This commit is contained in:
2026-07-04 05:01:54 +02:00
parent 524ee6e1ce
commit 12f0b1e422
116 changed files with 1355 additions and 231 deletions
+34
View File
@@ -0,0 +1,34 @@
{ config, pkgs, ... }:
{
boot = {
initrd = {
luks = {
devices."luks-9cd65807-a47b-4ffe-ac11-05680b9fffb0".device = "/dev/disk/by-uuid/9cd65807-a47b-4ffe-ac11-05680b9fffb0";
};
};
extraModulePackages = with config.boot.kernelPackages; [ ];
kernelParams = [ "debug" ];
loader = {
efi = {
# canTouchEfiVariables = true;
efiSysMountPoint = "/boot";
};
grub = {
enable = true;
copyKernels = true;
efiInstallAsRemovable = true;
enableCryptodisk = false;
efiSupport = true;
devices = [ "nodev" ];
extraEntries = ''
menuentry "Reboot" {
reboot
}
menuentry "Poweroff" {
halt
}
'';
};
};
};
}
+10
View File
@@ -0,0 +1,10 @@
{ config, pkgs, ... }:
{
imports = [
./boot.nix
./gaming.nix
./graphics.nix
./networking.nix
#./openrgb.nix
];
}
+4
View File
@@ -0,0 +1,4 @@
{ config, pkgs, ... }:
{
programs.steam.enable = true;
}
+12
View File
@@ -0,0 +1,12 @@
{ config, pkgs, ... }:
{
hardware = {
graphics = {
enable = true;
enable32Bit = true;
#extraPackage = [];
#extraPackage32 = [];
};
};
}
+25
View File
@@ -0,0 +1,25 @@
{ pkgs, ... }:
{
environment.systemPackages = with pkgs; [weechat];
services = {
weechat = {
enable = true;
};
tor = {
enable = true;
controlSocket.enable = true;
client = {
enable = true;
socksListenAddress = {
addr = "127.0.0.1";
port = 9050;
};
};
settings = {
MapAddress = "palladium.libera.chat libera75jm6of4wxpxt4aynol3xjmbtxgfyjpu34ss4d7r7q2v5zrpyd.onion";
ControlPort = [ 9051 ];
};
};
};
}
+22
View File
@@ -0,0 +1,22 @@
{ config, pkgs, ... }:
{
environment.systemPackages = with pkgs; [ wireguard-tools ];
services = {
mullvad-vpn = {
enable = true;
package = pkgs.mullvad-vpn;
};
};
networking = {
networkmanager = {
enable = true;
};
firewall = {
enable = false;
checkReversePath = false;
allowedTCPPorts = [];
allowedUDPPorts = [];
};
};
}
+27
View File
@@ -0,0 +1,27 @@
{ config, pkgs, lib, ... }:
let
no-rgb = pkgs.writeScriptBin "no-rgb" ''
#!/bin/sh
NUM_DEVICES=$(${pkgs.openrgb}/bin/openrgb --noautoconnect --list-devices | grep -E '^[0-9]+: ' | wc -l)
for i in $(seq 0 $(($NUM_DEVICES - 1))); do
${pkgs.openrgb}/bin/openrgb --noautoconnect --device $i --mode static --color 000000
done
'';
in {
config = {
services.udev.packages = [ pkgs.openrgb ];
boot.kernelModules = [ "i2c-dev" ];
hardware.i2c.enable = true;
systemd.services.no-rgb = {
description = "no-rgb";
serviceConfig = {
ExecStart = "${no-rgb}/bin/no-rgb";
#Type = "oneshot";
};
wantedBy = [ "multi-user.target" ];
};
};
}
+3 -2
View File
@@ -4,10 +4,11 @@
imports =
[
./hardware-configuration.nix
../../modules/default.nix
./config/default.nix
../../config/default/default.nix
];
networking.hostName = "darkstar";
boot.initrd.luks.devices."luks-9cd65807-a47b-4ffe-ac11-05680b9fffb0".device = "/dev/disk/by-uuid/9cd65807-a47b-4ffe-ac11-05680b9fffb0";
time.timeZone = "Europe/Berlin";
nixpkgs.config.allowUnfree = true;
+25
View File
@@ -0,0 +1,25 @@
_:
{
boot = {
loader = {
systemd-boot = {
enable = true;
};
efi = {
canTouchEfiVariables = true;
};
};
initrd.systemd.enable = true;
supportedFilesystems = [ "zfs" ];
zfs = {
devNodes = "/dev/disk/by-id";
forceImportRoot = true;
forceImportAll = true;
};
kernelParams = [ "scsi_mod.scan=sync" "rootdelay=10" "zfs.zfs_arc_max=34359738368" ];
extraModprobeConfig = ''
options scsi_mod scan=sync
'';
};
}
+15
View File
@@ -0,0 +1,15 @@
_:
{
imports = [
./boot.nix
./networking.nix
./gnupg.nix
./pkgs.nix
./system.nix
./ssh.nix
./jellyfin.nix
./shell.nix
./freedom/default.nix
./docker/default.nix
];
}
+21
View File
@@ -0,0 +1,21 @@
{ config, pkgs, ... }:
{
virtualisation = {
oci-containers = {
backend = "docker";
};
docker = {
enable = true;
enableOnBoot = true;
rootless = {
enable = true;
setSocketVariable = true;
};
};
};
imports = [
./gluetun.nix
./qbittorrent.nix
./jdownloader.nix
];
}
+56
View File
@@ -0,0 +1,56 @@
{ config, pkgs, ... }:
let
protonvpnConfig = {
VPN_SERVICE_PROVIDER = "protonvpn";
VPN_PORT_FORWARDING = "on";
VPN_PORT_FORWARDING_PROVIDER="protonvpn";
};
gluetunConfig = {
SHADOWSOCKS = "on";
HTTPPROXY = "on";
HTTPPROXY_STEALTH = "on";
FIREWALL_OUTBOUND_SUBNETS="10.11.0.0/24";
DNS_UPSTREAM_RESOLVERS = "cloudflare";
BLOCK_SURVEILLANCE="on";
BLOCK_ADS="on";
BLOCK_MALICIOUS="on";
};
in
{
virtualisation.oci-containers.containers = {
# protonvpn
pvpn-de-01 = {
autoStart = true;
image = "qmcgaw/gluetun:latest";
capabilities = { NET_ADMIN = true; };
devices = [ "/dev/net/tun:/dev/net/tun" ];
environmentFiles = [
"/etc/secrets/gluetun.env"
];
environment = {
# GLUETUN ENV VARS #
VPN_TYPE="openvpn";
SERVER_COUNTRIES = "Germany";
VPN_INTERFACE="tun0";
} // protonvpnConfig // gluetunConfig;
ports = [
# gluetun
"8000:8000"
"7001:8388/tcp"
"7001:8388/udp"
"8001:8888"
# qbittorrent
"8080:8080"
"6881:6881/tcp"
"6881:6881/udp"
# jdownloader
"5800:5800"
];
};
};
}
@@ -0,0 +1,22 @@
_:
{
virtualisation.oci-containers.containers = {
# qbittorrent
jdownloader = {
autoStart = true;
image = "jlesage/jdownloader-2:latest";
networks = [
"container:pvpn-de-01"
];
environment = {
TZ="Europe/Berlin";
KEEP_APP_RUNNING="1";
DARK_MODE="1";
};
volumes = [
"/srv/docker/jdownloader/config:/config:rw"
"/srv/docker/jdownloader/downloads:/output:rw"
];
};
};
}
@@ -0,0 +1,21 @@
_:
{
virtualisation.oci-containers.containers = {
# qbittorrent
qbittorrent = {
autoStart = true;
image = "qbittorrentofficial/qbittorrent-nox:latest";
networks = [
"container:pvpn-de-01"
];
environment = {
WEBUI_PORT = "8080";
TZ="Europe/Berlin";
};
volumes = [
"/srv/docker/qbittorrent/config:/config"
"/srv/docker/qbittorrent/downloads:/downloads"
];
};
};
}
+9
View File
@@ -0,0 +1,9 @@
_:
{
imports = [
./invidious.nix
./nitter.nix
./tor.nix
./unbound.nix
];
}
@@ -0,0 +1,9 @@
{ config, pkgs, ... }:
{
services = {
invidious = {
enable = true;
port = 3001;
};
};
}
+14
View File
@@ -0,0 +1,14 @@
{ config, pkgs, ... }:
{
services = {
nitter = {
enable = true;
server = {
https = true;
port = 3002;
hostname = "nitter twitter";
};
};
};
}
+15
View File
@@ -0,0 +1,15 @@
_:
{
services.tor = {
enable = true;
enableGeoIP = true;
client = {
enable = true;
socksListenAddress = {
IsolateDestAddr = true;
addr = "10.11.0.10";
port = 9050;
};
};
};
}
+28
View File
@@ -0,0 +1,28 @@
_:
{
services.unbound = {
enable = true;
enableRootTrustAnchor = true;
settings = {
server = {
interface = [ "127.0.0.1" "10.11.0.10" ];
access-control = [
"127.0.0.0/8 allow"
"10.11.0.0/24 allow"
];
prefetch = true;
prefetch-key = true;
qname-minimisation = true;
hide-identity = true;
hide-version = true;
harden-glue = true;
harden-below-nxdomain = true;
harden-dnssec-stripped = true;
};
};
};
}
+4
View File
@@ -0,0 +1,4 @@
_:
{
}
+8
View File
@@ -0,0 +1,8 @@
_:
{
programs.gnupg.agent = {
enable = true;
enableSSHSupport = true;
};
}
+10
View File
@@ -0,0 +1,10 @@
{ config, pkgs, ... }:
{
home = {
username = "user";
homeDirectory = "/home/user";
enableNixpkgsReleaseCheck = false;
stateVersion = "26.05";
};
}
+9
View File
@@ -0,0 +1,9 @@
{ config, pkgs, ... }:
{
services = {
jellyfin = {
enable = true;
openFirewall = false;
};
};
}
+22
View File
@@ -0,0 +1,22 @@
_:
{
networking = {
hostName = "kepler";
hostId = "a984053d";
networkmanager = { enable = true; };
firewall = { enable = false; };
interfaces = {
eno1 = {
ipv4.addresses = [{
address = "10.11.0.10";
prefixLength = 24;
}];
};
};
defaultGateway = {
address = "10.11.0.1";
interface = "eno1";
};
};
}
+22
View File
@@ -0,0 +1,22 @@
{ pkgs, ... }:
{
environment.systemPackages = with pkgs; [
vim
wget
git
curl
fastfetch
net-tools
ethtool
dhcpcd
dig
usbutils
dhcpcd
host
dnslookup
drill
dig
tree
lsof
];
}
+8
View File
@@ -0,0 +1,8 @@
_:
{
services = {
openssh = {
enable = true;
};
};
}
+7
View File
@@ -0,0 +1,7 @@
_:
{
nix.settings.experimental-features = [ "nix-command" "flakes" ];
system = {
stateVersion = "26.05";
};
}
+13
View File
@@ -0,0 +1,13 @@
{ config, lib, pkgs, ... }:
{
imports = [
./hardware-configuration.nix
./config/default.nix
../../config/default/default.nix
];
time.timeZone = "Europe/Berlin";
}
+31
View File
@@ -0,0 +1,31 @@
{ config, lib, pkgs, modulesPath, ... }:
{
imports =
[ (modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [ "ehci_pci" "ahci" "mpt3sas" "usb_storage" "usbhid" "sd_mod" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "rpool/root";
fsType = "zfs";
};
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/9B62-3696";
fsType = "vfat";
options = [ "fmask=0022" "dmask=0022" ];
};
fileSystems."/data/storage" = {
device = "data/storage";
fsType = "zfs";
};
swapDevices = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
+34
View File
@@ -0,0 +1,34 @@
{ config, pkgs, ... }:
{
boot = {
initrd = {
luks = {
devices."luks-d810fef7-b1c9-4007-bcb1-12c99c8692b0".device = "/dev/disk/by-uuid/d810fef7-b1c9-4007-bcb1-12c99c8692b0";
};
};
extraModulePackages = with config.boot.kernelPackages; [ ];
kernelParams = [ "debug" ];
loader = {
efi = {
# canTouchEfiVariables = true;
efiSysMountPoint = "/boot";
};
grub = {
enable = true;
copyKernels = true;
efiInstallAsRemovable = true;
enableCryptodisk = false;
efiSupport = true;
devices = [ "nodev" ];
extraEntries = ''
menuentry "Reboot" {
reboot
}
menuentry "Poweroff" {
halt
}
'';
};
};
};
}
+10
View File
@@ -0,0 +1,10 @@
{ config, pkgs, ... }:
{
imports =
[
./boot.nix
./networking.nix
./pkgs.nix
./irc.nix
];
}
+25
View File
@@ -0,0 +1,25 @@
{ pkgs, ... }:
{
environment.systemPackages = with pkgs; [weechat];
services = {
weechat = {
enable = true;
};
tor = {
enable = true;
controlSocket.enable = true;
client = {
enable = true;
socksListenAddress = {
addr = "127.0.0.1";
port = 9050;
};
};
settings = {
MapAddress = "palladium.libera.chat libera75jm6of4wxpxt4aynol3xjmbtxgfyjpu34ss4d7r7q2v5zrpyd.onion";
ControlPort = [ 9051 ];
};
};
};
}
+22
View File
@@ -0,0 +1,22 @@
{ config, pkgs, ... }:
{
environment.systemPackages = with pkgs; [ wireguard-tools ];
services = {
mullvad-vpn = {
enable = true;
package = pkgs.mullvad-vpn;
};
};
networking = {
networkmanager = {
enable = true;
};
firewall = {
enable = false;
checkReversePath = false;
allowedTCPPorts = [];
allowedUDPPorts = [];
};
};
}
+4 -5
View File
@@ -2,17 +2,16 @@
{
imports =
[
./hardware-configuration.nix
../../modules/default.nix
./hardware-configuration.nix
./config/default.nix
../../config/default/default.nix
../../config/desktop/default.nix
];
networking.hostName = "molniya";
boot.initrd.luks.devices."luks-9cd65807-a47b-4ffe-ac11-05680b9fffb0".device = "/dev/disk/by-uuid/9cd65807-a47b-4ffe-ac11-05680b9fffb0";
time.timeZone = "Europe/Berlin";
services.openssh.enable = true;
+13
View File
@@ -0,0 +1,13 @@
_:
{
boot = {
loader = {
systemd-boot = {
enable = true;
};
efi = {
canTouchEfiVariables = true;
};
};
};
}
+13
View File
@@ -0,0 +1,13 @@
{ config, pkgs, ... }:
{
imports = [
#./dhcp.nix
#./nat.nix
#./firewall.nix
./users.nix
./networking.nix
./time.nix
./system.nix
./boot.nix
];
}
View File
View File
View File
+21
View File
@@ -0,0 +1,21 @@
_:
{
networking = {
hostName = "voyager";
networkmanager = { enable = true; };
firewall = { enable = false; };
interfaces = {
eno1 = {
ipv4.addresses = [{
address = "10.11.0.10";
prefixLength = 24;
}];
};
};
defaultGateway = {
address = "10.11.0.1";
interface = "eno1";
};
};
}
+7
View File
@@ -0,0 +1,7 @@
_:
{
nix.settings.experimental-features = [ "nix-command" "flakes" ];
system = {
stateVersion = "26.05";
};
}
+4
View File
@@ -0,0 +1,4 @@
_:
{
time.timeZone = "Europe/Berlin";
}
+15
View File
@@ -0,0 +1,15 @@
_:
{
users.users.user = {
isNormalUser = true;
extraGroups = [ "wheel" "docker" "network" "plugdev" ];
openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDdCJK3NBMbGwvSxXq0kp/FzWUU0l0D1WX8f4vBubtZ7" ];
};
security = {
doas = {
enable = true;
extraConfig = "permit nopass keepenv :wheel";
};
};
}
+11
View File
@@ -0,0 +1,11 @@
{ config, lib, pkgs, ... }:
{
imports = [
./hardware-configuration.nix
./config/default.nix
../../config/default/default.nix
];
}
+28
View File
@@ -0,0 +1,28 @@
{ config, lib, pkgs, modulesPath, ... }:
{
imports =
[ (modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "nvme" "usb_storage" "sd_mod" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "/dev/disk/by-uuid/dfbd029b-d568-41fc-93f3-43a6ac059661";
fsType = "ext4";
};
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/1942-B7E9";
fsType = "vfat";
options = [ "fmask=0022" "dmask=0022" ];
};
swapDevices = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}