Inaho: new host
This commit is contained in:
@@ -1,41 +0,0 @@
|
|||||||
{
|
|
||||||
disko.devices = {
|
|
||||||
disk = {
|
|
||||||
my-disk = {
|
|
||||||
device = "/dev/sdb";
|
|
||||||
type = "disk";
|
|
||||||
content = {
|
|
||||||
type = "gpt";
|
|
||||||
partitions = {
|
|
||||||
ESP = {
|
|
||||||
type = "EF00";
|
|
||||||
size = "256M";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "vfat";
|
|
||||||
mountpoint = "/boot";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
swap = {
|
|
||||||
size = "8G";
|
|
||||||
content = {
|
|
||||||
type = "swap";
|
|
||||||
resumeDevice = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
root = {
|
|
||||||
size = "100%";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "ext4";
|
|
||||||
mountpoint = "/";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -23,6 +23,10 @@
|
|||||||
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
|
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
|
||||||
nixpkgs-stable.url = "github:nixos/nixpkgs/nixos-26.05";
|
nixpkgs-stable.url = "github:nixos/nixpkgs/nixos-26.05";
|
||||||
nixpkgs-pinned.url = "github:nixos/nixpkgs/ec942ba042dad5ef097e2ef3a3effc034241f011";
|
nixpkgs-pinned.url = "github:nixos/nixpkgs/ec942ba042dad5ef097e2ef3a3effc034241f011";
|
||||||
|
disko = {
|
||||||
|
url = "github:nix-community/disko";
|
||||||
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
};
|
||||||
sops-nix.url = "github:Mic92/sops-nix";
|
sops-nix.url = "github:Mic92/sops-nix";
|
||||||
stylix.url = "github:danth/stylix";
|
stylix.url = "github:danth/stylix";
|
||||||
ags.url = "github:Aylur/ags/3ed9737bdbc8fc7a7c7ceef2165c9109f336bff6";
|
ags.url = "github:Aylur/ags/3ed9737bdbc8fc7a7c7ceef2165c9109f336bff6";
|
||||||
@@ -63,6 +67,7 @@
|
|||||||
Senko = mkHost "Senko";
|
Senko = mkHost "Senko";
|
||||||
Eclipse = mkHost "Eclipse";
|
Eclipse = mkHost "Eclipse";
|
||||||
Impreza = mkHost "Impreza";
|
Impreza = mkHost "Impreza";
|
||||||
|
Inaho = mkHost "Inaho";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,49 @@
|
|||||||
|
ThinkPad T480
|
||||||
|
|
||||||
|
CPU: Intel i5-8350U
|
||||||
|
RAM: 16GB planned (8GB stock + 8GB SO-DIMM)
|
||||||
|
SSD: 256GB NVMe stock; disko assumes `/dev/nvme0n1`
|
||||||
|
|
||||||
|
## Installation notes
|
||||||
|
|
||||||
|
This host uses `disko` with GPT + unencrypted EFI System Partition + LUKS + Btrfs subvolumes.
|
||||||
|
|
||||||
|
Before formatting, verify the target disk:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
lsblk
|
||||||
|
```
|
||||||
|
|
||||||
|
If the internal drive is not `/dev/nvme0n1`, edit `host/Inaho/disko.nix` first.
|
||||||
|
For a 2.5" SATA SSD/HDD it will usually be `/dev/sda`.
|
||||||
|
|
||||||
|
Then partition, format and mount:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo nix --experimental-features "nix-command flakes" run github:nix-community/disko/latest -- \
|
||||||
|
--mode destroy,format,mount ./host/Inaho/disko.nix
|
||||||
|
```
|
||||||
|
|
||||||
|
This destroys the selected disk.
|
||||||
|
|
||||||
|
After that install the host:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo nixos-install --flake .#Inaho
|
||||||
|
```
|
||||||
|
|
||||||
|
The flake contains a new `disko` input. If `flake.lock` has not been updated yet, run:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nix flake lock --update-input disko
|
||||||
|
```
|
||||||
|
|
||||||
|
## After first boot
|
||||||
|
|
||||||
|
Update firmware, especially BIOS/UEFI and Thunderbolt, when batteries are installed and charged:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo fwupdmgr refresh
|
||||||
|
sudo fwupdmgr get-updates
|
||||||
|
sudo fwupdmgr update
|
||||||
|
```
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
{ config, pkgs, pkgs-stable, pkgs-pinned, lib, inputs, ... }: {
|
||||||
|
imports = [
|
||||||
|
inputs.disko.nixosModules.disko
|
||||||
|
./disko.nix
|
||||||
|
./secrets/secrets.nix
|
||||||
|
./modules/grub.nix
|
||||||
|
../modules/thinkpad.nix
|
||||||
|
../modules/gpu/intel.nix
|
||||||
|
|
||||||
|
(import ../modules/common.nix {
|
||||||
|
inherit lib;
|
||||||
|
inherit inputs;
|
||||||
|
hostname = "Inaho";
|
||||||
|
})
|
||||||
|
|
||||||
|
(import ../../user/common.nix {
|
||||||
|
inherit config;
|
||||||
|
inherit pkgs;
|
||||||
|
inherit pkgs-stable;
|
||||||
|
inherit pkgs-pinned;
|
||||||
|
inherit lib;
|
||||||
|
inherit inputs;
|
||||||
|
name = "sweetbread";
|
||||||
|
fullname = "Sweet Bread";
|
||||||
|
})
|
||||||
|
];
|
||||||
|
|
||||||
|
hardware.bluetooth.enable = true;
|
||||||
|
host.laptop = true;
|
||||||
|
|
||||||
|
programs.adb.enable = true;
|
||||||
|
users.users.sweetbread.extraGroups = [ "adbusers" "kvm" ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,85 @@
|
|||||||
|
{ lib, ... }:
|
||||||
|
|
||||||
|
let
|
||||||
|
# Verify with `lsblk` before running disko. For the stock T480 NVMe setup
|
||||||
|
# this is usually correct; for a 2.5" SATA SSD/HDD change it to /dev/sda.
|
||||||
|
disk = "/dev/nvme0n1";
|
||||||
|
|
||||||
|
btrfsMountOptions = [
|
||||||
|
"compress=zstd"
|
||||||
|
"noatime"
|
||||||
|
"ssd"
|
||||||
|
"discard=async"
|
||||||
|
];
|
||||||
|
in {
|
||||||
|
disko.devices = {
|
||||||
|
disk = {
|
||||||
|
main = {
|
||||||
|
type = "disk";
|
||||||
|
device = disk;
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
ESP = {
|
||||||
|
priority = 1;
|
||||||
|
name = "ESP";
|
||||||
|
start = "1M";
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
mountOptions = [ "umask=0077" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
luks = {
|
||||||
|
priority = 2;
|
||||||
|
name = "cryptsystem";
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "luks";
|
||||||
|
name = "crypted";
|
||||||
|
settings = {
|
||||||
|
# Allows fstrim/discard through LUKS for SSDs.
|
||||||
|
allowDiscards = true;
|
||||||
|
};
|
||||||
|
content = {
|
||||||
|
type = "btrfs";
|
||||||
|
extraArgs = [ "-f" "-L" "NixOS" ];
|
||||||
|
subvolumes = {
|
||||||
|
"/root" = {
|
||||||
|
mountpoint = "/";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"/home" = {
|
||||||
|
mountpoint = "/home";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"/nix" = {
|
||||||
|
mountpoint = "/nix";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"/log" = {
|
||||||
|
mountpoint = "/var/log";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"/swap" = {
|
||||||
|
mountpoint = "/.swapvol";
|
||||||
|
swap.swapfile.size = "16G";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||||
|
# and may be overwritten by future invocations. Please make changes
|
||||||
|
# to /etc/nixos/configuration.nix instead.
|
||||||
|
{ config, lib, pkgs, modulesPath, ... }:
|
||||||
|
|
||||||
|
{
|
||||||
|
imports = [ (modulesPath + "/installer/scan/not-detected.nix") ];
|
||||||
|
|
||||||
|
# File systems and swap are declared in ./disko.nix.
|
||||||
|
# If you regenerate this file after installation, use:
|
||||||
|
# nixos-generate-config --no-filesystems --root /mnt
|
||||||
|
|
||||||
|
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "nvme" "usb_storage" "usbhid" "sd_mod" "rtsx_pci_sdmmc" ];
|
||||||
|
boot.initrd.kernelModules = [ ];
|
||||||
|
boot.kernelModules = [ "kvm-intel" "thinkpad_acpi" ];
|
||||||
|
boot.extraModulePackages = [ ];
|
||||||
|
|
||||||
|
networking.useDHCP = lib.mkDefault true;
|
||||||
|
|
||||||
|
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||||
|
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
|
||||||
|
}
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{ pkgs, ... }: let
|
||||||
|
theme = pkgs.fetchFromGitHub {
|
||||||
|
owner = "Patato777";
|
||||||
|
repo = "dotfiles";
|
||||||
|
rev = "cc363921707807d7ad3e36b462f0df793a0fe18a";
|
||||||
|
hash = "sha256-fpXGFNrzbV6K9hoZRX4tGieTLzhpPeGm6wn8CF4OGow=";
|
||||||
|
};
|
||||||
|
in {
|
||||||
|
boot.loader.grub = {
|
||||||
|
gfxmodeEfi = "1920x1080";
|
||||||
|
theme = "${theme}/grub/themes/virtuaverse";
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{
|
||||||
|
wayland.windowManager.hyprland = {
|
||||||
|
settings = {
|
||||||
|
monitor = [
|
||||||
|
"eDP-1, 1920x1080@60, 0x0, 1"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
{
|
||||||
|
sops = {
|
||||||
|
age.keyFile = "/root/age.key";
|
||||||
|
secrets = {
|
||||||
|
vpn_bolt = {
|
||||||
|
format = "binary";
|
||||||
|
sopsFile = ../../Rias/secrets/vpn_bolt.db;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
{ config, lib, pkgs, ... }: {
|
||||||
|
# T480-specific hardware defaults.
|
||||||
|
hardware = {
|
||||||
|
enableRedistributableFirmware = true;
|
||||||
|
|
||||||
|
trackpoint = {
|
||||||
|
enable = true;
|
||||||
|
emulateWheel = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
boot = {
|
||||||
|
supportedFilesystems = [ "btrfs" ];
|
||||||
|
|
||||||
|
initrd.availableKernelModules = [
|
||||||
|
"nvme"
|
||||||
|
"ahci"
|
||||||
|
"xhci_pci"
|
||||||
|
"usb_storage"
|
||||||
|
"usbhid"
|
||||||
|
"sd_mod"
|
||||||
|
"rtsx_pci_sdmmc"
|
||||||
|
];
|
||||||
|
|
||||||
|
kernelModules = [ "kvm-intel" "thinkpad_acpi" ];
|
||||||
|
|
||||||
|
kernelParams = [
|
||||||
|
# Prefer S3/deep sleep when BIOS exposes it. If suspend behaves worse,
|
||||||
|
# remove this and use the BIOS sleep setting instead.
|
||||||
|
"mem_sleep_default=deep"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
powerManagement.enable = true;
|
||||||
|
services = {
|
||||||
|
# Firmware updates for BIOS/UEFI, Thunderbolt, SSDs where LVFS supports it.
|
||||||
|
fwupd.enable = true;
|
||||||
|
|
||||||
|
# Helps Intel laptops keep sane thermal behaviour under load.
|
||||||
|
thermald.enable = true;
|
||||||
|
|
||||||
|
# Fingerprint reader support. If fprintd does not detect the reader,
|
||||||
|
# leaving this enabled is harmless; login can still use a password.
|
||||||
|
fprintd.enable = true;
|
||||||
|
|
||||||
|
logind = {
|
||||||
|
lidSwitch = "suspend";
|
||||||
|
lidSwitchExternalPower = "suspend";
|
||||||
|
powerKey = "poweroff";
|
||||||
|
};
|
||||||
|
|
||||||
|
tlp.settings = {
|
||||||
|
# Preserve batteries when the laptop is usually on AC.
|
||||||
|
# Raise STOP_* to 100 if maximum autonomy matters more than battery wear.
|
||||||
|
START_CHARGE_THRESH_BAT0 = 70;
|
||||||
|
STOP_CHARGE_THRESH_BAT0 = 85;
|
||||||
|
START_CHARGE_THRESH_BAT1 = 70;
|
||||||
|
STOP_CHARGE_THRESH_BAT1 = 85;
|
||||||
|
RESTORE_THRESHOLDS_ON_BAT = 1;
|
||||||
|
|
||||||
|
# NVMe/SATA SSD power saving without making the system too sluggish.
|
||||||
|
AHCI_RUNTIME_PM_ON_AC = "on";
|
||||||
|
AHCI_RUNTIME_PM_ON_BAT = "auto";
|
||||||
|
SATA_LINKPWR_ON_AC = "med_power_with_dipm";
|
||||||
|
SATA_LINKPWR_ON_BAT = "med_power_with_dipm";
|
||||||
|
|
||||||
|
# Usually safe on ThinkPads; disable if some USB device randomly disconnects.
|
||||||
|
USB_AUTOSUSPEND = 1;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
networking.networkmanager.wifi.powersave = true;
|
||||||
|
|
||||||
|
environment.systemPackages = with pkgs; [
|
||||||
|
acpi
|
||||||
|
lm_sensors
|
||||||
|
pciutils
|
||||||
|
powertop
|
||||||
|
smartmontools
|
||||||
|
usbutils
|
||||||
|
nvme-cli
|
||||||
|
];
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user