98dc2917e8
Auf Basis des Grilling-Sessions mit 20 design decisions umgesetztes v1-Skeleton der Thin-Client-Rolle plus 3 Pilot-Hosts. Architektur: - roles/thin-client/ als geschlossene Rolle (default.nix compose + 7 Subdirectories: hardware, session, identity, network, peripherals, apps, monitoring, deployment) - hosts/AZ-TC-NN/default.nix als ~20-Zeilen-Wrapper pro Fleet-Host - flake.nix instanziiert AZ-TC-01..03 via Fleet-Helper - secrets.nix mit per-host agenix-Secret-Stubs Submodule: - hardware: dell-optiplex-micro + generic-x86_64-uefi Fallback - identity: AD (sssd/krb5/keytab via agenix), lokale Notfalluser (sascha.koenig + jannik.mueller ohne m3ta-home), sudo-Policy - session: KDE Plasma 6 + Wayland + SDDM, Branding (Wallpaper + Footer), PipeWire Audio - network: NetworkManager + wpa_supplicant + 802.1X EAP-TLS, NetBird + SSH via NetBird, systemd-resolved (Corp + NetBird DNS), hardened firewall, OpenSSH - peripherals: CUPS mit Pull-Print-Queue, pam_mount für DFS-Shares - apps: Chromium (ManagedBookmarks, Bitwarden force-install, no local passwords), Office-Web .desktop-Shortcuts, Remmina (mehrere TS, Kerberos SSO), RustDesk Client + Daemon, OBS Studio, Autostart - monitoring: node_exporter → Pushgateway, Alloy (stub für Loki), Snipe-IT Asset-Checkin (stub) - deployment: Disko BTRFS-Layout, auto-upgrade daily + reboot window, snapper snapshots Build-Validierung: 'nix flake check' bestanden für AZ-TC-01/02/03. Siehe roles/thin-client/README.md für den Provisionierungs-Workflow und die Liste der noch auszufüllenden Platzhalter (TODO-Kommentare in den jeweiligen Modulen).
145 lines
4.2 KiB
Nix
145 lines
4.2 KiB
Nix
{
|
|
description = ''
|
|
For questions just DM me on X: https://twitter.com/@m3tam3re
|
|
There is also some NIXOS content on my YT channel: https://www.youtube.com/@m3tam3re
|
|
|
|
One of the best ways to learn NIXOS is to read other peoples configurations. I have personally learned a lot from Gabriel Fontes configs:
|
|
https://github.com/Misterio77/nix-starter-configs
|
|
https://github.com/Misterio77/nix-config
|
|
|
|
Please also check out the starter configs mentioned above.
|
|
'';
|
|
|
|
inputs = {
|
|
home-manager = {
|
|
url = "github:nix-community/home-manager";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
|
|
nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable";
|
|
nixpkgs-stable.url = "github:nixos/nixpkgs/nixos-25.11";
|
|
|
|
m3ta-nixpkgs.url = "git+https://code.m3ta.dev/m3tam3re/nixpkgs";
|
|
m3ta-home = {
|
|
# url = "path:/home/sascha.koenig/p/NIX/m3ta-home";
|
|
url = "git+ssh://gitea@code.m3ta.dev/m3tam3re/m3ta-home";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
|
|
llm-agents.url = "github:numtide/llm-agents.nix";
|
|
|
|
nur = {
|
|
url = "github:nix-community/NUR";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
|
|
disko = {
|
|
url = "github:nix-community/disko";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
|
|
agenix.url = "github:ryantm/agenix";
|
|
|
|
nixos-anywhere = {
|
|
url = "github:nix-community/nixos-anywhere";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
agents = {
|
|
# url = "path:/home/m3tam3re/p/AI/AGENTS";
|
|
url = "git+ssh://gitea@code.m3ta.dev/m3tam3re/AGENTS";
|
|
};
|
|
nix-colors.url = "github:misterio77/nix-colors";
|
|
};
|
|
|
|
outputs = {
|
|
self,
|
|
agenix,
|
|
disko,
|
|
nixpkgs,
|
|
m3ta-nixpkgs,
|
|
...
|
|
} @ inputs: let
|
|
inherit (self) outputs;
|
|
systems = [
|
|
"aarch64-linux"
|
|
"i686-linux"
|
|
"x86_64-linux"
|
|
"aarch64-darwin"
|
|
"x86_64-darwin"
|
|
];
|
|
forAllSystems = nixpkgs.lib.genAttrs systems;
|
|
in {
|
|
packages =
|
|
forAllSystems (system: import ./pkgs nixpkgs.legacyPackages.${system});
|
|
overlays = let
|
|
all = import ./overlays {inherit inputs;};
|
|
in
|
|
removeAttrs all ["mkLlmAgentsOverlay"];
|
|
lib.mkLlmAgentsOverlay = (import ./overlays {inherit inputs;}).mkLlmAgentsOverlay;
|
|
|
|
devShells = forAllSystems (system: let
|
|
pkgs = import nixpkgs {
|
|
inherit system;
|
|
config.allowUnfree = true; # Allow unfree packages in devShell
|
|
};
|
|
in {
|
|
default = pkgs.mkShell {
|
|
buildInputs = with pkgs; [
|
|
alejandra
|
|
nixd
|
|
openssh
|
|
agenix.packages.${system}.default
|
|
statix
|
|
deadnix
|
|
];
|
|
};
|
|
});
|
|
|
|
nixosConfigurations = {
|
|
AZ-LT-NIX = inputs.nixpkgs.lib.nixosSystem {
|
|
specialArgs = {
|
|
inherit inputs outputs;
|
|
system = "x86_64-linux";
|
|
};
|
|
modules = [
|
|
./hosts/AZ-LT-NIX
|
|
agenix.nixosModules.default
|
|
inputs.home-manager.nixosModules.home-manager
|
|
m3ta-nixpkgs.nixosModules.default
|
|
];
|
|
};
|
|
|
|
# ── Thin Client fleet (AZ-TC-NN) ──────────────────────────────
|
|
# Each host is a minimal wrapper around the thin-client role.
|
|
# Add new hosts by:
|
|
# 1. Create hosts/AZ-TC-NN/default.nix (copy from AZ-TC-01).
|
|
# 2. Add an entry here.
|
|
# 3. Run `agenix -e secrets/AZ-TC-NN-*.age` to provision secrets.
|
|
AZ-TC-01 = inputs.nixpkgs.lib.nixosSystem {
|
|
specialArgs = {inherit inputs outputs; system = "x86_64-linux";};
|
|
modules = [
|
|
disko.nixosModules.disko
|
|
agenix.nixosModules.default
|
|
./hosts/AZ-TC-01
|
|
];
|
|
};
|
|
AZ-TC-02 = inputs.nixpkgs.lib.nixosSystem {
|
|
specialArgs = {inherit inputs outputs; system = "x86_64-linux";};
|
|
modules = [
|
|
disko.nixosModules.disko
|
|
agenix.nixosModules.default
|
|
./hosts/AZ-TC-02
|
|
];
|
|
};
|
|
AZ-TC-03 = inputs.nixpkgs.lib.nixosSystem {
|
|
specialArgs = {inherit inputs outputs; system = "x86_64-linux";};
|
|
modules = [
|
|
disko.nixosModules.disko
|
|
agenix.nixosModules.default
|
|
./hosts/AZ-TC-03
|
|
];
|
|
};
|
|
};
|
|
};
|
|
}
|