Files
nixos-config/system/core/boot.nix
T
jory cba6b18914 Harden server and add Nix-native CI + self-hosted Gitea Actions
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/
  X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail
  upstream copies via header_down on mail.severijnse.eu
- tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync
  _25/_465/_993, fail-safe placeholders; coredns zone updated
- pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint,
  ...); CI pre-commit job over x86_64 + aarch64 matrix
- gitea: enable Gitea Actions + self-hosted runner (native:host,
  aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook
- fix statix warnings (merge repeated systemd/database/configFile keys,
  inherit, bool-compare guards); add missing trailing newlines
2026-07-12 01:48:46 +02:00

40 lines
641 B
Nix

{
config,
pkgs,
...
}: {
boot = {
bootspec.enable = true;
initrd.systemd.enable = true;
supportedFilesystems = ["ntfs"];
kernelPackages = pkgs.linuxPackages_latest;
consoleLogLevel = 3;
kernelParams = [
"quiet"
"systemd.show_status=auto"
"rd.udev.log_level=3"
"plymouth.use-simpledrm"
];
plymouth.enable = true;
tmp = {
useTmpfs = true;
cleanOnBoot = true;
};
};
systemd.services.nix-daemon.environment.TMPDIR = "/var/tmp";
environment.systemPackages = [
config.boot.kernelPackages.cpupower
pkgs.brightnessctl
pkgs.ddcutil
];
}