Benjamin Bädorf
03685e9887
All checks were successful
continuous-integration/drone/push Build is passing
214 lines
6.3 KiB
Nix
214 lines
6.3 KiB
Nix
{
|
|
description = "A highly structured configuration database.";
|
|
|
|
nixConfig.extra-experimental-features = "nix-command flakes";
|
|
|
|
inputs = {
|
|
# Track channels with commits tested and built by hydra
|
|
nixos.url = "github:nixos/nixpkgs/nixos-23.05";
|
|
latest.url = "github:nixos/nixpkgs/nixos-unstable";
|
|
|
|
flake-compat.url = "github:edolstra/flake-compat";
|
|
flake-compat.flake = false;
|
|
|
|
digga.url = "github:pub-solar/digga/fix/bootstrap-iso";
|
|
digga.inputs.nixpkgs.follows = "nixos";
|
|
digga.inputs.nixlib.follows = "nixos";
|
|
digga.inputs.home-manager.follows = "home";
|
|
digga.inputs.deploy.follows = "deploy";
|
|
digga.inputs.darwin.follows = "darwin";
|
|
digga.inputs.flake-compat.follows = "flake-compat";
|
|
|
|
home.url = "github:nix-community/home-manager/release-23.05";
|
|
home.inputs.nixpkgs.follows = "nixos";
|
|
|
|
darwin.url = "github:LnL7/nix-darwin";
|
|
darwin.inputs.nixpkgs.follows = "nixos";
|
|
|
|
deploy.url = "github:serokell/deploy-rs";
|
|
deploy.inputs.nixpkgs.follows = "nixos";
|
|
deploy.inputs.flake-compat.follows = "flake-compat";
|
|
|
|
agenix.url = "github:ryantm/agenix";
|
|
agenix.inputs.nixpkgs.follows = "nixos";
|
|
agenix.inputs.darwin.follows = "darwin";
|
|
|
|
nixos-hardware.url = "github:nixos/nixos-hardware";
|
|
|
|
keycloak-theme-pub-solar.url = "git+https://git.pub.solar/pub-solar/keycloak-theme?ref=main";
|
|
keycloak-theme-pub-solar.inputs.nixpkgs.follows = "nixos";
|
|
|
|
master.url = "github:nixos/nixpkgs/master";
|
|
fix-yubikey-agent.url = "github:pub-solar/nixpkgs/fix/use-latest-unstable-yubikey-agent";
|
|
fix-atomic-container-restarts.url = "github:pub-solar/nixpkgs/fix/atomic-container-restarts";
|
|
scan2paperless.url = "git+https://git.pub.solar/b12f/scan2paperless.git";
|
|
musnix.url = "github:musnix/musnix";
|
|
|
|
adblock-unbound.url = "github:MayNiklas/nixos-adblock-unbound";
|
|
adblock-unbound.inputs.nixpkgs.follows = "nixos";
|
|
};
|
|
|
|
outputs = {
|
|
self,
|
|
digga,
|
|
nixos,
|
|
home,
|
|
nixos-hardware,
|
|
agenix,
|
|
deploy,
|
|
scan2paperless,
|
|
musnix,
|
|
...
|
|
} @ inputs:
|
|
digga.lib.mkFlake
|
|
{
|
|
inherit self inputs;
|
|
|
|
channelsConfig = {
|
|
allowUnfree = true;
|
|
};
|
|
|
|
supportedSystems = ["x86_64-linux" "aarch64-linux" "aarch64-darwin"];
|
|
|
|
channels = {
|
|
nixos = {
|
|
imports = [(digga.lib.importOverlays ./overlays)];
|
|
overlays = [
|
|
(self: super: {
|
|
deploy-rs = {
|
|
inherit (inputs.nixos.legacyPackages.x86_64-linux) deploy-rs;
|
|
lib = inputs.deploy.lib.x86_64-linux;
|
|
};
|
|
})
|
|
];
|
|
};
|
|
latest = {};
|
|
};
|
|
|
|
lib = import ./lib {lib = digga.lib // nixos.lib;};
|
|
|
|
sharedOverlays = [
|
|
(final: prev: {
|
|
__dontExport = true;
|
|
lib = prev.lib.extend (lfinal: lprev: {
|
|
our = self.lib;
|
|
});
|
|
})
|
|
agenix.overlays.default
|
|
|
|
(import ./pkgs)
|
|
];
|
|
|
|
nixos = {
|
|
hostDefaults = {
|
|
system = "x86_64-linux";
|
|
channelName = "nixos";
|
|
imports = [(digga.lib.importExportableModules ./modules)];
|
|
modules = [
|
|
{lib.our = self.lib;}
|
|
# FIXME: upstream module causes a huge number of unnecessary
|
|
# dependencies to be pulled in for all systems -- many of them are
|
|
# graphical. should only be imported as needed.
|
|
# digga.nixosModules.bootstrapIso
|
|
digga.nixosModules.nixConfig
|
|
home.nixosModules.home-manager
|
|
agenix.nixosModules.age
|
|
musnix.nixosModules.musnix
|
|
];
|
|
};
|
|
|
|
imports = [(digga.lib.importHosts ./hosts)];
|
|
hosts = {
|
|
# Set host-specific properties here
|
|
bootstrap = {
|
|
modules = [
|
|
digga.nixosModules.bootstrapIso
|
|
];
|
|
};
|
|
PubSolarOS = {
|
|
tests = [
|
|
#(import ./tests/first-test.nix {
|
|
# pkgs = nixos.legacyPackages.x86_64-linux;
|
|
# lib = nixos.lib;
|
|
#})
|
|
];
|
|
};
|
|
|
|
pie = {
|
|
system = "aarch64-linux";
|
|
modules = [nixos-hardware.nixosModules.raspberry-pi-4];
|
|
};
|
|
};
|
|
importables = rec {
|
|
profiles =
|
|
digga.lib.rakeLeaves ./profiles
|
|
// {
|
|
users = digga.lib.rakeLeaves ./users;
|
|
};
|
|
|
|
suites = with profiles; rec {
|
|
base = [users.pub-solar users.root];
|
|
iso = base ++ [base-user graphical pub-solar-iso];
|
|
pubsolaros = [full-install base-user users.root];
|
|
anonymous = [pubsolaros users.pub-solar];
|
|
|
|
b12f = pubsolaros ++ [users.b12f social gaming mobile];
|
|
biolimo = b12f ++ [graphical];
|
|
chocolatebar = b12f ++ [graphical virtualisation];
|
|
|
|
yule = pubsolaros ++ [users.yule];
|
|
droppie = yule ++ [];
|
|
pie = yule ++ [];
|
|
maoam = b12f ++ [];
|
|
};
|
|
};
|
|
};
|
|
|
|
home = {
|
|
imports = [(digga.lib.importExportableModules ./users/modules)];
|
|
modules = [];
|
|
importables = rec {
|
|
profiles = digga.lib.rakeLeaves ./users/profiles;
|
|
suites = with profiles; rec {
|
|
base = [direnv git];
|
|
};
|
|
};
|
|
users = let
|
|
default = {suites, ...}: {
|
|
imports = suites.base;
|
|
home.stateVersion = "21.03";
|
|
};
|
|
in {
|
|
pub-solar = default;
|
|
b12f = default;
|
|
yule = default;
|
|
};
|
|
};
|
|
|
|
devshell = ./shell;
|
|
|
|
homeConfigurations = digga.lib.mkHomeConfigurations self.nixosConfigurations;
|
|
|
|
deploy.nodes = digga.lib.mkDeployNodes self.nixosConfigurations {
|
|
droppie = {
|
|
hostname = "backup.b12f.io";
|
|
sshUser = "yule";
|
|
};
|
|
|
|
pie = {
|
|
sshUser = "yule";
|
|
};
|
|
#example = {
|
|
# hostname = "example.com:22";
|
|
# sshUser = "bartender";
|
|
# fastConnect = true;
|
|
# profilesOrder = ["system" "direnv"];
|
|
# profiles.direnv = {
|
|
# user = "bartender";
|
|
# path = self.pkgs.x86_64-linux.nixos.deploy-rs.lib.x86_64-linux.activate.home-manager self.homeConfigurationsPortable.x86_64-linux.bartender;
|
|
# };
|
|
#};
|
|
};
|
|
};
|
|
}
|