{ config, lib, pkgs, ... }: { nix.settings.experimental-features = [ "nix-command" "flakes" ]; system.stateVersion = "26.05"; time.timeZone = "Asia/Chita"; i18n.defaultLocale = "ru_RU.UTF-8"; console = { keyMap = "ruwin_alt_sh-UTF-8"; font = "cyr-sun16"; }; fileSystems = { "/" = { options = [ "noatime" ]; }; "/boot" = { options = [ "noatime" ]; }; }; swapDevices = [ { device = "/var/swapfile"; } ]; boot = { kernelModules = [ "amneziawg" ]; kernelPackages = pkgs.linuxPackages_latest; extraModulePackages = [ config.boot.kernelPackages.amneziawg ]; loader.limine = { enable = true; secureBoot.enable = true; panicOnChecksumMismatch = true; }; }; users.users.root.hashedPasswordFile = "/secrets/user/root-pw"; networking = { firewall = { allowedTCPPorts = [ 53 80 2049 ]; allowedUDPPorts = [ 53 67 69 547 ]; }; nat = { enable = true; enableIPv6 = true; internalInterfaces = [ "enp1s0" ]; }; wg-quick.interfaces.awg0 = { type = "amneziawg"; peers = [ { endpoint = "bogaledev.ru"; allowedIPs = [ "::/0" "0.0.0.0/0" ]; } ]; }; networkmanager = { enable = true; ensureProfiles = { environmentFiles = [ "/secrets/wifi.env" ]; profiles = { ethernet = { ipv6 = { method = "manual"; addresses = "fc02::1/64"; }; ipv4 = { method = "manual"; addresses = "10.2.0.1/16"; }; connection = { id = "ethernet"; type = "802-3-ethernet"; }; }; wifi = { wifi-security.key-mgmt = "sae"; ipv6 = { method = "manual"; gateway = "fc01::1"; }; ipv4 = { method = "manual"; gateway = "10.1.0.1"; }; connection = { id = "wifi"; type = "802-11-wireless"; }; }; }; }; }; }; environment.systemPackages = with pkgs; [ jq _7zz sbctl dracut openssl grub2_efi ]; services = { logind.settings.Login.HandleLidSwitch = "ignore"; openssh = { enable = true; settings.PasswordAuthentication = false; }; nginx = { enable = true; recommendedTlsSettings = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedBrotliSettings = true; }; nfs.server = { enable = true; exports = let clients."10.2.0.0/16" = [ "mp" "rw" "no_root_squash" ]; in { "/srv/nfs/arch/root" = clients; "/srv/nfs/fedora/root" = clients; }; }; dnsmasq = { enable = true; settings = { enable-ra = true; no-resolv = true; cache-size = 4096; bogus-priv = true; enable-tftp = true; interface = "enp1s0"; domain-needed = true; tftp-root = "/srv/tftp"; dhcp-boot = "grubx64.efi"; dhcp-range = [ "10.2.0.2,10.2.255.254,12h" "fc02::2,fc02::ffff:ffff:ffff:ffff,12h" ]; server = [ "1.1.1.2" "2606:4700:4700::1112" "1.0.0.2" "2606:4700:4700::1002" ]; }; }; }; systemd.services.pxeboot = { serviceConfig.Type = "oneshot"; wantedBy = [ "multi-user.target" ]; path = with pkgs; [ xz dracut grub2_efi util-linux ]; script = let grubCfg = pkgs.writeText "grub.cfg" '' set timeout=10 set path=(http,$net_default_server)/local/boot/pxe set nfs="rw ifname=ens0:$net_default_mac ip=$net_default_ip::$net_default_server:255.255.0.0::ens0:none root=nfs4:$net_default_server:/srv/nfs" menuentry Arch { linux $path/arch/linux $nfs/arch/root initrd $path/arch/initramfs } menuentry Fedora { linux $path/fedora/linux $nfs/fedora/root selinux=0 initrd $path/fedora/initramfs } ''; in '' if [ ! -e /srv/tftp/grubx64.efi ]; then echo "Building grub" grub-mkstandalone -O x86_64-efi --compress=xz --modules=efinet -o /srv/tftp/grubx64.efi /boot/grub/grub.cfg=${grubCfg} fi for distro in arch:arch/x86_64/airootfs.sfs fedora:LiveOS/squashfs.img; do rootfs=''${distro#*:} distro=''${distro%%:*} cd /srv/nfs/$distro mkdir -p loop lower upper work root mountpoint -q loop || mount $distro.iso loop mountpoint -q lower || mount loop/$rootfs lower mountpoint -q root || mount -t overlay overlay -o lowerdir=lower,upperdir=upper,workdir=work,nfs_export=on root cd /srv/http/local/boot/pxe if [ ! -e $distro ]; then mkdir $distro modsDir=$OLDPWD/lower/usr/lib/modules/* cp $modsDir/vmlinuz $distro/linux dracut -Nvm "network-manager nfs" --zstd --kver $(basename $modsDir) -k $modsDir $distro/initramfs chmod -R 640 $distro chgrp -R php $distro chmod ug+x $distro fi done ''; }; }