summaryrefslogtreecommitdiff
path: root/machines/iridium/default.nix
diff options
context:
space:
mode:
authorKleidi Bujari <mail@4kb.net>2024-12-10 13:24:51 -0500
committerKleidi Bujari <mail@4kb.net>2024-12-10 13:24:51 -0500
commitf5ed731abbc38d765333b005b9815a5f6d3e59c2 (patch)
treeff4b4f0c4aa1a51742fcefac3f40e05cddceb60e /machines/iridium/default.nix
parentf08f3812f40322b6098d75573413ed83f358871f (diff)
downloaddepot-f5ed731abbc38d765333b005b9815a5f6d3e59c2.tar.gz
depot-f5ed731abbc38d765333b005b9815a5f6d3e59c2.tar.bz2
depot-f5ed731abbc38d765333b005b9815a5f6d3e59c2.zip
Finalize working configs and prior to adding secrets
System configurations in a known good state. Secrets still have to be integrated, at this point the nixos-anywhere project will likely handle this to keep the bootstrap completely automatic since it can copy ssh host keys to the host prior to install/activation. This would work nicely with the sops secret module, but a good way to manage host keys for each machine still has to be decided.
Diffstat (limited to 'machines/iridium/default.nix')
-rw-r--r--machines/iridium/default.nix28
1 files changed, 27 insertions, 1 deletions
diff --git a/machines/iridium/default.nix b/machines/iridium/default.nix
index c915eb0..8a3edd0 100644
--- a/machines/iridium/default.nix
+++ b/machines/iridium/default.nix
@@ -1 +1,27 @@
-{ ... }: { }
+{ inputs, lib, ... }: {
+ system.stateVersion = "24.11";
+
+ users.mutableUsers = false;
+ users.users.root = {
+ initialPassword = "test";
+ };
+
+ xnet = {
+ disk = {
+ enable = true;
+ device = "/dev/nvme0n1";
+ };
+ net = {
+ sshd.enable = true;
+ };
+ users.enable = [ "kle" ];
+ gitServer = {
+ enable = true;
+ gitweb.enable = true;
+ keys = builtins.filter (x: x != "")
+ (lib.strings.splitString "\n" (builtins.readFile inputs.sshKeys));
+ };
+ };
+
+ nix.registry.nixpkgs.flake = inputs.nixpkgs;
+}