Commit graph

25563 commits

Author SHA1 Message Date
Bjørn Forsman d061c4df03
nixos/services.ddclient: remove nsupdate assertion (#443668) 2025-09-30 04:38:51 +00:00
Felix Buehler 53f95e2ea8 nixos/photoprism: use PHOTOPRISM_ADMIN_PASSWORD_FILE 2025-09-30 00:32:43 +02:00
Martin Weinelt 3a4e4f6c3d
nixos/wyoming/piper: relax ProcSubset to all
The onnxruntime library wants to query cpuinfo, which fails when the proc
subset is restricted.

Close: #445723
2025-09-30 00:29:35 +02:00
Arne Keller 2891f9938c
nixos/gerrit: Drop global lib expansion (#446636) 2025-09-29 20:35:19 +00:00
Jack Rosenberg 221e0ad60b nixos/pangolin: fix traefik error 2025-09-29 19:16:35 +02:00
Heitor Augusto c4ac791547
nixos/cosmic: add /share/cosmic-layouts to pathsToLink 2025-09-29 14:00:52 -03:00
dotlambda 6b36977077
nextcloud30: drop (#446070) 2025-09-29 16:18:14 +00:00
Masum Reza 9e538263a0
sssd: fix tests issues (#446589) 2025-09-29 14:35:47 +00:00
provokateurin 3afd6ec50d
nextcloud30: drop 2025-09-29 16:03:32 +02:00
xanderio 61dfdcf015
nixos/gitlab: add proxyWebsockets as recommended nginx setting (#431884) 2025-09-29 09:02:01 +00:00
xanderio 15a7cb4502
nixos: fix 'do not exist' typos (#434317) 2025-09-29 08:59:22 +00:00
Aleksana 3e5aa7dfe5
nixos/firezone: fix AmbientCapabilities systemd unit option typo (#444259) 2025-09-29 11:43:31 +08:00
Thomas Gerbet 18a91c2f83
morty: drop (#446354) 2025-09-28 19:26:27 +00:00
Aaron Andersen 43158d2f9d
nixos/redmine: Set ProtectSystem to strict (#446023) 2025-09-28 16:25:36 +00:00
Benjamin Staffin dad7e8f474
nixos/hddfancontrol: loosen pwmPaths and disks types to str, nixos/hddtemp: allow command substitution for drives (#421862) 2025-09-28 15:24:20 +00:00
liberodark 979a95c40a sssd: fix tests issues 2025-09-28 10:42:56 +02:00
xanderio 2a3cb7e9dc
nixos/onlyoffice: fix nginx syntax error (#444037) 2025-09-28 06:44:15 +00:00
xanderio 9dc59f7361
modules/postfix: fix manpage number in option description (#440866) 2025-09-27 12:58:50 +00:00
Felix Singer cfaae64388 nixos/gerrit: Drop global lib expansion
Signed-off-by: Felix Singer <felixsinger@posteo.net>
2025-09-27 14:58:05 +02:00
xanderio e3a3b32cc2
nixos/loki: refine option descriptions (#442975) 2025-09-27 12:33:33 +00:00
Masum Reza 1d84eb3dff
nixos/nvme-rs: init (#410730) 2025-09-27 10:57:22 +00:00
liberodark 74a08886b1 nixos/nvme-rs: init 2025-09-27 08:44:52 +02:00
Sandro 21a356df87
bird: print config file with line numbers to improve debugging (#411578) 2025-09-27 00:25:01 +00:00
dish ef50371e31
prometheus-storagebox-exporter: Init at 0-unstable-2025-07-28 (#446387) 2025-09-26 19:10:48 +00:00
Sandro 3656f7c1f1
cloudflare-ddns: init at 1.15.1 (#394668) 2025-09-26 17:43:27 +00:00
Dionysis Grigoropoulos 377847e3c8
nixos/prometheus/storagebox: Init module 2025-09-26 20:24:04 +03:00
Sandro Jäckel 3c6d1656bd
morty: drop 2025-09-26 15:45:40 +02:00
Masum Reza 0fe9557f85
openrgb: add startupProfile option to service (#408517) 2025-09-26 13:00:42 +00:00
Gaétan Lepage e72b496a44
COSMIC Beta (#440950) 2025-09-26 11:20:33 +00:00
Martin Weinelt 0b6585086d
nixos/wyoming/piper: remove piper package option
This is not customizable via the wyoming-piper cli anymore.
2025-09-25 22:26:06 +02:00
Heitor Augusto 5119b9837d
nixos/cosmic: enable xdg sounds 2025-09-25 13:56:58 -03:00
Heitor Augusto 5dca5c28b4
nixos/cosmic-greeter: update default session 2025-09-25 13:56:55 -03:00
Heitor Augusto 698cca54f9
nixos/cosmic: add cosmic-initial-setup 2025-09-25 13:56:51 -03:00
Felix Singer b19c6d9645 nixos/redmine: Set ProtectSystem to strict
Make the whole file system read-only except the directories related to
Redmine, like the state directory. The runtime directory is already
excluded by configuring it with the option `RuntimeDirectory`.

Signed-off-by: Felix Singer <felixsinger@posteo.net>
2025-09-25 16:00:26 +02:00
Felix Singer 31f095fa1a nixos/redmine: Set up runtime directory by using RuntimeDirectory option
Instead of letting systemd tmpfiles set up the runtime directory, use
the option `RuntimeDirectory` from the systemd service config since the
configured path stays read-writable when ProtectSystem is set to
`strict`. This is equal to adding the path to ReadWritePaths.

Signed-off-by: Felix Singer <felixsinger@posteo.net>
2025-09-25 15:58:31 +02:00
dish f4ac3ac7e4
{nixos/,}cockpit: add branding + small fixes (#413033) 2025-09-25 12:59:45 +00:00
Matthias Beyer 213d8d45bb
bspwm: 0.9.10 -> 0.9.11 (#445794) 2025-09-25 08:32:08 +00:00
Maximilian Bosch 2f8c1fda9c
victoriatraces: init at 0.2.0 (#441750) 2025-09-25 08:17:46 +00:00
Sandro 64d820fb2f
nixos/gnome: Adds pkgs attribute to shell extensions (#445927) 2025-09-25 07:53:10 +00:00
Sandro f611cb84ad
nixos/crowdsec: Change service type to notify like upstream (#445625) 2025-09-25 07:37:01 +00:00
Henry M bf1711c040
nixos/gnome: Adds pkgs attribute to shell extensions
This configuration was invalid as none of the packages were prefaced with the `pkgs` attribute.
2025-09-24 22:25:17 -04:00
Martin Weinelt 4d824a383a
wyoming-piper: 1.6.3 -> 2.0.0 (#445344) 2025-09-24 21:14:01 +00:00
Michele Guerini Rocco 42093d86bd
services.hostapd: convert iwd assertion ito an warning (#445760) 2025-09-24 17:36:15 +00:00
Naïm Camille Favier 02c0a71520
bspwm: 0.9.10 -> 0.9.11
https://github.com/baskerville/bspwm/releases/tag/0.9.11
2025-09-24 17:40:39 +02:00
6543 be8eb7a3ed services.hostapd: convert iwd assertion ito an warning 2025-09-24 12:31:17 +02:00
Cabia Rangris 320f897dda
outline: 0.87.3 -> 0.87.4 (#444287) 2025-09-24 09:49:02 +00:00
h7x4 4910b0b715
nixos/mealie: add extraOptions to allow setting trusted proxies (#408843) 2025-09-24 08:16:40 +00:00
dotlambda 1e596e3ee2
nixos/mosquitto: add retain_expiry_interval freeform key (#445313) 2025-09-24 07:45:11 +00:00
Franz Pletz e8387e23d3
nixos/nginx: set X-Forwarded-Server proxy header to hostname (#445633) 2025-09-24 07:25:28 +00:00
Sandro 830c3bf67c
pihole-ftl: Fix files.macvendor setting, and download database (fixes #428282) (#428690) 2025-09-23 21:51:28 +00:00
Leona Maroni 33dc105554
nixos/nginx: set X-Forwarded-Server proxy header to hostname
X-Forwarded-Server represents the last server in a row of reverse proxies
in the common use, see:
- https://www.fastly.com/documentation/reference/http/http-headers/X-Forwarded-Server/
- https://httpd.apache.org/docs/2.4/mod/mod_proxy.html#x-headers
- https://docs.valsight.com/on-premise/latest/reverse-proxy

X-Forwarded-Host instead is the original request host.

This change adapts our NGINX module to the common use of this header.
2025-09-23 22:22:35 +02:00
Nicolas Mémeint df100b8dc2 nixos/crowdsec: Change service type to notify like upstream 2025-09-23 19:11:55 +02:00
Matt Sturgeon 0f75922dcf
nixos/crowdsec: use full grep path (#443167) 2025-09-23 12:57:28 +00:00
Cody Allen 110d054cf5
nixos/crowdsec: use full grep path
I tried moving to the new crowdsec module and I got the error
`/nix/store/hj8y6b01r78fjka4351mdxvq5kd5q7j2-crowdsec-setup/bin/crowdsec-setup: line 10: grep: command not found`.
This seems to fix the issue.
2025-09-23 08:50:06 -04:00
dotlambda 79e615c4c6
nixos/miniflux: use freeformType (#443744) 2025-09-23 09:30:00 +00:00
K900 79838f3591 nixos/hostapd: fix type of channel option
0 is a valid value, and in fact the default.
Fixes #445244.
2025-09-23 11:37:55 +03:00
Martin Weinelt 3ceacb3a64 wyoming-piper: 1.6.3 -> 2.0.0
a9bedf7947/CHANGELOG.md
2025-09-22 23:55:38 +02:00
jopejoe1 2032412fdb
various: use more accurate int types (#445244) 2025-09-22 21:50:55 +00:00
Pol Dellaiera ea27db1959
various: use types.port instead of types.int (#445243) 2025-09-22 19:49:35 +00:00
h7x4 329da78738
nixos/murmur: Use lib.types.path where possible (#445293) 2025-09-22 19:34:54 +00:00
Marcus Ramberg 5b9188c03d
nixos/kanidm: allow unixd-tasks to read /etc/{passwd/group/shadow} (#444710) 2025-09-22 19:22:48 +00:00
tea 6adbfa11c5 nixos/mosquitto: add retain_expiry_interval freeform key 2025-09-22 21:11:22 +02:00
Felix Singer 5896ce3bca nixos/murmur: Use lib.types.path where possible
Signed-off-by: Felix Singer <felixsinger@posteo.net>
2025-09-22 20:11:59 +02:00
Robert Schütz bc58ca994c nixos/miniflux: use freeformType 2025-09-22 11:01:44 -07:00
Niklas Korz 2d5317c1a0
nixos/jenkins: Apply hardening options (#435751) 2025-09-22 16:48:34 +00:00
h7x4 b32466599d
nixos/redshift: use more accurate int types 2025-09-22 18:45:48 +02:00
h7x4 2b075e121e
nixos/cachix-watch-store: use more accurate int types 2025-09-22 18:45:48 +02:00
Niklas Korz a4ced97842
nixos/murmur: Set ProtectSystem to strict (#442008) 2025-09-22 16:35:49 +00:00
Jonas Heinrich 7d6f47b055
nixos/invoiceplane: Add quoteTemplates option (#384521) 2025-09-22 17:45:49 +02:00
h7x4 c2b14be993
nixos/nifi: use types.port 2025-09-22 16:48:08 +02:00
h7x4 a0f9e8c8b9
nixos/statsd: use types.port 2025-09-22 16:47:32 +02:00
h7x4 a955f6ac31
nixos/plantuml-server: use types.port 2025-09-22 16:46:45 +02:00
h7x4 24c79fd3cc
nixos/silverbullet: use types.port 2025-09-22 16:46:44 +02:00
h7x4 a7d64941f4
nixos/prosody: use types.port 2025-09-22 16:46:44 +02:00
h7x4 2fb06be29f
nixos/gitlab: use types.port 2025-09-22 16:46:44 +02:00
h7x4 637a259587
nixos/resilio: use types.port 2025-09-22 16:46:44 +02:00
h7x4 bb96a741c7
nixos/i2pd: use types.port 2025-09-22 16:46:43 +02:00
h7x4 71fb838c2f
nixos/livekit: use types.port 2025-09-22 16:46:43 +02:00
h7x4 5883645672
nixos/autossh: use types.port 2025-09-22 16:46:42 +02:00
h7x4 c9d2056db0
nixos/coturn: use types.port 2025-09-22 16:46:42 +02:00
h7x4 a3cd28b23e
nixos/buildbot: use types.port 2025-09-22 16:46:42 +02:00
h7x4 0d2a07b795
nixos/3proxy: use types.port 2025-09-22 16:46:42 +02:00
h7x4 f15acca831
nixos/distccd: use more accurate int types 2025-09-22 16:36:18 +02:00
h7x4 8c0bf2ac68
nixos/freenet: use more accurate int types 2025-09-22 16:36:18 +02:00
h7x4 2a3f551195
nixos/icecream: use more accurate int types 2025-09-22 16:36:17 +02:00
h7x4 33fb2c08bf
nixos/radvd: use more accurate int types 2025-09-22 16:36:17 +02:00
h7x4 adccbd9442
nixos/cpuminer-cryptonight: use more accurate int types 2025-09-22 16:36:17 +02:00
h7x4 016298079e
nixos/resilio: use more accurate int types 2025-09-22 16:36:17 +02:00
h7x4 54f5ec23ec
nixos/hostapd: use more accurate int types 2025-09-22 16:36:16 +02:00
h7x4 bda8f77974
nixos/rshim: use more accurate int types 2025-09-22 16:36:16 +02:00
h7x4 776e13baaf
nixos/stargazer: use more accurate int types 2025-09-22 16:36:16 +02:00
h7x4 5bd07053b4
nixos/gotenberg: use more accurate int types 2025-09-22 16:36:16 +02:00
h7x4 27a6fc2af5
nixos/apache-httpd: use more accurate int types 2025-09-22 16:36:15 +02:00
h7x4 ceb57eba5a
nixos/nfsd: use types.port 2025-09-22 16:33:04 +02:00
h7x4 a9f32669c8
nixos/tahoe: use types.port 2025-09-22 16:33:03 +02:00
h7x4 0269d83980
nixos/pgpkeyserver-lite: use types.port 2025-09-22 16:33:03 +02:00
h7x4 84d3b8350d
nixos/kasmweb: use types.port 2025-09-22 16:33:03 +02:00
h7x4 f2b5f25655
nixos/anuko-time-tracker: use types.port 2025-09-22 16:33:02 +02:00
h7x4 792ccdab5c
nixos/squid: use types.port 2025-09-22 16:33:02 +02:00
h7x4 51dd68f907
nixos/zerobin: use types.port 2025-09-22 16:33:02 +02:00