initial restructuring

This commit is contained in:
2026-08-08 21:12:37 -06:00
parent d1e4ae22d2
commit bb038bfba0
62 changed files with 0 additions and 3 deletions
+78
View File
@@ -0,0 +1,78 @@
{ config, lib, pkgs, ... }:
{
security.rtkit.enable = true;
services.avahi.enable = true;
services.pulseaudio.enable = false;
systemd.user.services.mpris-proxy = {
description = "Mpris proxy";
after = [ "network.target" "sound.target" ];
wantedBy = [ "default.target" ];
};
services.pipewire = {
enable = true;
alsa = {
enable = true;
support32Bit = true;
};
pulse.enable = true;
wireplumber.enable = true;
raopOpenFirewall = true;
# Dynamic, optimized buffer sizes to eliminate data starvation
extraConfig.pipewire = {
"context.properties" = {
"default.clock.rate" = 48000;
"default.clock.quantum" = 1024;
"default.clock.min-quantum" = 512;
"default.clock.max-quantum" = 2048;
};
"10-airplay" = {
"context-modules" = [
{
name = "libpipewire-module-raop-discover";
}
];
};
};
wireplumber.extraConfig = {
"10-bluetooth-policy" = {
"wireplumber.settings" = {
"bluetooth.autoswitch-to-headset" = false;
};
};
# Properly disables node suspension using WirePlumber 0.5+ syntax
"10-disable-suspend" = {
"monitor.bluez.rules" = [
{
matches = [
{
"node.name" = "~bluez_output.*";
}
];
actions = {
update-props = {
"session.suspend-timeout-seconds" = 0;
};
};
}
];
};
# Force High Quality Audio profiles ONLY (Blocks Handsfree Mic Downgrades)
"11-bluetooth-enhancements" = {
"monitor.bluez.properties" = {
"bluez5.roles" = [ "a2dp_sink" "a2dp_source" ];
"bluez5.codecs" = [ "aac" "aptx" "sbc" ];
"bluez5.enable-sbc-xq" = false;
"bluez5.enable-hw-volume" = true;
};
};
};
};
}
+10
View File
@@ -0,0 +1,10 @@
{ config, pkgs, ... }:
{
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = true;
boot.kernelPackages = pkgs.linuxPackages_latest;
boot.kernelModules = [ "uinput" ];
system.nixos.label = "niri-v.1.2";
environment.pathsToLink = [ "/libexec" ];
}
+11
View File
@@ -0,0 +1,11 @@
{ config, pkgs, ... }:
{
imports = [
./audio.nix
./boot.nix
./env.nix
./locale.nix
./power.nix
];
}
+53
View File
@@ -0,0 +1,53 @@
{ config, pkgs, ... }:
{
environment.shells = with pkgs; [ zsh ];
users.defaultUserShell = pkgs.zsh;
fonts.packages = with pkgs; [
nerd-fonts.hack
];
environment.sessionVariables = {
NIXOS_OZONE_WL = "1";
};
nix.settings = {
experimental-features = [ "nix-command" "flakes" ];
};
programs.zsh = {
enable = true;
enableCompletion = true;
autosuggestions.enable = true;
syntaxHighlighting.enable = true;
histSize = 1000000;
setOptions = [
"HIST_IGNORE_ALL_DUPS"
];
shellAliases = {
enix = "nvim $HOME/.dotfiles/flake.nix";
ehome = "nvim $HOME/.dotfiles/home/jashton.nix";
l = "ls -la";
ports = "cat $HOME/.dotfiles/ports.registry";
};
ohMyZsh = {
enable = true;
theme = "aussiegeek";
plugins = [
"git"
];
};
interactiveShellInit = ''
if [ -f "/run/secrets/vaultwarden_clientid" ]; then
export BW_CLIENTID=$(cat /run/secrets/vaultwarden_clientid)
export BW_CLIENTSECRET=$(cat /run/secrets/vaultwarden_clientsecret)
fi
'';
};
}
+20
View File
@@ -0,0 +1,20 @@
{ config, pkgs, ... }:
{
time.timeZone = "America/Denver";
i18n = {
defaultLocale = "en_US.UTF-8";
extraLocaleSettings = {
LC_ADDRESS = "en_US.UTF-8";
LC_IDENTIFICATION = "en_US.UTF-8";
LC_MEASUREMENT = "en_US.UTF-8";
LC_MONETARY = "en_US.UTF-8";
LC_NAME = "en_US.UTF-8";
LC_NUMERIC = "en_US.UTF-8";
LC_PAPER = "en_US.UTF-8";
LC_TELEPHONE = "en_US.UTF-8";
LC_TIME = "en_US.UTF-8";
LC_CTYPE = "en_US.UTF-8";
};
};
}
+32
View File
@@ -0,0 +1,32 @@
{ config, pkgs, ... }:
{
boot.kernelParams = [ "mem_sleep_default=deep" ];
services.power-profiles-daemon.enable = false;
services.tlp = {
enable = true;
settings = {
USB_AUTOSUSPEND = 0;
# AC
CPU_SCALING_GOVERNOR_ON_AC = "performance";
CPU_ENERGY_PERF_POLICY_ON_AC = "performance";
SOUND_POWER_SAVE_ON_AC = 0;
PCIE_ASPM_ON_AC = "default";
CPU_BOOST_ON_BAT = 0;
# Battery
CPU_SCALING_GOVERNOR_ON_BAT = "powersave";
CPU_ENERGY_PERF_POLICY_ON_BAT = "power";
SOUND_POWER_SAVE_ON_BAT = 1;
PCIE_ASPM_ON_BAT = "powersupersave";
CPU_BOOST_ON_AC = 1;
# Battery Thresholds
START_CHARGE_THRESH_BAT0 = 40;
STOP_CHARGE_THRESH_BAT0 = 80;
};
};
}
+12
View File
@@ -0,0 +1,12 @@
{ config, pkgs, ... }:
{
imports = [
./packages.nix
./core
./network
./security
./services
./virtualisation
];
}
+18
View File
@@ -0,0 +1,18 @@
{ config, pkgs, ... }:
{
imports = [
./pi-hole.nix
];
networking = {
networkmanager.enable = true;
firewall = {
enable = true;
allowedTCPPorts = [];
allowedUDPPorts = [];
};
};
}
+48
View File
@@ -0,0 +1,48 @@
{ config, pkgs, ... }:
{
networking.networkmanager.insertNameservers = [ "127.0.0.1" ];
systemd.tmpfiles.rules = [
"d /var/lib/pihole 0777 root root -"
"d /var/lib/pihole/etc 0777 root root -"
"d /var/lib/pihole/dnsmasq 0777 root root -"
];
# Explicitly set the OCI container backend to Podman
virtualisation.oci-containers.backend = "podman";
# Define the Pi-Hole container
virtualisation.oci-containers.containers.pihole = {
image = "docker.io/pihole/pihole:latest";
ports = [
"53:53/tcp" # DNS
"53:53/udp" # DNS
"8775:80/tcp" # Web UI
];
volumes = [
"/var/lib/pihole/etc:/etc/pihole"
"/var/lib/pihole/dnsmasq:/etc/dnsmasq.d"
];
environment = {
TZ = "America/Denver";
};
autoStart = true;
# Extra Podman arguments for additional capabilities Pi-Hole requires
extraOptions = [
"--cap-add=NET_ADMIN"
];
};
# Open the required ports in the NixOS firewall
networking.firewall = {
allowedTCPPorts = [ 53 80 ];
allowedUDPPorts = [ 53 ];
};
}
+104
View File
@@ -0,0 +1,104 @@
{ config, pkgs, ... }:
{
nixpkgs.config.allowUnfree = true;
environment.systemPackages = with pkgs; [
acpi
age
alacritty
bitwarden-cli
btop
dconf
fastfetch
firefox
git
github-cli
(google-chrome.override {
commandLineArgs = [
"--disable-pinch"
];
})
google-chrome
gnupg
jq
keepassxc
libnotify
mypy
networkmanagerapplet
nitrogen
ollama
pasystray
pulseaudioFull
rclone
rnote
sops
ssh-to-age
tldr
tmux
unrar
unzip
upower
v4l-utils
vim
wget
wl-clipboard
xclip
xournalpp
(pkgs.writeShellScriptBin "unix" ''
set -u
DOTFILES="$HOME/.dotfiles"
ERRFILE=$(mktemp)
HOST=$(cat /etc/hostname)
trap "rm -f '$ERRFILE'" EXIT
echo "Building NixOS..."
sudo nixos-rebuild switch --flake "$DOTFILES#$HOST" 2>&1 | tee "$ERRFILE"
STATUS=''${PIPESTATUS[0]}
if [ "$STATUS" -ne 0 ]; then
PATTERN=$(find "$DOTFILES" -type f -name "*.nix" -printf "%f\n" | sort -u | tr '\n' '|' | sed 's/|$//')
MATCHES=$(grep -E "$PATTERN" "$ERRFILE" | sort -u)
if [ -n "$MATCHES" ]; then
printf '\nErrors in repo files:\n%s\n' "$MATCHES"
fi
exit 1
fi
GEN=$(readlink /nix/var/nix/profiles/system | sed 's/system-\([0-9]*\)-link/\1/')
VER=$(nixos-version)
TIMESTAMP=$(date '+%Y-%m-%d %H:%M')
cd "$DOTFILES"
if [ -z "$(${pkgs.git}/bin/git status --porcelain)" ]; then
echo "Generation $GEN active — no config changes to commit."
exit 0
fi
echo "Append to default commit message? Hit enter to skip."
read -r msg_to_append
${pkgs.git}/bin/git add -A
${pkgs.git}/bin/git commit -m "nixos: gen $GEN @ $(hostname) — $TIMESTAMP $VER ----- $msg_to_append"
${pkgs.git}/bin/git push
'')
];
programs.firefox.enable = true;
programs.thunar.enable = true;
hardware.graphics = {
enable = true;
enable32Bit = true;
};
programs.steam = {
enable = true;
remotePlay.openFirewall = true;
dedicatedServer.openFirewall = true;
localNetworkGameTransfers.openFirewall = true;
};
}
+29
View File
@@ -0,0 +1,29 @@
{ config, pkgs, ... }:
{
imports = [
./sops.nix
./sudo.nix
./systemd.nix
./users.nix
];
systemd.user.services.niri-flake-polkit.enable = false;
security = {
pam.services.swaylock = {};
polkit.enable = true;
rtkit.enable = true;
tpm2 = {
enable = true;
pkcs11.enable = true;
tctiEnvironment.enable = true;
};
};
services.udev.extraRules = ''
KERNEL=="uinput", MODE="0660", GROUP="input", OPTIONS+="static_node=uinput"
'';
}
+10
View File
@@ -0,0 +1,10 @@
{ config, pkgs, ... }:
{
sops.defaultSopsFile = ../../secrets/secrets.yaml;
sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
sops.secrets."vaultwarden_clientid".owner = config.users.users.jashton.name;
sops.secrets."vaultwarden_clientsecret".owner = config.users.users.jashton.name;
}
+16
View File
@@ -0,0 +1,16 @@
{ config, pkgs, ... }:
{
security.sudo.extraRules = [
{
users = [ "jashton" ];
commands = [
{
command = "/run/current-system/sw/bin/tlp";
options = [ "NOPASSWD" ];
}
];
}
];
}
+3
View File
@@ -0,0 +1,3 @@
{ config, pkgs, ... }:
{}
+9
View File
@@ -0,0 +1,9 @@
{ config, lib, pkgs, ... }:
{
services.fprintd = {
enable = true;
#tod.enable = true;
#tod.driver = pkgs.libfprint-2-tod1-goodix;
};
}
+34
View File
@@ -0,0 +1,34 @@
{ config, pkgs, ... }:
{
users.groups.jashton = {};
users.groups.greetd = {};
users.groups.heliotrope-backups = {};
users.users.jashton = {
isNormalUser = true;
description = "Josh Ashton";
group = "jashton";
extraGroups = [ "networkmanager" "wheel" "tss" "video" "audio" "input" ];
shell = pkgs.zsh;
};
users.users.heliotrope-backups = {
isNormalUser = true;
description = "heliotrope remote server backups.";
group = "heliotrope-backups";
shell = pkgs.bash;
};
users.users.root = {
shell = pkgs.zsh;
};
users.extraUsers.greetd = {
isSystemUser = true;
group = "greetd";
extraGroups = [ "input" ];
};
}
+79
View File
@@ -0,0 +1,79 @@
{ config, pkgs, inputs, ... }:
let
# Instantiate the unstable package set for your system architecture
unstable = import inputs.nixpkgs-unstable {
system = pkgs.system;
config.allowUnfree = true;
};
in
{
imports = [
inputs.dms.nixosModules.greeter
];
programs.niri = {
enable = true;
# Tell the Niri module to use the unstable package directly from the niri-flake
package = inputs.niri.packages.${pkgs.system}.niri-unstable;
};
programs.dsearch.enable = true;
programs.dank-material-shell.greeter = {
enable = true;
compositor.name = "niri";
configHome = "/home/jashton";
};
programs.dms-shell = {
enable = true;
enableSystemMonitoring = true;
enableVPN = true;
enableDynamicTheming = true;
enableAudioWavelength = true;
enableCalendarEvents = true;
systemd = {
enable = false;
restartIfChanged = true;
};
quickshell.package = unstable.quickshell;
plugins = {
developerUtilities.enable = true;
batteryPlus.enable = true;
mediaDownloader.enable = true;
dankBatteryAlerts.enable = true;
dmsThemeSync.enable = true;
dmsPass.enable = true;
};
};
programs.gnupg.agent = {
enable = true;
enableSSHSupport = true;
};
services = {
libinput = {
enable = true;
};
openssh = {
enable = true;
};
tailscale = {
enable = true;
};
upower.enable = true;
printing.enable = true;
gvfs.enable = true;
gnome.gnome-keyring.enable = true;
blueman.enable = true;
};
}
+17
View File
@@ -0,0 +1,17 @@
{ config, pkgs, ... }:
{
virtualisation = {
podman = {
enable = true;
dockerCompat = true;
};
waydroid.enable = true;
virtualbox.host.enable = true;
libvirtd.enable = true;
};
networking.firewall.trustedInterfaces = [ "waydroid0" ];
}