feat: Add fingerprint scanner support and modularize work configurations
CI / Flake check (aarch64-linux) (push) Failing after 20m53s
CI / Flake check (x86_64-linux) (push) Failing after 3m20s
CI / Pre-commit checks (x86_64-linux) (push) Failing after 2m44s

- Add fingerprint.nix hardware module with TOD driver support
- Create separate laptop-work configuration with Cisco, Himmelblau, and MDATP work modules
- Move work-specific modules from shared to laptop-work profile
- Change work module enable defaults to false for better security-by-default
- Add MDATP support with enhanced modular structure
This commit is contained in:
2026-07-19 10:21:03 +02:00
parent 0893f80600
commit f489259af9
7 changed files with 84 additions and 9 deletions
+17 -6
View File
@@ -18,7 +18,7 @@
# get these into the module system
specialArgs = {inherit inputs self;};
# shared modules for all configurations
# shared modules for all configurations (personal + work)
sharedModules = [
./aesthetic
"${mod}/services/gnome-services.nix"
@@ -26,11 +26,6 @@
"${home}"
"${self}/work"
inputs.sops-nix.nixosModules.sops
inputs.himmelblau.nixosModules.himmelblau
inputs.mdatp.nixosModules.mdatp
{
services.mdatp.enable = true;
}
];
in {
flake.nixosConfigurations = {
@@ -86,6 +81,22 @@ in {
];
};
# Laptop work: laptop profile + work modules (himmelblau, cisco, mdatp)
laptop-work = nixosSystem {
inherit specialArgs;
modules =
laptop
++ sharedModules
++ [
"${mod}/services/location.nix"
{
work.cisco.enable = true;
work.himmelblau.enable = true;
work.mdatp.enable = true;
}
];
};
# Server: severijnse.eu (Hetzner) — fully isolated under servers/hetzner/.
# Uses nixos-24.05 + disko + sops-nix and does NOT inherit the laptop's shared modules.
hetzner = nixosSystem24 {
+2 -1
View File
@@ -21,9 +21,10 @@ let
./services/pipewire.nix # audio
];
# Laptop-specific modules (battery, bluetooth)
# Laptop-specific modules (battery, bluetooth, fingerprint)
laptop = [
./hardware/bluetooth.nix
./hardware/fingerprint.nix
./services/power.nix
];
in {
+36
View File
@@ -0,0 +1,36 @@
{ config, lib, pkgs, ... }:
# Fingerprint scanner configuration
#
# Enable on laptops with a fingerprint reader:
# hardware.fingerprint.enable = true;
#
# For some sensors (Goodix, Elan, Synaptics), you may also need to set
# the TOD driver:
# hardware.fingerprint.todDriver = pkgs.libfprint-2-tod1-goodix;
#
# Reference: https://wiki.nixos.org/wiki/Fingerprint_scanner
let
cfg = config.hardware.fingerprint;
in {
options.hardware.fingerprint = {
enable = lib.mkEnableOption "fingerprint scanner support (fprintd)";
todDriver = lib.mkOption {
description = "Touch OEM Drivers (TOD) package to use for the fingerprint sensor";
type = lib.types.nullOr lib.types.package;
default = null;
example = lib.literalExpression "pkgs.libfprint-2-tod1-goodix";
};
};
config = lib.mkIf cfg.enable {
services.fprintd.enable = true;
services.fprintd.tod = lib.mkIf (cfg.todDriver != null) {
enable = true;
driver = cfg.todDriver;
};
};
}
+1 -1
View File
@@ -17,7 +17,7 @@ let
in {
options.work.cisco = {
enable = lib.mkEnableOption "Cisco Secure Client" // {
default = true;
default = false;
};
package = lib.mkOption {
+1
View File
@@ -3,6 +3,7 @@
./overlay.nix
./cisco.nix
./himmelblau.nix
./mdatp.nix
];
# Create the work directory for the user
+5 -1
View File
@@ -18,9 +18,13 @@
let
cfg = config.work.himmelblau;
in {
imports = [
inputs.himmelblau.nixosModules.himmelblau
];
options.work.himmelblau = {
enable = lib.mkEnableOption "Himmelblau Entra ID authentication" // {
default = true;
default = false;
};
};
+22
View File
@@ -0,0 +1,22 @@
{ config, lib, pkgs, inputs, ... }:
# Microsoft Defender for Endpoint
#
# References:
# - https://github.com/epetousis/nix-mdatp
let
cfg = config.work.mdatp;
in {
imports = [
inputs.mdatp.nixosModules.mdatp
];
options.work.mdatp = {
enable = lib.mkEnableOption "Microsoft Defender for Endpoint";
};
config = lib.mkIf cfg.enable {
services.mdatp.enable = true;
};
}