Author SHA1 Message Date
phundrak ba018ef841 refactor: change to litterate config
Configuration is now held by the `.org` files. All `.nix` files are
tangled from the org-mode files.
2026-10-06 12:40:58 +02:00
phundrak 5f4a7a4a42 refactor!: switch to dendritic pattern
BREAKING CHANGE: complete reorganization of the repository
2026-09-30 18:36:06 +02:00
phundrak 12684b4e9c fix(zellij): properly merge options 2026-09-21 06:46:38 +02:00
phundrak 02f409e04b chore(nix): update flakes lockfile 2026-09-02 13:12:19 +02:00
phundrak 3027c76245 feat(jujutsu): adapt jj config for vc-jj.el in Emacs 2026-08-20 22:18:34 +02:00
phundrak 1031d91890 feat(opencode): add sensible default tool authorisations 2026-08-20 22:17:33 +02:00
phundrak b315247f33 feat(caelestia): make idle configurable 2026-08-20 22:16:48 +02:00
phundrak b75cb297a0 chore(flake): update flake lockfile 2026-08-20 22:04:06 +02:00
phundrak 6ec681887d feat(mopidy): disable mopidy for phundrak 2026-07-12 16:40:41 +02:00
phundrak 1504173111 fix(bun): fix bun and bun-dependent packages on old CPUs 2026-07-09 16:20:14 +02:00
phundrak 76fa31e3d2 feat(caelestia): disable launcher on hover 2026-06-29 11:13:29 +02:00
phundrak 09da554a23 feat(ai): make LM Studio deactivable 2026-06-29 11:12:54 +02:00
phundrak cade8db400 chore: update flakes 2026-06-29 11:12:25 +02:00
phundrak 07afcdffd5 feat(nix): add jj-cz to devshell 2026-06-21 15:10:48 +02:00
phundrak f8b7c4c1d8 chore(nix): update flake lockfile 2026-06-21 15:10:08 +02:00
phundrak e3c90daf6d feat(eww): remove eww config 2026-06-21 15:06:43 +02:00
355 changed files with 9146 additions and 7474 deletions
-2
View File
@@ -9,7 +9,6 @@ keys:
- &tilo-host age1awytvphvty4f9wmdn86xnjg9kgetqjx8qlwj5d2882t4fyyzy58s3vg5k4
- &NaroMk3 age1erkn7dd022e90ktyj66aux9j9xvl0uzd6ru5cmrjsvcm5rtr5pfs7q6k9h
- &NaroMk3-host age16crkeglm3j3f6rveylytuerptjf9mwtv3hl89ywkmnnvdkntfchsuvrsk5
- &steamdeck age1ztuc996dapd7gpw5g7t4k3e9egv3dj6czxyslhnwula97w3cuytqlgzru0
creation_rules:
- path_regex: secrets/secrets.yaml$
key_groups:
@@ -24,4 +23,3 @@ creation_rules:
- *NaroMk3-host
- *elcafe
- *elcafe-host
- *steamdeck
+17
View File
@@ -0,0 +1,17 @@
* Licensing
The source code you can find in various programming languages in this
repository including, but not limited to, Javascript and CSS source
code is under the [[https://www.gnu.org/licenses/agpl-3.0.html][AGPL-3.0]] licence.
The creative work contained in [[https://labs.phundrak.com/phundrak/langue-phundrak-com][the main code repository]], on my [[https://github.com/Phundrak/langue-phundrak-fr/][Github
mirror]], and on my website [[https://langue.phundrak.com][langue.phundrak.com]] is dual-licenced
between the [[https://www.gnu.org/licenses/#FDL][GNU Free Documentation License]] ([[file:fdl-1.3.md][legal code]]) for the text
and the /Creative Commons Attribution-NonCommercial-ShareAlike 4.0
International/ ([[https://creativecommons.org/licenses/by-nc-sa/4.0/][CC BY-NC-SA 4.0]], [[https://creativecommons.org/licenses/by-nc-sa/4.0/legalcode][legal code]]) license.
Copies of all the mentionned licenses can be found in this code
repository.
If you wish to obtain a special license that is incompatible with the
current ones, please contact me at [[mailto:lucien@phundrak.com][lucien@phundrak.com]] so we can
discuss it.
Generated
+132 -80
View File
@@ -35,11 +35,11 @@
]
},
"locked": {
"lastModified": 1780375472,
"narHash": "sha256-Q8RAJoYlakA6B2I5DVcuxzNbhCNU1nnIjqQZYP1KGrM=",
"lastModified": 1789186140,
"narHash": "sha256-CEKrGzjO7Zk+BC0bsIySyu7q0vdy68V5MMq8YNKPpsk=",
"owner": "caelestia-dots",
"repo": "cli",
"rev": "d1c8c8fc09738d1b40576e97c274b4a11a2e0ac7",
"rev": "6b84ee5090ec50f36aa1a53990d57ab0013925a0",
"type": "github"
},
"original": {
@@ -58,40 +58,20 @@
"quickshell": "quickshell"
},
"locked": {
"lastModified": 1781178648,
"narHash": "sha256-z6V1T7MHShM7TfFIMCDp94Bi1Wk9LJfK96vm8YFGY5M=",
"lastModified": 1789736975,
"narHash": "sha256-PVYroXR/tuQdsWjp2XAqOhgY6dV2kN5nyzH4zha6ZPs=",
"owner": "caelestia-dots",
"repo": "shell",
"rev": "a16c957a8bd13e0cfd09928ca0a22fecd3681e44",
"rev": "d999d4878ee4cec134168e60d913714566a8cfa6",
"type": "github"
},
"original": {
"owner": "caelestia-dots",
"ref": "stable",
"repo": "shell",
"type": "github"
}
},
"copyparty": {
"inputs": {
"flake-utils": "flake-utils",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1781307432,
"narHash": "sha256-96fOVwSAFEoZNZtJM10E4Fz1kr59CwzYfUFidypPkKY=",
"owner": "9001",
"repo": "copyparty",
"rev": "a00bc93fe1b6f71afffa43fab4efb88dceddea62",
"type": "github"
},
"original": {
"owner": "9001",
"repo": "copyparty",
"type": "github"
}
},
"fenix": {
"inputs": {
"nixpkgs": [
@@ -115,22 +95,40 @@
"type": "github"
}
},
"flake-utils": {
"flake-file": {
"locked": {
"lastModified": 1678901627,
"narHash": "sha256-U02riOqrKKzwjsxc/400XnElV+UtPUQWpANPlyazjH0=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "93a2b84fc4b70d9e089d029deacc3583435c2ed6",
"lastModified": 1790698230,
"narHash": "sha256-24oUHm2evb57Dgu46X41rLY9ue/au47nxbaUTo6lJVc=",
"owner": "vic",
"repo": "flake-file",
"rev": "91280a19eede3b3035e3889a3523c27e8fc07886",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"owner": "vic",
"repo": "flake-file",
"type": "github"
}
},
"flake-utils_2": {
"flake-parts": {
"inputs": {
"nixpkgs-lib": "nixpkgs-lib"
},
"locked": {
"lastModified": 1788450739,
"narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "flake-parts",
"type": "github"
}
},
"flake-utils": {
"inputs": {
"systems": "systems"
},
@@ -148,7 +146,7 @@
"type": "github"
}
},
"flake-utils_3": {
"flake-utils_2": {
"inputs": {
"systems": "systems_2"
},
@@ -166,7 +164,7 @@
"type": "github"
}
},
"flake-utils_4": {
"flake-utils_3": {
"inputs": {
"systems": "systems_3"
},
@@ -207,11 +205,11 @@
]
},
"locked": {
"lastModified": 1781305496,
"narHash": "sha256-g8Vv4Qfc7n+lgov97REu3X6BeJtvYY0hlSUZR1GrGQQ=",
"lastModified": 1788229478,
"narHash": "sha256-G0F2rFORVcFkEvVdE/qWQTnYekIc77YP5/vRF9nZlxU=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "c87a39aa979acc4848016d2220c6238390d84779",
"rev": "1dc2d1f720ab17fc7981e087346bf54b26d284b1",
"type": "github"
},
"original": {
@@ -220,21 +218,36 @@
"type": "github"
}
},
"import-tree": {
"locked": {
"lastModified": 1788467110,
"narHash": "sha256-ljEMTXP/rH0tOvDzc9gzwww6KcHRPRnEHzd9lK48V7s=",
"owner": "vic",
"repo": "import-tree",
"rev": "eb1b52eaecc57f7c136d07ae8a93e724dfecac46",
"type": "github"
},
"original": {
"owner": "vic",
"repo": "import-tree",
"type": "github"
}
},
"jj-cz": {
"inputs": {
"alejandra": "alejandra",
"flake-utils": "flake-utils_3",
"flake-utils": "flake-utils_2",
"nixpkgs": [
"nixpkgs"
],
"rust-overlay": "rust-overlay"
},
"locked": {
"lastModified": 1781450428,
"narHash": "sha256-EWQpPImWpq0RHgyqa/lBoiMsjRjNdJCYa9fU2q+7nOg=",
"lastModified": 1781867614,
"narHash": "sha256-GHy8hEZtToo7FLxEZm0x/pn/fjg1w9sx7ZP9hRd1fcM=",
"ref": "develop",
"rev": "4ad6e944b22a1d9990d43ac02650fc4d90fb1b4c",
"revCount": 49,
"rev": "d2c48605aac4ca9580d8a34aad4c65371c5a7cc1",
"revCount": 52,
"type": "git",
"url": "https://labs.phundrak.com/phundrak/jj-cz"
},
@@ -245,19 +258,24 @@
}
},
"m3shapes": {
"flake": false,
"inputs": {
"nixpkgs": [
"caelestia-shell",
"nixpkgs"
]
},
"locked": {
"lastModified": 1781017666,
"narHash": "sha256-kfHyzZaPHgqZML48OA+5JwBOsLdQJ2ci/aGPShvUB4Y=",
"lastModified": 1787906858,
"narHash": "sha256-YZelgEZflFNwGutX4/tIzBdbOeghJgE2oDw0uWYGxns=",
"owner": "soramanew",
"repo": "m3shapes",
"rev": "bdc327b29f95394a732baf3c9b19658ba23755b6",
"rev": "32ad9ce328bb77ed349b40a3be10ee9ea610b8ab",
"type": "github"
},
"original": {
"owner": "soramanew",
"repo": "m3shapes",
"rev": "bdc327b29f95394a732baf3c9b19658ba23755b6",
"rev": "32ad9ce328bb77ed349b40a3be10ee9ea610b8ab",
"type": "github"
}
},
@@ -268,11 +286,11 @@
]
},
"locked": {
"lastModified": 1780816331,
"narHash": "sha256-0BYqs8yKWkOz2Q7+SP18N5E5gmDKSo6LSxIVIa0wWes=",
"lastModified": 1788080100,
"narHash": "sha256-n14luQo3F/ZLfCEHk1QieiI1nGnW92ZQZeZ0UIb0UMQ=",
"owner": "nix-community",
"repo": "nix-index-database",
"rev": "1a2ea89c917781e88508d9fd2b507f2d2a0e173c",
"rev": "dbb978fa87faf13398e90ccbc52c343d21c7dd6d",
"type": "github"
},
"original": {
@@ -283,11 +301,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1781074563,
"narHash": "sha256-md8WlXOlfnIeHeOScMTTHFyf2d6iaTwPl2apR5EQ3P4=",
"lastModified": 1788179007,
"narHash": "sha256-hn1oU2rue2SYK8dAr8+WNZWtbsz1S2W5mnHlSEuh3bo=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "9ae611a455b90cf061d8f332b977e387bda8e1ca",
"rev": "34ab99075ac4f7e40cf037eef32cb1c360bb85e9",
"type": "github"
},
"original": {
@@ -297,13 +315,44 @@
"type": "github"
}
},
"nixpkgs-lib": {
"locked": {
"lastModified": 1788057806,
"narHash": "sha256-DTQSMxzDWmT0zhguthvegnVkn7CFqGCv4IHCzk5ZUpM=",
"owner": "nix-community",
"repo": "nixpkgs.lib",
"rev": "596e2e3940e09b2abbeb03f75fa1828c57fcd72c",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nixpkgs.lib",
"type": "github"
}
},
"nixpkgsPinetab2Kernel": {
"locked": {
"lastModified": 1782467914,
"narHash": "sha256-pGvFkM8N0xEkIIXDe5YYfbEAvHrk4IxBrjB/x8OomhE=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "e73de5be04e0eff4190a1432b946d469c794e7b4",
"type": "github"
},
"original": {
"owner": "nixos",
"repo": "nixpkgs",
"rev": "e73de5be04e0eff4190a1432b946d469c794e7b4",
"type": "github"
}
},
"nixpkgsStable": {
"locked": {
"lastModified": 1780952837,
"narHash": "sha256-Fwd1+spDtQ0hDyBwme6ufG3n4mY0UrjjFdYHv+G/Hds=",
"lastModified": 1782847189,
"narHash": "sha256-twXPFqFsrrY5r28Zh7Homgcp2gUMBgQ6WDS98Q/3xFI=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "e820eb4a444b46a19b2e03e8dfd2359439ff30fe",
"rev": "b6018f87da91d19d0ab4cf979885689b469cdd41",
"type": "github"
},
"original": {
@@ -314,7 +363,7 @@
},
"pumo-system-info": {
"inputs": {
"flake-utils": "flake-utils_4",
"flake-utils": "flake-utils_3",
"nixpkgs": [
"nixpkgs"
],
@@ -342,11 +391,11 @@
]
},
"locked": {
"lastModified": 1780303737,
"narHash": "sha256-7HgdJBG4BgAPDyHKKxWtxj7nziqsQo6zQCXtwy+L9fs=",
"lastModified": 1787994703,
"narHash": "sha256-6SUZyyALo19heYPa/Xmu2H4zV+wvdfVX4fTcqbgHRnI=",
"ref": "refs/heads/master",
"rev": "b66495fcc5022681b56b61f928c7acbe910e722c",
"revCount": 821,
"rev": "2d3b3e9c70ef380dff751b61d334dc88df016c29",
"revCount": 856,
"type": "git",
"url": "https://git.outfoxxed.me/outfoxxed/quickshell"
},
@@ -361,7 +410,7 @@
"nixpkgsStable"
],
"nixpkgsUnstable": [
"nixpkgs"
"nixpkgsPinetab2Kernel"
],
"utils": [
"flake-utils"
@@ -385,12 +434,15 @@
"root": {
"inputs": {
"caelestia-shell": "caelestia-shell",
"copyparty": "copyparty",
"flake-utils": "flake-utils_2",
"flake-file": "flake-file",
"flake-parts": "flake-parts",
"flake-utils": "flake-utils",
"home-manager": "home-manager",
"import-tree": "import-tree",
"jj-cz": "jj-cz",
"nix-index-database": "nix-index-database",
"nixpkgs": "nixpkgs",
"nixpkgsPinetab2Kernel": "nixpkgsPinetab2Kernel",
"nixpkgsStable": "nixpkgsStable",
"pumo-system-info": "pumo-system-info",
"rockchip": "rockchip",
@@ -466,11 +518,11 @@
]
},
"locked": {
"lastModified": 1780547341,
"narHash": "sha256-Gq8KNx5A7hBB3uGJaj6eQfLDIz5YdLu92gqBcvHvoUo=",
"lastModified": 1786629091,
"narHash": "sha256-gkig4nPi1CWc4Z50GBsjE4ygSE7hMpl/TwID2an2Cck=",
"owner": "Mic92",
"repo": "sops-nix",
"rev": "9ed65852b6257fbeae4355bc24ecfea307ca759a",
"rev": "a8627b21b9107c5711c96b84f32a9a4b3d45295f",
"type": "github"
},
"original": {
@@ -487,11 +539,11 @@
"systems": "systems_4"
},
"locked": {
"lastModified": 1781101834,
"narHash": "sha256-gNVY6SYglFe37FpD+NnOjTipsqvVMM2vh/uc22KDEsA=",
"lastModified": 1788263070,
"narHash": "sha256-Mw163zYcjr59hB2JMC1iKU1Y69SNKZ2r/haXZ07UWQY=",
"owner": "Gerg-L",
"repo": "spicetify-nix",
"rev": "0243dd6707c969fc8440216c811b3f2e4a4cceb7",
"rev": "27ff19b00338052e8a504e1d1a34efad82c4bb26",
"type": "github"
},
"original": {
@@ -507,11 +559,11 @@
]
},
"locked": {
"lastModified": 1781149687,
"narHash": "sha256-TanScAdzeSOcaVDN4V4rnTAlbuizMJlrVSSt9QkkPEA=",
"lastModified": 1788143273,
"narHash": "sha256-YXleehtVHiLcH2+V0lSrl5Nmo2c+J11tI3+l4l9q3AQ=",
"owner": "nix-community",
"repo": "srvos",
"rev": "7a66d11f03dd0588229af7a2b7018a435638dbf5",
"rev": "e4d3f8fe5f1d4246d32177315edf8d9104f1c32b",
"type": "github"
},
"original": {
@@ -587,11 +639,11 @@
]
},
"locked": {
"lastModified": 1781242638,
"narHash": "sha256-n0s/QM5ZJl3/v4tgDLsATIHR2dC+4+Aa2BT6FnthGy4=",
"lastModified": 1788083005,
"narHash": "sha256-e6U3sXUlu/QzZyJp/+ymW8s57Jbdb7bwT9+WaTAhHfQ=",
"owner": "youwen5",
"repo": "zen-browser-flake",
"rev": "79f7cca35f9e4e38d1f8767bac130159f60866cc",
"rev": "afbbbef7c3c00f160f4a9dfdd8c6c6b8b089a33f",
"type": "github"
},
"original": {
+42 -168
View File
@@ -1,205 +1,79 @@
# DO-NOT-EDIT. This file was auto-generated using github:denful/flake-file.
# Use `nix run .#write-flake` to regenerate it.
{
description = "Home Manager configuration of phundrak";
description = "NixOS and Home Manager configuration of P'undrak";
outputs = inputs: inputs.flake-parts.lib.mkFlake { inherit inputs; } (inputs.import-tree ./modules);
nixConfig = {
extra-experimental-features = [
"nix-command"
"flakes"
];
extra-substituters = [
"https://phundrak.cachix.org?priority=10"
"https://nix-community.cachix.org?priority=20"
"https://cache.nixos.org?priority=40"
];
extra-trusted-public-keys = [
"phundrak.cachix.org-1:osJAkYO0ioTOPqaQCIXMfIRz1/+YYlVFkup3R2KSexk="
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
];
http-connections = 128;
};
inputs = {
nixpkgsStable.url = "nixpkgs/nixos-25.11";
nixpkgs.url = "github:nixos/nixpkgs?ref=nixos-unstable";
caelestia-shell = {
url = "github:caelestia-dots/shell?ref=stable";
inputs.nixpkgs.follows = "nixpkgs";
};
flake-file.url = "github:vic/flake-file";
flake-parts.url = "github:hercules-ci/flake-parts";
flake-utils.url = "github:numtide/flake-utils";
home-manager = {
url = "github:nix-community/home-manager";
inputs.nixpkgs.follows = "nixpkgs";
};
nix-index-database = {
url = "github:nix-community/nix-index-database";
inputs.nixpkgs.follows = "nixpkgs";
};
caelestia-shell = {
url = "github:caelestia-dots/shell";
inputs.nixpkgs.follows = "nixpkgs";
};
copyparty = {
url = "github:9001/copyparty";
inputs.nixpkgs.follows = "nixpkgs";
};
import-tree.url = "github:vic/import-tree";
jj-cz = {
url = "git+https://labs.phundrak.com/phundrak/jj-cz?ref=develop";
inputs.nixpkgs.follows = "nixpkgs";
};
nix-index-database = {
url = "github:nix-community/nix-index-database";
inputs.nixpkgs.follows = "nixpkgs";
};
nixpkgs.url = "github:nixos/nixpkgs?ref=nixos-unstable";
nixpkgsPinetab2Kernel.url = "github:nixos/nixpkgs/e73de5be04e0eff4190a1432b946d469c794e7b4";
nixpkgsStable.url = "nixpkgs/nixos-25.11";
pumo-system-info = {
url = "git+https://labs.phundrak.com/phundrak/pumo-system-info";
inputs.nixpkgs.follows = "nixpkgs";
};
rockchip = {
url = "github:raboof/nixos-rockchip/pinetab-linux-7.0";
inputs.utils.follows = "flake-utils";
inputs.nixpkgsStable.follows = "nixpkgsStable";
inputs.nixpkgsUnstable.follows = "nixpkgs";
inputs = {
nixpkgsStable.follows = "nixpkgsStable";
nixpkgsUnstable.follows = "nixpkgsPinetab2Kernel";
utils.follows = "flake-utils";
};
};
sops-nix = {
url = "github:Mic92/sops-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
spicetify = {
url = "github:Gerg-L/spicetify-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
srvos = {
url = "github:nix-community/srvos";
inputs.nixpkgs.follows = "nixpkgs";
};
zen-browser = {
url = "github:youwen5/zen-browser-flake";
inputs.nixpkgs.follows = "nixpkgs";
};
};
nixConfig = {
extra-trusted-public-keys = [
"marpa-local:XoO+dFN4PeauF52pYuy3Vh4Sdtl2qIdxu5aUasWKv6Q="
"phundrak.cachix.org-1:osJAkYO0ioTOPqaQCIXMfIRz1/+YYlVFkup3R2KSexk="
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
];
extra-substituters = [
"http://marpa:5000?priority=5"
"https://phundrak.cachix.org?priority=10"
"https://nix-community.cachix.org?priority=20"
"https://cache.nixos.org?priority=40"
];
extra-experimental-features = [
"nix-command"
"flakes"
];
http-connections = 128;
};
outputs = {
self,
nixpkgs,
flake-utils,
home-manager,
rockchip,
srvos,
...
} @ inputs:
flake-utils.lib.eachDefaultSystem (
system: let
inherit (self) outputs;
pkgs = nixpkgs.legacyPackages.${system};
in {
formatter = pkgs.alejandra;
devShells.default = pkgs.mkShell {
buildInputs = [
pkgs.nh
pkgs.jujutsu
pkgs.git
];
};
packages = {
homeConfigurations = let
extraSpecialArgs = {inherit inputs outputs system;};
pkgs = nixpkgs.legacyPackages.x86_64-linux;
defaultUserModules = [
inputs.sops-nix.homeManagerModules.sops
inputs.spicetify.homeManagerModules.default
inputs.caelestia-shell.homeManagerModules.default
];
withUserModules = modules: nixpkgs.lib.lists.flatten (defaultUserModules ++ [modules]);
in {
"phundrak@alys" = home-manager.lib.homeManagerConfiguration {
inherit extraSpecialArgs pkgs;
modules = withUserModules ./users/phundrak/host/alys.nix;
};
"creug@elcafe" = home-manager.lib.homeManagerConfiguration {
inherit extraSpecialArgs pkgs;
modules = withUserModules ./users/creug/host/elcafe.nix;
};
"phundrak@elcafe" = home-manager.lib.homeManagerConfiguration {
inherit extraSpecialArgs pkgs;
modules = withUserModules ./users/phundrak/host/elcafe.nix;
};
"phundrak@gampo" = home-manager.lib.homeManagerConfiguration {
inherit extraSpecialArgs pkgs;
modules = withUserModules ./users/phundrak/host/gampo.nix;
};
"phundrak@marpa" = home-manager.lib.homeManagerConfiguration {
inherit extraSpecialArgs pkgs;
modules = withUserModules ./users/phundrak/host/marpa.nix;
};
"phundrak@NaroMk3" = home-manager.lib.homeManagerConfiguration {
inherit extraSpecialArgs pkgs;
modules = withUserModules ./users/phundrak/host/naromk3.nix;
};
"phundrak@pinetab2" = home-manager.lib.homeManagerConfiguration {
inherit extraSpecialArgs pkgs;
modules = withUserModules ./users/phundrak/host/pinetab2.nix;
};
"deck@steamdeck" = home-manager.lib.homeManagerConfiguration {
inherit extraSpecialArgs pkgs;
modules = withUserModules ./users/phundrak/host/steamdeck.nix;
};
"phundrak@tilo" = home-manager.lib.homeManagerConfiguration {
inherit extraSpecialArgs pkgs;
modules = withUserModules ./users/phundrak/host/tilo.nix;
};
};
nixosConfigurations = let
specialArgs = {inherit inputs outputs;};
defaultSystemModules = [
inputs.sops-nix.nixosModules.sops
inputs.copyparty.nixosModules.default
];
withSystemModules = modules: nixpkgs.lib.lists.flatten (defaultSystemModules ++ [modules]);
pinetabConfig = import ./utils/pinetab.nix {
inherit nixpkgs rockchip specialArgs;
additionalModules = defaultSystemModules;
};
in {
alys = nixpkgs.lib.nixosSystem {
inherit specialArgs;
modules = withSystemModules ./hosts/alys/configuration.nix;
};
elcafe = nixpkgs.lib.nixosSystem {
inherit specialArgs;
modules = withSystemModules ./hosts/elcafe/configuration.nix;
};
gampo = nixpkgs.lib.nixosSystem {
inherit specialArgs;
modules = withSystemModules ./hosts/gampo/configuration.nix;
};
marpa = nixpkgs.lib.nixosSystem {
inherit specialArgs;
modules = withSystemModules ./hosts/marpa;
};
NaroMk3 = nixpkgs.lib.nixosSystem {
inherit specialArgs;
modules = withSystemModules [
srvos.nixosModules.server
srvos.nixosModules.hardware-hetzner-cloud
srvos.nixosModules.mixins-terminfo
./hosts/naromk3
];
};
pinetab2 = pinetabConfig "x86_64-linux" ./hosts/pinetab2/gnome.nix;
tilo = nixpkgs.lib.nixosSystem {
inherit specialArgs;
modules = withSystemModules ./hosts/tilo/configuration.nix;
};
};
};
}
);
}
-41
View File
@@ -1,41 +0,0 @@
{inputs, ...}: {
imports = [
./hardware-configuration.nix
inputs.home-manager.nixosModules.default
../../system
];
mySystem = {
boot = {
kernel.hardened = true;
systemd-boot = false;
zram = {
enable = true;
memoryMax = 512;
};
};
dev.docker.enable = true;
networking = {
hostname = "alys";
domain = "phundrak.com";
id = "41157110";
};
packages.nix.gc.automatic = true;
services = {
endlessh.enable = true;
ssh = {
enable = true;
allowedUsers = ["phundrak"];
passwordAuthentication = false;
};
};
users = {
root.disablePassword = true;
phundrak = {
enable = true;
trusted = true;
};
};
};
system.stateVersion = "23.11";
}
-28
View File
@@ -1,28 +0,0 @@
{
modulesPath,
lib,
...
}: {
imports = [(modulesPath + "/profiles/qemu-guest.nix")];
boot = {
loader.grub = {
efiSupport = true;
efiInstallAsRemovable = true;
device = "nodev";
};
initrd.availableKernelModules = ["ata_piix" "uhci_hcd" "xen_blkfront" "vmw_pvscsi"];
initrd.kernelModules = ["nvme"];
};
fileSystems = {
"/" = {
device = "/dev/vda1";
fsType = "ext4";
};
"/boot" = {
device = "/dev/disk/by-uuid/F137-8D01";
fsType = "vfat";
};
};
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
-90
View File
@@ -1,90 +0,0 @@
{
inputs,
config,
...
}: {
imports = [
./hardware-configuration.nix
inputs.home-manager.nixosModules.default
../../system
];
sops.secrets = {
"elcafe/traefik/env".restartUnits = ["traefik.service"];
"elcafe/traefik/dynamic".restartUnits = ["traefik.service"];
# "elcafe/copyparty/passwords/creug" = {
# restartUnits = ["copyparty.service"];
# owner = "creug";
# };
# "elcafe/copyparty/passwords/phundrak" = {
# restartUnits = ["copyparty.service"];
# owner = "phundrak";
# };
};
mySystem = {
boot = {
kernel = {
hardened = true;
cpuVendor = "intel";
};
grub = {
enable = true;
device = "/dev/sdh";
};
zfs = {
enable = true;
pools = ["tank"];
};
};
dev.docker = {
enable = true;
storage = "/tank/docker/";
};
misc.keymap = "fr";
networking = {
hostname = "elcafe";
id = "501c7fb9";
};
packages.nix.gc.automatic = true;
services = {
endlessh.enable = true;
ssh = {
enable = true;
allowedUsers = ["phundrak"];
passwordAuthentication = true;
};
traefik = {
enable = false;
environmentFiles = [config.sops.secrets."elcafe/traefik/env".path];
dynamicConfigFile = config.sops.secrets."elcafe/traefik/dynamic".path;
};
};
users = {
root.disablePassword = true;
phundrak = {
enable = true;
trusted = true;
};
creug = {
enable = true;
sudo = true;
};
};
};
# services.copyparty = import ./copyparty.nix {
# passwordFiles = {
# creug = config.sops.secrets."elcafe/copyparty/passwords/creug".path;
# phundrak = config.sops.secrets."elcafe/copyparty/passwords/phundrak".path;
# };
# };
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions
# on your system were taken. It's perfectly fine and recommended to leave
# this value at the release version of the first install of this system.
# Before changing this value read the documentation for this option
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
system.stateVersion = "23.11"; # Did you read the comment?
}
-23
View File
@@ -1,23 +0,0 @@
{passwordFiles}: {
enable = true;
user = "creug";
group = "users";
accounts = {
creug.passwordFile = passwordFiles.creug;
phundrak.passwordFile = passwordFiles.phundrak;
};
volumes = {
"/plex" = {
path = "/plex";
access.rwmd = ["creug" "phundrak"];
flags = {
e2dsa = true;
e2ts = true;
xdev = true;
xvol = true;
dedup = true;
nohash = "\\.iso$";
};
};
};
}
-88
View File
@@ -1,88 +0,0 @@
{
config,
pkgs,
inputs,
...
}: {
imports = [
inputs.sops-nix.nixosModules.sops
./hardware-configuration.nix
../../system
];
mySystem = {
boot = {
plymouth.enable = true;
kernel = {
cpuVendor = "intel";
package = pkgs.linuxPackages;
};
systemd-boot = true;
};
desktop = {
hyprland.enable = true;
xserver = {
enable = true;
de = "gnome";
};
};
dev.docker = {
enable = true;
podman.enable = true;
autoprune.enable = true;
};
hardware = {
bluetooth.enable = true;
fingerprint.enable = true;
input = {
corne.allowHidAccess = true;
ibmTrackpoint.disable = true;
opentablet.enable = true;
};
sound.enable = true;
};
i18n.input.enable = true;
misc.keymap = "fr-bepo";
networking = {
hostname = "gampo";
id = "0630b33f";
};
packages = {
appimage.enable = true;
flatpak.enable = true;
nix = {
gc.automatic = true;
nix-ld.enable = true;
};
};
programs.steam.enable = true;
services = {
fwupd.enable = true;
ssh.enable = true;
};
users = {
root.disablePassword = true;
phundrak = {
enable = true;
trusted = true;
};
};
};
sops.secrets.extraHosts = {
inherit (config.users.users.root) group;
owner = config.users.users.phundrak.name;
mode = "0440";
};
security.rtkit.enable = true;
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database
# versions on your system were taken. It‘s perfectly fine and
# recommended to leave this value at the release version of the
# first install of this system. Before changing this value read
# the documentation for this option (e.g. man configuration.nix or
# on https://nixos.org/nixos/options.html).
system.stateVersion = "23.11"; # Did you read the comment?
}
-158
View File
@@ -1,158 +0,0 @@
{
config,
inputs,
...
}: {
imports = [
inputs.sops-nix.nixosModules.sops
./hardware-configuration.nix
../../system
];
fileSystems = {
"/home".options = [
"compress=zstd:3" # Good balance of compression vs speed
"space_cache=v2" # Better performance
"noatime" # Don't update access times (less writes)
];
"/mnt/ai" = {
device = "/dev/disk/by-uuid/47e87286-caaa-4e43-b2fd-b9eceac90fe9";
fsType = "btrfs";
options = [
"compress=zstd:3" # Good balance of compression vs speed
"space_cache=v2" # Better performance
"noatime" # Don't update access times (less writes)
];
};
"/mnt/games" = {
device = "/dev/disk/by-uuid/a8453133-76dc-44bd-a825-444c3305fd9b";
fsType = "btrfs";
options = [
"compress=zstd:3" # Good balance of compression vs speed
"space_cache=v2" # Better performance
"noatime" # Don't update access times (less writes)
];
};
"/games" = {
device = "/dev/disk/by-uuid/77d32db8-2e85-4593-b6b8-55d4f9d14e1a";
fsType = "ext4";
};
};
services.displayManager.autoLogin = {
user = "phundrak";
enable = true;
};
mySystem = {
boot = {
plymouth.enable = true;
kernel = {
cpuVendor = "amd";
v4l2loopback.enable = true;
extraModprobeConfig = ''
options snd_usb_audio vid=0x1235 pid=0x8212 device_setup=1
'';
};
systemd-boot = true;
};
desktop = {
hyprland.enable = true;
niri.enable = true;
waydroid.enable = true;
xserver = {
enable = true;
de = "gnome";
};
};
dev = {
docker = {
enable = true;
podman.enable = true;
autoprune.enable = true;
};
qemu.enable = true;
};
hardware = {
amdgpu.enable = true;
bluetooth.enable = true;
input = {
corne.allowHidAccess = true;
opentablet.enable = true;
};
sound = {
enable = true;
noisetorch = true;
jack = true;
scarlett.enable = true;
};
};
i18n.input.enable = true;
misc.keymap = "fr-bepo";
networking = {
hostname = "marpa";
id = "7EA4A111";
firewall.openPortRanges = [
{
# Sunshine
from = 1714;
to = 1764;
}
];
};
packages = {
appimage.enable = true;
flatpak.enable = true;
nix.nix-ld.enable = true;
};
programs.steam.enable = true;
services = {
fwupd.enable = true;
harmonia = {
enable = true;
signKeyPaths = [config.sops.secrets."marpa/nix-cache-priv-key".path];
};
languagetool.enable = true;
printing.enable = true;
ssh.enable = true;
sunshine = {
enable = true;
autostart = true;
};
};
users = {
root.disablePassword = true;
phundrak = {
enable = true;
trusted = true;
};
};
};
sops.secrets = {
"marpa/nix-cache-priv-key" = {};
extraHosts = {
inherit (config.users.users.root) group;
owner = config.users.users.phundrak.name;
mode = "0440";
};
};
services.udev.extraHwdb = ''
mouse:usb:047d:80a6:*
LIBINPUT_MIDDLE_EMULATION_ENABLED=1
'';
security = {
polkit.enable = true;
rtkit.enable = true;
};
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions
# on your system were taken. It‘s perfectly fine and recommended to leave
# this value at the release version of the first install of this system.
# Before changing this value read the documentation for this option
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
system.stateVersion = "23.11"; # Did you read the comment?
}
-24
View File
@@ -1,24 +0,0 @@
{
# imports = [
# ./logind.nix
# ../../../system
# ];
# imports = [
# ./logind.nix
# ../../../modules/ssh.nix
# ../../../modules/sunshine.nix
# ];
# modules = {
# sunshine = {
# enable = true;
# autostart = true;
# };
# };
# services = {
# blueman.enable = true;
# fwupd.enable = true;
# printing.enable = true;
# openssh.enable = true;
# };
}
-11
View File
@@ -1,11 +0,0 @@
{
services.xserver = {
enable = true;
displayManager.gdm.enable = true;
desktopManager.gnome.enable = true;
xkb = {
layout = "fr";
variant = "bepo_afnor";
};
};
}
-6
View File
@@ -1,6 +0,0 @@
{
services.logind = {
powerKey = "ignore";
powerKeyLongPress = "ignore";
};
}
-78
View File
@@ -1,78 +0,0 @@
{inputs, ...}: {
imports = [
./hardware-configuration.nix
inputs.home-manager.nixosModules.default
../../system
];
mySystem = {
boot = {
kernel = {
hardened = true;
cpuVendor = "amd";
};
grub = {
enable = true;
device = "/dev/sdb";
};
};
dev.docker.enable = true;
misc.keymap = "fr-bepo";
networking = {
hostname = "NaroMk3";
id = "0003beef";
firewall = {
openPorts = [
22 # Gitea SSH
25 # SMTP
80 # HTTP
443 # HTTPS
465 # SMTPS
993 # IMAPS
];
};
};
packages.nix.gc.automatic = true;
services = {
endlessh.enable = false;
ssh = {
enable = true;
allowedUsers = ["phundrak"];
passwordAuthentication = false;
port = 2222; # port 22 will be used by Gitea
};
};
users = {
root.disablePassword = true;
phundrak = {
enable = true;
trusted = true;
};
};
};
# This option defines the first version of NixOS you have installed
# on this particular machine, and is used to maintain compatibility
# with application data (e.g. databases) created on older NixOS
# versions.
#
# Most users should NEVER change this value after the initial
# install, for any reason, even if you've upgraded your system to a
# new NixOS release.
#
# This value does NOT affect the Nixpkgs version your packages and
# OS are pulled from, so changing it will NOT upgrade your system -
# see https://nixos.org/manual/nixos/stable/#sec-upgrading for how
# to actually do that.
#
# This value being lower than the current NixOS release does NOT
# mean your system is out of date, out of support, or vulnerable.
#
# Do NOT change this value unless you have manually inspected all
# the changes it would make to your configuration, and migrated your
# data accordingly.
#
# For more information, see `man configuration.nix` or
# https://nixos.org/manual/nixos/stable/options#opt-system.stateVersion
system.stateVersion = "25.05"; # Did you read the comment?
}
-74
View File
@@ -1,74 +0,0 @@
{
config,
inputs,
...
}: {
imports = [
inputs.sops-nix.nixosModules.sops
../../system/desktop
../../system/dev
../../system/hardware
../../system/i18n
../../system/misc.nix
../../system/network
../../system/packages
../../system/security
../../system/services
../../system/users
];
system.stateVersion = "25.11";
# documentation.nixos.enable = false;
# nix.settings.trusted-users = ["root" "@wheel"];
mySystem = {
desktop = {
hyprland.enable = true;
niri.enable = true;
waydroid.enable = true;
xserver = {
enable = true;
de = "gnome";
};
};
dev.docker = {
enable = true;
podman.enable = true;
autoprune.enable = true;
};
hardware = {
bluetooth.enable = true;
input.opentablet.enable = true;
sound.enable = true;
};
i18n.input.enable = true;
misc.keymap = "fr-bepo";
networking = {
hostname = "pinetab2";
id = "99a11b15";
wifi.disablePowersave = true;
};
packages = {
appimage.enable = true;
flatpak.enable = true;
nix = {
gc.automatic = true;
nix-ld.enable = true;
};
};
services.ssh.enable = true;
users = {
root.disablePassword = true;
phundrak = {
enable = true;
trusted = true;
};
};
};
sops.secrets.extraHosts = {
inherit (config.users.users.root) group;
owner = config.users.users.phundrak.name;
mode = "0440";
};
}
-37
View File
@@ -1,37 +0,0 @@
{
pkgs,
config,
...
}: {
# https://github.com/systemd/systemd/pull/35304#issuecomment-3855146191
# gnome autorotate expects 'normal' is the _display panel_ normal, but
# mutter autoconfiguration rotates by 90deg.
# compensating with gdctl for now, though it would be better to 'properly'
# fix this.
services.udev = {
extraHwdb = ''
sensor:modalias:*sc7a20:*
ACCEL_MOUNT_MATRIX=1, 0, 0; 0, 0, 1; 0, 1, 0
'';
extraRules = ''
ACTION=="add", SUBSYSTEM=="usb", ATTRS{idVendor}=="1018", ATTRS{idProduct}=="1006", ENV{SYSTEMD_WANTS}+="landscape.service", TAG+="systemd"
'';
};
systemd.services.landscape = {
script = ''
${pkgs.mutter}/bin/gdctl set --logical-monitor --primary --monitor=DSI-1 --transform normal
'';
serviceConfig.User = "phundrak";
serviceConfig.Type = "oneshot";
environment = {
"DBUS_SESSION_BUS_ADDRESS" = "unix:path=/run/user/${toString config.users.users."phundrak".uid}/bus";
};
};
environment.systemPackages = with pkgs; [
gnomeExtensions.arc-menu
gnomeExtensions.dash-to-dock
gnomeExtensions.dash-to-panel
gnomeExtensions.gjs-osk
gnomeExtensions.one-window-wonderland
];
}
-64
View File
@@ -1,64 +0,0 @@
{inputs, ...}: {
imports = [
./hardware-configuration.nix
inputs.home-manager.nixosModules.default
../../system
./services
];
mySystem = {
boot = {
kernel = {
hardened = true;
cpuVendor = "amd";
};
zfs = {
enable = true;
pools = ["tank"];
};
};
dev.docker.enable = true;
misc.keymap = "fr-bepo";
networking = {
hostname = "tilo";
id = "7110b33f";
firewall = {
openPorts = [
80 # HTTP
443 # HTTPS
25565 # Minecraft
];
};
};
packages.nix.gc.automatic = true;
services = {
calibre.enable = true;
endlessh.enable = true;
jellyfin.enable = true;
plex = {
enable = true;
dataDir = "/tank/web/stacks/plex/plex-config";
};
ssh = {
enable = true;
allowedUsers = ["phundrak"];
passwordAuthentication = false;
};
};
users = {
root.disablePassword = true;
phundrak = {
enable = true;
trusted = true;
};
};
};
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions
# on your system were taken. It‘s perfectly fine and recommended to leave
# this value at the release version of the first install of this system.
# Before changing this value read the documentation for this option
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
system.stateVersion = "24.11"; # Did you read the comment?
}
-3
View File
@@ -1,3 +0,0 @@
{
imports = [./nextcloud-cron.nix];
}
-33
View File
@@ -1,33 +0,0 @@
{pkgs, ...}: {
systemd = {
timers."nextcloud-cron" = {
wantedBy = ["timers.target"];
timerConfig = {
OnBootSec = "20m";
OnUnitActiveSec = "20m";
Unit = "nextcloud-cron.service";
};
};
services."nextcloud-cron" = {
script = ''
CONTAINER_NAME="nextcloud-nextcloud-1"
is_container_running() {
${pkgs.docker}/bin/docker inspect -f '{{.State.Running}}' "$CONTAINER_NAME" 2>/dev/null | grep -q "true"
}
while ! is_container_running; do
echo "Waiting for $CONTAINER_NAME to start..."
sleep 10
done
echo "$CONTAINER_NAME is running. Executing CRON job..."
${pkgs.docker}/bin/docker exec -u www-data -it nextcloud-nextcloud-1 php /var/www/html/cron.php
'';
serviceConfig = {
Type = "oneshot";
User = "root";
};
};
};
}
+26
View File
@@ -0,0 +1,26 @@
{
flake.modules.nixos.hardened = {
boot = {
kernelModules = ["tcp_bbr"];
kernel.sysctl = {
"kernel.sysrq" = 0;
"net.ipv4.icmp_echo_ignore_broadcasts" = 1;
"net.ipv4.icmp_ignore_bogus_error_responses" = 1;
"net.ipv4.conf.all.accept_redirects" = 0;
"net.ipv4.conf.default_accept_redirects" = 0;
"net.ipv4.conf.all.secure_redirects" = 0;
"net.ipv4.conf.default.secure_redirects" = 0;
"net.ipv6.conf.all.accept_redirects" = 0;
"net.ipv6.conf.default.accept_redirects" = 0;
"net.ipv4.conf.all.send_redirects" = 0;
"net.ipv4.conf.all.accept_source_route" = 0;
"net.ipv6.conf.all.accept_source_route" = 0;
"net.ipv4.tcp_syncookies" = 1;
"net.ipv4.tcp_rfc1337" = 1;
"net.ipv4.tcp_congestion_control" = "bbr";
"net.core.default_qdisc" = "cake";
"net.ipv4.tcp_fastopen" = 3;
};
};
};
}
+116
View File
@@ -0,0 +1,116 @@
#+title: Kernel Hardening
#+setupfile: ../headers
* Kernel Hardening
Some of my machines are exposed to the Internet, and therefore get
their kernel hardened. First, let me declare the Nix file’s skeleton,
with the =nixos.hardened= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.hardened = {
boot = {
<<kernel-modules>>
<<kernel-options>>
};
};
}
#+end_src
** Kernel Modules
The very first thing to do is to load the =tcp_bbr= kernel module. It
increases the connection speed of the system with a better congestion
control. It is particularly interesting for my servers, as they may
have to deal with high traffic if a crawler ever decides to explore
all webpages offered by some websites I host. See [[https://www.cyberciti.biz/cloud-computing/increase-your-linux-server-internet-speed-with-tcp-bbr-congestion-control/][this article]] by
Nixcraft for more details.
#+name: kernel-modules
#+begin_src nix
kernelModules = ["tcp_bbr"];
#+end_src
** Kernel Options
Next are a series of kernel options.
#+name: kernel-options
#+begin_src nix
kernel.sysctl = {
<<sysrq-key>>
<<icmp>>
<<icmp-no-accept-redirects>>
<<icmp-no-send-redirects>>
<<ip-source-route-packets>>
<<syn>>
<<tcp-time-wait>>
<<bufferfloat>>
<<latency>>
};
#+end_src
First, we’ll disable the magic SysRq key. Not that I expect anyone to
have physical access to my servers, but it is a really powerful tool
that I’d rather have off.
#+name: sysrq-key
#+begin_src nix
"kernel.sysrq" = 0;
#+end_src
Next, we’ll ignore ICMP broadcasts to avoid participating in Smurf
attacks, and we’ll also ignore ICMP errors.
#+name: icmp
#+begin_src nix
"net.ipv4.icmp_echo_ignore_broadcasts" = 1;
"net.ipv4.icmp_ignore_bogus_error_responses" = 1;
#+end_src
Speaking of ICMP, we won’t accept ICMP redirects to prevent some MITM
attacks.
#+name: icmp-no-accept-redirects
#+begin_src nix
"net.ipv4.conf.all.accept_redirects" = 0;
"net.ipv4.conf.default_accept_redirects" = 0;
"net.ipv4.conf.all.secure_redirects" = 0;
"net.ipv4.conf.default.secure_redirects" = 0;
"net.ipv6.conf.all.accept_redirects" = 0;
"net.ipv6.conf.default.accept_redirects" = 0;
#+end_src
And we won’t send ICMP redirects (we’re not a router).
#+name: icmp-no-send-redirects
#+begin_src nix
"net.ipv4.conf.all.send_redirects" = 0;
#+end_src
We’re stil not a router, so we’ll refuse IP source route packets, both
on IPV4 and IPV6.
#+name: ip-source-route-packets
#+begin_src nix
"net.ipv4.conf.all.accept_source_route" = 0;
"net.ipv6.conf.all.accept_source_route" = 0;
#+end_src
Now, let’s get some SYN flood protection.
#+name: syn
#+begin_src nix
"net.ipv4.tcp_syncookies" = 1;
#+end_src
And protection against TCP time-wait assassination hazards.
#+name: tcp-time-wait
#+begin_src nix
"net.ipv4.tcp_rfc1337" = 1;
#+end_src
We will also mitigate bufferfloat, including with BBR (hey, we enabled that above!)
#+name: bufferfloat
#+begin_src nix
"net.ipv4.tcp_congestion_control" = "bbr";
"net.core.default_qdisc" = "cake";
#+end_src
And lastly, we’ll reduce latency on IPV4.
#+name: latency
#+begin_src nix
"net.ipv4.tcp_fastopen" = 3;
#+end_src
And we should be good to go!
+44
View File
@@ -0,0 +1,44 @@
{
flake.modules.nixos.kernel = {
pkgs,
config,
lib,
...
}:
with lib; let
cfg = config.mySystem.boot.kernel;
in {
options.mySystem.boot.kernel = {
package = mkOption {
type = types.raw;
default = pkgs.linuxPackages_zen;
};
modules = mkOption {
type = types.listOf types.str;
default = [];
};
cpuVendor = mkOption {
description = "Intel or AMD?";
type = types.enum ["intel" "amd"];
default = "amd";
};
v4l2loopback.enable = mkEnableOption "Enables v4l2loopback kernel module";
extraModprobeConfig = mkOption {
type = types.lines;
default = "";
example = ''
options snd_usb_audio vid=0x1235 pid=0x8212 device_setup=1
'';
};
};
config.boot = {
initrd.kernelModules = ["i915"];
extraModprobeConfig =
strings.concatLines
([cfg.extraModprobeConfig]
++ lists.optional cfg.v4l2loopback.enable ''options v4l2loopback exclusive_caps=1 devices=1 video_nr=0 card_label="OBS Studio"'');
kernelPackages = cfg.package;
kernelModules = cfg.modules ++ ["kvm-${cfg.cpuVendor}"];
};
};
}
+136
View File
@@ -0,0 +1,136 @@
#+title: Kernel Configuration
#+setupfile: ../headers
* Kernel Configuration
This module centralises everything related to the kernel: which
package to boot, which extra modules to load, which KVM module the
CPU needs, and a couple of modprobe quirks for specific devices.
Here’s the skeleton of the =nixos.kernel= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.kernel = {
pkgs,
config,
lib,
...
}:
with lib; let
cfg = config.mySystem.boot.kernel;
in {
<<options>>
<<config>>
};
}
#+end_src
** Declaring the Options
#+name: options
#+begin_src nix
options.mySystem.boot.kernel = {
<<opt-package>>
<<opt-modules>>
<<opt-cpu-vendor>>
<<opt-v4l2loopback>>
<<opt-extra-modprobe>>
};
#+end_src
*** Kernel Package
=package= picks which kernel to boot. I default to the Zen kernel for
its desktop-tuned scheduler, but a host can override it with a
hardened or hardware-specific kernel instead.
#+name: opt-package
#+begin_src nix
package = mkOption {
type = types.raw;
default = pkgs.linuxPackages_zen;
};
#+end_src
*** Extra Kernel Modules
=modules= lists any extra kernel modules a host needs beyond the ones
this module already adds on its own.
#+name: opt-modules
#+begin_src nix
modules = mkOption {
type = types.listOf types.str;
default = [];
};
#+end_src
*** CPU Vendor
=cpuVendor= tells the module which KVM module to load, since Intel and
AMD CPUs each need their own.
#+name: opt-cpu-vendor
#+begin_src nix
cpuVendor = mkOption {
description = "Intel or AMD?";
type = types.enum ["intel" "amd"];
default = "amd";
};
#+end_src
*** Virtual Webcam
=v4l2loopback.enable= turns on a virtual video device. I feed it a
video source, and OBS Studio picks it up as if it were a webcam.
#+name: opt-v4l2loopback
#+begin_src nix
v4l2loopback.enable = mkEnableOption "Enables v4l2loopback kernel module";
#+end_src
*** Extra Modprobe Configuration
=extraModprobeConfig= lets a host inject raw =modprobe.d= lines. The
example below fixes a USB sound card that otherwise misconfigures
itself on boot.
#+name: opt-extra-modprobe
#+begin_src nix
extraModprobeConfig = mkOption {
type = types.lines;
default = "";
example = ''
options snd_usb_audio vid=0x1235 pid=0x8212 device_setup=1
'';
};
#+end_src
** Wiring It All Up
#+name: config
#+begin_src nix
config.boot = {
<<initrd-driver>>
<<extra-modprobe-lines>>
<<kernel-packages-and-modules>>
};
#+end_src
*** Choosing the Initrd Driver
Most of my machines have Intel graphics, so this module loads =i915=
early, in the initrd, to keep the Plymouth splash screen from flashing
or glitching before the proper driver takes over. Machines with an AMD
GPU instead load =amdgpu= early; the [[file:../hardware/amdgpu.org][AMD GPU module]] handles that
itself, so this module doesn’t need to know or care which GPU a host
actually has.
#+name: initrd-driver
#+begin_src nix
initrd.kernelModules = ["i915"];
#+end_src
*** Assembling Modprobe Configuration
This concatenates whatever a host set through =cfg.extraModprobeConfig=
with the v4l2loopback quirk line whenever =v4l2loopback.enable= is on.
#+name: extra-modprobe-lines
#+begin_src nix
extraModprobeConfig =
strings.concatLines
([cfg.extraModprobeConfig]
++ lists.optional cfg.v4l2loopback.enable ''options v4l2loopback exclusive_caps=1 devices=1 video_nr=0 card_label="OBS Studio"'');
#+end_src
*** Kernel Package and Extra Modules
Finally, =kernelPackages= and =kernelModules= wire the chosen package
and modules through, appending the vendor-specific KVM module.
#+name: kernel-packages-and-modules
#+begin_src nix
kernelPackages = cfg.package;
kernelModules = cfg.modules ++ ["kvm-${cfg.cpuVendor}"];
#+end_src
+31
View File
@@ -0,0 +1,31 @@
{
flake.modules.nixos.loader = {
lib,
config,
...
}:
with lib; let
cfg = config.mySystem.boot;
in {
options.mySystem.boot.systemd-boot = mkOption {
type = types.bool;
default = !cfg.grub.enable;
description = "Does the system use systemd-boot?";
};
options.mySystem.boot.grub = {
enable = mkEnableOption "Does the system use GRUB? (Disables systemd-boot)";
device = mkOption {
type = types.path;
description = "The GRUB device";
};
};
config.boot.loader = {
systemd-boot.enable = cfg.systemd-boot;
efi.canTouchEfiVariables = cfg.systemd-boot;
};
config.boot.loader.grub = mkIf cfg.grub.enable {
inherit (cfg.grub) enable device;
};
};
}
+73
View File
@@ -0,0 +1,73 @@
#+title: Bootloaders and Filesystems
#+setupfile: ../headers
* Bootloaders and Filesystems
This page sets up the bootloader of my machines. Whilst I generally
prefer to use [[https://systemd.io/BOOT/][systemd-boot]], some of my VPS use GRUB. All that gets
exposed with my module =nixos.loader=.
#+begin_src nix :tangle yes
{
flake.modules.nixos.loader = {
lib,
config,
...
}:
with lib; let
cfg = config.mySystem.boot;
in {
<<systemd-boot-options>>
<<grub-options>>
<<systemd-boot-config>>
<<grub-config>>
};
}
#+end_src
By default, I want to use systemd-boot on my machines, but I need it
to be disabled whenever I use something else. For now, this “something
else” is only GRUB, but I’m not excluding using something else on yet
another machine such as [[https://www.rodsbooks.com/refind/][rEFInd]]. To ensure a single source of truth
regarding whether systemd-boot is to be used, I have an option for
that.
#+name: systemd-boot-options
#+begin_src nix
options.mySystem.boot.systemd-boot = mkOption {
type = types.bool;
default = !cfg.grub.enable;
description = "Does the system use systemd-boot?";
};
#+end_src
I can now set some options depending on that, such as whether to
enable systemd-boot itself (duh), and whether the installation process
can touch my EFI variables.
#+name: systemd-boot-config
#+begin_src nix
config.boot.loader = {
systemd-boot.enable = cfg.systemd-boot;
efi.canTouchEfiVariables = cfg.systemd-boot;
};
#+end_src
But, I have a VPS that requires me to use GRUB. For this, I also have
an option to enable it.
#+name: grub-options
#+begin_src nix
options.mySystem.boot.grub = {
enable = mkEnableOption "Does the system use GRUB? (Disables systemd-boot)";
device = mkOption {
type = types.path;
description = "The GRUB device";
};
};
#+end_src
I can no pass these options to the boot configuration of my machine.
#+name: grub-config
#+begin_src nix
config.boot.loader.grub = mkIf cfg.grub.enable {
inherit (cfg.grub) enable device;
};
#+end_src
+25
View File
@@ -0,0 +1,25 @@
{
flake.modules.nixos.plymouth = {pkgs, ...}: {
boot = {
plymouth = {
enable = true;
theme = "circle_hud";
themePackages = with pkgs; [
(adi1090x-plymouth-themes.override {
selected_themes = ["circle_hud"];
})
];
};
kernelParams = [
"quiet"
"splash"
"boot.shell_on_fail"
"udev.log_level=3"
"rd.systemd.show_status=auto"
];
consoleLogLevel = 3;
initrd.verbose = false;
loader.timeout = 0;
};
};
}
+99
View File
@@ -0,0 +1,99 @@
#+title: Plymouth
#+setupfile: ../headers
* Plymouth
Plymouth is a utility which shows an animation at startup or when
powering off a device, instead of showing only terminal things. My
Plymouth settings are set in the =nixos.plymouth= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.plymouth = {pkgs, ...}: {
boot = {
<<plymouth>>
<<kernel-parameters>>
<<quiet-console>>
<<no-menu>>
};
};
}
#+end_src
** Quieting Down the Console
First, I need to set a few kernel parameters to make displaying
Plymouth possible:
#+name: kernel-parameters-list
- =quiet= :: silences the logs in the terminal
- =splash= :: show the splash screen (in our case, Plymouth)
- =boot.shell_on_fail= :: sets =allowShell=1=, which permits the =fail()=
handler to drop an interactive rescue shell if stage-1 boot fails
- =udev.log_level=3= :: sets udev’s log level to =err=
- =rd.systemd.show_status=auto= :: suppress systemd status messages in
initrd unless boot is significantly delayed
#+name: kernel-params
#+begin_src emacs-lisp :var params=kernel-parameters-list :cache yes
(mapconcat (lambda (param)
(format "\"%s\""
(s-chop-suffix "=" (s-chop-prefix "=" (car (s-split " ::" param))))))
params
"\n")
#+end_src
#+RESULTS[7a824c095f2934792b4a3749e56091a8603aaacf]: kernel-params
: "quiet"
: "splash"
: "boot.shell_on_fail"
: "udev.log_level=3"
: "rd.systemd.show_status=auto"
This translates into:
#+name: kernel-parameters
#+begin_src nix :noweb yes
kernelParams = [
<<kernel-params()>>
];
#+end_src
To further decrease the verbosity of the booting screen, we can
deactivate initrd’s verbosity and lower the console’s log level to
=err=.
#+name: quiet-console
#+begin_src nix
consoleLogLevel = 3;
initrd.verbose = false;
#+end_src
And we’ll show Plymouth immediately, skipping the bootloader’s menu.
We can hold a key to force displaying the menu, though.
#+name: no-menu
#+begin_src nix
loader.timeout = 0;
#+end_src
** Configuring Plymouth
Now, we can configure Plymouth proper.
#+name: plymouth
#+begin_src nix
plymouth = {
enable = true;
<<plymouth-theme>>
};
#+end_src
The only significant configuration I want to change in Plymouth is the
animation. I really like how it looks. You can find a preview of it in
[[https://github.com/adi1090x/plymouth-themes#previews][adi1090x's repository]], under the first pack. For this, I need to set
a theme package and the theme name.
#+name: plymouth-theme
#+begin_src nix
theme = "circle_hud";
themePackages = with pkgs; [
(adi1090x-plymouth-themes.override {
selected_themes = ["circle_hud"];
})
];
#+end_src
And we’re done!
+21
View File
@@ -0,0 +1,21 @@
{
flake.modules.nixos.zfs = {
lib,
config,
...
}:
with lib; let
cfg = config.mySystem.boot;
in {
options.mySystem.boot.zfs = {
pools = mkOption {
type = types.listOf types.str;
default = [];
};
forceImportRoot = mkEnableOption "Force-import the ZFS root pool at boot, even if it looks already imported elsewhere";
};
config.boot.supportedFilesystems = ["zfs"];
config.boot.zfs.extraPools = cfg.zfs.pools;
config.boot.zfs.forceImportRoot = cfg.zfs.forceImportRoot;
};
}
+62
View File
@@ -0,0 +1,62 @@
#+title: ZFS Support
#+setupfile: ../headers
* ZFS Support
Enabling ZFS is quite straightforward on my machines. In my module
=nixos.zfs=, I expose two options: which ZFS pools to import, and
whether to force-import the root pool. But first, here’s the skeleton
of my module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.zfs = {
lib,
config,
...
}:
with lib; let
cfg = config.mySystem.boot;
in {
<<options>>
<<enable>>
<<pools>>
<<force-import-root>>
};
}
#+end_src
The main option is the list of pools, which I pass directly to the
standard NixOS configuration.
#+name: options
#+begin_src nix
options.mySystem.boot.zfs = {
pools = mkOption {
type = types.listOf types.str;
default = [];
};
forceImportRoot = mkEnableOption "Force-import the ZFS root pool at boot, even if it looks already imported elsewhere";
};
#+end_src
Now, I can enable ZFS on the system importing the current module.
#+name: enable
#+begin_src nix
config.boot.supportedFilesystems = ["zfs"];
#+end_src
And lastly, passing the list of pools to the standard NixOS option is
quite simple.
#+name: pools
#+begin_src nix
config.boot.zfs.extraPools = cfg.zfs.pools;
#+end_src
Force-importing the root pool can paper over a stale or mismatched
host ID, but it also risks mounting a pool that’s already imported
elsewhere and corrupting it, so NixOS is moving to disable it by
default. I’d rather keep that safety and only turn it back on for the
rare host (or the rare boot) that actually needs it.
#+name: force-import-root
#+begin_src nix
config.boot.zfs.forceImportRoot = cfg.zfs.forceImportRoot;
#+end_src
+104
View File
@@ -0,0 +1,104 @@
{
inputs,
lib,
config,
...
}: {
imports = [
inputs.flake-parts.flakeModules.modules
inputs.flake-file.flakeModules.default
];
options.flake.homeConfigurations = lib.mkOption {
type = lib.types.lazyAttrsOf lib.types.raw;
default = {};
};
config = {
flake-file.inputs = {
flake-utils.url = "github:numtide/flake-utils";
nixpkgsPinetab2Kernel.url = "github:nixos/nixpkgs/e73de5be04e0eff4190a1432b946d469c794e7b4";
rockchip = {
url = "github:raboof/nixos-rockchip/pinetab-linux-7.0";
inputs.utils.follows = "flake-utils";
inputs.nixpkgsStable.follows = "nixpkgsStable";
inputs.nixpkgsUnstable.follows = "nixpkgsPinetab2Kernel";
};
};
systems = ["x86_64-linux" "aarch64-linux"];
flake.lib = {
mkNixos = system: name: {
${name} = inputs.nixpkgs.lib.nixosSystem {
modules = [
config.flake.modules.nixos.${name}
{nixpkgs.hostPlatform = lib.mkDefault system;}
];
};
};
mkHome = system: userName: hostName: {
"${userName}@${hostName}" = inputs.home-manager.lib.homeManagerConfiguration {
pkgs = inputs.nixpkgs.legacyPackages.${system};
extraSpecialArgs = {
inherit inputs;
bunBaseline = config.flake.packages.${system}.bun-baseline;
};
modules = [config.flake.modules.homeManager."${userName}-${hostName}"];
};
};
mkPinetab = buildPlatform: variantModule: {
pinetab2 = inputs.nixpkgs.lib.nixosSystem {
system = "aarch64-linux";
modules = [
inputs.rockchip.nixosModules.sdImageRockchip
inputs.rockchip.nixosModules.dtOverlayPCIeFix
inputs.rockchip.nixosModules.noZFS
config.flake.modules.nixos.pinetab2-base
variantModule
{
rockchip.uBoot = inputs.rockchip.packages.${buildPlatform}.uBootPineTab2;
boot.kernelPackages =
inputs.rockchip.legacyPackages.${buildPlatform}.kernel_linux_7_0_pinetab_unstable;
hardware.firmware = [inputs.rockchip.packages.aarch64-linux.bes2600];
nixpkgs.config.allowUnfreePredicate = pkg:
builtins.elem (inputs.nixpkgs.lib.getName pkg) ["bes2600-firmware"];
}
];
};
};
};
flake.nixosConfigurations = lib.mkMerge [
(config.flake.lib.mkNixos "x86_64-linux" "marpa")
(config.flake.lib.mkNixos "x86_64-linux" "gampo")
(config.flake.lib.mkNixos "x86_64-linux" "tilo")
(config.flake.lib.mkNixos "x86_64-linux" "elcafe")
(config.flake.lib.mkNixos "x86_64-linux" "NaroMk3")
(config.flake.lib.mkPinetab "x86_64-linux" config.flake.modules.nixos.pinetab2-gnome)
];
flake.homeConfigurations = lib.mkMerge [
(config.flake.lib.mkHome "x86_64-linux" "phundrak" "marpa")
(config.flake.lib.mkHome "x86_64-linux" "phundrak" "gampo")
(config.flake.lib.mkHome "x86_64-linux" "phundrak" "tilo")
(config.flake.lib.mkHome "x86_64-linux" "phundrak" "elcafe")
(config.flake.lib.mkHome "x86_64-linux" "creug" "elcafe")
(config.flake.lib.mkHome "x86_64-linux" "phundrak" "NaroMk3")
(config.flake.lib.mkHome "aarch64-linux" "phundrak" "pinetab2")
];
perSystem = {
pkgs,
system,
...
}: {
formatter = pkgs.alejandra;
devShells.default = pkgs.mkShell {
buildInputs = [
pkgs.nh
pkgs.jujutsu
pkgs.git
inputs.jj-cz.packages.${system}.default
];
};
};
};
}
+185
View File
@@ -0,0 +1,185 @@
{
flake.modules.homeManager.hyprland = {
config,
lib,
pkgs,
...
}:
with lib; let
cfg = config.home.desktop.hyprland;
laptops = ["gampo"];
caelestiaEnabled = config.home.desktop.caelestia.enable;
in {
options.home.desktop.hyprland = {
enable = mkEnableOption "Enables Hyprland";
emacsPkg = mkOption {
type = types.package;
default = config.home.dev.editors.emacs.package or pkgs.emacs;
example = pkgs.emacs;
};
host = mkOption {
type = types.enum ["gampo" "marpa"];
description = ''
Which host is Hyprland running on.
This helps determine the monitors layout and enable battery support in waybar.
'';
};
};
config = mkIf cfg.enable {
home.desktop = {
hyprpaper.enable = mkDefault (! caelestiaEnabled);
rofi.enable = mkDefault true;
swaync.enable = mkDefault (! caelestiaEnabled);
waybar = {
enable = mkDefault (! caelestiaEnabled);
battery = mkDefault (builtins.elem cfg.host laptops);
};
wlsunset.enable = mkDefault true;
};
services.blueman-applet.enable = ! caelestiaEnabled;
wayland.windowManager.hyprland = {
enable = true;
systemd.enable = false;
importantPrefixes = ["$left" "$right" "$up" "$down" "$menu"];
settings = {
env = [
"XMODIFIERS,@im=fcitx"
"XCURSOR_SIZE,12"
];
input = {
kb_layout = "fr,us";
kb_variant = "bepo_afnor,";
numlock_by_default = true;
follow_mouse = 1;
touchpad.natural_scroll = false;
sensitivity = "0";
};
device = {
name = "wacom-usb-bamboo-pad-finger";
sensitivity = 0.5;
};
monitor =
{
"marpa" = [
"DP-1, 3440x1440@144, 1080x550, 1"
# "DP-1, 2560x1440@144, 1080x550, 1" # streaming
"DP-2, 2560x1080@60, 0x0, 1, transform, 1"
];
"gampo" = [];
}."${cfg.host}";
general = {
gaps_in = 5;
gaps_out = 20;
border_size = 2;
"col.active_border" = "rgb(81a1c1) rgb(a3be8c) 45deg";
"col.inactive_border" = "rgb(4c566a)";
layout = "master";
};
master = {
orientation = "center";
new_status = "inherit";
};
workspace = [
"1, layoutopt:orientation:bottom"
"9, layoutopt:orientation:bottom"
"10, layoutopt:orientation:bottom"
];
decoration = {
rounding = 20;
};
animations = {
enabled = true;
animation = [
# "windows, 1, 7, myBezier"
"windowsOut, 1, 7, default, popin 80%"
"border, 1, 10, default"
"borderangle, 1, 8, default"
"fade, 1, 7, default"
"workspaces, 1, 6, default"
];
};
dwindle.preserve_split = true;
exec-once =
[
"pactl load-module module-switch-on-connect"
"${pkgs.mpc}/bin/mpc stop"
"${pkgs.polkit_gnome}/libexec/polkit-gnome-authentication-agent-1"
"${pkgs.mozc}/lib/mozc/mozc_server"
"${pkgs.fcitx5}/bin/fcitx5 -d"
]
++ lib.lists.optional (! caelestiaEnabled) "${pkgs.networkmanagerapplet}/bin/nm-applet";
};
extraConfig = ''
device {
name = wacom-usb-bamboo-pad-finger
sensitivity = 0.5
accel_profile = adaptive
}
$left = c
$right = r
$up = s
$down = t
$menu = rofi -combi-modi drun,calc -show combi
bind = SUPER, Return, exec, ${pkgs.kitty}/bin/kitty ${pkgs.tmux}/bin/tmux
bind = SUPER, Space, exec, ${pkgs.wlr-which-key}/bin/wlr-which-key
bind = , Print, exec, ${pkgs.wlr-which-key}/bin/wlr-which-key -k s
bindl = , XF86AudioPlay, exec, playerctl play-pause
bindl = , XF86AudioPause, exec, playerctl pause
bindl = , XF86AudioStop, exec, playerctl stop
bindl = , XF86AudioPrev, exec, playerctl previous
bindl = , XF86AudioNext, exec, playerctl next
bindl = , XF86AudioForward, exec, playerctl position +1
bindl = , XF86AudioRewind, exec, playerctl position -1
bindl = , XF86AudioRaiseVolume, exec, pamixer -i 2
bindl = , XF86AudioLowerVolume, exec, pamixer -d 2
bindl = , XF86MonBrightnessUp, exec, xbacklight -perceived -inc 2
bindl = , XF86MonBrightnessDown, exec, xbacklight -perceived -dec 2
bindl = , XF86KbdBrightnessUp, exec, xbacklight -perceived -inc 2
bindl = , XF86KbdBrightnessDown, exec, xbacklight -perceived -dec 2
bind = SUPER, a, exec, hyprctl switchxkblayout glove80-keyboard next
bind = SUPER, $left, movefocus, l
bind = SUPER, $right, movefocus, r
bind = SUPER, $up, movefocus, u
bind = SUPER, $down, movefocus, d
bind = SUPER_SHIFT, $left, movewindow, l
bind = SUPER_SHIFT, $right, movewindow, r
bind = SUPER_SHIFT, $up, movewindow, u
bind = SUPER_SHIFT, $down, movewindow, d
bind = SUPER_CTRL_SHIFT, $left, moveworkspacetomonitor, e+0 +1
bind = SUPER_CTRL_SHIFT, $right, moveworkspacetomonitor, e+0 -1
bind = SUPER, Tab, cyclenext,
bind = SUPER_SHIFT, Tab, cyclenext, prev
bindm = SUPER, mouse:272, movewindow
bindm = SUPER, mouse:273, resizewindow
bind = SUPER, quotedbl, workspace, 1
bind = SUPER, guillemotleft, workspace, 2
bind = SUPER, guillemotright, workspace, 3
bind = SUPER, parenleft, workspace, 4
bind = SUPER, parenright, workspace, 5
bind = SUPER, at, workspace, 6
bind = SUPER, plus, workspace, 7
bind = SUPER, minus, workspace, 8
bind = SUPER, slash, workspace, 9
bind = SUPER, asterisk, workspace, 10
bind = SUPER, mouse_down, workspace, e+1
bind = SUPER, mouse_up, workspace, e-1
bind = SUPER_SHIFT, quotedbl, movetoworkspace, 1
bind = SUPER_SHIFT, guillemotleft, movetoworkspace, 2
bind = SUPER_SHIFT, guillemotright, movetoworkspace, 3
bind = SUPER_SHIFT, parenleft, movetoworkspace, 4
bind = SUPER_SHIFT, parenright, movetoworkspace, 5
bind = SUPER_SHIFT, at, movetoworkspace, 6
bind = SUPER_SHIFT, plus, movetoworkspace, 7
bind = SUPER_SHIFT, minus, movetoworkspace, 8
bind = SUPER_SHIFT, slash, movetoworkspace, 9
bind = SUPER_SHIFT, asterisk, movetoworkspace, 10
'';
};
};
};
}
+16
View File
@@ -0,0 +1,16 @@
{
flake.modules.nixos.hyprland = {
config,
lib,
...
}:
with lib; let
cfg = config.mySystem.desktop.hyprland;
in {
options.mySystem.desktop.hyprland.enable = mkEnableOption "Enables Hyprland";
config.programs.hyprland = mkIf cfg.enable {
inherit (cfg) enable;
withUWSM = true;
};
};
}
+15
View File
@@ -0,0 +1,15 @@
{
flake.modules.nixos.niri = {
config,
lib,
...
}:
with lib; let
cfg = config.mySystem.desktop.niri;
in {
options.mySystem.desktop.niri.enable = mkEnableOption "Enables Niri";
config.programs.niri = mkIf cfg.enable {
inherit (cfg) enable;
};
};
}
+20
View File
@@ -0,0 +1,20 @@
{
flake.modules.nixos.waydroid = {
config,
lib,
pkgs,
...
}:
with lib; let
cfg = config.mySystem.desktop.waydroid;
in {
options.mySystem.desktop.waydroid.enable = mkEnableOption "Enables Waydroid";
config = mkIf cfg.enable {
virtualisation.waydroid = {
enable = cfg.enable;
package = pkgs.waydroid-nftables;
};
environment.systemPackages = [pkgs.waydroid-helper];
};
};
}
+53
View File
@@ -0,0 +1,53 @@
{
flake.modules.nixos.xserver = {
config,
lib,
...
}:
with lib; let
cfg = config.mySystem.desktop.xserver;
in {
options.mySystem.desktop.xserver = {
enable = mkEnableOption "Enables xserver";
de = mkOption {
type = types.enum ["gnome" "kde"];
default = "gnome";
example = "kde";
description = "Which DE to enable";
};
videoDrivers = mkOption {
type = types.listOf types.str;
default = [];
example = ["amdgpu"];
description = "Extra X11 video drivers to load";
};
};
config.services = mkIf cfg.enable {
displayManager = {
sddm.enable = mkIf (cfg.de == "kde") true;
gdm.enable = mkIf (cfg.de == "gnome") true;
};
desktopManager = {
plasma6.enable = mkIf (cfg.de == "kde") true;
gnome.enable = mkIf (cfg.de == "gnome") true;
};
gnome = mkIf (cfg.de == "gnome") {
gnome-browser-connector.enable = true;
games.enable = false;
gnome-remote-desktop.enable = true;
gnome-online-accounts.enable = true;
sushi.enable = true;
};
xserver = {
inherit (cfg) enable;
videoDrivers = cfg.videoDrivers;
xkb = {
layout = "fr";
variant = "bepo_afnor";
};
};
};
};
}
+32
View File
@@ -0,0 +1,32 @@
{
flake.modules.nixos.qemu = {
config,
lib,
pkgs,
...
}:
with lib; let
cfg = config.mySystem.dev.qemu;
in {
options.mySystem.dev.qemu.users = mkOption {
type = types.listOf types.str;
default = ["phundrak"];
example = ["user1" "user2"];
};
config = {
programs.virt-manager.enable = true;
users.groups.libvirtd.members = cfg.users;
virtualisation = {
libvirtd.enable = true;
spiceUSBRedirection.enable = true;
};
environment.systemPackages = with pkgs; [
qemu
quickemu
swtpm
];
systemd.tmpfiles.rules = ["L+ /var/lib/qemu/firmware - - - - ${pkgs.qemu}/share/qemu/firmware"];
boot.binfmt.emulatedSystems = ["aarch64-linux"];
};
};
}
+99
View File
@@ -0,0 +1,99 @@
#+title: QEMU
#+setupfile: ../headers
* QEMU
On machines where I run virtual machines, I want =virt-manager=,
=libvirtd=, and a few supporting pieces set up together. Here’s the
skeleton of the =nixos.qemu= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.qemu = {
config,
lib,
pkgs,
...
}:
with lib; let
cfg = config.mySystem.dev.qemu;
in {
<<options>>
config = {
<<virt-manager>>
<<libvirtd-group>>
<<virtualisation>>
<<packages>>
<<firmware-tmpfiles>>
<<binfmt>>
};
};
}
#+end_src
** Declaring the Options
=users= lists which users get added to the =libvirtd= group, so they can
manage VMs without needing root. By default, I add myself to this
group.
#+name: options
#+begin_src nix
options.mySystem.dev.qemu.users = mkOption {
type = types.listOf types.str;
default = ["phundrak"];
example = ["user1" "user2"];
};
#+end_src
This option is then passed onto the standard NixOS option.
#+name: libvirtd-group
#+begin_src nix
users.groups.libvirtd.members = cfg.users;
#+end_src
** virt-manager
This pulls in the GUI I actually use to create and manage VMs.
#+name: virt-manager
#+begin_src nix
programs.virt-manager.enable = true;
#+end_src
** Virtualisation Backend
=libvirtd= is the daemon that actually runs and manages the VMs. SPICE
USB redirection lets me pass a USB device straight through to a guest
without unplugging it from the host first.
#+name: virtualisation
#+begin_src nix
virtualisation = {
libvirtd.enable = true;
spiceUSBRedirection.enable = true;
};
#+end_src
** Extra Packages
Besides =qemu= itself, =quickemu= lets me spin up a VM from a template in
one command, and =swtpm= provides the software TPM that guests like
Windows 11 insist on.
#+name: packages
#+begin_src nix
environment.systemPackages = with pkgs; [
qemu
quickemu
swtpm
];
#+end_src
** Firmware Lookup Path
=virt-manager= and friends expect to find UEFI firmware images under
=/var/lib/qemu/firmware=, so I symlink QEMU’s own copy there instead of
making every tool aware of the Nix store path.
#+name: firmware-tmpfiles
#+begin_src nix
systemd.tmpfiles.rules = ["L+ /var/lib/qemu/firmware - - - - ${pkgs.qemu}/share/qemu/firmware"];
#+end_src
** ARM Emulation
This lets me run (and build) =aarch64-linux= binaries transparently
through QEMU’s user-mode emulation, which comes in handy when working
on the PineTab2 without needing actual ARM hardware on hand.
#+name: binfmt
#+begin_src nix
boot.binfmt.emulatedSystems = ["aarch64-linux"];
#+end_src
+50
View File
@@ -0,0 +1,50 @@
{
flake.modules.nixos.amdgpu = {pkgs, ...}: {
hardware.graphics = {
enable = true;
enable32Bit = true;
};
hardware.amdgpu = {
initrd.enable = true;
opencl.enable = true;
};
hardware.graphics.extraPackages = with pkgs; [
mesa
rocmPackages.clr
rocmPackages.clr.icd
rocmPackages.rocblas
rocmPackages.hipblas
rocmPackages.rpp
nvtopPackages.amd
];
environment.systemPackages = with pkgs; [
clinfo
amdgpu_top
nvtopPackages.amd
];
systemd = {
packages = with pkgs; [lact];
services.lactd.wantedBy = ["multi-user.target"];
tmpfiles.rules = let
rocmEnv = pkgs.symlinkJoin {
name = "rocm-combined";
paths = with pkgs.rocmPackages; [
clr
clr.icd
rocblas
hipblas
rpp
];
};
in [
"L+ /opt/rocm - - - - ${rocmEnv}"
];
};
environment.variables = {
ROCM_PATH = "/opt/rocm";
HIP_VISIBLE_DEVICES = "1";
ROCM_VISIBLE_DEVICES = "1";
HSA_OVERRIDE_GFX_VERSION = "10.3.0";
};
};
}
+147
View File
@@ -0,0 +1,147 @@
#+title: AMD GPU support
#+setupfile: ../headers
#+property: header-args:emacs-lisp :lexical t :exports none :tangle no
* AMD GPU support
Only one of my machines has an AMD GPU, but it does require some
tweaking. First, here’s the skeleton of the =nixos.amdgpu= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.amdgpu = {pkgs, ...}: {
<<enable-graphics>>
<<enable-hardware>>
<<hardware-extra-packages>>
<<system-packages>>
<<lact>>
<<environment-variables>>
};
}
#+end_src
** Enable the Hardware
The first thing is to enable graphics in NixOS. We’ll enable 32-bit
support while we’re at it.
#+name: enable-graphics
#+begin_src nix
hardware.graphics = {
enable = true;
enable32Bit = true;
};
#+end_src
We can now enable the hardware proper, including initrd and OpenCL
support for the GPU. =initrd.enable= already makes NixOS load =amdgpu= as
early as stage 1 on its own, which is why the kernel module (see
[[file:../boot/kernel.org][Kernel Configuration]]) doesn’t need to pick between =amdgpu= and =i915=
itself: it can simply default to =i915= and let this module handle its
own early loading.
#+name: enable-hardware
#+begin_src nix
hardware.amdgpu = {
initrd.enable = true;
opencl.enable = true;
};
#+end_src
Some software expect some packages to be installed by default, such as
rocblas or Hipblas. Here are these packages.
#+name: amd-packages
| Package Name | Description |
|----------------------+--------------------------------------------------------------------|
| =mesa= | Mesa drivers for AMD GPUs |
| =rocmPackages.clr= | Common Language Runtime for ROCm |
| =rocmPackages.clr.icd= | ROCm ICD for OpenCL |
| =rocmPackages.rocblas= | ROCm BLAS library |
| =rocmPackages.hipblas= | HIP BLAS marshalling library (CUDA-compatible interface to rocBLAS) |
| =rocmPackages.rpp= | High-performance computer vision library |
| =nvtopPackages.amd= | Just for me, GPU utilisation monitoring |
#+name: extra-hardware-packages
#+begin_src emacs-lisp :var packages=amd-packages :cache yes
(mapconcat (lambda (package) (s-chop-prefix "=" (s-chop-suffix "=" package)))
(mapcar #'car packages)
"\n")
#+end_src
#+RESULTS[28ba71596b4f184338e46c76c0ba1aa41899bba0]: extra-hardware-packages
: mesa
: rocmPackages.clr
: rocmPackages.clr.icd
: rocmPackages.rocblas
: rocmPackages.hipblas
: rocmPackages.rpp
: nvtopPackages.amd
#+name: hardware-extra-packages
#+begin_src nix
hardware.graphics.extraPackages = with pkgs; [
<<extra-hardware-packages()>>
];
#+end_src
** Diagnostics and Monitoring
Beyond what’s needed by the driver stack itself, I also want a couple
of tools available on the command line to check on the GPU: =clinfo= to
inspect the available OpenCL platforms and devices, =amdgpu_top= for a
=btop=-like view of the AMD GPU’s activity, and =nvtop= (packaged for AMD
under =nvtopPackages.amd=) for a more familiar process-oriented monitor.
#+name: system-packages
#+begin_src nix
environment.systemPackages = with pkgs; [
clinfo
amdgpu_top
nvtopPackages.amd
];
#+end_src
** LACT, the GPU Control Daemon
[[https://github.com/ilya-zlobintsev/LACT][LACT]] (Linux AMDGPU Control Application) lets me tweak fan curves,
power limits and clocks on the card, through a daemon (=lactd=) and a
GUI that talks to it. The package ships both a systemd service
definition and a udev rule, so all that’s left for me to do is install
the package and make sure the daemon is started.
I’m also consolidating the ROCm libraries under =/opt/rocm= via a
=tmpfiles= rule. Some tools out there still expect to find ROCm
installed at that standard filesystem location rather than resolved
through the Nix store, so I build a combined derivation of the ROCm
packages I need and symlink it into place.
#+name: lact
#+begin_src nix
systemd = {
packages = with pkgs; [lact];
services.lactd.wantedBy = ["multi-user.target"];
tmpfiles.rules = let
rocmEnv = pkgs.symlinkJoin {
name = "rocm-combined";
paths = with pkgs.rocmPackages; [
clr
clr.icd
rocblas
hipblas
rpp
];
};
in [
"L+ /opt/rocm - - - - ${rocmEnv}"
];
};
#+end_src
** Environment Variables
Finally, a handful of environment variables to point tools at that
=/opt/rocm= prefix and to steer ROCm/HIP towards the right GPU. This
machine exposes the AMD card as device ID =1= (the other device being an
iGPU), so I pin both =HIP_VISIBLE_DEVICES= and =ROCM_VISIBLE_DEVICES= to
it. The card also isn’t officially supported by ROCm, hence the
=HSA_OVERRIDE_GFX_VERSION= override, which tells ROCm to treat it as the
closest supported architecture instead of refusing to run.
#+name: environment-variables
#+begin_src nix
environment.variables = {
ROCM_PATH = "/opt/rocm";
HIP_VISIBLE_DEVICES = "1";
ROCM_VISIBLE_DEVICES = "1";
HSA_OVERRIDE_GFX_VERSION = "10.3.0";
};
#+end_src
+6
View File
@@ -0,0 +1,6 @@
{
flake.modules.nixos.bluetooth = {
hardware.bluetooth.enable = true;
services.blueman.enable = true;
};
}
+24
View File
@@ -0,0 +1,24 @@
#+title: Bluetooth
#+setupfile: ../headers
* Bluetooth
Not all of my machines have Bluetooth hardware worth turning on, so
this is a plain toggle rather than something applied unconditionally.
Here’s the skeleton of the =nixos.bluetooth= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.bluetooth = {
<<config>>
};
}
#+end_src
** Enabling Bluetooth
Turning the option on enables Bluetooth support at the kernel level
and installs =blueman=, a tray applet I use to pair and manage devices
without digging through a terminal.
#+name: config
#+begin_src nix
hardware.bluetooth.enable = true;
services.blueman.enable = true;
#+end_src
+5
View File
@@ -0,0 +1,5 @@
{
flake.modules.nixos.fingerprint = {
hardware.facter.detected.fingerprint.enable = true;
};
}
+22
View File
@@ -0,0 +1,22 @@
#+title: Fingerprint Reader
#+setupfile: ../headers
* Fingerprint Reader
My ThinkPad x220 has a fingerprint reader, so this is a plain toggle
rather than something applied unconditionally. Here’s the skeleton of
the =nixos.fingerprint= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.fingerprint = {
<<config>>
};
}
#+end_src
** Enabling the Reader
Rather than picking a driver myself, I let [[https://github.com/numtide/nixos-facter-modules][nixos-facter]] detect the
reader and wire up the matching driver automatically.
#+name: config
#+begin_src nix
hardware.facter.detected.fingerprint.enable = true;
#+end_src
+5
View File
@@ -0,0 +1,5 @@
{
flake.modules.nixos.firmware = {lib, ...}: {
hardware.enableAllFirmware = lib.mkDefault true;
};
}
+21
View File
@@ -0,0 +1,21 @@
#+title: Firmware
#+setupfile: ../headers
* Firmware
A small module to pull in the full firmware blob set, for machines
where I’d rather not chase down which specific firmware package a
piece of hardware needs. Here’s the =nixos.firmware= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.firmware = {lib, ...}: {
<<enable-all-firmware>>
};
}
#+end_src
=mkDefault= keeps this overridable, in case a host needs to turn it back
off or pin a narrower set of firmware packages itself.
#+name: enable-all-firmware
#+begin_src nix
hardware.enableAllFirmware = lib.mkDefault true;
#+end_src
+9
View File
@@ -0,0 +1,9 @@
{
flake.modules.nixos.corne = {
services.udev = {
extraRules = ''
KERNEL=="hidraw*", SUBSYSTEM=="hidraw", ATTRS{serial}=="*vial:f64c2b3c*", MODE="0660", GROUP="users", TAG+="uaccess", TAG+="udev-acl"
'';
};
};
}
+32
View File
@@ -0,0 +1,32 @@
#+title: Corne Keyboard
#+setupfile: ../../headers
* Corne Keyboard
I use a Corne (=crkbd=), a small split ergonomic keyboard, flashed with
[[https://get.vial.today/][Vial]], a QMK-based firmware that lets me remap keys live from a GUI
instead of having to reflash the keyboard every time I want to tweak
my layout. Here’s the skeleton of the =nixos.corne= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.corne = {
<<udev-rule>>
};
}
#+end_src
** Granting HID Access
By default, the =hidraw= device nodes created for the keyboard are only
accessible to root, which means Vial can’t talk to it without running
as root too. Instead, I add a =udev= rule matching my keyboard’s Vial
identifier (the part after =vial:= is the keyboard’s unique unlock ID,
burned into its firmware) and grant the =users= group read/write access
to it, tagging it for =uaccess= / =udev-acl= so it’s also picked up by the
logged-in session’s ACLs.
#+name: udev-rule
#+begin_src nix
services.udev = {
extraRules = ''
KERNEL=="hidraw*", SUBSYSTEM=="hidraw", ATTRS{serial}=="*vial:f64c2b3c*", MODE="0660", GROUP="users", TAG+="uaccess", TAG+="udev-acl"
'';
};
#+end_src
@@ -0,0 +1,7 @@
{
flake.modules.nixos.disable-ibm-trackpoint = {
services.udev.extraRules = ''
ATTRS{name}=="*TPPS/2 IBM TrackPoint", ENV{ID_INPUT}="", ENV{ID_INPUT_MOUSE}="", ENV{ID_INPUT_POINTINGSTICK}=""
'';
};
}
@@ -0,0 +1,30 @@
#+title: Disable the IBM TrackPoint
#+setupfile: ../../headers
* Disable the IBM TrackPoint
My ThinkPads come with IBM’s TrackPoint, the little red nub sitting
between the =G=, =H= and =B= keys. I don’t want it active, though, it has a
drift and I cannot fix it unless I change my keyboard. Thus, this
module exposes a way to turn it off. Here’s the skeleton of the
=nixos.disable-ibm-trackpoint= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.disable-ibm-trackpoint = {
<<udev-rule>>
};
}
#+end_src
** Disabling the TrackPoint
The TrackPoint shows up to the input stack as a regular pointer
device, so to disable it I can’t simply blacklist a driver — libinput
and friends would still pick it up through =evdev=. Instead, I match it
by its device name and clear the =ID_INPUT=, =ID_INPUT_MOUSE= and
=ID_INPUT_POINTINGSTICK= udev properties on it, which tells the input
stack to simply ignore the device as a pointing device.
#+name: udev-rule
#+begin_src nix
services.udev.extraRules = ''
ATTRS{name}=="*TPPS/2 IBM TrackPoint", ENV{ID_INPUT}="", ENV{ID_INPUT_MOUSE}="", ENV{ID_INPUT_POINTINGSTICK}=""
'';
#+end_src
+9
View File
@@ -0,0 +1,9 @@
{
flake.modules.nixos.opentablet = {
hardware.opentabletdriver = {
enable = true;
daemon.enable = true;
};
boot.kernelModules = ["wacom"];
};
}
+30
View File
@@ -0,0 +1,30 @@
#+title: OpenTabletDriver
#+setupfile: ../../headers
* OpenTabletDriver
Some of my machines are hooked up to a graphics tablet, a Wacom
Bamboo, driven by [[https://opentabletdriver.net/][OpenTabletDriver]]. I remember buying it for 15€, what
a deal that was! Anyway, since most of my hosts don’t have a tablet
attached, this is exposed as a regular toggle rather than enabled
unconditionally. Here’s the skeleton of the =nixos.opentablet= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.opentablet = {
<<config>>
};
}
#+end_src
** Enabling the Driver
Enabling OpenTabletDriver proper is just a matter of turning on the
module and its daemon. I also need to explicitly load the =wacom=
kernel module, since my tablet (like most of them) identifies itself
as a Wacom device at the hardware level regardless of brand.
#+name: config
#+begin_src nix
hardware.opentabletdriver = {
enable = true;
daemon.enable = true;
};
boot.kernelModules = ["wacom"];
#+end_src
+5
View File
@@ -0,0 +1,5 @@
{
flake.modules.nixos.trackball = {
services.libinput.mouse.middleEmulation = true;
};
}
+22
View File
@@ -0,0 +1,22 @@
#+title: Trackball
#+setupfile: ../../headers
* Trackball
I use a trackball on some of my machines, and I middle-click by
pressing the left and right buttons together rather than through a
dedicated button. That’s the only downside of the two trackballs I
own; otherwise, I can’t recommend one enough. Here’s the
=nixos.trackball= module enabling this behaviour.
#+begin_src nix :tangle yes
{
flake.modules.nixos.trackball = {
<<middle-emulation>>
};
}
#+end_src
Enabling middle-click emulation is simple:
#+name: middle-emulation
#+begin_src nix
services.libinput.mouse.middleEmulation = true;
#+end_src
@@ -1,13 +1,5 @@
{
lib,
config,
...
}:
with lib; let
cfg = config.mySystem.hardware.pinetab2;
in {
options.mySystem.hardware.pinetab2.enable = mkEnableOption "Activate support for the PineTab2";
config = {
flake.modules.nixos.pinetab2 = {
boot.kernelParams = ["console=tty0" "console=ttyS2,1500000n8" "rootwait" "root=LABEL=NIXOS_SD" "rw"];
hardware.sensor.iio.enable = true;
services.avahi = {
+48
View File
@@ -0,0 +1,48 @@
#+title: PineTab2
#+setupfile: ../headers
* PineTab2
A few tweaks are specific to my PineTab2 tablet: getting a serial
console working at boot, exposing its sensors, and making it easy to
find on whatever network it’s connected to. Here’s the skeleton of the
=nixos.pinetab2= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.pinetab2 = {
<<kernel-params>>
<<sensors>>
<<avahi>>
};
}
#+end_src
** Serial Console
These kernel parameters get me a working serial console on the
tablet’s UART at boot, and point the kernel at the SD card’s root
filesystem by label rather than by a device path that can shift
around.
#+name: kernel-params
#+begin_src nix
boot.kernelParams = ["console=tty0" "console=ttyS2,1500000n8" "rootwait" "root=LABEL=NIXOS_SD" "rw"];
#+end_src
** Sensors
Turning on the IIO (Industrial I/O) subsystem exposes the tablet’s
accelerometer and ambient light sensor, which is what lets things like
auto-rotate work.
#+name: sensors
#+begin_src nix
hardware.sensor.iio.enable = true;
#+end_src
** Finding It on the Network
The tablet moves between networks a lot, so Avahi lets me reach it by
its =.local= hostname over mDNS instead of having to look up whatever IP
it was handed.
#+name: avahi
#+begin_src nix
services.avahi = {
enable = true;
openFirewall = true;
};
#+end_src
+50
View File
@@ -0,0 +1,50 @@
{
flake.modules.nixos.sound = {
lib,
config,
pkgs,
...
}:
with lib; let
cfg = config.mySystem.hardware.sound;
in {
options.mySystem.hardware.sound = {
noisetorch = mkEnableOption "Whether to activate noisetorch support";
scarlett.enable = mkEnableOption "Activate support for Scarlett sound card";
alsa = mkOption {
type = types.bool;
example = true;
default = true;
description = "Whether to enable ALSA support with Pipewire";
};
jack = mkOption {
type = types.bool;
example = true;
default = false;
description = "Whether to enable JACK support with Pipewire";
};
package = mkOption {
type = types.package;
example = pkgs.pulseaudio;
default = pkgs.pulseaudioFull;
description = "Which base package to use for PulseAudio";
};
};
config = {
environment.systemPackages = mkIf cfg.scarlett.enable [pkgs.alsa-scarlett-gui];
services = {
pipewire = {
enable = true;
alsa = mkIf cfg.alsa {
enable = mkDefault true;
support32Bit = mkDefault true;
};
jack.enable = mkDefault cfg.jack;
};
pulseaudio.enable = false;
};
programs.noisetorch.enable = cfg.noisetorch;
};
};
}
+118
View File
@@ -0,0 +1,118 @@
#+title: Sound
#+setupfile: ../headers
* Sound
I use Pipewire for audio on my desktop machines, with a couple of
compatibility layers and bits of hardware-specific support switched on
as needed. Here’s the skeleton of the =nixos.sound= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.sound = {
lib,
config,
pkgs,
...
}:
with lib; let
cfg = config.mySystem.hardware.sound;
in {
options.mySystem.hardware.sound = {
<<opt-noisetorch>>
<<opt-scarlett>>
<<opt-alsa>>
<<opt-jack>>
<<opt-package>>
};
config = {
<<scarlett-package>>
<<pipewire-config>>
<<noisetorch-config>>
};
};
}
#+end_src
** Noise Suppression
=noisetorch= toggles [[https://github.com/noisetorch/NoiseTorch][NoiseTorch]], a real-time microphone noise
suppression tool I use for calls, so I have an option for that.
#+name: opt-noisetorch
#+begin_src nix
noisetorch = mkEnableOption "Whether to activate noisetorch support";
#+end_src
Passing it to NixOS is quite simple.
#+name: noisetorch-config
#+begin_src nix
programs.noisetorch.enable = cfg.noisetorch;
#+end_src
** Scarlett Sound Card
=scarlett.enable= is for the machine =marpa= with a Focusrite Scarlett 2i2
audio interface plugged in; it only pulls in that card’s control GUI.
#+name: opt-scarlett
#+begin_src nix
scarlett.enable = mkEnableOption "Activate support for Scarlett sound card";
#+end_src
It is installed quite easily in enabled.
#+name: scarlett-package
#+begin_src nix
environment.systemPackages = mkIf cfg.scarlett.enable [pkgs.alsa-scarlett-gui];
#+end_src
** Enabling Pipewire
Enabling Pipewire also means explicitly turning PulseAudio off, since
the two can’t run as the system’s sound server at the same time.
#+name: pipewire-config
#+begin_src nix
services = {
pipewire = {
enable = true;
alsa = mkIf cfg.alsa {
enable = mkDefault true;
support32Bit = mkDefault true;
};
jack.enable = mkDefault cfg.jack;
};
pulseaudio.enable = false;
};
#+end_src
** ALSA Compatibility
=alsa= enables Pipewire’s ALSA compatibility layer, on by default since
most of my audio software still expects ALSA.
#+name: opt-alsa
#+begin_src nix
alsa = mkOption {
type = types.bool;
example = true;
default = true;
description = "Whether to enable ALSA support with Pipewire";
};
#+end_src
** JACK Compatibility
=jack= enables Pipewire’s JACK compatibility layer, off by default since
only my production machine needs it.
#+name: opt-jack
#+begin_src nix
jack = mkOption {
type = types.bool;
example = true;
default = false;
description = "Whether to enable JACK support with Pipewire";
};
#+end_src
** Base Package
=package= picks which PulseAudio package to build things on top of.
#+name: opt-package
#+begin_src nix
package = mkOption {
type = types.package;
example = pkgs.pulseaudio;
default = pkgs.pulseaudioFull;
description = "Which base package to use for PulseAudio";
};
#+end_src
+22
View File
@@ -0,0 +1,22 @@
# -*- mode: org -*-
#+AUTHOR: Lucien Cartier-Tilet
#+EMAIL: lucien@phundrak.com
#+CREATOR: Lucien Cartier-Tilet
#+LANGUAGE: en
# ### ORG OPTIONS ##############################################################
#+options: H:4 broken_links:mark email:t ^:{} tex:dvisvgm toc:nil
#+KEYWORDS: dotfiles, linux, emacs, configuration, phundrak, drakpa
#+startup: content align hideblocks
#+property: header-args:emacs-lisp :noweb yes :exports none :eval yes :cache yes
#+property: header-args:nix :exports code :tangle no :noweb no-export
#+property: header-args:dot :dir img :exports results :eval yes :cache yes :class gentree
# ### MACROS ###################################################################
#+macro: phon @@html:/$1/@@
#+macro: newline @@html:<br>@@
#+macro: latex-html @@latex:$1@@@@html:$2@@
#+macro: v @@html:<span class=vertical>$1</span>@@
#+macro: begin-largetable @@html:<div class="largetable">@@
#+macro: end-largetable @@html:</div>@@
+40
View File
@@ -0,0 +1,40 @@
{config, ...}: let
m = config.flake.modules.homeManager;
in {
flake.modules.homeManager.home-base = {
config,
lib,
...
}:
with lib; let
cfg = config.home;
in {
imports = [
m.basics
m.cli
m.desktop
m.dev
m.media
m.my-services
m.security
m.shell
];
options.home = {
fullDesktop = mkEnableOption "Enable most modules";
gpuType = mkOption {
type = types.nullOr (types.enum ["nvidia" "amd" "intel"]);
default = null;
example = "amd";
};
};
config.home = {
cli.fullDesktop = mkDefault cfg.fullDesktop;
desktop.fullDesktop = mkDefault cfg.fullDesktop;
dev.fullDesktop = mkDefault cfg.fullDesktop;
media.fullDesktop = mkDefault cfg.fullDesktop;
security.fullDesktop = mkDefault cfg.fullDesktop;
myServices.fullDesktop = mkDefault cfg.fullDesktop;
};
};
}
+12
View File
@@ -0,0 +1,12 @@
{
flake.modules.homeManager.basics = {
programs = {
fd.enable = true;
fzf.enable = true;
home-manager.enable = true;
htop.enable = true;
jq.enable = true;
ripgrep.enable = true;
};
};
}
+26
View File
@@ -0,0 +1,26 @@
{
flake.modules.homeManager.bat = {
pkgs,
config,
lib,
...
}:
with lib; let
cfg = config.home.cli.bat;
in {
options.home.cli.bat.extras = mkEnableOption "Enables extra packages for bat.";
config.programs.bat = {
enable = true;
config = {
theme = "Nord";
map-syntax = [
".spacemacs*:Lisp"
];
};
extraPackages = mkIf cfg.extras (with pkgs.bat-extras; [
batman
batpipe
]);
};
};
}
+36
View File
@@ -0,0 +1,36 @@
{
flake.modules.homeManager.btop = {
pkgs,
config,
...
}: let
inherit (config.home) gpuType;
in {
programs.btop = {
enable = true;
package =
if gpuType != null
then
pkgs.btop.override {
rocmSupport = gpuType == "amd";
cudaSupport = gpuType == "nvidia";
}
else pkgs.btop;
settings = {
color_theme = "${pkgs.btop}/share/btop/themes/nord.theme";
cpu_bottom = false;
cpu_sensor = "auto";
io_graph_combined = false;
io_mode = true;
only_physical = true;
proc_tree = true;
rounded_corners = true;
show_disks = true;
show_gpu_info = "on";
show_uptime = true;
theme_background = true;
vim_keys = false;
};
};
};
}
+33
View File
@@ -0,0 +1,33 @@
{config, ...}: let
m = config.flake.modules.homeManager;
in {
flake.modules.homeManager.cli = {
config,
lib,
...
}:
with lib; let
cfg = config.home.cli;
in {
imports = [
m.bat
m.btop
m.direnv
m.eza
m.mu
m.nh
m.nix-index
m.scripts
m.tealdeer
m.yt-dlp
];
options.home.cli.fullDesktop = mkEnableOption "Enable all optional modules and options";
config.home.cli = {
bat.extras = mkDefault cfg.fullDesktop;
mu.enable = mkDefault cfg.fullDesktop;
scripts.enable = mkDefault cfg.fullDesktop;
yt-dlp.enable = mkDefault cfg.fullDesktop;
};
};
}
+12
View File
@@ -0,0 +1,12 @@
{
flake.modules.homeManager.direnv = {
programs.direnv = {
enable = true;
config.global = {
load_dotenv = true;
hide_env_diff = true;
};
nix-direnv.enable = true;
};
};
}
+10
View File
@@ -0,0 +1,10 @@
{
flake.modules.homeManager.eza = {
programs.eza = {
enable = true;
colors = "auto";
icons = "auto";
git = true;
};
};
}
+13
View File
@@ -0,0 +1,13 @@
{
flake.modules.homeManager.mu = {
config,
lib,
...
}:
with lib; let
cfg = config.home.cli.mu;
in {
options.home.cli.mu.enable = mkEnableOption "Enable mu";
config.programs.mu.enable = cfg.enable;
};
}
+22
View File
@@ -0,0 +1,22 @@
{
flake.modules.homeManager.nh = {
config,
lib,
...
}:
with lib; let
cfg = config.home.cli.nh;
in {
options.home.cli.nh.flake = mkOption {
type = types.path;
default = "/home/phundrak/.dotfiles";
example = "/etc/nixos";
};
config.programs.nh = {
enable = true;
clean.enable = true;
clean.extraArgs = "--keep-since 15d --keep 5";
inherit (cfg) flake;
};
};
}
+17
View File
@@ -0,0 +1,17 @@
{inputs, ...}: {
flake-file.inputs.nix-index-database = {
url = "github:nix-community/nix-index-database";
inputs.nixpkgs.follows = "nixpkgs";
};
flake.modules.homeManager.nix-index = {
imports = [
inputs.nix-index-database.homeModules.nix-index
];
programs = {
nix-index.enable = true;
nix-index-database.comma.enable = true;
};
};
}
+16
View File
@@ -0,0 +1,16 @@
{
flake.modules.homeManager.scripts = {
pkgs,
lib,
config,
...
}:
with lib; let
cfg = config.home.cli.scripts;
scriptFiles = filesystem.listFilesRecursive ./_scripts;
scripts = map (file: (import file {inherit pkgs config;})) scriptFiles;
in {
options.home.cli.scripts.enable = mkEnableOption "Add custom scripts to PATH";
config.home.packages = mkIf cfg.enable scripts;
};
}
+8
View File
@@ -0,0 +1,8 @@
{
flake.modules.homeManager.tealdeer = {
programs.tealdeer = {
enable = true;
enableAutoUpdates = true;
};
};
}
+20
View File
@@ -0,0 +1,20 @@
{
flake.modules.homeManager.yt-dlp = {
lib,
config,
...
}:
with lib; let
cfg = config.home.cli.yt-dlp;
in {
options.home.cli.yt-dlp.enable = mkEnableOption "Enable yt-dlp";
config.programs.yt-dlp = mkIf cfg.enable {
inherit (cfg) enable;
settings = {
embed-thumbnail = true;
embed-subs = true;
sub-langs = "all";
};
};
};
}
+71
View File
@@ -0,0 +1,71 @@
{config, ...}: let
m = config.flake.modules.homeManager;
in {
flake.modules.homeManager.creug = {
pkgs,
config,
lib,
...
}:
with lib; let
cfg = config.home.creug;
in {
imports = [m.home-base];
options.home.creug = {
sshKey = {
content = mkOption {
type = types.nullOr types.str;
example = "ssh-ed25519 AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA";
default = null;
};
file = mkOption {
type = with types; nullOr path;
default = "/home/creug/.ssh/id_ed25519.pub";
};
};
};
config = {
nixpkgs.config.allowUnfree = true;
home = {
username = "creug";
homeDirectory = "/home/creug";
packages = [pkgs.tree pkgs.ncdu];
preferXdgDirectories = true;
creug.sshKey.file = "${config.home.homeDirectory}/.ssh/id_ed25519.pub";
dev.vcs = {
name = "Creug";
email = "gregory.foulachon@gmail.com";
editor = "${pkgs.nano}/bin/nano";
jj = {
enable = true;
cz = {
enable = true;
alias = true;
};
};
git.enable = true;
publicKey = cfg.sshKey;
};
security.ssh.enable = true;
shell = {
bash.enable = true;
zsh.enable = true;
starship.enable = true;
tmux.enable = false;
zoxide.enable = false;
};
stateVersion = "24.11"; # Do not modify!
};
manual.manpages.enable = true;
};
};
}
+13
View File
@@ -0,0 +1,13 @@
{config, ...}: let
m = config.flake.modules.homeManager;
in {
flake.modules.homeManager."creug-elcafe" = {...}: {
imports = [m.creug];
home = {
cli.nh.flake = "/home/creug/.dotfiles";
dev.editors.emacs.enable = false;
creug.sshKey.content = builtins.readFile ../keys/id_elcafe.pub;
};
};
}
+98
View File
@@ -0,0 +1,98 @@
{inputs, ...}: {
flake-file.inputs.caelestia-shell = {
url = "github:caelestia-dots/shell?ref=stable";
inputs.nixpkgs.follows = "nixpkgs";
};
flake.modules.homeManager.caelestia = {
config,
lib,
pkgs,
...
}:
with lib; let
cfg = config.home.desktop.caelestia;
in {
imports = [inputs.caelestia-shell.homeManagerModules.default];
options.home.desktop.caelestia = {
enable = mkEnableOption "Enables Caelestia Shell";
idleTimeout = mkOption {
description = "Idle duration in seconds before locking the session";
default = 60 * 60; # an hour
type = types.int;
};
};
config.programs.caelestia = mkIf cfg.enable {
inherit (cfg) enable;
systemd = {
enable = true;
target = "graphical-session.target";
environment = ["QT3_QPA_PLATFORMTHEME=gtk3"];
};
settings = {
paths.wallpaperDir = "~/Pictures/Wallpapers/nord";
general = {
apps = {
terminal = ["kitty"];
audio = ["pavucontrol"];
playback = ["mpv"];
explorer = ["${pkgs.nemo-with-extensions}/bin/nemo"];
};
idle = {
inhibitWhenAudio = true;
timeouts = [
{
timeout = cfg.idleTimeout;
idleAction = "lock";
}
];
};
};
background = {
desktopClock.enabled = true;
visualiser.enabled = true;
};
dashboard = {
enabled = true;
showOnHover = true;
};
launcher = {
enabled = true;
showOnHover = false;
useFuzzy = {
apps = true;
schemes = true;
wallpapers = true;
};
};
osd.enableMicrophone = true;
bar = {
status = {
showAudio = true;
showKbLayout = false;
};
tray.compact = true;
};
services = mkIf (config.home.gpuType != null) {
inherit (config.home) gpuType;
};
session.commands = {
logout = ["uwsm" "stop"];
shutdown = ["systemctl" "poweroff"];
hibernate = ["systemctl" "hibernate"];
reboot = ["systemctl" "reboot"];
};
utilities.toasts = {
capsLockChanged = false;
numLockChanged = false;
kbLayoutChanged = false;
};
};
cli = {
enable = true;
settings.theme.enableGtk = true;
};
};
};
}
+44
View File
@@ -0,0 +1,44 @@
{config, ...}: let
m = config.flake.modules.homeManager;
in {
flake.modules.homeManager.desktop = {
lib,
config,
...
}:
with lib; let
cfg = config.home.desktop;
in {
imports = [
m.caelestia
m.firefox
m.hyprland
m.hyprpaper
m.kdeconnect
m.kitty
m.obs
m.rofi
m.spotify
m.swaync
m.theme
m.waybar
m.wl-kbptr
m.wlr-which-key
m.wlsunset
];
options.home.desktop.fullDesktop = mkEnableOption "Enable options for graphical environments";
config.home.desktop = {
firefox.enable = mkDefault cfg.fullDesktop;
hyprland.enable = mkDefault cfg.fullDesktop;
kdeconnect.enable = mkDefault cfg.fullDesktop;
kitty.enable = mkDefault cfg.fullDesktop;
obs.enable = mkDefault cfg.fullDesktop;
rofi.enable = mkDefault cfg.fullDesktop;
spotify.enable = mkDefault cfg.fullDesktop;
spotify.spicetify.enable = mkDefault cfg.fullDesktop;
theme.enable = mkDefault cfg.fullDesktop;
wlr-which-key.enable = mkDefault cfg.fullDesktop;
};
};
}
+78
View File
@@ -0,0 +1,78 @@
{inputs, ...}: {
flake-file.inputs.zen-browser = {
url = "github:youwen5/zen-browser-flake";
inputs.nixpkgs.follows = "nixpkgs";
};
flake.modules.homeManager.firefox = {
config,
lib,
pkgs,
...
}:
with lib; let
cfg = config.home.desktop.firefox;
inherit (pkgs.stdenv.hostPlatform) system;
zen = inputs.zen-browser.packages.${system}.default;
settingsToLines = settings:
concatStringsSep "\n" (mapAttrsToList (name: value: "set ${name} ${toString value}") settings);
in {
options.home.desktop.firefox = {
enable = mkEnableOption "enable Firefox";
useZen = mkEnableOption "use Zen instead of Firefox";
tridactyl = {
enable = mkEnableOption "enable Tridactyl";
preConfig = mkOption {
description = "Lines to add to the beginning of tridactylrc";
type = types.lines;
default = "";
};
config = mkOption {
type = with types;
attrsOf (oneOf [
int
str
bool
]);
description = "Tridactyl settings (converted to 'set key value' lines)";
default = {};
example = {
smoothscroll = true;
history = 1000;
};
};
extraConfig = mkOption {
description = "Extra lines to add to tridactylrc (for bindings, autocmds, etc)";
type = types.lines;
default = "";
};
};
};
config = mkIf cfg.enable {
home.sessionVariables.MOZ_ENABLE_WAYLAND = "1";
programs.firefox = {
inherit (cfg) enable;
package =
if cfg.useZen
then zen
else pkgs.firefox;
nativeMessagingHosts = lists.optional cfg.tridactyl.enable pkgs.tridactyl-native;
configPath = ".mozilla/firefox";
};
xdg.configFile."tridactyl/tridactylrc" = mkIf cfg.tridactyl.enable {
text = concatStringsSep "\n" (filter (s: s != "") [
cfg.tridactyl.preConfig
(settingsToLines (cfg.tridactyl.config
// {
browser =
if cfg.useZen
then "zen"
else "firefox";
}))
cfg.tridactyl.extraConfig
]);
};
};
};
}
+90
View File
@@ -0,0 +1,90 @@
{
flake.modules.homeManager.hyprpaper = {
config,
lib,
pkgs,
...
}:
with lib; let
cfg = config.home.desktop.hyprpaper;
in {
options.home.desktop.hyprpaper = {
enable = mkEnableOption "Enables Hyprpaper";
default = mkOption {
type = types.str;
default = "/home/phundrak/Pictures/Wallpapers/nord/Nordic6.jpg";
example = "/home/user/image.jpg";
};
wallpapers-dir = mkOption {
type = types.str;
default = "/home/phundrak/Pictures/Wallpapers/nord/";
example = "/home/user/Pictures/";
};
rotation-interval = mkOption {
type = types.str;
default = "5m";
example = "10m";
description = "Interval between wallpaper rotations";
};
};
config = mkIf cfg.enable {
services.hyprpaper = {
inherit (cfg) enable;
settings = {
ipc = "on";
splash = false;
preload = cfg.default;
wallpaper = ", ${cfg.default}";
};
};
systemd.user = {
services.hyprpaper-rotation = {
Unit = {
Description = "Rotate Hyprpaper wallpaper";
After = "graphical-session.target";
};
Service = {
Type = "oneshot";
ExecCondition = "${pkgs.procps}/bin/pidof Hyprland";
ExecStart = "${config.home.homeDirectory}/.config/hypr/hyprpaper-rotate.sh";
};
};
timers.hyprpaper-rotation = {
Unit = {
Description = "Timer for rotating Hyprpaper wallpaper";
};
Timer = {
OnBootSec = cfg.rotation-interval;
OnUnitActiveSec = cfg.rotation-interval;
};
Install = {
WantedBy = ["timers.target"];
};
};
};
home.file.".config/hypr/hyprpaper-rotate.sh" = {
text = ''
#!/usr/bin/env bash
set -euo pipefail
WALLPAPER_DIR="${cfg.wallpapers-dir}"
# Find a random wallpaper
WP=$(find "$WALLPAPER_DIR" -type f \( -iname "*.jpg" -o -iname "*.jpeg" -o -iname "*.png" \) | shuf -n 1)
if [ -z "$WP" ]; then
echo "No wallpapers found in $WALLPAPER_DIR"
exit 1
fi
echo "Setting wallpaper to: $WP"
# Load and set the wallpaper
${pkgs.hyprland}/bin/hyprctl hyprpaper preload "$WP" && ${pkgs.hyprland}/bin/hyprctl hyprpaper wallpaper ",$WP"
'';
executable = true;
};
};
};
}
+16
View File
@@ -0,0 +1,16 @@
{
flake.modules.homeManager.kdeconnect = {
lib,
config,
...
}:
with lib; let
cfg = config.home.desktop.kdeconnect;
in {
options.home.desktop.kdeconnect.enable = mkEnableOption "Enable KDE Connect";
config.services.kdeconnect = mkIf cfg.enable {
enable = true;
indicator = true;
};
};
}
+116
View File
@@ -0,0 +1,116 @@
{
flake.modules.homeManager.kitty = {
pkgs,
config,
lib,
...
}:
with lib; let
cfg = config.home.desktop.kitty;
in {
options.home.desktop.kitty.enable = mkEnableOption "Enable kitty terminal";
config.programs.kitty = mkIf cfg.enable {
inherit (cfg) enable;
themeFile = "Nord";
font = {
package = pkgs.cascadia-code;
name = "Cascadia Code";
size = 10;
};
settings = {
enable_audio_bell = true;
visual_bell_duration = 0.1;
enabled_layouts = "fat,fat:mirrored=true,tall,tall:mirrored=true";
kitty_mod = "ctrl+shift";
disable_ligatures = "never";
font_features = "Cascadia-Mono +onum +zero";
cursor_shape = "block";
scrollback_lines = "10000";
mouse_hide_wait = 3.0;
detect_urls = true;
background_opacity = 0.7;
};
keybindings = let
prefix = "kitty_mod+space";
in {
"alt+c" = "copy_to_clipboard";
"kitty_mod+c" = "copy_to_clipboard";
"alt+v" = "paste_from_clipboard";
"kitty_mod+v" = "paste_from_clipboard";
"${prefix}>s>c" = "show_scrollback";
"${prefix}>s>down" = "scroll_line_down";
"${prefix}>s>t" = "scroll_line_down";
"${prefix}>s>up" = "scroll_line_up";
"${prefix}>s>s" = "scroll_line_up";
"${prefix}>s>end" = "scroll_end";
"${prefix}>s>home" = "scroll_home";
"${prefix}>s>page_down" = "scroll_page_down";
"${prefix}>s>page_up" = "scroll_page_up";
"${prefix}>enter" = "new_window";
"${prefix}>w>q" = "close_window";
"${prefix}>w>p" = "next_window";
"${prefix}>w>n" = "previous_window";
"${prefix}>w>f" = "move_window_forward";
"${prefix}>w>b" = "move_window_backward";
"${prefix}>w>t" = "move_window_to_top";
"${prefix}>w>r" = "start_resizing_window";
"${prefix}>w>1" = "first_window";
"${prefix}>w>2" = "second_window";
"${prefix}>w>3" = "third_window";
"${prefix}>w>4" = "fourth_window";
"${prefix}>w>5" = "fifth_window";
"${prefix}>w>6" = "sixth_window";
"${prefix}>w>7" = "seventh_window";
"${prefix}>w>8" = "eighth_window";
"${prefix}>w>9" = "ninth_window";
"${prefix}>w>0" = "tenth_window";
"${prefix}>tab>n" = "next_tab";
"${prefix}>tab>p" = "previous_tab";
"${prefix}>tab>c" = "new_tab";
"${prefix}>tab>q" = "close_tab";
"${prefix}>tab>shift+n" = "move_tab_backward";
"${prefix}>tab>shift+p" = "move_tab_forward";
"${prefix}>tab>t" = "set_tab_title";
"${prefix}>l" = "next_layout";
"${prefix}>f>equal" = "change_font_size all 0";
"${prefix}>f>kp_add" = "change_font_size all +2.0";
"${prefix}>f>plus" = "change_font_size all +2.0";
"${prefix}>f>kp_subtract" = "change_font_size all -2.0";
"${prefix}>f>minus" = "change_font_size all -2.0";
"${prefix}>shift+h" = "kitten hints";
"${prefix}>h>p" = "kitten hints --type path --program -";
"${prefix}>h>shift+p" = "kitten hints --type path";
"${prefix}>h>l" = "kitten hints --type line --program -";
"${prefix}>h>w" = "kitten hints --type word --program -";
"${prefix}>h>h" = "kitten hints --type hash --program -";
"${prefix}>h>n" = "kitten hints --type linenum";
"${prefix}>h>y" = "kitten hints --type hyperlink";
"${prefix}>f10" = "toggle_maximized";
"${prefix}>f11" = "toggle_fullscreen";
"${prefix}>a>equal" = "set_background_opacity 1";
"${prefix}>a>d" = "set_background_opacity default";
"${prefix}>a>plus" = "set_background_opacity +0.1";
"${prefix}>a>up" = "set_background_opacity +0.1";
"${prefix}>a>kp_add" = "set_background_opacity +0.1";
"${prefix}>a>minus" = "set_background_opacity -0.1";
"${prefix}>a>down" = "set_background_opacity -0.1";
"${prefix}>a>kp_substract" = "set_background_opacity -0.1";
"${prefix}>delete" = "clear_terminal reset active";
"${prefix}>escape" = "kitty_shell window";
"${prefix}>f2" = "edit_config_file";
"${prefix}>n" = "new_os_window";
"${prefix}>o" = "pass_selection_to_program";
"${prefix}>u" = "kitten unicode_input";
};
};
};
}
+29
View File
@@ -0,0 +1,29 @@
{
flake.modules.homeManager.obs = {
config,
lib,
pkgs,
...
}:
with lib; let
cfg = config.home.desktop.obs;
obs-image-reaction = pkgs.callPackage ../../../packages/obs-image-reaction.nix {};
in {
options.home.desktop.obs.enable = mkEnableOption "Enables OBS Studio";
config.programs.obs-studio = mkIf cfg.enable {
inherit (cfg) enable;
plugins = with pkgs.obs-studio-plugins; [
input-overlay
obs-backgroundremoval
obs-markdown
obs-mute-filter
obs-pipewire-audio-capture
obs-scale-to-sound
obs-source-clone
obs-source-record
obs-tuna
obs-image-reaction
];
};
};
}

Before

Width:  |  Height:  |  Size: 228 KiB

After

Width:  |  Height:  |  Size: 228 KiB

+109
View File
@@ -0,0 +1,109 @@
{
flake.modules.homeManager.rofi = {
config,
lib,
pkgs,
...
}:
with lib; let
cfg = config.home.desktop.rofi;
inherit (config.lib.formats.rasi) mkLiteral;
in {
options.home.desktop.rofi = {
enable = mkEnableOption "Enable Rofi";
};
config = mkIf cfg.enable {
home.packages = with pkgs; [rofi-bluetooth];
programs.rofi = {
enable = true;
plugins = with pkgs; [
rofi-calc
rofi-emoji
];
terminal = "${pkgs.kitty}/bin/kitty";
location = "center";
modes = ["drun" "emoji" "calc" "combi"];
extraConfig.show-icons = true;
theme = {
"*" = {
font = "Cascadia Code 14";
blur = true;
padding = mkLiteral "10px";
background-color = mkLiteral "transparent";
border-radius = mkLiteral "0px";
};
window = {
width = mkLiteral "1050px";
height = mkLiteral "625px";
location = mkLiteral "center";
blur = true;
border = mkLiteral "2px";
border-radius = mkLiteral "3px";
border-color = mkLiteral "#61afef";
background-color = mkLiteral "transparent";
padding = mkLiteral "0px";
margin = mkLiteral "30px 50px";
};
mainbox = {
orientation = mkLiteral "horizontal";
children = map mkLiteral ["borderbox"];
spacing = mkLiteral "0px";
padding = mkLiteral "0px";
};
borderbox = {
orientation = mkLiteral "horizontal";
children = map mkLiteral ["imagebox" "contentbox"];
padding = mkLiteral "0px";
spacing = mkLiteral "0px";
border-radius = mkLiteral "3px";
};
contentbox = {
orientation = mkLiteral "vertical";
children = map mkLiteral ["entry" "listview"];
spacing = mkLiteral "0px";
padding = mkLiteral "0px";
expand = true;
};
imagebox = {
background-image = mkLiteral "url(\"${./image.jpg}\")";
background-repeat = false;
size = mkLiteral "200px 625px";
};
element = {
border-radius = mkLiteral "0px";
};
"element-text, element-icon" = {
padding = mkLiteral "6px 8px";
spacing = mkLiteral "2px";
text-color = mkLiteral "#fab387";
};
"element selected" = {
background-color = mkLiteral "#191919";
text-color = mkLiteral "#e5c07b";
border-radius = mkLiteral "3px";
};
prompt = {
enabled = false;
background-color = mkLiteral "transparent";
text-color = mkLiteral "#61afef";
padding = mkLiteral "5px 10px";
};
entry = {
padding = mkLiteral "8px";
expand = false;
font = "Cascadia Code 14";
text-color = mkLiteral "#fab387";
border-radius = mkLiteral "0px 3px 0px 0px";
background-color = mkLiteral "#292e36";
};
listview = {
lines = mkLiteral "1";
background-color = mkLiteral "rgba(46, 52, 64, 0.8)";
border-radius = mkLiteral "0px 0px 3px 0px";
padding = mkLiteral "5px";
};
};
};
};
};
}
+33
View File
@@ -0,0 +1,33 @@
{inputs, ...}: {
flake-file.inputs.spicetify = {
url = "github:Gerg-L/spicetify-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
flake.modules.homeManager.spotify = {
pkgs,
config,
lib,
...
}:
with lib; let
inherit (pkgs.stdenv.hostPlatform) system;
cfg = config.home.desktop.spotify;
spicePkgs = inputs.spicetify.legacyPackages.${system};
in {
imports = [inputs.spicetify.homeManagerModules.default];
options.home.desktop.spotify = {
enable = mkEnableOption "Enable Spotify";
spicetify.enable = mkEnableOption "Enable Spicetify";
};
config.programs = mkIf cfg.enable {
spotify-player.enable = cfg.enable;
spicetify = mkIf cfg.spicetify.enable {
inherit (cfg.spicetify) enable;
theme = spicePkgs.themes.sleek;
colorScheme = "Nord";
};
};
};
}
+17
View File
@@ -0,0 +1,17 @@
{...}: {
flake.modules.homeManager.swaync = {
config,
lib,
pkgs,
...
}:
with lib; let
cfg = config.home.desktop.swaync;
in {
options.home.desktop.swaync.enable = mkEnableOption "Enables swaync";
config = mkIf cfg.enable {
services.swaync.enable = true;
home.packages = [pkgs.swaynotificationcenter];
};
};
}
+36
View File
@@ -0,0 +1,36 @@
{
flake.modules.homeManager.theme = {
pkgs,
config,
lib,
...
}:
with lib; let
cfg = config.home.desktop.theme;
in {
options.home.desktop.theme.enable = mkEnableOption "Enable theme options";
config = mkIf cfg.enable {
gtk = {
enable = true;
colorScheme = "dark";
iconTheme = {
name = "Nordzy-icons";
package = pkgs.nordzy-icon-theme;
};
theme = {
package = pkgs.nordic;
name = "Nordic";
};
gtk4.theme = config.gtk.theme;
};
home.pointerCursor = {
enable = true;
gtk.enable = true;
hyprcursor.enable = config.home.desktop.hyprland.enable;
name = "Nordzy-cursors";
package = pkgs.nordzy-cursor-theme;
};
qt.enable = true;
};
};
}
+156
View File
@@ -0,0 +1,156 @@
{
flake.modules.homeManager.waybar = {
config,
lib,
...
}:
with lib; let
cfg = config.home.desktop.waybar;
in {
options.home.desktop.waybar = {
enable = mkEnableOption "Enables waybar.";
battery = mkEnableOption "Enables battery support.";
style = mkOption {
type = types.path;
example = ./style.css;
};
};
config.programs.waybar = mkIf cfg.enable {
inherit (cfg) enable;
systemd.enable = true;
settings = {
topBar = {
height = 24;
spacing = 2;
modules-left = ["hyprland/workspaces" "hyprland/submap" "hyprland/window"];
modules-center = [];
modules-right = [
"idle_inhibitor"
"group/audio"
"group/hardware"
"network"
"privacy"
"clock"
"tray"
];
idle_inhibitor = {
format = "{icon}";
format-icons = {
activated = "";
deactivated = "";
};
};
mpris = {
dynamic-order = ["title" "artist" "album"];
dynamic-importance-order = ["title" "artist" "album"];
format = "DEFAULT: {player_icon} {dynamic}";
format-paused = "DEFAULT: {status_icon} <i>{dynamic}</i>";
player-icons = {
default = "▶";
mpv = "🎵";
};
status-icons.paused = "⏸";
ignored-players = [];
};
pulseaudio = {
format = "{volume}% {icon} {format_source}";
format-bluetooth = "{volume}% {icon} {format_source}";
format-bluetooth-muted = " {icon} {format_source}";
format-muted = " {format_source}";
format-source = "{volume}% ";
format-source-muted = "";
format-icons = {
headphone = "";
hands-free = "";
headset = "";
phone = "";
portable = "";
car = "";
default = ["" "" ""];
};
on-click = "pavucontrol";
};
network = {
format-wifi = "{essid} ({signalStrength}%) ";
format-ethernet = "{ipaddr}/{cidr} ";
tooltip-format = "{ifname} via {gwaddr} ";
format-linked = "{ifname} (No IP) ";
format-disconnected = "Disconnected ⚠";
format-alt = "{ifname}: {ipaddr}/{cidr}";
};
"group/audio" = {
modules = ["pulseaudio" "pulseaudio/slider" "mpris"];
orientation = "inherit";
drawer.transition-duration = 300;
};
"group/hardware" = {
modules = lists.optional cfg.battery "battery" ++ ["cpu" "memory" "disk"];
orientation = "inherit";
drawer.transition-duration = 300;
};
cpu = {
format = "{usage}% ";
tooltip = false;
};
memory.format = "{}% ";
disk = {
format = "{path}: {used}/{total} ({percentage_used}%)";
unit = "GB";
};
battery = {
states = {
good = 90;
warning = 30;
critical = 15;
};
format = "{capacity}% {icon}";
format-charging = "{capacity}% ";
format-plugged = "{capacity}% ";
format-alt = "{time} {icon}";
# An empty format will hide the module
format-good = "";
format-full = "";
format-icons = ["" "" "" "" ""];
};
clock = {
timezones = ["Europe/Paris" "Asia/Tokyo" "America/New_York" "America/Los_Angeles" "Asia/Kathmandu"];
tooltip-format = "<big>{:%Y %B}</big>\n<tt><small>{calendar}</small></tt>";
format-alt = "{:%Y-%m-%d}";
actions = {
on-click-right = "mode";
on-scroll-up = "tz_up";
on-scroll-down = "tz_down";
};
calendar = {
mode = "year";
mode-mon-col = 3;
weeks-pos = "right";
on-scroll = 1;
format = {
months = "<span color='#eceff4'><b>{}</b></span>";
days = "<span color='#5e81ac'><b>{}</b></span>";
weeks = "<span color='#8fbcbb'><b>W{:%W}</b></span>";
weekdays = "<span color='#d8dee9'><b>{}</b></span>";
today = "<span color='#a3be8c'><b><u>{}</u></b></span>";
};
};
};
tray.spacing = 10;
};
};
style = builtins.readFile cfg.style;
};
};
}
+39
View File
@@ -0,0 +1,39 @@
{
flake.modules.homeManager.wl-kbptr = {
config,
lib,
pkgs,
...
}:
with lib; let
configDir = config.xdg.configHome;
cfg = config.home.desktop.wl-kbptr;
iniFormat = pkgs.formats.ini {};
in {
options.home.desktop.wl-kbptr = {
enable = mkEnableOption "enable wl-kbptr";
config = mkOption {
inherit (iniFormat) type;
default = {};
description = ''
Options to add to the {file}`config` file. See
<https://github.com/moverest/wl-kbptr/blob/main/config.example>
for options.
'';
example = {
general = {
home_row_keys = "abcd";
};
};
};
};
config = mkIf cfg.enable {
home = {
packages = [pkgs.wl-kbptr];
file."${configDir}/wl-kbptr/config" = mkIf (cfg.config != {}) {
source = iniFormat.generate "wl-kbptr-config" cfg.config;
};
};
};
};
}
+191
View File
@@ -0,0 +1,191 @@
{
flake.modules.homeManager.wlr-which-key = {
config,
lib,
pkgs,
...
}: let
inherit
(lib)
literalExpression
mkIf
mkOption
mkEnableOption
types
;
cfg = config.home.desktop.wlr-which-key;
yamlFormat = pkgs.formats.yaml {};
# Convert kebab-case to snake_case
toSnakeCase = str: builtins.replaceStrings ["-"] ["_"] str;
# Recursively filter out null values and convert kebab-case keys to snake_case
filterNulls = value:
if lib.isAttrs value
then lib.mapAttrs' (n: v: lib.nameValuePair (toSnakeCase n) (filterNulls v)) (lib.filterAttrs (_: v: v != null) value)
else if lib.isList value
then map filterNulls value
else value;
menuEntryType = types.submodule {
freeformType = yamlFormat.type;
options = with types; {
key = mkOption {
type = str;
example = "p";
};
desc = mkOption {
type = str;
example = "Power";
};
cmd = mkOption {
type = nullOr str;
default = null;
example = "echo example";
};
keep-open = mkOption {
type = nullOr bool;
default = null;
example = true;
};
submenu = mkOption {
type = nullOr (listOf menuEntryType);
default = null;
example = literalExpression ''
[
{ key = "s"; desc = "Suspend"; cmd = "systemctl suspend"; }
{ key = "r"; desc = "Reboot"; cmd = "systemctl reboot"; }
{ key = "o"; desc = "Poweroff"; cmd = "systemctl poweroff"; }
]
'';
};
};
};
settingsType = types.submodule {
freeformType = yamlFormat.type;
options = with types; {
background = mkOption {
type = nullOr str;
default = null;
example = "#282828FF";
};
color = mkOption {
type = nullOr str;
default = null;
example = "#FBF1C7FF";
};
border = mkOption {
type = nullOr str;
default = null;
example = "#8EC07CFF";
};
anchor = mkOption {
type = nullOr (enum ["center" "top" "bottom" "left" "right" "top-left" "top-right" "bottom-left" "bottom-right"]);
default = null;
example = "top-left";
};
margin-top = mkOption {
type = nullOr int;
default = null;
example = "0";
};
margin-right = mkOption {
type = nullOr int;
default = null;
example = "0";
};
margin-bottom = mkOption {
type = nullOr int;
default = null;
example = "0";
};
margin-left = mkOption {
type = nullOr int;
default = null;
example = "0";
};
font = mkOption {
type = nullOr str;
default = null;
example = "monospace 10";
};
separator = mkOption {
type = nullOr str;
default = null;
example = " ➜ ";
};
border-width = mkOption {
type = nullOr (either float int);
default = null;
example = 4.0;
};
corder-r = mkOption {
type = nullOr (either float int);
default = null;
example = 20.0;
};
padding = mkOption {
type = nullOr (either float int);
default = null;
example = 15.0;
};
rows-per-column = mkOption {
type = nullOr int;
default = null;
example = 5;
};
column-padding = mkOption {
type = nullOr (either float int);
default = null;
example = 25.0;
};
inhibit-compositor-keyboard-shortcuts = mkOption {
type = bool;
default = true;
example = false;
};
auto_kbd_layout = mkOption {
type = bool;
default = true;
example = false;
};
namespace = mkOption {
type = nullOr str;
default = null;
example = "wlr_which_key";
};
menu = mkOption {
type = listOf menuEntryType;
default = [];
example = literalExpression ''
[
{
key = "p";
desc = "Power";
submenu = [
{ key = "s"; desc = "Suspend"; cmd = "systemctl suspend"; }
{ key = "r"; desc = "Reboot"; cmd = "systemctl reboot"; }
{ key = "o"; desc = "Poweroff"; cmd = "systemctl poweroff"; }
];
}
]
'';
};
};
};
in {
options.home.desktop.wlr-which-key = {
enable = mkEnableOption "Enables wlr-which-key";
package = lib.mkPackageOption pkgs "wlr-which-key" {};
settings = mkOption {
type = settingsType;
default = {};
description = "Configuration written to {file}`$XDG_CONFIG_HOME/wlr-which-key/config.yaml`.";
};
};
config = mkIf cfg.enable {
xdg.configFile = {
"wlr-which-key/config.yaml".source = yamlFormat.generate "wlr-which-key-config.yml" (filterNulls cfg.settings);
};
};
};
}
+26
View File
@@ -0,0 +1,26 @@
{
flake.modules.homeManager.wlsunset = {
config,
lib,
...
}:
with lib; let
cfg = config.home.desktop.wlsunset;
in {
options.home.desktop.wlsunset = {
enable = mkEnableOption "Enables wlsunset";
latitude = mkOption {
type = with types; nullOr (oneOf [str ints.unsigned float]);
default = 48.5;
};
longitude = mkOption {
type = with types; nullOr (oneOf [str ints.unsigned float]);
default = 2.2;
};
};
config.services.wlsunset = mkIf cfg.enable {
inherit (cfg) enable latitude longitude;
};
};
}

Some files were not shown because too many files have changed in this diff Show More