Compare commits

...
70 Commits
Author SHA1 Message Date
Superredstone f8d5ed50cd feat(bomba): add mail 2026-08-16 18:23:17 +02:00
Superredstone af48bc4243 flake.lock: update 2026-08-11 07:07:58 +02:00
Superredstone c472ab6548 feat(package): add devenv 2026-08-03 09:19:39 +02:00
Superredstone 4c884aee53 feat(noctalia): update settings 2026-08-03 09:19:39 +02:00
Superredstone 3d94b88b8e feat(jellyfin): add sso button to login page 2026-08-02 12:46:21 +02:00
Superredstone f075d45940 feat(qbittorrent): replaced webui login with authentik 2026-08-01 12:01:44 +02:00
Superredstone 5a0da9e0c4 feat(package): move android-studio from workPackages to guiPackages 2026-08-01 11:58:28 +02:00
Superredstone 51db4bd2b7 flake.lock: update 2026-08-01 11:58:04 +02:00
Superredstone 81006c28ba feat(cache): remove garnix (broken) 2026-07-31 21:45:05 +02:00
Superredstone cf06ecb6f6 flake.lock: update 2026-07-31 16:13:08 +02:00
Superredstone 03a33a340c feat(font): add vista-fonts 2026-07-31 16:12:25 +02:00
Superredstone 2e896ece93 feat(package): add libreoffice 2026-07-31 16:12:25 +02:00
Superredstone 6f090a0f6b feat(mangohud): incresed fps limit to 180 2026-07-31 16:12:25 +02:00
Superredstone e217b7c9ca feat(niri): change border-radius to 0 2026-07-31 16:12:25 +02:00
Patrick Canal b875e51544 feat(bomba): add authentik and sso - #4 2026-07-29 14:05:36 +02:00
Superredstone daef5478e3 feat(font): add monocraft and miracode 2026-07-27 21:29:50 +02:00
Superredstone 80ed9fe8ca feat(package): remove onlyoffice 2026-07-27 14:29:30 +02:00
Superredstone f907059a56 flake.lock: update 2026-07-27 14:29:16 +02:00
Superredstone 932a549440 feat(qbittorrent): added sso 2026-07-26 22:47:49 +02:00
Superredstone 81ba782c92 feat(adguard): enable sso 2026-07-26 09:17:25 +02:00
Superredstone 041f84b476 flake.lock: update 2026-07-24 23:21:16 +02:00
Superredstone 4367838df1 feat(yamtrack): enable sso 2026-07-24 21:44:09 +02:00
Superredstone 07f584aee7 feat(vikunja): enable sso 2026-07-24 21:26:19 +02:00
Superredstone a387a61b50 feat(vaultwarden): enabled sso 2026-07-24 19:52:24 +02:00
Superredstone 1cd710e642 feat(bomba): add authentik 2026-07-23 15:46:30 +02:00
Superredstone 6496e7b6ed feat(bomba): update nextcloud to 43 2026-07-22 23:18:43 +02:00
Superredstone ef5402233b flake.lock: update 2026-07-22 11:42:25 +02:00
Superredstone 4dd411565d flake.lock: update 2026-07-19 09:39:45 +02:00
Superredstone c92264b7c9 feat(bomba): add podman-compose 2026-07-19 09:32:22 +02:00
Superredstone 68a0d85428 feat(bomba): open port 25565 2026-07-19 09:32:06 +02:00
Superredstone 9539818438 feat(bomba): add adguard 2026-07-16 19:08:45 +02:00
Superredstone 3ec2c6f4fa feat(bash): add alias to nix develop 2026-07-14 19:39:45 +02:00
Superredstone 8191fa945a flake.lock: update 2026-07-13 14:55:13 +02:00
Superredstone 9ad1698bb0 feat(bomba): add homebox 2026-07-11 13:50:03 +02:00
Superredstone f958e451f1 feat(bomba): add actual 2026-07-11 11:11:04 +02:00
Superredstone d297da3ea7 feat(bomba): add fail2ban 2026-07-11 10:31:40 +02:00
Superredstone 29a071a38c fix(bomba): remove gitea-act-runner 2026-07-11 08:24:19 +02:00
Superredstone a5313a1184 feat(package): add some packages 2026-07-10 08:40:21 +02:00
Superredstone 12ed9d8b12 feat(noctalia): update settings 2026-07-10 08:18:33 +02:00
Superredstone 7b49419b69 feat(program): replace discord with vesktop 2026-07-09 16:14:14 +02:00
Superredstone 04e6599d0c flake.lock: update 2026-07-08 17:27:26 +02:00
Superredstone 7f52f5697f feat(katana): move to cachy lts kernel with open beta nvidia drivers 2026-07-08 17:27:26 +02:00
Superredstone 1a95cfd98f feat(yamtrack): update env file 2026-07-08 08:55:22 +02:00
Superredstone 30dd8ed14f feat(bomba): add yamtrack 2026-07-08 05:59:07 +02:00
Superredstone e19581865d feat(navidrome): change art priority to external 2026-07-07 17:16:22 +02:00
Superredstone 5a0991c6b3 feat(niri): replace wlr with gnome portal to fix screenshare 2026-07-05 17:49:25 +02:00
Superredstone 4d466cbcd3 feat(niri): remove qt theme 2026-07-05 16:03:53 +02:00
Superredstone d785c22d68 feat(navidrome): add lastfm credentials 2026-07-04 11:52:59 +02:00
Superredstone b583c67e05 flake.lock: update 2026-07-04 11:51:25 +02:00
Superredstone 8920aaea58 feat(niri): fix missing icons in nautilus 2026-07-02 07:48:25 +02:00
Superredstone 50465d3801 flake.lock: update 2026-07-01 07:37:19 +02:00
Superredstone 941fa9f0b7 fix(bomba): remove navidrome plugins 2026-06-28 19:09:33 +02:00
Superredstone 097a835e7f feat(bomba): add navidrome plugin 2026-06-28 18:33:36 +02:00
Superredstone 2ca1473428 feat(bomba): add navidrome 2026-06-27 23:12:19 +02:00
Superredstone db11112757 feat(bomba): add recyclarr 2026-06-27 21:46:27 +02:00
Superredstone 5875162f2d flake.lock: update 2026-06-27 21:46:04 +02:00
Superredstone 838ddc962e fix(katana): fix nvidia kernel panic on shutdown 2026-06-27 08:26:50 +02:00
Superredstone b0885e290c feat(bomba): fix broken indexer 2026-06-26 19:50:04 +02:00
Superredstone 9b77126738 feat(niri): add new monitor config 2026-06-26 17:15:09 +02:00
Superredstone 3c86945919 feat(bomba): add indexers 2026-06-26 13:57:53 +02:00
Superredstone fc5a8e0898 feat(bomba): add lidarr 2026-06-26 13:57:52 +02:00
Superredstone 8b476b1193 flake.lock: update 2026-06-26 13:53:47 +02:00
Superredstone faf729802e feat(gnome): remove papirus theme 2026-06-26 13:52:53 +02:00
Superredstone 3d2cf6d9e2 feat(programs): replace protonplus with proton-ge-bin 2026-06-26 13:52:53 +02:00
Superredstone 74fd9de90f feat(katana): change nvidia driver 2026-06-23 19:16:42 +02:00
Superredstone 8220b23bbc feat(katana): replace cachy kernel with standard 2026-06-22 18:01:47 +02:00
Superredstone 891761c415 feat(noctalia): update config 2026-06-19 17:37:55 +02:00
Superredstone 6c8246cb33 feat(noctalia): update noctalia flake input 2026-06-18 15:25:08 +02:00
Superredstone 81d3c978a0 feat(niri): add keyboard layout switch key 2026-06-16 17:09:25 +02:00
Superredstone bff122ce0a flake.lock: update 2026-06-13 13:29:39 +02:00
34 changed files with 962 additions and 191 deletions
+37
View File
@@ -0,0 +1,37 @@
{
"lastRun": "1763873600000-backfill-files-owner.js",
"migrations": [
{
"title": "1694360000000-create-folders.js",
"timestamp": 1783750350595
},
{
"title": "1694360479680-create-account-db.js",
"timestamp": 1783750350654
},
{
"title": "1694362247011-create-secret-table.js",
"timestamp": 1783750350670
},
{
"title": "1702667624000-rename-nordigen-secrets.js",
"timestamp": 1783750350671
},
{
"title": "1718889148000-openid.js",
"timestamp": 1783750350688
},
{
"title": "1719409568000-multiuser.js",
"timestamp": 1783750350708
},
{
"title": "1763873568237-server-global-prefs.js",
"timestamp": 1783750350724
},
{
"title": "1763873600000-backfill-files-owner.js",
"timestamp": 1783750350726
}
]
}
+7 -1
View File
@@ -35,6 +35,10 @@ output "Acer Technologies Acer KG241Q 0x93210922" {
mode "1920x1080@74.986"
}
output "Microstep MSI G255F BC0M275402311" {
mode "1920x1080@179.998"
}
output "HDMI-A-1" {
mode "1920x1080@60.000"
}
@@ -150,7 +154,7 @@ window-rule {
}
window-rule {
geometry-corner-radius 12
geometry-corner-radius 0 // Embrace rectangles, reject modernity
clip-to-geometry true
}
@@ -194,6 +198,8 @@ binds {
XF86MonBrightnessUp { spawn "noctalia" "msg" "brightness-up"; }
XF86MonBrightnessDown { spawn "noctalia" "msg" "brightness-down"; }
Mod+Shift+Space { spawn "niri" "msg" "action" "switch-layout" "next"; }
Mod+O repeat=false { toggle-overview; }
Mod+Shift+Q repeat=false { close-window; }
+141 -9
View File
@@ -1,4 +1,9 @@
[accessibility]
ui_scale = 0.90000000596046448
[bar.default]
capsule_radius = 0
center = [ "clock" ]
end = [
"media",
"tray",
@@ -25,29 +30,103 @@ enabled = true
[desktop_widgets]
schema_version = 1
widget_order = []
widget_order = [
"desktop-widget-0000000000000001",
"desktop-widget-0000000000000002",
"desktop-widget-0000000000000003",
"desktop-widget-0000000000000005"
]
[desktop_widgets.grid]
cell_size = 16
major_interval = 4
visible = true
[desktop_widgets.widget]
[desktop_widgets.widget.desktop-widget-0000000000000001]
box_height = 0.0
box_width = 0.0
cx = 1762.0
cy = 133.70001220703125
output = "HDMI-A-1"
rotation = 0.0
type = "clock"
[desktop_widgets.widget.desktop-widget-0000000000000001.settings]
background_opacity = 0.0
background_padding = 11
background_radius = 0
center_text = false
clock_style = "digital"
shadow = false
[desktop_widgets.widget.desktop-widget-0000000000000002]
box_height = 0.0
box_width = 0.0
cx = 1114.0
cy = 995.4000244140625
output = "HDMI-A-1"
rotation = 0.0
type = "sysmon"
[desktop_widgets.widget.desktop-widget-0000000000000002.settings]
background_opacity = 0.0
display = "graph"
shadow = false
stat = "cpu_usage"
stat2 = "cpu_temp"
[desktop_widgets.widget.desktop-widget-0000000000000003]
box_height = 0.0
box_width = 0.0
cx = 154.0
cy = 130.60000610351562
output = "HDMI-A-1"
rotation = 0.0
type = "weather"
[desktop_widgets.widget.desktop-widget-0000000000000003.settings]
background_opacity = 0.0
background_padding = 19
background_radius = 0
shadow = false
[desktop_widgets.widget.desktop-widget-0000000000000005]
box_height = 0.0
box_width = 0.0
cx = 810.0
cy = 995.4000244140625
output = "HDMI-A-1"
rotation = 0.0
type = "sysmon"
[desktop_widgets.widget.desktop-widget-0000000000000005.settings]
background_opacity = 0.0
display = "graph"
shadow = false
show_label = true
stat = "ram_pct"
stat2 = "swap_pct"
[dock]
auto_hide = true
enabled = true
icon_size = 40
icon_size = 42
magnification_scale = 1.3000000044703484
padding = 4
radius = 0
reserve_space = false
show_dots = true
[location]
address = "Bolzano"
[lockscreen]
blurred_desktop = true
[lockscreen_widgets]
enabled = false
schema_version = 1
widget_order = [ "lockscreen-login-box@HDMI-A-1", "lockscreen-login-box@eDP-1" ]
widget_order = [ "lockscreen-login-box@winit", "lockscreen-login-box@HDMI-A-1", "lockscreen-login-box@eDP-1" ]
[lockscreen_widgets.grid]
cell_size = 16
@@ -55,6 +134,8 @@ widget_order = [ "lockscreen-login-box@HDMI-A-1", "lockscreen-login-box@eDP-1" ]
visible = true
[lockscreen_widgets.widget."lockscreen-login-box@HDMI-A-1"]
box_height = 70.0
box_width = 400.0
cx = 960.0
cy = 957.0
output = "HDMI-A-1"
@@ -62,7 +143,14 @@ widget_order = [ "lockscreen-login-box@HDMI-A-1", "lockscreen-login-box@eDP-1" ]
scale = 1.0
type = "login_box"
[lockscreen_widgets.widget."lockscreen-login-box@HDMI-A-1".settings]
show_caps_lock = true
show_keyboard_layout = true
show_login_button = true
[lockscreen_widgets.widget."lockscreen-login-box@eDP-1"]
box_height = 70.0
box_width = 400.0
cx = 960.0
cy = 957.0
output = "eDP-1"
@@ -70,20 +158,57 @@ widget_order = [ "lockscreen-login-box@HDMI-A-1", "lockscreen-login-box@eDP-1" ]
scale = 1.0
type = "login_box"
[lockscreen_widgets.widget."lockscreen-login-box@eDP-1".settings]
show_caps_lock = true
show_keyboard_layout = true
show_login_button = true
[lockscreen_widgets.widget."lockscreen-login-box@winit"]
box_height = 70.0
box_width = 400.0
cx = 464.0
cy = 863.0
output = "winit"
rotation = 0.0
type = "login_box"
[lockscreen_widgets.widget."lockscreen-login-box@winit".settings]
background_color = "surface_variant"
background_opacity = 0.88
background_radius = 12.0
input_opacity = 1.0
input_radius = 6.0
show_caps_lock = true
show_keyboard_layout = true
show_login_button = true
[osd.kinds]
media = false
[plugins]
enabled = []
[shell]
avatar_path = "/home/r3ddy/.face"
font_family = "Noto Sans"
corner_radius_scale = 0.0
font_family = "Monocraft"
polkit_agent = true
settings_show_advanced = true
[shell.screen_corners]
size = 1
[theme]
builtin = "Catppuccin"
community_palette = "Tokyo Night Moon"
community_palette = "One Dark Two"
custom_palette = "Tokyo Night Moon"
mode = "dark"
source = "builtin"
wallpaper_scheme = "m3-content"
wallpaper_scheme = "dysfunctional"
[theme.templates]
builtin_ids = [ "gtk3", "gtk4", "kitty", "niri", "qt" ]
community_ids = [ "telegram" ]
builtin_ids = [ "btop", "gtk3", "gtk4", "kcolorscheme", "kitty", "niri", "qt" ]
community_ids = [ "discord", "telegram", "vscode", "heroiclauncher", "steam", "obs", "lazygit" ]
[wallpaper]
directory = "/home/r3ddy/Pictures/Wallpapers"
@@ -104,6 +229,13 @@ directory = "/home/r3ddy/Pictures/Wallpapers"
address = "Bolzano"
refresh_minutes = 60
[widget.cat]
audio_spectrum = true
rave_mode = true
tappy_mode = true
type = "noctalia/bongocat:cat"
use_mpris_filter = true
[widget.clock]
format = "{:%a %d %b %Y %H:%M}"
Generated
+370 -87
View File
@@ -1,38 +1,116 @@
{
"nodes": {
"cachyos-kernel": {
"flake": false,
"authentik-nix": {
"inputs": {
"authentik-src": "authentik-src",
"client-ts-generator-src": "client-ts-generator-src",
"flake-compat": "flake-compat",
"flake-parts": "flake-parts",
"flake-utils": "flake-utils",
"nixpkgs": [
"nixpkgs"
],
"pyproject-build-systems": "pyproject-build-systems",
"pyproject-nix": "pyproject-nix",
"systems": "systems",
"uv2nix": "uv2nix"
},
"locked": {
"lastModified": 1780413908,
"narHash": "sha256-T15bnskj20rdc4vJ55bFF2lVCVR8edilWn0hiYR7vVs=",
"owner": "CachyOS",
"repo": "linux-cachyos",
"rev": "a61f943f5e94b75c5600a2968cb699d0e37945b3",
"lastModified": 1786375669,
"narHash": "sha256-w4kG3Alh6akMNbrsNwpKa0Pe/WLgvxjIAPXh9KYibmM=",
"owner": "nix-community",
"repo": "authentik-nix",
"rev": "b7a42b503f0c7bf26a30ddb48de0bfaf43d6ead1",
"type": "github"
},
"original": {
"owner": "CachyOS",
"repo": "linux-cachyos",
"owner": "nix-community",
"repo": "authentik-nix",
"type": "github"
}
},
"cachyos-kernel-patches": {
"authentik-src": {
"flake": false,
"locked": {
"lastModified": 1780462466,
"narHash": "sha256-t6c7FTqMB0skEz+4tei5v8GEyL4fRDgx24oW3LrnYiE=",
"owner": "CachyOS",
"repo": "kernel-patches",
"rev": "bb41330bd4372672f552beda66712fb70b17f0fa",
"lastModified": 1784731584,
"narHash": "sha256-/HdXzjjvuSW7zjbCNJKm3Fj8gvIwfrDf8mOYev0yuIg=",
"owner": "goauthentik",
"repo": "authentik",
"rev": "0c67ea476be6319f1b2a41cb0f5ed128af37b99b",
"type": "github"
},
"original": {
"owner": "CachyOS",
"repo": "kernel-patches",
"owner": "goauthentik",
"ref": "version/2026.5.6",
"repo": "authentik",
"type": "github"
}
},
"blobs": {
"flake": false,
"locked": {
"lastModified": 1604995301,
"narHash": "sha256-wcLzgLec6SGJA8fx1OEN1yV/Py5b+U5iyYpksUY/yLw=",
"owner": "simple-nixos-mailserver",
"repo": "blobs",
"rev": "2cccdf1ca48316f2cfd1c9a0017e8de5a7156265",
"type": "gitlab"
},
"original": {
"owner": "simple-nixos-mailserver",
"repo": "blobs",
"type": "gitlab"
}
},
"client-ts-generator-src": {
"flake": false,
"locked": {
"lastModified": 1784638510,
"narHash": "sha256-NfwEWQ/SRjgeUz+F/7uoWAMwk7OqdF2+686krhvJn2M=",
"owner": "goauthentik",
"repo": "client-ts",
"rev": "5850af5867bef6fd4291731797d21b704c7f189d",
"type": "github"
},
"original": {
"owner": "goauthentik",
"repo": "client-ts",
"type": "github"
}
},
"flake-compat": {
"flake": false,
"locked": {
"lastModified": 1767039857,
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-compat_2": {
"flake": false,
"locked": {
"lastModified": 1767039857,
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
"owner": "NixOS",
"repo": "flake-compat",
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "flake-compat",
"type": "github"
}
},
"flake-compat_3": {
"flake": false,
"locked": {
"lastModified": 1767039857,
@@ -53,11 +131,11 @@
"nixpkgs-lib": "nixpkgs-lib"
},
"locked": {
"lastModified": 1778716662,
"narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=",
"lastModified": 1785627969,
"narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb",
"rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a",
"type": "github"
},
"original": {
@@ -67,6 +145,24 @@
}
},
"flake-parts_2": {
"inputs": {
"nixpkgs-lib": "nixpkgs-lib_2"
},
"locked": {
"lastModified": 1785627969,
"narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "flake-parts",
"type": "github"
}
},
"flake-parts_3": {
"inputs": {
"nixpkgs-lib": [
"nixvim",
@@ -75,11 +171,11 @@
]
},
"locked": {
"lastModified": 1778716662,
"narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=",
"lastModified": 1782949081,
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb",
"rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e",
"type": "github"
},
"original": {
@@ -90,7 +186,10 @@
},
"flake-utils": {
"inputs": {
"systems": "systems"
"systems": [
"authentik-nix",
"systems"
]
},
"locked": {
"lastModified": 1731533236,
@@ -106,6 +205,49 @@
"type": "github"
}
},
"flake-utils_2": {
"inputs": {
"systems": "systems_2"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"git-hooks": {
"inputs": {
"flake-compat": [
"simple-mailserver",
"flake-compat"
],
"nixpkgs": [
"simple-mailserver",
"nixpkgs"
]
},
"locked": {
"lastModified": 1784288435,
"narHash": "sha256-ReRHaLgr/uVqdD8afFSn+myXIfpHeOhP0yYe0TJqAA8=",
"owner": "cachix",
"repo": "git-hooks.nix",
"rev": "43b3c1ab9d40fb1dbb008f451988a91e375825e9",
"type": "github"
},
"original": {
"owner": "cachix",
"repo": "git-hooks.nix",
"type": "github"
}
},
"home-manager": {
"inputs": {
"nixpkgs": [
@@ -113,11 +255,11 @@
]
},
"locked": {
"lastModified": 1781064232,
"narHash": "sha256-+7cIaqM6ucKf5fDyMnkwehxG8tBdaU51TZOMtxacXmI=",
"lastModified": 1786356609,
"narHash": "sha256-ou8fYz5w9yhXC8YbvvExybFIa19MyW5G/8dEPqa90hM=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "1ffdc28076a1809ee7c0cf08f06af18f31c480cd",
"rev": "c30c7955cec30d664a9baced6bc0112e263d4647",
"type": "github"
},
"original": {
@@ -144,18 +286,16 @@
},
"nix-cachyos-kernel": {
"inputs": {
"cachyos-kernel": "cachyos-kernel",
"cachyos-kernel-patches": "cachyos-kernel-patches",
"flake-compat": "flake-compat",
"flake-parts": "flake-parts",
"flake-compat": "flake-compat_2",
"flake-parts": "flake-parts_2",
"nixpkgs": "nixpkgs"
},
"locked": {
"lastModified": 1780771919,
"narHash": "sha256-cbace1ZTWYFG0luPL7OFlUxDh/t9lmPj+Isvg9hLN0k=",
"lastModified": 1785870829,
"narHash": "sha256-l+RTmz09TxwWJRLQuc+cKi3yY0K4PSz8tRPTbBUvaVo=",
"owner": "xddxdd",
"repo": "nix-cachyos-kernel",
"rev": "3d940a534da0ba6bce60e345ff2c9c7b062087fb",
"rev": "879f45ee15a3b06fdbbf9b6dc825c5fbca137fcd",
"type": "github"
},
"original": {
@@ -175,11 +315,11 @@
"vpn-confinement": "vpn-confinement"
},
"locked": {
"lastModified": 1780934252,
"narHash": "sha256-3++axEzhGBPO3QpajU7Ni1Byk9XI4+m3p0944HJNe6Q=",
"lastModified": 1786383226,
"narHash": "sha256-5cLjpODa1Valr3p00ReOnoiqQ3EKYjfsRZfpfcfdv0U=",
"owner": "kiriwalawren",
"repo": "nixflix",
"rev": "b34d4959c7092d17121b5da03d01704187ac7eeb",
"rev": "e9c20f232d0e09e346578bf6f8a390c34952643e",
"type": "github"
},
"original": {
@@ -190,11 +330,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1780751787,
"narHash": "sha256-nWR7F46SyrLvN8Ot39XJDpVCswekGakXlOD4KsTYKW0=",
"lastModified": 1785859399,
"narHash": "sha256-pY4X50au95QrTpAbEm08pURmeU3/Ud2oa0s2XzpDdz8=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "00fa9a692bafc08a86061886f888b843bf7fbdb0",
"rev": "85f62611fa3f3eacbcfe3bc7a6d6518b443ca442",
"type": "github"
},
"original": {
@@ -206,11 +346,11 @@
},
"nixpkgs-25-11": {
"locked": {
"lastModified": 1780952837,
"narHash": "sha256-Fwd1+spDtQ0hDyBwme6ufG3n4mY0UrjjFdYHv+G/Hds=",
"lastModified": 1782847189,
"narHash": "sha256-twXPFqFsrrY5r28Zh7Homgcp2gUMBgQ6WDS98Q/3xFI=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "e820eb4a444b46a19b2e03e8dfd2359439ff30fe",
"rev": "b6018f87da91d19d0ab4cf979885689b469cdd41",
"type": "github"
},
"original": {
@@ -222,11 +362,26 @@
},
"nixpkgs-lib": {
"locked": {
"lastModified": 1777168982,
"narHash": "sha256-GOkGPcboWE9BmGCRMLX3worL4EMnsnG8MyKmXNeYuhQ=",
"lastModified": 1785031560,
"narHash": "sha256-OmshNvn2vupOFpYinLUu+1Dnpu4n7Q5N3ggGVNHpkUI=",
"owner": "nix-community",
"repo": "nixpkgs.lib",
"rev": "f5901329dade4a6ea039af1433fb087bd9c1fe14",
"rev": "0e79af5e3d4dcfcd676ab5ba3f95d2e3352e078c",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nixpkgs.lib",
"type": "github"
}
},
"nixpkgs-lib_2": {
"locked": {
"lastModified": 1785031560,
"narHash": "sha256-OmshNvn2vupOFpYinLUu+1Dnpu4n7Q5N3ggGVNHpkUI=",
"owner": "nix-community",
"repo": "nixpkgs.lib",
"rev": "0e79af5e3d4dcfcd676ab5ba3f95d2e3352e078c",
"type": "github"
},
"original": {
@@ -253,11 +408,11 @@
},
"nixpkgs_2": {
"locked": {
"lastModified": 1780749050,
"narHash": "sha256-3av0pIjlOWQ6rDbNOmpUSvbNnJkGORQKKjb4LtCZsIY=",
"lastModified": 1786247143,
"narHash": "sha256-8S3Kcxs7D4UtxJxSJZz0m14CGhuW0MxfrIwJxeGWGnQ=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "a799d3e3886da994fa307f817a6bc705ae538eeb",
"rev": "279b4a8275f032c566576b3f181fa0f27197f588",
"type": "github"
},
"original": {
@@ -269,12 +424,11 @@
},
"nixpkgs_3": {
"locked": {
"lastModified": 1778869304,
"narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "d233902339c02a9c334e7e593de68855ad26c4cb",
"type": "github"
"lastModified": 1783816212,
"narHash": "sha256-M2X3JTJp7ktX73uVDEAm0Rws2A/xljf4Cu1ojd/o8pU=",
"rev": "3b32825de172d0bc85664f495edb096b10862524",
"type": "tarball",
"url": "https://releases.nixos.org/nixpkgs/nixpkgs-26.11pre1033157.3b32825de172/nixexprs.tar.xz"
},
"original": {
"id": "nixpkgs",
@@ -283,11 +437,11 @@
},
"nixpkgs_4": {
"locked": {
"lastModified": 1778794387,
"narHash": "sha256-BL04pOS9453Awkeb9f90XBJXBSkWxN+vB7HIgnL0iMM=",
"lastModified": 1783791668,
"narHash": "sha256-zbcZ1dmBTPfJ7Mlqh/yLEPGpgJnwuv4Xr1xucy2WqMA=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "8a1b0127302ea51e05bf4ea5a291743fac442406",
"rev": "716c7a2664ca8325617b8a7fbb609273f2c4cae7",
"type": "github"
},
"original": {
@@ -297,18 +451,34 @@
"type": "github"
}
},
"nixpkgs_5": {
"locked": {
"lastModified": 1786548149,
"narHash": "sha256-pBv1JbhCqqMcF5ciyLi8D9nzVyw4Gv2sk/tcGF4mBHA=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "5df1f9ae934fe1bffbd3867a1ae2870ab22302ed",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable-small",
"repo": "nixpkgs",
"type": "github"
}
},
"nixvim": {
"inputs": {
"flake-utils": "flake-utils",
"flake-utils": "flake-utils_2",
"nixpkgs": "nixpkgs_3",
"nixvim": "nixvim_2"
},
"locked": {
"lastModified": 1779534872,
"narHash": "sha256-5bzlMvP/1vTZljeNNr7uqNnlcatX9yBUuq4aAzIrsnc=",
"lastModified": 1785519995,
"narHash": "sha256-P992i06HHnCxeCZcnPC8etDyMpp/sb8Z389G1oLJxVY=",
"owner": "Superredstone",
"repo": "nixvim",
"rev": "3ff6d04d297aafb25bdd1e520e8f6857408b4090",
"rev": "66335842b406c763591bf323f9fc4844b012a5e7",
"type": "github"
},
"original": {
@@ -319,16 +489,16 @@
},
"nixvim_2": {
"inputs": {
"flake-parts": "flake-parts_2",
"flake-parts": "flake-parts_3",
"nixpkgs": "nixpkgs_4",
"systems": "systems_2"
"systems": "systems_3"
},
"locked": {
"lastModified": 1778906310,
"narHash": "sha256-LqASEJRtLuKRBJd9051T1KMAEaYvsVrc6m64jhD6xbw=",
"lastModified": 1783941741,
"narHash": "sha256-F+3M1IZrJa920cx2/k2AMKqedEodxLF7COJVkLJwUBo=",
"owner": "nix-community",
"repo": "nixvim",
"rev": "06cace835d7ee727852ac789e3dcd42fc2fd360e",
"rev": "e6715f01d9f56f07a27a01386b85ae22b06f0705",
"type": "github"
},
"original": {
@@ -344,22 +514,72 @@
]
},
"locked": {
"lastModified": 1780809674,
"narHash": "sha256-JFbpz7FeJ1pLND4sC2jE6L1oxufaJWM24QUPSofgIbc=",
"lastModified": 1786423020,
"narHash": "sha256-HuA2vXP7rqGoSg89S68w+VAuQpQ3asz5yAhDMyaD4TI=",
"owner": "noctalia-dev",
"repo": "noctalia-shell",
"rev": "3329444884247883597103776645419fb4b46d94",
"repo": "noctalia",
"rev": "352d4762d7a634ad4d2cc639b5f3b7059b01088d",
"type": "github"
},
"original": {
"owner": "noctalia-dev",
"ref": "v5",
"repo": "noctalia-shell",
"repo": "noctalia",
"type": "github"
}
},
"pyproject-build-systems": {
"inputs": {
"nixpkgs": [
"authentik-nix",
"nixpkgs"
],
"pyproject-nix": [
"authentik-nix",
"pyproject-nix"
],
"uv2nix": [
"authentik-nix",
"uv2nix"
]
},
"locked": {
"lastModified": 1785730568,
"narHash": "sha256-NjSPsgjJ7MSpBtTkUcmNhRe6AFZ96+zsca2M8YuQi8Y=",
"owner": "pyproject-nix",
"repo": "build-system-pkgs",
"rev": "90fde00db3687922d39d95fc591475fd0bbbcd72",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "build-system-pkgs",
"type": "github"
}
},
"pyproject-nix": {
"inputs": {
"nixpkgs": [
"authentik-nix",
"nixpkgs"
]
},
"locked": {
"lastModified": 1786031528,
"narHash": "sha256-cROiHKO3UbIKqF5FG5NikvydzlfIj4EcR1Cty9qOVt4=",
"owner": "pyproject-nix",
"repo": "pyproject.nix",
"rev": "1b1485546d85f6f6c7aadb10c4923dbc09633263",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "pyproject.nix",
"type": "github"
}
},
"root": {
"inputs": {
"authentik-nix": "authentik-nix",
"home-manager": "home-manager",
"nix-cachyos-kernel": "nix-cachyos-kernel",
"nixflix": "nixflix",
@@ -368,9 +588,31 @@
"nixpkgs-my-features": "nixpkgs-my-features",
"nixvim": "nixvim",
"noctalia": "noctalia",
"simple-mailserver": "simple-mailserver",
"sops-nix": "sops-nix"
}
},
"simple-mailserver": {
"inputs": {
"blobs": "blobs",
"flake-compat": "flake-compat_3",
"git-hooks": "git-hooks",
"nixpkgs": "nixpkgs_5"
},
"locked": {
"lastModified": 1786567397,
"narHash": "sha256-H713vbgy+n1asVNn/0kBwbFgroNgC1dnx8pEMKcFdgk=",
"owner": "simple-nixos-mailserver",
"repo": "nixos-mailserver",
"rev": "e668474df221aeef1ebd374d0364aa07f1d4f827",
"type": "gitlab"
},
"original": {
"owner": "simple-nixos-mailserver",
"repo": "nixos-mailserver",
"type": "gitlab"
}
},
"sops-nix": {
"inputs": {
"nixpkgs": [
@@ -378,11 +620,11 @@
]
},
"locked": {
"lastModified": 1780547341,
"narHash": "sha256-Gq8KNx5A7hBB3uGJaj6eQfLDIz5YdLu92gqBcvHvoUo=",
"lastModified": 1786375908,
"narHash": "sha256-G7qDAT98nywA4EFmJCwIRO5wKvDlBBN3BWpsOnjAto8=",
"owner": "Mic92",
"repo": "sops-nix",
"rev": "9ed65852b6257fbeae4355bc24ecfea307ca759a",
"rev": "d1337e05ba0a8e88a75d2c0e1595d82f3b3e2ac4",
"type": "github"
},
"original": {
@@ -393,16 +635,16 @@
},
"systems": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"lastModified": 1689347949,
"narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"repo": "default-linux",
"rev": "31732fcf5e8fea42e59c2488ad31a0e651500f68",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"repo": "default-linux",
"type": "github"
}
},
@@ -421,6 +663,22 @@
"type": "github"
}
},
"systems_3": {
"locked": {
"lastModified": 1774449309,
"narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=",
"owner": "nix-systems",
"repo": "default",
"rev": "c29398b59d2048c4ab79345812849c9bd15e9150",
"type": "github"
},
"original": {
"owner": "nix-systems",
"ref": "future-26.11",
"repo": "default",
"type": "github"
}
},
"treefmt-nix": {
"inputs": {
"nixpkgs": [
@@ -429,11 +687,11 @@
]
},
"locked": {
"lastModified": 1780220602,
"narHash": "sha256-eynAfOmbmxJnkp7YewvCEbShNnnYJ9gLLqkzsYtBPeM=",
"lastModified": 1785945821,
"narHash": "sha256-NLSyTCW4K4ofhNBllt3omPasm6QpralXH1DBZOc91Dw=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "db947814a175b7ca6ded66e21383d938df01c227",
"rev": "ae7910970dddc408fe6ab1c8e4b277bb21d72dc0",
"type": "github"
},
"original": {
@@ -442,13 +700,38 @@
"type": "github"
}
},
"uv2nix": {
"inputs": {
"nixpkgs": [
"authentik-nix",
"nixpkgs"
],
"pyproject-nix": [
"authentik-nix",
"pyproject-nix"
]
},
"locked": {
"lastModified": 1786026603,
"narHash": "sha256-payw8w/aqR/Vr7LvDp14jxa5egFrZN7g8INsPzn7rN0=",
"owner": "pyproject-nix",
"repo": "uv2nix",
"rev": "0dfa8388dc855b1774f509725d8ea6806291571d",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "uv2nix",
"type": "github"
}
},
"vpn-confinement": {
"locked": {
"lastModified": 1778182451,
"narHash": "sha256-Bz3n2THDGf90Z9gMqhH/J492prYH8B6RFRlxv/fPBwc=",
"lastModified": 1785142579,
"narHash": "sha256-WEPxDMiKt3uGVVu/aorHnIgYYW62mEq2Q+rlN3qH6bg=",
"owner": "Maroka-chan",
"repo": "VPN-Confinement",
"rev": "cf5bfc4c3559f2e783698b1aa23c165072039a7d",
"rev": "b3aa71a7edfe6af748c23729d1bdec3b499741ff",
"type": "github"
},
"original": {
+12 -2
View File
@@ -3,6 +3,8 @@
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
nixpkgs-25-11.url = "github:nixos/nixpkgs/nixos-25.11";
nixpkgs-my-features.url = "github:Superredstone/nixpkgs/my-features";
nix-cachyos-kernel.url = "github:xddxdd/nix-cachyos-kernel/release";
simple-mailserver.url = "gitlab:simple-nixos-mailserver/nixos-mailserver";
home-manager = {
url = "github:nix-community/home-manager";
inputs.nixpkgs.follows = "nixpkgs";
@@ -16,14 +18,17 @@
inputs.nixpkgs.follows = "nixpkgs";
};
noctalia = {
url = "github:noctalia-dev/noctalia-shell/v5";
url = "github:noctalia-dev/noctalia";
inputs.nixpkgs.follows = "nixpkgs";
};
nixflix = {
url = "github:kiriwalawren/nixflix";
inputs.nixpkgs.follows = "nixpkgs";
};
nix-cachyos-kernel.url = "github:xddxdd/nix-cachyos-kernel/release";
authentik-nix = {
url = "github:nix-community/authentik-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs =
@@ -37,6 +42,8 @@
nix-cachyos-kernel,
noctalia,
nixflix,
authentik-nix,
simple-mailserver,
...
}@inputs:
let
@@ -51,6 +58,7 @@
nixvim
sops-nix
noctalia
simple-mailserver
inputs
nixpkgs
nixpkgs-25-11
@@ -87,6 +95,8 @@
enableZram = true;
additionalModules = [
nixflix.nixosModules.default
authentik-nix.nixosModules.default
simple-mailserver.nixosModules.default
];
};
nixosConfigurations."frog" = mkSystem "frog" {
-4
View File
@@ -16,10 +16,6 @@
enable = true;
colorScheme = "dark";
gtk4.theme = null;
iconTheme = {
name = "Papirus";
package = pkgs.papirus-icon-theme;
};
cursorTheme = {
name = "Bibata-Modern-Classic";
package = pkgs.bibata-cursors;
+1 -1
View File
@@ -3,7 +3,7 @@
programs.mangohud = {
enable = gamingSystem;
settings = {
fps_limit = 75;
fps_limit = 180;
};
};
}
+2 -9
View File
@@ -14,8 +14,8 @@
colorScheme = "dark";
gtk4.theme = null;
iconTheme = {
name = "Papirus";
package = pkgs.papirus-icon-theme;
name = "Adwaita";
package = pkgs.adwaita-icon-theme;
};
cursorTheme = {
name = "Bibata-Modern-Classic";
@@ -23,13 +23,6 @@
};
};
qt = {
enable = true;
style = {
name = "adwaita-dark";
};
};
home.file = {
# Fix for steam cursor
".local/share/icons/default" = {
+2
View File
@@ -4,6 +4,7 @@
nixvim,
sops-nix,
noctalia,
simple-mailserver,
inputs,
nixpkgs,
nixpkgs-25-11,
@@ -32,6 +33,7 @@ let
workSystem
enableZram
nixvim
simple-mailserver
sops-nix
noctalia
inputs
+3
View File
@@ -8,15 +8,18 @@
allowedTCPPorts = [
22
25
53
80
143
443
465
587
993
25565
27015
];
allowedUDPPorts = [
53
80
443
34197
+8 -8
View File
@@ -1,4 +1,4 @@
{ config, ... }:
{ ... }:
{
sops =
let
@@ -17,17 +17,17 @@
qbittorrent_password = default;
radarr_api_key = default;
sonarr_api_key = default;
lidarr_api_key = default;
prowlarr_api_key = default;
seerr_api_key = default;
indexers_ilcorsaroblu_password = default;
gitea_registration_token = default;
};
templates = {
"gitea_runner.env".content = ''
GITEA_INSTANCE_URL=${config.services.gitea.settings.server.ROOT_URL}
GITEA_RUNNER_NAME="Runner"
GITEA_RUNNER_REGISTRATION_TOKEN=${config.sops.placeholder.gitea_registration_token}
'';
navidrome_env = default;
yamtrack_env = default;
authentik_env = default;
vaultwarden_env = default;
vikunja_env = default;
mail_password = default;
};
};
}
+9
View File
@@ -0,0 +1,9 @@
{ ... }:
{
services.actual = {
enable = true;
settings = {
port = 8015;
};
};
}
+18
View File
@@ -0,0 +1,18 @@
{ ... }:
{
services.adguardhome = {
enable = true;
port = 8017;
mutableSettings = true;
settings = {
dns = {
upstream_dns = [
"1.1.1.1"
"9.9.9.9"
];
bind_hosts = [ "192.168.1.223" ];
port = 53;
};
};
};
}
+11
View File
@@ -0,0 +1,11 @@
{ config, ... }:
{
services.authentik = {
enable = true;
environmentFile = config.sops.secrets.authentik_env.path;
settings = {
disable_startup_analytics = true;
avatars = "initials";
};
};
}
+34 -32
View File
@@ -1,15 +1,17 @@
{
pkgs,
config,
currentSystemUser,
...
}:
{
services.caddy =
let
basicAuth = ''
basicauth {
${currentSystemUser} $2a$14$L6SBwu.0FhGBYwH2LWa6uOrBSeRHo8Lo95Vkle/g5uB7kZl7nmJPO
authentikAuth = ''
reverse_proxy /outpost.goauthentik.io/* http://127.0.0.1:9000
forward_auth http://127.0.0.1:9000 {
uri /outpost.goauthentik.io/auth/caddy
copy_headers X-Authentik-Username X-Authentik-Groups X-Authentik-Entitlements X-Authentik-Email X-Authentik-Name X-Authentik-Uid X-Authentik-Jwt X-Authentik-Meta-Jwks X-Authentik-Meta-Outpost X-Authentik-Meta-Provider X-Authentik-Meta-App X-Authentik-Meta-Version
trusted_proxies private_ranges
}
'';
in
@@ -20,21 +22,13 @@
root /var/www/patrickcanal.it/public
file_server
'';
"novnc.patrickcanal.it".extraConfig = ''
handle {
${basicAuth}
root ${pkgs.novnc}/share/webapps/novnc
file_server browse
}
handle /websockify {
${basicAuth}
reverse_proxy 127.0.0.1:6080
}
"mail.patrickcanal.it".extraConfig = ''
root /var/www/patrickcanal.it/public
file_server
'';
"vaultwarden.patrickcanal.it".extraConfig = ''
encode zstd gzip
reverse_proxy :${toString config.services.vaultwarden.config.ROCKET_PORT} {
reverse_proxy :8003 {
header_up X-Real-IP {remote_host}
}
'';
@@ -54,6 +48,7 @@
reverse_proxy :${toString config.nixflix.jellyfin.network.internalHttpPort}
'';
"qbittorrent.patrickcanal.it".extraConfig = ''
${authentikAuth}
reverse_proxy :${toString config.nixflix.downloadarr.qbittorrent.port}
'';
"radarr.patrickcanal.it".extraConfig = ''
@@ -62,27 +57,34 @@
"sonarr.patrickcanal.it".extraConfig = ''
reverse_proxy :${toString config.nixflix.sonarr.settings.server.port}
'';
"lidarr.patrickcanal.it".extraConfig = ''
reverse_proxy :${toString config.nixflix.lidarr.settings.server.port}
'';
"prowlarr.patrickcanal.it".extraConfig = ''
reverse_proxy :${toString config.nixflix.prowlarr.settings.server.port}
'';
"seerr.patrickcanal.it".extraConfig = ''
reverse_proxy :${toString config.nixflix.seerr.port}
'';
"navidrome.patrickcanal.it".extraConfig = ''
reverse_proxy :${toString config.services.navidrome.settings.Port}
'';
"yamtrack.patrickcanal.it".extraConfig = ''
reverse_proxy :8014
'';
"actual.patrickcanal.it".extraConfig = ''
reverse_proxy :${toString config.services.actual.settings.port}
'';
"inventory.patrickcanal.it".extraConfig = ''
reverse_proxy :${toString config.services.homebox.settings.HBOX_WEB_PORT}
'';
"adguard.patrickcanal.it".extraConfig = ''
${authentikAuth}
reverse_proxy :${toString config.services.adguardhome.port}
'';
"auth.patrickcanal.it".extraConfig = ''
reverse_proxy :9000
'';
};
};
systemd.services.websockify = {
description = "Websockify for noVNC";
after = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
serviceConfig = {
Restart = "always";
DynamicUser = true;
ExecStart = ''
${pkgs.python3Packages.websockify}/bin/websockify \
--web ${pkgs.novnc}/share/webapps/novnc \
6080 127.0.0.1:5900
'';
};
};
}
+8
View File
@@ -1,14 +1,22 @@
{ ... }:
{
imports = [
./actual.nix
./adguard.nix
./authentik.nix
./caddy.nix
./fail2ban.nix
./gitea.nix
./homebox.nix
./mail.nix
./navidrome.nix
./nextcloud.nix
./nixflix.nix
./octoprint.nix
./teamspeak.nix
./vaultwarden.nix
./vikunja.nix
./yamtrack.nix
];
services.openssh.enable = true;
+13
View File
@@ -0,0 +1,13 @@
{ ... }:
{
services.fail2ban = {
enable = true;
ignoreIP = [ "192.168.1.0/24" ];
bantime = "4h";
bantime-increment = {
enable = true;
multipliers = "1 2 4 8 16 32 64";
overalljails = true;
};
};
}
-10
View File
@@ -11,14 +11,4 @@
service.DISABLE_REGISTRATION = true;
};
};
config.virtualisation.oci-containers.containers.gitea-act-runner = {
image = "docker.io/gitea/act_runner:latest";
environmentFiles = [
config.sops.templates."gitea_runner.env".path
];
volumes = [
"/var/run/docker.sock:/var/run/docker.sock"
];
};
}
+10
View File
@@ -0,0 +1,10 @@
{ ... }:
{
services.homebox = {
enable = true;
settings = {
HBOX_WEB_PORT = "8016";
HBOX_OPTIONS_ALLOW_REGISTRATION = "false";
};
};
}
+36
View File
@@ -0,0 +1,36 @@
{ config, ... }:
let
fqdn = "mail.patrickcanal.it";
in
{
security.acme = {
acceptTerms = true;
certs."mail.patrickcanal.it" = {
webroot = "/var/www/patrickcanal.it/public/";
};
};
mailserver = {
enable = true;
stateVersion = 5;
fqdn = fqdn;
domains = [ "patrickcanal.it" ];
# Reference the existing ACME configuration created by nginx
x509.useACMEHost = fqdn;
# A list of all login accounts. To create the password hashes, use
# nix-shell -p mkpasswd --run 'mkpasswd -s'
accounts = {
"me@patrickcanal.it" = {
hashedPassword = "$y$j9T$zEKbsELY3HcPZq9CH6bSe0$T9syGTl9haNhjS5SNjDbrY5uoN5z/LCYEmbFowFcAP/";
# Additional addresses delivered to this mailbox
aliases = [
"postmaster@patrickcanal.it"
"io@patrickcanal.it"
];
};
};
};
}
+15
View File
@@ -0,0 +1,15 @@
{ config, ... }:
{
services.navidrome = {
enable = true;
environmentFile = config.sops.secrets.navidrome_env.path;
settings = {
Port = 8013;
MusicFolder = "/var/lib/nixflix/media/music/";
EnableSharing = true;
ArtistArtPriority = "external, artist.*, album/artist.*";
CoverArtPriority = "external, cover.*, folder.*, front.*, embedded";
DiscArtPriority = "disc*.*, cd*.*, cover.*, folder.*, front.*, discsubtitle, embedded";
};
};
}
+1 -1
View File
@@ -8,7 +8,7 @@
services = {
nextcloud = {
enable = true;
package = pkgs.nextcloud33;
package = pkgs.nextcloud34;
hostName = "nextcloud.patrickcanal.it";
https = false;
config = {
+37
View File
@@ -11,6 +11,7 @@ let
prowlarrPort = 8008;
seerrPort = 8009;
sonarrPort = 8010;
lidarrPort = 8012;
hostConfig = {
username = user;
password._secret = config.sops.secrets.nixflix_password.path;
@@ -38,10 +39,18 @@ in
MaxAuthenticationFailCount = 0;
Username = user;
Password_PBKDF2 = "@ByteArray(8AhaCcVLo4H07+dv5uF7pQ==:m+wRuZuzus0N5mkOGXePQmDZfgTpRZiv2OSKbk1pnOA/QPa/JF4Ai1FwVbyZ1PF9odSOSI1UaRQwDMb3MxOKMg==)";
LocalHostAuth = false; # Disable auth because authentik is setup
};
};
};
recyclarr = {
enable = true;
radarrQuality = "1080p";
sonarrQuality = "1080p";
cleanupUnmanagedProfiles.enable = true;
};
radarr = {
enable = true;
settings.server.port = radarrPort;
@@ -64,6 +73,16 @@ in
};
};
lidarr = {
enable = true;
config = {
apiKey._secret = config.sops.secrets.lidarr_api_key.path;
hostConfig = hostConfig // {
port = lidarrPort;
};
};
};
prowlarr = {
enable = true;
settings.server.port = prowlarrPort;
@@ -78,6 +97,12 @@ in
username = "Petrich";
password._secret = config.sops.secrets.indexers_ilcorsaroblu_password.path;
}
{
name = "LimeTorrents";
}
{
name = "The Pirate Bay";
}
];
};
};
@@ -91,6 +116,11 @@ in
jellyfin = {
enable = true;
apiKey._secret = config.sops.secrets.jellyfin_api_key.path;
branding.loginDisclaimer = ''
<a href="/sso/OIDC/Start/authentik">
Sign in with Authentik
</a>
'';
network = {
knownProxies = [ "127.0.0.1" ];
internalHttpPort = jellyfinPort;
@@ -115,6 +145,13 @@ in
"${mediaDir}/tv"
];
};
Music = {
collectionType = "music";
paths = [
"${mediaDir}/music"
];
};
};
};
};
+21 -6
View File
@@ -1,11 +1,26 @@
{ ... }:
{ config, ... }:
{
services.vaultwarden = {
enable = true;
config = {
DOMAIN = "https://vaultwarden.patrickcanal.it";
ROCKET_ADDRESS = "127.0.0.1";
ROCKET_PORT = 8003;
};
environmentFile = config.sops.secrets.vaultwarden_env.path;
# config = {
# DOMAIN = "https://vaultwarden.patrickcanal.it";
# ROCKET_ADDRESS = "127.0.0.1";
# ROCKET_PORT = 8003;
# SSO_ENABLED = true;
# SSO_ONLY = false;
# SSO_AUTHORITY = "https://auth.patrickcanal.it";
# SSO_SCOPES = [
# "profile"
# "email"
# "offline_access"
# "vaultwarden"
# ];
# SSO_PKCE = true;
# SSO_CLIENT_ID = "vaultwarden";
# SSO_CLIENT_SECRET = config.sops.secrets.vaultwarden_sso_secret;
# SSO_ROLES_ENABLED = true;
# SSO_ROLES_DEFAULT_TO_USER = true;
# };
};
}
+4 -1
View File
@@ -1,9 +1,12 @@
{ ... }:
{ config, ... }:
{
services.vikunja = {
enable = true;
port = 8011;
frontendScheme = "http";
frontendHostname = "vikunja.patrickcanal.it";
environmentFiles = [
config.sops.secrets.vikunja_env.path
];
};
}
+121
View File
@@ -0,0 +1,121 @@
# Temporary solution until https://github.com/NixOS/nixpkgs/pull/501051 gets merged
# TODO: Once merged change also caddy.nix accordingly
# Auto-generated by compose2nix.
{ pkgs, lib, config, ... }:
{
# Enable container name DNS for all Podman networks.
networking.firewall.interfaces = let
matchAll = if !config.networking.nftables.enable then "podman+" else "podman*";
in {
"${matchAll}".allowedUDPPorts = [ 53 ];
};
virtualisation.oci-containers.backend = "podman";
# Containers
virtualisation.oci-containers.containers."yamtrack" = {
image = "ghcr.io/fuzzygrim/yamtrack";
environmentFiles = [ config.sops.secrets.yamtrack_env.path ];
volumes = [
"/var/lib/yamtrack:/yamtrack/db:rw"
];
ports = [
"8014:8000/tcp"
];
dependsOn = [
"yamtrack_redis"
];
log-driver = "journald";
extraOptions = [
"--network-alias=yamtrack"
"--network=yamtrack_default"
];
};
systemd.services."podman-yamtrack" = {
serviceConfig = {
Restart = lib.mkOverride 90 "always";
};
after = [
"podman-network-yamtrack_default.service"
];
requires = [
"podman-network-yamtrack_default.service"
];
partOf = [
"podman-compose-yamtrack-root.target"
];
wantedBy = [
"podman-compose-yamtrack-root.target"
];
};
virtualisation.oci-containers.containers."yamtrack_redis" = {
image = "redis:8-alpine";
volumes = [
"yamtrack_redis_data:/data:rw"
];
log-driver = "journald";
extraOptions = [
"--network-alias=yamtrack_redis"
"--network=yamtrack_default"
];
};
systemd.services."podman-yamtrack_redis" = {
serviceConfig = {
Restart = lib.mkOverride 90 "always";
};
after = [
"podman-network-yamtrack_default.service"
"podman-volume-yamtrack_redis_data.service"
];
requires = [
"podman-network-yamtrack_default.service"
"podman-volume-yamtrack_redis_data.service"
];
partOf = [
"podman-compose-yamtrack-root.target"
];
wantedBy = [
"podman-compose-yamtrack-root.target"
];
};
# Networks
systemd.services."podman-network-yamtrack_default" = {
path = [ pkgs.podman ];
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
ExecStop = "podman network rm -f yamtrack_default";
};
script = ''
podman network inspect yamtrack_default || podman network create yamtrack_default
'';
partOf = [ "podman-compose-yamtrack-root.target" ];
wantedBy = [ "podman-compose-yamtrack-root.target" ];
};
# Volumes
systemd.services."podman-volume-yamtrack_redis_data" = {
path = [ pkgs.podman ];
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
};
script = ''
podman volume inspect yamtrack_redis_data || podman volume create yamtrack_redis_data
'';
partOf = [ "podman-compose-yamtrack-root.target" ];
wantedBy = [ "podman-compose-yamtrack-root.target" ];
};
# Root service
# When started, this will automatically create all resources and start
# the containers. When stopped, this will teardown all resources.
systemd.targets."podman-compose-yamtrack-root" = {
unitConfig = {
Description = "Root target generated by compose2nix.";
};
wantedBy = [ "multi-user.target" ];
};
}
+6 -1
View File
@@ -1,11 +1,16 @@
{ pkgs, ... }:
{
virtualisation = {
docker.enable = true;
spiceUSBRedirection.enable = true;
libvirtd = {
enable = true;
package = pkgs.qemu_kvm;
};
podman = {
enable = true;
autoPrune.enable = true;
dockerCompat = true;
};
};
environment.systemPackages = with pkgs; [ podman-compose ];
}
+2 -1
View File
@@ -10,7 +10,8 @@
verbose = false;
systemd.enable = true;
};
kernelPackages = pkgs.cachyosKernels.linuxPackages-cachyos-latest; # pkgs.linuxPackages_latest;
# Do not remove cachy kernel, it fixes nvidia kernel panic on shutdown
kernelPackages = pkgs.cachyosKernels.linuxPackages-cachyos-lts-lto-x86_64-v3;
consoleLogLevel = 3;
kernelParams = [
"quiet"
+4 -4
View File
@@ -3,17 +3,17 @@
nix.settings = {
substituters = [
"https://cache.nixos.org"
"https://cache.garnix.io"
"https://nixvim-superredstone.cachix.org"
"https://attic.xuyh0120.win/lantian"
"https://noctalia.cachix.org"
"https://attic.xuyh0120.win/lantian"
"https://nix-community.cachix.org"
];
trusted-public-keys = [
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"cache.garnix.io:CTFPyKSLcx5RMJKfLo5EEPUObbA78b0YQ2DTCJXqr9g="
"nixvim-superredstone.cachix.org-1:mEXHVxEv5dKka3FOxTMFDfdk/DJ0baydsahi+zZIcQE="
"lantian:EeAUQ+W+6r7EtwnmYjeVwx5kOGEBpjlBfPlzGlTNvHc="
"noctalia.cachix.org-1:pCOR47nnMEo5thcxNDtzWpOxNFQsBRglJzxWPp3dkU4="
"lantian:EeAUQ+W+6r7EtwnmYjeVwx5kOGEBpjlBfPlzGlTNvHc="
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
];
trusted-users = [
"root"
+3
View File
@@ -59,6 +59,9 @@
};
fonts.packages = with pkgs; [
vista-fonts
monocraft
miracode
nerd-fonts.jetbrains-mono
noto-fonts
];
+8 -7
View File
@@ -27,6 +27,7 @@
btop
bun
busybox
devenv
dig
distrobox
docker
@@ -72,27 +73,29 @@
];
guiPackages = lib.optionals (currentSystemDe != "none") [
android-studio
baobab
bazaar
discord
brave
cinny-desktop
firefox
fladder
gapless
gimp
mpv
nautilus
nextcloud-client
obs-studio
ollama
onlyoffice-desktopeditors
piper
qbittorrent
rustdesk
seahorse
spotiflac
telegram-desktop
thunderbird
tor-browser
vesktop
vlc
vulkan-tools
libreoffice
];
gamingPackages = lib.optionals gamingSystem [
@@ -102,12 +105,10 @@
obs-studio
openrgb
prismlauncher
protonplus
satisfactorymodmanager
];
workPackages = lib.optionals workSystem [
android-studio
ansible
virt-manager
];
+4
View File
@@ -22,6 +22,7 @@
{
enable = true;
remotePlay.openFirewall = true;
extraCompatPackages = with pkgs; [ proton-ge-bin ];
}
else
{ };
@@ -33,5 +34,8 @@
nh = {
enable = true;
};
bash.shellAliases = {
dev = "nix develop --command 'fish'";
};
};
}
+4 -4
View File
@@ -38,17 +38,17 @@
enable = true;
xdgOpenUsePortal = true;
extraPortals = lib.mkForce [
pkgs.xdg-desktop-portal-wlr
pkgs.xdg-desktop-portal-gnome
pkgs.xdg-desktop-portal-gtk
];
config = {
niri = {
default = lib.mkForce [
"gnome"
"gtk"
"wlr"
];
"org.freedesktop.impl.portal.ScreenCast" = [ "wlr" ];
"org.freedesktop.impl.portal.Screenshot" = [ "wlr" ];
"org.freedesktop.impl.portal.ScreenCast" = [ "gnome" ];
"org.freedesktop.impl.portal.Screenshot" = [ "gnome" ];
};
};
};
+10 -3
View File
@@ -5,10 +5,17 @@ qbittorrent_api_key: ENC[AES256_GCM,data:EJmLZr15745Fcwu6zO1GJ68ptrZjS3NgG2BTNC0
qbittorrent_password: ENC[AES256_GCM,data:qZNlHLMcihmfaP8t6Bd0vbt89A5nzgukJ0lO+n52R9lldNQiHKNCNI2LpitIsHGfjNMiluuo5r4fTwVjJsA1zA==,iv:InCWhFfWkmMo1R0wGNx7n09Wpq2RW1TYtuaQWJknkvM=,tag:Qp59jzDWEjD/s04DUV9u8A==,type:str]
radarr_api_key: ENC[AES256_GCM,data:NxYoYFffrPFmI3cmtgi+qRBzH15imO3knq00GWcY+uJSvBL0hOs1Zem+n7Ij7L5V7PbZfWVnnuRJvjy2BnRzYA==,iv:+b5jm/Z8wHf3CidKV1L5a3vlSJvsi+eWhBBO6J48/8o=,tag:RiA0/dbcftCp79YqEwu7yA==,type:str]
sonarr_api_key: ENC[AES256_GCM,data:nm9lcY9/3aMce7MIEK9E+su9o0f7RdOafx52a8vgG8hxiv4J6bktiK8EAfLIr0ae8Yi17gDiHtRgPw/9EUOdCw==,iv:elRPggP64PdaV1j6fCyZSilgwi41cmG9rDpXVKcX0PY=,tag:o0ZdHxh1NaJSfW7iNlV9eg==,type:str]
lidarr_api_key: ENC[AES256_GCM,data:VDV3oJTjR5Tbf6bJeR9JgUr3ZjNIsAYEH7WqWGhUHU6WFa1Rld+jSNm4WKZMSN/+7sdQU9nPDHem9/i5lfVbIQ==,iv:z1nJosq9bJ1tXB3CQO2QTBssF/ZFCm3W/y4OTUs0SpM=,tag:tZ5FKkLnC5svLYxolZmtvw==,type:str]
prowlarr_api_key: ENC[AES256_GCM,data:UDpnqIP64k8Qt9k/sjbESNostFiGHfLo3CEYfyWppHEwfkjVu1oirdtzDgAO056rxWaLwwcqJs0jDFau5VZi8Q==,iv:N9d9Sdbo/akFecQRYfbrkigq2Za3CXzsRJvNljm1MQM=,tag:Et1kIBHPX4bLlCgqpZf4CA==,type:str]
seerr_api_key: ENC[AES256_GCM,data:KDQxxo2W4tz9UokscAUSz7pf7wY2AfsEQpZh2aXGjsQOBgSLt1DEe5LUxealBZju8gabhp4sNGFvp0+ioZpfkg==,iv:V/rbR6bZtVnDhLLVmygGyTf5Ujm8sb2xHy4JuvLiiV8=,tag:MxGzXHbZWgu3H+ICS2tSNQ==,type:str]
indexers_ilcorsaroblu_password: ENC[AES256_GCM,data:w3CIGQqLxHEkUHvscZc=,iv:fjsB3zt4Z43MKRECjpa7+gNDzM8D+JK0sbKt2P+Hdiw=,tag:KvLawon+KfrhGmi1TWRHLw==,type:str]
gitea_registration_token: ENC[AES256_GCM,data:aHoUBwPXtlme9RgGObwWt1V90JU5qeVBUtpINrb1hY6XjKi4+kLxAg==,iv:zkgDdx82Lku7/oNIoSoKUIrxvZuyPaGUI411V/rkW9c=,tag:0eBC0Kd71UwokH9scs/AKA==,type:str]
mail_password: ENC[AES256_GCM,data:fznlr+Mzu+cpHsLN8EYx6g==,iv:s/DidEGNar4jGHGcbXsysZ2grpwVO1T2Zd+jksb90T8=,tag:LgJ7r+stG7QCpX9n/UZUsA==,type:str]
navidrome_env: ENC[AES256_GCM,data:SjEg735zoiWNjp0+uYi5CyLadDd7mSXpG1LInLsaqESz0LNgMi+r46ohPjpEC3GD+WbE9D3XRwhB22oIey3K7p3GdB/bYjIR6wOa8MVjj3EDvzdBWbnhkXsGnIhLGuyZwDmMdA==,iv:gHv7lZzU09V3XVjs3nEOEm55xRwD23+sVWfgbuX18p4=,tag:8UAMIGXPGobQfBAao2nI6Q==,type:str]
yamtrack_env: ENC[AES256_GCM,data:fUaM7prLhu7aJQbWimzjPWmSD7SiCFTiXaWz4Ep34EadofCXvrBKnUa8ZDOSX9mw1PUAdqbao8l1TbA6LieV1ywW4VqC7+fUyJsfOhjRqtg+ud286UilIrMTcU/bodcKxbzxIjG9HMJ4HVs+hNnrVm4SUaloueXZm6pT0iB4Pm3ygXb/NjyBR5PdGc3MiJ0kJ4OvrLzMXYipdFTVqGvgiKazQm37ug3JFw+UjpRanYLlGT+q/aC0Km+UK41CQjvB06N8jwfd3vFWIxKHtWTfMaiJAarwSh6320lQWj5bIkbK5p4TXgqy+UgBqwEt6eWDbeZ5L46covfUi2ZUCDMBYSslFK5cYqaOvfRb0VO1nb+06djBi1WvuVR4i6PkNpyb5PGZa9f2cZB8yqXaUGNJQaut+nu7G8t8YWFlTP78fXAHOyd4kfCFot68LYJ1Vjo08v6SnUuF8JA+tmBOddBPpyO15IP5Ln7mEfinAhYRI7MACO/uOcfRX4ydcyHdELwKwM1hY69c8Ph2++1pkzJOtnSco1iJD07JreMTlOSyT7Y5Q96jR6OZdbPQ0KgoCQNjeRfoQlo2cRBwrCyvNb/Ajy2eW8JgRnY/U+SV+JkmjqrUh740sNbD0CNfFCOvvyIn9pSqQBkezfrqDKUznF6jMMATTdG75XMynbvS3RKfv/pd6ZR+m0DMFuWvvmL5cfjYsAe+M46TtfpHipCB+rxt27gn8+WN3o1cIm5OCsWK3bY51+pFFNr8P/S2kXPyRmq7B7GjLxfMBBYpERSPgzy1vTdpx+n1bREoFPll2d3KWSceVd+2izdj2S14ONPP/Ov4ImpIQQche1/Avaem6A/Go+y8Lpmnjp8/9ATwz3/b3RkbupX0bQy6y4gDg/V5bByaTpmb8Uh8,iv:rHGqUoLl6iJ1+LDHSuDFuIsl/YLlb75lUwl8gaxV79c=,tag:GVet48AfHBX5IXa/u1wXFA==,type:str]
authentik_env: ENC[AES256_GCM,data:kAva3C4pWZ4+BFhGbbq9j1rSXeldb+NAwU16aZUD7wiw8k7Sg0kVq/43rj1HtR2ZTQY6DxhPlsK5I7opVAg953GwN0kTErpuhKLRWaRGSb8rC8kkxnY=,iv:X61qSjH18KQRWNOtYq1o8IZmY6Dz4TrJzehJWxE7b2o=,tag:mifmD1C3A+XSQveLviLt2w==,type:str]
vaultwarden_env: ENC[AES256_GCM,data:vlwywspQDMrevce4dMgJTAbV4Fv9l8COK/k3ZMCZN4w0oIm4rQ3RfFzbagnG7oY9GRrqQNKM3gyRtxZ/5tPHHyiSNDDJ9lRBZ2g6w+VcVAmPyJaI736LOWZNwaYsK8yymfOWJuE8nZy5z07L/YjM+oQf0t6aqGIrHrwD4mB8GLIUhaDDNtB7xAJaDVtGCOKPseQGBwEXzs9S6hOKOUb/YeWXj290qDd9jVLSsBRZt8/ePxKMKnqSCekhrrlnGKGUitQBlHJgtUWd6wUtzR5DdTmh5Dn32JaAri51vlI+UuN6DOHxhh03rKsF5nTGXr1oclNMCrpk+uCOQZfjJ1U6jdz+vLxxuwocz3KRW2vi/v/MC2uutAu8KEskdcLBk+k6hnHse2WQ9HfePvY9hPcVMnnp1OaDLmJ3UnJsSuj+fTT/iGVyiDC+UpZ7XdF47VwohnYHbmsq30ruSxS05irhFqQ6Yla938V+l3ASSzAh7DNXmpGzYiit0evyt2wm+an29ulaU6oIaoh9etpvLK1I4WC9WjTG24Cq/4/S9d+Kzp6GaUxX7zOa9wANEAvPDHwUjreH/iIqbrIrbYBIdWLZacPWVj60JMP6ioaz8HfIsKel3q+pAfuZZbKJobSPOut/7jhz0RtLK9BN5zKv1UcAYRgcBF1Wy8d7eB5/k8IjDF6StfgJ+l5nEflrTx48ZouveMarincrj/i7PFmK2y5Ss31Xc3fvafPenxE8zT4CNaSu5RsUYQCIqAFcQfqdJSSu7S8OjQmzKGEwgFOhkG4mMqtPacvyNl2rDmgYcj8vbIkX5uC6wWejOJlqfDZwKIbnevBYaaoDLZWmzpqn47vBI4kveGLqhp2EqHH/yqAhz5Q=,iv:ziOAFuLGSngOmS9cOr8LE+Qf0Wh6CSCmWNHWFahpMUk=,tag:Ssm/6hC6A3t90502qo4zng==,type:str]
vikunja_env: ENC[AES256_GCM,data:dFh7Ev1HWL6AdjU3ZrWa7SzZicBRXdqUn53Mrguqh/EN/HrUHgk0pIa/SCM9kpt/xgEUkhDuxfMYWAXcJ8jX8yRgytN3ItF6aiivrV98lijGQR1rcAO7MR9T56Qp/FjXNEpleMJ6iv01JrpKTIFN47dC7Hal/AYrlXLqIyFG8uoje3b4xkTsNJeK+NfY4gNwddN454yNwADkJK+8QklM0Z73iGkVedPpOAi71JjsUIboJHGHUghxNIqalnTSZMs2jpI1HtPBAYdF/8WTwFGL7tAVwGUhctdQj+3LMuLBF5Z75ZDLJEbc16jf4ssfpnjAWQArb1oRsX5TCgceY7Qs5eso+hD1alWPVV0w/YygVTpWsSyBG0mN4Mm5r4mM7jW+B8y6aaQhtDb58laEZ1wDS1G+Fbnd/Y+ECJamKz8zi7xT0Qlh54hodFe4cXulOnt3/DQX8jPTttWawswBIq69k/j04T2oxpV33mR6MLrWvAU9vJKy+aYds0tbQS/j3DkeHtVo2Fsd6v5PHS/z8dP+vh1WYaFPg1NpYIQxr8ue0fB/S3Spme2EaiU9zdm6z0FYN1OJJlnQlt4YRbeUJMfCo+RoYkpR6VALtapKn40tXPiA22wCz5p3ErWblt0ZzOyWYkE3Q4d3DNhXUCbpnYw9WkS+GHYCXczfCc746+0tLpYTj3ncwtukblFjNY1glKJ7YV0v9fmDdm/zdfxrfZexTAeb8YSbKbCd5qxPyIzpwroLrwFleKmvBQ==,iv:y1XVaZV2Zt8d90CDoZXX5dAL3SBIZwTPNcopyGEr5SM=,tag:G+Yz18GWtyKRsXZsHWF5mg==,type:str]
sops:
age:
- enc: |
@@ -20,7 +27,7 @@ sops:
ZQ17gIIOjhKHlGx8Lo5t/PekzFyQKCKdijS7caq74dVib1vO3tk+uQ==
-----END AGE ENCRYPTED FILE-----
recipient: age1ynu6zhhy84rr5xqce0flp25x5tnfgskesxfe39u7ewsk900fvagq9sq0lx
lastmodified: "2026-05-28T09:37:32Z"
mac: ENC[AES256_GCM,data:NNYUj3P5mdw+zS7DLmMVwUOAP1Vz/GTYFLAZWP6pR1Y9+g9/R4mTo2Cb/piMb0Wqopifo4a2VeMPSwkgz2+yGKajqU+LsgCFQRCeWurJxo1NTZTW3jabWYY4aw20piIQAWaOwfpy4pC2uukwS48Wat0vbL+l4hgBRNUUymfukDU=,iv:If1h3b0WVEPwh7mrU/VKqnXG7Yz0wXnXxdiBwiNaYIs=,tag:LojwaxKBLUu40TrDROapnQ==,type:str]
lastmodified: "2026-08-16T15:41:59Z"
mac: ENC[AES256_GCM,data:JCmj1SmD62xYMckWkfereDLbWg5NnEGO53diijpFNtsJbHQqnoCRIekQNq53FOpHBUadl7Qjz2snjsd0a5NzFaV5jP4WXqFKpSuFE4BK16Xj15v/HSUSwYc0APKCMwFeX7Oeu39iQNgsQ/quOQy8LRQcX8ck99NCVBPV8xeqfIo=,iv:FGk3Y/GuFNPCZ4L04+ygvM+2LJQvn3f7uRvArhpbQ14=,tag:UTU2Fjj2gJl7Og2r45+jwQ==,type:str]
unencrypted_suffix: _unencrypted
version: 3.13.1
version: 3.13.3