Parametrize networking, users, and containers modules under myNetworking/myUsers/myContainers so both hosts share the same logic instead of duplicating it, and split desktop/server module imports into modules/profiles/. Adds hosts/vps (not installed yet, hardware config and bootloader device are placeholders) to run Traefik, Headscale, Headplane, and Gitea via a combined Docker Compose stack. Wires up agenix for secrets and migrates miku-homelab's WireGuard private key off a plain filesystem path into an encrypted secrets/miku-homelab-wg.age. The vps side of that tunnel still needs its own key generated and encrypted after install. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
28 lines
647 B
Nix
28 lines
647 B
Nix
{
|
|
services.samba = {
|
|
enable = true;
|
|
openFirewall = true;
|
|
settings = {
|
|
global = {
|
|
"vfs objects" = "acl_xattr";
|
|
"map acl inherit" = "yes";
|
|
"store dos attributes" = "yes";
|
|
};
|
|
mikufanclub = {
|
|
path = "/mnt/data/mikufanclub";
|
|
writable = "yes";
|
|
"valid users" = "mikushare emmatherock";
|
|
"force group" = "mikushare-group";
|
|
"create mask" = "0660";
|
|
"directory mask" = "0770";
|
|
};
|
|
data-private = {
|
|
path = "/mnt/data";
|
|
writable = "yes";
|
|
"valid users" = "emmatherock";
|
|
"browseable" = "yes";
|
|
};
|
|
};
|
|
};
|
|
}
|