nix/README.md

2.7 KiB

NixOS Configuration Repository

Repo for nix configuration files

Information

Home Manager

  • Home Manager Documentation - Link
  • Home Manager Options Search - Link

NixOS

  • NixOS Documentation - Stable - Link
  • NixOS Packages / Options Search - Link
  • Nix User Repository (NUR) Search - Link
  • Tons of good examples here - Link
  • Track a Nixpkgs PR - Link
  • NixOS Flakes Intro Guide - Link

Theming

  • To change system-wide themes, you need to change the following:

gnome

  1. desktops/gnome.nix - Change the imports at the bottom.
  2. users/albert/gnome-dconf.nix - Change the theme variants in the following:
    • org/gnome/shell/extensions/nightthemeswitcher/gtk-variants
    • org/gnome/shell/extensions/nightthemeswitcher/icon-variants
    • org/gnome/shell/extensions/nightthemeswitcher/shell-variants

neovim

  1. common/dotfiles/neovim.nix - Change the following:
    • plugins = with pkgs.vimPlugins - Add your theme under "Themes"
    • extraConfig - Change the colorscheme section

hyprland / waybar

  1. Work in progress...

GPG Keys

  1. Import your GPG key albert.key
  2. Add it to your GPG Keyring via gpg --import albert.key
  3. Mark it as ultimately trusted via gpg --edit-key albert@sysctl.io, then type trust, then 5
  4. Repeat this step for all users who need a GPG key assigned

SOPS Secrets

  1. To edit a file: cd to /path/to/nix-files/ and run:
    • nix-shell -p sops --run "sops secrets/secret_file.yml
    • New shell alias: sops secrets/secret_file.yml
  2. Ensure your GPG keys are set up.

Lanzaboote / SecureBoot

  • Instructions here - Link
  1. Create your keys: sbctl create-keys
  2. Verify your machine is ready for SecureBoot: sbctl verify - Everything except *-bzImage.efi are signed
  3. Enter Secureboot Setup mode in your EFI Settings on the motherboard (F10)
    • Security -> SecureBoot -> Set to Enabled and "Reset to Setup Mode" and exit
  4. Enroll the keys: sbctl enroll-keys --microsoft
    • If you wish, you acan select --tpm-eventlog, but checksums will change later (ie, at a kernel rebuild)
  5. Reboot and verify you are activated: bootctl status

Other