rework: more TUIs! (#62)

Signed-off-by: Hadi <[email protected]>
This commit is contained in:
Hadi
2026-09-28 20:18:12 +02:00
committed by GitHub
parent 1a3f23f248
commit 07a60e91d2
98 changed files with 1280 additions and 1093 deletions
+55
View File
@@ -0,0 +1,55 @@
# Secure Boot via lanzaboote (signed systemd-boot + unified kernel images)
#
# One-time setup on the machine (not handled by Nix):
# 1. sudo sbctl create-keys
# 2. Reboot into firmware setup, put Secure Boot in "Setup Mode"
# 3. nixos-rebuild switch (this signs the current generation with the new keys)
# 4. sudo sbctl enroll-keys --microsoft
# 5. Reboot, re-enable Secure Boot in firmware
{
pkgs,
lib,
...
}: {
boot = {
loader = {
efi.canTouchEfiVariables = true;
systemd-boot = {
enable = lib.mkForce false;
consoleMode = "auto";
configurationLimit = 8;
};
};
lanzaboote = {
enable = true;
pkiBundle = "/var/lib/sbctl";
};
tmp.cleanOnBoot = true;
kernelPackages = pkgs.linuxPackages; # _latest, _zen, _hardened, _rt, _rt_latest, etc.
# Silent boot
kernelParams = [
"quiet"
"splash"
"rd.systemd.show_status=false"
"rd.udev.log_level=3"
"udev.log_priority=3"
"boot.shell_on_fail"
];
consoleLogLevel = 0;
initrd.verbose = false;
};
environment.systemPackages = [pkgs.sbctl];
# To avoid systemd services hanging on shutdown
systemd.settings.Manager = {
DefaultTimeoutStopSec = "10s";
};
environment.persistence."/persist".directories = [
"/var/lib/sbctl"
];
}
+4 -2
View File
@@ -48,8 +48,6 @@ in {
# literally no documentation about this anywhere.
# might be good to write about this...
# https://www.reddit.com/r/NixOS/comments/u0cdpi/tuigreet_with_xmonad_how/
# Unlock the gnome-keyring with the login password so apps (browser
# secrets via libsecret, ProtonVPN credentials, …) don't reprompt.
systemd.services.greetd.serviceConfig = {
Type = "idle";
StandardInput = "tty";
@@ -60,4 +58,8 @@ in {
TTYVHangup = true;
TTYVTDisallocate = true;
};
environment.persistence."/persist".directories = [
"/var/cache/tuigreet"
];
}
+6 -1
View File
@@ -68,7 +68,12 @@ in {
];
};
gvfs.enable = true;
upower.enable = true;
upower = {
enable = true;
percentageLow = 10;
percentageCritical = 5;
percentageAction = 3;
};
power-profiles-daemon.enable = true;
udisks2.enable = true;
};
+4
View File
@@ -24,4 +24,8 @@
RandomizedDelaySec = "1h";
};
};
environment.persistence."/persist".directories = [
"/var/cache/vulnix"
];
}