diff --git a/README.md b/README.md index beb5187..1506d98 100644 --- a/README.md +++ b/README.md @@ -2,84 +2,55 @@ Avatar Nix logo - # adam0's infrastructure + # adam0's infra - NixOS and Home Manager flake for my system and user environment. + The Nix flake that keeps my desktop, laptop, and homelab server reproducible. [![Repo Size](https://img.shields.io/github/repo-size/adam01110/infra?style=flat-square&label=repo%20size&labelColor=504945&color=3c3836)](https://github.com/adam01110/infra)
[![NixOS](https://img.shields.io/badge/NixOS-unstable-458588?style=flat-square&labelColor=504945&logo=nixos&logoColor=ebdbb2)](https://nixos.org) [![Flakes](https://img.shields.io/badge/Nix-flakes-689d6a?style=flat-square&labelColor=504945&logo=nixos&logoColor=ebdbb2)](https://nixos.wiki/wiki/Flakes) - [![Home Manager](https://img.shields.io/badge/Home%20Manager-modules-b16286?style=flat-square&labelColor=504945&logo=nixos&logoColor=ebdbb2)](https://github.com/nix-community/home-manager) + [![Home Manager](https://img.shields.io/badge/Home%20Manager-managed-b16286?style=flat-square&labelColor=504945&logo=nixos&logoColor=ebdbb2)](https://github.com/nix-community/home-manager) [![Stylix](https://img.shields.io/badge/Stylix-theming-8f3f71?style=flat-square&labelColor=504945&logo=nixos&logoColor=ebdbb2)](https://github.com/danth/stylix) [![SOPS Nix](https://img.shields.io/badge/SOPS%20Nix-secrets-fe8019?style=flat-square&labelColor=504945&logo=nixos&logoColor=ebdbb2)](https://github.com/Mic92/sops-nix) [![Disko](https://img.shields.io/badge/Disko-storage-98971a?style=flat-square&labelColor=504945&logo=nixos&logoColor=ebdbb2)](https://github.com/nix-community/disko) - [Overview](#overview) - [Layout](#layout) - [Usage](#usage) - [Secrets](#secrets) - [Customization](#customization) - [Tooling](#tooling) + [What This Is](#what-this-is) - [Machines](#machines) - [Layout](#layout) -This repository contains my NixOS and Home Manager setup. It uses `flake-parts`, `flake-file`, and `import-tree` to expose NixOS modules, Home Manager modules, overlays, packages, Disko layouts, and development tooling from `modules/`. +This is my personal infrastructure repo. It is mostly here so I can rebuild my own machines without trying to remember every package, service, kernel tweak, browser preference, shell setting, and desktop detail by hand. -## Overview +It is not meant to be a starter template. Some parts are reusable, but a lot of it is deliberately shaped around my hardware, my domains, my secrets layout, and the way I like my desktop to feel. -- Public flake outputs are generated from `modules/` through `inputs.import-tree ./modules`. -- NixOS modules live under `modules/nix`, `modules/services`, `modules/profiles`, and top-level module files such as `modules/users.nix`. -- Home Manager modules live under `modules/programs`, `modules/desktop`, and shared profile modules. -- Desktop modules cover `Hyprland`, `UWSM`, `tuigreet`, `Noctalia Shell`, `Stylix`, XDG portals, MIME defaults, and TUI/GUI integration. -- Local packages, preview helpers, adapters, and overlays live under `modules/pkgs`. Shared helpers live under `lib/`. +## What This Is -## Layout - -| Path | Purpose | -| --- | --- | -| `assets/` | README images, user avatar, and shared static assets | -| `lib/` | Small helper libraries for environment, MIME, Hyprland, Stylix, Starship, and Yazi config | -| `modules/desktop/` | Hyprland, Noctalia, UWSM, greetd, XDG, clipboard, tablet, and desktop integration modules | -| `modules/development/` | Dev shell and treefmt configuration | -| `modules/nix/` | Core flake, Nix, Home Manager, SOPS, kernel, firmware, and input wiring | -| `modules/pkgs/` | Local packages and package overlays | -| `modules/profiles/` | Shared system and Home Manager profiles, partitioning, locale, theming, and tuning | -| `modules/programs/` | CLI, TUI, GUI, Git, GPG, SSH, GTK, Java, and Nix-LD modules | -| `modules/services/` | NixOS service modules for audio, networking, power, storage, containers, and system tuning | -| `vars.nix` | Shared identity, Git metadata, locale, and regional defaults | - -## Usage - -From the repository root: - -```bash -# Enter the development shell -nix develop - -# Format and lint the repository -nix fmt +- A multi-host NixOS flake for my `desktop`, `laptop`, and `euclid` server. +- Home Manager configuration for the user-facing parts of my setup. +- A Hyprland desktop built around UWSM, tuigreet, Noctalia Shell, Stylix, Zen Browser, themed apps, and a lot of small quality-of-life modules. +- A homelab/server stack for services like Authentik, Traefik, WireGuard, CrowdSec, databases, notifications, and media-related tooling. +- Local packages, overlays, preview helpers, and small libraries that make the rest of the tree less repetitive. -# Regenerate flake.nix after changing flake-file inputs -nix run .#write-flake -``` +The repo is wired with `flake-parts`, `flake-file`, and `import-tree`, so most of the structure is discovered from `modules/` instead of being manually listed in one giant flake file. -## Secrets +## Machines -- Runtime secrets live in a local `secrets.yml` at the project root (gitignored). -- Recipient rules live in `.sops.yaml` for one user PGP key and three host Age keys. -- SOPS Nix is shared between NixOS and Home Manager through `modules/nix/sops.nix`. - -Edit flow: - -```bash -sops secrets.yml -``` - -## Customization - -- Edit shared identity, locale, and Git metadata in `vars.nix`. -- Add NixOS behavior through `modules/nix`, `modules/services`, and `modules/profiles`. -- Add user-facing tools through `modules/programs` and `modules/desktop`. -- Add local packages and overlays under `modules/pkgs`. +| Host | What it is | +| --- | --- | +| `desktop` | Main workstation | +| `laptop` | Portable system | +| `euclid` | Homelab server | -## Tooling +## Layout -- `treefmt-nix` wires `alejandra`, `deadnix`, `statix`, `nixf-diagnose`, `keep-sorted`, `shellcheck`, `shfmt`, `stylua`, `rumdl-format`, and `yamllint`. -- `flake-file` owns the generated root `flake.nix`; update inputs in modules and regenerate with `nix run .#write-flake`. -- `import-tree` auto-discovers the module tree so most new modules only need to export the relevant flake attributes. -- The default dev shell currently provides `sops` and `tokei`. +| Path | Purpose | +| --- | --- | +| `assets/` | README images and shared static assets | +| `lib/` | Small helper libraries for Hyprland, Stylix, MIME, Starship, Yazi, and environment handling | +| `modules/hosts/` | The actual machine entrypoints | +| `modules/desktop/` | Hyprland, Noctalia, greetd, UWSM, portals, clipboard, tablet, MangoHud, and desktop glue | +| `modules/programs/` | CLI, TUI, GUI, browser, Git, GPG, SSH, GTK, Java, and Nix-LD modules | +| `modules/services/` | Audio, networking, power, storage, containers, homelab services, and system tuning | +| `modules/profiles/` | Shared base, personal, server, gaming, partitioning, locale, and theming profiles | +| `modules/pkgs/` | Local packages, adapters, previews, and overlays | +| `modules/nix/` | Flake inputs, Nix settings, Home Manager, SOPS, kernel, firmware, and boot-related modules | +| `vars.nix` | Shared identity, Git metadata, locale, and domain defaults | diff --git a/modules/hosts/euclid/default.nix b/modules/hosts/euclid/default.nix index d09f18e..3eadbfc 100644 --- a/modules/hosts/euclid/default.nix +++ b/modules/hosts/euclid/default.nix @@ -110,6 +110,8 @@ wants = ["podman.socket"]; }; + # Public Git SSH port for the Tangled knot container. + networking.firewall.allowedTCPPorts = [2223]; networking.firewall.allowedUDPPorts = [7359]; # Primary nvme disk for disko partitioning. diff --git a/modules/profiles/server.nix b/modules/profiles/server.nix index e7af6a1..6012200 100644 --- a/modules/profiles/server.nix +++ b/modules/profiles/server.nix @@ -26,6 +26,8 @@ disko.devices = (self.diskoConfigurations.btrfs config.disko.selectedDisk).disko.devices; + boot.kernel.sysctl."vm.overcommit_memory" = 1; + powerManagement.cpuFreqGovernor = "performance"; # Shell config exists before TTY/SSH login. diff --git a/modules/programs/gui/discord/themes/snippets.css b/modules/programs/gui/discord/themes/snippets.css index 66e3125..5c09594 100644 --- a/modules/programs/gui/discord/themes/snippets.css +++ b/modules/programs/gui/discord/themes/snippets.css @@ -202,3 +202,77 @@ time[datetime]:hover::after { #slate-toolbar::before { border-top: 8px solid var(--background-base-low); } + +/* Fix vc text being cut off. */ +.callContainer_cb9592::after { + display: none !important; +} +.wrapper_cb9592::after { + content: "vc"; + display: block; + color: var(--label-color); + font-weight: var(--label-font-weight); + position: absolute; + top: -10px; + left: 8px; + background-color: var(--background-base-low); + padding: 0 4px; + z-index: 100; + font-size: 16px; + transition: color var(--border-hover-transition); +} +.wrapper_cb9592:hover.wrapper_cb9592::after { + color: var(--label-hover-color); +} + +/* Fix background blur. */ +[class="layers__960e4 layers__160d8"] { + backdrop-filter: blur(8px) !important; +} + +/* Fix menus background. */ +.menu_c1e9c4::before { + width: calc(100% - 2px); + height: calc(100% - 2px); +} +.submenu_c1e9c4.menu_c1e9c4::before { + width: calc(100% - 18px) !important; +} + +/* Report popup hover effect fix. */ +.root__49fc1.small__49fc1.fullscreenOnMobile__49fc1.rootWithShadow__49fc1 { + border: var(--border-thickness) solid var(--border-subtle) !important; + transition: border-color var(--border-hover-transition) !important; + + &:hover { + border-color: var(--border-hover) !important; + } +} + +/* Fix panel labels colors */ +.wrapper_cb9592, +.guilds__5e434, +.panels__5e434, +.sidebarList__5e434, +.subtitleContainer_f75fb0, +.messagesWrapper__36d07, +.channelTextArea_f75fb0, +.content_f75fb0 > .membersWrap_c8ffbb, +.container_c8ffbb, +.container__133bf > .container__9293f, +.peopleColumn__133bf, +.nowPlayingColumn__133bf, +.container__01ae2 > .container__9293f, +.callContainer_cb9592 { + &::after { + background: hsl(from var(--bg-4) h s l / 1); + } +} +.divider__908e2 .content__908e2 { + background: var(--border-subtle); +} + +/* Fix vc top border thickness. */ +.callContainer_cb9592 { + border-top-width: 2px !important; +} diff --git a/modules/programs/gui/zen/chrome.nix b/modules/programs/gui/zen/chrome.nix index 2181a44..e379994 100644 --- a/modules/programs/gui/zen/chrome.nix +++ b/modules/programs/gui/zen/chrome.nix @@ -19,6 +19,7 @@ inputs, lib, pkgs, + vars, # keep-sorted end ... }: let @@ -28,6 +29,8 @@ inherit (pkgs.stdenv.hostPlatform) system; + inherit (vars) groundDomain; + # Convert the stylix base16 scheme into a format accepted by nix-userstyles. palette = stylixPalette config; in { @@ -94,6 +97,7 @@ "searchix" "spotify-web" "stack-overflow" + "tangled" "twitch" "web.dev" "wiki.nixos.org" @@ -105,7 +109,7 @@ { name = "anonymous-overflow"; - sites = [''domain("anonymous-overflow.zezura.xyz")'']; + sites = [''domain("anonymous-overflow.${groundDomain}")'']; } ]; diff --git a/modules/programs/gui/zen/extensions.nix b/modules/programs/gui/zen/extensions.nix index 90090d8..d3480e4 100644 --- a/modules/programs/gui/zen/extensions.nix +++ b/modules/programs/gui/zen/extensions.nix @@ -27,6 +27,7 @@ modrinthify pronoundb return-youtube-dislikes + terms-of-service-didnt-read translate-web-pages violentmonkey wikiwand-wikipedia-modernized @@ -46,9 +47,12 @@ ); in (mkExtensionSettings { + # keep-sorted start + "@crw-extension-firefox" = "consumer-rights-wiki"; + "helloyanis@ageverif-bypass" = "age-verification-bypass"; "{76ef94a4-e3d0-4c6f-961a-d38a429a332b}" = "ttv-lol-pro"; "{microslop@4o4}" = "microslop"; - "@crw-extension-firefox" = "consumer-rights-wiki"; + # keep-sorted end }) // { "magnolia@12.34" = { diff --git a/modules/programs/ssh.nix b/modules/programs/ssh.nix index 66d9fa7..4b2b94b 100644 --- a/modules/programs/ssh.nix +++ b/modules/programs/ssh.nix @@ -20,6 +20,13 @@ IdentityFile = "~/.ssh/git"; }; + knot = { + HostName = "knot.${groundDomain}"; + IdentityFile = "~/.ssh/git"; + Port = 2223; + User = "git"; + }; + euclid = { HostKeyAlias = "euclid.${groundDomain}"; HostName = "127.0.0.1"; diff --git a/modules/services/traefik.nix b/modules/services/traefik.nix index 661e435..91d7d04 100644 --- a/modules/services/traefik.nix +++ b/modules/services/traefik.nix @@ -22,6 +22,7 @@ "traefik/mail" = {}; "traefik/porkbun_api_key" = {}; + "traefik/porkbun_secret_api_key" = {}; # keep-sorted end };