{ modulesPath, lib, pkgs, commonArgs, ... }: { imports = [ (modulesPath + "/installer/scan/not-detected.nix") (modulesPath + "/profiles/qemu-guest.nix") ./nix-gc.nix ./logs.nix ]; boot.loader.grub = { efiSupport = true; efiInstallAsRemovable = true; }; services.openssh.enable = true; services.prometheus.exporters.node = { enable = true; openFirewall = false; enabledCollectors = ["systemd"]; }; networking.firewall.interfaces."tailscale0".allowedTCPPorts = [ 9100 ]; nix.extraOptions = '' experimental-features = nix-command flakes ca-derivations warn-dirty = false keep-outputs = false ''; # colmena uses tangler user, so we need it here for it the user to be able # to add unsigned paths through the nix daemon (happens when --no-build-on-target is used) nix.settings.trusted-users = lib.mkForce ["root" "tangler"]; # nixpkgs 25.11 still defaults docker to insecure docker 28 virtualisation.docker.package = pkgs.docker_29; environment.systemPackages = map lib.lowPrio [ pkgs.curl pkgs.gitMinimal pkgs.htop pkgs.httpie pkgs.jq pkgs.neovim ]; users.users.tangler = { extraGroups = ["networkmanager" "wheel"]; openssh.authorizedKeys.keys = commonArgs.sshKeys; isNormalUser = true; }; security.sudo.extraRules = [ { users = ["tangler"]; commands = [ { command = "ALL"; options = ["NOPASSWD"]; } ]; } ]; }