summaryrefslogtreecommitdiff
path: root/hosts/skadhi/default.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hosts/skadhi/default.nix')
-rw-r--r--hosts/skadhi/default.nix118
1 files changed, 118 insertions, 0 deletions
diff --git a/hosts/skadhi/default.nix b/hosts/skadhi/default.nix
new file mode 100644
index 00000000..cf25777b
--- /dev/null
+++ b/hosts/skadhi/default.nix
@@ -0,0 +1,118 @@
1{ flake, flakeInputs, pkgs, config, lib, ... }:
2{
3 imports = with flake.nixosModules.systemProfiles; [
4 ./hw.nix ./fs.nix ./networking
5 tmpfs-root default-locale openssh lanzaboote zswap initrd-all-crypto-modules
6 ];
7
8 config = {
9 system.stateVersion = "26.05";
10
11 boot = {
12 initrd = {
13 systemd = {
14 emergencyAccess = config.users.users.root.hashedPassword;
15 extraBin = {
16 "vim" = lib.getExe pkgs.vim;
17 "grep" = lib.getExe pkgs.gnugrep;
18 };
19 };
20
21 kernelModules = [ "dm-integrity" ];
22 };
23
24 lanzaboote.configurationLimit = 15;
25 loader = {
26 efi.canTouchEfiVariables = true;
27 timeout = null;
28 };
29
30 plymouth.enable = true;
31
32 kernelPackages = pkgs.linuxPackages_7_2;
33 consoleLogLevel = 3;
34 kernelParams = [
35 "quiet"
36 "boot.shell_on_fail"
37 "udev.log_priority=3"
38 "rd.systemd.show_status=auto"
39 "plymouth.use-simpledrm"
40 ];
41
42 tmp.useTmpfs = true;
43 };
44
45 services.timesyncd.enable = false;
46 services.chrony = {
47 enable = true;
48 enableNTS = true;
49 servers = [];
50 extraConfig = ''
51 pool time.cloudflare.com iburst nts
52 pool nts.netnod.se prefer iburst nts
53 server ptbtime1.ptb.de prefer iburst nts
54 server ptbtime2.ptb.de prefer iburst nts
55 server ptbtime3.ptb.de prefer iburst nts
56 server ptbtime4.ptb.de prefer iburst nts
57 pool ntppool1.time.nl prefer iburst nts
58 pool ntppool2.time.nl prefer iburst nts
59
60 authselectmode require
61 minsources 3
62
63 nocerttimecheck 1
64
65 leapsectz right/UTC
66
67 makestep 0.1 3
68
69 cmdport 0
70 '';
71 };
72
73 services.userborn.importLegacyState = false;
74
75 services.kmscon = {
76 enable = true;
77 config.hwaccel = true;
78 };
79
80 environment.persistence."/persistent".timezone = true;
81 time.timeZone = null;
82 systemd.tmpfiles.settings = {
83 "10-localtime"."/etc/localtime".L.argument = "/persistent/etc/localtime";
84 };
85
86 services.openssh.enable = true;
87
88 services.logind.settings.Login = {
89 HandleLidSwitch = "sleep";
90 HandleLidSwitchExternalPower = "ignore";
91 };
92
93 systemd.timers.nix-gc = lib.mkForce {
94 timerConfig = {
95 RandomizedDelaySec = "12h";
96 Persistent = true;
97 OnCalendar = "*-*-* 18:00:00 Europe/Berlin";
98 };
99 wantedBy = [ "timers.target" ];
100 };
101 systemd.services.nix-gc = lib.mkForce {
102 description = "Nix Garbage Collector";
103 serviceConfig = {
104 Type = "oneshot";
105 ExecStart = pkgs.resholve.writeScript "nix-gc" {
106 interpreter = lib.getExe pkgs.zsh;
107 inputs = [ pkgs.coreutils config.nix.package ];
108 execer = [ "cannot:${lib.getExe' config.nix.package "nix-collect-garbage"}" ];
109 } ''
110 max_size=$(($(du -bs /nix/store | cut -f 1) - 1024**4))
111 [[ $max_size -gt 0 ]] || exit 0
112 exec nix-collect-garbage -vv --max-freed $max_size --delete-older-than 30d
113 '';
114 };
115 restartIfChanged = false;
116 };
117 };
118}