Commit Graph

136 Commits

Author SHA1 Message Date
Ryan Hendrickson
7532d3bfc2 Reapply "nixos/seerr: use lib.mkStateRevisionOption"
This reverts commit 8820b84c40.
2026-08-12 15:38:03 -04:00
andre4ik3
6c74807efc nixos/zapret2: init module 2026-08-10 07:03:44 +00:00
K900
8820b84c40 Revert "nixos/seerr: use lib.mkStateRevisionOption" 2026-08-08 18:36:46 +03:00
Ryan Hendrickson
e060fe4584 nixos/seerr: use lib.mkStateRevisionOption (#509450) 2026-08-07 18:32:51 +00:00
Simon Gardling
f7f8bd3237 nixos/firefox-syncserver: add PostgreSQL backend support 2026-08-05 17:51:32 -07:00
WitteShadovv
1191021a7a nixos/portmaster: init 2026-08-04 20:44:43 +02:00
yaya
907474235e gitlab: 18.11.7 -> 19.0.4 (#535595) 2026-07-30 11:06:26 +00:00
Leona Maroni
82500abba9 gitlab: 18.11.7 -> 19.0.4
https://docs.gitlab.com/releases/19/gitlab-19-0-released/
2026-07-29 18:11:30 +02:00
Pol Dellaiera
be36232d8a nixos/rnsd: init 2026-07-24 17:48:55 +02:00
Pol Dellaiera
b85d98ec6a nixos/lxmd: init 2026-07-24 17:48:55 +02:00
Maximilian Bosch
483f2db40a nixos/testing: allow meta.teams in tests, fix maintainer pings for tests (#540388) 2026-07-21 21:42:07 +00:00
Tom Fitzhenry
3368852e7f doc: add NFS file systems documentation
Add a new section to the NixOS manual documenting how to mount NFS.

fixes https://github.com/NixOS/nixpkgs/issues/76671
2026-07-16 23:11:56 +00:00
Sanfer
fe14acf062 nixos/nordvpn: init module 2026-07-12 19:58:59 +05:30
Maximilian Bosch
93b2178163 nixos/testing: allow meta.teams in tests, fix maintainer pings for tests
With this patch I essentially get the expected list of maintainers for changes in
nixos-tests.

The downside of this approach is that the CI facility assumes that
there's at most a single definition of `meta.maintainers`, however it
can be more in a module-system context.

For simplicity, just use the first definition location for the time
being.

Verified with

    let
      lib = import ./lib;
      maintainers = import ./ci/eval/compare/maintainers.nix { inherit lib; };
    in
    maintainers {
      changedFiles = [
	"nixos/tests/matrix/matrix-authentication-service.nix"
      ];
      affectedAttrPaths = map (lib.splitString ".") [
	"nixosTests.matrix-authentication-service"
      ];
    }
2026-07-10 16:29:13 +02:00
Ryan Hendrickson
a102251d66 utils.mkStateRevisionOption: init 2026-06-16 21:02:44 -04:00
Sandro Jäckel
6c0cb2defd treewide: fix leftover docbook links 2026-06-13 23:37:09 +02:00
Mistyttm
4e861c2161 nixos/mautrix-discord: refactor
After fixing the registration bug I determined that the module was way
too verbose and did not need to provide all of the options provided in
the application. I've stopped explicitly declaring all options that
aren't needed to make a basic version of the module function. The
assertions have also been updated to mirror this fact and will alert a
user when the specific required options are unset. A new documnetation
file was also added as this module, like other mautrix modules, is quite
complex and may need more explaining.
2026-06-06 21:43:50 +10:00
yaya
ca22d15bca doc: Update for 26.11 2026-05-24 14:42:27 +02:00
Jacek Galowicz
1ecef5cad6 nixos-test-driver: require "/dev/net" in tests that need containers 2026-04-20 18:35:34 +01:00
nixpkgs-ci[bot]
48f1d600c8 Merge master into staging-nixos 2026-04-18 00:29:40 +00:00
oddlama
f244290cdf nixos/ente: include documentation in manual 2026-04-16 21:02:45 +02:00
Jacek Galowicz
ea044acd82 nixos/test-driver: use vhost-device-vsock for SSH backdoor (#453305) 2026-04-15 18:15:52 +00:00
Maximilian Bosch
1987c483d8 nixos/test-driver: use vhost-device-vsock for SSH backdoor
`vhost-device-vsock`[1] is a custom implementation of AF_VSOCK, but the
application on the host-side uses a UNIX domain-socket. This gives us
the following nice properties:

* We don't need to do `--arg sandbox-paths /dev/vhost-vsock` anymore for
  debugging builds within the sandbox. That means, untrusted users can
  also debug these kinds of tests now.

* This prevents CID conflicts on the host-side, i.e. there's no need for
  using `sshBackdoor.vsockOffset` for tests anymore.

A big shout-out goes to Allison Karlitskaya, the developer of test.thing[2]
who talked about this approach to do AF_VSOCK on All Systems Go 2025.

This patch requires systemd 258[3] because this contains `vhost-mux` in
its SSH config which is needed to connect to the VMs from now on.

To not blow up the patches even more, this only uses AF_VSOCK for the
debugger. A potential follow-up for the future would be a removal of the
current `backdoor.service` and replace it entirely by this
functionality.

The internal implementation tries to be consistent with how VLANs and
machines are handled, i.e. the processes are started when the Driver's
context is entered and cleaned up in __exit__().

I decided to push the process management and creation of sockets for
vhost-device-vsock into its own class, that's an implementation detail
and not a concern for the test-driver. In fact, `vhost-device-vsock` is
something we can drop once QEMU implements native support for using
AF_UNIX on the host-side[4]. `VsockPair` is its own class since
returning e.g. a triple of `(Path, Path, Int)` would be ambiguous in
what is the guest and what the host path (and frankly, I found it hard
to distinguish the two when reading the docs of `vhost-device-vsock`
initially).

Finally, now that we can do the SSH backdoor without adding additional
devices to the sandbox, I figured, it's time to write a test-case for
it.

[1] https://github.com/rust-vmm/vhost-device/blob/main/vhost-device-vsock/README.md
[2] https://codeberg.org/lis/test.thing
[3] https://github.com/NixOS/nixpkgs/pull/427968
[4] https://gitlab.com/qemu-project/qemu/-/issues/2095
2026-04-15 15:45:33 +01:00
Michael Schneider
5f5734db9d nixos/test-driver: add option to force kvm use 2026-04-15 12:15:00 +01:00
Michael Schneider
45e2f9a67e nixos/test-driver: use log levels 2026-04-14 10:09:15 +01:00
Will Fancher
5620d245ad nixos/systemd-stage-1: Enable by default 2026-04-07 21:53:09 -04:00
Jacek Galowicz
d95261b435 nixos-test-driver: Make overridable 2026-03-26 13:58:05 +01:00
Marie
3576d07e30 nixos/tdarr: init module (#495417) 2026-03-25 13:23:05 +00:00
zowoq
1f69b214e8 nixos/profiles: remove hardened (#501199) 2026-03-22 23:21:16 +00:00
Nico Felbinger
18a45284a2 nixos/profiles: remove hardened
- It lacks a consistent and transparent baseline or standard,
- It may introduce unexpected breakage or degrade performance without clear benefit,
- It is difficult to manage user expectations, especially since the implications of enabling it are not always obvious,
- and as multiple contributors have noted, it is often more of a “grab bag” of settings than a cohesive security policy.
2026-03-21 09:25:12 +10:00
Kierán Meinhardt
4e91a4a0f3 nixos/doc: document systemd-nspawn test containers 2026-03-19 12:14:51 +01:00
Mistyttm
e2f3c26865 nixos/tdarr: init module 2026-03-19 15:57:00 +10:00
Diogo Correia
c17119d4cb nixos/immich: drop pgvecto-rs support 2026-03-14 00:54:21 +00:00
rnhmjoj
ef62977786 nixos/doc: improve networking.wireless chapter 2026-02-07 17:49:46 +01:00
Fernando Rodrigues
a24d666578 nixos/xen: add basic documentation
This very basic documentation page contains a small introduction to Xen taken from my previous writeup at the NixOS Wiki, and some instructions on how to import the domU profile and enable Dom0.

Signed-off-by: Fernando Rodrigues <alpha@sigmasquadron.net>
2026-02-03 14:59:03 +11:00
Fernando Rodrigues
96448e0e84 nixos/amule: fix and improve (#403310) 2026-01-20 02:57:08 +00:00
Sefa Eyeoglu
dafae86e9d nixos/tandoor-recipes: update MEDIA_ROOT remediation docs
In preparation for the upcoming GHSA, update the remediation docs for
Tandoor Recipes.

Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
2026-01-18 12:52:29 +01:00
Anish Pallati
f68a960158 keycloak: add PostgreSQL Unix socket authentication support 2025-12-29 15:09:05 -05:00
Maximilian Bosch
6acb057de6 nixos/postgresql: document difference between postgresql.target and postgresql.service (#473313) 2025-12-29 12:20:27 +00:00
Sefa Eyeoglu
a77e2c1672 nixos/tandoor-recipes: fix database leak when serving media
To avoid serving the (default) SQLite database, set MEDIA_ROOT to a sub
directory of the data path. See
https://github.com/NixOS/nixpkgs/issues/338339 for details

Co-authored-by: bas <bas@noemail.invalid>
Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
2025-12-27 18:35:45 +01:00
Naxdy
fd676936a3 nixos/nextcloud-spreed-signaling: init module
Adds a nixos module for configuring `pkgs.nextcloud-spreed-signaling`
and running it as a systemd service. This allows setting up a "High
Performance Backend" for use with Nextcloud Talk.
2025-12-24 21:57:42 +02:00
Jörg Thalheim
f45d3d9b0a docs/facter: add documentation for nixos-facter 2025-12-23 14:58:54 +00:00
Maximilian Bosch
7a6ec4a99d nixos/postgresql: document difference between postgresql.target and postgresql.service
It's probably good to have this written down explicitly in the manual.
2025-12-22 22:35:37 +01:00
Gabriel Nützi
eea3af80ba nixosTests.gitlab.runner: add gitlab runner tests & docs (with IFD) 2025-12-21 10:04:31 +01:00
Gabriel Nützi
02167967fa Revert "docs: gitlab-runner with example & VM test (shell-runner & podman-runner) (#441161)"
This reverts commit 43070fab2b, reversing
changes made to ada3058e8f.
2025-12-20 18:04:23 +01:00
Gabriel Nützi
9b7256deb3 sync: with master 2025-12-15 20:51:36 +01:00
Andrea Ciceri
2fcb301742 nixos/amule: add manual 2025-12-14 18:27:20 +01:00
Tom Hunze
654110c162 nixos/pingvin-share: drop
The `pingvin-share.backend` package is broken [1] and upstream was
archived in June 2025 [2].

[1] https://hydra.nixos.org/build/311660333/nixlog/1
[2] https://github.com/stonith404/pingvin-share
2025-12-13 14:32:45 +01:00
jopejoe1
bf470a4fdd 26.05 Documentation 2025-11-24 20:52:26 +01:00
Gabriel Nützi
db247605a9 fix: documentation 2025-11-23 16:56:26 +01:00