71 Commits
Author SHA1 Message Date
Gitea Actions a196abbb2d Update flake.lock 2025-04-28 2026-07-20 00:32:59 +00:00
Gitea Actions 4ea28e044f Update flake.lock 2025-04-27 2026-07-20 00:32:59 +00:00
Gitea Actions 9c97cd1820 Update flake.lock 2025-04-26 2026-07-20 00:32:59 +00:00
Gitea Actions 1a091092c3 Update flake.lock 2025-04-25 2026-07-20 00:32:59 +00:00
Gitea Actions 06b56c7422 Update flake.lock 2025-04-24 2026-07-20 00:32:59 +00:00
Gitea Actions a1d0228b0d Update flake.lock 2025-04-23 2026-07-20 00:32:59 +00:00
Gitea Actions cf9d79d660 Update flake.lock 2025-04-22 2026-07-20 00:32:59 +00:00
Gitea Actions bdca60700c Update flake.lock 2025-04-21 2026-07-20 00:32:59 +00:00
Gitea Actions 81e665882c Update flake.lock 2025-04-20 2026-07-20 00:32:59 +00:00
Gitea Actions c1349d4fc7 Update flake.lock 2025-04-19 2026-07-20 00:32:59 +00:00
Gitea Actions e18601faa5 Update flake.lock 2025-04-18 2026-07-20 00:32:59 +00:00
Gitea Actions 3df4cafe28 Update flake.lock 2025-04-17 2026-07-20 00:32:59 +00:00
Gitea Actions 2745692e8a Update flake.lock 2025-04-16 2026-07-20 00:32:59 +00:00
Gitea Actions b43adbd161 Update flake.lock 2025-04-15 2026-07-20 00:32:59 +00:00
Gitea Actions f5f8a9b71b Update flake.lock 2025-04-14 2026-07-20 00:32:59 +00:00
Gitea Actions 14182669e1 Update flake.lock 2025-04-13 2026-07-20 00:32:59 +00:00
Gitea Actions ffec78a68b Update flake.lock 2025-04-12 2026-07-20 00:32:59 +00:00
Gitea Actions 369d8640cd Update flake.lock 2025-04-11 2026-07-20 00:32:59 +00:00
Gitea Actions f9ddbedb5f Update flake.lock 2025-04-10 2026-07-20 00:32:59 +00:00
Gitea Actions 7016d1f24c Update flake.lock 2025-04-09 2026-07-20 00:32:59 +00:00
Gitea Actions 70030a70e2 Update flake.lock 2025-04-08 2026-07-20 00:32:59 +00:00
Gitea Actions 7ffde2b6a1 Update flake.lock 2025-04-07 2026-07-20 00:32:59 +00:00
Gitea Actions bd2ba1f38c Update flake.lock 2025-04-06 2026-07-20 00:32:59 +00:00
Gitea Actions 9a5c1c4e51 Update flake.lock 2025-04-05 2026-07-20 00:32:59 +00:00
Gitea Actions ffce3398ef Update flake.lock 2025-04-04 2026-07-20 00:32:59 +00:00
Gitea Actions 4dfb1b6ee3 Update flake.lock 2025-04-03 2026-07-20 00:32:59 +00:00
Gitea Actions 1a123348dd Update flake.lock 2025-04-02 2026-07-20 00:32:59 +00:00
Gitea Actions 6a2872f207 Update flake.lock 2025-04-01 2026-07-20 00:32:59 +00:00
Gitea Actions 84d79462d2 Update flake.lock 2025-03-31 2026-07-20 00:32:59 +00:00
Gitea Actions b4d79e958d Update flake.lock 2025-03-30 2026-07-20 00:32:59 +00:00
Gitea Actions 5b3480529e Update flake.lock 2025-03-29 2026-07-20 00:32:59 +00:00
Gitea Actions 97849952a6 Update flake.lock 2025-03-28 2026-07-20 00:32:59 +00:00
Gitea Actions f0a304d9db Update flake.lock 2025-03-27 2026-07-20 00:32:59 +00:00
Gitea Actions 2054ee1a7b Update flake.lock 2025-03-26 2026-07-20 00:32:59 +00:00
Gitea Actions cb920eaefd Update flake.lock 2025-03-25 2026-07-20 00:32:59 +00:00
Gitea Actions de827013c6 Update flake.lock 2025-03-24 2026-07-20 00:32:59 +00:00
Gitea Actions ce801ec0a8 Update flake.lock 2025-03-23 2026-07-20 00:32:59 +00:00
julian 121f79e048 flake: update 2026-07-19 14:48:40 +02:00
julian e85156235c builder: use correct ssh keys for age 2026-07-19 14:01:09 +02:00
julian e89908b592 builder: store nix-serve key in sops 2026-07-19 13:56:33 +02:00
julian 139402db48 readme: change builder install to remote flake 2026-07-19 13:21:01 +02:00
julian 0bbce5c85e builder: enable gitea-runner 2026-07-19 13:20:42 +02:00
julian 3fd5c34aa1 builder: change ssh key for sops 2026-07-19 13:18:47 +02:00
julian a7df51dbb8 readme: document nixos-anywhere install for builder 2026-07-19 12:59:59 +02:00
julian d89b8b51cc builder: fix config for installation 2026-07-19 12:59:50 +02:00
julian 6c301d87fd builder: allow using modules 2026-07-19 12:53:01 +02:00
julian 4b6c84e63d fix modules not detected 2026-07-19 12:50:16 +02:00
julian 59780f39d0 kardorf: do not use builder 2026-07-19 12:32:11 +02:00
julian 48d784a964 builder: massive config cleanup, breakdown into modules, use disko 2026-07-19 12:29:39 +02:00
julian 76ad137946 hyprland: make monitor config dependent on config.monitors 2026-07-19 09:08:50 +02:00
julian de081fe38f kardorf: use k9s 2026-07-18 15:05:01 +02:00
julian 940ea05b3f fix noctalia if kde is installed alongside 2026-07-18 15:04:28 +02:00
julian 107e86d533 update flake 2026-07-18 15:04:19 +02:00
julian db11705c44 noctalia: update to v4.7.7 to fix hyprland issues 2026-07-03 17:56:22 +02:00
julian 6dca04621d noctalia: go back to v4 2026-07-01 21:28:54 +02:00
julian 00ef9ef193 noctalia: update config 2026-07-01 21:16:31 +02:00
julian d923423d52 locale: fix 2026-07-01 21:14:29 +02:00
julian 9595f16689 noctalia: update config 2026-07-01 21:08:16 +02:00
julian 77c9c87624 change time locale 2026-07-01 21:06:29 +02:00
julian a5ebf46d0c update flake 2026-07-01 20:54:00 +02:00
julian 1bd857c1ca Noctalia: migrate to v5 2026-07-01 20:53:52 +02:00
julian de10839976 noctalia: use cached flake input 2026-07-01 20:01:12 +02:00
julian ae2995e972 caches: prioritize cache.nixos.org 2026-07-01 19:57:25 +02:00
julian f494e364e1 hm: remove unavailable gtk4 config value 2026-06-25 20:07:50 +02:00
julian 39cac2aedb noctalia: use new config parameter name 2026-06-25 20:07:30 +02:00
julian 3260c774ca nixvim: fix warning at build 2026-06-25 20:07:12 +02:00
julian daf0980eb9 update flake 2026-06-25 20:07:06 +02:00
julian c61f1f6741 aspi: disable builder 2026-06-21 12:10:45 +02:00
julian 99cc802565 aspi: enable bluetooth 2026-06-18 20:55:16 +02:00
julian 4bc97efe7a aspi: add k9s config 2026-06-18 20:52:23 +02:00
julian 6260c56bbd Builder: add docker and devenv to gitea ci packets 2026-06-12 14:42:11 +02:00
26 changed files with 1818 additions and 523 deletions
+8 -1
View File
@@ -1,7 +1,7 @@
keys:
- &primary age1ee5udznhadk6m7jtglu4709rep080yjyd2ukzdl8jma4mm92y3psv0slpg
- &aspi-ssh age1q8lc5340gz5xw2f57nglrss68wv0j0hf36py2pdtrl6ky3yrq9qqk0njr4
- &builder-ssh age1kw4kmdm45zprvdkrrpvgq966l7585vhusmum083qlwnr0xxgd3uqatcyja
- &builder-ssh age1vwanu6jm80jzwe78jzz7z9vuzlg94tl7rpdg34vjmxcrnhddxu9q5zaf49
- &kardorf-ssh age15lxw97z03q40xrdscnxqqugh5ky5aqrerg2t2rphkcqm6rnllurq8v98q5
creation_rules:
@@ -17,3 +17,10 @@ creation_rules:
- age:
- *primary
- *builder-ssh
- path_regex: features-nixos/optional/k9s/kubeconfig.secret.yaml$
key_groups:
- age:
- *primary
- *aspi-ssh
- *kardorf-ssh
+8
View File
@@ -36,3 +36,11 @@ ssh-to-age < /etc/ssh/ssh_host_ed25519_key.pub
#+begin_src sh
sops updatekeys secrets/*
#+end_src
* Installation of builder
- Start recent nixos installer in VM
- Set password for root
#+begin_src sh
nix run github:nix-community/nixos-anywhere -- --flake git+https://gitlab.julian-mutter.de/julian/dotfiles.git#builder --target-host root@<ip>
#+end_src
+1 -1
View File
@@ -11,7 +11,7 @@
LC_NUMERIC = "en_US.UTF-8";
LC_PAPER = "de_DE.UTF-8";
LC_TELEPHONE = "de_DE.UTF-8";
LC_TIME = "de_DE.UTF-8";
LC_TIME = "en_GB.UTF-8"; # english weekdays, but 24h format
};
# Keymap
+4 -2
View File
@@ -6,8 +6,10 @@
# Setup binary caches
nix.settings = {
substituters = [
# high priority since it's almost always used
"https://cache.nixos.org?priority=10"
"https://nix-community.cachix.org"
"https://cache.nixos.org/"
"https://hyprland.cachix.org"
# "http://binarycache.julian-mutter.de"
"https://devenv.cachix.org"
@@ -16,7 +18,7 @@
trusted-public-keys = [
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
"hyprland.cachix.org-1:a7pgxzMz7+chwVL3/pzj6jIBMioiJM7ypFP8PwtkuGc="
"binarycache.julian-mutter.de:oJ67uRFwRhNPKL58CHzy3QQLv38Kx7OA1K+6xlEPu7E="
"binarycache.julian-mutter.de:7RB4Sif4WQU76XWIsRJ2KtKa45zg1QOTHEkUhi/JBe8="
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"devenv.cachix.org-1:w1cLUi8dv3hnoSPGAuibQv+f9TZLr6cv/Hm9XgU50cw="
"noctalia.cachix.org-1:pCOR47nnMEo5thcxNDtzWpOxNFQsBRglJzxWPp3dkU4="
+49
View File
@@ -0,0 +1,49 @@
# Host hydra
{...}: {
services.hydra = {
enable = true;
hydraURL = "http://hydra.julian-mutter.de"; # externally visible URL
port = 3000;
notificationSender = "hydra@julian-mutter.de"; # e-mail of hydra service
# a standalone hydra will require you to unset the buildMachinesFiles list to avoid using a nonexistant /etc/nix/machines
# buildMachinesFiles = [ ];
# you will probably also want, otherwise *everything* will be built from scratch
useSubstitutes = true;
minimumDiskFree = 5; # in GB
minimumDiskFreeEvaluator = 4; # in GB
};
# Uris allowed as flake inputs, otherwise hydra does not fetch them
nix.settings.allowed-uris = [
"github:"
"gitlab:"
"git+https://github.com/hyprwm/Hyprland"
"https://github.com/hyprwm/Hyprland"
"https://github"
"https://gitlab"
"https://gitlab.julian-mutter.de"
"git+https://gitlab.julian-mutter.de"
];
services.nginx = {
enable = true;
recommendedProxySettings = true;
# recommendedTlsSettings = true;
# other Nginx options
virtualHosts."hydra.julian-mutter.de" = {
# enableACME = true;
# forceSSL = true;
locations."/" = {
proxyPass = "http://127.0.0.1:3000";
# proxyWebsockets = true; # needed if you need to use WebSocket
# extraConfig =
# # required when the target is also TLS server with multiple hosts
# "proxy_ssl_server_name on;" +
# # required when the server wants to use HTTP Authentication
# "proxy_pass_header Authorization;"
# ;
};
};
};
}
+52
View File
@@ -0,0 +1,52 @@
# Setup the device as a jenkins agent
{pkgs, ...}: {
services.openssh = {
enable = true;
# require public key authentication for better security
settings.PasswordAuthentication = false;
settings.KbdInteractiveAuthentication = false;
settings.PermitRootLogin = "yes";
# Add older algorithms for jenkins ssh-agents-plugin to be compatible
settings.Macs = [
"hmac-sha2-512-etm@openssh.com"
"hmac-sha2-256-etm@openssh.com"
"umac-128-etm@openssh.com"
"hmac-sha2-512"
"hmac-sha2-256"
"umac-128@openssh.com"
];
settings.KexAlgorithms = [
"diffie-hellman-group-exchange-sha1"
"diffie-hellman-group14-sha1"
"mlkem768x25519-sha256"
"sntrup761x25519-sha512"
"sntrup761x25519-sha512@openssh.com"
"curve25519-sha256"
"curve25519-sha256@libssh.org"
"diffie-hellman-group-exchange-sha256"
];
};
users.users.jenkins = {
createHome = true;
home = "/var/lib/jenkins";
group = "jenkins";
isNormalUser = true;
openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ36sQhVz3kUEi8754G7r3rboihhG4iqFK/UvQm6SING jenkins@home"
];
packages = with pkgs; [
git
devenv
];
extraGroups = [
"docker"
];
};
users.groups.jenkins = {};
programs.java = {
enable = true;
package = pkgs.jdk21; # Same as jenkins version on home
};
}
+18
View File
@@ -0,0 +1,18 @@
{
config,
pkgs,
...
}: {
environment.systemPackages = with pkgs; [
kubectl
k9s
];
sops.secrets.kubeconfig = {
sopsFile = ./kubeconfig.secret.yaml;
format = "binary";
owner = config.users.users.julian.name;
group = config.users.users.julian.group;
};
environment.variables.KUBECONFIG = config.sops.secrets."kubeconfig".path;
}
@@ -0,0 +1,22 @@
{
"data": "ENC[AES256_GCM,data:nq2czkXqOhjRECF9kASPiBCiz1I7LQLljTV+LkrBp4+BH92YTV6ywRyerNoTDmaBmnY+fuhdnPkN7Q9jjT1SNGLIxBG4b6gOpzgr3amhfNAW3MAUUcPuqNsk0EZ4ZJiUluPCvRtAKHyXsrQpN8P04Rg0OjHoxCrOgKjmODr14QNiQH4RAONSai76dRgRBMQs0PIzcAiMSkwKc0OgBYTccSspV7DlulA3ngv0LuUavKS6QoJ4DuCnFgOu5KHGLQS0ww+Ijp1wAx/4/tq8Iimdn968uvzFjrZATb3bHVjHSR/cbNRCJn6GrpqFCNdpI5OPw3P9f9rodXZKai/bESu2aC8Dlya2by29lCPHkg5lp6atZA8ksnj9brYsFUb6xKPUAPGDElBaUEf+LidsZlI6hAz98/uf3bwyqq22+gMkfKUM1pX1YOtyTq+5eMSn0kBuSVupvEDJaO/G/YlTUDvJL0CzwO0hLzzotLrGcqhvYqjHCr2XhIER+YgYA7D22iml5YOLRxp5RQd3sj74hUGWJkGq1p/uhniaOvrjF0zmQsqHFC4+jUNBKVMVVTLBX/AdL45Lv+HDM4jYCvtNIKAGtTGT71cplhBI2xP1s607NiIbUsSY+2qayh3INOP7qGWwpYquYe/xAk6KZMu1/UuvneVqOjqlcJFOpLqydPnP0oQRy1dtCcJsvT5nv0QEI+Tr24Dbn3tX8fmc8EzZwpmEyHto7nYzHFicgvmYavmTHkmbzySDMI03ktZ7EdM0unlNe9EmR8YyGeg7tmG4bKx9K+7qs0Piqq03gHwN9L92O80J8jiKu8MDURWywYPYHUmCKYbkHh5en1qvyFTU7dDI7L+gdp9+VSqJrkQqPbWAouMBlLE0664lTpzmYQOXWo8riwjYPllkd8EqCaKxrMMHp4Y46X69lsZS1mImuHac3xJV57r6A+mMJajGW92KI13416rwG9sXS1ynNdBTi9+P/1f3Sy8B6ypYa1BP/6+tHqghNAuz5aaKZJnsCWYMAk6y5AuFaZ2ZkO1ruSfdPmyjKoMcp/qO5nmHxF+0h+teSuvLeCb7KrL80IlKElgDINlPYHDVtaoYVv4sZAWhSNJSOUWRbue3bJaqhKz3xOdq5lJy7H3P+MQF8YFgoY7Po4EcXqTP8Upm3tIehPr7BJXNIv6beDPwpMZrvVKqVIgsXD85DqyA1Mh7k5gQpB4uAhZfRUQ8T4reVumjOnGakXh+1DcFPYJumScCP1/68btIYGYJiPJTJhL7/U+12siGzzXXZeaJ7NpCzpvpgmFvoMfV+gFgrAUkb2+eSeEI6BNRjfXWc5NM03RQqotqW4E3Ui+gYbwU0D9/8b5UsRc4IiujnZFSKbCZGGHm79Yrm8IhtTuVyQV67/NeuRfIcJuPPmYGS8nnX8v7pymlagm/43sFHpupsrgeVStsLl1asKJanA6Njus/YA3zrdmgKb1kMK6ALBc73WaT9S+4aZeKB8A6jA5PD2GAgW/T5jaHxi0VPisg0eChKtJfhJVFoZFE+U2fx2YrTeC/joSdS4jqTKaqwDgJ19d5Wvs8ZDQDjHo5I8uUArWODTW/H8An9zp8jsEN6bS1mBeta8qhkz2v9diBUFwmDvmGNX5REirrm3bkqWF2xx6NEiDARTUVAf+fh9VQaQQKK2sQ35zjaAbI4aXmDTI9vy8aFs+6MvJ/iiIwKkjVgZYmyiUVtHy6ZRGwdzgpuOAcoYRxGHaDYIEL33nDQclLmgUwWAfbc0bTI1rvaIzZ25nZ6n4aFFtpANJHTtYeMrAAl1Sho0dio6clM7/k4XST5GA4BqDlRs/Oze4yNjjQb5WoYrBCFEuVcypvRBmLEbM3XOK1sHdQAEAqey/ZfhfNhAVeapVw3ir4E2jsX9pAqlTjH4YkrIURhG05yPb2D3+WMKGAoC4yyusd7siz6tJ4uXvFXkTeOjXMM/Xo/dBnm2J1FPHr9msELIxhtG046/m+I/MEaF6Hg9XC2CZrlxi5OsH61PGBOLLNVFiQ8NaPChHRppQEH1y1GSN+5FinxTK0R5GS3PxN15NZXjmMsj+ixYmbWjkJJXn2bDM7Muv7PRetpcMhU0UIr75+6MWbwPy6v62IsDoQCOslnQVbGc/oHY47EoZ7lKbuulP0ZvQOQxGNvcOtbVc0dJHdFUTgrPxpkCyOQ4NGSLSah1qzDP5j4Fq4ag+OdITPQpDdX6TkiufGfFqq7C5GNHDK8olYKGwH3D0GCGT8o9pFx+FIeRapaWJHkcPibDMyu3KumRy04HF1ih2Z6IoWFHa532pgsK9FlAMGHeqtL/LXWZKtLONR6wNU8DxfbIhV+lUlvbbs27VMj0VHXMXdYnbvGvXOPkb4iP4Pm+HQU4AF3ROA7rtWtrL401Qpdbln5qLEWz9hKCXbM1MbvpGvNvHKckKAWpKmCsVWY8oPCNOqqWAZF5sfrlLb4fULOXg0YQCeobo3O9DZjPf/D/ki6OX5KEgYlqikKdd9hR1d5koyt0bunuFHty2guh8oaUsPjJbcuSCLz80HND9j12msuG13qFWvf77rUiE3WZ5aTSGWh7VB/lUofuEn+aTaGBK7iLAj2PU+/YQUmEFAWaIXOdq7fumHgVdsBRThXvqf7RHD+ZkpMq3D0wsnCwIgCGvxH76ah1wZzPm0lg/tecL294e8ICDuQw+pyOVj96vMdiNF31ADd1BZCO505Y7jsEFdJCJvCGXNNvTr+ir4Vh9RdwBOXxxpX9DcQaaruVQ9nCty/ikBJ04Qok6ZVV8XXbN+HNu8iGVpLNrj1E1rRAJmeqfKiDuiG6ABqLDtq9beMS9K2xhKvwjG/z+AD3v6djipkdYjjlDOV6WNxWWv74LlzjSC9Se9ERATZfCj5U06LHO1yg8y+uIvRyoWIEaAFG7aFrEvfDH6OfzbhutGDMoxBThzKhxPDq9pm/N4cBcoRwGKgrlYmjLIl5Full/ArbLN1C6EXABn9Bu6lL7VrhwSj+HC0sp1vJb3ECmvtD7lzZsqejf4p6P/FPKLHUBNVr6sTJ9fHtOaYFi7DxQONqM/yoPBLB/TeZnB0KFFfKkCNM7YDOZjQ/UZscOZxztcYc7TeQ8dA0ZUfto=,iv:ZgZWZAQZmYUs0EqZuoTCTWQ52CnuSTS+zdIuIA1UNOM=,tag:vbI3RDpvU+X1xQo+lT7WbA==,type:str]",
"sops": {
"age": [
{
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSAvMVNBZDd4VndET2pMVjVr\nNkw4aW9HckJXYU0yREoyZ09oZ3JKSVlsQ3c4CkFRWURVN2tmOXNTZHhOdS91QW5a\nRlhhSDI3c2dHVVlTLzB3NjA4c1J2UncKLS0tIHFaL21rRWNpeGlqd0pIaXU5WFRP\neTZSOHpBTTE3ZjFIbXRuSnJjdlEwSXcKqWIxCnWJvE058ojm2RrwzXkTWQLZbE7L\nXPisgwudwY+vFaTziubbPp/U9P3LXs3oFhPSqgiuCkDNLETFkpw1ng==\n-----END AGE ENCRYPTED FILE-----\n",
"recipient": "age1ee5udznhadk6m7jtglu4709rep080yjyd2ukzdl8jma4mm92y3psv0slpg"
},
{
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBHZHc0TzJKNzBUSG9GajVr\nazFWSS96Z3VXdDZOM2hPdVB4QTRhOEtVNDNRCmJkWm1TUGRwb0hpS1BBWm5WcURx\nQ21idzVZZzR5U0o3eDM1NmwySFpGQzAKLS0tIG51ZndsSDI1N2M4b280SW53eEF0\nMStNSU9odzRhY05SL05RYWlpaUlFQUkKoxVqeqZ9xAR4+JMcJXdEq0cq2CkZz63/\nSjwNDdCHjePc62yj5Qyw15zLrL2t7jvLUG44kPUbDuOIVwMH2KV2hQ==\n-----END AGE ENCRYPTED FILE-----\n",
"recipient": "age1q8lc5340gz5xw2f57nglrss68wv0j0hf36py2pdtrl6ky3yrq9qqk0njr4"
},
{
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBYd1ZJTUtLbzY4d1hSRDA1\ndHdRQnhhUHVFMDJVOUQ0VFZCeW40S0lFODBJCmFvRSsyRkI3MDFGeDdkeGRSTVh5\nTEdwQTBWVVlwSjZHWXpoN0xzb0tuR1kKLS0tIEpvVU0rVTRWQUxLNW9zMFo3cVBr\ncGYxemF6MHlBS1dqSXM3aXRTZmdHQWMKjEcJJXRKCber6afB11j1VmWM3dObm45u\nkZ+E3bK1zd/L6YoLr1jF7GP9b62GjTG9Qv1M/JdKM4qlY//GmW6IIQ==\n-----END AGE ENCRYPTED FILE-----\n",
"recipient": "age15lxw97z03q40xrdscnxqqugh5ky5aqrerg2t2rphkcqm6rnllurq8v98q5"
}
],
"lastmodified": "2026-06-18T18:37:59Z",
"mac": "ENC[AES256_GCM,data:UXFXrUrbmyp+MnBNDKKr4FP0WFhWH97W68KXlE/UzEvBVpeHste92UPzdX4FMk2rEd7ldsMcTV9hmRavWI5v/Y/y/hzuhdCkqsYfnixS15Z9PrfuFX6YjrpeoJ84s1itmhjimKe4mmXt/aND8DLJ49rQ/A1hebJ2UndBlsRIGmc=,iv:YJPVWuajQ0tzhuoIBcWw8Wy5IBy+HC0JcR69gelGzGM=,tag:YW0STCsswNaqjKBta1OwyQ==,type:str]",
"version": "3.13.1"
}
}
Generated
+770 -208
View File
File diff suppressed because it is too large Load Diff
+3 -3
View File
@@ -9,9 +9,10 @@
impermanence.url = "github:nix-community/impermanence";
deploy-rs.url = "github:serokell/deploy-rs";
# For latest noctalia version
noctalia = {
url = "github:noctalia-dev/noctalia-shell";
inputs.nixpkgs.follows = "nixpkgs";
url = "github:noctalia-dev/noctalia/cachix";
# inputs.nixpkgs.follows = "nixpkgs";
};
stylix = {
@@ -52,7 +53,6 @@
};
nixvim = {
url = "github:nix-community/nixvim/nixos-26.05";
inputs.nixpkgs.follows = "nixpkgs";
};
nix-matlab = {
url = "gitlab:doronbehar/nix-matlab";
+27 -20
View File
@@ -4,15 +4,7 @@
config,
lib,
...
}: let
# Apply lib.mkDefault to a whole attrset recursively, used for the noctalia config
mkDefaultsRec = value:
if builtins.isAttrs value
then lib.mapAttrs (_: mkDefaultsRec) value
else if builtins.isList value
then map mkDefaultsRec value
else lib.mkDefault value;
in {
}: {
imports = [
# inputs.hyprland.homeManagerModules.default
# ./waybar
@@ -27,7 +19,7 @@ in {
./waypipe.nix
# ./hyprbars.nix
inputs.noctalia.homeModules.default
# inputs.noctalia.homeModules.default # Use for latest version from inputs
];
xdg.portal = {
@@ -47,16 +39,17 @@ in {
size = 24;
};
programs.imv.enable = true; # TODO: what is that
# noctalia-shell ipc call state all | jq .settings | xclip
xdg.configFile."noctalia/settings.json".source = ./noctalia.json;
programs.noctalia-shell = {
enable = true;
# noctalia-shell ipc call state all | jq .settings | xclip
# mkDefaultsRec used so that stylix can overwrite style options
settings = mkDefaultsRec (builtins.fromJSON (builtins.readFile ./noctalia.json));
};
# programs.noctalia = {
# enable = true;
# # noctalia config export full > noctalia.toml
# settings = ./noctalia.toml;
# };
home.packages = with pkgs; [
unstable.noctalia-shell # Use for stable version instead of latest from the input
hyprpicker
hyprcursor
brightnessctl
@@ -67,9 +60,13 @@ in {
wf-recorder
wl-clipboard
(pkgs.writeShellScriptBin "toggle-screen-mirroring" (
builtins.readFile ./toggle-screen-mirroring.sh
))
(pkgs.writeShellScriptBin "toggle-screen-mirroring"
(
builtins.replaceStrings
["@INTERNAL_MONITOR@" "@EXTERNAL_MONITOR@"]
[(builtins.elemAt config.monitors 0).name (builtins.elemAt config.monitors 1).name]
(builtins.readFile ./toggle-screen-mirroring.sh)
))
(pkgs.writeShellScriptBin "correct-workspace-locations" (
lib.concatStringsSep "\n" (
@@ -107,6 +104,7 @@ in {
local terminal = "${config.terminal}"
local fileManager = "pcmanfm"
-- local menu = "wofi --show drun,run"
-- local menu = "noctalia msg panel-toggle launcher"
local menu = "noctalia-shell ipc call launcher toggle"
local calculator = "qalculate-gtk"
local browser = "firefox"
@@ -114,6 +112,15 @@ in {
''
+ "-- Main config from `hyprland.lua`\n"
+ builtins.readFile ./hyprland.lua
+ "-- Monitor config\n"
+ lib.concatStringsSep "\n" (
map (
monitor: "hl.monitor({ output = \"${monitor.name}\", mode = \"preferred\", position = \"auto\", scale = \"auto\", mirror = \"\"})"
)
config.monitors
)
+ "\n-- For plugging in random monitors\n"
+ "hl.monitor({ output = \"\", mode = \"preferred\", position = \"auto\", scale = \"auto\", mirror = \"\"})\n"
+ "-- Assign workspaces to monitors\n"
+ lib.concatStringsSep "\n" (
builtins.concatLists (
+3 -45
View File
@@ -1,16 +1,3 @@
------------------
---- MONITORS ----
------------------
-- See https://wiki.hypr.land/Configuring/Basics/Monitors/
hl.monitor({
output = "",
mode = "preferred",
position = "auto",
scale = "auto",
mirror = "",
})
-------------------
---- AUTOSTART ----
-------------------
@@ -18,7 +5,7 @@ hl.monitor({
-- See https://wiki.hypr.land/Configuring/Basics/Autostart/
hl.on("hyprland.start", function()
-- hl.exec_cmd("waybar")
hl.exec_cmd("noctalia-shell")
hl.exec_cmd("env QT_QPA_PLATFORMTHEME=qt5ct noctalia-shell") -- env ensures noctalia works alongside kde
hl.exec_cmd("firefox")
end)
hl.on("config.reloaded", function()
@@ -84,7 +71,7 @@ hl.config({
},
animations = {
enabled = true,
enabled = false,
},
misc = {
@@ -98,34 +85,6 @@ hl.config({
},
})
-- Default curves and animations, see https://wiki.hypr.land/Configuring/Advanced-and-Cool/Animations/
hl.curve("easeOutQuint", { type = "bezier", points = { { 0.23, 1 }, { 0.32, 1 } } })
hl.curve("easeInOutCubic", { type = "bezier", points = { { 0.65, 0.05 }, { 0.36, 1 } } })
hl.curve("linear", { type = "bezier", points = { { 0, 0 }, { 1, 1 } } })
hl.curve("almostLinear", { type = "bezier", points = { { 0.5, 0.5 }, { 0.75, 1 } } })
hl.curve("quick", { type = "bezier", points = { { 0.15, 0 }, { 0.1, 1 } } })
-- Default springs
hl.curve("easy", { type = "spring", mass = 1, stiffness = 71.2633, dampening = 15.8273644 })
hl.animation({ leaf = "global", enabled = false })
hl.animation({ leaf = "border", enabled = true, speed = 5.39, bezier = "easeOutQuint" })
hl.animation({ leaf = "windows", enabled = true, speed = 4.79, spring = "easy" })
hl.animation({ leaf = "windowsIn", enabled = true, speed = 4.1, spring = "easy", style = "popin 87%" })
hl.animation({ leaf = "windowsOut", enabled = true, speed = 1.49, bezier = "linear", style = "popin 87%" })
hl.animation({ leaf = "fadeIn", enabled = true, speed = 1.73, bezier = "almostLinear" })
hl.animation({ leaf = "fadeOut", enabled = true, speed = 1.46, bezier = "almostLinear" })
hl.animation({ leaf = "fade", enabled = true, speed = 3.03, bezier = "quick" })
hl.animation({ leaf = "layers", enabled = true, speed = 3.81, bezier = "easeOutQuint" })
hl.animation({ leaf = "layersIn", enabled = true, speed = 4, bezier = "easeOutQuint", style = "fade" })
hl.animation({ leaf = "layersOut", enabled = true, speed = 1.5, bezier = "linear", style = "fade" })
hl.animation({ leaf = "fadeLayersIn", enabled = true, speed = 1.79, bezier = "almostLinear" })
hl.animation({ leaf = "fadeLayersOut", enabled = true, speed = 1.39, bezier = "almostLinear" })
hl.animation({ leaf = "workspaces", enabled = true, speed = 1.94, bezier = "almostLinear", style = "fade" })
hl.animation({ leaf = "workspacesIn", enabled = true, speed = 1.21, bezier = "almostLinear", style = "fade" })
hl.animation({ leaf = "workspacesOut", enabled = true, speed = 1.94, bezier = "almostLinear", style = "fade" })
hl.animation({ leaf = "zoomFactor", enabled = true, speed = 7, bezier = "quick" })
-- Ref https://wiki.hypr.land/Configuring/Basics/Workspace-Rules/
-- "Smart gaps" / "No gaps when only"
hl.workspace_rule({ workspace = "w[tv1]", gaps_out = 0, gaps_in = 0 })
@@ -147,8 +106,7 @@ hl.config({
hl.config({
misc = {
force_default_wallpaper = -1, -- Set to 0 or 1 to disable the anime mascot wallpapers
disable_hyprland_logo = false, -- If true disables the random hyprland logo / anime girl background. :(
disable_hyprland_logo = true, -- If true disables the random hyprland logo / anime girl background. :(
},
})
@@ -0,0 +1,628 @@
[audio]
enable_overdrive = true
enable_sounds = false
notification_sound = ""
sound_volume = 0.5
volume_change_sound = ""
[backdrop]
blur_intensity = 0.5
enabled = false
tint_intensity = 0.30000001192092896
[bar]
order = [ "widgets" ]
[bar.widgets]
auto_hide = false
background_opacity = 1.0
border = "outline"
border_width = 0.0
capsule = false
capsule_fill = "surface_variant"
capsule_group = []
capsule_opacity = 1.0
capsule_padding = 6.0
capsule_thickness = 0.75999999046325684
center = []
contact_shadow = false
enabled = true
end = [
"cpu",
"ram",
"sysmon",
"network_rx",
"network_tx",
"volume",
"battery",
"clock",
"network",
"clipboard",
"tray"
]
font_weight = 500
layer = "top"
margin_edge = 0
margin_ends = 0
margin_opposite_edge = 0
padding = 14
panel_overlap = 1
position = "bottom"
radius = 0
radius_bottom_left = 0
radius_bottom_right = 0
radius_top_left = 0
radius_top_right = 0
reserve_space = true
scale = 1.0
shadow = false
show_on_workspace_switch = true
start = [ "workspaces" ]
thickness = 34
widget_spacing = 12
[bar.widgets.dead_zone]
command = ""
middle_command = ""
right_command = ""
scroll_down_command = ""
scroll_up_command = ""
[battery]
warning_threshold = 10
[brightness]
enable_ddcutil = false
ignore_mmids = []
minimum_brightness = 0.0
sync_all_monitors = false
[calendar]
enabled = false
refresh_minutes = 15
[control_center]
hidden_tabs = []
sidebar = "full"
sidebar_section = "full"
width = 700
[[control_center.shortcuts]]
type = "wifi"
[[control_center.shortcuts]]
type = "bluetooth"
[[control_center.shortcuts]]
type = "caffeine"
[[control_center.shortcuts]]
type = "nightlight"
[[control_center.shortcuts]]
type = "notification"
[[control_center.shortcuts]]
type = "power_profile"
[desktop_widgets]
enabled = false
schema_version = 2
[desktop_widgets.grid]
cell_size = 16
major_interval = 4
visible = true
[dock]
active_monitor_only = false
active_opacity = 1.0
active_scale = 1.0
auto_hide = false
background_opacity = 0.87999999523162842
cross_axis_padding = 8
enabled = false
icon_size = 48
inactive_opacity = 0.85000002384185791
inactive_scale = 0.85000002384185791
item_spacing = 6
launcher_icon = "grid-dots"
launcher_position = "none"
magnification = true
magnification_scale = 1.4500000476837158
main_axis_padding = 16
margin_edge = 8
margin_ends = 0
monitors = []
pinned = []
position = "bottom"
radius = 16
radius_bottom_left = 16
radius_bottom_right = 16
radius_top_left = 16
radius_top_right = 16
reserve_space = true
shadow = true
show_dots = false
show_instance_count = true
show_running = true
[hooks]
battery_charging = []
battery_discharging = []
battery_percentage_changed = []
battery_plugged = []
bluetooth_disabled = []
bluetooth_enabled = []
colors_changed = []
logging_out = []
power_profile_changed = []
rebooting = []
session_locked = []
session_unlocked = []
shutting_down = []
started = []
theme_mode_changed = []
wallpaper_changed = []
wifi_disabled = []
wifi_enabled = []
[idle]
behavior_order = [ "lock", "screen-off", "lock-and-suspend" ]
pre_action_fade_seconds = 0.0
[idle.behavior.lock]
action = "lock"
command = ""
enabled = false
resume_command = ""
timeout = 600.0
[idle.behavior.lock-and-suspend]
action = "lock_and_suspend"
command = ""
enabled = false
resume_command = ""
timeout = 900.0
[idle.behavior.screen-off]
action = "screen_off"
command = ""
enabled = false
resume_command = ""
timeout = 660.0
[keybinds]
cancel = [ "Escape" ]
down = [ "Down" ]
left = [ "Left" ]
right = [ "Right" ]
tab_next = [ "Tab" ]
tab_previous = [ "Shift+ISO_Left_Tab" ]
up = [ "Up" ]
validate = [ "Return", "KP_Enter", "space" ]
[location]
address = "Würzburg, Germany"
auto_locate = false
sunrise = ""
sunset = ""
[lockscreen]
allow_empty_password = false
blur_intensity = 0.5
blurred_desktop = false
enabled = false
fingerprint = true
monitors = []
tint_intensity = 0.30000001192092896
wallpaper = ""
[lockscreen_widgets]
enabled = false
schema_version = 2
widget_order = [ "lockscreen-login-box@HDMI-A-1", "lockscreen-login-box@eDP-1" ]
[lockscreen_widgets.grid]
cell_size = 16
major_interval = 4
visible = true
[lockscreen_widgets.widget."lockscreen-login-box@HDMI-A-1"]
box_height = 70.0
box_width = 400.0
cx = 960.0
cy = 961.0
enabled = true
output = "HDMI-A-1"
rotation = 0.0
type = "login_box"
[lockscreen_widgets.widget."lockscreen-login-box@HDMI-A-1".settings]
background_color = "surface_variant"
background_opacity = 0.88
background_radius = 12.0
input_opacity = 1.0
input_radius = 6.0
show_caps_lock = true
show_keyboard_layout = true
show_login_button = true
show_password_hint = true
[lockscreen_widgets.widget."lockscreen-login-box@eDP-1"]
box_height = 70.0
box_width = 400.0
cx = 960.0
cy = 961.0
enabled = true
output = "eDP-1"
rotation = 0.0
type = "login_box"
[lockscreen_widgets.widget."lockscreen-login-box@eDP-1".settings]
background_color = "surface_variant"
background_opacity = 0.88
background_radius = 12.0
input_opacity = 1.0
input_radius = 6.0
show_caps_lock = true
show_keyboard_layout = true
show_login_button = true
show_password_hint = true
[nightlight]
enabled = false
force = false
temperature_day = 6500
temperature_night = 4000
[notification]
background_opacity = 0.97000002861022949
collapse_on_dismiss = true
enable_daemon = false
layer = "top"
monitors = []
offset_x = 20
offset_y = 8
position = "top_right"
scale = 1.0
show_actions = true
show_app_name = true
[osd]
background_opacity = 0.97000002861022949
monitors = []
offset_x = 20
offset_y = 8
orientation = "horizontal"
position = "top_center"
position_vertical = "top_center"
scale = 1.0
[osd.kinds]
bluetooth = false
brightness = false
caffeine = false
dnd = false
keyboard_layout = false
lock_keys = false
media = false
nightlight = false
power_profile = false
privacy = false
volume = false
volume_input = true
volume_output = true
wifi = false
[plugins]
enabled = []
[[plugins.source]]
auto_update = false
enabled = true
kind = "git"
location = "https://github.com/noctalia-dev/official-plugins"
name = "official"
[[plugins.source]]
auto_update = false
enabled = true
kind = "git"
location = "https://github.com/noctalia-dev/community-plugins"
name = "community"
[shell]
app_icon_colorize = false
avatar_path = ""
clipboard_auto_paste = "auto"
clipboard_confirm_clear_history = true
clipboard_enabled = true
clipboard_history_max_entries = 100
clipboard_image_action_command = ""
corner_radius_scale = 1.0
date_format = "%A, %x"
disable_mipmaps = false
font_family = "sans-serif"
launch_apps_as_systemd_services = false
launch_apps_custom_command = ""
middle_click_opens_widget_settings = true
niri_overview_type_to_launch_enabled = false
offline_mode = false
password_style = "default"
polkit_agent = false
screen_time_enabled = false
settings_show_advanced = false
setup_wizard_enabled = true
shared_gl_context = true
show_location = true
telemetry_enabled = false
time_format = "{:%H:%M}"
ui_scale = 1.0
[shell.animation]
enabled = false
speed = 1.0
[shell.greeter_sync]
auto_sync = false
[shell.launcher]
app_grid = false
categories = true
compact = true
session_search = false
show_icons = true
sort_by_usage = true
[shell.launcher.dmenu]
[shell.mpris]
blacklist = []
[shell.panel]
borders = true
clipboard_placement = "attached"
clipboard_position = "center"
control_center_placement = "attached"
control_center_position = "auto"
floating_offset = 13
launcher_placement = "floating"
launcher_position = "center"
open_near_click_clipboard = true
open_near_click_control_center = true
open_near_click_launcher = false
open_near_click_session = true
open_near_click_wallpaper = true
polkit_placement = "floating"
polkit_position = "center"
session_placement = "attached"
session_position = "auto"
shadow = true
transparency_mode = "solid"
wallpaper_placement = "attached"
wallpaper_position = "auto"
[shell.privacy]
cam_filter_regex = ""
mic_filter_regex = ""
[shell.screen_corners]
enabled = false
size = 32
[shell.screenshot]
confirm_region = false
copy_to_clipboard = true
directory = ""
filename_pattern = ""
freeze_screen = true
pipe_command = ""
pipe_to_command = false
save_to_file = true
[shell.session.power]
[[shell.session.actions]]
action = "lock"
command = ""
countdown_seconds = 0.0
enabled = true
glyph = ""
label = ""
shortcut = "1"
variant = "default"
[[shell.session.actions]]
action = "logout"
command = ""
countdown_seconds = 0.0
enabled = true
glyph = ""
label = ""
shortcut = "2"
variant = "default"
[[shell.session.actions]]
action = "lock_and_suspend"
command = ""
countdown_seconds = 0.0
enabled = false
glyph = ""
label = ""
shortcut = "3"
variant = "default"
[[shell.session.actions]]
action = "reboot"
command = ""
countdown_seconds = 0.0
enabled = true
glyph = ""
label = ""
shortcut = "4"
variant = "default"
[[shell.session.actions]]
action = "shutdown"
command = ""
countdown_seconds = 0.0
enabled = true
glyph = ""
label = ""
shortcut = "5"
variant = "destructive"
[shell.shadow]
alpha = 0.55000001192092896
direction = "down"
[system.monitor]
cpu_poll_seconds = 2.0
cpu_temp_activity_threshold = 60.0
cpu_temp_critical_threshold = 85.0
cpu_temp_sensor_path = ""
cpu_usage_activity_threshold = 50.0
cpu_usage_critical_threshold = 90.0
disk_pct_activity_threshold = 80.0
disk_pct_critical_threshold = 95.0
disk_poll_seconds = 10.0
enabled = true
gpu_poll_seconds = 0.0
gpu_temp_activity_threshold = 60.0
gpu_temp_critical_threshold = 85.0
gpu_usage_activity_threshold = 50.0
gpu_usage_critical_threshold = 95.0
gpu_vram_activity_threshold = 50.0
gpu_vram_critical_threshold = 90.0
memory_poll_seconds = 2.0
net_rx_activity_threshold = 1.0
net_rx_critical_threshold = 50.0
net_tx_activity_threshold = 1.0
net_tx_critical_threshold = 50.0
network_poll_seconds = 3.0
ram_pct_activity_threshold = 60.0
ram_pct_critical_threshold = 90.0
swap_pct_activity_threshold = 20.0
swap_pct_critical_threshold = 80.0
[theme]
builtin = "Catppuccin"
community_palette = "Oxocarbon"
custom_palette = ""
mode = "dark"
source = "builtin"
wallpaper_scheme = "m3-content"
[theme.templates]
builtin_ids = []
community_ids = []
enable_builtin_templates = false
enable_community_templates = false
[wallpaper]
directory = ""
directory_dark = ""
directory_light = ""
edge_smoothness = 0.30000001192092896
enabled = false
fill_color = ""
fill_mode = "crop"
per_monitor_directories = false
transition = [ "fade", "wipe", "disc", "stripes", "zoom", "honeycomb" ]
transition_duration = 1500.0
transition_on_startup = false
[wallpaper.automation]
enabled = false
interval_seconds = 1800
order = "random"
recursive = true
[weather]
effects = true
enabled = true
refresh_minutes = 30
unit = "metric"
[widget.active_window]
icon_size = 14.0
max_length = 260.0
min_length = 80.0
title_scroll = "none"
type = "active_window"
[widget.clock]
format = "{:%a %d.%m. %H:%M:%S}"
type = "clock"
[widget.cpu]
display = "text"
stat = "cpu_usage"
type = "sysmon"
[widget.custom_button_2]
type = "custom_button"
[widget.date]
format = "{:%a %d %b}"
type = "clock"
[widget.input_volume]
device = "input"
type = "volume"
[widget.keyboard_layout]
cycle_command = ""
hide_when_single_layout = false
type = "keyboard_layout"
[widget.lock_keys]
display = "short"
hide_when_off = false
show_caps_lock = true
show_num_lock = true
show_scroll_lock = false
type = "lock_keys"
[widget.media]
art_size = 16.0
max_length = 220.0
min_length = 80.0
title_scroll = "none"
type = "media"
[widget.network_rx]
display = "text"
stat = "net_rx"
type = "sysmon"
[widget.network_tx]
display = "text"
stat = "net_tx"
type = "sysmon"
[widget.output_volume]
device = "output"
type = "volume"
[widget.ram]
display = "text"
stat = "ram_pct"
type = "sysmon"
[widget.spacer]
type = "spacer"
[widget.sysmon]
display = "text"
stat = "disk_pct"
type = "sysmon"
[widget.temp]
stat = "cpu_temp"
type = "sysmon"
[widget.workspaces]
scale = 1.1000000000000001
type = "workspaces"
@@ -2,18 +2,17 @@
# A hyprland script for a laptop-external-monitor setup, toggling between which is in use
# TODO: Detect these instead of hardcoding them
INTERNAL_MONITOR="eDP-1"
EXTERNAL_MONITOR="HDMI-A-1"
INTERNAL_MONITOR="@INTERNAL_MONITOR@"
EXTERNAL_MONITOR="@EXTERNAL_MONITOR@"
MIRROR_SETTING=$(hyprctl monitors all -j | jq -r '.[] | select(.name == "HDMI-A-1") | .mirrorOf')
MIRROR_SETTING=$(hyprctl monitors all -j | jq -r --arg EXTERNAL "$EXTERNAL_MONITOR" '.[] | select(.name == $EXTERNAL) | .mirrorOf')
echo "current setting: "
echo $MIRROR_SETTING
if [ "$MIRROR_SETTING" = "none" ]; then
echo "mirroring..."
hyprctl eval "hl.monitor({output=\"$EXTERNAL_MONITOR\", mode=\"preferred\", position=\"auto\", scale=\"auto\", mirror=\"$INTERNAL_MONITOR\"})"
echo "mirroring..."
hyprctl eval "hl.monitor({output=\"$EXTERNAL_MONITOR\", mode=\"preferred\", position=\"auto\", scale=\"auto\", mirror=\"$INTERNAL_MONITOR\"})"
else
# hyprctl keyword monitor "$EXTERNAL_MONITOR, disable" # shortly disable monitor so waybar recognizes the new monitor again # TODO: find better solution
hyprctl eval "hl.monitor({output=\"$EXTERNAL_MONITOR\", mode=\"preferred\", position=\"auto\", scale=\"auto\", mirror=\"\"})"
# hyprctl keyword monitor "$EXTERNAL_MONITOR, disable" # shortly disable monitor so waybar recognizes the new monitor again # TODO: find better solution
hyprctl eval "hl.monitor({output=\"$EXTERNAL_MONITOR\", mode=\"preferred\", position=\"auto\", scale=\"auto\", mirror=\"\"})"
fi
@@ -9,8 +9,6 @@
services.syncthing.tray.enable = true;
services.syncthing.tray.command = "syncthingtray --wait"; # Wait for tray to become available
gtk.gtk4.theme = null; # Fix evaluation warning since using old home manager version
programs.chromium = {
enable = true;
extensions = [
+2 -1
View File
@@ -6,7 +6,7 @@
"${pwd}/features-nixos/users/julian"
"${pwd}/features-nixos/optional/binarycaches.nix"
"${pwd}/features-nixos/optional/remote-builder.nix"
# "${pwd}/features-nixos/optional/remote-builder.nix"
"${pwd}/features-nixos/optional/boot-efi.nix"
"${pwd}/features-nixos/optional/greetd.nix"
@@ -21,6 +21,7 @@
"${pwd}/features-nixos/optional/wireguard.nix"
"${pwd}/features-nixos/optional/wireshark.nix"
"${pwd}/features-nixos/optional/flatpak.nix"
"${pwd}/features-nixos/optional/k9s"
"${pwd}/features-nixos/optional/avahi.nix"
];
+5
View File
@@ -75,4 +75,9 @@
powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
hardware.nvidia.open = false;
hardware.bluetooth = {
enable = true;
powerOnBoot = true;
};
}
+47 -187
View File
@@ -4,18 +4,37 @@
{
pwd,
config,
pkgs,
inputs,
outputs,
lib,
...
}: {
imports = [
./hardware-configuration.nix
imports =
[
inputs.disko.nixosModules.disko
"${pwd}/features-nixos/global/fish.nix" # fish for admin
"${pwd}/features-nixos/global/locale.nix"
"${pwd}/features-nixos/global/nix.nix"
"${pwd}/features-nixos/global/sops.nix"
"${pwd}/features-nixos/global/root.nix"
];
./disko.nix
./hardware-configuration.nix
"${pwd}/features-nixos/global/fish.nix" # fish for admin
"${pwd}/features-nixos/global/locale.nix"
"${pwd}/features-nixos/global/nix.nix"
"${pwd}/features-nixos/global/sops.nix"
"${pwd}/features-nixos/global/root.nix"
# "${pwd}/features-nixos/optional/hydra.nix"
# "${pwd}/features-nixos/optional/jenkins-agent.nix"
]
++ (builtins.attrValues outputs.nixosModules);
frajul.gitlab-runner = {
enable = false;
secretsFile = ./secrets.yaml;
};
frajul.gitea-runner = {
enable = true;
secretsFile = ./secrets.yaml;
};
networking.hostName = "builder";
system.stateVersion = "23.11";
@@ -66,22 +85,22 @@
fallback = true;
};
# system.autoUpgrade = {
# enable = true;
# flake = "git+https://gitlab.julian-mutter.de/julian/dotfiles";
# flags = [
# "--recreate-lock-file" # update lock file
# ];
# dates = "02:13";
# };
system.autoUpgrade = {
enable = true;
flake = "git+https://gitlab.julian-mutter.de/julian/dotfiles";
flags = [
"--recreate-lock-file" # update lock file
];
dates = "02:13";
};
# optimize store by hardlinking store files
nix.optimise.automatic = true;
nix.optimise.dates = ["03:15"];
nix.optimise.automatic = lib.mkForce true;
nix.optimise.dates = lib.mkForce ["03:15"];
# nix.gc.automatic = true;
# nix.gc.dates = "daily";
# nix.gc.options = "--delete-old";
nix.gc.automatic = lib.mkForce true;
nix.gc.dates = lib.mkForce "daily";
nix.gc.options = lib.mkForce "--delete-old";
# nix.settings.keep-derivations = false;
# nix.settings.keep-outputs = true;
@@ -101,55 +120,12 @@
OOMScoreAdjust = 500;
};
# Ollama used by open-webui as llm backend
# services.ollama = {
# enable = true;
# # acceleration = "rocm";
# openFirewall = true;
# };
# services.nextjs-ollama-llm-ui = {
# enable = true;
# hostname = "192.168.3.118";
# port = 3001;
# };
# services.open-webui = {
# enable = true;
# port = 8080;
# openFirewall = true;
# host = "builder.julian-mutter.de";
# };
networking.firewall.allowedTCPPorts = [
80
3001 # ollama-ui
];
services.openssh = {
enable = true;
# require public key authentication for better security
settings.PasswordAuthentication = false;
settings.KbdInteractiveAuthentication = false;
settings.PermitRootLogin = "yes";
# Add older algorithms for jenkins ssh-agents-plugin to be compatible
settings.Macs = [
"hmac-sha2-512-etm@openssh.com"
"hmac-sha2-256-etm@openssh.com"
"umac-128-etm@openssh.com"
"hmac-sha2-512"
"hmac-sha2-256"
"umac-128@openssh.com"
];
settings.KexAlgorithms = [
"diffie-hellman-group-exchange-sha1"
"diffie-hellman-group14-sha1"
"mlkem768x25519-sha256"
"sntrup761x25519-sha512"
"sntrup761x25519-sha512@openssh.com"
"curve25519-sha256"
"curve25519-sha256@libssh.org"
"diffie-hellman-group-exchange-sha256"
];
};
users.users."root".openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFjSZYdoF/51F+ykcBAYVCzCPTF5EEigWBL1APiR0h+H julian@aspi"
@@ -163,20 +139,6 @@
# security.pam.sshAgentAuth.enable = true; # enable sudo via ssh
services.hydra = {
enable = true;
hydraURL = "http://hydra.julian-mutter.de"; # externally visible URL
port = 3000;
notificationSender = "hydra@julian-mutter.de"; # e-mail of hydra service
# a standalone hydra will require you to unset the buildMachinesFiles list to avoid using a nonexistant /etc/nix/machines
# buildMachinesFiles = [ ];
# you will probably also want, otherwise *everything* will be built from scratch
useSubstitutes = true;
minimumDiskFree = 5; # in GB
minimumDiskFreeEvaluator = 4; # in GB
};
# add builder itpwd as build machine so system emulation is properly supported
# nix.distributedBuilds = true;
nix.buildMachines = [
@@ -199,95 +161,30 @@
}
];
# Uris allowed as flake inputs, otherwise hydra does not fetch them
nix.settings.allowed-uris = [
"github:"
"gitlab:"
"git+https://github.com/hyprwm/Hyprland"
"https://github.com/hyprwm/Hyprland"
"https://github"
"https://gitlab"
"https://gitlab.julian-mutter.de"
"git+https://gitlab.julian-mutter.de"
networking.firewall.allowedTCPPorts = [
80
];
services.nginx = {
enable = true;
recommendedProxySettings = true;
# recommendedTlsSettings = true;
# other Nginx options
virtualHosts."hydra.julian-mutter.de" = {
# enableACME = true;
# forceSSL = true;
locations."/" = {
proxyPass = "http://127.0.0.1:3000";
# proxyWebsockets = true; # needed if you need to use WebSocket
# extraConfig =
# # required when the target is also TLS server with multiple hosts
# "proxy_ssl_server_name on;" +
# # required when the server wants to use HTTP Authentication
# "proxy_pass_header Authorization;"
# ;
};
};
# nix-serve
virtualHosts."binarycache.julian-mutter.de" = {
locations."/".proxyPass = "http://${config.services.nix-serve.bindAddress}:${toString config.services.nix-serve.port}";
};
# attic
clientMaxBodySize = "2G";
virtualHosts."cache.julian-mutter.de" = {
locations."/".proxyPass = "http://127.0.0.1:8080";
};
};
# =========== Gitea actions ==========
services.gitea-actions-runner.instances."builder" = {
enable = true;
url = "https://gitlab.julian-mutter.de";
name = "builder";
tokenFile = config.sops.secrets."gitea_token".path;
labels = [
# fake the ubuntu name, because node provides no ubuntu builds
"ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest"
# my custom nix+devenv ci container
"nix-ci:docker://gitlab.julian-mutter.de/julian/nix-ci-container:latest"
# devenv
"devenv:docker://ghcr.io/cachix/devenv/devenv:latest"
# provide native execution on the host
"nixos:host"
];
# Packages are intjected into PATH for "nixos:host"
hostPackages = with pkgs; [
bash
coreutils
curl
gawk
gitMinimal
nodejs # Required by many standard actions (like actions/checkout)
wget
nix
];
};
virtualisation.docker.enable = true;
# TODO: podman fails with: "cannot resolve hostname"
# virtualisation.podman = {
# enable = true;
# dockerCompat = true;
# defaultNetwork.settings.dns_enabled = true;
# };
sops.secrets."gitea_token" = {
owner = config.users.users.nix.name;
sopsFile = ./secrets.yaml;
};
# =========== Binary Cache ==========
sops.secrets."nix_serve_key".sopsFile = ./secrets.yaml;
services.nix-serve = {
enable = true;
secretKeyFile = "/var/cache-priv-key.pem";
secretKeyFile = config.sops.secrets."nix_serve_key".path;
};
# =========== Binary Cache with attic ==========
@@ -325,41 +222,4 @@
};
};
};
services.gitlab-runner.enable = true;
# runner for everything else
#
sops.secrets."gitlab_runner_token".sopsFile = ./secrets.yaml;
services.gitlab-runner.services.default = {
# File should contain at least these two variables:
authenticationTokenConfigFile = config.sops.secrets."gitlab_runner_token".path;
dockerImage = "alpine:latest";
dockerVolumes = [
"/var/run/docker.sock:/var/run/docker.sock"
];
};
### Jenkins node
users.users.jenkins = {
createHome = true;
home = "/var/lib/jenkins";
group = "jenkins";
isNormalUser = true;
openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ36sQhVz3kUEi8754G7r3rboihhG4iqFK/UvQm6SING jenkins@home"
];
packages = with pkgs; [
git
devenv
];
extraGroups = [
"docker"
];
};
users.groups.jenkins = {};
programs.java = {
enable = true;
package = pkgs.jdk21; # Same as jenkins version on home
};
}
+56
View File
@@ -0,0 +1,56 @@
# Example to create a bios compatible gpt partition
{ lib, ... }:
{
disko.devices = {
disk.disk1 = {
device = lib.mkDefault "/dev/sda";
type = "disk";
content = {
type = "gpt";
partitions = {
boot = {
name = "boot";
size = "1M";
type = "EF02";
};
esp = {
name = "ESP";
size = "500M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
root = {
name = "root";
size = "100%";
content = {
type = "lvm_pv";
vg = "pool";
};
};
};
};
};
lvm_vg = {
pool = {
type = "lvm_vg";
lvs = {
root = {
size = "100%FREE";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
mountOptions = [
"defaults"
];
};
};
};
};
};
};
}
-30
View File
@@ -7,43 +7,13 @@
"sd_mod"
"sr_mod"
];
# boot.initrd.kernelModules = [ "amdgpu" ]; # GPU support
boot.kernelModules = [];
boot.extraModulePackages = [];
fileSystems."/" = {
device = "/dev/disk/by-uuid/f088fe8e-bf3d-4a89-98bd-ead9852d381f";
fsType = "ext4";
};
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.ens18.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
# hardware.graphics = {
# enable = true;
# extraPackages = with pkgs; [
# rocmPackages.clr.icd
# linuxPackages.amdgpu-pro
# ];
# };
# boot.kernelParams = [
# "radeon.si_support=0"
# "radeon.cik_support=1"
# "amdgpu.si_support=0"
# "amdgpu.cik_support=1"
# ];
# boot.extraModulePackages = with config.boot.kernelPackages; [ amdgpu-pro ];
# boot.blacklistedKernelModules = [ "radeon" ];
boot.loader.grub.enable = true;
boot.loader.grub.device = "/dev/sda";
# Emulated systems used as alternative to cross-compiling
boot.binfmt.emulatedSystems = ["aarch64-linux"];
File diff suppressed because one or more lines are too long
+1
View File
@@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINgH+4xJMk4K5uBIq4hKwar4wt6GYCRE3Z2S4HETc4TK root@builder
+2 -1
View File
@@ -11,7 +11,7 @@
"${pwd}/features-nixos/users/wolfi"
"${pwd}/features-nixos/optional/binarycaches.nix"
"${pwd}/features-nixos/optional/remote-builder.nix"
# "${pwd}/features-nixos/optional/remote-builder.nix"
"${pwd}/features-nixos/optional/boot-efi.nix"
"${pwd}/features-nixos/optional/greetd.nix"
@@ -26,6 +26,7 @@
"${pwd}/features-nixos/optional/podman.nix"
"${pwd}/features-nixos/optional/wireshark.nix"
"${pwd}/features-nixos/optional/flatpak.nix"
"${pwd}/features-nixos/optional/k9s"
];
networking.hostName = "kardorf";
+2
View File
@@ -3,4 +3,6 @@
syncthing = import ./syncthing.nix;
frajulAutoUpgrade = import ./frajul-auto-upgrade.nix;
pianoLEDVisualizer = import ./piano-led-visualizer.nix;
gitea-runner = import ./gitea-runner.nix;
gitlab-runner = import ./gitlab-runner.nix;
}
+57
View File
@@ -0,0 +1,57 @@
{
config,
lib,
pkgs,
...
}: let
cfg = config.frajul.gitea-runner;
in {
options = {
frajul.gitea-runner = {
enable = lib.mkEnableOption "gitea-runner";
secretsFile = lib.mkOption {
type = lib.types.path;
description = "A sops encrpyted file containing a 'gitea_token' secret";
};
};
};
config = lib.mkIf cfg.enable {
virtualisation.docker.enable = true;
sops.secrets."gitea_token" = {
owner = config.users.users.nix.name;
sopsFile = cfg.secretsFile;
};
services.gitea-actions-runner.instances."builder" = {
enable = true;
url = "https://gitlab.julian-mutter.de";
name = "builder";
tokenFile = config.sops.secrets."gitea_token".path;
labels = [
# fake the ubuntu name, because node provides no ubuntu builds
"ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest"
# my custom nix+devenv ci container
"nix-ci:docker://gitlab.julian-mutter.de/julian/nix-ci-container:latest"
# devenv
"devenv:docker://ghcr.io/cachix/devenv/devenv:latest"
# provide native execution on the host
"nixos:host"
];
# Packages are intjected into PATH for "nixos:host"
hostPackages = with pkgs; [
bash
coreutils
curl
gawk
gitMinimal
nodejs # Required by many standard actions (like actions/checkout)
docker
devenv
wget
nix
];
};
};
}
+31
View File
@@ -0,0 +1,31 @@
{
config,
lib,
...
}: let
cfg = config.frajul.gitlab-runner;
in {
options = {
frajul.gitlab-runner = {
enable = lib.mkEnableOption "gitlab-runner";
secretsFile = lib.mkOption {
type = lib.types.path;
description = "A sops encrpyted file containing a 'gitlab_runner_token' secret";
};
};
};
config = lib.mkIf cfg.enable {
services.gitlab-runner.enable = true;
sops.secrets."gitlab_runner_token".sopsFile = cfg.secretsFile;
services.gitlab-runner.services.default = {
# File should contain at least these two variables:
authenticationTokenConfigFile = config.sops.secrets."gitlab_runner_token".path;
dockerImage = "alpine:latest";
dockerVolumes = [
"/var/run/docker.sock:/var/run/docker.sock"
];
};
};
}