{ config, pkgs, pkgs-unstable, inputs, configPath, hostname, hostTypes, lib, ... }: { imports = [ # Include the results of the hardware scan. ./hardware-configuration.nix # Declarative disk layout (consumed by disko + nixos-anywhere). ./disko-config.nix inputs.home-manager.nixosModules.default ]; # Bootloader. SeaBIOS/BIOS boot via GRUB installed to the whole disk # (writes boot.img to the MBR, core.img to the EF02 partition). boot.loader.grub.enable = lib.mkDefault true; boot.loader.grub.devices = ["/dev/sda"]; nix.settings.experimental-features = ["nix-command" "flakes"]; # Nix optimizations nix.optimise.automatic = true; nix.settings.auto-optimise-store = true; nix.gc = { automatic = true; dates = "weekly"; persistent = true; options = "--delete-older-than 30d"; }; networking.hostName = "buildbox"; # Define your hostname. # Enable networking networking.networkmanager.enable = true; # Virtualisation virtualisation.docker.enable = true; services.qemuGuest.enable = true; services.spice-vdagentd.enable = true; # zram zramSwap = { enable = true; priority = 100; memoryPercent = 30; swapDevices = 1; algorithm = "zstd"; }; # Btrfs auto-scrub services.btrfs.autoScrub = { enable = true; interval = "weekly"; fileSystems = ["/" "/home" "/nix"]; }; # Set your time zone. time.timeZone = "America/Los_Angeles"; # Select internationalisation properties. i18n.defaultLocale = "en_US.UTF-8"; i18n.extraLocaleSettings = { LC_ADDRESS = "en_US.UTF-8"; LC_IDENTIFICATION = "en_US.UTF-8"; LC_MEASUREMENT = "en_US.UTF-8"; LC_MONETARY = "en_US.UTF-8"; LC_NAME = "en_US.UTF-8"; LC_NUMERIC = "en_US.UTF-8"; LC_PAPER = "en_US.UTF-8"; LC_TELEPHONE = "en_US.UTF-8"; LC_TIME = "en_US.UTF-8"; }; # Disable X11 for servers services.xserver.enable = false; services.tailscale.enable = true; # Configure keymap in X11 services.xserver.xkb = { layout = "us"; variant = ""; }; # Enable CUPS to print documents. services.printing.enable = false; # VSCode-Server programs.nix-ld.enable = true; programs.nix-ld.libraries = with pkgs; [ stdenv.cc.cc.lib zlib glib libGL libGLU openssl ]; # Define a user account. Don't forget to set a password with ‘passwd’. programs.zsh.enable = true; users.users.rogueking = { isNormalUser = true; description = "rogueking"; extraGroups = ["networkmanager" "wheel" "docker"]; shell = pkgs.zsh; packages = with pkgs; []; }; # Install firefox. programs.firefox.enable = true; # Allow unfree packages nixpkgs.config.allowUnfree = true; security.polkit.enable = true; programs._1password.enable = true; programs._1password-gui = { enable = true; polkitPolicyOwners = ["rogueking"]; }; # Enable OpenSSH daemon services.openssh = { enable = true; ports = [22]; settings = { PasswordAuthentication = true; AllowUsers = ["rogueking"]; UseDns = true; X11Forwarding = false; PermitRootLogin = "no"; MaxAuthTries = 8; }; }; users.users."rogueking".openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINXqriPZVIuduc/J7GS1mD171LL0gIbgEjlImsxedWVX" ]; nixpkgs.config.permittedInsecurePackages = [ "qtwebengine-5.15.19" "python3.12-ecdsa-0.19.1" ]; # List packages installed in system profile. To search, run: # $ nix search wget environment.systemPackages = with pkgs; [ # System-level only — CLI tools moved to home-manager btrfs-progs ]; home-manager = { extraSpecialArgs = { inherit configPath inputs pkgs-unstable hostname hostTypes ; }; users = { "rogueking" = import ./../../home-manager/home.nix; }; backupFileExtension = "backup"; }; system.stateVersion = "26.05"; }