add profiles

This commit is contained in:
2026-07-27 18:31:50 +09:00
parent 6bd05887db
commit bf94d1183f
34 changed files with 327 additions and 14 deletions
+5 -2
View File
@@ -7,8 +7,11 @@
profiles = [ profiles = [
"base" "base"
"interface.cli-minimal" "interface.gui"
"platform.laptop" "platform.thinkpad"
"workload.development"
"workload.personal"
"workload.tailscale.client"
]; ];
}; };
} }
+52
View File
@@ -0,0 +1,52 @@
# Do not modify this file! It was generated by ‘nixos-generate-config’
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{
config,
lib,
modulesPath,
...
}:
{
imports = [
(modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [
"xhci_pci"
"thunderbolt"
"nvme"
"usb_storage"
"sd_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" = {
device = "/dev/disk/by-uuid/16b29578-6836-414b-a5e1-863bc21c5fc3";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/209A-C8C9";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [ ];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.wlp0s20f3.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
-1
View File
@@ -1 +0,0 @@
{ }
+1 -1
View File
@@ -1,5 +1,5 @@
{ {
imports = [ imports = [
./hardware.nix ./hardware-configuration.nix
]; ];
} }
+9
View File
@@ -0,0 +1,9 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.gnupg ];
services.gpg-agent = {
enable = false;
enableSshSupport = false;
};
}
+6
View File
@@ -0,0 +1,6 @@
{
programs.gnupg.agent = {
enable = true;
enableSSHSupport = false;
};
}
+4 -1
View File
@@ -4,5 +4,8 @@
includes = [ "systems.wayland" ]; includes = [ "systems.wayland" ];
imports.nixos = [ inputs.niri-flake.nixosModules.niri ]; imports = {
nixos = [ inputs.niri-flake.nixosModules.niri ];
home = [ ./niri-home-module.nix ];
};
} }
@@ -0,0 +1,9 @@
{
inputs,
lib,
system,
...
}:
{
imports = lib.optional (lib.hasSuffix "-darwin" system) inputs.niri-flake.homeModules.niri;
}
+3 -1
View File
@@ -2,9 +2,11 @@
description = "base system configuration"; description = "base system configuration";
includes = [ includes = [
"systems.boot.base"
"systems.disko"
"systems.hardware"
"systems.locale" "systems.locale"
"systems.networking.base" "systems.networking.base"
"systems.networking.wifi"
"systems.nix" "systems.nix"
"systems.sops" "systems.sops"
]; ];
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.tio ];
}
@@ -0,0 +1,10 @@
{
description = "interactive command-line environment";
includes = [
"profiles.interface.cli-minimal"
"applications.vim"
"applications.yazi"
"applications.zellij"
];
}
@@ -0,0 +1,34 @@
{ pkgs, ... }:
{
home.packages = with pkgs; [
bat
duf
dust
eza
fd
fastfetch
fzf
htop
jq
nurl
ripgrep
unrar
unzip
wget
];
home.activation.generateSshKey = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
key="$HOME/.ssh/id_ed25519"
if [ ! -f "$key" ]; then
umask 077
mkdir -p "$HOME/.ssh"
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
echo "Generated SSH key at $key"
fi
'';
};
}
@@ -3,5 +3,13 @@
includes = [ includes = [
"applications.btop" "applications.btop"
"applications.direnv"
"applications.git"
"applications.gnupg"
"applications.nh"
"applications.nix-index"
"applications.ssh"
"applications.zoxide"
"applications.zsh"
]; ];
} }
+14
View File
@@ -0,0 +1,14 @@
{
xdg.userDirs = {
enable = true;
createDirectories = true;
desktop = "$HOME/Desktop";
documents = "$HOME/Documents";
download = "$HOME/Downloads";
music = "$HOME/Music";
pictures = "$HOME/Pictures";
publicShare = "$HOME/Public";
templates = "$HOME/Templates";
videos = "$HOME/Videos";
};
}
+23
View File
@@ -0,0 +1,23 @@
{
description = "NixOS graphical desktop environment";
includes = [
"profiles.interface.cli-interactive"
"applications.1password"
"applications.fcitx5"
"applications.ghostty"
"applications.gnome"
"applications.gtk"
"applications.kde"
"applications.nautilus"
"applications.niri"
"applications.noctalia"
"applications.vicinae"
"hardwares.graphics"
"services.ly"
"services.swayidle"
"services.swaylock"
"systems.audio"
"systems.fonts"
];
}
+8
View File
@@ -0,0 +1,8 @@
{ pkgs, ... }:
{
environment.systemPackages = with pkgs; [
grim
slurp
wf-recorder
];
}
@@ -0,0 +1,5 @@
{
description = "UEFI desktop platform";
includes = [ "systems.boot.uefi" ];
}
@@ -2,6 +2,11 @@
description = "laptop platform configuration"; description = "laptop platform configuration";
includes = [ includes = [
"hardwares.bluetooth"
"hardwares.ipu6-camera"
"systems.boot.uefi" "systems.boot.uefi"
"systems.fingerprint"
"systems.networking.wifi"
"systems.power"
]; ];
} }
@@ -0,0 +1,8 @@
{
description = "ThinkPad laptop platform";
includes = [
"profiles.platform.laptop"
"hardwares.intel-driver"
];
}
+9
View File
@@ -0,0 +1,9 @@
{
description = "virtual-machine platform";
includes = [
"hardwares.qemu-guest"
"systems.boot.nfs"
"systems.boot.uefi"
];
}
@@ -0,0 +1,13 @@
{ lib, pkgs, ... }:
{
home.packages =
with pkgs;
[
bind
bun
nil
python312
uv
]
++ lib.optionals stdenv.hostPlatform.isLinux [ drawio ];
}
@@ -0,0 +1,16 @@
{
description = "software development workload";
includes = [
"applications.arduino"
"applications.claude"
"applications.codex"
"applications.codex-desktop"
"applications.docker"
"applications.grok"
"applications.java"
"applications.opencode"
"applications.vscode"
"applications.zed"
];
}
@@ -0,0 +1,3 @@
{
documentation.doc.enable = false;
}
@@ -0,0 +1,10 @@
{
description = "personal communication and browser workload";
includes = [
"applications.chrome"
"applications.discord"
"applications.slack"
"applications.zoom"
];
}
@@ -0,0 +1,5 @@
{
description = "remote-access workload";
includes = [ "services.openssh" ];
}
@@ -0,0 +1,8 @@
{
description = "secure boot and TPM-backed storage";
includes = [
"systems.boot.secure-boot"
"systems.boot.storage-crypto"
];
}
@@ -0,0 +1,8 @@
{
description = "server workload";
includes = [
"applications.docker"
"services.openssh"
];
}
@@ -0,0 +1,5 @@
{
description = "Tailscale client";
includes = [ "services.tailscale" ];
}
@@ -0,0 +1,10 @@
{ lib, ... }:
{
services.tailscale = {
useRoutingFeatures = lib.mkForce "client";
extraSetFlags = lib.mkForce [
"--accept-dns=false"
"--accept-routes=true"
];
};
}
@@ -0,0 +1,5 @@
{
description = "Tailscale subnet-router server";
includes = [ "services.tailscale" ];
}
@@ -0,0 +1,11 @@
{ lib, ... }:
{
services.tailscale = {
useRoutingFeatures = lib.mkForce "server";
extraSetFlags = lib.mkForce [
"--accept-dns=false"
"--accept-routes=false"
"--advertise-routes=10.50.0.0/16"
];
};
}
+2 -6
View File
@@ -1,11 +1,7 @@
{ lib, ... }:
{ {
services.tailscale = { services.tailscale = {
enable = true; enable = true;
openFirewall = false; openFirewall = lib.mkDefault false;
useRoutingFeatures = "client";
extraSetFlags = [
"--accept-dns=false"
"--accept-routes=true"
];
}; };
} }
@@ -0,0 +1,11 @@
{ pkgs, ... }:
{
boot.initrd = {
systemd.enable = true;
luks.devices.cryptroot.crypttabExtraOpts = [ "tpm2-device=auto" ];
};
security.tpm2.enable = true;
environment.systemPackages = [ pkgs.tpm2-tools ];
}
+3 -2
View File
@@ -1,8 +1,9 @@
{ primaryUser, ... }: { pkgs, primaryUser, ... }:
{ {
home = { home = {
username = primaryUser; username = primaryUser;
homeDirectory = "/home/${primaryUser}"; homeDirectory =
if pkgs.stdenv.hostPlatform.isDarwin then "/Users/${primaryUser}" else "/home/${primaryUser}";
}; };
programs.home-manager.enable = true; programs.home-manager.enable = true;