Files
nixos/configurations/server.nix
T
2026-10-03 23:39:21 +03:00

130 lines
4.0 KiB
Nix

# Host: "sapphira" (device: server)
#
# The host record lives in configurations/default.nix; this file is only the
# module body. `xlib` (identity, dirs, helpers) arrives as a module argument.
{
lib,
pkgs,
xlib,
inputs,
...
}:
{
imports = [
./hardware/server.nix
inputs.self.nixosModules.default
];
boot = {
# kernelPackages = pkgs.linuxPackages_xanmod_stable;
hardwareScan = true;
loader = {
systemd-boot.enable = lib.mkDefault true;
efi.canTouchEfiVariables = lib.mkDefault true;
};
};
hardware = {
bluetooth.enable = true;
graphics = {
enable = true;
extraPackages = with pkgs; [
intel-media-driver
intel-ocl
intel-vaapi-driver
];
};
intel-gpu-tools.enable = true;
};
fileSystems =
(xlib.helpers.mkExfatMount {
path = xlib.dirs.archive-drive;
label = "archive";
})
// (xlib.helpers.mkExfatMount {
path = xlib.dirs.mobile-drive;
uuid = "7EB1-DC99";
})
// (xlib.helpers.mkBindMount {
what = xlib.dirs.services-folder;
where = xlib.dirs.services-mnt-folder;
})
// {
# External drive
"${xlib.dirs.server-home}" = {
device = "/dev/disk/by-uuid/37e53ebc-5343-a94d-9fe2-0ca39e13a8de";
fsType = "ext4";
};
};
systemd.tmpfiles.rules = [
"z ${xlib.dirs.services-mnt-folder} 0777 root root -"
];
host.ssh.enable = true;
# Offload Nix builds to the WSL2 NixOS instance running on vetymae
# (Windows 11 host). Sapphira only has 2 logical cores; the WSL exposes
# 24 cores + 14 GiB. The matchBlock with ProxyCommand is generated by
# modules/server/builder.nix, the other side of the same option lives in
# modules/wsl/builder.nix.
#
# `proxyCommand` is what marks this builder as needing the SSH matchBlock
# (see modules/server/builder.nix). A builder reachable directly would
# omit it.
host.builder.clients = [
{
hostName = "vetymae-nix";
sshUser = "oqyude";
sshKey = "/root/.ssh/id_ed25519";
# NixOS calls this `systems` (plural), not `systemTypes`. The
# default is empty — every derivation is rejected. The WSL NixOS
# runs on x86_64-linux, matching sapphira.
systems = [ "x86_64-linux" ];
# vetymae-nix drops kvm + nixos-test from its advertised
# system-features (see modules/wsl/builder.nix). Listing them here
# would not break anything (Nix intersects), but listing the
# features the WSL actually has is the documented contract.
supportedFeatures = [
"benchmark"
"big-parallel"
];
mandatoryFeatures = [ ];
maxJobs = 24;
speedFactor = 0.5;
# Keep the SSH session alive across many small builds in one daemon
# session — compile-heavy workloads spam the daemon with hundreds of
# derivations and ControlMaster collapses those into one Windows hop.
# NB: `nix.buildMachines` has no `sshOptions` attribute, so the
# ControlMaster directive lives in the SSH matchBlock instead (see
# modules/server/builder.nix).
#
# The OpenSSH alias for this host (matches the user's
# ~/.ssh/config so known_hosts entries do not collide with the
# Windows OpenSSH entry on 127.0.0.1/vetymae) is consumed only by
# the SSH matchBlock below — not by `nix.buildMachines`, which has
# no such attribute.
hostKeyAlias = "wsl-nixos-on-vetymae";
# Use the Windows host's IP directly so the nix-daemon (running as
# root, without the user's ~/.ssh/config) does not need a separate
# `vetymae` host alias. With StrictHostKeyChecking=accept-new the
# first connection adds the Windows host key to /root/.ssh/known_hosts.
proxyCommand = "ssh oqyude@192.168.1.100 'wsl -d NixOS -- nc 127.0.0.1 22'";
}
];
networking = {
networkmanager.enable = true;
firewall.enable = false;
# nameservers = [
# "192.168.1.1"
# "127.0.0.1"
# ];
};
system = {
stateVersion = "25.05";
};
}