NixOS configuration for my home server, managed with flakes.
All .nix files in nixos/modules/ are automatically discovered and loaded by the flake. Each module should be self-contained around a particular system concern or service.
The following must be created or supplied separately when setting up a new system:
| Path | Purpose |
|---|---|
/home/server/.ssh/authorized_keys |
SSH public keys used to authenticate the server user |
/var/lib/radicale/users |
File used by Radicale. Create using `htpasswd' |
/etc/rclone/proton.conf |
Rclone configuration containing the Proton Drive authentication credentials. |
/var/lib/frigate/camera_password |
Frigate camera password |
The rest of the service configuration and required system directories are created and managed by NixOS.
Tailscale Serve terminates HTTPS and reverse-proxies each port to the service's local HTTP port. All endpoints are tailnet-only.
https://n150.tail617a34.ts.net:443
→ http://127.0.0.1:2283 Immich
https://n150.tail617a34.ts.net:8444
→ http://127.0.0.1:8123 Home Assistant
https://n150.tail617a34.ts.net:8445
→ http://127.0.0.1:8384 Syncthing
https://n150.tail617a34.ts.net:8446
→ http://127.0.0.1:5232 Radicale / CalDAV
https://n150.tail617a34.ts.net:8447
→ http://127.0.0.1:80 Frigate
```
## Rebuild
From the config directory:
```bash
sudo nixos-rebuild switch --flake .#server
Or using nh:
nh os switch .run nix develop to get dev tools such as nixd, nil, nixfmt, statix, and deadnix.