diff --git a/.config/hypr/hyprland.conf b/.config/hypr/hyprland.conf index 4edc802..1c8af75 100644 --- a/.config/hypr/hyprland.conf +++ b/.config/hypr/hyprland.conf @@ -52,6 +52,8 @@ exec-once = wl-paste --type text --watch cliphist store #Stores only text data exec-once = wl-paste --type image --watch cliphist store #Stores only image data #exec-once = hyprpm reload -n #exec-once = hyprctl plugin load $(find /nix/store -maxdepth 1 -wholename "*-hyprsplit-$(hyprctl version -j | jq -r .version)" -print -quit)/lib/libhyprsplit.so +exec-once = hyprctl plugin load ${$LIB_HYPRSPLIT} +exec-once = ${$POLKIT_GNOME} #exec-once = gentoo-pipewire-launcher #exec-once = kwalletd5 & diff --git a/nixos/flake.lock b/nixos/flake.lock index f9082d5..cfd8a61 100644 --- a/nixos/flake.lock +++ b/nixos/flake.lock @@ -56,26 +56,6 @@ "type": "github" } }, - "fennec-flake": { - "inputs": { - "flake-parts": "flake-parts", - "nixpkgs": "nixpkgs_2" - }, - "locked": { - "lastModified": 1754899525, - "narHash": "sha256-B1tfF/LeK7m/LFtB8t8H3lspOCtS9oOjztk297Juyvk=", - "ref": "mrrow", - "rev": "9ed246b1a635ed2edb5a7ff2bf55343494622f70", - "revCount": 43, - "type": "git", - "url": "https://git.killuaa.dev/Rouffy/fennec-flake" - }, - "original": { - "ref": "mrrow", - "type": "git", - "url": "https://git.killuaa.dev/Rouffy/fennec-flake" - } - }, "flake-compat": { "flake": false, "locked": { @@ -110,24 +90,6 @@ "type": "github" } }, - "flake-parts_2": { - "inputs": { - "nixpkgs-lib": "nixpkgs-lib_2" - }, - "locked": { - "lastModified": 1754487366, - "narHash": "sha256-pHYj8gUBapuUzKV/kN/tR3Zvqc7o6gdFB9XKXIp1SQ8=", - "owner": "hercules-ci", - "repo": "flake-parts", - "rev": "af66ad14b28a127c5c0f3bbb298218fc63528a18", - "type": "github" - }, - "original": { - "owner": "hercules-ci", - "repo": "flake-parts", - "type": "github" - } - }, "flake-schemas": { "locked": { "lastModified": 1721999734, @@ -295,7 +257,7 @@ "hyprlang": "hyprlang", "hyprutils": "hyprutils", "hyprwayland-scanner": "hyprwayland-scanner", - "nixpkgs": "nixpkgs_3", + "nixpkgs": "nixpkgs_2", "pre-commit-hooks": "pre-commit-hooks", "systems": "systems", "xdph": "xdph" @@ -314,36 +276,6 @@ "type": "github" } }, - "hyprland-plugins": { - "inputs": { - "hyprland": [ - "hyprland" - ], - "nixpkgs": [ - "hyprland-plugins", - "hyprland", - "nixpkgs" - ], - "systems": [ - "hyprland-plugins", - "hyprland", - "systems" - ] - }, - "locked": { - "lastModified": 1756806479, - "narHash": "sha256-+RLX4BmuMw4c97npsBcjjEuy+s83POX9Yp8Nkj499lA=", - "owner": "hyprwm", - "repo": "hyprland-plugins", - "rev": "b8d6d369618078b2dbb043480ca65fe3521f273b", - "type": "github" - }, - "original": { - "owner": "hyprwm", - "repo": "hyprland-plugins", - "type": "github" - } - }, "hyprland-protocols": { "inputs": { "nixpkgs": [ @@ -618,22 +550,23 @@ "type": "github" } }, - "nixpkgs-lib": { + "nixpkgs-extra-unstable": { "locked": { - "lastModified": 1753579242, - "narHash": "sha256-zvaMGVn14/Zz8hnp4VWT9xVnhc8vuL3TStRqwk22biA=", - "owner": "nix-community", - "repo": "nixpkgs.lib", - "rev": "0f36c44e01a6129be94e3ade315a5883f0228a6e", + "lastModified": 1757034884, + "narHash": "sha256-PgLSZDBEWUHpfTRfFyklmiiLBE1i1aGCtz4eRA3POao=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "ca77296380960cd497a765102eeb1356eb80fed0", "type": "github" }, "original": { - "owner": "nix-community", - "repo": "nixpkgs.lib", + "owner": "NixOS", + "ref": "nixpkgs-unstable", + "repo": "nixpkgs", "type": "github" } }, - "nixpkgs-lib_2": { + "nixpkgs-lib": { "locked": { "lastModified": 1753579242, "narHash": "sha256-zvaMGVn14/Zz8hnp4VWT9xVnhc8vuL3TStRqwk22biA=", @@ -648,34 +581,18 @@ "type": "github" } }, - "nixpkgs-pgks-unstable": { - "locked": { - "lastModified": 1757034884, - "narHash": "sha256-PgLSZDBEWUHpfTRfFyklmiiLBE1i1aGCtz4eRA3POao=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "ca77296380960cd497a765102eeb1356eb80fed0", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixpkgs-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, "nixpkgs-stable": { "locked": { - "lastModified": 1751274312, - "narHash": "sha256-/bVBlRpECLVzjV19t5KMdMFWSwKLtb5RyXdjz3LJT+g=", + "lastModified": 1757408970, + "narHash": "sha256-aSgK4BLNFFGvDTNKPeB28lVXYqVn8RdyXDNAvgGq+k0=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "50ab793786d9de88ee30ec4e4c24fb4236fc2674", + "rev": "d179d77c139e0a3f5c416477f7747e9d6b7ec315", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-24.11", + "ref": "nixos-25.05", "repo": "nixpkgs", "type": "github" } @@ -697,22 +614,6 @@ } }, "nixpkgs_2": { - "locked": { - "lastModified": 1754725699, - "narHash": "sha256-iAcj9T/Y+3DBy2J0N+yF9XQQQ8IEb5swLFzs23CdP88=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "85dbfc7aaf52ecb755f87e577ddbe6dbbdbc1054", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixos-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_3": { "locked": { "lastModified": 1757068644, "narHash": "sha256-NOrUtIhTkIIumj1E/Rsv1J37Yi3xGStISEo8tZm3KW4=", @@ -728,7 +629,7 @@ "type": "github" } }, - "nixpkgs_4": { + "nixpkgs_3": { "locked": { "lastModified": 1756731054, "narHash": "sha256-kifUBw3WDopsgxUq0X9hFb2MMDeqhREbF1YttEj6IpM=", @@ -743,7 +644,7 @@ "type": "github" } }, - "nixpkgs_5": { + "nixpkgs_4": { "locked": { "lastModified": 1755615617, "narHash": "sha256-HMwfAJBdrr8wXAkbGhtcby1zGFvs+StOp19xNsbqdOg=", @@ -785,13 +686,11 @@ "root": { "inputs": { "chaotic": "chaotic", - "fennec-flake": "fennec-flake", "home-manager": "home-manager_2", "hyprland": "hyprland", - "hyprland-plugins": "hyprland-plugins", "lsfg-vk-flake": "lsfg-vk-flake", "nix-index": "nix-index", - "nixpkgs-pgks-unstable": "nixpkgs-pgks-unstable", + "nixpkgs-extra-unstable": "nixpkgs-extra-unstable", "nixpkgs-stable": "nixpkgs-stable", "nixpkgs-unstable": "nixpkgs-unstable", "zed-editor": "zed-editor", @@ -877,8 +776,8 @@ }, "zed-editor": { "inputs": { - "flake-parts": "flake-parts_2", - "nixpkgs": "nixpkgs_4" + "flake-parts": "flake-parts", + "nixpkgs": "nixpkgs_3" }, "locked": { "lastModified": 1756797624, @@ -897,7 +796,7 @@ "zen-browser": { "inputs": { "home-manager": "home-manager_3", - "nixpkgs": "nixpkgs_5" + "nixpkgs": "nixpkgs_4" }, "locked": { "lastModified": 1757395105, diff --git a/nixos/flake.nix b/nixos/flake.nix index 59694dd..dae6cdc 100644 --- a/nixos/flake.nix +++ b/nixos/flake.nix @@ -40,7 +40,7 @@ chaotic, # fennec-flake, zed-editor, - nixpkgs-pgks-unstable, + nixpkgs-extra-unstable, lsfg-vk-flake, nix-index, ... diff --git a/nixos/home-manager/snowy.nix b/nixos/home-manager/snowy.nix index 8b5a2e5..290b554 100644 --- a/nixos/home-manager/snowy.nix +++ b/nixos/home-manager/snowy.nix @@ -62,8 +62,16 @@ wineWowPackages.staging # wine64 + pkgs-extra-unstable.hyprlandPlugins.hyprsplit ]; + + systemd.user.sessionVariables = { + # Define some locations of some files, this seemed like the least wack way to do things. + POLKIT_GNOME = "${pkgs.polkit_gnome}/libexec/polkit-gnome-authentication-agent-1"; + LIB_HYPRSPLIT = "${pkgs-extra-unstable.hyprlandPlugins.hyprsplit}/lib/libhyprsplit.so" + }; + programs = { helix = { @@ -143,7 +151,7 @@ ]; }; - # Make it base it on my hyprland config, I dont like managing configs throug home manager tbh. + # Make it base it on my hyprland config, I dont like managing configs trough home manager tbh. extraConfig = builtins.readFile ../../.config/hypr/hyprland.conf; }; diff --git a/nixos/home-manager/snowy/stow.sh b/nixos/home-manager/snowy/stow.sh new file mode 100644 index 0000000..98d5cad --- /dev/null +++ b/nixos/home-manager/snowy/stow.sh @@ -0,0 +1,4 @@ +#!/usr/bin/env nix-shell +#!nix-shell -i bash -p stow + +stow silly diff --git a/nixos/system/configuration.nix b/nixos/system/configuration.nix index 9f90a67..a470423 100644 --- a/nixos/system/configuration.nix +++ b/nixos/system/configuration.nix @@ -20,6 +20,8 @@ qt.enable = true; nix = { + package = pkgs.lix; + settings = { experimental-features = [ "nix-command" diff --git a/server/configuration.nix b/server/configuration.nix deleted file mode 100644 index ff05e50..0000000 --- a/server/configuration.nix +++ /dev/null @@ -1,254 +0,0 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page, on -# https://search.nixos.org/options and in the NixOS manual (`nixos-help`). - -{ config, lib, pkgs, ... }: - -{ - imports = - [ # Include the results of the hardware scan. - ./hardware-configuration.nix - ]; - - zramSwap = { - enable = true; - algorithm = "zstd"; - }; - - swapDevices = [{ - device = "/swapfile"; - size = 8 * 1024; # 16GB - }]; - - nix = { - settings = { - experimental-features = [ - "nix-command" - "flakes" - ]; - # trusted-user = { - # "@wheel" - # }; - auto-optimise-store = true; - }; - gc = { - automatic = true; - dates = "daily"; - }; - }; - - # Use grub so it works on both EFI and BOOT - boot = { - loader = { - efi.canTouchEfiVariables = true; - - grub = { - enable = true; - timeoutStyle = "hidden"; - efiSupport = true; - # efiInstallAsRemovable = true; - device = "nodev"; - splashImage = null; - }; - }; - - blacklistedKernelModules = [ - # Obscure network protocols - "ax25" - "netrom" - "rose" - - # Old or rare or insufficiently audited filesystems - "adfs" - "affs" - "bfs" - "befs" - "cramfs" - "efs" - "erofs" - "exofs" - "freevxfs" - "f2fs" - "hfs" - "hpfs" - "jfs" - "minix" - "nilfs2" - "ntfs" - "omfs" - "qnx4" - "qnx6" - "sysv" - "ufs" - ]; - }; - - networking = { - hostName = "snow-den"; - # nameservers = []; - - # interfaces = { - # ens18 = { - # ipv4 = { - # addresses = [ - # { - # address = "193.24.209.147"; - # prefixLength = 24; - # } - # ]; - # }; - # }; - # }; - - firewall = { - enable = true; - allowedTCPPorts = [ - 22 - 335 - ]; - allowedUDPPorts = [ - - ]; - }; - }; - - time.timeZone = "Europe/Berlin"; # Set your time zone. - i18n.defaultLocale = "en_US.UTF-8"; # Select internationalisation properties. - - environment = { - defaultPackages = []; # Disable any default installed packages - - systemPackages = with pkgs; [ - fastfetch - helix - # wget - btop - ]; - }; - - fonts.fontconfig.enable = false; - - system = { - stateVersion = "25.05"; - tools = { - nixos-version.enable = true; - nixos-rebuild.enable = true; - nixos-option.enable = true; - - nixos-generate-config.enable = false; - nixos-install.enable = false; - nixos-build-vms.enable = false; - }; - }; - - - services = { - dnsmasq = { - enable = true; - settings = { - server = [ - "1.1.1.1" - "2606:4700:4700::1111" - "1.0.0.1" - "2606:4700:4700::1001" - "194.242.2.2" - "2a07:e340::2" - ]; - }; - }; - - openssh = { - enable = true; - ports = [ - 335 - ]; - allowSFTP = true; - settings = { - PasswordAuthentication = false; - PermitRootLogin = "no"; - }; - }; - - endlessh-go = { - enable = true; - port = 22; - - # prometheus = { - # enable = true; - # port = 2112; - # }; - }; - - # prometheus = { - # enable = true; - # }; - }; - - programs = { - nano.enable = false; - fish.enable = true; - nh = { - enable = true; - flake = "/etc/nixos"; - }; - }; - - security = { - sudo.enable = false; - sudo-rs = { - enable = true; - wheelNeedsPassword = true; - execWheelOnly = true; - # extraConfig = '' - # Defaults passwd_timeout=0 - # ''; - }; - - wrappers = { - docker-rootlesskit = { - owner = "root"; - group = "root"; - capabilities = "cap_net_bind_service+ep"; - source = "${pkgs.rootlesskit}/bin/rootlesskit"; - }; - }; - }; - - virtualisation = { - docker = { - rootless = { - enable = true; - setSocketVariable = true; - }; - }; - - lxd = { - enable = true; - recommendedSysctlSettings = true; - ui = { - enable = true; - package = pkgs.lxd-ui; - }; - }; - }; - - users.users = { - snow = { - isNormalUser = true; - description = "snow"; - extraGroups = [ - "wheel" - ]; - shell = pkgs.fish; - openssh.authorizedKeys.keys = [ - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL2za6psnuIMZ6FrdUehhyQlqYvy05+wv8dKER+Lctna snowy@Snowflake" - ]; - }; - root = { - shell = pkgs.fish; - openssh.authorizedKeys.keys = [ - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL2za6psnuIMZ6FrdUehhyQlqYvy05+wv8dKER+Lctna snowy@Snowflake" - ]; - }; - }; -} diff --git a/server/flake.lock b/server/flake.lock index 8add1f5..e939e95 100644 --- a/server/flake.lock +++ b/server/flake.lock @@ -7,11 +7,11 @@ ] }, "locked": { - "lastModified": 1748737919, - "narHash": "sha256-5kvBbLYdp+n7Ftanjcs6Nv+UO6sBhelp6MIGJ9nWmjQ=", + "lastModified": 1754263839, + "narHash": "sha256-ck7lILfCNuunsLvExPI4Pw9OOCJksxXwozum24W8b+8=", "owner": "nix-community", "repo": "home-manager", - "rev": "5675a9686851d9626560052a032c4e14e533c1fa", + "rev": "1d7abbd5454db97e0af51416f4960b3fb64a4773", "type": "github" }, "original": { @@ -23,11 +23,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1748437600, - "narHash": "sha256-hYKMs3ilp09anGO7xzfGs3JqEgUqFMnZ8GMAqI6/k04=", + "lastModified": 1754292888, + "narHash": "sha256-1ziydHSiDuSnaiPzCQh1mRFBsM2d2yRX9I+5OPGEmIE=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "7282cb574e0607e65224d33be8241eae7cfe0979", + "rev": "ce01daebf8489ba97bd1609d185ea276efdeb121", "type": "github" }, "original": { @@ -37,78 +37,10 @@ "type": "github" } }, - "nixpkgs_2": { - "locked": { - "lastModified": 1748798537, - "narHash": "sha256-l7ObzI637Tvty57eGKWhDtILX+PTZNSSwMTLj8JOxoQ=", - "owner": "nixos", - "repo": "nixpkgs", - "rev": "f0baa02d9422bd78a1b9072950b6c3f53e885332", - "type": "github" - }, - "original": { - "owner": "nixos", - "repo": "nixpkgs", - "type": "github" - } - }, "root": { "inputs": { "home-manager": "home-manager", - "nixpkgs": "nixpkgs", - "zenium": "zenium" - } - }, - "systems": { - "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" - } - }, - "utils": { - "inputs": { - "systems": "systems" - }, - "locked": { - "lastModified": 1731533236, - "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", - "type": "github" - }, - "original": { - "owner": "numtide", - "repo": "flake-utils", - "type": "github" - } - }, - "zenium": { - "inputs": { - "nixpkgs": "nixpkgs_2", - "utils": "utils" - }, - "locked": { - "lastModified": 1748638806, - "narHash": "sha256-V8Qhs8TJXgYwxze5T36hpCUBK5U5aBDawFDIcsc9dkE=", - "ref": "refs/heads/project-refactor", - "rev": "f66c84a58b49727c2706628773ec041b03a602bb", - "revCount": 28458, - "type": "git", - "url": "https://git.killuaa.dev/Rouffy/Zenium" - }, - "original": { - "type": "git", - "url": "https://git.killuaa.dev/Rouffy/Zenium" + "nixpkgs": "nixpkgs" } } }, diff --git a/server/flake.nix b/server/flake.nix index 8410c23..ceb4817 100644 --- a/server/flake.nix +++ b/server/flake.nix @@ -1,5 +1,5 @@ { - description = "Snow's Server Flake"; + description = "Snow's Server Flake!"; inputs = { nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.05"; @@ -8,12 +8,14 @@ inputs.nixpkgs.follows = "nixpkgs"; }; + # zenium.url = "git+https://git.killuaa.dev/Rouffy/Zenium"; }; outputs = { nixpkgs, home-manager, + # zenium, ... }@inputs: @@ -27,8 +29,11 @@ }; modules = [ - ./configuration.nix + ./system/configuration.nix + # "${nixpkgs}/nixos/modules/profiles/minimal.nix" + # ./lxd-config.nix + # proxmox-nixos.nixosModules.proxmox-ve home-manager.nixosModules.home-manager { @@ -39,6 +44,7 @@ snow = import ./home-manager/snow.nix; }; } + ]; }; }; diff --git a/server/hardware-configuration.nix b/server/hardware-configuration.nix deleted file mode 100644 index 160677c..0000000 --- a/server/hardware-configuration.nix +++ /dev/null @@ -1,37 +0,0 @@ -# Do not modify this file! It was generated by ‘nixos-generate-config’ -# and may be overwritten by future invocations. Please make changes -# to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: - -{ - imports = - [ (modulesPath + "/profiles/qemu-guest.nix") - ]; - - boot.initrd.availableKernelModules = [ "ahci" "xhci_pci" "virtio_pci" "sr_mod" "virtio_blk" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ "kvm-amd" ]; - boot.extraModulePackages = [ ]; - - fileSystems."/" = - { device = "/dev/disk/by-label/nixos"; - fsType = "ext4"; - }; - - fileSystems."/boot" = - { device = "/dev/disk/by-label/boot"; - fsType = "vfat"; - options = [ "fmask=0077" "dmask=0077" ]; - }; - - swapDevices = [ ]; - - # Enables DHCP on each ethernet and wireless interface. In case of scripted networking - # (the default) this is the recommended approach. When using systemd-networkd it's - # still possible to use this option, but it's recommended to use it in conjunction - # with explicit per-interface declarations with `networking.interfaces..useDHCP`. - networking.useDHCP = lib.mkDefault true; - # networking.interfaces.enp1s0.useDHCP = lib.mkDefault true; - - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; -} diff --git a/server/home-manager/apps/fastfetch.nix b/server/home-manager/apps/fastfetch.nix index c3f5236..1fe7558 100644 --- a/server/home-manager/apps/fastfetch.nix +++ b/server/home-manager/apps/fastfetch.nix @@ -4,65 +4,81 @@ enable = true; settings = { "$schema" = "https://github.com/fastfetch-cli/fastfetch/raw/dev/doc/json_schema.json"; - # logo = { - # type = "raw"; - # source = "~/Documents/Misc./images/fastfetch/choppah2.sixel"; - # width = 40; - # height = 19; - # }; display = { separator = " ➜ "; }; + + logo = { + padding = { + top = 0; # Top padding + left = 1; # Left padding + right = 3; # Right padding + }; + }; + modules = [ { type = "title"; - format = "{6}{7}\u001b[33m{2}\u001b[0m"; + format = "{6}{7}{#33}{2}"; } { - type = "custom"; - format = "-====================-"; - outputColor = "separator"; + type = "custom"; + format = "-====================-"; + outputColor = "separator"; } { type = "os"; key = "{#34}  OS"; } + { + type = "host"; + key = "{#34}  Host"; + } { type = "kernel"; key = "{#33}  Kernel"; } { - type = "packages"; - key = "{#35} 󰏗 Packages"; + type = "uptime"; + key = "{#33}  Uptime"; } { - type = "wm"; - key = "{#36} 󰇄 WM"; + type = "packages"; + key = "{#35} 󰏗 Packages"; } { - type = "uptime"; - key = "{#33}  Uptime"; + type = "terminal"; + key = "{#34}  Terminal"; } { type = "shell"; - key = "{#34}  Shell"; + key = "{#34}  Shell"; } "break" { type = "cpu"; key = "{#35}  CPU"; } + { + type = "gpu"; + format = "{2}"; + key = "{#37}  GPU"; + } { type = "memory"; key = "{#39}  Memory"; } + { + type = "swap"; + key = "{#39}  Swap"; + } { type = "disk"; key = "{#37}  Drive"; } "break" - "break" + "colors" ]; }; }; -} \ No newline at end of file +} diff --git a/server/home-manager/apps/fish.nix b/server/home-manager/apps/fish.nix index cc21c5f..df30329 100644 --- a/server/home-manager/apps/fish.nix +++ b/server/home-manager/apps/fish.nix @@ -3,31 +3,37 @@ programs.fish = { enable = true; generateCompletions = true; - functions = { - docker = { - body = '' - if test (count $argv) -eq 1; and test "$argv[1]" = ps - ctop - else - command docker $argv - end - ''; - }; - }; + # functions = { + # docker = { + # body = '' + # if test (count $argv) -eq 1; and test "$argv[1]" = ps + # ctop + # else + # command docker $argv + # end + # ''; + # }; + # }; shellInit = '' set -xg fish_color_command blue ''; shellAliases = { fetch = "clear && fastfetch"; helix = "hx"; - ls = "eza -ihA --icons"; + nano = "$EDITOR"; + ls = "eza -ihg --icons"; cat = "/etc/profiles/per-user/snow/bin/bat"; bat = "/run/current-system/sw/bin/cat"; ctl = "sudo systemctl"; myip = "curl https://ipinfo.io/ip"; - reslave = "sudo nix flake update --flake ~/.config/nixos && nh os switch ~/.config/nixos && sudo nix-collect-garbage -d && nix-collect-garbage -d && sudo nix-env --delete-generations +1"; - rebuild = "nh os switch ~/.config/nixos"; + myip6 = "curl https://v6.ipinfo.io/ip"; docres = "docker compose down && docker compose up -d"; + docvol = "cd ~/.local/share/docker/volumes"; + + logboot = "journalctl --boot=-1 --reverse"; + reslave = "nh os switch ~/Nixos -u && nh clean all"; + rebuild = "nh os switch ~/Nixos"; + rebuildc = "nh os switch ~/Nixos && nh clean all"; }; }; -} +} \ No newline at end of file diff --git a/server/home-manager/snow.nix b/server/home-manager/snow.nix index f2e95e0..c0ec664 100644 --- a/server/home-manager/snow.nix +++ b/server/home-manager/snow.nix @@ -7,14 +7,6 @@ ]; home.username = "snow"; home.homeDirectory = "/home/snow"; - home.file = { - ".local/bin/zed_server/zenium-remote-server" = { - source = "${ - inputs.zenium.packages."${pkgs.system}".zenium-remote-server-bin - }/bin/zenium-remote-server"; - recursive = true; - }; - }; home.packages = with pkgs; [ git @@ -23,14 +15,14 @@ devenv # yazi ctop - inputs.zenium.packages."${system}".zenium-remote-server-bin + # inputs.zenium.packages."${system}".zenium-remote-server-bin ]; services = { - cliphist = { - enable = true; - allowImages = true; - }; + # cliphist = { + # enable = true; + # allowImages = true; + # }; }; programs = { @@ -47,7 +39,7 @@ icons = "always"; }; }; - + home.stateVersion = "25.05"; home.enableNixpkgsReleaseCheck = false; } diff --git a/server/justfile b/server/justfile new file mode 100644 index 0000000..543ec38 --- /dev/null +++ b/server/justfile @@ -0,0 +1,8 @@ +test: + nix flake check + +dry-run: + nixos-rebuild dry-run --flake .#snow-den + +deploy: + nixos-rebuild switch --flake .#snow-den --target-host server --use-remote-sudo \ No newline at end of file diff --git a/server/system/configuration.nix b/server/system/configuration.nix new file mode 100644 index 0000000..6a75d80 --- /dev/null +++ b/server/system/configuration.nix @@ -0,0 +1,266 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page, on +# https://search.nixos.org/options and in the NixOS manual (`nixos-help`). + +{ + # config, + # lib, + pkgs, + ... +}: + +{ + imports = [ + # Include the results of the hardware scan. + ./hardware-configuration.nix + ./lxd-config.nix + # ./ets2-config.nix + ./network.nix + ]; + + # nixpkgs.config.allowUnfree = true; + + zramSwap = { + enable = true; + algorithm = "zstd"; + }; + + swapDevices = [ + { + device = "/swapfile"; + size = 8 * 1024; + } + ]; + + nix = { + settings = { + experimental-features = [ + "nix-command" + "flakes" + ]; + # trusted-user = { + # "@wheel" + # }; + auto-optimise-store = true; + use-xdg-base-directories = true; + }; + gc = { + automatic = true; + dates = "daily"; + }; + }; + + # Use grub so it works on both EFI and BOOT + boot = { + # kernelPackages = pkgs.linuxKernel.packages.linux_hardened; + kernelModules = [ + # "overlay2" + ]; + + kernel.sysctl = { + # Hide kptrs even for processes with CAP_SYSLOG + "kernel.kptr_restrict" = 2; + + # Disable ftrace debugging + "kernel.ftrace_enabled" = false; + + # Disable bpf() JIT (to eliminate spray attacks) + # "net.core.bpf_jit_enable" = false; + + # https://wiki.archlinux.org/title/Sysctl#Enable_TCP_Fast_Open + "net.ipv4.tcp_fastopen" = 3; + + "kernel.unprivileged_userns_clone" = 1; + }; + + loader = { + efi.canTouchEfiVariables = true; + + grub = { + enable = true; + timeoutStyle = "hidden"; + efiSupport = true; + # efiInstallAsRemovable = true; + device = "nodev"; + splashImage = null; + }; + }; + + blacklistedKernelModules = [ + # Obscure network protocols + "ax25" + "netrom" + "rose" + + # Old or rare or insufficiently audited filesystems + "adfs" + "affs" + "bfs" + "befs" + "cramfs" + "efs" + "erofs" + "exofs" + "freevxfs" + "f2fs" + "hfs" + "hpfs" + "jfs" + "minix" + "nilfs2" + "ntfs" + "omfs" + "qnx4" + "qnx6" + "sysv" + "ufs" + ]; + }; + + time.timeZone = "Europe/Berlin"; # Set your time zone. + i18n.defaultLocale = "en_US.UTF-8"; # Select internationalisation properties. + + environment = { + defaultPackages = [ ]; # Disable any default installed packages + + systemPackages = with pkgs; [ + fastfetch + helix + # wget + btop + dysk + ]; + }; + + fonts.fontconfig.enable = false; + + system = { + stateVersion = "25.05"; + tools = { + nixos-version.enable = true; + nixos-rebuild.enable = true; + nixos-option.enable = true; + + nixos-generate-config.enable = false; + nixos-install.enable = false; + nixos-build-vms.enable = false; + }; + }; + + services = { + openssh = { + enable = true; + ports = [ + 335 + ]; + allowSFTP = true; + settings = { + PasswordAuthentication = false; + PermitRootLogin = "no"; + }; + }; + + # endlessh-go = { + # enable = true; + # port = 22; + + # prometheus = { + # enable = true; + # port = 2112; + # listenAddress = "0.0.0.0"; + # }; + # }; + + tailscale.enable = true; + + # prometheus = { + # enable = true; + # }; + }; + + programs = { + nano.enable = false; + fish.enable = true; + nh = { + enable = true; + flake = "/etc/nixos"; + }; + }; + + security = { + # lockKernelModules = true; + protectKernelImage = true; + + auditd.enable = true; + sudo.enable = false; + sudo-rs = { + enable = true; + wheelNeedsPassword = true; + execWheelOnly = true; + # extraConfig = '' + # Defaults passwd_timeout=0 + # ''; + }; + + pam = { + services.sudo.rssh = true; + services.sudo.unixAuth = false; + rssh = { + enable = true; + settings = { + # cue = true; + debug = true; + }; + }; + }; + + wrappers = { + docker-rootlesskit = { + owner = "root"; + group = "root"; + capabilities = "cap_net_bind_service+ep"; + source = "${pkgs.rootlesskit}/bin/rootlesskit"; + }; + }; + }; + + virtualisation = { + docker = { + rootless = { + enable = true; + setSocketVariable = true; + }; + }; + }; + + users = { + groups.radcliffe = { }; + users = { + snow = { + isNormalUser = true; + description = "snow"; + linger = true; + extraGroups = [ + "wheel" + ]; + shell = pkgs.fish; + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL2za6psnuIMZ6FrdUehhyQlqYvy05+wv8dKER+Lctna snowy@Snowflake" + ]; + }; + radcliffe = { + isNormalUser = true; + linger = true; + group = "radcliffe"; + shell = pkgs.fish; + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL2za6psnuIMZ6FrdUehhyQlqYvy05+wv8dKER+Lctna snowy@Snowflake" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGiRKJiC+keGpcnWC9vItrPGqYSq9+bK3pNWc+zgnrMR user@radcliffe" + ]; + }; + root = { + shell = pkgs.fish; + }; + }; + }; +} diff --git a/server/system/hardware-configuration.nix b/server/system/hardware-configuration.nix new file mode 100644 index 0000000..f553fd4 --- /dev/null +++ b/server/system/hardware-configuration.nix @@ -0,0 +1,62 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ + config, + lib, + pkgs, + modulesPath, + ... +}: + +{ + imports = [ + (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ + "ata_piix" + "uhci_hcd" + "virtio_pci" + "sr_mod" + "virtio_blk" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = { + device = "/dev/disk/by-uuid/b435993e-0760-44ba-afa7-ead509b87e62"; + fsType = "ext4"; + }; + + fileSystems."/proc" = { + device = "proc"; + fsType = "proc"; + options = [ + "hidepid=2" + "gid=wheel" + ]; + }; + + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/67AC-7FCE"; + fsType = "vfat"; + options = [ + "fmask=0077" + "dmask=0077" + ]; + }; + + swapDevices = [ ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.ens3.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/server/system/lxd-config.nix b/server/system/lxd-config.nix new file mode 100644 index 0000000..5a7641d --- /dev/null +++ b/server/system/lxd-config.nix @@ -0,0 +1,74 @@ +{ pkgs, ... }: +{ + virtualisation.lxd = { + enable = true; + recommendedSysctlSettings = true; + + ui = { + enable = true; + package = pkgs.lxd-ui; + }; + + preseed = { + config = { + "core.https_address" = ":8443"; + "core.shutdown_timeout" = "3"; + "images.compression_algorithm" = "xz"; + "backups.compression_algorithm" = "xz"; + }; + + networks = [ + { + name = "hestia-bridge"; + description = "Networking bridge for hestia"; + type = "bridge"; + config = { + "ipv4.address" = "10.0.100.1/24"; + # "ipv4.nat" = "true"; + "ipv4.dhcp" = true; + "ipv6.address" = "none"; + }; + } + ]; + + storage_pools = [ + { + name = "hestia-pool"; + description = "Storage pool for hestia"; + driver = "dir"; + config = { + source = "/var/lib/lxd/storage-pools/hestia-pool"; + }; + } + ]; + + storage_volumes = [ + { + name = "hestia-backups"; + # type = "custom"; + content_type = "filesystem"; + pool = "hestia-pool"; + config = { + size = "32GiB"; + }; + } + ]; + + # projects = [ + # { + # name = "hestia-project"; + # # descripion = "Project for hestia"; + # config = { + # "features.images" = true; + # "features.networks" = true; + # "features.networks.zones" = false; + # "features.profiles" = false; + # "features.storage.buckets" = false; + # "features.storage.volumes" = true; + # }; + # } + # ]; + + }; + }; +} diff --git a/server/system/network.nix b/server/system/network.nix new file mode 100644 index 0000000..4276c4a --- /dev/null +++ b/server/system/network.nix @@ -0,0 +1,169 @@ +{ ... }: +{ + networking = { + hostName = "snow-den"; + nameservers = [ + # Cloudflare + "2606:4700:4700::1111" + "1.1.1.1" + "2606:4700:4700::1001" + "1.0.0.1" + + # Mullvad + "2a07:e340::2" + "194.242.2.2" + ]; + + defaultGateway6 = { + address = "fe80::1"; + interface = "ens3"; + }; + + interfaces = { + ens3 = { + ipv6.addresses = [ + { + address = "2a0a:4cc0:0:1eb::c0ff:ee"; + prefixLength = 64; + } + ]; + }; + }; + + # interfaces = { + # ens18 = { + # ipv4 = { + # addresses = [ + # { + # address = "193.24.209.147"; + # prefixLength = 24; + # } + # ]; + # }; + # }; + # }; + + firewall = { + enable = true; + trustedInterfaces = [ + "hestia-bridge" + ]; + + extraCommands = '' + iptables -t nat -A POSTROUTING -s 10.0.100.0/24 ! -d 10.0.100.0/24 -j MASQUERADE + ''; + + allowedTCPPorts = [ + # HTTP + 80 + 443 + + # ssh + 22 + 335 + 665 + + # LXD + 8443 + + # email + ## IMAP + 143 + 993 + ## POP3 + 110 + 995 + ## SMTP + 25 + 465 + 587 + + # mumble + 64738 + + # broadcast-box + 9070 + + # Satisfactory + 7777 + 8888 + + # Steam + 27015 + 27016 + ]; + allowedUDPPorts = [ + # HTTP + 80 + 443 + + # mumble + 64738 + + # broadcast-box + 9070 + + # Satisfactory + 7777 + + # Steam + 27015 + 27016 + ]; + }; + + nat = { + enable = true; + # internalInterfaces = [ "hestia-bridge" ]; + externalInterface = "ens3"; + # externalInterface = "wg0"; + forwardPorts = [ + # SSH + { + sourcePort = 665; + proto = "tcp"; + destination = "10.0.100.126:22"; + } + + # IMAP + { + sourcePort = 143; + proto = "tcp"; + destination = "10.0.100.126:143"; + } + { + sourcePort = 993; + proto = "tcp"; + destination = "10.0.100.126:993"; + } + # POP3 + { + sourcePort = 110; + proto = "tcp"; + destination = "10.0.100.126:110"; + } + { + sourcePort = 995; + proto = "tcp"; + destination = "10.0.100.126:995"; + } + # SMTP + { + sourcePort = 25; + proto = "tcp"; + destination = "10.0.100.126:25"; + } + { + sourcePort = 465; + proto = "tcp"; + destination = "10.0.100.126:465"; + } + { + sourcePort = 587; + proto = "tcp"; + destination = "10.0.100.126:587"; + } + ]; + }; + }; +}