Compare commits
32
Commits
34f179465d
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9d2e52675e | ||
|
|
6c5c69945a | ||
|
|
9883f3d461 | ||
|
|
6d86bb8368 | ||
|
|
0dbc4792d4 | ||
|
|
753b763b6f | ||
|
|
2a690681cb | ||
|
|
82f4a2e1d4 | ||
|
|
eb18897355 | ||
|
|
00679a2c04 | ||
|
|
8e819e01ea | ||
|
|
cf4c179fc4 | ||
|
|
c991768cc2 | ||
|
|
268879ee01 | ||
|
|
7e9f617965 | ||
|
|
7d6482587a | ||
|
|
cf10e1e963 | ||
|
|
02b2b9cf32 | ||
|
|
dfe6ec5518 | ||
|
|
517d793c88 | ||
|
|
657a65522f | ||
|
|
7bc3ab64dd | ||
|
|
2b5cfe0934 | ||
|
|
cf345521e8 | ||
|
|
f43945d0d2 | ||
|
|
7874412a48 | ||
|
|
e33a6e181e | ||
|
|
928dc4a240 | ||
|
|
63d34640f7 | ||
|
|
921565fe12 | ||
|
|
88792d86db | ||
|
|
49b4ade156 |
No files matched your search
Generated
+64
-171
@@ -7,11 +7,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1764350888,
|
||||
"narHash": "sha256-6Rp18zavTlnlZzcoLoBTJMBahL2FycVkw2rAEs3cQvo=",
|
||||
"lastModified": 1779135526,
|
||||
"narHash": "sha256-glCununz6lmaK5fs2X946HA3EkNxB2JagdAAvInuRYU=",
|
||||
"owner": "nix-community",
|
||||
"repo": "disko",
|
||||
"rev": "2055a08fd0e2fd41318279a5355eb8a161accf26",
|
||||
"rev": "d405a179887d52b24c0ddd31e09a150bd1f66779",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -20,58 +20,6 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"flake-compat": {
|
||||
"flake": false,
|
||||
"locked": {
|
||||
"lastModified": 1747046372,
|
||||
"narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=",
|
||||
"owner": "edolstra",
|
||||
"repo": "flake-compat",
|
||||
"rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "edolstra",
|
||||
"repo": "flake-compat",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"flake-utils": {
|
||||
"inputs": {
|
||||
"systems": "systems"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1731533236,
|
||||
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"flake-utils_2": {
|
||||
"inputs": {
|
||||
"systems": "systems_2"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1731533236,
|
||||
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"home-manager": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
@@ -79,11 +27,32 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1764304195,
|
||||
"narHash": "sha256-bO7FN/bF6gG7TlZpKAZjO3VvfsLaPFkefeUfJJ7F/7w=",
|
||||
"lastModified": 1779157263,
|
||||
"narHash": "sha256-VbiyZkRf8/qr7ObmlyfOHJsNAW5tyZ4MB1+cUwAwdrw=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "86ff0ef506c209bb397849706e85cc3a913cb577",
|
||||
"rev": "866412a19866b4a8e32d2306a118040afa2b840c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"home-manager_2": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
"impermanence",
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1768598210,
|
||||
"narHash": "sha256-kkgA32s/f4jaa4UG+2f8C225Qvclxnqs76mf8zvTVPg=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "c47b2cc64a629f8e075de52e4742de688f930dc6",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -93,12 +62,16 @@
|
||||
}
|
||||
},
|
||||
"impermanence": {
|
||||
"inputs": {
|
||||
"home-manager": "home-manager_2",
|
||||
"nixpkgs": "nixpkgs"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1737831083,
|
||||
"narHash": "sha256-LJggUHbpyeDvNagTUrdhe/pRVp4pnS6wVKALS782gRI=",
|
||||
"lastModified": 1769548169,
|
||||
"narHash": "sha256-03+JxvzmfwRu+5JafM0DLbxgHttOQZkUtDWBmeUkN8Y=",
|
||||
"owner": "nix-community",
|
||||
"repo": "impermanence",
|
||||
"rev": "4b3e914cdf97a5b536a889e939fb2fd2b043a170",
|
||||
"rev": "7b1d382faf603b6d264f58627330f9faa5cba149",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -107,76 +80,13 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"madd": {
|
||||
"inputs": {
|
||||
"flake-utils": "flake-utils",
|
||||
"nixpkgs": [
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1754781336,
|
||||
"narHash": "sha256-EUavinU3psYqVDx7Cjdypsf4dUymdu1yawbwRYv6wbM=",
|
||||
"ref": "refs/heads/master",
|
||||
"rev": "d490b648ac5acb65aa24c8e8314c1a6fa9e2c0c1",
|
||||
"revCount": 8,
|
||||
"type": "git",
|
||||
"url": "https://git.bulthuis.dev/Jan/madd"
|
||||
},
|
||||
"original": {
|
||||
"type": "git",
|
||||
"url": "https://git.bulthuis.dev/Jan/madd"
|
||||
}
|
||||
},
|
||||
"nix-minecraft": {
|
||||
"inputs": {
|
||||
"flake-compat": "flake-compat",
|
||||
"flake-utils": "flake-utils_2",
|
||||
"nixpkgs": [
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1751650156,
|
||||
"narHash": "sha256-1gIPVDf159TQlcVg3WQBHMZVn8RllHOa8eT7AJPj2IE=",
|
||||
"owner": "Jan-Bulthuis",
|
||||
"repo": "nix-minecraft",
|
||||
"rev": "d3b3779fd78bd55db24d25e896438b2b51cbb6cb",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "Jan-Bulthuis",
|
||||
"repo": "nix-minecraft",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nix-modpack": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1747559249,
|
||||
"narHash": "sha256-+ygKEGMVcXNklO4RDYSd5XzydDmQOZWcOcxYZf/PH1U=",
|
||||
"owner": "Jan-Bulthuis",
|
||||
"repo": "nix-modpack",
|
||||
"rev": "a093625c2847afc3ef257513161c7fe318c6be1c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "Jan-Bulthuis",
|
||||
"repo": "nix-modpack",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1764242076,
|
||||
"narHash": "sha256-sKoIWfnijJ0+9e4wRvIgm/HgE27bzwQxcEmo2J/gNpI=",
|
||||
"lastModified": 1768564909,
|
||||
"narHash": "sha256-Kell/SpJYVkHWMvnhqJz/8DqQg2b6PguxVWOuadbHCc=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "2fad6eac6077f03fe109c4d4eb171cf96791faa4",
|
||||
"rev": "e4bae1bd10c9c57b2cf517953ab70060a828ee6f",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -188,11 +98,11 @@
|
||||
},
|
||||
"nixpkgs-stable": {
|
||||
"locked": {
|
||||
"lastModified": 1763049705,
|
||||
"narHash": "sha256-A5LS0AJZ1yDPTa2fHxufZN++n8MCmtgrJDtxFxrH4S8=",
|
||||
"lastModified": 1767313136,
|
||||
"narHash": "sha256-16KkgfdYqjaeRGBaYsNrhPRRENs0qzkQVUooNHtoy2w=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "3acb677ea67d4c6218f33de0db0955f116b7588c",
|
||||
"rev": "ac62194c3917d5f474c1a844b6fd6da2db95077d",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -202,15 +112,28 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_2": {
|
||||
"locked": {
|
||||
"lastModified": 1778869304,
|
||||
"narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "d233902339c02a9c334e7e593de68855ad26c4cb",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nixos",
|
||||
"ref": "nixos-unstable",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"root": {
|
||||
"inputs": {
|
||||
"disko": "disko",
|
||||
"home-manager": "home-manager",
|
||||
"impermanence": "impermanence",
|
||||
"madd": "madd",
|
||||
"nix-minecraft": "nix-minecraft",
|
||||
"nix-modpack": "nix-modpack",
|
||||
"nixpkgs": "nixpkgs",
|
||||
"nixpkgs": "nixpkgs_2",
|
||||
"nixpkgs-stable": "nixpkgs-stable",
|
||||
"secrets": "secrets",
|
||||
"sops-nix": "sops-nix"
|
||||
@@ -218,11 +141,11 @@
|
||||
},
|
||||
"secrets": {
|
||||
"locked": {
|
||||
"lastModified": 1762547267,
|
||||
"narHash": "sha256-bDYmYBJxtsSES+gcpHfpnURA7QDJ3cC1Mg2jzQl5zdg=",
|
||||
"lastModified": 1766822527,
|
||||
"narHash": "sha256-0qNxAxr7LQ8C6MjSxV2FkMSfdVmOVRq7Yz/wCea8plo=",
|
||||
"ref": "refs/heads/main",
|
||||
"rev": "601b97ba998f743a333fe7523dd5825816155778",
|
||||
"revCount": 17,
|
||||
"rev": "695e36891b5de248993845e1435df5e4116a26f2",
|
||||
"revCount": 21,
|
||||
"type": "git",
|
||||
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
|
||||
},
|
||||
@@ -238,11 +161,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1759635238,
|
||||
"narHash": "sha256-UvzKi02LMFP74csFfwLPAZ0mrE7k6EiYaKecplyX9Qk=",
|
||||
"lastModified": 1777944972,
|
||||
"narHash": "sha256-VfGRo1qTBKOe3s2gOv8LSoA6Fk19PvBlwQ1ECN0Evn8=",
|
||||
"owner": "Mic92",
|
||||
"repo": "sops-nix",
|
||||
"rev": "6e5a38e08a2c31ae687504196a230ae00ea95133",
|
||||
"rev": "c591bf665727040c6cc5cb409079acb22dcce33c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -250,36 +173,6 @@
|
||||
"repo": "sops-nix",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"systems": {
|
||||
"locked": {
|
||||
"lastModified": 1681028828,
|
||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||
"owner": "nix-systems",
|
||||
"repo": "default",
|
||||
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-systems",
|
||||
"repo": "default",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"systems_2": {
|
||||
"locked": {
|
||||
"lastModified": 1681028828,
|
||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||
"owner": "nix-systems",
|
||||
"repo": "default",
|
||||
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-systems",
|
||||
"repo": "default",
|
||||
"type": "github"
|
||||
}
|
||||
}
|
||||
},
|
||||
"root": "root",
|
||||
|
||||
@@ -19,15 +19,20 @@
|
||||
impermanence.url = "github:nix-community/impermanence";
|
||||
|
||||
# MADD
|
||||
madd.url = "git+https://git.bulthuis.dev/Jan/madd";
|
||||
madd.inputs.nixpkgs.follows = "nixpkgs";
|
||||
# madd.url = "git+https://git.bulthuis.dev/Jan/madd";
|
||||
# madd.inputs.nixpkgs.follows = "nixpkgs";
|
||||
|
||||
# For Minecraft VM
|
||||
nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
|
||||
nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
|
||||
nix-modpack.url = "github:Jan-Bulthuis/nix-modpack";
|
||||
nix-modpack.inputs.nixpkgs.follows = "nixpkgs";
|
||||
# nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
|
||||
# nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
|
||||
# nix-modpack.url = "github:Jan-Bulthuis/nix-modpack";
|
||||
# nix-modpack.inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
|
||||
outputs = inputs: import ./glue inputs;
|
||||
outputs =
|
||||
inputs:
|
||||
import ./glue {
|
||||
inherit inputs;
|
||||
excludeHomeManagerModules = [ "impermanence" ];
|
||||
};
|
||||
}
|
||||
+7
-2
@@ -1,4 +1,7 @@
|
||||
inputs:
|
||||
{
|
||||
inputs,
|
||||
excludeHomeManagerModules ? [ ],
|
||||
}:
|
||||
let
|
||||
flake = inputs.self;
|
||||
nixpkgs = inputs.nixpkgs;
|
||||
@@ -113,7 +116,9 @@ let
|
||||
homeProfiles = collectModules "${flake}/profiles/home";
|
||||
inputHomeModules = lib.map (flake: flake.outputs.homeManagerModules.default) (
|
||||
lib.filter (flake: lib.hasAttrByPath [ "outputs" "homeManagerModules" "default" ] flake) (
|
||||
lib.attrValues inputs
|
||||
lib.attrValues (
|
||||
lib.attrsets.filterAttrs (name: entry: !(lib.elem name excludeHomeManagerModules)) inputs
|
||||
)
|
||||
)
|
||||
);
|
||||
|
||||
|
||||
@@ -1,206 +0,0 @@
|
||||
{
|
||||
inputs,
|
||||
pkgs,
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
# State version
|
||||
system.stateVersion = "24.05";
|
||||
|
||||
# Machine hostname
|
||||
networking.hostName = "20212060";
|
||||
|
||||
# Admin users
|
||||
users.users.jan.extraGroups = [
|
||||
"wheel"
|
||||
"wireshark"
|
||||
"podman"
|
||||
];
|
||||
|
||||
# Set up kerberos
|
||||
security.krb5 = {
|
||||
enable = true;
|
||||
settings = {
|
||||
libdefaults = {
|
||||
rdns = false;
|
||||
};
|
||||
realms = (inputs.secrets.gewis.krb5Realm);
|
||||
};
|
||||
};
|
||||
|
||||
services.netbird = {
|
||||
enable = true;
|
||||
};
|
||||
|
||||
# TODO: Move clatd setup
|
||||
|
||||
# services.clatd = {
|
||||
# enable = true;
|
||||
# enableNetworkManagerIntegration = true;
|
||||
# };
|
||||
# networking.networkmanager.settings = {
|
||||
# connection."ipv6.clat" = "yes";
|
||||
# };
|
||||
networking.networkmanager.package = pkgs.networkmanager.overrideAttrs (
|
||||
final: prev: {
|
||||
src = pkgs.fetchFromGitLab {
|
||||
domain = "gitlab.freedesktop.org";
|
||||
owner = "Mstrodl";
|
||||
repo = "NetworkManager";
|
||||
# rev = "d367285a1fec5167f2fa94af2ea1448b6e21650e";
|
||||
# sha256 = "0BHxuJ6KtFoVxh2Xt0bq4oM3q87QBhtawyMtixz/cPs=";
|
||||
rev = "fa3b0c6ade05a67316520d143608c5bd9963a23c";
|
||||
hash = "sha256-7TENrRDKXMFPWv6oDuBWBYIBrDvNsy/JGtkppMk1oQo=";
|
||||
};
|
||||
|
||||
postPatch = prev.postPatch + ''
|
||||
substituteInPlace meson.build \
|
||||
--replace "find_program('clang'" "find_program('${pkgs.stdenv.cc.targetPrefix}clang'"
|
||||
'';
|
||||
|
||||
hardeningDisable = [
|
||||
"zerocallusedregs"
|
||||
"shadowstack"
|
||||
"pacret"
|
||||
];
|
||||
|
||||
nativeBuildInputs =
|
||||
prev.nativeBuildInputs
|
||||
++ (with pkgs; [
|
||||
xdp-tools
|
||||
bpftools
|
||||
buildPackages.llvmPackages.clang
|
||||
buildPackages.llvmPackages.libllvm
|
||||
]);
|
||||
|
||||
buildInputs =
|
||||
prev.buildInputs
|
||||
++ (with pkgs; [
|
||||
libbpf
|
||||
]);
|
||||
|
||||
mesonFlags = prev.mesonFlags ++ [
|
||||
"-Dclat=true"
|
||||
"-Dnbft=false"
|
||||
"-Dbpf-compiler=clang"
|
||||
];
|
||||
}
|
||||
);
|
||||
|
||||
# TODO: Remove once laptop is properly integrated into domain
|
||||
programs.ssh = {
|
||||
package = pkgs.openssh_gssapi;
|
||||
extraConfig = ''
|
||||
GSSAPIAuthentication yes
|
||||
'';
|
||||
};
|
||||
|
||||
# Enable virtualisation for VMs
|
||||
virtualisation.libvirtd.enable = true;
|
||||
|
||||
# Enable wireshark
|
||||
programs.wireshark = {
|
||||
enable = true;
|
||||
dumpcap.enable = true;
|
||||
usbmon.enable = true;
|
||||
};
|
||||
|
||||
# Enable Nix-LD
|
||||
programs.nix-ld = {
|
||||
enable = true;
|
||||
};
|
||||
|
||||
# Set up wstunnel client
|
||||
services.wstunnel = {
|
||||
enable = true;
|
||||
clients.wg-tunnel = {
|
||||
connectTo = "wss://tunnel.bulthuis.dev:443";
|
||||
settings.local-to-remote = [
|
||||
"udp://51820:10.10.40.100:51820"
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
# Enable flatpak
|
||||
services.flatpak.enable = true;
|
||||
|
||||
# Set up MADD
|
||||
# services.madd-client = {
|
||||
# enable = true;
|
||||
# endpoint = "http://localhost:3000";
|
||||
# interface = "wlp0s20f3";
|
||||
# };
|
||||
# services.madd-server = {
|
||||
# enable = true;
|
||||
# settings = {
|
||||
# bind = "127.0.0.1:3000";
|
||||
# zone = "lab.bulthuis.dev";
|
||||
# networks = [ "10.0.0.0/8" ];
|
||||
# registration_limit = 1;
|
||||
# dns_server = "127.0.0.1:2053";
|
||||
# tsig_key_name = "madd";
|
||||
# tsig_key_file = "/home/jan/Code/MADD/madd.tsig";
|
||||
# tsig_algorithm = "hmac-sha256";
|
||||
# data_dir = "/var/lib/madd";
|
||||
# };
|
||||
# };
|
||||
|
||||
# Module setup
|
||||
modules = {
|
||||
profiles.laptop.enable = true;
|
||||
};
|
||||
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
];
|
||||
|
||||
virtualisation.podman = {
|
||||
enable = true;
|
||||
dockerCompat = true;
|
||||
dockerSocket.enable = true;
|
||||
autoPrune.enable = true;
|
||||
};
|
||||
|
||||
environment.systemPackages =
|
||||
let
|
||||
wrapProgram =
|
||||
pkg: bwrapArgs:
|
||||
pkgs.runCommandLocal pkg.name { bwrapArgs = (lib.join " \\\n" bwrapArgs) + " \\"; } ''
|
||||
mkdir -p $out
|
||||
|
||||
# Link all top level folders
|
||||
ln -s ${pkg}/* $out
|
||||
|
||||
# Except for bin
|
||||
rm $out/bin
|
||||
mkdir -p $out/bin
|
||||
|
||||
# Wrap each executable
|
||||
for file in ${pkg}/bin/*; do
|
||||
base=$(basename $file)
|
||||
echo "#!/usr/bin/env bash" > $out/bin/$base
|
||||
echo "exec ${pkgs.bubblewrap}/bin/bwrap \\" >> $out/bin/$base
|
||||
echo "$bwrapArgs" >> $out/bin/$base
|
||||
echo "-- $file \"\$@\"" >> $out/bin/$base
|
||||
chmod +x $out/bin/$base
|
||||
done
|
||||
'';
|
||||
wish = pkgs.writeShellScriptBin "wish" ''
|
||||
env
|
||||
exec ${lib.getExe pkgs.firefox} "$@"
|
||||
'';
|
||||
in
|
||||
[
|
||||
(wrapProgram wish [
|
||||
"--new-session"
|
||||
"--unshare-all"
|
||||
"--clearenv"
|
||||
"--dev /dev"
|
||||
"--proc /proc"
|
||||
"--ro-bind /nix/store /nix/store"
|
||||
"--bind $HOME/Code $HOME/Code"
|
||||
])
|
||||
];
|
||||
}
|
||||
@@ -1,43 +0,0 @@
|
||||
{ ... }:
|
||||
|
||||
{
|
||||
# Machine platform
|
||||
nixpkgs.hostPlatform = "x86_64-linux";
|
||||
|
||||
# Hardware configuration
|
||||
hardware.enableRedistributableFirmware = true;
|
||||
boot.initrd.availableKernelModules = [
|
||||
"xhci_pci"
|
||||
"nvme"
|
||||
"usb_storage"
|
||||
"sd_mod"
|
||||
"rtsx_pci_sdmmc"
|
||||
];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ "kvm-intel" ];
|
||||
boot.extraModulePackages = [ ];
|
||||
hardware.cpu.intel.updateMicrocode = true;
|
||||
|
||||
# Filesystems
|
||||
fileSystems."/" = {
|
||||
device = "/dev/disk/by-uuid/3b91eaeb-ea95-4bea-8dc1-f55af7502d23";
|
||||
fsType = "ext4";
|
||||
};
|
||||
|
||||
fileSystems."/boot" = {
|
||||
device = "/dev/disk/by-uuid/46BF-DE2C";
|
||||
fsType = "vfat";
|
||||
options = [
|
||||
"fmask=0077"
|
||||
"dmask=0077"
|
||||
];
|
||||
};
|
||||
|
||||
# Swapfile
|
||||
swapDevices = [
|
||||
{
|
||||
device = "/var/lib/swapfile";
|
||||
size = 16 * 1024;
|
||||
}
|
||||
];
|
||||
}
|
||||
@@ -1,120 +0,0 @@
|
||||
{
|
||||
lib,
|
||||
config,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
home.stateVersion = "24.11";
|
||||
|
||||
home.packages = with pkgs; [
|
||||
# Desktop environment
|
||||
gnome-text-editor
|
||||
gnome-calculator
|
||||
gnome-console
|
||||
gnome-logs
|
||||
gnome-system-monitor
|
||||
nautilus
|
||||
adwaita-icon-theme
|
||||
gnome-control-center
|
||||
gnome-shell-extensions
|
||||
glib
|
||||
gnome-menus
|
||||
gtk3.out
|
||||
xdg-user-dirs
|
||||
xdg-user-dirs-gtk
|
||||
cantarell-fonts
|
||||
dejavu_fonts
|
||||
source-code-pro
|
||||
source-sans
|
||||
gnome-session
|
||||
adwaita-fonts
|
||||
|
||||
# Coding tools
|
||||
vim-full
|
||||
nano
|
||||
neovim
|
||||
emacs
|
||||
gedit
|
||||
geany
|
||||
kdePackages.kate
|
||||
vscode
|
||||
python310
|
||||
jdk17
|
||||
gnumake
|
||||
gcc
|
||||
lldb
|
||||
# pypy310
|
||||
|
||||
# Runners
|
||||
(writeShellScriptBin "mygcc" "gcc -std=gnu17 -x c -Wall -O2 -static -pipe -o $1 \"$1.c\" -lm")
|
||||
(writeShellScriptBin "mygpp" "g++ -std=gnu++20 -x c++ -Wall -O2 -static -pipe -o $1 \"$1.cpp\" -lm")
|
||||
(writeShellScriptBin "mypython" "python3 $@")
|
||||
(writeShellScriptBin "myjavac" "javac -encoding UTF-8 -sourcepath . -d . $@")
|
||||
(writeShellScriptBin "mykotlinc" "kotlinc -d . $@")
|
||||
];
|
||||
|
||||
modules.profiles.gnome.enable = true;
|
||||
|
||||
programs.vscode = {
|
||||
enable = true;
|
||||
mutableExtensionsDir = false;
|
||||
profiles.default = {
|
||||
extensions = with pkgs.vscode-extensions; [
|
||||
ms-vscode.cpptools
|
||||
ms-dotnettools.csharp
|
||||
formulahendry.code-runner
|
||||
vscjava.vscode-java-debug
|
||||
dbaeumer.vscode-eslint
|
||||
redhat.java
|
||||
ms-python.python
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
programs.firefox = {
|
||||
enable = true;
|
||||
package = pkgs.firefox;
|
||||
profiles.default = {
|
||||
settings = {
|
||||
"browser.startup.homepage" = "https://domjudge.bulthuis.dev";
|
||||
};
|
||||
bookmarks = {
|
||||
force = true;
|
||||
settings = [
|
||||
{
|
||||
name = "Sites";
|
||||
toolbar = true;
|
||||
bookmarks = [
|
||||
{
|
||||
name = "C Reference";
|
||||
url = "https://en.cppreference.com/w/c";
|
||||
}
|
||||
{
|
||||
name = "C++ Reference";
|
||||
url = "https://en.cppreference.com/w/cpp";
|
||||
}
|
||||
{
|
||||
name = "Python 3.10 documentation";
|
||||
url = "https://docs.python.org/3.10/download.html";
|
||||
}
|
||||
{
|
||||
name = "Java 17 API Specification";
|
||||
url = "https://docs.oracle.com/en/java/javase/17/docs/api/";
|
||||
}
|
||||
{
|
||||
name = "Kotlin Language Documentation";
|
||||
url = "https://kotlinlang.org/docs/kotlin-reference.pdf";
|
||||
}
|
||||
{
|
||||
name = "DOMjudge Team Manual";
|
||||
url = "https://www.domjudge.org/docs/manual/main/index.html";
|
||||
}
|
||||
];
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -1,31 +0,0 @@
|
||||
{
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
home.stateVersion = "24.11";
|
||||
|
||||
modules.profiles.jan.enable = true;
|
||||
|
||||
# home.packages = with pkgs; [
|
||||
# opencloud-desktop
|
||||
# code-nautilus
|
||||
# nautilus-open-in-blackbox
|
||||
# ];
|
||||
|
||||
xdg.desktopEntries = {
|
||||
canvas = {
|
||||
name = "Canvas";
|
||||
type = "Application";
|
||||
exec = "${pkgs.chromium}/bin/chromium --app=\"https://canvas.tue.nl\" --user-data-dir=/home/jan/.local/state/Canvas";
|
||||
settings.StartupWMClass = "chrome-canvas.tue.nl__-Default";
|
||||
};
|
||||
overleaf = {
|
||||
name = "Overleaf";
|
||||
type = "Application";
|
||||
exec = "${pkgs.chromium}/bin/chromium --app=\"https://www.overleaf.com\" --user-data-dir=/home/jan/.local/state/Overleaf";
|
||||
settings.StartupWMClass = "chrome-www.overleaf.com__-Default";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,254 @@
|
||||
{
|
||||
inputs,
|
||||
pkgs,
|
||||
config,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
# State version
|
||||
system.stateVersion = "25.05";
|
||||
|
||||
# Machine hostname
|
||||
networking.hostName = "vm-k1s";
|
||||
|
||||
# Enabled modules
|
||||
modules = {
|
||||
profiles.vm.enable = true;
|
||||
};
|
||||
|
||||
# Read in secrets
|
||||
sops.secrets."flux/git-ssh-key" = {
|
||||
sopsFile = "${inputs.secrets}/secrets/k3s-cluster.enc.yaml";
|
||||
};
|
||||
sops.secrets."flux/sops-decrypt-key" = {
|
||||
sopsFile = "${inputs.secrets}/secrets/k3s-cluster.enc.yaml";
|
||||
};
|
||||
|
||||
# Include NFS client module
|
||||
boot.supportedFilesystems = [ "nfs" ];
|
||||
|
||||
# Set up K3S cluster with CoreDNS, FluxCD and Cilium
|
||||
services.k3s = {
|
||||
enable = true;
|
||||
extraFlags = [
|
||||
"--cluster-domain ${inputs.secrets.lab.k3s.clusterDomain}"
|
||||
"--flannel-backend=none"
|
||||
"--disable-network-policy"
|
||||
"--disable-kube-proxy"
|
||||
];
|
||||
disable = [
|
||||
# "coredns" # CoreDNS is required for Flux to be able to bootstrap the cluster (Flux needs to resolve the git repo)
|
||||
"servicelb"
|
||||
"traefik"
|
||||
"local-storage"
|
||||
"metrics-server"
|
||||
"runtimes"
|
||||
];
|
||||
manifests = {
|
||||
git-ssh-key = {
|
||||
source = config.sops.secrets."flux/git-ssh-key".path;
|
||||
};
|
||||
sops-decrypt-key = {
|
||||
source = config.sops.secrets."flux/sops-decrypt-key".path;
|
||||
};
|
||||
# TODO: Move to flux config, once it is possible to easily install flux without CNI
|
||||
gateway-api =
|
||||
let
|
||||
manifest = pkgs.fetchurl {
|
||||
url = "https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.1/experimental-install.yaml";
|
||||
hash = "sha256-VTMn4P8yoaK+RGv5OCPIQTz5JTrGptVAfuvR6NJp9p4=";
|
||||
};
|
||||
in
|
||||
{
|
||||
source = manifest;
|
||||
};
|
||||
# TODO: Move to flux config, once it is possible to easily install flux without CNI
|
||||
netpol-system-allow-egress.content = {
|
||||
apiVersion = "cilium.io/v2";
|
||||
kind = "CiliumClusterwideNetworkPolicy";
|
||||
metadata.name = "allow-system-egress";
|
||||
spec = {
|
||||
description = "Allow all egress to system services.";
|
||||
endpointSelector = {
|
||||
matchExpressions = [
|
||||
{
|
||||
key = "io.kubernetes.pod.namespace";
|
||||
operator = "NotIn";
|
||||
values = [
|
||||
"bogus-namespace"
|
||||
# "kube-system"
|
||||
# "cilium-system"
|
||||
# "flux-system"
|
||||
];
|
||||
}
|
||||
];
|
||||
};
|
||||
egress = [
|
||||
{
|
||||
toEntities = [
|
||||
"all"
|
||||
];
|
||||
}
|
||||
];
|
||||
ingress = [
|
||||
{
|
||||
fromEntities = [
|
||||
"all"
|
||||
];
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
netpol-cluster-allow-dns.content = {
|
||||
apiVersion = "cilium.io/v2";
|
||||
kind = "CiliumClusterwideNetworkPolicy";
|
||||
metadata.name = "allow-dns";
|
||||
spec = {
|
||||
description = "Allow DNS";
|
||||
endpointSelector = { };
|
||||
egress = [
|
||||
{
|
||||
toEndpoints = [
|
||||
{
|
||||
matchLabels = {
|
||||
"io.kubernetes.pod.namespace" = "kube-system";
|
||||
"k8s-app" = "kube-dns";
|
||||
};
|
||||
}
|
||||
];
|
||||
toPorts = [
|
||||
{
|
||||
ports = [
|
||||
{
|
||||
port = 53;
|
||||
protocol = "ANY";
|
||||
}
|
||||
];
|
||||
rules.dns = [
|
||||
{
|
||||
matchPattern = "*";
|
||||
}
|
||||
];
|
||||
}
|
||||
];
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
netpol-flux-allow-egress.content = { };
|
||||
};
|
||||
autoDeployCharts = {
|
||||
# TODO: Move to flux config, once it is possible to easily install flux without CNI
|
||||
cilium = {
|
||||
name = "cilium";
|
||||
repo = "oci://quay.io/cilium/charts/cilium";
|
||||
version = "1.18.8";
|
||||
hash = "sha256-z1aDpWttEfQ+Af/l0Lxdafasm75QysRc8h7sPhWXr94=";
|
||||
createNamespace = true;
|
||||
targetNamespace = "cilium-system";
|
||||
values = {
|
||||
operator.replicas = 1;
|
||||
kubeProxyReplacement = true;
|
||||
ipam.operator.clusterPoolIPv4PodCIDRList = [ "10.42.0.0/16" ];
|
||||
cluster = {
|
||||
id = 1;
|
||||
name = "vm-k1s";
|
||||
};
|
||||
k8sServiceHost = "10.10.50.60";
|
||||
k8sServicePort = 6443;
|
||||
policyEnforcementMode = "always";
|
||||
gatewayAPI = {
|
||||
enabled = true;
|
||||
gatewayClass.create = "true";
|
||||
enableAlpn = true;
|
||||
};
|
||||
bgpControlPlane.enabled = true;
|
||||
tls.secretsNamespace.create = false;
|
||||
hubble = {
|
||||
relay.enabled = true;
|
||||
ui.enabled = true;
|
||||
peerService.clusterDomain = inputs.secrets.lab.k3s.clusterDomain;
|
||||
};
|
||||
};
|
||||
extraFieldDefinitions = {
|
||||
spec.bootstrap = true;
|
||||
};
|
||||
};
|
||||
flux-operator = {
|
||||
name = "flux-operator";
|
||||
repo = "oci://ghcr.io/controlplaneio-fluxcd/charts/flux-operator";
|
||||
version = "0.38.1";
|
||||
hash = "sha256-nb0mzEWC3IwjPenQ4LSWBN0NNJc2cc68RB+G60xBOEM=";
|
||||
createNamespace = true;
|
||||
targetNamespace = "flux-system";
|
||||
extraDeploy = [
|
||||
{
|
||||
apiVersion = "fluxcd.controlplane.io/v1";
|
||||
kind = "FluxInstance";
|
||||
metadata = {
|
||||
name = "flux";
|
||||
namespace = "flux-system";
|
||||
annotations = {
|
||||
"fluxcd.controlplane.io/reconcile" = "enabled";
|
||||
"fluxcd.controlplane.io/reconcileEvery" = "1h";
|
||||
"fluxcd.controlplane.io/reconcileTimeout" = "5m";
|
||||
};
|
||||
};
|
||||
spec = {
|
||||
distribution = {
|
||||
version = "2.x";
|
||||
registry = "ghcr.io/fluxcd";
|
||||
};
|
||||
components = [
|
||||
"source-controller"
|
||||
"kustomize-controller"
|
||||
"helm-controller"
|
||||
"notification-controller"
|
||||
];
|
||||
cluster = {
|
||||
type = "kubernetes";
|
||||
size = "small";
|
||||
multitenant = false;
|
||||
networkPolicy = true;
|
||||
domain = inputs.secrets.lab.k3s.clusterDomain;
|
||||
};
|
||||
commonMetadata.labels = {
|
||||
"app.kubernetes.io/name" = "flux";
|
||||
};
|
||||
sync = (
|
||||
{
|
||||
pullSecret = "git-ssh-key";
|
||||
}
|
||||
// inputs.secrets.lab.k3s.fluxRepo
|
||||
);
|
||||
};
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
modules.impermanence.directories = [
|
||||
"/var/lib/rancher/k3s"
|
||||
];
|
||||
|
||||
environment.variables = {
|
||||
KUBECONFIG = "/etc/rancher/k3s/k3s.yaml";
|
||||
CILIUM_NAMESPACE = "cilium-system";
|
||||
};
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
fluxcd
|
||||
k9s
|
||||
cilium-cli
|
||||
hubble
|
||||
];
|
||||
|
||||
# Use correct disko profile
|
||||
modules.disko.profile = "k3s";
|
||||
|
||||
# TEMP: Disable firewall for now
|
||||
networking.firewall.enable = false;
|
||||
security.sudo.wheelNeedsPassword = false;
|
||||
}
|
||||
@@ -30,6 +30,15 @@
|
||||
];
|
||||
};
|
||||
|
||||
# Set up impermanence
|
||||
modules.impermanence = {
|
||||
enable = true;
|
||||
resetScript = ''
|
||||
# Revert to the blank state for the root directory
|
||||
zfs rollback -r tank/root@blank
|
||||
'';
|
||||
};
|
||||
|
||||
# Set up kerberos
|
||||
security.krb5 = {
|
||||
enable = true;
|
||||
@@ -91,7 +100,7 @@
|
||||
clients.wg-tunnel = {
|
||||
connectTo = "wss://tunnel.bulthuis.dev:443";
|
||||
settings.local-to-remote = [
|
||||
"udp://51820:10.10.40.100:51820"
|
||||
"udp://51819:10.10.40.100:51820"
|
||||
];
|
||||
};
|
||||
};
|
||||
@@ -112,6 +121,56 @@
|
||||
autoPrune.enable = true;
|
||||
};
|
||||
|
||||
# Enable Gnome Remote Desktop
|
||||
services.gnome.gnome-remote-desktop.enable = true;
|
||||
systemd.services."gnome-remote-desktop".wantedBy = [ "graphical.target" ];
|
||||
systemd.services."gnome-remote-desktop".preStart =
|
||||
let
|
||||
credDir = "/var/lib/gnome-remote-desktop/.local/share/gnome-remote-desktop";
|
||||
credPath = "${credDir}/credentials.ini";
|
||||
credFile = pkgs.writeText "gnome-remote-desktop-credentials" ''
|
||||
[RDP]
|
||||
credentials={'username': <'remote'>, 'password': <'remote'>}
|
||||
'';
|
||||
script = pkgs.writeScript "gnome-remote-desktop-setup" ''
|
||||
mkdir -p ${credDir}
|
||||
touch ${credPath}
|
||||
chown gnome-remote-desktop:gnome-remote-desktop ${credPath}
|
||||
chmod 600 ${credPath}
|
||||
cat ${credFile} > ${credPath}
|
||||
'';
|
||||
in
|
||||
"${script}";
|
||||
environment.etc."gnome-remote-desktop/grd.conf" = {
|
||||
text = ''
|
||||
[RDP]
|
||||
port=3389
|
||||
tls-key=/run/secrets/gnome-remote-desktop/tls-key
|
||||
tls-cert=/run/secrets/gnome-remote-desktop/tls-crt
|
||||
enabled=true
|
||||
'';
|
||||
};
|
||||
networking.firewall = {
|
||||
allowedTCPPorts = [
|
||||
3389
|
||||
3390
|
||||
];
|
||||
allowedUDPPorts = [
|
||||
3389
|
||||
3390
|
||||
];
|
||||
};
|
||||
sops.secrets."gnome-remote-desktop/tls-key" = {
|
||||
sopsFile = "${inputs.secrets}/secrets/ws-think.enc.yaml";
|
||||
owner = config.users.users.gnome-remote-desktop.name;
|
||||
group = config.users.users.gnome-remote-desktop.group;
|
||||
};
|
||||
sops.secrets."gnome-remote-desktop/tls-crt" = {
|
||||
sopsFile = "${inputs.secrets}/secrets/ws-think.enc.yaml";
|
||||
owner = config.users.users.gnome-remote-desktop.name;
|
||||
group = config.users.users.gnome-remote-desktop.group;
|
||||
};
|
||||
|
||||
# Set up hardware
|
||||
imports = [ ./hardware-configuration.nix ];
|
||||
}
|
||||
@@ -7,6 +7,9 @@
|
||||
# Set hostid (required for ZFS)
|
||||
networking.hostId = "deadbeef";
|
||||
|
||||
# Use thermald
|
||||
services.thermald.ignoreCpuidCheck = true;
|
||||
|
||||
# Hardware configuration
|
||||
hardware.enableRedistributableFirmware = true;
|
||||
boot.initrd.availableKernelModules = [
|
||||
@@ -19,6 +22,7 @@
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ "kvm-intel" ];
|
||||
boot.extraModulePackages = [ ];
|
||||
boot.zfs.forceImportRoot = false;
|
||||
hardware.cpu.intel.updateMicrocode = true;
|
||||
|
||||
# Filesystems
|
||||
|
||||
@@ -28,4 +28,25 @@
|
||||
settings.StartupWMClass = "chrome-www.overleaf.com__-Default";
|
||||
};
|
||||
};
|
||||
|
||||
# TODO: Slowly remove
|
||||
modules.impermanence = {
|
||||
directories = [
|
||||
".cache"
|
||||
".config"
|
||||
".cargo"
|
||||
".dbus"
|
||||
".gnupg"
|
||||
".local"
|
||||
".MathWorks"
|
||||
".mozilla"
|
||||
".ssh"
|
||||
".steam"
|
||||
".SteamCloud"
|
||||
".thunderbird"
|
||||
".vscode"
|
||||
".wine"
|
||||
".Wolfram"
|
||||
];
|
||||
};
|
||||
}
|
||||
@@ -51,6 +51,10 @@ in
|
||||
mission-center
|
||||
dconf-editor
|
||||
gnome-calendar
|
||||
gnome-backgrounds
|
||||
gnome-bluetooth
|
||||
gnome-color-manager
|
||||
epiphany
|
||||
|
||||
# For theming gtk3
|
||||
# adw-gtk3 # TODO: Do this better, same for morewaita, not sure if it even works
|
||||
@@ -66,6 +70,7 @@ in
|
||||
mpris-label
|
||||
pip-on-top
|
||||
rounded-window-corners-reborn
|
||||
caffeine
|
||||
]);
|
||||
|
||||
# Set up gnome terminal as changing the default terminal is a pain
|
||||
|
||||
@@ -39,15 +39,15 @@ in
|
||||
programs.git = {
|
||||
enable = true;
|
||||
|
||||
extraConfig = {
|
||||
settings = {
|
||||
pull = {
|
||||
rebase = false;
|
||||
};
|
||||
};
|
||||
|
||||
userName = cfg.user;
|
||||
userEmail = cfg.email;
|
||||
ignores = cfg.ignores;
|
||||
settings.user.name = cfg.user;
|
||||
settings.user.email = cfg.email;
|
||||
# ignores = cfg.ignores;
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -18,7 +18,7 @@ in
|
||||
# Development packages
|
||||
home.packages = with pkgs; [
|
||||
nix-tree
|
||||
nixfmt-rfc-style
|
||||
nixfmt
|
||||
nixd
|
||||
];
|
||||
|
||||
|
||||
@@ -43,6 +43,7 @@ in
|
||||
tomoki1207.pdf
|
||||
ms-vsliveshare.vsliveshare
|
||||
ms-vscode-remote.remote-ssh
|
||||
myriad-dreamin.tinymist
|
||||
];
|
||||
|
||||
userSettings =
|
||||
|
||||
@@ -53,5 +53,8 @@ in
|
||||
fzf
|
||||
grc
|
||||
];
|
||||
|
||||
# Impermanence
|
||||
modules.impermanence.files = [ ".local/share/fish/fish_history" ];
|
||||
};
|
||||
}
|
||||
@@ -24,10 +24,9 @@ in
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
home.persistence."/persist/home/${config.home.username}" = {
|
||||
home.persistence."/persist/home" = {
|
||||
enable = true;
|
||||
hideMounts = true;
|
||||
allowOther = true;
|
||||
directories = cfg.directories;
|
||||
files = cfg.files;
|
||||
};
|
||||
|
||||
@@ -20,6 +20,12 @@ in
|
||||
console.font = "dina";
|
||||
console.earlySetup = true;
|
||||
|
||||
fonts.packages = with pkgs; [
|
||||
noto-fonts
|
||||
fira
|
||||
jetbrains-mono
|
||||
];
|
||||
|
||||
# TODO: Disable default fonts, fonts should be managed per user
|
||||
# fonts.enableDefaultPackages = false;
|
||||
# fonts.fontconfig = {
|
||||
|
||||
+7
-19
@@ -34,24 +34,8 @@ in
|
||||
glib
|
||||
gnome-menus
|
||||
gtk3.out
|
||||
xdg-user-dirs
|
||||
xdg-user-dirs-gtk
|
||||
];
|
||||
|
||||
# Enable Gnome Remote Desktop
|
||||
services.gnome.gnome-remote-desktop.enable = true;
|
||||
systemd.services."gnome-remote-desktop".wantedBy = [ "graphical.target" ];
|
||||
networking.firewall = {
|
||||
allowedTCPPorts = [
|
||||
3389
|
||||
3390
|
||||
];
|
||||
allowedUDPPorts = [
|
||||
3389
|
||||
3390
|
||||
];
|
||||
};
|
||||
|
||||
# For GSConnect/KDE Connect
|
||||
# TODO: Move to host config?
|
||||
networking.firewall = {
|
||||
@@ -70,8 +54,12 @@ in
|
||||
};
|
||||
|
||||
# Enable dependencies
|
||||
modules = {
|
||||
networkmanager.enable = true;
|
||||
};
|
||||
modules.networkmanager.enable = true;
|
||||
|
||||
# Impermanence
|
||||
modules.impermanence.directories = [
|
||||
"/etc/NetworkManager/system-connections"
|
||||
"/var/lib/bluetooth"
|
||||
];
|
||||
};
|
||||
}
|
||||
@@ -16,7 +16,11 @@ in
|
||||
# TODO: Add nvidia settings back in
|
||||
# TODO: Move to nvidia module
|
||||
hardware.nvidia = {
|
||||
open = true;
|
||||
open = false;
|
||||
prime = {
|
||||
intelBusId = "PCI:0@0:2:0";
|
||||
nvidiaBusId = "PCI:1@0:0:0";
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -50,11 +50,32 @@ in
|
||||
# For testing purposes with VM
|
||||
virtualisation.vmVariantWithDisko.virtualisation.fileSystems."/persist".neededForBoot = true;
|
||||
|
||||
environment.persistence."/persist/system" = {
|
||||
enable = true;
|
||||
hideMounts = true;
|
||||
directories = cfg.directories;
|
||||
files = cfg.files;
|
||||
environment.persistence = {
|
||||
"/persist/system" = {
|
||||
enable = true;
|
||||
hideMounts = true;
|
||||
directories = cfg.directories;
|
||||
files = cfg.files;
|
||||
};
|
||||
# "/persist/home" = {
|
||||
# enable = true;
|
||||
# hideMounts = true;
|
||||
# users = (
|
||||
# lib.mapAttrs' (
|
||||
# name: value:
|
||||
# let
|
||||
# user = name;
|
||||
# homeDir = "/home/${user}";
|
||||
# impConfig = value.modules.impermanence;
|
||||
# in
|
||||
# lib.nameValuePair user {
|
||||
# home = homeDir;
|
||||
# directories = impConfig.directories;
|
||||
# files = impConfig.files;
|
||||
# }
|
||||
# ) config.home-manager.users
|
||||
# );
|
||||
# };
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
{
|
||||
jq,
|
||||
lib,
|
||||
moreutils,
|
||||
tinymist,
|
||||
vscode-utils,
|
||||
}:
|
||||
|
||||
vscode-utils.buildVscodeMarketplaceExtension {
|
||||
mktplcRef = {
|
||||
name = "tinymist-vscode-html";
|
||||
publisher = "myriad-dreamin";
|
||||
inherit (tinymist) version;
|
||||
hash = "";
|
||||
};
|
||||
|
||||
nativeBuildInputs = [
|
||||
jq
|
||||
moreutils
|
||||
];
|
||||
|
||||
buildInputs = [ tinymist ];
|
||||
|
||||
postInstall = ''
|
||||
cd "$out/$installPrefix"
|
||||
jq '.contributes.configuration.properties."tinymist.serverPath".default = "${lib.getExe tinymist}"' package.json | sponge package.json
|
||||
'';
|
||||
|
||||
meta = {
|
||||
changelog = "https://marketplace.visualstudio.com/items/myriad-dreamin.tinymist/changelog";
|
||||
description = "VSCode extension for providing an integration solution for Typst";
|
||||
downloadPage = "https://marketplace.visualstudio.com/items?itemName=myriad-dreamin.tinymist";
|
||||
homepage = "https://github.com/myriad-dreamin/tinymist";
|
||||
license = lib.licenses.asl20;
|
||||
maintainers = [ ];
|
||||
};
|
||||
}
|
||||
@@ -1,82 +0,0 @@
|
||||
{
|
||||
fetchFromGitHub,
|
||||
fetchzip,
|
||||
lib,
|
||||
rustPlatform,
|
||||
git,
|
||||
installShellFiles,
|
||||
versionCheckHook,
|
||||
nix-update-script,
|
||||
}:
|
||||
|
||||
rustPlatform.buildRustPackage (final: rec {
|
||||
pname = "helix";
|
||||
version = "25.07.1";
|
||||
|
||||
# This release tarball includes source code for the tree-sitter grammars,
|
||||
# which is not ordinarily part of the repository.
|
||||
src = fetchFromGitHub {
|
||||
owner = "helix-editor";
|
||||
repo = "helix";
|
||||
rev = "109c812233e442addccf1739dec4406248bd3244";
|
||||
hash = "sha256-c3fpREWUKGonlmV/aesmyRxbJZQypHgXStR7SwdcCo0=";
|
||||
};
|
||||
grammars = fetchzip {
|
||||
url = "https://github.com/helix-editor/helix/releases/download/${final.version}/helix-${final.version}-source.tar.xz";
|
||||
hash = "sha256-Pj/lfcQXRWqBOTTWt6+Gk61F9F1UmeCYr+26hGdG974=";
|
||||
stripRoot = false;
|
||||
};
|
||||
|
||||
cargoHash = "sha256-g5MfCedLBiz41HMkIHl9NLWiewE8t3H2iRKOuWBmRig=";
|
||||
|
||||
nativeBuildInputs = [
|
||||
git
|
||||
installShellFiles
|
||||
];
|
||||
|
||||
env.HELIX_DEFAULT_RUNTIME = "${placeholder "out"}/lib/runtime";
|
||||
|
||||
patchPhase = ''
|
||||
# Add the runtime data
|
||||
rm -r runtime
|
||||
cp ${grammars}/languages.toml languages.toml
|
||||
cp -r ${grammars}/runtime runtime
|
||||
chmod -R u+w runtime
|
||||
'';
|
||||
|
||||
postInstall = ''
|
||||
# not needed at runtime
|
||||
rm -r runtime/grammars/sources
|
||||
|
||||
mkdir -p $out/lib
|
||||
cp -r runtime $out/lib
|
||||
installShellCompletion contrib/completion/hx.{bash,fish,zsh}
|
||||
mkdir -p $out/share/{applications,icons/hicolor/256x256/apps}
|
||||
cp contrib/Helix.desktop $out/share/applications
|
||||
cp contrib/helix.png $out/share/icons/hicolor/256x256/apps
|
||||
'';
|
||||
|
||||
nativeInstallCheckInputs = [
|
||||
versionCheckHook
|
||||
];
|
||||
versionCheckProgram = "${placeholder "out"}/bin/hx";
|
||||
versionCheckProgramArg = "--version";
|
||||
doInstallCheck = true;
|
||||
|
||||
passthru = {
|
||||
updateScript = nix-update-script { };
|
||||
};
|
||||
|
||||
meta = {
|
||||
description = "Post-modern modal text editor";
|
||||
homepage = "https://helix-editor.com";
|
||||
changelog = "https://github.com/helix-editor/helix/blob/${final.version}/CHANGELOG.md";
|
||||
license = lib.licenses.mpl20;
|
||||
mainProgram = "hx";
|
||||
maintainers = with lib.maintainers; [
|
||||
danth
|
||||
yusdacra
|
||||
zowoq
|
||||
];
|
||||
};
|
||||
})
|
||||
@@ -0,0 +1,82 @@
|
||||
{
|
||||
disko.devices = {
|
||||
disk = {
|
||||
main = {
|
||||
type = "disk";
|
||||
device = "/dev/sda";
|
||||
imageSize = "32G"; # For test VMs
|
||||
content = {
|
||||
type = "gpt";
|
||||
partitions = {
|
||||
boot = {
|
||||
size = "512M";
|
||||
type = "EF00";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "vfat";
|
||||
mountpoint = "/boot";
|
||||
mountOptions = [ "umask=0077" ];
|
||||
};
|
||||
};
|
||||
zfs = {
|
||||
end = "-4G";
|
||||
content = {
|
||||
type = "zfs";
|
||||
pool = "tank";
|
||||
};
|
||||
};
|
||||
swap = {
|
||||
size = "100%";
|
||||
content = {
|
||||
type = "swap";
|
||||
discardPolicy = "both";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
longhorn = {
|
||||
type = "disk";
|
||||
device = "/dev/sdb";
|
||||
imageSize = "64G"; # For longhorn storage
|
||||
content = {
|
||||
type = "gpt";
|
||||
partitions = {
|
||||
main = {
|
||||
size = "100%";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "ext4";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
zpool = {
|
||||
tank = {
|
||||
type = "zpool";
|
||||
rootFsOptions = {
|
||||
compression = "zstd";
|
||||
};
|
||||
mountpoint = null;
|
||||
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
|
||||
|
||||
datasets = {
|
||||
root = {
|
||||
type = "zfs_fs";
|
||||
mountpoint = "/";
|
||||
};
|
||||
nix = {
|
||||
type = "zfs_fs";
|
||||
mountpoint = "/nix";
|
||||
};
|
||||
persist = {
|
||||
type = "zfs_fs";
|
||||
mountpoint = "/persist";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -16,6 +16,7 @@ in
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
modules = {
|
||||
impermanence.enable = true;
|
||||
# btop.enable = true;
|
||||
direnv.enable = true;
|
||||
fish.enable = true;
|
||||
|
||||
@@ -20,8 +20,56 @@ in
|
||||
];
|
||||
|
||||
dconf.settings = {
|
||||
"org/gnome/calendar" = {
|
||||
active-view = "week";
|
||||
};
|
||||
"org/gnome/desktop/background" = {
|
||||
picture-uri = "file://${config.home.homeDirectory}/.local/share/backgrounds/background";
|
||||
};
|
||||
"org/gnome/desktop/input-sources" = {
|
||||
sources = [
|
||||
(lib.gvariant.mkTuple [
|
||||
"xkb"
|
||||
"us"
|
||||
])
|
||||
];
|
||||
xkb-options = [ "caps:escape_shifted_capslock" ];
|
||||
};
|
||||
"org/gnome/desktop/interface" = {
|
||||
accent-color = "purple";
|
||||
enable-hot-corners = false;
|
||||
};
|
||||
"org/gnome/desktop/peripherals/touchpad" = {
|
||||
speed = 0.214;
|
||||
two-finger-scrolling-enabled = true;
|
||||
};
|
||||
"org/gnome/mutter" = {
|
||||
workspaces-only-on-primary = true;
|
||||
};
|
||||
"org/gnome/nautilus/icon-view" = {
|
||||
default-zoom-level = "small";
|
||||
};
|
||||
"org/gnome/nautilus/preferences" = {
|
||||
default-folder-viewer = "icon-view";
|
||||
};
|
||||
"org/gnome/settings-daemon/plugins/color" = {
|
||||
night-light-enabled = true;
|
||||
night-light-schedule-automatic = false;
|
||||
night-light-schedule-from = 20.0;
|
||||
night-light-schedule-to = 6.0;
|
||||
night-light-temperature = 2700;
|
||||
};
|
||||
"org/gnome/shell" = {
|
||||
disable-extension-version-validation = true;
|
||||
enabled-extensions = [
|
||||
"disable-workspace-animation@ethnarque"
|
||||
"gsconnect@andyholmes.github.io"
|
||||
"rounded-window-corners@fxgn"
|
||||
"media-progress@krypion17"
|
||||
"mprisLabel@moon-0xff.github.com"
|
||||
"caffeube@patapon.info"
|
||||
];
|
||||
last-selected-power-profile = "power-saver";
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
+89
-4
@@ -25,14 +25,15 @@ in
|
||||
thunderbird
|
||||
signal-desktop
|
||||
prusa-slicer
|
||||
freecad-wayland
|
||||
pkgs-stable.freecad-wayland
|
||||
inkscape
|
||||
# ente-auth
|
||||
audacity
|
||||
carla
|
||||
pkgs-stable.winbox
|
||||
# pkgs-stable.winbox
|
||||
winbox4
|
||||
# whatsapp-for-linux
|
||||
wasistlos
|
||||
karere
|
||||
discord
|
||||
steam
|
||||
spotify
|
||||
@@ -48,6 +49,11 @@ in
|
||||
# kicad
|
||||
vlc
|
||||
authenticator
|
||||
hotspot
|
||||
btop
|
||||
winboat
|
||||
hieroglyphic
|
||||
shortwave
|
||||
|
||||
podman
|
||||
podman-compose
|
||||
@@ -56,6 +62,14 @@ in
|
||||
gnome-logs
|
||||
];
|
||||
|
||||
programs.zathura = {
|
||||
enable = true;
|
||||
options = {
|
||||
synctex = true;
|
||||
synctex-editor-command = "${pkgs.texlab}/bin/texlab inverse-search -i %{input} -l %{line}";
|
||||
};
|
||||
};
|
||||
|
||||
programs.helix = {
|
||||
enable = true;
|
||||
defaultEditor = true;
|
||||
@@ -66,6 +80,34 @@ in
|
||||
# fallback = "default";
|
||||
# };
|
||||
# };
|
||||
settings =
|
||||
let
|
||||
move_line_up = [
|
||||
"extend_to_line_bounds"
|
||||
"delete_selection"
|
||||
"move_line_up"
|
||||
"paste_before"
|
||||
];
|
||||
move_line_down = [
|
||||
"extend_to_line_bounds"
|
||||
"delete_selection"
|
||||
"paste_after"
|
||||
];
|
||||
in
|
||||
{
|
||||
keys.normal = {
|
||||
"A-up" = move_line_up;
|
||||
"A-down" = move_line_down;
|
||||
"A-k" = move_line_up;
|
||||
"A-j" = move_line_down;
|
||||
};
|
||||
keys.select = {
|
||||
"A-up" = move_line_up;
|
||||
"A-down" = move_line_down;
|
||||
"A-k" = move_line_up;
|
||||
"A-j" = move_line_down;
|
||||
};
|
||||
};
|
||||
extraPackages = with pkgs; [
|
||||
bash-language-server # Bash
|
||||
fish-lsp # Fish
|
||||
@@ -95,7 +137,8 @@ in
|
||||
ruff # Python
|
||||
basedpyright # Python
|
||||
|
||||
helix-gpt # Copilot
|
||||
#helix-gpt # Copilot
|
||||
ltex-ls-plus # Spellchecking
|
||||
|
||||
# texlab # Latex, Bibtex
|
||||
# bibtex-tidy # Bibtex
|
||||
@@ -114,6 +157,22 @@ in
|
||||
];
|
||||
languages = {
|
||||
language-server = {
|
||||
ltex = {
|
||||
command = "ltex-ls-plus";
|
||||
config.ltex = { };
|
||||
};
|
||||
texlab = {
|
||||
command = "texlab";
|
||||
config.texlab = {
|
||||
build.onSave = true;
|
||||
forwardSearch.executable = "${config.programs.zathura.package}/bin/zathura";
|
||||
forwardSearch.args = [
|
||||
"--synctex-forward"
|
||||
"%l:1:%f"
|
||||
"%p"
|
||||
];
|
||||
};
|
||||
};
|
||||
basedpyright = {
|
||||
command = "basedpyright-langserver";
|
||||
args = [ "--stdio" ];
|
||||
@@ -131,6 +190,16 @@ in
|
||||
};
|
||||
};
|
||||
language = [
|
||||
{
|
||||
name = "latex";
|
||||
# language-servers = [
|
||||
# { name = "texlab"; }
|
||||
# { name = "ltex"; }
|
||||
# ];
|
||||
soft-wrap = {
|
||||
enable = true;
|
||||
};
|
||||
}
|
||||
{
|
||||
name = "python";
|
||||
language-servers = [
|
||||
@@ -153,9 +222,25 @@ in
|
||||
};
|
||||
};
|
||||
|
||||
systemd.user.tmpfiles.rules = [
|
||||
"d ${config.home.homeDirectory}/Downloads - - - - -"
|
||||
];
|
||||
|
||||
modules = {
|
||||
profiles.gnome.enable = true;
|
||||
|
||||
impermanence = {
|
||||
directories = [
|
||||
"Code"
|
||||
"Documents"
|
||||
"Games"
|
||||
"Models"
|
||||
"Music"
|
||||
"Pictures"
|
||||
"Videos"
|
||||
];
|
||||
};
|
||||
|
||||
# Gaming
|
||||
# retroarch.enable = true;
|
||||
# ryujinx.enable = true;
|
||||
|
||||
+13
-3
@@ -19,9 +19,17 @@ in
|
||||
bootloader.enable = mkDefault true;
|
||||
ssh.enable = mkDefault true;
|
||||
|
||||
impermanence.directories = [
|
||||
"/var/lib/nixos"
|
||||
];
|
||||
impermanence = {
|
||||
files = [
|
||||
"/etc/machine-id"
|
||||
"/etc/zfs/zpool.cache" # TODO: Move to zfs module?
|
||||
];
|
||||
directories = [
|
||||
"/var/log/journal"
|
||||
"/var/lib/nixos"
|
||||
"/var/lib/systemd"
|
||||
];
|
||||
};
|
||||
|
||||
# TODO: Remove the secrets module and use sops directly?
|
||||
secrets = {
|
||||
@@ -67,6 +75,8 @@ in
|
||||
zip
|
||||
unzip
|
||||
tmux
|
||||
unixtools.net-tools
|
||||
tcpdump
|
||||
];
|
||||
};
|
||||
}
|
||||
@@ -20,7 +20,7 @@ in
|
||||
profiles.base.enable = true;
|
||||
disko = {
|
||||
enable = true;
|
||||
profile = "vm";
|
||||
profile = mkDefault "vm";
|
||||
};
|
||||
impermanence = {
|
||||
enable = true;
|
||||
|
||||
Reference in new issue
Block a user