532194b862
servo: speculative wg tunnel fix
2024-12-03 04:49:24 +00:00
08c5f5661f
modules/netns: make the wg port optional
2024-12-03 04:23:53 +00:00
fc239cfa34
modules/programs: support mime.priority when handling duplicated env
keys
2024-12-03 02:18:48 +00:00
de182e117d
modules/programs: enable even more /dev/video devices inside the relevant sandboxes
2024-11-29 18:33:35 +00:00
02286a24ba
modules/programs: add more /dev/video devices required by pinephone-pro rear camera
2024-11-29 18:29:35 +00:00
6be6c08e7c
servo: hardcode the doof/ovpns listen ports, and forward them through the NAT
2024-11-25 18:07:37 +00:00
3ed0ff6611
netns: make it *slightly* more debuggable
2024-11-25 15:55:23 +00:00
a84cf3dd90
podcasts: subscribe to Chris Chinchilla - Tech Lounge
2024-11-25 11:10:28 +00:00
3669780afe
podcasts: Sustain OSS: subscribe
2024-11-25 10:54:26 +00:00
e1a6f09667
buffyboard: acquire from upstream nixpkgs PR
2024-11-25 10:44:56 +00:00
4405f1bed0
buffyboard: push upstream (out for PR)
2024-11-25 10:05:00 +00:00
cee29af431
buffybox: 3.2.0-unstable-2024-10-05 -> 3.2.0-unstable-2024-11-10
2024-11-25 07:15:05 +00:00
f63c8a490e
feeds: subscribe to Matt Stoller - Organized Money
2024-11-23 17:26:42 +00:00
5788edbbc5
feeds: subscribe to Innuendo Studios
2024-11-14 14:25:16 +00:00
7b88c9c644
sane.fs: dont have local-fs.target depend on any of my (persistence) bind mounts
...
otherwise it's too easy for local-fs to hang (/mnt/persist/private), or fail (/mnt/pool), and i lose critical things like *networking*
this was only working because on servo the /mnt/persist/private deps caused a cycle and systemd just _removed_ local-fs.target
2024-11-13 12:05:31 +00:00
fed25f44d5
dyn-dns: allow services to subscribe *only* to change events, and not require DNS always be available
...
also switch back exclusively to UPnP / local source of trust
2024-11-12 04:06:24 +00:00
6513d927d4
hickory-dns: allow empty DNS substitutions, and handle those by filtering out the corresponding record
2024-11-12 04:05:25 +00:00
4779ad8f41
dyn-dns: better implementation
2024-11-12 02:31:50 +00:00
2134a9c738
WIP: dyn-dns: try a smarter trigger scheme, but im getting weird "resource" errors with systemd path units
2024-11-12 01:09:23 +00:00
5aa6c9b8c7
dyn-dns: when DNS changes, restart immediately instead of blocking on another dyn-dns.service query
...
the new behavior though causes dyn-dns consumers to be started even before we've learned the IP. that sort of matches the semantics of the module though. not sure the best design yet
2024-11-11 23:41:58 +00:00
388c58f656
servo: slim dependencies so that local-fs.target can be reached even if my media drives are inaccessible
...
this means some services which need access (like sftpgo) fail to start if the drive is unavailable
2024-11-11 20:40:13 +00:00
f3ee312dad
modules/ssh: start sshd as early in the boot as possible
...
this allows more scenarios to be recoverable
2024-11-11 20:35:47 +00:00
ec5e8a3269
netns: simplify the host -> netns response tunneling
...
i don't actually need any route table that's higher priority than 'local'
2024-11-11 11:02:42 +00:00
f6369bce8d
servo: doof: dont proxy DNS inside the net namespace
2024-11-11 02:46:06 +00:00
309bd04037
modules/netns: rename options for better grouping
2024-11-11 02:37:00 +00:00
23913c9cd2
netns: configure the device in a way that should allow named endpoints to be resolved outside the netns
2024-11-11 02:19:00 +00:00
2684b3c1aa
wg-home: re-enable keepalives
...
this should fix some of the flakiness i've seen when deploying moby?
2024-11-10 16:19:07 +00:00
2ed633cfe8
wg-ovpns/doof: port from networking.wireguard -> sane.netns
2024-11-10 15:48:43 +00:00
2962f2dc21
refactor: modules/netns.nix
2024-11-10 14:00:29 +00:00
cd870e70cd
hickory-dns: use upstream package, unpatched
...
I don't need the recursive resolver patches anymore
2024-11-10 05:56:09 +00:00
c30929e1a6
servo: switch to unbound for local DNS provider
2024-11-10 05:53:17 +00:00
e2dfbfe829
kiwix-serve: fix service sandboxing typo (ReadPaths -> ReadOnlyPaths)
2024-11-10 05:07:13 +00:00
5d1549bbeb
hickory-dns: update comment about status of upstream hickory-dns
2024-11-08 08:09:13 +00:00
1f84fc4b2b
programs: port a few programs from dconf -> gsettings, tested on desko
2024-11-07 05:06:44 +00:00
3a9e4af6da
modules/programs: introduce a gsettings
config option, which so far routes to dconf but later will stand alone
2024-11-07 03:30:34 +00:00
fa8cbd690d
feeds: subscribe to ergaster podcast
2024-11-04 12:24:26 +00:00
e230d40fae
ollama: ship gemma2-27b, package but dont ship codegemma-7b
2024-11-03 12:44:47 +00:00
3aadc12f04
services: ollama: remove some LLM models which ive found to not be useful
2024-11-03 12:16:27 +00:00
0dff9f993f
browserpass: sandbox
2024-10-29 08:21:42 +00:00
864e75afce
sanebox: purge
2024-10-29 05:59:01 +00:00
5b45282da6
buffybox/buffyboard: push systemd service upstream
2024-10-26 03:58:36 +00:00
ea4e230efd
feeds: switch Matrix Live to the Youtube channel (the RSS is dead)
2024-10-26 02:30:24 +00:00
94e391c9a7
feeds: podcasts: subscribe to Unexplainable
2024-10-25 03:43:11 +00:00
6b1ea48f7a
feeds: podcasts: subscribe to Stuff you should Know
2024-10-25 03:40:04 +00:00
d810c17cfd
feeds: podcasts: subscribe to Last Week In AI
2024-10-25 03:32:22 +00:00
969d4cbef2
feeds: subscribe to EFF How To Fix The Internet
2024-10-25 03:31:46 +00:00
1c57b9ce9e
programs/sandbox: include udev rules in the sandboxed program output
...
notably, this fixes feedbackd so that the PPP haptics/vibrator is writable by the user
2024-10-22 07:01:18 +00:00
ea65680a50
feeds: subscribe to TVW_Washington YouTube
2024-10-21 21:20:03 +00:00
d138cec9fc
users/systemd: fix so oneshot services arent stopped immediately after activation
2024-10-18 02:55:44 +00:00
dbc29db5fa
modules/programs: update docs for tryKeepUsers
2024-10-16 00:18:06 +00:00