{ config, lib, pkgs, ... }: { nix.settings.experimental-features = [ "nix-command" "flakes" ]; system.stateVersion = "26.05"; time.timeZone = "Asia/Chita"; i18n.defaultLocale = "ru_RU.UTF-8"; console = { keyMap = "ruwin_alt_sh-UTF-8"; font = "cyr-sun16"; }; fileSystems = { "/" = { options = [ "noatime" ]; }; "/boot" = { options = [ "noatime" ]; }; }; swapDevices = [ { device = "/var/swapfile"; } ]; boot = { kernelModules = [ "amneziawg" ]; kernelPackages = pkgs.linuxPackages_latest; extraModulePackages = [ config.boot.kernelPackages.amneziawg ]; loader.limine = { enable = true; secureBoot.enable = true; panicOnChecksumMismatch = true; }; }; users.users.root.hashedPasswordFile = "/secrets/user/root-pw"; networking = { firewall = { allowedTCPPorts = [ 53 80 ]; allowedUDPPorts = [ 53 67 69 547 ]; }; wg-quick.interfaces.awg0 = { type = "amneziawg"; peers = [ { endpoint = "bogaledev.ru"; allowedIPs = [ "::/0" "0.0.0.0/0" ]; } ]; }; networkmanager = { enable = true; ensureProfiles = { environmentFiles = [ "/secrets/wifi.env" ]; profiles.home-wifi = { wifi-security.key-mgmt = "sae"; connection = { id = "home-wifi"; type = "wifi"; }; ipv6 = { method = "manual"; gateway = "fc01::1"; }; ipv4 = { method = "manual"; gateway = "10.1.0.1"; }; }; }; }; }; environment.systemPackages = with pkgs; [ jq sbctl ]; services = { logind.settings.Login.HandleLidSwitch = "ignore"; openssh = { enable = true; settings.PasswordAuthentication = false; }; nginx = { enable = true; recommendedTlsSettings = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedBrotliSettings = true; }; dnsmasq = { enable = true; settings = { enable-ra = true; no-resolv = true; cache-size = 4096; bogus-priv = true; enable-tftp = true; interface = "enp1s0"; domain-needed = true; tftp-root = "/srv/tftp"; dhcp-boot = "grubx64.efi"; dhcp-range = [ "10.2.0.2,10.2.255.254,12h" "fc02::2,fc02::ffff:ffff:ffff:ffff,12h" ]; server = [ "2606:4700:4700::1112" "1.1.1.2" "2606:4700:4700::1002" "1.0.0.2" ]; }; }; }; }