Compare commits

...
12 Commits
10 changed files with 105 additions and 226 deletions

No files matched your search

Generated
+12 -160
View File
@@ -7,11 +7,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1769524058, "lastModified": 1779135526,
"narHash": "sha256-zygdD6X1PcVNR2PsyK4ptzrVEiAdbMqLos7utrMDEWE=", "narHash": "sha256-glCununz6lmaK5fs2X946HA3EkNxB2JagdAAvInuRYU=",
"owner": "nix-community", "owner": "nix-community",
"repo": "disko", "repo": "disko",
"rev": "71a3fc97d80881e91710fe721f1158d3b96ae14d", "rev": "d405a179887d52b24c0ddd31e09a150bd1f66779",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -20,58 +20,6 @@
"type": "github" "type": "github"
} }
}, },
"flake-compat": {
"flake": false,
"locked": {
"lastModified": 1747046372,
"narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-utils": {
"inputs": {
"systems": "systems"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"flake-utils_2": {
"inputs": {
"systems": "systems_2"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"home-manager": { "home-manager": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
@@ -79,11 +27,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1770476834, "lastModified": 1779157263,
"narHash": "sha256-cyxgVsNfHnJ4Zn6G1EOzfTXbjTy7Ds9zMOsZaX7VZWs=", "narHash": "sha256-VbiyZkRf8/qr7ObmlyfOHJsNAW5tyZ4MB1+cUwAwdrw=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "6cee0821577643e0b34e2c5d9a90d0b1b5cdca70", "rev": "866412a19866b4a8e32d2306a118040afa2b840c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -132,69 +80,6 @@
"type": "github" "type": "github"
} }
}, },
"madd": {
"inputs": {
"flake-utils": "flake-utils",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1754781336,
"narHash": "sha256-EUavinU3psYqVDx7Cjdypsf4dUymdu1yawbwRYv6wbM=",
"ref": "refs/heads/master",
"rev": "d490b648ac5acb65aa24c8e8314c1a6fa9e2c0c1",
"revCount": 8,
"type": "git",
"url": "https://git.bulthuis.dev/Jan/madd"
},
"original": {
"type": "git",
"url": "https://git.bulthuis.dev/Jan/madd"
}
},
"nix-minecraft": {
"inputs": {
"flake-compat": "flake-compat",
"flake-utils": "flake-utils_2",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1751650156,
"narHash": "sha256-1gIPVDf159TQlcVg3WQBHMZVn8RllHOa8eT7AJPj2IE=",
"owner": "Jan-Bulthuis",
"repo": "nix-minecraft",
"rev": "d3b3779fd78bd55db24d25e896438b2b51cbb6cb",
"type": "github"
},
"original": {
"owner": "Jan-Bulthuis",
"repo": "nix-minecraft",
"type": "github"
}
},
"nix-modpack": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1747559249,
"narHash": "sha256-+ygKEGMVcXNklO4RDYSd5XzydDmQOZWcOcxYZf/PH1U=",
"owner": "Jan-Bulthuis",
"repo": "nix-modpack",
"rev": "a093625c2847afc3ef257513161c7fe318c6be1c",
"type": "github"
},
"original": {
"owner": "Jan-Bulthuis",
"repo": "nix-modpack",
"type": "github"
}
},
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1768564909, "lastModified": 1768564909,
@@ -229,11 +114,11 @@
}, },
"nixpkgs_2": { "nixpkgs_2": {
"locked": { "locked": {
"lastModified": 1770197578, "lastModified": 1778869304,
"narHash": "sha256-AYqlWrX09+HvGs8zM6ebZ1pwUqjkfpnv8mewYwAo+iM=", "narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "00c21e4c93d963c50d4c0c89bfa84ed6e0694df2", "rev": "d233902339c02a9c334e7e593de68855ad26c4cb",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -248,9 +133,6 @@
"disko": "disko", "disko": "disko",
"home-manager": "home-manager", "home-manager": "home-manager",
"impermanence": "impermanence", "impermanence": "impermanence",
"madd": "madd",
"nix-minecraft": "nix-minecraft",
"nix-modpack": "nix-modpack",
"nixpkgs": "nixpkgs_2", "nixpkgs": "nixpkgs_2",
"nixpkgs-stable": "nixpkgs-stable", "nixpkgs-stable": "nixpkgs-stable",
"secrets": "secrets", "secrets": "secrets",
@@ -279,11 +161,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1770145881, "lastModified": 1777944972,
"narHash": "sha256-ktjWTq+D5MTXQcL9N6cDZXUf9kX8JBLLBLT0ZyOTSYY=", "narHash": "sha256-VfGRo1qTBKOe3s2gOv8LSoA6Fk19PvBlwQ1ECN0Evn8=",
"owner": "Mic92", "owner": "Mic92",
"repo": "sops-nix", "repo": "sops-nix",
"rev": "17eea6f3816ba6568b8c81db8a4e6ca438b30b7c", "rev": "c591bf665727040c6cc5cb409079acb22dcce33c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -291,36 +173,6 @@
"repo": "sops-nix", "repo": "sops-nix",
"type": "github" "type": "github"
} }
},
"systems": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"systems_2": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
} }
}, },
"root": "root", "root": "root",
+6 -6
View File
@@ -19,14 +19,14 @@
impermanence.url = "github:nix-community/impermanence"; impermanence.url = "github:nix-community/impermanence";
# MADD # MADD
madd.url = "git+https://git.bulthuis.dev/Jan/madd"; # madd.url = "git+https://git.bulthuis.dev/Jan/madd";
madd.inputs.nixpkgs.follows = "nixpkgs"; # madd.inputs.nixpkgs.follows = "nixpkgs";
# For Minecraft VM # For Minecraft VM
nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft"; # nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
nix-minecraft.inputs.nixpkgs.follows = "nixpkgs"; # nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
nix-modpack.url = "github:Jan-Bulthuis/nix-modpack"; # nix-modpack.url = "github:Jan-Bulthuis/nix-modpack";
nix-modpack.inputs.nixpkgs.follows = "nixpkgs"; # nix-modpack.inputs.nixpkgs.follows = "nixpkgs";
}; };
outputs = outputs =
+5 -55
View File
@@ -28,7 +28,7 @@
# Include NFS client module # Include NFS client module
boot.supportedFilesystems = [ "nfs" ]; boot.supportedFilesystems = [ "nfs" ];
# Set up K3S cluster with CoreDNS and FluxCD # Set up K3S cluster with CoreDNS, FluxCD and Cilium
services.k3s = { services.k3s = {
enable = true; enable = true;
extraFlags = [ extraFlags = [
@@ -52,26 +52,12 @@
sops-decrypt-key = { sops-decrypt-key = {
source = config.sops.secrets."flux/sops-decrypt-key".path; source = config.sops.secrets."flux/sops-decrypt-key".path;
}; };
# "0-secrets-backup-namespaces" = {
# source = "/opt/k3s-secrets-backup/namespaces.yaml";
# };
# "1-secrets-backup" = {
# source = "/opt/k3s-secrets-backup/secrets.yaml";
# };
# TODO: Move to flux config, once it is possible to easily install flux without CNI
cilium-secrets-namespace = {
content = {
apiVersion = "v1";
kind = "Namespace";
metadata.name = "cilium-secrets";
};
};
# TODO: Move to flux config, once it is possible to easily install flux without CNI # TODO: Move to flux config, once it is possible to easily install flux without CNI
gateway-api = gateway-api =
let let
manifest = pkgs.fetchurl { manifest = pkgs.fetchurl {
url = "https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.1/experimental-install.yaml"; url = "https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.1/experimental-install.yaml";
hash = "sha256-08IN1MBDGTZWemkXypMfbc7RMQJCvmK57KB72YkuICU="; hash = "sha256-VTMn4P8yoaK+RGv5OCPIQTz5JTrGptVAfuvR6NJp9p4=";
}; };
in in
{ {
@@ -157,8 +143,8 @@
cilium = { cilium = {
name = "cilium"; name = "cilium";
repo = "oci://quay.io/cilium/charts/cilium"; repo = "oci://quay.io/cilium/charts/cilium";
version = "1.18.6"; version = "1.18.8";
hash = "sha256-+yr38lc5X1+eXCFE/rq/K0m4g/IiNFJHuhB+Nu24eUs="; hash = "sha256-z1aDpWttEfQ+Af/l0Lxdafasm75QysRc8h7sPhWXr94=";
createNamespace = true; createNamespace = true;
targetNamespace = "cilium-system"; targetNamespace = "cilium-system";
values = { values = {
@@ -175,7 +161,6 @@
gatewayAPI = { gatewayAPI = {
enabled = true; enabled = true;
gatewayClass.create = "true"; gatewayClass.create = "true";
secretsNamespace.create = false;
enableAlpn = true; enableAlpn = true;
}; };
bgpControlPlane.enabled = true; bgpControlPlane.enabled = true;
@@ -244,44 +229,9 @@
}; };
}; };
# Backup secrets to avoid reissueing them
modules.impermanence.directories = [ modules.impermanence.directories = [
"/opt/k3s-secrets-backup" "/var/lib/rancher/k3s"
]; ];
systemd.timers.k3s-secrets-backup-timer = {
wantedBy = [ "timers.target" ];
timerConfig = {
OnBootSec = "15m";
OnUnitActiveSec = "1h";
Unit = "k3s-secrets-backup.service";
};
};
systemd.services.k3s-secrets-backup = {
script = ''
mkdir -p /opt/k3s-secrets-backup
touch /opt/k3s-secrets-backup/secrets.yaml
touch /opt/k3s-secrets-backup/namespaces.yaml
chmod 600 /opt/k3s-secrets-backup/secrets.yaml
chmod 600 /opt/k3s-secrets-backup/namespaces.yaml
${pkgs.k3s}/bin/kubectl get secrets -A -l controller.cert-manager\.io/fao=="true" -oyaml | ${pkgs.kubectl-neat}/bin/kubectl-neat > /opt/k3s-secrets-backup/secrets.yaml
echo "apiVersion: v1
kind: List
items:" > /opt/k3s-secrets-backup/namespaces.yaml
${pkgs.gnugrep}/bin/grep -oP '\snamespace: \K.*' /opt/k3s-secrets-backup/secrets.yaml | sort -u | while read -r ns; do
echo "- apiVersion: v1
kind: Namespace
metadata:
name: $ns"
done >> /opt/k3s-secrets-backup/namespaces.yaml
'';
serviceConfig = {
Type = "oneshot";
User = "root";
};
};
environment.variables = { environment.variables = {
KUBECONFIG = "/etc/rancher/k3s/k3s.yaml"; KUBECONFIG = "/etc/rancher/k3s/k3s.yaml";
@@ -7,6 +7,9 @@
# Set hostid (required for ZFS) # Set hostid (required for ZFS)
networking.hostId = "deadbeef"; networking.hostId = "deadbeef";
# Use thermald
services.thermald.ignoreCpuidCheck = true;
# Hardware configuration # Hardware configuration
hardware.enableRedistributableFirmware = true; hardware.enableRedistributableFirmware = true;
boot.initrd.availableKernelModules = [ boot.initrd.availableKernelModules = [
@@ -19,6 +22,7 @@
boot.initrd.kernelModules = [ ]; boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ]; boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ]; boot.extraModulePackages = [ ];
boot.zfs.forceImportRoot = false;
hardware.cpu.intel.updateMicrocode = true; hardware.cpu.intel.updateMicrocode = true;
# Filesystems # Filesystems
+1
View File
@@ -70,6 +70,7 @@ in
mpris-label mpris-label
pip-on-top pip-on-top
rounded-window-corners-reborn rounded-window-corners-reborn
caffeine
]); ]);
# Set up gnome terminal as changing the default terminal is a pain # Set up gnome terminal as changing the default terminal is a pain
+1 -1
View File
@@ -39,7 +39,7 @@ in
programs.git = { programs.git = {
enable = true; enable = true;
extraConfig = { settings = {
pull = { pull = {
rebase = false; rebase = false;
}; };
+1 -1
View File
@@ -18,7 +18,7 @@ in
# Development packages # Development packages
home.packages = with pkgs; [ home.packages = with pkgs; [
nix-tree nix-tree
nixfmt-rfc-style nixfmt
nixd nixd
]; ];
+5 -1
View File
@@ -16,7 +16,11 @@ in
# TODO: Add nvidia settings back in # TODO: Add nvidia settings back in
# TODO: Move to nvidia module # TODO: Move to nvidia module
hardware.nvidia = { hardware.nvidia = {
open = true; open = false;
prime = {
intelBusId = "PCI:0@0:2:0";
nvidiaBusId = "PCI:1@0:0:0";
};
}; };
}; };
} }
+1
View File
@@ -67,6 +67,7 @@ in
"rounded-window-corners@fxgn" "rounded-window-corners@fxgn"
"media-progress@krypion17" "media-progress@krypion17"
"mprisLabel@moon-0xff.github.com" "mprisLabel@moon-0xff.github.com"
"caffeube@patapon.info"
]; ];
last-selected-power-profile = "power-saver"; last-selected-power-profile = "power-saver";
}; };
+69 -2
View File
@@ -33,7 +33,7 @@ in
# pkgs-stable.winbox # pkgs-stable.winbox
winbox4 winbox4
# whatsapp-for-linux # whatsapp-for-linux
wasistlos karere
discord discord
steam steam
spotify spotify
@@ -50,6 +50,10 @@ in
vlc vlc
authenticator authenticator
hotspot hotspot
btop
winboat
hieroglyphic
shortwave
podman podman
podman-compose podman-compose
@@ -58,6 +62,14 @@ in
gnome-logs gnome-logs
]; ];
programs.zathura = {
enable = true;
options = {
synctex = true;
synctex-editor-command = "${pkgs.texlab}/bin/texlab inverse-search -i %{input} -l %{line}";
};
};
programs.helix = { programs.helix = {
enable = true; enable = true;
defaultEditor = true; defaultEditor = true;
@@ -68,6 +80,34 @@ in
# fallback = "default"; # fallback = "default";
# }; # };
# }; # };
settings =
let
move_line_up = [
"extend_to_line_bounds"
"delete_selection"
"move_line_up"
"paste_before"
];
move_line_down = [
"extend_to_line_bounds"
"delete_selection"
"paste_after"
];
in
{
keys.normal = {
"A-up" = move_line_up;
"A-down" = move_line_down;
"A-k" = move_line_up;
"A-j" = move_line_down;
};
keys.select = {
"A-up" = move_line_up;
"A-down" = move_line_down;
"A-k" = move_line_up;
"A-j" = move_line_down;
};
};
extraPackages = with pkgs; [ extraPackages = with pkgs; [
bash-language-server # Bash bash-language-server # Bash
fish-lsp # Fish fish-lsp # Fish
@@ -97,7 +137,8 @@ in
ruff # Python ruff # Python
basedpyright # Python basedpyright # Python
helix-gpt # Copilot #helix-gpt # Copilot
ltex-ls-plus # Spellchecking
# texlab # Latex, Bibtex # texlab # Latex, Bibtex
# bibtex-tidy # Bibtex # bibtex-tidy # Bibtex
@@ -116,6 +157,22 @@ in
]; ];
languages = { languages = {
language-server = { language-server = {
ltex = {
command = "ltex-ls-plus";
config.ltex = { };
};
texlab = {
command = "texlab";
config.texlab = {
build.onSave = true;
forwardSearch.executable = "${config.programs.zathura.package}/bin/zathura";
forwardSearch.args = [
"--synctex-forward"
"%l:1:%f"
"%p"
];
};
};
basedpyright = { basedpyright = {
command = "basedpyright-langserver"; command = "basedpyright-langserver";
args = [ "--stdio" ]; args = [ "--stdio" ];
@@ -133,6 +190,16 @@ in
}; };
}; };
language = [ language = [
{
name = "latex";
# language-servers = [
# { name = "texlab"; }
# { name = "ltex"; }
# ];
soft-wrap = {
enable = true;
};
}
{ {
name = "python"; name = "python";
language-servers = [ language-servers = [