From 6e0f938e65af7d07404efc8f514eaff6628d5801 Mon Sep 17 00:00:00 2001 From: Aner Zakobar Date: Sat, 25 Jul 2026 11:45:17 +0300 Subject: [PATCH] New beacon config, redone passwords --- _machines/beacon-wsl.nix | 17 ++++++ azos-core | 2 +- features/encryption/default.nix | 4 ++ features/git-config/pass-git-mapping.ini | 2 +- features/lauretta/emacs/config.org | 2 +- features/mail/default.nix | 6 +- flake.lock | 38 ++++++++++++ flake.nix | 6 ++ nixos/configuration-beacon-wsl.nix | 76 ++++++++++++++++++++++++ nixos/configuration.nix | 8 +++ 10 files changed, 155 insertions(+), 6 deletions(-) create mode 100644 _machines/beacon-wsl.nix create mode 100644 nixos/configuration-beacon-wsl.nix diff --git a/_machines/beacon-wsl.nix b/_machines/beacon-wsl.nix new file mode 100644 index 0000000..bb72599 --- /dev/null +++ b/_machines/beacon-wsl.nix @@ -0,0 +1,17 @@ +{ + config, + inputs, + ... +}: { + config.flake.nixosConfigurations.beacon-wsl = inputs.nixpkgs.lib.nixosSystem { + specialArgs = { + inherit inputs; + outputs = config.flake; + suiteModules = config.flake.modules; + }; + modules = [../nixos/configuration-beacon-wsl.nix]; + }; + + config.flake.packages.x86_64-linux.beacon-wsl-tarball = + config.flake.nixosConfigurations.beacon-wsl.config.system.build.tarballBuilder; +} diff --git a/azos-core b/azos-core index e4d4cf5..e30f21e 160000 --- a/azos-core +++ b/azos-core @@ -1 +1 @@ -Subproject commit e4d4cf5bb189eb688e74862064260d0a45d4d132 +Subproject commit e30f21ec1ce24f7e9e72ef0e3e8f62f9c985ed4f diff --git a/features/encryption/default.nix b/features/encryption/default.nix index 9c5012b..ccfd4ae 100644 --- a/features/encryption/default.nix +++ b/features/encryption/default.nix @@ -23,6 +23,10 @@ programs.gpg = { enable = true; }; + programs.browserpass = { + enable = true; + browsers = ["chromium"]; + }; services.gpg-agent = { enable = true; enableSshSupport = true; diff --git a/features/git-config/pass-git-mapping.ini b/features/git-config/pass-git-mapping.ini index 5e90f79..6b7305d 100644 --- a/features/git-config/pass-git-mapping.ini +++ b/features/git-config/pass-git-mapping.ini @@ -1,2 +1,2 @@ [*git.zakobar.com*] -target=zakobar.com/users/aner \ No newline at end of file +target=zakobar.com \ No newline at end of file diff --git a/features/lauretta/emacs/config.org b/features/lauretta/emacs/config.org index 09c5125..041b2ae 100644 --- a/features/lauretta/emacs/config.org +++ b/features/lauretta/emacs/config.org @@ -152,7 +152,7 @@ (interactive) (let* ((password (string-trim (shell-command-to-string - (format "pass zakobar.com/users/%s" azos/lauretta/nextcloud-user)))) + "pass zakobar.com | head -1"))) (url-http-real-basic-auth-storage (list (list "nextcloud.zakobar.com:443" (cons azos/lauretta/nextcloud-user password))))) diff --git a/features/mail/default.nix b/features/mail/default.nix index f72c9c9..702862e 100644 --- a/features/mail/default.nix +++ b/features/mail/default.nix @@ -45,14 +45,14 @@ // { address = "anerisgreat@gmail.com"; userName = "anerisgreat"; - passwordCommand = "pass gmail.com/mbsync-anerisgreat"; + passwordCommand = "pass mbsync/anerisgreat@gmail.com | head -1"; }; bgu = default_gmail_params // { address = "anerz@post.bgu.ac.il"; userName = "anerz@post.bgu.ac.il"; - passwordCommand = "pass post.bgu.ac.il/mbsync-anerz"; + passwordCommand = "pass mbsync/anerz@post.bgu.ac.il | head -1"; }; zakobar = default_account_params @@ -68,7 +68,7 @@ port = 587; host = "mail.privateemail.com"; }; - passwordCommand = "pass zakobar.com/mail/aner"; + passwordCommand = "pass privateemail.com | head -1"; }; }; }; diff --git a/flake.lock b/flake.lock index 3e7fff3..0d46e17 100644 --- a/flake.lock +++ b/flake.lock @@ -56,6 +56,22 @@ "type": "github" } }, + "flake-compat": { + "flake": false, + "locked": { + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", + "owner": "edolstra", + "repo": "flake-compat", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", + "type": "github" + }, + "original": { + "owner": "edolstra", + "repo": "flake-compat", + "type": "github" + } + }, "flake-parts": { "inputs": { "nixpkgs-lib": "nixpkgs-lib" @@ -220,6 +236,27 @@ "type": "github" } }, + "nixos-wsl": { + "inputs": { + "flake-compat": "flake-compat", + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1784642409, + "narHash": "sha256-hcbDqFuySAJawljt5r0sKBCJKYnbtGD0T/ZIozH1Dq0=", + "owner": "nix-community", + "repo": "nixos-wsl", + "rev": "eaeb18da90024448a60eb1ec7132eafa4003404e", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixos-wsl", + "type": "github" + } + }, "nixpkgs": { "locked": { "lastModified": 1769421245, @@ -349,6 +386,7 @@ "import-tree": "import-tree_2", "musnix": "musnix", "nixos-hardware": "nixos-hardware", + "nixos-wsl": "nixos-wsl", "nixpkgs": "nixpkgs_5", "nixpkgs-unstable": "nixpkgs-unstable" } diff --git a/flake.nix b/flake.nix index cf41c66..5e57ec8 100755 --- a/flake.nix +++ b/flake.nix @@ -21,6 +21,11 @@ flake = true; }; + nixos-wsl = { + url = "github:nix-community/nixos-wsl"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + flake-parts.url = "github:hercules-ci/flake-parts"; import-tree.url = "github:vic/import-tree"; }; @@ -34,6 +39,7 @@ ./_machines/lauretta.nix ./_machines/vm.nix ./_machines/beacon.nix + ./_machines/beacon-wsl.nix ]; systems = [ diff --git a/nixos/configuration-beacon-wsl.nix b/nixos/configuration-beacon-wsl.nix new file mode 100644 index 0000000..71b522d --- /dev/null +++ b/nixos/configuration-beacon-wsl.nix @@ -0,0 +1,76 @@ +{ + lib, + config, + pkgs, + inputs, + suiteModules, + ... +}: { + imports = [ + inputs.nixos-wsl.nixosModules.default + suiteModules.nixos.attic + ]; + + wsl.enable = true; + wsl.defaultUser = "aner"; + + nixpkgs.hostPlatform = "x86_64-linux"; + nixpkgs.config.allowUnfree = true; + + nix.settings = { + experimental-features = "nix-command flakes"; + auto-optimise-store = true; + substituters = [ + "https://cache.nixos.org" + "https://cuda-maintainers.cachix.org" + ]; + trusted-public-keys = [ + "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" + "cuda-maintainers.cachix.org-1:0dq3bujKpuEPMCX6U4WylrUDZ9JyUG0VpVZa7CNfq5E=" + ]; + }; + + security.sudo.wheelNeedsPassword = false; + + networking.hostName = "beacon"; + time.timeZone = "Asia/Jerusalem"; + + # GPU is exposed through WSL2 paravirtualization; no Linux NVIDIA KM needed + hardware.graphics.enable = true; + + services.openssh = { + enable = true; + settings = { + PermitRootLogin = "no"; + PasswordAuthentication = false; + }; + }; + + users.users.aner = { + isNormalUser = true; + extraGroups = ["wheel" "video"]; + openssh.authorizedKeys.keys = [ + "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDfzDDO5juINctECmWlsYtGghEiX/RnTJ1cazLvOWSrPfsTyEd+B1+Ig8kFefNryjkpApfRXqj5KtLPNlpLfdVBrOIfhIveEp2MGqhgOGZFNVxQyXnZgii8Zdh4cqZ2O3pZpMsaAQBaJ9nH6dK0dJjicWT5f6TqwrVcInywRc5SuyizoSxoFmg7ch2rnlVi0j5XMVqdh8XLzHXZ7yWCzXy7+hWl/d7pwpyuzoK8dBw2EU9TauhgRDruom5Q9vWJTLStALC9pAIb0v9UFj9y+1zwx7pXsXp5F1g73EYrE4QR+QQ6z2LebuK280W0t+VA/fSCEB13DnkmofgqZQxX5MSCmrxZ5lTFp1FjW6yJo7As9FheF/GECowYkMRIx4IiQsjjHjZqlLRpLas11yAp6tGoZnw59hFo6Lu0Kva39jGVVmioYHtAeE5rD5w+v5kseJR4jlQ8aKB5yOjYUQOIz2AHQyoidgaeR2jPWqZUeRQbACI+/p3CHO45r3hrjATtGloBg0xF95Qws7Be3mjHVhbBLOoob8MdZ8nYAGnhlWrZphlkvXsHC6OUkuDJW00tmMjWXRlFwhFJ+nqUQCgLVjxVHQJ5rq9GeXBUuNXAeCm5BKBsdq+9qqVlt7D9iGyfr0lcZ7peKz/96KwPCWpG2En1Ur0/cVcbWnXEfG/xWO10tQ== openpgp:0xFA67FAB0" + ]; + }; + + environment.systemPackages = with pkgs; [ + git + rsync + tmux + vim + wget + rclone + pciutils + nvtopPackages.nvidia + cudaPackages.cudatoolkit + cudaPackages.cudnn + cudaPackages.nccl + python3 + direnv + ]; + + azos.attic.enable = true; + + system.stateVersion = "25.11"; +} diff --git a/nixos/configuration.nix b/nixos/configuration.nix index e8cc835..0d76e39 100644 --- a/nixos/configuration.nix +++ b/nixos/configuration.nix @@ -84,6 +84,14 @@ nix.settings = { experimental-features = "nix-command flakes"; auto-optimise-store = true; + substituters = [ + "https://cache.nixos.org" + "https://cuda-maintainers.cachix.org" + ]; + trusted-public-keys = [ + "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" + "cuda-maintainers.cachix.org-1:0dq3bujKpuEPMCX6U4WylrUDZ9JyUG0VpVZa7CNfq5E=" + ]; }; azos.suites.exwm.enable = true;