add grafana and postgresql to web host, fix sops keys

This commit is contained in:
2023-08-19 01:10:15 +02:00
parent 5651351d68
commit 255896cb9f
6 changed files with 128 additions and 18 deletions

View File

@@ -20,10 +20,12 @@ creation_rules:
- path_regex: hosts/git.cloonar.com/[^/]+\.yaml$
key_groups:
- age:
- *dominik
- *git-server
- path_regex: hosts/web-01.cloonar.com/[^/]+\.yaml$
key_groups:
- age:
- *dominik
- *web-01-server
- path_regex: hosts/home-assistant.cloonar.com/[^/]+\.yaml$
key_groups:

View File

@@ -1,22 +1,31 @@
borg-passphrase: ENC[AES256_GCM,data:Rlb6pyuZjcR7qYt/O4o5AVjfZixKRWbdiHhR4wiwjLIKpPhgjO2ea2WaMP+XVcy5tDFA3Z30BxBloVIwK9rD6w==,iv:Jm9TIfxI7Tae3KN60VPrnIXvYpOCuquKB0Jf6wmp1oE=,tag:Ca/0FerPFn4+7WWhht1irw==,type:str]
borg-ssh-key: ENC[AES256_GCM,data:KsgiBHWDVFj7s1ueP6r/U0r2s/4aq+NmhGKMDd0rOgpkwn2SnkKCc3c5qsRp57AcDqyF2Vt9fsDCYNNg2mhBLmSbZ9VNy2EawounD5FINJ8gPI0EW9NgQHHEAdmGviH7eMRSoSTAAzPNM9T4I92iVYOjogdSTaHU/uSmJnxNOwVTdb8RGrHfXrj1bAvEYF3teNpdRsPh0Q+bNCCAp7aas9fSuV4NPyiCTwlXkLhM8P5hfCtNuFtpLvzLxMaLv2Z/OZAKjd6Kf/wNKyMdccUtGS/wdOn7fYTNlpmMB8cYprn37fqBmvbQhGOGG6ea6HTVrU6hrOaoDsOP/tXI7xGQW7YVrq6w5/bXQyf1xXbKp+QuVWwamERbh/NZUyJLBoS9rV8JG3vJyjn829mhm7F+UfGS5nBoY8dskKdHT86OBf3+K12mQWU4fS17hc4ugm3SGXMpv1/X8nB/Tv2ok65W+5kehx4Dk1NHu+gaEJ2j3KNZPupX5HOHK/SIkjU9ybUdDxzTQOCsb6kud1D18SZQV/14z8H1dMjxMY9tnqhNX37+yNhjTkFjoYHTbj4Tg4afhvMXWFIAw6dck6tVEMIAJ3L73MlfzaDjvSSxrbNPlfMu9B45FR27YMwBc57pHZ90lvROnEBdJ3NY3inYMNuC9EVAnFPDfGixG61qA54xGJuRF+hUPx5lF1cKxlMC4QDR3lW2oAt4x19irUKa/3ayEcIKj49lfv++pSlj+cP1/2z1/1+kJgxxmSoSanycLPIc8bvcn+RGnaoRkATR27WTGQ18Ga1kGlS106wIBsaxoZvOWghET/OPt1Xm6Y7n/x5vJTeeizFBe36vv1MqtER8oedcfn51vjVuCDVwndi0iyvm4qvlKKfl+DCz4JKOpCDc0uvdpHddQsXjiysZ8z2YVhgpj1ceaWQwU/MlIwK6pIra/mUYpdYXVMODgWNl8Mhtw9CA1BfPqTpUcDuO+sEC2CdgG7T/0GFVAfBiSl6LX4nBElaWQccjWQlxzDotW8xuBXlKvWoGKe9VztLwoJ1LN870mA+btESnIExiGQS2BAQoEWlqyfSB/y6RXuLHvIjuR6tCmkSawDrnS+GtXhPIcacRmSZGG+OsJAhE2JPOct9YSHInepyyn9cOEBsIlsBfDP+bI+cnRsMkYeQkwqQsWJVxRtXMmtj+qJUqU9Bznp3twLqvZIbfK/pE1nVf8lkYExxWrZzp62Rxplbil5UuBTYtaDHeKaSJSFxTSYat4Ap4jcL682h2Ubdssnw0u14u+CGliea3L5Tik09+3R/hKaOPU+zjWLd5GiPLhqoFADSu7NtbTqH/4yphq5tlpaIc9FVD5cheaX5oxVSnXeX3Bb8r/JWL2duNfRaUr+sjJtn5afinCxAR8xJJBFvRDQq5kG3V0iXlbh4KjUr0sridkjjZAq1dNc2zA0w/Y/2+SCGAs8y5IbwqjEBuOCklwlWxjV//3K/vanZIg/qX3mKDBOtVwyoecAzoekdgRhC4A6NSMDzuloQIaLWlwsvcYIvRr7g00BDUBLkwzlCxT+T8xLp3aXKZK8ZHniVdtniHKT52uHsPG5erMr272Bf67rxficStoRRW+h4bqz5DQ7PvGjBQil5DujeckjgIcyqaqNxq7iHaTUUutDQ6oa4UmCEyxzazS+IB89UyjdgQZL+8C4ho+ETFmqnDp7kFsl+qfuesgzaRsj/wb3fECMfUzQo0TBiE41/yiKKoz3Dq6yrESTw6BHBfp2518JUP3Jk21+ZOr0BjRVoZ0PRqFk3nw0QlBcb7eowysC+n/20ysnQ8TOYDfbFsa3//gnyMrv8/VBd004olvq5Om4BYZoOlkpzpwshsZz7ysZyKZlbb/Uxf4aDNVsFUcUdJHqIZE4bzResj0j2OrN3r5s51dm8vJLc8POTkWkCJ8oRmebjfqEwrXi98+LygB+jYUvJzMnrf02X9aBZy+QWDRCeOIyuCRkgnt3v5JS2k4v+vKphs7yg7iy6RbI7X/5QaOZlfBdd2zzOLlID3sRfz7QOXKNvZFFxADGmr2Eek2xUEF+TFfnJYxDVYl1OIQ2Rm3/908nWsLqUWhMhvcsTA/7kzlWDXHxEilvDMQcBsoEdEUoKREwEUJSi4Uxv+RmVG7QbfAjpuVe3QwvjRKntFvRZIinDUgWeqcifVr2A0P+9hnXGJDZzA+f6HRNbyieI9t1CLODU91tyoTXCpS3SmLmwUEx+F2M+Vu4ZLj/hmCiQg5s5380zBAd4wZx+EJ1MutK+VHAfK5yZ2F4HTAIoKW77vXbM998IH4CaH4X+lN0/1PdPqtsj+VvAhP3NP7G2xG4GsCTE1Xf+xgW4Oin+MiEwgPDXBaG6g/1ByqqgAo5iIVZ4tWVaHO9UF18GEu+O+XFGE39YUkEvo9GlLj4oZKRe50W7w5R9fr3DSIrsBj2XWF2Jhhui2KQ7oLrwdrQfuHbz7aS8i3PUTwQacCilLdbxc1joe+mYYQ+Y5Y3GPLebCwzaIWxrMHxIO1WtjDzpZTwj/i1PrwQsK+P9iUlJIo69awfnX6I6J2RNgipdECvLIVFi+gTaZ+XwbbV8WzYNo55fRAaSAEgaCsvUgFlyIlgajKkVVHJNwvffeg8p0hQ/cInBf3QPUBnb5MbYD7UO0p7VnWLGwcsWj1Yd+IuGy89gPzVBTyQcxpVZi0CYxAJ58JZ/8K/HzHKXa2bSOb0RM3C/6Z3HFW80AY20nwq+l0clh8BVbDCov1JwlxKuF6Ri21II2JRj7++ZQ2/9/Jl3Pk2e5DRU/ZQ6LWHAoYZ8zOb5pQxFJa1Mj++TYZhw7pNgIXui2o2ZCvKEVacz3wGND69EUZsxv+xLPH1tJFS/SPCFPBzNQDuVj7jMypFbNqlk8kzuasjUg9zFNcJ8+Uy3xaVOsekJnkjz/xfcwh+0/mjWBAaDxyLQK8AryuQFLfk1/MhY/MqrKcu1K0w7ttgXMdciMwGDJMwOrtHzTt1mf7ZLUgQBu/0cLrKp6Lo8KMKjWj9M52yVY3OKOdcrVxy95Fcu4iAkoAcxa526dcOrH0wtxVeRFJbqpuXhcq7tTstmgDenpzjjAa9mVUhOAX6x7h1oa2ku9p48xTGAMz2TsdAZmoKfruKFhVC0Exp7/4plxWFxl53u40e5cbmvXntFfqHR6/WUv8YTPH+bKyEYCgUbs1wyg9gjjmnGekPYx8ebnr+P91vAsR8VWEqgK4qWrv3NFoUFcttvns0iwTYiT0wrLVHT3l8xtrITKG39JxYruq69SfApQrsfyHi3Hj+bkyBw7+b4IA9L0ndt0K0iF93SmiO+HVk1Z8mw7CvmiJaCaZ8164X66MnVJny5wmlk+vO9hoQ1K8Tnh65q4jPLNQeiDykLFvuZN7tGUDW0SQRnjON+e6IGAxAxmYyd5uO587qC7xTfoBSQS0tYP56DvTULR5LfZDXEIdbtBglwmmQgZ7A==,iv:D+umppfFfO+t0h4Eq4gP+gVd4n1yKxegnELWqsvQVuQ=,tag:018/WLt77v80jG1wZ5RL7g==,type:str]
borg-passphrase: ENC[AES256_GCM,data:exjDVqrSVJzKrDrM3f8zALfrzNVDRfJP8PE8ykr21dfobYcG5q8dz45dxWt4sgChtWggfYpn4cklSfxwbbe9cw==,iv:BwST15IfZVRpYYPUbydyfTR2CVm7XmUGL+1jbnd2VUI=,tag:RS6vetOvaFMPcBKL51zH1g==,type:str]
borg-ssh-key: ENC[AES256_GCM,data:v3L+l3mfwLtczvuvYy9JNSTYmOFb7zukqEBMAr3jmFg/axKyGAt8gkYzmFXhVOndRxoq2jbKyvATPqA5dz0p0RWFUoZ4/dcnKQ+G2qLon5kkEAaPSiXDNi2IWDx5toOueHirFjX4R/PEMfPMxLsVA+x8mNJEC03nIJ4Y8G3fATkmay7TVtGXEXzLJH6/WAD2nGmnHQbpEIntsxvM2s11lh6uetUtrQ/79SKB9iZPWCD76j2+kLsr5jDKyjSeC/xrLehtBJFuFwB3keUJGCRk1GMSYsmlJm8ADi0tIkBf2hPEFCmO0j2QEHeK9zmh9WUiy6e8472+rOm+DKAWJz2mLmwjNXqGvX+mYjl0FW/BRipodUDVC6xipfh3mN4B4OEV5vo48xhvf7Ip6ZjIC5Z9j6cpk81GG1rLnJfw6Yjn8bcjkF1uelYy9poMBxGqQLRlQSP0vFttAh5Z5omlGl7laO/1bKs6dXxpxmHBYRcnHHP1frL92bUgVbHjC8naBqS4gjRhVrANNtkuQmIZHuCmdphKMDpIRqypXNT5OdO7GkuEIxAqiUFy+QjyRSHSjroMHPqxSOSNc/d9vQVC9JR3Fb7QP2ysvL1hz0L0Yz9PNiNNh1yRc5coFQ6L0TGotCsQQE9JOscDvZsary9vghWLWo6VT2RBMMCDcwTs1W8zLCnW09D5DNgIAjn3ykDIvR5x2RjnS6RDaOJqamQpakTmKhvff+kXGbAQfDq8Hnx9nj8+27lmu1g2B41F+8fUmjXXK+5vfoL+9Xcv+XrWpIQxdvhRBKzGiVLnn5pB1QBOHBjpNqLd+Ahv82x7jxNKLie1kLy2x/VN2DP3SIYWTl9QdRngpICTy1aapMeNbNSXhhSq873laVUXPWhOcm8MphatUlyrdySjF0RM6DBp40KlCXCebNGRSv0Yjn5zxIFXXEh6o5kJtoUzgsv3Y+Fzy5VibkFAHoAvMPCJZDtfFHLrmryp+L4GzgLktCKefsASL/xDxSiu5dJceOsefj7etXr5GoEvmrteS8Hm935R9I7MycmmDKAEKOPhO1RO1p/m9f8qUmaiY8WGkPoIJVHp+fQd2WjlE7qrvIr5e5U4aUV3FvRm1TEuWNuZ4gQ3lpQFNsWcnVpBwOtIT5OsDH45oVZ8xVyK2duMvFoMYRkRW4QnCZWPt0oaLa9/GHmPd39yAfStvK0ksOQwWiQGp3feeFtTxTWiWJicnAAMB6BK7xX3A2gOF4RkVii1YyuGXaj3c0fZakO2k2pQ9TXOn29lSxBNwNvxhP8uUnPVE5izlwSiPAcIy2x3cPEOWNeQQJJZxLunOil17Le+WDtxDsbcdmcEGUQLLQJRzUxWOvaiIo9PUwVcSjHEI8+t8JN7IgMNT8QOvIextuhY4G3ApVJCkgvXs+QwTckWKDcSIiHdIt/I6SHlv6BkNfja0zqZIJ727i4huNSfoO/vq4BUA89plxVMugmS/oLXIUQuKZM1xC1sypvjxu3W430BN3tkPmtSD5n4cuP4hLN7TtNNfkFBXe9qT4bynGHJ+q5Zr0SMK/sgF+cluuR6GLljUSCv4KH4UiVIj5ZS/iDE96vAfi0LXuOLe9TZmxgPeDVqWM1392sSwE62vJ/xTVb8Smq0yMqsGTCDg5yGBcXly3FTcbe6AU8NGGWhY+n2UoV3McHSZNzVVdeD9YvhXh1YbmXoYwguiPpv16GpxL+OnWkMFXHN0p/kK/nEX7eAq/okeMc8RHSZcp91ZYW62S7QXkIsxvQj025l589ta9S95S3BdeOWHmn/lE03yxRXn5Jn60gs02fWLnqkwPO0X6nrIWWZ5SHft3owpSttjertO27d+lZ9J41JJPU7m9wgDTENtK1UqxCsSA4x0943FLcZWNM1bNwStfHpWQsCdtcCNdNSWOJ5qpTySOnzyItckOLXOlTW/9L06kQeBFZj9Ci76TtcGUfdArRMA4xumbZAdiXsNz4IM6YjERkMj4iDL+jtRpPjCynQ/NVjd1IiWaMkndFxvlqyCcI83IZaqvRqbh6zd8p86IdGcWJYiB1cRlKNeIvltzsO4X6HM1LI8PHcBb+dXoU+c7Nik/2w0N42xvdFeMpCakNRA7wtqWDnvkEAkn+gaaQCKuk+aif/rPWey0JaE/f2JLrQiuBc1CHEOclPRNOW8UnQ4nBtddL6h7KdUJb5fTt1Hamsluzmz3/rR5v08pyKIvxGHDM4YZ/2t3mbK56pJuQhhrfPD8ZuzqYaxKTojG6Sk3ollN6CbjEsdO68aaLNyK7fzfSU5NbN45uLgo1w/+JywWhYIuWEm72GhoqJyaj74NpPn8Nz4dcL15wrivnuynfQ5rr93QZbxSoTFntHMJ9AIY3aNmyzVt+VB5F1Y/I4SfZ66MuCwXyAuZCNe1cHPk/CHB9BtrO/n5KzNdVnvNvH9edQYSzP63qRmGwtQ3iiNwIo2uMmEvmzfSgcrOE5ZCaY2roqESO8sPSoasbF9STOlMT4JfWkyjAozY9eRUnbqTAl6StYmTOaJ71Qyy0okujQVxXsq7ZFshsbX5xhy+h26pUQy/951frrAPn3cIhcBXFuoW9Re9Tiyx76L5cUzGGN1AcaQ0FvlLj5V40zfvSOOFrZEqjSGTWnFuRam8lVxGZEWy5zESeeWN97S7IyDlgOfq6KsH8UEr1ePnuLG7jyTSEeNGJQ56l6ht1MVyA+4To6KIEkhepEpOMd4G5wKpJbLHSqZLxbT8Z46VTOFr7ePllmBhZeFdw7YlI7E810BTB1qx7C8gQvSC+N7CrnRGoE90SRGBKBE3smHN44hdvHWl/tS3EdC0Jt7uev4v2jLhLyriuSyal87Nf8vVTsoiTV8y40R7CCum403RAowHVuPfhRWNl4kGR4wqb9Xib2g9siq8NyaY0Z7kIZloBPezCONpfjkIAYrTf8K6g5EVk/Jl5tG/ZzkfW9z9bTiO6jcrfAnQ7B+K5hTq7I1n9xTr7tejscFWUPZnDgx8hl1BpD5TkN8UoA/TtjqdofwqgYT5so/xqXc6mCCAB/OJyh6Q/6GCthP1haAwkyQpqLPlKklIo+gFWXJG4nsf570piqQ0OdKZ5LLKcUpysmCp0OHivQr/6sfNWxMXwMdCiEBt6pLaqv6tMI7PobZNJWHeesu3sPAngFwgf1c6BGxaVWXDY/eF5OBJevq9AoKrdsnt4Nd0veVgKrp3wImvw2HQBdR4wdCVizhESgvCFY8Lv/8zCQpNhSXlfQ32F8onRuMZl/ZHJ/+N1Vec3HQ61AAwObML3vs1xrkr52QG60UZQCUUYoxYBcfPU0RXNYOvrejCIVIHWb/NnWGQ8x+l3ysjf1fvT9DDcuLtcCO3+m7Qvl9WZdNChQchEGmscDOO1geT6oZUDH+ogzKUOWInccaX7eoUjL00CUF6D27KALXN+ySbVLG+ASFe/L/ntW+P9Y/p6CNL6KLZq4isrXSQ==,iv:FV3HSPTmmRT0TeT4eYzVN+nfSqgOnfgngDALBCDRhYE=,tag:vZy57/c/xwfowvTsEZ31CA==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age16veg3fmvpfm7a89a9fc8dvvsxmsthlm70nfxqspr6t8vnf9wkcwsvdq38d
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBWUmdFMFI2SndUVHM4TTNl
Q2ladjlZdVBrbEswQzJhN3ZKa2x2SjEydWw0Cmo4UHBKYWpJTTFvUis2cVY1djIy
RkZiS3huWWRnV25LSmZLc1MxNkhHRVkKLS0tIHpCSjVYd3FCZHhwL25iZXZKYXFJ
bGZ5cUs1TmZwTXhDZGZzMjZIMzY0dTgKq5APl91yuaaStDkDJ2L697sKJGeNLBt4
/Eatck1dvd+q5lHoqIDS5kInCfqFAxinR8oamLoYHbqKou1ArNpGbQ==
-----END AGE ENCRYPTED FILE-----
- recipient: age106n5n3rrrss45eqqzz8pq90la3kqdtnw63uw0sfa2mahk5xpe30sxs5x58
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB4WTlsdFVJcjFBL0x5ZHI1
alMwWVA4YkpTMDE5NmdLVjYvaFkzRnhJVEU0CmJ5U3pSZzZSR3B1ZE1TelZncXJx
KzBNUGszNlVld2ZJNmx0YnpZVnMzbGsKLS0tIEhKbEtFYTRST3BWTEF0d3NnTFVZ
WHlMYjlEUGZQR1pYUTFEWnNVcCtLYzAKc3Mp4M3DMys3XYomui+RVrdbTgs6lTQz
+e4NJH9/9fL73HfaoiMMiZZSrXObboh8Wl+iwpfZ6b6rWatBTLAn3A==
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBLQ3N6cVNjOVE1R2w5VS9I
RDF2TFR3Q0w3M3VVZVpCei9MNUF2Nk1aaVh3Cmk5SzlhVzcrK1ZvdmVob2J5SXVF
dmpQVW54RVhGR1BxM254Q0ZQdS9JWG8KLS0tIEE4WEdNdU9tVWRzWW5zajdLblNx
b3FkMi9iZjlKaDFyQ3Bid0sxSzluRkkKUgdqPYbOaWG+iSGNSIkvPc9V4O/WztQc
ak8iaZ83KR46o1m453ZesEGDjCRyfFQomcm+WcqM0Sdj1uT+JSVJSw==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2022-11-12T17:45:33Z"
mac: ENC[AES256_GCM,data:grOUX0hyU+F717M6Y86jnHKEInjRlwDB96G6IxB0E45hNy9kT2nYfDwnevu+swhgYb0GYTqJvLbmvhNPFXtL9x3Uc8aecW96a043YhQPUvUSa0dluCYGTInL6tsiuzAqpS2UgLRdF15lx8otvnCs2Gi+77SS8U7MoaIeKaFKN5s=,iv:MYpxbmM23soEd3t5uieLuMt6hpjiRmAn1sRPeHt50/0=,tag:9GFBtyAt3DxMMJunQlLHvg==,type:str]
lastmodified: "2023-08-18T23:09:30Z"
mac: ENC[AES256_GCM,data:w9q6bJl8yWm0f3hFljfthn6/h8JWH2ZJMdQCliu85QhmtcL2jg1pJeVCxxaeQFYUia+zdpwebB6ZQ/NVmmAwqkk2Kk9CyAvIifNwOz7PrJM3uycibhl39jiSnuuPvxe8MQnkBC5N8wymCBRHDRzn4gnFOzpoHxv/Rc64dwG63fQ=,iv:CjLFjoN9StU3m7lrgQtcJtV/8KMp5UTRZWjrc3O5nio=,tag:sHmc5HcdP4Qm/xZFGO7/BA==,type:str]
pgp: []
unencrypted_suffix: _unencrypted
version: 3.7.3

View File

@@ -11,6 +11,8 @@
./utils/modules/authelia/default.nix
./utils/modules/autoupgrade.nix
./utils/modules/nextcloud
./modules/postgresql.nix
./modules/grafana.nix
./utils/modules/borgbackup.nix
./utils/modules/netdata.nix

View File

@@ -0,0 +1,78 @@
{ pkgs
, config
, ...
}:
let
ldap = pkgs.writeTextFile {
name = "ldap.toml";
text = ''
[[servers]]
host = "ldap.cloonar.com"
port = 636
bind_dn = "cn=grafana,ou=system,ou=users,dc=cloonar,dc=com"
bind_password = "$__file{/run/secrets/grafana-ldap-password}"
search_filter = "(&(objectClass=grafana)(|(mail=%s)(uid=%s)))"
search_base_dns = ["ou=users,dc=cloonar,dc=com"]
[servers.attributes]
name = "givenName"
surname = "sn"
username = "uid"
email = "mail"
'';
};
in
{
services.grafana = {
enable = true;
settings = {
analytics.reporting_enabled = false;
"auth.ldap".enabled = true;
"auth.ldap".config_file = toString ldap;
"auth.anonymous".enabled = true;
"auth.anonymous".org_name = "Main Org.";
"auth.anonymous".org_role = "Viewer";
server = {
root_url = "https://grafana.cloonar.com";
domain = "grafana.cloonar.com";
enforce_domain = true;
enable_gzip = true;
http_addr = "0.0.0.0";
http_port = 3001;
};
smtp = {
enabled = true;
host = "mail.cloonar.com:587";
user = "grafana@cloonar.com";
password = "$__file{${config.sops.secrets.grafana-ldap-password.path}}";
fromAddress = "grafana@cloonar.com";
};
database = {
type = "postgres";
name = "grafana";
host = "/run/postgresql";
user = "grafana";
};
security.admin_password = "$__file{${config.sops.secrets.grafana-admin-password.path}}";
};
};
services.nginx.virtualHosts."grafana.cloonar.com" = {
forceSSL = true;
enableACME = true;
acmeRoot = null;
locations."/".extraConfig = "proxy_pass http://localhost:3001;";
};
services.postgresqlBackup.databases = [ "grafana" ];
sops.secrets = {
grafana-admin-password.owner = "grafana";
grafana-ldap-password.owner = "grafana";
};
}

View File

@@ -0,0 +1,9 @@
{ pkgs, ... }: {
services.postgresql.enable = true;
services.postgresql.package = pkgs.postgresql_14;
services.postgresql.settings = {
max_connections = "300";
shared_buffers = "80MB";
};
services.postgresqlBackup.enable = true;
}

View File

@@ -1,22 +1,32 @@
borg-passphrase: ENC[AES256_GCM,data:g85FvdFhbmBR5Gvh+7/qusK5Md66+7OPL2VRQu8R4E96LhsCjvpgDMQF9puO6wWNuIw3CsvrkYzQnU6/zo4BnA==,iv:Drv0wiZuZbaenZYx2m+QW85TaLIdpHbN0v6/3exP9gs=,tag:v6BNQFfphAMLyyXGZlo9Pg==,type:str]
borg-ssh-key: ENC[AES256_GCM,data:aE/MiD2fSxG0B8C0e4UYWtqToj+3cGIDZTYMGZRDWr4S3535CvtG2j9W9/wG6zKnsDX/EUGTOYretk6/RsThYI+p/iZRntwvZ0PG5lSfg4Y/7EA+tuRWxLekO1u05h4aYOJsRtJEl9/dRwOAjwxyeGvWV9bvtlMoZaOrbujAU7h0VabW/yC7L/D8c0CzR+Whx04ecnNhSz+aSdydHhTvCJKt0vtk3Qdo11MpQm3Hig3zltrhz9EwBm/Oq4Z+FCe3bYrqJI3kb+C15JTaOydHURrspwWIHB2WNJ/jChyM51M8GCx4SJGiOdbV2pYIF8v/mGoioUbemqG5yeq9tdqEnOqh/LYLREfZCvIVJ08BDLCllV0ajveiggynbdKWIJDMl2z9EsdQMIZYc+3wd3H8/FnpAVEJ0dw62vrmogw9xhQ6zQwpC2QyxY0b37QcsHX1IGI+u+Sn9zG+Ihmbo9BhSBWD2b22kt9JjaPgrN42kVWLUbmJhRySipeqShwH0dkcNHwMf+pF/9OzpYd8cUhBXCpTf/nkKSduxLmj6CsuUCVA/99D0TQg/X6e6qXcGRgXEr79iRyYlC6KKBNu1JLuQU2GqKhzs2wbIUjzCYalVZXL5abxoxatV7hO0YL9U8mmqoJtzHBSD1urKkn+mQcbrm95e3/kPZhQNQKcDyT3Cp3UpGiSG4fcUTXx2fZuPxyMJPE882UagTBM56g3fpAbWKGHeFaxxJoprWtjgYKT0oKFQuyYdVGt+HeGW27vzArObpRP84LSnhpWTNK+iqGMtF6hxZOjWZwmzKatIydCBx15ScH+N0NkIXdN7DxdmhCDie1e9N0DfWCJZn9RbGo/36ksfdc/sirYSxKCZ3gUIveirvzH2ovyC11WJTf56evudYU6LahJQzOg3KTTntNKV221OvuelRj+NKLCkbKE/Pi00cDQ5WTMCX3PUdb5fk2ZdqXfLD8vJWzy0G+7vkrsJtNvzzcXZcQms5knSgX8qwrnGKJ5nxlFaYLzHmSV9GINH0SYZV4S6EwF7Y2Vi3IGkkNGP7VPRcJS8MSoZXYcLdaHBO8DwMPfB9Wi3j4qC6OCiUK79iCRyO8bAG0Q9CFH29qVciesdXnV5t9gaeXeGXUkVUM8THW3sq89mV+iuPbQLaTr5To9NWC1+Loq6DOrgWf/6VqcuIy0p2Akfieey1REThE6Bf1fui5sr2tHD5n2yrTC3XiG5RVPee9Kkdr8JaMd/SYsoTHzYkqSr9HnGW8C1SR5PsAxZsnMx/B96LPHlh5BfXoNUlyRrAs6I0B316xQh9q1zGanMyl4pLGfR17P4CEQU6SX7nr24k/PMKfdMn3etumbXOgoKEeZKtwGeEUVhSUB18/+HBnKT+4N8+I3ekTsonz5X8poXio6yVJ7SlH8gjNAaq7siM9eIE63001EQLZzappJYWEB/LAfYcHfjyASzLTT+FNUN/CiaMUIIiuRPltvnDbBvvj3L/eaDg/yfiMGXZcl/2J96tRyzkuKwzmmaTMy8VQfqHC3ODcjibECIpj7ODtpqqsjB3rjosUKT7dL7Xe7rHFltLjt4aYYtay9WdCWEv1yl2WcQc6coyKwmwM3Cr1i6opzlZ7+bfIGDW3hRN+1GOr+UfViyhJbbczeuhIWTv9toFtsXWSLu31OBWntIDRsdLCOUQvfP2gj0aaR5LxsBdYo6Hm/qSSMXWsPLD3K0SgXZMJdX+JAz6pgYMTt/OJaFfn5hYiSCNRrbNmnTIB8r/9AJNjfpWtJwtIJj/d5tZr0F4J+ax16OCQAfL/zBhn1opHNtxhdHq3hFWH+DAEglBepnJt85I/h/RBQZs5MqlqDPzKRE7clPzkEB3dViQtrkrmOUCtWpGXhHslo7A3CDGoQ/0KCMLniGM8A+Ig6iffry2xuYzf78V81DM+Wq93XaOUhVn9ztJR22T5bWb2zK4W2PirMj0Zb8Oh7ihJW0OSavhllfrpnvdDU5aWzcQ8GaVRh6BwYS+sOctEvQxmYfFXHill9BMxyCW5OWXd3K7gQOLLewFcOHwNu1chBrDSamB1C7Zaf6HoZdGvCZRn9NMYi7vdc15uJMaoIbKF45QBaldspe6dUTMEM3AXtJyzONhGRINiYaMPfGEn4J2YHToyOyLEOsIb+zKU9iqxbvyLX46IVO8CyIeWNm4Nwo/C4hSPFVzHqmGPPL3lKrJIZwaucDPUTiveE/6AUodBPxDLGmqjx5k4mPQFyelrTUAF5VfWcTJlot99R32FGTuRIM3kN0MBE0JhI93rg/o25rLf1y2oHhkcAXlzTE+KWP030iiy8yhpgWeE5NAwPDlVQvSOnaUefEurCqAfalVylxBs8TNWw4qPv6NXDBVsjdHh4YQxlXG++YKnTZy9TG4N4p0HI6I1XDB7jwVyBsDAj1WhWmNeEdIZVBbfQmZ+wibLhIm0msDSoU2WlRwFC2BMBYvUJVLYGlLrcn00yCa1xuus6rycx80WhNoyUswlIUMhsGMmMnaU5coSt6X8Y2NuuA1DzLy+P1BHmwhtiZp6kvGBkqVLhToVbpOILaIFDqRfejsR6GgHYHqrw6dBn4IMZyZrxICPvPQVx3Wu6nsWskjlqbCILpGyt35CkyHe7lRdKZvQuAx5WhErj3T2KywElPH/TADy6oQ4KBKASjFEnDa5k38Ro6j0yaN5nFZqeNBG05oVZW7xD05C6BcyS9RqdqCMhlAmmN0YFvSm4QJv3BRmoX5x9PiLvbJP3n00FtG5kyrErA0IoKiG3yJyIj6ZKXMXs5v1MrkL1QlXt5+J9sKe2r5CETmwVZWBJg6Ou8R+yMVkEEvwx8h+Ngvu01borhECJVQdEci50ZTEaEt3+Ef6n7uMpwHll1LYlTfPenPyBR4zYeKb1Pipb+taFEvDZVshL9q/GwFLjC7+swKz8oRY2N381j7s2zSJdutMWCa/NbSgwPdQT4kla/jN7AeATEC/VJbXLGvdW2LVOuz/1VWb7MNCOxNM0uyv27jhdCfYecUDRYDR273GV/ia5WVtM9cx8DLLG6SgalBvyH1wqDgXvUuYC6ci/hV0ekfKyeobXs4unTeKG0bQTozcDnY7gr/6eclsyOSOK7kddjAHxFY+oLbBb3iQBv0vMYL5++YxE71LNn9Ql6mm+K1J5sRY05Gr2nbb4cqF7HcGP476O1hbiXf9cuGJN53CotGqHrdYhMcPW0wRO5o3z2jh7/9g8gebtUYkYmgKDdmPlFi9DQ1demdBmeszWF1/I9nS3aFdBSVbwa0pbKmLUzH6eu1eu7lxY9z+t70MNtcJxHUUQqLCOLW6qhi5BlDu+RqlyfdNWrMg01+FOZVH60Qi5jCIiWzhmwoeawa3++kxkVSX2wbNQXC2qdU5cjg9ighHnWw8K45JbUxVcI+NAc7AHPZEcLft4/jxYfPiB1zWQvQ5mtWh6PP3viZxCrrw/7MnXP1AofA==,iv:UkU0lvcPJVWqIRdM3isrr+JJP0xz7cf2CYeBynpa0ws=,tag:6UkLgdb6kIsWT8qFe5G+KQ==,type:str]
borg-passphrase: ENC[AES256_GCM,data:V77hfP5jk/DXcvRiZKu6RLAqsJhlIelkQwA6ClYJKNmMtvAXG+g6794YJ+ooof1h8qcnMoctEWMUcsBetjaguA==,iv:OyJF/dftfEaGUnmbzrcn0P0tvnUZX4l6Vk0Qf0NwwfE=,tag:AAkRMD+jq01BPq2LSYPQGA==,type:str]
borg-ssh-key: ENC[AES256_GCM,data:7F7uUlTP3ZKkpySj6/AGfH3K1/8/GzIdfp+ch1hU55zX51KgRs/KuGmj+yKyH9ua41oR4FR94MoiTb3u3MRpUj6dqO4VjVm6fRgJFNXOBhTUcelRR98Nq2QClkRqcNmPiHQC4bxjyW9C1tZfCA52AIILGh9O1Q9XnYAz2q8JwbrY+eTXS/U/1Fh1D+0Y9q1n+oingehal2huHzeVsLxFlip3TmGJx8QBlnAbANABKrMFxkHAlkvAVCrF1MULzeDeeWscHi5T80OvJfOZBSonNEZosw6QJVscMYxh047Yyl6YJ/sxIJjZjC7GiLuG/FC0FCLKRhD8PkZFjrDt/6xwrqePxIb7yIKZRpsvNVCplDDdVOB/V0AqRWAeZh3z813Zi+tnjynHPYaphso/qY2r/HZKlGInzW+QCUBdPVifhVL+y2TKytCWcp4A+c/3Dc2Ut59sfO+hqE946nYGl2S+kpNASHhBa7o6cnaMtfz8NT6rVtYN/3l1snlxeOUZo85XAuYCIerGsMkdVENg5RIJwIzwM0oaGwNzruq8cul5MfAf8hFMXpoLggYECynHk9TNdhsNtUzmsS9cXAyPnnzZT6HGI2/5cgU1weCHbbXAq+ZU9WZwOT41Fpwda/WrNJuMJYFCOFer2hcSLEyxsCfqmPSdwpYRRSYHiaCuVghV6lWyi1IVV5EsX9H6hD+Uetux1SEN95ga8edME16W2dubA0yukcOq+XHI7PMEHAs20H+dybsmVx1XjIsiV/XBWkrooFBXQp950p93XOK49vwNmHNohhCvmERkH0dczGQ5vTAMXwIYqydTqXWERDRzJVvK+pbzKiecEzhFHFge345poUKQS7BWNsv+eehgBAH4HEddtzzzjcPGYMHAhafAm1VqO2BvKg2r3XnzElUCjxWlGfrMkU+LhIgAjom8Mk9+Kha+OD84+iZnuoq73TjpqaUgC0TbkxLAm0DPgk8LsLE9XfJaroftKnrE7P7kyNGSQZfGYcl7ssLck5LJA07dTvDtytlL1Kk8RJe4FwFNPLtdiAnCVvKBe0kcClvCWrrxRt1QT85b+9IwG1yhRxlxheleePX1Fwlg/d2xj6AB3Cz7kAVO2phGPAF16Ke/UQeMxhbOIcy20g7RoiCpfx9jvdwExhDmbmUR7cleL1seFH+wgAM6uQwh80+q8IDJWPNyeXOwiA2siPwexb20xN+n1kIMa03U5Bn+lBqYoh0xXhlDHP3FiKew6xjSducNUtzyKm24kQaWSOfYIqTxYFRTI0bDgRu6xWGmZL37VSMWqDj3TIWOMBoLy0JBsRl6Jj07keJ0CwaNEa4cCWZ0s6nu49mp04JfJWF2r9ksX+2OVeDjSgX5JBB/V79j3I8iu4Nlp0pjyBKPlST/FUDAl1jT12X1grkYjXO8UyJ9AQqqnqK5lM+KYVR15Ui1lBb/vISPqiiw45bcUyHfVAAt7hcFpYLaYB0om3mernccN2fi26lawhhambRd7FGkILKA3byE9ytqGvDQ2CxtjA30kbGxeqXVFsyzROahR0c3KdKlnuCO9Uar4J5VEXgv2obNlNUfSMa9uleWDuhveBaE+2jtKUJd2P4wIIzF/VJGxgWGSge/ji0EV36EFfMg/Tyizdw5wtv4rQF0M+Uu6j/n/l62SmHnT/30H8IFCFuXWmtEo1xcssMymY4ricU3kJIgjGO9h+DrBP1GBczj7yVjLHTpEhRF0yP790xgsJrP4IQB2lOtGf5MCXLrBDYkOZ5xM3+Rq5ZNH0SAHRU/qtFUmLtfkcidjkPiwdqJ0e1LUtLwmSlsot1CkPs7hKORassyUrug7dCtv9QjRMDbtW61PlIbXqa59Aimql4IUcWyUybx12E8wRqmgcX5kG2wGfd9ZFUj6mXhQINFqChsTjXSavQw3u3m8kvd1mJXfjKS12ajr2X1e5wPDUEpLzc3wTOvVgZizGeykKTcKG+GXSjPXLR61ueAO26rboYiDAeSd73shFX/vvut/aB47kZobMOooljGVtnfZjVGY8dWzdNeGvBeLws7vnFrH1u/WXPxpktGz2/eJ0L8ANJd+BZ2+wC+R3OnHeDiXHfofm3dZJTncgxYPqboKKCXRzMviSCWB3poQTm5vEltsQOR6Lj17UmHu5MX7os7t7TrfW/op4Qko9ViWT5vtrUrCZzVqJS+d8hq4lm6ANMhi3Ql+nIMIxK+hjGZNBuKZEyKY+r+Lhz9E/xdOBGVB8QH4g32DWsYvaHfpcvJC8CkGO1nRIGFyrMc10lrv++XQYtiZ1Z4a0oOtQGAXaPGQTJB4KzwlGWc0+kguV+lK4h0QIvHvuorghYC4EJerNdRUviRxZB5mTDyJc1gGq6YgMr4d/a4tyXwoEzPbPGc/3YJATZPYLXOMaGDo0rd2961CFfrsneElNIZ71DWoy41P1fJG7qrfN0gLjU0aSC1vVnzDM8GQvoJGV35cONT7N7u+hjjFBFciLBNEE1DKge156EnP6VbR2LSptWrHeq3zOe9fN3FFR1WWor+lOl+SFztt7uVHCLuWxYPV+csOeBLQi6OhFnh9r4mLTc43wjPkbuci2jqEVM6Bf5gXQoEGzybhDb/3HfQK00NXovru5uEdREYDaj5NVyzyBhOT29JuOvqX7wEMNDqE//Me6Tx8bU12cuUM7Lne7grgYQMbYfLs3gKzRbeuYCqGCIz6KQMDOZvTR38EXqJxysrPb/HuiPfoSGHoAIHviJeIsy6bF7hKA8BikrMmoNc4762pKNKNzBGR+/HeQ1trDBCbYrTmlqoXPJaeANUZlD9NdwiopTJCBzjP/F61s5bpurAiJF6Ymx5yUHljZGVPFOH/ZawfhEcfYGvMUnAOup+EJCih5WQsrn2vodbVYFJ5GNMrDH9//uMi/cwqFWlBqnKGgnGdyqzXlLYTTMlv7fuh3XxkjRRTh6ZVuLyBqEBnXzSWwlcLOUdw3r/48JJ0JC2/rTLVnb+R7T2/+7uXVQISIrBx1ijtRCzFwaFWAPqsL+nMevAHnjpWl9NvanNWKIPIQ6cHGywxdi/7ynEnCYlY13fyIpagFKrgywsHcHuez8cyNtGLpg6hwbSEeN2wZYld+DQc5UH9pqPvvTuNHu3J62WJHZlkc6yBs/hiZBT/sEZUrL2Bf3SNFjzt/IcNSjlVbpP6dd6HpIH6tuN+lQJNypRe//TgKviHBkN0mzmw7IuRIDz1tcVA28COCo8NkzyD194zxDJ8yYKfKH/YwN5q8/R/r/EuUcY4qbeAokaS7XcIkOp/QFKHVM6AYKZ3SPyB5ZjkHFoHBG7YNDrx8AHDNemG+WUev/flmsEv3ykgTztgOoCmTqH/rduS+BGcKwsNW0iMwni9mUiJfuNdYLqhWohGLWb/mkUVoTgycXtsJ8x5BGkk4wSuGSwGCur8yVel7+Fr6CzsVGiPJOa0RHO6sN+Y9jnSMPIVm+mx16j3Q==,iv:ZGV3C0nvqdEnukiPkeMxDD66OjeXQF4anQLkALmBno8=,tag:ELar6NeP5bjL5L/Z5m7Piw==,type:str]
grafana-ldap-password: ENC[AES256_GCM,data:hNB6CRtXW98yqUqInD3LsZ75sA+lVfmbooehni0UKL60qE/XCZm5B9JVO9pjxbIYZN6Eu/RFX+9L9cJVa5jnEo2MVeLS4CSjqC8BHLArlOuEdA5v8vqqJofBpBfXXN5Ca5xeUDJKz2HgtoTg7G5nTkegGZPGrmj5QQiL1xzco38=,iv:ViQAPTGxEWnjLkJlGCdCq5wW+fbr/O9er8/71VjL/GE=,tag:+Mow4cw7tvtkXvV2iSHeQw==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age16veg3fmvpfm7a89a9fc8dvvsxmsthlm70nfxqspr6t8vnf9wkcwsvdq38d
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBUUlBLUlBleFpnek93MmRa
bXBuSG1VV1J3OWVpdWF6eGZzbytPa3BVL2pVCk01V3NXbTVjSytaY1lTeVZVc294
K1kwM0N3QmxKUTN6ZWVmQUZsT3pZeUEKLS0tIDgrYTFCUGhXQVlnajdpc0dCOWc2
Y0U2eUJJcHA5c1k1MlB6TjMwd1lJR0kKD1V40d1QsS4AWr1wFq5nWeVZlYXNxUKu
nrFju9Y/ceWUBHQ74m5mLzWv8NV0134XQRtQMLN1n1UT9G2kOk0BNA==
-----END AGE ENCRYPTED FILE-----
- recipient: age1y6lvl5jkwc47p5ae9yz9j9kuwhy7rtttua5xhygrgmr7ehd49svsszyt42
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBaVG04UDJWY3NQZ0hqc3FE
cE1wRDBMQzloeFlYclMyUEhTREdiNUcwVHpzCnp4UnpYYll6dVpTZ0dpcGlRbFgw
dTY3N2hRM2JCWWN6R0xZc003aW84MGMKLS0tIGorOW9LRmVrMmxWSEpia0owZk5p
eENYMyt1Qy9Ea29MemZwSnlsYnR1S1UKLC6KyS8tBX6new4iJTtYUl/Do5V2j+y7
+xALI95vVi93pRI0/T9agKkI4m5PqlZoUfo41csnTlcQEWDBcTEbGQ==
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBCaERrQXJycm01Z0NjdC9s
WG0veW9hSVVBVkdMZ3BiczRaSkxEeVNKUjBVCmM0QXNLejRla2xsYXI2b3F6ZDMr
OTRuK1JOVW9kN1NHSkFCeFZXcHh5U2cKLS0tIFhzcjBlVG1IVk8wVGZ0UER3ZjFO
elpwY3Q3dnRzR0loN1BiVk44TTF2VDQKs8Si2LHZ4L4oQqkYUhCI6affE0aTrWmE
L+am++gYdygVURIh0Z6ftUuhYHPwhlCgmKxx51mKRV2ydraOdUUw0g==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2022-12-31T11:41:18Z"
mac: ENC[AES256_GCM,data:2lQzO+BwvBnozb07+eQoCN3mDhVIivOo2RH9SI94xmFkWcit0o1RiWAsu6GDduqxa4DGpY25EV+yjnZJSGc01OyU3e11ycxpwfP6wLA9w62Dh87rM7bzQOmo01u2Dy4k1HUluVIkTgIfl4JZNJtG3iboSi5qlAN9dfiOGYPrSZs=,iv:ZYJ2TT01QKh+7mOpIcohzB8jWSa5F7gUwt8XbhdLr1w=,tag:AXCezSwoIfIcAuluHlIC+w==,type:str]
lastmodified: "2023-08-18T23:07:18Z"
mac: ENC[AES256_GCM,data:nBSL5yMMkdotUYxjQyKw25PHRW31nrpV7XerzNcXj7+tosgYGd8yGKLLKufBG3B3w7wCmDEBD25vK95vW8mlZhCFiVitVg1sI4ZPI9gl0xQFeVNLeeKlQa0Ywnpye+4BktYcEvcZeQSMWEzvh8IjfZWssL43Q35ZROUnsWUjMiE=,iv:ixvpw/oG7lSzZO64uMWyXdtmAIzo8CKEA1h30GbaShg=,tag:Rdb/Z6VW9u6fTzZ3vC+Ljw==,type:str]
pgp: []
unencrypted_suffix: _unencrypted
version: 3.7.3