commit 70284509f3bfa01b7a55632bf4ed03840c63752f Author: imnyang Date: Fri Jul 3 16:53:49 2026 +0900 Initial commit diff --git a/.forgejo/workflows/main.yml b/.forgejo/workflows/main.yml new file mode 100644 index 0000000..e14226e --- /dev/null +++ b/.forgejo/workflows/main.yml @@ -0,0 +1,74 @@ +name: CI + +on: + push: + branches: + - main + paths-ignore: + - "hosts/machine/kanade/**" + pull_request: + paths-ignore: + - "hosts/machine/kanade/**" + +jobs: + check: + runs-on: x86_64 + steps: + - name: Checkout code + uses: actions/checkout@v4 + - name: Check flake + run: | + source /etc/bashrc + nix flake check + ida: + runs-on: x86_64 + steps: + - name: Checkout code + uses: actions/checkout@v4 + - name: Prefetch IDA + run: | + source /etc/bashrc + nix-prefetch-url --type sha256 https://file.mizuki.guru/.ida/ida-free-pc_93_x64linux.run + cpt: + runs-on: x86_64 + steps: + - name: Checkout code + uses: actions/checkout@v4 + - name: Prefetch Cisco Packet Tracer + run: | + source /etc/bashrc + nix-prefetch-url --type sha256 https://file.mizuki.guru/.cpt/CiscoPacketTracer_900_Ubuntu_64bit.deb + nix-prefetch-url --type sha256 https://file.mizuki.guru/.cpt/CiscoPacketTracer822_amd64_signed.deb + + build-nixos: + needs: check + runs-on: x86_64 + strategy: + fail-fast: false + matrix: + host: [mizuki, ena, hako, kazusa] + + steps: + - name: Checkout code + uses: actions/checkout@v4 + + - name: Build NixOS configuration with nom + run: | + source /etc/bashrc + nix build .#nixosConfigurations.${{ matrix.host }}.config.system.build.toplevel + + - name: Cache & Push to Attic + if: success() + env: + ATTIC_SERVER: ${{ secrets.ATTIC_SERVER }} + ATTIC_TOKEN: ${{ secrets.ATTIC_TOKEN }} + run: | + source /etc/bashrc + nix shell nixpkgs#attic-client -c bash -c " + attic login imnyang \"$ATTIC_SERVER\" \"$ATTIC_TOKEN\" + attic push imnyang ./result + " + - name: Clean Builder Environment + if: success() + run: | + nix-collect-garbage -d diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..02a8587 --- /dev/null +++ b/.gitignore @@ -0,0 +1,13 @@ +result +result-* +*.swp +*.swo +*~ + +# sops: keep encrypted secret files in git, ignore local key material/artifacts +*.dec +*.decrypted +.sops-age-key +keys.txt + +.DS_Store diff --git a/README.md b/README.md new file mode 100644 index 0000000..7b18145 --- /dev/null +++ b/README.md @@ -0,0 +1,3 @@ +nr +clean +update diff --git a/assets/1password.desktop b/assets/1password.desktop new file mode 100644 index 0000000..a0cd3f8 --- /dev/null +++ b/assets/1password.desktop @@ -0,0 +1,19 @@ +[Desktop Entry] +Categories=Office; +Comment[en_US]=Password manager and secure wallet +Comment=Password manager and secure wallet +Exec=1password --silent %U +GenericName[en_US]= +GenericName= +Icon=1password +MimeType= +Name[en_US]=1Password +Name=1Password +Path= +StartupNotify=true +StartupWMClass=1Password +Terminal=false +TerminalOptions= +Type=Application +X-KDE-SubstituteUID=false +X-KDE-Username= diff --git a/assets/Kawa.colors b/assets/Kawa.colors new file mode 100644 index 0000000..d21fe24 --- /dev/null +++ b/assets/Kawa.colors @@ -0,0 +1,147 @@ +[ColorEffects:Disabled] +Color=56,56,56 +ColorAmount=0 +ColorEffect=0 +ContrastAmount=0.65 +ContrastEffect=1 +IntensityAmount=0.1 +IntensityEffect=2 + +[ColorEffects:Inactive] +ChangeSelectionColor=true +Color=112,111,110 +ColorAmount=0.025 +ColorEffect=2 +ContrastAmount=0.1 +ContrastEffect=2 +Enable=false +IntensityAmount=0 +IntensityEffect=0 + +[Colors:Button] +BackgroundAlternate=163,212,250 +BackgroundNormal=252,248,249 +DecorationFocus=61,174,233 +DecorationHover=61,174,233 +ForegroundActive=61,174,233 +ForegroundInactive=112,125,138 +ForegroundLink=41,128,185 +ForegroundNegative=218,68,83 +ForegroundNeutral=246,116,0 +ForegroundNormal=25,16,23 +ForegroundPositive=39,174,96 +ForegroundVisited=155,89,182 + +[Colors:Complementary] +BackgroundAlternate=27,30,32 +BackgroundNormal=42,46,50 +DecorationFocus=61,174,233 +DecorationHover=61,174,233 +ForegroundActive=61,174,233 +ForegroundInactive=161,169,177 +ForegroundLink=29,153,243 +ForegroundNegative=218,68,83 +ForegroundNeutral=246,116,0 +ForegroundNormal=252,252,252 +ForegroundPositive=39,174,96 +ForegroundVisited=155,89,182 + +[Colors:Header] +BackgroundAlternate=239,240,241 +BackgroundNormal=222,224,226 +DecorationFocus=61,174,233 +DecorationHover=61,174,233 +ForegroundActive=61,174,233 +ForegroundInactive=112,125,138 +ForegroundLink=41,128,185 +ForegroundNegative=218,68,83 +ForegroundNeutral=246,116,0 +ForegroundNormal=35,38,41 +ForegroundPositive=39,174,96 +ForegroundVisited=155,89,182 + +[Colors:Header][Inactive] +BackgroundAlternate=227,229,231 +BackgroundNormal=239,240,241 +DecorationFocus=61,174,233 +DecorationHover=61,174,233 +ForegroundActive=61,174,233 +ForegroundInactive=112,125,138 +ForegroundLink=41,128,185 +ForegroundNegative=218,68,83 +ForegroundNeutral=246,116,0 +ForegroundNormal=35,38,41 +ForegroundPositive=39,174,96 +ForegroundVisited=155,89,182 + +[Colors:Selection] +BackgroundAlternate=163,212,250 +BackgroundNormal=236,183,213 +DecorationFocus=61,174,233 +DecorationHover=61,174,233 +ForegroundActive=255,255,255 +ForegroundInactive=112,125,138 +ForegroundLink=253,188,75 +ForegroundNegative=176,55,69 +ForegroundNeutral=198,92,0 +ForegroundNormal=25,16,23 +ForegroundPositive=23,104,57 +ForegroundVisited=155,89,182 + +[Colors:Tooltip] +BackgroundAlternate=239,240,241 +BackgroundNormal=247,247,247 +DecorationFocus=61,174,233 +DecorationHover=61,174,233 +ForegroundActive=61,174,233 +ForegroundInactive=112,125,138 +ForegroundLink=41,128,185 +ForegroundNegative=218,68,83 +ForegroundNeutral=246,116,0 +ForegroundNormal=35,38,41 +ForegroundPositive=39,174,96 +ForegroundVisited=155,89,182 + +[Colors:View] +BackgroundAlternate=247,247,247 +BackgroundNormal=252,248,249 +DecorationFocus=61,174,233 +DecorationHover=61,174,233 +ForegroundActive=61,174,233 +ForegroundInactive=112,125,138 +ForegroundLink=41,128,185 +ForegroundNegative=218,68,83 +ForegroundNeutral=246,116,0 +ForegroundNormal=25,16,23 +ForegroundPositive=39,174,96 +ForegroundVisited=155,89,182 + +[Colors:Window] +BackgroundAlternate=227,229,231 +BackgroundNormal=252,248,249 +DecorationFocus=61,174,233 +DecorationHover=61,174,233 +ForegroundActive=61,174,233 +ForegroundInactive=112,125,138 +ForegroundLink=41,128,185 +ForegroundNegative=218,68,83 +ForegroundNeutral=246,116,0 +ForegroundNormal=25,16,23 +ForegroundPositive=39,174,96 +ForegroundVisited=155,89,182 + +[General] +ColorScheme=BreezeLight +Name=Kawa +shadeSortColumn=true + +[KDE] +contrast=4 + +[WM] +activeBackground=227,229,231 +activeBlend=227,229,231 +activeForeground=35,38,41 +inactiveBackground=239,240,241 +inactiveBlend=239,240,241 +inactiveForeground=112,125,138 diff --git a/assets/avatar.webp b/assets/avatar.webp new file mode 100644 index 0000000..caf050e Binary files /dev/null and b/assets/avatar.webp differ diff --git a/assets/wallpaper/README.md b/assets/wallpaper/README.md new file mode 100644 index 0000000..69b17ec --- /dev/null +++ b/assets/wallpaper/README.md @@ -0,0 +1,4 @@ +[wallpaper1.jpg - @Drift0827](https://x.com/Drift0827/status/1990350670445306010?s=20) +[wallpaper2.png - 服作り奮闘中 Card](https://sekai.best/card/1356) +[wallpaper3.png - 気づいてしまった想い Card](https://sekai.best/card/202) +[wallpaper4.png - 当たり前になった打ち上げ](https://sekai.best/card/363) diff --git a/assets/wallpaper/wallpaper1.jpg b/assets/wallpaper/wallpaper1.jpg new file mode 100644 index 0000000..527a601 Binary files /dev/null and b/assets/wallpaper/wallpaper1.jpg differ diff --git a/assets/wallpaper/wallpaper2.png b/assets/wallpaper/wallpaper2.png new file mode 100644 index 0000000..e60df6f Binary files /dev/null and b/assets/wallpaper/wallpaper2.png differ diff --git a/assets/wallpaper/wallpaper3.png b/assets/wallpaper/wallpaper3.png new file mode 100644 index 0000000..679f586 Binary files /dev/null and b/assets/wallpaper/wallpaper3.png differ diff --git a/assets/wallpaper/wallpaper4.png b/assets/wallpaper/wallpaper4.png new file mode 100644 index 0000000..c98e899 Binary files /dev/null and b/assets/wallpaper/wallpaper4.png differ diff --git a/flake.lock b/flake.lock new file mode 100644 index 0000000..128d296 --- /dev/null +++ b/flake.lock @@ -0,0 +1,1065 @@ +{ + "nodes": { + "brew-src": { + "flake": false, + "locked": { + "lastModified": 1781226006, + "narHash": "sha256-w4ZTuOnhYiDxjaynrMTASzp802QblBWmo3wpB8wVN4Y=", + "owner": "Homebrew", + "repo": "brew", + "rev": "109191be4988470b51a60a5ef1998520aa24c01b", + "type": "github" + }, + "original": { + "owner": "Homebrew", + "ref": "6.0.1", + "repo": "brew", + "type": "github" + } + }, + "catppuccin": { + "inputs": { + "nixpkgs": "nixpkgs" + }, + "locked": { + "lastModified": 1782462517, + "narHash": "sha256-HPzOASBxx1bAnPREm4syM5oTb8ls2qbudkLW4BTB94s=", + "owner": "catppuccin", + "repo": "nix", + "rev": "3f3b3511f9c433b93f20b24be32de01f675b046d", + "type": "github" + }, + "original": { + "owner": "catppuccin", + "repo": "nix", + "type": "github" + } + }, + "codex-app": { + "inputs": { + "flake-utils": "flake-utils", + "nixpkgs": "nixpkgs_2" + }, + "locked": { + "lastModified": 1782539005, + "narHash": "sha256-zfsPi5MkWBelenK7tR5Vaa210ojCQwwOiefOgSJuuv0=", + "owner": "ilysenko", + "repo": "codex-desktop-linux", + "rev": "6c5de005b05ff3a251b07727b5d428b4f69ef8e5", + "type": "github" + }, + "original": { + "owner": "ilysenko", + "repo": "codex-desktop-linux", + "type": "github" + } + }, + "darwin": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1781761792, + "narHash": "sha256-rCPytmKNjctLloB6UgK5CRrHSwV4b0ygxtJLPPp8R14=", + "owner": "nix-darwin", + "repo": "nix-darwin", + "rev": "a1fa429e945becaf60468600daf649be4ba0350c", + "type": "github" + }, + "original": { + "owner": "nix-darwin", + "repo": "nix-darwin", + "type": "github" + } + }, + "flake-compat": { + "locked": { + "lastModified": 1733328505, + "narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=", + "rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec", + "revCount": 69, + "type": "tarball", + "url": "https://api.flakehub.com/f/pinned/edolstra/flake-compat/1.1.0/01948eb7-9cba-704f-bbf3-3fa956735b52/source.tar.gz" + }, + "original": { + "type": "tarball", + "url": "https://flakehub.com/f/edolstra/flake-compat/1.tar.gz" + } + }, + "flake-compat_2": { + "flake": false, + "locked": { + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", + "owner": "edolstra", + "repo": "flake-compat", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", + "type": "github" + }, + "original": { + "owner": "edolstra", + "repo": "flake-compat", + "type": "github" + } + }, + "flake-compat_3": { + "flake": false, + "locked": { + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", + "owner": "NixOS", + "repo": "flake-compat", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", + "type": "github" + }, + "original": { + "owner": "NixOS", + "repo": "flake-compat", + "type": "github" + } + }, + "flake-parts": { + "inputs": { + "nixpkgs-lib": "nixpkgs-lib" + }, + "locked": { + "lastModified": 1778716662, + "narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "flake-parts", + "type": "github" + } + }, + "flake-utils": { + "inputs": { + "systems": "systems" + }, + "locked": { + "lastModified": 1731533236, + "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", + "owner": "numtide", + "repo": "flake-utils", + "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "flake-utils", + "type": "github" + } + }, + "flake-utils_2": { + "inputs": { + "systems": "systems_2" + }, + "locked": { + "lastModified": 1726560853, + "narHash": "sha256-X6rJYSESBVr3hBoH0WbKE5KvhPU5bloyZ2L4K60/fPQ=", + "owner": "numtide", + "repo": "flake-utils", + "rev": "c1dfcf08411b08f6b8615f7d8971a2bfa81d5e8a", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "flake-utils", + "type": "github" + } + }, + "flake-utils_3": { + "inputs": { + "systems": "systems_3" + }, + "locked": { + "lastModified": 1731533236, + "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", + "owner": "numtide", + "repo": "flake-utils", + "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "flake-utils", + "type": "github" + } + }, + "flake-utils_4": { + "inputs": { + "systems": "systems_4" + }, + "locked": { + "lastModified": 1731533236, + "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", + "owner": "numtide", + "repo": "flake-utils", + "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "flake-utils", + "type": "github" + } + }, + "home-manager": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1782522538, + "narHash": "sha256-CvOaUvJ+mXlxU3m2cPWKcOAhtKETsPUYhq+Xa5ewBp4=", + "owner": "nix-community", + "repo": "home-manager", + "rev": "8d8a6cc50ddc60748791a14ee1163c865ec57635", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "home-manager", + "type": "github" + } + }, + "imnyang": { + "inputs": { + "nixpkgs": "nixpkgs_3" + }, + "locked": { + "lastModified": 1779757090, + "narHash": "sha256-6DceKYQwk2o23dxMD1JQ3+CPHSv80d2khNQC6qJ+W+8=", + "ref": "refs/heads/main", + "rev": "96d4beeb6b8c22de1dc290ef85a75e740c5e0876", + "revCount": 72, + "type": "git", + "url": "https://git.mizuki.guru/imnyang/nix-packages.git" + }, + "original": { + "type": "git", + "url": "https://git.mizuki.guru/imnyang/nix-packages.git" + } + }, + "imnyang_2": { + "inputs": { + "nixpkgs": "nixpkgs_14" + }, + "locked": { + "lastModified": 1778582554, + "narHash": "sha256-cTh1Ki0o1/n7fFvuT0XOuiERC+uNxvYf306YsnIk3SU=", + "ref": "refs/heads/main", + "rev": "0ec3a0b5650fde3a1cec8b39d0a8655728e8bea4", + "revCount": 42, + "type": "git", + "url": "https://git.mizuki.guru/imnyang/nix-packages.git" + }, + "original": { + "type": "git", + "url": "https://git.mizuki.guru/imnyang/nix-packages.git" + } + }, + "millennium": { + "inputs": { + "millennium-src": "millennium-src", + "nixpkgs": "nixpkgs_4" + }, + "locked": { + "dir": "packages/nix", + "lastModified": 1782487025, + "narHash": "sha256-torOOjdUo1AxKV4zEKD0cdOZhigyIYpLCHZ2Y4w0lkE=", + "owner": "SteamClientHomebrew", + "repo": "Millennium", + "rev": "583149e477c0ed1114827d28708e6ea6619cada4", + "type": "github" + }, + "original": { + "dir": "packages/nix", + "owner": "SteamClientHomebrew", + "repo": "Millennium", + "type": "github" + } + }, + "millennium-src": { + "flake": false, + "locked": { + "lastModified": 1782335834, + "narHash": "sha256-nqNRtEkYgXawzpw/xCAgMSyaHKl5GFvzKm8WOoaUN24=", + "owner": "SteamClientHomebrew", + "repo": "Millennium", + "rev": "dc3eae41082dd6b3b3eacffc3bfc711afbbda707", + "type": "github" + }, + "original": { + "owner": "SteamClientHomebrew", + "repo": "Millennium", + "rev": "dc3eae41082dd6b3b3eacffc3bfc711afbbda707", + "type": "github" + } + }, + "mizuki-nc": { + "inputs": { + "nixpkgs": "nixpkgs_5" + }, + "locked": { + "lastModified": 1782378344, + "narHash": "sha256-25d8nVL5f3W1apIZ4amMAPpipgpH7gPyZAqsTGcJE34=", + "ref": "refs/heads/main", + "rev": "70b1c9a2befc933c63f2b3197655b4f1166f9fbb", + "revCount": 1, + "type": "git", + "url": "https://git.mizuki.guru/imnyang/mizuki.guru.git" + }, + "original": { + "rev": "70b1c9a2befc933c63f2b3197655b4f1166f9fbb", + "type": "git", + "url": "https://git.mizuki.guru/imnyang/mizuki.guru.git" + } + }, + "muvel": { + "inputs": { + "nixpkgs": "nixpkgs_6" + }, + "locked": { + "lastModified": 1782537345, + "narHash": "sha256-8yBe/CYAwp0zWLLat/q8QfEoxql4YXnvFLNYHMVjUpc=", + "owner": "imnyang", + "repo": "muvel-nix", + "rev": "cc57a70965daeece70b4a0f285c5952b37fa119b", + "type": "github" + }, + "original": { + "owner": "imnyang", + "repo": "muvel-nix", + "type": "github" + } + }, + "nix-flatpak": { + "locked": { + "lastModified": 1780908363, + "narHash": "sha256-llGS4y3Qh1eUkli3/Y2VY9FV3GOUKFZR1E2BDftt45Q=", + "owner": "gmodena", + "repo": "nix-flatpak", + "rev": "1df08625f0f8c7d6e300a0e5df7955bbb877d809", + "type": "github" + }, + "original": { + "owner": "gmodena", + "repo": "nix-flatpak", + "type": "github" + } + }, + "nix-homebrew": { + "inputs": { + "brew-src": "brew-src" + }, + "locked": { + "lastModified": 1781389246, + "narHash": "sha256-ORqLAo/hoJdsZC7UPAuEHev6S0+XIqKEC7vjo5prz1k=", + "owner": "zhaofengli", + "repo": "nix-homebrew", + "rev": "de7953a08ed4bb9245be043e468561c17b89130d", + "type": "github" + }, + "original": { + "owner": "zhaofengli", + "repo": "nix-homebrew", + "type": "github" + } + }, + "nixcord": { + "inputs": { + "flake-compat": "flake-compat", + "flake-parts": "flake-parts", + "nixpkgs": "nixpkgs_7", + "nixpkgs-nixcord": "nixpkgs-nixcord" + }, + "locked": { + "lastModified": 1782538638, + "narHash": "sha256-1sf87lVsQznNAgI/KeUl7mEgjan3Aid0w0SdmnLF2Rw=", + "owner": "FlameFlag", + "repo": "nixcord", + "rev": "5c33a22fe307170639d8b2f5aa452497566a4ed7", + "type": "github" + }, + "original": { + "owner": "FlameFlag", + "repo": "nixcord", + "type": "github" + } + }, + "nixos-wsl": { + "inputs": { + "flake-compat": "flake-compat_2", + "nixpkgs": "nixpkgs_8" + }, + "locked": { + "lastModified": 1781182279, + "narHash": "sha256-V5EQQbDnmdiXGQXrEF1PEL7QYsFqfH8N1E89Z5ONwFk=", + "owner": "nix-community", + "repo": "NixOS-WSL", + "rev": "5675822ba756e6e56f8f6a5a76e90e0da2ece94d", + "type": "github" + }, + "original": { + "owner": "nix-community", + "ref": "main", + "repo": "NixOS-WSL", + "type": "github" + } + }, + "nixpkgs": { + "locked": { + "lastModified": 1782175435, + "narHash": "sha256-8d2wCNWKnd86GzKZvbuqqlS+HqMrheXkvRf0qGJ/oA0=", + "rev": "89570f24e97e614aa34aa9ab1c927b6578a43775", + "type": "tarball", + "url": "https://releases.nixos.org/nixpkgs/nixpkgs-26.11pre1020805.89570f24e97e/nixexprs.tar.xz" + }, + "original": { + "type": "tarball", + "url": "https://channels.nixos.org/nixpkgs-unstable/nixexprs.tar.xz" + } + }, + "nixpkgs-2511": { + "locked": { + "lastModified": 1782335603, + "narHash": "sha256-sZkQH1CkiZtdvcaLx4sGQD9Q9h+A8qB04DRpqQCN530=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "03c72920da828594fae523aaef96f33dff10b340", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-25.11", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs-lib": { + "locked": { + "lastModified": 1777168982, + "narHash": "sha256-GOkGPcboWE9BmGCRMLX3worL4EMnsnG8MyKmXNeYuhQ=", + "owner": "nix-community", + "repo": "nixpkgs.lib", + "rev": "f5901329dade4a6ea039af1433fb087bd9c1fe14", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixpkgs.lib", + "type": "github" + } + }, + "nixpkgs-nixcord": { + "locked": { + "lastModified": 1781216227, + "narHash": "sha256-9mUW6gNwoN2SWc/l0fW4svPNOulXLl8ijqKyeSOGgJE=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "a0374025a863d007d98e3297f6aa46cc3141c2f0", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-26.05", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_10": { + "locked": { + "lastModified": 1730200266, + "narHash": "sha256-l253w0XMT8nWHGXuXqyiIC/bMvh1VRszGXgdpQlfhvU=", + "owner": "nixos", + "repo": "nixpkgs", + "rev": "807e9154dcb16384b1b765ebe9cd2bba2ac287fd", + "type": "github" + }, + "original": { + "owner": "nixos", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_11": { + "locked": { + "lastModified": 1772963539, + "narHash": "sha256-9jVDGZnvCckTGdYT53d/EfznygLskyLQXYwJLKMPsZs=", + "owner": "nixos", + "repo": "nixpkgs", + "rev": "9dcb002ca1690658be4a04645215baea8b95f31d", + "type": "github" + }, + "original": { + "owner": "nixos", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_12": { + "locked": { + "lastModified": 1781577229, + "narHash": "sha256-rcUHdUtJEvMdNEl2Wq+YpHraHKfcer3KsBscpZEF2Yg=", + "rev": "567a49d1913ce81ac6e9582e3553dd90a955875f", + "type": "tarball", + "url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1017464.567a49d1913c/nixexprs.tar.xz" + }, + "original": { + "type": "tarball", + "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz" + } + }, + "nixpkgs_13": { + "locked": { + "lastModified": 1772542754, + "narHash": "sha256-WGV2hy+VIeQsYXpsLjdr4GvHv5eECMISX1zKLTedhdg=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "8c809a146a140c5c8806f13399592dbcb1bb5dc4", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_14": { + "locked": { + "lastModified": 1777954456, + "narHash": "sha256-hGdgeU2Nk87RAuZyYjyDjFL6LK7dAZN5RE9+hrDTkDU=", + "owner": "nixos", + "repo": "nixpkgs", + "rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1", + "type": "github" + }, + "original": { + "owner": "nixos", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_2": { + "locked": { + "lastModified": 1772773019, + "narHash": "sha256-E1bxHxNKfDoQUuvriG71+f+s/NT0qWkImXsYZNFFfCs=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "aca4d95fce4914b3892661bcb80b8087293536c6", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_3": { + "locked": { + "lastModified": 1779508470, + "narHash": "sha256-Ap9KJX+5xHIn3bPIpfNgT6MEXdAECECwo4/rmlQD74M=", + "owner": "nixos", + "repo": "nixpkgs", + "rev": "29916453413845e54a65b8a1cf996842300cd299", + "type": "github" + }, + "original": { + "owner": "nixos", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_4": { + "locked": { + "lastModified": 1781577229, + "narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=", + "owner": "nixos", + "repo": "nixpkgs", + "rev": "567a49d1913ce81ac6e9582e3553dd90a955875f", + "type": "github" + }, + "original": { + "owner": "nixos", + "repo": "nixpkgs", + "rev": "567a49d1913ce81ac6e9582e3553dd90a955875f", + "type": "github" + } + }, + "nixpkgs_5": { + "locked": { + "lastModified": 1781577229, + "narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "567a49d1913ce81ac6e9582e3553dd90a955875f", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_6": { + "locked": { + "lastModified": 1781577229, + "narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "567a49d1913ce81ac6e9582e3553dd90a955875f", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_7": { + "locked": { + "lastModified": 1781216227, + "narHash": "sha256-9mUW6gNwoN2SWc/l0fW4svPNOulXLl8ijqKyeSOGgJE=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "a0374025a863d007d98e3297f6aa46cc3141c2f0", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-26.05", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_8": { + "locked": { + "lastModified": 1780243769, + "narHash": "sha256-x5UQuRsH3MqI0U9afaXSNqzTPSeZlRLvFAav2Ux1pNw=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "331800de5053fcebacf6813adb5db9c9dca22a0c", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_9": { + "locked": { + "lastModified": 1782467914, + "narHash": "sha256-pGvFkM8N0xEkIIXDe5YYfbEAvHrk4IxBrjB/x8OomhE=", + "owner": "nixos", + "repo": "nixpkgs", + "rev": "e73de5be04e0eff4190a1432b946d469c794e7b4", + "type": "github" + }, + "original": { + "owner": "nixos", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "notion-calendar-electron": { + "inputs": { + "flake-utils": "flake-utils_2", + "nixpkgs": "nixpkgs_10" + }, + "locked": { + "lastModified": 1764778294, + "narHash": "sha256-kYex7JjucpAMxOvLL9GbXxqgHcB4qhOMSE2VlNw7udI=", + "owner": "czlabinger", + "repo": "notion-calendar-electron", + "rev": "7e01efb90361048b27220abb9b9e703ab705d05d", + "type": "github" + }, + "original": { + "owner": "czlabinger", + "repo": "notion-calendar-electron", + "type": "github" + } + }, + "notion-desktop": { + "inputs": { + "flake-utils": "flake-utils_3", + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1768704570, + "narHash": "sha256-5yguPW33Gp2uYVKUgIiE5kgtct+/Sy5rsgI4Tu1yMHM=", + "owner": "heytcass", + "repo": "notion-mac-flake", + "rev": "8cc1e702d64270bd6517bf9fb640f80844d371fd", + "type": "github" + }, + "original": { + "owner": "heytcass", + "repo": "notion-mac-flake", + "type": "github" + } + }, + "paring": { + "inputs": { + "flake-utils": "flake-utils_4", + "nixpkgs": "nixpkgs_11" + }, + "locked": { + "lastModified": 1773918161, + "narHash": "sha256-m+BNlxiBcf/t3hROBNQ+Ni1dITej/Ixpafw83+gWrYE=", + "ref": "refs/heads/master", + "rev": "4d251d65e72d00f168354aca95a26fc04d12a936", + "revCount": 45, + "type": "git", + "url": "https://git.pari.ng/paring/nix-packages.git" + }, + "original": { + "type": "git", + "url": "https://git.pari.ng/paring/nix-packages.git" + } + }, + "plasma-manager": { + "inputs": { + "home-manager": [ + "home-manager" + ], + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1775856943, + "narHash": "sha256-b7Mp7P+q2Md5AGt4rjHfMcBykzMumFTen10ST++AuTU=", + "owner": "nix-community", + "repo": "plasma-manager", + "rev": "a524a6160e6df89f7673ba293cf7d78b559eb1a5", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "plasma-manager", + "type": "github" + } + }, + "quadlet-nix": { + "locked": { + "lastModified": 1782004439, + "narHash": "sha256-OANOcPKJ3JThp2x/ccz4DDrGDY2hIgM5SBLI51swgfI=", + "owner": "SEIAROTg", + "repo": "quadlet-nix", + "rev": "f1652b490b812c4e0b2a36565cdbedf87f35e438", + "type": "github" + }, + "original": { + "owner": "SEIAROTg", + "repo": "quadlet-nix", + "type": "github" + } + }, + "root": { + "inputs": { + "catppuccin": "catppuccin", + "codex-app": "codex-app", + "darwin": "darwin", + "home-manager": "home-manager", + "imnyang": "imnyang", + "millennium": "millennium", + "mizuki-nc": "mizuki-nc", + "muvel": "muvel", + "nix-flatpak": "nix-flatpak", + "nix-homebrew": "nix-homebrew", + "nixcord": "nixcord", + "nixos-wsl": "nixos-wsl", + "nixpkgs": "nixpkgs_9", + "nixpkgs-2511": "nixpkgs-2511", + "notion-calendar-electron": "notion-calendar-electron", + "notion-desktop": "notion-desktop", + "paring": "paring", + "plasma-manager": "plasma-manager", + "quadlet-nix": "quadlet-nix", + "rustfs": "rustfs", + "sops-nix": "sops-nix", + "spicetify-nix": "spicetify-nix", + "vicinae": "vicinae", + "vicinae-extensions": "vicinae-extensions", + "vscode-nigo": "vscode-nigo" + } + }, + "rustfs": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1781317333, + "narHash": "sha256-qnjeFFELEyOO0vkubMB96WCuFzkvftTZ/LE/VctU+SE=", + "owner": "rustfs", + "repo": "rustfs-flake", + "rev": "1d3ef7296a7b22b4b9849d0766f53a0300bce893", + "type": "github" + }, + "original": { + "owner": "rustfs", + "repo": "rustfs-flake", + "type": "github" + } + }, + "sops-nix": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1782165805, + "narHash": "sha256-478kKQBvK6SYTOdN2h9jhKJv94nbXRbFMfuL1WshErg=", + "owner": "Mic92", + "repo": "sops-nix", + "rev": "56b24064fdcaedca53553b1a6d607fd23b613a24", + "type": "github" + }, + "original": { + "owner": "Mic92", + "repo": "sops-nix", + "type": "github" + } + }, + "spicetify-nix": { + "inputs": { + "nixpkgs": "nixpkgs_12", + "systems": "systems_5" + }, + "locked": { + "lastModified": 1782031037, + "narHash": "sha256-a7oWSyS7SN81UOqVt481yIEMDsMpaJ7GNdV6Eaz5Yqg=", + "owner": "Gerg-L", + "repo": "spicetify-nix", + "rev": "9cb27462cfd20edac174353f1e95bc03aa888863", + "type": "github" + }, + "original": { + "owner": "Gerg-L", + "repo": "spicetify-nix", + "type": "github" + } + }, + "systems": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "systems_2": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "systems_3": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "systems_4": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "systems_5": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "systems_6": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "systems_7": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "vicinae": { + "inputs": { + "nixpkgs": "nixpkgs_13", + "systems": "systems_6" + }, + "locked": { + "lastModified": 1782513466, + "narHash": "sha256-u7TnJKoSgPglZeLTP/4PBMk+QSm4oVg38UhyM1y8cHI=", + "owner": "vicinaehq", + "repo": "vicinae", + "rev": "2fa382ea622d29d646045245ba6db49def980372", + "type": "github" + }, + "original": { + "owner": "vicinaehq", + "repo": "vicinae", + "type": "github" + } + }, + "vicinae-extensions": { + "inputs": { + "flake-compat": "flake-compat_3", + "nixpkgs": [ + "nixpkgs" + ], + "systems": "systems_7", + "vicinae": "vicinae_2" + }, + "locked": { + "lastModified": 1782258187, + "narHash": "sha256-JUv1Hf0P0B3k/c8/PyaqMQn+1VOSPJrB7EP3Us8fyFo=", + "owner": "vicinaehq", + "repo": "extensions", + "rev": "27d2b04f9ce48bdc69c29cd25d91d854fc8a835f", + "type": "github" + }, + "original": { + "owner": "vicinaehq", + "repo": "extensions", + "type": "github" + } + }, + "vicinae_2": { + "inputs": { + "nixpkgs": [ + "vicinae-extensions", + "nixpkgs" + ], + "systems": [ + "vicinae-extensions", + "systems" + ] + }, + "locked": { + "lastModified": 1780277152, + "narHash": "sha256-P3YrDLnggsMsSoiX/ox3CS6GkZtY37XQVon/QR6Agw8=", + "owner": "vicinaehq", + "repo": "vicinae", + "rev": "67290dff5b2191a6cb6dd78b31d623eeef3acdec", + "type": "github" + }, + "original": { + "owner": "vicinaehq", + "repo": "vicinae", + "type": "github" + } + }, + "vscode-nigo": { + "inputs": { + "imnyang": "imnyang_2", + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1778582610, + "narHash": "sha256-XzmvwRG9Ztjls52qYSDsq5U0x6jD6lRJfnp/A2TWv4M=", + "ref": "main", + "rev": "43b78f086143ade3fe37da41b9bc804055660022", + "revCount": 10, + "type": "git", + "url": "https://git.pari.ng/imnyang/vscode-nigo.git" + }, + "original": { + "ref": "main", + "type": "git", + "url": "https://git.pari.ng/imnyang/vscode-nigo.git" + } + } + }, + "root": "root", + "version": 7 +} diff --git a/flake.nix b/flake.nix new file mode 100644 index 0000000..d034a0b --- /dev/null +++ b/flake.nix @@ -0,0 +1,139 @@ +{ + description = "imnyang's Nix Configuration"; + + inputs = { + nixpkgs.url = "github:nixos/nixpkgs?ref=nixos-unstable"; + nixpkgs-2511.url = "github:NixOS/nixpkgs/nixos-25.11"; + + home-manager = { + url = "github:nix-community/home-manager"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + spicetify-nix.url = "github:Gerg-L/spicetify-nix"; + + catppuccin.url = "github:catppuccin/nix"; + + nix-flatpak.url = "github:gmodena/nix-flatpak/"; + + plasma-manager = { + url = "github:nix-community/plasma-manager"; + inputs.nixpkgs.follows = "nixpkgs"; + inputs.home-manager.follows = "home-manager"; + }; + + darwin = { + url = "github:nix-darwin/nix-darwin"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + nix-homebrew.url = "github:zhaofengli/nix-homebrew"; + + sops-nix = { + url = "github:Mic92/sops-nix"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + nixcord.url = "github:FlameFlag/nixcord"; + # nixcord.url = "path:/home/imnyang/workspaces/git/imnyang/nixcord"; + + vscode-nigo = { + url = "git+https://git.pari.ng/imnyang/vscode-nigo.git?ref=main"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + notion-desktop = { + url = "github:heytcass/notion-mac-flake"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + notion-calendar-electron.url = "github:czlabinger/notion-calendar-electron"; + + millennium.url = "github:SteamClientHomebrew/Millennium?dir=packages/nix"; + + vicinae.url = "github:vicinaehq/vicinae"; + + vicinae-extensions = { + url = "github:vicinaehq/extensions"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + nixos-wsl.url = "github:nix-community/NixOS-WSL/main"; + + codex-app = { + url = "github:ilysenko/codex-desktop-linux"; + }; + + quadlet-nix.url = "github:SEIAROTg/quadlet-nix"; + + rustfs = { + url = "github:rustfs/rustfs-flake"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + imnyang.url = "git+https://git.mizuki.guru/imnyang/nix-packages.git"; + + paring.url = "git+https://git.pari.ng/paring/nix-packages.git"; + + mizuki-nc.url = "git+https://git.mizuki.guru/imnyang/mizuki.guru.git?rev=70b1c9a2befc933c63f2b3197655b4f1166f9fbb"; + + muvel.url = "github:imnyang/muvel-nix"; + }; + + outputs = + inputs@{ + imnyang, + paring, + ... + }: + let + # Overlays + overlays = [ + paring.overlays.default + imnyang.overlays.default + inputs.millennium.overlays.default + (import ./overlays/spotx.nix) + (final: prev: { + pythonPackagesExtensions = (prev.pythonPackagesExtensions or [ ]) ++ [ + (python-final: python-prev: { + uefi-firmware-parser = python-prev.uefi-firmware-parser.overridePythonAttrs (old: { + build-system = (old.build-system or [ ]) ++ [ + python-final.setuptools-scm + ]; + }); + }) + ]; + }) + (import ./overlays/hoffice) + ]; + + mkHost = + hostPath: overlays: + import hostPath { + inherit inputs overlays; + }; + in + { + nixosConfigurations = { + # Machine + mafuyu = mkHost ./hosts/machine/mafuyu overlays; + mizuki = mkHost ./hosts/machine/mizuki overlays; + ena = mkHost ./hosts/machine/ena overlays; + ribbon = mkHost ./hosts/machine/ribbon [ + paring.overlays.default + imnyang.overlays.default + ]; + + # Server + hikari = mkHost ./hosts/server/hikari/default overlays; + hako = mkHost ./hosts/server/hikari/hako overlays; + natsu = mkHost ./hosts/server/natsu overlays; + kazusa = mkHost ./hosts/server/kazusa overlays; + }; + + darwinConfigurations = { + # Machine + kanade = mkHost ./hosts/machine/kanade overlays; + }; + }; +} diff --git a/hosts/machine/ena/configuration.nix b/hosts/machine/ena/configuration.nix new file mode 100644 index 0000000..d74a4af --- /dev/null +++ b/hosts/machine/ena/configuration.nix @@ -0,0 +1,59 @@ +{ + config, + pkgs, + inputs, + ... +}: +{ + imports = [ + ./hardware-configuration.nix + + "${inputs.self}/modules/nixos/base" + "${inputs.self}/modules/nixos/features/boot.nix" + "${inputs.self}/modules/nixos/features/fonts.nix" + "${inputs.self}/modules/nixos/features/plasma.nix" + "${inputs.self}/modules/nixos/features/sound.nix" + "${inputs.self}/modules/nixos/features/packages.nix" + "${inputs.self}/modules/nixos/features/catppuccin.nix" + "${inputs.self}/modules/nixos/features/figma-agent.nix" + "${inputs.self}/modules/nixos/features/sbctl.nix" + "${inputs.self}/modules/nixos/features/grub-standalone.nix" + "${inputs.self}/modules/nixos/features/virtualisation.nix" + "${inputs.self}/modules/nixos/features/cockpit.nix" + "${inputs.self}/modules/nixos/features/bluetooth.nix" + "${inputs.self}/modules/nixos/features/graphics.nix" + "${inputs.self}/modules/nixos/features/steam.nix" + "${inputs.self}/modules/nixos/features/ssh.nix" + ]; + + networking = { + hostName = "ena"; + networkmanager.enable = true; + firewall.enable = false; + }; + + networking.networkmanager.plugins = [ + pkgs.networkmanager-ssh + ]; + + services.printing.enable = true; + services.power-profiles-daemon.enable = true; + services.asusd.enable = true; + services.netbird.enable = true; + + systemd.services.asusctl-battery-limit = { + description = "Set ASUS battery charge limit"; + wantedBy = [ "multi-user.target" ]; + wants = [ "asusd.service" ]; + after = [ "asusd.service" ]; + serviceConfig = { + Type = "oneshot"; + ExecStart = "${pkgs.asusctl}/bin/asusctl battery limit 95"; + RemainAfterExit = true; + }; + }; + + services.cloudflare-warp.enable = true; + + system.stateVersion = "25.11"; +} diff --git a/hosts/machine/ena/default.nix b/hosts/machine/ena/default.nix new file mode 100644 index 0000000..68d2d69 --- /dev/null +++ b/hosts/machine/ena/default.nix @@ -0,0 +1,42 @@ +{ + inputs, + overlays, +}: +let + inherit (inputs) + nixpkgs + home-manager + catppuccin + nix-flatpak + plasma-manager + spicetify-nix + vicinae + ; +in +nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + ./hardware-configuration.nix + ./configuration.nix + catppuccin.nixosModules.catppuccin + nix-flatpak.nixosModules.nix-flatpak + # lanzaboote.nixosModules.lanzaboote + home-manager.nixosModules.home-manager + { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + home-manager.backupFileExtension = "backup"; + home-manager.sharedModules = [ + plasma-manager.homeModules.plasma-manager + spicetify-nix.homeManagerModules.default + vicinae.homeManagerModules.default + ]; + home-manager.extraSpecialArgs = { inherit inputs; }; + home-manager.users.imnyang = import ./home; + } + ]; + specialArgs = { + inherit inputs; + inherit overlays; + }; +} diff --git a/hosts/machine/ena/hardware-configuration.nix b/hosts/machine/ena/hardware-configuration.nix new file mode 100644 index 0000000..2fc5f7a --- /dev/null +++ b/hosts/machine/ena/hardware-configuration.nix @@ -0,0 +1,71 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ + config, + lib, + pkgs, + modulesPath, + ... +}: + +{ + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ + "xhci_pci" + "thunderbolt" + "nvme" + "usbhid" + ]; + boot.initrd.kernelModules = [ "xe" ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.kernelParams = [ + # NVMe APST(Autonomous Power State Transition) 관련 이슈 방지 + "nvme_core.default_ps_max_latency_us=0" + "xe.enable_psr=0" + "intel_idle.max_cstate=2" # C-state를 깊게 들어가지 않도록 제한 (테스트 후 점진적으로 상향 가능) + ]; + hardware.enableRedistributableFirmware = true; + boot.extraModulePackages = [ ]; + + fileSystems."/" = { + device = "/dev/disk/by-uuid/161e6b72-1ec6-4b9c-b1b7-325dd4320c2e"; + fsType = "ext4"; + }; + + boot.initrd.luks.devices."luks-5a2a5e2d-749d-408e-82df-82e8607ae67e" = { + device = "/dev/disk/by-uuid/5a2a5e2d-749d-408e-82df-82e8607ae67e"; + allowDiscards = true; + }; + + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/7078-16D1"; + fsType = "vfat"; + options = [ + "fmask=0077" + "dmask=0077" + ]; + }; + + swapDevices = [ ]; + + hardware.graphics = { + enable = true; + extraPackages = with pkgs; [ + intel-media-driver + intel-compute-runtime + vpl-gpu-rt # Lunar Lake 비디오 가속을 위한 핵심 패키지 + ]; + }; + + hardware.cpu.intel.updateMicrocode = true; + + services.thermald.enable = true; # 인텔 CPU 발열 및 전력 관리 보조 + services.fstrim.enable = true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + # hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/hosts/machine/ena/home/config/plasma.nix b/hosts/machine/ena/home/config/plasma.nix new file mode 100644 index 0000000..85a6f65 --- /dev/null +++ b/hosts/machine/ena/home/config/plasma.nix @@ -0,0 +1,15 @@ +{ inputs, ... }: +let + assets = "${inputs.self}/assets"; +in +{ + imports = [ "${inputs.self}/modules/home/plasma.nix" ]; + + programs.plasma.workspace.cursor = { + theme = "pjsk-cursor-n25-ena-ani"; + }; + + programs.plasma.workspace.wallpaper = "${assets}/wallpaper/wallpaper1.jpg"; + + programs.plasma.kscreenlocker.appearance.wallpaper = "${assets}/wallpaper/wallpaper3.png"; +} diff --git a/hosts/machine/ena/home/config/shell.nix b/hosts/machine/ena/home/config/shell.nix new file mode 100644 index 0000000..12bd876 --- /dev/null +++ b/hosts/machine/ena/home/config/shell.nix @@ -0,0 +1,59 @@ +{ + programs.fish = { + enable = true; + + shellAliases = { + # 디렉토리 네비게이션 + ".." = "cd .."; + "..." = "cd ../.."; + + # ls 별칭 + ls = "eza --icons=always"; + ll = "eza --icons=always -l"; + la = "eza --icons=always -a"; + lla = "eza --icons=always -la"; + + cat = "bat --plain"; + + # NixOS 관련 + rebuild = "nr"; + update = "nix flake update"; + clean = "sudo nix-collect-garbage -d"; + }; + + interactiveShellInit = '' + set -g fish_greeting "" + set -g fish_color_command blue + set -g fish_color_error red + set -g fish_color_param cyan + ''; + }; + + programs.starship = { + enable = true; + settings = { + format = "🎨 $directory:$character"; + add_newline = false; + # username = { + # style_user = "purple"; + # style_root = "purple"; + # format = "[$user]($style)"; + # show_always = true; + # }; + # hostname = { + # style = "green"; + # format = "[$hostname]($style)"; + # ssh_only = false; + # }; + directory = { + style = "fg:#fbb6c4"; + format = "[$path]($style)"; + truncation_length = 3; + }; + character = { + success_symbol = " 💕"; + error_symbol = " ⚠️"; + }; + }; + }; +} diff --git a/hosts/machine/ena/home/default.nix b/hosts/machine/ena/home/default.nix new file mode 100644 index 0000000..1374c9c --- /dev/null +++ b/hosts/machine/ena/home/default.nix @@ -0,0 +1,46 @@ +{ + config, + pkgs, + inputs, + ... +}: +{ + xdg.enable = true; + # gtk.enable = true; + + home.stateVersion = "25.05"; + home.username = "imnyang"; + home.homeDirectory = "/home/imnyang"; + home.packages = import ./packages.nix { inherit pkgs inputs; }; + + home.sessionVariables = { + EDITOR = "nano"; + VISUAL = "nano"; + }; + + xdg.configFile."fontconfig/conf.d/10-hm-fonts.conf".force = true; + + programs.vicinae = { + enable = true; + systemd = { + enable = true; + autoStart = true; + environment = { + USE_LAYER_SHELL = 1; + }; + }; + }; + + imports = [ + "${inputs.self}/modules/home/git.nix" + # "${inputs.self}/modules/home/firefox.nix + "${inputs.self}/modules/home/neovim.nix" + "${inputs.self}/modules/home/spicetify.nix" + "${inputs.self}/modules/home/ghostty.nix" + "${inputs.self}/modules/home/zed.nix" + "${inputs.self}/modules/home/discord/linux.nix" + "${inputs.self}/modules/home/vscode.nix" + ./config/shell.nix + ./config/plasma.nix + ]; +} diff --git a/hosts/machine/ena/home/packages.nix b/hosts/machine/ena/home/packages.nix new file mode 100644 index 0000000..ba89c7f --- /dev/null +++ b/hosts/machine/ena/home/packages.nix @@ -0,0 +1,27 @@ +{ pkgs, inputs }: +let + system = pkgs.stdenv.hostPlatform.system; + pkgsPacketTracer8 = import inputs.nixpkgs-2511 { + inherit system; + config = { + allowUnfree = true; + permittedInsecurePackages = [ + "ciscoPacketTracer8-8.2.2" + ]; + }; + }; +in +with pkgs; +(import ../../../../modules/home/packages.nix { inherit pkgs inputs; }) +++ [ + # tail-tray + kdePackages.kcolorchooser + fastfetch + # amnezia-vpn + # inputs.waterfox.packages.${pkgs.system}.waterfox + gnome-network-displays + element-desktop + cisco-packet-tracer_9 + pkgsPacketTracer8.ciscoPacketTracer8 + # hoffice +] diff --git a/hosts/machine/kanade/configuration.nix b/hosts/machine/kanade/configuration.nix new file mode 100644 index 0000000..9828834 --- /dev/null +++ b/hosts/machine/kanade/configuration.nix @@ -0,0 +1,23 @@ +{ + pkgs, + inputs, + overlays ? [ ], + ... +}: +{ + imports = [ + ./modules/nix.nix + ./modules/user.nix + ./modules/mac + ./modules/packages.nix + ./modules/homebrew/default.nix + "${inputs.self}/modules/home/discord/mac.nix" + ]; + + nixpkgs = { + hostPlatform = "aarch64-darwin"; + overlays = overlays; + }; + + system.stateVersion = 5; +} diff --git a/hosts/machine/kanade/default.nix b/hosts/machine/kanade/default.nix new file mode 100644 index 0000000..4f7c316 --- /dev/null +++ b/hosts/machine/kanade/default.nix @@ -0,0 +1,36 @@ +{ + inputs, + overlays, +}: +let + inherit (inputs) darwin home-manager; +in +darwin.lib.darwinSystem { + system = "aarch64-darwin"; + modules = [ + ./configuration.nix + home-manager.darwinModules.home-manager + inputs.nix-homebrew.darwinModules.nix-homebrew + { + nix-homebrew = { + enable = true; + user = "imnyang"; + mutableTaps = true; + # nix-darwin's Homebrew module uses /opt/homebrew/bin/brew directly. + # The nix-homebrew integration calls `brew` before it is on PATH. + enableFishIntegration = false; + }; + } + { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + home-manager.backupFileExtension = "backup"; + home-manager.extraSpecialArgs = { inherit inputs; }; + home-manager.users.imnyang = import ./home; + } + ]; + specialArgs = { + inherit inputs; + inherit overlays; + }; +} diff --git a/hosts/machine/kanade/home/config/git.nix b/hosts/machine/kanade/home/config/git.nix new file mode 100644 index 0000000..e648dfe --- /dev/null +++ b/hosts/machine/kanade/home/config/git.nix @@ -0,0 +1,31 @@ +{ pkgs, ... }: +{ + programs.git = { + enable = true; + + # 기본 사용자 설정 + # userName = "imnyang"; + # userEmail = "imnyang@pm.me"; + + settings = { + user = { + signingkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOHP3Z+AYrRh9f8TYyqChKfeyNm3lOe0F75AwRHTTaxD"; + name = "imnyang"; + email = "imnyang@pm.me"; + }; + # gpg = { + # format = "ssh"; + # "ssh".program = "/Applications/1Password.app/Contents/MacOS/op-ssh-sign"; + # }; + # commit.gpgsign = true; + init.defaultBranch = "main"; + pull.rebase = false; + includeIf."gitdir:~/workspaces/git/adofai.gg/" = { + path = builtins.toFile "gitconfig-adofaigg" '' + [user] + email = imnyang@adofai.gg + ''; + }; + }; + }; +} diff --git a/hosts/machine/kanade/home/config/shell.nix b/hosts/machine/kanade/home/config/shell.nix new file mode 100644 index 0000000..15189dc --- /dev/null +++ b/hosts/machine/kanade/home/config/shell.nix @@ -0,0 +1,64 @@ +{ + programs.fish = { + enable = true; + + shellAliases = { + ".." = "cd .."; + "..." = "cd ../.."; + + ls = "eza --icons=always"; + ll = "eza --icons=always -l"; + la = "eza --icons=always -a"; + lla = "eza --icons=always -la"; + + # nix-darwin 관련 + rebuild = "sudo darwin-rebuild switch --flake .#kanade"; + update = "nix flake update"; + clean = "nix-collect-garbage -d"; + }; + + interactiveShellInit = '' + set -g fish_greeting "" + set -g fish_color_command blue + set -g fish_color_error red + set -g fish_color_param cyan + + set -gx ANDROID_HOME "$HOME/Library/Android/sdk" + if test -d "$ANDROID_HOME/ndk" + set -l ndk_versions "$ANDROID_HOME"/ndk/* + if test (count $ndk_versions) -gt 0 + set -gx NDK_HOME $ndk_versions[-1] + end + end + + set -gx SSH_AUTH_SOCK /Users/imnyang/.ssh/proton-pass-agent.sock + ''; + }; + programs.starship = { + enable = true; + settings = { + format = "🎼 $directory:$character"; + add_newline = false; + # username = { + # style_user = "purple"; + # style_root = "purple"; + # format = "[$user]($style)"; + # show_always = true; + # }; + # hostname = { + # style = "green"; + # format = "[$hostname]($style)"; + # ssh_only = false; + # }; + directory = { + style = "fg:#fbb6c4"; + format = "[$path]($style)"; + truncation_length = 3; + }; + character = { + success_symbol = " 💕"; + error_symbol = " ⚠️"; + }; + }; + }; +} diff --git a/hosts/machine/kanade/home/default.nix b/hosts/machine/kanade/home/default.nix new file mode 100644 index 0000000..60c601c --- /dev/null +++ b/hosts/machine/kanade/home/default.nix @@ -0,0 +1,27 @@ +{ + config, + pkgs, + inputs, + ... +}: +{ + xdg.enable = true; + + home.stateVersion = "25.05"; + home.username = "imnyang"; + home.homeDirectory = "/Users/imnyang"; + home.packages = import ./packages.nix { inherit pkgs inputs; }; + + home.sessionVariables = { + EDITOR = "nvim"; + VISUAL = "nvim"; + }; + + imports = [ + "${inputs.self}/modules/home/neovim.nix" + "${inputs.self}/modules/home/ghostty.nix" + "${inputs.self}/modules/home/zed.nix" + ./config/git.nix + ./config/shell.nix + ]; +} diff --git a/hosts/machine/kanade/home/packages.nix b/hosts/machine/kanade/home/packages.nix new file mode 100644 index 0000000..485dd82 --- /dev/null +++ b/hosts/machine/kanade/home/packages.nix @@ -0,0 +1,55 @@ +{ pkgs, inputs, ... }: +let + dr = import ../../../../modules/nixos/features/packages/dr.nix { inherit pkgs; }; +in +with pkgs; +[ + # Language runtimes and package managers + nodejs + pnpm + yarn + bun + python3 + rustup + go + + # Editors and database tools + neovide + jetbrains.datagrip + jetbrains.idea + + # CLI utilities + ripgrep + fd + bat + fzf + jq + eza + fastfetch + btop + + # Source control + gh + lazygit + + # Browsers + google-chrome + + # Development applications + postman + scrcpy + + # Virtualisation + utm + + # Media + iina + + # Gaming + prismlauncher + + # Nix workflows + dr + + inputs.muvel.packages.${pkgs.stdenv.hostPlatform.system}.muvel +] diff --git a/hosts/machine/kanade/modules/homebrew/brews.nix b/hosts/machine/kanade/modules/homebrew/brews.nix new file mode 100644 index 0000000..34b265f --- /dev/null +++ b/hosts/machine/kanade/modules/homebrew/brews.nix @@ -0,0 +1,8 @@ +[ + # Apple and mobile development + "cocoapods" + "watchman" + + # Media customisation + "spicetify-cli" +] diff --git a/hosts/machine/kanade/modules/homebrew/casks.nix b/hosts/machine/kanade/modules/homebrew/casks.nix new file mode 100644 index 0000000..669b885 --- /dev/null +++ b/hosts/machine/kanade/modules/homebrew/casks.nix @@ -0,0 +1,46 @@ +[ + # Security and networking + "1password" + "cloudflare-warp" + "protonvpn" + "microsoft-edge@canary" + + # Communication + "discord" + "discord@canary" + "proton-mail" + "signal" + "zoom" + + # Productivity and design + "camo-studio" + "proton-drive" + "figma" + "notion" + + # Development + "android-studio" + "burp-suite" + "docker-desktop" + "unity-hub" + "visual-studio-code@insiders" + "zed" + "codex" + "codex-app" + "codexbar" + + # Media and audio + "finetune" + "spotify" + + # Gaming and remote access + "parsec" + "steam" + + # macOS utilities + "alt-tab" + "keka" + "raycast" + "thaw" + "mole-app" +] diff --git a/hosts/machine/kanade/modules/homebrew/default.nix b/hosts/machine/kanade/modules/homebrew/default.nix new file mode 100644 index 0000000..f616632 --- /dev/null +++ b/hosts/machine/kanade/modules/homebrew/default.nix @@ -0,0 +1,18 @@ +{ + ... +}: +{ + homebrew = { + enable = true; + enableFishIntegration = true; + + onActivation = { + autoUpdate = true; + cleanup = "zap"; + upgrade = true; + }; + + brews = import ./brews.nix; + casks = import ./casks.nix; + }; +} diff --git a/hosts/machine/kanade/modules/mac/avatar.nix b/hosts/machine/kanade/modules/mac/avatar.nix new file mode 100644 index 0000000..18ec72d --- /dev/null +++ b/hosts/machine/kanade/modules/mac/avatar.nix @@ -0,0 +1,34 @@ +{ + pkgs, + inputs, + ... +}: +let + avatar = pkgs.runCommand "kanade-avatar.jpg" { nativeBuildInputs = [ pkgs.imagemagick ]; } '' + magick "${inputs.self}/assets/avatar.webp" -quality 92 "$out" + ''; +in +{ + system.activationScripts.postActivation.text = '' + avatarPath="/Library/User Pictures/imnyang.jpg" + importFile="$(/usr/bin/mktemp /tmp/imnyang-avatar.XXXXXX)" + + /usr/bin/install -d -m 0755 "/Library/User Pictures" + /usr/bin/install -m 0644 "${avatar}" "$avatarPath" + + # Replace both account-picture representations. JPEGPhoto is embedded in + # the directory record and is used by the login screen and System Settings. + /usr/bin/dscl . -delete /Users/imnyang JPEGPhoto >/dev/null 2>&1 || true + /usr/bin/dscl . -delete /Users/imnyang Picture >/dev/null 2>&1 || true + /usr/bin/dscl . -create /Users/imnyang Picture "$avatarPath" + + /usr/bin/printf '%s\n%s:%s' \ + '0x0A 0x5C 0x3A 0x2C dsRecTypeStandard:Users 2 dsAttrTypeStandard:RecordName externalbinary:dsAttrTypeStandard:JPEGPhoto' \ + 'imnyang' \ + "$avatarPath" > "$importFile" + /usr/bin/dsimport "$importFile" /Local/Default M + /bin/rm -f "$importFile" + + /usr/bin/dscacheutil -flushcache + ''; +} diff --git a/hosts/machine/kanade/modules/mac/default.nix b/hosts/machine/kanade/modules/mac/default.nix new file mode 100644 index 0000000..779e535 --- /dev/null +++ b/hosts/machine/kanade/modules/mac/default.nix @@ -0,0 +1,10 @@ +{ + imports = [ + ./avatar.nix + ./dock.nix + ./keyboard.nix + ./preferences.nix + ./touch-id.nix + ./wallpaper.nix + ]; +} diff --git a/hosts/machine/kanade/modules/mac/dock.nix b/hosts/machine/kanade/modules/mac/dock.nix new file mode 100644 index 0000000..c52c081 --- /dev/null +++ b/hosts/machine/kanade/modules/mac/dock.nix @@ -0,0 +1,36 @@ +{ pkgs, ... }: +{ + system.defaults.dock = { + autohide = false; + show-recents = true; + + wvous-bl-corner = 1; + wvous-br-corner = 1; + wvous-tl-corner = 1; + wvous-tr-corner = 1; + + persistent-apps = [ + "/System/Applications/Apps.app" + "/Applications/Microsoft Edge Canary.app" + "/Applications/Discord.app" + "/Applications/KakaoTalk.app" + "/Applications/Signal.app" + "/Applications/Proton Mail.app" + # "/Applications/Proton Pass.app" + # "/System/Applications/Mail.app" + "/Applications/1Password.app" + "/Applications/Figma.app" + "/Applications/Notion.app" + # "/Applications/Notion Calendar.app" + "${pkgs.utm}/Applications/UTM.app" + "/Applications/Spotify.app" + "${pkgs.ghostty-bin}/Applications/Ghostty.app" + "/Applications/Visual Studio Code - Insiders.app" + "/Applications/Zed.app" + "/System/Applications/System Settings.app" + ]; + mru-spaces = false; + tilesize = 48; + orientation = "bottom"; + }; +} diff --git a/hosts/machine/kanade/modules/mac/keyboard.nix b/hosts/machine/kanade/modules/mac/keyboard.nix new file mode 100644 index 0000000..2d5b3fe --- /dev/null +++ b/hosts/machine/kanade/modules/mac/keyboard.nix @@ -0,0 +1,14 @@ +{ + system.keyboard.enableKeyMapping = true; + + system.defaults.NSGlobalDomain = { + ApplePressAndHoldEnabled = false; + InitialKeyRepeat = 15; + KeyRepeat = 2; + NSAutomaticCapitalizationEnabled = false; + NSAutomaticDashSubstitutionEnabled = false; + NSAutomaticPeriodSubstitutionEnabled = false; + NSAutomaticQuoteSubstitutionEnabled = false; + NSAutomaticSpellingCorrectionEnabled = false; + }; +} diff --git a/hosts/machine/kanade/modules/mac/preferences.nix b/hosts/machine/kanade/modules/mac/preferences.nix new file mode 100644 index 0000000..e7fb7dc --- /dev/null +++ b/hosts/machine/kanade/modules/mac/preferences.nix @@ -0,0 +1,92 @@ +{ pkgs, ... }: +{ + # sudo_local is managed as a regular file by touch-id.nix because macOS 26 + # rejects nix-darwin's symlink-based /etc/pam.d management. + security.pam.services.sudo_local.enable = false; + + networking = { + hostName = "kanade"; + computerName = "kanade"; + localHostName = "kanade"; + }; + + time.timeZone = "Asia/Seoul"; + + # Keep the terminal font declared in the Ghostty Home Manager module available + # to native macOS applications as well. + fonts.packages = [ pkgs.nerd-fonts.jetbrains-mono ]; + + system.defaults = { + NSGlobalDomain = { + AppleICUForce24HourTime = true; + AppleMeasurementUnits = "Centimeters"; + AppleTemperatureUnit = "Celsius"; + + AppleInterfaceStyleSwitchesAutomatically = false; + AppleInterfaceStyle = null; + + NSAutomaticCapitalizationEnabled = false; + NSAutomaticDashSubstitutionEnabled = false; + NSAutomaticPeriodSubstitutionEnabled = false; + NSAutomaticQuoteSubstitutionEnabled = false; + NSAutomaticSpellingCorrectionEnabled = false; + + AppleShowAllExtensions = true; + AppleShowAllFiles = true; + NSNavPanelExpandedStateForSaveMode = true; + NSNavPanelExpandedStateForSaveMode2 = true; + "com.apple.sound.beep.feedback" = 0; + }; + + SoftwareUpdate = { + AutomaticallyInstallMacOSUpdates = false; + }; + + finder = { + AppleShowAllExtensions = true; + FXEnableExtensionChangeWarning = false; + FXDefaultSearchScope = "SCcf"; + FXRemoveOldTrashItems = true; + ShowPathbar = true; + ShowStatusBar = true; + # _FXShowPosixPathInTitle = true; + }; + + menuExtraClock = { + ShowAMPM = false; + ShowDate = 1; + ShowSeconds = false; + Show24Hour = true; + }; + + trackpad = { + Clicking = true; + TrackpadRightClick = true; + TrackpadThreeFingerDrag = true; + }; + + loginwindow.GuestEnabled = false; + + CustomUserPreferences = { + "com.apple.AdLib" = { + allowApplePersonalizedAdvertising = false; + }; + "com.apple.controlcenter" = { + BatteryShowPercentage = true; + }; + "com.apple.desktopservices" = { + DSDontWriteNetworkStores = true; + DSDontWriteUSBStores = true; + }; + "com.apple.finder"._FXSortFoldersFirst = true; + "com.apple.screensaver" = { + askForPassword = 1; + askForPasswordDelay = 0; + }; + }; + }; + + system.activationScripts.postActivation.text = '' + /System/Library/PrivateFrameworks/SystemAdministration.framework/Resources/activateSettings -u + ''; +} diff --git a/hosts/machine/kanade/modules/mac/touch-id.nix b/hosts/machine/kanade/modules/mac/touch-id.nix new file mode 100644 index 0000000..17ab26b --- /dev/null +++ b/hosts/machine/kanade/modules/mac/touch-id.nix @@ -0,0 +1,12 @@ +{ pkgs, ... }: +let + sudoLocal = pkgs.writeText "sudo_local" '' + # Managed by nix-darwin: use Touch ID for sudo with password fallback. + auth sufficient pam_tid.so + ''; +in +{ + system.activationScripts.postActivation.text = '' + /usr/bin/install -m 0444 "${sudoLocal}" /etc/pam.d/sudo_local + ''; +} diff --git a/hosts/machine/kanade/modules/mac/wallpaper.nix b/hosts/machine/kanade/modules/mac/wallpaper.nix new file mode 100644 index 0000000..bb3847f --- /dev/null +++ b/hosts/machine/kanade/modules/mac/wallpaper.nix @@ -0,0 +1,42 @@ +{ + pkgs, + inputs, + ... +}: +let + wallpaper = "${inputs.self}/assets/wallpaper/wallpaper1.jpg"; + setWallpaperScript = pkgs.writeShellScriptBin "set-wallpaper-script" '' + set -eu + + # System Events runs in the logged-in Aqua session and updates every Space. + # Retry because launch agents can start before the desktop is fully ready. + for attempt in {1..12}; do + if /usr/bin/osascript <<'APPLESCRIPT' + tell application "System Events" + tell every desktop + set picture to "${wallpaper}" + end tell + end tell +APPLESCRIPT + then + exit 0 + fi + + /bin/sleep 5 + done + + exit 1 + ''; +in +{ + environment.systemPackages = [ setWallpaperScript ]; + + launchd.user.agents.set-wallpaper = { + command = "${setWallpaperScript}/bin/set-wallpaper-script"; + serviceConfig = { + RunAtLoad = true; + ProcessType = "Interactive"; + LimitLoadToSessionType = "Aqua"; + }; + }; +} diff --git a/hosts/machine/kanade/modules/nix.nix b/hosts/machine/kanade/modules/nix.nix new file mode 100644 index 0000000..4f7e202 --- /dev/null +++ b/hosts/machine/kanade/modules/nix.nix @@ -0,0 +1,37 @@ +{ ... }: +{ + nixpkgs.config.allowUnfree = true; + + nix.settings = { + sandbox = "relaxed"; + experimental-features = [ + "nix-command" + "flakes" + ]; + # Optimising during every build can race on Darwin. Run it separately instead. + auto-optimise-store = false; + trusted-users = [ + "imnyang" + ]; + substituters = [ + "https://cache.mizuki.guru" + "https://nix.mizuki.my/public" + ]; + trusted-public-keys = [ + "cache.mizuki.guru-1:EbUC9b0ryD7BJKqfT8fl4GoS2ojLV+hI9fW1al5Whp0=" + "public:SnHrtrxbCPcZujbJdgsKFeObTfRKQl5KhrI+LljtZUE=" + ]; + }; + + nix.optimise.automatic = true; + + nix.gc = { + automatic = true; + interval = { + Weekday = 0; + Hour = 3; + Minute = 15; + }; + options = "--delete-older-than 7d"; + }; +} diff --git a/hosts/machine/kanade/modules/packages.nix b/hosts/machine/kanade/modules/packages.nix new file mode 100644 index 0000000..ddc442c --- /dev/null +++ b/hosts/machine/kanade/modules/packages.nix @@ -0,0 +1,13 @@ +{ pkgs, ... }: +{ + environment.systemPackages = with pkgs; [ + # Recovery and bootstrap tools + curl + wget + vim + + # Nix tooling + nixd + nil + ]; +} diff --git a/hosts/machine/kanade/modules/user.nix b/hosts/machine/kanade/modules/user.nix new file mode 100644 index 0000000..b2c09ae --- /dev/null +++ b/hosts/machine/kanade/modules/user.nix @@ -0,0 +1,15 @@ +{ pkgs, ... }: +{ + system.primaryUser = "imnyang"; + + users.users.imnyang = { + name = "imnyang"; + home = "/Users/imnyang"; + shell = pkgs.fish; + }; + + environment.shells = [ pkgs.fish ]; + + programs.fish.enable = true; + programs.zsh.enable = true; +} diff --git a/hosts/machine/mafuyu/configuration.nix b/hosts/machine/mafuyu/configuration.nix new file mode 100644 index 0000000..f48c276 --- /dev/null +++ b/hosts/machine/mafuyu/configuration.nix @@ -0,0 +1,64 @@ +{ pkgs, inputs, ... }: +{ + imports = [ + ./hardware-configuration.nix + + "${inputs.self}/modules/nixos/base" + "${inputs.self}/modules/nixos/features/boot.nix" + "${inputs.self}/modules/nixos/features/fonts.nix" + "${inputs.self}/modules/nixos/features/packages.nix" + "${inputs.self}/modules/nixos/features/plasma.nix" + "${inputs.self}/modules/nixos/features/sound.nix" + "${inputs.self}/modules/nixos/features/catppuccin.nix" + "${inputs.self}/modules/nixos/features/ssh.nix" + "${inputs.self}/modules/nixos/features/steam.nix" + "${inputs.self}/modules/nixos/features/sunshine.nix" + ]; + + networking = { + hostName = "mafuyu"; + networkmanager.enable = true; + firewall.enable = false; + }; + + services.caddy = { + enable = true; + virtualHosts."http://broadcast.epc.mizuki.arpa".extraConfig = '' + @preflight method OPTIONS + + header { + Access-Control-Allow-Origin * + Access-Control-Allow-Methods "GET, POST, PUT, PATCH, DELETE, OPTIONS" + Access-Control-Allow-Headers * + } + + respond @preflight "" 204 + + reverse_proxy 127.0.0.1:6769 + ''; + virtualHosts."http://broadcast.epc.mizuki.arpa:8027".extraConfig = '' + @preflight method OPTIONS + + header { + Access-Control-Allow-Origin * + Access-Control-Allow-Methods "GET, POST, PUT, PATCH, DELETE, OPTIONS" + Access-Control-Allow-Headers * + } + + respond @preflight "" 204 + + reverse_proxy 127.0.0.1:1108 + ''; + }; + + services.displayManager = { + plasma-login-manager.enable = true; + autoLogin.user = "imnyang"; + }; + + users.users.imnyang.openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOHP3Z+AYrRh9f8TYyqChKfeyNm3lOe0F75AwRHTTaxD imnyang@mizuki" + ]; + + system.stateVersion = "26.05"; +} diff --git a/hosts/machine/mafuyu/default.nix b/hosts/machine/mafuyu/default.nix new file mode 100644 index 0000000..7738a04 --- /dev/null +++ b/hosts/machine/mafuyu/default.nix @@ -0,0 +1,37 @@ +{ + inputs, + overlays, +}: +let + inherit (inputs) + nixpkgs + home-manager + catppuccin + plasma-manager + spicetify-nix + ; +in +nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + ./hardware-configuration.nix + ./configuration.nix + catppuccin.nixosModules.catppuccin + home-manager.nixosModules.home-manager + { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + home-manager.backupFileExtension = "backup"; + home-manager.sharedModules = [ + plasma-manager.homeModules.plasma-manager + spicetify-nix.homeManagerModules.default + ]; + home-manager.extraSpecialArgs = { inherit inputs; }; + home-manager.users.imnyang = import ./home; + } + ]; + specialArgs = { + inherit inputs; + inherit overlays; + }; +} diff --git a/hosts/machine/mafuyu/hardware-configuration.nix b/hosts/machine/mafuyu/hardware-configuration.nix new file mode 100644 index 0000000..19107f8 --- /dev/null +++ b/hosts/machine/mafuyu/hardware-configuration.nix @@ -0,0 +1,79 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ + config, + lib, + pkgs, + modulesPath, + ... +}: + +{ + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ + "xhci_pci" + "ahci" + "usb_storage" + "usbhid" + "uas" + "sd_mod" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + boot.kernelParams = [ + # 가상 디스플레이(해상도) 1개 생성 + "video=virtual:1920x1080@60" + ]; + + fileSystems."/" = { + device = "/dev/disk/by-uuid/223889e0-caa4-4dc5-a7b3-e5260230896f"; + fsType = "ext4"; + }; + + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/7233-6B3C"; + fsType = "vfat"; + options = [ + "fmask=0077" + "dmask=0077" + ]; + }; + + swapDevices = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; + hardware.nvidia = { + modesetting.enable = true; + powerManagement.enable = true; + powerManagement.finegrained = false; # 이슈 있으면 비활하기 + + open = false; + nvidiaSettings = true; + package = config.boot.kernelPackages.nvidiaPackages.stable; + }; + services.xserver.videoDrivers = [ "nvidia" ]; + + hardware.graphics = { + enable = true; + enable32Bit = true; + + extraPackages = with pkgs; [ + libva-vdpau-driver + libvdpau-va-gl + vulkan-loader + nvidia-vaapi-driver + vulkan-validation-layers + vulkan-extension-layer + ]; + extraPackages32 = with pkgs.pkgsi686Linux; [ + libva-vdpau-driver + libvdpau-va-gl + ]; + }; +} diff --git a/hosts/machine/mafuyu/home/config/plasma.nix b/hosts/machine/mafuyu/home/config/plasma.nix new file mode 100644 index 0000000..c9e8d27 --- /dev/null +++ b/hosts/machine/mafuyu/home/config/plasma.nix @@ -0,0 +1,16 @@ +{ inputs, ... }: +let + assets = "${inputs.self}/assets"; +in +{ + imports = [ "${inputs.self}/modules/home/plasma.nix" ]; + services.kdeconnect.enable = true; + + programs.plasma.workspace.cursor = { + theme = "pjsk-cursor-n25-mafuyu-ani"; + }; + + programs.plasma.workspace.wallpaper = "${assets}/wallpaper/wallpaper3.png"; + + programs.plasma.kscreenlocker.appearance.wallpaper = "${assets}/wallpaper/wallpaper3.png"; +} diff --git a/hosts/machine/mafuyu/home/config/shell.nix b/hosts/machine/mafuyu/home/config/shell.nix new file mode 100644 index 0000000..17a5093 --- /dev/null +++ b/hosts/machine/mafuyu/home/config/shell.nix @@ -0,0 +1,54 @@ +{ + programs.fish = { + enable = true; + + shellAliases = { + ".." = "cd .."; + "..." = "cd ../.."; + + ls = "eza --icons=always"; + ll = "eza --icons=always -l"; + la = "eza --icons=always -a"; + lla = "eza --icons=always -la"; + + rebuild = "nr"; + update = "nix flake update"; + clean = "sudo nix-collect-garbage -d"; + }; + + interactiveShellInit = '' + set -g fish_greeting "" + set -g fish_color_command blue + set -g fish_color_error red + set -g fish_color_param cyan + ''; + }; + + programs.starship = { + enable = true; + settings = { + format = "❄️ $directory:$character"; + add_newline = false; + # username = { + # style_user = "purple"; + # style_root = "purple"; + # format = "[$user]($style)"; + # show_always = true; + # }; + # hostname = { + # style = "green"; + # format = "[$hostname]($style)"; + # ssh_only = false; + # }; + directory = { + style = "fg:#fbb6c4"; + format = "[$path]($style)"; + truncation_length = 3; + }; + character = { + success_symbol = " 💕"; + error_symbol = " ⚠️"; + }; + }; + }; +} diff --git a/hosts/machine/mafuyu/home/default.nix b/hosts/machine/mafuyu/home/default.nix new file mode 100644 index 0000000..2e69a57 --- /dev/null +++ b/hosts/machine/mafuyu/home/default.nix @@ -0,0 +1,44 @@ +{ + config, + pkgs, + inputs, + ... +}: +{ + xdg.enable = true; + + home.stateVersion = "25.05"; + home.username = "imnyang"; + home.homeDirectory = "/home/imnyang"; + home.packages = import ./packages.nix { inherit pkgs inputs; }; + + home.sessionVariables = { + EDITOR = "nvim"; + VISUAL = "nvim"; + }; + + xdg.configFile."fontconfig/conf.d/10-hm-fonts.conf".force = true; + + programs.git = { + enable = true; + settings = { + user = { + name = "imnyang"; + email = "imnyang@pm.me"; + }; + commit.gpgsign = false; + init.defaultBranch = "main"; + pull.rebase = false; + }; + }; + + imports = [ + "${inputs.self}/modules/home/firefox.nix" + "${inputs.self}/modules/home/neovim.nix" + "${inputs.self}/modules/home/ghostty.nix" + "${inputs.self}/modules/home/zed.nix" + "${inputs.self}/modules/home/discord/linux.nix" + ./config/shell.nix + ./config/plasma.nix + ]; +} diff --git a/hosts/machine/mafuyu/home/packages.nix b/hosts/machine/mafuyu/home/packages.nix new file mode 100644 index 0000000..3831639 --- /dev/null +++ b/hosts/machine/mafuyu/home/packages.nix @@ -0,0 +1,7 @@ +{ pkgs, inputs }: +with pkgs; +[ + pjsk-cursor.n25.ani + codex + inputs.codex-app.packages.${stdenv.buildPlatform.system}.codex-desktop +] diff --git a/hosts/machine/mizuki/configuration.nix b/hosts/machine/mizuki/configuration.nix new file mode 100644 index 0000000..a166c7d --- /dev/null +++ b/hosts/machine/mizuki/configuration.nix @@ -0,0 +1,55 @@ +{ pkgs, inputs, ... }: +{ + imports = [ + ./hardware-configuration.nix + + "${inputs.self}/modules/nixos/base" + "${inputs.self}/modules/nixos/features/boot.nix" + "${inputs.self}/modules/nixos/features/fonts.nix" + "${inputs.self}/modules/nixos/features/packages.nix" + "${inputs.self}/modules/nixos/features/plasma.nix" + "${inputs.self}/modules/nixos/features/sound.nix" + "${inputs.self}/modules/nixos/features/catppuccin.nix" + "${inputs.self}/modules/nixos/features/figma-agent.nix" + "${inputs.self}/modules/nixos/features/cockpit.nix" + "${inputs.self}/modules/nixos/features/bluetooth.nix" + "${inputs.self}/modules/nixos/features/graphics.nix" + "${inputs.self}/modules/nixos/features/ssh.nix" + "${inputs.self}/modules/nixos/features/virtualisation.nix" + "${inputs.self}/modules/nixos/features/steam.nix" + "${inputs.self}/modules/nixos/features/sunshine.nix" + ]; + + networking = { + hostName = "mizuki"; + networkmanager.enable = true; + firewall.enable = false; + interfaces = { + enp3s0 = { + wakeOnLan.enable = true; + }; + }; + }; + + services.caddy = { + enable = true; + virtualHosts."http://broadcast.epc.mizuki.arpa".extraConfig = '' + @preflight method OPTIONS + + header { + Access-Control-Allow-Origin * + Access-Control-Allow-Methods "GET, POST, PUT, PATCH, DELETE, OPTIONS" + Access-Control-Allow-Headers * + } + + respond @preflight "" 204 + + reverse_proxy 127.0.0.1:6769 + ''; + }; + + services.printing.enable = true; + services.flatpak.enable = true; + + system.stateVersion = "26.05"; +} diff --git a/hosts/machine/mizuki/default.nix b/hosts/machine/mizuki/default.nix new file mode 100644 index 0000000..b90728c --- /dev/null +++ b/hosts/machine/mizuki/default.nix @@ -0,0 +1,41 @@ +{ + inputs, + overlays, +}: +let + inherit (inputs) + nixpkgs + home-manager + catppuccin + nix-flatpak + plasma-manager + spicetify-nix + vicinae + ; +in +nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + ./hardware-configuration.nix + ./configuration.nix + catppuccin.nixosModules.catppuccin + nix-flatpak.nixosModules.nix-flatpak + home-manager.nixosModules.home-manager + { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + home-manager.backupFileExtension = "backup"; + home-manager.sharedModules = [ + plasma-manager.homeModules.plasma-manager + spicetify-nix.homeManagerModules.default + vicinae.homeManagerModules.default + ]; + home-manager.extraSpecialArgs = { inherit inputs; }; + home-manager.users.imnyang = import ./home; + } + ]; + specialArgs = { + inherit inputs; + inherit overlays; + }; +} diff --git a/hosts/machine/mizuki/hardware-configuration.nix b/hosts/machine/mizuki/hardware-configuration.nix new file mode 100644 index 0000000..73cdf61 --- /dev/null +++ b/hosts/machine/mizuki/hardware-configuration.nix @@ -0,0 +1,91 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ + config, + lib, + pkgs, + modulesPath, + ... +}: + +{ + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ + "xhci_pci" + "ahci" + "nvme" + "usbhid" + "sd_mod" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.kernelParams = [ "nvidia.NV_temporaryFilePath=/var/tmp" ]; + boot.extraModulePackages = [ ]; + boot.extraModprobeConfig = '' + options nvidia NVreg_PreserveVideoMemoryAllocations=1 + ''; + + fileSystems."/" = + { device = "/dev/mapper/luks-f103ab07-586f-4bfe-b8e9-cdee9d504a0a"; + fsType = "ext4"; + }; + + boot.initrd.luks.devices."luks-f103ab07-586f-4bfe-b8e9-cdee9d504a0a".device = "/dev/disk/by-uuid/f103ab07-586f-4bfe-b8e9-cdee9d504a0a"; + + fileSystems."/boot" = + { device = "/dev/disk/by-uuid/C9F2-8CD3"; + fsType = "vfat"; + options = [ "fmask=0077" "dmask=0077" ]; + }; + + fileSystems."/data" = { + device = "/dev/disk/by-uuid/0fa840c5-07ad-46b5-a0e8-0ed958d1bb7a"; + fsType = "ext4"; + options = [ + "defaults" + "nofail" + ]; + }; + + swapDevices = [ + { + device = "/swapfile"; + size = 32 * 1024; + } + ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; + hardware.nvidia = { + modesetting.enable = true; + powerManagement.enable = true; + powerManagement.finegrained = false; # 이슈 있으면 비활하기 + + open = false; + nvidiaSettings = true; + package = config.boot.kernelPackages.nvidiaPackages.stable; + }; + services.xserver.videoDrivers = [ "nvidia" ]; + + hardware.graphics = { + enable = true; + enable32Bit = true; + + extraPackages = with pkgs; [ + libva-vdpau-driver + libvdpau-va-gl + vulkan-loader + nvidia-vaapi-driver + vulkan-validation-layers + vulkan-extension-layer + ]; + extraPackages32 = with pkgs.pkgsi686Linux; [ + libva-vdpau-driver + libvdpau-va-gl + ]; + }; +} diff --git a/hosts/machine/mizuki/home/config/plasma.nix b/hosts/machine/mizuki/home/config/plasma.nix new file mode 100644 index 0000000..d8198d5 --- /dev/null +++ b/hosts/machine/mizuki/home/config/plasma.nix @@ -0,0 +1,16 @@ +{ inputs, ... }: +let + assets = "${inputs.self}/assets"; +in +{ + imports = [ "${inputs.self}/modules/home/plasma.nix" ]; + services.kdeconnect.enable = true; + + programs.plasma.workspace.cursor = { + theme = "pjsk-cursor-n25-mizuki-ani"; + }; + + programs.plasma.workspace.wallpaper = "${assets}/wallpaper/wallpaper1.jpg"; + + programs.plasma.kscreenlocker.appearance.wallpaper = "${assets}/wallpaper/wallpaper3.png"; +} diff --git a/hosts/machine/mizuki/home/config/shell.nix b/hosts/machine/mizuki/home/config/shell.nix new file mode 100644 index 0000000..1a29669 --- /dev/null +++ b/hosts/machine/mizuki/home/config/shell.nix @@ -0,0 +1,54 @@ +{ + programs.fish = { + enable = true; + + shellAliases = { + ".." = "cd .."; + "..." = "cd ../.."; + + ls = "eza --icons=always"; + ll = "eza --icons=always -l"; + la = "eza --icons=always -a"; + lla = "eza --icons=always -la"; + + rebuild = "nr"; + update = "nix flake update"; + clean = "sudo nix-collect-garbage -d"; + }; + + interactiveShellInit = '' + set -g fish_greeting "" + set -g fish_color_command blue + set -g fish_color_error red + set -g fish_color_param cyan + ''; + }; + + programs.starship = { + enable = true; + settings = { + format = "🎀 $directory:$character"; + add_newline = false; + # username = { + # style_user = "purple"; + # style_root = "purple"; + # format = "[$user]($style)"; + # show_always = true; + # }; + # hostname = { + # style = "green"; + # format = "[$hostname]($style)"; + # ssh_only = false; + # }; + directory = { + style = "fg:#fbb6c4"; + format = "[$path]($style)"; + truncation_length = 3; + }; + character = { + success_symbol = " 💕"; + error_symbol = " ⚠️"; + }; + }; + }; +} diff --git a/hosts/machine/mizuki/home/default.nix b/hosts/machine/mizuki/home/default.nix new file mode 100644 index 0000000..76f4fd6 --- /dev/null +++ b/hosts/machine/mizuki/home/default.nix @@ -0,0 +1,61 @@ +{ + config, + pkgs, + inputs, + ... +}: +{ + xdg.enable = true; + # gtk.enable = true; + + home.stateVersion = "25.05"; + home.username = "imnyang"; + home.homeDirectory = "/home/imnyang"; + home.packages = import ./packages.nix { inherit pkgs inputs; }; + + home.sessionVariables = { + EDITOR = "nvim"; + VISUAL = "nvim"; + }; + + programs.ssh = { + enable = true; + matchBlocks = { + "*" = { + forwardAgent = false; + identityAgent = "~/.1password/agent.sock"; + setEnv = { + TERM = "xterm-256color"; + }; + extraOptions = { + ServerAliveInterval = "0"; + ServerAliveCountMax = "3"; + Compression = "no"; + AddKeysToAgent = "no"; + HashKnownHosts = "no"; + UserKnownHostsFile = "~/.ssh/known_hosts"; + ControlMaster = "no"; + ControlPath = "~/.ssh/master-%r@%n:%p"; + ControlPersist = "no"; + }; + }; + }; + }; + + xdg.configFile."fontconfig/conf.d/10-hm-fonts.conf".force = true; + + imports = [ + "${inputs.self}/modules/home/git.nix" + "${inputs.self}/modules/home/neovim.nix" + "${inputs.self}/modules/home/spicetify.nix" + "${inputs.self}/modules/home/ghostty.nix" + "${inputs.self}/modules/home/zed.nix" + "${inputs.self}/modules/home/vicinae.nix" + ./config/shell.nix + ./config/plasma.nix + "${inputs.self}/modules/home/discord/linux.nix" + "${inputs.self}/modules/home/obs-studio.nix" + "${inputs.self}/modules/home/vscode.nix" + "${inputs.self}/modules/home/ciscopackettracer.nix" + ]; +} diff --git a/hosts/machine/mizuki/home/packages.nix b/hosts/machine/mizuki/home/packages.nix new file mode 100644 index 0000000..4a50fd0 --- /dev/null +++ b/hosts/machine/mizuki/home/packages.nix @@ -0,0 +1,16 @@ +{ pkgs, inputs }: +with pkgs; +(import ../../../../modules/home/packages.nix { inherit pkgs inputs; }) +++ [ + # tail-tray + kdePackages.kcolorchooser + fastfetch + android-studio + lmstudio + + # dotnet-runtime + dotnet-sdk + jetbrains.rider + # waterfox-bin + # inputs.waterfox.packages.${pkgs.system}.waterfox +] diff --git a/hosts/machine/ribbon/configuration.nix b/hosts/machine/ribbon/configuration.nix new file mode 100644 index 0000000..6e9de34 --- /dev/null +++ b/hosts/machine/ribbon/configuration.nix @@ -0,0 +1,21 @@ +{ pkgs, inputs, ... }: +{ + imports = [ + "${inputs.self}/modules/nixos/base" + "${inputs.self}/modules/nixos/features/ssh.nix" + ]; + + wsl.enable = true; + wsl.defaultUser = "imnyang"; + + networking = { + hostName = "ribbon"; + firewall.enable = false; + }; + + users.users.imnyang.openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOHP3Z+AYrRh9f8TYyqChKfeyNm3lOe0F75AwRHTTaxD imnyang@mizuki" + ]; + + system.stateVersion = "25.11"; +} diff --git a/hosts/machine/ribbon/default.nix b/hosts/machine/ribbon/default.nix new file mode 100644 index 0000000..6efc793 --- /dev/null +++ b/hosts/machine/ribbon/default.nix @@ -0,0 +1,31 @@ +{ + inputs, + overlays, +}: +let + inherit (inputs) + nixpkgs + nixos-wsl + home-manager + ; +in +nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + nixos-wsl.nixosModules.default + ./configuration.nix + home-manager.nixosModules.home-manager + { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + home-manager.backupFileExtension = "backup"; + home-manager.sharedModules = []; + home-manager.extraSpecialArgs = { inherit inputs; }; + home-manager.users.imnyang = import ./home/home.nix; + } + ]; + specialArgs = { + inherit inputs; + inherit overlays; + }; +} diff --git a/hosts/machine/ribbon/home/config/shell.nix b/hosts/machine/ribbon/home/config/shell.nix new file mode 100644 index 0000000..f944770 --- /dev/null +++ b/hosts/machine/ribbon/home/config/shell.nix @@ -0,0 +1,57 @@ +{ + programs.fish = { + enable = true; + + shellAliases = { + # 디렉토리 네비게이션 + ".." = "cd .."; + "..." = "cd ../.."; + + # ls 별칭 + ls = "eza --icons=always"; + ll = "eza --icons=always -l"; + la = "eza --icons=always -a"; + lla = "eza --icons=always -la"; + + # NixOS 관련 + rebuild = "nr"; + update = "nix flake update"; + clean = "sudo nix-collect-garbage -d"; + }; + + interactiveShellInit = '' + set -g fish_greeting "" + set -g fish_color_command blue + set -g fish_color_error red + set -g fish_color_param cyan + ''; + }; + + programs.starship = { + enable = true; + settings = { + format = "$username@$hostname:$directory$character"; + add_newline = false; + username = { + style_user = "purple"; + style_root = "purple"; + format = "[$user]($style)"; + show_always = true; + }; + hostname = { + style = "green"; + format = "[$hostname]($style)"; + ssh_only = false; + }; + directory = { + style = "blue"; + format = "[$path]($style)"; + truncation_length = 3; + }; + character = { + success_symbol = " >"; + error_symbol = " >"; + }; + }; + }; +} diff --git a/hosts/machine/ribbon/home/home.nix b/hosts/machine/ribbon/home/home.nix new file mode 100644 index 0000000..c08979b --- /dev/null +++ b/hosts/machine/ribbon/home/home.nix @@ -0,0 +1,35 @@ +{ + config, + pkgs, + inputs, + ... +}: +{ + home.stateVersion = "25.11"; + home.username = "imnyang"; + home.homeDirectory = "/home/imnyang"; + home.packages = import ./packages.nix { inherit pkgs inputs; }; + + home.sessionVariables = { + EDITOR = "nvim"; + VISUAL = "nvim"; + }; + + programs.git = { + enable = true; + settings = { + user = { + name = "imnyang"; + email = "imnyang@pm.me"; + }; + commit.gpgsign = false; + init.defaultBranch = "main"; + pull.rebase = false; + }; + }; + + imports = [ + "${inputs.self}/modules/home/neovim.nix" + ./config/shell.nix + ]; +} diff --git a/hosts/machine/ribbon/home/packages.nix b/hosts/machine/ribbon/home/packages.nix new file mode 100644 index 0000000..af9f70e --- /dev/null +++ b/hosts/machine/ribbon/home/packages.nix @@ -0,0 +1,10 @@ +{ pkgs, inputs }: +let + nr = import "${inputs.self}/modules/nixos/features/packages/nr.nix" { inherit pkgs; }; + nrr = import "${inputs.self}/modules/nixos/features/packages/nrr.nix" { inherit pkgs; }; +in +with pkgs; +[ + nr + nrr +] diff --git a/hosts/server/hikari/default/.sops.yaml b/hosts/server/hikari/default/.sops.yaml new file mode 100644 index 0000000..8246a92 --- /dev/null +++ b/hosts/server/hikari/default/.sops.yaml @@ -0,0 +1,7 @@ +creation_rules: + - path_regex: secrets/.*\.ya?ml$ + age: + - age1mgels4hjl7l07gcnt72g86kvhrvd82fha9kuvlp46mpks7unrpmqvy959u # mizuki + - age1dcvh6q9953es9fvt8rq8rdgcktlt64asn2tf2y3vmyz0gntxzynqg2xgzk # hako + - age1wnxeqyzqsnylm4vdgzrlyu7k4yev82zuru6nzy72hwvu6htde4gq9wc5vu # hikari + - age1hlld327xfhm44hns9l9j6h4csrl5cl50h2qkhpl3969awgl665fsnxd3zc # kanade diff --git a/hosts/server/hikari/default/configuration.nix b/hosts/server/hikari/default/configuration.nix new file mode 100644 index 0000000..6f03a7a --- /dev/null +++ b/hosts/server/hikari/default/configuration.nix @@ -0,0 +1,55 @@ +{ pkgs, inputs, ... }: +{ + imports = [ + ./hardware-configuration.nix + "${inputs.self}/modules/nixos/base" + "${inputs.self}/modules/nixos/features/cockpit.nix" + "${inputs.self}/modules/nixos/features/boot.nix" + "${inputs.self}/modules/nixos/features/ssh.nix" + "${inputs.self}/modules/nixos/features/podman.nix" + + ./services/rustfs.nix + ./services/nextcloud.nix + ]; + + # 1. 크론 설정 + services.cron = { + enable = true; + systemCronJobs = [ + "0 1 * * * imnyang printf '\\n%s : ' \"$(date)\" >> /home/imnyang/codelounge.log && /home/imnyang/codelounge.sh >> /home/imnyang/codelounge.log" + ]; + }; + + services.qemuGuest.enable = true; + + # 2. 사용자 SSH 키 등록 + users.users.imnyang.openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOHP3Z+AYrRh9f8TYyqChKfeyNm3lOe0F75AwRHTTaxD imnyang@kazusa" + ]; + + environment.systemPackages = with pkgs; [ + eza + neovim + nil + nixd + ]; + + programs.git.config = { + safe.directory = "*"; + }; + + nix.settings.require-sigs = false; + + networking = { + hostName = "hikari"; + networkmanager.enable = true; + firewall.enable = false; + bridges.br0 = { + interfaces = [ + "eno1" + ]; + }; + }; + + system.stateVersion = "26.05"; +} diff --git a/hosts/server/hikari/default/default.nix b/hosts/server/hikari/default/default.nix new file mode 100644 index 0000000..8404459 --- /dev/null +++ b/hosts/server/hikari/default/default.nix @@ -0,0 +1,33 @@ +{ + inputs, + overlays, +}: +let + inherit (inputs) + nixpkgs + home-manager + quadlet-nix + sops-nix + ; +in +nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + ./configuration.nix + ./hardware-configuration.nix + sops-nix.nixosModules.sops + home-manager.nixosModules.home-manager + inputs.rustfs.nixosModules.rustfs + quadlet-nix.nixosModules.quadlet + { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + home-manager.extraSpecialArgs = { inherit inputs; }; + home-manager.users.imnyang = import ./home.nix; + } + ]; + specialArgs = { + inherit inputs; + inherit overlays; + }; +} diff --git a/hosts/server/hikari/default/hardware-configuration.nix b/hosts/server/hikari/default/hardware-configuration.nix new file mode 100644 index 0000000..efa640b --- /dev/null +++ b/hosts/server/hikari/default/hardware-configuration.nix @@ -0,0 +1,65 @@ +# Do not modify this file! It was generated by nixos-generate-config +# and may be overwritten by future invocations. Please make changes +# to configuration.nix instead. +{ + config, + lib, + pkgs, + modulesPath, + ... +}: + +{ + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ + "nvme" + "xhci_pci" + "ahci" + "usb_storage" + "usbhid" + "uas" + "sd_mod" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-amd" ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = { + device = "/dev/mapper/luks-32ac59f9-fa04-4ec7-a7a2-9b6821c19e35"; + fsType = "ext4"; + }; + fileSystems."/".neededForBoot = true; + + boot.initrd.luks.devices."luks-32ac59f9-fa04-4ec7-a7a2-9b6821c19e35" = { + device = "/dev/disk/by-uuid/32ac59f9-fa04-4ec7-a7a2-9b6821c19e35"; + }; + + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/ED22-EDE6"; + fsType = "vfat"; + options = [ + "fmask=0077" + "dmask=0077" + ]; + }; + + fileSystems."/mnt/snow" = { + device = "/dev/disk/by-uuid/68ecc71d-66d7-4900-9ac2-1ddde0d607a8"; + fsType = "ext4"; + }; + + fileSystems."/mnt/rain" = { + device = "/dev/disk/by-uuid/311b9c03-eb92-42f1-824b-d1a997916abb"; + fsType = "ext4"; + }; + + swapDevices = [ ]; + + hardware.ksm.enable = true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/hosts/server/hikari/default/home.nix b/hosts/server/hikari/default/home.nix new file mode 100644 index 0000000..7d9d39d --- /dev/null +++ b/hosts/server/hikari/default/home.nix @@ -0,0 +1,66 @@ +{ + pkgs, + inputs, + ... +}: +let + nr = import "${inputs.self}/modules/nixos/features/packages/nr.nix" { inherit pkgs; }; + nrr = import "${inputs.self}/modules/nixos/features/packages/nrr.nix" { inherit pkgs; }; +in +{ + home.stateVersion = "26.05"; + home.username = "imnyang"; + home.homeDirectory = "/home/imnyang"; + + home.packages = [ + nr + nrr + ]; + + home.sessionVariables = { + EDITOR = "nano"; + VISUAL = "nano"; + }; + + programs.fish = { + enable = true; + + shellAliases = { + ".." = "cd .."; + "..." = "cd ../.."; + + ls = "eza"; + ll = "eza -l"; + la = "eza -a"; + lla = "eza -la"; + + rebuild = "sudo nixos-rebuild switch --flake .#hako"; + update = "nix flake update"; + clean = "sudo nix-collect-garbage -d"; + }; + + interactiveShellInit = '' + set -g fish_greeting "" + set -g fish_color_command blue + set -g fish_color_error red + set -g fish_color_param cyan + ''; + + functions = { + fish_prompt = '' + set_color purple + echo -n (whoami) + set_color normal + echo -n "@" + set_color green + echo -n (hostname) + set_color normal + echo -n ":" + set_color blue + echo -n (prompt_pwd) + set_color normal + echo -n " > " + ''; + }; + }; +} diff --git a/hosts/server/hikari/default/secrets/rustfs.yaml b/hosts/server/hikari/default/secrets/rustfs.yaml new file mode 100644 index 0000000..4a70473 --- /dev/null +++ b/hosts/server/hikari/default/secrets/rustfs.yaml @@ -0,0 +1,45 @@ +rustfs: + access-key: ENC[AES256_GCM,data:Cn7OLVdATw==,iv:D4SufuFFUMcX+yvVSoEQewjRKuYn2lTs1q6AD4mxUv4=,tag:ZW39Ss9aH0Yex1jyf29dFA==,type:str] + secret-key: ENC[AES256_GCM,data:cGvzwMB8GImZ7gqNzQ==,iv:R8zKJ7S7pZLvDR0+4NKoq1HGK75XGJU+kR7OZr5By20=,tag:dos2R8yxuXBMkh/0NkPMag==,type:str] +sops: + age: + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBuS1FVMkkvTm9iYzFjU0NB + UFRxRCsxK3FqYVVweTRNcktvOGl6MDdwRmljCllmaFVCZ2hmYmJtdjBqcDlLZTZk + SVl5SE05YnEvK3hkdEVYT3E2WGM5RzgKLS0tIHZlTEtwZmZZRTVWdVJxL1pGRlBt + ZEpCT3JuMXNtN1N2OGZpVFZPYm5HK1UKyGlt3NFaloUMJRNeRVFi8LCSAg6vXBMu + RJbfkCJBrzpHTPxNOKeFgsrgWt3FEmSSNN8180o4jymPyXhHqqOTEw== + -----END AGE ENCRYPTED FILE----- + recipient: age1mgels4hjl7l07gcnt72g86kvhrvd82fha9kuvlp46mpks7unrpmqvy959u + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBFUHlOUExVb0Z2U3FZUXgr + UVc4b0VBZXpxQm11eVN5UTF6MXNnZVBmV2hVCkxXRnFTY1IxWmI2dlJDS0kxU1lx + Rmd3QXZwTWhMRG1ncVhPM1FCK1RkZnMKLS0tIHdZR2VwRzB6UFQzbEpLalhJdk5Z + ZElITjd3U2laaUVIZklRQVJubmcwNXcK7mSlmQF9tG5sPsCxjTXb3qhRvny2rVbS + txx0i7WXyzNbzL/FC6T7vPhsmZMEt0aAQpNOPAF4mayr4zfL7X1QsA== + -----END AGE ENCRYPTED FILE----- + recipient: age1dcvh6q9953es9fvt8rq8rdgcktlt64asn2tf2y3vmyz0gntxzynqg2xgzk + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBJQnFQR0ZUSEZRbzQ5V01j + emZldE9tc2MwM1VSZzRGbGhvaHVTZm43elZnCk14MitpU0hRVzlvK1VSQktmYlFS + bWswd29nTUMycWpoVXkxbGl5TDZjN2MKLS0tIGhOcUw4T1hEdlU3bzY1TjNLcFlq + YjhTK3A2UVlLODZwa3cra0o5bEJ5QTQKgS9sFXhgqWmdqXRpfsN7g9SgFByVUhVq + L0TTu/5PUkAt88KdUQlFUsm1PgaFnfJWPqfkIclmW+RJHaO0fQWBBQ== + -----END AGE ENCRYPTED FILE----- + recipient: age1wnxeqyzqsnylm4vdgzrlyu7k4yev82zuru6nzy72hwvu6htde4gq9wc5vu + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBQb3E4K1d4NHJ2a1kwR3h5 + RWt4T0ppcTVFWjU3NUdPU1krejBqZjZkV0M4Ci9iYUdxd3NDOUlwZ1p2ODJOY1dk + SzE2MWZ5R2xXRFV1bVFpRzhEOWZJV2sKLS0tIEFDRTNnRmZMOVIxeGFGcmQ2aWhP + dTJYbEhlcCt2ZURReVlZWWpSQndiVXcKw+3Y9kIRgCdQGcpl++4llH8cAeQyhT/E + I3Pxi5GXMRMEgGGKom46WT8UzwXWT3tlCYQpPEmFp6OiJeuxUtU2mg== + -----END AGE ENCRYPTED FILE----- + recipient: age1hlld327xfhm44hns9l9j6h4csrl5cl50h2qkhpl3969awgl665fsnxd3zc + lastmodified: "2026-06-09T01:25:36Z" + mac: ENC[AES256_GCM,data:+I6s5nI7FKxolC3dVUToBFU4jULtTjCouKqR+VLT9XNUeZTin258mi0kD5fDhDWpKlC3pEzZ1lTvSOkPb3JX73fvHYjCKbchaW36HgEZi/QF7pQIaZZQUMQZ8ga5KpeUWOvRhJPdbZ/QwKB3+nCAJv7lDMpSLMEDHV2im9sT2e4=,iv:8gMmUef18qK/KIAFojyzVG/n/hOyjVy03aX05/dNukU=,tag:uqn3NSsSDsuyWfkrXvAW1Q==,type:str] + unencrypted_suffix: _unencrypted + version: 3.13.1 diff --git a/hosts/server/hikari/default/services/nextcloud.nix b/hosts/server/hikari/default/services/nextcloud.nix new file mode 100644 index 0000000..8a491b5 --- /dev/null +++ b/hosts/server/hikari/default/services/nextcloud.nix @@ -0,0 +1,133 @@ +{ ... }: + +{ + networking.firewall.allowedTCPPorts = [ + 60300 + 9980 + ]; + + virtualisation.quadlet = { + networks.nextcloud = { }; + + containers = { + nextcloud-db = { + containerConfig = { + image = "postgres:17"; + networks = [ "nextcloud" ]; + + volumes = [ + "/data/nextcloud/db:/var/lib/postgresql/data:Z" + ]; + + environmentFiles = [ + "/data/nextcloud/db.env" + ]; + + exec = "postgres -c listen_addresses='*' -c unix_socket_directories=''"; + }; + + serviceConfig.Restart = "always"; + }; + + nextcloud-redis = { + containerConfig = { + image = "redis:alpine"; + networks = [ "nextcloud" ]; + }; + + serviceConfig.Restart = "always"; + }; + + nextcloud-app = { + containerConfig = { + image = "nextcloud:apache"; + + publishPorts = [ "60300:80" ]; + + networks = [ "nextcloud" ]; + + volumes = [ + "/mnt/snow/Docker/nextcloud/data:/var/www/html:z" + ]; + + # environments로 변경 및 attrset 형식으로 정의 + environments = { + POSTGRES_HOST = "nextcloud-db"; + REDIS_HOST = "nextcloud-redis"; + NEXTCLOUD_OVERWRITEPROTOCOL = "https"; + }; + + environmentFiles = [ + "/data/nextcloud/db.env" + ]; + }; + + unitConfig = { + Requires = [ + "nextcloud-db.service" + "nextcloud-redis.service" + ]; + + After = [ + "nextcloud-db.service" + "nextcloud-redis.service" + ]; + }; + + serviceConfig.Restart = "always"; + }; + + nextcloud-cron = { + containerConfig = { + image = "nextcloud:apache"; + + networks = [ "nextcloud" ]; + + volumes = [ + "/mnt/snow/Docker/nextcloud/data:/var/www/html:z" + ]; + + exec = "/cron.sh"; + }; + + unitConfig = { + Requires = [ + "nextcloud-db.service" + "nextcloud-redis.service" + ]; + + After = [ + "nextcloud-db.service" + "nextcloud-redis.service" + ]; + }; + + serviceConfig.Restart = "always"; + }; + + collabora = { + containerConfig = { + image = "collabora/code:latest"; + + hostname = "collabora"; + + publishPorts = [ "9980:9980" ]; + + addCapabilities = [ "MKNOD" ]; + + podmanArgs = [ + "--privileged" + "--tty" + ]; + + # environments로 변경 및 attrset 형식으로 정의 + environments = { + extra_params = "--o:ssl.enable=false --o:ssl.termination=true"; + }; + }; + + serviceConfig.Restart = "always"; + }; + }; + }; +} diff --git a/hosts/server/hikari/default/services/rustfs.nix b/hosts/server/hikari/default/services/rustfs.nix new file mode 100644 index 0000000..3414a90 --- /dev/null +++ b/hosts/server/hikari/default/services/rustfs.nix @@ -0,0 +1,38 @@ +{ + config, + pkgs, + inputs, + ... +}: +{ + # sops.secrets = { + # "rustfs/access-key" = { + # sopsFile = ../secrets/rustfs.yaml; + # owner = config.services.rustfs.user; + # group = config.services.rustfs.group; + # mode = "0400"; + # restartUnits = [ "rustfs.service" ]; + # }; + + # "rustfs/secret-key" = { + # sopsFile = ../secrets/rustfs.yaml; + # owner = config.services.rustfs.user; + # group = config.services.rustfs.group; + # mode = "0400"; + # restartUnits = [ "rustfs.service" ]; + # }; + # }; + + services.rustfs = { + enable = true; + package = inputs.rustfs.packages.${pkgs.stdenv.hostPlatform.system}.default; + + accessKeyFile = "/etc/secrets/rustfs-access-key"; + secretKeyFile = "/etc/secrets/rustfs-secret-key"; + + volumes = "/mnt/snow/rustfs"; + address = ":9000"; + consoleAddress = ":9001"; + consoleEnable = true; + }; +} diff --git a/hosts/server/hikari/hako/.sops.yaml b/hosts/server/hikari/hako/.sops.yaml new file mode 100644 index 0000000..49f8ba8 --- /dev/null +++ b/hosts/server/hikari/hako/.sops.yaml @@ -0,0 +1,5 @@ +creation_rules: + - path_regex: secrets/.*\.ya?ml$ + age: + - age1mgels4hjl7l07gcnt72g86kvhrvd82fha9kuvlp46mpks7unrpmqvy959u # mizuki + - age1dcvh6q9953es9fvt8rq8rdgcktlt64asn2tf2y3vmyz0gntxzynqg2xgzk # hako diff --git a/hosts/server/hikari/hako/configuration.nix b/hosts/server/hikari/hako/configuration.nix new file mode 100644 index 0000000..cc68237 --- /dev/null +++ b/hosts/server/hikari/hako/configuration.nix @@ -0,0 +1,43 @@ +{ pkgs, inputs, ... }: +{ + imports = [ + ./hardware-configuration.nix + "${inputs.self}/modules/nixos/base" + "${inputs.self}/modules/nixos/features/boot.nix" + "${inputs.self}/modules/nixos/features/ssh.nix" + "${inputs.self}/modules/nixos/features/docker.nix" + ]; + + # 1. 크론 설정 + services.cron = { + enable = true; + systemCronJobs = [ + "0 1 * * * imnyang printf '\\n%s : ' \"$(date)\" >> /home/imnyang/codelounge.log && /home/imnyang/codelounge.sh >> /home/imnyang/codelounge.log" + ]; + }; + + services.qemuGuest.enable = true; + + # 2. 사용자 SSH 키 등록 + users.users.imnyang.openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOHP3Z+AYrRh9f8TYyqChKfeyNm3lOe0F75AwRHTTaxD imnyang@kazusa" + ]; + + environment.systemPackages = with pkgs; [ + eza + neovim + nil + nixd + ]; + + programs.git.config = { + safe.directory = "*"; + }; + + nix.settings.require-sigs = false; + + networking.firewall.enable = false; + + networking.hostName = "hako"; + system.stateVersion = "26.05"; +} diff --git a/hosts/server/hikari/hako/default.nix b/hosts/server/hikari/hako/default.nix new file mode 100644 index 0000000..bf4cf57 --- /dev/null +++ b/hosts/server/hikari/hako/default.nix @@ -0,0 +1,32 @@ +{ + inputs, + overlays, +}: +let + inherit (inputs) nixpkgs home-manager sops-nix; +in +nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + sops-nix.nixosModules.sops + ./services/forgejo.nix + ./services/immich.nix + ./services/attic.nix + ./services/postgresql.nix + ./services/nc.nix + + ./configuration.nix + ./hardware-configuration.nix + home-manager.nixosModules.home-manager + { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + home-manager.extraSpecialArgs = { inherit inputs; }; + home-manager.users.imnyang = import ./home.nix; + } + ]; + specialArgs = { + inherit inputs; + inherit overlays; + }; +} diff --git a/hosts/server/hikari/hako/hardware-configuration.nix b/hosts/server/hikari/hako/hardware-configuration.nix new file mode 100644 index 0000000..2b08638 --- /dev/null +++ b/hosts/server/hikari/hako/hardware-configuration.nix @@ -0,0 +1,51 @@ +# Do not modify this file! It was generated by nixos-generate-config +# and may be overwritten by future invocations. Please make changes +# to configuration.nix instead. +{ lib, modulesPath, ... }: + +{ + imports = [ + (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ + "uhci_hcd" + "ehci_pci" + "ahci" + "virtio_pci" + "virtio_scsi" + "sd_mod" + "sr_mod" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = { + device = "/dev/disk/by-uuid/d65b2c3a-c630-4a07-bcf3-ec1b728129c0"; + fsType = "ext4"; + }; + + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/67DC-8A41"; + fsType = "vfat"; + options = [ + "fmask=0077" + "dmask=0077" + ]; + }; + + fileSystems."/mnt/data" = { + device = "/dev/disk/by-uuid/edc0420b-8bec-438d-856d-bb345238e735"; + fsType = "ext4"; + }; + + fileSystems."/mnt/attic" = { + device = "/dev/disk/by-uuid/f45e0247-d2eb-4150-8116-e8d257c01aac"; + fsType = "ext4"; + }; + + swapDevices = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; +} diff --git a/hosts/server/hikari/hako/home.nix b/hosts/server/hikari/hako/home.nix new file mode 100644 index 0000000..7d9d39d --- /dev/null +++ b/hosts/server/hikari/hako/home.nix @@ -0,0 +1,66 @@ +{ + pkgs, + inputs, + ... +}: +let + nr = import "${inputs.self}/modules/nixos/features/packages/nr.nix" { inherit pkgs; }; + nrr = import "${inputs.self}/modules/nixos/features/packages/nrr.nix" { inherit pkgs; }; +in +{ + home.stateVersion = "26.05"; + home.username = "imnyang"; + home.homeDirectory = "/home/imnyang"; + + home.packages = [ + nr + nrr + ]; + + home.sessionVariables = { + EDITOR = "nano"; + VISUAL = "nano"; + }; + + programs.fish = { + enable = true; + + shellAliases = { + ".." = "cd .."; + "..." = "cd ../.."; + + ls = "eza"; + ll = "eza -l"; + la = "eza -a"; + lla = "eza -la"; + + rebuild = "sudo nixos-rebuild switch --flake .#hako"; + update = "nix flake update"; + clean = "sudo nix-collect-garbage -d"; + }; + + interactiveShellInit = '' + set -g fish_greeting "" + set -g fish_color_command blue + set -g fish_color_error red + set -g fish_color_param cyan + ''; + + functions = { + fish_prompt = '' + set_color purple + echo -n (whoami) + set_color normal + echo -n "@" + set_color green + echo -n (hostname) + set_color normal + echo -n ":" + set_color blue + echo -n (prompt_pwd) + set_color normal + echo -n " > " + ''; + }; + }; +} diff --git a/hosts/server/hikari/hako/secrets/forgejo.yaml b/hosts/server/hikari/hako/secrets/forgejo.yaml new file mode 100644 index 0000000..79fb332 --- /dev/null +++ b/hosts/server/hikari/hako/secrets/forgejo.yaml @@ -0,0 +1,29 @@ +forgejo: + server_lfs_jwt_secret: ENC[AES256_GCM,data:mBK+mUvGTlSPLEifBahWuKMWMAlMNXmgA5jdGl+RElA4+msogvHB1g7V1g==,iv:YDc7ZgDPP0st0hYLJGbsapkVAG2L372AXFGwax9y+hc=,tag:4rfv0tfvgk/octiBkFnD6Q==,type:str] + security_internal_token: ENC[AES256_GCM,data:zmEnyWTmZrcUQTu7zu/QaVGzMzNvzkWYpRsCygD/SKzQe+kHG/FGr8rPwUQGIoUvdc2FcAykfsFZtnBwDgIeEonG+jdGYF41yIrh18hAXG00jn+K5fhq9x2IAGJz6qtvM7usiw2aCLLF,iv:DkkKZl9KKbtOKk1OHxoQmBMhN91NGHKAijcaJVxHXgM=,tag:FJkWGty/yAUJQaZB6RNcuQ==,type:str] + oauth2_jwt_secret: ENC[AES256_GCM,data:SpTNvHaxR1Ai8hdoTVcl3HVm5ZwA4oNoXUD5Cw8J5cy63ZLOZMX6tCBLCg==,iv:cm0uqiaizsEqPWD6b1cusME6LGXhSEhmd2bcdf/kxUM=,tag:iYpIDsIRd6ahJdL2RgjPTw==,type:str] + mailer_passwd: ENC[AES256_GCM,data:FXQN7xvjtR2MJGp/DkiF6jyglztjZ7vKxmHB7YWux0E=,iv:G5DSbqeKykq1HjQfWwHdLeS3bHkCbjsgH57Nfaaev84=,tag:8Q1RC3f8wNjUPm1nL+J4IQ==,type:str] +sops: + age: + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBDQ1hzM3BEUEdqaUlnckhK + VXhHSzI1SmxBUCsxbU1FZmZhTkppa2xCbzNnCjhjc05oTFdnbjByR0N6eklpZTVh + dXNid290ZWRqNStKdkhiczdaQ1FaZlUKLS0tIEkvRmN5UTQ0dXBRRDB3YkR5UklL + OUh4NVZER0FOcGtZMksrdzk2c2ZHVHcKgkrUSWjK2+44+svbVSzHn31QPieTtXb2 + 7/A689V4CgGO+eoECxaKepEbWmXb2iCuLa2fNhUQIv1veKq/ga1aNA== + -----END AGE ENCRYPTED FILE----- + recipient: age1mgels4hjl7l07gcnt72g86kvhrvd82fha9kuvlp46mpks7unrpmqvy959u + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBVbjNtWjBRVFFEdGdKbXBC + RWo1UngvVEpqNW92MGlHZHI4dG9pWGdaS1VNCjhzakYyNUwzaWM3WjY4cHNvUW9t + N3hsTlpkV3BEQXZSSGh4MGlKVkNuWDAKLS0tIGFDcFNuQlBnaFN6SWs2K1dDVlVW + M1Z4VFdsWlhOTEZxR256a0xqa1dVcUkKrL52dR1o186VXcxp3ap5cyZUh5pjgQPC + TmBnn6qSneJHztKUBTz5PBsesdDrNX4m/UYahb7feRO70dQvGxeo0A== + -----END AGE ENCRYPTED FILE----- + recipient: age1dcvh6q9953es9fvt8rq8rdgcktlt64asn2tf2y3vmyz0gntxzynqg2xgzk + lastmodified: "2026-05-25T05:46:33Z" + mac: ENC[AES256_GCM,data:GY6EpM2BwOHFHtOGuQ6qHepH94xhEMnQDxshl+aGhIVGCi+34YW6WjFtBcFFLcmxSuMbEx8w2jK0T6PE7cyAwnphkz/G0qx2AAn836SN0wlfyY3Ni1czcdcuc9s2QdlBc9VhVU8s70fnso2tZxQsyM5wplgparJAJfxNycLFr9g=,iv:sHxJZm6waB+PW76rs6H26ffelsty1KAQFzwgbLv7Qls=,tag:Ofir+9DXvlSU/RtG4ivNCQ==,type:str] + unencrypted_suffix: _unencrypted + version: 3.13.1 diff --git a/hosts/server/hikari/hako/secrets/immich.yaml b/hosts/server/hikari/hako/secrets/immich.yaml new file mode 100644 index 0000000..6c79169 --- /dev/null +++ b/hosts/server/hikari/hako/secrets/immich.yaml @@ -0,0 +1,28 @@ +immich: + oauth2: + client-id: ENC[AES256_GCM,data:HY69lAGt3g7JqRG1EzmWXZpSCGSPwm2vqdIU2RkhXdon3C4JeXb9fw==,iv:Ew2r4kOx6cP2uZD6btyPmFpT0SOkJFM2WeT/fq6zaLc=,tag:aZimoy63KoR2hwRQUOGPRw==,type:str] + client-secret: ENC[AES256_GCM,data:U9YE9DnsNbLU2bTZWRWjEWFCCl0b2GS7IWfg2ooGrbmSi/A9DFzGSxvUdJQHKVbsX3bFCDd55citwJRVUQDiFSNSX78npQSzRJ8Jj9VSYOmHsO376I/Wm8sLQfvApcvltwaNV1rzfQyKGaBqGkFb58AbG55h/6bObqWWOl6+g5I=,iv:/odWOJedazBbMYsNwNVLPbBdAJb8f73brz+PUpaNwDg=,tag:VdY5zAHbPkYBRrmZyGSSTg==,type:str] +sops: + age: + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBJOXo0RkpUekJZN3lhaU1S + ZWNDaUdud0EzbUhIbU9lYVRyQ3pQazRrMlZRCjdPMDZDNVpST3p2VHJ0Tmg2WUZP + eWF4R0dBaW1zRmJNdjVaVWV3UjgvL2MKLS0tIFJQQ1pMQzB5aU9wNmYxYktJdHU5 + NWV6Q0NuWUwrMTZ5RE9PV3ZVMTkvK00KJaPJojaZGx8NNfgxO4Q6AUbbCRGxEHAz + QX4zycDizXnL3kWmF1T66Cew6EuhHZSl5ZYFYUilHjq8r0lx2RuCOg== + -----END AGE ENCRYPTED FILE----- + recipient: age1mgels4hjl7l07gcnt72g86kvhrvd82fha9kuvlp46mpks7unrpmqvy959u + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBvTjFKQlZVUCtNLzUzUGRO + TjlDYjQ3dmxEd0ZUcGZpTk5wU3kzWXVpRUY4CnI1bjBubU91dWJmSjlUOFlyYkNm + MkxIZTZ5SmFuT1ZqT3dkYVZQcmFWZk0KLS0tIGhPYzZpNEkwcTJzQUpwdndNNmlN + a05vWkZLeEpmaWpka1Z6RXRUdFRRZ3cKQBfF4IYpt5RO9+XmooTI58cSmkqwnQmN + aSt73yBzGVPJulggcYuDsy/k8lfPhPseKVvuR8p/jzwKG6iNGNm86g== + -----END AGE ENCRYPTED FILE----- + recipient: age1dcvh6q9953es9fvt8rq8rdgcktlt64asn2tf2y3vmyz0gntxzynqg2xgzk + lastmodified: "2026-04-02T15:08:04Z" + mac: ENC[AES256_GCM,data:uDCTiO0f3Ogj+dMNGoFIPptCBgLbN0goh/KDiLqCJXvLVkNCqpJYK0V46CmwQnSNyrth2jEQhnx0TBF2JSKfyU+UNpgC9zcLsuUznYQiBl+s2cT2nbApcLgJBSxWcvCpEEGqUp71jw8ajaUwjaLGdHePNsn4K3rAOL0j1Yythxo=,iv:bx3ctA+6hEeq0BHJqf4BQBJhihh3uGlS7NwalmXJgXg=,tag:sM4wAT0qfUZMI7gE0b++3g==,type:str] + unencrypted_suffix: _unencrypted + version: 3.12.2 diff --git a/hosts/server/hikari/hako/secrets/nc.yaml b/hosts/server/hikari/hako/secrets/nc.yaml new file mode 100644 index 0000000..8995915 --- /dev/null +++ b/hosts/server/hikari/hako/secrets/nc.yaml @@ -0,0 +1,26 @@ +google: + api-key: ENC[AES256_GCM,data:1BdTd7JyoeZ/U/6kWKAcgYeRokjR/mD0OLrmJrp7fXTE6rI4YT/RdQZauAA+xiGLBELdVCo=,iv:s9ms0pr7iwQW7HxhlpQSHCRc9pWlbnY3MH6iKxnoFYg=,tag:uWTmkMWikoFVGCeyG6fOrQ==,type:str] +sops: + age: + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB0U1FuMjg4Q0llaU1yUCtX + SG5aUnVoUGRaRG9WSGNKQlFmNFdtS1JOdDFVCjlDbHVnUWlCWWtQcXJjSExTL3JT + cHM3RTRNK1BVZzdXZ1g0bFdYcnltU2cKLS0tIHpHQmRqTndLNUJWYnR4TVVHOGJ0 + ZExCNlphODcrbGdxa0tYNGxQS1lJNDQKes+ZdaWVPmAHxsomvBhGSha58T0vOTvN + T14s3k+nAtyOq0oJ71AuzZVsWS/1ubMFvtOAnVTsCae1BZ5AAGTU0A== + -----END AGE ENCRYPTED FILE----- + recipient: age1mgels4hjl7l07gcnt72g86kvhrvd82fha9kuvlp46mpks7unrpmqvy959u + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBMQXNaR0dldTBMa3YrK1ZE + K1NhclpZblJzdVFGU1hLVHRtSFR1bmhBeFZjCmRyNXNRVGxrYUZEWGpQR2gycHd2 + TGJUVmpVTjcvaFBtZFpBTjNqVHVTcHMKLS0tIDUrYVI4LytnN0tCM3RZdzMwekFi + NnJkRGc5VUd3WUNXODRLZ2dkbWZ0QlUKPkU0P/fuGIVRwGgdwkxxEoeXTM7BBL7m + 29fTZi7bgVajYoaA52CIjGFYnzt6phqlvjMC6PFlGG23ifaYEKlgQQ== + -----END AGE ENCRYPTED FILE----- + recipient: age1dcvh6q9953es9fvt8rq8rdgcktlt64asn2tf2y3vmyz0gntxzynqg2xgzk + lastmodified: "2026-06-25T09:28:44Z" + mac: ENC[AES256_GCM,data:uZWZQ4u5gqfTnNp9uVqfXOqwAgaTL4hT5a/A5d+o0D6MCpM/f80hnaWBynFryI1NlPUFjQ6gyGBTFxkEeUnhB/pQit6XBE0Ex0F+UKy5U8QAcPhN2/5if/Upd9l3yiLaul+kH49FkkHwRhpA++GXFUr66stsHYPMFXM2vQAJQgQ=,iv:AwE69cX+jmrUz/pJqAIsS9Vhl2rd947xAViQYz6gkSA=,tag:qg4jpYHTYjBkt9vfER+YkA==,type:str] + unencrypted_suffix: _unencrypted + version: 3.13.1 diff --git a/hosts/server/hikari/hako/services/attic.nix b/hosts/server/hikari/hako/services/attic.nix new file mode 100644 index 0000000..4ae3d7e --- /dev/null +++ b/hosts/server/hikari/hako/services/attic.nix @@ -0,0 +1,21 @@ +{ + services.atticd = { + enable = true; + + # Replace with absolute path to your environment file + environmentFile = "/etc/atticd.env"; + + settings = { + listen = "[::]:8080"; + + jwt = { }; + + database.url = "postgresql:///attic"; + + storage = { + type = "local"; + path = "/mnt/attic"; + }; + }; + }; +} diff --git a/hosts/server/hikari/hako/services/forgejo.nix b/hosts/server/hikari/hako/services/forgejo.nix new file mode 100644 index 0000000..de4a561 --- /dev/null +++ b/hosts/server/hikari/hako/services/forgejo.nix @@ -0,0 +1,130 @@ +{ + config, + lib, + pkgs, + ... +}: + +{ + sops = { + defaultSopsFile = ../secrets/forgejo.yaml; + validateSopsFiles = false; + age = { + keyFile = "/var/lib/sops-nix/key.txt"; + generateKey = true; + }; + secrets = { + "forgejo/server_lfs_jwt_secret" = { + owner = "forgejo"; + group = "forgejo"; + restartUnits = [ "forgejo.service" ]; + }; + "forgejo/security_internal_token" = { + owner = "forgejo"; + group = "forgejo"; + restartUnits = [ "forgejo.service" ]; + }; + "forgejo/oauth2_jwt_secret" = { + owner = "forgejo"; + group = "forgejo"; + restartUnits = [ "forgejo.service" ]; + }; + "forgejo/mailer_passwd" = { + owner = "forgejo"; + group = "forgejo"; + restartUnits = [ "forgejo.service" ]; + }; + }; + }; + + services.forgejo = { + enable = true; + package = pkgs.forgejo; + + database = { + type = "postgres"; + createDatabase = true; + host = "/run/postgresql/"; + name = "forgejo"; + user = "forgejo"; + }; + + settings = { + DEFAULT = { + APP_NAME = "git.mizuki.guru"; + APP_SLOGAN = "with 🎀"; + RUN_MODE = "prod"; + }; + + federation = { + ENABLED = true; + }; + + server = { + DOMAIN = "git.mizuki.guru"; + SSH_DOMAIN = "mizuki.guru"; + HTTP_PORT = 3000; + ROOT_URL = "https://git.mizuki.guru/"; + DISABLE_SSH = false; + SSH_PORT = 22; + LFS_START_SERVER = true; + OFFLINE_MODE = false; + }; + + security = { + INSTALL_LOCK = true; + PASSWORD_HASH_ALGO = "pbkdf2_hi"; + }; + + service = { + REGISTER_EMAIL_CONFIRM = true; + ENABLE_NOTIFY_MAIL = true; + DISABLE_REGISTRATION = false; + ALLOW_ONLY_EXTERNAL_REGISTRATION = true; + ENABLE_CAPTCHA = false; + REQUIRE_SIGNIN_VIEW = false; + DEFAULT_KEEP_EMAIL_PRIVATE = false; + DEFAULT_ALLOW_CREATE_ORGANIZATION = true; + DEFAULT_ENABLE_TIMETRACKING = true; + NO_REPLY_ADDRESS = "noreply.relay.imnya.ng"; + }; + + mailer = { + ENABLED = true; + SMTP_ADDR = "mail.mizuki.guru"; + SMTP_PORT = 587; + FROM = "systemmail@mizuki.guru"; + USER = "systemmail@mizuki.guru"; + }; + + oauth2 = { + ENABLED = true; + }; + + actions = { + ENABLED = true; + }; + + ui = { + THEMES = "dark,light,auto,forgejo-auto,forgejo-light,forgejo-dark"; + DEFAULT_THEME = "auto"; + }; + + repository = { + ROOT = "/var/lib/forgejo/repositories"; + }; + "repository.pull-request".DEFAULT_MERGE_STYLE = "merge"; + "repository.signing".DEFAULT_TRUST_MODEL = "committer"; + "cron.update_checker".ENABLED = true; + session.PROVIDER = "file"; + oauth2_client.ENABLE_AUTO_REGISTRATION = true; + }; + + secrets = { + server.LFS_JWT_SECRET = lib.mkForce config.sops.secrets."forgejo/server_lfs_jwt_secret".path; + security.INTERNAL_TOKEN = lib.mkForce config.sops.secrets."forgejo/security_internal_token".path; + oauth2.JWT_SECRET = lib.mkForce config.sops.secrets."forgejo/oauth2_jwt_secret".path; + mailer.PASSWD = lib.mkForce config.sops.secrets."forgejo/mailer_passwd".path; + }; + }; +} diff --git a/hosts/server/hikari/hako/services/immich.nix b/hosts/server/hikari/hako/services/immich.nix new file mode 100644 index 0000000..a4cdce1 --- /dev/null +++ b/hosts/server/hikari/hako/services/immich.nix @@ -0,0 +1,37 @@ +{ config, ... }: +let + immichSecret = key: { + sopsFile = ../secrets/immich.yaml; + inherit key; + owner = "immich"; + }; +in +{ + sops.secrets."immich/oauth2/client-id" = immichSecret "immich/oauth2/client-id"; + sops.secrets."immich/oauth2/client-secret" = immichSecret "immich/oauth2/client-secret"; + + services.immich = { + enable = true; + host = "0.0.0.0"; + port = 10040; + + mediaLocation = "/mnt/data/immich/media"; + openFirewall = true; + machine-learning.enable = false; + + settings = { + server.externalDomain = "https://i.mizuki.guru"; + machineLearning = { + enabled = false; + }; + oauth = { + enabled = true; + issuerUrl = "https://auth.mizuki.guru/application/o/immich/.well-known/openid-configuration"; + clientId._secret = config.sops.secrets."immich/oauth2/client-id".path; + clientSecret._secret = config.sops.secrets."immich/oauth2/client-secret".path; + scope = "openid email profile"; + buttonText = "Login with mizuki"; + }; + }; + }; +} diff --git a/hosts/server/hikari/hako/services/nc.nix b/hosts/server/hikari/hako/services/nc.nix new file mode 100644 index 0000000..f6b2d92 --- /dev/null +++ b/hosts/server/hikari/hako/services/nc.nix @@ -0,0 +1,63 @@ +{ + pkgs, + inputs, + config, + ... +}: + +let + ncSecret = key: { + sopsFile = ../secrets/nc.yaml; + inherit key; + owner = "mizuki-nc"; + group = "mizuki-nc"; + mode = "0400"; + }; +in +{ + users.users.mizuki-nc = { + isSystemUser = true; + group = "mizuki-nc"; + }; + + users.groups.mizuki-nc = { }; + + sops.secrets."google/api-key" = ncSecret "google/api-key"; + + systemd.services.mizuki-nc = { + description = "mizuki.guru"; + wantedBy = [ "multi-user.target" ]; + + preStart = '' + set -eu + umask 077 + + rm -f /var/lib/mizuki-nc/config.toml + + cat > /tmp/mizuki-nc-config.toml <> /home/imnyang/codelounge.log && /home/imnyang/codelounge.sh >> /home/imnyang/codelounge.log" + ]; + }; + services.netbird.enable = true; + + # 3. 사용자 SSH 키 등록 + users.users.imnyang.openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOHP3Z+AYrRh9f8TYyqChKfeyNm3lOe0F75AwRHTTaxD imnyang@kazusa" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIrpjEYOBx7LTGb7QsPrmPBboqyTUNm/e+4+yqWruljv imnyang@natsu" + ]; + + environment.systemPackages = with pkgs; [ + eza + neovim + nil + nixd + bun + stdenv.cc.cc.lib + ]; + + programs.nix-ld.enable = true; + + systemd.services.blog = { + description = "blog.imnya.ng"; + after = [ "network-online.target" ]; + wants = [ "network-online.target" ]; + wantedBy = [ "multi-user.target" ]; + + serviceConfig = { + Type = "simple"; + User = "imnyang"; + Environment = [ + "LD_LIBRARY_PATH=${pkgs.stdenv.cc.cc.lib}/lib" + ]; + WorkingDirectory = "/home/imnyang/git/imnyang/blog"; + ExecStart = "${pkgs.bun}/bin/bun run preview"; + Restart = "always"; + RestartSec = 5; + }; + + path = [ pkgs.bun ]; + }; + + services.qemuGuest.enable = true; + + boot.kernel.sysctl = { + "net.ipv4.ip_forward" = 1; + "net.ipv6.conf.all.forwarding" = 1; + }; + + programs.git.config = { + safe.directory = "*"; + }; + + networking.firewall.allowedTCPPorts = [ + 22 + 80 + 443 + ]; + + networking.hostName = "natsu"; + system.stateVersion = "26.05"; +} diff --git a/hosts/server/natsu/default.nix b/hosts/server/natsu/default.nix new file mode 100644 index 0000000..d37a986 --- /dev/null +++ b/hosts/server/natsu/default.nix @@ -0,0 +1,30 @@ +{ + inputs, + overlays, +}: +let + inherit (inputs) nixpkgs home-manager sops-nix; +in +nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + sops-nix.nixosModules.sops + # ./services/attic.nix + ./services/caddy.nix + ./services/forgejo-runner.nix + # ./services/harmonia.nix + ./configuration.nix + ./hardware-configuration.nix + home-manager.nixosModules.home-manager + { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + home-manager.extraSpecialArgs = { inherit inputs; }; + home-manager.users.imnyang = import ./home.nix; + } + ]; + specialArgs = { + inherit inputs; + inherit overlays; + }; +} diff --git a/hosts/server/natsu/hardware-configuration.nix b/hosts/server/natsu/hardware-configuration.nix new file mode 100644 index 0000000..85c315f --- /dev/null +++ b/hosts/server/natsu/hardware-configuration.nix @@ -0,0 +1,31 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ "xhci_pci" "virtio_pci" "virtio_scsi" "usbhid" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/ffe787e4-f39c-4c9b-b2f5-273386198307"; + fsType = "ext4"; + }; + + fileSystems."/boot" = + { device = "/dev/disk/by-uuid/E854-0DD3"; + fsType = "vfat"; + options = [ "fmask=0022" "dmask=0022" ]; + }; + + swapDevices = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "aarch64-linux"; +} + diff --git a/hosts/server/natsu/home.nix b/hosts/server/natsu/home.nix new file mode 100644 index 0000000..f371120 --- /dev/null +++ b/hosts/server/natsu/home.nix @@ -0,0 +1,80 @@ +{ + config, + pkgs, + inputs, + ... +}: +let + nr = import "${inputs.self}/modules/nixos/features/packages/nr.nix" { inherit pkgs; }; + nrr = import "${inputs.self}/modules/nixos/features/packages/nrr.nix" { inherit pkgs; }; +in +{ + home.stateVersion = "26.05"; + home.username = "imnyang"; + home.homeDirectory = "/home/imnyang"; + + home.packages = [ + nr + nrr + ]; + + home.sessionVariables = { + EDITOR = "nano"; + VISUAL = "nano"; + }; + + programs.fish = { + enable = true; + + shellAliases = { + # 디렉토리 네비게이션 + ".." = "cd .."; + "..." = "cd ../.."; + + # ls 별칭 + ls = "eza"; + ll = "eza -l"; + la = "eza -a"; + lla = "eza -la"; + + # NixOS 관련 + rebuild = "sudo nixos-rebuild switch --flake .#natsu"; + update = "nix flake update"; + clean = "sudo nix-collect-garbage -d"; + }; + interactiveShellInit = '' + set -g fish_greeting "" + set -g fish_color_command blue + set -g fish_color_error red + set -g fish_color_param cyan + ''; + }; + + programs.starship = { + enable = true; + settings = { + format = "$username@$hostname:$directory$character"; + add_newline = false; + username = { + style_user = "purple"; + style_root = "purple"; + format = "[$user]($style)"; + show_always = true; + }; + hostname = { + style = "green"; + format = "[$hostname]($style)"; + ssh_only = false; + }; + directory = { + style = "blue"; + format = "[$path]($style)"; + truncation_length = 3; + }; + character = { + success_symbol = " >"; + error_symbol = " >"; + }; + }; + }; +} diff --git a/hosts/server/natsu/secrets/forgejo-runner.yaml b/hosts/server/natsu/secrets/forgejo-runner.yaml new file mode 100644 index 0000000..5de50bc --- /dev/null +++ b/hosts/server/natsu/secrets/forgejo-runner.yaml @@ -0,0 +1,35 @@ +forgejo-runner: + token: ENC[AES256_GCM,data:NBOcn5Z99hyQEHotUuVOwvlOqd/lKrXy4pUSobbmPSnVB5yAzTdUv5vv+J9z27z4wg==,iv:C9QBd+Kw2BcX+LkTwuRHpl/G6fw8iGWJPIWDvL8lcKU=,tag:2ZRQzx2P6THlpuDDdpuZgw==,type:str] +sops: + age: + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBLNzVoeHM2LzRYdGp5Snlj + UUlKNThlczFZcFJKMXpJSG42eHVLbjFsamxNCkZiaGNJRFA4bmZHT0g4ZytjZEJY + SHhWblNOa2ZGUWtJZzZLYi9RTjJjcW8KLS0tIHRBV0Z6bEdybUppSHpGMHBsN1A2 + ZitWOTJsUHlvUXp3NEtUK0Jwc1VSU1EK9tZNPBKuY9G0vsDP0RMA/W2xBrN5LBj1 + 0j9N309gyFNqCuR3ZEpoarAx6rpD1Q8wQYhhZQw+z7h2+eGPNp9Qvw== + -----END AGE ENCRYPTED FILE----- + recipient: age10kkqzxkxdkr9322fd536gcs43xqvdw609ffpc4vqqf3f77tzmvlq45q55s + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB1VDI1L0lzZHVTMHNaRTZS + Y3prZnpNMFEwL2dPdlZreGRjRzNLUGFFZEVNCndML3BHKy9EaGpqREVlQVJCdkRC + MXlMeW5sTXZzUE83d2FtbW5ybHh5dzAKLS0tIDVKdTNxdC9yRCtvQmhNbzhtdFA4 + OFJtaG0rcHFPaHJUVjNKckl5UGpDSm8K1cyMiVEVir4uaFJuwQkpcbLmXet4txX+ + 9QrM+WQr73JfoIirHZhZLM0aAXQDwXG791N6iu2x/Q9BbbqLT5c73A== + -----END AGE ENCRYPTED FILE----- + recipient: age1dcvh6q9953es9fvt8rq8rdgcktlt64asn2tf2y3vmyz0gntxzynqg2xgzk + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSArTzJNUkZWVCtQNVpyeEpj + TG44TEppaXkrR2M4K3Y2TEVFWHlKWDYwaFY0CmxNN3Awb0wzUHo0Q21yUERBUXBz + WXYzL0VHcnQxa3UwS3hMRzM0cndtUjAKLS0tIERjaDhZYzlJWmZ6R09Ub0NmTytT + QjZxRUJGU01XRCs5aGZVUElTQ2wxTUEKhnM25DGalV+mfPp8FD40x25Eq5/XudPn + jBWu84zEtL8Ja9XECKaXJiP7oi1YaX8+BV8BdlIfDGR9ceiZRIhlrA== + -----END AGE ENCRYPTED FILE----- + recipient: age1p0hw9lwk33x5w83a4gkjva325leq5h0pgeglhcwm4c9kju4qtu4ss7qppr + lastmodified: "2026-05-28T02:55:30Z" + mac: ENC[AES256_GCM,data:DSY6wQyYBBWcA9aqZkFVJ7JyvFTvXm3r6Zu4xE0dStBgyv/0O5l0pEmekKlYuMWXd3VmAWhH7VCsVN7RyeoLpimm97MfedKIfd/wVISuBy0SA2q3frfwbuith6yfXRqmsGNzG7ivnZ146w8uWGf5RCef1m2Nl9QPeai7dUcB/3c=,iv:XPV8gTSWJzXoOj5bqa+R23deWD2GUaQp+w2b9ThG6V4=,tag:BLWeaRbfYjV8fzieemVBfg==,type:str] + unencrypted_suffix: _unencrypted + version: 3.13.1 diff --git a/hosts/server/natsu/services/caddy.nix b/hosts/server/natsu/services/caddy.nix new file mode 100644 index 0000000..5449a8f --- /dev/null +++ b/hosts/server/natsu/services/caddy.nix @@ -0,0 +1,122 @@ +{ pkgs, ... }: + +{ + services.caddy = { + enable = true; + virtualHosts."http://natsu.icn.mizuki.guru".extraConfig = '' + respond "우응" 200 + ''; + virtualHosts."https://file.mizuki.guru".extraConfig = '' + reverse_proxy 10.11.8.112 { + header_up Host {host} + header_up X-Real-IP {remote_host} + header_up X-Forwarded-For {remote_host} + } + ''; + virtualHosts."http://file.mizuki.guru".extraConfig = '' + reverse_proxy 10.11.8.112 { + header_up Host {host} + header_up X-Real-IP {remote_host} + header_up X-Forwarded-For {remote_host} + } + ''; + + virtualHosts."auth.mizuki.guru".extraConfig = '' + reverse_proxy 10.11.8.102:9080 + ''; + + virtualHosts."plutos.dazzle.st".extraConfig = '' + reverse_proxy epc.hikari.mizuki.arpa:3000 + ''; + + virtualHosts."event.dazzle.st".extraConfig = '' + reverse_proxy 10.11.8.102:9794 + ''; + + virtualHosts."pve.hikari.icn.mizuki.guru".extraConfig = '' + reverse_proxy https://10.11.8.100:8006 { + header_up X-Real-Ip {remote_host} + header_up X-Http-Version {http.request.proto} + transport http { + tls_insecure_skip_verify + } + } + ''; + + virtualHosts."cockpit.hikari.icn.mizuki.guru".extraConfig = '' + reverse_proxy https://10.11.8.100:9090 { + header_up X-Real-Ip {remote_host} + header_up X-Http-Version {http.request.proto} + transport http { + tls_insecure_skip_verify + } + } + ''; + + virtualHosts."cache.mizuki.guru".extraConfig = '' + reverse_proxy 127.0.0.1:5000 + ''; + + virtualHosts."paste.mizuki.guru".extraConfig = '' + reverse_proxy 10.11.8.102:11108 + ''; + virtualHosts."komodo.mizuki.guru".extraConfig = '' + reverse_proxy 10.11.8.102:9120 + ''; + + virtualHosts."ena.mizuki.guru".extraConfig = '' + basic_auth { + imnyang $2a$10$zA83XKt84pcXiwfkuvNmKOpQ5Cw0IP6m/.1AX0ahkVQaPOzrmFlxm + } + reverse_proxy 10.20.31.103:3000 + ''; + + virtualHosts."akiyama.mizuki.guru".extraConfig = '' + rewrite / /index.avif + root * /var/static/akiyama.mizuki.guru + file_server + ''; + + virtualHosts."chef.mizuki.guru".extraConfig = '' + root * /var/static/chef.mizuki.guru + rewrite / /CyberChef_v10.22.1.html + file_server { + precompressed br gzip + } + header { + Cache-Control "public, max-age=31536000" + } + ''; + + virtualHosts."blog.imnya.ng".extraConfig = '' + reverse_proxy 127.0.0.1:4321 + ''; + virtualHosts."netbird.mizuki.guru".extraConfig = '' + # Native gRPC (needs HTTP/2 cleartext to backend) + @grpc header Content-Type application/grpc* + reverse_proxy @grpc h2c://127.0.0.1:8081 + + # Combined server paths (relay, signal, management, OAuth2) + @backend path /relay* /ws-proxy/* /api/* /oauth2/* + reverse_proxy @backend 127.0.0.1:8081 + + # Dashboard (everything else) + reverse_proxy /* 127.0.0.1:8080 + ''; + + package = pkgs.caddy.withPlugins { + plugins = [ + "github.com/caddy-dns/cloudflare@v0.2.2" + "github.com/aksdb/caddy-cgi/v2@v2.2.6" + "github.com/shift72/caddy-geo-ip@v0.6.0" + "github.com/lolPants/caddy-requestid@v1.1.2" + "github.com/WeidiDeng/caddy-cloudflare-ip@v0.0.0-20231130002422-f53b62aa13cb" + "github.com/caddyserver/ntlm-transport@v0.1.2" + "github.com/ueffel/caddy-brotli@v1.6.0" + "github.com/RussellLuo/caddy-ext/ratelimit@v0.3.0" + "github.com/neodyme-labs/user_agent_parse@v0.0.1" + ]; + hash = "sha256-n0LkDBE3JB3zrGYND0EGrKXC+CT0SzRiIjj0QXNZZ8k="; + }; + }; +} diff --git a/hosts/server/natsu/services/forgejo-runner.nix b/hosts/server/natsu/services/forgejo-runner.nix new file mode 100644 index 0000000..d25b6e3 --- /dev/null +++ b/hosts/server/natsu/services/forgejo-runner.nix @@ -0,0 +1,67 @@ +{ + config, + lib, + pkgs, + ... +}: +let + runnerSecret = key: { + sopsFile = ../secrets/forgejo-runner.yaml; + inherit key; + owner = "root"; + group = "root"; + }; +in +{ + sops.secrets."forgejo-runner/token" = runnerSecret "forgejo-runner/token"; + + services.gitea-actions-runner = { + package = pkgs.forgejo-runner; + instances.my-forgejo-instance = { + enable = true; + name = "natsu-cicd"; + tokenFile = config.sops.secrets."forgejo-runner/token".path; + url = "https://git.mizuki.guru/"; + labels = [ + "node-24:docker://node:24-bookworm" + "nixos-latest:docker://nixos/nix" + "native:host" + "AArch64:host" + "ubuntu-latest:docker://git.mizuki.guru/packages/act:ubuntu-latest-aarch64" + ]; + + # act 엔진의 컨테이너 보안 가드 및 디렉토리 이탈 방지 설정 주입 + settings = { + container = { + # 호스트 측의 임시 디렉토리 마운트 허용 범위를 명시 + valid_volumes = [ + "/var/run/docker.sock" + "/tmp" + "/run/user" + ]; + # 컨테이너 내 작업 디렉토리를 절대 경로로 고정하여 탈출 방지 + workdir = "/workspace"; + }; + runner = { + # act 실행 환경 내부 임시 경로 강제 고정 + envs = { + ACT_TEMP_DIR = "/tmp/act"; + }; + }; + }; + + hostPackages = with pkgs; [ + bash + git + python3 + docker + docker-compose + docker-buildx + nodejs + bun + wget + curl + ]; + }; + }; +} diff --git a/modules/home/ciscopackettracer.nix b/modules/home/ciscopackettracer.nix new file mode 100644 index 0000000..805f510 --- /dev/null +++ b/modules/home/ciscopackettracer.nix @@ -0,0 +1,19 @@ +{ pkgs, inputs, ... }: +let + system = pkgs.stdenv.hostPlatform.system; + pkgsPacketTracer8 = import inputs.nixpkgs-2511 { + inherit system; + config = { + allowUnfree = true; + permittedInsecurePackages = [ + "ciscoPacketTracer8-8.2.2" + ]; + }; + }; +in +{ + home.packages = [ + pkgs.cisco-packet-tracer_9 + pkgsPacketTracer8.ciscoPacketTracer8 + ]; +} diff --git a/modules/home/discord/linux.nix b/modules/home/discord/linux.nix new file mode 100644 index 0000000..21a483f --- /dev/null +++ b/modules/home/discord/linux.nix @@ -0,0 +1,34 @@ +{ + pkgs, + inputs, + lib, + options, + ... +}: +{ + imports = [ inputs.nixcord.homeModules.nixcord ]; + # imports = [ inputs.nixcord.nixosModules.nixcord ]; + programs.nixcord = { + enable = true; + + discord = { + branch = "canary"; + vencord.enable = false; + equicord.enable = true; + krisp.enable = true; + }; + + vesktop.enable = true; + # equibop.enable = true; + config.plugins = import ./plugin.nix; + }; + home.packages = with pkgs; [ + discord-gamesdk + ]; + + # home.activation.krispPatch = lib.mkIf (!pkgs.stdenv.isDarwin) ( + # lib.hm.dag.entryAfter [ "writeBoundary" ] '' + # ${krisp-patcher}/bin/krisp-patcher $(${pkgs.findutils}/bin/find $HOME/.config/discord/ -name "discord_krisp.node" -path "*/modules/discord_krisp/*") || true + # '' + # ); +} diff --git a/modules/home/discord/mac.nix b/modules/home/discord/mac.nix new file mode 100644 index 0000000..b1497a5 --- /dev/null +++ b/modules/home/discord/mac.nix @@ -0,0 +1,23 @@ +# darwin-configuration.nix +{ inputs, pkgs, ... }: +{ + imports = [ inputs.nixcord.darwinModules.nixcord ]; + + programs.nixcord = { + enable = true; + user = "imnyang"; # Needed for system-level config + + discord = { + package = pkgs.discord-canary; + vencord.enable = false; + equicord.enable = true; + # krisp.enable = true; + }; + + equibop.enable = true; + + config.plugins = import ./plugin.nix; + }; + + environment.systemPackages = [ pkgs.discord-gamesdk ]; +} diff --git a/modules/home/discord/plugin.nix b/modules/home/discord/plugin.nix new file mode 100644 index 0000000..1b2fff0 --- /dev/null +++ b/modules/home/discord/plugin.nix @@ -0,0 +1,69 @@ +{ + alwaysAnimate.enable = true; + alwaysExpandRoles.enable = true; + blurNsfw.enable = true; + callTimer = { + enable = true; + format = "human"; + }; + crashHandler.enable = true; + disableCallIdle.enable = true; + dontRoundMyTimestamps.enable = true; + fixCodeblockGap.enable = true; + fixImagesQuality.enable = true; + fixYoutubeEmbeds.enable = true; + forceOwnerCrown.enable = true; + messageLogger = { + enable = true; + }; + clientSideBlock = { + enable = true; + hideBlockedUsers = true; + hideBlockedMessages = true; + hideEmptyRoles = false; + hideVc = true; + blockedReplyDisplay = "hideReply"; + }; + serverListIndicators.enable = true; + showTimeoutDuration.enable = true; + # silentTyping.enable = true; + textReplace.enable = true; + textReplace.regexRules = [ + { + find = "https?:\\/\\/(www\\.)?instagram\\.com\\/[^\\/]+\\/(p|reel)\\/([A-Za-z0-9-_]+)\\/?"; + replace = "https://g.ddinstagram.com/$2/$3"; + } + { + find = "https:\\/\\/x\\.com\\/([^\\/]+\\/status\\/[0-9]+)"; + replace = "https://fixupx.com/$1"; + } + { + find = "https:\\/\\/twitter\\.com\\/([^\\/]+\\/status\\/[0-9]+)"; + replace = "https://fixupx.com/$1"; + } + { + find = "https:\\/\\/(www\\.|old\\.)?reddit\\.com\\/(r\\/[a-zA-Z0-9_]+\\/comments\\/[a-zA-Z0-9_]+\\/[^\\s]*)"; + replace = "https://vxreddit.com/$2"; + } + { + find = "https:\\/\\/(www\\.)?pixiv\\.net\\/(.*)"; + replace = "https://phixiv.net/$2"; + } + { + find = "https:\\/\\/(?:www\\.|m\\.)?twitch\\.tv\\/twitch\\/clip\\/(.*)"; + replace = "https://clips.fxtwitch.tv/$1"; + } + { + find = "https:\\/\\/(?:www\\.)?youtube\\.com\\/(?:watch\\?v=|shorts\\/)([a-zA-Z0-9_-]+)"; + replace = "https://youtu.be/$1"; + } + ]; + translate.enable = true; + typingIndicator.enable = true; + typingTweaks.enable = true; + userVoiceShow.enable = true; + validReply.enable = true; + validUser.enable = true; + volumeBooster.enable = true; + spotifyCrack.enable = true; +} diff --git a/modules/home/firefox.nix b/modules/home/firefox.nix new file mode 100644 index 0000000..7a0e4dd --- /dev/null +++ b/modules/home/firefox.nix @@ -0,0 +1,29 @@ +{ pkgs, config, ... }: +{ + programs.firefox = { + enable = true; + configPath = ".mozilla/firefox"; + package = pkgs.firefox-devedition; + policies = { + Preferences = { + "widget.use-xdg-desktop-portal.file-picker" = { + Value = 1; + Status = "default"; + }; + "middlemouse.paste" = { + Value = false; + Status = "default"; + }; + }; + ExtensionSettings = { + "figma-windows-ua-spoofer@imnyang.local" = { + installation_mode = "force_installed"; + install_url = "https://git.mizuki.guru/imnyang/thisiswindowsfigma/releases/download/v1.0.0/d168a70cb6a24fe4a478-1.0.0.xpi"; + }; + }; + }; + }; + + home.file.".waterfox/native-messaging-hosts".source = + config.lib.file.mkOutOfStoreSymlink "${config.home.homeDirectory}/.mozilla/native-messaging-hosts"; +} diff --git a/modules/home/ghostty.nix b/modules/home/ghostty.nix new file mode 100644 index 0000000..2aeba40 --- /dev/null +++ b/modules/home/ghostty.nix @@ -0,0 +1,49 @@ +{pkgs, ...}: { + programs.ghostty = { + enable = true; + package = if pkgs.stdenv.isDarwin then pkgs.ghostty-bin else pkgs.ghostty; + + enableFishIntegration = true; + settings = { + background = "#fcf8f9"; + foreground = "#191017"; + + cursor-color = "#301d23"; + selection-background = "#f4ecee"; + selection-foreground = "#191017"; + + palette = [ + "0=#5c5f77" + "1=#d20f39" + "2=#40a02b" + "3=#df8e1d" + "4=#1e66f5" + "5=#ea76cb" + "6=#179299" + "7=#acb0be" + "8=#6c6f85" + "9=#d20f39" + "10=#40a02b" + "11=#df8e1d" + "12=#1e66f5" + "13=#ea76cb" + "14=#179299" + "15=#bcc0cc" + ]; + + window-colorspace = "srgb"; + window-theme = "ghostty"; + window-subtitle = "working-directory"; + + font-family = "JetBrainsMono NFM Regular"; + font-family-bold = "JetBrainsMono NFM Bold"; + font-family-italic = "JetBrainsMono NFM Bold Italic"; + font-family-bold-italic = "JetBrainsMono NFM Italic"; + + window-width = 100; + window-height = 30; + + auto-update = "off"; + }; + }; +} diff --git a/modules/home/git.nix b/modules/home/git.nix new file mode 100644 index 0000000..aa9cd42 --- /dev/null +++ b/modules/home/git.nix @@ -0,0 +1,26 @@ +{ pkgs, ... }: +{ + programs.git = { + enable = true; + settings = { + user = { + name = "imnyang"; + email = "imnyang@pm.me"; + signingkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOHP3Z+AYrRh9f8TYyqChKfeyNm3lOe0F75AwRHTTaxD"; + }; + gpg = { + format = "ssh"; + "ssh".program = "${pkgs._1password-gui}/bin/op-ssh-sign"; + }; + commit.gpgsign = true; + init.defaultBranch = "main"; + pull.rebase = false; + includeIf."gitdir:~/workspaces/git/adofai.gg/" = { + path = builtins.toFile "gitconfig-adofaigg" '' + [user] + email = imnyang@adofai.gg + ''; + }; + }; + }; +} diff --git a/modules/home/neovim.nix b/modules/home/neovim.nix new file mode 100644 index 0000000..7f23538 --- /dev/null +++ b/modules/home/neovim.nix @@ -0,0 +1,23 @@ +{ + pkgs, + config, + lib, + ... +}: +{ + programs.neovim = { + enable = true; + withRuby = true; + withPython3 = true; + viAlias = true; + vimAlias = true; + }; + + home.activation.nvimConfigRepo = lib.hm.dag.entryAfter [ "writeBoundary" ] '' + target="${config.xdg.configHome}/nvim" + + rm -rf "$target" + + ${pkgs.git}/bin/git clone https://git.pari.ng/imnyang/nvim-config.git "$target" + ''; +} diff --git a/modules/home/obs-studio.nix b/modules/home/obs-studio.nix new file mode 100644 index 0000000..7e1b664 --- /dev/null +++ b/modules/home/obs-studio.nix @@ -0,0 +1,28 @@ +{ pkgs, ... }: +let + obs-wrapped = (pkgs.obs-studio.override { + cudaSupport = true; + }).overrideAttrs (old: { + nativeBuildInputs = (old.nativeBuildInputs or []) ++ [ pkgs.makeWrapper ]; + postInstall = (old.postInstall or "") + '' + wrapProgram $out/bin/obs \ + --set QT_QPA_PLATFORM xcb \ + --set GS_DEVICE_TYPE opengl + ''; + }); +in +{ + programs.obs-studio = { + enable = true; + package = obs-wrapped; + + plugins = with pkgs.obs-studio-plugins; [ + obs-backgroundremoval + obs-pipewire-audio-capture + obs-vaapi + obs-gstreamer + obs-vkcapture + obs-move-transition + ]; + }; +} \ No newline at end of file diff --git a/modules/home/packages.nix b/modules/home/packages.nix new file mode 100644 index 0000000..e4b0882 --- /dev/null +++ b/modules/home/packages.nix @@ -0,0 +1,103 @@ +{ + pkgs, + inputs, +}: +with pkgs; +[ + nodejs + pnpm + yarn + python3 + rustc + cargo + go + bun + + virtualbox + + bibata-cursors + xcursor-mizuki + pjsk-cursor.n25.ani + + zed-editor + jetbrains.datagrip + # jetbrains.rider + jetbrains.idea + # inputs.vscode-nigo.packages.${stdenv.hostPlatform.system}.vscode-nigo + neovide + + ripgrep + fd + bat + fzf + jq + fastfetch + eza + btop + + gh + lazygit + + thunderbird + + mpv + prismlauncher + lunar-client + + pkgs."libreoffice-fresh" + + gimp + inkscape + + gnome-disk-utility + + antigravity + postman + + burpsuite + + krita + + scrcpy + + upscayl + signal-desktop + witr + + vial + wireguard-go + + corretto21 + + ghostty + remmina + codex + + # waterfox-bin + + unityhub + + ida-free + (ghidra.withExtensions ( + p: with p; [ + ret-sync + ghidraninja-ghidra-scripts + ] + )) + + inputs.notion-desktop.packages.${stdenv.hostPlatform.system}.default + inputs.notion-calendar-electron.packages.${stdenv.hostPlatform.system}.default + inputs.codex-app.packages.${stdenv.buildPlatform.system}.codex-desktop + + proton-vpn + + moonlight-qt + + code-cursor + + microsoft-edge + + galaxy-buds-client + + # another +] diff --git a/modules/home/plasma.nix b/modules/home/plasma.nix new file mode 100644 index 0000000..f63646f --- /dev/null +++ b/modules/home/plasma.nix @@ -0,0 +1,38 @@ +{ inputs, ... }: +let + assets = "${inputs.self}/assets"; + genericFonts = { + family = "Pretendard JP"; + pointSize = 10; + }; +in +{ + home.file.".local/share/color-schemes/Kawa.colors".source = "${assets}/Kawa.colors"; + home.file.".config/autostart/1password.desktop".source = "${assets}/1password.desktop"; + + programs.plasma = { + enable = true; + + workspace = { + clickItemTo = "select"; + enableMiddleClickPaste = false; + colorScheme = "Kawa"; + }; + + fonts = { + fixedWidth = { + family = "NanumGothicCoding"; + pointSize = 10; + }; + general = genericFonts; + toolbar = genericFonts; + menu = genericFonts; + windowTitle = genericFonts; + small = genericFonts // { + pointSize = 8; + }; + }; + + session.sessionRestore.restoreOpenApplicationsOnLogin = "startWithEmptySession"; + }; +} diff --git a/modules/home/spicetify.nix b/modules/home/spicetify.nix new file mode 100644 index 0000000..70e37b0 --- /dev/null +++ b/modules/home/spicetify.nix @@ -0,0 +1,17 @@ +{ config, pkgs, inputs, ... }: + +{ + programs.spicetify = let + spicePkgs = inputs.spicetify-nix.legacyPackages.${pkgs.stdenv.hostPlatform.system}; + in{ + enable = true; + + # Theme: catppuccin with mocha palette + theme = spicePkgs.themes.catppuccin; + colorScheme = "latte"; + enabledExtensions = with spicePkgs.extensions; [ + adblockify + hidePodcasts + ]; + }; +} diff --git a/modules/home/vicinae.nix b/modules/home/vicinae.nix new file mode 100644 index 0000000..9c9986c --- /dev/null +++ b/modules/home/vicinae.nix @@ -0,0 +1,38 @@ +{ pkgs, inputs, ... }: { + programs.vicinae = { + enable = true; # default: false + systemd = { + enable = true; # default: false + autoStart = true; # default: false + environment = { + USE_LAYER_SHELL = 1; + }; + }; + settings = { + close_on_focus_loss = true; + consider_preedit = true; + launcher_window = { + opacity = 0.98; + }; + font = { + normal = { + size = 10; + family = "SUIT"; + }; + }; + }; + extensions = with inputs.vicinae-extensions.packages.${pkgs.stdenv.hostPlatform.system}; [ + bluetooth + nix + power-profile + kde-system-settings + npm + port-killer + pulseaudio + case-converter + zed-recents + vscode-recents + timer + ]; + }; +} diff --git a/modules/home/vscode.nix b/modules/home/vscode.nix new file mode 100644 index 0000000..28e9efc --- /dev/null +++ b/modules/home/vscode.nix @@ -0,0 +1,51 @@ +{ pkgs, ... }: +let + styleScript = pkgs.writeText "inject.js" '' + ;(() => { + const el = document.createElement('style') + el.innerText = ` + .part.editor>.content .editor-group-container .editor-group-watermark .letterpress { + background-image: url("https://file.mizuki.guru/.tesiotjosaeifjpoeawsjfnpoiawsejfopieawjfopjakweopfjawieof/IN_VISUAL_STUDIO_CODE.webp") !important; + opacity: 1.0; + overflow: visible; + filter: none; + aspect-ratio: 16 / 9 !important; + max-height: fit-content !important; + } + ` + document.head.appendChild(el) + })(); + ''; +in +{ + programs.vscode = { + enable = true; + mutableExtensionsDir = true; + userSettings = { + "extensions.autoUpdate" = true; + }; + package = (pkgs.vscode.override { isInsiders = true; }).overrideAttrs (oldAttrs: { + version = "latest"; + + src = builtins.fetchTarball { + url = "https://code.visualstudio.com/sha/download?build=insider&os=linux-x64"; + sha256 = "1vzf897inlzxfwmnaykkj3gqg18wbh9zhv7lnh3if6agixv0v91b"; + }; + + buildInputs = oldAttrs.buildInputs ++ [ + pkgs.krb5 + pkgs.libsoup_3 + pkgs.webkitgtk_4_1 + pkgs.libxtst + pkgs.libjpeg8 + pkgs.pipewire + pkgs.libei + ]; + + postFixup = '' + cat ${styleScript} >> $out/lib/vscode/resources/app/out/vs/code/electron-browser/workbench/workbench.js + '' + + (oldAttrs.postFixup or ""); + }); + }; +} diff --git a/modules/home/zed.nix b/modules/home/zed.nix new file mode 100644 index 0000000..dbe252e --- /dev/null +++ b/modules/home/zed.nix @@ -0,0 +1,75 @@ +{ pkgs, ... }: + +{ + programs.zed-editor = { + enable = true; + package = if pkgs.stdenv.isDarwin then null else pkgs.zed-editor; + extensions = [ + "nix" + "toml" + "rust" + "git-firefly" + ]; + userSettings = { + "autosave" = "on_focus_change"; + "ui_font_size" = 16; + "buffer_font_size" = 15; + + "theme" = { + "mode" = "light"; + "light" = "One Light"; + "dark" = "One Dark"; + }; + + "theme_overrides" = { + "One Light" = { + "background" = "#FDF7F9"; + "status_bar.background" = "#FDF7F9"; + "title_bar.background" = "#FDF7F9"; + "elevated_surface.background" = "#FDF7F9"; + + # 핵심: sidebar/project panel 쪽은 투명 제거 + "surface.background" = "#FDF7F9"; + "panel.background" = "#FDF7F9"; + "editor.gutter.background" = "#FDF7F9"; + "tab_bar.background" = "#FDF7F9"; + "toolbar.background" = "#FDF7F9"; + "terminal.background" = "#FDF7F9"; + + # editor만 투명 유지하고 싶으면 이건 남겨도 됨 + "editor.background" = "#00000000"; + + "editor.line_number" = "#A38F96"; + "border" = "#F2E6EA"; + "hint.background" = "#F7EBEE"; + "editor.active_line_number" = "#191013"; + + "tab.active_background" = "#8165701a"; + "element.selected" = "#8165701a"; + "tab.inactive_background" = "#FDF7F9"; + + "editor.indent_guide" = "#F2E6EA"; + "editor.indent_guide_active" = "#E6D5DB"; + "panel.indent_guide" = "#F2E6EA"; + "panel.indent_guide_hover" = "#E6D5DB"; + "panel.indent_guide_active" = "#D9C4CC"; + + "panel.focused_border" = "#00000000"; + "element.active" = "#81657029"; + "border.variant" = "#00000000"; + "scrollbar.track.border" = "#00000000"; + "editor.active_line.background" = "#8165700f"; + "scrollbar.track.background" = "#00000000"; + "scrollbar.thumb.background" = "#A38F9680"; + "ghost_element.background" = "#00000000"; + "element.hover" = "#8165700f"; + "ghost_element.hover" = "#8165700f"; + "ghost_element.active" = "#8165701a"; + "ghost_element.selected" = "#81657024"; + "drop_target.background" = "#8165701a"; + "editor.highlighted_line.background" = "#8165701a"; + }; + }; + }; + }; +} diff --git a/modules/nixos/base/default.nix b/modules/nixos/base/default.nix new file mode 100644 index 0000000..7a5b322 --- /dev/null +++ b/modules/nixos/base/default.nix @@ -0,0 +1,9 @@ +{ ... }: +{ + imports = [ + ./nix.nix + ./user.nix + ./i18n.nix + ./packages.nix + ]; +} diff --git a/modules/nixos/base/i18n.nix b/modules/nixos/base/i18n.nix new file mode 100644 index 0000000..af3c6b7 --- /dev/null +++ b/modules/nixos/base/i18n.nix @@ -0,0 +1,62 @@ +{ pkgs, ... }: +{ + # 시간대 설정 + time.timeZone = "Asia/Seoul"; + + # 로케일 설정 (영어 기본 + 한국 로케일) + i18n = { + defaultLocale = "en_US.UTF-8"; + extraLocaleSettings = { + LC_ADDRESS = "en_US.UTF-8"; + LC_IDENTIFICATION = "en_US.UTF-8"; + LC_MEASUREMENT = "en_US.UTF-8"; + LC_MONETARY = "en_US.UTF-8"; + LC_NAME = "en_US.UTF-8"; + LC_NUMERIC = "en_US.UTF-8"; + LC_PAPER = "en_US.UTF-8"; + LC_TELEPHONE = "en_US.UTF-8"; + LC_TIME = "en_US.UTF-8"; + }; + }; + + i18n.inputMethod = { + enable = true; + type = "fcitx5"; + fcitx5 = { + settings.globalOptions = { + "Hotkey/TriggerKeys" = { + "0" = "Hangul"; + }; + "Hotkey/ActivateKeys" = { + "0" = "Hangul_Hanja"; + }; + "Hotkey/DeactivateKeys" = { + "0" = "Hangul_Romaja"; + }; + "Hotkey/EnumerateGroupForwardKeys" = { + "0" = "Super+space"; + }; + "Hotkey/PrevPage" = { + "0" = "Up"; + }; + "Hotkey/NextPage" = { + "0" = "Down"; + }; + "Hotkey" = { + "AltTriggerKeys" = ""; + "EnumerateForwardKeys" = ""; + "EnumerateBackwardKeys" = ""; + }; + }; + }; + fcitx5.addons = with pkgs; [ + fcitx5-hangul + ]; + }; + + environment.sessionVariables = { + GTK_IM_MODULE = "fcitx"; + QT_IM_MODULE = "fcitx"; + XMODIFIERS = "@im=fcitx"; + }; +} diff --git a/modules/nixos/base/nix.nix b/modules/nixos/base/nix.nix new file mode 100644 index 0000000..39762e2 --- /dev/null +++ b/modules/nixos/base/nix.nix @@ -0,0 +1,46 @@ +{ overlays, ... }: +{ + # Apply overlays + nixpkgs.overlays = overlays; + nixpkgs.config.allowUnfree = true; + + # Nix 설정 + nix.settings = { + sandbox = false; + experimental-features = [ + "nix-command" + "flakes" + ]; + auto-optimise-store = true; + }; + + nix.settings.trusted-users = [ + "root" + "imnyang" + ]; + + nix.settings = { + substituters = [ + "https://cache.mizuki.guru/public" + "https://cache.mizuki.guru/imnyang" + "https://nix.mizuki.my/public" + "https://vicinae.cachix.org" + ]; + trusted-public-keys = [ + "public:IgipakDD/clr0XbuaIejPYMT5UkTVGKVTxtWXcsbiAg=" + "imnyang:x8Oex2DLzZUBxS/3VvkVptT3DiugjsCbQ23VjsxMT5c=" + "public:SnHrtrxbCPcZujbJdgsKFeObTfRKQl5KhrI+LljtZUE=" + "vicinae.cachix.org-1:1kDrfienkGHPYbkpNj1mWTr7Fm1+zcenzgTizIcI3oc=" + ]; + }; + + nix.gc = { + automatic = true; + dates = "weekly"; + options = "--delete-older-than 7d"; + }; + + nixpkgs.config.permittedInsecurePackages = [ + "openssl-1.1.1w" + ]; +} diff --git a/modules/nixos/base/packages.nix b/modules/nixos/base/packages.nix new file mode 100644 index 0000000..2b48c5f --- /dev/null +++ b/modules/nixos/base/packages.nix @@ -0,0 +1,31 @@ +{ pkgs, ... }: +{ + programs.nix-ld.enable = true; + programs.nix-ld.libraries = with pkgs; [ + glib + stdenv.cc.cc + zlib + ]; + + # Unfree 패키지 허용 + nixpkgs.config.allowUnfree = true; + + programs.direnv.enable = true; + + # 기본 시스템 패키지 + environment.systemPackages = with pkgs; [ + eza + btop + vim + wget + curl + git + tree + unzip + zip + file + attic-client + direnv + devenv + ]; +} diff --git a/modules/nixos/base/user.nix b/modules/nixos/base/user.nix new file mode 100644 index 0000000..cc79c55 --- /dev/null +++ b/modules/nixos/base/user.nix @@ -0,0 +1,34 @@ +{ pkgs, inputs, ... }: +{ + users.users.imnyang = { + isNormalUser = true; + linger = true; + description = "@imnya.ng"; + + extraGroups = [ + "imnyang" + "networkmanager" + "wheel" + "docker" + "libvirtd" + "podman" + ]; + shell = pkgs.fish; + }; + + security.sudo.extraRules = [ + { + users = [ "imnyang" ]; + commands = [ + { + command = "ALL"; + options = [ "NOPASSWD" ]; + } + ]; + } + ]; + + system.activationScripts.createIcon = "ln -sfn ${inputs.self}/assets/avatar.webp /var/lib/AccountsService/icons/imnyang"; + + programs.fish.enable = true; +} diff --git a/modules/nixos/features/bluetooth.nix b/modules/nixos/features/bluetooth.nix new file mode 100644 index 0000000..5bb93ca --- /dev/null +++ b/modules/nixos/features/bluetooth.nix @@ -0,0 +1,16 @@ +{ ... }: +{ + hardware.bluetooth = { + enable = true; + powerOnBoot = true; + settings = { + General = { + Experimental = true; + FastConnectable = true; + }; + Policy = { + AutoEnable = true; + }; + }; + }; +} diff --git a/modules/nixos/features/boot.nix b/modules/nixos/features/boot.nix new file mode 100644 index 0000000..5e416b1 --- /dev/null +++ b/modules/nixos/features/boot.nix @@ -0,0 +1,32 @@ +{ pkgs, ... }: +{ + # boot.plymouth.enable = true; + boot.loader = { + grub = { + enable = true; + efiSupport = true; + useOSProber = true; + efiInstallAsRemovable = true; + device = "nodev"; + enableCryptodisk = true; + + # extraInstallCommands = '' + # mkdir -p /boot/EFI/BOOT + + # cp -f /boot/EFI/NixOS-boot/grubx64.efi /boot/EFI/BOOT/BOOTX64.EFI + # ''; + + default = "saved"; + extraConfig = '' + GRUB_SAVEDEFAULT=true + ''; + }; + # efi.canTouchEfiVariables = true; + efi.efiSysMountPoint = "/boot"; + }; + + boot.initrd.systemd.enable = true; + boot.initrd.systemd.emergencyAccess = true; + + boot.kernelPackages = pkgs.linuxPackages_latest; +} diff --git a/modules/nixos/features/catppuccin.nix b/modules/nixos/features/catppuccin.nix new file mode 100644 index 0000000..60f1af5 --- /dev/null +++ b/modules/nixos/features/catppuccin.nix @@ -0,0 +1,18 @@ +{ pkgs, ... }: +{ + catppuccin.enable = true; + catppuccin.flavor = "latte"; + catppuccin.autoEnable = false; + catppuccin = { + cache.enable = true; + cursors.enable = false; + fcitx5.enable = true; + forgejo.enable = false; + limine.enable = false; + gitea.enable = false; + grub.enable = true; + plymouth.enable = false; + sddm.enable = false; + tty.enable = true; + }; +} diff --git a/modules/nixos/features/cockpit.nix b/modules/nixos/features/cockpit.nix new file mode 100644 index 0000000..172622e --- /dev/null +++ b/modules/nixos/features/cockpit.nix @@ -0,0 +1,26 @@ +{ pkgs, ... }: + +{ + virtualisation.libvirtd = { + enable = true; + dbus.enable = true; + }; + users.groups.libvirtd.members = [ "imnyang" ]; + + services.cockpit = { + enable = true; + plugins = with pkgs; [ + cockpit-machines + cockpit-files + cockpit-podman + ]; + openFirewall = true; + allowed-origins = [ "*" ]; + }; + + environment.systemPackages = with pkgs; [ + libvirt-dbus + virt-manager + virt-viewer + ]; +} diff --git a/modules/nixos/features/docker.nix b/modules/nixos/features/docker.nix new file mode 100644 index 0000000..9201bf8 --- /dev/null +++ b/modules/nixos/features/docker.nix @@ -0,0 +1,4 @@ +{ ... }: +{ + virtualisation.docker.enable = true; +} diff --git a/modules/nixos/features/figma-agent.nix b/modules/nixos/features/figma-agent.nix new file mode 100644 index 0000000..f908186 --- /dev/null +++ b/modules/nixos/features/figma-agent.nix @@ -0,0 +1,19 @@ +{ pkgs, ... }: { + systemd.user.services.figma-agent = { + description = "Figma Agent for local font access"; + wantedBy = [ "default.target" ]; + serviceConfig = { + ExecStart = "${pkgs.figma-agent}/bin/figma-agent"; + Restart = "on-failure"; + }; + }; + + systemd.user.sockets.figma-agent = { + description = "Figma Agent socket"; + wantedBy = [ "default.target" ]; + socketConfig = { + ListenStream = "127.0.0.1:44950"; + NoDelay = true; + }; + }; +} \ No newline at end of file diff --git a/modules/nixos/features/fonts.nix b/modules/nixos/features/fonts.nix new file mode 100644 index 0000000..08199b5 --- /dev/null +++ b/modules/nixos/features/fonts.nix @@ -0,0 +1,70 @@ +{ pkgs, ... }: +let + wantedSans = pkgs.stdenvNoCC.mkDerivation { + pname = "wanted-sans"; + version = "1.0.3"; + + src = pkgs.fetchzip { + url = "https://github.com/wanteddev/wanted-sans/releases/download/v1.0.3/WantedSans-1.0.3.zip"; + hash = "sha256-uksJ7Qmwv0kQw/mXyI179XaFHGMI8fuumcitD/XpA/w="; + stripRoot = false; + }; + + installPhase = '' + runHook preInstall + install -Dm644 variable/*.ttf -t $out/share/fonts/truetype + install -Dm644 otf/*.otf -t $out/share/fonts/opentype + runHook postInstall + ''; + }; + + suit-font = pkgs.stdenvNoCC.mkDerivation { + pname = "suit-font"; + version = "v2.0.5"; + + # name을 다르게 지정하여 unpack 시 충돌을 방지합니다. + srcs = [ + (pkgs.fetchzip { + name = "suit-variable"; + url = "https://github.com/sun-typeface/SUIT/releases/download/v2.0.5/SUIT-Variable-ttf.zip"; + hash = "sha256-oRZGxT/v6jBa5cOsYWG8qHfdPIRBqPAyt6hjfBTD1jo="; + stripRoot = false; + }) + (pkgs.fetchzip { + name = "suit-static"; + url = "https://github.com/sun-typeface/SUIT/releases/download/v2.0.5/SUIT-otf.zip"; + hash = "sha256-YDyBKU5P+tlMsK4L2dEn6ibOo6UxDK2B507rm/zy2FA="; + stripRoot = false; + }) + ]; + + sourceRoot = "."; + + installPhase = '' + runHook preInstall + mkdir -p $out/share/fonts/truetype $out/share/fonts/opentype + + # 각 소스가 suit-variable, suit-static 디렉토리에 풀려 있으므로 전체 탐색하여 복사 + find . -name "__MACOSX" -prune -o -name "*.ttf" -exec cp {} $out/share/fonts/truetype/ \; + find . -name "__MACOSX" -prune -o -name "*.otf" -exec cp {} $out/share/fonts/opentype/ \; + + runHook postInstall + ''; + }; +in +{ + fonts = { + packages = with pkgs; [ + liberation_ttf + fira-code + fira-code-symbols + dejavu_fonts + pretendard + pretendard-jp + nanum-gothic-coding + nerd-fonts.jetbrains-mono + wantedSans + suit-font + ]; + }; +} diff --git a/modules/nixos/features/graphics.nix b/modules/nixos/features/graphics.nix new file mode 100644 index 0000000..5f9bc45 --- /dev/null +++ b/modules/nixos/features/graphics.nix @@ -0,0 +1,7 @@ +{ ... }: +{ + hardware.graphics = { + enable = true; + enable32Bit = true; + }; +} diff --git a/modules/nixos/features/grub-standalone.nix b/modules/nixos/features/grub-standalone.nix new file mode 100644 index 0000000..b43a81a --- /dev/null +++ b/modules/nixos/features/grub-standalone.nix @@ -0,0 +1,74 @@ +{ pkgs, config, ... }: +{ + environment.systemPackages = with pkgs; [ + grub2_efi + ]; + + system.activationScripts = { + # This, has to be the LAST GRUB script to run. + # The reason is that a standalone GRUB image takes with it + # the configuration too, apparently. + # "90-generate-standalone-grub" = { + # text = '' + # if [ "$NIXOS_ACTION" = "switch" ] || [ "$NIXOS_ACTION" = "boot" ]; then + # echo "Generating standalone GRUB EFI entry..." + + # ESP="${config.boot.loader.efi.efiSysMountPoint}" + # OUT_DIR="$ESP/EFI/NixOS-boot" + # FALLBACK_DIR="$ESP/EFI/BOOT" + # mkdir -p "$OUT_DIR" "$FALLBACK_DIR" + + # OUT="$OUT_DIR/grubx64.efi" + # FALLBACK="$FALLBACK_DIR/BOOTX64.EFI" + + # # GPT-5 told me to add all those modules, idk. + # ${pkgs.grub2_efi}/bin/grub-mkstandalone -O x86_64-efi -o "$OUT" \ + # "boot/grub/grub.cfg=${pkgs.writeText "grub-standalone-template.cfg" '' + # search --file --no-floppy --set=esp /EFI/NixOS-boot/grubx64.efi + # set prefix=($esp)/grub + # if [ -f ($esp)/grub/grubenv ]; then + # load_env ($esp)/grub/grubenv + # fi + # if [ -f ($esp)/grub/grub.cfg ]; then + # configfile ($esp)/grub/grub.cfg + # else + # echo "Error: ($esp)/grub/grub.cfg not found." + # sleep 5 + # fi + # ''}" \ + # --modules="part_gpt part_msdos fat normal search search_fs_uuid search_label configfile linux gzio efi_gop efi_uga all_video gfxterm gfxmenu png jpeg tga font" \ + # --disable-shim-lock + + # # It's so stupid but otherwise it won't boot: + # # https://wejn.org/2021/09/fixing-grub-verification-requested-nobody-cares/ + # ${pkgs.gnused}/bin/sed -i 's/SecureBoot/SecureB00t/' "$OUT" + + # cp -f "$OUT" "$FALLBACK" + # fi + # ''; + # }; + "99-sign-all" = { + text = '' + if [ "$NIXOS_ACTION" = "switch" ] || [ "$NIXOS_ACTION" = "boot" ]; then + echo "Signing all EFI binaries with sbctl..." + + # 1. 파일이 존재하는지 먼저 확인하고, + # 2. 이미 등록되어 있다면 sign-all로 한 번에 처리하거나, + # 3. 개별 파일에 대해 에러가 나도 스크립트가 중단되지 않도록 || true를 붙입니다. + + # 주요 바이너리들을 DB에 등록 (이미 등록되어 있으면 sbctl이 알아서 스킵하거나 에러를 낼 텐데, 그걸 무시합니다) + ${pkgs.sbctl}/bin/sbctl sign -s /boot/EFI/NixOS-boot/grubx64.efi || true + ${pkgs.sbctl}/bin/sbctl sign -s /boot/EFI/BOOT/BOOTX64.EFI || true + + # Windows 부트로더 등 다른 파일들도 필요한 경우 추가 + if [ -f /boot/EFI/Microsoft/Boot/bootmgfw.efi ]; then + ${pkgs.sbctl}/bin/sbctl sign -s /boot/EFI/Microsoft/Boot/bootmgfw.efi || true + fi + + # 4. 마지막으로 전체 서명 수행 + ${pkgs.sbctl}/bin/sbctl sign-all || echo "Some files failed to sign, but continuing..." + fi + ''; + }; + }; +} diff --git a/modules/nixos/features/packages.nix b/modules/nixos/features/packages.nix new file mode 100644 index 0000000..e399d8b --- /dev/null +++ b/modules/nixos/features/packages.nix @@ -0,0 +1,77 @@ +{ + pkgs, + inputs, + ... +}: +let + nr = import ./packages/nr.nix { inherit pkgs; }; + nrr = import ./packages/nrr.nix { inherit pkgs; }; +in +{ + programs._1password.enable = true; + programs._1password-gui = { + enable = true; + polkitPolicyOwners = [ "imnyang" ]; + }; + + environment.etc = { + "1password/custom_allowed_browsers" = { + text = '' + microsoft-edge + firefox-devedition + ''; + mode = "0755"; + }; + }; + + # 시스템 전역 패키지 (데스크탑/개발용) + environment.systemPackages = with pkgs; [ + nr + nrr + + # 네트워크 도구 + networkmanager + networkmanager-ssh + + # 개발 도구 + gcc + gnumake + + nil + nixd + + cockpit + libvirt + virt-manager + + mono + msbuild + + docker + docker-buildx + docker-compose + docker-client + uv + python3 + + openssl + pkg-config + + mtr + glibc + + gtk3 + pango + librsvg + penelope + + ntfs3g + + _1password-cli + _1password-gui + + inputs.muvel.packages.${pkgs.stdenv.hostPlatform.system}.muvel + + sbctl + ]; +} diff --git a/modules/nixos/features/packages/dr.nix b/modules/nixos/features/packages/dr.nix new file mode 100644 index 0000000..9528cc3 --- /dev/null +++ b/modules/nixos/features/packages/dr.nix @@ -0,0 +1,44 @@ +{ pkgs }: +pkgs.writeShellApplication { + name = "dr"; + + runtimeInputs = with pkgs; [ + nix-output-monitor + coreutils + nix + attic-client + ]; + + text = '' + set -e + + TARGET_NAME="''${1:-$(hostname -s)}" + FLAKE_PATH="." + UPLOAD_CACHE=true + + while [[ $# -gt 0 ]]; do + case "$1" in + --no-upload) UPLOAD_CACHE=false ;; + *) TARGET_NAME="$1" ;; + esac + shift + done + + echo "macOS 시스템 빌드 중... ($TARGET_NAME)" + + BUILD_PATH=$(nom build "$FLAKE_PATH#darwinConfigurations.$TARGET_NAME.system" --print-out-paths --no-link) + + echo "프로필 등록 및 스위치 중..." + + sudo nix-env --profile /nix/var/nix/profiles/system --set "$BUILD_PATH" + + sudo "$BUILD_PATH/activate" + + if [ "$UPLOAD_CACHE" = true ]; then + echo "캐시 업로드 중..." + attic push imnyang "$BUILD_PATH" || echo "푸시 실패" + fi + + echo "nix-darwin 스위치 완료!" + ''; +} diff --git a/modules/nixos/features/packages/nr.nix b/modules/nixos/features/packages/nr.nix new file mode 100644 index 0000000..157d2ba --- /dev/null +++ b/modules/nixos/features/packages/nr.nix @@ -0,0 +1,50 @@ +{ pkgs }: +pkgs.writeShellApplication { + name = "nr"; + + runtimeInputs = with pkgs; [ + nix-output-monitor + openssh + coreutils + nix + attic-client + ]; + + text = '' + set -e + + TARGET_NAME="''${1:-$(hostname)}" + FLAKE_PATH="." + UPLOAD_CACHE=true + + while [[ $# -gt 0 ]]; do + case "$1" in + --no-upload) UPLOAD_CACHE=false ;; + *) TARGET_NAME="$1" ;; + esac + shift + done + + EXTRA_BUILD_FLAGS=() + if [ "$TARGET_NAME" = "kazusa" ]; then + EXTRA_BUILD_FLAGS+=("--max-substituter-jobs" "2") + fi + + echo "시스템 빌드 중... $TARGET_NAME" + # shellcheck disable=SC2086 + BUILD_PATH=$(nom build "$FLAKE_PATH#nixosConfigurations.$TARGET_NAME.config.system.build.toplevel" \ + "''${EXTRA_BUILD_FLAGS[@]}" \ + --print-out-paths --no-link) + + echo "스위치 중..." + sudo nix-env --profile /nix/var/nix/profiles/system --set "$BUILD_PATH" + sudo "$BUILD_PATH/bin/switch-to-configuration" switch + + if [ "$UPLOAD_CACHE" = true ]; then + echo "캐시 업로드 중..." + attic push imnyang "$BUILD_PATH" || echo "푸시 실패" + fi + + echo "스위치 완료!" + ''; +} \ No newline at end of file diff --git a/modules/nixos/features/packages/nrr.nix b/modules/nixos/features/packages/nrr.nix new file mode 100644 index 0000000..7c4d5c7 --- /dev/null +++ b/modules/nixos/features/packages/nrr.nix @@ -0,0 +1,59 @@ +{ pkgs }: +pkgs.writeShellApplication { + name = "nrr"; + + runtimeInputs = with pkgs; [ + nix-output-monitor + openssh + coreutils + ]; + + text = '' + set -e + + TARGET_NAME="" + if [ $# -gt 0 ]; then + TARGET_NAME="$1" + fi + FLAKE_PATH="." + + declare -A HOST_MAP + HOST_MAP["hikari"]="10.11.8.100" + HOST_MAP["hako"]="10.11.8.102" + HOST_MAP["kazusa"]="82.21.82.30" + HOST_MAP["natsu"]="natsu.icn.mizuki.guru" + + HOST_MAP["mafuyu"]="10.20.30.101" + HOST_MAP["mizuki"]="10.20.30.103" + HOST_MAP["ena"]="10.20.30.104" + + if [ -z "$TARGET_NAME" ]; then + echo "nrr - 로컬에서 NixOS 빌드 후 스위치합니다" + echo "사용법: nrr " + exit 1 + fi + + if [[ -v "HOST_MAP[$TARGET_NAME]" ]]; then + TARGET_IP=''${HOST_MAP[$TARGET_NAME]} + echo "호스트 사용: $TARGET_NAME -> $TARGET_IP" + else + echo "매핑되지 않은 호스트입니다." + exit 1 + fi + + echo "시스템 빌드 중..." + BUILD_PATH=$(nom build "$FLAKE_PATH#nixosConfigurations.$TARGET_NAME.config.system.build.toplevel" --print-out-paths --no-link --eval-cache --accept-flake-config) + + echo "시스템 복사 중... ($BUILD_PATH -> $TARGET_IP)" + nix copy --to "ssh://imnyang@$TARGET_IP" "$BUILD_PATH" + + echo "스위치 중..." + # shellcheck disable=SC2029 + ssh "imnyang@$TARGET_IP" "sudo nix-env --profile /nix/var/nix/profiles/system --set \"$BUILD_PATH\" && sudo $BUILD_PATH/bin/switch-to-configuration switch" + + echo "캐시 업로드 중..." + attic push imnyang "$BUILD_PATH" || echo "푸시 실패" + + echo "배포 완료!" + ''; +} diff --git a/modules/nixos/features/plasma.nix b/modules/nixos/features/plasma.nix new file mode 100644 index 0000000..47d195b --- /dev/null +++ b/modules/nixos/features/plasma.nix @@ -0,0 +1,22 @@ +{ pkgs, ... }: +{ + services.xserver = { + enable = true; + xkb = { + layout = "us"; + variant = ""; + }; + }; + + services.displayManager.sddm.enable = true; + services.desktopManager.plasma6.enable = true; + + xdg.portal = { + enable = true; + extraPortals = with pkgs; [ kdePackages.xdg-desktop-portal-kde ]; + config.common.default = "kde"; + }; + + system.nixos.variant_id = "mizuki"; + system.nixos.variantName = "Mizuki"; +} diff --git a/modules/nixos/features/podman.nix b/modules/nixos/features/podman.nix new file mode 100644 index 0000000..d3c42dc --- /dev/null +++ b/modules/nixos/features/podman.nix @@ -0,0 +1,29 @@ +{ + config, + lib, + pkgs, + ... +}: + +{ + virtualisation = { + containers.enable = true; + podman = { + enable = true; + dockerCompat = true; + defaultNetwork.settings.dns_enabled = true; # Required for containers under podman-compose to be able to talk to each other. + }; + }; + + environment.systemPackages = with pkgs; [ + podman-compose + podman + podman-tui + ]; + + users.users.imnyang = { + extraGroups = [ + "podman" + ]; + }; +} diff --git a/modules/nixos/features/sbctl.nix b/modules/nixos/features/sbctl.nix new file mode 100644 index 0000000..be2790a --- /dev/null +++ b/modules/nixos/features/sbctl.nix @@ -0,0 +1,37 @@ +{ pkgs, config, ... }: +{ + environment.systemPackages = with pkgs; [ + sbctl + ]; + + # The 99 here ensures that this runs AFTER the grub activation scripts. + system.activationScripts."99-sign-all" = { + text = '' + if [ "$NIXOS_ACTION" = "switch" ] || [ "$NIXOS_ACTION" = "boot" ]; then + # `sbctl verify --json` returns "null" if there is an error, + # empty string if there are no files in the database. + if [ "$(${pkgs.sbctl}/bin/sbctl verify --json)" != "null" ]; then + + echo "Signing all EFI binaries with sbctl..." + + ESP="${config.boot.loader.efi.efiSysMountPoint}" + readarray -t files < <(find "$ESP" -type f -iname "*.efi" -o -iname "*bzImage") + + # Removing all the files first. + for file in "${"$"}{files[@]}"; do + echo "Removing from sbctl: $file" + # The `|| true` part is because otherwise some files might not exist and + # the script would return an error. + ${pkgs.sbctl}/bin/sbctl remove-file "$file" >/dev/null 2>&1 || true + done + + for file in "${"$"}{files[@]}"; do + echo "Signing with sbctl: $file" + ${pkgs.sbctl}/bin/sbctl sign -s "$file" >/dev/null 2>&1 + done + + fi + fi + ''; + }; +} \ No newline at end of file diff --git a/modules/nixos/features/sound.nix b/modules/nixos/features/sound.nix new file mode 100644 index 0000000..1f5faa8 --- /dev/null +++ b/modules/nixos/features/sound.nix @@ -0,0 +1,12 @@ +{ ... }: +{ + # 사운드 + services.pulseaudio.enable = false; + security.rtkit.enable = true; + services.pipewire = { + enable = true; + alsa.enable = true; + alsa.support32Bit = true; + pulse.enable = true; + }; +} diff --git a/modules/nixos/features/ssh.nix b/modules/nixos/features/ssh.nix new file mode 100644 index 0000000..f379154 --- /dev/null +++ b/modules/nixos/features/ssh.nix @@ -0,0 +1,9 @@ +{ ... }: +{ + services.openssh = { + enable = true; + settings = { + PermitRootLogin = "prohibit-password"; + }; + }; +} diff --git a/modules/nixos/features/steam.nix b/modules/nixos/features/steam.nix new file mode 100644 index 0000000..cf656ee --- /dev/null +++ b/modules/nixos/features/steam.nix @@ -0,0 +1,23 @@ +{ pkgs, ... }: +{ + programs.steam = { + enable = true; + remotePlay.openFirewall = true; + dedicatedServer.openFirewall = true; + localNetworkGameTransfers.openFirewall = true; + gamescopeSession.enable = true; + package = pkgs.millennium-steam; + extraCompatPackages = with pkgs; [ + proton-ge-bin + ]; + }; + hardware.steam-hardware.enable = true; + + environment.systemPackages = with pkgs; [ + steam-run + sgdboop + mangohud + protontricks + ]; + +} diff --git a/modules/nixos/features/sunshine.nix b/modules/nixos/features/sunshine.nix new file mode 100644 index 0000000..ffab79b --- /dev/null +++ b/modules/nixos/features/sunshine.nix @@ -0,0 +1,16 @@ +{ + ... +}: + +{ + services.sunshine = { + enable = true; + autoStart = true; + capSysAdmin = true; # only needed for Wayland -- omit this when using with Xorg + openFirewall = true; + }; + users.users.imnyang = { + extraGroups = [ "uinput" ]; + }; + hardware.uinput.enable = true; +} diff --git a/modules/nixos/features/virtualisation.nix b/modules/nixos/features/virtualisation.nix new file mode 100644 index 0000000..a7fcfb4 --- /dev/null +++ b/modules/nixos/features/virtualisation.nix @@ -0,0 +1,23 @@ +{ pkgs, ... }: +{ + virtualisation.docker = { + enable = true; + }; + + virtualisation.libvirtd = { + enable = true; + qemu = { + package = pkgs.qemu_kvm; + runAsRoot = true; + swtpm.enable = true; + }; + }; + + # Override the virt-secret-init-encryption service to use correct shell path + systemd.services.virt-secret-init-encryption = { + serviceConfig.ExecStart = [ + "" + "${pkgs.bash}/bin/bash -c 'umask 0077 && (${pkgs.coreutils}/bin/dd if=/dev/urandom status=none bs=32 count=1 | ${pkgs.systemd}/bin/systemd-creds encrypt --name=secrets-encryption-key - /var/lib/libvirt/secrets/secrets-encryption-key)'" + ]; + }; +} diff --git a/overlays/hoffice/.SRCINFO b/overlays/hoffice/.SRCINFO new file mode 100644 index 0000000..1640ca4 --- /dev/null +++ b/overlays/hoffice/.SRCINFO @@ -0,0 +1,34 @@ +pkgbase = hoffice + pkgdesc = Office document editor for Linux. Hancom Office Editor is an application to allow you to edit office documents that is developed and distributed by Hancom Inc. / 본 어플리케이션은 리눅스용 문서 편집 프로그램으로, 한컴에 의해 개발되고 배포된 형식의 문서들을 편집할 수 있도록 해주는 프로그램입니다. + pkgver = 11.20.0.1520 + pkgrel = 4 + url = https://www.hancom.com + install = hoffice.install + arch = x86_64 + license = custom:hoffice + makedepends = wget + depends = cairo + depends = fontconfig + depends = freetype2 + depends = gcc-libs + depends = glibc + depends = glu + depends = harfbuzz + depends = harfbuzz-icu + depends = libcups + depends = libcurl-gnutls + depends = libxcb + depends = openssl-1.1 + depends = qt5-base + depends = qt5-x11extras + depends = zlib + provides = hoffice=${pkgver} + conflicts = hoffice-hwp + source = https://dl.dropbox.com/scl/fi/ia3ub05nti01h8lzb3vwr/1732118678_hoffice_11.20.0.1520_amd64.deb?rlkey=8bnxl9chpm7rt6sr6nc4eoqp0&st=yaxlb481&dl=0 + source = LICENSE + source = libqt5im-nimf.so + sha256sums = 1ecb2f82e915b49706d1f5f6d206f8bd4a9384fda2bd56798c94046865fe5730 + sha256sums = 09b74399a45cde2b28e672784dbd1eb6397454a025e05a51fb3367eadb834583 + sha256sums = d246c02a20a1e4ea123f9c2275dfc4a2ea091a65032ddbbe8a59bfc71418f60c + +pkgname = hoffice diff --git a/overlays/hoffice/.gitignore b/overlays/hoffice/.gitignore new file mode 100644 index 0000000..b314cd2 --- /dev/null +++ b/overlays/hoffice/.gitignore @@ -0,0 +1,5 @@ +pkg +src +*.deb +*.zst +libkime-qt-5.11.3.so diff --git a/overlays/hoffice/LICENSE b/overlays/hoffice/LICENSE new file mode 100644 index 0000000..7f23726 --- /dev/null +++ b/overlays/hoffice/LICENSE @@ -0,0 +1,64 @@ +한컴오피스 2022 Linux Beta 소프트웨어 사용권 계약서 + + +본 사용권 계약서는 한컴오피스 2022 Linux Beta(이하 “소프트웨어”라 하며, 한컴오피스 2022 Linux Beta 제품은 (주)한글과컴퓨터에서 개발하여 배포하는 [한글,한워드,한셀,한쇼]를 통합한 Linux 전용 편집기입니다) 및 이를 구성하는 개별 제품군에 대하여 공통으로 적용되는 사항이며 각 품목별 별도 증서 또는 계약서가 있는 경우 해당 증서 또는 계약서의 내용이 본 계약서 대비 우선시됨을 안내드립니다. + +이 계약은 (주)한글과컴퓨터와 사용자 사이의 법적인 사용 허가 계약으로서 매매 계약이 아닙니다. (주)한글과컴퓨터와 사용자는 (주)한글과컴퓨터의 소프트웨어 제품을 사용함에 있어서의 제반 법률관계를 규율하기 위하여 제품을 실행하는 경우 본 계약의 내용에 동의하는 것으로 간주합니다. 만일 본 계약서의 내용에 동의하지 않는다면 제품을 실행하지 않거나, 제품을 삭제해 주십시오. 또한 비상업적인 목적으로 출시되었다고 판단되는 제품에 한해서는 제품의 환불 및 사용권의 이전, 양도가 불가함을 안내드립니다. + +1. 사용권: (주)한글과컴퓨터는 소프트웨어 사용권을 취득한 제품의 사용기간 동안 이 소프트웨어를 사용할 권리를 드립니다. 이 소프트웨어의 전부 또는 일부가 컴퓨터의 주기억장치에 실려 있거나 기타 기억 장치에 저장되어 있는 경우, 소프트웨어를 “사용하고 있는” 것으로 간주합니다. 개인 사용자(single user) 제품 또는 단체 사용자용 제품(영구 라이선스)을 네트워크 서버(server)에 설치하거나 복사하여 사용할 수 없으며, 랜(LAN) 사용자용 제품을 허가된 사용자 수만큼 사용하고 있더라도 이를 랜에 연결하지 않은 독립된 컴퓨터에 나누어 설치하거나 사용할 수 없습니다. 이 경우에는 독립된 컴퓨터에 설치된 실행파일의 수만큼 소프트웨어를 구입해야 합니다. + +2. 사용권의 이전: 사용자가 이전 버전으로 보상을 받아 이 소프트웨어의 사용권을 취득한 경우 이전 버전의 사용권은 새 버전으로 옮겨집니다. 따라서 이전 버전의 사용권은 더 이상 존속되지 않으므로 제3자에의 양도, 대여 및 판매는 금지됩니다. + +3. 사용권의 양도: 이 소프트웨어의 사용자(양도인)는 (주)한글과컴퓨터의 사전 동의를 얻은 후에 이 소프트웨어의 사용권을 한 차례 양도할 수 있습니다. 이 경우 사용자(양도인)는 설치된 소프트웨어를 삭제하여야 하며, 자신이 보관하고 있는 모든 제품 구성물 또는 이의 복사본을 양도 또는 파기하여야 합니다. 단, 다운로드 방식의 제품의 경우 이 소프트웨어의 사용권은 타인에게 양도할 수 없습니다. + +4. 저작권: 이 소프트웨어와 모든 부속물에 대한 저작권과 지적 소유권은 (주)한글과컴퓨터 또는 해당 개발사가 가지고 있으며, 이 권리는 대한민국의 저작권법과 국제 저작권 조약으로 보호받습니다. 따라서 사용자는 이 소프트웨어를 사용하거나 보관용 복사본 하나를 만드는 것 이외에는 더 이상의 복사본을 만들어 사용할 수 없습니다. + +5. 글꼴 및 클립아트의 사용 범위: 제품에 포함된 글꼴 및 클립아트 중 일부는 (주)한글과컴퓨터와 글꼴 및 클립아트의 저작권자와의 계약에 따라 본 제품 사용 시에만 사용하도록 제한되어 있습니다. 따라서 본 제품 외에서 해당 글꼴 및 클립아트를 사용 시, 사전에 저작권이 있는 해당 저작사 또는 저작권자에게 사용권 문의를 하시기 바랍니다. 이의 부주의로 인한 문제 발생 시 (주)한글과컴퓨터는 이에 대한 책임을 지지 않습니다. + +6. 설치: 이 소프트웨어의 사용자는 한 대의 컴퓨터에만 설치하여 사용할 수 있으며, 소프트웨어의 구성 요소를 분리하여 서로 다른 장치에 설치하거나 한 대의 컴퓨터에 이 소프트웨어를 설치한 후 하나 이상의 다른 장치를 통해 접근(access)하여 사용할 수 없습니다. + +7. 자동업데이트: (주)한글과컴퓨터는 자동업데이트를 통해 소프트웨어에서 확인된 오류를 수정하거나 기능을 개선하며, 특히 보안상 문제를 야기할 수 있는 심각한 사항에 대해 사용자의 동의 없이 소프트웨어를 업데이트할 수 있습니다. 사용자는 이 자동업데이트에 동의하지 않을 권리가 있으며 동의하지 않음으로써 발생할 수 있는 사용자의 사업상 손실, 이익 손실, 사업 중단, 사업 정보 또는 기타 데이터 손실 및 금전적 손실을 포함하되 이에 국한되지 않는 모든 피해에 대해 (주)한글과컴퓨터는 책임지지 않습니다. + +8. 보증의 한계: (주)한글과컴퓨터는 제품을 수령한 날로부터 30일 동안 모든 물리적인 결함이 없음을 보증합니다. 그러므로 이 기간 동안에 제품 제작상의 실수로 결함이 발생할 경우에는 교환해 드립니다. 교환 대상 제품은 수령일로부터 30일 이내의 제품임을 증명할 수 있는 것이어야 하며, 사용자의 부주의나 실수 또는 취급 소홀에 의한 손상일 경우에는 교환해 드리지 않습니다. 또한, 제품에 포함된 통·번역 기능과 관련하여, 번역할 문서의 내용은 보안 처리되어 인터넷을 통해 (주)한글과컴퓨터 또는 번역 서비스 공급자인 (주)한컴인터프리에 전송되며, (주)한글과컴퓨터는 통·번역 품질의 정확성, 가독성, 완결성을 보장하지 않습니다. 아울러 (주)한글과컴퓨터는 이 소프트웨어에 포함된 기능이 고객의 특정 목적에 적합할 것이라는 보증은 하지 않으며, 본 제품의 사용으로 인해 초래된 모든 결과에 대해 책임을 지지 않습니다. + +9. 책임: (주)한글과컴퓨터를 제외한 (주)한글과컴퓨터의 제품 공급자, 대리점을 포함한 제3자가 구두, 문서 및 기타 고지 수단을 이용하여 사용자에게 한 약속에 대해, (주)한글과컴퓨터는 책임을 지지 않습니다. + +10. 계약준수 여부의 확인 : (주)한글과컴퓨터는 계약 기간 동안 당사의 비용으로 본 계약의 준수 여부를 확인할 수 있습니다. 확인 작업은 최소한 15일 전에 사용자에게 통지함으로써 이루어지며, 통상적인 영업시간 동안 사용자의 협조 아래 업무를 부당하게 방해하지 않는 방식으로 행해질 것입니다. 확인 결과 사용 계약에 위배된 행위가 발견될 경우, 사용자는 당사가 확인 작업에서 부담한 비용을 부담하여야 하며, (주)한글과컴퓨터는 (주)한글과컴퓨터의 주소지를 관할하는 법원 또는 서울중앙지방법원에 제소하여 사용자에게 손해배상을 포함한 모든 법적 수단을 취할 수 있습니다. + +11. 사용권의 종료: 본 계약은 사용자가 프로그램과 그 부속물 및 보관본을 파기하거나 기타 사용자가 계약 내용을 준수하지 않는 등 본 계약의 목적을 달성할 수 없다고 (주)한글과컴퓨터가 판단할 경우에 사전에 종료될 수 있습니다. + +12. 사용자 정보 수집 및 이용: (주)한글과컴퓨터는 다음의 목적으로 사용자 정보를 수집합니다. 수집된 사용자 정보는 정해진 목적 이외의 용도로는 이용되지 않으며, 수집 목적이 변경될 경우 사전에 알리고 동의를 받을 예정입니다. + +① 수집(이용) 목적 및 개인정보를 제공받는 자 + +- 신규 서비스(제품) 개발, 접속 빈도 파악에 활용하기 위한 정보 저장 + +- 자동업데이트 및 말랑말랑 한컴스페이스 서비스 제공을 위한 정보 저장 및 전달 + +- 번역 서비스 제공을 위한 정보 전송 + +- 개인정보를 제공받는 자 (주)한컴인터프리, 주식회사 아큐플라이에이아이 + +② 수집하는 개인정보 항목 + +- 제품 정보 : 제품번호, 제품종류 + +- 로그 정보 : 인터넷 프로토콜 주소 + +- 번역 정보 : 번역할 문서의 내용 + +- 대화 정보 : 오피스 톡 대화 내역 + +- 말랑말랑 한컴스페이스 계정 정보 : 사용자 아이디 + +③ 개인정보의 보유 및 이용 기간: 자동업데이트 서비스 보안 및 침해 사고 대응을 위하여 자동업데이트 수행 시점마다 해당 정보를 수집하며, 수집된 정보는 1년간 로그 백업 장치를 통하여 보관하고 이후 즉시 파기합니다. 보다 상세한 개인정보 취급 방침은 (주)한글과컴퓨터 홈페이지(www.hancom.com)를 통해 확인하실 수 있습니다. + +13. 제품 등록: 구입한 소프트웨어에 대한 고객 지원 혜택을 얻기 위해서는 반드시 제품 등록을 하셔야 합니다. (주)한글과컴퓨터는 제품 등록을 마친 사용자에 한해서 고객 지원을 제공하여 드립니다. + +14. 고객 지원: (주)한글과컴퓨터는 제품 등록을 한 사용자에 한하여 관련 소프트웨어를 사용할 수 있는 시스템 환경에서 발생한 문제에 대한 기술적인 문의에 대하여 해결책을 제공하고자 최선을 다하며, 사용 불편에 따른 신고에 대한 결과 통보에도 최선을 다합니다. 고객 지원의 기간은 (주)한글과컴퓨터 홈페이지를 참조하시기 바랍니다. + +15. 인정: 귀하는 이 사용계약서에 명시된 모든 내용을 읽고 이해하며, 계약 조건에 동의하고, 나아가 이 내용이 이전 버전의 사용계약서나 과거의 모든 주문, 약속, 광고, 고지, 또는 서면 합의 사항에 우선하는 것임을 인정하는 데 동의합니다. + +16. 문의: 이 계약서에 대하여 의문 사항이 있으면, (주)한글과컴퓨터에 전화, 팩스, 온라인, 서신 등을 통하여 연락하여 주십시오. + +Copyright 1989. Hancom Inc. All rights reserved. diff --git a/overlays/hoffice/PKGBUILD b/overlays/hoffice/PKGBUILD new file mode 100644 index 0000000..2a15d80 --- /dev/null +++ b/overlays/hoffice/PKGBUILD @@ -0,0 +1,75 @@ +# Maintainer : 00ein00 + +HNCDIR=opt/hnc +HNCCONTEXT=opt/hnc/hoffice11/Bin/qt/plugins/platforminputcontexts +NIMFLIB=libqt5im-nimf.so +KIMELIB=libkime-qt-5.11.3.so + +DLAGENTS=("https::/usr/bin/wget -N --timestamping %u") + +pkgname='hoffice' +pkgver=11.20.0.1520 +pkgrel=4 +pkgdesc='Office document editor for Linux. Hancom Office Editor is an application to allow you to edit office documents that is developed and distributed by Hancom Inc. + / 본 어플리케이션은 리눅스용 문서 편집 프로그램으로, 한컴에 의해 개발되고 배포된 형식의 문서들을 편집할 수 있도록 해주는 프로그램입니다.' +arch=('x86_64') +source=( + 'https://dl.dropbox.com/scl/fi/ia3ub05nti01h8lzb3vwr/1732118678_hoffice_11.20.0.1520_amd64.deb?rlkey=8bnxl9chpm7rt6sr6nc4eoqp0&st=yaxlb481&dl=0' + 'LICENSE' + 'libqt5im-nimf.so' +) + +url='https://www.hancom.com' + +license=('custom:hoffice') +makedepends=('wget') +depends=('cairo' 'fontconfig' 'freetype2' 'gcc-libs' 'glibc' 'glu' 'harfbuzz' 'harfbuzz-icu' 'libcups' 'libcurl-gnutls' 'libxcb' 'openssl-1.1' 'qt5-base' 'qt5-x11extras' 'zlib') +provides=('hoffice=${pkgver}') +conflicts=('hoffice-hwp') +install=hoffice.install + +sha256sums=('1ecb2f82e915b49706d1f5f6d206f8bd4a9384fda2bd56798c94046865fe5730' + '09b74399a45cde2b28e672784dbd1eb6397454a025e05a51fb3367eadb834583' + 'd246c02a20a1e4ea123f9c2275dfc4a2ea091a65032ddbbe8a59bfc71418f60c') + +pre_remove() { + echo "Removing installed files..." + if [[ -f "/${HNCCONTEXT}/${NIMFLIB}" ]]; then + rm -vf "/${HNCCONTEXT}/${NIMFLIB}" + rm -rf "/${HNCDIR}" + fi +} + +post_remove() { + xdg-icon-resource forceupdate --theme hicolor &>/dev/null + update-desktop-database -q +} + +package() { + + curl -# -o "${srcdir}/${KIMELIB}" -fL 'https://github.com/Riey/kime/releases/latest/download/libkime-qt-5.11.3.so' + + bsdtar -xf "${srcdir}/data.tar.xz" -C "${pkgdir}/" + + install -Dm644 -t "${pkgdir}/usr/share/licenses/hoffice" "${srcdir}/LICENSE" + + if [ -f "${srcdir}/${KIMELIB}" ] && [ -f "${srcdir}/${NIMFLIB}" ]; then + install -Dm755 -t "${pkgdir}/${HNCCONTEXT}" "${srcdir}/${KIMELIB}" + install -Dm755 -t "${pkgdir}/${HNCCONTEXT}" "${srcdir}/${NIMFLIB}" + fi + + mkdir -p "$pkgdir"/usr/bin/ + echo "Creating symbolic link: /opt/hnc/hoffice11/Bin/hwp -> /usr/bin/hwp" + echo '"/opt/hnc/hoffice11/Bin/hwp" $@' >"$pkgdir"/usr/bin/hwp + chmod +x "$pkgdir"/usr/bin/hwp + echo "Creating symbolic link: /opt/hnc/hoffice11/Bin/hsl -> /usr/bin/hsl" + echo '"/opt/hnc/hoffice11/Bin/hsl" $@' >"$pkgdir"/usr/bin/hsl + chmod +x "$pkgdir"/usr/bin/hsl + echo "Creating symbolic link: /opt/hnc/hoffice11/Bin/hword -> /usr/bin/hword" + echo '"/opt/hnc/hoffice11/Bin/hword" $@' >"$pkgdir"/usr/bin/hword + chmod +x "$pkgdir"/usr/bin/hword + echo "Creating symbolic link: /opt/hnc/hoffice11/Bin/hcl -> /usr/bin/hcl" + echo '"/opt/hnc/hoffice11/Bin/hcl" $@' >"$pkgdir"/usr/bin/hcl + chmod +x "$pkgdir"/usr/bin/hcl + +} diff --git a/overlays/hoffice/default.nix b/overlays/hoffice/default.nix new file mode 100644 index 0000000..4549ace --- /dev/null +++ b/overlays/hoffice/default.nix @@ -0,0 +1,185 @@ +final: prev: +{ + hoffice = prev.stdenv.mkDerivation rec { + pname = "hoffice"; + version = "11.20.0.1520"; + + src = prev.fetchurl { + url = "https://dl.dropbox.com/scl/fi/ia3ub05nti01h8lzb3vwr/1732118678_hoffice_11.20.0.1520_amd64.deb?rlkey=8bnxl9chpm7rt6sr6nc4eoqp0&st=yaxlb481&dl=0"; + sha256 = "1ecb2f82e915b49706d1f5f6d206f8bd4a9384fda2bd56798c94046865fe5730"; + name = "hoffice-${version}.deb"; + }; + + kimeLib = prev.fetchurl { + url = "https://github.com/Riey/kime/releases/latest/download/libkime-qt-5.11.3.so"; + sha256 = "sha256-26udhVyqW+z5Calp3x4uSPM34/u1kSWViJv3LGWeEG0="; + }; + + nativeBuildInputs = with prev; [ + wget + libarchive + xdg-utils + makeWrapper + autoPatchelfHook + ]; + + dontWrapQtApps = true; + + # dontPatchELF = true; + + buildInputs = with prev; [ + cairo + fontconfig + freetype + glibc + libGLU + (harfbuzz.override { withIcu = true; }) + cups + curl + curlWithGnuTls + icu63 + openssl_1_1 + libxcb + libsForQt5.qtbase + libsForQt5.qtx11extras + libsForQt5.qtwayland + libsForQt5.qtmultimedia + libsForQt5.qtwebsockets + zlib + pulseaudio + gst_all_1.gstreamer + gst_all_1.gst-plugins-base + gst_all_1.gst-plugins-good + alsa-lib + nss + nspr + gtk3 + atk + pango + gdk-pixbuf + xorg.libXcursor + xorg.libXdamage + xorg.libXtst + xorg.libXrandr + xorg.libX11 + xorg.libXext + xorg.libXrender + xorg.libXi + xorg.libXfixes + xorg.libXcomposite + xorg.libXxf86vm + libdrm + mesa + libglvnd + kime + ]; + + unpackPhase = '' + mkdir -p $out/tmp + cd $out/tmp + bsdtar -xf ${src} + bsdtar -xf data.tar.xz + cd - + ''; + + installPhase = '' + mkdir -p $out/opt + cp -r $out/tmp/opt/hnc $out/opt/ + + mkdir -p $out/usr/share/licenses/hoffice + cp ${./LICENSE} $out/usr/share/licenses/hoffice/LICENSE + + # Install input method libraries + mkdir -p "$out/opt/hnc/hoffice11/Bin/qt/plugins/platforminputcontexts" + cp ${kimeLib} "$out/opt/hnc/hoffice11/Bin/qt/plugins/platforminputcontexts/libkime-qt-5.11.3.so" + + # Create wrapper scripts + mkdir -p $out/bin + libPath="${prev.lib.makeLibraryPath [ + prev.glibc + prev.libxcb + prev.libsForQt5.qtbase + prev.libsForQt5.qtx11extras + prev.libsForQt5.qtwayland + prev.libsForQt5.qtmultimedia + prev.libsForQt5.qtwebsockets + prev.cairo + prev.fontconfig + prev.freetype + (prev.harfbuzz.override { withIcu = true; }) + prev.icu63 + prev.cups + prev.curl + prev.curlWithGnuTls + prev.openssl_1_1 + prev.libGLU + prev.zlib + prev.pulseaudio + prev.gst_all_1.gstreamer + prev.gst_all_1.gst-plugins-base + prev.gst_all_1.gst-plugins-good + prev.alsa-lib + prev.nss + prev.nspr + prev.gtk3 + prev.atk + prev.pango + prev.gdk-pixbuf + prev.xorg.libXcursor + prev.xorg.libXdamage + prev.xorg.libXtst + prev.xorg.libXrandr + prev.xorg.libX11 + prev.xorg.libXext + prev.xorg.libXrender + prev.xorg.libXi + prev.xorg.libXfixes + prev.xorg.libXcomposite + prev.xorg.libXxf86vm + prev.libdrm + prev.mesa + prev.libglvnd + prev.kime + ]}" + for cmd in hwp hsl hword hcl; do + mv "$out/opt/hnc/hoffice11/Bin/$cmd" "$out/opt/hnc/hoffice11/Bin/$cmd.real" + makeWrapper "$out/opt/hnc/hoffice11/Bin/$cmd.real" "$out/opt/hnc/hoffice11/Bin/$cmd" \ + --set LD_LIBRARY_PATH "$libPath" \ + --set QT_QPA_PLATFORM xcb \ + --set QT_XCB_GL_INTEGRATION none \ + --set QT_OPENGL software \ + --set QT_QUICK_BACKEND software \ + --set LIBGL_ALWAYS_SOFTWARE 1 + makeWrapper "$out/opt/hnc/hoffice11/Bin/$cmd.real" "$out/bin/$cmd" \ + --set LD_LIBRARY_PATH "$libPath" \ + --set QT_QPA_PLATFORM xcb \ + --set QT_XCB_GL_INTEGRATION none \ + --set QT_OPENGL software \ + --set QT_QUICK_BACKEND software \ + --set LIBGL_ALWAYS_SOFTWARE 1 + done + + rm -rf $out/tmp + ''; + + postInstall = '' + xdg-icon-resource forceupdate --theme hicolor &>/dev/null || true + update-desktop-database -q || true + ''; + + meta = with prev.lib; { + description = "Office document editor for Linux - Hancom Office Editor"; + longDescription = '' + 본 어플리케이션은 리눅스용 문서 편집 프로그램으로, + 한컴에 의해 개발되고 배포된 형식의 문서들을 편집할 수 있도록 해주는 프로그램입니다. + ''; + homepage = "https://www.hancom.com"; + license = licenses.unfree; + platforms = [ "x86_64-linux" ]; + maintainers = [{ + name = "imnyang"; + email = "me@imnya.ng"; + }]; + }; + }; +} diff --git a/overlays/hoffice/hoffice.install b/overlays/hoffice/hoffice.install new file mode 100644 index 0000000..d1267d7 --- /dev/null +++ b/overlays/hoffice/hoffice.install @@ -0,0 +1,8 @@ +post_install() { + xdg-icon-resource forceupdate --theme hicolor &>/dev/null + update-desktop-database -q +} + +post_upgrade() { + post_install +} diff --git a/overlays/hoffice/libqt5im-nimf.so b/overlays/hoffice/libqt5im-nimf.so new file mode 100755 index 0000000..b066947 Binary files /dev/null and b/overlays/hoffice/libqt5im-nimf.so differ diff --git a/overlays/spotx.nix b/overlays/spotx.nix new file mode 100644 index 0000000..0377ed3 --- /dev/null +++ b/overlays/spotx.nix @@ -0,0 +1,48 @@ +final: prev: +let + spotx = prev.fetchurl { + url = "https://raw.githubusercontent.com/SpotX-Official/SpotX-Bash/c9b506c7749f853c827b6d4bd1d57818f953f68d/spotx.sh"; + hash = "sha256-irUHPR0Qdff2dpVtLNKGhgBBSd7Es1z7TkamxWi6JtI="; + }; + + # 맥 여부를 변수로 저장 + isDarwin = prev.stdenv.isDarwin; +in +{ + spotify = prev.spotify.overrideAttrs (old: { + # 1. 의존성은 플랫폼에 상관없이 추가 (맥에서도 빌드 도구로 쓰일 수 있음) + nativeBuildInputs = (old.nativeBuildInputs or [ ]) ++ (with prev; [ + util-linux + perl + unzip + zip + curl + ]); + + # 2. unpackPhase: 맥이 아닐 때만 shebang 패치 적용 + unpackPhase = if (old ? unpackPhase && !isDarwin) then + builtins.replaceStrings + [ "runHook postUnpack" ] + [ + '' + patchShebangs --build ${spotx} + runHook postUnpack + '' + ] + old.unpackPhase + else old.unpackPhase or null; + + # 3. installPhase: 맥이 아닐 때만 SpotX 스크립트 실행 + installPhase = if (old ? installPhase && !isDarwin) then + builtins.replaceStrings + [ "runHook postInstall" ] + [ + '' + bash ${spotx} -f -P "$out/share/spotify" + runHook postInstall + '' + ] + old.installPhase + else old.installPhase or null; + }); +}