname = "jellyfin";
-      port = 8096;
-      authKey = "tskey-auth-khZwt3ASDX11CNTRL-jYDAVuX7VVLCebLUGdvnVLLoUkeEevXEV"; # One-time key
-    };
-    sonarr = {
-      enable = true;
-      openFirewall = true;
-    };
-    tailproxy.sonarr = {
-      enable = true;
-      hostname = "sonarr";
-      port = 8989;
-      authKey = "tskey-auth-k1mZ4587A511CNTRL-uxq54KBAvb6YuhvZbxscb6rf7x8UwNiP"; # One-time key
-    };
-    radarr = {
-      enable = true;
-      openFirewall = true;
-    };
-    tailproxy.radarr = {
-      enable = true;
-      hostname = "radarr";
-      port = 7878;
-      authKey = "tskey-auth-kjuWphWmFp11CNTRL-dcpVCTbdPTAAiqQHaKVhTA27uNQeHxmq5"; # One-time key
-    };
-    bazarr = {
-      enable = true;
-      openFirewall = true;
-    };
-    tailproxy.bazarr = {
-      enable = true;
-      hostname = "bazarr";
-      port = 6767;
-      authKey = "tskey-auth-kydeAt7KDA21CNTRL-bLfZMG4ip4i4a91DX1b85ipjnZi9KgoN9"; # One-time key
-    };
-    prowlarr = {
-      enable = true;
-      openFirewall = true;
-    };
-    tailproxy.prowlarr = {
-      enable = true;
-      hostname = "prowlarr";
-      port = 9696;
-      authKey = "tskey-auth-koCbGEVEvh11CNTRL-7pxqVBdP4v5xNvsPP5mMv5oW8PrgVQmb"; # One-time key
-    };
   };
 
   users = {
     users = {
-      "${username}" = {
+      "${jolheiser.username}" = {
         extraGroups = [
           "wheel"
           "docker"
@@ -124,9 +70,6 @@     };
     groups.media.members = [
       "jolheiser"
       "olheiser"
-      "jellyfin"
-      "radarr"
-      "sonarr"
     ];
   };
 
I gunpowder/services/bazarr.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
diff --git a/gunpowder/services/bazarr.nix b/gunpowder/services/bazarr.nix
new file mode 100644
index 0000000000000000000000000000000000000000..9a1ea19bd78afc4f5576f652b8939a5f9cc360fe
--- /dev/null
+++ b/gunpowder/services/bazarr.nix
@@ -0,0 +1,18 @@
+{ lib, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
+  services = {
+    bazarr = {
+      enable = true;
+      openFirewall = true;
+    };
+    tailproxy.bazarr = {
+      enable = true;
+      hostname = "bazarr";
+      port = 6767;
+      authKey = "tskey-auth-kydeAt7KDA21CNTRL-bLfZMG4ip4i4a91DX1b85ipjnZi9KgoN9"; # One-time key
+    };
+  };
+}
I gunpowder/services/jellyfin.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
diff --git a/gunpowder/services/jellyfin.nix b/gunpowder/services/jellyfin.nix
new file mode 100644
index 0000000000000000000000000000000000000000..2f8374d7eefd66c06e0c231a4aec3caee7007bde
--- /dev/null
+++ b/gunpowder/services/jellyfin.nix
@@ -0,0 +1,19 @@
+{ lib, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
+  services = {
+    jellyfin = {
+      enable = true;
+      openFirewall = true;
+    };
+    tailproxy.jellyfin = {
+      enable = true;
+      hostname = "jellyfin";
+      port = 8096;
+      authKey = "tskey-auth-khZwt3ASDX11CNTRL-jYDAVuX7VVLCebLUGdvnVLLoUkeEevXEV"; # One-time key
+    };
+  };
+  users.groups.media.members = [ "jellyfin" ];
+}
I gunpowder/services/prowlarr.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
diff --git a/gunpowder/services/prowlarr.nix b/gunpowder/services/prowlarr.nix
new file mode 100644
index 0000000000000000000000000000000000000000..d3dc752b8e133ca10dcd9e01dd9ae0ca99179811
--- /dev/null
+++ b/gunpowder/services/prowlarr.nix
@@ -0,0 +1,18 @@
+{ lib, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
+  services = {
+    prowlarr = {
+      enable = true;
+      openFirewall = true;
+    };
+    tailproxy.prowlarr = {
+      enable = true;
+      hostname = "prowlarr";
+      port = 9696;
+      authKey = "tskey-auth-koCbGEVEvh11CNTRL-7pxqVBdP4v5xNvsPP5mMv5oW8PrgVQmb"; # One-time key
+    };
+  };
+}
I gunpowder/services/radarr.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
diff --git a/gunpowder/services/radarr.nix b/gunpowder/services/radarr.nix
new file mode 100644
index 0000000000000000000000000000000000000000..14afd26fb07ff5782d5fc1569f403ab03cd997c3
--- /dev/null
+++ b/gunpowder/services/radarr.nix
@@ -0,0 +1,19 @@
+{ lib, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
+  services = {
+    radarr = {
+      enable = true;
+      openFirewall = true;
+    };
+    tailproxy.radarr = {
+      enable = true;
+      hostname = "radarr";
+      port = 7878;
+      authKey = "tskey-auth-kjuWphWmFp11CNTRL-dcpVCTbdPTAAiqQHaKVhTA27uNQeHxmq5"; # One-time key
+    };
+  };
+  users.groups.media.members = [ "radarr" ];
+}
I gunpowder/services/sonarr.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
diff --git a/gunpowder/services/sonarr.nix b/gunpowder/services/sonarr.nix
new file mode 100644
index 0000000000000000000000000000000000000000..7ff6f9354eec58dac82b181cb6458a26736e993d
--- /dev/null
+++ b/gunpowder/services/sonarr.nix
@@ -0,0 +1,19 @@
+{ lib, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
+  services = {
+    sonarr = {
+      enable = true;
+      openFirewall = true;
+    };
+    tailproxy.sonarr = {
+      enable = true;
+      hostname = "sonarr";
+      port = 8989;
+      authKey = "tskey-auth-k1mZ4587A511CNTRL-uxq54KBAvb6YuhvZbxscb6rf7x8UwNiP"; # One-time key
+    };
+  };
+  users.groups.media.members = [ "sonarr" ];
+}
D jasmine/beszel.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
diff --git a/jasmine/beszel.nix b/jasmine/beszel.nix
deleted file mode 100644
index eb7e365c97c24da7d856564f87b6673160addfa8..0000000000000000000000000000000000000000
--- a/jasmine/beszel.nix
+++ /dev/null
@@ -1,9 +0,0 @@
-{ config, ... }:
-{
-  age.secrets.beszel-jasmine.file = ../secrets/beszel-jasmine.age;
-  services.beszel.agent = {
-    enable = true;
-    environment.LOG_LEVEL = "info";
-    environmentFile = config.age.secrets.beszel-jasmine.path;
-  };
-}
M jasmine/cifs.nix -> jasmine/services/cifs.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
diff --git a/jasmine/cifs.nix b/jasmine/services/cifs.nix
rename from jasmine/cifs.nix
rename to jasmine/services/cifs.nix
index 67cd47fb413ebb7ec6b66a4e44d8ffa8a6f3fece..bd664b66c97a6cd6c620b7a78c212f01864069c0 100644
--- a/jasmine/cifs.nix
+++ b/jasmine/services/cifs.nix
@@ -1,6 +1,14 @@
-{ pkgs, config, ... }:
 {
-  age.secrets.cifs.file = ../secrets/cifs.age;
+  pkgs,
+  lib,
+  config,
+  ...
+}:
+let
+  enable = true;
+in
+lib.mkIf enable {
+  age.secrets.cifs.file = ../../secrets/cifs.age;
   environment.systemPackages = [ pkgs.cifs-utils ];
   fileSystems."/mnt/slideshow" = {
     device = "//192.168.40.244/slideshow";
M jasmine/default.nix -> jasmine/default.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
diff --git a/jasmine/default.nix b/jasmine/default.nix
index 8c66d174aa477608eeeacf8c2b19d085f1c4edb1..0a2111e64105bbf1de243efb93c1a60baad14eb3 100644
--- a/jasmine/default.nix
+++ b/jasmine/default.nix
@@ -1,16 +1,11 @@
-{ pkgs, ... }:
+{ jolheiser, pkgs, ... }:
 let
-  username = "jolheiser";
   key = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIM7cgpIUaEY3q12xBct9a0gIl7rdckBBPsWQea7Wtj7P";
 in
 {
-  imports = [
-    ./beszel.nix
-    ./cifs.nix
-    ./homeassistant.nix
-    ./slideshow.nix
-    ./hardware.nix
-  ];
+  imports =
+    (map (name: ./services + "/${name}") (builtins.attrNames (builtins.readDir ./services)))
+    ++ [ ./hardware.nix ];
 
   boot.loader.grub = {
     enable = true;
@@ -48,7 +43,7 @@     displayManager = {
       lightdm.enable = true;
       autoLogin = {
         enable = true;
-        user = username;
+        user = jolheiser.username;
       };
       defaultSession = "none+i3";
     };
@@ -62,7 +57,7 @@     fail2ban.enable = true;
   };
 
   users.users = {
-    "${username}" = {
+    "${jolheiser.username}" = {
       isNormalUser = true;
       extraGroups = [
         "networkmanager"
@@ -86,7 +81,7 @@     settings = {
       trusted-users = [
         "@sudo"
         "@wheel"
-        "jolheiser"
+        "${jolheiser.username}"
       ];
       experimental-features = [
         "flakes"
D jasmine/homeassistant.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
diff --git a/jasmine/homeassistant.nix b/jasmine/homeassistant.nix
deleted file mode 100644
index 9e7eb2df922b4ab263484c458c4d97430cd80e13..0000000000000000000000000000000000000000
--- a/jasmine/homeassistant.nix
+++ /dev/null
@@ -1,18 +0,0 @@
-{
-  virtualisation.oci-containers = {
-    backend = "podman";
-    containers.homeassistant = {
-      volumes = [ "home-assistant:/config" ];
-      environment.TZ = "America/Chicago";
-      image = "ghcr.io/home-assistant/home-assistant:stable"; # Warning: if the tag does not change, the image will not be updated
-      extraOptions = [
-        "--network=host"
-        # "--device=/dev/ttyACM0:/dev/ttyACM0" # Example, change this to match your own hardware
-      ];
-    };
-  };
-  networking.firewall.allowedTCPPorts = [
-    4001
-    8123
-  ];
-}
I jasmine/services/beszel.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
diff --git a/jasmine/services/beszel.nix b/jasmine/services/beszel.nix
new file mode 100644
index 0000000000000000000000000000000000000000..080293f0a46c4bb78affce11ef129b2d86ad7e5f
--- /dev/null
+++ b/jasmine/services/beszel.nix
@@ -0,0 +1,12 @@
+{ config, lib, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
+  age.secrets.beszel-jasmine.file = ../../secrets/beszel-jasmine.age;
+  services.beszel.agent = {
+    enable = true;
+    environment.LOG_LEVEL = "info";
+    environmentFile = config.age.secrets.beszel-jasmine.path;
+  };
+}
I jasmine/services/homeassistant.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
diff --git a/jasmine/services/homeassistant.nix b/jasmine/services/homeassistant.nix
new file mode 100644
index 0000000000000000000000000000000000000000..0970eedeec0a01fdd586eb9e1b53c78d7ba16d0b
--- /dev/null
+++ b/jasmine/services/homeassistant.nix
@@ -0,0 +1,21 @@
+{ lib, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
+  virtualisation.oci-containers = {
+    backend = "podman";
+    containers.homeassistant = {
+      volumes = [ "home-assistant:/config" ];
+      environment.TZ = "America/Chicago";
+      image = "ghcr.io/home-assistant/home-assistant:stable";
+      extraOptions = [
+        "--network=host"
+      ];
+    };
+  };
+  networking.firewall.allowedTCPPorts = [
+    4001
+    8123
+  ];
+}
M jasmine/slideshow.nix -> jasmine/services/slideshow.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
diff --git a/jasmine/slideshow.nix b/jasmine/services/slideshow.nix
rename from jasmine/slideshow.nix
rename to jasmine/services/slideshow.nix
index e9ff241c2676cfbf93563eb49f0273da66df8822..1b64a6cd315cda310d24d47360347445ae4319e4 100644
--- a/jasmine/slideshow.nix
+++ b/jasmine/services/slideshow.nix
@@ -1,5 +1,6 @@
-{ pkgs, ... }:
+{ pkgs, lib, ... }:
 let
+  enable = true;
   root = "/mnt/slideshow";
   slideshow = pkgs.writeShellApplication {
     name = "slideshow";
@@ -26,7 +27,7 @@       done
     '';
   };
 in
-{
+lib.mkIf enable {
   systemd.user.services = {
     slideshow = {
       description = "Autostart slideshow";
M shincha/beszel.nix -> shincha/services/beszel.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
diff --git a/shincha/beszel.nix b/shincha/services/beszel.nix
rename from shincha/beszel.nix
rename to shincha/services/beszel.nix
index 994c9bae452b48dcfa244f820c2f996e8b9d2029..2dabfc532355111581407a80a8daabbdff161fa2 100644
--- a/shincha/beszel.nix
+++ b/shincha/services/beszel.nix
@@ -1,6 +1,10 @@
-{ config, ... }:
-{
-  age.secrets.beszel-shincha.file = ../secrets/beszel-shincha.age;
+{ lib, config, ... }:
+let
+  enable = true;
+  host = "monit";
+in
+lib.mkIf enable {
+  age.secrets.beszel-shincha.file = ../../secrets/beszel-shincha.age;
   services = {
     beszel = {
       agent = {
@@ -11,14 +15,14 @@       };
       hub = {
         enable = true;
         environment = {
-          APP_URL = "https://monit";
+          APP_URL = "https://${host}";
           DISABLE_PASSWORD_AUTH = "true";
         };
       };
     };
     tailproxy.beszel = {
       enable = true;
-      hostname = "monit";
+      hostname = host;
       authKey = "tskey-auth-krRJB4JVL321CNTRL-Vfaa8HZwsVXzTU4MUAnBWXsZMCcFbrLVe"; # One-time key
       port = 8090;
     };
M shincha/cfg.nix -> shincha/services/cfg.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
diff --git a/shincha/cfg.nix b/shincha/services/cfg.nix
rename from shincha/cfg.nix
rename to shincha/services/cfg.nix
index 3f2ef70e0d880571df46bcbaeb7a1ee608a936b0..0f6ff9b2ae41291f32a686942b7d4c2467ce58fc 100644
--- a/shincha/cfg.nix
+++ b/shincha/services/cfg.nix
@@ -1,4 +1,8 @@
-{
+{ lib, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
   services.cfg-playground = {
     enable = true;
     verbose = true;
M shincha/default.nix -> shincha/default.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
diff --git a/shincha/default.nix b/shincha/default.nix
index ab95b4ed457cef2e64caed915d5c036f8f56ed92..3248ae73e3b3043683c5c83c70facec3f8c541af 100644
--- a/shincha/default.nix
+++ b/shincha/default.nix
@@ -1,17 +1,11 @@
+{ jolheiser, ... }:
 let
-  username = "jolheiser";
   key = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJBxdG9mduIWiQ+egYKMvUKKCyShdeM8O6QsLs6g5aGt";
 in
 {
-  imports = [
-    ./beszel.nix
-    ./cfg.nix
-    ./golink.nix
-    ./mazanoke.nix
-    ./oidc.nix
-    ./tclip.nix
-    ./hardware.nix
-  ];
+  imports =
+    (map (name: ./services + "/${name}") (builtins.attrNames (builtins.readDir ./services)))
+    ++ [ ./hardware.nix ];
 
   boot.loader.grub = {
     enable = true;
@@ -59,7 +53,7 @@     openssh.enable = true;
   };
 
   users.users = {
-    "${username}" = {
+    "${jolheiser.username}" = {
       isNormalUser = true;
       extraGroups = [
         "networkmanager"
@@ -83,7 +77,7 @@     settings = {
       trusted-users = [
         "@sudo"
         "@wheel"
-        "jolheiser"
+        "${jolheiser.username}"
       ];
       experimental-features = [
         "flakes"
M shincha/golink.nix -> shincha/services/golink.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
diff --git a/shincha/golink.nix b/shincha/services/golink.nix
rename from shincha/golink.nix
rename to shincha/services/golink.nix
index 887a64d14787a93a00bdd342e2c74355a045ae4b..df19e38068712ec12690f1f0555dfcc375ca1860 100644
--- a/shincha/golink.nix
+++ b/shincha/services/golink.nix
@@ -1,5 +1,8 @@
-{ pkgs, ... }:
-{
+{ pkgs, lib, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
   services.golink = {
     enable = true;
     tailscaleAuthKeyFile = pkgs.writeText "tskey" "tskey-auth-k7Tfyvczdn11CNTRL-tE6VsLtnqEaTzfugS2XYEaEEaVQPxUsbf"; # One-time key
M shincha/mazanoke.nix -> shincha/services/mazanoke.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
diff --git a/shincha/mazanoke.nix b/shincha/services/mazanoke.nix
rename from shincha/mazanoke.nix
rename to shincha/services/mazanoke.nix
index db0415476f795cba4c8c4a20e7bcba8344248e8b..7c89e1e3e984d0208d48941605bc6b4555d91b56 100644
--- a/shincha/mazanoke.nix
+++ b/shincha/services/mazanoke.nix
@@ -1,4 +1,8 @@
-{
+{ lib, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
   services = {
     mazanoke.enable = true;
     tailproxy.mazanoke = {
M shincha/oidc.nix -> shincha/services/oidc.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
diff --git a/shincha/oidc.nix b/shincha/services/oidc.nix
rename from shincha/oidc.nix
rename to shincha/services/oidc.nix
index 5e32e51e8a5fa9232b4f5d65de28d87763778245..0f8712e74e2bf5b630e96e9132cbe939fb609bd1 100644
--- a/shincha/oidc.nix
+++ b/shincha/services/oidc.nix
@@ -1,12 +1,17 @@
-{
+{ lib, ... }:
+let
+  enable = true;
+  host = "oidc";
+in
+lib.mkIf enable {
   services = {
     oidc-playground = {
       enable = true;
-      origin = "https://oidc";
+      origin = "https://${host}";
     };
     tailproxy.oidc-playground = {
       enable = true;
-      hostname = "oidc";
+      hostname = host;
       authKey = "tskey-auth-kkFJ2NFkCX11CNTRL-Doq9XTGfm9Vxn8nb6QQU9VjmAh6ZFgih"; # One-time key
       port = 6432;
     };
M shincha/tclip.nix -> shincha/services/tclip.nix
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
diff --git a/shincha/tclip.nix b/shincha/services/tclip.nix
rename from shincha/tclip.nix
rename to shincha/services/tclip.nix
index 3c202edf97dceba83f4e0085bc3ac8dadeb65ece..8f159fafe73404b2417fc15a7f47dce0e0aba734 100644
--- a/shincha/tclip.nix
+++ b/shincha/services/tclip.nix
@@ -1,4 +1,8 @@
-{
+{ lib, ... }:
+let
+  enable = true;
+in
+lib.mkIf enable {
   services.tclip = {
     enable = true;
     hostname = "paste";