Nixos resources for uptime-sensitive services (archived / migrating off of)
  • Nix 96.5%
  • Shell 2.3%
  • HTML 1.2%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-08-22 21:42:48 +00:00
docs Remove icecast 2026-02-18 15:18:02 +00:00
modules Increase size minimums for image repository 2026-08-22 21:42:48 +00:00
scripts/mediamtx Add mediamtx server 2026-02-12 15:42:19 +00:00
static Add landing page 2025-08-02 14:48:26 +00:00
.gitignore Add irc network, small fixes, remove non-tls soju 2025-12-01 02:29:02 +00:00
.goosehints Remove unused modules 2026-02-12 17:44:18 +00:00
.rules Remove unused modules 2026-02-12 17:44:18 +00:00
.sops.yaml Add sops secret management, postgres server 2026-02-12 15:21:07 +00:00
configuration.nix Mopidy to snapcast 2026-02-18 14:58:43 +00:00
flake.lock Add sops secret management, postgres server 2026-02-12 15:21:07 +00:00
flake.nix Add sops secret management, postgres server 2026-02-12 15:21:07 +00:00
README.md Remove icecast 2026-02-18 15:18:02 +00:00
secrets.yaml Remove icecast 2026-02-18 15:18:02 +00:00

DumpNet Service Stack

This NixOS configuration manages a comprehensive suite of self-hosted services including communication (XMPP, Matrix, IRC network & bouncer, BitlBee bridge, Mumble VoIP), media streaming (Mopidy music server, Snapcast multi-room audio, MediaMTX), collaboration (CalDAV/CardDAV, Forgejo git forge, PicoShare file sharing, Bin pastebin), content (Gemini capsule), and monitoring tools. Each service is modularized for easy maintenance and configuration.

Services Overview

Gemini (Molly Brown) - modules/molly-brown.nix

  • Gemini capsule at: gemini://capsule.keane.sh
  • Content directory: /var/lib/molly/content

Initial Setup:

  1. Set up SSH access for content management:
sudo mkdir -p /var/lib/molly/.ssh
sudo touch /var/lib/molly/.ssh/authorized_keys
sudo chown -R molly:molly /var/lib/molly/.ssh
sudo chmod 700 /var/lib/molly/.ssh
sudo chmod 600 /var/lib/molly/.ssh/authorized_keys
# Add your public key to authorized_keys
sudo vim /var/lib/molly/.ssh/authorized_keys
  1. Copy files to the server:
scp your_file molly@dumpnet.chat:/var/lib/molly/content/

XMPP (Prosody) - modules/prosody.nix

  • Main domain: dumpnet.chat
  • Group chat domain: group.dumpnet.chat
  • File uploads: upload.dumpnet.chat
  • Connection URLs:
    • BOSH: https://dumpnet.chat:5281/http-bind
    • WebSocket: wss://dumpnet.chat:5281/xmpp-websocket

Initial Setup:

  1. Admin account is automatically created as ian@dumpnet.chat
  2. Password is stored in /var/lib/prosody/secrets.env
  3. Public registration is disabled by default

Matrix (Conduit) - modules/conduit.nix

  • Server URL: matrix.dumpnet.chat
  • Federation enabled
  • Public registration disabled by default

Initial Setup:

  1. Connect using a Matrix client (e.g., Element)
  2. Server URL: https://matrix.dumpnet.chat
  3. To create additional accounts, temporarily enable registration in the configuration

CalDAV/CardDAV (Radicale) - modules/radicale.nix

  • Web Interface: https://cal.dumpnet.chat
  • Features: Calendar and Contacts sync

Initial Setup:

  1. Admin account created automatically
  2. Password stored in /var/lib/radicale/secrets.env
  3. Configure clients using:
    • CalDAV URL: https://cal.dumpnet.chat/ian/
    • CardDAV URL: https://cal.dumpnet.chat/ian/

Monitoring (Uptime Kuma) - modules/uptime-kuma.nix

  • Dashboard: https://up.dumpnet.chat

Initial Setup:

  1. Visit https://up.dumpnet.chat
  2. Create initial admin account
  3. Configure monitoring for other services

IRC Bouncer (Soju) - modules/soju.nix

  • Bouncer service for persistent IRC connections
  • TLS enabled by default
  • Supports multiple networks and users

Initial Setup:

  1. Get your credentials:
sudo cat /var/lib/soju/secrets.env
  1. Connect using any IRC client with these settings:
  • Server: dumpnet.chat
  • Port: 6699 (TLS) or 6698 (plain)
  • Nick: your-chosen-nick
  • SASL username: admin
  • SASL password: (from secrets.env)
  1. Once connected, configure networks using Soju commands:
# Add a new network
/network add libera irc.libera.chat
/network add oftc irc.oftc.net

# Configure nick and username for a network
/network set libera nick your-nick
/network set libera username your-username

# Enable SASL authentication for networks that support it
/network set libera sasl.username your-username
/network set libera sasl.password your-password

# Connect to networks
/network connect libera
/network connect oftc

# Join channels (they'll be rejoined automatically after reconnects)
/join -network libera #nixos
/join -network oftc #debian

Weechat - modules/weechat.nix

  • IRC client running in tmux
  • Preconfigured for Soju bouncer
  • Persistent session across SSH disconnects

Initial Setup:

  1. SSH into server
  2. Attach to tmux session:
tmux attach -t weechat
  1. Initial WeeChat Configuration:
# Set up Soju bouncer connection
/server add soju dumpnet.chat/6699 -ssl -username=admin -password=YOUR_SOJU_PASSWORD -autoconnect

# Enable SASL authentication
/set irc.server.soju.sasl_username "admin"
/set irc.server.soju.sasl_password "YOUR_SOJU_PASSWORD"

# Connect to bouncer
/connect soju

# Save configuration
/save

# Basic WeeChat settings for better experience
/set weechat.look.buffer_time_format "%H:%M"
/set weechat.look.prefix_align_max 15
/set irc.look.smart_filter on
/filter add irc_smart * irc_smart_filter *
/set weechat.bar.status.items "[time],buffer_count,buffer_plugin,buffer_number,buffer_name,completion,scroll"
  1. Common WeeChat Commands:
# Switch between buffers
Ctrl-p / Ctrl-n - Previous/Next buffer
Alt-1,2,3... - Jump to buffer by number
/buffer # - Switch to buffer number #

# Window management
Alt-w - Buffer list
/window splith - Split horizontally
/window splitv - Split vertically
/window merge - Merge split windows

# Channel management
/join #channel - Join a channel
/part - Leave current channel
/close - Close current buffer

# Nick management
/nick newnick - Change nickname
/whois nick - Get info about user

# Other useful commands
/away [message] - Set away status
/back - Remove away status
/query nick - Open private chat
/help command - Get help on a command
  1. Key WeeChat Keyboard Shortcuts:
Ctrl-s          Search text in current buffer
Ctrl-r          Search backwards in current buffer
Alt-s           Switch between configurations in split windows
F11/F12         Scroll nick list
PageUp/PageDown Scroll buffer content
Alt-l           Refresh screen
  1. Managing Multiple Networks:
# When connected through Soju, use network-specific commands
/msg -server soju *status network connect libera
/msg -server soju *status network connect oftc

# Join channels on specific networks
/join -server soju #nixos@libera
/join -server soju #debian@oftc
  1. Useful WeeChat Scripts:
# Install script manager
/script install script.pl

# Recommended scripts
/script install autosort.py    # Automatically sort buffers
/script install buffer_autoset.py  # Save buffer settings
/script install go.py         # Quick buffer switching
/script install urlgrab.py    # URL handling

# After installing go.py, you can quickly switch buffers:
Ctrl-g followed by part of buffer name
  1. Detaching/Reattaching:
# In WeeChat, detach from tmux:
Ctrl-b d

# Reattach to session:
tmux attach -t weechat

# List all tmux sessions:
tmux ls

SSL Certificates (ACME) - modules/acme.nix

  • Manages Let's Encrypt certificates for all services
  • Auto-renewal configured

Getting Started

1. DNS Setup

Configure DNS records for all subdomains:

dumpnet.chat.        IN A    <your-server-ip>
group.dumpnet.chat.  IN A    <your-server-ip>
upload.dumpnet.chat. IN A    <your-server-ip>
matrix.dumpnet.chat. IN A    <your-server-ip>
cal.dumpnet.chat.    IN A    <your-server-ip>
up.dumpnet.chat.     IN A    <your-server-ip>

2. Initial Deployment

# Clone configuration
git clone <repo-url> /etc/nixos

# Deploy
nixos-rebuild switch

4. Retrieve Initial Passwords

After deployment, retrieve auto-generated passwords:

# XMPP admin password
sudo cat /var/lib/prosody/secrets.env

# Radicale admin password
sudo cat /var/lib/radicale/secrets.env

# Soju IRC password
sudo cat /var/lib/soju/secrets.env

5. Service Verification

After deployment, verify each service:

  1. XMPP: Connect using a client like Conversations or Gajim
  2. Matrix: Connect using Element
  3. Calendar: Connect using any CalDAV client
  4. Uptime Kuma: Set up initial monitoring
  5. IRC: Connect to bouncer using credentials

Configuration Updates

To modify settings:

  1. Edit relevant module in /etc/nixos/modules/
  2. Apply changes:
nixos-rebuild switch

Maintenance

Logs

View service logs:

# XMPP
journalctl -u prosody

# Matrix
journalctl -u matrix-conduit

# Calendar
journalctl -u radicale

# Monitoring
journalctl -u uptime-kuma

# IRC Bouncer
journalctl -u soju

Backups

Important directories to backup:

  • /var/lib/prosody/ - XMPP data
  • /var/lib/matrix-conduit/ - Matrix data
  • /var/lib/radicale/ - Calendar/Contacts data
  • /var/lib/soju/ - IRC bouncer data

Security Notes

  • All services require HTTPS
  • Public registration is disabled by default
  • Admin passwords are automatically generated and stored securely
  • Regular updates via NixOS channels recommended

Troubleshooting

Certificate Issues

# Force certificate renewal
systemctl restart acme-dumpnet.chat.service

Service Issues

# Restart specific service
systemctl restart prosody
systemctl restart matrix-conduit
systemctl restart radicale
systemctl restart uptime-kuma
systemctl restart soju

Configuration Testing

# Test configuration before applying
nixos-rebuild test

# Check service status
systemctl status prosody
systemctl status matrix-conduit
systemctl status radicale
systemctl status uptime-kuma
systemctl status soju
```sojuctl user create -username bl0rt -password <password>
sojuctl user run bl0rt network create  -addr irc.lainchan.org:6697  -name lainchan

root@dumpnet ~# sojuctl user run bl0rt network
available commands: network create, network delete, network quote, network status, network update
root@dumpnet ~# sojuctl user run bl0rt channel
available commands: channel create, channel delete, channel status, channel update

sojuctl user run bl0rt sasl set-plain -network lainchan yourNick 'YourPassword'

/msg NickServ REGISTER StrongPassword you@example.com

/msg NickServ STATUS MyCoolNick


sojuctl user run bl0rt network update lainchan -auto-away true


# Setting up bitlbee

sojuctl user run bl0rt network create -addr irc+insecure://127.0.0.1:6668 -name bitlbee

in &bitlbee channel:
register <password>
account add discord <email> <password>

acc discord set token_cache xxxx


# To fix
- default enable to false in options?
- all enables in configuration.nix (or none)
- document enable logic and variable setting

# Forgejo
set enable_registration to true, create user (will automatically be admin), set back to false