{ pkgs, ... }: { # European timezone time.timeZone = "Europe/Amsterdam"; i18n.defaultLocale = "en_US.UTF-8"; # SSH: key-only, no passwords, no root login services.openssh = { enable = true; settings = { PasswordAuthentication = false; PermitRootLogin = "no"; KbdInteractiveAuthentication = false; }; }; # Firewall: SSH, HTTP/HTTPS (Caddy), plain DNS, and AdGuard's own # DNS-over-TLS (853) + DNS-over-HTTPS (8443) listeners. # Port 3000 (AdGuard's plain-HTTP web UI) is deliberately NOT opened here - # see modules/adguard.nix for why it still binds 0.0.0.0 anyway. networking.firewall = { enable = true; allowedTCPPorts = [ 22 80 443 53 853 8443 ]; allowedUDPPorts = [ 53 ]; }; # Nix settings: flakes, auto-gc, auto-optimise nix = { settings = { experimental-features = [ "nix-command" "flakes" ]; auto-optimise-store = true; trusted-users = [ "root" "admin" ]; }; gc = { automatic = true; dates = "weekly"; options = "--delete-older-than 14d"; }; }; # Base system packages environment.systemPackages = with pkgs; [ git htop curl vim age ssh-to-age sops ]; # Automatic security updates for the OS. # This repo is self-hosted via cgit (modules/cgit.nix), so the flake URL # below points at this same server rather than GitHub - update the repo # name if you push this config somewhere else. system.autoUpgrade = { enable = false; # set to true once you are comfortable with unattended reboots flake = "git+https://git.karanj.com/feynman.git#eurovm"; flags = [ "--update-input" "nixpkgs" ]; }; }