diff --git a/flake.lock b/flake.lock index 8f1f222..c1287d7 100644 --- a/flake.lock +++ b/flake.lock @@ -171,11 +171,11 @@ ] }, "locked": { - "lastModified": 1766881808, - "narHash": "sha256-JR7A2xS3EBPWFeONzhqez5vp7nKEsp7eLj2Ks210Srk=", + "lastModified": 1766980997, + "narHash": "sha256-oegDNAvyQwaG3GqSi4U5jpKM7SYHGESGVIuKMRV/lbw=", "owner": "nix-community", "repo": "home-manager", - "rev": "d2e0458d6531885600b346e161c38790dc356fa8", + "rev": "7a7b43c7231a439d248179ba8d561dd6cd81799b", "type": "github" }, "original": { @@ -227,11 +227,11 @@ ] }, "locked": { - "lastModified": 1766880341, - "narHash": "sha256-yYh/TNwR9GsJUT8d73nsK39lZ/j240jDwNr6807lx60=", + "lastModified": 1766966701, + "narHash": "sha256-3AGsMM+RuiIBcnB0I02YyZ5AMMBPYPsNZYU48Yjyntk=", "owner": "nix-community", "repo": "neovim-nightly-overlay", - "rev": "7e6bb31ced1de2c6360122173f63c44113223622", + "rev": "c2a582cef5ccd506e2fae438c7506238d38ced30", "type": "github" }, "original": { @@ -243,11 +243,11 @@ "neovim-src": { "flake": false, "locked": { - "lastModified": 1766877615, - "narHash": "sha256-iojFwrzLMqEaOLkXVjIVLWFW5DU1Vhh40Xndx3fR/Xs=", + "lastModified": 1766966205, + "narHash": "sha256-0QP+beaZydoVTJT8gKVInyKX4yMPWfvS2feY9hulW5E=", "owner": "neovim", "repo": "neovim", - "rev": "ab5a92bff67d654c543d89b4803a64b2e648253a", + "rev": "e916f0327728c78945e6353eeeeb88749b077c0b", "type": "github" }, "original": { @@ -258,11 +258,11 @@ }, "nix-secrets": { "locked": { - "lastModified": 1766928588, - "narHash": "sha256-VCFWAg/72EB8H8ur4WaPwwkkICCzo1lecyOVpPJJRG4=", + "lastModified": 1767035320, + "narHash": "sha256-vcIKF8fLOinWI35OVZzFP6jyXLEvfCcibgEGDqcVDcA=", "ref": "refs/heads/main", - "rev": "1a3cefcb97c5afede0ad69fcdb3e3aa5ba86e027", - "revCount": 8, + "rev": "458133e3b9d33f64d0e79102c09d20bb8568f089", + "revCount": 9, "type": "git", "url": "https://git.ts.endless.li/ed209/nix-secrets.git" }, @@ -362,11 +362,11 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1766651565, - "narHash": "sha256-QEhk0eXgyIqTpJ/ehZKg9IKS7EtlWxF3N7DXy42zPfU=", + "lastModified": 1766902085, + "narHash": "sha256-coBu0ONtFzlwwVBzmjacUQwj3G+lybcZ1oeNSQkgC0M=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "3e2499d5539c16d0d173ba53552a4ff8547f4539", + "rev": "c0b0e0fddf73fd517c3471e546c0df87a42d53f4", "type": "github" }, "original": { @@ -399,11 +399,11 @@ ] }, "locked": { - "lastModified": 1766890375, - "narHash": "sha256-0Zi7ChAtjq/efwQYmp7kOJPcSt6ya9ynSUe6ppgZhsQ=", + "lastModified": 1766976750, + "narHash": "sha256-w+o3AIBI56tzfMJRqRXg9tSXnpQRN5hAT15o2t9rxYw=", "owner": "oxalica", "repo": "rust-overlay", - "rev": "91e1f7a0017065360f447622d11b7ce6ed04772f", + "rev": "9fe44e7f05b734a64a01f92fc51ad064fb0a884f", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix index 62eb78c..3aabfcf 100644 --- a/flake.nix +++ b/flake.nix @@ -71,6 +71,7 @@ outputs = { self, nixpkgs, + agenix, disko, home-manager, nixos-generators, @@ -133,6 +134,7 @@ modules = [ ./hosts/sachiel/configuration.nix disko.nixosModules.disko + agenix.nixosModules.default home-manager.nixosModules.home-manager { home-manager.users."${inputs.nix-secrets.username}" = import ./home-manager/home.nix; diff --git a/home-manager/home.nix b/home-manager/home.nix index c56f083..db502e1 100644 --- a/home-manager/home.nix +++ b/home-manager/home.nix @@ -63,7 +63,7 @@ age age-plugin-tpm age-plugin-yubikey - agenix + agenix.packages.x86_64-linux.default atproto-goat bacon-ls.defaultPackage.x86_64-linux dua diff --git a/hosts/sachiel/configuration.nix b/hosts/sachiel/configuration.nix index 2d438f0..a94cc67 100644 --- a/hosts/sachiel/configuration.nix +++ b/hosts/sachiel/configuration.nix @@ -16,7 +16,6 @@ # Or modules from other flakes (such as nixos-hardware): # inputs.hardware.nixosModules.common-cpu-amd # inputs.hardware.nixosModules.common-ssd - agenix.nixosModules.default impermanence.nixosModules.impermanence # You can also split up your configuration and import pieces of it here: @@ -99,6 +98,9 @@ # Bootloader. boot.loader.systemd-boot.enable = true; + # Load the TPM drivers in the initram to allow for decryption of agenix + # secrets. + boot.initrd.availableKernelModules = ["tpm_crb" "tpm_tis"]; networking.hostName = "sachiel-vm"; # Define your hostname. # networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. @@ -185,8 +187,9 @@ }; # Define a user account. Don't forget to set a password with ‘passwd’. - users.mutableUsers = false; + users.mutableUsers = true; users.users."${inputs.nix-secrets.username}" = { + uid = 1000; isNormalUser = true; description = inputs.nix-secrets.name; extraGroups = ["networkmanager" "wheel"]; @@ -194,7 +197,6 @@ packages = with pkgs; []; shell = pkgs.fish; hashedPasswordFile = config.age.secrets.password.path; - # initialPassword = "test"; }; # Disable root user # users.users.root.hashedPassword = "!";