From c4c3e0051fa1bd2a97d52c771d515a57499bd85c Mon Sep 17 00:00:00 2001 From: MrSnowy Date: Sun, 09 Nov 2025 20:13:41 +0000 Subject: [PATCH] Init home-labbing stuff, some other changes --- desktop/home-manager/snowy/hypr/hyprland.conf | 0 .gitignore | 5 +++++ desktop/flake.lock | 304 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++------------------------------------------------------------------------------------------------------------ desktop/flake.nix | 17 ++++++++++++----- desktop/home-manager/snowy.nix | 127 ++++++++++++++++++++++++++++++++++++++++++++++++++++--------------------------------------------------------------------------- desktop/home-manager/snowy/mpv/mpv.conf | 16 ++++++++++++++++ desktop/home-manager/snowy/stow.sh | 1 + desktop/repos.nix | 7 ++++++- desktop/system/audio.nix | 68 ++++++++++++++++++++++++++++++++++---------------------------------- desktop/system/configuration.nix | 20 ++++++++++---------- desktop/system/networking.nix | 11 +++++++++-- home-server/flake.lock | 49 +++++++++++++++++++++++++++++++++++++++++++++++++ home-server/flake.nix | 48 ++++++++++++++++++++++++++++++++++++++++++++++++ home-server/home-manager/apps/fish.nix | 33 +++++++++++++++++++++++++++++++++ home-server/home-manager/user.nix | 24 ++++++++++++++++++++++++ home-server/justfile | 2 ++ home-server/result | 1 + home-server/system/configuration.nix | 213 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ home-server/system/hardware-configuration.nix | 58 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ home-server/system/network.nix | 71 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ home-server/system/services.nix | 24 ++++++++++++++++++++++++ server/containers/caddy.nix | 59 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ server/flake.nix | 6 ------ server/home-manager/apps/fish.nix | 24 ++++-------------------- server/home-manager/apps/helix.nix | 14 +++++++------- server/home-manager/snow.nix | 39 +++++++++++++++++++++------------------ server/justfile | 5 ++++- server/result | 1 + server/services/main.nix | 11 +++++++++++ server/system/configuration.nix | 21 ++++++++++++++++----- server/system/hardware-configuration.nix | 6 +++++- server/services/incus.nix | 22 ++++++++++++---------- server/system/network.nix | 42 +++++++++++++++++++++++++++--------------- 33 file(s) changed, 1031 insertion(s)(+), 318 deletion(s)(-) diff --git a/.config/hypr/hyprland.conf b/desktop/home-manager/snowy/hypr/hyprland.conf rename from .config/hypr/hyprland.conf rename to desktop/home-manager/snowy/hypr/hyprland.conf --- a/.config/hypr/hyprland.conf +++ b/desktop/home-manager/snowy/hypr/hyprland.conf diff --git a/.gitignore b/.gitignore new file mode 100644 --- /dev/null +++ b/.gitignore @@ -0,0 +1,5 @@ +result/ + +# For nixos-vms +*.qcow2 +*.fd diff --git a/desktop/flake.lock b/desktop/flake.lock --- a/desktop/flake.lock +++ b/desktop/flake.lock @@ -20,11 +20,11 @@ "systems" ] }, "locked": { - "lastModified": 1755946532, - "narHash": "sha256-POePremlUY5GyA1zfbtic6XLxDaQcqHN6l+bIxdT5gc=", + "lastModified": 1762356719, + "narHash": "sha256-qwd/xdoOya1m8FENle+4hWnydCtlXUWLAW/Auk6WL7s=", "owner": "hyprwm", "repo": "aquamarine", - "rev": "81584dae2df6ac79f6b6dae0ecb7705e95129ada", + "rev": "6d0b3567584691bf9d8fedb5d0093309e2f979c7", "type": "github" }, "original": { @@ -42,11 +42,11 @@ "nixpkgs": "nixpkgs", "rust-overlay": "rust-overlay" }, "locked": { - "lastModified": 1759348172, - "narHash": "sha256-ZPUJX2ZA0ndcHndIA/S/nRESIJV0rifPr91SUpzJtEM=", + "lastModified": 1762525922, + "narHash": "sha256-DX0/D0o/lUQRMCuoAoJiXkDqoISLSgkQAlsPqPS4i6M=", "owner": "chaotic-cx", "repo": "nyx", - "rev": "dd1af56ad79c965ee20c236ba6adbb2135ac02af", + "rev": "863eed9a7967cb307ecdcdba0c7b87db6a314865", "type": "github" }, "original": { @@ -134,11 +134,11 @@ "nixpkgs" ] }, "locked": { - "lastModified": 1759261733, - "narHash": "sha256-G104PUPKBgJmcu4NWs0LUaPpSOTD4jiq4mamLWu3Oc0=", + "lastModified": 1762463325, + "narHash": "sha256-33YUsWpPyeBZEWrKQ2a1gkRZ7i0XCC/2MYpU6BVeQSU=", "owner": "nix-community", "repo": "home-manager", - "rev": "5a21f4819ee1be645f46d6b255d49f4271ef6723", + "rev": "0562fef070a1027325dd4ea10813d64d2c967b39", "type": "github" }, "original": { @@ -154,11 +154,11 @@ "nixpkgs-unstable" ] }, "locked": { - "lastModified": 1759337100, - "narHash": "sha256-CcT3QvZ74NGfM+lSOILcCEeU+SnqXRvl1XCRHenZ0Us=", + "lastModified": 1762704774, + "narHash": "sha256-iodz4xQbULkHqetbPu5BCSWsVEzZiiNSv0/dzfH4XiE=", "owner": "nix-community", "repo": "home-manager", - "rev": "004753ae6b04c4b18aa07192c1106800aaacf6c3", + "rev": "be4a9233dd3f6104c9b0fdd3d56f953eb519a4c7", "type": "github" }, "original": { @@ -176,11 +176,11 @@ "nixpkgs" ] }, "locked": { - "lastModified": 1752603129, - "narHash": "sha256-S+wmHhwNQ5Ru689L2Gu8n1OD6s9eU9n9mD827JNR+kw=", + "lastModified": 1762351818, + "narHash": "sha256-0ptUDbYwxv1kk/uzEX4+NJjY2e16MaAhtzAOJ6K0TG0=", "owner": "nix-community", "repo": "home-manager", - "rev": "e8c19a3cec2814c754f031ab3ae7316b64da085b", + "rev": "b959c67241cae17fc9e4ee7eaf13dfa8512477ea", "type": "github" }, "original": { @@ -234,11 +234,11 @@ "systems" ] }, "locked": { - "lastModified": 1758192433, - "narHash": "sha256-CR6RnqEJSTiFgA6KQY4TTLUWbZ8RBnb+hxQqesuQNzQ=", + "lastModified": 1762462052, + "narHash": "sha256-6roLYzcDf4V38RUMSqycsOwAnqfodL6BmhRkUtwIgdA=", "owner": "hyprwm", "repo": "hyprgraphics", - "rev": "c44e749dd611521dee940d00f7c444ee0ae4cfb7", + "rev": "ffc999d980c7b3bca85d3ebd0a9fbadf984a8162", "type": "github" }, "original": { @@ -252,22 +252,22 @@ "inputs": { "aquamarine": "aquamarine", "hyprcursor": "hyprcursor", "hyprgraphics": "hyprgraphics", + "hyprland-guiutils": "hyprland-guiutils", "hyprland-protocols": "hyprland-protocols", - "hyprland-qtutils": "hyprland-qtutils", "hyprlang": "hyprlang", "hyprutils": "hyprutils", - "hyprwayland-scanner": "hyprwayland-scanner", + "hyprwayland-scanner": "hyprwayland-scanner_2", "nixpkgs": "nixpkgs_2", "pre-commit-hooks": "pre-commit-hooks", "systems": "systems", "xdph": "xdph" }, "locked": { - "lastModified": 1759399554, - "narHash": "sha256-FsFugHj7He5siEcmoRUdMKHB8uMzyneK/fynPS57W4E=", + "lastModified": 1762703954, + "narHash": "sha256-tBNyAKujRoltMh3lsCnEiYza7YC+kK6pcwsCp33QpV4=", "owner": "hyprwm", "repo": "Hyprland", - "rev": "3bcfa94ee4189faaa4daf661949e88cf28c00d94", + "rev": "0bd11d5eb941b8038f0723135768d84aa5512b4a", "type": "github" }, "original": { @@ -276,6 +276,48 @@ "repo": "Hyprland", "type": "github" } }, + "hyprland-guiutils": { + "inputs": { + "aquamarine": [ + "hyprland", + "aquamarine" + ], + "hyprgraphics": [ + "hyprland", + "hyprgraphics" + ], + "hyprlang": [ + "hyprland", + "hyprlang" + ], + "hyprtoolkit": "hyprtoolkit", + "hyprutils": [ + "hyprland", + "hyprutils" + ], + "nixpkgs": [ + "hyprland", + "nixpkgs" + ], + "systems": [ + "hyprland", + "systems" + ] + }, + "locked": { + "lastModified": 1762465111, + "narHash": "sha256-dS13YZdWjgGGLBjpT4FHB6xf8I/WiAU+mgNWXsZgDUs=", + "owner": "hyprwm", + "repo": "hyprland-guiutils", + "rev": "a415eba866a953f3096d661318f771aa0082eb98", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "hyprland-guiutils", + "type": "github" + } + }, "hyprland-protocols": { "inputs": { "nixpkgs": [ @@ -288,11 +330,11 @@ "systems" ] }, "locked": { - "lastModified": 1749046714, - "narHash": "sha256-kymV5FMnddYGI+UjwIw8ceDjdeg7ToDVjbHCvUlhn14=", + "lastModified": 1759610243, + "narHash": "sha256-+KEVnKBe8wz+a6dTLq8YDcF3UrhQElwsYJaVaHXJtoI=", "owner": "hyprwm", "repo": "hyprland-protocols", - "rev": "613878cb6f459c5e323aaafe1e6f388ac8a36330", + "rev": "bd153e76f751f150a09328dbdeb5e4fab9d23622", "type": "github" }, "original": { @@ -301,80 +343,85 @@ "repo": "hyprland-protocols", "type": "github" } }, - "hyprland-qt-support": { + "hyprlang": { "inputs": { - "hyprlang": [ + "hyprutils": [ "hyprland", - "hyprland-qtutils", - "hyprlang" + "hyprutils" ], "nixpkgs": [ "hyprland", - "hyprland-qtutils", "nixpkgs" ], "systems": [ "hyprland", - "hyprland-qtutils", "systems" ] }, "locked": { - "lastModified": 1749154592, - "narHash": "sha256-DO7z5CeT/ddSGDEnK9mAXm1qlGL47L3VAHLlLXoCjhE=", + "lastModified": 1758927902, + "narHash": "sha256-LZgMds7M94+vuMql2bERQ6LiFFdhgsEFezE4Vn+Ys3A=", "owner": "hyprwm", - "repo": "hyprland-qt-support", - "rev": "4c8053c3c888138a30c3a6c45c2e45f5484f2074", + "repo": "hyprlang", + "rev": "4dafa28d4f79877d67a7d1a654cddccf8ebf15da", "type": "github" }, "original": { "owner": "hyprwm", - "repo": "hyprland-qt-support", + "repo": "hyprlang", "type": "github" } }, - "hyprland-qtutils": { + "hyprtoolkit": { "inputs": { - "hyprland-qt-support": "hyprland-qt-support", + "aquamarine": [ + "hyprland", + "hyprland-guiutils", + "aquamarine" + ], + "hyprgraphics": [ + "hyprland", + "hyprland-guiutils", + "hyprgraphics" + ], "hyprlang": [ "hyprland", + "hyprland-guiutils", "hyprlang" ], "hyprutils": [ "hyprland", - "hyprland-qtutils", - "hyprlang", + "hyprland-guiutils", "hyprutils" ], + "hyprwayland-scanner": "hyprwayland-scanner", "nixpkgs": [ "hyprland", + "hyprland-guiutils", "nixpkgs" ], "systems": [ "hyprland", + "hyprland-guiutils", "systems" ] }, "locked": { - "lastModified": 1757694755, - "narHash": "sha256-j+w5QUUr2QT/jkxgVKecGYV8J7fpzXCMgzEEr6LG9ug=", + "lastModified": 1762463729, + "narHash": "sha256-2fYkU/mdz8WKY3dkDPlE/j6hTxIwqultsx4gMMsMns0=", "owner": "hyprwm", - "repo": "hyprland-qtutils", - "rev": "5ffdfc13ed03df1dae5084468d935f0a3f2c9a4c", + "repo": "hyprtoolkit", + "rev": "88483bdee5329ec985f0c8f834c519cd18cfe532", "type": "github" }, "original": { "owner": "hyprwm", - "repo": "hyprland-qtutils", + "repo": "hyprtoolkit", "type": "github" } }, - "hyprlang": { + "hyprutils": { "inputs": { - "hyprutils": [ - "hyprland", - "hyprutils" - ], "nixpkgs": [ "hyprland", "nixpkgs" @@ -385,45 +432,49 @@ "systems" ] }, "locked": { - "lastModified": 1756810301, - "narHash": "sha256-wgZ3VW4VVtjK5dr0EiK9zKdJ/SOqGIBXVG85C3LVxQA=", + "lastModified": 1762387740, + "narHash": "sha256-gQ9zJ+pUI4o+Gh4Z6jhJll7jjCSwi8ZqJIhCE2oqwhQ=", "owner": "hyprwm", - "repo": "hyprlang", - "rev": "3d63fb4a42c819f198deabd18c0c2c1ded1de931", + "repo": "hyprutils", + "rev": "926689ddb9c0a8787e58c02c765a62e32d63d1f7", "type": "github" }, "original": { "owner": "hyprwm", - "repo": "hyprlang", + "repo": "hyprutils", "type": "github" } }, - "hyprutils": { + "hyprwayland-scanner": { "inputs": { "nixpkgs": [ "hyprland", + "hyprland-guiutils", + "hyprtoolkit", "nixpkgs" ], "systems": [ "hyprland", + "hyprland-guiutils", + "hyprtoolkit", "systems" ] }, "locked": { - "lastModified": 1756117388, - "narHash": "sha256-oRDel6pNl/T2tI+nc/USU9ZP9w08dxtl7hiZxa0C/Wc=", + "lastModified": 1755184602, + "narHash": "sha256-RCBQN8xuADB0LEgaKbfRqwm6CdyopE1xIEhNc67FAbw=", "owner": "hyprwm", - "repo": "hyprutils", - "rev": "b2ae3204845f5f2f79b4703b441252d8ad2ecfd0", + "repo": "hyprwayland-scanner", + "rev": "b3b0f1f40ae09d4447c20608e5a4faf8bf3c492d", "type": "github" }, "original": { "owner": "hyprwm", - "repo": "hyprutils", + "repo": "hyprwayland-scanner", "type": "github" } }, - "hyprwayland-scanner": { + "hyprwayland-scanner_2": { "inputs": { "nixpkgs": [ "hyprland", @@ -457,11 +508,11 @@ "nixpkgs" ] }, "locked": { - "lastModified": 1759217228, - "narHash": "sha256-P13ExJlhMVkrc5LxZLNkIJZhjNYo3LLXnxDsUNrdnMQ=", + "lastModified": 1762452596, + "narHash": "sha256-Iaga+mkwWnWa6FxsAYknpHzeP344VCKGkdudX420LgA=", "owner": "Jovian-Experiments", "repo": "Jovian-NixOS", - "rev": "e52c15ab25f7dc68dde527c8df5bfa9d80d8e64f", + "rev": "99919fd35e70c1b18ce948d5329928d751031312", "type": "github" }, "original": { @@ -521,11 +572,11 @@ "nixpkgs-unstable" ] }, "locked": { - "lastModified": 1759032422, - "narHash": "sha256-WZf+FhebP2/1pK2np5xj/NuDjD6fXK2BHnq/tPUN18o=", + "lastModified": 1762660502, + "narHash": "sha256-C9F1C31ys0V7mnp4EcDy7L1cLZw/sCTEXqqTtGnvu08=", "owner": "nix-community", "repo": "nix-index-database", - "rev": "ec7a78cb0e098832d8acac091a4df393259c4839", + "rev": "15c5451c63f4c612874a43846bfe3fa828b03eee", "type": "github" }, "original": { @@ -536,11 +587,11 @@ } }, "nixpkgs": { "locked": { - "lastModified": 1759147044, - "narHash": "sha256-3ZPFytJOcLjTChljeaGgoaNj+tOqzgEpqZAvRe3bU90=", - "owner": "PedroHLC", + "lastModified": 1762363567, + "narHash": "sha256-YRqMDEtSMbitIMj+JLpheSz0pwEr0Rmy5mC7myl17xs=", + "owner": "NixOS", "repo": "nixpkgs", - "rev": "18e83bbe13aa50992777832b52bd0e0d8585fb3b", + "rev": "ae814fd3904b621d8ab97418f1d0f2eb0d3716f4", "type": "github" }, "original": { @@ -552,11 +603,11 @@ } }, "nixpkgs-extra-unstable": { "locked": { - "lastModified": 1759386674, - "narHash": "sha256-wg1Lz/1FC5Q13R+mM5a2oTV9TA9L/CHHTm3/PiLayfA=", + "lastModified": 1762482733, + "narHash": "sha256-g/da4FzvckvbiZT075Sb1/YDNDr+tGQgh4N8i5ceYMg=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "625ad6366178f03acd79f9e3822606dd7985b657", + "rev": "e1ebeec86b771e9d387dd02d82ffdc77ac753abc", "type": "github" }, "original": { @@ -583,11 +634,11 @@ } }, "nixpkgs-stable": { "locked": { - "lastModified": 1759281824, - "narHash": "sha256-FIBE1qXv9TKvSNwst6FumyHwCRH3BlWDpfsnqRDCll0=", + "lastModified": 1762498405, + "narHash": "sha256-Zg/SCgCaAioc0/SVZQJxuECGPJy+OAeBcGeA5okdYDc=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "5b5be50345d4113d04ba58c444348849f5585b4a", + "rev": "6faeb062ee4cf4f105989d490831713cc5a43ee1", "type": "github" }, "original": { @@ -599,11 +650,11 @@ } }, "nixpkgs-unstable": { "locked": { - "lastModified": 1759036355, - "narHash": "sha256-0m27AKv6ka+q270dw48KflE0LwQYrO7Fm4/2//KCVWg=", + "lastModified": 1762596750, + "narHash": "sha256-rXXuz51Bq7DHBlfIjN7jO8Bu3du5TV+3DSADBX7/9YQ=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "e9f00bd893984bc8ce46c895c3bf7cac95331127", + "rev": "b6a8526db03f735b89dd5ff348f53f752e7ddc8e", "type": "github" }, "original": { @@ -615,11 +666,11 @@ } }, "nixpkgs_2": { "locked": { - "lastModified": 1758198701, - "narHash": "sha256-7To75JlpekfUmdkUZewnT6MoBANS0XVypW6kjUOXQwc=", + "lastModified": 1762363567, + "narHash": "sha256-YRqMDEtSMbitIMj+JLpheSz0pwEr0Rmy5mC7myl17xs=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "0147c2f1d54b30b5dd6d4a8c8542e8d7edf93b5d", + "rev": "ae814fd3904b621d8ab97418f1d0f2eb0d3716f4", "type": "github" }, "original": { @@ -631,31 +682,31 @@ } }, "nixpkgs_3": { "locked": { - "lastModified": 1756731054, - "narHash": "sha256-kifUBw3WDopsgxUq0X9hFb2MMDeqhREbF1YttEj6IpM=", - "owner": "nixos", + "lastModified": 1762363567, + "narHash": "sha256-YRqMDEtSMbitIMj+JLpheSz0pwEr0Rmy5mC7myl17xs=", + "owner": "NixOS", "repo": "nixpkgs", - "rev": "d042fb41a92f948e2f42038b0b9641bd501d08ce", + "rev": "ae814fd3904b621d8ab97418f1d0f2eb0d3716f4", "type": "github" }, "original": { - "owner": "nixos", + "owner": "NixOS", + "ref": "nixos-unstable", "repo": "nixpkgs", "type": "github" } }, "nixpkgs_4": { "locked": { - "lastModified": 1755615617, - "narHash": "sha256-HMwfAJBdrr8wXAkbGhtcby1zGFvs+StOp19xNsbqdOg=", + "lastModified": 1756731054, + "narHash": "sha256-kifUBw3WDopsgxUq0X9hFb2MMDeqhREbF1YttEj6IpM=", "owner": "nixos", "repo": "nixpkgs", - "rev": "20075955deac2583bb12f07151c2df830ef346b4", + "rev": "d042fb41a92f948e2f42038b0b9641bd501d08ce", "type": "github" }, "original": { "owner": "nixos", - "ref": "nixos-unstable", "repo": "nixpkgs", "type": "github" } @@ -670,11 +721,11 @@ "nixpkgs" ] }, "locked": { - "lastModified": 1758108966, - "narHash": "sha256-ytw7ROXaWZ7OfwHrQ9xvjpUWeGVm86pwnEd1QhzawIo=", + "lastModified": 1762441963, + "narHash": "sha256-j+rNQ119ffYUkYt2YYS6rnd6Jh/crMZmbqpkGLXaEt0=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "54df955a695a84cd47d4a43e08e1feaf90b1fd9b", + "rev": "8e7576e79b88c16d7ee3bbd112c8d90070832885", "type": "github" }, "original": { @@ -693,6 +744,7 @@ "nix-index": "nix-index", "nixpkgs-extra-unstable": "nixpkgs-extra-unstable", "nixpkgs-stable": "nixpkgs-stable", "nixpkgs-unstable": "nixpkgs-unstable", + "spicetify-nix": "spicetify-nix", "zed-editor": "zed-editor", "zen-browser": "zen-browser" } @@ -705,11 +757,11 @@ "nixpkgs" ] }, "locked": { - "lastModified": 1759286284, - "narHash": "sha256-JLdGGc4XDutzSD1L65Ni6Ye+oTm8kWfm0KTPMcyl7Y4=", + "lastModified": 1762483116, + "narHash": "sha256-Z8EVsTH10BjCdFyPxbUu5jBV+HGL39rh9+beQcnNRm0=", "owner": "oxalica", "repo": "rust-overlay", - "rev": "f6f2da475176bb7cff51faae8b3fe879cd393545", + "rev": "9de55b59b6aaadbd9dbf223765a835239b767ee5", "type": "github" }, "original": { @@ -718,6 +770,25 @@ "repo": "rust-overlay", "type": "github" } }, + "spicetify-nix": { + "inputs": { + "nixpkgs": "nixpkgs_3", + "systems": "systems_2" + }, + "locked": { + "lastModified": 1762705543, + "narHash": "sha256-yoJBNxZySJduVdzfy8zxlfx5OL2CvBOYtuQsYsbD/qw=", + "owner": "Gerg-L", + "repo": "spicetify-nix", + "rev": "954fd25c1dc799f732a23da844befe71f03a5ff0", + "type": "github" + }, + "original": { + "owner": "Gerg-L", + "repo": "spicetify-nix", + "type": "github" + } + }, "systems": { "locked": { "lastModified": 1689347949, @@ -733,6 +804,21 @@ "repo": "default-linux", "type": "github" } }, + "systems_2": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, "xdph": { "inputs": { "hyprland-protocols": [ @@ -761,11 +847,11 @@ "systems" ] }, "locked": { - "lastModified": 1755354946, - "narHash": "sha256-zdov5f/GcoLQc9qYIS1dUTqtJMeDqmBmo59PAxze6e4=", + "lastModified": 1761431178, + "narHash": "sha256-xzjC1CV3+wpUQKNF+GnadnkeGUCJX+vgaWIZsnz9tzI=", "owner": "hyprwm", "repo": "xdg-desktop-portal-hyprland", - "rev": "a10726d6a8d0ef1a0c645378f983b6278c42eaa0", + "rev": "4b8801228ff958d028f588f0c2b911dbf32297f9", "type": "github" }, "original": { @@ -777,7 +863,7 @@ }, "zed-editor": { "inputs": { "flake-parts": "flake-parts", - "nixpkgs": "nixpkgs_3" + "nixpkgs": "nixpkgs_4" }, "locked": { "lastModified": 1756797624, @@ -796,14 +882,16 @@ }, "zen-browser": { "inputs": { "home-manager": "home-manager_3", - "nixpkgs": "nixpkgs_4" + "nixpkgs": [ + "nixpkgs-unstable" + ] }, "locked": { - "lastModified": 1759378939, - "narHash": "sha256-MWCIUqkxoMnvNYjooFiFHzlcZDBOp4DTXERe8xdEWoU=", + "lastModified": 1762665515, + "narHash": "sha256-0+A0nHL1+x1H4NL5bE6GyA252JOpUK6kvfHg/g75260=", "owner": "0xc000022070", "repo": "zen-browser-flake", - "rev": "3ac78827a82614c394e6f8fcc84c5cea9c3847f4", + "rev": "1bea5e777dd0b99158c504da1fb2913ff119e96c", "type": "github" }, "original": { diff --git a/desktop/flake.nix b/desktop/flake.nix --- a/desktop/flake.nix +++ b/desktop/flake.nix @@ -11,7 +11,12 @@ url = "github:nix-community/home-manager/master"; inputs.nixpkgs.follows = "nixpkgs-unstable"; }; - zen-browser.url = "github:0xc000022070/zen-browser-flake"; + zen-browser = { + url = "github:0xc000022070/zen-browser-flake"; + # IMPORTANT: we're using "libgbm" and is only available in unstable so ensure + # to have it up-to-date or simply don't specify the nixpkgs input + inputs.nixpkgs.follows = "nixpkgs-unstable"; + }; hyprland.url = "github:hyprwm/Hyprland"; @@ -28,6 +33,8 @@ nix-index = { url = "github:nix-community/nix-index-database"; inputs.nixpkgs.follows = "nixpkgs-unstable"; }; + + spicetify-nix.url = "github:Gerg-L/spicetify-nix"; # modrinth-fix.url = "github:getchoo-contrib/nixpkgs/pkgs/modrinth-app/0.10.3"; }; @@ -40,10 +47,10 @@ { nixosConfigurations = { Snowflake = - let - system = "x86_64-linux"; - repos = import ./repos.nix { inherit inputs system; }; - in + let + system = "x86_64-linux"; + repos = import ./repos.nix { inherit inputs system; }; + in # Set the default pkgs the system follows repos.pkgs-system { inherit system; diff --git a/desktop/home-manager/snowy.nix b/desktop/home-manager/snowy.nix --- a/desktop/home-manager/snowy.nix +++ b/desktop/home-manager/snowy.nix @@ -3,43 +3,63 @@ inputs, pkgs, config, repos, - # pkgs-modrinth-fix, ... }: { imports = [ inputs.nix-index.homeModules.nix-index - inputs.zen-browser.homeModules.beta + # inputs.zen-browser.homeModules.beta + # inputs.spicetify-nix.homeManagerModules.spicetify ]; + # home.file = { + # ".config/hypr/hyprland.conf" = { + # source = config.lib.file.mkOutOfStoreSymlink "./snowy/hypr/hyprland.conf"; + # }; + # ".config/mpv/mpv.conf" = { + # source = config.lib.file.mkOutOfStoreSymlink "./snowy/mpv/mpv.conf"; + # }; + # }; + home.packages = with pkgs; [ - # inputs.zen-browser.packages."${system}".twilight - corretto17 - android-studio - forgejo-actions-runner - ctop + inputs.zen-browser.packages."${system}".twilight inputs.zed-editor.packages."${pkgs.system}".zed-editor-bin + # corretto17 + # android-studio + # forgejo-actions-runner + ctop # pkgs-modrinth-fix.modrinth-app # zed stuffz ente-desktop - bash-language-server - hyprls + vscode + helix + mpv + # shellcheck # for zed basher? # vscodium jetbrains.idea-ultimate jetbrains.rider orca-slicer - godot + # godot unityhub + # simplex-chat-desktop + + #language servers + bash-language-server + hyprls + kdePackages.qtdeclarative + kdePackages.qtutilities + python313Packages.python-lsp-server fzf # for fish - hextazy + chafa + # hextazy repos.pkgs-extra-unstable.grayjay # gaphor - d-spy - bustle + # d-spyd + # bustle rustup gcc @@ -50,6 +70,7 @@ # silly game clonehero # silly + papers loupe gnome-clocks helvum @@ -62,11 +83,13 @@ obsidian element-desktop radio-cli # rust heroic - hydralauncher + # hydralauncher wineWowPackages.staging + easyeffects monocraft + python3 # wine64 # nixpkgs-extra-unstable.hyprlandPlugins.hyprsplit ]; @@ -77,17 +100,22 @@ POLKIT_GNOME = "${pkgs.polkit_gnome}/libexec/polkit-gnome-authentication-agent-1"; # LIB_HYPRSPLIT = "${nixpkgs-extra-unstable.hyprlandPlugins.hyprsplit}/lib/libhyprsplit.so"; }; - programs = { - - helix = { - defaultEditor = true; - }; - - vscode = { - enable = true; - package = pkgs.vscode; - }; + # programs.spicetify = + # let + # spicePkgs = inputs.spicetify-nix.legacyPackages.${pkgs.stdenv.system}; + # in + # { + # enable = true; + # enabledExtensions = with spicePkgs.extensions; [ + # adblockify + # # hidePodcasts + # # shuffle # shuffle+ (special characters are sanitized out of extension names) + # ]; + # theme = spicePkgs.themes.catppuccin; + # colorScheme = "mocha"; + # }; + programs = { nix-your-shell = { enable = true; enableFishIntegration = true; @@ -102,62 +130,11 @@ obs-studio-plugins.obs-text-pthread ]; }; - zen-browser = { - enable = true; - }; - - # zed-editor = { - # enable = true; - # }; - direnv = { enable = true; silent = true; nix-direnv.enable = true; }; - - mpv = { - enable = true; - config = { - sub-font = "Arial Regular"; - sub-border-size = 10; - sub-font-size = 52; - sub-pos = 102; - sub-color = "#ffffff"; - sub-ass-override = "force"; - profile = "high-quality"; - # gpu-api = "vulkan"; - gpu-api = "opengl"; - vo = "gpu-next"; - hwdec = "auto-copy"; - vaapi-device = "/dev/dri/renderD128"; - demuxer-max-bytes = "5120MiB"; - }; - }; - }; - - # services = { - # # ollama = { - # # enable = true; - # # acceleration = "rocm"; - # # }; - # }; - - wayland.windowManager.hyprland = { - enable = true; - - plugins = [ - # inputs.nixpkgs-extra-unstable.hyprlandPlugins.hyprsplit - ]; - - settings = { - exec-once = [ - "${pkgs.polkit_gnome}/libexec/polkit-gnome-authentication-agent-1" - ]; - }; - - # Make it base it on my hyprland config, I dont like managing configs trough home manager tbh. - extraConfig = builtins.readFile ../../.config/hypr/hyprland.conf; }; dconf.settings = { diff --git a/desktop/home-manager/snowy/mpv/mpv.conf b/desktop/home-manager/snowy/mpv/mpv.conf new file mode 100644 --- /dev/null +++ b/desktop/home-manager/snowy/mpv/mpv.conf @@ -0,0 +1,16 @@ +#sub-font='JetBrainsMono NF ExtraBold' +sub-font='Arial Regular' + +sub-border-size=10 +sub-font-size=52 + +sub-pos=102 +sub-color='#ffffff' + +sub-ass-override=force + +#sub-shadow=3 +#sub-shadow-color='#000000' +#sub-shadow-offset=3 + + diff --git a/desktop/home-manager/snowy/stow.sh b/desktop/home-manager/snowy/stow.sh --- a/desktop/home-manager/snowy/stow.sh +++ b/desktop/home-manager/snowy/stow.sh @@ -2,3 +2,4 @@ #!/usr/bin/env nix-shell #!nix-shell -i bash -p stow stow silly +ni \ No newline at end of file diff --git a/desktop/repos.nix b/desktop/repos.nix --- a/desktop/repos.nix +++ b/desktop/repos.nix @@ -39,5 +39,10 @@ # }; in { - inherit pkgs-extra-unstable pks-unstable pkgs-stable pkgs-system; + inherit + pkgs-extra-unstable + pks-unstable + pkgs-stable + pkgs-system + ; } diff --git a/desktop/system/audio.nix b/desktop/system/audio.nix --- a/desktop/system/audio.nix +++ b/desktop/system/audio.nix @@ -5,8 +5,8 @@ pkgs, ... }: { - # # In order to save the sound card state on shutdown - # hardware.alsa.enablePersistence = true; + # In order to save the sound card state on shutdown + hardware.alsa.enablePersistence = true; services = { pipewire = { @@ -18,39 +18,39 @@ jack.enable = true; wireplumber = { enable = true; - extraConfig = { - "arctis-nova" = { - "monitor.alsa.rules" = [ - # { - # matches = [ - # { - # "device.name" = "alsa_card.usb-SteelSeries_Arctis_Nova_7-00"; - # } - # ]; - # actions = { - # update-props = { - # # "device.description" = "Puppy Headphones"; + # extraConfig = { + # "arctis-nova" = { + # "monitor.alsa.rules" = [ + # # { + # # matches = [ + # # { + # # "device.name" = "alsa_card.usb-SteelSeries_Arctis_Nova_7-00"; + # # } + # # ]; + # # actions = { + # # update-props = { + # # # "device.description" = "Puppy Headphones"; - # }; - # }; - # } - { - matches = [ - { - "device.name" = "alsa_card.pci-0000_0f_00.4"; - } - ]; - actions = { - update-props = { - "device.description" = "Speakers"; - "audio.channels" = 6; - "audio.position" = "FL,FR,FC,LFE,RL,RR"; - }; - }; - } - ]; - }; - }; + # # }; + # # }; + # # } + # { + # matches = [ + # { + # "device.name" = "alsa_card.pci-0000_0f_00.4"; + # } + # ]; + # actions = { + # update-props = { + # "device.description" = "Speakers"; + # "audio.channels" = 6; + # "audio.position" = "FL,FR,FC,LFE,RL,RR"; + # }; + # }; + # } + # ]; + # }; + # }; }; }; }; diff --git a/desktop/system/configuration.nix b/desktop/system/configuration.nix --- a/desktop/system/configuration.nix +++ b/desktop/system/configuration.nix @@ -7,6 +7,7 @@ config, lib, pkgs, pkgs-unstable, + inputs, ... }: @@ -95,9 +96,11 @@ libvirtd = { enable = true; qemu = { swtpm.enable = true; - ovmf.packages = [ - pkgs.OVMFFull.fd - ]; + # ovmf.packages = [ + # pkgs.OVMFFull.fd + # ]; + # + vhostUserPackages = with pkgs; [ virtiofsd ]; }; }; @@ -466,7 +469,9 @@ jq openssh dosfstools btrfs-progs - corretto21 + # corretto21 + jdk + jdk17 gst_all_1.gstreamer gst_all_1.gst-plugins-base @@ -560,14 +565,9 @@ vesktop r2modman #libsForQt5.xp-pen-g430-drive libsForQt5.xp-pen-deco-01-v2-driver - # jetbrains-toolbox - # jetbrains.webstorm - # jetbrains.rust-rover - # jetbrains.idea-ultimate # postman # insomnia hoppscotch - # zed-editor-fhs ani-cli syncplay @@ -584,7 +584,7 @@ # grayjay # QUICKSHELL quickshell - qt6.full + # qt6.full distrobox diff --git a/desktop/system/networking.nix b/desktop/system/networking.nix --- a/desktop/system/networking.nix +++ b/desktop/system/networking.nix @@ -11,8 +11,10 @@ # services.resolved.enable = false; networking = { hostName = "Snowflake"; - #wireless.enable = true; + # wireless.enable = true; networkmanager.enable = true; + # networkmanager.wifi.backend = "iwd"; + # wireless.iwd.enable = true; # useDHCP = true; # search = [ @@ -25,7 +27,6 @@ "2606:4700:4700::1111" "1.1.1.1" "2606:4700:4700::1001" "1.0.0.1" - # "100.100.100.100" ]; # resolvconf = { @@ -70,6 +71,9 @@ 53 33693 + + # SimpleX + 36167 ]; allowedUDPPorts = [ @@ -79,6 +83,9 @@ # networking 53 67 + + # SimpleX + 36167 ]; }; }; diff --git a/home-server/flake.lock b/home-server/flake.lock new file mode 100644 --- /dev/null +++ b/home-server/flake.lock @@ -0,0 +1,49 @@ +{ + "nodes": { + "home-manager": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1762704774, + "narHash": "sha256-iodz4xQbULkHqetbPu5BCSWsVEzZiiNSv0/dzfH4XiE=", + "owner": "nix-community", + "repo": "home-manager", + "rev": "be4a9233dd3f6104c9b0fdd3d56f953eb519a4c7", + "type": "github" + }, + "original": { + "owner": "nix-community", + "ref": "master", + "repo": "home-manager", + "type": "github" + } + }, + "nixpkgs": { + "locked": { + "lastModified": 1762596750, + "narHash": "sha256-rXXuz51Bq7DHBlfIjN7jO8Bu3du5TV+3DSADBX7/9YQ=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "b6a8526db03f735b89dd5ff348f53f752e7ddc8e", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "root": { + "inputs": { + "home-manager": "home-manager", + "nixpkgs": "nixpkgs" + } + } + }, + "root": "root", + "version": 7 +} diff --git a/home-server/flake.nix b/home-server/flake.nix new file mode 100644 --- /dev/null +++ b/home-server/flake.nix @@ -0,0 +1,48 @@ +{ + description = "Snow's home-lab server flake"; + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; + + home-manager = { + url = "github:nix-community/home-manager/master"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + }; + + outputs = + { + ... # Passes all arguments in inputs without having to specify them + }@inputs: + + let + system = "x86_64-linux"; + in + { + nixosConfigurations.snowlab = inputs.nixpkgs.lib.nixosSystem { + inherit system; + + # Any arugments we want our config files to have (like configuration.nix) + specialArgs = { + inherit inputs; + }; + + modules = [ + ./system/configuration.nix + "${inputs.nixpkgs}/nixos/modules/profiles/minimal.nix" # Disables some options by default for a minimal installation: https://github.com/NixOS/nixpkgs/blob/master/nixos/modules/profiles/minimal.nix + + inputs.home-manager.nixosModules.home-manager + { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + home-manager.extraSpecialArgs = { + inherit inputs; # Makes sure we have access to inputs in our home-manager configs. + }; + home-manager.users = { + # All users managed by home-manager :3 + user = import ./home-manager/user.nix; + }; + } + ]; + }; + }; +} diff --git a/home-server/home-manager/apps/fish.nix b/home-server/home-manager/apps/fish.nix new file mode 100644 --- /dev/null +++ b/home-server/home-manager/apps/fish.nix @@ -0,0 +1,33 @@ +{ ... }: +{ + programs.fish = { + enable = true; + generateCompletions = true; + + shellAliases = { + ls = "eza -ihg --icons"; + + cat = "/run/current-system/sw/bin/bat"; + bat = "/run/current-system/sw/bin/cat"; + + myip4 = "curl https://ipinfo.io/ip"; + myip6 = "curl https://v6.ipinfo.io/ip"; + + docres = "docker compose down && docker compose up -d"; + docvol = "cd ~/.local/share/docker/volumes"; + + logboot = "journalctl --boot=-1 --reverse"; + listgens = "sudo nix-env -p /nix/var/nix/profiles/system --list-generations"; + }; + + shellInit = '' + if status is-interactive + set -xg fish_color_command blue + echo "Welcome to $(whoami)@$(hostname)!" + echo "" + fastfetch + echo "" + end + ''; + }; +} diff --git a/home-server/home-manager/user.nix b/home-server/home-manager/user.nix new file mode 100644 --- /dev/null +++ b/home-server/home-manager/user.nix @@ -0,0 +1,24 @@ +{ pkgs, inputs, ... }: +{ + imports = [ + ./apps/fish.nix + ]; + + home = { + stateVersion = "25.05"; + + packages = with pkgs; [ + ctop + ]; + }; + + programs = { + # enable eza, a more functional replacement of ls + eza = { + enable = true; + enableFishIntegration = true; + git = true; + icons = "always"; + }; + }; +} diff --git a/home-server/justfile b/home-server/justfile new file mode 100644 --- /dev/null +++ b/home-server/justfile @@ -0,0 +1,2 @@ +test-vm: + nixos-rebuild build-vm-with-bootloader --flake .#snowlab && QEMU_NET_OPTS="hostfwd=tcp::2221-:22,hostfwd=tcp::8080-:80" ./result/bin/run-snowlab-vm diff --git a/home-server/result b/home-server/result new file mode 100644 --- /dev/null +++ b/home-server/result @@ -0,0 +1,1 @@ +/nix/store/wsmk41hbyl6kpv4snj02csn4vmdj1yld-nixos-vm \ No newline at end of file diff --git a/home-server/system/configuration.nix b/home-server/system/configuration.nix new file mode 100644 --- /dev/null +++ b/home-server/system/configuration.nix @@ -0,0 +1,213 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page, on +# https://search.nixos.org/options and in the NixOS manual (`nixos-help`). + +{ + # config, + # lib, + pkgs, + ... +}: + +{ + imports = [ + ./hardware-configuration.nix # Include the results of the hardware scan. + ./network.nix + ./services.nix + ]; + + virtualisation.vmVariant.virtualisation = { + qemu.guestAgent.enable = true; + diskSize = 1024 * 12; + memorySize = 1024 * 4; + cores = 4; + }; + + fileSystems."/" = { + autoResize = true; + }; + + boot.growPartition = true; + + services.spice-vdagentd.enable = true; + services.qemuGuest.enable = true; + + # Enable zram (compressed ram) + zramSwap = { + enable = true; + algorithm = "zstd"; + }; + + # Add a swapfile + swapDevices = [ + { + device = "/swapfile"; + size = 8 * 1024; + } + ]; + + nix = { + settings = { + experimental-features = [ + "nix-command" + "flakes" + ]; + trusted-users = [ + "@wheel" + ]; + auto-optimise-store = true; + use-xdg-base-directories = true; + }; + + # Automatically clean up old generations every week + gc = { + automatic = true; + dates = "weekly"; + }; + }; + + boot = { + enableContainers = true; + kernelModules = [ ]; + + kernel.sysctl = { + # https://wiki.archlinux.org/title/Sysctl#Enable_TCP_Fast_Open + "net.ipv4.tcp_fastopen" = 3; + }; + + loader = { + efi.canTouchEfiVariables = true; + + # Use grub so it works on both EFI and BOOT + grub = { + enable = true; + timeoutStyle = "hidden"; + efiSupport = true; + # efiInstallAsRemovable = true; + device = "nodev"; + splashImage = null; + }; + }; + + blacklistedKernelModules = [ + # Obscure network protocols + "ax25" + "netrom" + "rose" + + # Old or rare or insufficiently audited filesystems + "adfs" + "affs" + "bfs" + "befs" + "cramfs" + "efs" + "erofs" + "exofs" + "freevxfs" + "f2fs" + "hfs" + "hpfs" + "jfs" + "minix" + "nilfs2" + "ntfs" + "omfs" + "qnx4" + "qnx6" + "sysv" + "ufs" + ]; + }; + + time.timeZone = "Europe/Berlin"; # Set your time zone. + i18n.defaultLocale = "en_US.UTF-8"; # Select internationalisation properties. + + environment = { + defaultPackages = [ ]; # Disable any default installed packages + + systemPackages = with pkgs; [ + fastfetch + wget + btop + dysk + git + ]; + }; + + fonts.fontconfig.enable = false; + + system = { + stateVersion = "25.05"; + tools = { + nixos-version.enable = true; + nixos-rebuild.enable = true; + nixos-option.enable = true; + + nixos-generate-config.enable = false; + nixos-install.enable = false; + nixos-build-vms.enable = false; + }; + }; + + programs = { + nano.enable = true; + fish.enable = true; + bat.enable = true; # Enable bat, a nicer replacement of cat + }; + + security = { + # lockKernelModules = true; + protectKernelImage = true; + + # use sudo-rs instead of sudo + sudo.enable = false; + sudo-rs = { + enable = true; + wheelNeedsPassword = true; + execWheelOnly = true; + }; + + # # Enable this if you want docker to bind to ports lower than 1024 + # wrappers = { + # docker-rootlesskit = { + # owner = "root"; + # group = "root"; + # capabilities = "cap_net_bind_service+ep"; + # source = "${pkgs.rootlesskit}/bin/rootlesskit"; + # }; + # }; + }; + + # virtualisation = { + # docker = { + # rootless = { + # enable = true; + # setSocketVariable = true; + # }; + # }; + # }; + + users = { + groups.user = { }; + users = { + user = { + isNormalUser = true; + linger = true; + group = "user"; + extraGroups = [ ]; + shell = pkgs.fish; + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL2za6psnuIMZ6FrdUehhyQlqYvy05+wv8dKER+Lctna snowy@Snowflake" + ]; + }; + + root = { + shell = pkgs.fish; + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL2za6psnuIMZ6FrdUehhyQlqYvy05+wv8dKER+Lctna snowy@Snowflake" + ]; + }; + }; + }; +} diff --git a/home-server/system/hardware-configuration.nix b/home-server/system/hardware-configuration.nix new file mode 100644 --- /dev/null +++ b/home-server/system/hardware-configuration.nix @@ -0,0 +1,58 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ + config, + lib, + pkgs, + modulesPath, + ... +}: + +{ + imports = [ + (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ + "ata_piix" + "uhci_hcd" + "virtio_pci" + "sr_mod" + "virtio_blk" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = { + device = "/dev/disk/by-uuid/b435993e-0760-44ba-afa7-ead509b87e62"; + fsType = "ext4"; + }; + + fileSystems."/proc" = { + device = "proc"; + fsType = "proc"; + }; + + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/67AC-7FCE"; + fsType = "vfat"; + options = [ + "fmask=0077" + "dmask=0077" + ]; + }; + + swapDevices = [ ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.ens3.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/home-server/system/network.nix b/home-server/system/network.nix new file mode 100644 --- /dev/null +++ b/home-server/system/network.nix @@ -0,0 +1,71 @@ +{ ... }: +{ + networking = { + hostName = "snowlab"; + + # Some good default dns servers + nameservers = [ + # Cloudflare + "2606:4700:4700::1111" + "1.1.1.1" + "2606:4700:4700::1001" + "1.0.0.1" + + # Mullvad + "2a07:e340::2" + "194.242.2.2" + ]; + + # Use more modern nftables instead of iptables + nftables.enable = true; + + # # Gateways, these are specified in netcup + # defaultGateway6 = { + # address = "fe80::1"; + # interface = "ens3"; + # }; + + # defaultGateway = { + # address = "89.58.16.1"; + # interface = "ens3"; + # }; + + # interfaces = { + # ens3 = { + # ipv6.addresses = [ + # { + # # Based on ipv6 block allocated in netcup + # address = "2a0a:4cc0:0:1eb::c0ff:ee"; + # prefixLength = 64; + # } + # ]; + # ipv4.addresses = [ + # { + # # Based on ipv4 allocated in netcup + # address = "89.58.19.34"; + # prefixLength = 22; + # } + # ]; + # }; + # }; + + firewall = { + enable = true; + + allowedTCPPorts = [ + # HTTP + 80 + 443 + + # ssh + 22 + ]; + allowedUDPPorts = [ + # HTTP3 + 80 + 443 + ]; + }; + + }; +} diff --git a/home-server/system/services.nix b/home-server/system/services.nix new file mode 100644 --- /dev/null +++ b/home-server/system/services.nix @@ -0,0 +1,24 @@ +{ config, ... }: +{ + services = { + # openssh, lol + openssh = { + enable = true; + ports = [ + 22 + ]; + allowSFTP = true; + settings = { + PasswordAuthentication = false; + PermitRootLogin = "yes"; + }; + }; + + # caddy = { + # enable = true; + # virtualHosts = { + # + # }; + # }; + }; +} diff --git a/server/containers/caddy.nix b/server/containers/caddy.nix new file mode 100644 --- /dev/null +++ b/server/containers/caddy.nix @@ -0,0 +1,59 @@ +{ + config, + lib, + pkgs, + ... +}: + +let + release = "nixos-25.05"; + +in +{ + containers.caddy = { + autoStart = true; + privateNetwork = false; + config = + { + config, + pkgs, + lib, + ... + }: + { + system.stateVersion = "25.05"; + + services.caddy = { + enable = true; + virtualHosts = { + "mrsnowy.dev" = { + serverAliases = [ + "fpps4.net" + "www.paradijs-in-hongarije.nl" + "paradijs-in-hongarije.nl" + "prowebservice.nl" + "smarty.nl" + "www.zendojaku.nl" + "zendojaku.nl" + ]; + + extraConfig = '' + reverse_proxy https://10.0.100.65 { + transport http { + tls_insecure_skip_verify + } + } + ''; + }; + + "headscale.mrsnowy.dev" = { + extraConfig = '' + reverse_proxy http://localhost:3443 + ''; + }; + }; + }; + }; + + }; +} diff --git a/server/flake.nix b/server/flake.nix --- a/server/flake.nix +++ b/server/flake.nix @@ -9,8 +9,6 @@ inputs.nixpkgs.follows = "nixpkgs"; }; deploy-rs.url = "github:serokell/deploy-rs"; - - # zenium.url = "git+https://git.killuaa.dev/Rouffy/Zenium"; }; outputs = @@ -37,10 +35,7 @@ modules = [ ./system/configuration.nix ./containers/main.nix - # "${nixpkgs}/nixos/modules/profiles/minimal.nix" - # ./lxd-config.nix - # proxmox-nixos.nixosModules.proxmox-ve home-manager.nixosModules.home-manager { @@ -51,7 +46,6 @@ home-manager.users = { snow = import ./home-manager/snow.nix; }; } - ]; }; diff --git a/server/home-manager/apps/fish.nix b/server/home-manager/apps/fish.nix --- a/server/home-manager/apps/fish.nix +++ b/server/home-manager/apps/fish.nix @@ -3,35 +3,20 @@ { programs.fish = { enable = true; generateCompletions = true; - # functions = { - # docker = { - # body = '' - # if test (count $argv) -eq 1; and test "$argv[1]" = ps - # ctop - # else - # command docker $argv - # end - # ''; - # }; - # }; shellAliases = { - fetch = "clear && fastfetch"; - helix = "hx"; - nano = "$EDITOR"; ls = "eza -ihg --icons"; + cat = "/etc/profiles/per-user/snow/bin/bat"; bat = "/run/current-system/sw/bin/cat"; - ctl = "sudo systemctl"; - myip = "curl https://ipinfo.io/ip"; + + myip4 = "curl https://ipinfo.io/ip"; myip6 = "curl https://v6.ipinfo.io/ip"; + docres = "docker compose down && docker compose up -d"; docvol = "cd ~/.local/share/docker/volumes"; logboot = "journalctl --boot=-1 --reverse"; - # reslave = "nh os switch ~/Nixos -u && nh clean all"; - # rebuild = "nh os switch ~/Nixos"; - # rebuildc = "nh os switch ~/Nixos && nh clean all"; listgens = "sudo nix-env -p /nix/var/nix/profiles/system --list-generations"; }; @@ -43,6 +28,5 @@ echo "" fastfetch end ''; - }; } diff --git a/server/home-manager/apps/helix.nix b/server/home-manager/apps/helix.nix --- a/server/home-manager/apps/helix.nix +++ b/server/home-manager/apps/helix.nix @@ -37,12 +37,12 @@ editor.lsp = { display-inlay-hints = true; display-progress-messages = true; }; - keys.select = { - y = ":clipboard-yank"; - }; - keys.normal = { - y = ":clipboard-yank"; - }; + # keys.select = { + # y = ":clipboard-yank"; + # }; + # keys.normal = { + # y = ":clipboard-yank"; + # }; }; }; -} \ No newline at end of file +} diff --git a/server/home-manager/snow.nix b/server/home-manager/snow.nix --- a/server/home-manager/snow.nix +++ b/server/home-manager/snow.nix @@ -5,25 +5,30 @@ ./apps/helix.nix ./apps/fish.nix ./apps/fastfetch.nix ]; - home.username = "snow"; - home.homeDirectory = "/home/snow"; - home.packages = with pkgs; [ - git - nixd - nixfmt-rfc-style - devenv - # yazi - ctop - # inputs.zenium.packages."${system}".zenium-remote-server-bin - ]; + home = { + username = "snow"; + homeDirectory = "/home/snow"; + stateVersion = "25.05"; + enableNixpkgsReleaseCheck = false; - services = { - # cliphist = { - # enable = true; - # allowImages = true; - # }; + packages = with pkgs; [ + git + # nixd + # nixfmt-rfc-style + devenv + # yazi + ctop + # inputs.zenium.packages."${system}".zenium-remote-server-bin + ]; }; + + # services = { + # # cliphist = { + # # enable = true; + # # allowImages = true; + # # }; + # }; programs = { home-manager = { @@ -40,6 +45,4 @@ icons = "always"; }; }; - home.stateVersion = "25.05"; - home.enableNixpkgsReleaseCheck = false; } diff --git a/server/justfile b/server/justfile --- a/server/justfile +++ b/server/justfile @@ -5,4 +5,7 @@ dry-run: nixos-rebuild dry-run --flake .#snow-den deploy: - nixos-rebuild switch --flake .#snow-den --target-host server --use-remote-sudo \ No newline at end of file + nixos-rebuild switch --flake .#snow-den --target-host server --use-remote-sudo + +test-vm: + nixos-rebuild build-vm-with-bootloader --flake .#snow-den && QEMU_NET_OPTS="hostfwd=tcp::2221-:335,hostfwd=tcp::8080-:80" ./result/bin/run-snow-den-vm diff --git a/server/result b/server/result new file mode 100644 --- /dev/null +++ b/server/result @@ -0,0 +1,1 @@ +/nix/store/q2l4r4920q2zrm7mh6j718h68k8kz4nz-nixos-vm \ No newline at end of file diff --git a/server/services/main.nix b/server/services/main.nix new file mode 100644 --- /dev/null +++ b/server/services/main.nix @@ -0,0 +1,11 @@ +{ + config, + lib, + pkgs, + ... +}: +{ + imports = [ + ./incus.nix + ]; +} diff --git a/server/system/configuration.nix b/server/system/configuration.nix --- a/server/system/configuration.nix +++ b/server/system/configuration.nix @@ -13,12 +13,9 @@ { imports = [ # Include the results of the hardware scan. ./hardware-configuration.nix - ./lxd-config.nix - # ./ets2-config.nix + ../services/main.nix ./network.nix ]; - - # nixpkgs.config.allowUnfree = true; zramSwap = { enable = true; @@ -172,6 +169,15 @@ # listenAddress = "0.0.0.0"; # }; # }; + headscale = { + enable = true; + port = 3443; + settings = { + server_url = "https://headscale.mrsnowy.dev:3443"; + dns.base_domain = "magicdns.headscale.mrsnowy.dev"; + }; + }; + tailscale.enable = true; # prometheus = { @@ -206,6 +212,7 @@ pam = { services.sudo.rssh = true; services.sudo.unixAuth = false; + rssh = { enable = true; settings = { @@ -236,6 +243,7 @@ }; users = { groups.radcliffe = { }; + groups.proc-bypass = { }; users = { snow = { isNormalUser = true; @@ -243,6 +251,7 @@ description = "snow"; linger = true; extraGroups = [ "wheel" + "proc-bypass" ]; shell = pkgs.fish; openssh.authorizedKeys.keys = [ @@ -253,10 +262,12 @@ radcliffe = { isNormalUser = true; linger = true; group = "radcliffe"; + extraGroups = [ + "proc-bypass" + ]; shell = pkgs.fish; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL2za6psnuIMZ6FrdUehhyQlqYvy05+wv8dKER+Lctna snowy@Snowflake" - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGiRKJiC+keGpcnWC9vItrPGqYSq9+bK3pNWc+zgnrMR user@radcliffe" ]; }; root = { diff --git a/server/system/hardware-configuration.nix b/server/system/hardware-configuration.nix --- a/server/system/hardware-configuration.nix +++ b/server/system/hardware-configuration.nix @@ -28,14 +28,18 @@ fileSystems."/" = { device = "/dev/disk/by-uuid/b435993e-0760-44ba-afa7-ead509b87e62"; fsType = "ext4"; + autoResize = true; }; + + boot.growPartition = true; + virtualisation.diskSize = 12144; fileSystems."/proc" = { device = "proc"; fsType = "proc"; options = [ "hidepid=2" - "gid=wheel" + "gid=proc-bypass" ]; }; diff --git a/server/system/lxd-config.nix b/server/services/incus.nix rename from server/system/lxd-config.nix rename to server/services/incus.nix --- a/server/system/lxd-config.nix +++ b/server/services/incus.nix @@ -1,17 +1,19 @@ { pkgs, ... }: { - virtualisation.lxd = { + virtualisation.incus = { enable = true; - recommendedSysctlSettings = true; + + softDaemonRestart = true; + socketActivation = false; ui = { enable = true; - package = pkgs.lxd-ui; + package = pkgs.incus-ui-canonical; }; preseed = { config = { - "core.https_address" = ":8443"; + "core.https_address" = ":8444"; "core.shutdown_timeout" = "3"; "images.compression_algorithm" = "xz"; "backups.compression_algorithm" = "xz"; @@ -33,21 +35,21 @@ ]; storage_pools = [ { - name = "hestia-pool"; + name = "hestia_pool"; description = "Storage pool for hestia"; driver = "dir"; - config = { - source = "/var/lib/lxd/storage-pools/hestia-pool"; - }; + # config = { + # source = "/var/lib/incus/storage-pools/hestia_pool"; + # }; } ]; storage_volumes = [ { - name = "hestia-backups"; + name = "hestia_volume_backups"; # type = "custom"; content_type = "filesystem"; - pool = "hestia-pool"; + pool = "hestia_pool"; config = { size = "32GiB"; }; diff --git a/server/system/network.nix b/server/system/network.nix --- a/server/system/network.nix +++ b/server/system/network.nix @@ -2,17 +2,20 @@ { ... }: { networking = { hostName = "snow-den"; + nameservers = [ + # Mullvad + "2a07:e340::2" + "194.242.2.2" + # Cloudflare "2606:4700:4700::1111" "1.1.1.1" "2606:4700:4700::1001" "1.0.0.1" + ]; - # Mullvad - "2a07:e340::2" - "194.242.2.2" - ]; + nftables.enable = true; defaultGateway6 = { address = "fe80::1"; @@ -49,9 +52,9 @@ trustedInterfaces = [ "hestia-bridge" ]; - extraCommands = '' - iptables -t nat -A POSTROUTING -s 10.0.100.0/24 ! -d 10.0.100.0/24 -j MASQUERADE - ''; + # extraCommands = '' + # iptables -t nat -A POSTROUTING -s 10.0.100.0/24 ! -d 10.0.100.0/24 -j MASQUERADE + # ''; allowedTCPPorts = [ # HTTP @@ -65,6 +68,9 @@ 665 # LXD 8443 + + # Incus + 8444 # email ## IMAP @@ -94,6 +100,8 @@ 27016 # mc 25565 + 41448 + 8100 ]; allowedUDPPorts = [ # HTTP @@ -112,6 +120,10 @@ # Steam 27015 27016 + + # mc + 41448 + 8100 ]; }; @@ -125,46 +137,46 @@ # SSH { sourcePort = 665; proto = "tcp"; - destination = "10.0.100.126:22"; + destination = "10.0.100.65:22"; } # IMAP { sourcePort = 143; proto = "tcp"; - destination = "10.0.100.126:143"; + destination = "10.0.100.65:143"; } { sourcePort = 993; proto = "tcp"; - destination = "10.0.100.126:993"; + destination = "10.0.100.65:993"; } # POP3 { sourcePort = 110; proto = "tcp"; - destination = "10.0.100.126:110"; + destination = "10.0.100.65:110"; } { sourcePort = 995; proto = "tcp"; - destination = "10.0.100.126:995"; + destination = "10.0.100.65:995"; } # SMTP { sourcePort = 25; proto = "tcp"; - destination = "10.0.100.126:25"; + destination = "10.0.100.65:25"; } { sourcePort = 465; proto = "tcp"; - destination = "10.0.100.126:465"; + destination = "10.0.100.65:465"; } { sourcePort = 587; proto = "tcp"; - destination = "10.0.100.126:587"; + destination = "10.0.100.65:587"; } ]; }; -- tangled.sh