diff --git a/flake.lock b/flake.lock index 23c3280..3851eed 100644 --- a/flake.lock +++ b/flake.lock @@ -46,37 +46,37 @@ "determinate-nixd-aarch64-darwin": { "flake": false, "locked": { - "narHash": "sha256-g1r0dPwlUi1h96c4BuHzv9M2lWDqRy9bPDW9tRSq35I=", + "narHash": "sha256-uWDS94cAYprGj+AwuT42nuuDDicRLj1S0JwalZGeBRU=", "type": "file", - "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/macOS" + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.15.1/macOS" }, "original": { "type": "file", - "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/macOS" + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.15.1/macOS" } }, "determinate-nixd-aarch64-linux": { "flake": false, "locked": { - "narHash": "sha256-xn324irXG/EpUdUfUGFrlJNg23JN2cVArd5LsFPjGKc=", + "narHash": "sha256-uHBcZCh2/Bj5/88TDihupA336tSQDk7s5lVP66IDAX0=", "type": "file", - "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/aarch64-linux" + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.15.1/aarch64-linux" }, "original": { "type": "file", - "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/aarch64-linux" + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.15.1/aarch64-linux" } }, "determinate-nixd-x86_64-linux": { "flake": false, "locked": { - "narHash": "sha256-VPM5FOGwEjl56b7Edvg3sduvauPHCyXZ11fN9hcUdTU=", + "narHash": "sha256-y+l05H6GNv/1WcrMztDYem8VBWqjc9gNg4WjeQ1PQxo=", "type": "file", - "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/x86_64-linux" + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.15.1/x86_64-linux" }, "original": { "type": "file", - "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/x86_64-linux" + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.15.1/x86_64-linux" } }, "determinite": { @@ -90,12 +90,12 @@ ] }, "locked": { - "lastModified": 1763536872, - "narHash": "sha256-QCYGGghBya+qsY59f1zzgYzxEzz+N9S7YRkVWDIDbgo=", - "rev": "f4e598cbb10021c93f73dd4c0cf01ec791ea53f9", - "revCount": 315, + "lastModified": 1766549083, + "narHash": "sha256-G1Hljg7vIBt8n9cxO382YAZWtZU/mYfQcg3icdNG8RQ=", + "rev": "ba8999fac986e70f52b4cba15047be7bbb7b6346", + "revCount": 318, "type": "tarball", - "url": "https://api.flakehub.com/f/pinned/DeterminateSystems/determinate/3.13.2/019a9b01-c0c6-7e1c-959e-98ac5b7675de/source.tar.gz" + "url": "https://api.flakehub.com/f/pinned/DeterminateSystems/determinate/3.15.1/019b4e8a-dc22-75db-aef5-a447efbb1a13/source.tar.gz" }, "original": { "type": "tarball", @@ -137,11 +137,11 @@ "flake-compat_3": { "flake": false, "locked": { - "lastModified": 1696426674, - "narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=", + "lastModified": 1761588595, + "narHash": "sha256-XKUZz9zewJNUj46b4AJdiRZJAvSZ0Dqj2BNfXvFlJC4=", "owner": "edolstra", "repo": "flake-compat", - "rev": "0f9255e01c2351cc7d116c072cb317785dd33b33", + "rev": "f387cd2afec9419c8ee37694406ca490c3f34ee5", "type": "github" }, "original": { @@ -246,11 +246,11 @@ ] }, "locked": { - "lastModified": 1764776959, - "narHash": "sha256-d+5CGloq7Lo1u2SkzhF8oiOdUc6Z5emh22nTXUB9CFA=", + "lastModified": 1766553861, + "narHash": "sha256-ZbnG01yA3O8Yr1vUm3+NQ2qk9iRhS5bloAnuXHHy7+c=", "owner": "nix-community", "repo": "home-manager", - "rev": "e1680d594a9281651cbf7d126941a8c8e2396183", + "rev": "0999ed8f965bbbd991437ad9c5ed3434cecbc30e", "type": "github" }, "original": { @@ -269,12 +269,12 @@ "nixpkgs-regression": "nixpkgs-regression" }, "locked": { - "lastModified": 1763534330, - "narHash": "sha256-gTuB2qBdSKCKnZwENTqScs/pPBaZQOv6zZ1KJvV/ohk=", - "rev": "be871f9baf5366a220b5f25634eebab6f452a017", - "revCount": 23278, + "lastModified": 1766546676, + "narHash": "sha256-GsC52VFF9Gi2pgP/haQyPdQoF5Qe2myk1tsPcuJZI28=", + "rev": "51dacdd248e8071cd0243a8245c8c42ac1f33307", + "revCount": 24299, "type": "tarball", - "url": "https://api.flakehub.com/f/pinned/DeterminateSystems/nix-src/3.13.2/019a9af6-3d7b-71bc-bccd-8b18e147ad77/source.tar.gz" + "url": "https://api.flakehub.com/f/pinned/DeterminateSystems/nix-src/3.15.1/019b4e84-d036-75db-b6c6-6bc2e2035c53/source.tar.gz" }, "original": { "type": "tarball", @@ -287,11 +287,11 @@ "nixpkgs": "nixpkgs_3" }, "locked": { - "lastModified": 1765483419, - "narHash": "sha256-w6wznH1lBzlSH3+pWDkE+L6xA0F02drFAzu2E7PD/Jo=", + "lastModified": 1765841014, + "narHash": "sha256-55V0AJ36V5Egh4kMhWtDh117eE3GOjwq5LhwxDn9eHg=", "owner": "nix-community", "repo": "NixOS-WSL", - "rev": "0c040f28b44b18e0d4240e027096078e34dbb029", + "rev": "be4af8042e7a61fa12fda58fe9a3b3babdefe17b", "type": "github" }, "original": { @@ -351,11 +351,11 @@ }, "nixpkgs-unstable": { "locked": { - "lastModified": 1744463964, - "narHash": "sha256-LWqduOgLHCFxiTNYi3Uj5Lgz0SR+Xhw3kr/3Xd0GPTM=", + "lastModified": 1766651565, + "narHash": "sha256-QEhk0eXgyIqTpJ/ehZKg9IKS7EtlWxF3N7DXy42zPfU=", "owner": "nixos", "repo": "nixpkgs", - "rev": "2631b0b7abcea6e640ce31cd78ea58910d31e650", + "rev": "3e2499d5539c16d0d173ba53552a4ff8547f4539", "type": "github" }, "original": { @@ -381,11 +381,11 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1764950072, - "narHash": "sha256-BmPWzogsG2GsXZtlT+MTcAWeDK5hkbGRZTeZNW42fwA=", + "lastModified": 1765472234, + "narHash": "sha256-9VvC20PJPsleGMewwcWYKGzDIyjckEz8uWmT0vCDYK0=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "f61125a668a320878494449750330ca58b78c557", + "rev": "2fbfb1d73d239d2402a8fe03963e37aab15abe8b", "type": "github" }, "original": { @@ -397,11 +397,11 @@ }, "nixpkgs_4": { "locked": { - "lastModified": 1764522689, - "narHash": "sha256-SqUuBFjhl/kpDiVaKLQBoD8TLD+/cTUzzgVFoaHrkqY=", + "lastModified": 1766736597, + "narHash": "sha256-BASnpCLodmgiVn0M1MU2Pqyoz0aHwar/0qLkp7CjvSQ=", "owner": "nixos", "repo": "nixpkgs", - "rev": "8bb5646e0bed5dbd3ab08c7a7cc15b75ab4e1d0f", + "rev": "f560ccec6b1116b22e6ed15f4c510997d99d5852", "type": "github" }, "original": { @@ -413,11 +413,11 @@ }, "nixpkgs_5": { "locked": { - "lastModified": 1730768919, - "narHash": "sha256-8AKquNnnSaJRXZxc5YmF/WfmxiHX6MMZZasRP6RRQkE=", + "lastModified": 1764947035, + "narHash": "sha256-EYHSjVM4Ox4lvCXUMiKKs2vETUSL5mx+J2FfutM7T9w=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "a04d33c0c3f1a59a2c1cb0c6e34cd24500e5a1dc", + "rev": "a672be65651c80d3f592a89b3945466584a22069", "type": "github" }, "original": { @@ -434,11 +434,11 @@ "nixpkgs": "nixpkgs_5" }, "locked": { - "lastModified": 1742649964, - "narHash": "sha256-DwOTp7nvfi8mRfuL1escHDXabVXFGT1VlPD1JHrtrco=", + "lastModified": 1765911976, + "narHash": "sha256-t3T/xm8zstHRLx+pIHxVpQTiySbKqcQbK+r+01XVKc0=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "dcf5072734cb576d2b0c59b2ac44f5050b5eac82", + "rev": "b68b780b69702a090c8bb1b973bab13756cc7a27", "type": "github" }, "original": { diff --git a/host-specific/odin/default.nix b/host-specific/odin/default.nix new file mode 100644 index 0000000..8aa846d --- /dev/null +++ b/host-specific/odin/default.nix @@ -0,0 +1,11 @@ +{ ... }: +{ + imports = [ + # WSL has no hardware configuration + ./hardware-configuration.nix + ../../users.nix + ./networking.nix + ./packages.nix + ./services.nix + ]; +} diff --git a/host-specific/odin/hardware-configuration.nix b/host-specific/odin/hardware-configuration.nix new file mode 100644 index 0000000..e6df0fc --- /dev/null +++ b/host-specific/odin/hardware-configuration.nix @@ -0,0 +1,93 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ + config, + lib, + modulesPath, + pkgs, + ... +}: + +{ + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.kernelPackages = pkgs.linuxPackages_latest; + boot.initrd.availableKernelModules = [ + "nvme" + "xhci_pci" + "thunderbolt" + "usb_storage" + "usbhid" + "sd_mod" + "sdhci_pci" + ]; + boot.initrd.kernelModules = [ + "kvm-amd" + "amdgpu" + "nvme" + "xhci_pci" + "thunderbolt" + "usb_storage" + "usbhid" + "sd_mod" + "sdhci_pci" + ]; + boot.kernelModules = [ + "kvm-amd" + "amdgpu" + "nvme" + "xhci_pci" + "thunderbolt" + "usb_storage" + "usbhid" + "sd_mod" + "sdhci_pci" + ]; + virtualisation.libvirtd = { + enable = true; + qemu = { + runAsRoot = false; + }; + }; + #boot.extraModulePackages = with config.boot.kernelPackages; [ ]; + boot.kernelParams = [ ]; + + hardware.enableRedistributableFirmware = true; + + fileSystems."/" = { + device = "/dev/disk/by-uuid/07019c69-2597-410d-a8a0-a8ffb0f58883"; + fsType = "ext4"; + }; + + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/4B85-C90A"; + fsType = "vfat"; + }; + + swapDevices = [ + { + device = "/swapfile"; + size = 32 * 1024; + } + ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.enp1s0.useDHCP = lib.mkDefault true; + # networking.interfaces.wlp2s0.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = { + #gcc.arch = "znver2"; + #gcc.tune = "znver2"; + system = "x86_64-linux"; + #gcc.arch = "x86-64-v3"; + }; + #nix.settings.system-features = ["gccarch-znver2" "big-parallel" "nixos-test" "benchmark" "kvm"]; + hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/host-specific/odin/networking.nix b/host-specific/odin/networking.nix new file mode 100644 index 0000000..869fabf --- /dev/null +++ b/host-specific/odin/networking.nix @@ -0,0 +1,39 @@ +{ ... }: +{ + # networking.hostName = "nixos"; # Define your hostname. + # Pick only one of the below networking options. + # networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. + # networking.networkmanager.enable = true; # Easiest to use and most distros use this by default. + networking.hostName = "odin"; + # I like systemd-networkd + systemd.network.enable = true; + systemd.network.networks."50-wlp2s0" = { + matchConfig.name = "wlp2s0"; + networkConfig.DHCP = "yes"; + linkConfig.RequiredForOnline = "no"; + }; + networking.useNetworkd = true; + # TODO: static IP @ 192.168.1.2 + + # Configure network proxy if necessary + # networking.proxy.default = "http://user:password@proxy:port/"; + # networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain"; + # Open ports in the firewall. + # networking.firewall.allowedTCPPorts = [ ... ]; + # networking.firewall.allowedUDPPorts = [ ... ]; + # Or disable the firewall altogether. + # TODO: allow some ports + networking.firewall.enable = true; + + services.avahi = { + enable = true; + nssmdns = true; + openFirewall = true; + publish = { + enable = true; + addresses = true; + workstation = true; + }; + }; + +} diff --git a/host-specific/odin/packages.nix b/host-specific/odin/packages.nix new file mode 100644 index 0000000..80a15c6 --- /dev/null +++ b/host-specific/odin/packages.nix @@ -0,0 +1,98 @@ +{ pkgs, lib, ... }: +let # bash script to let dbus know about important env variables and + # propagate them to relevent services run at the end of sway config + # see + # https://github.com/emersion/xdg-desktop-portal-wlr/wiki/"It-doesn't-work"-Troubleshooting-Checklist + # note: this is pretty much the same as /etc/sway/config.d/nixos.conf but also restarts + # some user services to make sure they have the correct environment variables + dbus-sway-environment = pkgs.writeTextFile { + name = "dbus-sway-environment"; + destination = "/bin/dbus-sway-environment"; + executable = true; + + text = '' + dbus-update-activation-environment --systemd WAYLAND_DISPLAY XDG_CURRENT_DESKTOP=sway + systemctl --user stop pipewire pipewire-media-session xdg-desktop-portal xdg-desktop-portal-wlr + systemctl --user start pipewire pipewire-media-session xdg-desktop-portal xdg-desktop-portal-wlr + ''; + }; + + # currently, there is some friction between sway and gtk: + # https://github.com/swaywm/sway/wiki/GTK-3-settings-on-Wayland + # the suggested way to set gtk settings is with gsettings + # for gsettings to work, we need to tell it where the schemas are + # using the XDG_DATA_DIR environment variable + # run at the end of sway config + configure-gtk = pkgs.writeTextFile { + name = "configure-gtk"; + destination = "/bin/configure-gtk"; + executable = true; + text = + let + # TODO: figure out why these bindings exist or where they're used + schema = pkgs.gsettings-desktop-schemas; + datadir = "${schema}/share/gsettings-schemas/${schema.name}"; + in + '' + 6 gnome_schema=org.gnome.desktop.interface + gsettings set $gnome_schema gtk-theme 'Dracula' + ''; + }; +in +{ + + # List packages installed in system profile. To search, run: + # $ nix search wget + environment.systemPackages = with pkgs; [ + neovim + appimage-run + wget + kitty + w3m + fishPlugins.fzf-fish + fzf + qemu + OVMF + + # Sway stuff + wdisplays + mako + bemenu + wl-clipboard + slurp + grim + swayidle + swaylock + gnome3.adwaita-icon-theme + dracula-theme + glib + xdg-utils + wayland + configure-gtk + dbus-sway-environment + dbus + ]; + + # Fix dynamically linked libraries for unpackaged binaries + programs.nix-ld = { + enable = true; + libraries = with pkgs; [ + # Add missing dynamic libraries for unpackaged programs HERE + # NOT in environment.systemPackages + zlib + ]; + }; + + # Logseq uses an ancient version of Electron, so we enable that + nixpkgs.config.permittedInsecurePackages = [ "electron-25.9.0" ]; + + # Whitelist some unfree packages + nixpkgs.config.allowUnfreePredicate = + pkg: + builtins.elem (lib.getName pkg) [ + "discord" + "spotify" + "obsidian" + "tailscale" + ]; +} diff --git a/host-specific/odin/services.nix b/host-specific/odin/services.nix new file mode 100644 index 0000000..2342aa0 --- /dev/null +++ b/host-specific/odin/services.nix @@ -0,0 +1,36 @@ +{ ... }: +{ + # Some programs need SUID wrappers, can be configured further or are + # started in user sessions. + # programs.mtr.enable = true; + programs.gnupg.agent = { + enable = true; + enableSSHSupport = true; + }; + + # Fish shell, the best + programs.fish.enable = true; + + # List services that you want to enable: + + # Enable the OpenSSH daemon. + services.openssh.enable = true; + + # This option is for enabling the bolt daemon for managing Thunderbolt/USB4 Devices. + services.hardware.bolt.enable = true; + + # Tailscale + services.tailscale = { + enable = true; + useRoutingFeatures = "client"; + }; + + # Containers and VMs + virtualisation = { + podman = { + enable = true; + dockerCompat = true; + defaultNetwork.settings.dns_enabled = true; + }; + }; +} diff --git a/services.nix b/services.nix index 57ce3c6..3f4dc36 100644 --- a/services.nix +++ b/services.nix @@ -1,4 +1,6 @@ -{ ... }: { +{ ... }: +{ + # Some programs need SUID wrappers, can be configured further or are # started in user sessions. programs.mtr.enable = true; diff --git a/users.nix b/users.nix index 490ce63..4c7a572 100644 --- a/users.nix +++ b/users.nix @@ -1,7 +1,4 @@ { pkgs, lib, ... }: -let - home-manager = builtins.fetchTarball "https://github.com/nix-community/home-manager/archive/release-25.11.tar.gz"; -in { # Declarative only optoins.