mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-06 07:08:12 +09:00
x1g13
This commit is contained in:
@@ -504,6 +504,28 @@ A host registry may use a specification like this:
|
|||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
x1g13 = {
|
||||||
|
system = "x86_64-linux";
|
||||||
|
stateVersion = "26.05";
|
||||||
|
user = "moons";
|
||||||
|
path = ./x1g13;
|
||||||
|
|
||||||
|
profiles = [
|
||||||
|
"base"
|
||||||
|
"interface.cli"
|
||||||
|
"interface.gnome"
|
||||||
|
"interface.niri"
|
||||||
|
"networking.tailscale-client"
|
||||||
|
"platform.thinkpad-x1"
|
||||||
|
"security.fingerprint"
|
||||||
|
"security.secrets"
|
||||||
|
"security.secure-boot"
|
||||||
|
"security.tpm-storage"
|
||||||
|
"workload.development"
|
||||||
|
"workload.personal"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
m2 = {
|
m2 = {
|
||||||
system = "aarch64-darwin";
|
system = "aarch64-darwin";
|
||||||
stateVersion = "26.05";
|
stateVersion = "26.05";
|
||||||
@@ -524,9 +546,12 @@ A host registry may use a specification like this:
|
|||||||
|
|
||||||
The current role assignment is intentional: x1g9 is a full NixOS desktop with
|
The current role assignment is intentional: x1g9 is a full NixOS desktop with
|
||||||
niri, GNOME, ly, the shared Linux desktop applications, and the personal
|
niri, GNOME, ly, the shared Linux desktop applications, and the personal
|
||||||
workload. m2 is the daily-use macOS development and personal machine with the
|
workload. x1g13 is the secure NixOS development and personal ThinkPad, with the
|
||||||
macOS interface defaults. Keep the desktop sessions independently selectable,
|
same desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed
|
||||||
and keep m2's development and personal profiles usable on Darwin.
|
disk unlock. m2 is the daily-use macOS development and personal machine with
|
||||||
|
the macOS interface defaults. Keep the desktop sessions independently
|
||||||
|
selectable, and keep the development and personal profiles usable across NixOS
|
||||||
|
and Darwin.
|
||||||
|
|
||||||
Treat entries in `profiles` and the exceptional `applications` field as IDs
|
Treat entries in `profiles` and the exceptional `applications` field as IDs
|
||||||
relative to their respective category roots. Add the category prefixes during
|
relative to their respective category roots. Add the category prefixes during
|
||||||
@@ -559,14 +584,20 @@ hosts/
|
|||||||
├── x1g9/
|
├── x1g9/
|
||||||
│ ├── nixos.nix
|
│ ├── nixos.nix
|
||||||
│ └── hardware-configuration.nix
|
│ └── hardware-configuration.nix
|
||||||
|
├── x1g13/
|
||||||
|
│ ├── nixos.nix
|
||||||
|
│ ├── home.nix
|
||||||
|
│ ├── disko.nix
|
||||||
|
│ └── hardware-configuration.nix
|
||||||
└── m2/
|
└── m2/
|
||||||
└── darwin.nix
|
└── darwin.nix
|
||||||
```
|
```
|
||||||
|
|
||||||
`hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the
|
`hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the
|
||||||
normal top-level Nix module `imports`. A future host-local `disko.nix` would be
|
normal top-level Nix module `imports`. `hosts/x1g13/nixos.nix` loads its
|
||||||
loaded the same way. Do not confuse these host imports with the prohibition on
|
generated hardware configuration and host-local `disko.nix` the same way. Do
|
||||||
top-level `imports` in unit configuration fragments.
|
not confuse these host imports with the prohibition on top-level `imports` in
|
||||||
|
unit configuration fragments.
|
||||||
|
|
||||||
Derive the system class from the host's `system`:
|
Derive the system class from the host's `system`:
|
||||||
|
|
||||||
@@ -664,8 +695,9 @@ For profile changes, additionally:
|
|||||||
- When adding a Darwin application fragment, verify the resulting
|
- When adding a Darwin application fragment, verify the resulting
|
||||||
`homebrew.casks` selection as well as module evaluation.
|
`homebrew.casks` selection as well as module evaluation.
|
||||||
- Preserve the intended host roles: x1g9 provides niri, GNOME, ly, and the
|
- Preserve the intended host roles: x1g9 provides niri, GNOME, ly, and the
|
||||||
personal application set, while m2 remains the daily-use development and
|
personal application set; x1g13 additionally provides the development,
|
||||||
personal machine.
|
Tailscale client, secrets, Secure Boot, and TPM storage roles; m2 remains the
|
||||||
|
daily-use development and personal machine.
|
||||||
|
|
||||||
## Commit and Pull Request Guidelines
|
## Commit and Pull Request Guidelines
|
||||||
|
|
||||||
|
|||||||
@@ -17,6 +17,28 @@
|
|||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
x1g13 = {
|
||||||
|
system = "x86_64-linux";
|
||||||
|
stateVersion = "26.05";
|
||||||
|
user = "moons";
|
||||||
|
path = ./x1g13;
|
||||||
|
|
||||||
|
profiles = [
|
||||||
|
"base"
|
||||||
|
"interface.cli"
|
||||||
|
"interface.gnome"
|
||||||
|
"interface.niri"
|
||||||
|
"networking.tailscale-client"
|
||||||
|
"platform.thinkpad-x1"
|
||||||
|
"security.fingerprint"
|
||||||
|
"security.secrets"
|
||||||
|
"security.secure-boot"
|
||||||
|
"security.tpm-storage"
|
||||||
|
"workload.development"
|
||||||
|
"workload.personal"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
m2 = {
|
m2 = {
|
||||||
system = "aarch64-darwin";
|
system = "aarch64-darwin";
|
||||||
stateVersion = "26.05";
|
stateVersion = "26.05";
|
||||||
|
|||||||
@@ -0,0 +1,89 @@
|
|||||||
|
_:
|
||||||
|
let
|
||||||
|
espPart = "/dev/disk/by-partuuid/a53e3b19-67de-40de-9ded-3eac3117689a";
|
||||||
|
nixosPart = "/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e";
|
||||||
|
|
||||||
|
btrfsMountOptions = [
|
||||||
|
"compress=zstd"
|
||||||
|
"noatime"
|
||||||
|
"ssd"
|
||||||
|
"space_cache=v2"
|
||||||
|
];
|
||||||
|
in
|
||||||
|
{
|
||||||
|
disko.enableConfig = true;
|
||||||
|
|
||||||
|
disko.devices.disk = {
|
||||||
|
esp = {
|
||||||
|
type = "disk";
|
||||||
|
device = espPart;
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
mountOptions = [ "umask=0077" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
nixos = {
|
||||||
|
type = "disk";
|
||||||
|
device = nixosPart;
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "luks";
|
||||||
|
name = "cryptroot";
|
||||||
|
askPassword = true;
|
||||||
|
settings.allowDiscards = true;
|
||||||
|
|
||||||
|
extraFormatArgs = [
|
||||||
|
"--type"
|
||||||
|
"luks2"
|
||||||
|
"--pbkdf"
|
||||||
|
"argon2id"
|
||||||
|
"--label"
|
||||||
|
"NixOS-LUKS"
|
||||||
|
];
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "btrfs";
|
||||||
|
extraArgs = [
|
||||||
|
"-f"
|
||||||
|
"-L"
|
||||||
|
"NixOS"
|
||||||
|
];
|
||||||
|
|
||||||
|
subvolumes = {
|
||||||
|
"@root" = {
|
||||||
|
mountpoint = "/";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@home" = {
|
||||||
|
mountpoint = "/home";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@nix" = {
|
||||||
|
mountpoint = "/nix";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@log" = {
|
||||||
|
mountpoint = "/var/log";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@swap" = {
|
||||||
|
mountpoint = "/.swapvol";
|
||||||
|
mountOptions = [ "noatime" ];
|
||||||
|
swap.swapfile.size = "32G";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
# Do not modify this file! It was generated by `nixos-generate-config`
|
||||||
|
# and may be overwritten by future invocations. Make changes in nixos.nix.
|
||||||
|
{
|
||||||
|
config,
|
||||||
|
lib,
|
||||||
|
modulesPath,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
(modulesPath + "/installer/scan/not-detected.nix")
|
||||||
|
];
|
||||||
|
|
||||||
|
boot.initrd.availableKernelModules = [
|
||||||
|
"xhci_pci"
|
||||||
|
"thunderbolt"
|
||||||
|
"nvme"
|
||||||
|
"usb_storage"
|
||||||
|
"sd_mod"
|
||||||
|
];
|
||||||
|
boot.initrd.kernelModules = [ ];
|
||||||
|
boot.kernelModules = [ "kvm-intel" ];
|
||||||
|
boot.extraModulePackages = [ ];
|
||||||
|
|
||||||
|
swapDevices = [ ];
|
||||||
|
|
||||||
|
networking.useDHCP = lib.mkDefault true;
|
||||||
|
|
||||||
|
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||||
|
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
|
||||||
|
}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{
|
||||||
|
programs.niri.settings.outputs."eDP-1" = {
|
||||||
|
scale = 1.2;
|
||||||
|
position = {
|
||||||
|
x = 0;
|
||||||
|
y = 0;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{
|
||||||
|
imports = [
|
||||||
|
./hardware-configuration.nix
|
||||||
|
./disko.nix
|
||||||
|
];
|
||||||
|
|
||||||
|
boot.initrd.luks.devices.cryptroot.device =
|
||||||
|
"/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e";
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user