init
This commit is contained in:
33
modules/laptop/bluetooth.nix
Normal file
33
modules/laptop/bluetooth.nix
Normal file
@@ -0,0 +1,33 @@
|
||||
# Module: Bluetooth Configuration
|
||||
# Description: Enables Bluetooth with dual controller mode and experimental features
|
||||
# Services: bluetooth, blueman (GUI manager)
|
||||
|
||||
{ config, lib, ... }:
|
||||
|
||||
{
|
||||
options.custom.bluetooth = {
|
||||
enable = lib.mkEnableOption "Bluetooth support with blueman GUI";
|
||||
|
||||
powerOnBoot = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = true;
|
||||
description = "Power on Bluetooth adapter on boot";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf config.custom.bluetooth.enable {
|
||||
hardware.bluetooth = {
|
||||
enable = true;
|
||||
powerOnBoot = config.custom.bluetooth.powerOnBoot;
|
||||
settings = {
|
||||
General = {
|
||||
ControllerMode = "dual";
|
||||
Privacy = "device";
|
||||
JustWorksRepairing = "always";
|
||||
Experimental = true;
|
||||
};
|
||||
};
|
||||
};
|
||||
services.blueman.enable = true;
|
||||
};
|
||||
}
|
||||
36
modules/laptop/default.nix
Normal file
36
modules/laptop/default.nix
Normal file
@@ -0,0 +1,36 @@
|
||||
# Module: Laptop Secrets & Base Configuration
|
||||
# Description: Secrets management (sops-nix) and keyboard layout
|
||||
# Services: sops-nix
|
||||
# Dependencies: sops-nix for secrets management
|
||||
# Note: Other laptop features (gaming, virtualization, etc.) are in separate modules
|
||||
|
||||
{ customConfig, ... }:
|
||||
|
||||
let
|
||||
userHome = "/home/${customConfig.username}";
|
||||
in
|
||||
{
|
||||
sops.validateSopsFiles = false;
|
||||
sops.age.keyFile = "${userHome}/.config/sops/age/keys.txt";
|
||||
|
||||
# WiFi networks configuration - entire network list encrypted
|
||||
sops.secrets.wifi-networks = {
|
||||
path = "/run/secrets/wifi-networks.conf";
|
||||
sopsFile = ../../secrets/wifi-networks.yaml;
|
||||
format = "yaml";
|
||||
key = "wifi-networks";
|
||||
owner = "wpa_supplicant";
|
||||
group = "wpa_supplicant";
|
||||
mode = "0400";
|
||||
};
|
||||
|
||||
sops.secrets.zwift = {
|
||||
path = "${userHome}/.config/zwift/config";
|
||||
sopsFile = ../../secrets/zwift.yaml;
|
||||
owner = customConfig.username;
|
||||
group = "users";
|
||||
mode = "0400";
|
||||
};
|
||||
|
||||
services.xserver.xkb.layout = "fr";
|
||||
}
|
||||
10
modules/laptop/fingerprint.nix
Normal file
10
modules/laptop/fingerprint.nix
Normal file
@@ -0,0 +1,10 @@
|
||||
{ pkgs, ... }:
|
||||
|
||||
{
|
||||
services.fprintd.enable = true;
|
||||
services.fprintd.tod.enable = true;
|
||||
services.fprintd.tod.driver = pkgs.libfprint-2-tod1-goodix-550a;
|
||||
|
||||
security.pam.services.login.fprintAuth = true;
|
||||
security.pam.services.sudo.fprintAuth = true;
|
||||
}
|
||||
29
modules/laptop/gaming.nix
Normal file
29
modules/laptop/gaming.nix
Normal file
@@ -0,0 +1,29 @@
|
||||
# Module: Gaming Support
|
||||
# Description: Enables Steam and gamepad drivers (xpadneo for Xbox controllers)
|
||||
# Services: Steam, steam-hardware
|
||||
|
||||
{ config, lib, pkgs, ... }:
|
||||
|
||||
{
|
||||
options.custom.gaming = {
|
||||
enable = lib.mkEnableOption "gaming support (Steam, gamepad drivers)";
|
||||
|
||||
enableXpadneo = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = true;
|
||||
description = "Enable xpadneo driver for Xbox controllers";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf config.custom.gaming.enable {
|
||||
hardware.steam-hardware.enable = true;
|
||||
|
||||
programs.steam = {
|
||||
enable = true;
|
||||
};
|
||||
|
||||
boot.extraModulePackages = lib.mkIf config.custom.gaming.enableXpadneo [
|
||||
pkgs.linuxPackages.xpadneo
|
||||
];
|
||||
};
|
||||
}
|
||||
21
modules/laptop/power.nix
Normal file
21
modules/laptop/power.nix
Normal file
@@ -0,0 +1,21 @@
|
||||
# Module: Power Management
|
||||
# Description: CPU frequency governor and power management settings
|
||||
# Services: powerManagement
|
||||
|
||||
{ config, lib, ... }:
|
||||
|
||||
{
|
||||
options.custom.power = {
|
||||
enable = lib.mkEnableOption "power management configuration";
|
||||
|
||||
cpuGovernor = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "powersave";
|
||||
description = "CPU frequency governor (powersave, performance, ondemand, etc.)";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf config.custom.power.enable {
|
||||
powerManagement.cpuFreqGovernor = config.custom.power.cpuGovernor;
|
||||
};
|
||||
}
|
||||
33
modules/laptop/printing.nix
Normal file
33
modules/laptop/printing.nix
Normal file
@@ -0,0 +1,33 @@
|
||||
# Module: Printing Configuration
|
||||
# Description: CUPS printing service with configured printers
|
||||
# Services: printing (CUPS)
|
||||
|
||||
{ config, lib, ... }:
|
||||
|
||||
{
|
||||
options.custom.printing = {
|
||||
enable = lib.mkEnableOption "printing support (CUPS)";
|
||||
|
||||
printers = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.attrs;
|
||||
default = [];
|
||||
description = "List of printers to configure";
|
||||
};
|
||||
|
||||
defaultPrinter = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.str;
|
||||
default = null;
|
||||
description = "Default printer name";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf config.custom.printing.enable {
|
||||
services.printing.enable = true;
|
||||
|
||||
hardware.printers = lib.mkIf (config.custom.printing.printers != []) {
|
||||
ensurePrinters = config.custom.printing.printers;
|
||||
ensureDefaultPrinter = lib.mkIf (config.custom.printing.defaultPrinter != null)
|
||||
config.custom.printing.defaultPrinter;
|
||||
};
|
||||
};
|
||||
}
|
||||
60
modules/laptop/users.nix
Normal file
60
modules/laptop/users.nix
Normal file
@@ -0,0 +1,60 @@
|
||||
# Module: User Configuration
|
||||
# Description: Defines the main user 'alice' with groups, permissions, and user packages
|
||||
# Packages: Browsers (Firefox), Office (LibreOffice), Development (VSCode, Git),
|
||||
# Media (VLC, Spotify), Communication (Slack, Thunderbird), and more
|
||||
|
||||
{ pkgs, customConfig, ... }:
|
||||
|
||||
{
|
||||
users.users."${customConfig.username}" = {
|
||||
isNormalUser = true;
|
||||
home = "/home/${customConfig.username}";
|
||||
# Base groups - docker/vboxusers are added by virtualization.nix if enabled
|
||||
extraGroups = [ "wheel" "audio" "dialout" "plugdev" ];
|
||||
packages = with pkgs; [
|
||||
# Browsers & Web
|
||||
firefox
|
||||
|
||||
# Office & Productivity
|
||||
libreoffice
|
||||
onlyoffice-desktopeditors
|
||||
obsidian
|
||||
ticktick
|
||||
nextcloud-client
|
||||
|
||||
# Development
|
||||
neovim
|
||||
git
|
||||
vscode
|
||||
zotero
|
||||
tcpdump
|
||||
pandoc
|
||||
libsecret
|
||||
|
||||
# Communication
|
||||
slack
|
||||
thunderbird
|
||||
discord
|
||||
|
||||
# Media & Creative
|
||||
vlc
|
||||
spotify
|
||||
mixxx
|
||||
pympress
|
||||
|
||||
# Gaming & Entertainment
|
||||
prismlauncher # Minecraft launcher
|
||||
widelands # Strategy game
|
||||
wasistlos # Game
|
||||
moonlight-qt # Game streaming
|
||||
|
||||
# System & Cloud
|
||||
rclone
|
||||
fuse3
|
||||
pavucontrol
|
||||
tree
|
||||
sops
|
||||
age
|
||||
];
|
||||
};
|
||||
}
|
||||
42
modules/laptop/virtualization.nix
Normal file
42
modules/laptop/virtualization.nix
Normal file
@@ -0,0 +1,42 @@
|
||||
# Module: Virtualization
|
||||
# Description: Docker and VirtualBox virtualization support
|
||||
# Services: Docker daemon, VirtualBox
|
||||
|
||||
{ config, lib, pkgs, customConfig, ... }:
|
||||
|
||||
{
|
||||
options.custom.virtualization = {
|
||||
docker = {
|
||||
enable = lib.mkEnableOption "Docker container runtime";
|
||||
|
||||
dnsServers = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ "172.17.0.1" ];
|
||||
description = "DNS servers for Docker containers (points to dnscrypt-proxy)";
|
||||
};
|
||||
};
|
||||
|
||||
virtualbox = {
|
||||
enable = lib.mkEnableOption "VirtualBox virtualization";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkMerge [
|
||||
(lib.mkIf config.custom.virtualization.docker.enable {
|
||||
virtualisation.docker = {
|
||||
enable = true;
|
||||
daemon.settings = {
|
||||
# Docker DNS points to dnscrypt-proxy configured in net.nix
|
||||
dns = config.custom.virtualization.docker.dnsServers;
|
||||
};
|
||||
};
|
||||
|
||||
users.users."${customConfig.username}".extraGroups = [ "docker" ];
|
||||
})
|
||||
|
||||
(lib.mkIf config.custom.virtualization.virtualbox.enable {
|
||||
virtualisation.virtualbox.host.enable = true;
|
||||
users.users."${customConfig.username}".extraGroups = [ "vboxusers" ];
|
||||
})
|
||||
];
|
||||
}
|
||||
35
modules/laptop/zwift.nix
Normal file
35
modules/laptop/zwift.nix
Normal file
@@ -0,0 +1,35 @@
|
||||
# Module: Zwift Configuration
|
||||
# Description: Configures Zwift cycling simulator via Docker with proper networking
|
||||
# Services: Zwift Docker container
|
||||
# Ports: UDP 3022, 3024 / TCP 21587, 21588
|
||||
|
||||
{ config, lib, pkgs, customConfig, ... }:
|
||||
|
||||
{
|
||||
options.custom.zwift = {
|
||||
enable = lib.mkEnableOption "Zwift cycling simulator";
|
||||
};
|
||||
|
||||
config = lib.mkIf config.custom.zwift.enable {
|
||||
programs.zwift = {
|
||||
enable = true;
|
||||
image = "docker.io/netbrain/zwift";
|
||||
version = "latest"; # FIXME: Pin to specific version for reproducibility
|
||||
containerTool = "docker";
|
||||
zwiftWorkoutDir = "/var/lib/zwift/workouts";
|
||||
zwiftActivityDir = "/var/lib/zwift/activities";
|
||||
zwiftLogDir = "/var/lib/zwift/logs";
|
||||
zwiftScreenshotsDir = "/var/lib/zwift/screenshots";
|
||||
zwiftFg = true;
|
||||
networking = "bridge";
|
||||
# Use actual user UID/GID instead of hardcoded 1000
|
||||
zwiftUid = toString config.users.users."${customConfig.username}".uid;
|
||||
zwiftGid = toString config.users.groups.users.gid;
|
||||
};
|
||||
|
||||
networking.firewall = {
|
||||
allowedUDPPorts = [ 3022 3024 ];
|
||||
allowedTCPPorts = [ 21587 21588 ];
|
||||
};
|
||||
};
|
||||
}
|
||||
Reference in New Issue
Block a user