319 lines
7.4 KiB
Nix
319 lines
7.4 KiB
Nix
# Edit this configuration file to define what should be installed on
|
||
# your system. Help is available in the configuration.nix(5) man page
|
||
# and in the NixOS manual (accessible by running ‘nixos-help’).
|
||
|
||
{
|
||
config,
|
||
lib,
|
||
pkgs,
|
||
inputs,
|
||
...
|
||
}:
|
||
|
||
with lib;
|
||
|
||
{
|
||
imports = [
|
||
# Include the results of the hardware scan.
|
||
./hardware-configuration.nix
|
||
../../modules/nixos/clamav.nix
|
||
];
|
||
|
||
hardware.bluetooth = {
|
||
enable = true;
|
||
powerOnBoot = true;
|
||
settings = {
|
||
General = {
|
||
Name = "Hello";
|
||
ControllerMode = "dual";
|
||
FastConnectable = "true";
|
||
Experimental = "true";
|
||
};
|
||
Policy = {
|
||
AutoEnable = "true";
|
||
};
|
||
};
|
||
};
|
||
services.blueman.enable = true;
|
||
hardware.enableAllFirmware = true;
|
||
|
||
# boot.kernelPackages = pkgs.linuxPackages_latest;
|
||
|
||
boot.kernelPackages = pkgs.linuxPackagesFor (
|
||
pkgs.linux_latest.override {
|
||
argsOverride = rec {
|
||
version = "7.0.6";
|
||
modDirVersion = "7.0.6";
|
||
src = pkgs.fetchurl {
|
||
url = "mirror://kernel/linux/kernel/v7.x/linux-${version}.tar.xz";
|
||
sha256 = "08vm18wx6399phzgr3wz94yga3ab4fyca79445ygvbspm904996b";
|
||
};
|
||
};
|
||
}
|
||
);
|
||
|
||
# Bootloader.
|
||
boot.loader.systemd-boot.enable = true;
|
||
boot.loader.efi.canTouchEfiVariables = true;
|
||
|
||
boot.initrd.luks.devices."luks-1dfcf980-6806-4f69-bd86-ee87c904c04b".device =
|
||
"/dev/disk/by-uuid/1dfcf980-6806-4f69-bd86-ee87c904c04b";
|
||
networking.hostName = "fw"; # Define your hostname.
|
||
# networking.wireless.enable = true; # Enables wireless support via wpa_supplicant.
|
||
networking.extraHosts = ''
|
||
# 204.168.170.249 talk.timo.social
|
||
# 204.168.170.249 turn.talk.timo.social
|
||
'';
|
||
|
||
# Configure network proxy if necessary
|
||
# networking.proxy.default = "http://user:password@proxy:port/";
|
||
# networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain";
|
||
|
||
# Enable networking
|
||
networking.networkmanager.enable = true;
|
||
|
||
# Set your time zone.
|
||
time.timeZone = "Europe/Berlin";
|
||
|
||
# Select internationalisation properties.
|
||
i18n.defaultLocale = "en_US.UTF-8";
|
||
|
||
i18n.extraLocaleSettings = {
|
||
LC_ADDRESS = "de_DE.UTF-8";
|
||
LC_IDENTIFICATION = "de_DE.UTF-8";
|
||
LC_MEASUREMENT = "de_DE.UTF-8";
|
||
LC_MONETARY = "de_DE.UTF-8";
|
||
LC_NAME = "de_DE.UTF-8";
|
||
LC_NUMERIC = "de_DE.UTF-8";
|
||
LC_PAPER = "de_DE.UTF-8";
|
||
LC_TELEPHONE = "de_DE.UTF-8";
|
||
LC_TIME = "de_DE.UTF-8";
|
||
};
|
||
|
||
# Enable the X11 windowing system.
|
||
# You can disable this if you're only using the Wayland session.
|
||
services.xserver.enable = true;
|
||
|
||
# Configure keymap in X11
|
||
services.xserver.xkb = {
|
||
layout = "us";
|
||
variant = "";
|
||
};
|
||
|
||
#services.xserver.windowManager.dwm = {
|
||
# enable = true;
|
||
# package = pkgs.dwm.overrideAttrs {
|
||
# src = ./config/dwm;
|
||
# };
|
||
#};
|
||
|
||
# Enable the KDE Plasma Desktop Environment.
|
||
services.displayManager.sddm.enable = true;
|
||
services.desktopManager.plasma6.enable = true;
|
||
|
||
#services.displayManager.ly.enable = true;
|
||
|
||
# Enable CUPS to print documents.
|
||
services.printing.enable = true;
|
||
|
||
# Enable sound with pipewire.
|
||
services.pulseaudio.enable = false;
|
||
security.rtkit.enable = true;
|
||
services.pipewire = {
|
||
enable = true;
|
||
alsa.enable = true;
|
||
alsa.support32Bit = true;
|
||
pulse.enable = true;
|
||
# If you want to use JACK applications, uncomment this
|
||
#jack.enable = true;
|
||
|
||
# use the example session manager (no others are packaged yet so this is enabled by default,
|
||
# no need to redefine it in your config for now)
|
||
#media-session.enable = true;
|
||
};
|
||
|
||
# Enable touchpad support (enabled default in most desktopManager).
|
||
# services.xserver.libinput.enable = true;
|
||
|
||
# Define a user account. Don't forget to set a password with ‘passwd’.
|
||
users.users.tsi = {
|
||
isNormalUser = true;
|
||
description = "tsi";
|
||
extraGroups = [
|
||
"networkmanager"
|
||
"wheel"
|
||
"libvirtd"
|
||
"docker"
|
||
"video"
|
||
];
|
||
packages = with pkgs; [ ];
|
||
};
|
||
|
||
# Install firefox.
|
||
programs.firefox.enable = true;
|
||
|
||
# Allow unfree packages
|
||
nixpkgs.config.allowUnfree = true;
|
||
|
||
virtualisation.libvirtd.enable = true;
|
||
virtualisation.docker = {
|
||
enable = true;
|
||
package = pkgs.docker_29;
|
||
};
|
||
programs.virt-manager.enable = true;
|
||
programs.fuse.userAllowOther = true;
|
||
services.pcscd.enable = true;
|
||
|
||
services.netbird.enable = true;
|
||
#services.netbird.clients.wt0 = {
|
||
# login = {
|
||
# enable = true;
|
||
# #setupKeyFile = /home/tsi/.config/netbird/setup-key;
|
||
# };
|
||
|
||
# port = 51821;
|
||
# ui.enable = true;
|
||
# #openFirewall = true;
|
||
# #oepnInternalFirewall = true;
|
||
#};
|
||
|
||
# Some programs need SUID wrappers, can be configured further or are
|
||
# started in user sessions.
|
||
# programs.mtr.enable = true;
|
||
# programs.gnupg.agent = {
|
||
# enable = true;
|
||
# enableSSHSupport = true;
|
||
# };
|
||
|
||
# List services that you want to enable:
|
||
|
||
# Enable the OpenSSH daemon.
|
||
# services.openssh.enable = true;
|
||
|
||
# Open ports in the firewall.
|
||
# networking.firewall.allowedTCPPorts = [ ... ];
|
||
# networking.firewall.allowedUDPPorts = [ ... ];
|
||
# Or disable the firewall altogether.
|
||
networking.firewall.enable = false;
|
||
|
||
# This value determines the NixOS release from which the default
|
||
# settings for stateful data, like file locations and database versions
|
||
# on your system were taken. It‘s perfectly fine and recommended to leave
|
||
# this value at the release version of the first install of this system.
|
||
# Before changing this value read the documentation for this option
|
||
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
|
||
system.stateVersion = "25.11"; # Did you read the comment?
|
||
|
||
nix.settings.experimental-features = [
|
||
"nix-command"
|
||
"flakes"
|
||
];
|
||
|
||
programs.nix-index-database.comma.enable = true;
|
||
|
||
home-manager = {
|
||
extraSpecialArgs = { inherit inputs; };
|
||
users = {
|
||
"tsi" = import ./home.nix;
|
||
};
|
||
};
|
||
|
||
services.xserver.dpi = 192;
|
||
# services.xserver.dpi = 96;
|
||
|
||
environment.variables = {
|
||
### ## Used by GTK 3
|
||
### # `GDK_SCALE` is limited to integer values
|
||
### GDK_SCALE = "2";
|
||
### # Inverse of GDK_SCALE
|
||
### GDK_DPI_SCALE = "0.5";
|
||
|
||
### # Used by Qt 5
|
||
### QT_AUTO_SCREEN_SCALE_FACTOR = "1";
|
||
|
||
_JAVA_OPTIONS = "-Dsun.java2d.uiScale=2";
|
||
|
||
XCURSOR_SIZE = "64";
|
||
};
|
||
|
||
### # Expose variables to graphical systemd user services
|
||
### services.xserver.displayManager.importedVariables = [
|
||
### "GDK_SCALE"
|
||
### "GDK_DPI_SCALE"
|
||
### "QT_AUTO_SCREEN_SCALE_FACTOR"
|
||
### ];
|
||
|
||
# List packages installed in system profile. To search, run:
|
||
# $ nix search wget
|
||
environment.systemPackages = with pkgs; [
|
||
vim
|
||
alacritty
|
||
keepassxc
|
||
nextcloud-client
|
||
dmenu
|
||
arandr
|
||
brave
|
||
pavucontrol
|
||
signal-desktop
|
||
simplex-chat-desktop
|
||
ayugram-desktop
|
||
dnsmasq
|
||
file
|
||
gnumake
|
||
nmap
|
||
usbutils
|
||
brightnessctl
|
||
pulseaudio
|
||
moreutils
|
||
spacer
|
||
yubioath-flutter
|
||
slack
|
||
mpv
|
||
netbird-ui
|
||
python3
|
||
dig
|
||
htop
|
||
gcc
|
||
wireguard-tools
|
||
gh
|
||
rustdesk
|
||
anydesk
|
||
jq
|
||
android-tools
|
||
gdu
|
||
gron
|
||
mkvtoolnix-cli
|
||
ydiff
|
||
wl-clipboard-rs
|
||
proton-vpn
|
||
iperf3
|
||
pv
|
||
libarchive
|
||
libreoffice
|
||
traceroute
|
||
pciutils
|
||
usbutils
|
||
bc
|
||
pstree
|
||
tmux
|
||
wget
|
||
gnupg
|
||
mosh
|
||
openvpn
|
||
clamav
|
||
conntrack-tools
|
||
kdotool
|
||
trash-cli
|
||
bat
|
||
psmisc
|
||
mupdf
|
||
signal-cli
|
||
exfat
|
||
fprintd
|
||
ranger
|
||
];
|
||
|
||
services.power-profiles-daemon.enable = true;
|
||
|
||
environment.localBinInPath = true;
|
||
}
|