initial commit
This commit is contained in:
commit
733dce18a0
11 changed files with 295 additions and 0 deletions
57
common.nix
Normal file
57
common.nix
Normal file
|
|
@ -0,0 +1,57 @@
|
||||||
|
{ config, lib, pkgs, ... }:
|
||||||
|
{
|
||||||
|
nix.settings.experimental-features = [ "nix-command" "flakes" ];
|
||||||
|
system.stateVersion = "26.05";
|
||||||
|
time.timeZone = "Asia/Chita";
|
||||||
|
i18n.defaultLocale = "ru_RU.UTF-8";
|
||||||
|
console = {
|
||||||
|
keyMap = "ruwin_alt_sh-UTF-8";
|
||||||
|
font = "cyr-sun16";
|
||||||
|
};
|
||||||
|
fileSystems = {
|
||||||
|
"/" = { options = [ "noatime" ]; };
|
||||||
|
"/boot" = { options = [ "noatime" ]; };
|
||||||
|
};
|
||||||
|
swapDevices = [ { device = "/var/swapfile"; } ];
|
||||||
|
boot.loader.limine = {
|
||||||
|
enable = true;
|
||||||
|
secureBoot.enable = true;
|
||||||
|
};
|
||||||
|
users.users = {
|
||||||
|
root = {
|
||||||
|
home = "/root";
|
||||||
|
hashedPasswordFile = "/root/secrets/root.passwd";
|
||||||
|
};
|
||||||
|
bogale = {
|
||||||
|
isNormalUser = true;
|
||||||
|
home = "/home/bogale";
|
||||||
|
extraGroups = [ "wheel" ];
|
||||||
|
hashedPasswordFile = "/root/secrets/bogale.passwd";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
networking = {
|
||||||
|
nftables.enable = true;
|
||||||
|
#networking.wg-quick.interfaces.awg0 = {
|
||||||
|
#type = "amneziawg";
|
||||||
|
#configFile = "/root/secrets/awg0.conf";
|
||||||
|
#};
|
||||||
|
networkmanager = {
|
||||||
|
enable = true;
|
||||||
|
ensureProfiles.profiles.home-wifi = {
|
||||||
|
wifi-security.key-mgmt = "sae";
|
||||||
|
connection = {
|
||||||
|
id = "home-wifi";
|
||||||
|
type = "wifi";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
environment.systemPackages = with pkgs; [
|
||||||
|
amneziawg-go
|
||||||
|
amneziawg-tools
|
||||||
|
sbctl
|
||||||
|
];
|
||||||
|
services = {
|
||||||
|
logind.settings.Login.HandleLidSwitch = "ignore";
|
||||||
|
};
|
||||||
|
}
|
||||||
6
home/bogale.nix
Normal file
6
home/bogale.nix
Normal file
|
|
@ -0,0 +1,6 @@
|
||||||
|
{ config, pkgs, ... }:
|
||||||
|
{
|
||||||
|
imports = [ ./common.nix ];
|
||||||
|
home.username = "bogale";
|
||||||
|
home.homeDirectory = "/home/bogale";
|
||||||
|
}
|
||||||
58
home/common.nix
Normal file
58
home/common.nix
Normal file
|
|
@ -0,0 +1,58 @@
|
||||||
|
{ config, pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.stateVersion = "26.05";
|
||||||
|
programs = {
|
||||||
|
home-manager.enable = true;
|
||||||
|
bash = {
|
||||||
|
enable = true;
|
||||||
|
historyControl = [ "ignoreboth" ];
|
||||||
|
shellAliases = { la = "ls -lAtr"; };
|
||||||
|
};
|
||||||
|
git = {
|
||||||
|
enable = true;
|
||||||
|
settings = {
|
||||||
|
init.defaultbranch = "main";
|
||||||
|
user = {
|
||||||
|
name = "bogale";
|
||||||
|
email = "git@bogaledev.ru";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
neovim = {
|
||||||
|
enable = true;
|
||||||
|
defaultEditor = true;
|
||||||
|
extraConfig = ''
|
||||||
|
set tabstop=4
|
||||||
|
set shiftwidth=4
|
||||||
|
set expandtab
|
||||||
|
set number
|
||||||
|
set relativenumber
|
||||||
|
autocmd FileType nix set tabstop=2 shiftwidth=2
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
tmux = {
|
||||||
|
enable = true;
|
||||||
|
clock24 = true;
|
||||||
|
keyMode = "vi";
|
||||||
|
escapeTime = 0;
|
||||||
|
terminal = "screen-256color";
|
||||||
|
extraConfig = ''
|
||||||
|
unbind C-b
|
||||||
|
set -g mouse on
|
||||||
|
set -g prefix M-d
|
||||||
|
set -g prefix M-f
|
||||||
|
set-option -g focus-events on
|
||||||
|
set -s set-clipboard external
|
||||||
|
set-option -a terminal-features "xterm-256color:RGB"
|
||||||
|
bind f send-prefix
|
||||||
|
bind d send-prefix
|
||||||
|
bind h select-pane -L
|
||||||
|
bind j select-pane -D
|
||||||
|
bind k select-pane -U
|
||||||
|
bind l select-pane -R
|
||||||
|
bind u split-window -h
|
||||||
|
bind i split-window -v
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
6
home/root.nix
Normal file
6
home/root.nix
Normal file
|
|
@ -0,0 +1,6 @@
|
||||||
|
{ config, pkgs, ... }:
|
||||||
|
{
|
||||||
|
imports = [ ./common.nix ];
|
||||||
|
home.username = "root";
|
||||||
|
home.homeDirectory = "/root";
|
||||||
|
}
|
||||||
4
home/server/bogale.nix
Normal file
4
home/server/bogale.nix
Normal file
|
|
@ -0,0 +1,4 @@
|
||||||
|
{ config, pkgs, ... }:
|
||||||
|
{
|
||||||
|
imports = [ ../bogale.nix ];
|
||||||
|
}
|
||||||
7
home/server/root.nix
Normal file
7
home/server/root.nix
Normal file
|
|
@ -0,0 +1,7 @@
|
||||||
|
{ config, pkgs, ... }:
|
||||||
|
{
|
||||||
|
imports = [ ../root.nix ];
|
||||||
|
programs.bash = {
|
||||||
|
shellAliases = { "nixos-rebuild" = "nixos-rebuild --impure --flake /etc/nixos/server#nixos-server"; };
|
||||||
|
};
|
||||||
|
}
|
||||||
15
marks
Normal file
15
marks
Normal file
|
|
@ -0,0 +1,15 @@
|
||||||
|
installation:
|
||||||
|
secure erase / sanitize
|
||||||
|
gdisk
|
||||||
|
cryptsetup
|
||||||
|
mkfs
|
||||||
|
mount
|
||||||
|
copy private files
|
||||||
|
mkswap -s $SIZE -F /mnt/var/swapfile
|
||||||
|
swapon /mnt/var/swapfile
|
||||||
|
sbctl enroll-keys --yes-this-might-brick-my-machine
|
||||||
|
nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd
|
||||||
|
systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 <LUKS_DEV>
|
||||||
|
|
||||||
|
todo:
|
||||||
|
- lanzaboote
|
||||||
36
server/configuration.nix
Normal file
36
server/configuration.nix
Normal file
|
|
@ -0,0 +1,36 @@
|
||||||
|
{ config, lib, pkgs, ... }:
|
||||||
|
{
|
||||||
|
imports = [ ../common.nix ./hardware-configuration.nix ];
|
||||||
|
boot.kernelParams = [ "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ];
|
||||||
|
networking = {
|
||||||
|
hostName = "nixos-server";
|
||||||
|
networkmanager.ensureProfiles.profiles.home-wifi = {
|
||||||
|
wifi.ssid = "bogale_2.4";
|
||||||
|
wifi-security.psk = builtins.readFile "/root/secrets/home-wifi.psk";
|
||||||
|
};
|
||||||
|
firewall = {
|
||||||
|
allowedTCPPorts = [ 80 ];
|
||||||
|
extraInputRules = ''
|
||||||
|
ip saddr 192.168.1.0/24 tcp dport 22 accept
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
services = {
|
||||||
|
openssh = {
|
||||||
|
enable = true;
|
||||||
|
openFirewall = false;
|
||||||
|
};
|
||||||
|
nginx = {
|
||||||
|
enable = true;
|
||||||
|
virtualHosts."_".default = true;
|
||||||
|
virtualHosts."_" = {
|
||||||
|
locations."/" = {
|
||||||
|
return = "200 '<html><body>It works</body></html>'";
|
||||||
|
extraConfig = ''
|
||||||
|
default_type text/html;
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
49
server/flake.lock
generated
Normal file
49
server/flake.lock
generated
Normal file
|
|
@ -0,0 +1,49 @@
|
||||||
|
{
|
||||||
|
"nodes": {
|
||||||
|
"home-manager": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"nixpkgs"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1789267039,
|
||||||
|
"narHash": "sha256-LWiBv9yAYFi2LPbUhDGHPGKYskJQjj2fw12OlyO1uQo=",
|
||||||
|
"owner": "nix-community",
|
||||||
|
"repo": "home-manager",
|
||||||
|
"rev": "ec172013fa62135f58fb58dd17ae9651e8f39727",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "nix-community",
|
||||||
|
"ref": "release-26.05",
|
||||||
|
"repo": "home-manager",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"nixpkgs": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1789459628,
|
||||||
|
"narHash": "sha256-JOaadoI/IC9qEvwlnjwAhwdcWkCDqEeOJ+cOtUH/8RQ=",
|
||||||
|
"owner": "NixOS",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "b67c7a60c3732edd4b947a7df8af06215851a614",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "NixOS",
|
||||||
|
"ref": "nixos-26.05",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"root": {
|
||||||
|
"inputs": {
|
||||||
|
"home-manager": "home-manager",
|
||||||
|
"nixpkgs": "nixpkgs"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"root": "root",
|
||||||
|
"version": 7
|
||||||
|
}
|
||||||
24
server/flake.nix
Normal file
24
server/flake.nix
Normal file
|
|
@ -0,0 +1,24 @@
|
||||||
|
{
|
||||||
|
inputs = {
|
||||||
|
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
|
||||||
|
home-manager = {
|
||||||
|
url = "github:nix-community/home-manager/release-26.05";
|
||||||
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
outputs = inputs@{ self, nixpkgs, home-manager, ... }: {
|
||||||
|
nixosConfigurations.nixos-server = nixpkgs.lib.nixosSystem {
|
||||||
|
modules = [
|
||||||
|
./configuration.nix
|
||||||
|
home-manager.nixosModules.home-manager
|
||||||
|
{
|
||||||
|
home-manager.useGlobalPkgs = true;
|
||||||
|
home-manager.useUserPackages = true;
|
||||||
|
home-manager.extraSpecialArgs = { inherit inputs; };
|
||||||
|
home-manager.users.root = ../home/server/root.nix;
|
||||||
|
home-manager.users.bogale = ../home/server/bogale.nix;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
33
server/hardware-configuration.nix
Normal file
33
server/hardware-configuration.nix
Normal file
|
|
@ -0,0 +1,33 @@
|
||||||
|
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||||
|
# and may be overwritten by future invocations. Please make changes
|
||||||
|
# to /etc/nixos/configuration.nix instead.
|
||||||
|
{ config, lib, pkgs, modulesPath, ... }:
|
||||||
|
|
||||||
|
{
|
||||||
|
imports =
|
||||||
|
[ (modulesPath + "/installer/scan/not-detected.nix")
|
||||||
|
];
|
||||||
|
|
||||||
|
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "ehci_pci" "sd_mod" "sdhci_pci" ];
|
||||||
|
boot.initrd.kernelModules = [ ];
|
||||||
|
boot.kernelModules = [ ];
|
||||||
|
boot.extraModulePackages = [ ];
|
||||||
|
|
||||||
|
fileSystems."/" =
|
||||||
|
{ device = "/dev/mapper/root";
|
||||||
|
fsType = "ext4";
|
||||||
|
};
|
||||||
|
|
||||||
|
boot.initrd.luks.devices."root".device = "/dev/disk/by-uuid/e0288e5e-87eb-453f-ab22-0d6e54576609";
|
||||||
|
|
||||||
|
fileSystems."/boot" =
|
||||||
|
{ device = "/dev/disk/by-uuid/86F4-A8F1";
|
||||||
|
fsType = "vfat";
|
||||||
|
options = [ "fmask=0077" "dmask=0077" ];
|
||||||
|
};
|
||||||
|
|
||||||
|
swapDevices = [ ];
|
||||||
|
|
||||||
|
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||||
|
hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
|
||||||
|
}
|
||||||
Loading…
Add table
Add a link
Reference in a new issue