index
:
nix-config
master
All my NixOS and home-manager configurations.
summary
refs
log
tree
commit
diff
log msg
author
committer
range
path:
root
/
sys
(
follow
)
Age
Commit message (
Collapse
)
Author
2025-04-19
sys/mta: improve postfix hardening
Alejandro Soto
2025-04-19
sys/net: harden firewall reverse-path checks, ICMP redirects
Alejandro Soto
2025-04-19
sys/net: redefine gate0 and nat64 nets using link-local addressing
Alejandro Soto
2025-04-06
sys: reload services after certificate renewal
Alejandro Soto
2025-04-06
sys/platform/[lustrated]: prevent default global IPv6 traffic from going ↵
Alejandro Soto
through VPN routes
2025-04-06
sys/net: create custom iptables chains for local rules
Alejandro Soto
2025-03-30
sys/mta: implement backup MX
Alejandro Soto
2025-01-25
home, sys: enable syncthing as user service
Alejandro Soto
2025-01-25
sys/hardware/thinkpad: remove digimend
Alejandro Soto
2025-01-25
sys/[lustrated]: enable syncthing
Alejandro Soto
2025-01-22
sys: remove IPv4 on dmz, gate; enable DNS64 for dmz
Alejandro Soto
2025-01-12
sys/platform/{[lustrated], [lustrated]}: enable virt
Alejandro Soto
2025-01-11
flake, sys: remove conduit
Alejandro Soto
2025-01-04
sys/nspawn/dmz: restore IPv4 private subnet for DMZ
Alejandro Soto
2025-01-03
sys: update deprecated option names under config.systemd.network
Alejandro Soto
2025-01-03
sys: allocate global IPv6 addresses for DMZ services
Alejandro Soto
2025-01-03
sys/net: add conntrack-tools to environment
Alejandro Soto
2025-01-03
sys/[lustrated]: implement NAT64
Alejandro Soto
2025-01-03
sys: unify gate and vpn into a globally-addressable IPv6-only network
Alejandro Soto
2025-01-02
sys/net: switch gate0 to public subnet 2a03:3b40:fe:888::/64
Alejandro Soto
2025-01-01
sys: refactor address and network number management
Alejandro Soto
2025-01-01
sys/web: do not return 403 for ACME challenge requests
Alejandro Soto
2025-01-01
sys/mta: fix OpenDKIM signing
Alejandro Soto
2024-12-17
sys/platform/[lustrated]: enable address-restricted ssh password auth, fail2ban
Alejandro Soto
2024-12-17
sys/auth: support openssh password authentication (off by default)
Alejandro Soto
2024-12-14
sys/baseline: completely disable Nix channels
Alejandro Soto
2024-12-03
sys/platform/[lustrated]: initial commit, adapted from old [lustrated] repo
Alejandro Soto
2024-12-03
flake: update to 24.11
Alejandro Soto
2024-10-03
sys/seat: add xdg-desktop-portal-gtk to xdg.portals
Alejandro Soto
2024-09-30
sys/nspawn/dmz: add imap domain for ACME
Alejandro Soto
2024-09-30
sys/virt/libvirt: do not restart user doms after config changes
Alejandro Soto
2024-09-09
sys/seat: enable xdg.portal.wlre
Alejandro Soto
2024-08-19
sys/mail: restore access to sieve extensions
Alejandro Soto
2024-08-18
sys/platform/[lustrated], home/ssh: setup for hv SSH over vsock
Alejandro Soto
2024-08-18
sys/[lustrated]: implement FIDO2 auth over vsock
Alejandro Soto
2024-08-17
sys/mta: enable recipient extensions
Alejandro Soto
2024-08-17
home/desktop: enable swayidle, swaylock
Alejandro Soto
2024-08-17
home/desktop, sys/seat: switch from xorg/i3 to wayland/sway
Alejandro Soto
2024-08-17
sys/seat: switch from pulseaudio to pipewire
Alejandro Soto
2024-08-15
sys/hardware/printing: limit interfaces on which port 5353 is open
Alejandro Soto
2024-08-13
sys/web/sites/matrix: enable sliding sync
Alejandro Soto
2024-08-13
sys/web/sites/portal: add redirect: exdev.io/fsociety
Alejandro Soto
2024-08-12
sys/conduit: switch to conduwuit
Alejandro Soto
2024-08-12
sys/[lustrated]: enable SSH over vsock
Alejandro Soto
2024-08-11
sys/baseline: add lshw, parted
Alejandro Soto
2024-08-10
sys/jobs/pki-expiry: initial commit
Alejandro Soto
2024-08-10
sys/ns/34project.org: switch to local nameservers
Alejandro Soto
2024-08-10
sys/net: add dnsutils, nmap, socat, tcpdump
Alejandro Soto
2024-08-08
sys: add exceptions for new IPv6 prefixes
Alejandro Soto
2024-08-08
platform: enable IPv6 routing in gate net
Alejandro Soto
[next]