summaryrefslogtreecommitdiff
path: root/microvms
diff options
context:
space:
mode:
Diffstat (limited to 'microvms')
-rw-r--r--microvms/auth/default.nix78
-rw-r--r--microvms/auth/keycloak.nix18
-rw-r--r--microvms/radicale/default.nix74
3 files changed, 0 insertions, 170 deletions
diff --git a/microvms/auth/default.nix b/microvms/auth/default.nix
deleted file mode 100644
index b4c23f1..0000000
--- a/microvms/auth/default.nix
+++ /dev/null
@@ -1,78 +0,0 @@
-{ config, lib, ... }:
-let
- mac = "02:00:00:00:00:01";
-in
-{
- imports = [
- ./keycloak.nix
- ];
- sops.defaultSopsFile = ../../secrets/auth/secrets.yaml;
- sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
-
- sops.secrets = {
- "wg/0xa-proxy" = {
- owner = config.users.users.systemd-network.name;
- };
- "keycloak/db_pass" = { };
- };
-
- microvm = {
- hypervisor = "qemu";
- mem = 2 * 1024;
- vcpu = 2;
- interfaces = [
- {
- type = "tap";
- id = "uvm-auth";
- mac = mac;
- }
- ];
- shares =
- [
- {
- source = "/nix/store";
- mountPoint = "/nix/.ro-store";
- tag = "store";
- proto = "virtiofs";
- socket = "store.socket";
- }
- ]
- ++ map
- (dir: {
- source = dir;
- mountPoint = "/${dir}";
- tag = dir;
- proto = "virtiofs";
- socket = "${dir}.socket";
- })
- [
- "etc"
- "var"
- "home"
- ];
- };
-
- networking.useNetworkd = true;
- networking.firewall.enable = lib.mkForce false; # firewalling done by the host
-
- systemd.network = {
- enable = true;
- networks."11-host" = {
- matchConfig.MACAddress = mac;
- networkConfig = {
- Address = "10.99.99.11/24";
- DHCP = "no";
- };
- routes = [
- {
- Gateway = "10.99.99.1";
- Destination = "0.0.0.0/0";
- Metric = 1024;
- }
- ];
- };
- };
-
- networking.hostName = "auth";
- system.stateVersion = "24.11";
-}
diff --git a/microvms/auth/keycloak.nix b/microvms/auth/keycloak.nix
deleted file mode 100644
index de537ef..0000000
--- a/microvms/auth/keycloak.nix
+++ /dev/null
@@ -1,18 +0,0 @@
-{ config, ... }:
-{
- services.keycloak = {
- enable = true;
- database = {
- type = "postgresql";
- createLocally = true;
- passwordFile = config.sops.secrets."keycloak/db_pass".path;
- };
- settings = {
- hostname = "https://auth.oxapentane.com";
- http-port = 38080;
- http-enabled = true;
- proxy-headers = "xforwarded";
- proxy-trusted-addresses = "10.89.88.0/24,fd31:185d:722f::/48";
- };
- };
-}
diff --git a/microvms/radicale/default.nix b/microvms/radicale/default.nix
deleted file mode 100644
index 7ed8f11..0000000
--- a/microvms/radicale/default.nix
+++ /dev/null
@@ -1,74 +0,0 @@
-{ config, lib, ... }:
-let
- mac = "02:00:00:00:00:02";
-in
-{
- sops.defaultSopsFile = ../../secrets/radicale/secrets.yaml;
- sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
-
- sops.secrets = {
- "wg/0xa-proxy" = {
- owner = config.users.users.systemd-network.name;
- };
- };
-
- microvm = {
- hypervisor = "qemu";
- mem = 1 * 1024;
- vcpu = 1;
- interfaces = [
- {
- type = "tap";
- id = "uvm-radicale";
- mac = mac;
- }
- ];
- shares =
- [
- {
- source = "/nix/store";
- mountPoint = "/nix/.ro-store";
- tag = "store";
- proto = "virtiofs";
- socket = "store.socket";
- }
- ]
- ++ map
- (dir: {
- source = dir;
- mountPoint = "/${dir}";
- tag = dir;
- proto = "virtiofs";
- socket = "${dir}.socket";
- })
- [
- "etc"
- "var"
- "home"
- ];
- };
-
- networking.useNetworkd = true;
- networking.firewall.enable = lib.mkForce false; # firewalling done by the host
-
- systemd.network = {
- enable = true;
- networks."11-host" = {
- matchConfig.MACAddress = mac;
- networkConfig = {
- Address = "10.99.99.12/24";
- DHCP = "no";
- };
- routes = [
- {
- Gateway = "10.99.99.1";
- Destination = "0.0.0.0/0";
- Metric = 1024;
- }
- ];
- };
- };
-
- networking.hostName = "radicale";
- system.stateVersion = "24.11";
-}