Files
homelab/flake.nix
T
erik ac05d948b6 refactor: rename vps host -> neptun (solar-system theme)
git-mv hosts/vps->neptun, secrets/vps.yaml->neptun.yaml; update flake, .sops.yaml
rules, hostName, sops paths, README/CLAUDE. Off-repo host key dir renamed too.
2026-07-14 13:32:44 +02:00

138 lines
5.3 KiB
Nix

{
description = "Homelab NixOS configuration";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
disko = {
url = "github:nix-community/disko";
inputs.nixpkgs.follows = "nixpkgs";
};
sops-nix = {
url = "github:Mic92/sops-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
nixos-images = {
url = "github:nix-community/nixos-images";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = { self, nixpkgs, disko, sops-nix, nixos-images, ... }@inputs:
let
system = "x86_64-linux";
in
{
nixosConfigurations = {
# Real host — install on the ZimaBlade.
# disko owns the OS-disk partitioning + filesystems (see disk-config.nix).
jupiter = nixpkgs.lib.nixosSystem {
inherit system;
specialArgs = { inherit inputs; };
modules = [
disko.nixosModules.disko
sops-nix.nixosModules.sops
./hosts/jupiter/configuration.nix
];
};
# netcup VPS — public reverse proxy + tailnet node.
neptun = nixpkgs.lib.nixosSystem {
inherit system;
specialArgs = { inherit inputs; };
modules = [
disko.nixosModules.disko
sops-nix.nixosModules.sops
./hosts/neptun/configuration.nix
];
};
# mercury — Raspberry Pi 3B+ (aarch64), DNS/DHCP. Boots from an SD image:
# nix build .#nixosConfigurations.mercury.config.system.build.sdImage
# (aarch64 build — needs binfmt/qemu on this x86 host, or a remote/aarch64
# builder; substitutes most paths from cache.nixos.org.)
mercury = nixpkgs.lib.nixosSystem {
system = "aarch64-linux";
specialArgs = { inherit inputs; };
modules = [
(nixpkgs + "/nixos/modules/installer/sd-card/sd-image-aarch64.nix")
sops-nix.nixosModules.sops
./hosts/mercury/configuration.nix
];
};
# x86_64 QEMU VM to runtime-test mercury's DNS/DHCP stack (pihole +
# unbound) before flashing the aarch64 SD. Build + run:
# nix build .#nixosConfigurations.mercury-vm.config.system.build.vm
# ./result/bin/run-mercury-vm-vm
mercury-vm = nixpkgs.lib.nixosSystem {
inherit system; # x86_64-linux, fast to build/boot with KVM
modules = [
(nixpkgs + "/nixos/modules/virtualisation/qemu-vm.nix")
./common.nix
./services/unbound.nix
./services/pihole.nix
({ lib, ... }: {
networking.hostName = "mercury-vm";
networking.nameservers = [ "1.1.1.1" "9.9.9.9" ]; # host resolver (not pihole)
users.users.darman.initialPassword = "test";
users.users.root.initialPassword = "test";
services.openssh.settings.PasswordAuthentication = lib.mkForce true;
virtualisation.graphics = false;
virtualisation.memorySize = 2048;
virtualisation.forwardPorts = [
{ from = "host"; host.port = 2223; guest.port = 22; }
{ from = "host"; host.port = 8081; guest.port = 80; }
];
system.stateVersion = "26.05";
})
];
};
# VirtualBox test image. Build the OVA with:
# nix build .#nixosConfigurations.jupiter-vbox.config.system.build.virtualBoxOVA
# NOTE: no disko here — the virtualbox-image module supplies the disk.
jupiter-vbox = nixpkgs.lib.nixosSystem {
inherit system;
specialArgs = { inherit inputs; };
modules = [ ./hosts/jupiter/vm.nix ];
};
# Custom kexec installer with our SSH key baked in, for headless install
# onto a box with a read-only root (ZimaOS) where nixos-anywhere can't
# ssh-copy-id. Build the tarball:
# nix build .#nixosConfigurations.kexec.config.system.build.kexecInstallerTarball
# then scp it to the target's writable /tmp and run kexec/run (see README).
kexec = nixpkgs.lib.nixosSystem {
inherit system;
modules = [
nixos-images.nixosModules.kexec-installer
({ ... }: {
users.users.root.openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGZpkPVhzi1zG5JI9hWyUgdyvNIQbp4ts4jw3idpMhhN erik@laptop"
];
})
];
};
# Bootable USB recovery installer with our SSH key + sshd + DHCP.
# Build the ISO:
# nix build .#nixosConfigurations.installer-iso.config.system.build.isoImage
# dd it to a USB stick, boot the ZimaBlade from it, SSH in, ./deploy install.
installer-iso = nixpkgs.lib.nixosSystem {
inherit system;
modules = [
(nixpkgs + "/nixos/modules/installer/cd-dvd/installation-cd-minimal.nix")
({ ... }: {
services.openssh.enable = true;
services.openssh.settings.PermitRootLogin = "prohibit-password";
users.users.root.openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGZpkPVhzi1zG5JI9hWyUgdyvNIQbp4ts4jw3idpMhhN erik@laptop"
];
networking.hostName = "jupiter-installer";
})
];
};
};
};
}