From 87331d98262be08ee4a0e6fe58ad0ab42023cf0d Mon Sep 17 00:00:00 2001 From: Stefan Kempinger Date: Wed, 28 Jan 2026 22:07:48 +0100 Subject: [PATCH 1/5] added mum config (cage kiosk) --- flake.nix | 6 ++ mum/configuration.nix | 147 +++++++++++++++++++++++++++++++++ mum/hardware-configuration.nix | 24 ++++++ 3 files changed, 177 insertions(+) create mode 100644 mum/configuration.nix create mode 100644 mum/hardware-configuration.nix diff --git a/flake.nix b/flake.nix index bac12fd..640896f 100644 --- a/flake.nix +++ b/flake.nix @@ -52,6 +52,12 @@ modules = [ ./wohnzimmer/configuration.nix ]; + }; + mum = nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + ./mum/configuration.nix + ]; }; }; }; diff --git a/mum/configuration.nix b/mum/configuration.nix new file mode 100644 index 0000000..c4340e8 --- /dev/null +++ b/mum/configuration.nix @@ -0,0 +1,147 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page +# and in the NixOS manual (accessible by running ‘nixos-help’). + +{ config, pkgs, ... }: + +{ + imports = + [ # Include the results of the hardware scan. + ./hardware-configuration.nix + ]; + + # Bootloader. + boot.loader.grub.enable = true; + boot.loader.grub.device = "/dev/vda"; + boot.loader.grub.useOSProber = true; + + networking.hostName = "nixos"; # Define your hostname. + # networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. + + # Configure network proxy if necessary + # networking.proxy.default = "http://user:password@proxy:port/"; + # networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain"; + + # Enable networking + networking.networkmanager.enable = true; + + # Set your time zone. + time.timeZone = "Europe/Vienna"; + + # Select internationalisation properties. + i18n.defaultLocale = "en_US.UTF-8"; + + i18n.extraLocaleSettings = { + LC_ADDRESS = "de_AT.UTF-8"; + LC_IDENTIFICATION = "de_AT.UTF-8"; + LC_MEASUREMENT = "de_AT.UTF-8"; + LC_MONETARY = "de_AT.UTF-8"; + LC_NAME = "de_AT.UTF-8"; + LC_NUMERIC = "de_AT.UTF-8"; + LC_PAPER = "de_AT.UTF-8"; + LC_TELEPHONE = "de_AT.UTF-8"; + LC_TIME = "de_AT.UTF-8"; + }; + + # Configure keymap in X11 + services.xserver.xkb = { + layout = "de"; + variant = ""; + }; + + # Configure console keymap + console.keyMap = "de"; + + # Define a user account. Don't forget to set a password with ‘passwd’. + users.users.kemp = { + isNormalUser = true; + description = "kemp"; + extraGroups = [ "networkmanager" "wheel" ]; + packages = with pkgs; []; + + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINGHadFhDCUU/ta3p1FQgpm7NExHkyHNrJbNJP6np5w9 kempinger@ins.jku.at" + ]; + }; + + users.users.root = { + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINGHadFhDCUU/ta3p1FQgpm7NExHkyHNrJbNJP6np5w9 kempinger@ins.jku.at" + ]; + }; + + # Allow unfree packages + nixpkgs.config.allowUnfree = true; + + # List packages installed in system profile. To search, run: + # $ nix search wget + environment.systemPackages = with pkgs; [ + # vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default. + # wget + git + nil + nixd + ]; + programs.firefox = { + enable = true; + }; + + + systemd.services.cage-tty1={ + after = [ + "network-online.target" + #"systemd-resolved.service" + ];serviceConfig = { + Restart = "always"; + RestartSec = "1s"; + }; + environment.XKB_DEFAULT_LAYOUT = "de"; + }; + + services.cage = { + enable = true; + user = "kemp"; + program = "${pkgs.firefox}/bin/firefox"; + }; + services.getty.loginProgram = "${pkgs.coreutils}/bin/true"; + + # Some programs need SUID wrappers, can be configured further or are + # started in user sessions. + # programs.mtr.enable = true; + # programs.gnupg.agent = { + # enable = true; + # enableSSHSupport = true; + # }; + + # List services that you want to enable: + + # Enable the OpenSSH daemon. + services.openssh = { + enable = true; + settings = { + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + PermitRootLogin = "prohibit-password"; # Allow root with SSH keys only + }; + }; + + nix.settings.experimental-features = [ + "nix-command" + "flakes" + ]; + + # Open ports in the firewall. + # networking.firewall.allowedTCPPorts = [ ... ]; + # networking.firewall.allowedUDPPorts = [ ... ]; + # Or disable the firewall altogether. + networking.firewall.enable = false; + + # This value determines the NixOS release from which the default + # settings for stateful data, like file locations and database versions + # on your system were taken. It‘s perfectly fine and recommended to leave + # this value at the release version of the first install of this system. + # Before changing this value read the documentation for this option + # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). + system.stateVersion = "25.11"; # Did you read the comment? + +} diff --git a/mum/hardware-configuration.nix b/mum/hardware-configuration.nix new file mode 100644 index 0000000..3578db9 --- /dev/null +++ b/mum/hardware-configuration.nix @@ -0,0 +1,24 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ "ahci" "xhci_pci" "virtio_pci" "sr_mod" "virtio_blk" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-amd" ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/88cc8a52-5a15-4782-a322-fe280fa0f7b8"; + fsType = "ext4"; + }; + + swapDevices = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; +} From 2a54626ab05f4b7f26d6588e6099940499c9cc9e Mon Sep 17 00:00:00 2001 From: Stefan Kempinger Date: Wed, 28 Jan 2026 22:26:17 +0100 Subject: [PATCH 2/5] add screen rotation --- mum/configuration.nix | 56 +++++++++++++++++++++++++++---------------- 1 file changed, 35 insertions(+), 21 deletions(-) diff --git a/mum/configuration.nix b/mum/configuration.nix index c4340e8..e3afaf9 100644 --- a/mum/configuration.nix +++ b/mum/configuration.nix @@ -5,10 +5,10 @@ { config, pkgs, ... }: { - imports = - [ # Include the results of the hardware scan. - ./hardware-configuration.nix - ]; + imports = [ + # Include the results of the hardware scan. + ./hardware-configuration.nix + ]; # Bootloader. boot.loader.grub.enable = true; @@ -56,8 +56,11 @@ users.users.kemp = { isNormalUser = true; description = "kemp"; - extraGroups = [ "networkmanager" "wheel" ]; - packages = with pkgs; []; + extraGroups = [ + "networkmanager" + "wheel" + ]; + packages = with pkgs; [ ]; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINGHadFhDCUU/ta3p1FQgpm7NExHkyHNrJbNJP6np5w9 kempinger@ins.jku.at" @@ -76,32 +79,43 @@ # List packages installed in system profile. To search, run: # $ nix search wget environment.systemPackages = with pkgs; [ - # vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default. - # wget - git - nil - nixd + # vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default. + # wget + git + nil + nixd + wlr-randr + kmsxx ]; programs.firefox = { enable = true; }; - - systemd.services.cage-tty1={ + systemd.services.cage-tty1 = { after = [ - "network-online.target" - #"systemd-resolved.service" - ];serviceConfig = { - Restart = "always"; - RestartSec = "1s"; - }; - environment.XKB_DEFAULT_LAYOUT = "de"; + "network-online.target" + #"systemd-resolved.service" + ]; + serviceConfig = { + Restart = "always"; + RestartSec = "1s"; + }; + environment.XKB_DEFAULT_LAYOUT = "de"; }; services.cage = { enable = true; user = "kemp"; - program = "${pkgs.firefox}/bin/firefox"; + program = "${pkgs.writeScriptBin "start-cage-app" '' + #!/usr/bin/env bash + kmsprint | + grep '(connected)' | + sed -E 's/.* ([^ ]+) \(connected\).*/\1/' | + while read -r output; do + wlr-randr --output "$output" --transform 180 + done + exec ${pkgs.firefox}/bin/firefox + ''}/bin/start-cage-app"; }; services.getty.loginProgram = "${pkgs.coreutils}/bin/true"; From a07cf335efba505c7a770631d693590d261666fb Mon Sep 17 00:00:00 2001 From: Stefan Kempinger Date: Wed, 28 Jan 2026 23:40:35 +0100 Subject: [PATCH 3/5] Add libinput and udev calibration rule Set LIBINPUT_CALIBRATION_MATRIX via a udev rule to "-1 0 1 0 -1 1" to apply input calibration/inversion for libinput devices --- mum/configuration.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/mum/configuration.nix b/mum/configuration.nix index e3afaf9..c833500 100644 --- a/mum/configuration.nix +++ b/mum/configuration.nix @@ -86,6 +86,7 @@ nixd wlr-randr kmsxx + libinput ]; programs.firefox = { enable = true; @@ -118,7 +119,9 @@ ''}/bin/start-cage-app"; }; services.getty.loginProgram = "${pkgs.coreutils}/bin/true"; - + services.udev.extraRules = '' + ENV{LIBINPUT_CALIBRATION_MATRIX}="-1 0 1 0 -1 1" + ''; # Some programs need SUID wrappers, can be configured further or are # started in user sessions. # programs.mtr.enable = true; From 018dc5b26d28138f677c6ba07132bec31896eb03 Mon Sep 17 00:00:00 2001 From: Stefan Kempinger Date: Wed, 28 Jan 2026 23:45:20 +0100 Subject: [PATCH 4/5] Set hostname and enable wireless Remove commented example configs (proxy, SUID wrappers, programs, firewall port examples) to tidy configuration.nix --- mum/configuration.nix | 26 ++++---------------------- 1 file changed, 4 insertions(+), 22 deletions(-) diff --git a/mum/configuration.nix b/mum/configuration.nix index c833500..670fefe 100644 --- a/mum/configuration.nix +++ b/mum/configuration.nix @@ -15,12 +15,8 @@ boot.loader.grub.device = "/dev/vda"; boot.loader.grub.useOSProber = true; - networking.hostName = "nixos"; # Define your hostname. - # networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. - - # Configure network proxy if necessary - # networking.proxy.default = "http://user:password@proxy:port/"; - # networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain"; + networking.hostName = "nixos-mum"; # Define your hostname. + networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. # Enable networking networking.networkmanager.enable = true; @@ -122,17 +118,7 @@ services.udev.extraRules = '' ENV{LIBINPUT_CALIBRATION_MATRIX}="-1 0 1 0 -1 1" ''; - # Some programs need SUID wrappers, can be configured further or are - # started in user sessions. - # programs.mtr.enable = true; - # programs.gnupg.agent = { - # enable = true; - # enableSSHSupport = true; - # }; - - # List services that you want to enable: - - # Enable the OpenSSH daemon. + services.openssh = { enable = true; settings = { @@ -146,11 +132,7 @@ "nix-command" "flakes" ]; - - # Open ports in the firewall. - # networking.firewall.allowedTCPPorts = [ ... ]; - # networking.firewall.allowedUDPPorts = [ ... ]; - # Or disable the firewall altogether. + networking.firewall.enable = false; # This value determines the NixOS release from which the default From 767495988eacc878ae5b05c1c7e1f6d4bf10540d Mon Sep 17 00:00:00 2001 From: Stefan Kempinger Date: Wed, 28 Jan 2026 23:54:09 +0100 Subject: [PATCH 5/5] add dad config --- dad/configuration.nix | 146 +++++++++++++++++++++++++++++++++ dad/hardware-configuration.nix | 24 ++++++ flake.nix | 6 ++ 3 files changed, 176 insertions(+) create mode 100644 dad/configuration.nix create mode 100644 dad/hardware-configuration.nix diff --git a/dad/configuration.nix b/dad/configuration.nix new file mode 100644 index 0000000..9c02e3c --- /dev/null +++ b/dad/configuration.nix @@ -0,0 +1,146 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page +# and in the NixOS manual (accessible by running ‘nixos-help’). + +{ config, pkgs, ... }: + +{ + imports = [ + # Include the results of the hardware scan. + ./hardware-configuration.nix + ]; + + # Bootloader. + boot.loader.grub.enable = true; + boot.loader.grub.device = "/dev/vda"; + boot.loader.grub.useOSProber = true; + + networking.hostName = "nixos-dad"; # Define your hostname. + networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. + + # Enable networking + networking.networkmanager.enable = true; + + # Set your time zone. + time.timeZone = "Europe/Vienna"; + + # Select internationalisation properties. + i18n.defaultLocale = "en_US.UTF-8"; + + i18n.extraLocaleSettings = { + LC_ADDRESS = "de_AT.UTF-8"; + LC_IDENTIFICATION = "de_AT.UTF-8"; + LC_MEASUREMENT = "de_AT.UTF-8"; + LC_MONETARY = "de_AT.UTF-8"; + LC_NAME = "de_AT.UTF-8"; + LC_NUMERIC = "de_AT.UTF-8"; + LC_PAPER = "de_AT.UTF-8"; + LC_TELEPHONE = "de_AT.UTF-8"; + LC_TIME = "de_AT.UTF-8"; + }; + + # Configure keymap in X11 + services.xserver.xkb = { + layout = "de"; + variant = ""; + }; + + # Configure console keymap + console.keyMap = "de"; + + # Define a user account. Don't forget to set a password with ‘passwd’. + users.users.kemp = { + isNormalUser = true; + description = "kemp"; + extraGroups = [ + "networkmanager" + "wheel" + ]; + packages = with pkgs; [ ]; + + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINGHadFhDCUU/ta3p1FQgpm7NExHkyHNrJbNJP6np5w9 kempinger@ins.jku.at" + ]; + }; + + users.users.root = { + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINGHadFhDCUU/ta3p1FQgpm7NExHkyHNrJbNJP6np5w9 kempinger@ins.jku.at" + ]; + }; + + # Allow unfree packages + nixpkgs.config.allowUnfree = true; + + # List packages installed in system profile. To search, run: + # $ nix search wget + environment.systemPackages = with pkgs; [ + # vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default. + # wget + git + nil + nixd + wlr-randr + kmsxx + libinput + ]; + programs.firefox = { + enable = true; + }; + + systemd.services.cage-tty1 = { + after = [ + "network-online.target" + #"systemd-resolved.service" + ]; + serviceConfig = { + Restart = "always"; + RestartSec = "1s"; + }; + environment.XKB_DEFAULT_LAYOUT = "de"; + }; + + services.cage = { + enable = true; + user = "kemp"; + program = "${pkgs.writeScriptBin "start-cage-app" '' + #!/usr/bin/env bash + # kmsprint | + # grep '(connected)' | + # sed -E 's/.* ([^ ]+) \(connected\).*/\1/' | + # while read -r output; do + # wlr-randr --output "$output" --transform 180 + # done + exec ${pkgs.firefox}/bin/firefox + ''}/bin/start-cage-app"; + }; + services.getty.loginProgram = "${pkgs.coreutils}/bin/true"; + services.udev.extraRules = '' + # ENV{LIBINPUT_CALIBRATION_MATRIX}="-1 0 1 0 -1 1" + ''; + + services.openssh = { + enable = true; + settings = { + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + PermitRootLogin = "prohibit-password"; # Allow root with SSH keys only + }; + }; + + nix.settings.experimental-features = [ + "nix-command" + "flakes" + ]; + + networking.firewall.enable = false; + + # This value determines the NixOS release from which the default + # settings for stateful data, like file locations and database versions + # on your system were taken. It‘s perfectly fine and recommended to leave + # this value at the release version of the first install of this system. + # Before changing this value read the documentation for this option + # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). + system.stateVersion = "25.11"; # Did you read the comment? + +} diff --git a/dad/hardware-configuration.nix b/dad/hardware-configuration.nix new file mode 100644 index 0000000..3578db9 --- /dev/null +++ b/dad/hardware-configuration.nix @@ -0,0 +1,24 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ "ahci" "xhci_pci" "virtio_pci" "sr_mod" "virtio_blk" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-amd" ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/88cc8a52-5a15-4782-a322-fe280fa0f7b8"; + fsType = "ext4"; + }; + + swapDevices = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; +} diff --git a/flake.nix b/flake.nix index 640896f..d007398 100644 --- a/flake.nix +++ b/flake.nix @@ -58,6 +58,12 @@ modules = [ ./mum/configuration.nix ]; + }; + dad = nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + ./dad/configuration.nix + ]; }; }; };