diff --git a/flake.lock b/flake.lock index 44edeab..f53b1f6 100644 --- a/flake.lock +++ b/flake.lock @@ -266,11 +266,11 @@ ] }, "locked": { - "lastModified": 1751117291, - "narHash": "sha256-iOeiPypZkl6uPL5mQ4aFG4wYVs9w9BJZ2/5XHlLgyIk=", + "lastModified": 1757763404, + "narHash": "sha256-a1h+58wDOtbQXrHoZwLwB7PhXwFhBXRHhNRhAQGq/oY=", "ref": "refs/heads/main", - "rev": "2a4818dc2158cbdad34a701ab12d0b1cf7f52c46", - "revCount": 45, + "rev": "07a5fbca27ec941c841ad93f2ac65bc529225a51", + "revCount": 46, "type": "git", "url": "https://git.berlin.ccc.de/servicepoint/servicepoint-cli.git" }, @@ -290,11 +290,11 @@ ] }, "locked": { - "lastModified": 1752323001, - "narHash": "sha256-YEcYegmlv12yN9VWrz2qt0nyL+9EeGIlrDvac8Pf7Cw=", + "lastModified": 1757763091, + "narHash": "sha256-V3E6JKGzCrq5u+hp38sAdKv/EoxU+X0qfSoBIPxALi4=", "ref": "refs/heads/main", - "rev": "75a0ae7a59e687bea5f92791a2d64c048f35846d", - "revCount": 119, + "rev": "493b7b0343334019b372176f811a966839ba9aa5", + "revCount": 121, "type": "git", "url": "https://git.berlin.ccc.de/servicepoint/servicepoint-simulator.git" }, @@ -358,11 +358,11 @@ ] }, "locked": { - "lastModified": 1755431984, - "narHash": "sha256-iBgSdzkta6zQ2eIRWjmJTLZ3b1e1EZiCyCPcgCdqPGU=", + "lastModified": 1757847061, + "narHash": "sha256-YW8fpD35tD+1zTkxk0WhP7FJSL15JlFfG7tscgkdI+A=", "ref": "refs/heads/main", - "rev": "31abcb7a9583c4ed931f658eca3e3c1970e60814", - "revCount": 28, + "rev": "ddff8c9b206564dd9b9007e4e894afa6f7860fc8", + "revCount": 30, "type": "git", "url": "https://git.berlin.ccc.de/vinzenz/zerforschen.plus" }, diff --git a/flake.nix b/flake.nix index c7e62e0..4d7ec50 100644 --- a/flake.nix +++ b/flake.nix @@ -1,7 +1,6 @@ { inputs = { nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.05"; - nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable"; home-manager = { @@ -50,7 +49,7 @@ }; outputs = - inputs@{ + { self, nixpkgs, home-manager, @@ -59,31 +58,74 @@ nixpkgs-unstable, servicepoint-cli, servicepoint-simulator, - naersk, nix-vscode-extensions, ... }: let devices = { - vinzenz-lpt2 = "x86_64-linux"; - vinzenz-pc2 = "x86_64-linux"; - ronja-pc = "x86_64-linux"; - hetzner-vpn2 = "aarch64-linux"; - forgejo-runner-1 = "aarch64-linux"; + vinzenz-lpt2 = { + system = "x86_64-linux"; + additional-modules = [ + self.nixosModules.user-vinzenz + + self.nixosModules.gnome + self.nixosModules.wine-gaming + self.nixosModules.steam + self.nixosModules.printing + self.nixosModules.podman + self.nixosModules.vinzenz-desktop-settings + self.nixosModules.intel-graphics + ]; + home-manager-users = { + inherit (self.homeConfigurations) vinzenz; + }; + }; + vinzenz-pc2 = { + system = "x86_64-linux"; + additional-modules = [ + self.nixosModules.user-vinzenz + self.nixosModules.user-ronja + + self.nixosModules.gnome + self.nixosModules.wine-gaming + self.nixosModules.steam + self.nixosModules.printing + self.nixosModules.podman + self.nixosModules.vinzenz-desktop-settings + self.nixosModules.amd-graphics + ]; + home-manager-users = { + inherit (self.homeConfigurations) vinzenz ronja; + }; + }; + ronja-pc = { + system = "x86_64-linux"; + additional-modules = [ + self.nixosModules.user-ronja + + self.nixosModules.gnome + self.nixosModules.steam + self.nixosModules.wine-gaming + self.nixosModules.vinzenz-desktop-settings + ]; + home-manager-users = { + inherit (self.homeConfigurations) ronja; + }; + }; + hetzner-vpn2 = { + system = "aarch64-linux"; + }; + forgejo-runner-1 = { + system = "aarch64-linux"; + additional-modules = [ self.nixosModules.podman ]; + }; }; - homeDevices = [ - "vinzenz-lpt2" - "vinzenz-pc2" - "ronja-pc" - ]; - forDevice = f: nixpkgs.lib.mapAttrs f devices; - supported-systems = [ - "x86_64-linux" - "aarch64-linux" - ]; + inherit (nixpkgs) lib; + forDevice = f: lib.mapAttrs (device: value: f (value // { inherit device; })) devices; + supported-systems = lib.attrsets.mapAttrsToList (k: v: v.system) devices; forAllSystems = f: - nixpkgs.lib.genAttrs supported-systems ( + lib.genAttrs supported-systems ( system: f rec { inherit system; @@ -91,67 +133,141 @@ } ); in - rec { + { + lib = { + importDir = + dir: + (lib.attrsets.mapAttrs' ( + m: _: + lib.attrsets.nameValuePair (lib.strings.removeSuffix ".nix" m) { imports = [ "${dir}/${m}" ]; } + ) (builtins.readDir dir)); + }; + + overlays = { + unstable-packages = final: prev: { + unstable = import nixpkgs-unstable { + inherit (prev) system config; + }; + }; + }; + + nixosModules = (self.lib.importDir ./nixosModules) // { + niri = { + imports = [ niri.nixosModules.niri ]; + nixpkgs.overlays = [ niri.overlays.niri ]; + }; + pkgs-unstable = { + nixpkgs.overlays = [ self.overlays.unstable-packages ]; + }; + pkgs-vscode-extensions = { + nixpkgs.overlays = [ nix-vscode-extensions.overlays.default ]; + }; + # required modules to use other modules, should not do anything on their own + default = { + imports = [ self.nixosModules.allowed-unfree-list ]; + }; + }; + + homeModules = self.lib.importDir ./homeModules; + homeConfigurations = self.lib.importDir ./homeConfigurations; + + formatter = forAllSystems ({ pkgs, ... }: pkgs.nixfmt-tree); + nixosConfigurations = forDevice ( - device: system: + { + device, + system, + home-manager-users ? { }, + additional-modules ? [ ], + }: let specialArgs = { - inherit inputs device; + inherit device; }; in nixpkgs.lib.nixosSystem { inherit system specialArgs; modules = [ - { networking.hostName = device; } - - ./modules/globalinstalls.nix - ./modules/networking.nix - ./modules/nixpkgs.nix - ./modules/lix.nix - - ./hosts/${device}/hardware.nix - ./hosts/${device}/imports.nix - ./hosts/${device}/configuration.nix - { + networking.hostName = device; + nixpkgs = { + inherit system; + hostPlatform = lib.mkDefault system; + }; + system = { + stateVersion = "22.11"; + autoUpgrade.flake = "git+https://git.berlin.ccc.de/vinzenz/nixos-configuration.git"; + }; + nixpkgs.overlays = [ - overlays.unstable-packages + self.overlays.unstable-packages ]; + + nix.settings.experimental-features = [ + "nix-command" + "flakes" + ]; + + documentation = { + info.enable = false; # info pages and the info command + doc.enable = false; # documentation distributed in packages' /share/doc + }; } + + ./nixosConfigurations/${device} + + self.nixosModules.default + self.nixosModules.lix-is-nix + self.nixosModules.globalinstalls + self.nixosModules.autoupdate + self.nixosModules.openssh + self.nixosModules.tailscale + self.nixosModules.allowed-unfree-list + self.nixosModules.extra-caches + self.nixosModules.systemd-boot + + zerforschen-plus.nixosModules.default ] - ++ (nixpkgs.lib.optionals (builtins.elem device homeDevices) [ - home-manager.nixosModules.home-manager - { home-manager.extraSpecialArgs = specialArgs; } - ./modules/home-manager.nix - - ./modules/i18n.nix - - niri.nixosModules.niri + ++ (nixpkgs.lib.optionals (home-manager-users != { }) [ { - nixpkgs.overlays = [ - niri.overlays.niri - overlays.servicepoint-packages - nix-vscode-extensions.overlays.default + home-manager = { + extraSpecialArgs = specialArgs; + useGlobalPkgs = true; + useUserPackages = true; + }; + + time.timeZone = "Europe/Berlin"; + + home-manager.sharedModules = [ + { home.stateVersion = "22.11"; } + self.homeModules.adwaita + self.homeModules.git + self.homeModules.templates + self.homeModules.zsh-basics + self.homeModules.nano + self.homeModules.gnome-extensions ]; + + home-manager.users = home-manager-users; } - ]); + + self.nixosModules.pkgs-unstable + self.nixosModules.pkgs-vscode-extensions + self.nixosModules.niri + self.nixosModules.kdeconnect + self.nixosModules.en-de + self.nixosModules.gnome + self.nixosModules.modern-desktop + self.nixosModules.nix-ld + self.nixosModules.quiet-boot + self.nixosModules.firmware-updates + + home-manager.nixosModules.home-manager + servicepoint-simulator.nixosModules.default + servicepoint-cli.nixosModules.default + ]) + ++ additional-modules; } ); - - overlays = { - unstable-packages = final: prev: { - unstable = import nixpkgs-unstable { - system = prev.system; - config = prev.config; - }; - }; - servicepoint-packages = final: prev: { - servicepoint-cli = servicepoint-cli.legacyPackages."${prev.system}".servicepoint-cli; - servicepoint-simulator = - servicepoint-simulator.legacyPackages."${prev.system}".servicepoint-simulator; - }; - }; - - formatter = forAllSystems ({ pkgs, ... }: pkgs.nixfmt-tree); }; } diff --git a/home/ronja/default.nix b/home/ronja/default.nix deleted file mode 100644 index 7c2f96d..0000000 --- a/home/ronja/default.nix +++ /dev/null @@ -1,25 +0,0 @@ -{ pkgs, ... }: -{ - config = { - # Define user account - users.users.ronja = { - isNormalUser = true; - name = "ronja"; - description = "Ronja"; - home = "/home/ronja"; - extraGroups = [ - "networkmanager" - "wheel" - "games" - "podman" - "openvscode-server" - ]; - shell = pkgs.zsh; - }; - - home-manager.users.ronja.imports = [ - ./configuration.nix - ./vscode.nix - ]; - }; -} diff --git a/home/vinzenz/default.nix b/home/vinzenz/default.nix deleted file mode 100644 index e555eba..0000000 --- a/home/vinzenz/default.nix +++ /dev/null @@ -1,51 +0,0 @@ -{ pkgs, ... }: -{ - config = { - users.users.vinzenz = { - isNormalUser = true; - name = "vinzenz"; - description = "Vinzenz"; - home = "/home/vinzenz"; - extraGroups = [ - "networkmanager" - "wheel" - "games" - "dialout" - "podman" - "nginx" - "adbusers" - "kvm" - "input" - "video" - ]; - shell = pkgs.zsh; - autoSubUidGidRange = true; - }; - - nix.settings.trusted-users = [ "vinzenz" ]; - - home-manager.users.vinzenz.imports = [ - ./configuration.nix - ./editorconfig.nix - ./fuzzel.nix - ./git.nix - ./gnome.nix - #./niri.nix - ./ssh.nix - ./swaylock.nix - ./vscode.nix - ./waybar.nix - ./zsh.nix - ]; - - allowedUnfreePackages = [ - "rider" - "pycharm-professional" - "jetbrains-toolbox" - - "anydesk" - - "vscode-extension-ms-dotnettools-csharp" - ]; - }; -} diff --git a/home/vinzenz/gnome.nix b/home/vinzenz/gnome.nix deleted file mode 100644 index 5648cf6..0000000 --- a/home/vinzenz/gnome.nix +++ /dev/null @@ -1,26 +0,0 @@ -{ pkgs, ... }: -{ - config = { - home.packages = - with pkgs.gnomeExtensions; - [ - gsconnect - # battery-health-charging - quick-settings-tweaker - solaar-extension - alphabetical-app-grid - ] - ++ (with pkgs; [ foliate ]); - - dconf.settings = { - "org/gnome/shell" = { - enabled-extensions = [ - "GPaste@gnome-shell-extensions.gnome.org" - "gsconnect@andyholmes.github.io" - "solaar-extension@sidevesh" - "AlphabeticalAppGrid@stuarthayhurst" - ]; - }; - }; - }; -} diff --git a/home/ronja/configuration.nix b/homeConfigurations/ronja/default.nix similarity index 98% rename from home/ronja/configuration.nix rename to homeConfigurations/ronja/default.nix index 26cceac..0f202cd 100644 --- a/home/ronja/configuration.nix +++ b/homeConfigurations/ronja/default.nix @@ -1,5 +1,6 @@ { config, pkgs, ... }: { + imports = [ ./vscode.nix ]; config = { home.packages = with pkgs; [ ## Apps diff --git a/home/ronja/vscode.nix b/homeConfigurations/ronja/vscode.nix similarity index 100% rename from home/ronja/vscode.nix rename to homeConfigurations/ronja/vscode.nix diff --git a/home/vinzenz/.config/containers/policy.json b/homeConfigurations/vinzenz/.config/containers/policy.json similarity index 100% rename from home/vinzenz/.config/containers/policy.json rename to homeConfigurations/vinzenz/.config/containers/policy.json diff --git a/home/vinzenz/.zsh/p10k.zsh b/homeConfigurations/vinzenz/.zsh/p10k.zsh similarity index 99% rename from home/vinzenz/.zsh/p10k.zsh rename to homeConfigurations/vinzenz/.zsh/p10k.zsh index 3b6355d..fc3c2b2 100644 --- a/home/vinzenz/.zsh/p10k.zsh +++ b/homeConfigurations/vinzenz/.zsh/p10k.zsh @@ -60,8 +60,8 @@ nodeenv # node.js environment (https://github.com/ekalinin/nodeenv) # node_version # node.js version # go_version # go version (https://golang.org) - # rust_version # rustc version (https://www.rust-lang.org) - # dotnet_version # .NET version (https://dotnet.microsoft.com) + rust_version # rustc version (https://www.rust-lang.org) + dotnet_version # .NET version (https://dotnet.microsoft.com) # php_version # php version (https://www.php.net/) # laravel_version # laravel php framework version (https://laravel.com/) # java_version # java version (https://www.java.com/) @@ -756,14 +756,14 @@ typeset -g POWERLEVEL9K_RANGER_BACKGROUND=0 # Custom icon. # typeset -g POWERLEVEL9K_RANGER_VISUAL_IDENTIFIER_EXPANSION='⭐' - + ####################[ yazi: yazi shell (https://github.com/sxyazi/yazi) ]##################### # Yazi shell color. typeset -g POWERLEVEL9K_YAZI_FOREGROUND=3 typeset -g POWERLEVEL9K_YAZI_BACKGROUND=0 # Custom icon. # typeset -g POWERLEVEL9K_YAZI_VISUAL_IDENTIFIER_EXPANSION='⭐' - + ######################[ nnn: nnn shell (https://github.com/jarun/nnn) ]####################### # Nnn shell color. typeset -g POWERLEVEL9K_NNN_FOREGROUND=0 diff --git a/home/vinzenz/configuration.nix b/homeConfigurations/vinzenz/configuration.nix similarity index 97% rename from home/vinzenz/configuration.nix rename to homeConfigurations/vinzenz/configuration.nix index 74be21f..ace8086 100644 --- a/home/vinzenz/configuration.nix +++ b/homeConfigurations/vinzenz/configuration.nix @@ -56,6 +56,10 @@ icu nextcloud-client + + lutris + + foliate ]; home.file = { diff --git a/homeConfigurations/vinzenz/default.nix b/homeConfigurations/vinzenz/default.nix new file mode 100644 index 0000000..33cfceb --- /dev/null +++ b/homeConfigurations/vinzenz/default.nix @@ -0,0 +1,15 @@ +{ + imports = [ + ./configuration.nix + ./editorconfig.nix + ./fuzzel.nix + ./git.nix + ./gnome.nix + #./niri.nix + ./ssh.nix + ./swaylock.nix + ./vscode.nix + ./waybar.nix + ./zsh.nix + ]; +} diff --git a/home/vinzenz/editorconfig.nix b/homeConfigurations/vinzenz/editorconfig.nix similarity index 97% rename from home/vinzenz/editorconfig.nix rename to homeConfigurations/vinzenz/editorconfig.nix index 496c714..1ebffa8 100644 --- a/home/vinzenz/editorconfig.nix +++ b/homeConfigurations/vinzenz/editorconfig.nix @@ -1,4 +1,3 @@ -{ ... }: { config.editorconfig = { enable = true; diff --git a/home/vinzenz/fuzzel.nix b/homeConfigurations/vinzenz/fuzzel.nix similarity index 100% rename from home/vinzenz/fuzzel.nix rename to homeConfigurations/vinzenz/fuzzel.nix diff --git a/home/vinzenz/git.nix b/homeConfigurations/vinzenz/git.nix similarity index 98% rename from home/vinzenz/git.nix rename to homeConfigurations/vinzenz/git.nix index ddaa890..537fe61 100644 --- a/home/vinzenz/git.nix +++ b/homeConfigurations/vinzenz/git.nix @@ -1,4 +1,3 @@ -{ ... }: { config.programs.git = { enable = true; diff --git a/homeConfigurations/vinzenz/gnome.nix b/homeConfigurations/vinzenz/gnome.nix new file mode 100644 index 0000000..7424363 --- /dev/null +++ b/homeConfigurations/vinzenz/gnome.nix @@ -0,0 +1,31 @@ +{ pkgs, ... }: +{ + config = { + home.packages = with pkgs; [ + gitg + meld + simple-scan + pinta + dconf-editor + impression # usb image writer + papers # pdf viewer + gnome-software # for flatpak apps + gnomeExtensions.solaar-extension + snapshot + ]; + + dconf.settings = { + "org/gnome/shell".enabled-extensions = [ + "GPaste@gnome-shell-extensions.gnome.org" + "solaar-extension@sidevesh" + ]; + "org/gnome/desktop/interface".color-scheme = "prefer-dark"; + "org/gnome/desktop/wm/keybindings" = { + switch-windows = [ "Tab" ]; + switch-windows-backward = [ "Tab" ]; + switch-applications = [ "Tab" ]; + switch-applications-backward = [ "Tab" ]; + }; + }; + }; +} diff --git a/home/vinzenz/niri.nix b/homeConfigurations/vinzenz/niri.nix similarity index 98% rename from home/vinzenz/niri.nix rename to homeConfigurations/vinzenz/niri.nix index 3cb557a..3562ae1 100644 --- a/home/vinzenz/niri.nix +++ b/homeConfigurations/vinzenz/niri.nix @@ -16,16 +16,7 @@ name = "adwaita-dark"; }; - services = { - kdeconnect = { - enable = true; - # this still shows up in gnome session starting with 25.05 - # indicator = true; - }; - mako = { - enable = true; - }; - }; + services.mako.enable = true; programs.niri.settings = { input.keyboard.xkb.layout = "de"; diff --git a/home/vinzenz/ssh.nix b/homeConfigurations/vinzenz/ssh.nix similarity index 99% rename from home/vinzenz/ssh.nix rename to homeConfigurations/vinzenz/ssh.nix index 98acce9..20b4bae 100644 --- a/home/vinzenz/ssh.nix +++ b/homeConfigurations/vinzenz/ssh.nix @@ -1,4 +1,3 @@ -{ ... }: { config.programs.ssh = { enable = true; diff --git a/home/vinzenz/swaylock.nix b/homeConfigurations/vinzenz/swaylock.nix similarity index 100% rename from home/vinzenz/swaylock.nix rename to homeConfigurations/vinzenz/swaylock.nix diff --git a/home/vinzenz/vscode.nix b/homeConfigurations/vinzenz/vscode.nix similarity index 100% rename from home/vinzenz/vscode.nix rename to homeConfigurations/vinzenz/vscode.nix diff --git a/home/vinzenz/waybar.nix b/homeConfigurations/vinzenz/waybar.nix similarity index 100% rename from home/vinzenz/waybar.nix rename to homeConfigurations/vinzenz/waybar.nix diff --git a/home/vinzenz/zsh.nix b/homeConfigurations/vinzenz/zsh.nix similarity index 94% rename from home/vinzenz/zsh.nix rename to homeConfigurations/vinzenz/zsh.nix index d7cbcfa..1278aca 100644 --- a/home/vinzenz/zsh.nix +++ b/homeConfigurations/vinzenz/zsh.nix @@ -20,7 +20,7 @@ my-direnvallow = "echo \"use nix\" > .envrc && direnv allow"; my-ip4 = "ip addr show | grep 192"; deadnix = "nix run github:astro/deadnix -- "; - statix = "nix run git+https://git.peppe.rs/languages/statix -- "; + statix = "nix run github:oppiliappan/statix -- "; }; history = { diff --git a/homeModules/adwaita.nix b/homeModules/adwaita.nix new file mode 100644 index 0000000..96d24c7 --- /dev/null +++ b/homeModules/adwaita.nix @@ -0,0 +1,12 @@ +{ pkgs, ... }: +{ + gtk = { + enable = true; + iconTheme.name = "Adwaita"; + cursorTheme.name = "Adwaita"; + theme = { + name = "adw-gtk3-dark"; + package = pkgs.adw-gtk3; + }; + }; +} diff --git a/homeModules/git.nix b/homeModules/git.nix new file mode 100644 index 0000000..76afceb --- /dev/null +++ b/homeModules/git.nix @@ -0,0 +1,13 @@ +{ + programs = { + git = { + enable = true; + extraConfig.init.defaultBranch = "main"; + }; + + gh = { + enable = true; + gitCredentialHelper.enable = true; + }; + }; +} diff --git a/homeModules/gnome-extensions.nix b/homeModules/gnome-extensions.nix new file mode 100644 index 0000000..9c30c40 --- /dev/null +++ b/homeModules/gnome-extensions.nix @@ -0,0 +1,101 @@ +{ + lib, + pkgs, + osConfig, + config, + ... +}: +{ + options.vinzenz.gnome-extensions = + let + mkDefaultEnabledOption = + name: + lib.mkOption { + default = true; + example = false; + description = "Whether to enable ${name}."; + type = lib.types.bool; + }; + in + { + enable = mkDefaultEnabledOption "gnome extended options"; + appindicator.enable = mkDefaultEnabledOption "appindicator"; + caffeine.enable = mkDefaultEnabledOption "caffeine"; + tailscale-qs.enable = lib.mkOption { + default = osConfig.services.tailscale.enable; + example = true; + description = "Whether to enable tailscale quick setting."; + type = lib.types.bool; + }; + alphabetic-apps.enable = mkDefaultEnabledOption "alphabetic app grid"; + clock-show-seconds = mkDefaultEnabledOption "clock seconds"; + show-battery-percentage = mkDefaultEnabledOption "battery percentage"; + enable-numlock = mkDefaultEnabledOption "num lock on login"; + enable-systool-warning = lib.mkEnableOption "system configuration tool warning"; + edge-tiling = mkDefaultEnabledOption "edge tiling"; + dynamic-workspaces = mkDefaultEnabledOption "dynamic workspaces"; + tap-to-click = mkDefaultEnabledOption "tap to click"; + two-finger-scrolling = mkDefaultEnabledOption "two finger scrolling"; + }; + + config = + let + cfg = config.vinzenz.gnome-extensions; + in + lib.mkIf cfg.enable ( + lib.mkMerge [ + { + dconf = { + enable = true; + settings = { + "org/gnome/shell" = { + disable-user-extensions = false; + disabled-extensions = [ ]; + enabled-extensions = [ ]; + }; + + "ca/desrt/dconf-editor".show-warning = cfg.enable-systool-warning; + "org/gnome/tweaks".show-extensions-notice = cfg.enable-systool-warning; + "org/gnome/mutter" = { + inherit (cfg) edge-tiling dynamic-workspaces; + }; + "org/gnome/desktop/peripherals/touchpad" = { + inherit (cfg) tap-to-click; + two-finger-scrolling-enabled = cfg.two-finger-scrolling; + }; + "org/gnome/desktop/interface" = { + inherit (cfg) clock-show-seconds show-battery-percentage; + }; + }; + }; + } + + (lib.mkIf cfg.tailscale-qs.enable { + home.packages = [ pkgs.gnomeExtensions.tailscale-qs ]; + dconf.settings."org/gnome/shell".enabled-extensions = [ "tailscale@joaophi.github.com" ]; + }) + + (lib.mkIf cfg.appindicator.enable { + home.packages = [ pkgs.gnomeExtensions.appindicator ]; + dconf.settings."org/gnome/shell".enabled-extensions = [ "appindicatorsupport@rgcjonas.gmail.com" ]; + }) + + (lib.mkIf cfg.caffeine.enable { + home.packages = [ pkgs.gnomeExtensions.caffeine ]; + dconf.settings."org/gnome/shell".enabled-extensions = [ "caffeine@patapon.info" ]; + }) + + (lib.mkIf cfg.alphabetic-apps.enable { + home.packages = [ pkgs.gnomeExtensions.alphabetical-app-grid ]; + dconf.settings = { + "org/gnome/shell".enabled-extensions = [ "AlphabeticalAppGrid@stuarthayhurst" ]; + "org/gnome/shell/extensions/alphabetical-app-grid".folder-order-position = "start"; + }; + }) + + (lib.mkIf cfg.enable-numlock { + dconf.settings."org/gnome/desktop/peripherals/keyboard".numlock-state = true; + }) + ] + ); +} diff --git a/homeModules/nano.nix b/homeModules/nano.nix new file mode 100644 index 0000000..ab3e7b2 --- /dev/null +++ b/homeModules/nano.nix @@ -0,0 +1,9 @@ +{ + home = { + sessionVariables.EDITOR = "nano"; + file.".nanorc".text = '' + set linenumbers + set mouse + ''; + }; +} diff --git a/homeModules/templates.nix b/homeModules/templates.nix new file mode 100644 index 0000000..71d2e0b --- /dev/null +++ b/homeModules/templates.nix @@ -0,0 +1,12 @@ +{ + home.file = { + "Templates/Empty file".text = ""; + "Templates/Empty bash script".text = '' + #!/usr/bin/env bash + # abort on error, undefined variables + set -eu + # print commands before execution + set -x + ''; + }; +} diff --git a/homeModules/zsh-basics.nix b/homeModules/zsh-basics.nix new file mode 100644 index 0000000..0b0e281 --- /dev/null +++ b/homeModules/zsh-basics.nix @@ -0,0 +1,13 @@ +{ + programs = { + command-not-found.enable = true; + dircolors.enable = true; + + zsh = { + enable = true; + syntaxHighlighting.enable = true; + autosuggestion.enable = true; + enableVteIntegration = true; + }; + }; +} diff --git a/hooks/pre-commit b/hooks/pre-commit new file mode 100755 index 0000000..6b6b870 --- /dev/null +++ b/hooks/pre-commit @@ -0,0 +1,6 @@ +#!/usr/bin/env bash +set -euxo pipefail + +nix fmt + +nix flake check --all-systems --show-trace diff --git a/hosts/forgejo-runner-1/configuration.nix b/hosts/forgejo-runner-1/configuration.nix deleted file mode 100644 index 345e622..0000000 --- a/hosts/forgejo-runner-1/configuration.nix +++ /dev/null @@ -1,15 +0,0 @@ -{ ... }: -{ - # uncomment for build check on non arm system (requires --impure) - # nixpkgs.buildPlatform = builtins.currentSystem; - services.tailscale.useRoutingFeatures = "both"; - system.autoUpgrade.allowReboot = true; - - users.users = { - root.openssh.authorizedKeys.keys = [ - ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFCJUpbpB3KEKVoKWsKoar9J4RNah8gmQoSH6jQEw5dY vinzenz-pixel-JuiceSSH'' - ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO1CRn4yYTL4XUdCebE8Z4ZeuMujBjorTdWifg911EOv vinzenz-pc2 home roaming'' - ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDNpLDmctyqGpow/ElQvdhY4BLBPS/sigDJ1QEcC7wC vinzenz-lpt2-roaming'' - ]; - }; -} diff --git a/hosts/forgejo-runner-1/imports.nix b/hosts/forgejo-runner-1/imports.nix deleted file mode 100644 index 8b867c6..0000000 --- a/hosts/forgejo-runner-1/imports.nix +++ /dev/null @@ -1,6 +0,0 @@ -{ - imports = [ - ../../modules/podman.nix - ./forgejo-runner.nix - ]; -} diff --git a/hosts/hetzner-vpn2/configuration.nix b/hosts/hetzner-vpn2/configuration.nix deleted file mode 100644 index 8e16ff7..0000000 --- a/hosts/hetzner-vpn2/configuration.nix +++ /dev/null @@ -1,21 +0,0 @@ -{ ... }: -{ - # uncomment for build check on non arm system (requires --impure) - # nixpkgs.buildPlatform = builtins.currentSystem; - - services.tailscale.useRoutingFeatures = "both"; - - users.users = { - root.openssh.authorizedKeys.keys = [ - ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICdYqY3Y1/f1bsAi5Qfyr/UWuX9ixu96IeAlhoQaJkbf'' - ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFCJUpbpB3KEKVoKWsKoar9J4RNah8gmQoSH6jQEw5dY vinzenz-pixel-JuiceSSH'' - ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO1CRn4yYTL4XUdCebE8Z4ZeuMujBjorTdWifg911EOv vinzenz-pc2 home roaming'' - ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDNpLDmctyqGpow/ElQvdhY4BLBPS/sigDJ1QEcC7wC vinzenz-lpt2-roaming'' - ]; - #ronja.openssh.authorizedKeys.keys = [ - # ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIALWKm+d6KL6Vl3grPOcGouiNTkvdhXuWJmcrdEBY2nw ronja-ssh-host-key'' - #]; - }; - - system.autoUpgrade.allowReboot = true; -} diff --git a/hosts/hetzner-vpn2/imports.nix b/hosts/hetzner-vpn2/imports.nix deleted file mode 100644 index 3fadabb..0000000 --- a/hosts/hetzner-vpn2/imports.nix +++ /dev/null @@ -1,5 +0,0 @@ -{ - imports = [ - ./nginx.nix - ]; -} diff --git a/hosts/ronja-pc/configuration.nix b/hosts/ronja-pc/configuration.nix deleted file mode 100644 index 0e9124d..0000000 --- a/hosts/ronja-pc/configuration.nix +++ /dev/null @@ -1,26 +0,0 @@ -{ - config, - pkgs, - ... -}: -{ - # Configure keymap in X11 - services.xserver.xkb = { - layout = "de"; - variant = ""; - }; - - # Configure console keymap - console.keyMap = "de"; - - # List packages installed in system profile. To search, run: - # $ nix search wget - environment.systemPackages = with pkgs; [ - # vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default. - # wget - ]; - - # Open ports in the firewall. - # networking.firewall.allowedTCPPorts = [ ... ]; - # networking.firewall.allowedUDPPorts = [ ... ]; -} diff --git a/hosts/ronja-pc/imports.nix b/hosts/ronja-pc/imports.nix deleted file mode 100644 index 8b9ed4b..0000000 --- a/hosts/ronja-pc/imports.nix +++ /dev/null @@ -1,10 +0,0 @@ -{ - imports = [ - ../../modules/gnome.nix - ../../modules/gaming.nix - ../../modules/desktop-environment.nix - ../../modules/desktop-hardware.nix - - ../../home/ronja - ]; -} diff --git a/hosts/vinzenz-lpt2/hardware.nix b/hosts/vinzenz-lpt2/hardware.nix deleted file mode 100644 index f51ccd1..0000000 --- a/hosts/vinzenz-lpt2/hardware.nix +++ /dev/null @@ -1,63 +0,0 @@ -{ lib, ... }: -{ - imports = [ ../../modules/intel-graphics.nix ]; - config = { - # intel cpu - boot.kernelModules = [ - "kvm-intel" - "xe" - ]; - hardware.cpu.intel.updateMicrocode = true; - - boot.loader = { - systemd-boot.enable = true; - efi.canTouchEfiVariables = true; - }; - - # Enables DHCP on each ethernet and wireless interface. In case of scripted networking - # (the default) this is the recommended approach. When using systemd-networkd it's - # still possible to use this option, but it's recommended to use it in conjunction - # with explicit per-interface declarations with `networking.interfaces..useDHCP`. - networking.useDHCP = lib.mkDefault true; - - hardware.enableRedistributableFirmware = true; - - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; - - boot.initrd = { - availableKernelModules = [ - "xhci_pci" - "thunderbolt" - "nvme" - ]; - luks.devices = { - "luks-2c654ff2-3c42-48d3-a1e3-9545679afaa3" = { - device = "/dev/disk/by-uuid/2c654ff2-3c42-48d3-a1e3-9545679afaa3"; - }; - }; - }; - - fileSystems = { - "/" = { - device = "/dev/disk/by-uuid/e4dad0c8-26a1-45e9-bbd9-48565eb6574e"; - fsType = "btrfs"; - options = [ "subvol=@" ]; - }; - - "/boot" = { - device = "/dev/disk/by-uuid/E2B7-2BC1"; - fsType = "vfat"; - }; - }; - - swapDevices = [ - { - device = "/var/lib/swapfile"; - size = 32 * 1024; - } - ]; - - services.thermald.enable = true; - services.hardware.bolt.enable = true; # thunderbolt security - }; -} diff --git a/hosts/vinzenz-lpt2/imports.nix b/hosts/vinzenz-lpt2/imports.nix deleted file mode 100644 index f9a0ae1..0000000 --- a/hosts/vinzenz-lpt2/imports.nix +++ /dev/null @@ -1,14 +0,0 @@ -{ - imports = [ - ../../modules/gnome.nix - ../../modules/gaming.nix - ../../modules/printing.nix - ../../modules/podman.nix - #../../modules/niri.nix - ../../modules/desktop-environment.nix - ../../modules/desktop-hardware.nix - - ../../home/vinzenz - ../../home/ronja - ]; -} diff --git a/hosts/vinzenz-pc2/hardware.nix b/hosts/vinzenz-pc2/hardware.nix deleted file mode 100644 index 316d9a2..0000000 --- a/hosts/vinzenz-pc2/hardware.nix +++ /dev/null @@ -1,25 +0,0 @@ -{ ... }: -{ - imports = [ ../../modules/amd-graphics.nix ]; - config = { - # amd cpu - boot.kernelModules = [ "kvm-amd" ]; - hardware.cpu.amd.updateMicrocode = true; - - boot = { - initrd.availableKernelModules = [ - "nvme" - "xhci_pci" - "ahci" - "usbhid" - "sd_mod" - ]; # "usb_storage" - loader.efi.efiSysMountPoint = "/boot"; - }; - - fileSystems = import ./fstab.nix; - swapDevices = [ ]; - - networking.interfaces.eno1.wakeOnLan.enable = true; - }; -} diff --git a/hosts/vinzenz-pc2/imports.nix b/hosts/vinzenz-pc2/imports.nix deleted file mode 100644 index f9a0ae1..0000000 --- a/hosts/vinzenz-pc2/imports.nix +++ /dev/null @@ -1,14 +0,0 @@ -{ - imports = [ - ../../modules/gnome.nix - ../../modules/gaming.nix - ../../modules/printing.nix - ../../modules/podman.nix - #../../modules/niri.nix - ../../modules/desktop-environment.nix - ../../modules/desktop-hardware.nix - - ../../home/vinzenz - ../../home/ronja - ]; -} diff --git a/modules/amd-graphics.nix b/modules/amd-graphics.nix deleted file mode 100644 index 041d700..0000000 --- a/modules/amd-graphics.nix +++ /dev/null @@ -1,22 +0,0 @@ -{ pkgs, config, ... }: -{ - config = { - boot.kernelModules = [ "amdgpu" ]; - services.xserver.videoDrivers = [ "amdgpu" ]; - - hardware = { - graphics.enable = true; - amdgpu = { - opencl.enable = true; - amdvlk = { - # TODO: this creates black borders around GNOME apps - # enable = true; - # support32Bit.enable = config.hardware.graphics.enable32Bit; - }; - overdrive.enable = true; - }; - }; - - environment.systemPackages = with pkgs; [ nvtopPackages.amd ]; - }; -} diff --git a/modules/desktop-environment.nix b/modules/desktop-environment.nix deleted file mode 100644 index ffb00eb..0000000 --- a/modules/desktop-environment.nix +++ /dev/null @@ -1,121 +0,0 @@ -{ pkgs, ... }: -{ - config = { - services = { - xserver.enable = true; - libinput.enable = true; - flatpak.enable = true; - fstrim.enable = true; - earlyoom = { - enable = true; - freeMemThreshold = 5; - }; - }; - - # Enable sound with pipewire. - security.rtkit.enable = true; - services = { - pulseaudio.enable = false; - pipewire = { - enable = true; - alsa.enable = true; - alsa.support32Bit = true; - pulse.enable = true; - #jack.enable = true; - }; - }; - - programs = { - kdeconnect.enable = true; - firefox = { - enable = true; - languagePacks = [ - "en-US" - "de" - ]; - }; - nix-ld = { - enable = true; - libraries = with pkgs; [ - stdenv.cc.cc - zlib - zstd - curl - openssl - attr - libssh - bzip2 - libxml2 - acl - libsodium - util-linux - xz - systemd - ]; - }; - appimage = { - enable = true; - binfmt = true; - }; - }; - - networking = { - firewall = { - allowedTCPPortRanges = [ - { - # KDE Connect / gsconnect - from = 1714; - to = 1764; - } - ]; - allowedUDPPortRanges = [ - { - # KDE Connect / gsconnect - from = 1714; - to = 1764; - } - ]; - }; - }; - - systemd = { - # save some boot time because nothing actually requires network connectivity - services.NetworkManager-wait-online.enable = false; - - # prevent stuck units from preventing shutdown (default is 120s) - extraConfig = '' - DefaultTimeoutStopSec=10s - ''; - }; - - environment.systemPackages = with pkgs; [ - lm_sensors - - # office - libreoffice-qt - hunspell - hunspellDicts.de-de - hunspellDicts.en-us-large - ]; - - fonts = { - enableDefaultPackages = true; - fontconfig.defaultFonts.monospace = [ "FiraCode Nerd Font" ]; - packages = with pkgs; [ - nerd-fonts.fira-code - roboto-mono - recursive - ]; - }; - - hardware.logitech.wireless = { - enable = true; - enableGraphical = true; - }; - - system.autoUpgrade = { - allowReboot = false; - operation = "boot"; - }; - }; -} diff --git a/modules/desktop-hardware.nix b/modules/desktop-hardware.nix deleted file mode 100644 index a8b2f93..0000000 --- a/modules/desktop-hardware.nix +++ /dev/null @@ -1,48 +0,0 @@ -{ - lib, - pkgs, - ... -}: -{ - config = { - boot = { - kernelPackages = pkgs.linuxPackages_zen; - kernelParams = [ - "quiet" - "udev.log_level=3" - ]; - supportedFilesystems = [ "btrfs" ]; - initrd.supportedFilesystems = [ "btrfs" ]; - consoleLogLevel = 0; - initrd.verbose = false; - plymouth.enable = true; - loader = { - timeout = 3; - efi.canTouchEfiVariables = true; - systemd-boot = { - enable = true; - editor = false; # do not allow changing kernel parameters - consoleMode = "max"; - }; - }; - }; - - networking.networkmanager.enable = true; - # Enables DHCP on each ethernet and wireless interface. In case of scripted networking - # (the default) this is the recommended approach. When using systemd-networkd it's - # still possible to use this option, but it's recommended to use it in conjunction - # with explicit per-interface declarations with `networking.interfaces..useDHCP`. - networking.useDHCP = lib.mkDefault true; - # networking.interfaces.eno1.useDHCP = lib.mkDefault true; - # networking.interfaces.wlp5s0.useDHCP = lib.mkDefault true; - - hardware = { - enableRedistributableFirmware = true; - bluetooth.enable = true; - }; - - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; - - services.fwupd.enable = true; - }; -} diff --git a/modules/gaming.nix b/modules/gaming.nix deleted file mode 100644 index 4214c23..0000000 --- a/modules/gaming.nix +++ /dev/null @@ -1,81 +0,0 @@ -{ pkgs, ... }: -{ - config = { - hardware = { - graphics = { - enable32Bit = true; - extraPackages = with pkgs; [ mangohud ]; - extraPackages32 = with pkgs; [ mangohud ]; - }; - - steam-hardware.enable = true; - xpadneo.enable = true; - }; - - environment.systemPackages = with pkgs; [ - wineWowPackages.stagingFull - wineWowPackages.fonts - winetricks - dxvk - mangohud - vulkan-tools - glxinfo - lutris - ]; - - programs = { - xwayland.enable = true; - steam = { - enable = true; - remotePlay.openFirewall = true; - dedicatedServer.openFirewall = true; - localNetworkGameTransfers.openFirewall = true; - gamescopeSession.enable = false; - }; - gamemode.enable = true; - }; - - networking.firewall = { - allowedUDPPorts = [ - # Factorio - 34197 - - # steam network transfer - 3478 - ]; - - allowedTCPPorts = [ - # steam network transfer - 24070 - ]; - - allowedTCPPortRanges = [ - # steam network transfer - { - from = 27015; - to = 27050; - } - ]; - - allowedUDPPortRanges = [ - # steam network transfer - { - from = 4379; - to = 4380; - } - { - from = 27000; - to = 27100; - } - ]; - }; - - allowedUnfreePackages = [ - "steam" - "steam-original" - "steam-run" - "steam-unwrapped" - "ut1999" - ]; - }; -} diff --git a/modules/globalinstalls.nix b/modules/globalinstalls.nix deleted file mode 100644 index c4c21d2..0000000 --- a/modules/globalinstalls.nix +++ /dev/null @@ -1,34 +0,0 @@ -{ pkgs, ... }: -{ - config = { - environment = { - systemPackages = with pkgs; [ - ncdu - glances - iotop - - pciutils - lsof - dig - - screen - - tldr - neofetch - - nix-output-monitor - ]; - }; - - programs = { - zsh.enable = true; - htop.enable = true; - iotop.enable = true; - git.enable = true; - nano = { - enable = true; - syntaxHighlight = true; - }; - }; - }; -} diff --git a/modules/gnome-shared-dconf.nix b/modules/gnome-shared-dconf.nix deleted file mode 100644 index b9b3716..0000000 --- a/modules/gnome-shared-dconf.nix +++ /dev/null @@ -1,46 +0,0 @@ -{ - "org/gnome/desktop/interface" = { - color-scheme = "prefer-dark"; - clock-show-seconds = true; - show-battery-percentage = true; - }; - "org/gnome/mutter" = { - edge-tiling = true; - dynamic-workspaces = true; - }; - "org/gnome/desktop/peripherals/keyboard" = { - numlock-state = true; - }; - "org/gnome/desktop/peripherals/touchpad" = { - tap-to-click = true; - two-finger-scrolling-enabled = true; - }; - "org/gnome/tweaks" = { - show-extensions-notice = false; - }; - "org/gnome/shell" = { - disable-user-extensions = false; - disabled-extensions = [ ]; - enabled-extensions = [ - "tailscale@joaophi.github.com" - "appindicatorsupport@rgcjonas.gmail.com" - "workspace-indicator@gnome-shell-extensions.gcampax.github.com" - "caffeine@patapon.info" - ]; - }; - "ca/desrt/dconf-editor" = { - show-warning = false; - }; - "org/gnome/desktop/wm/keybindings" = { - switch-windows = [ "Tab" ]; - switch-windows-backward = [ "Tab" ]; - switch-applications = [ "Tab" ]; - switch-applications-backward = [ "Tab" ]; - }; - "org/gnome/shell/extensions/alphabetical-app-grid" = { - folder-order-position = "start"; - }; - "org/gnome/shell/extensions/gsconnect" = { - enabled = true; - }; -} diff --git a/modules/gnome.nix b/modules/gnome.nix deleted file mode 100644 index f5a5dc0..0000000 --- a/modules/gnome.nix +++ /dev/null @@ -1,101 +0,0 @@ -{ pkgs, ... }: -{ - config = { - services = { - xserver = { - # Enable the GNOME Desktop Environment. - desktopManager.gnome = { - enable = true; - extraGSettingsOverridePackages = [ pkgs.mutter ]; - extraGSettingsOverrides = '' - [org.gnome.mutter] - experimental-features=['scale-monitor-framebuffer'] - ''; - }; - displayManager.gdm.enable = true; - excludePackages = with pkgs; [ xterm ]; - }; - - displayManager.defaultSession = "gnome"; - - gnome = { - tinysparql.enable = false; - localsearch.enable = false; - sushi.enable = true; - gnome-remote-desktop.enable = true; - }; - }; - - programs = { - dconf.enable = true; - gpaste.enable = true; - kdeconnect.package = pkgs.gnomeExtensions.gsconnect; - }; - - # remove some gnome default apps - environment.gnome.excludePackages = with pkgs; [ - cheese # photo booth - epiphany # web browser - evince # document viewer - geary # email client - gnome-maps - gnome-weather - gnome-tour - sysprof - orca # screen reader - gnome-weather - gnome-backgrounds - gnome-user-docs - yelp # help app - # gnome-music - # totem # video player - # snapshot # camera - # baobab # disk usage - ]; - - # RDP connections - networking.firewall.allowedTCPPorts = [ 3389 ]; - - home-manager.sharedModules = [ - { - home.packages = - with pkgs; - [ - gitg - meld - simple-scan - pinta - dconf-editor - gpaste - ghex - impression - papers - - # graphical installer for flatpak apps - gnome-software - ] - ++ (with gnomeExtensions; [ - caffeine - appindicator - ]); - - dconf.settings = import ./gnome-shared-dconf.nix; - - gtk = { - enable = true; - iconTheme.name = "Adwaita"; - cursorTheme.name = "Adwaita"; - theme = { - name = "adw-gtk3-dark"; - package = pkgs.adw-gtk3; - }; - }; - } - - { - home.packages = with pkgs; [ trayscale ] ++ (with gnomeExtensions; [ tailscale-qs ]); - dconf.settings."org/gnome/shell".enabled-extensions = [ "tailscale@joaophi.github.com" ]; - } - ]; - }; -} diff --git a/modules/home-manager.nix b/modules/home-manager.nix deleted file mode 100644 index 9af6a19..0000000 --- a/modules/home-manager.nix +++ /dev/null @@ -1,61 +0,0 @@ -_: { - home-manager = { - useGlobalPkgs = true; - useUserPackages = true; - sharedModules = [ - # set stateVersion - { home.stateVersion = "22.11"; } - # make nano the default editor - { - home = { - sessionVariables.EDITOR = "nano"; - file.".nanorc".text = '' - set linenumbers - set mouse - ''; - }; - } - # command line niceness - { - programs = { - command-not-found.enable = true; - dircolors.enable = true; - - zsh = { - enable = true; - syntaxHighlighting.enable = true; - autosuggestion.enable = true; - enableVteIntegration = true; - }; - }; - } - # common git config - { - programs = { - git = { - enable = true; - extraConfig.init.defaultBranch = "main"; - }; - - gh = { - enable = true; - gitCredentialHelper.enable = true; - }; - }; - } - # Templates - { - home.file = { - "Templates/Empty file".text = ""; - "Templates/Empty bash script".text = '' - #!/usr/bin/env bash - # abort on error, undefined variables - set -eu - # print commands before execution - set -x - ''; - }; - } - ]; - }; -} diff --git a/modules/i18n.nix b/modules/i18n.nix deleted file mode 100644 index 3d789f0..0000000 --- a/modules/i18n.nix +++ /dev/null @@ -1,19 +0,0 @@ -_: { - config = { - time.timeZone = "Europe/Berlin"; - i18n = { - defaultLocale = "en_US.UTF-8"; - extraLocaleSettings = { - LC_ADDRESS = "de_DE.UTF-8"; - LC_IDENTIFICATION = "de_DE.UTF-8"; - LC_MEASUREMENT = "de_DE.UTF-8"; - LC_MONETARY = "de_DE.UTF-8"; - LC_NAME = "de_DE.UTF-8"; - LC_NUMERIC = "de_DE.UTF-8"; - LC_PAPER = "de_DE.UTF-8"; - LC_TELEPHONE = "de_DE.UTF-8"; - LC_TIME = "de_DE.UTF-8"; - }; - }; - }; -} diff --git a/modules/lix.nix b/modules/lix.nix deleted file mode 100644 index 55a3265..0000000 --- a/modules/lix.nix +++ /dev/null @@ -1,12 +0,0 @@ -{ pkgs, ... }: -{ - nixpkgs.overlays = [ (final: prev: { - inherit (prev.lixPackageSets.stable) - nixpkgs-review - nix-eval-jobs - nix-fast-build - colmena; - }) ]; - - nix.package = pkgs.lixPackageSets.stable.lix; -} diff --git a/modules/networking.nix b/modules/networking.nix deleted file mode 100644 index a6a8d03..0000000 --- a/modules/networking.nix +++ /dev/null @@ -1,23 +0,0 @@ -_: { - config = { - services.openssh = { - enable = true; - openFirewall = true; - settings = { - PermitRootLogin = "without-password"; - PasswordAuthentication = false; - KbdInteractiveAuthentication = false; - }; - }; - - services.tailscale = { - enable = true; - openFirewall = true; - }; - - networking.firewall = { - enable = true; - checkReversePath = "loose"; - }; - }; -} diff --git a/modules/nixpkgs.nix b/modules/nixpkgs.nix deleted file mode 100644 index aba3504..0000000 --- a/modules/nixpkgs.nix +++ /dev/null @@ -1,59 +0,0 @@ -{ config, lib, ... }: -{ - options.allowedUnfreePackages = lib.mkOption { - type = lib.types.listOf lib.types.str; - default = [ ]; - example = [ "steam" ]; - }; - config = { - nixpkgs.config = { - # https://github.com/NixOS/nixpkgs/issues/197325#issuecomment-1579420085 - allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) config.allowedUnfreePackages; - }; - - nix = { - settings = { - substituters = [ - "https://cache.nixos.org/" - "https://nix-community.cachix.org" - "https://cache.lix.systems" - "https://niri.cachix.org" - ]; - trusted-public-keys = [ - "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" - "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" - "cache.lix.systems:aBnZUw8zA7H35Cz2RyKFVs3H4PlGTLawyY5KRbvJR8o=" - "niri.cachix.org-1:Wv0OmO7PsuocRKzfDoJ3mulSl7Z6oezYhGhR+3W2964=" - ]; - experimental-features = [ - "nix-command" - "flakes" - ]; - }; - gc = { - automatic = true; - dates = "daily"; - options = "--delete-older-than 7d"; - }; - optimise.automatic = true; - }; - - system = { - stateVersion = "22.11"; - # enable auto updates - autoUpgrade = { - enable = true; - dates = "daily"; - flake = "git+https://git.berlin.ccc.de/vinzenz/nixos-configuration.git"; - }; - }; - - documentation = { - enable = true; # documentation of packages - nixos.enable = false; # nixos documentation - man.enable = true; # manual pages and the man command - info.enable = false; # info pages and the info command - doc.enable = false; # documentation distributed in packages' /share/doc - }; - }; -} diff --git a/modules/printing.nix b/modules/printing.nix deleted file mode 100644 index 4b74421..0000000 --- a/modules/printing.nix +++ /dev/null @@ -1,14 +0,0 @@ -_: { - config = { - services = { - # Enable CUPS to print documents. - printing.enable = true; - - avahi = { - enable = true; # runs the Avahi daemon - nssmdns4 = true; # enables the mDNS NSS plug-in - openFirewall = true; # opens the firewall for UDP port 5353 - }; - }; - }; -} diff --git a/nixosConfigurations/forgejo-runner-1/default.nix b/nixosConfigurations/forgejo-runner-1/default.nix new file mode 100644 index 0000000..f9d3c3f --- /dev/null +++ b/nixosConfigurations/forgejo-runner-1/default.nix @@ -0,0 +1,21 @@ +{ + imports = [ + ./hardware.nix + ./forgejo-runner.nix + ]; + + config = { + # uncomment for build check on non arm system (requires --impure) + # nixpkgs.buildPlatform = builtins.currentSystem; + services.tailscale.useRoutingFeatures = "both"; + system.autoUpgrade.allowReboot = true; + + users.users = { + root.openssh.authorizedKeys.keys = [ + ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFCJUpbpB3KEKVoKWsKoar9J4RNah8gmQoSH6jQEw5dY vinzenz-pixel-JuiceSSH'' + ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO1CRn4yYTL4XUdCebE8Z4ZeuMujBjorTdWifg911EOv vinzenz-pc2 home roaming'' + ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDNpLDmctyqGpow/ElQvdhY4BLBPS/sigDJ1QEcC7wC vinzenz-lpt2-roaming'' + ]; + }; + }; +} diff --git a/hosts/forgejo-runner-1/forgejo-runner.nix b/nixosConfigurations/forgejo-runner-1/forgejo-runner.nix similarity index 100% rename from hosts/forgejo-runner-1/forgejo-runner.nix rename to nixosConfigurations/forgejo-runner-1/forgejo-runner.nix diff --git a/hosts/forgejo-runner-1/hardware.nix b/nixosConfigurations/forgejo-runner-1/hardware.nix similarity index 93% rename from hosts/forgejo-runner-1/hardware.nix rename to nixosConfigurations/forgejo-runner-1/hardware.nix index e3e6880..e8fbc56 100644 --- a/hosts/forgejo-runner-1/hardware.nix +++ b/nixosConfigurations/forgejo-runner-1/hardware.nix @@ -3,11 +3,6 @@ imports = [ (modulesPath + "/profiles/qemu-guest.nix") ]; config = { - nixpkgs = { - hostPlatform = "aarch64-linux"; - system = "aarch64-linux"; - }; - boot = { tmp.cleanOnBoot = true; kernelParams = [ "console=tty" ]; diff --git a/nixosConfigurations/hetzner-vpn2/default.nix b/nixosConfigurations/hetzner-vpn2/default.nix new file mode 100644 index 0000000..591dc20 --- /dev/null +++ b/nixosConfigurations/hetzner-vpn2/default.nix @@ -0,0 +1,27 @@ +{ + imports = [ + ./hardware.nix + ./nginx.nix + ]; + + config = { + # uncomment for build check on non arm system (requires --impure) + # nixpkgs.buildPlatform = builtins.currentSystem; + + services.tailscale.useRoutingFeatures = "both"; + + users.users = { + root.openssh.authorizedKeys.keys = [ + ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICdYqY3Y1/f1bsAi5Qfyr/UWuX9ixu96IeAlhoQaJkbf'' + ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFCJUpbpB3KEKVoKWsKoar9J4RNah8gmQoSH6jQEw5dY vinzenz-pixel-JuiceSSH'' + ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO1CRn4yYTL4XUdCebE8Z4ZeuMujBjorTdWifg911EOv vinzenz-pc2 home roaming'' + ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDNpLDmctyqGpow/ElQvdhY4BLBPS/sigDJ1QEcC7wC vinzenz-lpt2-roaming'' + ]; + #ronja.openssh.authorizedKeys.keys = [ + # ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIALWKm+d6KL6Vl3grPOcGouiNTkvdhXuWJmcrdEBY2nw ronja-ssh-host-key'' + #]; + }; + + system.autoUpgrade.allowReboot = true; + }; +} diff --git a/hosts/hetzner-vpn2/hardware.nix b/nixosConfigurations/hetzner-vpn2/hardware.nix similarity index 93% rename from hosts/hetzner-vpn2/hardware.nix rename to nixosConfigurations/hetzner-vpn2/hardware.nix index e8fa931..d7c96f0 100644 --- a/hosts/hetzner-vpn2/hardware.nix +++ b/nixosConfigurations/hetzner-vpn2/hardware.nix @@ -3,11 +3,6 @@ imports = [ (modulesPath + "/profiles/qemu-guest.nix") ]; config = { - nixpkgs = { - hostPlatform = "aarch64-linux"; - system = "aarch64-linux"; - }; - boot = { tmp.cleanOnBoot = true; kernelParams = [ "console=tty" ]; diff --git a/hosts/hetzner-vpn2/nginx.nix b/nixosConfigurations/hetzner-vpn2/nginx.nix similarity index 84% rename from hosts/hetzner-vpn2/nginx.nix rename to nixosConfigurations/hetzner-vpn2/nginx.nix index 8fa27c6..2520533 100644 --- a/hosts/hetzner-vpn2/nginx.nix +++ b/nixosConfigurations/hetzner-vpn2/nginx.nix @@ -1,4 +1,4 @@ -{ inputs, pkgs, ... }: +{ pkgs, ... }: let blog-domain-socket = "/run/nginx/blog.sock"; anubis-domain-socket = "/run/anubis/anubis-blog.sock"; @@ -72,28 +72,26 @@ in addSSL = true; enableACME = true; locations."/" = { - proxyPass = ("http://unix:" + anubis-domain-socket); + proxyPass = "http://unix:" + anubis-domain-socket; }; }; "blog-in-anubis" = { - root = inputs.zerforschen-plus.packages."${pkgs.system}".zerforschen-plus-content; + root = pkgs.zerforschen-plus-content; listen = [ { - addr = ("unix:" + blog-domain-socket); + addr = "unix:" + blog-domain-socket; } ]; }; }; }; - anubis = { - instances.main = { - enable = true; - settings = { - BIND = anubis-domain-socket; - TARGET = "unix://" + blog-domain-socket; - }; + anubis.instances.main = { + enable = true; + settings = { + BIND = anubis-domain-socket; + TARGET = "unix://" + blog-domain-socket; }; }; }; diff --git a/nixosConfigurations/ronja-pc/default.nix b/nixosConfigurations/ronja-pc/default.nix new file mode 100644 index 0000000..dd22382 --- /dev/null +++ b/nixosConfigurations/ronja-pc/default.nix @@ -0,0 +1,32 @@ +{ + config, + pkgs, + ... +}: +{ + imports = [ + ./hardware.nix + ]; + + config = { + # Configure keymap in X11 + services.xserver.xkb = { + layout = "de"; + variant = ""; + }; + + # Configure console keymap + console.keyMap = "de"; + + # List packages installed in system profile. To search, run: + # $ nix search wget + environment.systemPackages = with pkgs; [ + # vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default. + # wget + ]; + + # Open ports in the firewall. + # networking.firewall.allowedTCPPorts = [ ... ]; + # networking.firewall.allowedUDPPorts = [ ... ];}; + }; +} diff --git a/hosts/ronja-pc/hardware.nix b/nixosConfigurations/ronja-pc/hardware.nix similarity index 77% rename from hosts/ronja-pc/hardware.nix rename to nixosConfigurations/ronja-pc/hardware.nix index f668726..e6ad854 100644 --- a/hosts/ronja-pc/hardware.nix +++ b/nixosConfigurations/ronja-pc/hardware.nix @@ -1,6 +1,8 @@ { lib, ... }: { boot = { + supportedFilesystems = [ "btrfs" ]; + initrd.supportedFilesystems = [ "btrfs" ]; kernelModules = [ "kvm-intel" ]; extraModulePackages = [ ]; initrd = { @@ -37,6 +39,10 @@ { device = "/dev/disk/by-uuid/bf9d19fb-499b-4bfb-b67d-131fa5bf8259"; } ]; - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; - hardware.cpu.intel.updateMicrocode = true; + hardware.bluetooth.enable = true; + + networking = { + networkmanager.enable = true; + useDHCP = lib.mkDefault true; + }; } diff --git a/hosts/vinzenz-lpt2/configuration.nix b/nixosConfigurations/vinzenz-lpt2/default.nix similarity index 94% rename from hosts/vinzenz-lpt2/configuration.nix rename to nixosConfigurations/vinzenz-lpt2/default.nix index b38f25a..58eac82 100644 --- a/hosts/vinzenz-lpt2/configuration.nix +++ b/nixosConfigurations/vinzenz-lpt2/default.nix @@ -1,6 +1,8 @@ -{ ... }: { - imports = [ ./nginx.nix ]; + imports = [ + ./hardware.nix + ./nginx.nix + ]; config = { nix.settings.extra-platforms = [ diff --git a/nixosConfigurations/vinzenz-lpt2/hardware.nix b/nixosConfigurations/vinzenz-lpt2/hardware.nix new file mode 100644 index 0000000..175a168 --- /dev/null +++ b/nixosConfigurations/vinzenz-lpt2/hardware.nix @@ -0,0 +1,56 @@ +{ pkgs, lib, ... }: +{ + # intel cpu + boot.kernelModules = [ + "kvm-intel" + "xe" + ]; + + networking = { + networkmanager.enable = true; + useDHCP = lib.mkDefault true; + }; + + boot = { + kernelPackages = pkgs.linuxPackages_zen; + supportedFilesystems = [ "btrfs" ]; + initrd = { + supportedFilesystems = [ "btrfs" ]; + availableKernelModules = [ + "xhci_pci" + "thunderbolt" + "nvme" + ]; + luks.devices = { + "luks-2c654ff2-3c42-48d3-a1e3-9545679afaa3" = { + device = "/dev/disk/by-uuid/2c654ff2-3c42-48d3-a1e3-9545679afaa3"; + }; + }; + }; + }; + + fileSystems = { + "/" = { + device = "/dev/disk/by-uuid/e4dad0c8-26a1-45e9-bbd9-48565eb6574e"; + fsType = "btrfs"; + options = [ "subvol=@" ]; + }; + + "/boot" = { + device = "/dev/disk/by-uuid/E2B7-2BC1"; + fsType = "vfat"; + }; + }; + + swapDevices = [ + { + device = "/var/lib/swapfile"; + size = 32 * 1024; + } + ]; + + services.thermald.enable = true; + services.hardware.bolt.enable = true; # thunderbolt security + + hardware.bluetooth.enable = true; +} diff --git a/hosts/vinzenz-lpt2/nginx.nix b/nixosConfigurations/vinzenz-lpt2/nginx.nix similarity index 83% rename from hosts/vinzenz-lpt2/nginx.nix rename to nixosConfigurations/vinzenz-lpt2/nginx.nix index 302a271..d5fd6a4 100644 --- a/hosts/vinzenz-lpt2/nginx.nix +++ b/nixosConfigurations/vinzenz-lpt2/nginx.nix @@ -1,4 +1,4 @@ -{ inputs, pkgs, ... }: +{ pkgs, ... }: let blog-domain-socket = "/run/nginx/blog.sock"; anubis-domain-socket = "/run/anubis/anubis-blog.sock"; @@ -29,15 +29,15 @@ in "vinzenz-lpt2" = { locations."/" = { - proxyPass = ("http://unix:" + anubis-domain-socket); + proxyPass = "http://unix:" + anubis-domain-socket; }; }; "vinzenz-lpt2-in-anubis" = { - root = inputs.zerforschen-plus.packages."${pkgs.system}".zerforschen-plus-content; + root = pkgs.zerforschen-plus-content; listen = [ { - addr = ("unix:" + blog-domain-socket); + addr = "unix:" + blog-domain-socket; } ]; }; diff --git a/hosts/vinzenz-lpt2/zerforschen-plus.nix b/nixosConfigurations/vinzenz-lpt2/zerforschen-plus.nix similarity index 86% rename from hosts/vinzenz-lpt2/zerforschen-plus.nix rename to nixosConfigurations/vinzenz-lpt2/zerforschen-plus.nix index af3ea3c..d2b919d 100644 --- a/hosts/vinzenz-lpt2/zerforschen-plus.nix +++ b/nixosConfigurations/vinzenz-lpt2/zerforschen-plus.nix @@ -1,7 +1,5 @@ { pkgs, - system, - inputs, ... }: { @@ -28,7 +26,7 @@ "zerforschen.plus" = { #addSSL = true; #enableACME = true; - root = inputs.zerforschen-plus.packages."${pkgs.system}".zerforschen-plus-content; + root = pkgs.zerforschen-plus-content; }; }; }; diff --git a/hosts/vinzenz-pc2/configuration.nix b/nixosConfigurations/vinzenz-pc2/default.nix similarity index 93% rename from hosts/vinzenz-pc2/configuration.nix rename to nixosConfigurations/vinzenz-pc2/default.nix index 4f6b859..23505b1 100644 --- a/hosts/vinzenz-pc2/configuration.nix +++ b/nixosConfigurations/vinzenz-pc2/default.nix @@ -5,6 +5,7 @@ ./vscode-server.nix ./hass.nix ]; + config = { nix.settings.extra-platforms = [ "aarch64-linux" @@ -32,5 +33,10 @@ ]; environment.systemPackages = with pkgs; [ lact ]; + + networking.firewall.allowedUDPPorts = [ + # Factorio + 34197 + ]; }; } diff --git a/hosts/vinzenz-pc2/fstab.nix b/nixosConfigurations/vinzenz-pc2/fstab.nix similarity index 100% rename from hosts/vinzenz-pc2/fstab.nix rename to nixosConfigurations/vinzenz-pc2/fstab.nix diff --git a/nixosConfigurations/vinzenz-pc2/hardware.nix b/nixosConfigurations/vinzenz-pc2/hardware.nix new file mode 100644 index 0000000..9e875c3 --- /dev/null +++ b/nixosConfigurations/vinzenz-pc2/hardware.nix @@ -0,0 +1,30 @@ +{ pkgs, lib, ... }: +{ + # amd cpu + boot.kernelModules = [ "kvm-amd" ]; + + boot = { + initrd.availableKernelModules = [ + "nvme" + "xhci_pci" + "ahci" + "usbhid" + "sd_mod" + ]; # "usb_storage" + kernelPackages = pkgs.linuxPackages_zen; + supportedFilesystems = [ "btrfs" ]; + initrd.supportedFilesystems = [ "btrfs" ]; + loader.efi.efiSysMountPoint = "/boot"; + }; + + fileSystems = import ./fstab.nix; + swapDevices = [ ]; + + networking = { + networkmanager.enable = true; + useDHCP = lib.mkDefault true; + interfaces.eno1.wakeOnLan.enable = true; + }; + + hardware.bluetooth.enable = true; +} diff --git a/hosts/vinzenz-pc2/hass.nix b/nixosConfigurations/vinzenz-pc2/hass.nix similarity index 100% rename from hosts/vinzenz-pc2/hass.nix rename to nixosConfigurations/vinzenz-pc2/hass.nix diff --git a/hosts/vinzenz-pc2/vscode-server.nix b/nixosConfigurations/vinzenz-pc2/vscode-server.nix similarity index 66% rename from hosts/vinzenz-pc2/vscode-server.nix rename to nixosConfigurations/vinzenz-pc2/vscode-server.nix index 199c015..6632b1f 100644 --- a/hosts/vinzenz-pc2/vscode-server.nix +++ b/nixosConfigurations/vinzenz-pc2/vscode-server.nix @@ -15,16 +15,12 @@ ]; }; - networking = { - firewall = { - allowedTCPPorts = [ - 8542 - 8543 - 8544 - 80 - 1313 - 5201 - ]; - }; - }; + networking.firewall.allowedTCPPorts = [ + 8542 + 8543 + 8544 + 80 + 1313 + 5201 + ]; } diff --git a/nixosModules/allowed-unfree-list.nix b/nixosModules/allowed-unfree-list.nix new file mode 100644 index 0000000..7bfa758 --- /dev/null +++ b/nixosModules/allowed-unfree-list.nix @@ -0,0 +1,17 @@ +{ lib, config, ... }: +{ + options.allowedUnfreePackages = lib.mkOption { + type = lib.types.listOf lib.types.str; + default = [ ]; + example = [ "steam" ]; + }; + + config = { + nixpkgs.config = { + # https://github.com/NixOS/nixpkgs/issues/197325#issuecomment-1579420085 + allowUnfreePredicate = lib.mkDefault ( + pkg: builtins.elem (lib.getName pkg) config.allowedUnfreePackages + ); + }; + }; +} diff --git a/nixosModules/amd-graphics.nix b/nixosModules/amd-graphics.nix new file mode 100644 index 0000000..cca6393 --- /dev/null +++ b/nixosModules/amd-graphics.nix @@ -0,0 +1,20 @@ +{ pkgs, ... }: +{ + boot.kernelModules = [ "amdgpu" ]; + services.xserver.videoDrivers = [ "amdgpu" ]; + + hardware = { + graphics.enable = true; + amdgpu = { + opencl.enable = true; + amdvlk = { + # TODO: this creates black borders around GNOME apps + # enable = true; + # support32Bit.enable = config.hardware.graphics.enable32Bit; + }; + overdrive.enable = true; + }; + }; + + environment.systemPackages = with pkgs; [ nvtopPackages.amd ]; +} diff --git a/nixosModules/autoupdate.nix b/nixosModules/autoupdate.nix new file mode 100644 index 0000000..0f26b7e --- /dev/null +++ b/nixosModules/autoupdate.nix @@ -0,0 +1,16 @@ +{ + nix = { + optimise.automatic = true; + gc = { + automatic = true; + dates = "daily"; + options = "--delete-older-than 7d"; + }; + }; + + system.autoUpgrade = { + enable = true; + dates = "daily"; + # do not forget to set `flake` when using this module! + }; +} diff --git a/nixosModules/en-de.nix b/nixosModules/en-de.nix new file mode 100644 index 0000000..a91780e --- /dev/null +++ b/nixosModules/en-de.nix @@ -0,0 +1,31 @@ +{ pkgs, ... }: +{ + i18n = { + defaultLocale = "en_US.UTF-8"; + extraLocales = [ + "de_DE.UTF-8/UTF-8" + ]; + extraLocaleSettings = { + LC_ADDRESS = "de_DE.UTF-8"; + LC_IDENTIFICATION = "de_DE.UTF-8"; + LC_MEASUREMENT = "de_DE.UTF-8"; + LC_MONETARY = "de_DE.UTF-8"; + LC_NAME = "de_DE.UTF-8"; + LC_NUMERIC = "de_DE.UTF-8"; + LC_PAPER = "de_DE.UTF-8"; + LC_TELEPHONE = "de_DE.UTF-8"; + LC_TIME = "de_DE.UTF-8"; + }; + }; + + programs.firefox.languagePacks = [ + "en-US" + "de" + ]; + + environment.systemPackages = [ + pkgs.hunspell + pkgs.hunspellDicts.de-de + pkgs.hunspellDicts.en-us + ]; +} diff --git a/nixosModules/extra-caches.nix b/nixosModules/extra-caches.nix new file mode 100644 index 0000000..6af372f --- /dev/null +++ b/nixosModules/extra-caches.nix @@ -0,0 +1,16 @@ +{ + nix.settings = { + substituters = [ + "https://cache.nixos.org/" + "https://nix-community.cachix.org" + "https://cache.lix.systems" + "https://niri.cachix.org" + ]; + trusted-public-keys = [ + "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" + "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" + "cache.lix.systems:aBnZUw8zA7H35Cz2RyKFVs3H4PlGTLawyY5KRbvJR8o=" + "niri.cachix.org-1:Wv0OmO7PsuocRKzfDoJ3mulSl7Z6oezYhGhR+3W2964=" + ]; + }; +} diff --git a/nixosModules/firmware-updates.nix b/nixosModules/firmware-updates.nix new file mode 100644 index 0000000..8e81b72 --- /dev/null +++ b/nixosModules/firmware-updates.nix @@ -0,0 +1,11 @@ +{ + hardware = { + enableRedistributableFirmware = true; + cpu = { + amd.updateMicrocode = true; + intel.updateMicrocode = true; + }; + }; + + services.fwupd.enable = true; +} diff --git a/nixosModules/globalinstalls.nix b/nixosModules/globalinstalls.nix new file mode 100644 index 0000000..47fb343 --- /dev/null +++ b/nixosModules/globalinstalls.nix @@ -0,0 +1,23 @@ +{ pkgs, ... }: +{ + environment.systemPackages = with pkgs; [ + ncdu + glances + lsof + dig + screen + tldr + nix-output-monitor + ]; + + programs = { + zsh.enable = true; + htop.enable = true; + iotop.enable = true; + git.enable = true; + nano = { + enable = true; + syntaxHighlight = true; + }; + }; +} diff --git a/nixosModules/gnome.nix b/nixosModules/gnome.nix new file mode 100644 index 0000000..7a6f920 --- /dev/null +++ b/nixosModules/gnome.nix @@ -0,0 +1,65 @@ +{ + pkgs, + lib, + config, + ... +}: +{ + options.vinzenz = { + keep-gnome-default-apps = lib.mkEnableOption "keep gnome default apps"; + }; + + config = lib.mkMerge [ + { + services = { + xserver = { + # Enable the GNOME Desktop Environment. + desktopManager.gnome = { + enable = true; + extraGSettingsOverridePackages = [ pkgs.mutter ]; + extraGSettingsOverrides = '' + [org.gnome.mutter] + experimental-features=['scale-monitor-framebuffer'] + ''; + }; + displayManager.gdm.enable = true; + excludePackages = [ pkgs.xterm ]; + }; + + displayManager.defaultSession = "gnome"; + + gnome = { + tinysparql.enable = false; + localsearch.enable = false; + sushi.enable = true; + }; + }; + + programs = { + dconf.enable = true; + gpaste.enable = true; + }; + } + (lib.mkIf (!config.vinzenz.keep-gnome-default-apps) { + environment.gnome.excludePackages = with pkgs; [ + cheese # photo booth + epiphany # web browser + evince # document viewer + geary # email client + gnome-maps + gnome-weather + gnome-tour + sysprof + orca # screen reader + gnome-weather + gnome-backgrounds + gnome-user-docs + yelp # help app + gnome-music + totem # video player + snapshot # camera + baobab # disk usage + ]; + }) + ]; +} diff --git a/modules/intel-graphics.nix b/nixosModules/intel-graphics.nix similarity index 100% rename from modules/intel-graphics.nix rename to nixosModules/intel-graphics.nix diff --git a/nixosModules/kdeconnect.nix b/nixosModules/kdeconnect.nix new file mode 100644 index 0000000..16b669f --- /dev/null +++ b/nixosModules/kdeconnect.nix @@ -0,0 +1,53 @@ +{ + lib, + config, + pkgs, + ... +}: +{ + config = lib.mkMerge [ + { + networking.firewall = + let + kdeconnect-range = { + from = 1714; + to = 1764; + }; + in + { + allowedTCPPortRanges = [ kdeconnect-range ]; + allowedUDPPortRanges = [ kdeconnect-range ]; + }; + + programs.kdeconnect.enable = true; + home-manager.sharedModules = [ + { + services.kdeconnect = { + enable = true; + # this still shows up in gnome session starting with 25.05 + # indicator = true; + }; + } + ]; + } + + (lib.mkIf config.services.xserver.desktopManager.gnome.enable { + # replace kdeconnect with gsconnect + programs.kdeconnect.package = pkgs.gnomeExtensions.gsconnect; + + home-manager.sharedModules = [ + ( + { pkgs, ... }: + { + home.packages = [ pkgs.gnomeExtensions.gsconnect ]; + # enable gsconnect extension + dconf.settings = { + "org/gnome/shell".enabled-extensions = [ "gsconnect@andyholmes.github.io" ]; + "org/gnome/shell/extensions/gsconnect".enabled = true; + }; + } + ) + ]; + }) + ]; +} diff --git a/modules/latex.nix b/nixosModules/latex.nix similarity index 100% rename from modules/latex.nix rename to nixosModules/latex.nix diff --git a/nixosModules/lix-is-nix.nix b/nixosModules/lix-is-nix.nix new file mode 100644 index 0000000..3480d06 --- /dev/null +++ b/nixosModules/lix-is-nix.nix @@ -0,0 +1,15 @@ +{ pkgs, ... }: +{ + nixpkgs.overlays = [ + (final: prev: { + inherit (prev.lixPackageSets.stable) + nixpkgs-review + nix-eval-jobs + nix-fast-build + colmena + ; + }) + ]; + + nix.package = pkgs.lixPackageSets.latest.lix; +} diff --git a/nixosModules/modern-desktop.nix b/nixosModules/modern-desktop.nix new file mode 100644 index 0000000..f1879bd --- /dev/null +++ b/nixosModules/modern-desktop.nix @@ -0,0 +1,49 @@ +{ + services = { + xserver.enable = true; + libinput.enable = true; + flatpak.enable = true; + fstrim.enable = true; + earlyoom = { + enable = true; + freeMemThreshold = 5; + }; + }; + + # Enable sound with pipewire. + security.rtkit.enable = true; + services = { + pulseaudio.enable = false; + pipewire = { + enable = true; + alsa.enable = true; + alsa.support32Bit = true; + pulse.enable = true; + #jack.enable = true; + }; + }; + + systemd = { + # save some boot time because nothing actually requires network connectivity + services.NetworkManager-wait-online.enable = false; + + # prevent stuck units from preventing shutdown (default is 120s) + extraConfig = '' + DefaultTimeoutStopSec=10s + ''; + }; + + programs = { + xwayland.enable = true; + + appimage = { + enable = true; + binfmt = true; + }; + }; + + system.autoUpgrade = { + allowReboot = false; + operation = "boot"; + }; +} diff --git a/modules/niri.nix b/nixosModules/niri.nix similarity index 100% rename from modules/niri.nix rename to nixosModules/niri.nix diff --git a/nixosModules/nix-ld.nix b/nixosModules/nix-ld.nix new file mode 100644 index 0000000..382aa3d --- /dev/null +++ b/nixosModules/nix-ld.nix @@ -0,0 +1,22 @@ +{ pkgs, ... }: +{ + programs.nix-ld = { + enable = true; + libraries = with pkgs; [ + stdenv.cc.cc + zlib + zstd + curl + openssl + attr + libssh + bzip2 + libxml2 + acl + libsodium + util-linux + xz + systemd + ]; + }; +} diff --git a/nixosModules/openssh.nix b/nixosModules/openssh.nix new file mode 100644 index 0000000..ed24fe2 --- /dev/null +++ b/nixosModules/openssh.nix @@ -0,0 +1,11 @@ +{ + services.openssh = { + enable = true; + openFirewall = true; + settings = { + PermitRootLogin = "without-password"; + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + }; + }; +} diff --git a/modules/podman.nix b/nixosModules/podman.nix similarity index 97% rename from modules/podman.nix rename to nixosModules/podman.nix index abecea4..93540f8 100644 --- a/modules/podman.nix +++ b/nixosModules/podman.nix @@ -1,4 +1,4 @@ -_: { +{ virtualisation = { containers.enable = true; podman = { diff --git a/nixosModules/printing.nix b/nixosModules/printing.nix new file mode 100644 index 0000000..c85edd7 --- /dev/null +++ b/nixosModules/printing.nix @@ -0,0 +1,12 @@ +{ + services = { + # Enable CUPS to print documents. + printing.enable = true; + + avahi = { + enable = true; # runs the Avahi daemon + nssmdns4 = true; # enables the mDNS NSS plug-in + openFirewall = true; # opens the firewall for UDP port 5353 + }; + }; +} diff --git a/nixosModules/quiet-boot.nix b/nixosModules/quiet-boot.nix new file mode 100644 index 0000000..8dbcd57 --- /dev/null +++ b/nixosModules/quiet-boot.nix @@ -0,0 +1,11 @@ +{ + boot = { + kernelParams = [ + "quiet" + "udev.log_level=3" + ]; + consoleLogLevel = 0; + initrd.verbose = false; + plymouth.enable = true; + }; +} diff --git a/nixosModules/steam.nix b/nixosModules/steam.nix new file mode 100644 index 0000000..b0991e6 --- /dev/null +++ b/nixosModules/steam.nix @@ -0,0 +1,45 @@ +{ + hardware.steam-hardware.enable = true; + + programs = { + steam = { + enable = true; + remotePlay.openFirewall = true; + dedicatedServer.openFirewall = true; + localNetworkGameTransfers.openFirewall = true; + gamescopeSession.enable = false; + }; + gamemode.enable = true; + }; + + # steam network transfer + networking.firewall = { + allowedUDPPorts = [ 3478 ]; + allowedTCPPorts = [ 24070 ]; + + allowedTCPPortRanges = [ + { + from = 27015; + to = 27050; + } + ]; + + allowedUDPPortRanges = [ + { + from = 4379; + to = 4380; + } + { + from = 27000; + to = 27100; + } + ]; + }; + + allowedUnfreePackages = [ + "steam" + "steam-original" + "steam-run" + "steam-unwrapped" + ]; +} diff --git a/nixosModules/systemd-boot.nix b/nixosModules/systemd-boot.nix new file mode 100644 index 0000000..321a26c --- /dev/null +++ b/nixosModules/systemd-boot.nix @@ -0,0 +1,11 @@ +{ + boot.loader = { + timeout = 3; + efi.canTouchEfiVariables = true; + systemd-boot = { + enable = true; + editor = false; # do not allow changing kernel parameters + consoleMode = "max"; + }; + }; +} diff --git a/nixosModules/tailscale.nix b/nixosModules/tailscale.nix new file mode 100644 index 0000000..e51ee7f --- /dev/null +++ b/nixosModules/tailscale.nix @@ -0,0 +1,8 @@ +{ + services.tailscale = { + enable = true; + openFirewall = true; + }; + + networking.firewall.checkReversePath = "loose"; +} diff --git a/nixosModules/user-ronja.nix b/nixosModules/user-ronja.nix new file mode 100644 index 0000000..b374ab9 --- /dev/null +++ b/nixosModules/user-ronja.nix @@ -0,0 +1,19 @@ +{ pkgs, ... }: +{ + users.users.ronja = { + isNormalUser = true; + name = "ronja"; + description = "Ronja"; + home = "/home/ronja"; + extraGroups = [ + "networkmanager" + "wheel" + "games" + "podman" + "openvscode-server" + ]; + shell = pkgs.zsh; + }; + + nix.settings.trusted-users = [ "ronja" ]; +} diff --git a/nixosModules/user-vinzenz.nix b/nixosModules/user-vinzenz.nix new file mode 100644 index 0000000..b48e750 --- /dev/null +++ b/nixosModules/user-vinzenz.nix @@ -0,0 +1,35 @@ +{ pkgs, ... }: +{ + users.users.vinzenz = { + isNormalUser = true; + name = "vinzenz"; + description = "Vinzenz"; + home = "/home/vinzenz"; + extraGroups = [ + "networkmanager" + "wheel" + "games" + "dialout" + "podman" + "nginx" + "adbusers" + "kvm" + "input" + "video" + ]; + shell = pkgs.zsh; + autoSubUidGidRange = true; + }; + + nix.settings.trusted-users = [ "vinzenz" ]; + + allowedUnfreePackages = [ + "rider" + "pycharm-professional" + "jetbrains-toolbox" + + "anydesk" + + "vscode-extension-ms-dotnettools-csharp" + ]; +} diff --git a/nixosModules/vinzenz-desktop-settings.nix b/nixosModules/vinzenz-desktop-settings.nix new file mode 100644 index 0000000..24b4b4f --- /dev/null +++ b/nixosModules/vinzenz-desktop-settings.nix @@ -0,0 +1,28 @@ +{ pkgs, ... }: +{ + programs.firefox.enable = true; + + environment.systemPackages = with pkgs; [ + lm_sensors + libreoffice-qt6 + ]; + + fonts = { + enableDefaultPackages = true; + fontconfig.defaultFonts.monospace = [ "FiraCode Nerd Font" ]; + packages = with pkgs; [ + nerd-fonts.fira-code + roboto-mono + recursive + ]; + }; + + hardware.logitech.wireless = { + enable = true; + enableGraphical = true; + }; + + # RDP connections + services.gnome.gnome-remote-desktop.enable = true; + networking.firewall.allowedTCPPorts = [ 3389 ]; +} diff --git a/nixosModules/wine-gaming.nix b/nixosModules/wine-gaming.nix new file mode 100644 index 0000000..2b9cb51 --- /dev/null +++ b/nixosModules/wine-gaming.nix @@ -0,0 +1,22 @@ +{ pkgs, ... }: +{ + hardware = { + graphics = { + enable32Bit = true; + extraPackages = with pkgs; [ mangohud ]; + extraPackages32 = with pkgs; [ mangohud ]; + }; + + xpadneo.enable = true; + }; + + environment.systemPackages = with pkgs; [ + wineWowPackages.stagingFull + wineWowPackages.fonts + winetricks + dxvk + mangohud + vulkan-tools + glxinfo + ]; +}