Add elara

Signed-off-by: Nikolaos Karaolidis <nick@karaolidis.com>
This commit is contained in:
2024-12-18 20:57:26 +00:00
parent f96a5c7776
commit e23e71560f
48 changed files with 655 additions and 246 deletions

8
.gitignore vendored
View File

@@ -1,8 +0,0 @@
**/secrets/key.txt
!**/secrets/key.txt.pub
**/secrets/ssh_host_*_key
!**/secrets/ssh_host_*_key.pub
**/secrets/ssh/id_*_*_*
!**/secrets/ssh/id_*_*_*.pub

View File

@@ -23,15 +23,13 @@ NixOS dotfiles and configuration for various hosts and users.
- `users/`: User-specific settings for the host.
- `format.nix`: Disk layout definition using [`disko`](https://github.com/nix-community/disko).
- `users/<name>/`: Global configurations for individual users that apply across all hosts. This includes secrets (like GPG keys and third-party service passwords), wallpapers, and more.
- `secrets/<namespace>/`: Global secrets for individual namespaces that apply across all hosts.
- [`lib/`](./lib): Nix library function definitions and utilities.
- [`scripts/`](./scripts): Utility scripts for managing the repository.
- [`add-host.sh`](./scripts/add-host.sh): Instantiate the keys for a new host configuration.
- [`remove-host.sh`](./scripts/remove-host.sh): Remove references to a host.
- [`add-user.sh`](./scripts/add-user.sh): Instantiate the keys for a new user configuration.
- [`remove-user.sh`](./scripts/remove-user.sh): Remove references to a user.
- [`update-keys.sh`](./scripts/update-keys.sh): Update the encryption keys in all relevant files using `sops.yaml` configurations.
- [`update.sh`](./scripts/update.sh): Update flake and all git submodules.
- [`install.sh`](./scripts/install.sh): Install or repair a selected NixOS host.
@@ -47,3 +45,4 @@ Below is a table of all hosts, with links to their respective README files, whic
| Host | README |
|----------|----------------------------------------------------|
| `eirene` | [hosts/eirene/README.md](./hosts/eirene/README.md) |
| `elara` | [hosts/elara/README.md](./hosts/elara/README.md) |

36
flake.lock generated
View File

@@ -69,11 +69,11 @@
]
},
"locked": {
"lastModified": 1734088167,
"narHash": "sha256-OIitVU+IstPbX/NWn2jLF+/sT9dVKcO2FKeRAzlyX6c=",
"lastModified": 1734343412,
"narHash": "sha256-b7G8oFp0Nj01BYUJ6ENC9Qf/HsYAIZvN9k/p0Kg/PFU=",
"owner": "nix-community",
"repo": "disko",
"rev": "d32f2d1750d61a476a236526b725ec5a32e16342",
"rev": "a08bfe06b39e94eec98dd089a2c1b18af01fef19",
"type": "github"
},
"original": {
@@ -144,11 +144,11 @@
]
},
"locked": {
"lastModified": 1734267456,
"narHash": "sha256-gUE1Pj5bxRlOSph00IU4Y5i06lIKAclc1YcynQLXTOQ=",
"lastModified": 1734529492,
"narHash": "sha256-U+8snNnPq87a0SkqRqvX3X4hHL//nbHnvtN1Th6Xja4=",
"owner": "karaolidis",
"repo": "home-manager",
"rev": "b27691db93b0348b9b0bf151ae952a6f9f95089d",
"rev": "24d660ebd62d3fee4578777efb4f38b042ac6f84",
"type": "github"
},
"original": {
@@ -160,11 +160,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1734267453,
"narHash": "sha256-dgFTPB2ER5akiAWRJbSpPbWar5D6n0BGD5Wcmhkt6pE=",
"lastModified": 1734529489,
"narHash": "sha256-HmUlOWpBp62kr/hFPObhbIXjDPuo915OiUBbL/4CkD8=",
"owner": "karaolidis",
"repo": "nixpkgs",
"rev": "59f98681ef21402ef93ccf43ae6c52547dee168e",
"rev": "9d03f3a891c104cdf1de7c76900642614a929ce5",
"type": "github"
},
"original": {
@@ -176,11 +176,11 @@
},
"nixpkgs_2": {
"locked": {
"lastModified": 1733940404,
"narHash": "sha256-Pj39hSoUA86ZePPF/UXiYHHM7hMIkios8TYG29kQT4g=",
"lastModified": 1734424634,
"narHash": "sha256-cHar1vqHOOyC7f1+tVycPoWTfKIaqkoe1Q6TnKzuti4=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "5d67ea6b4b63378b9c13be21e2ec9d1afc921713",
"rev": "d3c42f187194c26d9f0309a8ecc469d6c878ce33",
"type": "github"
},
"original": {
@@ -197,11 +197,11 @@
"treefmt-nix": "treefmt-nix"
},
"locked": {
"lastModified": 1734263230,
"narHash": "sha256-S5N87tEKOEqsQvZ874e5aMhh2r8K51Q0530I8eh5uC0=",
"lastModified": 1734526336,
"narHash": "sha256-qI+dxxvmYNLhus/4CCE6QjjjPOjTz2olmnc5nZv0SE8=",
"owner": "nix-community",
"repo": "NUR",
"rev": "2562c7e526c1e66c837106dbb99623efb88f32ce",
"rev": "409fe7866b2171633d7be0b7de262d861c61a726",
"type": "github"
},
"original": {
@@ -251,11 +251,11 @@
]
},
"locked": {
"lastModified": 1734236158,
"narHash": "sha256-PlzILP+aSuxXyaI9zuZs9T4QSFn+/c5/eImYBxThLbg=",
"lastModified": 1734495402,
"narHash": "sha256-NicfWsazv+LpZk2Xny9pzCd26IJttnzuou3yGZ5/1AA=",
"owner": "Gerg-L",
"repo": "spicetify-nix",
"rev": "6a83f1889a56760dedb93539360424b64766bc81",
"rev": "5b15daf10de2ce488771e6aabf72a7400b8500fc",
"type": "github"
},
"original": {

View File

@@ -76,6 +76,14 @@
system = "x86_64-linux";
modules = [ ./hosts/eirene ];
};
elara = nixpkgs.lib.nixosSystem {
specialArgs = {
inherit inputs;
};
system = "x86_64-linux";
modules = [ ./hosts/elara ];
};
};
}
// inputs.flake-utils.lib.eachDefaultSystem (

1
hosts/.gitignore vendored Normal file
View File

@@ -0,0 +1 @@
*/secrets/ssh_host_ed25519_key

View File

@@ -24,8 +24,10 @@
environment = {
systemPackages = [ config.virtualisation.libvirtd.qemu.swtpm.package ];
etc = {
"ovmf/edk2-x86_64-secure-code.fd".source = "${config.virtualisation.libvirtd.qemu.package}/share/qemu/edk2-x86_64-secure-code.fd";
"ovmf/edk2-i386-vars.fd".source = "${config.virtualisation.libvirtd.qemu.package}/share/qemu/edk2-i386-vars.fd";
"ovmf/edk2-x86_64-secure-code.fd".source =
"${config.virtualisation.libvirtd.qemu.package}/share/qemu/edk2-x86_64-secure-code.fd";
"ovmf/edk2-i386-vars.fd".source =
"${config.virtualisation.libvirtd.qemu.package}/share/qemu/edk2-i386-vars.fd";
};
persistence."/persist"."/var/lib/libvirt" = { };
};

View File

@@ -1,5 +1,5 @@
if [[ "$(id -u)" -ne 0 ]]; then
echo "This script must be run as root."
if [[ "${EUID}" -ne 0 ]]; then
echo "Please run the script as root."
exit 1
fi

View File

@@ -1,6 +1,9 @@
{ config, inputs, ... }:
{
sops.secrets."nix/accessTokens/github".group = "users";
sops.secrets."nix/accessTokens/github" = {
sopsFile = ../../../../../secrets/personal/secrets.yaml;
group = "users";
};
nix = {
settings = {

View File

@@ -3,6 +3,7 @@
programs.ssh = {
knownHosts = {
eirene.publicKeyFile = ../../../../eirene/secrets/ssh_host_ed25519_key.pub;
elara.publicKeyFile = ../../../../elara/secrets/ssh_host_ed25519_key.pub;
};
};
}

View File

@@ -43,10 +43,5 @@ in
);
};
};
sops.secrets = {
"git/credentials".path = "${home}/.config/git/credentials";
"git/cookies".path = "${home}/.config/git/cookies";
};
};
}

View File

@@ -61,10 +61,5 @@
Install.WantedBy = [ "default.target" ];
};
};
sops.secrets = {
"gpg-agent/pgp/key" = { };
"gpg-agent/pgp/pass" = { };
};
};
}

View File

@@ -713,7 +713,7 @@ in
}
) hmConfig.programs.obsidian.vaults;
sops.secrets."google/geocoding" = { };
sops.secrets."google/geocoding".sopsFile = ../../../../../../secrets/personal/secrets.yaml;
wayland.windowManager.hyprland.settings.bind = [ "$mod, o, exec, ${pkgs.obsidian}/bin/obsidian" ];
};

View File

@@ -62,7 +62,7 @@ in
];
};
sops.secrets."spotify/username" = { };
sops.secrets."spotify/username".sopsFile = ../../../../../../secrets/personal/secrets.yaml;
xdg.configFile = {
"spotify/prefs.init" = {

View File

@@ -12,6 +12,10 @@ let
name = "theme-init";
runtimeInputs = with pkgs; [ matugen ];
text = ''
[[ ! -d "${cfg.configDir}" ]] && mkdir -p "${cfg.configDir}"
[[ ! -L "${cfg.configDir}"/wallpaper ]] && ln -sf "${cfg.wallpaper}" "${cfg.configDir}"/wallpaper
[[ ! -f "${cfg.configDir}"/mode ]] && echo "${cfg.mode}" > "${cfg.configDir}"/mode
matugen image "${cfg.configDir}/wallpaper" \
--type scheme-${cfg.flavour} \
--mode "$(cat "${cfg.configDir}/mode")" \

View File

@@ -1,7 +1,3 @@
[[ ! -d "${CONFIG}" ]] && mkdir -p "${CONFIG}"
[[ ! -L "${CONFIG}"/wallpaper ]] && ln -sf "${DEFAULT_WALLPAPER}" "${CONFIG}"/wallpaper
[[ ! -f "${CONFIG}"/mode ]] && echo "${DEFAULT_MODE}" > "${CONFIG}"/mode
WALLPAPER=""
MODE=""

View File

@@ -43,6 +43,7 @@ in
ms-vsliveshare.vsliveshare
github.copilot
naumovs.color-highlight
signageos.signageos-vscode-sops
];
userSettings = {
@@ -117,5 +118,7 @@ in
./langs/python
./langs/svelte
];
wayland.windowManager.hyprland.settings.bind = [ "$mod, c, exec, ${lib.meta.getExe pkgs.vscode}" ];
};
}

View File

@@ -27,6 +27,7 @@
../common/system/configs/neovim
../common/system/configs/networking
../common/system/configs/nix
../common/system/configs/nix-cleanup
../common/system/configs/nix-ld
../common/system/configs/nixpkgs
../common/system/configs/ntp
@@ -45,8 +46,7 @@
../common/system/configs/users
../common/system/configs/wget
../common/system/configs/zsh
../common/system/scripts/cleanup
./users/nick.nix
./users/nick
];
networking.hostName = "eirene";
@@ -128,7 +128,7 @@
powerManagement.enable = true;
systemd.services.powertop.postStart = builtins.readFile ./scripts/mouse.sh;
systemd.services.powertop.postStart = builtins.readFile ./system/scripts/mouse.sh;
services = {
xserver.videoDrivers = [ "nvidia" ];
@@ -170,7 +170,7 @@
};
programs = {
zsh.loginExtra = lib.mkBefore (builtins.readFile ./scripts/card.sh);
zsh.loginExtra = lib.mkBefore (builtins.readFile ./system/scripts/card.sh);
# VSCode does not play well with fractional scaling
vscode.userSettings."window.zoomLevel" = (1.25 - 1) / 0.2;
@@ -188,9 +188,7 @@
};
};
theme = {
cursor.size = 24;
};
theme.cursor.size = 24;
}
];
}

View File

@@ -1,125 +0,0 @@
{ config, lib, ... }:
let
# FIXME: https://github.com/NixOS/nixpkgs/issues/24570
# FIXME: https://github.com/NixOS/nixpkgs/issues/305643
user = "nick";
home = "/home/nick";
in
{
imports = [
../../common/user/configs/options.nix
(import ../../common/user/configs/console/android { inherit user home; })
(import ../../common/user/configs/console/bashmount { inherit user home; })
(import ../../common/user/configs/console/bluetooth { inherit user home; })
(import ../../common/user/configs/console/brightnessctl { inherit user home; })
(import ../../common/user/configs/console/btop { inherit user home; })
(import ../../common/user/configs/console/docker { inherit user home; })
(import ../../common/user/configs/console/fastfetch { inherit user home; })
(import ../../common/user/configs/console/ffmpeg { inherit user home; })
(import ../../common/user/configs/console/git { inherit user home; })
(import ../../common/user/configs/console/gpg-agent { inherit user home; })
(import ../../common/user/configs/console/home-manager { inherit user home; })
(import ../../common/user/configs/console/imagemagick { inherit user home; })
(import ../../common/user/configs/console/libvirt { inherit user home; })
(import ../../common/user/configs/console/ncdu { inherit user home; })
(import ../../common/user/configs/console/neovim { inherit user home; })
(import ../../common/user/configs/console/nix-develop { inherit user home; })
(import ../../common/user/configs/console/nix-direnv { inherit user home; })
(import ../../common/user/configs/console/nixpkgs { inherit user home; })
(import ../../common/user/configs/console/pipewire { inherit user home; })
(import ../../common/user/configs/console/ranger { inherit user home; })
(import ../../common/user/configs/console/sops { inherit user home; })
(import ../../common/user/configs/console/syncthing { inherit user home; })
(import ../../common/user/configs/console/tmux { inherit user home; })
(import ../../common/user/configs/console/tree { inherit user home; })
(import ../../common/user/configs/console/wget { inherit user home; })
(import ../../common/user/configs/console/xdg { inherit user home; })
(import ../../common/user/configs/console/yt-dlp { inherit user home; })
(import ../../common/user/configs/console/zsh { inherit user home; })
(import ../../common/user/configs/gui/astal { inherit user home; })
(import ../../common/user/configs/gui/bluetooth { inherit user home; })
(import ../../common/user/configs/gui/brightnessctl { inherit user home; })
(import ../../common/user/configs/gui/btop { inherit user home; })
(import ../../common/user/configs/gui/chromium { inherit user home; })
(import ../../common/user/configs/gui/cliphist { inherit user home; })
(import ../../common/user/configs/gui/darktable { inherit user home; })
(import ../../common/user/configs/gui/discord { inherit user home; })
(import ../../common/user/configs/gui/emoji { inherit user home; })
(import ../../common/user/configs/gui/firefox { inherit user home; })
(import ../../common/user/configs/gui/gaming { inherit user home; })
(import ../../common/user/configs/gui/gtk { inherit user home; })
(import ../../common/user/configs/gui/hyprland { inherit user home; })
(import ../../common/user/configs/gui/hyprshot { inherit user home; })
(import ../../common/user/configs/gui/kitty { inherit user home; })
(import ../../common/user/configs/gui/libreoffice { inherit user home; })
(import ../../common/user/configs/gui/networking { inherit user home; })
(import ../../common/user/configs/gui/obs { inherit user home; })
(import ../../common/user/configs/gui/obsidian { inherit user home; })
(import ../../common/user/configs/gui/pipewire { inherit user home; })
(import ../../common/user/configs/gui/qalculate { inherit user home; })
(import ../../common/user/configs/gui/qt { inherit user home; })
(import ../../common/user/configs/gui/rofi { inherit user home; })
(import ../../common/user/configs/gui/spicetify { inherit user home; })
(import ../../common/user/configs/gui/swww { inherit user home; })
(import ../../common/user/configs/gui/theme { inherit user home; })
(import ../../common/user/configs/gui/transmission { inherit user home; })
(import ../../common/user/configs/gui/vscode { inherit user home; })
(import ../../common/user/configs/gui/wev { inherit user home; })
(import ../../common/user/configs/gui/x11 { inherit user home; })
(import ../../common/user/configs/gui/xdg { inherit user home; })
];
sops.secrets."${user}-password" = {
sopsFile = ../../../users/${user}/secrets/secrets.yaml;
key = "password";
neededForUsers = true;
};
users.users.${user} = {
inherit home;
isNormalUser = true;
email = "nick@karaolidis.com";
fullName = "Nikolaos Karaolidis";
description = "Nikolaos Karaolidis";
hashedPasswordFile = config.sops.secrets."${user}-password".path;
extraGroups = [ "wheel" ];
linger = true;
uid = lib.strings.toInt (builtins.readFile ../../../users/${user}/uid);
};
services.getty.autologinUser = user;
home-manager.users.${user} = {
home = {
username = user;
homeDirectory = home;
};
sops.defaultSopsFile = ../../../users/${user}/secrets/secrets.yaml;
theme.wallpaper = ../../../users/${user}/secrets/wallpapers/clouds.png;
programs.obsidian.vaults."Documents/Obsidian/master".enable = true;
services.syncthing.settings.folders = {
obsidian = {
label = "Obsidian";
path = "${home}/Documents/Obsidian";
devices = [
"amalthea"
"ganymede"
];
};
official = {
label = "Official";
path = "${home}/Documents/Official";
devices = [
"amalthea"
"ganymede"
];
};
};
home.file."Documents/Obsidian/.stignore".source =
../../common/user/configs/gui/obsidian/config/.stignore;
};
}

View File

@@ -0,0 +1,138 @@
{ config, lib, ... }:
let
# FIXME: https://github.com/NixOS/nixpkgs/issues/24570
# FIXME: https://github.com/NixOS/nixpkgs/issues/305643
user = "nick";
home = "/home/nick";
in
{
imports = [
../../../common/user/configs/options.nix
(import ../../../common/user/configs/console/android { inherit user home; })
(import ../../../common/user/configs/console/bashmount { inherit user home; })
(import ../../../common/user/configs/console/bluetooth { inherit user home; })
(import ../../../common/user/configs/console/brightnessctl { inherit user home; })
(import ../../../common/user/configs/console/btop { inherit user home; })
(import ../../../common/user/configs/console/docker { inherit user home; })
(import ../../../common/user/configs/console/fastfetch { inherit user home; })
(import ../../../common/user/configs/console/ffmpeg { inherit user home; })
(import ../../../common/user/configs/console/git { inherit user home; })
(import ../../../common/user/configs/console/gpg-agent { inherit user home; })
(import ../../../common/user/configs/console/home-manager { inherit user home; })
(import ../../../common/user/configs/console/imagemagick { inherit user home; })
(import ../../../common/user/configs/console/libvirt { inherit user home; })
(import ../../../common/user/configs/console/ncdu { inherit user home; })
(import ../../../common/user/configs/console/neovim { inherit user home; })
(import ../../../common/user/configs/console/nix-develop { inherit user home; })
(import ../../../common/user/configs/console/nix-direnv { inherit user home; })
(import ../../../common/user/configs/console/nixpkgs { inherit user home; })
(import ../../../common/user/configs/console/pipewire { inherit user home; })
(import ../../../common/user/configs/console/ranger { inherit user home; })
(import ../../../common/user/configs/console/sops { inherit user home; })
(import ../../../common/user/configs/console/syncthing { inherit user home; })
(import ../../../common/user/configs/console/tmux { inherit user home; })
(import ../../../common/user/configs/console/tree { inherit user home; })
(import ../../../common/user/configs/console/wget { inherit user home; })
(import ../../../common/user/configs/console/xdg { inherit user home; })
(import ../../../common/user/configs/console/yt-dlp { inherit user home; })
(import ../../../common/user/configs/console/zsh { inherit user home; })
(import ../../../common/user/configs/gui/astal { inherit user home; })
(import ../../../common/user/configs/gui/bluetooth { inherit user home; })
(import ../../../common/user/configs/gui/brightnessctl { inherit user home; })
(import ../../../common/user/configs/gui/btop { inherit user home; })
(import ../../../common/user/configs/gui/chromium { inherit user home; })
(import ../../../common/user/configs/gui/cliphist { inherit user home; })
(import ../../../common/user/configs/gui/darktable { inherit user home; })
(import ../../../common/user/configs/gui/discord { inherit user home; })
(import ../../../common/user/configs/gui/emoji { inherit user home; })
(import ../../../common/user/configs/gui/firefox { inherit user home; })
(import ../../../common/user/configs/gui/gaming { inherit user home; })
(import ../../../common/user/configs/gui/gtk { inherit user home; })
(import ../../../common/user/configs/gui/hyprland { inherit user home; })
(import ../../../common/user/configs/gui/hyprshot { inherit user home; })
(import ../../../common/user/configs/gui/kitty { inherit user home; })
(import ../../../common/user/configs/gui/libreoffice { inherit user home; })
(import ../../../common/user/configs/gui/networking { inherit user home; })
(import ../../../common/user/configs/gui/obs { inherit user home; })
(import ../../../common/user/configs/gui/obsidian { inherit user home; })
(import ../../../common/user/configs/gui/pipewire { inherit user home; })
(import ../../../common/user/configs/gui/qalculate { inherit user home; })
(import ../../../common/user/configs/gui/qt { inherit user home; })
(import ../../../common/user/configs/gui/rofi { inherit user home; })
(import ../../../common/user/configs/gui/spicetify { inherit user home; })
(import ../../../common/user/configs/gui/swww { inherit user home; })
(import ../../../common/user/configs/gui/theme { inherit user home; })
(import ../../../common/user/configs/gui/transmission { inherit user home; })
(import ../../../common/user/configs/gui/vscode { inherit user home; })
(import ../../../common/user/configs/gui/wev { inherit user home; })
(import ../../../common/user/configs/gui/x11 { inherit user home; })
(import ../../../common/user/configs/gui/xdg { inherit user home; })
];
# echo "password" | mkpasswd -s
sops.secrets."${user}-password" = {
sopsFile = ../../../../secrets/personal/secrets.yaml;
key = "password";
neededForUsers = true;
};
users.users.${user} = {
inherit home;
isNormalUser = true;
email = "nick@karaolidis.com";
fullName = "Nikolaos Karaolidis";
description = "Nikolaos Karaolidis";
hashedPasswordFile = config.sops.secrets."${user}-password".path;
extraGroups = [ "wheel" ];
linger = true;
uid = lib.strings.toInt (builtins.readFile ./uid);
};
services.getty.autologinUser = user;
home-manager.users.${user} = {
home = {
username = user;
homeDirectory = home;
};
sops.secrets = {
"git/credentials" = {
sopsFile = ../../../../secrets/personal/secrets.yaml;
path = "${home}/.config/git/credentials";
};
"git/cookies" = {
sopsFile = ../../../../secrets/personal/secrets.yaml;
path = "${home}/.config/git/cookies";
};
"gpg-agent/personal/key".sopsFile = ../../../../secrets/personal/secrets.yaml;
"gpg-agent/personal/pass".sopsFile = ../../../../secrets/personal/secrets.yaml;
};
theme.wallpaper = ../../../../static/wallpapers/clouds.png;
programs.obsidian.vaults."Documents/Obsidian/master".enable = true;
services.syncthing.settings.folders = {
obsidian = {
label = "Obsidian";
path = "${home}/Documents/Obsidian";
devices = [
"amalthea"
"ganymede"
];
};
official = {
label = "Official";
path = "${home}/Documents/Official";
devices = [
"amalthea"
"ganymede"
];
};
};
home.file."Documents/Obsidian/.stignore".source =
../../../common/user/configs/gui/obsidian/config/.stignore;
};
}

18
hosts/elara/README.md Normal file
View File

@@ -0,0 +1,18 @@
# sas
## Post-Install Checklist
### Networking
- [ ] Add NetworkManager connections
- [ ] Connect Bluetooth devices
- [ ] Add printers
### Third-party Services
- [ ] Firefox
- [ ] Authenticate
- [ ] Spotify
- [ ] Authenticate
- [ ] Local Files

168
hosts/elara/default.nix Normal file
View File

@@ -0,0 +1,168 @@
{
inputs,
lib,
pkgs,
...
}:
{
imports = [
../../lib
inputs.disko.nixosModules.disko
(import ./format.nix {
device = "/dev/disk/by-id/usb-SanDisk_Ultra_Trek_0501990ddf7236633373ea7dd2e6715f954e2dbb35cadae343333f0562cda6aa7ec80000000000000000000042c100baff1e08109f5581078ea6d9c3-0:0";
})
../common/system/configs/bluetooth
../common/system/configs/boot
../common/system/configs/brightnessctl
../common/system/configs/btop
../common/system/configs/btrfs
../common/system/configs/cpu
../common/system/configs/docker
../common/system/configs/fastfetch
../common/system/configs/getty
../common/system/configs/git
../common/system/configs/gpg-agent
../common/system/configs/impermanence
../common/system/configs/libvirt
../common/system/configs/lsof
../common/system/configs/ncdu
../common/system/configs/neovim
../common/system/configs/networking
../common/system/configs/nix
../common/system/configs/nix-cleanup
../common/system/configs/nix-ld
../common/system/configs/nixpkgs
../common/system/configs/ntp
../common/system/configs/pipewire
../common/system/configs/plymouth
../common/system/configs/powertop
../common/system/configs/printing
../common/system/configs/ranger
../common/system/configs/sops
../common/system/configs/ssh
../common/system/configs/system
../common/system/configs/timezone
../common/system/configs/tlp
../common/system/configs/tmux
../common/system/configs/tree
../common/system/configs/users
../common/system/configs/wget
../common/system/configs/zsh
./users/nikara
];
networking.hostName = "sas";
i18n.defaultLocale = "en_US.UTF-8";
sops.defaultSopsFile = ./secrets/secrets.yaml;
# https://github.com/NixOS/nixos-hardware/tree/master/lenovo/legion/16achg6
hardware = {
enableAllFirmware = true;
cpu = {
cores = 8;
threads = 16;
amd.updateMicrocode = true;
};
nvidia = {
modesetting.enable = true;
powerManagement.enable = true;
open = false;
prime = {
offload = {
enable = true;
enableOffloadCmd = true;
};
nvidiaBusId = "PCI:1:0:0";
amdgpuBusId = "PCI:6:0:0";
};
};
graphics = {
enable32Bit = true;
extraPackages = with pkgs; [
amdvlk
driversi686Linux.amdvlk
rocmPackages.clr
rocmPackages.clr.icd
];
};
};
boot = {
kernelParams = [
"amd_pstate=active"
"video=eDP-1:2560x1600@165"
];
kernelModules = [ "kvm-amd" ];
initrd.kernelModules = [
"nvme"
"ahci"
"usbhid"
"amdgpu"
"xhci_pci"
"usb_storage"
"sd_mod"
];
};
nixpkgs = {
hostPlatform = "x86_64-linux";
config = {
cudaSupport = true;
rocmSupport = true;
};
};
powerManagement.enable = true;
systemd.services.powertop.postStart = builtins.readFile ./system/scripts/mouse.sh;
services = {
xserver.videoDrivers = [ "nvidia" ];
fstrim.enable = true;
tlp.settings.DISK_DEVICES = "nvme0n1 nvme1n1";
};
home-manager.sharedModules = [
{
wayland.windowManager.hyprland.settings = {
monitor = "eDP-1, 2560x1600@165, 0x0, 1.25";
env = [ "WLR_DRM_DEVICES,$HOME/.config/hypr/card" ];
device = [
{
name = "syna2ba6:00-06cb:ce44-touchpad";
sensitivity = 0.5;
}
];
gestures.workspace_swipe_distance = 600;
};
programs = {
zsh.loginExtra = lib.mkBefore (builtins.readFile ./system/scripts/card.sh);
# VSCode does not play well with fractional scaling
vscode.userSettings."window.zoomLevel" = (1.25 - 1) / 0.2;
obs-studio.resolution = {
base = {
x = 4096;
y = 2560;
};
output = {
x = 2048;
y = 1280;
};
};
};
theme.cursor.size = 24;
}
];
}

74
hosts/elara/format.nix Normal file
View File

@@ -0,0 +1,74 @@
{
device ? throw "device argument is required",
...
}:
{
disko.devices = {
disk.main = {
inherit device;
type = "disk";
content = {
type = "gpt";
partitions = {
boot = {
name = "boot";
size = "1M";
type = "EF02";
};
esp = {
name = "esp";
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
root = {
name = "root";
size = "100%";
content = {
name = "luks";
type = "luks";
settings = {
allowDiscards = true;
};
content = {
type = "btrfs";
extraArgs = [ "-f" ];
subvolumes = {
"@" = {
mountpoint = "/";
};
"@persist" = {
mountpoint = "/persist";
mountOptions = [
"compress=zstd"
"noatime"
];
};
"@nix" = {
mountpoint = "/nix";
mountOptions = [
"compress=zstd"
"noatime"
];
};
"@cache" = {
mountpoint = "/cache";
mountOptions = [
"compress=zstd"
"noatime"
];
};
};
};
};
};
};
};
};
};
}

View File

@@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB2sVagJ2CqpitBK4izlfKWIe2n2xkfV95F0VNkAc3FD nick@eirene

View File

@@ -0,0 +1,10 @@
AMD=/dev/dri/by-path/pci-0000:06:00.0-card
NVIDIA=/dev/dri/by-path/pci-0000:01:00.0-card
if [[ -e "${AMD}" ]]; then
CARD=${AMD}
else
CARD=${NVIDIA}
fi
ln -sf "${CARD}" "${HOME}"/.config/hypr/card

View File

@@ -0,0 +1,14 @@
SEARCH_STRINGS=(
"Mouse"
"Razer DeathAdder Elite"
"Razer DeathAdder V3 HyperSpeed"
)
for search_string in "${SEARCH_STRINGS[@]}"; do
echo "Searching for devices matching: ${search_string}"
for f in $(grep -l "${search_string}" /sys/bus/usb/devices/*/product 2>/dev/null | sed "s/product/power\\/control/"); do
echo "Setting power control to 'on' for: ${f}"
echo on >| "${f}"
done
done

View File

@@ -0,0 +1,116 @@
{ config, lib, ... }:
let
# FIXME: https://github.com/NixOS/nixpkgs/issues/24570
# FIXME: https://github.com/NixOS/nixpkgs/issues/305643
user = "nikara";
home = "/home/nikara";
in
{
imports = [
../../../common/user/configs/options.nix
(import ../../../common/user/configs/console/bashmount { inherit user home; })
(import ../../../common/user/configs/console/bluetooth { inherit user home; })
(import ../../../common/user/configs/console/brightnessctl { inherit user home; })
(import ../../../common/user/configs/console/btop { inherit user home; })
(import ../../../common/user/configs/console/docker { inherit user home; })
(import ../../../common/user/configs/console/fastfetch { inherit user home; })
(import ../../../common/user/configs/console/git { inherit user home; })
(import ../../../common/user/configs/console/gpg-agent { inherit user home; })
(import ../../../common/user/configs/console/home-manager { inherit user home; })
(import ../../../common/user/configs/console/imagemagick { inherit user home; })
(import ../../../common/user/configs/console/libvirt { inherit user home; })
(import ../../../common/user/configs/console/ncdu { inherit user home; })
(import ../../../common/user/configs/console/neovim { inherit user home; })
(import ../../../common/user/configs/console/nix-develop { inherit user home; })
(import ../../../common/user/configs/console/nix-direnv { inherit user home; })
(import ../../../common/user/configs/console/nixpkgs { inherit user home; })
(import ../../../common/user/configs/console/pipewire { inherit user home; })
(import ../../../common/user/configs/console/ranger { inherit user home; })
(import ../../../common/user/configs/console/sops { inherit user home; })
(import ../../../common/user/configs/console/tmux { inherit user home; })
(import ../../../common/user/configs/console/tree { inherit user home; })
(import ../../../common/user/configs/console/wget { inherit user home; })
(import ../../../common/user/configs/console/xdg { inherit user home; })
(import ../../../common/user/configs/console/zsh { inherit user home; })
(import ../../../common/user/configs/gui/astal { inherit user home; })
(import ../../../common/user/configs/gui/bluetooth { inherit user home; })
(import ../../../common/user/configs/gui/brightnessctl { inherit user home; })
(import ../../../common/user/configs/gui/btop { inherit user home; })
(import ../../../common/user/configs/gui/chromium { inherit user home; })
(import ../../../common/user/configs/gui/cliphist { inherit user home; })
(import ../../../common/user/configs/gui/emoji { inherit user home; })
(import ../../../common/user/configs/gui/firefox { inherit user home; })
(import ../../../common/user/configs/gui/gtk { inherit user home; })
(import ../../../common/user/configs/gui/hyprland { inherit user home; })
(import ../../../common/user/configs/gui/hyprshot { inherit user home; })
(import ../../../common/user/configs/gui/kitty { inherit user home; })
(import ../../../common/user/configs/gui/libreoffice { inherit user home; })
(import ../../../common/user/configs/gui/networking { inherit user home; })
(import ../../../common/user/configs/gui/obs { inherit user home; })
(import ../../../common/user/configs/gui/obsidian { inherit user home; })
(import ../../../common/user/configs/gui/pipewire { inherit user home; })
(import ../../../common/user/configs/gui/qalculate { inherit user home; })
(import ../../../common/user/configs/gui/qt { inherit user home; })
(import ../../../common/user/configs/gui/rofi { inherit user home; })
(import ../../../common/user/configs/gui/spicetify { inherit user home; })
(import ../../../common/user/configs/gui/swww { inherit user home; })
(import ../../../common/user/configs/gui/theme { inherit user home; })
(import ../../../common/user/configs/gui/vscode { inherit user home; })
(import ../../../common/user/configs/gui/wev { inherit user home; })
(import ../../../common/user/configs/gui/x11 { inherit user home; })
(import ../../../common/user/configs/gui/xdg { inherit user home; })
(import ../../user/configs/console/globalprotect-remote-connect { inherit user home; })
];
# echo "password" | mkpasswd -s
sops.secrets."${user}-password" = {
sopsFile = ../../../../secrets/sas/secrets.yaml;
key = "password";
neededForUsers = true;
};
users.users.${user} = {
inherit home;
isNormalUser = true;
email = "Nick.Karaolidis@sas.com";
fullName = "Nick Karaolidis";
description = "Nick Karaolidis";
hashedPasswordFile = config.sops.secrets."${user}-password".path;
extraGroups = [ "wheel" ];
linger = true;
uid = lib.strings.toInt (builtins.readFile ./uid);
};
services.getty.autologinUser = user;
home-manager.users.${user} = {
home = {
username = user;
homeDirectory = home;
};
sops.secrets = {
# Personal
"git/credentials" = {
sopsFile = ../../../../secrets/personal/secrets.yaml;
path = "${home}/.config/git/credentials";
};
"git/cookies" = {
sopsFile = ../../../../secrets/personal/secrets.yaml;
path = "${home}/.config/git/cookies";
};
"gpg-agent/personal/key".sopsFile = ../../../../secrets/personal/secrets.yaml;
"gpg-agent/personal/pass".sopsFile = ../../../../secrets/personal/secrets.yaml;
# SAS
"globalprotect/server".sopsFile = ../../../../secrets/sas/secrets.yaml;
"globalprotect/email".sopsFile = ../../../../secrets/sas/secrets.yaml;
"globalprotect/password".sopsFile = ../../../../secrets/sas/secrets.yaml;
"globalprotect/gateway".sopsFile = ../../../../secrets/sas/secrets.yaml;
};
theme.wallpaper = ../../../../static/wallpapers/clouds.png;
programs.obsidian.vaults."Documents/Obsidian/master".enable = true;
};
}

View File

@@ -0,0 +1 @@
1000

View File

@@ -1,5 +1,9 @@
#!/usr/bin/env bash
set -o errexit
set -o nounset
set -o pipefail
if [[ "$#" -ne 2 ]]; then
echo "Usage: $0 <host> <sops-master-key>"
exit 1

View File

@@ -1,23 +0,0 @@
#!/usr/bin/env bash
if [[ "$#" -ne 2 ]]; then
echo "Usage: $0 <user> <sops-master-key>"
exit 1
fi
USER="$1"
mkdir -p "./users/${USER}/secrets"
nix shell nixpkgs#age --command age-keygen -o "./users/${USER}/secrets/key.txt"
AGE_KEY=$(grep "^# public key: " "./users/${USER}/secrets/key.txt" | sed "s/# public key: //")
for SOPS_FILE in $(find . -type f -name "sops.yaml"); do
sed -i "/- users:/a\ - &${USER} ${AGE_KEY}" "${SOPS_FILE}"
sed -i "/- age:/a\ - *${USER}" "${SOPS_FILE}"
done
"$(dirname "$0")/update-keys.sh" "$2"
echo "User ${USER} has been successfully added."

View File

@@ -1,5 +1,9 @@
#!/usr/bin/env bash
set -o errexit
set -o nounset
set -o pipefail
check_root() {
if [[ "${EUID}" -ne 0 ]]; then
echo "Please run the script as root."
@@ -8,6 +12,8 @@ check_root() {
}
check_network() {
rfkill unblock all
if ping -c 1 google.com &>/dev/null; then
echo "Network connection detected, skipping Wi-Fi setup."
return
@@ -33,16 +39,15 @@ setup_wifi() {
echo "Enter the network interface you want to use:"
read -r interface
echo "Enter the SSID of the open network:"
read -r ssid
echo "Do you want to connect to an open network? [y/N]"
read -r open_network
if [[ "${open_network}" =~ ^([yY][eE][sS]|[yY])$ ]]; then
echo "Enter the SSID of the open network:"
read -r ssid
wpa_supplicant -i "${interface}" -c <(wpa_passphrase "${ssid}") -B
else
echo "Enter the SSID:"
read -r ssid
echo "Enter the passphrase:"
read -rs passphrase
@@ -52,24 +57,30 @@ setup_wifi() {
fi
dhcpcd
echo "Waiting for a network connection..."
for i in {1..10}; do
if ping -c 1 google.com &>/dev/null; then
echo "Connected to the network successfully."
return
fi
sleep 1
done
echo "Failed to establish a connection within the timeout period."
exit 1
}
select_host() {
echo "Available hosts:"
echo $(nix --experimental-features "nix-command flakes" flake show --json | nix --experimental-features "nix-command flakes" shell nixpkgs#jq --command jq -r '.nixosConfigurations | keys[]')
echo $(nix --experimental-features "nix-command flakes" flake show --json |
nix --experimental-features "nix-command flakes" shell nixpkgs#jq --command jq -r '.nixosConfigurations | keys[]')
echo "Enter host:"
read -r host
}
select_users() {
echo "Available users:"
ls users/
echo "Enter the users to copy keys for (space-separated):"
read -r -a users
}
prepare_disk() {
local mode="$1"
device=$(grep -oP '(?<=device = ")[^"]+' "./hosts/${host}/default.nix")
@@ -80,11 +91,25 @@ copy_keys() {
mkdir -p /mnt/persist/etc/ssh
cp "./hosts/${host}/secrets/ssh_host_ed25519_key" /mnt/persist/etc/ssh/ssh_host_ed25519_key
for user in "${users[@]}"; do
mkdir -p "/mnt/persist/home/${user}/.config/sops-nix"
cp "./users/${user}/secrets/key.txt" "/mnt/persist/home/${user}/.config/sops-nix/key.txt"
for path in "./hosts/${host}/users"/*; do
user=$(basename "${path}")
echo "User detected: ${user}"
uid=$(cat "./users/${user}/uid")
echo "Available keys for ${user}:"
ls ./secrets/*/key.txt
echo "Enter the key file to copy (or press Enter to skip this user):"
read -r key
if [[ -z "${key}" ]]; then
echo "Skipping ${user}"
continue
fi
mkdir -p "/mnt/persist/home/${user}/.config/sops-nix"
cp "${key}" "/mnt/persist/home/${user}/.config/sops-nix/key.txt"
uid=$(cat "./hosts/${host}/users/${user}/uid")
gid=100
chown -R "${uid}:${gid}" "/mnt/persist/home/${user}"
@@ -107,7 +132,6 @@ main() {
case ${choice} in
1)
select_users
prepare_disk "disko"
copy_keys
install

View File

@@ -1,5 +1,9 @@
#!/usr/bin/env bash
set -o errexit
set -o nounset
set -o pipefail
if [[ "$#" -ne 2 ]]; then
echo "Usage: $0 <host> <sops-master-key>"
exit 1

View File

@@ -1,21 +0,0 @@
#!/usr/bin/env bash
if [[ "$#" -ne 2 ]]; then
echo "Usage: $0 <user> <sops-master-key>"
exit 1
fi
USER="$1"
AGE_KEY=$(grep "^# public key: " "./users/${USER}/secrets/key.txt" | sed "s/# public key: //")
for SOPS_FILE in $(find . -type f -name "sops.yaml"); do
sed -i "/ - &${USER} ${AGE_KEY}/d" "${SOPS_FILE}"
sed -i "/ - \*${USER}/d" "${SOPS_FILE}"
done
"$(dirname "$0")/update-keys.sh" "$2"
rm -rf ./users/"${USER}"
echo "User ${USER} has been successfully removed."

View File

@@ -1,5 +1,9 @@
#!/usr/bin/env bash
set -o errexit
set -o nounset
set -o pipefail
if [[ "$#" -ne 1 ]]; then
echo "Usage: $0 <sops-master-key>"
exit 1

View File

@@ -1,5 +1,9 @@
#!/usr/bin/env bash
set -o errexit
set -o nounset
set -o pipefail
paths=$(git config --file .gitmodules --name-only --get-regexp path | while read -r line; do
path=$(git config --file .gitmodules --get "${line}")
url=$(git config --file .gitmodules --get "${line%.*}.url")

1
secrets/.gitignore vendored Normal file
View File

@@ -0,0 +1 @@
*/key.txt