Configuration is now held by the `.org` files. All `.nix` files are tangled from the org-mode files.
3.0 KiB
Nix Settings
Nix Settings
This module gathers the Nix daemon settings I want tuned on every
host: unfree packages, the build sandbox, garbage collection, trusted
users, and a couple of things I just want on everywhere. Here’s the
skeleton of the nixos.nix-settings module.
{
flake.modules.nixos.nix-settings = {
lib,
config,
...
}:
with lib; let
cfg = config.mySystem.packages.nix;
in {
options.mySystem.packages.nix = {
<<opt-allow-unfree>>
<<opt-disable-sandbox>>
<<opt-gc>>
<<opt-nix-ld>>
<<opt-trusted-users>>
};
config = {
<<cfg-allow-unfree>>
<<cfg-disable-sandbox>>
<<cfg-gc>>
<<cfg-nix-ld>>
<<cfg-trusted-users>>
<<fixed-settings>>
};
};
}
Unfree Packages
allowUnfree = mkEnableOption "Enable unfree packages";
nixpkgs.config.allowUnfree = true;
Nix Sandbox
disableSandbox = mkEnableOption "Disable Nix sandbox";
nix.settings.sandbox = cfg.disableSandbox;
Garbage Collection
By default, this runs automatically once a week, early Monday morning, and deletes anything older than 30 days.
gc = {
automatic = mkOption {
type = types.bool;
default = true;
};
dates = mkOption {
type = types.str;
default = "Monday 01:00 UTC";
};
options = mkOption {
type = types.str;
default = "--delete-older-than 30d";
};
};
nix.gc = cfg.gc;
nix-ld
nix-ld lets prebuilt binaries that weren’t built for NixOS — a
downloaded compiler toolchain, a VS Code extension’s native binary —
find the shared libraries they expect at the usual FHS paths.
nix-ld.enable = mkEnableOption "Enable unpatched binaries support";
programs.nix-ld = cfg.nix-ld;
Trusted Users
Trusted users can do things like point Nix at arbitrary substituters, which I need so my own binary cache and the nix-community one are actually trusted.
trusted-users = mkOption {
type = types.listOf types.str;
example = ["alice" "bob"];
default = ["@wheel" "root"];
};
nix.settings.trusted-users = cfg.trusted-users;
Always-On Settings
flakes and the new nix command are on everywhere, since this whole
configuration is itself a flake, and auto-optimise-store hardlinks
identical files across store paths to save some disk space.
nix.settings.experimental-features = ["nix-command" "flakes"];
nix.settings.auto-optimise-store = true;