Compare commits
6 Commits
0783fc03b3
...
feature/do
| Author | SHA1 | Date | |
|---|---|---|---|
|
920b128ed7
|
|||
| 978bd0e12b | |||
|
2ab6ccb7a0
|
|||
| b8e7708b59 | |||
| e84c99e6b2 | |||
|
efec8e6def
|
125
INSTALLATION.md
Normal file
125
INSTALLATION.md
Normal file
@@ -0,0 +1,125 @@
|
||||
# basic system installation
|
||||
|
||||
- The installations presented in this repository are always luks encrypted
|
||||
- For simplicity I'm using device labels rather than uuids
|
||||
|
||||
1. the partitioning layout should look somewhat like this after the installation
|
||||
|
||||
```bash
|
||||
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTS
|
||||
nvme0n1 259:0 0 476.9G 0 disk
|
||||
├─nvme0n1p1 259:1 0 2G 0 part /boot
|
||||
└─nvme0n1p2 259:2 0 474.9G 0 part
|
||||
└─cryptroot 254:0 0 474.9G 0 crypt
|
||||
├─lvmroot-swap 254:1 0 20G 0 lvm [SWAP]
|
||||
├─lvmroot-home 254:2 0 250G 0 lvm /home
|
||||
└─lvmroot-root 254:3 0 204.9G 0 lvm /nix/store
|
||||
```
|
||||
|
||||
2. prepare the installation
|
||||
|
||||
```bash
|
||||
# format the boot partition
|
||||
mkfs.fat -F 32 /dev/sda1 -n "nixboot"
|
||||
# create an encrypted partition
|
||||
cryptsetup luksFormat -y --label="nixcrypt" /dev/sda2
|
||||
# open the encrypted partition and map it to /dev/mapper/cryptroot
|
||||
cryptsetup luksOpen /dev/sda2 cryptroot
|
||||
|
||||
# create the physical volume
|
||||
pvcreate /dev/mapper/cryptroot
|
||||
# create a volume group inside
|
||||
vgcreate lvmroot /dev/mapper/cryptroot
|
||||
# create the swap volume
|
||||
lvcreate --size 8G lvmroot --name nwap
|
||||
# if you desire, create a home volume
|
||||
lvcreate --size 150G lvmroot --name home
|
||||
# create the root volume
|
||||
lvcreate -l 100%FREE lvmroot --name root
|
||||
|
||||
# format as usual for root partition
|
||||
mkfs.ext4 -L "nixroot" /dev/mapper/lvmroot-root
|
||||
# if you previously made the home partition, do it too
|
||||
mkfs.ext4 -L "nixhome" /dev/mapper/lvmroot-home
|
||||
# format the swap partition
|
||||
mkswap -L "nixswap" /dev/mapper/lvmroot-swap
|
||||
|
||||
# mount root
|
||||
mount /dev/disk/by-label/nixroot /mnt
|
||||
# mount boot
|
||||
mount --mkdir /dev/sda1 /mnt/boot
|
||||
# again, if you did the home volume
|
||||
mount --mkdir /dev/disk/by-label/nixhome /mnt/home
|
||||
# turn on swap
|
||||
swapon /dev/disk/by-label/nixswap
|
||||
```
|
||||
|
||||
3. prepare nixos
|
||||
|
||||
```bash
|
||||
# generate templates and update the hardware-configuration.nix
|
||||
sudo nixos-generate-config --root /mnt
|
||||
|
||||
# add cryptd to the kernelModules
|
||||
boot.initrd.kernelModules = [ "dm-snapshot" "cryptd" ];
|
||||
|
||||
# add file systems using labels
|
||||
fileSystems."/" =
|
||||
{ device = "/dev/disk/by-label/nixroot";
|
||||
fsType = "ext4";
|
||||
};
|
||||
fileSystems."/boot" =
|
||||
{ device = "/dev/disk/by-label/nixboot";
|
||||
fsType = "vfat";
|
||||
options = [ "fmask=0022" "dmask=0022" ];
|
||||
};
|
||||
fileSystems."/home" =
|
||||
{ device = "/dev/disk/by-label/nixhome";
|
||||
fsType = "ext4";
|
||||
};
|
||||
swapDevices =
|
||||
[ { device = "/dev/disk/by-label/nixswap"; }
|
||||
];
|
||||
|
||||
# point the bootloader to the luks device
|
||||
boot.initrd.luks.devices."cryptroot".device = "/dev/disk/by-label/nixcrypt";
|
||||
```
|
||||
|
||||
4. install nixos
|
||||
|
||||
```bash
|
||||
cd /mnt
|
||||
sudo nixos-install
|
||||
```
|
||||
|
||||
## how to deploy the inital config
|
||||
|
||||
- Don't forget to install the bootloader, if you changed it since `nixos-install`
|
||||
|
||||
```bash
|
||||
$ sudo nixos-rebuild --install-bootloader switch --flake .#host_name
|
||||
```
|
||||
|
||||
## how to upgrade the system
|
||||
|
||||
```bash
|
||||
$ cd /path/to/repo
|
||||
$ sudo nix flake update
|
||||
$ sudo nixos-rebuild switch --flake .#host_name
|
||||
$ sudo nix-collect-garbage
|
||||
```
|
||||
|
||||
## how to use nix-helper
|
||||
|
||||
The tool nix-helper is installed by this configuration. It simplifies administrating nixos and adds more output to the rebuild command. It also features a diff after a successful build. The command uses the `NH_FLAKE` environment variable to be able to run from whatever directory.
|
||||
|
||||
Basic commands with a set `NH_FLAKE` variable are:
|
||||
|
||||
```bash
|
||||
$ nh os switch
|
||||
$ nh os build
|
||||
$ nh os test
|
||||
$ nh clean all --keep 5
|
||||
```
|
||||
|
||||
There is also the option to interface with home-manager by using `nh home switch` but this isn't necessary since home-manager is imported as a module in this config.
|
||||
143
README.md
143
README.md
@@ -1,133 +1,30 @@
|
||||
# 0x29a nixos config
|
||||
# NixOS config
|
||||
|
||||
My personal nixos configuration files for different environments.
|
||||
My personal NixOS configurations.
|
||||
|
||||
## basic system installation
|
||||
|
||||
- The installations presented in this repository are always luks encrypted
|
||||
- For simplicity I'm using device labels rather than uuids
|
||||
|
||||
1. the partitioning layout should look somewhat like this after the installation
|
||||
## config structure
|
||||
|
||||
```bash
|
||||
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTS
|
||||
nvme0n1 259:0 0 476.9G 0 disk
|
||||
├─nvme0n1p1 259:1 0 2G 0 part /boot
|
||||
└─nvme0n1p2 259:2 0 474.9G 0 part
|
||||
└─cryptroot 254:0 0 474.9G 0 crypt
|
||||
├─lvmroot-swap 254:1 0 20G 0 lvm [SWAP]
|
||||
├─lvmroot-home 254:2 0 250G 0 lvm /home
|
||||
└─lvmroot-root 254:3 0 204.9G 0 lvm /nix/store
|
||||
```
|
||||
|
||||
2. prepare the installation
|
||||
|
||||
```bash
|
||||
# format the boot partition
|
||||
mkfs.fat -F 32 /dev/sda1 -n "nixboot"
|
||||
# create an encrypted partition
|
||||
cryptsetup luksFormat -y --label="nixcrypt" /dev/sda2
|
||||
# open the encrypted partition and map it to /dev/mapper/cryptroot
|
||||
cryptsetup luksOpen /dev/sda2 cryptroot
|
||||
|
||||
# create the physical volume
|
||||
pvcreate /dev/mapper/cryptroot
|
||||
# create a volume group inside
|
||||
vgcreate lvmroot /dev/mapper/cryptroot
|
||||
# create the swap volume
|
||||
lvcreate --size 8G lvmroot --name nwap
|
||||
# if you desire, create a home volume
|
||||
lvcreate --size 150G lvmroot --name home
|
||||
# create the root volume
|
||||
lvcreate -l 100%FREE lvmroot --name root
|
||||
|
||||
# format as usual for root partition
|
||||
mkfs.ext4 -L "nixroot" /dev/mapper/lvmroot-root
|
||||
# if you previously made the home partition, do it too
|
||||
mkfs.ext4 -L "nixhome" /dev/mapper/lvmroot-home
|
||||
# format the swap partition
|
||||
mkswap -L "nixswap" /dev/mapper/lvmroot-swap
|
||||
|
||||
# mount root
|
||||
mount /dev/disk/by-label/nixroot /mnt
|
||||
# mount boot
|
||||
mount --mkdir /dev/sda1 /mnt/boot
|
||||
# again, if you did the home volume
|
||||
mount --mkdir /dev/disk/by-label/nixhome /mnt/home
|
||||
# turn on swap
|
||||
swapon /dev/disk/by-label/nixswap
|
||||
.
|
||||
├── flake.lock
|
||||
├── flake.nix # flake definition
|
||||
├── hosts
|
||||
│ └── neon
|
||||
│ ├── configuration.nix # import nix-modules for specific host
|
||||
│ └── hardware-configuration.nix # hardware configs for specific host
|
||||
├── modules
|
||||
│ ├── home-manager
|
||||
│ │ ├── xyz_module.nix
|
||||
│ └── nixos
|
||||
│ └── xyz_module.nix
|
||||
└── users
|
||||
└── aaron
|
||||
└── home.nix # import home-manager modules for specific user
|
||||
```
|
||||
|
||||
3. prepare nixos
|
||||
## installation
|
||||
|
||||
|
||||
```bash
|
||||
# generate templates and update the hardware-configuration.nix
|
||||
sudo nixos-generate-config --root /mnt
|
||||
|
||||
# add cryptd to the kernelModules
|
||||
boot.initrd.kernelModules = [ "dm-snapshot" "cryptd" ];
|
||||
|
||||
# add file systems using labels
|
||||
fileSystems."/" =
|
||||
{ device = "/dev/disk/by-label/nixroot";
|
||||
fsType = "ext4";
|
||||
};
|
||||
fileSystems."/boot" =
|
||||
{ device = "/dev/disk/by-label/nixboot";
|
||||
fsType = "vfat";
|
||||
options = [ "fmask=0022" "dmask=0022" ];
|
||||
};
|
||||
fileSystems."/home" =
|
||||
{ device = "/dev/disk/by-label/nixhome";
|
||||
fsType = "ext4";
|
||||
};
|
||||
swapDevices =
|
||||
[ { device = "/dev/disk/by-label/nixswap"; }
|
||||
];
|
||||
|
||||
# point the bootloader to the luks device
|
||||
boot.initrd.luks.devices."cryptroot".device = "/dev/disk/by-label/nixcrypt";
|
||||
```
|
||||
|
||||
4. install nixos
|
||||
|
||||
```bash
|
||||
cd /mnt
|
||||
sudo nixos-install
|
||||
```
|
||||
|
||||
## how to deploy the inital config
|
||||
|
||||
- Don't forget to install the bootloader, if you changed it since `nixos-install`
|
||||
|
||||
```bash
|
||||
$ sudo nixos-rebuild --install-bootloader switch --flake .#host_name
|
||||
```
|
||||
|
||||
## how to upgrade the system
|
||||
|
||||
```bash
|
||||
$ cd /path/to/repo
|
||||
$ sudo nix flake update
|
||||
$ sudo nixos-rebuild switch --flake .#host_name
|
||||
$ sudo nix-collect-garbage
|
||||
```
|
||||
|
||||
## how to use nix-helper
|
||||
|
||||
The tool nix-helper is installed by this configuration. It simplifies administrating nixos and adds more output to the rebuild command. It also features a diff after a successful build. The command uses the `NH_FLAKE` environment variable to be able to run from whatever directory.
|
||||
|
||||
Basic commands with a set `NH_FLAKE` variable are:
|
||||
|
||||
```bash
|
||||
$ nh os switch
|
||||
$ nh os build
|
||||
$ nh os test
|
||||
$ nh clean all --keep 5
|
||||
```
|
||||
|
||||
There is also the option to interface with home-manager by using `nh home switch`but this isn't necessary since home-manager is imported as a module in this config.
|
||||
For more details about the installation procedure see: [INSTALLATION.md](INSTALLATION.md)
|
||||
|
||||
## author
|
||||
|
||||
|
||||
30
flake.lock
generated
30
flake.lock
generated
@@ -8,11 +8,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1768135262,
|
||||
"narHash": "sha256-PVvu7OqHBGWN16zSi6tEmPwwHQ4rLPU9Plvs8/1TUBY=",
|
||||
"lastModified": 1769996383,
|
||||
"narHash": "sha256-AnYjnFWgS49RlqX7LrC4uA+sCCDBj0Ry/WOJ5XWAsa0=",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"rev": "80daad04eddbbf5a4d883996a73f3f542fa437ac",
|
||||
"rev": "57928607ea566b5db3ad13af0e57e921e6b12381",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -28,11 +28,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1769872935,
|
||||
"narHash": "sha256-07HMIGQ/WJeAQJooA7Kkg1SDKxhAiV6eodvOwTX6WKI=",
|
||||
"lastModified": 1770491427,
|
||||
"narHash": "sha256-8b+0vixdqGnIIcgsPhjdX7EGPdzcVQqYxF+ujjex654=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "f4ad5068ee8e89e4a7c2e963e10dd35cd77b37b7",
|
||||
"rev": "cbd8a72e5fe6af19d40e2741dc440d9227836860",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -43,11 +43,11 @@
|
||||
},
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1769789167,
|
||||
"narHash": "sha256-kKB3bqYJU5nzYeIROI82Ef9VtTbu4uA3YydSk/Bioa8=",
|
||||
"lastModified": 1770197578,
|
||||
"narHash": "sha256-AYqlWrX09+HvGs8zM6ebZ1pwUqjkfpnv8mewYwAo+iM=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "62c8382960464ceb98ea593cb8321a2cf8f9e3e5",
|
||||
"rev": "00c21e4c93d963c50d4c0c89bfa84ed6e0694df2",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -66,11 +66,11 @@
|
||||
"systems": "systems"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1769644746,
|
||||
"narHash": "sha256-1X9o0GjCzku03magX4pM+1OZXA0aUTN7KvEReZ9t3OU=",
|
||||
"lastModified": 1770388595,
|
||||
"narHash": "sha256-0NvpmDqFcJAtRFJE3RDZWnN7PDJBZutoDtN+Cl8a3DY=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nixvim",
|
||||
"rev": "3c27e1b35ca0fee6a89bfc20840654361ffe888d",
|
||||
"rev": "51abc532525e486176f9a7b24b17908c60017b54",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -86,11 +86,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1769946076,
|
||||
"narHash": "sha256-Iek7AHXTMzWi3U5EeCM1pygtvyANKY1Ax8WGn4FXh+Y=",
|
||||
"lastModified": 1770543184,
|
||||
"narHash": "sha256-2FFYjurrYjCAT6bpN2Fv63G6vDuWybB91uvqBjJfcWE=",
|
||||
"owner": "noctalia-dev",
|
||||
"repo": "noctalia-shell",
|
||||
"rev": "348763cc9645fb53bebde40fae9ec4122ee51b60",
|
||||
"rev": "bf1a0f76bb5ca48991d51130022af6bead64d153",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
|
||||
Reference in New Issue
Block a user