nixdots/hosts/herugrim/default.nix

88 lines
2 KiB
Nix
Raw Normal View History

2024-04-07 12:38:24 +00:00
{ lib, pkgs, ... }:
{
imports = [
./hardware-configuration.nix
];
boot.supportedFilesystems = [ "btrfs" ];
2024-04-12 18:57:52 +00:00
# My flake disables this by default for security reasons. However,
# with an encrypted setup, which requires entering password before
# booting anyways, this is not a security concern, and changing the
# kernel params can be useful for debugging.
boot.loader.systemd-boot.editor = true;
2024-04-07 12:38:24 +00:00
nix.settings = {
max-jobs = 6;
cores = 6;
};
# NixOS release from which this machine was first installed.
# (for stateful data, like file locations and db versions)
# Leave this alone!
system.stateVersion = lib.mkForce "23.11";
services.openssh.settings.PasswordAuthentication = lib.mkForce true;
myOptions = {
system = {
hostname = "herugrim";
username = "itsdrike";
2024-04-07 16:28:15 +00:00
2024-04-07 22:36:02 +00:00
impermanence = {
root = {
enable = true;
# Some people use /nix/persist/system for this, leaving persistent files in /nix subvolume
# I much prefer using a standalone subvolume for this though.
persistentMountPoint = "/persist";
};
2024-04-07 16:28:15 +00:00
# Configure automatic root subvolume wiping on boot from initrd
2024-04-07 22:36:02 +00:00
autoWipeBtrfs = {
enable = true;
devices."/dev/disk/by-label/NIXROOT".subvolumes = [ "root" ];
2024-04-07 16:28:15 +00:00
};
};
2024-04-12 16:25:26 +00:00
2024-04-12 18:57:52 +00:00
boot = {
secure-boot.enable = true;
tmpOnTmpfs = true;
};
2024-04-07 12:38:24 +00:00
};
2024-04-07 16:28:15 +00:00
2024-04-07 12:38:24 +00:00
device = {
2024-04-13 18:10:01 +00:00
roles = {
type = "laptop";
virtual-machine = false;
};
2024-04-07 12:38:24 +00:00
cpu.type = "intel";
2024-05-15 18:29:28 +00:00
gpu.type = "nvidia";
2024-04-12 19:38:05 +00:00
hasTPM = true;
2024-04-07 12:38:24 +00:00
};
2024-04-07 16:28:15 +00:00
2024-04-15 20:47:54 +00:00
security = {
auditd = {
enable = true;
autoPrune.enable = true;
};
};
2024-04-13 19:15:25 +00:00
workstation = {
printing.enable = true;
};
2024-04-07 12:38:24 +00:00
home-manager = {
2024-04-07 14:54:36 +00:00
enable = true;
2024-04-07 12:38:24 +00:00
stateVersion = "23.11";
git = {
userName = "ItsDrike";
userEmail = "itsdrike@protonmail.com";
signing = {
2024-04-16 09:55:53 +00:00
enable = true;
2024-04-07 12:38:24 +00:00
key = "FA2745890B7048C0";
};
};
};
};
}