mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 14:27:26 +03:00
Review of dev vs16644fcfound 1 BLOCKING + 3 IMPORTANT + 2 MINOR. All addressed in this commit: B1 (R1.4 stale files in project-rules.md + AGENTS.md): Replaced 'vds/nginx.nix' (removed inef38dc4) with 'home/termux.nix' (added in958247b). R1.4 now correctly lists the 4 files that use 100.64.0.0: home/termux.nix:256, modules/server/nextcloud.nix:73, modules/server/nginx.nix:109,253, modules/vds/systemd.nix:10. I1 (count drift in '15 modules' docs): - AGENTS.md:84 + project-rules.md:97: '15 → 14' (with note that stirling-pdf was deleted in5dd7a58) - manifest.json (T16): rewritten acceptance to '15 archived (13 from server/default.nix:37-50 + 2 from containers/ kokoro-tts and openhands) + 1 deleted (stirling-pdf) + 1 active (open-webui in containers/)' - modules/server/default.nix:37-50: comment now explains the three categories I2 (T1 + T13 status stuck on pending): Both flipped to 'completed' in manifest.json. T1 import fix verified by nix eval (epral stateVersion = '24.05'). T13 done in61b3724(nginx firewall rule removed). I3 (.ci/checks.sh committed) satisfied. M1 (R1.3 stale nginx.nix:225 line number): Removed line number from both project-rules.md and AGENTS.md. Replaced with 'nginx.nix (networking.firewall)'. M2 (R1.2 listed 7 services, 2 in archive): Updated to 12 actual services in both files. n8n and minecraft were archived in T16; they no longer need storage guard. T10 (reality443Forwarding погашен): Removed option from options.nix:66-74, realityPorts from 3x-ui.nix:33-35, and 'reality443Forwarding = true' from vds/default.nix:19. ADR-note comments left in place. T15 (kokoro-tts and openhands archived): git mv modules/containers/kokoro-tts.nix → archive/containers/ git mv modules/containers/openhands.nix → archive/containers/ Also moved modules/containers/kokoro-tts/ (Dockerfile, app.py, etc.) to archive/containers/kokoro-tts/ for completeness. any.nix (nix flake check support): Added stub fileSystems + boot.loader.grub to configurations/any.nix so 'nix flake check' can evaluate the 'default' template config (which is never deployed — real hosts have their own disko/grub). wsl cleanup (dead imports blocking nix flake check): - Removed modules/wsl/containers/default.nix (was only imported nowhere, contained kokoro-tts reference) - Removed './containers' import from modules/wsl/default.nix (resolved to the now-removed default.nix) nix flake check: previously failed with 'Path modules/containers does not exist' (cached evaluation referenced old path). After this commit the error is gone — flake check progressed past the path resolution and started building derivations. Full build output not captured (5-min timeout for download from cache.nixos.org), but path errors are resolved. T5 risk acknowledgment: .agent/decisions/0002-backups-external.md updated with explicit risk table for 'if no backups' scenario + ADR/R1.9 guidance. T1, T2, T6, T7, T8, T9, T10, T12, T13, T15, T16, T17: all → completed in manifest.json. T3, T4, T5, T11, T14: previously completed. Remaining DEFERRED: T3 (otrecа SSH recovery), T5 (5.6 answer).
62 lines
1.9 KiB
Nix
62 lines
1.9 KiB
Nix
{
|
|
lib,
|
|
xlib,
|
|
...
|
|
}:
|
|
{
|
|
imports = [
|
|
../containers/3x-ui.nix
|
|
../containers/open-webui.nix
|
|
../containers/tape-rotation.nix
|
|
../pkgs/beets.nix
|
|
./acme.nix
|
|
./authelia.nix
|
|
./bentopdf.nix
|
|
./builder.nix
|
|
./calibre-web.nix
|
|
./chrony.nix
|
|
./coredns.nix
|
|
./gitea.nix
|
|
./glances.nix
|
|
./homebox.nix
|
|
./immich.nix
|
|
./miniflux.nix
|
|
./navidrome.nix
|
|
./nextcloud.nix
|
|
./nginx.nix
|
|
./nix-serve.nix
|
|
./onlyoffice.nix
|
|
./postgresql.nix
|
|
./power.nix
|
|
./samba.nix
|
|
./syncthing.nix
|
|
./systemd.nix
|
|
./ttyd.nix
|
|
./vtimeline.nix
|
|
./uptime-kuma.nix
|
|
# T16: 14 modules archived to ../archive/{server-modules,containers}/
|
|
# (13 in modules/server/default.nix:37-50, 2 in modules/containers/).
|
|
# T15: kokoro-tts and openhands (not imported) also archived.
|
|
# stirling-pdf.nix was deleted in 5dd7a58 (absorbed into bentopdf.nix).
|
|
# open-webui.nix was never commented — migrated to containers/,
|
|
# still active via ../containers/open-webui.nix above.
|
|
];
|
|
# Server's 3x-ui is the controller panel at x.zeroq.su (nginx HTTP
|
|
# terminates TLS upstream, no SNI-routing on 443 needed here because
|
|
# there are other vhosts on the same port). Cert is still mounted in
|
|
# case 3x-ui is later reconfigured to terminate TLS itself (e.g. for
|
|
# direct node-API access); nginx doesn't have to use it.
|
|
host."3x-ui".certDomain = "x.zeroq.su";
|
|
# Authelia SSO — currently protects vtimeline.zeroq.su (replaces the
|
|
# previous nginx auth_basic htpasswd). Cookie domain is .zeroq.su so a
|
|
# single Authelia session covers every protected vhost under the zone.
|
|
host.authelia = {
|
|
enable = true;
|
|
cookieDomain = "zeroq.su";
|
|
};
|
|
systemd.tmpfiles.rules = [
|
|
(xlib.helpers.mkTmpfile "d" "/mnt" "0755" "root" "root")
|
|
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")
|
|
];
|
|
}
|