diff options
| author | adikro <adikro@disroot.org> | 2026-03-13 23:41:17 +0100 |
|---|---|---|
| committer | adikro <adikro@disroot.org> | 2026-03-13 23:41:17 +0100 |
| commit | f0c0e311c003057f24d8045509a627ad2acab978 (patch) | |
| tree | a1955fe601c487aab46fa47838cd25b8273508ac | |
| parent | ffefb53956c38909da77fe7ebbbb5d8b5dd823b9 (diff) | |
removing obsolete stuff
| -rw-r--r-- | .sops.yaml | 2 | ||||
| -rw-r--r-- | flake.lock | 84 | ||||
| -rw-r--r-- | flake.nix | 14 | ||||
| -rw-r--r-- | hm/editors/nixvim/nixvim.nix | 2 | ||||
| -rw-r--r-- | hm/env/env.nix | 1 | ||||
| -rw-r--r-- | hm/env/mako.nix | 15 | ||||
| -rw-r--r-- | hm/env/niri/binds.nix | 14 | ||||
| -rw-r--r-- | hm/shell/foot.nix | 12 | ||||
| -rw-r--r-- | hm/soft/nixcord.nix | 15 | ||||
| -rw-r--r-- | hosts/desktop/configuration.nix | 43 | ||||
| -rw-r--r-- | hosts/desktop/home.nix | 1 | ||||
| -rw-r--r-- | os/core/audio.nix | 15 | ||||
| -rw-r--r-- | os/core/drivers.nix | 37 | ||||
| -rw-r--r-- | os/core/security.nix | 18 | ||||
| -rw-r--r-- | os/srv/gaming.nix | 4 | ||||
| -rw-r--r-- | os/srv/sops.nix | 9 | ||||
| -rw-r--r-- | scripts/default.nix | 33 | ||||
| -rw-r--r-- | scripts/install.sh | 88 | ||||
| -rw-r--r-- | scripts/setup.sh | 98 | ||||
| -rw-r--r-- | secrets.yaml (renamed from secrets/common.yaml) | 0 |
20 files changed, 151 insertions, 354 deletions
@@ -6,7 +6,7 @@ keys: - &host_laptop age1m4u7n6mt5d3jv39lf4aedr9gqu3khl4sahuqx5n5h7v48gkyc9zqkp9qs8 creation_rules: - - path_regex: .*secrets/common\.yaml$ + - path_regex: ^secrets\.yaml$ key_groups: - age: - *host_szpont @@ -136,11 +136,11 @@ ] }, "locked": { - "lastModified": 1773093840, - "narHash": "sha256-u/96NoAyN8BSRuM3ZimGf7vyYgXa3pLx4MYWjokuoH4=", + "lastModified": 1773422513, + "narHash": "sha256-MPjR48roW7CUMU6lu0+qQGqj92Kuh3paIulMWFZy+NQ=", "owner": "nix-community", "repo": "home-manager", - "rev": "bb014746edb2a98d975abde4dd40fa240de4cf86", + "rev": "ef12a9a2b0f77c8fa3dda1e7e494fca668909056", "type": "github" }, "original": { @@ -150,22 +150,6 @@ "type": "github" } }, - "kernelv": { - "locked": { - "lastModified": 1766069213, - "narHash": "sha256-h2501PoQofwr3Ds/O/SHlm/izeKWqnRYuT7Yl5t6ZVI=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "52e64396e98aef211f4127416dbdae17a01b3d3f", - "type": "github" - }, - "original": { - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "52e64396e98aef211f4127416dbdae17a01b3d3f", - "type": "github" - } - }, "neovim-nightly-overlay": { "inputs": { "flake-parts": "flake-parts", @@ -175,11 +159,11 @@ ] }, "locked": { - "lastModified": 1773101084, - "narHash": "sha256-XljZHTJCn26qu7oAgcLq8DtZ+BSbXY3iQ/1ylPsw54I=", + "lastModified": 1773360308, + "narHash": "sha256-Asr6gDwzxvcglRaXEZSTL4lEA6braemURJc6wKBhKrs=", "owner": "nix-community", "repo": "neovim-nightly-overlay", - "rev": "eee7ee7a7936b1aa7f6e5115535f6daf805f6896", + "rev": "b550599eedc54514f5b71cee8e480e337d104d84", "type": "github" }, "original": { @@ -191,11 +175,11 @@ "neovim-src": { "flake": false, "locked": { - "lastModified": 1773098641, - "narHash": "sha256-tgtRikZ+jtvdHiUSFpXq+AKFV0nvPDlEyxlGG9CCAOU=", + "lastModified": 1773359104, + "narHash": "sha256-vWu0zLThxpsx6vbPK5eAgvkMKu1LV8tbybS/sjWn8S8=", "owner": "neovim", "repo": "neovim", - "rev": "a81b059a45ba832f9ad0bdb1b37b7519e5922cac", + "rev": "957eb1fde04496b4a2c07fd8427a8d78844d1bf7", "type": "github" }, "original": { @@ -216,11 +200,11 @@ "xwayland-satellite-unstable": "xwayland-satellite-unstable" }, "locked": { - "lastModified": 1773170801, - "narHash": "sha256-TB9/4xKh8tZcbOtxlHB24EO4NlEIorxtcL3L7LOWLqA=", + "lastModified": 1773433102, + "narHash": "sha256-0q2Uz4oNTX0+dIpN3zV2HLMHI8NOoRDwScatBS1v8ng=", "owner": "sodiboo", "repo": "niri-flake", - "rev": "5336c8d137d1a3ad055e83fa08dcb17c1f2b9444", + "rev": "20f866c7416799ebf5b88b07c9d32c6a440e825d", "type": "github" }, "original": { @@ -268,14 +252,15 @@ "flake-parts": "flake-parts_2", "nixpkgs": [ "nixpkgs" - ] + ], + "nixpkgs-nixcord": "nixpkgs-nixcord" }, "locked": { - "lastModified": 1773144845, - "narHash": "sha256-bU+q8v1xjbYEjWaqCL1P5y/mloSqXGkGot5MZhLCSf4=", + "lastModified": 1773426551, + "narHash": "sha256-xkdf5jU1HDphAFy89WQsyStYdq0EjRsYCYsz5IrDEjo=", "owner": "KaylorBen", "repo": "nixcord", - "rev": "df70a89c4aaf0bfaf419e1deafd43e92e9c98430", + "rev": "efe6a34e34d5ab0983d26ca290e5e0dba6e1abd1", "type": "github" }, "original": { @@ -302,11 +287,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1772963539, - "narHash": "sha256-9jVDGZnvCckTGdYT53d/EfznygLskyLQXYwJLKMPsZs=", + "lastModified": 1773282481, + "narHash": "sha256-b/GV2ysM8mKHhinse2wz+uP37epUrSE+sAKXy/xvBY4=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "9dcb002ca1690658be4a04645215baea8b95f31d", + "rev": "fe416aaedd397cacb33a610b33d60ff2b431b127", "type": "github" }, "original": { @@ -331,13 +316,29 @@ "type": "github" } }, + "nixpkgs-nixcord": { + "locked": { + "lastModified": 1773222311, + "narHash": "sha256-BHoB/XpbqoZkVYZCfXJXfkR+GXFqwb/4zbWnOr2cRcU=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "0590cd39f728e129122770c029970378a79d076a", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-25.11", + "repo": "nixpkgs", + "type": "github" + } + }, "nixpkgs-stable": { "locked": { - "lastModified": 1773068389, - "narHash": "sha256-vMrm7Pk2hjBRPnCSjhq1pH0bg350Z+pXhqZ9ICiqqCs=", + "lastModified": 1773375660, + "narHash": "sha256-SEzUWw2Rf5Ki3bcM26nSKgbeoqi2uYy8IHVBqOKjX3w=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "44bae273f9f82d480273bab26f5c50de3724f52f", + "rev": "3e20095fe3c6cbb1ddcef89b26969a69a1570776", "type": "github" }, "original": { @@ -389,7 +390,6 @@ "inputs": { "disko": "disko", "home-manager": "home-manager", - "kernelv": "kernelv", "neovim-nightly-overlay": "neovim-nightly-overlay", "niri": "niri", "nixcord": "nixcord", @@ -612,11 +612,11 @@ "rust-overlay": "rust-overlay_2" }, "locked": { - "lastModified": 1773118567, - "narHash": "sha256-fPMoWlLZIagImpv45pIs/KJ/jGfaH9Srm74iSSCadYI=", + "lastModified": 1773404924, + "narHash": "sha256-HczaRbfStxmt83umm0Eiie8ECdUELPAcoH/q/DdYpss=", "owner": "sxyazi", "repo": "yazi", - "rev": "dee27a237788d99c0c2dc6d76c95dd3e10b3fba6", + "rev": "fa1ee46edce52e0d3bc0c4179b9d65ca46b1efbd", "type": "github" }, "original": { @@ -4,9 +4,6 @@ inputs = { nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; - # Snapshot of nixpkgs with the 6.17.13 kernel for compatibility - kernelv.url = "github:NixOS/nixpkgs/52e64396e98aef211f4127416dbdae17a01b3d3f"; - nixos-hardware.url = "github:NixOS/nixos-hardware/master"; sops-nix = { @@ -68,7 +65,6 @@ outputs = { self, nixpkgs, ... }@inputs: let - scripts = import ./scripts; mkHost = { hostname, @@ -87,16 +83,6 @@ }; in { - apps."x86_64-linux" = { - install = { - type = "app"; - program = "${scripts.install}/bin/nixos-install"; - }; - setup = { - type = "app"; - program = "${scripts.setup}/bin/nixos-setup"; - }; - }; nixosConfigurations = { szpont = mkHost { hostname = "szpont"; diff --git a/hm/editors/nixvim/nixvim.nix b/hm/editors/nixvim/nixvim.nix index 068012f..835556a 100644 --- a/hm/editors/nixvim/nixvim.nix +++ b/hm/editors/nixvim/nixvim.nix @@ -260,7 +260,7 @@ in lsp = { enable = true; servers = { - # zls.enable = true; + zls.enable = true; nil_ls.enable = true; clangd.enable = true; }; diff --git a/hm/env/env.nix b/hm/env/env.nix index 80e19f8..a5caec2 100644 --- a/hm/env/env.nix +++ b/hm/env/env.nix @@ -11,5 +11,6 @@ ./swaylock.nix ./theme.nix ./waybar.nix + ./mako.nix ]; } diff --git a/hm/env/mako.nix b/hm/env/mako.nix new file mode 100644 index 0000000..3f9e3ef --- /dev/null +++ b/hm/env/mako.nix @@ -0,0 +1,15 @@ +{ config, lib, ... }: +let + cfg = config.hm.env.mako; +in +{ + options.hm.env.mako.enable = lib.mkEnableOption "enables mako notifications"; + config = lib.mkIf cfg.enable { + services.mako = { + enable = true; + settings = { + + }; + }; + }; +} diff --git a/hm/env/niri/binds.nix b/hm/env/niri/binds.nix index c071d2e..ff8353e 100644 --- a/hm/env/niri/binds.nix +++ b/hm/env/niri/binds.nix @@ -9,7 +9,7 @@ with config.lib.niri.actions; let playerctl = spawn "${pkgs.playerctl}/bin/playerctl"; ssPath = "${toString config.hm.conf.xdg-dirs.storagePath}/pics/ss/$(date +%Y-%m-%d_%H-%M-%S)"; - # obsPass = osConfig.sops.secrets."obs/websocket_password".path; + obsPass = osConfig.sops.secrets."obs/websocket_password".path; in { # --- System & Media --- @@ -21,7 +21,7 @@ in XF86AudioLowerVolume.action = spawn "wpctl" "set-volume" "@DEFAULT_AUDIO_SINK@" "3%-"; XF86AudioMute.action = spawn "sh" "-c" - "wpctl set-mute @DEFAULT_AUDIO_SINK@ toggle && wpctl set-mute @DEFAULT_AUDIO_SOURCE@ toggle"; + "wpctl set-mute @DEFAULT_AUDIO_SINK@ toggle && wpctl set-mute @DEFAULT_AUDIO_SOURCE@ toggle && toggle-mute-notify"; # Media Control XF86AudioPlay.action = playerctl "play-pause"; @@ -29,14 +29,14 @@ in XF86AudioNext.action = playerctl "next"; # Brightness - XF86MonBrightnessUp.action = spawn "light" "-A" "10"; - XF86MonBrightnessDown.action = spawn "light" "-U" "10"; + XF86MonBrightnessUp.action = spawn "brightnessctl" "set" "5%+"; + XF86MonBrightnessDown.action = spawn "brightnessctl" "set" "5%-"; # --- Applications --- "Mod+Return".action = spawn "footclient"; "Mod+D".action = spawn "fuzzel"; "Mod+Shift+D".action = spawn "sh" "-c" "cliphist list | fuzzel --dmenu | cliphist decode | wl-copy"; - # "Super+Return".action = spawn "sh" "-c" "OBS_WEBSOCKET_URL=$(cat ${obsPass}) obs-cmd replay save"; + "Super+Return".action = spawn "sh" "-c" "OBS_WEBSOCKET_URL=$(cat ${obsPass}) obs-cmd replay save"; "Super+C".action = spawn "qalculate-gtk"; "Super+D".action = spawn "equibop"; @@ -68,6 +68,10 @@ in }; XF86Tools = { + action = spawn "sh" "-c" "wpctl set-mute @DEFAULT_AUDIO_SOURCE@ toggle && toggle-mute-notify"; + repeat = false; + }; + "Mod+XF86Tools" = { action = spawn "sh" "-c" "niri msg action set-dynamic-cast-window --id $(niri msg --json pick-window | ${pkgs.jq}/bin/jq .id)"; diff --git a/hm/shell/foot.nix b/hm/shell/foot.nix index 91dbfa0..1a86474 100644 --- a/hm/shell/foot.nix +++ b/hm/shell/foot.nix @@ -8,14 +8,10 @@ let cfg = config.hm.shell.foot; - footTheme = pkgs.runCommand "gruvbox-dark" { } '' - sed -e 's/\[colors-dark\]/\[colors\]/g' ${ - pkgs.fetchurl { - url = "https://codeberg.org/dnkl/foot/raw/branch/master/themes/gruvbox-dark"; - sha256 = "sha256-hlmLklG/vAEDy8I+k13+o4ZR6Cq6lTxOconjf9M75eo="; - } - } > $out - ''; + footTheme = pkgs.fetchurl { + url = "https://codeberg.org/dnkl/foot/raw/branch/master/themes/gruvbox-dark"; + sha256 = "sha256-hlmLklG/vAEDy8I+k13+o4ZR6Cq6lTxOconjf9M75eo="; + }; in { options.hm.shell.foot = { diff --git a/hm/soft/nixcord.nix b/hm/soft/nixcord.nix index 8e5ae12..a929b2e 100644 --- a/hm/soft/nixcord.nix +++ b/hm/soft/nixcord.nix @@ -16,6 +16,7 @@ in home.packages = with pkgs; [ stoat-desktop element-desktop + gajim ]; programs.nixcord = { enable = true; @@ -51,7 +52,7 @@ in enable = true; domain = false; }; - anammox.enable = true; + # anammox.enable = true; betterGifAltText.enable = true; # betterGifPicker = { # enable = true; @@ -108,14 +109,14 @@ in preventDuplicates = true; showCopyImageLink = true; }; - gifRoulette = { - enable = true; - pingOwnerChance = false; - }; + # gifRoulette = { + # enable = true; + # pingOwnerChance = false; + # }; guildTagSettings.enable = true; homeTyping.enable = true; iLoveSpam.enable = true; - ignoreTerms.enable = true; + # ignoreTerms.enable = true; imageFilename = { enable = true; showFullUrl = true; @@ -157,7 +158,7 @@ in }; noF1.enable = true; noMaskedUrlPaste.enable = true; - noModalAnimation.enable = true; + # noModalAnimation.enable = true; noMosaic.enable = true; noNitroUpsell.enable = true; noOnboardingDelay.enable = true; diff --git a/hosts/desktop/configuration.nix b/hosts/desktop/configuration.nix index 69c95da..c0d7cfa 100644 --- a/hosts/desktop/configuration.nix +++ b/hosts/desktop/configuration.nix @@ -16,7 +16,7 @@ ../../os/default.nix ]; - # hardware.facter.reportPath = /etc/nixos/hosts/desktop/facter.json; + # hardware.facter.reportPath = ./facter.json; os = { core = { @@ -39,7 +39,8 @@ enable = true; amdgpu.enable = true; }; - kernel = "unstable"; + # kernel = "unstable"; + kernel = "stable"; }; fonts.enable = true; greet.enable = true; @@ -70,6 +71,7 @@ gaming = { enable = true; steam.enable = true; + vr.enable = true; }; virtualization = { kvm.enable = true; @@ -77,7 +79,7 @@ }; kdeconnect.enable = true; nix-helper.enable = true; - # ollama.enable = true; + ollama.enable = true; monero.enable = true; sops.enable = true; syncthing.enable = true; @@ -89,37 +91,24 @@ }; }; - systemd.services.oci-arm-claimer = { - description = "OCI ARM Instance Claimer Script"; - after = [ "network.target" ]; - wantedBy = [ "multi-user.target" ]; - - serviceConfig = { - WorkingDirectory = "/home/${username}/docs/oci-arm-host-capacity"; - - ExecStart = "${pkgs.php}/bin/php -d error_reporting='E_ALL & ~E_DEPRECATED' /home/${username}/docs/oci-arm-host-capacity/index.php"; - - Restart = "always"; - RestartSec = "60"; - User = "${username}"; - }; - path = [ - pkgs.php - pkgs.php82Packages.composer - ]; - }; - services.hardware.openrgb = { enable = true; motherboard = "amd"; package = pkgs.openrgb-with-all-plugins; }; + systemd.user.services.polkit-gnome-authentication-agent-1 = { + description = "polkit-gnome-authentication-agent-1"; + wantedBy = [ "graphical-session.target" ]; # No 'Install' block, lowercase 'w' + serviceConfig = { + Type = "simple"; + ExecStart = "${pkgs.polkit_gnome}/libexec/polkit-gnome-authentication-agent-1"; + Restart = "on-failure"; + RestartSec = 1; + TimeoutStopSec = 10; + }; + }; boot = { - kernelParams = [ - "video=DP-1:2560x1440@240" - "video=DP-2:1920x1080@144" - ]; kernelModules = [ "nct6687" "binder_linux" diff --git a/hosts/desktop/home.nix b/hosts/desktop/home.nix index 9ca7073..a637d12 100644 --- a/hosts/desktop/home.nix +++ b/hosts/desktop/home.nix @@ -23,6 +23,7 @@ }; editors.nixvim.enable = true; env = { + mako.enable = true; niri.enable = true; cursor = { size = 48; diff --git a/os/core/audio.nix b/os/core/audio.nix index e677a90..7527501 100644 --- a/os/core/audio.nix +++ b/os/core/audio.nix @@ -2,11 +2,19 @@ config, lib, pkgs, - username, ... }: let cfg = config.os.core.audio; + toggleMuteNotify = pkgs.writeShellScriptBin "toggle-mute-notify" '' + IS_MUTED=$(${pkgs.wireplumber}/bin/wpctl get-volume @DEFAULT_AUDIO_SOURCE@ | grep -c "MUTED") + + if [ "$IS_MUTED" -eq 1 ]; then + ${pkgs.libnotify}/bin/notify-send -a "MuteIndicator" -t 0 -u critical "Microphone Muted" "Mic is currently OFF" + else + ${pkgs.mako}/bin/makoctl dismiss -a "MuteIndicator" + fi + ''; in { options.os.core.audio = { @@ -30,12 +38,9 @@ in spotifyd.enable = true; }; - users.users.${username}.linger = true; - security.rtkit.enable = true; - hardware.enableAllFirmware = true; - environment.systemPackages = with pkgs; [ + toggleMuteNotify crosspipe alsa-utils ]; diff --git a/os/core/drivers.nix b/os/core/drivers.nix index da9d83a..77ea721 100644 --- a/os/core/drivers.nix +++ b/os/core/drivers.nix @@ -2,16 +2,21 @@ config, lib, pkgs, - inputs, ... -}: let +}: +let cfg = config.os.core.drivers; -in { +in +{ options.os.core.drivers = { enable = lib.mkEnableOption "enables hardware drivers"; cpu = lib.mkOption { - type = lib.types.enum ["intel" "amd" "none"]; + type = lib.types.enum [ + "intel" + "amd" + "none" + ]; default = "none"; description = "cpu manufacturer for microcode and platform-specific drivers"; }; @@ -40,7 +45,7 @@ in { smartd.enable = true; fwupd.enable = true; }; - environment.systemPackages = [pkgs.rivalcfg]; + environment.systemPackages = [ pkgs.rivalcfg ]; } (lib.mkIf (cfg.cpu == "amd") { @@ -57,6 +62,9 @@ in { hardware.graphics = { enable = true; enable32Bit = true; + extraPackages = with pkgs; [ + libva + ]; }; hardware.sensor.iio.enable = true; }) @@ -69,17 +77,20 @@ in { }; hardware.graphics.extraPackages = with pkgs; [ rocmPackages.clr.icd + libva + libva-utils ]; }) { - boot.kernelPackages = let - kernels = { - "stable" = pkgs.linuxPackages_latest; - "zen" = pkgs.linuxPackages_zen; - "hardened" = pkgs.linuxPackages_hardened; - "unstable" = inputs.kernelv.legacyPackages.x86_64-linux.linuxPackages_6_17; - }; - in + boot.kernelPackages = + let + kernels = { + "stable" = pkgs.linuxPackages_latest; + "zen" = pkgs.linuxPackages_zen; + "hardened" = pkgs.linuxPackages_hardened; + # "unstable" = pkgs.linuxPackages.; + }; + in kernels.${cfg.kernel} or kernels."stable"; } ] diff --git a/os/core/security.nix b/os/core/security.nix index f1c41c2..afd2b2a 100644 --- a/os/core/security.nix +++ b/os/core/security.nix @@ -2,6 +2,7 @@ config, lib, pkgs, + username, ... }: let @@ -13,6 +14,17 @@ in services.gnome.gnome-keyring.enable = true; security = { + doas = { + enable = true; + extraRules = [ + { + users = [ username ]; + keepEnv = true; + persist = true; + } + ]; + }; + # sudo.enable = false; pam.services = { swaylock = { }; login.enableGnomeKeyring = true; @@ -22,13 +34,11 @@ in }; environment.systemPackages = with pkgs; [ - veracrypt + doas-sudo-shim + veracrypt bitwarden-desktop - keyguard - keepassxc - keepassxc-go git-credential-keepassxc ]; }; diff --git a/os/srv/gaming.nix b/os/srv/gaming.nix index 3e2eea4..237098c 100644 --- a/os/srv/gaming.nix +++ b/os/srv/gaming.nix @@ -70,7 +70,7 @@ in localNetworkGameTransfers.openFirewall = true; dedicatedServer.openFirewall = true; remotePlay.openFirewall = false; - extest.enable = true; + # extest.enable = true; protontricks.enable = true; extraCompatPackages = with pkgs; [ @@ -86,6 +86,8 @@ in enable = true; openFirewall = true; }; + environment.systemPackages = [ pkgs.android-tools ]; + users.users.${username}.extraGroups = [ "adbusers" ]; }) ]; } diff --git a/os/srv/sops.nix b/os/srv/sops.nix index fecb9df..36ab9ef 100644 --- a/os/srv/sops.nix +++ b/os/srv/sops.nix @@ -18,7 +18,7 @@ in }; config = lib.mkIf cfg.enable { sops = { - defaultSopsFile = ../../secrets/common.yaml; + defaultSopsFile = ../../secrets.yaml; defaultSopsFormat = "yaml"; age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; @@ -26,12 +26,7 @@ in "syncthing/gui_password".owner = username; "syncthing/encryption/game-saves".owner = username; "syncthing/encryption/keepass".owner = username; - "vpn/warp_private_key" = { - owner = "root"; - group = "networkmanager"; - mode = "0400"; - restartUnits = [ "NetworkManager.service" ]; - }; + "vpn/warp_private_key".owner = "root"; "obs/websocket_password".owner = username; root_password.neededForUsers = true; user_password.neededForUsers = true; diff --git a/scripts/default.nix b/scripts/default.nix deleted file mode 100644 index 983216d..0000000 --- a/scripts/default.nix +++ /dev/null @@ -1,33 +0,0 @@ -{ pkgs }: -let - commonInputs = with pkgs; [ - git - gnupg - sops - nix - coreutils - util-linux - nixos-facter - ]; -in -{ - install = pkgs.writeShellApplication { - name = "nixos-install"; - runtimeInputs = commonInputs ++ [ pkgs.disko-install ]; - text = builtins.readFile ./install.sh; - }; - - setup = pkgs.writeShellApplication { - name = "nixos-setup"; - runtimeInputs = - commonInputs - ++ (with pkgs; [ - ssh-to-age - ripgrep - sd - nh - fd - ]); - text = builtins.readFile ./setup.sh; - }; -} diff --git a/scripts/install.sh b/scripts/install.sh deleted file mode 100644 index 8a8c3d7..0000000 --- a/scripts/install.sh +++ /dev/null @@ -1,88 +0,0 @@ -#!/usr/bin/env bash -set -euo pipefail - -# --- Defaults --- -HOSTNAME="" -DISKS=() -KEY_LOCATION="./private.asc" -REPO_URL="https://codeberg.org/adikro/nixos-config.git" -TEMP_CONFIG="/tmp/config/etc/nixos" -USE_FACTER=true -WRITE_EFI=true - -# --- Parse Arguments --- -PARSED_ARGS=$(getopt -o h:d:r:k:gn --long hostname:,disk:,repo:,key:,generate-config,no-efi -- "$@") -eval set -- "$PARSED_ARGS" - -while true; do - case "$1" in - -h|--hostname) HOSTNAME="$2"; shift 2 ;; - -d|--disk) DISKS+=("$2"); shift 2 ;; - -r|--repo) REPO_URL="$2"; shift 2 ;; - -k|--key) KEY_LOCATION="$2"; shift 2 ;; - -g|--generate-config) USE_FACTER=false; shift ;; - -n|--no-efi) WRITE_EFI=false; shift ;; - --) shift; break ;; - *) echo "Internal error!"; exit 1 ;; - esac -done - -# --- Validation --- -if [[ -z "$HOSTNAME" || ${#DISKS[@]} -eq 0 ]]; then - echo "Usage: sudo nix run .#install -- -h <name> -d main:/dev/nvme0n1 [-d storage:/dev/sda]" - exit 1 -fi - -if [[ ! -f "$KEY_LOCATION" ]]; then - echo "Error: Private key not found at $KEY_LOCATION. Cannot proceed without GPG." - exit 1 -fi - -# --- Summary & Confirmation --- -echo "------------------------------------------------------------" -echo "INSTALLATION PLAN" -echo " Hostname: $HOSTNAME" -echo " Target Disks:" -for disk in "${DISKS[@]}"; do echo " - $disk"; done -echo "------------------------------------------------------------" -read -p "Warning: This will format the disks listed above. Proceed? (y/N): " confirm -[[ "$confirm" != [yY] ]] && exit 1 - -echo "### 1. Importing GPG Key ###" -export GPG_TTY=$(tty) -gpg --import "$KEY_LOCATION" - -echo "### 2. Cloning Configuration ###" -sudo rm -rf "$TEMP_CONFIG" -git clone "$REPO_URL" "$TEMP_CONFIG" -cd "$TEMP_CONFIG" - -echo "### 3. Hardware Configuration ###" -HOST_DIR="./hosts/$HOSTNAME" -mkdir -p "$HOST_DIR" - -if [ "$USE_FACTER" = true ]; then - nixos-facter -o "$HOST_DIR/facter.json" - git add "$HOST_DIR/facter.json" -else - sudo nixos-generate-config --no-filesystems --root /tmp/nixos-gen-root - mv /tmp/nixos-gen-root/etc/nixos/hardware-configuration.nix "$HOST_DIR/hardware-configuration.nix" - git add "$HOST_DIR/hardware-configuration.nix" -fi - -echo "### 4. SOPS Key Extraction ###" -if printf '%s\n' "${DISKS[@]}" | rg -qv "^main:"; then - sops -d --extract '["crypt_key"]' secrets/secrets.yaml > /tmp/crypt.key -fi - -echo "### 5. Disko Install ###" -DISKO_ARGS=(--flake ".#$HOSTNAME") -for pair in "${DISKS[@]}"; do - IFS=":" read -r D_NAME D_DEV <<< "$pair" - DISKO_ARGS+=(--disk "$D_NAME" "$D_DEV") -done -[[ "$WRITE_EFI" == true ]] && DISKO_ARGS+=(--write-efi-boot-entries) - -sudo disko-install "${DISKO_ARGS[@]}" - -echo "INSTALL COMPLETE. Reboot and run setup script." diff --git a/scripts/setup.sh b/scripts/setup.sh deleted file mode 100644 index fb9a603..0000000 --- a/scripts/setup.sh +++ /dev/null @@ -1,98 +0,0 @@ -#!/usr/bin/env bash -set -euo pipefail - -# --- Defaults --- -HOSTNAME=$(hostname) -USB_DEVICE="" -REPO_URL="git@codeberg.org:adikro/nixos-config.git" -KEY_LOCATION="" -USE_FACTER=true - -# --- Parse Arguments --- -PARSED_ARGS=$(getopt -o u:h:r:k:g --long usb:,hostname:,repo:,key:,generate-config -- "$@") -eval set -- "$PARSED_ARGS" - -while true; do - case "$1" in - -u|--usb) USB_DEVICE="$2"; shift 2 ;; - -h|--hostname) HOSTNAME="$2"; shift 2 ;; - -r|--repo) REPO_URL="$2"; shift 2 ;; - -k|--key) KEY_LOCATION="$2"; shift 2 ;; - -g|--generate-config) USE_FACTER=false; shift ;; - --) shift; break ;; - *) echo "Internal error!"; exit 1 ;; - esac -done - -echo "### 1. GPG Key Preparation ###" -export GPG_TTY=$(tty) - -if [[ -n "$KEY_LOCATION" ]]; then - gpg --import "$KEY_LOCATION" -elif [[ -n "$USB_DEVICE" ]]; then - echo "Mounting $USB_DEVICE..." - sudo mkdir -p /mnt/usb - findmnt -rno SOURCE "$USB_DEVICE" >/dev/null || sudo mount "$USB_DEVICE" /mnt/usb - - echo "Searching USB for private.asc..." - KEY_FILE=$(sudo fd -H -t f "private.asc" /mnt/usb --max-results 1) - - if [[ -n "$KEY_FILE" ]]; then - KEY_DIR=$(dirname "$KEY_FILE") - echo "Found keys in $KEY_DIR. Importing..." - ( - cd "$KEY_DIR" - gpg --import private.asc - [[ -f "public.asc" ]] && gpg --import public.asc - [[ -f "trust.txt" ]] && gpg --import-ownertrust trust.txt - ) - else - echo "Error: private.asc not found on $USB_DEVICE" - sudo umount /mnt/usb; exit 1 - fi - sudo umount /mnt/usb -else - gpg -K | grep -q "sec" || { echo "No keys found. Use --usb or --key."; exit 1; } -fi - -echo "### 2. Repo Setup ###" -sudo mkdir -p /etc/nixos -sudo chown -R "$USER":users /etc/nixos -[[ ! -d "/etc/nixos/.git" ]] && git clone "$REPO_URL" /etc/nixos -cd /etc/nixos - -echo "### 3. Hardware Refresh ###" -HOST_DIR="./hosts/$HOSTNAME" -mkdir -p "$HOST_DIR" -if [ "$USE_FACTER" = true ]; then - nixos-facter -o "$HOST_DIR/facter.json" -else - sudo nixos-generate-config --no-filesystems --root / - mv /etc/nixos/hardware-configuration.nix "$HOST_DIR/hardware-configuration.nix" -fi - -echo "### 4. SOPS Rotation ###" -NEW_AGE=$(ssh-to-age < /etc/ssh/ssh_host_ed25519_key.pub) -if grep -q "&host_$HOSTNAME" .sops.yaml; then - sd "(&host_$HOSTNAME\s+-) age1.*" "\$1 $NEW_AGE" .sops.yaml -else - sd "(keys:\n)" "\$1 - &host_$HOSTNAME $NEW_AGE\n" .sops.yaml - sd "(age:\n(.*\n)*?\s+age:\n)" "\$1 - *host_$HOSTNAME\n" .sops.yaml -fi - -sops updatekeys secrets/secrets.yaml -y - -echo "### 5. System Rebuild ###" -git add . -nh os switch . -u -H "$HOSTNAME" - -echo "### 6. Git Finalization ###" -[[ $(git remote) =~ "origin" ]] && git remote rename origin codeberg -git remote set-url codeberg "$REPO_URL" -git add . -git commit -m "chore($HOSTNAME): hardware refresh and sops rotation" || echo "No changes." - -read -p "Push to Codeberg? (y/N): " push_confirm -[[ "$push_confirm" == [yY] ]] && git push -u codeberg main - -echo "SETUP COMPLETE. Rebooting is recommended." diff --git a/secrets/common.yaml b/secrets.yaml index d4aae53..d4aae53 100644 --- a/secrets/common.yaml +++ b/secrets.yaml |
