2022-02-19 23:03:59 +00:00
|
|
|
{ lib, pkgs, pkgs', inputs, config, ... }:
|
2022-02-13 13:10:21 +00:00
|
|
|
let
|
2022-05-16 00:05:02 +01:00
|
|
|
inherit (lib) mkIf mkDefault mkMerge;
|
2022-02-19 23:03:59 +00:00
|
|
|
inherit (lib.my) mkBoolOpt' dummyOption;
|
2022-02-13 13:10:21 +00:00
|
|
|
in
|
|
|
|
{
|
2022-02-15 20:50:27 +00:00
|
|
|
options = with lib.types; {
|
|
|
|
my = {
|
2022-02-17 19:14:10 +00:00
|
|
|
ssh = {
|
2022-02-19 22:55:53 +00:00
|
|
|
strictModes = mkBoolOpt' true
|
2022-02-17 19:14:10 +00:00
|
|
|
("Specifies whether sshd(8) should check file modes and ownership of the user's files and home directory "+
|
|
|
|
"before accepting login.");
|
|
|
|
};
|
2022-02-15 20:50:27 +00:00
|
|
|
};
|
2022-02-13 13:10:21 +00:00
|
|
|
};
|
2022-02-06 00:06:26 +00:00
|
|
|
|
2022-02-20 15:59:07 +00:00
|
|
|
imports = [
|
|
|
|
inputs.impermanence.nixosModule
|
|
|
|
inputs.agenix.nixosModules.age
|
|
|
|
];
|
|
|
|
|
2022-02-16 01:38:17 +00:00
|
|
|
config = mkMerge [
|
2022-02-19 22:55:53 +00:00
|
|
|
{
|
2022-02-20 23:55:51 +00:00
|
|
|
system = {
|
2022-05-28 18:38:03 +01:00
|
|
|
stateVersion = "22.05";
|
2022-02-20 23:55:51 +00:00
|
|
|
configurationRevision = with inputs; mkIf (self ? rev) self.rev;
|
|
|
|
};
|
|
|
|
|
2022-02-13 23:06:31 +00:00
|
|
|
home-manager = {
|
2022-02-15 20:50:27 +00:00
|
|
|
# Installs packages in the system config instead of in the local profile on activation
|
2022-02-13 23:06:31 +00:00
|
|
|
useUserPackages = mkDefault true;
|
|
|
|
};
|
2022-02-06 00:06:26 +00:00
|
|
|
|
2022-02-13 13:10:21 +00:00
|
|
|
users = {
|
|
|
|
mutableUsers = false;
|
|
|
|
};
|
2022-02-06 00:06:26 +00:00
|
|
|
|
2022-02-13 13:10:21 +00:00
|
|
|
security = {
|
|
|
|
sudo.enable = mkDefault false;
|
|
|
|
doas = {
|
|
|
|
enable = mkDefault true;
|
|
|
|
wheelNeedsPassword = mkDefault false;
|
2022-02-06 00:06:26 +00:00
|
|
|
};
|
2022-02-13 13:10:21 +00:00
|
|
|
};
|
2022-02-06 00:06:26 +00:00
|
|
|
|
2022-02-13 13:10:21 +00:00
|
|
|
nix = {
|
2022-05-07 15:12:29 +01:00
|
|
|
package = pkgs'.mine.nix;
|
2022-05-28 18:38:03 +01:00
|
|
|
settings = {
|
|
|
|
trusted-users = [ "@wheel" ];
|
|
|
|
experimental-features = [ "nix-command" "flakes" "ca-derivations" ];
|
|
|
|
};
|
2022-06-06 13:24:46 +01:00
|
|
|
gc = {
|
|
|
|
options = mkDefault "--max-freed $((8 * 1024**3))";
|
|
|
|
automatic = mkDefault true;
|
|
|
|
};
|
2022-02-13 13:10:21 +00:00
|
|
|
};
|
|
|
|
nixpkgs = {
|
2022-02-13 17:44:14 +00:00
|
|
|
overlays = [
|
2022-02-19 22:55:53 +00:00
|
|
|
inputs.deploy-rs.overlay
|
2022-02-13 17:44:14 +00:00
|
|
|
];
|
2022-02-13 13:10:21 +00:00
|
|
|
config = {
|
|
|
|
allowUnfree = true;
|
2022-02-11 01:15:24 +00:00
|
|
|
};
|
2022-02-13 13:10:21 +00:00
|
|
|
};
|
2022-02-11 01:15:24 +00:00
|
|
|
|
2022-02-15 20:50:27 +00:00
|
|
|
documentation = {
|
2022-02-21 01:15:27 +00:00
|
|
|
enable = mkDefault true;
|
2022-02-15 20:50:27 +00:00
|
|
|
nixos = {
|
|
|
|
enable = mkDefault true;
|
|
|
|
options.warningsAreErrors = mkDefault false;
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2022-02-13 23:06:31 +00:00
|
|
|
time.timeZone = mkDefault "Europe/Dublin";
|
|
|
|
|
2022-02-13 13:10:21 +00:00
|
|
|
boot = {
|
|
|
|
# Use latest LTS release by default
|
|
|
|
kernelPackages = mkDefault pkgs.linuxKernel.packages.linux_5_15;
|
2022-05-23 00:57:25 +01:00
|
|
|
kernel = {
|
|
|
|
sysctl = {
|
|
|
|
"net.ipv6.route.max_size" = mkDefault 16384;
|
|
|
|
};
|
|
|
|
};
|
2022-02-13 13:10:21 +00:00
|
|
|
loader = {
|
|
|
|
efi = {
|
|
|
|
efiSysMountPoint = mkDefault "/boot";
|
|
|
|
canTouchEfiVariables = mkDefault false;
|
|
|
|
};
|
2022-02-17 15:47:24 +00:00
|
|
|
grub = {
|
|
|
|
memtest86.enable = mkDefault true;
|
|
|
|
};
|
2022-02-13 13:10:21 +00:00
|
|
|
systemd-boot = {
|
|
|
|
enable = mkDefault true;
|
|
|
|
editor = mkDefault true;
|
|
|
|
consoleMode = mkDefault "max";
|
|
|
|
configurationLimit = mkDefault 10;
|
|
|
|
memtest86.enable = mkDefault true;
|
2022-02-11 01:15:24 +00:00
|
|
|
};
|
|
|
|
};
|
2022-02-13 13:10:21 +00:00
|
|
|
};
|
2022-02-06 00:19:29 +00:00
|
|
|
|
2022-02-13 13:10:21 +00:00
|
|
|
environment.systemPackages = with pkgs; [
|
|
|
|
bash-completion
|
|
|
|
vim
|
|
|
|
];
|
2022-02-06 00:06:26 +00:00
|
|
|
|
2022-02-20 23:55:51 +00:00
|
|
|
programs = {
|
|
|
|
# This will enable generating completions at build time and prevent home-manager fish from generating them
|
|
|
|
# locally
|
|
|
|
fish.enable = mkDefault true;
|
|
|
|
};
|
|
|
|
|
2022-02-16 01:38:17 +00:00
|
|
|
services = {
|
|
|
|
kmscon = {
|
2022-02-20 16:10:57 +00:00
|
|
|
# As it turns out, kmscon hasn't been updated in years and has some bugs...
|
|
|
|
enable = mkDefault false;
|
2022-02-16 01:38:17 +00:00
|
|
|
hwRender = mkDefault true;
|
|
|
|
extraOptions = "--verbose";
|
|
|
|
extraConfig =
|
|
|
|
''
|
|
|
|
font-name=SauceCodePro Nerd Font Mono
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
openssh = {
|
2022-02-17 17:08:25 +00:00
|
|
|
enable = mkDefault true;
|
2022-02-17 19:14:10 +00:00
|
|
|
extraConfig = ''StrictModes ${if config.my.ssh.strictModes then "yes" else "no"}'';
|
2022-02-19 22:55:53 +00:00
|
|
|
permitRootLogin = mkDefault "no";
|
|
|
|
passwordAuthentication = mkDefault false;
|
2022-02-16 01:38:17 +00:00
|
|
|
};
|
2022-02-13 13:10:21 +00:00
|
|
|
};
|
2022-02-16 01:38:17 +00:00
|
|
|
}
|
|
|
|
(mkIf config.services.kmscon.enable {
|
|
|
|
fonts.fonts = with pkgs; [
|
|
|
|
(nerdfonts.override {
|
|
|
|
fonts = [ "SourceCodePro" ];
|
|
|
|
})
|
|
|
|
];
|
|
|
|
})
|
|
|
|
];
|
2022-02-15 20:50:27 +00:00
|
|
|
|
|
|
|
meta.buildDocsInSandbox = false;
|
2022-02-13 13:10:21 +00:00
|
|
|
}
|