Files
AZ-NIX-CLIENTS/roles/thin-client/default.nix
T
m3ta-chiron 98dc2917e8 feat: +thin-client role + AZ-TC-01..03 pilot
Auf Basis des Grilling-Sessions mit 20 design decisions umgesetztes
v1-Skeleton der Thin-Client-Rolle plus 3 Pilot-Hosts.

Architektur:
- roles/thin-client/ als geschlossene Rolle (default.nix compose + 7
  Subdirectories: hardware, session, identity, network, peripherals,
  apps, monitoring, deployment)
- hosts/AZ-TC-NN/default.nix als ~20-Zeilen-Wrapper pro Fleet-Host
- flake.nix instanziiert AZ-TC-01..03 via Fleet-Helper
- secrets.nix mit per-host agenix-Secret-Stubs

Submodule:
- hardware: dell-optiplex-micro + generic-x86_64-uefi Fallback
- identity: AD (sssd/krb5/keytab via agenix), lokale Notfalluser
  (sascha.koenig + jannik.mueller ohne m3ta-home), sudo-Policy
- session: KDE Plasma 6 + Wayland + SDDM, Branding (Wallpaper + Footer),
  PipeWire Audio
- network: NetworkManager + wpa_supplicant + 802.1X EAP-TLS, NetBird
  + SSH via NetBird, systemd-resolved (Corp + NetBird DNS), hardened
  firewall, OpenSSH
- peripherals: CUPS mit Pull-Print-Queue, pam_mount für DFS-Shares
- apps: Chromium (ManagedBookmarks, Bitwarden force-install, no local
  passwords), Office-Web .desktop-Shortcuts, Remmina (mehrere TS,
  Kerberos SSO), RustDesk Client + Daemon, OBS Studio, Autostart
- monitoring: node_exporter → Pushgateway, Alloy (stub für Loki),
  Snipe-IT Asset-Checkin (stub)
- deployment: Disko BTRFS-Layout, auto-upgrade daily + reboot window,
  snapper snapshots

Build-Validierung: 'nix flake check' bestanden für AZ-TC-01/02/03.

Siehe roles/thin-client/README.md für den Provisionierungs-Workflow
und die Liste der noch auszufüllenden Platzhalter (TODO-Kommentare
in den jeweiligen Modulen).
2026-07-29 08:34:01 +02:00

115 lines
3.6 KiB
Nix

# roles/thin-client/default.nix
#
# Top-level NixOS role module for the AZ-NIX-CLIENTS Thin Client fleet
# (AZ-TC-01..NN). Replaces a Windows 10 workstation with a locked-down
# NixOS + KDE Plasma client that authenticates against Active Directory
# and provides pre-configured RDP, browser, and Office-Web access.
#
# A Fleet Host (hosts/AZ-TC-NN/default.nix) only needs to set:
# az.tc.enable = true;
# az.tc.hardwareClass = "dell-optiplex-micro";
# networking.hostName = "AZ-TC-01";
# Everything else is composed by this role.
#
# See roles/thin-client/README.md for the provisioning workflow.
{
config,
lib,
pkgs,
...
}: let
cfg = config.az.tc;
in {
imports = [
./hardware
./session
./identity
./network
./peripherals
./apps
./monitoring
./deployment
];
options.az.tc = {
enable = lib.mkEnableOption "the AzIntec Thin Client role (KDE Plasma + AD + RDP fleet host)";
hardwareClass = lib.mkOption {
type = lib.types.enum ["dell-optiplex-micro" "generic-x86_64-uefi"];
default = "generic-x86_64-uefi";
description = ''
Hardware class of the Thin Client. Selects the appropriate
kernel modules, firmware, and video driver under
`roles/thin-client/hardware/`.
'';
};
site = lib.mkOption {
type = lib.types.str;
default = "default";
description = ''
Site identifier (e.g. "BER", "MUC"). Currently informational;
reserved for per-site printer maps or branding variations.
'';
};
};
config = lib.mkIf cfg.enable {
# ── Fleet-wide base configuration ────────────────────────────────
# Everything that every Thin Client needs regardless of which
# submodule pulls it in. Submodules opt-in via mkIf themselves.
# We do NOT import hosts/common here — that pulls nushell as default
# shell and m3ta-home profile system, neither of which belongs on a
# Thin Client. The minimum system config is set explicitly below.
nixpkgs.hostPlatform = "x86_64-linux";
nixpkgs.config.allowUnfree = true;
nix = {
settings = {
experimental-features = "nix-command flakes";
trusted-users = ["root"];
};
gc = {
automatic = true;
dates = "weekly";
options = "--delete-older-than 14d";
};
optimise.automatic = true;
};
# Thin Clients are managed centrally; users do not run nix commands.
users.defaultUserShell = pkgs.bash;
# Console / i18n / time — matches AZ-LT-NIX conventions.
i18n.defaultLocale = "de_DE.UTF-8";
time.timeZone = "Europe/Berlin";
console.useXkbConfig = true;
# Persistence-relevant state lives on the BTRFS root; nothing
# tmpfs-related here. /home persists per-user (Q6: "alles persistieren").
# Polkit for udisks/colord/etc. — needed so non-root users can mount
# USB sticks, change brightness, etc.
security.polkit.enable = true;
# XDG portal wiring for Wayland screen-capture (RustDesk + OBS).
environment.pathsToLink = [
"/share/xdg-desktop-portal"
"/share/applications"
];
# SSH is enabled by the network module (via NetBird only).
# Firewall is enabled by the network module.
# ── assertions / warnings ────────────────────────────────────────
assertions = [
{
assertion = cfg.enable -> (config.networking.hostName or "") != "";
message = "az.tc.enable requires networking.hostName to be set (e.g. 'AZ-TC-01').";
}
];
};
}