Compare commits

...

3 commits

Author SHA1 Message Date
Nick
e25a9bffc1 chore: removed fuckery 2025-11-23 03:02:08 -06:00
Nick
ccd625105c fix: miniserve removed 2025-11-23 03:01:57 -06:00
Nick
3790698e42 fix: tls certs 2025-11-23 03:01:42 -06:00
3 changed files with 33 additions and 45 deletions

View file

@ -23,7 +23,7 @@ in
networking.firewall.allowedTCPPorts = [ networking.firewall.allowedTCPPorts = [
22 22
8080 80
]; ];
services.openssh = { services.openssh = {
@ -44,15 +44,17 @@ in
gateway = [ serviceCfg.interface.gate ]; gateway = [ serviceCfg.interface.gate ];
}; };
}; };
};
services.website = { services.caddy = {
wantedBy = [ "multi-user.target" ]; enable = true;
after = [ "network.target" ]; virtualHosts.":80".extraConfig = ''
serviceConfig = { root * /etc/website
ExecStart = "${pkgs.miniserve}/bin/miniserve /etc/website --index index.html -p 8080";
Restart = "always"; file_server
};
}; try_files {path} /index.html
'';
}; };
microvm = { microvm = {
@ -66,6 +68,7 @@ in
mac = serviceCfg.interface.mac; mac = serviceCfg.interface.mac;
} }
]; ];
shares = [ shares = [
{ {
source = "/nix/store"; source = "/nix/store";
@ -81,7 +84,9 @@ in
services.caddy = { services.caddy = {
enable = true; enable = true;
virtualHosts.${host}.extraConfig = '' virtualHosts.${host}.extraConfig = ''
reverse_proxy ${serviceCfg.interface.ip}:8080 reverse_proxy ${serviceCfg.interface.ip}:80
tls /var/lib/acme/${host}/fullchain.pem /var/lib/acme/${host}/key.pem
''; '';
}; };

View file

@ -16,23 +16,17 @@ in
autostart = true; autostart = true;
config = { config = {
system.stateVersion = "25.05"; system.stateVersion = "25.05";
networking.firewall.allowedTCPPorts = [ networking.firewall.allowedTCPPorts = [
22 22
8080 80
]; ];
services.openssh = { services.openssh = {
enable = true; enable = true;
settings.PasswordAuthentication = false; settings.PasswordAuthentication = false;
}; };
environment.etc."website".source = websitePkg; environment.etc."website".source = websitePkg;
users.users.root.openssh.authorizedKeys.keys = flake.config.people.users.${user0}.sshKeys; users.users.root.openssh.authorizedKeys.keys = flake.config.people.users.${user0}.sshKeys;
systemd.network = {
systemd = {
network = {
enable = true; enable = true;
networks."10-enp" = { networks."10-enp" = {
matchConfig.Name = "enp0s3"; matchConfig.Name = "enp0s3";
@ -42,17 +36,14 @@ in
gateway = [ serviceCfg.interface.gate ]; gateway = [ serviceCfg.interface.gate ];
}; };
}; };
services.caddy = {
services.website = { enable = true;
wantedBy = [ "multi-user.target" ]; virtualHosts.":80".extraConfig = ''
after = [ "network.target" ]; root * /etc/website
serviceConfig = { file_server
ExecStart = "${pkgs.miniserve}/bin/miniserve /etc/website --index index.html -p 8080"; try_files {path} /index.html
Restart = "always"; '';
}; };
};
};
microvm = { microvm = {
vcpu = 2; vcpu = 2;
mem = 3072; mem = 3072;
@ -75,23 +66,17 @@ in
}; };
}; };
}; };
services.caddy = { services.caddy = {
enable = true;
virtualHosts.${host}.extraConfig = '' virtualHosts.${host}.extraConfig = ''
reverse_proxy ${serviceCfg.interface.ip}:8080 reverse_proxy ${serviceCfg.interface.ip}:80
tls ${serviceCfg.ssl.cert} ${serviceCfg.ssl.key} tls ${serviceCfg.ssl.cert} ${serviceCfg.ssl.key}
''; '';
}; };
security.acme.certs.${host} = { security.acme.certs.${host} = {
dnsProvider = instances.web.dns.provider0; dnsProvider = instances.web.dns.provider0;
environmentFile = config.sops.secrets."dns/${instances.web.dns.provider0}".path; environmentFile = config.sops.secrets."dns/${instances.web.dns.provider0}".path;
}; };
systemd.tmpfiles.rules = [ systemd.tmpfiles.rules = [
"d ${serviceCfg.mntPaths.path0} 0755 microvm wheel - -" "d ${serviceCfg.mntPaths.path0} 0755 microvm wheel - -"
]; ];
} }

View file

@ -63,8 +63,6 @@ in
${remoteRebuild} ${remoteRebuild}
${sshCommand} ${sshCommand}
${microVMSshCommand} ${microVMSshCommand}
addr:
http get https://mine.defensio.io/api/statistics/addr1q87k2jlckh6ujqx4ymkdd4jrhy6gukdtum0p77pdh5gqcw8ctl65fvaw097l32ta6m8hth3xu9cjfz70y34gs2mdfzlsj465th | get local_with_donate | get dfo_allocation | $in / 1000000
balance: balance:
#!/usr/bin/env nu #!/usr/bin/env nu
let results = [${balanceHosts}] | each { |h| let val = (^ssh ...($h.ssh | split row " ") 'nu -c "open /var/lib/defenseio-data/MidnightMiner/balances.json | get snapshots | last | get balance"' | into float); print $"($h.name):"; print $val; $val } let results = [${balanceHosts}] | each { |h| let val = (^ssh ...($h.ssh | split row " ") 'nu -c "open /var/lib/defenseio-data/MidnightMiner/balances.json | get snapshots | last | get balance"' | into float); print $"($h.name):"; print $val; $val }