# Raspberry Pi 5 (aarch64) headless server. Two roles, split into submodules: # ./docker.nix (Docker host with a network socket) and ./reverse-proxy.nix # (native nginx). The raspberry-pi-5 nixos-hardware profile (kernel, firmware, # device tree) and key-only sshd (../../modules/ssh.nix) are layered on in the # flake host table. Install notes: see ../../docs/hosts/rpi5.md. { ... }: { imports = [ ./hardware-configuration.nix ./docker.nix ./reverse-proxy.nix ]; # Match the flake's nixosConfigurations attribute name so `nh os switch` # (which selects by the local hostname) resolves without an explicit -H flag. networking.hostName = "lyrathorpe-rpi5"; # Headless server: the Sway desktop is intentionally not set up. modules/sway.nix is # not imported and features.swayDesktop.enable defaults to false (declared in # modules/features.nix), so this host keeps plain TTY/SSH login. # Raspberry Pi boots via U-Boot + extlinux, not GRUB/systemd-boot. The # raspberry-pi-5 nixos-hardware profile supplies the kernel, firmware and # device tree. boot.loader.grub.enable = false; boot.loader.generic-extlinux-compatible.enable = true; # Remote administration: the daemon, port 22 and key-only policy all come from # ../../modules/ssh.nix. # Default-deny inbound; the Docker and nginx submodules open their own ports # (Docker via a source-restricted nftables rule, nginx via 80/443). networking.firewall.enable = true; # See `man configuration.nix` / the stateVersion docs before changing. system.stateVersion = "26.05"; }