103 lines
2.6 KiB
Nix
103 lines
2.6 KiB
Nix
{ config, lib, pkgs, ... }:
|
|
{
|
|
time.timeZone = "Asia/Chita";
|
|
system.stateVersion = "26.05";
|
|
imports = [ ./mods/pxeboot.nix ];
|
|
i18n.defaultLocale = "ru_RU.UTF-8";
|
|
swapDevices = [ { device = "/var/swapfile"; } ];
|
|
users.users.root.hashedPasswordFile = "/secrets/user/root-pw";
|
|
nix.settings.experimental-features = [ "nix-command" "flakes" ];
|
|
console = {
|
|
font = "cyr-sun16";
|
|
keyMap = "ruwin_alt_sh-UTF-8";
|
|
};
|
|
environment.systemPackages = with pkgs; [
|
|
jq _7zz sbctl
|
|
openssl grub2_efi
|
|
];
|
|
fileSystems = let
|
|
noatime = { options = [ "noatime" ]; };
|
|
in {
|
|
"/" = noatime;
|
|
"/boot" = noatime;
|
|
};
|
|
services = {
|
|
logind.settings.Login.HandleLidSwitch = "ignore";
|
|
openssh = {
|
|
enable = true;
|
|
settings.PasswordAuthentication = false;
|
|
};
|
|
};
|
|
systemd.tmpfiles.rules = [
|
|
"d /root/backup"
|
|
"d /root/backup/base"
|
|
"L /root/backup/base/nixos - - - - /etc/nixos"
|
|
"L /root/backup/base/secrets - - - - /secrets"
|
|
"L /root/backup/base/sbctl - - - - /var/lib/sbctl"
|
|
];
|
|
boot = {
|
|
kernelModules = [ "amneziawg" ];
|
|
kernelPackages = pkgs.linuxPackages_latest;
|
|
extraModulePackages = [ config.boot.kernelPackages.amneziawg ];
|
|
loader.limine = {
|
|
enable = true;
|
|
secureBoot.enable = true;
|
|
panicOnChecksumMismatch = true;
|
|
};
|
|
};
|
|
networking = {
|
|
firewall = {
|
|
allowedTCPPorts = [ 53 80 2049 ];
|
|
allowedUDPPorts = [ 53 67 69 547 ];
|
|
};
|
|
nat = {
|
|
enable = true;
|
|
enableIPv6 = true;
|
|
internalInterfaces = [ "enp1s0" ];
|
|
};
|
|
wg-quick.interfaces.awg0 = {
|
|
type = "amneziawg";
|
|
peers = [ {
|
|
endpoint = "bogaledev.ru";
|
|
allowedIPs = [ "::/0" "0.0.0.0/0" ];
|
|
} ];
|
|
};
|
|
networkmanager = {
|
|
enable = true;
|
|
ensureProfiles = {
|
|
environmentFiles = [ "/secrets/wifi.env" ];
|
|
profiles = {
|
|
ethernet = {
|
|
ipv6 = {
|
|
method = "manual";
|
|
addresses = "fc02::1/64";
|
|
};
|
|
ipv4 = {
|
|
method = "manual";
|
|
addresses = "10.2.0.1/16";
|
|
};
|
|
connection = {
|
|
id = "ethernet";
|
|
type = "802-3-ethernet";
|
|
};
|
|
};
|
|
wifi = {
|
|
wifi-security.key-mgmt = "sae";
|
|
ipv6 = {
|
|
method = "manual";
|
|
gateway = "fc01::1";
|
|
};
|
|
ipv4 = {
|
|
method = "manual";
|
|
gateway = "10.1.0.1";
|
|
};
|
|
connection = {
|
|
id = "wifi";
|
|
type = "802-11-wireless";
|
|
};
|
|
};
|
|
};
|
|
};
|
|
};
|
|
};
|
|
}
|