Compare commits

..
11 Commits
11 changed files with 195 additions and 15 deletions

No files matched your search

+18 -4
View File
@@ -4,8 +4,22 @@ My NixOS configuration.
## Installation
For disk configuration we use disko, this means that installing the system from the configuration is just a single command:
For disk configuration we use disko, this means that installing the system can be done with the following commands:
```
sudo nix --experimental-features "nix-command flakes" run "github:nix-community/disko/latest#disko-install" -- --flake git+https://git.bulthuis.dev/Jan/dotfiles#<hostname> --disk main /dev/sda
```
nix-shell -p disko
sudo disko --mode disko --flake git+https://git.bulthuis.dev/Jan/dotfiles#<system>
sudo nixos-install --no-channel-copy --no-root-password --flake git+https://git.bulthuis.dev/Jan/dotfiles#<system>
```
If `nixos-install` is being stopped by the OOM-killer, you can try adding `-j 1` to limit the amount of jobs that will be executed at the same time to 1. It might require running nixos-install multiple times untill it has managed to download all requirements and slowly start building the rest of the system.
## Updating
To update the system configuration, it is a single command:
```
sudo system-update
```
Or if this shell script has not been installed for some reason:
```
sudo nixos-rebuild switch --flake git+https://git.bulthuis.dev/Jan/dotfiles
```
Sometimes it may be necessary to reboot of course.
Generated
+38 -1
View File
@@ -154,7 +154,44 @@
"impermanence": "impermanence",
"nix-minecraft": "nix-minecraft",
"nix-modpack": "nix-modpack",
"nixpkgs": "nixpkgs"
"nixpkgs": "nixpkgs",
"secrets": "secrets",
"sops-nix": "sops-nix"
}
},
"secrets": {
"locked": {
"lastModified": 1748558035,
"narHash": "sha256-2rcRntqj4l2TGvJfxcUqWk0fUQ/R2TXlzXsUUfAIhhE=",
"ref": "refs/heads/main",
"rev": "b79d30edaa496f13c2549507d54bbf6ec574e6c2",
"revCount": 2,
"type": "git",
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
},
"original": {
"type": "git",
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
}
},
"sops-nix": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1747603214,
"narHash": "sha256-lAblXm0VwifYCJ/ILPXJwlz0qNY07DDYdLD+9H+Wc8o=",
"owner": "Mic92",
"repo": "sops-nix",
"rev": "8d215e1c981be3aa37e47aeabd4e61bb069548fd",
"type": "github"
},
"original": {
"owner": "Mic92",
"repo": "sops-nix",
"type": "github"
}
},
"systems": {
+7
View File
@@ -6,6 +6,13 @@
nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable";
home-manager.url = "github:nix-community/home-manager";
home-manager.inputs.nixpkgs.follows = "nixpkgs";
# Secrets
sops-nix.url = "github:Mic92/sops-nix";
sops-nix.inputs.nixpkgs.follows = "nixpkgs";
secrets.url = "git+ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets";
# Disk setup
disko.url = "github:nix-community/disko";
disko.inputs.nixpkgs.follows = "nixpkgs";
impermanence.url = "github:nix-community/impermanence";
+22
View File
@@ -0,0 +1,22 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.bitwarden;
in
{
options.modules.bitwarden = {
enable = mkEnableOption "Bitwarden";
};
config = mkIf cfg.enable {
home.packages = with pkgs; [
bitwarden-desktop
];
};
}
+39
View File
@@ -0,0 +1,39 @@
{
inputs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.secrets;
secrets = inputs.secrets;
in
{
options.modules.secrets = {
enable = mkEnableOption "secrets";
defaultFile = mkOption {
type = types.str;
default = "${secrets}/secrets/common.enc.yaml";
description = ''
The default file to use for SOPS.
'';
};
secrets = mkOption {
type = types.attrs;
default = { };
description = ''
All secrets that should be made available.
'';
};
};
config = mkIf cfg.enable {
# Set up SOPS
sops.defaultSopsFile = cfg.defaultFile;
sops.age.sshKeyPaths = [ "${config.home.homeDirectory}/.config/sops/sops_ed25519_key" ];
sops.secrets = cfg.secrets;
modules.impermanence.directories = [ ".config/" ];
};
}
+39
View File
@@ -0,0 +1,39 @@
{
inputs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.secrets;
secrets = inputs.secrets;
in
{
options.modules.secrets = {
enable = mkEnableOption "secrets";
defaultFile = mkOption {
type = types.str;
default = "${secrets}/secrets/common.enc.yaml";
description = ''
The default file to use for SOPS.
'';
};
secrets = mkOption {
type = types.attrs;
default = { };
description = ''
All secrets that should be made available.
'';
};
};
config = mkIf cfg.enable {
# Set up SOPS
sops.defaultSopsFile = cfg.defaultFile;
sops.age.sshKeyPaths = [ "/etc/sops/sops_ed25519_key" ];
sops.secrets = cfg.secrets;
modules.impermanence.directories = [ "/etc/sops" ];
};
}
+12
View File
@@ -11,5 +11,17 @@ in
config = mkIf cfg.enable {
services.openssh.enable = true;
# TODO: Is this default configuration secure?
services.openssh.hostKeys = mkIf (config.modules.impermanence.enable) [
{
type = "ed25519";
path = "/persist/system/etc/ssh/ssh_host_ed25519_key";
}
{
type = "rsa";
bits = 4096;
path = "/persist/system/etc/ssh/ssh_host_rsa_key";
}
];
};
}
+1
View File
@@ -3,6 +3,7 @@
disk = {
main = {
type = "disk";
device = "/dev/sda";
content = {
type = "gpt";
partitions = {
+1 -1
View File
@@ -24,7 +24,6 @@ in
freecad-wayland
inkscape
ente-auth
bitwarden
carla
winbox
whatsapp-for-linux
@@ -61,6 +60,7 @@ in
"flake.lock"
];
};
bitwarden.enable = true;
xpra = {
enable = true;
hosts = [
-5
View File
@@ -1,5 +1,4 @@
{
mkModule,
pkgs,
lib,
config,
@@ -20,13 +19,9 @@ in
bootloader.enable = mkDefault true;
ssh.enable = mkDefault true;
# Setup sensible default persistent data
impermanence.directories = [
"/var/lib/nixos"
];
impermanence.files = [
"/etc/shadow"
];
};
# Localization
+18 -4
View File
@@ -1,5 +1,4 @@
{
mkModule,
pkgs,
lib,
config,
@@ -30,18 +29,33 @@ in
zfs rollback -r tank/root@blank
'';
};
secrets = {
enable = true;
secrets = {
"ssh-keys/deploy/private-key" = { };
"ssh-keys/deploy/public-key" = { };
};
};
ssh.enable = true;
};
# Admin users
# Local user
services.getty.autologinUser = "local";
users.mutableUsers = false;
users.users.local = {
initialPassword = "local";
hashedPassword = "$y$j9T$f/uFTdcVyFUPJLn4VhRTx.$c9e2QPXYGKFNt3lUf8QD3KLJi4AKgPldfQTvc0WCe..";
extraGroups = [ "wheel" ];
openssh.authorizedKeys.keys = [
"ssh-ed25519 jan@bulthuis.dev"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKKxoQSxfYqf9ITN8Fhckk8WbY4dwtBAXOhC9jxihJvq Laptop"
];
};
# System packages
environment.systemPackages = with pkgs; [
# TODO: Make module for utilities/scripts
(writeShellScriptBin "system-update" "nixos-rebuild switch --flake git+https://git.bulthuis.dev/Jan/dotfiles")
];
# Enable qemu guest agent
services.qemuGuest.enable = true;