1
0
forked from c3d2/nix-config
nix-config/hosts/server10/default.nix

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

48 lines
960 B
Nix
Raw Normal View History

2022-05-14 20:33:56 +02:00
{ config, pkgs, ... }:
{
imports = [
./hardware-configuration.nix
2022-05-15 02:46:14 +02:00
./microvm-staging.nix
2022-05-28 00:12:18 +02:00
./microvms.nix
2022-06-12 17:26:32 +02:00
];
2022-05-17 01:14:05 +02:00
c3d2.hq.statistics.enable = true;
c3d2.deployment.microvmBaseZfsDataset = "server10/vm";
2022-06-12 17:26:32 +02:00
boot= {
2022-05-14 20:33:56 +02:00
loader.grub = {
enable = true;
version = 2;
device = "/dev/sda";
2022-06-12 17:26:32 +02:00
};
2022-07-20 20:57:17 +02:00
kernelPackages = config.boot.zfs.package.latestCompatibleLinuxPackages;
2022-05-14 20:33:56 +02:00
kernelParams = [
"preempt=none"
# No server/router runs any untrusted user code
"mitigations=off"
];
tmpOnTmpfs = true;
tmpOnTmpfsSize = "80%";
2022-06-12 17:26:32 +02:00
};
2022-05-14 20:33:56 +02:00
networking = {
hostName = "server10";
# TODO: change that to something more random
hostId = "10101010";
2022-06-12 17:26:32 +02:00
};
2022-05-14 20:33:56 +02:00
networking.firewall = {
enable = true;
allowedTCPPorts = [ 22 ];
};
2022-05-17 01:14:05 +02:00
services.openssh.enable = true;
2022-06-29 20:04:57 +02:00
services.zfs.autoScrub.enable = true;
services.smartd.enable = true;
2022-06-29 20:04:57 +02:00
2022-05-14 20:33:56 +02:00
system.stateVersion = "21.11"; # Did you read the comment?
}