configs/appserver/configuration.nix

99 lines
2.3 KiB
Nix
Raw Normal View History

2024-05-20 12:24:36 +02:00
{ config, pkgs, ... }:
{
imports =
[ # Include the results of the hardware scan.
./hardware-configuration.nix
./starship.nix
./aliases.nix
./podman.nix
./libvirt.nix
./incus.nix
./jellyfin.nix
./tailscale.nix
./calibre-web.nix
./audiobook.nix
2024-07-02 13:09:53 +02:00
#./ollama.nix
2024-07-02 21:07:46 +02:00
./forgejo.nix
2024-05-20 12:24:36 +02:00
];
# Swap zram
zramSwap = {
enable = true;
algorithm = "zstd";
};
# Use the GRUB 2 boot loader.
boot.loader.grub.enable = true;
boot.loader.grub.efiSupport = true;
boot.loader.grub.efiInstallAsRemovable = true;
boot.loader.efi.efiSysMountPoint = "/boot/";
boot.loader.grub.device = "nodev";
# Disks and Updates
services.fstrim.enable = true;
# Mount remote filesystem
fileSystems."/mnt/remote/media" = {
2024-05-20 20:26:56 +02:00
device = "files:/mnt/storage";
2024-05-20 12:24:36 +02:00
fsType = "nfs";
2024-06-15 11:30:38 +02:00
options = [ "x-systemd.automount" ];
2024-05-20 12:24:36 +02:00
};
# Enable all unfree hardware support.
hardware.firmware = with pkgs; [ firmwareLinuxNonfree ];
hardware.enableAllFirmware = true;
hardware.enableRedistributableFirmware = true;
nixpkgs.config.allowUnfree = true;
services.fwupd.enable = true;
# Networking
2024-05-20 20:11:08 +02:00
networking.hostName = "apps";
2024-05-20 12:24:36 +02:00
networking.networkmanager.enable = true;
# Set your time zone.
time.timeZone = "Europe/Oslo";
i18n.defaultLocale = "en_US.UTF-8";
console = {
font = "Lat2-Terminus16";
keyMap = "no";
};
users.users.geir = {
isNormalUser = true;
extraGroups = [ "wheel"
"networkmanager"
"libvirt"
"podman"
2024-08-02 11:17:05 +02:00
"incus-admin"
2024-05-20 12:24:36 +02:00
];
packages = with pkgs; [
bottom
];
};
environment.systemPackages = with pkgs; [
neovim emacs nano curl htop glances kitty
wget git inxi nethogs fastfetch
2024-08-02 11:17:05 +02:00
emacsPackages.vterm
2024-05-20 12:24:36 +02:00
];
# Enable the OpenSSH daemon.
services.openssh.enable = true;
2024-06-15 11:30:38 +02:00
services.openssh.settings.PermitRootLogin = "no";
2024-05-20 12:24:36 +02:00
services.openssh.settings.PasswordAuthentication = true;
# Enable Netdata
services.netdata.enable = true;
# Firewall
networking.firewall.enable = true;
networking.firewall.allowedTCPPorts = [ 22 19999 23231];
networking.firewall.allowedUDPPorts = [ 22 23231 ];
2024-06-01 11:08:39 +02:00
networking.nftables.enable = true;
2024-05-20 12:24:36 +02:00
system.stateVersion = "23.05";
}