summaryrefslogtreecommitdiffstats
path: root/hosts/icon/configuration.nix
diff options
context:
space:
mode:
authorSkullheadx <admonty1@protonmail.com>2026-06-13 23:05:19 -0400
committerSkullheadx <admonty1@protonmail.com>2026-06-13 23:05:19 -0400
commit6bd2d69a5806d9cc498a65ddc7fc79a199140b55 (patch)
tree9678f0f2f6d324b66a250d1f7ad2f3889e83bf14 /hosts/icon/configuration.nix
parentuse fira code nerf font (diff)
downloadnixos-6bd2d69a5806d9cc498a65ddc7fc79a199140b55.tar.gz
nixos-6bd2d69a5806d9cc498a65ddc7fc79a199140b55.tar.bz2
nixos-6bd2d69a5806d9cc498a65ddc7fc79a199140b55.zip
format using alejandra
Diffstat (limited to 'hosts/icon/configuration.nix')
-rw-r--r--hosts/icon/configuration.nix29
1 files changed, 24 insertions, 5 deletions
diff --git a/hosts/icon/configuration.nix b/hosts/icon/configuration.nix
index f15fbf2..62c5bb8 100644
--- a/hosts/icon/configuration.nix
+++ b/hosts/icon/configuration.nix
@@ -50,8 +50,15 @@
users.users.nginx.extraGroups = ["git"];
systemd.services.nginx.serviceConfig = {
SupplementaryGroups = ["git"];
- ReadOnlyPaths = ["/srv/git" "/srv"];
- InaccessiblePaths = ["/srv/git/.ssh" "/srv/git/migrate_from_gh.sh" "/srv/git/make_new_repo.sh"];
+ ReadOnlyPaths = [
+ "/srv/git"
+ "/srv"
+ ];
+ InaccessiblePaths = [
+ "/srv/git/.ssh"
+ "/srv/git/migrate_from_gh.sh"
+ "/srv/git/make_new_repo.sh"
+ ];
};
# systemd.services.fcgiwrap.serviceConfig.ReadOnlyPaths = ["/srv/git"];
# Define a user account. Don't forget to set a password with ‘passwd’.
@@ -72,7 +79,11 @@
home = "/srv/git";
createHome = true;
homeMode = "755";
- openssh.authorizedKeys.keyFiles = [../../pubkeys/desktop_ssh.pub ../../pubkeys/homelab_ssh.pub ../../pubkeys/laptop_ssh.pub];
+ openssh.authorizedKeys.keyFiles = [
+ ../../pubkeys/desktop_ssh.pub
+ ../../pubkeys/homelab_ssh.pub
+ ../../pubkeys/laptop_ssh.pub
+ ];
};
};
@@ -151,7 +162,10 @@
fileSystems."/srv/data" = {
device = "/dev/disk/by-uuid/9014f510-b08e-488f-8c43-20a4ac7f15cc";
fsType = "ext4";
- options = ["defaults" "nofail"];
+ options = [
+ "defaults"
+ "nofail"
+ ];
};
networking.hostName = "icon";
# networking.wireless.enable = true; # Enables wireless support via wpa_supplicant.
@@ -197,7 +211,12 @@
};
# Open ports in the firewall.
- networking.firewall.allowedTCPPorts = [9418 8080 6667 2049]; # git, gitweb, irc, nfs
+ networking.firewall.allowedTCPPorts = [
+ 9418
+ 8080
+ 6667
+ 2049
+ ]; # git, gitweb, irc, nfs
networking.firewall.allowedUDPPorts = [55555]; # wireguard
# Or disable the firewall altogether.
# networking.firewall.enable = false;