56 lines
2.3 KiB
Nix
56 lines
2.3 KiB
Nix
{ config, pkgs, ... }:
|
|
|
|
# mars — on-site x86_64 box, single-purpose: runs Hermes Agent only.
|
|
# See hermes-agent.nix for what that is and why it moved here from jupiter.
|
|
{
|
|
imports = [
|
|
./hardware-configuration.nix
|
|
./disk-config.nix # disko: OS-disk partitions + filesystems
|
|
./secrets.nix # sops-nix: samba/tailscale/hermes secrets
|
|
./hermes-agent.nix
|
|
../../common.nix # shared base: user / ssh / nix / firewall
|
|
../../services/containers.nix
|
|
../../services/vpn/tailscale.nix
|
|
../../services/monitoring/node-exporter.nix
|
|
../../services/dev/gitea-hermes-webhook-relay.nix
|
|
];
|
|
|
|
networking.hostName = "mars";
|
|
networking.networkmanager.enable = true; # DHCP on-site, same as jupiter
|
|
users.users.darman.extraGroups = [ "docker" ]; # merges with common.nix; podman debug access
|
|
|
|
# ---- Boot (UEFI, confirmed) ----
|
|
boot.loader.systemd-boot.enable = true;
|
|
boot.loader.efi.canTouchEfiVariables = true;
|
|
|
|
# jupiter's samba share (services/network/samba.nix) — mounted on demand so
|
|
# mars doesn't stall boot/login when jupiter is off or unreachable. This is
|
|
# also where Hermes's shared dropbox lives now (hermes-agent.nix). Modes are
|
|
# tighter than terra's equivalent mount (0770 not 0755, gid=hermes not
|
|
# gid=users) since the hermes-agent container (uid 986, gid 983 — no podman
|
|
# userns remapping, see services/network/pihole.nix) needs group write into
|
|
# it, not just darman.
|
|
fileSystems."/mnt/jupiter" = {
|
|
device = "//jupiter/data";
|
|
fsType = "cifs";
|
|
options = [
|
|
"credentials=${config.sops.templates."jupiter-smb.credentials".path}"
|
|
"uid=1000"
|
|
"gid=983"
|
|
"file_mode=0770"
|
|
"dir_mode=0770"
|
|
"nofail"
|
|
"x-systemd.automount" # lazy-mount so boot doesn't stall if jupiter's down
|
|
# NO idle-timeout here (unlike terra's equivalent mount): hermes-agent's
|
|
# podman-hermes-agent.service RequiresMountsFor this path, so an idle
|
|
# auto-unmount tears the container down with it — confirmed the hard
|
|
# way, it killed the service ~60-70s after every start with no crash
|
|
# or error, just "Unmounting /mnt/jupiter" right before the stop.
|
|
"x-systemd.mount-timeout=10s"
|
|
"_netdev"
|
|
];
|
|
};
|
|
|
|
system.stateVersion = "26.05"; # set at install time; do NOT bump on upgrades
|
|
}
|