From 527bfddbc4bb4eccf5303cc4c5e05d68a0134685 Mon Sep 17 00:00:00 2001 From: Sweetbread Date: Wed, 8 Jul 2026 19:18:37 +0300 Subject: [PATCH] Inaho: new host --- disko.nix | 41 ------------- flake.nix | 5 ++ host/Inaho/README.md | 49 +++++++++++++++ host/Inaho/configuration.nix | 33 +++++++++++ host/Inaho/disko.nix | 85 +++++++++++++++++++++++++++ host/Inaho/hardware-configuration.nix | 22 +++++++ host/Inaho/modules/grub.nix | 13 ++++ host/Inaho/modules/hyprland.nix | 9 +++ host/Inaho/secrets/secrets.nix | 11 ++++ host/modules/thinkpad.nix | 83 ++++++++++++++++++++++++++ 10 files changed, 310 insertions(+), 41 deletions(-) delete mode 100644 disko.nix create mode 100644 host/Inaho/README.md create mode 100644 host/Inaho/configuration.nix create mode 100644 host/Inaho/disko.nix create mode 100644 host/Inaho/hardware-configuration.nix create mode 100644 host/Inaho/modules/grub.nix create mode 100644 host/Inaho/modules/hyprland.nix create mode 100644 host/Inaho/secrets/secrets.nix create mode 100644 host/modules/thinkpad.nix diff --git a/disko.nix b/disko.nix deleted file mode 100644 index 6046c50..0000000 --- a/disko.nix +++ /dev/null @@ -1,41 +0,0 @@ -{ - disko.devices = { - disk = { - my-disk = { - device = "/dev/sdb"; - type = "disk"; - content = { - type = "gpt"; - partitions = { - ESP = { - type = "EF00"; - size = "256M"; - content = { - type = "filesystem"; - format = "vfat"; - mountpoint = "/boot"; - }; - }; - - swap = { - size = "8G"; - content = { - type = "swap"; - resumeDevice = true; - }; - }; - - root = { - size = "100%"; - content = { - type = "filesystem"; - format = "ext4"; - mountpoint = "/"; - }; - }; - }; - }; - }; - }; - }; -} diff --git a/flake.nix b/flake.nix index 2c2192a..8f04993 100644 --- a/flake.nix +++ b/flake.nix @@ -23,6 +23,10 @@ nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable"; nixpkgs-stable.url = "github:nixos/nixpkgs/nixos-26.05"; nixpkgs-pinned.url = "github:nixos/nixpkgs/ec942ba042dad5ef097e2ef3a3effc034241f011"; + disko = { + url = "github:nix-community/disko"; + inputs.nixpkgs.follows = "nixpkgs"; + }; sops-nix.url = "github:Mic92/sops-nix"; stylix.url = "github:danth/stylix"; ags.url = "github:Aylur/ags/3ed9737bdbc8fc7a7c7ceef2165c9109f336bff6"; @@ -63,6 +67,7 @@ Senko = mkHost "Senko"; Eclipse = mkHost "Eclipse"; Impreza = mkHost "Impreza"; + Inaho = mkHost "Inaho"; }; }; } diff --git a/host/Inaho/README.md b/host/Inaho/README.md new file mode 100644 index 0000000..b218813 --- /dev/null +++ b/host/Inaho/README.md @@ -0,0 +1,49 @@ +ThinkPad T480 + +CPU: Intel i5-8350U +RAM: 16GB planned (8GB stock + 8GB SO-DIMM) +SSD: 256GB NVMe stock; disko assumes `/dev/nvme0n1` + +## Installation notes + +This host uses `disko` with GPT + unencrypted EFI System Partition + LUKS + Btrfs subvolumes. + +Before formatting, verify the target disk: + +```bash +lsblk +``` + +If the internal drive is not `/dev/nvme0n1`, edit `host/Inaho/disko.nix` first. +For a 2.5" SATA SSD/HDD it will usually be `/dev/sda`. + +Then partition, format and mount: + +```bash +sudo nix --experimental-features "nix-command flakes" run github:nix-community/disko/latest -- \ + --mode destroy,format,mount ./host/Inaho/disko.nix +``` + +This destroys the selected disk. + +After that install the host: + +```bash +sudo nixos-install --flake .#Inaho +``` + +The flake contains a new `disko` input. If `flake.lock` has not been updated yet, run: + +```bash +nix flake lock --update-input disko +``` + +## After first boot + +Update firmware, especially BIOS/UEFI and Thunderbolt, when batteries are installed and charged: + +```bash +sudo fwupdmgr refresh +sudo fwupdmgr get-updates +sudo fwupdmgr update +``` diff --git a/host/Inaho/configuration.nix b/host/Inaho/configuration.nix new file mode 100644 index 0000000..311e227 --- /dev/null +++ b/host/Inaho/configuration.nix @@ -0,0 +1,33 @@ +{ config, pkgs, pkgs-stable, pkgs-pinned, lib, inputs, ... }: { + imports = [ + inputs.disko.nixosModules.disko + ./disko.nix + ./secrets/secrets.nix + ./modules/grub.nix + ../modules/thinkpad.nix + ../modules/gpu/intel.nix + + (import ../modules/common.nix { + inherit lib; + inherit inputs; + hostname = "Inaho"; + }) + + (import ../../user/common.nix { + inherit config; + inherit pkgs; + inherit pkgs-stable; + inherit pkgs-pinned; + inherit lib; + inherit inputs; + name = "sweetbread"; + fullname = "Sweet Bread"; + }) + ]; + + hardware.bluetooth.enable = true; + host.laptop = true; + + programs.adb.enable = true; + users.users.sweetbread.extraGroups = [ "adbusers" "kvm" ]; +} diff --git a/host/Inaho/disko.nix b/host/Inaho/disko.nix new file mode 100644 index 0000000..5d55c25 --- /dev/null +++ b/host/Inaho/disko.nix @@ -0,0 +1,85 @@ +{ lib, ... }: + +let + # Verify with `lsblk` before running disko. For the stock T480 NVMe setup + # this is usually correct; for a 2.5" SATA SSD/HDD change it to /dev/sda. + disk = "/dev/nvme0n1"; + + btrfsMountOptions = [ + "compress=zstd" + "noatime" + "ssd" + "discard=async" + ]; +in { + disko.devices = { + disk = { + main = { + type = "disk"; + device = disk; + content = { + type = "gpt"; + partitions = { + ESP = { + priority = 1; + name = "ESP"; + start = "1M"; + size = "512M"; + type = "EF00"; + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + mountOptions = [ "umask=0077" ]; + }; + }; + + luks = { + priority = 2; + name = "cryptsystem"; + size = "100%"; + content = { + type = "luks"; + name = "crypted"; + settings = { + # Allows fstrim/discard through LUKS for SSDs. + allowDiscards = true; + }; + content = { + type = "btrfs"; + extraArgs = [ "-f" "-L" "NixOS" ]; + subvolumes = { + "/root" = { + mountpoint = "/"; + mountOptions = btrfsMountOptions; + }; + + "/home" = { + mountpoint = "/home"; + mountOptions = btrfsMountOptions; + }; + + "/nix" = { + mountpoint = "/nix"; + mountOptions = btrfsMountOptions; + }; + + "/log" = { + mountpoint = "/var/log"; + mountOptions = btrfsMountOptions; + }; + + "/swap" = { + mountpoint = "/.swapvol"; + swap.swapfile.size = "16G"; + }; + }; + }; + }; + }; + }; + }; + }; + }; + }; +} diff --git a/host/Inaho/hardware-configuration.nix b/host/Inaho/hardware-configuration.nix new file mode 100644 index 0000000..1d4670f --- /dev/null +++ b/host/Inaho/hardware-configuration.nix @@ -0,0 +1,22 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = [ (modulesPath + "/installer/scan/not-detected.nix") ]; + + # File systems and swap are declared in ./disko.nix. + # If you regenerate this file after installation, use: + # nixos-generate-config --no-filesystems --root /mnt + + boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "nvme" "usb_storage" "usbhid" "sd_mod" "rtsx_pci_sdmmc" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" "thinkpad_acpi" ]; + boot.extraModulePackages = [ ]; + + networking.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/host/Inaho/modules/grub.nix b/host/Inaho/modules/grub.nix new file mode 100644 index 0000000..a101564 --- /dev/null +++ b/host/Inaho/modules/grub.nix @@ -0,0 +1,13 @@ +{ pkgs, ... }: let + theme = pkgs.fetchFromGitHub { + owner = "Patato777"; + repo = "dotfiles"; + rev = "cc363921707807d7ad3e36b462f0df793a0fe18a"; + hash = "sha256-fpXGFNrzbV6K9hoZRX4tGieTLzhpPeGm6wn8CF4OGow="; + }; +in { + boot.loader.grub = { + gfxmodeEfi = "1920x1080"; + theme = "${theme}/grub/themes/virtuaverse"; + }; +} diff --git a/host/Inaho/modules/hyprland.nix b/host/Inaho/modules/hyprland.nix new file mode 100644 index 0000000..a74ec69 --- /dev/null +++ b/host/Inaho/modules/hyprland.nix @@ -0,0 +1,9 @@ +{ + wayland.windowManager.hyprland = { + settings = { + monitor = [ + "eDP-1, 1920x1080@60, 0x0, 1" + ]; + }; + }; +} \ No newline at end of file diff --git a/host/Inaho/secrets/secrets.nix b/host/Inaho/secrets/secrets.nix new file mode 100644 index 0000000..0eeb702 --- /dev/null +++ b/host/Inaho/secrets/secrets.nix @@ -0,0 +1,11 @@ +{ + sops = { + age.keyFile = "/root/age.key"; + secrets = { + vpn_bolt = { + format = "binary"; + sopsFile = ../../Rias/secrets/vpn_bolt.db; + }; + }; + }; +} diff --git a/host/modules/thinkpad.nix b/host/modules/thinkpad.nix new file mode 100644 index 0000000..f39ba52 --- /dev/null +++ b/host/modules/thinkpad.nix @@ -0,0 +1,83 @@ +{ config, lib, pkgs, ... }: { + # T480-specific hardware defaults. + hardware = { + enableRedistributableFirmware = true; + + trackpoint = { + enable = true; + emulateWheel = true; + }; + }; + + boot = { + supportedFilesystems = [ "btrfs" ]; + + initrd.availableKernelModules = [ + "nvme" + "ahci" + "xhci_pci" + "usb_storage" + "usbhid" + "sd_mod" + "rtsx_pci_sdmmc" + ]; + + kernelModules = [ "kvm-intel" "thinkpad_acpi" ]; + + kernelParams = [ + # Prefer S3/deep sleep when BIOS exposes it. If suspend behaves worse, + # remove this and use the BIOS sleep setting instead. + "mem_sleep_default=deep" + ]; + }; + + powerManagement.enable = true; + services = { + # Firmware updates for BIOS/UEFI, Thunderbolt, SSDs where LVFS supports it. + fwupd.enable = true; + + # Helps Intel laptops keep sane thermal behaviour under load. + thermald.enable = true; + + # Fingerprint reader support. If fprintd does not detect the reader, + # leaving this enabled is harmless; login can still use a password. + fprintd.enable = true; + + logind = { + lidSwitch = "suspend"; + lidSwitchExternalPower = "suspend"; + powerKey = "poweroff"; + }; + + tlp.settings = { + # Preserve batteries when the laptop is usually on AC. + # Raise STOP_* to 100 if maximum autonomy matters more than battery wear. + START_CHARGE_THRESH_BAT0 = 70; + STOP_CHARGE_THRESH_BAT0 = 85; + START_CHARGE_THRESH_BAT1 = 70; + STOP_CHARGE_THRESH_BAT1 = 85; + RESTORE_THRESHOLDS_ON_BAT = 1; + + # NVMe/SATA SSD power saving without making the system too sluggish. + AHCI_RUNTIME_PM_ON_AC = "on"; + AHCI_RUNTIME_PM_ON_BAT = "auto"; + SATA_LINKPWR_ON_AC = "med_power_with_dipm"; + SATA_LINKPWR_ON_BAT = "med_power_with_dipm"; + + # Usually safe on ThinkPads; disable if some USB device randomly disconnects. + USB_AUTOSUSPEND = 1; + }; + }; + + networking.networkmanager.wifi.powersave = true; + + environment.systemPackages = with pkgs; [ + acpi + lm_sensors + pciutils + powertop + smartmontools + usbutils + nvme-cli + ]; +}