From fcd0d755375bfe68a968cf4f0cdbf73c710a56d7 Mon Sep 17 00:00:00 2001 From: moons Date: Mon, 27 Jul 2026 20:55:05 +0900 Subject: [PATCH] feat --- hosts/default.nix | 14 +++-- modules/applications/chrome/darwin.nix | 6 +++ modules/applications/chrome/home.nix | 4 +- modules/applications/discord/darwin.nix | 6 +++ modules/applications/discord/home.nix | 3 +- modules/applications/drawio/darwin.nix | 6 +++ modules/applications/drawio/home.nix | 4 ++ modules/applications/slack/darwin.nix | 6 +++ modules/applications/slack/home.nix | 4 +- modules/applications/zoom/darwin.nix | 6 +++ modules/applications/zoom/home.nix | 4 +- modules/profiles/README.md | 53 +++++++++++++++++++ modules/profiles/base/meta.nix | 12 +---- .../interface/cli-interactive/home.nix | 4 -- .../interface/cli-interactive/meta.nix | 10 ---- .../interface/{cli-minimal => cli}/home.nix | 1 + .../interface/{cli-minimal => cli}/meta.nix | 5 +- modules/profiles/interface/gnome/meta.nix | 8 +++ modules/profiles/interface/gui/meta.nix | 23 -------- .../interface/{gui => linux-desktop}/home.nix | 0 .../profiles/interface/linux-desktop/meta.nix | 14 +++++ modules/profiles/interface/niri/meta.nix | 12 +++++ .../interface/{gui => niri}/nixos.nix | 0 .../networking/tailscale-client/meta.nix | 5 ++ .../tailscale-client}/nixos.nix | 0 .../tailscale-subnet-router/meta.nix | 5 ++ .../tailscale-subnet-router}/nixos.nix | 0 modules/profiles/platform/desktop/meta.nix | 8 ++- modules/profiles/platform/laptop/meta.nix | 6 +-- modules/profiles/platform/nixos/meta.nix | 9 ++++ .../profiles/platform/thinkpad-x1/meta.nix | 10 ++++ modules/profiles/platform/thinkpad/meta.nix | 8 --- modules/profiles/platform/vm/meta.nix | 5 +- modules/profiles/security/secrets/meta.nix | 5 ++ .../profiles/security/secure-boot/meta.nix | 5 ++ .../profiles/security/tpm-storage/meta.nix | 5 ++ .../profiles/workload/development/home.nix | 19 +++---- .../profiles/workload/development/meta.nix | 3 +- modules/profiles/workload/personal/meta.nix | 4 +- .../profiles/workload/remote-access/meta.nix | 5 ++ modules/profiles/workload/remote/meta.nix | 5 -- .../profiles/workload/secure-storage/meta.nix | 8 --- modules/profiles/workload/server/meta.nix | 2 +- .../workload/tailscale/client/meta.nix | 5 -- .../workload/tailscale/server/meta.nix | 5 -- modules/systems/fingerprint/darwin.nix | 6 +++ 46 files changed, 226 insertions(+), 112 deletions(-) create mode 100644 modules/applications/chrome/darwin.nix create mode 100644 modules/applications/discord/darwin.nix create mode 100644 modules/applications/drawio/darwin.nix create mode 100644 modules/applications/drawio/home.nix create mode 100644 modules/applications/slack/darwin.nix create mode 100644 modules/applications/zoom/darwin.nix create mode 100644 modules/profiles/README.md delete mode 100644 modules/profiles/interface/cli-interactive/home.nix delete mode 100644 modules/profiles/interface/cli-interactive/meta.nix rename modules/profiles/interface/{cli-minimal => cli}/home.nix (98%) rename modules/profiles/interface/{cli-minimal => cli}/meta.nix (63%) create mode 100644 modules/profiles/interface/gnome/meta.nix delete mode 100644 modules/profiles/interface/gui/meta.nix rename modules/profiles/interface/{gui => linux-desktop}/home.nix (100%) create mode 100644 modules/profiles/interface/linux-desktop/meta.nix create mode 100644 modules/profiles/interface/niri/meta.nix rename modules/profiles/interface/{gui => niri}/nixos.nix (100%) create mode 100644 modules/profiles/networking/tailscale-client/meta.nix rename modules/profiles/{workload/tailscale/client => networking/tailscale-client}/nixos.nix (100%) create mode 100644 modules/profiles/networking/tailscale-subnet-router/meta.nix rename modules/profiles/{workload/tailscale/server => networking/tailscale-subnet-router}/nixos.nix (100%) create mode 100644 modules/profiles/platform/nixos/meta.nix create mode 100644 modules/profiles/platform/thinkpad-x1/meta.nix delete mode 100644 modules/profiles/platform/thinkpad/meta.nix create mode 100644 modules/profiles/security/secrets/meta.nix create mode 100644 modules/profiles/security/secure-boot/meta.nix create mode 100644 modules/profiles/security/tpm-storage/meta.nix create mode 100644 modules/profiles/workload/remote-access/meta.nix delete mode 100644 modules/profiles/workload/remote/meta.nix delete mode 100644 modules/profiles/workload/secure-storage/meta.nix delete mode 100644 modules/profiles/workload/tailscale/client/meta.nix delete mode 100644 modules/profiles/workload/tailscale/server/meta.nix create mode 100644 modules/systems/fingerprint/darwin.nix diff --git a/hosts/default.nix b/hosts/default.nix index e2f9b58..9fcfb35 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -7,10 +7,13 @@ profiles = [ "base" - "interface.gui" - "platform.thinkpad" + "interface.cli" + "interface.gnome" + "interface.niri" + "networking.tailscale-client" + "platform.thinkpad-x1" + "security.secrets" "workload.personal" - "workload.tailscale.client" ]; }; @@ -22,7 +25,10 @@ profiles = [ "base" - "interface.cli-minimal" + "interface.cli" + "security.secrets" ]; + + units = [ "systems.fingerprint" ]; }; } diff --git a/modules/applications/chrome/darwin.nix b/modules/applications/chrome/darwin.nix new file mode 100644 index 0000000..5e87fbb --- /dev/null +++ b/modules/applications/chrome/darwin.nix @@ -0,0 +1,6 @@ +{ + homebrew = { + enable = true; + casks = [ "google-chrome" ]; + }; +} diff --git a/modules/applications/chrome/home.nix b/modules/applications/chrome/home.nix index d58c4c8..2916f99 100644 --- a/modules/applications/chrome/home.nix +++ b/modules/applications/chrome/home.nix @@ -1,4 +1,4 @@ -{ pkgs, ... }: -{ +{ lib, pkgs, ... }: +lib.mkIf pkgs.stdenv.hostPlatform.isLinux { home.packages = [ pkgs.google-chrome ]; } diff --git a/modules/applications/discord/darwin.nix b/modules/applications/discord/darwin.nix new file mode 100644 index 0000000..73c0e65 --- /dev/null +++ b/modules/applications/discord/darwin.nix @@ -0,0 +1,6 @@ +{ + homebrew = { + enable = true; + casks = [ "vesktop" ]; + }; +} diff --git a/modules/applications/discord/home.nix b/modules/applications/discord/home.nix index b5af79f..c0cb43e 100644 --- a/modules/applications/discord/home.nix +++ b/modules/applications/discord/home.nix @@ -1,3 +1,4 @@ -{ +{ lib, pkgs, ... }: +lib.mkIf pkgs.stdenv.hostPlatform.isLinux { programs.vesktop.enable = true; } diff --git a/modules/applications/drawio/darwin.nix b/modules/applications/drawio/darwin.nix new file mode 100644 index 0000000..229b52a --- /dev/null +++ b/modules/applications/drawio/darwin.nix @@ -0,0 +1,6 @@ +{ + homebrew = { + enable = true; + casks = [ "drawio" ]; + }; +} diff --git a/modules/applications/drawio/home.nix b/modules/applications/drawio/home.nix new file mode 100644 index 0000000..056ed78 --- /dev/null +++ b/modules/applications/drawio/home.nix @@ -0,0 +1,4 @@ +{ lib, pkgs, ... }: +lib.mkIf pkgs.stdenv.hostPlatform.isLinux { + home.packages = [ pkgs.drawio ]; +} diff --git a/modules/applications/slack/darwin.nix b/modules/applications/slack/darwin.nix new file mode 100644 index 0000000..04518ce --- /dev/null +++ b/modules/applications/slack/darwin.nix @@ -0,0 +1,6 @@ +{ + homebrew = { + enable = true; + casks = [ "slack" ]; + }; +} diff --git a/modules/applications/slack/home.nix b/modules/applications/slack/home.nix index 4ff5f05..68d110a 100644 --- a/modules/applications/slack/home.nix +++ b/modules/applications/slack/home.nix @@ -1,4 +1,4 @@ -{ pkgs, ... }: -{ +{ lib, pkgs, ... }: +lib.mkIf pkgs.stdenv.hostPlatform.isLinux { home.packages = [ pkgs.slack ]; } diff --git a/modules/applications/zoom/darwin.nix b/modules/applications/zoom/darwin.nix new file mode 100644 index 0000000..05037c6 --- /dev/null +++ b/modules/applications/zoom/darwin.nix @@ -0,0 +1,6 @@ +{ + homebrew = { + enable = true; + casks = [ "zoom" ]; + }; +} diff --git a/modules/applications/zoom/home.nix b/modules/applications/zoom/home.nix index 78c6b5d..d8eb06d 100644 --- a/modules/applications/zoom/home.nix +++ b/modules/applications/zoom/home.nix @@ -1,4 +1,4 @@ -{ pkgs, ... }: -{ +{ lib, pkgs, ... }: +lib.mkIf pkgs.stdenv.hostPlatform.isLinux { home.packages = [ pkgs.zoom-us ]; } diff --git a/modules/profiles/README.md b/modules/profiles/README.md new file mode 100644 index 0000000..c374348 --- /dev/null +++ b/modules/profiles/README.md @@ -0,0 +1,53 @@ +# Profiles + +Profiles are host-selectable compositions of independently owned units. They +describe why a group of units is enabled; application, service, system, and +hardware configuration remains in its owning unit. + +## Layers + +| Namespace | Purpose | Compatibility | +| ------------ | ------------------------------------------------------- | --------------- | +| `base` | Invariants required by every host | NixOS and macOS | +| `interface` | Command-line and graphical ways to operate a host | Per-profile | +| `platform` | NixOS foundation and physical or virtual hardware shape | NixOS | +| `workload` | Optional activities performed on a host | Per-profile | +| `networking` | Network roles and topology | Per-profile | +| `security` | Optional security and secret-management policies | Per-profile | + +`base` intentionally contains only `systems.nix`. A unit belongs there only +when removing it from any supported host would make that host invalid. + +## Compatibility + +| Profile | Supported host class | +| ------------------------------------ | ------------------------------------- | +| `base` | NixOS, macOS | +| `interface.cli` | NixOS, macOS with Home Manager | +| `interface.linux-desktop` | NixOS with Home Manager | +| `interface.gnome` | NixOS with Home Manager | +| `interface.niri` | NixOS with Home Manager | +| `platform.nixos` | NixOS | +| `platform.desktop` | Physical NixOS desktop | +| `platform.laptop` | Physical NixOS laptop | +| `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS | +| `platform.vm` | QEMU NixOS guest | +| `workload.development` | NixOS, macOS with Home Manager | +| `workload.personal` | NixOS, macOS with Home Manager | +| `workload.remote-access` | NixOS, macOS | +| `workload.server` | NixOS, macOS with Home Manager | +| `networking.tailscale-client` | NixOS, macOS | +| `networking.tailscale-subnet-router` | NixOS | +| `security.secrets` | NixOS, macOS | +| `security.secure-boot` | NixOS | +| `security.tpm-storage` | NixOS with a host-defined LUKS device | + +Select independent concerns independently in `hosts/default.nix`. For example, +a NixOS laptop can combine `base`, `platform.thinkpad-x1`, +`interface.cli`, and `interface.niri`, while a macOS host can combine +`base`, `interface.cli`, and cross-platform workloads. A graphical profile does +not implicitly select a CLI profile or personal applications. + +`security.tpm-storage` deliberately does not own a disk identifier. A host that +selects it must define `boot.initrd.luks.devices.cryptroot.device` in its +machine-specific NixOS module. diff --git a/modules/profiles/base/meta.nix b/modules/profiles/base/meta.nix index c0e618c..6ac3558 100644 --- a/modules/profiles/base/meta.nix +++ b/modules/profiles/base/meta.nix @@ -1,13 +1,5 @@ { - description = "base system configuration"; + description = "Host-independent Nix foundation required everywhere"; - includes = [ - "systems.boot.base" - "systems.disko" - "systems.hardware" - "systems.locale" - "systems.networking.base" - "systems.nix" - "systems.sops" - ]; + includes = [ "systems.nix" ]; } diff --git a/modules/profiles/interface/cli-interactive/home.nix b/modules/profiles/interface/cli-interactive/home.nix deleted file mode 100644 index 1fc56f9..0000000 --- a/modules/profiles/interface/cli-interactive/home.nix +++ /dev/null @@ -1,4 +0,0 @@ -{ pkgs, ... }: -{ - home.packages = [ pkgs.tio ]; -} diff --git a/modules/profiles/interface/cli-interactive/meta.nix b/modules/profiles/interface/cli-interactive/meta.nix deleted file mode 100644 index 1a16add..0000000 --- a/modules/profiles/interface/cli-interactive/meta.nix +++ /dev/null @@ -1,10 +0,0 @@ -{ - description = "interactive command-line environment"; - - includes = [ - "profiles.interface.cli-minimal" - "applications.vim" - "applications.yazi" - "applications.zellij" - ]; -} diff --git a/modules/profiles/interface/cli-minimal/home.nix b/modules/profiles/interface/cli/home.nix similarity index 98% rename from modules/profiles/interface/cli-minimal/home.nix rename to modules/profiles/interface/cli/home.nix index 8b1535b..be27627 100644 --- a/modules/profiles/interface/cli-minimal/home.nix +++ b/modules/profiles/interface/cli/home.nix @@ -12,6 +12,7 @@ jq nurl ripgrep + tio unrar unzip wget diff --git a/modules/profiles/interface/cli-minimal/meta.nix b/modules/profiles/interface/cli/meta.nix similarity index 63% rename from modules/profiles/interface/cli-minimal/meta.nix rename to modules/profiles/interface/cli/meta.nix index 076124b..2ddce05 100644 --- a/modules/profiles/interface/cli-minimal/meta.nix +++ b/modules/profiles/interface/cli/meta.nix @@ -1,5 +1,5 @@ { - description = "minimal command-line environment"; + description = "Cross-platform interactive command-line environment"; includes = [ "applications.btop" @@ -9,6 +9,9 @@ "applications.nh" "applications.nix-index" "applications.ssh" + "applications.vim" + "applications.yazi" + "applications.zellij" "applications.zoxide" "applications.zsh" ]; diff --git a/modules/profiles/interface/gnome/meta.nix b/modules/profiles/interface/gnome/meta.nix new file mode 100644 index 0000000..f2829ec --- /dev/null +++ b/modules/profiles/interface/gnome/meta.nix @@ -0,0 +1,8 @@ +{ + description = "GNOME desktop session for NixOS"; + + includes = [ + "profiles.interface.linux-desktop" + "applications.gnome" + ]; +} diff --git a/modules/profiles/interface/gui/meta.nix b/modules/profiles/interface/gui/meta.nix deleted file mode 100644 index 18dca3a..0000000 --- a/modules/profiles/interface/gui/meta.nix +++ /dev/null @@ -1,23 +0,0 @@ -{ - description = "NixOS graphical desktop environment"; - - includes = [ - "profiles.interface.cli-interactive" - "applications.1password" - "applications.fcitx5" - "applications.ghostty" - "applications.gnome" - "applications.gtk" - "applications.kde" - "applications.nautilus" - "applications.niri" - "applications.noctalia" - "applications.vicinae" - "hardwares.graphics" - "services.ly" - "services.swayidle" - "services.swaylock" - "systems.audio" - "systems.fonts" - ]; -} diff --git a/modules/profiles/interface/gui/home.nix b/modules/profiles/interface/linux-desktop/home.nix similarity index 100% rename from modules/profiles/interface/gui/home.nix rename to modules/profiles/interface/linux-desktop/home.nix diff --git a/modules/profiles/interface/linux-desktop/meta.nix b/modules/profiles/interface/linux-desktop/meta.nix new file mode 100644 index 0000000..ffcbdf1 --- /dev/null +++ b/modules/profiles/interface/linux-desktop/meta.nix @@ -0,0 +1,14 @@ +{ + description = "Shared NixOS graphical desktop foundation"; + + includes = [ + "applications.fcitx5" + "applications.ghostty" + "applications.gtk" + "applications.nautilus" + "applications.vicinae" + "hardwares.graphics" + "systems.audio" + "systems.fonts" + ]; +} diff --git a/modules/profiles/interface/niri/meta.nix b/modules/profiles/interface/niri/meta.nix new file mode 100644 index 0000000..95d7501 --- /dev/null +++ b/modules/profiles/interface/niri/meta.nix @@ -0,0 +1,12 @@ +{ + description = "niri desktop session for NixOS"; + + includes = [ + "profiles.interface.linux-desktop" + "applications.niri" + "applications.noctalia" + "services.ly" + "services.swayidle" + "services.swaylock" + ]; +} diff --git a/modules/profiles/interface/gui/nixos.nix b/modules/profiles/interface/niri/nixos.nix similarity index 100% rename from modules/profiles/interface/gui/nixos.nix rename to modules/profiles/interface/niri/nixos.nix diff --git a/modules/profiles/networking/tailscale-client/meta.nix b/modules/profiles/networking/tailscale-client/meta.nix new file mode 100644 index 0000000..37b5dcc --- /dev/null +++ b/modules/profiles/networking/tailscale-client/meta.nix @@ -0,0 +1,5 @@ +{ + description = "Tailscale client for NixOS and macOS"; + + includes = [ "services.tailscale" ]; +} diff --git a/modules/profiles/workload/tailscale/client/nixos.nix b/modules/profiles/networking/tailscale-client/nixos.nix similarity index 100% rename from modules/profiles/workload/tailscale/client/nixos.nix rename to modules/profiles/networking/tailscale-client/nixos.nix diff --git a/modules/profiles/networking/tailscale-subnet-router/meta.nix b/modules/profiles/networking/tailscale-subnet-router/meta.nix new file mode 100644 index 0000000..26bad73 --- /dev/null +++ b/modules/profiles/networking/tailscale-subnet-router/meta.nix @@ -0,0 +1,5 @@ +{ + description = "Tailscale subnet router for NixOS"; + + includes = [ "services.tailscale" ]; +} diff --git a/modules/profiles/workload/tailscale/server/nixos.nix b/modules/profiles/networking/tailscale-subnet-router/nixos.nix similarity index 100% rename from modules/profiles/workload/tailscale/server/nixos.nix rename to modules/profiles/networking/tailscale-subnet-router/nixos.nix diff --git a/modules/profiles/platform/desktop/meta.nix b/modules/profiles/platform/desktop/meta.nix index 502dfd0..1f8f791 100644 --- a/modules/profiles/platform/desktop/meta.nix +++ b/modules/profiles/platform/desktop/meta.nix @@ -1,5 +1,9 @@ { - description = "UEFI desktop platform"; + description = "Physical NixOS desktop"; - includes = [ "systems.boot.uefi" ]; + includes = [ + "profiles.platform.nixos" + "systems.boot.uefi" + "systems.hardware" + ]; } diff --git a/modules/profiles/platform/laptop/meta.nix b/modules/profiles/platform/laptop/meta.nix index 88721f8..0d27111 100644 --- a/modules/profiles/platform/laptop/meta.nix +++ b/modules/profiles/platform/laptop/meta.nix @@ -1,11 +1,11 @@ { - description = "laptop platform configuration"; + description = "Physical NixOS laptop"; includes = [ + "profiles.platform.nixos" "hardwares.bluetooth" - "hardwares.ipu6-camera" "systems.boot.uefi" - "systems.fingerprint" + "systems.hardware" "systems.networking.wifi" "systems.power" ]; diff --git a/modules/profiles/platform/nixos/meta.nix b/modules/profiles/platform/nixos/meta.nix new file mode 100644 index 0000000..d2451e0 --- /dev/null +++ b/modules/profiles/platform/nixos/meta.nix @@ -0,0 +1,9 @@ +{ + description = "Foundation shared by all NixOS platforms"; + + includes = [ + "systems.boot.base" + "systems.locale" + "systems.networking.base" + ]; +} diff --git a/modules/profiles/platform/thinkpad-x1/meta.nix b/modules/profiles/platform/thinkpad-x1/meta.nix new file mode 100644 index 0000000..e317e1f --- /dev/null +++ b/modules/profiles/platform/thinkpad-x1/meta.nix @@ -0,0 +1,10 @@ +{ + description = "Intel ThinkPad X1 laptop hardware"; + + includes = [ + "profiles.platform.laptop" + "hardwares.intel-driver" + "hardwares.ipu6-camera" + "systems.fingerprint" + ]; +} diff --git a/modules/profiles/platform/thinkpad/meta.nix b/modules/profiles/platform/thinkpad/meta.nix deleted file mode 100644 index 8408b1e..0000000 --- a/modules/profiles/platform/thinkpad/meta.nix +++ /dev/null @@ -1,8 +0,0 @@ -{ - description = "ThinkPad laptop platform"; - - includes = [ - "profiles.platform.laptop" - "hardwares.intel-driver" - ]; -} diff --git a/modules/profiles/platform/vm/meta.nix b/modules/profiles/platform/vm/meta.nix index 16bc6c5..8c7f6a3 100644 --- a/modules/profiles/platform/vm/meta.nix +++ b/modules/profiles/platform/vm/meta.nix @@ -1,9 +1,8 @@ { - description = "virtual-machine platform"; + description = "QEMU NixOS guest"; includes = [ + "profiles.platform.nixos" "hardwares.qemu-guest" - "systems.boot.nfs" - "systems.boot.uefi" ]; } diff --git a/modules/profiles/security/secrets/meta.nix b/modules/profiles/security/secrets/meta.nix new file mode 100644 index 0000000..3bacb5b --- /dev/null +++ b/modules/profiles/security/secrets/meta.nix @@ -0,0 +1,5 @@ +{ + description = "Cross-platform SOPS and age secret management"; + + includes = [ "systems.sops" ]; +} diff --git a/modules/profiles/security/secure-boot/meta.nix b/modules/profiles/security/secure-boot/meta.nix new file mode 100644 index 0000000..5988eb0 --- /dev/null +++ b/modules/profiles/security/secure-boot/meta.nix @@ -0,0 +1,5 @@ +{ + description = "Secure Boot for NixOS"; + + includes = [ "systems.boot.secure-boot" ]; +} diff --git a/modules/profiles/security/tpm-storage/meta.nix b/modules/profiles/security/tpm-storage/meta.nix new file mode 100644 index 0000000..122a9cd --- /dev/null +++ b/modules/profiles/security/tpm-storage/meta.nix @@ -0,0 +1,5 @@ +{ + description = "TPM-backed LUKS unlock for NixOS"; + + includes = [ "systems.boot.storage-crypto" ]; +} diff --git a/modules/profiles/workload/development/home.nix b/modules/profiles/workload/development/home.nix index 31615aa..92038ee 100644 --- a/modules/profiles/workload/development/home.nix +++ b/modules/profiles/workload/development/home.nix @@ -1,13 +1,10 @@ -{ lib, pkgs, ... }: +{ pkgs, ... }: { - home.packages = - with pkgs; - [ - bind - bun - nil - python312 - uv - ] - ++ lib.optionals stdenv.hostPlatform.isLinux [ drawio ]; + home.packages = with pkgs; [ + bind + bun + nil + python312 + uv + ]; } diff --git a/modules/profiles/workload/development/meta.nix b/modules/profiles/workload/development/meta.nix index 9f4f487..d34e7fb 100644 --- a/modules/profiles/workload/development/meta.nix +++ b/modules/profiles/workload/development/meta.nix @@ -1,5 +1,5 @@ { - description = "software development workload"; + description = "Cross-platform software development environment"; includes = [ "applications.arduino" @@ -7,6 +7,7 @@ "applications.codex" "applications.codex-desktop" "applications.docker" + "applications.drawio" "applications.grok" "applications.java" "applications.opencode" diff --git a/modules/profiles/workload/personal/meta.nix b/modules/profiles/workload/personal/meta.nix index e25493c..7d380a5 100644 --- a/modules/profiles/workload/personal/meta.nix +++ b/modules/profiles/workload/personal/meta.nix @@ -1,9 +1,11 @@ { - description = "personal communication and browser workload"; + description = "Cross-platform personal desktop applications"; includes = [ + "applications.1password" "applications.chrome" "applications.discord" + "applications.kde" "applications.slack" "applications.zoom" ]; diff --git a/modules/profiles/workload/remote-access/meta.nix b/modules/profiles/workload/remote-access/meta.nix new file mode 100644 index 0000000..7729959 --- /dev/null +++ b/modules/profiles/workload/remote-access/meta.nix @@ -0,0 +1,5 @@ +{ + description = "Cross-platform remote shell access"; + + includes = [ "services.openssh" ]; +} diff --git a/modules/profiles/workload/remote/meta.nix b/modules/profiles/workload/remote/meta.nix deleted file mode 100644 index b6173ac..0000000 --- a/modules/profiles/workload/remote/meta.nix +++ /dev/null @@ -1,5 +0,0 @@ -{ - description = "remote-access workload"; - - includes = [ "services.openssh" ]; -} diff --git a/modules/profiles/workload/secure-storage/meta.nix b/modules/profiles/workload/secure-storage/meta.nix deleted file mode 100644 index 2327dc9..0000000 --- a/modules/profiles/workload/secure-storage/meta.nix +++ /dev/null @@ -1,8 +0,0 @@ -{ - description = "secure boot and TPM-backed storage"; - - includes = [ - "systems.boot.secure-boot" - "systems.boot.storage-crypto" - ]; -} diff --git a/modules/profiles/workload/server/meta.nix b/modules/profiles/workload/server/meta.nix index a77b30e..f531845 100644 --- a/modules/profiles/workload/server/meta.nix +++ b/modules/profiles/workload/server/meta.nix @@ -1,5 +1,5 @@ { - description = "server workload"; + description = "Cross-platform container and remote-access server"; includes = [ "applications.docker" diff --git a/modules/profiles/workload/tailscale/client/meta.nix b/modules/profiles/workload/tailscale/client/meta.nix deleted file mode 100644 index e36e64d..0000000 --- a/modules/profiles/workload/tailscale/client/meta.nix +++ /dev/null @@ -1,5 +0,0 @@ -{ - description = "Tailscale client"; - - includes = [ "services.tailscale" ]; -} diff --git a/modules/profiles/workload/tailscale/server/meta.nix b/modules/profiles/workload/tailscale/server/meta.nix deleted file mode 100644 index aec7d49..0000000 --- a/modules/profiles/workload/tailscale/server/meta.nix +++ /dev/null @@ -1,5 +0,0 @@ -{ - description = "Tailscale subnet-router server"; - - includes = [ "services.tailscale" ]; -} diff --git a/modules/systems/fingerprint/darwin.nix b/modules/systems/fingerprint/darwin.nix new file mode 100644 index 0000000..1937a8a --- /dev/null +++ b/modules/systems/fingerprint/darwin.nix @@ -0,0 +1,6 @@ +{ + security.pam.services.sudo_local = { + touchIdAuth = true; + reattach = true; + }; +}