1{ lib, pkgs, ... }:
2let
3 adminKey = lib.fileContents ../config/admin.pub;
4 pool = "globe";
5 encryptionRoots = {
6 apps = "apps";
7 clover = "clover";
8 media = "clover/Media";
9 logs = "logs";
10 prod = "prod";
11 staging = "staging";
12 };
13in
14{
15 imports = [ ./zenith-network.nix ];
16
17 networking.hostName = "zenith";
18 networking.hostId = "4fa19ccb";
19 networking.firewall.allowedTCPPorts = [ 80 443 ];
20 networking.firewall.interfaces.enp4s0.allowedTCPPorts = [ 445 ];
21
22 boot.loader.systemd-boot.enable = true;
23 boot.loader.efi.canTouchEfiVariables = true;
24 boot.zfs.forceImportRoot = false;
25 boot.zfs.extraPools = [ pool ];
26 boot.zfs.requestEncryptionCredentials = false;
27 security.tpm2.enable = true;
28
29 systemd.services.studio-zfs-unlock = {
30 requires = [ "zfs-import-${pool}.service" "dev-tpmrm0.device" ];
31 after = [ "zfs-import-${pool}.service" "dev-tpmrm0.device" ];
32 before = [ "zfs-mount.service" ];
33 requiredBy = [ "zfs-mount.service" ];
34 unitConfig.DefaultDependencies = false;
35 serviceConfig = {
36 Type = "oneshot";
37 RemainAfterExit = true;
38 LoadCredentialEncrypted = lib.mapAttrsToList
39 (name: _: "zfs-${name}:/etc/credstore.encrypted/zfs-${name}") encryptionRoots;
40 };
41 script = lib.concatStrings (lib.mapAttrsToList (name: dataset: ''
42 if test "$(${pkgs.zfs}/bin/zfs get -H -o value keystatus ${pool}/${dataset})" = unavailable; then
43 ${pkgs.zfs}/bin/zfs load-key -L "file://$CREDENTIALS_DIRECTORY/zfs-${name}" ${pool}/${dataset}
44 fi
45 '') encryptionRoots);
46 };
47
48 services.xserver.videoDrivers = [ "nvidia" ];
49 hardware.graphics.enable = true;
50 hardware.nvidia.open = false;
51 hardware.nvidia.nvidiaPersistenced = true;
52 hardware.nvidia.nvidiaSettings = false;
53
54 systemd.services.nomad = {
55 requires = [ "zfs-import-${pool}.service" ];
56 after = [ "zfs-import-${pool}.service" "zfs-mount.service" ];
57 preStart = ''
58 test "$(${pkgs.util-linux}/bin/findmnt -n -o SOURCE --mountpoint /srv)" = ${pool}
59 test "$(${pkgs.util-linux}/bin/findmnt -n -o SOURCE --mountpoint /srv/clover)" = ${pool}/clover
60 test "$(${pkgs.util-linux}/bin/findmnt -n -o SOURCE --mountpoint /srv/clover/Media)" = ${pool}/clover/Media
61 test "$(${pkgs.util-linux}/bin/findmnt -n -o SOURCE --mountpoint /srv/prod)" = ${pool}/prod
62 test "$(${pkgs.util-linux}/bin/findmnt -n -o SOURCE --mountpoint /srv/staging)" = ${pool}/staging
63 '';
64 };
65
66 users.groups.chloe.gid = 3000;
67 users.users.root.openssh.authorizedKeys.keys = [ adminKey ];
68 users.users.clo = {
69 isNormalUser = true;
70 uid = 3000;
71 group = "chloe";
72 extraGroups = [ "wheel" ];
73 openssh.authorizedKeys.keys = [ adminKey ];
74 };
75 environment.variables.STUDIO_POOL = pool;
76 environment.variables.STUDIO_DOMAIN = "paperclover.net";
77 environment.variables.STUDIO_LOCAL_AI = "true";
78
79 system.stateVersion = "26.05";
80}