{ config, pkgs, lib, inputs, vars, ... }: { imports = [ ../docker/enable-service.nix ]; nixpkgs.overlays = [ (final: prev: { docker = prev.docker_29; docker_cli = prev.docker_29; }) ]; environment.systemPackages = with pkgs; [ inputs.nixos-conf-editor.packages.${pkgs.stdenv.hostPlatform.system}.nixos-conf-editor nodejs appimage-run seahorse vscode p7zip popsicle # balena-etcher shotcut gimp pdfarranger terminator libreoffice-qt transmission_4-qt ]; boot.loader.grub.useOSProber = true; programs.direnv.enable = true; services = { xserver = { enable = true; displayManager = { lightdm.enable = true; sessionCommands = '' eval $(gnome-keyring-daemon --start --components=secrets,ssh) export SSH_AUTH_SOCK ''; }; desktopManager.cinnamon.enable = true; xkb = { layout = "au"; variant = ""; }; }; printing.enable = true; pipewire = { enable = true; alsa.enable = true; alsa.support32Bit = true; pulse.enable = true; }; xrdp = { enable = true; defaultWindowManager = "cinnamon-session"; openFirewall = true; }; gnome.gnome-keyring.enable = true; }; security = { rtkit.enable = true; pam.services.login.enableGnomeKeyring = true; }; # The networkmanager group only exists when NM is actually enabled — the # lxc platform module force-disables it, so don't add the user to a group # that won't exist there. users.users.${vars.primaryUser}.extraGroups = lib.mkIf config.networking.networkmanager.enable [ "networkmanager" ]; programs.firefox.enable = true; nixpkgs.config.allowUnfree = true; # GUI-specific Home Manager additions for the IPA primary user, extending # the baseline in modules/ipa/client.nix with desktop apps and services # that only make sense on a graphical workstation. home-manager.users.${vars.ipaUser} = { pkgs, ... }: { home = { packages = with pkgs; [ git vim nextcloud-client chromium claude-code fish sops ]; sessionVariables = { EDITOR = "nano"; SOPS_AGE_KEY_FILE = "/home/${vars.ipaUser}/.config/sops/age/keys.txt"; }; file = { ".local/share/applications/proxmox-chromium-app.desktop".text = '' [Desktop Entry] Type=Application Name=Proxmox (Chromium) Exec=chromium --app=https://pve.${vars.homeDomain}:${toString vars.ports.pveWeb} --window-size=1920,1080 --window-position=0,0 Icon=/home/${vars.ipaUser}/.local/share/icons/proxmox.png Terminal=false Categories=Hypervisor; StartupWMClass=PVE ''; ".local/share/applications/pbs-chromium-app.desktop".text = '' [Desktop Entry] Type=Application Name=Proxmox Backup Server (Chromium) Exec=chromium --app=https://${vars.pbsIp}:${toString vars.ports.pbsWeb} --window-size=1920,1080 --window-position=0,0 Icon=/home/${vars.ipaUser}/.local/share/icons/proxmox.png Terminal=false Categories=backup; ''; ".local/share/applications/proxmox-firefox-app.desktop".text = '' [Desktop Entry] Type=Application Name=Proxmox (Firefox) Exec=firefox --new-instance https://pve.${vars.homeDomain}:${toString vars.ports.pveWeb} --profile ProxmoxWebApp --window-size=1920,1080 --class ProxmoxWebApp Icon=/home/${vars.ipaUser}/.local/share/icons/proxmox.png Terminal=false Categories=Hypervisor; StartupWMClass=PVE ''; ".local/share/applications/pbs-firefox-app.desktop".text = '' [Desktop Entry] Type=Application Name=Proxmox Backup Server (Firefox) Exec=firefox --new-window https://${vars.pbsIp}:${toString vars.ports.pbsWeb} --profile PbsWebApp --window-size=1920,1080 --class PbsWebApp Icon=/home/${vars.ipaUser}/.local/share/icons/proxmox.png Terminal=false Categories=backup; StartupWMClass=PBS ''; }; }; services.nextcloud-client = { enable = true; startInBackground = true; }; }; }