refactor(modules): split monolithic system/desktop config

This commit is contained in:
randogoth 2026-02-04 10:29:55 +02:00
parent c299acb87d
commit febdf2702c
13 changed files with 249 additions and 209 deletions

View file

@ -1,124 +1,13 @@
{
config,
lib,
pkgs,
...
}:
{ config, ... }:
{
time.timeZone = "UTC";
i18n.defaultLocale = "en_US.UTF-8";
console.keyMap = "us";
boot.supportedFilesystems = [
"btrfs"
"ext4"
"vfat"
"xfs"
imports = [
./locale.nix
./boot-efi.nix
./nix-core.nix
./services.nix
./networking.nix
./virtualization.nix
./security.nix
];
boot.loader = {
systemd-boot = {
enable = true;
# Only keep 10 generations maximum
configurationLimit = lib.mkDefault 10;
};
efi.canTouchEfiVariables = true;
};
nix.settings = {
experimental-features = [
"nix-command"
"flakes"
];
# Only allow root and sudoers to run Nix commands
allowed-users = [
"root"
"@wheel"
];
substituters = lib.mkBefore [
"https://cache.lix.systems"
];
trusted-public-keys = lib.mkBefore [
"cache.lix.systems:aBnZUw8zA7H35Cz2RyKFVs3H4PlGTLawyY5KRbvJR8o="
];
};
services = {
openssh.enable = true;
gvfs.enable = true;
tumbler.enable = true;
};
networking = {
useDHCP = lib.mkDefault true;
firewall.trustedInterfaces = [ "virbr0" ];
};
nixpkgs.config.allowUnfree = true;
programs = {
nix-index = {
enable = lib.mkDefault true;
enableBashIntegration = lib.mkDefault true;
};
nix-index-database.comma.enable = lib.mkDefault true;
thunar = {
enable = true;
plugins = [
pkgs.xfce.thunar-archive-plugin
pkgs.xfce.thunar-media-tags-plugin
pkgs.xfce.thunar-vcs-plugin
pkgs.xfce.thunar-volman
];
};
virt-manager.enable = true;
xfconf.enable = true;
};
# Optimise the Nix store once a day
nix.optimise = lib.mkDefault {
automatic = true;
dates = [ "daily" ];
};
# Clean the Nix store once a day
nix.gc = lib.mkDefault {
automatic = true;
dates = "daily";
options = "--delete-older-than 30d";
};
system.stateVersion = "25.11";
virtualisation = {
containers.enable = true;
# docker.enable = true;
podman = {
enable = true;
dockerCompat = true;
# Required for containers under podman-compose to be able to talk to each other.
defaultNetwork.settings.dns_enabled = true;
};
libvirtd.enable = true;
};
security.sudo = {
enable = lib.mkDefault true;
wheelNeedsPassword = lib.mkForce false;
};
# Locked down root user as a default
users.users.root = lib.mkDefault {
shell = pkgs.zsh;
extraGroups = [
"networkmanager"
"wheel"
];
hashedPassword = lib.mkDefault "!";
initialHashedPassword = lib.mkDefault "!";
};
}