nixfiles/nixos/modules/common.nix

253 lines
6.8 KiB
Nix
Raw Normal View History

{ lib, pkgsFlake, pkgs, pkgs', self, inputs, config, ... }:
2022-02-13 13:10:21 +00:00
let
inherit (lib) mkIf mkDefault mkMerge;
inherit (lib.my) mkDefault';
2022-02-13 13:10:21 +00:00
in
{
options = with lib.types; {
2023-06-24 16:33:16 +01:00
my = { };
2022-02-13 13:10:21 +00:00
};
2022-02-06 00:06:26 +00:00
imports = [
inputs.impermanence.nixosModule
2023-01-08 18:50:52 +00:00
inputs.ragenix.nixosModules.age
2022-11-20 18:41:49 +00:00
inputs.sharry.nixosModules.default
];
2022-02-16 01:38:17 +00:00
config = mkMerge [
2022-02-19 22:55:53 +00:00
{
system = {
stateVersion = "22.05";
configurationRevision = with inputs; mkIf (self ? rev) self.rev;
};
2022-02-13 23:06:31 +00:00
home-manager = {
# Installs packages in the system config instead of in the local profile on activation
2022-02-13 23:06:31 +00:00
useUserPackages = mkDefault true;
};
2022-02-06 00:06:26 +00:00
2022-02-13 13:10:21 +00:00
users = {
mutableUsers = false;
};
2022-02-06 00:06:26 +00:00
2022-02-13 13:10:21 +00:00
security = {
sudo.enable = mkDefault false;
doas = {
enable = mkDefault true;
wheelNeedsPassword = mkDefault false;
2022-02-06 00:06:26 +00:00
};
2022-02-13 13:10:21 +00:00
};
2022-02-06 00:06:26 +00:00
2022-02-13 13:10:21 +00:00
nix = {
package = pkgs'.mine.nix;
2024-12-12 12:25:34 +00:00
channel.enable = false;
2023-11-17 22:57:44 +00:00
settings = with lib.my.c.nix; {
trusted-users = [ "@wheel" ];
experimental-features = [ "nix-command" "flakes" "ca-derivations" ];
2023-11-17 22:57:44 +00:00
extra-substituters = cache.substituters;
extra-trusted-public-keys = cache.keys;
2023-11-18 00:10:05 +00:00
connect-timeout = 5;
fallback = true;
};
registry = {
pkgs = {
to = {
type = "path";
path = "${pkgsFlake}";
};
exact = true;
};
};
gc = {
options = mkDefault "--max-freed $((8 * 1024**3))";
automatic = mkDefault true;
};
2022-02-13 13:10:21 +00:00
};
nixpkgs = {
2022-02-13 17:44:14 +00:00
overlays = [
2022-02-19 22:55:53 +00:00
inputs.deploy-rs.overlay
2022-11-20 18:41:49 +00:00
inputs.sharry.overlays.default
2023-02-20 01:43:48 +00:00
inputs.borgthin.overlays.default
2023-04-23 23:44:55 +01:00
inputs.boardie.overlays.default
2022-02-13 17:44:14 +00:00
];
2022-02-13 13:10:21 +00:00
config = {
allowUnfree = true;
};
2022-02-13 13:10:21 +00:00
};
documentation = {
2022-02-21 01:15:27 +00:00
enable = mkDefault true;
nixos = {
enable = mkDefault true;
options.warningsAreErrors = mkDefault false;
};
};
2022-02-13 23:06:31 +00:00
time.timeZone = mkDefault "Europe/Dublin";
2022-09-08 20:31:44 +01:00
i18n.defaultLocale = "en_IE.UTF-8";
2022-02-13 23:06:31 +00:00
2022-02-13 13:10:21 +00:00
boot = {
# Use latest LTS release by default
kernelPackages = mkDefault (lib.my.c.kernel.lts pkgs);
2022-05-23 00:57:25 +01:00
kernel = {
sysctl = {
"net.ipv6.route.max_size" = mkDefault 16384;
};
};
2023-12-04 23:00:25 +00:00
2022-02-13 13:10:21 +00:00
loader = {
efi = {
efiSysMountPoint = mkDefault "/boot";
2022-06-30 00:49:23 +01:00
# Should generally be enough with just /EFI/BOOT/BOOTX64.EFI in place
2022-02-13 13:10:21 +00:00
canTouchEfiVariables = mkDefault false;
};
2022-02-17 15:47:24 +00:00
grub = {
memtest86.enable = mkDefault true;
};
2022-02-13 13:10:21 +00:00
systemd-boot = {
enable = mkDefault true;
editor = mkDefault true;
consoleMode = mkDefault "max";
configurationLimit = mkDefault 10;
memtest86.enable = mkDefault true;
};
};
2023-12-04 23:00:25 +00:00
initrd = {
systemd = {
enable = mkDefault true;
emergencyAccess = mkDefault true;
};
services.lvm.enable = mkDefault true;
};
2022-02-13 13:10:21 +00:00
};
system = {
nixos = {
distroName = mkDefault' "JackOS";
};
};
2022-02-06 00:19:29 +00:00
environment.etc = {
"nixos/flake.nix".source = "/run/nixfiles/flake.nix";
};
environment.systemPackages = with pkgs; mkMerge [
[
bash-completion
git
2023-05-13 22:19:56 +01:00
unzip
]
(mkIf config.services.netdata.enable [ netdata ])
2022-02-13 13:10:21 +00:00
];
2022-02-06 00:06:26 +00:00
programs = {
# This will enable generating completions at build time and prevent home-manager fish from generating them
# locally
fish.enable = mkDefault true;
# TODO: This is expecting to look up the channel for the database...
command-not-found.enable = mkDefault false;
2024-11-30 17:45:59 +00:00
vim = {
enable = true;
defaultEditor = true;
};
};
2022-02-16 01:38:17 +00:00
services = {
kmscon = {
2022-02-20 16:10:57 +00:00
# As it turns out, kmscon hasn't been updated in years and has some bugs...
enable = mkDefault false;
2022-02-16 01:38:17 +00:00
hwRender = mkDefault true;
extraOptions = "--verbose";
extraConfig =
''
font-name=SauceCodePro Nerd Font Mono
'';
};
getty.greetingLine = mkDefault' ''<<< Welcome to ${config.system.nixos.distroName} ${config.system.nixos.label} (\m) - \l >>>'';
2022-02-16 01:38:17 +00:00
openssh = {
enable = mkDefault true;
2023-06-24 16:33:16 +01:00
settings = {
PermitRootLogin = mkDefault "no";
PasswordAuthentication = mkDefault false;
StrictModes = mkDefault true;
};
2022-02-16 01:38:17 +00:00
};
2022-06-12 17:27:11 +01:00
netdata = {
config = {
global = {
"memory mode" = "dbengine";
"page cache size" = 32;
"dbengine multihost disk space" = 256;
};
"plugin:cgroups" = {
"cgroups to match as systemd services" =
" /system.slice/system-*.slice/*.service !/system.slice/*/*.service /system.slice/*.service";
};
2022-06-12 17:27:11 +01:00
};
configDir = {
"go.d.conf" = mkDefault (pkgs.writeText "netdata-go.d.conf" ''
modules:
systemdunits: yes
'');
"go.d/systemdunits.conf" = mkDefault (pkgs.writeText "netdata-systemdunits.conf" ''
jobs:
- name: service-units
include:
- '*.service'
- name: socket-units
include:
- '*.socket'
'');
};
2022-06-12 17:27:11 +01:00
};
2022-02-13 13:10:21 +00:00
};
systemd = {
tmpfiles.rules = [
"d /nix/tmp 0775 root nixbld 24h"
];
services = {
nix-daemon.environment.TMPDIR = "/nix/tmp";
netdata = mkIf config.services.netdata.enable {
# python.d plugin script does #!/usr/bin/env bash
path = with pkgs; [ bash ];
};
nixfiles-mutable = {
description = "Mutable nixfiles";
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
};
path = with pkgs; [ util-linux ];
script = ''
nixfilesDir="${self}"
mkdir -p /run/nixfiles{,/.rw,/.work}
mount -t overlay overlay -o lowerdir="$nixfilesDir",upperdir=/run/nixfiles/.rw,workdir=/run/nixfiles/.work /run/nixfiles
chmod -R u+w /run/nixfiles
'';
preStop = ''
umount /run/nixfiles
rm -rf /run/nixfiles
'';
wantedBy = [ "multi-user.target" ];
};
};
};
2022-02-16 01:38:17 +00:00
}
(mkIf config.services.kmscon.enable {
fonts.fonts = with pkgs; [
2024-11-30 17:45:59 +00:00
nerd-fonts.sauce-code-pro
2022-02-16 01:38:17 +00:00
];
})
];
meta.buildDocsInSandbox = false;
2022-02-13 13:10:21 +00:00
}