0cc0b5064d
Tiefen-Validierung via 'nix build .#nixosConfigurations.AZ-TC-NN.config.
system.build.toplevel' hat mehrere reale Bugs gefunden, die 'nix flake
check' nicht sah. Alle drei Pilot-Hosts bauen jetzt sauber durch.
Gefixst:
- freerdp3 → freerdp (umbenannt in nixpkgs-unstable)
- SDDM Theme.Logo will INI-Atom (string), nicht Nix-path → '${path}'
- security.pam.mount.extraVolumes will list-of-string, nicht ein String
- sudoers: 'domain admins' muss als 'domain\ admins' escaped werden
- agenix file-Pfade: ../../secrets/ → ../../../secrets/ (Tiefe korrigiert)
- snapper: config.services.snapper.package gibt es nicht → pkgs.snapper
- samba4Full entfernt (blockiert durch ceph-common python metadata issue
in nixpkgs-unstable; Thin Clients brauchen es nicht — cifs-utils reicht)
- corp-wifi-ca.pem durch gültiges Dummy-PEM ersetzt (openssl-generiert,
mit明显 REPLACE-MARKER; build kann PEM parsen)
Functional gemacht:
- Alloy: echtes River-Config mit loki.source.journal + loki.write statt
barem logging-stub. Journal-Logs mit host/unit/severity-Labels nach
Loki.
- Snipe-IT: echte Check-in-Logik via curl + jq. Lookup by asset_tag,
PATCH falls exists, POST falls neu. startAt täglich 03:30. API-Token
via agenix (snipeit-api-token.age).
- node_exporter push: realer curl-Push alle 60s mit retry on failure.
Safety:
- Placeholder-Assertions in roles/thin-client/default.nix: build schlägt
fehl, wenn wifi.ssid/hotline/company noch Placeholder sind (außer
site='staging'). Pilot-Hosts haben site='staging' bis echte Werte da.
- assets/corp-wifi-ca.pem hat deutlich sichtbaren REPLACE-Hinweis.
Neue Options:
- az.tc.monitoring.snipeItUrl (default: snipeit.az-group.local)
Neue Secrets (Placeholder .age-Files zum Ausfüllen):
- snipeit-api-token.age (fleet-wide shared)
87 lines
2.7 KiB
Nix
87 lines
2.7 KiB
Nix
# roles/thin-client/session/branding.nix
|
|
#
|
|
# Light branding: corporate wallpaper, SDDM logo overlay, Breeze Light,
|
|
# Property-of-footer (hostname + IT hotline) on the lock screen.
|
|
# Q17 decisions: Light Branding, no login banner, user may adjust KDE.
|
|
{
|
|
config,
|
|
lib,
|
|
pkgs,
|
|
...
|
|
}: let
|
|
inherit (lib) mkIf;
|
|
cfg = config.az.tc;
|
|
in {
|
|
options.az.tc.branding = {
|
|
hotline = lib.mkOption {
|
|
type = lib.types.str;
|
|
default = "+49 30 1234567"; # TODO: real hotline
|
|
description = "IT-Hotline phone number for the property-of footer.";
|
|
};
|
|
wallpaper = lib.mkOption {
|
|
type = lib.types.path;
|
|
default = ./assets/wallpaper.svg;
|
|
description = ''
|
|
Path to a corporate wallpaper image (JPEG or SVG). Replace
|
|
`roles/thin-client/session/assets/wallpaper.svg` with the real
|
|
asset, or override this option.
|
|
'';
|
|
};
|
|
logo = lib.mkOption {
|
|
type = lib.types.path;
|
|
default = ./assets/logo.svg;
|
|
description = ''
|
|
Path to the corporate logo (SVG or PNG). Used in SDDM and lock
|
|
screen footer.
|
|
'';
|
|
};
|
|
company = lib.mkOption {
|
|
type = lib.types.str;
|
|
default = "AzIntec GmbH";
|
|
description = "Company name shown in the property-of footer.";
|
|
};
|
|
};
|
|
|
|
config = mkIf cfg.enable {
|
|
environment = {
|
|
etc = {
|
|
# Wallpaper — install to /etc/az-wallpaper so KDE's wallpaper plugin
|
|
# can find it via the standard search path.
|
|
"az-wallpaper".source = config.az.tc.branding.wallpaper;
|
|
|
|
# Default Plasma configuration as /etc/xdg — KDE reads these as
|
|
# the system-wide defaults. User-specific changes are layered on top.
|
|
"xdg/kdeglobals".text = ''
|
|
[General]
|
|
ColorScheme=Breeze Light
|
|
|
|
[KDE]
|
|
widgetStyle=Breeze
|
|
|
|
[Icons]
|
|
Theme=breeze
|
|
|
|
[Wallpaper]
|
|
Image=file:///etc/az-wallpaper
|
|
'';
|
|
|
|
# Lock-screen footer (rendered by kscreenlocker_greet).
|
|
"xdg/kscreenlockerrc".text = ''
|
|
[Greeter]
|
|
Logo=${config.az.tc.branding.logo}
|
|
Footer=${config.az.tc.branding.company} · ${config.networking.hostName} · IT-Hotline: ${config.az.tc.branding.hotline}
|
|
'';
|
|
};
|
|
};
|
|
|
|
# Property-of-footer via SDDM theme config. Lightweight: we don't
|
|
# ship a full custom SDDM theme — we just set the footer string that
|
|
# the default Breeze SDDM theme shows. SDDM's settings module wants
|
|
# strings (INI atoms), not Nix paths, so we use absolute paths.
|
|
services.displayManager.sddm.settings.Theme = {
|
|
Wallpaper = "${config.az.tc.branding.wallpaper}";
|
|
Logo = "${config.az.tc.branding.logo}";
|
|
};
|
|
};
|
|
}
|