diff --git a/flake.lock b/flake.lock index 0005f62..eea3108 100644 --- a/flake.lock +++ b/flake.lock @@ -729,6 +729,22 @@ } }, "nixpkgs_10": { + "locked": { + "lastModified": 1770107345, + "narHash": "sha256-tbS0Ebx2PiA1FRW8mt8oejR0qMXmziJmPaU1d4kYY9g=", + "owner": "nixos", + "repo": "nixpkgs", + "rev": "4533d9293756b63904b7238acb84ac8fe4c8c2c4", + "type": "github" + }, + "original": { + "owner": "nixos", + "ref": "nixpkgs-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_11": { "locked": { "lastModified": 1772542754, "narHash": "sha256-WGV2hy+VIeQsYXpsLjdr4GvHv5eECMISX1zKLTedhdg=", @@ -744,7 +760,7 @@ "type": "github" } }, - "nixpkgs_11": { + "nixpkgs_12": { "locked": { "lastModified": 1778869304, "narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=", @@ -868,18 +884,15 @@ }, "nixpkgs_9": { "locked": { - "lastModified": 1770107345, - "narHash": "sha256-tbS0Ebx2PiA1FRW8mt8oejR0qMXmziJmPaU1d4kYY9g=", - "owner": "nixos", - "repo": "nixpkgs", - "rev": "4533d9293756b63904b7238acb84ac8fe4c8c2c4", - "type": "github" + "lastModified": 1784796856, + "narHash": "sha256-vwxWgF+Gj276WznzGb1LxGsK/39HaQwgQXiU3EkC844=", + "rev": "e2587caef70cea85dd97d7daab492899902dbf5d", + "type": "tarball", + "url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1040357.e2587caef70c/nixexprs.tar.xz" }, "original": { - "owner": "nixos", - "ref": "nixpkgs-unstable", - "repo": "nixpkgs", - "type": "github" + "type": "tarball", + "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz" } }, "nixvim": { @@ -907,20 +920,19 @@ }, "noctalia": { "inputs": { - "nixpkgs": [ - "nixpkgs" - ] + "nixpkgs": "nixpkgs_9" }, "locked": { - "lastModified": 1785099099, - "narHash": "sha256-hwmc/ov72HfpuZvLX7KvaHFw3cI4KTD+O5znR9a7pcI=", + "lastModified": 1785150509, + "narHash": "sha256-9YohBD2ceAWQYoT/1/QZIuaqi99hgbiUgBWyV3z6/xM=", "owner": "noctalia-dev", "repo": "noctalia", - "rev": "02a846f5c947da00f3d4acdf7cf00f056d92fe3d", + "rev": "cf5c9a28fc27facf42309a558c075259e512ba66", "type": "github" }, "original": { "owner": "noctalia-dev", + "ref": "cachix", "repo": "noctalia", "type": "github" } @@ -1058,7 +1070,7 @@ }, "soulver-cpp": { "inputs": { - "nixpkgs": "nixpkgs_11", + "nixpkgs": "nixpkgs_12", "nixpkgs-libxml2": "nixpkgs-libxml2" }, "locked": { @@ -1316,7 +1328,7 @@ }, "treefmt-nix_2": { "inputs": { - "nixpkgs": "nixpkgs_9" + "nixpkgs": "nixpkgs_10" }, "locked": { "lastModified": 1784369104, @@ -1334,7 +1346,7 @@ }, "vicinae": { "inputs": { - "nixpkgs": "nixpkgs_10", + "nixpkgs": "nixpkgs_11", "soulver-cpp": "soulver-cpp", "systems": "systems_7" }, diff --git a/hosts/default.nix b/hosts/default.nix index 9fcfb35..a72bbe4 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -8,12 +8,9 @@ profiles = [ "base" "interface.cli" - "interface.gnome" - "interface.niri" - "networking.tailscale-client" "platform.thinkpad-x1" + "security.fingerprint" "security.secrets" - "workload.personal" ]; }; @@ -26,9 +23,10 @@ profiles = [ "base" "interface.cli" + "security.fingerprint" "security.secrets" + "workload.development" + "workload.personal" ]; - - units = [ "systems.fingerprint" ]; }; } diff --git a/modules/profiles/README.md b/modules/profiles/README.md index c374348..403bbe9 100644 --- a/modules/profiles/README.md +++ b/modules/profiles/README.md @@ -38,15 +38,16 @@ when removing it from any supported host would make that host invalid. | `workload.server` | NixOS, macOS with Home Manager | | `networking.tailscale-client` | NixOS, macOS | | `networking.tailscale-subnet-router` | NixOS | +| `security.fingerprint` | NixOS, macOS | | `security.secrets` | NixOS, macOS | | `security.secure-boot` | NixOS | | `security.tpm-storage` | NixOS with a host-defined LUKS device | Select independent concerns independently in `hosts/default.nix`. For example, -a NixOS laptop can combine `base`, `platform.thinkpad-x1`, -`interface.cli`, and `interface.niri`, while a macOS host can combine -`base`, `interface.cli`, and cross-platform workloads. A graphical profile does -not implicitly select a CLI profile or personal applications. +a minimal NixOS laptop can combine `base`, `platform.thinkpad-x1`, and +`interface.cli`, while a daily-use macOS development machine can add +`workload.development` and `workload.personal`. Hardware support does not +implicitly select an interface or workload. `security.tpm-storage` deliberately does not own a disk identifier. A host that selects it must define `boot.initrd.luks.devices.cryptroot.device` in its diff --git a/modules/profiles/platform/thinkpad-x1/meta.nix b/modules/profiles/platform/thinkpad-x1/meta.nix index e317e1f..5f3f0c2 100644 --- a/modules/profiles/platform/thinkpad-x1/meta.nix +++ b/modules/profiles/platform/thinkpad-x1/meta.nix @@ -5,6 +5,5 @@ "profiles.platform.laptop" "hardwares.intel-driver" "hardwares.ipu6-camera" - "systems.fingerprint" ]; } diff --git a/modules/profiles/security/fingerprint/meta.nix b/modules/profiles/security/fingerprint/meta.nix new file mode 100644 index 0000000..200af8b --- /dev/null +++ b/modules/profiles/security/fingerprint/meta.nix @@ -0,0 +1,5 @@ +{ + description = "Fingerprint authentication for NixOS and macOS"; + + includes = [ "systems.fingerprint" ]; +}