From 733dce18a0e3e0ae92b4d841aa93d64702c2374d Mon Sep 17 00:00:00 2001 From: bogale Date: Thu, 17 Sep 2026 00:21:44 +0900 Subject: [PATCH] initial commit --- common.nix | 57 ++++++++++++++++++++++++++++++ home/bogale.nix | 6 ++++ home/common.nix | 58 +++++++++++++++++++++++++++++++ home/root.nix | 6 ++++ home/server/bogale.nix | 4 +++ home/server/root.nix | 7 ++++ marks | 15 ++++++++ server/configuration.nix | 36 +++++++++++++++++++ server/flake.lock | 49 ++++++++++++++++++++++++++ server/flake.nix | 24 +++++++++++++ server/hardware-configuration.nix | 33 ++++++++++++++++++ 11 files changed, 295 insertions(+) create mode 100644 common.nix create mode 100644 home/bogale.nix create mode 100644 home/common.nix create mode 100644 home/root.nix create mode 100644 home/server/bogale.nix create mode 100644 home/server/root.nix create mode 100644 marks create mode 100644 server/configuration.nix create mode 100644 server/flake.lock create mode 100644 server/flake.nix create mode 100644 server/hardware-configuration.nix diff --git a/common.nix b/common.nix new file mode 100644 index 0000000..759a349 --- /dev/null +++ b/common.nix @@ -0,0 +1,57 @@ +{ config, lib, pkgs, ... }: +{ + nix.settings.experimental-features = [ "nix-command" "flakes" ]; + system.stateVersion = "26.05"; + time.timeZone = "Asia/Chita"; + i18n.defaultLocale = "ru_RU.UTF-8"; + console = { + keyMap = "ruwin_alt_sh-UTF-8"; + font = "cyr-sun16"; + }; + fileSystems = { + "/" = { options = [ "noatime" ]; }; + "/boot" = { options = [ "noatime" ]; }; + }; + swapDevices = [ { device = "/var/swapfile"; } ]; + boot.loader.limine = { + enable = true; + secureBoot.enable = true; + }; + users.users = { + root = { + home = "/root"; + hashedPasswordFile = "/root/secrets/root.passwd"; + }; + bogale = { + isNormalUser = true; + home = "/home/bogale"; + extraGroups = [ "wheel" ]; + hashedPasswordFile = "/root/secrets/bogale.passwd"; + }; + }; + networking = { + nftables.enable = true; + #networking.wg-quick.interfaces.awg0 = { + #type = "amneziawg"; + #configFile = "/root/secrets/awg0.conf"; + #}; + networkmanager = { + enable = true; + ensureProfiles.profiles.home-wifi = { + wifi-security.key-mgmt = "sae"; + connection = { + id = "home-wifi"; + type = "wifi"; + }; + }; + }; + }; + environment.systemPackages = with pkgs; [ + amneziawg-go + amneziawg-tools + sbctl + ]; + services = { + logind.settings.Login.HandleLidSwitch = "ignore"; + }; +} diff --git a/home/bogale.nix b/home/bogale.nix new file mode 100644 index 0000000..372df57 --- /dev/null +++ b/home/bogale.nix @@ -0,0 +1,6 @@ +{ config, pkgs, ... }: +{ + imports = [ ./common.nix ]; + home.username = "bogale"; + home.homeDirectory = "/home/bogale"; +} diff --git a/home/common.nix b/home/common.nix new file mode 100644 index 0000000..b789ab6 --- /dev/null +++ b/home/common.nix @@ -0,0 +1,58 @@ +{ config, pkgs, ... }: +{ + home.stateVersion = "26.05"; + programs = { + home-manager.enable = true; + bash = { + enable = true; + historyControl = [ "ignoreboth" ]; + shellAliases = { la = "ls -lAtr"; }; + }; + git = { + enable = true; + settings = { + init.defaultbranch = "main"; + user = { + name = "bogale"; + email = "git@bogaledev.ru"; + }; + }; + }; + neovim = { + enable = true; + defaultEditor = true; + extraConfig = '' + set tabstop=4 + set shiftwidth=4 + set expandtab + set number + set relativenumber + autocmd FileType nix set tabstop=2 shiftwidth=2 + ''; + }; + tmux = { + enable = true; + clock24 = true; + keyMode = "vi"; + escapeTime = 0; + terminal = "screen-256color"; + extraConfig = '' + unbind C-b + set -g mouse on + set -g prefix M-d + set -g prefix M-f + set-option -g focus-events on + set -s set-clipboard external + set-option -a terminal-features "xterm-256color:RGB" + bind f send-prefix + bind d send-prefix + bind h select-pane -L + bind j select-pane -D + bind k select-pane -U + bind l select-pane -R + bind u split-window -h + bind i split-window -v + ''; + }; + }; +} diff --git a/home/root.nix b/home/root.nix new file mode 100644 index 0000000..ae559a9 --- /dev/null +++ b/home/root.nix @@ -0,0 +1,6 @@ +{ config, pkgs, ... }: +{ + imports = [ ./common.nix ]; + home.username = "root"; + home.homeDirectory = "/root"; +} diff --git a/home/server/bogale.nix b/home/server/bogale.nix new file mode 100644 index 0000000..f6bd6f1 --- /dev/null +++ b/home/server/bogale.nix @@ -0,0 +1,4 @@ +{ config, pkgs, ... }: +{ + imports = [ ../bogale.nix ]; +} diff --git a/home/server/root.nix b/home/server/root.nix new file mode 100644 index 0000000..8998624 --- /dev/null +++ b/home/server/root.nix @@ -0,0 +1,7 @@ +{ config, pkgs, ... }: +{ + imports = [ ../root.nix ]; + programs.bash = { + shellAliases = { "nixos-rebuild" = "nixos-rebuild --impure --flake /etc/nixos/server#nixos-server"; }; + }; +} diff --git a/marks b/marks new file mode 100644 index 0000000..6101e34 --- /dev/null +++ b/marks @@ -0,0 +1,15 @@ +installation: +secure erase / sanitize +gdisk +cryptsetup +mkfs +mount +copy private files +mkswap -s $SIZE -F /mnt/var/swapfile +swapon /mnt/var/swapfile +sbctl enroll-keys --yes-this-might-brick-my-machine +nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd +systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 + +todo: +- lanzaboote diff --git a/server/configuration.nix b/server/configuration.nix new file mode 100644 index 0000000..c572485 --- /dev/null +++ b/server/configuration.nix @@ -0,0 +1,36 @@ +{ config, lib, pkgs, ... }: +{ + imports = [ ../common.nix ./hardware-configuration.nix ]; + boot.kernelParams = [ "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ]; + networking = { + hostName = "nixos-server"; + networkmanager.ensureProfiles.profiles.home-wifi = { + wifi.ssid = "bogale_2.4"; + wifi-security.psk = builtins.readFile "/root/secrets/home-wifi.psk"; + }; + firewall = { + allowedTCPPorts = [ 80 ]; + extraInputRules = '' + ip saddr 192.168.1.0/24 tcp dport 22 accept + ''; + }; + }; + services = { + openssh = { + enable = true; + openFirewall = false; + }; + nginx = { + enable = true; + virtualHosts."_".default = true; + virtualHosts."_" = { + locations."/" = { + return = "200 'It works'"; + extraConfig = '' + default_type text/html; + ''; + }; + }; + }; + }; +} diff --git a/server/flake.lock b/server/flake.lock new file mode 100644 index 0000000..0a16ff3 --- /dev/null +++ b/server/flake.lock @@ -0,0 +1,49 @@ +{ + "nodes": { + "home-manager": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1789267039, + "narHash": "sha256-LWiBv9yAYFi2LPbUhDGHPGKYskJQjj2fw12OlyO1uQo=", + "owner": "nix-community", + "repo": "home-manager", + "rev": "ec172013fa62135f58fb58dd17ae9651e8f39727", + "type": "github" + }, + "original": { + "owner": "nix-community", + "ref": "release-26.05", + "repo": "home-manager", + "type": "github" + } + }, + "nixpkgs": { + "locked": { + "lastModified": 1789459628, + "narHash": "sha256-JOaadoI/IC9qEvwlnjwAhwdcWkCDqEeOJ+cOtUH/8RQ=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "b67c7a60c3732edd4b947a7df8af06215851a614", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-26.05", + "repo": "nixpkgs", + "type": "github" + } + }, + "root": { + "inputs": { + "home-manager": "home-manager", + "nixpkgs": "nixpkgs" + } + } + }, + "root": "root", + "version": 7 +} diff --git a/server/flake.nix b/server/flake.nix new file mode 100644 index 0000000..705a8a3 --- /dev/null +++ b/server/flake.nix @@ -0,0 +1,24 @@ +{ + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05"; + home-manager = { + url = "github:nix-community/home-manager/release-26.05"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + }; + outputs = inputs@{ self, nixpkgs, home-manager, ... }: { + nixosConfigurations.nixos-server = nixpkgs.lib.nixosSystem { + modules = [ + ./configuration.nix + home-manager.nixosModules.home-manager + { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + home-manager.extraSpecialArgs = { inherit inputs; }; + home-manager.users.root = ../home/server/root.nix; + home-manager.users.bogale = ../home/server/bogale.nix; + } + ]; + }; + }; +} diff --git a/server/hardware-configuration.nix b/server/hardware-configuration.nix new file mode 100644 index 0000000..6b53763 --- /dev/null +++ b/server/hardware-configuration.nix @@ -0,0 +1,33 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "ehci_pci" "sd_mod" "sdhci_pci" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/mapper/root"; + fsType = "ext4"; + }; + + boot.initrd.luks.devices."root".device = "/dev/disk/by-uuid/e0288e5e-87eb-453f-ab22-0d6e54576609"; + + fileSystems."/boot" = + { device = "/dev/disk/by-uuid/86F4-A8F1"; + fsType = "vfat"; + options = [ "fmask=0077" "dmask=0077" ]; + }; + + swapDevices = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +}