summaryrefslogtreecommitdiff
path: root/eligos
Commit message (Collapse)AuthorAge
* configure systemd-resolved with DoTHEADmasterKenny Ballou2021-07-23
| | | | | | | | | | Disable networkmanager from writing `/etc/resolv.conf` and use configured DNS servers with DNS over TLS. Prune down list of nameservers as Level3 and OpenDNS do not currently support DoT. Signed-off-by: Kenny Ballou <kb@devnulllabs.io>
* update firewall rulesKenny Ballou2021-02-24
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* use user package for gpg-agentKenny Ballou2020-10-23
| | | | | | | The system version is older than the user version since the system is tracking the stable branch. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* system/nix: add some nix configurationsKenny Ballou2020-10-23
| | | | | | | enable automatic garbage collection and add wheel users to trusted nix users. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* Allow unfreeKenny Ballou2020-10-14
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: add printing servicesKenny Ballou2020-08-11
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewall: add irc portKenny Ballou2020-08-10
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: switch to gnome shellKenny Ballou2020-06-25
| | | | | | Disable wayland since it doesn't work well on this machine. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: add gpgcard support for encrypted drivesKenny Ballou2020-06-05
| | | | | | | | | | | | Found this configuration options in a [reddit][0] post. This works out pretty well. Remove the keyfiles since they are never available when the system is unlocking. [0]: https://www.reddit.com/r/NixOS/comments/fv3iza/yubikey_and_luks_on_multiple_machines/ Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* services: x11: set specific video driversKenny Ballou2020-05-23
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: remove redshift service.Kenny Ballou2020-05-14
| | | | | | | Similar to a197c85 ("orobas: remove redshift service", Wed May 13 12:02:37 2020 -0600), we no longer need redshift. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* move gnupg and mtr configuration into `programs`Kenny Ballou2020-05-14
| | | | | | | | | | | The configurations for these applications was done in the root file for each machine. This led to issues where each machine had different behaviour, specifically, when it came to changes in GnuPG were introduced after upgrading to 20.03. By moving these common configurations into a separate file, each machine can be sure to have similar configurations. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* Move i18n settings to consoleKenny Ballou2020-05-12
| | | | | | keymap and font have been renamed in 20.03. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* move freecad package into system specific listKenny Ballou2020-05-08
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* services: add redshiftKenny Ballou2020-04-13
| | | | | | At least until wayland lands. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* services: remove syncthingKenny Ballou2020-02-26
| | | | | | This isn't really working as well as I would like for now. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* firewalls: add xmpp port outboundKenny Ballou2020-02-09
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: create host specific firewall rulesKenny Ballou2020-01-29
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* services: syncthing: initial service configurationKenny Ballou2020-01-29
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: add dbus service configurationKenny Ballou2020-01-06
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: remove compton serviceKenny Ballou2020-01-06
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: blacklist iptables kernel moduleKenny Ballou2019-11-28
| | | | | | | | Similar to 95db843 ("phenex: module blacklist iptables", Mon Nov 18 23:17:01 2019 -0700), we want to blacklist the iptables module such that it does not interfere with nftables modules. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* add new system/security moduleKenny Ballou2019-11-18
| | | | | | Simply flip the hide process information security knob for now. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: use generated hardware-configurationKenny Ballou2019-10-30
| | | | | | | | Similar to f54116d ("phenex: use generated hardware-configuration", Wed Oct 30 09:15:40 2019 -0600), we want to use the generated configuration file instead of the currently saved one. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* system: add documentation configurationKenny Ballou2019-08-14
| | | | | | Enable all the documentation. Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: add sshd serviceKenny Ballou2019-07-31
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: create list of system specific packagesKenny Ballou2019-07-29
| | | | Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>
* eligos: initial machine configurationKenny Ballou2019-07-29
Signed-off-by: Kenny Ballou <kballou@devnulllabs.io>