2019-03-20 04:37:00 +01:00
|
|
|
{ config, lib, ... }:
|
2019-03-20 02:57:59 +01:00
|
|
|
|
|
|
|
with lib;
|
|
|
|
|
2019-02-26 13:44:40 +01:00
|
|
|
{
|
2019-03-20 02:57:59 +01:00
|
|
|
imports = [
|
|
|
|
../../options/machine.nix
|
|
|
|
./Ophanim.nix
|
2019-02-26 13:44:40 +01:00
|
|
|
];
|
2019-03-20 02:57:59 +01:00
|
|
|
|
|
|
|
config.machine = {
|
|
|
|
hostName = "Ophanim";
|
2019-02-26 13:44:40 +01:00
|
|
|
allowUnfree = true;
|
2019-03-20 02:57:59 +01:00
|
|
|
conffiles = [
|
|
|
|
"etcvars"
|
2019-03-20 04:37:00 +01:00
|
|
|
"security"
|
2019-03-20 02:57:59 +01:00
|
|
|
"zsh"
|
|
|
|
];
|
|
|
|
pkgs = [
|
|
|
|
"base"
|
|
|
|
"emacs"
|
|
|
|
"server"
|
|
|
|
];
|
|
|
|
services = [
|
2019-03-20 04:37:00 +01:00
|
|
|
"fail2ban"
|
2019-03-20 02:57:59 +01:00
|
|
|
"gitea"
|
|
|
|
"hydra"
|
|
|
|
"mailserver"
|
|
|
|
"mariaDB"
|
|
|
|
"nextcloud"
|
|
|
|
"nginx"
|
|
|
|
"openssh"
|
|
|
|
];
|
|
|
|
firewall = {
|
|
|
|
allowPing = false;
|
|
|
|
allowedUDPPorts = [ 22 80 443 ];
|
|
|
|
allowedTCPPorts = [ 80 443 ]; # 5222 5269 ];
|
|
|
|
allowedUDPPortRanges = [];
|
|
|
|
allowedTCPPortRanges = [];
|
2019-02-26 13:44:40 +01:00
|
|
|
};
|
|
|
|
};
|
|
|
|
}
|