diff --git a/.gitignore b/.gitignore index 0510680..4fea4d9 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1,5 @@ result/ +result # For nixos-vms *.qcow2 diff --git a/desktop/flake.lock b/desktop/flake.lock index 316d422..cea9f4f 100644 --- a/desktop/flake.lock +++ b/desktop/flake.lock @@ -1,164 +1,17 @@ { "nodes": { - "aquamarine": { - "inputs": { - "hyprutils": [ - "hyprland", - "hyprutils" - ], - "hyprwayland-scanner": [ - "hyprland", - "hyprwayland-scanner" - ], - "nixpkgs": [ - "hyprland", - "nixpkgs" - ], - "systems": [ - "hyprland", - "systems" - ] - }, - "locked": { - "lastModified": 1762356719, - "narHash": "sha256-qwd/xdoOya1m8FENle+4hWnydCtlXUWLAW/Auk6WL7s=", - "owner": "hyprwm", - "repo": "aquamarine", - "rev": "6d0b3567584691bf9d8fedb5d0093309e2f979c7", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "aquamarine", - "type": "github" - } - }, - "chaotic": { - "inputs": { - "flake-schemas": "flake-schemas", - "home-manager": "home-manager", - "jovian": "jovian", - "nixpkgs": "nixpkgs", - "rust-overlay": "rust-overlay" - }, - "locked": { - "lastModified": 1762525922, - "narHash": "sha256-DX0/D0o/lUQRMCuoAoJiXkDqoISLSgkQAlsPqPS4i6M=", - "owner": "chaotic-cx", - "repo": "nyx", - "rev": "863eed9a7967cb307ecdcdba0c7b87db6a314865", - "type": "github" - }, - "original": { - "owner": "chaotic-cx", - "ref": "nyxpkgs-unstable", - "repo": "nyx", - "type": "github" - } - }, - "flake-compat": { - "flake": false, - "locked": { - "lastModified": 1747046372, - "narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=", - "owner": "edolstra", - "repo": "flake-compat", - "rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885", - "type": "github" - }, - "original": { - "owner": "edolstra", - "repo": "flake-compat", - "type": "github" - } - }, - "flake-parts": { - "inputs": { - "nixpkgs-lib": "nixpkgs-lib" - }, - "locked": { - "lastModified": 1754487366, - "narHash": "sha256-pHYj8gUBapuUzKV/kN/tR3Zvqc7o6gdFB9XKXIp1SQ8=", - "owner": "hercules-ci", - "repo": "flake-parts", - "rev": "af66ad14b28a127c5c0f3bbb298218fc63528a18", - "type": "github" - }, - "original": { - "owner": "hercules-ci", - "repo": "flake-parts", - "type": "github" - } - }, - "flake-schemas": { - "locked": { - "lastModified": 1721999734, - "narHash": "sha256-G5CxYeJVm4lcEtaO87LKzOsVnWeTcHGKbKxNamNWgOw=", - "rev": "0a5c42297d870156d9c57d8f99e476b738dcd982", - "revCount": 75, - "type": "tarball", - "url": "https://api.flakehub.com/f/pinned/DeterminateSystems/flake-schemas/0.1.5/0190ef2f-61e0-794b-ba14-e82f225e55e6/source.tar.gz" - }, - "original": { - "type": "tarball", - "url": "https://flakehub.com/f/DeterminateSystems/flake-schemas/%3D0.1.5.tar.gz" - } - }, - "gitignore": { - "inputs": { - "nixpkgs": [ - "hyprland", - "pre-commit-hooks", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1709087332, - "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=", - "owner": "hercules-ci", - "repo": "gitignore.nix", - "rev": "637db329424fd7e46cf4185293b9cc8c88c95394", - "type": "github" - }, - "original": { - "owner": "hercules-ci", - "repo": "gitignore.nix", - "type": "github" - } - }, "home-manager": { - "inputs": { - "nixpkgs": [ - "chaotic", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1762463325, - "narHash": "sha256-33YUsWpPyeBZEWrKQ2a1gkRZ7i0XCC/2MYpU6BVeQSU=", - "owner": "nix-community", - "repo": "home-manager", - "rev": "0562fef070a1027325dd4ea10813d64d2c967b39", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "home-manager", - "type": "github" - } - }, - "home-manager_2": { "inputs": { "nixpkgs": [ "nixpkgs-unstable" ] }, "locked": { - "lastModified": 1762704774, - "narHash": "sha256-iodz4xQbULkHqetbPu5BCSWsVEzZiiNSv0/dzfH4XiE=", + "lastModified": 1766387499, + "narHash": "sha256-AjK3/UKDzeXFeYNLVBaJ3+HLE9he1g5UrlNd4/BM3eA=", "owner": "nix-community", "repo": "home-manager", - "rev": "be4a9233dd3f6104c9b0fdd3d56f953eb519a4c7", + "rev": "527ad07e6625302b648ed3b28c34b62a79bd103e", "type": "github" }, "original": { @@ -168,7 +21,7 @@ "type": "github" } }, - "home-manager_3": { + "home-manager_2": { "inputs": { "nixpkgs": [ "zen-browser", @@ -176,11 +29,11 @@ ] }, "locked": { - "lastModified": 1762351818, - "narHash": "sha256-0ptUDbYwxv1kk/uzEX4+NJjY2e16MaAhtzAOJ6K0TG0=", + "lastModified": 1765682243, + "narHash": "sha256-yeCxFV/905Wr91yKt5zrVvK6O2CVXWRMSrxqlAZnLp0=", "owner": "nix-community", "repo": "home-manager", - "rev": "b959c67241cae17fc9e4ee7eaf13dfa8512477ea", + "rev": "58bf3ecb2d0bba7bdf363fc8a6c4d49b4d509d03", "type": "github" }, "original": { @@ -189,338 +42,6 @@ "type": "github" } }, - "hyprcursor": { - "inputs": { - "hyprlang": [ - "hyprland", - "hyprlang" - ], - "nixpkgs": [ - "hyprland", - "nixpkgs" - ], - "systems": [ - "hyprland", - "systems" - ] - }, - "locked": { - "lastModified": 1753964049, - "narHash": "sha256-lIqabfBY7z/OANxHoPeIrDJrFyYy9jAM4GQLzZ2feCM=", - "owner": "hyprwm", - "repo": "hyprcursor", - "rev": "44e91d467bdad8dcf8bbd2ac7cf49972540980a5", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "hyprcursor", - "type": "github" - } - }, - "hyprgraphics": { - "inputs": { - "hyprutils": [ - "hyprland", - "hyprutils" - ], - "nixpkgs": [ - "hyprland", - "nixpkgs" - ], - "systems": [ - "hyprland", - "systems" - ] - }, - "locked": { - "lastModified": 1762462052, - "narHash": "sha256-6roLYzcDf4V38RUMSqycsOwAnqfodL6BmhRkUtwIgdA=", - "owner": "hyprwm", - "repo": "hyprgraphics", - "rev": "ffc999d980c7b3bca85d3ebd0a9fbadf984a8162", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "hyprgraphics", - "type": "github" - } - }, - "hyprland": { - "inputs": { - "aquamarine": "aquamarine", - "hyprcursor": "hyprcursor", - "hyprgraphics": "hyprgraphics", - "hyprland-guiutils": "hyprland-guiutils", - "hyprland-protocols": "hyprland-protocols", - "hyprlang": "hyprlang", - "hyprutils": "hyprutils", - "hyprwayland-scanner": "hyprwayland-scanner_2", - "nixpkgs": "nixpkgs_2", - "pre-commit-hooks": "pre-commit-hooks", - "systems": "systems", - "xdph": "xdph" - }, - "locked": { - "lastModified": 1762703954, - "narHash": "sha256-tBNyAKujRoltMh3lsCnEiYza7YC+kK6pcwsCp33QpV4=", - "owner": "hyprwm", - "repo": "Hyprland", - "rev": "0bd11d5eb941b8038f0723135768d84aa5512b4a", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "Hyprland", - "type": "github" - } - }, - "hyprland-guiutils": { - "inputs": { - "aquamarine": [ - "hyprland", - "aquamarine" - ], - "hyprgraphics": [ - "hyprland", - "hyprgraphics" - ], - "hyprlang": [ - "hyprland", - "hyprlang" - ], - "hyprtoolkit": "hyprtoolkit", - "hyprutils": [ - "hyprland", - "hyprutils" - ], - "nixpkgs": [ - "hyprland", - "nixpkgs" - ], - "systems": [ - "hyprland", - "systems" - ] - }, - "locked": { - "lastModified": 1762465111, - "narHash": "sha256-dS13YZdWjgGGLBjpT4FHB6xf8I/WiAU+mgNWXsZgDUs=", - "owner": "hyprwm", - "repo": "hyprland-guiutils", - "rev": "a415eba866a953f3096d661318f771aa0082eb98", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "hyprland-guiutils", - "type": "github" - } - }, - "hyprland-protocols": { - "inputs": { - "nixpkgs": [ - "hyprland", - "nixpkgs" - ], - "systems": [ - "hyprland", - "systems" - ] - }, - "locked": { - "lastModified": 1759610243, - "narHash": "sha256-+KEVnKBe8wz+a6dTLq8YDcF3UrhQElwsYJaVaHXJtoI=", - "owner": "hyprwm", - "repo": "hyprland-protocols", - "rev": "bd153e76f751f150a09328dbdeb5e4fab9d23622", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "hyprland-protocols", - "type": "github" - } - }, - "hyprlang": { - "inputs": { - "hyprutils": [ - "hyprland", - "hyprutils" - ], - "nixpkgs": [ - "hyprland", - "nixpkgs" - ], - "systems": [ - "hyprland", - "systems" - ] - }, - "locked": { - "lastModified": 1758927902, - "narHash": "sha256-LZgMds7M94+vuMql2bERQ6LiFFdhgsEFezE4Vn+Ys3A=", - "owner": "hyprwm", - "repo": "hyprlang", - "rev": "4dafa28d4f79877d67a7d1a654cddccf8ebf15da", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "hyprlang", - "type": "github" - } - }, - "hyprtoolkit": { - "inputs": { - "aquamarine": [ - "hyprland", - "hyprland-guiutils", - "aquamarine" - ], - "hyprgraphics": [ - "hyprland", - "hyprland-guiutils", - "hyprgraphics" - ], - "hyprlang": [ - "hyprland", - "hyprland-guiutils", - "hyprlang" - ], - "hyprutils": [ - "hyprland", - "hyprland-guiutils", - "hyprutils" - ], - "hyprwayland-scanner": "hyprwayland-scanner", - "nixpkgs": [ - "hyprland", - "hyprland-guiutils", - "nixpkgs" - ], - "systems": [ - "hyprland", - "hyprland-guiutils", - "systems" - ] - }, - "locked": { - "lastModified": 1762463729, - "narHash": "sha256-2fYkU/mdz8WKY3dkDPlE/j6hTxIwqultsx4gMMsMns0=", - "owner": "hyprwm", - "repo": "hyprtoolkit", - "rev": "88483bdee5329ec985f0c8f834c519cd18cfe532", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "hyprtoolkit", - "type": "github" - } - }, - "hyprutils": { - "inputs": { - "nixpkgs": [ - "hyprland", - "nixpkgs" - ], - "systems": [ - "hyprland", - "systems" - ] - }, - "locked": { - "lastModified": 1762387740, - "narHash": "sha256-gQ9zJ+pUI4o+Gh4Z6jhJll7jjCSwi8ZqJIhCE2oqwhQ=", - "owner": "hyprwm", - "repo": "hyprutils", - "rev": "926689ddb9c0a8787e58c02c765a62e32d63d1f7", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "hyprutils", - "type": "github" - } - }, - "hyprwayland-scanner": { - "inputs": { - "nixpkgs": [ - "hyprland", - "hyprland-guiutils", - "hyprtoolkit", - "nixpkgs" - ], - "systems": [ - "hyprland", - "hyprland-guiutils", - "hyprtoolkit", - "systems" - ] - }, - "locked": { - "lastModified": 1755184602, - "narHash": "sha256-RCBQN8xuADB0LEgaKbfRqwm6CdyopE1xIEhNc67FAbw=", - "owner": "hyprwm", - "repo": "hyprwayland-scanner", - "rev": "b3b0f1f40ae09d4447c20608e5a4faf8bf3c492d", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "hyprwayland-scanner", - "type": "github" - } - }, - "hyprwayland-scanner_2": { - "inputs": { - "nixpkgs": [ - "hyprland", - "nixpkgs" - ], - "systems": [ - "hyprland", - "systems" - ] - }, - "locked": { - "lastModified": 1755184602, - "narHash": "sha256-RCBQN8xuADB0LEgaKbfRqwm6CdyopE1xIEhNc67FAbw=", - "owner": "hyprwm", - "repo": "hyprwayland-scanner", - "rev": "b3b0f1f40ae09d4447c20608e5a4faf8bf3c492d", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "hyprwayland-scanner", - "type": "github" - } - }, - "jovian": { - "inputs": { - "nix-github-actions": "nix-github-actions", - "nixpkgs": [ - "chaotic", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1762452596, - "narHash": "sha256-Iaga+mkwWnWa6FxsAYknpHzeP344VCKGkdudX420LgA=", - "owner": "Jovian-Experiments", - "repo": "Jovian-NixOS", - "rev": "99919fd35e70c1b18ce948d5329928d751031312", - "type": "github" - }, - "original": { - "owner": "Jovian-Experiments", - "repo": "Jovian-NixOS", - "type": "github" - } - }, "lsfg-vk-flake": { "inputs": { "nixpkgs": [ @@ -542,29 +63,6 @@ "type": "github" } }, - "nix-github-actions": { - "inputs": { - "nixpkgs": [ - "chaotic", - "jovian", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1729697500, - "narHash": "sha256-VFTWrbzDlZyFHHb1AlKRiD/qqCJIripXKiCSFS8fAOY=", - "owner": "zhaofengli", - "repo": "nix-github-actions", - "rev": "e418aeb728b6aa5ca8c5c71974e7159c2df1d8cf", - "type": "github" - }, - "original": { - "owner": "zhaofengli", - "ref": "matrix-name", - "repo": "nix-github-actions", - "type": "github" - } - }, "nix-index": { "inputs": { "nixpkgs": [ @@ -572,11 +70,11 @@ ] }, "locked": { - "lastModified": 1762660502, - "narHash": "sha256-C9F1C31ys0V7mnp4EcDy7L1cLZw/sCTEXqqTtGnvu08=", + "lastModified": 1765267181, + "narHash": "sha256-d3NBA9zEtBu2JFMnTBqWj7Tmi7R5OikoU2ycrdhQEws=", "owner": "nix-community", "repo": "nix-index-database", - "rev": "15c5451c63f4c612874a43846bfe3fa828b03eee", + "rev": "82befcf7dc77c909b0f2a09f5da910ec95c5b78f", "type": "github" }, "original": { @@ -585,60 +83,45 @@ "type": "github" } }, - "nixpkgs": { + "nixpkgs-extra-unstable": { "locked": { - "lastModified": 1762363567, - "narHash": "sha256-YRqMDEtSMbitIMj+JLpheSz0pwEr0Rmy5mC7myl17xs=", + "lastModified": 1766314097, + "narHash": "sha256-laJftWbghBehazn/zxVJ8NdENVgjccsWAdAqKXhErrM=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "ae814fd3904b621d8ab97418f1d0f2eb0d3716f4", + "rev": "306ea70f9eb0fb4e040f8540e2deab32ed7e2055", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-unstable", + "ref": "nixpkgs-unstable", "repo": "nixpkgs", "type": "github" } }, - "nixpkgs-extra-unstable": { + "nixpkgs-master": { "locked": { - "lastModified": 1762482733, - "narHash": "sha256-g/da4FzvckvbiZT075Sb1/YDNDr+tGQgh4N8i5ceYMg=", + "lastModified": 1766403040, + "narHash": "sha256-nA6yZyc/HDo6JsmfX8aiVYEv++QXqzH80QTNRG1KEgQ=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "e1ebeec86b771e9d387dd02d82ffdc77ac753abc", + "rev": "3ffc59654f4bbc433cf7202f43360b9d19aed3ea", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixpkgs-unstable", + "ref": "master", "repo": "nixpkgs", "type": "github" } }, - "nixpkgs-lib": { - "locked": { - "lastModified": 1753579242, - "narHash": "sha256-zvaMGVn14/Zz8hnp4VWT9xVnhc8vuL3TStRqwk22biA=", - "owner": "nix-community", - "repo": "nixpkgs.lib", - "rev": "0f36c44e01a6129be94e3ade315a5883f0228a6e", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "nixpkgs.lib", - "type": "github" - } - }, "nixpkgs-stable": { "locked": { - "lastModified": 1762498405, - "narHash": "sha256-Zg/SCgCaAioc0/SVZQJxuECGPJy+OAeBcGeA5okdYDc=", + "lastModified": 1766014764, + "narHash": "sha256-+73VffE5GP5fvbib6Hs1Su6LehG+9UV1Kzs90T2gBLA=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "6faeb062ee4cf4f105989d490831713cc5a43ee1", + "rev": "2b0d2b456e4e8452cf1c16d00118d145f31160f9", "type": "github" }, "original": { @@ -650,43 +133,11 @@ }, "nixpkgs-unstable": { "locked": { - "lastModified": 1762596750, - "narHash": "sha256-rXXuz51Bq7DHBlfIjN7jO8Bu3du5TV+3DSADBX7/9YQ=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "b6a8526db03f735b89dd5ff348f53f752e7ddc8e", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixos-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_2": { - "locked": { - "lastModified": 1762363567, - "narHash": "sha256-YRqMDEtSMbitIMj+JLpheSz0pwEr0Rmy5mC7myl17xs=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "ae814fd3904b621d8ab97418f1d0f2eb0d3716f4", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixos-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_3": { - "locked": { - "lastModified": 1762363567, - "narHash": "sha256-YRqMDEtSMbitIMj+JLpheSz0pwEr0Rmy5mC7myl17xs=", + "lastModified": 1766070988, + "narHash": "sha256-G/WVghka6c4bAzMhTwT2vjLccg/awmHkdKSd2JrycLc=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "ae814fd3904b621d8ab97418f1d0f2eb0d3716f4", + "rev": "c6245e83d836d0433170a16eb185cefe0572f8b8", "type": "github" }, "original": { @@ -696,202 +147,31 @@ "type": "github" } }, - "nixpkgs_4": { - "locked": { - "lastModified": 1756731054, - "narHash": "sha256-kifUBw3WDopsgxUq0X9hFb2MMDeqhREbF1YttEj6IpM=", - "owner": "nixos", - "repo": "nixpkgs", - "rev": "d042fb41a92f948e2f42038b0b9641bd501d08ce", - "type": "github" - }, - "original": { - "owner": "nixos", - "repo": "nixpkgs", - "type": "github" - } - }, - "pre-commit-hooks": { - "inputs": { - "flake-compat": "flake-compat", - "gitignore": "gitignore", - "nixpkgs": [ - "hyprland", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1762441963, - "narHash": "sha256-j+rNQ119ffYUkYt2YYS6rnd6Jh/crMZmbqpkGLXaEt0=", - "owner": "cachix", - "repo": "git-hooks.nix", - "rev": "8e7576e79b88c16d7ee3bbd112c8d90070832885", - "type": "github" - }, - "original": { - "owner": "cachix", - "repo": "git-hooks.nix", - "type": "github" - } - }, "root": { "inputs": { - "chaotic": "chaotic", - "home-manager": "home-manager_2", - "hyprland": "hyprland", + "home-manager": "home-manager", "lsfg-vk-flake": "lsfg-vk-flake", "nix-index": "nix-index", "nixpkgs-extra-unstable": "nixpkgs-extra-unstable", + "nixpkgs-master": "nixpkgs-master", "nixpkgs-stable": "nixpkgs-stable", "nixpkgs-unstable": "nixpkgs-unstable", - "spicetify-nix": "spicetify-nix", - "zed-editor": "zed-editor", "zen-browser": "zen-browser" } }, - "rust-overlay": { - "inputs": { - "nixpkgs": [ - "chaotic", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1762483116, - "narHash": "sha256-Z8EVsTH10BjCdFyPxbUu5jBV+HGL39rh9+beQcnNRm0=", - "owner": "oxalica", - "repo": "rust-overlay", - "rev": "9de55b59b6aaadbd9dbf223765a835239b767ee5", - "type": "github" - }, - "original": { - "owner": "oxalica", - "repo": "rust-overlay", - "type": "github" - } - }, - "spicetify-nix": { - "inputs": { - "nixpkgs": "nixpkgs_3", - "systems": "systems_2" - }, - "locked": { - "lastModified": 1762705543, - "narHash": "sha256-yoJBNxZySJduVdzfy8zxlfx5OL2CvBOYtuQsYsbD/qw=", - "owner": "Gerg-L", - "repo": "spicetify-nix", - "rev": "954fd25c1dc799f732a23da844befe71f03a5ff0", - "type": "github" - }, - "original": { - "owner": "Gerg-L", - "repo": "spicetify-nix", - "type": "github" - } - }, - "systems": { - "locked": { - "lastModified": 1689347949, - "narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=", - "owner": "nix-systems", - "repo": "default-linux", - "rev": "31732fcf5e8fea42e59c2488ad31a0e651500f68", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default-linux", - "type": "github" - } - }, - "systems_2": { - "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" - } - }, - "xdph": { - "inputs": { - "hyprland-protocols": [ - "hyprland", - "hyprland-protocols" - ], - "hyprlang": [ - "hyprland", - "hyprlang" - ], - "hyprutils": [ - "hyprland", - "hyprutils" - ], - "hyprwayland-scanner": [ - "hyprland", - "hyprwayland-scanner" - ], - "nixpkgs": [ - "hyprland", - "nixpkgs" - ], - "systems": [ - "hyprland", - "systems" - ] - }, - "locked": { - "lastModified": 1761431178, - "narHash": "sha256-xzjC1CV3+wpUQKNF+GnadnkeGUCJX+vgaWIZsnz9tzI=", - "owner": "hyprwm", - "repo": "xdg-desktop-portal-hyprland", - "rev": "4b8801228ff958d028f588f0c2b911dbf32297f9", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "xdg-desktop-portal-hyprland", - "type": "github" - } - }, - "zed-editor": { - "inputs": { - "flake-parts": "flake-parts", - "nixpkgs": "nixpkgs_4" - }, - "locked": { - "lastModified": 1756797624, - "narHash": "sha256-8EWKUNW90lu6B13B/97CROw4iji6v3CAm3avvioXho8=", - "owner": "HPsaucii", - "repo": "zed-editor-flake", - "rev": "2c2a2aaac1cd9dd95e92dc045ce51a6d8372b02e", - "type": "github" - }, - "original": { - "owner": "HPsaucii", - "repo": "zed-editor-flake", - "type": "github" - } - }, "zen-browser": { "inputs": { - "home-manager": "home-manager_3", + "home-manager": "home-manager_2", "nixpkgs": [ "nixpkgs-unstable" ] }, "locked": { - "lastModified": 1762665515, - "narHash": "sha256-0+A0nHL1+x1H4NL5bE6GyA252JOpUK6kvfHg/g75260=", + "lastModified": 1766378463, + "narHash": "sha256-ZGTxrMJktO2TiqrWdZZ7FCw26LKcw3sJkn9MnDLWg4I=", "owner": "0xc000022070", "repo": "zen-browser-flake", - "rev": "1bea5e777dd0b99158c504da1fb2913ff119e96c", + "rev": "b6b1e625e4aa049b59930611fc20790c0ccbc840", "type": "github" }, "original": { diff --git a/desktop/flake.nix b/desktop/flake.nix index 17f9b68..7b0db1f 100644 --- a/desktop/flake.nix +++ b/desktop/flake.nix @@ -5,6 +5,7 @@ nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-25.05"; nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixos-unstable"; nixpkgs-extra-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable"; + nixpkgs-master.url = "github:NixOS/nixpkgs/master"; home-manager = { # url = "github:nix-community/home-manager/release-25.05"; url = "github:nix-community/home-manager/master"; @@ -13,16 +14,12 @@ zen-browser = { url = "github:0xc000022070/zen-browser-flake"; - # IMPORTANT: we're using "libgbm" and is only available in unstable so ensure - # to have it up-to-date or simply don't specify the nixpkgs input inputs.nixpkgs.follows = "nixpkgs-unstable"; }; - hyprland.url = "github:hyprwm/Hyprland"; + # hyprland.url = "github:hyprwm/Hyprland"; - chaotic.url = "github:chaotic-cx/nyx/nyxpkgs-unstable"; - zed-editor.url = "github:HPsaucii/zed-editor-flake"; - # fennec-flake.url = "git+https://git.killuaa.dev/Rouffy/fennec-flake?ref=mrrow"; + # chaotic.url = "github:chaotic-cx/nyx/nyxpkgs-unstable"; lsfg-vk-flake = { url = "github:pabloaul/lsfg-vk-flake/main"; @@ -34,9 +31,7 @@ inputs.nixpkgs.follows = "nixpkgs-unstable"; }; - spicetify-nix.url = "github:Gerg-L/spicetify-nix"; - - # modrinth-fix.url = "github:getchoo-contrib/nixpkgs/pkgs/modrinth-app/0.10.3"; + # spicetify-nix.url = "github:Gerg-L/spicetify-nix"; }; outputs = @@ -58,6 +53,7 @@ # This makes these args available in all other modules specialArgs = { inherit inputs; + inherit repos; }; modules = [ @@ -66,13 +62,17 @@ inherit system; config.allowUnfree = true; config.android_sdk.accept_license = true; + overlays = [ + (final: prev: { + }) + ]; }; } ./system/configuration.nix # Main configuration ./system/networking.nix # Network config - inputs.chaotic.nixosModules.default + # inputs.chaotic.nixosModules.default inputs.lsfg-vk-flake.nixosModules.default inputs.home-manager.nixosModules.home-manager diff --git a/desktop/home-manager/snowy.nix b/desktop/home-manager/snowy.nix index cd06d9f..7d3b279 100644 --- a/desktop/home-manager/snowy.nix +++ b/desktop/home-manager/snowy.nix @@ -23,8 +23,8 @@ # }; home.packages = with pkgs; [ - inputs.zen-browser.packages."${system}".twilight - inputs.zed-editor.packages."${pkgs.system}".zed-editor-bin + inputs.zen-browser.packages."${stdenv.hostPlatform.system}".twilight + repos.extra-unstable.zed-editor # corretto17 # android-studio # forgejo-actions-runner @@ -35,10 +35,12 @@ vscode helix mpv + tauon + yt-dlp # shellcheck # for zed basher? # vscodium - jetbrains.idea-ultimate + jetbrains.idea jetbrains.rider orca-slicer # godot @@ -55,7 +57,7 @@ fzf # for fish chafa # hextazy - repos.pkgs-extra-unstable.grayjay + # repos.extra-unstable.grayjay # gaphor # d-spyd @@ -65,6 +67,7 @@ gcc just jujutsu + sops # silly game clonehero @@ -90,6 +93,7 @@ monocraft python3 + repos.master.jellyfin-desktop # wine64 # nixpkgs-extra-unstable.hyprlandPlugins.hyprsplit ]; @@ -102,7 +106,7 @@ # programs.spicetify = # let - # spicePkgs = inputs.spicetify-nix.legacyPackages.${pkgs.stdenv.system}; + # spicePkgs = inputs.spicetify-nix.legacyPackages.${pkgs.stdenv.hostPlatform.system}; # in # { # enable = true; diff --git a/desktop/repos.nix b/desktop/repos.nix index 2bd02c0..09e96e2 100644 --- a/desktop/repos.nix +++ b/desktop/repos.nix @@ -3,28 +3,34 @@ system, ... }: -let +{ inherit system; - pkgs-extra-unstable = import inputs.nixpkgs-extra-unstable { + master = import inputs.nixpkgs-master { + inherit system; + config.allowUnfree = true; + }; + + extra-unstable = import inputs.nixpkgs-extra-unstable { inherit system; config.allowUnfree = true; config.android_sdk.accept_license = true; }; - pks-unstable = import inputs.nixpkgs-unstable { + unstable = import inputs.nixpkgs-unstable { inherit system; config.allowUnfree = true; config.android_sdk.accept_license = true; }; - pkgs-stable = import inputs.nixpkgs-stable { + stable = import inputs.nixpkgs-stable { inherit system; config.allowUnfree = true; config.android_sdk.accept_license = true; }; pkgs-system = inputs.nixpkgs-unstable.lib.nixosSystem; + # { # modules = [ # { @@ -36,13 +42,4 @@ let # } # ]; # }; - -in -{ - inherit - pkgs-extra-unstable - pks-unstable - pkgs-stable - pkgs-system - ; } diff --git a/desktop/system/configuration.nix b/desktop/system/configuration.nix index 4383179..27e0624 100644 --- a/desktop/system/configuration.nix +++ b/desktop/system/configuration.nix @@ -6,8 +6,7 @@ config, lib, pkgs, - pkgs-unstable, - inputs, + repos, ... }: @@ -18,8 +17,11 @@ ./audio.nix ]; - # QUICKSHELl - qt.enable = true; + qt = { + enable = true; + # style = "adwaita-dark"; + platformTheme = "qt5ct"; + }; nix = { package = pkgs.lix; @@ -58,14 +60,19 @@ boot = { supportedFilesystems = [ "ntfs" ]; # kernelPackages = pkgs.linuxPackages_cachyos-rc; - kernelPackages = pkgs.linuxPackages_cachyos; + # kernelPackages = pkgs.linuxPackages_cachyos; + kernelPackages = pkgs.linuxPackages_lqx; + kernelParams = [ ]; kernel.sysctl = { "vm.swappiness" = 100; + "vm.max_map_count" = 1048576; + "net.ipv4.conf.all.forwarding" = true; + "net.ipv6.conf.all.forwarding" = true; }; extraModprobeConfig = '' - options snd-hda-intel power_save=0 power_save_controller=N + options snd-hda-intel power_save=0 power_save_controller=N # Disable speakers going into a powersaving state options amdgpu ppfeaturemask=0xFFF7FFFF ''; @@ -78,7 +85,6 @@ "ntsync" ]; - # todo! do the gaming vm_mapsize thing loader = { systemd-boot = { enable = true; @@ -96,10 +102,6 @@ enable = true; qemu = { swtpm.enable = true; - # ovmf.packages = [ - # pkgs.OVMFFull.fd - # ]; - # vhostUserPackages = with pkgs; [ virtiofsd ]; }; }; @@ -116,14 +118,6 @@ # waydroid = { # enable = true; # }; - - # lxd = { - # enable = true; - # recommendedSysctlSettings = true; - # ui = { - # enable = true; - # }; - # }; }; hardware = { @@ -139,10 +133,6 @@ vulkan-loader vulkan-validation-layers - #AMD VLK - # amdvlk - # driversi686Linux.amdvlk - #opencl rocmPackages.clr.icd ]; @@ -206,11 +196,10 @@ passt = { source = "${pkgs.passt}/bin/passt"; capabilities = "cap_net_bind_service=ep"; - owner = "snowy"; # Replace with your actual username + owner = "snowy"; group = "wheel"; }; }; - }; # Set your time zone. @@ -306,12 +295,16 @@ lsfg-vk = { enable = true; + ui.enable = true; # installs gui for configuring lsfg-vk }; # xserver.enable = true; #xserver.displayManager.gdm.enable = true; desktopManager.gnome.enable = true; + # Enable the COSMIC desktop environment + # desktopManager.cosmic.enable = true; + sunshine = { enable = true; autoStart = true; @@ -354,6 +347,7 @@ "wireshark" "input" "libvirtd" + "gamemode" ]; }; }; @@ -361,7 +355,7 @@ programs = { # firefox = { # enable = true; - # package = pkgs-unstable.firefox-devedition; + # package = repos.unstable.firefox-devedition; # }; steam = { @@ -381,9 +375,14 @@ enable = true; settings = { + gpu = { + apply_gpu_optimisations = "accept-responsibility"; # Setting this to the keyphrase "accept-responsibility" will allow gamemode to apply GPU optimisations such as overclocks + amd_performance_level = "high"; # This corresponds to power_dpm_force_performance_level, "manual" is not supported for now + gpu_device = 1; # The DRM device number on the system (usually 0), ie. the number in /sys/class/drm/card0/ + }; custom = { - start = "${pkgs.libnotify}/bin/notify-send 'GameMode started!'"; - end = "${pkgs.libnotify}/bin/notify-send 'GameMode stopped!'"; + start = "${pkgs.libnotify}/bin/notify-send 'GameMode started!' && systemctl --user stop docker opentabletdriver obex gvfs-daemon.service && pkexec systemctl stop bluetooth.service mullvad-daemon.service avahi-daemon.service systemd-machined ntpd"; + end = "${pkgs.libnotify}/bin/notify-send 'GameMode stopped!' && systemctl --user start docker opentabletdriver obex gvfs-daemon.service && pkexec systemctl start bluetooth.service mullvad-daemon.service avahi-daemon.service systemd-machined ntpd"; }; }; }; @@ -421,6 +420,12 @@ nix-ld.enable = true; + winbox = { + package = pkgs.winbox4; + openFirewall = true; + enable = true; + }; + # home-manager.enable = true; }; @@ -446,6 +451,8 @@ # }; systemPackages = with pkgs; [ + # dnsmasq + nh glib # for gsettings # vscodium-fhs @@ -501,6 +508,11 @@ # zopfli fwupd android-tools + netcap + # nemo + nemo-with-extensions + nemo-fileroller + nemo-preview zellij helix @@ -534,6 +546,8 @@ libsForQt5.qt5ct kdePackages.qt6ct + kdePackages.breeze + kdePackages.breeze-icons dconf-editor nautilus file-roller @@ -543,10 +557,12 @@ pavucontrol # niri - xwayland-satellite + repos.unstable.xwayland-satellite xdg-desktop-portal-gnome - hyprpaper + # hyprpaper + swaybg + swww cosmic-session virt-manager @@ -564,7 +580,7 @@ vesktop r2modman #libsForQt5.xp-pen-g430-drive - libsForQt5.xp-pen-deco-01-v2-driver + # libsForQt5.xp-pen-deco-01-v2-driver # postman # insomnia hoppscotch diff --git a/desktop/system/networking.nix b/desktop/system/networking.nix index a48eee1..b2a67c6 100644 --- a/desktop/system/networking.nix +++ b/desktop/system/networking.nix @@ -9,18 +9,63 @@ { # services.resolved.enable = false; + # dnsmasq = { + # enable = true; + # settings = { + # servers = [ + # "1.1.1.1" + # ]; + # dhcp-range = [ "192.168.0.2,192.168.0.254" ]; + # }; + # }; + networking = { hostName = "Snowflake"; # wireless.enable = true; - networkmanager.enable = true; + networkmanager.enable = false; # networkmanager.wifi.backend = "iwd"; # wireless.iwd.enable = true; - # useDHCP = true; + useDHCP = true; + + # dhcpcd = { + # enable = true; + + # denyInterfaces = [ + # "br0" + # "virbr0" + # ]; + # }; + + # interfaces.br0.useDHCP = true; + # interfaces.enp9s0.useDHCP = false; + + # bridges = { + # br0 = { + # interfaces = [ "enp9s0" ]; + # }; + # }; # search = [ # "taila3a3d2.ts.net" # ]; + # interfaces = { + # enp9s0 = { + # ipv4.addresses = [ + # { + # address = "192.168.88.69"; + # prefixLength = 24; + # } + # ]; + # # ipv6.addresses = [ + # # { + # # address = "2a0a:4cc0:0:1eb::c0ff:ee"; + # # prefixLength = 64; + # # } + # # ]; + # }; + # }; + nameservers = [ # Cloudflare "2606:4700:4700::1111" diff --git a/home-server/justfile b/home-server/justfile index dd88d5b..b61b63f 100644 --- a/home-server/justfile +++ b/home-server/justfile @@ -1,2 +1,2 @@ test-vm: - nixos-rebuild build-vm-with-bootloader --flake .#snowlab && QEMU_NET_OPTS="hostfwd=tcp::2221-:22,hostfwd=tcp::8080-:80" ./result/bin/run-snowlab-vm + nh os build-vm .#nixosConfigurations.snowlab --hostname snowlab --with-bootloader && ./result/bin/run-snowlab-vm diff --git a/home-server/result b/home-server/result deleted file mode 120000 index ad68211..0000000 --- a/home-server/result +++ /dev/null @@ -1 +0,0 @@ -/nix/store/wsmk41hbyl6kpv4snj02csn4vmdj1yld-nixos-vm \ No newline at end of file diff --git a/home-server/system/configuration.nix b/home-server/system/configuration.nix index bbef9d0..8f6326f 100644 --- a/home-server/system/configuration.nix +++ b/home-server/system/configuration.nix @@ -17,20 +17,41 @@ ]; virtualisation.vmVariant.virtualisation = { - qemu.guestAgent.enable = true; - diskSize = 1024 * 12; - memorySize = 1024 * 4; + memorySize = 4096; cores = 4; + # diskImage = "./temp_disk"; + forwardPorts = [ + { + from = "host"; + proto = "tcp"; + host = { + port = 2222; + }; + guest = { + port = 22; + }; + } + ]; + qemu.guestAgent.enable = true; + useEFIBoot = false; + diskSize = 15360; }; - fileSystems."/" = { - autoResize = true; - }; + # virtualisation.vmVariant.virtualisation = { + # qemu.guestAgent.enable = true; + # diskSize = 1024 * 12; + # memorySize = 1024 * 4; + # cores = 4; + # }; - boot.growPartition = true; + # fileSystems."/" = { + # autoResize = true; + # }; + + # boot.growPartition = true; - services.spice-vdagentd.enable = true; - services.qemuGuest.enable = true; + # services.spice-vdagentd.enable = true; + # services.qemuGuest.enable = true; # Enable zram (compressed ram) zramSwap = { @@ -77,15 +98,17 @@ loader = { efi.canTouchEfiVariables = true; - + refind.enable = true; + timeout = 1; # Set timeout to null, so the refind nix options dont get overriden, its silly... + # refind.extraConfig = '' + # timeout -1 + # ''; # Use grub so it works on both EFI and BOOT grub = { - enable = true; - timeoutStyle = "hidden"; - efiSupport = true; - # efiInstallAsRemovable = true; - device = "nodev"; - splashImage = null; + enable = false; + # timeoutStyle = "hidden"; + # efiSupport = true; + # splashImage = null; }; }; @@ -179,16 +202,8 @@ # }; }; - # virtualisation = { - # docker = { - # rootless = { - # enable = true; - # setSocketVariable = true; - # }; - # }; - # }; - users = { + mutableUsers = false; groups.user = { }; users = { user = { @@ -204,6 +219,7 @@ root = { shell = pkgs.fish; + password = "goon"; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL2za6psnuIMZ6FrdUehhyQlqYvy05+wv8dKER+Lctna snowy@Snowflake" ]; diff --git a/readme.md b/readme.md index c5d8bd9..8f40195 100644 --- a/readme.md +++ b/readme.md @@ -2,4 +2,5 @@ This repo is split into two parts. - nixos -> This is my desktop called snowflake. - - server -> This is my server called snow-den. + - server -> This is my vps called snow-den. + - home-server -> This is my homelab called snowlab. diff --git a/server/.sops.yaml b/server/.sops.yaml new file mode 100644 index 0000000..4b5a5d8 --- /dev/null +++ b/server/.sops.yaml @@ -0,0 +1,14 @@ +# This example uses YAML anchors which allows reuse of multiple keys +# without having to repeat yourself. +# Also see https://github.com/Mic92/dotfiles/blob/d6114726d859df36ccaa32891c4963ae5717ef7f/nixos/.sops.yaml +# for a more complex example. +keys: + - &admin_snowyboo D40CE1579C09BFD7EF4AB7E631250420834310B5 + - &root_server age16e3uae0sktxmwzlmcdxwn07jpudtjl0s42hnwx2qsdh9h72gc5ssktkazg +creation_rules: + - path_regex: secrets/[^/]+\.(yaml|json|env|ini)$ + key_groups: + - pgp: + - *admin_snowyboo + age: + - *root_server diff --git a/server/containers/caddy.nix b/server/containers/caddy.nix deleted file mode 100644 index 74f099b..0000000 --- a/server/containers/caddy.nix +++ /dev/null @@ -1,59 +0,0 @@ -{ - config, - lib, - pkgs, - ... -}: - -let - release = "nixos-25.05"; - -in -{ - containers.caddy = { - autoStart = true; - privateNetwork = false; - config = - { - config, - pkgs, - lib, - ... - }: - { - system.stateVersion = "25.05"; - - services.caddy = { - enable = true; - virtualHosts = { - "mrsnowy.dev" = { - serverAliases = [ - "fpps4.net" - "www.paradijs-in-hongarije.nl" - "paradijs-in-hongarije.nl" - "prowebservice.nl" - "smarty.nl" - "www.zendojaku.nl" - "zendojaku.nl" - ]; - - extraConfig = '' - reverse_proxy https://10.0.100.65 { - transport http { - tls_insecure_skip_verify - } - } - ''; - }; - - "headscale.mrsnowy.dev" = { - extraConfig = '' - reverse_proxy http://localhost:3443 - ''; - }; - }; - }; - }; - - }; -} diff --git a/server/containers/main.nix b/server/containers/default.nix similarity index 100% rename from server/containers/main.nix rename to server/containers/default.nix diff --git a/server/flake.lock b/server/flake.lock index e9112cb..e60db40 100644 --- a/server/flake.lock +++ b/server/flake.lock @@ -1,41 +1,5 @@ { "nodes": { - "deploy-rs": { - "inputs": { - "flake-compat": "flake-compat", - "nixpkgs": "nixpkgs", - "utils": "utils" - }, - "locked": { - "lastModified": 1756719547, - "narHash": "sha256-N9gBKUmjwRKPxAafXEk1EGadfk2qDZPBQp4vXWPHINQ=", - "owner": "serokell", - "repo": "deploy-rs", - "rev": "125ae9e3ecf62fb2c0fd4f2d894eb971f1ecaed2", - "type": "github" - }, - "original": { - "owner": "serokell", - "repo": "deploy-rs", - "type": "github" - } - }, - "flake-compat": { - "flake": false, - "locked": { - "lastModified": 1733328505, - "narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=", - "owner": "edolstra", - "repo": "flake-compat", - "rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec", - "type": "github" - }, - "original": { - "owner": "edolstra", - "repo": "flake-compat", - "type": "github" - } - }, "home-manager": { "inputs": { "nixpkgs": [ @@ -43,11 +7,11 @@ ] }, "locked": { - "lastModified": 1754263839, - "narHash": "sha256-ck7lILfCNuunsLvExPI4Pw9OOCJksxXwozum24W8b+8=", + "lastModified": 1765860045, + "narHash": "sha256-7Lxp/PfOy4h3QIDtmWG/EgycaswqRSkDX4DGtet14NE=", "owner": "nix-community", "repo": "home-manager", - "rev": "1d7abbd5454db97e0af51416f4960b3fb64a4773", + "rev": "09de9577d47d8bffb11c449b6a3d24e32ac16c99", "type": "github" }, "original": { @@ -59,27 +23,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1743014863, - "narHash": "sha256-jAIUqsiN2r3hCuHji80U7NNEafpIMBXiwKlSrjWMlpg=", + "lastModified": 1765687488, + "narHash": "sha256-7YAJ6xgBAQ/Nr+7MI13Tui1ULflgAdKh63m1tfYV7+M=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "bd3bac8bfb542dbde7ffffb6987a1a1f9d41699f", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixpkgs-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_2": { - "locked": { - "lastModified": 1754292888, - "narHash": "sha256-1ziydHSiDuSnaiPzCQh1mRFBsM2d2yRX9I+5OPGEmIE=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "ce01daebf8489ba97bd1609d185ea276efdeb121", + "rev": "d02bcc33948ca19b0aaa0213fe987ceec1f4ebe1", "type": "github" }, "original": { @@ -91,41 +39,28 @@ }, "root": { "inputs": { - "deploy-rs": "deploy-rs", "home-manager": "home-manager", - "nixpkgs": "nixpkgs_2" - } - }, - "systems": { - "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" + "nixpkgs": "nixpkgs", + "sops-nix": "sops-nix" } }, - "utils": { + "sops-nix": { "inputs": { - "systems": "systems" + "nixpkgs": [ + "nixpkgs" + ] }, "locked": { - "lastModified": 1731533236, - "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", + "lastModified": 1765836173, + "narHash": "sha256-hWRYfdH2ONI7HXbqZqW8Q1y9IRbnXWvtvt/ONZovSNY=", + "owner": "Mic92", + "repo": "sops-nix", + "rev": "443a7f2e7e118c4fc63b7fae05ab3080dd0e5c63", "type": "github" }, "original": { - "owner": "numtide", - "repo": "flake-utils", + "owner": "Mic92", + "repo": "sops-nix", "type": "github" } } diff --git a/server/flake.nix b/server/flake.nix index 0c64483..c48bc28 100644 --- a/server/flake.nix +++ b/server/flake.nix @@ -7,8 +7,10 @@ url = "github:nix-community/home-manager/master"; inputs.nixpkgs.follows = "nixpkgs"; }; - - deploy-rs.url = "github:serokell/deploy-rs"; + sops-nix = { + url = "github:Mic92/sops-nix"; + inputs.nixpkgs.follows = "nixpkgs"; + }; }; outputs = @@ -16,8 +18,6 @@ self, nixpkgs, home-manager, - deploy-rs, - # zenium, ... }@inputs: @@ -34,9 +34,13 @@ modules = [ ./system/configuration.nix - ./containers/main.nix + ./containers + ./services "${nixpkgs}/nixos/modules/profiles/minimal.nix" + # Nix secrets hehe :3 + inputs.sops-nix.nixosModules.sops + home-manager.nixosModules.home-manager { home-manager.useGlobalPkgs = true; @@ -48,17 +52,5 @@ } ]; }; - - # deploy-rs config - deploy.nodes.snow-den = { - hostname = "server"; # can be IP or hostname in SSH config - profiles.system = { - sshUser = "snow"; # non-root user with access - user = "root"; - interacticeSudo = true; - remoteBuild = true; - path = deploy-rs.lib.x86_64-linux.activate.nixos self.nixosConfigurations.snow-den; - }; - }; }; } diff --git a/server/home-manager/snow.nix b/server/home-manager/snow.nix index 5a4bd4b..c096815 100644 --- a/server/home-manager/snow.nix +++ b/server/home-manager/snow.nix @@ -14,12 +14,9 @@ packages = with pkgs; [ git - # nixd - # nixfmt-rfc-style devenv # yazi ctop - # inputs.zenium.packages."${system}".zenium-remote-server-bin ]; }; diff --git a/server/justfile b/server/justfile index 162ecd0..d994f80 100644 --- a/server/justfile +++ b/server/justfile @@ -5,7 +5,10 @@ dry-run: nixos-rebuild dry-run --flake .#snow-den deploy: - nixos-rebuild switch --flake .#snow-den --target-host server --use-remote-sudo + nixos-rebuild switch --flake .#snow-den --target-host server --build-host server --use-remote-sudo + +update: + nix flake update test-vm: nixos-rebuild build-vm-with-bootloader --flake .#snow-den && QEMU_NET_OPTS="hostfwd=tcp::2221-:335,hostfwd=tcp::8080-:80" ./result/bin/run-snow-den-vm diff --git a/server/result b/server/result deleted file mode 120000 index 433e1c0..0000000 --- a/server/result +++ /dev/null @@ -1 +0,0 @@ -/nix/store/q2l4r4920q2zrm7mh6j718h68k8kz4nz-nixos-vm \ No newline at end of file diff --git a/server/secrets/example.yaml b/server/secrets/example.yaml new file mode 100644 index 0000000..56280e0 --- /dev/null +++ b/server/secrets/example.yaml @@ -0,0 +1,45 @@ +example_key: ENC[AES256_GCM,data:xqHoe3fPJwbpEytLkw==,iv:KLQf+7WKGViSrNIqR1sWIAEg2WVH0UfjK6PwVxbXVWM=,tag:zeWSmtJO3kJ/eCXJNp/h8Q==,type:str] +#ENC[AES256_GCM,data:+b7sZjD7+b6SgA==,iv:x6SjxKlIOSH6CgT7Yb9e31p4bHlPZuRJ9FBMKpir+3k=,tag:j8gk26rDYzMIr/zUM+tKDQ==,type:comment] +garage: + #ENC[AES256_GCM,data:Yx8PEnI/5OpHx6iVtE1oASzXSMJpEdgdX5V+5zUGDP6R1g==,iv:ggeiDdg3uzZKwRyw/yFFWg1ohxGbrHiSrhXbydhG10g=,tag:RrwmHXYdERfyh0JE1xEq0g==,type:comment] + rpc_secret: ENC[AES256_GCM,data:4pv/pkXGajsUxxcQ/qrn4S5rB1sVATgTlDK58aZmtR7vu777DhnMnC+kIYijKt/Sr/fKbbfcNnYHVx1XV0LnhA==,iv:WY+V7viT7LSoKLbEgjncyzih82zQvFjWlvDDpDEuwb0=,tag:Fd98GTbXnqYWw5Onh1BR6A==,type:str] + #ENC[AES256_GCM,data:Df0g74tf3/UB0jOq1tIwxzyipJ66ZVdt4Qe17kS4ou635wM0jTyxuqw0hIM=,iv:M91CxwA7PsUJse7sIwWEdF54a0o+ZuOyT5IS5UGaWdk=,tag:CrCbgoPh1dHCmC/BxaVBtw==,type:comment] + admin_token: ENC[AES256_GCM,data:RAftH7+QvGbGiY3V+COPFwsSiiqfcg3w0JTOgabLNujcK+6eXz25mveeSQd6kBe8wbZm3+nC21fq1Q3SRXo10w==,iv:1Hy9p6c+0N/pu8m+AevCcWQj2AwWtKcL9/W43R1XDn0=,tag:Aaj1vFWsBqhiyz0fdohokA==,type:str] + #ENC[AES256_GCM,data:Df0g74tf3/UB0jOq1tIwxzyipJ66ZVdt4Qe17kS4ou635wM0jTyxuqw0hIM=,iv:M91CxwA7PsUJse7sIwWEdF54a0o+ZuOyT5IS5UGaWdk=,tag:CrCbgoPh1dHCmC/BxaVBtw==,type:comment] + metrics_token: ENC[AES256_GCM,data:aMEA+JL+Dnd+S4v6ypA/eMocI1nOOHLvGrOtaKN0Vkx2U6c9EYnOZ09DfpPb4n+r9p0X/cOt09zW+ZSQEJqS7A==,iv:a5UUHkybp87dO0Gk6vbta9L5C4EbYZ3oRQS8ItlQILE=,tag:4HCPGq5+jmVsgpODBxefPg==,type:str] +sops: + age: + - recipient: age16e3uae0sktxmwzlmcdxwn07jpudtjl0s42hnwx2qsdh9h72gc5ssktkazg + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBkTDYwLy9Sanh4aWttNnVk + WGJHQ1lmcDcwLzlEY3hhKzBmQkgyb0lwdGlrCjZXVm1hT1hKOU11ZndIVVhuRHFO + SDN4ZDJYSGRQMldZa2dPNmQyelR5cjQKLS0tIHVPNVBqT3pmWVdySlZPK001c3p5 + dUp2cU1wMU1Kd2J2cmlBMmlnbjVJV2sKkKx5nO2auold0qB6066aY1KXAjC2slna + G+Cy8EcjgRh29w5RFRyx541jOGvtf+wuz11R1dUY1o/NHdn2wFhJTg== + -----END AGE ENCRYPTED FILE----- + lastmodified: "2025-12-21T11:43:03Z" + mac: ENC[AES256_GCM,data:2MfZXU76GBuqU1ZYvknpPys24hW5eVEqotg3yFt8xupdS4EVGLGV1Ay36iL7Nd79j4iU3TSMqbyx5Gepqtwix/XnBy91bcq9TFKcvZ868PuntJR2BUKKggDwK544P0Mhh8BGHYsHCbwiemfGZUecoEqe9caToKBlZL2MITvav3I=,iv:kIeHl8m+HVcHtqzPF+jiiIV8k2/WtKXuToZ+gR385UA=,tag:+m9wK2Q5GwSFHKkK3GMPrg==,type:str] + pgp: + - created_at: "2025-12-19T16:08:52Z" + enc: |- + -----BEGIN PGP MESSAGE----- + + hQIMA09oKgMfawMUAQ//WkbrA+iFyXsH1YRr1hT2gxG406yD+c4jfTBY/CAzARgj + vyyjJ5rVcltzXQBKNzgnBFsn6GW95vWVKh98Q7KksC3Qm72NOZtPc5iai3y151Z2 + qxiwNFKD/VBIpuxX86MypkbwEuZn3N0teiGTaTx9dKxc9/y4WqjusD5Xp6O2T4oO + 617JWKTTp+66Ca8t8SuUZQ+bl1nNmJOETn7a8Ws+HZe6n0Pcx9VCfHnAGPziVYTc + x5n6z5FnGWf+kmBpExmRiE+37Waa3+YMm7SOY7HlsompVWNww1WyiMnPGs9cAUOj + XsfMnMnoxiGoPeTvFbsLobeY0S8TcpIfJ43LmPqurK4a3/Cd8Z5rKS8BqrpchFy1 + uqPzQ/4oKmduzWcTdzmqxBDe1AsUXZZs7Tq2ypJ9oFdQy226baur85PJb9skLe2k + UcJaJ/UTxlnUv4LTCBOXbBglpoFLcwIQeT54MyoozhMBY2Cndj9ffto8UaZwMq2l + ppnfAGbUVVk1OFd/DNTzflXDb0W1ZN7e2+4voYlggplFfqqDVEi5b1WyJc6EE0ep + uhJjeokdtKbAwSbrN78+WWnrGFIb6x3w6jh9VTqLw3zFlHL0YIcz5pyJMrA++Wh8 + qJwDGpPNVkrq5a1vJovYqtQM34Ih9MGLQvf7cCbHDoO+1OqGULGlm3jXtev+/0/S + XgE2h3SCo2eCXBGaGYttIq+s0QDFNueT7luAvr81wTHBiKnMdg7cnjkJPebE4AM3 + OJKxYUb7ie7MsDTZBiR6Wgpp0Ygqo1J+YTcyQPeKy/HbmLiv9jlAmRKqxxIVHjg= + =JhLZ + -----END PGP MESSAGE----- + fp: D40CE1579C09BFD7EF4AB7E631250420834310B5 + unencrypted_suffix: _unencrypted + version: 3.11.0 diff --git a/server/services/caddy.nix b/server/services/caddy.nix new file mode 100644 index 0000000..af4a8cf --- /dev/null +++ b/server/services/caddy.nix @@ -0,0 +1,129 @@ +{ + config, + lib, + pkgs, + ... +}: +let + hestia_ip = "10.0.100.65"; +in +{ + services.caddy = { + enable = true; + globalConfig = '' + + ''; + + extraConfig = '' + mrsnowy.dev, mail.mrsnowy.dev, fpps4.net, www.paradijs-in-hongarije.nl, paradijs-in-hongarije.nl, prowebservice.nl, smarty.nl, www.zendojaku.nl, zendojaku.nl { + reverse_proxy https://${hestia_ip} { + transport http { + tls_insecure_skip_verify + } + } + } + + hestia.mrsnowy.dev { + reverse_proxy https://${hestia_ip}:8083 { + transport http { + tls_insecure_skip_verify + } + } + } + + api.fpps4.net { + encode zstd gzip + + reverse_proxy https://${hestia_ip} { + transport http { + tls_insecure_skip_verify + } + } + + header { + Access-Control-Allow-Origin * + } + } + + dockge.mrsnowy.dev { + reverse_proxy :${toString config.ports.dockge} + } + + vaultwarden.mrsnowy.dev { + reverse_proxy :${toString config.ports.vaultwarden} + } + + stream.mrsnowy.dev { + reverse_proxy :${toString config.ports.broadcast_box} + } + + board.mrsnowy.dev { + reverse_proxy :${toString config.ports.grafana} + } + + adminpg.mrsnowy.dev { + reverse_proxy :${toString config.ports.pgadmin} + } + + obsidian.mrsnowy.dev { + reverse_proxy :${toString config.ports.couchdb} + } + + ente.mrsnowy.dev { + reverse_proxy :${toString config.ports.ente.web} + header { + Access-Control-Allow-Origin https://minio.ente.mrsnowy.dev + } + } + + api.ente.mrsnowy.dev { + reverse_proxy :${toString config.ports.ente.api} + } + + accounts.ente.mrsnowy.dev { + reverse_proxy :${toString config.ports.ente.accounts} + } + + albums.ente.mrsnowy.dev { + reverse_proxy :${toString config.ports.ente.albums} + } + + auth.ente.mrsnowy.dev { + reverse_proxy :${toString config.ports.ente.auth} + } + + cast.ente.mrsnowy.dev { + reverse_proxy :${toString config.ports.ente.cast} + } + + embed.ente.mrsnowy.dev { + reverse_proxy :${toString config.ports.ente.embed} + } + + minio.ente.mrsnowy.dev { + reverse_proxy :${toString config.ports.ente.minio.api} + } + + minio-web.ente.mrsnowy.dev { + reverse_proxy :${toString config.ports.ente.minio.web} + } + + headscale.mrsnowy.dev { + reverse_proxy :${toString config.ports.headscale} + } + + syncthing.mrsnowy.dev { + reverse_proxy :${toString config.ports.syncthing} + } + + *.garage.mrsnowy.dev, garage.mrsnowy.dev { + reverse_proxy :${toString config.ports.garage.web_api} + } + + *.s3.mrsnowy.dev, s3.mrsnowy.dev { + reverse_proxy :${toString config.ports.garage.s3_api} + } + ''; + }; + +} diff --git a/server/services/main.nix b/server/services/default.nix similarity index 59% rename from server/services/main.nix rename to server/services/default.nix index cf6ee6e..43857ed 100644 --- a/server/services/main.nix +++ b/server/services/default.nix @@ -4,8 +4,12 @@ pkgs, ... }: + { imports = [ ./incus.nix + ./random.nix + ./garage.nix + ./caddy.nix ]; } diff --git a/server/services/garage.nix b/server/services/garage.nix new file mode 100644 index 0000000..b58ce0f --- /dev/null +++ b/server/services/garage.nix @@ -0,0 +1,58 @@ +{ + config, + lib, + pkgs, + ... +}: +{ + # todo! garage-webui :3 + services.garage = { + enable = true; + package = pkgs.garage_2; + settings = { + db_engine = "sqlite"; + compression_level = 18; + replication_factor = 1; + consistency_mode = "consistent"; + metadata_fsync = true; + data_fsync = true; + allow_world_readable_secrets = true; + + data_dir = [ + { + capacity = "200G"; + path = "/var/lib/garage/data"; + } + ]; + + rpc_bind_addr = "[::]:3901"; + # rpc_public_addr = "127.0.0.1:3901"; + rpc_secret_file = config.sops.secrets."garage/rpc_secret".path; + + bootstrap_peers = [ ]; + + s3_api = { + api_bind_addr = "[::]:${toString config.ports.garage.s3_api}"; + s3_region = "Europe-1"; + root_domain = "s3.mrsnowy.dev"; + }; + + s3_web = { + bind_addr = "[::]:${toString config.ports.garage.web_api}"; + index = "index.html"; + root_domain = "garage.mrsnowy.dev"; + }; + + admin = { + api_bind_addr = "[::]:${toString config.ports.garage.admin}"; + admin_token_file = config.sops.secrets."garage/admin_token".path; + metrics_token_file = config.sops.secrets."garage/metrics_token".path; + metrics_require_token = true; + }; + + # k2v_api = { + # api_bind_addr = "[::]:3904"; + # }; + }; + }; +} diff --git a/server/services/incus.nix b/server/services/incus.nix index 50a8548..a3d1a7d 100644 --- a/server/services/incus.nix +++ b/server/services/incus.nix @@ -1,4 +1,9 @@ -{ pkgs, ... }: +{ + config, + lib, + pkgs, + ... +}: { virtualisation.incus = { enable = true; @@ -13,7 +18,7 @@ preseed = { config = { - "core.https_address" = ":8444"; + "core.https_address" = ":${toString config.ports.incus}"; "core.shutdown_timeout" = "3"; "images.compression_algorithm" = "xz"; "backups.compression_algorithm" = "xz"; @@ -55,22 +60,6 @@ }; } ]; - - # projects = [ - # { - # name = "hestia-project"; - # # descripion = "Project for hestia"; - # config = { - # "features.images" = true; - # "features.networks" = true; - # "features.networks.zones" = false; - # "features.profiles" = false; - # "features.storage.buckets" = false; - # "features.storage.volumes" = true; - # }; - # } - # ]; - }; }; } diff --git a/server/services/random.nix b/server/services/random.nix new file mode 100644 index 0000000..3d17b0b --- /dev/null +++ b/server/services/random.nix @@ -0,0 +1,62 @@ +{ + config, + lib, + pkgs, + ... +}: + +{ + + services = { + openssh = { + enable = true; + ports = [ + 335 + ]; + allowSFTP = true; + banner = "meow meow\n"; + authorizedKeysInHomedir = false; + settings = { + PasswordAuthentication = false; + PermitRootLogin = "no"; + AllowUsers = [ + "snow" + "file-backup" + ]; + }; + extraConfig = '' + Match User file-backup + ChrootDirectory %h + ForceCommand internal-sftp -d /meow -u 700 + ''; + }; + + endlessh-go = { + enable = true; + port = 22; + prometheus = { + enable = true; + port = 2112; + }; + }; + + headscale = { + enable = true; + port = config.ports.headscale; + settings = { + server_url = "https://headscale.mrsnowy.dev"; + dns.base_domain = "magicdns.headscale.mrsnowy.dev"; + }; + }; + + syncthing = { + enable = false; + overrideDevices = true; + overrideFolders = false; + guiAddress = "127.0.0.1:${toString config.ports.syncthing}"; + settings.options.urAccepted = -1; + }; + + tailscale.enable = true; + }; +} diff --git a/server/system/configuration.nix b/server/system/configuration.nix index a506e43..9e3826f 100644 --- a/server/system/configuration.nix +++ b/server/system/configuration.nix @@ -3,8 +3,8 @@ # https://search.nixos.org/options and in the NixOS manual (`nixos-help`). { - # config, - # lib, + config, + lib, pkgs, ... }: @@ -13,8 +13,9 @@ imports = [ # Include the results of the hardware scan. ./hardware-configuration.nix - ../services/main.nix ./network.nix + ./sops.nix + ./ports.nix ]; zramSwap = { @@ -76,7 +77,7 @@ grub = { enable = true; - timeoutStyle = "hidden"; + timeoutStyle = "menu"; efiSupport = true; # efiInstallAsRemovable = true; device = "nodev"; @@ -145,53 +146,13 @@ }; }; - services = { - openssh = { - enable = true; - ports = [ - 335 - ]; - allowSFTP = true; - settings = { - PasswordAuthentication = false; - PermitRootLogin = "no"; - }; - }; - - # endlessh-go = { - # enable = true; - # port = 22; - - # prometheus = { - # enable = true; - # port = 2112; - # listenAddress = "0.0.0.0"; - # }; - # }; - - headscale = { - enable = true; - port = 3443; - settings = { - server_url = "https://headscale.mrsnowy.dev:3443"; - dns.base_domain = "magicdns.headscale.mrsnowy.dev"; - }; - }; - - tailscale.enable = true; - - # prometheus = { - # enable = true; - # }; - }; - programs = { nano.enable = false; fish.enable = true; - nh = { - enable = true; - flake = "/etc/nixos"; - }; + # nh = { + # enable = true; + # flake = "/etc/nixos"; + # }; }; security = { @@ -242,29 +203,41 @@ }; users = { - groups.radcliffe = { }; - groups.proc-bypass = { }; + groups = { + snow = { }; + file-share = { }; + proc-bypass = { }; + file-backup = { }; + }; users = { snow = { isNormalUser = true; description = "snow"; linger = true; + group = "snow"; extraGroups = [ "wheel" "proc-bypass" + "users" ]; shell = pkgs.fish; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL2za6psnuIMZ6FrdUehhyQlqYvy05+wv8dKER+Lctna snowy@Snowflake" ]; }; - radcliffe = { + # file-backup = { + # isNormalUser = true; + # description = "A user for backuping files onto"; + # group = "file-backup"; + # # shell = "${pkgs.util-linux}/bin/nologin"; + # openssh.authorizedKeys.keys = [ + # "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL2za6psnuIMZ6FrdUehhyQlqYvy05+wv8dKER+Lctna snowy@Snowflake" + # "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJWIEtXpj/CKFep8RqmpSQchYPNEUHGFnwP4UjJS16ey snowy@Snowflake" + # ]; + # }; + file-share = { isNormalUser = true; - linger = true; - group = "radcliffe"; - extraGroups = [ - "proc-bypass" - ]; + group = "file-share"; shell = pkgs.fish; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL2za6psnuIMZ6FrdUehhyQlqYvy05+wv8dKER+Lctna snowy@Snowflake" @@ -275,4 +248,12 @@ }; }; }; + + systemd = { + user.services.docker.unitConfig.ConditionUser = lib.mkForce "snow"; + # tmpfiles.rules = [ + # "d ${config.users.users.file-backup.home} 0755 root root -" + # "d ${config.users.users.file-backup.home}/meow 0700 ${config.users.users.file-backup.name} ${config.users.users.file-backup.group} -" + # ]; + }; } diff --git a/server/system/network.nix b/server/system/network.nix index 0fb03ce..1c155d0 100644 --- a/server/system/network.nix +++ b/server/system/network.nix @@ -114,7 +114,7 @@ # broadcast-box 9070 - # Satisfactory + # Satisfactory && Astroneer 7777 # Steam diff --git a/server/system/ports.nix b/server/system/ports.nix new file mode 100644 index 0000000..75ec966 --- /dev/null +++ b/server/system/ports.nix @@ -0,0 +1,40 @@ +# All http ports +{ lib, config, ... }: + +{ + options.ports = lib.mkOption { + type = lib.types.attrsOf lib.types.anything; + default = { + dockge = 3000; + vaultwarden = 3001; + broadcast_box = 3002; + grafana = 3003; + pgadmin = 3004; + couchdb = 3005; + + ente = { + api = 3006; + web = 3007; + accounts = 3008; + albums = 3009; + auth = 3010; + cast = 3011; + embed = 3017; + minio = { + api = 3012; + web = 3013; + }; + }; + + garage = { + s3_api = 3014; + web_api = 3015; + admin = 3016; + }; + + syncthing = 3020; + headscale = 3443; + incus = 8444; + }; + }; +} diff --git a/server/system/sops.nix b/server/system/sops.nix new file mode 100644 index 0000000..0d6d26f --- /dev/null +++ b/server/system/sops.nix @@ -0,0 +1,46 @@ +{ + config, + lib, + pkgs, + ... +}: + +{ + sops = { + defaultSopsFile = ../secrets/example.yaml; + age = { + keyFile = "/root/.config/sops/age/keys.txt"; + generateKey = false; + }; + secrets = { + example_key = { }; + "garage/rpc_secret" = { + mode = "0440"; + # owner = config.users.users.root.name; + group = "sops_garage"; + }; + + "garage/admin_token" = { + mode = "0440"; + # owner = config.users.users.root.name; + group = "sops_garage"; + }; + + "garage/metrics_token" = { + mode = "0440"; + # owner = config.users.users.root.name; + group = "sops_garage"; + }; + }; + }; + + users.groups = { + sops_garage = { }; + }; + + systemd.services = { + garage.serviceConfig.SupplementaryGroups = [ + "sops_garage" + ]; + }; +}