mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-06 04:08:12 +09:00
delete
This commit is contained in:
@@ -1,113 +0,0 @@
|
||||
{
|
||||
inputs,
|
||||
config,
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
let
|
||||
inherit (inputs.nixpkgs.lib) nixosSystem;
|
||||
|
||||
username = "moons";
|
||||
|
||||
mkSystem =
|
||||
{
|
||||
host,
|
||||
system,
|
||||
profiles ? [ ],
|
||||
extraModules ? [ ],
|
||||
}:
|
||||
let
|
||||
unstable = import inputs.nixpkgs-unstable {
|
||||
inherit system;
|
||||
config = {
|
||||
allowUnfree = true;
|
||||
};
|
||||
};
|
||||
in
|
||||
assert lib.assertMsg (lib.elem system config.systems)
|
||||
"mkSystem: system '${system}' not in valid systems: ${lib.generators.toPretty { } config.systems}";
|
||||
nixosSystem {
|
||||
inherit system;
|
||||
modules = [
|
||||
{
|
||||
nixpkgs.config.allowUnfree = true;
|
||||
nixpkgs.overlays = builtins.attrValues inputs.self.overlays;
|
||||
}
|
||||
../modules
|
||||
./${host}/default.nix
|
||||
]
|
||||
++ map (p: ../profiles/${p}.nix) profiles
|
||||
++ extraModules;
|
||||
specialArgs = {
|
||||
inherit
|
||||
inputs
|
||||
username
|
||||
unstable
|
||||
host
|
||||
;
|
||||
};
|
||||
};
|
||||
|
||||
nixosConfigurations = {
|
||||
nix-example = mkSystem {
|
||||
host = "nix-example";
|
||||
system = "x86_64-linux";
|
||||
profiles = [
|
||||
"interfaces/cli-interactive"
|
||||
"platforms/vm"
|
||||
"workloads/dev"
|
||||
"workloads/remote"
|
||||
];
|
||||
};
|
||||
ops = mkSystem {
|
||||
host = "ops";
|
||||
system = "x86_64-linux";
|
||||
profiles = [
|
||||
"interfaces/cli-interactive"
|
||||
"platforms/vm"
|
||||
"workloads/remote"
|
||||
];
|
||||
};
|
||||
|
||||
internal-app-01 = mkSystem {
|
||||
host = "internal-app-01";
|
||||
system = "x86_64-linux";
|
||||
profiles = [
|
||||
"interfaces/cli-interactive"
|
||||
"platforms/vm"
|
||||
"workloads/srv"
|
||||
];
|
||||
};
|
||||
x1g13 = mkSystem {
|
||||
host = "x1g13";
|
||||
system = "x86_64-linux";
|
||||
profiles = [
|
||||
"interfaces/gui"
|
||||
"platforms/thinkpad"
|
||||
"workloads/dev"
|
||||
"workloads/personal"
|
||||
"workloads/secure-storage"
|
||||
"workloads/tailscale/client"
|
||||
];
|
||||
};
|
||||
|
||||
installer = nixosSystem {
|
||||
system = "x86_64-linux";
|
||||
modules = [
|
||||
./installer/default.nix
|
||||
];
|
||||
specialArgs = {
|
||||
inherit inputs;
|
||||
};
|
||||
};
|
||||
};
|
||||
in
|
||||
{
|
||||
flake = {
|
||||
inherit nixosConfigurations;
|
||||
|
||||
checks.x86_64-linux = lib.mapAttrs' (
|
||||
name: nixos: lib.nameValuePair "nixos-${name}" nixos.config.system.build.toplevel
|
||||
) nixosConfigurations;
|
||||
};
|
||||
}
|
||||
@@ -1,193 +0,0 @@
|
||||
{
|
||||
pkgs,
|
||||
lib,
|
||||
modulesPath,
|
||||
...
|
||||
}:
|
||||
{
|
||||
imports = [
|
||||
"${modulesPath}/installer/cd-dvd/installation-cd-minimal.nix"
|
||||
];
|
||||
|
||||
boot.zfs.forceImportRoot = false;
|
||||
|
||||
networking = {
|
||||
hostName = "nixos-installer";
|
||||
|
||||
networkmanager = {
|
||||
enable = true;
|
||||
wifi.powersave = false;
|
||||
};
|
||||
};
|
||||
|
||||
services.openssh = {
|
||||
enable = true;
|
||||
settings = {
|
||||
PermitRootLogin = "prohibit-password";
|
||||
PasswordAuthentication = false;
|
||||
KbdInteractiveAuthentication = false;
|
||||
PubkeyAuthentication = "yes";
|
||||
};
|
||||
};
|
||||
|
||||
users.users.root.openssh.authorizedKeys.keys = [
|
||||
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIKhxDkucmeCor6CKoXAua7DgDSzuXrZOtpdkyzQxz5+aAAAABHNzaDo= moons@moons14.com"
|
||||
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIN6hZJyng/5LgFKPjR6uZAd/00UkO0vN0uQOoIvfSELdAAAABHNzaDo= moons@moons14.com"
|
||||
];
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
git # Clone dotfiles repository
|
||||
disko # Disk partitioning
|
||||
sops # Secrets management
|
||||
age # Age encryption
|
||||
ssh-to-age # Convert SSH keys to age
|
||||
age-plugin-yubikey # YubiKey support
|
||||
yubikey-manager # YubiKey management
|
||||
pcsc-tools # Smart card tools
|
||||
mkpasswd # Password hash generation
|
||||
rsync # File synchronization
|
||||
vim # Text editor
|
||||
wget # Download files
|
||||
curl # HTTP client
|
||||
jq # JSON processor
|
||||
parted # Partition tools
|
||||
cryptsetup # LUKS encryption
|
||||
btrfs-progs # Btrfs filesystem tools
|
||||
];
|
||||
|
||||
services.pcscd.enable = true;
|
||||
|
||||
environment.etc."installer-help.txt".text = ''
|
||||
|
||||
╔══════════════════════════════════════════════════════════════╗
|
||||
║ NixOS Installer ISO ║
|
||||
╠══════════════════════════════════════════════════════════════╣
|
||||
║ ║
|
||||
║ SSH Access: ║
|
||||
║ ssh root@<ip-address> ║
|
||||
║ ║
|
||||
║ Network Setup: ║
|
||||
║ Wired: Auto-configured via DHCP ║
|
||||
║ WiFi: nmcli device wifi connect <SSID> --ask ║
|
||||
║ ║
|
||||
║ Installation Workflow: ║
|
||||
║ ║
|
||||
║ 1. Clone dotfiles: ║
|
||||
║ git clone git@github.com:moons-14/dotfiles.git ~/dotfiles║
|
||||
║ ║
|
||||
║ 2. Generate SSH host key for new host: ║
|
||||
║ ssh-keygen -t ed25519 -f /tmp/ssh_host_ed25519_key -N "" ║
|
||||
║ ║
|
||||
║ 3. Get age public key from SSH host key: ║
|
||||
║ ssh-to-age -i /tmp/ssh_host_ed25519_key.pub ║
|
||||
║ ║
|
||||
║ 4. Add age key to .sops.yaml: ║
|
||||
║ cd ~/dotfiles ║
|
||||
║ # Edit .sops.yaml and add the age key ║
|
||||
║ # Add new host entry to creation_rules ║
|
||||
║ ║
|
||||
║ 5. Re-encrypt secrets: ║
|
||||
║ sops updatekeys secrets/common/system.yaml ║
|
||||
║ sops updatekeys secrets/hosts/<host>/*.yaml ║
|
||||
║ ║
|
||||
║ 6. Create disko.nix for new host: ║
|
||||
║ # Check disk devices ║
|
||||
║ lsblk -f ║
|
||||
║ ║
|
||||
║ # Create hosts/<host>/disko.nix ║
|
||||
║ # Example: LUKS + btrfs ║
|
||||
║ # See hosts/x1g13/disko.nix for reference ║
|
||||
║ ║
|
||||
║ 7. Partition disk with disko: ║
|
||||
║ nix run github:nix-community/disko -- \ ║
|
||||
║ --mode disko hosts/<host>/disko.nix ║
|
||||
║ ║
|
||||
║ 8. Copy host key to installed system: ║
|
||||
║ mkdir -p /mnt/etc/ssh ║
|
||||
║ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ ║
|
||||
║ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ║
|
||||
║ ║
|
||||
║ 9. Install NixOS: ║
|
||||
║ nixos-install --flake ~/dotfiles#<host> ║
|
||||
║ ║
|
||||
║ Disko Configuration Examples: ║
|
||||
║ ║
|
||||
║ Simple (no encryption): ║
|
||||
║ disko.devices.disk.main = { ║
|
||||
║ type = "disk"; ║
|
||||
║ device = "/dev/sda"; ║
|
||||
║ content = { ║
|
||||
║ type = "gpt"; ║
|
||||
║ partitions = { ║
|
||||
║ ESP = { size = "512M"; type = "EF00"; ║
|
||||
║ content = { type = "filesystem"; ║
|
||||
║ format = "vfat"; mountpoint = "/boot"; }; }; ║
|
||||
║ root = { size = "100%"; ║
|
||||
║ content = { type = "filesystem"; ║
|
||||
║ format = "ext4"; mountpoint = "/"; }; }; ║
|
||||
║ }; ║
|
||||
║ }; ║
|
||||
║ }; ║
|
||||
║ ║
|
||||
║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║
|
||||
║ - Use partuuid for device path ║
|
||||
║ - Set askPassword = true for LUKS ║
|
||||
║ - Configure btrfs subvolumes ║
|
||||
║ ║
|
||||
╚══════════════════════════════════════════════════════════════╝
|
||||
|
||||
'';
|
||||
|
||||
systemd.services.installer-banner = {
|
||||
description = "Display installer help on console";
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
ExecStart = "${pkgs.coreutils}/bin/cat /etc/installer-help.txt";
|
||||
StandardOutput = "tty";
|
||||
TTYPath = "/dev/tty1";
|
||||
};
|
||||
};
|
||||
|
||||
systemd.services.display-ip = {
|
||||
description = "Display IP address on console";
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
after = [ "network-online.target" ];
|
||||
wants = [ "network-online.target" ];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
ExecStart = pkgs.writeShellScript "display-ip" ''
|
||||
sleep 2
|
||||
echo ""
|
||||
echo "=== Network Interfaces ==="
|
||||
${pkgs.iproute2}/bin/ip -4 addr show | ${pkgs.gnugrep}/bin/grep inet
|
||||
echo ""
|
||||
echo "=== SSH Access ==="
|
||||
for ip in $(${pkgs.iproute2}/bin/ip -4 addr show | ${pkgs.gnugrep}/bin/grep -oP 'inet \K[\d.]+' | ${pkgs.gnugrep}/bin/grep -v '127.0.0.1'); do
|
||||
echo " ssh root@$ip"
|
||||
done
|
||||
echo ""
|
||||
'';
|
||||
StandardOutput = "tty";
|
||||
TTYPath = "/dev/tty1";
|
||||
};
|
||||
};
|
||||
|
||||
nix = {
|
||||
settings = {
|
||||
experimental-features = [
|
||||
"nix-command"
|
||||
"flakes"
|
||||
];
|
||||
trusted-users = [ "root" ];
|
||||
};
|
||||
|
||||
extraOptions = ''
|
||||
experimental-features = nix-command flakes
|
||||
'';
|
||||
};
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
|
||||
system.stateVersion = "26.05";
|
||||
}
|
||||
@@ -1,6 +0,0 @@
|
||||
{ ... }:
|
||||
{
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
];
|
||||
}
|
||||
@@ -1,40 +0,0 @@
|
||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{ lib, modulesPath, ... }:
|
||||
|
||||
{
|
||||
imports = [
|
||||
(modulesPath + "/profiles/qemu-guest.nix")
|
||||
];
|
||||
|
||||
boot.initrd.availableKernelModules = [
|
||||
"ata_piix"
|
||||
"uhci_hcd"
|
||||
"virtio_pci"
|
||||
"virtio_scsi"
|
||||
"sd_mod"
|
||||
"sr_mod"
|
||||
];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
fileSystems."/" = {
|
||||
device = "/dev/disk/by-uuid/1b12ab98-2537-4207-a3f4-bb8ba7b53b00";
|
||||
fsType = "ext4";
|
||||
};
|
||||
|
||||
fileSystems."/boot" = {
|
||||
device = "/dev/disk/by-uuid/8365-C778";
|
||||
fsType = "vfat";
|
||||
options = [
|
||||
"fmask=0077"
|
||||
"dmask=0077"
|
||||
];
|
||||
};
|
||||
|
||||
swapDevices = [ ];
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
}
|
||||
@@ -1,6 +0,0 @@
|
||||
{ ... }:
|
||||
{
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
];
|
||||
}
|
||||
@@ -1,43 +0,0 @@
|
||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{
|
||||
lib,
|
||||
modulesPath,
|
||||
...
|
||||
}:
|
||||
{
|
||||
imports = [
|
||||
(modulesPath + "/profiles/qemu-guest.nix")
|
||||
];
|
||||
|
||||
boot.initrd.availableKernelModules = [
|
||||
"ata_piix"
|
||||
"uhci_hcd"
|
||||
"virtio_pci"
|
||||
"virtio_scsi"
|
||||
"sd_mod"
|
||||
"sr_mod"
|
||||
];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
fileSystems."/" = {
|
||||
device = "/dev/disk/by-uuid/8f0eaec6-5dc9-4821-aa8d-fb6809b5a5bf";
|
||||
fsType = "ext4";
|
||||
};
|
||||
|
||||
fileSystems."/boot" = {
|
||||
device = "/dev/disk/by-uuid/201C-961B";
|
||||
fsType = "vfat";
|
||||
options = [
|
||||
"fmask=0077"
|
||||
"dmask=0077"
|
||||
];
|
||||
};
|
||||
|
||||
swapDevices = [ ];
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
}
|
||||
@@ -1,56 +0,0 @@
|
||||
{ ... }:
|
||||
{
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
];
|
||||
|
||||
networking = {
|
||||
useDHCP = false;
|
||||
|
||||
interfaces = {
|
||||
ens18 = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.128.20";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
ens19 = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.7.101";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
ens20 = {
|
||||
useDHCP = false;
|
||||
ipv4.routes = [
|
||||
{
|
||||
address = "10.50.64.0";
|
||||
prefixLength = 24;
|
||||
via = "10.50.82.1";
|
||||
}
|
||||
];
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.82.10";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
defaultGateway = {
|
||||
address = "10.50.128.1";
|
||||
interface = "ens18";
|
||||
};
|
||||
|
||||
};
|
||||
}
|
||||
@@ -1,44 +0,0 @@
|
||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{
|
||||
lib,
|
||||
modulesPath,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
imports = [
|
||||
(modulesPath + "/profiles/qemu-guest.nix")
|
||||
];
|
||||
|
||||
boot.initrd.availableKernelModules = [
|
||||
"ata_piix"
|
||||
"uhci_hcd"
|
||||
"virtio_pci"
|
||||
"virtio_scsi"
|
||||
"sd_mod"
|
||||
"sr_mod"
|
||||
];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
fileSystems."/" = {
|
||||
device = "/dev/disk/by-uuid/69fa2193-1e4f-438a-8898-5de8a3f36e5b";
|
||||
fsType = "ext4";
|
||||
};
|
||||
|
||||
fileSystems."/boot" = {
|
||||
device = "/dev/disk/by-uuid/D09B-4277";
|
||||
fsType = "vfat";
|
||||
options = [
|
||||
"fmask=0077"
|
||||
"dmask=0077"
|
||||
];
|
||||
};
|
||||
|
||||
swapDevices = [ ];
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
}
|
||||
@@ -1,10 +0,0 @@
|
||||
{ ... }:
|
||||
{
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
./disko.nix
|
||||
];
|
||||
|
||||
boot.initrd.luks.devices.cryptroot.device =
|
||||
"/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e";
|
||||
}
|
||||
@@ -1,99 +0,0 @@
|
||||
_:
|
||||
let
|
||||
espPart = "/dev/disk/by-partuuid/a53e3b19-67de-40de-9ded-3eac3117689a";
|
||||
|
||||
nixosPart = "/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e";
|
||||
|
||||
btrfsMountOptions = [
|
||||
"compress=zstd"
|
||||
"noatime"
|
||||
"ssd"
|
||||
"space_cache=v2"
|
||||
];
|
||||
in
|
||||
{
|
||||
disko.enableConfig = true;
|
||||
|
||||
disko.devices.disk = {
|
||||
esp = {
|
||||
type = "disk";
|
||||
device = espPart;
|
||||
destroy = false;
|
||||
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "vfat";
|
||||
mountpoint = "/boot";
|
||||
mountOptions = [
|
||||
"umask=0077"
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
nixos = {
|
||||
type = "disk";
|
||||
device = nixosPart;
|
||||
destroy = false;
|
||||
|
||||
content = {
|
||||
type = "luks";
|
||||
name = "cryptroot";
|
||||
|
||||
askPassword = true;
|
||||
|
||||
settings = {
|
||||
allowDiscards = true;
|
||||
};
|
||||
|
||||
extraFormatArgs = [
|
||||
"--type"
|
||||
"luks2"
|
||||
"--pbkdf"
|
||||
"argon2id"
|
||||
"--label"
|
||||
"NixOS-LUKS"
|
||||
];
|
||||
|
||||
content = {
|
||||
type = "btrfs";
|
||||
extraArgs = [
|
||||
"-f"
|
||||
"-L"
|
||||
"NixOS"
|
||||
];
|
||||
|
||||
subvolumes = {
|
||||
"@root" = {
|
||||
mountpoint = "/";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"@home" = {
|
||||
mountpoint = "/home";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"@nix" = {
|
||||
mountpoint = "/nix";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"@log" = {
|
||||
mountpoint = "/var/log";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"@swap" = {
|
||||
mountpoint = "/.swapvol";
|
||||
mountOptions = [
|
||||
"noatime"
|
||||
];
|
||||
|
||||
swap.swapfile.size = "32G";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -1,33 +0,0 @@
|
||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
modulesPath,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
imports = [
|
||||
(modulesPath + "/installer/scan/not-detected.nix")
|
||||
];
|
||||
|
||||
boot.initrd.availableKernelModules = [
|
||||
"xhci_pci"
|
||||
"thunderbolt"
|
||||
"nvme"
|
||||
"usb_storage"
|
||||
"sd_mod"
|
||||
];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ "kvm-intel" ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
swapDevices = [ ];
|
||||
|
||||
networking.useDHCP = lib.mkDefault true;
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
|
||||
}
|
||||
Reference in New Issue
Block a user