This commit is contained in:
2026-07-30 16:46:44 +09:00
parent ee9ce66d55
commit b477446f5c
12 changed files with 266 additions and 33 deletions
+65 -31
View File
@@ -35,31 +35,33 @@ Before adding configuration, decide whether it is owned by an application,
system foundation, service, hardware family, user, profile, or individual host. system foundation, service, hardware family, user, profile, or individual host.
Prefer the following placements: Prefer the following placements:
| Configuration | Placement | | Configuration | Placement |
| ---------------------------------------------------- | ------------------------------------------------------- | | ---------------------------------------------------- | --------------------------------------------------------- |
| Nix settings shared by every system host | `modules/systems/nix/common.nix` | | Nix settings shared by every system host | `modules/systems/nix/common.nix` |
| NixOS-only boot configuration | `modules/systems/boot/.../nixos.nix` | | NixOS-only boot configuration | `modules/systems/boot/.../nixos.nix` |
| Disko NixOS module and CLI | `modules/systems/disko/` | | Disko NixOS module and CLI | `modules/systems/disko/` |
| macOS-wide input, document, and dialog defaults | `modules/systems/macos-defaults/darwin.nix` | | macOS-wide input, document, and dialog defaults | `modules/systems/macos-defaults/darwin.nix` |
| macOS Dock defaults | `modules/systems/dock/darwin.nix` | | macOS Dock defaults | `modules/systems/dock/darwin.nix` |
| macOS trackpad defaults | `modules/systems/trackpad/darwin.nix` | | macOS trackpad defaults | `modules/systems/trackpad/darwin.nix` |
| Finder-specific preferences | `modules/applications/finder/darwin.nix` | | Finder-specific preferences | `modules/applications/finder/darwin.nix` |
| Ghostty-specific configuration | `modules/applications/ghostty/` | | Ghostty-specific configuration | `modules/applications/ghostty/` |
| niri-specific configuration | `modules/applications/niri/` | | niri-specific configuration | `modules/applications/niri/` |
| Desktop applications shared by labwc and niri | `modules/profiles/interface/linux-desktop/meta.nix` | | Desktop applications shared by labwc and niri | `modules/profiles/interface/linux-desktop/meta.nix` |
| Applications and services specific to niri | `modules/profiles/interface/niri/meta.nix` | | Applications and services specific to niri | `modules/profiles/interface/niri/meta.nix` |
| labwc and its session configuration | `modules/applications/labwc/` | | labwc and its session configuration | `modules/applications/labwc/` |
| A Linux package plus its macOS Homebrew cask | `modules/applications/<name>/home.nix` and `darwin.nix` | | A Linux package plus its macOS Homebrew cask | `modules/applications/<name>/home.nix` and `darwin.nix` |
| Docker daemon and Docker group membership | `modules/services/docker/nixos.nix` | | Docker daemon and Docker group membership | `modules/services/docker/nixos.nix` |
| The laptop unit composition | `modules/profiles/platform/laptop/meta.nix` | | The laptop unit composition | `modules/profiles/platform/laptop/meta.nix` |
| The Intel ThinkPad X1 composition | `modules/profiles/platform/thinkpad-x1/meta.nix` | | The Intel ThinkPad X1 composition | `modules/profiles/platform/thinkpad-x1/meta.nix` |
| The development-environment unit composition | `modules/profiles/workload/development/meta.nix` | | The Intel/NVIDIA desktop composition | `modules/profiles/platform/intel-nvidia-desktop/meta.nix` |
| Cross-platform fingerprint selection | `modules/profiles/security/fingerprint/meta.nix` | | NVIDIA GPU driver configuration | `modules/hardwares/nvidia/` |
| A user's OS- and Home Manager-specific configuration | `modules/users/<name>/` | | The development-environment unit composition | `modules/profiles/workload/development/meta.nix` |
| Host-specific monitor layout | `hosts/<name>/home.nix` | | Cross-platform fingerprint selection | `modules/profiles/security/fingerprint/meta.nix` |
| Generated host disk UUIDs | `hosts/<name>/hardware-configuration.nix` | | A user's OS- and Home Manager-specific configuration | `modules/users/<name>/` |
| Package replacement or addition | `overlays/` | | Host-specific monitor layout | `hosts/<name>/home.nix` |
| Formatter, checks, or Git hooks | `flake/` | | Generated host disk UUIDs | `hosts/<name>/hardware-configuration.nix` |
| Package replacement or addition | `overlays/` |
| Formatter, checks, or Git hooks | `flake/` |
## Unit Discovery and Identity ## Unit Discovery and Identity
@@ -344,6 +346,7 @@ modules/profiles/
│ └── tailscale-subnet-router/ │ └── tailscale-subnet-router/
├── platform/ ├── platform/
│ ├── nixos/ │ ├── nixos/
│ ├── intel-nvidia-desktop/
│ ├── laptop/ │ ├── laptop/
│ ├── thinkpad-x1/ │ ├── thinkpad-x1/
│ ├── desktop/ │ ├── desktop/
@@ -583,6 +586,27 @@ A host registry may use a specification like this:
]; ];
}; };
galleria = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./galleria;
profiles = [
"base"
"interface.cli"
"interface.labwc"
"interface.niri"
"platform.intel-nvidia-desktop"
"security.secrets"
"security.secure-boot"
"security.tpm-storage"
"workload.development"
"workload.game"
"workload.personal"
];
};
m2 = { m2 = {
system = "aarch64-darwin"; system = "aarch64-darwin";
stateVersion = "26.05"; stateVersion = "26.05";
@@ -608,9 +632,11 @@ installation ISO without Home Manager. x1g9 is a full NixOS desktop with niri,
labwc, ly, the shared Linux desktop applications, and the personal workload. labwc, ly, the shared Linux desktop applications, and the personal workload.
x1g13 is the secure NixOS development and personal ThinkPad, with the same x1g13 is the secure NixOS development and personal ThinkPad, with the same
desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk
unlock. m2 is the daily-use macOS development and personal machine with the unlock. galleria is the Intel/NVIDIA physical desktop shared with Windows; it
macOS interface defaults. Keep the desktop sessions independently selectable, uses dedicated NixOS partitions, LUKS, Secure Boot, and TPM-backed disk unlock.
and keep the development and personal profiles usable across NixOS and Darwin. m2 is the daily-use macOS development and personal machine with the macOS
interface defaults. Keep the desktop sessions independently selectable, and
keep the development and personal profiles usable across NixOS and Darwin.
Treat entries in `profiles` and the exceptional `applications` field as IDs Treat entries in `profiles` and the exceptional `applications` field as IDs
relative to their respective category roots. Add the category prefixes during relative to their respective category roots. Add the category prefixes during
@@ -651,6 +677,11 @@ hosts/
├── ops/ ├── ops/
│ ├── nixos.nix │ ├── nixos.nix
│ └── hardware-configuration.nix │ └── hardware-configuration.nix
├── galleria/
│ ├── disk-identifiers.nix
│ ├── disko.nix
│ ├── hardware-configuration.nix
│ └── nixos.nix
├── x1g9/ ├── x1g9/
│ ├── nixos.nix │ ├── nixos.nix
│ └── hardware-configuration.nix │ └── hardware-configuration.nix
@@ -667,7 +698,9 @@ hosts/
normal top-level Nix module `imports`. `hosts/x1g13/nixos.nix` loads its normal top-level Nix module `imports`. `hosts/x1g13/nixos.nix` loads its
generated hardware configuration and host-local `disko.nix` the same way. Do generated hardware configuration and host-local `disko.nix` the same way. Do
not confuse these host imports with the prohibition on top-level `imports` in not confuse these host imports with the prohibition on top-level `imports` in
unit configuration fragments. unit configuration fragments. `hosts/galleria/disko.nix` manages only the two
dedicated NixOS partitions by PARTUUID and deliberately excludes the Windows
disk, Windows partitions, and the Windows EFI System Partition.
Derive the system class from the host's `system`: Derive the system class from the host's `system`:
@@ -770,8 +803,9 @@ For profile changes, additionally:
the container server VM; installer remains the Home Manager-free installation the container server VM; installer remains the Home Manager-free installation
ISO; x1g9 provides niri, labwc, ly, and the personal application set; x1g13 ISO; x1g9 provides niri, labwc, ly, and the personal application set; x1g13
additionally provides the development, Tailscale client, secrets, Secure Boot, additionally provides the development, Tailscale client, secrets, Secure Boot,
and TPM storage roles; m2 remains the daily-use development and personal and TPM storage roles; galleria remains the Intel/NVIDIA dual-boot desktop
machine. with LUKS, Secure Boot, and TPM storage; m2 remains the daily-use development
and personal machine.
## Commit and Pull Request Guidelines ## Commit and Pull Request Guidelines
+21
View File
@@ -93,6 +93,27 @@
]; ];
}; };
galleria = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./galleria;
profiles = [
"base"
"interface.cli"
"interface.labwc"
"interface.niri"
"platform.intel-nvidia-desktop"
"security.secrets"
"security.secure-boot"
"security.tpm-storage"
"workload.development"
"workload.game"
"workload.personal"
];
};
m2 = { m2 = {
system = "aarch64-darwin"; system = "aarch64-darwin";
stateVersion = "26.05"; stateVersion = "26.05";
+5
View File
@@ -0,0 +1,5 @@
{
# Replace both values after creating the two dedicated NixOS partitions.
espPartUuid = "REPLACE-WITH-GALLERIA-ESP-PARTUUID";
nixosPartUuid = "REPLACE-WITH-GALLERIA-NIXOS-PARTUUID";
}
+92
View File
@@ -0,0 +1,92 @@
_:
let
diskIdentifiers = import ./disk-identifiers.nix;
espPart = "/dev/disk/by-partuuid/${diskIdentifiers.espPartUuid}";
nixosPart = "/dev/disk/by-partuuid/${diskIdentifiers.nixosPartUuid}";
btrfsMountOptions = [
"compress=zstd"
"noatime"
"ssd"
"space_cache=v2"
];
in
{
disko.enableConfig = true;
# These are deliberately partition paths, not the whole Windows disk. Disko
# must never own or destroy the disk's GPT or any Windows partition.
disko.devices.disk = {
esp = {
type = "disk";
device = espPart;
destroy = false;
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
nixos = {
type = "disk";
device = nixosPart;
destroy = false;
content = {
type = "luks";
name = "cryptroot";
askPassword = true;
settings.allowDiscards = true;
extraFormatArgs = [
"--type"
"luks2"
"--pbkdf"
"argon2id"
"--label"
"NixOS-LUKS"
];
content = {
type = "btrfs";
extraArgs = [
"-f"
"-L"
"NixOS"
];
subvolumes = {
"@root" = {
mountpoint = "/";
mountOptions = btrfsMountOptions;
};
"@home" = {
mountpoint = "/home";
mountOptions = btrfsMountOptions;
};
"@nix" = {
mountpoint = "/nix";
mountOptions = btrfsMountOptions;
};
"@log" = {
mountpoint = "/var/log";
mountOptions = btrfsMountOptions;
};
"@swap" = {
mountpoint = "/.swapvol";
mountOptions = [ "noatime" ];
swap.swapfile.size = "32G";
};
};
};
};
};
};
}
+30
View File
@@ -0,0 +1,30 @@
# Bootstrap hardware configuration. Replace this file with the output of
# nixos-generate-config on galleria before installing the system.
{
config,
lib,
modulesPath,
...
}:
{
imports = [ (modulesPath + "/installer/scan/not-detected.nix") ];
boot.initrd.availableKernelModules = [
"ahci"
"nvme"
"xhci_pci"
"usb_storage"
"usbhid"
"sd_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
swapDevices = [ ];
networking.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
+13
View File
@@ -0,0 +1,13 @@
_:
let
diskIdentifiers = import ./disk-identifiers.nix;
in
{
imports = [
./hardware-configuration.nix
./disko.nix
];
boot.initrd.luks.devices.cryptroot.device =
"/dev/disk/by-partuuid/${diskIdentifiers.nixosPartUuid}";
}
+5
View File
@@ -51,6 +51,11 @@
parted parted
cryptsetup cryptsetup
btrfs-progs btrfs-progs
efibootmgr
pciutils
sbctl
tpm2-tools
util-linux
]; ];
services.pcscd.enable = true; services.pcscd.enable = true;
+6
View File
@@ -0,0 +1,6 @@
{ config, lib, ... }:
{
boot.kernelModules = lib.mkDefault [ "kvm-intel" ];
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
+5
View File
@@ -0,0 +1,5 @@
{
description = "NVIDIA desktop graphics";
includes = [ "hardwares.graphics" ];
}
+11
View File
@@ -0,0 +1,11 @@
{
services.xserver.videoDrivers = [ "nvidia" ];
hardware.nvidia = {
modesetting.enable = true;
nvidiaSettings = true;
# RTX 3060 Ti (Ampere) supports NVIDIA's open kernel modules.
open = true;
};
}
+4 -2
View File
@@ -31,6 +31,7 @@ when removing it from any supported host would make that host invalid.
| `interface.niri` | NixOS with Home Manager | | `interface.niri` | NixOS with Home Manager |
| `platform.nixos` | NixOS | | `platform.nixos` | NixOS |
| `platform.desktop` | Physical NixOS desktop | | `platform.desktop` | Physical NixOS desktop |
| `platform.intel-nvidia-desktop` | Intel/NVIDIA physical NixOS desktop |
| `platform.laptop` | Physical NixOS laptop | | `platform.laptop` | Physical NixOS laptop |
| `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS | | `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS |
| `platform.vm` | UEFI QEMU NixOS guest with NFS client support | | `platform.vm` | UEFI QEMU NixOS guest with NFS client support |
@@ -48,8 +49,9 @@ when removing it from any supported host would make that host invalid.
Select independent concerns independently in `hosts/default.nix`. For example, Select independent concerns independently in `hosts/default.nix`. For example,
a NixOS desktop can combine `interface.labwc` and `interface.niri` to provide a NixOS desktop can combine `interface.labwc` and `interface.niri` to provide
both sessions while sharing `interface.linux-desktop` and `interface.gui`; both both sessions while sharing `interface.linux-desktop` and `interface.gui`.
session profiles select ly. A The shared Linux desktop profile provides the resident application drawer and
four-finger pinch gesture service; both session profiles select ly. A
daily-use macOS development machine can combine `interface.macos`, daily-use macOS development machine can combine `interface.macos`,
`workload.development`, and `workload.personal`. Hardware support does not `workload.development`, and `workload.personal`. Hardware support does not
implicitly select an interface or workload. implicitly select an interface or workload.
@@ -0,0 +1,9 @@
{
description = "Physical NixOS desktop with an Intel CPU and NVIDIA GPU";
includes = [
"profiles.platform.desktop"
"hardwares.intel-cpu"
"hardwares.nvidia"
];
}