summaryrefslogtreecommitdiff
path: root/flora
diff options
context:
space:
mode:
Diffstat (limited to '')
-rw-r--r--flora/services/akkoma.nix28
-rw-r--r--flora/services/blog.nix6
-rw-r--r--flora/services/cgit.nix8
-rw-r--r--flora/services/mail.nix6
-rw-r--r--flora/services/monit.nix16
5 files changed, 44 insertions, 20 deletions
diff --git a/flora/services/akkoma.nix b/flora/services/akkoma.nix
index 6864a29..d7e7b49 100644
--- a/flora/services/akkoma.nix
+++ b/flora/services/akkoma.nix
@@ -114,7 +114,7 @@ in
database = "pleroma";
socket_dir = "/run/postgresql";
pool_size = 10;
- # prepare = ":named";
+ prepare = mkAtom ":named";
show_sensitive_data_on_connection_error = true;
parameters = { plan_cache_mode = "force_custom_plan"; };
};
@@ -166,16 +166,16 @@ in
} ];
settings = {
- max_connections = 20;
- shared_buffers = "256MB";
- effective_cache_size = "768MB";
- maintenance_work_mem = "64MB";
+ max_connections = 300;
+ shared_buffers = "768MB";
+ effective_cache_size = "2304MB";
+ maintenance_work_mem = "192MB";
checkpoint_completion_target = 0.9;
- wal_buffers = "7864kB";
+ wal_buffers = "16MB";
default_statistics_target = 100;
random_page_cost = 1.1;
effective_io_concurrency = 200;
- work_mem = "6553kB";
+ work_mem = "4MB";
huge_pages = "off";
min_wal_size = "2GB";
max_wal_size = "8GB";
@@ -203,8 +203,18 @@ in
networking.firewall.allowedTCPPorts = [ 4000 ];
- environment.etc."resolv.conf".text =
- "nameserver 1.1.1.1";
+ # environment.etc."resolv.conf".text =
+ # "nameserver 1.1.1.1";
+ #
+ # TODO: Possibly?
+ # services.coredns = {
+ # enable = true;
+ # config = ''
+ # .:53 {
+ # forward . 1.1.1.1
+ # }
+ # '';
+ # };
};
};
diff --git a/flora/services/blog.nix b/flora/services/blog.nix
index e77cc7c..89436df 100644
--- a/flora/services/blog.nix
+++ b/flora/services/blog.nix
@@ -6,7 +6,7 @@ let
src = pkgs.fetchgit {
url = "https://stuebinm.eu/git/forks/lux";
rev = "refs/heads/master";
- sha256 = "sha256-L2y5SEGOaoWl+jQGP3TmpQQLojjkRAjiRjbwhGKOg14=";
+ hash = "sha256-ooRgRhs50D6TEFVpL9QfsCUKX/R7dUoETIorJoS9FNY=";
};
buildInputs = [ pkgs.mdbook ];
buildPhase = ''
@@ -27,8 +27,8 @@ let
'';
installPhase = ''
mkdir -p $out
- mv gtfs-book-html $out/gtfs
- mv gtfs-realtime-book-html $out/gtfs-realtime
+ mv /build/gtfs-book-html $out/gtfs
+ mv /build/gtfs-realtime-book-html $out/gtfs-realtime
cp -r ${lux.outPath} $out/lux
'';
};
diff --git a/flora/services/cgit.nix b/flora/services/cgit.nix
index b846ad4..5ee8103 100644
--- a/flora/services/cgit.nix
+++ b/flora/services/cgit.nix
@@ -2,7 +2,13 @@
let
cgitconf = ''
- source-filter=${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py
+ source-filter=${pkgs.writeScript ''highlighter'' ''
+ if [[ $1 == *.thy ]]; then
+ ${pkgs.isabelle-utils}/bin/isabelle2unicode | ${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py "$1"
+ else
+ ${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py "$1"
+ fi
+ ''}
about-filter=${pkgs.cgit}/lib/cgit/filters/about-formatting.sh
cache-size=1000
logo=/git/cgit.png
diff --git a/flora/services/mail.nix b/flora/services/mail.nix
index 0ee8418..4705e25 100644
--- a/flora/services/mail.nix
+++ b/flora/services/mail.nix
@@ -12,15 +12,11 @@
# A list of all login accounts. To create the password hashes, use
# nix run nixpkgs.apacheHttpd -c htpasswd -nbB "" "super secret password" | cut -d: -f2
- loginAccounts = {
+ accounts = {
"hello@stuebinm.eu" = {
hashedPasswordFile = "/run/secrets/mail/hashedPassword";
aliases = ["postmaster@stuebinm.eu" "abuse@stuebinm.eu"];
};
};
-
- # Use Let's Encrypt certificates. Note that this needs to set up a stripped
- # down nginx and opens port 80.
- certificateScheme = "acme-nginx";
};
}
diff --git a/flora/services/monit.nix b/flora/services/monit.nix
index cc5f3c4..e67f424 100644
--- a/flora/services/monit.nix
+++ b/flora/services/monit.nix
@@ -30,11 +30,23 @@
if failed port 443 with protocol https
then alert
- check host nobelium with address colorspace.club
+ check host erpu.eu with address erpu.eu
if failed port 443 with protocol https
then alert
- check host billy with address preprint.books.exposed
+ check host erpu-zulip with address zulip.erpu.eu
+ if failed port 443 with protocol https
+ then alert
+
+ check host erpu-authentik with address login.erpu.eu
+ if failed port 443 with protocol https
+ then alert
+
+ check host erpu-nextcloud with address nextcloud.erpu.eu
+ if failed port 443 with protocol https
+ then alert
+
+ check host erpu-hedgedoc with address pad.erpu.eu
if failed port 443 with protocol https
then alert
'';