Compare commits
33 Commits
b8e7708b59
...
feature/ar
| Author | SHA1 | Date | |
|---|---|---|---|
|
9b02617698
|
|||
|
bd6546263b
|
|||
|
53c2cf1a63
|
|||
|
80638a920b
|
|||
|
e4674e5828
|
|||
|
16ea94e160
|
|||
|
afd3113cf3
|
|||
|
d7a08c2571
|
|||
|
8cdcb15618
|
|||
|
a0fd1e9264
|
|||
|
d60bdd1245
|
|||
|
404868aa85
|
|||
|
7566d0d1ef
|
|||
|
6a132670e2
|
|||
|
f182b2418a
|
|||
| eb0bc149e8 | |||
|
f53a2aceee
|
|||
| d64f10ad3f | |||
|
cc44e68a2e
|
|||
|
b97d6cc47d
|
|||
|
0d495039ee
|
|||
| 64b76ad7fd | |||
|
aea7ba5c97
|
|||
| 135f2bdac9 | |||
|
d288f6828f
|
|||
| 159cd6f2f2 | |||
|
763a69bf09
|
|||
| 9b6ed91d37 | |||
|
39f7658a34
|
|||
| 50b2aaae60 | |||
|
920b128ed7
|
|||
| 978bd0e12b | |||
|
2ab6ccb7a0
|
118
INSTALLATION.md
Normal file
118
INSTALLATION.md
Normal file
@@ -0,0 +1,118 @@
|
|||||||
|
# basic system installation
|
||||||
|
|
||||||
|
- The installations presented in this repository are always luks encrypted
|
||||||
|
- For simplicity I'm using device labels rather than uuids
|
||||||
|
|
||||||
|
1. the partitioning layout should look somewhat like this after the installation
|
||||||
|
```bash
|
||||||
|
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTS
|
||||||
|
nvme0n1 259:0 0 476.9G 0 disk
|
||||||
|
├─nvme0n1p1 259:1 0 2G 0 part /boot
|
||||||
|
└─nvme0n1p2 259:2 0 474.9G 0 part
|
||||||
|
└─cryptroot 254:0 0 474.9G 0 crypt
|
||||||
|
├─lvmroot-swap 254:1 0 20G 0 lvm [SWAP]
|
||||||
|
├─lvmroot-home 254:2 0 250G 0 lvm /home
|
||||||
|
└─lvmroot-root 254:3 0 204.9G 0 lvm /
|
||||||
|
```
|
||||||
|
|
||||||
|
> Note: `lsblk` may additionally show `/nix/store` as a mountpoint on `lvmroot-root`. This is not a separate partition. NixOS mounts the root device a second time at `/nix/store` with `ro,nosuid,nodev` flags to enforce store immutability at runtime.
|
||||||
|
|
||||||
|
2. prepare the installation
|
||||||
|
```bash
|
||||||
|
# format the boot partition
|
||||||
|
mkfs.fat -F 32 /dev/nvme0n1p1 -n "nixboot"
|
||||||
|
# create an encrypted partition
|
||||||
|
cryptsetup luksFormat -y --label="nixcrypt" /dev/nvme0n1p2
|
||||||
|
# open the encrypted partition and map it to /dev/mapper/cryptroot
|
||||||
|
cryptsetup luksOpen /dev/nvme0n1p2 cryptroot
|
||||||
|
|
||||||
|
# create the physical volume
|
||||||
|
pvcreate /dev/mapper/cryptroot
|
||||||
|
# create a volume group inside
|
||||||
|
vgcreate lvmroot /dev/mapper/cryptroot
|
||||||
|
# create the swap volume
|
||||||
|
lvcreate --size 8G lvmroot --name swap
|
||||||
|
# if you desire, create a home volume
|
||||||
|
lvcreate --size 150G lvmroot --name home
|
||||||
|
# create the root volume
|
||||||
|
lvcreate -l 100%FREE lvmroot --name root
|
||||||
|
|
||||||
|
# format as usual for root partition
|
||||||
|
mkfs.ext4 -L "nixroot" /dev/mapper/lvmroot-root
|
||||||
|
# if you previously made the home partition, do it too
|
||||||
|
mkfs.ext4 -L "nixhome" /dev/mapper/lvmroot-home
|
||||||
|
# format the swap partition
|
||||||
|
mkswap -L "nixswap" /dev/mapper/lvmroot-swap
|
||||||
|
|
||||||
|
# mount root
|
||||||
|
mount /dev/disk/by-label/nixroot /mnt
|
||||||
|
# mount boot
|
||||||
|
mount --mkdir /dev/nvme0n1p1 /mnt/boot
|
||||||
|
# again, if you did the home volume
|
||||||
|
mount --mkdir /dev/disk/by-label/nixhome /mnt/home
|
||||||
|
# turn on swap
|
||||||
|
swapon /dev/disk/by-label/nixswap
|
||||||
|
```
|
||||||
|
|
||||||
|
3. prepare nixos
|
||||||
|
```bash
|
||||||
|
# generate templates and update the hardware-configuration.nix
|
||||||
|
nixos-generate-config --root /mnt
|
||||||
|
|
||||||
|
# add dm-crypt and dm-mod to the kernelModules
|
||||||
|
boot.initrd.kernelModules = [ "dm-crypt" "dm-mod" ];
|
||||||
|
|
||||||
|
# add file systems using labels
|
||||||
|
fileSystems."/" =
|
||||||
|
{ device = "/dev/disk/by-label/nixroot";
|
||||||
|
fsType = "ext4";
|
||||||
|
};
|
||||||
|
fileSystems."/boot" =
|
||||||
|
{ device = "/dev/disk/by-label/nixboot";
|
||||||
|
fsType = "vfat";
|
||||||
|
options = [ "fmask=0022" "dmask=0022" ];
|
||||||
|
};
|
||||||
|
fileSystems."/home" =
|
||||||
|
{ device = "/dev/disk/by-label/nixhome";
|
||||||
|
fsType = "ext4";
|
||||||
|
};
|
||||||
|
swapDevices =
|
||||||
|
[ { device = "/dev/disk/by-label/nixswap"; }
|
||||||
|
];
|
||||||
|
|
||||||
|
# point the bootloader to the luks device
|
||||||
|
boot.initrd.luks.devices."cryptroot".device = "/dev/disk/by-label/nixcrypt";
|
||||||
|
```
|
||||||
|
|
||||||
|
4. install nixos
|
||||||
|
```bash
|
||||||
|
nixos-install
|
||||||
|
```
|
||||||
|
|
||||||
|
## how to deploy the initial config
|
||||||
|
- Don't forget to install the bootloader, if you changed it since `nixos-install`
|
||||||
|
```bash
|
||||||
|
$ sudo nixos-rebuild --install-bootloader switch --flake .#host_name
|
||||||
|
```
|
||||||
|
|
||||||
|
## how to upgrade the system
|
||||||
|
```bash
|
||||||
|
$ cd /path/to/repo
|
||||||
|
$ nix flake update
|
||||||
|
$ sudo nixos-rebuild switch --flake .#host_name
|
||||||
|
$ sudo nix-collect-garbage
|
||||||
|
```
|
||||||
|
|
||||||
|
## how to use nix-helper
|
||||||
|
|
||||||
|
The tool nix-helper is installed by this configuration. It simplifies administrating nixos and adds more output to the rebuild command. It also features a diff after a successful build. The command uses the `NH_FLAKE` environment variable to be able to run from whatever directory.
|
||||||
|
|
||||||
|
Basic commands with a set `NH_FLAKE` variable are:
|
||||||
|
```bash
|
||||||
|
$ nh os switch
|
||||||
|
$ nh os build
|
||||||
|
$ nh os test
|
||||||
|
$ nh clean all --keep 5
|
||||||
|
```
|
||||||
|
|
||||||
|
There is also the option to interface with home-manager by using `nh home switch` but this isn't necessary since home-manager is imported as a module in this config.
|
||||||
143
README.md
143
README.md
@@ -1,133 +1,30 @@
|
|||||||
# 0x29a nixos config
|
# NixOS config
|
||||||
|
|
||||||
My personal nixos configuration files for different environments.
|
My personal NixOS configurations.
|
||||||
|
|
||||||
## basic system installation
|
## config structure
|
||||||
|
|
||||||
- The installations presented in this repository are always luks encrypted
|
|
||||||
- For simplicity I'm using device labels rather than uuids
|
|
||||||
|
|
||||||
1. the partitioning layout should look somewhat like this after the installation
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTS
|
.
|
||||||
nvme0n1 259:0 0 476.9G 0 disk
|
├── flake.lock
|
||||||
├─nvme0n1p1 259:1 0 2G 0 part /boot
|
├── flake.nix # flake definition
|
||||||
└─nvme0n1p2 259:2 0 474.9G 0 part
|
├── hosts
|
||||||
└─cryptroot 254:0 0 474.9G 0 crypt
|
│ └── neon
|
||||||
├─lvmroot-swap 254:1 0 20G 0 lvm [SWAP]
|
│ ├── configuration.nix # import nix-modules for specific host
|
||||||
├─lvmroot-home 254:2 0 250G 0 lvm /home
|
│ └── hardware-configuration.nix # hardware configs for specific host
|
||||||
└─lvmroot-root 254:3 0 204.9G 0 lvm /nix/store
|
├── modules
|
||||||
|
│ ├── home-manager
|
||||||
|
│ │ ├── xyz_module.nix
|
||||||
|
│ └── nixos
|
||||||
|
│ └── xyz_module.nix
|
||||||
|
└── users
|
||||||
|
└── aaron
|
||||||
|
└── home.nix # import home-manager modules for specific user
|
||||||
```
|
```
|
||||||
|
|
||||||
2. prepare the installation
|
## installation
|
||||||
|
|
||||||
```bash
|
For more details about the installation procedure see: [INSTALLATION.md](INSTALLATION.md)
|
||||||
# format the boot partition
|
|
||||||
mkfs.fat -F 32 /dev/sda1 -n "nixboot"
|
|
||||||
# create an encrypted partition
|
|
||||||
cryptsetup luksFormat -y --label="nixcrypt" /dev/sda2
|
|
||||||
# open the encrypted partition and map it to /dev/mapper/cryptroot
|
|
||||||
cryptsetup luksOpen /dev/sda2 cryptroot
|
|
||||||
|
|
||||||
# create the physical volume
|
|
||||||
pvcreate /dev/mapper/cryptroot
|
|
||||||
# create a volume group inside
|
|
||||||
vgcreate lvmroot /dev/mapper/cryptroot
|
|
||||||
# create the swap volume
|
|
||||||
lvcreate --size 8G lvmroot --name nwap
|
|
||||||
# if you desire, create a home volume
|
|
||||||
lvcreate --size 150G lvmroot --name home
|
|
||||||
# create the root volume
|
|
||||||
lvcreate -l 100%FREE lvmroot --name root
|
|
||||||
|
|
||||||
# format as usual for root partition
|
|
||||||
mkfs.ext4 -L "nixroot" /dev/mapper/lvmroot-root
|
|
||||||
# if you previously made the home partition, do it too
|
|
||||||
mkfs.ext4 -L "nixhome" /dev/mapper/lvmroot-home
|
|
||||||
# format the swap partition
|
|
||||||
mkswap -L "nixswap" /dev/mapper/lvmroot-swap
|
|
||||||
|
|
||||||
# mount root
|
|
||||||
mount /dev/disk/by-label/nixroot /mnt
|
|
||||||
# mount boot
|
|
||||||
mount --mkdir /dev/sda1 /mnt/boot
|
|
||||||
# again, if you did the home volume
|
|
||||||
mount --mkdir /dev/disk/by-label/nixhome /mnt/home
|
|
||||||
# turn on swap
|
|
||||||
swapon /dev/disk/by-label/nixswap
|
|
||||||
```
|
|
||||||
|
|
||||||
3. prepare nixos
|
|
||||||
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# generate templates and update the hardware-configuration.nix
|
|
||||||
sudo nixos-generate-config --root /mnt
|
|
||||||
|
|
||||||
# add cryptd to the kernelModules
|
|
||||||
boot.initrd.kernelModules = [ "dm-snapshot" "cryptd" ];
|
|
||||||
|
|
||||||
# add file systems using labels
|
|
||||||
fileSystems."/" =
|
|
||||||
{ device = "/dev/disk/by-label/nixroot";
|
|
||||||
fsType = "ext4";
|
|
||||||
};
|
|
||||||
fileSystems."/boot" =
|
|
||||||
{ device = "/dev/disk/by-label/nixboot";
|
|
||||||
fsType = "vfat";
|
|
||||||
options = [ "fmask=0022" "dmask=0022" ];
|
|
||||||
};
|
|
||||||
fileSystems."/home" =
|
|
||||||
{ device = "/dev/disk/by-label/nixhome";
|
|
||||||
fsType = "ext4";
|
|
||||||
};
|
|
||||||
swapDevices =
|
|
||||||
[ { device = "/dev/disk/by-label/nixswap"; }
|
|
||||||
];
|
|
||||||
|
|
||||||
# point the bootloader to the luks device
|
|
||||||
boot.initrd.luks.devices."cryptroot".device = "/dev/disk/by-label/nixcrypt";
|
|
||||||
```
|
|
||||||
|
|
||||||
4. install nixos
|
|
||||||
|
|
||||||
```bash
|
|
||||||
cd /mnt
|
|
||||||
sudo nixos-install
|
|
||||||
```
|
|
||||||
|
|
||||||
## how to deploy the inital config
|
|
||||||
|
|
||||||
- Don't forget to install the bootloader, if you changed it since `nixos-install`
|
|
||||||
|
|
||||||
```bash
|
|
||||||
$ sudo nixos-rebuild --install-bootloader switch --flake .#host_name
|
|
||||||
```
|
|
||||||
|
|
||||||
## how to upgrade the system
|
|
||||||
|
|
||||||
```bash
|
|
||||||
$ cd /path/to/repo
|
|
||||||
$ sudo nix flake update
|
|
||||||
$ sudo nixos-rebuild switch --flake .#host_name
|
|
||||||
$ sudo nix-collect-garbage
|
|
||||||
```
|
|
||||||
|
|
||||||
## how to use nix-helper
|
|
||||||
|
|
||||||
The tool nix-helper is installed by this configuration. It simplifies administrating nixos and adds more output to the rebuild command. It also features a diff after a successful build. The command uses the `NH_FLAKE` environment variable to be able to run from whatever directory.
|
|
||||||
|
|
||||||
Basic commands with a set `NH_FLAKE` variable are:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
$ nh os switch
|
|
||||||
$ nh os build
|
|
||||||
$ nh os test
|
|
||||||
$ nh clean all --keep 5
|
|
||||||
```
|
|
||||||
|
|
||||||
There is also the option to interface with home-manager by using `nh home switch`but this isn't necessary since home-manager is imported as a module in this config.
|
|
||||||
|
|
||||||
## author
|
## author
|
||||||
|
|
||||||
|
|||||||
54
flake.lock
generated
54
flake.lock
generated
@@ -8,11 +8,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1768135262,
|
"lastModified": 1769996383,
|
||||||
"narHash": "sha256-PVvu7OqHBGWN16zSi6tEmPwwHQ4rLPU9Plvs8/1TUBY=",
|
"narHash": "sha256-AnYjnFWgS49RlqX7LrC4uA+sCCDBj0Ry/WOJ5XWAsa0=",
|
||||||
"owner": "hercules-ci",
|
"owner": "hercules-ci",
|
||||||
"repo": "flake-parts",
|
"repo": "flake-parts",
|
||||||
"rev": "80daad04eddbbf5a4d883996a73f3f542fa437ac",
|
"rev": "57928607ea566b5db3ad13af0e57e921e6b12381",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -28,11 +28,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1769872935,
|
"lastModified": 1772633327,
|
||||||
"narHash": "sha256-07HMIGQ/WJeAQJooA7Kkg1SDKxhAiV6eodvOwTX6WKI=",
|
"narHash": "sha256-jl+DJB2DUx7EbWLRng+6HNWW/1/VQOnf0NsQB4PlA7I=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "home-manager",
|
"repo": "home-manager",
|
||||||
"rev": "f4ad5068ee8e89e4a7c2e963e10dd35cd77b37b7",
|
"rev": "5a75730e6f21ee624cbf86f4915c6e7489c74acc",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -43,11 +43,11 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs": {
|
"nixpkgs": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1769789167,
|
"lastModified": 1772542754,
|
||||||
"narHash": "sha256-kKB3bqYJU5nzYeIROI82Ef9VtTbu4uA3YydSk/Bioa8=",
|
"narHash": "sha256-WGV2hy+VIeQsYXpsLjdr4GvHv5eECMISX1zKLTedhdg=",
|
||||||
"owner": "nixos",
|
"owner": "nixos",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "62c8382960464ceb98ea593cb8321a2cf8f9e3e5",
|
"rev": "8c809a146a140c5c8806f13399592dbcb1bb5dc4",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -66,11 +66,11 @@
|
|||||||
"systems": "systems"
|
"systems": "systems"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1769644746,
|
"lastModified": 1772402258,
|
||||||
"narHash": "sha256-1X9o0GjCzku03magX4pM+1OZXA0aUTN7KvEReZ9t3OU=",
|
"narHash": "sha256-3DmCFOdmbkFML1/G9gj8Wb+rCCZFPOQtNoMCpqOF8SA=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "nixvim",
|
"repo": "nixvim",
|
||||||
"rev": "3c27e1b35ca0fee6a89bfc20840654361ffe888d",
|
"rev": "21ae25e13b01d3b4cdc750b5f9e7bad68b150c10",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -83,14 +83,15 @@
|
|||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
"nixpkgs"
|
"nixpkgs"
|
||||||
]
|
],
|
||||||
|
"noctalia-qs": "noctalia-qs"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1769946076,
|
"lastModified": 1772639853,
|
||||||
"narHash": "sha256-Iek7AHXTMzWi3U5EeCM1pygtvyANKY1Ax8WGn4FXh+Y=",
|
"narHash": "sha256-u8/61CqpmQprdEiVYHnzZe1Ujv98+MRPJdFuAaOmp4c=",
|
||||||
"owner": "noctalia-dev",
|
"owner": "noctalia-dev",
|
||||||
"repo": "noctalia-shell",
|
"repo": "noctalia-shell",
|
||||||
"rev": "348763cc9645fb53bebde40fae9ec4122ee51b60",
|
"rev": "13dad396520b05691bf1fea1af11f94d3ce4142d",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -99,6 +100,27 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"noctalia-qs": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"noctalia",
|
||||||
|
"nixpkgs"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1772227064,
|
||||||
|
"narHash": "sha256-f821ZSoGpa/aXrWq0gPpea9qBnX8KDyavGKkptz2Mog=",
|
||||||
|
"owner": "noctalia-dev",
|
||||||
|
"repo": "noctalia-qs",
|
||||||
|
"rev": "0741d27d2f7db567270f139c5d1684614ecf9863",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "noctalia-dev",
|
||||||
|
"repo": "noctalia-qs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
"root": {
|
"root": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"home-manager": "home-manager",
|
"home-manager": "home-manager",
|
||||||
|
|||||||
17
flake.nix
17
flake.nix
@@ -53,6 +53,23 @@
|
|||||||
}
|
}
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
argon = nixpkgs.lib.nixosSystem {
|
||||||
|
system = "x86_64-linux";
|
||||||
|
specialArgs = { inherit inputs; };
|
||||||
|
modules = [
|
||||||
|
./hosts/argon/hardware-configuration.nix
|
||||||
|
./hosts/argon/configuration.nix
|
||||||
|
home-manager.nixosModules.home-manager
|
||||||
|
{
|
||||||
|
home-manager.extraSpecialArgs = { inherit inputs; };
|
||||||
|
home-manager.users.aaron.imports = [
|
||||||
|
nixvim.homeModules.nixvim
|
||||||
|
./users/aaron/home.nix
|
||||||
|
];
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
31
hosts/argon/configuration.nix
Normal file
31
hosts/argon/configuration.nix
Normal file
@@ -0,0 +1,31 @@
|
|||||||
|
{ config, pkgs, inputs, ... }:
|
||||||
|
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
../../modules/nixos/audio.nix
|
||||||
|
../../modules/nixos/bootloader.nix
|
||||||
|
../../modules/nixos/certificates.nix
|
||||||
|
../../modules/nixos/drives.nix
|
||||||
|
../../modules/nixos/gnupg.nix
|
||||||
|
../../modules/nixos/graphics.nix
|
||||||
|
../../modules/nixos/greetd.nix
|
||||||
|
../../modules/nixos/locales.nix
|
||||||
|
../../modules/nixos/networking.nix
|
||||||
|
../../modules/nixos/niri.nix
|
||||||
|
../../modules/nixos/noctalia.nix
|
||||||
|
../../modules/nixos/openssh.nix
|
||||||
|
../../modules/nixos/packages.nix
|
||||||
|
../../modules/nixos/protonvpn.nix
|
||||||
|
../../modules/nixos/services.nix
|
||||||
|
../../modules/nixos/settings.nix
|
||||||
|
../../modules/nixos/steam.nix
|
||||||
|
../../modules/nixos/users.nix
|
||||||
|
];
|
||||||
|
|
||||||
|
# set hostname
|
||||||
|
networking.hostName = "argon";
|
||||||
|
|
||||||
|
# install state version
|
||||||
|
system.stateVersion = "25.11"; # Don't change
|
||||||
|
}
|
||||||
|
|
||||||
39
hosts/argon/hardware-configuration.nix
Normal file
39
hosts/argon/hardware-configuration.nix
Normal file
@@ -0,0 +1,39 @@
|
|||||||
|
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||||
|
# and may be overwritten by future invocations. Please make changes
|
||||||
|
# to /etc/nixos/configuration.nix instead.
|
||||||
|
{ config, lib, pkgs, modulesPath, ... }:
|
||||||
|
|
||||||
|
{
|
||||||
|
imports =
|
||||||
|
[ (modulesPath + "/installer/scan/not-detected.nix")
|
||||||
|
];
|
||||||
|
|
||||||
|
boot.initrd.availableKernelModules = [ "nvme" "xhci_pci" "ahci" "usbhid" "usb_storage" "sd_mod" ];
|
||||||
|
boot.initrd.kernelModules = [ "dm-crypt dm-mod" ];
|
||||||
|
boot.initrd.luks.devices."cryptroot".device = "/dev/disk/by-label/nixcrypt";
|
||||||
|
boot.kernelModules = [ ];
|
||||||
|
boot.extraModulePackages = [ ];
|
||||||
|
|
||||||
|
fileSystems."/" =
|
||||||
|
{ device = "/dev/mapper/lvmroot-root";
|
||||||
|
fsType = "ext4";
|
||||||
|
};
|
||||||
|
|
||||||
|
fileSystems."/boot" =
|
||||||
|
{ device = "/dev/disk/by-uuid/AC1C-20EB";
|
||||||
|
fsType = "vfat";
|
||||||
|
options = [ "fmask=0022" "dmask=0022" ];
|
||||||
|
};
|
||||||
|
|
||||||
|
fileSystems."/home" =
|
||||||
|
{ device = "/dev/mapper/lvmroot-home";
|
||||||
|
fsType = "ext4";
|
||||||
|
};
|
||||||
|
|
||||||
|
swapDevices =
|
||||||
|
[ { device = "/dev/mapper/lvmroot-swap"; }
|
||||||
|
];
|
||||||
|
|
||||||
|
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||||
|
hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
|
||||||
|
}
|
||||||
@@ -5,6 +5,7 @@
|
|||||||
../../modules/nixos/audio.nix
|
../../modules/nixos/audio.nix
|
||||||
../../modules/nixos/bootloader.nix
|
../../modules/nixos/bootloader.nix
|
||||||
../../modules/nixos/certificates.nix
|
../../modules/nixos/certificates.nix
|
||||||
|
../../modules/nixos/docker.nix
|
||||||
../../modules/nixos/gnupg.nix
|
../../modules/nixos/gnupg.nix
|
||||||
../../modules/nixos/locales.nix
|
../../modules/nixos/locales.nix
|
||||||
../../modules/nixos/networking.nix
|
../../modules/nixos/networking.nix
|
||||||
@@ -19,6 +20,9 @@
|
|||||||
../../modules/nixos/users.nix
|
../../modules/nixos/users.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
|
# set hostname
|
||||||
|
networking.hostName = "neon";
|
||||||
|
|
||||||
# install state version
|
# install state version
|
||||||
system.stateVersion = "25.11"; # Don't change
|
system.stateVersion = "25.11"; # Don't change
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -7,9 +7,9 @@
|
|||||||
clipboard-paste-protection = false;
|
clipboard-paste-protection = false;
|
||||||
clipboard-read = "allow";
|
clipboard-read = "allow";
|
||||||
font-family = "0xProto Nerd Font Mono";
|
font-family = "0xProto Nerd Font Mono";
|
||||||
font-size = 9;
|
font-size = 12;
|
||||||
gtk-titlebar = false;
|
gtk-titlebar = false;
|
||||||
scrollback-limit = 10000;
|
scrollback-limit = 100000;
|
||||||
shell-integration = "zsh";
|
shell-integration = "zsh";
|
||||||
theme = "noctalia"; # generated by noctalia-shell
|
theme = "noctalia"; # generated by noctalia-shell
|
||||||
window-decoration = "auto";
|
window-decoration = "auto";
|
||||||
|
|||||||
@@ -8,7 +8,7 @@
|
|||||||
oh-my-zsh = {
|
oh-my-zsh = {
|
||||||
enable = true;
|
enable = true;
|
||||||
theme = "agnoster";
|
theme = "agnoster";
|
||||||
#plugins = [ "git" "ssh-agent" ];
|
plugins = [ "git" "ssh-agent" "gpg-agent" ];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
23
modules/nixos/docker.nix
Normal file
23
modules/nixos/docker.nix
Normal file
@@ -0,0 +1,23 @@
|
|||||||
|
{ config, lib, pkgs, ...}:
|
||||||
|
|
||||||
|
{
|
||||||
|
virtualisation.docker = {
|
||||||
|
enable = true;
|
||||||
|
# Customize Docker daemon settings
|
||||||
|
daemon.settings = {
|
||||||
|
dns = [ "1.1.1.1" "8.8.8.8" ];
|
||||||
|
log-driver = "journald";
|
||||||
|
registry-mirrors = [ "https://mirror.gcr.io" ];
|
||||||
|
storage-driver = "overlay2";
|
||||||
|
};
|
||||||
|
# Use the rootless mode
|
||||||
|
rootless = {
|
||||||
|
enable = true;
|
||||||
|
setSocketVariable = true;
|
||||||
|
};
|
||||||
|
# Install docker-compose
|
||||||
|
extraPackages = with pkgs; [
|
||||||
|
docker-compose
|
||||||
|
];
|
||||||
|
};
|
||||||
|
}
|
||||||
47
modules/nixos/drives.nix
Normal file
47
modules/nixos/drives.nix
Normal file
@@ -0,0 +1,47 @@
|
|||||||
|
{ config, lib, pkgs, ... }:
|
||||||
|
|
||||||
|
# Add encrypted drives to argon
|
||||||
|
|
||||||
|
{
|
||||||
|
# copy keyfiles into initrd to make them available during early boot
|
||||||
|
boot.initrd.secrets = {
|
||||||
|
"/etc/nixos/keys/data1.key" = "/etc/nixos/keys/data1.key";
|
||||||
|
"/etc/nixos/keys/data2.key" = "/etc/nixos/keys/data2.key";
|
||||||
|
"/etc/nixos/keys/nvmecache.key" = "/etc/nixos/keys/nvmecache.key";
|
||||||
|
};
|
||||||
|
|
||||||
|
# decrypt data drives with keyfiles for argon
|
||||||
|
boot.initrd.luks.devices = {
|
||||||
|
"data1" = {
|
||||||
|
device = "/dev/disk/by-uuid/dfae62cc-bad1-4879-bf9a-461bde833625";
|
||||||
|
keyFile = "/etc/nixos/keys/data1.key";
|
||||||
|
};
|
||||||
|
"data2" = {
|
||||||
|
device = "/dev/disk/by-uuid/8312edae-9247-481b-a313-52a7f848f027";
|
||||||
|
keyFile = "/etc/nixos/keys/data2.key";
|
||||||
|
};
|
||||||
|
"nvmecache" = {
|
||||||
|
device = "/dev/disk/by-uuid/2352250e-4ebe-4f9a-bf66-0d4aaa961bd8";
|
||||||
|
keyFile = "/etc/nixos/keys/nvmecache.key";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# mount decrypted filesystems
|
||||||
|
fileSystems."/mnt/data1" = {
|
||||||
|
device = "/dev/mapper/data1";
|
||||||
|
fsType = "ext4";
|
||||||
|
options = [ "nofail" ];
|
||||||
|
};
|
||||||
|
|
||||||
|
fileSystems."/mnt/data2" = {
|
||||||
|
device = "/dev/mapper/data2";
|
||||||
|
fsType = "ext4";
|
||||||
|
options = [ "nofail" ];
|
||||||
|
};
|
||||||
|
|
||||||
|
fileSystems."/mnt/nvmecache" = {
|
||||||
|
device = "/dev/mapper/nvmecache";
|
||||||
|
fsType = "ext4";
|
||||||
|
options = [ "nofail" ];
|
||||||
|
};
|
||||||
|
}
|
||||||
17
modules/nixos/graphics.nix
Normal file
17
modules/nixos/graphics.nix
Normal file
@@ -0,0 +1,17 @@
|
|||||||
|
{ config, lib, pkgs, ... }:
|
||||||
|
|
||||||
|
{
|
||||||
|
# enable amd GPU acceleration (mesa, vulkan, egl)
|
||||||
|
hardware.graphics = {
|
||||||
|
enable = true;
|
||||||
|
enable32Bit = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
# install amdgpu_top
|
||||||
|
environment.systemPackages = with pkgs; [
|
||||||
|
amdgpu_top
|
||||||
|
];
|
||||||
|
|
||||||
|
# add amdgpu to the initrd for plymouth
|
||||||
|
hardware.amdgpu.initrd.enable = true;
|
||||||
|
}
|
||||||
14
modules/nixos/greetd.nix
Normal file
14
modules/nixos/greetd.nix
Normal file
@@ -0,0 +1,14 @@
|
|||||||
|
{ config, lib, pkgs, ... }:
|
||||||
|
|
||||||
|
{
|
||||||
|
# greetd display manager with tuigreet
|
||||||
|
services.greetd = {
|
||||||
|
enable = true;
|
||||||
|
settings = {
|
||||||
|
default_session = {
|
||||||
|
command = "${pkgs.tuigreet}/bin/tuigreet --time --cmd niri-session";
|
||||||
|
user = "greeter";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -1,9 +1,6 @@
|
|||||||
{ config, lib, pkgs, ... }:
|
{ config, lib, pkgs, ... }:
|
||||||
|
|
||||||
{
|
{
|
||||||
# set hostnname
|
|
||||||
networking.hostName = "neon";
|
|
||||||
|
|
||||||
# user networkmanager
|
# user networkmanager
|
||||||
networking.networkmanager.enable = true;
|
networking.networkmanager.enable = true;
|
||||||
|
|
||||||
|
|||||||
@@ -8,5 +8,6 @@
|
|||||||
adwaita-qt6
|
adwaita-qt6
|
||||||
brightnessctl
|
brightnessctl
|
||||||
playerctl
|
playerctl
|
||||||
|
quickshell
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,5 +5,15 @@
|
|||||||
services.openssh = {
|
services.openssh = {
|
||||||
enable = true;
|
enable = true;
|
||||||
openFirewall = true;
|
openFirewall = true;
|
||||||
|
ports = [ 666 ];
|
||||||
|
|
||||||
|
settings = {
|
||||||
|
AuthenticationMethods = "publickey";
|
||||||
|
KbdInteractiveAuthentication = false;
|
||||||
|
MaxAuthTries = 5;
|
||||||
|
PasswordAuthentication = false;
|
||||||
|
PermitRootLogin = "no";
|
||||||
|
X11Forwarding = false;
|
||||||
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
9
modules/nixos/protonvpn.nix
Normal file
9
modules/nixos/protonvpn.nix
Normal file
@@ -0,0 +1,9 @@
|
|||||||
|
{ config, lib, pkgs, ... }:
|
||||||
|
|
||||||
|
{
|
||||||
|
networking.firewall.checkReversePath = false;
|
||||||
|
environment.systemPackages = with pkgs; [
|
||||||
|
wireguard-tools
|
||||||
|
protonvpn-gui
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -5,7 +5,7 @@
|
|||||||
users.users.aaron = {
|
users.users.aaron = {
|
||||||
isNormalUser = true;
|
isNormalUser = true;
|
||||||
group = "users";
|
group = "users";
|
||||||
extraGroups = [ "wheel" "networkmanager" ];
|
extraGroups = [ "wheel" "networkmanager" "docker" ];
|
||||||
shell = pkgs.zsh;
|
shell = pkgs.zsh;
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -14,10 +14,5 @@
|
|||||||
enable = true;
|
enable = true;
|
||||||
enableCompletion = true;
|
enableCompletion = true;
|
||||||
autosuggestions.enable = true;
|
autosuggestions.enable = true;
|
||||||
ohMyZsh = {
|
|
||||||
enable = true;
|
|
||||||
plugins = [ "git" "sudo" ];
|
|
||||||
theme = "gentoo";
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user