From 1ff6f0eb48961e6482ec1b7d0dd9b606e85ddc79 Mon Sep 17 00:00:00 2001 From: adikro Date: Thu, 12 Feb 2026 00:41:07 +0100 Subject: disko and bootloader changes --- flake.lock | 83 +++++++++++++--------- flake.nix | 2 + hosts/desktop/configuration.nix | 12 +++- hosts/desktop/disko.nix | 44 +++++------- hosts/laptop/configuration.nix | 9 ++- hosts/thinkpad/configuration.nix | 16 +++-- hosts/thinkpad/disko.nix | 150 ++++++++++++++++++++++++++++++++++++--- os/core/bootloader.nix | 106 +++++++++++++-------------- os/core/power.nix | 64 +++++++++-------- scripts/install.sh | 101 ++++++++++++++++++++++++++ scripts/setup.sh | 22 ++++++ 11 files changed, 446 insertions(+), 163 deletions(-) create mode 100644 scripts/install.sh create mode 100644 scripts/setup.sh diff --git a/flake.lock b/flake.lock index 50e56e5..a27060d 100644 --- a/flake.lock +++ b/flake.lock @@ -77,11 +77,11 @@ "nixpkgs-lib": "nixpkgs-lib" }, "locked": { - "lastModified": 1768135262, - "narHash": "sha256-PVvu7OqHBGWN16zSi6tEmPwwHQ4rLPU9Plvs8/1TUBY=", + "lastModified": 1769996383, + "narHash": "sha256-AnYjnFWgS49RlqX7LrC4uA+sCCDBj0Ry/WOJ5XWAsa0=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "80daad04eddbbf5a4d883996a73f3f542fa437ac", + "rev": "57928607ea566b5db3ad13af0e57e921e6b12381", "type": "github" }, "original": { @@ -136,11 +136,11 @@ ] }, "locked": { - "lastModified": 1770654520, - "narHash": "sha256-mg5WZMIPGsFu9MxSrUcuJUPMbfMsF77el5yb/7rc10k=", + "lastModified": 1770818644, + "narHash": "sha256-DYS4jIRpRoKOzJjnR/QqEd/MlT4OZZpt8CrBLv+cjsE=", "owner": "nix-community", "repo": "home-manager", - "rev": "6c4fdbe1ad198fac36c320fd45c5957324a80b8e", + "rev": "0acbd1180697de56724821184ad2c3e6e7202cd7", "type": "github" }, "original": { @@ -175,11 +175,11 @@ ] }, "locked": { - "lastModified": 1770681890, - "narHash": "sha256-ommto8XEvGMYGuvrIjj2VM1tFZkRoLLmSuie+fvTTOk=", + "lastModified": 1770768285, + "narHash": "sha256-VHslWcx9wSkWgGKnZwFa9TgsY7pmDBZ5mIdRAXLKViI=", "owner": "nix-community", "repo": "neovim-nightly-overlay", - "rev": "3560c52c15aad8fccd4f62ae794b622969050202", + "rev": "2934421063ec25f994956a892ce3603d73254b3d", "type": "github" }, "original": { @@ -191,11 +191,11 @@ "neovim-src": { "flake": false, "locked": { - "lastModified": 1770678367, - "narHash": "sha256-suvGeMX6UQdyGuSNRLH4zJ25b72XfQBDva7Fxm+PNiA=", + "lastModified": 1770763009, + "narHash": "sha256-oJCLtEd9uRG9mLdH/QYrpeZyr4UhE0WXBrsxKd/lcVU=", "owner": "neovim", "repo": "neovim", - "rev": "57fc77ed29ad9005d893a9dc2f37b3ad53aec4e6", + "rev": "1e9143879d6b05bf7e4ed2a59d64d18418d2594f", "type": "github" }, "original": { @@ -216,11 +216,11 @@ "xwayland-satellite-unstable": "xwayland-satellite-unstable" }, "locked": { - "lastModified": 1770739738, - "narHash": "sha256-sLpvik461SjSY1b23gHhNbM9aMJF9iU4h2vPepi9JoM=", + "lastModified": 1770844822, + "narHash": "sha256-QgJZ+W6YE6nAzO/m7ezamAzr9DTflIEXRozMivL0+hc=", "owner": "sodiboo", "repo": "niri-flake", - "rev": "9e23010320cfe4012adc2d8810495bad0fe2d4a6", + "rev": "7634add8bf2dd225d04f535de4bd0ee60982f367", "type": "github" }, "original": { @@ -271,11 +271,11 @@ ] }, "locked": { - "lastModified": 1770711111, - "narHash": "sha256-fwqwewKc+TGDz593PzfA3YCzZRYdmYDWk6pRTaRNPWg=", + "lastModified": 1770761134, + "narHash": "sha256-65Xg7Rfx9Cj/D+OUF7KZUcYSQPbToBDZpqUfFUAKuwc=", "owner": "KaylorBen", "repo": "nixcord", - "rev": "b3f36f48d83a78653b86b4fe997ff1fccae38c6d", + "rev": "f77d6e05efd34581cbc30e7f426496285711bcde", "type": "github" }, "original": { @@ -284,6 +284,22 @@ "type": "github" } }, + "nixos-hardware": { + "locked": { + "lastModified": 1770631810, + "narHash": "sha256-b7iK/x+zOXbjhRqa+XBlYla4zFvPZyU5Ln2HJkiSnzc=", + "owner": "NixOS", + "repo": "nixos-hardware", + "rev": "2889685785848de940375bf7fea5e7c5a3c8d502", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "master", + "repo": "nixos-hardware", + "type": "github" + } + }, "nixpkgs": { "locked": { "lastModified": 1770562336, @@ -302,11 +318,11 @@ }, "nixpkgs-lib": { "locked": { - "lastModified": 1765674936, - "narHash": "sha256-k00uTP4JNfmejrCLJOwdObYC9jHRrr/5M/a/8L2EIdo=", + "lastModified": 1769909678, + "narHash": "sha256-cBEymOf4/o3FD5AZnzC3J9hLbiZ+QDT/KDuyHXVJOpM=", "owner": "nix-community", "repo": "nixpkgs.lib", - "rev": "2075416fcb47225d9b68ac469a5c4801a9c4dd85", + "rev": "72716169fe93074c333e8d0173151350670b824c", "type": "github" }, "original": { @@ -317,11 +333,11 @@ }, "nixpkgs-stable": { "locked": { - "lastModified": 1770617025, - "narHash": "sha256-1jZvgZoAagZZB6NwGRv2T2ezPy+X6EFDsJm+YSlsvEs=", + "lastModified": 1770770419, + "narHash": "sha256-iKZMkr6Cm9JzWlRYW/VPoL0A9jVKtZYiU4zSrVeetIs=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "2db38e08fdadcc0ce3232f7279bab59a15b94482", + "rev": "6c5e707c6b5339359a9a9e215c5e66d6d802fd7a", "type": "github" }, "original": { @@ -377,6 +393,7 @@ "neovim-nightly-overlay": "neovim-nightly-overlay", "niri": "niri", "nixcord": "nixcord", + "nixos-hardware": "nixos-hardware", "nixpkgs": "nixpkgs", "nixvim": "nixvim", "satty": "satty", @@ -474,11 +491,11 @@ "systems": "systems_2" }, "locked": { - "lastModified": 1770528352, - "narHash": "sha256-KO51BALxgLUlhg1CqQgA3Rj8vgAcDvoLxzNLTxD65cc=", + "lastModified": 1770846656, + "narHash": "sha256-wdYpo8++TqKp3GdRgLFykjuIVW1m9GlUnxID2FG74cE=", "owner": "Gerg-L", "repo": "spicetify-nix", - "rev": "9f4ab243968118026f4ff82f7ce41d30319e2bf0", + "rev": "40e65cfc4608402674e1efaac3fccce20d2a72d3", "type": "github" }, "original": { @@ -540,11 +557,11 @@ ] }, "locked": { - "lastModified": 1770731745, - "narHash": "sha256-GDl0P8Gc/uvDnT/0yGOalpWa4MGuSmBiGpiQNPlznFA=", + "lastModified": 1770841346, + "narHash": "sha256-rGgJCBXpdl4IsEPvW9AzehNAFWQ90VmMHjM/iDD0oY8=", "owner": "Alexays", "repo": "Waybar", - "rev": "d527ccd4c1f53f4bb161677b451aabb89556f2d5", + "rev": "03a77c592b2a3855e293708cd0ca8205484d591d", "type": "github" }, "original": { @@ -595,11 +612,11 @@ "rust-overlay": "rust-overlay_2" }, "locked": { - "lastModified": 1770694186, - "narHash": "sha256-z4kRmmOkCMTF6dk9Id5tnuBEZ+cI7wcGfAGThMShSIc=", + "lastModified": 1770826362, + "narHash": "sha256-4EIzP/6xNQPmTliuww3B7m7E1MdRexrSJCWviiH+qt4=", "owner": "sxyazi", "repo": "yazi", - "rev": "30ec603441733a19510a0d7d9ab8698fe6ff0844", + "rev": "c3bc4fecad9308846251ded5aad8509dd7a04158", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix index 4d432a7..11d2419 100644 --- a/flake.nix +++ b/flake.nix @@ -7,6 +7,8 @@ # Snapshot of nixpkgs with the 6.17.13 kernel for compatibility kernelv.url = "github:NixOS/nixpkgs/52e64396e98aef211f4127416dbdae17a01b3d3f"; + nixos-hardware.url = "github:NixOS/nixos-hardware/master"; + sops-nix = { url = "github:Mic92/sops-nix"; inputs.nixpkgs.follows = "nixpkgs"; diff --git a/hosts/desktop/configuration.nix b/hosts/desktop/configuration.nix index f825848..50fb2c9 100644 --- a/hosts/desktop/configuration.nix +++ b/hosts/desktop/configuration.nix @@ -9,11 +9,14 @@ imports = [ inputs.disko.nixosModules.disko - + # ./disko.nix ./hardware-configuration.nix + ../../os/default.nix ]; + # hardware.facter.reportPath = /etc/nixos/hosts/desktop/facter.json; + os = { core = { allowUnfree.enable = true; @@ -23,7 +26,11 @@ enable = true; disable-devices.enable = true; }; - bootloader.type = "systemd-boot"; + bootloader = { + type = "systemd-boot"; + timeout = 0; + # luks.enable = true; + }; drivers = { enable = true; cpu = "amd"; @@ -85,7 +92,6 @@ }; boot = { - kernelParams = [ "video=DP-1:2560x1440@240" ]; kernelModules = [ "nct6687" ]; extraModulePackages = [ config.boot.kernelPackages.nct6687d diff --git a/hosts/desktop/disko.nix b/hosts/desktop/disko.nix index 78eb6a0..cda1979 100644 --- a/hosts/desktop/disko.nix +++ b/hosts/desktop/disko.nix @@ -31,76 +31,65 @@ mountpoint = "/"; mountOptions = [ "compress=zstd:1" - "noatime" + "space_cache=v2" "discard=async" + "noatime" ]; }; "nix" = { mountpoint = "/nix"; mountOptions = [ "compress=zstd:1" - "noatime" - "discard=async" + "nodev" ]; }; "home" = { mountpoint = "/home"; mountOptions = [ "compress=zstd:1" - "noatime" "nosuid" "nodev" - "discard=async" ]; }; "log" = { mountpoint = "/var/log"; mountOptions = [ "compress=zstd:1" - "noatime" "nosuid" "nodev" - "discard=async" ]; }; "games" = { mountpoint = "/games"; mountOptions = [ - "compress=zstd:1" - "noatime" + "compress=none" "nosuid" "nodev" - "discard=async" ]; }; "llms" = { mountpoint = "/llms"; mountOptions = [ - "nodatacow" "compress=none" - "noatime" + "nodatacow" "nosuid" "nodev" - "discard=async" ]; }; "vms" = { mountpoint = "/vms"; mountOptions = [ - "nodatacow" "compress=none" - "noatime" + "nodatacow" "nosuid" "nodev" - "discard=async" ]; }; "swap" = { mountpoint = "/.swapvol"; mountOptions = [ + "compress=none" "nodatacow" - "noatime" - "discard=async" ]; }; }; @@ -131,54 +120,53 @@ mountOptions = [ "compress=zstd:1" "autodefrag" - "noatime" - "nofail" "nosuid" "nodev" + "nofail" "x-systemd.device-timeout=5s" ]; }; "movies" = { mountpoint = "/storage/movies"; mountOptions = [ + "compress=none" "autodefrag" - "noatime" - "nofail" "nosuid" "nodev" + "nofail" "x-systemd.device-timeout=5s" ]; }; "anime" = { mountpoint = "/storage/anime"; mountOptions = [ + "compress=none" "autodefrag" - "noatime" - "nofail" "nosuid" "nodev" + "nofail" "x-systemd.device-timeout=5s" ]; }; "pictures" = { mountpoint = "/storage/pics"; mountOptions = [ + "compress=none" "autodefrag" - "noatime" - "nofail" "nosuid" "nodev" + "nofail" "x-systemd.device-timeout=5s" ]; }; "videos" = { mountpoint = "/storage/vids"; mountOptions = [ + "compress=none" "autodefrag" - "noatime" - "nofail" "nosuid" "nodev" + "nofail" "x-systemd.device-timeout=5s" ]; }; diff --git a/hosts/laptop/configuration.nix b/hosts/laptop/configuration.nix index 304302d..a6c6b56 100644 --- a/hosts/laptop/configuration.nix +++ b/hosts/laptop/configuration.nix @@ -1,4 +1,5 @@ -{username, ...}: { +{ username, ... }: +{ system.stateVersion = "25.05"; imports = [ @@ -13,8 +14,10 @@ audio.enable = true; bootloader = { type = "grub"; - useOSProber = true; - grubDevice = "nodev"; + grub = { + useOSProber = true; + defaultEntry = 2; + }; }; drivers = { enable = true; diff --git a/hosts/thinkpad/configuration.nix b/hosts/thinkpad/configuration.nix index a38d74b..d58858a 100644 --- a/hosts/thinkpad/configuration.nix +++ b/hosts/thinkpad/configuration.nix @@ -2,17 +2,20 @@ inputs, username, ... -}: { +}: +{ system.stateVersion = "25.05"; imports = [ + inputs.nixos-hardware.nixosModules.lenovo-thinkpad-t480s inputs.disko.nixosModules.disko ./disko.nix - ./hardware-configuration.nix ../../os/default.nix ]; + hardware.facter.reportPath = /etc/nixos/hosts/thinkpad/facter.json; + os = { core = { allowUnfree.enable = true; @@ -20,15 +23,15 @@ audio.enable = true; bootloader = { type = "grub"; - enableEncryption = true; - grubDevice = "/dev/nvme0n1"; - luksDevice = "/dev/nvme0n1p2"; + efi = false; + timeout = 0; + luks.enable = true; }; drivers = { enable = true; cpu = "intel"; graphics.enable = true; - kernel = "hardened"; + kernel = "stable"; }; fonts.enable = true; greet.enable = true; @@ -73,5 +76,4 @@ }; }; services.thinkfan.enable = true; - boot.kernelModules = ["thinkpad_acpi"]; } diff --git a/hosts/thinkpad/disko.nix b/hosts/thinkpad/disko.nix index 97e5c87..31427d3 100644 --- a/hosts/thinkpad/disko.nix +++ b/hosts/thinkpad/disko.nix @@ -7,38 +7,56 @@ content = { type = "gpt"; partitions = { - biosboot = { + bootloader = { size = "1M"; type = "EF02"; }; + boot = { + size = "2G"; + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + mountOptions = [ "umask=0077" ]; + }; + }; luks = { size = "100%"; content = { type = "luks"; - name = "crypted"; + name = "crypted_main"; settings.allowDiscards = true; content = { type = "btrfs"; - extraArgs = ["-f"]; + extraArgs = [ "-f" ]; subvolumes = { "root" = { mountpoint = "/"; mountOptions = [ "compress=zstd:1" + "space_cache=v2" + "discard=async" "noatime" ]; }; - "home" = { - mountpoint = "/home"; + "nix" = { + mountpoint = "/nix"; mountOptions = [ "compress=zstd:1" + "space_cache=v2" + "discard=async" + "nodev" "noatime" ]; }; - "nix" = { - mountpoint = "/nix"; + "home" = { + mountpoint = "/home"; mountOptions = [ "compress=zstd:1" + "space_cache=v2" + "discard=async" + "nosuid" + "nodev" "noatime" ]; }; @@ -46,21 +64,43 @@ mountpoint = "/var/log"; mountOptions = [ "compress=zstd:1" + "space_cache=v2" + "discard=async" + "nosuid" + "nodev" + "noatime" + ]; + }; + "games" = { + mountpoint = "/games"; + mountOptions = [ + "compress=none" + "space_cache=v2" + "discard=async" + "nosuid" + "nodev" "noatime" ]; }; "vms" = { mountpoint = "/vms"; mountOptions = [ + "compress=none" + "space_cache=v2" + "discard=async" "nodatacow" + "nosuid" + "nodev" "noatime" ]; }; "swap" = { mountpoint = "/.swapvol"; mountOptions = [ + "compress=none" + "space_cache=v2" + "discard=async" "nodatacow" - "compress=no" "noatime" ]; }; @@ -71,6 +111,100 @@ }; }; }; + storage = { + type = "disk"; + device = "/dev/sda"; + content = { + type = "gpt"; + partitions = { + luks = { + size = "100%"; + content = { + type = "luks"; + name = "crypted_storage"; + keyFile = "/tmp/storage.key"; + settings.allowDiscards = true; + content = { + type = "btrfs"; + extraArgs = [ "-f" ]; + subvolumes = { + "archive" = { + mountpoint = "/storage/archive"; + mountOptions = [ + "compress=zstd:1" + "space_cache=v2" + "discard=async" + "nosuid" + "nodev" + "noatime" + + "nofail" + "x-systemd.device-timeout=5s" + ]; + }; + "movies" = { + mountpoint = "/storage/movies"; + mountOptions = [ + "compress=none" + "space_cache=v2" + "discard=async" + "nosuid" + "nodev" + "noatime" + + "nofail" + "x-systemd.device-timeout=5s" + ]; + }; + "anime" = { + mountpoint = "/storage/anime"; + mountOptions = [ + "compress=none" + "space_cache=v2" + "discard=async" + "nosuid" + "nodev" + "noatime" + + "nofail" + "x-systemd.device-timeout=5s" + ]; + }; + "pictures" = { + mountpoint = "/storage/pics"; + mountOptions = [ + "compress=none" + "space_cache=v2" + "discard=async" + "nosuid" + "nodev" + "noatime" + + "nofail" + "x-systemd.device-timeout=5s" + ]; + }; + "videos" = { + mountpoint = "/storage/vids"; + mountOptions = [ + "compress=none" + "space_cache=v2" + "discard=async" + "nosuid" + "nodev" + "noatime" + + "nofail" + "x-systemd.device-timeout=5s" + ]; + }; + }; + }; + }; + }; + }; + }; + }; }; }; } diff --git a/os/core/bootloader.nix b/os/core/bootloader.nix index 52761f1..7f3a85e 100644 --- a/os/core/bootloader.nix +++ b/os/core/bootloader.nix @@ -15,32 +15,50 @@ in "none" ]; default = "systemd-boot"; - description = "which bootloader to use"; + description = "Which bootloader to use"; }; - useOSProber = lib.mkOption { - type = lib.types.bool; - default = false; - description = "scan for other operating systems"; - }; - enableEncryption = lib.mkOption { + + efi = lib.mkOption { type = lib.types.bool; - default = false; - description = "Enables LUKS encryption"; + default = true; + description = "Whether the system uses UEFI or Legacy BIOS"; }; - grubDevice = lib.mkOption { - type = lib.types.str; - default = "nodev"; + + timeout = lib.mkOption { + type = lib.types.int; + default = 3; + description = "Boot menu timeout in seconds"; }; - luksDevice = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "The underlying partition for LUKS"; + + grub = { + device = lib.mkOption { + type = lib.types.str; + default = "nodev"; + description = "Device to install GRUB to (e.g. /dev/nvme0n1). Use 'nodev' for UEFI."; + }; + useOSProber = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Scan for other operating systems"; + }; + defaultEntry = lib.mkOption { + type = lib.types.int; + default = 0; + description = "Index of the default boot entry"; + }; }; + + luks.enable = lib.mkEnableOption "LUKS encryption support"; }; config = lib.mkMerge [ + # 1. Common Kernel & Initrd Settings { boot = { + loader = { + timeout = cfg.timeout; + efi.canTouchEfiVariables = cfg.efi; + }; supportedFilesystems = [ "ntfs" "btrfs" @@ -49,53 +67,35 @@ in "quiet" "splash" ]; - initrd = { - availableKernelModules = [ - "aesni_intel" - "cryptd" - ]; - luks.devices = lib.mkIf (cfg.enableEncryption && cfg.luksDevice != null) { - "crypted" = { - device = cfg.luksDevice; - preLVM = true; - allowDiscards = true; - }; - }; - }; + consoleLogLevel = 0; + initrd.availableKernelModules = [ + "aesni_intel" + "cryptd" + ]; }; systemd.settings.Manager.DefaultTimeoutStopSec = "5s"; } + # 2. Systemd-boot Implementation (lib.mkIf (cfg.type == "systemd-boot") { - boot = { - consoleLogLevel = 0; - loader = { - efi.canTouchEfiVariables = true; - timeout = 0; - systemd-boot = { - enable = true; - editor = false; - consoleMode = "max"; - }; - }; + boot.loader.systemd-boot = { + enable = true; + editor = false; + consoleMode = "max"; }; }) + # 3. GRUB Implementation (lib.mkIf (cfg.type == "grub") { - boot.loader = { - timeout = 3; - efi.canTouchEfiVariables = cfg.grubDevice == "nodev"; - grub = { - enable = true; - device = cfg.grubDevice; - useOSProber = cfg.useOSProber; - enableCryptodisk = cfg.enableEncryption; + boot.loader.grub = { + enable = true; + device = cfg.grub.device; + efiSupport = cfg.efi; + useOSProber = cfg.grub.useOSProber; + default = cfg.grub.defaultEntry; - default = if cfg.useOSProber then 2 else 0; - - efiSupport = lib.mkDefault (cfg.grubDevice == "nodev"); - copyKernels = lib.mkIf cfg.enableEncryption true; - }; + enableCryptodisk = cfg.luks.enable; + copyKernels = true; }; }) ]; diff --git a/os/core/power.nix b/os/core/power.nix index 3929033..b3dbf91 100644 --- a/os/core/power.nix +++ b/os/core/power.nix @@ -2,45 +2,53 @@ config, lib, ... -}: let +}: +let cfg = config.os.core.power; -in { +in +{ options.os.core.power = { enable = lib.mkEnableOption "enables power management"; mode = lib.mkOption { - type = lib.types.enum ["amd" "intel" "none"]; + type = lib.types.enum [ + "amd" + "intel" + "none" + ]; default = "none"; }; }; - config = lib.mkIf cfg.enable (lib.mkMerge [ - { - powerManagement.powertop.enable = true; - boot.kernelParams = ["nvme_core.default_ps_max_latency_us=0"]; - } + config = lib.mkIf cfg.enable ( + lib.mkMerge [ + { + powerManagement.powertop.enable = true; + boot.kernelParams = [ "nvme_core.default_ps_max_latency_us=0" ]; + } - (lib.mkIf (cfg.mode == "amd") { - services.power-profiles-daemon.enable = true; - boot.kernelParams = ["amd_pstate=active"]; - }) + (lib.mkIf (cfg.mode == "amd") { + services.power-profiles-daemon.enable = true; + boot.kernelParams = [ "amd_pstate=active" ]; + }) - (lib.mkIf (cfg.mode == "intel") { - services = { - power-profiles-daemon.enable = false; + (lib.mkIf (cfg.mode == "intel") { + services = { + power-profiles-daemon.enable = false; - thermald.enable = true; - tlp = { - enable = true; - settings = { - START_CHARGE_THRESH_BAT0 = 75; - STOP_CHARGE_THRESH_BAT0 = 80; - START_CHARGE_THRESH_BAT1 = 75; - STOP_CHARGE_THRESH_BAT1 = 80; - CPU_SCALING_GOVERNOR_ON_AC = "performance"; - CPU_SCALING_GOVERNOR_ON_BAT = "powersave"; + thermald.enable = true; + tlp = { + enable = true; + settings = { + START_CHARGE_THRESH_BAT0 = 75; + STOP_CHARGE_THRESH_BAT0 = 80; + START_CHARGE_THRESH_BAT1 = 75; + STOP_CHARGE_THRESH_BAT1 = 80; + CPU_SCALING_GOVERNOR_ON_AC = "performance"; + CPU_SCALING_GOVERNOR_ON_BAT = "powersave"; + }; }; }; - }; - }) - ]); + }) + ] + ); } diff --git a/scripts/install.sh b/scripts/install.sh new file mode 100644 index 0000000..9173646 --- /dev/null +++ b/scripts/install.sh @@ -0,0 +1,101 @@ +#!/usr/bin/env bash +set -euo pipefail + +# --- Defaults --- +HOSTNAME="" +MAIN_DISK="/dev/nvme0n1" +STORAGE_DISK="" +REPO_URL="https://codeberg.org/adikro/nixos-config.git" +TEMP_CONFIG="/tmp/config/etc/nixos-config" +USE_FACTER=true +WRITE_EFI=true + +# --- Parse Arguments --- +# Added 'g' (generate-config) and 'n' (no-efi) to options +PARSED_ARGS=$(getopt -z -o h:m:s:r:c:gn --long hostname:,main:,storage:,repo:,config:,generate-config,no-efi -- "$@") +eval set -- "$PARSED_ARGS" + +while true; do + case "$1" in + -h|--hostname) HOSTNAME="$2"; shift 2 ;; + -m|--main) MAIN_DISK="$2"; shift 2 ;; + -s|--storage) STORAGE_DISK="$2"; shift 2 ;; + -r|--repo) REPO_URL="$2"; shift 2 ;; + -c|--config) TEMP_CONFIG="$2"; shift 2 ;; + -g|--generate-config) USE_FACTER=false; shift ;; + -n|--no-efi) WRITE_EFI=false; shift ;; + --) shift; break ;; + *) echo "Internal error!"; exit 1 ;; + esac +done + +# --- Validation --- +if [[ -z "$HOSTNAME" || -z "$MAIN_DISK" ]]; then + echo "Usage: sudo ./install.sh --hostname [options]" + echo "Options: --main --storage --repo --config --generate-config --no-efi" + exit 1 +fi + +# --- Summary & Confirmation --- +echo "------------------------------------------------------------" +echo "INSTALLATION PLAN" +echo " Hostname: $HOSTNAME" +echo " Main Disk: $MAIN_DISK" +echo " Storage Disk: ${STORAGE_DISK:-None}" +echo " Hardware Mode: $([ "$USE_FACTER" = true ] && echo "Facter" || echo "Legacy Generate-Config")" +echo " Write EFI: $WRITE_EFI" +echo " Repo URL: $REPO_URL" +echo "------------------------------------------------------------" +read -p "Proceed with formatting? (y/N): " confirm +[[ "$confirm" != [yY] ]] && exit 1 + +echo "### 1. Preparing GPG ###" +gpg --import ./private.asc || echo "GPG key already present." + +echo "### 2. Cloning Configuration ###" +sudo rm -rf "$TEMP_CONFIG" +git clone "$REPO_URL" "$TEMP_CONFIG" +cd "$TEMP_CONFIG" + +echo "### 3. Hardware Configuration ###" +mkdir -p "./hosts/$HOSTNAME" + +if [ "$USE_FACTER" = true ]; then + echo "Running Facter scan..." + # Note: Using your specified format for the command + sudo nix run github:nix-community/nixos-facter -- -o "./hosts/$HOSTNAME/facter.json" + git add "./hosts/$HOSTNAME/facter.json" +else + echo "Generating legacy hardware config..." + sudo nixos-generate-config --no-filesystems --root /tmp/nixos-gen-root + sudo mv /tmp/nixos-gen-root/etc/nixos/hardware-configuration.nix "./hosts/$HOSTNAME/hardware-configuration.nix" + sudo rm -rf /tmp/nixos-gen-root + git add "./hosts/$HOSTNAME/hardware-configuration.nix" +fi + +echo "### 4. SOPS Key Extraction ###" +if [[ -n "$STORAGE_DISK" ]]; then + echo "Extracting storage_key..." + nix shell nixpkgs#sops -c sops -d --extract '["storage_key"]' secrets.yaml > /tmp/storage.key +fi + +echo "### 5. Disko Install ###" +DISKO_ARGS=( + --flake ".#$HOSTNAME" + --disk main "$MAIN_DISK" +) + +# Conditionally add the EFI flag +if [ "$WRITE_EFI" = true ]; then + DISKO_ARGS+=(--write-efi-boot-entries) +fi + +# Append storage disk if defined +if [[ -n "$STORAGE_DISK" ]]; then + DISKO_ARGS+=(--disk storage "$STORAGE_DISK") +fi + +sudo nix run 'github:nix-community/disko/latest#disko-install' -- "${DISKO_ARGS[@]}" + +echo "------------------------------------------------------------" +echo "INSTALL COMPLETE. Remove pendrive and reboot." diff --git a/scripts/setup.sh b/scripts/setup.sh new file mode 100644 index 0000000..a3b0cb2 --- /dev/null +++ b/scripts/setup.sh @@ -0,0 +1,22 @@ +#!/usr/bin/env bash +# Automate the post-reboot steps +sudo mkdir -p /mnt/usb && sudo mount /dev/sdb1 /mnt/usb +gpg --import /mnt/usb/private.asc +gpg --import /mnt/usb/public.asc +gpg --import-ownertrust /mnt/usb/trust.txt + +# Setup the repo properly +sudo mkdir -p /etc/nixos +sudo chown -R $USER:users /etc/nixos +git clone git@codeberg.org:adikro/nixos-config.git /etc/nixos + +# Fix hardware config for the actual live system +sudo rm /etc/nixos/hosts/desktop/hardware-configuration.nix +sudo nixos-generate-config --no-filesystems --root / +# Move it to the right place +sudo mv /etc/nixos/hardware-configuration.nix /etc/nixos/hosts/desktop/ + +# Update SOPS with new SSH key +NEW_AGE=$(ssh-to-age < /etc/ssh/ssh_host_ed25519_key.pub) +echo "New Age Key: $NEW_AGE" +# You'll still need to manually edit .sops.yaml unless you use 'sed' to replace the key -- cgit v1.3