From 899b79f30494822ba226406782df204ea51d8183 Mon Sep 17 00:00:00 2001 From: Adam0 Date: Sun, 17 May 2026 02:44:31 +0200 Subject: [PATCH] more --- flake.lock | 291 ++++++++++++++++-- flake.nix | 5 + modules/desktop/hyprland/cursor.nix | 31 ++ modules/desktop/hyprland/default.nix | 23 +- modules/desktop/hyprland/picker.nix | 5 + modules/desktop/hyprland/plugins.nix | 4 +- modules/desktop/hyprland/screenshot.nix | 5 + modules/desktop/noctalia/default.nix | 16 +- modules/desktop/noctalia/theme.nix | 24 +- modules/nix/default.nix | 61 ++++ modules/nix/dendritic.nix | 4 +- modules/nix/determinate.nix | 10 + modules/nix/firmware.nix | 5 + modules/nix/home-manager.nix | 27 ++ modules/nix/kernel.nix | 24 ++ modules/nix/lanzaboote.nix | 66 ++++ modules/profiles/personal.nix | 2 + modules/programs/appimage.nix | 8 + modules/programs/cli/eza/default.nix | 20 +- modules/programs/java.nix | 8 + modules/programs/nix-ld.nix | 5 + modules/programs/tui/neovim/default.nix | 10 + modules/programs/tui/opencode/plugins.nix | 3 + .../programs/tui/television/nix-search.nix | 1 - modules/services/libinput.nix | 15 + modules/services/nftables.nix | 6 + modules/services/pipewire.nix | 2 + modules/users.nix | 55 ++++ todo.md | 16 +- 29 files changed, 682 insertions(+), 70 deletions(-) create mode 100644 modules/desktop/hyprland/cursor.nix create mode 100644 modules/desktop/hyprland/picker.nix create mode 100644 modules/desktop/hyprland/screenshot.nix create mode 100644 modules/nix/default.nix create mode 100644 modules/nix/firmware.nix create mode 100644 modules/nix/kernel.nix create mode 100644 modules/nix/lanzaboote.nix create mode 100644 modules/programs/appimage.nix create mode 100644 modules/programs/java.nix create mode 100644 modules/programs/nix-ld.nix create mode 100644 modules/services/nftables.nix create mode 100644 modules/users.nix diff --git a/flake.lock b/flake.lock index ba38894..860c8e4 100644 --- a/flake.lock +++ b/flake.lock @@ -101,7 +101,54 @@ "type": "github" } }, + "cachyos-kernel": { + "flake": false, + "locked": { + "lastModified": 1778851262, + "narHash": "sha256-lEtNQQdQkC1bWIxBr9po1cW6aD+UzAMxUbe6k3hH1tA=", + "owner": "CachyOS", + "repo": "linux-cachyos", + "rev": "e625438b981d774a22e2ba431a2d93e1737462ff", + "type": "github" + }, + "original": { + "owner": "CachyOS", + "repo": "linux-cachyos", + "type": "github" + } + }, + "cachyos-kernel-patches": { + "flake": false, + "locked": { + "lastModified": 1778864443, + "narHash": "sha256-3OIBgFPMab0avw5A0OcnGrmRTAbw573aAIgYERYRZ8g=", + "owner": "CachyOS", + "repo": "kernel-patches", + "rev": "a62c86e5d6ce4efcd4f3be9526adfa52aa7286af", + "type": "github" + }, + "original": { + "owner": "CachyOS", + "repo": "kernel-patches", + "type": "github" + } + }, "crane": { + "locked": { + "lastModified": 1765145449, + "narHash": "sha256-aBVHGWWRzSpfL++LubA0CwOOQ64WNLegrYHwsVuVN7A=", + "owner": "ipetkov", + "repo": "crane", + "rev": "69f538cdce5955fcd47abfed4395dc6d5194c1c5", + "type": "github" + }, + "original": { + "owner": "ipetkov", + "repo": "crane", + "type": "github" + } + }, + "crane_2": { "locked": { "lastModified": 1777830388, "narHash": "sha256-2uoQAqUk2H0ijQtGiWAyNeQYGYc6yfAcRRLlJAz4Gp8=", @@ -180,11 +227,11 @@ ] }, "locked": { - "lastModified": 1778749419, - "narHash": "sha256-SayfylyfDvjOwMj4hfkvM8lY6CAdWju741FAhq/nYus=", + "lastModified": 1778940504, + "narHash": "sha256-icE/A507esXXgvNN0KjrqlWNupu9dx61J0qV9sU645E=", "owner": "NotAShelf", "repo": "eh", - "rev": "3475917b4276cbc8b668f2ddf3b4f4214d91ca8f", + "rev": "add693289faa2291b04c1168befcb772ebf734b6", "type": "github" }, "original": { @@ -242,6 +289,38 @@ } }, "flake-compat_3": { + "flake": false, + "locked": { + "lastModified": 1761588595, + "narHash": "sha256-XKUZz9zewJNUj46b4AJdiRZJAvSZ0Dqj2BNfXvFlJC4=", + "owner": "edolstra", + "repo": "flake-compat", + "rev": "f387cd2afec9419c8ee37694406ca490c3f34ee5", + "type": "github" + }, + "original": { + "owner": "edolstra", + "repo": "flake-compat", + "type": "github" + } + }, + "flake-compat_4": { + "flake": false, + "locked": { + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", + "owner": "NixOS", + "repo": "flake-compat", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", + "type": "github" + }, + "original": { + "owner": "NixOS", + "repo": "flake-compat", + "type": "github" + } + }, + "flake-compat_5": { "locked": { "lastModified": 1733328505, "narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=", @@ -255,7 +334,7 @@ "url": "https://flakehub.com/f/edolstra/flake-compat/1.tar.gz" } }, - "flake-compat_4": { + "flake-compat_6": { "flake": false, "locked": { "lastModified": 1751685974, @@ -327,6 +406,24 @@ "type": "github" } }, + "flake-parts_3": { + "inputs": { + "nixpkgs-lib": "nixpkgs-lib" + }, + "locked": { + "lastModified": 1778716662, + "narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "flake-parts", + "type": "github" + } + }, "fromYaml": { "flake": false, "locked": { @@ -407,6 +504,28 @@ "type": "github" } }, + "gitignore_2": { + "inputs": { + "nixpkgs": [ + "lanzaboote", + "pre-commit", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1709087332, + "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=", + "owner": "hercules-ci", + "repo": "gitignore.nix", + "rev": "637db329424fd7e46cf4185293b9cc8c88c95394", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "gitignore.nix", + "type": "github" + } + }, "gnome-shell": { "flake": false, "locked": { @@ -431,11 +550,11 @@ ] }, "locked": { - "lastModified": 1778921576, - "narHash": "sha256-jgIbBcGgKTtkp+lBas29hNFUU1t5O/2+GFvUjbiG0vM=", + "lastModified": 1778954430, + "narHash": "sha256-oaNyOr05lblaQdtbkbN1wO0b2KLIL2O1LkmwDgdQp4I=", "owner": "nix-community", "repo": "home-manager", - "rev": "32b42d71b4b22c4465963285bb6e462d7c93d45e", + "rev": "26aaab785b0bab4af60a2c42b22760fa906ef22a", "type": "github" }, "original": { @@ -810,6 +929,30 @@ "type": "github" } }, + "lanzaboote": { + "inputs": { + "crane": "crane", + "nixpkgs": [ + "nixpkgs" + ], + "pre-commit": "pre-commit", + "rust-overlay": "rust-overlay" + }, + "locked": { + "lastModified": 1765382359, + "narHash": "sha256-RJmgVDzjRI18BWVogG6wpsl1UCuV6ui8qr4DJ1LfWZ8=", + "owner": "nix-community", + "repo": "lanzaboote", + "rev": "e8c096ade12ec9130ff931b0f0e25d2f1bc63607", + "type": "github" + }, + "original": { + "owner": "nix-community", + "ref": "v1.0.0", + "repo": "lanzaboote", + "type": "github" + } + }, "luajit-src": { "flake": false, "locked": { @@ -926,6 +1069,29 @@ "url": "https://flakehub.com/f/DeterminateSystems/nix-src/%2A" } }, + "nix-cachyos-kernel": { + "inputs": { + "cachyos-kernel": "cachyos-kernel", + "cachyos-kernel-patches": "cachyos-kernel-patches", + "flake-compat": "flake-compat_4", + "flake-parts": "flake-parts_3", + "nixpkgs": "nixpkgs_4" + }, + "locked": { + "lastModified": 1778956518, + "narHash": "sha256-bbZMrzJtCqksaUBmAWSqmme/7PHEedPRAI3VmOSuP4A=", + "owner": "xddxdd", + "repo": "nix-cachyos-kernel", + "rev": "ae5bc7641fb4178e4d9582ea49cab201f60f7869", + "type": "github" + }, + "original": { + "owner": "xddxdd", + "ref": "release", + "repo": "nix-cachyos-kernel", + "type": "github" + } + }, "nix-flatpak": { "locked": { "lastModified": 1777402031, @@ -963,11 +1129,11 @@ }, "nixcord": { "inputs": { - "flake-compat": "flake-compat_3", + "flake-compat": "flake-compat_5", "flake-parts": [ "flake-parts" ], - "nixpkgs": "nixpkgs_4", + "nixpkgs": "nixpkgs_5", "nixpkgs-nixcord": "nixpkgs-nixcord" }, "locked": { @@ -1040,6 +1206,21 @@ "type": "github" } }, + "nixpkgs-lib": { + "locked": { + "lastModified": 1777168982, + "narHash": "sha256-GOkGPcboWE9BmGCRMLX3worL4EMnsnG8MyKmXNeYuhQ=", + "owner": "nix-community", + "repo": "nixpkgs.lib", + "rev": "f5901329dade4a6ea039af1433fb087bd9c1fe14", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixpkgs.lib", + "type": "github" + } + }, "nixpkgs-nixcord": { "locked": { "lastModified": 1778003029, @@ -1103,6 +1284,22 @@ } }, "nixpkgs_4": { + "locked": { + "lastModified": 1778930970, + "narHash": "sha256-FqqcYr0c5in/HRL5bkRWykAGp/Q10Vj/zUiSr1P8URE=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "5a51fe22e18a6ce886b3cffa4c255378c151323c", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable-small", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_5": { "locked": { "lastModified": 1778003029, "narHash": "sha256-q/nkKLDtHIyLjZpKhWk3cSK5IYsFqtMd6UtXF3ddjgA=", @@ -1118,13 +1315,13 @@ "type": "github" } }, - "nixpkgs_5": { + "nixpkgs_6": { "locked": { - "lastModified": 1778794387, - "narHash": "sha256-9yR9UAI7ZI5a98+eTkNFl8XogSQxU8bF3+pAU5zvuYI=", - "rev": "8a1b0127302ea51e05bf4ea5a291743fac442406", + "lastModified": 1778869304, + "narHash": "sha256-vZOcDniDPc1cS8A4Xi5YE6AGyPIvEpy4GMyayA3SWIM=", + "rev": "d233902339c02a9c334e7e593de68855ad26c4cb", "type": "tarball", - "url": "https://releases.nixos.org/nixpkgs/nixpkgs-26.05pre998133.8a1b0127302e/nixexprs.tar.xz" + "url": "https://releases.nixos.org/nixpkgs/nixpkgs-26.05pre998534.d233902339c0/nixexprs.tar.xz" }, "original": { "type": "tarball", @@ -1187,11 +1384,11 @@ ] }, "locked": { - "lastModified": 1778922546, - "narHash": "sha256-OR7V4uG8WfAoZh4HE0fGBWGPDzgqKfyJkFgL7QdHCd0=", + "lastModified": 1778975037, + "narHash": "sha256-iycosu6o+g2d6wn+BjtJOzY6a7qLXm/56jv15Z1CNBs=", "owner": "nix-community", "repo": "NUR", - "rev": "65936b3620f4b3ad7f39a6c29029e3c9366fd796", + "rev": "acefc7787b20a437d7c33d0a4b37be214758894d", "type": "github" }, "original": { @@ -1202,7 +1399,7 @@ }, "nvf": { "inputs": { - "flake-compat": "flake-compat_4", + "flake-compat": "flake-compat_6", "flake-parts": [ "flake-parts" ], @@ -1258,6 +1455,29 @@ "type": "github" } }, + "pre-commit": { + "inputs": { + "flake-compat": "flake-compat_3", + "gitignore": "gitignore_2", + "nixpkgs": [ + "lanzaboote", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1765016596, + "narHash": "sha256-rhSqPNxDVow7OQKi4qS5H8Au0P4S3AYbawBSmJNUtBQ=", + "owner": "cachix", + "repo": "pre-commit-hooks.nix", + "rev": "548fc44fca28a5e81c5d6b846e555e6b9c2a5a3c", + "type": "github" + }, + "original": { + "owner": "cachix", + "repo": "pre-commit-hooks.nix", + "type": "github" + } + }, "pre-commit-hooks": { "inputs": { "flake-compat": "flake-compat_2", @@ -1292,12 +1512,14 @@ "hyprland": "hyprland", "hyprland-plugins": "hyprland-plugins", "import-tree": "import-tree", + "lanzaboote": "lanzaboote", "millennium": "millennium", + "nix-cachyos-kernel": "nix-cachyos-kernel", "nix-flatpak": "nix-flatpak", "nix-index-database": "nix-index-database", "nixcord": "nixcord", "nixhypr": "nixhypr", - "nixpkgs": "nixpkgs_5", + "nixpkgs": "nixpkgs_6", "noctalia": "noctalia", "noctalia-qs": "noctalia-qs", "nur": "nur", @@ -1312,6 +1534,27 @@ } }, "rust-overlay": { + "inputs": { + "nixpkgs": [ + "lanzaboote", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1765075567, + "narHash": "sha256-KFDCdQcHJ0hE3Nt5Gm5enRIhmtEifAjpxgUQ3mzSJpA=", + "owner": "oxalica", + "repo": "rust-overlay", + "rev": "769156779b41e8787a46ca3d7d76443aaf68be6f", + "type": "github" + }, + "original": { + "owner": "oxalica", + "repo": "rust-overlay", + "type": "github" + } + }, + "rust-overlay_2": { "inputs": { "nixpkgs": [ "tuigreet", @@ -1607,18 +1850,18 @@ }, "tuigreet": { "inputs": { - "crane": "crane", + "crane": "crane_2", "nixpkgs": [ "nixpkgs" ], - "rust-overlay": "rust-overlay" + "rust-overlay": "rust-overlay_2" }, "locked": { - "lastModified": 1778842706, - "narHash": "sha256-clofLNZWBununCewLVQr86TpVgI/oeAWuIZpE28R1RY=", + "lastModified": 1778952707, + "narHash": "sha256-ykv8R+YziXbeu4RwfWvwmEQlTMA2jZDSDptxatYhp50=", "owner": "notashelf", "repo": "tuigreet", - "rev": "8e77e88b3d08298e3a369e4a8ebf574ea5d49679", + "rev": "879634d1cdc7cf0b887545c6826cd0d392fb731c", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix index a1ef959..63d6fbe 100644 --- a/flake.nix +++ b/flake.nix @@ -28,10 +28,15 @@ inputs.hyprland.follows = "hyprland"; }; import-tree.url = "github:vic/import-tree"; + lanzaboote = { + url = "github:nix-community/lanzaboote?ref=v1.0.0"; + inputs.nixpkgs.follows = "nixpkgs"; + }; millennium = { url = "github:SteamClientHomebrew/Millennium?dir=packages/nix"; inputs.nixpkgs.follows = "nixpkgs"; }; + nix-cachyos-kernel.url = "github:xddxdd/nix-cachyos-kernel?ref=release"; nix-flatpak.url = "github:gmodena/nix-flatpak"; nix-index-database = { url = "github:nix-community/nix-index-database"; diff --git a/modules/desktop/hyprland/cursor.nix b/modules/desktop/hyprland/cursor.nix new file mode 100644 index 0000000..481b690 --- /dev/null +++ b/modules/desktop/hyprland/cursor.nix @@ -0,0 +1,31 @@ +{self, ...}: { + flake.modules.homeManager.hyprland = { + # keep-sorted start + config, + lib, + pkgs, + # keep-sorted end + ... + }: let + inherit (lib) mkForce; + in { + imports = [ + # keep-sorted start + self.modules.homeManager.nur + self.modules.homeManager.stylixPersonal + # keep-sorted end + ]; + + # Install and export the Hyprcursor theme selected by Stylix. + home = { + # Hyprcursor variant of the configured Bibata cursor package. + packages = [pkgs.nur.repos.adam0.bibata-modern-cursors-gruvbox-dark-hyprcursor]; + + # Match the hyprcursor package suffix. + sessionVariables.HYPRCURSOR_THEME = mkForce "${config.stylix.cursor.name}-hyprcursor"; + }; + + # Let Home Manager link Hyprcursor assets. + home.pointerCursor.hyprcursor.enable = true; + }; +} diff --git a/modules/desktop/hyprland/default.nix b/modules/desktop/hyprland/default.nix index 930f38b..8392a76 100644 --- a/modules/desktop/hyprland/default.nix +++ b/modules/desktop/hyprland/default.nix @@ -48,8 +48,7 @@ config, inputs, - lib, - pkgs, ... + lib, ... # keep-sorted end }: let inherit @@ -87,24 +86,10 @@ portalPackage = null; }; - # keep-sorted start block=yes newline_separated=yes - # Install hyprpicker for the color-pick keybind. - home.packages = [pkgs.hyprpicker]; - - # Enable hyprcursor theme support. - home.pointerCursor.hyprcursor.enable = true; - - # Enable hyprshot for screenshotting with hyprland. - programs = { - hyprshot.enable = true; - - nixhypr = { - enable = true; - extraLua = concatStringsSep "\n" cfg.extraLuaSnippets; - }; + programs.nixhypr = { + enable = true; + extraLua = concatStringsSep "\n" cfg.extraLuaSnippets; }; - - # keep-sorted end }; }; } diff --git a/modules/desktop/hyprland/picker.nix b/modules/desktop/hyprland/picker.nix new file mode 100644 index 0000000..952fa75 --- /dev/null +++ b/modules/desktop/hyprland/picker.nix @@ -0,0 +1,5 @@ +{pkgs, ...}: { + flake.modules.homeManager.hyprland = { + home.packages = [pkgs.hyprpicker]; + }; +} diff --git a/modules/desktop/hyprland/plugins.nix b/modules/desktop/hyprland/plugins.nix index ffe39da..a9a1c11 100644 --- a/modules/desktop/hyprland/plugins.nix +++ b/modules/desktop/hyprland/plugins.nix @@ -1,8 +1,8 @@ { # keep-sorted start + inputs, - self, - ... + self, ... # keep-sorted end }: { flake-file.inputs = { diff --git a/modules/desktop/hyprland/screenshot.nix b/modules/desktop/hyprland/screenshot.nix new file mode 100644 index 0000000..ea34c7a --- /dev/null +++ b/modules/desktop/hyprland/screenshot.nix @@ -0,0 +1,5 @@ +{ + flake.modules.homeManager.hyprland = { + programs.hyprshot.enable = true; + }; +} diff --git a/modules/desktop/noctalia/default.nix b/modules/desktop/noctalia/default.nix index 930da55..5c07ab8 100644 --- a/modules/desktop/noctalia/default.nix +++ b/modules/desktop/noctalia/default.nix @@ -16,6 +16,16 @@ }; }; + flake.modules.nixos.noctalia = { + nix.settings = let + cache = "https://noctalia.cachix.org"; + in { + substituters = [cache]; + trusted-substituters = [cache]; + trusted-public-keys = ["noctalia.cachix.org-1:pCOR47nnMEo5thcxNDtzWpOxNFQsBRglJzxWPp3dkU4="]; + }; + }; + flake.modules.homeManager.noctalia = {lib, ...}: let inherit (lib) mkEnableOption; in { @@ -29,7 +39,11 @@ enable = true; systemd.enable = true; - # keep-sorted start + # keep-sorted start block=yes newline_separated=yes + # Enable calendar support in the flake-provided Noctalia build. + packageOverrides.calendarSupport = true; + + # Use the current theming schema. settings.templates.enableUserTheming = false; # keep-sorted end }; diff --git a/modules/desktop/noctalia/theme.nix b/modules/desktop/noctalia/theme.nix index 272a6b0..46c181c 100644 --- a/modules/desktop/noctalia/theme.nix +++ b/modules/desktop/noctalia/theme.nix @@ -1,27 +1,25 @@ { flake.modules.homeManager.noctalia = { # keep-sorted start + config, lib, - osConfig, # keep-sorted end ... }: let inherit (lib) mkForce; - colors = osConfig.lib.stylix.colors.withHashtag; + colors = config.lib.stylix.colors.withHashtag; in { + stylix.targets.noctalia-shell.colors.override.withHashtag = with colors; { + # keep-sorted start + base05 = base06; + base0C = base0D; + base0D = base0B; + base0E = base0A; + # keep-sorted end + }; + programs.noctalia-shell = { # keep-sorted start block=yes newline_separated=yes - # Write the noctalia color palette to a json file. - colors = with colors; { - # keep-sorted start - mHover = mkForce base0D; - mOnSurface = mkForce base06; - mPrimary = mkForce base0B; - mSecondary = mkForce base0A; - mTertiary = mkForce base0D; - # keep-sorted end - }; - # System monitor colors from stylix. settings = { # keep-sorted start block=yes newline_separated=yes diff --git a/modules/nix/default.nix b/modules/nix/default.nix new file mode 100644 index 0000000..c26131d --- /dev/null +++ b/modules/nix/default.nix @@ -0,0 +1,61 @@ +{self, ...}: { + flake.modules.nixos.nix = {config, ...}: { + imports = [self.modules.nixos.sops]; + + sops = { + secrets."nix_access_tokens/github" = {}; + templates.access_tokens.content = ''access-tokens = github.com=${config.sops.placeholder."nix_access_tokens/github"}''; + }; + + nix = { + settings = let + substituters = [ + # keep-sorted start + "https://adam01110-nur.cachix.org/" + "https://cache.numtide.com" + "https://forkprince.cachix.org/" + "https://mic92.cachix.org" + "https://nix-community.cachix.org" + "https://numtide.cachix.org" + # keep-sorted end + ]; + in { + # Add binary caches. + inherit substituters; + + # Allow trusted users to opt into the same caches from per-user config. + trusted-substituters = substituters; + + trusted-public-keys = [ + # keep-sorted start + "adam01110-nur.cachix.org-1:43B8awTREG19aQ20luDD9BkxijKG/Q7hf8voMzS1X9I=" + "cache.flakehub.com-3:hJuILl5sVK4iKm86JzgdXW12Y2Hwd5G07qKtHTOcDCM=" + "forkprince.cachix.org-1:9cN+fX492ZKlfd228xpYAC3T9gNKwS1sZvCqH8iAy1M=" + "mic92.cachix.org-1:gi8IhgiT3CYZnJsaW7fxznzTkMUOn1RY4GmXdT/nXYQ=" + "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" + "numtide.cachix.org-1:2ps1kLBUWjxIneOy1Ik6cQjb41X0iXVXeHigGmycPPE=" + # keep-sorted end + ]; + + experimental-features = [ + # keep-sorted start + "flakes" + "nix-command" + "pipe-operators" + # keep-sorted end + ]; + + lazy-trees = true; + eval-cores = 0; + + # Store profile and channel links under XDG state directories. + use-xdg-base-directories = true; + }; + + # Load access tokens from the generated sops template. + extraOptions = "!include ${config.sops.templates."access_tokens".path}"; + }; + + nixpkgs.config.allowUnfree = true; + }; +} diff --git a/modules/nix/dendritic.nix b/modules/nix/dendritic.nix index 6401c6f..3956784 100644 --- a/modules/nix/dendritic.nix +++ b/modules/nix/dendritic.nix @@ -6,7 +6,9 @@ }; imports = [ - inputs.flake-parts.flakeModules.modules + # keep-sorted start inputs.flake-file.flakeModules.dendritic + inputs.flake-parts.flakeModules.modules + # keep-sorted end ]; } diff --git a/modules/nix/determinate.nix b/modules/nix/determinate.nix index 02f1148..d37417a 100644 --- a/modules/nix/determinate.nix +++ b/modules/nix/determinate.nix @@ -8,4 +8,14 @@ in { nix = inputs.determinate.packages.${system}.default; }; + + flake.modules.nixos.determinate = { + nix.settings = let + cache = "https://install.determinate.systems"; + in { + substituters = [cache]; + trusted-substituters = [cache]; + trusted-public-keys = ["cache.flakehub.com-3:hJuILl5sVK4iKm86JzgdXW12Y2Hwd5G07qKtHTOcDCM="]; + }; + }; } diff --git a/modules/nix/firmware.nix b/modules/nix/firmware.nix new file mode 100644 index 0000000..ded0e36 --- /dev/null +++ b/modules/nix/firmware.nix @@ -0,0 +1,5 @@ +{ + flake.modules.nixos.firmware = { + hardware.enableAllFirmware = true; + }; +} diff --git a/modules/nix/home-manager.nix b/modules/nix/home-manager.nix index ab8b03a..4615f87 100644 --- a/modules/nix/home-manager.nix +++ b/modules/nix/home-manager.nix @@ -7,4 +7,31 @@ }; imports = [inputs.home-manager.flakeModules.home-manager]; + + flake.modules.nixos.home-manager = { + config, + vars, + ... + }: let + inherit (vars) username; + in { + imports = [inputs.home-manager.nixosModules.home-manager]; + + home-manager = { + useGlobalPkgs = true; + useUserPackages = true; + + backupFileExtension = "backup"; + + users.${username} = { + home = { + inherit username; + homeDirectory = "/home/${username}"; + + # Align home manager state version with the system. + inherit (config.system) stateVersion; + }; + }; + }; + }; } diff --git a/modules/nix/kernel.nix b/modules/nix/kernel.nix new file mode 100644 index 0000000..220801b --- /dev/null +++ b/modules/nix/kernel.nix @@ -0,0 +1,24 @@ +{ + inputs, + self, + ... +}: { + flake-file.inputs.nix-cachyos-kernel.url = "github:xddxdd/nix-cachyos-kernel?ref=release"; + + flake.overlays.nix-cachyos-kernel = inputs.nix-cachyos-kernel.overlays.pinned; + + flake.modules.nixos.kernel = {pkgs, ...}: { + nixpkgs.overlays = [self.overlays.nix-cachyos-kernel]; + + nix.settings = let + cache = "https://attic.xuyh0120.win/lantian"; + in { + substituters = [cache]; + trusted-substituters = [cache]; + trusted-public-keys = ["lantian:EeAUQ+W+6r7EtwnmYjeVwx5kOGEBpjlBfPlzGlTNvHc="]; + }; + + # Use cachyos kernel for performance optimizations. + boot.kernelPackages = pkgs.cachyosKernels.linuxPackages-cachyos-latest-lto; + }; +} diff --git a/modules/nix/lanzaboote.nix b/modules/nix/lanzaboote.nix new file mode 100644 index 0000000..e96b843 --- /dev/null +++ b/modules/nix/lanzaboote.nix @@ -0,0 +1,66 @@ +{ + flake-file.inputs.lanzaboote = { + url = "github:nix-community/lanzaboote?ref=v1.0.0"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + flake.modules.nixos.lanzaboote = { + # keep-sorted start + + inputs, + lib, + pkgs, ... + # keep-sorted end + }: let + inherit (builtins) attrValues; + inherit (lib) mkForce; + in { + imports = [inputs.lanzaboote.nixosModules.lanzaboote]; + + nix.settings = let + cache = "https://lanzaboote.cachix.org"; + in { + substituters = [cache]; + trusted-substituters = [cache]; + trusted-public-keys = ["lanzaboote.cachix.org-1:Nt9//zGmqkg1k5iu+B3bkj3OmHKjSw9pvf3faffLLNk="]; + }; + + boot = { + initrd.systemd.enable = true; + + loader = { + # Skip bootloader timeout for faster boot. + timeout = 0; + + # Secure boot is handled via lanzaboote below. + systemd-boot.enable = mkForce false; + efi.canTouchEfiVariables = true; + }; + + lanzaboote = { + enable = true; + + # Manage secure boot keys on the host during initial setup. + autoGenerateKeys.enable = true; + autoEnrollKeys = { + # Reboot after enrollment so firmware picks up the new keys. + enable = true; + autoReboot = true; + }; + + pkiBundle = "/var/lib/sbctl"; + }; + }; + + # Extra packages for lanzaboote. + environment.systemPackages = attrValues { + inherit + (pkgs) + # keep-sorted start + sbctl + tpm2-tss + # keep-sorted end + ; + }; + }; +} diff --git a/modules/profiles/personal.nix b/modules/profiles/personal.nix index 9018a05..1c42469 100644 --- a/modules/profiles/personal.nix +++ b/modules/profiles/personal.nix @@ -5,11 +5,13 @@ # Profile common. # keep-sorted start + home-manager locale slim stylixPersonal timezone tweaks + users # keep-sorted end ]; diff --git a/modules/programs/appimage.nix b/modules/programs/appimage.nix new file mode 100644 index 0000000..2433e3f --- /dev/null +++ b/modules/programs/appimage.nix @@ -0,0 +1,8 @@ +{ + flake.modules.nixos.appimage = { + programs.appimage = { + enable = true; + binfmt = true; + }; + }; +} diff --git a/modules/programs/cli/eza/default.nix b/modules/programs/cli/eza/default.nix index 6776e2d..d909e24 100644 --- a/modules/programs/cli/eza/default.nix +++ b/modules/programs/cli/eza/default.nix @@ -1,5 +1,13 @@ { - flake.modules.homeManager.eza = _: { + flake.modules.homeManager.eza = { + # keep-sorted start + config, + lib, + # keep-sorted end + ... + }: let + inherit (lib) getExe; + in { programs.eza = { enable = true; @@ -15,5 +23,15 @@ # keep-sorted end ]; }; + + home.shellAliases = let + eza = getExe config.programs.eza.package; + ezaTree = "${eza} --tree --git-ignore"; + in { + # keep-sorted start + lt = ezaTree; + tree = ezaTree; + # keep-sorted end + }; }; } diff --git a/modules/programs/java.nix b/modules/programs/java.nix new file mode 100644 index 0000000..053f256 --- /dev/null +++ b/modules/programs/java.nix @@ -0,0 +1,8 @@ +{ + flake.modules.nixos.java = { + programs.java = { + enable = true; + binfmt = true; + }; + }; +} diff --git a/modules/programs/nix-ld.nix b/modules/programs/nix-ld.nix new file mode 100644 index 0000000..fb78095 --- /dev/null +++ b/modules/programs/nix-ld.nix @@ -0,0 +1,5 @@ +{ + flake.modules.nixos.nix-ld = { + programs.nix-ld.enable = true; + }; +} diff --git a/modules/programs/tui/neovim/default.nix b/modules/programs/tui/neovim/default.nix index baaf55d..6d545c5 100644 --- a/modules/programs/tui/neovim/default.nix +++ b/modules/programs/tui/neovim/default.nix @@ -13,6 +13,16 @@ }; }; + flake.modules.nixos.neovim = { + nix.settings = let + cache = "https://nvf.cachix.org/"; + in { + substituters = [cache]; + trusted-substituters = [cache]; + trusted-public-keys = ["nvf.cachix.org-1:GMQWiUhZ6ux9D5CvFFMwnc2nFrUHTeGaXRlVBXo+naI="]; + }; + }; + flake.modules.homeManager.neovim = { config, lib, diff --git a/modules/programs/tui/opencode/plugins.nix b/modules/programs/tui/opencode/plugins.nix index 3822fa5..b1c047e 100644 --- a/modules/programs/tui/opencode/plugins.nix +++ b/modules/programs/tui/opencode/plugins.nix @@ -1,8 +1,10 @@ {self, ...}: { flake.modules.homeManager.opencode = {pkgs, ...}: { imports = [ + # keep-sorted start pkgs.nur.repos.adam0.hmModules.opencode-plugins self.modules.homeManager.nur + # keep-sorted end ]; programs.opencode.plugins = { @@ -12,6 +14,7 @@ dynamic-context-pruning.enable = true; ignore.enable = true; lazy-mcp.enable = true; + oc-tps.enable = true; unmoji.enable = true; # keep-sorted end diff --git a/modules/programs/tui/television/nix-search.nix b/modules/programs/tui/television/nix-search.nix index 9ef3391..cb27bf1 100644 --- a/modules/programs/tui/television/nix-search.nix +++ b/modules/programs/tui/television/nix-search.nix @@ -174,7 +174,6 @@ prefixes = ["home-manager"]; }; - # TODO: Enable after migrating the lanzaboote flake input. lanzaboote = { rawDoc = mkNixosDoc inputs.lanzaboote.nixosModules.lanzaboote; prefixes = ["boot.lanzaboote"]; diff --git a/modules/services/libinput.nix b/modules/services/libinput.nix index 5f9cf37..2bf8154 100644 --- a/modules/services/libinput.nix +++ b/modules/services/libinput.nix @@ -3,4 +3,19 @@ # Input stack defaults (touchpad, mouse) via libinput. services.libinput.enable = true; }; + + flake.modules.nixos.roccat = { + environment.etc."libinput/local-overrides.quirks" = let + name = "ROCCAT ROCCAT Kain 100"; + in { + text = '' + [${name}] + MatchName=${name} + ModelBouncingKeys=1 + ''; + mode = "0644"; + user = "root"; + group = "root"; + }; + }; } diff --git a/modules/services/nftables.nix b/modules/services/nftables.nix new file mode 100644 index 0000000..4992486 --- /dev/null +++ b/modules/services/nftables.nix @@ -0,0 +1,6 @@ +{ + flake.modules.nixos.nftables = { + # Use nftables; individual services will add rules if needed. + networking.nftables.enable = true; + }; +} diff --git a/modules/services/pipewire.nix b/modules/services/pipewire.nix index 56f2d2b..9b3c37c 100644 --- a/modules/services/pipewire.nix +++ b/modules/services/pipewire.nix @@ -1,5 +1,7 @@ { flake.modules.nixos.pipewire = { + security.rtkit.enable = true; + services.pipewire = { enable = true; diff --git a/modules/users.nix b/modules/users.nix new file mode 100644 index 0000000..3e3fa8d --- /dev/null +++ b/modules/users.nix @@ -0,0 +1,55 @@ +{self, ...}: { + flake.modules.nixos.users = { + # keep-sorted start + + config, + pkgs, + vars, ... + # keep-sorted end + }: let + inherit + (vars) + # keep-sorted start + fullName + username + # keep-sorted end + ; + in { + imports = [self.modules.nixos.sops]; + + # Ensure the user account can be created with a password managed by sops-nix. + sops.secrets.user_password.neededForUsers = true; + + # Allow the user to perform privileged nix operations. + nix.settings = { + # keep-sorted start + allowed-users = [username]; + trusted-users = [username]; + # keep-sorted end + }; + + users = { + # Manage users declaratively, disables imperative changes via passwd/useradd. + mutableUsers = false; + + users.${username} = { + # Hashed password file provided by sops-nix. + hashedPasswordFile = config.sops.secrets.user_password.path; + + extraGroups = [ + # keep-sorted start + "audio" + "wheel" + # keep-sorted end + ]; + + isNormalUser = true; + description = fullName; + shell = pkgs.fish; + + # Allow non-standard shells without /etc/shells checks. + ignoreShellProgramCheck = true; + }; + }; + }; +} diff --git a/todo.md b/todo.md index 825322a..e2e1d3a 100644 --- a/todo.md +++ b/todo.md @@ -17,11 +17,11 @@ ## .github/ -- [ ] dependabot.yml +- [-] dependabot.yml ## .github/workflows/ -- [ ] ci.yml +- [-] ci.yml ## flake/ @@ -204,8 +204,8 @@ - [x] discord.nix - [x] eza.nix - [x] gtk.nix -- [ ] hyprcursor.nix -- [ ] noctalia.nix +- [x] hyprcursor.nix +- [x] noctalia.nix - [x] opencode.nix - [x] other.nix - [x] overzicht.nix @@ -487,14 +487,14 @@ ## modules/system/ -- [ ] default.nix +- [x] default.nix - [ ] disk.nix - [x] locale.nix (moved to modules/profiles/locale.nix) -- [ ] nix.nix +- [x] nix.nix - [x] slim.nix (moved to modules/profiles/slim.nix) - [x] sops.nix (moved to modules/nix/sops.nix) - [x] tweaks.nix (moved to modules/profiles/tweaks.nix) -- [ ] user.nix +- [x] user.nix ## modules/system/cli/ @@ -568,7 +568,7 @@ - [-] default.nix - [x] envfs.nix (moved into the envfs module) - [x] external-pkgs.nix -- [ ] hyprland-plugins.nix +- [x] hyprland-plugins.nix - [-] pkgs.nix - [-] superhtml.nix - [-] zaread.nix -- 2.51.2