This commit is contained in:
2026-07-30 16:46:44 +09:00
parent ee9ce66d55
commit b477446f5c
12 changed files with 266 additions and 33 deletions
+21
View File
@@ -93,6 +93,27 @@
];
};
galleria = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./galleria;
profiles = [
"base"
"interface.cli"
"interface.labwc"
"interface.niri"
"platform.intel-nvidia-desktop"
"security.secrets"
"security.secure-boot"
"security.tpm-storage"
"workload.development"
"workload.game"
"workload.personal"
];
};
m2 = {
system = "aarch64-darwin";
stateVersion = "26.05";
+5
View File
@@ -0,0 +1,5 @@
{
# Replace both values after creating the two dedicated NixOS partitions.
espPartUuid = "REPLACE-WITH-GALLERIA-ESP-PARTUUID";
nixosPartUuid = "REPLACE-WITH-GALLERIA-NIXOS-PARTUUID";
}
+92
View File
@@ -0,0 +1,92 @@
_:
let
diskIdentifiers = import ./disk-identifiers.nix;
espPart = "/dev/disk/by-partuuid/${diskIdentifiers.espPartUuid}";
nixosPart = "/dev/disk/by-partuuid/${diskIdentifiers.nixosPartUuid}";
btrfsMountOptions = [
"compress=zstd"
"noatime"
"ssd"
"space_cache=v2"
];
in
{
disko.enableConfig = true;
# These are deliberately partition paths, not the whole Windows disk. Disko
# must never own or destroy the disk's GPT or any Windows partition.
disko.devices.disk = {
esp = {
type = "disk";
device = espPart;
destroy = false;
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
nixos = {
type = "disk";
device = nixosPart;
destroy = false;
content = {
type = "luks";
name = "cryptroot";
askPassword = true;
settings.allowDiscards = true;
extraFormatArgs = [
"--type"
"luks2"
"--pbkdf"
"argon2id"
"--label"
"NixOS-LUKS"
];
content = {
type = "btrfs";
extraArgs = [
"-f"
"-L"
"NixOS"
];
subvolumes = {
"@root" = {
mountpoint = "/";
mountOptions = btrfsMountOptions;
};
"@home" = {
mountpoint = "/home";
mountOptions = btrfsMountOptions;
};
"@nix" = {
mountpoint = "/nix";
mountOptions = btrfsMountOptions;
};
"@log" = {
mountpoint = "/var/log";
mountOptions = btrfsMountOptions;
};
"@swap" = {
mountpoint = "/.swapvol";
mountOptions = [ "noatime" ];
swap.swapfile.size = "32G";
};
};
};
};
};
};
}
+30
View File
@@ -0,0 +1,30 @@
# Bootstrap hardware configuration. Replace this file with the output of
# nixos-generate-config on galleria before installing the system.
{
config,
lib,
modulesPath,
...
}:
{
imports = [ (modulesPath + "/installer/scan/not-detected.nix") ];
boot.initrd.availableKernelModules = [
"ahci"
"nvme"
"xhci_pci"
"usb_storage"
"usbhid"
"sd_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
swapDevices = [ ];
networking.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
+13
View File
@@ -0,0 +1,13 @@
_:
let
diskIdentifiers = import ./disk-identifiers.nix;
in
{
imports = [
./hardware-configuration.nix
./disko.nix
];
boot.initrd.luks.devices.cryptroot.device =
"/dev/disk/by-partuuid/${diskIdentifiers.nixosPartUuid}";
}
+5
View File
@@ -51,6 +51,11 @@
parted
cryptsetup
btrfs-progs
efibootmgr
pciutils
sbctl
tpm2-tools
util-linux
];
services.pcscd.enable = true;