mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 14:27:26 +03:00
Review of dev vs16644fcfound 1 BLOCKING + 3 IMPORTANT + 2 MINOR. All addressed in this commit: B1 (R1.4 stale files in project-rules.md + AGENTS.md): Replaced 'vds/nginx.nix' (removed inef38dc4) with 'home/termux.nix' (added in958247b). R1.4 now correctly lists the 4 files that use 100.64.0.0: home/termux.nix:256, modules/server/nextcloud.nix:73, modules/server/nginx.nix:109,253, modules/vds/systemd.nix:10. I1 (count drift in '15 modules' docs): - AGENTS.md:84 + project-rules.md:97: '15 → 14' (with note that stirling-pdf was deleted in5dd7a58) - manifest.json (T16): rewritten acceptance to '15 archived (13 from server/default.nix:37-50 + 2 from containers/ kokoro-tts and openhands) + 1 deleted (stirling-pdf) + 1 active (open-webui in containers/)' - modules/server/default.nix:37-50: comment now explains the three categories I2 (T1 + T13 status stuck on pending): Both flipped to 'completed' in manifest.json. T1 import fix verified by nix eval (epral stateVersion = '24.05'). T13 done in61b3724(nginx firewall rule removed). I3 (.ci/checks.sh committed) satisfied. M1 (R1.3 stale nginx.nix:225 line number): Removed line number from both project-rules.md and AGENTS.md. Replaced with 'nginx.nix (networking.firewall)'. M2 (R1.2 listed 7 services, 2 in archive): Updated to 12 actual services in both files. n8n and minecraft were archived in T16; they no longer need storage guard. T10 (reality443Forwarding погашен): Removed option from options.nix:66-74, realityPorts from 3x-ui.nix:33-35, and 'reality443Forwarding = true' from vds/default.nix:19. ADR-note comments left in place. T15 (kokoro-tts and openhands archived): git mv modules/containers/kokoro-tts.nix → archive/containers/ git mv modules/containers/openhands.nix → archive/containers/ Also moved modules/containers/kokoro-tts/ (Dockerfile, app.py, etc.) to archive/containers/kokoro-tts/ for completeness. any.nix (nix flake check support): Added stub fileSystems + boot.loader.grub to configurations/any.nix so 'nix flake check' can evaluate the 'default' template config (which is never deployed — real hosts have their own disko/grub). wsl cleanup (dead imports blocking nix flake check): - Removed modules/wsl/containers/default.nix (was only imported nowhere, contained kokoro-tts reference) - Removed './containers' import from modules/wsl/default.nix (resolved to the now-removed default.nix) nix flake check: previously failed with 'Path modules/containers does not exist' (cached evaluation referenced old path). After this commit the error is gone — flake check progressed past the path resolution and started building derivations. Full build output not captured (5-min timeout for download from cache.nixos.org), but path errors are resolved. T5 risk acknowledgment: .agent/decisions/0002-backups-external.md updated with explicit risk table for 'if no backups' scenario + ADR/R1.9 guidance. T1, T2, T6, T7, T8, T9, T10, T12, T13, T15, T16, T17: all → completed in manifest.json. T3, T4, T5, T11, T14: previously completed. Remaining DEFERRED: T3 (otrecа SSH recovery), T5 (5.6 answer).
67 lines
2.7 KiB
Nix
67 lines
2.7 KiB
Nix
{
|
|
lib,
|
|
...
|
|
}:
|
|
# Cross-module options: declared here, not in the module that reads them.
|
|
#
|
|
# An option belongs in this file when at least one context *sets* it while
|
|
# another module *reads* it — the reader cannot be the only place that knows
|
|
# the option exists. `modules/essentials/ssh.nix` does not belong here: it
|
|
# declares and reads `host.ssh.enable` itself, within one module.
|
|
{
|
|
# Remote-builder wiring. A coordinator (e.g. sapphira) sets
|
|
# `host.builder.clients` to register remote build machines;
|
|
# a builder host (e.g. the WSL on vetymae) sets `host.builder.enable`
|
|
# to advertise itself. The two halves are intentionally split so a single
|
|
# declaration in configurations/* is enough to flip each side.
|
|
options.host.builder = {
|
|
enable = lib.mkOption {
|
|
type = lib.types.bool;
|
|
default = false;
|
|
description = ''
|
|
Advertise this host as a remote Nix builder and accept builds
|
|
from other machines in the flake over SSH.
|
|
'';
|
|
};
|
|
clients = lib.mkOption {
|
|
type = lib.types.listOf lib.types.attrs;
|
|
default = [ ];
|
|
description = ''
|
|
List of remote Nix build machines this coordinator should
|
|
register via `nix.buildMachines`. Each entry matches the NixOS
|
|
option schema (hostName, sshUser, sshKey, systems,
|
|
supportedFeatures, ...). Two extra attributes are consumed by
|
|
modules/server/builder.nix and stripped before reaching
|
|
`nix.buildMachines`:
|
|
- `proxyCommand` — generates a per-builder Host block in the
|
|
system-wide OpenSSH config (the nix-daemon runs as root and
|
|
cannot see the user's ~/.ssh/config).
|
|
- `hostKeyAlias` — alias used inside that SSH matchBlock.
|
|
A builder reachable on its own (no ProxyCommand needed) omits
|
|
both and gets no SSH matchBlock. Empty by default — opt in by
|
|
setting this list.
|
|
'';
|
|
};
|
|
};
|
|
|
|
options.host."3x-ui" = {
|
|
# Domain whose Let's Encrypt cert (at /var/lib/acme/<domain>/)
|
|
# gets mounted read-only into the 3x-ui container so the panel
|
|
# can terminate TLS itself. Set null if 3x-ui serves plain HTTP
|
|
# and TLS is terminated by an upstream nginx.
|
|
certDomain = lib.mkOption {
|
|
type = lib.types.nullOr lib.types.str;
|
|
default = null;
|
|
example = "pubray1.zeroq.su";
|
|
description = ''
|
|
Domain whose LE cert should be mounted into the 3x-ui
|
|
container at /root/cert/fullchain.pem and key.pem.
|
|
'';
|
|
};
|
|
# reality443Forwarding was removed (T10/C5, 2026-10-10). The
|
|
# option's purpose was lost after the c8d4a12 revert (manifest:177-178);
|
|
# nginx stream on otreca still works without it. See ADR-0002
|
|
# in .agent/decisions/ for the decision record.
|
|
};
|
|
}
|