diff options
| author | Martin Fischer <martin@push-f.com> | 2026-06-12 08:06:52 +0200 |
|---|---|---|
| committer | Martin Fischer <martin@push-f.com> | 2026-06-12 20:35:43 +0200 |
| commit | 73631772f255546179ea12c728c96f507f2364d0 (patch) | |
| tree | 7a34a52e1d6824f71b36edb51e02533c8f563fa4 | |
| parent | e553f2d5f3b39b1b99a29177fd5f4612658f1007 (diff) | |
deps: update to NixOS 26.05
For all:
tailscale: 1.90.9 -> 1.98.2
zsh: 5.9 -> 5.9.1
hamac:
android-studio 2025.2.1.8 -> 2025.3.4.7
anki: 25.09.3 -> 25.09.4
chromium: 148.0.7778.167 -> 149.0.7827.53
firefox: 150.0.3 -> 151.0.3
foot: 1.25.0 -> 1.27.0
gimp: 3.0.4 -> 3.0.8
i3status-rust: 0.34.0 -> 0.36.1
inkscape: 1.4.2 -> 1.4.4
krita: 5.2.15 -> 6.0.1
mako: 1.10.0 -> 1.11.0
thunderbird: 150.0.2 -> 151.0.1
vscodium: 1.106.27818 -> 1.116.02821
wireshark-qt: 4.6.5 -> 4.6.6
zathura: 0.5.13 -> 2026.05.20
zed-editor: 1.1.7 -> 1.5.4
docker-compose: 2.40.3 -> 5.1.4
go: 1.25.9 -> 1.26.3
hugo: 0.161.1 -> 0.162.1
jujutsu: 0.41.0 -> 0.42.0
just: 1.43.1 -> 1.51.0
scc: 3.5.0 -> 3.7.0
skim: 0.20.5 -> 4.0.0
coreutils-full: 9.8 -> 9.11
curl: 8.19.0 -> 8.20.0
file: 5.45 -> 5.47
gawk: 5.3.2 -> 5.4.0
git: 2.51.2 -> 2.54.0
htop: 3.4.1 -> 3.5.1
bluez: 5.84, 5.86 -> 5.86
iproute2: 6.17.0 -> 7.0.0
iptables: 1.8.11 -> 1.8.13
less: 679 -> 692
nix: 2.31.5 -> 2.34.7
nixfmt: 1.2.0 -> 1.3.1
npins: 0.3.1 -> 0.4.1
podman: 5.7.0 -> 5.8.2
networkmanager: 1.54.3 -> 1.56.0
openssl(bin): 3.6.1, 3.6.2 -> 3.6.2
shadow: 4.18.0 -> 4.19.4
swaylock: 1.8.4 -> 1.8.5
systemd: 258.7, 260.1 -> 260.1
time: 1.9 -> 1.10
tree: 2.2.1 -> 2.3.2
vim: 9.2.0340 -> 9.2.0389
wireguard-tools: 1.0.20250521 -> 1.0.20260223
xwayland: 24.1.10 -> 24.1.12
For ev:
kodi-peripheral.joystick: 20.1.9 -> 21.1.23
miniflux: 2.2.19 -> 2.3.1
navidrome: 0.61.1 -> 0.61.2
qbittorrent-nox: 5.1.4 -> 5.2.1
grafana-alloy: 1.12.2 -> 1.16.0
grafana-loki: 3.6.3 -> 3.7.2
linux: 6.12.89 -> 6.18.35
mosquitto: 2.0.22 -> 2.1.2
node_exporter: 1.10.2 -> 1.11.1
prometheus: 3.7.2 -> 3.11.3
zigbee2mqtt: 2.6.3 -> 2.12.0
For tente:
cgit: 1.2.3 -> 1.3.1
grafana-alloy: 1.12.2 -> 1.16.0
grafana-loki: 3.6.3 -> 3.7.2
grafana: 12.3.6+security-01 -> 13.0.2
headscale: 0.27.1 -> 0.28.0
lego: 4.31.0 -> 4.35.2
nginx: 1.28.3 -> 1.30.2
node_exporter: 1.10.2 -> 1.11.1
prometheus: 3.7.2 -> 3.11.3
| -rw-r--r-- | nixos/hosts/ev/default.nix | 11 | ||||
| -rw-r--r-- | nixos/hosts/ev/hardware-configuration.nix | 2 | ||||
| -rw-r--r-- | nixos/hosts/hamac/hardware-configuration.nix | 2 | ||||
| -rw-r--r-- | nixos/hosts/tente/grafana.nix | 2 | ||||
| -rw-r--r-- | nixos/npins/sources.json | 16 | ||||
| -rw-r--r-- | nixos/profiles/common/basics.nix | 2 | ||||
| -rw-r--r-- | nixos/profiles/workstation/default.nix | 4 |
7 files changed, 22 insertions, 17 deletions
diff --git a/nixos/hosts/ev/default.nix b/nixos/hosts/ev/default.nix index 29e0ffd..7fcc724 100644 --- a/nixos/hosts/ev/default.nix +++ b/nixos/hosts/ev/default.nix @@ -43,10 +43,13 @@ in enable = true; port = 2222; hostKeys = ["/etc/secrets/initrd/ssh_host_ed25519_key"]; - authorizedKeys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDo/Y7w3hQgUIOQi63e8+L7eTMsVWl1vqY+Bd4tvwShdAj8ECU6JnD6gkCVzqXfUNdpA0Csd9PZlGAbXU+0kxudryFV6mxbXvYf+z70vcF02L5lDJ1tzCV7t7SwXnoenSNBIra/M2zDFgGM4oUkl9iZ2wxn/X/mvFzopJsM3xe2YNtJhXzCyaQTakKRDdHMyj9E867Ko03H6ZD2PI+9G+S39tk5ZLIcG9qhLTfDPziiZj7AIeTYVoxQycajwSlvp8BLzxxCKH8Mq7qW86jfT4lYvUuL5ItQ1cdFbmvJNKpgGXBzgBU+6kWf5c7P2aajhE3otgpfBXWBZRA3hKk+E+xX martin@hamac" - ]; - shell = "/bin/cryptsetup-askpass"; + authorizedKeys = + let + key = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDo/Y7w3hQgUIOQi63e8+L7eTMsVWl1vqY+Bd4tvwShdAj8ECU6JnD6gkCVzqXfUNdpA0Csd9PZlGAbXU+0kxudryFV6mxbXvYf+z70vcF02L5lDJ1tzCV7t7SwXnoenSNBIra/M2zDFgGM4oUkl9iZ2wxn/X/mvFzopJsM3xe2YNtJhXzCyaQTakKRDdHMyj9E867Ko03H6ZD2PI+9G+S39tk5ZLIcG9qhLTfDPziiZj7AIeTYVoxQycajwSlvp8BLzxxCKH8Mq7qW86jfT4lYvUuL5ItQ1cdFbmvJNKpgGXBzgBU+6kWf5c7P2aajhE3otgpfBXWBZRA3hKk+E+xX martin@hamac"; + in + [ + ''command="systemctl default" ${key}'' + ]; }; }; }; diff --git a/nixos/hosts/ev/hardware-configuration.nix b/nixos/hosts/ev/hardware-configuration.nix index 65300c8..20e2906 100644 --- a/nixos/hosts/ev/hardware-configuration.nix +++ b/nixos/hosts/ev/hardware-configuration.nix @@ -14,7 +14,7 @@ boot.extraModulePackages = [ ]; fileSystems."/" = - { device = "/dev/disk/by-uuid/2c273b8a-7f40-41dd-ab63-2194d4bfd328"; + { device = "/dev/mapper/luks-d9d95f9b-5f7d-4193-859f-d36dae4ed814"; fsType = "ext4"; }; diff --git a/nixos/hosts/hamac/hardware-configuration.nix b/nixos/hosts/hamac/hardware-configuration.nix index 54b9d60..0de35e8 100644 --- a/nixos/hosts/hamac/hardware-configuration.nix +++ b/nixos/hosts/hamac/hardware-configuration.nix @@ -14,7 +14,7 @@ boot.extraModulePackages = [ ]; fileSystems."/" = - { device = "/dev/disk/by-uuid/7b33d046-ffd6-4baf-8bd8-a88e3c04d538"; + { device = "/dev/mapper/luks-cf2639e7-1f9c-4c2d-989a-ef2d9950f751"; fsType = "ext4"; }; diff --git a/nixos/hosts/tente/grafana.nix b/nixos/hosts/tente/grafana.nix index f6db5ca..44d1815 100644 --- a/nixos/hosts/tente/grafana.nix +++ b/nixos/hosts/tente/grafana.nix @@ -31,6 +31,8 @@ in from_address = user; password = "$__file{${config.age.secrets.alerts-smtp.path}}"; }; + # TODO: rotate this secret and use an encrypted secret (this was the default value before NixOS 26.05) + security.secret_key = "SW2YcwTIb9zpOOhoPsMm"; }; provision = { diff --git a/nixos/npins/sources.json b/nixos/npins/sources.json index 23c918f..907cf23 100644 --- a/nixos/npins/sources.json +++ b/nixos/npins/sources.json @@ -134,21 +134,21 @@ }, "nixos": { "type": "Channel", - "name": "nixos-25.11", - "url": "https://releases.nixos.org/nixos/25.11/nixos-25.11.10830.d7a713c0b7e4/nixexprs.tar.xz", - "hash": "046szh6p14ffkayjcwa5ixm8kx71s9p4giq03i6v102y91ws1b69" + "name": "nixos-26.05", + "url": "https://releases.nixos.org/nixos/26.05/nixos-26.05.1550.bd0ff2d3eac2/nixexprs.tar.xz", + "hash": "1in8gma5ciwjxavcqbir3fss0s1qdqi4krm7pqhbdz34v5zw3jb0" }, "nixos-small": { "type": "Channel", - "name": "nixos-25.11-small", - "url": "https://releases.nixos.org/nixos/25.11-small/nixos-25.11.10941.30f30521f3fc/nixexprs.tar.xz", - "hash": "0m21l2rwbhc2hdnna2lih0zjav629mipw7a28hrsz1ym5caamvyg" + "name": "nixos-26.05-small", + "url": "https://releases.nixos.org/nixos/26.05-small/nixos-26.05.1896.88a9d48c8af8/nixexprs.tar.xz", + "hash": "1dwjwj42z6zpx6kfd00k0xbwb359rbvyfrcdycdr4mnydvnr3jc3" }, "nixos-unstable": { "type": "Channel", "name": "nixos-unstable", - "url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre995699.da5ad661ba4e/nixexprs.tar.xz", - "hash": "1xj1yx3nj4p8gpcdylqqhp51v0v51b4dabrwa595wkc9bp6wkl5c" + "url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1014179.9ae611a455b9/nixexprs.tar.xz", + "hash": "05b67zykhi139zwg9s6m4hxlql605yrcbhn9c0m85dwy0f32azkp" }, "prometheus-sql-exporter": { "type": "GitRelease", diff --git a/nixos/profiles/common/basics.nix b/nixos/profiles/common/basics.nix index e9fadb4..7bd7125 100644 --- a/nixos/profiles/common/basics.nix +++ b/nixos/profiles/common/basics.nix @@ -35,7 +35,7 @@ }; # without this `apropos` doesn't work - documentation.man.generateCaches = true; + documentation.man.cache.enable = true; # system-wide vi-mode in readline (handy when executing sqlite3 as root) environment.etc.inputrc.text = '' diff --git a/nixos/profiles/workstation/default.nix b/nixos/profiles/workstation/default.nix index f88f77c..e5c2437 100644 --- a/nixos/profiles/workstation/default.nix +++ b/nixos/profiles/workstation/default.nix @@ -64,14 +64,14 @@ in builtins.elem (lib.getName pkg) [ # The device mirroring feature is nice. Also I couldn't get kotlin-lsp (nor any of the open source # Kotlin language servers) to reliably resolve references and show documentation on hover. - "android-studio-stable" + "android-studio" ]; environment.systemPackages = with pkgs; [ npins (callPackage "${sources.agenix}/pkgs/agenix.nix" {}) (callPackage sources.my-vdf {}) - nixfmt-rfc-style + nixfmt vim-full |
