Initial commit

This commit is contained in:
2026-03-31 16:53:11 +02:00
commit d0eba1c834
343 changed files with 34443 additions and 0 deletions
+37
View File
@@ -0,0 +1,37 @@
{ config, pkgs, lib, ... }:
{
boot = {
bootspec.enable = true;
initrd.systemd.enable = true;
supportedFilesystems = [ "ntfs" ];
kernelPackages = pkgs.linuxPackages_latest;
consoleLogLevel = 3;
kernelParams = [
"quiet"
"systemd.show_status=auto"
"rd.udev.log_level=3"
"plymouth.use-simpledrm"
];
plymouth.enable = true;
tmp = {
useTmpfs = true;
cleanOnBoot = true;
};
};
systemd.services.nix-daemon.environment.TMPDIR = "/var/tmp";
environment.systemPackages = [
config.boot.kernelPackages.cpupower
pkgs.brightnessctl
pkgs.ddcutil
];
}
+43
View File
@@ -0,0 +1,43 @@
{lib, ...}: {
imports = [
./security.nix
./users.nix
../nix
../programs/fish.nix
];
i18n = {
defaultLocale = "en_US.UTF-8";
extraLocaleSettings = {
LC_ADDRESS = "nl_NL.UTF-8";
LC_IDENTIFICATION = "nl_NL.UTF-8";
LC_MEASUREMENT = "nl_NL.UTF-8";
LC_MONETARY = "nl_NL.UTF-8";
LC_NAME = "nl_NL.UTF-8";
LC_NUMERIC = "nl_NL.UTF-8";
LC_PAPER = "nl_NL.UTF-8";
LC_TELEPHONE = "nl_NL.UTF-8";
LC_TIME = "nl_NL.UTF-8";
};
};
console.keyMap = "us";
# don't touch this
system = {
switch.enable = true;
stateVersion = lib.mkDefault "25.05";
};
time = {
timeZone = lib.mkDefault "Europe/Amsterdam";
hardwareClockInLocalTime = lib.mkDefault true;
};
# compresses half the ram for use as swap
zramSwap = {
enable = true;
algorithm = "zstd";
memoryPercent = 25;
};
}
+19
View File
@@ -0,0 +1,19 @@
{ lib, pkgs, ... }:
{
boot.loader = {
limine = {
enable = true;
efiSupport = true;
biosSupport = true;
biosDevice = "/dev/nvme1n1";
maxGenerations = 10;
style.wallpapers = [
pkgs.nixos-artwork.wallpapers.simple-dark-gray-bootloader.gnomeFilePath
];
};
grub.enable = lib.mkForce false;
systemd-boot.enable = lib.mkForce false;
};
}
+87
View File
@@ -0,0 +1,87 @@
# security tweaks borrowed from @hlissner
{
boot.kernel.sysctl = {
# The Magic SysRq key is a key combo that allows users connected to the
# system console of a Linux kernel to perform some low-level commands.
## TCP hardening
# Prevent bogus ICMP errors from filling up logs.
"net.ipv4.icmp_ignore_bogus_error_responses" = 1;
# Reverse path filtering causes the kernel to do source validation of
# packets received from all interfaces. This can mitigate IP spoofing.
"net.ipv4.conf.default.rp_filter" = 1;
"net.ipv4.conf.all.rp_filter" = 1;
# Do not accept IP source route packets (we're not a router)
"net.ipv4.conf.all.accept_source_route" = 0;
"net.ipv6.conf.all.accept_source_route" = 0;
# Don't send ICMP redirects (again, we're not a router)
"net.ipv4.conf.all.send_redirects" = 0;
"net.ipv4.conf.default.send_redirects" = 0;
# Refuse ICMP redirects (MITM mitigations)
"net.ipv4.conf.all.accept_redirects" = 0;
"net.ipv4.conf.default.accept_redirects" = 0;
"net.ipv4.conf.all.secure_redirects" = 0;
"net.ipv4.conf.default.secure_redirects" = 0;
"net.ipv6.conf.all.accept_redirects" = 0;
"net.ipv6.conf.default.accept_redirects" = 0;
# Protects against SYN flood attacks
"net.ipv4.tcp_syncookies" = 1;
# Incomplete protection again TIME-WAIT assassination
"net.ipv4.tcp_rfc1337" = 1;
## TCP optimization
# TCP Fast Open is a TCP extension that reduces network latency by packing
# data in the senders initial TCP SYN. Setting 3 = enable TCP Fast Open for
# both incoming and outgoing connections:
"net.ipv4.tcp_fastopen" = 3;
# Enable IPv4 forwarding for VPN/container routing
"net.ipv4.ip_forward" = 1;
# Bufferbloat mitigations + slight improvement in throughput & latency
"net.ipv4.tcp_congestion_control" = "bbr";
"net.core.default_qdisc" = "cake";
## Network performance optimizations
# Increase network buffer sizes
"net.core.rmem_default" = 262144;
"net.core.rmem_max" = 134217728;
"net.core.wmem_default" = 262144;
"net.core.wmem_max" = 134217728;
# TCP buffer sizes
"net.ipv4.tcp_rmem" = "4096 131072 134217728";
"net.ipv4.tcp_wmem" = "4096 65536 134217728";
# TCP performance
"net.ipv4.tcp_window_scaling" = 1;
"net.ipv4.tcp_timestamps" = 1;
"net.ipv4.tcp_sack" = 1;
"net.ipv4.tcp_fack" = 1;
"net.ipv4.tcp_low_latency" = 1;
"net.ipv4.tcp_adv_win_scale" = 1;
# Reduce TIME_WAIT sockets
"net.ipv4.tcp_fin_timeout" = 15;
"net.ipv4.tcp_tw_reuse" = 1;
};
boot.kernelModules = ["tcp_bbr"];
security = {
# allow wayland lockers to unlock the screen
# userland niceness
rtkit.enable = true;
polkit.enable = true;
sudo-rs = {
enable = true;
execWheelOnly = true;
wheelNeedsPassword = false;
};
# don't ask for password for wheel group
sudo = {
wheelNeedsPassword = false;
};
};
}
+19
View File
@@ -0,0 +1,19 @@
{pkgs, ...}: {
users.users.someone = {
isNormalUser = true;
shell = pkgs.fish;
ignoreShellProgramCheck = true;
initialPassword = "nixos";
extraGroups = [
"adbusers"
"input"
"networkmanager"
"plugdev"
"video"
"wheel"
"kvm"
"i2c"
"docker"
];
};
}
+28
View File
@@ -0,0 +1,28 @@
let
desktop = [
./core/boot.nix
./core/default.nix
./hardware/graphics.nix
./hardware/fwupd.nix
./network/default.nix
./programs
./services
./services/docker.nix
./services/greetd.nix
./services/pipewire.nix
./services/xdg-portal-fix.nix
];
laptop =
desktop
++ [
./hardware/bluetooth.nix
./services/power.nix
];
in {
inherit desktop laptop;
}
+8
View File
@@ -0,0 +1,8 @@
{pkgs, ...}: {
hardware.bluetooth = {
enable = true;
package = pkgs.bluez5-experimental;
};
systemd.user.services.telephony_client.enable = false;
}
+3
View File
@@ -0,0 +1,3 @@
{
services.fwupd.enable = true;
}
+16
View File
@@ -0,0 +1,16 @@
{pkgs, ...}: {
hardware.graphics = {
enable = true;
extraPackages = with pkgs; [
libva
libva-vdpau-driver
libvdpau-va-gl
libGL
mesa
];
extraPackages32 = with pkgs.pkgsi686Linux; [
libva-vdpau-driver
libvdpau-va-gl
];
};
}
+12
View File
@@ -0,0 +1,12 @@
{
# network discovery, mDNS
services.avahi = {
enable = true;
nssmdns4 = true;
publish = {
enable = true;
domain = true;
userServices = true;
};
};
}
+31
View File
@@ -0,0 +1,31 @@
{pkgs, ...}: {
networking = {
nameservers = ["1.1.1.1" "1.0.0.1"];
nftables.enable = true;
networkmanager = {
enable = true;
dns = "none";
wifi.powersave = true;
plugins = with pkgs; [
networkmanager-openvpn
];
};
useDHCP = false;
dhcpcd.enable = false;
};
services = {
openssh = {
enable = true;
settings.UseDns = true;
};
};
# Don't wait for network startup
systemd.services.NetworkManager-wait-online.serviceConfig.ExecStart = ["" "${pkgs.networkmanager}/bin/nm-online -q"];
# Editable /etc/hosts for htb machines
environment.etc.hosts.enable = false;
}
+42
View File
@@ -0,0 +1,42 @@
{
config,
pkgs,
inputs,
lib,
...
}: {
imports = [
./nh.nix
./nixpkgs.nix
./substituters.nix
];
# we need git for flakes
environment.systemPackages = [pkgs.git];
nix = let
flakeInputs = lib.filterAttrs (_: v: lib.isType "flake" v) inputs;
in {
package = pkgs.lix;
# pin the registry to avoid downloading and evaling a new nixpkgs version every time
registry = lib.mapAttrs (_: v: {flake = v;}) flakeInputs;
# set the path for channels compat
nixPath = lib.mapAttrsToList (key: _: "${key}=flake:${key}") config.nix.registry;
settings = {
auto-optimise-store = true;
builders-use-substitutes = true;
experimental-features = ["nix-command" "flakes"];
flake-registry = "/etc/nix/registry.json";
# for direnv GC roots
keep-derivations = true;
keep-outputs = true;
trusted-users = ["root" "@wheel"];
accept-flake-config = false;
};
};
}
+13
View File
@@ -0,0 +1,13 @@
_: {
# nh default flake
environment.variables.NH_FLAKE = "/etc/nixos";
programs.nh = {
enable = true;
# weekly cleanup
clean = {
enable = true;
extraArgs = "--keep-since 7d";
};
};
}
+10
View File
@@ -0,0 +1,10 @@
_: {
nixpkgs = {
config = {
allowUnfree = true;
permittedInsecurePackages = [
"electron-38.7.1"
];
};
};
}
+25
View File
@@ -0,0 +1,25 @@
{
nix.settings = {
substituters = [
# high priority since it's almost always used
"https://cache.nixos.org?priority=10"
"https://attic.xuyh0120.win/lantian"
"https://chaotic-nyx.cachix.org/"
"https://fufexan.cachix.org"
"https://niri.cachix.org"
"https://nix-community.cachix.org"
];
trusted-public-keys = [
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"chaotic-nyx.cachix.org-1:HfnXSw4pj95iI/n17rIDy40agHj12WfF+Gqk6SonIT8="
"fufexan.cachix.org-1:LwCDjCJNJQf5XD2BV+yamQIMZfcKWR9ISIFy5curUsY="
"lantian:EeAUQ+W+6r7EtwnmYjeVwx5kOGEBpjlBfPlzGlTNvHc="
"someone.cachix.org-1:2K7KEjzbd3U+qMQRte/DGqttosw8EGgGVvu8vKu8D6A="
"niri.cachix.org-1:Wv0OmO7PsuocRKzfDoJ3mulSl7Z6oezYhGhR+3W2964="
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
];
};
}
+11
View File
@@ -0,0 +1,11 @@
_: {
imports = [
./fonts.nix
./xdg.nix
];
programs = {
dconf.enable = true;
seahorse.enable = true;
};
}
+10
View File
@@ -0,0 +1,10 @@
{pkgs, ...}: {
environment = {
shells = [pkgs.fish];
pathsToLink = ["/share/fish"];
};
programs = {
less.enable = true;
};
}
+54
View File
@@ -0,0 +1,54 @@
{
inputs,
pkgs,
...
}: {
fonts = {
packages = with pkgs; [
# icon fonts
material-symbols
# normal fonts
noto-fonts
noto-fonts-cjk-sans
noto-fonts-color-emoji
# nerdfonts
nerd-fonts.symbols-only
nerd-fonts.sauce-code-pro
cozette
inputs.self.packages.${stdenv.hostPlatform.system}.apple-fonts
];
# causes more issues than it solves
enableDefaultPackages = false;
fontconfig = {
enable = true;
antialias = true;
hinting = {
enable = true;
autohint = false;
style = "full";
};
subpixel = {
lcdfilter = "default";
rgba = "rgb";
};
defaultFonts = let
addAll = builtins.mapAttrs (_: v: ["Symbols Nerd Font"] ++ v ++ ["Noto Color Emoji"]);
in
addAll {
serif = ["New York Small"];
sansSerif = ["SF Pro Display"];
monospace = ["SauceCodePro Nerd Font"];
emoji = ["Noto Color Emoji"];
};
};
fontDir = {
enable = true;
decompressFonts = true;
};
};
}
+7
View File
@@ -0,0 +1,7 @@
{
qt = {
enable = true;
platformTheme = "gnome";
style = "adwaita-dark";
};
}
+28
View File
@@ -0,0 +1,28 @@
{
lib,
pkgs,
...
}: {
xdg.portal = {
enable = true;
config = {
common = {
default = ["gnome" "gtk"];
"org.freedesktop.impl.portal.ScreenCast" = "gnome";
"org.freedesktop.impl.portal.Screenshot" = "gnome";
"org.freedesktop.impl.portal.RemoteDesktop" = "gnome";
"org.freedesktop.impl.portal.Secret" = ["gnome-keyring"];
"org.freedesktop.impl.portal.OpenURI" = "gtk";
"org.freedesktop.impl.portal.OpenFile" = "gtk";
};
};
extraPortals = [
pkgs.xdg-desktop-portal-gtk
pkgs.xdg-desktop-portal-gnome
];
};
environment.sessionVariables = {
NIX_XDG_DESKTOP_PORTAL_DIR = lib.mkForce null;
};
}
+30
View File
@@ -0,0 +1,30 @@
{
lib,
pkgs,
...
}: {
services = {
printing = {
enable = true;
drivers = [pkgs.hplip];
};
irqbalance.enable = true;
thermald.enable = true;
speechd.enable = lib.mkForce false;
};
# Use in place of hypridle's before_sleep_cmd, since systemd does not wait for
# it to complete
powerManagement = {
enable = true;
cpuFreqGovernor = "schedutil";
powerDownCommands = ''
# Lock all sessions
loginctl lock-sessions
# Wait for lockscreen(s) to be up
sleep 1
'';
};
}
+3
View File
@@ -0,0 +1,3 @@
{
virtualisation.docker.enable = true;
}
+16
View File
@@ -0,0 +1,16 @@
{pkgs, ...}: {
services = {
# needed for GNOME services outside of GNOME Desktop
dbus = {
implementation = "broker";
packages = with pkgs; [
gcr
gnome-settings-daemon
libsecret
];
};
gnome.gnome-keyring.enable = true;
gvfs.enable = true;
};
}
+22
View File
@@ -0,0 +1,22 @@
{pkgs, ...}: {
# greetd display manager
services = {
greetd = let
session = {
command = "${pkgs.niri}/bin/niri-session";
user = "someone";
};
in {
enable = true;
settings = {
terminal.vt = 1;
default_session = session;
initial_session = session;
};
};
displayManager.autoLogin = {
user = "someone";
enable = true;
};
};
}
+17
View File
@@ -0,0 +1,17 @@
{
# enable location service
location.provider = "geoclue2";
# provide location
services.geoclue2 = {
enable = true;
geoProviderUrl = "https://beacondb.net/v1/geolocate";
submissionUrl = "https://beacondb.net/v2/geosubmit";
submissionNick = "geoclue";
appConfig.gammastep = {
isAllowed = true;
isSystem = false;
};
};
}
+39
View File
@@ -0,0 +1,39 @@
{pkgs, ...}: {
services.pipewire = {
enable = true;
alsa.enable = true;
alsa.support32Bit = true;
jack.enable = true;
pulse.enable = true;
wireplumber = {
enable = true;
configPackages = [
(pkgs.writeTextDir "share/wireplumber/bluetooth.lua.d/51-bluez-config.lua" ''
bluez_monitor.properties = {
["bluez5.enable-sbc-xq"] = true,
["bluez5.enable-msbc"] = true,
["bluez5.enable-hw-volume"] = true,
["bluez5.headset-roles"] = "[ hsp_hs hsp_ag hfp_hf hfp_ag ]",
["bluez5.a2dp.ldac.quality"] = "auto",
["bluez5.a2dp.aac.bitratemode"] = 0,
["bluez5.default.rate"] = 48000,
["bluez5.default.channels"] = 2,
["bluez5.headset-profile"] = "a2dp-only"
}
'')
];
};
extraConfig.pipewire."99-custom" = {
"context.properties" = {
default.clock = {
rate = 48000;
quantum = 1024;
min-quantum = 32;
max-quantum = 2048;
};
};
};
};
}
+20
View File
@@ -0,0 +1,20 @@
{
services = {
logind.settings.Login = {
powerKey = "suspend";
lidSwitch = "suspend";
lidSwitchExternalPower = "lock";
};
power-profiles-daemon.enable = true;
# battery info
upower = {
enable = true;
percentageLow = 20;
percentageCritical = 10;
percentageAction = 3;
criticalPowerAction = "PowerOff";
};
};
}
+7
View File
@@ -0,0 +1,7 @@
{...}: {
systemd.user.services.xdg-desktop-portal = {
serviceConfig = {
UnsetEnvironment = "NIX_XDG_DESKTOP_PORTAL_DIR";
};
};
}