Files
nix-config/modules/packages/nix-settings.org
T
phundrak 216065c4f2 refactor: change to litterate config
Configuration is now held by the `.org` files. All `.nix` files are
tangled from the org-mode files.
2026-10-08 15:18:56 +02:00

3.0 KiB
Raw Blame History

Nix Settings

Nix Settings

This module gathers the Nix daemon settings I want tuned on every host: unfree packages, the build sandbox, garbage collection, trusted users, and a couple of things I just want on everywhere. Here’s the skeleton of the nixos.nix-settings module.

{
  flake.modules.nixos.nix-settings = {
    lib,
    config,
    ...
  }:
    with lib; let
      cfg = config.mySystem.packages.nix;
    in {
      options.mySystem.packages.nix = {
        <<opt-allow-unfree>>
        <<opt-disable-sandbox>>
        <<opt-gc>>
        <<opt-nix-ld>>
        <<opt-trusted-users>>
      };

      config = {
        <<cfg-allow-unfree>>
        <<cfg-disable-sandbox>>
        <<cfg-gc>>
        <<cfg-nix-ld>>
        <<cfg-trusted-users>>
        <<fixed-settings>>
      };
    };
}

Unfree Packages

allowUnfree = mkEnableOption "Enable unfree packages";
nixpkgs.config.allowUnfree = true;

Nix Sandbox

disableSandbox = mkEnableOption "Disable Nix sandbox";
nix.settings.sandbox = cfg.disableSandbox;

Garbage Collection

By default, this runs automatically once a week, early Monday morning, and deletes anything older than 30 days.

gc = {
  automatic = mkOption {
    type = types.bool;
    default = true;
  };
  dates = mkOption {
    type = types.str;
    default = "Monday 01:00 UTC";
  };
  options = mkOption {
    type = types.str;
    default = "--delete-older-than 30d";
  };
};
nix.gc = cfg.gc;

nix-ld

nix-ld lets prebuilt binaries that weren’t built for NixOS — a downloaded compiler toolchain, a VS Code extension’s native binary — find the shared libraries they expect at the usual FHS paths.

nix-ld.enable = mkEnableOption "Enable unpatched binaries support";
programs.nix-ld = cfg.nix-ld;

Trusted Users

Trusted users can do things like point Nix at arbitrary substituters, which I need so my own binary cache and the nix-community one are actually trusted.

trusted-users = mkOption {
  type = types.listOf types.str;
  example = ["alice" "bob"];
  default = ["@wheel" "root"];
};
nix.settings.trusted-users = cfg.trusted-users;

Always-On Settings

flakes and the new nix command are on everywhere, since this whole configuration is itself a flake, and auto-optimise-store hardlinks identical files across store paths to save some disk space.

nix.settings.experimental-features = ["nix-command" "flakes"];
nix.settings.auto-optimise-store = true;