nix config
  • Nix 99.7%
  • Just 0.3%
Find a file
JMARyA e05e1ffcac
feat(gato): netbird mesh connectivity
Wraps the upstream netbird client module, which exposes no options for the
control plane. NetBird maps flags to NB_<FLAG> env vars and the upstream
module bakes `environment` into the CLI wrapper with --set-default, so the
management/admin URL can be pinned there for both the daemon and interactive
`netbird up`, with no setup key in the store.

gato joins the self-hosted mesh with routing enabled (IP forwarding), so it
can advertise the homelab LAN and act as an exit node. Enrollment stays
manual SSO.

`hardened` defaults to services.resolved.enable: without resolved, NetBird
rewrites /etc/resolv.conf directly, which a hardened unit cannot do under
ProtectSystem=strict — DNS would silently stop resolving. gato has no
resolved, so the daemon runs as root there.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-25 17:42:44 +02:00
.secrets/home chore: remove server infrastructure migrated to iac 2026-04-10 22:53:42 +02:00
.woodpecker add checks 2025-10-25 17:34:06 +02:00
assets update gato 2025-11-18 23:26:51 +01:00
machines feat(gato): netbird mesh connectivity 2026-07-25 17:42:44 +02:00
modules feat(gato): netbird mesh connectivity 2026-07-25 17:42:44 +02:00
vars/per-machine/wohnzimmer/state-version/version cleanup: remove stale references, orphaned vars, and sync-conflict artifacts 2026-05-09 15:15:37 +02:00
.gitignore live system 2025-09-13 20:54:53 +02:00
.sops.yaml chore: remove server infrastructure migrated to iac 2026-04-10 22:53:42 +02:00
flake.lock feat(gato): register as moira agent 2026-07-24 20:05:44 +02:00
flake.nix feat(gato): register as moira agent 2026-07-24 20:05:44 +02:00
justfile update 2025-10-07 17:32:47 +02:00
README.md cleanup: remove stale references, orphaned vars, and sync-conflict artifacts 2026-05-09 15:15:37 +02:00
renovate.json fix 2025-09-16 00:10:33 +02:00

❄️ Machines

NixOS & Darwin system configurations.