This commit is contained in:
2026-05-30 19:03:33 +09:00
parent f5ecef894d
commit 5f1cfc5275
155 changed files with 4168 additions and 300 deletions
+11
View File
@@ -0,0 +1,11 @@
{
pkgs,
lib,
...
}:
{
boot = {
loader.systemd-boot.configurationLimit = lib.mkDefault 8;
kernelPackages = pkgs.linuxPackages_latest;
};
}
+18
View File
@@ -0,0 +1,18 @@
{
lib,
config,
...
}:
let
cfg = config.my.system.boot.nfs;
in
{
options.my.system.boot.nfs = {
enable = lib.mkEnableOption "NFS boot support";
};
config = lib.mkIf cfg.enable {
boot.supportedFilesystems = [ "nfs" ];
fuse.userAllowOther = true;
};
}
+20
View File
@@ -0,0 +1,20 @@
{
lib,
config,
...
}:
let
cfg = config.my.system.boot.uefi;
in
{
options.my.system.boot.uefi = {
enable = lib.mkEnableOption "UEFI boot support";
};
config = lib.mkIf cfg.enable {
boot.loader = {
systemd-boot.enable = lib.mkDefault true;
efi.canTouchEfiVariables = lib.mkDefault true;
};
};
}
+35
View File
@@ -0,0 +1,35 @@
{
pkgs,
lib,
config,
...
}:
let
cfg = config.my.system.camera;
in
{
options.my.system.camera = {
enable = lib.mkEnableOption "camera support";
};
config = lib.mkIf cfg.enable {
boot.kernelModules = [ "uvcvideo" ];
environment.systemPackages = with pkgs; [
v4l-utils
ffmpeg-full
];
services.pipewire = {
enable = true;
alsa.enable = true;
pulse.enable = true;
};
security.rtkit.enable = true;
xdg.portal = {
enable = true;
extraPortals = [ pkgs.xdg-desktop-portal-gtk ];
};
};
}
+17
View File
@@ -0,0 +1,17 @@
{
imports = [
./boot
./nix.nix
./camera.nix
./fingerprint.nix
./fonts.nix
./gc.nix
./locale.nix
./hardware
./network
./power.nix
./secure-boot.nix
./user
./version.nix
];
}
+23
View File
@@ -0,0 +1,23 @@
{
lib,
config,
...
}:
let
cfg = config.my.system.fingerprint;
in
{
options.my.system.fingerprint = {
enable = lib.mkEnableOption "fingerprint authentication";
};
config = lib.mkIf cfg.enable {
services.fprintd.enable = true;
security.pam.services = {
login.fprintAuth = true;
sudo.fprintAuth = true;
greetd.fprintAuth = true;
};
};
}
+43
View File
@@ -0,0 +1,43 @@
{
pkgs,
lib,
config,
...
}:
let
cfg = config.my.system.fonts;
in
{
options.my.system.fonts = {
enable = lib.mkEnableOption "system font configuration";
};
config = lib.mkIf cfg.enable {
fonts = {
packages = with pkgs; [
noto-fonts
noto-fonts-cjk-sans
noto-fonts-color-emoji
terminus_font
cantarell-fonts
font-awesome
nerd-fonts.blex-mono
];
fontDir.enable = true;
fontconfig = {
defaultFonts = {
serif = [
"Noto Serif CJK JP"
"Noto Color Emoji"
];
sansSerif = [
"Noto Sans CJK JP"
"Noto Clor Emoji"
];
emoji = [ "Noto Color Emoji" ];
};
};
};
};
}
+10
View File
@@ -0,0 +1,10 @@
_: {
nix.gc = {
automatic = true;
dates = "daily";
options = "--delete-older-than 7d";
};
nix.settings.auto-optimise-store = true;
nix.optimise.automatic = true;
}
+26
View File
@@ -0,0 +1,26 @@
{
lib,
config,
...
}:
let
cfg = config.my.system.hardware.bluetooth;
in
{
options.my.system.hardware.bluetooth = {
enable = lib.mkEnableOption "Bluetooth support";
};
config = lib.mkIf cfg.enable {
hardware = {
bluetooth.enable = true;
bluetooth.powerOnBoot = true;
};
services = {
bluetooth.enable = true;
bluetooth.startWhenNeeded = true;
blueman.enable = true;
};
};
}
+7
View File
@@ -0,0 +1,7 @@
{ lib, ... }:
{
hardware = {
enableRedistributableFirmware = lib.mkDefault true;
keyboard.qmk.enable = true;
};
}
+19
View File
@@ -0,0 +1,19 @@
{
lib,
config,
...
}:
let
cfg = config.my.system.hardware.gui;
in
{
options.my.system.hardware.gui = {
enable = lib.mkEnableOption "GPU/graphics hardware acceleration";
};
config = lib.mkIf cfg.enable {
hardware = {
graphics.enable = true;
};
};
}
+18
View File
@@ -0,0 +1,18 @@
_: {
time.timeZone = "Asia/Tokyo";
i18n.defaultLocale = "ja_JP.UTF-8";
i18n.extraLocaleSettings = {
LC_ADDRESS = "ja_JP.UTF-8";
LC_IDENTIFICATION = "ja_JP.UTF-8";
LC_MEASUREMENT = "ja_JP.UTF-8";
LC_MONETARY = "ja_JP.UTF-8";
LC_NAME = "ja_JP.UTF-8";
LC_NUMERIC = "ja_JP.UTF-8";
LC_PAPER = "ja_JP.UTF-8";
LC_TELEPHONE = "ja_JP.UTF-8";
LC_TIME = "ja_JP.UTF-8";
};
console.keyMap = "jp106";
}
+23
View File
@@ -0,0 +1,23 @@
{
host,
lib,
...
}:
{
networking = {
hostName = host;
nameservers = lib.mkDefault [
"1.1.1.1"
"1.0.0.1"
"10.50.80.53"
"10.50.80.54"
];
};
services.resolved.enable = lib.mkDefault false;
security.pki.certificateFiles = [
./root_ca.crt
];
}
+13
View File
@@ -0,0 +1,13 @@
-----BEGIN CERTIFICATE-----
MIIBszCCAVqgAwIBAgIRAPCAxajuCEmnXKploQS+KAkwCgYIKoZIzj0EAwIwODEW
MBQGA1UEChMNTW9vbnMgSG9tZSBDQTEeMBwGA1UEAxMVTW9vbnMgSG9tZSBDQSBS
b290IENBMB4XDTI1MTIwNjE4MDgwN1oXDTM1MTIwNDE4MDgwN1owODEWMBQGA1UE
ChMNTW9vbnMgSG9tZSBDQTEeMBwGA1UEAxMVTW9vbnMgSG9tZSBDQSBSb290IENB
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEDw2M0NQMju2zN5ZXwsYaTieWggId
XmRSXjOHW4/pBEI11xk1GkMFbeVmppr1cbcNmbB+fmxoFa+oKguhFDSsdaNFMEMw
DgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQEwHQYDVR0OBBYEFGuC
UGL5CxdamFfBVC8xH306Wo6xMAoGCCqGSM49BAMCA0cAMEQCIBqWCNWBuwhWDYoi
fpqOqz2HSChOsKCIAgfTJlUUgSlSAiALekUJ+4M+L4/vP4GpkrSovuQ7JOMXV44+
30Pcx4AoJg==
-----END CERTIFICATE-----
+38
View File
@@ -0,0 +1,38 @@
{
lib,
config,
...
}:
let
cfg = config.my.system.network.wifi;
in
{
options.my.system.network.wifi = {
enable = lib.mkEnableOption "WiFi (NetworkManager) support";
};
config = lib.mkIf cfg.enable {
networking = {
networkmanager = {
enable = true;
dns = "none";
wifi.powersave = false;
wifi.backend = "wpa_supplicant";
settings = {
"device"."wifi.scan-rand-mac-address" = "no";
"connection"."wifi.cloned-mac-address" = "permanent";
};
};
wireless.iwd.enable = false;
};
boot.extraModprobeConfig = ''
options cfg80211 ieee80211_regdom=JP
options iwlwifi power_save=0
options iwlwifi uapsd_disable=1
'';
programs.nm-applet.enable = true;
};
}
+24
View File
@@ -0,0 +1,24 @@
_: {
nix.settings = {
extra-substituters = [
"https://cache.nixos.org"
"https://nix-community.cachix.org"
"https://moons-dotfiles.cachix.org"
"https://noctalia.cachix.org"
"https://vicinae.cachix.org"
];
extra-trusted-public-keys = [
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
"moons-dotfiles.cachix.org-1:WHoroKiNScG2/dpxHHL1I0qVmvuQhJbEAP+DS2j9Rr0="
"noctalia.cachix.org-1:pCOR47nnMEo5thcxNDtzWpOxNFQsBRglJzxWPp3dkU4="
"vicinae.cachix.org-1:1kDrfienkGHPYbkpNj1mWTr7Fm1+zcenzgTizIcI3oc="
];
experimental-features = [
"nix-command"
"flakes"
];
};
}
+28
View File
@@ -0,0 +1,28 @@
{
lib,
config,
...
}:
let
cfg = config.my.system.power;
in
{
options.my.system.power = {
enable = lib.mkEnableOption "power management";
};
config = lib.mkIf cfg.enable {
boot.kernelParams = [
"mem_sleep_default=deep"
];
powerManagement = {
enable = true;
powertop.enable = true;
};
services.power-profiles-daemon.enable = true;
services.tlp.enable = false;
services.upower.enable = true;
};
}
+31
View File
@@ -0,0 +1,31 @@
{
inputs,
lib,
config,
...
}:
let
cfg = config.my.system.secure-boot;
in
{
imports = [
inputs.lanzaboote.nixosModules.lanzaboote
];
options.my.system.secure-boot = {
enable = lib.mkEnableOption "secure boot (lanzaboote)";
};
config = lib.mkIf cfg.enable {
boot.loader = {
systemd-boot.enable = lib.mkForce false;
efi.canTouchEfiVariables = true;
efi.efiSysMountPoint = "/boot";
};
boot.lanzaboote = {
enable = true;
pkiBundle = "/var/lib/sbctl";
};
};
}
+13
View File
@@ -0,0 +1,13 @@
{
imports = [
./moons.nix
];
users.mutableUsers = true;
nix.settings.allowed-users = [ "moons" ];
nix.settings.trusted-users = [
"root"
"moons"
];
}
+25
View File
@@ -0,0 +1,25 @@
{ pkgs, ... }:
{
users.users.moons = {
isNormalUser = true;
description = "moons-14";
extraGroups = [
"adbusers"
"docker"
"libvirtd"
"lp"
"networkmanager"
"scanner"
"wheel"
"vboxusers"
"dialout"
];
shell = pkgs.zsh;
ignoreShellProgramCheck = true;
openssh.authorizedKeys.keys = [
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIKhxDkucmeCor6CKoXAua7DgDSzuXrZOtpdkyzQxz5+aAAAABHNzaDo= moons@moons14.com"
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIN6hZJyng/5LgFKPjR6uZAd/00UkO0vN0uQOoIvfSELdAAAABHNzaDo= moons@moons14.com"
];
};
}
+22
View File
@@ -0,0 +1,22 @@
{
config,
lib,
...
}:
{
options.my.stateVersions = {
nixos = lib.mkOption {
type = lib.types.str;
default = "25.11";
};
homeManager = lib.mkOption {
type = lib.types.str;
default = "25.11";
};
};
config = {
system.stateVersion = lib.mkDefault config.my.stateVersions.nixos;
};
}