{ pkgs, ... }:
{
networking.hostName = "arges";
mjm.profiles.raspberry-pi.enable = true;
system.stateVersion = "21.03";
<<config>>
_class = "nixos";
}arges is a Raspberry Pi 4B running SPIRE server for the lab.
=> raspberry-pi profile module
fileSystems."/persist" = {
device = "/dev/disk/by-label/NIXOS_SD";
fsType = "ext4";
options = [ "noatime" ];
neededForBoot = true;
};
mjm.state.persistDir = "/persist";
system.etc.overlay.mutable = false;arges is using a transient root filesystem, so persistent content from /var is bind-mounted into place from /persist/var. This setup also makes it easy to use the immutable etc overlay.
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/E8CE-A0C1";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};My Raspberry Pi systems use firmware that supports UEFI, so I need an ESP to use with systemd-boot.
swapDevices = [
{
device = "/persist/swap";
size = 4 * 1024;
}
];
boot.zswap.enable = true;arges has a 4G swap file. Since it has disk-backed swap, it can use zswap.
mjm.server.enable = true;
This machine is running as a server, so it needs the common server infrastructure for my lab.
mjm.spire.server.enable = true; services.postgresql.package = pkgs.postgresql_18;
The main service that arges runs is the SPIRE server. It is responsible for issuing SPIFFE certificates to every other server in the lab. These form the authentication mechanism for machine-to-machine communication wherever possible.
Because the SPIRE server stores data in PostgreSQL, I need to configure the version of PostgreSQL that it is using.
=> spire/server service module
mjm.nut = {
enable = true;
mode = "server";
};arges also runs the NUT server for the other machines, so it is the one that the UPSes are connected to via USB. It's probably a bad idea to combine this task with security-critical infrastructure, so I might move this responsibility to brontes in the future.
text/gemini;lang=en-USThis content has been proxied by September (UNKNO).