Commit message (Collapse) | Author | Age | ||
---|---|---|---|---|
... | ||||
* | Fix(system/fs-layout): Remove persistent dir as it's now in /srv | Soispha | 2023-06-25 | |
| | ||||
* | Fix(system/services/acme): Leave certs generation to nixos | Soispha | 2023-06-25 | |
| | ||||
* | Fix(system/services/git-sync): Use correct systemd options | Soispha | 2023-06-25 | |
| | ||||
* | Fix(system/services/git-sync): Switch to str to avoid impurity | Soispha | 2023-06-25 | |
| | ||||
* | Fix(system/services/git-sync): Purge assertion, as we're always on linux | Soispha | 2023-06-25 | |
| | ||||
* | Fix(system/services/nginx): Actually enable git-sync | Soispha | 2023-06-25 | |
| | ||||
* | Fix(system/services/minecraft): Reduce simulation-distance | sils | 2023-06-19 | |
| | ||||
* | Fix(system/services/minecraft): Finetuning | sils | 2023-06-19 | |
| | ||||
* | Fix(system/services): Allow minecraft-server, which is sadly unfree | sils | 2023-06-19 | |
| | ||||
* | Fix(system/services): Ignore unnecessary inputs | sils | 2023-06-19 | |
| | ||||
* | Feat(system/services): Add minecraft server | sils | 2023-06-19 | |
| | ||||
* | Refactor(services): Remove dead code | Soispha | 2023-06-18 | |
| | ||||
* | Fix(system/services/acme): Add multiple domains | Soispha | 2023-06-17 | |
| | ||||
* | Fix(system/services/nginx): Switch to git-sync | Soispha | 2023-06-17 | |
| | ||||
* | Feat(system/services/git-sync): Add | Soispha | 2023-06-17 | |
| | ||||
* | Merge branch 'keycloak' into develop | sils | 2023-06-06 | |
|\ | ||||
| * | Fix(system/services/keycloak): Correct path to passwordfile | sils | 2023-06-06 | |
| | | ||||
| * | Fix(system/services/keycloak): Change value of 'passwordFile' to path | sils | 2023-06-06 | |
| | | ||||
| * | Feat(system/services): Enable keycloak | sils | 2023-06-06 | |
| | | ||||
| * | Feat(system/services/keycloak): Add keycloak | sils | 2023-06-06 | |
| | | ||||
| * | Feat(system/file_system_layout): Add bindmount for postgresql | sils | 2023-06-06 | |
| | | ||||
* | | Feat(system/packages): Add git-crypt to standard packages to minimize | sils | 2023-06-06 | |
|/ | | | | pain while rebuilding | |||
* | Fix(system/services/opensshd): Rename passwordAuthentication to | sils | 2023-06-06 | |
| | | | | settings.PassowrdAuthentication | |||
* | Fix(system/mail): give certificateScheme string as value | sils | 2023-06-06 | |
| | ||||
* | Fix(system/packages): Explicitly enable zsh to make Nix Vars available | sils | 2023-06-06 | |
| | ||||
* | Revert: Remove Conduit | sils | 2023-06-06 | |
| | | | | | | It didn't deploy either and we'd probably use synapse anyway This reverts commit fbba7df4b7c9de5b1926612647e1d9d06b7d22cf. | |||
* | Feat(system/matrix/conduit): Add matrix-conduit | Soispha | 2023-05-20 | |
| | ||||
* | Style(system): Format | Soispha | 2023-05-20 | |
| | ||||
* | Refactor(system/mail): Hide user emails | Soispha | 2023-05-20 | |
| | ||||
* | Fix(system/services/nginx): Correct path to index.html | sils | 2023-04-21 | |
| | ||||
* | Feat(system/services/nginx): Change to declarative websites | Soispha | 2023-04-19 | |
| | ||||
* | Fix(system/mail): Allow opening ports in the firewall | ene | 2023-04-07 | |
| | | | | | | | | | | | As the previous configuration only opened some ports, receiving mail was impossible. This allows NSM to open the required ports directly, ensuring that none was missed. SECURITY: As all other options than SSL are still disabled, this change should not introduce unencrypted mail transfer. This has not been tested. | |||
* | Fix(system/services/rust-motd): Quote ssl-cert names | ene | 2023-03-25 | |
| | ||||
* | Feat(system/services/rust-motd): Info about filesystems | ene | 2023-03-25 | |
| | ||||
* | Feat(system/services/rust-motd): Show status of ssl-certs | ene | 2023-03-25 | |
| | ||||
* | Fix(system/services/rust-motd): Add fail2ban binary | ene | 2023-03-25 | |
| | ||||
* | Feat(system/services/fail2ban): Add dovecot jail | ene | 2023-03-25 | |
| | | | | This should reduce the log spam even further. | |||
* | Fix(system/services/fail2ban): Make db persistent | ene | 2023-03-25 | |
| | ||||
* | Feat(system/services/fail2ban): Add fail2ban | ene | 2023-03-25 | |
| | | | | This should clear the logs somewhat. | |||
* | Fix(acme): Store certs permanently. | sils | 2023-03-20 | |
| | | | | | Before, new certs were requested at every rebuild. This caused issues due to letsencrypt ratelimiting. | |||
* | Revert "Fix(system/mail): Change placeholder" | sils | 2023-03-20 | |
| | | | | | | This reverts commit ecb274ba49042f1dfdf63b9c54ff6920f24a9a58. It may be a security-risk, but I care much more about a running mailserver for now. | |||
* | Fix(system/mail): Change placeholder | ene | 2023-03-20 | |
| | | | | The old one, could have exposed a weak hash. | |||
* | Refactor(system/hardware): Move hardware to host | ene | 2023-03-19 | |
| | | | | | The hardware settings are (somewhat) host specific, and putting them in `system` just builds the wrong expectations. | |||
* | Fix(system/hardware): Use actually needed modules and UUID | ene | 2023-03-19 | |
| | | | | | The old values did work, but these should just make things a bit clearer. | |||
* | Fix(system/services/minecraft): Remove to make compile | ene | 2023-03-19 | |
| | ||||
* | Fix(system/mail): Only accept connections on safe ports | ene | 2023-03-19 | |
| | | | | | It is sort of standard to ignore connections over the unencrypted port 25, thus we are doing the same. | |||
* | Feat(system/mail): Add other users, so the admin thing works | ene | 2023-03-18 | |
| | ||||
* | Style(system/mail): Reorder options | ene | 2023-03-18 | |
| | | | | I just think this is easier to read. | |||
* | Feat(system/mail): Use '/' to separate mailboxes | ene | 2023-03-18 | |
| | | | | | This is something that just makes the file system easier to traverse, but isn't really necessary. | |||
* | Fix(system/mail): Declare the password directly | ene | 2023-03-18 | |
| | | | | | | As outlined in commit 19f0808, placing a password hash in the world readable nix-store is perfectly safe as long as the hashing function is not reversible, which should be a necessity for a password hash. |