From 5ee891fe2bf62ee9e19b6963554cacdcc92285ce Mon Sep 17 00:00:00 2001 From: Shahab Dogar Date: Sat, 15 Nov 2025 13:21:18 +0500 Subject: [PATCH] sec: NixOS | remove nixos configuration and move to nix-config repo --- nixos/master/configuration.nix | 145 ------------------------ nixos/master/disko-config.nix | 45 -------- nixos/master/flake.lock | 48 -------- nixos/master/flake.nix | 37 ------ nixos/master/hardware-configuration.nix | 24 ---- 5 files changed, 299 deletions(-) delete mode 100644 nixos/master/configuration.nix delete mode 100644 nixos/master/disko-config.nix delete mode 100644 nixos/master/flake.lock delete mode 100644 nixos/master/flake.nix delete mode 100644 nixos/master/hardware-configuration.nix diff --git a/nixos/master/configuration.nix b/nixos/master/configuration.nix deleted file mode 100644 index e20b495..0000000 --- a/nixos/master/configuration.nix +++ /dev/null @@ -1,145 +0,0 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page, on -# https://search.nixos.org/options and in the NixOS manual (`nixos-help`). - -{ pkgs, meta, ... }: - -{ - imports = [ ./hardware-configuration.nix ]; - - nix = { - settings = { - require-sigs = false; - experimental-features = [ "nix-command" "flakes" ]; - }; - }; - - # Use the systemd-boot EFI boot loader. - boot.loader.systemd-boot.enable = true; - boot.loader.efi.canTouchEfiVariables = true; - - networking.hostName = meta.hostname; # Define your hostname. - # Pick only one of the below networking options. - networking.networkmanager.enable = true; - networking.interfaces.enp1s0.ipv4.addresses = [ - { - address = ( - if meta.hostname == "homelab-0" then "192.168.18.10" - else if meta.hostname == "homelab-1" then "192.168.18.11" - else if meta.hostname == "homelab-2" then "192.168.18.12" - else throw "Unknown hostname" - ); - prefixLength = 24; - } - ]; - networking.defaultGateway = "192.168.18.1"; - networking.nameservers = [ - "192.168.18.250" - "1.1.1.1" - ]; - - # Set your time zone. - time.timeZone = "Asia/Karachi"; - - # Select internationalisation properties. - i18n.defaultLocale = "en_US.UTF-8"; - console = { - font = "Lat2-Terminus16"; - keyMap = "us"; - }; - - # Fixes for longhorn - systemd.tmpfiles.rules = [ - "L+ /usr/local/bin - - - - /run/current-system/sw/bin/" - ]; - virtualisation.docker.logDriver = "json-file"; - - services.k3s = { - enable = true; - role = "server"; - tokenFile = /var/lib/rancher/k3s/server/token; - extraFlags = toString ([ - "--write-kubeconfig-mode \"0644\"" - "--cluster-init" - "--disable servicelb" - "--disable traefik" - "--disable local-storage" - ] ++ (if meta.hostname == "homelab-0" then [] else [ - "--server https://192.168.18.10:6443" - ])); - clusterInit = (meta.hostname == "homelab-0"); - }; - - services.openiscsi = { - enable = true; - name = "iqn.2016-04.com.open-iscsi:${meta.hostname}"; - }; - - # Define a user account. Don't forget to set a password with ‘passwd’. - users.users.shahab = { - isNormalUser = true; - extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user. - packages = with pkgs; [ - tree - cloudflared - ]; - # Created using mkpasswd - hashedPassword = "$6$.ZlYnf2cZph4tCbM$E/JJUDirRV8MZrgX4Rh.Pi1q95tev1ZxcKjPA1I.uURv56qoWcC39MJWO9S2T5MlkPVbSLGiM8Ihfz9mERImo/"; - openssh.authorizedKeys.keys = [ - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGD/V4jLpuk7uAovkbHFr6uulfBKZmsH+BqmXIR2aYD0" - ]; - }; - - security.sudo.extraRules = [ - { - users = ["shahab"]; - commands = [ - { command = "ALL"; options = ["NOPASSWD"]; } - ]; - } - ]; - - # List packages installed in system profile. To search, run: - # $ nix search wget - environment.systemPackages = with pkgs; [ - neovim - k3s - cifs-utils - nfs-utils - git - ]; - - # List services that you want to enable: - - # Enable the OpenSSH daemon. - services.openssh.enable = true; - - # Open ports in the firewall. - # networking.firewall.allowedTCPPorts = [ 80 ]; - # networking.firewall.allowedUDPPorts = [ ... ]; - # Or disable the firewall altogether. - networking.firewall.enable = false; - - # Copy the NixOS configuration file and link it from the resulting system - # (/run/current-system/configuration.nix). This is useful in case you - # accidentally delete configuration.nix. - # system.copySystemConfiguration = true; - - # This option defines the first version of NixOS you have installed on this particular machine, - # and is used to maintain compatibility with application data (e.g. databases) created on older NixOS versions. - # - # Most users should NEVER change this value after the initial install, for any reason, - # even if you've upgraded your system to a new NixOS release. - # - # This value does NOT affect the Nixpkgs version your packages and OS are pulled from, - # so changing it will NOT upgrade your system. - # - # This value being lower than the current NixOS release does NOT mean your system is - # out of date, out of support, or vulnerable. - # - # Do NOT change this value unless you have manually inspected all the changes it would make to your configuration, - # and migrated your data accordingly. - # - # For more information, see `man configuration.nix` or https://nixos.org/manual/nixos/stable/options#opt-system.stateVersion . - system.stateVersion = "24.05"; # Did you read the comment? -} diff --git a/nixos/master/disko-config.nix b/nixos/master/disko-config.nix deleted file mode 100644 index 3e371ca..0000000 --- a/nixos/master/disko-config.nix +++ /dev/null @@ -1,45 +0,0 @@ -{ - disko.devices = { - disk = { - vdb = { - type = "disk"; - device = "/dev/nvme0n1"; - content = { - type = "gpt"; - partitions = { - ESP = { - priority = 1; - name = "ESP"; - start = "1M"; - end = "128M"; - type = "EF00"; - content = { - type = "filesystem"; - format = "vfat"; - mountpoint = "/boot"; - }; - }; - luks = { - size = "100%"; - content = { - name = "crypted"; - type = "luks"; - passwordFile = "/tmp/secret.key"; - settings = { - allowDiscards = true; - crypttabExtraOpts = - [ "fido2-device=auto" "token-timeout=10" ]; - }; - content = { - type = "filesystem"; - format = "ext4"; - mountpoint = "/"; - }; - }; - }; - }; - }; - }; - }; - }; -} diff --git a/nixos/master/flake.lock b/nixos/master/flake.lock deleted file mode 100644 index a56a7c2..0000000 --- a/nixos/master/flake.lock +++ /dev/null @@ -1,48 +0,0 @@ -{ - "nodes": { - "disko": { - "inputs": { - "nixpkgs": [ - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1758287904, - "narHash": "sha256-IGmaEf3Do8o5Cwp1kXBN1wQmZwQN3NLfq5t4nHtVtcU=", - "owner": "nix-community", - "repo": "disko", - "rev": "67ff9807dd148e704baadbd4fd783b54282ca627", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "disko", - "type": "github" - } - }, - "nixpkgs": { - "locked": { - "lastModified": 1759994382, - "narHash": "sha256-wSK+3UkalDZRVHGCRikZ//CyZUJWDJkBDTQX1+G77Ow=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "5da4a26309e796daa7ffca72df93dbe53b8164c7", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixos-25.05", - "repo": "nixpkgs", - "type": "github" - } - }, - "root": { - "inputs": { - "disko": "disko", - "nixpkgs": "nixpkgs" - } - } - }, - "root": "root", - "version": 7 -} diff --git a/nixos/master/flake.nix b/nixos/master/flake.nix deleted file mode 100644 index 0fe77fc..0000000 --- a/nixos/master/flake.nix +++ /dev/null @@ -1,37 +0,0 @@ -{ - description = "Homelab NixOS Flake"; - - inputs = { - nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.05"; - # Disko - disko = { - url = "github:nix-community/disko"; - inputs.nixpkgs.follows = "nixpkgs"; - }; - }; - - outputs = { nixpkgs, disko, ... }: let - nodes = [ - "homelab-0" - "homelab-1" - "homelab-2" - ]; - in { - nixosConfigurations = builtins.listToAttrs (map (name: { - name = name; - value = nixpkgs.lib.nixosSystem { - specialArgs = { - meta = { hostname = name; }; - }; - system = "x86_64-linux"; - modules = [ - # Modules - disko.nixosModules.disko - ./hardware-configuration.nix - ./disko-config.nix - ./configuration.nix - ]; - }; - }) nodes); - }; -} diff --git a/nixos/master/hardware-configuration.nix b/nixos/master/hardware-configuration.nix deleted file mode 100644 index 422af6e..0000000 --- a/nixos/master/hardware-configuration.nix +++ /dev/null @@ -1,24 +0,0 @@ -# Do not modify this file! It was generated by ‘nixos-generate-config’ -# and may be overwritten by future invocations. Please make changes -# to /etc/nixos/configuration.nix instead. -{ config, lib, modulesPath, ... }: - -{ - imports = [(modulesPath + "/installer/scan/not-detected.nix")]; - - boot.initrd.availableKernelModules = [ "nvme" "xhci_pci" "usbhid" "usb_storage" "sd_mod" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ "kvm-amd" ]; - boot.extraModulePackages = [ ]; - - # Enables DHCP on each ethernet and wireless interface. In case of scripted networking - # (the default) this is the recommended approach. When using systemd-networkd it's - # still possible to use this option, but it's recommended to use it in conjunction - # with explicit per-interface declarations with `networking.interfaces..useDHCP`. - networking.useDHCP = lib.mkDefault false; - networking.interfaces.enp1s0.useDHCP = lib.mkDefault false; - # networking.interfaces.wlo1.useDHCP = lib.mkDefault true; - - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; - hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; -}