Compare commits

..
14 Commits
Author SHA1 Message Date
k3t 4772a085ae rename a few things, add minizen host, rebase with other changes 2026-09-04 15:52:13 -06:00
k3t a00258ed3d disable redundant features 2026-09-03 08:28:03 +00:00
k3t 1eb528fdc7 oops 2026-09-03 07:52:55 +00:00
k3t 900a830660 add nvidia support 2026-09-03 07:52:07 +00:00
k3t 4e32f3c193 flake update 2026-08-27 18:20:33 -06:00
k3t 8f32d561f5 flake update 2026-08-23 15:08:14 -06:00
k3t e766d73c6d e 2026-08-09 14:05:20 -06:00
k3t 550b91fd59 disable nftables again 2026-08-09 14:02:28 -06:00
k3t 9d5b87e036 e 2026-08-09 13:01:49 -06:00
k3t 7b729d68aa e 2026-08-09 12:53:34 -06:00
k3t 71b94afced e 2026-08-09 12:52:44 -06:00
k3t af7fee8ea7 e 2026-08-09 12:50:41 -06:00
k3t b8594b37b5 enable ios support on tbb 2026-08-09 12:50:13 -06:00
k3t f39b398e8a add ios support 2026-08-09 12:48:45 -06:00
14 changed files with 290 additions and 80 deletions
Generated
+22 -22
View File
@@ -37,11 +37,11 @@
"nixpkgs": "nixpkgs" "nixpkgs": "nixpkgs"
}, },
"locked": { "locked": {
"lastModified": 1786031233, "lastModified": 1788229478,
"narHash": "sha256-TIDlLTLI1/pB7IqgjzcKQjpODQsZE2oII4XGG9B6KjI=", "narHash": "sha256-G0F2rFORVcFkEvVdE/qWQTnYekIc77YP5/vRF9nZlxU=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "7834e82588860aaf780cec1366524456a70898d7", "rev": "1dc2d1f720ab17fc7981e087346bf54b26d284b1",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -97,11 +97,11 @@
"nixpkgs": "nixpkgs_3" "nixpkgs": "nixpkgs_3"
}, },
"locked": { "locked": {
"lastModified": 1785770546, "lastModified": 1788146779,
"narHash": "sha256-I1csyD4Z1uHxJ8NOvdEOXYjtEEI3J3bBvXylzlzLRPc=", "narHash": "sha256-DPpSweCi/XNpD7r2mrL83gaN0/UsQIF6ihb2HY2G2Jc=",
"owner": "cynicsketch", "owner": "cynicsketch",
"repo": "nix-mineral", "repo": "nix-mineral",
"rev": "a488ad7d35f658f0d7bd8363bbf3be32bcd992a3", "rev": "9e05f8a852c7ca53e797379deef275b608d47ef4",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -115,11 +115,11 @@
"nixpkgs": "nixpkgs_4" "nixpkgs": "nixpkgs_4"
}, },
"locked": { "locked": {
"lastModified": 1785232496, "lastModified": 1788044418,
"narHash": "sha256-65EQYIRRpTdpH8lUiB6Mvo5uBkG60aBIzAJuALfx+O0=", "narHash": "sha256-cmOd3iGoE140M2GidgQMQbyxHZ4dT7C0QZq2+CrXQyA=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixos-hardware", "repo": "nixos-hardware",
"rev": "2e790b0a6be8ec2b76174ac0931b8ff11919ec98", "rev": "dc3f0cfde2050172abf6c3cdb684f735c15a57c5",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -131,11 +131,11 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1785141334, "lastModified": 1787209939,
"narHash": "sha256-kh35kIx7el4Jk8Ki3BH9/Pn1eZYSYLJ6LMALos0zOy0=", "narHash": "sha256-WvvHR4kSQLAbtouMC/ruZ5UpLwlUcY3K4FAllMN+yGk=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "38a4887411571457d700c51c64a6e49ead2ed5ab", "rev": "391b592eb44808b3bd0cb80bb71b63a5a118b8bb",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -207,11 +207,11 @@
}, },
"nixpkgs_5": { "nixpkgs_5": {
"locked": { "locked": {
"lastModified": 1785967620, "lastModified": 1788179007,
"narHash": "sha256-IItrdb7Puk05RqOBWZYFC5X6Wl1sJmCfh5MWVHw5iMM=", "narHash": "sha256-hn1oU2rue2SYK8dAr8+WNZWtbsz1S2W5mnHlSEuh3bo=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "b7c2ada94fe99c15b0dbcf4d11fd7850b957a436", "rev": "34ab99075ac4f7e40cf037eef32cb1c360bb85e9",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -223,11 +223,11 @@
}, },
"nixpkgs_6": { "nixpkgs_6": {
"locked": { "locked": {
"lastModified": 1785571196, "lastModified": 1787900134,
"narHash": "sha256-xwSqxTsama0YTtS78+4YyCm6jJg09v78QWfP1cAyoVA=", "narHash": "sha256-5GWj0FI2uOwKNpXkmpWrSFDe1rCaNBCUQ8d+HDtFQPI=",
"rev": "148bab9c1c3c53136ecb44a6ea356a0ed5b39b06", "rev": "83199d0d373dd3ac2b9a1996b1d0263f76ab7a4c",
"type": "tarball", "type": "tarball",
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1045728.148bab9c1c3c/nixexprs.tar.xz" "url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1063296.83199d0d373d/nixexprs.tar.xz"
}, },
"original": { "original": {
"type": "tarball", "type": "tarball",
@@ -250,11 +250,11 @@
"systems": "systems" "systems": "systems"
}, },
"locked": { "locked": {
"lastModified": 1785652745, "lastModified": 1788083617,
"narHash": "sha256-pD0VE/XwjQ3tLyxTzXKdm6JuIEWr/Jaote6xpXGZrXk=", "narHash": "sha256-aXMDRUxm/9se+vgKViKdDcClk1k3qA3sUwT0kAYo3Fg=",
"owner": "Gerg-L", "owner": "Gerg-L",
"repo": "spicetify-nix", "repo": "spicetify-nix",
"rev": "802040514e09bb8539237f52f68cf053b987c65e", "rev": "bf4ed54253a61c8324a5b461638c42db77c0b980",
"type": "github" "type": "github"
}, },
"original": { "original": {
+24 -45
View File
@@ -42,19 +42,6 @@
in { in {
nixosConfigurations = { nixosConfigurations = {
# repurposed for use as nas
#"TheBlackBox" = mkHost "x86_64-linux" [
# ./modules/common.nix
# ./modules/desktop-common.nix
# ./hosts/desktop/configuration.nix
# spicetify-nix.nixosModules.spicetify
# home-manager.nixosModules.home-manager
# {
# home-manager.useGlobalPkgs = true;
# home-manager.useUserPackages = true;
# home-manager.users.k3t = ./home/desktop.nix;
# }
#];
"TheBlackBox" = mkHost "x86_64-linux" [ "TheBlackBox" = mkHost "x86_64-linux" [
./modules/audio/base.nix ./modules/audio/base.nix
./modules/audio/zeroconf.nix ./modules/audio/zeroconf.nix
@@ -87,24 +74,30 @@
./modules/sys/fs/btrfs.nix ./modules/sys/fs/btrfs.nix
./modules/sys/fs/mounts/efi.nix ./modules/sys/fs/mounts/efi.nix
./modules/sys/fs/mounts/btrfs/tbb-btrfs.nix ./modules/sys/fs/mounts/btrfs/btrfs-with-subvols.nix
./modules/sys/fs/mounts/swap.nix ./modules/sys/fs/mounts/swap.nix
./modules/sys/hw/boot.nix ./modules/sys/hw/boot.nix
./modules/sys/hw/libinput.nix ./modules/sys/hw/libinput.nix
<<<<<<< HEAD
./modules/sys/hw/cpu/amd64.nix ./modules/sys/hw/cpu/amd64.nix
./modules/sys/hw/gpu/amd.nix ./modules/sys/hw/gpu/nvidia.nix
./modules/sys/hw/gpu/vmware.nix ./modules/sys/hw/gpu/vmware.nix
=======
./modules/sys/hw/cpu/intel.nix
./modules/sys/hw/gpu/nvidia.nix
>>>>>>> 29fc11b (whole lotta changes, check individual files)
./modules/sys/hw/input/keyboard.nix ./modules/sys/hw/input/keyboard.nix
./modules/sys/hw/input/tablet.nix ./modules/sys/hw/input/tablet.nix
./modules/sys/hw/input/xbox.nix ./modules/sys/hw/input/xbox.nix
./modules/sys/hw/misc/ios.nix
./modules/sys/nix.nix ./modules/sys/nix.nix
./modules/sys/perf.nix ./modules/sys/perf.nix
./modules/sys/pkgs.nix ./modules/sys/pkgs.nix
./modules/sys/rc/openssh.nix ./modules/sys/rc/openssh.nix
./modules/sys/rc/sunshine.nix ./modules/sys/rc/sunshine.nix
./modules/sys/rc/synergy.nix
./modules/sys/rgb.nix ./modules/sys/rgb.nix
./modules/sys/security.nix ./modules/sys/security.nix
@@ -174,60 +167,45 @@
./hosts/IdeaPad/configuration.nix ./hosts/IdeaPad/configuration.nix
]; ];
"htpc" = mkHost "x86_64-linux" [ "minizen" = mkHost "x86_64-linux" [
./modules/audio/base.nix ./modules/audio/base.nix
./modules/audio/zeroconf.nix ./modules/audio/zeroconf.nix
./modules/bluetooth/desktop.nix
./modules/de/kde.nix
./modules/de/i3.nix
./modules/desktop-common.nix
./modules/gui/services/fcast.nix
./modules/gui/apps/firefox.nix
./modules/gui/apps/spicetify.nix
./modules/gui/apps/steam.nix
./modules/gui/fonts.nix
./modules/gui/services/flatpak.nix
./modules/gui/services/kdeconnect.nix
./modules/gui/services/kwallet.nix
./modules/gui/services/xdg.nix
./modules/net/services/avahi.nix
./modules/net/services/fail2ban.nix ./modules/net/services/fail2ban.nix
./modules/net/services/networkmanager.nix ./modules/net/services/networkmanager.nix
./modules/net/services/printing.nix
./modules/net/services/tailscale.nix ./modules/net/services/tailscale.nix
./modules/sys/compat.nix ./modules/sys/compat.nix
./modules/sys/firewall.nix ./modules/sys/firewall.nix
./modules/sys/fs/btrfs.nix ./modules/sys/fs/btrfs.nix
./modules/sys/fs/mounts/efi.nix
./modules/sys/fs/mounts/btrfs/btrfs-with-subvols.nix
./modules/sys/fs/mounts/swap.nix
./modules/sys/hw/boot.nix ./modules/sys/hw/boot.nix
./modules/sys/hw/cpu/amd64.nix ./modules/sys/hw/cpu/arm64.nix
./modules/sys/hw/gpu/amd.nix
./modules/sys/nix.nix ./modules/sys/nix.nix
./modules/sys/perf.nix ./modules/sys/perf.nix
./modules/sys/pkgs.nix ./modules/sys/pkgs.nix
./modules/sys/rc/openssh.nix ./modules/sys/rc/openssh.nix
./modules/sys/rc/synergy.nix
./modules/sys/rc/sunshine.nix
./modules/sys/rgb.nix
./modules/sys/security.nix ./modules/sys/security.nix
./modules/sys/shell.nix ./modules/sys/shell.nix
./modules/sys/stateversion.nix ./modules/sys/stateversion.nix
./modules/sys/sysctl.nix ./modules/sys/sysctl.nix
./modules/sys/time.nix ./modules/sys/time.nix
./modules/sys/users/k3t.nix ./modules/sys/users/k3t.nix
./hosts/minizen/configuration.nix
./hosts/htpc/configuration.nix
spicetify-nix.nixosModules.spicetify
home-manager.nixosModules.home-manager home-manager.nixosModules.home-manager
{ {
home-manager.useGlobalPkgs = true; home-manager.useGlobalPkgs = true;
home-manager.useUserPackages = true; home-manager.useUserPackages = true;
home-manager.users.k3t = ./home/desktop.nix; home-manager.users.k3t = ./home/server.nix;
} }
]; ];
};
"ThinkPad" = mkHost "x86_64-linux" [ "ThinkPad" = mkHost "x86_64-linux" [
./modules/audio/base.nix ./modules/audio/base.nix
./modules/audio/zeroconf.nix ./modules/audio/zeroconf.nix
@@ -260,13 +238,14 @@
./modules/sys/fs/btrfs.nix ./modules/sys/fs/btrfs.nix
./modules/sys/fs/mounts/efi.nix ./modules/sys/fs/mounts/efi.nix
./modules/sys/fs/mounts/btrfs/tbb-btrfs.nix ./modules/sys/fs/mounts/btrfs/btrfs-with-subvols.nix
./modules/sys/fs/mounts/swap.nix ./modules/sys/fs/mounts/swap.nix
./modules/sys/hw/boot.nix ./modules/sys/hw/boot.nix
./modules/sys/hw/cpu/intel.nix ./modules/sys/hw/cpu/intel.nix
./modules/sys/hw/gpu/intel.nix ./modules/sys/hw/gpu/intel.nix
./modules/sys/hw/misc/ios.nix
./modules/sys/nix.nix ./modules/sys/nix.nix
./modules/sys/perf.nix ./modules/sys/perf.nix
./modules/sys/pkgs.nix ./modules/sys/pkgs.nix
+11 -11
View File
@@ -4,12 +4,12 @@
{ config, pkgs, ... }: { config, pkgs, ... }:
let #let
amdgpu-kernel-module = pkgs.callPackage ./amdgpu-kernel-module.nix { # amdgpu-kernel-module = pkgs.callPackage ./amdgpu-kernel-module.nix {
# Make sure the module targets the same kernel as your system is using. # Make sure the module targets the same kernel as your system is using.
kernel = config.boot.kernelPackages.kernel; # kernel = config.boot.kernelPackages.kernel;
}; # };
in #in
{ {
imports = imports =
@@ -20,14 +20,14 @@ in
networking.hostName = "TheBlackBox"; networking.hostName = "TheBlackBox";
# Linux and VR... nightmare below # Linux and VR... nightmare below
boot.extraModulePackages = [ #boot.extraModulePackages = [
(amdgpu-kernel-module.overrideAttrs (_: { # (amdgpu-kernel-module.overrideAttrs (_: {
patches = [ ./amdgpu-cap_sys_nice_begone.patch ]; # patches = [ ./amdgpu-cap_sys_nice_begone.patch ];
})) # }))
]; #];
# Synergy # Synergy
services.synergy.server.enable = true; #services.synergy.server.enable = true;
services.wivrn = { services.wivrn = {
enable = true; enable = true;
+45
View File
@@ -0,0 +1,45 @@
# Edit this configuration file to define what should be installed on
# your system. Help is available in the configuration.nix(5) man page, on
# https://search.nixos.org/options and in the NixOS manual (`nixos-help`).
{ config, lib, pkgs, inputs, ... }:
{
imports =
(lib.filesystem.listFilesRecursive ./services.d)
++ [ # Include the results of the hardware scan.
./hardware-configuration.nix
];
networking.hostName = "minizen"; # Define your hostname.
# podman
virtualisation.podman = {
enable = true;
autoPrune.enable = true;
dockerCompat = true; # optional; lets you use `docker` CLI
};
virtualisation.oci-containers.backend = "podman";
# Enable container name DNS for all Podman networks.
networking.firewall.interfaces = let
matchAll = if !config.networking.nftables.enable then "podman+" else "podman*";
in {
"${matchAll}".allowedUDPPorts = [ 53 ];
};
# List packages installed in system profile.
# You can use https://search.nixos.org/ to find more packages (and options).
environment.systemPackages = with pkgs; [
waypipe
];
# Open ports in the firewall.
networking.firewall.allowedTCPPorts = [ 80 443 25565 4433 9971 853 ];
networking.firewall.allowedUDPPorts = [ 443 24454 4433 9971 ];
# Copy the NixOS configuration file and link it from the resulting system
# (/run/current-system/configuration.nix). This is useful in case you
# accidentally delete configuration.nix.
# system.copySystemConfiguration = true;
}
+26
View File
@@ -0,0 +1,26 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
imports =
[ (modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [ "xhci_pci" "virtio_pci" "virtio_scsi" "usbhid" "sr_mod" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
swapDevices = [ ];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.enp7s0.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
+64
View File
@@ -0,0 +1,64 @@
{ config, lib, pkgs, ... }:
{
services.blocky = {
enable = true;
settings = {
certFile = "/etc/nixos/dns.crt";
keyFile = "/etc/nixos/dns.key";
caching = {
minTime = "5m";
maxTime = "30m";
prefetching = true;
};
ports = {
dns = 5353;
tls = 853;
http = 4000;
};
upstreams.groups.default = [
"https://dns.quad9.net/dns-query"
];
# For initially solving DoH/DoT Requests when no system Resolver is available.
bootstrapDns = {
upstream = "https://dns.quad9.net/dns-query";
ips = [ "9.9.9.9" "1.1.1.1" ];
};
#Enable Blocking of certain domains.
blocking = {
loading.refreshPeriod = "1h";
denylists = {
ads = [
"https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts"
"https://v.firebog.net/hosts/AdguardDNS.txt"
"https://v.firebog.net/hosts/Admiral.txt"
"https://raw.githubusercontent.com/anudeepND/blacklist/master/adservers.txt"
"https://raw.githubusercontent.com/FadeMind/hosts.extras/master/UncheckyAds/hosts"
];
tracking = [
"https://v.firebog.net/hosts/Easyprivacy.txt"
"https://v.firebog.net/hosts/Prigent-Ads.txt"
"https://raw.githubusercontent.com/crazy-max/WindowsSpyBlocker/master/data/hosts/spy.txt"
"https://hostfiles.frogeye.fr/firstparty-trackers-hosts.txt"
"https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.2o7Net/hosts"
];
sus = [
"https://someonewhocares.org/hosts/zero/hosts"
"https://raw.githubusercontent.com/RooneyMcNibNug/pihole-stuff/master/SNAFU.txt"
"https://raw.githubusercontent.com/matomo-org/referrer-spam-blacklist/master/spammers.txt"
"https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.Spam/hosts"
"https://raw.githubusercontent.com/PolishFiltersTeam/KADhosts/master/KADhosts.txt"
"https://raw.githubusercontent.com/matomo-org/referrer-spam-blacklist/master/spammers.txt"
];
};
#Configure what block categories are used
clientGroupsBlock = {
default = [ "ads" "tracking" "sus" ];
};
};
};
};
}
+25
View File
@@ -0,0 +1,25 @@
{ config, lib, pkgs, ... }:
{
services.gonic = {
enable = true;
settings = {
music-path = [
"/home/k3t/Music"
];
playlists-path = "/home/k3t/Playlists";
podcast-path = "/home/k3t/Podcasts";
};
};
services.nginx.virtualHosts."fckurspotify.lostin06.duckdns.org" = {
enableACME = true;
forceSSL = true;
locations."/" = {
proxyPass = "http://127.0.0.1:4747";
proxyWebsockets = true;
recommendedProxySettings = true;
};
};
}
+20
View File
@@ -0,0 +1,20 @@
{ config, pkgs, lib, ... }:
{
virtualisation.oci-containers.containers."minecraft-server" = {
image = "ghcr.io/graalvm/graalvm-community:25";
volumes = [
"/var/lib/minecraft:/data:rw"
];
ports = [
"25565:25565/tcp"
"24454:24454/udp"
];
extraOptions = [
"--tty"
"--interactive"
];
entrypoint = "/data/run.sh";
log-driver = "journald";
};
}
+17
View File
@@ -0,0 +1,17 @@
{ config, lib, pkgs, ... }:
{
services.nginx = {
enable = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
};
security.acme = {
acceptTerms = true;
defaults.email = "k3t@k3t.dev";
};
}
+1 -1
View File
@@ -1,7 +1,7 @@
{ {
networking = { networking = {
nftables = { nftables = {
enable = true; enable = false;
}; };
firewall = { firewall = {
enable = true; enable = true;
+22
View File
@@ -0,0 +1,22 @@
{ pkgs, ... }:
{
nixpkgs.config.rocmSupport = true;
hardware = {
enableRedistributableFirmware = true;
graphics = {
enable = true;
enable32Bit = true;
extraPackages = with pkgs; [
vkbasalt
mangohud
lsfg-vk
];
};
nvidia = {
open = true;
modesetting.enable = true;
};
};
services.xserver.videoDrivers = [ "nvidia" ];
}
+12
View File
@@ -0,0 +1,12 @@
{pkgs, ...}:
{
services.usbmuxd = {
enable = true;
package = pkgs.usbmuxd2;
};
environment.systemPackages = with pkgs; [
libimobiledevice
ifuse # optional, to mount using 'ifuse'
];
}
+1 -1
View File
@@ -1,7 +1,7 @@
{ {
services.synergy = { services.synergy = {
client = { client = {
enable = true; #enable = true;
serverAddress = "theblackbox"; serverAddress = "theblackbox";
}; };
#server.enable = true; #server.enable = true;