| 1 | { |
| 2 | pkgs, |
| 3 | user, |
| 4 | host, |
| 5 | ... |
| 6 | }: |
| 7 | { |
| 8 | imports = [ |
| 9 | # Include the results of the hardware scan. |
| 10 | ./hardware-configuration.nix |
| 11 | ]; |
| 12 | documentation.man.generateCaches = false; |
| 13 | services.displayManager = { |
| 14 | enable = true; |
| 15 | cosmic-greeter.enable = true; |
| 16 | autoLogin = { |
| 17 | enable = true; |
| 18 | user = user.username; |
| 19 | }; |
| 20 | }; |
| 21 | |
| 22 | services.desktopManager = { |
| 23 | cosmic.enable = true; |
| 24 | }; |
| 25 | |
| 26 | # Slightly improves cosmic performances |
| 27 | services.system76-scheduler.enable = true; |
| 28 | |
| 29 | programs = { |
| 30 | # hyprland = { |
| 31 | # enable = true; |
| 32 | # withUWSM = true; |
| 33 | # }; |
| 34 | gamemode.enable = true; |
| 35 | |
| 36 | _1password.enable = true; |
| 37 | _1password-gui = { |
| 38 | enable = true; |
| 39 | # Certain features, including CLI integration and system authentication support, |
| 40 | # require enabling PolKit integration on some desktop environments (e.g. Plasma). |
| 41 | polkitPolicyOwners = [ user.username ]; |
| 42 | }; |
| 43 | |
| 44 | noisetorch.enable = true; |
| 45 | |
| 46 | fish.enable = true; |
| 47 | virt-manager.enable = true; |
| 48 | |
| 49 | nh = { |
| 50 | enable = true; |
| 51 | # clean.enable = true; |
| 52 | # clean.extraArgs = "--keep-since 4d --keep 3"; |
| 53 | flake = "/home/nmarks/.dotfiles#nixosConfigurations.nixos"; |
| 54 | }; |
| 55 | |
| 56 | steam = { |
| 57 | enable = true; |
| 58 | remotePlay.openFirewall = true; |
| 59 | # package = pkgs.steam.override { |
| 60 | # extraPackages = ( |
| 61 | # pkgs: [ |
| 62 | # pkgs.gamemode |
| 63 | # ] |
| 64 | # ); |
| 65 | # }; |
| 66 | |
| 67 | gamescopeSession.enable = true; |
| 68 | extraCompatPackages = [ pkgs.proton-ge-bin ]; |
| 69 | }; |
| 70 | |
| 71 | gamescope = { |
| 72 | enable = true; |
| 73 | capSysNice = true; |
| 74 | args = [ |
| 75 | "--rt" |
| 76 | "--expose-wayland" |
| 77 | ]; |
| 78 | }; |
| 79 | |
| 80 | git = { |
| 81 | enable = true; |
| 82 | lfs.enable = true; |
| 83 | }; |
| 84 | |
| 85 | # Some programs need SUID wrappers, can be configured further or are |
| 86 | # started in user sessions. |
| 87 | mtr.enable = true; |
| 88 | gnupg.agent = { |
| 89 | enable = true; |
| 90 | enableSSHSupport = true; |
| 91 | pinentryPackage = pkgs.pinentry-curses; |
| 92 | }; |
| 93 | |
| 94 | kdeconnect.enable = true; |
| 95 | }; |
| 96 | |
| 97 | hardware.bluetooth.enable = true; |
| 98 | hardware.graphics.enable = true; |
| 99 | |
| 100 | xdg.portal = { |
| 101 | enable = true; |
| 102 | xdgOpenUsePortal = true; |
| 103 | config = { |
| 104 | common = { |
| 105 | default = [ |
| 106 | "cosmic" |
| 107 | "gtk" |
| 108 | ]; |
| 109 | |
| 110 | "org.freedesktop.impl.portal.Secret" = [ |
| 111 | "gnome-keyring" |
| 112 | ]; |
| 113 | }; |
| 114 | |
| 115 | }; |
| 116 | |
| 117 | extraPortals = with pkgs; [ |
| 118 | xdg-desktop-portal-gtk |
| 119 | xdg-desktop-portal-cosmic |
| 120 | ]; |
| 121 | }; |
| 122 | virtualisation = { |
| 123 | waydroid.enable = true; |
| 124 | containers.enable = true; |
| 125 | podman = { |
| 126 | enable = true; |
| 127 | # dockerCompat = true; |
| 128 | }; |
| 129 | docker.enable = true; |
| 130 | |
| 131 | libvirtd.enable = true; |
| 132 | }; |
| 133 | |
| 134 | nix.settings.trusted-users = [ |
| 135 | "root" |
| 136 | user.username |
| 137 | ]; |
| 138 | systemd = { |
| 139 | targets = { |
| 140 | sleep.enable = false; |
| 141 | suspend.enable = false; |
| 142 | hibernate.enable = false; |
| 143 | hybrid-sleep.enable = false; |
| 144 | }; |
| 145 | settings.Manager.DefaultTimeoutStopSec = "10s"; |
| 146 | |
| 147 | services.monitord.wantedBy = [ "multi-user.target" ]; |
| 148 | }; |
| 149 | |
| 150 | i18n = { |
| 151 | # Select internationalisation properties. |
| 152 | defaultLocale = "en_US.UTF-8"; |
| 153 | |
| 154 | supportedLocales = [ "all" ]; |
| 155 | |
| 156 | extraLocaleSettings = { |
| 157 | LC_ADDRESS = "en_US.UTF-8"; |
| 158 | LC_IDENTIFICATION = "en_US.UTF-8"; |
| 159 | LC_MEASUREMENT = "en_US.UTF-8"; |
| 160 | LC_MONETARY = "en_US.UTF-8"; |
| 161 | LC_NAME = "en_US.UTF-8"; |
| 162 | LC_NUMERIC = "en_US.UTF-8"; |
| 163 | LC_PAPER = "en_US.UTF-8"; |
| 164 | LC_TELEPHONE = "en_US.UTF-8"; |
| 165 | LC_TIME = "en_US.UTF-8"; |
| 166 | }; |
| 167 | |
| 168 | inputMethod = { |
| 169 | type = "fcitx5"; |
| 170 | enable = true; |
| 171 | fcitx5.waylandFrontend = true; |
| 172 | fcitx5.addons = with pkgs; [ |
| 173 | # fcitx5-gtk |
| 174 | # kdePackages.fcitx5-qt |
| 175 | rime-data |
| 176 | fcitx5-rime |
| 177 | fcitx5-rose-pine |
| 178 | ]; |
| 179 | }; |
| 180 | }; |
| 181 | |
| 182 | # Enable sound with pipewire. |
| 183 | security.rtkit.enable = true; |
| 184 | |
| 185 | # Enable touchpad support (enabled default in most desktopManager). |
| 186 | # services.xserver.libinput.enable = true; |
| 187 | |
| 188 | # Define a user account. Don't forget to set a password with ‘passwd’. |
| 189 | # users.defaultUserShell = pkgs.fish; |
| 190 | users.users.${user.username} = { |
| 191 | shell = pkgs.fish; |
| 192 | isNormalUser = true; |
| 193 | description = user.name; |
| 194 | extraGroups = [ |
| 195 | "networkmanager" |
| 196 | "wheel" |
| 197 | "docker" |
| 198 | ]; |
| 199 | # openssh.authorizedKeys.keyFiles = ["~/.ssh/id_ed25519.pub"]; |
| 200 | packages = with pkgs; [ |
| 201 | firefox |
| 202 | vim |
| 203 | steam |
| 204 | |
| 205 | # thunderbird |
| 206 | ]; |
| 207 | }; |
| 208 | environment = { |
| 209 | sessionVariables = { |
| 210 | COSMIC_DATA_CONTROL_ENABLED = 1; |
| 211 | NIXOS_OZONE_WL = "1"; |
| 212 | }; |
| 213 | variables.EDITOR = "nvim"; |
| 214 | |
| 215 | systemPackages = with pkgs; [ |
| 216 | vim |
| 217 | ]; |
| 218 | |
| 219 | etc = { |
| 220 | "1password/custom_allowed_browsers" = { |
| 221 | text = '' |
| 222 | zen |
| 223 | ''; |
| 224 | mode = "0755"; |
| 225 | }; |
| 226 | }; |
| 227 | }; |
| 228 | |
| 229 | networking = { |
| 230 | hostName = host.name; # Define your hostname. |
| 231 | # wireless.enable = true; # Enables wireless support via wpa_supplicant. |
| 232 | networkmanager.enable = true; |
| 233 | firewall = { |
| 234 | allowedTCPPorts = [ |
| 235 | 22 |
| 236 | 80 |
| 237 | 443 |
| 238 | ]; |
| 239 | enable = true; |
| 240 | }; |
| 241 | interfaces.enp11s0.wakeOnLan = { |
| 242 | enable = true; |
| 243 | policy = [ "magic" ]; |
| 244 | }; |
| 245 | }; |
| 246 | |
| 247 | # Open ports in the firewall. |
| 248 | # networking.firewall.allowedUDPPorts = [ ... ]; |
| 249 | # Or disable the firewall altogether. |
| 250 | # networking.firewall.enable = false; |
| 251 | |
| 252 | # This value determines the NixOS release from which the default |
| 253 | # settings for stateful data, like file locations and database versions |
| 254 | # on your system were taken. It‘s perfectly fine and recommended to leave |
| 255 | # this value at the release version of the first install of this system. |
| 256 | # Before changing this value read the documentation for this option |
| 257 | # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). |
| 258 | system.stateVersion = "23.05"; # Did you read the comment? |
| 259 | } |