{ config, lib, pkgs, vars, ... }: { imports = [ # Include the results of the hardware scan. # ./hardware-configuration.nix ./set-locale.nix ]; # Use the GRUB 2 boot loader. # boot.loader.grub.enable = true; #boot.loader.grub.device = "/dev/sda"; # or "nodev" for efi only networking.networkmanager.enable = true; # Easiest to use and most distros use this by default. # Set your time zone. time.timeZone = vars.timeZone; # Enable QEMU agent services.qemuGuest.enable = true; # Enable docker-compose environment.systemPackages = with pkgs; [ vim btop git gcr ]; # Secrets shared by every host, decrypted at activation via each host's # existing SSH host key (sops-nix derives the age key from # /etc/ssh/ssh_host_ed25519_key automatically — see modules/common/README # or docs/ for the sops workflow). hashedPassword/hashedPasswordFile need # neededForUsers so they're available before the normal secret-activation # step, since user creation happens very early in boot. sops = { defaultSopsFile = ../../secrets/common.yaml; secrets = { "root-hashedPassword".neededForUsers = true; "nixos-hashedPassword".neededForUsers = true; "nix-github-token" = { }; }; # nix.conf doesn't support a *File-style option for access-tokens, so the # token is rendered into a runtime-only file (never touches the Nix store) # and pulled in via nix.conf's native !include directive. templates."nix-github-token.conf".content = '' access-tokens = github.com=${config.sops.placeholder."nix-github-token"} ''; }; nix.extraOptions = '' !include ${config.sops.templates."nix-github-token.conf".path} ''; #Set root password users.users.root = { hashedPasswordFile = config.sops.secrets."root-hashedPassword".path; }; # Define a user account. Don't forget to set a password with ‘passwd’. users.users.${vars.primaryUser} = { isNormalUser = true; extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user. packages = with pkgs; [ tree ]; hashedPasswordFile = config.sops.secrets."nixos-hashedPassword".path; openssh.authorizedKeys.keys = [ vars.adminSshKey "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICMJhrfFayLBG+gWtO6oAvgambw5nWWgztiTFEaaaVRH debian@surface" ]; }; # Enable the OpenSSH daemon. services.openssh.enable = true; #Enable flakes nix.settings = { experimental-features = [ "nix-command" "flakes" ]; auto-optimise-store = true; }; programs.git = { enable = true; package = pkgs.git; config = { credential.helper = "store"; }; }; }