diff --git a/configuration.nix b/configuration.nix index 9723ce4..297d6cd 100644 --- a/configuration.nix +++ b/configuration.nix @@ -2,7 +2,7 @@ # your system. Help is available in the configuration.nix(5) man page # and in the NixOS manual (accessible by running ‘nixos-help’). -{ config, pkgs, lib, hostname, ... }: +{ config, pkgs, lib, hostname, agenix, ... }: { nix.settings.experimental-features = [ "nix-command" "flakes" ]; @@ -102,7 +102,7 @@ description = "HP LaserJet M283fdw"; } ]; - hardware.printers.ensureDefaultPrinter = "hp-m283fdw"; + hardware.printers.ensureDefaultPrinter = "inki"; # fingerprint reader security.pam.services = { @@ -171,11 +171,14 @@ # List packages installed in system profile. To search, run: # $ nix search wget environment.systemPackages = with pkgs; [ + agenix.packages.${pkgs.stdenv.hostPlatform.system}.default opencode brave vim wget - google-chrome + (google-chrome.override { + commandLineArgs = "--disable-features=VaapiVideoDecoder,VaapiVideoEncoder,VaapiVideoDecodeLinuxGL,VaapiOnNvidiaGPUs"; + }) gnome-tweaks slack ghostty diff --git a/controld.nix b/controld.nix index f9ea819..109e7f4 100644 --- a/controld.nix +++ b/controld.nix @@ -1,4 +1,4 @@ -{ pkgs, ... }: +{ pkgs, config, hostname, ... }: let ctrld = pkgs.stdenv.mkDerivation rec { @@ -31,22 +31,21 @@ in }; }; - # Create writable config directory - systemd.tmpfiles.rules = [ - "d /etc/ctrld 0755 jgarr jgarr - -" - ]; + age.secrets.ctrld-config.file = ./secrets/ctrld-${hostname}.age; # Ensure ctrld starts before resolved systemd.services.ctrld = { description = "ControlD DNS Proxy"; before = [ "systemd-resolved.service" ]; - after = [ "network.target" ]; + after = [ "network.target" "agenix.service" ]; + wants = [ "agenix.service" ]; wantedBy = [ "multi-user.target" ]; + restartTriggers = [ config.age.secrets.ctrld-config.file ]; serviceConfig = { - ExecStart = "${ctrld}/bin/ctrld run --config /etc/ctrld/config.toml"; + RuntimeDirectory = "ctrld"; + ExecStartPre = "${pkgs.coreutils}/bin/install -m 600 ${config.age.secrets.ctrld-config.path} /run/ctrld/config.toml"; + ExecStart = "${ctrld}/bin/ctrld run --config /run/ctrld/config.toml"; Restart = "on-failure"; - DynamicUser = true; - AmbientCapabilities = [ "CAP_NET_BIND_SERVICE" ]; }; }; } diff --git a/flake.lock b/flake.lock index 4dd2427..735d78f 100644 --- a/flake.lock +++ b/flake.lock @@ -1,5 +1,28 @@ { "nodes": { + "agenix": { + "inputs": { + "darwin": "darwin", + "home-manager": "home-manager", + "nixpkgs": [ + "nixpkgs" + ], + "systems": "systems" + }, + "locked": { + "lastModified": 1770165109, + "narHash": "sha256-9VnK6Oqai65puVJ4WYtCTvlJeXxMzAp/69HhQuTdl/I=", + "owner": "ryantm", + "repo": "agenix", + "rev": "b027ee29d959fda4b60b57566d64c98a202e0feb", + "type": "github" + }, + "original": { + "owner": "ryantm", + "repo": "agenix", + "type": "github" + } + }, "amp-pkgs": { "locked": { "lastModified": 1780030872, @@ -35,9 +58,31 @@ "type": "github" } }, + "darwin": { + "inputs": { + "nixpkgs": [ + "agenix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1744478979, + "narHash": "sha256-dyN+teG9G82G+m+PX/aSAagkC+vUv0SgUw3XkPhQodQ=", + "owner": "lnl7", + "repo": "nix-darwin", + "rev": "43975d782b418ebf4969e9ccba82466728c2851b", + "type": "github" + }, + "original": { + "owner": "lnl7", + "ref": "master", + "repo": "nix-darwin", + "type": "github" + } + }, "flake-utils": { "inputs": { - "systems": "systems" + "systems": "systems_2" }, "locked": { "lastModified": 1731533236, @@ -55,7 +100,7 @@ }, "flake-utils_2": { "inputs": { - "systems": "systems_2" + "systems": "systems_3" }, "locked": { "lastModified": 1731533236, @@ -72,6 +117,27 @@ } }, "home-manager": { + "inputs": { + "nixpkgs": [ + "agenix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1745494811, + "narHash": "sha256-YZCh2o9Ua1n9uCvrvi5pRxtuVNml8X2a03qIFfRKpFs=", + "owner": "nix-community", + "repo": "home-manager", + "rev": "abfad3d2958c9e6300a883bd443512c55dfeb1be", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "home-manager", + "type": "github" + } + }, + "home-manager_2": { "inputs": { "nixpkgs": [ "nixpkgs" @@ -197,7 +263,7 @@ "noctalia-shell", "nixpkgs" ], - "systems": "systems_3", + "systems": "systems_4", "treefmt-nix": "treefmt-nix" }, "locked": { @@ -235,9 +301,10 @@ }, "root": { "inputs": { + "agenix": "agenix", "amp-pkgs": "amp-pkgs", "claude-code": "claude-code", - "home-manager": "home-manager", + "home-manager": "home-manager_2", "k": "k", "nixpkgs": "nixpkgs_3", "nixpkgs-unstable": "nixpkgs-unstable", @@ -275,6 +342,21 @@ } }, "systems_3": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "systems_4": { "locked": { "lastModified": 1689347949, "narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=", diff --git a/flake.nix b/flake.nix index b75e4b8..fabacc4 100644 --- a/flake.nix +++ b/flake.nix @@ -10,18 +10,21 @@ k.url = "github:rothgar/k"; claude-code.url = "github:sadjow/claude-code-nix"; noctalia-shell.url = "github:noctalia-dev/noctalia-shell"; + agenix.url = "github:ryantm/agenix"; + agenix.inputs.nixpkgs.follows = "nixpkgs"; }; - outputs = { self, nixpkgs, nixpkgs-unstable, amp-pkgs, home-manager, k, claude-code, noctalia-shell, ... }: + outputs = { self, nixpkgs, nixpkgs-unstable, amp-pkgs, home-manager, k, claude-code, noctalia-shell, agenix, ... }: let system = "x86_64-linux"; unstablePkgs = import nixpkgs-unstable { inherit system; config.allowUnfree = true; }; ampPkgs = import amp-pkgs { inherit system; config.allowUnfree = true; }; mkHost = { hostname, hostModule, hardwareModule, homeModules ? [] }: nixpkgs.lib.nixosSystem { - inherit system; - specialArgs = { inherit hostname nixpkgs-unstable; unstable = unstablePkgs; }; + specialArgs = { inherit hostname nixpkgs-unstable agenix; unstable = unstablePkgs; }; modules = [ + { nixpkgs.hostPlatform = system; } + agenix.nixosModules.default ./configuration.nix hardwareModule hostModule diff --git a/home.nix b/home.nix index 55b2058..d4d0979 100644 --- a/home.nix +++ b/home.nix @@ -59,6 +59,7 @@ xdg.userDirs = { enable = true; createDirectories = true; + setSessionVariables = false; desktop = "$HOME/desktop"; documents = "$HOME/documents"; download = "$HOME/downloads"; diff --git a/secrets/ctrld-s.age b/secrets/ctrld-s.age new file mode 100644 index 0000000000000000000000000000000000000000..0bc6aa784841c4162b0f1ed32ed9e377305ec3ef GIT binary patch literal 728 zcmYdHPt{G$OD?J`D9Oyv)5|YP*Do{V(zR14F3!+RO))YxHMCU72+0X^3skTu&d=}- ziYhNG4DgMJDD^fd)=zXR(Kjo~4z}<})GyA=@DDT7*LRN$%jdGl5BBj7@yzyjOgGIg zwFvSJbj|V(bj>UZi}EZ_cQJKybSm{Ja831%FhI90($v(W!coDr(lXT8*frfXG(VuE zD&ILcsL) z+&in#JlrC77mn?4HOy=c~t3BL@UuR3TmQ>?yked7W_dmihopG(`KIM;9J z5X-)D@w(}eYA8=4VJERIJ#E2 zsO~`O@1nJi1@e;~{Jf`iNp|w=M!U_6{>(bGyX9`-!prlscdj|Bw@R|_-I;#AC)S=4 zv4#xEFCCn9HXfY6$^A$CtCsgBD|aL&>UN#Wob{yE^mW@6-Et+nW#`qUmw5<2j5gTz zhxf3-pOpKLp1Dp-)%bBGWcv1{vP#>!KSype(-NM@s5)