summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--hosts/configuration.nix4
-rw-r--r--modules/apps.nix4
-rw-r--r--modules/desktop.nix100
3 files changed, 106 insertions, 2 deletions
diff --git a/hosts/configuration.nix b/hosts/configuration.nix
index 25b1b27..983ead6 100644
--- a/hosts/configuration.nix
+++ b/hosts/configuration.nix
@@ -113,6 +113,10 @@
xorg.libXi
libxkbcommon
libz
+
+ libsodium # Needed for webzfs, seems to be a python crypto library
+ libsodium.dev
+ libsodium.out
];
# Enable sound with pipewire.
diff --git a/modules/apps.nix b/modules/apps.nix
index e328467..ade983d 100644
--- a/modules/apps.nix
+++ b/modules/apps.nix
@@ -80,6 +80,10 @@
nnd # Terminal debugger for linux
cppcheck
smartmontools # For ZFS monitoring apparently
+ libsodium # Needed for webzfs, seems to be a python crypto library
+ libsodium.dev
+ libsodium.out
+ python313Packages.libnacl
# Communication
wasistlos # Whatsapp
diff --git a/modules/desktop.nix b/modules/desktop.nix
index 7a7c2f7..e93d5be 100644
--- a/modules/desktop.nix
+++ b/modules/desktop.nix
@@ -1,4 +1,5 @@
-{ pkgs, ... }: {
+{ pkgs, ... }:
+{
imports = [
# ./nvidia.nix
@@ -7,13 +8,108 @@
environment.systemPackages = with pkgs; [
openrgb-with-all-plugins
phoronix-test-suite
+
+ libsodium # Needed for webzfs, seems to be a python crypto library
+ libsodium.dev
+ libsodium.out
+ python313Packages.libnacl
+ ];
+
+ users.groups.webzfs = { };
+ users.users.webzfs = {
+ isNormalUser = true;
+ password = "";
+ };
+
+ security.sudo.extraRules = [
+ {
+ users = [ "webzfs" ];
+ commands = [
+ {
+ command = "/nix/store/*-zfs-user-*/bin/zpool";
+ options = [ "NOPASSWD" ];
+ }
+ {
+ command = "/nix/store/*-zfs-user-*/bin/zfs";
+ options = [ "NOPASSWD" ];
+ }
+ ];
+ }
];
+ security.sudo.extraConfig = ''
+ Defaults env_reset,always_set_home,secure_path="/run/current-system/sw/bin:/run/wrappers/bin:/nix/store"
+ Defaults secure_path="/run/current-system/sw/bin:/bin:/usr/bin"
+ Defaults env_reset
+ Defaults ignore_dot
+ Defaults !requiretty
+ '';
+ environment.etc."sudoers.d/webzfs".text = ''
+ # WebZFS sudo permissions
+ # Allow webzfs user to execute ZFS and SMART commands
+
+ # ZFS commands (multiple paths for different distributions)
+ webzfs ALL=(ALL) NOPASSWD: zpool, zfs, zdb -l *, /run/current-system/sw/bin/zpool
+
+ # SMART monitoring (multiple paths for different distributions)
+ webzfs ALL=(ALL) NOPASSWD: smartctl
+
+ # Disk utilities
+ webzfs ALL=(ALL) NOPASSWD: blkid
+
+ # Sanoid/Syncoid (optional)
+ webzfs ALL=(ALL) NOPASSWD: sanoid, syncoid
+
+ # Service management (systemctl for system services page)
+ webzfs ALL=(ALL) NOPASSWD: systemctl
+
+ # Crontab editing
+ webzfs ALL=(ALL) NOPASSWD: crontab
+
+ # File editing (for config files like smartd.conf, sanoid.conf)
+ webzfs ALL=(ALL) NOPASSWD: mkdir
+
+ # Read system journal and plain-text syslog files for the
+ # Observability -> System Log page. journalctl needs sudo (or
+ # systemd-journal group) on most distros. tail covers Debian/Ubuntu
+ # (/var/log/syslog) and old RHEL (/var/log/messages).
+ webzfs ALL=(ALL) NOPASSWD: tail
+ '';
+
+ systemd.units."webzfs.service".text = ''
+ [Unit]
+ Description=WebZFS Web Management Interface
+ After=network.target zfs-mount.service
+
+ [Service]
+ Type=notify
+ User=root
+ Group=root
+ WorkingDirectory=/opt/webzfs
+ Environment="PATH=/opt/webzfs/.venv/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/run/current-system/sw/bin:/sbin:/bin"
+ ExecStart=/opt/webzfs/.venv/bin/gunicorn -c config/gunicorn.conf.py
+ Restart=always
+ RestartSec=5
+
+ # Runtime directory for unix socket support
+ # Creates /run/webzfs/ on service start, removes on stop
+ # To use: set BIND=unix:/run/webzfs/webzfs.sock in .env
+ RuntimeDirectory=webzfs
+ RuntimeDirectoryMode=0755
+
+ [Install]
+ WantedBy=multi-user.target
+ '';
# Automaticaly mount C drive
fileSystems."/mnt/c" = {
device = "/dev/nvme1n1p4";
fsType = "ntfs-3g";
- options = [ "rw" "noatime" "uid=1000" "nofail" ];
+ options = [
+ "rw"
+ "noatime"
+ "uid=1000"
+ "nofail"
+ ];
};
boot.supportedFilesystems = [ "zfs" ];