{ config, lib, pkgs, ... }: { time.timeZone = "Asia/Chita"; system.stateVersion = "26.05"; imports = [ ./mods/pxeboot.nix ]; i18n.defaultLocale = "ru_RU.UTF-8"; swapDevices = [ { device = "/var/swapfile"; } ]; users.users.root.hashedPasswordFile = "/secrets/user/root-pw"; nix.settings.experimental-features = [ "nix-command" "flakes" ]; console = { font = "cyr-sun16"; keyMap = "ruwin_alt_sh-UTF-8"; }; environment.systemPackages = with pkgs; [ jq _7zz sbctl openssl grub2_efi ]; fileSystems = let noatime.options = [ "noatime" ]; in { "/" = noatime; "/boot" = noatime; }; services = { logind.settings.Login.HandleLidSwitch = "ignore"; openssh = { enable = true; settings.PasswordAuthentication = false; }; }; systemd.tmpfiles.rules = [ "d /root/backup" "d /root/backup/base" "L /root/backup/base/nixos - - - - /etc/nixos" "L /root/backup/base/secrets - - - - /secrets" "L /root/backup/base/sbctl - - - - /var/lib/sbctl" ]; boot = { kernelModules = [ "amneziawg" ]; kernelPackages = pkgs.linuxPackages_latest; extraModulePackages = [ config.boot.kernelPackages.amneziawg ]; loader.limine = { enable = true; secureBoot.enable = true; panicOnChecksumMismatch = true; }; }; networking = { firewall = { allowedTCPPorts = [ 53 80 2049 ]; allowedUDPPorts = [ 53 67 69 547 ]; }; nat = { enable = true; enableIPv6 = true; internalInterfaces = [ "enp1s0" ]; }; wg-quick.interfaces.awg0 = { type = "amneziawg"; peers = [ { endpoint = "bogaledev.ru"; allowedIPs = [ "::/0" "0.0.0.0/0" ]; } ]; }; networkmanager = { enable = true; ensureProfiles = { environmentFiles = [ "/secrets/wifi.env" ]; profiles = { ethernet = { ipv6 = { method = "manual"; addresses = "fc02::1/64"; }; ipv4 = { method = "manual"; addresses = "10.2.0.1/16"; }; connection = { id = "ethernet"; type = "802-3-ethernet"; }; }; wifi = { wifi-security.key-mgmt = "sae"; ipv6 = { method = "manual"; gateway = "fc01::1"; }; ipv4 = { method = "manual"; gateway = "10.1.0.1"; }; connection = { id = "wifi"; type = "802-11-wireless"; }; }; }; }; }; }; }