From 1f4ec6b8cd4048d25d068de27258828fd04c6b82 Mon Sep 17 00:00:00 2001 From: moons Date: Mon, 27 Jul 2026 23:45:54 +0900 Subject: [PATCH] x1g13 --- AGENTS.md | 48 +++++++++++--- hosts/default.nix | 22 +++++++ hosts/x1g13/disko.nix | 89 ++++++++++++++++++++++++++ hosts/x1g13/hardware-configuration.nix | 32 +++++++++ hosts/x1g13/home.nix | 9 +++ hosts/x1g13/nixos.nix | 9 +++ 6 files changed, 201 insertions(+), 8 deletions(-) create mode 100644 hosts/x1g13/disko.nix create mode 100644 hosts/x1g13/hardware-configuration.nix create mode 100644 hosts/x1g13/home.nix create mode 100644 hosts/x1g13/nixos.nix diff --git a/AGENTS.md b/AGENTS.md index 6db36b1..027dbe1 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -504,6 +504,28 @@ A host registry may use a specification like this: ]; }; + x1g13 = { + system = "x86_64-linux"; + stateVersion = "26.05"; + user = "moons"; + path = ./x1g13; + + profiles = [ + "base" + "interface.cli" + "interface.gnome" + "interface.niri" + "networking.tailscale-client" + "platform.thinkpad-x1" + "security.fingerprint" + "security.secrets" + "security.secure-boot" + "security.tpm-storage" + "workload.development" + "workload.personal" + ]; + }; + m2 = { system = "aarch64-darwin"; stateVersion = "26.05"; @@ -524,9 +546,12 @@ A host registry may use a specification like this: The current role assignment is intentional: x1g9 is a full NixOS desktop with niri, GNOME, ly, the shared Linux desktop applications, and the personal -workload. m2 is the daily-use macOS development and personal machine with the -macOS interface defaults. Keep the desktop sessions independently selectable, -and keep m2's development and personal profiles usable on Darwin. +workload. x1g13 is the secure NixOS development and personal ThinkPad, with the +same desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed +disk unlock. m2 is the daily-use macOS development and personal machine with +the macOS interface defaults. Keep the desktop sessions independently +selectable, and keep the development and personal profiles usable across NixOS +and Darwin. Treat entries in `profiles` and the exceptional `applications` field as IDs relative to their respective category roots. Add the category prefixes during @@ -559,14 +584,20 @@ hosts/ ├── x1g9/ │ ├── nixos.nix │ └── hardware-configuration.nix +├── x1g13/ +│ ├── nixos.nix +│ ├── home.nix +│ ├── disko.nix +│ └── hardware-configuration.nix └── m2/ └── darwin.nix ``` `hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the -normal top-level Nix module `imports`. A future host-local `disko.nix` would be -loaded the same way. Do not confuse these host imports with the prohibition on -top-level `imports` in unit configuration fragments. +normal top-level Nix module `imports`. `hosts/x1g13/nixos.nix` loads its +generated hardware configuration and host-local `disko.nix` the same way. Do +not confuse these host imports with the prohibition on top-level `imports` in +unit configuration fragments. Derive the system class from the host's `system`: @@ -664,8 +695,9 @@ For profile changes, additionally: - When adding a Darwin application fragment, verify the resulting `homebrew.casks` selection as well as module evaluation. - Preserve the intended host roles: x1g9 provides niri, GNOME, ly, and the - personal application set, while m2 remains the daily-use development and - personal machine. + personal application set; x1g13 additionally provides the development, + Tailscale client, secrets, Secure Boot, and TPM storage roles; m2 remains the + daily-use development and personal machine. ## Commit and Pull Request Guidelines diff --git a/hosts/default.nix b/hosts/default.nix index 8858b66..fdb725c 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -17,6 +17,28 @@ ]; }; + x1g13 = { + system = "x86_64-linux"; + stateVersion = "26.05"; + user = "moons"; + path = ./x1g13; + + profiles = [ + "base" + "interface.cli" + "interface.gnome" + "interface.niri" + "networking.tailscale-client" + "platform.thinkpad-x1" + "security.fingerprint" + "security.secrets" + "security.secure-boot" + "security.tpm-storage" + "workload.development" + "workload.personal" + ]; + }; + m2 = { system = "aarch64-darwin"; stateVersion = "26.05"; diff --git a/hosts/x1g13/disko.nix b/hosts/x1g13/disko.nix new file mode 100644 index 0000000..82d5288 --- /dev/null +++ b/hosts/x1g13/disko.nix @@ -0,0 +1,89 @@ +_: +let + espPart = "/dev/disk/by-partuuid/a53e3b19-67de-40de-9ded-3eac3117689a"; + nixosPart = "/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e"; + + btrfsMountOptions = [ + "compress=zstd" + "noatime" + "ssd" + "space_cache=v2" + ]; +in +{ + disko.enableConfig = true; + + disko.devices.disk = { + esp = { + type = "disk"; + device = espPart; + destroy = false; + + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + mountOptions = [ "umask=0077" ]; + }; + }; + + nixos = { + type = "disk"; + device = nixosPart; + destroy = false; + + content = { + type = "luks"; + name = "cryptroot"; + askPassword = true; + settings.allowDiscards = true; + + extraFormatArgs = [ + "--type" + "luks2" + "--pbkdf" + "argon2id" + "--label" + "NixOS-LUKS" + ]; + + content = { + type = "btrfs"; + extraArgs = [ + "-f" + "-L" + "NixOS" + ]; + + subvolumes = { + "@root" = { + mountpoint = "/"; + mountOptions = btrfsMountOptions; + }; + + "@home" = { + mountpoint = "/home"; + mountOptions = btrfsMountOptions; + }; + + "@nix" = { + mountpoint = "/nix"; + mountOptions = btrfsMountOptions; + }; + + "@log" = { + mountpoint = "/var/log"; + mountOptions = btrfsMountOptions; + }; + + "@swap" = { + mountpoint = "/.swapvol"; + mountOptions = [ "noatime" ]; + swap.swapfile.size = "32G"; + }; + }; + }; + }; + }; + }; +} diff --git a/hosts/x1g13/hardware-configuration.nix b/hosts/x1g13/hardware-configuration.nix new file mode 100644 index 0000000..3c59f0f --- /dev/null +++ b/hosts/x1g13/hardware-configuration.nix @@ -0,0 +1,32 @@ +# Do not modify this file! It was generated by `nixos-generate-config` +# and may be overwritten by future invocations. Make changes in nixos.nix. +{ + config, + lib, + modulesPath, + ... +}: + +{ + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ + "xhci_pci" + "thunderbolt" + "nvme" + "usb_storage" + "sd_mod" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.extraModulePackages = [ ]; + + swapDevices = [ ]; + + networking.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/hosts/x1g13/home.nix b/hosts/x1g13/home.nix new file mode 100644 index 0000000..e884ec8 --- /dev/null +++ b/hosts/x1g13/home.nix @@ -0,0 +1,9 @@ +{ + programs.niri.settings.outputs."eDP-1" = { + scale = 1.2; + position = { + x = 0; + y = 0; + }; + }; +} diff --git a/hosts/x1g13/nixos.nix b/hosts/x1g13/nixos.nix new file mode 100644 index 0000000..3b3f5a7 --- /dev/null +++ b/hosts/x1g13/nixos.nix @@ -0,0 +1,9 @@ +{ + imports = [ + ./hardware-configuration.nix + ./disko.nix + ]; + + boot.initrd.luks.devices.cryptroot.device = + "/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e"; +}