Nixos resources for uptime-sensitive services (archived / migrating off of)
- Nix 96.5%
- Shell 2.3%
- HTML 1.2%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
| docs | ||
| modules | ||
| scripts/mediamtx | ||
| static | ||
| .gitignore | ||
| .goosehints | ||
| .rules | ||
| .sops.yaml | ||
| configuration.nix | ||
| flake.lock | ||
| flake.nix | ||
| README.md | ||
| secrets.yaml | ||
DumpNet Service Stack
This NixOS configuration manages a comprehensive suite of self-hosted services including communication (XMPP, Matrix, IRC network & bouncer, BitlBee bridge, Mumble VoIP), media streaming (Mopidy music server, Snapcast multi-room audio, MediaMTX), collaboration (CalDAV/CardDAV, Forgejo git forge, PicoShare file sharing, Bin pastebin), content (Gemini capsule), and monitoring tools. Each service is modularized for easy maintenance and configuration.
Services Overview
Gemini (Molly Brown) - modules/molly-brown.nix
- Gemini capsule at:
gemini://capsule.keane.sh - Content directory:
/var/lib/molly/content
Initial Setup:
- Set up SSH access for content management:
sudo mkdir -p /var/lib/molly/.ssh
sudo touch /var/lib/molly/.ssh/authorized_keys
sudo chown -R molly:molly /var/lib/molly/.ssh
sudo chmod 700 /var/lib/molly/.ssh
sudo chmod 600 /var/lib/molly/.ssh/authorized_keys
# Add your public key to authorized_keys
sudo vim /var/lib/molly/.ssh/authorized_keys
- Copy files to the server:
scp your_file molly@dumpnet.chat:/var/lib/molly/content/
XMPP (Prosody) - modules/prosody.nix
- Main domain:
dumpnet.chat - Group chat domain:
group.dumpnet.chat - File uploads:
upload.dumpnet.chat - Connection URLs:
- BOSH:
https://dumpnet.chat:5281/http-bind - WebSocket:
wss://dumpnet.chat:5281/xmpp-websocket
- BOSH:
Initial Setup:
- Admin account is automatically created as
ian@dumpnet.chat - Password is stored in
/var/lib/prosody/secrets.env - Public registration is disabled by default
Matrix (Conduit) - modules/conduit.nix
- Server URL:
matrix.dumpnet.chat - Federation enabled
- Public registration disabled by default
Initial Setup:
- Connect using a Matrix client (e.g., Element)
- Server URL:
https://matrix.dumpnet.chat - To create additional accounts, temporarily enable registration in the configuration
CalDAV/CardDAV (Radicale) - modules/radicale.nix
- Web Interface:
https://cal.dumpnet.chat - Features: Calendar and Contacts sync
Initial Setup:
- Admin account created automatically
- Password stored in
/var/lib/radicale/secrets.env - Configure clients using:
- CalDAV URL:
https://cal.dumpnet.chat/ian/ - CardDAV URL:
https://cal.dumpnet.chat/ian/
- CalDAV URL:
Monitoring (Uptime Kuma) - modules/uptime-kuma.nix
- Dashboard:
https://up.dumpnet.chat
Initial Setup:
- Visit
https://up.dumpnet.chat - Create initial admin account
- Configure monitoring for other services
IRC Bouncer (Soju) - modules/soju.nix
- Bouncer service for persistent IRC connections
- TLS enabled by default
- Supports multiple networks and users
Initial Setup:
- Get your credentials:
sudo cat /var/lib/soju/secrets.env
- Connect using any IRC client with these settings:
- Server: dumpnet.chat
- Port: 6699 (TLS) or 6698 (plain)
- Nick: your-chosen-nick
- SASL username: admin
- SASL password: (from secrets.env)
- Once connected, configure networks using Soju commands:
# Add a new network
/network add libera irc.libera.chat
/network add oftc irc.oftc.net
# Configure nick and username for a network
/network set libera nick your-nick
/network set libera username your-username
# Enable SASL authentication for networks that support it
/network set libera sasl.username your-username
/network set libera sasl.password your-password
# Connect to networks
/network connect libera
/network connect oftc
# Join channels (they'll be rejoined automatically after reconnects)
/join -network libera #nixos
/join -network oftc #debian
Weechat - modules/weechat.nix
- IRC client running in tmux
- Preconfigured for Soju bouncer
- Persistent session across SSH disconnects
Initial Setup:
- SSH into server
- Attach to tmux session:
tmux attach -t weechat
- Initial WeeChat Configuration:
# Set up Soju bouncer connection
/server add soju dumpnet.chat/6699 -ssl -username=admin -password=YOUR_SOJU_PASSWORD -autoconnect
# Enable SASL authentication
/set irc.server.soju.sasl_username "admin"
/set irc.server.soju.sasl_password "YOUR_SOJU_PASSWORD"
# Connect to bouncer
/connect soju
# Save configuration
/save
# Basic WeeChat settings for better experience
/set weechat.look.buffer_time_format "%H:%M"
/set weechat.look.prefix_align_max 15
/set irc.look.smart_filter on
/filter add irc_smart * irc_smart_filter *
/set weechat.bar.status.items "[time],buffer_count,buffer_plugin,buffer_number,buffer_name,completion,scroll"
- Common WeeChat Commands:
# Switch between buffers
Ctrl-p / Ctrl-n - Previous/Next buffer
Alt-1,2,3... - Jump to buffer by number
/buffer # - Switch to buffer number #
# Window management
Alt-w - Buffer list
/window splith - Split horizontally
/window splitv - Split vertically
/window merge - Merge split windows
# Channel management
/join #channel - Join a channel
/part - Leave current channel
/close - Close current buffer
# Nick management
/nick newnick - Change nickname
/whois nick - Get info about user
# Other useful commands
/away [message] - Set away status
/back - Remove away status
/query nick - Open private chat
/help command - Get help on a command
- Key WeeChat Keyboard Shortcuts:
Ctrl-s Search text in current buffer
Ctrl-r Search backwards in current buffer
Alt-s Switch between configurations in split windows
F11/F12 Scroll nick list
PageUp/PageDown Scroll buffer content
Alt-l Refresh screen
- Managing Multiple Networks:
# When connected through Soju, use network-specific commands
/msg -server soju *status network connect libera
/msg -server soju *status network connect oftc
# Join channels on specific networks
/join -server soju #nixos@libera
/join -server soju #debian@oftc
- Useful WeeChat Scripts:
# Install script manager
/script install script.pl
# Recommended scripts
/script install autosort.py # Automatically sort buffers
/script install buffer_autoset.py # Save buffer settings
/script install go.py # Quick buffer switching
/script install urlgrab.py # URL handling
# After installing go.py, you can quickly switch buffers:
Ctrl-g followed by part of buffer name
- Detaching/Reattaching:
# In WeeChat, detach from tmux:
Ctrl-b d
# Reattach to session:
tmux attach -t weechat
# List all tmux sessions:
tmux ls
SSL Certificates (ACME) - modules/acme.nix
- Manages Let's Encrypt certificates for all services
- Auto-renewal configured
Getting Started
1. DNS Setup
Configure DNS records for all subdomains:
dumpnet.chat. IN A <your-server-ip>
group.dumpnet.chat. IN A <your-server-ip>
upload.dumpnet.chat. IN A <your-server-ip>
matrix.dumpnet.chat. IN A <your-server-ip>
cal.dumpnet.chat. IN A <your-server-ip>
up.dumpnet.chat. IN A <your-server-ip>
2. Initial Deployment
# Clone configuration
git clone <repo-url> /etc/nixos
# Deploy
nixos-rebuild switch
4. Retrieve Initial Passwords
After deployment, retrieve auto-generated passwords:
# XMPP admin password
sudo cat /var/lib/prosody/secrets.env
# Radicale admin password
sudo cat /var/lib/radicale/secrets.env
# Soju IRC password
sudo cat /var/lib/soju/secrets.env
5. Service Verification
After deployment, verify each service:
- XMPP: Connect using a client like Conversations or Gajim
- Matrix: Connect using Element
- Calendar: Connect using any CalDAV client
- Uptime Kuma: Set up initial monitoring
- IRC: Connect to bouncer using credentials
Configuration Updates
To modify settings:
- Edit relevant module in
/etc/nixos/modules/ - Apply changes:
nixos-rebuild switch
Maintenance
Logs
View service logs:
# XMPP
journalctl -u prosody
# Matrix
journalctl -u matrix-conduit
# Calendar
journalctl -u radicale
# Monitoring
journalctl -u uptime-kuma
# IRC Bouncer
journalctl -u soju
Backups
Important directories to backup:
/var/lib/prosody/- XMPP data/var/lib/matrix-conduit/- Matrix data/var/lib/radicale/- Calendar/Contacts data/var/lib/soju/- IRC bouncer data
Security Notes
- All services require HTTPS
- Public registration is disabled by default
- Admin passwords are automatically generated and stored securely
- Regular updates via NixOS channels recommended
Troubleshooting
Certificate Issues
# Force certificate renewal
systemctl restart acme-dumpnet.chat.service
Service Issues
# Restart specific service
systemctl restart prosody
systemctl restart matrix-conduit
systemctl restart radicale
systemctl restart uptime-kuma
systemctl restart soju
Configuration Testing
# Test configuration before applying
nixos-rebuild test
# Check service status
systemctl status prosody
systemctl status matrix-conduit
systemctl status radicale
systemctl status uptime-kuma
systemctl status soju
```sojuctl user create -username bl0rt -password <password>
sojuctl user run bl0rt network create -addr irc.lainchan.org:6697 -name lainchan
root@dumpnet ~# sojuctl user run bl0rt network
available commands: network create, network delete, network quote, network status, network update
root@dumpnet ~# sojuctl user run bl0rt channel
available commands: channel create, channel delete, channel status, channel update
sojuctl user run bl0rt sasl set-plain -network lainchan yourNick 'YourPassword'
/msg NickServ REGISTER StrongPassword you@example.com
/msg NickServ STATUS MyCoolNick
sojuctl user run bl0rt network update lainchan -auto-away true
# Setting up bitlbee
sojuctl user run bl0rt network create -addr irc+insecure://127.0.0.1:6668 -name bitlbee
in &bitlbee channel:
register <password>
account add discord <email> <password>
acc discord set token_cache xxxx
# To fix
- default enable to false in options?
- all enables in configuration.nix (or none)
- document enable logic and variable setting
# Forgejo
set enable_registration to true, create user (will automatically be admin), set back to false