Compare commits

...
14 Commits
Author SHA1 Message Date
ShatteredMINT 781ea4f7b5 disable all but public key auth for ssh 2026-07-07 20:55:02 +02:00
ShatteredMINT 734f9db4ba working qemu bridges 2026-07-07 20:47:08 +02:00
ShatteredMINT 3cf8aff4d9 fix typo wg-client 2026-06-15 10:37:00 +02:00
ShatteredMINT 56d4fe4a3d remove redundant option (see cb8f7107) 2026-06-14 22:45:42 +02:00
ShatteredMINT cb8f7107f5 disable sudo password 2026-06-14 22:44:43 +02:00
ShatteredMINT f5991f624a update 2026-06-14 22:42:03 +02:00
ShatteredMINT 54bf93d7a0 switch to amd graphics 2026-06-03 21:39:57 +02:00
ShatteredMINT 335a6b3238 make kdeconnect part of graphical setup 2026-05-13 11:13:12 +02:00
ShatteredMINT 07531e3691 change wireguard config to include DNS 2026-05-13 11:11:43 +02:00
ShatteredMINT db8c11c83a update 2026-05-12 10:25:07 +02:00
ShatteredMINT b09bd7f9f8 create starting neovim config 2026-05-12 10:21:58 +02:00
ShatteredMINT 9ced8b9273 new defaults after update 2026-05-12 09:29:15 +02:00
ShatteredMINT 18fe700d10 update 2026-05-06 13:17:00 +02:00
ShatteredMINT d8c9cf955e add kde-connect 2026-05-06 13:16:54 +02:00
10 changed files with 46 additions and 21 deletions
+9 -3
View File
@@ -83,6 +83,11 @@
htop
];
programs.neovim = {
withRuby = false;
withPython3 = false;
};
# Some programs need SUID wrappers, can be configured further or are
# started in user sessions.
# programs.mtr.enable = true;
@@ -98,10 +103,9 @@
enable = true;
ports = [ 22 ];
settings = {
PasswordAuthentication = true;
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;
# AllowUsers = [ "backup" ];
# UseDns = true;
AuthenticationMethods = "publickey";
X11Forwarding = false;
PermitRootLogin = "no";
};
@@ -133,5 +137,7 @@
system.stateVersion = "24.11"; # Did you read the comment?
nix.settings.trusted-users = [ "shatteredmint" ];
# if people get to that point we are fucked anyways
security.sudo.wheelNeedsPassword = false;
}
+2 -1
View File
@@ -12,6 +12,7 @@
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-amd sg" ];
boot.extraModulePackages = [ ];
boot.zfs.forceImportRoot = false;
fileSystems."/" =
{ device = "NIX_CONV_POOL/root";
@@ -63,7 +64,7 @@
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# make custom dns work while gracefully falling back on public servers
networking.networkmanager.insertNameservers = [ "192.168.178.108" ];
# networking.networkmanager.insertNameservers = [ "192.168.178.108" ];
# networking.interfaces.enp4s0f3u1u4u1.useDHCP = lib.mkDefault true;
# networking.interfaces.wlp2s0.useDHCP = lib.mkDefault true;
+6
View File
@@ -14,6 +14,7 @@
boot.kernelModules = [ "kvm-amd" "sg" ];
boot.extraModulePackages = [ ];
boot.binfmt.emulatedSystems = [ "aarch64-linux" ];
boot.zfs.forceImportRoot = false;
fileSystems."/" =
{ device = "NIX_DESK_POOL/root";
@@ -59,4 +60,9 @@
networking.networkmanager.enable = true; # Easiest to use and most distros use this by default.
# required for ZFS
networking.hostId = "00000001";
hardware.graphics = {
enable = true;
enable32Bit = true;
};
}
-2
View File
@@ -14,8 +14,6 @@
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
security.sudo.wheelNeedsPassword = false;
fileSystems."/" =
{ device = "/dev/disk/by-uuid/44444444-4444-4444-8888-888888888888";
fsType = "ext4";
Generated
+9 -9
View File
@@ -27,11 +27,11 @@
]
},
"locked": {
"lastModified": 1774875815,
"narHash": "sha256-PzqwM4njoB3aznqwPZUawD4uOcJeu7N6GBTJKg81EQ4=",
"lastModified": 1781365335,
"narHash": "sha256-zqDBhXMzfbdlO7F2bGHe7MOtB3xngd/+4ieMHDC+ZXo=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "9340f51314713c83360bf72d75c8b404778ab5b1",
"rev": "5b6f5733726a1b2ccafb5dec6ac4ca7299fad66c",
"type": "github"
},
"original": {
@@ -42,11 +42,11 @@
},
"nix-flatpak": {
"locked": {
"lastModified": 1768656715,
"narHash": "sha256-Sbh037scxKFm7xL0ahgSCw+X2/5ZKeOwI2clqrYr9j4=",
"lastModified": 1780908363,
"narHash": "sha256-llGS4y3Qh1eUkli3/Y2VY9FV3GOUKFZR1E2BDftt45Q=",
"owner": "gmodena",
"repo": "nix-flatpak",
"rev": "123fe29340a5b8671367055b75a6e7c320d6f89a",
"rev": "1df08625f0f8c7d6e300a0e5df7955bbb877d809",
"type": "github"
},
"original": {
@@ -57,11 +57,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1774709303,
"narHash": "sha256-D3Q07BbIA2KnTcSXIqqu9P586uWxN74zNoCH3h2ESHg=",
"lastModified": 1781074563,
"narHash": "sha256-md8WlXOlfnIeHeOScMTTHFyf2d6iaTwPl2apR5EQ3P4=",
"owner": "NixOs",
"repo": "nixpkgs",
"rev": "8110df5ad7abf5d4c0f6fb0f8f978390e77f9685",
"rev": "9ae611a455b90cf061d8f332b977e387bda8e1ca",
"type": "github"
},
"original": {
+1 -2
View File
@@ -26,7 +26,6 @@
specialArgs = inputs;
modules = [
./devices/desk.nix
./hardware/nvidia.nix
./hardware/scanner.nix
./configuration.nix
@@ -37,7 +36,7 @@
./backup-target.nix
./users/shatteredmint.nix
# ./qemu-bridges.nix
./qemu-bridges.nix
];
};
+1
View File
@@ -8,6 +8,7 @@
networking.interfaces.virtbr0 = {
useDHCP = true;
macAddress = "04:92:26:c3:06:c2";
};
virtualisation.libvirtd = {
+3
View File
@@ -18,6 +18,9 @@
makemkv
];
};
programs.kdeconnect.enable = true;
# enable flatpak
services.flatpak.enable = true;
home-manager.users.shatteredmint.imports = [
+5 -4
View File
@@ -5,16 +5,17 @@
{ip}: {
networking = {
firewall.allowedUDPPorts = [56878];
wireguard = {
enable = true;
wg-quick = {
# enable = true;
interfaces.wg0 = {
ips = [ ("192.168.87." + builtins.toString(ip) + "/32")];
address = [ ("192.168.87." + builtins.toString(ip) + "/32")];
listenPort = 56878;
privateKeyFile = "/root/wg.keys";
dns = [ "192.168.178.108" ];
peers = [
{
name = "hub";
# name = "hub";
publicKey = "XEaJXQW+7llbreoK161NkMhFxlctL1UK8nFiY/GtuC0=";
allowedIPs = [ "192.168.178.0/24" "192.168.87.127/32" "192.168.87.128/25"];
endpoint = "173.249.36.74:56878";
+10
View File
@@ -64,7 +64,17 @@
enable = true;
extraPackages = with pkgs; [
wl-clipboard
vimPlugins.lazy-nvim
];
withRuby = false;
withPython3 = false;
initLua = ''
vim.opt.rtp:prepend("${pkgs.vimPlugins.lazy-nvim.outPath}")
require ('config')
require ('plugins')
'';
};