Compare commits
30
Commits
c61f1f6741
...
master
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
121f79e048 | ||
|
|
e85156235c | ||
|
|
e89908b592 | ||
|
|
139402db48 | ||
|
|
0bbce5c85e | ||
|
|
3fd5c34aa1 | ||
|
|
a7df51dbb8 | ||
|
|
d89b8b51cc | ||
|
|
6c301d87fd | ||
|
|
4b6c84e63d | ||
|
|
59780f39d0 | ||
|
|
48d784a964 | ||
|
|
76ad137946 | ||
|
|
de081fe38f | ||
|
|
940ea05b3f | ||
|
|
107e86d533 | ||
|
|
db11705c44 | ||
|
|
6dca04621d | ||
|
|
00ef9ef193 | ||
|
|
d923423d52 | ||
|
|
9595f16689 | ||
|
|
77c9c87624 | ||
|
|
a5ebf46d0c | ||
|
|
1bd857c1ca | ||
|
|
de10839976 | ||
|
|
ae2995e972 | ||
|
|
f494e364e1 | ||
|
|
39cac2aedb | ||
|
|
3260c774ca | ||
|
|
daf0980eb9 |
+1
-1
@@ -1,7 +1,7 @@
|
||||
keys:
|
||||
- &primary age1ee5udznhadk6m7jtglu4709rep080yjyd2ukzdl8jma4mm92y3psv0slpg
|
||||
- &aspi-ssh age1q8lc5340gz5xw2f57nglrss68wv0j0hf36py2pdtrl6ky3yrq9qqk0njr4
|
||||
- &builder-ssh age1kw4kmdm45zprvdkrrpvgq966l7585vhusmum083qlwnr0xxgd3uqatcyja
|
||||
- &builder-ssh age1vwanu6jm80jzwe78jzz7z9vuzlg94tl7rpdg34vjmxcrnhddxu9q5zaf49
|
||||
- &kardorf-ssh age15lxw97z03q40xrdscnxqqugh5ky5aqrerg2t2rphkcqm6rnllurq8v98q5
|
||||
|
||||
creation_rules:
|
||||
|
||||
@@ -36,3 +36,11 @@ ssh-to-age < /etc/ssh/ssh_host_ed25519_key.pub
|
||||
#+begin_src sh
|
||||
sops updatekeys secrets/*
|
||||
#+end_src
|
||||
|
||||
* Installation of builder
|
||||
- Start recent nixos installer in VM
|
||||
- Set password for root
|
||||
|
||||
#+begin_src sh
|
||||
nix run github:nix-community/nixos-anywhere -- --flake git+https://gitlab.julian-mutter.de/julian/dotfiles.git#builder --target-host root@<ip>
|
||||
#+end_src
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
LC_NUMERIC = "en_US.UTF-8";
|
||||
LC_PAPER = "de_DE.UTF-8";
|
||||
LC_TELEPHONE = "de_DE.UTF-8";
|
||||
LC_TIME = "de_DE.UTF-8";
|
||||
LC_TIME = "en_GB.UTF-8"; # english weekdays, but 24h format
|
||||
};
|
||||
|
||||
# Keymap
|
||||
|
||||
@@ -6,8 +6,10 @@
|
||||
# Setup binary caches
|
||||
nix.settings = {
|
||||
substituters = [
|
||||
# high priority since it's almost always used
|
||||
"https://cache.nixos.org?priority=10"
|
||||
|
||||
"https://nix-community.cachix.org"
|
||||
"https://cache.nixos.org/"
|
||||
"https://hyprland.cachix.org"
|
||||
# "http://binarycache.julian-mutter.de"
|
||||
"https://devenv.cachix.org"
|
||||
@@ -16,7 +18,7 @@
|
||||
trusted-public-keys = [
|
||||
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
|
||||
"hyprland.cachix.org-1:a7pgxzMz7+chwVL3/pzj6jIBMioiJM7ypFP8PwtkuGc="
|
||||
"binarycache.julian-mutter.de:oJ67uRFwRhNPKL58CHzy3QQLv38Kx7OA1K+6xlEPu7E="
|
||||
"binarycache.julian-mutter.de:7RB4Sif4WQU76XWIsRJ2KtKa45zg1QOTHEkUhi/JBe8="
|
||||
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
|
||||
"devenv.cachix.org-1:w1cLUi8dv3hnoSPGAuibQv+f9TZLr6cv/Hm9XgU50cw="
|
||||
"noctalia.cachix.org-1:pCOR47nnMEo5thcxNDtzWpOxNFQsBRglJzxWPp3dkU4="
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
# Host hydra
|
||||
{...}: {
|
||||
services.hydra = {
|
||||
enable = true;
|
||||
hydraURL = "http://hydra.julian-mutter.de"; # externally visible URL
|
||||
port = 3000;
|
||||
notificationSender = "hydra@julian-mutter.de"; # e-mail of hydra service
|
||||
# a standalone hydra will require you to unset the buildMachinesFiles list to avoid using a nonexistant /etc/nix/machines
|
||||
# buildMachinesFiles = [ ];
|
||||
# you will probably also want, otherwise *everything* will be built from scratch
|
||||
useSubstitutes = true;
|
||||
|
||||
minimumDiskFree = 5; # in GB
|
||||
minimumDiskFreeEvaluator = 4; # in GB
|
||||
};
|
||||
|
||||
# Uris allowed as flake inputs, otherwise hydra does not fetch them
|
||||
nix.settings.allowed-uris = [
|
||||
"github:"
|
||||
"gitlab:"
|
||||
"git+https://github.com/hyprwm/Hyprland"
|
||||
"https://github.com/hyprwm/Hyprland"
|
||||
"https://github"
|
||||
"https://gitlab"
|
||||
"https://gitlab.julian-mutter.de"
|
||||
"git+https://gitlab.julian-mutter.de"
|
||||
];
|
||||
|
||||
services.nginx = {
|
||||
enable = true;
|
||||
recommendedProxySettings = true;
|
||||
# recommendedTlsSettings = true;
|
||||
# other Nginx options
|
||||
virtualHosts."hydra.julian-mutter.de" = {
|
||||
# enableACME = true;
|
||||
# forceSSL = true;
|
||||
locations."/" = {
|
||||
proxyPass = "http://127.0.0.1:3000";
|
||||
# proxyWebsockets = true; # needed if you need to use WebSocket
|
||||
# extraConfig =
|
||||
# # required when the target is also TLS server with multiple hosts
|
||||
# "proxy_ssl_server_name on;" +
|
||||
# # required when the server wants to use HTTP Authentication
|
||||
# "proxy_pass_header Authorization;"
|
||||
# ;
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,52 @@
|
||||
# Setup the device as a jenkins agent
|
||||
{pkgs, ...}: {
|
||||
services.openssh = {
|
||||
enable = true;
|
||||
# require public key authentication for better security
|
||||
settings.PasswordAuthentication = false;
|
||||
settings.KbdInteractiveAuthentication = false;
|
||||
settings.PermitRootLogin = "yes";
|
||||
# Add older algorithms for jenkins ssh-agents-plugin to be compatible
|
||||
settings.Macs = [
|
||||
"hmac-sha2-512-etm@openssh.com"
|
||||
"hmac-sha2-256-etm@openssh.com"
|
||||
"umac-128-etm@openssh.com"
|
||||
"hmac-sha2-512"
|
||||
"hmac-sha2-256"
|
||||
"umac-128@openssh.com"
|
||||
];
|
||||
settings.KexAlgorithms = [
|
||||
"diffie-hellman-group-exchange-sha1"
|
||||
"diffie-hellman-group14-sha1"
|
||||
"mlkem768x25519-sha256"
|
||||
"sntrup761x25519-sha512"
|
||||
"sntrup761x25519-sha512@openssh.com"
|
||||
"curve25519-sha256"
|
||||
"curve25519-sha256@libssh.org"
|
||||
"diffie-hellman-group-exchange-sha256"
|
||||
];
|
||||
};
|
||||
|
||||
users.users.jenkins = {
|
||||
createHome = true;
|
||||
home = "/var/lib/jenkins";
|
||||
group = "jenkins";
|
||||
isNormalUser = true;
|
||||
openssh.authorizedKeys.keys = [
|
||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ36sQhVz3kUEi8754G7r3rboihhG4iqFK/UvQm6SING jenkins@home"
|
||||
];
|
||||
packages = with pkgs; [
|
||||
git
|
||||
devenv
|
||||
];
|
||||
extraGroups = [
|
||||
"docker"
|
||||
];
|
||||
};
|
||||
|
||||
users.groups.jenkins = {};
|
||||
programs.java = {
|
||||
enable = true;
|
||||
package = pkgs.jdk21; # Same as jenkins version on home
|
||||
};
|
||||
}
|
||||
Generated
+78
-113
@@ -90,11 +90,11 @@
|
||||
"utils": "utils"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1770019181,
|
||||
"narHash": "sha256-hwsYgDnby50JNVpTRYlF3UR/Rrpt01OrxVuryF40CFY=",
|
||||
"lastModified": 1781627888,
|
||||
"narHash": "sha256-5yHuAh9k7rT7rtf3uRaXkiUyYvQE9oaCgzhprLm2mr8=",
|
||||
"owner": "serokell",
|
||||
"repo": "deploy-rs",
|
||||
"rev": "77c906c0ba56aabdbc72041bf9111b565cdd6171",
|
||||
"rev": "6d3087eedff75a715b40c0e124ba15d2dd7bec28",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -110,11 +110,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1780290312,
|
||||
"narHash": "sha256-eTAlX0CwgB84Ts3GaBd944A3DRXVMzgA0EqroZBISUo=",
|
||||
"lastModified": 1781152676,
|
||||
"narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=",
|
||||
"owner": "nix-community",
|
||||
"repo": "disko",
|
||||
"rev": "115e5211780054d8a890b41f0b7734cafad54dfe",
|
||||
"rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -251,7 +251,7 @@
|
||||
},
|
||||
"flake-utils_3": {
|
||||
"inputs": {
|
||||
"systems": "systems_6"
|
||||
"systems": "systems_5"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1731533236,
|
||||
@@ -307,11 +307,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1780361225,
|
||||
"narHash": "sha256-wnV9ttf4fPWNonBIQmvlrSlNpQYgx5HgWWd007mwIFA=",
|
||||
"lastModified": 1784350909,
|
||||
"narHash": "sha256-ZWyzLbS1yKUTeFJLmdVuWNnHttL333/ldJbEE+KzCrM=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "e28654b71096e08c019d4861ca26acb646f583d8",
|
||||
"rev": "4ce190229c73d44536caa7072f6308fb2d8feeb3",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -430,11 +430,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1780210899,
|
||||
"narHash": "sha256-4axz3OBPTKa6LIkXV8n0lc63MQU+et2CB5DGobEAi6k=",
|
||||
"lastModified": 1784440659,
|
||||
"narHash": "sha256-Q5kNLlWngt7TaIIZoxDKWMHjiSaNRVqr70FqWCRRfr4=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nix-index-database",
|
||||
"rev": "97df9dc0b7c924344b793a15c1e8e4522ebb854e",
|
||||
"rev": "4f8d52a3598b0dc7db7a5e7b419e3edd9d1ecfdb",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -505,11 +505,11 @@
|
||||
"nixpkgs": "nixpkgs_4"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1780310866,
|
||||
"narHash": "sha256-fPBRVf6A5xlACYcOI59shGrjURuvwu0lRsDoSCEXt/I=",
|
||||
"lastModified": 1784310968,
|
||||
"narHash": "sha256-rkSPTePrKqs4dg+i7ZFCq93+HrClac6oSwXX927SVjA=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixos-hardware",
|
||||
"rev": "4ed851c979641e28597a05086332d75cdc9e395f",
|
||||
"rev": "779c32a00155994c86cde8213a8dd4df139d4355",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -536,11 +536,11 @@
|
||||
},
|
||||
"nixpkgs-unstable": {
|
||||
"locked": {
|
||||
"lastModified": 1780243769,
|
||||
"narHash": "sha256-x5UQuRsH3MqI0U9afaXSNqzTPSeZlRLvFAav2Ux1pNw=",
|
||||
"lastModified": 1784356753,
|
||||
"narHash": "sha256-12KrbMiWLcf8m7pCvAtZh1ZrgF85ZXDXvfR/fWTKy84=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "331800de5053fcebacf6813adb5db9c9dca22a0c",
|
||||
"rev": "61b7c44c4073f0b827768aff0049561b5110ea5a",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -593,11 +593,11 @@
|
||||
},
|
||||
"nixpkgs_5": {
|
||||
"locked": {
|
||||
"lastModified": 1780203844,
|
||||
"narHash": "sha256-K5sT4jTpGs15ADhviMKNBH38REpPf5Q6mM1+N6cArVE=",
|
||||
"lastModified": 1784280462,
|
||||
"narHash": "sha256-DtoqIqM7VkR6NxAkcLpMwmi02USwWb3JdmNGLyhthc0=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "b51242d7d43689db2f3be91bd05d5b24fbb469c4",
|
||||
"rev": "293d6abedf0478e681a4dfcfcb35b30fc796a32f",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -607,20 +607,47 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_6": {
|
||||
"locked": {
|
||||
"lastModified": 1781216227,
|
||||
"narHash": "sha256-9mUW6gNwoN2SWc/l0fW4svPNOulXLl8ijqKyeSOGgJE=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "a0374025a863d007d98e3297f6aa46cc3141c2f0",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixos-26.05",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_7": {
|
||||
"locked": {
|
||||
"lastModified": 1784356753,
|
||||
"narHash": "sha256-zupdTm41be2fY8cexroEOGjopl3F2Gqs3gk7ieqaM3s=",
|
||||
"rev": "61b7c44c4073f0b827768aff0049561b5110ea5a",
|
||||
"type": "tarball",
|
||||
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1036777.61b7c44c4073/nixexprs.tar.xz"
|
||||
},
|
||||
"original": {
|
||||
"type": "tarball",
|
||||
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
|
||||
}
|
||||
},
|
||||
"nixvim": {
|
||||
"inputs": {
|
||||
"flake-parts": "flake-parts",
|
||||
"nixpkgs": [
|
||||
"nixpkgs"
|
||||
],
|
||||
"nixpkgs": "nixpkgs_6",
|
||||
"systems": "systems_4"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1780214453,
|
||||
"narHash": "sha256-Bfq9y0X6Vs4UPb67u7hN3jt7fJKHtl3+g0lBSDebRNg=",
|
||||
"lastModified": 1782919967,
|
||||
"narHash": "sha256-pRwjfB5HQJ3m8J8bOR43pPHtHI7VUJSqwLA3P06cOY0=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nixvim",
|
||||
"rev": "167da56c3ab1e51751a6ae4a997ed66587f9edae",
|
||||
"rev": "667c8471f4a0fb24d702d1a61af8609f1a5f1ba6",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -632,45 +659,20 @@
|
||||
},
|
||||
"noctalia": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
"nixpkgs"
|
||||
],
|
||||
"noctalia-qs": "noctalia-qs"
|
||||
"nixpkgs": "nixpkgs_7"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1780371321,
|
||||
"narHash": "sha256-WCaU6npdMdjZSZHe3XATNDFijmzRnsV8V+iR80e5deg=",
|
||||
"lastModified": 1784456694,
|
||||
"narHash": "sha256-WjF2/HV1swc1Fwug/8Hf4jtCCQeQqdSVIT6peWB8CGs=",
|
||||
"owner": "noctalia-dev",
|
||||
"repo": "noctalia-shell",
|
||||
"rev": "3aab45a2f34fd47666b05892b95054952e788de1",
|
||||
"repo": "noctalia",
|
||||
"rev": "98f0d2b4afc2b1389d8480ce64e7f30957ff3800",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "noctalia-dev",
|
||||
"repo": "noctalia-shell",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"noctalia-qs": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
"noctalia",
|
||||
"nixpkgs"
|
||||
],
|
||||
"systems": "systems_5",
|
||||
"treefmt-nix": "treefmt-nix"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1780194487,
|
||||
"narHash": "sha256-M+YtjKCTkHrkplNaKVyaxfa8hAWjRF6wFOUBAZvxQ4U=",
|
||||
"owner": "noctalia-dev",
|
||||
"repo": "noctalia-qs",
|
||||
"rev": "07398e12b54f194e3a2d47c87e3fd10b8eeaa27d",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "noctalia-dev",
|
||||
"repo": "noctalia-qs",
|
||||
"ref": "cachix",
|
||||
"repo": "noctalia",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
@@ -718,7 +720,7 @@
|
||||
"sheet-organizer": "sheet-organizer",
|
||||
"sops-nix": "sops-nix",
|
||||
"stylix": "stylix",
|
||||
"systems": "systems_8",
|
||||
"systems": "systems_7",
|
||||
"yazi-flavors": "yazi-flavors"
|
||||
}
|
||||
},
|
||||
@@ -751,11 +753,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1777944972,
|
||||
"narHash": "sha256-VfGRo1qTBKOe3s2gOv8LSoA6Fk19PvBlwQ1ECN0Evn8=",
|
||||
"lastModified": 1783174389,
|
||||
"narHash": "sha256-aCWC8ngycU7OdJrU2+Je3qf+1a2ykuBvpPhZT/9tXMc=",
|
||||
"owner": "Mic92",
|
||||
"repo": "sops-nix",
|
||||
"rev": "c591bf665727040c6cc5cb409079acb22dcce33c",
|
||||
"rev": "f1406619a3884cd5c47992a70b8b35c9c0fcb4c9",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -777,18 +779,18 @@
|
||||
"nixpkgs"
|
||||
],
|
||||
"nur": "nur",
|
||||
"systems": "systems_7",
|
||||
"systems": "systems_6",
|
||||
"tinted-kitty": "tinted-kitty",
|
||||
"tinted-schemes": "tinted-schemes",
|
||||
"tinted-tmux": "tinted-tmux",
|
||||
"tinted-zed": "tinted-zed"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1780418496,
|
||||
"narHash": "sha256-m34WEd1dxo17CQUz702xJrMsnTewsaYyeKKi5Y86HJw=",
|
||||
"lastModified": 1784060273,
|
||||
"narHash": "sha256-14rIy2kTs5CufmDpgJrwkR+7IzuCAXyLYDAx6ixfRFc=",
|
||||
"owner": "nix-community",
|
||||
"repo": "stylix",
|
||||
"rev": "45b51150627b28b1d4a4ab4e5d645af8cb7c2ef6",
|
||||
"rev": "2245fa9e16034149b6501834b99863a486e94725",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -860,16 +862,16 @@
|
||||
},
|
||||
"systems_5": {
|
||||
"locked": {
|
||||
"lastModified": 1689347949,
|
||||
"narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=",
|
||||
"lastModified": 1681028828,
|
||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||
"owner": "nix-systems",
|
||||
"repo": "default-linux",
|
||||
"rev": "31732fcf5e8fea42e59c2488ad31a0e651500f68",
|
||||
"repo": "default",
|
||||
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-systems",
|
||||
"repo": "default-linux",
|
||||
"repo": "default",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
@@ -889,21 +891,6 @@
|
||||
}
|
||||
},
|
||||
"systems_7": {
|
||||
"locked": {
|
||||
"lastModified": 1681028828,
|
||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||
"owner": "nix-systems",
|
||||
"repo": "default",
|
||||
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-systems",
|
||||
"repo": "default",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"systems_8": {
|
||||
"locked": {
|
||||
"lastModified": 1689347949,
|
||||
"narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=",
|
||||
@@ -982,28 +969,6 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"treefmt-nix": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
"noctalia",
|
||||
"noctalia-qs",
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1775636079,
|
||||
"narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=",
|
||||
"owner": "numtide",
|
||||
"repo": "treefmt-nix",
|
||||
"rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "numtide",
|
||||
"repo": "treefmt-nix",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"utils": {
|
||||
"inputs": {
|
||||
"systems": "systems"
|
||||
@@ -1025,11 +990,11 @@
|
||||
"yazi-flavors": {
|
||||
"flake": false,
|
||||
"locked": {
|
||||
"lastModified": 1780204176,
|
||||
"narHash": "sha256-qWNArjWuxWL+rOjLzyIniW5hJgWiAWTCgXmMXJpaWZE=",
|
||||
"lastModified": 1782552321,
|
||||
"narHash": "sha256-erZI0H5TxqFu2P917juL5PIB3LC0oJGKPcB1VibJDqo=",
|
||||
"owner": "yazi-rs",
|
||||
"repo": "flavors",
|
||||
"rev": "0f9204bc948c8313963f5c9d571a82edc201f8aa",
|
||||
"rev": "4770a3467169bfdb0a3b11601921aaf27c100630",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
|
||||
@@ -9,9 +9,10 @@
|
||||
impermanence.url = "github:nix-community/impermanence";
|
||||
deploy-rs.url = "github:serokell/deploy-rs";
|
||||
|
||||
# For latest noctalia version
|
||||
noctalia = {
|
||||
url = "github:noctalia-dev/noctalia-shell";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
url = "github:noctalia-dev/noctalia/cachix";
|
||||
# inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
|
||||
stylix = {
|
||||
@@ -52,7 +53,6 @@
|
||||
};
|
||||
nixvim = {
|
||||
url = "github:nix-community/nixvim/nixos-26.05";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
nix-matlab = {
|
||||
url = "gitlab:doronbehar/nix-matlab";
|
||||
|
||||
@@ -4,15 +4,7 @@
|
||||
config,
|
||||
lib,
|
||||
...
|
||||
}: let
|
||||
# Apply lib.mkDefault to a whole attrset recursively, used for the noctalia config
|
||||
mkDefaultsRec = value:
|
||||
if builtins.isAttrs value
|
||||
then lib.mapAttrs (_: mkDefaultsRec) value
|
||||
else if builtins.isList value
|
||||
then map mkDefaultsRec value
|
||||
else lib.mkDefault value;
|
||||
in {
|
||||
}: {
|
||||
imports = [
|
||||
# inputs.hyprland.homeManagerModules.default
|
||||
# ./waybar
|
||||
@@ -27,7 +19,7 @@ in {
|
||||
./waypipe.nix
|
||||
|
||||
# ./hyprbars.nix
|
||||
inputs.noctalia.homeModules.default
|
||||
# inputs.noctalia.homeModules.default # Use for latest version from inputs
|
||||
];
|
||||
|
||||
xdg.portal = {
|
||||
@@ -47,16 +39,17 @@ in {
|
||||
size = 24;
|
||||
};
|
||||
|
||||
programs.imv.enable = true; # TODO: what is that
|
||||
|
||||
programs.noctalia-shell = {
|
||||
enable = true;
|
||||
# noctalia-shell ipc call state all | jq .settings | xclip
|
||||
# mkDefaultsRec used so that stylix can overwrite style options
|
||||
settings = mkDefaultsRec (builtins.fromJSON (builtins.readFile ./noctalia.json));
|
||||
};
|
||||
xdg.configFile."noctalia/settings.json".source = ./noctalia.json;
|
||||
|
||||
# programs.noctalia = {
|
||||
# enable = true;
|
||||
# # noctalia config export full > noctalia.toml
|
||||
# settings = ./noctalia.toml;
|
||||
# };
|
||||
|
||||
home.packages = with pkgs; [
|
||||
unstable.noctalia-shell # Use for stable version instead of latest from the input
|
||||
hyprpicker
|
||||
hyprcursor
|
||||
brightnessctl
|
||||
@@ -67,8 +60,12 @@ in {
|
||||
wf-recorder
|
||||
wl-clipboard
|
||||
|
||||
(pkgs.writeShellScriptBin "toggle-screen-mirroring" (
|
||||
builtins.readFile ./toggle-screen-mirroring.sh
|
||||
(pkgs.writeShellScriptBin "toggle-screen-mirroring"
|
||||
(
|
||||
builtins.replaceStrings
|
||||
["@INTERNAL_MONITOR@" "@EXTERNAL_MONITOR@"]
|
||||
[(builtins.elemAt config.monitors 0).name (builtins.elemAt config.monitors 1).name]
|
||||
(builtins.readFile ./toggle-screen-mirroring.sh)
|
||||
))
|
||||
|
||||
(pkgs.writeShellScriptBin "correct-workspace-locations" (
|
||||
@@ -107,6 +104,7 @@ in {
|
||||
local terminal = "${config.terminal}"
|
||||
local fileManager = "pcmanfm"
|
||||
-- local menu = "wofi --show drun,run"
|
||||
-- local menu = "noctalia msg panel-toggle launcher"
|
||||
local menu = "noctalia-shell ipc call launcher toggle"
|
||||
local calculator = "qalculate-gtk"
|
||||
local browser = "firefox"
|
||||
@@ -114,6 +112,15 @@ in {
|
||||
''
|
||||
+ "-- Main config from `hyprland.lua`\n"
|
||||
+ builtins.readFile ./hyprland.lua
|
||||
+ "-- Monitor config\n"
|
||||
+ lib.concatStringsSep "\n" (
|
||||
map (
|
||||
monitor: "hl.monitor({ output = \"${monitor.name}\", mode = \"preferred\", position = \"auto\", scale = \"auto\", mirror = \"\"})"
|
||||
)
|
||||
config.monitors
|
||||
)
|
||||
+ "\n-- For plugging in random monitors\n"
|
||||
+ "hl.monitor({ output = \"\", mode = \"preferred\", position = \"auto\", scale = \"auto\", mirror = \"\"})\n"
|
||||
+ "-- Assign workspaces to monitors\n"
|
||||
+ lib.concatStringsSep "\n" (
|
||||
builtins.concatLists (
|
||||
|
||||
@@ -1,16 +1,3 @@
|
||||
------------------
|
||||
---- MONITORS ----
|
||||
------------------
|
||||
|
||||
-- See https://wiki.hypr.land/Configuring/Basics/Monitors/
|
||||
hl.monitor({
|
||||
output = "",
|
||||
mode = "preferred",
|
||||
position = "auto",
|
||||
scale = "auto",
|
||||
mirror = "",
|
||||
})
|
||||
|
||||
-------------------
|
||||
---- AUTOSTART ----
|
||||
-------------------
|
||||
@@ -18,7 +5,7 @@ hl.monitor({
|
||||
-- See https://wiki.hypr.land/Configuring/Basics/Autostart/
|
||||
hl.on("hyprland.start", function()
|
||||
-- hl.exec_cmd("waybar")
|
||||
hl.exec_cmd("noctalia-shell")
|
||||
hl.exec_cmd("env QT_QPA_PLATFORMTHEME=qt5ct noctalia-shell") -- env ensures noctalia works alongside kde
|
||||
hl.exec_cmd("firefox")
|
||||
end)
|
||||
hl.on("config.reloaded", function()
|
||||
@@ -84,7 +71,7 @@ hl.config({
|
||||
},
|
||||
|
||||
animations = {
|
||||
enabled = true,
|
||||
enabled = false,
|
||||
},
|
||||
|
||||
misc = {
|
||||
@@ -98,34 +85,6 @@ hl.config({
|
||||
},
|
||||
})
|
||||
|
||||
-- Default curves and animations, see https://wiki.hypr.land/Configuring/Advanced-and-Cool/Animations/
|
||||
hl.curve("easeOutQuint", { type = "bezier", points = { { 0.23, 1 }, { 0.32, 1 } } })
|
||||
hl.curve("easeInOutCubic", { type = "bezier", points = { { 0.65, 0.05 }, { 0.36, 1 } } })
|
||||
hl.curve("linear", { type = "bezier", points = { { 0, 0 }, { 1, 1 } } })
|
||||
hl.curve("almostLinear", { type = "bezier", points = { { 0.5, 0.5 }, { 0.75, 1 } } })
|
||||
hl.curve("quick", { type = "bezier", points = { { 0.15, 0 }, { 0.1, 1 } } })
|
||||
|
||||
-- Default springs
|
||||
hl.curve("easy", { type = "spring", mass = 1, stiffness = 71.2633, dampening = 15.8273644 })
|
||||
|
||||
hl.animation({ leaf = "global", enabled = false })
|
||||
hl.animation({ leaf = "border", enabled = true, speed = 5.39, bezier = "easeOutQuint" })
|
||||
hl.animation({ leaf = "windows", enabled = true, speed = 4.79, spring = "easy" })
|
||||
hl.animation({ leaf = "windowsIn", enabled = true, speed = 4.1, spring = "easy", style = "popin 87%" })
|
||||
hl.animation({ leaf = "windowsOut", enabled = true, speed = 1.49, bezier = "linear", style = "popin 87%" })
|
||||
hl.animation({ leaf = "fadeIn", enabled = true, speed = 1.73, bezier = "almostLinear" })
|
||||
hl.animation({ leaf = "fadeOut", enabled = true, speed = 1.46, bezier = "almostLinear" })
|
||||
hl.animation({ leaf = "fade", enabled = true, speed = 3.03, bezier = "quick" })
|
||||
hl.animation({ leaf = "layers", enabled = true, speed = 3.81, bezier = "easeOutQuint" })
|
||||
hl.animation({ leaf = "layersIn", enabled = true, speed = 4, bezier = "easeOutQuint", style = "fade" })
|
||||
hl.animation({ leaf = "layersOut", enabled = true, speed = 1.5, bezier = "linear", style = "fade" })
|
||||
hl.animation({ leaf = "fadeLayersIn", enabled = true, speed = 1.79, bezier = "almostLinear" })
|
||||
hl.animation({ leaf = "fadeLayersOut", enabled = true, speed = 1.39, bezier = "almostLinear" })
|
||||
hl.animation({ leaf = "workspaces", enabled = true, speed = 1.94, bezier = "almostLinear", style = "fade" })
|
||||
hl.animation({ leaf = "workspacesIn", enabled = true, speed = 1.21, bezier = "almostLinear", style = "fade" })
|
||||
hl.animation({ leaf = "workspacesOut", enabled = true, speed = 1.94, bezier = "almostLinear", style = "fade" })
|
||||
hl.animation({ leaf = "zoomFactor", enabled = true, speed = 7, bezier = "quick" })
|
||||
|
||||
-- Ref https://wiki.hypr.land/Configuring/Basics/Workspace-Rules/
|
||||
-- "Smart gaps" / "No gaps when only"
|
||||
hl.workspace_rule({ workspace = "w[tv1]", gaps_out = 0, gaps_in = 0 })
|
||||
@@ -147,8 +106,7 @@ hl.config({
|
||||
|
||||
hl.config({
|
||||
misc = {
|
||||
force_default_wallpaper = -1, -- Set to 0 or 1 to disable the anime mascot wallpapers
|
||||
disable_hyprland_logo = false, -- If true disables the random hyprland logo / anime girl background. :(
|
||||
disable_hyprland_logo = true, -- If true disables the random hyprland logo / anime girl background. :(
|
||||
},
|
||||
})
|
||||
|
||||
|
||||
@@ -0,0 +1,628 @@
|
||||
[audio]
|
||||
enable_overdrive = true
|
||||
enable_sounds = false
|
||||
notification_sound = ""
|
||||
sound_volume = 0.5
|
||||
volume_change_sound = ""
|
||||
|
||||
[backdrop]
|
||||
blur_intensity = 0.5
|
||||
enabled = false
|
||||
tint_intensity = 0.30000001192092896
|
||||
|
||||
[bar]
|
||||
order = [ "widgets" ]
|
||||
|
||||
[bar.widgets]
|
||||
auto_hide = false
|
||||
background_opacity = 1.0
|
||||
border = "outline"
|
||||
border_width = 0.0
|
||||
capsule = false
|
||||
capsule_fill = "surface_variant"
|
||||
capsule_group = []
|
||||
capsule_opacity = 1.0
|
||||
capsule_padding = 6.0
|
||||
capsule_thickness = 0.75999999046325684
|
||||
center = []
|
||||
contact_shadow = false
|
||||
enabled = true
|
||||
end = [
|
||||
"cpu",
|
||||
"ram",
|
||||
"sysmon",
|
||||
"network_rx",
|
||||
"network_tx",
|
||||
"volume",
|
||||
"battery",
|
||||
"clock",
|
||||
"network",
|
||||
"clipboard",
|
||||
"tray"
|
||||
]
|
||||
font_weight = 500
|
||||
layer = "top"
|
||||
margin_edge = 0
|
||||
margin_ends = 0
|
||||
margin_opposite_edge = 0
|
||||
padding = 14
|
||||
panel_overlap = 1
|
||||
position = "bottom"
|
||||
radius = 0
|
||||
radius_bottom_left = 0
|
||||
radius_bottom_right = 0
|
||||
radius_top_left = 0
|
||||
radius_top_right = 0
|
||||
reserve_space = true
|
||||
scale = 1.0
|
||||
shadow = false
|
||||
show_on_workspace_switch = true
|
||||
start = [ "workspaces" ]
|
||||
thickness = 34
|
||||
widget_spacing = 12
|
||||
|
||||
[bar.widgets.dead_zone]
|
||||
command = ""
|
||||
middle_command = ""
|
||||
right_command = ""
|
||||
scroll_down_command = ""
|
||||
scroll_up_command = ""
|
||||
|
||||
[battery]
|
||||
warning_threshold = 10
|
||||
|
||||
[brightness]
|
||||
enable_ddcutil = false
|
||||
ignore_mmids = []
|
||||
minimum_brightness = 0.0
|
||||
sync_all_monitors = false
|
||||
|
||||
[calendar]
|
||||
enabled = false
|
||||
refresh_minutes = 15
|
||||
|
||||
[control_center]
|
||||
hidden_tabs = []
|
||||
sidebar = "full"
|
||||
sidebar_section = "full"
|
||||
width = 700
|
||||
|
||||
[[control_center.shortcuts]]
|
||||
type = "wifi"
|
||||
|
||||
[[control_center.shortcuts]]
|
||||
type = "bluetooth"
|
||||
|
||||
[[control_center.shortcuts]]
|
||||
type = "caffeine"
|
||||
|
||||
[[control_center.shortcuts]]
|
||||
type = "nightlight"
|
||||
|
||||
[[control_center.shortcuts]]
|
||||
type = "notification"
|
||||
|
||||
[[control_center.shortcuts]]
|
||||
type = "power_profile"
|
||||
|
||||
[desktop_widgets]
|
||||
enabled = false
|
||||
schema_version = 2
|
||||
|
||||
[desktop_widgets.grid]
|
||||
cell_size = 16
|
||||
major_interval = 4
|
||||
visible = true
|
||||
|
||||
[dock]
|
||||
active_monitor_only = false
|
||||
active_opacity = 1.0
|
||||
active_scale = 1.0
|
||||
auto_hide = false
|
||||
background_opacity = 0.87999999523162842
|
||||
cross_axis_padding = 8
|
||||
enabled = false
|
||||
icon_size = 48
|
||||
inactive_opacity = 0.85000002384185791
|
||||
inactive_scale = 0.85000002384185791
|
||||
item_spacing = 6
|
||||
launcher_icon = "grid-dots"
|
||||
launcher_position = "none"
|
||||
magnification = true
|
||||
magnification_scale = 1.4500000476837158
|
||||
main_axis_padding = 16
|
||||
margin_edge = 8
|
||||
margin_ends = 0
|
||||
monitors = []
|
||||
pinned = []
|
||||
position = "bottom"
|
||||
radius = 16
|
||||
radius_bottom_left = 16
|
||||
radius_bottom_right = 16
|
||||
radius_top_left = 16
|
||||
radius_top_right = 16
|
||||
reserve_space = true
|
||||
shadow = true
|
||||
show_dots = false
|
||||
show_instance_count = true
|
||||
show_running = true
|
||||
|
||||
[hooks]
|
||||
battery_charging = []
|
||||
battery_discharging = []
|
||||
battery_percentage_changed = []
|
||||
battery_plugged = []
|
||||
bluetooth_disabled = []
|
||||
bluetooth_enabled = []
|
||||
colors_changed = []
|
||||
logging_out = []
|
||||
power_profile_changed = []
|
||||
rebooting = []
|
||||
session_locked = []
|
||||
session_unlocked = []
|
||||
shutting_down = []
|
||||
started = []
|
||||
theme_mode_changed = []
|
||||
wallpaper_changed = []
|
||||
wifi_disabled = []
|
||||
wifi_enabled = []
|
||||
|
||||
[idle]
|
||||
behavior_order = [ "lock", "screen-off", "lock-and-suspend" ]
|
||||
pre_action_fade_seconds = 0.0
|
||||
|
||||
[idle.behavior.lock]
|
||||
action = "lock"
|
||||
command = ""
|
||||
enabled = false
|
||||
resume_command = ""
|
||||
timeout = 600.0
|
||||
|
||||
[idle.behavior.lock-and-suspend]
|
||||
action = "lock_and_suspend"
|
||||
command = ""
|
||||
enabled = false
|
||||
resume_command = ""
|
||||
timeout = 900.0
|
||||
|
||||
[idle.behavior.screen-off]
|
||||
action = "screen_off"
|
||||
command = ""
|
||||
enabled = false
|
||||
resume_command = ""
|
||||
timeout = 660.0
|
||||
|
||||
[keybinds]
|
||||
cancel = [ "Escape" ]
|
||||
down = [ "Down" ]
|
||||
left = [ "Left" ]
|
||||
right = [ "Right" ]
|
||||
tab_next = [ "Tab" ]
|
||||
tab_previous = [ "Shift+ISO_Left_Tab" ]
|
||||
up = [ "Up" ]
|
||||
validate = [ "Return", "KP_Enter", "space" ]
|
||||
|
||||
[location]
|
||||
address = "Würzburg, Germany"
|
||||
auto_locate = false
|
||||
sunrise = ""
|
||||
sunset = ""
|
||||
|
||||
[lockscreen]
|
||||
allow_empty_password = false
|
||||
blur_intensity = 0.5
|
||||
blurred_desktop = false
|
||||
enabled = false
|
||||
fingerprint = true
|
||||
monitors = []
|
||||
tint_intensity = 0.30000001192092896
|
||||
wallpaper = ""
|
||||
|
||||
[lockscreen_widgets]
|
||||
enabled = false
|
||||
schema_version = 2
|
||||
widget_order = [ "lockscreen-login-box@HDMI-A-1", "lockscreen-login-box@eDP-1" ]
|
||||
|
||||
[lockscreen_widgets.grid]
|
||||
cell_size = 16
|
||||
major_interval = 4
|
||||
visible = true
|
||||
|
||||
[lockscreen_widgets.widget."lockscreen-login-box@HDMI-A-1"]
|
||||
box_height = 70.0
|
||||
box_width = 400.0
|
||||
cx = 960.0
|
||||
cy = 961.0
|
||||
enabled = true
|
||||
output = "HDMI-A-1"
|
||||
rotation = 0.0
|
||||
type = "login_box"
|
||||
|
||||
[lockscreen_widgets.widget."lockscreen-login-box@HDMI-A-1".settings]
|
||||
background_color = "surface_variant"
|
||||
background_opacity = 0.88
|
||||
background_radius = 12.0
|
||||
input_opacity = 1.0
|
||||
input_radius = 6.0
|
||||
show_caps_lock = true
|
||||
show_keyboard_layout = true
|
||||
show_login_button = true
|
||||
show_password_hint = true
|
||||
|
||||
[lockscreen_widgets.widget."lockscreen-login-box@eDP-1"]
|
||||
box_height = 70.0
|
||||
box_width = 400.0
|
||||
cx = 960.0
|
||||
cy = 961.0
|
||||
enabled = true
|
||||
output = "eDP-1"
|
||||
rotation = 0.0
|
||||
type = "login_box"
|
||||
|
||||
[lockscreen_widgets.widget."lockscreen-login-box@eDP-1".settings]
|
||||
background_color = "surface_variant"
|
||||
background_opacity = 0.88
|
||||
background_radius = 12.0
|
||||
input_opacity = 1.0
|
||||
input_radius = 6.0
|
||||
show_caps_lock = true
|
||||
show_keyboard_layout = true
|
||||
show_login_button = true
|
||||
show_password_hint = true
|
||||
|
||||
[nightlight]
|
||||
enabled = false
|
||||
force = false
|
||||
temperature_day = 6500
|
||||
temperature_night = 4000
|
||||
|
||||
[notification]
|
||||
background_opacity = 0.97000002861022949
|
||||
collapse_on_dismiss = true
|
||||
enable_daemon = false
|
||||
layer = "top"
|
||||
monitors = []
|
||||
offset_x = 20
|
||||
offset_y = 8
|
||||
position = "top_right"
|
||||
scale = 1.0
|
||||
show_actions = true
|
||||
show_app_name = true
|
||||
|
||||
[osd]
|
||||
background_opacity = 0.97000002861022949
|
||||
monitors = []
|
||||
offset_x = 20
|
||||
offset_y = 8
|
||||
orientation = "horizontal"
|
||||
position = "top_center"
|
||||
position_vertical = "top_center"
|
||||
scale = 1.0
|
||||
|
||||
[osd.kinds]
|
||||
bluetooth = false
|
||||
brightness = false
|
||||
caffeine = false
|
||||
dnd = false
|
||||
keyboard_layout = false
|
||||
lock_keys = false
|
||||
media = false
|
||||
nightlight = false
|
||||
power_profile = false
|
||||
privacy = false
|
||||
volume = false
|
||||
volume_input = true
|
||||
volume_output = true
|
||||
wifi = false
|
||||
|
||||
[plugins]
|
||||
enabled = []
|
||||
|
||||
[[plugins.source]]
|
||||
auto_update = false
|
||||
enabled = true
|
||||
kind = "git"
|
||||
location = "https://github.com/noctalia-dev/official-plugins"
|
||||
name = "official"
|
||||
|
||||
[[plugins.source]]
|
||||
auto_update = false
|
||||
enabled = true
|
||||
kind = "git"
|
||||
location = "https://github.com/noctalia-dev/community-plugins"
|
||||
name = "community"
|
||||
|
||||
[shell]
|
||||
app_icon_colorize = false
|
||||
avatar_path = ""
|
||||
clipboard_auto_paste = "auto"
|
||||
clipboard_confirm_clear_history = true
|
||||
clipboard_enabled = true
|
||||
clipboard_history_max_entries = 100
|
||||
clipboard_image_action_command = ""
|
||||
corner_radius_scale = 1.0
|
||||
date_format = "%A, %x"
|
||||
disable_mipmaps = false
|
||||
font_family = "sans-serif"
|
||||
launch_apps_as_systemd_services = false
|
||||
launch_apps_custom_command = ""
|
||||
middle_click_opens_widget_settings = true
|
||||
niri_overview_type_to_launch_enabled = false
|
||||
offline_mode = false
|
||||
password_style = "default"
|
||||
polkit_agent = false
|
||||
screen_time_enabled = false
|
||||
settings_show_advanced = false
|
||||
setup_wizard_enabled = true
|
||||
shared_gl_context = true
|
||||
show_location = true
|
||||
telemetry_enabled = false
|
||||
time_format = "{:%H:%M}"
|
||||
ui_scale = 1.0
|
||||
|
||||
[shell.animation]
|
||||
enabled = false
|
||||
speed = 1.0
|
||||
|
||||
[shell.greeter_sync]
|
||||
auto_sync = false
|
||||
|
||||
[shell.launcher]
|
||||
app_grid = false
|
||||
categories = true
|
||||
compact = true
|
||||
session_search = false
|
||||
show_icons = true
|
||||
sort_by_usage = true
|
||||
|
||||
[shell.launcher.dmenu]
|
||||
|
||||
[shell.mpris]
|
||||
blacklist = []
|
||||
|
||||
[shell.panel]
|
||||
borders = true
|
||||
clipboard_placement = "attached"
|
||||
clipboard_position = "center"
|
||||
control_center_placement = "attached"
|
||||
control_center_position = "auto"
|
||||
floating_offset = 13
|
||||
launcher_placement = "floating"
|
||||
launcher_position = "center"
|
||||
open_near_click_clipboard = true
|
||||
open_near_click_control_center = true
|
||||
open_near_click_launcher = false
|
||||
open_near_click_session = true
|
||||
open_near_click_wallpaper = true
|
||||
polkit_placement = "floating"
|
||||
polkit_position = "center"
|
||||
session_placement = "attached"
|
||||
session_position = "auto"
|
||||
shadow = true
|
||||
transparency_mode = "solid"
|
||||
wallpaper_placement = "attached"
|
||||
wallpaper_position = "auto"
|
||||
|
||||
[shell.privacy]
|
||||
cam_filter_regex = ""
|
||||
mic_filter_regex = ""
|
||||
|
||||
[shell.screen_corners]
|
||||
enabled = false
|
||||
size = 32
|
||||
|
||||
[shell.screenshot]
|
||||
confirm_region = false
|
||||
copy_to_clipboard = true
|
||||
directory = ""
|
||||
filename_pattern = ""
|
||||
freeze_screen = true
|
||||
pipe_command = ""
|
||||
pipe_to_command = false
|
||||
save_to_file = true
|
||||
|
||||
[shell.session.power]
|
||||
|
||||
[[shell.session.actions]]
|
||||
action = "lock"
|
||||
command = ""
|
||||
countdown_seconds = 0.0
|
||||
enabled = true
|
||||
glyph = ""
|
||||
label = ""
|
||||
shortcut = "1"
|
||||
variant = "default"
|
||||
|
||||
[[shell.session.actions]]
|
||||
action = "logout"
|
||||
command = ""
|
||||
countdown_seconds = 0.0
|
||||
enabled = true
|
||||
glyph = ""
|
||||
label = ""
|
||||
shortcut = "2"
|
||||
variant = "default"
|
||||
|
||||
[[shell.session.actions]]
|
||||
action = "lock_and_suspend"
|
||||
command = ""
|
||||
countdown_seconds = 0.0
|
||||
enabled = false
|
||||
glyph = ""
|
||||
label = ""
|
||||
shortcut = "3"
|
||||
variant = "default"
|
||||
|
||||
[[shell.session.actions]]
|
||||
action = "reboot"
|
||||
command = ""
|
||||
countdown_seconds = 0.0
|
||||
enabled = true
|
||||
glyph = ""
|
||||
label = ""
|
||||
shortcut = "4"
|
||||
variant = "default"
|
||||
|
||||
[[shell.session.actions]]
|
||||
action = "shutdown"
|
||||
command = ""
|
||||
countdown_seconds = 0.0
|
||||
enabled = true
|
||||
glyph = ""
|
||||
label = ""
|
||||
shortcut = "5"
|
||||
variant = "destructive"
|
||||
|
||||
[shell.shadow]
|
||||
alpha = 0.55000001192092896
|
||||
direction = "down"
|
||||
|
||||
[system.monitor]
|
||||
cpu_poll_seconds = 2.0
|
||||
cpu_temp_activity_threshold = 60.0
|
||||
cpu_temp_critical_threshold = 85.0
|
||||
cpu_temp_sensor_path = ""
|
||||
cpu_usage_activity_threshold = 50.0
|
||||
cpu_usage_critical_threshold = 90.0
|
||||
disk_pct_activity_threshold = 80.0
|
||||
disk_pct_critical_threshold = 95.0
|
||||
disk_poll_seconds = 10.0
|
||||
enabled = true
|
||||
gpu_poll_seconds = 0.0
|
||||
gpu_temp_activity_threshold = 60.0
|
||||
gpu_temp_critical_threshold = 85.0
|
||||
gpu_usage_activity_threshold = 50.0
|
||||
gpu_usage_critical_threshold = 95.0
|
||||
gpu_vram_activity_threshold = 50.0
|
||||
gpu_vram_critical_threshold = 90.0
|
||||
memory_poll_seconds = 2.0
|
||||
net_rx_activity_threshold = 1.0
|
||||
net_rx_critical_threshold = 50.0
|
||||
net_tx_activity_threshold = 1.0
|
||||
net_tx_critical_threshold = 50.0
|
||||
network_poll_seconds = 3.0
|
||||
ram_pct_activity_threshold = 60.0
|
||||
ram_pct_critical_threshold = 90.0
|
||||
swap_pct_activity_threshold = 20.0
|
||||
swap_pct_critical_threshold = 80.0
|
||||
|
||||
[theme]
|
||||
builtin = "Catppuccin"
|
||||
community_palette = "Oxocarbon"
|
||||
custom_palette = ""
|
||||
mode = "dark"
|
||||
source = "builtin"
|
||||
wallpaper_scheme = "m3-content"
|
||||
|
||||
[theme.templates]
|
||||
builtin_ids = []
|
||||
community_ids = []
|
||||
enable_builtin_templates = false
|
||||
enable_community_templates = false
|
||||
|
||||
[wallpaper]
|
||||
directory = ""
|
||||
directory_dark = ""
|
||||
directory_light = ""
|
||||
edge_smoothness = 0.30000001192092896
|
||||
enabled = false
|
||||
fill_color = ""
|
||||
fill_mode = "crop"
|
||||
per_monitor_directories = false
|
||||
transition = [ "fade", "wipe", "disc", "stripes", "zoom", "honeycomb" ]
|
||||
transition_duration = 1500.0
|
||||
transition_on_startup = false
|
||||
|
||||
[wallpaper.automation]
|
||||
enabled = false
|
||||
interval_seconds = 1800
|
||||
order = "random"
|
||||
recursive = true
|
||||
|
||||
[weather]
|
||||
effects = true
|
||||
enabled = true
|
||||
refresh_minutes = 30
|
||||
unit = "metric"
|
||||
|
||||
[widget.active_window]
|
||||
icon_size = 14.0
|
||||
max_length = 260.0
|
||||
min_length = 80.0
|
||||
title_scroll = "none"
|
||||
type = "active_window"
|
||||
|
||||
[widget.clock]
|
||||
format = "{:%a %d.%m. %H:%M:%S}"
|
||||
type = "clock"
|
||||
|
||||
[widget.cpu]
|
||||
display = "text"
|
||||
stat = "cpu_usage"
|
||||
type = "sysmon"
|
||||
|
||||
[widget.custom_button_2]
|
||||
type = "custom_button"
|
||||
|
||||
[widget.date]
|
||||
format = "{:%a %d %b}"
|
||||
type = "clock"
|
||||
|
||||
[widget.input_volume]
|
||||
device = "input"
|
||||
type = "volume"
|
||||
|
||||
[widget.keyboard_layout]
|
||||
cycle_command = ""
|
||||
hide_when_single_layout = false
|
||||
type = "keyboard_layout"
|
||||
|
||||
[widget.lock_keys]
|
||||
display = "short"
|
||||
hide_when_off = false
|
||||
show_caps_lock = true
|
||||
show_num_lock = true
|
||||
show_scroll_lock = false
|
||||
type = "lock_keys"
|
||||
|
||||
[widget.media]
|
||||
art_size = 16.0
|
||||
max_length = 220.0
|
||||
min_length = 80.0
|
||||
title_scroll = "none"
|
||||
type = "media"
|
||||
|
||||
[widget.network_rx]
|
||||
display = "text"
|
||||
stat = "net_rx"
|
||||
type = "sysmon"
|
||||
|
||||
[widget.network_tx]
|
||||
display = "text"
|
||||
stat = "net_tx"
|
||||
type = "sysmon"
|
||||
|
||||
[widget.output_volume]
|
||||
device = "output"
|
||||
type = "volume"
|
||||
|
||||
[widget.ram]
|
||||
display = "text"
|
||||
stat = "ram_pct"
|
||||
type = "sysmon"
|
||||
|
||||
[widget.spacer]
|
||||
type = "spacer"
|
||||
|
||||
[widget.sysmon]
|
||||
display = "text"
|
||||
stat = "disk_pct"
|
||||
type = "sysmon"
|
||||
|
||||
[widget.temp]
|
||||
stat = "cpu_temp"
|
||||
type = "sysmon"
|
||||
|
||||
[widget.workspaces]
|
||||
scale = 1.1000000000000001
|
||||
type = "workspaces"
|
||||
@@ -2,11 +2,10 @@
|
||||
|
||||
# A hyprland script for a laptop-external-monitor setup, toggling between which is in use
|
||||
|
||||
# TODO: Detect these instead of hardcoding them
|
||||
INTERNAL_MONITOR="eDP-1"
|
||||
EXTERNAL_MONITOR="HDMI-A-1"
|
||||
INTERNAL_MONITOR="@INTERNAL_MONITOR@"
|
||||
EXTERNAL_MONITOR="@EXTERNAL_MONITOR@"
|
||||
|
||||
MIRROR_SETTING=$(hyprctl monitors all -j | jq -r '.[] | select(.name == "HDMI-A-1") | .mirrorOf')
|
||||
MIRROR_SETTING=$(hyprctl monitors all -j | jq -r --arg EXTERNAL "$EXTERNAL_MONITOR" '.[] | select(.name == $EXTERNAL) | .mirrorOf')
|
||||
|
||||
echo "current setting: "
|
||||
echo $MIRROR_SETTING
|
||||
|
||||
@@ -9,8 +9,6 @@
|
||||
services.syncthing.tray.enable = true;
|
||||
services.syncthing.tray.command = "syncthingtray --wait"; # Wait for tray to become available
|
||||
|
||||
gtk.gtk4.theme = null; # Fix evaluation warning since using old home manager version
|
||||
|
||||
programs.chromium = {
|
||||
enable = true;
|
||||
extensions = [
|
||||
|
||||
+41
-183
@@ -4,10 +4,16 @@
|
||||
{
|
||||
pwd,
|
||||
config,
|
||||
pkgs,
|
||||
inputs,
|
||||
outputs,
|
||||
lib,
|
||||
...
|
||||
}: {
|
||||
imports = [
|
||||
imports =
|
||||
[
|
||||
inputs.disko.nixosModules.disko
|
||||
|
||||
./disko.nix
|
||||
./hardware-configuration.nix
|
||||
|
||||
"${pwd}/features-nixos/global/fish.nix" # fish for admin
|
||||
@@ -15,7 +21,20 @@
|
||||
"${pwd}/features-nixos/global/nix.nix"
|
||||
"${pwd}/features-nixos/global/sops.nix"
|
||||
"${pwd}/features-nixos/global/root.nix"
|
||||
];
|
||||
|
||||
# "${pwd}/features-nixos/optional/hydra.nix"
|
||||
# "${pwd}/features-nixos/optional/jenkins-agent.nix"
|
||||
]
|
||||
++ (builtins.attrValues outputs.nixosModules);
|
||||
|
||||
frajul.gitlab-runner = {
|
||||
enable = false;
|
||||
secretsFile = ./secrets.yaml;
|
||||
};
|
||||
frajul.gitea-runner = {
|
||||
enable = true;
|
||||
secretsFile = ./secrets.yaml;
|
||||
};
|
||||
|
||||
networking.hostName = "builder";
|
||||
system.stateVersion = "23.11";
|
||||
@@ -66,22 +85,22 @@
|
||||
fallback = true;
|
||||
};
|
||||
|
||||
# system.autoUpgrade = {
|
||||
# enable = true;
|
||||
# flake = "git+https://gitlab.julian-mutter.de/julian/dotfiles";
|
||||
# flags = [
|
||||
# "--recreate-lock-file" # update lock file
|
||||
# ];
|
||||
# dates = "02:13";
|
||||
# };
|
||||
system.autoUpgrade = {
|
||||
enable = true;
|
||||
flake = "git+https://gitlab.julian-mutter.de/julian/dotfiles";
|
||||
flags = [
|
||||
"--recreate-lock-file" # update lock file
|
||||
];
|
||||
dates = "02:13";
|
||||
};
|
||||
|
||||
# optimize store by hardlinking store files
|
||||
nix.optimise.automatic = true;
|
||||
nix.optimise.dates = ["03:15"];
|
||||
nix.optimise.automatic = lib.mkForce true;
|
||||
nix.optimise.dates = lib.mkForce ["03:15"];
|
||||
|
||||
# nix.gc.automatic = true;
|
||||
# nix.gc.dates = "daily";
|
||||
# nix.gc.options = "--delete-old";
|
||||
nix.gc.automatic = lib.mkForce true;
|
||||
nix.gc.dates = lib.mkForce "daily";
|
||||
nix.gc.options = lib.mkForce "--delete-old";
|
||||
|
||||
# nix.settings.keep-derivations = false;
|
||||
# nix.settings.keep-outputs = true;
|
||||
@@ -101,55 +120,12 @@
|
||||
OOMScoreAdjust = 500;
|
||||
};
|
||||
|
||||
# Ollama used by open-webui as llm backend
|
||||
# services.ollama = {
|
||||
# enable = true;
|
||||
# # acceleration = "rocm";
|
||||
# openFirewall = true;
|
||||
# };
|
||||
|
||||
# services.nextjs-ollama-llm-ui = {
|
||||
# enable = true;
|
||||
# hostname = "192.168.3.118";
|
||||
# port = 3001;
|
||||
# };
|
||||
# services.open-webui = {
|
||||
# enable = true;
|
||||
# port = 8080;
|
||||
# openFirewall = true;
|
||||
# host = "builder.julian-mutter.de";
|
||||
# };
|
||||
|
||||
networking.firewall.allowedTCPPorts = [
|
||||
80
|
||||
3001 # ollama-ui
|
||||
];
|
||||
|
||||
services.openssh = {
|
||||
enable = true;
|
||||
# require public key authentication for better security
|
||||
settings.PasswordAuthentication = false;
|
||||
settings.KbdInteractiveAuthentication = false;
|
||||
settings.PermitRootLogin = "yes";
|
||||
# Add older algorithms for jenkins ssh-agents-plugin to be compatible
|
||||
settings.Macs = [
|
||||
"hmac-sha2-512-etm@openssh.com"
|
||||
"hmac-sha2-256-etm@openssh.com"
|
||||
"umac-128-etm@openssh.com"
|
||||
"hmac-sha2-512"
|
||||
"hmac-sha2-256"
|
||||
"umac-128@openssh.com"
|
||||
];
|
||||
settings.KexAlgorithms = [
|
||||
"diffie-hellman-group-exchange-sha1"
|
||||
"diffie-hellman-group14-sha1"
|
||||
"mlkem768x25519-sha256"
|
||||
"sntrup761x25519-sha512"
|
||||
"sntrup761x25519-sha512@openssh.com"
|
||||
"curve25519-sha256"
|
||||
"curve25519-sha256@libssh.org"
|
||||
"diffie-hellman-group-exchange-sha256"
|
||||
];
|
||||
};
|
||||
users.users."root".openssh.authorizedKeys.keys = [
|
||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFjSZYdoF/51F+ykcBAYVCzCPTF5EEigWBL1APiR0h+H julian@aspi"
|
||||
@@ -163,20 +139,6 @@
|
||||
|
||||
# security.pam.sshAgentAuth.enable = true; # enable sudo via ssh
|
||||
|
||||
services.hydra = {
|
||||
enable = true;
|
||||
hydraURL = "http://hydra.julian-mutter.de"; # externally visible URL
|
||||
port = 3000;
|
||||
notificationSender = "hydra@julian-mutter.de"; # e-mail of hydra service
|
||||
# a standalone hydra will require you to unset the buildMachinesFiles list to avoid using a nonexistant /etc/nix/machines
|
||||
# buildMachinesFiles = [ ];
|
||||
# you will probably also want, otherwise *everything* will be built from scratch
|
||||
useSubstitutes = true;
|
||||
|
||||
minimumDiskFree = 5; # in GB
|
||||
minimumDiskFreeEvaluator = 4; # in GB
|
||||
};
|
||||
|
||||
# add builder itpwd as build machine so system emulation is properly supported
|
||||
# nix.distributedBuilds = true;
|
||||
nix.buildMachines = [
|
||||
@@ -199,97 +161,30 @@
|
||||
}
|
||||
];
|
||||
|
||||
# Uris allowed as flake inputs, otherwise hydra does not fetch them
|
||||
nix.settings.allowed-uris = [
|
||||
"github:"
|
||||
"gitlab:"
|
||||
"git+https://github.com/hyprwm/Hyprland"
|
||||
"https://github.com/hyprwm/Hyprland"
|
||||
"https://github"
|
||||
"https://gitlab"
|
||||
"https://gitlab.julian-mutter.de"
|
||||
"git+https://gitlab.julian-mutter.de"
|
||||
networking.firewall.allowedTCPPorts = [
|
||||
80
|
||||
];
|
||||
|
||||
services.nginx = {
|
||||
enable = true;
|
||||
recommendedProxySettings = true;
|
||||
# recommendedTlsSettings = true;
|
||||
# other Nginx options
|
||||
virtualHosts."hydra.julian-mutter.de" = {
|
||||
# enableACME = true;
|
||||
# forceSSL = true;
|
||||
locations."/" = {
|
||||
proxyPass = "http://127.0.0.1:3000";
|
||||
# proxyWebsockets = true; # needed if you need to use WebSocket
|
||||
# extraConfig =
|
||||
# # required when the target is also TLS server with multiple hosts
|
||||
# "proxy_ssl_server_name on;" +
|
||||
# # required when the server wants to use HTTP Authentication
|
||||
# "proxy_pass_header Authorization;"
|
||||
# ;
|
||||
};
|
||||
};
|
||||
|
||||
# nix-serve
|
||||
virtualHosts."binarycache.julian-mutter.de" = {
|
||||
locations."/".proxyPass = "http://${config.services.nix-serve.bindAddress}:${toString config.services.nix-serve.port}";
|
||||
};
|
||||
|
||||
# attic
|
||||
clientMaxBodySize = "2G";
|
||||
virtualHosts."cache.julian-mutter.de" = {
|
||||
locations."/".proxyPass = "http://127.0.0.1:8080";
|
||||
};
|
||||
};
|
||||
|
||||
# =========== Gitea actions ==========
|
||||
services.gitea-actions-runner.instances."builder" = {
|
||||
enable = true;
|
||||
url = "https://gitlab.julian-mutter.de";
|
||||
name = "builder";
|
||||
tokenFile = config.sops.secrets."gitea_token".path;
|
||||
labels = [
|
||||
# fake the ubuntu name, because node provides no ubuntu builds
|
||||
"ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest"
|
||||
# my custom nix+devenv ci container
|
||||
"nix-ci:docker://gitlab.julian-mutter.de/julian/nix-ci-container:latest"
|
||||
# devenv
|
||||
"devenv:docker://ghcr.io/cachix/devenv/devenv:latest"
|
||||
# provide native execution on the host
|
||||
"nixos:host"
|
||||
];
|
||||
# Packages are intjected into PATH for "nixos:host"
|
||||
hostPackages = with pkgs; [
|
||||
bash
|
||||
coreutils
|
||||
curl
|
||||
gawk
|
||||
gitMinimal
|
||||
nodejs # Required by many standard actions (like actions/checkout)
|
||||
docker
|
||||
devenv
|
||||
wget
|
||||
nix
|
||||
];
|
||||
};
|
||||
|
||||
virtualisation.docker.enable = true;
|
||||
|
||||
# TODO: podman fails with: "cannot resolve hostname"
|
||||
# virtualisation.podman = {
|
||||
# enable = true;
|
||||
# dockerCompat = true;
|
||||
# defaultNetwork.settings.dns_enabled = true;
|
||||
# };
|
||||
|
||||
sops.secrets."gitea_token" = {
|
||||
owner = config.users.users.nix.name;
|
||||
sopsFile = ./secrets.yaml;
|
||||
};
|
||||
|
||||
# =========== Binary Cache ==========
|
||||
sops.secrets."nix_serve_key".sopsFile = ./secrets.yaml;
|
||||
services.nix-serve = {
|
||||
enable = true;
|
||||
secretKeyFile = "/var/cache-priv-key.pem";
|
||||
secretKeyFile = config.sops.secrets."nix_serve_key".path;
|
||||
};
|
||||
|
||||
# =========== Binary Cache with attic ==========
|
||||
@@ -327,41 +222,4 @@
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
services.gitlab-runner.enable = true;
|
||||
# runner for everything else
|
||||
#
|
||||
sops.secrets."gitlab_runner_token".sopsFile = ./secrets.yaml;
|
||||
services.gitlab-runner.services.default = {
|
||||
# File should contain at least these two variables:
|
||||
authenticationTokenConfigFile = config.sops.secrets."gitlab_runner_token".path;
|
||||
dockerImage = "alpine:latest";
|
||||
dockerVolumes = [
|
||||
"/var/run/docker.sock:/var/run/docker.sock"
|
||||
];
|
||||
};
|
||||
|
||||
### Jenkins node
|
||||
users.users.jenkins = {
|
||||
createHome = true;
|
||||
home = "/var/lib/jenkins";
|
||||
group = "jenkins";
|
||||
isNormalUser = true;
|
||||
openssh.authorizedKeys.keys = [
|
||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ36sQhVz3kUEi8754G7r3rboihhG4iqFK/UvQm6SING jenkins@home"
|
||||
];
|
||||
packages = with pkgs; [
|
||||
git
|
||||
devenv
|
||||
];
|
||||
extraGroups = [
|
||||
"docker"
|
||||
];
|
||||
};
|
||||
|
||||
users.groups.jenkins = {};
|
||||
programs.java = {
|
||||
enable = true;
|
||||
package = pkgs.jdk21; # Same as jenkins version on home
|
||||
};
|
||||
}
|
||||
|
||||
@@ -0,0 +1,56 @@
|
||||
# Example to create a bios compatible gpt partition
|
||||
{ lib, ... }:
|
||||
{
|
||||
disko.devices = {
|
||||
disk.disk1 = {
|
||||
device = lib.mkDefault "/dev/sda";
|
||||
type = "disk";
|
||||
content = {
|
||||
type = "gpt";
|
||||
partitions = {
|
||||
boot = {
|
||||
name = "boot";
|
||||
size = "1M";
|
||||
type = "EF02";
|
||||
};
|
||||
esp = {
|
||||
name = "ESP";
|
||||
size = "500M";
|
||||
type = "EF00";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "vfat";
|
||||
mountpoint = "/boot";
|
||||
};
|
||||
};
|
||||
root = {
|
||||
name = "root";
|
||||
size = "100%";
|
||||
content = {
|
||||
type = "lvm_pv";
|
||||
vg = "pool";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
lvm_vg = {
|
||||
pool = {
|
||||
type = "lvm_vg";
|
||||
lvs = {
|
||||
root = {
|
||||
size = "100%FREE";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "ext4";
|
||||
mountpoint = "/";
|
||||
mountOptions = [
|
||||
"defaults"
|
||||
];
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -7,43 +7,13 @@
|
||||
"sd_mod"
|
||||
"sr_mod"
|
||||
];
|
||||
# boot.initrd.kernelModules = [ "amdgpu" ]; # GPU support
|
||||
boot.kernelModules = [];
|
||||
boot.extraModulePackages = [];
|
||||
|
||||
fileSystems."/" = {
|
||||
device = "/dev/disk/by-uuid/f088fe8e-bf3d-4a89-98bd-ead9852d381f";
|
||||
fsType = "ext4";
|
||||
};
|
||||
|
||||
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
|
||||
# (the default) this is the recommended approach. When using systemd-networkd it's
|
||||
# still possible to use this option, but it's recommended to use it in conjunction
|
||||
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
|
||||
networking.useDHCP = lib.mkDefault true;
|
||||
# networking.interfaces.ens18.useDHCP = lib.mkDefault true;
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
|
||||
# hardware.graphics = {
|
||||
# enable = true;
|
||||
# extraPackages = with pkgs; [
|
||||
# rocmPackages.clr.icd
|
||||
# linuxPackages.amdgpu-pro
|
||||
# ];
|
||||
# };
|
||||
|
||||
# boot.kernelParams = [
|
||||
# "radeon.si_support=0"
|
||||
# "radeon.cik_support=1"
|
||||
# "amdgpu.si_support=0"
|
||||
# "amdgpu.cik_support=1"
|
||||
# ];
|
||||
# boot.extraModulePackages = with config.boot.kernelPackages; [ amdgpu-pro ];
|
||||
# boot.blacklistedKernelModules = [ "radeon" ];
|
||||
|
||||
boot.loader.grub.enable = true;
|
||||
boot.loader.grub.device = "/dev/sda";
|
||||
|
||||
# Emulated systems used as alternative to cross-compiling
|
||||
boot.binfmt.emulatedSystems = ["aarch64-linux"];
|
||||
|
||||
+15
-14
File diff suppressed because one or more lines are too long
@@ -0,0 +1 @@
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINgH+4xJMk4K5uBIq4hKwar4wt6GYCRE3Z2S4HETc4TK root@builder
|
||||
@@ -11,7 +11,7 @@
|
||||
"${pwd}/features-nixos/users/wolfi"
|
||||
"${pwd}/features-nixos/optional/binarycaches.nix"
|
||||
|
||||
"${pwd}/features-nixos/optional/remote-builder.nix"
|
||||
# "${pwd}/features-nixos/optional/remote-builder.nix"
|
||||
"${pwd}/features-nixos/optional/boot-efi.nix"
|
||||
|
||||
"${pwd}/features-nixos/optional/greetd.nix"
|
||||
@@ -26,6 +26,7 @@
|
||||
"${pwd}/features-nixos/optional/podman.nix"
|
||||
"${pwd}/features-nixos/optional/wireshark.nix"
|
||||
"${pwd}/features-nixos/optional/flatpak.nix"
|
||||
"${pwd}/features-nixos/optional/k9s"
|
||||
];
|
||||
|
||||
networking.hostName = "kardorf";
|
||||
|
||||
@@ -3,4 +3,6 @@
|
||||
syncthing = import ./syncthing.nix;
|
||||
frajulAutoUpgrade = import ./frajul-auto-upgrade.nix;
|
||||
pianoLEDVisualizer = import ./piano-led-visualizer.nix;
|
||||
gitea-runner = import ./gitea-runner.nix;
|
||||
gitlab-runner = import ./gitlab-runner.nix;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,57 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}: let
|
||||
cfg = config.frajul.gitea-runner;
|
||||
in {
|
||||
options = {
|
||||
frajul.gitea-runner = {
|
||||
enable = lib.mkEnableOption "gitea-runner";
|
||||
secretsFile = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
description = "A sops encrpyted file containing a 'gitea_token' secret";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
virtualisation.docker.enable = true;
|
||||
|
||||
sops.secrets."gitea_token" = {
|
||||
owner = config.users.users.nix.name;
|
||||
sopsFile = cfg.secretsFile;
|
||||
};
|
||||
|
||||
services.gitea-actions-runner.instances."builder" = {
|
||||
enable = true;
|
||||
url = "https://gitlab.julian-mutter.de";
|
||||
name = "builder";
|
||||
tokenFile = config.sops.secrets."gitea_token".path;
|
||||
labels = [
|
||||
# fake the ubuntu name, because node provides no ubuntu builds
|
||||
"ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest"
|
||||
# my custom nix+devenv ci container
|
||||
"nix-ci:docker://gitlab.julian-mutter.de/julian/nix-ci-container:latest"
|
||||
# devenv
|
||||
"devenv:docker://ghcr.io/cachix/devenv/devenv:latest"
|
||||
# provide native execution on the host
|
||||
"nixos:host"
|
||||
];
|
||||
# Packages are intjected into PATH for "nixos:host"
|
||||
hostPackages = with pkgs; [
|
||||
bash
|
||||
coreutils
|
||||
curl
|
||||
gawk
|
||||
gitMinimal
|
||||
nodejs # Required by many standard actions (like actions/checkout)
|
||||
docker
|
||||
devenv
|
||||
wget
|
||||
nix
|
||||
];
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
...
|
||||
}: let
|
||||
cfg = config.frajul.gitlab-runner;
|
||||
in {
|
||||
options = {
|
||||
frajul.gitlab-runner = {
|
||||
enable = lib.mkEnableOption "gitlab-runner";
|
||||
secretsFile = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
description = "A sops encrpyted file containing a 'gitlab_runner_token' secret";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
services.gitlab-runner.enable = true;
|
||||
|
||||
sops.secrets."gitlab_runner_token".sopsFile = cfg.secretsFile;
|
||||
services.gitlab-runner.services.default = {
|
||||
# File should contain at least these two variables:
|
||||
authenticationTokenConfigFile = config.sops.secrets."gitlab_runner_token".path;
|
||||
dockerImage = "alpine:latest";
|
||||
dockerVolumes = [
|
||||
"/var/run/docker.sock:/var/run/docker.sock"
|
||||
];
|
||||
};
|
||||
};
|
||||
}
|
||||
Reference in New Issue
Block a user