Inaho: new host

This commit is contained in:
2026-07-08 19:18:37 +03:00
parent 9a5ac146cb
commit fe12a5b50e
10 changed files with 310 additions and 41 deletions
-41
View File
@@ -1,41 +0,0 @@
{
disko.devices = {
disk = {
my-disk = {
device = "/dev/sdb";
type = "disk";
content = {
type = "gpt";
partitions = {
ESP = {
type = "EF00";
size = "256M";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
swap = {
size = "8G";
content = {
type = "swap";
resumeDevice = true;
};
};
root = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
};
};
};
};
};
}
+5
View File
@@ -23,6 +23,10 @@
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
nixpkgs-stable.url = "github:nixos/nixpkgs/nixos-26.05";
nixpkgs-pinned.url = "github:nixos/nixpkgs/ec942ba042dad5ef097e2ef3a3effc034241f011";
disko = {
url = "github:nix-community/disko";
inputs.nixpkgs.follows = "nixpkgs";
};
sops-nix.url = "github:Mic92/sops-nix";
stylix.url = "github:danth/stylix";
ags.url = "github:Aylur/ags/3ed9737bdbc8fc7a7c7ceef2165c9109f336bff6";
@@ -63,6 +67,7 @@
Senko = mkHost "Senko";
Eclipse = mkHost "Eclipse";
Impreza = mkHost "Impreza";
Inaho = mkHost "Inaho";
};
};
}
+49
View File
@@ -0,0 +1,49 @@
ThinkPad T480
CPU: Intel i5-8350U
RAM: 16GB planned (8GB stock + 8GB SO-DIMM)
SSD: 256GB NVMe stock; disko assumes `/dev/nvme0n1`
## Installation notes
This host uses `disko` with GPT + unencrypted EFI System Partition + LUKS + Btrfs subvolumes.
Before formatting, verify the target disk:
```bash
lsblk
```
If the internal drive is not `/dev/nvme0n1`, edit `host/Inaho/disko.nix` first.
For a 2.5" SATA SSD/HDD it will usually be `/dev/sda`.
Then partition, format and mount:
```bash
sudo nix --experimental-features "nix-command flakes" run github:nix-community/disko/latest -- \
--mode destroy,format,mount ./host/Inaho/disko.nix
```
This destroys the selected disk.
After that install the host:
```bash
sudo nixos-install --flake .#Inaho
```
The flake contains a new `disko` input. If `flake.lock` has not been updated yet, run:
```bash
nix flake lock --update-input disko
```
## After first boot
Update firmware, especially BIOS/UEFI and Thunderbolt, when batteries are installed and charged:
```bash
sudo fwupdmgr refresh
sudo fwupdmgr get-updates
sudo fwupdmgr update
```
+33
View File
@@ -0,0 +1,33 @@
{ config, pkgs, pkgs-stable, pkgs-pinned, lib, inputs, ... }: {
imports = [
inputs.disko.nixosModules.disko
./disko.nix
./secrets/secrets.nix
./modules/grub.nix
../modules/thinkpad.nix
../modules/gpu/intel.nix
(import ../modules/common.nix {
inherit lib;
inherit inputs;
hostname = "Inaho";
})
(import ../../user/common.nix {
inherit config;
inherit pkgs;
inherit pkgs-stable;
inherit pkgs-pinned;
inherit lib;
inherit inputs;
name = "sweetbread";
fullname = "Sweet Bread";
})
];
hardware.bluetooth.enable = true;
host.laptop = true;
programs.adb.enable = true;
users.users.sweetbread.extraGroups = [ "adbusers" "kvm" ];
}
+85
View File
@@ -0,0 +1,85 @@
{ lib, ... }:
let
# Verify with `lsblk` before running disko. For the stock T480 NVMe setup
# this is usually correct; for a 2.5" SATA SSD/HDD change it to /dev/sda.
disk = "/dev/nvme0n1";
btrfsMountOptions = [
"compress=zstd"
"noatime"
"ssd"
"discard=async"
];
in {
disko.devices = {
disk = {
main = {
type = "disk";
device = disk;
content = {
type = "gpt";
partitions = {
ESP = {
priority = 1;
name = "ESP";
start = "1M";
size = "1G";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
luks = {
priority = 2;
name = "cryptsystem";
size = "100%";
content = {
type = "luks";
name = "crypted";
settings = {
# Allows fstrim/discard through LUKS for SSDs.
allowDiscards = true;
};
content = {
type = "btrfs";
extraArgs = [ "-f" "-L" "NixOS" ];
subvolumes = {
"/root" = {
mountpoint = "/";
mountOptions = btrfsMountOptions;
};
"/home" = {
mountpoint = "/home";
mountOptions = btrfsMountOptions;
};
"/nix" = {
mountpoint = "/nix";
mountOptions = btrfsMountOptions;
};
"/log" = {
mountpoint = "/var/log";
mountOptions = btrfsMountOptions;
};
"/swap" = {
mountpoint = "/.swapvol";
swap.swapfile.size = "16G";
};
};
};
};
};
};
};
};
};
};
}
+22
View File
@@ -0,0 +1,22 @@
# Do not modify this file! It was generated by ‘nixos-generate-config’
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
imports = [ (modulesPath + "/installer/scan/not-detected.nix") ];
# File systems and swap are declared in ./disko.nix.
# If you regenerate this file after installation, use:
# nixos-generate-config --no-filesystems --root /mnt
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "nvme" "usb_storage" "usbhid" "sd_mod" "rtsx_pci_sdmmc" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" "thinkpad_acpi" ];
boot.extraModulePackages = [ ];
networking.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
+13
View File
@@ -0,0 +1,13 @@
{ pkgs, ... }: let
theme = pkgs.fetchFromGitHub {
owner = "Patato777";
repo = "dotfiles";
rev = "cc363921707807d7ad3e36b462f0df793a0fe18a";
hash = "sha256-fpXGFNrzbV6K9hoZRX4tGieTLzhpPeGm6wn8CF4OGow=";
};
in {
boot.loader.grub = {
gfxmodeEfi = "1920x1080";
theme = "${theme}/grub/themes/virtuaverse";
};
}
+9
View File
@@ -0,0 +1,9 @@
{
wayland.windowManager.hyprland = {
settings = {
monitor = [
"eDP-1, 1920x1080@60, 0x0, 1"
];
};
};
}
+11
View File
@@ -0,0 +1,11 @@
{
sops = {
age.keyFile = "/root/age.key";
secrets = {
vpn_bolt = {
format = "binary";
sopsFile = ../../Rias/secrets/vpn_bolt.db;
};
};
};
}
+83
View File
@@ -0,0 +1,83 @@
{ config, lib, pkgs, ... }: {
# T480-specific hardware defaults.
hardware = {
enableRedistributableFirmware = true;
trackpoint = {
enable = true;
emulateWheel = true;
};
};
boot = {
supportedFilesystems = [ "btrfs" ];
initrd.availableKernelModules = [
"nvme"
"ahci"
"xhci_pci"
"usb_storage"
"usbhid"
"sd_mod"
"rtsx_pci_sdmmc"
];
kernelModules = [ "kvm-intel" "thinkpad_acpi" ];
kernelParams = [
# Prefer S3/deep sleep when BIOS exposes it. If suspend behaves worse,
# remove this and use the BIOS sleep setting instead.
"mem_sleep_default=deep"
];
};
powerManagement.enable = true;
services = {
# Firmware updates for BIOS/UEFI, Thunderbolt, SSDs where LVFS supports it.
fwupd.enable = true;
# Helps Intel laptops keep sane thermal behaviour under load.
thermald.enable = true;
# Fingerprint reader support. If fprintd does not detect the reader,
# leaving this enabled is harmless; login can still use a password.
fprintd.enable = true;
logind = {
lidSwitch = "suspend";
lidSwitchExternalPower = "suspend";
powerKey = "poweroff";
};
tlp.settings = {
# Preserve batteries when the laptop is usually on AC.
# Raise STOP_* to 100 if maximum autonomy matters more than battery wear.
START_CHARGE_THRESH_BAT0 = 70;
STOP_CHARGE_THRESH_BAT0 = 85;
START_CHARGE_THRESH_BAT1 = 70;
STOP_CHARGE_THRESH_BAT1 = 85;
RESTORE_THRESHOLDS_ON_BAT = 1;
# NVMe/SATA SSD power saving without making the system too sluggish.
AHCI_RUNTIME_PM_ON_AC = "on";
AHCI_RUNTIME_PM_ON_BAT = "auto";
SATA_LINKPWR_ON_AC = "med_power_with_dipm";
SATA_LINKPWR_ON_BAT = "med_power_with_dipm";
# Usually safe on ThinkPads; disable if some USB device randomly disconnects.
USB_AUTOSUSPEND = 1;
};
};
networking.networkmanager.wifi.powersave = true;
environment.systemPackages = with pkgs; [
acpi
lm_sensors
pciutils
powertop
smartmontools
usbutils
nvme-cli
];
}