feat: Add fingerprint scanner support and modularize work configurations
CI / Flake check (aarch64-linux) (push) Failing after 20m53s
CI / Flake check (x86_64-linux) (push) Failing after 3m20s
CI / Pre-commit checks (x86_64-linux) (push) Failing after 2m44s

- Add fingerprint.nix hardware module with TOD driver support
- Create separate laptop-work configuration with Cisco, Himmelblau, and MDATP work modules
- Move work-specific modules from shared to laptop-work profile
- Change work module enable defaults to false for better security-by-default
- Add MDATP support with enhanced modular structure
This commit is contained in:
2026-07-19 10:21:03 +02:00
parent 0893f80600
commit f489259af9
7 changed files with 84 additions and 9 deletions
+1 -1
View File
@@ -17,7 +17,7 @@ let
in {
options.work.cisco = {
enable = lib.mkEnableOption "Cisco Secure Client" // {
default = true;
default = false;
};
package = lib.mkOption {
+1
View File
@@ -3,6 +3,7 @@
./overlay.nix
./cisco.nix
./himmelblau.nix
./mdatp.nix
];
# Create the work directory for the user
+5 -1
View File
@@ -18,9 +18,13 @@
let
cfg = config.work.himmelblau;
in {
imports = [
inputs.himmelblau.nixosModules.himmelblau
];
options.work.himmelblau = {
enable = lib.mkEnableOption "Himmelblau Entra ID authentication" // {
default = true;
default = false;
};
};
+22
View File
@@ -0,0 +1,22 @@
{ config, lib, pkgs, inputs, ... }:
# Microsoft Defender for Endpoint
#
# References:
# - https://github.com/epetousis/nix-mdatp
let
cfg = config.work.mdatp;
in {
imports = [
inputs.mdatp.nixosModules.mdatp
];
options.work.mdatp = {
enable = lib.mkEnableOption "Microsoft Defender for Endpoint";
};
config = lib.mkIf cfg.enable {
services.mdatp.enable = true;
};
}