Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
35 lines
1.6 KiB
Nix
35 lines
1.6 KiB
Nix
# Docker host with the daemon socket exposed over the network.
|
|
#
|
|
# SECURITY: the daemon listens on plain TCP 2375 with NO TLS and NO auth. Access
|
|
# to that port is root-equivalent on this host (the Docker API can mount the
|
|
# host filesystem and run privileged containers). The ONLY thing protecting it
|
|
# is the nftables rule below, which accepts 2375 solely from the trusted LAN
|
|
# subnet. Do not widen that subnet to anything you do not fully trust. The
|
|
# secure upgrade path is mutual TLS on 2376 (--tlsverify with client certs);
|
|
# that needs out-of-band cert provisioning and is intentionally not wired here.
|
|
{ ... }:
|
|
{
|
|
virtualisation.docker.enable = true;
|
|
|
|
# Expose the daemon over TCP by extending systemd socket activation rather than
|
|
# setting daemon.settings.hosts. The NixOS docker unit starts dockerd with
|
|
# `-H fd://` and takes its listeners from this socket; putting `hosts` in
|
|
# daemon.json as well would conflict with that and dockerd would refuse to
|
|
# start. Adding the TCP listener here keeps a single source of truth.
|
|
# The leading "" resets the unit's default (unix-socket-only) ListenStream list.
|
|
systemd.sockets.docker.socketConfig.ListenStream = [
|
|
""
|
|
"/run/docker.sock"
|
|
"0.0.0.0:2375"
|
|
];
|
|
|
|
# Source-restricted firewall rule for the Docker TCP port. 2375 is deliberately
|
|
# NOT added to networking.firewall.allowedTCPPorts (that would open it to every
|
|
# source); instead nftables accepts it only from the trusted subnet. Adjust the
|
|
# CIDR to match the LAN that should reach the Docker API.
|
|
networking.nftables.enable = true;
|
|
networking.firewall.extraInputRules = ''
|
|
ip saddr 10.187.1.0/24 tcp dport 2375 accept
|
|
'';
|
|
}
|