Inaho: new host
This commit is contained in:
@@ -0,0 +1,49 @@
|
||||
ThinkPad T480
|
||||
|
||||
CPU: Intel i5-8350U
|
||||
RAM: 16GB planned (8GB stock + 8GB SO-DIMM)
|
||||
SSD: 256GB NVMe stock; disko assumes `/dev/nvme0n1`
|
||||
|
||||
## Installation notes
|
||||
|
||||
This host uses `disko` with GPT + unencrypted EFI System Partition + LUKS + Btrfs subvolumes.
|
||||
|
||||
Before formatting, verify the target disk:
|
||||
|
||||
```bash
|
||||
lsblk
|
||||
```
|
||||
|
||||
If the internal drive is not `/dev/nvme0n1`, edit `host/Inaho/disko.nix` first.
|
||||
For a 2.5" SATA SSD/HDD it will usually be `/dev/sda`.
|
||||
|
||||
Then partition, format and mount:
|
||||
|
||||
```bash
|
||||
sudo nix --experimental-features "nix-command flakes" run github:nix-community/disko/latest -- \
|
||||
--mode destroy,format,mount ./host/Inaho/disko.nix
|
||||
```
|
||||
|
||||
This destroys the selected disk.
|
||||
|
||||
After that install the host:
|
||||
|
||||
```bash
|
||||
sudo nixos-install --flake .#Inaho
|
||||
```
|
||||
|
||||
The flake contains a new `disko` input. If `flake.lock` has not been updated yet, run:
|
||||
|
||||
```bash
|
||||
nix flake lock --update-input disko
|
||||
```
|
||||
|
||||
## After first boot
|
||||
|
||||
Update firmware, especially BIOS/UEFI and Thunderbolt, when batteries are installed and charged:
|
||||
|
||||
```bash
|
||||
sudo fwupdmgr refresh
|
||||
sudo fwupdmgr get-updates
|
||||
sudo fwupdmgr update
|
||||
```
|
||||
@@ -0,0 +1,34 @@
|
||||
{ config, pkgs, pkgs-stable, pkgs-pinned, lib, inputs, ... }: {
|
||||
imports = [
|
||||
inputs.disko.nixosModules.disko
|
||||
./disko.nix
|
||||
./secrets/secrets.nix
|
||||
./modules/grub.nix
|
||||
./modules/syncthing.nix
|
||||
../modules/thinkpad.nix
|
||||
../modules/gpu/intel.nix
|
||||
|
||||
(import ../modules/common.nix {
|
||||
inherit lib;
|
||||
inherit inputs;
|
||||
hostname = "Inaho";
|
||||
})
|
||||
|
||||
(import ../../user/common.nix {
|
||||
inherit config;
|
||||
inherit pkgs;
|
||||
inherit pkgs-stable;
|
||||
inherit pkgs-pinned;
|
||||
inherit lib;
|
||||
inherit inputs;
|
||||
name = "sweetbread";
|
||||
fullname = "Sweet Bread";
|
||||
})
|
||||
];
|
||||
|
||||
hardware.bluetooth.enable = true;
|
||||
host.laptop = true;
|
||||
|
||||
hardware.usb-modeswitch.enable = true;
|
||||
networking.modemmanager.enable = true;
|
||||
}
|
||||
@@ -0,0 +1,85 @@
|
||||
{ lib, ... }:
|
||||
|
||||
let
|
||||
# Verify with `lsblk` before running disko. For the stock T480 NVMe setup
|
||||
# this is usually correct; for a 2.5" SATA SSD/HDD change it to /dev/sda.
|
||||
disk = "/dev/sda";
|
||||
|
||||
btrfsMountOptions = [
|
||||
"compress=zstd"
|
||||
"noatime"
|
||||
"ssd"
|
||||
"discard=async"
|
||||
];
|
||||
in {
|
||||
disko.devices = {
|
||||
disk = {
|
||||
main = {
|
||||
type = "disk";
|
||||
device = disk;
|
||||
content = {
|
||||
type = "gpt";
|
||||
partitions = {
|
||||
ESP = {
|
||||
priority = 1;
|
||||
name = "ESP";
|
||||
start = "1M";
|
||||
size = "512M";
|
||||
type = "EF00";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "vfat";
|
||||
mountpoint = "/boot";
|
||||
mountOptions = [ "umask=0077" ];
|
||||
};
|
||||
};
|
||||
|
||||
luks = {
|
||||
priority = 2;
|
||||
name = "cryptsystem";
|
||||
size = "100%";
|
||||
content = {
|
||||
type = "luks";
|
||||
name = "crypted";
|
||||
settings = {
|
||||
# Allows fstrim/discard through LUKS for SSDs.
|
||||
allowDiscards = true;
|
||||
};
|
||||
content = {
|
||||
type = "btrfs";
|
||||
extraArgs = [ "-f" "-L" "NixOS" ];
|
||||
subvolumes = {
|
||||
"/root" = {
|
||||
mountpoint = "/";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"/home" = {
|
||||
mountpoint = "/home";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"/nix" = {
|
||||
mountpoint = "/nix";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"/log" = {
|
||||
mountpoint = "/var/log";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"/swap" = {
|
||||
mountpoint = "/.swapvol";
|
||||
swap.swapfile.size = "16G";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{ config, lib, pkgs, modulesPath, ... }:
|
||||
|
||||
{
|
||||
imports = [ (modulesPath + "/installer/scan/not-detected.nix") ];
|
||||
|
||||
# File systems and swap are declared in ./disko.nix.
|
||||
# If you regenerate this file after installation, use:
|
||||
# nixos-generate-config --no-filesystems --root /mnt
|
||||
|
||||
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "nvme" "usb_storage" "usbhid" "sd_mod" "rtsx_pci_sdmmc" ];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ "kvm-intel" "thinkpad_acpi" ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
networking.useDHCP = lib.mkDefault true;
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
{ pkgs, ... }: let
|
||||
theme = pkgs.fetchFromGitHub {
|
||||
owner = "Patato777";
|
||||
repo = "dotfiles";
|
||||
rev = "cc363921707807d7ad3e36b462f0df793a0fe18a";
|
||||
hash = "sha256-fpXGFNrzbV6K9hoZRX4tGieTLzhpPeGm6wn8CF4OGow=";
|
||||
};
|
||||
in {
|
||||
boot.loader.grub = {
|
||||
gfxmodeEfi = "1920x1080";
|
||||
theme = "${theme}/grub/themes/virtuaverse";
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
{
|
||||
wayland.windowManager.hyprland = {
|
||||
settings = {
|
||||
monitor = [
|
||||
"eDP-1, 1920x1080@60, 0x0, 1"
|
||||
];
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,34 @@
|
||||
{ config, ... }: {
|
||||
services.syncthing = {
|
||||
enable = true;
|
||||
openDefaultPorts = true;
|
||||
|
||||
user = "sweetbread";
|
||||
dataDir = "/home/sweetbread/.config/syncthing";
|
||||
|
||||
key = config.sops.secrets.syncthing_key.path;
|
||||
cert = config.sops.secrets.syncthing_cert.path;
|
||||
|
||||
settings = {
|
||||
devices = {
|
||||
Rias.id = "EC5AGVN-2RKJDHN-NOSB7PQ-IRYCEEW-NPPDUGX-6QGSLUU-YIT5ZZZ-RVPTHQ6";
|
||||
Akeno.id = "QDW3WJX-J7ETS4R-32CUAIY-EGNM2RD-ZEHOUW2-CHOEOUG-USZOWTR-HHQS2QX";
|
||||
Koneko.id = "PJFWQRY-ZFUBGDR-NV7KVBL-UBDQ4HT-KPTYP34-MUDFPJU-4EZUHTT-ZLYRMAB";
|
||||
};
|
||||
|
||||
folders = {
|
||||
"Music" = {
|
||||
path = "/home/sweetbread/Music";
|
||||
devices = [ "Rias" "Akeno" "Koneko" ];
|
||||
};
|
||||
|
||||
"Obsidian" = {
|
||||
path = "/home/sweetbread/Documents/Obsidian";
|
||||
devices = [ "Rias" "Akeno" "Koneko" ];
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
systemd.services.syncthing.environment.STNODEFAULTFOLDER = "true";
|
||||
}
|
||||
@@ -0,0 +1,20 @@
|
||||
{
|
||||
sops = {
|
||||
age.keyFile = "/root/age.key";
|
||||
secrets = {
|
||||
vpn_bolt = {
|
||||
format = "binary";
|
||||
sopsFile = ../../Rias/secrets/vpn_bolt.db;
|
||||
};
|
||||
|
||||
syncthing_cert = {
|
||||
format = "binary";
|
||||
sopsFile = ./syncthing_cert.pem;
|
||||
};
|
||||
syncthing_key = {
|
||||
format = "binary";
|
||||
sopsFile = ./syncthing_key.pem;
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"data": "ENC[AES256_GCM,data:rMr83F9VyGV5dp2XqXGAh3X2sCczUb0chH/2Hn9N9tijfRsOLGqHuy/zy29aOHR0PJ4euTU3bhmxWrBV/7oTnnEfI7DFF0vX4eBDaK8BzwAzrzXHYJOAgcwuYSqEEyWiLvTGABuLhTEto9kIMLxVIssa679s7zQSRwemVJSA3fEdtYD0BLAiO/ZtiAEmitgEt4EBRp9DhJPqlh2YfMmP6DpkDSy0hk+S+0NZg7eyrp7fivldiLzjsYDwCsugFcZQtWOqLMHY0kYhou8c2CKXu8UyqVVx24DyWfBfD1TH2pOk1ZsXFsxhFFKp5wcsfi0xDF1BG4hANcHVa6pR6y5JxNzh53xaH3NuvNJFEQSGJw5fNMuCrDnkYLDpU3xezzjvvxI01y7i2A00zsLli1fc9HA67ZlP1OBzsI7FyMgZlnOXQpbqnkj+kZdYAdOTjjMzQvrPusVS3RvqvcWj1qZtnHa1ZGmWh7xG0J10lQB4uDmTSxWoUUi7VmLXTC16HQNMySd8GbFmD/4Nj+/SxDShgsiug7L4hICjPC8Isosy99tE2wRXpjmMYUdlD7zu/vyEMxVPhkWnJyZZPXG+DjGBc/Diaw4ufYNxUs4yIRDceMArirubt/sN/eUoGOBGVWxvGm0/olTott7Yr+YKRSrDyWo9SWCz1qgz/ydpXm+xE7bPtbj9eAObZwneB/0tZTyo8o1WKd9yUST89m91EMQ31R97yCBwDW19VftWVCZH2w+QHNunih4ZUNiALQS745T2petbvc63iNiZswu0l3qoVM8x3y1RhAPLbsZpwQWSca307iDfBTB6uVW4HwLtL30=,iv:ajC3mjCYKUqS7XGIN64NiJoG6wHMvGdcHhazSO860ms=,tag:31fWG7m2neW2Pft9TjmBGg==,type:str]",
|
||||
"sops": {
|
||||
"age": [
|
||||
{
|
||||
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBuQUNTSDVIeDRuMmtTWXZD\nU0x4OVJrUStFeW5QV0pOZ2hEZnJZQ09UbW5RCmwxbjhuWis1Q3BCTGtOdS8zNE0w\nL0pDK3dBY1hxZ2dCNG96RlA0dkNWVWMKLS0tIHFld2hUdm11dk5hT2ZtRXpId0VG\nRDM0L05jS0lGcnJBYWVNWElIazdlaUEKugvBGcCzYTZL6aC6mI6GCzhiPFYql75z\nSBfalDmqSVU2k1IBqsNHIYSxzOXwUiGS3MSHJUCf7M2y9X3dHJGeyw==\n-----END AGE ENCRYPTED FILE-----\n",
|
||||
"recipient": "age1j3uuyax673fvl5x4dveupq3dylngnrq0e5uy7fmclsexkfd25vysk646wk"
|
||||
}
|
||||
],
|
||||
"lastmodified": "2026-07-21T20:27:59Z",
|
||||
"mac": "ENC[AES256_GCM,data:lYZH1f3TyvcgqWI9hVOP3l2xImRh+LL0volXVUYSdGBnQTsAJfzMdsol/SsETwNNn+KrANC3ucO0/MXOWDK7ZPJ5Oq9R+OQnM8LK9/5mNfbzgodTw0RaH8FsrrtBCtHn3H2rlrBoPFEArblWKOh0G9iyrmufT09OREGt/G0tE5o=,iv:vmB1CY3sVajvLS8zAS/0I+NgnAOStbUkzQdw6XY45y4=,tag:mZP/eZVn+DJq+OT1ghtOkQ==,type:str]",
|
||||
"version": "3.13.2"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"data": "ENC[AES256_GCM,data:2nMwCxU1y0zE5VtnmEf3lT4XyI9e8dokPkipo3TXpxuRJZ9OXCOb0n4pHb4Xx9OlDgAeW2UX70cR1Wtj7QPQx9h/HYZTmUeIP4rvlTPhaxs/2F33ud1lPKceV2DK2q8G/EvPLnlCcLWMvy6BVsqBlNmjAzNonWI=,iv:7H0o0i3zp7K2demt1O2Pw4BNt+2q4PhHBw1K/jC7OH4=,tag:Bx82eo5kQqwlb6egYmopgQ==,type:str]",
|
||||
"sops": {
|
||||
"age": [
|
||||
{
|
||||
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA2Vzl3M3pFblY5SmRQRUtI\nNWFCbWZJQTJTOWFHdTd1YkJEbXFGOFhBTUNNClBKdWhGdmh3Q2dUNkpMUUU3Zmdq\nUFd1M2twNW1KRGErRHUvc1BLY2pMT3MKLS0tIElVZ0RVVFQrb1FuYnJ0OU44RWZK\nbnpJZnFLR3kzV3VRaytQRDMrYkg5S2sKkr97EwJmtcIsRYH4di+tadTWnWzuCDa9\ngY+CKCVEPUgD1AXSgCwCP2AVd/zaKUbm6d6UA2QzZyqGsRim56WFsQ==\n-----END AGE ENCRYPTED FILE-----\n",
|
||||
"recipient": "age1j3uuyax673fvl5x4dveupq3dylngnrq0e5uy7fmclsexkfd25vysk646wk"
|
||||
}
|
||||
],
|
||||
"lastmodified": "2026-07-21T20:28:23Z",
|
||||
"mac": "ENC[AES256_GCM,data:ohYjzIYDilW7lsmZFZXpF629yevO2p8laA7Zl0+NCvZ8dB4nthLUePsnLTYCrEo5ADbboM5Cka11FiYbmB1IMR4mEdRwTN37EsQtyYLZbZ+j4XPsuXO0UT0NmWWiFNJlQEWfTVbhaZRDQXcPpVvm+6qQfRub018/0C59oWpmbyA=,iv:SX1QDDUWZyxE0zODAImcGGHJI7KGKYx9/6Q9F+9SVCQ=,tag:AExTZIfAKTCeU9c3Qj+IUw==,type:str]",
|
||||
"version": "3.13.2"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user