diff --git a/AGENTS.md b/AGENTS.md index dce8dbf..bb04ed8 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -35,31 +35,33 @@ Before adding configuration, decide whether it is owned by an application, system foundation, service, hardware family, user, profile, or individual host. Prefer the following placements: -| Configuration | Placement | -| ---------------------------------------------------- | ------------------------------------------------------- | -| Nix settings shared by every system host | `modules/systems/nix/common.nix` | -| NixOS-only boot configuration | `modules/systems/boot/.../nixos.nix` | -| Disko NixOS module and CLI | `modules/systems/disko/` | -| macOS-wide input, document, and dialog defaults | `modules/systems/macos-defaults/darwin.nix` | -| macOS Dock defaults | `modules/systems/dock/darwin.nix` | -| macOS trackpad defaults | `modules/systems/trackpad/darwin.nix` | -| Finder-specific preferences | `modules/applications/finder/darwin.nix` | -| Ghostty-specific configuration | `modules/applications/ghostty/` | -| niri-specific configuration | `modules/applications/niri/` | -| Desktop applications shared by labwc and niri | `modules/profiles/interface/linux-desktop/meta.nix` | -| Applications and services specific to niri | `modules/profiles/interface/niri/meta.nix` | -| labwc and its session configuration | `modules/applications/labwc/` | -| A Linux package plus its macOS Homebrew cask | `modules/applications//home.nix` and `darwin.nix` | -| Docker daemon and Docker group membership | `modules/services/docker/nixos.nix` | -| The laptop unit composition | `modules/profiles/platform/laptop/meta.nix` | -| The Intel ThinkPad X1 composition | `modules/profiles/platform/thinkpad-x1/meta.nix` | -| The development-environment unit composition | `modules/profiles/workload/development/meta.nix` | -| Cross-platform fingerprint selection | `modules/profiles/security/fingerprint/meta.nix` | -| A user's OS- and Home Manager-specific configuration | `modules/users//` | -| Host-specific monitor layout | `hosts//home.nix` | -| Generated host disk UUIDs | `hosts//hardware-configuration.nix` | -| Package replacement or addition | `overlays/` | -| Formatter, checks, or Git hooks | `flake/` | +| Configuration | Placement | +| ---------------------------------------------------- | --------------------------------------------------------- | +| Nix settings shared by every system host | `modules/systems/nix/common.nix` | +| NixOS-only boot configuration | `modules/systems/boot/.../nixos.nix` | +| Disko NixOS module and CLI | `modules/systems/disko/` | +| macOS-wide input, document, and dialog defaults | `modules/systems/macos-defaults/darwin.nix` | +| macOS Dock defaults | `modules/systems/dock/darwin.nix` | +| macOS trackpad defaults | `modules/systems/trackpad/darwin.nix` | +| Finder-specific preferences | `modules/applications/finder/darwin.nix` | +| Ghostty-specific configuration | `modules/applications/ghostty/` | +| niri-specific configuration | `modules/applications/niri/` | +| Desktop applications shared by labwc and niri | `modules/profiles/interface/linux-desktop/meta.nix` | +| Applications and services specific to niri | `modules/profiles/interface/niri/meta.nix` | +| labwc and its session configuration | `modules/applications/labwc/` | +| A Linux package plus its macOS Homebrew cask | `modules/applications//home.nix` and `darwin.nix` | +| Docker daemon and Docker group membership | `modules/services/docker/nixos.nix` | +| The laptop unit composition | `modules/profiles/platform/laptop/meta.nix` | +| The Intel ThinkPad X1 composition | `modules/profiles/platform/thinkpad-x1/meta.nix` | +| The Intel/NVIDIA desktop composition | `modules/profiles/platform/intel-nvidia-desktop/meta.nix` | +| NVIDIA GPU driver configuration | `modules/hardwares/nvidia/` | +| The development-environment unit composition | `modules/profiles/workload/development/meta.nix` | +| Cross-platform fingerprint selection | `modules/profiles/security/fingerprint/meta.nix` | +| A user's OS- and Home Manager-specific configuration | `modules/users//` | +| Host-specific monitor layout | `hosts//home.nix` | +| Generated host disk UUIDs | `hosts//hardware-configuration.nix` | +| Package replacement or addition | `overlays/` | +| Formatter, checks, or Git hooks | `flake/` | ## Unit Discovery and Identity @@ -344,6 +346,7 @@ modules/profiles/ │ └── tailscale-subnet-router/ ├── platform/ │ ├── nixos/ +│ ├── intel-nvidia-desktop/ │ ├── laptop/ │ ├── thinkpad-x1/ │ ├── desktop/ @@ -583,6 +586,27 @@ A host registry may use a specification like this: ]; }; + galleria = { + system = "x86_64-linux"; + stateVersion = "26.05"; + user = "moons"; + path = ./galleria; + + profiles = [ + "base" + "interface.cli" + "interface.labwc" + "interface.niri" + "platform.intel-nvidia-desktop" + "security.secrets" + "security.secure-boot" + "security.tpm-storage" + "workload.development" + "workload.game" + "workload.personal" + ]; + }; + m2 = { system = "aarch64-darwin"; stateVersion = "26.05"; @@ -608,9 +632,11 @@ installation ISO without Home Manager. x1g9 is a full NixOS desktop with niri, labwc, ly, the shared Linux desktop applications, and the personal workload. x1g13 is the secure NixOS development and personal ThinkPad, with the same desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk -unlock. m2 is the daily-use macOS development and personal machine with the -macOS interface defaults. Keep the desktop sessions independently selectable, -and keep the development and personal profiles usable across NixOS and Darwin. +unlock. galleria is the Intel/NVIDIA physical desktop shared with Windows; it +uses dedicated NixOS partitions, LUKS, Secure Boot, and TPM-backed disk unlock. +m2 is the daily-use macOS development and personal machine with the macOS +interface defaults. Keep the desktop sessions independently selectable, and +keep the development and personal profiles usable across NixOS and Darwin. Treat entries in `profiles` and the exceptional `applications` field as IDs relative to their respective category roots. Add the category prefixes during @@ -651,6 +677,11 @@ hosts/ ├── ops/ │ ├── nixos.nix │ └── hardware-configuration.nix +├── galleria/ +│ ├── disk-identifiers.nix +│ ├── disko.nix +│ ├── hardware-configuration.nix +│ └── nixos.nix ├── x1g9/ │ ├── nixos.nix │ └── hardware-configuration.nix @@ -667,7 +698,9 @@ hosts/ normal top-level Nix module `imports`. `hosts/x1g13/nixos.nix` loads its generated hardware configuration and host-local `disko.nix` the same way. Do not confuse these host imports with the prohibition on top-level `imports` in -unit configuration fragments. +unit configuration fragments. `hosts/galleria/disko.nix` manages only the two +dedicated NixOS partitions by PARTUUID and deliberately excludes the Windows +disk, Windows partitions, and the Windows EFI System Partition. Derive the system class from the host's `system`: @@ -770,8 +803,9 @@ For profile changes, additionally: the container server VM; installer remains the Home Manager-free installation ISO; x1g9 provides niri, labwc, ly, and the personal application set; x1g13 additionally provides the development, Tailscale client, secrets, Secure Boot, - and TPM storage roles; m2 remains the daily-use development and personal - machine. + and TPM storage roles; galleria remains the Intel/NVIDIA dual-boot desktop + with LUKS, Secure Boot, and TPM storage; m2 remains the daily-use development + and personal machine. ## Commit and Pull Request Guidelines diff --git a/hosts/default.nix b/hosts/default.nix index 75c2044..847ac1a 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -93,6 +93,27 @@ ]; }; + galleria = { + system = "x86_64-linux"; + stateVersion = "26.05"; + user = "moons"; + path = ./galleria; + + profiles = [ + "base" + "interface.cli" + "interface.labwc" + "interface.niri" + "platform.intel-nvidia-desktop" + "security.secrets" + "security.secure-boot" + "security.tpm-storage" + "workload.development" + "workload.game" + "workload.personal" + ]; + }; + m2 = { system = "aarch64-darwin"; stateVersion = "26.05"; diff --git a/hosts/galleria/disk-identifiers.nix b/hosts/galleria/disk-identifiers.nix new file mode 100644 index 0000000..71cd5c1 --- /dev/null +++ b/hosts/galleria/disk-identifiers.nix @@ -0,0 +1,5 @@ +{ + # Replace both values after creating the two dedicated NixOS partitions. + espPartUuid = "REPLACE-WITH-GALLERIA-ESP-PARTUUID"; + nixosPartUuid = "REPLACE-WITH-GALLERIA-NIXOS-PARTUUID"; +} diff --git a/hosts/galleria/disko.nix b/hosts/galleria/disko.nix new file mode 100644 index 0000000..c556b15 --- /dev/null +++ b/hosts/galleria/disko.nix @@ -0,0 +1,92 @@ +_: +let + diskIdentifiers = import ./disk-identifiers.nix; + espPart = "/dev/disk/by-partuuid/${diskIdentifiers.espPartUuid}"; + nixosPart = "/dev/disk/by-partuuid/${diskIdentifiers.nixosPartUuid}"; + + btrfsMountOptions = [ + "compress=zstd" + "noatime" + "ssd" + "space_cache=v2" + ]; +in +{ + disko.enableConfig = true; + + # These are deliberately partition paths, not the whole Windows disk. Disko + # must never own or destroy the disk's GPT or any Windows partition. + disko.devices.disk = { + esp = { + type = "disk"; + device = espPart; + destroy = false; + + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + mountOptions = [ "umask=0077" ]; + }; + }; + + nixos = { + type = "disk"; + device = nixosPart; + destroy = false; + + content = { + type = "luks"; + name = "cryptroot"; + askPassword = true; + settings.allowDiscards = true; + + extraFormatArgs = [ + "--type" + "luks2" + "--pbkdf" + "argon2id" + "--label" + "NixOS-LUKS" + ]; + + content = { + type = "btrfs"; + extraArgs = [ + "-f" + "-L" + "NixOS" + ]; + + subvolumes = { + "@root" = { + mountpoint = "/"; + mountOptions = btrfsMountOptions; + }; + + "@home" = { + mountpoint = "/home"; + mountOptions = btrfsMountOptions; + }; + + "@nix" = { + mountpoint = "/nix"; + mountOptions = btrfsMountOptions; + }; + + "@log" = { + mountpoint = "/var/log"; + mountOptions = btrfsMountOptions; + }; + + "@swap" = { + mountpoint = "/.swapvol"; + mountOptions = [ "noatime" ]; + swap.swapfile.size = "32G"; + }; + }; + }; + }; + }; + }; +} diff --git a/hosts/galleria/hardware-configuration.nix b/hosts/galleria/hardware-configuration.nix new file mode 100644 index 0000000..345cb57 --- /dev/null +++ b/hosts/galleria/hardware-configuration.nix @@ -0,0 +1,30 @@ +# Bootstrap hardware configuration. Replace this file with the output of +# nixos-generate-config on galleria before installing the system. +{ + config, + lib, + modulesPath, + ... +}: +{ + imports = [ (modulesPath + "/installer/scan/not-detected.nix") ]; + + boot.initrd.availableKernelModules = [ + "ahci" + "nvme" + "xhci_pci" + "usb_storage" + "usbhid" + "sd_mod" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.extraModulePackages = [ ]; + + swapDevices = [ ]; + + networking.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/hosts/galleria/nixos.nix b/hosts/galleria/nixos.nix new file mode 100644 index 0000000..6d3e5c2 --- /dev/null +++ b/hosts/galleria/nixos.nix @@ -0,0 +1,13 @@ +_: +let + diskIdentifiers = import ./disk-identifiers.nix; +in +{ + imports = [ + ./hardware-configuration.nix + ./disko.nix + ]; + + boot.initrd.luks.devices.cryptroot.device = + "/dev/disk/by-partuuid/${diskIdentifiers.nixosPartUuid}"; +} diff --git a/hosts/installer/nixos.nix b/hosts/installer/nixos.nix index d6ce7e5..e46f5f2 100644 --- a/hosts/installer/nixos.nix +++ b/hosts/installer/nixos.nix @@ -51,6 +51,11 @@ parted cryptsetup btrfs-progs + efibootmgr + pciutils + sbctl + tpm2-tools + util-linux ]; services.pcscd.enable = true; diff --git a/modules/hardwares/intel-cpu/nixos.nix b/modules/hardwares/intel-cpu/nixos.nix new file mode 100644 index 0000000..ccfacdf --- /dev/null +++ b/modules/hardwares/intel-cpu/nixos.nix @@ -0,0 +1,6 @@ +{ config, lib, ... }: +{ + boot.kernelModules = lib.mkDefault [ "kvm-intel" ]; + + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/modules/hardwares/nvidia/meta.nix b/modules/hardwares/nvidia/meta.nix new file mode 100644 index 0000000..c32b136 --- /dev/null +++ b/modules/hardwares/nvidia/meta.nix @@ -0,0 +1,5 @@ +{ + description = "NVIDIA desktop graphics"; + + includes = [ "hardwares.graphics" ]; +} diff --git a/modules/hardwares/nvidia/nixos.nix b/modules/hardwares/nvidia/nixos.nix new file mode 100644 index 0000000..4bfe311 --- /dev/null +++ b/modules/hardwares/nvidia/nixos.nix @@ -0,0 +1,11 @@ +{ + services.xserver.videoDrivers = [ "nvidia" ]; + + hardware.nvidia = { + modesetting.enable = true; + nvidiaSettings = true; + + # RTX 3060 Ti (Ampere) supports NVIDIA's open kernel modules. + open = true; + }; +} diff --git a/modules/profiles/README.md b/modules/profiles/README.md index 2489bec..e1c9746 100644 --- a/modules/profiles/README.md +++ b/modules/profiles/README.md @@ -31,6 +31,7 @@ when removing it from any supported host would make that host invalid. | `interface.niri` | NixOS with Home Manager | | `platform.nixos` | NixOS | | `platform.desktop` | Physical NixOS desktop | +| `platform.intel-nvidia-desktop` | Intel/NVIDIA physical NixOS desktop | | `platform.laptop` | Physical NixOS laptop | | `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS | | `platform.vm` | UEFI QEMU NixOS guest with NFS client support | @@ -48,8 +49,9 @@ when removing it from any supported host would make that host invalid. Select independent concerns independently in `hosts/default.nix`. For example, a NixOS desktop can combine `interface.labwc` and `interface.niri` to provide -both sessions while sharing `interface.linux-desktop` and `interface.gui`; both -session profiles select ly. A +both sessions while sharing `interface.linux-desktop` and `interface.gui`. +The shared Linux desktop profile provides the resident application drawer and +four-finger pinch gesture service; both session profiles select ly. A daily-use macOS development machine can combine `interface.macos`, `workload.development`, and `workload.personal`. Hardware support does not implicitly select an interface or workload. diff --git a/modules/profiles/platform/intel-nvidia-desktop/meta.nix b/modules/profiles/platform/intel-nvidia-desktop/meta.nix new file mode 100644 index 0000000..511f92e --- /dev/null +++ b/modules/profiles/platform/intel-nvidia-desktop/meta.nix @@ -0,0 +1,9 @@ +{ + description = "Physical NixOS desktop with an Intel CPU and NVIDIA GPU"; + + includes = [ + "profiles.platform.desktop" + "hardwares.intel-cpu" + "hardwares.nvidia" + ]; +}