add systems

This commit is contained in:
2026-07-27 18:02:48 +09:00
parent 3e32c9874b
commit 6bd05887db
29 changed files with 342 additions and 9 deletions
+8
View File
@@ -0,0 +1,8 @@
{
hardware.bluetooth = {
enable = true;
powerOnBoot = true;
};
services.blueman.enable = true;
}
+3
View File
@@ -0,0 +1,3 @@
{
hardware.graphics.enable = true;
}
+21
View File
@@ -0,0 +1,21 @@
{ pkgs, ... }:
{
boot.kernelModules = [ "uvcvideo" ];
hardware.ipu6 = {
enable = true;
platform = "ipu6epmtl";
};
environment.systemPackages = with pkgs; [
v4l-utils
ffmpeg-full
libcamera
];
services.pipewire = {
enable = true;
alsa.enable = true;
pulse.enable = true;
};
security.rtkit.enable = true;
}
+3
View File
@@ -0,0 +1,3 @@
{
services.qemuGuest.enable = true;
}
+3 -1
View File
@@ -3,7 +3,9 @@
includes = [
"systems.locale"
"systems.networking"
"systems.networking.base"
"systems.networking.wifi"
"systems.nix"
"systems.sops"
];
}
+12
View File
@@ -0,0 +1,12 @@
{
security.rtkit.enable = true;
services.pipewire = {
enable = true;
alsa.enable = true;
alsa.support32Bit = true;
pulse.enable = true;
jack.enable = true;
wireplumber.enable = true;
};
}
+6
View File
@@ -0,0 +1,6 @@
{ pkgs, lib, ... }:
{
boot.loader.systemd-boot.configurationLimit = lib.mkDefault 8;
boot.kernelPackages = pkgs.linuxPackages_latest;
programs.nix-ld.enable = true;
}
+5
View File
@@ -0,0 +1,5 @@
{
boot.supportedFilesystems = [ "nfs" ];
programs.fuse.userAllowOther = true;
services.rpcbind.enable = true;
}
@@ -0,0 +1,6 @@
{ inputs, ... }:
{
description = "Lanzaboote Secure Boot";
imports.nixos = [ inputs.lanzaboote.nixosModules.lanzaboote ];
}
@@ -0,0 +1,17 @@
{ pkgs, lib, ... }:
{
boot.loader = {
systemd-boot.enable = lib.mkForce false;
efi = {
canTouchEfiVariables = true;
efiSysMountPoint = "/boot";
};
};
boot.lanzaboote = {
enable = true;
pkiBundle = "/var/lib/sbctl";
};
environment.systemPackages = [ pkgs.sbctl ];
}
-1
View File
@@ -2,7 +2,6 @@
{
boot.loader = {
systemd-boot.enable = lib.mkDefault true;
systemd-boot.configurationLimit = lib.mkDefault 8;
efi.canTouchEfiVariables = lib.mkDefault true;
};
}
+6
View File
@@ -0,0 +1,6 @@
{ inputs, ... }:
{
description = "Disko declarative disk partitioning";
imports.nixos = [ inputs.disko.nixosModules.disko ];
}
+4
View File
@@ -0,0 +1,4 @@
{ lib, ... }:
{
disko.enableConfig = lib.mkDefault false;
}
+12
View File
@@ -0,0 +1,12 @@
{ lib, ... }:
{
services.fprintd.enable = true;
security.polkit.enable = true;
security.pam.services.polkit-1.fprintAuth = true;
security.pam.services = {
login.fprintAuth = false;
sudo.fprintAuth = true;
greetd.fprintAuth = lib.mkForce false;
ly.fprintAuth = lib.mkForce false;
};
}
+26
View File
@@ -0,0 +1,26 @@
{ pkgs, ... }:
{
fonts = {
packages = with pkgs; [
noto-fonts
noto-fonts-cjk-sans
noto-fonts-color-emoji
terminus_font
cantarell-fonts
font-awesome
nerd-fonts.blex-mono
];
fontDir.enable = true;
fontconfig.defaultFonts = {
serif = [
"Noto Serif CJK JP"
"Noto Color Emoji"
];
sansSerif = [
"Noto Sans CJK JP"
"Noto Color Emoji"
];
emoji = [ "Noto Color Emoji" ];
};
};
}
+9
View File
@@ -0,0 +1,9 @@
{ lib, ... }:
{
hardware = {
enableRedistributableFirmware = lib.mkDefault true;
keyboard.qmk.enable = true;
};
services.fwupd.enable = true;
}
+12
View File
@@ -0,0 +1,12 @@
{ lib, ... }:
{
networking.nameservers = lib.mkDefault [
"1.1.1.1"
"1.0.0.1"
"10.50.80.53"
"10.50.80.54"
];
services.resolved.enable = lib.mkDefault false;
security.pki.certificateFiles = [ ./root_ca.crt ];
}
@@ -0,0 +1,12 @@
-----BEGIN CERTIFICATE-----
MIIBszCCAVqgAwIBAgIRAPCAxajuCEmnXKploQS+KAkwCgYIKoZIzj0EAwIwODEW
MBQGA1UEChMNTW9vbnMgSG9tZSBDQTEeMBwGA1UEAxMVTW9vbnMgSG9tZSBDQSBS
b290IENBMB4XDTI1MTIwNjE4MDgwN1oXDTM1MTIwNDE4MDgwN1owODEWMBQGA1UE
ChMNTW9vbnMgSG9tZSBDQTEeMBwGA1UEAxMVTW9vbnMgSG9tZSBDQSBSb290IENB
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEDw2M0NQMju2zN5ZXwsYaTieWggId
XmRSXjOHW4/pBEI11xk1GkMFbeVmppr1cbcNmbB+fmxoFa+oKguhFDSsdaNFMEMw
DgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQEwHQYDVR0OBBYEFGuC
UGL5CxdamFfBVC8xH306Wo6xMAoGCCqGSM49BAMCA0cAMEQCIBqWCNWBuwhWDYoi
fpqOqz2HSChOsKCIAgfTJlUUgSlSAiALekUJ+4M+L4/vP4GpkrSovuQ7JOMXV44+
30Pcx4AoJg==
-----END CERTIFICATE-----
-3
View File
@@ -1,3 +0,0 @@
{
networking.networkmanager.enable = true;
}
+25
View File
@@ -0,0 +1,25 @@
{
networking = {
networkmanager = {
enable = true;
dns = "none";
wifi = {
powersave = false;
backend = "wpa_supplicant";
};
settings = {
"device"."wifi.scan-rand-mac-address" = "no";
"connection"."wifi.cloned-mac-address" = "permanent";
};
};
wireless.iwd.enable = false;
};
boot.extraModprobeConfig = ''
options cfg80211 ieee80211_regdom=JP
options iwlwifi power_save=0
options iwlwifi uapsd_disable=1
'';
programs.nm-applet.enable = true;
}
+26 -4
View File
@@ -1,8 +1,30 @@
{
nixpkgs.config.allowUnfree = true;
nix.settings.experimental-features = [
"nix-command"
"flakes"
];
nix.settings = {
experimental-features = [
"nix-command"
"flakes"
];
extra-substituters = [
"https://cache.nixos.org"
"https://nix-community.cachix.org"
"https://moons-dotfiles.cachix.org"
"https://noctalia.cachix.org"
"https://vicinae.cachix.org"
"https://cache.numtide.com"
"https://codex-desktop-linux.cachix.org"
];
extra-trusted-public-keys = [
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
"moons-dotfiles.cachix.org-1:WHoroKiNScG2/dpxHHL1I0qVmvuQhJbEAP+DS2j9Rr0="
"noctalia.cachix.org-1:pCOR47nnMEo5thcxNDtzWpOxNFQsBRglJzxWPp3dkU4="
"vicinae.cachix.org-1:1kDrfienkGHPYbkpNj1mWTr7Fm1+zcenzgTizIcI3oc="
"niks3.numtide.com-1:DTx8wZduET09hRmMtKdQDxNNthLQETkc/yaX7M4qK0g="
"codex-desktop-linux.cachix.org-1:nX/xy6AdK9hQE24A8ALGjkCKj2ObFmcnemiL5Cid4nk="
];
};
}
+16
View File
@@ -0,0 +1,16 @@
{
nix.gc = {
automatic = true;
interval = [
{
Weekday = 7;
Hour = 3;
Minute = 15;
}
];
options = "--delete-older-than 14d";
};
nix.settings.auto-optimise-store = true;
nix.optimise.automatic = true;
}
+8
View File
@@ -0,0 +1,8 @@
{
nix.gc.automatic = false;
nix.settings.auto-optimise-store = true;
nix.optimise = {
automatic = true;
dates = [ "weekly" ];
};
}
+18
View File
@@ -0,0 +1,18 @@
{
boot.kernelParams = [ "mem_sleep_default=deep" ];
powerManagement = {
enable = true;
powertop.enable = true;
};
services.power-profiles-daemon.enable = true;
services.tlp.enable = false;
services.upower.enable = true;
services.logind.settings.Login = {
HandleLidSwitch = "suspend";
HandleLidSwitchDocked = "ignore";
HandleLidSwitchExternalPower = "suspend";
LidSwitchIgnoreInhibited = "no";
};
}
+17
View File
@@ -0,0 +1,17 @@
{ pkgs, ... }:
{
environment.systemPackages = with pkgs; [
sops
age
ssh-to-age
age-plugin-yubikey
yubikey-manager
pcsc-tools
mkpasswd
];
sops = {
defaultSopsFormat = "yaml";
age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
};
}
+11
View File
@@ -0,0 +1,11 @@
{ inputs, ... }:
{
description = "sops-nix system integration";
includes = [ "services.openssh" ];
imports = {
nixos = [ inputs.sops-nix.nixosModules.sops ];
darwin = [ inputs.sops-nix.darwinModules.sops ];
};
}
+8
View File
@@ -0,0 +1,8 @@
{
services.pcscd.enable = true;
sops.secrets."users/moons/hashedPassword" = {
sopsFile = ../../../secrets/common/system.yaml;
neededForUsers = true;
};
}
+2
View File
@@ -1,5 +1,7 @@
{ primaryUser, pkgs, ... }:
{
users.mutableUsers = true;
users.users.${primaryUser} = {
isNormalUser = true;
description = "moons";