refactor: move host configs under hosts/{jupiter,vps}
- git-mv jupiter/ vps/ into hosts/; fix ../ -> ../../ for common/services/secrets - flake.nix + deploy point at hosts/<config>/ - README structure updated - verified: jupiter/vps/vbox all eval
This commit is contained in:
@@ -0,0 +1,49 @@
|
||||
{ config, pkgs, lib, modulesPath, ... }:
|
||||
|
||||
# VirtualBox test image — mirrors jupiter's services (minus tailscale/sops/disk)
|
||||
# and adds console/SSH login credentials. Disk + bootloader come from the
|
||||
# virtualbox-image module, so hardware-configuration.nix is NOT imported.
|
||||
{
|
||||
imports = [
|
||||
(modulesPath + "/virtualisation/virtualbox-image.nix")
|
||||
../../common.nix # shared base: user / ssh / nix / firewall
|
||||
../../services/samba.nix
|
||||
../../services/avahi.nix
|
||||
../../services/audiobookshelf.nix
|
||||
../../services/containers.nix
|
||||
../../services/caddy.nix
|
||||
];
|
||||
|
||||
networking.hostName = "jupiter";
|
||||
networking.networkmanager.enable = true;
|
||||
users.users.darman.extraGroups = [ "docker" ];
|
||||
|
||||
# Allow password login for testing (real host is key-only).
|
||||
services.openssh.settings.PasswordAuthentication = lib.mkForce true;
|
||||
|
||||
# Login: darman / test (change or remove for anything but local testing).
|
||||
users.users.darman.initialPassword = "test";
|
||||
users.users.root.initialPassword = "test";
|
||||
|
||||
# Throwaway SMB password for testing (samba-smbd login = darman / test).
|
||||
# Single line — the provisioning oneshot feeds it twice for smbpasswd.
|
||||
# Real host must NOT do this — plaintext lands in the world-readable Nix
|
||||
# store. It uses sops-nix (secrets.nix) instead.
|
||||
environment.etc."samba/smb-password" = {
|
||||
text = "test\n";
|
||||
mode = "0600";
|
||||
};
|
||||
|
||||
# Caddy vhosts (same as the LAN host, so the proxy path is testable).
|
||||
services.caddy.virtualHosts = {
|
||||
"http://localhost".extraConfig = "reverse_proxy localhost:8080";
|
||||
"http://audiobookshelf.jupiter.sol".extraConfig = "reverse_proxy localhost:8000";
|
||||
};
|
||||
|
||||
# Guest additions for clipboard/resize (optional).
|
||||
virtualisation.virtualbox.guest.enable = true;
|
||||
|
||||
# Smaller virtual disk = faster image assembly + VMDK compression.
|
||||
# Size in MiB (default is ~50G).
|
||||
virtualisation.diskSize = 6144; # 6 GiB total disk
|
||||
}
|
||||
Reference in New Issue
Block a user