summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authoradikro <adikro@disroot.org>2026-03-13 23:41:17 +0100
committeradikro <adikro@disroot.org>2026-03-13 23:41:17 +0100
commitf0c0e311c003057f24d8045509a627ad2acab978 (patch)
treea1955fe601c487aab46fa47838cd25b8273508ac
parentffefb53956c38909da77fe7ebbbb5d8b5dd823b9 (diff)
removing obsolete stuff
-rw-r--r--.sops.yaml2
-rw-r--r--flake.lock84
-rw-r--r--flake.nix14
-rw-r--r--hm/editors/nixvim/nixvim.nix2
-rw-r--r--hm/env/env.nix1
-rw-r--r--hm/env/mako.nix15
-rw-r--r--hm/env/niri/binds.nix14
-rw-r--r--hm/shell/foot.nix12
-rw-r--r--hm/soft/nixcord.nix15
-rw-r--r--hosts/desktop/configuration.nix43
-rw-r--r--hosts/desktop/home.nix1
-rw-r--r--os/core/audio.nix15
-rw-r--r--os/core/drivers.nix37
-rw-r--r--os/core/security.nix18
-rw-r--r--os/srv/gaming.nix4
-rw-r--r--os/srv/sops.nix9
-rw-r--r--scripts/default.nix33
-rw-r--r--scripts/install.sh88
-rw-r--r--scripts/setup.sh98
-rw-r--r--secrets.yaml (renamed from secrets/common.yaml)0
20 files changed, 151 insertions, 354 deletions
diff --git a/.sops.yaml b/.sops.yaml
index 6d18f5f..498f70e 100644
--- a/.sops.yaml
+++ b/.sops.yaml
@@ -6,7 +6,7 @@ keys:
- &host_laptop age1m4u7n6mt5d3jv39lf4aedr9gqu3khl4sahuqx5n5h7v48gkyc9zqkp9qs8
creation_rules:
- - path_regex: .*secrets/common\.yaml$
+ - path_regex: ^secrets\.yaml$
key_groups:
- age:
- *host_szpont
diff --git a/flake.lock b/flake.lock
index 2100e41..5fbc73f 100644
--- a/flake.lock
+++ b/flake.lock
@@ -136,11 +136,11 @@
]
},
"locked": {
- "lastModified": 1773093840,
- "narHash": "sha256-u/96NoAyN8BSRuM3ZimGf7vyYgXa3pLx4MYWjokuoH4=",
+ "lastModified": 1773422513,
+ "narHash": "sha256-MPjR48roW7CUMU6lu0+qQGqj92Kuh3paIulMWFZy+NQ=",
"owner": "nix-community",
"repo": "home-manager",
- "rev": "bb014746edb2a98d975abde4dd40fa240de4cf86",
+ "rev": "ef12a9a2b0f77c8fa3dda1e7e494fca668909056",
"type": "github"
},
"original": {
@@ -150,22 +150,6 @@
"type": "github"
}
},
- "kernelv": {
- "locked": {
- "lastModified": 1766069213,
- "narHash": "sha256-h2501PoQofwr3Ds/O/SHlm/izeKWqnRYuT7Yl5t6ZVI=",
- "owner": "NixOS",
- "repo": "nixpkgs",
- "rev": "52e64396e98aef211f4127416dbdae17a01b3d3f",
- "type": "github"
- },
- "original": {
- "owner": "NixOS",
- "repo": "nixpkgs",
- "rev": "52e64396e98aef211f4127416dbdae17a01b3d3f",
- "type": "github"
- }
- },
"neovim-nightly-overlay": {
"inputs": {
"flake-parts": "flake-parts",
@@ -175,11 +159,11 @@
]
},
"locked": {
- "lastModified": 1773101084,
- "narHash": "sha256-XljZHTJCn26qu7oAgcLq8DtZ+BSbXY3iQ/1ylPsw54I=",
+ "lastModified": 1773360308,
+ "narHash": "sha256-Asr6gDwzxvcglRaXEZSTL4lEA6braemURJc6wKBhKrs=",
"owner": "nix-community",
"repo": "neovim-nightly-overlay",
- "rev": "eee7ee7a7936b1aa7f6e5115535f6daf805f6896",
+ "rev": "b550599eedc54514f5b71cee8e480e337d104d84",
"type": "github"
},
"original": {
@@ -191,11 +175,11 @@
"neovim-src": {
"flake": false,
"locked": {
- "lastModified": 1773098641,
- "narHash": "sha256-tgtRikZ+jtvdHiUSFpXq+AKFV0nvPDlEyxlGG9CCAOU=",
+ "lastModified": 1773359104,
+ "narHash": "sha256-vWu0zLThxpsx6vbPK5eAgvkMKu1LV8tbybS/sjWn8S8=",
"owner": "neovim",
"repo": "neovim",
- "rev": "a81b059a45ba832f9ad0bdb1b37b7519e5922cac",
+ "rev": "957eb1fde04496b4a2c07fd8427a8d78844d1bf7",
"type": "github"
},
"original": {
@@ -216,11 +200,11 @@
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
},
"locked": {
- "lastModified": 1773170801,
- "narHash": "sha256-TB9/4xKh8tZcbOtxlHB24EO4NlEIorxtcL3L7LOWLqA=",
+ "lastModified": 1773433102,
+ "narHash": "sha256-0q2Uz4oNTX0+dIpN3zV2HLMHI8NOoRDwScatBS1v8ng=",
"owner": "sodiboo",
"repo": "niri-flake",
- "rev": "5336c8d137d1a3ad055e83fa08dcb17c1f2b9444",
+ "rev": "20f866c7416799ebf5b88b07c9d32c6a440e825d",
"type": "github"
},
"original": {
@@ -268,14 +252,15 @@
"flake-parts": "flake-parts_2",
"nixpkgs": [
"nixpkgs"
- ]
+ ],
+ "nixpkgs-nixcord": "nixpkgs-nixcord"
},
"locked": {
- "lastModified": 1773144845,
- "narHash": "sha256-bU+q8v1xjbYEjWaqCL1P5y/mloSqXGkGot5MZhLCSf4=",
+ "lastModified": 1773426551,
+ "narHash": "sha256-xkdf5jU1HDphAFy89WQsyStYdq0EjRsYCYsz5IrDEjo=",
"owner": "KaylorBen",
"repo": "nixcord",
- "rev": "df70a89c4aaf0bfaf419e1deafd43e92e9c98430",
+ "rev": "efe6a34e34d5ab0983d26ca290e5e0dba6e1abd1",
"type": "github"
},
"original": {
@@ -302,11 +287,11 @@
},
"nixpkgs": {
"locked": {
- "lastModified": 1772963539,
- "narHash": "sha256-9jVDGZnvCckTGdYT53d/EfznygLskyLQXYwJLKMPsZs=",
+ "lastModified": 1773282481,
+ "narHash": "sha256-b/GV2ysM8mKHhinse2wz+uP37epUrSE+sAKXy/xvBY4=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "9dcb002ca1690658be4a04645215baea8b95f31d",
+ "rev": "fe416aaedd397cacb33a610b33d60ff2b431b127",
"type": "github"
},
"original": {
@@ -331,13 +316,29 @@
"type": "github"
}
},
+ "nixpkgs-nixcord": {
+ "locked": {
+ "lastModified": 1773222311,
+ "narHash": "sha256-BHoB/XpbqoZkVYZCfXJXfkR+GXFqwb/4zbWnOr2cRcU=",
+ "owner": "NixOS",
+ "repo": "nixpkgs",
+ "rev": "0590cd39f728e129122770c029970378a79d076a",
+ "type": "github"
+ },
+ "original": {
+ "owner": "NixOS",
+ "ref": "nixos-25.11",
+ "repo": "nixpkgs",
+ "type": "github"
+ }
+ },
"nixpkgs-stable": {
"locked": {
- "lastModified": 1773068389,
- "narHash": "sha256-vMrm7Pk2hjBRPnCSjhq1pH0bg350Z+pXhqZ9ICiqqCs=",
+ "lastModified": 1773375660,
+ "narHash": "sha256-SEzUWw2Rf5Ki3bcM26nSKgbeoqi2uYy8IHVBqOKjX3w=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "44bae273f9f82d480273bab26f5c50de3724f52f",
+ "rev": "3e20095fe3c6cbb1ddcef89b26969a69a1570776",
"type": "github"
},
"original": {
@@ -389,7 +390,6 @@
"inputs": {
"disko": "disko",
"home-manager": "home-manager",
- "kernelv": "kernelv",
"neovim-nightly-overlay": "neovim-nightly-overlay",
"niri": "niri",
"nixcord": "nixcord",
@@ -612,11 +612,11 @@
"rust-overlay": "rust-overlay_2"
},
"locked": {
- "lastModified": 1773118567,
- "narHash": "sha256-fPMoWlLZIagImpv45pIs/KJ/jGfaH9Srm74iSSCadYI=",
+ "lastModified": 1773404924,
+ "narHash": "sha256-HczaRbfStxmt83umm0Eiie8ECdUELPAcoH/q/DdYpss=",
"owner": "sxyazi",
"repo": "yazi",
- "rev": "dee27a237788d99c0c2dc6d76c95dd3e10b3fba6",
+ "rev": "fa1ee46edce52e0d3bc0c4179b9d65ca46b1efbd",
"type": "github"
},
"original": {
diff --git a/flake.nix b/flake.nix
index bb957f7..ab0a358 100644
--- a/flake.nix
+++ b/flake.nix
@@ -4,9 +4,6 @@
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
- # Snapshot of nixpkgs with the 6.17.13 kernel for compatibility
- kernelv.url = "github:NixOS/nixpkgs/52e64396e98aef211f4127416dbdae17a01b3d3f";
-
nixos-hardware.url = "github:NixOS/nixos-hardware/master";
sops-nix = {
@@ -68,7 +65,6 @@
outputs =
{ self, nixpkgs, ... }@inputs:
let
- scripts = import ./scripts;
mkHost =
{
hostname,
@@ -87,16 +83,6 @@
};
in
{
- apps."x86_64-linux" = {
- install = {
- type = "app";
- program = "${scripts.install}/bin/nixos-install";
- };
- setup = {
- type = "app";
- program = "${scripts.setup}/bin/nixos-setup";
- };
- };
nixosConfigurations = {
szpont = mkHost {
hostname = "szpont";
diff --git a/hm/editors/nixvim/nixvim.nix b/hm/editors/nixvim/nixvim.nix
index 068012f..835556a 100644
--- a/hm/editors/nixvim/nixvim.nix
+++ b/hm/editors/nixvim/nixvim.nix
@@ -260,7 +260,7 @@ in
lsp = {
enable = true;
servers = {
- # zls.enable = true;
+ zls.enable = true;
nil_ls.enable = true;
clangd.enable = true;
};
diff --git a/hm/env/env.nix b/hm/env/env.nix
index 80e19f8..a5caec2 100644
--- a/hm/env/env.nix
+++ b/hm/env/env.nix
@@ -11,5 +11,6 @@
./swaylock.nix
./theme.nix
./waybar.nix
+ ./mako.nix
];
}
diff --git a/hm/env/mako.nix b/hm/env/mako.nix
new file mode 100644
index 0000000..3f9e3ef
--- /dev/null
+++ b/hm/env/mako.nix
@@ -0,0 +1,15 @@
+{ config, lib, ... }:
+let
+ cfg = config.hm.env.mako;
+in
+{
+ options.hm.env.mako.enable = lib.mkEnableOption "enables mako notifications";
+ config = lib.mkIf cfg.enable {
+ services.mako = {
+ enable = true;
+ settings = {
+
+ };
+ };
+ };
+}
diff --git a/hm/env/niri/binds.nix b/hm/env/niri/binds.nix
index c071d2e..ff8353e 100644
--- a/hm/env/niri/binds.nix
+++ b/hm/env/niri/binds.nix
@@ -9,7 +9,7 @@ with config.lib.niri.actions;
let
playerctl = spawn "${pkgs.playerctl}/bin/playerctl";
ssPath = "${toString config.hm.conf.xdg-dirs.storagePath}/pics/ss/$(date +%Y-%m-%d_%H-%M-%S)";
- # obsPass = osConfig.sops.secrets."obs/websocket_password".path;
+ obsPass = osConfig.sops.secrets."obs/websocket_password".path;
in
{
# --- System & Media ---
@@ -21,7 +21,7 @@ in
XF86AudioLowerVolume.action = spawn "wpctl" "set-volume" "@DEFAULT_AUDIO_SINK@" "3%-";
XF86AudioMute.action =
spawn "sh" "-c"
- "wpctl set-mute @DEFAULT_AUDIO_SINK@ toggle && wpctl set-mute @DEFAULT_AUDIO_SOURCE@ toggle";
+ "wpctl set-mute @DEFAULT_AUDIO_SINK@ toggle && wpctl set-mute @DEFAULT_AUDIO_SOURCE@ toggle && toggle-mute-notify";
# Media Control
XF86AudioPlay.action = playerctl "play-pause";
@@ -29,14 +29,14 @@ in
XF86AudioNext.action = playerctl "next";
# Brightness
- XF86MonBrightnessUp.action = spawn "light" "-A" "10";
- XF86MonBrightnessDown.action = spawn "light" "-U" "10";
+ XF86MonBrightnessUp.action = spawn "brightnessctl" "set" "5%+";
+ XF86MonBrightnessDown.action = spawn "brightnessctl" "set" "5%-";
# --- Applications ---
"Mod+Return".action = spawn "footclient";
"Mod+D".action = spawn "fuzzel";
"Mod+Shift+D".action = spawn "sh" "-c" "cliphist list | fuzzel --dmenu | cliphist decode | wl-copy";
- # "Super+Return".action = spawn "sh" "-c" "OBS_WEBSOCKET_URL=$(cat ${obsPass}) obs-cmd replay save";
+ "Super+Return".action = spawn "sh" "-c" "OBS_WEBSOCKET_URL=$(cat ${obsPass}) obs-cmd replay save";
"Super+C".action = spawn "qalculate-gtk";
"Super+D".action = spawn "equibop";
@@ -68,6 +68,10 @@ in
};
XF86Tools = {
+ action = spawn "sh" "-c" "wpctl set-mute @DEFAULT_AUDIO_SOURCE@ toggle && toggle-mute-notify";
+ repeat = false;
+ };
+ "Mod+XF86Tools" = {
action =
spawn "sh" "-c"
"niri msg action set-dynamic-cast-window --id $(niri msg --json pick-window | ${pkgs.jq}/bin/jq .id)";
diff --git a/hm/shell/foot.nix b/hm/shell/foot.nix
index 91dbfa0..1a86474 100644
--- a/hm/shell/foot.nix
+++ b/hm/shell/foot.nix
@@ -8,14 +8,10 @@
let
cfg = config.hm.shell.foot;
- footTheme = pkgs.runCommand "gruvbox-dark" { } ''
- sed -e 's/\[colors-dark\]/\[colors\]/g' ${
- pkgs.fetchurl {
- url = "https://codeberg.org/dnkl/foot/raw/branch/master/themes/gruvbox-dark";
- sha256 = "sha256-hlmLklG/vAEDy8I+k13+o4ZR6Cq6lTxOconjf9M75eo=";
- }
- } > $out
- '';
+ footTheme = pkgs.fetchurl {
+ url = "https://codeberg.org/dnkl/foot/raw/branch/master/themes/gruvbox-dark";
+ sha256 = "sha256-hlmLklG/vAEDy8I+k13+o4ZR6Cq6lTxOconjf9M75eo=";
+ };
in
{
options.hm.shell.foot = {
diff --git a/hm/soft/nixcord.nix b/hm/soft/nixcord.nix
index 8e5ae12..a929b2e 100644
--- a/hm/soft/nixcord.nix
+++ b/hm/soft/nixcord.nix
@@ -16,6 +16,7 @@ in
home.packages = with pkgs; [
stoat-desktop
element-desktop
+ gajim
];
programs.nixcord = {
enable = true;
@@ -51,7 +52,7 @@ in
enable = true;
domain = false;
};
- anammox.enable = true;
+ # anammox.enable = true;
betterGifAltText.enable = true;
# betterGifPicker = {
# enable = true;
@@ -108,14 +109,14 @@ in
preventDuplicates = true;
showCopyImageLink = true;
};
- gifRoulette = {
- enable = true;
- pingOwnerChance = false;
- };
+ # gifRoulette = {
+ # enable = true;
+ # pingOwnerChance = false;
+ # };
guildTagSettings.enable = true;
homeTyping.enable = true;
iLoveSpam.enable = true;
- ignoreTerms.enable = true;
+ # ignoreTerms.enable = true;
imageFilename = {
enable = true;
showFullUrl = true;
@@ -157,7 +158,7 @@ in
};
noF1.enable = true;
noMaskedUrlPaste.enable = true;
- noModalAnimation.enable = true;
+ # noModalAnimation.enable = true;
noMosaic.enable = true;
noNitroUpsell.enable = true;
noOnboardingDelay.enable = true;
diff --git a/hosts/desktop/configuration.nix b/hosts/desktop/configuration.nix
index 69c95da..c0d7cfa 100644
--- a/hosts/desktop/configuration.nix
+++ b/hosts/desktop/configuration.nix
@@ -16,7 +16,7 @@
../../os/default.nix
];
- # hardware.facter.reportPath = /etc/nixos/hosts/desktop/facter.json;
+ # hardware.facter.reportPath = ./facter.json;
os = {
core = {
@@ -39,7 +39,8 @@
enable = true;
amdgpu.enable = true;
};
- kernel = "unstable";
+ # kernel = "unstable";
+ kernel = "stable";
};
fonts.enable = true;
greet.enable = true;
@@ -70,6 +71,7 @@
gaming = {
enable = true;
steam.enable = true;
+ vr.enable = true;
};
virtualization = {
kvm.enable = true;
@@ -77,7 +79,7 @@
};
kdeconnect.enable = true;
nix-helper.enable = true;
- # ollama.enable = true;
+ ollama.enable = true;
monero.enable = true;
sops.enable = true;
syncthing.enable = true;
@@ -89,37 +91,24 @@
};
};
- systemd.services.oci-arm-claimer = {
- description = "OCI ARM Instance Claimer Script";
- after = [ "network.target" ];
- wantedBy = [ "multi-user.target" ];
-
- serviceConfig = {
- WorkingDirectory = "/home/${username}/docs/oci-arm-host-capacity";
-
- ExecStart = "${pkgs.php}/bin/php -d error_reporting='E_ALL & ~E_DEPRECATED' /home/${username}/docs/oci-arm-host-capacity/index.php";
-
- Restart = "always";
- RestartSec = "60";
- User = "${username}";
- };
- path = [
- pkgs.php
- pkgs.php82Packages.composer
- ];
- };
-
services.hardware.openrgb = {
enable = true;
motherboard = "amd";
package = pkgs.openrgb-with-all-plugins;
};
+ systemd.user.services.polkit-gnome-authentication-agent-1 = {
+ description = "polkit-gnome-authentication-agent-1";
+ wantedBy = [ "graphical-session.target" ]; # No 'Install' block, lowercase 'w'
+ serviceConfig = {
+ Type = "simple";
+ ExecStart = "${pkgs.polkit_gnome}/libexec/polkit-gnome-authentication-agent-1";
+ Restart = "on-failure";
+ RestartSec = 1;
+ TimeoutStopSec = 10;
+ };
+ };
boot = {
- kernelParams = [
- "video=DP-1:2560x1440@240"
- "video=DP-2:1920x1080@144"
- ];
kernelModules = [
"nct6687"
"binder_linux"
diff --git a/hosts/desktop/home.nix b/hosts/desktop/home.nix
index 9ca7073..a637d12 100644
--- a/hosts/desktop/home.nix
+++ b/hosts/desktop/home.nix
@@ -23,6 +23,7 @@
};
editors.nixvim.enable = true;
env = {
+ mako.enable = true;
niri.enable = true;
cursor = {
size = 48;
diff --git a/os/core/audio.nix b/os/core/audio.nix
index e677a90..7527501 100644
--- a/os/core/audio.nix
+++ b/os/core/audio.nix
@@ -2,11 +2,19 @@
config,
lib,
pkgs,
- username,
...
}:
let
cfg = config.os.core.audio;
+ toggleMuteNotify = pkgs.writeShellScriptBin "toggle-mute-notify" ''
+ IS_MUTED=$(${pkgs.wireplumber}/bin/wpctl get-volume @DEFAULT_AUDIO_SOURCE@ | grep -c "MUTED")
+
+ if [ "$IS_MUTED" -eq 1 ]; then
+ ${pkgs.libnotify}/bin/notify-send -a "MuteIndicator" -t 0 -u critical "Microphone Muted" "Mic is currently OFF"
+ else
+ ${pkgs.mako}/bin/makoctl dismiss -a "MuteIndicator"
+ fi
+ '';
in
{
options.os.core.audio = {
@@ -30,12 +38,9 @@ in
spotifyd.enable = true;
};
- users.users.${username}.linger = true;
-
security.rtkit.enable = true;
- hardware.enableAllFirmware = true;
-
environment.systemPackages = with pkgs; [
+ toggleMuteNotify
crosspipe
alsa-utils
];
diff --git a/os/core/drivers.nix b/os/core/drivers.nix
index da9d83a..77ea721 100644
--- a/os/core/drivers.nix
+++ b/os/core/drivers.nix
@@ -2,16 +2,21 @@
config,
lib,
pkgs,
- inputs,
...
-}: let
+}:
+let
cfg = config.os.core.drivers;
-in {
+in
+{
options.os.core.drivers = {
enable = lib.mkEnableOption "enables hardware drivers";
cpu = lib.mkOption {
- type = lib.types.enum ["intel" "amd" "none"];
+ type = lib.types.enum [
+ "intel"
+ "amd"
+ "none"
+ ];
default = "none";
description = "cpu manufacturer for microcode and platform-specific drivers";
};
@@ -40,7 +45,7 @@ in {
smartd.enable = true;
fwupd.enable = true;
};
- environment.systemPackages = [pkgs.rivalcfg];
+ environment.systemPackages = [ pkgs.rivalcfg ];
}
(lib.mkIf (cfg.cpu == "amd") {
@@ -57,6 +62,9 @@ in {
hardware.graphics = {
enable = true;
enable32Bit = true;
+ extraPackages = with pkgs; [
+ libva
+ ];
};
hardware.sensor.iio.enable = true;
})
@@ -69,17 +77,20 @@ in {
};
hardware.graphics.extraPackages = with pkgs; [
rocmPackages.clr.icd
+ libva
+ libva-utils
];
})
{
- boot.kernelPackages = let
- kernels = {
- "stable" = pkgs.linuxPackages_latest;
- "zen" = pkgs.linuxPackages_zen;
- "hardened" = pkgs.linuxPackages_hardened;
- "unstable" = inputs.kernelv.legacyPackages.x86_64-linux.linuxPackages_6_17;
- };
- in
+ boot.kernelPackages =
+ let
+ kernels = {
+ "stable" = pkgs.linuxPackages_latest;
+ "zen" = pkgs.linuxPackages_zen;
+ "hardened" = pkgs.linuxPackages_hardened;
+ # "unstable" = pkgs.linuxPackages.;
+ };
+ in
kernels.${cfg.kernel} or kernels."stable";
}
]
diff --git a/os/core/security.nix b/os/core/security.nix
index f1c41c2..afd2b2a 100644
--- a/os/core/security.nix
+++ b/os/core/security.nix
@@ -2,6 +2,7 @@
config,
lib,
pkgs,
+ username,
...
}:
let
@@ -13,6 +14,17 @@ in
services.gnome.gnome-keyring.enable = true;
security = {
+ doas = {
+ enable = true;
+ extraRules = [
+ {
+ users = [ username ];
+ keepEnv = true;
+ persist = true;
+ }
+ ];
+ };
+ # sudo.enable = false;
pam.services = {
swaylock = { };
login.enableGnomeKeyring = true;
@@ -22,13 +34,11 @@ in
};
environment.systemPackages = with pkgs; [
- veracrypt
+ doas-sudo-shim
+ veracrypt
bitwarden-desktop
- keyguard
-
keepassxc
- keepassxc-go
git-credential-keepassxc
];
};
diff --git a/os/srv/gaming.nix b/os/srv/gaming.nix
index 3e2eea4..237098c 100644
--- a/os/srv/gaming.nix
+++ b/os/srv/gaming.nix
@@ -70,7 +70,7 @@ in
localNetworkGameTransfers.openFirewall = true;
dedicatedServer.openFirewall = true;
remotePlay.openFirewall = false;
- extest.enable = true;
+ # extest.enable = true;
protontricks.enable = true;
extraCompatPackages = with pkgs; [
@@ -86,6 +86,8 @@ in
enable = true;
openFirewall = true;
};
+ environment.systemPackages = [ pkgs.android-tools ];
+ users.users.${username}.extraGroups = [ "adbusers" ];
})
];
}
diff --git a/os/srv/sops.nix b/os/srv/sops.nix
index fecb9df..36ab9ef 100644
--- a/os/srv/sops.nix
+++ b/os/srv/sops.nix
@@ -18,7 +18,7 @@ in
};
config = lib.mkIf cfg.enable {
sops = {
- defaultSopsFile = ../../secrets/common.yaml;
+ defaultSopsFile = ../../secrets.yaml;
defaultSopsFormat = "yaml";
age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
@@ -26,12 +26,7 @@ in
"syncthing/gui_password".owner = username;
"syncthing/encryption/game-saves".owner = username;
"syncthing/encryption/keepass".owner = username;
- "vpn/warp_private_key" = {
- owner = "root";
- group = "networkmanager";
- mode = "0400";
- restartUnits = [ "NetworkManager.service" ];
- };
+ "vpn/warp_private_key".owner = "root";
"obs/websocket_password".owner = username;
root_password.neededForUsers = true;
user_password.neededForUsers = true;
diff --git a/scripts/default.nix b/scripts/default.nix
deleted file mode 100644
index 983216d..0000000
--- a/scripts/default.nix
+++ /dev/null
@@ -1,33 +0,0 @@
-{ pkgs }:
-let
- commonInputs = with pkgs; [
- git
- gnupg
- sops
- nix
- coreutils
- util-linux
- nixos-facter
- ];
-in
-{
- install = pkgs.writeShellApplication {
- name = "nixos-install";
- runtimeInputs = commonInputs ++ [ pkgs.disko-install ];
- text = builtins.readFile ./install.sh;
- };
-
- setup = pkgs.writeShellApplication {
- name = "nixos-setup";
- runtimeInputs =
- commonInputs
- ++ (with pkgs; [
- ssh-to-age
- ripgrep
- sd
- nh
- fd
- ]);
- text = builtins.readFile ./setup.sh;
- };
-}
diff --git a/scripts/install.sh b/scripts/install.sh
deleted file mode 100644
index 8a8c3d7..0000000
--- a/scripts/install.sh
+++ /dev/null
@@ -1,88 +0,0 @@
-#!/usr/bin/env bash
-set -euo pipefail
-
-# --- Defaults ---
-HOSTNAME=""
-DISKS=()
-KEY_LOCATION="./private.asc"
-REPO_URL="https://codeberg.org/adikro/nixos-config.git"
-TEMP_CONFIG="/tmp/config/etc/nixos"
-USE_FACTER=true
-WRITE_EFI=true
-
-# --- Parse Arguments ---
-PARSED_ARGS=$(getopt -o h:d:r:k:gn --long hostname:,disk:,repo:,key:,generate-config,no-efi -- "$@")
-eval set -- "$PARSED_ARGS"
-
-while true; do
- case "$1" in
- -h|--hostname) HOSTNAME="$2"; shift 2 ;;
- -d|--disk) DISKS+=("$2"); shift 2 ;;
- -r|--repo) REPO_URL="$2"; shift 2 ;;
- -k|--key) KEY_LOCATION="$2"; shift 2 ;;
- -g|--generate-config) USE_FACTER=false; shift ;;
- -n|--no-efi) WRITE_EFI=false; shift ;;
- --) shift; break ;;
- *) echo "Internal error!"; exit 1 ;;
- esac
-done
-
-# --- Validation ---
-if [[ -z "$HOSTNAME" || ${#DISKS[@]} -eq 0 ]]; then
- echo "Usage: sudo nix run .#install -- -h <name> -d main:/dev/nvme0n1 [-d storage:/dev/sda]"
- exit 1
-fi
-
-if [[ ! -f "$KEY_LOCATION" ]]; then
- echo "Error: Private key not found at $KEY_LOCATION. Cannot proceed without GPG."
- exit 1
-fi
-
-# --- Summary & Confirmation ---
-echo "------------------------------------------------------------"
-echo "INSTALLATION PLAN"
-echo " Hostname: $HOSTNAME"
-echo " Target Disks:"
-for disk in "${DISKS[@]}"; do echo " - $disk"; done
-echo "------------------------------------------------------------"
-read -p "Warning: This will format the disks listed above. Proceed? (y/N): " confirm
-[[ "$confirm" != [yY] ]] && exit 1
-
-echo "### 1. Importing GPG Key ###"
-export GPG_TTY=$(tty)
-gpg --import "$KEY_LOCATION"
-
-echo "### 2. Cloning Configuration ###"
-sudo rm -rf "$TEMP_CONFIG"
-git clone "$REPO_URL" "$TEMP_CONFIG"
-cd "$TEMP_CONFIG"
-
-echo "### 3. Hardware Configuration ###"
-HOST_DIR="./hosts/$HOSTNAME"
-mkdir -p "$HOST_DIR"
-
-if [ "$USE_FACTER" = true ]; then
- nixos-facter -o "$HOST_DIR/facter.json"
- git add "$HOST_DIR/facter.json"
-else
- sudo nixos-generate-config --no-filesystems --root /tmp/nixos-gen-root
- mv /tmp/nixos-gen-root/etc/nixos/hardware-configuration.nix "$HOST_DIR/hardware-configuration.nix"
- git add "$HOST_DIR/hardware-configuration.nix"
-fi
-
-echo "### 4. SOPS Key Extraction ###"
-if printf '%s\n' "${DISKS[@]}" | rg -qv "^main:"; then
- sops -d --extract '["crypt_key"]' secrets/secrets.yaml > /tmp/crypt.key
-fi
-
-echo "### 5. Disko Install ###"
-DISKO_ARGS=(--flake ".#$HOSTNAME")
-for pair in "${DISKS[@]}"; do
- IFS=":" read -r D_NAME D_DEV <<< "$pair"
- DISKO_ARGS+=(--disk "$D_NAME" "$D_DEV")
-done
-[[ "$WRITE_EFI" == true ]] && DISKO_ARGS+=(--write-efi-boot-entries)
-
-sudo disko-install "${DISKO_ARGS[@]}"
-
-echo "INSTALL COMPLETE. Reboot and run setup script."
diff --git a/scripts/setup.sh b/scripts/setup.sh
deleted file mode 100644
index fb9a603..0000000
--- a/scripts/setup.sh
+++ /dev/null
@@ -1,98 +0,0 @@
-#!/usr/bin/env bash
-set -euo pipefail
-
-# --- Defaults ---
-HOSTNAME=$(hostname)
-USB_DEVICE=""
-REPO_URL="git@codeberg.org:adikro/nixos-config.git"
-KEY_LOCATION=""
-USE_FACTER=true
-
-# --- Parse Arguments ---
-PARSED_ARGS=$(getopt -o u:h:r:k:g --long usb:,hostname:,repo:,key:,generate-config -- "$@")
-eval set -- "$PARSED_ARGS"
-
-while true; do
- case "$1" in
- -u|--usb) USB_DEVICE="$2"; shift 2 ;;
- -h|--hostname) HOSTNAME="$2"; shift 2 ;;
- -r|--repo) REPO_URL="$2"; shift 2 ;;
- -k|--key) KEY_LOCATION="$2"; shift 2 ;;
- -g|--generate-config) USE_FACTER=false; shift ;;
- --) shift; break ;;
- *) echo "Internal error!"; exit 1 ;;
- esac
-done
-
-echo "### 1. GPG Key Preparation ###"
-export GPG_TTY=$(tty)
-
-if [[ -n "$KEY_LOCATION" ]]; then
- gpg --import "$KEY_LOCATION"
-elif [[ -n "$USB_DEVICE" ]]; then
- echo "Mounting $USB_DEVICE..."
- sudo mkdir -p /mnt/usb
- findmnt -rno SOURCE "$USB_DEVICE" >/dev/null || sudo mount "$USB_DEVICE" /mnt/usb
-
- echo "Searching USB for private.asc..."
- KEY_FILE=$(sudo fd -H -t f "private.asc" /mnt/usb --max-results 1)
-
- if [[ -n "$KEY_FILE" ]]; then
- KEY_DIR=$(dirname "$KEY_FILE")
- echo "Found keys in $KEY_DIR. Importing..."
- (
- cd "$KEY_DIR"
- gpg --import private.asc
- [[ -f "public.asc" ]] && gpg --import public.asc
- [[ -f "trust.txt" ]] && gpg --import-ownertrust trust.txt
- )
- else
- echo "Error: private.asc not found on $USB_DEVICE"
- sudo umount /mnt/usb; exit 1
- fi
- sudo umount /mnt/usb
-else
- gpg -K | grep -q "sec" || { echo "No keys found. Use --usb or --key."; exit 1; }
-fi
-
-echo "### 2. Repo Setup ###"
-sudo mkdir -p /etc/nixos
-sudo chown -R "$USER":users /etc/nixos
-[[ ! -d "/etc/nixos/.git" ]] && git clone "$REPO_URL" /etc/nixos
-cd /etc/nixos
-
-echo "### 3. Hardware Refresh ###"
-HOST_DIR="./hosts/$HOSTNAME"
-mkdir -p "$HOST_DIR"
-if [ "$USE_FACTER" = true ]; then
- nixos-facter -o "$HOST_DIR/facter.json"
-else
- sudo nixos-generate-config --no-filesystems --root /
- mv /etc/nixos/hardware-configuration.nix "$HOST_DIR/hardware-configuration.nix"
-fi
-
-echo "### 4. SOPS Rotation ###"
-NEW_AGE=$(ssh-to-age < /etc/ssh/ssh_host_ed25519_key.pub)
-if grep -q "&host_$HOSTNAME" .sops.yaml; then
- sd "(&host_$HOSTNAME\s+-) age1.*" "\$1 $NEW_AGE" .sops.yaml
-else
- sd "(keys:\n)" "\$1 - &host_$HOSTNAME $NEW_AGE\n" .sops.yaml
- sd "(age:\n(.*\n)*?\s+age:\n)" "\$1 - *host_$HOSTNAME\n" .sops.yaml
-fi
-
-sops updatekeys secrets/secrets.yaml -y
-
-echo "### 5. System Rebuild ###"
-git add .
-nh os switch . -u -H "$HOSTNAME"
-
-echo "### 6. Git Finalization ###"
-[[ $(git remote) =~ "origin" ]] && git remote rename origin codeberg
-git remote set-url codeberg "$REPO_URL"
-git add .
-git commit -m "chore($HOSTNAME): hardware refresh and sops rotation" || echo "No changes."
-
-read -p "Push to Codeberg? (y/N): " push_confirm
-[[ "$push_confirm" == [yY] ]] && git push -u codeberg main
-
-echo "SETUP COMPLETE. Rebooting is recommended."
diff --git a/secrets/common.yaml b/secrets.yaml
index d4aae53..d4aae53 100644
--- a/secrets/common.yaml
+++ b/secrets.yaml