Compare commits

..
52 Commits
Author SHA1 Message Date
Jan-Bulthuis 9d2e52675e fix: replace nixfmt-rfc-style with nixfmt 2026-05-19 12:38:40 +02:00
Jan-Bulthuis 6c5c69945a fix: use git.settings instead of git.extraConfig 2026-05-19 12:38:26 +02:00
Jan-Bulthuis 9883f3d461 fix: set forceImportRoot to false as recommended 2026-05-19 12:38:07 +02:00
Jan-Bulthuis 6d86bb8368 fix: replace wasistlos with karere 2026-05-19 12:38:07 +02:00
Jan-Bulthuis 0dbc4792d4 chore: update flake 2026-05-19 12:38:07 +02:00
Jan-Bulthuis 753b763b6f fix: use thermald on laptop 2026-05-19 12:38:07 +02:00
Jan-Bulthuis 2a690681cb feat: set up nvidia prime 2026-05-19 12:38:07 +02:00
Jan-Bulthuis 82f4a2e1d4 feat: add caffeine gnome extension 2026-05-19 12:38:07 +02:00
Jan-Bulthuis eb18897355 feat: Configure helix, install software 2026-05-19 12:11:16 +02:00
Jan-Bulthuis 00679a2c04 chore: Update flake 2026-05-19 12:10:43 +02:00
Jan-Bulthuis 8e819e01ea feat: Persist K3s cluster 2026-04-04 12:17:55 +02:00
Jan-Bulthuis cf4c179fc4 chore: Update flake 2026-04-04 12:03:33 +02:00
Jan-Bulthuis c991768cc2 chore: Update 2026-02-07 17:12:07 +01:00
Jan-Bulthuis 268879ee01 fix: Add Downloads folder fix preference for workspaces 2026-02-07 17:02:56 +01:00
Jan-Bulthuis 7e9f617965 chore: Update impermanence 2026-02-07 17:02:17 +01:00
Jan-Bulthuis 7d6482587a feat: Move to Cilium 2026-01-28 15:28:47 +01:00
Jan-Bulthuis cf10e1e963 feat: Declarative K3S node 2025-12-31 02:00:35 +01:00
Jan-Bulthuis 02b2b9cf32 fix: Git settings setup 2025-12-23 12:17:38 +01:00
Jan-Bulthuis dfe6ec5518 feat: Add typst extension 2025-12-23 12:16:46 +01:00
Jan-Bulthuis 517d793c88 fix: Add additional impermanence directories 2025-12-23 12:16:09 +01:00
Jan-Bulthuis 657a65522f feat: Declarative GNOME setup 2025-12-23 12:15:48 +01:00
Jan-Bulthuis 7bc3ab64dd feat: Install some basic fonts 2025-12-23 12:15:17 +01:00
Jan-Bulthuis 2b5cfe0934 feat: Add some GNOME packages 2025-12-23 12:15:05 +01:00
Jan-Bulthuis cf345521e8 feat: Impermanence move to bind mounts for user impermanence 2025-12-23 12:14:46 +01:00
Jan-Bulthuis f43945d0d2 bug: Add very wide initial impermanence setup 2025-12-23 12:13:59 +01:00
Jan-Bulthuis 7874412a48 fix: NetworkManager impermanence 2025-12-23 12:13:28 +01:00
Jan-Bulthuis e33a6e181e chore: Remove Helix package 2025-12-23 12:12:35 +01:00
Jan-Bulthuis 928dc4a240 feat: Add Tinymist VSCode extension 2025-12-23 12:12:22 +01:00
Jan-Bulthuis 63d34640f7 feat: Impermanence and GRD 2025-12-23 12:10:40 +01:00
Jan-Bulthuis 921565fe12 fix: Add fish history to impermanence 2025-12-23 12:08:17 +01:00
Jan-Bulthuis 88792d86db chore: Remove old configuration 2025-12-23 12:00:01 +01:00
Jan-Bulthuis 49b4ade156 chore: Update 2025-12-23 11:59:10 +01:00
Jan-Bulthuis 34f179465d feat: Finished user setup 2025-11-30 16:19:03 +01:00
Jan-Bulthuis 588bea133c feat: Set up disk layout for ws-think 2025-11-30 12:42:41 +01:00
Jan-Bulthuis 61ec61e22e fix: Disable GNOME extension version validation 2025-11-30 12:29:31 +01:00
Jan-Bulthuis 10a3de42ac chore: Install software 2025-11-30 12:29:12 +01:00
Jan-Bulthuis 6f98d674b1 fix: Improve unfree consistency 2025-11-30 12:28:52 +01:00
Jan-Bulthuis 4278ceebc1 feat: Add new laptop configuration 2025-11-30 12:28:39 +01:00
Jan-Bulthuis 3358dd324e fix: Allow unfree consistently 2025-11-30 12:27:59 +01:00
Jan-Bulthuis c3014ec109 chore: Update 2025-11-30 12:27:42 +01:00
Jan-Bulthuis 08ca6a2846 fix: Fix mathematica 2025-11-14 14:32:52 +01:00
Jan-Bulthuis 2fbe36d497 featL Add helix and osc package 2025-11-14 14:32:38 +01:00
Jan-Bulthuis 9929cd297a feat: Helix configuration 2025-11-14 14:32:20 +01:00
Jan-Bulthuis 869a219ab7 feat: Add initial carla project 2025-11-14 14:31:09 +01:00
Jan-Bulthuis af1a275dd8 feat: Add NAT64 VM 2025-11-14 14:23:18 +01:00
Jan-Bulthuis 9d302345ac fix: Remove gtk3 theme 2025-11-14 14:22:50 +01:00
Jan-Bulthuis e0b3fe191c break: Add temporary laptop configuration 2025-11-14 14:22:33 +01:00
Jan-Bulthuis d3681fcd4f feat: Switch from tayga to jool 2025-11-07 22:04:13 +01:00
Jan-Bulthuis 5458f74c83 fix: Set correct subnet for tayga 2025-11-07 21:30:13 +01:00
Jan-Bulthuis 13302deaef chore: Update flake 2025-11-07 21:16:24 +01:00
Jan-Bulthuis 828face9d5 fix: Set tayga IPv6 address 2025-11-07 21:11:35 +01:00
Jan-Bulthuis e4402eaf19 fix: Update tayga address 2025-11-07 20:47:22 +01:00
32 changed files with 1329 additions and 404 deletions

No files matched your search

Generated
+79 -186
View File
@@ -7,11 +7,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1758287904, "lastModified": 1779135526,
"narHash": "sha256-IGmaEf3Do8o5Cwp1kXBN1wQmZwQN3NLfq5t4nHtVtcU=", "narHash": "sha256-glCununz6lmaK5fs2X946HA3EkNxB2JagdAAvInuRYU=",
"owner": "nix-community", "owner": "nix-community",
"repo": "disko", "repo": "disko",
"rev": "67ff9807dd148e704baadbd4fd783b54282ca627", "rev": "d405a179887d52b24c0ddd31e09a150bd1f66779",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -20,58 +20,6 @@
"type": "github" "type": "github"
} }
}, },
"flake-compat": {
"flake": false,
"locked": {
"lastModified": 1747046372,
"narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-utils": {
"inputs": {
"systems": "systems"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"flake-utils_2": {
"inputs": {
"systems": "systems_2"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"home-manager": { "home-manager": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
@@ -79,11 +27,32 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1759853171, "lastModified": 1779157263,
"narHash": "sha256-uqbhyXtqMbYIiMqVqUhNdSuh9AEEkiasoK3mIPIVRhk=", "narHash": "sha256-VbiyZkRf8/qr7ObmlyfOHJsNAW5tyZ4MB1+cUwAwdrw=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "1a09eb84fa9e33748432a5253102d01251f72d6d", "rev": "866412a19866b4a8e32d2306a118040afa2b840c",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "home-manager",
"type": "github"
}
},
"home-manager_2": {
"inputs": {
"nixpkgs": [
"impermanence",
"nixpkgs"
]
},
"locked": {
"lastModified": 1768598210,
"narHash": "sha256-kkgA32s/f4jaa4UG+2f8C225Qvclxnqs76mf8zvTVPg=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "c47b2cc64a629f8e075de52e4742de688f930dc6",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -93,12 +62,16 @@
} }
}, },
"impermanence": { "impermanence": {
"inputs": {
"home-manager": "home-manager_2",
"nixpkgs": "nixpkgs"
},
"locked": { "locked": {
"lastModified": 1737831083, "lastModified": 1769548169,
"narHash": "sha256-LJggUHbpyeDvNagTUrdhe/pRVp4pnS6wVKALS782gRI=", "narHash": "sha256-03+JxvzmfwRu+5JafM0DLbxgHttOQZkUtDWBmeUkN8Y=",
"owner": "nix-community", "owner": "nix-community",
"repo": "impermanence", "repo": "impermanence",
"rev": "4b3e914cdf97a5b536a889e939fb2fd2b043a170", "rev": "7b1d382faf603b6d264f58627330f9faa5cba149",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -107,76 +80,45 @@
"type": "github" "type": "github"
} }
}, },
"madd": {
"inputs": {
"flake-utils": "flake-utils",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1754781336,
"narHash": "sha256-EUavinU3psYqVDx7Cjdypsf4dUymdu1yawbwRYv6wbM=",
"ref": "refs/heads/master",
"rev": "d490b648ac5acb65aa24c8e8314c1a6fa9e2c0c1",
"revCount": 8,
"type": "git",
"url": "https://git.bulthuis.dev/Jan/madd"
},
"original": {
"type": "git",
"url": "https://git.bulthuis.dev/Jan/madd"
}
},
"nix-minecraft": {
"inputs": {
"flake-compat": "flake-compat",
"flake-utils": "flake-utils_2",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1751650156,
"narHash": "sha256-1gIPVDf159TQlcVg3WQBHMZVn8RllHOa8eT7AJPj2IE=",
"owner": "Jan-Bulthuis",
"repo": "nix-minecraft",
"rev": "d3b3779fd78bd55db24d25e896438b2b51cbb6cb",
"type": "github"
},
"original": {
"owner": "Jan-Bulthuis",
"repo": "nix-minecraft",
"type": "github"
}
},
"nix-modpack": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1747559249,
"narHash": "sha256-+ygKEGMVcXNklO4RDYSd5XzydDmQOZWcOcxYZf/PH1U=",
"owner": "Jan-Bulthuis",
"repo": "nix-modpack",
"rev": "a093625c2847afc3ef257513161c7fe318c6be1c",
"type": "github"
},
"original": {
"owner": "Jan-Bulthuis",
"repo": "nix-modpack",
"type": "github"
}
},
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1759831965, "lastModified": 1768564909,
"narHash": "sha256-vgPm2xjOmKdZ0xKA6yLXPJpjOtQPHfaZDRtH+47XEBo=", "narHash": "sha256-Kell/SpJYVkHWMvnhqJz/8DqQg2b6PguxVWOuadbHCc=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "c9b6fb798541223bbb396d287d16f43520250518", "rev": "e4bae1bd10c9c57b2cf517953ab70060a828ee6f",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs-stable": {
"locked": {
"lastModified": 1767313136,
"narHash": "sha256-16KkgfdYqjaeRGBaYsNrhPRRENs0qzkQVUooNHtoy2w=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "ac62194c3917d5f474c1a844b6fd6da2db95077d",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixos-25.05",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_2": {
"locked": {
"lastModified": 1778869304,
"narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "d233902339c02a9c334e7e593de68855ad26c4cb",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -191,22 +133,19 @@
"disko": "disko", "disko": "disko",
"home-manager": "home-manager", "home-manager": "home-manager",
"impermanence": "impermanence", "impermanence": "impermanence",
"madd": "madd", "nixpkgs": "nixpkgs_2",
"nix-minecraft": "nix-minecraft", "nixpkgs-stable": "nixpkgs-stable",
"nix-modpack": "nix-modpack",
"nixpkgs": "nixpkgs",
"secrets": "secrets", "secrets": "secrets",
"sops-nix": "sops-nix", "sops-nix": "sops-nix"
"stable-nixpkgs": "stable-nixpkgs"
} }
}, },
"secrets": { "secrets": {
"locked": { "locked": {
"lastModified": 1753885198, "lastModified": 1766822527,
"narHash": "sha256-UM57wnpaDbG/l4891u0LnYFgyyr9o3w9ot4gmjBL6mA=", "narHash": "sha256-0qNxAxr7LQ8C6MjSxV2FkMSfdVmOVRq7Yz/wCea8plo=",
"ref": "refs/heads/main", "ref": "refs/heads/main",
"rev": "9d5275538af75b1539faf16c478140aaf2ed6738", "rev": "695e36891b5de248993845e1435df5e4116a26f2",
"revCount": 15, "revCount": 21,
"type": "git", "type": "git",
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets" "url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
}, },
@@ -222,11 +161,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1759635238, "lastModified": 1777944972,
"narHash": "sha256-UvzKi02LMFP74csFfwLPAZ0mrE7k6EiYaKecplyX9Qk=", "narHash": "sha256-VfGRo1qTBKOe3s2gOv8LSoA6Fk19PvBlwQ1ECN0Evn8=",
"owner": "Mic92", "owner": "Mic92",
"repo": "sops-nix", "repo": "sops-nix",
"rev": "6e5a38e08a2c31ae687504196a230ae00ea95133", "rev": "c591bf665727040c6cc5cb409079acb22dcce33c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -234,52 +173,6 @@
"repo": "sops-nix", "repo": "sops-nix",
"type": "github" "type": "github"
} }
},
"stable-nixpkgs": {
"locked": {
"lastModified": 1759735786,
"narHash": "sha256-a0+h02lyP2KwSNrZz4wLJTu9ikujNsTWIC874Bv7IJ0=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "20c4598c84a671783f741e02bf05cbfaf4907cff",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixos-25.05",
"repo": "nixpkgs",
"type": "github"
}
},
"systems": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"systems_2": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
} }
}, },
"root": "root", "root": "root",
+13 -8
View File
@@ -3,7 +3,7 @@
inputs = { inputs = {
# General inputs # General inputs
stable-nixpkgs.url = "github:nixos/nixpkgs/nixos-25.05"; nixpkgs-stable.url = "github:nixos/nixpkgs/nixos-25.05";
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable"; nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
home-manager.url = "github:nix-community/home-manager"; home-manager.url = "github:nix-community/home-manager";
home-manager.inputs.nixpkgs.follows = "nixpkgs"; home-manager.inputs.nixpkgs.follows = "nixpkgs";
@@ -19,15 +19,20 @@
impermanence.url = "github:nix-community/impermanence"; impermanence.url = "github:nix-community/impermanence";
# MADD # MADD
madd.url = "git+https://git.bulthuis.dev/Jan/madd"; # madd.url = "git+https://git.bulthuis.dev/Jan/madd";
madd.inputs.nixpkgs.follows = "nixpkgs"; # madd.inputs.nixpkgs.follows = "nixpkgs";
# For Minecraft VM # For Minecraft VM
nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft"; # nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
nix-minecraft.inputs.nixpkgs.follows = "nixpkgs"; # nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
nix-modpack.url = "github:Jan-Bulthuis/nix-modpack"; # nix-modpack.url = "github:Jan-Bulthuis/nix-modpack";
nix-modpack.inputs.nixpkgs.follows = "nixpkgs"; # nix-modpack.inputs.nixpkgs.follows = "nixpkgs";
}; };
outputs = inputs: import ./glue inputs; outputs =
inputs:
import ./glue {
inherit inputs;
excludeHomeManagerModules = [ "impermanence" ];
};
} }
+30 -4
View File
@@ -1,9 +1,16 @@
inputs: {
inputs,
excludeHomeManagerModules ? [ ],
}:
let let
flake = inputs.self; flake = inputs.self;
nixpkgs = inputs.nixpkgs; nixpkgs = inputs.nixpkgs;
lib = nixpkgs.lib; lib = nixpkgs.lib;
nixpkgs-config = {
allowUnfree = true;
};
importDir = importDir =
path: fn: path: fn:
let let
@@ -49,6 +56,13 @@ let
pkgs = ( pkgs = (
import inputs.nixpkgs { import inputs.nixpkgs {
inherit system; inherit system;
config = nixpkgs-config;
}
);
stable-pkgs = (
import inputs.nixpkgs-stable {
inherit system;
config = nixpkgs-config;
} }
); );
}); });
@@ -102,7 +116,9 @@ let
homeProfiles = collectModules "${flake}/profiles/home"; homeProfiles = collectModules "${flake}/profiles/home";
inputHomeModules = lib.map (flake: flake.outputs.homeManagerModules.default) ( inputHomeModules = lib.map (flake: flake.outputs.homeManagerModules.default) (
lib.filter (flake: lib.hasAttrByPath [ "outputs" "homeManagerModules" "default" ] flake) ( lib.filter (flake: lib.hasAttrByPath [ "outputs" "homeManagerModules" "default" ] flake) (
lib.attrValues inputs lib.attrValues (
lib.attrsets.filterAttrs (name: entry: !(lib.elem name excludeHomeManagerModules)) inputs
)
) )
); );
@@ -118,13 +134,22 @@ let
nixpkgs.overlays = [ overlay ] ++ inputOverlays; nixpkgs.overlays = [ overlay ] ++ inputOverlays;
}; };
nixpkgsModule =
{ ... }:
{
nixpkgs.config = nixpkgs-config;
};
nixosConfigurations = importDir "${flake}/hosts" ( nixosConfigurations = importDir "${flake}/hosts" (
attrs: attrs:
lib.mapAttrs ( lib.mapAttrs (
name: entry: name: entry:
let
pkgs-stable = systemArgs."x86_64-linux".stable-pkgs;
in
lib.nixosSystem { lib.nixosSystem {
specialArgs = { specialArgs = {
inherit inputs; inherit inputs pkgs-stable;
}; };
modules = modules =
let let
@@ -144,7 +169,7 @@ let
{ ... }: { ... }:
{ {
home-manager.extraSpecialArgs = { home-manager.extraSpecialArgs = {
inherit inputs; inherit inputs pkgs-stable;
}; };
home-manager.sharedModules = homeModules ++ homeProfiles ++ inputHomeModules; home-manager.sharedModules = homeModules ++ homeProfiles ++ inputHomeModules;
home-manager.useUserPackages = true; home-manager.useUserPackages = true;
@@ -158,6 +183,7 @@ let
systemPath systemPath
overlayModule overlayModule
usersModule usersModule
nixpkgsModule
] ]
++ nixosModules ++ nixosModules
++ nixosProfiles ++ nixosProfiles
-69
View File
@@ -1,69 +0,0 @@
{ inputs, pkgs, ... }:
{
# State version
system.stateVersion = "24.05";
# Machine hostname
networking.hostName = "20212060";
# Admin users
users.users.jan.extraGroups = [
"wheel"
"wireshark"
];
# Set up kerberos
security.krb5 = {
enable = true;
settings = {
libdefaults = {
rdns = false;
};
realms = (inputs.secrets.gewis.krb5Realm);
};
};
# TODO: Remove once laptop is properly integrated into domain
programs.ssh = {
package = pkgs.openssh_gssapi;
extraConfig = ''
GSSAPIAuthentication yes
'';
};
# Enable virtualisation for VMs
virtualisation.libvirtd.enable = true;
# Enable wireshark
programs.wireshark = {
enable = true;
dumpcap.enable = true;
usbmon.enable = true;
};
# Enable Nix-LD
programs.nix-ld = {
enable = true;
};
# Set up wstunnel client
services.wstunnel = {
enable = true;
clients.wg-tunnel = {
connectTo = "wss://tunnel.bulthuis.dev:443";
settings.local-to-remote = [
"udp://51820:10.10.40.100:51820"
];
};
};
# Module setup
modules = {
profiles.laptop.enable = true;
};
imports = [
./hardware-configuration.nix
];
}
-43
View File
@@ -1,43 +0,0 @@
{ ... }:
{
# Machine platform
nixpkgs.hostPlatform = "x86_64-linux";
# Hardware configuration
hardware.enableRedistributableFirmware = true;
boot.initrd.availableKernelModules = [
"xhci_pci"
"nvme"
"usb_storage"
"sd_mod"
"rtsx_pci_sdmmc"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
hardware.cpu.intel.updateMicrocode = true;
# Filesystems
fileSystems."/" = {
device = "/dev/disk/by-uuid/3b91eaeb-ea95-4bea-8dc1-f55af7502d23";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/46BF-DE2C";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
# Swapfile
swapDevices = [
{
device = "/var/lib/swapfile";
size = 16 * 1024;
}
];
}
-9
View File
@@ -1,9 +0,0 @@
{
...
}:
{
home.stateVersion = "24.11";
modules.profiles.jan.enable = true;
}
Binary file not shown.
+19 -20
View File
@@ -1,4 +1,5 @@
{ {
inputs,
... ...
}: }:
@@ -14,27 +15,25 @@
profiles.vm.enable = true; profiles.vm.enable = true;
}; };
# Setup Tayga NAT64 # Setup JOOL NAT64
services.tayga = { networking.jool = {
enable = true; enable = true;
ipv4 = { nat64.default = {
address = "10.64.0.0"; global.pool6 = "64:ff9b::/96";
router = { pool4 = [
address = "10.64.0.1"; {
}; protocol = "TCP";
pool = { prefix = "10.64.0.1/32";
address = "10.64.0.1"; }
prefixLength = 16; {
}; protocol = "UDP";
}; prefix = "10.64.0.1/32";
ipv6 = { }
router = { {
address = "fc00:6464::1"; protocol = "ICMP";
}; prefix = "10.64.0.1/32";
pool = { }
address = "fc00:6464::"; ];
prefixLength = 96;
};
}; };
}; };
} }
+254
View File
@@ -0,0 +1,254 @@
{
inputs,
pkgs,
config,
...
}:
{
# State version
system.stateVersion = "25.05";
# Machine hostname
networking.hostName = "vm-k1s";
# Enabled modules
modules = {
profiles.vm.enable = true;
};
# Read in secrets
sops.secrets."flux/git-ssh-key" = {
sopsFile = "${inputs.secrets}/secrets/k3s-cluster.enc.yaml";
};
sops.secrets."flux/sops-decrypt-key" = {
sopsFile = "${inputs.secrets}/secrets/k3s-cluster.enc.yaml";
};
# Include NFS client module
boot.supportedFilesystems = [ "nfs" ];
# Set up K3S cluster with CoreDNS, FluxCD and Cilium
services.k3s = {
enable = true;
extraFlags = [
"--cluster-domain ${inputs.secrets.lab.k3s.clusterDomain}"
"--flannel-backend=none"
"--disable-network-policy"
"--disable-kube-proxy"
];
disable = [
# "coredns" # CoreDNS is required for Flux to be able to bootstrap the cluster (Flux needs to resolve the git repo)
"servicelb"
"traefik"
"local-storage"
"metrics-server"
"runtimes"
];
manifests = {
git-ssh-key = {
source = config.sops.secrets."flux/git-ssh-key".path;
};
sops-decrypt-key = {
source = config.sops.secrets."flux/sops-decrypt-key".path;
};
# TODO: Move to flux config, once it is possible to easily install flux without CNI
gateway-api =
let
manifest = pkgs.fetchurl {
url = "https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.1/experimental-install.yaml";
hash = "sha256-VTMn4P8yoaK+RGv5OCPIQTz5JTrGptVAfuvR6NJp9p4=";
};
in
{
source = manifest;
};
# TODO: Move to flux config, once it is possible to easily install flux without CNI
netpol-system-allow-egress.content = {
apiVersion = "cilium.io/v2";
kind = "CiliumClusterwideNetworkPolicy";
metadata.name = "allow-system-egress";
spec = {
description = "Allow all egress to system services.";
endpointSelector = {
matchExpressions = [
{
key = "io.kubernetes.pod.namespace";
operator = "NotIn";
values = [
"bogus-namespace"
# "kube-system"
# "cilium-system"
# "flux-system"
];
}
];
};
egress = [
{
toEntities = [
"all"
];
}
];
ingress = [
{
fromEntities = [
"all"
];
}
];
};
};
netpol-cluster-allow-dns.content = {
apiVersion = "cilium.io/v2";
kind = "CiliumClusterwideNetworkPolicy";
metadata.name = "allow-dns";
spec = {
description = "Allow DNS";
endpointSelector = { };
egress = [
{
toEndpoints = [
{
matchLabels = {
"io.kubernetes.pod.namespace" = "kube-system";
"k8s-app" = "kube-dns";
};
}
];
toPorts = [
{
ports = [
{
port = 53;
protocol = "ANY";
}
];
rules.dns = [
{
matchPattern = "*";
}
];
}
];
}
];
};
};
netpol-flux-allow-egress.content = { };
};
autoDeployCharts = {
# TODO: Move to flux config, once it is possible to easily install flux without CNI
cilium = {
name = "cilium";
repo = "oci://quay.io/cilium/charts/cilium";
version = "1.18.8";
hash = "sha256-z1aDpWttEfQ+Af/l0Lxdafasm75QysRc8h7sPhWXr94=";
createNamespace = true;
targetNamespace = "cilium-system";
values = {
operator.replicas = 1;
kubeProxyReplacement = true;
ipam.operator.clusterPoolIPv4PodCIDRList = [ "10.42.0.0/16" ];
cluster = {
id = 1;
name = "vm-k1s";
};
k8sServiceHost = "10.10.50.60";
k8sServicePort = 6443;
policyEnforcementMode = "always";
gatewayAPI = {
enabled = true;
gatewayClass.create = "true";
enableAlpn = true;
};
bgpControlPlane.enabled = true;
tls.secretsNamespace.create = false;
hubble = {
relay.enabled = true;
ui.enabled = true;
peerService.clusterDomain = inputs.secrets.lab.k3s.clusterDomain;
};
};
extraFieldDefinitions = {
spec.bootstrap = true;
};
};
flux-operator = {
name = "flux-operator";
repo = "oci://ghcr.io/controlplaneio-fluxcd/charts/flux-operator";
version = "0.38.1";
hash = "sha256-nb0mzEWC3IwjPenQ4LSWBN0NNJc2cc68RB+G60xBOEM=";
createNamespace = true;
targetNamespace = "flux-system";
extraDeploy = [
{
apiVersion = "fluxcd.controlplane.io/v1";
kind = "FluxInstance";
metadata = {
name = "flux";
namespace = "flux-system";
annotations = {
"fluxcd.controlplane.io/reconcile" = "enabled";
"fluxcd.controlplane.io/reconcileEvery" = "1h";
"fluxcd.controlplane.io/reconcileTimeout" = "5m";
};
};
spec = {
distribution = {
version = "2.x";
registry = "ghcr.io/fluxcd";
};
components = [
"source-controller"
"kustomize-controller"
"helm-controller"
"notification-controller"
];
cluster = {
type = "kubernetes";
size = "small";
multitenant = false;
networkPolicy = true;
domain = inputs.secrets.lab.k3s.clusterDomain;
};
commonMetadata.labels = {
"app.kubernetes.io/name" = "flux";
};
sync = (
{
pullSecret = "git-ssh-key";
}
// inputs.secrets.lab.k3s.fluxRepo
);
};
}
];
};
};
};
modules.impermanence.directories = [
"/var/lib/rancher/k3s"
];
environment.variables = {
KUBECONFIG = "/etc/rancher/k3s/k3s.yaml";
CILIUM_NAMESPACE = "cilium-system";
};
environment.systemPackages = with pkgs; [
fluxcd
k9s
cilium-cli
hubble
];
# Use correct disko profile
modules.disko.profile = "k3s";
# TEMP: Disable firewall for now
networking.firewall.enable = false;
security.sudo.wheelNeedsPassword = false;
}
+176
View File
@@ -0,0 +1,176 @@
{
inputs,
pkgs,
config,
...
}:
{
# State version
system.stateVersion = "24.05";
# Machine hostname
networking.hostName = "ws-think";
# Set up users
sops.secrets."passwords/jan-hashed" = {
sopsFile = "${inputs.secrets}/secrets/ws-think.enc.yaml";
neededForUsers = true;
};
users.mutableUsers = false;
users.users.Jan = {
hashedPasswordFile = config.sops.secrets."passwords/jan-hashed".path;
# Extra admin groups
# TODO: Streamline setup of this
extraGroups = [
"wheel"
"wireshark"
"podman"
"libvirtd"
];
};
# Set up impermanence
modules.impermanence = {
enable = true;
resetScript = ''
# Revert to the blank state for the root directory
zfs rollback -r tank/root@blank
'';
};
# Set up kerberos
security.krb5 = {
enable = true;
settings = {
libdefaults = {
rdns = false;
};
realms = (inputs.secrets.gewis.krb5Realm);
};
};
services.netbird = {
enable = true;
};
# SSH X11 forwarding
programs.ssh.forwardX11 = true;
# Enable older samba versions
services.samba = {
enable = true;
settings = {
global = {
"invalid users" = [ "root" ];
"passwd program" = "/run/wrappers/bin/passwd %u";
"security" = "user";
"client min protocol" = "NT1";
};
};
};
# TODO: Remove once laptop is properly integrated into domain
programs.ssh = {
package = pkgs.openssh_gssapi;
extraConfig = ''
GSSAPIAuthentication yes
'';
};
# Enable virtualisation for VMs
virtualisation.libvirtd.enable = true;
programs.virt-manager.enable = true;
# Enable wireshark
programs.wireshark = {
enable = true;
dumpcap.enable = true;
usbmon.enable = true;
};
# Enable Nix-LD
programs.nix-ld = {
enable = true;
};
# Set up wstunnel client
services.wstunnel = {
enable = true;
clients.wg-tunnel = {
connectTo = "wss://tunnel.bulthuis.dev:443";
settings.local-to-remote = [
"udp://51819:10.10.40.100:51820"
];
};
};
# Enable flatpak
services.flatpak.enable = true;
# Module setup
modules = {
profiles.laptop.enable = true;
};
# Set up podman
virtualisation.podman = {
enable = true;
dockerCompat = true;
dockerSocket.enable = true;
autoPrune.enable = true;
};
# Enable Gnome Remote Desktop
services.gnome.gnome-remote-desktop.enable = true;
systemd.services."gnome-remote-desktop".wantedBy = [ "graphical.target" ];
systemd.services."gnome-remote-desktop".preStart =
let
credDir = "/var/lib/gnome-remote-desktop/.local/share/gnome-remote-desktop";
credPath = "${credDir}/credentials.ini";
credFile = pkgs.writeText "gnome-remote-desktop-credentials" ''
[RDP]
credentials={'username': <'remote'>, 'password': <'remote'>}
'';
script = pkgs.writeScript "gnome-remote-desktop-setup" ''
mkdir -p ${credDir}
touch ${credPath}
chown gnome-remote-desktop:gnome-remote-desktop ${credPath}
chmod 600 ${credPath}
cat ${credFile} > ${credPath}
'';
in
"${script}";
environment.etc."gnome-remote-desktop/grd.conf" = {
text = ''
[RDP]
port=3389
tls-key=/run/secrets/gnome-remote-desktop/tls-key
tls-cert=/run/secrets/gnome-remote-desktop/tls-crt
enabled=true
'';
};
networking.firewall = {
allowedTCPPorts = [
3389
3390
];
allowedUDPPorts = [
3389
3390
];
};
sops.secrets."gnome-remote-desktop/tls-key" = {
sopsFile = "${inputs.secrets}/secrets/ws-think.enc.yaml";
owner = config.users.users.gnome-remote-desktop.name;
group = config.users.users.gnome-remote-desktop.group;
};
sops.secrets."gnome-remote-desktop/tls-crt" = {
sopsFile = "${inputs.secrets}/secrets/ws-think.enc.yaml";
owner = config.users.users.gnome-remote-desktop.name;
group = config.users.users.gnome-remote-desktop.group;
};
# Set up hardware
imports = [ ./hardware-configuration.nix ];
}
+65
View File
@@ -0,0 +1,65 @@
{ ... }:
{
# Machine platform
nixpkgs.hostPlatform = "x86_64-linux";
# Set hostid (required for ZFS)
networking.hostId = "deadbeef";
# Use thermald
services.thermald.ignoreCpuidCheck = true;
# Hardware configuration
hardware.enableRedistributableFirmware = true;
boot.initrd.availableKernelModules = [
"xhci_pci"
"nvme"
"usb_storage"
"sd_mod"
"rtsx_pci_sdmmc"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
boot.zfs.forceImportRoot = false;
hardware.cpu.intel.updateMicrocode = true;
# Filesystems
fileSystems = {
"/" = {
device = "tank/root";
fsType = "zfs";
options = [ "zfsutil" ];
};
"/nix" = {
device = "tank/nix";
fsType = "zfs";
options = [ "zfsutil" ];
};
"/persist" = {
device = "tank/persist";
fsType = "zfs";
options = [ "zfsutil" ];
};
"/boot" = {
device = "/dev/disk/by-uuid/46BF-DE2C";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
};
# Swap setup
swapDevices = [
{
device = "/dev/disk/by-uuid/9f6f2a47-e53a-45a0-8cb2-8c1082f54ccb";
discardPolicy = "both";
}
];
}
+52
View File
@@ -0,0 +1,52 @@
{
pkgs,
...
}:
{
home.stateVersion = "25.11";
modules.profiles.jan.enable = true;
# home.packages = with pkgs; [
# opencloud-desktop
# code-nautilus
# nautilus-open-in-blackbox
# ];
xdg.desktopEntries = {
canvas = {
name = "Canvas";
type = "Application";
exec = "${pkgs.chromium}/bin/chromium --app=\"https://canvas.tue.nl\" --user-data-dir=/home/jan/.local/state/Canvas";
settings.StartupWMClass = "chrome-canvas.tue.nl__-Default";
};
overleaf = {
name = "Overleaf";
type = "Application";
exec = "${pkgs.chromium}/bin/chromium --app=\"https://www.overleaf.com\" --user-data-dir=/home/jan/.local/state/Overleaf";
settings.StartupWMClass = "chrome-www.overleaf.com__-Default";
};
};
# TODO: Slowly remove
modules.impermanence = {
directories = [
".cache"
".config"
".cargo"
".dbus"
".gnupg"
".local"
".MathWorks"
".mozilla"
".ssh"
".steam"
".SteamCloud"
".thunderbird"
".vscode"
".wine"
".Wolfram"
];
};
}
+23 -15
View File
@@ -18,11 +18,11 @@ in
# TODO: Enable extensions (declaratively) with dconf # TODO: Enable extensions (declaratively) with dconf
home.pointerCursor = { home.pointerCursor = {
enable = true;
name = "capitaine-cursors"; name = "capitaine-cursors";
size = 24; size = 24;
package = pkgs.capitaine-cursors; package = pkgs.capitaine-cursors;
gtk.enable = true; gtk.enable = true;
x11.enable = true;
}; };
home.packages = home.packages =
@@ -51,18 +51,26 @@ in
mission-center mission-center
dconf-editor dconf-editor
gnome-calendar gnome-calendar
gnome-backgrounds
gnome-bluetooth
gnome-color-manager
epiphany
# For theming gtk3 # For theming gtk3
adw-gtk3 # adw-gtk3 # TODO: Do this better, same for morewaita, not sure if it even works
# More icons # More icons
morewaita-icon-theme # morewaita-icon-theme
] ]
++ (with pkgs.gnomeExtensions; [ ++ (with pkgs.gnomeExtensions; [
gsconnect gsconnect
disable-workspace-animation disable-workspace-animation
wallpaper-slideshow wallpaper-slideshow
media-progress media-progress
mpris-label
pip-on-top
rounded-window-corners-reborn
caffeine
]); ]);
# Set up gnome terminal as changing the default terminal is a pain # Set up gnome terminal as changing the default terminal is a pain
@@ -75,19 +83,19 @@ in
}; };
# Enable and set the gtk themes # Enable and set the gtk themes
gtk = { # gtk = {
enable = true; # enable = true;
gtk3.extraConfig = { # gtk3.extraConfig = {
gtk-theme-name = "adw-gtk3"; # gtk-theme-name = "adw-gtk3";
}; # };
gtk4.extraConfig = { # gtk4.extraConfig = {
gtk-theme-name = "Adwaita"; # gtk-theme-name = "Adwaita";
}; # };
}; # };
# Set the theme with dconf # Set the theme with dconf
dconf.settings."org/gnome/desktop/interface" = { # dconf.settings."org/gnome/desktop/interface" = {
gtk-theme = "adw-gtk3"; # gtk-theme = "adw-gtk3";
}; # };
}; };
} }
+4 -4
View File
@@ -39,15 +39,15 @@ in
programs.git = { programs.git = {
enable = true; enable = true;
extraConfig = { settings = {
pull = { pull = {
rebase = false; rebase = false;
}; };
}; };
userName = cfg.user; settings.user.name = cfg.user;
userEmail = cfg.email; settings.user.email = cfg.email;
ignores = cfg.ignores; # ignores = cfg.ignores;
}; };
}; };
} }
+1 -1
View File
@@ -18,7 +18,7 @@ in
# Development packages # Development packages
home.packages = with pkgs; [ home.packages = with pkgs; [
nix-tree nix-tree
nixfmt-rfc-style nixfmt
nixd nixd
]; ];
+4 -2
View File
@@ -9,10 +9,11 @@ with lib;
let let
cfg = config.modules.mathematica; cfg = config.modules.mathematica;
my-mathematica = pkgs.mathematica.override { my-mathematica = pkgs.mathematica.overrideAttrs (old: {
force-rebuild = "1";
# TODO: Just use a generic name for the installer? # TODO: Just use a generic name for the installer?
# source = ./Wolfram_14.2.1_LIN_Bndl.sh; # source = ./Wolfram_14.2.1_LIN_Bndl.sh;
}; });
in in
{ {
options.modules.mathematica = { options.modules.mathematica = {
@@ -21,6 +22,7 @@ in
config = mkIf cfg.enable { config = mkIf cfg.enable {
home.packages = [ home.packages = [
# pkgs.mathematica-cuda
my-mathematica my-mathematica
]; ];
}; };
+1
View File
@@ -43,6 +43,7 @@ in
tomoki1207.pdf tomoki1207.pdf
ms-vsliveshare.vsliveshare ms-vsliveshare.vsliveshare
ms-vscode-remote.remote-ssh ms-vscode-remote.remote-ssh
myriad-dreamin.tinymist
]; ];
userSettings = userSettings =
+3
View File
@@ -53,5 +53,8 @@ in
fzf fzf
grc grc
]; ];
# Impermanence
modules.impermanence.files = [ ".local/share/fish/fish_history" ];
}; };
} }
+1 -2
View File
@@ -24,10 +24,9 @@ in
}; };
config = mkIf cfg.enable { config = mkIf cfg.enable {
home.persistence."/persist/home/${config.home.username}" = { home.persistence."/persist/home" = {
enable = true; enable = true;
hideMounts = true; hideMounts = true;
allowOther = true;
directories = cfg.directories; directories = cfg.directories;
files = cfg.files; files = cfg.files;
}; };
+6
View File
@@ -20,6 +20,12 @@ in
console.font = "dina"; console.font = "dina";
console.earlySetup = true; console.earlySetup = true;
fonts.packages = with pkgs; [
noto-fonts
fira
jetbrains-mono
];
# TODO: Disable default fonts, fonts should be managed per user # TODO: Disable default fonts, fonts should be managed per user
# fonts.enableDefaultPackages = false; # fonts.enableDefaultPackages = false;
# fonts.fontconfig = { # fonts.fontconfig = {
+7 -19
View File
@@ -34,24 +34,8 @@ in
glib glib
gnome-menus gnome-menus
gtk3.out gtk3.out
xdg-user-dirs
xdg-user-dirs-gtk
]; ];
# Enable Gnome Remote Desktop
services.gnome.gnome-remote-desktop.enable = true;
systemd.services."gnome-remote-desktop".wantedBy = [ "graphical.target" ];
networking.firewall = {
allowedTCPPorts = [
3389
3390
];
allowedUDPPorts = [
3389
3390
];
};
# For GSConnect/KDE Connect # For GSConnect/KDE Connect
# TODO: Move to host config? # TODO: Move to host config?
networking.firewall = { networking.firewall = {
@@ -70,8 +54,12 @@ in
}; };
# Enable dependencies # Enable dependencies
modules = { modules.networkmanager.enable = true;
networkmanager.enable = true;
}; # Impermanence
modules.impermanence.directories = [
"/etc/NetworkManager/system-connections"
"/var/lib/bluetooth"
];
}; };
} }
+5 -1
View File
@@ -16,7 +16,11 @@ in
# TODO: Add nvidia settings back in # TODO: Add nvidia settings back in
# TODO: Move to nvidia module # TODO: Move to nvidia module
hardware.nvidia = { hardware.nvidia = {
open = true; open = false;
prime = {
intelBusId = "PCI:0@0:2:0";
nvidiaBusId = "PCI:1@0:0:0";
};
}; };
}; };
} }
+22 -1
View File
@@ -50,11 +50,32 @@ in
# For testing purposes with VM # For testing purposes with VM
virtualisation.vmVariantWithDisko.virtualisation.fileSystems."/persist".neededForBoot = true; virtualisation.vmVariantWithDisko.virtualisation.fileSystems."/persist".neededForBoot = true;
environment.persistence."/persist/system" = { environment.persistence = {
"/persist/system" = {
enable = true; enable = true;
hideMounts = true; hideMounts = true;
directories = cfg.directories; directories = cfg.directories;
files = cfg.files; files = cfg.files;
}; };
# "/persist/home" = {
# enable = true;
# hideMounts = true;
# users = (
# lib.mapAttrs' (
# name: value:
# let
# user = name;
# homeDir = "/home/${user}";
# impConfig = value.modules.impermanence;
# in
# lib.nameValuePair user {
# home = homeDir;
# directories = impConfig.directories;
# files = impConfig.files;
# }
# ) config.home-manager.users
# );
# };
};
}; };
} }
+37
View File
@@ -0,0 +1,37 @@
{
jq,
lib,
moreutils,
tinymist,
vscode-utils,
}:
vscode-utils.buildVscodeMarketplaceExtension {
mktplcRef = {
name = "tinymist-vscode-html";
publisher = "myriad-dreamin";
inherit (tinymist) version;
hash = "";
};
nativeBuildInputs = [
jq
moreutils
];
buildInputs = [ tinymist ];
postInstall = ''
cd "$out/$installPrefix"
jq '.contributes.configuration.properties."tinymist.serverPath".default = "${lib.getExe tinymist}"' package.json | sponge package.json
'';
meta = {
changelog = "https://marketplace.visualstudio.com/items/myriad-dreamin.tinymist/changelog";
description = "VSCode extension for providing an integration solution for Typst";
downloadPage = "https://marketplace.visualstudio.com/items?itemName=myriad-dreamin.tinymist";
homepage = "https://github.com/myriad-dreamin/tinymist";
license = lib.licenses.asl20;
maintainers = [ ];
};
}
+104
View File
@@ -0,0 +1,104 @@
{
lib,
buildNpmPackage,
fetchFromGitHub,
makeBinaryWrapper,
makeDesktopItem,
copyDesktopItems,
nodejs_20,
electron,
python3,
nix-update-script,
}:
buildNpmPackage rec {
pname = "open-stage-control";
version = "1.29.8";
src = fetchFromGitHub {
owner = "jean-emmanuel";
repo = "open-stage-control";
rev = "v${version}";
hash = "sha256-518KXvNffLOV2aIWlLJcnPzxEbWxYdjWeiDBC1jlecQ=";
};
# Remove some Electron stuff from package.json
postPatch = ''
sed -i -e '/"electron"\|"electron-installer-debian"/d' package.json
'';
npmDepsHash = "sha256-U4zwYL5URNW0y0W4WvWAVL0hubiiU+2z9F5mDE9l8UU=";
nodejs = nodejs_20;
nativeBuildInputs = [
copyDesktopItems
makeBinaryWrapper
];
buildInputs = [
python3.pkgs.python-rtmidi
];
doInstallCheck = true;
makeCacheWritable = true;
npmFlags = [
"--legacy-peer-deps"
"--skip-pkg"
];
# Override installPhase so we can copy the only directory that matters (app)
installPhase = ''
runHook preInstall
# copy built app and node_modules directories
mkdir -p $out/lib/node_modules/open-stage-control
cp -r app $out/lib/node_modules/open-stage-control/
# copy icon
install -Dm644 resources/images/logo.png $out/share/icons/hicolor/256x256/apps/open-stage-control.png
install -Dm644 resources/images/logo.svg $out/share/icons/hicolor/scalable/apps/open-stage-control.svg
# wrap electron and include python-rtmidi
makeWrapper '${electron}/bin/electron' $out/bin/open-stage-control \
--inherit-argv0 \
--add-flags $out/lib/node_modules/open-stage-control/app \
--prefix PYTHONPATH : "$PYTHONPATH" \
--prefix PATH : '${lib.makeBinPath [ python3 ]}'
runHook postInstall
'';
installCheckPhase = ''
XDG_CONFIG_HOME="$(mktemp -d)" $out/bin/open-stage-control --help
'';
desktopItems = [
(makeDesktopItem {
name = "open-stage-control";
exec = "open-stage-control";
icon = "open-stage-control";
desktopName = "Open Stage Control";
comment = meta.description;
categories = [
"Network"
"Audio"
"AudioVideo"
"Midi"
];
startupWMClass = "open-stage-control";
})
];
passthru.updateScript = nix-update-script { };
meta = with lib; {
description = "Libre and modular OSC / MIDI controller";
homepage = "https://openstagecontrol.ammd.net/";
license = licenses.gpl3Only;
maintainers = [ ];
platforms = platforms.linux;
mainProgram = "open-stage-control";
};
}
+82
View File
@@ -0,0 +1,82 @@
{
disko.devices = {
disk = {
main = {
type = "disk";
device = "/dev/sda";
imageSize = "32G"; # For test VMs
content = {
type = "gpt";
partitions = {
boot = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
zfs = {
end = "-4G";
content = {
type = "zfs";
pool = "tank";
};
};
swap = {
size = "100%";
content = {
type = "swap";
discardPolicy = "both";
};
};
};
};
};
longhorn = {
type = "disk";
device = "/dev/sdb";
imageSize = "64G"; # For longhorn storage
content = {
type = "gpt";
partitions = {
main = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
};
};
};
};
};
};
zpool = {
tank = {
type = "zpool";
rootFsOptions = {
compression = "zstd";
};
mountpoint = null;
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
datasets = {
root = {
type = "zfs_fs";
mountpoint = "/";
};
nix = {
type = "zfs_fs";
mountpoint = "/nix";
};
persist = {
type = "zfs_fs";
mountpoint = "/persist";
};
};
};
};
};
}
+65
View File
@@ -0,0 +1,65 @@
{
disko.devices = {
disk = {
main = {
type = "disk";
device = "/dev/sda";
imageSize = "64G"; # For test VMs
content = {
type = "gpt";
partitions = {
boot = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
zfs = {
end = "-16G";
content = {
type = "zfs";
pool = "tank";
};
};
swap = {
size = "100%";
content = {
type = "swap";
discardPolicy = "both";
};
};
};
};
};
};
zpool = {
tank = {
type = "zpool";
rootFsOptions = {
compression = "zstd";
};
mountpoint = null;
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
datasets = {
root = {
type = "zfs_fs";
mountpoint = "/";
};
nix = {
type = "zfs_fs";
mountpoint = "/nix";
};
persist = {
type = "zfs_fs";
mountpoint = "/persist";
};
};
};
};
};
}
+1
View File
@@ -16,6 +16,7 @@ in
config = mkIf cfg.enable { config = mkIf cfg.enable {
modules = { modules = {
impermanence.enable = true;
# btop.enable = true; # btop.enable = true;
direnv.enable = true; direnv.enable = true;
fish.enable = true; fish.enable = true;
+55 -1
View File
@@ -16,9 +16,63 @@ in
config = mkIf cfg.enable { config = mkIf cfg.enable {
home.packages = with pkgs; [ home.packages = with pkgs; [
firefox # TODO: Move to dediated module # firefox # TODO: Move to dediated module
]; ];
dconf.settings = {
"org/gnome/calendar" = {
active-view = "week";
};
"org/gnome/desktop/background" = {
picture-uri = "file://${config.home.homeDirectory}/.local/share/backgrounds/background";
};
"org/gnome/desktop/input-sources" = {
sources = [
(lib.gvariant.mkTuple [
"xkb"
"us"
])
];
xkb-options = [ "caps:escape_shifted_capslock" ];
};
"org/gnome/desktop/interface" = {
accent-color = "purple";
enable-hot-corners = false;
};
"org/gnome/desktop/peripherals/touchpad" = {
speed = 0.214;
two-finger-scrolling-enabled = true;
};
"org/gnome/mutter" = {
workspaces-only-on-primary = true;
};
"org/gnome/nautilus/icon-view" = {
default-zoom-level = "small";
};
"org/gnome/nautilus/preferences" = {
default-folder-viewer = "icon-view";
};
"org/gnome/settings-daemon/plugins/color" = {
night-light-enabled = true;
night-light-schedule-automatic = false;
night-light-schedule-from = 20.0;
night-light-schedule-to = 6.0;
night-light-temperature = 2700;
};
"org/gnome/shell" = {
disable-extension-version-validation = true;
enabled-extensions = [
"disable-workspace-animation@ethnarque"
"gsconnect@andyholmes.github.io"
"rounded-window-corners@fxgn"
"media-progress@krypion17"
"mprisLabel@moon-0xff.github.com"
"caffeube@patapon.info"
];
last-selected-power-profile = "power-saver";
};
};
modules = { modules = {
profiles.base.enable = true; profiles.base.enable = true;
+207 -13
View File
@@ -1,7 +1,9 @@
{ {
pkgs, pkgs,
pkgs-stable,
lib, lib,
config, config,
inputs,
... ...
}: }:
@@ -16,37 +18,229 @@ in
config = mkIf cfg.enable { config = mkIf cfg.enable {
home.packages = with pkgs; [ home.packages = with pkgs; [
libreoffice-still firefox
# inputs.stable-nixpkgs.legacyPackages.${config.nixpkgs.hostPlatform}.libreoffice
libreoffice
remmina remmina
thunderbird thunderbird
signal-desktop signal-desktop
prusa-slicer prusa-slicer
freecad-wayland pkgs-stable.freecad-wayland
inkscape inkscape
ente-auth # ente-auth
audacity
carla carla
winbox # pkgs-stable.winbox
whatsapp-for-linux winbox4
# whatsapp-for-linux
karere
discord discord
steam steam
spotify spotify
feishin # feishin
eduvpn-client eduvpn-client
river # TODO: Move
ryubing ryubing
bottles bottles
prismlauncher prismlauncher
foliate foliate
wireshark wireshark
obsidian obsidian
devenv # devenv
kicad # kicad
vlc vlc
authenticator
hotspot
btop
winboat
hieroglyphic
shortwave
podman
podman-compose
gnome-network-displays
gnome-logs
];
programs.zathura = {
enable = true;
options = {
synctex = true;
synctex-editor-command = "${pkgs.texlab}/bin/texlab inverse-search -i %{input} -l %{line}";
};
};
programs.helix = {
enable = true;
defaultEditor = true;
# settings = {
# theme = {
# light = "adwaita-light";
# dark = "adwaita-dark";
# fallback = "default";
# };
# };
settings =
let
move_line_up = [
"extend_to_line_bounds"
"delete_selection"
"move_line_up"
"paste_before"
];
move_line_down = [
"extend_to_line_bounds"
"delete_selection"
"paste_after"
];
in
{
keys.normal = {
"A-up" = move_line_up;
"A-down" = move_line_down;
"A-k" = move_line_up;
"A-j" = move_line_down;
};
keys.select = {
"A-up" = move_line_up;
"A-down" = move_line_down;
"A-k" = move_line_up;
"A-j" = move_line_down;
};
};
extraPackages = with pkgs; [
bash-language-server # Bash
fish-lsp # Fish
systemd-lsp # Systemd
yaml-language-server # Yaml
taplo # Toml
nixd # Nix
protols # Protobuf
dockerfile-language-server # Dockerfile
docker-compose-language-service # Docker compose
clang-tools # C, C++
neocmakelsp # Cmake
rust-analyzer # Rust
lldb # C, C++, Rust
zls # Zig
texlab # Latex
tinymist # Typst
marksman # Markdown
markdown-oxide # Markdown
vscode-langservers-extracted # HTML, CSS, JSON, ESLint
typescript-language-server # Typescript, Javascript
intelephense # PHP
vue-language-server # Vue
ruff # Python
basedpyright # Python
#helix-gpt # Copilot
ltex-ls-plus # Spellchecking
# texlab # Latex, Bibtex
# bibtex-tidy # Bibtex
# docker-langserver # Dockerfile
# docker-compose-langserver # Docker compose
# elixir-ls # Elixir
# gopls # Go
# golangci-lint-langserver # Go
# dlv # Go
# haskell-language-server # Haskell
# julia # Julia
# kotlin-language-server # Kotlin
# lua-language-server # Lua
# slint-lsp # Slint
# tinymist # Typst
];
languages = {
language-server = {
ltex = {
command = "ltex-ls-plus";
config.ltex = { };
};
texlab = {
command = "texlab";
config.texlab = {
build.onSave = true;
forwardSearch.executable = "${config.programs.zathura.package}/bin/zathura";
forwardSearch.args = [
"--synctex-forward"
"%l:1:%f"
"%p"
];
};
};
basedpyright = {
command = "basedpyright-langserver";
args = [ "--stdio" ];
};
tinymist = {
command = "tinymist";
config.preview.background = {
enabled = true;
args = [
"--data-plane-host=127.0.0.1:23635"
"--invert-colors=never"
"--open"
];
};
};
};
language = [
{
name = "latex";
# language-servers = [
# { name = "texlab"; }
# { name = "ltex"; }
# ];
soft-wrap = {
enable = true;
};
}
{
name = "python";
language-servers = [
{
name = "basedpyright";
except-features = [ "diagnostics" ];
}
"ruff"
];
auto-format = true;
formatter = {
command = "ruff";
args = [
"format"
"-"
];
};
}
];
};
};
systemd.user.tmpfiles.rules = [
"d ${config.home.homeDirectory}/Downloads - - - - -"
]; ];
modules = { modules = {
profiles.gnome.enable = true; profiles.gnome.enable = true;
impermanence = {
directories = [
"Code"
"Documents"
"Games"
"Models"
"Music"
"Pictures"
"Videos"
];
};
# Gaming # Gaming
# retroarch.enable = true; # retroarch.enable = true;
# ryujinx.enable = true; # ryujinx.enable = true;
@@ -68,14 +262,14 @@ in
xpra = { xpra = {
enable = true; enable = true;
hosts = [ hosts = [
"mixer@10.20.60.251" "mixer@10.20.40.100"
]; ];
}; };
# Development # Development
# docker.enable = true; # docker.enable = true;
# matlab.enable = true; # matlab.enable = true;
mathematica.enable = true; # mathematica.enable = true;
# Languages # Languages
haskell.enable = false; haskell.enable = false;
@@ -84,8 +278,8 @@ in
rust.enable = true; rust.enable = true;
python.enable = true; python.enable = true;
cpp.enable = true; cpp.enable = true;
tex.enable = true; tex.enable = false;
jupyter.enable = false; jupyter.enable = true;
go.enable = true; go.enable = true;
}; };
}; };
+12 -5
View File
@@ -19,9 +19,17 @@ in
bootloader.enable = mkDefault true; bootloader.enable = mkDefault true;
ssh.enable = mkDefault true; ssh.enable = mkDefault true;
impermanence.directories = [ impermanence = {
"/var/lib/nixos" files = [
"/etc/machine-id"
"/etc/zfs/zpool.cache" # TODO: Move to zfs module?
]; ];
directories = [
"/var/log/journal"
"/var/lib/nixos"
"/var/lib/systemd"
];
};
# TODO: Remove the secrets module and use sops directly? # TODO: Remove the secrets module and use sops directly?
secrets = { secrets = {
@@ -45,9 +53,6 @@ in
defaultEditor = true; defaultEditor = true;
}; };
# Allow unfree packages
nixpkgs.config.allowUnfree = true;
# Enable the usage of flakes # Enable the usage of flakes
nix.settings.experimental-features = [ nix.settings.experimental-features = [
"nix-command" "nix-command"
@@ -70,6 +75,8 @@ in
zip zip
unzip unzip
tmux tmux
unixtools.net-tools
tcpdump
]; ];
}; };
} }
+1 -1
View File
@@ -20,7 +20,7 @@ in
profiles.base.enable = true; profiles.base.enable = true;
disko = { disko = {
enable = true; enable = true;
profile = "vm"; profile = mkDefault "vm";
}; };
impermanence = { impermanence = {
enable = true; enable = true;