7ed54e51a2
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/ X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail upstream copies via header_down on mail.severijnse.eu - tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync _25/_465/_993, fail-safe placeholders; coredns zone updated - pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint, ...); CI pre-commit job over x86_64 + aarch64 matrix - gitea: enable Gitea Actions + self-hosted runner (native:host, aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook - fix statix warnings (merge repeated systemd/database/configFile keys, inherit, bool-compare guards); add missing trailing newlines
21 lines
533 B
Nix
21 lines
533 B
Nix
{
|
|
lib,
|
|
pkgs,
|
|
...
|
|
}: let
|
|
toKDL = import ./_to-KDL.nix {inherit lib pkgs;};
|
|
settings = import ./_settings.nix {inherit lib pkgs;};
|
|
binds = import ./_binds.nix {inherit pkgs;};
|
|
rules = import ./_rules.nix;
|
|
|
|
finalConfig = toKDL.generate "niri-config.kdl" (settings // {inherit binds;} // rules);
|
|
in {
|
|
environment.sessionVariables = {
|
|
NIRI_CONFIG = "$HOME/.config/niri/config.kdl";
|
|
};
|
|
|
|
users.users.someone.packages = with pkgs; [niri];
|
|
|
|
xdg.configFile."niri/config.kdl".text = builtins.readFile finalConfig;
|
|
}
|