diff --git a/.envrc b/.envrc new file mode 100644 index 0000000..2a8255d --- /dev/null +++ b/.envrc @@ -0,0 +1,2 @@ +# shellcheck shell=bash +use flake .#dotnix diff --git a/.github/workflows/nix-cache.yml b/.github/workflows/nix-cache.yml deleted file mode 100644 index 8b76c31..0000000 --- a/.github/workflows/nix-cache.yml +++ /dev/null @@ -1,71 +0,0 @@ -name: nix-build-and-cache - -on: - pull_request: - paths: - - "flake.nix" - - "flake.lock" - - "hosts/**" - - "modules/**" - - "profiles/**" - - "overlays/**" - - ".github/workflows/nix-cache.yml" - push: - branches: - - main - paths: - - "flake.nix" - - "flake.lock" - - "hosts/**" - - "modules/**" - - "profiles/**" - - "overlays/**" - - ".github/workflows/nix-cache.yml" - workflow_dispatch: - -concurrency: - group: nix-${{ github.ref }} - cancel-in-progress: true - -jobs: - build: - runs-on: ubuntu-latest - strategy: - fail-fast: false - matrix: - host: - - x1g9 - - x1g13-wsl - - x1g13 - - monitor - - dev-1 - - service-1 - - steps: - - name: Checkout - uses: actions/checkout@v6 - - - name: Install Nix - uses: cachix/install-nix-action@v31 - with: - github_access_token: ${{ secrets.GITHUB_TOKEN }} - extra_nix_config: | - accept-flake-config = true - - - name: Setup Cachix for PR - if: github.event_name == 'pull_request' - uses: cachix/cachix-action@v17 - with: - name: moons-dotfiles - skipPush: true - - - name: Setup Cachix for main push - if: github.event_name == 'push' && github.ref == 'refs/heads/main' - uses: cachix/cachix-action@v17 - with: - name: moons-dotfiles - authToken: "${{ secrets.CACHIX_AUTH_TOKEN }}" - - - name: Build host - run: | - nix build -L .#nixosConfigurations.${{ matrix.host }}.config.system.build.toplevel diff --git a/.gitignore b/.gitignore index a7f6ba0..ea12eb1 100644 --- a/.gitignore +++ b/.gitignore @@ -3,17 +3,22 @@ !.gitignore !README.md !LICENSE +!AGENTS.md + +!.envrc + +!.sops.yaml !/flake.nix !/flake.lock -!/hosts/ -!/modules/ -!/home-manager/ -!/shells/ -!/images/ -!/profiles/ -!/overlays/ +!shells/ +!hosts/ +!overlays/ +!profiles/ +!modules/ +!docs/ +!images/ +!secrets/ -!renovate.json -!.github/ +!/flake/ diff --git a/.sops.yaml b/.sops.yaml new file mode 100644 index 0000000..27698bb --- /dev/null +++ b/.sops.yaml @@ -0,0 +1,14 @@ +keys: + - &admin_yubikey1 age1yubikey1qvy5y8kxqc63y7fk0tfv43u499a8z8q332ff087lythry9cc6hdxxkznc6t + - &host_x1g13_old age1xfc7ksg69l5kwsxxgtynsuxgpwltcf9gmqlhfl7efq0clc8lwspqnveyx3 +creation_rules: + - path_regex: ^secrets/common/[^/]+\.ya?ml$ + key_groups: + - age: + - *admin_yubikey1 + - *host_x1g13_old + - path_regex: ^secrets/hosts/x1g13/[^/]+\.ya?ml$ + key_groups: + - age: + - *admin_yubikey1 + - *host_x1g13_old diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..265287a --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,400 @@ +# AGENTS.md + +NixOS + Home Manager flake (v2)。flake-parts ベース。 + +## Commands + +```sh +nix flake update # flake の更新 +nix fmt # フォーマット +sudo nixos-rebuild build --flake .# # ビルド確認 +sudo nixos-rebuild switch --flake .# # 適用 +``` + +## Conventions + +- User: `moons`, locale: `ja_JP.UTF-8`, timezone: `Asia/Tokyo` +- Commits: conventional commits (`feat:`, `chore:`, `fix:`, etc.) +- リモート: `git@github.com:moons-14/dotfiles.git` +- `environment.systemPackages` にパッケージを追加する際はパッケージ名の横に簡単な説明をコメントで追加する +- 警告を抑制する設定は書かない。根本原因を調査して修正する +- home-manager の `sharedModules` 内で `lib.hm.*` を使う場合は、そのモジュール関数の引数で `lib` を受け取る必要がある(NixOSモジュールの `lib` とは別スコープ) +- `useGlobalPkgs = true` なので、home-manager 内で `nixpkgs.config` を設定しない(NixOSレベルで一括設定) +- `allowUnfree` は `hosts/default.nix` でグローバルに設定済み。各モジュールで個別設定しない + +## Architecture + +``` +flake.nix +└── hosts/default.nix # mkSystem でホスト構成を生成 + ├── modules/ # 全モジュール(常にインポートされる) + │ ├── applications/ # アプリケーション設定 + │ ├── system/ # システム設定 + │ ├── drivers/ # ドライバ設定 + │ ├── features/ # 機能バンドル(application/systemを束ねる) + │ └── integrations/ # home-manager 統合 + └── profiles/ # ホストごとに有効化するfeaturesの組み合わせ + ├── interfaces/ # 操作インターフェース (CLI/GUI) + ├── platforms/ # ハードウェア (desktop/laptop/vm) + └── workloads/ # 用途 (dev/personal/srv) +``` + +### 評価の流れ + +``` +profile (featuresの有効化) + → features (application/systemの有効化 + パッケージ追加) + → applications (system.nix + home.nix) + → system (NixOS設定) +``` + +## Layer Design + +### `modules/system/` — NixOS システム設定 + +OS全体に影響する設定。`config.my.system.*` namespace。 + +- boot, hardware, network, user, locale, fonts, power, secure-boot, gc, version +- 常にインポートされるが、`enable` オプションで実効性を制御 +- home-manager の設定は含めない + +### `modules/applications/` — アプリケーション設定 + +個別に有効/無効を切り替えたいアプリケーション。`config.my.applications.*` namespace。 + +- NixOS設定のみ、または NixOS + Home Manager の両方 +- Complex Module は system.nix と home.nix に分離 + +### `modules/features/` — 機能バンドル + +application や system より抽象度の高い「機能」単位で、複数の application/system を束ねて有効化する層。`config.my.features.*` namespace。 + +**features がやること:** + +1. 複数の `my.applications.*.enable` / `my.system.*.enable` をまとめて有効化 +2. application/system に属さないパッケージや設定を直接記述(`environment.systemPackages`、`home.activation` 等) +3. 追加オプションの受け渡し(例: tailscale の `acceptDns` を feature から application に passthrough) + +**features がやらないこと:** + +- 個別アプリケーションの詳細設定(それは applications 層の責務) + +### `profiles/` — ホスト構成 + +features の `enable` を指定するだけの薄い層。ロジックは書かない。 + +| カテゴリ | 役割 | 例 | +| ------------- | -------------------- | --------------------------------- | +| `interfaces/` | 操作インターフェース | cli-minimal, cli-interactive, gui | +| `platforms/` | ハードウェア固有設定 | desktop, laptop, thinkpad, vm | +| `workloads/` | 用途・ワークロード | dev, personal, srv | + +profiles は継承可能: + +```nix +# cli-interactive.nix +{ + imports = [ ./cli-minimal.nix ]; + my.features.cli.interactive.enable = true; +} +``` + +### `hosts/` — ホスト定義 + +`mkSystem` でホストを定義。profiles のリストを指定: + +```nix +nix-example = mkSystem { + host = "nix-example"; + system = "x86_64-linux"; + profiles = [ + "interfaces/cli-interactive" + "platforms/vm" + "workloads/dev" + ]; +}; +``` + +`specialArgs` で `inputs`, `username`, `unstable`, `host` が全モジュールに渡される。 + +## Module Patterns + +### Simple Module(NixOS のみ) + +home-manager の設定を含まない。1ファイルで完結: + +```nix +# modules/system/audio.nix +{ lib, config, ... }: +let + cfg = config.my.system.audio; +in +{ + options.my.system.audio = { + enable = lib.mkEnableOption "Audio support (PipeWire)"; + }; + + config = lib.mkIf cfg.enable { + # NixOS設定をここに書く + }; +} +``` + +### Simple Module(Home Manager のみ) + +NixOS設定を含まず、home-manager のみ: + +```nix +# modules/applications/zoom.nix +{ pkgs, lib, config, ... }: +let + cfg = config.my.applications.zoom; +in +{ + options.my.applications.zoom = { + enable = lib.mkEnableOption "Zoom video conferencing"; + }; + + config = lib.mkIf cfg.enable { + home-manager.sharedModules = [ + { + home.packages = with pkgs; [ + zoom-us # Video conferencing application + ]; + } + ]; + }; +} +``` + +### Complex Module(NixOS + Home Manager) + +ディレクトリ構造で system と home を分離: + +``` +modules/applications// +├── default.nix # マスター enable + imports +├── system.nix # NixOS 設定 +├── home.nix # Home Manager 設定 +└── (other files) # 設定ファイル等 +``` + +**default.nix** — `enable` のみ宣言。`system.enable`/`homeManager.enable` は sub-file に任せる: + +```nix +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications. = { + enable = lib.mkEnableOption ""; + }; + + config = lib.mkIf cfg.enable { + my.applications..system.enable = lib.mkDefault true; + my.applications..homeManager.enable = lib.mkDefault true; + }; +} +``` + +**system.nix:** + +```nix +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications..system; +in +{ + options.my.applications..system = { + enable = lib.mkEnableOption " system configuration"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + # Description + ]; + }; +} +``` + +**home.nix** — `home-manager.sharedModules` を使用: + +```nix +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.; + hmCfg = config.my.applications..homeManager; +in +{ + options.my.applications..homeManager = { + enable = lib.mkEnableOption " home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + { + config = lib.mkIf hmCfg.enable { + # home-manager 設定をここに書く + }; + } + ]; +} +``` + +**注意点:** + +- `default.nix` では `enable` のみ宣言。`system.enable`/`homeManager.enable` は `system.nix`/`home.nix` で宣言する(重複宣言エラー回避) +- home.nix で親の `cfg` を参照する場合は `cfg` と `hmCfg` の両方を let で定義 +- Complex Module の home-manager 設定は `home-manager.sharedModules` で記述(`home-manager.users.` は使わない) + +### Feature Module + +**application/system を束ねる場合:** + +```nix +# modules/features/services/container.nix +{ lib, config, ... }: +let + cfg = config.my.features.services.container; +in +{ + options.my.features.services.container = { + enable = lib.mkEnableOption "Container runtime (Docker)"; + }; + + config = lib.mkIf cfg.enable { + my.applications.docker.enable = true; + }; +} +``` + +**パッケージを直接追加する場合(application/system に属さない):** + +```nix +# modules/features/gui/capture.nix +{ pkgs, lib, config, ... }: +let + cfg = config.my.features.gui.capture; +in +{ + options.my.features.gui.capture = { + enable = lib.mkEnableOption "Screen capture tools"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + slurp # Tool for selecting a region of the screen + grim # Screenshot tool for Wayland + ]; + }; +} +``` + +**オプションを passthrough する場合:** + +```nix +# modules/features/network/tailscale.nix +{ + options.my.features.network.tailscale = { + enable = lib.mkEnableOption "Tailscale VPN"; + acceptDns = lib.mkOption { type = lib.types.bool; default = false; }; + }; + + config = lib.mkIf cfg.enable { + my.applications.tailscale = { + enable = true; + inherit (cfg) acceptDns; + }; + }; +} +``` + +**home.activation を使う場合(identity 等):** + +```nix +# modules/features/identity/ssh-default-key.nix +config.home-manager.sharedModules = [ + ( + { lib, ... }: + { + config = lib.mkIf cfg.enable { + home.activation.generateSshKey = lib.hm.dag.entryAfter [ "writeBoundary" ] '' + # shell script here + ''; + }; + } + ) +]; +``` + +### Profile + +features の有効化のみを記述: + +```nix +# profiles/platforms/laptop.nix +{ + my.features = { + boot.power.enable = true; + connect = { + wifi.enable = true; + bluetooth.enable = true; + }; + gui.camera.enable = true; + identity.fingerprint.enable = true; + network.tailscale.enable = true; + }; +} +``` + +## Adding New Features — Checklist + +### 新しいアプリケーションを追加する場合 + +1. `modules/applications/` にモジュール作成(Simple or Complex) +2. `modules/applications/default.nix` の `imports` に追加 +3. `modules/features/` の適切なカテゴリに feature を作成(既存の feature に追記でも可) +4. `modules/features//default.nix` の `imports` に追加 +5. `profiles/` の適切な profile で feature を有効化 + +### 新しいシステム設定を追加する場合 + +1. `modules/system/` にモジュール作成(Simple Module) +2. `modules/system/default.nix` の `imports` に追加 +3. `modules/features/` の適切なカテゴリに feature を作成 +4. `modules/features//default.nix` の `imports` に追加 +5. `profiles/` の適切な profile で feature を有効化 + +### 新しいホストを追加する場合 + +1. `hosts//default.nix` を作成(`hardware-configuration.nix` を import) +2. `hosts/default.nix` の `flake.nixosConfigurations` に `mkSystem` で追加 +3. profiles のリストを指定 + +## Key Technical Notes + +- **nixpkgs channel**: `nixos-26.05` (stable) + `nixpkgs-unstable` +- **unstable パッケージ**: `specialArgs.unstable` 経由で参照(`unstable.`) +- **llm-agents**: `inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.` で参照 +- **nixvim**: `nixpkgs.source = pkgs.path` と `nixpkgs.config.allowUnfree = true` を vim/home/default.nix で設定 +- **home-manager**: `useGlobalPkgs = true`, `useUserPackages = true` +- **hostname**: `specialArgs.host` から `modules/system/network/default.nix` で `networking.hostName` に設定 +- **stateVersion**: `config.my.stateVersions.nixos` / `config.my.stateVersions.homeManager` で管理(`modules/system/version.nix`) diff --git a/README.md b/README.md deleted file mode 100644 index 8d3b6a2..0000000 --- a/README.md +++ /dev/null @@ -1,189 +0,0 @@ -# dotfiles - -NixOS + Home Manager configuration for moons. This repository uses Nix flakes to -manage multiple NixOS hosts and project-specific development shells. - -This is a personal configuration. It assumes the `moons` user, `ja_JP.UTF-8` -locale, and `Asia/Tokyo` timezone. - -## Features - -- NixOS 25.11 based flake configuration -- Home Manager integrated as a NixOS module -- Wayland GUI profile with Niri, Hyprland, greetd, and Noctalia -- Home Manager modules for zsh, git, btop, zellij, direnv, NixVim, fcitx5, and more -- Separate hosts for ThinkPad X1 Carbon Gen 9 / Gen 13, WSL, and server machines -- `nix develop` shells for Next.js, Jupyter, and Rust projects -- GitHub Actions + Cachix build cache for host builds -- Renovate maintenance for flake inputs and the lock file - -## Hosts - -The following hosts are defined in `flake.nix` under `nixosConfigurations`. - -| Host | Profile | Notes | -| --- | --- | --- | -| `x1g9` | `laptop` | ThinkPad X1 9th gen, using `nixos-hardware` and the Intel driver module | -| `x1g13` | `laptop` | ThinkPad X1 13th gen, using the Intel driver module and Lanzaboote secure boot | -| `x1g13-wsl` | `cli` | NixOS-WSL with `moons` as the default user | -| `monitor` | `cli-server` | Server host | -| `dev-1` | `cli-server` | Server host | -| `service-1` | `cli-server` | Server host with Immich / Cloudreve NFS mounts | - -## Profiles - -Profiles live in `profiles/` and are selected per host from `flake.nix`. - -| Profile | Role | -| --- | --- | -| `cli-minimal` | Minimal profile with no extra imports. Shared NixOS and Home Manager modules are still always applied | -| `cli` | CLI profile extending `cli-minimal` | -| `cli-server` | Server profile extending `cli` | -| `gui` | GUI profile extending `cli` with Niri, Hyprland, greetd, Noctalia, KDE/GUI support, and GUI Home Manager modules | -| `laptop` | Laptop profile extending `gui` with fingerprint, power, and camera modules | - -## Directory Layout - -```text -. -|-- flake.nix # inputs, host definitions, devShells -|-- flake.lock # locked flake inputs -|-- hosts/ # host-specific NixOS settings -| `-- / -| |-- default.nix -| `-- hardware-configuration.nix -|-- profiles/ # reusable host profiles -|-- modules/ -| |-- core/ # NixOS modules -| |-- drivers/ # hardware / driver modules -| `-- home/ # Home Manager modules -|-- overlays/ # package overlays -|-- shells/ # nix develop environments -|-- images/ # managed image assets -|-- renovate.json # Renovate config -`-- .github/workflows/ # CI builds and Cachix integration -``` - -## System Usage - -Rebuild the current machine by selecting the matching `#` output. - -```sh -sudo nixos-rebuild switch --flake .#x1g13 -``` - -Switch on the next boot instead: - -```sh -sudo nixos-rebuild boot --flake .#x1g13 -``` - -Build a system closure in the same form used by CI: - -```sh -nix build -L .#nixosConfigurations.x1g13.config.system.build.toplevel -``` - -List available hosts and development shells: - -```sh -nix flake show -``` - -## Development Shells - -`devShells.x86_64-linux` provides the following shells. - -| Shell | Command | Main tools | -| --- | --- | --- | -| `next-web` | `nix develop .#next-web` | Node.js 24, pnpm, Vercel CLI, Prisma, OpenSSL, jq, ngrok | -| `jupyter` | `nix develop .#jupyter` | Python 3.12, JupyterLab, NumPy, pandas, matplotlib, scipy, scikit-learn | -| `rust` | `nix develop .#rust` | rustup, clang, LLVM/binutils, pkg-config | - -To use a shell through direnv, add an `.envrc` to the target project. - -```sh -use flake ~/dotfiles#next-web -``` - -## Adding A Host - -1. Create `hosts//hardware-configuration.nix`. - For an existing NixOS install, use the output from `sudo nixos-generate-config`. -2. Create `hosts//default.nix` and import hardware modules or host-specific settings. -3. Add a `mkSystem` entry to `nixosConfigurations` in `flake.nix` and choose a `profile`. -4. Check the build with `nix build -L .#nixosConfigurations..config.system.build.toplevel`. -5. Run `sudo nixos-rebuild switch --flake .#` on the target host. - -## Common Modules - -### NixOS - -`modules/core/default.nix` imports boot, Cachix, environment, fonts, GC, hardware, -i18n, network, packages, services, SSH, system, user, and xserver modules. - -Main settings include: - -- flakes / nix-command enabled -- `moons` user and Home Manager integration -- zsh, Docker, Tailscale, PipeWire, adb, Java 25, Python, Bun, Claude Code, Codex, and more -- NetworkManager, fixed nameservers, and JP Wi-Fi regulatory domain -- OpenSSH server with password login and root login disabled -- Cachix caches for `moons-dotfiles` and `vicinae` - -### Home Manager - -`modules/home/default.nix` imports btop, git, fcitx5, SSH, NixVim, zsh, direnv, -zellij, and Claude configuration. - -The GUI profile additionally manages Niri, VS Code, Google Chrome, Vicinae, -Noctalia, Ghostty, wallpaper, lock screen, Discord, Nautilus, GTK, and Zoom. - -NixVim is split into modules for LSP, formatters, completion, git integration, -UI plugins, editor plugins, options, keymaps, and autocmds. - -## Manual Steps - -The following setup is not fully declarative or needs host-specific manual work. - -- Register an SSH public key with GitHub. -- Enroll fingerprints on laptop hosts. - -```sh -fprintd-enroll -``` - -- `x1g13` uses Lanzaboote / sbctl for secure boot. The PKI bundle is read from - `/var/lib/sbctl`. -- Log in to services that require authentication, such as Tailscale and 1Password. - -## Maintenance - -Update all flake inputs: - -```sh -nix flake update -``` - -Update a single input: - -```sh -nix flake lock --update-input nixpkgs -``` - -GitHub Actions builds all hosts when `flake.nix`, `flake.lock`, `hosts/**`, -`modules/**`, `profiles/**`, or `overlays/**` changes. Pushes to `main` upload -to the `moons-dotfiles` Cachix cache. - -Renovate enables Nix lock file maintenance and has a separate package rule for -`llm-agents`. - -## Inspired - -- [Zaney/zaneyos](https://gitlab.com/Zaney/zaneyos) -- [fa0311/.zshrc](https://gist.github.com/fa0311/d37d53ff39c73c54c883379e8e3732df) -- [AsianLovesLinux/Niri](https://github.com/AsianLovesLinux/Niri) -- [natsukium/dotfiles](https://github.com/natsukium/dotfiles) -- [dracula](https://github.com/dracula) -- [akazdayo/nix-configs](https://github.com/akazdayo/nix-configs) -- [yutakobayashidev/dotnix](https://github.com/yutakobayashidev/dotnix) diff --git a/docs/fingerprint.md b/docs/fingerprint.md new file mode 100644 index 0000000..2875af3 --- /dev/null +++ b/docs/fingerprint.md @@ -0,0 +1,68 @@ +# Fingerprint Commands + +This note covers the basic `fprintd` commands used by the fingerprint module. + +## Enroll a new fingerprint + +Register a fingerprint for the current user: + +```sh +fprintd-enroll $USER +``` + +To enroll a specific finger, pass the finger name: + +```sh +fprintd-enroll -f right-index-finger $USER +``` + +Common finger names include: + +- `left-thumb` +- `left-index-finger` +- `right-thumb` +- `right-index-finger` + +Follow the prompts and swipe or touch the sensor until enrollment completes. + +## List enrolled fingerprints + +Show fingerprints registered for the current user: + +```sh +fprintd-list $USER +``` + +You can also list fingerprints for another user: + +```sh +fprintd-list +``` + +## Delete fingerprints + +Delete one enrolled fingerprint for the current user: + +```sh +fprintd-delete +``` + +Delete all enrolled fingerprints for the current user: + +```sh +fprintd-delete $USER +``` + +Delete fingerprints for another user: + +```sh +fprintd-delete +``` + +## Verify authentication + +Test fingerprint authentication for the current user: + +```sh +fprintd-verify +``` diff --git a/docs/install.md b/docs/install.md new file mode 100644 index 0000000..cd5786a --- /dev/null +++ b/docs/install.md @@ -0,0 +1,157 @@ +# NixOSインストール手順 + +## 事前準備 + +1. [ISOビルド](iso-build.md)を参照してISOを作成 +2. USBに書き込んで対象マシンでブート + +## ネットワーク接続 + +### 有線LAN + +DHCPで自動設定される。 + +### WiFi(有線が使えない場合) + +```bash +nmcli device wifi connect --ask +``` + +## SSH接続 + +コンソールに表示されたIPアドレスに接続: + +```bash +ssh root@ +``` + +## インストール手順 + +### 1. dotfilesのクローン + +```bash +git clone git@github.com:moons-14/dotfiles.git ~/dotfiles +``` + +### 2. SSHホストキーの生成 + +新しいホスト用のSSHホストキーを生成: + +```bash +ssh-keygen -t ed25519 -f /tmp/ssh_host_ed25519_key -N "" +``` + +### 3. age公開鍵の取得 + +SSHホストキーからage公開鍵を取得: + +```bash +ssh-to-age -i /tmp/ssh_host_ed25519_key.pub +``` + +出力されたage公開鍵をコピー。 + +### 4. .sops.yamlの編集 + +```bash +cd ~/dotfiles +vim .sops.yaml +``` + +以下を追加: + +```yaml +keys: + - &host_ + +creation_rules: + - path_regex: ^secrets/hosts//[^/]+\.ya?ml$ + key_groups: + - age: + - *admin_yubikey1 + - *host_ +``` + +### 5. シークレットの再暗号化 + +```bash +sops updatekeys secrets/common/system.yaml +sops updatekeys secrets/hosts//*.yaml +``` + +### 6. disko設定の作成 + +新しいホスト用の`hosts//disko.nix`を作成。 + +#### シンプル構成(暗号化なし) + +```nix +_: +{ + disko.enableConfig = true; + + disko.devices.disk.main = { + type = "disk"; + device = "/dev/sda"; + content = { + type = "gpt"; + partitions = { + ESP = { + size = "512M"; + type = "EF00"; + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + }; + }; + root = { + size = "100%"; + content = { + type = "filesystem"; + format = "ext4"; + mountpoint = "/"; + }; + }; + }; + }; + }; +} +``` + +#### LUKS暗号化 + btrfs + +`hosts/x1g13/disko.nix`を参照。 + +### 7. ディスクのパーティション + +```bash +cd ~/dotfiles +nix run github:nix-community/disko -- --mode disko hosts//disko.nix +``` + +### 8. ホストキーのコピー + +```bash +mkdir -p /mnt/etc/ssh +cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ +chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key +``` + +### 9. NixOSインストール + +```bash +nixos-install --flake ~/dotfiles# +``` + +### 10. 再起動 + +```bash +reboot +``` + +## インストール後の確認 + +- SSHでログインできるか +- sopsシークレットが復号できるか +- diskoでパーティションが正しく設定されているか diff --git a/docs/iso-build.md b/docs/iso-build.md new file mode 100644 index 0000000..d62af15 --- /dev/null +++ b/docs/iso-build.md @@ -0,0 +1,26 @@ +# カスタムISOビルド + +## ビルド + +```bash +nix build .#nixosConfigurations.installer.config.system.build.isoImage +``` + +## ISO書き込み + +```bash +# USBデバイスの確認 +lsblk + +# 書き込み(/dev/sdXは実際のデバイスに置き換える) +sudo dd if=./result/nixos-minimal-*.iso of=/dev/sdX bs=4M status=progress +sync +``` + +## ISOの特徴 + +- SSH鍵認証でrootログイン可能 +- 有線LANはDHCPで自動設定 +- WiFiは`nmcli`で手動設定可能 +- disko/sops/ageなどのツールを内蔵 +- ブート時にIPアドレスとヘルプを表示 diff --git a/docs/sops-key.md b/docs/sops-key.md new file mode 100644 index 0000000..8dbc9d3 --- /dev/null +++ b/docs/sops-key.md @@ -0,0 +1,17 @@ +# Generate Sops key file + +```bash +mkdir -p ~/.config/sops/age +chmod 700 ~/.config/sops/age + +age-plugin-yubikey --identity --slot 1 \ + > ~/.config/sops/age/yubikey-identity.txt + +chmod 600 ~/.config/sops/age/yubikey-identity.txt +``` + +## Edit sops file + +```bash +sops secrets/common/system.yaml +``` diff --git a/flake.lock b/flake.lock index 4de7c0d..837b384 100644 --- a/flake.lock +++ b/flake.lock @@ -38,11 +38,11 @@ "base16-helix": { "flake": false, "locked": { - "lastModified": 1760703920, - "narHash": "sha256-m82fGUYns4uHd+ZTdoLX2vlHikzwzdu2s2rYM2bNwzw=", + "lastModified": 1776754714, + "narHash": "sha256-E3OAK27smtATTmX45uoTSRsVD+Y+ZiVVfgM/tjpbtYg=", "owner": "tinted-theming", "repo": "base16-helix", - "rev": "d646af9b7d14bff08824538164af99d0c521b185", + "rev": "4d508123037e7851ad36ebf7d9c48b0e9e1eb581", "type": "github" }, "original": { @@ -68,13 +68,71 @@ "type": "github" } }, + "blueprint": { + "inputs": { + "nixpkgs": [ + "llm-agents", + "nixpkgs" + ], + "systems": [ + "llm-agents", + "systems" + ] + }, + "locked": { + "lastModified": 1776249299, + "narHash": "sha256-Dt9t1TGRmJFc0xVYhttNBD6QsAgHOHCArqGa0AyjrJY=", + "owner": "numtide", + "repo": "blueprint", + "rev": "56131e8628f173d24a27f6d27c0215eff57e40dd", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "blueprint", + "type": "github" + } + }, + "bun2nix": { + "inputs": { + "flake-parts": [ + "llm-agents", + "flake-parts" + ], + "nixpkgs": [ + "llm-agents", + "nixpkgs" + ], + "systems": [ + "llm-agents", + "systems" + ], + "treefmt-nix": [ + "llm-agents", + "treefmt-nix" + ] + }, + "locked": { + "lastModified": 1778446047, + "narHash": "sha256-oQvcadh2BCkrog+SGrG6YffKJrveYpjj3TdQJWaKhaM=", + "owner": "nix-community", + "repo": "bun2nix", + "rev": "f2bc12af1a6369648aac41041ceeaa0b866599c6", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "bun2nix", + "type": "github" + } + }, "crane": { "locked": { - "lastModified": 1777242778, - "narHash": "sha256-VWTeqWeb8Sel/QiWyaPvCa9luAbcGawR+Rw09FJoHz0=", + "lastModified": 1779130139, + "narHash": "sha256-BLrtr42azquO7MdGFU5a7KiMl3YpFlTeIXqy1fT5GlQ=", "owner": "ipetkov", "repo": "crane", - "rev": "ad8b31ad0ba8448bd958d7a5d50d811dc5d271c0", + "rev": "edb38893982a3338972bb4a2ec7ce7c29ba10fd9", "type": "github" }, "original": { @@ -83,14 +141,34 @@ "type": "github" } }, + "disko": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1781152676, + "narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=", + "owner": "nix-community", + "repo": "disko", + "rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "disko", + "type": "github" + } + }, "firefox-gnome-theme": { "flake": false, "locked": { - "lastModified": 1775176642, - "narHash": "sha256-2veEED0Fg7Fsh81tvVDNYR6SzjqQxa7hbi18Jv4LWpM=", + "lastModified": 1779670703, + "narHash": "sha256-UdfMivNMwCCqQsYDg5pSz8X2IOaOrIZLIIy+Bg3CO2o=", "owner": "rafaelmardojai", "repo": "firefox-gnome-theme", - "rev": "179704030c5286c729b5b0522037d1d51341022c", + "rev": "942159e73e40bf785816f7f1f5feed9ef3d7c8f9", "type": "github" }, "original": { @@ -132,6 +210,22 @@ } }, "flake-compat_3": { + "flake": false, + "locked": { + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", + "owner": "NixOS", + "repo": "flake-compat", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", + "type": "github" + }, + "original": { + "owner": "NixOS", + "repo": "flake-compat", + "type": "github" + } + }, + "flake-compat_4": { "flake": false, "locked": { "lastModified": 1767039857, @@ -147,7 +241,7 @@ "type": "github" } }, - "flake-compat_4": { + "flake-compat_5": { "flake": false, "locked": { "lastModified": 1767039857, @@ -165,17 +259,14 @@ }, "flake-parts": { "inputs": { - "nixpkgs-lib": [ - "nixvim", - "nixpkgs" - ] + "nixpkgs-lib": "nixpkgs-lib" }, "locked": { - "lastModified": 1768135262, - "narHash": "sha256-PVvu7OqHBGWN16zSi6tEmPwwHQ4rLPU9Plvs8/1TUBY=", + "lastModified": 1778716662, + "narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "80daad04eddbbf5a4d883996a73f3f542fa437ac", + "rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb", "type": "github" }, "original": { @@ -187,16 +278,16 @@ "flake-parts_2": { "inputs": { "nixpkgs-lib": [ - "stylix", + "llm-agents", "nixpkgs" ] }, "locked": { - "lastModified": 1775087534, - "narHash": "sha256-91qqW8lhL7TLwgQWijoGBbiD4t7/q75KTi8NxjVmSmA=", + "lastModified": 1778716662, + "narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "3107b77cd68437b9a76194f0f7f9c55f2329ca5b", + "rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb", "type": "github" }, "original": { @@ -205,21 +296,45 @@ "type": "github" } }, - "flake-utils": { + "flake-parts_3": { "inputs": { - "systems": "systems_2" + "nixpkgs-lib": [ + "nixvim", + "nixpkgs" + ] }, "locked": { - "lastModified": 1731533236, - "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", + "lastModified": 1778716662, + "narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb", "type": "github" }, "original": { - "owner": "numtide", - "repo": "flake-utils", + "owner": "hercules-ci", + "repo": "flake-parts", + "type": "github" + } + }, + "flake-parts_4": { + "inputs": { + "nixpkgs-lib": [ + "stylix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1778716662, + "narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "flake-parts", "type": "github" } }, @@ -249,11 +364,11 @@ "zon2nix": "zon2nix" }, "locked": { - "lastModified": 1777773742, - "narHash": "sha256-dZFc+8az7BUIs8+v45XqNnY5G6oXEwVfVVHZQuATSGQ=", + "lastModified": 1779893562, + "narHash": "sha256-gxAXdy7JYtYJem6lCJZdgU3XlDU30ruswQF1nRLKWsA=", "owner": "ghostty-org", "repo": "ghostty", - "rev": "1547dd667ab6d1f4ebcdc7282adc54c95752ee67", + "rev": "3103ae883880fe6cccdc17ea923e3ccd3587a83e", "type": "github" }, "original": { @@ -262,7 +377,48 @@ "type": "github" } }, + "git-hooks-nix": { + "inputs": { + "flake-compat": "flake-compat_2", + "gitignore": "gitignore", + "nixpkgs": "nixpkgs_2" + }, + "locked": { + "lastModified": 1778507602, + "narHash": "sha256-kTwur1wV+01SdqskVMSo6JMEpg71ps3HpbFY2GsflKs=", + "owner": "cachix", + "repo": "git-hooks.nix", + "rev": "61ab0e80d9c7ab14c256b5b453d8b3fb0189ba0a", + "type": "github" + }, + "original": { + "owner": "cachix", + "repo": "git-hooks.nix", + "type": "github" + } + }, "gitignore": { + "inputs": { + "nixpkgs": [ + "git-hooks-nix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1709087332, + "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=", + "owner": "hercules-ci", + "repo": "gitignore.nix", + "rev": "637db329424fd7e46cf4185293b9cc8c88c95394", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "gitignore.nix", + "type": "github" + } + }, + "gitignore_2": { "inputs": { "nixpkgs": [ "lanzaboote", @@ -329,48 +485,19 @@ ] }, "locked": { - "lastModified": 1777771528, - "narHash": "sha256-YycygK6n7KeW1YCobdFJcORWzkmrvNcp6xT+IovA0d4=", + "lastModified": 1779726696, + "narHash": "sha256-/p37CB5n6Wpw250b0Lq0CYwNq2D8uGKzDoBulyLcQqA=", "owner": "nix-community", "repo": "home-manager", - "rev": "0585fbf645640973e3398863bbaf3bd1ddce4a51", + "rev": "1a95e2efb477959b70b4a14c51035975c0481df6", "type": "github" }, "original": { "owner": "nix-community", - "ref": "release-25.11", "repo": "home-manager", "type": "github" } }, - "ixx": { - "inputs": { - "flake-utils": [ - "nixvim", - "nuschtosSearch", - "flake-utils" - ], - "nixpkgs": [ - "nixvim", - "nuschtosSearch", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1754860581, - "narHash": "sha256-EM0IE63OHxXCOpDHXaTyHIOk2cNvMCGPqLt/IdtVxgk=", - "owner": "NuschtOS", - "repo": "ixx", - "rev": "babfe85a876162c4acc9ab6fb4483df88fa1f281", - "type": "github" - }, - "original": { - "owner": "NuschtOS", - "ref": "v0.1.1", - "repo": "ixx", - "type": "github" - } - }, "lanzaboote": { "inputs": { "crane": "crane", @@ -381,11 +508,11 @@ "rust-overlay": "rust-overlay" }, "locked": { - "lastModified": 1777299656, - "narHash": "sha256-c0r3xXp2+xFJwkryS+nhyQwoACbFzSt4C1TVs3QMh8E=", + "lastModified": 1779865172, + "narHash": "sha256-QZuox/4ww6vOmUu9lCpKlQbU3MER1kmgnJmXP1LO1K0=", "owner": "nix-community", "repo": "lanzaboote", - "rev": "079c608988c2747db3902c9de033572cd50e8656", + "rev": "f42b84f9fb03db98dee2073e932010f3a76eeb9a", "type": "github" }, "original": { @@ -394,21 +521,44 @@ "type": "github" } }, + "llm-agents": { + "inputs": { + "blueprint": "blueprint", + "bun2nix": "bun2nix", + "flake-parts": "flake-parts_2", + "nixpkgs": "nixpkgs_3", + "systems": "systems_2", + "treefmt-nix": "treefmt-nix" + }, + "locked": { + "lastModified": 1780119579, + "narHash": "sha256-EnWR9fQzTfmIkyWD8ynYdAM573x3wzkOzZuMagrEosQ=", + "owner": "numtide", + "repo": "llm-agents.nix", + "rev": "b8adcd1a8e45e6d84f511c1a3b12998634481204", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "llm-agents.nix", + "type": "github" + } + }, "niri-flake": { "inputs": { "niri-stable": "niri-stable", "niri-unstable": "niri-unstable", - "nixpkgs": "nixpkgs_2", + "nixpkgs": "nixpkgs_4", "nixpkgs-stable": "nixpkgs-stable", "xwayland-satellite-stable": "xwayland-satellite-stable", "xwayland-satellite-unstable": "xwayland-satellite-unstable" }, "locked": { - "lastModified": 1777815637, - "narHash": "sha256-jQnoHmnFgUWYDNosplgd5eFnUTT0MtEj2w9HCA4g1C0=", + "lastModified": 1779748545, + "narHash": "sha256-AbRQrrpcNTBUoIf7Kc1qsdhsRLtZ0DDw+udm+8NWlJk=", "owner": "sodiboo", "repo": "niri-flake", - "rev": "945748d71d3422d4f1dada2cd10222e34ed9d767", + "rev": "3754a033e05c750ef46fe4f078d79b826c4f9287", "type": "github" }, "original": { @@ -437,11 +587,11 @@ "niri-unstable": { "flake": false, "locked": { - "lastModified": 1777733745, - "narHash": "sha256-1TlpdT0WYyBGtUS3PH4oXHUmdno2EUh2TfHadK2BmJo=", + "lastModified": 1779374863, + "narHash": "sha256-qKWgJ2MUODpg+b8tOwWMdMKREvs8TdGBz63SHaQZCeA=", "owner": "YaLTeR", "repo": "niri", - "rev": "1f07cffa9f355298a31d7efe1b400ede93a97728", + "rev": "4294948cf1c70c50e938383c2c865d7ca455ac7e", "type": "github" }, "original": { @@ -452,11 +602,11 @@ }, "nixos-hardware": { "locked": { - "lastModified": 1777796046, - "narHash": "sha256-bEJp/zaQApzynGRaAO62BZSz9tFikKtIHCn2yIA/s7Q=", + "lastModified": 1779826373, + "narHash": "sha256-3sRzgLX86qV5NlhWUAufLmHwkyP03tmL3VdZIM13dEo=", "owner": "NixOS", "repo": "nixos-hardware", - "rev": "eeb02f6e29fc8139c0b15af5ff0fdfdc6d0d3d90", + "rev": "ef4efb84766a166c906bd55759574676bf91267c", "type": "github" }, "original": { @@ -468,8 +618,8 @@ }, "nixos-wsl": { "inputs": { - "flake-compat": "flake-compat_3", - "nixpkgs": "nixpkgs_3" + "flake-compat": "flake-compat_4", + "nixpkgs": "nixpkgs_5" }, "locked": { "lastModified": 1777732699, @@ -498,13 +648,28 @@ "url": "https://channels.nixos.org/nixpkgs-unstable/nixexprs.tar.xz" } }, + "nixpkgs-lib": { + "locked": { + "lastModified": 1777168982, + "narHash": "sha256-GOkGPcboWE9BmGCRMLX3worL4EMnsnG8MyKmXNeYuhQ=", + "owner": "nix-community", + "repo": "nixpkgs.lib", + "rev": "f5901329dade4a6ea039af1433fb087bd9c1fe14", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixpkgs.lib", + "type": "github" + } + }, "nixpkgs-stable": { "locked": { - "lastModified": 1777673416, - "narHash": "sha256-5c2POKPOjU40Kh0MirOdScBLG0bu9TAuPYAtPRNZMBs=", + "lastModified": 1779467186, + "narHash": "sha256-nOesoDCiXcUftqbRBMz9tt4blI5PvljMWbm3kuCA+0s=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "26ef669cffa904b6f6832ab57b77892a37c1a671", + "rev": "b77b3de8775677f84492abe84635f87b0e153f0f", "type": "github" }, "original": { @@ -516,11 +681,11 @@ }, "nixpkgs-unstable": { "locked": { - "lastModified": 1777641297, - "narHash": "sha256-WNGcmeOZ8Tr9dq6ztCspYbzWFswr2mPebM9LpsfGxPk=", + "lastModified": 1779786838, + "narHash": "sha256-0geHoGiR5f8qiXg+gO4rSF6Up6Var+kKqiOv9AO/uUc=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "c6d65881c5624c9cae5ea6cedef24699b0c0a4c0", + "rev": "f44f7788c891fbe5542177df78374f8cdab10e8f", "type": "github" }, "original": { @@ -532,11 +697,43 @@ }, "nixpkgs_2": { "locked": { - "lastModified": 1777578337, - "narHash": "sha256-Ad49moKWeXtKBJNy2ebiTQUEgdLyvGmTeykAQ9xM+Z4=", + "lastModified": 1770073757, + "narHash": "sha256-Vy+G+F+3E/Tl+GMNgiHl9Pah2DgShmIUBJXmbiQPHbI=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "15f4ee454b1dce334612fa6843b3e05cf546efab", + "rev": "47472570b1e607482890801aeaf29bfb749884f6", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixpkgs-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_3": { + "locked": { + "lastModified": 1779955849, + "narHash": "sha256-31mhzm2HpzRr/rupWAFfWBmt9SUjzwr5+giv5Nmb/rA=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "a2c6938835fca96e4a10c8561d461efd2f91d04f", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable-small", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_4": { + "locked": { + "lastModified": 1779560665, + "narHash": "sha256-tpyBcxPpcQb8ukyNF7DoCwfSY3VPsxHoYwj00Cayv5o=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "64c08a7ca051951c8eae34e3e3cb1e202fe36786", "type": "github" }, "original": { @@ -546,7 +743,7 @@ "type": "github" } }, - "nixpkgs_3": { + "nixpkgs_5": { "locked": { "lastModified": 1776169885, "narHash": "sha256-l/iNYDZ4bGOAFQY2q8y5OAfBBtrDAaPuRQqWaFHVRXM=", @@ -562,23 +759,39 @@ "type": "github" } }, - "nixpkgs_4": { + "nixpkgs_6": { "locked": { - "lastModified": 1777673416, - "narHash": "sha256-5c2POKPOjU40Kh0MirOdScBLG0bu9TAuPYAtPRNZMBs=", + "lastModified": 1779622335, + "narHash": "sha256-ViA62qtL5za7V3d5I8OA9q9JcFhsVAiL5jVHwEclWqk=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "26ef669cffa904b6f6832ab57b77892a37c1a671", + "rev": "705e9929918b43bd7b715dc0a878ac870449bb03", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-25.11", + "ref": "nixos-26.05", "repo": "nixpkgs", "type": "github" } }, - "nixpkgs_5": { + "nixpkgs_7": { + "locked": { + "lastModified": 1770107345, + "narHash": "sha256-tbS0Ebx2PiA1FRW8mt8oejR0qMXmziJmPaU1d4kYY9g=", + "owner": "nixos", + "repo": "nixpkgs", + "rev": "4533d9293756b63904b7238acb84ac8fe4c8c2c4", + "type": "github" + }, + "original": { + "owner": "nixos", + "ref": "nixpkgs-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_8": { "locked": { "lastModified": 1772542754, "narHash": "sha256-WGV2hy+VIeQsYXpsLjdr4GvHv5eECMISX1zKLTedhdg=", @@ -596,24 +809,22 @@ }, "nixvim": { "inputs": { - "flake-parts": "flake-parts", + "flake-parts": "flake-parts_3", "nixpkgs": [ "nixpkgs" ], - "nuschtosSearch": "nuschtosSearch", "systems": "systems_3" }, "locked": { - "lastModified": 1769049374, - "narHash": "sha256-h0Os2qqNyycDY1FyZgtbn28VF1ySP74/n0f+LDd8j+w=", + "lastModified": 1779816597, + "narHash": "sha256-Kgod3gZlhSp6WozZ2pFaclXbWpjs6kQLAtldoxb85Lc=", "owner": "nix-community", "repo": "nixvim", - "rev": "b8f76bf5751835647538ef8784e4e6ee8deb8f95", + "rev": "297f9341476ba7f821a42d7a2805e206ef8c6ef8", "type": "github" }, "original": { "owner": "nix-community", - "ref": "nixos-25.11", "repo": "nixvim", "type": "github" } @@ -626,11 +837,11 @@ "noctalia-qs": "noctalia-qs" }, "locked": { - "lastModified": 1777772763, - "narHash": "sha256-MIFrNTX+x42UdOiL9lWmwyyymh80/pxtU4afvEizZDk=", + "lastModified": 1779763713, + "narHash": "sha256-as2Vo4PitnWfXezfkQB2H3Rsr/DXJPp4Oe+dE+dZ0Xo=", "owner": "noctalia-dev", "repo": "noctalia-shell", - "rev": "f0469d2d6f9b1ca873932dcef6583f9d6a2eee28", + "rev": "272cd91408b5ff6e329e6397eed042fe422069e7", "type": "github" }, "original": { @@ -646,14 +857,14 @@ "nixpkgs" ], "systems": "systems_4", - "treefmt-nix": "treefmt-nix" + "treefmt-nix": "treefmt-nix_2" }, "locked": { - "lastModified": 1777380063, - "narHash": "sha256-q5mWOEICcZzr+KnjIwDHV9EXiBxOC9cnBpxZbDAViU8=", + "lastModified": 1779588472, + "narHash": "sha256-CVonDVo41DqdqS/kNeXFatwEuTltyXcppm9zkVOnrsM=", "owner": "noctalia-dev", "repo": "noctalia-qs", - "rev": "8742a7a748c43bf44eb6862a8ebd3591ed71502d", + "rev": "70fea8a39a908e395de63024a4dfdb829bff1ffe", "type": "github" }, "original": { @@ -674,11 +885,11 @@ ] }, "locked": { - "lastModified": 1775228139, - "narHash": "sha256-ebbeHmg+V7w8050bwQOuhmQHoLOEOfqKzM1KgCTexK4=", + "lastModified": 1779766384, + "narHash": "sha256-P7Ohnlq8b8b2fU+Sgkrej7LBTM60LBTkHleLuYzmLmU=", "owner": "nix-community", "repo": "NUR", - "rev": "601971b9c89e0304561977f2c28fa25e73aa7132", + "rev": "57800b7ab648725ccd33551d01484ee14952ad3f", "type": "github" }, "original": { @@ -687,44 +898,21 @@ "type": "github" } }, - "nuschtosSearch": { - "inputs": { - "flake-utils": "flake-utils", - "ixx": "ixx", - "nixpkgs": [ - "nixvim", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1768249818, - "narHash": "sha256-ANfn5OqIxq3HONPIXZ6zuI5sLzX1sS+2qcf/Pa0kQEc=", - "owner": "NuschtOS", - "repo": "search", - "rev": "b6f77b88e9009bfde28e2130e218e5123dc66796", - "type": "github" - }, - "original": { - "owner": "NuschtOS", - "repo": "search", - "type": "github" - } - }, "pre-commit": { "inputs": { - "flake-compat": "flake-compat_2", - "gitignore": "gitignore", + "flake-compat": "flake-compat_3", + "gitignore": "gitignore_2", "nixpkgs": [ "lanzaboote", "nixpkgs" ] }, "locked": { - "lastModified": 1776796298, - "narHash": "sha256-PcRvlWayisPSjd0UcRQbhG8Oqw78AcPE6x872cPRHN8=", + "lastModified": 1778507602, + "narHash": "sha256-kTwur1wV+01SdqskVMSo6JMEpg71ps3HpbFY2GsflKs=", "owner": "cachix", "repo": "pre-commit-hooks.nix", - "rev": "3cfd774b0a530725a077e17354fbdb87ea1c4aad", + "rev": "61ab0e80d9c7ab14c256b5b453d8b3fb0189ba0a", "type": "github" }, "original": { @@ -740,11 +928,11 @@ ] }, "locked": { - "lastModified": 1777706159, - "narHash": "sha256-TuD8hw9lkRCEb+6v93iB7HDvcmvH8R0qyD6wBmPGfv8=", + "lastModified": 1779430452, + "narHash": "sha256-zTslhsxLqUlRTML506iougTGzyR38Fzhzn7t4KDEuuE=", "owner": "outfoxxed", "repo": "quickshell", - "rev": "8db8ca1fecfcce8def1f9265fa1742baa0e0c271", + "rev": "4b4fca3224ab977dc515ac0bb78d00b3dfa71e00", "type": "github" }, "original": { @@ -755,18 +943,26 @@ }, "root": { "inputs": { + "disko": "disko", + "flake-parts": "flake-parts", "ghostty": "ghostty", + "git-hooks-nix": "git-hooks-nix", "home-manager": "home-manager_2", "lanzaboote": "lanzaboote", + "llm-agents": "llm-agents", "niri-flake": "niri-flake", "nixos-hardware": "nixos-hardware", "nixos-wsl": "nixos-wsl", - "nixpkgs": "nixpkgs_4", + "nixpkgs": "nixpkgs_6", "nixpkgs-unstable": "nixpkgs-unstable", "nixvim": "nixvim", "noctalia": "noctalia", "quickshell": "quickshell", + "services-flake": "services-flake", + "sops-nix": "sops-nix", "stylix": "stylix", + "systems": "systems_6", + "treefmt-nix": "treefmt-nix_3", "vicinae": "vicinae", "vicinae-extensions": "vicinae-extensions" } @@ -779,11 +975,11 @@ ] }, "locked": { - "lastModified": 1777173302, - "narHash": "sha256-ERiu3cbxvnTDxiDcimRA7af7xp6x1y0sRyLGm28Qzz8=", + "lastModified": 1779592685, + "narHash": "sha256-p9d56GezhHRf4QfANxwa1d+fvwShvjB5XUhdIl7WEd0=", "owner": "oxalica", "repo": "rust-overlay", - "rev": "aaec8c50baeaf2f2ba653e8aae71778a2bbbac94", + "rev": "3a58b199e7c83a80b85c28044f808085ba7e941c", "type": "github" }, "original": { @@ -792,6 +988,41 @@ "type": "github" } }, + "services-flake": { + "locked": { + "lastModified": 1779042632, + "narHash": "sha256-WgQZ1AsDMCTL+0x0yZEd1g3yMQbgEwAq0VUg73YU50M=", + "owner": "juspay", + "repo": "services-flake", + "rev": "b0012dbf955efc3f6e2decd61610da5cea17dce6", + "type": "github" + }, + "original": { + "owner": "juspay", + "repo": "services-flake", + "type": "github" + } + }, + "sops-nix": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1780547341, + "narHash": "sha256-Gq8KNx5A7hBB3uGJaj6eQfLDIz5YdLu92gqBcvHvoUo=", + "owner": "Mic92", + "repo": "sops-nix", + "rev": "9ed65852b6257fbeae4355bc24ecfea307ca759a", + "type": "github" + }, + "original": { + "owner": "Mic92", + "repo": "sops-nix", + "type": "github" + } + }, "stylix": { "inputs": { "base16": "base16", @@ -799,7 +1030,7 @@ "base16-helix": "base16-helix", "base16-vim": "base16-vim", "firefox-gnome-theme": "firefox-gnome-theme", - "flake-parts": "flake-parts_2", + "flake-parts": "flake-parts_4", "gnome-shell": "gnome-shell", "nixpkgs": [ "nixpkgs" @@ -812,11 +1043,11 @@ "tinted-zed": "tinted-zed" }, "locked": { - "lastModified": 1777580129, - "narHash": "sha256-6buSTzDtHYCJP1JNAIZCmgNcOs76oN03j+21CxdijVo=", + "lastModified": 1779835981, + "narHash": "sha256-3VQklog/kSD9dw6uj6ElSfq3qwEHQWHCThR/cGcJ5Dc=", "owner": "nix-community", "repo": "stylix", - "rev": "20ff51f523e2dd67e5f31a321719d30708c1b771", + "rev": "d7ba76c960a84333a7a1fc62ccf84a266086903a", "type": "github" }, "original": { @@ -902,6 +1133,21 @@ } }, "systems_6": { + "locked": { + "lastModified": 1689347949, + "narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=", + "owner": "nix-systems", + "repo": "default-linux", + "rev": "31732fcf5e8fea42e59c2488ad31a0e651500f68", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default-linux", + "type": "github" + } + }, + "systems_7": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -916,7 +1162,7 @@ "type": "github" } }, - "systems_7": { + "systems_8": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -950,11 +1196,11 @@ "tinted-schemes": { "flake": false, "locked": { - "lastModified": 1772661346, - "narHash": "sha256-4eu3LqB9tPqe0Vaqxd4wkZiBbthLbpb7llcoE/p5HT0=", + "lastModified": 1777806186, + "narHash": "sha256-PDF0/wObw4nIsSBeXVYLsloXOiphXCgIdsrNcVXguKs=", "owner": "tinted-theming", "repo": "schemes", - "rev": "13b5b0c299982bb361039601e2d72587d6846294", + "rev": "0c94645546f4f3ddac77a1a5fce54eb95bf50795", "type": "github" }, "original": { @@ -966,11 +1212,11 @@ "tinted-tmux": { "flake": false, "locked": { - "lastModified": 1772934010, - "narHash": "sha256-x+6+4UvaG+RBRQ6UaX+o6DjEg28u4eqhVRM9kpgJGjQ=", + "lastModified": 1778379944, + "narHash": "sha256-wPDFzMGSlARlw0Sfsn48Q2+jPSfk6N0Ng6BC/d+7Q24=", "owner": "tinted-theming", "repo": "tinted-tmux", - "rev": "c3529673a5ab6e1b6830f618c45d9ce1bcdd829d", + "rev": "fe0203a198690e71a5ff11e08812a4673de3678d", "type": "github" }, "original": { @@ -982,11 +1228,11 @@ "tinted-zed": { "flake": false, "locked": { - "lastModified": 1772909925, - "narHash": "sha256-jx/5+pgYR0noHa3hk2esin18VMbnPSvWPL5bBjfTIAU=", + "lastModified": 1778378178, + "narHash": "sha256-OXPXRIQgGwV77HjYRryOHguh4ALX96jkg+tseLkGgHA=", "owner": "tinted-theming", "repo": "base16-zed", - "rev": "b4d3a1b3bcbd090937ef609a0a3b37237af974df", + "rev": "9cd816033ff969415b190722cddf134e78a5665f", "type": "github" }, "original": { @@ -996,6 +1242,27 @@ } }, "treefmt-nix": { + "inputs": { + "nixpkgs": [ + "llm-agents", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1775636079, + "narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=", + "owner": "numtide", + "repo": "treefmt-nix", + "rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "treefmt-nix", + "type": "github" + } + }, + "treefmt-nix_2": { "inputs": { "nixpkgs": [ "noctalia", @@ -1017,17 +1284,35 @@ "type": "github" } }, - "vicinae": { + "treefmt-nix_3": { "inputs": { - "nixpkgs": "nixpkgs_5", - "systems": "systems_6" + "nixpkgs": "nixpkgs_7" }, "locked": { - "lastModified": 1777815457, - "narHash": "sha256-tOHe63NSWVFYBry/KSd5wwF9Khha5AXT5Dqx+Z6ICww=", + "lastModified": 1775636079, + "narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=", + "owner": "numtide", + "repo": "treefmt-nix", + "rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "treefmt-nix", + "type": "github" + } + }, + "vicinae": { + "inputs": { + "nixpkgs": "nixpkgs_8", + "systems": "systems_7" + }, + "locked": { + "lastModified": 1779832601, + "narHash": "sha256-/dtn1sOTEcb/rNInzkdnK8PNIIDfQi7fEJfQEq+Is4g=", "owner": "vicinaehq", "repo": "vicinae", - "rev": "5ab9b061690e9e8695ec62dc793f9a3bda2eb616", + "rev": "dc1f7d47725c68debdb31be26781a96c14bac059", "type": "github" }, "original": { @@ -1038,19 +1323,19 @@ }, "vicinae-extensions": { "inputs": { - "flake-compat": "flake-compat_4", + "flake-compat": "flake-compat_5", "nixpkgs": [ "nixpkgs" ], - "systems": "systems_7", + "systems": "systems_8", "vicinae": "vicinae_2" }, "locked": { - "lastModified": 1777597325, - "narHash": "sha256-LfqeVlMwclHJKsJu5jJoztjlaCeIasQsiv3P9+eKDNw=", + "lastModified": 1779152347, + "narHash": "sha256-V9ByOBzaUCMessP9T8LwXQTYl+eIQr+NeGceRprbsT8=", "owner": "vicinaehq", "repo": "extensions", - "rev": "89cc49471c3e7119bfd36d68998cefe534bddab8", + "rev": "5ef25b54b9db906b391ef7e6b85177f6ecd7f3d6", "type": "github" }, "original": { @@ -1104,11 +1389,11 @@ "xwayland-satellite-unstable": { "flake": false, "locked": { - "lastModified": 1773622265, - "narHash": "sha256-wToKwH7IgWdGLMSIWksEDs4eumR6UbbsuPQ42r0oTXQ=", + "lastModified": 1779745227, + "narHash": "sha256-yqY7RtEJGJiENzR0GwL6q69tSAy6xAAmAcLuIhLjPf8=", "owner": "Supreeeme", "repo": "xwayland-satellite", - "rev": "a879e5e0896a326adc79c474bf457b8b99011027", + "rev": "5d1efbc9dc3ab1c10160b656e0247f3325daf0f2", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix index 6aeb50f..95922bb 100644 --- a/flake.nix +++ b/flake.nix @@ -1,142 +1,106 @@ { - description = "moons nix configurations and development shells"; + description = "moons NixOS configurations"; inputs = { - nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11"; + # NixOS + nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05"; nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable"; - nixos-hardware.url = "github:NixOS/nixos-hardware/master"; - nixos-wsl.url = "github:nix-community/NixOS-WSL"; + home-manager = { - url = "github:nix-community/home-manager/release-25.11"; + url = "github:nix-community/home-manager"; inputs.nixpkgs.follows = "nixpkgs"; }; + # Hardware / Platform + nixos-hardware.url = "github:NixOS/nixos-hardware/master"; + nixos-wsl.url = "github:nix-community/NixOS-WSL"; + + # Desktop + niri-flake.url = "github:sodiboo/niri-flake"; + + stylix = { + url = "github:nix-community/stylix"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + # Terminal + ghostty.url = "github:ghostty-org/ghostty"; + + # Shell / Launcher vicinae.url = "github:vicinaehq/vicinae"; + vicinae-extensions = { url = "github:vicinaehq/extensions"; inputs.nixpkgs.follows = "nixpkgs"; }; - ghostty.url = "github:ghostty-org/ghostty"; - niri-flake.url = "github:sodiboo/niri-flake"; - quickshell = { url = "github:outfoxxed/quickshell"; inputs.nixpkgs.follows = "nixpkgs"; }; + noctalia = { url = "github:noctalia-dev/noctalia-shell"; inputs.nixpkgs.follows = "nixpkgs"; inputs.quickshell.follows = "quickshell"; }; - stylix = { - url = "github:nix-community/stylix"; + + # Editor + nixvim = { + url = "github:nix-community/nixvim"; inputs.nixpkgs.follows = "nixpkgs"; }; + + # Secrets management + sops-nix = { + url = "github:Mic92/sops-nix"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + # Disk management + disko = { + url = "github:nix-community/disko"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + # Boot lanzaboote = { url = "github:nix-community/lanzaboote"; inputs.nixpkgs.follows = "nixpkgs"; }; - nixvim = { - url = "github:nix-community/nixvim/nixos-25.11"; - inputs.nixpkgs.follows = "nixpkgs"; - }; + # Flake framework + flake-parts.url = "github:hercules-ci/flake-parts"; + + # Code formatting and git hooks + treefmt-nix.url = "github:numtide/treefmt-nix"; + git-hooks-nix.url = "github:cachix/git-hooks.nix"; + + # Dev services + services-flake.url = "github:juspay/services-flake"; + + # LLM agents + llm-agents.url = "github:numtide/llm-agents.nix"; + + # Systems + systems.url = "github:nix-systems/default-linux"; }; - outputs = inputs @ { - self, - nixpkgs, - nixpkgs-unstable, - nixos-hardware, - home-manager, - ... - }: let - mkSystem = { - host, - system, - profile, - extraModules ? [], + outputs = + inputs@{ + flake-parts, + systems, + ... }: - nixpkgs.lib.nixosSystem { - inherit system; - specialArgs = { - inherit inputs; - inherit host; - inherit profile; - }; - modules = - [ - ./overlays - ./modules/core - ./profiles/${profile}.nix - ./hosts/${host} - ] - ++ extraModules; - }; - in { - nixosConfigurations = { - x1g9 = mkSystem { - host = "x1g9"; - system = "x86_64-linux"; - profile = "laptop"; - extraModules = []; - }; - x1g13-wsl = mkSystem { - host = "x1g13-wsl"; - system = "x86_64-linux"; - profile = "cli"; - extraModules = []; - }; - x1g13 = mkSystem { - host = "x1g13"; - system = "x86_64-linux"; - profile = "laptop"; - extraModules = []; - }; - monitor = mkSystem { - host = "monitor"; - system = "x86_64-linux"; - profile = "cli-server"; - extraModules = []; - }; - dev-1 = mkSystem { - host = "dev-1"; - system = "x86_64-linux"; - profile = "cli-server"; - extraModules = []; - }; - service-1 = mkSystem { - host = "service-1"; - system = "x86_64-linux"; - profile = "cli-server"; - extraModules = []; - }; - ops = mkSystem { - host = "ops"; - system = "x86_64-linux"; - profile = "cli-server"; - extraModules = []; - }; - nix-test = mkSystem { - host = "nix-test"; - system = "x86_64-linux"; - profile = "cli-server"; - extraModules = []; - }; - }; + flake-parts.lib.mkFlake { inherit inputs; } { + systems = import systems; - devShells = { - x86_64-linux = let - pkgs = import nixpkgs { - system = "x86_64-linux"; - config.allowUnfreePredicate = pkg: builtins.elem (nixpkgs.lib.getName pkg) ["ngrok"]; - }; - in { - next-web = import ./shells/next-web.nix {inherit pkgs;}; - jupyter = import ./shells/jupyter.nix {inherit pkgs;}; - rust = import ./shells/rust/default.nix {inherit pkgs;}; - }; + imports = [ + ./overlays + ./hosts + ./shells + ./flake/formatter.nix + ./flake/git-hooks.nix + ]; }; - }; } diff --git a/flake/formatter.nix b/flake/formatter.nix new file mode 100644 index 0000000..e86b7d4 --- /dev/null +++ b/flake/formatter.nix @@ -0,0 +1,35 @@ +{ inputs, ... }: +{ + imports = [ + inputs.treefmt-nix.flakeModule + ]; + + perSystem = _: { + treefmt = { + projectRootFile = "flake.nix"; + + programs = { + nixfmt.enable = true; + deadnix.enable = true; + statix.enable = true; + + shfmt.enable = true; + shellcheck.enable = true; + + prettier.enable = true; + yamlfmt.enable = true; + taplo.enable = true; + oxfmt.enable = true; + }; + + settings = { + excludes = [ + ".git/**" + "*.lock" + ".direnv/**" + "*.age" + ]; + }; + }; + }; +} diff --git a/flake/git-hooks.nix b/flake/git-hooks.nix new file mode 100644 index 0000000..31ffd2c --- /dev/null +++ b/flake/git-hooks.nix @@ -0,0 +1,43 @@ +{ inputs, ... }: +{ + imports = [ + inputs.git-hooks-nix.flakeModule + ]; + + perSystem = + { + pkgs, + config, + ... + }: + { + pre-commit.settings = { + hooks = { + treefmt = { + enable = true; + + package = config.treefmt.build.wrapper; + }; + + gitleaks = { + enable = true; + name = "gitleaks"; + description = "Detect hardcoded secrets"; + + entry = "${pkgs.gitleaks}/bin/gitleaks dir --no-banner --redact --verbose ."; + + pass_filenames = false; + + stages = [ + "pre-commit" + "pre-push" + ]; + }; + + deadnix.enable = true; + statix.enable = true; + shellcheck.enable = true; + }; + }; + }; +} diff --git a/hosts/default.nix b/hosts/default.nix new file mode 100644 index 0000000..0cbb0c1 --- /dev/null +++ b/hosts/default.nix @@ -0,0 +1,84 @@ +{ + inputs, + pkgs, + config, + lib, + ... +}: +let + inherit (inputs.nixpkgs.lib) nixosSystem; + + username = "moons"; + + unstable = import inputs.nixpkgs-unstable { + inherit (pkgs) system; + config = { + allowUnfree = true; + }; + }; + + mkSystem = + { + host, + system, + profiles ? [ ], + extraModules ? [ ], + }: + assert lib.assertMsg (lib.elem system config.systems) + "mkSystem: system '${system}' not in valid systems: ${lib.generators.toPretty { } config.systems}"; + nixosSystem { + inherit system; + modules = [ + { + nixpkgs.config.allowUnfree = true; + } + ../modules + ./${host}/default.nix + ] + ++ map (p: ../profiles/${p}.nix) profiles + ++ extraModules; + specialArgs = { + inherit + inputs + username + unstable + host + ; + }; + }; +in +{ + flake.nixosConfigurations = { + nix-example = mkSystem { + host = "nix-example"; + system = "x86_64-linux"; + profiles = [ + "interfaces/cli-interactive" + "platforms/vm" + "workloads/dev" + "workloads/remote" + ]; + }; + x1g13 = mkSystem { + host = "x1g13"; + system = "x86_64-linux"; + profiles = [ + "interfaces/gui" + "platforms/thinkpad" + "workloads/dev" + "workloads/personal" + "workloads/secure-storage" + ]; + }; + + installer = nixosSystem { + system = "x86_64-linux"; + modules = [ + ./installer/default.nix + ]; + specialArgs = { + inherit inputs; + }; + }; + }; +} diff --git a/hosts/dev-1/default.nix b/hosts/dev-1/default.nix deleted file mode 100644 index 1ad056a..0000000 --- a/hosts/dev-1/default.nix +++ /dev/null @@ -1,12 +0,0 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page -# and in the NixOS manual (accessible by running ‘nixos-help’). - -{ ... }: - -{ - imports = - [ - ./hardware-configuration.nix - ]; -} diff --git a/hosts/dev-1/hardware-configuration.nix b/hosts/dev-1/hardware-configuration.nix deleted file mode 100644 index 44e95bd..0000000 --- a/hosts/dev-1/hardware-configuration.nix +++ /dev/null @@ -1,37 +0,0 @@ -# Do not modify this file! It was generated by ‘nixos-generate-config’ -# and may be overwritten by future invocations. Please make changes -# to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: - -{ - imports = - [ (modulesPath + "/profiles/qemu-guest.nix") - ]; - - boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ ]; - boot.extraModulePackages = [ ]; - - fileSystems."/" = - { device = "/dev/disk/by-uuid/53d2fe07-d84b-4cda-9428-45a3361d6b11"; - fsType = "ext4"; - }; - - fileSystems."/boot" = - { device = "/dev/disk/by-uuid/72E9-E469"; - fsType = "vfat"; - options = [ "fmask=0022" "dmask=0022" ]; - }; - - swapDevices = [ ]; - - # Enables DHCP on each ethernet and wireless interface. In case of scripted networking - # (the default) this is the recommended approach. When using systemd-networkd it's - # still possible to use this option, but it's recommended to use it in conjunction - # with explicit per-interface declarations with `networking.interfaces..useDHCP`. - networking.useDHCP = lib.mkDefault true; - # networking.interfaces.ens18.useDHCP = lib.mkDefault true; - - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; -} diff --git a/hosts/installer/default.nix b/hosts/installer/default.nix new file mode 100644 index 0000000..fcbe24f --- /dev/null +++ b/hosts/installer/default.nix @@ -0,0 +1,191 @@ +{ + pkgs, + lib, + modulesPath, + ... +}: +{ + imports = [ + "${modulesPath}/installer/cd-dvd/installation-cd-minimal.nix" + ]; + + networking = { + hostName = "nixos-installer"; + + networkmanager = { + enable = true; + wifi.powersave = false; + }; + }; + + services.openssh = { + enable = true; + settings = { + PermitRootLogin = "prohibit-password"; + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + PubkeyAuthentication = "yes"; + }; + }; + + users.users.root.openssh.authorizedKeys.keys = [ + "sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIKhxDkucmeCor6CKoXAua7DgDSzuXrZOtpdkyzQxz5+aAAAABHNzaDo= moons@moons14.com" + "sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIN6hZJyng/5LgFKPjR6uZAd/00UkO0vN0uQOoIvfSELdAAAABHNzaDo= moons@moons14.com" + ]; + + environment.systemPackages = with pkgs; [ + git # Clone dotfiles repository + disko # Disk partitioning + sops # Secrets management + age # Age encryption + ssh-to-age # Convert SSH keys to age + age-plugin-yubikey # YubiKey support + yubikey-manager # YubiKey management + pcsc-tools # Smart card tools + mkpasswd # Password hash generation + rsync # File synchronization + vim # Text editor + wget # Download files + curl # HTTP client + jq # JSON processor + parted # Partition tools + cryptsetup # LUKS encryption + btrfs-progs # Btrfs filesystem tools + ]; + + services.pcscd.enable = true; + + environment.etc."installer-help.txt".text = '' + + ╔══════════════════════════════════════════════════════════════╗ + ║ NixOS Installer ISO ║ + ╠══════════════════════════════════════════════════════════════╣ + ║ ║ + ║ SSH Access: ║ + ║ ssh root@ ║ + ║ ║ + ║ Network Setup: ║ + ║ Wired: Auto-configured via DHCP ║ + ║ WiFi: nmcli device wifi connect --ask ║ + ║ ║ + ║ Installation Workflow: ║ + ║ ║ + ║ 1. Clone dotfiles: ║ + ║ git clone git@github.com:moons-14/dotfiles.git ~/dotfiles║ + ║ ║ + ║ 2. Generate SSH host key for new host: ║ + ║ ssh-keygen -t ed25519 -f /tmp/ssh_host_ed25519_key -N "" ║ + ║ ║ + ║ 3. Get age public key from SSH host key: ║ + ║ ssh-to-age -i /tmp/ssh_host_ed25519_key.pub ║ + ║ ║ + ║ 4. Add age key to .sops.yaml: ║ + ║ cd ~/dotfiles ║ + ║ # Edit .sops.yaml and add the age key ║ + ║ # Add new host entry to creation_rules ║ + ║ ║ + ║ 5. Re-encrypt secrets: ║ + ║ sops updatekeys secrets/common/system.yaml ║ + ║ sops updatekeys secrets/hosts//*.yaml ║ + ║ ║ + ║ 6. Create disko.nix for new host: ║ + ║ # Check disk devices ║ + ║ lsblk -f ║ + ║ ║ + ║ # Create hosts//disko.nix ║ + ║ # Example: LUKS + btrfs ║ + ║ # See hosts/x1g13/disko.nix for reference ║ + ║ ║ + ║ 7. Partition disk with disko: ║ + ║ nix run github:nix-community/disko -- \ ║ + ║ --mode disko hosts//disko.nix ║ + ║ ║ + ║ 8. Copy host key to installed system: ║ + ║ mkdir -p /mnt/etc/ssh ║ + ║ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ ║ + ║ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ║ + ║ ║ + ║ 9. Install NixOS: ║ + ║ nixos-install --flake ~/dotfiles# ║ + ║ ║ + ║ Disko Configuration Examples: ║ + ║ ║ + ║ Simple (no encryption): ║ + ║ disko.devices.disk.main = { ║ + ║ type = "disk"; ║ + ║ device = "/dev/sda"; ║ + ║ content = { ║ + ║ type = "gpt"; ║ + ║ partitions = { ║ + ║ ESP = { size = "512M"; type = "EF00"; ║ + ║ content = { type = "filesystem"; ║ + ║ format = "vfat"; mountpoint = "/boot"; }; }; ║ + ║ root = { size = "100%"; ║ + ║ content = { type = "filesystem"; ║ + ║ format = "ext4"; mountpoint = "/"; }; }; ║ + ║ }; ║ + ║ }; ║ + ║ }; ║ + ║ ║ + ║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║ + ║ - Use partuuid for device path ║ + ║ - Set askPassword = true for LUKS ║ + ║ - Configure btrfs subvolumes ║ + ║ ║ + ╚══════════════════════════════════════════════════════════════╝ + + ''; + + systemd.services.installer-banner = { + description = "Display installer help on console"; + wantedBy = [ "multi-user.target" ]; + serviceConfig = { + Type = "oneshot"; + ExecStart = "${pkgs.coreutils}/bin/cat /etc/installer-help.txt"; + StandardOutput = "tty"; + TTYPath = "/dev/tty1"; + }; + }; + + systemd.services.display-ip = { + description = "Display IP address on console"; + wantedBy = [ "multi-user.target" ]; + after = [ "network-online.target" ]; + wants = [ "network-online.target" ]; + serviceConfig = { + Type = "oneshot"; + ExecStart = pkgs.writeShellScript "display-ip" '' + sleep 2 + echo "" + echo "=== Network Interfaces ===" + ${pkgs.iproute2}/bin/ip -4 addr show | ${pkgs.gnugrep}/bin/grep inet + echo "" + echo "=== SSH Access ===" + for ip in $(${pkgs.iproute2}/bin/ip -4 addr show | ${pkgs.gnugrep}/bin/grep -oP 'inet \K[\d.]+' | ${pkgs.gnugrep}/bin/grep -v '127.0.0.1'); do + echo " ssh root@$ip" + done + echo "" + ''; + StandardOutput = "tty"; + TTYPath = "/dev/tty1"; + }; + }; + + nix = { + settings = { + experimental-features = [ + "nix-command" + "flakes" + ]; + trusted-users = [ "root" ]; + }; + + extraOptions = '' + experimental-features = nix-command flakes + ''; + }; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + + system.stateVersion = "26.05"; +} diff --git a/hosts/monitor/default.nix b/hosts/monitor/default.nix deleted file mode 100644 index 1ad056a..0000000 --- a/hosts/monitor/default.nix +++ /dev/null @@ -1,12 +0,0 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page -# and in the NixOS manual (accessible by running ‘nixos-help’). - -{ ... }: - -{ - imports = - [ - ./hardware-configuration.nix - ]; -} diff --git a/hosts/monitor/hardware-configuration.nix b/hosts/monitor/hardware-configuration.nix deleted file mode 100644 index 85b921e..0000000 --- a/hosts/monitor/hardware-configuration.nix +++ /dev/null @@ -1,37 +0,0 @@ -# Do not modify this file! It was generated by ‘nixos-generate-config’ -# and may be overwritten by future invocations. Please make changes -# to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: - -{ - imports = - [ (modulesPath + "/profiles/qemu-guest.nix") - ]; - - boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ ]; - boot.extraModulePackages = [ ]; - - fileSystems."/" = - { device = "/dev/disk/by-uuid/770de3b2-eb30-4ccd-b7a6-13e7655b1d5c"; - fsType = "ext4"; - }; - - fileSystems."/boot" = - { device = "/dev/disk/by-uuid/1308-E5E7"; - fsType = "vfat"; - options = [ "fmask=0077" "dmask=0077" ]; - }; - - swapDevices = [ ]; - - # Enables DHCP on each ethernet and wireless interface. In case of scripted networking - # (the default) this is the recommended approach. When using systemd-networkd it's - # still possible to use this option, but it's recommended to use it in conjunction - # with explicit per-interface declarations with `networking.interfaces..useDHCP`. - networking.useDHCP = lib.mkDefault true; - # networking.interfaces.ens18.useDHCP = lib.mkDefault true; - - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; -} diff --git a/hosts/nix-example/default.nix b/hosts/nix-example/default.nix new file mode 100644 index 0000000..2db9801 --- /dev/null +++ b/hosts/nix-example/default.nix @@ -0,0 +1,6 @@ +{ ... }: +{ + imports = [ + ./hardware-configuration.nix + ]; +} diff --git a/hosts/nix-example/hardware-configuration.nix b/hosts/nix-example/hardware-configuration.nix new file mode 100644 index 0000000..9eab558 --- /dev/null +++ b/hosts/nix-example/hardware-configuration.nix @@ -0,0 +1,43 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ + lib, + modulesPath, + ... +}: +{ + imports = [ + (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ + "ata_piix" + "uhci_hcd" + "virtio_pci" + "virtio_scsi" + "sd_mod" + "sr_mod" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = { + device = "/dev/disk/by-uuid/8f0eaec6-5dc9-4821-aa8d-fb6809b5a5bf"; + fsType = "ext4"; + }; + + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/201C-961B"; + fsType = "vfat"; + options = [ + "fmask=0077" + "dmask=0077" + ]; + }; + + swapDevices = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; +} diff --git a/hosts/nix-test/default.nix b/hosts/nix-test/default.nix deleted file mode 100644 index 1ad056a..0000000 --- a/hosts/nix-test/default.nix +++ /dev/null @@ -1,12 +0,0 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page -# and in the NixOS manual (accessible by running ‘nixos-help’). - -{ ... }: - -{ - imports = - [ - ./hardware-configuration.nix - ]; -} diff --git a/hosts/nix-test/hardware-configuration.nix b/hosts/nix-test/hardware-configuration.nix deleted file mode 100644 index 2fc6e47..0000000 --- a/hosts/nix-test/hardware-configuration.nix +++ /dev/null @@ -1,30 +0,0 @@ -# Do not modify this file! It was generated by ‘nixos-generate-config’ -# and may be overwritten by future invocations. Please make changes -# to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: - -{ - imports = - [ (modulesPath + "/profiles/qemu-guest.nix") - ]; - - boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ ]; - boot.extraModulePackages = [ ]; - - fileSystems."/" = - { device = "/dev/disk/by-uuid/8f0eaec6-5dc9-4821-aa8d-fb6809b5a5bf"; - fsType = "ext4"; - }; - - fileSystems."/boot" = - { device = "/dev/disk/by-uuid/201C-961B"; - fsType = "vfat"; - options = [ "fmask=0077" "dmask=0077" ]; - }; - - swapDevices = [ ]; - - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; -} diff --git a/hosts/ops/default.nix b/hosts/ops/default.nix deleted file mode 100644 index 16e1728..0000000 --- a/hosts/ops/default.nix +++ /dev/null @@ -1,45 +0,0 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page -# and in the NixOS manual (accessible by running ‘nixos-help’). -{...}: { - imports = [ - ./hardware-configuration.nix - ]; - - services.qemuGuest.enable = true; - - networking = { - useDHCP = false; - - interfaces = { - ens18 = { - useDHCP = false; - ipv4.addresses = [ - { - address = "10.50.128.20"; - prefixLength = 24; - } - ]; - }; - - ens19 = { - useDHCP = false; - ipv4.addresses = [ - { - address = "10.50.7.101"; - prefixLength = 24; - } - ]; - }; - }; - - defaultGateway = { - address = "10.50.128.1"; - interface = "ens18"; - }; - - nameservers = [ - "1.1.1.1" - ]; - }; -} diff --git a/hosts/ops/hardware-configuration.nix b/hosts/ops/hardware-configuration.nix deleted file mode 100644 index d8c4f55..0000000 --- a/hosts/ops/hardware-configuration.nix +++ /dev/null @@ -1,30 +0,0 @@ -# Do not modify this file! It was generated by ‘nixos-generate-config’ -# and may be overwritten by future invocations. Please make changes -# to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: - -{ - imports = - [ (modulesPath + "/profiles/qemu-guest.nix") - ]; - - boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ ]; - boot.extraModulePackages = [ ]; - - fileSystems."/" = - { device = "/dev/disk/by-uuid/69fa2193-1e4f-438a-8898-5de8a3f36e5b"; - fsType = "ext4"; - }; - - fileSystems."/boot" = - { device = "/dev/disk/by-uuid/D09B-4277"; - fsType = "vfat"; - options = [ "fmask=0077" "dmask=0077" ]; - }; - - swapDevices = [ ]; - - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; -} diff --git a/hosts/service-1/default.nix b/hosts/service-1/default.nix deleted file mode 100644 index 2133000..0000000 --- a/hosts/service-1/default.nix +++ /dev/null @@ -1,43 +0,0 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page -# and in the NixOS manual (accessible by running ‘nixos-help’). - -{ ... }: - -{ - imports = [ - ./hardware-configuration.nix - ]; - - fileSystems."/mnt/immich-nfs" = { - device = "unas.moons14.com:/var/nfs/shared/immich"; - fsType = "nfs"; - options = [ - "nfsvers=3" - "hard" - "timeo=600" - "retrans=2" - "noatime" - "_netdev" - "nofail" - "x-systemd.requires=network-online.target" - "x-systemd.after=network-online.target" - ]; - }; - - fileSystems."/mnt/cloudreve-nfs" = { - device = "unas.moons14.com:/var/nfs/shared/cloudreve"; - fsType = "nfs"; - options = [ - "nfsvers=3" - "hard" - "timeo=600" - "retrans=2" - "noatime" - "_netdev" - "nofail" - "x-systemd.requires=network-online.target" - "x-systemd.after=network-online.target" - ]; - }; -} diff --git a/hosts/service-1/hardware-configuration.nix b/hosts/service-1/hardware-configuration.nix deleted file mode 100644 index 2fd7fcf..0000000 --- a/hosts/service-1/hardware-configuration.nix +++ /dev/null @@ -1,37 +0,0 @@ -# Do not modify this file! It was generated by ‘nixos-generate-config’ -# and may be overwritten by future invocations. Please make changes -# to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: - -{ - imports = - [ (modulesPath + "/profiles/qemu-guest.nix") - ]; - - boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ ]; - boot.extraModulePackages = [ ]; - - fileSystems."/" = - { device = "/dev/disk/by-uuid/d9f05715-e68a-4d69-bf46-bd903b0782f0"; - fsType = "ext4"; - }; - - fileSystems."/boot" = - { device = "/dev/disk/by-uuid/1772-FC70"; - fsType = "vfat"; - options = [ "fmask=0077" "dmask=0077" ]; - }; - - swapDevices = [ ]; - - # Enables DHCP on each ethernet and wireless interface. In case of scripted networking - # (the default) this is the recommended approach. When using systemd-networkd it's - # still possible to use this option, but it's recommended to use it in conjunction - # with explicit per-interface declarations with `networking.interfaces..useDHCP`. - networking.useDHCP = lib.mkDefault true; - # networking.interfaces.ens18.useDHCP = lib.mkDefault true; - - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; -} diff --git a/hosts/x1g13-wsl/default.nix b/hosts/x1g13-wsl/default.nix deleted file mode 100644 index 04bfa4c..0000000 --- a/hosts/x1g13-wsl/default.nix +++ /dev/null @@ -1,18 +0,0 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page -# and in the NixOS manual (accessible by running ‘nixos-help’). - -{ lib, inputs, ... }: - -{ - imports = - [ - inputs.nixos-wsl.nixosModules.wsl - ]; - - wsl.enable = true; - wsl.defaultUser = "moons"; - - boot.loader.systemd-boot.enable = lib.mkForce false; - boot.loader.grub.enable = lib.mkForce false; -} diff --git a/hosts/x1g13/default.nix b/hosts/x1g13/default.nix index abb7787..81f90fb 100644 --- a/hosts/x1g13/default.nix +++ b/hosts/x1g13/default.nix @@ -1,15 +1,7 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page -# and in the NixOS manual (accessible by running ‘nixos-help’). - -{ inputs, ... }: - +{ ... }: { - imports = - [ - inputs.nixos-hardware.nixosModules.lenovo-thinkpad-x1-13th-gen - ./../../modules/drivers/intel-drivers.nix - ./../../modules/core/secure-boot.nix - ./hardware-configuration.nix - ]; + imports = [ + ./hardware-configuration.nix + ./disko.nix + ]; } diff --git a/hosts/x1g13/disko.nix b/hosts/x1g13/disko.nix new file mode 100644 index 0000000..6569d4c --- /dev/null +++ b/hosts/x1g13/disko.nix @@ -0,0 +1,99 @@ +_: +let + espPart = "/dev/disk/by-partuuid/a53e3b19-67de-40de-9ded-3eac3117689a"; + + nixosPart = "/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e"; + + btrfsMountOptions = [ + "compress=zstd" + "noatime" + "ssd" + "space_cache=v2" + ]; +in +{ + disko.enableConfig = true; + + disko.devices.disk = { + esp = { + type = "disk"; + device = espPart; + destroy = false; + + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + mountOptions = [ + "umask=0077" + ]; + }; + }; + + nixos = { + type = "disk"; + device = nixosPart; + destroy = false; + + content = { + type = "luks"; + name = "cryptroot"; + + askPassword = true; + + settings = { + allowDiscards = true; + }; + + extraFormatArgs = [ + "--type" + "luks2" + "--pbkdf" + "argon2id" + "--label" + "NixOS-LUKS" + ]; + + content = { + type = "btrfs"; + extraArgs = [ + "-f" + "-L" + "NixOS" + ]; + + subvolumes = { + "@root" = { + mountpoint = "/"; + mountOptions = btrfsMountOptions; + }; + + "@home" = { + mountpoint = "/home"; + mountOptions = btrfsMountOptions; + }; + + "@nix" = { + mountpoint = "/nix"; + mountOptions = btrfsMountOptions; + }; + + "@log" = { + mountpoint = "/var/log"; + mountOptions = btrfsMountOptions; + }; + + "@swap" = { + mountpoint = "/.swapvol"; + mountOptions = [ + "noatime" + ]; + + swap.swapfile.size = "32G"; + }; + }; + }; + }; + }; + }; +} diff --git a/hosts/x1g13/hardware-configuration.nix b/hosts/x1g13/hardware-configuration.nix index 44222de..775079e 100644 --- a/hosts/x1g13/hardware-configuration.nix +++ b/hosts/x1g13/hardware-configuration.nix @@ -1,37 +1,32 @@ # Do not modify this file! It was generated by ‘nixos-generate-config’ # and may be overwritten by future invocations. Please make changes # to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: +{ + config, + lib, + modulesPath, + ... +}: { - imports = - [ (modulesPath + "/installer/scan/not-detected.nix") - ]; + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + ]; - boot.initrd.availableKernelModules = [ "xhci_pci" "thunderbolt" "nvme" "usb_storage" "sd_mod" ]; + boot.initrd.availableKernelModules = [ + "xhci_pci" + "thunderbolt" + "nvme" + "usb_storage" + "sd_mod" + ]; boot.initrd.kernelModules = [ ]; boot.kernelModules = [ "kvm-intel" ]; boot.extraModulePackages = [ ]; - fileSystems."/" = - { device = "/dev/disk/by-uuid/29b4b68d-c25e-48b1-beb3-30f63ac2f491"; - fsType = "ext4"; - }; - - fileSystems."/boot" = - { device = "/dev/disk/by-uuid/EA69-77EE"; - fsType = "vfat"; - options = [ "fmask=0077" "dmask=0077" ]; - }; - swapDevices = [ ]; - # Enables DHCP on each ethernet and wireless interface. In case of scripted networking - # (the default) this is the recommended approach. When using systemd-networkd it's - # still possible to use this option, but it's recommended to use it in conjunction - # with explicit per-interface declarations with `networking.interfaces..useDHCP`. networking.useDHCP = lib.mkDefault true; - # networking.interfaces.wlp0s20f3.useDHCP = lib.mkDefault true; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; diff --git a/hosts/x1g9/default.nix b/hosts/x1g9/default.nix deleted file mode 100644 index 73221ad..0000000 --- a/hosts/x1g9/default.nix +++ /dev/null @@ -1,14 +0,0 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page -# and in the NixOS manual (accessible by running ‘nixos-help’). - -{ inputs, ... }: - -{ - imports = - [ - inputs.nixos-hardware.nixosModules.lenovo-thinkpad-x1-9th-gen - ./../../modules/drivers/intel-drivers.nix - ./hardware-configuration.nix - ]; -} diff --git a/hosts/x1g9/hardware-configuration.nix b/hosts/x1g9/hardware-configuration.nix deleted file mode 100644 index 7aa4105..0000000 --- a/hosts/x1g9/hardware-configuration.nix +++ /dev/null @@ -1,38 +0,0 @@ -# Do not modify this file! It was generated by ‘nixos-generate-config’ -# and may be overwritten by future invocations. Please make changes -# to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: - -{ - imports = - [ (modulesPath + "/installer/scan/not-detected.nix") - ]; - - boot.initrd.availableKernelModules = [ "xhci_pci" "thunderbolt" "nvme" "usb_storage" "sd_mod" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ ]; - boot.extraModulePackages = [ ]; - - fileSystems."/" = - { device = "/dev/disk/by-uuid/16b29578-6836-414b-a5e1-863bc21c5fc3"; - fsType = "ext4"; - }; - - fileSystems."/boot" = - { device = "/dev/disk/by-uuid/209A-C8C9"; - fsType = "vfat"; - options = [ "fmask=0077" "dmask=0077" ]; - }; - - swapDevices = [ ]; - - # Enables DHCP on each ethernet and wireless interface. In case of scripted networking - # (the default) this is the recommended approach. When using systemd-networkd it's - # still possible to use this option, but it's recommended to use it in conjunction - # with explicit per-interface declarations with `networking.interfaces..useDHCP`. - networking.useDHCP = lib.mkDefault true; - # networking.interfaces.wlp0s20f3.useDHCP = lib.mkDefault true; - - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; - hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; -} diff --git a/modules/applications/arduino.nix b/modules/applications/arduino.nix new file mode 100644 index 0000000..6117fed --- /dev/null +++ b/modules/applications/arduino.nix @@ -0,0 +1,21 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.arduino; +in +{ + options.my.applications.arduino = { + enable = lib.mkEnableOption "Arduino development tools"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + arduino-cli # Arduino command-line interface + arduino-ide # Arduino IDE (GUI) + ]; + }; +} diff --git a/modules/applications/btop/default.nix b/modules/applications/btop/default.nix new file mode 100644 index 0000000..1e27b13 --- /dev/null +++ b/modules/applications/btop/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.btop; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.btop = { + enable = lib.mkEnableOption "btop system monitor"; + }; + + config = lib.mkIf cfg.enable { + my.applications.btop.system.enable = lib.mkDefault true; + my.applications.btop.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/home/btop/dracula.theme b/modules/applications/btop/dracula.theme similarity index 100% rename from modules/home/btop/dracula.theme rename to modules/applications/btop/dracula.theme diff --git a/modules/applications/btop/home.nix b/modules/applications/btop/home.nix new file mode 100644 index 0000000..41ee0cc --- /dev/null +++ b/modules/applications/btop/home.nix @@ -0,0 +1,25 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.btop.homeManager; +in +{ + options.my.applications.btop.homeManager = { + enable = lib.mkEnableOption "btop home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + { + config = lib.mkIf cfg.enable { + programs.btop = { + enable = true; + settings.color_theme = "dracula"; + themes.dracula = builtins.readFile ./dracula.theme; + }; + }; + } + ]; +} diff --git a/modules/applications/btop/system.nix b/modules/applications/btop/system.nix new file mode 100644 index 0000000..ae68aee --- /dev/null +++ b/modules/applications/btop/system.nix @@ -0,0 +1,20 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.btop.system; +in +{ + options.my.applications.btop.system = { + enable = lib.mkEnableOption "btop system configuration"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + btop # Resource monitor that shows usage and stats + ]; + }; +} diff --git a/modules/applications/chrome.nix b/modules/applications/chrome.nix new file mode 100644 index 0000000..8e6acd8 --- /dev/null +++ b/modules/applications/chrome.nix @@ -0,0 +1,44 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.chrome; +in +{ + options.my.applications.chrome = { + enable = lib.mkEnableOption "Google Chrome browser"; + }; + + config = lib.mkIf cfg.enable { + home-manager.sharedModules = [ + { + home.packages = with pkgs; [ + google-chrome # Popular web browser from Google + ]; + + xdg.desktopEntries."google-chrome" = { + name = "Google Chrome"; + genericName = "Web Browser"; + exec = "${pkgs.google-chrome}/bin/google-chrome-stable --enable-features=TouchpadOverscrollHistoryNavigation %U"; + terminal = false; + icon = "google-chrome"; + categories = [ + "Network" + "WebBrowser" + ]; + startupNotify = true; + type = "Application"; + }; + + xdg.mimeApps.defaultApplications = { + "text/html" = "google-chrome.desktop"; + "x-scheme-handler/http" = "google-chrome.desktop"; + "x-scheme-handler/https" = "google-chrome.desktop"; + }; + } + ]; + }; +} diff --git a/modules/applications/claude/default.nix b/modules/applications/claude/default.nix new file mode 100644 index 0000000..91c914c --- /dev/null +++ b/modules/applications/claude/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.claude; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.claude = { + enable = lib.mkEnableOption "Claude Code AI assistant"; + }; + + config = lib.mkIf cfg.enable { + my.applications.claude.system.enable = lib.mkDefault true; + my.applications.claude.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/applications/claude/home.nix b/modules/applications/claude/home.nix new file mode 100644 index 0000000..0afcdca --- /dev/null +++ b/modules/applications/claude/home.nix @@ -0,0 +1,27 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.claude.homeManager; +in +{ + options.my.applications.claude.homeManager = { + enable = lib.mkEnableOption "Claude Code home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + { + config = lib.mkIf cfg.enable { + home.file.".claude/settings.json".text = builtins.toJSON { + statusLine = { + type = "command"; + command = "bun x ccusage statusline --no-offline"; + padding = 0; + }; + }; + }; + } + ]; +} diff --git a/modules/applications/claude/system.nix b/modules/applications/claude/system.nix new file mode 100644 index 0000000..7eaee9d --- /dev/null +++ b/modules/applications/claude/system.nix @@ -0,0 +1,21 @@ +{ + pkgs, + inputs, + lib, + config, + ... +}: +let + cfg = config.my.applications.claude.system; +in +{ + options.my.applications.claude.system = { + enable = lib.mkEnableOption "Claude Code system configuration"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = [ + inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.claude-code # AI coding assistant + ]; + }; +} diff --git a/modules/applications/codex.nix b/modules/applications/codex.nix new file mode 100644 index 0000000..f3faa31 --- /dev/null +++ b/modules/applications/codex.nix @@ -0,0 +1,21 @@ +{ + pkgs, + inputs, + lib, + config, + ... +}: +let + cfg = config.my.applications.codex; +in +{ + options.my.applications.codex = { + enable = lib.mkEnableOption "Codex AI coding assistant"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = [ + inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.codex # OpenAI Codex CLI + ]; + }; +} diff --git a/modules/applications/default.nix b/modules/applications/default.nix new file mode 100644 index 0000000..bb87d41 --- /dev/null +++ b/modules/applications/default.nix @@ -0,0 +1,37 @@ +{ + imports = [ + ./arduino.nix + ./btop + ./chrome.nix + ./claude + ./codex.nix + ./direnv.nix + ./discord.nix + ./docker.nix + ./fcitx5 + ./ghostty + ./git + ./gnupg.nix + ./greetd.nix + ./gtk + ./java + ./kde.nix + ./nautilus.nix + ./nh.nix + ./niri + ./noctalia + ./opencode.nix + ./openssh.nix + ./slack.nix + ./ssh + ./swayidle.nix + ./tailscale.nix + ./vicinae.nix + ./vim + ./vscode + ./wayland.nix + ./zellij + ./zoom.nix + ./zsh + ]; +} diff --git a/modules/applications/direnv.nix b/modules/applications/direnv.nix new file mode 100644 index 0000000..75d1009 --- /dev/null +++ b/modules/applications/direnv.nix @@ -0,0 +1,16 @@ +{ lib, config, ... }: +let + cfg = config.my.applications.direnv; +in +{ + options.my.applications.direnv = { + enable = lib.mkEnableOption "direnv environment variable manager"; + }; + + config = lib.mkIf cfg.enable { + programs.direnv = { + enable = true; + nix-direnv.enable = true; + }; + }; +} diff --git a/modules/applications/discord.nix b/modules/applications/discord.nix new file mode 100644 index 0000000..28b121c --- /dev/null +++ b/modules/applications/discord.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.discord; +in +{ + options.my.applications.discord = { + enable = lib.mkEnableOption "Discord (Vesktop)"; + }; + + config = lib.mkIf cfg.enable { + home-manager.sharedModules = [ + { + programs.vesktop = { + enable = true; + }; + } + ]; + }; +} diff --git a/modules/applications/docker.nix b/modules/applications/docker.nix new file mode 100644 index 0000000..e6f4ba7 --- /dev/null +++ b/modules/applications/docker.nix @@ -0,0 +1,34 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.docker; +in +{ + options.my.applications.docker = { + enable = lib.mkEnableOption "Docker container runtime"; + }; + + config = lib.mkIf cfg.enable { + virtualisation.docker = { + enable = true; + autoPrune = { + enable = true; + dates = "weekly"; + }; + daemon.settings = { + ipv6 = true; + "fixed-cidr-v6" = "fd00:30::/64"; + ip6tables = true; + }; + }; + + environment.systemPackages = with pkgs; [ + docker # Container runtime + oxker # Docker TUI Tool + ]; + }; +} diff --git a/modules/home/fcitx5/config b/modules/applications/fcitx5/config similarity index 99% rename from modules/home/fcitx5/config rename to modules/applications/fcitx5/config index 1e330aa..a11fae8 100644 --- a/modules/home/fcitx5/config +++ b/modules/applications/fcitx5/config @@ -67,4 +67,3 @@ AllowInputMethodForPassword=False ShowPreeditForPassword=False # ユーザーデータを保存する間隔(分) AutoSavePeriod=30 - diff --git a/modules/applications/fcitx5/default.nix b/modules/applications/fcitx5/default.nix new file mode 100644 index 0000000..11c198e --- /dev/null +++ b/modules/applications/fcitx5/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.fcitx5; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.fcitx5 = { + enable = lib.mkEnableOption "fcitx5 input method"; + }; + + config = lib.mkIf cfg.enable { + my.applications.fcitx5.system.enable = lib.mkDefault true; + my.applications.fcitx5.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/applications/fcitx5/home.nix b/modules/applications/fcitx5/home.nix new file mode 100644 index 0000000..94f5452 --- /dev/null +++ b/modules/applications/fcitx5/home.nix @@ -0,0 +1,24 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.fcitx5.homeManager; +in +{ + options.my.applications.fcitx5.homeManager = { + enable = lib.mkEnableOption "fcitx5 home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + { + config = lib.mkIf cfg.enable { + home.file.".config/fcitx5/config" = { + recursive = true; + source = ./config; + }; + }; + } + ]; +} diff --git a/modules/applications/fcitx5/system.nix b/modules/applications/fcitx5/system.nix new file mode 100644 index 0000000..03ef957 --- /dev/null +++ b/modules/applications/fcitx5/system.nix @@ -0,0 +1,48 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.fcitx5.system; +in +{ + options.my.applications.fcitx5.system = { + enable = lib.mkEnableOption "fcitx5 system configuration"; + }; + + config = lib.mkIf cfg.enable { + i18n.inputMethod = { + enable = true; + type = "fcitx5"; + fcitx5 = { + waylandFrontend = true; + addons = with pkgs; [ + fcitx5-mozc-ut + fcitx5-gtk + kdePackages.fcitx5-qt + qt6Packages.fcitx5-configtool + ]; + settings.inputMethod = { + GroupOrder = { + "0" = "Default"; + }; + "Groups/0" = { + Name = "Default"; + "Default Layout" = "jp"; + DefaultIM = "mozc"; + }; + "Groups/0/Items/0" = { + Name = "keyboard-jp"; + Layout = ""; + }; + "Groups/0/Items/1" = { + Name = "mozc"; + Layout = ""; + }; + }; + }; + }; + }; +} diff --git a/modules/home/ghostty/config b/modules/applications/ghostty/config similarity index 91% rename from modules/home/ghostty/config rename to modules/applications/ghostty/config index 2410ddb..0e55901 100644 --- a/modules/home/ghostty/config +++ b/modules/applications/ghostty/config @@ -9,7 +9,7 @@ window-decoration = true # keybind # Copy/Paste -keybind = ctrl+shift+c=copy_to_clipboard +keybind = performable:ctrl+shift+c=copy_to_clipboard keybind = ctrl+shift+v=paste_from_clipboard # create new tab @@ -28,3 +28,4 @@ keybind = ctrl+shift+minus=increase_font_size:1 shell-integration-features = ssh-terminfo,ssh-env + diff --git a/modules/applications/ghostty/default.nix b/modules/applications/ghostty/default.nix new file mode 100644 index 0000000..966e80c --- /dev/null +++ b/modules/applications/ghostty/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.ghostty; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.ghostty = { + enable = lib.mkEnableOption "ghostty terminal emulator"; + }; + + config = lib.mkIf cfg.enable { + my.applications.ghostty.system.enable = lib.mkDefault true; + my.applications.ghostty.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/home/ghostty/dracula.theme b/modules/applications/ghostty/dracula.theme similarity index 97% rename from modules/home/ghostty/dracula.theme rename to modules/applications/ghostty/dracula.theme index 172180b..413226e 100644 --- a/modules/home/ghostty/dracula.theme +++ b/modules/applications/ghostty/dracula.theme @@ -41,4 +41,5 @@ foreground = #f8f8f2 cursor-color = #f8f8f2 cursor-text = #282a36 selection-foreground = #f8f8f2 -selection-background = #44475a \ No newline at end of file +selection-background = #44475a + diff --git a/modules/applications/ghostty/home.nix b/modules/applications/ghostty/home.nix new file mode 100644 index 0000000..dda43d8 --- /dev/null +++ b/modules/applications/ghostty/home.nix @@ -0,0 +1,29 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.ghostty.homeManager; +in +{ + options.my.applications.ghostty.homeManager = { + enable = lib.mkEnableOption "ghostty home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + { + config = lib.mkIf cfg.enable { + home.file.".config/ghostty/config" = { + recursive = true; + source = ./config; + }; + + home.file.".config/ghostty/themes/dracula" = { + recursive = true; + source = ./dracula.theme; + }; + }; + } + ]; +} diff --git a/modules/applications/ghostty/system.nix b/modules/applications/ghostty/system.nix new file mode 100644 index 0000000..26fd7e8 --- /dev/null +++ b/modules/applications/ghostty/system.nix @@ -0,0 +1,20 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.ghostty.system; +in +{ + options.my.applications.ghostty.system = { + enable = lib.mkEnableOption "ghostty system configuration"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + ghostty # A fast and minimal terminal emulator for Wayland + ]; + }; +} diff --git a/modules/applications/git/default.nix b/modules/applications/git/default.nix new file mode 100644 index 0000000..6d7bbf9 --- /dev/null +++ b/modules/applications/git/default.nix @@ -0,0 +1,33 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.git; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.git = { + enable = lib.mkEnableOption "git version control"; + userName = lib.mkOption { + type = lib.types.str; + default = "moons-14"; + description = "Git user name"; + }; + userEmail = lib.mkOption { + type = lib.types.str; + default = "moons@moons14.com"; + description = "Git user email"; + }; + }; + + config = lib.mkIf cfg.enable { + my.applications.git.system.enable = lib.mkDefault true; + my.applications.git.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/applications/git/home.nix b/modules/applications/git/home.nix new file mode 100644 index 0000000..f16ce85 --- /dev/null +++ b/modules/applications/git/home.nix @@ -0,0 +1,59 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.git; + hmCfg = config.my.applications.git.homeManager; +in +{ + options.my.applications.git.homeManager = { + enable = lib.mkEnableOption "git home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + { + config = lib.mkIf hmCfg.enable { + programs.git = { + enable = true; + ignores = [ + ".direnv/" + ".envrc" + "!.envrc.example" + ]; + + signing = { + key = "~/.ssh/id_ed25519.pub"; + signByDefault = true; + }; + + settings = { + user.name = cfg.userName; + user.email = cfg.userEmail; + push.default = "simple"; + credential.helper = "cache --timeout=7200"; + init.defaultBranch = "main"; + log.decorate = "full"; + log.date = "iso"; + merge.conflictStyle = "diff3"; + + gpg.format = "ssh"; + tag.gpgSign = true; + + alias = { + br = "branch --sort=-committerdate"; + co = "checkout"; + df = "diff"; + com = "commit -a"; + gs = "stash"; + gp = "pull"; + lg = "log --graph --pretty=format:'%Cred%h%Creset - %C(yellow)%d%Creset %s %C(green)(%cr)%C(bold blue) <%an>%Creset' --abbrev-commit"; + st = "status"; + }; + }; + }; + }; + } + ]; +} diff --git a/modules/applications/git/system.nix b/modules/applications/git/system.nix new file mode 100644 index 0000000..3d32726 --- /dev/null +++ b/modules/applications/git/system.nix @@ -0,0 +1,20 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.git.system; +in +{ + options.my.applications.git.system = { + enable = lib.mkEnableOption "git system configuration"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + git # Distributed version control system + ]; + }; +} diff --git a/modules/applications/gnupg.nix b/modules/applications/gnupg.nix new file mode 100644 index 0000000..d6cc900 --- /dev/null +++ b/modules/applications/gnupg.nix @@ -0,0 +1,16 @@ +{ lib, config, ... }: +let + cfg = config.my.applications.gnupg; +in +{ + options.my.applications.gnupg = { + enable = lib.mkEnableOption "GnuPG agent"; + }; + + config = lib.mkIf cfg.enable { + programs.gnupg.agent = { + enable = true; + enableSSHSupport = false; + }; + }; +} diff --git a/modules/applications/greetd.nix b/modules/applications/greetd.nix new file mode 100644 index 0000000..09f00e4 --- /dev/null +++ b/modules/applications/greetd.nix @@ -0,0 +1,26 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.greetd; +in +{ + options.my.applications.greetd = { + enable = lib.mkEnableOption "greetd login manager"; + }; + + config = lib.mkIf cfg.enable { + services.greetd = { + enable = true; + settings = { + default_session = { + user = "greeter"; + command = "${pkgs.tuigreet}/bin/tuigreet --time --remember --cmd niri-session"; + }; + }; + }; + }; +} diff --git a/modules/applications/gtk/default.nix b/modules/applications/gtk/default.nix new file mode 100644 index 0000000..bc3bb9b --- /dev/null +++ b/modules/applications/gtk/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.gtk; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.gtk = { + enable = lib.mkEnableOption "GTK theme configuration"; + }; + + config = lib.mkIf cfg.enable { + my.applications.gtk.system.enable = lib.mkDefault true; + my.applications.gtk.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/applications/gtk/home.nix b/modules/applications/gtk/home.nix new file mode 100644 index 0000000..58cfdce --- /dev/null +++ b/modules/applications/gtk/home.nix @@ -0,0 +1,36 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.gtk.homeManager; +in +{ + options.my.applications.gtk.homeManager = { + enable = lib.mkEnableOption "GTK home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + { + config = lib.mkIf cfg.enable { + gtk = { + enable = true; + theme = { + name = "Dracula"; + package = pkgs.dracula-theme; + }; + cursorTheme = { + package = pkgs.adwaita-icon-theme; + name = "Adwaita"; + }; + iconTheme = { + package = pkgs.papirus-icon-theme; + name = "Papirus-Dark"; + }; + }; + }; + } + ]; +} diff --git a/modules/applications/gtk/system.nix b/modules/applications/gtk/system.nix new file mode 100644 index 0000000..c3434fc --- /dev/null +++ b/modules/applications/gtk/system.nix @@ -0,0 +1,20 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.gtk.system; +in +{ + options.my.applications.gtk.system = { + enable = lib.mkEnableOption "GTK system configuration"; + }; + + config = lib.mkIf cfg.enable { + programs.dconf.enable = true; + programs.seahorse.enable = true; + + services.gnome.gnome-keyring.enable = true; + }; +} diff --git a/modules/applications/java/default.nix b/modules/applications/java/default.nix new file mode 100644 index 0000000..ef8ecb5 --- /dev/null +++ b/modules/applications/java/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.java; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.java = { + enable = lib.mkEnableOption "Java runtime"; + }; + + config = lib.mkIf cfg.enable { + my.applications.java.system.enable = lib.mkDefault true; + my.applications.java.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/applications/java/home.nix b/modules/applications/java/home.nix new file mode 100644 index 0000000..3661470 --- /dev/null +++ b/modules/applications/java/home.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.java.homeManager; +in +{ + options.my.applications.java.homeManager = { + enable = lib.mkEnableOption "Java home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + { + config = lib.mkIf cfg.enable { + programs.java = { + enable = true; + }; + }; + } + ]; +} diff --git a/modules/applications/java/system.nix b/modules/applications/java/system.nix new file mode 100644 index 0000000..ec6f1b8 --- /dev/null +++ b/modules/applications/java/system.nix @@ -0,0 +1,27 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.java.system; +in +{ + options.my.applications.java.system = { + enable = lib.mkEnableOption "Java system configuration"; + }; + + config = lib.mkIf cfg.enable { + programs.java = { + enable = true; + package = pkgs.jdk25; + }; + + environment.systemPackages = with pkgs; [ + jdk25 # Java Development Kit 25 + maven # Java Build Tool + gradle # Java Build Tool + ]; + }; +} diff --git a/modules/applications/kde.nix b/modules/applications/kde.nix new file mode 100644 index 0000000..b5f462e --- /dev/null +++ b/modules/applications/kde.nix @@ -0,0 +1,19 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.kde; +in +{ + options.my.applications.kde = { + enable = lib.mkEnableOption "KDE Connect"; + }; + + config = lib.mkIf cfg.enable { + programs.kdeconnect = { + enable = true; + }; + }; +} diff --git a/modules/applications/nautilus.nix b/modules/applications/nautilus.nix new file mode 100644 index 0000000..4293dd5 --- /dev/null +++ b/modules/applications/nautilus.nix @@ -0,0 +1,22 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.nautilus; +in +{ + options.my.applications.nautilus = { + enable = lib.mkEnableOption "Nautilus file manager"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + nautilus # GNOME file manager + gvfs # GNOME virtual file system + sushi # Nautilus file previewer + ]; + }; +} diff --git a/modules/applications/nh.nix b/modules/applications/nh.nix new file mode 100644 index 0000000..8feba6d --- /dev/null +++ b/modules/applications/nh.nix @@ -0,0 +1,21 @@ +{ + username, + lib, + config, + ... +}: +let + cfg = config.my.applications.nh; +in +{ + options.my.applications.nh = { + enable = lib.mkEnableOption "nh Nix CLI helper"; + }; + + config = lib.mkIf cfg.enable { + programs.nh = { + enable = true; + flake = "/home/${username}/dotfiles"; + }; + }; +} diff --git a/modules/applications/niri/default.nix b/modules/applications/niri/default.nix new file mode 100644 index 0000000..f42e307 --- /dev/null +++ b/modules/applications/niri/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.niri; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.niri = { + enable = lib.mkEnableOption "niri window manager"; + }; + + config = lib.mkIf cfg.enable { + my.applications.niri.system.enable = lib.mkDefault true; + my.applications.niri.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/applications/niri/defaultKeyBind.nix b/modules/applications/niri/defaultKeyBind.nix new file mode 100644 index 0000000..e745297 --- /dev/null +++ b/modules/applications/niri/defaultKeyBind.nix @@ -0,0 +1,166 @@ +{ + "Mod+Shift+Slash".action.show-hotkey-overlay = { }; + + "XF86AudioRaiseVolume" = { + allow-when-locked = true; + action.spawn = [ + "wpctl" + "set-volume" + "@DEFAULT_AUDIO_SINK@" + "0.1+" + ]; + }; + "XF86AudioLowerVolume" = { + allow-when-locked = true; + action.spawn = [ + "wpctl" + "set-volume" + "@DEFAULT_AUDIO_SINK@" + "0.1-" + ]; + }; + "XF86AudioMute" = { + allow-when-locked = true; + action.spawn = [ + "wpctl" + "set-mute" + "@DEFAULT_AUDIO_SINK@" + "toggle" + ]; + }; + "XF86AudioMicMute" = { + allow-when-locked = true; + action.spawn = [ + "wpctl" + "set-mute" + "@DEFAULT_AUDIO_SOURCE@" + "toggle" + ]; + }; + + "Mod+Q".action.close-window = { }; + + "Mod+Left".action.focus-column-left = { }; + "Mod+Down".action.focus-window-down = { }; + "Mod+Up".action.focus-window-up = { }; + "Mod+Right".action.focus-column-right = { }; + "Mod+H".action.focus-column-left = { }; + "Mod+J".action.focus-window-down = { }; + "Mod+K".action.focus-window-up = { }; + "Mod+L".action.focus-column-right = { }; + + "Mod+Ctrl+Left".action.move-column-left = { }; + "Mod+Ctrl+Down".action.move-window-down = { }; + "Mod+Ctrl+Up".action.move-window-up = { }; + "Mod+Ctrl+Right".action.move-column-right = { }; + "Mod+Ctrl+H".action.move-column-left = { }; + "Mod+Ctrl+J".action.move-window-down = { }; + "Mod+Ctrl+K".action.move-window-up = { }; + "Mod+Ctrl+L".action.move-column-right = { }; + + "Mod+Home".action.focus-column-first = { }; + "Mod+End".action.focus-column-last = { }; + "Mod+Ctrl+Home".action.move-column-to-first = { }; + "Mod+Ctrl+End".action.move-column-to-last = { }; + + "Mod+Shift+Left".action.focus-monitor-left = { }; + "Mod+Shift+Down".action.focus-monitor-down = { }; + "Mod+Shift+Up".action.focus-monitor-up = { }; + "Mod+Shift+Right".action.focus-monitor-right = { }; + "Mod+Shift+H".action.focus-monitor-left = { }; + "Mod+Shift+J".action.focus-monitor-down = { }; + "Mod+Shift+K".action.focus-monitor-up = { }; + "Mod+Shift+L".action.focus-monitor-right = { }; + + "Mod+Shift+Ctrl+Left".action.move-column-to-monitor-left = { }; + "Mod+Shift+Ctrl+Down".action.move-column-to-monitor-down = { }; + "Mod+Shift+Ctrl+Up".action.move-column-to-monitor-up = { }; + "Mod+Shift+Ctrl+Right".action.move-column-to-monitor-right = { }; + "Mod+Shift+Ctrl+H".action.move-column-to-monitor-left = { }; + "Mod+Shift+Ctrl+J".action.move-column-to-monitor-down = { }; + "Mod+Shift+Ctrl+K".action.move-column-to-monitor-up = { }; + "Mod+Shift+Ctrl+L".action.move-column-to-monitor-right = { }; + + "Mod+Page_Down".action.focus-workspace-down = { }; + "Mod+Page_Up".action.focus-workspace-up = { }; + "Mod+U".action.focus-workspace-down = { }; + "Mod+I".action.focus-workspace-up = { }; + "Mod+Ctrl+Page_Down".action.move-column-to-workspace-down = { }; + "Mod+Ctrl+Page_Up".action.move-column-to-workspace-up = { }; + "Mod+Ctrl+U".action.move-column-to-workspace-down = { }; + "Mod+Ctrl+I".action.move-column-to-workspace-up = { }; + + "Mod+Shift+Page_Down".action.move-workspace-down = { }; + "Mod+Shift+Page_Up".action.move-workspace-up = { }; + "Mod+Shift+U".action.move-workspace-down = { }; + "Mod+Shift+I".action.move-workspace-up = { }; + + "Mod+WheelScrollDown" = { + cooldown-ms = 150; + action.focus-workspace-down = { }; + }; + "Mod+WheelScrollUp" = { + cooldown-ms = 150; + action.focus-workspace-up = { }; + }; + "Mod+Ctrl+WheelScrollDown" = { + cooldown-ms = 150; + action.move-column-to-workspace-down = { }; + }; + "Mod+Ctrl+WheelScrollUp" = { + cooldown-ms = 150; + action.move-column-to-workspace-up = { }; + }; + + "Mod+WheelScrollRight".action.focus-column-right = { }; + "Mod+WheelScrollLeft".action.focus-column-left = { }; + "Mod+Ctrl+WheelScrollRight".action.move-column-right = { }; + "Mod+Ctrl+WheelScrollLeft".action.move-column-left = { }; + + "Mod+Shift+WheelScrollDown".action.focus-column-right = { }; + "Mod+Shift+WheelScrollUp".action.focus-column-left = { }; + "Mod+Ctrl+Shift+WheelScrollDown".action.move-column-right = { }; + "Mod+Ctrl+Shift+WheelScrollUp".action.move-column-left = { }; + + "Mod+1".action.focus-workspace = 1; + "Mod+2".action.focus-workspace = 2; + "Mod+3".action.focus-workspace = 3; + "Mod+4".action.focus-workspace = 4; + "Mod+5".action.focus-workspace = 5; + "Mod+6".action.focus-workspace = 6; + "Mod+7".action.focus-workspace = 7; + "Mod+8".action.focus-workspace = 8; + "Mod+9".action.focus-workspace = 9; + "Mod+Ctrl+1".action.move-column-to-workspace = 1; + "Mod+Ctrl+2".action.move-column-to-workspace = 2; + "Mod+Ctrl+3".action.move-column-to-workspace = 3; + "Mod+Ctrl+4".action.move-column-to-workspace = 4; + "Mod+Ctrl+5".action.move-column-to-workspace = 5; + "Mod+Ctrl+6".action.move-column-to-workspace = 6; + "Mod+Ctrl+7".action.move-column-to-workspace = 7; + "Mod+Ctrl+8".action.move-column-to-workspace = 8; + "Mod+Ctrl+9".action.move-column-to-workspace = 9; + + "Mod+Comma".action.consume-window-into-column = { }; + "Mod+Period".action.expel-window-from-column = { }; + + "Mod+R".action.switch-preset-column-width = { }; + "Mod+Shift+R".action.reset-window-height = { }; + "Mod+F".action.maximize-column = { }; + "Mod+Shift+F".action.fullscreen-window = { }; + "Mod+C".action.center-column = { }; + + "Mod+Minus".action.set-column-width = "-10%"; + "Mod+Equal".action.set-column-width = "+10%"; + + "Mod+Shift+Minus".action.set-window-height = "-10%"; + "Mod+Shift+Equal".action.set-window-height = "+10%"; + + "Print".action.screenshot = { }; + "Ctrl+Print".action.screenshot-screen = { }; + "Alt+Print".action.screenshot-window = { }; + + "Mod+Shift+E".action.quit = { }; + + "Mod+Shift+P".action.power-off-monitors = { }; +} diff --git a/modules/applications/niri/home.nix b/modules/applications/niri/home.nix new file mode 100644 index 0000000..a893e63 --- /dev/null +++ b/modules/applications/niri/home.nix @@ -0,0 +1,164 @@ +{ + inputs, + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.niri.homeManager; + defaultKeyBind = import ./defaultKeyBind.nix; +in +{ + options.my.applications.niri.homeManager = { + enable = lib.mkEnableOption "niri home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + inputs.niri-flake.homeModules.niri + { + config = lib.mkIf cfg.enable { + programs.niri.package = pkgs.niri; + + programs.niri.settings = { + input.touchpad = { + natural-scroll = true; + scroll-factor = 4.0; + scroll-method = "two-finger"; + click-method = "clickfinger"; + drag = true; + drag-lock = true; + }; + + input.keyboard.xkb = { + layout = "jp"; + options = "ctrl:nocaps"; + }; + + spawn-at-startup = [ + { command = [ "noctalia-shell" ]; } + ]; + + outputs."eDP-1".scale = 1; + cursor.size = 16; + + layout = { + focus-ring = { + active.color = "#bd93f9"; + inactive.color = "#6272a4"; + }; + border = { + active.color = "#ffc87f"; + inactive.color = "#505050"; + urgent.color = "#9b0000"; + }; + shadow = { + color = "#0007"; + }; + }; + + binds = defaultKeyBind // { + "Mod+T" = { + action.spawn = "ghostty"; + hotkey-overlay.title = "Open a Terminal: ghostty"; + }; + "Mod+D" = { + action.spawn = [ + "vicinae" + "toggle" + ]; + hotkey-overlay.title = "Run an Application: vicinae"; + }; + "Mod+Space" = { + action.spawn = [ + "vicinae" + "toggle" + ]; + hotkey-overlay.title = "Run an Application: vicinae"; + }; + "Mod+E" = { + action.spawn = [ + "nautilus" + "--new-window" + ]; + hotkey-overlay.title = "Open File Manager: nautilus"; + }; + "Mod+L" = { + action.spawn = [ + "noctalia-shell" + "ipc" + "call" + "sessionMenu" + "lockAndSuspend" + ]; + hotkey-overlay.title = "Lock the Screen: noctalia"; + }; + "Mod+V" = { + action.spawn = [ + "vicinae" + "vicinae://extensions/vicinae/clipboard/history" + ]; + hotkey-overlay.title = "Clipboard History"; + }; + + "XF86AudioRaiseVolume" = { + action.spawn = [ + "noctalia-shell" + "ipc" + "call" + "volume" + "increase" + ]; + }; + "XF86AudioLowerVolume" = { + action.spawn = [ + "noctalia-shell" + "ipc" + "call" + "volume" + "decrease" + ]; + }; + "XF86AudioMute" = { + action.spawn = [ + "noctalia-shell" + "ipc" + "call" + "volume" + "muteOutput" + ]; + }; + "XF86AudioMicMute" = { + action.spawn = [ + "noctalia-shell" + "ipc" + "call" + "volume" + "muteInput" + ]; + }; + + "XF86MonBrightnessUp" = { + action.spawn = [ + "noctalia-shell" + "ipc" + "call" + "brightness" + "increase" + ]; + }; + "XF86MonBrightnessDown" = { + action.spawn = [ + "noctalia-shell" + "ipc" + "call" + "brightness" + "decrease" + ]; + }; + }; + }; + }; + } + ]; +} diff --git a/modules/applications/niri/system.nix b/modules/applications/niri/system.nix new file mode 100644 index 0000000..b9c52cb --- /dev/null +++ b/modules/applications/niri/system.nix @@ -0,0 +1,17 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.niri.system; +in +{ + options.my.applications.niri.system = { + enable = lib.mkEnableOption "niri system configuration"; + }; + + config = lib.mkIf cfg.enable { + programs.niri.enable = true; + }; +} diff --git a/modules/applications/noctalia/default.nix b/modules/applications/noctalia/default.nix new file mode 100644 index 0000000..9ac464b --- /dev/null +++ b/modules/applications/noctalia/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.noctalia; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.noctalia = { + enable = lib.mkEnableOption "noctalia-shell"; + }; + + config = lib.mkIf cfg.enable { + my.applications.noctalia.system.enable = lib.mkDefault true; + my.applications.noctalia.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/applications/noctalia/home.nix b/modules/applications/noctalia/home.nix new file mode 100644 index 0000000..3d69c7d --- /dev/null +++ b/modules/applications/noctalia/home.nix @@ -0,0 +1,178 @@ +{ + inputs, + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.noctalia.homeManager; + walls = pkgs.fetchFromGitHub { + owner = "moons-14"; + repo = "wallpapers"; + rev = "cc3256f4aaf2c8e7d16fb000b1ee251af54085db"; + hash = "sha256-emQ/FqKqMq3YI5bLx8gBZg/ZE72OG9Ilh71ggq78WdQ="; + }; +in +{ + options.my.applications.noctalia.homeManager = { + enable = lib.mkEnableOption "noctalia-shell home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + inputs.noctalia.homeModules.default + { + config = lib.mkIf cfg.enable { + home.file.".face" = { + recursive = true; + source = ../../../images/avatar.jpg; + }; + + home.file.".wallpapers" = { + source = walls; + recursive = true; + }; + + home.file.".cache/noctalia/wallpapers.json" = { + text = builtins.toJSON { + defaultWallpaper = "~/.wallpapers/1.jpg"; + wallpapers = { + "DP-1" = "~/.wallpapers/1.jpg"; + }; + }; + }; + + programs.noctalia-shell = { + enable = true; + settings = { + bar = { + density = "default"; + position = "top"; + showCapsule = true; + backgroundOpacity = 0.8; + floating = true; + widgets = { + left = [ + { id = "WiFi"; } + { + id = "CustomButton"; + icon = "access-point"; + leftClickExec = "nm-connection-editor"; + } + { id = "Bluetooth"; } + { id = "SystemMonitor"; } + { id = "Taskbar"; } + { id = "ActiveWindow"; } + ]; + center = [ + { + hideUnoccupied = false; + id = "Workspace"; + labelMode = "none"; + } + ]; + right = [ + { id = "MediaMini"; } + { id = "NotificationHistory"; } + { + displayMode = "alwaysShow"; + id = "Battery"; + warningThreshold = 30; + } + { + displayMode = "alwaysShow"; + id = "Volume"; + } + { + displayMode = "alwaysShow"; + id = "Brightness"; + } + { + formatHorizontal = "HH:mm"; + formatVertical = "HH mm"; + id = "Clock"; + useMonospacedFont = true; + usePrimaryColor = true; + } + { + id = "ControlCenter"; + useDistroLogo = true; + } + ]; + }; + }; + colorSchemes.predefinedScheme = "dracula"; + general = { + avatarImage = "~/.face"; + radiusRatio = 0.2; + }; + location = { + monthBeforeDay = true; + weatherEnabled = false; + name = "Tokyo"; + }; + wallpaper = { + enabled = true; + directory = "~/.wallpapers/"; + setWallpaperOnAllMonitors = true; + linkLightAndDarkWallpapers = true; + fillMode = "crop"; + randomEnabled = true; + randomIntervalSec = 60; + transitionDuration = 1500; + }; + dock = { + enabled = true; + displayMode = "auto_hide"; + backgroundOpacity = 0.8; + floatingRatio = 1; + size = 1; + onlySameOutput = true; + monitors = [ "eDP-1" ]; + pinnedApps = [ + "com.mitchellh.ghostty" + "org.gnome.Nautilus" + "google-chrome" + "code" + ]; + colorizeIcons = false; + }; + controlCenter = { + position = "close_to_bar_button"; + shortcuts = { + left = [ + { id = "WiFi"; } + { id = "Bluetooth"; } + { id = "ScreenRecorder"; } + { id = "WallpaperSelector"; } + ]; + right = [ + { id = "Notifications"; } + { id = "NightLight"; } + ]; + }; + cards = [ + { + enabled = true; + id = "profile-card"; + } + { + enabled = true; + id = "shortcuts-card"; + } + { + enabled = true; + id = "audio-card"; + } + { + enabled = true; + id = "media-sysmon-card"; + } + ]; + }; + }; + }; + }; + } + ]; +} diff --git a/modules/applications/noctalia/system.nix b/modules/applications/noctalia/system.nix new file mode 100644 index 0000000..6dec66e --- /dev/null +++ b/modules/applications/noctalia/system.nix @@ -0,0 +1,21 @@ +{ + pkgs, + inputs, + lib, + config, + ... +}: +let + cfg = config.my.applications.noctalia.system; +in +{ + options.my.applications.noctalia.system = { + enable = lib.mkEnableOption "noctalia-shell system package"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + inputs.noctalia.packages.${system}.default + ]; + }; +} diff --git a/modules/applications/opencode.nix b/modules/applications/opencode.nix new file mode 100644 index 0000000..0476c31 --- /dev/null +++ b/modules/applications/opencode.nix @@ -0,0 +1,21 @@ +{ + pkgs, + inputs, + lib, + config, + ... +}: +let + cfg = config.my.applications.opencode; +in +{ + options.my.applications.opencode = { + enable = lib.mkEnableOption "OpenCode AI coding assistant"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = [ + inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.opencode # OpenCode CLI + ]; + }; +} diff --git a/modules/applications/openssh.nix b/modules/applications/openssh.nix new file mode 100644 index 0000000..f45a857 --- /dev/null +++ b/modules/applications/openssh.nix @@ -0,0 +1,23 @@ +{ lib, config, ... }: +let + cfg = config.my.applications.openssh; +in +{ + options.my.applications.openssh = { + enable = lib.mkEnableOption "OpenSSH server"; + }; + + config = lib.mkIf cfg.enable { + services.openssh = { + enable = true; + openFirewall = true; + + settings = { + PermitRootLogin = "no"; + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + PubkeyAuthentication = "yes"; + }; + }; + }; +} diff --git a/modules/applications/slack.nix b/modules/applications/slack.nix new file mode 100644 index 0000000..f52e68a --- /dev/null +++ b/modules/applications/slack.nix @@ -0,0 +1,24 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.slack; +in +{ + options.my.applications.slack = { + enable = lib.mkEnableOption "Slack messaging client"; + }; + + config = lib.mkIf cfg.enable { + home-manager.sharedModules = [ + { + home.packages = with pkgs; [ + slack # Team messaging and collaboration platform + ]; + } + ]; + }; +} diff --git a/modules/applications/ssh/default.nix b/modules/applications/ssh/default.nix new file mode 100644 index 0000000..f3debb2 --- /dev/null +++ b/modules/applications/ssh/default.nix @@ -0,0 +1,41 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.ssh; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.ssh = { + enable = lib.mkEnableOption "OpenSSH client"; + + defaultIdentityFile = lib.mkOption { + type = lib.types.str; + default = "~/.ssh/id_ed25519"; + description = "Default SSH identity file"; + }; + + addKeysToAgent = lib.mkOption { + type = lib.types.str; + default = "yes"; + description = "Add keys to SSH agent"; + }; + + matchBlocks = lib.mkOption { + type = lib.types.attrs; + default = { }; + description = "SSH match blocks"; + }; + }; + + config = lib.mkIf cfg.enable { + my.applications.ssh.system.enable = lib.mkDefault true; + my.applications.ssh.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/applications/ssh/home.nix b/modules/applications/ssh/home.nix new file mode 100644 index 0000000..e0e34b7 --- /dev/null +++ b/modules/applications/ssh/home.nix @@ -0,0 +1,37 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.ssh; + hmCfg = config.my.applications.ssh.homeManager; +in +{ + options.my.applications.ssh.homeManager = { + enable = lib.mkEnableOption "SSH home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + { + config = lib.mkIf hmCfg.enable { + home.packages = [ + pkgs.openssh + ]; + + programs.ssh = { + enable = true; + enableDefaultConfig = false; + + settings = cfg.matchBlocks // { + "*" = { + IdentityFile = cfg.defaultIdentityFile; + AddKeysToAgent = cfg.addKeysToAgent; + }; + }; + }; + }; + } + ]; +} diff --git a/modules/applications/ssh/system.nix b/modules/applications/ssh/system.nix new file mode 100644 index 0000000..b53e372 --- /dev/null +++ b/modules/applications/ssh/system.nix @@ -0,0 +1,20 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.ssh.system; +in +{ + options.my.applications.ssh.system = { + enable = lib.mkEnableOption "SSH system configuration"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + openssh # OpenSSH client and server + ]; + }; +} diff --git a/modules/applications/swayidle.nix b/modules/applications/swayidle.nix new file mode 100644 index 0000000..7477b3f --- /dev/null +++ b/modules/applications/swayidle.nix @@ -0,0 +1,101 @@ +{ + pkgs, + lib, + config, + inputs, + ... +}: +let + cfg = config.my.applications.swayidle; + + noctaliaPkg = inputs.noctalia.packages.${pkgs.system}.default; + noctalia = lib.getExe noctaliaPkg; + + bash = lib.getExe pkgs.bash; + brightnessctl = lib.getExe pkgs.brightnessctl; + niri = lib.getExe pkgs.niri; + rm = "${pkgs.coreutils}/bin/rm"; + + brightnessState = "$XDG_RUNTIME_DIR/swayidle-brightness"; + + noctaliaCall = target: action: "${bash} -lc '${noctalia} ipc call ${target} ${action}'"; + + lockCmd = noctaliaCall "lockScreen" "lock"; + + # AC 接続中は何もしない。つまり battery-only の処理にする。 + skipIfOnAC = '' + for supply in /sys/class/power_supply/*; do + if [ -f "$supply/type" ] \ + && [ "$(< "$supply/type")" = "Mains" ] \ + && [ -f "$supply/online" ] \ + && [ "$(< "$supply/online")" = "1" ]; then + exit 0 + fi + done + ''; + + dimScreen = pkgs.writeShellScript "swayidle-dim-screen" '' + ${skipIfOnAC} + + ${brightnessctl} get > "${brightnessState}" 2>/dev/null || exit 0 + ${brightnessctl} set 10% >/dev/null 2>&1 || true + ''; + + restoreBrightness = pkgs.writeShellScript "swayidle-restore-brightness" '' + if [ -f "${brightnessState}" ]; then + saved=$(< "${brightnessState}") + ${brightnessctl} set "$saved" >/dev/null 2>&1 || true + ${rm} -f "${brightnessState}" + fi + ''; + + lockAndSuspend = pkgs.writeShellScript "swayidle-lock-and-suspend" '' + ${skipIfOnAC} + ${noctaliaCall "sessionMenu" "lockAndSuspend"} + ''; + + afterResume = pkgs.writeShellScript "swayidle-after-resume" '' + ${niri} msg action power-on-monitors + ${restoreBrightness} + ''; +in +{ + options.my.applications.swayidle = { + enable = lib.mkEnableOption "swayidle idle manager"; + }; + + config = lib.mkIf cfg.enable { + home-manager.sharedModules = [ + { + services.swayidle = { + enable = true; + systemdTargets = [ "graphical-session.target" ]; + + timeouts = [ + { + timeout = 300; + command = "${dimScreen}"; + resumeCommand = "${restoreBrightness}"; + } + { + timeout = 360; + command = "${lockAndSuspend}"; + } + ]; + + events = { + lock = lockCmd; + before-sleep = lockCmd; + after-resume = "${afterResume}"; + }; + }; + + systemd.user.services.swayidle.Service.PassEnvironment = [ + "WAYLAND_DISPLAY" + "XDG_RUNTIME_DIR" + "DBUS_SESSION_BUS_ADDRESS" + ]; + } + ]; + }; +} diff --git a/modules/applications/tailscale.nix b/modules/applications/tailscale.nix new file mode 100644 index 0000000..8c9fc30 --- /dev/null +++ b/modules/applications/tailscale.nix @@ -0,0 +1,38 @@ +{ lib, config, ... }: +let + cfg = config.my.applications.tailscale; +in +{ + options.my.applications.tailscale = { + enable = lib.mkEnableOption "Tailscale VPN"; + + acceptDns = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Accept DNS configuration from Tailscale"; + }; + + acceptRoutes = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Accept subnet routes from Tailscale"; + }; + + extraUpFlags = lib.mkOption { + type = lib.types.listOf lib.types.str; + default = [ ]; + description = "Additional flags to pass to tailscale up"; + }; + }; + + config = lib.mkIf cfg.enable { + services.tailscale = { + enable = true; + extraUpFlags = [ + "--accept-dns=${if cfg.acceptDns then "true" else "false"}" + ] + ++ lib.optional cfg.acceptRoutes "--accept-routes" + ++ cfg.extraUpFlags; + }; + }; +} diff --git a/modules/applications/vicinae.nix b/modules/applications/vicinae.nix new file mode 100644 index 0000000..2edfa33 --- /dev/null +++ b/modules/applications/vicinae.nix @@ -0,0 +1,62 @@ +{ + inputs, + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.vicinae; +in +{ + options.my.applications.vicinae = { + enable = lib.mkEnableOption "Vicinae application launcher"; + }; + + config = lib.mkIf cfg.enable { + home-manager.sharedModules = [ + inputs.vicinae.homeManagerModules.default + { + services.vicinae = { + enable = true; + systemd = { + enable = true; + autoStart = true; + environment = { + USE_LAYER_SHELL = 1; + }; + }; + + settings = { + font.size = 11; + close_on_focus_loss = true; + consider_preedit = true; + pop_to_root_on_close = true; + favicon_service = "twenty"; + search_files_in_root = true; + theme = { + light = { + name = "dracula"; + icon_theme = "default"; + }; + dark = { + name = "vicinae-light"; + icon_theme = "default"; + }; + }; + window = { + csd = true; + opacity = 0.95; + rounding = 10; + }; + }; + extensions = with inputs.vicinae-extensions.packages.${pkgs.stdenv.hostPlatform.system}; [ + bluetooth + nix + power-profile + ]; + }; + } + ]; + }; +} diff --git a/modules/applications/vim/default.nix b/modules/applications/vim/default.nix new file mode 100644 index 0000000..17711f3 --- /dev/null +++ b/modules/applications/vim/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.vim; +in +{ + imports = [ + ./home + ./system.nix + ]; + + options.my.applications.vim = { + enable = lib.mkEnableOption "vim text editor"; + }; + + config = lib.mkIf cfg.enable { + my.applications.vim.system.enable = lib.mkDefault true; + my.applications.vim.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/home/nixvim/autocmds.nix b/modules/applications/vim/home/autocmds.nix similarity index 94% rename from modules/home/nixvim/autocmds.nix rename to modules/applications/vim/home/autocmds.nix index 4e8a2ec..5b98f8b 100644 --- a/modules/home/nixvim/autocmds.nix +++ b/modules/applications/vim/home/autocmds.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim.autoCmd = [ { event = "TextYankPost"; diff --git a/modules/home/nixvim/colorscheme.nix b/modules/applications/vim/home/colorscheme.nix similarity index 92% rename from modules/home/nixvim/colorscheme.nix rename to modules/applications/vim/home/colorscheme.nix index ff6c363..7a4049d 100644 --- a/modules/home/nixvim/colorscheme.nix +++ b/modules/applications/vim/home/colorscheme.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim.colorschemes.catppuccin = { enable = true; settings.transparent_background = true; diff --git a/modules/applications/vim/home/default.nix b/modules/applications/vim/home/default.nix new file mode 100644 index 0000000..b2a1060 --- /dev/null +++ b/modules/applications/vim/home/default.nix @@ -0,0 +1,62 @@ +{ + pkgs, + inputs, + lib, + config, + ... +}: +let + cfg = config.my.applications.vim.homeManager; +in +{ + options.my.applications.vim.homeManager = { + enable = lib.mkEnableOption "vim home-manager configuration"; + }; + + config = lib.mkIf cfg.enable { + home-manager.sharedModules = [ + inputs.nixvim.homeModules.nixvim + ./options.nix + ./autocmds.nix + ./keymaps.nix + ./language.nix + ./colorscheme.nix + ./lsp.nix + ./plugins + { + programs.nixvim = { + enable = true; + vimAlias = true; + viAlias = true; + withNodeJs = true; + + nixpkgs = { + source = pkgs.path; + config.allowUnfree = true; + }; + + extraPackages = with pkgs; [ + git + ripgrep + fd + nodejs + zellij + + # LSP / formatter / misc + vtsls + vscode-langservers-extracted + tailwindcss-language-server + prettierd + prettier + biome + stylua + shfmt + alejandra + lua-language-server + nixd + ]; + }; + } + ]; + }; +} diff --git a/modules/home/nixvim/keymaps.nix b/modules/applications/vim/home/keymaps.nix similarity index 80% rename from modules/home/nixvim/keymaps.nix rename to modules/applications/vim/home/keymaps.nix index 4d550aa..cefe442 100644 --- a/modules/home/nixvim/keymaps.nix +++ b/modules/applications/vim/home/keymaps.nix @@ -1,4 +1,5 @@ -{...}: let +_: +let mk = key: action: desc: { mode = "n"; inherit key action; @@ -28,7 +29,31 @@ inherit desc; }; }; -in { + + mkSmartWindowNav = key: direction: zellijDirection: desc: { + mode = "n"; + inherit key; + action.__raw = '' + function() + local current_win = vim.api.nvim_get_current_win() + vim.cmd.wincmd("${direction}") + + local at_edge = vim.api.nvim_get_current_win() == current_win + local in_zellij = vim.env.ZELLIJ ~= nil + local has_zellij_cli = vim.fn.executable("zellij") == 1 + + if at_edge and in_zellij and has_zellij_cli then + vim.system({ "zellij", "action", "move-focus-or-tab", "${zellijDirection}" }) + end + end + ''; + options = { + silent = true; + inherit desc; + }; + }; +in +{ programs.nixvim = { opts = { # ジャンプ履歴をスタック寄りに扱う @@ -65,7 +90,10 @@ in { # Convenience aliases (mkRaw "rn" "vim.lsp.buf.rename" "シンボル名を一括変換") - (mkRaw "cf" "function() require('conform').format({ timeout_ms = 1000, lsp_format = 'fallback' }) end" "コードをフォーマット") + (mkRaw "cf" + "function() require('conform').format({ timeout_ms = 1000, lsp_format = 'fallback' }) end" + "コードをフォーマット" + ) (mkRaw "ca" "vim.lsp.buf.code_action" "コードアクション") # Diagnostics @@ -93,14 +121,14 @@ in { (mk "[l" "lprev" "前のLocation Listへ") # Window navigation - (mk "" "h" "左のウィンドウへ") - (mk "" "j" "下のウィンドウへ") - (mk "" "k" "上のウィンドウへ") - (mk "" "l" "右のウィンドウへ") - (mk "" "h" "左のウィンドウへ") - (mk "" "j" "下のウィンドウへ") - (mk "" "k" "上のウィンドウへ") - (mk "" "l" "右のウィンドウへ") + (mkSmartWindowNav "" "h" "left" "左のウィンドウへ(端ならZellijペイン/タブへ)") + (mkSmartWindowNav "" "j" "down" "下のウィンドウへ(端ならZellijペインへ)") + (mkSmartWindowNav "" "k" "up" "上のウィンドウへ(端ならZellijペインへ)") + (mkSmartWindowNav "" "l" "right" "右のウィンドウへ(端ならZellijペイン/タブへ)") + (mkSmartWindowNav "" "h" "left" "左のウィンドウへ(端ならZellijペイン/タブへ)") + (mkSmartWindowNav "" "j" "down" "下のウィンドウへ(端ならZellijペインへ)") + (mkSmartWindowNav "" "k" "up" "上のウィンドウへ(端ならZellijペインへ)") + (mkSmartWindowNav "" "l" "right" "右のウィンドウへ(端ならZellijペイン/タブへ)") # Alternate file / previous file (mk "" "" "直前のファイルへ戻る") diff --git a/modules/home/nixvim/language.nix b/modules/applications/vim/home/language.nix similarity index 96% rename from modules/home/nixvim/language.nix rename to modules/applications/vim/home/language.nix index 3e66375..10faa21 100644 --- a/modules/home/nixvim/language.nix +++ b/modules/applications/vim/home/language.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim = { env = { LANG = "ja_JP.UTF-8"; diff --git a/modules/home/nixvim/lsp.nix b/modules/applications/vim/home/lsp.nix similarity index 99% rename from modules/home/nixvim/lsp.nix rename to modules/applications/vim/home/lsp.nix index 171ad5e..5761b87 100644 --- a/modules/home/nixvim/lsp.nix +++ b/modules/applications/vim/home/lsp.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim = { plugins.lsp = { enable = true; diff --git a/modules/home/nixvim/options.nix b/modules/applications/vim/home/options.nix similarity index 99% rename from modules/home/nixvim/options.nix rename to modules/applications/vim/home/options.nix index 5f7c3e4..2470b1c 100644 --- a/modules/home/nixvim/options.nix +++ b/modules/applications/vim/home/options.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim = { opts = { # display diff --git a/modules/home/nixvim/plugins/default.nix b/modules/applications/vim/home/plugins/default.nix similarity index 79% rename from modules/home/nixvim/plugins/default.nix rename to modules/applications/vim/home/plugins/default.nix index 8657654..ec310f7 100644 --- a/modules/home/nixvim/plugins/default.nix +++ b/modules/applications/vim/home/plugins/default.nix @@ -1,6 +1,7 @@ -{...}: { +{ ... }: +{ imports = [ - ./ui ./editor + ./ui ]; } diff --git a/modules/home/nixvim/plugins/editor/autopairs.nix b/modules/applications/vim/home/plugins/editor/autopairs.nix similarity index 86% rename from modules/home/nixvim/plugins/editor/autopairs.nix rename to modules/applications/vim/home/plugins/editor/autopairs.nix index 810bcf2..3802ad6 100644 --- a/modules/home/nixvim/plugins/editor/autopairs.nix +++ b/modules/applications/vim/home/plugins/editor/autopairs.nix @@ -1,3 +1,3 @@ -{...}: { +_: { programs.nixvim.plugins.nvim-autopairs.enable = true; } diff --git a/modules/home/nixvim/plugins/editor/blink-cmp.nix b/modules/applications/vim/home/plugins/editor/blink-cmp.nix similarity index 65% rename from modules/home/nixvim/plugins/editor/blink-cmp.nix rename to modules/applications/vim/home/plugins/editor/blink-cmp.nix index ba01396..9d114cf 100644 --- a/modules/home/nixvim/plugins/editor/blink-cmp.nix +++ b/modules/applications/vim/home/plugins/editor/blink-cmp.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim.plugins.blink-cmp = { enable = true; setupLspCapabilities = true; @@ -7,10 +7,10 @@ keymap = { preset = "enter"; - "" = ["show"]; - "" = ["scroll_documentation_up"]; - "" = ["hide"]; - "" = ["scroll_documentation_down"]; + "" = [ "show" ]; + "" = [ "scroll_documentation_up" ]; + "" = [ "hide" ]; + "" = [ "scroll_documentation_down" ]; "" = [ "accept" @@ -27,9 +27,18 @@ } "fallback" ]; - "" = ["select_prev" "fallback"]; - "" = ["select_next" "fallback"]; - "" = ["select_prev" "fallback"]; + "" = [ + "select_prev" + "fallback" + ]; + "" = [ + "select_next" + "fallback" + ]; + "" = [ + "select_prev" + "fallback" + ]; }; completion.list.selection = { diff --git a/modules/home/nixvim/plugins/editor/comment.nix b/modules/applications/vim/home/plugins/editor/comment.nix similarity index 85% rename from modules/home/nixvim/plugins/editor/comment.nix rename to modules/applications/vim/home/plugins/editor/comment.nix index 2f68e6c..c6a216d 100644 --- a/modules/home/nixvim/plugins/editor/comment.nix +++ b/modules/applications/vim/home/plugins/editor/comment.nix @@ -1,3 +1,3 @@ -{...}: { +_: { programs.nixvim.plugins.comment.enable = true; } diff --git a/modules/home/nixvim/plugins/editor/conform.nix b/modules/applications/vim/home/plugins/editor/conform.nix similarity index 90% rename from modules/home/nixvim/plugins/editor/conform.nix rename to modules/applications/vim/home/plugins/editor/conform.nix index 16f6e1e..40013ed 100644 --- a/modules/home/nixvim/plugins/editor/conform.nix +++ b/modules/applications/vim/home/plugins/editor/conform.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim.plugins."conform-nvim" = { enable = true; settings = { @@ -10,9 +10,9 @@ json.__raw = ''{ "biome", "prettierd", "prettier", stop_after_first = true }''; yaml.__raw = ''{ "prettierd", "prettier", stop_after_first = true }''; markdown.__raw = ''{ "prettierd", "prettier", stop_after_first = true }''; - lua = ["stylua"]; - nix = ["alejandra"]; - sh = ["shfmt"]; + lua = [ "stylua" ]; + nix = [ "alejandra" ]; + sh = [ "shfmt" ]; }; format_on_save.__raw = '' function(_) diff --git a/modules/home/nixvim/plugins/editor/copilot.nix b/modules/applications/vim/home/plugins/editor/copilot.nix similarity index 95% rename from modules/home/nixvim/plugins/editor/copilot.nix rename to modules/applications/vim/home/plugins/editor/copilot.nix index 783bfd1..4bbb86f 100644 --- a/modules/home/nixvim/plugins/editor/copilot.nix +++ b/modules/applications/vim/home/plugins/editor/copilot.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim.plugins.copilot-lua = { enable = true; settings = { diff --git a/modules/home/nixvim/plugins/editor/default.nix b/modules/applications/vim/home/plugins/editor/default.nix similarity index 97% rename from modules/home/nixvim/plugins/editor/default.nix rename to modules/applications/vim/home/plugins/editor/default.nix index bb6c431..d03d572 100644 --- a/modules/home/nixvim/plugins/editor/default.nix +++ b/modules/applications/vim/home/plugins/editor/default.nix @@ -1,22 +1,23 @@ -{...}: { +{ ... }: +{ imports = [ - ./snacks.nix - ./treesitter.nix - ./blink-cmp.nix - ./gitsigns.nix - ./comment.nix ./autopairs.nix - ./lsp-signature.nix - ./copilot.nix - ./trouble.nix + ./blink-cmp.nix + ./comment.nix ./conform.nix - ./surround.nix - ./git.nix - ./git-conflict.nix - ./glance.nix + ./copilot.nix ./flash.nix - ./todo-comments.nix + ./git-conflict.nix + ./git.nix + ./gitsigns.nix + ./glance.nix + ./lsp-signature.nix + ./snacks.nix ./spectre.nix + ./surround.nix + ./todo-comments.nix + ./treesitter.nix + ./trouble.nix ./wakatime.nix ]; } diff --git a/modules/home/nixvim/plugins/editor/flash.nix b/modules/applications/vim/home/plugins/editor/flash.nix similarity index 89% rename from modules/home/nixvim/plugins/editor/flash.nix rename to modules/applications/vim/home/plugins/editor/flash.nix index 3396c61..d899445 100644 --- a/modules/home/nixvim/plugins/editor/flash.nix +++ b/modules/applications/vim/home/plugins/editor/flash.nix @@ -1,4 +1,5 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim = { extraPlugins = [ pkgs.vimPlugins.flash-nvim ]; extraConfigLua = '' diff --git a/modules/home/nixvim/plugins/editor/git-conflict.nix b/modules/applications/vim/home/plugins/editor/git-conflict.nix similarity index 90% rename from modules/home/nixvim/plugins/editor/git-conflict.nix rename to modules/applications/vim/home/plugins/editor/git-conflict.nix index 84d119a..8c8663c 100644 --- a/modules/home/nixvim/plugins/editor/git-conflict.nix +++ b/modules/applications/vim/home/plugins/editor/git-conflict.nix @@ -1,4 +1,5 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim = { extraPlugins = [ pkgs.vimPlugins.git-conflict-nvim ]; extraConfigLua = '' diff --git a/modules/home/nixvim/plugins/editor/git.nix b/modules/applications/vim/home/plugins/editor/git.nix similarity index 89% rename from modules/home/nixvim/plugins/editor/git.nix rename to modules/applications/vim/home/plugins/editor/git.nix index 713f896..cd904cb 100644 --- a/modules/home/nixvim/plugins/editor/git.nix +++ b/modules/applications/vim/home/plugins/editor/git.nix @@ -1,4 +1,5 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim = { extraPackages = [ pkgs.lazygit ]; diff --git a/modules/applications/vim/home/plugins/editor/gitsigns.nix b/modules/applications/vim/home/plugins/editor/gitsigns.nix new file mode 100644 index 0000000..6a7e881 --- /dev/null +++ b/modules/applications/vim/home/plugins/editor/gitsigns.nix @@ -0,0 +1,25 @@ +_: { + # git change view + programs.nixvim.plugins.gitsigns = { + enable = true; + settings = { + signs = { + add = { + text = "+"; + }; + change = { + text = "~"; + }; + delete = { + text = "_"; + }; + topdelete = { + text = "‾"; + }; + changedelete = { + text = "~"; + }; + }; + }; + }; +} diff --git a/modules/home/nixvim/plugins/editor/glance.nix b/modules/applications/vim/home/plugins/editor/glance.nix similarity index 89% rename from modules/home/nixvim/plugins/editor/glance.nix rename to modules/applications/vim/home/plugins/editor/glance.nix index d5b6c24..bea6bd3 100644 --- a/modules/home/nixvim/plugins/editor/glance.nix +++ b/modules/applications/vim/home/plugins/editor/glance.nix @@ -1,4 +1,5 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim = { extraPlugins = [ pkgs.vimPlugins.glance-nvim ]; extraConfigLua = '' diff --git a/modules/home/nixvim/plugins/editor/lsp-signature.nix b/modules/applications/vim/home/plugins/editor/lsp-signature.nix similarity index 95% rename from modules/home/nixvim/plugins/editor/lsp-signature.nix rename to modules/applications/vim/home/plugins/editor/lsp-signature.nix index b9a2711..361bb67 100644 --- a/modules/home/nixvim/plugins/editor/lsp-signature.nix +++ b/modules/applications/vim/home/plugins/editor/lsp-signature.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim.plugins.lsp-signature = { enable = true; settings = { diff --git a/modules/home/nixvim/plugins/editor/snacks.nix b/modules/applications/vim/home/plugins/editor/snacks.nix similarity index 89% rename from modules/home/nixvim/plugins/editor/snacks.nix rename to modules/applications/vim/home/plugins/editor/snacks.nix index 4af9f49..86ace40 100644 --- a/modules/home/nixvim/plugins/editor/snacks.nix +++ b/modules/applications/vim/home/plugins/editor/snacks.nix @@ -1,6 +1,7 @@ -{pkgs, ...}: { +{ pkgs, ... }: +{ programs.nixvim = { - extraPlugins = [pkgs.vimPlugins.snacks-nvim]; + extraPlugins = [ pkgs.vimPlugins.snacks-nvim ]; extraConfigLua = '' require("snacks").setup({ diff --git a/modules/home/nixvim/plugins/editor/spectre.nix b/modules/applications/vim/home/plugins/editor/spectre.nix similarity index 91% rename from modules/home/nixvim/plugins/editor/spectre.nix rename to modules/applications/vim/home/plugins/editor/spectre.nix index 98a1403..60c2e4c 100644 --- a/modules/home/nixvim/plugins/editor/spectre.nix +++ b/modules/applications/vim/home/plugins/editor/spectre.nix @@ -1,4 +1,5 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim = { extraPackages = [ pkgs.ripgrep ]; extraPlugins = [ pkgs.vimPlugins.nvim-spectre ]; diff --git a/modules/home/nixvim/plugins/editor/surround.nix b/modules/applications/vim/home/plugins/editor/surround.nix similarity index 86% rename from modules/home/nixvim/plugins/editor/surround.nix rename to modules/applications/vim/home/plugins/editor/surround.nix index a6575b0..83276b4 100644 --- a/modules/home/nixvim/plugins/editor/surround.nix +++ b/modules/applications/vim/home/plugins/editor/surround.nix @@ -1,3 +1,3 @@ -{...}: { +_: { programs.nixvim.plugins.nvim-surround.enable = true; } diff --git a/modules/home/nixvim/plugins/editor/todo-comments.nix b/modules/applications/vim/home/plugins/editor/todo-comments.nix similarity index 90% rename from modules/home/nixvim/plugins/editor/todo-comments.nix rename to modules/applications/vim/home/plugins/editor/todo-comments.nix index 495eb25..fa3303a 100644 --- a/modules/home/nixvim/plugins/editor/todo-comments.nix +++ b/modules/applications/vim/home/plugins/editor/todo-comments.nix @@ -1,4 +1,5 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim = { extraPlugins = [ pkgs.vimPlugins.todo-comments-nvim ]; extraConfigLua = '' diff --git a/modules/home/nixvim/plugins/editor/treesitter.nix b/modules/applications/vim/home/plugins/editor/treesitter.nix similarity index 94% rename from modules/home/nixvim/plugins/editor/treesitter.nix rename to modules/applications/vim/home/plugins/editor/treesitter.nix index 62b8fd4..32208b1 100644 --- a/modules/home/nixvim/plugins/editor/treesitter.nix +++ b/modules/applications/vim/home/plugins/editor/treesitter.nix @@ -1,4 +1,5 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim = { plugins.treesitter = { enable = true; diff --git a/modules/home/nixvim/plugins/editor/trouble.nix b/modules/applications/vim/home/plugins/editor/trouble.nix similarity index 85% rename from modules/home/nixvim/plugins/editor/trouble.nix rename to modules/applications/vim/home/plugins/editor/trouble.nix index b702029..c7ce674 100644 --- a/modules/home/nixvim/plugins/editor/trouble.nix +++ b/modules/applications/vim/home/plugins/editor/trouble.nix @@ -1,3 +1,3 @@ -{...}: { +_: { programs.nixvim.plugins.trouble.enable = true; } diff --git a/modules/home/nixvim/plugins/editor/wakatime.nix b/modules/applications/vim/home/plugins/editor/wakatime.nix similarity index 80% rename from modules/home/nixvim/plugins/editor/wakatime.nix rename to modules/applications/vim/home/plugins/editor/wakatime.nix index 4918da6..04dc233 100644 --- a/modules/home/nixvim/plugins/editor/wakatime.nix +++ b/modules/applications/vim/home/plugins/editor/wakatime.nix @@ -1,3 +1,4 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim.extraPlugins = [ pkgs.vimPlugins.vim-wakatime ]; } diff --git a/modules/home/nixvim/plugins/ui/barbar.nix b/modules/applications/vim/home/plugins/ui/barbar.nix similarity index 98% rename from modules/home/nixvim/plugins/ui/barbar.nix rename to modules/applications/vim/home/plugins/ui/barbar.nix index 2d9926a..474a5a0 100644 --- a/modules/home/nixvim/plugins/ui/barbar.nix +++ b/modules/applications/vim/home/plugins/ui/barbar.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim.plugins.barbar = { enable = true; settings = { diff --git a/modules/home/nixvim/plugins/ui/blankline.nix b/modules/applications/vim/home/plugins/ui/blankline.nix similarity index 97% rename from modules/home/nixvim/plugins/ui/blankline.nix rename to modules/applications/vim/home/plugins/ui/blankline.nix index 657f113..3439350 100644 --- a/modules/home/nixvim/plugins/ui/blankline.nix +++ b/modules/applications/vim/home/plugins/ui/blankline.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim.plugins.indent-blankline = { enable = true; settings = { diff --git a/modules/home/nixvim/plugins/ui/colorizer.nix b/modules/applications/vim/home/plugins/ui/colorizer.nix similarity index 84% rename from modules/home/nixvim/plugins/ui/colorizer.nix rename to modules/applications/vim/home/plugins/ui/colorizer.nix index acb3d20..54b6c4e 100644 --- a/modules/home/nixvim/plugins/ui/colorizer.nix +++ b/modules/applications/vim/home/plugins/ui/colorizer.nix @@ -1,9 +1,12 @@ -{...}: { +_: { programs.nixvim.plugins.colorizer = { enable = true; settings = { - filetypes = ["*" "!markdown"]; + filetypes = [ + "*" + "!markdown" + ]; user_commands = true; options = { diff --git a/modules/home/nixvim/plugins/ui/default.nix b/modules/applications/vim/home/plugins/ui/default.nix similarity index 96% rename from modules/home/nixvim/plugins/ui/default.nix rename to modules/applications/vim/home/plugins/ui/default.nix index fcac723..0e72a6f 100644 --- a/modules/home/nixvim/plugins/ui/default.nix +++ b/modules/applications/vim/home/plugins/ui/default.nix @@ -1,19 +1,20 @@ -{...}: { +{ ... }: +{ imports = [ - ./lualine.nix - ./neo-tree.nix - ./blankline.nix - ./which-key.nix - ./web-devicons.nix - ./toggleterm.nix - ./treesitter.nix ./barbar.nix - ./lightbulb.nix + ./blankline.nix ./colorizer.nix ./dropbar.nix - ./scrollbar.nix - ./ufo.nix - ./zen-mode.nix + ./lightbulb.nix + ./lualine.nix ./markview.nix + ./neo-tree.nix + ./scrollbar.nix + ./toggleterm.nix + ./treesitter.nix + ./ufo.nix + ./web-devicons.nix + ./which-key.nix + ./zen-mode.nix ]; } diff --git a/modules/home/nixvim/plugins/ui/dropbar.nix b/modules/applications/vim/home/plugins/ui/dropbar.nix similarity index 85% rename from modules/home/nixvim/plugins/ui/dropbar.nix rename to modules/applications/vim/home/plugins/ui/dropbar.nix index 586aff5..d6eea7d 100644 --- a/modules/home/nixvim/plugins/ui/dropbar.nix +++ b/modules/applications/vim/home/plugins/ui/dropbar.nix @@ -1,3 +1,3 @@ -{...}: { +_: { programs.nixvim.plugins.dropbar.enable = true; } diff --git a/modules/home/nixvim/plugins/ui/lightbulb.nix b/modules/applications/vim/home/plugins/ui/lightbulb.nix similarity index 92% rename from modules/home/nixvim/plugins/ui/lightbulb.nix rename to modules/applications/vim/home/plugins/ui/lightbulb.nix index f862079..fd887e3 100644 --- a/modules/home/nixvim/plugins/ui/lightbulb.nix +++ b/modules/applications/vim/home/plugins/ui/lightbulb.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim.plugins.nvim-lightbulb = { enable = true; settings.autocmd.enabled = true; diff --git a/modules/home/nixvim/plugins/ui/lualine.nix b/modules/applications/vim/home/plugins/ui/lualine.nix similarity index 98% rename from modules/home/nixvim/plugins/ui/lualine.nix rename to modules/applications/vim/home/plugins/ui/lualine.nix index 328f3cf..8c7a508 100644 --- a/modules/home/nixvim/plugins/ui/lualine.nix +++ b/modules/applications/vim/home/plugins/ui/lualine.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim.plugins.lualine = { enable = true; settings.sections.lualine_x = [ diff --git a/modules/home/nixvim/plugins/ui/markview.nix b/modules/applications/vim/home/plugins/ui/markview.nix similarity index 91% rename from modules/home/nixvim/plugins/ui/markview.nix rename to modules/applications/vim/home/plugins/ui/markview.nix index af2a0e1..a67adc1 100644 --- a/modules/home/nixvim/plugins/ui/markview.nix +++ b/modules/applications/vim/home/plugins/ui/markview.nix @@ -1,4 +1,5 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim = { extraPlugins = [ pkgs.vimPlugins.markview-nvim ]; extraConfigLua = '' diff --git a/modules/home/nixvim/plugins/ui/neo-tree.nix b/modules/applications/vim/home/plugins/ui/neo-tree.nix similarity index 76% rename from modules/home/nixvim/plugins/ui/neo-tree.nix rename to modules/applications/vim/home/plugins/ui/neo-tree.nix index e151a65..f3fe5e8 100644 --- a/modules/home/nixvim/plugins/ui/neo-tree.nix +++ b/modules/applications/vim/home/plugins/ui/neo-tree.nix @@ -1,4 +1,4 @@ -{...}: { +_: { programs.nixvim = { plugins.neo-tree = { enable = true; @@ -18,17 +18,17 @@ hide_ignored = false; hide_hidden = false; - hide_by_name = []; - hide_by_pattern = []; + hide_by_name = [ ]; + hide_by_pattern = [ ]; - always_show = []; - always_show_by_pattern = []; + always_show = [ ]; + always_show_by_pattern = [ ]; never_show = [ ".DS_Store" "thumbs.db" ]; - never_show_by_pattern = []; + never_show_by_pattern = [ ]; }; }; }; diff --git a/modules/home/nixvim/plugins/ui/scrollbar.nix b/modules/applications/vim/home/plugins/ui/scrollbar.nix similarity index 89% rename from modules/home/nixvim/plugins/ui/scrollbar.nix rename to modules/applications/vim/home/plugins/ui/scrollbar.nix index c31d384..c7c53b5 100644 --- a/modules/home/nixvim/plugins/ui/scrollbar.nix +++ b/modules/applications/vim/home/plugins/ui/scrollbar.nix @@ -1,4 +1,5 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim = { extraPlugins = [ pkgs.vimPlugins.nvim-scrollbar ]; extraConfigLua = '' diff --git a/modules/home/nixvim/plugins/ui/toggleterm.nix b/modules/applications/vim/home/plugins/ui/toggleterm.nix similarity index 85% rename from modules/home/nixvim/plugins/ui/toggleterm.nix rename to modules/applications/vim/home/plugins/ui/toggleterm.nix index ccdee4b..123dde3 100644 --- a/modules/home/nixvim/plugins/ui/toggleterm.nix +++ b/modules/applications/vim/home/plugins/ui/toggleterm.nix @@ -1,3 +1,3 @@ -{...}: { +_: { programs.nixvim.plugins.toggleterm.enable = true; } diff --git a/modules/home/nixvim/plugins/ui/treesitter.nix b/modules/applications/vim/home/plugins/ui/treesitter.nix similarity index 87% rename from modules/home/nixvim/plugins/ui/treesitter.nix rename to modules/applications/vim/home/plugins/ui/treesitter.nix index b43df40..9a3f85e 100644 --- a/modules/home/nixvim/plugins/ui/treesitter.nix +++ b/modules/applications/vim/home/plugins/ui/treesitter.nix @@ -1,3 +1,3 @@ -{...}: { +_: { programs.nixvim.plugins."treesitter-context".enable = true; } diff --git a/modules/home/nixvim/plugins/ui/ufo.nix b/modules/applications/vim/home/plugins/ui/ufo.nix similarity index 96% rename from modules/home/nixvim/plugins/ui/ufo.nix rename to modules/applications/vim/home/plugins/ui/ufo.nix index 91319d4..d59f54c 100644 --- a/modules/home/nixvim/plugins/ui/ufo.nix +++ b/modules/applications/vim/home/plugins/ui/ufo.nix @@ -1,4 +1,5 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim = { opts = { foldcolumn = "1"; diff --git a/modules/home/nixvim/plugins/ui/web-devicons.nix b/modules/applications/vim/home/plugins/ui/web-devicons.nix similarity index 89% rename from modules/home/nixvim/plugins/ui/web-devicons.nix rename to modules/applications/vim/home/plugins/ui/web-devicons.nix index 4f251bf..12d195f 100644 --- a/modules/home/nixvim/plugins/ui/web-devicons.nix +++ b/modules/applications/vim/home/plugins/ui/web-devicons.nix @@ -1,4 +1,4 @@ -{...}: { +_: { # icon set preview programs.nixvim.plugins.web-devicons.enable = true; } diff --git a/modules/home/nixvim/plugins/ui/which-key.nix b/modules/applications/vim/home/plugins/ui/which-key.nix similarity index 88% rename from modules/home/nixvim/plugins/ui/which-key.nix rename to modules/applications/vim/home/plugins/ui/which-key.nix index 9499982..7f0441d 100644 --- a/modules/home/nixvim/plugins/ui/which-key.nix +++ b/modules/applications/vim/home/plugins/ui/which-key.nix @@ -1,4 +1,4 @@ -{...}: { +_: { # key map help programs.nixvim.plugins.which-key.enable = true; } diff --git a/modules/home/nixvim/plugins/ui/zen-mode.nix b/modules/applications/vim/home/plugins/ui/zen-mode.nix similarity index 89% rename from modules/home/nixvim/plugins/ui/zen-mode.nix rename to modules/applications/vim/home/plugins/ui/zen-mode.nix index 562eb5b..23c7a5f 100644 --- a/modules/home/nixvim/plugins/ui/zen-mode.nix +++ b/modules/applications/vim/home/plugins/ui/zen-mode.nix @@ -1,4 +1,5 @@ -{ pkgs, ... }: { +{ pkgs, ... }: +{ programs.nixvim = { extraPlugins = [ pkgs.vimPlugins.zen-mode-nvim ]; extraConfigLua = '' diff --git a/modules/applications/vim/system.nix b/modules/applications/vim/system.nix new file mode 100644 index 0000000..8098b91 --- /dev/null +++ b/modules/applications/vim/system.nix @@ -0,0 +1,22 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.vim.system; +in +{ + options.my.applications.vim.system = { + enable = lib.mkEnableOption "vim system configuration"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + vim # Highly configurable text editor + ]; + + environment.variables.EDITOR = "nvim"; + }; +} diff --git a/modules/applications/vscode/default.nix b/modules/applications/vscode/default.nix new file mode 100644 index 0000000..96a36d3 --- /dev/null +++ b/modules/applications/vscode/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.vscode; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.vscode = { + enable = lib.mkEnableOption "Visual Studio Code editor"; + }; + + config = lib.mkIf cfg.enable { + my.applications.vscode.system.enable = lib.mkDefault true; + my.applications.vscode.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/home/vscode.nix b/modules/applications/vscode/home.nix similarity index 78% rename from modules/home/vscode.nix rename to modules/applications/vscode/home.nix index d198d54..ab8286a 100644 --- a/modules/home/vscode.nix +++ b/modules/applications/vscode/home.nix @@ -1,12 +1,15 @@ { pkgs, lib, + config, ... -}: let +}: +let + cfg = config.my.applications.vscode.homeManager; vsc = pkgs.vscode-extensions; inherit (lib) recursiveUpdate; - rustLibclangPath = pkgs.lib.makeLibraryPath [pkgs.llvmPackages_latest.libclang.lib]; + rustLibclangPath = pkgs.lib.makeLibraryPath [ pkgs.llvmPackages_latest.libclang.lib ]; rustBindgenExtraClangArgs = lib.concatStringsSep " " ( (builtins.map (a: ''-I"${a}/include"'') [ @@ -15,7 +18,7 @@ ++ [ ''-I"${pkgs.llvmPackages_latest.libclang.lib}/lib/clang/${pkgs.llvmPackages_latest.libclang.version}/include"'' ''-I"${pkgs.glib.dev}/include/glib-2.0"'' - ''-I${pkgs.glib.out}/lib/glib-2.0/include/'' + "-I${pkgs.glib.out}/lib/glib-2.0/include/" ] ); @@ -93,7 +96,7 @@ hash = "sha256-MAfjS/oFfFuiE+Q2w6leSlao436QSw2fKjd7/BE/Q8Y="; } ]; - userSettings = {}; + userSettings = { }; }; web-biome = { @@ -142,18 +145,16 @@ ms-toolsai.jupyter ms-python.python ]; - userSettings = {}; + userSettings = { }; }; java = { - extensions = ( - with vsc; [ - vscjava.vscode-java-pack - sonarsource.sonarlint-vscode - vscjava.vscode-java-debug - redhat.java - ] - ); + extensions = with vsc; [ + vscjava.vscode-java-pack + sonarsource.sonarlint-vscode + vscjava.vscode-java-debug + redhat.java + ]; userSettings = { "java.jdt.ls.java.home" = "${pkgs.jdk25.home}"; @@ -231,53 +232,63 @@ }; }; - combine = ( + combine = ls: - builtins.foldl' + builtins.foldl' (acc: l: { - extensions = acc.extensions ++ (l.extensions or []); - userSettings = recursiveUpdate acc.userSettings (l.userSettings or {}); + extensions = acc.extensions ++ (l.extensions or [ ]); + userSettings = recursiveUpdate acc.userSettings (l.userSettings or { }); }) { - extensions = []; - userSettings = {}; + extensions = [ ]; + userSettings = { }; } - ls - ); + ls; - # mkProfile [layers...] { extensions = [...]; userSettings = { ... }; } - mkProfile = layersList: extras: let - base = combine layersList; - in { - extensions = base.extensions ++ (extras.extensions or []); - userSettings = recursiveUpdate base.userSettings (extras.userSettings or {}); - }; -in { - nixpkgs.config.allowUnfree = true; - - programs.vscode = { - enable = true; - - profiles = { - default = mkProfile [layers.common] {}; - - nix = mkProfile [layers.common layers.nix] {}; - - web = mkProfile [layers.common layers.web layers.web-biome] {}; - - web-oxc = mkProfile [layers.common layers.web layers.web-oxc] {}; - - jupyter = mkProfile [layers.common layers.jupyter] {}; - - java = mkProfile [layers.common layers.java] {}; - - rust = mkProfile [layers.common layers.rust] {}; - }; - }; - - xdg.configFile."Code/User/locale.json".text = '' + mkProfile = + layersList: extras: + let + base = combine layersList; + in { - "locale": "ja" - } - ''; + extensions = base.extensions ++ (extras.extensions or [ ]); + userSettings = recursiveUpdate base.userSettings (extras.userSettings or { }); + }; +in +{ + options.my.applications.vscode.homeManager = { + enable = lib.mkEnableOption "VSCode home-manager configuration"; + }; + + config = lib.mkIf cfg.enable { + home-manager.sharedModules = [ + { + programs.vscode = { + enable = true; + + profiles = { + default = mkProfile [ layers.common ] { }; + + nix = mkProfile [ layers.common layers.nix ] { }; + + web = mkProfile [ layers.common layers.web layers.web-biome ] { }; + + web-oxc = mkProfile [ layers.common layers.web layers.web-oxc ] { }; + + jupyter = mkProfile [ layers.common layers.jupyter ] { }; + + java = mkProfile [ layers.common layers.java ] { }; + + rust = mkProfile [ layers.common layers.rust ] { }; + }; + }; + + xdg.configFile."Code/User/locale.json".text = '' + { + "locale": "ja" + } + ''; + } + ]; + }; } diff --git a/modules/applications/vscode/system.nix b/modules/applications/vscode/system.nix new file mode 100644 index 0000000..99f05d7 --- /dev/null +++ b/modules/applications/vscode/system.nix @@ -0,0 +1,20 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.vscode.system; +in +{ + options.my.applications.vscode.system = { + enable = lib.mkEnableOption "VSCode system configuration"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + sqlite # SQLite database library (VSCode dependency) + ]; + }; +} diff --git a/modules/applications/wayland.nix b/modules/applications/wayland.nix new file mode 100644 index 0000000..e702877 --- /dev/null +++ b/modules/applications/wayland.nix @@ -0,0 +1,49 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.wayland; +in +{ + options.my.applications.wayland = { + enable = lib.mkEnableOption "Wayland session support"; + }; + + config = lib.mkIf cfg.enable { + programs.xwayland.enable = true; + + xdg.portal = { + enable = true; + wlr.enable = true; + extraPortals = [ + pkgs.xdg-desktop-portal-wlr + pkgs.xdg-desktop-portal-gtk + ]; + xdgOpenUsePortal = true; + config = { + common.default = [ + "wlr" + "gtk" + ]; + }; + }; + + environment.variables = { + NIXOS_OZONE_WL = "1"; + }; + + environment.sessionVariables = { + ELECTRON_OZONE_PLATFORM_HINT = "wayland"; + QT_QPA_PLATFORM = "wayland;xcb"; + NIXOS_OZONE_WL = "1"; + }; + + environment.systemPackages = with pkgs; [ + xwayland-satellite # X11 compatibility layer for Wayland + uwsm # Universal Wayland Session Manager + ]; + }; +} diff --git a/modules/applications/zellij/default.nix b/modules/applications/zellij/default.nix new file mode 100644 index 0000000..81a0c8a --- /dev/null +++ b/modules/applications/zellij/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.zellij; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.zellij = { + enable = lib.mkEnableOption "Zellij terminal multiplexer"; + }; + + config = lib.mkIf cfg.enable { + my.applications.zellij.system.enable = lib.mkDefault true; + my.applications.zellij.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/applications/zellij/home.nix b/modules/applications/zellij/home.nix new file mode 100644 index 0000000..98c40ee --- /dev/null +++ b/modules/applications/zellij/home.nix @@ -0,0 +1,83 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.zellij.homeManager; +in +{ + options.my.applications.zellij.homeManager = { + enable = lib.mkEnableOption "Zellij home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + { + config = lib.mkIf cfg.enable { + programs.zellij = { + enable = true; + + enableZshIntegration = false; + + settings = { + pane_frames = true; + copy_clipboard = "system"; + copy_on_select = false; + default_mode = "locked"; + default_shell = "/run/current-system/sw/bin/zsh"; + }; + + extraConfig = '' + keybinds { + locked { + bind "Ctrl g" { SwitchToMode "normal"; } + bind "Alt h" "Alt Left" { MoveFocusOrTab "Left"; } + bind "Alt j" "Alt Down" { MoveFocus "Down"; } + bind "Alt k" "Alt Up" { MoveFocus "Up"; } + bind "Alt l" "Alt Right" { MoveFocusOrTab "Right"; } + bind "Alt n" { NewPane; } + bind "Alt t" { NewTab; } + bind "Alt H" { Resize "Increase Left"; } + bind "Alt J" { Resize "Increase Down"; } + bind "Alt K" { Resize "Increase Up"; } + bind "Alt L" { Resize "Increase Right"; } + bind "Alt c" "Ctrl Shift c" { Copy; } + } + normal { + bind "Alt h" "Alt Left" { MoveFocusOrTab "Left"; } + bind "Alt j" "Alt Down" { MoveFocus "Down"; } + bind "Alt k" "Alt Up" { MoveFocus "Up"; } + bind "Alt l" "Alt Right" { MoveFocusOrTab "Right"; } + bind "Alt n" { NewPane; } + bind "Alt t" { NewTab; } + bind "Ctrl Shift c" { Copy; } + bind "Alt H" { Resize "Increase Left"; } + bind "Alt J" { Resize "Increase Down"; } + bind "Alt K" { Resize "Increase Up"; } + bind "Alt L" { Resize "Increase Right"; } + } + } + ''; + + layouts.dev = '' + layout { + pane split_direction="vertical" { + pane { + pane command="nvim" + pane stacked=true size="30%" { + pane expanded=true + pane + } + } + + pane size=1 borderless=true { + plugin location="zellij:compact-bar" + } + } + } + ''; + }; + }; + } + ]; +} diff --git a/modules/applications/zellij/system.nix b/modules/applications/zellij/system.nix new file mode 100644 index 0000000..65a6cb3 --- /dev/null +++ b/modules/applications/zellij/system.nix @@ -0,0 +1,20 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.zellij.system; +in +{ + options.my.applications.zellij.system = { + enable = lib.mkEnableOption "Zellij system configuration"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + zellij # Terminal multiplexer with batteries included + ]; + }; +} diff --git a/modules/applications/zoom.nix b/modules/applications/zoom.nix new file mode 100644 index 0000000..5e78408 --- /dev/null +++ b/modules/applications/zoom.nix @@ -0,0 +1,24 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.applications.zoom; +in +{ + options.my.applications.zoom = { + enable = lib.mkEnableOption "Zoom video conferencing"; + }; + + config = lib.mkIf cfg.enable { + home-manager.sharedModules = [ + { + home.packages = with pkgs; [ + zoom-us # Video conferencing application + ]; + } + ]; + }; +} diff --git a/modules/applications/zsh/default.nix b/modules/applications/zsh/default.nix new file mode 100644 index 0000000..ce95586 --- /dev/null +++ b/modules/applications/zsh/default.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.applications.zsh; +in +{ + imports = [ + ./home.nix + ./system.nix + ]; + + options.my.applications.zsh = { + enable = lib.mkEnableOption "Zsh shell"; + }; + + config = lib.mkIf cfg.enable { + my.applications.zsh.system.enable = lib.mkDefault true; + my.applications.zsh.homeManager.enable = lib.mkDefault true; + }; +} diff --git a/modules/applications/zsh/home.nix b/modules/applications/zsh/home.nix new file mode 100644 index 0000000..529edc1 --- /dev/null +++ b/modules/applications/zsh/home.nix @@ -0,0 +1,58 @@ +{ lib, config, ... }: +let + cfg = config.my.applications.zsh.homeManager; +in +{ + options.my.applications.zsh.homeManager = { + enable = lib.mkEnableOption "Zsh home-manager configuration"; + }; + + config.home-manager.sharedModules = [ + { + config = lib.mkIf cfg.enable { + programs.zsh = { + enable = true; + enableCompletion = true; + + oh-my-zsh = { + enable = true; + theme = "robbyrussell"; + plugins = [ "git" ]; + }; + + autosuggestion.enable = true; + syntaxHighlighting.enable = true; + + initContent = '' + # ---- from gist: export / history size ---- + export HISTSIZE=999999999 + export HISTFILESIZE=999999999 + + # ---- from gist: setopt ---- + setopt extended_history + setopt hist_allow_clobber + setopt hist_fcntl_lock + setopt hist_find_no_dups + setopt hist_ignore_all_dups + setopt hist_ignore_dups + setopt hist_ignore_space + # setopt hist_no_functions + # setopt hist_no_store + setopt hist_reduce_blanks + setopt hist_save_no_dups + setopt hist_verify + setopt inc_append_history_time + + unsetopt SHARE_HISTORY + setopt APPEND_HISTORY + setopt INC_APPEND_HISTORY_TIME + + # ---- from gist: aliases ---- + alias docker-compose="docker compose" + alias clearsign='export GPG_TTY=$(tty) && openssl rand -hex 16 | gpg --clearsign' + ''; + }; + }; + } + ]; +} diff --git a/modules/applications/zsh/system.nix b/modules/applications/zsh/system.nix new file mode 100644 index 0000000..ef4a98d --- /dev/null +++ b/modules/applications/zsh/system.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.applications.zsh.system; +in +{ + options.my.applications.zsh.system = { + enable = lib.mkEnableOption "Zsh system configuration"; + }; + + config = lib.mkIf cfg.enable { + programs.zsh.enable = true; + }; +} diff --git a/modules/core/boot.nix b/modules/core/boot.nix deleted file mode 100644 index c0d7041..0000000 --- a/modules/core/boot.nix +++ /dev/null @@ -1,11 +0,0 @@ -{ pkgs, ... }: -{ - boot.loader = { - systemd-boot.enable = true; - systemd-boot.configurationLimit = 8; - efi.canTouchEfiVariables = true; - }; - - boot.supportedFilesystems = [ "nfs" ]; - boot.kernelPackages = pkgs.linuxPackages_latest; -} \ No newline at end of file diff --git a/modules/core/camera.nix b/modules/core/camera.nix deleted file mode 100644 index 9204cd6..0000000 --- a/modules/core/camera.nix +++ /dev/null @@ -1,21 +0,0 @@ -{ pkgs, ... }: -{ - boot.kernelModules = [ "uvcvideo" ]; - - environment.systemPackages = with pkgs; [ - v4l-utils - (ffmpeg-full) - ]; - - services.pipewire = { - enable = true; - alsa.enable = true; - pulse.enable = true; - }; - security.rtkit.enable = true; - - xdg.portal = { - enable = true; - extraPortals = [ pkgs.xdg-desktop-portal-gtk ]; - }; -} \ No newline at end of file diff --git a/modules/core/default.nix b/modules/core/default.nix deleted file mode 100644 index 196cbe6..0000000 --- a/modules/core/default.nix +++ /dev/null @@ -1,18 +0,0 @@ -{...}: { - imports = [ - ./boot.nix - ./cachix.nix - ./environment.nix - ./fonts.nix - ./gc.nix - ./hardware.nix - ./i18n.nix - ./network.nix - ./packages.nix - ./services.nix - ./ssh.nix - ./system.nix - ./user.nix - ./xserver.nix - ]; -} diff --git a/modules/core/environment.nix b/modules/core/environment.nix deleted file mode 100644 index 14f0ee7..0000000 --- a/modules/core/environment.nix +++ /dev/null @@ -1,9 +0,0 @@ -{ ... }: -{ - environment.sessionVariables = { - ELECTRON_OZONE_PLATFORM_HINT = "wayland"; - QT_QPA_PLATFORM = "wayland;xcb"; - NIXOS_OZONE_WL = "1"; - }; - environment.variables.EDITOR = "nvim"; -} \ No newline at end of file diff --git a/modules/core/fingerprint.nix b/modules/core/fingerprint.nix deleted file mode 100644 index 10f0ea6..0000000 --- a/modules/core/fingerprint.nix +++ /dev/null @@ -1,21 +0,0 @@ -{ ... }: -{ - services.fprintd.enable = true; - - # Add fingerprint command - # fprintd-enroll - # List fingerprints - # fprintd-list $USER - # Test fingerprint authentication - # fprintd-verify - - security.pam.services = { - login.fprintAuth = true; - - # sudo - sudo.fprintAuth = true; - - # greetd (tuigreet / ReGreet) - greetd.fprintAuth = true; - }; -} \ No newline at end of file diff --git a/modules/core/fonts.nix b/modules/core/fonts.nix deleted file mode 100644 index 466ceb4..0000000 --- a/modules/core/fonts.nix +++ /dev/null @@ -1,29 +0,0 @@ -{ pkgs, ... }: -{ - fonts = { - packages = with pkgs; [ - noto-fonts - noto-fonts-cjk-sans - noto-fonts-color-emoji - terminus_font - cantarell-fonts - font-awesome - nerd-fonts.blex-mono - ]; - - fontDir.enable = true; - fontconfig = { - defaultFonts = { - serif = [ - "Noto Serif CJK JP" - "Noto Color Emoji" - ]; - sansSerif =[ - "Noto Sans CJK JP" - "Noto Clor Emoji" - ]; - emoji = ["Noto Color Emoji"]; - }; - }; - }; -} diff --git a/modules/core/greetd.nix b/modules/core/greetd.nix deleted file mode 100644 index 09ca405..0000000 --- a/modules/core/greetd.nix +++ /dev/null @@ -1,11 +0,0 @@ -{ pkgs, username, ... }: { - services.greetd = { - enable = true; - settings = { - default_session = { - user = "greeter"; - command = "${pkgs.tuigreet}/bin/tuigreet --time --remember --cmd niri-session"; - }; - }; - }; -} diff --git a/modules/core/gui.nix b/modules/core/gui.nix deleted file mode 100644 index 4b0d337..0000000 --- a/modules/core/gui.nix +++ /dev/null @@ -1,8 +0,0 @@ -{ pkgs, ... }: -{ - environment.systemPackages = with pkgs; [ - slack - insomnia - obsidian - ]; -} \ No newline at end of file diff --git a/modules/core/hardware.nix b/modules/core/hardware.nix deleted file mode 100644 index b5a337c..0000000 --- a/modules/core/hardware.nix +++ /dev/null @@ -1,15 +0,0 @@ -{ pkgs, ... }: -{ - hardware = { - sane = { - enable = true; - extraBackends = [ pkgs.sane-airscan ]; - disabledDefaultBackends = [ "escl" ]; - }; - graphics.enable = true; - enableRedistributableFirmware = true; - keyboard.qmk.enable = true; - bluetooth.enable = true; - bluetooth.powerOnBoot = true; - }; -} diff --git a/modules/core/hyprland.nix b/modules/core/hyprland.nix deleted file mode 100644 index f2681cc..0000000 --- a/modules/core/hyprland.nix +++ /dev/null @@ -1,10 +0,0 @@ -{ ... }: -{ - programs = { - hyprland = { - enable = true; - withUWSM = false; - }; - hyprlock.enable = true; - }; -} \ No newline at end of file diff --git a/modules/core/i18n.nix b/modules/core/i18n.nix deleted file mode 100644 index 7d3a526..0000000 --- a/modules/core/i18n.nix +++ /dev/null @@ -1,32 +0,0 @@ -{ pkgs, ... }: -{ - i18n.inputMethod = { - enable = true; - type = "fcitx5"; - fcitx5 = { - addons = with pkgs; [ - fcitx5-mozc - fcitx5-gtk - qt6Packages.fcitx5-configtool - ]; - settings.inputMethod = { - GroupOrder = { - "0" = "Default"; - }; - "Groups/0" = { - Name = "Default"; - "Default Layout" = "keyboard-jp"; - DefaultIM = "mozc"; - }; - "Groups/0/Items/0" = { - Name = "keyboard-jp"; - Layout = ""; - }; - "Groups/0/Items/1" = { - Name = "mozc"; - Layout = ""; - }; - }; - }; - }; -} \ No newline at end of file diff --git a/modules/core/kde.nix b/modules/core/kde.nix deleted file mode 100644 index dd5f20c..0000000 --- a/modules/core/kde.nix +++ /dev/null @@ -1,6 +0,0 @@ -{...}: { - programs.kdeconnect = { - enable = true; - }; -} - diff --git a/modules/core/network.nix b/modules/core/network.nix deleted file mode 100644 index 41400ee..0000000 --- a/modules/core/network.nix +++ /dev/null @@ -1,39 +0,0 @@ -{ - host, - pkgs, - ... -}: { - networking = { - hostName = "${host}"; - nameservers = [ - "1.1.1.1" - "1.0.0.1" - ]; - - networkmanager = { - enable = true; - dns = "none"; - wifi.powersave = false; - wifi.backend = "wpa_supplicant"; - settings = { - "device"."wifi.scan-rand-mac-address" = "no"; - "connection"."wifi.cloned-mac-address" = "permanent"; - }; - }; - - wireless.iwd.enable = false; - }; - - boot.extraModprobeConfig = '' - options cfg80211 ieee80211_regdom=JP - options iwlwifi power_save=0 - options iwlwifi uapsd_disable=1 - ''; - - services.resolved.enable = false; - - environment.systemPackages = [pkgs.networkmanagerapplet]; - programs.nm-applet.enable = true; - - security.pki.certificateFiles = [./ca/root_ca.crt]; -} diff --git a/modules/core/niri.nix b/modules/core/niri.nix deleted file mode 100644 index 6e16b96..0000000 --- a/modules/core/niri.nix +++ /dev/null @@ -1,6 +0,0 @@ -{ pkgs, ... }: -{ - programs.niri = { - enable = true; - }; -} \ No newline at end of file diff --git a/modules/core/noctalia.nix b/modules/core/noctalia.nix deleted file mode 100644 index 48eb326..0000000 --- a/modules/core/noctalia.nix +++ /dev/null @@ -1,6 +0,0 @@ -{ pkgs, inputs, ... }: -{ - environment.systemPackages = with pkgs; [ - inputs.noctalia.packages.${system}.default - ]; -} \ No newline at end of file diff --git a/modules/core/packages.nix b/modules/core/packages.nix deleted file mode 100644 index 9210bee..0000000 --- a/modules/core/packages.nix +++ /dev/null @@ -1,68 +0,0 @@ -{ - pkgs, - inputs, - ... -}: let - unstable = import inputs.nixpkgs-unstable { - system = pkgs.system; - config = { - allowUnfree = true; - }; - }; -in { - programs = { - xwayland.enable = true; - dconf.enable = true; - seahorse.enable = true; - fuse.userAllowOther = true; - adb.enable = true; - gnupg.agent = { - enable = true; - enableSSHSupport = false; - }; - zsh = { - enable = true; - }; - java.enable = true; - java.package = pkgs.jdk25; - }; - - nixpkgs.config.allowUnfree = true; - - environment.systemPackages = with pkgs; [ - tuigreet # The Login Manager (Sometimes Referred To As Display Manager) - htop - btop # Simple Terminal Based System Monitor - unrar # Tool For Handling .rar Files - unzip # Tool For Handling .zip Files - uwsm # Universal Wayland Session Manager (optional must be enabled) - wget # Tool For Fetching Files With Links - curl # Tool For Fetching Files With Links - alacritty # A GPU Accelerated Terminal Emulator - fuzzel # A Simple And Lightweight Application Launcher - git # Version Control System - tailscale # Zero-Config VPN - unstable.msedit # Microsoft Editor - nil # Nix Language Server - docker # Containerization Platform - unstable._1password-cli - unstable._1password-gui - unstable.ghostty - tio - sbctl - xwayland-satellite - slurp - grim - wf-recorder - sqlite # Vscode Raycast Extension Dependency - oxker # Docker TUI Tool - jdk25 - maven - gradle - python312 - uv - bun - unstable.claude-code - unstable.codex - ]; -} diff --git a/modules/core/power.nix b/modules/core/power.nix deleted file mode 100644 index df3b17c..0000000 --- a/modules/core/power.nix +++ /dev/null @@ -1,14 +0,0 @@ -{...}: { - boot.kernelParams = [ - "mem_sleep_default=deep" - ]; - - powerManagement = { - enable = true; - powertop.enable = true; - }; - - services.power-profiles-daemon.enable = true; - services.tlp.enable = false; - services.upower.enable = true; -} diff --git a/modules/core/secure-boot.nix b/modules/core/secure-boot.nix deleted file mode 100644 index fa89542..0000000 --- a/modules/core/secure-boot.nix +++ /dev/null @@ -1,17 +0,0 @@ -{ inputs, pkgs, lib, ... }: -{ - imports = [ - inputs.lanzaboote.nixosModules.lanzaboote - ]; - - boot.loader = { - systemd-boot.enable = lib.mkForce false; - efi.canTouchEfiVariables = true; - efi.efiSysMountPoint = "/boot"; - }; - - boot.lanzaboote = { - enable = true; - pkiBundle = "/var/lib/sbctl"; - }; -} \ No newline at end of file diff --git a/modules/core/services.nix b/modules/core/services.nix deleted file mode 100644 index fa72590..0000000 --- a/modules/core/services.nix +++ /dev/null @@ -1,76 +0,0 @@ -{pkgs, ...}: { - services = { - blueman.enable = true; # Bluetooth Support - tumbler.enable = true; # Image/video preview - - fwupd.enable = true; - - gnome.gnome-keyring.enable = true; - - upower.enable = true; - - tailscale = { - enable = true; - extraUpFlags = [ - "--accept-dns=false" - "--accept-routes" - ]; - }; - - pipewire = { - enable = true; - alsa.enable = true; - alsa.support32Bit = true; - pulse.enable = true; - jack.enable = true; - wireplumber.enable = true; - }; - - logind = { - settings.Login = { - HandleLidSwitch = "suspend"; - HandleLidSwitchDocked = "ignore"; - HandleLidSwitchExternalPower = "suspend"; - LidSwitchIgnoreInhibited = "no"; - }; - }; - - rpcbind.enable = true; - }; - - virtualisation.docker = { - enable = true; - autoPrune = { - enable = true; - dates = "weekly"; - }; - daemon.settings = { - ipv6 = true; - "fixed-cidr-v6" = "fd00:30::/64"; - ip6tables = true; - }; - }; - - programs.nix-ld.enable = true; - security.rtkit.enable = true; - - xdg.portal = { - enable = true; - wlr.enable = true; - extraPortals = [ - pkgs.xdg-desktop-portal-wlr - pkgs.xdg-desktop-portal-gtk - ]; - xdgOpenUsePortal = true; - config = { - common.default = [ - "wlr" - "gtk" - ]; - niri.default = [ - "wlr" - "gtk" - ]; - }; - }; -} diff --git a/modules/core/ssh.nix b/modules/core/ssh.nix deleted file mode 100644 index 64851f7..0000000 --- a/modules/core/ssh.nix +++ /dev/null @@ -1,24 +0,0 @@ -{ pkgs, ... }: -{ - - services.openssh = { - enable = true; - openFirewall = true; - - settings = { - PermitRootLogin = "no"; - PasswordAuthentication = false; - KbdInteractiveAuthentication = false; - PubkeyAuthentication = "yes"; - }; - }; - - users.users.moons = { - - openssh.authorizedKeys.keys = [ - "sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIKhxDkucmeCor6CKoXAua7DgDSzuXrZOtpdkyzQxz5+aAAAABHNzaDo= moons@moons14.com" - "sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIN6hZJyng/5LgFKPjR6uZAd/00UkO0vN0uQOoIvfSELdAAAABHNzaDo= moons@moons14.com" - ]; - }; - -} diff --git a/modules/core/user.nix b/modules/core/user.nix deleted file mode 100644 index e052c8d..0000000 --- a/modules/core/user.nix +++ /dev/null @@ -1,38 +0,0 @@ -{ pkgs, inputs, username, host, profile, ...}: -{ - imports = [ inputs.home-manager.nixosModules.home-manager ]; - home-manager = { - useUserPackages = true; - useGlobalPkgs = false; - backupFileExtension = "backup"; - extraSpecialArgs = { inherit inputs username host profile; }; - users.moons = { - imports = [ ./../home ]; - home = { - username = "moons"; - homeDirectory = "/home/moons"; - stateVersion = "25.11"; - }; - }; - }; - users.mutableUsers = true; - users.users.moons = { - isNormalUser = true; - description = "moons-14"; - extraGroups = [ - "adbusers" - "docker" #access to docker as non-root - "libvirtd" #Virt manager/QEMU access - "lp" - "networkmanager" - "scanner" - "wheel" #subdo access - "vboxusers" #Virtual Box - "dialout" #Serial Port Access - ]; - shell = pkgs.zsh; - ignoreShellProgramCheck = true; - }; - nix.settings.allowed-users = [ "moons" ]; - nix.settings.trusted-users = [ "root" "moons" ]; -} diff --git a/modules/core/xserver.nix b/modules/core/xserver.nix deleted file mode 100644 index c21bdbc..0000000 --- a/modules/core/xserver.nix +++ /dev/null @@ -1,13 +0,0 @@ -{ ... }: -{ - services = { - xserver = { - enable = true; - xkb = { - layout = "jp"; - variant = ""; - options = "ctrl:nocaps"; - }; - }; - }; -} \ No newline at end of file diff --git a/modules/default.nix b/modules/default.nix new file mode 100644 index 0000000..b8ff541 --- /dev/null +++ b/modules/default.nix @@ -0,0 +1,9 @@ +{ + imports = [ + ./applications + ./drivers + ./features + ./integrations + ./system + ]; +} diff --git a/modules/drivers/default.nix b/modules/drivers/default.nix new file mode 100644 index 0000000..812230f --- /dev/null +++ b/modules/drivers/default.nix @@ -0,0 +1,5 @@ +{ + imports = [ + ./intel-drivers.nix + ]; +} diff --git a/modules/drivers/intel-drivers.nix b/modules/drivers/intel-drivers.nix index bb8cc83..b0d5383 100644 --- a/modules/drivers/intel-drivers.nix +++ b/modules/drivers/intel-drivers.nix @@ -1,20 +1,24 @@ -{ lib, pkgs, config, ... }: -with lib; let - cfg = config.drivers.intel; +{ + lib, + pkgs, + config, + ... +}: +let + cfg = config.my.drivers.intel; in { - options.drivers.intel = { - enable = mkEnableOption "Enable Intel Graphics Drivers"; + options.my.drivers.intel = { + enable = lib.mkEnableOption "Intel Graphics Drivers"; }; - config = mkIf cfg.enable { - # OpenGL + config = lib.mkIf cfg.enable { hardware.graphics = { extraPackages = with pkgs; [ - intel-media-driver - vaapiIntel - vaapiVdpau - libvdpau-va-gl + intel-media-driver # Intel Media Driver for VA-API + intel-vaapi-driver # VA-API Intel driver + libva-vdpau-driver # VA-API to VDPAU adapter + libvdpau-va-gl # VDPAU driver with OpenGL/VAAPI backend ]; }; }; diff --git a/modules/features/application/browser.nix b/modules/features/application/browser.nix new file mode 100644 index 0000000..221de91 --- /dev/null +++ b/modules/features/application/browser.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.application.browser; +in +{ + options.my.features.application.browser = { + enable = lib.mkEnableOption "Web browser (Chrome)"; + }; + + config = lib.mkIf cfg.enable { + my.applications.chrome.enable = true; + }; +} diff --git a/modules/features/application/communication.nix b/modules/features/application/communication.nix new file mode 100644 index 0000000..edd2036 --- /dev/null +++ b/modules/features/application/communication.nix @@ -0,0 +1,17 @@ +{ lib, config, ... }: +let + cfg = config.my.features.application.communication; +in +{ + options.my.features.application.communication = { + enable = lib.mkEnableOption "Communication applications (Discord, Zoom, Slack)"; + }; + + config = lib.mkIf cfg.enable { + my.applications = { + discord.enable = true; + zoom.enable = true; + slack.enable = true; + }; + }; +} diff --git a/modules/features/application/default.nix b/modules/features/application/default.nix new file mode 100644 index 0000000..3e2d7e0 --- /dev/null +++ b/modules/features/application/default.nix @@ -0,0 +1,6 @@ +{ + imports = [ + ./browser.nix + ./communication.nix + ]; +} diff --git a/modules/features/boot/default.nix b/modules/features/boot/default.nix new file mode 100644 index 0000000..22e06ea --- /dev/null +++ b/modules/features/boot/default.nix @@ -0,0 +1,8 @@ +{ + imports = [ + ./power.nix + ./secure-boot.nix + ./storage-crypto.nix + ./uefi.nix + ]; +} diff --git a/modules/features/boot/power.nix b/modules/features/boot/power.nix new file mode 100644 index 0000000..7cc0a83 --- /dev/null +++ b/modules/features/boot/power.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.boot.power; +in +{ + options.my.features.boot.power = { + enable = lib.mkEnableOption "Power management"; + }; + + config = lib.mkIf cfg.enable { + my.system.power.enable = true; + }; +} diff --git a/modules/features/boot/secure-boot.nix b/modules/features/boot/secure-boot.nix new file mode 100644 index 0000000..28f90cd --- /dev/null +++ b/modules/features/boot/secure-boot.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.boot.secureBoot; +in +{ + options.my.features.boot.secureBoot = { + enable = lib.mkEnableOption "Secure boot (lanzaboote)"; + }; + + config = lib.mkIf cfg.enable { + my.system.secure-boot.enable = true; + }; +} diff --git a/modules/features/boot/storage-crypto.nix b/modules/features/boot/storage-crypto.nix new file mode 100644 index 0000000..d4f41b8 --- /dev/null +++ b/modules/features/boot/storage-crypto.nix @@ -0,0 +1,30 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.features.boot.storageCrypto; +in +{ + options.my.features.boot.storageCrypto = { + enable = lib.mkEnableOption "LUKS decryption via TPM2"; + }; + + config = lib.mkIf cfg.enable { + boot.initrd.systemd.enable = true; + + boot.initrd.luks.devices.cryptroot = { + crypttabExtraOpts = [ + "tpm2-device=auto" + ]; + }; + + security.tpm2.enable = true; + + environment.systemPackages = with pkgs; [ + tpm2-tools # TPM2 management tools + ]; + }; +} diff --git a/modules/features/boot/uefi.nix b/modules/features/boot/uefi.nix new file mode 100644 index 0000000..b12c228 --- /dev/null +++ b/modules/features/boot/uefi.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.boot.uefi; +in +{ + options.my.features.boot.uefi = { + enable = lib.mkEnableOption "UEFI boot support"; + }; + + config = lib.mkIf cfg.enable { + my.system.boot.uefi.enable = true; + }; +} diff --git a/modules/features/cli/base.nix b/modules/features/cli/base.nix new file mode 100644 index 0000000..d31374d --- /dev/null +++ b/modules/features/cli/base.nix @@ -0,0 +1,35 @@ +{ + lib, + config, + pkgs, + ... +}: +let + cfg = config.my.features.cli.base; +in +{ + options.my.features.cli.base = { + enable = lib.mkEnableOption "Base CLI configuration"; + sshServer = lib.mkEnableOption "OpenSSH server"; + }; + + config = lib.mkIf cfg.enable { + my.applications = { + btop.enable = true; + git.enable = true; + ssh.enable = true; + direnv.enable = true; + gnupg.enable = true; + nh.enable = true; + openssh.enable = cfg.sshServer; + }; + + environment.systemPackages = with pkgs; [ + htop # Interactive Process Viewer + curl # Tool For Fetching Files With Links + wget # Tool For Fetching Files With Links + unzip # Tool For Handling .zip Files + unrar # Tool For Handling .rar Files + ]; + }; +} diff --git a/modules/features/cli/default.nix b/modules/features/cli/default.nix new file mode 100644 index 0000000..1a2a937 --- /dev/null +++ b/modules/features/cli/default.nix @@ -0,0 +1,7 @@ +{ + imports = [ + ./base.nix + ./interactive.nix + ./shell.nix + ]; +} diff --git a/modules/features/cli/interactive.nix b/modules/features/cli/interactive.nix new file mode 100644 index 0000000..0aa5699 --- /dev/null +++ b/modules/features/cli/interactive.nix @@ -0,0 +1,25 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.features.cli.interactive; +in +{ + options.my.features.cli.interactive = { + enable = lib.mkEnableOption "Interactive CLI tools (vim, btop, zellij)"; + }; + + config = lib.mkIf cfg.enable { + my.applications = { + vim.enable = true; + zellij.enable = true; + }; + + environment.systemPackages = with pkgs; [ + tio # A Simple TTY Terminal I/O Application + ]; + }; +} diff --git a/modules/features/cli/shell.nix b/modules/features/cli/shell.nix new file mode 100644 index 0000000..533c0e9 --- /dev/null +++ b/modules/features/cli/shell.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.cli.shell; +in +{ + options.my.features.cli.shell = { + enable = lib.mkEnableOption "Shell configuration (zsh)"; + }; + + config = lib.mkIf cfg.enable { + my.applications.zsh.enable = true; + }; +} diff --git a/modules/features/connect/bluetooth.nix b/modules/features/connect/bluetooth.nix new file mode 100644 index 0000000..f0f5cfd --- /dev/null +++ b/modules/features/connect/bluetooth.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.connect.bluetooth; +in +{ + options.my.features.connect.bluetooth = { + enable = lib.mkEnableOption "Bluetooth support"; + }; + + config = lib.mkIf cfg.enable { + my.system.hardware.bluetooth.enable = true; + }; +} diff --git a/modules/features/connect/default.nix b/modules/features/connect/default.nix new file mode 100644 index 0000000..412300c --- /dev/null +++ b/modules/features/connect/default.nix @@ -0,0 +1,6 @@ +{ + imports = [ + ./bluetooth.nix + ./wifi.nix + ]; +} diff --git a/modules/features/connect/wifi.nix b/modules/features/connect/wifi.nix new file mode 100644 index 0000000..e78e9aa --- /dev/null +++ b/modules/features/connect/wifi.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.connect.wifi; +in +{ + options.my.features.connect.wifi = { + enable = lib.mkEnableOption "WiFi (NetworkManager) support"; + }; + + config = lib.mkIf cfg.enable { + my.system.network.wifi.enable = true; + }; +} diff --git a/modules/features/default.nix b/modules/features/default.nix new file mode 100644 index 0000000..b3aa070 --- /dev/null +++ b/modules/features/default.nix @@ -0,0 +1,14 @@ +{ + imports = [ + ./application + ./boot + ./cli + ./connect + ./dev + ./gui + ./identity + ./network + ./services + ./storage + ]; +} diff --git a/modules/features/dev/agent.nix b/modules/features/dev/agent.nix new file mode 100644 index 0000000..1ad04f2 --- /dev/null +++ b/modules/features/dev/agent.nix @@ -0,0 +1,21 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.features.dev.agent; +in +{ + options.my.features.dev.agent = { + enable = lib.mkEnableOption "AI coding agents (Claude Code, Codex, OpenCode)"; + }; + + config = lib.mkIf cfg.enable { + my.applications = { + claude.enable = true; + # codex.enable = true; + opencode.enable = true; + }; + }; +} diff --git a/modules/features/dev/arduino.nix b/modules/features/dev/arduino.nix new file mode 100644 index 0000000..9cc2c8a --- /dev/null +++ b/modules/features/dev/arduino.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.dev.arduino; +in +{ + options.my.features.dev.arduino = { + enable = lib.mkEnableOption "Arduino development environment"; + }; + + config = lib.mkIf cfg.enable { + my.applications.arduino.enable = true; + }; +} diff --git a/modules/features/dev/bun.nix b/modules/features/dev/bun.nix new file mode 100644 index 0000000..706e021 --- /dev/null +++ b/modules/features/dev/bun.nix @@ -0,0 +1,20 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.features.dev.bun; +in +{ + options.my.features.dev.bun = { + enable = lib.mkEnableOption "Bun JavaScript runtime"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + bun # A Fast JavaScript Runtime Like Node.js And Deno + ]; + }; +} diff --git a/modules/features/dev/default.nix b/modules/features/dev/default.nix new file mode 100644 index 0000000..6d2893a --- /dev/null +++ b/modules/features/dev/default.nix @@ -0,0 +1,10 @@ +{ + imports = [ + ./agent.nix + ./arduino.nix + ./bun.nix + ./java.nix + ./nix.nix + ./python.nix + ]; +} diff --git a/modules/features/dev/java.nix b/modules/features/dev/java.nix new file mode 100644 index 0000000..2b532e9 --- /dev/null +++ b/modules/features/dev/java.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.dev.java; +in +{ + options.my.features.dev.java = { + enable = lib.mkEnableOption "Java development environment"; + }; + + config = lib.mkIf cfg.enable { + my.applications.java.enable = true; + }; +} diff --git a/modules/features/dev/nix.nix b/modules/features/dev/nix.nix new file mode 100644 index 0000000..195670a --- /dev/null +++ b/modules/features/dev/nix.nix @@ -0,0 +1,20 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.features.dev.nix; +in +{ + options.my.features.dev.nix = { + enable = lib.mkEnableOption "Nix development tools (nil language server)"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + nil # Nix Language Server + ]; + }; +} diff --git a/modules/features/dev/python.nix b/modules/features/dev/python.nix new file mode 100644 index 0000000..9da0595 --- /dev/null +++ b/modules/features/dev/python.nix @@ -0,0 +1,23 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.features.dev.python; +in +{ + options.my.features.dev.python = { + enable = lib.mkEnableOption "Python development environment"; + }; + + config = lib.mkIf cfg.enable { + documentation.doc.enable = false; + + environment.systemPackages = with pkgs; [ + python312 # Python 3.12 + uv # Universal Virtual Environment Manager For Python + ]; + }; +} diff --git a/modules/features/gui/audio.nix b/modules/features/gui/audio.nix new file mode 100644 index 0000000..d966cd8 --- /dev/null +++ b/modules/features/gui/audio.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.gui.audio; +in +{ + options.my.features.gui.audio = { + enable = lib.mkEnableOption "Audio support (PipeWire)"; + }; + + config = lib.mkIf cfg.enable { + my.system.audio.enable = true; + }; +} diff --git a/modules/features/gui/camera.nix b/modules/features/gui/camera.nix new file mode 100644 index 0000000..3236dd9 --- /dev/null +++ b/modules/features/gui/camera.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.gui.camera; +in +{ + options.my.features.gui.camera = { + enable = lib.mkEnableOption "Camera support"; + }; + + config = lib.mkIf cfg.enable { + my.system.camera.enable = true; + }; +} diff --git a/modules/features/gui/capture.nix b/modules/features/gui/capture.nix new file mode 100644 index 0000000..c0377dc --- /dev/null +++ b/modules/features/gui/capture.nix @@ -0,0 +1,22 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.features.gui.capture; +in +{ + options.my.features.gui.capture = { + enable = lib.mkEnableOption "Screen capture tools (slurp, grim, wf-recorder)"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = with pkgs; [ + slurp # Tool for selecting a region of the screen + grim # Screenshot tool for Wayland + wf-recorder # Screen recorder for Wayland + ]; + }; +} diff --git a/modules/features/gui/default.nix b/modules/features/gui/default.nix new file mode 100644 index 0000000..63b1199 --- /dev/null +++ b/modules/features/gui/default.nix @@ -0,0 +1,13 @@ +{ + imports = [ + ./audio.nix + ./camera.nix + ./capture.nix + ./desktop.nix + ./editor.nix + ./file-manager.nix + ./graphic.nix + ./jp-input.nix + ./terminal.nix + ]; +} diff --git a/modules/features/gui/desktop.nix b/modules/features/gui/desktop.nix new file mode 100644 index 0000000..c24de7f --- /dev/null +++ b/modules/features/gui/desktop.nix @@ -0,0 +1,28 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.features.gui.desktop; +in +{ + options.my.features.gui.desktop = { + enable = lib.mkEnableOption "Niri Wayland compositor environment"; + }; + + config = lib.mkIf cfg.enable { + my.applications = { + gtk.enable = true; + niri.enable = true; + wayland.enable = true; + greetd.enable = true; + noctalia.enable = true; + swayidle.enable = true; + vicinae.enable = true; + }; + my.system = { + fonts.enable = true; + }; + }; +} diff --git a/modules/features/gui/editor.nix b/modules/features/gui/editor.nix new file mode 100644 index 0000000..e10c20d --- /dev/null +++ b/modules/features/gui/editor.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.gui.editor; +in +{ + options.my.features.gui.editor = { + enable = lib.mkEnableOption "GUI code editor (VSCode)"; + }; + + config = lib.mkIf cfg.enable { + my.applications.vscode.enable = true; + }; +} diff --git a/modules/features/gui/file-manager.nix b/modules/features/gui/file-manager.nix new file mode 100644 index 0000000..50996cd --- /dev/null +++ b/modules/features/gui/file-manager.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.gui.fileManager; +in +{ + options.my.features.gui.fileManager = { + enable = lib.mkEnableOption "File manager (Nautilus)"; + }; + + config = lib.mkIf cfg.enable { + my.applications.nautilus.enable = true; + }; +} diff --git a/modules/features/gui/graphic.nix b/modules/features/gui/graphic.nix new file mode 100644 index 0000000..28eaecd --- /dev/null +++ b/modules/features/gui/graphic.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.gui.graphic; +in +{ + options.my.features.gui.graphic = { + enable = lib.mkEnableOption "GPU/graphics hardware acceleration"; + }; + + config = lib.mkIf cfg.enable { + my.system.hardware.gui.enable = true; + }; +} diff --git a/modules/features/gui/jp-input.nix b/modules/features/gui/jp-input.nix new file mode 100644 index 0000000..864f503 --- /dev/null +++ b/modules/features/gui/jp-input.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.gui.jpInput; +in +{ + options.my.features.gui.jpInput = { + enable = lib.mkEnableOption "Japanese input method (fcitx5)"; + }; + + config = lib.mkIf cfg.enable { + my.applications.fcitx5.enable = true; + }; +} diff --git a/modules/features/gui/terminal.nix b/modules/features/gui/terminal.nix new file mode 100644 index 0000000..85e4e5a --- /dev/null +++ b/modules/features/gui/terminal.nix @@ -0,0 +1,22 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.features.gui.terminal; +in +{ + options.my.features.gui.terminal = { + enable = lib.mkEnableOption "Terminal emulators (Ghostty, Alacritty)"; + }; + + config = lib.mkIf cfg.enable { + my.applications.ghostty.enable = true; + + environment.systemPackages = with pkgs; [ + alacritty # A GPU Accelerated Terminal Emulator + ]; + }; +} diff --git a/modules/features/identity/default.nix b/modules/features/identity/default.nix new file mode 100644 index 0000000..1f694c3 --- /dev/null +++ b/modules/features/identity/default.nix @@ -0,0 +1,6 @@ +{ + imports = [ + ./fingerprint.nix + ./ssh-default-key.nix + ]; +} diff --git a/modules/features/identity/fingerprint.nix b/modules/features/identity/fingerprint.nix new file mode 100644 index 0000000..b1d135e --- /dev/null +++ b/modules/features/identity/fingerprint.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.identity.fingerprint; +in +{ + options.my.features.identity.fingerprint = { + enable = lib.mkEnableOption "Fingerprint authentication"; + }; + + config = lib.mkIf cfg.enable { + my.system.fingerprint.enable = true; + }; +} diff --git a/modules/features/identity/ssh-default-key.nix b/modules/features/identity/ssh-default-key.nix new file mode 100644 index 0000000..eeef32b --- /dev/null +++ b/modules/features/identity/ssh-default-key.nix @@ -0,0 +1,34 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.features.identity.sshDefaultKey; +in +{ + options.my.features.identity.sshDefaultKey = { + enable = lib.mkEnableOption "Generate default SSH key (ed25519)"; + }; + + config.home-manager.sharedModules = [ + ( + { lib, ... }: + { + config = lib.mkIf cfg.enable { + home.activation.generateSshKey = lib.hm.dag.entryAfter [ "writeBoundary" ] '' + key="$HOME/.ssh/id_ed25519" + if [ ! -f "$key" ]; then + umask 077 + mkdir -p "$HOME/.ssh" + ${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \ + -C "moons@$(${pkgs.hostname}/bin/hostname || echo host)" + echo "Generated SSH key at $key" + fi + ''; + }; + } + ) + ]; +} diff --git a/modules/features/network/default.nix b/modules/features/network/default.nix new file mode 100644 index 0000000..1f59251 --- /dev/null +++ b/modules/features/network/default.nix @@ -0,0 +1,5 @@ +{ + imports = [ + ./tailscale.nix + ]; +} diff --git a/modules/features/network/tailscale.nix b/modules/features/network/tailscale.nix new file mode 100644 index 0000000..495e5aa --- /dev/null +++ b/modules/features/network/tailscale.nix @@ -0,0 +1,31 @@ +{ lib, config, ... }: +let + cfg = config.my.features.network.tailscale; +in +{ + options.my.features.network.tailscale = { + enable = lib.mkEnableOption "Tailscale VPN"; + acceptDns = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Accept DNS configuration from Tailscale"; + }; + acceptRoutes = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Accept subnet routes from Tailscale"; + }; + extraUpFlags = lib.mkOption { + type = lib.types.listOf lib.types.str; + default = [ ]; + description = "Additional flags to pass to tailscale up"; + }; + }; + + config = lib.mkIf cfg.enable { + my.applications.tailscale = { + enable = true; + inherit (cfg) acceptDns acceptRoutes extraUpFlags; + }; + }; +} diff --git a/modules/features/services/container.nix b/modules/features/services/container.nix new file mode 100644 index 0000000..c26435b --- /dev/null +++ b/modules/features/services/container.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.services.container; +in +{ + options.my.features.services.container = { + enable = lib.mkEnableOption "Container runtime (Docker)"; + }; + + config = lib.mkIf cfg.enable { + my.applications.docker.enable = true; + }; +} diff --git a/modules/features/services/default.nix b/modules/features/services/default.nix new file mode 100644 index 0000000..e4e39fa --- /dev/null +++ b/modules/features/services/default.nix @@ -0,0 +1,6 @@ +{ + imports = [ + ./container.nix + ./kde.nix + ]; +} diff --git a/modules/features/services/kde.nix b/modules/features/services/kde.nix new file mode 100644 index 0000000..1c5bcff --- /dev/null +++ b/modules/features/services/kde.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.services.kde; +in +{ + options.my.features.services.kde = { + enable = lib.mkEnableOption "KDE Connect"; + }; + + config = lib.mkIf cfg.enable { + my.applications.kde.enable = true; + }; +} diff --git a/modules/features/storage/default.nix b/modules/features/storage/default.nix new file mode 100644 index 0000000..0b3cf91 --- /dev/null +++ b/modules/features/storage/default.nix @@ -0,0 +1,5 @@ +{ + imports = [ + ./nfs-client.nix + ]; +} diff --git a/modules/features/storage/nfs-client.nix b/modules/features/storage/nfs-client.nix new file mode 100644 index 0000000..5a92e2f --- /dev/null +++ b/modules/features/storage/nfs-client.nix @@ -0,0 +1,13 @@ +{ lib, config, ... }: +let + cfg = config.my.features.storage.nfsClient; +in +{ + options.my.features.storage.nfsClient = { + enable = lib.mkEnableOption "NFS client support"; + }; + + config = lib.mkIf cfg.enable { + my.system.boot.nfs.enable = true; + }; +} diff --git a/modules/home/avatar.nix b/modules/home/avatar.nix deleted file mode 100644 index f57ef45..0000000 --- a/modules/home/avatar.nix +++ /dev/null @@ -1,7 +0,0 @@ -{ ... }: -{ - home.file.".face" = { - recursive = true; - source = ./../../images/avatar.jpg; - }; -} \ No newline at end of file diff --git a/modules/home/browser.nix b/modules/home/browser.nix deleted file mode 100644 index ed5cfe6..0000000 --- a/modules/home/browser.nix +++ /dev/null @@ -1,26 +0,0 @@ -{ pkgs, ... }: - -{ - nixpkgs.config.allowUnfree = true; - - home.packages = with pkgs; [ - google-chrome - ]; - - xdg.desktopEntries."google-chrome" = { - name = "Google Chrome"; - genericName = "Web Browser"; - exec = "${pkgs.google-chrome}/bin/google-chrome-stable --enable-features=TouchpadOverscrollHistoryNavigation %U"; - terminal = false; - icon = "google-chrome"; - categories = [ "Network" "WebBrowser" ]; - startupNotify = true; - type = "Application"; - }; - - xdg.mimeApps.defaultApplications = { - "text/html" = "google-chrome.desktop"; - "x-scheme-handler/http" = "google-chrome.desktop"; - "x-scheme-handler/https" = "google-chrome.desktop"; - }; -} diff --git a/modules/home/btop/default.nix b/modules/home/btop/default.nix deleted file mode 100644 index 106d982..0000000 --- a/modules/home/btop/default.nix +++ /dev/null @@ -1,12 +0,0 @@ -{ ... }: -{ - programs = { - btop = { - enable = true; - settings.color_theme = "dracula"; - themes = { - dracula = builtins.readFile ./dracula.theme; - }; - }; - }; -} \ No newline at end of file diff --git a/modules/home/claude.nix b/modules/home/claude.nix deleted file mode 100644 index f0c9735..0000000 --- a/modules/home/claude.nix +++ /dev/null @@ -1,9 +0,0 @@ -{...}: { - home.file.".claude/settings.json".text = builtins.toJSON { - statusLine = { - type = "command"; - command = "bun x ccusage statusline --no-offline"; - padding = 0; - }; - }; -} diff --git a/modules/home/default.nix b/modules/home/default.nix deleted file mode 100644 index 3f5c4a9..0000000 --- a/modules/home/default.nix +++ /dev/null @@ -1,13 +0,0 @@ -{...}: { - imports = [ - ./btop - ./git.nix - ./fcitx5 - ./ssh.nix - ./nixvim - ./zsh.nix - ./environment.nix - ./zellij.nix - ./claude.nix - ]; -} diff --git a/modules/home/discord.nix b/modules/home/discord.nix deleted file mode 100644 index 2220975..0000000 --- a/modules/home/discord.nix +++ /dev/null @@ -1,6 +0,0 @@ -{ ... }: -{ - programs.vesktop = { - enable = true; - }; -} \ No newline at end of file diff --git a/modules/home/environment.nix b/modules/home/environment.nix deleted file mode 100644 index 7ce78b9..0000000 --- a/modules/home/environment.nix +++ /dev/null @@ -1,7 +0,0 @@ -{ - # use project directory: `echo 'use flake ~/dotfiles#next-web' > .envrc` - programs.direnv = { - enable = true; - nix-direnv.enable = true; - }; -} diff --git a/modules/home/fcitx5/default.nix b/modules/home/fcitx5/default.nix deleted file mode 100644 index c7cf1e1..0000000 --- a/modules/home/fcitx5/default.nix +++ /dev/null @@ -1,7 +0,0 @@ -{ ... }: -{ - home.file.".config/fcitx5/config" = { - recursive = true; - source = ./config; - }; -} \ No newline at end of file diff --git a/modules/home/ghostty/default.nix b/modules/home/ghostty/default.nix deleted file mode 100644 index cc6c658..0000000 --- a/modules/home/ghostty/default.nix +++ /dev/null @@ -1,13 +0,0 @@ -{ ... }: -{ - - home.file.".config/ghostty/config" = { - recursive = true; - source = ./config; - }; - - home.file.".config/ghostty/themes/dracula" = { - recursive = true; - source = ./dracula.theme; - }; -} \ No newline at end of file diff --git a/modules/home/git.nix b/modules/home/git.nix deleted file mode 100644 index 1f6d84f..0000000 --- a/modules/home/git.nix +++ /dev/null @@ -1,32 +0,0 @@ -{ host, ... }: -{ - programs.git = { - enable = true; - ignores = [ - ".direnv/" - ".envrc" - "!.envrc.example" - ]; - - settings = { - user.name = "moons-14"; - user.email = "moons@moons14.com"; - push.default = "simple"; - credential.helper = "cache --timeout=7200"; - init.defaultBranch = "main"; - log.decorate = "full"; - log.date = "iso"; - merge.conflictStyle = "diff3"; - alias = { - br = "branch --sort=-committerdate"; - co = "checkout"; - df = "diff"; - com = "commit -a"; - gs = "stash"; - gp = "pull"; - lg = "log --graph --pretty=format:'%Cred%h%Creset - %C(yellow)%d%Creset %s %C(green)(%cr)%C(bold blue) <%an>%Creset' --abbrev-commit"; - st = "status"; - }; - }; - }; -} diff --git a/modules/home/gtk.nix b/modules/home/gtk.nix deleted file mode 100644 index 235ef58..0000000 --- a/modules/home/gtk.nix +++ /dev/null @@ -1,18 +0,0 @@ -{ pkgs, ... }: -{ - gtk = { - enable = true; - theme = { - name = "Dracula"; - package = pkgs.dracula-theme; - }; - cursorTheme = { - package = pkgs.adwaita-icon-theme; - name = "Adwaita"; - }; - iconTheme = { - package = pkgs.papirus-icon-theme; - name = "Papirus-Dark"; - }; - }; -} \ No newline at end of file diff --git a/modules/home/lock.nix b/modules/home/lock.nix deleted file mode 100644 index 4322151..0000000 --- a/modules/home/lock.nix +++ /dev/null @@ -1,34 +0,0 @@ -{ pkgs, lib, inputs, ... }: - -let - noctaliaPkg = inputs.noctalia.packages.${pkgs.system}.default; - noctaliaExe = lib.getExe noctaliaPkg; - - lockCmd = "${pkgs.bash}/bin/bash -lc '${noctaliaExe} ipc call lockScreen lock'"; - lockAndSuspendCmd = "${pkgs.bash}/bin/bash -lc '${noctaliaExe} ipc call sessionMenu lockAndSuspend'"; - - dpmsOff = "${pkgs.niri}/bin/niri msg action power-off-monitors"; - dpmsOn = "${pkgs.niri}/bin/niri msg action power-on-monitors"; -in -{ - services.swayidle = { - enable = true; - systemdTarget = "graphical-session.target"; - - timeouts = [ - { timeout = 300; command = lockAndSuspendCmd; } - ]; - - events = [ - { event = "lock"; command = lockCmd; } - { event = "before-sleep"; command = lockCmd; } - { event = "after-resume"; command = dpmsOn; } - ]; - }; - - systemd.user.services.swayidle = { - Service = { - PassEnvironment = [ "WAYLAND_DISPLAY" "XDG_RUNTIME_DIR" "DBUS_SESSION_BUS_ADDRESS" ]; - }; - }; -} diff --git a/modules/home/nautilus.nix b/modules/home/nautilus.nix deleted file mode 100644 index d3c5d01..0000000 --- a/modules/home/nautilus.nix +++ /dev/null @@ -1,9 +0,0 @@ -{ pkgs, ... }: -{ - home.packages = with pkgs; [ - nautilus - gvfs sushi - ]; - - -} diff --git a/modules/home/niri/default.nix b/modules/home/niri/default.nix deleted file mode 100644 index 1dbc2bd..0000000 --- a/modules/home/niri/default.nix +++ /dev/null @@ -1,147 +0,0 @@ -{ - inputs, - pkgs, - ... -}: let - defaultKeyBind = import ./defaultKeyBind.nix; -in { - imports = [inputs.niri-flake.homeModules.niri]; - programs.niri.package = pkgs.niri; - - programs.niri.settings = { - input.touchpad = { - natural-scroll = true; - scroll-factor = 4.0; - scroll-method = "two-finger"; - click-method = "clickfinger"; - drag = true; - drag-lock = true; - }; - - spawn-at-startup = [ - {command = ["noctalia-shell"];} - ]; - - outputs."eDP-1".scale = 1; - cursor.size = 16; - - # Doracura color - layout = { - focus-ring = { - active.color = "#bd93f9"; - inactive.color = "#6272a4"; - }; - border = { - active.color = "#ffc87f"; - inactive.color = "#505050"; - urgent.color = "#9b0000"; - }; - shadow = { - color = "#0007"; - }; - }; - - binds = - defaultKeyBind - // { - "Mod+T" = { - action.spawn = "ghostty"; - hotkey-overlay.title = "Open a Terminal: ghostty"; - }; - "Mod+D" = { - action.spawn = [ - "vicinae" - "toggle" - ]; - hotkey-overlay.title = "Run an Application: vicinae"; - }; - "Mod+Space" = { - action.spawn = [ - "vicinae" - "toggle" - ]; - hotkey-overlay.title = "Run an Application: vicinae"; - }; - "Mod+E" = { - action.spawn = [ - "nautilus" - "--new-window" - ]; - hotkey-overlay.title = "Open File Manager: nautilus"; - }; - "Mod+L" = { - action.spawn = [ - "noctalia-shell" - "ipc" - "call" - "sessionMenu" - "lockAndSuspend" - ]; - hotkey-overlay.title = "Lock the Screen: noctalia"; - }; - "Mod+V" = { - action.spawn = [ - "vicinae" - "vicinae://extensions/vicinae/clipboard/history" - ]; - hotkey-overlay.title = "Clipboard History"; - }; - - "XF86AudioRaiseVolume" = { - action.spawn = [ - "noctalia-shell" - "ipc" - "call" - "volume" - "increase" - ]; - }; - "XF86AudioLowerVolume" = { - action.spawn = [ - "noctalia-shell" - "ipc" - "call" - "volume" - "decrease" - ]; - }; - "XF86AudioMute" = { - action.spawn = [ - "noctalia-shell" - "ipc" - "call" - "volume" - "muteOutput" - ]; - }; - "XF86AudioMicMute" = { - action.spawn = [ - "noctalia-shell" - "ipc" - "call" - "volume" - "muteInput" - ]; - }; - - "XF86MonBrightnessUp" = { - action.spawn = [ - "noctalia-shell" - "ipc" - "call" - "brightness" - "increase" - ]; - }; - "XF86MonBrightnessDown" = { - action.spawn = [ - "noctalia-shell" - "ipc" - "call" - "brightness" - "decrease" - ]; - }; - }; - }; -} diff --git a/modules/home/niri/defaultKeyBind.nix b/modules/home/niri/defaultKeyBind.nix deleted file mode 100644 index db095f2..0000000 --- a/modules/home/niri/defaultKeyBind.nix +++ /dev/null @@ -1,240 +0,0 @@ -{ - # https://github.com/sodiboo/niri-flake/issues/483 - - # Keys consist of modifiers separated by + signs, followed by an XKB key name - # in the end. To find an XKB name for a particular key, you may use a program - # like wev. - # - # "Mod" is a special modifier equal to Super when running on a TTY, and to Alt - # when running as a winit window. - # - # Most actions that you can bind here can also be invoked programmatically with - # `niri msg action do-something`. - - # Mod-Shift-/, which is usually the same as Mod-?, - # shows a list of important hotkeys. - "Mod+Shift+Slash".action.show-hotkey-overlay = {}; - - # You can also use a shell. Do this if you need pipes, multiple commands, etc. - # Note: the entire command goes as a single argument in the end. - # Mod+T { spawn "bash" "-c" "notify-send hello && exec alacritty"; } - - # Example volume keys mappings for PipeWire & WirePlumber. - # The allow-when-locked=true property makes them work even when the session is locked. - "XF86AudioRaiseVolume" = { - allow-when-locked = true; - action.spawn = [ "wpctl" "set-volume" "@DEFAULT_AUDIO_SINK@" "0.1+" ]; - }; - "XF86AudioLowerVolume" = { - allow-when-locked = true; - action.spawn = ["wpctl" "set-volume" "@DEFAULT_AUDIO_SINK@" "0.1-"]; - }; - "XF86AudioMute" = { - allow-when-locked = true; - action.spawn = [ "wpctl" "set-mute" "@DEFAULT_AUDIO_SINK@" "toggle" ]; - }; - "XF86AudioMicMute" = { - allow-when-locked = true; - action.spawn = [ "wpctl" "set-mute" "@DEFAULT_AUDIO_SOURCE@" "toggle" ]; - }; - - "Mod+Q".action.close-window = {}; - - "Mod+Left".action.focus-column-left = {}; - "Mod+Down".action.focus-window-down = {}; - "Mod+Up".action.focus-window-up = {}; - "Mod+Right".action.focus-column-right = {}; - "Mod+H".action.focus-column-left = {}; - "Mod+J".action.focus-window-down = {}; - "Mod+K".action.focus-window-up = {}; - "Mod+L".action.focus-column-right = {}; - - "Mod+Ctrl+Left".action.move-column-left = {}; - "Mod+Ctrl+Down".action.move-window-down = {}; - "Mod+Ctrl+Up".action.move-window-up = {}; - "Mod+Ctrl+Right".action.move-column-right = {}; - "Mod+Ctrl+H".action.move-column-left = {}; - "Mod+Ctrl+J".action.move-window-down = {}; - "Mod+Ctrl+K".action.move-window-up = {}; - "Mod+Ctrl+L".action.move-column-right = {}; - - # Alternative commands that move across workspaces when reaching - # the first or last window in a column. - # Mod+J { focus-window-or-workspace-down; } - # Mod+K { focus-window-or-workspace-up; } - # Mod+Ctrl+J { move-window-down-or-to-workspace-down; } - # Mod+Ctrl+K { move-window-up-or-to-workspace-up; } - - "Mod+Home".action.focus-column-first = {}; - "Mod+End".action.focus-column-last = {}; - "Mod+Ctrl+Home".action.move-column-to-first = {}; - "Mod+Ctrl+End".action.move-column-to-last = {}; - - "Mod+Shift+Left".action.focus-monitor-left = {}; - "Mod+Shift+Down".action.focus-monitor-down = {}; - "Mod+Shift+Up".action.focus-monitor-up = {}; - "Mod+Shift+Right".action.focus-monitor-right = {}; - "Mod+Shift+H".action.focus-monitor-left = {}; - "Mod+Shift+J".action.focus-monitor-down = {}; - "Mod+Shift+K".action.focus-monitor-up = {}; - "Mod+Shift+L".action.focus-monitor-right = {}; - - "Mod+Shift+Ctrl+Left".action.move-column-to-monitor-left = {}; - "Mod+Shift+Ctrl+Down".action.move-column-to-monitor-down = {}; - "Mod+Shift+Ctrl+Up".action.move-column-to-monitor-up = {}; - "Mod+Shift+Ctrl+Right".action.move-column-to-monitor-right = {}; - "Mod+Shift+Ctrl+H".action.move-column-to-monitor-left = {}; - "Mod+Shift+Ctrl+J".action.move-column-to-monitor-down = {}; - "Mod+Shift+Ctrl+K".action.move-column-to-monitor-up = {}; - "Mod+Shift+Ctrl+L".action.move-column-to-monitor-right = {}; - - # Alternatively, there are commands to move just a single window: - # Mod+Shift+Ctrl+Left { move-window-to-monitor-left; } - # ... - - # And you can also move a whole workspace to another monitor: - # Mod+Shift+Ctrl+Left { move-workspace-to-monitor-left; } - # ... - - "Mod+Page_Down".action.focus-workspace-down = {}; - "Mod+Page_Up".action.focus-workspace-up = {}; - "Mod+U".action.focus-workspace-down = {}; - "Mod+I".action.focus-workspace-up = {}; - "Mod+Ctrl+Page_Down".action.move-column-to-workspace-down = {}; - "Mod+Ctrl+Page_Up".action.move-column-to-workspace-up = {}; - "Mod+Ctrl+U".action.move-column-to-workspace-down = {}; - "Mod+Ctrl+I".action.move-column-to-workspace-up = {}; - - # Alternatively, there are commands to move just a single window: - # Mod+Ctrl+Page_Down { move-window-to-workspace-down; } - # ... - - "Mod+Shift+Page_Down".action.move-workspace-down = {}; - "Mod+Shift+Page_Up".action.move-workspace-up = {}; - "Mod+Shift+U".action.move-workspace-down = {}; - "Mod+Shift+I".action.move-workspace-up = {}; - - # You can bind mouse wheel scroll ticks using the following syntax. - # These binds will change direction based on the natural-scroll setting. - # - # To avoid scrolling through workspaces really fast, you can use - # the cooldown-ms property. The bind will be rate-limited to this value. - # You can set a cooldown on any bind, but it's most useful for the wheel. - "Mod+WheelScrollDown" = { - cooldown-ms = 150; - action.focus-workspace-down = {}; - }; - "Mod+WheelScrollUp" = { - cooldown-ms = 150; - action.focus-workspace-up = {}; - }; - "Mod+Ctrl+WheelScrollDown" = { - cooldown-ms = 150; - action.move-column-to-workspace-down = {}; - }; - "Mod+Ctrl+WheelScrollUp" = { - cooldown-ms = 150; - action.move-column-to-workspace-up = {}; - }; - - "Mod+WheelScrollRight".action.focus-column-right = {}; - "Mod+WheelScrollLeft".action.focus-column-left = {}; - "Mod+Ctrl+WheelScrollRight".action.move-column-right = {}; - "Mod+Ctrl+WheelScrollLeft".action.move-column-left = {}; - - # Usually scrolling up and down with Shift in applications results in - # horizontal scrolling; these binds replicate that. - "Mod+Shift+WheelScrollDown".action.focus-column-right = {}; - "Mod+Shift+WheelScrollUp".action.focus-column-left = {}; - "Mod+Ctrl+Shift+WheelScrollDown".action.move-column-right = {}; - "Mod+Ctrl+Shift+WheelScrollUp".action.move-column-left = {}; - - # Similarly, you can bind touchpad scroll "ticks". - # Touchpad scrolling is continuous, so for these binds it is split into - # discrete intervals. - # These binds are also affected by touchpad's natural-scroll, so these - # example binds are "inverted", since we have natural-scroll enabled for - # touchpads by default. - # Mod+TouchpadScrollDown { spawn "wpctl" "set-volume" "@DEFAULT_AUDIO_SINK@" "0.02+"; } - # Mod+TouchpadScrollUp { spawn "wpctl" "set-volume" "@DEFAULT_AUDIO_SINK@" "0.02-"; } - - # You can refer to workspaces by index. However, keep in mind that - # niri is a dynamic workspace system, so these commands are kind of - # "best effort". Trying to refer to a workspace index bigger than - # the current workspace count will instead refer to the bottommost - # (empty) workspace. - # - # For example, with 2 workspaces + 1 empty, indices 3, 4, 5 and so on - # will all refer to the 3rd workspace. - "Mod+1".action.focus-workspace = 1; - "Mod+2".action.focus-workspace = 2; - "Mod+3".action.focus-workspace = 3; - "Mod+4".action.focus-workspace = 4; - "Mod+5".action.focus-workspace = 5; - "Mod+6".action.focus-workspace = 6; - "Mod+7".action.focus-workspace = 7; - "Mod+8".action.focus-workspace = 8; - "Mod+9".action.focus-workspace = 9; - "Mod+Ctrl+1".action.move-column-to-workspace = 1; - "Mod+Ctrl+2".action.move-column-to-workspace = 2; - "Mod+Ctrl+3".action.move-column-to-workspace = 3; - "Mod+Ctrl+4".action.move-column-to-workspace = 4; - "Mod+Ctrl+5".action.move-column-to-workspace = 5; - "Mod+Ctrl+6".action.move-column-to-workspace = 6; - "Mod+Ctrl+7".action.move-column-to-workspace = 7; - "Mod+Ctrl+8".action.move-column-to-workspace = 8; - "Mod+Ctrl+9".action.move-column-to-workspace = 9; - - # Alternatively, there are commands to move just a single window: - # Mod+Ctrl+1 { move-window-to-workspace 1; } - - # Switches focus between the current and the previous workspace. - # Mod+Tab { focus-workspace-previous; } - - "Mod+Comma".action.consume-window-into-column = {}; - "Mod+Period".action.expel-window-from-column = {}; - - # There are also commands that consume or expel a single window to the side. - # Mod+BracketLeft { consume-or-expel-window-left; } - # Mod+BracketRight { consume-or-expel-window-right; } - - "Mod+R".action.switch-preset-column-width = {}; - "Mod+Shift+R".action.reset-window-height = {}; - "Mod+F".action.maximize-column = {}; - "Mod+Shift+F".action.fullscreen-window = {}; - "Mod+C".action.center-column = {}; - - # Finer width adjustments. - # This command can also: - # * set width in pixels: "1000" - # * adjust width in pixels: "-5" or "+5" - # * set width as a percentage of screen width: "25%" - # * adjust width as a percentage of screen width: "-10%" or "+10%" - # Pixel sizes use logical, or scaled, pixels. I.e. on an output with scale 2.0, - # set-column-width "100" will make the column occupy 200 physical screen pixels. - "Mod+Minus".action.set-column-width = "-10%"; - "Mod+Equal".action.set-column-width = "+10%"; - - # Finer height adjustments when in column with other windows. - "Mod+Shift+Minus".action.set-window-height = "-10%"; - "Mod+Shift+Equal".action.set-window-height = "+10%"; - - # Actions to switch layouts. - # Note: if you uncomment these, make sure you do NOT have - # a matching layout switch hotkey configured in xkb options above. - # Having both at once on the same hotkey will break the switching, - # since it will switch twice upon pressing the hotkey (once by xkb, once by niri). - # Mod+Space { switch-layout "next"; } - # Mod+Shift+Space { switch-layout "prev"; } - - "Print".action.screenshot = {}; - "Ctrl+Print".action.screenshot-screen = {}; - "Alt+Print".action.screenshot-window = {}; - - # The quit action will show a confirmation dialog to avoid accidental exits. - "Mod+Shift+E".action.quit = {}; - - # Powers off the monitors. To> turn them back on, do any input like - # moving the mouse or pressing any other key. - "Mod+Shift+P".action.power-off-monitors = {}; -} \ No newline at end of file diff --git a/modules/home/nixvim/default.nix b/modules/home/nixvim/default.nix deleted file mode 100644 index 6058473..0000000 --- a/modules/home/nixvim/default.nix +++ /dev/null @@ -1,45 +0,0 @@ -{ - pkgs, - inputs, - ... -}: { - imports = [ - inputs.nixvim.homeModules.nixvim - ./options.nix - ./autocmds.nix - ./keymaps.nix - ./language.nix - ./colorscheme.nix - ./lsp.nix - ./plugins - ]; - - programs.nixvim = { - enable = true; - vimAlias = true; - viAlias = true; - withNodeJs = true; - - extraPackages = with pkgs; [ - git - ripgrep - fd - nodejs - zellij - - # LSP / formatter / misc - vtsls - vscode-langservers-extracted - tailwindcss-language-server - prettierd - prettier - biome - stylua - shfmt - alejandra - lua-language-server - nixd - ]; - - }; -} diff --git a/modules/home/nixvim/plugins/editor/gitsigns.nix b/modules/home/nixvim/plugins/editor/gitsigns.nix deleted file mode 100644 index eba120a..0000000 --- a/modules/home/nixvim/plugins/editor/gitsigns.nix +++ /dev/null @@ -1,15 +0,0 @@ -{...}: { - # git change view - programs.nixvim.plugins.gitsigns = { - enable = true; - settings = { - signs = { - add = {text = "+";}; - change = {text = "~";}; - delete = {text = "_";}; - topdelete = {text = "‾";}; - changedelete = {text = "~";}; - }; - }; - }; -} diff --git a/modules/home/noctalia.nix b/modules/home/noctalia.nix deleted file mode 100644 index 0d40ade..0000000 --- a/modules/home/noctalia.nix +++ /dev/null @@ -1,168 +0,0 @@ -{ - pkgs, - inputs, - ... -}: { - # import the home manager module - imports = [ - inputs.noctalia.homeModules.default - ]; - - # configure options - programs.noctalia-shell = { - enable = true; - settings = { - # configure noctalia here; defaults will - # be deep merged with these attributes. - bar = { - density = "default"; - position = "top"; - showCapsule = true; - backgroundOpacity = 0.8; - floating = true; - widgets = { - left = [ - { - id = "WiFi"; - } - { - id = "CustomButton"; - icon = "access-point"; - leftClickExec = "nm-connection-editor"; - } - { - id = "Bluetooth"; - } - { - id = "SystemMonitor"; - } - { - id = "Taskbar"; - } - { - id = "ActiveWindow"; - } - ]; - center = [ - { - hideUnoccupied = false; - id = "Workspace"; - labelMode = "none"; - } - ]; - right = [ - { - id = "MediaMini"; - } - { - id = "NotificationHistory"; - } - { - displayMode = "alwaysShow"; - id = "Battery"; - warningThreshold = 30; - } - { - displayMode = "alwaysShow"; - id = "Volume"; - } - { - displayMode = "alwaysShow"; - id = "Brightness"; - } - { - formatHorizontal = "HH:mm"; - formatVertical = "HH mm"; - id = "Clock"; - useMonospacedFont = true; - usePrimaryColor = true; - } - { - id = "ControlCenter"; - useDistroLogo = true; - } - ]; - }; - }; - colorSchemes.predefinedScheme = "dracula"; - general = { - avatarImage = "~/.face"; - radiusRatio = 0.2; - }; - location = { - monthBeforeDay = true; - weatherEnabled = false; - name = "Tokyo"; - }; - wallpaper = { - enabled = true; - directory = "~/.wallpapers/"; - setWallpaperOnAllMonitors = true; - linkLightAndDarkWallpapers = true; - fillMode = "crop"; - randomEnabled = true; - randomIntervalSec = 60; - transitionDuration = 1500; - }; - dock = { - enabled = true; - displayMode = "auto_hide"; - backgroundOpacity = 0.8; - floatingRatio = 1; - size = 1; - onlySameOutput = true; - monitors = ["eDP-1"]; - pinnedApps = ["com.mitchellh.ghostty" "org.gnome.Nautilus" "google-chrome" "code"]; - colorizeIcons = false; - }; - controlCenter = { - position = "close_to_bar_button"; - shortcuts = { - left = [ - { - id = "WiFi"; - } - { - id = "Bluetooth"; - } - { - id = "ScreenRecorder"; - } - { - id = "WallpaperSelector"; - } - ]; - right = [ - { - id = "Notifications"; - } - { - id = "NightLight"; - } - ]; - }; - cards = [ - { - enabled = true; - id = "profile-card"; - } - { - enabled = true; - id = "shortcuts-card"; - } - { - enabled = true; - id = "audio-card"; - } - { - enabled = true; - id = "media-sysmon-card"; - } - ]; - }; - }; - # this may also be a string or a path to a JSON file, - # but in this case must include *all* settings. - }; -} - diff --git a/modules/home/ssh.nix b/modules/home/ssh.nix deleted file mode 100644 index e45ff6b..0000000 --- a/modules/home/ssh.nix +++ /dev/null @@ -1,67 +0,0 @@ -{ - config, - lib, - pkgs, - host, - ... -}: -{ - - home.packages = [ pkgs.openssh ]; - - programs.ssh = { - enable = true; - - matchBlocks = { - "monitor.moons14.com" = { - host = "monitor.moons14.com"; - identityFile = "~/.ssh/id_ed25519_sk_rk"; - identitiesOnly = true; - }; - - "dev-1.moons14.com" = { - host = "dev-1.moons14.com"; - identityFile = "~/.ssh/id_ed25519_sk_rk"; - identitiesOnly = true; - }; - - "service-1.moons14.com" = { - host = "service-1.moons14.com"; - identityFile = "~/.ssh/id_ed25519_sk_rk"; - identitiesOnly = true; - }; - }; - - enableDefaultConfig = false; - - matchBlocks."*" = { - identityFile = "~/.ssh/id_ed25519"; - extraOptions.AddKeysToAgent = "yes"; - }; - }; - - home.activation.generateSshKey = lib.hm.dag.entryAfter [ "writeBoundary" ] '' - key="$HOME/.ssh/id_ed25519" - if [ ! -f "$key" ]; then - umask 077 - mkdir -p "$HOME/.ssh" - ${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \ - -C "moons@$(${host} || echo host)" - echo "Generated SSH key at $key" - fi - ''; - - programs.git = { - enable = true; - - signing = { - key = "~/.ssh/id_ed25519.pub"; - signByDefault = true; - }; - - settings = { - gpg.format = "ssh"; - tag.gpgSign = true; - }; - }; -} diff --git a/modules/home/vicinae.nix b/modules/home/vicinae.nix deleted file mode 100644 index 0169104..0000000 --- a/modules/home/vicinae.nix +++ /dev/null @@ -1,50 +0,0 @@ -{ - inputs, - pkgs, - ... -}: { - imports = [ - inputs.vicinae.homeManagerModules.default - ]; - - services.vicinae = { - enable = true; - systemd = { - enable = true; - autoStart = true; - environment = { - USE_LAYER_SHELL = 1; - }; - }; - - settings = { - font.size = 11; - close_on_focus_loss = true; - consider_preedit = true; - pop_to_root_on_close = true; - favicon_service = "twenty"; - search_files_in_root = true; - theme = { - light = { - name = "dracula"; - icon_theme = "default"; - }; - dark = { - name = "vicinae-light"; - icon_theme = "default"; - }; - }; - window = { - csd = true; - opacity = 0.95; - rounding = 10; - }; - }; - extensions = with inputs.vicinae-extensions.packages.${pkgs.stdenv.hostPlatform.system}; [ - bluetooth - nix - power-profile - # Extension names can be found in the link below, it's just the folder names - ]; - }; -} diff --git a/modules/home/wallpaper.nix b/modules/home/wallpaper.nix deleted file mode 100644 index 6013794..0000000 --- a/modules/home/wallpaper.nix +++ /dev/null @@ -1,26 +0,0 @@ -{ - pkgs, - lib, - ... -}: let - walls = pkgs.fetchFromGitHub { - owner = "moons-14"; - repo = "wallpapers"; - rev = "cc3256f4aaf2c8e7d16fb000b1ee251af54085db"; - hash = "sha256-emQ/FqKqMq3YI5bLx8gBZg/ZE72OG9Ilh71ggq78WdQ="; - }; -in { - home.file.".wallpapers" = { - source = walls; - recursive = true; - }; - - home.file.".cache/noctalia/wallpapers.json" = { - text = builtins.toJSON { - defaultWallpaper = "~/.wallpapers/1.jpg"; - wallpapers = { - "DP-1" = "~/.wallpapers/1.jpg"; - }; - }; - }; -} diff --git a/modules/home/zellij.nix b/modules/home/zellij.nix deleted file mode 100644 index c38d526..0000000 --- a/modules/home/zellij.nix +++ /dev/null @@ -1,61 +0,0 @@ -{...}: { - programs.zellij = { - enable = true; - - enableZshIntegration = false; - - settings = { - pane_frames = true; - default_mode = "locked"; - default_shell = "/run/current-system/sw/bin/zsh"; - }; - - extraConfig = '' - keybinds { - locked { - bind "Ctrl g" { SwitchToMode "normal"; } - bind "Alt h" "Alt Left" { MoveFocusOrTab "Left"; } - bind "Alt j" "Alt Down" { MoveFocus "Down"; } - bind "Alt k" "Alt Up" { MoveFocus "Up"; } - bind "Alt l" "Alt Right" { MoveFocusOrTab "Right"; } - bind "Alt n" { NewPane; } - bind "Alt t" { NewTab; } - bind "Alt H" { Resize "Increase Left"; } - bind "Alt J" { Resize "Increase Down"; } - bind "Alt K" { Resize "Increase Up"; } - bind "Alt L" { Resize "Increase Right"; } - } - normal { - bind "Alt h" "Alt Left" { MoveFocusOrTab "Left"; } - bind "Alt j" "Alt Down" { MoveFocus "Down"; } - bind "Alt k" "Alt Up" { MoveFocus "Up"; } - bind "Alt l" "Alt Right" { MoveFocusOrTab "Right"; } - bind "Alt n" { NewPane; } - bind "Alt t" { NewTab; } - bind "Alt H" { Resize "Increase Left"; } - bind "Alt J" { Resize "Increase Down"; } - bind "Alt K" { Resize "Increase Up"; } - bind "Alt L" { Resize "Increase Right"; } - } - } - ''; - - layouts.dev = '' - layout { - pane split_direction="vertical" { - pane { - pane command="nvim" - pane stacked=true size="30%" { - pane expanded=true - pane - } - } - - pane size=1 borderless=true { - plugin location="zellij:compact-bar" - } - } - } - ''; - }; -} diff --git a/modules/home/zoom.nix b/modules/home/zoom.nix deleted file mode 100644 index 63d87c9..0000000 --- a/modules/home/zoom.nix +++ /dev/null @@ -1,9 +0,0 @@ -{ pkgs, lib, ... }: -{ - nixpkgs.config.allowUnfreePredicate = pkg: - lib.getName pkg == "zoom-us"; - - home.packages = with pkgs; [ - zoom-us - ]; -} diff --git a/modules/home/zsh.nix b/modules/home/zsh.nix deleted file mode 100644 index 5c3e656..0000000 --- a/modules/home/zsh.nix +++ /dev/null @@ -1,47 +0,0 @@ -{ config, pkgs, ... }: - -{ - programs.zsh = { - enable = true; - enableCompletion = true; - - # Oh My Zsh - oh-my-zsh = { - enable = true; - theme = "robbyrussell"; - plugins = [ "git" ]; - }; - - autosuggestion.enable = true; - syntaxHighlighting.enable = true; - - initContent = '' - # ---- from gist: export / history size ---- - export HISTSIZE=999999999 - export HISTFILESIZE=999999999 - - # ---- from gist: setopt ---- - setopt extended_history - setopt hist_allow_clobber - setopt hist_fcntl_lock - setopt hist_find_no_dups - setopt hist_ignore_all_dups - setopt hist_ignore_dups - setopt hist_ignore_space - # setopt hist_no_functions - # setopt hist_no_store - setopt hist_reduce_blanks - setopt hist_save_no_dups - setopt hist_verify - setopt inc_append_history_time - - unsetopt SHARE_HISTORY - setopt APPEND_HISTORY - setopt INC_APPEND_HISTORY_TIME - - # ---- from gist: aliases ---- - alias docker-compose="docker compose" - alias clearsign='export GPG_TTY=$(tty) && openssl rand -hex 16 | gpg --clearsign' - ''; - }; -} diff --git a/modules/integrations/default.nix b/modules/integrations/default.nix new file mode 100644 index 0000000..1e9a5a4 --- /dev/null +++ b/modules/integrations/default.nix @@ -0,0 +1,5 @@ +{ + imports = [ + ./home-manager.nix + ]; +} diff --git a/modules/integrations/home-manager.nix b/modules/integrations/home-manager.nix new file mode 100644 index 0000000..8dde697 --- /dev/null +++ b/modules/integrations/home-manager.nix @@ -0,0 +1,25 @@ +{ + username, + inputs, + config, + ... +}: +{ + imports = [ + inputs.home-manager.nixosModules.home-manager + ]; + + home-manager = { + useUserPackages = true; + useGlobalPkgs = true; + backupFileExtension = "backup"; + + users.${username} = { + home = { + inherit username; + homeDirectory = "/home/${username}"; + stateVersion = config.my.stateVersions.homeManager; + }; + }; + }; +} diff --git a/modules/system/audio.nix b/modules/system/audio.nix new file mode 100644 index 0000000..d859857 --- /dev/null +++ b/modules/system/audio.nix @@ -0,0 +1,22 @@ +{ lib, config, ... }: +let + cfg = config.my.system.audio; +in +{ + options.my.system.audio = { + enable = lib.mkEnableOption "Audio support (PipeWire)"; + }; + + config = lib.mkIf cfg.enable { + security.rtkit.enable = true; + + services.pipewire = { + enable = true; + alsa.enable = true; + alsa.support32Bit = true; + pulse.enable = true; + jack.enable = true; + wireplumber.enable = true; + }; + }; +} diff --git a/modules/system/boot/default.nix b/modules/system/boot/default.nix new file mode 100644 index 0000000..63e8b0a --- /dev/null +++ b/modules/system/boot/default.nix @@ -0,0 +1,17 @@ +{ + pkgs, + lib, + ... +}: +{ + imports = [ + ./nfs.nix + ./uefi.nix + ]; + + boot = { + loader.systemd-boot.configurationLimit = lib.mkDefault 8; + kernelPackages = pkgs.linuxPackages_latest; + }; + programs.nix-ld.enable = true; +} diff --git a/modules/system/boot/nfs.nix b/modules/system/boot/nfs.nix new file mode 100644 index 0000000..7c9bc27 --- /dev/null +++ b/modules/system/boot/nfs.nix @@ -0,0 +1,19 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.system.boot.nfs; +in +{ + options.my.system.boot.nfs = { + enable = lib.mkEnableOption "NFS boot support"; + }; + + config = lib.mkIf cfg.enable { + boot.supportedFilesystems = [ "nfs" ]; + programs.fuse.userAllowOther = true; + services.rpcbind.enable = true; + }; +} diff --git a/modules/system/boot/uefi.nix b/modules/system/boot/uefi.nix new file mode 100644 index 0000000..6ad8e92 --- /dev/null +++ b/modules/system/boot/uefi.nix @@ -0,0 +1,20 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.system.boot.uefi; +in +{ + options.my.system.boot.uefi = { + enable = lib.mkEnableOption "UEFI boot support"; + }; + + config = lib.mkIf cfg.enable { + boot.loader = { + systemd-boot.enable = lib.mkDefault true; + efi.canTouchEfiVariables = lib.mkDefault true; + }; + }; +} diff --git a/modules/system/camera.nix b/modules/system/camera.nix new file mode 100644 index 0000000..9419576 --- /dev/null +++ b/modules/system/camera.nix @@ -0,0 +1,35 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.system.camera; +in +{ + options.my.system.camera = { + enable = lib.mkEnableOption "camera support"; + }; + + config = lib.mkIf cfg.enable { + boot.kernelModules = [ "uvcvideo" ]; + + environment.systemPackages = with pkgs; [ + v4l-utils + ffmpeg-full + ]; + + services.pipewire = { + enable = true; + alsa.enable = true; + pulse.enable = true; + }; + security.rtkit.enable = true; + + xdg.portal = { + enable = true; + extraPortals = [ pkgs.xdg-desktop-portal-gtk ]; + }; + }; +} diff --git a/modules/system/default.nix b/modules/system/default.nix new file mode 100644 index 0000000..2206bcd --- /dev/null +++ b/modules/system/default.nix @@ -0,0 +1,21 @@ +{ + imports = [ + ./audio.nix + ./boot + ./camera.nix + ./disko.nix + ./fingerprint.nix + ./fonts.nix + ./gc.nix + ./hardware + ./locale.nix + ./network + ./nix.nix + ./power.nix + ./secure-boot.nix + ./sops.nix + ./user + ./version.nix + ./secret.nix + ]; +} diff --git a/modules/system/disko.nix b/modules/system/disko.nix new file mode 100644 index 0000000..ccec8f5 --- /dev/null +++ b/modules/system/disko.nix @@ -0,0 +1,10 @@ +{ inputs, lib, ... }: +{ + imports = [ + inputs.disko.nixosModules.disko + ]; + + config = { + disko.enableConfig = lib.mkDefault false; + }; +} diff --git a/modules/system/fingerprint.nix b/modules/system/fingerprint.nix new file mode 100644 index 0000000..20450b3 --- /dev/null +++ b/modules/system/fingerprint.nix @@ -0,0 +1,23 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.system.fingerprint; +in +{ + options.my.system.fingerprint = { + enable = lib.mkEnableOption "fingerprint authentication"; + }; + + config = lib.mkIf cfg.enable { + services.fprintd.enable = true; + + security.pam.services = { + login.fprintAuth = true; + sudo.fprintAuth = true; + greetd.fprintAuth = true; + }; + }; +} diff --git a/modules/system/fonts.nix b/modules/system/fonts.nix new file mode 100644 index 0000000..12654a5 --- /dev/null +++ b/modules/system/fonts.nix @@ -0,0 +1,43 @@ +{ + pkgs, + lib, + config, + ... +}: +let + cfg = config.my.system.fonts; +in +{ + options.my.system.fonts = { + enable = lib.mkEnableOption "system font configuration"; + }; + + config = lib.mkIf cfg.enable { + fonts = { + packages = with pkgs; [ + noto-fonts + noto-fonts-cjk-sans + noto-fonts-color-emoji + terminus_font + cantarell-fonts + font-awesome + nerd-fonts.blex-mono + ]; + + fontDir.enable = true; + fontconfig = { + defaultFonts = { + serif = [ + "Noto Serif CJK JP" + "Noto Color Emoji" + ]; + sansSerif = [ + "Noto Sans CJK JP" + "Noto Clor Emoji" + ]; + emoji = [ "Noto Color Emoji" ]; + }; + }; + }; + }; +} diff --git a/modules/core/gc.nix b/modules/system/gc.nix similarity index 93% rename from modules/core/gc.nix rename to modules/system/gc.nix index 76bbd7f..31312b7 100644 --- a/modules/core/gc.nix +++ b/modules/system/gc.nix @@ -1,5 +1,4 @@ -{ ... }: -{ +_: { nix.gc = { automatic = true; dates = "daily"; @@ -8,4 +7,4 @@ nix.settings.auto-optimise-store = true; nix.optimise.automatic = true; -} \ No newline at end of file +} diff --git a/modules/system/hardware/bluetooth.nix b/modules/system/hardware/bluetooth.nix new file mode 100644 index 0000000..6b0f8a8 --- /dev/null +++ b/modules/system/hardware/bluetooth.nix @@ -0,0 +1,22 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.system.hardware.bluetooth; +in +{ + options.my.system.hardware.bluetooth = { + enable = lib.mkEnableOption "Bluetooth support"; + }; + + config = lib.mkIf cfg.enable { + hardware.bluetooth = { + enable = true; + powerOnBoot = true; + }; + + services.blueman.enable = true; + }; +} diff --git a/modules/system/hardware/default.nix b/modules/system/hardware/default.nix new file mode 100644 index 0000000..722b480 --- /dev/null +++ b/modules/system/hardware/default.nix @@ -0,0 +1,14 @@ +{ lib, ... }: +{ + imports = [ + ./bluetooth.nix + ./gui.nix + ]; + + hardware = { + enableRedistributableFirmware = lib.mkDefault true; + keyboard.qmk.enable = true; + }; + + services.fwupd.enable = true; +} diff --git a/modules/system/hardware/gui.nix b/modules/system/hardware/gui.nix new file mode 100644 index 0000000..19ed7ef --- /dev/null +++ b/modules/system/hardware/gui.nix @@ -0,0 +1,19 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.system.hardware.gui; +in +{ + options.my.system.hardware.gui = { + enable = lib.mkEnableOption "GPU/graphics hardware acceleration"; + }; + + config = lib.mkIf cfg.enable { + hardware = { + graphics.enable = true; + }; + }; +} diff --git a/modules/core/system.nix b/modules/system/locale.nix similarity index 65% rename from modules/core/system.nix rename to modules/system/locale.nix index bcb41e5..85aa356 100644 --- a/modules/core/system.nix +++ b/modules/system/locale.nix @@ -1,12 +1,6 @@ -{...}: { - nix = { - settings = { - experimental-features = ["nix-command" "flakes"]; - }; - }; - - # Localization settings +_: { time.timeZone = "Asia/Tokyo"; + i18n.defaultLocale = "ja_JP.UTF-8"; i18n.extraLocaleSettings = { LC_ADDRESS = "ja_JP.UTF-8"; @@ -20,11 +14,5 @@ LC_TIME = "ja_JP.UTF-8"; }; - environment.variables = { - NIXOS_OZONE_WL = "1"; - }; - console.keyMap = "jp106"; - system.stateVersion = "25.11"; } - diff --git a/modules/system/network/default.nix b/modules/system/network/default.nix new file mode 100644 index 0000000..894fe2e --- /dev/null +++ b/modules/system/network/default.nix @@ -0,0 +1,27 @@ +{ + host, + lib, + ... +}: +{ + imports = [ + ./wifi.nix + ]; + + networking = { + hostName = host; + + nameservers = lib.mkDefault [ + "1.1.1.1" + "1.0.0.1" + "10.50.80.53" + "10.50.80.54" + ]; + }; + + services.resolved.enable = lib.mkDefault false; + + security.pki.certificateFiles = [ + ./root_ca.crt + ]; +} diff --git a/modules/core/ca/root_ca.crt b/modules/system/network/root_ca.crt similarity index 99% rename from modules/core/ca/root_ca.crt rename to modules/system/network/root_ca.crt index 1e60529..5985efb 100644 --- a/modules/core/ca/root_ca.crt +++ b/modules/system/network/root_ca.crt @@ -10,3 +10,4 @@ UGL5CxdamFfBVC8xH306Wo6xMAoGCCqGSM49BAMCA0cAMEQCIBqWCNWBuwhWDYoi fpqOqz2HSChOsKCIAgfTJlUUgSlSAiALekUJ+4M+L4/vP4GpkrSovuQ7JOMXV44+ 30Pcx4AoJg== -----END CERTIFICATE----- + diff --git a/modules/system/network/wifi.nix b/modules/system/network/wifi.nix new file mode 100644 index 0000000..8b55002 --- /dev/null +++ b/modules/system/network/wifi.nix @@ -0,0 +1,38 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.system.network.wifi; +in +{ + options.my.system.network.wifi = { + enable = lib.mkEnableOption "WiFi (NetworkManager) support"; + }; + + config = lib.mkIf cfg.enable { + networking = { + networkmanager = { + enable = true; + + dns = "none"; + wifi.powersave = false; + wifi.backend = "wpa_supplicant"; + settings = { + "device"."wifi.scan-rand-mac-address" = "no"; + "connection"."wifi.cloned-mac-address" = "permanent"; + }; + }; + wireless.iwd.enable = false; + }; + + boot.extraModprobeConfig = '' + options cfg80211 ieee80211_regdom=JP + options iwlwifi power_save=0 + options iwlwifi uapsd_disable=1 + ''; + + programs.nm-applet.enable = true; + }; +} diff --git a/modules/core/cachix.nix b/modules/system/nix.nix similarity index 59% rename from modules/core/cachix.nix rename to modules/system/nix.nix index a117257..0c5af08 100644 --- a/modules/core/cachix.nix +++ b/modules/system/nix.nix @@ -1,15 +1,24 @@ -{...}: { +_: { nix.settings = { extra-substituters = [ + "https://cache.nixos.org" + "https://nix-community.cachix.org" "https://moons-dotfiles.cachix.org" "https://noctalia.cachix.org" "https://vicinae.cachix.org" ]; extra-trusted-public-keys = [ + "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" + "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" "moons-dotfiles.cachix.org-1:WHoroKiNScG2/dpxHHL1I0qVmvuQhJbEAP+DS2j9Rr0=" "noctalia.cachix.org-1:pCOR47nnMEo5thcxNDtzWpOxNFQsBRglJzxWPp3dkU4=" "vicinae.cachix.org-1:1kDrfienkGHPYbkpNj1mWTr7Fm1+zcenzgTizIcI3oc=" ]; + + experimental-features = [ + "nix-command" + "flakes" + ]; }; } diff --git a/modules/system/power.nix b/modules/system/power.nix new file mode 100644 index 0000000..6ab8466 --- /dev/null +++ b/modules/system/power.nix @@ -0,0 +1,37 @@ +{ + lib, + config, + ... +}: +let + cfg = config.my.system.power; +in +{ + options.my.system.power = { + enable = lib.mkEnableOption "power management"; + }; + + config = lib.mkIf cfg.enable { + boot.kernelParams = [ + "mem_sleep_default=deep" + ]; + + powerManagement = { + enable = true; + powertop.enable = true; + }; + + services.power-profiles-daemon.enable = true; + services.tlp.enable = false; + services.upower.enable = true; + + services.logind = { + settings.Login = { + HandleLidSwitch = "suspend"; + HandleLidSwitchDocked = "ignore"; + HandleLidSwitchExternalPower = "suspend"; + LidSwitchIgnoreInhibited = "no"; + }; + }; + }; +} diff --git a/modules/system/secret.nix b/modules/system/secret.nix new file mode 100644 index 0000000..bb393d2 --- /dev/null +++ b/modules/system/secret.nix @@ -0,0 +1,14 @@ +_: +let + commonSyetemSecrets = ../../secrets/common/system.yaml; +in +{ + sops.secrets = { + "users/moons/hashedPassword" = { + sopsFile = commonSyetemSecrets; + + # need before user creation + neededForUsers = true; + }; + }; +} diff --git a/modules/system/secure-boot.nix b/modules/system/secure-boot.nix new file mode 100644 index 0000000..8eda80d --- /dev/null +++ b/modules/system/secure-boot.nix @@ -0,0 +1,36 @@ +{ + pkgs, + inputs, + lib, + config, + ... +}: +let + cfg = config.my.system.secure-boot; +in +{ + imports = [ + inputs.lanzaboote.nixosModules.lanzaboote + ]; + + options.my.system.secure-boot = { + enable = lib.mkEnableOption "secure boot (lanzaboote)"; + }; + + config = lib.mkIf cfg.enable { + boot.loader = { + systemd-boot.enable = lib.mkForce false; + efi.canTouchEfiVariables = true; + efi.efiSysMountPoint = "/boot"; + }; + + boot.lanzaboote = { + enable = true; + pkiBundle = "/var/lib/sbctl"; + }; + + environment.systemPackages = with pkgs; [ + sbctl # A tool to manage UEFI Secure Boot keys and signatures + ]; + }; +} diff --git a/modules/system/sops.nix b/modules/system/sops.nix new file mode 100644 index 0000000..caf3184 --- /dev/null +++ b/modules/system/sops.nix @@ -0,0 +1,41 @@ +{ + inputs, + pkgs, + ... +}: +{ + imports = [ + inputs.sops-nix.nixosModules.sops + ]; + + environment.systemPackages = with pkgs; [ + # sops / age + sops + age + ssh-to-age + + # YubiKey edit key + age-plugin-yubikey + yubikey-manager + pcsc-tools + + # password hash generation + mkpasswd + ]; + + # age-plugin-yubikey depend + services.pcscd.enable = true; + + services.openssh.enable = true; + + sops = { + defaultSopsFormat = "yaml"; + + age = { + # system keys + sshKeyPaths = [ + "/etc/ssh/ssh_host_ed25519_key" + ]; + }; + }; +} diff --git a/modules/system/user/default.nix b/modules/system/user/default.nix new file mode 100644 index 0000000..3882832 --- /dev/null +++ b/modules/system/user/default.nix @@ -0,0 +1,13 @@ +{ + imports = [ + ./moons.nix + ]; + + users.mutableUsers = true; + + nix.settings.allowed-users = [ "moons" ]; + nix.settings.trusted-users = [ + "root" + "moons" + ]; +} diff --git a/modules/system/user/moons.nix b/modules/system/user/moons.nix new file mode 100644 index 0000000..47d70c2 --- /dev/null +++ b/modules/system/user/moons.nix @@ -0,0 +1,32 @@ +{ + pkgs, + config, + ... +}: +{ + users.mutableUsers = false; + + users.users.moons = { + isNormalUser = true; + description = "moons-14"; + hashedPasswordFile = config.sops.secrets."users/moons/hashedPassword".path; + extraGroups = [ + "adbusers" + "docker" + "libvirtd" + "lp" + "networkmanager" + "scanner" + "wheel" + "vboxusers" + "dialout" + ]; + shell = pkgs.zsh; + ignoreShellProgramCheck = true; + + openssh.authorizedKeys.keys = [ + "sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIKhxDkucmeCor6CKoXAua7DgDSzuXrZOtpdkyzQxz5+aAAAABHNzaDo= moons@moons14.com" + "sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIN6hZJyng/5LgFKPjR6uZAd/00UkO0vN0uQOoIvfSELdAAAABHNzaDo= moons@moons14.com" + ]; + }; +} diff --git a/modules/system/version.nix b/modules/system/version.nix new file mode 100644 index 0000000..3218185 --- /dev/null +++ b/modules/system/version.nix @@ -0,0 +1,22 @@ +{ + config, + lib, + ... +}: +{ + options.my.stateVersions = { + nixos = lib.mkOption { + type = lib.types.str; + default = "26.05"; + }; + + homeManager = lib.mkOption { + type = lib.types.str; + default = "26.05"; + }; + }; + + config = { + system.stateVersion = lib.mkDefault config.my.stateVersions.nixos; + }; +} diff --git a/overlays/default.nix b/overlays/default.nix index 368fac2..958608a 100644 --- a/overlays/default.nix +++ b/overlays/default.nix @@ -1,3 +1 @@ -{ inputs, ... }: -{ -} \ No newline at end of file +_: { } diff --git a/profiles/cli-minimal.nix b/profiles/cli-minimal.nix deleted file mode 100644 index 368bd5f..0000000 --- a/profiles/cli-minimal.nix +++ /dev/null @@ -1,8 +0,0 @@ -{ ... }: -{ - imports = [ - ]; - - home-manager.users.moons.imports = [ - ]; -} \ No newline at end of file diff --git a/profiles/cli-server.nix b/profiles/cli-server.nix deleted file mode 100644 index 8be0bc9..0000000 --- a/profiles/cli-server.nix +++ /dev/null @@ -1,10 +0,0 @@ -{ ... }: -{ - imports = [ - ./cli.nix - ]; - - home-manager.users.moons.imports = [ - - ]; -} \ No newline at end of file diff --git a/profiles/cli.nix b/profiles/cli.nix deleted file mode 100644 index 701ce85..0000000 --- a/profiles/cli.nix +++ /dev/null @@ -1,10 +0,0 @@ -{ ... }: -{ - imports = [ - ./cli-minimal.nix - ]; - - home-manager.users.moons.imports = [ - - ]; -} \ No newline at end of file diff --git a/profiles/gui.nix b/profiles/gui.nix deleted file mode 100644 index 867f1b5..0000000 --- a/profiles/gui.nix +++ /dev/null @@ -1,27 +0,0 @@ -{...}: { - imports = [ - ./cli.nix - ./../modules/core/niri.nix - ./../modules/core/hyprland.nix - ./../modules/core/greetd.nix - ./../modules/core/noctalia.nix - ./../modules/core/gui.nix - ./../modules/core/kde.nix - ]; - - home-manager.users.moons.imports = [ - ./../modules/home/niri - ./../modules/home/vscode.nix - ./../modules/home/browser.nix - ./../modules/home/vicinae.nix - ./../modules/home/noctalia.nix - ./../modules/home/avatar.nix - ./../modules/home/ghostty - ./../modules/home/wallpaper.nix - ./../modules/home/lock.nix - ./../modules/home/discord.nix - ./../modules/home/nautilus.nix - ./../modules/home/gtk.nix - ./../modules/home/zoom.nix - ]; -} diff --git a/profiles/interfaces/cli-interactive.nix b/profiles/interfaces/cli-interactive.nix new file mode 100644 index 0000000..6703a38 --- /dev/null +++ b/profiles/interfaces/cli-interactive.nix @@ -0,0 +1,7 @@ +{ + imports = [ + ./cli-minimal.nix + ]; + + my.features.cli.interactive.enable = true; +} diff --git a/profiles/interfaces/cli-minimal.nix b/profiles/interfaces/cli-minimal.nix new file mode 100644 index 0000000..e3f2f38 --- /dev/null +++ b/profiles/interfaces/cli-minimal.nix @@ -0,0 +1,9 @@ +{ + my.features = { + cli = { + base.enable = true; + shell.enable = true; + }; + identity.sshDefaultKey.enable = true; + }; +} diff --git a/profiles/interfaces/gui.nix b/profiles/interfaces/gui.nix new file mode 100644 index 0000000..25f3e5f --- /dev/null +++ b/profiles/interfaces/gui.nix @@ -0,0 +1,18 @@ +{ + imports = [ + ./cli-interactive.nix + ]; + + my.features = { + gui = { + desktop.enable = true; + terminal.enable = true; + audio.enable = true; + jpInput.enable = true; + graphic.enable = true; + capture.enable = true; + fileManager.enable = true; + }; + services.kde.enable = true; + }; +} diff --git a/profiles/laptop.nix b/profiles/laptop.nix deleted file mode 100644 index 6fdbc9b..0000000 --- a/profiles/laptop.nix +++ /dev/null @@ -1,13 +0,0 @@ -{ ... }: -{ - imports = [ - ./gui.nix - ./../modules/core/fingerprint.nix - ./../modules/core/power.nix - ./../modules/core/camera.nix - ]; - - home-manager.users.moons.imports = [ - - ]; -} \ No newline at end of file diff --git a/profiles/platforms/desktop.nix b/profiles/platforms/desktop.nix new file mode 100644 index 0000000..395d7d0 --- /dev/null +++ b/profiles/platforms/desktop.nix @@ -0,0 +1,3 @@ +{ + my.features.boot.uefi.enable = true; +} diff --git a/profiles/platforms/laptop.nix b/profiles/platforms/laptop.nix new file mode 100644 index 0000000..20f357a --- /dev/null +++ b/profiles/platforms/laptop.nix @@ -0,0 +1,12 @@ +{ + my.features = { + boot.power.enable = true; + connect = { + wifi.enable = true; + bluetooth.enable = true; + }; + gui.camera.enable = true; + identity.fingerprint.enable = true; + network.tailscale.enable = true; + }; +} diff --git a/profiles/platforms/thinkpad.nix b/profiles/platforms/thinkpad.nix new file mode 100644 index 0000000..af1e980 --- /dev/null +++ b/profiles/platforms/thinkpad.nix @@ -0,0 +1,7 @@ +{ + imports = [ + ./laptop.nix + ]; + + my.drivers.intel.enable = true; +} diff --git a/profiles/platforms/vm.nix b/profiles/platforms/vm.nix new file mode 100644 index 0000000..f95077f --- /dev/null +++ b/profiles/platforms/vm.nix @@ -0,0 +1,6 @@ +{ + my.features = { + boot.uefi.enable = true; + storage.nfsClient.enable = true; + }; +} diff --git a/profiles/workloads/dev.nix b/profiles/workloads/dev.nix new file mode 100644 index 0000000..6142d9a --- /dev/null +++ b/profiles/workloads/dev.nix @@ -0,0 +1,14 @@ +{ + my.features = { + dev = { + agent.enable = true; + arduino.enable = true; + nix.enable = true; + python.enable = true; + bun.enable = true; + java.enable = true; + }; + gui.editor.enable = true; + services.container.enable = true; + }; +} diff --git a/profiles/workloads/personal.nix b/profiles/workloads/personal.nix new file mode 100644 index 0000000..1b9da2a --- /dev/null +++ b/profiles/workloads/personal.nix @@ -0,0 +1,6 @@ +{ + my.features.application = { + browser.enable = true; + communication.enable = true; + }; +} diff --git a/profiles/workloads/remote.nix b/profiles/workloads/remote.nix new file mode 100644 index 0000000..78d47c9 --- /dev/null +++ b/profiles/workloads/remote.nix @@ -0,0 +1,5 @@ +{ + my.features = { + cli.base.sshServer = true; + }; +} diff --git a/profiles/workloads/secure-storage.nix b/profiles/workloads/secure-storage.nix new file mode 100644 index 0000000..c3820e1 --- /dev/null +++ b/profiles/workloads/secure-storage.nix @@ -0,0 +1,4 @@ +{ + my.features.boot.secureBoot.enable = true; + my.features.boot.storageCrypto.enable = true; +} diff --git a/profiles/workloads/srv.nix b/profiles/workloads/srv.nix new file mode 100644 index 0000000..f0c433c --- /dev/null +++ b/profiles/workloads/srv.nix @@ -0,0 +1,7 @@ +{ + my.features = { + cli.base.sshServer = true; + network.tailscale.enable = true; + services.container.enable = true; + }; +} diff --git a/renovate.json b/renovate.json deleted file mode 100644 index 50a306a..0000000 --- a/renovate.json +++ /dev/null @@ -1,15 +0,0 @@ -{ - "$schema": "https://docs.renovatebot.com/renovate-schema.json", - "extends": ["config:recommended"], - - "nix": { - "enabled": true - }, - - "lockFileMaintenance": { - "enabled": true - }, - - "minimumReleaseAge": "7 days", - "minimumReleaseAgeBehaviour": "timestamp-required" -} diff --git a/secrets/common/system.yaml b/secrets/common/system.yaml new file mode 100644 index 0000000..e9f7735 --- /dev/null +++ b/secrets/common/system.yaml @@ -0,0 +1,28 @@ +users: + moons: + hashedPassword: ENC[AES256_GCM,data:QtZei/BXPn/PDxUlOu0ZVrAfRM5jiHChAE5j5NVscPmm4OWjr94nPVOmJlYjL2WAiJY3/JSthmbrEIqiUF6E9qv10HQzAxzmZQ==,iv:ksshJX9S/20lw/8IDZYadNZLLE/gNgENZJ3/wRgJCds=,tag:xJPiO8O/q4rKmb+YNnpZdg==,type:str] +sops: + age: + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHBpdi1wMjU2IGxWc2NMZyBBM09Pclhu + K0ozcS90TG9Qam1YUjdCUGw5QjRoNXNGMU92WVdJOVluUk0vNQpjb3AxeGVpaFBT + L2hLYnZ1WWtOQjdyRFR1SnNMb1JITTVwWlNXb003YUFJCi0tLSBPNnowdm00ZEhR + b2VGZ1drRG4rU01TODk5Rm5KbXJjVkNhQ0hNeUxwdXBzCqKtUyprjagTVajskgXg + OBMMuflEZQH+mtFWsBc0k1Mm7MAS8DpMVLNZnkfNNPpFTP4pAOWFd2LhuMkDONFQ + vnA= + -----END AGE ENCRYPTED FILE----- + recipient: age1yubikey1qvy5y8kxqc63y7fk0tfv43u499a8z8q332ff087lythry9cc6hdxxkznc6t + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBPU0d5bVUrditWVCtDbyt6 + WFpJTVdLOGpqZ1hLZTJGZi83MXZLMzR6RVhFCnBZRU53V3NvYXFpVXVJaDJHdlhz + SlV4NFUvTDZUQWdTaUJNZElidk1zMjgKLS0tIEd3QTRldzBJamp0OWhNUTBFMExC + dlhiMGp4b1JqY2JVTG5vSitadXI4cEUKvhqw+A5CXktuHR3JBDNKg2SrNIy4++l8 + e58uQoTjJab1ivvLVAZOdtIdoulca50W9+ALNOFqBn9j5VD0BfFeKg== + -----END AGE ENCRYPTED FILE----- + recipient: age1xfc7ksg69l5kwsxxgtynsuxgpwltcf9gmqlhfl7efq0clc8lwspqnveyx3 + lastmodified: "2026-06-15T10:20:19Z" + mac: ENC[AES256_GCM,data:Tw58FneoksiOuol1aUOFXoAnFiTzddmFfYAA0B0RfPPyj6UKQbBvRYJhOMuOMRE1fVlDhqxxDiqZI5y14vJg8gLusAZt1JKi7ODR7MqcImvxboaee8DIj4uIcN254g0c0cmZWsGrt7yTYoSLDUc3QdAxj9/Az/CMls6XjM+RL8E=,iv:XGgWgbexCUxzuJzRVG3V2GZGwmwjAtowgz+NRPxk1+o=,tag:FwYJXfwS2f70okl0bhS+Sw==,type:str] + unencrypted_suffix: _unencrypted + version: 3.13.1 diff --git a/shells/default.nix b/shells/default.nix new file mode 100644 index 0000000..f2bbc99 --- /dev/null +++ b/shells/default.nix @@ -0,0 +1,5 @@ +{ + imports = [ + ./dotnix.nix + ]; +} diff --git a/shells/dotnix.nix b/shells/dotnix.nix new file mode 100644 index 0000000..bef8bb2 --- /dev/null +++ b/shells/dotnix.nix @@ -0,0 +1,35 @@ +_: { + perSystem = + { + pkgs, + config, + ... + }: + { + devShells.dotnix = pkgs.mkShell { + packages = [ + config.treefmt.build.wrapper + + pkgs.git + pkgs.gitleaks + pkgs.pre-commit + + # sops-nix / age + pkgs.sops + pkgs.age + pkgs.ssh-to-age + + # YubiKey for sops editing + pkgs.age-plugin-yubikey + pkgs.yubikey-manager + pkgs.pcsc-tools + ]; + + shellHook = '' + ${config.pre-commit.settings.shellHook} + + export SOPS_AGE_KEY_FILE="$HOME/.config/sops/age/yubikey-identity.txt" + ''; + }; + }; +} diff --git a/shells/jupyter.nix b/shells/jupyter.nix deleted file mode 100644 index 36138af..0000000 --- a/shells/jupyter.nix +++ /dev/null @@ -1,46 +0,0 @@ -{ pkgs }: -let - py = pkgs.python312; - pyEnv = py.withPackages ( - ps: with ps; [ - ipykernel - notebook - jupyterlab - numpy - pandas - matplotlib - scipy - scikit-learn - - pyathena - python-dotenv - plotly - seaborn - ] - ); -in -pkgs.mkShell { - name = "jupyter-notebook"; - - packages = with pkgs; [ - pyEnv - zsh - ]; - - PYTHONNOUSERSITE = "1"; - JUPYTER_CONFIG_DIR = "$PWD/.jupyter"; - IPYTHONDIR = "$PWD/.ipython"; - - shellHook = '' - set -e - - if command -v python >/dev/null; then - echo "📓 jupyter shell → python $(python -V | awk '{print $2}')" - fi - - if [ -z "''${ZSH_VERSION:-}" ] && [[ $- == *i* ]] && [ -t 1 ] && [ -z "''${NIX_SHELL_ZSH_ACTIVATED:-}" ]; then - export NIX_SHELL_ZSH_ACTIVATED=1 - exec ${pkgs.zsh}/bin/zsh -i - fi - ''; -} diff --git a/shells/next-web.nix b/shells/next-web.nix deleted file mode 100644 index 2b079a7..0000000 --- a/shells/next-web.nix +++ /dev/null @@ -1,66 +0,0 @@ -{ pkgs }: -let - node = pkgs.nodejs_24; -in -pkgs.mkShell { - name = "next-web"; - - packages = with pkgs; [ - node - nodePackages_latest.pnpm - nodePackages_latest.vercel - nodePackages_latest.prisma - zsh - openssl - pkg-config - jq - ngrok - ]; - - NODE_ENV = "development"; - - shellHook = '' - # corepack store under repo (avoid polluting home) - export COREPACK_HOME="$PWD/.corepack" - - # pnpm global bin dir (NixOS/zshでも確実に有効にする) - export PNPM_HOME="''${XDG_DATA_HOME:-$HOME/.local/share}/pnpm" - mkdir -p "$PNPM_HOME" - case ":$PATH:" in - *":$PNPM_HOME:"*) ;; - *) export PATH="$PNPM_HOME:$PATH" ;; - esac - - # Prisma engines from nixpkgs (avoid binaries.prisma.sh fetch on NixOS) - export PKG_CONFIG_PATH="${pkgs.openssl.dev}/lib/pkgconfig" - export PRISMA_FMT_BINARY="${pkgs.prisma-engines}/bin/prisma-fmt" - - # ---- show tool versions - if command -v node >/dev/null; then - echo "next-web shell -> node $(node -v)" - fi - if command -v pnpm >/dev/null; then - echo " pnpm $(pnpm --version)" - echo " PNPM_HOME=$PNPM_HOME" - fi - - # Activate packageManager from package.json if present. - if command -v corepack >/dev/null 2>&1; then - if [ -f package.json ] && command -v jq >/dev/null 2>&1 && jq -e '.packageManager' package.json >/dev/null; then - COREPACK_ENABLE_DOWNLOADS=1 corepack prepare --activate || true - fi - fi - - # ---- switch to zsh (interactive only). Don't break `nix develop -c ...` - if [ -z "''${ZSH_VERSION:-}" ] && [[ $- == *i* ]] && [ -t 1 ] && [ -z "''${NIX_SHELL_ZSH_ACTIVATED:-}" ]; then - export NIX_SHELL_ZSH_ACTIVATED=1 - exec ${pkgs.zsh}/bin/zsh -i - fi - ''; - - env = { - PRISMA_QUERY_ENGINE_LIBRARY = "${pkgs.prisma-engines}/lib/libquery_engine.node"; - PRISMA_QUERY_ENGINE_BINARY = "${pkgs.prisma-engines}/bin/query-engine"; - PRISMA_SCHEMA_ENGINE_BINARY = "${pkgs.prisma-engines}/bin/schema-engine"; - }; -} diff --git a/shells/rust/default.nix b/shells/rust/default.nix deleted file mode 100644 index 147c23b..0000000 --- a/shells/rust/default.nix +++ /dev/null @@ -1,49 +0,0 @@ -# ref: https://nixos.wiki/wiki/Rust - -{ pkgs ? import {} }: - let - overrides = (builtins.fromTOML (builtins.readFile ./rust-toolchain.toml)); - libPath = with pkgs; lib.makeLibraryPath [ - # load external libraries that you need in your rust project here - ]; -in - pkgs.mkShell rec { - nativeBuildInputs = [ pkgs.pkg-config ]; - buildInputs = with pkgs; [ - clang - # Replace llvmPackages with llvmPackages_X, where X is the latest LLVM version (at the time of writing, 16) - llvmPackages.bintools - rustup - ]; - - RUSTC_VERSION = overrides.toolchain.channel; - - # https://github.com/rust-lang/rust-bindgen#environment-variables - LIBCLANG_PATH = pkgs.lib.makeLibraryPath [ pkgs.llvmPackages_latest.libclang.lib ]; - - shellHook = '' - export PATH=$PATH:''${CARGO_HOME:-~/.cargo}/bin - export PATH=$PATH:''${RUSTUP_HOME:-~/.rustup}/toolchains/$RUSTC_VERSION-x86_64-unknown-linux-gnu/bin/ - ''; - - # Add precompiled library to rustc search path - RUSTFLAGS = (builtins.map (a: ''-L ${a}/lib'') [ - # add libraries here (e.g. pkgs.libvmi) - ]); - - LD_LIBRARY_PATH = libPath; - - # Add glibc, clang, glib, and other headers to bindgen search path - BINDGEN_EXTRA_CLANG_ARGS = - # Includes normal include path - (builtins.map (a: ''-I"${a}/include"'') [ - # add dev libraries here (e.g. pkgs.libvmi.dev) - pkgs.glibc.dev - ]) - # Includes with special directory paths - ++ [ - ''-I"${pkgs.llvmPackages_latest.libclang.lib}/lib/clang/${pkgs.llvmPackages_latest.libclang.version}/include"'' - ''-I"${pkgs.glib.dev}/include/glib-2.0"'' - ''-I${pkgs.glib.out}/lib/glib-2.0/include/'' - ]; - } \ No newline at end of file diff --git a/shells/rust/rust-toolchain.toml b/shells/rust/rust-toolchain.toml deleted file mode 100644 index 292fe49..0000000 --- a/shells/rust/rust-toolchain.toml +++ /dev/null @@ -1,2 +0,0 @@ -[toolchain] -channel = "stable"