# Edit this configuration file to define what should be installed on # your system. Help is available in the configuration.nix(5) man page # and in the NixOS manual (accessible by running ‘nixos-help’). { config, pkgs, ... }: { imports = [ # Include the results of the hardware scan. ./cube-hardware-configuration.nix ]; # Bootloader. boot.loader.systemd-boot.enable = false; boot.loader.grub = { enable = true; device = "nodev"; efiSupport = true; useOSProber = true; }; boot.loader.efi.canTouchEfiVariables = true; nix.settings.experimental-features = [ "nix-command" "flakes" ]; networking.hostName = "cube"; # Define your hostname. # networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. # Configure network proxy if necessary # networking.proxy.default = "http://user:password@proxy:port/"; # networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain"; # Enable networking networking.networkmanager.enable = true; # Set your time zone. time.timeZone = "Europe/Berlin"; # Select internationalisation properties. i18n.defaultLocale = "en_US.UTF-8"; i18n.extraLocaleSettings = { LC_ADDRESS = "de_DE.UTF-8"; LC_IDENTIFICATION = "de_DE.UTF-8"; LC_MEASUREMENT = "de_DE.UTF-8"; LC_MONETARY = "de_DE.UTF-8"; LC_NAME = "de_DE.UTF-8"; LC_NUMERIC = "de_DE.UTF-8"; LC_PAPER = "de_DE.UTF-8"; LC_TELEPHONE = "de_DE.UTF-8"; LC_TIME = "de_DE.UTF-8"; }; security = { pam.services.swaylock = {}; polkit.enable = true; rtkit.enable = true; }; services.envfs.enable = true; services.flatpak.enable = true; services.fwupd.enable = true; services.openssh.enable = true; services.pipewire = { enable = true; alsa.enable = true; alsa.support32Bit = true; pulse.enable = true; # If you want to use JACK applications, uncomment this #jack.enable = true; }; services.plex = { enable = true; dataDir = "/var/lib/plex"; openFirewall = true; user = "plex"; group = "plex"; }; services.tailscale = { enable = true; authKeyFile = config.sops.secrets.tailscale_auth_key.path; }; # Configure keymap in X11 services.xserver = { xkb.layout = "eu"; xkb.options = "compose:ralt"; }; sops.defaultSopsFile = ../secrets/secrets.yaml; sops.age.keyFile = "/home/muhh/.config/sops/age/keys.txt"; sops.secrets.tailscale_auth_key = {}; # Define a user account. Don't forget to set a password with ‘passwd’. users.users.muhh = { isNormalUser = true; name = "muhh"; description = "Markus Heurung"; extraGroups = [ "libvirtd" "qemu-libvirtd" "audio" "input" "networkmanager" "video" "wheel" ]; shell = pkgs.fish; linger = true; }; # Allow unfree packages nixpkgs.config.allowUnfree = true; nixpkgs.config.allowUnfreePredicate = pkg: true; environment.shells = with pkgs; [ bash fish zsh ]; # List packages installed in system profile. To search, run: # $ nix search wget environment.systemPackages = with pkgs; [ git home-manager toolbox vim wget ]; fonts.packages = with pkgs; [ atkinson-hyperlegible iosevka ]; # Some programs need SUID wrappers, can be configured further or are # started in user sessions. # programs.mtr.enable = true; programs = { fish.enable = true; gnupg.agent = { enable = true; enableSSHSupport = true; }; light = { enable = true; brightnessKeys.enable = true; }; sway.enable = true; }; virtualisation = { libvirtd = { enable = true; }; podman = { enable = true; dockerCompat = true; }; }; xdg = { portal = { enable = true; extraPortals = with pkgs; [ xdg-desktop-portal-wlr xdg-desktop-portal-gtk ]; }; }; # Enable the OpenSSH daemon. # services.openssh.enable = true; # Open ports in the firewall. # FIREWALL IS ENABLED BY DEFAULT - muhh # networking.firewall.allowedTCPPorts = [ ... ]; # networking.firewall.allowedUDPPorts = [ ... ]; # Or disable the firewall altogether. # networking.firewall.enable = false; # This value determines the NixOS release from which the default # settings for stateful data, like file locations and database versions # on your system were taken. It‘s perfectly fine and recommended to leave # this value at the release version of the first install of this system. # Before changing this value read the documentation for this option # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). system.stateVersion = "23.11"; # Did you read the comment? }