{ pkgs, lib, vars, ... }: { imports = [ ./host-keys.nix ]; networking.useDHCP = lib.mkDefault true; # Recommended over the true default (bypasses ZFS's own import safeguards) # per the option's own docs. This installer environment has no ZFS pools # of its own to import, so this is a no-op here — just silences the # eval-time warning, matching modules/common/configuration.nix. boot.zfs.forceImportRoot = false; time.timeZone = vars.timeZone; # Without this, the installer only ever sees cache.nixos.org, which # doesn't carry sops-install-secrets (it's built straight from the # sops-nix flake's own Go source, not part of nixpkgs) — every install # would otherwise compile it from scratch, which is what ran an 8GB LXC # container's disk out of space. Push a built copy to nix-cache once # (from a machine with real disk headroom) and every future install, # of any type, fetches instead of rebuilding. nix.settings = { substituters = [ "http://nix-cache" "https://cache.nixos.org/" ]; trusted-public-keys = [ "cache.local-1:usoWYanY3Kpq2+kDIS2nhWoLZiRxanmdysdzqCFBHW4=" "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" ]; }; environment = { systemPackages = with pkgs; [ git curl jq parted e2fsprogs btrfs-progs util-linux disko ]; # Auto-install script, kept as a real, version-controlled shell file at # scripts/installer/auto-install.sh rather than an inline Nix string -- # replaceVars only substitutes the one value (lanDomain) that genuinely # needs to come from variables.nix; every other "@..." pattern in the # script is a literal `${...}` bash reference, untouched by this. etc."auto-install.sh" = { source = pkgs.replaceVars ../../scripts/installer/auto-install.sh { inherit (vars) lanDomain; }; mode = "0755"; }; }; programs.git.enable = true; # Run the installer on first login. Previously this copied an /etc file # into the nixos user's ~/.bash_profile via an activation script that # got dropped in a refactor (and only ever worked for that one user # anyway) — loginShellInit is NixOS's native hook for this, applies to # any user's login shell (root included), and needs no home-directory # file-copying/chown. programs.bash.loginShellInit = '' if [ -n "$PS1" ] && [ ! -e "$HOME/.auto_install_ran" ]; then sudo /etc/auto-install.sh touch "$HOME/.auto_install_ran" fi ''; services.openssh.enable = true; services.openssh.settings = { PermitRootLogin = "yes"; PasswordAuthentication = true; }; # nixpkgs' own installer profile (profiles/installation-device.nix, pulled # in via installation-cd-minimal.nix) sets initialHashedPassword = "" for # both users — its own passwordless-login convention for install media. # That's a second, non-null password option alongside our hashedPassword # below, which NixOS warns about as ambiguous precedence. Force it null # rather than adopting passwordless login: this image now also boots over # LAN PXE with PasswordAuthentication enabled, so passwordless root SSH # would be reachable by anyone on the LAN, not just local console. users.users.root = { hashedPassword = "$6$Kwv9KAyvcurAViQF$H4.u3feqGE7lVoNgkFXhE3n2Pmo//9JYDTCz8ifrVHBxPjwa1xMby7tEZ8Bpt5MXs9Rkx6/YbZWxs5CpH0s/70"; initialHashedPassword = lib.mkForce null; }; users.users.${vars.primaryUser} = { isNormalUser = true; extraGroups = [ "wheel" ]; shell = pkgs.bashInteractive; hashedPassword = "$6$Kwv9KAyvcurAViQF$H4.u3feqGE7lVoNgkFXhE3n2Pmo//9JYDTCz8ifrVHBxPjwa1xMby7tEZ8Bpt5MXs9Rkx6/YbZWxs5CpH0s/70"; initialHashedPassword = lib.mkForce null; openssh.authorizedKeys.keys = [ vars.adminSshKey ]; }; system.stateVersion = "26.05"; }