feat: port Phase 1 foundational modules and setup comin in flake.nix

This commit is contained in:
Tibo De Peuter 2026-07-17 22:05:43 +02:00
parent 647ccfd6e2
commit 17de32268d
Signed by: tdpeuter
SSH key fingerprint: SHA256:u/h/LVoqKF1Iz02uOyxe6hcjmoZASCGV2HM0TG9ZMoU
9 changed files with 196 additions and 0 deletions

65
flake.nix Normal file
View file

@ -0,0 +1,65 @@
{
description = "Homelab configuration using flakes (v2 GitOps)";
inputs = {
nixpkgs.url = "nixpkgs/nixos-unstable";
flake-utils.url = "github:numtide/flake-utils";
sops-nix = {
url = "github:Mic92/sops-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
utils = {
url = "github:gytis-ivaskevicius/flake-utils-plus";
inputs.flake-utils.follows = "flake-utils";
};
comin = {
url = "github:nlewo/comin";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = inputs@{
self, nixpkgs,
flake-utils, sops-nix, utils, comin,
...
}:
let
system = utils.lib.system.x86_64-linux;
in
utils.lib.mkFlake {
inherit self inputs;
hostDefaults = {
inherit system;
modules = [
./modules
./users
sops-nix.nixosModules.sops
comin.nixosModules.comin
# Base comin configuration for all nodes
({ config, pkgs, ... }: {
services.comin = {
enable = true;
remotes = [{
name = "origin";
# Replace with actual internal forgejo URL once available
url = "https://github.com/example/nix-config.git";
branches.main.name = "v2";
}];
};
})
];
};
hosts = {
# Hosts will be populated here as they are migrated to the v2 branch.
};
};
}

View file

@ -0,0 +1,16 @@
{
config = {
homelab = {
services.openssh.enable = true;
users.admin.enable = true;
};
nix.settings.experimental-features = [
"flakes"
"nix-command"
];
# Set your time zone.
time.timeZone = "Europe/Brussels";
};
}

7
modules/default.nix Normal file
View file

@ -0,0 +1,7 @@
{
imports = [
./common
./services
./virtualisation
];
}

View file

@ -0,0 +1,5 @@
{
imports = [
./openssh
];
}

View file

@ -0,0 +1,20 @@
{ config, lib, pkgs, ... }:
let
cfg = config.homelab.services.openssh;
in {
options.homelab.services.openssh.enable = lib.mkEnableOption "OpenSSH daemon";
config = lib.mkIf cfg.enable {
services.openssh = {
# Enable the OpenSSH daemon.
enable = true;
settings = {
PasswordAuthentication = false;
PermitRootLogin = "no";
# Disable keyboard-interactive authentication.
KbdInteractiveAuthentication = false;
};
};
};
}

View file

@ -0,0 +1,5 @@
{
imports = [
./guest
];
}

View file

@ -0,0 +1,34 @@
{ config, lib, modulesPath, ... }:
let
cfg = config.homelab.virtualisation.guest;
in {
options.homelab.virtualisation.guest.enable = lib.mkEnableOption "Settings for devices running on virtualisation, e.g. Proxmox";
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
config = lib.mkIf cfg.enable {
boot = {
# Whether to enable growing the root partition on boot.
growPartition = true;
# Use Grub bootloader
loader.grub = {
enable = true;
devices = [
"nodev"
];
};
};
fileSystems."/" = lib.mkDefault {
device = "/dev/disk/by-label/nixos";
autoResize = true;
fsType = "ext4";
};
# Enable QEMU Guest for Proxmox
services.qemuGuest.enable = true;
};
}

39
users/admin/default.nix Normal file
View file

@ -0,0 +1,39 @@
{ config, lib, pkgs, ... }:
let
cfg = config.homelab.users.admin;
in {
options.homelab.users.admin = {
enable = lib.mkEnableOption "user System Administrator";
authorizedKeys = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [
# HomeLab > NixOS > admin > ssh
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGWIOOEqTy8cWKpENVbzD4p7bsQgQb/Dgpzk8i0dZ00T"
];
};
};
config = lib.mkIf cfg.enable {
nix.settings.trusted-users = [
config.users.users.gh0st.name
];
users.users.gh0st = {
description = "System Administrator";
isNormalUser = true;
extraGroups = [
config.users.groups.wheel.name # Enable 'sudo' for the user.
];
initialPassword = "ChangeMe";
openssh.authorizedKeys.keys = cfg.authorizedKeys;
packages = with pkgs; [
curl
git
tmux
vim
wget
];
};
};
}

5
users/default.nix Normal file
View file

@ -0,0 +1,5 @@
{
imports = [
./admin
];
}