nix-conf/modules/nix/default.nix

74 lines
2 KiB
Nix
Raw Normal View History

2023-12-29 16:43:40 +01:00
{ config, lib, pkgs, self, ... }:
2023-05-19 20:53:02 +02:00
2023-12-30 23:39:33 +01:00
let cfg = config.jopejoe1.nix;
in {
options.jopejoe1.nix = { enable = lib.mkEnableOption "Enable Nix"; };
2023-05-19 20:53:02 +02:00
2023-12-29 16:43:40 +01:00
config = lib.mkIf cfg.enable {
nix = {
settings = {
2024-01-11 00:11:01 +01:00
substituters = lib.mkForce [
"https://cache.nixos.org"
"https://nix-community.cachix.org"
];
trusted-public-keys = lib.mkForce [
2023-12-29 16:43:40 +01:00
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
];
trusted-users = [ "root" ];
sandbox = true;
require-sigs = true;
max-jobs = "auto";
auto-optimise-store = true;
allowed-users = [ "*" ];
experimental-features = [ "nix-command" "flakes" ];
2024-01-11 00:11:01 +01:00
warn-dirty = true;
2023-12-29 16:43:40 +01:00
use-xdg-base-directories = true;
};
package = pkgs.nix;
2024-01-11 00:11:01 +01:00
registry = lib.mkForce ((lib.mapAttrs (_: flake: { inherit flake; })) ((lib.filterAttrs (_: lib.isType "flake")) self.inputs) // {
2024-01-10 23:55:40 +01:00
self.flake = self;
2024-01-11 00:11:01 +01:00
});
nixPath = lib.mkForce [ "/etc/nix/path" ];
2023-12-29 16:43:40 +01:00
};
2023-12-17 15:25:49 +01:00
2024-01-02 19:32:20 +01:00
nixpkgs = {
config.allowUnfree = true;
};
2024-01-10 23:55:40 +01:00
environment.etc = lib.mapAttrs' (name: value: { name = "nix/path/${name}"; value.source = value.flake; }) config.nix.registry;
2023-12-29 16:43:40 +01:00
environment.systemPackages = with pkgs; [
deploy-rs
nixfmt
nixpkgs-fmt
nix-index
nix-prefetch-git
nixpkgs-review
nurl
nix-init
];
2023-12-17 15:25:49 +01:00
2023-12-29 16:43:40 +01:00
home-manager = {
useGlobalPkgs = true;
useUserPackages = true;
backupFileExtension = "backup";
sharedModules = [
self.outputs.homeManagerModules.default
];
2023-12-29 16:43:40 +01:00
};
2023-05-19 20:53:02 +02:00
2023-12-29 16:43:40 +01:00
system.stateVersion = "24.05";
2024-01-10 23:55:40 +01:00
services.openssh = {
enable = true;
banner = "Hackers are in Your System!!!";
settings = {
PasswordAuthentication = false;
PermitRootLogin = "prohibit-password";
};
};
2024-01-02 20:58:18 +01:00
systemd.services.nix-daemon.serviceConfig.LimitNOFILE = lib.mkForce 1048576000;
2023-12-29 16:43:40 +01:00
};
}
2023-05-19 20:53:02 +02:00