Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
50 lines
2.0 KiB
Nix
50 lines
2.0 KiB
Nix
# Form-factor-agnostic base for the physical graphical NixOS machines. Imported
|
|
# by both ./laptop.nix and ./desktop.nix; those add only the bits that differ
|
|
# between portable and desktop hosts (chiefly the networking backend).
|
|
#
|
|
# The bootloader is NOT set here -- it is firmware-specific, not form-factor:
|
|
# UEFI hosts (MBP, Mac Pro 3,1) use systemd-boot, the BIOS-only T400 uses GRUB.
|
|
# Each machine config declares its own.
|
|
{ lib, pkgs, ... }:
|
|
{
|
|
features.swayDesktop.enable = true;
|
|
|
|
console.keyMap = "dvorak";
|
|
|
|
# Intel thermal management. x86 only -- the Asahi MBP governs its own SoC
|
|
# thermals, and thermald is an Intel-platform daemon.
|
|
services.thermald.enable = lib.mkIf pkgs.stdenv.hostPlatform.isx86_64 true;
|
|
|
|
# Default-deny inbound. Hosts that run a listening service open their own
|
|
# ports next to where the service is enabled (e.g. sshd -> 22 on X1).
|
|
networking.firewall.enable = true;
|
|
|
|
# Disk hygiene for the physical hosts. fstrim reclaims unused SSD blocks on a
|
|
# weekly timer; cleanOnBoot wipes /tmp at every boot.
|
|
services.fstrim.enable = true;
|
|
boot.tmp.cleanOnBoot = true;
|
|
|
|
# Userspace OOM killer: act on memory pressure early instead of letting the
|
|
# kernel OOM-thrash. Matters on the 4 GiB T400 and the elderly Mac Pro.
|
|
services.earlyoom.enable = true;
|
|
|
|
# Firmware updates via LVFS. No-op on the Asahi MBP (Apple-managed firmware),
|
|
# useful for UEFI/SSD updates on the x86 hosts.
|
|
services.fwupd.enable = true;
|
|
|
|
# Audio. PipeWire with the PulseAudio shim covers every graphical host; no
|
|
# per-machine audio config is needed.
|
|
services.pipewire = {
|
|
enable = true;
|
|
pulse.enable = true;
|
|
};
|
|
|
|
# swaylock PAM stack. None of these machines has working fingerprint auth, so
|
|
# an empty service is enough -- swaylock falls back to password.
|
|
security.pam.services.swaylock = { };
|
|
|
|
# Redistributable firmware (GPU/Wi-Fi/NIC blobs) for the x86 hosts. Harmless
|
|
# on the Asahi MBP, which supplies its own peripheral firmware out-of-band.
|
|
hardware.enableRedistributableFirmware = true;
|
|
}
|