initial commit

This commit is contained in:
bogale 2026-09-17 00:21:44 +09:00
commit 733dce18a0
11 changed files with 295 additions and 0 deletions

57
common.nix Normal file
View file

@ -0,0 +1,57 @@
{ config, lib, pkgs, ... }:
{
nix.settings.experimental-features = [ "nix-command" "flakes" ];
system.stateVersion = "26.05";
time.timeZone = "Asia/Chita";
i18n.defaultLocale = "ru_RU.UTF-8";
console = {
keyMap = "ruwin_alt_sh-UTF-8";
font = "cyr-sun16";
};
fileSystems = {
"/" = { options = [ "noatime" ]; };
"/boot" = { options = [ "noatime" ]; };
};
swapDevices = [ { device = "/var/swapfile"; } ];
boot.loader.limine = {
enable = true;
secureBoot.enable = true;
};
users.users = {
root = {
home = "/root";
hashedPasswordFile = "/root/secrets/root.passwd";
};
bogale = {
isNormalUser = true;
home = "/home/bogale";
extraGroups = [ "wheel" ];
hashedPasswordFile = "/root/secrets/bogale.passwd";
};
};
networking = {
nftables.enable = true;
#networking.wg-quick.interfaces.awg0 = {
#type = "amneziawg";
#configFile = "/root/secrets/awg0.conf";
#};
networkmanager = {
enable = true;
ensureProfiles.profiles.home-wifi = {
wifi-security.key-mgmt = "sae";
connection = {
id = "home-wifi";
type = "wifi";
};
};
};
};
environment.systemPackages = with pkgs; [
amneziawg-go
amneziawg-tools
sbctl
];
services = {
logind.settings.Login.HandleLidSwitch = "ignore";
};
}

6
home/bogale.nix Normal file
View file

@ -0,0 +1,6 @@
{ config, pkgs, ... }:
{
imports = [ ./common.nix ];
home.username = "bogale";
home.homeDirectory = "/home/bogale";
}

58
home/common.nix Normal file
View file

@ -0,0 +1,58 @@
{ config, pkgs, ... }:
{
home.stateVersion = "26.05";
programs = {
home-manager.enable = true;
bash = {
enable = true;
historyControl = [ "ignoreboth" ];
shellAliases = { la = "ls -lAtr"; };
};
git = {
enable = true;
settings = {
init.defaultbranch = "main";
user = {
name = "bogale";
email = "git@bogaledev.ru";
};
};
};
neovim = {
enable = true;
defaultEditor = true;
extraConfig = ''
set tabstop=4
set shiftwidth=4
set expandtab
set number
set relativenumber
autocmd FileType nix set tabstop=2 shiftwidth=2
'';
};
tmux = {
enable = true;
clock24 = true;
keyMode = "vi";
escapeTime = 0;
terminal = "screen-256color";
extraConfig = ''
unbind C-b
set -g mouse on
set -g prefix M-d
set -g prefix M-f
set-option -g focus-events on
set -s set-clipboard external
set-option -a terminal-features "xterm-256color:RGB"
bind f send-prefix
bind d send-prefix
bind h select-pane -L
bind j select-pane -D
bind k select-pane -U
bind l select-pane -R
bind u split-window -h
bind i split-window -v
'';
};
};
}

6
home/root.nix Normal file
View file

@ -0,0 +1,6 @@
{ config, pkgs, ... }:
{
imports = [ ./common.nix ];
home.username = "root";
home.homeDirectory = "/root";
}

4
home/server/bogale.nix Normal file
View file

@ -0,0 +1,4 @@
{ config, pkgs, ... }:
{
imports = [ ../bogale.nix ];
}

7
home/server/root.nix Normal file
View file

@ -0,0 +1,7 @@
{ config, pkgs, ... }:
{
imports = [ ../root.nix ];
programs.bash = {
shellAliases = { "nixos-rebuild" = "nixos-rebuild --impure --flake /etc/nixos/server#nixos-server"; };
};
}

15
marks Normal file
View file

@ -0,0 +1,15 @@
installation:
secure erase / sanitize
gdisk
cryptsetup
mkfs
mount
copy private files
mkswap -s $SIZE -F /mnt/var/swapfile
swapon /mnt/var/swapfile
sbctl enroll-keys --yes-this-might-brick-my-machine
nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd
systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 <LUKS_DEV>
todo:
- lanzaboote

36
server/configuration.nix Normal file
View file

@ -0,0 +1,36 @@
{ config, lib, pkgs, ... }:
{
imports = [ ../common.nix ./hardware-configuration.nix ];
boot.kernelParams = [ "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ];
networking = {
hostName = "nixos-server";
networkmanager.ensureProfiles.profiles.home-wifi = {
wifi.ssid = "bogale_2.4";
wifi-security.psk = builtins.readFile "/root/secrets/home-wifi.psk";
};
firewall = {
allowedTCPPorts = [ 80 ];
extraInputRules = ''
ip saddr 192.168.1.0/24 tcp dport 22 accept
'';
};
};
services = {
openssh = {
enable = true;
openFirewall = false;
};
nginx = {
enable = true;
virtualHosts."_".default = true;
virtualHosts."_" = {
locations."/" = {
return = "200 '<html><body>It works</body></html>'";
extraConfig = ''
default_type text/html;
'';
};
};
};
};
}

49
server/flake.lock generated Normal file
View file

@ -0,0 +1,49 @@
{
"nodes": {
"home-manager": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1789267039,
"narHash": "sha256-LWiBv9yAYFi2LPbUhDGHPGKYskJQjj2fw12OlyO1uQo=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "ec172013fa62135f58fb58dd17ae9651e8f39727",
"type": "github"
},
"original": {
"owner": "nix-community",
"ref": "release-26.05",
"repo": "home-manager",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1789459628,
"narHash": "sha256-JOaadoI/IC9qEvwlnjwAhwdcWkCDqEeOJ+cOtUH/8RQ=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "b67c7a60c3732edd4b947a7df8af06215851a614",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-26.05",
"repo": "nixpkgs",
"type": "github"
}
},
"root": {
"inputs": {
"home-manager": "home-manager",
"nixpkgs": "nixpkgs"
}
}
},
"root": "root",
"version": 7
}

24
server/flake.nix Normal file
View file

@ -0,0 +1,24 @@
{
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
home-manager = {
url = "github:nix-community/home-manager/release-26.05";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = inputs@{ self, nixpkgs, home-manager, ... }: {
nixosConfigurations.nixos-server = nixpkgs.lib.nixosSystem {
modules = [
./configuration.nix
home-manager.nixosModules.home-manager
{
home-manager.useGlobalPkgs = true;
home-manager.useUserPackages = true;
home-manager.extraSpecialArgs = { inherit inputs; };
home-manager.users.root = ../home/server/root.nix;
home-manager.users.bogale = ../home/server/bogale.nix;
}
];
};
};
}

View file

@ -0,0 +1,33 @@
# Do not modify this file! It was generated by ‘nixos-generate-config’
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
imports =
[ (modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "ehci_pci" "sd_mod" "sdhci_pci" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "/dev/mapper/root";
fsType = "ext4";
};
boot.initrd.luks.devices."root".device = "/dev/disk/by-uuid/e0288e5e-87eb-453f-ab22-0d6e54576609";
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/86F4-A8F1";
fsType = "vfat";
options = [ "fmask=0077" "dmask=0077" ];
};
swapDevices = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}