| 1 | { lib, pkgs, ... }: |
| 2 | let |
| 3 | adminKey = lib.fileContents ../config/admin.pub; |
| 4 | pool = "globe"; |
| 5 | encryptionRoots = { |
| 6 | apps = "apps"; |
| 7 | clover = "clover"; |
| 8 | media = "clover/Media"; |
| 9 | logs = "logs"; |
| 10 | prod = "prod"; |
| 11 | staging = "staging"; |
| 12 | }; |
| 13 | in |
| 14 | { |
| 15 | imports = [ ./zenith-network.nix ]; |
| 16 | |
| 17 | networking.hostName = "zenith"; |
| 18 | networking.hostId = "4fa19ccb"; |
| 19 | networking.firewall.allowedTCPPorts = [ 80 443 ]; |
| 20 | networking.firewall.interfaces.enp4s0.allowedTCPPorts = [ 445 ]; |
| 21 | |
| 22 | boot.loader.systemd-boot.enable = true; |
| 23 | boot.loader.efi.canTouchEfiVariables = true; |
| 24 | boot.zfs.forceImportRoot = false; |
| 25 | boot.zfs.extraPools = [ pool ]; |
| 26 | boot.zfs.requestEncryptionCredentials = false; |
| 27 | security.tpm2.enable = true; |
| 28 | |
| 29 | systemd.services.studio-zfs-unlock = { |
| 30 | requires = [ "zfs-import-${pool}.service" "dev-tpmrm0.device" ]; |
| 31 | after = [ "zfs-import-${pool}.service" "dev-tpmrm0.device" ]; |
| 32 | before = [ "zfs-mount.service" ]; |
| 33 | requiredBy = [ "zfs-mount.service" ]; |
| 34 | unitConfig.DefaultDependencies = false; |
| 35 | serviceConfig = { |
| 36 | Type = "oneshot"; |
| 37 | RemainAfterExit = true; |
| 38 | LoadCredentialEncrypted = lib.mapAttrsToList |
| 39 | (name: _: "zfs-${name}:/etc/credstore.encrypted/zfs-${name}") encryptionRoots; |
| 40 | }; |
| 41 | script = lib.concatStrings (lib.mapAttrsToList (name: dataset: '' |
| 42 | if test "$(${pkgs.zfs}/bin/zfs get -H -o value keystatus ${pool}/${dataset})" = unavailable; then |
| 43 | ${pkgs.zfs}/bin/zfs load-key -L "file://$CREDENTIALS_DIRECTORY/zfs-${name}" ${pool}/${dataset} |
| 44 | fi |
| 45 | '') encryptionRoots); |
| 46 | }; |
| 47 | |
| 48 | services.xserver.videoDrivers = [ "nvidia" ]; |
| 49 | hardware.graphics.enable = true; |
| 50 | hardware.nvidia.open = false; |
| 51 | hardware.nvidia.nvidiaPersistenced = true; |
| 52 | hardware.nvidia.nvidiaSettings = false; |
| 53 | |
| 54 | systemd.services.nomad = { |
| 55 | requires = [ "zfs-import-${pool}.service" ]; |
| 56 | after = [ "zfs-import-${pool}.service" "zfs-mount.service" ]; |
| 57 | preStart = '' |
| 58 | test "$(${pkgs.util-linux}/bin/findmnt -n -o SOURCE --mountpoint /srv)" = ${pool} |
| 59 | test "$(${pkgs.util-linux}/bin/findmnt -n -o SOURCE --mountpoint /srv/clover)" = ${pool}/clover |
| 60 | test "$(${pkgs.util-linux}/bin/findmnt -n -o SOURCE --mountpoint /srv/clover/Media)" = ${pool}/clover/Media |
| 61 | test "$(${pkgs.util-linux}/bin/findmnt -n -o SOURCE --mountpoint /srv/prod)" = ${pool}/prod |
| 62 | test "$(${pkgs.util-linux}/bin/findmnt -n -o SOURCE --mountpoint /srv/staging)" = ${pool}/staging |
| 63 | ''; |
| 64 | }; |
| 65 | |
| 66 | users.groups.chloe.gid = 3000; |
| 67 | users.users.root.openssh.authorizedKeys.keys = [ adminKey ]; |
| 68 | users.users.clo = { |
| 69 | isNormalUser = true; |
| 70 | uid = 3000; |
| 71 | group = "chloe"; |
| 72 | extraGroups = [ "wheel" ]; |
| 73 | openssh.authorizedKeys.keys = [ adminKey ]; |
| 74 | }; |
| 75 | environment.variables.STUDIO_POOL = pool; |
| 76 | environment.variables.STUDIO_DOMAIN = "paperclover.net"; |
| 77 | environment.variables.STUDIO_LOCAL_AI = "true"; |
| 78 | |
| 79 | system.stateVersion = "26.05"; |
| 80 | } |