{ config, lib, pkgs, vars, ... }: { imports = [ # Include the results of the hardware scan. # ./hardware-configuration.nix ./set-locale.nix ]; # Use the GRUB 2 boot loader. # boot.loader.grub.enable = true; #boot.loader.grub.device = "/dev/sda"; # or "nodev" for efi only networking.networkmanager.enable = true; # Easiest to use and most distros use this by default. # No host declares a DNS search domain anywhere else, and cross-host # references throughout this repo (vars.nfsServerHost, vars.nixCacheHost, # vars.dockerHost, ...) are bare short names, not FQDNs -- resolving them # depends entirely on whatever network stack happens to be in play # picking up the DHCP-advertised domain as a search suffix. NetworkManager # does that by default, which is why this went unnoticed on # NetworkManager-managed hosts, but LXC containers (modules/platforms/lxc.nix # force-disables NetworkManager and Proxmox writes their systemd-networkd # config itself) never get one. Confirmed live on lxc-docker: systemd-resolved # had no search domain for eth0, "server" failed to resolve # ("Name or service not known") while "server.sweet.home" resolved fine via # the same DNS server, so every NFS mount in modules/docker/mount-data.nix # failed even after fixing the automount/mount=nfs bugs. This applies the # search domain globally via systemd-resolved's own config rather than the # per-link DHCP path, so it isn't at the mercy of whichever component owns # a given host's interface file. networking.search = [ vars.homeDomain ]; # Recommended over the true default (bypasses ZFS's own import safeguards) # per the option's own docs; matches hosts/docker/host.nix and # modules/services/zfs/enable-service.nix, which already set this # explicitly. Harmless no-op on hosts that don't use ZFS at all. boot.zfs.forceImportRoot = false; # Set your time zone. time.timeZone = vars.timeZone; # Enable QEMU agent services.qemuGuest.enable = true; # Enable docker-compose environment.systemPackages = with pkgs; [ vim btop git gcr ]; # Secrets shared by every host, decrypted at activation via each host's # existing SSH host key (sops-nix derives the age key from # /etc/ssh/ssh_host_ed25519_key automatically — see modules/common/README # or docs/ for the sops workflow). hashedPassword/hashedPasswordFile need # neededForUsers so they're available before the normal secret-activation # step, since user creation happens very early in boot. sops = { defaultSopsFile = ../../secrets/common.yaml; secrets = { "root-hashedPassword".neededForUsers = true; "nixos-hashedPassword".neededForUsers = true; "nix-github-token" = { }; }; # nix.conf doesn't support a *File-style option for access-tokens, so the # token is rendered into a runtime-only file (never touches the Nix store) # and pulled in via nix.conf's native !include directive. templates."nix-github-token.conf".content = '' access-tokens = github.com=${config.sops.placeholder."nix-github-token"} ''; }; nix.extraOptions = '' !include ${config.sops.templates."nix-github-token.conf".path} ''; #Set root password users.users.root = { hashedPasswordFile = config.sops.secrets."root-hashedPassword".path; }; # Define a user account. Don't forget to set a password with ‘passwd’. users.users.${vars.primaryUser} = { isNormalUser = true; extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user. packages = with pkgs; [ tree ]; hashedPasswordFile = config.sops.secrets."nixos-hashedPassword".path; openssh.authorizedKeys.keys = [ vars.adminSshKey "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICMJhrfFayLBG+gWtO6oAvgambw5nWWgztiTFEaaaVRH debian@surface" ]; }; # Enable the OpenSSH daemon. services.openssh.enable = true; #Enable flakes nix.settings = { experimental-features = [ "nix-command" "flakes" ]; auto-optimise-store = true; }; programs.git = { enable = true; package = pkgs.git; config = { credential.helper = "store"; }; }; }