diff --git a/hosts/sachiel/configuration.nix b/hosts/sachiel/configuration.nix index 9bf102a..99bb381 100644 --- a/hosts/sachiel/configuration.nix +++ b/hosts/sachiel/configuration.nix @@ -44,7 +44,8 @@ user = { username = "${inputs.nix-secrets.username}"; name = "${inputs.nix-secrets.name}"; - authorizedKeys = "${inputs.nix-secrets.ssh-keys}"; + authorizedKeys = inputs.nix-secrets.ssh-keys; + inherit (inputs.nix-secrets) hashedPassword; }; system = { impermanence.enable = true; @@ -56,7 +57,7 @@ secureBoot = true; }; network = { - hostname = "sachiel-vm"; + hostName = "sachiel-vm"; wireless.enable = true; }; }; diff --git a/modules/nixos/system/agenix/default.nix b/modules/nixos/system/agenix/default.nix index a83c845..9799df9 100644 --- a/modules/nixos/system/agenix/default.nix +++ b/modules/nixos/system/agenix/default.nix @@ -23,7 +23,7 @@ in { default = ["/persistent/age-tpm.txt"]; example = '' { - password.file = "${nix-secrets}/password.age"; + password.file = "\$\{nix-secrets}/password.age"; } ''; type = lib.types.attrs; @@ -37,7 +37,7 @@ in { boot.initrd.availableKernelModules = ["tpm_crb" "tpm_tis"]; age = { - inherit (cfg) indentityPaths; + inherit (cfg) identityPaths; ageBin = "PATH=$PATH:${lib.makeBinPath [pkgs.age-plugin-tpm]} ${pkgs.age}/bin/age"; inherit (cfg) secrets; }; diff --git a/modules/nixos/system/boot/default.nix b/modules/nixos/system/boot/default.nix index 475b74e..88b8374 100644 --- a/modules/nixos/system/boot/default.nix +++ b/modules/nixos/system/boot/default.nix @@ -3,22 +3,21 @@ lib, pkgs, ... -}: -with lib; let +}: let cfg = config.system.boot; in { options.system.boot = { enable = - mkEnableOption "Enable boot"; + lib.mkEnableOption "Enable boot"; - secureBoot = mkEnableOption "Enable secure boot"; + secureBoot = lib.mkEnableOption "Enable secure boot"; }; - config = mkIf cfg.enable { + config = lib.mkIf cfg.enable { boot = { - lanzaboote = mkIf cfg.secureBoot { + lanzaboote = lib.mkIf cfg.secureBoot { enable = true; - pkiBundle = "/etc/secureboot"; + pkiBundle = "/etc/secureboot/pki"; autoGenerateKeys.enable = true; autoEnrollKeys = { @@ -30,7 +29,7 @@ in { }; }; loader.systemd-boot = { - enable = !cfg.secureBoot; + enable = lib.mkForce (!cfg.secureBoot); configurationLimit = 10; editor = false; }; @@ -41,9 +40,9 @@ in { # efitools # efivar ] - ++ optionals cfg.secureBoot [sbctl]; - environment.persistence = mkIf (cfg.secureBoot && config.system.impermanence.enable) { - "/persist" = { + ++ lib.optionals cfg.secureBoot [sbctl]; + environment.persistence = lib.mkIf (cfg.secureBoot && config.system.impermanence.enable) { + "/persistent" = { directories = [ "/etc/secureboot" ]; diff --git a/modules/nixos/system/network/default.nix b/modules/nixos/system/network/default.nix index bef1d54..df4145c 100644 --- a/modules/nixos/system/network/default.nix +++ b/modules/nixos/system/network/default.nix @@ -37,7 +37,7 @@ in { # Enable networking networkmanager.enable = true; - networking.networkmanager.wifi.backend = "iwd"; + networkmanager.wifi.backend = "iwd"; }; }; } diff --git a/modules/nixos/user/default.nix b/modules/nixos/user/default.nix index b50cf66..ff888d1 100644 --- a/modules/nixos/user/default.nix +++ b/modules/nixos/user/default.nix @@ -19,8 +19,8 @@ in { }; hashedPassword = lib.mkOption { example = "$6$jLSvA3N6TFsO87CK$1RynQlkNfmf59pzdHH.NuY3lc3nrR3m4nIBjTbdZkXV.t1IbhOOs1FG1qN67ghJaZYYoiBgDkzQn8AtsS8FXo0"; - type = lib.passwdEntry lib.types.str; - description = "Generage hased password using `mkpasswd -m sha-512`"; + type = lib.types.str; + description = "Generate hashed password using `mkpasswd -m sha-512`"; }; authorizedKeys = lib.mkOption { type = lib.types.listOf lib.types.str; @@ -74,6 +74,6 @@ in { } // cfg.extraOptions; }; - users.root.hashedPassword = lib.mkIf cfg.disableRoot "!"; + users.users.root.hashedPassword = lib.mkIf cfg.disableRoot "!"; }; }