From 41c00697305ee4ee910b12a8d7aa803cf09d1a5a Mon Sep 17 00:00:00 2001 From: imnyang Date: Sun, 2 Aug 2026 20:03:19 +0900 Subject: [PATCH] wow --- flake.lock | 169 ++++----- hosts/machine/mizuki/configuration.nix | 2 + hosts/server/hikari/hako/default.nix | 1 + hosts/server/hikari/hako/services/caddy.nix | 327 ++++++++++++++++++ hosts/server/kazusa/services/mailserver.nix | 5 - modules/home/firefox-devedition.nix | 6 +- .../features/packages/docker2libc.nix | 39 +++ modules/mizukios/features/system/boot.nix | 14 + 8 files changed, 474 insertions(+), 89 deletions(-) create mode 100644 hosts/server/hikari/hako/services/caddy.nix create mode 100644 modules/mizukios/features/packages/docker2libc.nix diff --git a/flake.lock b/flake.lock index 79aefc0..692e335 100644 --- a/flake.lock +++ b/flake.lock @@ -3,11 +3,11 @@ "amiaBot": { "flake": false, "locked": { - "lastModified": 1785125005, - "narHash": "sha256-ukQsV27B7IdZkjLfY20HPIgybBt6zve7jqi3QDDc64o=", + "lastModified": 1785639691, + "narHash": "sha256-xf3jTLY5gPmdOIlWoHLrgRFkdrz1n1YggCi3Z81JZ1A=", "ref": "refs/heads/main", - "rev": "25bdd14067f9eb9d05e332ee41d88b9d71741aff", - "revCount": 7, + "rev": "2ee718a3bf4b0a721978be6b2defc9e87012492b", + "revCount": 8, "type": "git", "url": "ssh://forgejo@mizuki.guru/imnyang/amia" }, @@ -19,16 +19,16 @@ "brew-src": { "flake": false, "locked": { - "lastModified": 1784558651, - "narHash": "sha256-woXJ1ATKpSYRWCy46TQJjmm9XzAeZVEZw9xDfVG9NYI=", + "lastModified": 1785146564, + "narHash": "sha256-Sa7/HrfB04H32OJ7/ofxXjiZEbkWtCNOriONYYTL1OA=", "owner": "Homebrew", "repo": "brew", - "rev": "b48c7994b5f0eed7bef532efa63cb4e4f763887a", + "rev": "b2cfc03346d482f79886de108fee5dc49a6efc10", "type": "github" }, "original": { "owner": "Homebrew", - "ref": "6.0.12", + "ref": "6.0.13", "repo": "brew", "type": "github" } @@ -38,11 +38,11 @@ "nixpkgs": "nixpkgs" }, "locked": { - "lastModified": 1784366307, - "narHash": "sha256-VKatYOZwLQ+MuNkWH6/gZYxrNeSK1Mqb7mC0H1WSu+M=", + "lastModified": 1785485193, + "narHash": "sha256-JgUmb34d3Zv1W5fYukqEUEDHSaWhw7WV9HVUXOmOCaA=", "owner": "catppuccin", "repo": "nix", - "rev": "673f730d0fc8db3468c51575f1d3d777cc55e51f", + "rev": "41c4ebf8cb3e4052001947a457b4ac093e5dc119", "type": "github" }, "original": { @@ -57,11 +57,11 @@ "nixpkgs": "nixpkgs_2" }, "locked": { - "lastModified": 1784981070, - "narHash": "sha256-BB3If4U5avDjQ/Ufnp+GquYqbIZP3LpbbYqs49E6cKQ=", + "lastModified": 1785621037, + "narHash": "sha256-9T3/l1/PrfpayWhXAAZNfxTfZ1gcgiYZ1Q2Q34iNkb4=", "owner": "ilysenko", "repo": "codex-desktop-linux", - "rev": "ef284ae8dc07917c42b2e6b6435e4820280df989", + "rev": "c4581195c2bfec50a271f59146f680b9a0ebdd03", "type": "github" }, "original": { @@ -77,11 +77,11 @@ ] }, "locked": { - "lastModified": 1784500460, - "narHash": "sha256-UvORnAxTRHax7RG74W8Z2t4GvIkX6AjJ5kk0QlwZomo=", + "lastModified": 1785389976, + "narHash": "sha256-0tLW8Ff5yt8AH97jw4ZpFJ0OCJ122zIlgWGDmOfU/VU=", "owner": "nix-darwin", "repo": "nix-darwin", - "rev": "57a3171f94705599a2499248ca5758d5eb47c0e0", + "rev": "15abb8c98f336cd8bd840d71059adebabe60bf04", "type": "github" }, "original": { @@ -91,20 +91,6 @@ } }, "flake-compat": { - "locked": { - "lastModified": 1733328505, - "narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=", - "rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec", - "revCount": 69, - "type": "tarball", - "url": "https://api.flakehub.com/f/pinned/edolstra/flake-compat/1.1.0/01948eb7-9cba-704f-bbf3-3fa956735b52/source.tar.gz" - }, - "original": { - "type": "tarball", - "url": "https://flakehub.com/f/edolstra/flake-compat/1.tar.gz" - } - }, - "flake-compat_2": { "flake": false, "locked": { "lastModified": 1767039857, @@ -120,7 +106,7 @@ "type": "github" } }, - "flake-compat_3": { + "flake-compat_2": { "flake": false, "locked": { "lastModified": 1767039857, @@ -215,11 +201,11 @@ ] }, "locked": { - "lastModified": 1784913159, - "narHash": "sha256-JWq0BfjO4ktpH5USfQNQzdvHpIDT8fSKD5K7LvdMRFs=", + "lastModified": 1785531816, + "narHash": "sha256-vkMnV0JIyw+g/NmcfoajlGaAO+9a0ezia+FZohQJrik=", "owner": "nix-community", "repo": "home-manager", - "rev": "079a3b5d1aa6a719920a51316253b7d6dd22738d", + "rev": "bf9ce9fec78f95f374e8dd3b503863a3ec128ebe", "type": "github" }, "original": { @@ -271,11 +257,11 @@ }, "locked": { "dir": "packages/nix", - "lastModified": 1784860807, - "narHash": "sha256-nznQFS9H8er9bTwxKG4LSa2D0lGsxIPUqDuWa1rbJkA=", + "lastModified": 1785163789, + "narHash": "sha256-nHTGaYBPKqOY4SPTqRJNX8MfV/GuIjgPCUxDHHeinGc=", "owner": "SteamClientHomebrew", "repo": "Millennium", - "rev": "266e41ea8924c41e51145ae986a9bdf68f9415d9", + "rev": "1375ceda332171907e64e9a9324f9a869f715d6c", "type": "github" }, "original": { @@ -326,11 +312,11 @@ "nixpkgs": "nixpkgs_6" }, "locked": { - "lastModified": 1783821302, - "narHash": "sha256-yrlsrPvCUBUS6minT8VBMemHa47qzXRcHdzvYzRTSTo=", + "lastModified": 1785240044, + "narHash": "sha256-k2NeeoGaLJ9o8SwDGoH7r7e+8YiYG2qTMJx6ORfKwTE=", "owner": "imnyang", "repo": "muvel-nix", - "rev": "90f3b4f37c57d0c73dfd4131c6d190147654e1df", + "rev": "c07bdb4bb3e897e07924457f36ec215a8d4649a2", "type": "github" }, "original": { @@ -359,11 +345,11 @@ "brew-src": "brew-src" }, "locked": { - "lastModified": 1784906761, - "narHash": "sha256-2v0H8+Ert+xbm0oliHblXTPPczuKiibBUBvRax59kxg=", + "lastModified": 1785544760, + "narHash": "sha256-qV6OoNuly4ntqpCg7esIeJjUboxSnQNlLPxz+y5h9/o=", "owner": "zhaofengli", "repo": "nix-homebrew", - "rev": "60623ec512406261f553d24033c8a0c53fd0b7f2", + "rev": "937ce52c7d046310571f3a070713804ead496843", "type": "github" }, "original": { @@ -374,17 +360,17 @@ }, "nixcord": { "inputs": { - "flake-compat": "flake-compat", "flake-parts": "flake-parts", "nixpkgs": "nixpkgs_7", - "nixpkgs-nixcord": "nixpkgs-nixcord" + "nixpkgs-nixcord": "nixpkgs-nixcord", + "treefmt-nix": "treefmt-nix" }, "locked": { - "lastModified": 1784998108, - "narHash": "sha256-Bcplstv6cEphwzggdZ2LB3sZDimmF/QkaVkW9qk17no=", + "lastModified": 1785665023, + "narHash": "sha256-oIh4qaMSUaeyYHVZ8MyO6s6WTGKSUACVwDPT/4qEeAU=", "owner": "FlameFlag", "repo": "nixcord", - "rev": "cca6d30eb701c1189f046f7d22f24ba85a6e07e3", + "rev": "87f4db7b3135b815a2969e99ef493fe3a663af7d", "type": "github" }, "original": { @@ -395,7 +381,7 @@ }, "nixos-wsl": { "inputs": { - "flake-compat": "flake-compat_2", + "flake-compat": "flake-compat", "nixpkgs": "nixpkgs_8" }, "locked": { @@ -415,11 +401,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1783279667, - "narHash": "sha256-2l8yOB5aYd+05Q9V9Y1YhgbSa1j1o5QX+nvYs5FL80A=", - "rev": "f205b5574fd0cb7da5b702a2da51507b7f4fdd1b", + "lastModified": 1785301185, + "narHash": "sha256-PlAXr9kpfXhMFU0OQ7qtE8FhLQo21WXFVGqIC85UFyc=", + "rev": "9bc02893134c733dd85de46ee4fb2fac696b5529", "type": "tarball", - "url": "https://releases.nixos.org/nixpkgs/nixpkgs-26.11pre1028110.f205b5574fd0/nixexprs.tar.xz" + "url": "https://releases.nixos.org/nixpkgs/nixpkgs-26.11pre1043539.9bc02893134c/nixexprs.tar.xz" }, "original": { "type": "tarball", @@ -475,11 +461,11 @@ }, "nixpkgs-nixcord": { "locked": { - "lastModified": 1784432872, - "narHash": "sha256-n3gKTBIV4ZA5VQpUakffBe3KGu4+mhPoA34rrqS0GkA=", + "lastModified": 1785386831, + "narHash": "sha256-sPS3CaXH8RAT3FZRuy4VcV47iuYIWMMfa0GbyJKC3o4=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "fd1462031fdee08f65fd0b4c6b64e22239a77870", + "rev": "21ea275a7c46aef9d4d6ddc962e6d562e9d94183", "type": "github" }, "original": { @@ -507,11 +493,11 @@ }, "nixpkgs_11": { "locked": { - "lastModified": 1784356753, - "narHash": "sha256-zupdTm41be2fY8cexroEOGjopl3F2Gqs3gk7ieqaM3s=", - "rev": "61b7c44c4073f0b827768aff0049561b5110ea5a", + "lastModified": 1785571196, + "narHash": "sha256-xwSqxTsama0YTtS78+4YyCm6jJg09v78QWfP1cAyoVA=", + "rev": "148bab9c1c3c53136ecb44a6ea356a0ed5b39b06", "type": "tarball", - "url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1036777.61b7c44c4073/nixexprs.tar.xz" + "url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1045728.148bab9c1c3c/nixexprs.tar.xz" }, "original": { "type": "tarball", @@ -632,27 +618,27 @@ }, "nixpkgs_6": { "locked": { - "lastModified": 1782959384, - "narHash": "sha256-xnJJk+ct+D2+wdRxj1wk36w5zV9RVESwRqcklPdt3fM=", + "lastModified": 1785104993, + "narHash": "sha256-eKbrvPoAOFutbYMdbB3r5EQVmFxKv24iKqHPPUXA0gM=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "65179426c83bb3f6bc14898b42ea1c6f01d374b0", + "rev": "8623c4c20aa4ca2f5fb81510d2944066c3fb0d96", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-unstable", + "ref": "nixos-26.05", "repo": "nixpkgs", "type": "github" } }, "nixpkgs_7": { "locked": { - "lastModified": 1784432872, - "narHash": "sha256-n3gKTBIV4ZA5VQpUakffBe3KGu4+mhPoA34rrqS0GkA=", + "lastModified": 1785386831, + "narHash": "sha256-sPS3CaXH8RAT3FZRuy4VcV47iuYIWMMfa0GbyJKC3o4=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "fd1462031fdee08f65fd0b4c6b64e22239a77870", + "rev": "21ea275a7c46aef9d4d6ddc962e6d562e9d94183", "type": "github" }, "original": { @@ -680,11 +666,11 @@ }, "nixpkgs_9": { "locked": { - "lastModified": 1784796856, - "narHash": "sha256-wWFrV5/Qbm+lyt5x20E/bSbfJiGKMo4RCxZV8cl/WZI=", + "lastModified": 1785571196, + "narHash": "sha256-KoTsyMQqnXQZq8deCEnu4QkyldkwH/bpMMhUcfMdGIw=", "owner": "nixos", "repo": "nixpkgs", - "rev": "e2587caef70cea85dd97d7daab492899902dbf5d", + "rev": "148bab9c1c3c53136ecb44a6ea356a0ed5b39b06", "type": "github" }, "original": { @@ -866,11 +852,11 @@ "systems": "systems_4" }, "locked": { - "lastModified": 1784481035, - "narHash": "sha256-nC0QN+GPTnA5i+WBx8S2rG8+VFh+EeBnEe5mU3hlAcQ=", + "lastModified": 1785652745, + "narHash": "sha256-pD0VE/XwjQ3tLyxTzXKdm6JuIEWr/Jaote6xpXGZrXk=", "owner": "Gerg-L", "repo": "spicetify-nix", - "rev": "a6baa7464f9b21a106dcfabb0bdcfe96fb434409", + "rev": "802040514e09bb8539237f52f68cf053b987c65e", "type": "github" }, "original": { @@ -969,6 +955,27 @@ "type": "github" } }, + "treefmt-nix": { + "inputs": { + "nixpkgs": [ + "nixcord", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1785360170, + "narHash": "sha256-XE1lKgQ3eIO3E7zWryqcRsax+mYXod/5RHBn4YaR9YE=", + "owner": "numtide", + "repo": "treefmt-nix", + "rev": "d1187f8bc71fb8aab02395869ec3f5c1920f75c0", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "treefmt-nix", + "type": "github" + } + }, "vicinae": { "inputs": { "nixpkgs": "nixpkgs_12", @@ -976,11 +983,11 @@ "systems": "systems_5" }, "locked": { - "lastModified": 1785004009, - "narHash": "sha256-VjnxwcdpTINauc6eq4vSez3zeXpNClEQqKUlAYr2WIU=", + "lastModified": 1785357589, + "narHash": "sha256-gSnnTuV07zUVspSBs3lqub496ulxaI919DPSc2pZTEY=", "owner": "vicinaehq", "repo": "vicinae", - "rev": "1644a0b8b251c10a14c5a329916496836748c531", + "rev": "def25a330d5b5dc6ccef78b3be7949ce9bb74881", "type": "github" }, "original": { @@ -991,7 +998,7 @@ }, "vicinae-extensions": { "inputs": { - "flake-compat": "flake-compat_3", + "flake-compat": "flake-compat_2", "nixpkgs": [ "nixpkgs" ], @@ -999,11 +1006,11 @@ "vicinae": "vicinae_2" }, "locked": { - "lastModified": 1784504910, - "narHash": "sha256-fzPBEJZiRvc/FNMdpbdcfaZzF01U4IQenHW9IQFzhos=", + "lastModified": 1785650543, + "narHash": "sha256-u2VtHkzueezRNZIfn0HVA2WCZtSt3VKusAjhaPWvDl4=", "owner": "vicinaehq", "repo": "extensions", - "rev": "ca74eede9a778a9373c8f5fd221b0a5026dcd1ef", + "rev": "7b5905d08a2c9fda456b2e66894ba3e17997a6cb", "type": "github" }, "original": { diff --git a/hosts/machine/mizuki/configuration.nix b/hosts/machine/mizuki/configuration.nix index 8c93bcd..bd09038 100644 --- a/hosts/machine/mizuki/configuration.nix +++ b/hosts/machine/mizuki/configuration.nix @@ -61,5 +61,7 @@ services.flatpak.enable = true; + hardware.nvidia-container-toolkit.enable = true; + system.stateVersion = "26.05"; } diff --git a/hosts/server/hikari/hako/default.nix b/hosts/server/hikari/hako/default.nix index bf4cf57..594acb7 100644 --- a/hosts/server/hikari/hako/default.nix +++ b/hosts/server/hikari/hako/default.nix @@ -12,6 +12,7 @@ nixpkgs.lib.nixosSystem { ./services/forgejo.nix ./services/immich.nix ./services/attic.nix + ./services/caddy.nix ./services/postgresql.nix ./services/nc.nix diff --git a/hosts/server/hikari/hako/services/caddy.nix b/hosts/server/hikari/hako/services/caddy.nix new file mode 100644 index 0000000..bcca6da --- /dev/null +++ b/hosts/server/hikari/hako/services/caddy.nix @@ -0,0 +1,327 @@ +{ pkgs, ... }: + +let + errorHandlers = '' + handle_errors { + @unauthorized expression {http.error.status_code} == 401 + handle @unauthorized { + rewrite * /401.html + root * /var/static/error + header Hey "Are you Hacker??? 😠" + file_server + } + + @notFound expression {http.error.status_code} == 404 + handle @notFound { + rewrite * /404.html + root * /var/static/error + file_server + } + + @gone expression {http.error.status_code} == 410 + handle @gone { + rewrite * /410.html + root * /var/static/error + file_server + } + + @serverError expression {http.error.status_code} in [500, 502, 504, 505] + handle @serverError { + rewrite * /server.html + root * /var/static/error + file_server + } + + @clientError expression {http.error.status_code} in [403, 405, 411, 497] + handle @clientError { + rewrite * /client.html + root * /var/static/error + file_server + } + } + ''; + + withErrors = config: '' + ${config} + + ${errorHandlers} + ''; + + reverseProxy = + upstream: + withErrors '' + reverse_proxy ${upstream} + ''; + + reverseProxyWithHeaders = + upstream: + withErrors '' + reverse_proxy ${upstream} { + header_up Host {host} + header_up X-Real-IP {remote_host} + header_up X-Forwarded-For {remote_host} + header_up X-Forwarded-Proto {scheme} + header_up Upgrade {>Upgrade} + header_up Connection {>Connection} + } + ''; + + staticHost = host: { + extraConfig = withErrors '' + root * /var/static/${host} + + @notExist { + not file + not file {path}/ + } + + handle @notExist { + rewrite * /410.html + root * /var/static/error + file_server + } + + file_server + + @txt path *.txt + header @txt Content-Type "text/plain; charset=utf-8" + + header { + Access-Control-Allow-Origin * + Access-Control-Allow-Methods "GET, POST, PUT, DELETE, OPTIONS" + Access-Control-Allow-Headers "Content-Type, Authorization" + Access-Control-Max-Age 3600 + } + ''; + }; + + # These were previously served by *.imnya.ng. Listing them explicitly lets + # stock Caddy obtain an individual certificate without a DNS challenge. + staticHosts = [ + "26layer7beginner.imnya.ng" + "alt.imnya.ng" + "dday.imnya.ng" + "download.imnya.ng" + "f.imnya.ng" + "hako.imnya.ng" + "ilovecloudflare.imnya.ng" + "img.imnya.ng" + "jongyeol.imnya.ng" + "letters.imnya.ng" + "log.imnya.ng" + "nixos.imnya.ng" + "pack.imnya.ng" + "pf.imnya.ng" + "potato.imnya.ng" + "sometesting.imnya.ng" + "spam.imnya.ng" + "twohearts.imnya.ng" + "whs.imnya.ng" + ]; +in +{ + services.caddy = { + enable = true; + email = "imnyang@pm.me"; + openFirewall = true; + package = pkgs.caddy; + + virtualHosts = + builtins.listToAttrs ( + map (host: { + name = host; + value = staticHost host; + }) staticHosts + ) + // { + "api.imnya.ng".extraConfig = reverseProxyWithHeaders "10.11.8.101:1108"; + "nou.imnya.ng".extraConfig = reverseProxyWithHeaders "10.11.8.101:6974"; + "docs.imnya.ng".extraConfig = reverseProxy "100.70.1.1:3939"; + "panel.imnya.ng".extraConfig = reverseProxy "127.0.0.1:32981"; + "monitorss.imnya.ng".extraConfig = reverseProxy "127.0.0.1:3132"; + + "imnya.ng".extraConfig = withErrors '' + handle_path /.well-known/webfinger { + root * /var/www/imnya.ng + file_server + } + + root * /var/static/imnya.ng + file_server { + index index.html + } + + redir /testtesttest "https://docs.google.com/forms/d/e/1FAIpQLScFDIU151s-CwKZccCET0kfdPigluiGb8BY7vL2US85dAgmhw/viewform?entry.2088744905=test" 302 + redir /discord https://api.imnya.ng/discord_invite 302 + redir /al https://f.imnya.ng/archlinux/install 302 + redir /a https://cloud.hrts.kr/s/ZSHcpHgb9jdtaMR 302 + redir /당신은김치찌개의무구한역사를자의적으로이해할수있습니까 https://www.figma.com/deck/LtnSWN6FHhHhTMIPECkdKT 302 + redir /tree https://colormytree.me/2025/01KB8E3N0YS1X4EQZDZQ855HAG 302 + redir /memos https://discord.gg/CrSjzppDed 302 + redir /ctf/29hackcampwriteup "https://imneko.notion.site/29-CTF-31ca3fe0643b809291d2c7c3a1a818b6?source=copy_link" 302 + redir /ctf/2025logcon "https://imneko.notion.site/2025-LOGCON-Write-UP-17fa3fe0643b80c0833adf1bd85f46fa?source=copy_link" 302 + redir /ctf/2024layer7 "https://imneko.notion.site/2024-Layer7-CTF-177a3fe0643b802d96d9e255f32bf034?pvs=74" 302 + ''; + + "cdn-wiki.tpr.kr".extraConfig = withErrors '' + handle_path /i/* { + rewrite * /thetree/i{uri} + reverse_proxy 127.0.0.1:9000 + } + ''; + + "tts.imnya.ng".extraConfig = '' + reverse_proxy 10.11.8.30:8080 + ''; + + "vw.imnya.ng".extraConfig = reverseProxy "127.0.0.1:30505"; + + "jongyeoliswebscale.imnya.ng".extraConfig = withErrors '' + basic_auth { + jongyeol $2a$10$I00t8tJJLrcl4jZznO/XmOtd84uGAeJxL71wbN/sYksFrAvZ08n0q + } + + reverse_proxy 10.20.31.48:3001 { + header_up Host {host} + header_up X-Real-IP {remote_host} + header_up X-Forwarded-For {remote_host} + header_up X-Forwarded-Proto {scheme} + header_up Upgrade {>Upgrade} + header_up Connection {>Connection} + } + ''; + + "auth.imnyang.dev".extraConfig = reverseProxy "10.11.8.25:3000"; + "imnyang.dev".extraConfig = reverseProxy "82.21.82.30:3000"; + "wiki.imnyang.dev".extraConfig = reverseProxy "10.11.8.150:51337"; + + "adofai.gay".extraConfig = withErrors '' + handle_path /.well-known/discord { + respond "dh=81062ffb49f63e8b7310905aee38aada33a68edb" 200 + header Content-Type text/plain + } + + redir https://7thbe.at/#adofai 302 + ''; + + "wiki.tpr.kr".extraConfig = reverseProxy "127.0.0.1:51337"; + + "imlo.li".extraConfig = withErrors '' + handle /rpmfusion.sh { + root * /var/static/scripts + file_server + } + + handle { + reverse_proxy 127.0.0.1:4000 + } + ''; + + "http://117.110.40.206".extraConfig = ""; + + "event.dazzle.st".extraConfig = '' + reverse_proxy 127.0.0.1:9794 + ''; + + "plutos.dazzle.st".extraConfig = '' + reverse_proxy 10.11.8.200:3000 + ''; + + "multiplay.rpc.dazzle.st".extraConfig = '' + @preflight method OPTIONS + + header { + Access-Control-Allow-Origin * + Access-Control-Allow-Methods "GET, POST, PUT, PATCH, DELETE, OPTIONS" + Access-Control-Allow-Headers * + } + + respond @preflight "" 204 + reverse_proxy 10.20.30.101:6769 + ''; + + "t.hrts.kr".extraConfig = reverseProxy "10.11.8.101:4041"; + "wakapi.hrts.kr".extraConfig = reverseProxy "127.0.0.1:13000"; + "ziit.hrts.kr".extraConfig = reverseProxy "127.0.0.1:6030"; + "hikari-panel.hrts.kr".extraConfig = reverseProxy "10.11.8.104:8080"; + + "http://hikari.icn.hrts.kr".extraConfig = withErrors '' + respond "우응" 200 + ''; + + "pve.hrts.kr".extraConfig = withErrors '' + reverse_proxy https://10.11.8.100:8006 { + header_up X-Real-Ip {remote_host} + header_up X-Http-Version {http.request.proto} + transport http { + tls_insecure_skip_verify + } + } + ''; + + "auth.hrts.kr".extraConfig = reverseProxy "10.11.8.32:1411"; + "git.hrts.kr".extraConfig = reverseProxy "127.0.0.1:3000"; + "api-ftp.hrts.kr".extraConfig = reverseProxy "10.11.8.101:25716"; + "panel.hrts.kr".extraConfig = reverseProxy "127.0.0.1:3929"; + "pgadmin.hrts.kr".extraConfig = reverseProxy "127.0.0.1:5050"; + "al-1s.hrts.kr".extraConfig = reverseProxy "127.0.0.1:9120"; + + "hrts.kr".extraConfig = withErrors '' + redir / https://imnya.ng 302 + redir /whyididmakethis.md "https://md.imnya.ng/?c=唣𣏫𧆘𡚴唿𢓬𧆬𣺯𢓬𧊈𣪖㸿堊𧈠𠪕𢷬𧆁𠪏𧈠𣪝𣣪喌𢓬𧆬𣺯𢓬𧊈𣪖㸿" 302 + ''; + + "cloud.hrts.kr".extraConfig = '' + redir https://cloud.mizuki.guru{uri} + ''; + + "i.mizuki.guru".extraConfig = reverseProxy "127.0.0.1:10040"; + "git.mizuki.guru".extraConfig = reverseProxy "127.0.0.1:3000"; + "cloud.mizuki.guru".extraConfig = reverseProxy "10.11.8.100:60300"; + + "mizuki.guru".extraConfig = withErrors '' + redir / https://akiyama.mizuki.guru 302 + reverse_proxy /_matrix* 127.0.0.1:6167 + ''; + + "api.kanade.mizuki.guru".extraConfig = reverseProxy "10.20.31.41:3000"; + + "akiyama.mizuki.guru".extraConfig = withErrors '' + handle /api { + reverse_proxy 10.11.8.121:1108 + } + + handle /api/* { + reverse_proxy 10.11.8.121:1108 + } + + handle { + reverse_proxy 10.11.8.121:3000 + } + ''; + + "cache.mizuki.guru".extraConfig = reverseProxy "127.0.0.1:8080"; + + "phrygiacomo.mizuki.guru".extraConfig = withErrors '' + basic_auth { + imnyang $2a$10$zA83XKt84pcXiwfkuvNmKOpQ5Cw0IP6m/.1AX0ahkVQaPOzrmFlxm + } + + reverse_proxy 10.20.31.103:3000 + ''; + + "http://hikari.icn.mizuki.guru".extraConfig = withErrors '' + respond "우응" 200 + ''; + + "fs.mizuki.guru".extraConfig = reverseProxy "10.11.8.121:9000"; + + "broadcast.epc.mizuki.guru".extraConfig = '' + reverse_proxy 10.20.30.101:1234 + ''; + + "apijongyeoltts.mizuki.guru".extraConfig = reverseProxy "10.20.30.103:9880"; + "demo.mizuki.guru".extraConfig = reverseProxy "10.20.30.103:3000"; + }; + }; +} diff --git a/hosts/server/kazusa/services/mailserver.nix b/hosts/server/kazusa/services/mailserver.nix index c4a03f6..10542c6 100644 --- a/hosts/server/kazusa/services/mailserver.nix +++ b/hosts/server/kazusa/services/mailserver.nix @@ -137,11 +137,6 @@ in ]; oauth2_tokeninfo_url = "https://auth.mizuki.guru/application/o/userinfo/?access_token="; - - # 주의: - # 여기는 아직 secret '값'이 아니라 secret '경로'가 들어감. - # Dovecot이 URL 안에서 file_get_contents 같은 처리를 안 하므로 - # 이 방식은 제대로 동작하지 않을 가능성이 큼. oauth2_introspection_url = "https://auth.mizuki.guru/application/o/introspect/"; oauth2_introspection_mode = "post"; diff --git a/modules/home/firefox-devedition.nix b/modules/home/firefox-devedition.nix index 2bf305e..337eeb4 100644 --- a/modules/home/firefox-devedition.nix +++ b/modules/home/firefox-devedition.nix @@ -9,13 +9,13 @@ ExtensionSettings = { "figma-windows-ua-spoofer@imnyang.local" = { - installation_mode = "force_installed"; + installation_mode = "normal_installed"; install_url = "https://git.mizuki.guru/imnyang/thisiswindowsfigma/releases/download/v1.0.0/d168a70cb6a24fe4a478-1.0.0.xpi"; }; "thisiswindowschromiumnetflix@imnya.ng" = { - installation_mode = "force_installed"; - install_url = "https://git.mizuki.guru/imnyang/thisiswindowschromiumnetflix/releases/download/v2026.07.27/b30e361a21474a79be8d-2026.7.27.xpi"; + installation_mode = "normal_installed"; + install_url = "https://git.mizuki.guru/imnyang/thisischromiumnetflix/releases/download/v2026.07.27.1/b30e361a21474a79be8d-2026.7.27.1.xpi"; }; }; }; diff --git a/modules/mizukios/features/packages/docker2libc.nix b/modules/mizukios/features/packages/docker2libc.nix new file mode 100644 index 0000000..f3de70a --- /dev/null +++ b/modules/mizukios/features/packages/docker2libc.nix @@ -0,0 +1,39 @@ +{ pkgs }: +pkgs.writeShellApplication { + name = "nr"; + + runtimeInputs = with pkgs; [ + nix-output-monitor + openssh + coreutils + nix + attic-client + ]; + + text = '' + #!/usr/bin/env bash + set -euo pipefail + + image="${1:-tmp-elf-extract}" + + docker build -t "$image" . + + cid="$(docker create "$image" /bin/true)" + cleanup() { + docker rm -f "$cid" >/dev/null 2>&1 || true + } + trap cleanup EXIT + + libc_path="$(docker run --rm --entrypoint /bin/sh "$image" -c 'for p in /lib/x86_64-linux-gnu/libc.so.6 /usr/lib/x86_64-linux-gnu/libc.so.6 /lib64/libc.so.6 /lib/libc.so.6; do if [ -e "$p" ]; then echo "$p"; exit 0; fi; done; exit 1')" + ld_path="$(docker run --rm --entrypoint /bin/sh "$image" -c 'for p in /lib64/ld-linux-x86-64.so.2 /lib/x86_64-linux-gnu/ld-linux-x86-64.so.2 /lib/ld-linux-x86-64.so.2; do if [ -e "$p" ]; then echo "$p"; exit 0; fi; done; find /lib /usr/lib /lib64 -type f \( -name "ld-linux*.so*" -o -name "ld-*.so*" \) 2>/dev/null | head -n 1')" + + [ -n "$libc_path" ] || { echo "libc.so.6 not found" >&2; exit 1; } + [ -n "$ld_path" ] || { echo "ld-linux not found" >&2; exit 1; } + + docker cp -L "${cid}:${libc_path}" ./libc.so.6 + docker cp -L "${cid}:${ld_path}" ./ld-linux-x86-64.so.2 + + file libc.so.6 ld-linux-x86-64.so.2 + ls -lh libc.so.6 ld-linux-x86-64.so.2 + ''; +} diff --git a/modules/mizukios/features/system/boot.nix b/modules/mizukios/features/system/boot.nix index 5e416b1..13769fa 100644 --- a/modules/mizukios/features/system/boot.nix +++ b/modules/mizukios/features/system/boot.nix @@ -20,6 +20,20 @@ extraConfig = '' GRUB_SAVEDEFAULT=true ''; + + extraEntries = '' + menuentry "netboot.xyz" --class netboot { + search --no-floppy --file --set=root /EFI/netboot.xyz/netboot.xyz.efi + chainloader /EFI/netboot.xyz/netboot.xyz.efi + } + ''; + + extraInstallCommands = '' + install -Dm0644 ${pkgs.fetchurl { + url = "https://boot.netboot.xyz/ipxe/netboot.xyz.efi"; + hash = "sha256-ZoAa7s8Xqru8n+ECKjRYg3uzbXTUe02ip+OqeYseM+s="; + }} /boot/EFI/netboot.xyz/netboot.xyz.efi + ''; }; # efi.canTouchEfiVariables = true; efi.efiSysMountPoint = "/boot";