diff --git a/flake.nix b/flake.nix index 624c8aa..713af5e 100644 --- a/flake.nix +++ b/flake.nix @@ -83,7 +83,15 @@ { # incomplete nixosConfigurations.odin = basicSystem { + extraGroups = [ + "libvirtd" + "qemu-libvirtd" + "docker" + ]; unstable = true; + modules = [ + ./host-specific/odin/configuration.nix + ]; }; nixosConfigurations.misaki = basicSystem { unstable = true; diff --git a/host-specific/misaki/services.nix b/host-specific/misaki/services.nix index 676df2f..11e8446 100644 --- a/host-specific/misaki/services.nix +++ b/host-specific/misaki/services.nix @@ -36,12 +36,6 @@ # This option is for enabling the bolt daemon for managing Thunderbolt/USB4 Devices. services.hardware.bolt.enable = true; - # Tailscale - services.tailscale = { - enable = true; - useRoutingFeatures = "client"; - }; - # Containers and VMs virtualisation = { podman = { diff --git a/host-specific/odin/boot.nix b/host-specific/odin/boot.nix new file mode 100644 index 0000000..a100fd3 --- /dev/null +++ b/host-specific/odin/boot.nix @@ -0,0 +1,6 @@ +{ ... }: +{ + # Use the systemd-boot EFI boot loader. + boot.loader.systemd-boot.enable = true; + boot.loader.efi.canTouchEfiVariables = true; +} diff --git a/host-specific/odin/configuration.nix b/host-specific/odin/configuration.nix new file mode 100644 index 0000000..14fbb21 --- /dev/null +++ b/host-specific/odin/configuration.nix @@ -0,0 +1,62 @@ +# Edit this configuration file to define what should be installed on +## your system. Help is available in the configuration.nix(5) man page, on +# https://search.nixos.org/options and in the NixOS manual (`nixos-help`). + +{ ... }: +{ + imports = [ + # Include the results of the hardware scan. + ./hardware-configuration.nix + ./boot.nix + ./networking.nix + #./gui.nix + ./packages.nix + ./services.nix + ]; + + nixpkgs.config.allowUnfree = true; + + # Set your time zone. + time.timeZone = "America/Chicago"; + + # Select internationalisation properties. + i18n.defaultLocale = "en_US.UTF-8"; + # console = { + # font = "Lat2-Terminus16"; + # keyMap = "us"; + # useXkbConfig = true; # use xkb.options in tty. + # }; + + # Automatic doc cache generation + documentation.man.generateCaches = true; + + # Automatic system upgrades + system.autoUpgrade = { + enable = true; + dates = "09:00"; + randomizedDelaySec = "45min"; + }; + + # Automatic Garbage Collection + nix.gc.automatic = true; + nix.gc.options = "--delete-older-than 8d"; + + # This option defines the first version of NixOS you have installed on this particular machine, + # and is used to maintain compatibility with application data (e.g. databases) created on older NixOS versions. + # + # Most users should NEVER change this value after the initial install, for any reason, + # even if you've upgraded your system to a new NixOS release. + # + # This value does NOT affect the Nixpkgs version your packages and OS are pulled from, + # so changing it will NOT upgrade your system. + # + # This value being lower than the current NixOS release does NOT mean your system is + # out of date, out of support, or vulnerable. + # + # Do NOT change this value unless you have manually inspected all the changes it would make to your configuration, + # and migrated your data accordingly. + # + # For more information, see `man configuration.nix` or https://nixos.org/manual/nixos/stable/options#opt-system.stateVersion . + system.stateVersion = "23.11"; # Did you read the comment? + +} diff --git a/host-specific/odin/default.nix b/host-specific/odin/default.nix index 8aa846d..5a832ff 100644 --- a/host-specific/odin/default.nix +++ b/host-specific/odin/default.nix @@ -1,9 +1,7 @@ { ... }: { imports = [ - # WSL has no hardware configuration ./hardware-configuration.nix - ../../users.nix ./networking.nix ./packages.nix ./services.nix diff --git a/host-specific/odin/gui.nix b/host-specific/odin/gui.nix new file mode 100644 index 0000000..7e567ad --- /dev/null +++ b/host-specific/odin/gui.nix @@ -0,0 +1,98 @@ +{ pkgs, ... }: +{ + # Enable the X11 windowing system. + services.xserver = { + enable = true; + videoDrivers = [ "amdgpu" ]; + }; + + # Fix for HIP libraries + systemd.tmpfiles.rules = [ + "L+ /opt/rocm/hip - - - - ${pkgs.rocmPackages.clr}" + ]; + + # Configure keymap in X11 + # services.xserver.xkb.layout = "us"; + # services.xserver.xkb.options = "eurosign:e,caps:escape"; + + # Enable CUPS to print documents. + # services.printing.enable = true; + + # Enable sound. + security.rtkit.enable = true; + services.pipewire = { + enable = true; + alsa.enable = true; + alsa.support32Bit = true; + pulse.enable = true; + wireplumber.enable = true; + }; + + # Graphics and parallel compute configuration + hardware.graphics = { + enable = true; + extraPackages = with pkgs; [ + libva + mesa + rocmPackages.clr.icd + ]; + }; + + # Enable touchpad support (enabled default in most desktopManager). + # services.xserver.libinput.enable = true; + + # Fonts + fonts.packages = with pkgs; [ + fira-code + fira-code-symbols + noto-fonts + noto-fonts-cjk-sans + noto-fonts-color-emoji + nerd-fonts.fira-code + ]; + + # Polkit is a dependency of Sway. It's responsible for handling security policies + security.polkit.enable = true; + + # Enable the sway window manager + programs.sway = { + enable = true; + #package = unstable.sway; + wrapperFeatures.gtk = true; + }; + # Use greetd as the displaymanager + #services.xserver.displayManager.greetd.enable = true; + #services.xserver.displayManager.lightdm.enable = false; + services.displayManager.sddm.enable = true; + services.displayManager.defaultSession = "sway"; + services.displayManager.autoLogin = { + enable = true; + user = "noah"; + }; + + # i3, for when I need XOrg + services.xserver.windowManager.i3 = { + enable = true; + extraPackages = with pkgs; [ + dmenu + i3status + i3lock + i3blocks + ]; + }; + + xdg.portal = { + enable = true; + wlr.enable = true; + extraPortals = [ pkgs.xdg-desktop-portal-gtk ]; + }; + xdg.mime = { + enable = true; + defaultApplications = { + "x-scheme-handler/http" = "org.firefox.firefox.desktop"; + "x-scheme-handler/https" = "org.firefox.firefox.desktop"; + }; + }; + services.dbus.enable = true; + services.gnome.gnome-keyring.enable = true; +} diff --git a/host-specific/odin/networking.nix b/host-specific/odin/networking.nix index 869fabf..e63f1af 100644 --- a/host-specific/odin/networking.nix +++ b/host-specific/odin/networking.nix @@ -12,8 +12,11 @@ networkConfig.DHCP = "yes"; linkConfig.RequiredForOnline = "no"; }; + + networking.tempAddresses = "disabled"; + networking.useNetworkd = true; - # TODO: static IP @ 192.168.1.2 + # TODO: static IP @ 192.168.1.6 # Configure network proxy if necessary # networking.proxy.default = "http://user:password@proxy:port/"; @@ -22,18 +25,54 @@ # networking.firewall.allowedTCPPorts = [ ... ]; # networking.firewall.allowedUDPPorts = [ ... ]; # Or disable the firewall altogether. - # TODO: allow some ports - networking.firewall.enable = true; + networking.firewall = { + enable = true; + allowPing = true; + allowedUDPPorts = [ ]; + allowedUDPPortRanges = [ ]; + allowedTCPPorts = [ + 2375 + 3000 + ]; + }; services.avahi = { enable = true; - nssmdns = true; + nssmdns4 = true; + nssmdns6 = true; + ipv6 = true; openFirewall = true; publish = { enable = true; addresses = true; workstation = true; + userServices = true; + domain = true; }; }; + # NFS mounts + + fileSystems = { + "/srv/shokuhou" = { + device = "192.168.1.3:/srv/shokuhou"; + fsType = "nfs"; + options = [ + "nfsvers=4" + "user" + "x-system.automount" + "x-system.idle-timeout=600" + ]; + }; + "/srv/mentalout" = { + device = "192.168.1.3:/srv/mentalout"; + fsType = "nfs"; + options = [ + "nfsvers=4" + "user" + "x-system.automount" + "x-system.idle-timeout=600" + ]; + }; + }; } diff --git a/host-specific/odin/packages.nix b/host-specific/odin/packages.nix index 80a15c6..5ccab9d 100644 --- a/host-specific/odin/packages.nix +++ b/host-specific/odin/packages.nix @@ -46,13 +46,26 @@ in environment.systemPackages = with pkgs; [ neovim appimage-run + tzdata wget kitty + file w3m fishPlugins.fzf-fish fzf qemu + qemu-user + qemu-utils + qemu_full OVMF + #9p stuff + diod + plan9port + vis + rc + ncdu + + smartmontools # Sway stuff wdisplays @@ -63,7 +76,7 @@ in grim swayidle swaylock - gnome3.adwaita-icon-theme + adwaita-icon-theme dracula-theme glib xdg-utils @@ -71,7 +84,14 @@ in configure-gtk dbus-sway-environment dbus + pkg-config + zlib + # why wouldn't I want documentation on my system + man-pages + man-pages-posix + linuxPackages_latest.perf ]; + documentation.dev.enable = true; # Fix dynamically linked libraries for unpackaged binaries programs.nix-ld = { @@ -80,8 +100,28 @@ in # Add missing dynamic libraries for unpackaged programs HERE # NOT in environment.systemPackages zlib + openssl + sqlite + libunwind + libglvnd + libclang + systemdLibs ]; }; + programs.nix-index = { + enable = true; + enableFishIntegration = true; + enableBashIntegration = false; + enableZshIntegration = false; + }; + + # Run other bins in QEMU + boot.binfmt.emulatedSystems = [ + "aarch64-linux" + "riscv64-linux" + ]; + # UEFI firmware support for QEMU + systemd.tmpfiles.rules = [ "L+ /var/lib/qemu/firmware - - - - ${pkgs.qemu}/share/qemu/firmware" ]; # Logseq uses an ancient version of Electron, so we enable that nixpkgs.config.permittedInsecurePackages = [ "electron-25.9.0" ]; @@ -93,6 +133,9 @@ in "discord" "spotify" "obsidian" + "unstable.obsidian" "tailscale" + "google-chrome" + "slack" ]; } diff --git a/host-specific/odin/services.nix b/host-specific/odin/services.nix index 2342aa0..e9d8679 100644 --- a/host-specific/odin/services.nix +++ b/host-specific/odin/services.nix @@ -5,7 +5,7 @@ # programs.mtr.enable = true; programs.gnupg.agent = { enable = true; - enableSSHSupport = true; + enableSSHSupport = false; }; # Fish shell, the best @@ -13,24 +13,21 @@ # List services that you want to enable: - # Enable the OpenSSH daemon. - services.openssh.enable = true; - - # This option is for enabling the bolt daemon for managing Thunderbolt/USB4 Devices. - services.hardware.bolt.enable = true; - - # Tailscale - services.tailscale = { + services.redis.servers."" = { enable = true; - useRoutingFeatures = "client"; }; # Containers and VMs virtualisation = { podman = { - enable = true; + enable = false; dockerCompat = true; defaultNetwork.settings.dns_enabled = true; + dockerSocket.enable = true; + }; + docker = { + enable = true; + storageDriver = "overlay2"; }; }; } diff --git a/secrets/secrets.nix b/secrets/secrets.nix index 40251fc..837190b 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -1,10 +1,20 @@ let - noah = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDQFlX3hhXxsqAUYLvF+IX1YWQ+k22OHlqMOjgyNBe9e noah@misaki"; + noah = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDQFlX3hhXxsqAUYLvF+IX1YWQ+k22OHlqMOjgyNBe9e noah@misaki" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC/cXL1cV6QUW5z2bJp1mCu0CXrcc0Dntdxaeo3fg60N noah@odin" + ]; misaki = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO+Rcf4Lr+JPWGKQol6eAml6SMgERkGJWgN7y1qYUUvX root@nixos"; edge = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINCmFKYXpQf1E8E7fj5s+3R33HPRjPhXrv++FCKYBCd4 root@nixos"; - hosts = [ misaki edge ]; + odin = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJIuvOXEK7M2i/Q8FeableBS+L20zwQpLetOuFGUhba2 root@nixos"; + touma-wsl = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFeyj52bQ/nf5k4HwDckeHy8wU3weDtY6IF6VlUJ/hAH root@nixos"; + hosts = [ + misaki + edge + odin + touma-wsl + ]; in { - "porkbun-api-key.age".publicKeys = [ noah misaki ]; + "porkbun-api-key.age".publicKeys = [ misaki ] ++ noah; "noah-hashed-password.age".publicKeys = hosts; } diff --git a/services.nix b/services.nix index 62ae0b9..839e491 100644 --- a/services.nix +++ b/services.nix @@ -7,4 +7,20 @@ # Fish shell, the best programs.fish.enable = true; + + # Tailscale + services.tailscale = { + enable = true; + useRoutingFeatures = "client"; + }; + + # Enable the OpenSSH daemon. + services.openssh = { + enable = true; + openFirewall = true; + settings.PasswordAuthentication = false; + }; + + # MOSH, SSH over flakey connections + programs.mosh.enable = true; }