mirror of
https://git.pvv.ntnu.no/Drift/pvv-nixos-config.git
synced 2026-08-11 05:42:33 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b350554bf3 | ||
|
|
f41e6c0a74 | ||
|
|
8bb86ef634 |
@@ -197,6 +197,7 @@
|
||||
inputs.pvv-calendar-bot.nixosModules.default
|
||||
inputs.minecraft-heatmap.nixosModules.default
|
||||
self.nixosModules.gickup
|
||||
self.nixosModules.hugepages
|
||||
self.nixosModules.matrix-ooye
|
||||
];
|
||||
overlays = [
|
||||
@@ -309,6 +310,7 @@
|
||||
bluemap = ./modules/bluemap.nix;
|
||||
drumknotty = ./modules/drumknotty;
|
||||
gickup = ./modules/gickup;
|
||||
hugepages = ./modules/hugepages.nix;
|
||||
matrix-ooye = ./modules/matrix-ooye.nix;
|
||||
python-http-handlers = ./modules/python-http-handlers.nix;
|
||||
robots-txt = ./modules/robots-txt.nix;
|
||||
|
||||
@@ -1,70 +1,25 @@
|
||||
{ lib, ... }:
|
||||
{
|
||||
# TODO: move this to base so that all virtualHosts take effect on their respecitve hosts
|
||||
|
||||
# NOTE: automatically hosting well-known files by looping over all existing `virtualHosts`
|
||||
# unfortunately causes infinite recursuion due to submodule usage within the nginx
|
||||
# module. For now, the easiest solution was to manually specify a list of virtualHosts
|
||||
# here, but it would be nice to find a better solution in the future.
|
||||
services.nginx.virtualHosts = lib.mkMerge [
|
||||
(lib.genAttrs [
|
||||
"pvv.ntnu.no"
|
||||
"pvv.org"
|
||||
|
||||
"www.pvv.ntnu.no"
|
||||
"www.pvv.org"
|
||||
"www2.pvv.ntnu.no"
|
||||
"www2.pvv.org"
|
||||
|
||||
# NOTE: this list is probably not complete
|
||||
"alps.pvv.ntnu.no"
|
||||
"chat.pvv.ntnu.no"
|
||||
"grafana.pvv.ntnu.no"
|
||||
"status.pvv.ntnu.no"
|
||||
"matrix.pvv.ntnu.no"
|
||||
"mirrors.pvv.ntnu.no"
|
||||
"pages.pvv.ntnu.no"
|
||||
"ooye.pvv.ntnu.no"
|
||||
"ooye.pvv.ntnu.no"
|
||||
"dav.pvv.ntnu.no"
|
||||
"git.pvv.ntnu.no"
|
||||
"idp.pvv.ntnu.no"
|
||||
"minecraft.pvv.ntnu.no"
|
||||
"pw.pvv.ntnu.no"
|
||||
"snappymail.pvv.ntnu.no"
|
||||
"webmail.pvv.ntnu.no"
|
||||
"wiki.pvv.ntnu.no"
|
||||
] (_: {
|
||||
locations."^~ /.well-known/security.txt" = {
|
||||
alias = toString ./root/security.txt;
|
||||
services.nginx.virtualHosts = lib.genAttrs [
|
||||
"pvv.ntnu.no"
|
||||
"www.pvv.ntnu.no"
|
||||
"pvv.org"
|
||||
"www.pvv.org"
|
||||
] (_: {
|
||||
locations = {
|
||||
"^~ /.well-known/" = {
|
||||
alias = (toString ./root) + "/";
|
||||
};
|
||||
}))
|
||||
|
||||
(lib.genAttrs [
|
||||
"pvv.ntnu.no"
|
||||
"pvv.org"
|
||||
"mail.pvv.ntnu.no"
|
||||
"mail.pvv.org"
|
||||
"smtp.pvv.ntnu.no"
|
||||
"smtp.pvv.org"
|
||||
] (_: {
|
||||
locations."^~ /.well-known/autoconfig/mail/" = {
|
||||
root = toString ./root/autoconfig/mail;
|
||||
};
|
||||
}))
|
||||
|
||||
(lib.genAttrs [
|
||||
"pvv.ntnu.no"
|
||||
"pvv.org"
|
||||
"www.pvv.ntnu.no"
|
||||
"www.pvv.org"
|
||||
] (_: {
|
||||
locations."^~ /.well-known/matrix/" = {
|
||||
# Proxy the matrix well-known files
|
||||
# Host has be set before proxy_pass
|
||||
# The header must be set so nginx on the other side routes it to the right place
|
||||
"^~ /.well-known/matrix/" = {
|
||||
extraConfig = ''
|
||||
proxy_set_header Host matrix.pvv.ntnu.no;
|
||||
proxy_pass https://matrix.pvv.ntnu.no/.well-known/matrix/;
|
||||
'';
|
||||
};
|
||||
}))
|
||||
];
|
||||
};
|
||||
});
|
||||
}
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
let
|
||||
cfg = config.services.mysql;
|
||||
dataDir = "/data/mysql";
|
||||
|
||||
innodbBufferPoolMB = 128;
|
||||
in
|
||||
{
|
||||
imports = [ ./backup.nix ];
|
||||
@@ -26,6 +28,10 @@ in
|
||||
# Useful for the mysqld prometheus exporter
|
||||
userstat = 1;
|
||||
|
||||
# Memory settings
|
||||
innodb_buffer_pool_size = "${toString innodbBufferPoolMB}M";
|
||||
"large-pages" = 1;
|
||||
|
||||
# This was needed in order to be able to use all of the old users
|
||||
# during migration from knakelibrak to bicep in Sep. 2023
|
||||
secure_auth = 0;
|
||||
@@ -47,6 +53,10 @@ in
|
||||
}];
|
||||
};
|
||||
|
||||
boot.kernel.hugepages.reservations.mysql = lib.mkIf cfg.enable (
|
||||
builtins.ceil (innodbBufferPoolMB / config.boot.kernel.hugepages.size)
|
||||
);
|
||||
|
||||
networking.firewall.allowedTCPPorts = lib.mkIf cfg.enable [ 3306 ];
|
||||
|
||||
systemd.tmpfiles.settings."10-mysql".${dataDir}.d = lib.mkIf cfg.enable {
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
{ config, lib, pkgs, values, ... }:
|
||||
let
|
||||
cfg = config.services.postgresql;
|
||||
|
||||
sharedBuffersMB = 8192;
|
||||
in
|
||||
{
|
||||
imports = [
|
||||
@@ -29,7 +31,7 @@ in
|
||||
superuser_reserved_connections = 3;
|
||||
|
||||
# Memory Settings
|
||||
shared_buffers = "8192 MB";
|
||||
shared_buffers = "${toString sharedBuffersMB} MB";
|
||||
work_mem = "32 MB";
|
||||
maintenance_work_mem = "420 MB";
|
||||
effective_cache_size = "22 GB";
|
||||
@@ -93,6 +95,10 @@ in
|
||||
};
|
||||
};
|
||||
|
||||
boot.kernel.hugepages.reservations.postgresql = lib.mkIf cfg.enable (
|
||||
builtins.ceil (sharedBuffersMB / config.boot.kernel.hugepages.size)
|
||||
);
|
||||
|
||||
systemd.tmpfiles.settings."10-postgresql"."/data/postgresql".d = lib.mkIf cfg.enable {
|
||||
user = config.systemd.services.postgresql.serviceConfig.User;
|
||||
group = config.systemd.services.postgresql.serviceConfig.Group;
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
{ config, lib, ... }:
|
||||
let
|
||||
cfg = config.boot.kernel.hugepages;
|
||||
in
|
||||
{
|
||||
options.boot.kernel.hugepages = {
|
||||
size = lib.mkOption {
|
||||
type = lib.types.enum [ 2 1024 ];
|
||||
default = 2;
|
||||
description = ''
|
||||
Hugepage size in MB.
|
||||
|
||||
You can use this value to calculate the amount of memory you will have available as hugepages.
|
||||
'';
|
||||
};
|
||||
|
||||
reservations = lib.mkOption {
|
||||
type = lib.types.attrsOf lib.types.ints.unsigned;
|
||||
default = { };
|
||||
description = ''
|
||||
Number of hugepages each service wants reserved in vm.nr_hugepages,
|
||||
keyed by service name.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = {
|
||||
boot.kernelParams = let
|
||||
num = {
|
||||
"2" = "2M";
|
||||
"1024" = "1G";
|
||||
}.${toString cfg.size};
|
||||
in [ "hugepagesz=${num}" ];
|
||||
|
||||
boot.kernel.sysctl."vm.nr_hugepages" =
|
||||
lib.foldl' (a: b: a + b) 0 (lib.attrValues cfg.reservations);
|
||||
};
|
||||
}
|
||||
Reference in New Issue
Block a user