
106 lines
3.3 KiB

{ config, pkgs, lib, ... }:
release = "nixos-23.05";
in {
imports =
(builtins.fetchTarball {
url = "${release}/nixos-mailserver-${release}.tar.gz";
# This hash needs to be updated
sha256 = "1i56llz037x416bw698v8j6arvv622qc0vsycd20lx3yx8n77n44";
## grub
boot.loader.grub.enable = true;
boot.loader.grub.version = 2;
boot.loader.grub.device = "/dev/vda";
## networking = true;
networking.hostName = "hua";
networking.interfaces.ens3.ipv4.addresses = [ {
address = "";
prefixLength = 24;
} ];
networking.defaultGateway = "";
# networking.nameservers = [ "" "" ];
networking.nameservers = [ "" "" ];
## time
time.timeZone = "Europe/London";
## users
users.users.emilis = {
isNormalUser = true;
home = "/home/emilis";
extraGroups = [ "wheel" ];
# packages = with pkgs; [
# firefox
# thunderbird
# ];
openssh.authorizedKeys.keys = [
users.users.cel = {
isNormalUser = true;
home = "/home/cel";
extraGroups = [ "wheel" ];
# packages = with pkgs; [
# firefox
# thunderbird
# ];
openssh.authorizedKeys.keys = [
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCz+UymES/Ki9/ugCh8/S9fpD0Gf9oarx0xwVK7JIBWfaoGQt505JLjff2w8yI/uEi4QEaGk70g1Tkx0SX4VVOkTo4PdGdehGhrn1sDm6muo5CHGtH9jjBAMia5fLBtmQgRZsmqYnmm7C02I8JRAqCcwpTSqr1sSfoPXyEzyAdCMpDRGbO5nvK1K1ctOrFQRXu52Tq3gZ4fEwXeZkgV1zGT4t1qAUlfW9B3U++hHGk3XrrPq6n98tntPLI0uqN0K2xStMkymVOzQH2NM+vr2wLRmYtlQuy3IBZv2t6Al14ZvgzmzELgqDDj2FNEIptK4trfQvIKFcGMUj/O3EnZZ5HoBPc8b+5qYYHR+9tm8hJokoU0DlWF6DH9iv1863Mu3EUO79euTPZml1l/P7SdLRhWP4EyUvb5jN9mnKzQnPhz/iQLBxfEaXFxPkM2tUaQafJvPi2hlRqTnofVMgp1ktxd19RY5mB3X5jzZFtOtrDA6sdttFuKo+1L/WHrVq0sGTR5/aJIN5AJL+kDSHuTANY2euNJKKKvElQYyugsNnDzENUK59ictpnmtH+CZITTJxdlJLN43hi+OwXoEznnI6zc4dsc+3SV5K7+KdXqLquxqxmZZGP8JPnxJrspS18ycacIMYRFgLexFIS34qNCerazVX1CwXFXOsYF7V2ZY4SJIw== openpgp:0xDDB3D176"
security.sudo.wheelNeedsPassword = false;
## autoupgrade
system.autoUpgrade.enable = true;
system.autoUpgrade.allowReboot = true;
## packages
# List packages installed in system profile. To search, run:
# $ nix search wget
environment.systemPackages = [
# ssh
services.openssh.enable = true;
services.openssh.permitRootLogin = "no";
services.openssh.passwordAuthentication = false;
# mail
mailserver = {
enable = true;
fqdn = "";
domains = [ "" "" ];
# A list of all login accounts. To create the password hashes, use
# nix-shell -p mkpasswd --run 'mkpasswd -sm bcrypt'
loginAccounts = {
"" = {
hashedPasswordFile = "/etc/nixos/mailserver/";
aliases = ["" ""];
"" = {
hashedPasswordFile = "/etc/nixos/mailserver/";
# Use Let's Encrypt certificates. Note that this needs to set up a stripped
# down nginx and opens port 80.
certificateScheme = "acme-nginx";