diff --git a/.gitignore b/.gitignore index b52b1c1..2f8c505 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1,3 @@ -home/private.nix +# nixos-rebuild build / nix build output symlinks +result +result-* diff --git a/flake.lock b/flake.lock new file mode 100644 index 0000000..1c63d42 --- /dev/null +++ b/flake.lock @@ -0,0 +1,49 @@ +{ + "nodes": { + "home-manager": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1789267039, + "narHash": "sha256-LWiBv9yAYFi2LPbUhDGHPGKYskJQjj2fw12OlyO1uQo=", + "owner": "nix-community", + "repo": "home-manager", + "rev": "ec172013fa62135f58fb58dd17ae9651e8f39727", + "type": "github" + }, + "original": { + "owner": "nix-community", + "ref": "release-26.05", + "repo": "home-manager", + "type": "github" + } + }, + "nixpkgs": { + "locked": { + "lastModified": 1789749394, + "narHash": "sha256-cFTsMQz8Hzn8MT49oaeLSHg62tE86NykugCWkeM2ypk=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "cf9d2fb3e50fa1cd5114c47505ea9177f7ff5f49", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-26.05", + "repo": "nixpkgs", + "type": "github" + } + }, + "root": { + "inputs": { + "home-manager": "home-manager", + "nixpkgs": "nixpkgs" + } + } + }, + "root": "root", + "version": 7 +} diff --git a/flake.nix b/flake.nix new file mode 100644 index 0000000..ad4e03e --- /dev/null +++ b/flake.nix @@ -0,0 +1,37 @@ +{ + description = "shihaam's NixOS + home-manager configuration"; + + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05"; + + home-manager = { + url = "github:nix-community/home-manager/release-26.05"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + }; + + outputs = { self, nixpkgs, home-manager, ... }: { + nixosConfigurations.la2410 = nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + + modules = [ + ./hosts/la2410/configuration.nix + + home-manager.nixosModules.home-manager + { + home-manager = { + useGlobalPkgs = true; + useUserPackages = true; + backupFileExtension = "hm-bak"; + users.shihaam = import ./home/shihaam.nix; + }; + } + + { + nix.registry.nixpkgs.flake = nixpkgs; + nix.nixPath = [ "nixpkgs=${nixpkgs}" ]; + } + ]; + }; + }; +} diff --git a/home/bash.nix b/home/bash.nix index b9bd867..74816d0 100644 --- a/home/bash.nix +++ b/home/bash.nix @@ -59,6 +59,10 @@ in source "$(blesh-share)/ble.sh" # ---- prompt -------------------------------------------------------- source ${bash-seafly-prompt}/command_prompt.bash + + # ---- machine-local non-public env -------------------------------------- + [ -r "$HOME/.config/private-env" ] && source "$HOME/.config/private-env" + # needed for gpg-sign export GPG_TTY=$(tty) diff --git a/home/nano.nix b/home/nano.nix new file mode 100644 index 0000000..22afae9 --- /dev/null +++ b/home/nano.nix @@ -0,0 +1,21 @@ +{ ... }: + +{ + xdg.configFile."nano/nanorc".text = '' + set autoindent + set linenumbers + #set smooth + + set backup + set backupdir "~/.cache/nano" + + set titlecolor brightblue,black + set statuscolor brightgreen,blue + set selectedcolor brightwhite,magenta + set numbercolor yellow + set keycolor brightcyan + set functioncolor green + set nohelp + ''; + home.file.".cache/nano/.keep".text = ""; +} diff --git a/home/private.nix.example b/home/private.nix.example deleted file mode 100644 index f623554..0000000 --- a/home/private.nix.example +++ /dev/null @@ -1,11 +0,0 @@ -# Template. Copy to private.nix and fill in; private.nix is gitignored. -# -# cp home/private.nix.example home/private.nix -# -{ config, ... }: - -{ - home.sessionVariables = { - # HELLO=WORLD - }; -} diff --git a/home/shihaam.nix b/home/shihaam.nix index fd1c38d..58b2268 100644 --- a/home/shihaam.nix +++ b/home/shihaam.nix @@ -1,4 +1,4 @@ -# Imported from /etc/nixos/configuration.nix +# Entry point for the shihaam home-manager profile (see flake.nix). { config, pkgs, lib, ... }: { @@ -6,12 +6,8 @@ ./bash.nix ./packages.nix ./fonts.nix - ] ++ ( - # import non public vars - if builtins.pathExists ./private.nix - then [ ./private.nix ] - else lib.warn "home/private.nix not found -- private session variables will be unset" [ ] - ); + ./nano.nix + ]; home.username = "shihaam"; home.homeDirectory = "/home/shihaam"; diff --git a/hosts/la2410/configuration.nix b/hosts/la2410/configuration.nix new file mode 100644 index 0000000..2741883 --- /dev/null +++ b/hosts/la2410/configuration.nix @@ -0,0 +1,293 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page +# and in the NixOS manual (accessible by running ‘nixos-help’). + +{ config, pkgs, lib, ... }: + +{ + imports = + [ # Include the results of the hardware scan. + ./hardware-configuration.nix + ]; + +# Bootloader. +boot.loader = { +# efi.canTouchEfiVariables = true; + grub = { + efiInstallAsRemovable = true; + enable = true; + device = "nodev"; + efiSupport = true; + }; +}; +boot.kernelModules = [ "rfcomm" "i2c-dev" ]; +boot.kernel.sysctl."net.ipv4.ip_unprivileged_port_start" = "80"; +hardware.bluetooth = { + enable = true; + powerOnBoot = true; + settings = { + General = { + # Shows battery charge of connected devices on supported + # Bluetooth adapters. Defaults to 'false'. + Experimental = true; + # When enabled other devices can connect faster to us, however + # the tradeoff is increased power consumption. Defaults to + # 'false'. + FastConnectable = true; + }; + Policy = { + # Enable all controllers when they are found. This includes + # adapters present on start as well as adapters that are plugged + # in later on. Defaults to 'true'. + AutoEnable = true; + }; + }; +}; + +services.blueman.enable = true; + networking.hostName = "la2410"; # Define your hostname. +# networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. + + # Configure network proxy if necessary + # networking.proxy.default = "http://user:password@proxy:port/"; + # networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain"; + + # Enable networking + networking.networkmanager.enable = true; + networking.networkmanager.plugins = with pkgs; [ networkmanager-openvpn ]; + networking.networkmanager.dns = "default"; + services.resolved.enable = false; + networking.extraHosts = + '' +10.0.1.2 dns01.sarlink.net +10.0.1.22 piped.shihaam.me pipedapi.shihaam.me pipedproxy.shihaam.me typetype.shihaam.me +10.0.1.3 mapmaker.sarlink.net +10.0.1.16 git.shihaam.dev + ''; + +nixpkgs.config.allowUnfree = true; +nix.settings.experimental-features = [ "nix-command" "flakes" ]; + +virtualisation.docker.rootless = { + enable = true; + setSocketVariable = true; + daemon.settings = { + "insecure-registries" = [ "git.shihaam.dev" ]; + }; +}; +virtualisation = { + containers.enable = true; + podman = { + enable = true; + dockerCompat = false; + defaultNetwork.settings.dns_enabled = false; # Required for containers under podman-compose to be able to talk to each other. + }; +}; + +#security.pam.services.login.kwallet.enable = true; +#programs.kdeconnect.enable = true; +#services.dbus.packages = [ pkgs.kwallet ]; +services.gnome.gnome-keyring.enable = true; + # Set your time zone. + time.timeZone = "Indian/Maldives"; + + # Select internationalisation properties. + i18n.defaultLocale = "en_US.UTF-8"; + + i18n.extraLocaleSettings = { +# LC_ADDRESS = "dv_MV"; +# LC_IDENTIFICATION = "dv_MV"; +# LC_MEASUREMENT = "dv_MV"; +# LC_MONETARY = "dv_MV"; +# LC_NAME = "dv_MV"; +# LC_NUMERIC = "dv_MV"; +# LC_PAPER = "dv_MV"; +# LC_TELEPHONE = "dv_MV"; +# LC_TIME = "dv_MV"; +LC_ALL = "en_US.UTF-8"; + }; + + # Configure keymap in X11 + services.xserver.xkb = { + layout = "us"; + variant = ""; + }; + + # Define a user account. Don't forget to set a password with ‘passwd’. + users.users.shihaam = { + isNormalUser = true; + description = "shihaam"; + extraGroups = [ "adbusers" "networkmanager" "wheel" "podman" "dialout" "wireshark" "i2c" ]; + packages = with pkgs; []; + }; +nix.settings.trusted-users = [ "shihaam" ]; +hardware.i2c.enable = true; +# programs.adb.enable = true; + + # List packages installed in system profile. To search, run: + # $ nix search wget + environment.systemPackages = with pkgs; [ + pkgs.devenv + pkgs.jdk25 + steam-run + nmap + openssl +# blesh +# wireshark + picocom + minicom + tio +# direnv + android-tools + traceroute + usbutils + apktool + file + tesseract + vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default. + wget + jq + wl-clipboard + swappy +# firefox + pavucontrol + rofi + networkmanagerapplet + libsecret + oath-toolkit + git + slurp +# fastfetch + btop + htop +# brave +# vlc +# obs-studio +# claude-code + cmatrix + speedtest-cli + android-studio + gnupg + pinentry-curses + imagemagick + tree + unzip + zip +# codex + ncdu + bc +# httptoolkit +# libreoffice +# opencode +# lmstudio + wdisplays + scrcpy +# opentofu +# anydesk + python3 + ffmpeg +# jre +# feh + dig +# mpv +# _64gram + davfs2 + arch-install-scripts +# glab + ddcui + ddcutil + ]; + +nixpkgs.config.android_sdk.accept_license = true; +programs.nix-ld.enable = true; + + +# Nix reads flakes out of git via libgit2, which refuses a repository owned +# by a different user than the one evaluating it. The flake lives in +# /home/shihaam but `doas nixos-rebuild` evaluates as root, so root has to be +# told this repo is trustworthy. Without it: +# error: repository path '...' is not owned by current user +environment.etc."gitconfig".text = '' + [safe] + directory = /home/shihaam/git/sargit/dotfiles +''; + +security.doas.enable = true; +security.doas.extraRules = [ + { + users = ["shihaam"]; + noPass = true; + keepEnv = true; + } +]; + + programs.sway = { + enable = true; + wrapperFeatures.gtk = true; +# extraPackages = with pkgs; [ +# swaylock +# swayidle +# swaybg +# grim +# ]; + }; + programs.waybar.enable = true; +programs.xfconf.enable = true; + +services.pipewire = { +enable = true; +alsa.enable = true; +alsa.support32Bit = true; +pulse.enable = true; +}; + + +services.displayManager.ly = { + enable = true; + settings = { +# auto_login_user = "shihaam"; +# auto_login_session = "sway"; +# auto_login_service = "ly-autologin"; + animation = "matrix"; + bigclock = "en"; + asterisk = null; + battery_id = "BAT0"; + brightness_up_cmd = "${pkgs.brightnessctl}/bin/brightnessctl -q -n s +10%"; + brightness_down_cmd = "${pkgs.brightnessctl}/bin/brightnessctl -q -n s 10%-"; + }; +}; +#boot.kernelModules = [ "i2c-dev" ]; +#hardware.i2c.enable = true; + +#environment.sessionVariables = { +# PATH = "/home/shihaam/.local/bin:$PATH"; +#}; +# Some programs need SUID wrappers, can be configured further or are + # started in user sessions. + # programs.mtr.enable = true; + # programs.gnupg.agent = { + # enable = true; + # enableSSHSupport = true; + # }; + + # List services that you want to enable: + + # Enable the OpenSSH daemon. + services.openssh.enable = true; + + # Open ports in the firewall. + # 5173 = Vite dev server, 8000 = Django backend (sarlinkportal LAN access) + networking.firewall.allowedTCPPorts = [ 5173 8000 80 ]; + # networking.firewall.allowedUDPPorts = [ ... ]; + # Or disable the firewall altogether. + # networking.firewall.enable = false; + + # This value determines the NixOS release from which the default + # settings for stateful data, like file locations and database versions + # on your system were taken. It‘s perfectly fine and recommended to leave + # this value at the release version of the first install of this system. + # Before changing this value read the documentation for this option + # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). + system.stateVersion = "25.11"; # Did you read the comment? +} + diff --git a/hosts/la2410/hardware-configuration.nix b/hosts/la2410/hardware-configuration.nix new file mode 100644 index 0000000..4df90ec --- /dev/null +++ b/hosts/la2410/hardware-configuration.nix @@ -0,0 +1,39 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ "xhci_pci" "thunderbolt" "nvme" "usbhid" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/mapper/luks-f1f87ec2-2936-42d7-8868-df9809a94bdd"; + fsType = "btrfs"; + options = [ "subvol=@" ]; + }; + + boot.initrd.luks.devices."luks-f1f87ec2-2936-42d7-8868-df9809a94bdd".device = "/dev/disk/by-uuid/f1f87ec2-2936-42d7-8868-df9809a94bdd"; + + fileSystems."/boot" = + { device = "/dev/disk/by-uuid/4704-5F49"; + fsType = "vfat"; + options = [ "fmask=0077" "dmask=0077" ]; + }; + + fileSystems."/home/shihaam" = + { device = "/dev/disk/by-uuid/7725ca8d-07cf-46b1-a025-efc7210a4a75"; + fsType = "btrfs"; + }; + + swapDevices = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +}