Inaho: new host
This commit is contained in:
@@ -1,41 +0,0 @@
|
||||
{
|
||||
disko.devices = {
|
||||
disk = {
|
||||
my-disk = {
|
||||
device = "/dev/sdb";
|
||||
type = "disk";
|
||||
content = {
|
||||
type = "gpt";
|
||||
partitions = {
|
||||
ESP = {
|
||||
type = "EF00";
|
||||
size = "256M";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "vfat";
|
||||
mountpoint = "/boot";
|
||||
};
|
||||
};
|
||||
|
||||
swap = {
|
||||
size = "8G";
|
||||
content = {
|
||||
type = "swap";
|
||||
resumeDevice = true;
|
||||
};
|
||||
};
|
||||
|
||||
root = {
|
||||
size = "100%";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "ext4";
|
||||
mountpoint = "/";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -23,6 +23,10 @@
|
||||
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
|
||||
nixpkgs-stable.url = "github:nixos/nixpkgs/nixos-26.05";
|
||||
nixpkgs-pinned.url = "github:nixos/nixpkgs/ec942ba042dad5ef097e2ef3a3effc034241f011";
|
||||
disko = {
|
||||
url = "github:nix-community/disko";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
sops-nix.url = "github:Mic92/sops-nix";
|
||||
stylix.url = "github:danth/stylix";
|
||||
ags.url = "github:Aylur/ags/3ed9737bdbc8fc7a7c7ceef2165c9109f336bff6";
|
||||
@@ -63,6 +67,7 @@
|
||||
Senko = mkHost "Senko";
|
||||
Eclipse = mkHost "Eclipse";
|
||||
Impreza = mkHost "Impreza";
|
||||
Inaho = mkHost "Inaho";
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
ThinkPad T480
|
||||
|
||||
CPU: Intel i5-8350U
|
||||
RAM: 16GB planned (8GB stock + 8GB SO-DIMM)
|
||||
SSD: 256GB NVMe stock; disko assumes `/dev/nvme0n1`
|
||||
|
||||
## Installation notes
|
||||
|
||||
This host uses `disko` with GPT + unencrypted EFI System Partition + LUKS + Btrfs subvolumes.
|
||||
|
||||
Before formatting, verify the target disk:
|
||||
|
||||
```bash
|
||||
lsblk
|
||||
```
|
||||
|
||||
If the internal drive is not `/dev/nvme0n1`, edit `host/Inaho/disko.nix` first.
|
||||
For a 2.5" SATA SSD/HDD it will usually be `/dev/sda`.
|
||||
|
||||
Then partition, format and mount:
|
||||
|
||||
```bash
|
||||
sudo nix --experimental-features "nix-command flakes" run github:nix-community/disko/latest -- \
|
||||
--mode destroy,format,mount ./host/Inaho/disko.nix
|
||||
```
|
||||
|
||||
This destroys the selected disk.
|
||||
|
||||
After that install the host:
|
||||
|
||||
```bash
|
||||
sudo nixos-install --flake .#Inaho
|
||||
```
|
||||
|
||||
The flake contains a new `disko` input. If `flake.lock` has not been updated yet, run:
|
||||
|
||||
```bash
|
||||
nix flake lock --update-input disko
|
||||
```
|
||||
|
||||
## After first boot
|
||||
|
||||
Update firmware, especially BIOS/UEFI and Thunderbolt, when batteries are installed and charged:
|
||||
|
||||
```bash
|
||||
sudo fwupdmgr refresh
|
||||
sudo fwupdmgr get-updates
|
||||
sudo fwupdmgr update
|
||||
```
|
||||
@@ -0,0 +1,33 @@
|
||||
{ config, pkgs, pkgs-stable, pkgs-pinned, lib, inputs, ... }: {
|
||||
imports = [
|
||||
inputs.disko.nixosModules.disko
|
||||
./disko.nix
|
||||
./secrets/secrets.nix
|
||||
./modules/grub.nix
|
||||
../modules/thinkpad.nix
|
||||
../modules/gpu/intel.nix
|
||||
|
||||
(import ../modules/common.nix {
|
||||
inherit lib;
|
||||
inherit inputs;
|
||||
hostname = "Inaho";
|
||||
})
|
||||
|
||||
(import ../../user/common.nix {
|
||||
inherit config;
|
||||
inherit pkgs;
|
||||
inherit pkgs-stable;
|
||||
inherit pkgs-pinned;
|
||||
inherit lib;
|
||||
inherit inputs;
|
||||
name = "sweetbread";
|
||||
fullname = "Sweet Bread";
|
||||
})
|
||||
];
|
||||
|
||||
hardware.bluetooth.enable = true;
|
||||
host.laptop = true;
|
||||
|
||||
programs.adb.enable = true;
|
||||
users.users.sweetbread.extraGroups = [ "adbusers" "kvm" ];
|
||||
}
|
||||
@@ -0,0 +1,85 @@
|
||||
{ lib, ... }:
|
||||
|
||||
let
|
||||
# Verify with `lsblk` before running disko. For the stock T480 NVMe setup
|
||||
# this is usually correct; for a 2.5" SATA SSD/HDD change it to /dev/sda.
|
||||
disk = "/dev/nvme0n1";
|
||||
|
||||
btrfsMountOptions = [
|
||||
"compress=zstd"
|
||||
"noatime"
|
||||
"ssd"
|
||||
"discard=async"
|
||||
];
|
||||
in {
|
||||
disko.devices = {
|
||||
disk = {
|
||||
main = {
|
||||
type = "disk";
|
||||
device = disk;
|
||||
content = {
|
||||
type = "gpt";
|
||||
partitions = {
|
||||
ESP = {
|
||||
priority = 1;
|
||||
name = "ESP";
|
||||
start = "1M";
|
||||
size = "1G";
|
||||
type = "EF00";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "vfat";
|
||||
mountpoint = "/boot";
|
||||
mountOptions = [ "umask=0077" ];
|
||||
};
|
||||
};
|
||||
|
||||
luks = {
|
||||
priority = 2;
|
||||
name = "cryptsystem";
|
||||
size = "100%";
|
||||
content = {
|
||||
type = "luks";
|
||||
name = "crypted";
|
||||
settings = {
|
||||
# Allows fstrim/discard through LUKS for SSDs.
|
||||
allowDiscards = true;
|
||||
};
|
||||
content = {
|
||||
type = "btrfs";
|
||||
extraArgs = [ "-f" "-L" "NixOS" ];
|
||||
subvolumes = {
|
||||
"/root" = {
|
||||
mountpoint = "/";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"/home" = {
|
||||
mountpoint = "/home";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"/nix" = {
|
||||
mountpoint = "/nix";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"/log" = {
|
||||
mountpoint = "/var/log";
|
||||
mountOptions = btrfsMountOptions;
|
||||
};
|
||||
|
||||
"/swap" = {
|
||||
mountpoint = "/.swapvol";
|
||||
swap.swapfile.size = "16G";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{ config, lib, pkgs, modulesPath, ... }:
|
||||
|
||||
{
|
||||
imports = [ (modulesPath + "/installer/scan/not-detected.nix") ];
|
||||
|
||||
# File systems and swap are declared in ./disko.nix.
|
||||
# If you regenerate this file after installation, use:
|
||||
# nixos-generate-config --no-filesystems --root /mnt
|
||||
|
||||
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "nvme" "usb_storage" "usbhid" "sd_mod" "rtsx_pci_sdmmc" ];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ "kvm-intel" "thinkpad_acpi" ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
networking.useDHCP = lib.mkDefault true;
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
{ pkgs, ... }: let
|
||||
theme = pkgs.fetchFromGitHub {
|
||||
owner = "Patato777";
|
||||
repo = "dotfiles";
|
||||
rev = "cc363921707807d7ad3e36b462f0df793a0fe18a";
|
||||
hash = "sha256-fpXGFNrzbV6K9hoZRX4tGieTLzhpPeGm6wn8CF4OGow=";
|
||||
};
|
||||
in {
|
||||
boot.loader.grub = {
|
||||
gfxmodeEfi = "1920x1080";
|
||||
theme = "${theme}/grub/themes/virtuaverse";
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
{
|
||||
wayland.windowManager.hyprland = {
|
||||
settings = {
|
||||
monitor = [
|
||||
"eDP-1, 1920x1080@60, 0x0, 1"
|
||||
];
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
{
|
||||
sops = {
|
||||
age.keyFile = "/root/age.key";
|
||||
secrets = {
|
||||
vpn_bolt = {
|
||||
format = "binary";
|
||||
sopsFile = ../../Rias/secrets/vpn_bolt.db;
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,83 @@
|
||||
{ config, lib, pkgs, ... }: {
|
||||
# T480-specific hardware defaults.
|
||||
hardware = {
|
||||
enableRedistributableFirmware = true;
|
||||
|
||||
trackpoint = {
|
||||
enable = true;
|
||||
emulateWheel = true;
|
||||
};
|
||||
};
|
||||
|
||||
boot = {
|
||||
supportedFilesystems = [ "btrfs" ];
|
||||
|
||||
initrd.availableKernelModules = [
|
||||
"nvme"
|
||||
"ahci"
|
||||
"xhci_pci"
|
||||
"usb_storage"
|
||||
"usbhid"
|
||||
"sd_mod"
|
||||
"rtsx_pci_sdmmc"
|
||||
];
|
||||
|
||||
kernelModules = [ "kvm-intel" "thinkpad_acpi" ];
|
||||
|
||||
kernelParams = [
|
||||
# Prefer S3/deep sleep when BIOS exposes it. If suspend behaves worse,
|
||||
# remove this and use the BIOS sleep setting instead.
|
||||
"mem_sleep_default=deep"
|
||||
];
|
||||
};
|
||||
|
||||
powerManagement.enable = true;
|
||||
services = {
|
||||
# Firmware updates for BIOS/UEFI, Thunderbolt, SSDs where LVFS supports it.
|
||||
fwupd.enable = true;
|
||||
|
||||
# Helps Intel laptops keep sane thermal behaviour under load.
|
||||
thermald.enable = true;
|
||||
|
||||
# Fingerprint reader support. If fprintd does not detect the reader,
|
||||
# leaving this enabled is harmless; login can still use a password.
|
||||
fprintd.enable = true;
|
||||
|
||||
logind = {
|
||||
lidSwitch = "suspend";
|
||||
lidSwitchExternalPower = "suspend";
|
||||
powerKey = "poweroff";
|
||||
};
|
||||
|
||||
tlp.settings = {
|
||||
# Preserve batteries when the laptop is usually on AC.
|
||||
# Raise STOP_* to 100 if maximum autonomy matters more than battery wear.
|
||||
START_CHARGE_THRESH_BAT0 = 70;
|
||||
STOP_CHARGE_THRESH_BAT0 = 85;
|
||||
START_CHARGE_THRESH_BAT1 = 70;
|
||||
STOP_CHARGE_THRESH_BAT1 = 85;
|
||||
RESTORE_THRESHOLDS_ON_BAT = 1;
|
||||
|
||||
# NVMe/SATA SSD power saving without making the system too sluggish.
|
||||
AHCI_RUNTIME_PM_ON_AC = "on";
|
||||
AHCI_RUNTIME_PM_ON_BAT = "auto";
|
||||
SATA_LINKPWR_ON_AC = "med_power_with_dipm";
|
||||
SATA_LINKPWR_ON_BAT = "med_power_with_dipm";
|
||||
|
||||
# Usually safe on ThinkPads; disable if some USB device randomly disconnects.
|
||||
USB_AUTOSUSPEND = 1;
|
||||
};
|
||||
};
|
||||
|
||||
networking.networkmanager.wifi.powersave = true;
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
acpi
|
||||
lm_sensors
|
||||
pciutils
|
||||
powertop
|
||||
smartmontools
|
||||
usbutils
|
||||
nvme-cli
|
||||
];
|
||||
}
|
||||
Reference in New Issue
Block a user