{ config, lib, pkgs, ... }: { imports = [ ./acme.nix ./backup.nix ./bjj-booker.nix ./cgithub.nix ./clippersnip.nix ./dns.nix ./dyndns.nix ./email.nix ./garage.nix ./git.nix ./hardware-configuration.nix ./home-assistant.nix ./media.nix ./oidc.nix ./pinchflat.nix ./rss.nix ./syncthing.nix ./system.nix ./typetype.nix ./usenet.nix ./web.nix ./wireguard.nix ./yakatak.nix ]; nix.settings.experimental-features = [ "nix-command" "flakes" ]; security.sudo.wheelNeedsPassword = false; users.users.joe = { isNormalUser = true; description = "Joe Mou"; extraGroups = [ "networkmanager" "wheel" ]; packages = with pkgs; [ jq sqlite-interactive ]; openssh.authorizedKeys.keys = [ "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIvvJXGg1HVDU2z2osjq5FEAcwte8ZybuYj1wpTtwr1m joe@doughboy" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPsci2NPhPgg7T77vtcnkcv5Z9sbHAsmp9XC11WPePvL joe@Joes-Mac-mini.local" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILU1pGPkl/6A2DXrEZd5elLCJ7OCnG9QCEvaopFW8gEg joe@penguin" ]; }; # TODO make into a module nixpkgs.config.allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) [ "unrar" # from nzbget ]; environment.systemPackages = with pkgs; [ dig file gitFull openssl psmisc python3 restic tmux tree unzip ]; programs.vim = { enable = true; defaultEditor = true; }; programs.nano.enable = false; services.envfs.enable = true; services.fstrim.enable = true; services.openssh.enable = true; services.sshguard = { enable = true; whitelist = [ "192.168.0.0/24" ]; }; services.locate.enable = true; services.postgresql = { enable = true; package = pkgs.postgresql_15; }; systemd.services.duperemove = { serviceConfig = { Type = "simple"; CacheDirectory = "duperemove"; }; script = '' exec ${pkgs.duperemove}/bin/duperemove -dhrq --hashfile $CACHE_DIRECTORY/hashfile /srv /var ''; }; networking.firewall.allowedTCPPorts = [ 80 443 ]; # This value determines the NixOS release from which the default # settings for stateful data, like file locations and database versions # on your system were taken. It's perfectly fine and recommended to leave # this value at the release version of the first install of this system. # Before changing this value read the documentation for this option # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). system.stateVersion = "23.11"; # Did you read the comment? }