h7x4
d23adbd4c2
temmie/userweb: deny access to documentRoot
2026-06-17 08:49:44 +09:00
h7x4
48c0a4e504
temmie/userweb: fix directory denylist enforcement
2026-06-17 08:23:08 +09:00
h7x4
374d9b1bc7
flake.nix: passthru machine config, pkgs and config.system.build
...
This shortens down the path needed to build both overlayed packages and
all the other machine derivations. Here are some examples:
```
nix build .#machine.etc
nix build '.#machine.units."nginx.service".unit'
nix build .#machine.pkgs.overlayed-package
nix build .#machine.config.services.nginx.package
```
2026-06-17 08:10:17 +09:00
h7x4
d84cc73819
temmie/userweb: handle more .php\d suffixes
2026-06-16 19:07:58 +09:00
h7x4
b738f08c09
temmie/userweb: render path denylist into Directory/Files directives
2026-06-16 19:07:57 +09:00
h7x4
8252bba3ad
temmie/userweb: enable httpd trace on debugMode
2026-06-16 19:07:57 +09:00
h7x4
a776a5a5fe
temmie/userweb: explicitly override mod_perl and mod_userdir
2026-06-16 19:07:57 +09:00
h7x4
ed57744ec3
temmie/userweb: add more patterns to denylist
2026-06-16 16:07:32 +09:00
h7x4
226db1f46e
temmie/userweb: add more DirectoryIndex variants
2026-06-16 16:07:32 +09:00
h7x4
51e1656177
temmie/userweb: disable ~pvv
2026-06-16 15:53:52 +09:00
h7x4
47d2dcf9ff
temmie/userweb: add bro server to userweb slice
2026-06-16 03:37:28 +09:00
h7x4
254b1d9b14
temmie/userweb: split into more modules
2026-06-16 03:33:28 +09:00
h7x4
2301672a21
temmie/userweb: run log processors as separate systemd units
...
This lets us divide up some of the logic making httpd itself less
brittle, and also reduces the amount of privileges for httpd.
2026-06-16 02:56:28 +09:00
h7x4
b533b09c8f
base/various: add to slice system-monitoring
2026-06-13 04:45:39 +09:00
h7x4
526b55c49a
{ildkule/prometheus,base}: send stats over HTTPS through nginx
2026-06-13 02:54:28 +09:00
h7x4
e80189c6eb
temmie/userweb: stop cating passwd on startup
2026-06-13 01:41:05 +09:00
h7x4
56a51e4c6f
temmie/userweb: mount homedirs under /amd
2026-06-13 01:39:20 +09:00
h7x4
f54109f6f3
temmie/userweb: set handlers for php and perl scripts
2026-06-13 01:26:27 +09:00
h7x4
b57a935b4c
base/rsyslogd: init
2026-06-08 12:58:37 +09:00
h7x4
b4582a160f
skrot/dibbler: rotate database password
2026-06-07 17:58:33 +09:00
h7x4
ac094d350d
base/timesyncd: specify ntp servers
2026-06-07 17:52:54 +09:00
h7x4
b848e0f1cc
temmie/userweb: add log processor for apache
2026-06-07 06:03:18 +09:00
h7x4
c671329b93
temmie/userweb: inject users from passwd into httpd sandbox
2026-06-07 05:28:24 +09:00
h7x4
cafc95db8f
bicep/mjolnir: use nodejs v22
2026-06-06 04:43:58 +09:00
h7x4
2d6b09cb32
bikkje: label ports in firewall port list
2026-06-06 04:08:16 +09:00
h7x4
ce0af2f6e4
flake.nix: add app for building gitea workflows locally
2026-06-06 04:05:26 +09:00
h7x4
88892115b5
base: enable autoScrub for all btrfs machine by default
2026-06-06 04:05:26 +09:00
h7x4 and Vegard Bieker Matthey
8a290d30e7
modules/drumknotty: split into several parts
...
This also fixes a few issues, such as enabling `createLocalDatabase` for
multiple programs, and wraps all the screen logic within a screenrc
file. Some assertions were also added to avoid some easy-to-make
mistakes.
2026-06-05 14:21:35 +02:00
h7x4
fcd81aed00
packages/ooye: 3.5.1 -> 3.6.0
2026-06-04 19:17:29 +09:00
h7x4
966081ebfc
bicep/mysql: enable userstat
2026-06-03 15:31:27 +09:00
h7x4
39d313579c
bicep/mysql: rotate slow query logs
2026-06-03 15:21:18 +09:00
h7x4
3386153b8b
ildkule/prometheus/exim: make scheme explicit
2026-06-03 13:35:13 +09:00
h7x4
56906241f6
bekkalokk/roundcube: temporary fix for webmail redirects
2026-06-01 03:52:09 +09:00
h7x4
3fe71d21f6
bekkalokk/roundcube: webdir moved to public_html within package
2026-06-01 02:57:43 +09:00
h7x4
074d240595
base: tag generation as auto if built by auto upgrade service
2026-06-01 01:00:50 +09:00
h7x4
1ce3372683
lupine/binfmt: enable
2026-06-01 01:00:50 +09:00
h7x4
e05eab4ddf
{georg,brzeczyszczykiewicz}: use sane IPv6 addresses
2026-05-29 16:04:52 +09:00
h7x4
64843087be
kommode/gitea: only allow webhooks to external hosts
...
We don't have any servers with intranet IPs, and we want webhooks that
hook back to kommode to pass through its firewall.
2026-05-29 12:58:26 +09:00
h7x4
0c45345050
bicep/matrix-ooye harden
2026-05-28 16:07:36 +09:00
h7x4
788f23bf04
bicep/matrix-hookshot: harden
2026-05-28 15:58:04 +09:00
h7x4
8416014aeb
bicep/mjolnir: harden
2026-05-28 15:58:04 +09:00
h7x4
654eeb83d8
base: tag generation as dirty if built from uncommitted source code
2026-05-28 04:39:49 +09:00
h7x4
5bf0de1d0d
bekkalokk/website/fetch-gallery: use proper shellscript builder
2026-05-28 03:58:08 +09:00
h7x4
a550bbf1e0
bekkalokk/roundcube: use specialized builder for nginx root dir
2026-05-28 03:46:59 +09:00
h7x4
6d9bd8256f
kommode/gitea/install-customization: disable networking
2026-05-28 03:15:47 +09:00
h7x4
5c859d9809
kommode/gitea/install-customization: remove ExecStart bash wrapper
2026-05-28 03:15:06 +09:00
h7x4
68481b999b
modules/grzegorz: remove ExecStart bash wrapper
2026-05-28 03:09:38 +09:00
h7x4
dfbed75cd9
kommode/gitea/gpg: remove ExecStart bash wrapper
2026-05-28 03:06:07 +09:00
h7x4
6237a0a0e7
bicep/minecraft-heatmap: remove ExecStartPre bash wrapper
2026-05-28 03:03:38 +09:00
h7x4
bd2263a0a9
kommode/gitea/import-users: remove ExecStartPre bash wrapper
2026-05-28 03:02:59 +09:00
h7x4
2faff6340c
flake.lock: bump pvv-nettsiden
2026-05-28 02:39:32 +09:00
h7x4
532e8b0eee
bekkalokk/mediawiki: install PdfHandler extension
2026-05-28 01:22:13 +09:00
h7x4
eef3f8fe8b
bekkalokk/mediawiki: cleanup executable path config
2026-05-28 01:22:13 +09:00
h7x4
e17025aca6
packages/mediawiki-extensions: add PdfHandler, bump all
2026-05-28 00:55:20 +09:00
h7x4
e062a849f3
base/scrutiny-collector: disable if machine is qemu guest
2026-05-27 23:45:30 +09:00
h7x4
b0f81c9379
lupine/smartd: reenable
2026-05-27 23:41:54 +09:00
h7x4
2c819776f8
treewide/nginx: enable kTLS for a bunch more virtualHosts
2026-05-27 23:36:18 +09:00
h7x4
c2d6989350
base/scrutiny-collector: init
2026-05-27 23:35:32 +09:00
h7x4
2b4817b75a
ildkule/scrutiny: init
2026-05-27 23:33:45 +09:00
h7x4
0e2a8ed3ed
base/polkit: let wheel users use AUTH_KEEP_SELF for systemd actions
2026-05-27 14:13:36 +09:00
h7x4
3372712e26
modules/ooye: move StartLimit* options to correct section
2026-05-26 15:03:27 +09:00
h7x4
7e586e082e
flake.lock: bump pvv-calendar-bot
2026-05-26 14:55:58 +09:00
h7x4
47a744f68f
ildkule/uptime-kuma: set up rsync pull target for principal
2026-05-26 13:37:29 +09:00
h7x4
18ab1ef982
temmie/userweb: set -i and -t in sendmail wrapper
2026-05-25 18:49:57 +09:00
h7x4
5023edeb13
temmie/userweb: install mod_perl with custom env
2026-05-25 18:24:23 +09:00
h7x4
0d8c26c548
temmie/userweb: send propagatedBuildInputs through perl env wrapper
2026-05-25 17:05:02 +09:00
h7x4
bd244e7797
temmie/userweb: add www2 server alias
2026-05-25 16:24:35 +09:00
h7x4
e9220bb31e
temmie/userweb: use www-datas UID + GID for backwards compat
2026-05-25 15:25:26 +09:00
h7x4
6beb9c62c3
temmie/userweb: use bro to proxy sendmail requests out of sandbox
2026-05-25 15:02:40 +09:00
h7x4
7429b334ca
README: add temmie to machine overview
2026-05-25 11:59:17 +09:00
h7x4
1595f67c55
flake.nix: allow nvidia-kernel-modules for wenche
2026-05-25 11:35:25 +09:00
h7x4
3f5eadcb87
base/resolved: use RFC42 format
2026-05-25 10:40:04 +09:00
h7x4
70c0ad8724
base: use RFC42 format for systemd.sleep
2026-05-25 10:40:04 +09:00
h7x4
61ea0181a1
packages/mediawiki-extensions: REL1_44 -> REL1_45
2026-05-25 10:40:04 +09:00
h7x4
3e22c1a47e
nixpkgs 26.05 🎉
2026-05-25 10:40:02 +09:00
h7x4
53670b4d05
flake.nix/inputs/disko: v1.11.0 -> v1.13.0
2026-05-24 23:05:48 +09:00
h7x4
d92a5f13ad
base/journald-upload: fix target url
2026-05-24 16:41:54 +09:00
h7x4
16d3251ee2
shells/cuda: fix deprecated package attr warnings
2026-05-24 15:23:33 +09:00
h7x4
9a6fdecb03
kommode/gitea/dump: only keep a single dump at a time
2026-05-22 18:27:57 +09:00
h7x4
82ab97fb45
bekkalokk/roundcube: restart service on changed sops secrets
2026-05-22 18:10:44 +09:00
h7x4
543fd19f8d
bekkalokk/vaultwarden: restart service on changed sops secrets
2026-05-22 18:10:40 +09:00
h7x4
6f99fa575d
bekkalokk/vaultwarden: render environment_file as sops template
2026-05-22 18:02:13 +09:00
h7x4
3141b1f76b
bekkalokk/vaultwarden: remove redundant hardening
...
This has already been upstreamed
2026-05-22 17:51:03 +09:00
h7x4
475f6a8c9b
bekkalokk/vaultwarden: add rsa key to sops
2026-05-22 17:49:31 +09:00
h7x4
9c1687f8f2
bekkalokk/vaultwarden: use envvar keys
...
It seems like the nixpkgs module is compensating for previous config
that might've ended up in a file, which are now being turned into
screaming snake case environment variables. Let's just name them as they
are supposed to be named instead of having the upstream module translate
them.
2026-05-22 17:08:31 +09:00
h7x4
0f53bcd731
bekkalokk/roundcube: add des_key to sops
2026-05-22 17:08:31 +09:00
h7x4
5745648f87
bicep/postgres/repack: use local unix socket
2026-05-22 15:59:59 +09:00
h7x4
2c34a93abf
bicep/postgres/repack: don't kill connections on timeout
2026-05-22 15:57:57 +09:00
h7x4
9ebc947eab
ustetind: bai bai 👋
2026-05-22 15:41:28 +09:00
h7x4
6fcc19f0a2
base/fluentbit: init
2026-05-22 15:32:13 +09:00
h7x4
9224f04bd1
base/promtail: remove
2026-05-22 15:32:13 +09:00
h7x4
5d6c153007
kommode/gitea: fix dump command
2026-05-21 17:54:54 +09:00
h7x4
8b483a92f8
ildkule: set fsType for bindmounts
2026-05-21 17:52:47 +09:00
h7x4
0d7f05e56d
bicep/postgres: add cleanup timers
2026-05-21 04:14:34 +09:00
h7x4
08a23bd380
base/hardening: ban a few more modules
2026-05-20 23:15:25 +09:00
h7x4
28b67c3578
base/mitigations: blacklist modules for copyfail and pintheft
2026-05-20 23:15:25 +09:00
h7x4
0fd41c214a
flake.{nix,lock}: bump deps
2026-05-13 01:19:35 +09:00
h7x4
5c1ee958ea
flake.{nix,lock}: bump roowho2
2026-05-12 00:25:55 +09:00
h7x4
d8e97715c9
flake.lock: bump pvv-nettsiden
2026-05-12 00:24:56 +09:00
h7x4
33297b0436
treewide: lib.cli.toGNUCommandLineShell -> lib.cli.toCommandLineShellGNU
2026-05-11 23:09:50 +09:00