Vincent Ambo 473604f567 refactor: Move nixpkgs attribute to third_party.nixpkgs
Please read b/108 to make sense of this.

This gets rid of the explicit list of exposed packages from nixpkgs,
and instead makes the entire package set available at

To accommodate this, a LOT of things have to be very slightly shuffled
around. Some of this was done in already submitted CLs, but this
change is unfortunately still quite noisy.

Pay extra attention to:

* overlay-like functionality that was partially moved to actual
  overlays (partially as in, the minimum required to get a green

* modified uses of the package set path, esp. in NixOS systems

Special notes:

* xanthous has been disabled in CI because of issues with the Haskell
* //third_party/nix has been disabled because of other unclear
  dependency issues

Both of these will be tackled in a followup CL.

Change-Id: I2f9c60a4d275fdb5209264be0addfd7e06c53118
Reviewed-by: glittershark <>
Reviewed-by: sterni <>
Tested-by: BuildkiteCI
2021-04-10 21:18:55 +00:00

361 lines
8.4 KiB

# This file configures, my homeserver.
{ depot, pkgs, lib, ... }:
config: let
nixpkgs = import pkgs.path {
config.allowUnfree = true;
nginxRedirect = { from, to, acmeHost }: {
serverName = from;
useACMEHost = acmeHost;
forceSSL = true;
extraConfig = "return 301 https://${to}$request_uri;";
in lib.fix(self: {
# Disable the current ACME module and use the old one from 19.09
# instead, until the various regressions have been sorted out.
# TODO(tazjin): Remove this once the new ACME module works.
disabledModules = [ "security/acme.nix" ];
imports =
let oldChannel = fetchTarball {
# NixOS 19.09 on 2020-10-04
url = "";
sha256 = "157c64220lf825ll4c0cxsdwg7cxqdx4z559fdp7kpz0g6p8fhhr";
in [
# camden is intended to boot unattended, despite having an encrypted
# root partition.
# The below configuration uses an externally connected USB drive
# that contains a LUKS key file to unlock the disk automatically at
# boot.
# TODO(tazjin): Configure LUKS unlocking via SSH instead.
boot = {
initrd = {
availableKernelModules = [
"ahci" "xhci_pci" "usbhid" "usb_storage" "sd_mod" "sdhci_pci"
"rtsx_usb_sdmmc" "r8169"
kernelModules = [ "dm-snapshot" ];
luks.devices.camden-crypt = {
fallbackToPassword = true;
device = "/dev/disk/by-label/camden-crypt";
keyFile = "/dev/sdb";
keyFileSize = 4096;
loader = {
systemd-boot.enable = true;
efi.canTouchEfiVariables = true;
cleanTmpDir = true;
fileSystems = {
"/" = {
device = "/dev/disk/by-label/camden-root";
fsType = "ext4";
"/home" = {
device = "/dev/disk/by-label/camden-home";
fsType = "ext4";
"/boot" = {
device = "/dev/disk/by-label/BOOT";
fsType = "vfat";
nix = {
maxJobs = lib.mkDefault 4;
nixPath = [
trustedUsers = [ "root" "tazjin" ];
binaryCaches = [
binaryCachePublicKeys = [
nixpkgs.pkgs = nixpkgs;
powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
networking = {
hostName = "camden";
interfaces.enp1s0.useDHCP = true;
interfaces.enp1s0.ipv6.addresses = [
address = "2a01:4b00:821a:ce02::5";
prefixLength = 64;
firewall.enable = false;
time.timeZone = "UTC";
# System-wide application setup = true;
programs.mosh.enable = true;
fonts = {
fonts = [ nixpkgs.jetbrains-mono ];
fontconfig.defaultFonts.monospace = [ "JetBrains Mono" ];
environment.systemPackages =
# programs from the depot
(with depot; [
]) ++
# programs from nixpkgs
(with nixpkgs; [
users = {
# Set up my own user for logging in and doing things ...
users.tazjin = {
isNormalUser = true;
uid = 1000;
extraGroups = [ "git" "wheel" "quassel" "video" ];
shell =;
# Set up a user & group for general git shenanigans
groups.git = {};
users.git = {
group = "git";
isNormalUser = false;
# Services setup
services.openssh.enable = true;
services.haveged.enable = true;
# Join Tailscale into home network
services.tailscale.enable = true;
# Allow sudo-ing via the forwarded SSH agent.
security.pam.enableSSHAgentAuth = true;
# NixOS 20.03 broke nginx and I can't be bothered to debug it
# anymore, all solution attempts have failed, so here's a
# brute-force fix. = {
script = "${nixpkgs.coreutils}/bin/chown -R nginx: /var/spool/nginx /var/cache/nginx";
serviceConfig = {
User = "root";
Type = "oneshot";
systemd.timers.fix-nginx = {
wantedBy = [ "" ];
timerConfig = {
OnCalendar = "minutely";
# Provision a TLS certificate outside of nginx to avoid
# nixpkgs#38144
security.acme = {
# acceptTerms = true;
certs."" = {
email = "";
user = "nginx";
group = "nginx";
webroot = "/var/lib/acme/acme-challenge";
extraDomains = {
"" = null;
"" = null;
"" = null;
# Local domains (for this machine only)
"" = null;
postRun = "systemctl reload nginx";
certs."" = {
email = "";
webroot = "/var/lib/acme/challenge-quassel";
user = "nginx"; # required because of a bug in the ACME module
group = "quassel";
allowKeysForGroup = true;
# Forward logs to Google Cloud Platform
services.journaldriver = {
enable = true;
logStream = "home";
googleCloudProject = "tazjins-infrastructure";
applicationCredentials = "/etc/gcp/key.json";
services.depot.quassel = {
enable = true;
acmeHost = "";
bindAddresses = [
services.bitlbee = {
enable = true;
portNumber = 2337; # bees
# serve my website(s)
services.nginx = {
enable = true;
enableReload = true;
package = with nixpkgs; nginx.override {
modules = [ nginxModules.rtmp ];
recommendedTlsSettings = true;
recommendedGzipSettings = true;
recommendedProxySettings = true;
appendConfig = ''
rtmp_auto_push on;
rtmp {
server {
listen 1935;
chunk_size 4000;
application tvl {
live on;
allow publish;
allow publish;
deny publish all;
allow play all;
commonHttpConfig = ''
log_format json_combined escape=json
access_log syslog:server=unix:/dev/log,nohostname json_combined;
virtualHosts.homepage = {
serverName = "";
serverAliases = [ "" ];
default = true;
useACMEHost = "";
root = depot.users.tazjin.homepage;
forceSSL = true;
extraConfig = ''
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
location ~* \.(webp|woff2)$ {
add_header Cache-Control "public, max-age=31536000";
location /blog/ {
alias ${}/;
if ($request_uri ~ ^/(.*)\.html$) {
return 302 /$1;
try_files $uri $uri.html $uri/ =404;
location = /tazjin {
return 200 "tazjin";
location /blobs/ {
alias /var/www/blobs/;
virtualHosts.cgit-old = nginxRedirect {
from = "";
to = "";
acmeHost = "";
virtualHosts.cs-old = nginxRedirect {
from = "";
to = "";
acmeHost = "";
# Timer units that can be started with systemd-run to set my alarm. = {
script = "${}/bin/idualctl wakey";
postStart = "${pkgs.systemd}/bin/systemctl --user stop light-alarm.timer";
serviceConfig = {
Type = "oneshot";
system.stateVersion = "19.09";