This commit is contained in:
2026-07-27 23:45:54 +09:00
parent 5132a1af1b
commit 1f4ec6b8cd
6 changed files with 201 additions and 8 deletions
+40 -8
View File
@@ -504,6 +504,28 @@ A host registry may use a specification like this:
]; ];
}; };
x1g13 = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./x1g13;
profiles = [
"base"
"interface.cli"
"interface.gnome"
"interface.niri"
"networking.tailscale-client"
"platform.thinkpad-x1"
"security.fingerprint"
"security.secrets"
"security.secure-boot"
"security.tpm-storage"
"workload.development"
"workload.personal"
];
};
m2 = { m2 = {
system = "aarch64-darwin"; system = "aarch64-darwin";
stateVersion = "26.05"; stateVersion = "26.05";
@@ -524,9 +546,12 @@ A host registry may use a specification like this:
The current role assignment is intentional: x1g9 is a full NixOS desktop with The current role assignment is intentional: x1g9 is a full NixOS desktop with
niri, GNOME, ly, the shared Linux desktop applications, and the personal niri, GNOME, ly, the shared Linux desktop applications, and the personal
workload. m2 is the daily-use macOS development and personal machine with the workload. x1g13 is the secure NixOS development and personal ThinkPad, with the
macOS interface defaults. Keep the desktop sessions independently selectable, same desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed
and keep m2's development and personal profiles usable on Darwin. disk unlock. m2 is the daily-use macOS development and personal machine with
the macOS interface defaults. Keep the desktop sessions independently
selectable, and keep the development and personal profiles usable across NixOS
and Darwin.
Treat entries in `profiles` and the exceptional `applications` field as IDs Treat entries in `profiles` and the exceptional `applications` field as IDs
relative to their respective category roots. Add the category prefixes during relative to their respective category roots. Add the category prefixes during
@@ -559,14 +584,20 @@ hosts/
├── x1g9/ ├── x1g9/
│ ├── nixos.nix │ ├── nixos.nix
│ └── hardware-configuration.nix │ └── hardware-configuration.nix
├── x1g13/
│ ├── nixos.nix
│ ├── home.nix
│ ├── disko.nix
│ └── hardware-configuration.nix
└── m2/ └── m2/
└── darwin.nix └── darwin.nix
``` ```
`hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the `hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the
normal top-level Nix module `imports`. A future host-local `disko.nix` would be normal top-level Nix module `imports`. `hosts/x1g13/nixos.nix` loads its
loaded the same way. Do not confuse these host imports with the prohibition on generated hardware configuration and host-local `disko.nix` the same way. Do
top-level `imports` in unit configuration fragments. not confuse these host imports with the prohibition on top-level `imports` in
unit configuration fragments.
Derive the system class from the host's `system`: Derive the system class from the host's `system`:
@@ -664,8 +695,9 @@ For profile changes, additionally:
- When adding a Darwin application fragment, verify the resulting - When adding a Darwin application fragment, verify the resulting
`homebrew.casks` selection as well as module evaluation. `homebrew.casks` selection as well as module evaluation.
- Preserve the intended host roles: x1g9 provides niri, GNOME, ly, and the - Preserve the intended host roles: x1g9 provides niri, GNOME, ly, and the
personal application set, while m2 remains the daily-use development and personal application set; x1g13 additionally provides the development,
personal machine. Tailscale client, secrets, Secure Boot, and TPM storage roles; m2 remains the
daily-use development and personal machine.
## Commit and Pull Request Guidelines ## Commit and Pull Request Guidelines
+22
View File
@@ -17,6 +17,28 @@
]; ];
}; };
x1g13 = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./x1g13;
profiles = [
"base"
"interface.cli"
"interface.gnome"
"interface.niri"
"networking.tailscale-client"
"platform.thinkpad-x1"
"security.fingerprint"
"security.secrets"
"security.secure-boot"
"security.tpm-storage"
"workload.development"
"workload.personal"
];
};
m2 = { m2 = {
system = "aarch64-darwin"; system = "aarch64-darwin";
stateVersion = "26.05"; stateVersion = "26.05";
+89
View File
@@ -0,0 +1,89 @@
_:
let
espPart = "/dev/disk/by-partuuid/a53e3b19-67de-40de-9ded-3eac3117689a";
nixosPart = "/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e";
btrfsMountOptions = [
"compress=zstd"
"noatime"
"ssd"
"space_cache=v2"
];
in
{
disko.enableConfig = true;
disko.devices.disk = {
esp = {
type = "disk";
device = espPart;
destroy = false;
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
nixos = {
type = "disk";
device = nixosPart;
destroy = false;
content = {
type = "luks";
name = "cryptroot";
askPassword = true;
settings.allowDiscards = true;
extraFormatArgs = [
"--type"
"luks2"
"--pbkdf"
"argon2id"
"--label"
"NixOS-LUKS"
];
content = {
type = "btrfs";
extraArgs = [
"-f"
"-L"
"NixOS"
];
subvolumes = {
"@root" = {
mountpoint = "/";
mountOptions = btrfsMountOptions;
};
"@home" = {
mountpoint = "/home";
mountOptions = btrfsMountOptions;
};
"@nix" = {
mountpoint = "/nix";
mountOptions = btrfsMountOptions;
};
"@log" = {
mountpoint = "/var/log";
mountOptions = btrfsMountOptions;
};
"@swap" = {
mountpoint = "/.swapvol";
mountOptions = [ "noatime" ];
swap.swapfile.size = "32G";
};
};
};
};
};
};
}
+32
View File
@@ -0,0 +1,32 @@
# Do not modify this file! It was generated by `nixos-generate-config`
# and may be overwritten by future invocations. Make changes in nixos.nix.
{
config,
lib,
modulesPath,
...
}:
{
imports = [
(modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [
"xhci_pci"
"thunderbolt"
"nvme"
"usb_storage"
"sd_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
swapDevices = [ ];
networking.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
+9
View File
@@ -0,0 +1,9 @@
{
programs.niri.settings.outputs."eDP-1" = {
scale = 1.2;
position = {
x = 0;
y = 0;
};
};
}
+9
View File
@@ -0,0 +1,9 @@
{
imports = [
./hardware-configuration.nix
./disko.nix
];
boot.initrd.luks.devices.cryptroot.device =
"/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e";
}