Compare commits
11 changed files with 59 additions and 347 deletions
138
flake.lock
generated
138
flake.lock
generated
|
|
@ -1,21 +1,5 @@
|
||||||
{
|
{
|
||||||
"nodes": {
|
"nodes": {
|
||||||
"argononed": {
|
|
||||||
"flake": false,
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1729566243,
|
|
||||||
"narHash": "sha256-DPNI0Dpk5aym3Baf5UbEe5GENDrSmmXVdriRSWE+rgk=",
|
|
||||||
"owner": "nvmd",
|
|
||||||
"repo": "argononed",
|
|
||||||
"rev": "16dbee54d49b66d5654d228d1061246b440ef7cf",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nvmd",
|
|
||||||
"repo": "argononed",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"base16": {
|
"base16": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"fromYaml": "fromYaml"
|
"fromYaml": "fromYaml"
|
||||||
|
|
@ -197,21 +181,6 @@
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"flake-compat_2": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1767039857,
|
|
||||||
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
|
|
||||||
"owner": "edolstra",
|
|
||||||
"repo": "flake-compat",
|
|
||||||
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "edolstra",
|
|
||||||
"repo": "flake-compat",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"flake-parts": {
|
"flake-parts": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs-lib": "nixpkgs-lib"
|
"nixpkgs-lib": "nixpkgs-lib"
|
||||||
|
|
@ -390,11 +359,11 @@
|
||||||
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
|
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1776879043,
|
"lastModified": 1776363101,
|
||||||
"narHash": "sha256-M9RjuowtoqQbFRdQAm2P6GjFwgHjRcnWYcB7ChSjDms=",
|
"narHash": "sha256-PIsrdhbaD+aqB473D3IjVjRdO5uQJ6etnm5b7nvdnmU=",
|
||||||
"owner": "sodiboo",
|
"owner": "sodiboo",
|
||||||
"repo": "niri-flake",
|
"repo": "niri-flake",
|
||||||
"rev": "535ebbe038039215a5d1c6c0c67f833409a5be96",
|
"rev": "f273e1406713b729e02e419d31c48200a285fac1",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
|
|
@ -423,11 +392,11 @@
|
||||||
"niri-unstable": {
|
"niri-unstable": {
|
||||||
"flake": false,
|
"flake": false,
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1776853441,
|
"lastModified": 1776358048,
|
||||||
"narHash": "sha256-mSxfoEs7DiDhMCBzprI/1K7UXzMISuGq0b7T06LVJXE=",
|
"narHash": "sha256-0OpEyuTrEVVkQXFJ5iSmjFXqSEsTNje0ldmiTNgEkOQ=",
|
||||||
"owner": "YaLTeR",
|
"owner": "YaLTeR",
|
||||||
"repo": "niri",
|
"repo": "niri",
|
||||||
"rev": "74d2b18603366b98ec9045ecf4a632422f472365",
|
"rev": "a1b0bd6d1cbbc695188f53839e42def4c5d38f43",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
|
|
@ -458,11 +427,11 @@
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1776828494,
|
"lastModified": 1776310443,
|
||||||
"narHash": "sha256-gQ5+syn8ndyF/+c5g5ZpeAScNKhkTF4/63JsO2hqGHo=",
|
"narHash": "sha256-XQo/vlS6xak3iT3xS2Q3TUMbreeeqe+PR99feUoV0UQ=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "nix-vscode-extensions",
|
"repo": "nix-vscode-extensions",
|
||||||
"rev": "ea6764d22ff5478f5db39ede57eeafc70d14e8e6",
|
"rev": "3a6d0ea13d092493b285b9093b5ce81e79df5cee",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
|
|
@ -507,61 +476,13 @@
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixos-images": {
|
|
||||||
"inputs": {
|
|
||||||
"nixos-stable": [
|
|
||||||
"nixos-raspberrypi",
|
|
||||||
"nixpkgs"
|
|
||||||
],
|
|
||||||
"nixos-unstable": [
|
|
||||||
"nixos-raspberrypi",
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1747747741,
|
|
||||||
"narHash": "sha256-LUOH27unNWbGTvZFitHonraNx0JF/55h30r9WxqrznM=",
|
|
||||||
"owner": "nvmd",
|
|
||||||
"repo": "nixos-images",
|
|
||||||
"rev": "cbbd6db325775096680b65e2a32fb6187c09bbb4",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nvmd",
|
|
||||||
"ref": "sdimage-installer",
|
|
||||||
"repo": "nixos-images",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixos-raspberrypi": {
|
|
||||||
"inputs": {
|
|
||||||
"argononed": "argononed",
|
|
||||||
"flake-compat": "flake-compat_2",
|
|
||||||
"nixos-images": "nixos-images",
|
|
||||||
"nixpkgs": "nixpkgs"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1775857096,
|
|
||||||
"narHash": "sha256-+eSij7C0oMqz76rGnB99RuWptBuEkJBm9vgb5fIwRrg=",
|
|
||||||
"owner": "nvmd",
|
|
||||||
"repo": "nixos-raspberrypi",
|
|
||||||
"rev": "1dc4ca5f93587932383c0b61e1753f5eed1c3bba",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nvmd",
|
|
||||||
"ref": "main",
|
|
||||||
"repo": "nixos-raspberrypi",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixpkgs": {
|
"nixpkgs": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1775595990,
|
"lastModified": 1776067740,
|
||||||
"narHash": "sha256-OEf7YqhF9IjJFYZJyuhAypgU+VsRB5lD4DuiMws5Ltc=",
|
"narHash": "sha256-B35lpsqnSZwn1Lmz06BpwF7atPgFmUgw1l8KAV3zpVQ=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "4e92bbcdb030f3b4782be4751dc08e6b6cb6ccf2",
|
"rev": "7e495b747b51f95ae15e74377c5ce1fe69c1765f",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
|
|
@ -603,22 +524,6 @@
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixpkgs_2": {
|
"nixpkgs_2": {
|
||||||
"locked": {
|
|
||||||
"lastModified": 1776734388,
|
|
||||||
"narHash": "sha256-vl3dkhlE5gzsItuHoEMVe+DlonsK+0836LIRDnm6MXQ=",
|
|
||||||
"owner": "NixOS",
|
|
||||||
"repo": "nixpkgs",
|
|
||||||
"rev": "10e7ad5bbcb421fe07e3a4ad53a634b0cd57ffac",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "NixOS",
|
|
||||||
"ref": "nixos-25.11",
|
|
||||||
"repo": "nixpkgs",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixpkgs_3": {
|
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1757545623,
|
"lastModified": 1757545623,
|
||||||
"narHash": "sha256-mCxPABZ6jRjUQx3bPP4vjA68ETbPLNz9V2pk9tO7pRQ=",
|
"narHash": "sha256-mCxPABZ6jRjUQx3bPP4vjA68ETbPLNz9V2pk9tO7pRQ=",
|
||||||
|
|
@ -643,11 +548,11 @@
|
||||||
"treefmt-nix": "treefmt-nix"
|
"treefmt-nix": "treefmt-nix"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1777295064,
|
"lastModified": 1776893458,
|
||||||
"narHash": "sha256-A+Ooli4ckGyiT+zh10Ybj3nY2ql4QX1p6q6HrKCDvpA=",
|
"narHash": "sha256-/oT77s8xQGAr80mWV+zcRixZMOqU6AJBloC97xuGY34=",
|
||||||
"ref": "refs/heads/main",
|
"ref": "refs/heads/main",
|
||||||
"rev": "adb6c21135c93e0c57517ba90a32dd8f6bf2704d",
|
"rev": "2c370afe8ed3ea4c198f65246a32a8809c246fd6",
|
||||||
"revCount": 578,
|
"revCount": 524,
|
||||||
"type": "git",
|
"type": "git",
|
||||||
"url": "https://git.berlin.ccc.de/vinzenz/nova-shell"
|
"url": "https://git.berlin.ccc.de/vinzenz/nova-shell"
|
||||||
},
|
},
|
||||||
|
|
@ -666,11 +571,11 @@
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1776893492,
|
"lastModified": 1776364314,
|
||||||
"narHash": "sha256-V4r/mdAFHe6fRiu3D+3+UdclSH7LJoHfv+4Y1YNawK0=",
|
"narHash": "sha256-xH/BIk0BBiZRhcJrurLBzpe0tAdmpeE3FAExIPnb3/w=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "NUR",
|
"repo": "NUR",
|
||||||
"rev": "0aa8e8fc21887cc34a4c0e3816f08b56795f52ca",
|
"rev": "528ff912ac19b61c3be7d29e3976e7f2186c2101",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
|
|
@ -736,8 +641,7 @@
|
||||||
"nix-filter": "nix-filter",
|
"nix-filter": "nix-filter",
|
||||||
"nix-vscode-extensions": "nix-vscode-extensions",
|
"nix-vscode-extensions": "nix-vscode-extensions",
|
||||||
"nixos-generators": "nixos-generators",
|
"nixos-generators": "nixos-generators",
|
||||||
"nixos-raspberrypi": "nixos-raspberrypi",
|
"nixpkgs": "nixpkgs",
|
||||||
"nixpkgs": "nixpkgs_2",
|
|
||||||
"nixpkgs-unstable": "nixpkgs-unstable",
|
"nixpkgs-unstable": "nixpkgs-unstable",
|
||||||
"nova-shell": "nova-shell",
|
"nova-shell": "nova-shell",
|
||||||
"nur": "nur",
|
"nur": "nur",
|
||||||
|
|
@ -824,7 +728,7 @@
|
||||||
"nix-filter": [
|
"nix-filter": [
|
||||||
"nix-filter"
|
"nix-filter"
|
||||||
],
|
],
|
||||||
"nixpkgs": "nixpkgs_3"
|
"nixpkgs": "nixpkgs_2"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1757763091,
|
"lastModified": 1757763091,
|
||||||
|
|
|
||||||
62
flake.nix
62
flake.nix
|
|
@ -9,7 +9,6 @@
|
||||||
};
|
};
|
||||||
|
|
||||||
#keep-sorted start block=yes
|
#keep-sorted start block=yes
|
||||||
|
|
||||||
flake-parts = {
|
flake-parts = {
|
||||||
url = "github:hercules-ci/flake-parts";
|
url = "github:hercules-ci/flake-parts";
|
||||||
#inputs.nixpkgs.follows = "nixpkgs";
|
#inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
|
@ -38,9 +37,6 @@
|
||||||
url = "github:nix-community/nixos-generators";
|
url = "github:nix-community/nixos-generators";
|
||||||
inputs.nixpkgs.follows = "nixpkgs";
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
};
|
};
|
||||||
nixos-raspberrypi = {
|
|
||||||
url = "github:nvmd/nixos-raspberrypi/main";
|
|
||||||
};
|
|
||||||
nova-shell = {
|
nova-shell = {
|
||||||
url = "git+https://git.berlin.ccc.de/vinzenz/nova-shell";
|
url = "git+https://git.berlin.ccc.de/vinzenz/nova-shell";
|
||||||
inputs.nixpkgs.follows = "nixpkgs-unstable";
|
inputs.nixpkgs.follows = "nixpkgs-unstable";
|
||||||
|
|
@ -103,7 +99,6 @@
|
||||||
niri,
|
niri,
|
||||||
nix-vscode-extensions,
|
nix-vscode-extensions,
|
||||||
nixos-generators,
|
nixos-generators,
|
||||||
nixos-raspberrypi,
|
|
||||||
nixpkgs-unstable,
|
nixpkgs-unstable,
|
||||||
servicepoint-cli,
|
servicepoint-cli,
|
||||||
servicepoint-simulator,
|
servicepoint-simulator,
|
||||||
|
|
@ -116,28 +111,6 @@
|
||||||
}:
|
}:
|
||||||
let
|
let
|
||||||
devices = {
|
devices = {
|
||||||
# keep-sorted start block=yes
|
|
||||||
aur0ra = {
|
|
||||||
system = "aarch64-linux";
|
|
||||||
nixosSystem = nixos-raspberrypi.lib.nixosSystem;
|
|
||||||
};
|
|
||||||
aur0ra-installer = {
|
|
||||||
# build with nix build .\#nixosConfigurations.aur0ra-installer.config.system.build.sdImage
|
|
||||||
system = "aarch64-linux";
|
|
||||||
nixosSystem = nixos-raspberrypi.lib.nixosInstaller;
|
|
||||||
};
|
|
||||||
damocles = {
|
|
||||||
system = "x86_64-linux";
|
|
||||||
};
|
|
||||||
epimetheus = {
|
|
||||||
system = "aarch64-linux";
|
|
||||||
};
|
|
||||||
forgejo-runner-1 = {
|
|
||||||
system = "aarch64-linux";
|
|
||||||
};
|
|
||||||
hetzner-vpn2 = {
|
|
||||||
system = "aarch64-linux";
|
|
||||||
};
|
|
||||||
muede-lpt2 = {
|
muede-lpt2 = {
|
||||||
system = "x86_64-linux";
|
system = "x86_64-linux";
|
||||||
home-manager-users = {
|
home-manager-users = {
|
||||||
|
|
@ -156,7 +129,18 @@
|
||||||
inherit (self.homeConfigurations) ronja;
|
inherit (self.homeConfigurations) ronja;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
# keep-sorted end
|
hetzner-vpn2 = {
|
||||||
|
system = "aarch64-linux";
|
||||||
|
};
|
||||||
|
forgejo-runner-1 = {
|
||||||
|
system = "aarch64-linux";
|
||||||
|
};
|
||||||
|
epimetheus = {
|
||||||
|
system = "aarch64-linux";
|
||||||
|
};
|
||||||
|
damocles = {
|
||||||
|
system = "x86_64-linux";
|
||||||
|
};
|
||||||
};
|
};
|
||||||
inherit (nixpkgs) lib;
|
inherit (nixpkgs) lib;
|
||||||
forDevice = f: lib.mapAttrs (device: value: f (value // { inherit device; })) devices;
|
forDevice = f: lib.mapAttrs (device: value: f (value // { inherit device; })) devices;
|
||||||
|
|
@ -232,19 +216,18 @@
|
||||||
device,
|
device,
|
||||||
system,
|
system,
|
||||||
home-manager-users ? { },
|
home-manager-users ? { },
|
||||||
nixosSystem ? nixpkgs.lib.nixosSystem
|
|
||||||
}:
|
}:
|
||||||
let
|
let
|
||||||
specialArgs = inputs // {
|
specialArgs = inputs // {
|
||||||
inherit device home-manager-users;
|
inherit device home-manager-users;
|
||||||
};
|
};
|
||||||
in
|
in
|
||||||
nixosSystem {
|
nixpkgs.lib.nixosSystem {
|
||||||
inherit specialArgs;
|
inherit specialArgs;
|
||||||
modules = [
|
modules = [
|
||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
./nixosConfigurations/${device}
|
./nixosConfigurations/${device}
|
||||||
self.nixosModules.global-settings
|
self.nixosModules.global-settings
|
||||||
]
|
]
|
||||||
++ (lib.optionals (home-manager-users != { }) [
|
++ (lib.optionals (home-manager-users != { }) [
|
||||||
|
|
@ -267,5 +250,22 @@
|
||||||
formatting = treefmt-eval.config.build.check self;
|
formatting = treefmt-eval.config.build.check self;
|
||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
|
packages = forAllSystems (
|
||||||
|
{ ... }:
|
||||||
|
{
|
||||||
|
nixos-aarch64-pxvirt-lxc-template = nixos-generators.nixosGenerate {
|
||||||
|
system = "aarch64-linux";
|
||||||
|
format = "proxmox-lxc";
|
||||||
|
specialArgs = inputs // {
|
||||||
|
device = "nixos-aarch64-pxvirt-lxc-template";
|
||||||
|
};
|
||||||
|
modules = [
|
||||||
|
self.nixosModules.global-settings
|
||||||
|
self.nixosModules.pxvirt-guest
|
||||||
|
];
|
||||||
|
};
|
||||||
|
}
|
||||||
|
);
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -19,6 +19,7 @@
|
||||||
# ./waybar.nix
|
# ./waybar.nix
|
||||||
# ./wlogout.nix
|
# ./wlogout.nix
|
||||||
./zsh.nix
|
./zsh.nix
|
||||||
|
self.inputs.nova-shell.homeModules.default
|
||||||
# keep-sorted end
|
# keep-sorted end
|
||||||
];
|
];
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,17 +0,0 @@
|
||||||
{
|
|
||||||
nixos-images,
|
|
||||||
config,
|
|
||||||
lib,
|
|
||||||
modulesPath,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
{
|
|
||||||
imports = [
|
|
||||||
../aur0ra
|
|
||||||
# nixos-images.nixosModules.sdimage-installer
|
|
||||||
];
|
|
||||||
disabledModules = [
|
|
||||||
# disable the sd-image module that nixos-images uses
|
|
||||||
# (modulesPath + "/installer/sd-card/sd-image-aarch64-installer.nix")
|
|
||||||
];
|
|
||||||
}
|
|
||||||
|
|
@ -1,56 +0,0 @@
|
||||||
{ lib, ... }:
|
|
||||||
{
|
|
||||||
imports = [
|
|
||||||
./hardware.nix
|
|
||||||
./nice-looking-console.nix
|
|
||||||
];
|
|
||||||
|
|
||||||
users.users.ruth = {
|
|
||||||
# initialPassword = "setup";
|
|
||||||
isNormalUser = true;
|
|
||||||
extraGroups = [
|
|
||||||
"wheel"
|
|
||||||
"networkmanager"
|
|
||||||
"video"
|
|
||||||
];
|
|
||||||
# Allow the graphical user to login without password
|
|
||||||
initialHashedPassword = "";
|
|
||||||
openssh.authorizedKeys.keys = [
|
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDNpLDmctyqGpow/ElQvdhY4BLBPS/sigDJ1QEcC7wC lpt2-roaming"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
nix.settings.trusted-users = [ "ruth" ];
|
|
||||||
|
|
||||||
# Don't require sudo/root to `reboot` or `poweroff`.
|
|
||||||
security.polkit.enable = true;
|
|
||||||
|
|
||||||
# Allow passwordless sudo from nixos user
|
|
||||||
security.sudo = {
|
|
||||||
enable = true;
|
|
||||||
wheelNeedsPassword = false;
|
|
||||||
};
|
|
||||||
|
|
||||||
services.openssh.enable = true;
|
|
||||||
|
|
||||||
# https://github.com/nvmd/nixos-raspberrypi-demo/blob/c521600570f0365ae9c846af4b023049b80ae331/modules/server-networking.nix
|
|
||||||
|
|
||||||
networking.firewall.logRefusedConnections = lib.mkDefault false;
|
|
||||||
|
|
||||||
# Use networkd instead of the pile of shell scripts
|
|
||||||
# NOTE: SK: is it safe to combine with NetworkManager on desktops?
|
|
||||||
networking.useNetworkd = lib.mkDefault true;
|
|
||||||
|
|
||||||
# The notion of "online" is a broken concept
|
|
||||||
# https://github.com/systemd/systemd/blob/e1b45a756f71deac8c1aa9a008bd0dab47f64777/NEWS#L13
|
|
||||||
# https://github.com/NixOS/nixpkgs/issues/247608
|
|
||||||
systemd.services.NetworkManager-wait-online.enable = false;
|
|
||||||
systemd.network.wait-online.enable = false;
|
|
||||||
|
|
||||||
# Do not take down the network for too long when upgrading,
|
|
||||||
# This also prevents failures of services that are restarted instead of stopped.
|
|
||||||
# It will use `systemctl restart` rather than stopping it with `systemctl stop`
|
|
||||||
# followed by a delayed `systemctl start`.
|
|
||||||
systemd.services.systemd-networkd.stopIfChanged = false;
|
|
||||||
# Services that are only restarted might be not able to resolve when resolved is stopped before
|
|
||||||
systemd.services.systemd-resolved.stopIfChanged = false;
|
|
||||||
}
|
|
||||||
|
|
@ -1,64 +0,0 @@
|
||||||
{ nixos-raspberrypi, lib, ... }:
|
|
||||||
{
|
|
||||||
imports = with nixos-raspberrypi.nixosModules; [
|
|
||||||
raspberry-pi-5.base
|
|
||||||
raspberry-pi-5.bluetooth
|
|
||||||
raspberry-pi-5.page-size-16k
|
|
||||||
raspberry-pi-5.display-vc4
|
|
||||||
];
|
|
||||||
|
|
||||||
# No one got time for xz compression.
|
|
||||||
#isoImage.squashfsCompression = "zstd";
|
|
||||||
|
|
||||||
boot.loader = {
|
|
||||||
raspberry-pi.bootloader = "kernel";
|
|
||||||
systemd-boot.enable = lib.mkForce false;
|
|
||||||
#generic-extlinux-compatible.enable = lib.mkForce false;
|
|
||||||
};
|
|
||||||
|
|
||||||
/*
|
|
||||||
fileSystems = {
|
|
||||||
"/boot/firmware" = {
|
|
||||||
# TODO
|
|
||||||
device = "/dev/disk/by-uuid/2175-794E";
|
|
||||||
fsType = "vfat";
|
|
||||||
options = [
|
|
||||||
"noatime"
|
|
||||||
"noauto"
|
|
||||||
"x-systemd.automount"
|
|
||||||
"x-systemd.idle-timeout=1min"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
"/" = {
|
|
||||||
# TODO
|
|
||||||
device = "/dev/disk/by-uuid/44444444-4444-4444-8888-888888888888";
|
|
||||||
fsType = "ext4";
|
|
||||||
options = [ "noatime" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
*/
|
|
||||||
|
|
||||||
hardware.raspberry-pi.config = {
|
|
||||||
all = {
|
|
||||||
# [all] conditional filter, https://www.raspberrypi.com/documentation/computers/config_txt.html#conditional-filters
|
|
||||||
# Base DTB parameters
|
|
||||||
# https://github.com/raspberrypi/linux/blob/a1d3defcca200077e1e382fe049ca613d16efd2b/arch/arm/boot/dts/overlays/README#L132
|
|
||||||
base-dt-params = {
|
|
||||||
|
|
||||||
# https://www.raspberrypi.com/documentation/computers/raspberry-pi.html#enable-pcie
|
|
||||||
pciex1 = {
|
|
||||||
enable = true;
|
|
||||||
value = "on";
|
|
||||||
};
|
|
||||||
# PCIe Gen 3.0
|
|
||||||
# https://www.raspberrypi.com/documentation/computers/raspberry-pi.html#pcie-gen-3-0
|
|
||||||
pciex1_gen = {
|
|
||||||
enable = true;
|
|
||||||
value = "3";
|
|
||||||
};
|
|
||||||
|
|
||||||
};
|
|
||||||
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
@ -1,32 +0,0 @@
|
||||||
# re-borrowed from https://github.com/nvmd/nixos-raspberrypi-demo/blob/main/modules/nice-looking-console.nix
|
|
||||||
{ lib, pkgs, ... }:
|
|
||||||
{
|
|
||||||
# The following have been borrowed from:
|
|
||||||
# https://github.com/nix-community/nixos-images/blob/b733f0680a42cc01d6ad53896fb5ca40a66d5e79/nix/image-installer/module.nix#L84
|
|
||||||
|
|
||||||
console.earlySetup = true;
|
|
||||||
# ter-u22n is probably too big
|
|
||||||
console.font = lib.mkDefault "${pkgs.terminus_font}/share/consolefonts/ter-u16n.psf.gz";
|
|
||||||
|
|
||||||
# Make colored console output more readable
|
|
||||||
# for example, `ip addr`s (blues are too dark by default)
|
|
||||||
# Tango theme: https://yayachiken.net/en/posts/tango-colors-in-terminal/
|
|
||||||
console.colors = lib.mkDefault [
|
|
||||||
"000000"
|
|
||||||
"CC0000"
|
|
||||||
"4E9A06"
|
|
||||||
"C4A000"
|
|
||||||
"3465A4"
|
|
||||||
"75507B"
|
|
||||||
"06989A"
|
|
||||||
"D3D7CF"
|
|
||||||
"555753"
|
|
||||||
"EF2929"
|
|
||||||
"8AE234"
|
|
||||||
"FCE94F"
|
|
||||||
"739FCF"
|
|
||||||
"AD7FA8"
|
|
||||||
"34E2E2"
|
|
||||||
"EEEEEC"
|
|
||||||
];
|
|
||||||
}
|
|
||||||
|
|
@ -1,9 +1,4 @@
|
||||||
{
|
{ pkgs, self, ... }:
|
||||||
pkgs,
|
|
||||||
lib,
|
|
||||||
self,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
{
|
{
|
||||||
imports = [ ./android-dev.nix ];
|
imports = [ ./android-dev.nix ];
|
||||||
|
|
||||||
|
|
@ -11,12 +6,6 @@
|
||||||
|
|
||||||
boot.isContainer = true;
|
boot.isContainer = true;
|
||||||
|
|
||||||
# Container shares host network namespace (privateNetwork = false), so the
|
|
||||||
# host's tailscale already covers this. Running a second tailscaled in the
|
|
||||||
# same netns fights over routing and breaks connectivity after sleep/wake.
|
|
||||||
services.tailscale.enable = lib.mkForce false;
|
|
||||||
networking.firewall.checkReversePath = lib.mkForce "strict";
|
|
||||||
|
|
||||||
allowedUnfreePackages = [ "claude-code" ];
|
allowedUnfreePackages = [ "claude-code" ];
|
||||||
|
|
||||||
environment.systemPackages = with pkgs; [
|
environment.systemPackages = with pkgs; [
|
||||||
|
|
|
||||||
|
|
@ -69,12 +69,7 @@
|
||||||
|
|
||||||
# Global DefaultTimeoutStopSec is 10s (modern-desktop.nix), which kills systemd-nspawn
|
# Global DefaultTimeoutStopSec is 10s (modern-desktop.nix), which kills systemd-nspawn
|
||||||
# before it finishes halting, leaving cgroups busy and breaking restarts.
|
# before it finishes halting, leaving cgroups busy and breaking restarts.
|
||||||
systemd.services."container@damocles".serviceConfig = {
|
systemd.services."container@damocles".serviceConfig.TimeoutStopSec = "60s";
|
||||||
TimeoutStopSec = "60s";
|
|
||||||
# After a SIGKILL of nspawn, the kernel needs a moment to reap its cgroups.
|
|
||||||
# Without this, the immediate restart attempt fails with "Device or resource busy".
|
|
||||||
RestartSec = "5s";
|
|
||||||
};
|
|
||||||
|
|
||||||
boot.enableContainers = true;
|
boot.enableContainers = true;
|
||||||
virtualisation.containers.enable = true;
|
virtualisation.containers.enable = true;
|
||||||
|
|
|
||||||
|
|
@ -1,22 +1,16 @@
|
||||||
{
|
{
|
||||||
nix.settings = {
|
nix.settings = {
|
||||||
substituters = [
|
substituters = [
|
||||||
# keep-sorted start
|
|
||||||
"https://cache.lix.systems"
|
|
||||||
"https://cache.nixos.org/"
|
"https://cache.nixos.org/"
|
||||||
"https://niri.cachix.org"
|
|
||||||
"https://nix-community.cachix.org"
|
"https://nix-community.cachix.org"
|
||||||
"https://nixos-raspberrypi.cachix.org"
|
"https://cache.lix.systems"
|
||||||
# keep-sorted end
|
"https://niri.cachix.org"
|
||||||
];
|
];
|
||||||
trusted-public-keys = [
|
trusted-public-keys = [
|
||||||
# keep-sorted start
|
|
||||||
"cache.lix.systems:aBnZUw8zA7H35Cz2RyKFVs3H4PlGTLawyY5KRbvJR8o="
|
|
||||||
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
|
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
|
||||||
"niri.cachix.org-1:Wv0OmO7PsuocRKzfDoJ3mulSl7Z6oezYhGhR+3W2964="
|
|
||||||
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
|
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
|
||||||
"nixos-raspberrypi.cachix.org-1:4iMO9LXa8BqhU+Rpg6LQKiGa2lsNh/j2oiYLNOQ5sPI="
|
"cache.lix.systems:aBnZUw8zA7H35Cz2RyKFVs3H4PlGTLawyY5KRbvJR8o="
|
||||||
# keep-sorted end
|
"niri.cachix.org-1:Wv0OmO7PsuocRKzfDoJ3mulSl7Z6oezYhGhR+3W2964="
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -7,14 +7,12 @@
|
||||||
servicepoint-tanks,
|
servicepoint-tanks,
|
||||||
stylix,
|
stylix,
|
||||||
specialArgs,
|
specialArgs,
|
||||||
nova-shell,
|
|
||||||
...
|
...
|
||||||
}:
|
}:
|
||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
# keep-sorted start
|
# keep-sorted start
|
||||||
home-manager.nixosModules.home-manager
|
home-manager.nixosModules.home-manager
|
||||||
nova-shell.nixosModules.default
|
|
||||||
self.nixosModules.en-de
|
self.nixosModules.en-de
|
||||||
self.nixosModules.firmware-updates
|
self.nixosModules.firmware-updates
|
||||||
self.nixosModules.gnome
|
self.nixosModules.gnome
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue