{ config, pkgs, ... }: # mars — on-site x86_64 box, single-purpose: runs Hermes Agent only. # See hermes-agent.nix for what that is and why it moved here from jupiter. { imports = [ ./hardware-configuration.nix ./disk-config.nix # disko: OS-disk partitions + filesystems ./secrets.nix # sops-nix: samba/tailscale/hermes secrets ./hermes-agent.nix ../../common.nix # shared base: user / ssh / nix / firewall ../../services/containers.nix ../../services/vpn/tailscale.nix ../../services/monitoring/node-exporter.nix ]; networking.hostName = "mars"; networking.networkmanager.enable = true; # DHCP on-site, same as jupiter users.users.darman.extraGroups = [ "docker" ]; # merges with common.nix; podman debug access # ---- Boot (UEFI, confirmed) ---- boot.loader.systemd-boot.enable = true; boot.loader.efi.canTouchEfiVariables = true; # jupiter's samba share (services/network/samba.nix) — mounted on demand so # mars doesn't stall boot/login when jupiter is off or unreachable. This is # also where Hermes's shared dropbox lives now (hermes-agent.nix). Modes are # tighter than terra's equivalent mount (0770 not 0755, gid=hermes not # gid=users) since the hermes-agent container (uid 986, gid 983 — no podman # userns remapping, see services/network/pihole.nix) needs group write into # it, not just darman. fileSystems."/mnt/jupiter" = { device = "//jupiter/data"; fsType = "cifs"; options = [ "credentials=${config.sops.templates."jupiter-smb.credentials".path}" "uid=1000" "gid=983" "file_mode=0770" "dir_mode=0770" "nofail" "x-systemd.automount" # lazy-mount so boot doesn't stall if jupiter's down # NO idle-timeout here (unlike terra's equivalent mount): hermes-agent's # podman-hermes-agent.service RequiresMountsFor this path, so an idle # auto-unmount tears the container down with it — confirmed the hard # way, it killed the service ~60-70s after every start with no crash # or error, just "Unmounting /mnt/jupiter" right before the stop. "x-systemd.mount-timeout=10s" "_netdev" ]; }; system.stateVersion = "26.05"; # set at install time; do NOT bump on upgrades }