blob: cc076b2ff8c86246216f542d8468323bf48d9d82 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
|
{ pkgs, inputs, config, ... }: {
imports = [
inputs.sops-nix.nixosModules.sops
../modules/apps.nix
../modules/overrides.nix
../modules/kde.nix
../modules/networking.nix
../modules/development.nix
../modules/gaming.nix
../modules/secrets.nix
../modules/systemd.nix
inputs.home-manager.nixosModules.default
];
home-manager = {
extraSpecialArgs = { inherit inputs pkgs; };
useUserPackages = true;
useGlobalPkgs = true;
users = {
"kyren" = import ./home.nix;
};
};
users.users.kyren = {
isNormalUser = true;
description = "Kyren";
extraGroups = [ "networkmanager" "wheel" ];
shell = pkgs.zsh;
};
programs.zsh.enable = true;
# Localization
time.timeZone = "Asia/Hebron";
i18n.defaultLocale = "en_US.UTF-8";
i18n.supportedLocales = [
"en_US.UTF-8/UTF-8"
"C.UTF-8/UTF-8"
"en_IL/UTF-8"
];
# Allow sudo without a password if in "wheel" group.
security.sudo.wheelNeedsPassword = false;
# Bootloader
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = true;
boot.supportedFilesystems = [ "ntfs" ]; # for windows fs
# Nix Config
system.stateVersion = "24.05"; # DO NOT CHANGE!
nixpkgs.config.allowUnfree = true;
nix.settings.experimental-features = [ "nix-command" "flakes" ];
nix.settings.auto-optimise-store = true; # reduces nix store size
nixpkgs.config = {
packageOverrides = pkgs: {
emojipin = import <emojipin> {
config = config.nixpkgs.config;
};
};
};
# Enable dynamic linking of apps that are not in nixpkgs
# Fixes issues with neovim plugins not working
programs.nix-ld.enable = true;
programs.nix-ld.libraries = with pkgs; [
stdenv.cc.cc
wayland
libxkbcommon
libGL
];
# Enable sound with pipewire.
services.pulseaudio.enable = false;
security.rtkit.enable = true;
services.pipewire = {
enable = true;
alsa.enable = true;
alsa.support32Bit = true;
pulse.enable = true;
# If you want to use JACK applications, uncomment this
#jack.enable = true;
# use the example session manager (no others are packaged yet so this is enabled by default,
# no need to redefine it in your config for now)
#media-session.enable = true;
};
# ENable CUPS daemon for printing
services.printing.enable = false;
# Install Flatpak and Flathub
services.flatpak.enable = true;
# Enable openssh
services.openssh.enable = true;
services.openssh.settings.PasswordAuthentication = false;
users.users.root.openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO7P9K9D5RkBk+JCRRS6AtHuTAc6cRpXfRfRMg/Kyren"
];
# Enable KVM/QEMU virtualization
programs.virt-manager.enable = true;
users.groups.libvirtd.members = ["kyren"];
virtualisation.libvirtd.enable = true;
virtualisation.spiceUSBRedirection.enable = true;
virtualisation.libvirtd.qemu = {
runAsRoot = true;
ovmf.enable = true;
};
environment.systemPackages = [ pkgs.virtiofsd ]; # For shared fs
services.syncthing.enable = true;
services.syncthing = {
group = "users";
user = "kyren";
dataDir = "/home/kyren";
configDir = "/home/kyren/.config/syncthing";
};
systemd.tmpfiles.rules = [
"d /home/kyren/.config/syncthing 0700 kyren users"
];
}
|