@@ -0,0 +1,231 @@
# Edit this configuration file to define what should be installed on
# your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running ‘ nixos-help’ ).
{ inputs , lib , config , pkgs , . . . }:
{
imports =
[ # Include the results of the hardware scan.
./hardware-configuration.nix
# NixCommunity binary cache
./cachix.nix
] ;
# Enable flakes
# Keep nix-shell from grabage collection for direnv (keep-outputs + keep-derivations)
nix = {
package = pkgs . nixFlakes ;
extraOptions = ''
e x p e r i m e n t a l - f e a t u r e s = n i x - c o m m a n d f l a k e s
k e e p - o u t p u t s = t r u e
k e e p - d e r i v a t i o n s = t r u e
'' ;
} ;
# TODO: Understand this
# This will add your inputs as registries, making operations with them (such
# as nix shell nixpkgs#name) consistent with your flake inputs.
nix . registry = lib . mapAttrs' ( n : v : lib . nameValuePair n { flake = v ; } ) inputs ;
# TODO: Understand that
# Will activate home-manager profiles for each user upon login
# This is useful when using ephemeral installations
environment . loginShellInit = ''
[ - d " $H O M E / . n i x - p r o f i l e " ] | | / n i x / v a r / n i x / p r o f i l e s / p e r - u s e r / $U S E R / h o m e - m a n a g e r / a c t i v a t e & > / d e v / n u l l
'' ;
# Kernel
boot . kernelPackages = pkgs . linuxPackages_zen ;
boot . kernelParams = [ " m i t i g a t i o n s = o f f " ] ;
security . protectKernelImage = true ;
# Bootloader.
boot . loader . systemd-boot . enable = true ;
boot . loader . systemd-boot . configurationLimit = 5 ;
boot . loader . systemd-boot . editor = false ;
boot . loader . systemd-boot . consoleMode = " m a x " ;
boot . loader . efi . canTouchEfiVariables = true ;
boot . loader . efi . efiSysMountPoint = " / b o o t / e f i " ;
hardware . cpu . intel . updateMicrocode = true ;
# Make /tmp volatile
boot . tmpOnTmpfs = true ;
networking . hostName = " n i x i n a t o r " ; # Define your hostname.
# networking.wireless.enable = true; # Enables wireless support via wpa_supplicant.
# Configure network proxy if necessary
# networking.proxy.default = "http://user:password@proxy:port/";
# networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain";
# Enable networking
networking . networkmanager . enable = true ;
# Set your time zone.
time . timeZone = " E u r o p e / B e r l i n " ;
# Select internationalisation properties.
i18n . defaultLocale = " e n _ U S . U T F - 8 " ;
i18n . extraLocaleSettings = {
LC_ADDRESS = " d e _ D E . U T F - 8 " ;
LC_IDENTIFICATION = " d e _ D E . U T F - 8 " ;
LC_MEASUREMENT = " d e _ D E . U T F - 8 " ;
LC_MONETARY = " d e _ D E . U T F - 8 " ;
LC_NAME = " d e _ D E . U T F - 8 " ;
LC_NUMERIC = " d e _ D E . U T F - 8 " ;
LC_PAPER = " d e _ D E . U T F - 8 " ;
LC_TELEPHONE = " d e _ D E . U T F - 8 " ;
LC_TIME = " d e _ D E . U T F - 8 " ;
} ;
# Enable the X11 windowing system.
services . xserver . enable = true ;
# Enable the KDE Plasma Desktop Environment.
services . xserver . videoDrivers = [ " n v i d i a " ] ;
hardware . nvidia . modesetting . enable = true ; # Not officially supported by NVidia
services . xserver . displayManager . sddm . enable = true ;
services . xserver . desktopManager . plasma5 . enable = true ;
services . xserver . desktopManager . plasma5 . runUsingSystemd = true ;
# Configure keymap in X11
services . xserver = {
layout = " u s " ;
xkbVariant = " a l t g r - i n t l " ;
} ;
# Enable CUPS to print documents.
services . printing . enable = true ;
# TODO: Printer driver
services . avahi . enable = true ; # Network printers
services . avahi . nssmdns = true ;
hardware . sane . enable = true ; # Scanning
# Enable sound with pipewire.
sound . enable = true ;
hardware . pulseaudio . enable = false ;
security . rtkit . enable = true ;
services . pipewire = {
enable = true ;
alsa . enable = true ;
alsa . support32Bit = true ;
pulse . enable = true ;
# If you want to use JACK applications, uncomment this
jack . enable = true ; # We need this for low latency audio
# use the example session manager (no others are packaged yet so this is enabled by default,
# no need to redefine it in your config for now)
#media-session.enable = true;
} ;
# Enable touchpad support (enabled default in most desktopManager).
# services.xserver.libinput.enable = true;
# Define a user account. Don't forget to set a password with ‘ passwd’ .
users . users . christoph = {
isNormalUser = true ;
description = " C h r i s t o p h " ;
extraGroups = [ " n e t w o r k m a n a g e r " " w h e e l " " a u d i o " " r e a l t i m e " " d o c k e r " " a d b u s e r s " " s c a n n e r " " l p " ] ;
shell = pkgs . fish ;
# Do this with HomeManager
packages = with pkgs ; [
# firefox
# kate
# thunderbird
] ;
} ;
environment . shells = with pkgs ; [ fish ] ;
# Allow unfree packages
nixpkgs . config . allowUnfree = true ;
# List packages installed in system profile. To search, run:
# $ nix search wget
environment . systemPackages = with pkgs ; [
vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default.
wget
git
dosfstools
ntfs3g
e2fsprogs
] ;
# Auto garbage-collect and optimize store
nix . gc . automatic = true ;
nix . gc . options = " - - d e l e t e - o l d e r - t h a n 5 d " ;
nix . autoOptimiseStore = true ;
nix . optimise . automatic = true ;
# Use all redistributable firmware (i.e. nonfree)
hardware . enableRedistributableFirmware = true ;
# Enable automatic upgrades.
system . autoUpgrade . enable = false ;
system . autoUpgrade . allowReboot = false ;
# Docker
virtualisation . docker = {
enable = true ;
autoPrune . enable = true ;
} ;
# Some programs need SUID wrappers, can be configured further or are
# started in user sessions.
# programs.mtr.enable = true;
# programs.gnupg.agent = {
# enable = true;
# enableSSHSupport = true;
# };
# List services that you want to enable:
# Enable the OpenSSH daemon.
services . openssh . enable = true ;
services . journald . extraConfig = ''
S y s t e m M a x U s e = 5 0 M
'' ;
# TODO: What to transfer to HomeManager?
services . lorri . enable = true ; # Cache direnv
services . locate . enable = true ; # Periodically update index
services . emacs . enable = false ; # timeout?
services . fstrim . enable = true ;
services . xserver . wacom . enable = true ;
# TODO: Other ports (tcp/udp/ssh...)?
# Open ports in the firewall.
networking . firewall . allowedTCPPorts = [ ] ;
networking . firewall . allowedTCPPortRanges = [
{ # KDEConnect
from = 1714 ;
to = 1764 ;
}
] ;
networking . firewall . allowedUDPPorts = [ ] ;
networking . firewall . allowedUDPPortRanges = [
{ # KDEConnect
from = 1714 ;
to = 1764 ;
}
] ;
# Or disable the firewall altogether.
# networking.firewall.enable = false;
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions
# on your system were taken. It‘ s perfectly fine and recommended to leave
# this value at the release version of the first install of this system.
# Before changing this value read the documentation for this option
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
system . stateVersion = " 2 2 . 0 5 " ; # Did you read the comment?
}