summaryrefslogtreecommitdiff
path: root/nixos
diff options
context:
space:
mode:
authorseraphim <18ycm9tx@anonaddy.me>2026-07-30 12:48:20 +0700
committerseraphim <18ycm9tx@anonaddy.me>2026-07-30 12:48:20 +0700
commit59226408d8bc950d7ec8c21623f28b5f7de8fce0 (patch)
tree894884db76e33f9130f519e82ebfefd39ea70309 /nixos
parent012d59987c8d78264f4a405ca595c50706e43b33 (diff)
Dendritic nixos update!
Diffstat (limited to 'nixos')
-rw-r--r--nixos/configuration.nix453
-rw-r--r--nixos/docs/ADDING_PACKAGES.md133
-rw-r--r--nixos/modules/features/fonts/default.nix2
-rw-r--r--nixos/modules/features/terminals/default.nix2
-rw-r--r--nixos/modules/system/boot/default.nix14
5 files changed, 136 insertions, 468 deletions
diff --git a/nixos/configuration.nix b/nixos/configuration.nix
deleted file mode 100644
index 760c077..0000000
--- a/nixos/configuration.nix
+++ /dev/null
@@ -1,453 +0,0 @@
-{ config, pkgs, inputs, ... }:
-
-{
- # =========================================================================
- # IMPORTS & NIX CONFIGURATION
- # =========================================================================
- imports = [
- ./hardware-configuration.nix
- inputs.noctalia-greeter.nixosModules.default
- ];
-
- nix.settings.experimental-features = [ "nix-command" "flakes" ];
- nixpkgs.config.allowUnfree = true;
-
- nix.gc = {
- automatic = true;
- dates = "weekly";
- options = "--delete-older-than 7d";
- };
-
- # Dynamic binary execution & FHS compatibility
- programs.nix-ld.enable = true;
- services.envfs.enable = true;
- security.polkit.enable = true;
-
- # =========================================================================
- # BOOT & KERNEL CONFIGURATION
- # =========================================================================
- boot.loader.systemd-boot.enable = true;
- boot.loader.efi.canTouchEfiVariables = true;
-
-# boot.kernelParams = [
-# "drm.edid_firmware=DP-1:edid/mi_edid.bin"
-# "video=DP-1:2560x1440@180"
-# ];
-
- # Custom EDID firmware loading for monitor
- hardware.firmware = [
- (pkgs.runCommand "custom-edid" {} ''
- mkdir -p $out/lib/firmware/edid
- cp ${./mi_edid.bin} $out/lib/firmware/edid/mi_edid.bin
- '')
- ];
-
- # =========================================================================
- # HARDWARE, FILESYSTEMS & GRAPHICS
- # =========================================================================
- fileSystems."/mnt/giga" = {
- device = "/dev/disk/by-uuid/bfed3a37-05e1-465b-a4b7-d74cd31bf937";
- fsType = "ext4";
- options = [ "defaults" "user" "rw" ];
- };
-
- hardware.graphics = {
- enable = true;
- enable32Bit = true;
- };
-
- services.xserver.videoDrivers = [ "nvidia" ];
- hardware.nvidia = {
- modesetting.enable = true;
- powerManagement.enable = false;
- open = false;
- nvidiaSettings = true;
- package = config.boot.kernelPackages.nvidiaPackages.latest;
- };
-
- # Appimage settings
- programs.appimage = {
- enable = true;
- binfmt = true;
- package = pkgs.appimage-run.override {
- extraPkgs = pkgs: [
- pkgs.webkitgtk_4_1
- ];
- };
- };
-
- # =========================================================================
- # NETWORKING, DNS & VPN
- # =========================================================================
- networking.hostName = "opus";
- networking.networkmanager.enable = true;
- programs.amnezia-vpn.enable = true;
- # Primary DNS Server: Mullvad DoT (Base Mode)
- networking.nameservers = [
- "194.242.2.4#base.dns.mullvad.net"
- "194.242.2.2#dns.mullvad.net"
- ];
-
- # systemd-resolved Configuration (Mullvad Base Primary -> Quad9 Fallback)
- services.resolved = {
- enable = true;
- dnsovertls = "opportunistic"; # Encrypts DNS via DoT, falls back if port 853 is blocked
- dnssec = "false"; # Disables DNSSEC validation drops
- domains = [ "~." ]; # Forces systemd-resolved to use global DNS, ignoring DHCP DNS
- fallbackDns = [
- "9.9.9.9#dns.quad9.net"
- "149.112.112.112#dns.quad9.net"
- ];
- };
-
-
- # Avahi (Printer / Network Discovery)
- services.avahi = {
- enable = true;
- nssmdns4 = true;
- openFirewall = true;
- };
-
- # =========================================================================
- # LOCALIZATION & TIMEZONE
- # =========================================================================
- time.timeZone = "Etc/GMT-7";
- i18n.defaultLocale = "en_US.UTF-8";
- i18n.extraLocaleSettings = {
- LC_ADDRESS = "en_US.UTF-8";
- LC_IDENTIFICATION = "en_US.UTF-8";
- LC_MEASUREMENT = "en_US.UTF-8";
- LC_MONETARY = "en_US.UTF-8";
- LC_NAME = "en_US.UTF-8";
- LC_NUMERIC = "en_US.UTF-8";
- LC_PAPER = "en_US.UTF-8";
- LC_TELEPHONE = "en_US.UTF-8";
- LC_TIME = "en_US.UTF-8";
- };
-
- # =========================================================================
- # USER ACCOUNTS & PRIVILEGES
- # =========================================================================
- users.users."seraphim" = {
- isNormalUser = true;
- description = "seraphim";
- shell = pkgs.fish; # Sets Fish as your default user shell
- extraGroups = [ "networkmanager" "wheel" ];
- packages = with pkgs; [];
- };
-
- security.doas = {
- enable = true;
- extraRules = [
- {
- users = [ "seraphim" ];
- keepEnv = true;
- persist = true;
- }
- ];
- };
-
- # =========================================================================
- # SHELLS & ENHANCEMENTS
- # =========================================================================
- programs.fish = {
- enable = true;
- interactiveShellInit = ''
- set -g fish_greeting "" # Disables the welcome message
- fzf --fish |
- source
- '';
- shellAliases = {
- ls = "eza -al --icons=auto";
- ll = "eza -al --icons=auto";
- };
- };
-
- programs.starship.enable = true;
-
- # =========================================================================
- # DISPLAY, WAYLAND & DESKTOP ENVIRONMENT
- # =========================================================================
- programs.niri.enable = true;
- programs.noctalia-greeter = {
- enable = true;
- settings = {
- cursor = {
- theme = "Bibata-Modern-Ice";
- size = 24;
- path = "${pkgs.bibata-cursors}/share/icons";
- };
- };
- };
-
- qt = {
- enable = true;
- platformTheme = "qt5ct";
- style = "breeze";
- };
-
- xdg.portal = {
- enable = true;
- extraPortals = [
- pkgs.xdg-desktop-portal-gnome
- pkgs.xdg-desktop-portal-gtk
- ];
- };
-
- # Environment Variables
- environment.variables = {
- SSL_CERT_FILE = "/etc/ssl/certs/ca-certificates.crt";
- NIX_SSL_CERT_FILE = "/etc/ssl/certs/ca-certificates.crt";
- };
-
- environment.sessionVariables = {
- SHELL = "${pkgs.fish}/bin/fish";
- LIBVA_DRIVER_NAME = "nvidia";
- XCURSOR_THEME = "Bibata-Modern-Ice";
- XCURSOR_SIZE = "20";
- __GLX_VENDOR_LIBRARY_NAME = "nvidia";
- NIXOS_OZONE_WL = "1";
- CC = "clang";
- ELECTRON_OZONE_PLATFORM_HINT = "auto";
- GSK_RENDERER = "ngl";
- QT_QPA_PLATFORM = "wayland;xcb";
- QT_ENABLE_HIGHDPI_SCALING = "1";
- QT_AUTO_SCREEN_SCALE_FACTOR = "1";
- QT_SCREEN_SCALE_FACTORS = "1.5";
- };
-
- # Fonts Configuration
- fonts.fontconfig.enable = true;
- fonts.packages = with pkgs; [
- font-awesome
- nerd-fonts.jetbrains-mono
- nerd-fonts.symbols-only
- jetbrains-mono
- noto-fonts-color-emoji
- ];
-
- # =========================================================================
- # AUDIO & SERVICES
- # =========================================================================
- security.rtkit.enable = true;
- services.pipewire = {
- enable = true;
- alsa.enable = true;
- alsa.support32Bit = true;
- pulse.enable = true;
- };
- # printer service
- services.printing = {
- enable = true;
- drivers = with pkgs; [
- brlaser
- cups-filters
- gutenprint
- ];
- };
-
- # MPD Music Server
- services.mpd = {
- enable = true;
- user = "seraphim";
- openFirewall = false;
- settings = {
- music_directory = "/mnt/giga/music";
- bind_to_address = "any";
- port = 6600;
- auto_update = "yes";
- audio_output = [
- {
- type = "pulse";
- name = "PipeWire Output";
- mixer_type = "hardware";
- }
- ];
- };
- };
-
- systemd.services.mpd.environment = {
- XDG_RUNTIME_DIR = "/run/user/1000";
- };
-
- # System Utilities & Gaming
- services.gvfs.enable = true;
- services.tumbler.enable = true;
- services.gnome.gnome-keyring.enable = true;
- programs.dconf.enable = true;
-
- services.journald.extraConfig = ''
- SystemMaxUse=50M
- MaxRetentionSec=1month
- '';
-
- programs.steam = {
- enable = true;
- remotePlay.openFirewall = true;
- dedicatedServer.openFirewall = true;
- };
-
- programs.throne = {
- enable = true;
- tunMode.enable = true;
- };
-
- # =========================================================================
- # USER SERVICES
- # =========================================================================
- systemd.user.services.swingmusic = {
- description = "Swing Music Local Server";
- wantedBy = [ "graphical-session.target" ];
- after = [ "graphical-session.target" ];
- serviceConfig = {
- ExecStart = "/home/seraphim/.swingmusic/swingmusic";
- Restart = "on-failure";
- WorkingDirectory = "/home/seraphim";
- NoNewPrivileges = true;
- PrivateTmp = true;
- ProtectSystem = "strict";
- ProtectHome = "false";
- RestrictAddressFamilies = [ "AF_INET" "AF_INET6" ];
- };
- };
-
- systemd.user.services.mpd-mpris = {
- description = "MPD MPRIS Service for Waybar";
- wantedBy = [ "default.target" ];
- after = [ "graphical-session.target" ];
- serviceConfig = {
- ExecStart = "${pkgs.mpd-mpris}/bin/mpd-mpris -network tcp -host 127.0.0.1 -port 6600";
- Restart = "on-failure";
- };
- };
-
- systemd.user.services.niri.enableDefaultPath = false;
-
- # =========================================================================
- # SYSTEM PACKAGES
- # =========================================================================
- environment.systemPackages = with pkgs;
- [
- # Flake Inputs & Hardware Overrides
- inputs.noctalia.packages.${pkgs.stdenv.hostPlatform.system}.default
- (btop.override { cudaSupport = true; })
-
- # Terminals & CLI Utilities
- cacert
- tree
- pkgs.libsixel
- libGL
- nss
- cups
- libdrm
- glib
- pango
- gtk3
- zlib
- expat
- alsa-lib
- libxkbcommon
- atk
- pkg-config
- cmake
-
- nftables
- pkgs.rsync
- duf
- eza
- fastfetch
- fd
- foot
- fzf
- ghfetch
- ghostty
- hyfetch
- stow
- util-linux
- pkgs.vimPlugins.im-select-nvim
-
- # Audio & Music Controls
- brightnessctl
- mpc
- mpd
- mpd-mpris
- mpv
- pamixer
- pavucontrol
- playerctl
- rmpc
-
- # Text Editors
- micro
- neovim
- (emacs.override {
- withNativeCompilation = true;
- })
-
- # File Managers & Archiving
- file-roller
- kdePackages.ark
- kdePackages.qt6ct
- loupe
- nautilus
- sushi
- yazi
-
- # Utilities & Disk Tools
- caligula
- cryptsetup
- yt-dlp
-
- # GStreamer Codecs
- gst_all_1.gst-plugins-bad
- gst_all_1.gst-plugins-base
- gst_all_1.gst-plugins-good
- gst_all_1.gst-plugins-ugly
-
- # Wayland, Desktop UI & Utilities
- adwaita-icon-theme
- bibata-cursors
- cliphist
- fuzzel
- grim
- hicolor-icon-theme
- hyprpolkitagent
- noctalia-shell
- slurp
- wl-clipboard
- wtype
- xwayland-satellite
-
- # Desktop Applications & Office
- claude-code
- keepassxc
- libreoffice
- hunspellDicts.ru_RU
- nvidia-vaapi-driver
- opencode
- pkgs.ayugram-desktop
- pkgs.legcord
- pkgs.amnezia-vpn
- obsidian
- pkgs.lutris
- pkgs.qbittorrent
- pkgs.prismlauncher
- pkgs.wireshark
- # Software Development & Toolchains
- black
- cargo
- clang
- clippy
- gcc
- git
- gnumake
- nodejs
- pyright
- python3
- rust-analyzer
- rustc
- tree-sitter
- ];
-
- system.stateVersion = "26.05";
-}
diff --git a/nixos/docs/ADDING_PACKAGES.md b/nixos/docs/ADDING_PACKAGES.md
new file mode 100644
index 0000000..a4c0c5a
--- /dev/null
+++ b/nixos/docs/ADDING_PACKAGES.md
@@ -0,0 +1,133 @@
+# Adding Packages
+
+This configuration is composed from `hosts/opus/default.nix` and focused modules
+under `modules/system/` and `modules/features/`. There is no central package list.
+
+## Where a package belongs
+
+| Package type | Module |
+| --- | --- |
+| Terminal | `modules/features/terminals/default.nix` |
+| CLI tool | `modules/features/cli-tools/default.nix` |
+| Editor or IDE | `modules/features/editors/default.nix` |
+| Desktop application | `modules/features/desktop-apps/default.nix` |
+| Compiler, linter, language tool | `modules/features/dev-tools/default.nix` |
+| File manager or archive tool | `modules/features/file-managers/default.nix` |
+| Wayland clipboard, screenshot, or input tool | `modules/features/wayland-tools/default.nix` |
+| Audio application | `modules/features/audio-tools/default.nix` |
+| System monitor or fetch tool | `modules/features/monitoring/default.nix` |
+| Font | `modules/features/fonts/default.nix` |
+| GStreamer plugin | `modules/features/gst-codecs/default.nix` |
+| Runtime library for external binaries | `modules/features/binary-compat/default.nix` |
+
+First use an existing category. Create a new feature module only if the package is
+its own service, subsystem, or a group of related packages without a fitting category.
+
+## Add to an existing module
+
+Add the package to that module's `environment.systemPackages` list:
+
+```nix
+{ pkgs, ... }:
+
+{
+ environment.systemPackages = with pkgs; [
+ existing-package
+ ripgrep
+ ];
+}
+```
+
+Most modules use `with pkgs;`, so use unqualified package names. Use `pkgs.<name>`
+when an explicit path is useful, such as `pkgs.vimPlugins.im-select-nvim`, or when
+applying an override:
+
+```nix
+(emacs.override { withNativeCompilation = true; })
+```
+
+Keep related packages together and follow the local ordering of the file.
+
+## Fonts are different
+
+Fonts belong in `modules/features/fonts/default.nix` under `fonts.packages`, not
+`environment.systemPackages`:
+
+```nix
+fonts.packages = with pkgs; [
+ nerd-fonts.jetbrains-mono
+ noto-fonts-color-emoji
+];
+```
+
+## Create a new feature module
+
+1. Create `modules/features/<category>/default.nix`:
+
+ ```nix
+ { pkgs, ... }:
+
+ {
+ environment.systemPackages = with pkgs; [
+ package-name
+ ];
+ }
+ ```
+
+2. Add its directory to the `imports` list in `hosts/opus/default.nix`:
+
+ ```nix
+ ../../modules/features/<category>
+ ```
+
+3. Put services and program options in the same module when they belong to that
+ feature, as done by `modules/features/mpd/default.nix`.
+
+## Host-only packages
+
+For a package that is truly specific to this desktop, add it to the small
+`environment.systemPackages` list in `hosts/opus/default.nix`. Gaming is the current
+example. If that list starts to represent a reusable category, extract a feature module.
+
+## Packages from flake inputs
+
+Packages provided by a flake input use `inputs` and the host platform, following
+`modules/features/desktop-apps/default.nix`:
+
+```nix
+{ pkgs, inputs, ... }:
+
+{
+ environment.systemPackages = with pkgs; [
+ inputs.helium-browser.packages.${pkgs.stdenv.hostPlatform.system}.helium
+ ];
+}
+```
+
+If an input provides a NixOS module, import it in the feature module, following
+`modules/features/noctalia-greeter/default.nix`:
+
+```nix
+imports = [
+ inputs.some-input.nixosModules.default
+];
+```
+
+The input itself must first be declared in `flake.nix`.
+
+## Build and switch
+
+From the `nixos/` directory, first test that the configuration evaluates and builds:
+
+```bash
+doas nixos-rebuild build --flake .#opus
+```
+
+Then activate it:
+
+```bash
+doas nixos-rebuild switch --flake .#opus
+```
+
+If a terminal's font icons do not update after adding fonts, restart the terminal or
+log out and back in after the switch.
diff --git a/nixos/modules/features/fonts/default.nix b/nixos/modules/features/fonts/default.nix
index 8ac4785..cecdd8f 100644
--- a/nixos/modules/features/fonts/default.nix
+++ b/nixos/modules/features/fonts/default.nix
@@ -3,7 +3,7 @@
{
fonts.fontconfig.enable = true;
- environment.systemPackages = with pkgs; [
+ fonts.packages = with pkgs; [
font-awesome
nerd-fonts.jetbrains-mono
nerd-fonts.symbols-only
diff --git a/nixos/modules/features/terminals/default.nix b/nixos/modules/features/terminals/default.nix
index 22c5662..a290b42 100644
--- a/nixos/modules/features/terminals/default.nix
+++ b/nixos/modules/features/terminals/default.nix
@@ -5,4 +5,4 @@
foot
ghostty
];
-} \ No newline at end of file
+}
diff --git a/nixos/modules/system/boot/default.nix b/nixos/modules/system/boot/default.nix
index eedf939..df64426 100644
--- a/nixos/modules/system/boot/default.nix
+++ b/nixos/modules/system/boot/default.nix
@@ -1,18 +1,9 @@
-{ config, pkgs, lib, modulesPath, ... }:
+{ pkgs, ... }:
{
- imports = [
- (modulesPath + "/installer/scan/not-detected.nix")
- ];
-
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = true;
- boot.initrd.availableKernelModules = [ "nvme" "xhci_pci" "ahci" "usbhid" "usb_storage" "sd_mod" ];
- boot.initrd.kernelModules = [ ];
- boot.kernelModules = [ "kvm-amd" ];
- boot.extraModulePackages = [ ];
-
# EDID firmware loading is kept here because it's a kernel-level boot concern.
# Commented kernel params from the original config are preserved.
# boot.kernelParams = [
@@ -25,7 +16,4 @@
cp ${../../../mi_edid.bin} $out/lib/firmware/edid/mi_edid.bin
'')
];
-
- nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
- hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
} \ No newline at end of file