CI / flake (push) Skipped
CI / flake (pull_request) Successful in 4m6s
security.sudo-rs.enable sets security.sudo.enable = false via mkDefault, so this is a straight swap; the two modules assert against being on together. The fleet only uses the stock policy -- wheel may run anything, with a password -- which sudo-rs implements fully. It does not cover host aliases, LDAP/SSSD sudoers, sudoreplay or most Defaults settings; needing any of those means reverting to security.sudo. The macOS host is unaffected and keeps Apple's sudo with Touch ID. Recovery from a host that will not escalate is documented in the module and in home/README.md: get a root shell that does not go through sudo, then roll back the generation.
79 lines
3.2 KiB
Nix
79 lines
3.2 KiB
Nix
# Options shared by every NixOS host (laptops and the WSL box). Imported via
|
|
# baseModules in flake.nix. Host- and platform-specific settings stay in the
|
|
# per-machine configs; laptop-only settings live in ./laptop.nix.
|
|
{ pkgs, ... }:
|
|
{
|
|
time.timeZone = "Europe/London";
|
|
i18n.defaultLocale = "en_GB.UTF-8";
|
|
|
|
# Store hygiene. auto-optimise-store hard-links identical files in the store
|
|
# after each build (cheap dedupe; NOT a garbage collector -- there is
|
|
# deliberately no automatic GC timer). The larger download buffer avoids
|
|
# "buffer full" stalls when fetching big NARs over a fast link.
|
|
nix.settings.auto-optimise-store = true;
|
|
nix.settings.download-buffer-size = 134217728; # 128 MiB
|
|
|
|
# Extra binary cache for the nix-community toolchain (home-manager, nixvim,
|
|
# treefmt, ...). Merges with any host-specific caches (e.g. the Asahi cache on
|
|
# the MBP) rather than replacing them.
|
|
nix.settings.substituters = [ "https://nix-community.cachix.org" ];
|
|
nix.settings.trusted-public-keys = [
|
|
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
|
|
];
|
|
|
|
# Run dynamically-linked foreign binaries (VS Code remote server, prebuilt
|
|
# toolchains, language-server downloads) on every NixOS host, not just WSL.
|
|
programs.nix-ld.enable = true;
|
|
|
|
# Memory-safe sudo. The two modules assert against being enabled together;
|
|
# this one sets `security.sudo.enable = false` via mkDefault, so it is a
|
|
# straight swap and not an addition.
|
|
#
|
|
# Safe here because this fleet only ever uses the stock policy -- wheel may
|
|
# run anything, with a password -- which sudo-rs implements completely. It
|
|
# does not cover the more exotic sudoers surface (host aliases, LDAP/SSSD
|
|
# sudoers, most `Defaults` settings, `sudoreplay`); adding any of those means
|
|
# going back to `security.sudo`.
|
|
#
|
|
# Recovery if a host ever refuses to escalate: get a root shell without sudo
|
|
# (`wsl -u root -d NixOS` on the WSL box, the console or a serial/HDMI login
|
|
# elsewhere) and roll back -- `nixos-rebuild switch --rollback`, or pick the
|
|
# previous generation from the boot menu.
|
|
security.sudo-rs.enable = true;
|
|
|
|
# Minimal system-level CLI available before the home-manager profile loads
|
|
# (e.g. early boot / rescue). User-level tooling lives in home-manager.
|
|
environment.systemPackages = with pkgs; [
|
|
git
|
|
fastfetch
|
|
];
|
|
|
|
# Fonts on every host. The Nerd Font carries the powerline/Nerd glyphs the
|
|
# tmux statusline uses (foot names it explicitly in home/sway.nix); Noto sans +
|
|
# colour emoji prevent tofu in terminals/TUIs/Firefox -- important on the WSL
|
|
# box, which does not pull the graphical hosts' default Noto stack. The Mac
|
|
# installs the Nerd Font via the Darwin config.
|
|
fonts.packages = with pkgs; [
|
|
nerd-fonts.jetbrains-mono
|
|
noto-fonts
|
|
noto-fonts-color-emoji
|
|
];
|
|
# Map the generic fontconfig families so anything asking for "monospace" gets
|
|
# the Nerd Font (with emoji fallback), not DejaVu.
|
|
fonts.fontconfig.defaultFonts = {
|
|
monospace = [
|
|
"JetBrainsMono Nerd Font"
|
|
"Noto Color Emoji"
|
|
];
|
|
sansSerif = [
|
|
"Noto Sans"
|
|
"Noto Color Emoji"
|
|
];
|
|
serif = [
|
|
"Noto Serif"
|
|
"Noto Color Emoji"
|
|
];
|
|
emoji = [ "Noto Color Emoji" ];
|
|
};
|
|
}
|