Compare commits

...
438 Commits
Author SHA1 Message Date
Jan-Bulthuis 9d2e52675e fix: replace nixfmt-rfc-style with nixfmt 2026-05-19 12:38:40 +02:00
Jan-Bulthuis 6c5c69945a fix: use git.settings instead of git.extraConfig 2026-05-19 12:38:26 +02:00
Jan-Bulthuis 9883f3d461 fix: set forceImportRoot to false as recommended 2026-05-19 12:38:07 +02:00
Jan-Bulthuis 6d86bb8368 fix: replace wasistlos with karere 2026-05-19 12:38:07 +02:00
Jan-Bulthuis 0dbc4792d4 chore: update flake 2026-05-19 12:38:07 +02:00
Jan-Bulthuis 753b763b6f fix: use thermald on laptop 2026-05-19 12:38:07 +02:00
Jan-Bulthuis 2a690681cb feat: set up nvidia prime 2026-05-19 12:38:07 +02:00
Jan-Bulthuis 82f4a2e1d4 feat: add caffeine gnome extension 2026-05-19 12:38:07 +02:00
Jan-Bulthuis eb18897355 feat: Configure helix, install software 2026-05-19 12:11:16 +02:00
Jan-Bulthuis 00679a2c04 chore: Update flake 2026-05-19 12:10:43 +02:00
Jan-Bulthuis 8e819e01ea feat: Persist K3s cluster 2026-04-04 12:17:55 +02:00
Jan-Bulthuis cf4c179fc4 chore: Update flake 2026-04-04 12:03:33 +02:00
Jan-Bulthuis c991768cc2 chore: Update 2026-02-07 17:12:07 +01:00
Jan-Bulthuis 268879ee01 fix: Add Downloads folder fix preference for workspaces 2026-02-07 17:02:56 +01:00
Jan-Bulthuis 7e9f617965 chore: Update impermanence 2026-02-07 17:02:17 +01:00
Jan-Bulthuis 7d6482587a feat: Move to Cilium 2026-01-28 15:28:47 +01:00
Jan-Bulthuis cf10e1e963 feat: Declarative K3S node 2025-12-31 02:00:35 +01:00
Jan-Bulthuis 02b2b9cf32 fix: Git settings setup 2025-12-23 12:17:38 +01:00
Jan-Bulthuis dfe6ec5518 feat: Add typst extension 2025-12-23 12:16:46 +01:00
Jan-Bulthuis 517d793c88 fix: Add additional impermanence directories 2025-12-23 12:16:09 +01:00
Jan-Bulthuis 657a65522f feat: Declarative GNOME setup 2025-12-23 12:15:48 +01:00
Jan-Bulthuis 7bc3ab64dd feat: Install some basic fonts 2025-12-23 12:15:17 +01:00
Jan-Bulthuis 2b5cfe0934 feat: Add some GNOME packages 2025-12-23 12:15:05 +01:00
Jan-Bulthuis cf345521e8 feat: Impermanence move to bind mounts for user impermanence 2025-12-23 12:14:46 +01:00
Jan-Bulthuis f43945d0d2 bug: Add very wide initial impermanence setup 2025-12-23 12:13:59 +01:00
Jan-Bulthuis 7874412a48 fix: NetworkManager impermanence 2025-12-23 12:13:28 +01:00
Jan-Bulthuis e33a6e181e chore: Remove Helix package 2025-12-23 12:12:35 +01:00
Jan-Bulthuis 928dc4a240 feat: Add Tinymist VSCode extension 2025-12-23 12:12:22 +01:00
Jan-Bulthuis 63d34640f7 feat: Impermanence and GRD 2025-12-23 12:10:40 +01:00
Jan-Bulthuis 921565fe12 fix: Add fish history to impermanence 2025-12-23 12:08:17 +01:00
Jan-Bulthuis 88792d86db chore: Remove old configuration 2025-12-23 12:00:01 +01:00
Jan-Bulthuis 49b4ade156 chore: Update 2025-12-23 11:59:10 +01:00
Jan-Bulthuis 34f179465d feat: Finished user setup 2025-11-30 16:19:03 +01:00
Jan-Bulthuis 588bea133c feat: Set up disk layout for ws-think 2025-11-30 12:42:41 +01:00
Jan-Bulthuis 61ec61e22e fix: Disable GNOME extension version validation 2025-11-30 12:29:31 +01:00
Jan-Bulthuis 10a3de42ac chore: Install software 2025-11-30 12:29:12 +01:00
Jan-Bulthuis 6f98d674b1 fix: Improve unfree consistency 2025-11-30 12:28:52 +01:00
Jan-Bulthuis 4278ceebc1 feat: Add new laptop configuration 2025-11-30 12:28:39 +01:00
Jan-Bulthuis 3358dd324e fix: Allow unfree consistently 2025-11-30 12:27:59 +01:00
Jan-Bulthuis c3014ec109 chore: Update 2025-11-30 12:27:42 +01:00
Jan-Bulthuis 08ca6a2846 fix: Fix mathematica 2025-11-14 14:32:52 +01:00
Jan-Bulthuis 2fbe36d497 featL Add helix and osc package 2025-11-14 14:32:38 +01:00
Jan-Bulthuis 9929cd297a feat: Helix configuration 2025-11-14 14:32:20 +01:00
Jan-Bulthuis 869a219ab7 feat: Add initial carla project 2025-11-14 14:31:09 +01:00
Jan-Bulthuis af1a275dd8 feat: Add NAT64 VM 2025-11-14 14:23:18 +01:00
Jan-Bulthuis 9d302345ac fix: Remove gtk3 theme 2025-11-14 14:22:50 +01:00
Jan-Bulthuis e0b3fe191c break: Add temporary laptop configuration 2025-11-14 14:22:33 +01:00
Jan-Bulthuis d3681fcd4f feat: Switch from tayga to jool 2025-11-07 22:04:13 +01:00
Jan-Bulthuis 5458f74c83 fix: Set correct subnet for tayga 2025-11-07 21:30:13 +01:00
Jan-Bulthuis 13302deaef chore: Update flake 2025-11-07 21:16:24 +01:00
Jan-Bulthuis 828face9d5 fix: Set tayga IPv6 address 2025-11-07 21:11:35 +01:00
Jan-Bulthuis e4402eaf19 fix: Update tayga address 2025-11-07 20:47:22 +01:00
Jan-Bulthuis 081084648f Add VM for NAT64 2025-11-03 13:45:59 +01:00
Jan-Bulthuis 9d629c4656 Change home-manager to use global packages 2025-11-03 13:45:34 +01:00
Jan-Bulthuis 4a65f64a20 Update nixpkgs 2025-11-03 13:45:14 +01:00
Jan-Bulthuis d3b3e9be1c Updated flake 2025-09-26 08:28:14 +02:00
Jan-Bulthuis 5224a6e4b6 Add carla_osc_bridge package 2025-09-26 08:17:59 +02:00
Jan-Bulthuis dd0778e5f0 Make omada controller logs non-persistent 2025-09-26 08:17:39 +02:00
Jan-Bulthuis 7247fc94ab Update audio vm 2025-09-26 08:17:21 +02:00
Jan-Bulthuis 655803bd1f Add MADD as flake input 2025-09-26 08:16:40 +02:00
Jan-Bulthuis 9992039edb Set up ssh client with GSSAPI auth 2025-07-30 16:06:17 +02:00
Jan-Bulthuis f31c0f92da Installed vlc and go 2025-07-30 16:05:56 +02:00
Jan-Bulthuis 307aac4ae0 Added initial workstation disko config 2025-07-30 16:05:46 +02:00
Jan-Bulthuis 160185ef20 Remove gnome control center from system-wide install 2025-07-30 16:05:27 +02:00
Jan-Bulthuis 42619807bc Enable gnome terminal 2025-07-30 16:04:53 +02:00
Jan-Bulthuis 86c853de20 Added module for go support 2025-07-30 16:03:56 +02:00
Jan-Bulthuis f52e880b4c Opened up firewall 2025-07-23 12:25:40 +02:00
Jan-Bulthuis e157071962 Add omada user and group 2025-07-23 12:15:41 +02:00
Jan-Bulthuis d324c957be Make logs persist 2025-07-23 12:09:30 +02:00
Jan-Bulthuis 1fa6092498 Fixed ulimit argument 2025-07-23 12:06:41 +02:00
Jan-Bulthuis e43a91fe31 Run as root 2025-07-23 12:01:41 +02:00
Jan-Bulthuis f06880d6d7 Added Omada software controller to vm-oddjob 2025-07-23 10:52:23 +02:00
Jan-Bulthuis fa17ce5b03 Switched mc server to fabric 2025-07-13 16:04:16 +02:00
Jan-Bulthuis cf42666c1f Reverted delay 2025-07-05 13:29:25 +02:00
Jan-Bulthuis df49791fb7 Added delay to adcli-join 2025-07-05 13:24:44 +02:00
Jan-Bulthuis cf4a324617 Set up ssh client, temporarily removed network home mount 2025-07-05 13:05:04 +02:00
Jan-Bulthuis 66b2662030 Updated vm-minecraft 2025-07-04 19:55:22 +02:00
Jan-Bulthuis 21045c3dd1 Installed kicad 2025-07-04 19:36:25 +02:00
Jan-Bulthuis 5f68b9b1e6 Updated vm-minecraft 2025-07-04 19:34:30 +02:00
Jan-Bulthuis bb6edfdefd Updated systemd credentials for backup job 2025-06-21 18:03:38 +02:00
Jan-Bulthuis afebac0d46 Updated backup script to unmount shares 2025-06-21 17:48:16 +02:00
Jan-Bulthuis 06eaf13ec0 Limit amount of open file handles for backup job 2025-06-20 00:27:04 +02:00
Jan-Bulthuis 0b5beaf63d Updated VM-Oddjob to generically update multiple shares 2025-06-19 21:36:26 +02:00
Jan-Bulthuis 03604f9352 Updated GNOME config 2025-06-19 21:36:06 +02:00
Jan-Bulthuis 5047f1ab24 Updated secrets 2025-06-19 21:35:51 +02:00
Jan-Bulthuis 22271d33d1 Make homedir for su users 2025-06-11 17:33:55 +02:00
Jan-Bulthuis c8bf78999a Added test VM 2025-06-11 17:21:19 +02:00
Jan-Bulthuis 0d25c1deff Fixed wireguard VPNs 2025-06-11 17:13:53 +02:00
Jan-Bulthuis 3603fe28a7 Removed authorizedKeys integration from sssd 2025-06-11 14:27:16 +02:00
Jan-Bulthuis ce7c940f65 Switched to openssh package with kerberos support 2025-06-11 14:21:57 +02:00
Jan-Bulthuis d8327c3edf Updated SSH to use GSSAPI 2025-06-11 14:13:25 +02:00
Jan-Bulthuis af9f7e0ee0 Updated sssd dyndns config 2025-06-11 13:01:02 +02:00
Jan-Bulthuis 3285b483e2 Created standard local user hm config for VMs 2025-06-11 12:42:06 +02:00
Jan-Bulthuis affa333969 Moved to systemd for initrd, added integration for vmWithDisko 2025-06-11 11:58:54 +02:00
Jan-Bulthuis 3c20190709 Create additional directories 2025-06-10 03:27:46 +02:00
Jan-Bulthuis 0305b8d33a Moved to bind mounts 2025-06-10 03:23:30 +02:00
Jan-Bulthuis 5ade637e57 Included package path 2025-06-10 03:07:57 +02:00
Jan-Bulthuis 029ff0c9a3 Added link creation to activation script 2025-06-10 03:04:44 +02:00
Jan-Bulthuis db4bd8cfd9 Used persistence for mounting network folders 2025-06-10 02:37:26 +02:00
Jan-Bulthuis 41d25d9695 Updated autofs 2025-06-10 02:12:19 +02:00
Jan-Bulthuis 7e2e012f3a Changed autofs map 2025-06-10 01:56:23 +02:00
Jan-Bulthuis 071e904990 Updated autofs setup 2025-06-10 01:27:47 +02:00
Jan-Bulthuis b68ca558d8 Set up autofs 2025-06-10 01:15:50 +02:00
Jan-Bulthuis cf760b8b85 Simplified sude config 2025-06-10 00:07:58 +02:00
Jan-Bulthuis 7d4ee43283 Filter out locally defined users and groups 2025-06-10 00:07:22 +02:00
Jan-Bulthuis 4e08366901 Changed backup ID 2025-06-09 16:39:13 +02:00
Jan-Bulthuis a0ca155f7c Set backup id 2025-06-09 16:34:42 +02:00
Jan-Bulthuis 110aa4215f Added dependency on network for krb5 auth 2025-06-09 16:28:37 +02:00
Jan-Bulthuis 08a161ff0d Set up mount dependencies 2025-06-09 16:18:02 +02:00
Jan-Bulthuis f4472de631 Updated backup script 2025-06-09 16:13:25 +02:00
Jan-Bulthuis 3c154de819 Changed correct script 2025-06-09 16:00:05 +02:00
Jan-Bulthuis 709040c072 exported configuration 2025-06-09 15:55:53 +02:00
Jan-Bulthuis 28193823c8 Added backup cron job 2025-06-09 15:45:14 +02:00
Jan-Bulthuis dd25c9323d Reenabled kinit 2025-06-09 15:15:17 +02:00
Jan-Bulthuis 5796bee499 Removed unneeded dependencies 2025-06-09 15:11:13 +02:00
Jan-Bulthuis 986afe4b32 Added packages 2025-06-09 15:07:54 +02:00
Jan-Bulthuis 537e30a347 Move request-key configuration 2025-06-09 15:00:44 +02:00
Jan-Bulthuis 2fec5ead38 Use kinit from krb5 package 2025-06-09 14:28:54 +02:00
Jan-Bulthuis d4e6283c2f Added service to set up user keytab 2025-06-09 14:23:11 +02:00
Jan-Bulthuis 32e7d99292 Set up request-key.conf 2025-06-09 13:54:31 +02:00
Jan-Bulthuis d9dab5b9d3 Resource bashrc 2025-06-09 13:24:58 +02:00
Jan-Bulthuis cdd94eefb3 Enabled base profile for domain users 2025-06-09 13:06:29 +02:00
Jan-Bulthuis 209dbea02a Disable sanity checks 2025-06-09 13:01:56 +02:00
Jan-Bulthuis c683809a78 Added initial homeConfiguration for domain users 2025-06-09 12:50:30 +02:00
Jan-Bulthuis 739e335c28 Added test loginShellInit 2025-06-09 04:29:25 +02:00
Jan-Bulthuis 3c6758b343 Quick fix 2025-06-09 04:07:18 +02:00
Jan-Bulthuis 799b91a509 Update PAM 2025-06-09 04:05:52 +02:00
Jan-Bulthuis 50ff958d35 Setup strict ssh auth 2025-06-09 03:42:25 +02:00
Jan-Bulthuis ecc2779ce9 Made SSSD strict for login in PAM 2025-06-09 03:28:39 +02:00
Jan-Bulthuis 10dab81fb5 Disable PTR update 2025-06-09 03:09:14 +02:00
Jan-Bulthuis 03e96662cc Set ad_gpo_implicit_deny to true 2025-06-09 02:57:06 +02:00
Jan-Bulthuis d6d54e213e Implement SSH domain integration 2025-06-09 02:36:07 +02:00
Jan-Bulthuis f491be0ace Added sudo domain integration 2025-06-09 02:17:05 +02:00
Jan-Bulthuis fef1eff181 Simplified kerberos config 2025-06-09 01:54:39 +02:00
Jan-Bulthuis e869e5d790 Setup kerberos config 2025-06-09 01:47:48 +02:00
Jan-Bulthuis 48caacd9e5 Enforce GPO access control 2025-06-09 01:34:29 +02:00
Jan-Bulthuis ce4401033a Enabled dyndns 2025-06-08 03:45:33 +02:00
Jan-Bulthuis 8b331ad3ae Added SSSD config 2025-06-08 03:39:12 +02:00
Jan-Bulthuis 417383f89b Updated adcli script 2025-06-08 03:22:10 +02:00
Jan-Bulthuis cc75c95ad4 Moved domain config 2025-06-08 03:04:14 +02:00
Jan-Bulthuis a321251b93 Update secrets 2025-06-08 03:04:00 +02:00
Jan-Bulthuis 54677248af Installed some packages 2025-06-08 00:56:26 +02:00
Jan-Bulthuis d8f18016cd Added krb5 setup 2025-06-08 00:10:13 +02:00
Jan-Bulthuis 6522ebc15e Added krb5 as sec for smb mount 2025-06-07 23:47:20 +02:00
Jan-Bulthuis 10216784e8 Set correct hostname 2025-06-07 23:38:38 +02:00
Jan-Bulthuis f3abb6d2f3 Added samba mount 2025-06-07 23:36:21 +02:00
Jan-Bulthuis 936d654877 Added oddjob VM 2025-06-07 21:15:31 +02:00
Jan-Bulthuis 61d207db04 Installed obsidian 2025-06-07 21:15:14 +02:00
Jan-Bulthuis e7b66cb40c Added kerberos config 2025-06-07 21:14:59 +02:00
Jan-Bulthuis c9b18219af Updated secrets 2025-06-07 21:14:43 +02:00
Jan-Bulthuis d5c4a78fba Updated README.md 2025-06-07 21:14:28 +02:00
Jan-Bulthuis 369d655a38 Autologin to root for access from hypervisor 2025-05-30 16:44:23 +02:00
Jan-Bulthuis eab130b99d Removed swapfile 2025-05-30 16:38:25 +02:00
Jan-Bulthuis 5ce6b9bdf2 Added swap partition 2025-05-30 16:37:48 +02:00
Jan-Bulthuis 5db52a4f84 Removed need for password for local wheel group on VMs 2025-05-30 16:22:09 +02:00
Jan-Bulthuis 3524f6b038 Replaced key 2025-05-30 16:19:12 +02:00
Jan-Bulthuis 0cf53a97cf Restricted SSH access 2025-05-30 16:15:52 +02:00
Jan-Bulthuis 46fe5b8056 Set local password 2025-05-30 16:15:42 +02:00
Jan-Bulthuis ec3d9e6049 Updated modules 2025-05-30 16:08:51 +02:00
Jan-Bulthuis fc0476ca5a Added admin-pub secret 2025-05-30 16:08:39 +02:00
Jan-Bulthuis 4b7c62d00b Gave local passwordless sudo, rerolled and encrypted the authorized key. 2025-05-30 16:05:00 +02:00
Jan-Bulthuis cfc276184f Updated README.md 2025-05-30 15:37:19 +02:00
Jan-Bulthuis 87b50bfb4d Updated secrets 2025-05-30 15:26:05 +02:00
Jan-Bulthuis 1bc34518e1 Added deployment key to root account 2025-05-30 15:11:22 +02:00
Jan-Bulthuis f1dcb8c72b Updated sops-nix to also directly point at /persist 2025-05-30 14:35:59 +02:00
Jan-Bulthuis ec002467fa Updated secrets 2025-05-30 14:03:14 +02:00
Jan-Bulthuis 5a228cb375 Updated update script 2025-05-30 14:03:05 +02:00
Jan-Bulthuis d53e395d42 Added a module for SOPS 2025-05-30 13:56:50 +02:00
Jan-Bulthuis cb39f82a48 Updated flake.lock 2025-05-30 12:42:35 +02:00
Jan-Bulthuis 0efee5bceb Added dependency on nixos-secrets 2025-05-30 12:06:21 +02:00
Jan-Bulthuis 844118055c Updated README.md 2025-05-29 21:00:40 +02:00
Jan-Bulthuis 0ba9de0030 Set disk device for vm disko 2025-05-29 20:46:44 +02:00
Jan-Bulthuis a745b35c84 Added update script 2025-05-29 20:37:12 +02:00
Jan-Bulthuis 6c74dcbc22 Automatically login to user 2025-05-29 20:32:19 +02:00
Jan-Bulthuis 76e609372f Added persistence to ssh host keys 2025-05-29 20:28:07 +02:00
Jan-Bulthuis cd91944b1e Updated local user configuration 2025-05-29 20:20:18 +02:00
Jan-Bulthuis bebd2748d1 Moved bitwarden to a module 2025-05-29 19:23:52 +02:00
Jan 12a4ba0482 Merge pull request 'Add disko support' (#2) from disko into main
Reviewed-on: Jan/dotfiles#2
2025-05-29 16:33:31 +00:00
Jan-Bulthuis 68c241f31a Changed location of some persistence files 2025-05-29 18:32:08 +02:00
Jan-Bulthuis 81c37abadd Fixed impermanence not mounting persist 2025-05-29 17:05:15 +02:00
Jan-Bulthuis 85c962fd6d Updated REAME.md 2025-05-29 17:04:58 +02:00
Jan-Bulthuis b0a8874a93 Set up impermanence 2025-05-29 16:34:24 +02:00
Jan-Bulthuis 01021d179d Fixed hold command 2025-05-29 15:49:24 +02:00
Jan-Bulthuis b8a607c3d0 Fixed hold command 2025-05-29 15:31:46 +02:00
Jan-Bulthuis 793015646d Updated base vm config 2025-05-29 15:10:10 +02:00
Jan-Bulthuis 43f472fe88 Fixed reference to incorrect zfs pool 2025-05-29 14:36:07 +02:00
Jan-Bulthuis 51ab89cd98 Better disko setup 2025-05-29 14:19:19 +02:00
Jan-Bulthuis f0d56df191 Addid disko config for zfs 2025-05-29 13:06:13 +02:00
Jan-Bulthuis 9a97168950 Moved profiles to dedicated directory 2025-05-29 12:16:38 +02:00
Jan-Bulthuis cdffa07675 Reenable timeout 2025-05-29 09:59:09 +02:00
Jan-Bulthuis 13fbcea361 Disabled https 2025-05-28 19:26:11 +02:00
Jan-Bulthuis 36c2c907d5 Fixed tls private key file name 2025-05-28 16:46:25 +02:00
Jan-Bulthuis 11bc7221e3 Added batch flag 2025-05-28 16:39:52 +02:00
Jan-Bulthuis 3a6122784b Generate self-signed tls for wstunnel 2025-05-28 16:35:59 +02:00
Jan-Bulthuis d4338f1861 Added local to the minecraft group 2025-05-28 16:15:38 +02:00
Jan-Bulthuis ea290d9158 Install tmux 2025-05-28 16:13:49 +02:00
Jan-Bulthuis 9cc07cdfaf Created a minecraft server vm 2025-05-28 15:59:22 +02:00
Jan-Bulthuis 33b9cee6a0 Installed wireshark 2025-05-28 15:59:13 +02:00
Jan-Bulthuis 47479f40d1 Installed wireshark 2025-05-28 15:58:52 +02:00
Jan-Bulthuis e1cc2342b2 Added certificates back in 2025-05-28 14:12:00 +02:00
Jan-Bulthuis 092b3551c1 Remove tls certificates 2025-05-28 14:06:31 +02:00
Jan-Bulthuis 9d50a66388 Set up admin user 2025-05-28 13:59:30 +02:00
Jan-Bulthuis 4a644607c6 Restructured glue 2025-05-28 13:39:00 +02:00
Jan e134b3db6e Merge pull request 'Restructuring' (#1) from blueprint into main
Reviewed-on: Jan/dotfiles#1
2025-05-28 10:41:38 +00:00
Jan-Bulthuis 4cd01f17a3 Remove unorganized 2025-05-28 12:37:29 +02:00
Jan-Bulthuis e872cf3788 Changed tunnel address 2025-05-28 12:36:12 +02:00
Jan-Bulthuis f4d938073c Update 2025-05-28 12:23:48 +02:00
Jan-Bulthuis 01374fe5b0 Added vpn vm with wstunnel server 2025-05-28 12:23:31 +02:00
Jan-Bulthuis a75b839bc1 Replaced evince with papers 2025-05-28 12:22:49 +02:00
Jan-Bulthuis 8c8b6b0206 Made vm-audio buildable 2025-05-28 12:22:34 +02:00
Jan-Bulthuis 1829531f25 Fixed build issue due to home-manager not working for root for some reason 2025-05-28 12:22:07 +02:00
Jan-Bulthuis daab746b40 Fixed printing 2025-05-28 12:21:45 +02:00
Jan-Bulthuis 6c452c6649 Refactor home manager profile 2025-05-25 11:55:51 +02:00
Jan-Bulthuis 63386512a8 System update 2025-05-23 15:11:06 +02:00
Jan-Bulthuis ad8d7c8c09 Reworked DE 2025-05-18 15:01:25 +02:00
Jan-Bulthuis c37238700d Added dconf-editor and bottles 2025-05-18 15:01:14 +02:00
Jan-Bulthuis 330f5e2a50 Enabled libvirtd 2025-05-18 15:01:05 +02:00
Jan-Bulthuis fbbe869550 Reworked glue input 2025-05-18 15:00:51 +02:00
Jan-Bulthuis 5e23488cae Progress 2025-05-13 14:26:22 +02:00
Jan-Bulthuis 760815da50 Reorganized 2025-05-09 15:27:44 +02:00
Jan-Bulthuis c3c61ce654 Updated personal config 2025-05-09 15:01:50 +02:00
Jan-Bulthuis 626d78f088 Added BvA user 2025-05-09 15:01:40 +02:00
Jan-Bulthuis bcd5606107 Restarted firewall 2025-05-09 15:01:25 +02:00
Jan-Bulthuis f8fbb52607 Small change 2025-05-09 15:01:14 +02:00
Jan-Bulthuis 2b0bdb0248 Enabled grdp correctly by adding GDM 2025-05-09 15:01:07 +02:00
Jan-Bulthuis f0403330e2 Fixed package 2025-05-09 15:00:51 +02:00
Jan-Bulthuis e10079e578 Updated some theming 2025-05-09 15:00:21 +02:00
Jan-Bulthuis 2a8fcf627b Fixed some packages 2025-05-09 14:59:38 +02:00
Jan-Bulthuis 3d54536168 Set up account or programming contests 2025-05-09 14:59:11 +02:00
Jan-Bulthuis 2c0ae15417 Set controller mode 2025-04-26 14:26:19 +02:00
Jan-Bulthuis 4ed934350d Enabled JustWorksRepairing 2025-04-26 13:49:33 +02:00
Jan-Bulthuis 989ee1f6e5 Set bluez5 role 2025-04-26 13:31:01 +02:00
Jan-Bulthuis 1c9f01034e Updated BT config 2025-04-26 13:04:51 +02:00
Jan-Bulthuis f62780826b Simplified settings 2025-04-26 01:06:22 +02:00
Jan-Bulthuis 83829303b5 Further bluetooth configuration 2025-04-26 00:50:43 +02:00
Jan-Bulthuis d46d321142 Enabled bluetooth 2025-04-26 00:30:17 +02:00
Jan-Bulthuis f6442c65dd Enabled graphics 2025-04-24 17:58:04 +02:00
Jan-Bulthuis e7aac4bef4 Reordered arguments 2025-04-24 16:50:31 +02:00
Jan-Bulthuis 8799c3c943 Fix typo 2025-04-24 15:29:36 +02:00
Jan-Bulthuis 3631918db2 Simplified carla-osc setup 2025-04-24 15:24:52 +02:00
Jan-Bulthuis 180d0b3b00 Fixed issue in carla_osc_bridge 2025-04-24 15:24:12 +02:00
Jan-Bulthuis b191a3ff94 More firewall expansion 2025-04-24 14:46:34 +02:00
Jan-Bulthuis 54d8f51fb5 Updated firewall 2025-04-24 14:38:30 +02:00
Jan-Bulthuis 9089f9d936 Added carla_osc_bridge for bidirectional osc commands 2025-04-24 14:08:51 +02:00
Jan-Bulthuis cdee5ca0e8 Enabled qt 2025-04-24 10:48:17 +02:00
Jan-Bulthuis ca9757fecb Simplified setup 2025-04-23 15:13:51 +02:00
Jan-Bulthuis d516be8e29 System update 2025-04-23 14:44:20 +02:00
Jan-Bulthuis bfe15b2409 Disabled modrinth 2025-04-23 14:44:08 +02:00
Jan-Bulthuis 466fff5753 Fixed stylix vscode profile name 2025-04-23 14:44:00 +02:00
Jan-Bulthuis b965351818 Disabled non-free emulators 2025-04-23 14:21:29 +02:00
Jan-Bulthuis 7d806c7548 Removed wprsd service 2025-04-23 14:21:17 +02:00
Jan-Bulthuis c28b56fc63 Set volume 2025-04-23 14:21:07 +02:00
Jan-Bulthuis e6374ca39b Made Xpra floating in River 2025-04-22 19:42:58 +02:00
Jan-Bulthuis cd9653561c Added wireshark 2025-04-22 19:42:47 +02:00
Jan-Bulthuis 6664cce060 Enabled spotifyd autoplay 2025-04-19 10:46:36 +02:00
Jan-Bulthuis 22853f0190 Set default osc target 2025-04-19 10:46:25 +02:00
Jan-Bulthuis bc5148e601 Opened port for open-stage-control 2025-04-18 21:50:14 +02:00
Jan-Bulthuis 6b99c0f771 Added a module for Xpra 2025-04-18 21:49:36 +02:00
Jan-Bulthuis 41867fb653 Added a service for open stage control 2025-04-18 21:49:10 +02:00
Jan-Bulthuis c063cf2dac Fixed an error 2025-04-18 17:41:01 +02:00
Jan-Bulthuis 755ce711fe Added xpra setup 2025-04-18 17:34:36 +02:00
Jan-Bulthuis a6190e3bb2 Install waypipe 2025-04-18 16:30:19 +02:00
Jan-Bulthuis 5c575254a1 Supplied project file to carla 2025-04-18 15:22:40 +02:00
Jan-Bulthuis f06855c2a2 Set up firewall for Carla 2025-04-18 15:19:27 +02:00
Jan-Bulthuis 435787f440 Added a carla service 2025-04-18 15:12:08 +02:00
Jan-Bulthuis b7c1710046 Fixed some sysctl values 2025-04-18 11:59:36 +02:00
Jan-Bulthuis aac0926608 Dedicated more memory to network hardware 2025-04-18 11:57:35 +02:00
Jan-Bulthuis 8393f03b2a wprs back to default build 2025-04-18 11:57:20 +02:00
Jan-Bulthuis 26a4cba43c Moved wprs to a debug version 2025-04-18 10:22:52 +02:00
Jan-Bulthuis 102433be68 Set up xdg icons 2025-04-18 10:02:16 +02:00
Jan-Bulthuis ba3d327a1b Setup qt 2025-04-18 09:58:54 +02:00
Jan-Bulthuis a518fab421 Added xserver 2025-04-18 09:49:49 +02:00
Jan-Bulthuis 268276ceb3 Removed display manager xpra 2025-04-17 23:58:45 +02:00
Jan-Bulthuis 31f47d22d7 Enabled xserver 2025-04-17 22:31:56 +02:00
Jan-Bulthuis e6a8899c1f Added xpra 2025-04-17 22:21:05 +02:00
Jan-Bulthuis 55dc78ed46 Set spotifyd pulseaudio device name 2025-04-17 22:07:52 +02:00
Jan-Bulthuis 11245c49ce Back to new version 2025-04-17 21:52:49 +02:00
Jan-Bulthuis 6034a44d61 Went bang to older wprs version 2025-04-17 21:28:30 +02:00
Jan-Bulthuis 27dde8e40a Added some null sinks 2025-04-17 19:44:46 +02:00
Jan-Bulthuis af3984498c Made mixer user linger 2025-04-17 18:46:20 +02:00
Jan-Bulthuis 65605dbf57 Moved spotifyd to user service 2025-04-17 18:44:52 +02:00
Jan-Bulthuis d3798b201a Changed backend to pulseaudio 2025-04-17 18:40:12 +02:00
Jan-Bulthuis 74f62b34cf Changed spotifyd user to mixer, disabled mpris 2025-04-17 18:32:25 +02:00
Jan-Bulthuis 78077638fc Added spotifyd 2025-04-17 18:19:48 +02:00
Jan-Bulthuis baca029fcc Revert 2025-04-17 16:55:05 +02:00
Jan-Bulthuis ce620d3eb2 Fixed missing field 2025-04-17 16:50:36 +02:00
Jan-Bulthuis 0786e3b13c Reenabled roc with jack rule to prevent self connections 2025-04-17 16:49:03 +02:00
Jan-Bulthuis 281dbd7779 Removed roc again 2025-04-17 16:15:28 +02:00
Jan-Bulthuis 05c2c9dc30 Reverted adding latency target 2025-04-17 16:14:14 +02:00
Jan-Bulthuis 11496e21e2 Set target latency for roc 2025-04-17 16:11:40 +02:00
Jan-Bulthuis af7181e705 Reenable roc source 2025-04-17 15:30:00 +02:00
Jan-Bulthuis 7311a0f94f Cleanup 2025-04-17 15:20:50 +02:00
Jan-Bulthuis 9b0bcc56d6 Disabled roc source 2025-04-17 15:03:01 +02:00
Jan-Bulthuis 2321832fbf Updated roc configuration 2025-04-17 14:48:22 +02:00
Jan-Bulthuis dd23e88fc1 Added roc source and sink 2025-04-17 14:42:54 +02:00
Jan-Bulthuis b77bc17058 Added distrho-ports plugins 2025-04-17 13:30:03 +02:00
Jan-Bulthuis 14a8061913 Cleanup 2025-04-17 05:11:13 +02:00
Jan-Bulthuis 4168ac91d9 Added pugl to dependencies 2025-04-17 05:07:39 +02:00
Jan-Bulthuis 31360d7963 Changed some packages around 2025-04-17 04:44:03 +02:00
Jan-Bulthuis 512c7206b4 Added more plugins 2025-04-17 04:27:10 +02:00
Jan-Bulthuis cab19bedb7 Installed lsp-plugins systemwide 2025-04-17 03:52:48 +02:00
Jan-Bulthuis a580b69c40 Added dependency on lsp-plugins 2025-04-17 03:47:30 +02:00
Jan-Bulthuis d1ed464438 Added fontconfig and libx11 dependency 2025-04-17 03:36:17 +02:00
Jan-Bulthuis e16c0072a7 Fixed conflicting definition 2025-04-17 03:10:32 +02:00
Jan-Bulthuis 712c81af12 Added dependencies to path 2025-04-17 03:04:54 +02:00
Jan-Bulthuis 51e102bb39 Added some plugins to vm-audio 2025-04-17 02:17:47 +02:00
Jan-Bulthuis 13b66648fd Added wprs desktop entries 2025-04-17 02:17:38 +02:00
Jan-Bulthuis a43d2bf6b5 Added users to the audio group 2025-04-16 21:35:26 +02:00
Jan-Bulthuis 31188f0438 Removed older kernel 2025-04-16 21:16:00 +02:00
Jan-Bulthuis 0fff6a7d7d Even older kernel version 2025-04-16 20:31:29 +02:00
Jan-Bulthuis 5a97cd69e2 Changed kernel version 2025-04-16 20:28:38 +02:00
Jan-Bulthuis 18db7c616d Added rtkit for pipewire 2025-04-16 20:01:02 +02:00
Jan-Bulthuis 7c37e5d216 Moved to login shell 2025-04-16 18:33:26 +02:00
Jan-Bulthuis a7a4294195 Added path echo 2025-04-16 17:59:33 +02:00
Jan-Bulthuis a3a2616cf8 Added dependencies to path 2025-04-16 17:55:38 +02:00
Jan-Bulthuis ea95dfa0d3 Added xwayland 2025-04-16 17:50:28 +02:00
Jan-Bulthuis 5e8d66d34e Added wprs 2025-04-16 17:16:18 +02:00
Jan-Bulthuis 65b480a007 Added Carla and enable audio 2025-04-16 17:15:33 +02:00
Jan-Bulthuis d72ecc6b27 Added ssh key for mixer 2025-04-16 17:04:16 +02:00
Jan-Bulthuis db2d29131c Added path to xwayland-xdg-shell 2025-04-16 16:51:01 +02:00
Jan-Bulthuis ce9f10504a Added xwayland 2025-04-16 16:42:48 +02:00
Jan-Bulthuis f1bb1df177 Add full logs 2025-04-16 16:37:47 +02:00
Jan-Bulthuis 780cd0dfab Updated wprs 2025-04-16 16:26:49 +02:00
Jan-Bulthuis 1ddc3eae29 Added wprs for dependencies 2025-04-16 16:02:03 +02:00
Jan-Bulthuis 44878527f5 Added mixer to journal group 2025-04-16 15:58:48 +02:00
Jan-Bulthuis 21c7272015 Update wprsd service 2025-04-16 15:47:59 +02:00
Jan-Bulthuis 26c5ce5cf3 Moved wprsd to proper user service 2025-04-16 15:43:58 +02:00
Jan-Bulthuis 12c56eaac5 Fixed UID 2025-04-16 15:38:54 +02:00
Jan-Bulthuis 137b380b73 Added XDG_RUNTIME_DIR to wprsd service 2025-04-16 15:35:45 +02:00
Jan-Bulthuis 8629061724 Added group for mixer user 2025-04-16 15:24:55 +02:00
Jan-Bulthuis 16b781f11d Added wprsd service 2025-04-16 15:23:22 +02:00
Jan-Bulthuis 2e36274256 Disable some color theme settings without desktop enabled 2025-04-16 14:35:23 +02:00
Jan-Bulthuis ccdbfd81ac Added qemu guestagent 2025-04-16 14:33:15 +02:00
Jan-Bulthuis 59a16df0a3 Removed some programs 2025-04-16 14:22:09 +02:00
Jan-Bulthuis fa2413f272 Split up code to support server configuration 2025-04-16 13:54:14 +02:00
Jan-Bulthuis 6364d8afa0 Updated CSD logic 2025-04-16 13:06:16 +02:00
Jan-Bulthuis c894f00eb0 Added flatpak options 2025-04-16 13:06:09 +02:00
Jan-Bulthuis 1300acd7ce Remove wpa_supplicant_gui 2025-04-16 13:05:40 +02:00
Jan-Bulthuis 5b1022a52b Update 2025-04-16 13:05:20 +02:00
Jan-Bulthuis b9c7a4c4c7 Fixed firefox searchengine name 2025-04-16 13:05:10 +02:00
Jan-Bulthuis cdedce8d5b Renamed wpaperd 2025-04-16 13:04:20 +02:00
Jan-Bulthuis 3f6fcdc283 Fixed wireguard issue with firewall 2025-04-16 13:04:00 +02:00
Jan-Bulthuis 8738fa3066 Fixed vscode customization 2025-04-16 13:03:45 +02:00
Jan-Bulthuis 9c9fe6b18a Added gnome environment back in, fixed es-de 2025-04-16 13:02:27 +02:00
Jan-Bulthuis 885940fd69 Removed unneeded hash 2025-04-16 13:01:24 +02:00
Jan-Bulthuis f41cd9c922 Added battery state to GNOME 2025-04-16 13:01:15 +02:00
Jan-Bulthuis 2f069029e9 Moved to beta nvidia driver 2025-04-16 13:00:52 +02:00
Jan-Bulthuis bebe6eaeeb Enabled grdp and printing 2025-04-16 13:00:40 +02:00
Jan-Bulthuis 7b92e0d364 Added Jack support to pipewire 2025-04-16 13:00:30 +02:00
Jan-Bulthuis 24519ceea7 Added printing and grdp modules 2025-04-16 13:00:18 +02:00
Jan-Bulthuis a0cb0d1f44 Set default background 2025-02-27 11:18:09 +01:00
Jan-Bulthuis 4fed3712b0 Added background module for themed backgrounds 2025-02-27 11:13:47 +01:00
Jan-Bulthuis 2aa2a5ecba Fixed the system keyring 2025-02-27 11:13:33 +01:00
Jan-Bulthuis c4326f1aba Removed the use for dbus-run-session 2025-02-27 11:13:03 +01:00
Jan-Bulthuis 8b70bcb229 Removed i3 module 2025-02-27 11:12:42 +01:00
Jan-Bulthuis d2fa73f887 Modified specialisation generation slightly 2025-02-27 11:12:24 +01:00
Jan-Bulthuis 3619713bf2 Updated nixgreety 2025-02-27 11:12:01 +01:00
Jan-Bulthuis a61d63ff2c Fixed systemwide config 2025-02-27 11:11:52 +01:00
Jan-Bulthuis 8ca41a3a46 Enabled rtkit 2025-02-27 11:10:45 +01:00
Jan-Bulthuis 00ce18733e Removed wpa_supplicant line from laptop config 2025-02-27 11:10:14 +01:00
Jan-Bulthuis b5b5063065 Set up desktop environments 2025-02-23 14:53:11 +01:00
Jan-Bulthuis 1d5233512b Added cosmic desktop flake 2025-02-23 14:53:00 +01:00
Jan-Bulthuis 8858b2967c Pinned es-de reference to nixpkgs-stable 2025-02-23 14:52:46 +01:00
Jan-Bulthuis 8f2708d137 Removed unnecessary imports 2025-02-23 14:52:28 +01:00
Jan-Bulthuis f224a5efa7 Set default terminal 2025-02-23 14:52:07 +01:00
Jan-Bulthuis 63093d8a87 Progress on desktop system, added integration with nixgreety 2025-02-23 14:51:56 +01:00
Jan-Bulthuis 86b8a5571b Switched to nixgreety for greeter 2025-02-23 14:51:07 +01:00
Jan-Bulthuis 4775dac377 Added nixgreety module 2025-02-23 14:50:51 +01:00
Jan-Bulthuis 839df21c46 Added nixgreety package 2025-02-23 14:50:14 +01:00
Jan-Bulthuis 539b63cc1c Removed debug info from dina-psfu 2025-02-23 14:49:55 +01:00
Jan-Bulthuis b62640e1df Moved pipewire to base 2025-02-23 14:49:36 +01:00
Jan-Bulthuis ef385b01e8 Updated systemwide to look into specialisations 2025-02-23 14:48:54 +01:00
Jan-Bulthuis f7ea0d0c11 Added swap file 2025-02-23 14:48:32 +01:00
Jan-Bulthuis 77fc328c84 Moved desktop config 2025-02-17 15:38:32 +01:00
Jan-Bulthuis a68f032fee Moved theming modules 2025-02-17 15:06:20 +01:00
Jan-Bulthuis c6cd3018db Implement quick and dirty es-de fix 2025-02-17 14:53:20 +01:00
Jan-Bulthuis 3b6a8104bf Pass system as specialArg 2025-02-17 14:52:57 +01:00
Jan-Bulthuis ae96717720 System update 2025-02-17 13:05:27 +01:00
Jan-Bulthuis 036f619673 Rewrote systemwide system, fixed broken build 2025-02-17 12:53:45 +01:00
Jan-Bulthuis 42040403b1 Removed i3 and glpaper from personal config 2025-02-17 12:52:16 +01:00
Jan-Bulthuis 07c056b0cd Fixed package import name 2025-02-17 12:51:56 +01:00
Jan-Bulthuis d35276baeb Renamed dina-psf to dina-psfu 2025-02-17 12:51:43 +01:00
Jan-Bulthuis 07bad003ba Removed insecure package exceptions 2025-02-17 12:49:33 +01:00
Jan-Bulthuis 9a5bd2177c Reorganized desktop, simplified systemwide setup 2025-02-16 18:15:44 +01:00
Jan-Bulthuis 627c29ba9f Moved from nixos-unstable to nixpkgs-unstable 2025-02-15 16:30:07 +01:00
Jan-Bulthuis a7c8793fdd Added some more settings to vscode 2025-02-15 16:29:53 +01:00
Jan-Bulthuis 5193284380 Updated cpp module 2025-02-15 16:28:59 +01:00
Jan-Bulthuis 187b23fd64 Added mkenv script 2025-02-15 16:28:38 +01:00
Jan-Bulthuis 7080ae11af Revert "System update"
This reverts commit f98b995b80.
2025-02-12 11:56:37 +01:00
Jan-Bulthuis 0981168012 Disabled Mathematica 2025-02-12 04:09:08 +01:00
Jan-Bulthuis 135a4b76a7 Undid some work because it was not pure and hence not possible 2025-02-12 04:08:29 +01:00
Jan-Bulthuis 596494e41b Added mathematica installer 2025-02-12 04:06:53 +01:00
Jan-Bulthuis f98b995b80 System update 2025-02-12 03:37:45 +01:00
Jan-Bulthuis c44bffaeb0 Made quit action repeating 2025-02-12 03:35:09 +01:00
Jan-Bulthuis 4f4e2087b0 Updated river configuration 2025-02-12 03:32:53 +01:00
Jan-Bulthuis a04f791e06 Ly implementation 2025-02-12 03:23:49 +01:00
Jan-Bulthuis fa95171f28 Code cleanup 2025-02-12 02:18:58 +01:00
Jan-Bulthuis 4c04d14d8f Fixed dina-psf 2025-02-12 02:17:20 +01:00
Jan-Bulthuis 86f4a23831 Corrected filename 2025-02-12 00:57:09 +01:00
Jan-Bulthuis e3877111b5 Added sfm file 2025-02-12 00:54:56 +01:00
Jan-Bulthuis 2374c19a0f Added custom fontset 2025-02-12 00:40:12 +01:00
Jan-Bulthuis 5995d1ea37 Progress on dina-psf 2025-02-11 23:01:54 +01:00
Jan-Bulthuis fc5429a981 Added ly dependencies 2025-02-11 22:33:14 +01:00
Jan-Bulthuis b453a32d70 Added overlay package for ly 2025-02-11 22:28:25 +01:00
Jan-Bulthuis f94242e4b5 Removed dina-vector 2025-02-11 22:27:40 +01:00
Jan-Bulthuis 7a1dca2a96 Added ly as displaymanager 2025-02-11 22:21:52 +01:00
Jan-Bulthuis f9bf846c72 Modified font 2025-02-11 19:31:06 +01:00
Jan-Bulthuis 4400dc070f Fixed font 2025-02-11 19:30:26 +01:00
Jan-Bulthuis 555c48dc3b Removed console 2025-02-11 19:30:20 +01:00
Jan-Bulthuis 2c533f6f57 Added derivation for ttf2psf 2025-02-11 18:45:13 +01:00
Jan-Bulthuis 7bd321e3f6 Added config file for console 2025-02-11 18:15:04 +01:00
Jan-Bulthuis 1e8b56f03b Moved from overrides to overlay for custom packages 2025-02-11 16:09:01 +01:00
Jan-Bulthuis fc5a748fa5 Created dina-psf package 2025-02-11 15:48:55 +01:00
Jan-Bulthuis 1b35d92f6b Adding dina as console font 2025-02-11 13:27:35 +01:00
Jan-Bulthuis 750ca2f3a8 Added GDM 2025-02-11 12:24:10 +01:00
Jan-Bulthuis 3ae7a5e8d4 Rewrote if statement around defining LD_LIBRARY_PATH 2025-02-10 00:33:28 +01:00
Jan-Bulthuis e1d061ffbf Added libPackages 2025-02-10 00:31:08 +01:00
Jan-Bulthuis 299813134e Added clippy and rustfmt 2025-02-10 00:10:55 +01:00
Jan-Bulthuis 9287815cd2 Fixed packages 2025-02-09 23:57:47 +01:00
Jan-Bulthuis b850b164f5 Removed language installation from rust module 2025-02-09 23:53:52 +01:00
Jan-Bulthuis fcbbb03060 Added rust to devShell 2025-02-09 23:53:27 +01:00
Jan-Bulthuis f32764b652 Updated python 2025-02-09 23:45:15 +01:00
Jan-Bulthuis ba6aec06a3 Removed pkgs import 2025-02-09 02:37:50 +01:00
Jan-Bulthuis 97f69bb208 Added jupyter to devShell 2025-02-09 02:19:49 +01:00
Jan-Bulthuis e2abde8b28 Changes 2025-02-09 01:11:07 +01:00
Jan-Bulthuis f1f4255d7d Moved env to shell 2025-02-08 23:25:05 +01:00
Jan-Bulthuis 944d74060e Added env helper 2025-02-08 23:16:50 +01:00
Jan-Bulthuis ffc4e6a90b Fixed typo 2025-02-08 23:07:08 +01:00
Jan-Bulthuis 47c7b69afa Added python skeleton 2025-02-08 23:06:32 +01:00
Jan-Bulthuis 74ddbc24bb Start work on devshell configuration 2025-02-08 21:52:42 +01:00
Jan-Bulthuis 512c6066fa Added ente auth 2025-02-08 21:52:28 +01:00
Jan-Bulthuis 798d468706 Modified xfce environment 2025-02-08 21:52:04 +01:00
Jan-Bulthuis dec735c9d6 Added unfree retroarch emulators 2025-02-08 21:51:46 +01:00
Jan-Bulthuis 7776f845cc Added i3 systemwide config 2025-02-02 14:23:37 +01:00
Jan-Bulthuis 6072b9fdd2 Added i3 2025-02-02 14:09:09 +01:00
Jan-Bulthuis c832f5ff72 Allowed mathematica as unfree package 2025-01-30 19:06:49 +01:00
Jan-Bulthuis 030c41f7a0 Added mathematica 2025-01-30 19:05:44 +01:00
Jan-Bulthuis 02e5532cb3 removed folder 2025-01-29 16:50:17 +01:00
170 changed files with 4189 additions and 5558 deletions

No files matched your search

+37 -2
View File
@@ -2,6 +2,41 @@
My NixOS configuration. My NixOS configuration.
## Usage ## Installation
Clone the repository to some directory. And build with `sudo nixos-rebuild switch --flake /directory/containing/flake.nix/`. For disk configuration we use disko, but for secrets management we use sops-nix and the particular setup makes the installation process a bit more involved. It is required that the computer from which the installation is being run has access to the `nixos-secrets` repository, otherwise you will need to manually add the required ssh keys to the installation image.
```bash
# Load into the installer
sudo passwd # Set a root password
# From a machine with network access to the installer
# and access to the nixos-secrets repo
ssh -A root@(installer-ip)
# Set up disks
nix-shell -p disko
disko --mode disko --flake git+https://git.bulthuis.dev/Jan/nixos-config#(system)
exit
# Install NixOS
nixos-install --no-channel-copy --no-root-password --flake git+https://git.bulthuis.dev/Jan/nixos-config#(system)
# Set up host credentials for access to the secrets
cd /mnt/persist/system/etc/sops
touch sops_ed25519_key
chmod 600 sops_ed25519_key
nano sops_ed25519_key
```
If `nixos-install` is being stopped by the OOM-killer, you can try adding `-j 1` to limit the amount of jobs that will be executed at the same time to 1. It might require running nixos-install multiple times untill it has managed to download all requirements and slowly start building the rest of the system.
## Updating
To update the system configuration, it is a single command:
```bash
sudo system-update
```
Or if this shell script has not been installed for some reason:
```bash
sudo nixos-rebuild switch --flake git+https://git.bulthuis.dev/Jan/nixos-config
```
Sometimes it may be necessary to reboot of course.
-11
View File
@@ -1,11 +0,0 @@
{ ... }:
{
imports = [
# Import modules
./modules/default.nix
# Import custom packages
./pkgs/default.nix
];
}
Submodule dotfiles deleted from 9d73b0d728.
Generated
+71 -688
View File
@@ -1,361 +1,22 @@
{ {
"nodes": { "nodes": {
"base16": { "disko": {
"inputs": {
"fromYaml": "fromYaml"
},
"locked": {
"lastModified": 1732200724,
"narHash": "sha256-+R1BH5wHhfnycySb7Sy5KbYEaTJZWm1h+LW1OtyhiTs=",
"owner": "SenchoPens",
"repo": "base16.nix",
"rev": "153d52373b0fb2d343592871009a286ec8837aec",
"type": "github"
},
"original": {
"owner": "SenchoPens",
"repo": "base16.nix",
"type": "github"
}
},
"base16-fish": {
"flake": false,
"locked": {
"lastModified": 1622559957,
"narHash": "sha256-PebymhVYbL8trDVVXxCvZgc0S5VxI7I1Hv4RMSquTpA=",
"owner": "tomyun",
"repo": "base16-fish",
"rev": "2f6dd973a9075dabccd26f1cded09508180bf5fe",
"type": "github"
},
"original": {
"owner": "tomyun",
"repo": "base16-fish",
"type": "github"
}
},
"base16-helix": {
"flake": false,
"locked": {
"lastModified": 1736852337,
"narHash": "sha256-esD42YdgLlEh7koBrSqcT7p2fsMctPAcGl/+2sYJa2o=",
"owner": "tinted-theming",
"repo": "base16-helix",
"rev": "03860521c40b0b9c04818f2218d9cc9efc21e7a5",
"type": "github"
},
"original": {
"owner": "tinted-theming",
"repo": "base16-helix",
"type": "github"
}
},
"base16-vim": {
"flake": false,
"locked": {
"lastModified": 1735953590,
"narHash": "sha256-YbQwaApLFJobn/0lbpMKcJ8N5axKlW2QIGkDS5+xoSU=",
"owner": "tinted-theming",
"repo": "base16-vim",
"rev": "c2a1232aa2c0ed27dcbf005779bcfe0e0ab5e85d",
"type": "github"
},
"original": {
"owner": "tinted-theming",
"repo": "base16-vim",
"type": "github"
}
},
"devshell": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
"nixvim",
"nixpkgs" "nixpkgs"
] ]
}, },
"locked": { "locked": {
"lastModified": 1735644329, "lastModified": 1779135526,
"narHash": "sha256-tO3HrHriyLvipc4xr+Ewtdlo7wM1OjXNjlWRgmM7peY=", "narHash": "sha256-glCununz6lmaK5fs2X946HA3EkNxB2JagdAAvInuRYU=",
"owner": "numtide", "owner": "nix-community",
"repo": "devshell", "repo": "disko",
"rev": "f7795ede5b02664b57035b3b757876703e2c3eac", "rev": "d405a179887d52b24c0ddd31e09a150bd1f66779",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "numtide", "owner": "nix-community",
"repo": "devshell", "repo": "disko",
"type": "github"
}
},
"firefox-gnome-theme": {
"flake": false,
"locked": {
"lastModified": 1736899990,
"narHash": "sha256-S79Hqn2EtSxU4kp99t8tRschSifWD4p/51++0xNWUxw=",
"owner": "rafaelmardojai",
"repo": "firefox-gnome-theme",
"rev": "91ca1f82d717b02ceb03a3f423cbe8082ebbb26d",
"type": "github"
},
"original": {
"owner": "rafaelmardojai",
"repo": "firefox-gnome-theme",
"type": "github"
}
},
"flake-compat": {
"flake": false,
"locked": {
"lastModified": 1733328505,
"narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-compat_2": {
"locked": {
"lastModified": 1733328505,
"narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=",
"rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec",
"revCount": 69,
"type": "tarball",
"url": "https://api.flakehub.com/f/pinned/edolstra/flake-compat/1.1.0/01948eb7-9cba-704f-bbf3-3fa956735b52/source.tar.gz"
},
"original": {
"type": "tarball",
"url": "https://flakehub.com/f/edolstra/flake-compat/1.tar.gz"
}
},
"flake-compat_3": {
"flake": false,
"locked": {
"lastModified": 1733328505,
"narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-parts": {
"inputs": {
"nixpkgs-lib": [
"nixvim",
"nixpkgs"
]
},
"locked": {
"lastModified": 1736143030,
"narHash": "sha256-+hu54pAoLDEZT9pjHlqL9DNzWz0NbUn8NEAHP7PQPzU=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "b905f6fc23a9051a6e1b741e1438dbfc0634c6de",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "flake-parts",
"type": "github"
}
},
"flake-parts_2": {
"inputs": {
"nixpkgs-lib": [
"nur",
"nixpkgs"
]
},
"locked": {
"lastModified": 1733312601,
"narHash": "sha256-4pDvzqnegAfRkPwO3wmwBhVi/Sye1mzps0zHWYnP88c=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "205b12d8b7cd4802fbcb8e8ef6a0f1408781a4f9",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "flake-parts",
"type": "github"
}
},
"flake-utils": {
"inputs": {
"systems": "systems"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"flake-utils_2": {
"inputs": {
"systems": [
"stylix",
"systems"
]
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"fromYaml": {
"flake": false,
"locked": {
"lastModified": 1731966426,
"narHash": "sha256-lq95WydhbUTWig/JpqiB7oViTcHFP8Lv41IGtayokA8=",
"owner": "SenchoPens",
"repo": "fromYaml",
"rev": "106af9e2f715e2d828df706c386a685698f3223b",
"type": "github"
},
"original": {
"owner": "SenchoPens",
"repo": "fromYaml",
"type": "github"
}
},
"git-hooks": {
"inputs": {
"flake-compat": [
"nixvim",
"flake-compat"
],
"gitignore": "gitignore",
"nixpkgs": [
"nixvim",
"nixpkgs"
]
},
"locked": {
"lastModified": 1737465171,
"narHash": "sha256-R10v2hoJRLq8jcL4syVFag7nIGE7m13qO48wRIukWNg=",
"owner": "cachix",
"repo": "git-hooks.nix",
"rev": "9364dc02281ce2d37a1f55b6e51f7c0f65a75f17",
"type": "github"
},
"original": {
"owner": "cachix",
"repo": "git-hooks.nix",
"type": "github"
}
},
"git-hooks_2": {
"inputs": {
"flake-compat": [
"stylix",
"flake-compat"
],
"gitignore": "gitignore_2",
"nixpkgs": [
"stylix",
"nixpkgs"
]
},
"locked": {
"lastModified": 1735882644,
"narHash": "sha256-3FZAG+pGt3OElQjesCAWeMkQ7C/nB1oTHLRQ8ceP110=",
"owner": "cachix",
"repo": "git-hooks.nix",
"rev": "a5a961387e75ae44cc20f0a57ae463da5e959656",
"type": "github"
},
"original": {
"owner": "cachix",
"repo": "git-hooks.nix",
"type": "github"
}
},
"gitignore": {
"inputs": {
"nixpkgs": [
"nixvim",
"git-hooks",
"nixpkgs"
]
},
"locked": {
"lastModified": 1709087332,
"narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=",
"owner": "hercules-ci",
"repo": "gitignore.nix",
"rev": "637db329424fd7e46cf4185293b9cc8c88c95394",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "gitignore.nix",
"type": "github"
}
},
"gitignore_2": {
"inputs": {
"nixpkgs": [
"stylix",
"git-hooks",
"nixpkgs"
]
},
"locked": {
"lastModified": 1709087332,
"narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=",
"owner": "hercules-ci",
"repo": "gitignore.nix",
"rev": "637db329424fd7e46cf4185293b9cc8c88c95394",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "gitignore.nix",
"type": "github"
}
},
"gnome-shell": {
"flake": false,
"locked": {
"lastModified": 1732369855,
"narHash": "sha256-JhUWbcYPjHO3Xs3x9/Z9RuqXbcp5yhPluGjwsdE2GMg=",
"owner": "GNOME",
"repo": "gnome-shell",
"rev": "dadd58f630eeea41d645ee225a63f719390829dc",
"type": "github"
},
"original": {
"owner": "GNOME",
"ref": "47.2",
"repo": "gnome-shell",
"type": "github" "type": "github"
} }
}, },
@@ -366,11 +27,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1737762889, "lastModified": 1779157263,
"narHash": "sha256-5HGG09bh/Yx0JA8wtBMAzt0HMCL1bYZ93x4IqzVExio=", "narHash": "sha256-VbiyZkRf8/qr7ObmlyfOHJsNAW5tyZ4MB1+cUwAwdrw=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "daf04c5950b676f47a794300657f1d3d14c1a120", "rev": "866412a19866b4a8e32d2306a118040afa2b840c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -382,16 +43,16 @@
"home-manager_2": { "home-manager_2": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
"nixvim", "impermanence",
"nixpkgs" "nixpkgs"
] ]
}, },
"locked": { "locked": {
"lastModified": 1737762889, "lastModified": 1768598210,
"narHash": "sha256-5HGG09bh/Yx0JA8wtBMAzt0HMCL1bYZ93x4IqzVExio=", "narHash": "sha256-kkgA32s/f4jaa4UG+2f8C225Qvclxnqs76mf8zvTVPg=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "daf04c5950b676f47a794300657f1d3d14c1a120", "rev": "c47b2cc64a629f8e075de52e4742de688f930dc6",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -400,104 +61,32 @@
"type": "github" "type": "github"
} }
}, },
"home-manager_3": { "impermanence": {
"inputs": { "inputs": {
"nixpkgs": [ "home-manager": "home-manager_2",
"stylix", "nixpkgs": "nixpkgs"
"nixpkgs"
]
}, },
"locked": { "locked": {
"lastModified": 1736785676, "lastModified": 1769548169,
"narHash": "sha256-TY0jUwR3EW0fnS0X5wXMAVy6h4Z7Y6a3m+Yq++C9AyE=", "narHash": "sha256-03+JxvzmfwRu+5JafM0DLbxgHttOQZkUtDWBmeUkN8Y=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "impermanence",
"rev": "fc52a210b60f2f52c74eac41a8647c1573d2071d", "rev": "7b1d382faf603b6d264f58627330f9faa5cba149",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "impermanence",
"type": "github" "type": "github"
} }
}, },
"ixx": {
"inputs": {
"flake-utils": [
"nixvim",
"nuschtosSearch",
"flake-utils"
],
"nixpkgs": [
"nixvim",
"nuschtosSearch",
"nixpkgs"
]
},
"locked": {
"lastModified": 1729958008,
"narHash": "sha256-EiOq8jF4Z/zQe0QYVc3+qSKxRK//CFHMB84aYrYGwEs=",
"owner": "NuschtOS",
"repo": "ixx",
"rev": "9fd01aad037f345350eab2cd45e1946cc66da4eb",
"type": "github"
},
"original": {
"owner": "NuschtOS",
"ref": "v0.0.6",
"repo": "ixx",
"type": "github"
}
},
"nix-darwin": {
"inputs": {
"nixpkgs": [
"nixvim",
"nixpkgs"
]
},
"locked": {
"lastModified": 1737504076,
"narHash": "sha256-/B4XJnzYU/6K1ZZOBIgsa3K4pqDJrnC2579c44c+4rI=",
"owner": "lnl7",
"repo": "nix-darwin",
"rev": "65cc1fa8e36ceff067daf6cfb142331f02f524d3",
"type": "github"
},
"original": {
"owner": "lnl7",
"repo": "nix-darwin",
"type": "github"
}
},
"nix-matlab": {
"inputs": {
"flake-compat": "flake-compat",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1737840943,
"narHash": "sha256-64j4mytkcPjd+k8KwDRzti/mc5cOJgY/LeOxbAykoag=",
"owner": "doronbehar",
"repo": "nix-matlab",
"rev": "4151ee1768ae1842f3505c0927eefbc977fcf046",
"type": "gitlab"
},
"original": {
"owner": "doronbehar",
"repo": "nix-matlab",
"type": "gitlab"
}
},
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1737746512, "lastModified": 1768564909,
"narHash": "sha256-nU6AezEX4EuahTO1YopzueAXfjFfmCHylYEFCagduHU=", "narHash": "sha256-Kell/SpJYVkHWMvnhqJz/8DqQg2b6PguxVWOuadbHCc=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "825479c345a7f806485b7f00dbe3abb50641b083", "rev": "e4bae1bd10c9c57b2cf517953ab70060a828ee6f",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -507,287 +96,81 @@
"type": "github" "type": "github"
} }
}, },
"nixpkgs-stable": {
"locked": {
"lastModified": 1767313136,
"narHash": "sha256-16KkgfdYqjaeRGBaYsNrhPRRENs0qzkQVUooNHtoy2w=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "ac62194c3917d5f474c1a844b6fd6da2db95077d",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixos-25.05",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_2": { "nixpkgs_2": {
"locked": { "locked": {
"lastModified": 1737717945, "lastModified": 1778869304,
"narHash": "sha256-ET91TMkab3PmOZnqiJQYOtSGvSTvGeHoegAv4zcTefM=", "narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=",
"owner": "NixOS", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "ecd26a469ac56357fd333946a99086e992452b6a", "rev": "d233902339c02a9c334e7e593de68855ad26c4cb",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "NixOS", "owner": "nixos",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_3": {
"locked": {
"lastModified": 1736798957,
"narHash": "sha256-qwpCtZhSsSNQtK4xYGzMiyEDhkNzOCz/Vfu4oL2ETsQ=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "9abb87b552b7f55ac8916b6fc9e5cb486656a2f3",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable", "ref": "nixos-unstable",
"repo": "nixpkgs", "repo": "nixpkgs",
"type": "github" "type": "github"
} }
}, },
"nixvim": {
"inputs": {
"devshell": "devshell",
"flake-compat": "flake-compat_2",
"flake-parts": "flake-parts",
"git-hooks": "git-hooks",
"home-manager": "home-manager_2",
"nix-darwin": "nix-darwin",
"nixpkgs": "nixpkgs_2",
"nuschtosSearch": "nuschtosSearch",
"treefmt-nix": "treefmt-nix"
},
"locked": {
"lastModified": 1737832569,
"narHash": "sha256-VkK73VRVgvSQOPw9qx9HzvbulvUM9Ae4nNd3xNP+pkI=",
"owner": "nix-community",
"repo": "nixvim",
"rev": "d7df58321110d3b0e12a829bbd110db31ccd34b1",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nixvim",
"type": "github"
}
},
"nur": {
"inputs": {
"flake-parts": "flake-parts_2",
"nixpkgs": [
"nixpkgs"
],
"treefmt-nix": "treefmt-nix_2"
},
"locked": {
"lastModified": 1737897819,
"narHash": "sha256-oVr0st3IHSgIPLDCoDtbI/TiLcMqs85KGBfLqFV3xQU=",
"owner": "nix-community",
"repo": "NUR",
"rev": "ee6e560d3cbfdbb2d92d1d95c83aaa434ed42dc5",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "NUR",
"type": "github"
}
},
"nuschtosSearch": {
"inputs": {
"flake-utils": "flake-utils",
"ixx": "ixx",
"nixpkgs": [
"nixvim",
"nixpkgs"
]
},
"locked": {
"lastModified": 1737372689,
"narHash": "sha256-nH3zK2ki0fd5o5qvbGHxukE4qnOLJa1uCzoDObG5vrE=",
"owner": "NuschtOS",
"repo": "search",
"rev": "570cc17bbc25650eb7d69e4fcda8cfd2f1656922",
"type": "github"
},
"original": {
"owner": "NuschtOS",
"repo": "search",
"type": "github"
}
},
"root": { "root": {
"inputs": { "inputs": {
"disko": "disko",
"home-manager": "home-manager", "home-manager": "home-manager",
"nix-matlab": "nix-matlab", "impermanence": "impermanence",
"nixpkgs": "nixpkgs", "nixpkgs": "nixpkgs_2",
"nixvim": "nixvim", "nixpkgs-stable": "nixpkgs-stable",
"nur": "nur", "secrets": "secrets",
"stylix": "stylix" "sops-nix": "sops-nix"
} }
}, },
"stylix": { "secrets": {
"inputs": {
"base16": "base16",
"base16-fish": "base16-fish",
"base16-helix": "base16-helix",
"base16-vim": "base16-vim",
"firefox-gnome-theme": "firefox-gnome-theme",
"flake-compat": "flake-compat_3",
"flake-utils": "flake-utils_2",
"git-hooks": "git-hooks_2",
"gnome-shell": "gnome-shell",
"home-manager": "home-manager_3",
"nixpkgs": "nixpkgs_3",
"systems": "systems_2",
"tinted-foot": "tinted-foot",
"tinted-kitty": "tinted-kitty",
"tinted-tmux": "tinted-tmux",
"tinted-zed": "tinted-zed"
},
"locked": { "locked": {
"lastModified": 1737861120, "lastModified": 1766822527,
"narHash": "sha256-V/GWU1BQwbxyZif9RBvwn10S1KX+86uPkkI41KQEcQQ=", "narHash": "sha256-0qNxAxr7LQ8C6MjSxV2FkMSfdVmOVRq7Yz/wCea8plo=",
"owner": "danth", "ref": "refs/heads/main",
"repo": "stylix", "rev": "695e36891b5de248993845e1435df5e4116a26f2",
"rev": "d6951d0b2ffe74e4779a180e9b6a0e17627756e1", "revCount": 21,
"type": "github" "type": "git",
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
}, },
"original": { "original": {
"owner": "danth", "type": "git",
"repo": "stylix", "url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
"type": "github"
} }
}, },
"systems": { "sops-nix": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"systems_2": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"tinted-foot": {
"flake": false,
"locked": {
"lastModified": 1726913040,
"narHash": "sha256-+eDZPkw7efMNUf3/Pv0EmsidqdwNJ1TaOum6k7lngDQ=",
"owner": "tinted-theming",
"repo": "tinted-foot",
"rev": "fd1b924b6c45c3e4465e8a849e67ea82933fcbe4",
"type": "github"
},
"original": {
"owner": "tinted-theming",
"repo": "tinted-foot",
"rev": "fd1b924b6c45c3e4465e8a849e67ea82933fcbe4",
"type": "github"
}
},
"tinted-kitty": {
"flake": false,
"locked": {
"lastModified": 1716423189,
"narHash": "sha256-2xF3sH7UIwegn+2gKzMpFi3pk5DlIlM18+vj17Uf82U=",
"owner": "tinted-theming",
"repo": "tinted-kitty",
"rev": "eb39e141db14baef052893285df9f266df041ff8",
"type": "github"
},
"original": {
"owner": "tinted-theming",
"repo": "tinted-kitty",
"rev": "eb39e141db14baef052893285df9f266df041ff8",
"type": "github"
}
},
"tinted-tmux": {
"flake": false,
"locked": {
"lastModified": 1735737224,
"narHash": "sha256-FO2hRBkZsjlIRqzNHCPc/52yxg11kHGA8MEtSun9RwE=",
"owner": "tinted-theming",
"repo": "tinted-tmux",
"rev": "aead506a9930c717ebf81cc83a2126e9ca08fa64",
"type": "github"
},
"original": {
"owner": "tinted-theming",
"repo": "tinted-tmux",
"type": "github"
}
},
"tinted-zed": {
"flake": false,
"locked": {
"lastModified": 1725758778,
"narHash": "sha256-8P1b6mJWyYcu36WRlSVbuj575QWIFZALZMTg5ID/sM4=",
"owner": "tinted-theming",
"repo": "base16-zed",
"rev": "122c9e5c0e6f27211361a04fae92df97940eccf9",
"type": "github"
},
"original": {
"owner": "tinted-theming",
"repo": "base16-zed",
"type": "github"
}
},
"treefmt-nix": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
"nixvim",
"nixpkgs" "nixpkgs"
] ]
}, },
"locked": { "locked": {
"lastModified": 1737483750, "lastModified": 1777944972,
"narHash": "sha256-5An1wq5U8sNycOBBg3nsDDgpwBmR9liOpDGlhliA6Xo=", "narHash": "sha256-VfGRo1qTBKOe3s2gOv8LSoA6Fk19PvBlwQ1ECN0Evn8=",
"owner": "numtide", "owner": "Mic92",
"repo": "treefmt-nix", "repo": "sops-nix",
"rev": "f2cc121df15418d028a59c9737d38e3a90fbaf8f", "rev": "c591bf665727040c6cc5cb409079acb22dcce33c",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "numtide", "owner": "Mic92",
"repo": "treefmt-nix", "repo": "sops-nix",
"type": "github"
}
},
"treefmt-nix_2": {
"inputs": {
"nixpkgs": [
"nur",
"nixpkgs"
]
},
"locked": {
"lastModified": 1733222881,
"narHash": "sha256-JIPcz1PrpXUCbaccEnrcUS8jjEb/1vJbZz5KkobyFdM=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "49717b5af6f80172275d47a418c9719a31a78b53",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "treefmt-nix",
"type": "github" "type": "github"
} }
} }
+29 -62
View File
@@ -1,71 +1,38 @@
{ {
description = "NixOS system"; description = "System configuration for NixOS";
inputs = { inputs = {
# General inputs
nixpkgs-stable.url = "github:nixos/nixpkgs/nixos-25.05";
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable"; nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
home-manager = { home-manager.url = "github:nix-community/home-manager";
url = "github:nix-community/home-manager"; home-manager.inputs.nixpkgs.follows = "nixpkgs";
inputs.nixpkgs.follows = "nixpkgs";
}; # Secrets
stylix.url = "github:danth/stylix"; sops-nix.url = "github:Mic92/sops-nix";
nixvim.url = "github:nix-community/nixvim"; sops-nix.inputs.nixpkgs.follows = "nixpkgs";
nur = { secrets.url = "git+ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets";
url = "github:nix-community/NUR";
inputs.nixpkgs.follows = "nixpkgs"; # Disk setup
}; disko.url = "github:nix-community/disko";
nix-matlab = { disko.inputs.nixpkgs.follows = "nixpkgs";
url = "gitlab:doronbehar/nix-matlab"; impermanence.url = "github:nix-community/impermanence";
inputs.nixpkgs.follows = "nixpkgs";
}; # MADD
# madd.url = "git+https://git.bulthuis.dev/Jan/madd";
# madd.inputs.nixpkgs.follows = "nixpkgs";
# For Minecraft VM
# nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
# nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
# nix-modpack.url = "github:Jan-Bulthuis/nix-modpack";
# nix-modpack.inputs.nixpkgs.follows = "nixpkgs";
}; };
outputs = outputs =
{ inputs:
nixpkgs, import ./glue {
home-manager, inherit inputs;
stylix, excludeHomeManagerModules = [ "impermanence" ];
nixvim,
nur,
nix-matlab,
...
}:
let
makeConfig =
machineConfig: userConfig:
(nixpkgs.lib.nixosSystem {
system = "x86_64-linux";
modules = [
machineConfig
home-manager.nixosModules.home-manager
{
machine.users = userConfig;
home-manager.sharedModules = [
stylix.homeManagerModules.stylix
nixvim.homeManagerModules.nixvim
nur.modules.homeManager.default
{
# TODO: Remove insecure package exception
nixpkgs.config.permittedInsecurePackages = [
"freeimage-unstable-2021-11-01" # For emulation station
"electron-31.7.7" # For feishin
];
nixpkgs.overlays = [
nix-matlab.overlay
];
}
];
}
];
});
in
{
nixosConfigurations = {
"20212060" = makeConfig ./machines/laptop.nix {
jan = {
sudo = true;
configuration = ./users/jan.nix;
};
};
};
}; };
} }
+199
View File
@@ -0,0 +1,199 @@
{
inputs,
excludeHomeManagerModules ? [ ],
}:
let
flake = inputs.self;
nixpkgs = inputs.nixpkgs;
lib = nixpkgs.lib;
nixpkgs-config = {
allowUnfree = true;
};
importDir =
path: fn:
let
entries = builtins.readDir path;
# Get paths to directories
dirs = lib.filterAttrs (_: type: type == "directory") entries;
dirPaths = lib.mapAttrs (name: type: {
path = "${path}/${name}";
type = type;
}) dirs;
# Get paths to nix files
nixName = name: builtins.match "(.*)\\.nix" name;
files = lib.filterAttrs (name: type: (type != "directory") && ((nixName name) != null)) entries;
filePaths = lib.mapAttrs' (name: type: {
name = builtins.head (nixName name);
value = {
path = "${path}/${name}";
type = type;
};
}) files;
combined = dirPaths // filePaths;
in
fn (lib.optionalAttrs (builtins.pathExists path) combined);
# Split out into getNixFiles, getNixFilesRecursive, getDirs
importDirRecursive =
path: fn:
let
entries = importDir path lib.id;
# Dig down recursively
dirs = lib.filterAttrs (_: entry: entry.type == "directory") entries;
recursedEntries = lib.mapAttrs (name: entry: (importDirRecursive entry.path lib.id)) dirs;
in
fn (entries // recursedEntries);
eachSystem = fn: lib.genAttrs lib.systems.flakeExposed fn;
systemArgs = eachSystem (system: {
pkgs = (
import inputs.nixpkgs {
inherit system;
config = nixpkgs-config;
}
);
stable-pkgs = (
import inputs.nixpkgs-stable {
inherit system;
config = nixpkgs-config;
}
);
});
allPackages = importDir "${flake}/packages" (
attrs:
lib.mapAttrs (
name: entry: (if entry.type == "directory" then "${entry.path}/default.nix" else entry.path)
) attrs
);
packages =
let
# TODO: Filter out packages that are not supported on the platform?
mkPackages =
system:
let
args = systemArgs."${system}";
pkgs = args.pkgs;
in
lib.mapAttrs (name: package: pkgs.callPackage package { }) allPackages;
in
eachSystem mkPackages;
overlay = final: prev: (lib.mapAttrs (name: package: prev.callPackage package { }) allPackages);
collectEntries =
attrs:
lib.attrsets.collect (
entry: (lib.isAttrs entry) && (lib.hasAttr "path" entry) && (lib.hasAttr "type" entry)
) attrs;
collectModules =
path:
importDirRecursive path (
attrs:
map (entry: if entry.type == "directory" then entry.path + "/default.nix" else entry.path) (
collectEntries attrs
)
);
nixosModules = collectModules "${flake}/modules/nixos";
nixosProfiles = collectModules "${flake}/profiles/nixos";
inputNixosModules = lib.map (flake: flake.outputs.nixosModules.default) (
lib.filter (flake: lib.hasAttrByPath [ "outputs" "nixosModules" "default" ] flake) (
lib.attrValues inputs
)
);
homeModules = collectModules "${flake}/modules/home";
homeProfiles = collectModules "${flake}/profiles/home";
inputHomeModules = lib.map (flake: flake.outputs.homeManagerModules.default) (
lib.filter (flake: lib.hasAttrByPath [ "outputs" "homeManagerModules" "default" ] flake) (
lib.attrValues (
lib.attrsets.filterAttrs (name: entry: !(lib.elem name excludeHomeManagerModules)) inputs
)
)
);
inputOverlays = lib.map (flake: flake.outputs.overlays.default) (
lib.filter (flake: lib.hasAttrByPath [ "outputs" "overlays" "default" ] flake) (
lib.attrValues inputs
)
);
overlayModule =
{ ... }:
{
nixpkgs.overlays = [ overlay ] ++ inputOverlays;
};
nixpkgsModule =
{ ... }:
{
nixpkgs.config = nixpkgs-config;
};
nixosConfigurations = importDir "${flake}/hosts" (
attrs:
lib.mapAttrs (
name: entry:
let
pkgs-stable = systemArgs."x86_64-linux".stable-pkgs;
in
lib.nixosSystem {
specialArgs = {
inherit inputs pkgs-stable;
};
modules =
let
systemPath = "${entry.path}/configuration.nix";
userEntries = importDir "${entry.path}/users" lib.id;
usersConfiguration = lib.mapAttrs (name: entry: {
isNormalUser = true;
group = name;
}) userEntries;
groupsConfiguration = lib.mapAttrs (name: entry: {
}) userEntries;
homesConfiguration = lib.mapAttrs (name: entry: entry.path) userEntries;
usersModule =
{ ... }:
{
home-manager.extraSpecialArgs = {
inherit inputs pkgs-stable;
};
home-manager.sharedModules = homeModules ++ homeProfiles ++ inputHomeModules;
home-manager.useUserPackages = true;
home-manager.useGlobalPkgs = true;
home-manager.users = homesConfiguration;
users.users = usersConfiguration;
users.groups = groupsConfiguration;
};
in
[
systemPath
overlayModule
usersModule
nixpkgsModule
]
++ nixosModules
++ nixosProfiles
++ inputNixosModules;
}
) (lib.attrsets.filterAttrs (name: entry: entry.type == "directory") attrs)
);
in
{
inherit packages nixosConfigurations overlay;
overlays.default = overlay;
}
Binary file not shown.
+241
View File
@@ -0,0 +1,241 @@
{
lib,
pkgs,
config,
...
}:
{
# State version
system.stateVersion = "24.11";
# Machine hostname
networking.hostName = "vm-audio";
# Enabled modules
modules = {
profiles.vm.enable = true;
sound.enable = true;
# spotifyd.enable = true; # TODO: Add this as a local module
};
# Install system packages
environment.systemPackages = with pkgs; [
carla
xpra
alsa-utils
pulsemixer
adwaita-icon-theme
open-stage-control
carla_osc_bridge
# Add LV2 plugins
lsp-plugins
airwindows-lv2
distrho-ports
cardinal
calf
];
# Setup firewall
networking.firewall = {
allowedTCPPorts = [
8080
10402
15151
22752
];
allowedUDPPorts = [
8080
10402
15151
22752
];
};
# Setup dependencies
environment.variables.LD_LIBRARY_PATH = lib.mkForce "${lib.makeLibraryPath (
with pkgs;
[
cairo
pipewire.jack
]
)}";
qt = {
enable = true;
style = "adwaita";
};
xdg.icons = {
enable = true;
fallbackCursorThemes = [ "Adwaita" ];
};
hardware.graphics.enable = true;
# User for audio mixing
users.users.mixer = {
isNormalUser = true;
group = "mixer";
extraGroups = [ "systemd-journal" ];
openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKKxoQSxfYqf9ITN8Fhckk8WbY4dwtBAXOhC9jxihJvq Personal"
];
};
users.groups.mixer = { };
users.groups.audio = {
members = [
"mixer"
];
};
users.groups.bluetooth = {
members = [
"mixer"
];
};
# Xpra service
systemd.user.services.xpra = {
description = "Xpra Service";
wantedBy = [ "default.target" ];
after = [
"network.target"
];
unitConfig = {
ConditionUser = "mixer";
};
serviceConfig = {
ExecStart = "${pkgs.xpra}/bin/xpra start :7 --bind-tcp=0.0.0.0:15151 --daemon=no";
Restart = "always";
RestartSec = 5;
};
};
# Carla service
systemd.user.services.carla = {
description = "Carla Service";
wantedBy = [ "default.target" ];
after = [
"network.target"
"sound.target"
];
requires = [
"xpra.service"
];
unitConfig = {
ConditionUser = "mixer";
};
serviceConfig = {
ExecStart = "${pkgs.carla}/bin/carla /home/mixer/Default.carxp -platform xcb";
Environment = "\"DISPLAY=:7\"";
Restart = "always";
RestartSec = 5;
};
};
# Carla service
systemd.user.services.carla-bridge = {
description = "Carla OSC Bridge";
wantedBy = [ "default.target" ];
after = [
"network.target"
"sound.target"
];
requires = [
"carla.service"
];
unitConfig = {
ConditionUser = "mixer";
};
serviceConfig = {
ExecStart = "${pkgs.carla_osc_bridge}/bin/carla_osc_bridge --clients \"127.0.0.1:8080\"";
Restart = "always";
RestartSec = 5;
};
};
# Open stage control service
systemd.user.services.osc = {
description = "OSC Service";
wantedBy = [ "default.target" ];
after = [
"network.target"
];
requires = [
"carla.service"
];
unitConfig = {
ConditionUser = "mixer";
};
serviceConfig = {
ExecStart = "${pkgs.open-stage-control}/bin/open-stage-control --no-gui --send 127.0.0.1:10402 --load /home/mixer/open-stage-control/session.json --theme /home/mixer/open-stage-control/theme.css";
Environment = "\"ELECTRON_RUN_AS_NODE=1\"";
Restart = "always";
RestartSec = 5;
};
};
# Create bluetooth A2DP source
hardware.bluetooth = {
enable = true;
disabledPlugins = [ "hostname" ];
settings.General = {
Name = "Linox";
Class = "0x240414";
DiscoverableTimeout = 0;
AlwaysPairable = true;
PairableTimeout = 0;
FastConnectable = true;
JustWorksRepairing = "always";
};
};
services.pipewire.wireplumber.extraConfig."50-bluetooth-a2dp" = {
"monitor.bluez.properties" = {
"bluez5.roles" = [ "a2dp_source" ];
};
};
# Create null sinks
services.pipewire.extraConfig.pipewire."91-null-sinks" = {
"context.objects" = [
{
factory = "adapter";
args = {
"factory.name" = "support.null-audio-sink";
"node.name" = "Speaker-Proxy";
"node.description" = "Proxy for Speaker Output";
"media.class" = "Audio/Sink";
"audio.position" = "L,R";
};
}
{
factory = "adapter";
args = {
"factory.name" = "support.null-audio-sink";
"node.name" = "Headphone-Proxy";
"node.description" = "Proxy for Headphone Output";
"media.class" = "Audio/Sink";
"audio.position" = "L,R";
};
}
{
factory = "adapter";
args = {
"factory.name" = "support.null-audio-sink";
"node.name" = "SpotifyD-Proxy";
"node.description" = "Proxy for SpotifyD";
"media.class" = "Audio/Sink";
"audio.position" = "L,R";
};
}
{
factory = "adapter";
args = {
"factory.name" = "support.null-audio-sink";
"node.name" = "AnalogIn-Proxy";
"node.description" = "Proxy for the analog input";
"media.class" = "Audio/Source/Virtual";
"audio.position" = "L,R";
};
}
];
};
}
+39
View File
@@ -0,0 +1,39 @@
{
inputs,
...
}:
{
# State version
system.stateVersion = "25.05";
# Machine hostname
networking.hostName = "vm-infra";
# Enabled modules
modules = {
profiles.vm.enable = true;
};
# Setup JOOL NAT64
networking.jool = {
enable = true;
nat64.default = {
global.pool6 = "64:ff9b::/96";
pool4 = [
{
protocol = "TCP";
prefix = "10.64.0.1/32";
}
{
protocol = "UDP";
prefix = "10.64.0.1/32";
}
{
protocol = "ICMP";
prefix = "10.64.0.1/32";
}
];
};
};
}
+254
View File
@@ -0,0 +1,254 @@
{
inputs,
pkgs,
config,
...
}:
{
# State version
system.stateVersion = "25.05";
# Machine hostname
networking.hostName = "vm-k1s";
# Enabled modules
modules = {
profiles.vm.enable = true;
};
# Read in secrets
sops.secrets."flux/git-ssh-key" = {
sopsFile = "${inputs.secrets}/secrets/k3s-cluster.enc.yaml";
};
sops.secrets."flux/sops-decrypt-key" = {
sopsFile = "${inputs.secrets}/secrets/k3s-cluster.enc.yaml";
};
# Include NFS client module
boot.supportedFilesystems = [ "nfs" ];
# Set up K3S cluster with CoreDNS, FluxCD and Cilium
services.k3s = {
enable = true;
extraFlags = [
"--cluster-domain ${inputs.secrets.lab.k3s.clusterDomain}"
"--flannel-backend=none"
"--disable-network-policy"
"--disable-kube-proxy"
];
disable = [
# "coredns" # CoreDNS is required for Flux to be able to bootstrap the cluster (Flux needs to resolve the git repo)
"servicelb"
"traefik"
"local-storage"
"metrics-server"
"runtimes"
];
manifests = {
git-ssh-key = {
source = config.sops.secrets."flux/git-ssh-key".path;
};
sops-decrypt-key = {
source = config.sops.secrets."flux/sops-decrypt-key".path;
};
# TODO: Move to flux config, once it is possible to easily install flux without CNI
gateway-api =
let
manifest = pkgs.fetchurl {
url = "https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.1/experimental-install.yaml";
hash = "sha256-VTMn4P8yoaK+RGv5OCPIQTz5JTrGptVAfuvR6NJp9p4=";
};
in
{
source = manifest;
};
# TODO: Move to flux config, once it is possible to easily install flux without CNI
netpol-system-allow-egress.content = {
apiVersion = "cilium.io/v2";
kind = "CiliumClusterwideNetworkPolicy";
metadata.name = "allow-system-egress";
spec = {
description = "Allow all egress to system services.";
endpointSelector = {
matchExpressions = [
{
key = "io.kubernetes.pod.namespace";
operator = "NotIn";
values = [
"bogus-namespace"
# "kube-system"
# "cilium-system"
# "flux-system"
];
}
];
};
egress = [
{
toEntities = [
"all"
];
}
];
ingress = [
{
fromEntities = [
"all"
];
}
];
};
};
netpol-cluster-allow-dns.content = {
apiVersion = "cilium.io/v2";
kind = "CiliumClusterwideNetworkPolicy";
metadata.name = "allow-dns";
spec = {
description = "Allow DNS";
endpointSelector = { };
egress = [
{
toEndpoints = [
{
matchLabels = {
"io.kubernetes.pod.namespace" = "kube-system";
"k8s-app" = "kube-dns";
};
}
];
toPorts = [
{
ports = [
{
port = 53;
protocol = "ANY";
}
];
rules.dns = [
{
matchPattern = "*";
}
];
}
];
}
];
};
};
netpol-flux-allow-egress.content = { };
};
autoDeployCharts = {
# TODO: Move to flux config, once it is possible to easily install flux without CNI
cilium = {
name = "cilium";
repo = "oci://quay.io/cilium/charts/cilium";
version = "1.18.8";
hash = "sha256-z1aDpWttEfQ+Af/l0Lxdafasm75QysRc8h7sPhWXr94=";
createNamespace = true;
targetNamespace = "cilium-system";
values = {
operator.replicas = 1;
kubeProxyReplacement = true;
ipam.operator.clusterPoolIPv4PodCIDRList = [ "10.42.0.0/16" ];
cluster = {
id = 1;
name = "vm-k1s";
};
k8sServiceHost = "10.10.50.60";
k8sServicePort = 6443;
policyEnforcementMode = "always";
gatewayAPI = {
enabled = true;
gatewayClass.create = "true";
enableAlpn = true;
};
bgpControlPlane.enabled = true;
tls.secretsNamespace.create = false;
hubble = {
relay.enabled = true;
ui.enabled = true;
peerService.clusterDomain = inputs.secrets.lab.k3s.clusterDomain;
};
};
extraFieldDefinitions = {
spec.bootstrap = true;
};
};
flux-operator = {
name = "flux-operator";
repo = "oci://ghcr.io/controlplaneio-fluxcd/charts/flux-operator";
version = "0.38.1";
hash = "sha256-nb0mzEWC3IwjPenQ4LSWBN0NNJc2cc68RB+G60xBOEM=";
createNamespace = true;
targetNamespace = "flux-system";
extraDeploy = [
{
apiVersion = "fluxcd.controlplane.io/v1";
kind = "FluxInstance";
metadata = {
name = "flux";
namespace = "flux-system";
annotations = {
"fluxcd.controlplane.io/reconcile" = "enabled";
"fluxcd.controlplane.io/reconcileEvery" = "1h";
"fluxcd.controlplane.io/reconcileTimeout" = "5m";
};
};
spec = {
distribution = {
version = "2.x";
registry = "ghcr.io/fluxcd";
};
components = [
"source-controller"
"kustomize-controller"
"helm-controller"
"notification-controller"
];
cluster = {
type = "kubernetes";
size = "small";
multitenant = false;
networkPolicy = true;
domain = inputs.secrets.lab.k3s.clusterDomain;
};
commonMetadata.labels = {
"app.kubernetes.io/name" = "flux";
};
sync = (
{
pullSecret = "git-ssh-key";
}
// inputs.secrets.lab.k3s.fluxRepo
);
};
}
];
};
};
};
modules.impermanence.directories = [
"/var/lib/rancher/k3s"
];
environment.variables = {
KUBECONFIG = "/etc/rancher/k3s/k3s.yaml";
CILIUM_NAMESPACE = "cilium-system";
};
environment.systemPackages = with pkgs; [
fluxcd
k9s
cilium-cli
hubble
];
# Use correct disko profile
modules.disko.profile = "k3s";
# TEMP: Disable firewall for now
networking.firewall.enable = false;
security.sudo.wheelNeedsPassword = false;
}
+58
View File
@@ -0,0 +1,58 @@
{
lib,
pkgs,
config,
inputs,
...
}:
{
# State version
system.stateVersion = "24.11";
# Import the nix-minecraft modules
imports = [
inputs.nix-minecraft.nixosModules.minecraft-servers
];
# Machine hostname
networking.hostName = "vm-minecraft";
# Enabled modules
modules = {
profiles.vm.enable = true;
};
# Set up minecraft servers
users.users.local.extraGroups = [ "minecraft" ];
modules.impermanence.directories = [
"/srv/minecraft"
];
services.minecraft-servers = {
enable = true;
eula = true;
openFirewall = true;
servers = {
vanilla = {
enable = true;
autoStart = true;
serverProperties = {
white-list = true;
difficulty = "normal";
max-players = 5;
};
package = inputs.nix-minecraft.legacyPackages.${pkgs.system}.fabricServers.fabric-1_21_7;
};
modpack = {
enable = false;
autoStart = true;
serverProperties = { };
package = inputs.nix-modpack.packages.${pkgs.system}.mkModpackServer {
packUrl = "https://raw.githubusercontent.com/Jan-Bulthuis/Modpack/refs/heads/master/pack.toml";
server = inputs.nix-minecraft.legacyPackages.${pkgs.system}.neoForgeServers.neoforge-20_1_106;
};
jvmOpts = "-Xms6144M -Xmx8192M";
};
};
};
}
+143
View File
@@ -0,0 +1,143 @@
{
inputs,
lib,
pkgs,
config,
...
}:
{
# State version
system.stateVersion = "24.11";
# Machine hostname
networking.hostName = "vm-oddjob";
# Enabled modules
modules = {
profiles.vm.enable = true;
};
# Omada Software Controller
users.users.omada = {
isSystemUser = true;
group = "omada";
};
users.groups.omada = { };
virtualisation.podman = {
enable = true;
dockerCompat = true;
defaultNetwork.settings.dns_enabled = true;
};
virtualisation.oci-containers = {
backend = "podman";
containers = {
omada-controller = {
volumes = [
"/var/lib/omada:/opt/tplink/EAPController/data"
];
environment = {
TZ = "Europe/Amsterdam";
};
extraOptions = [
"--network=host"
"--ulimit"
"nofile=4096:8192"
];
image = "mbentley/omada-controller:5.15";
};
};
};
modules.impermanence.directories = [
"/var/lib/omada"
];
networking.firewall = {
allowedTCPPorts = [
8088
8043
8843
];
allowedTCPPortRanges = [
{
from = 29811;
to = 29816;
}
];
allowedUDPPorts = [
19810
27001
29810
];
};
# Setup NAS backups
environment.systemPackages = with pkgs; [
keyutils
];
environment.etc."request-key.d/cifs.spnego.conf".text = ''
create cifs.spnego * * ${pkgs.cifs-utils}/bin/cifs.upcall -t %k
'';
environment.etc."request-key.d/cifs.idmap.conf".text = ''
create cifs.idmap * * ${pkgs.cifs-utils}/bin/cifs.idmap %k
'';
sops.secrets."smb-credentials" = {
sopsFile = "${inputs.secrets}/secrets/vm-oddjob.enc.yaml";
};
sops.secrets."backup-script-env" = {
sopsFile = "${inputs.secrets}/secrets/vm-oddjob.enc.yaml";
};
services.cron = {
enable = true;
systemCronJobs =
let
script = pkgs.writeShellScript "backup-script" (
lib.concatStrings (
[
''
. ${config.sops.secrets."backup-script-env".path}
export PBS_REPOSITORY=$PBS_REPOSITORY
export PBS_NAMESPACE=$PBS_NAMESPACE
export PBS_PASSWORD=$PBS_PASSWORD
export PBS_FINGERPRINT=$PBS_FINGERPRINT
''
]
++ lib.map (share: ''
systemctl start mnt-${share}.mount
${pkgs.util-linux}/bin/prlimit --nofile=1024:1024 ${pkgs.proxmox-backup-client}/bin/proxmox-backup-client backup nfs.pxar:/mnt/${share} --ns $PBS_NAMESPACE --backup-id share-${share} --change-detection-mode=metadata --exclude "#recycle"
systemctl stop mnt-${share}.mount
'') inputs.secrets.lab.nas.backupShares
)
);
in
[
"0 0 * * * root ${script}"
];
};
# Mount filesystems
systemd.services.krb5-mnt-credentials = {
description = "Set up Kerberos credentials for mounting shares";
before = map (share: "mnt-${share}.mount") inputs.secrets.lab.nas.backupShares;
requiredBy = map (share: "mnt-${share}.mount") inputs.secrets.lab.nas.backupShares;
after = [ "network-online.target" ];
requires = [ "network-online.target" ];
serviceConfig.Type = "oneshot";
script = ''
. ${config.sops.secrets."smb-credentials".path}
echo $password | ${pkgs.krb5}/bin/kinit $username
'';
};
fileSystems = lib.listToAttrs (
lib.map (share: {
name = "/mnt/${share}";
value = {
device = "//${inputs.secrets.lab.nas.host}/${share}";
fsType = "cifs";
options = [
"noauto"
"sec=krb5,credentials=${config.sops.secrets."smb-credentials".path}"
];
};
}) inputs.secrets.lab.nas.backupShares
);
}
+19
View File
@@ -0,0 +1,19 @@
{
lib,
pkgs,
config,
...
}:
{
# State version
system.stateVersion = "24.11";
# Machine hostname
networking.hostName = "vm-test";
# Enabled modules
modules = {
profiles.vm.enable = true;
};
}
+40
View File
@@ -0,0 +1,40 @@
{
lib,
pkgs,
config,
...
}:
{
# State version
system.stateVersion = "24.11";
# Machine hostname
networking.hostName = "vm-vpn";
# Enabled modules
modules = {
profiles.vm.enable = true;
};
# Setup wstunnel server
services.wstunnel = {
enable = true;
servers.wg-tunnel = {
enableHTTPS = false;
listen = {
host = "0.0.0.0";
port = 8080;
};
restrictTo = [
{
host = "10.10.40.100";
port = 51820;
}
];
};
};
networking.firewall = {
allowedTCPPorts = [ 8080 ];
};
}
+176
View File
@@ -0,0 +1,176 @@
{
inputs,
pkgs,
config,
...
}:
{
# State version
system.stateVersion = "24.05";
# Machine hostname
networking.hostName = "ws-think";
# Set up users
sops.secrets."passwords/jan-hashed" = {
sopsFile = "${inputs.secrets}/secrets/ws-think.enc.yaml";
neededForUsers = true;
};
users.mutableUsers = false;
users.users.Jan = {
hashedPasswordFile = config.sops.secrets."passwords/jan-hashed".path;
# Extra admin groups
# TODO: Streamline setup of this
extraGroups = [
"wheel"
"wireshark"
"podman"
"libvirtd"
];
};
# Set up impermanence
modules.impermanence = {
enable = true;
resetScript = ''
# Revert to the blank state for the root directory
zfs rollback -r tank/root@blank
'';
};
# Set up kerberos
security.krb5 = {
enable = true;
settings = {
libdefaults = {
rdns = false;
};
realms = (inputs.secrets.gewis.krb5Realm);
};
};
services.netbird = {
enable = true;
};
# SSH X11 forwarding
programs.ssh.forwardX11 = true;
# Enable older samba versions
services.samba = {
enable = true;
settings = {
global = {
"invalid users" = [ "root" ];
"passwd program" = "/run/wrappers/bin/passwd %u";
"security" = "user";
"client min protocol" = "NT1";
};
};
};
# TODO: Remove once laptop is properly integrated into domain
programs.ssh = {
package = pkgs.openssh_gssapi;
extraConfig = ''
GSSAPIAuthentication yes
'';
};
# Enable virtualisation for VMs
virtualisation.libvirtd.enable = true;
programs.virt-manager.enable = true;
# Enable wireshark
programs.wireshark = {
enable = true;
dumpcap.enable = true;
usbmon.enable = true;
};
# Enable Nix-LD
programs.nix-ld = {
enable = true;
};
# Set up wstunnel client
services.wstunnel = {
enable = true;
clients.wg-tunnel = {
connectTo = "wss://tunnel.bulthuis.dev:443";
settings.local-to-remote = [
"udp://51819:10.10.40.100:51820"
];
};
};
# Enable flatpak
services.flatpak.enable = true;
# Module setup
modules = {
profiles.laptop.enable = true;
};
# Set up podman
virtualisation.podman = {
enable = true;
dockerCompat = true;
dockerSocket.enable = true;
autoPrune.enable = true;
};
# Enable Gnome Remote Desktop
services.gnome.gnome-remote-desktop.enable = true;
systemd.services."gnome-remote-desktop".wantedBy = [ "graphical.target" ];
systemd.services."gnome-remote-desktop".preStart =
let
credDir = "/var/lib/gnome-remote-desktop/.local/share/gnome-remote-desktop";
credPath = "${credDir}/credentials.ini";
credFile = pkgs.writeText "gnome-remote-desktop-credentials" ''
[RDP]
credentials={'username': <'remote'>, 'password': <'remote'>}
'';
script = pkgs.writeScript "gnome-remote-desktop-setup" ''
mkdir -p ${credDir}
touch ${credPath}
chown gnome-remote-desktop:gnome-remote-desktop ${credPath}
chmod 600 ${credPath}
cat ${credFile} > ${credPath}
'';
in
"${script}";
environment.etc."gnome-remote-desktop/grd.conf" = {
text = ''
[RDP]
port=3389
tls-key=/run/secrets/gnome-remote-desktop/tls-key
tls-cert=/run/secrets/gnome-remote-desktop/tls-crt
enabled=true
'';
};
networking.firewall = {
allowedTCPPorts = [
3389
3390
];
allowedUDPPorts = [
3389
3390
];
};
sops.secrets."gnome-remote-desktop/tls-key" = {
sopsFile = "${inputs.secrets}/secrets/ws-think.enc.yaml";
owner = config.users.users.gnome-remote-desktop.name;
group = config.users.users.gnome-remote-desktop.group;
};
sops.secrets."gnome-remote-desktop/tls-crt" = {
sopsFile = "${inputs.secrets}/secrets/ws-think.enc.yaml";
owner = config.users.users.gnome-remote-desktop.name;
group = config.users.users.gnome-remote-desktop.group;
};
# Set up hardware
imports = [ ./hardware-configuration.nix ];
}
+65
View File
@@ -0,0 +1,65 @@
{ ... }:
{
# Machine platform
nixpkgs.hostPlatform = "x86_64-linux";
# Set hostid (required for ZFS)
networking.hostId = "deadbeef";
# Use thermald
services.thermald.ignoreCpuidCheck = true;
# Hardware configuration
hardware.enableRedistributableFirmware = true;
boot.initrd.availableKernelModules = [
"xhci_pci"
"nvme"
"usb_storage"
"sd_mod"
"rtsx_pci_sdmmc"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
boot.zfs.forceImportRoot = false;
hardware.cpu.intel.updateMicrocode = true;
# Filesystems
fileSystems = {
"/" = {
device = "tank/root";
fsType = "zfs";
options = [ "zfsutil" ];
};
"/nix" = {
device = "tank/nix";
fsType = "zfs";
options = [ "zfsutil" ];
};
"/persist" = {
device = "tank/persist";
fsType = "zfs";
options = [ "zfsutil" ];
};
"/boot" = {
device = "/dev/disk/by-uuid/46BF-DE2C";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
};
# Swap setup
swapDevices = [
{
device = "/dev/disk/by-uuid/9f6f2a47-e53a-45a0-8cb2-8c1082f54ccb";
discardPolicy = "both";
}
];
}
+52
View File
@@ -0,0 +1,52 @@
{
pkgs,
...
}:
{
home.stateVersion = "25.11";
modules.profiles.jan.enable = true;
# home.packages = with pkgs; [
# opencloud-desktop
# code-nautilus
# nautilus-open-in-blackbox
# ];
xdg.desktopEntries = {
canvas = {
name = "Canvas";
type = "Application";
exec = "${pkgs.chromium}/bin/chromium --app=\"https://canvas.tue.nl\" --user-data-dir=/home/jan/.local/state/Canvas";
settings.StartupWMClass = "chrome-canvas.tue.nl__-Default";
};
overleaf = {
name = "Overleaf";
type = "Application";
exec = "${pkgs.chromium}/bin/chromium --app=\"https://www.overleaf.com\" --user-data-dir=/home/jan/.local/state/Overleaf";
settings.StartupWMClass = "chrome-www.overleaf.com__-Default";
};
};
# TODO: Slowly remove
modules.impermanence = {
directories = [
".cache"
".config"
".cargo"
".dbus"
".gnupg"
".local"
".MathWorks"
".mozilla"
".ssh"
".steam"
".SteamCloud"
".thunderbird"
".vscode"
".wine"
".Wolfram"
];
};
}
-56
View File
@@ -1,56 +0,0 @@
{ lib, ... }:
{
imports = [
# Import environment
../default.nix
];
config = {
# State version
system.stateVersion = "24.05";
# Machine hostname
networking.hostName = "20212060";
# Enabled modules
modules = {
base.enable = true;
bluetooth.enable = true;
power-saving.enable = false;
pipewire.enable = true;
networkmanager.enable = true;
# wpa_supplicant.enable = true;
};
# Hardware configuration
hardware.enableRedistributableFirmware = true;
boot.initrd.availableKernelModules = [
"xhci_pci"
"nvme"
"usb_storage"
"sd_mod"
"rtsx_pci_sdmmc"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
swapDevices = [ ];
hardware.cpu.intel.updateMicrocode = true;
# Filesystems
fileSystems."/" = {
device = "/dev/disk/by-uuid/3b91eaeb-ea95-4bea-8dc1-f55af7502d23";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/46BF-DE2C";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
};
}
-103
View File
@@ -1,103 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.base;
in
{
options.modules.base = {
enable = mkEnableOption "base";
};
config = mkIf cfg.enable {
environment.systemPackages = with pkgs; [
# Add base linux utilities
git
wget
curl
dig
procps
wireguard-tools
usbutils
pciutils
zip
unzip
# TODO: MOVE
quickemu # TODO: Reenable once building this is fixed
pdftk
# TODO: Move to USB module
# usbutils
# udiskie
# udisks
];
security.krb5 = {
enable = true;
settings = {
libdefaults = {
rdns = false;
};
realms = {
"GEWISWG.GEWIS.NL" = {
kdc = [
"https://gewisvdesktop.gewis.nl/KdcProxy"
];
};
};
};
};
modules = {
# Enable base modules
clean-tmp.enable = true;
fontconfig.enable = true;
neovim.enable = true;
systemd-boot.enable = true;
tuigreet.enable = true;
};
# TODO: Remove everything below, it is here out of convenience and should be elsewhere
# networking.nameservers = [
# "9.9.9.9"
# "149.112.112.112"
# ];
# programs.captive-browser.enable = true;
services.resolved = {
enable = true;
};
networking.firewall.enable = true;
programs.dconf.enable = true;
services.libinput.enable = true;
modules.unfree.enable = true;
modules.unfree.allowedPackages = [
"nvidia-x11"
"nvidia-settings"
];
nix.settings.experimental-features = "nix-command flakes";
# networking.useDHCP = true;
nixpkgs.hostPlatform = "x86_64-linux";
networking.firewall.allowedTCPPortRanges = [
{
from = 10000;
to = 11000;
}
];
networking.firewall.allowedUDPPortRanges = [
{
from = 10000;
to = 11000;
}
];
# TODO: Move to USB module
# services.gvfs.enable = true;
services.udisks2.enable = true;
};
}
-23
View File
@@ -1,23 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.bluetooth;
in
{
options.modules.bluetooth = {
enable = mkEnableOption "bluetooth";
};
config = mkIf cfg.enable {
environment.systemPackages = with pkgs; [ bluez ];
hardware.bluetooth.enable = true;
hardware.bluetooth.powerOnBoot = true;
};
}
-18
View File
@@ -1,18 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.clean-tmp;
in
{
options.modules.clean-tmp = {
enable = mkEnableOption "clean-tmp";
};
config = mkIf cfg.enable { boot.tmp.cleanOnBoot = true; };
}
-37
View File
@@ -1,37 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.silent-boot;
in
{
options.modules.silent-boot = {
enable = mkEnableOption "silent-boot";
};
config = mkIf cfg.enable {
boot = {
loader.timeout = 0;
consoleLogLevel = 0;
initrd.verbose = false;
initrd.checkJournalingFS = false;
kernelParams = [
"quiet"
"boot.shell_on_fail"
"loglevel=3"
"rd.systemd.show_status=false"
"rd.udev.log_level=3"
"udev.log_priority=3"
"video=efifb:nobgrt"
"bgrt_disable"
];
};
};
}
-24
View File
@@ -1,24 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.systemd-boot;
in
{
options.modules.systemd-boot = {
enable = mkEnableOption "systemd-boot";
};
config = mkIf cfg.enable {
boot.loader = {
systemd-boot.enable = true;
systemd-boot.editor = false;
efi.canTouchEfiVariables = true;
};
};
}
-18
View File
@@ -1,18 +0,0 @@
{
config,
lib,
pkgs,
...
}:
with lib;
let
cfg = config.modules.brightnessctl;
in
{
options.modules.brightnessctl = {
enable = mkEnableOption "brightnessctl";
};
config = mkIf cfg.enable { environment.systemPackages = [ pkgs.brightnessctl ]; };
}
-32
View File
@@ -1,32 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
{
imports = [
# Import modules
./base/default.nix
./bluetooth/default.nix
./boot/clean-tmp.nix
./boot/silent-boot.nix
./boot/systemd-boot.nix
./brightnessctl/default.nix
./fontconfig/default.nix
./graphics/default.nix
./greeter/greetd/default.nix
./greeter/greetd/tuigreet.nix
./locale/default.nix
./neovim/default.nix
./networkmanager/default.nix
./power-saving/default.nix
./sound/pipewire.nix
./users/default.nix
./unfree/default.nix
./vpn/tailscale.nix
./wifi/wpa_supplicant.nix
];
}
-27
View File
@@ -1,27 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.fontconfig;
in
{
options.modules.fontconfig = {
enable = mkEnableOption "fontconfig";
};
config = {
fonts.fontconfig.enable = cfg.enable;
fonts.enableDefaultPackages = false;
fonts.fontconfig.defaultFonts = {
serif = mkDefault [ ];
sansSerif = mkDefault [ ];
monospace = mkDefault [ ];
emoji = mkDefault [ ];
};
};
}
-32
View File
@@ -1,32 +0,0 @@
{
lib,
config,
pkgs,
...
}:
{
config = {
# TODO: Modularize further, especially modesetting should be its own module.
# Set up graphics
hardware.graphics.enable32Bit = true;
hardware.graphics.enable = true;
services.xserver.videoDrivers = [ "nvidia" ];
hardware.nvidia = {
modesetting.enable = true;
powerManagement.enable = false;
powerManagement.finegrained = false;
open = false;
nvidiaSettings = true;
package = config.boot.kernelPackages.nvidiaPackages.stable;
prime = {
intelBusId = "PCI:0:2:0";
nvidiaBusId = "PCI:1:0:0";
offload = {
enable = true;
enableOffloadCmd = true;
};
};
};
};
}
-31
View File
@@ -1,31 +0,0 @@
{
config,
lib,
pkgs,
...
}:
with lib;
let
cfg = config.modules.greetd;
in
{
options.modules.greetd = {
enable = mkEnableOption "greetd";
command = mkOption {
type = types.str;
default = "";
description = "Command to run to show greeter.";
};
};
config = mkIf cfg.enable {
services.greetd = {
enable = true;
settings.default_session = {
command = cfg.command;
user = "greeter";
};
};
};
}
-37
View File
@@ -1,37 +0,0 @@
{
config,
lib,
pkgs,
...
}:
with lib;
let
cfg = config.modules.tuigreet;
in
{
options.modules.tuigreet = {
enable = mkEnableOption "tuigreet";
greeting = mkOption {
type = types.str;
default = "Hewwo! >_< :3";
description = "Greeting message to show.";
};
command = mkOption {
type = types.str;
default = "~/.initrc";
description = "Command to run after logging in.";
};
};
config = mkIf cfg.enable {
# Enable greetd
modules.greetd = {
enable = true;
command = "${pkgs.greetd.tuigreet}/bin/tuigreet --remember --greeting \"${cfg.greeting}\" --time --cmd \"${cfg.command}\" --asterisks";
};
# Enable silent boot to prevent late log messages from messing up tuigreet
modules.silent-boot.enable = true;
};
}
+101
View File
@@ -0,0 +1,101 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.desktop.gnome;
in
{
options.modules.desktop.gnome = {
enable = mkEnableOption "gnome";
};
config = mkIf cfg.enable {
# TODO: Enable extensions (declaratively) with dconf
home.pointerCursor = {
enable = true;
name = "capitaine-cursors";
size = 24;
package = pkgs.capitaine-cursors;
gtk.enable = true;
};
home.packages =
with pkgs;
[
gnome-session
gnome-shell
gnome-tweaks
gnome-calculator
snapshot
gnome-characters
gnome-connections
blackbox-terminal
baobab
gnome-disk-utility
papers
nautilus
gnome-font-viewer
loupe
gnome-maps
gnome-music
gnome-control-center
gnome-text-editor
showtime
file-roller
mission-center
dconf-editor
gnome-calendar
gnome-backgrounds
gnome-bluetooth
gnome-color-manager
epiphany
# For theming gtk3
# adw-gtk3 # TODO: Do this better, same for morewaita, not sure if it even works
# More icons
# morewaita-icon-theme
]
++ (with pkgs.gnomeExtensions; [
gsconnect
disable-workspace-animation
wallpaper-slideshow
media-progress
mpris-label
pip-on-top
rounded-window-corners-reborn
caffeine
]);
# Set up gnome terminal as changing the default terminal is a pain
programs.gnome-terminal = {
enable = true;
profile."12d2da79-b36c-43d5-8e1f-cf70907b84b3" = {
visibleName = "Default";
default = true;
};
};
# Enable and set the gtk themes
# gtk = {
# enable = true;
# gtk3.extraConfig = {
# gtk-theme-name = "adw-gtk3";
# };
# gtk4.extraConfig = {
# gtk-theme-name = "Adwaita";
# };
# };
# Set the theme with dconf
# dconf.settings."org/gnome/desktop/interface" = {
# gtk-theme = "adw-gtk3";
# };
};
}
@@ -39,15 +39,15 @@ in
programs.git = { programs.git = {
enable = true; enable = true;
extraConfig = { settings = {
pull = { pull = {
rebase = false; rebase = false;
}; };
}; };
userName = cfg.user; settings.user.name = cfg.user;
userEmail = cfg.email; settings.user.email = cfg.email;
ignores = cfg.ignores; # ignores = cfg.ignores;
}; };
}; };
} }
@@ -0,0 +1,50 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.cpp;
in
{
options.modules.cpp = {
enable = mkEnableOption "cpp";
};
config = mkIf cfg.enable {
# Gitignore additions
modules.git.ignores = [
".ccls-cache"
];
# Development packages
home.packages = with pkgs; [
gnumake
gcc
];
# VSCode configuration
programs.vscode = {
profiles.default = {
extensions = with pkgs.vscode-extensions; [
ms-vscode.cpptools
ms-vscode.cmake-tools
ms-vscode.cpptools-extension-pack
];
userSettings = {
# TODO: Add setting to set the compiler, it currently needs to be set for each workspace individually
# "C_Cpp.clang_format_fallbackStyle" = "{ BasedOnStyle: Google, IndentWidth: 4 }";
};
};
};
# Neovim configuration
# programs.nixvim = {
# plugins.lsp.servers.ccls.enable = true;
# };
};
}
+42
View File
@@ -0,0 +1,42 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.go;
in
{
options.modules.go = {
enable = mkEnableOption "go";
};
config = mkIf cfg.enable {
# Development packages
home.packages = with pkgs; [
];
# VSCode configuration
programs.vscode = {
profiles.default = {
extensions = with pkgs.vscode-extensions; [
golang.go
];
userSettings = {
};
};
};
# Neovim configuration
# programs.nixvim = {
# plugins.rustaceanvim = {
# enable = true;
# };
# };
};
}
@@ -23,18 +23,20 @@ in
# VSCode configuration # VSCode configuration
programs.vscode = { programs.vscode = {
extensions = with pkgs.vscode-extensions; [ profiles.default = {
haskell.haskell extensions = with pkgs.vscode-extensions; [
justusadam.language-haskell haskell.haskell
]; justusadam.language-haskell
];
userSettings = { userSettings = {
"[haskell]" = { }; "[haskell]" = { };
# "haskell.formattingProvider" = "fourmolu"; # "haskell.formattingProvider" = "fourmolu";
};
}; };
}; };
# Neovim configuration # Neovim configuration
programs.nixvim = { }; # programs.nixvim = { };
}; };
} }
@@ -23,14 +23,16 @@ in
# VSCode configuration # VSCode configuration
programs.vscode = { programs.vscode = {
extensions = with pkgs.vscode-extensions; [ profiles.default = {
bradlc.vscode-tailwindcss extensions = with pkgs.vscode-extensions; [
]; bradlc.vscode-tailwindcss
];
userSettings = { }; userSettings = { };
};
}; };
# Neovim configuration # Neovim configuration
programs.nixvim = { }; # programs.nixvim = { };
}; };
} }
@@ -0,0 +1,44 @@
{
lib,
config,
pkgs,
...
}:
# TODO: Move to a module for notebooks in general
with lib;
let
cfg = config.modules.jupyter;
in
{
options.modules.jupyter = {
enable = mkEnableOption "jupyter";
};
config = mkIf cfg.enable {
# Development packages
# home.packages = with pkgs; [
# evcxr
# ];
# modules.python.extraPythonPackages = p: [
# p.jupyter
# p.notebook
# ];
# VSCode configuration
programs.vscode = {
profiles.default = {
extensions = with pkgs.vscode-extensions; [
ms-toolsai.jupyter
ms-toolsai.jupyter-renderers
];
userSettings = { };
};
};
# Neovim configuration
# programs.nixvim = { };
};
}
@@ -18,7 +18,7 @@ in
# Development packages # Development packages
home.packages = with pkgs; [ home.packages = with pkgs; [
nix-tree nix-tree
nixfmt-rfc-style nixfmt
nixd nixd
]; ];
@@ -32,18 +32,20 @@ in
# VSCode configuration # VSCode configuration
programs.vscode = { programs.vscode = {
extensions = with pkgs.vscode-extensions; [ jnoortheen.nix-ide ]; profiles.default = {
extensions = with pkgs.vscode-extensions; [ jnoortheen.nix-ide ];
userSettings = { userSettings = {
"[nix]" = { "[nix]" = {
"editor.tabSize" = 2; "editor.tabSize" = 2;
}; };
"nix.enableLanguageServer" = true; "nix.enableLanguageServer" = true;
"nix.serverPath" = "nixd"; "nix.serverPath" = "nixd";
"nix.serverSettings" = { "nix.serverSettings" = {
nixd = { nixd = {
formatting = { formatting = {
command = [ "nixfmt" ]; command = [ "nixfmt" ];
};
}; };
}; };
}; };
@@ -51,8 +53,8 @@ in
}; };
# Neovim configuration # Neovim configuration
programs.nixvim = { # programs.nixvim = {
}; # };
}; };
} }
@@ -8,7 +8,6 @@
with lib; with lib;
let let
cfg = config.modules.python; cfg = config.modules.python;
package = pkgs.python3.withPackages cfg.extraPythonPackages;
in in
{ {
options.modules.python = { options.modules.python = {
@@ -26,32 +25,28 @@ in
config = mkIf cfg.enable { config = mkIf cfg.enable {
# Development packages # Development packages
home.packages = [ home.packages = [ ];
package
];
# Allow unfree
modules.unfree.allowedPackages = [
"vscode-extension-MS-python-vscode-pylance"
];
# VSCode configuration # VSCode configuration
programs.vscode = { programs.vscode = {
extensions = with pkgs.vscode-extensions; [ profiles.default = {
ms-python.python extensions = with pkgs.vscode-extensions; [
ms-python.debugpy ms-python.python
ms-python.vscode-pylance ms-python.debugpy
ms-python.black-formatter ms-python.vscode-pylance
]; ms-python.black-formatter
];
userSettings = { userSettings = {
"[python]" = { "python.defaultInterpreterPath" = "\${env:PYTHONINTERPRETER}";
"editor.defaultFormatter" = "ms-python.black-formatter"; "[python]" = {
"editor.defaultFormatter" = "ms-python.black-formatter";
};
}; };
}; };
}; };
# Neovim configuration # Neovim configuration
programs.nixvim = { }; # programs.nixvim = { };
}; };
} }
@@ -0,0 +1,59 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.rust;
in
{
options.modules.rust = {
enable = mkEnableOption "rust";
};
config = mkIf cfg.enable {
# Development packages
home.packages = with pkgs; [
# rustup
# rustc
# cargo
# gcc
# lldb
# bacon
# rust-analyzer
# rustfmt
# clippy
# evcxr
];
# VSCode configuration
programs.vscode = {
profiles.default = {
extensions = with pkgs.vscode-extensions; [
rust-lang.rust-analyzer
vadimcn.vscode-lldb
tamasfe.even-better-toml
serayuzgur.crates
];
userSettings = {
"[rust]" = {
"editor.inlayHints.enabled" = "off";
};
"rust-analyzer.check.command" = "clippy";
"rust-analyzer.showUnlinkedFileNotification" = false;
};
};
};
# Neovim configuration
# programs.nixvim = {
# plugins.rustaceanvim = {
# enable = true;
# };
# };
};
}
@@ -0,0 +1,69 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.tex;
in
{
options.modules.tex = {
enable = mkEnableOption "tex";
};
config = mkIf cfg.enable {
# Development packages
home.packages = with pkgs; [
(texlive.combine {
inherit (texlive) scheme-full;
})
];
# Pygments for minted
modules.python.extraPythonPackages = p: [
p.pygments
];
# VSCode configuration
programs.vscode = {
profiles.default = {
extensions = with pkgs.vscode-extensions; [ jnoortheen.nix-ide ];
userSettings = {
"[tex]" = { };
};
};
};
# Neovim configuration
# programs.nixvim = {
# extraConfigVim = ''
# " Enforce latexmk
# let g:vimtex_compiler_method = 'latexmk'
# " Set latexmk compilation settings
# let g:vimtex_compiler_latexmk = {
# \ 'options': [
# \ '-shell-escape',
# \ '-verbose',
# \ '-file-line-error',
# \ '-synctex=1',
# \ '-interaction=nonstopmode',
# \ ],
# \}
# '';
# # Vimtex plugin
# plugins.vimtex = {
# enable = true;
# texlivePackage = null;
# settings = {
# view_method = "zathura";
# };
# };
# };
};
}
+29
View File
@@ -0,0 +1,29 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.mathematica;
my-mathematica = pkgs.mathematica.overrideAttrs (old: {
force-rebuild = "1";
# TODO: Just use a generic name for the installer?
# source = ./Wolfram_14.2.1_LIN_Bndl.sh;
});
in
{
options.modules.mathematica = {
enable = mkEnableOption "mathematica";
};
config = mkIf cfg.enable {
home.packages = [
# pkgs.mathematica-cuda
my-mathematica
];
};
}
+190
View File
@@ -0,0 +1,190 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.neovim;
# theme = config.desktop.theming;
# colors = theme.colors;
in
{
options.modules.neovim = {
enable = mkEnableOption "neovim";
};
config = mkIf cfg.enable {
# programs.nixvim = {
# enable = true;
# defaultEditor = true;
# viAlias = true;
# vimAlias = true;
# # extraPackages = with pkgs; [ ];
# opts = {
# number = true;
# relativenumber = true;
# signcolumn = "yes";
# ignorecase = true;
# smartcase = true;
# tabstop = 4;
# shiftwidth = 4;
# softtabstop = 0;
# expandtab = true;
# smarttab = true;
# list = true;
# listchars = "tab:»┈«,trail:·,extends:→,precedes:←,nbsp:␣";
# };
# diagnostic.settings = {
# enable = true;
# signs = true;
# underline = true;
# update_in_insert = true;
# };
# extraConfigLua = ''
# vim.fn.sign_define("DiagnosticSignError",
# {text = "", texthl = "DiagnosticSignError"})
# vim.fn.sign_define("DiagnosticSignWarn",
# {text = "", texthl = "DiagnosticSignWarn"})
# vim.fn.sign_define("DiagnosticSignInfo",
# {text = "", texthl = "DiagnosticSignInfo"})
# vim.fn.sign_define("DiagnosticSignHint",
# {text = "💡", texthl = "DiagnosticSignHint"})
# '';
# keymaps = [
# # Save shortcut
# {
# action = ":update<CR>";
# key = "<C-s>";
# mode = "n";
# }
# {
# action = "<C-o>:update<CR>";
# key = "<C-s>";
# mode = "i";
# }
# # Neo tree
# {
# action = ":Neotree action=focus reveal toggle<CR>";
# key = "<leader>n";
# mode = "n";
# options.silent = true;
# }
# ];
# autoCmd = [
# {
# desc = "Automatic formatting";
# event = "BufWritePre";
# callback = {
# __raw = ''
# function()
# vim.lsp.buf.format {
# async = false,
# }
# end
# '';
# };
# }
# ];
# # highlight = {
# # Comment = {
# # italic = true;
# # fg = theme.schemeColors.withHashtag.base03; # TODO: Come up with a good name colors.muted maybe?
# # };
# # };
# plugins.lsp = {
# enable = true;
# };
# #plugins.treesitter = {
# # enable = true;
# #};
# plugins.cmp = {
# enable = true;
# settings = {
# mapping = {
# "<C-Space>" = "cmp.mapping.complete()";
# "<C-d>" = "cmp.mapping.scroll_docs(-4)";
# "<C-e>" = "cmp.mapping.close()";
# "<C-f>" = "cmp.mapping.scroll_docs(4)";
# "<CR>" = "cmp.mapping.confirm({ select = true })";
# "<S-Tab>" = "cmp.mapping(cmp.mapping.select_prev_item(), {'i', 's'})";
# "<Tab>" = "cmp.mapping(cmp.mapping.select_next_item(), {'i', 's'})";
# };
# sources = [
# { name = "path"; }
# { name = "nvim_lsp"; }
# ];
# };
# };
# plugins.web-devicons = {
# enable = true;
# };
# plugins.neo-tree = {
# enable = true;
# closeIfLastWindow = true;
# window = {
# width = 30;
# autoExpandWidth = true;
# };
# extraOptions = {
# default_component_configs.git_status.symbols = {
# # Change type
# added = "+";
# deleted = "✕";
# modified = "✦";
# renamed = "→";
# # Status type
# untracked = "?";
# ignored = "▫";
# unstaged = "□";
# staged = "■";
# conflict = "‼";
# };
# };
# };
# #plugins.cmp-nvim-lsp.enable = true;
# plugins.gitsigns = {
# enable = true;
# settings.current_line_blame = true;
# };
# #plugins.copilot-vim = {
# # enable = true;
# #};
# # plugins.vimtex = {
# # enable = true;
# # texlivePackage = null;
# # settings = {
# # view_method = "zathura";
# # };
# # };
# };
# programs.neovim.defaultEditor = true;
};
}
+100
View File
@@ -0,0 +1,100 @@
{
config,
lib,
pkgs,
...
}:
with lib;
let
cfg = config.modules.vscode;
# theme = config.desktop.theming;
in
{
options.modules.vscode = {
enable = mkEnableOption "vscode";
# codeFont = mkOption {
# type = types.anything;
# default = theme.fonts.pkgs."Fira Code";
# };
# fallbackFont = mkOption {
# type = types.anything;
# default = theme.fonts.pkgs."Symbols Nerd Font Mono";
# };
};
config = mkIf cfg.enable {
# TODO: Fix theming
# desktop.theming.fonts.extraFonts = [ cfg.codeFont ];
programs.vscode = {
enable = true;
mutableExtensionsDir = false;
profiles.default = {
extensions = with pkgs.vscode-extensions; [
eamodio.gitlens
ms-vscode.hexeditor
mkhl.direnv
usernamehw.errorlens
gruntfuggly.todo-tree
github.copilot
github.copilot-chat
tomoki1207.pdf
ms-vsliveshare.vsliveshare
ms-vscode-remote.remote-ssh
myriad-dreamin.tinymist
];
userSettings =
let
# font-family = mkForce "'${cfg.codeFont.name}', '${cfg.fallbackFont.name}'";
# TODO: Move the conversion factor to theme settings
# font-size = mkForce cfg.codeFont.recommendedSize; # Convert pt to px
in
{
# Font setup
# "editor.fontFamily" = font-family;
# "editor.inlayHints.fontFamily" = font-family;
# "editor.inlineSuggest.fontFamily" = font-family;
# "editor.fontSize" = font-size;
# "editor.fontLigatures" = true;
# "terminal.integrated.fontFamily" = font-family;
# "terminal.integrated.fontSize" = font-size;
# "chat.editor.fontFamily" = font-family; # TODO: Change this font to the standard UI font
# "chat.editor.fontSize" = font-size;
# "debug.console.fontFamily" = font-family;
# "debug.console.fontSize" = font-size;
# "scm.inputFontFamily" = font-family; # TODO: Change this font to the standard UI font
# "scm.inputFontSize" = font-size;
# "markdown.preview.fontFamily" = mkForce theme.fonts.sansSerif.name; # TODO: Change this font to the standard UI font
# "markdown.preview.fontSize" = mkForce theme.fonts.sansSerif.recommendedSize;
# Formatting
"editor.formatOnSave" = true;
"editor.tabSize" = 4;
# Layout
"window.menuBarVisibility" = "hidden";
# Git settings
"git.autofetch" = true;
"git.enableSmartCommit" = false;
"git.suggestSmartCommit" = false;
# Disable update notifications
"update.mode" = "none";
# Set themes
"window.autoDetectColorScheme" = true;
# TODO: Move to direnv module
# Ignore direnv folder
"files.exclude" = {
".direnv" = true;
};
};
};
};
};
}
@@ -1,13 +1,16 @@
{ {
pkgs,
lib, lib,
config, config,
... ...
}: }:
with lib; with lib;
let
cfg = config.modules.bash;
in
{ {
options.modules.shell = { options.modules.bash = {
enable = mkEnableOption "bash";
aliases = mkOption { aliases = mkOption {
type = types.attrsOf types.str; type = types.attrsOf types.str;
default = { default = {
@@ -16,4 +19,9 @@ with lib;
description = "Shell aliases"; description = "Shell aliases";
}; };
}; };
config.programs.bash = {
enable = cfg.enable;
shellAliases = cfg.aliases;
};
} }
@@ -7,16 +7,16 @@
with lib; with lib;
let let
cfg = config.modules.retroarch; cfg = config.modules.bitwarden;
in in
{ {
options.modules.retroarch = { options.modules.bitwarden = {
enable = mkEnableOption "RetroArch"; enable = mkEnableOption "Bitwarden";
}; };
config = mkIf cfg.enable { config = mkIf cfg.enable {
home.packages = with pkgs; [ home.packages = with pkgs; [
retroarch-free bitwarden-desktop
]; ];
}; };
} }
+26
View File
@@ -0,0 +1,26 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.direnv;
in
{
options.modules.direnv = {
enable = mkEnableOption "direnv";
};
config = mkIf cfg.enable {
programs.direnv = {
enable = true;
nix-direnv.enable = true;
};
modules.git.ignores = [
".direnv"
];
};
}
@@ -12,12 +12,6 @@ in
{ {
options.modules.fish = { options.modules.fish = {
enable = mkEnableOption "fish"; enable = mkEnableOption "fish";
plugins = {
done = mkEnableOption "done";
fzf = mkEnableOption "fzf";
grc = mkEnableOption "grc";
};
}; };
config = mkIf cfg.enable { config = mkIf cfg.enable {
@@ -36,28 +30,31 @@ in
programs.fish = { programs.fish = {
enable = true; enable = true;
shellAliases = config.modules.shell.aliases; shellAliases = config.modules.bash.aliases;
plugins = [ plugins = [
(mkIf cfg.plugins.done { {
name = "done"; name = "done";
src = pkgs.fishPlugins.done.src; src = pkgs.fishPlugins.done.src;
}) }
(mkIf cfg.plugins.fzf { {
name = "fzf"; name = "fzf";
src = pkgs.fishPlugins.fzf-fish.src; src = pkgs.fishPlugins.fzf-fish.src;
}) }
(mkIf cfg.plugins.grc { {
name = "grc"; name = "grc";
src = pkgs.fishPlugins.grc.src; src = pkgs.fishPlugins.grc.src;
}) }
]; ];
}; };
# Fish plugin dependencies # Fish plugin dependencies
home.packages = with pkgs; [ home.packages = with pkgs; [
(mkIf cfg.plugins.fzf fzf) fzf
(mkIf cfg.plugins.grc grc) grc
]; ];
# Impermanence
modules.impermanence.files = [ ".local/share/fish/fish_history" ];
}; };
} }
+34
View File
@@ -0,0 +1,34 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.impermanence;
in
{
options.modules.impermanence = {
enable = mkEnableOption "Impermanence";
directories = mkOption {
type = types.listOf types.str;
default = [ ];
description = ''
Directories that should be stored in persistent storage.
'';
};
files = mkOption {
type = types.listOf types.str;
default = [ ];
description = ''
Files that should be stored in persistent storage.
'';
};
};
config = mkIf cfg.enable {
home.persistence."/persist/home" = {
enable = true;
hideMounts = true;
directories = cfg.directories;
files = cfg.files;
};
};
}
+43
View File
@@ -0,0 +1,43 @@
{
inputs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.secrets;
secrets = inputs.secrets;
in
{
options.modules.secrets = {
enable = mkEnableOption "secrets";
defaultFile = mkOption {
type = types.str;
default = "${secrets}/secrets/common.enc.yaml";
description = ''
The default file to use for SOPS.
'';
};
secrets = mkOption {
type = types.attrs;
default = { };
description = ''
All secrets that should be made available.
'';
};
};
config = mkIf cfg.enable {
# Set up SOPS
# TODO: Fix the key not being present in .config/sops before sops-nix runs
sops.defaultSopsFile = cfg.defaultFile;
sops.age.sshKeyPaths = [
"${config.home.homeDirectory}/.config/sops/sops_ed25519_key"
# "/persist/home/${config.home.username}/.config/sops/sops_ed25519_key"
];
sops.secrets = cfg.secrets;
modules.impermanence.directories = [ ".config/sops" ];
};
}
+63
View File
@@ -0,0 +1,63 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.xpra;
in
{
options.modules.xpra = {
enable = mkEnableOption "Enable xpra";
hosts = mkOption {
type = types.listOf types.str;
default = { };
description = "xpra hosts";
};
};
config = mkIf cfg.enable {
home.packages = with pkgs; [
xpra
];
xdg.desktopEntries = (
listToAttrs (
map
(entry: {
name = "xpra${
builtins.substring 0 12 (builtins.hashString "sha256" "${entry.name} (${entry.comment})")
}";
value = entry // {
type = "Application";
terminal = false;
genericName = entry.comment;
};
})
(
concatMap (
host:
let
uri = "tcp://${host}:15151/7";
in
[
{
name = "Xpra - Attach";
comment = host;
exec = "xpra attach --min-quality=100 --min-speed=100 --encoding=png --speaker=off ${uri}";
}
{
name = "Xpra - Detach";
comment = host;
exec = "xpra detach ${uri}";
}
]
) cfg.hosts
)
)
);
};
}
-14
View File
@@ -1,14 +0,0 @@
{
lib,
config,
pkgs,
...
}:
{
config = {
time.timeZone = "Europe/Amsterdam";
i18n.defaultLocale = "en_US.UTF-8";
console.keyMap = "us";
};
}
-23
View File
@@ -1,23 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.neovim;
in
{
options.modules.neovim = {
enable = mkEnableOption "neovim";
};
config = mkIf cfg.enable {
programs.neovim = {
enable = true;
defaultEditor = true;
};
};
}
-25
View File
@@ -1,25 +0,0 @@
{
lib,
config,
...
}:
with lib;
let
cfg = config.modules.networkmanager;
in
{
options.modules.networkmanager = {
enable = mkEnableOption "networkmanager";
};
config = mkIf cfg.enable {
machine.sudo-groups = [ "networkmanager" ];
networking = {
networkmanager = {
enable = true;
wifi.powersave = true;
};
};
};
}
+18
View File
@@ -0,0 +1,18 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.bluetooth;
in
{
options.modules.bluetooth = {
enable = mkEnableOption "bluetooth";
};
config = mkIf cfg.enable {
# Enable bluetooth
hardware.bluetooth = {
enable = true;
powerOnBoot = true;
};
};
}
+23
View File
@@ -0,0 +1,23 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.bootloader;
in
{
options.modules.bootloader = {
enable = mkEnableOption "bootloader";
};
config = mkIf cfg.enable {
# Bootloader
boot.loader = {
timeout = 0;
systemd-boot.enable = true;
systemd-boot.editor = false;
efi.canTouchEfiVariables = true;
};
# Initrd
boot.initrd.systemd.enable = true;
};
}
+26
View File
@@ -0,0 +1,26 @@
{
lib,
config,
inputs,
...
}:
with lib;
let
cfg = config.modules.disko;
profile = import "${inputs.self}/profiles/disko/${cfg.profile}.nix";
in
{
options.modules.disko = {
enable = mkEnableOption "Disko module";
profile = mkOption {
type = types.str;
default = null;
description = "The profile to use for the disko module.";
};
};
config = mkIf cfg.enable {
disko.devices = profile.disko.devices;
};
}
+218
View File
@@ -0,0 +1,218 @@
{
inputs,
lib,
pkgs,
config,
...
}:
with lib;
let
cfg = config.modules.domain;
domain = inputs.secrets.lab.domain;
domainUpper = lib.strings.toUpper domain;
in
{
options.modules.domain = {
enable = mkEnableOption "Domain Integration";
join = {
userFile = mkOption {
type = types.str;
description = "File containing the user used to join the computer.";
};
passwordFile = mkOption {
type = types.str;
description = "File containing the password for the join user.";
};
domainOUFile = mkOption {
type = types.str;
description = "The OU to join the computer to.";
};
};
};
config = mkIf cfg.enable {
# Set network domain
networking.domain = domain;
networking.search = [ domain ];
# Automatically join the domain
systemd.services.adcli-join = {
description = "Automatically join the domain";
wantedBy = [ "default.target" ];
before = [ "sssd.service" ];
requiredBy = [ "sssd.service" ];
after = [
"network-online.target"
];
requires = [
"network-online.target"
];
serviceConfig = {
Type = "oneshot";
};
script = ''
ADCLI_JOIN_USER=$(cat ${cfg.join.userFile})
ADCLI_JOIN_OU=$(cat ${cfg.join.domainOUFile})
${pkgs.adcli}/bin/adcli join -D ${domain} \
-U $ADCLI_JOIN_USER \
-O $ADCLI_JOIN_OU \
--dont-expire-password=true \
--stdin-password < ${cfg.join.passwordFile}
'';
};
# Set up Kerberos
security.krb5 = {
enable = true;
settings = {
libdefaults = {
default_realm = domainUpper;
};
realms.${domainUpper} = {
};
domain_realm = {
"${domain}" = domainUpper;
".${domain}" = domainUpper;
};
};
};
# Set up SSSD
services.sssd = {
enable = true;
config = ''
[sssd]
domains = ${domain}
config_file_version = 2
services = nss, pam
[nss]
filter_users = ${concatStringsSep "," (lib.attrNames config.users.users)}
filter_groups = ${concatStringsSep "," (lib.attrNames config.users.groups)}
[domain/${domain}]
enumerate = False
ad_domain = ${domain}
krb5_realm = ${domainUpper}H
id_provider = ad
auth_provider = ad
access_provider = ad
chpass_provider = ad
use_fully_qualified_names = False
ldap_schema = ad
ldap_id_mapping = True
ad_gpo_access_control = enforcing
ad_gpo_implicit_deny = True
dyndns_update = True
dyndns_update_ptr = False
dyndns_refresh_interval = 86400
dyndns_ttl = 3600
'';
};
security.pam.services.login.sssdStrictAccess = true;
security.pam.services.sshd.sssdStrictAccess = true;
security.pam.services.su.sssdStrictAccess = true;
# Set up Sudo
security.sudo =
let
admin_group = "host_${lib.replaceStrings [ "-" ] [ "_" ] config.networking.hostName}_admin";
in
{
extraConfig = ''
%${admin_group} ALL=(ALL) SETENV: ALL
'';
};
# Set up SSH
programs.ssh = {
package = pkgs.openssh_gssapi;
extraConfig = ''
GSSAPIAuthentication yes
'';
};
services.openssh = {
package = pkgs.openssh_gssapi;
settings = {
GSSAPIAuthentication = true;
GSSAPICleanupCredentials = true;
GSSAPIStrictAcceptorCheck = true;
};
};
# Set up home directory
security.pam.services.login.makeHomeDir = true;
security.pam.services.sshd.makeHomeDir = true;
security.pam.services.su.makeHomeDir = true;
environment.etc.profile.text =
let
# TODO: Activate configuration based on AD group
homeConfiguration = inputs.home-manager.lib.homeManagerConfiguration {
inherit pkgs;
modules = [
(
{ lib, ... }:
{
home.stateVersion = "24.11";
home.username = "$USER";
home.homeDirectory = "/.$HOME";
modules.profiles.base.enable = true;
# Mount the directories from the network share
# home.activation.dirMount =
# let
# bindScript = dir: ''
# mkdir -p /network/$USER/${dir}
# mkdir -p $HOME/${dir}
# ${pkgs.bindfs}/bin/bindfs /network/$USER/${dir} $HOME/${dir}
# '';
# in
# lib.hm.dag.entryAfter [ "writeBoundary" ] ''
# if ! ${pkgs.krb5}/bin/klist -s; then
# echo "No kerberos ticket found"
# ${pkgs.krb5}/bin/kinit
# fi
# if ${pkgs.krb5}/bin/klist -s; then
# echo "Kerberos ticket found, mounting home directory"
# ${bindScript "Documents"}
# ${bindScript "Music"}
# ${bindScript "Pictures"}
# ${bindScript "Video"}
# else
# echo "Still no kerberos ticket found, skipping home directory mount"
# fi
# '';
}
)
] ++ config.home-manager.sharedModules;
};
in
mkAfter ''
# Activate Home Manager configuration for domain users
if id | egrep -o 'groups=.*' | sed 's/,/\n/g' | cut -d'(' -f2 | sed 's/)//' | egrep -o "^domain users$"; then
echo "Setting up environment for domain user"
SKIP_SANITY_CHECKS=1 ${homeConfiguration.activationPackage}/activate
if test -f "$HOME/.bashrc"; then
. $HOME/.bashrc
fi
fi
'';
# Automatically mount home share
# Can be accessed at /network/$USER
# services.autofs = {
# enable = true;
# autoMaster =
# let
# networkMap = pkgs.writeText "auto" ''
# * -fstype=cifs,sec=krb5,user=&,uid=$UID,gid=$GID,cruid=$UID ://${inputs.secrets.lab.nas.host}/home
# '';
# in
# ''
# /network ${networkMap} --timeout=30
# '';
# };
};
}
+41
View File
@@ -0,0 +1,41 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.fonts;
in
{
options.modules.fonts = {
enable = mkEnableOption "fonts";
};
config = mkIf cfg.enable {
console.packages = [
pkgs.dina-psfu
];
console.font = "dina";
console.earlySetup = true;
fonts.packages = with pkgs; [
noto-fonts
fira
jetbrains-mono
];
# TODO: Disable default fonts, fonts should be managed per user
# fonts.enableDefaultPackages = false;
# fonts.fontconfig = {
# enable = true;
# defaultFonts = {
# serif = mkDefault [ ];
# sansSerif = mkDefault [ ];
# monospace = mkDefault [ ];
# emoji = mkDefault [ ];
# };
# };
};
}
+65
View File
@@ -0,0 +1,65 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.gnome;
in
{
options.modules.gnome = {
enable = mkEnableOption "gnome";
# TODO: Add RDP toggle
};
config = mkIf cfg.enable {
# Enable GDM and Gnome
services.displayManager.gdm.enable = true;
services.desktopManager.gnome.enable = true;
services.gnome.core-apps.enable = false;
services.gnome.games.enable = false;
services.gnome.core-developer-tools.enable = false;
environment.gnome.excludePackages = with pkgs; [
adwaita-icon-theme
(derivation { name = "nixos-background-info"; })
gnome-backgrounds
gnome-bluetooth
gnome-color-manager
gnome-shell-extensions
gnome-tour
gnome-user-docs
glib
gnome-menus
gtk3.out
];
# For GSConnect/KDE Connect
# TODO: Move to host config?
networking.firewall = {
allowedTCPPortRanges = [
{
from = 1714;
to = 1764;
}
];
allowedUDPPortRanges = [
{
from = 1714;
to = 1764;
}
];
};
# Enable dependencies
modules.networkmanager.enable = true;
# Impermanence
modules.impermanence.directories = [
"/etc/NetworkManager/system-connections"
"/var/lib/bluetooth"
];
};
}
+26
View File
@@ -0,0 +1,26 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.graphics;
in
{
options.modules.graphics = {
enable = mkEnableOption "graphics";
# TODO: Add toggle for hybrid graphics
};
config = mkIf cfg.enable {
hardware.graphics.enable = true;
hardware.graphics.enable32Bit = true;
services.xserver.videoDrivers = [ "nvidia" ];
# TODO: Add nvidia settings back in
# TODO: Move to nvidia module
hardware.nvidia = {
open = false;
prime = {
intelBusId = "PCI:0@0:2:0";
nvidiaBusId = "PCI:1@0:0:0";
};
};
};
}
+81
View File
@@ -0,0 +1,81 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.impermanence;
in
{
options.modules.impermanence = {
enable = mkEnableOption "Impermanence";
directories = mkOption {
type = types.listOf types.str;
default = [ ];
description = ''
Directories that should be stored in persistent storage.
'';
};
files = mkOption {
type = types.listOf types.str;
default = [ ];
description = ''
Files that should be stored in persistent storage.
'';
};
resetScript = mkOption {
type = types.lines;
description = ''
Script to run in order to reset the system to a clean state.
'';
};
};
config = mkIf cfg.enable {
# Filesystem setup
fileSystems."/persist".neededForBoot = true;
# boot.initrd.postResumeCommands = mkAfter cfg.resetScript;
# TODO: Reduce dependency on the root filesystem being ZFS?
boot.initrd.systemd.services.impermanence-rollback = {
description = "Rollback filesystem to clean state.";
wantedBy = [ "initrd.target" ];
after = [ "zfs-import.target" ];
before = [ "sysroot.mount" ];
unitConfig.DefaultDependencies = "no";
serviceConfig.Type = "oneshot";
script = cfg.resetScript;
};
# For home-manager persistence
programs.fuse.userAllowOther = true;
# For testing purposes with VM
virtualisation.vmVariantWithDisko.virtualisation.fileSystems."/persist".neededForBoot = true;
environment.persistence = {
"/persist/system" = {
enable = true;
hideMounts = true;
directories = cfg.directories;
files = cfg.files;
};
# "/persist/home" = {
# enable = true;
# hideMounts = true;
# users = (
# lib.mapAttrs' (
# name: value:
# let
# user = name;
# homeDir = "/home/${user}";
# impConfig = value.modules.impermanence;
# in
# lib.nameValuePair user {
# home = homeDir;
# directories = impConfig.directories;
# files = impConfig.files;
# }
# ) config.home-manager.users
# );
# };
};
};
}
+17
View File
@@ -0,0 +1,17 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.networkmanager;
in
{
options.modules.networkmanager = {
enable = mkEnableOption "networkmanager";
};
config = mkIf cfg.enable {
# TODO: Add sudo users to the networkmanager group?
networking.networkmanager.enable = true;
networking.firewall.checkReversePath = false;
};
}
+20
View File
@@ -0,0 +1,20 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.power-saving;
in
{
options.modules.power-saving = {
enable = mkEnableOption "power saving";
};
config = mkIf cfg.enable {
# Setup power management
powerManagement.enable = true;
services.thermald.enable = true;
services.power-profiles-daemon.enable = true;
# Enable wifi power saving
networking.networkmanager.wifi.powersave = true;
};
}
+25
View File
@@ -0,0 +1,25 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.printing;
in
{
options.modules.printing = {
enable = mkEnableOption "printing";
};
config = mkIf cfg.enable {
# Enable CUPS
services.printing.enable = true;
# Enable Avahi to auto-detect network printers
services.avahi = {
enable = true;
nssmdns4 = true;
openFirewall = true;
};
# For SMB network printers
services.samba.enable = true;
};
}
+44
View File
@@ -0,0 +1,44 @@
{
inputs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.secrets;
secrets = inputs.secrets;
in
{
options.modules.secrets = {
enable = mkEnableOption "secrets";
defaultFile = mkOption {
type = types.str;
default = "${secrets}/secrets/common.enc.yaml";
description = ''
The default file to use for SOPS.
'';
};
secrets = mkOption {
type = types.attrs;
default = { };
description = ''
All secrets that should be made available.
'';
};
};
config = mkIf cfg.enable {
# Set up SOPS
# TODO: Fix the key not being present in /etc/sops before sops-nix runs
sops.defaultSopsFile = cfg.defaultFile;
sops.age.sshKeyPaths = [
"/etc/sops/sops_ed25519_key"
"/persist/system/etc/sops/sops_ed25519_key"
];
sops.secrets = cfg.secrets;
modules.impermanence.directories = [ "/etc/sops" ];
virtualisation.vmVariantWithDisko.sops.age.sshKeyPaths = [ "/tmp/shared/sops_ed25519_key" ];
};
}
+24
View File
@@ -0,0 +1,24 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.sound;
in
{
options.modules.sound = {
enable = mkEnableOption "sound";
};
config = mkIf cfg.enable {
# Enable pipewire
services.pipewire = {
enable = true;
alsa.enable = true;
alsa.support32Bit = true;
pulse.enable = true;
jack.enable = true;
};
# Recommended by wiki, allows user processes to use realtime kernel
security.rtkit.enable = true;
};
}
+32
View File
@@ -0,0 +1,32 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.ssh;
in
{
options.modules.ssh = {
enable = mkEnableOption "ssh";
};
config = mkIf cfg.enable {
services.openssh = {
enable = true;
settings = {
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;
PermitRootLogin = "no";
};
hostKeys = mkIf (config.modules.impermanence.enable) [
{
type = "ed25519";
path = "/persist/system/etc/ssh/ssh_host_ed25519_key";
}
{
type = "rsa";
bits = 4096;
path = "/persist/system/etc/ssh/ssh_host_rsa_key";
}
];
};
};
}
-36
View File
@@ -1,36 +0,0 @@
{
lib,
config,
...
}:
with lib;
let
cfg = config.modules.power-saving;
in
{
options.modules.power-saving = {
enable = mkEnableOption "power-saving";
};
config = mkIf cfg.enable {
powerManagement.enable = true;
services.thermald.enable = true;
services.tlp = {
enable = true;
settings = {
CPU_SCALING_GOVERNOR_ON_AC = "performance";
CPU_SCALING_GOVERNOR_ON_BAT = "powersave";
CPU_ENERGY_PERF_POLICY_ON_BAT = "power";
CPU_ENERGY_PERF_POLICY_ON_AC = "performance";
CPU_MIN_PERF_ON_AC = 0;
CPU_MAX_PERF_ON_AC = 100;
CPU_MIN_PERF_ON_BAT = 0;
CPU_MAX_PERF_ON_BAT = 20;
};
};
};
}
-24
View File
@@ -1,24 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.pipewire;
in
{
options.modules.pipewire = {
enable = mkEnableOption "pipewire";
};
config = mkIf cfg.enable {
services.pipewire = {
enable = true;
alsa.enable = true;
pulse.enable = true;
};
};
}
-24
View File
@@ -1,24 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.unfree;
in
{
options.modules.unfree = {
enable = mkEnableOption "unfree";
allowedPackages = mkOption {
type = types.listOf types.str;
default = [ ];
};
};
config = mkIf cfg.enable {
nixpkgs.config.allowUnfreePredicate = pkg: builtins.elem (getName pkg) cfg.allowedPackages;
};
}
-82
View File
@@ -1,82 +0,0 @@
{
config,
lib,
pkgs,
...
}:
with lib;
let
# User configuration
userModule = types.submodule {
options = {
sudo = mkOption {
type = types.bool;
default = false;
example = true;
description = "Whether the user is allowed sudo access.";
};
configuration = mkOption {
type = types.path;
default = ./users/base.nix;
description = "What home manager configuration to use for this user.";
};
desktopInit = mkOption {
type = types.lines;
default = "";
description = "Bash script to execute after initial log in.";
};
};
};
in
{
imports = [
# Import home manager
# <home-manager/nixos>
# Import system wide configuration required for user modules
../../user-modules/systemwide/default.nix
];
options = {
machine.sudo-groups = mkOption {
type = types.listOf types.str;
default = [ ];
description = "Groups assigned to sudo users.";
};
machine.users = mkOption {
type = types.attrsOf userModule;
default = { };
description = "Users configured on this system.";
};
};
config = {
# Add required home manager modules
home-manager.sharedModules = [
# Modules
../../user-modules/default.nix
# Custom packages
../../pkgs/default.nix
];
# Create users
users.users = attrsets.concatMapAttrs (name: value: {
${name} = {
isNormalUser = true;
extraGroups = mkIf value.sudo (
[
"wheel"
]
++ config.machine.sudo-groups
);
};
}) config.machine.users;
# Create home manager configuration for users
home-manager.users = attrsets.concatMapAttrs (name: value: {
${name} = value.configuration;
}) config.machine.users;
};
}
-23
View File
@@ -1,23 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.tailscale;
in
{
options.modules.tailscale = {
enable = mkEnableOption "tailscale";
};
config = mkIf cfg.enable {
services.tailscale = {
enable = true;
useRoutingFeatures = "client";
};
};
}
-24
View File
@@ -1,24 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.wpa_supplicant;
in
{
options.modules.wpa_supplicant = {
enable = mkEnableOption "wpa_supplicant";
};
config = mkIf cfg.enable {
networking.wireless = {
enable = true;
userControlled.enable = true;
allowAuxiliaryImperativeNetworks = true;
};
};
}
+19
View File
@@ -0,0 +1,19 @@
{ pkgs, ... }:
with pkgs;
rustPlatform.buildRustPackage {
pname = "carla_osc_bridge";
version = "master";
src = fetchFromGitea {
domain = "git.bulthuis.dev";
owner = "Jan";
repo = "carla_osc_bridge";
rev = "c037e2d2a1b29b785d8acc10fa0cb761afdb3fcf";
hash = "sha256-Wvdfm+4dfygZwkvaUhO9w7DrrUl3ZYvtD7nYrPSD0eA=";
};
cargoHash = "sha256-s1ZKbhHudgPOy7613zbT8TkbM6B7oloLEuTYHoWjX5o=";
useFetchCargoVendor = true;
}
+73
View File
@@ -0,0 +1,73 @@
{
pkgs,
...
}:
pkgs.stdenv.mkDerivation {
pname = "dina-psfu";
version = "1.0.0";
src = pkgs.fetchzip {
url = "https://www.dcmembers.com/jibsen/download/61/?wpdmdl=61";
hash = "sha256-JK+vnOyhAbwT825S+WKbQuWgRrfZZHfyhaMQ/6ljO8s=";
extension = "zip";
stripRoot = false;
};
buildInputs = with pkgs; [
bdf2psf
fontforge
];
buildPhase = ''
# Get the base Dina font
cp BDF/Dina_r400-9.bdf ./dina.bdf
# Set the AVERAGE_WIDTH property on the font
sed 's/STARTPROPERTIES 16/STARTPROPERTIES 17\
AVERAGE_WIDTH 70/' ./dina.bdf > ./dina-mod.bdf
# Reencode the font from code page CP1252 (Windows) to unicode
fontforge -lang=ff -c "Open(\"dina-mod.bdf\"); Reencode(\"win\", 1); Reencode(\"iso10646-1\"); Generate(\"dina-enc.bdf\")"
mv dina-enc-*.bdf dina-enc.bdf
# Move the artsy characters around
sed -i 's/STARTCHAR uni000E$/STARTCHAR uni2518/' ./dina-enc.bdf
sed -i 's/ENCODING 14$/ENCODING 9496/' ./dina-enc.bdf
sed -i 's/STARTCHAR uni000F$/STARTCHAR uni2514/' ./dina-enc.bdf
sed -i 's/ENCODING 15$/ENCODING 9492/' ./dina-enc.bdf
sed -i 's/STARTCHAR uni0010$/STARTCHAR uni250C/' ./dina-enc.bdf
sed -i 's/ENCODING 16$/ENCODING 9484/' ./dina-enc.bdf
sed -i 's/STARTCHAR uni0011$/STARTCHAR uni2510/' ./dina-enc.bdf
sed -i 's/ENCODING 17$/ENCODING 9488/' ./dina-enc.bdf
sed -i 's/STARTCHAR uni0012$/STARTCHAR uni2500/' ./dina-enc.bdf
sed -i 's/ENCODING 18$/ENCODING 9472/' ./dina-enc.bdf
sed -i 's/STARTCHAR uni0013$/STARTCHAR uni2502/' ./dina-enc.bdf
sed -i 's/ENCODING 19$/ENCODING 9474/' ./dina-enc.bdf
sed -i 's/STARTCHAR uni0014$/STARTCHAR uni2524/' ./dina-enc.bdf
sed -i 's/ENCODING 20$/ENCODING 9508/' ./dina-enc.bdf
sed -i 's/STARTCHAR uni0015$/STARTCHAR uni2534/' ./dina-enc.bdf
sed -i 's/ENCODING 21$/ENCODING 9524/' ./dina-enc.bdf
sed -i 's/STARTCHAR uni0016$/STARTCHAR uni251C/' ./dina-enc.bdf
sed -i 's/ENCODING 22$/ENCODING 9500/' ./dina-enc.bdf
sed -i 's/STARTCHAR uni0017$/STARTCHAR uni252C/' ./dina-enc.bdf
sed -i 's/ENCODING 23$/ENCODING 9516/' ./dina-enc.bdf
sed -i 's/STARTCHAR uni0018$/STARTCHAR uni253C/' ./dina-enc.bdf
sed -i 's/ENCODING 24$/ENCODING 9532/' ./dina-enc.bdf
sed -i 's/STARTCHAR uni0019$/STARTCHAR uni2592/' ./dina-enc.bdf
sed -i 's/ENCODING 25$/ENCODING 9618/' ./dina-enc.bdf
# Create the equivalents file
touch empty.equivalents
# Convert the bdf to psf
bdf2psf --fb ./dina-enc.bdf \
./empty.equivalents \
${pkgs.bdf2psf}/share/bdf2psf/fontsets/Uni2.512 \
512 ./dina.psfu ./dina.sfm
'';
installPhase = ''
install -Dm644 -t $out/share/consolefonts dina.psfu
'';
}
+37
View File
@@ -0,0 +1,37 @@
{
jq,
lib,
moreutils,
tinymist,
vscode-utils,
}:
vscode-utils.buildVscodeMarketplaceExtension {
mktplcRef = {
name = "tinymist-vscode-html";
publisher = "myriad-dreamin";
inherit (tinymist) version;
hash = "";
};
nativeBuildInputs = [
jq
moreutils
];
buildInputs = [ tinymist ];
postInstall = ''
cd "$out/$installPrefix"
jq '.contributes.configuration.properties."tinymist.serverPath".default = "${lib.getExe tinymist}"' package.json | sponge package.json
'';
meta = {
changelog = "https://marketplace.visualstudio.com/items/myriad-dreamin.tinymist/changelog";
description = "VSCode extension for providing an integration solution for Typst";
downloadPage = "https://marketplace.visualstudio.com/items?itemName=myriad-dreamin.tinymist";
homepage = "https://github.com/myriad-dreamin/tinymist";
license = lib.licenses.asl20;
maintainers = [ ];
};
}
+104
View File
@@ -0,0 +1,104 @@
{
lib,
buildNpmPackage,
fetchFromGitHub,
makeBinaryWrapper,
makeDesktopItem,
copyDesktopItems,
nodejs_20,
electron,
python3,
nix-update-script,
}:
buildNpmPackage rec {
pname = "open-stage-control";
version = "1.29.8";
src = fetchFromGitHub {
owner = "jean-emmanuel";
repo = "open-stage-control";
rev = "v${version}";
hash = "sha256-518KXvNffLOV2aIWlLJcnPzxEbWxYdjWeiDBC1jlecQ=";
};
# Remove some Electron stuff from package.json
postPatch = ''
sed -i -e '/"electron"\|"electron-installer-debian"/d' package.json
'';
npmDepsHash = "sha256-U4zwYL5URNW0y0W4WvWAVL0hubiiU+2z9F5mDE9l8UU=";
nodejs = nodejs_20;
nativeBuildInputs = [
copyDesktopItems
makeBinaryWrapper
];
buildInputs = [
python3.pkgs.python-rtmidi
];
doInstallCheck = true;
makeCacheWritable = true;
npmFlags = [
"--legacy-peer-deps"
"--skip-pkg"
];
# Override installPhase so we can copy the only directory that matters (app)
installPhase = ''
runHook preInstall
# copy built app and node_modules directories
mkdir -p $out/lib/node_modules/open-stage-control
cp -r app $out/lib/node_modules/open-stage-control/
# copy icon
install -Dm644 resources/images/logo.png $out/share/icons/hicolor/256x256/apps/open-stage-control.png
install -Dm644 resources/images/logo.svg $out/share/icons/hicolor/scalable/apps/open-stage-control.svg
# wrap electron and include python-rtmidi
makeWrapper '${electron}/bin/electron' $out/bin/open-stage-control \
--inherit-argv0 \
--add-flags $out/lib/node_modules/open-stage-control/app \
--prefix PYTHONPATH : "$PYTHONPATH" \
--prefix PATH : '${lib.makeBinPath [ python3 ]}'
runHook postInstall
'';
installCheckPhase = ''
XDG_CONFIG_HOME="$(mktemp -d)" $out/bin/open-stage-control --help
'';
desktopItems = [
(makeDesktopItem {
name = "open-stage-control";
exec = "open-stage-control";
icon = "open-stage-control";
desktopName = "Open Stage Control";
comment = meta.description;
categories = [
"Network"
"Audio"
"AudioVideo"
"Midi"
];
startupWMClass = "open-stage-control";
})
];
passthru.updateScript = nix-update-script { };
meta = with lib; {
description = "Libre and modular OSC / MIDI controller";
homepage = "https://openstagecontrol.ammd.net/";
license = licenses.gpl3Only;
maintainers = [ ];
platforms = platforms.linux;
mainProgram = "open-stage-control";
};
}
-14
View File
@@ -1,14 +0,0 @@
{
...
}:
{
nixpkgs.config = {
packageOverrides = pkgs: {
dina-vector = pkgs.callPackage ./fonts/dina-vector.nix { };
wqy-zenhei = pkgs.callPackage ./fonts/wqy-zenhei.nix { };
wqy-microhei = pkgs.callPackage ./fonts/wqy-microhei.nix { };
wqy-bitmapsong = pkgs.callPackage ./fonts/wqy-bitmapsong.nix { };
};
};
}
-30
View File
@@ -1,30 +0,0 @@
{
pkgs,
...
}:
pkgs.stdenv.mkDerivation {
pname = "dina-font";
version = "1.0.0";
# src = pkgs.fetchurl {
# url = "mirror://sourceforge/wqy/${pname}-${version}.tar.gz";
# # hash = "sha256-r2Vf7ftJCqu7jOc2AqCKaoR/r8eNw2P/OQGqbDOEyl0=";
# hash = "sha256-0uvwkRUbvJ0remTnlP8dElRjaBVd6iukNYBTE/CTO7s=";
# };
unpackPhase = "true";
buildInputs = [
pkgs.fontforge
pkgs.dina-font
pkgs.wqy-bitmapsong
pkgs.tree
];
buildPhase = ''
tree > debug.txt
'';
installPhase = ''
install -Dm644 $out/debug.txt
'';
}
-36
View File
@@ -1,36 +0,0 @@
{
pkgs,
...
}:
pkgs.stdenv.mkDerivation rec {
pname = "wqy-bitmapsong-pcf";
version = "1.0.0-RC1";
src = pkgs.fetchurl {
url = "mirror://sourceforge/wqy/${pname}-${version}.tar.gz";
# hash = "sha256-r2Vf7ftJCqu7jOc2AqCKaoR/r8eNw2P/OQGqbDOEyl0=";
hash = "sha256-0uvwkRUbvJ0remTnlP8dElRjaBVd6iukNYBTE/CTO7s=";
};
buildInputs = [ pkgs.fontforge ];
buildPhase = ''
newName() {
test "''${1:5:1}" = i && _it=Italic || _it=
case ''${1:6:3} in
400) test -z $it && _weight=Medium ;;
700) _weight=Bold ;;
esac
_pt=''${1%.pcf}
_pt=''${_pt#*-}
echo "WenQuanYi_Bitmap_Song$_weight$_it$_pt"
}
for i in *.pcf; do
fontforge -lang=ff -c "Open(\"$i\"); Generate(\"$(newName $i).otb\")"
done
'';
installPhase = ''
install -Dm644 *.otb -t $out/share/fonts/
'';
}
-22
View File
@@ -1,22 +0,0 @@
{
pkgs,
...
}:
pkgs.stdenv.mkDerivation rec {
pname = "wqy-microhei";
version = "0.2.0-beta";
src = pkgs.fetchurl {
url = "mirror://sourceforge/wqy/${pname}-${version}.tar.gz";
hash = "sha256-KAKsgCOqNqZupudEWFTjoHjTd///QhaTQb0jeHH3IT4=";
};
installPhase = ''
runHook preInstall
install -Dm644 *.ttc -t $out/share/fonts/
runHook postInstall
'';
}
-22
View File
@@ -1,22 +0,0 @@
{
pkgs,
...
}:
pkgs.stdenv.mkDerivation rec {
pname = "wqy-zenhei";
version = "0.9.45";
src = pkgs.fetchurl {
url = "mirror://sourceforge/wqy/${pname}-${version}.tar.gz";
hash = "sha256-5LfjBkdb+UJ9F1dXjw5FKJMMhMROqj8WfUxC8RDuddY=";
};
installPhase = ''
runHook preInstall
install -Dm644 *.ttc -t $out/share/fonts/
runHook postInstall
'';
}
+82
View File
@@ -0,0 +1,82 @@
{
disko.devices = {
disk = {
main = {
type = "disk";
device = "/dev/sda";
imageSize = "32G"; # For test VMs
content = {
type = "gpt";
partitions = {
boot = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
zfs = {
end = "-4G";
content = {
type = "zfs";
pool = "tank";
};
};
swap = {
size = "100%";
content = {
type = "swap";
discardPolicy = "both";
};
};
};
};
};
longhorn = {
type = "disk";
device = "/dev/sdb";
imageSize = "64G"; # For longhorn storage
content = {
type = "gpt";
partitions = {
main = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
};
};
};
};
};
};
zpool = {
tank = {
type = "zpool";
rootFsOptions = {
compression = "zstd";
};
mountpoint = null;
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
datasets = {
root = {
type = "zfs_fs";
mountpoint = "/";
};
nix = {
type = "zfs_fs";
mountpoint = "/nix";
};
persist = {
type = "zfs_fs";
mountpoint = "/persist";
};
};
};
};
};
}
+65
View File
@@ -0,0 +1,65 @@
{
disko.devices = {
disk = {
main = {
type = "disk";
device = "/dev/sda";
imageSize = "32G"; # For test VMs
content = {
type = "gpt";
partitions = {
boot = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
zfs = {
end = "-4G";
content = {
type = "zfs";
pool = "tank";
};
};
swap = {
size = "100%";
content = {
type = "swap";
discardPolicy = "both";
};
};
};
};
};
};
zpool = {
tank = {
type = "zpool";
rootFsOptions = {
compression = "zstd";
};
mountpoint = null;
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
datasets = {
root = {
type = "zfs_fs";
mountpoint = "/";
};
nix = {
type = "zfs_fs";
mountpoint = "/nix";
};
persist = {
type = "zfs_fs";
mountpoint = "/persist";
};
};
};
};
};
}
+65
View File
@@ -0,0 +1,65 @@
{
disko.devices = {
disk = {
main = {
type = "disk";
device = "/dev/sda"; # How do I handle this for laptops
imageSize = "64G"; # For test VMs
content = {
type = "gpt";
partitions = {
boot = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
zfs = {
end = "-16G";
content = {
type = "zfs";
pool = "tank";
};
};
swap = {
size = "100%";
content = {
type = "swap";
discardPolicy = "both";
};
};
};
};
};
};
zpool = {
tank = {
type = "zpool";
rootFsOptions = {
compression = "zstd";
};
mountpoint = null;
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
datasets = {
root = {
type = "zfs_fs";
mountpoint = "/";
};
nix = {
type = "zfs_fs";
mountpoint = "/nix";
};
persist = {
type = "zfs_fs";
mountpoint = "/persist";
};
};
};
};
};
}
+65
View File
@@ -0,0 +1,65 @@
{
disko.devices = {
disk = {
main = {
type = "disk";
device = "/dev/sda";
imageSize = "64G"; # For test VMs
content = {
type = "gpt";
partitions = {
boot = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
zfs = {
end = "-16G";
content = {
type = "zfs";
pool = "tank";
};
};
swap = {
size = "100%";
content = {
type = "swap";
discardPolicy = "both";
};
};
};
};
};
};
zpool = {
tank = {
type = "zpool";
rootFsOptions = {
compression = "zstd";
};
mountpoint = null;
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
datasets = {
root = {
type = "zfs_fs";
mountpoint = "/";
};
nix = {
type = "zfs_fs";
mountpoint = "/nix";
};
persist = {
type = "zfs_fs";
mountpoint = "/persist";
};
};
};
};
};
}
+32
View File
@@ -0,0 +1,32 @@
{
pkgs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.profiles.base;
in
{
options.modules.profiles.base = {
enable = mkEnableOption "Base home-manager profile";
};
config = mkIf cfg.enable {
modules = {
impermanence.enable = true;
# btop.enable = true;
direnv.enable = true;
fish.enable = true;
# scripts.enable = true;
# Development
# neovim.enable = true;
# Languages
nix.enable = true;
};
};
}
+102
View File
@@ -0,0 +1,102 @@
{
pkgs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.profiles.gnome;
in
{
options.modules.profiles.gnome = {
enable = mkEnableOption "Graphical GNOME environment";
};
config = mkIf cfg.enable {
home.packages = with pkgs; [
# firefox # TODO: Move to dediated module
];
dconf.settings = {
"org/gnome/calendar" = {
active-view = "week";
};
"org/gnome/desktop/background" = {
picture-uri = "file://${config.home.homeDirectory}/.local/share/backgrounds/background";
};
"org/gnome/desktop/input-sources" = {
sources = [
(lib.gvariant.mkTuple [
"xkb"
"us"
])
];
xkb-options = [ "caps:escape_shifted_capslock" ];
};
"org/gnome/desktop/interface" = {
accent-color = "purple";
enable-hot-corners = false;
};
"org/gnome/desktop/peripherals/touchpad" = {
speed = 0.214;
two-finger-scrolling-enabled = true;
};
"org/gnome/mutter" = {
workspaces-only-on-primary = true;
};
"org/gnome/nautilus/icon-view" = {
default-zoom-level = "small";
};
"org/gnome/nautilus/preferences" = {
default-folder-viewer = "icon-view";
};
"org/gnome/settings-daemon/plugins/color" = {
night-light-enabled = true;
night-light-schedule-automatic = false;
night-light-schedule-from = 20.0;
night-light-schedule-to = 6.0;
night-light-temperature = 2700;
};
"org/gnome/shell" = {
disable-extension-version-validation = true;
enabled-extensions = [
"disable-workspace-animation@ethnarque"
"gsconnect@andyholmes.github.io"
"rounded-window-corners@fxgn"
"media-progress@krypion17"
"mprisLabel@moon-0xff.github.com"
"caffeube@patapon.info"
];
last-selected-power-profile = "power-saver";
};
};
modules = {
profiles.base.enable = true;
# Desktop environment
desktop.gnome.enable = true;
# desktop.tiling.enable = true;
# Browser
# firefox = {
# enable = true;
# default = false;
# };
# qutebrowser = {
# enable = true;
# default = true;
# };
# Tools
# obsidian.enable = true;
# zathura.enable = true;
# Development
# neovim.enable = true;
vscode.enable = true;
};
};
}
+286
View File
@@ -0,0 +1,286 @@
{
pkgs,
pkgs-stable,
lib,
config,
inputs,
...
}:
with lib;
let
cfg = config.modules.profiles.jan;
in
{
options.modules.profiles.jan = {
enable = mkEnableOption "Jan's personal profile";
};
config = mkIf cfg.enable {
home.packages = with pkgs; [
firefox
# inputs.stable-nixpkgs.legacyPackages.${config.nixpkgs.hostPlatform}.libreoffice
libreoffice
remmina
thunderbird
signal-desktop
prusa-slicer
pkgs-stable.freecad-wayland
inkscape
# ente-auth
audacity
carla
# pkgs-stable.winbox
winbox4
# whatsapp-for-linux
karere
discord
steam
spotify
# feishin
eduvpn-client
ryubing
bottles
prismlauncher
foliate
wireshark
obsidian
# devenv
# kicad
vlc
authenticator
hotspot
btop
winboat
hieroglyphic
shortwave
podman
podman-compose
gnome-network-displays
gnome-logs
];
programs.zathura = {
enable = true;
options = {
synctex = true;
synctex-editor-command = "${pkgs.texlab}/bin/texlab inverse-search -i %{input} -l %{line}";
};
};
programs.helix = {
enable = true;
defaultEditor = true;
# settings = {
# theme = {
# light = "adwaita-light";
# dark = "adwaita-dark";
# fallback = "default";
# };
# };
settings =
let
move_line_up = [
"extend_to_line_bounds"
"delete_selection"
"move_line_up"
"paste_before"
];
move_line_down = [
"extend_to_line_bounds"
"delete_selection"
"paste_after"
];
in
{
keys.normal = {
"A-up" = move_line_up;
"A-down" = move_line_down;
"A-k" = move_line_up;
"A-j" = move_line_down;
};
keys.select = {
"A-up" = move_line_up;
"A-down" = move_line_down;
"A-k" = move_line_up;
"A-j" = move_line_down;
};
};
extraPackages = with pkgs; [
bash-language-server # Bash
fish-lsp # Fish
systemd-lsp # Systemd
yaml-language-server # Yaml
taplo # Toml
nixd # Nix
protols # Protobuf
dockerfile-language-server # Dockerfile
docker-compose-language-service # Docker compose
clang-tools # C, C++
neocmakelsp # Cmake
rust-analyzer # Rust
lldb # C, C++, Rust
zls # Zig
texlab # Latex
tinymist # Typst
marksman # Markdown
markdown-oxide # Markdown
vscode-langservers-extracted # HTML, CSS, JSON, ESLint
typescript-language-server # Typescript, Javascript
intelephense # PHP
vue-language-server # Vue
ruff # Python
basedpyright # Python
#helix-gpt # Copilot
ltex-ls-plus # Spellchecking
# texlab # Latex, Bibtex
# bibtex-tidy # Bibtex
# docker-langserver # Dockerfile
# docker-compose-langserver # Docker compose
# elixir-ls # Elixir
# gopls # Go
# golangci-lint-langserver # Go
# dlv # Go
# haskell-language-server # Haskell
# julia # Julia
# kotlin-language-server # Kotlin
# lua-language-server # Lua
# slint-lsp # Slint
# tinymist # Typst
];
languages = {
language-server = {
ltex = {
command = "ltex-ls-plus";
config.ltex = { };
};
texlab = {
command = "texlab";
config.texlab = {
build.onSave = true;
forwardSearch.executable = "${config.programs.zathura.package}/bin/zathura";
forwardSearch.args = [
"--synctex-forward"
"%l:1:%f"
"%p"
];
};
};
basedpyright = {
command = "basedpyright-langserver";
args = [ "--stdio" ];
};
tinymist = {
command = "tinymist";
config.preview.background = {
enabled = true;
args = [
"--data-plane-host=127.0.0.1:23635"
"--invert-colors=never"
"--open"
];
};
};
};
language = [
{
name = "latex";
# language-servers = [
# { name = "texlab"; }
# { name = "ltex"; }
# ];
soft-wrap = {
enable = true;
};
}
{
name = "python";
language-servers = [
{
name = "basedpyright";
except-features = [ "diagnostics" ];
}
"ruff"
];
auto-format = true;
formatter = {
command = "ruff";
args = [
"format"
"-"
];
};
}
];
};
};
systemd.user.tmpfiles.rules = [
"d ${config.home.homeDirectory}/Downloads - - - - -"
];
modules = {
profiles.gnome.enable = true;
impermanence = {
directories = [
"Code"
"Documents"
"Games"
"Models"
"Music"
"Pictures"
"Videos"
];
};
# Gaming
# retroarch.enable = true;
# ryujinx.enable = true;
# Tools
git = {
enable = true;
user = "Jan-Bulthuis";
email = "git@bulthuis.dev";
# TODO: Move
ignores = [
".envrc"
".direnv"
"flake.nix"
"flake.lock"
];
};
bitwarden.enable = true;
xpra = {
enable = true;
hosts = [
"mixer@10.20.40.100"
];
};
# Development
# docker.enable = true;
# matlab.enable = true;
# mathematica.enable = true;
# Languages
haskell.enable = false;
js.enable = true;
nix.enable = true;
rust.enable = true;
python.enable = true;
cpp.enable = true;
tex.enable = false;
jupyter.enable = true;
go.enable = true;
};
};
}
+82
View File
@@ -0,0 +1,82 @@
{
pkgs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.profiles.base;
in
{
options.modules.profiles.base = {
enable = mkEnableOption "base profile";
};
config = mkIf cfg.enable {
modules = {
bootloader.enable = mkDefault true;
ssh.enable = mkDefault true;
impermanence = {
files = [
"/etc/machine-id"
"/etc/zfs/zpool.cache" # TODO: Move to zfs module?
];
directories = [
"/var/log/journal"
"/var/lib/nixos"
"/var/lib/systemd"
];
};
# TODO: Remove the secrets module and use sops directly?
secrets = {
enable = true;
secrets = {
"ssh-keys/deploy-priv" = {
path = "/root/.ssh/id_ed25519";
};
};
};
};
# Localization
time.timeZone = "Europe/Amsterdam";
i18n.defaultLocale = "en_US.UTF-8";
console.keyMap = "us";
# Enable neovim
programs.neovim = {
enable = true;
defaultEditor = true;
};
# Enable the usage of flakes
nix.settings.experimental-features = [
"nix-command"
"flakes"
];
# Clean tmp
boot.tmp.cleanOnBoot = true;
# Base packages
environment.systemPackages = with pkgs; [
git
wget
curl
dig
procps
wireguard-tools
usbutils
pciutils
zip
unzip
tmux
unixtools.net-tools
tcpdump
];
};
}
+28
View File
@@ -0,0 +1,28 @@
{
pkgs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.profiles.desktop;
in
{
options.modules.profiles.desktop = {
enable = mkEnableOption "desktop profile";
};
config = mkIf cfg.enable {
modules = {
profiles.base.enable = mkDefault true;
fonts.enable = mkDefault true;
graphics.enable = mkDefault true;
gnome.enable = mkDefault true; # TODO: Rename to display manager?
networkmanager.enable = mkDefault true;
printing.enable = mkDefault true;
sound.enable = mkDefault true;
};
};
}
+30
View File
@@ -0,0 +1,30 @@
{
pkgs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.profiles.laptop;
in
{
options.modules.profiles.laptop = {
enable = mkEnableOption "laptop profile";
};
config = mkIf cfg.enable {
# Setup modules
modules = {
profiles.desktop.enable = mkDefault true;
bluetooth.enable = mkDefault true;
power-saving.enable = mkDefault true;
};
# Add packages
environment.systemPackages = with pkgs; [
brightnessctl
];
};
}
+109
View File
@@ -0,0 +1,109 @@
{
pkgs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.profiles.vm;
in
{
options.modules.profiles.vm = {
enable = mkEnableOption "Base VM profile";
};
config = mkIf cfg.enable {
# Enabled modules
modules = {
profiles.base.enable = true;
disko = {
enable = true;
profile = mkDefault "vm";
};
impermanence = {
enable = true;
resetScript = ''
# Revert to the blank state for the root directory
zfs rollback -r tank/root@blank
'';
};
domain = {
enable = true;
join = {
userFile = config.sops.secrets."vm-join/user".path;
passwordFile = config.sops.secrets."vm-join/password".path;
domainOUFile = config.sops.secrets."vm-join/ou".path;
};
};
ssh.enable = true;
};
# Initialize domain join secrets
sops.secrets."vm-join/user" = { };
sops.secrets."vm-join/password" = { };
sops.secrets."vm-join/ou" = { };
# Autologin to root for access from hypervisor
services.getty.autologinUser = "root";
# Local user
sops.secrets."passwords/local-hashed".neededForUsers = true;
users.mutableUsers = false;
users.users.local = {
isNormalUser = true;
group = "local";
hashedPasswordFile = config.sops.secrets."passwords/local-hashed".path;
extraGroups = [ "wheel" ];
openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKKxoQSxfYqf9ITN8Fhckk8WbY4dwtBAXOhC9jxihJvq Admin"
];
};
users.groups.local = { };
home-manager.users.local =
{ ... }:
{
home.stateVersion = "24.11";
modules.profiles.base.enable = true;
};
# System packages
environment.systemPackages = with pkgs; [
# TODO: Make module for utilities/scripts
(writeShellScriptBin "system-update" "nixos-rebuild switch --flake git+https://git.bulthuis.dev/Jan/nixos-config")
];
# Enable qemu guest agent
services.qemuGuest.enable = true;
# Machine platform
nixpkgs.hostPlatform = "x86_64-linux";
# Set hostid (required for ZFS)
networking.hostId = "deadbeef";
# Hardware configuration
hardware.enableRedistributableFirmware = true;
boot.initrd.availableKernelModules = [
"ata_piix"
"uhci_hcd"
"virtio_net"
"virtio_pci"
"virtio_mmio"
"virtio_blk"
"virtio_scsi"
"9p"
"9pnet_virtio"
"sd_mod"
"sr_mod"
];
boot.kernelModules = [
"kvm-intel"
"virtio_balloon"
"virtio_console"
"virtio_rng"
"virtio_gpu"
];
};
}
-28
View File
@@ -1,28 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.bluetuith;
in
{
options.modules.bluetuith = {
enable = mkEnableOption "bluetuith";
};
config = mkIf cfg.enable {
home.packages = with pkgs; [ bluetuith ];
# Add nix tree
xdg.desktopEntries.bluetuith = {
exec = "${pkgs.bluetuith}/bin/bluetuith";
name = "Bluetuith";
terminal = true;
type = "Application";
};
};
}
-34
View File
@@ -1,34 +0,0 @@
{
lib,
config,
pkgs,
...
}:
with lib;
{
imports = [
./firefox/default.nix
./qutebrowser/default.nix
];
options.default.browser = mkOption {
type = types.str;
default = "";
description = "Default browser";
};
config = {
xdg.mimeApps = {
enable = true;
defaultApplications = {
"text/html" = "${config.default.browser}";
"x-scheme-handler/http" = "${config.default.browser}";
"x-scheme-handler/https" = "${config.default.browser}";
"x-scheme-handler/about" = "${config.default.browser}";
"x-scheme-handler/unknown" = "${config.default.browser}";
};
};
};
}
-77
View File
@@ -1,77 +0,0 @@
{
config,
lib,
pkgs,
...
}:
with lib;
let
cfg = config.modules.firefox;
in
{
options.modules.firefox = {
enable = lib.mkEnableOption "firefox";
default = lib.mkEnableOption "default";
};
config = lib.mkIf cfg.enable {
default.browser = mkIf cfg.default "firefox.desktop";
programs.firefox = {
enable = true;
policies = {
AppAutoUpdate = false;
BlockAboutAddons = true;
BlockAboutConfig = true;
BlockAboutProfiles = true;
DisableAppUpdate = true;
DisableFeedbackCommands = true;
DisableMasterPasswordCreation = true;
DisablePocket = true;
DisableProfileImport = true;
DisableProfileRefresh = true;
DisableSetDesktopBackground = true;
DisableTelemetry = true;
DisplayBookmarksToolbar = "never";
DisplayMenuBar = "never";
DNSOverHTTPS = {
Enabled = false;
};
DontCheckDefaultBrowser = true;
PasswordManagerEnabled = false;
TranslateEnabled = true;
UseSystemPrintDialog = true;
};
profiles.nixos = {
search.default = "DuckDuckGo";
extensions = with pkgs.nur.repos.rycee.firefox-addons; [
ublock-origin
];
# Theming
userChrome = readFile (
pkgs.substituteAll {
src = ./userChrome.css;
colors = config.theming.colorsCSS;
}
);
settings = {
"browser.tabs.inTitlebar" = 0;
"extensions.autoDisableScopes" = 0;
"devtools.chrome.enabled" = true;
"devtools.debugger.remote-enabled" = true;
"toolkit.legacyUserProfileCustomizations.stylesheets" = true;
};
# Force overwriting configuration file
search.force = true;
containersForce = true;
};
};
};
}
@@ -1,73 +0,0 @@
/* Import theme colors */
@colors@
/* Configure titlebar */
#titlebar {
/* Add consistent margins to tab bar */
padding: 0 2px !important;
/* Add emphasized color to background of tab bar */
background-color: var(--nix-color-bg-status) !important;
/* Set correct text color */
color: var(--nix-color-fg) !important;
}
.tab-background:is([selected], [multiselected]) {
/* Set correct background color */
background-color: var(--nix-color-bg) !important;
}
.tab-content {
/* Set correct text color */
color: var(--nix-color-fg) !important;
}
/* Configure navigation bar */
#nav-bar {
/* Set correct background color */
background-color: var(--nix-color-bg) !important;
/* Set correct text color */
color: var(--nix-color-fg) !important;
}
#urlbar {
/* Set correct text color */
color: var(--nix-color-fg) !important;
}
#urlbar[open]>#urlbar-background {
/* Set correct background color when opened */
background-color: var(--nix-color-bg) !important;
/* Use same box-shadow as tabs when opened */
border: none !important;
box-shadow: 0 0 4px rgba(0, 0, 0, .4) !important;
}
#urlbar[focused]:not([suppress-focus-border])>#urlbar-background {
/* Set better outline for focused urlbar */
outline-color: var(--nix-color-border-focused) !important;
outline-width: 1px !important;
outline-offset: 0 !important;
}
#urlbar-background {
/* Set the correct background color */
background-color: var(--nix-color-bg-status) !important;
}
/* Configure popups */
panelview {
/* Set correct background color for popups */
background-color: var(--nix-color-bg) !important;
/* Set correct text color */
color: var(--nix-color-fg) !important;
}
menupopup {
/* Set correct background color for context menus */
--panel-background: var(--nix-color-bg) !important;
}
Whitespace-only changes.
@@ -1,34 +0,0 @@
{
config,
lib,
pkgs,
...
}:
with lib;
let
cfg = config.modules.qutebrowser;
theme = config.theming;
in
{
options.modules.qutebrowser = {
enable = mkEnableOption "qutebrowser";
default = mkEnableOption "default";
};
config = mkIf cfg.enable {
default.browser = mkIf cfg.default "org.qutebrowser.qutebrowser.desktop";
programs.qutebrowser = {
enable = true;
extraConfig = ''
# config.set("completion.web_history.max_items", 30)
config.set("colors.webpage.darkmode.enabled", False)
config.set("colors.webpage.preferred_color_scheme", "${if theme.darkMode then "dark" else "light"}")
config.set("fonts.default_family", "${theme.fonts.interface.name}")
config.set("fonts.default_size", "${toString theme.fonts.interface.recommendedSize}pt")
'';
};
};
}
-368
View File
@@ -1,368 +0,0 @@
{
config,
lib,
pkgs,
...
}:
with lib;
let
cfg = config.modules.btop;
colors = config.theming.schemeColors;
in
{
options.modules.btop = {
enable = mkEnableOption "btop";
};
config = mkIf cfg.enable {
home.packages = with pkgs; [ btop ];
xdg.configFile."btop/btop.conf" = {
enable = true;
text = ''
#? Config file for btop v. 1.4.0
#* Name of a btop++/bpytop/bashtop formatted ".theme" file, "Default" and "TTY" for builtin themes.
#* Themes should be placed in "../share/btop/themes" relative to binary or "$HOME/.config/btop/themes"
color_theme = "nixos"
#* If the theme set background should be shown, set to False if you want terminal background transparency.
theme_background = True
#* Sets if 24-bit truecolor should be used, will convert 24-bit colors to 256 color (6x6x6 color cube) if false.
truecolor = True
#* Set to true to force tty mode regardless if a real tty has been detected or not.
#* Will force 16-color mode and TTY theme, set all graph symbols to "tty" and swap out other non tty friendly symbols.
force_tty = False
#* Define presets for the layout of the boxes. Preset 0 is always all boxes shown with default settings. Max 9 presets.
#* Format: "box_name:P:G,box_name:P:G" P=(0 or 1) for alternate positions, G=graph symbol to use for box.
#* Use whitespace " " as separator between different presets.
#* Example: "cpu:0:default,mem:0:tty,proc:1:default cpu:0:braille,proc:0:tty"
presets = "cpu:1:default,proc:0:default cpu:0:default,mem:0:default,net:0:default cpu:0:block,net:0:tty"
#* Set to True to enable "h,j,k,l,g,G" keys for directional control in lists.
#* Conflicting keys for h:"help" and k:"kill" is accessible while holding shift.
vim_keys = False
#* Rounded corners on boxes, is ignored if TTY mode is ON.
rounded_corners = False
#* Default symbols to use for graph creation, "braille", "block" or "tty".
#* "braille" offers the highest resolution but might not be included in all fonts.
#* "block" has half the resolution of braille but uses more common characters.
#* "tty" uses only 3 different symbols but will work with most fonts and should work in a real TTY.
#* Note that "tty" only has half the horizontal resolution of the other two, so will show a shorter historical view.
graph_symbol = "braille"
# Graph symbol to use for graphs in cpu box, "default", "braille", "block" or "tty".
graph_symbol_cpu = "default"
# Graph symbol to use for graphs in gpu box, "default", "braille", "block" or "tty".
graph_symbol_gpu = "default"
# Graph symbol to use for graphs in cpu box, "default", "braille", "block" or "tty".
graph_symbol_mem = "default"
# Graph symbol to use for graphs in cpu box, "default", "braille", "block" or "tty".
graph_symbol_net = "default"
# Graph symbol to use for graphs in cpu box, "default", "braille", "block" or "tty".
graph_symbol_proc = "default"
#* Manually set which boxes to show. Available values are "cpu mem net proc" and "gpu0" through "gpu5", separate values with whitespace.
shown_boxes = "cpu net proc mem"
#* Update time in milliseconds, recommended 2000 ms or above for better sample times for graphs.
update_ms = 500
#* Processes sorting, "pid" "program" "arguments" "threads" "user" "memory" "cpu lazy" "cpu direct",
#* "cpu lazy" sorts top process over time (easier to follow), "cpu direct" updates top process directly.
proc_sorting = "cpu lazy"
#* Reverse sorting order, True or False.
proc_reversed = False
#* Show processes as a tree.
proc_tree = False
#* Use the cpu graph colors in the process list.
proc_colors = True
#* Use a darkening gradient in the process list.
proc_gradient = True
#* If process cpu usage should be of the core it's running on or usage of the total available cpu power.
proc_per_core = False
#* Show process memory as bytes instead of percent.
proc_mem_bytes = True
#* Show cpu graph for each process.
proc_cpu_graphs = True
#* Use /proc/[pid]/smaps for memory information in the process info box (very slow but more accurate)
proc_info_smaps = False
#* Show proc box on left side of screen instead of right.
proc_left = False
#* (Linux) Filter processes tied to the Linux kernel(similar behavior to htop).
proc_filter_kernel = False
#* In tree-view, always accumulate child process resources in the parent process.
proc_aggregate = False
#* Sets the CPU stat shown in upper half of the CPU graph, "total" is always available.
#* Select from a list of detected attributes from the options menu.
cpu_graph_upper = "Auto"
#* Sets the CPU stat shown in lower half of the CPU graph, "total" is always available.
#* Select from a list of detected attributes from the options menu.
cpu_graph_lower = "Auto"
#* If gpu info should be shown in the cpu box. Available values = "Auto", "On" and "Off".
show_gpu_info = "Auto"
#* Toggles if the lower CPU graph should be inverted.
cpu_invert_lower = True
#* Set to True to completely disable the lower CPU graph.
cpu_single_graph = False
#* Show cpu box at bottom of screen instead of top.
cpu_bottom = False
#* Shows the system uptime in the CPU box.
show_uptime = True
#* Show cpu temperature.
check_temp = True
#* Which sensor to use for cpu temperature, use options menu to select from list of available sensors.
cpu_sensor = "Auto"
#* Show temperatures for cpu cores also if check_temp is True and sensors has been found.
show_coretemp = True
#* Set a custom mapping between core and coretemp, can be needed on certain cpus to get correct temperature for correct core.
#* Use lm-sensors or similar to see which cores are reporting temperatures on your machine.
#* Format "x:y" x=core with wrong temp, y=core with correct temp, use space as separator between multiple entries.
#* Example: "4:0 5:1 6:3"
cpu_core_map = ""
#* Which temperature scale to use, available values: "celsius", "fahrenheit", "kelvin" and "rankine".
temp_scale = "celsius"
#* Use base 10 for bits/bytes sizes, KB = 1000 instead of KiB = 1024.
base_10_sizes = False
#* Show CPU frequency.
show_cpu_freq = True
#* Draw a clock at top of screen, formatting according to strftime, empty string to disable.
#* Special formatting: /host = hostname | /user = username | /uptime = system uptime
clock_format = "%X"
#* Update main ui in background when menus are showing, set this to false if the menus is flickering too much for comfort.
background_update = True
#* Custom cpu model name, empty string to disable.
custom_cpu_name = ""
#* Optional filter for shown disks, should be full path of a mountpoint, separate multiple values with whitespace " ".
#* Begin line with "exclude=" to change to exclude filter, otherwise defaults to "most include" filter. Example: disks_filter="exclude=/boot /home/user".
disks_filter = ""
#* Show graphs instead of meters for memory values.
mem_graphs = True
#* Show mem box below net box instead of above.
mem_below_net = False
#* Count ZFS ARC in cached and available memory.
zfs_arc_cached = True
#* If swap memory should be shown in memory box.
show_swap = True
#* Show swap as a disk, ignores show_swap value above, inserts itself after first disk.
swap_disk = True
#* If mem box should be split to also show disks info.
show_disks = True
#* Filter out non physical disks. Set this to False to include network disks, RAM disks and similar.
only_physical = True
#* Read disks list from /etc/fstab. This also disables only_physical.
use_fstab = True
#* Setting this to True will hide all datasets, and only show ZFS pools. (IO stats will be calculated per-pool)
zfs_hide_datasets = False
#* Set to true to show available disk space for privileged users.
disk_free_priv = False
#* Toggles if io activity % (disk busy time) should be shown in regular disk usage view.
show_io_stat = True
#* Toggles io mode for disks, showing big graphs for disk read/write speeds.
io_mode = True
#* Set to True to show combined read/write io graphs in io mode.
io_graph_combined = False
#* Set the top speed for the io graphs in MiB/s (100 by default), use format "mountpoint:speed" separate disks with whitespace " ".
#* Example: "/mnt/media:100 /:20 /boot:1".
io_graph_speeds = ""
#* Set fixed values for network graphs in Mebibits. Is only used if net_auto is also set to False.
net_download = 100
net_upload = 100
#* Use network graphs auto rescaling mode, ignores any values set above and rescales down to 10 Kibibytes at the lowest.
net_auto = True
#* Sync the auto scaling for download and upload to whichever currently has the highest scale.
net_sync = True
#* Starts with the Network Interface specified here.
net_iface = ""
#* Show battery stats in top right if battery is present.
show_battery = False
#* Which battery to use if multiple are present. "Auto" for auto detection.
selected_battery = "Auto"
#* Show power stats of battery next to charge indicator.
show_battery_watts = True
#* Set loglevel for "~/.config/btop/btop.log" levels are: "ERROR" "WARNING" "INFO" "DEBUG".
#* The level set includes all lower levels, i.e. "DEBUG" will show all logging info.
log_level = "WARNING"
#* Measure PCIe throughput on NVIDIA cards, may impact performance on certain cards.
nvml_measure_pcie_speeds = True
#* Horizontally mirror the GPU graph.
gpu_mirror_graph = True
#* Custom gpu0 model name, empty string to disable.
custom_gpu_name0 = ""
#* Custom gpu1 model name, empty string to disable.
custom_gpu_name1 = ""
#* Custom gpu2 model name, empty string to disable.
custom_gpu_name2 = ""
#* Custom gpu3 model name, empty string to disable.
custom_gpu_name3 = ""
#* Custom gpu4 model name, empty string to disable.
custom_gpu_name4 = ""
#* Custom gpu5 model name, empty string to disable.
custom_gpu_name5 = ""
'';
};
xdg.configFile."btop/themes/nixos.theme" = {
enable = true;
text = with colors; ''
# Main background, empty for terminal default, need to be empty if you want transparent background
theme[main_bg]="#${base00}"
# Main text color
theme[main_fg]="#${base05}"
# Title color for boxes
theme[title]="#${base05}"
# Highlight color for keyboard shortcuts
theme[hi_fg]="#${base0D}"
# Background color of selected item in processes box
theme[selected_bg]="#${base03}"
# Foreground color of selected item in processes box
theme[selected_fg]="#${base0D}"
# Color of inactive/disabled text
theme[inactive_fg]="#8c8fa1"
# Color of text appearing on top of graphs, i.e uptime and current network graph scaling
theme[graph_text]="#${base06}"
# Background color of the percentage meters
theme[meter_bg]="#${base03}"
# Misc colors for processes box including mini cpu graphs, details memory graph and details status text
theme[proc_misc]="#${base06}"
# CPU, Memory, Network, Proc box outline colors
theme[cpu_box]="#${base0E}" #Mauve
theme[mem_box]="#${base0B}" #Green
theme[net_box]="#e64553" #Maroon
theme[proc_box]="#${colors.base0D}" #Blue
# Box divider line and small boxes line color
theme[div_line]="#9ca0b0"
# Temperature graph color (Green -> Yellow -> Red)
theme[temp_start]="#${base0B}"
theme[temp_mid]="#${base0A}"
theme[temp_end]="#${base08}"
# CPU graph colors (Teal -> Lavender)
theme[cpu_start]="#${base0C}"
theme[cpu_mid]="#209fb5"
theme[cpu_end]="#${base07}"
# Mem/Disk free meter (Mauve -> Lavender -> Blue)
theme[free_start]="#${base0E}"
theme[free_mid]="#${base07}"
theme[free_end]="#${base0D}"
# Mem/Disk cached meter (Sapphire -> Lavender)
theme[cached_start]="#209fb5"
theme[cached_mid]="#${base0D}"
theme[cached_end]="#${base07}"
# Mem/Disk available meter (Peach -> Red)
theme[available_start]="#${base09}"
theme[available_mid]="#e64553"
theme[available_end]="#${base08}"
# Mem/Disk used meter (Green -> Sky)
theme[used_start]="#${base0B}"
theme[used_mid]="#${base0C}"
theme[used_end]="#04a5e5"
# Download graph colors (Peach -> Red)
theme[download_start]="#${base09}"
theme[download_mid]="#e64553"
theme[download_end]="#${base08}"
# Upload graph colors (Green -> Sky)
theme[upload_start]="#${base0B}"
theme[upload_mid]="#${base0C}"
theme[upload_end]="#04a5e5"
# Process box color gradient for threads, mem and cpu usage (Sapphire -> Mauve)
theme[process_start]="#209fb5"
theme[process_mid]="#${base07}"
theme[process_end]="#${base0E}"
'';
};
modules.shell.aliases = {
top = "btop";
};
};
}
Loaded 100 of 170 files, more files were not shown because too many files have changed in this diff. Show more