Compare commits
78
Commits
5f68b9b1e6
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9d2e52675e | ||
|
|
6c5c69945a | ||
|
|
9883f3d461 | ||
|
|
6d86bb8368 | ||
|
|
0dbc4792d4 | ||
|
|
753b763b6f | ||
|
|
2a690681cb | ||
|
|
82f4a2e1d4 | ||
|
|
eb18897355 | ||
|
|
00679a2c04 | ||
|
|
8e819e01ea | ||
|
|
cf4c179fc4 | ||
|
|
c991768cc2 | ||
|
|
268879ee01 | ||
|
|
7e9f617965 | ||
|
|
7d6482587a | ||
|
|
cf10e1e963 | ||
|
|
02b2b9cf32 | ||
|
|
dfe6ec5518 | ||
|
|
517d793c88 | ||
|
|
657a65522f | ||
|
|
7bc3ab64dd | ||
|
|
2b5cfe0934 | ||
|
|
cf345521e8 | ||
|
|
f43945d0d2 | ||
|
|
7874412a48 | ||
|
|
e33a6e181e | ||
|
|
928dc4a240 | ||
|
|
63d34640f7 | ||
|
|
921565fe12 | ||
|
|
88792d86db | ||
|
|
49b4ade156 | ||
|
|
34f179465d | ||
|
|
588bea133c | ||
|
|
61ec61e22e | ||
|
|
10a3de42ac | ||
|
|
6f98d674b1 | ||
|
|
4278ceebc1 | ||
|
|
3358dd324e | ||
|
|
c3014ec109 | ||
|
|
08ca6a2846 | ||
|
|
2fbe36d497 | ||
|
|
9929cd297a | ||
|
|
869a219ab7 | ||
|
|
af1a275dd8 | ||
|
|
9d302345ac | ||
|
|
e0b3fe191c | ||
|
|
d3681fcd4f | ||
|
|
5458f74c83 | ||
|
|
13302deaef | ||
|
|
828face9d5 | ||
|
|
e4402eaf19 | ||
|
|
081084648f | ||
|
|
9d629c4656 | ||
|
|
4a65f64a20 | ||
|
|
d3b3e9be1c | ||
|
|
5224a6e4b6 | ||
|
|
dd0778e5f0 | ||
|
|
7247fc94ab | ||
|
|
655803bd1f | ||
|
|
9992039edb | ||
|
|
f31c0f92da | ||
|
|
307aac4ae0 | ||
|
|
160185ef20 | ||
|
|
42619807bc | ||
|
|
86c853de20 | ||
|
|
f52e880b4c | ||
|
|
e157071962 | ||
|
|
d324c957be | ||
|
|
1fa6092498 | ||
|
|
e43a91fe31 | ||
|
|
f06880d6d7 | ||
|
|
fa17ce5b03 | ||
|
|
cf42666c1f | ||
|
|
df49791fb7 | ||
|
|
cf4a324617 | ||
|
|
66b2662030 | ||
|
|
21045c3dd1 |
No files matched your search
Generated
+79
-114
@@ -7,11 +7,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1750040002,
|
"lastModified": 1779135526,
|
||||||
"narHash": "sha256-KrC9iOVYIn6ukpVlHbqSA4hYCZ6oDyJKrcLqv4c5v84=",
|
"narHash": "sha256-glCununz6lmaK5fs2X946HA3EkNxB2JagdAAvInuRYU=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "disko",
|
"repo": "disko",
|
||||||
"rev": "7f1857b31522062a6a00f88cbccf86b43acceed1",
|
"rev": "d405a179887d52b24c0ddd31e09a150bd1f66779",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -20,40 +20,6 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"flake-compat": {
|
|
||||||
"flake": false,
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1747046372,
|
|
||||||
"narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=",
|
|
||||||
"owner": "edolstra",
|
|
||||||
"repo": "flake-compat",
|
|
||||||
"rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "edolstra",
|
|
||||||
"repo": "flake-compat",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"flake-utils": {
|
|
||||||
"inputs": {
|
|
||||||
"systems": "systems"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1731533236,
|
|
||||||
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"home-manager": {
|
"home-manager": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
@@ -61,11 +27,32 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1750107071,
|
"lastModified": 1779157263,
|
||||||
"narHash": "sha256-yfuHCO4m+gu3OBNGnP0/TL5W8nLXrC/EV1fs/+YcoL8=",
|
"narHash": "sha256-VbiyZkRf8/qr7ObmlyfOHJsNAW5tyZ4MB1+cUwAwdrw=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "home-manager",
|
"repo": "home-manager",
|
||||||
"rev": "0edffd088e42fdc48598b37d88eb5345e2ca3937",
|
"rev": "866412a19866b4a8e32d2306a118040afa2b840c",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "nix-community",
|
||||||
|
"repo": "home-manager",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"home-manager_2": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"impermanence",
|
||||||
|
"nixpkgs"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1768598210,
|
||||||
|
"narHash": "sha256-kkgA32s/f4jaa4UG+2f8C225Qvclxnqs76mf8zvTVPg=",
|
||||||
|
"owner": "nix-community",
|
||||||
|
"repo": "home-manager",
|
||||||
|
"rev": "c47b2cc64a629f8e075de52e4742de688f930dc6",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -75,12 +62,16 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"impermanence": {
|
"impermanence": {
|
||||||
|
"inputs": {
|
||||||
|
"home-manager": "home-manager_2",
|
||||||
|
"nixpkgs": "nixpkgs"
|
||||||
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1737831083,
|
"lastModified": 1769548169,
|
||||||
"narHash": "sha256-LJggUHbpyeDvNagTUrdhe/pRVp4pnS6wVKALS782gRI=",
|
"narHash": "sha256-03+JxvzmfwRu+5JafM0DLbxgHttOQZkUtDWBmeUkN8Y=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "impermanence",
|
"repo": "impermanence",
|
||||||
"rev": "4b3e914cdf97a5b536a889e939fb2fd2b043a170",
|
"rev": "7b1d382faf603b6d264f58627330f9faa5cba149",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -89,60 +80,50 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nix-minecraft": {
|
|
||||||
"inputs": {
|
|
||||||
"flake-compat": "flake-compat",
|
|
||||||
"flake-utils": "flake-utils",
|
|
||||||
"nixpkgs": [
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1751650156,
|
|
||||||
"narHash": "sha256-1gIPVDf159TQlcVg3WQBHMZVn8RllHOa8eT7AJPj2IE=",
|
|
||||||
"owner": "Jan-Bulthuis",
|
|
||||||
"repo": "nix-minecraft",
|
|
||||||
"rev": "d3b3779fd78bd55db24d25e896438b2b51cbb6cb",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "Jan-Bulthuis",
|
|
||||||
"repo": "nix-minecraft",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nix-modpack": {
|
|
||||||
"inputs": {
|
|
||||||
"nixpkgs": [
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1747559249,
|
|
||||||
"narHash": "sha256-+ygKEGMVcXNklO4RDYSd5XzydDmQOZWcOcxYZf/PH1U=",
|
|
||||||
"owner": "Jan-Bulthuis",
|
|
||||||
"repo": "nix-modpack",
|
|
||||||
"rev": "a093625c2847afc3ef257513161c7fe318c6be1c",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "Jan-Bulthuis",
|
|
||||||
"repo": "nix-modpack",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixpkgs": {
|
"nixpkgs": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1749903597,
|
"lastModified": 1768564909,
|
||||||
"narHash": "sha256-jp0D4vzBcRKwNZwfY4BcWHemLGUs4JrS3X9w5k/JYDA=",
|
"narHash": "sha256-Kell/SpJYVkHWMvnhqJz/8DqQg2b6PguxVWOuadbHCc=",
|
||||||
"owner": "nixos",
|
"owner": "nixos",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "41da1e3ea8e23e094e5e3eeb1e6b830468a7399e",
|
"rev": "e4bae1bd10c9c57b2cf517953ab70060a828ee6f",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "nixos",
|
"owner": "nixos",
|
||||||
"ref": "nixpkgs-unstable",
|
"ref": "nixos-unstable",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"nixpkgs-stable": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1767313136,
|
||||||
|
"narHash": "sha256-16KkgfdYqjaeRGBaYsNrhPRRENs0qzkQVUooNHtoy2w=",
|
||||||
|
"owner": "nixos",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "ac62194c3917d5f474c1a844b6fd6da2db95077d",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "nixos",
|
||||||
|
"ref": "nixos-25.05",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"nixpkgs_2": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1778869304,
|
||||||
|
"narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=",
|
||||||
|
"owner": "nixos",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "d233902339c02a9c334e7e593de68855ad26c4cb",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "nixos",
|
||||||
|
"ref": "nixos-unstable",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
@@ -152,20 +133,19 @@
|
|||||||
"disko": "disko",
|
"disko": "disko",
|
||||||
"home-manager": "home-manager",
|
"home-manager": "home-manager",
|
||||||
"impermanence": "impermanence",
|
"impermanence": "impermanence",
|
||||||
"nix-minecraft": "nix-minecraft",
|
"nixpkgs": "nixpkgs_2",
|
||||||
"nix-modpack": "nix-modpack",
|
"nixpkgs-stable": "nixpkgs-stable",
|
||||||
"nixpkgs": "nixpkgs",
|
|
||||||
"secrets": "secrets",
|
"secrets": "secrets",
|
||||||
"sops-nix": "sops-nix"
|
"sops-nix": "sops-nix"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"secrets": {
|
"secrets": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1750361251,
|
"lastModified": 1766822527,
|
||||||
"narHash": "sha256-yfK2ArCYImg5vIfWP8f2O9+TF18K0dGOVqjheI23zuo=",
|
"narHash": "sha256-0qNxAxr7LQ8C6MjSxV2FkMSfdVmOVRq7Yz/wCea8plo=",
|
||||||
"ref": "refs/heads/main",
|
"ref": "refs/heads/main",
|
||||||
"rev": "498db9fadb1810dd2c3e5d130b655ff7632f9640",
|
"rev": "695e36891b5de248993845e1435df5e4116a26f2",
|
||||||
"revCount": 14,
|
"revCount": 21,
|
||||||
"type": "git",
|
"type": "git",
|
||||||
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
|
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
|
||||||
},
|
},
|
||||||
@@ -181,11 +161,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1749592509,
|
"lastModified": 1777944972,
|
||||||
"narHash": "sha256-VunQzfZFA+Y6x3wYi2UE4DEQ8qKoAZZCnZPUlSoqC+A=",
|
"narHash": "sha256-VfGRo1qTBKOe3s2gOv8LSoA6Fk19PvBlwQ1ECN0Evn8=",
|
||||||
"owner": "Mic92",
|
"owner": "Mic92",
|
||||||
"repo": "sops-nix",
|
"repo": "sops-nix",
|
||||||
"rev": "50754dfaa0e24e313c626900d44ef431f3210138",
|
"rev": "c591bf665727040c6cc5cb409079acb22dcce33c",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -193,21 +173,6 @@
|
|||||||
"repo": "sops-nix",
|
"repo": "sops-nix",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
|
||||||
"systems": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1681028828,
|
|
||||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"repo": "default",
|
|
||||||
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"repo": "default",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"root": "root",
|
"root": "root",
|
||||||
|
|||||||
@@ -3,7 +3,8 @@
|
|||||||
|
|
||||||
inputs = {
|
inputs = {
|
||||||
# General inputs
|
# General inputs
|
||||||
nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable";
|
nixpkgs-stable.url = "github:nixos/nixpkgs/nixos-25.05";
|
||||||
|
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
|
||||||
home-manager.url = "github:nix-community/home-manager";
|
home-manager.url = "github:nix-community/home-manager";
|
||||||
home-manager.inputs.nixpkgs.follows = "nixpkgs";
|
home-manager.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
|
||||||
@@ -17,12 +18,21 @@
|
|||||||
disko.inputs.nixpkgs.follows = "nixpkgs";
|
disko.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
impermanence.url = "github:nix-community/impermanence";
|
impermanence.url = "github:nix-community/impermanence";
|
||||||
|
|
||||||
|
# MADD
|
||||||
|
# madd.url = "git+https://git.bulthuis.dev/Jan/madd";
|
||||||
|
# madd.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
|
||||||
# For Minecraft VM
|
# For Minecraft VM
|
||||||
nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
|
# nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
|
||||||
nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
|
# nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
nix-modpack.url = "github:Jan-Bulthuis/nix-modpack";
|
# nix-modpack.url = "github:Jan-Bulthuis/nix-modpack";
|
||||||
nix-modpack.inputs.nixpkgs.follows = "nixpkgs";
|
# nix-modpack.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
};
|
};
|
||||||
|
|
||||||
outputs = inputs: import ./glue inputs;
|
outputs =
|
||||||
|
inputs:
|
||||||
|
import ./glue {
|
||||||
|
inherit inputs;
|
||||||
|
excludeHomeManagerModules = [ "impermanence" ];
|
||||||
|
};
|
||||||
}
|
}
|
||||||
+33
-4
@@ -1,9 +1,16 @@
|
|||||||
inputs:
|
{
|
||||||
|
inputs,
|
||||||
|
excludeHomeManagerModules ? [ ],
|
||||||
|
}:
|
||||||
let
|
let
|
||||||
flake = inputs.self;
|
flake = inputs.self;
|
||||||
nixpkgs = inputs.nixpkgs;
|
nixpkgs = inputs.nixpkgs;
|
||||||
lib = nixpkgs.lib;
|
lib = nixpkgs.lib;
|
||||||
|
|
||||||
|
nixpkgs-config = {
|
||||||
|
allowUnfree = true;
|
||||||
|
};
|
||||||
|
|
||||||
importDir =
|
importDir =
|
||||||
path: fn:
|
path: fn:
|
||||||
let
|
let
|
||||||
@@ -49,6 +56,13 @@ let
|
|||||||
pkgs = (
|
pkgs = (
|
||||||
import inputs.nixpkgs {
|
import inputs.nixpkgs {
|
||||||
inherit system;
|
inherit system;
|
||||||
|
config = nixpkgs-config;
|
||||||
|
}
|
||||||
|
);
|
||||||
|
stable-pkgs = (
|
||||||
|
import inputs.nixpkgs-stable {
|
||||||
|
inherit system;
|
||||||
|
config = nixpkgs-config;
|
||||||
}
|
}
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
@@ -102,7 +116,9 @@ let
|
|||||||
homeProfiles = collectModules "${flake}/profiles/home";
|
homeProfiles = collectModules "${flake}/profiles/home";
|
||||||
inputHomeModules = lib.map (flake: flake.outputs.homeManagerModules.default) (
|
inputHomeModules = lib.map (flake: flake.outputs.homeManagerModules.default) (
|
||||||
lib.filter (flake: lib.hasAttrByPath [ "outputs" "homeManagerModules" "default" ] flake) (
|
lib.filter (flake: lib.hasAttrByPath [ "outputs" "homeManagerModules" "default" ] flake) (
|
||||||
lib.attrValues inputs
|
lib.attrValues (
|
||||||
|
lib.attrsets.filterAttrs (name: entry: !(lib.elem name excludeHomeManagerModules)) inputs
|
||||||
|
)
|
||||||
)
|
)
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -118,13 +134,22 @@ let
|
|||||||
nixpkgs.overlays = [ overlay ] ++ inputOverlays;
|
nixpkgs.overlays = [ overlay ] ++ inputOverlays;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
nixpkgsModule =
|
||||||
|
{ ... }:
|
||||||
|
{
|
||||||
|
nixpkgs.config = nixpkgs-config;
|
||||||
|
};
|
||||||
|
|
||||||
nixosConfigurations = importDir "${flake}/hosts" (
|
nixosConfigurations = importDir "${flake}/hosts" (
|
||||||
attrs:
|
attrs:
|
||||||
lib.mapAttrs (
|
lib.mapAttrs (
|
||||||
name: entry:
|
name: entry:
|
||||||
|
let
|
||||||
|
pkgs-stable = systemArgs."x86_64-linux".stable-pkgs;
|
||||||
|
in
|
||||||
lib.nixosSystem {
|
lib.nixosSystem {
|
||||||
specialArgs = {
|
specialArgs = {
|
||||||
inherit inputs;
|
inherit inputs pkgs-stable;
|
||||||
};
|
};
|
||||||
modules =
|
modules =
|
||||||
let
|
let
|
||||||
@@ -143,8 +168,11 @@ let
|
|||||||
usersModule =
|
usersModule =
|
||||||
{ ... }:
|
{ ... }:
|
||||||
{
|
{
|
||||||
|
home-manager.extraSpecialArgs = {
|
||||||
|
inherit inputs pkgs-stable;
|
||||||
|
};
|
||||||
home-manager.sharedModules = homeModules ++ homeProfiles ++ inputHomeModules;
|
home-manager.sharedModules = homeModules ++ homeProfiles ++ inputHomeModules;
|
||||||
home-manager.useUserPackages = false; # TODO: See if this should be changed to true?
|
home-manager.useUserPackages = true;
|
||||||
home-manager.useGlobalPkgs = true;
|
home-manager.useGlobalPkgs = true;
|
||||||
home-manager.users = homesConfiguration;
|
home-manager.users = homesConfiguration;
|
||||||
users.users = usersConfiguration;
|
users.users = usersConfiguration;
|
||||||
@@ -155,6 +183,7 @@ let
|
|||||||
systemPath
|
systemPath
|
||||||
overlayModule
|
overlayModule
|
||||||
usersModule
|
usersModule
|
||||||
|
nixpkgsModule
|
||||||
]
|
]
|
||||||
++ nixosModules
|
++ nixosModules
|
||||||
++ nixosProfiles
|
++ nixosProfiles
|
||||||
|
|||||||
@@ -1,56 +0,0 @@
|
|||||||
{ inputs, ... }:
|
|
||||||
|
|
||||||
{
|
|
||||||
# State version
|
|
||||||
system.stateVersion = "24.05";
|
|
||||||
|
|
||||||
# Machine hostname
|
|
||||||
networking.hostName = "20212060";
|
|
||||||
|
|
||||||
# Admin users
|
|
||||||
users.users.jan.extraGroups = [
|
|
||||||
"wheel"
|
|
||||||
"wireshark"
|
|
||||||
];
|
|
||||||
|
|
||||||
# Set up kerberos
|
|
||||||
security.krb5 = {
|
|
||||||
enable = true;
|
|
||||||
settings = {
|
|
||||||
libdefaults = {
|
|
||||||
rdns = false;
|
|
||||||
};
|
|
||||||
realms = (inputs.secrets.gewis.krb5Realm);
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
# Enable virtualisation for VMs
|
|
||||||
virtualisation.libvirtd.enable = true;
|
|
||||||
|
|
||||||
# Enable wireshark
|
|
||||||
programs.wireshark = {
|
|
||||||
enable = true;
|
|
||||||
dumpcap.enable = true;
|
|
||||||
usbmon.enable = true;
|
|
||||||
};
|
|
||||||
|
|
||||||
# Set up wstunnel client
|
|
||||||
services.wstunnel = {
|
|
||||||
enable = true;
|
|
||||||
clients.wg-tunnel = {
|
|
||||||
connectTo = "wss://tunnel.bulthuis.dev:443";
|
|
||||||
localToRemote = [
|
|
||||||
"udp://51820:10.10.40.100:51820"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
# Module setup
|
|
||||||
modules = {
|
|
||||||
profiles.laptop.enable = true;
|
|
||||||
};
|
|
||||||
|
|
||||||
imports = [
|
|
||||||
./hardware-configuration.nix
|
|
||||||
];
|
|
||||||
}
|
|
||||||
@@ -1,43 +0,0 @@
|
|||||||
{ ... }:
|
|
||||||
|
|
||||||
{
|
|
||||||
# Machine platform
|
|
||||||
nixpkgs.hostPlatform = "x86_64-linux";
|
|
||||||
|
|
||||||
# Hardware configuration
|
|
||||||
hardware.enableRedistributableFirmware = true;
|
|
||||||
boot.initrd.availableKernelModules = [
|
|
||||||
"xhci_pci"
|
|
||||||
"nvme"
|
|
||||||
"usb_storage"
|
|
||||||
"sd_mod"
|
|
||||||
"rtsx_pci_sdmmc"
|
|
||||||
];
|
|
||||||
boot.initrd.kernelModules = [ ];
|
|
||||||
boot.kernelModules = [ "kvm-intel" ];
|
|
||||||
boot.extraModulePackages = [ ];
|
|
||||||
hardware.cpu.intel.updateMicrocode = true;
|
|
||||||
|
|
||||||
# Filesystems
|
|
||||||
fileSystems."/" = {
|
|
||||||
device = "/dev/disk/by-uuid/3b91eaeb-ea95-4bea-8dc1-f55af7502d23";
|
|
||||||
fsType = "ext4";
|
|
||||||
};
|
|
||||||
|
|
||||||
fileSystems."/boot" = {
|
|
||||||
device = "/dev/disk/by-uuid/46BF-DE2C";
|
|
||||||
fsType = "vfat";
|
|
||||||
options = [
|
|
||||||
"fmask=0077"
|
|
||||||
"dmask=0077"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
# Swapfile
|
|
||||||
swapDevices = [
|
|
||||||
{
|
|
||||||
device = "/var/lib/swapfile";
|
|
||||||
size = 16 * 1024;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
}
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
{
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
|
|
||||||
{
|
|
||||||
home.stateVersion = "24.11";
|
|
||||||
|
|
||||||
modules.profiles.jan.enable = true;
|
|
||||||
}
|
|
||||||
Binary file not shown.
@@ -77,7 +77,7 @@
|
|||||||
group = "mixer";
|
group = "mixer";
|
||||||
extraGroups = [ "systemd-journal" ];
|
extraGroups = [ "systemd-journal" ];
|
||||||
openssh.authorizedKeys.keys = [
|
openssh.authorizedKeys.keys = [
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKKxoQSxfYqf9ITN8Fhckk8WbY4dwtBAXOhC9jxihJvq jan@bulthuis.dev"
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKKxoQSxfYqf9ITN8Fhckk8WbY4dwtBAXOhC9jxihJvq Personal"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
users.groups.mixer = { };
|
users.groups.mixer = { };
|
||||||
|
|||||||
@@ -0,0 +1,39 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
# State version
|
||||||
|
system.stateVersion = "25.05";
|
||||||
|
|
||||||
|
# Machine hostname
|
||||||
|
networking.hostName = "vm-infra";
|
||||||
|
|
||||||
|
# Enabled modules
|
||||||
|
modules = {
|
||||||
|
profiles.vm.enable = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
# Setup JOOL NAT64
|
||||||
|
networking.jool = {
|
||||||
|
enable = true;
|
||||||
|
nat64.default = {
|
||||||
|
global.pool6 = "64:ff9b::/96";
|
||||||
|
pool4 = [
|
||||||
|
{
|
||||||
|
protocol = "TCP";
|
||||||
|
prefix = "10.64.0.1/32";
|
||||||
|
}
|
||||||
|
{
|
||||||
|
protocol = "UDP";
|
||||||
|
prefix = "10.64.0.1/32";
|
||||||
|
}
|
||||||
|
{
|
||||||
|
protocol = "ICMP";
|
||||||
|
prefix = "10.64.0.1/32";
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,254 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
pkgs,
|
||||||
|
config,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
# State version
|
||||||
|
system.stateVersion = "25.05";
|
||||||
|
|
||||||
|
# Machine hostname
|
||||||
|
networking.hostName = "vm-k1s";
|
||||||
|
|
||||||
|
# Enabled modules
|
||||||
|
modules = {
|
||||||
|
profiles.vm.enable = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
# Read in secrets
|
||||||
|
sops.secrets."flux/git-ssh-key" = {
|
||||||
|
sopsFile = "${inputs.secrets}/secrets/k3s-cluster.enc.yaml";
|
||||||
|
};
|
||||||
|
sops.secrets."flux/sops-decrypt-key" = {
|
||||||
|
sopsFile = "${inputs.secrets}/secrets/k3s-cluster.enc.yaml";
|
||||||
|
};
|
||||||
|
|
||||||
|
# Include NFS client module
|
||||||
|
boot.supportedFilesystems = [ "nfs" ];
|
||||||
|
|
||||||
|
# Set up K3S cluster with CoreDNS, FluxCD and Cilium
|
||||||
|
services.k3s = {
|
||||||
|
enable = true;
|
||||||
|
extraFlags = [
|
||||||
|
"--cluster-domain ${inputs.secrets.lab.k3s.clusterDomain}"
|
||||||
|
"--flannel-backend=none"
|
||||||
|
"--disable-network-policy"
|
||||||
|
"--disable-kube-proxy"
|
||||||
|
];
|
||||||
|
disable = [
|
||||||
|
# "coredns" # CoreDNS is required for Flux to be able to bootstrap the cluster (Flux needs to resolve the git repo)
|
||||||
|
"servicelb"
|
||||||
|
"traefik"
|
||||||
|
"local-storage"
|
||||||
|
"metrics-server"
|
||||||
|
"runtimes"
|
||||||
|
];
|
||||||
|
manifests = {
|
||||||
|
git-ssh-key = {
|
||||||
|
source = config.sops.secrets."flux/git-ssh-key".path;
|
||||||
|
};
|
||||||
|
sops-decrypt-key = {
|
||||||
|
source = config.sops.secrets."flux/sops-decrypt-key".path;
|
||||||
|
};
|
||||||
|
# TODO: Move to flux config, once it is possible to easily install flux without CNI
|
||||||
|
gateway-api =
|
||||||
|
let
|
||||||
|
manifest = pkgs.fetchurl {
|
||||||
|
url = "https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.1/experimental-install.yaml";
|
||||||
|
hash = "sha256-VTMn4P8yoaK+RGv5OCPIQTz5JTrGptVAfuvR6NJp9p4=";
|
||||||
|
};
|
||||||
|
in
|
||||||
|
{
|
||||||
|
source = manifest;
|
||||||
|
};
|
||||||
|
# TODO: Move to flux config, once it is possible to easily install flux without CNI
|
||||||
|
netpol-system-allow-egress.content = {
|
||||||
|
apiVersion = "cilium.io/v2";
|
||||||
|
kind = "CiliumClusterwideNetworkPolicy";
|
||||||
|
metadata.name = "allow-system-egress";
|
||||||
|
spec = {
|
||||||
|
description = "Allow all egress to system services.";
|
||||||
|
endpointSelector = {
|
||||||
|
matchExpressions = [
|
||||||
|
{
|
||||||
|
key = "io.kubernetes.pod.namespace";
|
||||||
|
operator = "NotIn";
|
||||||
|
values = [
|
||||||
|
"bogus-namespace"
|
||||||
|
# "kube-system"
|
||||||
|
# "cilium-system"
|
||||||
|
# "flux-system"
|
||||||
|
];
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
egress = [
|
||||||
|
{
|
||||||
|
toEntities = [
|
||||||
|
"all"
|
||||||
|
];
|
||||||
|
}
|
||||||
|
];
|
||||||
|
ingress = [
|
||||||
|
{
|
||||||
|
fromEntities = [
|
||||||
|
"all"
|
||||||
|
];
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
netpol-cluster-allow-dns.content = {
|
||||||
|
apiVersion = "cilium.io/v2";
|
||||||
|
kind = "CiliumClusterwideNetworkPolicy";
|
||||||
|
metadata.name = "allow-dns";
|
||||||
|
spec = {
|
||||||
|
description = "Allow DNS";
|
||||||
|
endpointSelector = { };
|
||||||
|
egress = [
|
||||||
|
{
|
||||||
|
toEndpoints = [
|
||||||
|
{
|
||||||
|
matchLabels = {
|
||||||
|
"io.kubernetes.pod.namespace" = "kube-system";
|
||||||
|
"k8s-app" = "kube-dns";
|
||||||
|
};
|
||||||
|
}
|
||||||
|
];
|
||||||
|
toPorts = [
|
||||||
|
{
|
||||||
|
ports = [
|
||||||
|
{
|
||||||
|
port = 53;
|
||||||
|
protocol = "ANY";
|
||||||
|
}
|
||||||
|
];
|
||||||
|
rules.dns = [
|
||||||
|
{
|
||||||
|
matchPattern = "*";
|
||||||
|
}
|
||||||
|
];
|
||||||
|
}
|
||||||
|
];
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
netpol-flux-allow-egress.content = { };
|
||||||
|
};
|
||||||
|
autoDeployCharts = {
|
||||||
|
# TODO: Move to flux config, once it is possible to easily install flux without CNI
|
||||||
|
cilium = {
|
||||||
|
name = "cilium";
|
||||||
|
repo = "oci://quay.io/cilium/charts/cilium";
|
||||||
|
version = "1.18.8";
|
||||||
|
hash = "sha256-z1aDpWttEfQ+Af/l0Lxdafasm75QysRc8h7sPhWXr94=";
|
||||||
|
createNamespace = true;
|
||||||
|
targetNamespace = "cilium-system";
|
||||||
|
values = {
|
||||||
|
operator.replicas = 1;
|
||||||
|
kubeProxyReplacement = true;
|
||||||
|
ipam.operator.clusterPoolIPv4PodCIDRList = [ "10.42.0.0/16" ];
|
||||||
|
cluster = {
|
||||||
|
id = 1;
|
||||||
|
name = "vm-k1s";
|
||||||
|
};
|
||||||
|
k8sServiceHost = "10.10.50.60";
|
||||||
|
k8sServicePort = 6443;
|
||||||
|
policyEnforcementMode = "always";
|
||||||
|
gatewayAPI = {
|
||||||
|
enabled = true;
|
||||||
|
gatewayClass.create = "true";
|
||||||
|
enableAlpn = true;
|
||||||
|
};
|
||||||
|
bgpControlPlane.enabled = true;
|
||||||
|
tls.secretsNamespace.create = false;
|
||||||
|
hubble = {
|
||||||
|
relay.enabled = true;
|
||||||
|
ui.enabled = true;
|
||||||
|
peerService.clusterDomain = inputs.secrets.lab.k3s.clusterDomain;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
extraFieldDefinitions = {
|
||||||
|
spec.bootstrap = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
flux-operator = {
|
||||||
|
name = "flux-operator";
|
||||||
|
repo = "oci://ghcr.io/controlplaneio-fluxcd/charts/flux-operator";
|
||||||
|
version = "0.38.1";
|
||||||
|
hash = "sha256-nb0mzEWC3IwjPenQ4LSWBN0NNJc2cc68RB+G60xBOEM=";
|
||||||
|
createNamespace = true;
|
||||||
|
targetNamespace = "flux-system";
|
||||||
|
extraDeploy = [
|
||||||
|
{
|
||||||
|
apiVersion = "fluxcd.controlplane.io/v1";
|
||||||
|
kind = "FluxInstance";
|
||||||
|
metadata = {
|
||||||
|
name = "flux";
|
||||||
|
namespace = "flux-system";
|
||||||
|
annotations = {
|
||||||
|
"fluxcd.controlplane.io/reconcile" = "enabled";
|
||||||
|
"fluxcd.controlplane.io/reconcileEvery" = "1h";
|
||||||
|
"fluxcd.controlplane.io/reconcileTimeout" = "5m";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
spec = {
|
||||||
|
distribution = {
|
||||||
|
version = "2.x";
|
||||||
|
registry = "ghcr.io/fluxcd";
|
||||||
|
};
|
||||||
|
components = [
|
||||||
|
"source-controller"
|
||||||
|
"kustomize-controller"
|
||||||
|
"helm-controller"
|
||||||
|
"notification-controller"
|
||||||
|
];
|
||||||
|
cluster = {
|
||||||
|
type = "kubernetes";
|
||||||
|
size = "small";
|
||||||
|
multitenant = false;
|
||||||
|
networkPolicy = true;
|
||||||
|
domain = inputs.secrets.lab.k3s.clusterDomain;
|
||||||
|
};
|
||||||
|
commonMetadata.labels = {
|
||||||
|
"app.kubernetes.io/name" = "flux";
|
||||||
|
};
|
||||||
|
sync = (
|
||||||
|
{
|
||||||
|
pullSecret = "git-ssh-key";
|
||||||
|
}
|
||||||
|
// inputs.secrets.lab.k3s.fluxRepo
|
||||||
|
);
|
||||||
|
};
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
modules.impermanence.directories = [
|
||||||
|
"/var/lib/rancher/k3s"
|
||||||
|
];
|
||||||
|
|
||||||
|
environment.variables = {
|
||||||
|
KUBECONFIG = "/etc/rancher/k3s/k3s.yaml";
|
||||||
|
CILIUM_NAMESPACE = "cilium-system";
|
||||||
|
};
|
||||||
|
|
||||||
|
environment.systemPackages = with pkgs; [
|
||||||
|
fluxcd
|
||||||
|
k9s
|
||||||
|
cilium-cli
|
||||||
|
hubble
|
||||||
|
];
|
||||||
|
|
||||||
|
# Use correct disko profile
|
||||||
|
modules.disko.profile = "k3s";
|
||||||
|
|
||||||
|
# TEMP: Disable firewall for now
|
||||||
|
networking.firewall.enable = false;
|
||||||
|
security.sudo.wheelNeedsPassword = false;
|
||||||
|
}
|
||||||
@@ -25,6 +25,9 @@
|
|||||||
|
|
||||||
# Set up minecraft servers
|
# Set up minecraft servers
|
||||||
users.users.local.extraGroups = [ "minecraft" ];
|
users.users.local.extraGroups = [ "minecraft" ];
|
||||||
|
modules.impermanence.directories = [
|
||||||
|
"/srv/minecraft"
|
||||||
|
];
|
||||||
services.minecraft-servers = {
|
services.minecraft-servers = {
|
||||||
enable = true;
|
enable = true;
|
||||||
eula = true;
|
eula = true;
|
||||||
@@ -33,8 +36,12 @@
|
|||||||
vanilla = {
|
vanilla = {
|
||||||
enable = true;
|
enable = true;
|
||||||
autoStart = true;
|
autoStart = true;
|
||||||
serverProperties = { };
|
serverProperties = {
|
||||||
package = inputs.nix-minecraft.legacyPackages.${pkgs.system}.vanillaServers.vanilla-1_20_7;
|
white-list = true;
|
||||||
|
difficulty = "normal";
|
||||||
|
max-players = 5;
|
||||||
|
};
|
||||||
|
package = inputs.nix-minecraft.legacyPackages.${pkgs.system}.fabricServers.fabric-1_21_7;
|
||||||
};
|
};
|
||||||
modpack = {
|
modpack = {
|
||||||
enable = false;
|
enable = false;
|
||||||
|
|||||||
@@ -18,6 +18,58 @@
|
|||||||
profiles.vm.enable = true;
|
profiles.vm.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
# Omada Software Controller
|
||||||
|
users.users.omada = {
|
||||||
|
isSystemUser = true;
|
||||||
|
group = "omada";
|
||||||
|
};
|
||||||
|
users.groups.omada = { };
|
||||||
|
virtualisation.podman = {
|
||||||
|
enable = true;
|
||||||
|
dockerCompat = true;
|
||||||
|
defaultNetwork.settings.dns_enabled = true;
|
||||||
|
};
|
||||||
|
virtualisation.oci-containers = {
|
||||||
|
backend = "podman";
|
||||||
|
containers = {
|
||||||
|
omada-controller = {
|
||||||
|
volumes = [
|
||||||
|
"/var/lib/omada:/opt/tplink/EAPController/data"
|
||||||
|
];
|
||||||
|
environment = {
|
||||||
|
TZ = "Europe/Amsterdam";
|
||||||
|
};
|
||||||
|
extraOptions = [
|
||||||
|
"--network=host"
|
||||||
|
"--ulimit"
|
||||||
|
"nofile=4096:8192"
|
||||||
|
];
|
||||||
|
image = "mbentley/omada-controller:5.15";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
modules.impermanence.directories = [
|
||||||
|
"/var/lib/omada"
|
||||||
|
];
|
||||||
|
networking.firewall = {
|
||||||
|
allowedTCPPorts = [
|
||||||
|
8088
|
||||||
|
8043
|
||||||
|
8843
|
||||||
|
];
|
||||||
|
allowedTCPPortRanges = [
|
||||||
|
{
|
||||||
|
from = 29811;
|
||||||
|
to = 29816;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
allowedUDPPorts = [
|
||||||
|
19810
|
||||||
|
27001
|
||||||
|
29810
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
# Setup NAS backups
|
# Setup NAS backups
|
||||||
environment.systemPackages = with pkgs; [
|
environment.systemPackages = with pkgs; [
|
||||||
keyutils
|
keyutils
|
||||||
|
|||||||
@@ -0,0 +1,176 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
pkgs,
|
||||||
|
config,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
# State version
|
||||||
|
system.stateVersion = "24.05";
|
||||||
|
|
||||||
|
# Machine hostname
|
||||||
|
networking.hostName = "ws-think";
|
||||||
|
|
||||||
|
# Set up users
|
||||||
|
sops.secrets."passwords/jan-hashed" = {
|
||||||
|
sopsFile = "${inputs.secrets}/secrets/ws-think.enc.yaml";
|
||||||
|
neededForUsers = true;
|
||||||
|
};
|
||||||
|
users.mutableUsers = false;
|
||||||
|
users.users.Jan = {
|
||||||
|
hashedPasswordFile = config.sops.secrets."passwords/jan-hashed".path;
|
||||||
|
# Extra admin groups
|
||||||
|
# TODO: Streamline setup of this
|
||||||
|
extraGroups = [
|
||||||
|
"wheel"
|
||||||
|
"wireshark"
|
||||||
|
"podman"
|
||||||
|
"libvirtd"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
# Set up impermanence
|
||||||
|
modules.impermanence = {
|
||||||
|
enable = true;
|
||||||
|
resetScript = ''
|
||||||
|
# Revert to the blank state for the root directory
|
||||||
|
zfs rollback -r tank/root@blank
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
# Set up kerberos
|
||||||
|
security.krb5 = {
|
||||||
|
enable = true;
|
||||||
|
settings = {
|
||||||
|
libdefaults = {
|
||||||
|
rdns = false;
|
||||||
|
};
|
||||||
|
realms = (inputs.secrets.gewis.krb5Realm);
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
services.netbird = {
|
||||||
|
enable = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
# SSH X11 forwarding
|
||||||
|
programs.ssh.forwardX11 = true;
|
||||||
|
|
||||||
|
# Enable older samba versions
|
||||||
|
services.samba = {
|
||||||
|
enable = true;
|
||||||
|
settings = {
|
||||||
|
global = {
|
||||||
|
"invalid users" = [ "root" ];
|
||||||
|
"passwd program" = "/run/wrappers/bin/passwd %u";
|
||||||
|
"security" = "user";
|
||||||
|
"client min protocol" = "NT1";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# TODO: Remove once laptop is properly integrated into domain
|
||||||
|
programs.ssh = {
|
||||||
|
package = pkgs.openssh_gssapi;
|
||||||
|
extraConfig = ''
|
||||||
|
GSSAPIAuthentication yes
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
# Enable virtualisation for VMs
|
||||||
|
virtualisation.libvirtd.enable = true;
|
||||||
|
programs.virt-manager.enable = true;
|
||||||
|
|
||||||
|
# Enable wireshark
|
||||||
|
programs.wireshark = {
|
||||||
|
enable = true;
|
||||||
|
dumpcap.enable = true;
|
||||||
|
usbmon.enable = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
# Enable Nix-LD
|
||||||
|
programs.nix-ld = {
|
||||||
|
enable = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
# Set up wstunnel client
|
||||||
|
services.wstunnel = {
|
||||||
|
enable = true;
|
||||||
|
clients.wg-tunnel = {
|
||||||
|
connectTo = "wss://tunnel.bulthuis.dev:443";
|
||||||
|
settings.local-to-remote = [
|
||||||
|
"udp://51819:10.10.40.100:51820"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# Enable flatpak
|
||||||
|
services.flatpak.enable = true;
|
||||||
|
|
||||||
|
# Module setup
|
||||||
|
modules = {
|
||||||
|
profiles.laptop.enable = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
# Set up podman
|
||||||
|
virtualisation.podman = {
|
||||||
|
enable = true;
|
||||||
|
dockerCompat = true;
|
||||||
|
dockerSocket.enable = true;
|
||||||
|
autoPrune.enable = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
# Enable Gnome Remote Desktop
|
||||||
|
services.gnome.gnome-remote-desktop.enable = true;
|
||||||
|
systemd.services."gnome-remote-desktop".wantedBy = [ "graphical.target" ];
|
||||||
|
systemd.services."gnome-remote-desktop".preStart =
|
||||||
|
let
|
||||||
|
credDir = "/var/lib/gnome-remote-desktop/.local/share/gnome-remote-desktop";
|
||||||
|
credPath = "${credDir}/credentials.ini";
|
||||||
|
credFile = pkgs.writeText "gnome-remote-desktop-credentials" ''
|
||||||
|
[RDP]
|
||||||
|
credentials={'username': <'remote'>, 'password': <'remote'>}
|
||||||
|
'';
|
||||||
|
script = pkgs.writeScript "gnome-remote-desktop-setup" ''
|
||||||
|
mkdir -p ${credDir}
|
||||||
|
touch ${credPath}
|
||||||
|
chown gnome-remote-desktop:gnome-remote-desktop ${credPath}
|
||||||
|
chmod 600 ${credPath}
|
||||||
|
cat ${credFile} > ${credPath}
|
||||||
|
'';
|
||||||
|
in
|
||||||
|
"${script}";
|
||||||
|
environment.etc."gnome-remote-desktop/grd.conf" = {
|
||||||
|
text = ''
|
||||||
|
[RDP]
|
||||||
|
port=3389
|
||||||
|
tls-key=/run/secrets/gnome-remote-desktop/tls-key
|
||||||
|
tls-cert=/run/secrets/gnome-remote-desktop/tls-crt
|
||||||
|
enabled=true
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
networking.firewall = {
|
||||||
|
allowedTCPPorts = [
|
||||||
|
3389
|
||||||
|
3390
|
||||||
|
];
|
||||||
|
allowedUDPPorts = [
|
||||||
|
3389
|
||||||
|
3390
|
||||||
|
];
|
||||||
|
};
|
||||||
|
sops.secrets."gnome-remote-desktop/tls-key" = {
|
||||||
|
sopsFile = "${inputs.secrets}/secrets/ws-think.enc.yaml";
|
||||||
|
owner = config.users.users.gnome-remote-desktop.name;
|
||||||
|
group = config.users.users.gnome-remote-desktop.group;
|
||||||
|
};
|
||||||
|
sops.secrets."gnome-remote-desktop/tls-crt" = {
|
||||||
|
sopsFile = "${inputs.secrets}/secrets/ws-think.enc.yaml";
|
||||||
|
owner = config.users.users.gnome-remote-desktop.name;
|
||||||
|
group = config.users.users.gnome-remote-desktop.group;
|
||||||
|
};
|
||||||
|
|
||||||
|
# Set up hardware
|
||||||
|
imports = [ ./hardware-configuration.nix ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,65 @@
|
|||||||
|
{ ... }:
|
||||||
|
|
||||||
|
{
|
||||||
|
# Machine platform
|
||||||
|
nixpkgs.hostPlatform = "x86_64-linux";
|
||||||
|
|
||||||
|
# Set hostid (required for ZFS)
|
||||||
|
networking.hostId = "deadbeef";
|
||||||
|
|
||||||
|
# Use thermald
|
||||||
|
services.thermald.ignoreCpuidCheck = true;
|
||||||
|
|
||||||
|
# Hardware configuration
|
||||||
|
hardware.enableRedistributableFirmware = true;
|
||||||
|
boot.initrd.availableKernelModules = [
|
||||||
|
"xhci_pci"
|
||||||
|
"nvme"
|
||||||
|
"usb_storage"
|
||||||
|
"sd_mod"
|
||||||
|
"rtsx_pci_sdmmc"
|
||||||
|
];
|
||||||
|
boot.initrd.kernelModules = [ ];
|
||||||
|
boot.kernelModules = [ "kvm-intel" ];
|
||||||
|
boot.extraModulePackages = [ ];
|
||||||
|
boot.zfs.forceImportRoot = false;
|
||||||
|
hardware.cpu.intel.updateMicrocode = true;
|
||||||
|
|
||||||
|
# Filesystems
|
||||||
|
fileSystems = {
|
||||||
|
"/" = {
|
||||||
|
device = "tank/root";
|
||||||
|
fsType = "zfs";
|
||||||
|
options = [ "zfsutil" ];
|
||||||
|
};
|
||||||
|
|
||||||
|
"/nix" = {
|
||||||
|
device = "tank/nix";
|
||||||
|
fsType = "zfs";
|
||||||
|
options = [ "zfsutil" ];
|
||||||
|
};
|
||||||
|
|
||||||
|
"/persist" = {
|
||||||
|
device = "tank/persist";
|
||||||
|
fsType = "zfs";
|
||||||
|
options = [ "zfsutil" ];
|
||||||
|
};
|
||||||
|
|
||||||
|
"/boot" = {
|
||||||
|
device = "/dev/disk/by-uuid/46BF-DE2C";
|
||||||
|
fsType = "vfat";
|
||||||
|
options = [
|
||||||
|
"fmask=0077"
|
||||||
|
"dmask=0077"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# Swap setup
|
||||||
|
swapDevices = [
|
||||||
|
{
|
||||||
|
device = "/dev/disk/by-uuid/9f6f2a47-e53a-45a0-8cb2-8c1082f54ccb";
|
||||||
|
discardPolicy = "both";
|
||||||
|
}
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
{
|
||||||
|
pkgs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
home.stateVersion = "25.11";
|
||||||
|
|
||||||
|
modules.profiles.jan.enable = true;
|
||||||
|
|
||||||
|
# home.packages = with pkgs; [
|
||||||
|
# opencloud-desktop
|
||||||
|
# code-nautilus
|
||||||
|
# nautilus-open-in-blackbox
|
||||||
|
# ];
|
||||||
|
|
||||||
|
xdg.desktopEntries = {
|
||||||
|
canvas = {
|
||||||
|
name = "Canvas";
|
||||||
|
type = "Application";
|
||||||
|
exec = "${pkgs.chromium}/bin/chromium --app=\"https://canvas.tue.nl\" --user-data-dir=/home/jan/.local/state/Canvas";
|
||||||
|
settings.StartupWMClass = "chrome-canvas.tue.nl__-Default";
|
||||||
|
};
|
||||||
|
overleaf = {
|
||||||
|
name = "Overleaf";
|
||||||
|
type = "Application";
|
||||||
|
exec = "${pkgs.chromium}/bin/chromium --app=\"https://www.overleaf.com\" --user-data-dir=/home/jan/.local/state/Overleaf";
|
||||||
|
settings.StartupWMClass = "chrome-www.overleaf.com__-Default";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# TODO: Slowly remove
|
||||||
|
modules.impermanence = {
|
||||||
|
directories = [
|
||||||
|
".cache"
|
||||||
|
".config"
|
||||||
|
".cargo"
|
||||||
|
".dbus"
|
||||||
|
".gnupg"
|
||||||
|
".local"
|
||||||
|
".MathWorks"
|
||||||
|
".mozilla"
|
||||||
|
".ssh"
|
||||||
|
".steam"
|
||||||
|
".SteamCloud"
|
||||||
|
".thunderbird"
|
||||||
|
".vscode"
|
||||||
|
".wine"
|
||||||
|
".Wolfram"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -15,14 +15,14 @@ in
|
|||||||
};
|
};
|
||||||
|
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
# TODO: Enable extensions with dconf
|
# TODO: Enable extensions (declaratively) with dconf
|
||||||
|
|
||||||
home.pointerCursor = {
|
home.pointerCursor = {
|
||||||
|
enable = true;
|
||||||
name = "capitaine-cursors";
|
name = "capitaine-cursors";
|
||||||
size = 24;
|
size = 24;
|
||||||
package = pkgs.capitaine-cursors;
|
package = pkgs.capitaine-cursors;
|
||||||
gtk.enable = true;
|
gtk.enable = true;
|
||||||
x11.enable = true;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
home.packages =
|
home.packages =
|
||||||
@@ -50,32 +50,52 @@ in
|
|||||||
file-roller
|
file-roller
|
||||||
mission-center
|
mission-center
|
||||||
dconf-editor
|
dconf-editor
|
||||||
|
gnome-calendar
|
||||||
|
gnome-backgrounds
|
||||||
|
gnome-bluetooth
|
||||||
|
gnome-color-manager
|
||||||
|
epiphany
|
||||||
|
|
||||||
# For theming gtk3
|
# For theming gtk3
|
||||||
adw-gtk3
|
# adw-gtk3 # TODO: Do this better, same for morewaita, not sure if it even works
|
||||||
|
|
||||||
|
# More icons
|
||||||
|
# morewaita-icon-theme
|
||||||
]
|
]
|
||||||
++ (with pkgs.gnomeExtensions; [
|
++ (with pkgs.gnomeExtensions; [
|
||||||
gsconnect
|
gsconnect
|
||||||
disable-workspace-animation
|
disable-workspace-animation
|
||||||
wallpaper-slideshow
|
wallpaper-slideshow
|
||||||
media-progress
|
media-progress
|
||||||
# luminus-desktop
|
mpris-label
|
||||||
|
pip-on-top
|
||||||
|
rounded-window-corners-reborn
|
||||||
|
caffeine
|
||||||
]);
|
]);
|
||||||
|
|
||||||
# Enable and set the gtk themes
|
# Set up gnome terminal as changing the default terminal is a pain
|
||||||
gtk = {
|
programs.gnome-terminal = {
|
||||||
enable = true;
|
enable = true;
|
||||||
gtk3.extraConfig = {
|
profile."12d2da79-b36c-43d5-8e1f-cf70907b84b3" = {
|
||||||
gtk-theme-name = "adw-gtk3";
|
visibleName = "Default";
|
||||||
};
|
default = true;
|
||||||
gtk4.extraConfig = {
|
|
||||||
gtk-theme-name = "Adwaita";
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
# Enable and set the gtk themes
|
||||||
|
# gtk = {
|
||||||
|
# enable = true;
|
||||||
|
# gtk3.extraConfig = {
|
||||||
|
# gtk-theme-name = "adw-gtk3";
|
||||||
|
# };
|
||||||
|
# gtk4.extraConfig = {
|
||||||
|
# gtk-theme-name = "Adwaita";
|
||||||
|
# };
|
||||||
|
# };
|
||||||
|
|
||||||
# Set the theme with dconf
|
# Set the theme with dconf
|
||||||
dconf.settings."org/gnome/desktop/interface" = {
|
# dconf.settings."org/gnome/desktop/interface" = {
|
||||||
gtk-theme = "adw-gtk3";
|
# gtk-theme = "adw-gtk3";
|
||||||
};
|
# };
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -39,15 +39,15 @@ in
|
|||||||
programs.git = {
|
programs.git = {
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
||||||
extraConfig = {
|
settings = {
|
||||||
pull = {
|
pull = {
|
||||||
rebase = false;
|
rebase = false;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
userName = cfg.user;
|
settings.user.name = cfg.user;
|
||||||
userEmail = cfg.email;
|
settings.user.email = cfg.email;
|
||||||
ignores = cfg.ignores;
|
# ignores = cfg.ignores;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
{
|
||||||
|
lib,
|
||||||
|
config,
|
||||||
|
pkgs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
with lib;
|
||||||
|
let
|
||||||
|
cfg = config.modules.go;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
options.modules.go = {
|
||||||
|
enable = mkEnableOption "go";
|
||||||
|
};
|
||||||
|
|
||||||
|
config = mkIf cfg.enable {
|
||||||
|
# Development packages
|
||||||
|
home.packages = with pkgs; [
|
||||||
|
];
|
||||||
|
|
||||||
|
# VSCode configuration
|
||||||
|
programs.vscode = {
|
||||||
|
profiles.default = {
|
||||||
|
extensions = with pkgs.vscode-extensions; [
|
||||||
|
golang.go
|
||||||
|
|
||||||
|
];
|
||||||
|
|
||||||
|
userSettings = {
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# Neovim configuration
|
||||||
|
# programs.nixvim = {
|
||||||
|
# plugins.rustaceanvim = {
|
||||||
|
# enable = true;
|
||||||
|
# };
|
||||||
|
# };
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -18,7 +18,7 @@ in
|
|||||||
# Development packages
|
# Development packages
|
||||||
home.packages = with pkgs; [
|
home.packages = with pkgs; [
|
||||||
nix-tree
|
nix-tree
|
||||||
nixfmt-rfc-style
|
nixfmt
|
||||||
nixd
|
nixd
|
||||||
];
|
];
|
||||||
|
|
||||||
|
|||||||
@@ -9,10 +9,11 @@ with lib;
|
|||||||
let
|
let
|
||||||
cfg = config.modules.mathematica;
|
cfg = config.modules.mathematica;
|
||||||
|
|
||||||
my-mathematica = pkgs.mathematica.override {
|
my-mathematica = pkgs.mathematica.overrideAttrs (old: {
|
||||||
|
force-rebuild = "1";
|
||||||
# TODO: Just use a generic name for the installer?
|
# TODO: Just use a generic name for the installer?
|
||||||
# source = ./Wolfram_14.2.1_LIN_Bndl.sh;
|
# source = ./Wolfram_14.2.1_LIN_Bndl.sh;
|
||||||
};
|
});
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
options.modules.mathematica = {
|
options.modules.mathematica = {
|
||||||
@@ -21,6 +22,7 @@ in
|
|||||||
|
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
home.packages = [
|
home.packages = [
|
||||||
|
# pkgs.mathematica-cuda
|
||||||
my-mathematica
|
my-mathematica
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -43,6 +43,7 @@ in
|
|||||||
tomoki1207.pdf
|
tomoki1207.pdf
|
||||||
ms-vsliveshare.vsliveshare
|
ms-vsliveshare.vsliveshare
|
||||||
ms-vscode-remote.remote-ssh
|
ms-vscode-remote.remote-ssh
|
||||||
|
myriad-dreamin.tinymist
|
||||||
];
|
];
|
||||||
|
|
||||||
userSettings =
|
userSettings =
|
||||||
|
|||||||
@@ -53,5 +53,8 @@ in
|
|||||||
fzf
|
fzf
|
||||||
grc
|
grc
|
||||||
];
|
];
|
||||||
|
|
||||||
|
# Impermanence
|
||||||
|
modules.impermanence.files = [ ".local/share/fish/fish_history" ];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -24,10 +24,9 @@ in
|
|||||||
};
|
};
|
||||||
|
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
home.persistence."/persist/home/${config.home.username}" = {
|
home.persistence."/persist/home" = {
|
||||||
enable = true;
|
enable = true;
|
||||||
hideMounts = true;
|
hideMounts = true;
|
||||||
allowOther = true;
|
|
||||||
directories = cfg.directories;
|
directories = cfg.directories;
|
||||||
files = cfg.files;
|
files = cfg.files;
|
||||||
};
|
};
|
||||||
|
|||||||
+42
-36
@@ -126,8 +126,14 @@ in
|
|||||||
};
|
};
|
||||||
|
|
||||||
# Set up SSH
|
# Set up SSH
|
||||||
|
programs.ssh = {
|
||||||
|
package = pkgs.openssh_gssapi;
|
||||||
|
extraConfig = ''
|
||||||
|
GSSAPIAuthentication yes
|
||||||
|
'';
|
||||||
|
};
|
||||||
services.openssh = {
|
services.openssh = {
|
||||||
package = pkgs.opensshWithKerberos;
|
package = pkgs.openssh_gssapi;
|
||||||
settings = {
|
settings = {
|
||||||
GSSAPIAuthentication = true;
|
GSSAPIAuthentication = true;
|
||||||
GSSAPICleanupCredentials = true;
|
GSSAPICleanupCredentials = true;
|
||||||
@@ -154,30 +160,30 @@ in
|
|||||||
modules.profiles.base.enable = true;
|
modules.profiles.base.enable = true;
|
||||||
|
|
||||||
# Mount the directories from the network share
|
# Mount the directories from the network share
|
||||||
home.activation.dirMount =
|
# home.activation.dirMount =
|
||||||
let
|
# let
|
||||||
bindScript = dir: ''
|
# bindScript = dir: ''
|
||||||
mkdir -p /network/$USER/${dir}
|
# mkdir -p /network/$USER/${dir}
|
||||||
mkdir -p $HOME/${dir}
|
# mkdir -p $HOME/${dir}
|
||||||
${pkgs.bindfs}/bin/bindfs /network/$USER/${dir} $HOME/${dir}
|
# ${pkgs.bindfs}/bin/bindfs /network/$USER/${dir} $HOME/${dir}
|
||||||
'';
|
# '';
|
||||||
in
|
# in
|
||||||
lib.hm.dag.entryAfter [ "writeBoundary" ] ''
|
# lib.hm.dag.entryAfter [ "writeBoundary" ] ''
|
||||||
if ! ${pkgs.krb5}/bin/klist -s; then
|
# if ! ${pkgs.krb5}/bin/klist -s; then
|
||||||
echo "No kerberos ticket found"
|
# echo "No kerberos ticket found"
|
||||||
${pkgs.krb5}/bin/kinit
|
# ${pkgs.krb5}/bin/kinit
|
||||||
fi
|
# fi
|
||||||
|
|
||||||
if ${pkgs.krb5}/bin/klist -s; then
|
# if ${pkgs.krb5}/bin/klist -s; then
|
||||||
echo "Kerberos ticket found, mounting home directory"
|
# echo "Kerberos ticket found, mounting home directory"
|
||||||
${bindScript "Documents"}
|
# ${bindScript "Documents"}
|
||||||
${bindScript "Music"}
|
# ${bindScript "Music"}
|
||||||
${bindScript "Pictures"}
|
# ${bindScript "Pictures"}
|
||||||
${bindScript "Video"}
|
# ${bindScript "Video"}
|
||||||
else
|
# else
|
||||||
echo "Still no kerberos ticket found, skipping home directory mount"
|
# echo "Still no kerberos ticket found, skipping home directory mount"
|
||||||
fi
|
# fi
|
||||||
'';
|
# '';
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
] ++ config.home-manager.sharedModules;
|
] ++ config.home-manager.sharedModules;
|
||||||
@@ -196,17 +202,17 @@ in
|
|||||||
|
|
||||||
# Automatically mount home share
|
# Automatically mount home share
|
||||||
# Can be accessed at /network/$USER
|
# Can be accessed at /network/$USER
|
||||||
services.autofs = {
|
# services.autofs = {
|
||||||
enable = true;
|
# enable = true;
|
||||||
autoMaster =
|
# autoMaster =
|
||||||
let
|
# let
|
||||||
networkMap = pkgs.writeText "auto" ''
|
# networkMap = pkgs.writeText "auto" ''
|
||||||
* -fstype=cifs,sec=krb5,user=&,uid=$UID,gid=$GID,cruid=$UID ://${inputs.secrets.lab.nas.host}/home
|
# * -fstype=cifs,sec=krb5,user=&,uid=$UID,gid=$GID,cruid=$UID ://${inputs.secrets.lab.nas.host}/home
|
||||||
'';
|
# '';
|
||||||
in
|
# in
|
||||||
''
|
# ''
|
||||||
/network ${networkMap} --timeout=30
|
# /network ${networkMap} --timeout=30
|
||||||
'';
|
# '';
|
||||||
};
|
# };
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -20,6 +20,12 @@ in
|
|||||||
console.font = "dina";
|
console.font = "dina";
|
||||||
console.earlySetup = true;
|
console.earlySetup = true;
|
||||||
|
|
||||||
|
fonts.packages = with pkgs; [
|
||||||
|
noto-fonts
|
||||||
|
fira
|
||||||
|
jetbrains-mono
|
||||||
|
];
|
||||||
|
|
||||||
# TODO: Disable default fonts, fonts should be managed per user
|
# TODO: Disable default fonts, fonts should be managed per user
|
||||||
# fonts.enableDefaultPackages = false;
|
# fonts.enableDefaultPackages = false;
|
||||||
# fonts.fontconfig = {
|
# fonts.fontconfig = {
|
||||||
|
|||||||
+7
-20
@@ -28,31 +28,14 @@ in
|
|||||||
gnome-backgrounds
|
gnome-backgrounds
|
||||||
gnome-bluetooth
|
gnome-bluetooth
|
||||||
gnome-color-manager
|
gnome-color-manager
|
||||||
gnome-control-center
|
|
||||||
gnome-shell-extensions
|
gnome-shell-extensions
|
||||||
gnome-tour
|
gnome-tour
|
||||||
gnome-user-docs
|
gnome-user-docs
|
||||||
glib
|
glib
|
||||||
gnome-menus
|
gnome-menus
|
||||||
gtk3.out
|
gtk3.out
|
||||||
xdg-user-dirs
|
|
||||||
xdg-user-dirs-gtk
|
|
||||||
];
|
];
|
||||||
|
|
||||||
# Enable Gnome Remote Desktop
|
|
||||||
services.gnome.gnome-remote-desktop.enable = true;
|
|
||||||
systemd.services."gnome-remote-desktop".wantedBy = [ "graphical.target" ];
|
|
||||||
networking.firewall = {
|
|
||||||
allowedTCPPorts = [
|
|
||||||
3389
|
|
||||||
3390
|
|
||||||
];
|
|
||||||
allowedUDPPorts = [
|
|
||||||
3389
|
|
||||||
3390
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
# For GSConnect/KDE Connect
|
# For GSConnect/KDE Connect
|
||||||
# TODO: Move to host config?
|
# TODO: Move to host config?
|
||||||
networking.firewall = {
|
networking.firewall = {
|
||||||
@@ -71,8 +54,12 @@ in
|
|||||||
};
|
};
|
||||||
|
|
||||||
# Enable dependencies
|
# Enable dependencies
|
||||||
modules = {
|
modules.networkmanager.enable = true;
|
||||||
networkmanager.enable = true;
|
|
||||||
};
|
# Impermanence
|
||||||
|
modules.impermanence.directories = [
|
||||||
|
"/etc/NetworkManager/system-connections"
|
||||||
|
"/var/lib/bluetooth"
|
||||||
|
];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -16,7 +16,11 @@ in
|
|||||||
# TODO: Add nvidia settings back in
|
# TODO: Add nvidia settings back in
|
||||||
# TODO: Move to nvidia module
|
# TODO: Move to nvidia module
|
||||||
hardware.nvidia = {
|
hardware.nvidia = {
|
||||||
open = true;
|
open = false;
|
||||||
|
prime = {
|
||||||
|
intelBusId = "PCI:0@0:2:0";
|
||||||
|
nvidiaBusId = "PCI:1@0:0:0";
|
||||||
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -50,11 +50,32 @@ in
|
|||||||
# For testing purposes with VM
|
# For testing purposes with VM
|
||||||
virtualisation.vmVariantWithDisko.virtualisation.fileSystems."/persist".neededForBoot = true;
|
virtualisation.vmVariantWithDisko.virtualisation.fileSystems."/persist".neededForBoot = true;
|
||||||
|
|
||||||
environment.persistence."/persist/system" = {
|
environment.persistence = {
|
||||||
enable = true;
|
"/persist/system" = {
|
||||||
hideMounts = true;
|
enable = true;
|
||||||
directories = cfg.directories;
|
hideMounts = true;
|
||||||
files = cfg.files;
|
directories = cfg.directories;
|
||||||
|
files = cfg.files;
|
||||||
|
};
|
||||||
|
# "/persist/home" = {
|
||||||
|
# enable = true;
|
||||||
|
# hideMounts = true;
|
||||||
|
# users = (
|
||||||
|
# lib.mapAttrs' (
|
||||||
|
# name: value:
|
||||||
|
# let
|
||||||
|
# user = name;
|
||||||
|
# homeDir = "/home/${user}";
|
||||||
|
# impConfig = value.modules.impermanence;
|
||||||
|
# in
|
||||||
|
# lib.nameValuePair user {
|
||||||
|
# home = homeDir;
|
||||||
|
# directories = impConfig.directories;
|
||||||
|
# files = impConfig.files;
|
||||||
|
# }
|
||||||
|
# ) config.home-manager.users
|
||||||
|
# );
|
||||||
|
# };
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
|
||||||
|
with pkgs;
|
||||||
|
rustPlatform.buildRustPackage {
|
||||||
|
pname = "carla_osc_bridge";
|
||||||
|
version = "master";
|
||||||
|
|
||||||
|
src = fetchFromGitea {
|
||||||
|
domain = "git.bulthuis.dev";
|
||||||
|
owner = "Jan";
|
||||||
|
repo = "carla_osc_bridge";
|
||||||
|
rev = "c037e2d2a1b29b785d8acc10fa0cb761afdb3fcf";
|
||||||
|
hash = "sha256-Wvdfm+4dfygZwkvaUhO9w7DrrUl3ZYvtD7nYrPSD0eA=";
|
||||||
|
};
|
||||||
|
|
||||||
|
cargoHash = "sha256-s1ZKbhHudgPOy7613zbT8TkbM6B7oloLEuTYHoWjX5o=";
|
||||||
|
|
||||||
|
useFetchCargoVendor = true;
|
||||||
|
}
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
{
|
||||||
|
jq,
|
||||||
|
lib,
|
||||||
|
moreutils,
|
||||||
|
tinymist,
|
||||||
|
vscode-utils,
|
||||||
|
}:
|
||||||
|
|
||||||
|
vscode-utils.buildVscodeMarketplaceExtension {
|
||||||
|
mktplcRef = {
|
||||||
|
name = "tinymist-vscode-html";
|
||||||
|
publisher = "myriad-dreamin";
|
||||||
|
inherit (tinymist) version;
|
||||||
|
hash = "";
|
||||||
|
};
|
||||||
|
|
||||||
|
nativeBuildInputs = [
|
||||||
|
jq
|
||||||
|
moreutils
|
||||||
|
];
|
||||||
|
|
||||||
|
buildInputs = [ tinymist ];
|
||||||
|
|
||||||
|
postInstall = ''
|
||||||
|
cd "$out/$installPrefix"
|
||||||
|
jq '.contributes.configuration.properties."tinymist.serverPath".default = "${lib.getExe tinymist}"' package.json | sponge package.json
|
||||||
|
'';
|
||||||
|
|
||||||
|
meta = {
|
||||||
|
changelog = "https://marketplace.visualstudio.com/items/myriad-dreamin.tinymist/changelog";
|
||||||
|
description = "VSCode extension for providing an integration solution for Typst";
|
||||||
|
downloadPage = "https://marketplace.visualstudio.com/items?itemName=myriad-dreamin.tinymist";
|
||||||
|
homepage = "https://github.com/myriad-dreamin/tinymist";
|
||||||
|
license = lib.licenses.asl20;
|
||||||
|
maintainers = [ ];
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,104 @@
|
|||||||
|
{
|
||||||
|
lib,
|
||||||
|
buildNpmPackage,
|
||||||
|
fetchFromGitHub,
|
||||||
|
makeBinaryWrapper,
|
||||||
|
makeDesktopItem,
|
||||||
|
copyDesktopItems,
|
||||||
|
nodejs_20,
|
||||||
|
electron,
|
||||||
|
python3,
|
||||||
|
nix-update-script,
|
||||||
|
}:
|
||||||
|
|
||||||
|
buildNpmPackage rec {
|
||||||
|
pname = "open-stage-control";
|
||||||
|
version = "1.29.8";
|
||||||
|
|
||||||
|
src = fetchFromGitHub {
|
||||||
|
owner = "jean-emmanuel";
|
||||||
|
repo = "open-stage-control";
|
||||||
|
rev = "v${version}";
|
||||||
|
hash = "sha256-518KXvNffLOV2aIWlLJcnPzxEbWxYdjWeiDBC1jlecQ=";
|
||||||
|
};
|
||||||
|
|
||||||
|
# Remove some Electron stuff from package.json
|
||||||
|
postPatch = ''
|
||||||
|
sed -i -e '/"electron"\|"electron-installer-debian"/d' package.json
|
||||||
|
'';
|
||||||
|
|
||||||
|
npmDepsHash = "sha256-U4zwYL5URNW0y0W4WvWAVL0hubiiU+2z9F5mDE9l8UU=";
|
||||||
|
|
||||||
|
nodejs = nodejs_20;
|
||||||
|
|
||||||
|
nativeBuildInputs = [
|
||||||
|
copyDesktopItems
|
||||||
|
makeBinaryWrapper
|
||||||
|
];
|
||||||
|
|
||||||
|
buildInputs = [
|
||||||
|
python3.pkgs.python-rtmidi
|
||||||
|
];
|
||||||
|
|
||||||
|
doInstallCheck = true;
|
||||||
|
|
||||||
|
makeCacheWritable = true;
|
||||||
|
npmFlags = [
|
||||||
|
"--legacy-peer-deps"
|
||||||
|
"--skip-pkg"
|
||||||
|
];
|
||||||
|
|
||||||
|
# Override installPhase so we can copy the only directory that matters (app)
|
||||||
|
installPhase = ''
|
||||||
|
runHook preInstall
|
||||||
|
|
||||||
|
# copy built app and node_modules directories
|
||||||
|
mkdir -p $out/lib/node_modules/open-stage-control
|
||||||
|
cp -r app $out/lib/node_modules/open-stage-control/
|
||||||
|
|
||||||
|
# copy icon
|
||||||
|
install -Dm644 resources/images/logo.png $out/share/icons/hicolor/256x256/apps/open-stage-control.png
|
||||||
|
install -Dm644 resources/images/logo.svg $out/share/icons/hicolor/scalable/apps/open-stage-control.svg
|
||||||
|
|
||||||
|
# wrap electron and include python-rtmidi
|
||||||
|
makeWrapper '${electron}/bin/electron' $out/bin/open-stage-control \
|
||||||
|
--inherit-argv0 \
|
||||||
|
--add-flags $out/lib/node_modules/open-stage-control/app \
|
||||||
|
--prefix PYTHONPATH : "$PYTHONPATH" \
|
||||||
|
--prefix PATH : '${lib.makeBinPath [ python3 ]}'
|
||||||
|
|
||||||
|
runHook postInstall
|
||||||
|
'';
|
||||||
|
|
||||||
|
installCheckPhase = ''
|
||||||
|
XDG_CONFIG_HOME="$(mktemp -d)" $out/bin/open-stage-control --help
|
||||||
|
'';
|
||||||
|
|
||||||
|
desktopItems = [
|
||||||
|
(makeDesktopItem {
|
||||||
|
name = "open-stage-control";
|
||||||
|
exec = "open-stage-control";
|
||||||
|
icon = "open-stage-control";
|
||||||
|
desktopName = "Open Stage Control";
|
||||||
|
comment = meta.description;
|
||||||
|
categories = [
|
||||||
|
"Network"
|
||||||
|
"Audio"
|
||||||
|
"AudioVideo"
|
||||||
|
"Midi"
|
||||||
|
];
|
||||||
|
startupWMClass = "open-stage-control";
|
||||||
|
})
|
||||||
|
];
|
||||||
|
|
||||||
|
passthru.updateScript = nix-update-script { };
|
||||||
|
|
||||||
|
meta = with lib; {
|
||||||
|
description = "Libre and modular OSC / MIDI controller";
|
||||||
|
homepage = "https://openstagecontrol.ammd.net/";
|
||||||
|
license = licenses.gpl3Only;
|
||||||
|
maintainers = [ ];
|
||||||
|
platforms = platforms.linux;
|
||||||
|
mainProgram = "open-stage-control";
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,82 @@
|
|||||||
|
{
|
||||||
|
disko.devices = {
|
||||||
|
disk = {
|
||||||
|
main = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/sda";
|
||||||
|
imageSize = "32G"; # For test VMs
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
boot = {
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
mountOptions = [ "umask=0077" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
zfs = {
|
||||||
|
end = "-4G";
|
||||||
|
content = {
|
||||||
|
type = "zfs";
|
||||||
|
pool = "tank";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
swap = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "swap";
|
||||||
|
discardPolicy = "both";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
longhorn = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/sdb";
|
||||||
|
imageSize = "64G"; # For longhorn storage
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
main = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
zpool = {
|
||||||
|
tank = {
|
||||||
|
type = "zpool";
|
||||||
|
rootFsOptions = {
|
||||||
|
compression = "zstd";
|
||||||
|
};
|
||||||
|
mountpoint = null;
|
||||||
|
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
|
||||||
|
|
||||||
|
datasets = {
|
||||||
|
root = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
nix = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/nix";
|
||||||
|
};
|
||||||
|
persist = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/persist";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,65 @@
|
|||||||
|
{
|
||||||
|
disko.devices = {
|
||||||
|
disk = {
|
||||||
|
main = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/sda"; # How do I handle this for laptops
|
||||||
|
imageSize = "64G"; # For test VMs
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
boot = {
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
mountOptions = [ "umask=0077" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
zfs = {
|
||||||
|
end = "-16G";
|
||||||
|
content = {
|
||||||
|
type = "zfs";
|
||||||
|
pool = "tank";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
swap = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "swap";
|
||||||
|
discardPolicy = "both";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
zpool = {
|
||||||
|
tank = {
|
||||||
|
type = "zpool";
|
||||||
|
rootFsOptions = {
|
||||||
|
compression = "zstd";
|
||||||
|
};
|
||||||
|
mountpoint = null;
|
||||||
|
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
|
||||||
|
|
||||||
|
datasets = {
|
||||||
|
root = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
nix = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/nix";
|
||||||
|
};
|
||||||
|
persist = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/persist";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,65 @@
|
|||||||
|
{
|
||||||
|
disko.devices = {
|
||||||
|
disk = {
|
||||||
|
main = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/sda";
|
||||||
|
imageSize = "64G"; # For test VMs
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
boot = {
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
mountOptions = [ "umask=0077" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
zfs = {
|
||||||
|
end = "-16G";
|
||||||
|
content = {
|
||||||
|
type = "zfs";
|
||||||
|
pool = "tank";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
swap = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "swap";
|
||||||
|
discardPolicy = "both";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
zpool = {
|
||||||
|
tank = {
|
||||||
|
type = "zpool";
|
||||||
|
rootFsOptions = {
|
||||||
|
compression = "zstd";
|
||||||
|
};
|
||||||
|
mountpoint = null;
|
||||||
|
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
|
||||||
|
|
||||||
|
datasets = {
|
||||||
|
root = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
nix = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/nix";
|
||||||
|
};
|
||||||
|
persist = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/persist";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -16,6 +16,7 @@ in
|
|||||||
|
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
modules = {
|
modules = {
|
||||||
|
impermanence.enable = true;
|
||||||
# btop.enable = true;
|
# btop.enable = true;
|
||||||
direnv.enable = true;
|
direnv.enable = true;
|
||||||
fish.enable = true;
|
fish.enable = true;
|
||||||
|
|||||||
+55
-1
@@ -16,9 +16,63 @@ in
|
|||||||
|
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
home.packages = with pkgs; [
|
home.packages = with pkgs; [
|
||||||
firefox # TODO: Move to dediated module
|
# firefox # TODO: Move to dediated module
|
||||||
];
|
];
|
||||||
|
|
||||||
|
dconf.settings = {
|
||||||
|
"org/gnome/calendar" = {
|
||||||
|
active-view = "week";
|
||||||
|
};
|
||||||
|
"org/gnome/desktop/background" = {
|
||||||
|
picture-uri = "file://${config.home.homeDirectory}/.local/share/backgrounds/background";
|
||||||
|
};
|
||||||
|
"org/gnome/desktop/input-sources" = {
|
||||||
|
sources = [
|
||||||
|
(lib.gvariant.mkTuple [
|
||||||
|
"xkb"
|
||||||
|
"us"
|
||||||
|
])
|
||||||
|
];
|
||||||
|
xkb-options = [ "caps:escape_shifted_capslock" ];
|
||||||
|
};
|
||||||
|
"org/gnome/desktop/interface" = {
|
||||||
|
accent-color = "purple";
|
||||||
|
enable-hot-corners = false;
|
||||||
|
};
|
||||||
|
"org/gnome/desktop/peripherals/touchpad" = {
|
||||||
|
speed = 0.214;
|
||||||
|
two-finger-scrolling-enabled = true;
|
||||||
|
};
|
||||||
|
"org/gnome/mutter" = {
|
||||||
|
workspaces-only-on-primary = true;
|
||||||
|
};
|
||||||
|
"org/gnome/nautilus/icon-view" = {
|
||||||
|
default-zoom-level = "small";
|
||||||
|
};
|
||||||
|
"org/gnome/nautilus/preferences" = {
|
||||||
|
default-folder-viewer = "icon-view";
|
||||||
|
};
|
||||||
|
"org/gnome/settings-daemon/plugins/color" = {
|
||||||
|
night-light-enabled = true;
|
||||||
|
night-light-schedule-automatic = false;
|
||||||
|
night-light-schedule-from = 20.0;
|
||||||
|
night-light-schedule-to = 6.0;
|
||||||
|
night-light-temperature = 2700;
|
||||||
|
};
|
||||||
|
"org/gnome/shell" = {
|
||||||
|
disable-extension-version-validation = true;
|
||||||
|
enabled-extensions = [
|
||||||
|
"disable-workspace-animation@ethnarque"
|
||||||
|
"gsconnect@andyholmes.github.io"
|
||||||
|
"rounded-window-corners@fxgn"
|
||||||
|
"media-progress@krypion17"
|
||||||
|
"mprisLabel@moon-0xff.github.com"
|
||||||
|
"caffeube@patapon.info"
|
||||||
|
];
|
||||||
|
last-selected-power-profile = "power-saver";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
modules = {
|
modules = {
|
||||||
profiles.base.enable = true;
|
profiles.base.enable = true;
|
||||||
|
|
||||||
|
|||||||
+209
-11
@@ -1,7 +1,9 @@
|
|||||||
{
|
{
|
||||||
pkgs,
|
pkgs,
|
||||||
|
pkgs-stable,
|
||||||
lib,
|
lib,
|
||||||
config,
|
config,
|
||||||
|
inputs,
|
||||||
...
|
...
|
||||||
}:
|
}:
|
||||||
|
|
||||||
@@ -16,34 +18,229 @@ in
|
|||||||
|
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
home.packages = with pkgs; [
|
home.packages = with pkgs; [
|
||||||
libreoffice-still
|
firefox
|
||||||
|
# inputs.stable-nixpkgs.legacyPackages.${config.nixpkgs.hostPlatform}.libreoffice
|
||||||
|
libreoffice
|
||||||
remmina
|
remmina
|
||||||
thunderbird
|
thunderbird
|
||||||
signal-desktop
|
signal-desktop
|
||||||
prusa-slicer
|
prusa-slicer
|
||||||
freecad-wayland
|
pkgs-stable.freecad-wayland
|
||||||
inkscape
|
inkscape
|
||||||
ente-auth
|
# ente-auth
|
||||||
|
audacity
|
||||||
carla
|
carla
|
||||||
winbox
|
# pkgs-stable.winbox
|
||||||
whatsapp-for-linux
|
winbox4
|
||||||
|
# whatsapp-for-linux
|
||||||
|
karere
|
||||||
discord
|
discord
|
||||||
steam
|
steam
|
||||||
spotify
|
spotify
|
||||||
# feishin # TODO: Fix or replace as insecure
|
# feishin
|
||||||
eduvpn-client
|
eduvpn-client
|
||||||
river # TODO: Move
|
|
||||||
ryubing
|
ryubing
|
||||||
bottles
|
bottles
|
||||||
prismlauncher
|
prismlauncher
|
||||||
foliate
|
foliate
|
||||||
wireshark
|
wireshark
|
||||||
obsidian
|
obsidian
|
||||||
|
# devenv
|
||||||
|
# kicad
|
||||||
|
vlc
|
||||||
|
authenticator
|
||||||
|
hotspot
|
||||||
|
btop
|
||||||
|
winboat
|
||||||
|
hieroglyphic
|
||||||
|
shortwave
|
||||||
|
|
||||||
|
podman
|
||||||
|
podman-compose
|
||||||
|
|
||||||
|
gnome-network-displays
|
||||||
|
gnome-logs
|
||||||
|
];
|
||||||
|
|
||||||
|
programs.zathura = {
|
||||||
|
enable = true;
|
||||||
|
options = {
|
||||||
|
synctex = true;
|
||||||
|
synctex-editor-command = "${pkgs.texlab}/bin/texlab inverse-search -i %{input} -l %{line}";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
programs.helix = {
|
||||||
|
enable = true;
|
||||||
|
defaultEditor = true;
|
||||||
|
# settings = {
|
||||||
|
# theme = {
|
||||||
|
# light = "adwaita-light";
|
||||||
|
# dark = "adwaita-dark";
|
||||||
|
# fallback = "default";
|
||||||
|
# };
|
||||||
|
# };
|
||||||
|
settings =
|
||||||
|
let
|
||||||
|
move_line_up = [
|
||||||
|
"extend_to_line_bounds"
|
||||||
|
"delete_selection"
|
||||||
|
"move_line_up"
|
||||||
|
"paste_before"
|
||||||
|
];
|
||||||
|
move_line_down = [
|
||||||
|
"extend_to_line_bounds"
|
||||||
|
"delete_selection"
|
||||||
|
"paste_after"
|
||||||
|
];
|
||||||
|
in
|
||||||
|
{
|
||||||
|
keys.normal = {
|
||||||
|
"A-up" = move_line_up;
|
||||||
|
"A-down" = move_line_down;
|
||||||
|
"A-k" = move_line_up;
|
||||||
|
"A-j" = move_line_down;
|
||||||
|
};
|
||||||
|
keys.select = {
|
||||||
|
"A-up" = move_line_up;
|
||||||
|
"A-down" = move_line_down;
|
||||||
|
"A-k" = move_line_up;
|
||||||
|
"A-j" = move_line_down;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
extraPackages = with pkgs; [
|
||||||
|
bash-language-server # Bash
|
||||||
|
fish-lsp # Fish
|
||||||
|
systemd-lsp # Systemd
|
||||||
|
yaml-language-server # Yaml
|
||||||
|
taplo # Toml
|
||||||
|
nixd # Nix
|
||||||
|
protols # Protobuf
|
||||||
|
dockerfile-language-server # Dockerfile
|
||||||
|
docker-compose-language-service # Docker compose
|
||||||
|
|
||||||
|
clang-tools # C, C++
|
||||||
|
neocmakelsp # Cmake
|
||||||
|
rust-analyzer # Rust
|
||||||
|
lldb # C, C++, Rust
|
||||||
|
zls # Zig
|
||||||
|
|
||||||
|
texlab # Latex
|
||||||
|
tinymist # Typst
|
||||||
|
marksman # Markdown
|
||||||
|
markdown-oxide # Markdown
|
||||||
|
vscode-langservers-extracted # HTML, CSS, JSON, ESLint
|
||||||
|
typescript-language-server # Typescript, Javascript
|
||||||
|
intelephense # PHP
|
||||||
|
vue-language-server # Vue
|
||||||
|
|
||||||
|
ruff # Python
|
||||||
|
basedpyright # Python
|
||||||
|
|
||||||
|
#helix-gpt # Copilot
|
||||||
|
ltex-ls-plus # Spellchecking
|
||||||
|
|
||||||
|
# texlab # Latex, Bibtex
|
||||||
|
# bibtex-tidy # Bibtex
|
||||||
|
# docker-langserver # Dockerfile
|
||||||
|
# docker-compose-langserver # Docker compose
|
||||||
|
# elixir-ls # Elixir
|
||||||
|
# gopls # Go
|
||||||
|
# golangci-lint-langserver # Go
|
||||||
|
# dlv # Go
|
||||||
|
# haskell-language-server # Haskell
|
||||||
|
# julia # Julia
|
||||||
|
# kotlin-language-server # Kotlin
|
||||||
|
# lua-language-server # Lua
|
||||||
|
# slint-lsp # Slint
|
||||||
|
# tinymist # Typst
|
||||||
|
];
|
||||||
|
languages = {
|
||||||
|
language-server = {
|
||||||
|
ltex = {
|
||||||
|
command = "ltex-ls-plus";
|
||||||
|
config.ltex = { };
|
||||||
|
};
|
||||||
|
texlab = {
|
||||||
|
command = "texlab";
|
||||||
|
config.texlab = {
|
||||||
|
build.onSave = true;
|
||||||
|
forwardSearch.executable = "${config.programs.zathura.package}/bin/zathura";
|
||||||
|
forwardSearch.args = [
|
||||||
|
"--synctex-forward"
|
||||||
|
"%l:1:%f"
|
||||||
|
"%p"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
basedpyright = {
|
||||||
|
command = "basedpyright-langserver";
|
||||||
|
args = [ "--stdio" ];
|
||||||
|
};
|
||||||
|
tinymist = {
|
||||||
|
command = "tinymist";
|
||||||
|
config.preview.background = {
|
||||||
|
enabled = true;
|
||||||
|
args = [
|
||||||
|
"--data-plane-host=127.0.0.1:23635"
|
||||||
|
"--invert-colors=never"
|
||||||
|
"--open"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
language = [
|
||||||
|
{
|
||||||
|
name = "latex";
|
||||||
|
# language-servers = [
|
||||||
|
# { name = "texlab"; }
|
||||||
|
# { name = "ltex"; }
|
||||||
|
# ];
|
||||||
|
soft-wrap = {
|
||||||
|
enable = true;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
{
|
||||||
|
name = "python";
|
||||||
|
language-servers = [
|
||||||
|
{
|
||||||
|
name = "basedpyright";
|
||||||
|
except-features = [ "diagnostics" ];
|
||||||
|
}
|
||||||
|
"ruff"
|
||||||
|
];
|
||||||
|
auto-format = true;
|
||||||
|
formatter = {
|
||||||
|
command = "ruff";
|
||||||
|
args = [
|
||||||
|
"format"
|
||||||
|
"-"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
systemd.user.tmpfiles.rules = [
|
||||||
|
"d ${config.home.homeDirectory}/Downloads - - - - -"
|
||||||
];
|
];
|
||||||
|
|
||||||
modules = {
|
modules = {
|
||||||
profiles.gnome.enable = true;
|
profiles.gnome.enable = true;
|
||||||
|
|
||||||
|
impermanence = {
|
||||||
|
directories = [
|
||||||
|
"Code"
|
||||||
|
"Documents"
|
||||||
|
"Games"
|
||||||
|
"Models"
|
||||||
|
"Music"
|
||||||
|
"Pictures"
|
||||||
|
"Videos"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
# Gaming
|
# Gaming
|
||||||
# retroarch.enable = true;
|
# retroarch.enable = true;
|
||||||
# ryujinx.enable = true;
|
# ryujinx.enable = true;
|
||||||
@@ -65,14 +262,14 @@ in
|
|||||||
xpra = {
|
xpra = {
|
||||||
enable = true;
|
enable = true;
|
||||||
hosts = [
|
hosts = [
|
||||||
"mixer@10.20.60.251"
|
"mixer@10.20.40.100"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
# Development
|
# Development
|
||||||
# docker.enable = true;
|
# docker.enable = true;
|
||||||
# matlab.enable = true;
|
# matlab.enable = true;
|
||||||
mathematica.enable = true;
|
# mathematica.enable = true;
|
||||||
|
|
||||||
# Languages
|
# Languages
|
||||||
haskell.enable = false;
|
haskell.enable = false;
|
||||||
@@ -81,8 +278,9 @@ in
|
|||||||
rust.enable = true;
|
rust.enable = true;
|
||||||
python.enable = true;
|
python.enable = true;
|
||||||
cpp.enable = true;
|
cpp.enable = true;
|
||||||
tex.enable = true;
|
tex.enable = false;
|
||||||
jupyter.enable = false;
|
jupyter.enable = true;
|
||||||
|
go.enable = true;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
+13
-6
@@ -19,9 +19,17 @@ in
|
|||||||
bootloader.enable = mkDefault true;
|
bootloader.enable = mkDefault true;
|
||||||
ssh.enable = mkDefault true;
|
ssh.enable = mkDefault true;
|
||||||
|
|
||||||
impermanence.directories = [
|
impermanence = {
|
||||||
"/var/lib/nixos"
|
files = [
|
||||||
];
|
"/etc/machine-id"
|
||||||
|
"/etc/zfs/zpool.cache" # TODO: Move to zfs module?
|
||||||
|
];
|
||||||
|
directories = [
|
||||||
|
"/var/log/journal"
|
||||||
|
"/var/lib/nixos"
|
||||||
|
"/var/lib/systemd"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
# TODO: Remove the secrets module and use sops directly?
|
# TODO: Remove the secrets module and use sops directly?
|
||||||
secrets = {
|
secrets = {
|
||||||
@@ -45,9 +53,6 @@ in
|
|||||||
defaultEditor = true;
|
defaultEditor = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
# Allow unfree packages
|
|
||||||
nixpkgs.config.allowUnfree = true;
|
|
||||||
|
|
||||||
# Enable the usage of flakes
|
# Enable the usage of flakes
|
||||||
nix.settings.experimental-features = [
|
nix.settings.experimental-features = [
|
||||||
"nix-command"
|
"nix-command"
|
||||||
@@ -70,6 +75,8 @@ in
|
|||||||
zip
|
zip
|
||||||
unzip
|
unzip
|
||||||
tmux
|
tmux
|
||||||
|
unixtools.net-tools
|
||||||
|
tcpdump
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
+15
-4
@@ -20,7 +20,7 @@ in
|
|||||||
profiles.base.enable = true;
|
profiles.base.enable = true;
|
||||||
disko = {
|
disko = {
|
||||||
enable = true;
|
enable = true;
|
||||||
profile = "vm";
|
profile = mkDefault "vm";
|
||||||
};
|
};
|
||||||
impermanence = {
|
impermanence = {
|
||||||
enable = true;
|
enable = true;
|
||||||
@@ -49,7 +49,7 @@ in
|
|||||||
services.getty.autologinUser = "root";
|
services.getty.autologinUser = "root";
|
||||||
|
|
||||||
# Local user
|
# Local user
|
||||||
modules.secrets.secrets."passwords/local-hashed".neededForUsers = true;
|
sops.secrets."passwords/local-hashed".neededForUsers = true;
|
||||||
users.mutableUsers = false;
|
users.mutableUsers = false;
|
||||||
users.users.local = {
|
users.users.local = {
|
||||||
isNormalUser = true;
|
isNormalUser = true;
|
||||||
@@ -80,7 +80,7 @@ in
|
|||||||
# Machine platform
|
# Machine platform
|
||||||
nixpkgs.hostPlatform = "x86_64-linux";
|
nixpkgs.hostPlatform = "x86_64-linux";
|
||||||
|
|
||||||
# Set hostid for ZFS
|
# Set hostid (required for ZFS)
|
||||||
networking.hostId = "deadbeef";
|
networking.hostId = "deadbeef";
|
||||||
|
|
||||||
# Hardware configuration
|
# Hardware configuration
|
||||||
@@ -88,11 +88,22 @@ in
|
|||||||
boot.initrd.availableKernelModules = [
|
boot.initrd.availableKernelModules = [
|
||||||
"ata_piix"
|
"ata_piix"
|
||||||
"uhci_hcd"
|
"uhci_hcd"
|
||||||
|
"virtio_net"
|
||||||
"virtio_pci"
|
"virtio_pci"
|
||||||
|
"virtio_mmio"
|
||||||
|
"virtio_blk"
|
||||||
"virtio_scsi"
|
"virtio_scsi"
|
||||||
|
"9p"
|
||||||
|
"9pnet_virtio"
|
||||||
"sd_mod"
|
"sd_mod"
|
||||||
"sr_mod"
|
"sr_mod"
|
||||||
];
|
];
|
||||||
boot.kernelModules = [ "kvm-intel" ];
|
boot.kernelModules = [
|
||||||
|
"kvm-intel"
|
||||||
|
"virtio_balloon"
|
||||||
|
"virtio_console"
|
||||||
|
"virtio_rng"
|
||||||
|
"virtio_gpu"
|
||||||
|
];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
Reference in new issue
Block a user