From bf94d1183f0d3d64571b2fcd63d1b95f617403b4 Mon Sep 17 00:00:00 2001 From: moons Date: Mon, 27 Jul 2026 18:31:50 +0900 Subject: [PATCH] add profiles --- hosts/default.nix | 7 ++- hosts/x1g9/hardware-configuration.nix | 52 +++++++++++++++++++ hosts/x1g9/hardware.nix | 1 - hosts/x1g9/nixos.nix | 2 +- modules/applications/gnupg/home.nix | 9 ++++ modules/applications/gnupg/nixos.nix | 6 +++ modules/applications/niri/meta.nix | 5 +- .../applications/niri/niri-home-module.nix | 9 ++++ modules/profiles/base/meta.nix | 4 +- .../interface/cli-interactive/home.nix | 4 ++ .../interface/cli-interactive/meta.nix | 10 ++++ .../profiles/interface/cli-minimal/home.nix | 34 ++++++++++++ .../profiles/interface/cli-minimal/meta.nix | 8 +++ modules/profiles/interface/gui/home.nix | 14 +++++ modules/profiles/interface/gui/meta.nix | 23 ++++++++ modules/profiles/interface/gui/nixos.nix | 8 +++ modules/profiles/platform/desktop/meta.nix | 5 ++ modules/profiles/platform/laptop/meta.nix | 5 ++ modules/profiles/platform/thinkpad/meta.nix | 8 +++ modules/profiles/platform/vm/meta.nix | 9 ++++ .../profiles/workload/development/home.nix | 13 +++++ .../profiles/workload/development/meta.nix | 16 ++++++ .../profiles/workload/development/nixos.nix | 3 ++ modules/profiles/workload/personal/meta.nix | 10 ++++ modules/profiles/workload/remote/meta.nix | 5 ++ .../profiles/workload/secure-storage/meta.nix | 8 +++ modules/profiles/workload/server/meta.nix | 8 +++ .../workload/tailscale/client/meta.nix | 5 ++ .../workload/tailscale/client/nixos.nix | 10 ++++ .../workload/tailscale/server/meta.nix | 5 ++ .../workload/tailscale/server/nixos.nix | 11 ++++ modules/services/tailscale/nixos.nix | 8 +-- modules/systems/boot/storage-crypto/nixos.nix | 11 ++++ modules/users/moons/home.nix | 5 +- 34 files changed, 327 insertions(+), 14 deletions(-) create mode 100644 hosts/x1g9/hardware-configuration.nix delete mode 100644 hosts/x1g9/hardware.nix create mode 100644 modules/applications/gnupg/home.nix create mode 100644 modules/applications/gnupg/nixos.nix create mode 100644 modules/applications/niri/niri-home-module.nix create mode 100644 modules/profiles/interface/cli-interactive/home.nix create mode 100644 modules/profiles/interface/cli-interactive/meta.nix create mode 100644 modules/profiles/interface/cli-minimal/home.nix create mode 100644 modules/profiles/interface/gui/home.nix create mode 100644 modules/profiles/interface/gui/meta.nix create mode 100644 modules/profiles/interface/gui/nixos.nix create mode 100644 modules/profiles/platform/desktop/meta.nix create mode 100644 modules/profiles/platform/thinkpad/meta.nix create mode 100644 modules/profiles/platform/vm/meta.nix create mode 100644 modules/profiles/workload/development/home.nix create mode 100644 modules/profiles/workload/development/meta.nix create mode 100644 modules/profiles/workload/development/nixos.nix create mode 100644 modules/profiles/workload/personal/meta.nix create mode 100644 modules/profiles/workload/remote/meta.nix create mode 100644 modules/profiles/workload/secure-storage/meta.nix create mode 100644 modules/profiles/workload/server/meta.nix create mode 100644 modules/profiles/workload/tailscale/client/meta.nix create mode 100644 modules/profiles/workload/tailscale/client/nixos.nix create mode 100644 modules/profiles/workload/tailscale/server/meta.nix create mode 100644 modules/profiles/workload/tailscale/server/nixos.nix create mode 100644 modules/systems/boot/storage-crypto/nixos.nix diff --git a/hosts/default.nix b/hosts/default.nix index 3be311a..b6308b6 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -7,8 +7,11 @@ profiles = [ "base" - "interface.cli-minimal" - "platform.laptop" + "interface.gui" + "platform.thinkpad" + "workload.development" + "workload.personal" + "workload.tailscale.client" ]; }; } diff --git a/hosts/x1g9/hardware-configuration.nix b/hosts/x1g9/hardware-configuration.nix new file mode 100644 index 0000000..02b18d2 --- /dev/null +++ b/hosts/x1g9/hardware-configuration.nix @@ -0,0 +1,52 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ + config, + lib, + modulesPath, + ... +}: + +{ + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ + "xhci_pci" + "thunderbolt" + "nvme" + "usb_storage" + "sd_mod" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = { + device = "/dev/disk/by-uuid/16b29578-6836-414b-a5e1-863bc21c5fc3"; + fsType = "ext4"; + }; + + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/209A-C8C9"; + fsType = "vfat"; + options = [ + "fmask=0077" + "dmask=0077" + ]; + }; + + swapDevices = [ ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.wlp0s20f3.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/hosts/x1g9/hardware.nix b/hosts/x1g9/hardware.nix deleted file mode 100644 index ffcd441..0000000 --- a/hosts/x1g9/hardware.nix +++ /dev/null @@ -1 +0,0 @@ -{ } diff --git a/hosts/x1g9/nixos.nix b/hosts/x1g9/nixos.nix index 83548c1..67c19d2 100644 --- a/hosts/x1g9/nixos.nix +++ b/hosts/x1g9/nixos.nix @@ -1,5 +1,5 @@ { imports = [ - ./hardware.nix + ./hardware-configuration.nix ]; } diff --git a/modules/applications/gnupg/home.nix b/modules/applications/gnupg/home.nix new file mode 100644 index 0000000..741340e --- /dev/null +++ b/modules/applications/gnupg/home.nix @@ -0,0 +1,9 @@ +{ pkgs, ... }: +{ + home.packages = [ pkgs.gnupg ]; + + services.gpg-agent = { + enable = false; + enableSshSupport = false; + }; +} diff --git a/modules/applications/gnupg/nixos.nix b/modules/applications/gnupg/nixos.nix new file mode 100644 index 0000000..2119103 --- /dev/null +++ b/modules/applications/gnupg/nixos.nix @@ -0,0 +1,6 @@ +{ + programs.gnupg.agent = { + enable = true; + enableSSHSupport = false; + }; +} diff --git a/modules/applications/niri/meta.nix b/modules/applications/niri/meta.nix index 7385a22..b7dced2 100644 --- a/modules/applications/niri/meta.nix +++ b/modules/applications/niri/meta.nix @@ -4,5 +4,8 @@ includes = [ "systems.wayland" ]; - imports.nixos = [ inputs.niri-flake.nixosModules.niri ]; + imports = { + nixos = [ inputs.niri-flake.nixosModules.niri ]; + home = [ ./niri-home-module.nix ]; + }; } diff --git a/modules/applications/niri/niri-home-module.nix b/modules/applications/niri/niri-home-module.nix new file mode 100644 index 0000000..95bcb4e --- /dev/null +++ b/modules/applications/niri/niri-home-module.nix @@ -0,0 +1,9 @@ +{ + inputs, + lib, + system, + ... +}: +{ + imports = lib.optional (lib.hasSuffix "-darwin" system) inputs.niri-flake.homeModules.niri; +} diff --git a/modules/profiles/base/meta.nix b/modules/profiles/base/meta.nix index 9ae68ac..c0e618c 100644 --- a/modules/profiles/base/meta.nix +++ b/modules/profiles/base/meta.nix @@ -2,9 +2,11 @@ description = "base system configuration"; includes = [ + "systems.boot.base" + "systems.disko" + "systems.hardware" "systems.locale" "systems.networking.base" - "systems.networking.wifi" "systems.nix" "systems.sops" ]; diff --git a/modules/profiles/interface/cli-interactive/home.nix b/modules/profiles/interface/cli-interactive/home.nix new file mode 100644 index 0000000..1fc56f9 --- /dev/null +++ b/modules/profiles/interface/cli-interactive/home.nix @@ -0,0 +1,4 @@ +{ pkgs, ... }: +{ + home.packages = [ pkgs.tio ]; +} diff --git a/modules/profiles/interface/cli-interactive/meta.nix b/modules/profiles/interface/cli-interactive/meta.nix new file mode 100644 index 0000000..1a16add --- /dev/null +++ b/modules/profiles/interface/cli-interactive/meta.nix @@ -0,0 +1,10 @@ +{ + description = "interactive command-line environment"; + + includes = [ + "profiles.interface.cli-minimal" + "applications.vim" + "applications.yazi" + "applications.zellij" + ]; +} diff --git a/modules/profiles/interface/cli-minimal/home.nix b/modules/profiles/interface/cli-minimal/home.nix new file mode 100644 index 0000000..8b1535b --- /dev/null +++ b/modules/profiles/interface/cli-minimal/home.nix @@ -0,0 +1,34 @@ +{ pkgs, ... }: +{ + home.packages = with pkgs; [ + bat + duf + dust + eza + fd + fastfetch + fzf + htop + jq + nurl + ripgrep + unrar + unzip + wget + ]; + + home.activation.generateSshKey = { + after = [ "writeBoundary" ]; + before = [ ]; + data = '' + key="$HOME/.ssh/id_ed25519" + if [ ! -f "$key" ]; then + umask 077 + mkdir -p "$HOME/.ssh" + ${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \ + -C "moons@$(${pkgs.hostname}/bin/hostname || echo host)" + echo "Generated SSH key at $key" + fi + ''; + }; +} diff --git a/modules/profiles/interface/cli-minimal/meta.nix b/modules/profiles/interface/cli-minimal/meta.nix index 00efff4..076124b 100644 --- a/modules/profiles/interface/cli-minimal/meta.nix +++ b/modules/profiles/interface/cli-minimal/meta.nix @@ -3,5 +3,13 @@ includes = [ "applications.btop" + "applications.direnv" + "applications.git" + "applications.gnupg" + "applications.nh" + "applications.nix-index" + "applications.ssh" + "applications.zoxide" + "applications.zsh" ]; } diff --git a/modules/profiles/interface/gui/home.nix b/modules/profiles/interface/gui/home.nix new file mode 100644 index 0000000..3c02fb6 --- /dev/null +++ b/modules/profiles/interface/gui/home.nix @@ -0,0 +1,14 @@ +{ + xdg.userDirs = { + enable = true; + createDirectories = true; + desktop = "$HOME/Desktop"; + documents = "$HOME/Documents"; + download = "$HOME/Downloads"; + music = "$HOME/Music"; + pictures = "$HOME/Pictures"; + publicShare = "$HOME/Public"; + templates = "$HOME/Templates"; + videos = "$HOME/Videos"; + }; +} diff --git a/modules/profiles/interface/gui/meta.nix b/modules/profiles/interface/gui/meta.nix new file mode 100644 index 0000000..18dca3a --- /dev/null +++ b/modules/profiles/interface/gui/meta.nix @@ -0,0 +1,23 @@ +{ + description = "NixOS graphical desktop environment"; + + includes = [ + "profiles.interface.cli-interactive" + "applications.1password" + "applications.fcitx5" + "applications.ghostty" + "applications.gnome" + "applications.gtk" + "applications.kde" + "applications.nautilus" + "applications.niri" + "applications.noctalia" + "applications.vicinae" + "hardwares.graphics" + "services.ly" + "services.swayidle" + "services.swaylock" + "systems.audio" + "systems.fonts" + ]; +} diff --git a/modules/profiles/interface/gui/nixos.nix b/modules/profiles/interface/gui/nixos.nix new file mode 100644 index 0000000..8e91684 --- /dev/null +++ b/modules/profiles/interface/gui/nixos.nix @@ -0,0 +1,8 @@ +{ pkgs, ... }: +{ + environment.systemPackages = with pkgs; [ + grim + slurp + wf-recorder + ]; +} diff --git a/modules/profiles/platform/desktop/meta.nix b/modules/profiles/platform/desktop/meta.nix new file mode 100644 index 0000000..502dfd0 --- /dev/null +++ b/modules/profiles/platform/desktop/meta.nix @@ -0,0 +1,5 @@ +{ + description = "UEFI desktop platform"; + + includes = [ "systems.boot.uefi" ]; +} diff --git a/modules/profiles/platform/laptop/meta.nix b/modules/profiles/platform/laptop/meta.nix index 57411c9..88721f8 100644 --- a/modules/profiles/platform/laptop/meta.nix +++ b/modules/profiles/platform/laptop/meta.nix @@ -2,6 +2,11 @@ description = "laptop platform configuration"; includes = [ + "hardwares.bluetooth" + "hardwares.ipu6-camera" "systems.boot.uefi" + "systems.fingerprint" + "systems.networking.wifi" + "systems.power" ]; } diff --git a/modules/profiles/platform/thinkpad/meta.nix b/modules/profiles/platform/thinkpad/meta.nix new file mode 100644 index 0000000..8408b1e --- /dev/null +++ b/modules/profiles/platform/thinkpad/meta.nix @@ -0,0 +1,8 @@ +{ + description = "ThinkPad laptop platform"; + + includes = [ + "profiles.platform.laptop" + "hardwares.intel-driver" + ]; +} diff --git a/modules/profiles/platform/vm/meta.nix b/modules/profiles/platform/vm/meta.nix new file mode 100644 index 0000000..16bc6c5 --- /dev/null +++ b/modules/profiles/platform/vm/meta.nix @@ -0,0 +1,9 @@ +{ + description = "virtual-machine platform"; + + includes = [ + "hardwares.qemu-guest" + "systems.boot.nfs" + "systems.boot.uefi" + ]; +} diff --git a/modules/profiles/workload/development/home.nix b/modules/profiles/workload/development/home.nix new file mode 100644 index 0000000..31615aa --- /dev/null +++ b/modules/profiles/workload/development/home.nix @@ -0,0 +1,13 @@ +{ lib, pkgs, ... }: +{ + home.packages = + with pkgs; + [ + bind + bun + nil + python312 + uv + ] + ++ lib.optionals stdenv.hostPlatform.isLinux [ drawio ]; +} diff --git a/modules/profiles/workload/development/meta.nix b/modules/profiles/workload/development/meta.nix new file mode 100644 index 0000000..9f4f487 --- /dev/null +++ b/modules/profiles/workload/development/meta.nix @@ -0,0 +1,16 @@ +{ + description = "software development workload"; + + includes = [ + "applications.arduino" + "applications.claude" + "applications.codex" + "applications.codex-desktop" + "applications.docker" + "applications.grok" + "applications.java" + "applications.opencode" + "applications.vscode" + "applications.zed" + ]; +} diff --git a/modules/profiles/workload/development/nixos.nix b/modules/profiles/workload/development/nixos.nix new file mode 100644 index 0000000..e0d1efc --- /dev/null +++ b/modules/profiles/workload/development/nixos.nix @@ -0,0 +1,3 @@ +{ + documentation.doc.enable = false; +} diff --git a/modules/profiles/workload/personal/meta.nix b/modules/profiles/workload/personal/meta.nix new file mode 100644 index 0000000..e25493c --- /dev/null +++ b/modules/profiles/workload/personal/meta.nix @@ -0,0 +1,10 @@ +{ + description = "personal communication and browser workload"; + + includes = [ + "applications.chrome" + "applications.discord" + "applications.slack" + "applications.zoom" + ]; +} diff --git a/modules/profiles/workload/remote/meta.nix b/modules/profiles/workload/remote/meta.nix new file mode 100644 index 0000000..b6173ac --- /dev/null +++ b/modules/profiles/workload/remote/meta.nix @@ -0,0 +1,5 @@ +{ + description = "remote-access workload"; + + includes = [ "services.openssh" ]; +} diff --git a/modules/profiles/workload/secure-storage/meta.nix b/modules/profiles/workload/secure-storage/meta.nix new file mode 100644 index 0000000..2327dc9 --- /dev/null +++ b/modules/profiles/workload/secure-storage/meta.nix @@ -0,0 +1,8 @@ +{ + description = "secure boot and TPM-backed storage"; + + includes = [ + "systems.boot.secure-boot" + "systems.boot.storage-crypto" + ]; +} diff --git a/modules/profiles/workload/server/meta.nix b/modules/profiles/workload/server/meta.nix new file mode 100644 index 0000000..a77b30e --- /dev/null +++ b/modules/profiles/workload/server/meta.nix @@ -0,0 +1,8 @@ +{ + description = "server workload"; + + includes = [ + "applications.docker" + "services.openssh" + ]; +} diff --git a/modules/profiles/workload/tailscale/client/meta.nix b/modules/profiles/workload/tailscale/client/meta.nix new file mode 100644 index 0000000..e36e64d --- /dev/null +++ b/modules/profiles/workload/tailscale/client/meta.nix @@ -0,0 +1,5 @@ +{ + description = "Tailscale client"; + + includes = [ "services.tailscale" ]; +} diff --git a/modules/profiles/workload/tailscale/client/nixos.nix b/modules/profiles/workload/tailscale/client/nixos.nix new file mode 100644 index 0000000..0c733c6 --- /dev/null +++ b/modules/profiles/workload/tailscale/client/nixos.nix @@ -0,0 +1,10 @@ +{ lib, ... }: +{ + services.tailscale = { + useRoutingFeatures = lib.mkForce "client"; + extraSetFlags = lib.mkForce [ + "--accept-dns=false" + "--accept-routes=true" + ]; + }; +} diff --git a/modules/profiles/workload/tailscale/server/meta.nix b/modules/profiles/workload/tailscale/server/meta.nix new file mode 100644 index 0000000..aec7d49 --- /dev/null +++ b/modules/profiles/workload/tailscale/server/meta.nix @@ -0,0 +1,5 @@ +{ + description = "Tailscale subnet-router server"; + + includes = [ "services.tailscale" ]; +} diff --git a/modules/profiles/workload/tailscale/server/nixos.nix b/modules/profiles/workload/tailscale/server/nixos.nix new file mode 100644 index 0000000..00fcd63 --- /dev/null +++ b/modules/profiles/workload/tailscale/server/nixos.nix @@ -0,0 +1,11 @@ +{ lib, ... }: +{ + services.tailscale = { + useRoutingFeatures = lib.mkForce "server"; + extraSetFlags = lib.mkForce [ + "--accept-dns=false" + "--accept-routes=false" + "--advertise-routes=10.50.0.0/16" + ]; + }; +} diff --git a/modules/services/tailscale/nixos.nix b/modules/services/tailscale/nixos.nix index 3177bd2..863eb94 100644 --- a/modules/services/tailscale/nixos.nix +++ b/modules/services/tailscale/nixos.nix @@ -1,11 +1,7 @@ +{ lib, ... }: { services.tailscale = { enable = true; - openFirewall = false; - useRoutingFeatures = "client"; - extraSetFlags = [ - "--accept-dns=false" - "--accept-routes=true" - ]; + openFirewall = lib.mkDefault false; }; } diff --git a/modules/systems/boot/storage-crypto/nixos.nix b/modules/systems/boot/storage-crypto/nixos.nix new file mode 100644 index 0000000..3dc02d8 --- /dev/null +++ b/modules/systems/boot/storage-crypto/nixos.nix @@ -0,0 +1,11 @@ +{ pkgs, ... }: +{ + boot.initrd = { + systemd.enable = true; + luks.devices.cryptroot.crypttabExtraOpts = [ "tpm2-device=auto" ]; + }; + + security.tpm2.enable = true; + + environment.systemPackages = [ pkgs.tpm2-tools ]; +} diff --git a/modules/users/moons/home.nix b/modules/users/moons/home.nix index 2abe851..29a3463 100644 --- a/modules/users/moons/home.nix +++ b/modules/users/moons/home.nix @@ -1,8 +1,9 @@ -{ primaryUser, ... }: +{ pkgs, primaryUser, ... }: { home = { username = primaryUser; - homeDirectory = "/home/${primaryUser}"; + homeDirectory = + if pkgs.stdenv.hostPlatform.isDarwin then "/Users/${primaryUser}" else "/home/${primaryUser}"; }; programs.home-manager.enable = true;