From 843f0bafa1e3b29fed080f7f8e9576989a1c4410 Mon Sep 17 00:00:00 2001 From: oqyude Date: Tue, 11 Aug 2026 02:45:23 +0300 Subject: [PATCH] br v2 --- configurations/mini-laptop.nix | 86 +-------------------------- configurations/mini-pc.nix | 90 ++++++++-------------------- configurations/server.nix | 27 +-------- configurations/vds.nix | 39 +++--------- configurations/wsl.nix | 53 +---------------- flake.lock | 102 -------------------------------- flake.nix | 8 +-- home/home.nix | 24 ++++++++ home/server.nix | 16 ----- home/vds.nix | 19 ------ home/wsl.nix | 16 ----- modules/default.nix | 61 ++++++++++--------- modules/desktop/default.nix | 65 +++++++++++++++----- modules/essentials/default.nix | 1 + modules/essentials/services.nix | 14 +++-- modules/essentials/ssh.nix | 23 +++++++ modules/minimal/default.nix | 7 --- modules/options.nix | 7 +++ modules/primary/default.nix | 9 --- modules/secondary/default.nix | 9 --- 20 files changed, 183 insertions(+), 493 deletions(-) create mode 100644 modules/essentials/ssh.nix delete mode 100644 modules/minimal/default.nix delete mode 100644 modules/primary/default.nix delete mode 100644 modules/secondary/default.nix diff --git a/configurations/mini-laptop.nix b/configurations/mini-laptop.nix index bdb3175..e2a1fed 100644 --- a/configurations/mini-laptop.nix +++ b/configurations/mini-laptop.nix @@ -4,11 +4,10 @@ modules = [ ( { - config, - inputs, lib, pkgs, xlib, + inputs, ... }: { @@ -39,88 +38,7 @@ ]; }; - hardware = { - bluetooth.enable = true; - }; - - networking = { - networkmanager.enable = true; - firewall.enable = false; - }; - - i18n = { - extraLocaleSettings = { - LC_ADDRESS = "ru_RU.UTF-8"; - LC_IDENTIFICATION = "ru_RU.UTF-8"; - LC_MEASUREMENT = "ru_RU.UTF-8"; - LC_MONETARY = "ru_RU.UTF-8"; - LC_NAME = "ru_RU.UTF-8"; - LC_NUMERIC = "ru_RU.UTF-8"; - LC_PAPER = "ru_RU.UTF-8"; - LC_TELEPHONE = "ru_RU.UTF-8"; - LC_TIME = "ru_RU.UTF-8"; - }; - }; - - services = { - # xserver = { - # videoDrivers = [ - # "nomodeset" - # ]; - # }; - syncthing = { - enable = true; - systemService = true; - configDir = "${xlib.dirs.user-storage}/Syncthing/${config.system.name}"; - dataDir = "${xlib.dirs.user-home}"; - group = "users"; - user = "${xlib.device.username}"; - }; - # pipewire = { - # enable = lib.mkDefault true; - # systemWide = true; - # alsa.enable = false; - # alsa.support32Bit = true; - # pulse.enable = true; - # jack.enable = true; - # extraConfig.pipewire = { - # "99-default.conf" = { - # "context.properties" = { - # "default.clock.rate" = 96000; - # "default.clock.allowed-rates" = [ - # 44100 - # 48000 - # 96000 - # ]; - # "default.clock.quantum" = 1024; - # "default.clock.min-quantum" = 256; - # "default.clock.max-quantum" = 2048; - # }; - # }; - # }; - # }; - thermald.enable = true; - earlyoom.enable = true; - openssh = { - enable = true; - allowSFTP = true; - hostKeys = [ - { - path = "/etc/ssh/id_ed25519"; - type = "ed25519"; - } - ]; - settings = { - PasswordAuthentication = false; - PermitRootLogin = "yes"; - UsePAM = true; - }; - }; - }; - security = { - rtkit.enable = true; - }; - + xlib.ssh.enable = true; hardware.intel-gpu-tools.enable = true; system.stateVersion = "26.05"; diff --git a/configurations/mini-pc.nix b/configurations/mini-pc.nix index da2c94d..d1625c7 100644 --- a/configurations/mini-pc.nix +++ b/configurations/mini-pc.nix @@ -4,11 +4,10 @@ modules = [ ( { - config, - inputs, lib, pkgs, xlib, + inputs, ... }: { @@ -69,77 +68,36 @@ }; }; - hardware = { - bluetooth.enable = true; + services.xserver = { + videoDrivers = [ + "amdgpu" + ]; }; - - networking = { - networkmanager.enable = true; - firewall.enable = false; - }; - - i18n = { - extraLocaleSettings = { - LC_ADDRESS = "ru_RU.UTF-8"; - LC_IDENTIFICATION = "ru_RU.UTF-8"; - LC_MEASUREMENT = "ru_RU.UTF-8"; - LC_MONETARY = "ru_RU.UTF-8"; - LC_NAME = "ru_RU.UTF-8"; - LC_NUMERIC = "ru_RU.UTF-8"; - LC_PAPER = "ru_RU.UTF-8"; - LC_TELEPHONE = "ru_RU.UTF-8"; - LC_TIME = "ru_RU.UTF-8"; - }; - }; - - services = { - #logrotate.checkConfig = false; - #power-profiles-daemon.enable = false; - xserver = { - videoDrivers = [ - "amdgpu" - ]; - }; - syncthing = { - enable = true; - systemService = true; - configDir = "${xlib.dirs.user-storage}/Syncthing/${config.system.name}"; - dataDir = "${xlib.dirs.user-home}"; - group = "users"; - user = "${xlib.device.username}"; - }; - pipewire = { - enable = lib.mkDefault true; - systemWide = true; - alsa.enable = false; - alsa.support32Bit = true; - pulse.enable = true; - jack.enable = true; - extraConfig.pipewire = { - "99-default.conf" = { - "context.properties" = { - "default.clock.rate" = 96000; - "default.clock.allowed-rates" = [ - 44100 - 48000 - 96000 - ]; - "default.clock.quantum" = 1024; - "default.clock.min-quantum" = 256; - "default.clock.max-quantum" = 2048; - }; + services.pipewire = { + enable = lib.mkDefault true; + systemWide = true; + alsa.enable = false; + alsa.support32Bit = true; + pulse.enable = true; + jack.enable = true; + extraConfig.pipewire = { + "99-default.conf" = { + "context.properties" = { + "default.clock.rate" = 96000; + "default.clock.allowed-rates" = [ + 44100 + 48000 + 96000 + ]; + "default.clock.quantum" = 1024; + "default.clock.min-quantum" = 256; + "default.clock.max-quantum" = 2048; }; }; }; - thermald.enable = true; - earlyoom.enable = true; }; nixpkgs.config.pulseaudio = true; - security = { - rtkit.enable = true; - }; - system.stateVersion = "26.05"; } ) diff --git a/configurations/server.nix b/configurations/server.nix index bfe3241..b351973 100644 --- a/configurations/server.nix +++ b/configurations/server.nix @@ -4,11 +4,10 @@ modules = [ ( { - config, - inputs, lib, pkgs, xlib, + inputs, ... }: { @@ -80,29 +79,7 @@ "z ${xlib.dirs.services-mnt-folder} 0777 root root -" ]; - services = { - earlyoom.enable = true; - journald = { - extraConfig = '' - SystemMaxUse=512M - ''; - }; - openssh = { - enable = true; - allowSFTP = true; - hostKeys = [ - { - path = "/etc/ssh/id_ed25519"; - type = "ed25519"; - } - ]; - settings = { - PasswordAuthentication = false; - PermitRootLogin = "yes"; - UsePAM = true; - }; - }; - }; + xlib.ssh.enable = true; networking = { networkmanager.enable = true; diff --git a/configurations/vds.nix b/configurations/vds.nix index ef6149b..6972ef3 100644 --- a/configurations/vds.nix +++ b/configurations/vds.nix @@ -5,11 +5,11 @@ ( { config, - inputs, lib, modulesPath, pkgs, xlib, + inputs, ... }: { @@ -43,42 +43,17 @@ }; }; - services = { - earlyoom.enable = true; - journald = { - extraConfig = '' - SystemMaxUse=512M - ''; - }; - openssh = { - enable = true; - allowSFTP = true; - openFirewall = true; - hostKeys = [ - { - path = "/etc/ssh/id_ed25519"; - type = "ed25519"; - } - ]; - settings = { - PasswordAuthentication = false; - PermitRootLogin = "yes"; - UsePAM = true; - }; - }; - tailscale = { - enable = true; - openFirewall = true; - }; + xlib.ssh.enable = true; + services.openssh.openFirewall = true; + + services.tailscale = { + enable = true; + openFirewall = true; }; networking = { nameservers = [ "1.1.1.1" "8.8.8.8" - # "2001:4860:4860::8844" - # "2001:4860:4860::8888" - # "2606:4700:4700::1111" - # "2606:4700:4700::1001" ]; networkmanager.enable = true; tempAddresses = "disabled"; diff --git a/configurations/wsl.nix b/configurations/wsl.nix index b1cfc5c..321ee73 100644 --- a/configurations/wsl.nix +++ b/configurations/wsl.nix @@ -5,11 +5,11 @@ ( { config, - inputs, lib, - modulesPath, pkgs, + modulesPath, xlib, + inputs, ... }: { @@ -18,65 +18,16 @@ inputs.self.nixosModules.default ]; - #zramSwap.enable = true; - services = { - journald = { - extraConfig = '' - SystemMaxUse=512M - ''; - }; - earlyoom.enable = true; - }; - hardware = { graphics.enable = true; - # amdgpu.opencl.enable = true; - # amdgpu.amdvlk.enable = true; }; networking = { - # nameservers = [ - # "1.1.1.1" - # "8.8.8.8" - # "2001:4860:4860::8844" - # "2001:4860:4860::8888" - # "2606:4700:4700::1111" - # "2606:4700:4700::1001" - # ]; - # networkmanager.enable = true; - # tempAddresses = "disabled"; - # dhcpcd = { - # enable = true; - # IPv6rs = true; - # }; firewall = { enable = false; allowPing = true; }; enableIPv6 = true; - # interfaces.ens3 = { - # useDHCP = true; - # # ipv4.addresses = [ - # # { - # # address = "31.57.158.109"; - # # prefixLength = 24; - # # } - # # ]; - # ipv6.addresses = [ - # { - # address = "2a13:7c00:10:6:f816:3eff:fe36:fe1b"; - # prefixLength = 64; - # } - # ]; - # }; - # # defaultGateway = { - # # address = "31.57.158.1"; - # # interface = "ens3"; - # # }; - # defaultGateway6 = { - # address = "2a13:7c00:10:6::1"; - # interface = "ens3"; - # }; }; wsl = { diff --git a/flake.lock b/flake.lock index dbf4fea..31e7063 100644 --- a/flake.lock +++ b/flake.lock @@ -211,38 +211,6 @@ "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz" } }, - "nixpkgs-beets": { - "locked": { - "lastModified": 1774610258, - "narHash": "sha256-HaThtroVD9wRdx7KQk0B75JmFcXlMUoEdDFNOMOlsOs=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "832efc09b4caf6b4569fbf9dc01bec3082a00611", - "type": "github" - }, - "original": { - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "832efc09b4caf6b4569fbf9dc01bec3082a00611", - "type": "github" - } - }, - "nixpkgs-calibre": { - "locked": { - "lastModified": 1776255774, - "narHash": "sha256-psVTpH6PK3q1htMJpmdz1hLF5pQgEshu7gQWgKO6t6Y=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "566acc07c54dc807f91625bb286cb9b321b5f42a", - "type": "github" - }, - "original": { - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "566acc07c54dc807f91625bb286cb9b321b5f42a", - "type": "github" - } - }, "nixpkgs-docs": { "locked": { "lastModified": 1705957679, @@ -275,70 +243,6 @@ "type": "github" } }, - "nixpkgs-master": { - "locked": { - "lastModified": 1786198689, - "narHash": "sha256-XkvYmpRd4cmcrzKS8QplEHPZkDDeKwpalJQwosCd3+Q=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "94ec6671dbe7d4879c2c8103e67425e85bf066d7", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "master", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs-previous": { - "locked": { - "lastModified": 1767892417, - "narHash": "sha256-dhhvQY67aboBk8b0/u0XB6vwHdgbROZT3fJAjyNh5Ww=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba", - "type": "github" - }, - "original": { - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba", - "type": "github" - } - }, - "nixpkgs-stable": { - "locked": { - "lastModified": 1782847189, - "narHash": "sha256-twXPFqFsrrY5r28Zh7Homgcp2gUMBgQ6WDS98Q/3xFI=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "b6018f87da91d19d0ab4cf979885689b469cdd41", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixos-25.11", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs-unstable": { - "locked": { - "lastModified": 1785975029, - "narHash": "sha256-X44cn5rzytELc3NNoQsh0aLkjWA/QzPfc6HPQmsG3sU=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "70ce234312134a463ba7728e94da2486a1d237ac", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixpkgs-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, "nixpkgs_2": { "locked": { "lastModified": 1785967620, @@ -448,12 +352,6 @@ "nixos-hardware": "nixos-hardware", "nixos-wsl": "nixos-wsl", "nixpkgs": "nixpkgs_2", - "nixpkgs-beets": "nixpkgs-beets", - "nixpkgs-calibre": "nixpkgs-calibre", - "nixpkgs-master": "nixpkgs-master", - "nixpkgs-previous": "nixpkgs-previous", - "nixpkgs-stable": "nixpkgs-stable", - "nixpkgs-unstable": "nixpkgs-unstable", "plasma-manager": "plasma-manager", "proxy-suite": "proxy-suite", "sops-nix": "sops-nix", diff --git a/flake.nix b/flake.nix index b4cf2e8..26e3584 100644 --- a/flake.nix +++ b/flake.nix @@ -7,14 +7,8 @@ # nixpkgs nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; - nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable"; # nixpkgs-last-unstable.url = "github:NixOS/nixpkgs/6b4955211758ba47fac850c040a27f23b9b4008f"; - nixpkgs-calibre.url = "github:NixOS/nixpkgs/566acc07c54dc807f91625bb286cb9b321b5f42a"; - nixpkgs-previous.url = "github:NixOS/nixpkgs/3497aa5c9457a9d88d71fa93a4a8368816fbeeba"; - nixpkgs-master.url = "github:NixOS/nixpkgs/master"; - nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-25.11"; - nixpkgs-beets.url = "github:NixOS/nixpkgs/832efc09b4caf6b4569fbf9dc01bec3082a00611"; # 2343bbb58f99267223bc2aac4fc9ea301a155a16 - #nixpkgs-fingerprint.url = "github:NixOS/nixpkgs/nixos-24.11"; + # nixpkgs-fingerprint.url = "github:NixOS/nixpkgs/nixos-24.11"; # nix-community nixos-wsl = { diff --git a/home/home.nix b/home/home.nix index 599dce4..7231b4d 100644 --- a/home/home.nix +++ b/home/home.nix @@ -20,6 +20,30 @@ let if username == "root" then lib.mkDefault "/${username}" else lib.mkDefault "/home/${username}"; enableNixpkgsReleaseCheck = false; }; + # Headless hosts: no GUI user dirs + xdg = + lib.mkIf + (builtins.elem xlib.device.type [ + "server" + "vds" + "wsl" + ]) + { + enable = true; + autostart.enable = true; + userDirs = { + enable = true; + createDirectories = false; + desktop = null; + documents = null; + download = null; + music = null; + pictures = null; + publicShare = null; + templates = null; + videos = null; + }; + }; }; mkRootModule = username: { home = { diff --git a/home/server.nix b/home/server.nix index fd0bbff..f893366 100644 --- a/home/server.nix +++ b/home/server.nix @@ -19,22 +19,6 @@ in ./minimal.nix ]; home.file = mkLinks; - xdg = { - enable = true; - autostart.enable = true; - userDirs = { - enable = true; - createDirectories = false; - desktop = null; - documents = null; - download = null; - music = null; - pictures = null; - publicShare = null; - templates = null; - videos = null; - }; - }; home.activation = { yaziSync = '' ${pkgs.rsync}/bin/rsync -Lrv --no-A --no-X "${config.home.homeDirectory}/.config/yazi/" "${xlib.dirs.storage}/yazi/" diff --git a/home/vds.nix b/home/vds.nix index 15d68db..a6ac0d2 100644 --- a/home/vds.nix +++ b/home/vds.nix @@ -1,27 +1,8 @@ { - config, - pkgs, - xlib, ... }: { imports = [ ./minimal.nix ]; - xdg = { - enable = true; - autostart.enable = true; - userDirs = { - enable = true; - createDirectories = false; - desktop = null; - documents = null; - download = null; - music = null; - pictures = null; - publicShare = null; - templates = null; - videos = null; - }; - }; } diff --git a/home/wsl.nix b/home/wsl.nix index 5f9c327..f44e0be 100644 --- a/home/wsl.nix +++ b/home/wsl.nix @@ -22,22 +22,6 @@ in ./minimal.nix ]; home.file = mkLinks; - xdg = { - enable = true; - autostart.enable = true; - userDirs = { - enable = true; - createDirectories = false; - desktop = null; - documents = null; - download = null; - music = null; - pictures = null; - publicShare = null; - templates = null; - videos = null; - }; - }; home.activation = { yaziSync = '' ${pkgs.rsync}/bin/rsync -Lrv "${config.home.homeDirectory}/.config/yazi/" "${xlib.dirs.wsl-storage}/yazi/" diff --git a/modules/default.nix b/modules/default.nix index ce433ac..055485e 100644 --- a/modules/default.nix +++ b/modules/default.nix @@ -1,5 +1,12 @@ { inputs, ... }@flakeContext: let + # NixOS-only modules. termux runs nix-on-droid (its own module system, + # class = "nixOnDroid"): options like services.*, users.*, sops.*, disko.* + # and nixpkgs.overlays (flake assertion) do not exist there. + moduleArgs = config: { + inherit inputs; + xlib = config.xlib; + }; defaultModule = { config, @@ -8,31 +15,35 @@ let xlib, ... }: - { - # NixOS-only modules. termux runs nix-on-droid (its own module system, - # class = "nixOnDroid"): options like services.*, users.*, sops.*, disko.* - # and nixpkgs.overlays (flake assertion) do not exist there. - imports = with inputs; [ - ./essentials - ./options.nix - ./users.nix - (./. + "/${deviceType}") - - home-manager.nixosModules.home-manager # home-manager module - # nix-index-database.nixosModules.nix-index # nix-index module - grub2-themes.nixosModules.default # grub2 themes module - sops-nix.nixosModules.sops # sops module - self.homeConfigurations.default.nixosModule # default homeConfigurations - disko.nixosModules.disko # disko module + let + isDesktop = builtins.elem deviceType [ + "primary" + "secondary" ]; + in + { + imports = + with inputs; + [ + ./essentials + ./options.nix + ./users.nix + + home-manager.nixosModules.home-manager # home-manager module + # nix-index-database.nixosModules.nix-index # nix-index module + grub2-themes.nixosModules.default # grub2 themes module + sops-nix.nixosModules.sops # sops module + self.homeConfigurations.default.nixosModule # default homeConfigurations + disko.nixosModules.disko # disko module + ] + ++ lib.optional isDesktop ../desktop # desktop class: primary/secondary + # device-type module dir; "minimal" has no extra modules + ++ lib.optional (!isDesktop && deviceType != "minimal") (./. + "/${deviceType}"); nixpkgs.overlays = with inputs; [ self.nixosOverlays.default ]; networking.hostName = lib.mkDefault config.xlib.device.hostname; - _module.args = { - inputs = inputs; - xlib = config.xlib; - }; + _module.args = moduleArgs config; }; publicModule = { @@ -51,10 +62,7 @@ let sops-nix.nixosModules.sops # sops module ]; - _module.args = { - inputs = inputs; - xlib = config.xlib; - }; + _module.args = moduleArgs config; }; strictModule = { @@ -73,10 +81,7 @@ let # sops-nix.nixosModules.sops ]; - _module.args = { - inputs = inputs; - xlib = config.xlib; - }; + _module.args = moduleArgs config; }; in { diff --git a/modules/desktop/default.nix b/modules/desktop/default.nix index 977d620..8042c42 100644 --- a/modules/desktop/default.nix +++ b/modules/desktop/default.nix @@ -3,6 +3,7 @@ inputs, lib, pkgs, + xlib, ... }: { @@ -11,6 +12,54 @@ ./theming.nix ]; + # Things every desktop host has in common + hardware.bluetooth.enable = true; + + i18n.extraLocaleSettings = { + LC_ADDRESS = "ru_RU.UTF-8"; + LC_IDENTIFICATION = "ru_RU.UTF-8"; + LC_MEASUREMENT = "ru_RU.UTF-8"; + LC_MONETARY = "ru_RU.UTF-8"; + LC_NAME = "ru_RU.UTF-8"; + LC_NUMERIC = "ru_RU.UTF-8"; + LC_PAPER = "ru_RU.UTF-8"; + LC_TELEPHONE = "ru_RU.UTF-8"; + LC_TIME = "ru_RU.UTF-8"; + }; + + networking = { + networkmanager.enable = true; + firewall.enable = false; + }; + + security.rtkit.enable = true; + + services = { + syncthing = { + enable = true; + systemService = true; + configDir = "${xlib.dirs.user-storage}/Syncthing/${config.system.name}"; + dataDir = "${xlib.dirs.user-home}"; + group = "users"; + user = "${xlib.device.username}"; + }; + thermald.enable = true; + xserver = { + enable = true; + xkb = { + layout = "us,ru"; + variant = ""; + # options = "grp:alt_shift_toggle"; + }; + }; + libinput.enable = true; + colord.enable = true; + printing = { + enable = true; + cups-pdf.enable = true; + }; + }; + boot = { plymouth = { enable = true; @@ -53,22 +102,6 @@ steam.enable = true; xwayland.enable = true; }; - services = { - xserver = { - enable = true; - xkb = { - layout = "us,ru"; - variant = ""; - # options = "grp:alt_shift_toggle"; - }; - }; - libinput.enable = true; - colord.enable = true; - printing = { - enable = true; - cups-pdf.enable = true; - }; - }; # environment = { # systemPackages = [ # pkgs.pcbu-desktop diff --git a/modules/essentials/default.nix b/modules/essentials/default.nix index 3a8a275..b0dfb51 100644 --- a/modules/essentials/default.nix +++ b/modules/essentials/default.nix @@ -7,6 +7,7 @@ ./packages.nix ./services.nix ./settings.nix + ./ssh.nix ./systemd-routines.nix ./shell.nix ]; diff --git a/modules/essentials/services.nix b/modules/essentials/services.nix index 519f1fb..7c011a8 100644 --- a/modules/essentials/services.nix +++ b/modules/essentials/services.nix @@ -1,13 +1,15 @@ { - config, - inputs, lib, - pkgs, xlib, ... }: { - services = { - tailscale.enable = xlib.device.type != "wsl"; # true, if not wsl - }; + services.tailscale.enable = xlib.device.type != "wsl"; # true, if not wsl + + # All real hosts (not the bare "minimal" test config) get OOM protection + # and a bounded journal. + services.earlyoom.enable = lib.mkIf (xlib.device.type != "minimal") true; + services.journald.extraConfig = lib.mkIf (xlib.device.type != "minimal") '' + SystemMaxUse=512M + ''; } diff --git a/modules/essentials/ssh.nix b/modules/essentials/ssh.nix new file mode 100644 index 0000000..4069fbb --- /dev/null +++ b/modules/essentials/ssh.nix @@ -0,0 +1,23 @@ +{ + config, + lib, + ... +}: +lib.mkIf config.xlib.ssh.enable { + services.openssh = { + enable = true; + allowSFTP = true; + openFirewall = lib.mkDefault false; + hostKeys = [ + { + path = "/etc/ssh/id_ed25519"; + type = "ed25519"; + } + ]; + settings = { + PasswordAuthentication = false; + PermitRootLogin = "yes"; + UsePAM = true; + }; + }; +} diff --git a/modules/minimal/default.nix b/modules/minimal/default.nix deleted file mode 100644 index 17268e1..0000000 --- a/modules/minimal/default.nix +++ /dev/null @@ -1,7 +0,0 @@ -{ - lib, - pkgs, - ... -}: -{ -} diff --git a/modules/options.nix b/modules/options.nix index bb4a3f6..66ff180 100644 --- a/modules/options.nix +++ b/modules/options.nix @@ -31,6 +31,13 @@ description = "Hostname..."; }; }; + ssh = { + enable = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Enable SSH server with the standard config."; + }; + }; dirs = { user-home = lib.mkOption { type = lib.types.str; diff --git a/modules/primary/default.nix b/modules/primary/default.nix deleted file mode 100644 index e343ffa..0000000 --- a/modules/primary/default.nix +++ /dev/null @@ -1,9 +0,0 @@ -{ - lib, - ... -}: -{ - imports = [ - ../desktop - ]; -} diff --git a/modules/secondary/default.nix b/modules/secondary/default.nix deleted file mode 100644 index e343ffa..0000000 --- a/modules/secondary/default.nix +++ /dev/null @@ -1,9 +0,0 @@ -{ - lib, - ... -}: -{ - imports = [ - ../desktop - ]; -}