{ config, lib, pkgs, ... }: { nix.settings.experimental-features = [ "nix-command" "flakes" ]; system.stateVersion = "26.05"; time.timeZone = "Asia/Chita"; i18n.defaultLocale = "ru_RU.UTF-8"; console = { keyMap = "ruwin_alt_sh-UTF-8"; font = "cyr-sun16"; }; fileSystems = { "/" = { options = [ "noatime" ]; }; "/boot" = { options = [ "noatime" ]; }; }; swapDevices = [ { device = "/var/swapfile"; } ]; boot = { kernelModules = [ "amneziawg" ]; kernelPackages = pkgs.linuxPackages_latest; extraModulePackages = [ config.boot.kernelPackages.amneziawg ]; loader.limine = { enable = true; secureBoot.enable = true; panicOnChecksumMismatch = true; }; }; users.users.root.hashedPasswordFile = "/secrets/user/root-pw"; networking = { firewall = { allowedTCPPorts = [ 53 80 2049 ]; allowedUDPPorts = [ 53 67 69 547 ]; }; nat = { enable = true; enableIPv6 = true; internalInterfaces = [ "enp1s0" ]; }; wg-quick.interfaces.awg0 = { type = "amneziawg"; peers = [ { endpoint = "bogaledev.ru"; allowedIPs = [ "::/0" "0.0.0.0/0" ]; } ]; }; networkmanager = { enable = true; ensureProfiles = { environmentFiles = [ "/secrets/wifi.env" ]; profiles = { ethernet = { ipv6 = { method = "manual"; addresses = "fc02::1/64"; }; ipv4 = { method = "manual"; addresses = "10.2.0.1/16"; }; connection = { id = "ethernet"; type = "802-3-ethernet"; }; }; wifi = { wifi-security.key-mgmt = "sae"; ipv6 = { method = "manual"; gateway = "fc01::1"; }; ipv4 = { method = "manual"; gateway = "10.1.0.1"; }; connection = { id = "wifi"; type = "802-11-wireless"; }; }; }; }; }; }; environment.systemPackages = with pkgs; [ jq _7zz sbctl openssl grub2_efi ]; services = { logind.settings.Login.HandleLidSwitch = "ignore"; openssh = { enable = true; settings.PasswordAuthentication = false; }; nginx = { enable = true; recommendedTlsSettings = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedBrotliSettings = true; }; nfs.server = { enable = true; exports = let clients."10.2.0.0/16" = [ "mp" "rw" "no_root_squash" ]; in { "/srv/nfs/arch/root" = clients; "/srv/nfs/fedora/root" = clients; }; }; dnsmasq = { enable = true; settings = { enable-ra = true; no-resolv = true; cache-size = 4096; bogus-priv = true; enable-tftp = true; interface = "enp1s0"; domain-needed = true; tftp-root = "/srv/tftp"; dhcp-boot = "grubx64.efi"; dhcp-range = [ "10.2.0.2,10.2.255.254,12h" "fc02::2,fc02::ffff:ffff:ffff:ffff,12h" ]; server = [ "1.1.1.2" "2606:4700:4700::1112" "1.0.0.2" "2606:4700:4700::1002" ]; }; }; }; virtualisation.oci-containers.containers.fedora-dracut = { pull = "newer"; autoStart = false; entrypoint = "bash"; image = "docker.io/fedora:latest"; cmd = [ "/data/workdir/entry.sh" ]; volumes = [ "/var/lib/podman-dracut:/data/workdir" "/srv/nfs/arch/lower:/data/arch:ro" "/srv/nfs/fedora/lower:/data/fedora:ro" ]; }; systemd = { tmpfiles.rules = [ "d /var/lib/podman-dracut 0755 root root -" ]; services.pxeboot = { serviceConfig.Type = "oneshot"; wantedBy = [ "multi-user.target" ]; path = with pkgs; [ xz e2fsprogs grub2_efi util-linux ]; script = let resolv = pkgs.writeText "resolv.conf" '' nameserver fc02::1 nameserver 10.2.0.1 options edns0 trust-ad ''; grubCfg = pkgs.writeText "grub.cfg" '' set timeout=10 set path=(http,$net_default_server)/local/boot/pxe set nfs="rw ifname=ens0:$net_default_mac ip=$net_default_ip::$net_default_server:255.255.0.0::ens0:none root=nfs4:$net_default_server:/srv/nfs" . $path/grub.cfg ''; entryScript = pkgs.writeText "entry.sh" '' set -e dnf install -y dracut-network nfs-utils cd /data/workdir for target in $(cd ..; ls | grep -v workdir); do modsDir=../$target/usr/lib/modules/* mkdir $target cp $modsDir/vmlinuz $target dracut -Nm "network-manager nfs" --zstd -k $modsDir --kver $(basename $modsDir) $target/initramfs done ''; in '' cd /srv/tftp if [ ! -e grubx64.efi ]; then grub-mkstandalone -O x86_64-efi --compress=xz --modules=efinet -o grubx64.efi /boot/grub/grub.cfg=${grubCfg} fi for distro in arch:arch/x86_64/airootfs.sfs fedora:LiveOS/squashfs.img; do rootfs=''${distro##*:} distro=''${distro%:*} cd /srv/nfs/$distro mkdir -p loop lower upper work root mountpoint -q loop || mount $distro.iso loop mountpoint -q lower || mount loop/$rootfs lower mountpoint -q root || mount -t overlay overlay -o lowerdir=lower,upperdir=upper,workdir=work,nfs_export=on root if [ ! -e upper/etc/resolv.conf ]; then cd root/etc rm -f resolv.conf cp ${resolv} resolv.conf chattr +i resolv.conf fi done cd /srv/http/local/boot if [ ! -e pxe ]; then mkdir pxe cp ${entryScript} /var/lib/podman-dracut/entry.sh systemctl --wait start podman-fedora-dracut.service for distro in arch: fedora:selinux=0; do cmdline=''${distro##*:} distro=''${distro%:*} mv /var/lib/podman-dracut/$distro pxe echo "menuentry $distro { linux \$path/$distro/vmlinuz \$nfs/$distro/root $cmdline initrd \$path/$distro/initramfs }" >> pxe/grub.cfg done chmod -R 640 pxe chgrp -R php pxe chmod ug+x $(find pxe -type d) fi ''; }; }; }