# Edit this configuration file to define what should be installed on # your system. Help is available in the configuration.nix(5) man page # and in the NixOS manual (accessible by running ‘nixos-help’). { config, pkgs, ... }: { imports = [ # Include the results of the hardware scan. ./hardware-configuration.nix ]; # Bootloader. #boot.loader.systemd-boot.enable = true; #boot.loader.efi.canTouchEfiVariables = true; boot.loader.grub.enable = true; boot.loader.grub.device = "/dev/vda"; boot.loader.grub.useOSProber = true; networking.hostName = "nixos-dad"; # Define your hostname. networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. # Enable networking networking.networkmanager.enable = true; # Set your time zone. time.timeZone = "Europe/Vienna"; # Select internationalisation properties. i18n.defaultLocale = "en_US.UTF-8"; i18n.extraLocaleSettings = { LC_ADDRESS = "de_AT.UTF-8"; LC_IDENTIFICATION = "de_AT.UTF-8"; LC_MEASUREMENT = "de_AT.UTF-8"; LC_MONETARY = "de_AT.UTF-8"; LC_NAME = "de_AT.UTF-8"; LC_NUMERIC = "de_AT.UTF-8"; LC_PAPER = "de_AT.UTF-8"; LC_TELEPHONE = "de_AT.UTF-8"; LC_TIME = "de_AT.UTF-8"; }; # Configure keymap in X11 services.xserver.xkb = { layout = "de"; variant = ""; }; # Configure console keymap console.keyMap = "de"; # Define a user account. Don't forget to set a password with ‘passwd’. users.users.kemp = { isNormalUser = true; description = "kemp"; extraGroups = [ "networkmanager" "wheel" ]; packages = with pkgs; [ ]; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINGHadFhDCUU/ta3p1FQgpm7NExHkyHNrJbNJP6np5w9 kempinger@ins.jku.at" ]; }; users.users.root = { openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINGHadFhDCUU/ta3p1FQgpm7NExHkyHNrJbNJP6np5w9 kempinger@ins.jku.at" ]; }; # Allow unfree packages nixpkgs.config.allowUnfree = true; # List packages installed in system profile. To search, run: # $ nix search wget environment.systemPackages = with pkgs; [ git nil nixd wlr-randr kmsxx libinput pciutils pulseaudio pwvucontrol (pkgs.wrapFirefox (pkgs.firefox-unwrapped.override { pipewireSupport = true; }) { }) ]; programs.firefox = { enable = true; package = (pkgs.wrapFirefox (pkgs.firefox-unwrapped.override { pipewireSupport = true; }) { }); }; systemd.services.cage-tty1 = { after = [ "network-online.target" #"systemd-resolved.service" ]; serviceConfig = { Restart = "always"; RestartSec = "1s"; }; environment.XKB_DEFAULT_LAYOUT = "de"; }; services.cage = { enable = true; user = "kemp"; program = "${pkgs.writeScriptBin "start-cage-app" '' #!/usr/bin/env bash exec pwvucontrol exec firefox ''}/bin/start-cage-app"; }; services.getty.loginProgram = "${pkgs.coreutils}/bin/true"; services.actkbd.enable = true; services.actkbd.bindings = [ # Mute { keys = [ 113 ]; events = [ "key" ]; command = "wpctl set-mute @DEFAULT_AUDIO_SINK@ toggle"; } # Volume down { keys = [ 114 ]; events = [ "key" "rep" ]; command = "wpctl set-volume @DEFAULT_AUDIO_SINK@ 5%-"; } # Volume up { keys = [ 115 ]; events = [ "key" "rep" ]; command = "wpctl set-volume @DEFAULT_AUDIO_SINK@ 5%+"; } ]; security.rtkit.enable = true; services.pipewire = { enable = true; # if not already enabled alsa.enable = true; alsa.support32Bit = true; pulse.enable = true; # If you want to use JACK applications, uncomment the following jack.enable = true; }; services.openssh = { enable = true; settings = { PasswordAuthentication = false; KbdInteractiveAuthentication = false; PermitRootLogin = "prohibit-password"; # Allow root with SSH keys only }; }; nix.settings.experimental-features = [ "nix-command" "flakes" ]; networking.firewall.enable = false; # This value determines the NixOS release from which the default # settings for stateful data, like file locations and database versions # on your system were taken. It‘s perfectly fine and recommended to leave # this value at the release version of the first install of this system. # Before changing this value read the documentation for this option # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). system.stateVersion = "25.11"; # Did you read the comment? }