initial commit
This commit is contained in:
commit
733dce18a0
11 changed files with 295 additions and 0 deletions
57
common.nix
Normal file
57
common.nix
Normal file
|
|
@ -0,0 +1,57 @@
|
|||
{ config, lib, pkgs, ... }:
|
||||
{
|
||||
nix.settings.experimental-features = [ "nix-command" "flakes" ];
|
||||
system.stateVersion = "26.05";
|
||||
time.timeZone = "Asia/Chita";
|
||||
i18n.defaultLocale = "ru_RU.UTF-8";
|
||||
console = {
|
||||
keyMap = "ruwin_alt_sh-UTF-8";
|
||||
font = "cyr-sun16";
|
||||
};
|
||||
fileSystems = {
|
||||
"/" = { options = [ "noatime" ]; };
|
||||
"/boot" = { options = [ "noatime" ]; };
|
||||
};
|
||||
swapDevices = [ { device = "/var/swapfile"; } ];
|
||||
boot.loader.limine = {
|
||||
enable = true;
|
||||
secureBoot.enable = true;
|
||||
};
|
||||
users.users = {
|
||||
root = {
|
||||
home = "/root";
|
||||
hashedPasswordFile = "/root/secrets/root.passwd";
|
||||
};
|
||||
bogale = {
|
||||
isNormalUser = true;
|
||||
home = "/home/bogale";
|
||||
extraGroups = [ "wheel" ];
|
||||
hashedPasswordFile = "/root/secrets/bogale.passwd";
|
||||
};
|
||||
};
|
||||
networking = {
|
||||
nftables.enable = true;
|
||||
#networking.wg-quick.interfaces.awg0 = {
|
||||
#type = "amneziawg";
|
||||
#configFile = "/root/secrets/awg0.conf";
|
||||
#};
|
||||
networkmanager = {
|
||||
enable = true;
|
||||
ensureProfiles.profiles.home-wifi = {
|
||||
wifi-security.key-mgmt = "sae";
|
||||
connection = {
|
||||
id = "home-wifi";
|
||||
type = "wifi";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
environment.systemPackages = with pkgs; [
|
||||
amneziawg-go
|
||||
amneziawg-tools
|
||||
sbctl
|
||||
];
|
||||
services = {
|
||||
logind.settings.Login.HandleLidSwitch = "ignore";
|
||||
};
|
||||
}
|
||||
6
home/bogale.nix
Normal file
6
home/bogale.nix
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
{ config, pkgs, ... }:
|
||||
{
|
||||
imports = [ ./common.nix ];
|
||||
home.username = "bogale";
|
||||
home.homeDirectory = "/home/bogale";
|
||||
}
|
||||
58
home/common.nix
Normal file
58
home/common.nix
Normal file
|
|
@ -0,0 +1,58 @@
|
|||
{ config, pkgs, ... }:
|
||||
{
|
||||
home.stateVersion = "26.05";
|
||||
programs = {
|
||||
home-manager.enable = true;
|
||||
bash = {
|
||||
enable = true;
|
||||
historyControl = [ "ignoreboth" ];
|
||||
shellAliases = { la = "ls -lAtr"; };
|
||||
};
|
||||
git = {
|
||||
enable = true;
|
||||
settings = {
|
||||
init.defaultbranch = "main";
|
||||
user = {
|
||||
name = "bogale";
|
||||
email = "git@bogaledev.ru";
|
||||
};
|
||||
};
|
||||
};
|
||||
neovim = {
|
||||
enable = true;
|
||||
defaultEditor = true;
|
||||
extraConfig = ''
|
||||
set tabstop=4
|
||||
set shiftwidth=4
|
||||
set expandtab
|
||||
set number
|
||||
set relativenumber
|
||||
autocmd FileType nix set tabstop=2 shiftwidth=2
|
||||
'';
|
||||
};
|
||||
tmux = {
|
||||
enable = true;
|
||||
clock24 = true;
|
||||
keyMode = "vi";
|
||||
escapeTime = 0;
|
||||
terminal = "screen-256color";
|
||||
extraConfig = ''
|
||||
unbind C-b
|
||||
set -g mouse on
|
||||
set -g prefix M-d
|
||||
set -g prefix M-f
|
||||
set-option -g focus-events on
|
||||
set -s set-clipboard external
|
||||
set-option -a terminal-features "xterm-256color:RGB"
|
||||
bind f send-prefix
|
||||
bind d send-prefix
|
||||
bind h select-pane -L
|
||||
bind j select-pane -D
|
||||
bind k select-pane -U
|
||||
bind l select-pane -R
|
||||
bind u split-window -h
|
||||
bind i split-window -v
|
||||
'';
|
||||
};
|
||||
};
|
||||
}
|
||||
6
home/root.nix
Normal file
6
home/root.nix
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
{ config, pkgs, ... }:
|
||||
{
|
||||
imports = [ ./common.nix ];
|
||||
home.username = "root";
|
||||
home.homeDirectory = "/root";
|
||||
}
|
||||
4
home/server/bogale.nix
Normal file
4
home/server/bogale.nix
Normal file
|
|
@ -0,0 +1,4 @@
|
|||
{ config, pkgs, ... }:
|
||||
{
|
||||
imports = [ ../bogale.nix ];
|
||||
}
|
||||
7
home/server/root.nix
Normal file
7
home/server/root.nix
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
{ config, pkgs, ... }:
|
||||
{
|
||||
imports = [ ../root.nix ];
|
||||
programs.bash = {
|
||||
shellAliases = { "nixos-rebuild" = "nixos-rebuild --impure --flake /etc/nixos/server#nixos-server"; };
|
||||
};
|
||||
}
|
||||
15
marks
Normal file
15
marks
Normal file
|
|
@ -0,0 +1,15 @@
|
|||
installation:
|
||||
secure erase / sanitize
|
||||
gdisk
|
||||
cryptsetup
|
||||
mkfs
|
||||
mount
|
||||
copy private files
|
||||
mkswap -s $SIZE -F /mnt/var/swapfile
|
||||
swapon /mnt/var/swapfile
|
||||
sbctl enroll-keys --yes-this-might-brick-my-machine
|
||||
nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd
|
||||
systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 <LUKS_DEV>
|
||||
|
||||
todo:
|
||||
- lanzaboote
|
||||
36
server/configuration.nix
Normal file
36
server/configuration.nix
Normal file
|
|
@ -0,0 +1,36 @@
|
|||
{ config, lib, pkgs, ... }:
|
||||
{
|
||||
imports = [ ../common.nix ./hardware-configuration.nix ];
|
||||
boot.kernelParams = [ "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ];
|
||||
networking = {
|
||||
hostName = "nixos-server";
|
||||
networkmanager.ensureProfiles.profiles.home-wifi = {
|
||||
wifi.ssid = "bogale_2.4";
|
||||
wifi-security.psk = builtins.readFile "/root/secrets/home-wifi.psk";
|
||||
};
|
||||
firewall = {
|
||||
allowedTCPPorts = [ 80 ];
|
||||
extraInputRules = ''
|
||||
ip saddr 192.168.1.0/24 tcp dport 22 accept
|
||||
'';
|
||||
};
|
||||
};
|
||||
services = {
|
||||
openssh = {
|
||||
enable = true;
|
||||
openFirewall = false;
|
||||
};
|
||||
nginx = {
|
||||
enable = true;
|
||||
virtualHosts."_".default = true;
|
||||
virtualHosts."_" = {
|
||||
locations."/" = {
|
||||
return = "200 '<html><body>It works</body></html>'";
|
||||
extraConfig = ''
|
||||
default_type text/html;
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
49
server/flake.lock
generated
Normal file
49
server/flake.lock
generated
Normal file
|
|
@ -0,0 +1,49 @@
|
|||
{
|
||||
"nodes": {
|
||||
"home-manager": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1789267039,
|
||||
"narHash": "sha256-LWiBv9yAYFi2LPbUhDGHPGKYskJQjj2fw12OlyO1uQo=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "ec172013fa62135f58fb58dd17ae9651e8f39727",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-community",
|
||||
"ref": "release-26.05",
|
||||
"repo": "home-manager",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1789459628,
|
||||
"narHash": "sha256-JOaadoI/IC9qEvwlnjwAhwdcWkCDqEeOJ+cOtUH/8RQ=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "b67c7a60c3732edd4b947a7df8af06215851a614",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixos-26.05",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"root": {
|
||||
"inputs": {
|
||||
"home-manager": "home-manager",
|
||||
"nixpkgs": "nixpkgs"
|
||||
}
|
||||
}
|
||||
},
|
||||
"root": "root",
|
||||
"version": 7
|
||||
}
|
||||
24
server/flake.nix
Normal file
24
server/flake.nix
Normal file
|
|
@ -0,0 +1,24 @@
|
|||
{
|
||||
inputs = {
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
|
||||
home-manager = {
|
||||
url = "github:nix-community/home-manager/release-26.05";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
};
|
||||
outputs = inputs@{ self, nixpkgs, home-manager, ... }: {
|
||||
nixosConfigurations.nixos-server = nixpkgs.lib.nixosSystem {
|
||||
modules = [
|
||||
./configuration.nix
|
||||
home-manager.nixosModules.home-manager
|
||||
{
|
||||
home-manager.useGlobalPkgs = true;
|
||||
home-manager.useUserPackages = true;
|
||||
home-manager.extraSpecialArgs = { inherit inputs; };
|
||||
home-manager.users.root = ../home/server/root.nix;
|
||||
home-manager.users.bogale = ../home/server/bogale.nix;
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
}
|
||||
33
server/hardware-configuration.nix
Normal file
33
server/hardware-configuration.nix
Normal file
|
|
@ -0,0 +1,33 @@
|
|||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{ config, lib, pkgs, modulesPath, ... }:
|
||||
|
||||
{
|
||||
imports =
|
||||
[ (modulesPath + "/installer/scan/not-detected.nix")
|
||||
];
|
||||
|
||||
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "ehci_pci" "sd_mod" "sdhci_pci" ];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
fileSystems."/" =
|
||||
{ device = "/dev/mapper/root";
|
||||
fsType = "ext4";
|
||||
};
|
||||
|
||||
boot.initrd.luks.devices."root".device = "/dev/disk/by-uuid/e0288e5e-87eb-453f-ab22-0d6e54576609";
|
||||
|
||||
fileSystems."/boot" =
|
||||
{ device = "/dev/disk/by-uuid/86F4-A8F1";
|
||||
fsType = "vfat";
|
||||
options = [ "fmask=0077" "dmask=0077" ];
|
||||
};
|
||||
|
||||
swapDevices = [ ];
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue