jupiter had a leftover docker-compose Immich on the RAID (/mnt/data/Immich, 9.9G) that survived the NixOS install. Native module now, media at /mnt/data/AppData/immich, caddy vhost on 2283 with a 50GB body limit (caddy's default rejects video uploads). The package comes from nixpkgs-unstable, the module from the 26.05 pin: 26.05 ships immich 2.7.5, but that database was last written by 3.0.0 and migrations only run forward -- corrupted migrations: previously executed migration 1776217577402-DropAuditTable is missing Safe because the two module files are byte-identical at these revisions; services/media/immich.nix carries the diff command to re-check on a bump. Drop the input once the stable pin ships >= 3.0.0. immich needs group "users" only to traverse /mnt/data/AppData (drwx--x---); its own dir stays 0700 immich:immich. mediaLocation is outside /var/lib, so the module's tmpfiles entry only ADJUSTS it -- add a rule that creates it. scripts/immich-import-legacy-db does the database half: boots a copy of the legacy PGDATA under the matching image (PG14 + vchord 0.3.0 + pgvector 0.8.1), dumps it with the local pg_dump 17, restores into a scratch DB, fixes ownership, and only swaps after confirmation. Never touches the original. The old cluster ran VectorChord, not pgvecto.rs, so the smart search and face embeddings survive -- no ML re-run. Imported: 666 assets, 25 people, 647 clip + 359 face embeddings, 2 users.
151 lines
6.1 KiB
Nix
151 lines
6.1 KiB
Nix
{
|
|
description = "Homelab NixOS configuration";
|
|
|
|
inputs = {
|
|
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
|
|
# Second nixpkgs, used for ONE package: immich. 26.05 pins 2.7.5, but
|
|
# jupiter's imported database was written by 3.0.0 and immich never
|
|
# migrates a schema backwards. NOT `follows` — the point is a different
|
|
# package set. See services/media/immich.nix.
|
|
nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
|
disko = {
|
|
url = "github:nix-community/disko";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
sops-nix = {
|
|
url = "github:Mic92/sops-nix";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
nixos-images = {
|
|
url = "github:nix-community/nixos-images";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
mediamanager-nix = {
|
|
url = "github:strangeglyph/mediamanager-nix";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
# Deliberately NOT `inputs.nixpkgs.follows` — upstream states overriding it
|
|
# breaks their pinned python dependency set. Costs a second nixpkgs in the
|
|
# lock; builds come prebuilt from nix-community's Cachix.
|
|
authentik-nix.url = "github:nix-community/authentik-nix";
|
|
};
|
|
|
|
outputs = { self, nixpkgs, disko, sops-nix, nixos-images, mediamanager-nix, authentik-nix, ... }@inputs:
|
|
let
|
|
system = "x86_64-linux";
|
|
in
|
|
{
|
|
nixosConfigurations = {
|
|
# Real host — install on the ZimaBlade.
|
|
# disko owns the OS-disk partitioning + filesystems (see disk-config.nix).
|
|
jupiter = nixpkgs.lib.nixosSystem {
|
|
inherit system;
|
|
specialArgs = { inherit inputs; };
|
|
modules = [
|
|
disko.nixosModules.disko
|
|
sops-nix.nixosModules.sops
|
|
./hosts/jupiter/configuration.nix
|
|
];
|
|
};
|
|
|
|
# netcup VPS — public reverse proxy + tailnet node.
|
|
neptun = nixpkgs.lib.nixosSystem {
|
|
inherit system;
|
|
specialArgs = { inherit inputs; };
|
|
modules = [
|
|
disko.nixosModules.disko
|
|
sops-nix.nixosModules.sops
|
|
./hosts/neptun/configuration.nix
|
|
];
|
|
};
|
|
|
|
# mercury — Raspberry Pi 3B+ (aarch64), DNS/DHCP. Boots from an SD image:
|
|
# nix build .#nixosConfigurations.mercury.config.system.build.sdImage
|
|
# (aarch64 build — needs binfmt/qemu on this x86 host, or a remote/aarch64
|
|
# builder; substitutes most paths from cache.nixos.org.)
|
|
mercury = nixpkgs.lib.nixosSystem {
|
|
system = "aarch64-linux";
|
|
specialArgs = { inherit inputs; };
|
|
modules = [
|
|
(nixpkgs + "/nixos/modules/installer/sd-card/sd-image-aarch64.nix")
|
|
sops-nix.nixosModules.sops
|
|
./hosts/mercury/configuration.nix
|
|
];
|
|
};
|
|
|
|
# x86_64 QEMU VM to runtime-test mercury's DNS/DHCP stack (pihole +
|
|
# unbound) before flashing the aarch64 SD. Build + run:
|
|
# nix build .#nixosConfigurations.mercury-vm.config.system.build.vm
|
|
# ./result/bin/run-mercury-vm-vm
|
|
mercury-vm = nixpkgs.lib.nixosSystem {
|
|
inherit system; # x86_64-linux, fast to build/boot with KVM
|
|
modules = [
|
|
(nixpkgs + "/nixos/modules/virtualisation/qemu-vm.nix")
|
|
./common.nix
|
|
./services/network/unbound.nix
|
|
./services/network/pihole.nix
|
|
({ lib, ... }: {
|
|
networking.hostName = "mercury-vm";
|
|
networking.nameservers = [ "1.1.1.1" "9.9.9.9" ]; # host resolver (not pihole)
|
|
users.users.darman.initialPassword = "test";
|
|
users.users.root.initialPassword = "test";
|
|
services.openssh.settings.PasswordAuthentication = lib.mkForce true;
|
|
virtualisation.graphics = false;
|
|
virtualisation.memorySize = 2048;
|
|
virtualisation.forwardPorts = [
|
|
{ from = "host"; host.port = 2223; guest.port = 22; }
|
|
{ from = "host"; host.port = 8081; guest.port = 80; }
|
|
];
|
|
system.stateVersion = "26.05";
|
|
})
|
|
];
|
|
};
|
|
|
|
# VirtualBox test image. Build the OVA with:
|
|
# nix build .#nixosConfigurations.jupiter-vbox.config.system.build.virtualBoxOVA
|
|
# NOTE: no disko here — the virtualbox-image module supplies the disk.
|
|
jupiter-vbox = nixpkgs.lib.nixosSystem {
|
|
inherit system;
|
|
specialArgs = { inherit inputs; };
|
|
modules = [ ./hosts/jupiter/vm.nix ];
|
|
};
|
|
|
|
# Custom kexec installer with our SSH key baked in, for headless install
|
|
# onto a box with a read-only root (ZimaOS) where nixos-anywhere can't
|
|
# ssh-copy-id. Build the tarball:
|
|
# nix build .#nixosConfigurations.kexec.config.system.build.kexecInstallerTarball
|
|
# then scp it to the target's writable /tmp and run kexec/run (see README).
|
|
kexec = nixpkgs.lib.nixosSystem {
|
|
inherit system;
|
|
modules = [
|
|
nixos-images.nixosModules.kexec-installer
|
|
({ ... }: {
|
|
users.users.root.openssh.authorizedKeys.keys = [
|
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGZpkPVhzi1zG5JI9hWyUgdyvNIQbp4ts4jw3idpMhhN erik@laptop"
|
|
];
|
|
})
|
|
];
|
|
};
|
|
|
|
# Bootable USB recovery installer with our SSH key + sshd + DHCP.
|
|
# Build the ISO:
|
|
# nix build .#nixosConfigurations.installer-iso.config.system.build.isoImage
|
|
# dd it to a USB stick, boot the ZimaBlade from it, SSH in, ./deploy install.
|
|
installer-iso = nixpkgs.lib.nixosSystem {
|
|
inherit system;
|
|
modules = [
|
|
(nixpkgs + "/nixos/modules/installer/cd-dvd/installation-cd-minimal.nix")
|
|
({ ... }: {
|
|
services.openssh.enable = true;
|
|
services.openssh.settings.PermitRootLogin = "prohibit-password";
|
|
users.users.root.openssh.authorizedKeys.keys = [
|
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGZpkPVhzi1zG5JI9hWyUgdyvNIQbp4ts4jw3idpMhhN erik@laptop"
|
|
];
|
|
networking.hostName = "jupiter-installer";
|
|
})
|
|
];
|
|
};
|
|
};
|
|
};
|
|
}
|