Files
nix-config/modules/packages/nix-settings.org
T
phundrak 216065c4f2 refactor: change to litterate config
Configuration is now held by the `.org` files. All `.nix` files are
tangled from the org-mode files.
2026-10-08 15:18:56 +02:00

123 lines
3.0 KiB
Org Mode
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
#+title: Nix Settings
#+setupfile: ../headers
* Nix Settings
This module gathers the Nix daemon settings I want tuned on every
host: unfree packages, the build sandbox, garbage collection, trusted
users, and a couple of things I just want on everywhere. Here’s the
skeleton of the =nixos.nix-settings= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.nix-settings = {
lib,
config,
...
}:
with lib; let
cfg = config.mySystem.packages.nix;
in {
options.mySystem.packages.nix = {
<<opt-allow-unfree>>
<<opt-disable-sandbox>>
<<opt-gc>>
<<opt-nix-ld>>
<<opt-trusted-users>>
};
config = {
<<cfg-allow-unfree>>
<<cfg-disable-sandbox>>
<<cfg-gc>>
<<cfg-nix-ld>>
<<cfg-trusted-users>>
<<fixed-settings>>
};
};
}
#+end_src
** Unfree Packages
#+name: opt-allow-unfree
#+begin_src nix
allowUnfree = mkEnableOption "Enable unfree packages";
#+end_src
#+name: cfg-allow-unfree
#+begin_src nix
nixpkgs.config.allowUnfree = true;
#+end_src
** Nix Sandbox
#+name: opt-disable-sandbox
#+begin_src nix
disableSandbox = mkEnableOption "Disable Nix sandbox";
#+end_src
#+name: cfg-disable-sandbox
#+begin_src nix
nix.settings.sandbox = cfg.disableSandbox;
#+end_src
** Garbage Collection
By default, this runs automatically once a week, early Monday morning,
and deletes anything older than 30 days.
#+name: opt-gc
#+begin_src nix
gc = {
automatic = mkOption {
type = types.bool;
default = true;
};
dates = mkOption {
type = types.str;
default = "Monday 01:00 UTC";
};
options = mkOption {
type = types.str;
default = "--delete-older-than 30d";
};
};
#+end_src
#+name: cfg-gc
#+begin_src nix
nix.gc = cfg.gc;
#+end_src
** nix-ld
=nix-ld= lets prebuilt binaries that weren’t built for NixOS — a
downloaded compiler toolchain, a VS Code extension’s native binary —
find the shared libraries they expect at the usual FHS paths.
#+name: opt-nix-ld
#+begin_src nix
nix-ld.enable = mkEnableOption "Enable unpatched binaries support";
#+end_src
#+name: cfg-nix-ld
#+begin_src nix
programs.nix-ld = cfg.nix-ld;
#+end_src
** Trusted Users
Trusted users can do things like point Nix at arbitrary substituters,
which I need so my own binary cache and the nix-community one are
actually trusted.
#+name: opt-trusted-users
#+begin_src nix
trusted-users = mkOption {
type = types.listOf types.str;
example = ["alice" "bob"];
default = ["@wheel" "root"];
};
#+end_src
#+name: cfg-trusted-users
#+begin_src nix
nix.settings.trusted-users = cfg.trusted-users;
#+end_src
** Always-On Settings
=flakes= and the new =nix= command are on everywhere, since this whole
configuration is itself a flake, and =auto-optimise-store= hardlinks
identical files across store paths to save some disk space.
#+name: fixed-settings
#+begin_src nix
nix.settings.experimental-features = ["nix-command" "flakes"];
nix.settings.auto-optimise-store = true;
#+end_src