Compare commits

..
Author SHA1 Message Date
h7x4 3bcb178ae7 WIP: base/nginx: host well-known content on multiple subdomains 2026-07-21 17:57:41 +09:00
5 changed files with 62 additions and 73 deletions
-2
View File
@@ -197,7 +197,6 @@
inputs.pvv-calendar-bot.nixosModules.default inputs.pvv-calendar-bot.nixosModules.default
inputs.minecraft-heatmap.nixosModules.default inputs.minecraft-heatmap.nixosModules.default
self.nixosModules.gickup self.nixosModules.gickup
self.nixosModules.hugepages
self.nixosModules.matrix-ooye self.nixosModules.matrix-ooye
]; ];
overlays = [ overlays = [
@@ -310,7 +309,6 @@
bluemap = ./modules/bluemap.nix; bluemap = ./modules/bluemap.nix;
drumknotty = ./modules/drumknotty; drumknotty = ./modules/drumknotty;
gickup = ./modules/gickup; gickup = ./modules/gickup;
hugepages = ./modules/hugepages.nix;
matrix-ooye = ./modules/matrix-ooye.nix; matrix-ooye = ./modules/matrix-ooye.nix;
python-http-handlers = ./modules/python-http-handlers.nix; python-http-handlers = ./modules/python-http-handlers.nix;
robots-txt = ./modules/robots-txt.nix; robots-txt = ./modules/robots-txt.nix;
+58 -13
View File
@@ -1,25 +1,70 @@
{ lib, ... }: { lib, ... }:
{ {
services.nginx.virtualHosts = lib.genAttrs [ # TODO: move this to base so that all virtualHosts take effect on their respecitve hosts
# NOTE: automatically hosting well-known files by looping over all existing `virtualHosts`
# unfortunately causes infinite recursuion due to submodule usage within the nginx
# module. For now, the easiest solution was to manually specify a list of virtualHosts
# here, but it would be nice to find a better solution in the future.
services.nginx.virtualHosts = lib.mkMerge [
(lib.genAttrs [
"pvv.ntnu.no" "pvv.ntnu.no"
"www.pvv.ntnu.no"
"pvv.org" "pvv.org"
"www.pvv.ntnu.no"
"www.pvv.org"
"www2.pvv.ntnu.no"
"www2.pvv.org"
# NOTE: this list is probably not complete
"alps.pvv.ntnu.no"
"chat.pvv.ntnu.no"
"grafana.pvv.ntnu.no"
"status.pvv.ntnu.no"
"matrix.pvv.ntnu.no"
"mirrors.pvv.ntnu.no"
"pages.pvv.ntnu.no"
"ooye.pvv.ntnu.no"
"ooye.pvv.ntnu.no"
"dav.pvv.ntnu.no"
"git.pvv.ntnu.no"
"idp.pvv.ntnu.no"
"minecraft.pvv.ntnu.no"
"pw.pvv.ntnu.no"
"snappymail.pvv.ntnu.no"
"webmail.pvv.ntnu.no"
"wiki.pvv.ntnu.no"
] (_: {
locations."^~ /.well-known/security.txt" = {
alias = toString ./root/security.txt;
};
}))
(lib.genAttrs [
"pvv.ntnu.no"
"pvv.org"
"mail.pvv.ntnu.no"
"mail.pvv.org"
"smtp.pvv.ntnu.no"
"smtp.pvv.org"
] (_: {
locations."^~ /.well-known/autoconfig/mail/" = {
root = toString ./root/autoconfig/mail;
};
}))
(lib.genAttrs [
"pvv.ntnu.no"
"pvv.org"
"www.pvv.ntnu.no"
"www.pvv.org" "www.pvv.org"
] (_: { ] (_: {
locations = { locations."^~ /.well-known/matrix/" = {
"^~ /.well-known/" = {
alias = (toString ./root) + "/";
};
# Proxy the matrix well-known files
# Host has be set before proxy_pass
# The header must be set so nginx on the other side routes it to the right place
"^~ /.well-known/matrix/" = {
extraConfig = '' extraConfig = ''
proxy_set_header Host matrix.pvv.ntnu.no; proxy_set_header Host matrix.pvv.ntnu.no;
proxy_pass https://matrix.pvv.ntnu.no/.well-known/matrix/; proxy_pass https://matrix.pvv.ntnu.no/.well-known/matrix/;
''; '';
}; };
}; }))
}); ];
} }
-10
View File
@@ -2,8 +2,6 @@
let let
cfg = config.services.mysql; cfg = config.services.mysql;
dataDir = "/data/mysql"; dataDir = "/data/mysql";
innodbBufferPoolMB = 128;
in in
{ {
imports = [ ./backup.nix ]; imports = [ ./backup.nix ];
@@ -28,10 +26,6 @@ in
# Useful for the mysqld prometheus exporter # Useful for the mysqld prometheus exporter
userstat = 1; userstat = 1;
# Memory settings
innodb_buffer_pool_size = "${toString innodbBufferPoolMB}M";
"large-pages" = 1;
# This was needed in order to be able to use all of the old users # This was needed in order to be able to use all of the old users
# during migration from knakelibrak to bicep in Sep. 2023 # during migration from knakelibrak to bicep in Sep. 2023
secure_auth = 0; secure_auth = 0;
@@ -53,10 +47,6 @@ in
}]; }];
}; };
boot.kernel.hugepages.reservations.mysql = lib.mkIf cfg.enable (
builtins.ceil (innodbBufferPoolMB / config.boot.kernel.hugepages.size)
);
networking.firewall.allowedTCPPorts = lib.mkIf cfg.enable [ 3306 ]; networking.firewall.allowedTCPPorts = lib.mkIf cfg.enable [ 3306 ];
systemd.tmpfiles.settings."10-mysql".${dataDir}.d = lib.mkIf cfg.enable { systemd.tmpfiles.settings."10-mysql".${dataDir}.d = lib.mkIf cfg.enable {
+1 -7
View File
@@ -1,8 +1,6 @@
{ config, lib, pkgs, values, ... }: { config, lib, pkgs, values, ... }:
let let
cfg = config.services.postgresql; cfg = config.services.postgresql;
sharedBuffersMB = 8192;
in in
{ {
imports = [ imports = [
@@ -31,7 +29,7 @@ in
superuser_reserved_connections = 3; superuser_reserved_connections = 3;
# Memory Settings # Memory Settings
shared_buffers = "${toString sharedBuffersMB} MB"; shared_buffers = "8192 MB";
work_mem = "32 MB"; work_mem = "32 MB";
maintenance_work_mem = "420 MB"; maintenance_work_mem = "420 MB";
effective_cache_size = "22 GB"; effective_cache_size = "22 GB";
@@ -95,10 +93,6 @@ in
}; };
}; };
boot.kernel.hugepages.reservations.postgresql = lib.mkIf cfg.enable (
builtins.ceil (sharedBuffersMB / config.boot.kernel.hugepages.size)
);
systemd.tmpfiles.settings."10-postgresql"."/data/postgresql".d = lib.mkIf cfg.enable { systemd.tmpfiles.settings."10-postgresql"."/data/postgresql".d = lib.mkIf cfg.enable {
user = config.systemd.services.postgresql.serviceConfig.User; user = config.systemd.services.postgresql.serviceConfig.User;
group = config.systemd.services.postgresql.serviceConfig.Group; group = config.systemd.services.postgresql.serviceConfig.Group;
-38
View File
@@ -1,38 +0,0 @@
{ config, lib, ... }:
let
cfg = config.boot.kernel.hugepages;
in
{
options.boot.kernel.hugepages = {
size = lib.mkOption {
type = lib.types.enum [ 2 1024 ];
default = 2;
description = ''
Hugepage size in MB.
You can use this value to calculate the amount of memory you will have available as hugepages.
'';
};
reservations = lib.mkOption {
type = lib.types.attrsOf lib.types.ints.unsigned;
default = { };
description = ''
Number of hugepages each service wants reserved in vm.nr_hugepages,
keyed by service name.
'';
};
};
config = {
boot.kernelParams = let
num = {
"2" = "2M";
"1024" = "1G";
}.${toString cfg.size};
in [ "hugepagesz=${num}" ];
boot.kernel.sysctl."vm.nr_hugepages" =
lib.foldl' (a: b: a + b) 0 (lib.attrValues cfg.reservations);
};
}