Files
m3ta-chiron 98dc2917e8 feat: +thin-client role + AZ-TC-01..03 pilot
Auf Basis des Grilling-Sessions mit 20 design decisions umgesetztes
v1-Skeleton der Thin-Client-Rolle plus 3 Pilot-Hosts.

Architektur:
- roles/thin-client/ als geschlossene Rolle (default.nix compose + 7
  Subdirectories: hardware, session, identity, network, peripherals,
  apps, monitoring, deployment)
- hosts/AZ-TC-NN/default.nix als ~20-Zeilen-Wrapper pro Fleet-Host
- flake.nix instanziiert AZ-TC-01..03 via Fleet-Helper
- secrets.nix mit per-host agenix-Secret-Stubs

Submodule:
- hardware: dell-optiplex-micro + generic-x86_64-uefi Fallback
- identity: AD (sssd/krb5/keytab via agenix), lokale Notfalluser
  (sascha.koenig + jannik.mueller ohne m3ta-home), sudo-Policy
- session: KDE Plasma 6 + Wayland + SDDM, Branding (Wallpaper + Footer),
  PipeWire Audio
- network: NetworkManager + wpa_supplicant + 802.1X EAP-TLS, NetBird
  + SSH via NetBird, systemd-resolved (Corp + NetBird DNS), hardened
  firewall, OpenSSH
- peripherals: CUPS mit Pull-Print-Queue, pam_mount für DFS-Shares
- apps: Chromium (ManagedBookmarks, Bitwarden force-install, no local
  passwords), Office-Web .desktop-Shortcuts, Remmina (mehrere TS,
  Kerberos SSO), RustDesk Client + Daemon, OBS Studio, Autostart
- monitoring: node_exporter → Pushgateway, Alloy (stub für Loki),
  Snipe-IT Asset-Checkin (stub)
- deployment: Disko BTRFS-Layout, auto-upgrade daily + reboot window,
  snapper snapshots

Build-Validierung: 'nix flake check' bestanden für AZ-TC-01/02/03.

Siehe roles/thin-client/README.md für den Provisionierungs-Workflow
und die Liste der noch auszufüllenden Platzhalter (TODO-Kommentare
in den jeweiligen Modulen).
2026-07-29 08:34:01 +02:00

52 lines
1.8 KiB
Nix
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# roles/thin-client/hardware/dell-optiplex-micro.nix
#
# Hardware class for Dell OptiPlex Micro (3020/3040/5040/7040).
# These are 5th7th gen Intel Core mini-PCs, all using Intel i915 graphics,
# all UEFI-bootable. Driver-wise they're nearly identical.
#
# Notes:
# - 3020 (Broadwell, 5th gen) — slightly older firmware, but i915 supports it.
# - 3040/5040 (Skylake, 6th gen) — mainstream.
# - 7040 (Skylake/Kaby Lake, 6th/7th gen) — some vPro variants exist.
# All variants: Intel ME present (mostly inactive unless explicitly provisioned).
{
config,
lib,
pkgs,
...
}: {
config = lib.mkIf (config.az.tc.enable && config.az.tc.hardwareClass == "dell-optiplex-micro") {
boot = {
loader.systemd-boot.enable = true;
loader.efi.canTouchEfiVariables = true;
initrd.kernelModules = ["i915" "snd_hda_intel"];
kernelModules = ["i915" "thinkpad_acpi" "coretemp"];
kernelParams = [
# Quiet boot for kiosk-like feel
"quiet"
"splash"
# Avoid rare i915 glitches on Skylake
"i915.enable_guc=2"
];
kernelPackages = pkgs.linuxPackages_latest;
};
services.xserver.videoDrivers = ["modesetting"];
# Firmware for Intel WiFi/BT on these models
hardware.enableRedistributableFirmware = true;
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
# Audio via Pipewire (set up in session/default.nix); just ensure
# sound firmware is present.
hardware.firmware = lib.mkDefault [pkgs.sof-firmware];
# Suspend/wake — Thin Clients are typically always-on; disable sleep
# to avoid Wake-on-LAN issues on the Dell NIC.
systemd.targets.sleep.enable = false;
systemd.targets.suspend.enable = false;
systemd.targets.hibernate.enable = false;
systemd.targets.hybrid-sleep.enable = false;
};
}