{ config, pkgs, ... }: { imports = [ ./cube-hardware-configuration.nix ./common.nix ]; # Bootloader. boot.loader.systemd-boot.enable = false; boot.loader.grub = { enable = true; device = "nodev"; efiSupport = true; useOSProber = true; }; boot.loader.efi.canTouchEfiVariables = true; networking.hostName = "cube"; # Define your hostname. # networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. # Configure network proxy if necessary # networking.proxy.default = "http://user:password@proxy:port/"; # networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain"; # Enable networking networking.networkmanager.enable = true; networking.hosts = { # "178.63.121.197" = ["www.boell.de"]; "127.0.0.1" = ["muhh.local"]; }; # Workaround for broken networkmanager/systemd thing # https://github.com/NixOS/nixpkgs/issues/180175#issuecomment-1658731959 systemd.services.NetworkManager-wait-online = { serviceConfig = { ExecStart = [ "" "${pkgs.networkmanager}/bin/nm-online -q" ]; }; }; security = { pam.services.swaylock = {}; polkit.enable = true; rtkit.enable = true; sudo = { wheelNeedsPassword = true; }; }; services.envfs.enable = true; services.flatpak.enable = true; services.fwupd.enable = true; services.openssh.enable = true; services.pipewire = { enable = true; alsa.enable = true; alsa.support32Bit = true; pulse.enable = true; wireplumber.enable = true; # If you want to use JACK applications, uncomment this # jack.enable = true; }; services.plex = { enable = true; dataDir = "/var/lib/plex"; openFirewall = true; user = "plex"; group = "plex"; }; services.tailscale = { enable = true; authKeyFile = config.sops.secrets.tailscale_auth_key.path; }; # Configure keymap in X11 services.xserver = { xkb.layout = "eu"; xkb.options = "compose:ralt"; }; sops.defaultSopsFile = ../secrets/secrets.yaml; sops.age.keyFile = "/home/muhh/.config/sops/age/keys.txt"; sops.secrets.tailscale_auth_key = {}; # Define a user account. Don't forget to set a password with ‘passwd’. users.users.muhh = { isNormalUser = true; name = "muhh"; description = "Markus Heurung"; extraGroups = [ "audio" "docker" "libvirtd" "input" "networkmanager" "plugdev" "qemu-libvirtd" "video" "wheel"]; shell = pkgs.fish; linger = true; }; nixpkgs.config = { allowUnfree = true; allowUnfreePredicate = pkg: true; }; environment.shells = with pkgs; [ bash fish zsh ]; environment.systemPackages = with pkgs; [ git home-manager toolbox vim wget ]; fonts.packages = with pkgs; [ atkinson-hyperlegible iosevka # secret-config.packages.x86_64-linux.default ]; programs = { _1password.enable = true; _1password-gui = { enable = true; polkitPolicyOwners = ["muhh"]; }; fish.enable = true; gnupg.agent = { enable = true; enableSSHSupport = true; }; light = { enable = true; brightnessKeys.enable = true; }; hyprland.enable = true; niri.enable = true; sway.enable = true; # ssh = { # pubkeyAcceptedKeyTypes = ["ssh-ed25519" "ssh-rsa"]; # hostKeyAlgorithms = ["ssh-ed25519" "ssh-rsa"]; # }; }; virtualisation = { docker.enable = true; libvirtd = { enable = true; }; podman = { enable = false; dockerCompat = true; }; }; xdg = { portal = { enable = true; extraPortals = with pkgs; [ xdg-desktop-portal-wlr xdg-desktop-portal-gtk ]; }; }; # Enable the OpenSSH daemon. # services.openssh.enable = true; # Open ports in the firewall. # FIREWALL IS ENABLED BY DEFAULT - muhh # networking.firewall.allowedTCPPorts = [ ... ]; # networking.firewall.allowedUDPPorts = [ ... ]; # Or disable the firewall altogether. # networking.firewall.enable = false; # This value determines the NixOS release from which the default # settings for stateful data, like file locations and database versions # on your system were taken. It‘s perfectly fine and recommended to leave # this value at the release version of the first install of this system. # Before changing this value read the documentation for this option # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). system.stateVersion = "23.11"; # Did you read the comment? }