summaryrefslogtreecommitdiff
path: root/modules/users.nix
blob: a7895803e862aa99c828847b2488ab0b592cc778 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
{ config, lib, pkgs, ... }:
let
  aliases = import ../data/aliases.nix;
  enableBuilder = config.networking.hostName == "dragon";
in {
  users = {
    defaultUserShell = pkgs.zsh;
    users = {
      orbekk = {
        isNormalUser = true;
        home = "/home/orbekk";
        uid = 1000;
        description = "KJ";
        extraGroups = [
          "wheel"
          "networkmanager"
          "dialout"
          "uucp"
          "audio"
          "pulse"
          "plugdev"
          "lxd"
          "readonly"
          "input"
          "vboxusers"
          "video"
          "sound"
          "tty"
          "hledger"
        ];
        openssh.authorizedKeys.keyFiles = [ ../data/yubikey_rsa.pub ];
      };
      guest = {
        isNormalUser = true;
        home = "/home/guest";
        uid = 1500;
        description = "Guest";
        extraGroups = [ "networkmanager" "audio" "pulse" "input" ];
      };
      fcgi = {
        group = "fcgi";
        extraGroups = [ "readonly" ];
        uid = 500;
        isSystemUser = true;
      };
      systemhttpd = {
        name = "systemhttpd";
        group = "systemhttpd";
        createHome = true;
        uid = 502;
        home = "/var/lib/systemhttpd";
        isSystemUser = true;
      };
      linoquotes = {
        name = "linoquotes";
        group = "linoquotes";
        createHome = true;
        uid = 503;
        home = "/var/lib/linoquotes";
        isSystemUser = true;
      };
      minecraft = {
        name = "minecraft";
        uid = config.ids.uids.minecraft;
        extraGroups = [ "readonly" ];
        isSystemUser = true;
      };
      stats = {
        name = "stats";
        group = "stats";
        createHome = true;
        uid = 504;
        home = aliases.services.stats.home;
        isSystemUser = true;
      };
      terraria = {
        name = "terraria";
        group = "terraria";
        createHome = true;
        uid = 505;
        home = "/var/lib/terraria";
        isSystemUser = true;
      };
      readonly = {
        group = "readonly";
        createHome = false;
        uid = 506;
        useDefaultShell = true;
        home = "/storage";
        isNormalUser = true;
      };
      pjournal = {
        group = "pjournal";
        createHome = false;
        uid = 507;
        isNormalUser = true;
      };
      pjournal_test = {
        group = "pjournal_test";
        createHome = false;
        uid = 508;
        isSystemUser = true;
      };
      builder = lib.mkIf enableBuilder {
        isSystemUser = true;
        openssh.authorizedKeys.keys = [
          "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA2W9SkVc1xKo5QiYOgbCgZbPlFhZLrbG1lS7TUjiZwi root@firelink"
        ];
        useDefaultShell = true;
      };
      mpd = lib.mkIf config.services.mpd.enable {
        isSystemUser = true;
        group = "mpd";
        extraGroups = [ "readonly" ];
      };
      nginx = lib.mkIf config.services.nginx.enable {
        isSystemUser = true;
        extraGroups = [ "readonly" ];
      };
      hledger = lib.mkIf config.orbekk.hledger-web.enable {
        isSystemUser = true;
        home = "/var/lib/hledger-web";
        group = "hledger";
      };
    };
    extraGroups = {
      fcgi = {
        name = "fcgi";
        gid = 500;
      };
      plugdev = {
        name = "plugdev";
        gid = 501;
      };
      systemhttpd = {
        name = "systemhttpd";
        gid = 502;
      };
      linoquotes = {
        name = "linoquotes";
        gid = 503;
      };
      stats = {
        name = "stats";
        gid = 504;
      };
      terraria = {
        name = "terraria";
        gid = 505;
      };
      readonly = { gid = 506; };
      pjournal = { gid = 507; };
      pjournal_test = { gid = 508; };
      hledger = lib.mkIf config.orbekk.hledger-web.enable { };
    };
  };
}