This commit is contained in:
2026-08-11 03:05:52 +03:00
parent 871fad26d4
commit 843f0bafa1
20 changed files with 183 additions and 493 deletions
+33 -28
View File
@@ -1,5 +1,12 @@
{ inputs, ... }@flakeContext:
let
# NixOS-only modules. termux runs nix-on-droid (its own module system,
# class = "nixOnDroid"): options like services.*, users.*, sops.*, disko.*
# and nixpkgs.overlays (flake assertion) do not exist there.
moduleArgs = config: {
inherit inputs;
xlib = config.xlib;
};
defaultModule =
{
config,
@@ -8,31 +15,35 @@ let
xlib,
...
}:
{
# NixOS-only modules. termux runs nix-on-droid (its own module system,
# class = "nixOnDroid"): options like services.*, users.*, sops.*, disko.*
# and nixpkgs.overlays (flake assertion) do not exist there.
imports = with inputs; [
./essentials
./options.nix
./users.nix
(./. + "/${deviceType}")
home-manager.nixosModules.home-manager # home-manager module
# nix-index-database.nixosModules.nix-index # nix-index module
grub2-themes.nixosModules.default # grub2 themes module
sops-nix.nixosModules.sops # sops module
self.homeConfigurations.default.nixosModule # default homeConfigurations
disko.nixosModules.disko # disko module
let
isDesktop = builtins.elem deviceType [
"primary"
"secondary"
];
in
{
imports =
with inputs;
[
./essentials
./options.nix
./users.nix
home-manager.nixosModules.home-manager # home-manager module
# nix-index-database.nixosModules.nix-index # nix-index module
grub2-themes.nixosModules.default # grub2 themes module
sops-nix.nixosModules.sops # sops module
self.homeConfigurations.default.nixosModule # default homeConfigurations
disko.nixosModules.disko # disko module
]
++ lib.optional isDesktop ../desktop # desktop class: primary/secondary
# device-type module dir; "minimal" has no extra modules
++ lib.optional (!isDesktop && deviceType != "minimal") (./. + "/${deviceType}");
nixpkgs.overlays = with inputs; [
self.nixosOverlays.default
];
networking.hostName = lib.mkDefault config.xlib.device.hostname;
_module.args = {
inputs = inputs;
xlib = config.xlib;
};
_module.args = moduleArgs config;
};
publicModule =
{
@@ -51,10 +62,7 @@ let
sops-nix.nixosModules.sops # sops module
];
_module.args = {
inputs = inputs;
xlib = config.xlib;
};
_module.args = moduleArgs config;
};
strictModule =
{
@@ -73,10 +81,7 @@ let
# sops-nix.nixosModules.sops
];
_module.args = {
inputs = inputs;
xlib = config.xlib;
};
_module.args = moduleArgs config;
};
in
{
+49 -16
View File
@@ -3,6 +3,7 @@
inputs,
lib,
pkgs,
xlib,
...
}:
{
@@ -11,6 +12,54 @@
./theming.nix
];
# Things every desktop host has in common
hardware.bluetooth.enable = true;
i18n.extraLocaleSettings = {
LC_ADDRESS = "ru_RU.UTF-8";
LC_IDENTIFICATION = "ru_RU.UTF-8";
LC_MEASUREMENT = "ru_RU.UTF-8";
LC_MONETARY = "ru_RU.UTF-8";
LC_NAME = "ru_RU.UTF-8";
LC_NUMERIC = "ru_RU.UTF-8";
LC_PAPER = "ru_RU.UTF-8";
LC_TELEPHONE = "ru_RU.UTF-8";
LC_TIME = "ru_RU.UTF-8";
};
networking = {
networkmanager.enable = true;
firewall.enable = false;
};
security.rtkit.enable = true;
services = {
syncthing = {
enable = true;
systemService = true;
configDir = "${xlib.dirs.user-storage}/Syncthing/${config.system.name}";
dataDir = "${xlib.dirs.user-home}";
group = "users";
user = "${xlib.device.username}";
};
thermald.enable = true;
xserver = {
enable = true;
xkb = {
layout = "us,ru";
variant = "";
# options = "grp:alt_shift_toggle";
};
};
libinput.enable = true;
colord.enable = true;
printing = {
enable = true;
cups-pdf.enable = true;
};
};
boot = {
plymouth = {
enable = true;
@@ -53,22 +102,6 @@
steam.enable = true;
xwayland.enable = true;
};
services = {
xserver = {
enable = true;
xkb = {
layout = "us,ru";
variant = "";
# options = "grp:alt_shift_toggle";
};
};
libinput.enable = true;
colord.enable = true;
printing = {
enable = true;
cups-pdf.enable = true;
};
};
# environment = {
# systemPackages = [
# pkgs.pcbu-desktop
+1
View File
@@ -7,6 +7,7 @@
./packages.nix
./services.nix
./settings.nix
./ssh.nix
./systemd-routines.nix
./shell.nix
];
+8 -6
View File
@@ -1,13 +1,15 @@
{
config,
inputs,
lib,
pkgs,
xlib,
...
}:
{
services = {
tailscale.enable = xlib.device.type != "wsl"; # true, if not wsl
};
services.tailscale.enable = xlib.device.type != "wsl"; # true, if not wsl
# All real hosts (not the bare "minimal" test config) get OOM protection
# and a bounded journal.
services.earlyoom.enable = lib.mkIf (xlib.device.type != "minimal") true;
services.journald.extraConfig = lib.mkIf (xlib.device.type != "minimal") ''
SystemMaxUse=512M
'';
}
+23
View File
@@ -0,0 +1,23 @@
{
config,
lib,
...
}:
lib.mkIf config.xlib.ssh.enable {
services.openssh = {
enable = true;
allowSFTP = true;
openFirewall = lib.mkDefault false;
hostKeys = [
{
path = "/etc/ssh/id_ed25519";
type = "ed25519";
}
];
settings = {
PasswordAuthentication = false;
PermitRootLogin = "yes";
UsePAM = true;
};
};
}
-7
View File
@@ -1,7 +0,0 @@
{
lib,
pkgs,
...
}:
{
}
+7
View File
@@ -31,6 +31,13 @@
description = "Hostname...";
};
};
ssh = {
enable = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Enable SSH server with the standard config.";
};
};
dirs = {
user-home = lib.mkOption {
type = lib.types.str;
-9
View File
@@ -1,9 +0,0 @@
{
lib,
...
}:
{
imports = [
../desktop
];
}
-9
View File
@@ -1,9 +0,0 @@
{
lib,
...
}:
{
imports = [
../desktop
];
}