From fe4340f5559b5f38d8b8bbb212ae9a31320099dc Mon Sep 17 00:00:00 2001 From: Lukas Wurzinger Date: Sat, 13 Apr 2024 22:29:14 +0200 Subject: [PATCH] improvements --- class/desktop/compatibility.nix | 67 -------------------------------- class/desktop/default.nix | 3 +- class/desktop/vm.nix | 4 ++ class/desktop/wine.nix | 3 ++ common/users.nix | 5 +-- pubkeys.nix | 23 +++++++++++ secrets/mail-lukas.age | 16 ++++---- secrets/nextcloud-lukas.age | 16 ++++---- secrets/restic-vessel.age | Bin 447 -> 447 bytes secrets/secrets.nix | 22 +---------- secrets/user-guest.age | 21 +++++----- secrets/user-lukas.age | 31 +++++++-------- secrets/vaultwarden.age | Bin 616 -> 616 bytes 13 files changed, 75 insertions(+), 136 deletions(-) delete mode 100644 class/desktop/compatibility.nix create mode 100644 class/desktop/vm.nix create mode 100644 class/desktop/wine.nix create mode 100644 pubkeys.nix diff --git a/class/desktop/compatibility.nix b/class/desktop/compatibility.nix deleted file mode 100644 index 7d72476..0000000 --- a/class/desktop/compatibility.nix +++ /dev/null @@ -1,67 +0,0 @@ -{pkgs, ...}: { - environment.systemPackages = [ - pkgs.appimage-run - pkgs.wineWowPackages.unstableFull - ]; - - services.envfs.enable = true; - - programs.nix-ld = { - enable = true; - libraries = [ - pkgs.alsa-lib - pkgs.atk - pkgs.at-spi2-atk - pkgs.at-spi2-core - pkgs.cairo - pkgs.cups - pkgs.curl - pkgs.dbus - pkgs.expat - pkgs.fontconfig - pkgs.freetype - pkgs.fuse - pkgs.fuse3 - pkgs.gdk-pixbuf - pkgs.glib - pkgs.gtk3 - pkgs.gtk4 - pkgs.icu - pkgs.libappindicator - pkgs.libdrm - pkgs.libGL - pkgs.libglvnd - pkgs.libnotify - pkgs.libpulseaudio - pkgs.libunwind - pkgs.libusb1 - pkgs.libuuid - pkgs.libxkbcommon - pkgs.libxml2 - pkgs.mesa - pkgs.nspr - pkgs.nss - pkgs.openssl - pkgs.pango - pkgs.pipewire - pkgs.stdenv.cc.cc - pkgs.systemd - pkgs.vulkan-loader - pkgs.xorg.libX11 - pkgs.xorg.libxcb - pkgs.xorg.libXcomposite - pkgs.xorg.libXcursor - pkgs.xorg.libXdamage - pkgs.xorg.libXext - pkgs.xorg.libXfixes - pkgs.xorg.libXi - pkgs.xorg.libxkbfile - pkgs.xorg.libXrandr - pkgs.xorg.libXrender - pkgs.xorg.libXScrnSaver - pkgs.xorg.libxshmfence - pkgs.xorg.libXtst - pkgs.zlib - ]; - }; -} diff --git a/class/desktop/default.nix b/class/desktop/default.nix index 7896690..4532d4b 100644 --- a/class/desktop/default.nix +++ b/class/desktop/default.nix @@ -1,7 +1,6 @@ { imports = [ ./clipboard.nix - ./compatibility.nix ./docker.nix ./flatpak.nix ./fonts.nix @@ -17,5 +16,7 @@ ./printing.nix ./syncthing.nix ./users.nix + ./vm.nix + ./wine.nix ]; } diff --git a/class/desktop/vm.nix b/class/desktop/vm.nix new file mode 100644 index 0000000..d923a08 --- /dev/null +++ b/class/desktop/vm.nix @@ -0,0 +1,4 @@ +{ + virtualisation.libvirtd.enable = true; + programs.virt-manager.enable = true; +} diff --git a/class/desktop/wine.nix b/class/desktop/wine.nix new file mode 100644 index 0000000..632cc98 --- /dev/null +++ b/class/desktop/wine.nix @@ -0,0 +1,3 @@ +{pkgs, ...}: { + environment.systemPackages = [pkgs.wineWowPackages.stableFull]; +} diff --git a/common/users.nix b/common/users.nix index b56b3c7..b1fdbee 100644 --- a/common/users.nix +++ b/common/users.nix @@ -11,10 +11,7 @@ lukas = { isNormalUser = true; hashedPasswordFile = config.age.secrets.user-lukas.path; - openssh.authorizedKeys.keys = [ - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK4U9RzV/gVGBfrCOye7BlS11g5BS7SmuZ36n2ZIJyAX lukas@glacier" - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAztZgcRBHqX8Wb2nAlP1qCKF205M3un/D1YnREcO7Dy lukas@flamingo" - ]; + openssh.authorizedKeys.keys = builtins.attrValues (import ../pubkeys.nix).users; extraGroups = ["wheel" "networkmanager" "gamemode"]; linger = true; }; diff --git a/pubkeys.nix b/pubkeys.nix new file mode 100644 index 0000000..837ec24 --- /dev/null +++ b/pubkeys.nix @@ -0,0 +1,23 @@ +let + users = { + "lukas@flamingo" = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAztZgcRBHqX8Wb2nAlP1qCKF205M3un/D1YnREcO7Dy"; + "lukas@glacier" = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK4U9RzV/gVGBfrCOye7BlS11g5BS7SmuZ36n2ZIJyAX"; + }; + + hosts = { + glacier = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHrKpoDV/ImivtTZVbSsQ59IbGYVvSsKls4av2Zc9Nk8"; + abacus = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHoUgClpkOlBEffQOb9KkVn970RwnIhU0OiVr7P2WVzg"; + vessel = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKkYcOb1JPNLTJtob1TcuC08cH9P2APAhLR26RYd573d"; + flamingo = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIInV+UpCZhoTwgkgnCzCPEu3TD5b5mu6tagRslljrFJ/"; + }; +in { + inherit users hosts; + + desktops = { + inherit (hosts) glacier flamingo; + }; + + servers = { + inherit (hosts) abacus vessel; + }; +} diff --git a/secrets/mail-lukas.age b/secrets/mail-lukas.age index 097c9e0..46f32f4 100644 --- a/secrets/mail-lukas.age +++ b/secrets/mail-lukas.age @@ -1,9 +1,9 @@ age-encryption.org/v1 --> ssh-ed25519 SFHVrw LiDCAhLHNnb0AbtKaSxP32Erwaqpm9rkVqqTYsg7VX4 -rgZBcTW88Zynex2AWXHpJ5VdlLAe3MtNN4vRhV03/yw --> ssh-ed25519 S+dwQQ b1tjzc5ipNB1O5+sj+NTdPquv842V1SNfVLwlhllpmo -q0KI/Rb1D359bRSsrwJrG0Sfy7YFe1y2qZZY6e5SySE --> ssh-ed25519 ffmsLw OLoQCT99w3kM1wyzCWGeh6tO7fH46GbIzLSWJNxA+V8 -+hfzOs8JPE5/Paag/7PkIYmRG8ppJMouvxDcyyfrzv4 ---- Q2ZHMtaw0pwEOOGBxnRRNzjfEbcQqzP82QNFPRgazGw -D$|dtS}N{`vbfn5ߝR*O@ހXwyזj?O4b  ]8N|+% \ No newline at end of file +-> ssh-ed25519 SFHVrw 9+APWz/u61v8zE6auzspntqrKNdCFb7fZPFMIdOBx0E +KMMD8n0klfeMN41AHX7sgXOdjI4eCgODKpkaFBkiesQ +-> ssh-ed25519 S+dwQQ nPqPcy5Ksk6W14xacleMie+mNKInhdlOcjtb3iEaSDU +IB7VAISMPvD8goodgcahuCab5r59zD/O3fKAePLBKAc +-> ssh-ed25519 ffmsLw Rf4/ibog+At3JqyvQkkXKAsmhkK6/8wWeMSrwsJzGSs +To4HRcE12BiFQZp1z+dT9DiE24LxJdFVxYZUalstfgo +--- dnS4XgHvGt9ZROAl+daSLO4VDj8ihnJenDNvfG43zFA +ĕhqA #!V9T5ӱKruktUq\/W%FXRDYZx+7SwAQhrTz+8B>*,$+EfaAl \ No newline at end of file diff --git a/secrets/nextcloud-lukas.age b/secrets/nextcloud-lukas.age index dda3b74..2cb5aa7 100644 --- a/secrets/nextcloud-lukas.age +++ b/secrets/nextcloud-lukas.age @@ -1,9 +1,9 @@ age-encryption.org/v1 --> ssh-ed25519 SFHVrw jUO5Z4j1ADd4QMPziuvNDh0iUirvrV32Z1+xbnkoVks -FJGle7Kr6knbPrgCg6Lk1ge+jV7Im4Z8FAmkQKlP6Ik --> ssh-ed25519 S+dwQQ wKH3jZM/aruNPE5tYSROFGUdXw2o3lws76OvAXubhxk -Jhv2kqxgHM26iuvDs0LTf4ahlaiRacN6wpH7iHuknF4 --> ssh-ed25519 ffmsLw kNKHrTEm4pFyC1r6Kjah3pl+0xnTuFt9ccha0uh0Z3Q -bLP4RrHR5gUm2ZuFNcK2m6tnC24PiGdevnuNTQ9Kb0g ---- FznEfHzpAG79LYYxIBJYgCFeUrb9Tn9yS5wXfJVeeEU -+c8:vbT]4$\)Є[T@W;FfNFG \ No newline at end of file +-> ssh-ed25519 SFHVrw 6oAZL86Esb8hewQ6ylGb7k0RsQlJoQbwyHDB8cEiVH0 +TvD14WLXzxCvDb1/iWljWNgR+qF0yjwlSLZ06HoNh9I +-> ssh-ed25519 S+dwQQ KoANzMyOZKHMFBg+nqblxAP+bWKGXceexVYUbExu80s +kUIcinUKIvPuBlFgnPKIomq+yk9P8GnjsujM63+Hm68 +-> ssh-ed25519 ffmsLw Ad9EVWmpxhiAaREltE2J7APUn/NeNg9tw8vG8yeC3HU +R26AmfZEq1Q0qKJ4npuQV5Yc/aIKJMiP68/Rd8l7lDg +--- Y3yFHxXo16Z9hQVFdDut04ioZ0H4x4YUy/SBGn8+MWw +[@/1[7RM,B7A_iQ'@6dcqrnbg$s8^P>1zA4=EpU zJkNrINCe&?=lVlw%F36WA$NeKA?{W-|;WW0TsA#TfZR6*C?|0yC80LdWF* zl}cmdY@8{WHq#)}CS#|UMP7KC_=3Q2-o@LOvr<^(`nX9h5!X{Zd8FH1TlrS_F1=p6 zQk+?8B~+pVKwJE z2Q4%OU6cwzHWw18^?KsiK=Ul{}a)dM~}Pw dr~NKc(kq-f***ex0G@{9jlZXosb92HwZxZQPUyGuJP>@m zqbL$+PkCIMX4`OK>C2v$Nv7lF=}aAx=EUZb2y%wz_D zRLuiY`>+yitELWdO7&%d{>h9plw8Y8qe(PT8?)eJ7gBs`9sg|1!1 z>=sZU^$h|Kj#ysMM=gAzm ssh-ed25519 SFHVrw XwFbvZ91rDE2Ux6BOxWqa0tpmp9W93n6c15WewMd83g -bHU1wwzxwEc2Ie6KcGBWhRv2IeQDKEtzWpRSujPvzLk --> ssh-ed25519 S+dwQQ O9Nd+LXDcf7fP8xgqcmVpM44LEk1KaB8p9RHRfp+6Bw -LOmhTxVX93XgM6lmr26MrNOMG2jf0ZAOAMiYR7KxRro --> ssh-ed25519 d2fKsw 5jpAhGTQ7VqJrT7SWfaAudYrVtIFYRRv1R5FgL8FeCs -rRJe5oiSVtjPBGTJOdgFTXOzld0SxKpqAtXz7hHgB6c --> ssh-ed25519 US6ATA jol1HBmQUl3qjxLkSOZ17r9dqxu7lB/dDBqrccuq4Qk -EyPFGHi1jI2fIRCourzGvvMJGQYsAjttEGiOUachi9Q ---- lhZyqOVkSJS/30/cyWdLTVNMltAIHYF4DOIyK32VR/0 - 50 0 -=0MKFu \ No newline at end of file +-> ssh-ed25519 SFHVrw DCt2GZWNEMSghE2UN3bXoILlWnuJcwyC/NZeMq02CAc ++QUTcHu/7xuzWjwveWAlGvsI2cO47uGwR4BSvOLtjjs +-> ssh-ed25519 S+dwQQ 6rAan8TWKoUaAhBHpNsMkVo2p+Lgz0ZoQmxFEaNTSHU +PdiHcuv08y1iOlaLFVpSwd3Hhf2eVkhmAk+ERUgQcck +-> ssh-ed25519 d2fKsw JVyjUdSyNjZwm+YT6ADU9NdtdB/b4BRXvNeY1Rf3j2E +vMSNQGFCbIsK+QvurnxSk+bOhGAT0auQGUGi61Xu718 +-> ssh-ed25519 US6ATA 1P9NLhIOtAfIDoPkFhvcXKmABtKeT/DwcnpAKnZOFm8 +E4JXWldgwLJpVHObEL8x5WILVyXCwCzM3KUwtkitG6w +--- b838whGkA7DIZ58mqtWg/LYmXwSNNDBTLuRcsSwXQWg +GQhtYP6x [)YUgygҴWϋiLikϟ;V/EUDKUmeųco[CO \ No newline at end of file diff --git a/secrets/user-lukas.age b/secrets/user-lukas.age index 46e44f4..2a3f5bd 100644 --- a/secrets/user-lukas.age +++ b/secrets/user-lukas.age @@ -1,17 +1,16 @@ age-encryption.org/v1 --> ssh-ed25519 SFHVrw RbCDTFm8etGA6wAA26l52Ezrj5g151L/uYmkCC57rh0 -az9uaQvCJy8ocB0ij+qmu1MayhkFYVK2NHvlB0+8RhA --> ssh-ed25519 S+dwQQ xUmmLtRfmdxSWv9sU2OIgced3+hn6H2fvHxtlrThF3Q -hr3tB+uqcv3JNBFyjf2O6xanN2hnlbCdHH5wLidcbfk --> ssh-ed25519 ffmsLw NxXG3+tjYTxrAnZ/gIy/E08ozfSkl2GbUaaCAextd1E -fKwGEIu4I1sczSvu2bsGcMZSkuYuO5gWFRyg1PoLfV4 --> ssh-ed25519 d2fKsw glKuNTvDZxE7SsxBKP+0P4Ldl/a4MwvpzwkgbqFNuEM -8XqemFkix1MjVJm42fQ0vtWaxiFGZWOer+OoRaVLccg --> ssh-ed25519 US6ATA J5l4UYEZVCUS4J69YTwEyTdFvPRoWlpp88iWgEEDe0Y -ogUa74Vg22CN2zyDZzIoxUokMVPXzllfb1Vj53/CbmM --> ssh-ed25519 Sm0lOA 5YoOeiPiEfqT9mWUTSUusm9h5CceeeCVJS1iofooTHw -A47tIbHSaQzaxrBatwqQEE2JIa67sqMlstkDyWIuE7Q ---- QzbsNPZn7A5mPNUXOkkSZYt/mx/KrLiBHtI4wi2ynLE -p ssh-ed25519 SFHVrw Wu34V3CgoW7F6AlycCYTYS8V2BqzTiJEciHSmlYk3yY +8PrJc2enz9lfjIZ19DnDWARp5bVc11H5xWzuzSQORYU +-> ssh-ed25519 S+dwQQ QeMwBHRfGiAnVprkdWZvHxvZB2gfTI3L6L/A+LaA22U +fI2BklLzA3oYtXD9ZJB7ckDIDZAzsGLXki1hsYDTe18 +-> ssh-ed25519 ffmsLw UxgpvU2hr7v4fVxPkakM+x/Gib7pgkOnAr0t9MtEMF8 +xBCEBjx++nBZVnmpOmQz8fjJNJhpqJO7RU6ApY0yUp8 +-> ssh-ed25519 d2fKsw zfmx5GJLF1xvvd9rnrtS28aCpLKtYzefXQ6ZBNKunSY +a1//LH2PoCbKJXgMt2zxtNfv13GpP+Q9AgSitbPsi2c +-> ssh-ed25519 US6ATA 6KqoDVREh7obNXYnpUW5rMfpYT3wLb3QwFZ03Ixe1Q8 +/F5qNiOBTgcjwjuwqU6T1s21AuaXVlpCg65AkSSaOuA +-> ssh-ed25519 Sm0lOA GV5uqJ3ur7RDx+KyQbiDP94zJjBxDopOJoKPeS+Nino +iQrxyMaKXcKk8pbbrrDNPXtX+kxifohBFNDDEa/bIWo +--- /wyQ79QmsnO+louJTkcdUXx9+lZAu/dVJP03aFqKQ50 +ݸ$hS)/ޔ( +^3ȓ+>F#V5 }o])X3pf_BRtNj2I&``h~NX5d5LML'j(ėG%T8Rj>ˍ \ No newline at end of file diff --git a/secrets/vaultwarden.age b/secrets/vaultwarden.age index 516d5316e431dee8e425e3989ad6e4e0d363d3b2..faf5a6df42a279be2c1b7e44270d1f3716eaabe0 100644 GIT binary patch delta 563 zcmV-30?hsB1n2~iEPrq@T5C;OP*PH4b5codL~3Y3IaY2oYByzfbW&15QbILaS#)Mq zZcJxXNeWR-M^tuVHdaVEQ!rysYBzFpGEi%Gb#7BDI7%`#N?JHIaBpN$bucqjZ)z)cMQnLWH&91sW^zpmEiEk|ZAURH zOlD0^YDIHxcxhT#XGmvmVp>*YPBd~%b#+W~VJ}C2Pi#;{VoYx^3IJ9o;pGha0eRs` z)dcfcwP`vE`S|@z{MtgXqFdCdTF)zQ4Qaa{xJ}rQpjb~|n(ZZxeFBoDM(CS@KOo0yVp&ZzST!$mLrOALbVxT)R8v=aFL!QobVV{nD{*rx zV|j0CcM3B`b}vf|fctUM&NoQtOG+0+rdSp^`Y-d+kO$seO zAaiqQEoEdfH8n9gAX6)3cTrIwby_fWH*iH)HF8LKPx3R6u=bW~1uST|*3OF42^Mp9yKLuylKXj5uRYf@5SSYk6yNKj!o zQ%Gt_k?|LQV>3cCLPK{+D|mNDcx7X3HFrc}MlgA1bZ=8ucuPr1dQWLIaWzgdM=?bT zb3!QdwhbF;PWjWJqfYEiEk|Vn{b{ zZ!~OEIaEnRa&b?3FljJFO*L{ibSq4FZ)7VqO<8DvQdw6sWnyq+3f2-YwV9~Rb2rt{ zLwYK?Th>`=4=@oTg&TsCRFRY8oz(XA!O7t9zv?0YYLrNF0UMx_Md2+h`}yGyd9iL< z!_`Eq82cJ=G0#>vQvKUkQQt<|kGPrVu3z1Thz|7$%)2`|5Rb<)+!`sY$bV|D#_kDZ zk&&um-*F}R(mH;>lf<@QoF_mY?lg)pXAZ8%%$eJ>P;HIG(}S=90{)N8!O_rhF^)Nv zT3&RKnejwJriN5`@k*Pk+Z0+mX4BK%H5?ibGSO*U1xzIOYJSya__kmfPOLKoX)z}) B;9md$