nixos/common.nix
2026-09-23 11:28:13 +09:00

83 lines
2.2 KiB
Nix

{ config, lib, pkgs, ... }:
{
nix.settings.experimental-features = [ "nix-command" "flakes" ];
system.stateVersion = "26.05";
time.timeZone = "Asia/Chita";
i18n.defaultLocale = "ru_RU.UTF-8";
console = {
keyMap = "ruwin_alt_sh-UTF-8";
font = "cyr-sun16";
};
fileSystems = {
"/" = { options = [ "noatime" ]; };
"/boot" = { options = [ "noatime" ]; };
};
swapDevices = [ { device = "/var/swapfile"; } ];
boot = {
kernelModules = [ "amneziawg" ];
kernelPackages = pkgs.linuxPackages_latest;
extraModulePackages = [ config.boot.kernelPackages.amneziawg ];
loader.limine = {
enable = true;
maxGenerations = 20;
secureBoot.enable = true;
panicOnChecksumMismatch = true;
};
};
users.users.root.hashedPasswordFile = "/secrets/root.passwd";
networking = {
firewall = {
allowedTCPPorts = [ 53 80 ];
allowedUDPPorts = [ 53 67 69 547 ];
};
wg-quick.interfaces.awg0 = {
type = "amneziawg";
configFile = "/secrets/awg0.conf";
};
networkmanager = {
enable = true;
ensureProfiles = {
environmentFiles = [ "/secrets/wifi.env" ];
profiles.home-wifi = {
wifi-security.key-mgmt = "sae";
connection = {
id = "home-wifi";
type = "wifi";
};
};
};
};
};
environment.systemPackages = with pkgs; [
sbctl
];
services = {
logind.settings.Login.HandleLidSwitch = "ignore";
nginx = {
enable = true;
recommendedTlsSettings = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedBrotliSettings = true;
};
dnsmasq = {
enable = true;
settings = {
enable-ra = true;
no-resolv = true;
cache-size = 1024;
bogus-priv = true;
enable-tftp = true;
interface = "enp1s0";
domain-needed = true;
tftp-root = "/srv/tftp";
dhcp-boot = "grubx64.efi";
dhcp-range = [ "10.2.0.2,10.2.255.254,12h"
"fc02::2,fc02::ffff:ffff:ffff:ffff,12h" ];
server = [ "1.0.0.1" "2606:4700:4700::1001"
"1.1.1.1" "2606:4700:4700::1111" ];
};
};
};
}