diff --git a/13-inch-thin-cannon/configuration.nix b/13-inch-thin-cannon/configuration.nix index 158a28e..c3a6f0c 100644 --- a/13-inch-thin-cannon/configuration.nix +++ b/13-inch-thin-cannon/configuration.nix @@ -1,20 +1,18 @@ # Edit this configuration file to define what should be installed on # your system. Help is available in the configuration.nix(5) man page # and in the NixOS manual (accessible by running ‘nixos-help’). - { config, pkgs, lib, ... -}: - -{ - imports = [ - ./hardware-configuration.nix - ../modules/secrets.nix - ] - ++ lib.optional (builtins.pathExists ./wireguard.nix) ./wireguard.nix; +}: { + imports = + [ + ./hardware-configuration.nix + ../modules/secrets.nix + ] + ++ lib.optional (builtins.pathExists ./wireguard.nix) ./wireguard.nix; nix.settings.experimental-features = [ "nix-command" "flakes" diff --git a/13-inch-thin-cannon/hardware-configuration.nix b/13-inch-thin-cannon/hardware-configuration.nix index a84fd66..66a48b1 100644 --- a/13-inch-thin-cannon/hardware-configuration.nix +++ b/13-inch-thin-cannon/hardware-configuration.nix @@ -1,34 +1,36 @@ # Do not modify this file! It was generated by ‘nixos-generate-config’ # and may be overwritten by future invocations. Please make changes # to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: - { - imports = - [ - (modulesPath + "/installer/scan/not-detected.nix") - - ]; + config, + lib, + pkgs, + modulesPath, + ... +}: { + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + ]; - boot.initrd.availableKernelModules = [ "xhci_pci" "nvme" "usb_storage" "usbhid" "sd_mod" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ "kvm-intel" ]; - boot.extraModulePackages = [ ]; + boot.initrd.availableKernelModules = ["xhci_pci" "nvme" "usb_storage" "usbhid" "sd_mod"]; + boot.initrd.kernelModules = []; + boot.kernelModules = ["kvm-intel"]; + boot.extraModulePackages = []; - fileSystems."/" = - { device = "/dev/disk/by-uuid/76cffb2a-7482-4116-a423-c7ede185ca7d"; - fsType = "ext4"; - }; + fileSystems."/" = { + device = "/dev/disk/by-uuid/76cffb2a-7482-4116-a423-c7ede185ca7d"; + fsType = "ext4"; + }; - fileSystems."/boot" = - { device = "/dev/disk/by-uuid/209F-2960"; - fsType = "vfat"; - options = [ "fmask=0077" "dmask=0077" ]; - }; + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/209F-2960"; + fsType = "vfat"; + options = ["fmask=0077" "dmask=0077"]; + }; - swapDevices = - [ { device = "/dev/disk/by-uuid/5bece5cb-4baf-4d7b-87bd-400f997c401e"; } - ]; + swapDevices = [ + {device = "/dev/disk/by-uuid/5bece5cb-4baf-4d7b-87bd-400f997c401e";} + ]; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; diff --git a/13-inch-thin-cannon/home.nix b/13-inch-thin-cannon/home.nix index 4e42e4d..158affc 100644 --- a/13-inch-thin-cannon/home.nix +++ b/13-inch-thin-cannon/home.nix @@ -3,60 +3,60 @@ pkgs, lib, ... -}: -let - hyprModule = import ../modules/hyprland.nix { inherit pkgs lib; }; -in -{ - imports = [ ../home.nix ]; +}: let + hyprModule = import ../modules/hyprland.nix {inherit pkgs lib;}; +in { + imports = [../home.nix]; fonts.fontconfig.enable = true; wayland.windowManager.hyprland = hyprModule.hyprland; - home.packages = hyprModule.packages ++ (with pkgs; [ - alacritty - neovim - nautilus - nautilus-python - sushi - kdiff3 - krename - thunderbird - file - pandoc - ripgrep - audacity - bat - p7zip - parallel - outils - dbeaver-bin - android-studio - pciutils - nextcloud-client - obs-studio - vlc - swayidle - dracula-theme - wl-clipboard - wdisplays - swww - fira-code - fira-code-symbols - font-awesome - liberation_ttf - mplus-outline-fonts.githubRelease - proggyfonts - hack-font - lutris - wine - pavucontrol - mupdf - networkmanagerapplet - ansible-lint - orca-slicer - opencode - ]); + home.packages = + hyprModule.packages + ++ (with pkgs; [ + alacritty + neovim + nautilus + nautilus-python + sushi + kdiff3 + krename + thunderbird + file + pandoc + ripgrep + audacity + bat + p7zip + parallel + outils + dbeaver-bin + android-studio + pciutils + nextcloud-client + obs-studio + vlc + swayidle + dracula-theme + wl-clipboard + wdisplays + swww + fira-code + fira-code-symbols + font-awesome + liberation_ttf + mplus-outline-fonts.githubRelease + proggyfonts + hack-font + lutris + wine + pavucontrol + mupdf + networkmanagerapplet + ansible-lint + orca-slicer + opencode + ]); home.pointerCursor = { gtk.enable = true; @@ -78,7 +78,7 @@ in s = "status"; }; extraConfig = { - init = { defaultBranch = "main"; }; + init = {defaultBranch = "main";}; }; }; }; diff --git a/13-inch-thin-cannon/wireguard.nix b/13-inch-thin-cannon/wireguard.nix index 9a277a4..20633f6 100644 --- a/13-inch-thin-cannon/wireguard.nix +++ b/13-inch-thin-cannon/wireguard.nix @@ -1,14 +1,16 @@ -{ config, pkgs, ... }: { + config, + pkgs, + ... +}: { networking.wireguard.interfaces = { wg0 = { - ips = [ "10.0.0.3/24" ]; - dns = [ "10.2.0.1"]; + ips = ["10.0.0.3/24"]; privateKeyFile = config.age.secrets."wireguard-key-13-inch-thin-cannon".path; peers = [ { publicKey = "sn2DwUHXSLYbub6dVFKRhE2QHcji5I8TMSotCTlGFw0"; - allowedIPs = [ "0.0.0.0/0" "::/0" ]; + allowedIPs = ["0.0.0.0/0" "::/0"]; endpoint = "185.159.158.226:51820"; persistentKeepalive = 25; } diff --git a/flake.nix b/flake.nix index 48aaa17..cd03abb 100644 --- a/flake.nix +++ b/flake.nix @@ -17,87 +17,84 @@ }; }; - outputs = - { - self, - nixpkgs, - home-manager, - nur, - agenix, - ... - }: - let - lib = nixpkgs.lib; - system = "x86_64-linux"; - nurOverlay = final: prev: { - nur = import nur { - nurpkgs = import nixpkgs { system = final.system; }; - pkgs = final; - }; - }; - in - { - checks."${system}" = { - thick-black-cannon = self.nixosConfigurations.thick-black-cannon.config.system.build.toplevel; - "13-inch-thin-cannon" = self.nixosConfigurations."13-inch-thin-cannon".config.system.build.toplevel; + outputs = { + self, + nixpkgs, + home-manager, + nur, + agenix, + ... + }: let + lib = nixpkgs.lib; + system = "x86_64-linux"; + nurOverlay = final: prev: { + nur = import nur { + nurpkgs = import nixpkgs {system = final.system;}; + pkgs = final; }; + }; + in { + checks."${system}" = { + thick-black-cannon = self.nixosConfigurations.thick-black-cannon.config.system.build.toplevel; + "13-inch-thin-cannon" = self.nixosConfigurations."13-inch-thin-cannon".config.system.build.toplevel; + }; - devShells."${system}".default = nixpkgs.legacyPackages.${system}.mkShell { - packages = [ agenix.packages."${system}".agenix ]; - }; + devShells."${system}".default = nixpkgs.legacyPackages.${system}.mkShell { + packages = [agenix.packages."${system}".agenix]; + }; - nixosConfigurations = { - thick-black-cannon = lib.nixosSystem { - inherit system; - modules = [ - ./thick-black-cannon/configuration.nix - agenix.nixosModules.age - home-manager.nixosModules.default - { - home-manager = { - useGlobalPkgs = true; - useUserPackages = true; - users.file_magic = ./thick-black-cannon/home.nix; - }; + nixosConfigurations = { + thick-black-cannon = lib.nixosSystem { + inherit system; + modules = [ + ./thick-black-cannon/configuration.nix + agenix.nixosModules.age + home-manager.nixosModules.default + { + home-manager = { + useGlobalPkgs = true; + useUserPackages = true; + users.file_magic = ./thick-black-cannon/home.nix; + }; - environment.pathsToLink = [ - "/share/applications" - "/share/xdg-desktop-portal" - ]; - nixpkgs.overlays = [ nurOverlay ]; - nixpkgs.config = { - allowUnfree = true; - permittedInsecurePackages = [ "electron-39.8.10" ]; - }; - } - ]; - }; + environment.pathsToLink = [ + "/share/applications" + "/share/xdg-desktop-portal" + ]; + nixpkgs.overlays = [nurOverlay]; + nixpkgs.config = { + allowUnfree = true; + permittedInsecurePackages = ["electron-39.8.10"]; + }; + } + ]; + }; - "13-inch-thin-cannon" = lib.nixosSystem { - inherit system; - modules = [ - ./13-inch-thin-cannon/configuration.nix - agenix.nixosModules.age - home-manager.nixosModules.default - { - home-manager = { - useGlobalPkgs = true; - useUserPackages = true; - users.file_magic = ./13-inch-thin-cannon/home.nix; - }; + "13-inch-thin-cannon" = lib.nixosSystem { + inherit system; + modules = [ + ./13-inch-thin-cannon/configuration.nix + agenix.nixosModules.age + home-manager.nixosModules.default + { + home-manager = { + useGlobalPkgs = true; + useUserPackages = true; + users.file_magic = ./13-inch-thin-cannon/home.nix; + }; - environment.pathsToLink = [ - "/share/applications" - "/share/xdg-desktop-portal" - ]; - nixpkgs.overlays = [ nurOverlay ]; - nixpkgs.config = { - allowUnfree = true; - permittedInsecurePackages = [ "electron-39.8.10" ]; - }; - } - ]; - }; + environment.pathsToLink = [ + "/share/applications" + "/share/xdg-desktop-portal" + ]; + nixpkgs.overlays = [nurOverlay]; + nixpkgs.config = { + allowUnfree = true; + permittedInsecurePackages = ["electron-39.8.10"]; + }; + } + ]; }; }; + }; } diff --git a/home.nix b/home.nix index a129aad..732c05a 100644 --- a/home.nix +++ b/home.nix @@ -3,8 +3,7 @@ pkgs, lib, ... -}: -{ +}: { imports = [ ./modules/firefox.nix ./modules/bash.nix @@ -16,47 +15,46 @@ enable = true; associations.added = { - "x-scheme-handler/http" = [ "firefox.desktop;" ]; - "x-scheme-handler/https" = [ "firefox.desktop;" ]; - "x-scheme-handler/chrome" = [ "firefox.desktop;" ]; - "text/html" = [ "firefox.desktop;" ]; - "application/x-extension-htm" = [ "firefox.desktop;" ]; - "application/x-extension-html" = [ "firefox.desktop;" ]; - "application/x-extension-shtml" = [ "firefox.desktop;" ]; - "application/xhtml+xml" = [ "firefox.desktop;" ]; - "application/x-extension-xhtml" = [ "firefox.desktop;" ]; - "application/x-extension-insv" = [ "vlc.desktop;" ]; - "application/x-extension-mp4" = [ "vlc.desktop;" ]; - "application/x-extension-lrv" = [ "vlc.desktop;" ]; - "application/x-extension-xht" = [ "firefox.desktop;" ]; - "inode/directory" = [ "nautilus.desktop" ]; + "x-scheme-handler/http" = ["firefox.desktop;"]; + "x-scheme-handler/https" = ["firefox.desktop;"]; + "x-scheme-handler/chrome" = ["firefox.desktop;"]; + "text/html" = ["firefox.desktop;"]; + "application/x-extension-htm" = ["firefox.desktop;"]; + "application/x-extension-html" = ["firefox.desktop;"]; + "application/x-extension-shtml" = ["firefox.desktop;"]; + "application/xhtml+xml" = ["firefox.desktop;"]; + "application/x-extension-xhtml" = ["firefox.desktop;"]; + "application/x-extension-insv" = ["vlc.desktop;"]; + "application/x-extension-mp4" = ["vlc.desktop;"]; + "application/x-extension-lrv" = ["vlc.desktop;"]; + "application/x-extension-xht" = ["firefox.desktop;"]; + "inode/directory" = ["nautilus.desktop"]; }; defaultApplications = { "x-scheme-handler/https" = "firefox.desktop"; "x-scheme-handler/about" = "firefox.desktop"; - "x-scheme-handler/http" = [ "firefox.desktop" ]; - "x-scheme-handler/chrome" = [ "firefox.desktop" ]; - "text/html" = [ "firefox.desktop" ]; - "application/x-extension-htm" = [ "firefox.desktop" ]; - "application/x-extension-html" = [ "firefox.desktop" ]; - "application/x-extension-shtml" = [ "firefox.desktop" ]; - "application/xhtml+xml" = [ "firefox.desktop" ]; - "application/x-extension-xhtml" = [ "firefox.desktop" ]; - "application/x-extension-xht" = [ "firefox.desktop" ]; - "inode/directory" = [ "nautilus.desktop" ]; + "x-scheme-handler/http" = ["firefox.desktop"]; + "x-scheme-handler/chrome" = ["firefox.desktop"]; + "text/html" = ["firefox.desktop"]; + "application/x-extension-htm" = ["firefox.desktop"]; + "application/x-extension-html" = ["firefox.desktop"]; + "application/x-extension-shtml" = ["firefox.desktop"]; + "application/xhtml+xml" = ["firefox.desktop"]; + "application/x-extension-xhtml" = ["firefox.desktop"]; + "application/x-extension-xht" = ["firefox.desktop"]; + "inode/directory" = ["nautilus.desktop"]; "x-scheme-handler/unknown" = "zeditor.desktop"; }; associations.removed = { - "application/pdf" = [ "chromium-browser.desktop" ]; - "image/png" = [ "chromium-browser.desktop" ]; - "inode/directory" = [ "code.desktop" ]; + "application/pdf" = ["chromium-browser.desktop"]; + "image/png" = ["chromium-browser.desktop"]; + "inode/directory" = ["code.desktop"]; }; }; }; nixpkgs = { config = { - allowUnfreePredicate = - pkg: + allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) [ "steam" "steam-unwrapped" @@ -64,7 +62,6 @@ "spotify" ]; }; - }; services = { podman.enable = true; @@ -151,16 +148,16 @@ OpenCode = { type = "custom"; command = "opencode"; - args = [ "acp" ]; + args = ["acp"]; }; }; edit_predictions = { allow_data_collection = "no"; }; agent = { - favorite_models = [ ]; + favorite_models = []; single_file_review = true; - model_parameters = [ ]; + model_parameters = []; }; telemetry = { diagnostics = false; diff --git a/kubernetes/common.nix b/kubernetes/common.nix index 7108c64..7d26fd5 100644 --- a/kubernetes/common.nix +++ b/kubernetes/common.nix @@ -7,8 +7,7 @@ subnetThirdOctet ? 122, nodeHosts ? "", ... -}: -{ +}: { # System system.stateVersion = "25.11"; nix.settings.experimental-features = [ @@ -21,7 +20,7 @@ boot.loader.systemd-boot.consoleMode = "max"; boot.loader.efi.canTouchEfiVariables = true; boot.kernelPackages = pkgs.linuxPackages_latest; - boot.kernelParams = [ "console=ttyS0" ]; + boot.kernelParams = ["console=ttyS0"]; # Kernel modules required for Cilium boot.extraModprobeConfig = "options br_netfilter enable_netfilter_for_l3=1"; @@ -94,14 +93,14 @@ # from a running Cilium container using ctr. systemd.services.install-cilium-cni = { description = "Install cilium-cni binary from running Cilium container"; - wantedBy = [ "multi-user.target" ]; + wantedBy = ["multi-user.target"]; after = [ "containerd.service" "kubelet.service" ]; - requires = [ "containerd.service" ]; + requires = ["containerd.service"]; serviceConfig.Type = "oneshot"; - path = with pkgs; [ kubectl ]; + path = with pkgs; [kubectl]; preStart = '' mkdir -p /opt/cni/bin ''; @@ -128,10 +127,11 @@ # Base packages environment.systemPackages = with pkgs; [ (python3.withPackages ( - ps: with ps; [ - pyyaml - kubernetes - ] + ps: + with ps; [ + pyyaml + kubernetes + ] )) kubectl kubernetes-helm @@ -164,12 +164,12 @@ # On workers: writes directly to secrets path. systemd.services.k8s-write-apitoken = { description = "Write fixed cfssl API token"; - wantedBy = [ "multi-user.target" ]; + wantedBy = ["multi-user.target"]; before = [ "cfssl.service" "kube-certmgr-bootstrap.service" ]; - after = [ "local-fs.target" ]; + after = ["local-fs.target"]; serviceConfig.Type = "oneshot"; script = '' TOKEN_FILE=/tmp/k8s-apitoken.tmp diff --git a/kubernetes/flake.nix b/kubernetes/flake.nix index 2f0be12..a21ba70 100644 --- a/kubernetes/flake.nix +++ b/kubernetes/flake.nix @@ -5,98 +5,100 @@ nixpkgs.url = "github:nixos/nixpkgs?ref=nixos-unstable"; }; - outputs = - { self, nixpkgs, ... }: - let - lib = nixpkgs.lib; - system = "x86_64-linux"; - pkgs = nixpkgs.legacyPackages.${system}; - - sshPublicKey = builtins.readFile ./ssh-public-key; - k8sApiToken = "8c3ff57ab1e1de5de0dd0feddb3f26ac"; - - # Read cluster configuration from environment - clusterIndex = - let - envVal = builtins.getEnv "CLUSTER_INDEX"; - in - if envVal == "" then 0 else builtins.fromJSON envVal; - - workerCount = - let - envVal = builtins.getEnv "WORKER_COUNT"; - in - if envVal == "" then 3 else builtins.fromJSON envVal; - - subnetThirdOctet = 122 + clusterIndex; - subnetPrefix = "192.168.${toString subnetThirdOctet}"; + outputs = { + self, + nixpkgs, + ... + }: let + lib = nixpkgs.lib; + system = "x86_64-linux"; + pkgs = nixpkgs.legacyPackages.${system}; + + sshPublicKey = builtins.readFile ./ssh-public-key; + k8sApiToken = "8c3ff57ab1e1de5de0dd0feddb3f26ac"; + + # Read cluster configuration from environment + clusterIndex = let + envVal = builtins.getEnv "CLUSTER_INDEX"; + in + if envVal == "" + then 0 + else builtins.fromJSON envVal; - qemuGuestModule = { - imports = [ "${toString nixpkgs}/nixos/modules/profiles/qemu-guest.nix" ]; - fileSystems."/" = { - device = "/dev/disk/by-label/nixos"; - autoResize = true; - fsType = "ext4"; - }; - virtualisation.diskSize = 20480; + workerCount = let + envVal = builtins.getEnv "WORKER_COUNT"; + in + if envVal == "" + then 3 + else builtins.fromJSON envVal; + + subnetThirdOctet = 122 + clusterIndex; + subnetPrefix = "192.168.${toString subnetThirdOctet}"; + + qemuGuestModule = { + imports = ["${toString nixpkgs}/nixos/modules/profiles/qemu-guest.nix"]; + fileSystems."/" = { + device = "/dev/disk/by-label/nixos"; + autoResize = true; + fsType = "ext4"; }; + virtualisation.diskSize = 20480; + }; - # Master node (always index 0) - masterNode = { - k8s-master-0 = { - ip = "${subnetPrefix}.10"; - modules = [ ./master.nix ]; - }; + # Master node (always index 0) + masterNode = { + k8s-master-0 = { + ip = "${subnetPrefix}.10"; + modules = [./master.nix]; }; + }; - # Worker nodes (dynamically generated) - workerNodes = lib.genAttrs (lib.genList (i: "k8s-worker-${toString i}") workerCount) ( - name: - let - idx = lib.last (lib.splitString "-" name); - ipSuffix = 11 + (builtins.fromJSON idx); - in + # Worker nodes (dynamically generated) + workerNodes = lib.genAttrs (lib.genList (i: "k8s-worker-${toString i}") workerCount) ( + name: let + idx = lib.last (lib.splitString "-" name); + ipSuffix = 11 + (builtins.fromJSON idx); + in { + ip = "${subnetPrefix}.${toString ipSuffix}"; + modules = [./worker.nix]; + extraConfig = { + services.kubernetes.kubelet.nodeIp = "${subnetPrefix}.${toString ipSuffix}"; + }; + } + ); + + nodeConfigs = masterNode // workerNodes; + + # Generate /etc/hosts content for all nodes + nodeHosts = lib.concatStringsSep "\n" ( + lib.mapAttrsToList (name: node: "${node.ip} ${name}") nodeConfigs + ); + + mkModules = name: node: + [ + qemuGuestModule + ./common.nix + ] + ++ node.modules + ++ [ { - ip = "${subnetPrefix}.${toString ipSuffix}"; - modules = [ ./worker.nix ]; - extraConfig = { - services.kubernetes.kubelet.nodeIp = "${subnetPrefix}.${toString ipSuffix}"; - }; + networking.hostName = name; + networking.interfaces.enp1s0.ipv4.addresses = [ + { + address = node.ip; + prefixLength = 24; + } + ]; } - ); - - nodeConfigs = masterNode // workerNodes; - - # Generate /etc/hosts content for all nodes - nodeHosts = lib.concatStringsSep "\n" ( - lib.mapAttrsToList (name: node: "${node.ip} ${name}") nodeConfigs - ); - - mkModules = - name: node: - [ - qemuGuestModule - ./common.nix - ] - ++ node.modules - ++ [ - { - networking.hostName = name; - networking.interfaces.enp1s0.ipv4.addresses = [ - { - address = node.ip; - prefixLength = 24; - } - ]; - } - ] - ++ lib.optionals (node ? extraConfig) [ node.extraConfig ]; - - mkNixosConfig = - name: node: - lib.nixosSystem { - inherit system; - modules = mkModules name node ++ [ + ] + ++ lib.optionals (node ? extraConfig) [node.extraConfig]; + + mkNixosConfig = name: node: + lib.nixosSystem { + inherit system; + modules = + mkModules name node + ++ [ { _module.args.sshPublicKey = sshPublicKey; _module.args.k8sApiToken = k8sApiToken; @@ -104,28 +106,28 @@ _module.args.nodeHosts = nodeHosts; } ]; - }; - - configs = lib.mapAttrs mkNixosConfig nodeConfigs; - - in - { - nixosConfigurations = configs; + }; - packages.${system} = - lib.mapAttrs' (name: cfg: { - name = name; - value = cfg.config.system.build.images.qemu-efi; - }) configs - // { - images = pkgs.runCommand "k8s-images" { } '' - mkdir -p $out - ${lib.concatStringsSep "\n" ( - lib.mapAttrsToList (name: cfg: '' - cp ${cfg.config.system.build.images.qemu-efi}/nixos*.qcow2 $out/${name}.qcow2 - '') configs - )} - ''; - }; - }; + configs = lib.mapAttrs mkNixosConfig nodeConfigs; + in { + nixosConfigurations = configs; + + packages.${system} = + lib.mapAttrs' (name: cfg: { + name = name; + value = cfg.config.system.build.images.qemu-efi; + }) + configs + // { + images = pkgs.runCommand "k8s-images" {} '' + mkdir -p $out + ${lib.concatStringsSep "\n" ( + lib.mapAttrsToList (name: cfg: '' + cp ${cfg.config.system.build.images.qemu-efi}/nixos*.qcow2 $out/${name}.qcow2 + '') + configs + )} + ''; + }; + }; } diff --git a/kubernetes/master.nix b/kubernetes/master.nix index 70269a6..fc3b0fb 100644 --- a/kubernetes/master.nix +++ b/kubernetes/master.nix @@ -4,9 +4,8 @@ lib, subnetThirdOctet ? 122, ... -}: -{ - imports = [ ./common.nix ]; +}: { + imports = [./common.nix]; networking.hostName = "k8s-master-0"; networking.interfaces.enp1s0.ipv4.addresses = [ @@ -18,7 +17,7 @@ networking.defaultGateway = "192.168.${toString subnetThirdOctet}.1"; services.kubernetes = { - roles = [ "master" ]; + roles = ["master"]; masterAddress = "192.168.${toString subnetThirdOctet}.10"; easyCerts = true; pki.genCfsslAPIToken = false; # We write a fixed token via k8s-write-apitoken service diff --git a/kubernetes/shell.nix b/kubernetes/shell.nix index cbef0b0..3c0779d 100644 --- a/kubernetes/shell.nix +++ b/kubernetes/shell.nix @@ -1,5 +1,4 @@ -{ pkgs ? import { } }: - +{pkgs ? import {}}: pkgs.mkShell { packages = [ pkgs.alejandra diff --git a/kubernetes/worker.nix b/kubernetes/worker.nix index 50f59a1..a2b2c92 100644 --- a/kubernetes/worker.nix +++ b/kubernetes/worker.nix @@ -4,14 +4,13 @@ lib, subnetThirdOctet ? 122, ... -}: -{ - imports = [ ./common.nix ]; +}: { + imports = [./common.nix]; networking.defaultGateway = "192.168.${toString subnetThirdOctet}.1"; services.kubernetes = { - roles = [ "node" ]; + roles = ["node"]; masterAddress = "192.168.${toString subnetThirdOctet}.10"; easyCerts = true; kubelet = { diff --git a/modules/bash.nix b/modules/bash.nix index 7c76386..45f7534 100644 --- a/modules/bash.nix +++ b/modules/bash.nix @@ -3,11 +3,9 @@ pkgs, lib, ... -}: -let +}: let homeDir = config.home.homeDirectory; -in -{ +in { programs.bash = { enable = true; shellAliases = { @@ -32,6 +30,5 @@ in ''; k8s-build = "nix build ${homeDir}/Projects/tangled/nix/kubernetes#images && ls -lh ${homeDir}/Projects/tangled/nix/kubernetes/result/"; }; - }; } diff --git a/modules/firefox.nix b/modules/firefox.nix index 8297c6d..8e13794 100644 --- a/modules/firefox.nix +++ b/modules/firefox.nix @@ -58,47 +58,76 @@ default = "ddg"; engines = { "Nix Packages" = { - urls = [{ - template = "https://search.nixos.org/packages"; - params = [ - { name = "type"; value = "packages"; } - { name = "query"; value = "{searchTerms}"; } - ]; - }]; + urls = [ + { + template = "https://search.nixos.org/packages"; + params = [ + { + name = "type"; + value = "packages"; + } + { + name = "query"; + value = "{searchTerms}"; + } + ]; + } + ]; icon = "''${pkgs.nixos-icons}/share/icons/hicolor/scalable/apps/nix-snowflake.svg"; - definedAliases = [ "@np" ]; + definedAliases = ["@np"]; }; "Nix Options" = { - urls = [{ - template = "https://search.nixos.org/options"; - params = [ - { name = "type"; value = "options"; } - { name = "query"; value = "{searchTerms}"; } - ]; - }]; + urls = [ + { + template = "https://search.nixos.org/options"; + params = [ + { + name = "type"; + value = "options"; + } + { + name = "query"; + value = "{searchTerms}"; + } + ]; + } + ]; icon = "''${pkgs.nixos-icons}/share/icons/hicolor/scalable/apps/nix-snowflake.svg"; - definedAliases = [ "@no" ]; + definedAliases = ["@no"]; }; "Nix Flakes" = { - urls = [{ - template = "https://search.nixos.org/flakes"; - params = [ - { name = "type"; value = "flakes"; } - { name = "query"; value = "{searchTerms}"; } - ]; - }]; + urls = [ + { + template = "https://search.nixos.org/flakes"; + params = [ + { + name = "type"; + value = "flakes"; + } + { + name = "query"; + value = "{searchTerms}"; + } + ]; + } + ]; icon = "''${pkgs.nixos-icons}/share/icons/hicolor/scalable/apps/nix-snowflake.svg"; - definedAliases = [ "@nf" ]; + definedAliases = ["@nf"]; }; "Home Manager Options" = { - urls = [{ - template = "https://home-manager-options.extranix.com"; - params = [ - { name = "query"; value = "{searchTerms}"; } - ]; - }]; + urls = [ + { + template = "https://home-manager-options.extranix.com"; + params = [ + { + name = "query"; + value = "{searchTerms}"; + } + ]; + } + ]; icon = "''${pkgs.nixos-icons}/share/icons/hicolor/scalable/apps/nix-snowflake.svg"; - definedAliases = [ "@hm" ]; + definedAliases = ["@hm"]; }; }; }; diff --git a/modules/hyprland.nix b/modules/hyprland.nix index b6f7203..91ef156 100644 --- a/modules/hyprland.nix +++ b/modules/hyprland.nix @@ -1,8 +1,7 @@ { pkgs, lib, -}: -let +}: let lua = lib.generators.mkLuaInline; dsp = { @@ -39,11 +38,9 @@ let }; workspaceBinds = lib.concatMap ( - i: - let + i: let key = toString (lib.mod i 10); - in - [ + in [ (bind "SUPER + ${key}" (dsp.focusWorkspace i)) (bind "SUPER + SHIFT + ${key}" (dsp.moveToWorkspace i)) ] @@ -58,8 +55,7 @@ let steam & discord & ''; -in -{ +in { gtk = { enable = true; @@ -239,69 +235,70 @@ in ]; }; - bind = [ - # App launchers - (bind "SUPER + RETURN" (dsp.exec "kitty")) - (bind "SUPER + D" (dsp.exec "walker")) - (bind "SUPER + R" (dsp.exec "walker -m runner")) - (bind "SUPER + CTRL + V" (dsp.exec "walker -m clipboard")) + bind = + [ + # App launchers + (bind "SUPER + RETURN" (dsp.exec "kitty")) + (bind "SUPER + D" (dsp.exec "walker")) + (bind "SUPER + R" (dsp.exec "walker -m runner")) + (bind "SUPER + CTRL + V" (dsp.exec "walker -m clipboard")) - # Screenshots - (bind "SUPER + SHIFT + S" (dsp.exec "grimblast copysave active")) + # Screenshots + (bind "SUPER + SHIFT + S" (dsp.exec "grimblast copysave active")) - # Universal copy/paste - (bind "SUPER + C" (dsp.sendshortcut "CTRL" "Insert")) - (bind "SUPER + V" (dsp.sendshortcut "SHIFT" "Insert")) - (bind "SUPER + X" (dsp.sendshortcut "CTRL" "X")) + # Universal copy/paste + (bind "SUPER + C" (dsp.sendshortcut "CTRL" "Insert")) + (bind "SUPER + V" (dsp.sendshortcut "SHIFT" "Insert")) + (bind "SUPER + X" (dsp.sendshortcut "CTRL" "X")) - # Window management - (bind "SUPER + SHIFT + Q" dsp.close) - (bind "SUPER + SHIFT + E" dsp.exit) - (bind "SUPER + L" (dsp.exec "hyprlock")) - (bind "SUPER + T" dsp.float) - (bind "SUPER + F" dsp.fullscreen) - (bind "SUPER + P" dsp.pseudo) - (bind "SUPER + J" (dsp.layout "togglesplit")) + # Window management + (bind "SUPER + SHIFT + Q" dsp.close) + (bind "SUPER + SHIFT + E" dsp.exit) + (bind "SUPER + L" (dsp.exec "hyprlock")) + (bind "SUPER + T" dsp.float) + (bind "SUPER + F" dsp.fullscreen) + (bind "SUPER + P" dsp.pseudo) + (bind "SUPER + J" (dsp.layout "togglesplit")) - # Focus - (bind "SUPER + left" (dsp.focus "left")) - (bind "SUPER + right" (dsp.focus "right")) - (bind "SUPER + up" (dsp.focus "up")) - (bind "SUPER + down" (dsp.focus "down")) + # Focus + (bind "SUPER + left" (dsp.focus "left")) + (bind "SUPER + right" (dsp.focus "right")) + (bind "SUPER + up" (dsp.focus "up")) + (bind "SUPER + down" (dsp.focus "down")) - # Swap windows - (bind "SUPER + SHIFT + left" (dsp.swap "left")) - (bind "SUPER + SHIFT + right" (dsp.swap "right")) - (bind "SUPER + SHIFT + up" (dsp.swap "up")) - (bind "SUPER + SHIFT + down" (dsp.swap "down")) + # Swap windows + (bind "SUPER + SHIFT + left" (dsp.swap "left")) + (bind "SUPER + SHIFT + right" (dsp.swap "right")) + (bind "SUPER + SHIFT + up" (dsp.swap "up")) + (bind "SUPER + SHIFT + down" (dsp.swap "down")) - # Special workspace - (bind "SUPER + S" (dsp.toggleSpecial "magic")) - (bind "SUPER + SHIFT + S" (dsp.moveToSpecial "magic")) + # Special workspace + (bind "SUPER + S" (dsp.toggleSpecial "magic")) + (bind "SUPER + SHIFT + S" (dsp.moveToSpecial "magic")) - # Scroll through workspaces - (bind "SUPER + mouse_down" (dsp.focusWorkspace "e+1")) - (bind "SUPER + mouse_up" (dsp.focusWorkspace "e-1")) + # Scroll through workspaces + (bind "SUPER + mouse_down" (dsp.focusWorkspace "e+1")) + (bind "SUPER + mouse_up" (dsp.focusWorkspace "e-1")) - # Volume keys - (bindOpts "XF86AudioRaiseVolume" (dsp.exec "wpctl set-volume @ 5%+") { - locked = true; - repeating = true; - }) - (bindOpts "XF86AudioLowerVolume" (dsp.exec "wpctl set-volume @ 5%-") { - locked = true; - repeating = true; - }) - (bindOpts "XF86AudioMute" (dsp.exec "wpctl set-mute @ toggle") { locked = true; }) - (bindOpts "XF86AudioMicMute" (dsp.exec "wpctl set-mute u/DEFAULT_AUDIO_SOURCE@ toggle") { - locked = true; - }) + # Volume keys + (bindOpts "XF86AudioRaiseVolume" (dsp.exec "wpctl set-volume @ 5%+") { + locked = true; + repeating = true; + }) + (bindOpts "XF86AudioLowerVolume" (dsp.exec "wpctl set-volume @ 5%-") { + locked = true; + repeating = true; + }) + (bindOpts "XF86AudioMute" (dsp.exec "wpctl set-mute @ toggle") {locked = true;}) + (bindOpts "XF86AudioMicMute" (dsp.exec "wpctl set-mute u/DEFAULT_AUDIO_SOURCE@ toggle") { + locked = true; + }) - # Mouse move/resize - (bindOpts "SUPER + mouse:272" dsp.drag { mouse = true; }) - (bindOpts "SUPER + mouse:273" dsp.resize { mouse = true; }) - ] - ++ workspaceBinds; + # Mouse move/resize + (bindOpts "SUPER + mouse:272" dsp.drag {mouse = true;}) + (bindOpts "SUPER + mouse:273" dsp.resize {mouse = true;}) + ] + ++ workspaceBinds; }; }; packages = with pkgs; [ diff --git a/thick-black-cannon/configuration.nix b/thick-black-cannon/configuration.nix index f9c7f2b..9c3589c 100644 --- a/thick-black-cannon/configuration.nix +++ b/thick-black-cannon/configuration.nix @@ -1,19 +1,17 @@ # Edit this configuration file to define what should be installed on # your system. Help is available in the configuration.nix(5) man page # and in the NixOS manual (accessible by running ‘nixos-help’). - { pkgs, lib, ... -}: - -{ - imports = [ - ./hardware-configuration.nix - ../modules/secrets.nix - ] - ++ lib.optional (builtins.pathExists ./wireguard.nix) ./wireguard.nix; +}: { + imports = + [ + ./hardware-configuration.nix + ../modules/secrets.nix + ] + ++ lib.optional (builtins.pathExists ./wireguard.nix) ./wireguard.nix; # Auto update system.autoUpgrade = { diff --git a/thick-black-cannon/hardware-configuration.nix b/thick-black-cannon/hardware-configuration.nix index b324d4e..41dec89 100644 --- a/thick-black-cannon/hardware-configuration.nix +++ b/thick-black-cannon/hardware-configuration.nix @@ -6,9 +6,7 @@ lib, modulesPath, ... -}: - -{ +}: { imports = [ (modulesPath + "/installer/scan/not-detected.nix") ]; @@ -22,23 +20,22 @@ "usb_storage" "sd_mod" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ "kvm-amd" ]; - boot.extraModulePackages = [ ]; + boot.initrd.kernelModules = []; + boot.kernelModules = ["kvm-amd"]; + boot.extraModulePackages = []; fileSystems."/" = { device = "/dev/mapper/luks-2c1d4d31-36be-4108-8f2c-1987fd4650a8"; fsType = "btrfs"; - options = [ "subvol=@" ]; + options = ["subvol=@"]; }; - boot.initrd.luks.devices."luks-2c1d4d31-36be-4108-8f2c-1987fd4650a8".device = - "/dev/disk/by-uuid/2c1d4d31-36be-4108-8f2c-1987fd4650a8"; + boot.initrd.luks.devices."luks-2c1d4d31-36be-4108-8f2c-1987fd4650a8".device = "/dev/disk/by-uuid/2c1d4d31-36be-4108-8f2c-1987fd4650a8"; fileSystems."/home" = { device = "/dev/mapper/luks-2c1d4d31-36be-4108-8f2c-1987fd4650a8"; fsType = "btrfs"; - options = [ "subvol=@home" ]; + options = ["subvol=@home"]; }; fileSystems."/boot" = { @@ -50,7 +47,7 @@ ]; }; - swapDevices = [ ]; + swapDevices = []; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; diff --git a/thick-black-cannon/home.nix b/thick-black-cannon/home.nix index 53aae71..6b2d4d7 100644 --- a/thick-black-cannon/home.nix +++ b/thick-black-cannon/home.nix @@ -3,12 +3,10 @@ pkgs, lib, ... -}: -let - hyprModule = import ../modules/hyprland.nix { inherit pkgs lib; }; -in -{ - imports = [ ../home.nix ]; +}: let + hyprModule = import ../modules/hyprland.nix {inherit pkgs lib;}; +in { + imports = [../home.nix]; services.pipewire.wireplumber.configs = { log-level-debug = { diff --git a/thick-black-cannon/wireguard.nix b/thick-black-cannon/wireguard.nix index 44cc1ae..061eb34 100644 --- a/thick-black-cannon/wireguard.nix +++ b/thick-black-cannon/wireguard.nix @@ -1,13 +1,16 @@ -{ config, pkgs, ... }: { + config, + pkgs, + ... +}: { networking.wireguard.interfaces = { wg0 = { - ips = [ "10.0.0.2/24" ]; + ips = ["10.0.0.2/24"]; privateKeyFile = config.age.secrets."wireguard-key-thick-black-cannon".path; peers = [ { publicKey = "CHANGE_ME"; - allowedIPs = [ "10.0.0.0/24" ]; + allowedIPs = ["10.0.0.0/24"]; endpoint = "CHANGE_ME:51820"; persistentKeepalive = 25; }