New beacon config, redone passwords

This commit is contained in:
2026-07-25 11:45:17 +03:00
parent 59c05832b1
commit 6e0f938e65
10 changed files with 155 additions and 6 deletions
+17
View File
@@ -0,0 +1,17 @@
{
config,
inputs,
...
}: {
config.flake.nixosConfigurations.beacon-wsl = inputs.nixpkgs.lib.nixosSystem {
specialArgs = {
inherit inputs;
outputs = config.flake;
suiteModules = config.flake.modules;
};
modules = [../nixos/configuration-beacon-wsl.nix];
};
config.flake.packages.x86_64-linux.beacon-wsl-tarball =
config.flake.nixosConfigurations.beacon-wsl.config.system.build.tarballBuilder;
}
+4
View File
@@ -23,6 +23,10 @@
programs.gpg = { programs.gpg = {
enable = true; enable = true;
}; };
programs.browserpass = {
enable = true;
browsers = ["chromium"];
};
services.gpg-agent = { services.gpg-agent = {
enable = true; enable = true;
enableSshSupport = true; enableSshSupport = true;
+1 -1
View File
@@ -1,2 +1,2 @@
[*git.zakobar.com*] [*git.zakobar.com*]
target=zakobar.com/users/aner target=zakobar.com
+1 -1
View File
@@ -152,7 +152,7 @@
(interactive) (interactive)
(let* ((password (string-trim (let* ((password (string-trim
(shell-command-to-string (shell-command-to-string
(format "pass zakobar.com/users/%s" azos/lauretta/nextcloud-user)))) "pass zakobar.com | head -1")))
(url-http-real-basic-auth-storage (url-http-real-basic-auth-storage
(list (list "nextcloud.zakobar.com:443" (list (list "nextcloud.zakobar.com:443"
(cons azos/lauretta/nextcloud-user password))))) (cons azos/lauretta/nextcloud-user password)))))
+3 -3
View File
@@ -45,14 +45,14 @@
// { // {
address = "anerisgreat@gmail.com"; address = "anerisgreat@gmail.com";
userName = "anerisgreat"; userName = "anerisgreat";
passwordCommand = "pass gmail.com/mbsync-anerisgreat"; passwordCommand = "pass mbsync/anerisgreat@gmail.com | head -1";
}; };
bgu = bgu =
default_gmail_params default_gmail_params
// { // {
address = "anerz@post.bgu.ac.il"; address = "anerz@post.bgu.ac.il";
userName = "anerz@post.bgu.ac.il"; userName = "anerz@post.bgu.ac.il";
passwordCommand = "pass post.bgu.ac.il/mbsync-anerz"; passwordCommand = "pass mbsync/anerz@post.bgu.ac.il | head -1";
}; };
zakobar = zakobar =
default_account_params default_account_params
@@ -68,7 +68,7 @@
port = 587; port = 587;
host = "mail.privateemail.com"; host = "mail.privateemail.com";
}; };
passwordCommand = "pass zakobar.com/mail/aner"; passwordCommand = "pass privateemail.com | head -1";
}; };
}; };
}; };
Generated
+38
View File
@@ -56,6 +56,22 @@
"type": "github" "type": "github"
} }
}, },
"flake-compat": {
"flake": false,
"locked": {
"lastModified": 1767039857,
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-parts": { "flake-parts": {
"inputs": { "inputs": {
"nixpkgs-lib": "nixpkgs-lib" "nixpkgs-lib": "nixpkgs-lib"
@@ -220,6 +236,27 @@
"type": "github" "type": "github"
} }
}, },
"nixos-wsl": {
"inputs": {
"flake-compat": "flake-compat",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1784642409,
"narHash": "sha256-hcbDqFuySAJawljt5r0sKBCJKYnbtGD0T/ZIozH1Dq0=",
"owner": "nix-community",
"repo": "nixos-wsl",
"rev": "eaeb18da90024448a60eb1ec7132eafa4003404e",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nixos-wsl",
"type": "github"
}
},
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1769421245, "lastModified": 1769421245,
@@ -349,6 +386,7 @@
"import-tree": "import-tree_2", "import-tree": "import-tree_2",
"musnix": "musnix", "musnix": "musnix",
"nixos-hardware": "nixos-hardware", "nixos-hardware": "nixos-hardware",
"nixos-wsl": "nixos-wsl",
"nixpkgs": "nixpkgs_5", "nixpkgs": "nixpkgs_5",
"nixpkgs-unstable": "nixpkgs-unstable" "nixpkgs-unstable": "nixpkgs-unstable"
} }
+6
View File
@@ -21,6 +21,11 @@
flake = true; flake = true;
}; };
nixos-wsl = {
url = "github:nix-community/nixos-wsl";
inputs.nixpkgs.follows = "nixpkgs";
};
flake-parts.url = "github:hercules-ci/flake-parts"; flake-parts.url = "github:hercules-ci/flake-parts";
import-tree.url = "github:vic/import-tree"; import-tree.url = "github:vic/import-tree";
}; };
@@ -34,6 +39,7 @@
./_machines/lauretta.nix ./_machines/lauretta.nix
./_machines/vm.nix ./_machines/vm.nix
./_machines/beacon.nix ./_machines/beacon.nix
./_machines/beacon-wsl.nix
]; ];
systems = [ systems = [
+76
View File
@@ -0,0 +1,76 @@
{
lib,
config,
pkgs,
inputs,
suiteModules,
...
}: {
imports = [
inputs.nixos-wsl.nixosModules.default
suiteModules.nixos.attic
];
wsl.enable = true;
wsl.defaultUser = "aner";
nixpkgs.hostPlatform = "x86_64-linux";
nixpkgs.config.allowUnfree = true;
nix.settings = {
experimental-features = "nix-command flakes";
auto-optimise-store = true;
substituters = [
"https://cache.nixos.org"
"https://cuda-maintainers.cachix.org"
];
trusted-public-keys = [
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"cuda-maintainers.cachix.org-1:0dq3bujKpuEPMCX6U4WylrUDZ9JyUG0VpVZa7CNfq5E="
];
};
security.sudo.wheelNeedsPassword = false;
networking.hostName = "beacon";
time.timeZone = "Asia/Jerusalem";
# GPU is exposed through WSL2 paravirtualization; no Linux NVIDIA KM needed
hardware.graphics.enable = true;
services.openssh = {
enable = true;
settings = {
PermitRootLogin = "no";
PasswordAuthentication = false;
};
};
users.users.aner = {
isNormalUser = true;
extraGroups = ["wheel" "video"];
openssh.authorizedKeys.keys = [
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDfzDDO5juINctECmWlsYtGghEiX/RnTJ1cazLvOWSrPfsTyEd+B1+Ig8kFefNryjkpApfRXqj5KtLPNlpLfdVBrOIfhIveEp2MGqhgOGZFNVxQyXnZgii8Zdh4cqZ2O3pZpMsaAQBaJ9nH6dK0dJjicWT5f6TqwrVcInywRc5SuyizoSxoFmg7ch2rnlVi0j5XMVqdh8XLzHXZ7yWCzXy7+hWl/d7pwpyuzoK8dBw2EU9TauhgRDruom5Q9vWJTLStALC9pAIb0v9UFj9y+1zwx7pXsXp5F1g73EYrE4QR+QQ6z2LebuK280W0t+VA/fSCEB13DnkmofgqZQxX5MSCmrxZ5lTFp1FjW6yJo7As9FheF/GECowYkMRIx4IiQsjjHjZqlLRpLas11yAp6tGoZnw59hFo6Lu0Kva39jGVVmioYHtAeE5rD5w+v5kseJR4jlQ8aKB5yOjYUQOIz2AHQyoidgaeR2jPWqZUeRQbACI+/p3CHO45r3hrjATtGloBg0xF95Qws7Be3mjHVhbBLOoob8MdZ8nYAGnhlWrZphlkvXsHC6OUkuDJW00tmMjWXRlFwhFJ+nqUQCgLVjxVHQJ5rq9GeXBUuNXAeCm5BKBsdq+9qqVlt7D9iGyfr0lcZ7peKz/96KwPCWpG2En1Ur0/cVcbWnXEfG/xWO10tQ== openpgp:0xFA67FAB0"
];
};
environment.systemPackages = with pkgs; [
git
rsync
tmux
vim
wget
rclone
pciutils
nvtopPackages.nvidia
cudaPackages.cudatoolkit
cudaPackages.cudnn
cudaPackages.nccl
python3
direnv
];
azos.attic.enable = true;
system.stateVersion = "25.11";
}
+8
View File
@@ -84,6 +84,14 @@
nix.settings = { nix.settings = {
experimental-features = "nix-command flakes"; experimental-features = "nix-command flakes";
auto-optimise-store = true; auto-optimise-store = true;
substituters = [
"https://cache.nixos.org"
"https://cuda-maintainers.cachix.org"
];
trusted-public-keys = [
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"cuda-maintainers.cachix.org-1:0dq3bujKpuEPMCX6U4WylrUDZ9JyUG0VpVZa7CNfq5E="
];
}; };
azos.suites.exwm.enable = true; azos.suites.exwm.enable = true;