Commit graph

72 commits

Author SHA1 Message Date
5c4df54d2c
Merge branch 'master' of gitlab2.federez.net:federez/nix 2025-06-21 12:00:25 +02:00
a13930e3cc
secrets: add jargon + niangon 2025-06-21 11:58:39 +02:00
e29b562898 Merge branch 'asyncnomi-keys-and-gitlab-link' into 'master'
Add gitlab links to point to its fqdn and not its hostname, add asyncnomi keys for agenix

See merge request federez/nix!1
2025-06-21 09:57:26 +00:00
10f55b04ca
refactor host/guest profiles + add niangon 2025-06-21 11:55:11 +02:00
698bde5856
monitoring: refactoring + blackbox 2025-06-21 11:51:39 +02:00
267b8d94c8 unstable-small version bump to update gitlab 2025-06-19 22:28:27 +02:00
342b9a17c6 me cannot see 2025-06-19 21:29:22 +02:00
9517f24d6f add gitlab url to point to its fqdn, add asyncnomi keys for agenix 2025-06-19 21:11:12 +02:00
59789595d1
monitoring: cleanup rules + NodeLastBorgmaticTooOld 2025-04-07 20:29:09 +02:00
c7b9a8d839
fix(infra): typo enabled → enable 2025-04-07 20:29:09 +02:00
8129b26c4c
add backups + fix appservice-irc media proxy 2025-04-07 20:29:05 +02:00
d672a1d1ee
gitlab: store secrets in age
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:27:02 +02:00
a64b34810d
wip: nixpkgs versions + infra network + monitoring
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:26:29 +02:00
01b5a0fe25
Bump version + minor cleanups
Signed-off-by: jeltz@federez.net
2025-04-05 21:25:28 +02:00
09d82c6b88
wip: add vogon + many other things
Added lots of things done in a hurry following the dodecagon failure.

Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:22:50 +02:00
a184d18f4b
WIP: add grafana & victoriametrics 2025-04-05 21:19:37 +02:00
a8e3c97ef4
Add host 'martagon'
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:36 +02:00
dfc05aad4a
indico: use upstream qTip2
See https://github.com/indico/qTip2/pull/1

Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:36 +02:00
5d32735063
indico: use systemd-creds
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:36 +02:00
6c627daa51
secrets: remove \n at the end of indico password files
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:36 +02:00
6b529aeb16
indico: I'm dumb
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:35 +02:00
b1039a6859
indico: slightly better socket/unit config
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:35 +02:00
e47358876e
indico: update profile with age passwords
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:35 +02:00
cfc5775ba5
secrets: add indico passwords
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:35 +02:00
2f93570ac4
indico: use files for passwords
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:34 +02:00
dd2afc2cfb
indico: wip: add LDAP support
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:34 +02:00
0a8ae58334
indico: wip: main pkg is almost working
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:34 +02:00
abbafb082d
indico: wip: create module
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:34 +02:00
d75eba0b8e
indico: add package react-jsx-i18n
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:33 +02:00
5dbe2bd6d1
indico: add package flask-url-map-serializer
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:33 +02:00
a0fe0fdd34
Relax hatch version requirement in flask-multipass
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:33 +02:00
43f5d686cc
Update npins
The update is necessary in particular because npmConfigHook now supports git+https:// URLs, which was not the case with the version in the old nixpkgs.

Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:33 +02:00
d12f9d91d1
WIP: Add indico profile + required packages
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:32 +02:00
bb03bd9054
Add host 'perdrigon'
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:32 +02:00
817aab82b6
discourse: add mail config and somme plugins
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:32 +02:00
7c46eed7ed
secrets: rekey for pendragon
Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:32 +02:00
Ryan Lahfa
0d411f83c6
secrets: rekey for jeltz
Signed-off-by: Ryan Lahfa <federez-infra@lahfa.xyz>
2025-04-05 21:19:31 +02:00
7491e221d3
discourse: init (wip)
Incomplete installation of Discourse on pendragon.

Missing in particular are emails (both outgoing and incoming).

Signed-off-by: Jeltz <jeltz@federez.net>
2025-04-05 21:19:31 +02:00
Ryan Lahfa
61ed6e9571
profiles/sysadmin: move to Lix, purge journald to 512M, add GC/NGINX/net optimizations
This should reduce some churn.

Signed-off-by: Ryan Lahfa <federez-infra@lahfa.xyz>
2025-04-05 21:19:31 +02:00
Ryan Lahfa
918610b56e
sources: bump & address deprecations
Signed-off-by: Ryan Lahfa <federez-infra@lahfa.xyz>
2025-04-05 21:19:30 +02:00
Ryan Lahfa
c3844094b2
profiles/wayf: further wip work
Signed-off-by: Ryan Lahfa <federez-infra@lahfa.xyz>
2025-04-05 21:19:30 +02:00
Ryan Lahfa
3b6c3f6d70
profiles/gitlab: init
Signed-off-by: Ryan Lahfa <federez-infra@lahfa.xyz>
2025-04-05 21:19:25 +02:00
raito
0b55fc629f Merge branch 'enroll_jeltz' into 'master'
admins: enroll Jeltz

See merge request federez/nix!1
2024-08-08 14:31:56 +00:00
d595fc2c1f
admins: enroll Jeltz
Jeltz est membre d'Aurore et du bureau de FedeRez.

Signed-off-by: Jeltz <jeltz@federez.net>
2024-08-08 16:17:19 +02:00
69130134cd irc-bot: reduce reply threshold 2024-02-15 16:43:43 +00:00
Ryan Lahfa
0355dd4b80 admins: enroll Tom Hubrecht
Tom Hubrecht est un sysadmin / membre d'honneur de la DGNum, membre du CA d'AliENS.

Signed-off-by: Ryan Lahfa <federez-infra@lahfa.xyz>
2024-02-14 21:10:57 +01:00
Ryan Lahfa
a4ab0fce56 profiles/auditd: enable on all systems
Signed-off-by: Ryan Lahfa <federez-infra@lahfa.xyz>
2024-02-14 20:40:47 +01:00
Ryan Lahfa
4fbfa50b10 profiles/sysadmin: do not log refused connections
Signed-off-by: Ryan Lahfa <federez-infra@lahfa.xyz>
2024-02-14 20:40:38 +01:00
Ryan Lahfa
cb13a67c63 profiles/federez: add Federez MOTD for NixOS systems
Signed-off-by: Ryan Lahfa <federez-infra@lahfa.xyz>
2024-02-14 20:40:31 +01:00
Ryan Lahfa
0a637e5079 profiles/ldap: init
Phew, this is working?

Signed-off-by: Ryan Lahfa <federez-infra@lahfa.xyz>
2024-02-14 20:40:20 +01:00