{ config, pkgs, lib, inputs, ... }: { # Nix itself: enable the flake + nix-command features this config relies on. nix.settings.experimental-features = [ "nix-command" "flakes" ]; nixpkgs.config.allowUnfree = true; # Automatic garbage collection — drop builds older than a week. nix.gc = { automatic = true; dates = "weekly"; options = "--delete-older-than 7d"; }; # envfs is the modern replacement for nix-ld: it mounts a FUSE filesystem # on /usr/bin and /bin that resolves shebangs (e.g. #!/usr/bin/env) to the # executables on the caller's PATH. It supersedes programs.nix-ld entirely. services.envfs.enable = true; security.polkit.enable = true; environment.variables = { SSL_CERT_FILE = "/etc/ssl/certs/ca-certificates.crt"; NIX_SSL_CERT_FILE = "/etc/ssl/certs/ca-certificates.crt"; }; }