summaryrefslogtreecommitdiff
path: root/hosts/skadhi
diff options
context:
space:
mode:
Diffstat (limited to 'hosts/skadhi')
-rw-r--r--hosts/skadhi/default.nix118
-rw-r--r--hosts/skadhi/fs.nix86
-rw-r--r--hosts/skadhi/hw.nix20
-rw-r--r--hosts/skadhi/networking/default.nix38
-rw-r--r--hosts/skadhi/networking/ruleset.nft237
5 files changed, 499 insertions, 0 deletions
diff --git a/hosts/skadhi/default.nix b/hosts/skadhi/default.nix
new file mode 100644
index 00000000..cf25777b
--- /dev/null
+++ b/hosts/skadhi/default.nix
@@ -0,0 +1,118 @@
1{ flake, flakeInputs, pkgs, config, lib, ... }:
2{
3 imports = with flake.nixosModules.systemProfiles; [
4 ./hw.nix ./fs.nix ./networking
5 tmpfs-root default-locale openssh lanzaboote zswap initrd-all-crypto-modules
6 ];
7
8 config = {
9 system.stateVersion = "26.05";
10
11 boot = {
12 initrd = {
13 systemd = {
14 emergencyAccess = config.users.users.root.hashedPassword;
15 extraBin = {
16 "vim" = lib.getExe pkgs.vim;
17 "grep" = lib.getExe pkgs.gnugrep;
18 };
19 };
20
21 kernelModules = [ "dm-integrity" ];
22 };
23
24 lanzaboote.configurationLimit = 15;
25 loader = {
26 efi.canTouchEfiVariables = true;
27 timeout = null;
28 };
29
30 plymouth.enable = true;
31
32 kernelPackages = pkgs.linuxPackages_7_2;
33 consoleLogLevel = 3;
34 kernelParams = [
35 "quiet"
36 "boot.shell_on_fail"
37 "udev.log_priority=3"
38 "rd.systemd.show_status=auto"
39 "plymouth.use-simpledrm"
40 ];
41
42 tmp.useTmpfs = true;
43 };
44
45 services.timesyncd.enable = false;
46 services.chrony = {
47 enable = true;
48 enableNTS = true;
49 servers = [];
50 extraConfig = ''
51 pool time.cloudflare.com iburst nts
52 pool nts.netnod.se prefer iburst nts
53 server ptbtime1.ptb.de prefer iburst nts
54 server ptbtime2.ptb.de prefer iburst nts
55 server ptbtime3.ptb.de prefer iburst nts
56 server ptbtime4.ptb.de prefer iburst nts
57 pool ntppool1.time.nl prefer iburst nts
58 pool ntppool2.time.nl prefer iburst nts
59
60 authselectmode require
61 minsources 3
62
63 nocerttimecheck 1
64
65 leapsectz right/UTC
66
67 makestep 0.1 3
68
69 cmdport 0
70 '';
71 };
72
73 services.userborn.importLegacyState = false;
74
75 services.kmscon = {
76 enable = true;
77 config.hwaccel = true;
78 };
79
80 environment.persistence."/persistent".timezone = true;
81 time.timeZone = null;
82 systemd.tmpfiles.settings = {
83 "10-localtime"."/etc/localtime".L.argument = "/persistent/etc/localtime";
84 };
85
86 services.openssh.enable = true;
87
88 services.logind.settings.Login = {
89 HandleLidSwitch = "sleep";
90 HandleLidSwitchExternalPower = "ignore";
91 };
92
93 systemd.timers.nix-gc = lib.mkForce {
94 timerConfig = {
95 RandomizedDelaySec = "12h";
96 Persistent = true;
97 OnCalendar = "*-*-* 18:00:00 Europe/Berlin";
98 };
99 wantedBy = [ "timers.target" ];
100 };
101 systemd.services.nix-gc = lib.mkForce {
102 description = "Nix Garbage Collector";
103 serviceConfig = {
104 Type = "oneshot";
105 ExecStart = pkgs.resholve.writeScript "nix-gc" {
106 interpreter = lib.getExe pkgs.zsh;
107 inputs = [ pkgs.coreutils config.nix.package ];
108 execer = [ "cannot:${lib.getExe' config.nix.package "nix-collect-garbage"}" ];
109 } ''
110 max_size=$(($(du -bs /nix/store | cut -f 1) - 1024**4))
111 [[ $max_size -gt 0 ]] || exit 0
112 exec nix-collect-garbage -vv --max-freed $max_size --delete-older-than 30d
113 '';
114 };
115 restartIfChanged = false;
116 };
117 };
118}
diff --git a/hosts/skadhi/fs.nix b/hosts/skadhi/fs.nix
new file mode 100644
index 00000000..41ef24f6
--- /dev/null
+++ b/hosts/skadhi/fs.nix
@@ -0,0 +1,86 @@
1{ flake, flakeInputs, pkgs, config, lib, ... }:
2{
3 imports = with flake.nixosModules.systemProfiles; [
4 disko
5 ];
6
7 config = {
8 fileSystems."/persistent".neededForBoot = true;
9 environment.persistence."/persistent" = {
10 hideMounts = true;
11 directories = [
12 "/nix"
13 "/root"
14 "/var/log"
15 "/var/lib/nixos"
16 "/var/lib/sops-nix"
17 "/var/lib/systemd"
18 "/var/lib/fprint"
19 "/var/lib/chrony"
20 "/var/lib/postfix"
21 config.boot.lanzaboote.pkiBundle
22 ];
23 };
24
25 disko.devices = {
26 disk.nvm = {
27 type = "disk";
28 device = "/dev/nvme0n1";
29 content = {
30 type = "gpt";
31 partitions = {
32 ESP = {
33 size = "512M";
34 type = "EF00";
35 content = {
36 type = "filesystem";
37 format = "vfat";
38 mountpoint = "/boot";
39 mountOptions = [
40 "fmask=0033" "dmask=0022"
41 ];
42 };
43 };
44 luks = {
45 size = "100%";
46 content = {
47 type = "luks";
48 name = "nvm";
49 extraFormatArgs = [
50 "--cipher" "aegis128-random"
51 "--key-size" "128"
52 "--integrity" "aead"
53 ];
54 content = {
55 type = "btrfs";
56 extraArgs = let
57 dirs = map (p: "/persistent/${p}") ["/etc"];
58 subvols = ["/persistent"] ++ map (p: "/persistent/${p}") ["/nix" "/var/log"];
59 restricted = map (p: "/persistent/${p}") ["/root"];
60 in [
61 "--csum" "blake2"
62 "--compress" "zstd:15"
63 "--rootdir" (toString (pkgs.runCommand "rootdir" {
64 } ''
65 mkdir $out
66 install -d ${lib.concatMapStringsSep " " (p: "$out/${p}") (dirs ++ subvols)}
67 install -m 0700 -d ${lib.concatMapStringsSep " " (p: "$out/${p}") restricted}
68 ln -s /etc/zoneinfo/UTC /persistent/etc/localtime
69 ''))
70 ] ++ lib.concatMap (p: ["--subvol" p]) (subvols ++ restricted);
71 subvolumes = {
72 "/persistent".mountpoint = "/persistent";
73 "/swap" = {
74 mountpoint = "/.swap";
75 swap.swapfile.size = "96G";
76 };
77 };
78 };
79 };
80 };
81 };
82 };
83 };
84 };
85 };
86}
diff --git a/hosts/skadhi/hw.nix b/hosts/skadhi/hw.nix
new file mode 100644
index 00000000..687f04d8
--- /dev/null
+++ b/hosts/skadhi/hw.nix
@@ -0,0 +1,20 @@
1{ flake, flakeInputs, pkgs, config, lib, ... }:
2{
3 imports = [
4 flakeInputs.nixos-hardware.nixosModules.framework-13-7040-amd
5 ];
6
7 config = {
8 hardware.framework.laptop13.audioEnhancement.enable = false;
9 hardware.enableRedistributableFirmware = true;
10 services.fstrim.enable = false;
11
12 services.udev.extraRules = ''
13 ACTION=="add", SUBSYSTEM=="platform", DRIVER=="acpi-button", KERNEL=="PNP0C0D:00", ATTR{power/wakeup}="disabled"
14 ACTION=="add", SUBSYSTEM=="serio", DRIVERS=="atkbd", ATTR{power/wakeup}="disabled"
15 ACTION=="add", SUBSYSTEM=="i2c", DRIVERS=="i2c_hid_acpi", ATTRS{name}=="PIXA3854:00", ATTR{power/wakeup}="disabled"
16 '';
17
18 nixpkgs.system = "x86_64-linux";
19 };
20}
diff --git a/hosts/skadhi/networking/default.nix b/hosts/skadhi/networking/default.nix
new file mode 100644
index 00000000..4d6edd97
--- /dev/null
+++ b/hosts/skadhi/networking/default.nix
@@ -0,0 +1,38 @@
1{ flake, config, ... }:
2{
3 imports = with flake.nixosModules.systemProfiles; [
4 networkmanager
5 ];
6
7 config = {
8 environment.persistence."/persistent".directories = [
9 "/etc/NetworkManager/system-connections"
10 ];
11
12 networking = {
13 domain = "yggdrasil";
14 search = [ "yggdrasil" ];
15 hosts = {
16 "127.0.0.1" = [ "${config.networking.hostName}.yggdrasil" config.networking.hostName ];
17 "::1" = [ "${config.networking.hostName}.yggdrasil" config.networking.hostName ];
18 };
19
20 firewall.enable = false;
21 nftables = {
22 enable = true;
23 rulesetFile = ./ruleset.nft;
24 };
25
26 useDHCP = false;
27 useNetworkd = true;
28 };
29
30 environment.etc."NetworkManager/dnsmasq.d/yggdrasil.conf" = {
31 text = ''
32 server=/yggdrasil/2a03:4000:52:ada:1:1::@yggdrasil
33 server=/141.10.in-addr.arpa/2a03:4000:52:ada:1:1::@yggdrasil
34 server=/1.0.0.0.a.d.a.0.2.5.0.0.0.0.0.4.3.0.a.2.ip6.arpa/2a03:4000:52:ada:1:1::@yggdrasil
35 '';
36 };
37 };
38}
diff --git a/hosts/skadhi/networking/ruleset.nft b/hosts/skadhi/networking/ruleset.nft
new file mode 100644
index 00000000..94e21b10
--- /dev/null
+++ b/hosts/skadhi/networking/ruleset.nft
@@ -0,0 +1,237 @@
1define icmp_protos = { ipv6-icmp, icmp, igmp }
2
3table arp filter {
4 limit lim_arp {
5 rate over 50 mbytes/second burst 50 mbytes
6 }
7
8 counter arp-rx {}
9 counter arp-tx {}
10
11 counter arp-ratelimit-rx {}
12 counter arp-ratelimit-tx {}
13
14 chain input {
15 type filter hook input priority filter
16 policy accept
17
18 limit name lim_arp counter name arp-ratelimit-rx drop
19
20 counter name arp-rx
21 }
22
23 chain output {
24 type filter hook output priority filter
25 policy accept
26
27 limit name lim_arp counter name arp-ratelimit-tx drop
28
29 counter name arp-tx
30 }
31}
32
33table inet filter {
34 limit lim_reject {
35 rate over 1000/second burst 1000 packets
36 }
37
38 limit lim_icmp {
39 rate over 50 mbytes/second burst 50 mbytes
40 }
41
42 counter invalid-fw {}
43
44 counter fw-lo {}
45
46 counter reject-ratelimit-fw {}
47 counter reject-fw {}
48 counter reject-tcp-fw {}
49 counter reject-icmp-fw {}
50
51
52 counter invalid-rx {}
53 counter rx-lo {}
54 counter invalid-local4-rx {}
55 counter invalid-local6-rx {}
56
57 counter icmp-ratelimit-rx {}
58 counter icmp-rx {}
59
60 counter ssh-rx {}
61 counter mosh-rx {}
62 counter wg-rx {}
63 counter yggdrasil-gre-rx {}
64 counter miniserve-rx {}
65 counter ausweisapp2-rx {}
66
67 counter established-rx {}
68
69 counter reject-ratelimit-rx {}
70 counter reject-rx {}
71 counter reject-tcp-rx {}
72 counter reject-icmp-rx {}
73
74
75 counter tx-lo {}
76
77 counter icmp-ratelimit-tx {}
78 counter icmp-tx {}
79
80 counter ssh-tx {}
81 counter mosh-tx {}
82 counter wg-tx {}
83 counter yggdrasil-gre-tx {}
84 counter miniserve-tx {}
85
86 counter tx {}
87
88 counter fw-libvirt {}
89 counter libvirt-dhcp {}
90 counter libvirt-dns {}
91
92
93 chain forward_tmp {}
94 chain forward {
95 type filter hook forward priority filter
96 policy drop
97
98
99 ct state invalid log level debug prefix "drop invalid forward: " counter name invalid-fw drop
100
101
102 iifname lo counter name fw-lo accept
103
104 jump forward_tmp
105
106 iifname virbr0 oifname != {lo, wgrz, yggdrasil-wg-4, yggdrasil-wg-6, yggdrasil, ip6tnl, ip6gre, yggre-surtr-6, yggre-surtr-4, yggre-vidhar-4} counter name fw-libvirt accept
107 oifname virbr0 ct state {established, related} counter name fw-libvirt accept
108
109
110 limit name lim_reject log level debug prefix "drop forward: " counter name reject-ratelimit-fw drop
111 log level debug prefix "reject forward: " counter name reject-fw
112 meta l4proto tcp ct state new counter name reject-tcp-fw reject with tcp reset
113 ct state new counter name reject-icmp-fw reject
114 }
115
116 ct helper ftp-standard {
117 type "ftp" protocol tcp
118 }
119 chain input_pr_tmp {
120 # tcp dport 2121 ct helper set "ftp-standard"
121 }
122 chain input_pr {
123 type filter hook prerouting priority 0
124
125 jump input_pr_tmp
126 }
127
128 chain input_tmp {
129 # tcp dport 2121 accept
130 }
131 chain input {
132 type filter hook input priority filter
133 policy drop
134
135
136 ct state invalid log level debug prefix "drop invalid input: " counter name invalid-rx drop
137
138
139 iifname lo counter name rx-lo accept
140 iif != lo ip daddr 127.0.0.1/8 counter name invalid-local4-rx reject
141 iif != lo ip6 daddr ::1/128 counter name invalid-local6-rx reject
142
143 meta l4proto $icmp_protos limit name lim_icmp counter name icmp-ratelimit-rx drop
144 meta l4proto $icmp_protos counter name icmp-rx accept
145
146 jump input_tmp
147
148 tcp dport 22 counter name ssh-rx accept
149 udp dport 60000-61000 counter name mosh-rx accept
150
151 tcp dport 8080 counter name miniserve-rx accept
152 udp dport 24727 counter name ausweisapp2-rx accept
153
154 udp dport 51820-51822 counter name wg-rx accept
155 iifname "yggdrasil-wg-*" meta l4proto gre counter name yggdrasil-gre-rx accept
156
157 iifname virbr0 udp dport 67 counter name libvirt-dhcp accept
158 iifname virbr0 udp dport 547 counter name libvirt-dhcp accept
159 iifname virbr0 udp dport 53 counter name libvirt-dns accept
160 iifname virbr0 tcp dport 53 counter name libvirt-dns accept
161
162 iifname wgrz ip saddr 10.200.116.1 meta l4proto gre counter accept
163
164 ct state {established, related} counter name established-rx accept
165
166
167 limit name lim_reject log level debug prefix "drop input: " counter name reject-ratelimit-rx drop
168 log level debug prefix "reject input: " counter name reject-rx
169 meta l4proto tcp ct state new counter name reject-tcp-rx reject with tcp reset
170 ct state new counter name reject-icmp-rx reject
171 }
172
173 chain output {
174 type filter hook output priority filter
175 policy accept
176
177
178 oifname lo counter name tx-lo accept
179
180 meta l4proto $icmp_protos limit name lim_icmp counter name icmp-ratelimit-tx drop
181 meta l4proto $icmp_protos counter name icmp-tx accept
182
183
184 tcp sport 22 counter name ssh-tx
185 udp sport 60000-61000 counter name mosh-tx
186
187 udp sport 51820-51822 counter name wg-tx
188 iifname "yggdrasil-wg-*" meta l4proto gre counter name yggdrasil-gre-tx
189
190 tcp sport 8080 counter name miniserve-tx accept
191
192 oifname virbr0 udp sport 67 counter name libvirt-dhcp accept
193 oifname virbr0 udp sport 547 counter name libvirt-dhcp accept
194 oifname virbr0 udp sport 53 counter name libvirt-dns accept
195 oifname virbr0 tcp sport 53 counter name libvirt-dns accept
196
197
198 counter name tx
199 }
200}
201
202table ip nat {
203 counter libvirt-nat {}
204
205 chain postrouting_tmp {}
206 chain postrouting {
207 type nat hook postrouting priority srcnat
208 policy accept
209
210 iifname virbr0 oifname != virbr0 counter name libvirt-nat masquerade
211 jump postrouting_tmp
212 }
213}
214
215table ip6 nat {
216 counter libvirt-nat {}
217
218 chain postrouting {
219 type nat hook postrouting priority srcnat
220 policy accept
221
222 iifname virbr0 oifname != virbr0 counter name libvirt-nat masquerade
223 }
224}
225
226table ip mss_clamp {
227 counter libvirt-mss-clamp {}
228
229 chain postrouting_tmp {}
230 chain postrouting {
231 type filter hook postrouting priority mangle
232 policy accept
233
234 iifname virbr0 oifname != virbr0 tcp flags & (syn|rst) == syn counter name libvirt-mss-clamp tcp option maxseg size set rt mtu
235 jump postrouting_tmp
236 }
237}