# roles/thin-client/default.nix # # Top-level NixOS role module for the AZ-NIX-CLIENTS Thin Client fleet # (AZ-TC-01..NN). Replaces a Windows 10 workstation with a locked-down # NixOS + KDE Plasma client that authenticates against Active Directory # and provides pre-configured RDP, browser, and Office-Web access. # # A Fleet Host (hosts/AZ-TC-NN/default.nix) only needs to set: # az.tc.enable = true; # az.tc.hardwareClass = "dell-optiplex-micro"; # networking.hostName = "AZ-TC-01"; # Everything else is composed by this role. # # See roles/thin-client/README.md for the provisioning workflow. { config, lib, pkgs, ... }: let cfg = config.az.tc; in { imports = [ ./hardware ./session ./identity ./network ./peripherals ./apps ./monitoring ./deployment ]; options.az.tc = { enable = lib.mkEnableOption "the AzIntec Thin Client role (KDE Plasma + AD + RDP fleet host)"; hardwareClass = lib.mkOption { type = lib.types.enum ["dell-optiplex-micro" "generic-x86_64-uefi"]; default = "generic-x86_64-uefi"; description = '' Hardware class of the Thin Client. Selects the appropriate kernel modules, firmware, and video driver under `roles/thin-client/hardware/`. ''; }; site = lib.mkOption { type = lib.types.str; default = "default"; description = '' Site identifier (e.g. "BER", "MUC"). Currently informational; reserved for per-site printer maps or branding variations. ''; }; }; config = lib.mkIf cfg.enable { # ── Fleet-wide base configuration ──────────────────────────────── # Everything that every Thin Client needs regardless of which # submodule pulls it in. Submodules opt-in via mkIf themselves. # We do NOT import hosts/common here — that pulls nushell as default # shell and m3ta-home profile system, neither of which belongs on a # Thin Client. The minimum system config is set explicitly below. nixpkgs.hostPlatform = "x86_64-linux"; nixpkgs.config.allowUnfree = true; nix = { settings = { experimental-features = "nix-command flakes"; trusted-users = ["root"]; }; gc = { automatic = true; dates = "weekly"; options = "--delete-older-than 14d"; }; optimise.automatic = true; }; # Thin Clients are managed centrally; users do not run nix commands. users.defaultUserShell = pkgs.bash; # Console / i18n / time — matches AZ-LT-NIX conventions. i18n.defaultLocale = "de_DE.UTF-8"; time.timeZone = "Europe/Berlin"; console.useXkbConfig = true; # Persistence-relevant state lives on the BTRFS root; nothing # tmpfs-related here. /home persists per-user (Q6: "alles persistieren"). # Polkit for udisks/colord/etc. — needed so non-root users can mount # USB sticks, change brightness, etc. security.polkit.enable = true; # XDG portal wiring for Wayland screen-capture (RustDesk + OBS). environment.pathsToLink = [ "/share/xdg-desktop-portal" "/share/applications" ]; # SSH is enabled by the network module (via NetBird only). # Firewall is enabled by the network module. # ── assertions / warnings ──────────────────────────────────────── assertions = [ { assertion = cfg.enable -> (config.networking.hostName or "") != ""; message = "az.tc.enable requires networking.hostName to be set (e.g. 'AZ-TC-01')."; } ]; }; }