Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
58 lines
2.4 KiB
Nix
58 lines
2.4 KiB
Nix
# ThinkPad T400 (NixOS). Shared laptop options live in ../../modules/laptop.nix;
|
|
# only host-specific settings are here. Install notes (boot variants, GPU,
|
|
# partitions): see ./README.md.
|
|
{ config, ... }:
|
|
|
|
{
|
|
imports = [
|
|
./hardware-configuration.nix
|
|
# Boot: import exactly ONE, matching the firmware currently flashed.
|
|
# Stock Lenovo BIOS and coreboot+SeaBIOS both use boot-bios.nix.
|
|
./boot-bios.nix
|
|
# ./boot-coreboot-grub.nix # coreboot with the GRUB payload (config-only GRUB)
|
|
# ./boot-coreboot-uefi.nix # coreboot with the Tianocore/edk2 UEFI payload
|
|
# # (systemd-boot; carries its own ESP mount)
|
|
];
|
|
|
|
networking.hostName = "T400-NixOS";
|
|
|
|
console.font = "Lat2-Terminus16";
|
|
|
|
# Low-RAM host (4 GiB max): a compressed RAM swap reduces disk paging.
|
|
zramSwap.enable = true;
|
|
|
|
# This host accepts SSH, so open 22 (the firewall itself is enabled in
|
|
# laptop.nix with a default-deny policy).
|
|
services.openssh.enable = true;
|
|
networking.firewall.allowedTCPPorts = [ 22 ];
|
|
|
|
# Intel Core 2 (Penryn) microcode. Redistributable firmware (enabled in
|
|
# workstation.nix) supplies the iwlwifi blobs (Intel WiFi Link 5100/5300) and
|
|
# the radeon firmware needed by the discrete GPU below.
|
|
hardware.cpu.intel.updateMicrocode = true;
|
|
|
|
# Battery longevity: cap charging to 75-80%. tlp itself comes from the
|
|
# nixos-hardware lenovo-thinkpad profile; tp_smapi supplies the threshold
|
|
# sysfs on this 2008-era ThinkPad (kernel-native natacpi is too new for it).
|
|
boot.kernelModules = [ "tp_smapi" ];
|
|
boot.extraModulePackages = [ config.boot.kernelPackages.tp_smapi ];
|
|
services.tlp.settings = {
|
|
START_CHARGE_THRESH_BAT0 = 75;
|
|
STOP_CHARGE_THRESH_BAT0 = 80;
|
|
};
|
|
|
|
# This T400 has the optional discrete GPU fitted: an ATI Mobility Radeon HD
|
|
# 3470 (RV620), driven by the open `radeon` KMS driver. Load it in the initrd
|
|
# for early modesetting (clean Sway/Wayland start); firmware comes from
|
|
# enableRedistributableFirmware above.
|
|
#
|
|
# The T400 has switchable graphics (this discrete GPU + the Intel GMA
|
|
# 4500MHD). Select "Discrete" in the firmware's graphics setting so only the
|
|
# ATI is live; if you instead run "Integrated", the Intel i915 driver takes
|
|
# over with no extra config and `radeon` simply stays idle.
|
|
boot.initrd.kernelModules = [ "radeon" ];
|
|
|
|
# See `man configuration.nix` / the stateVersion docs before changing.
|
|
system.stateVersion = "26.05";
|
|
}
|