{ config, pkgs, lib, ... }: # Real-host config: hardware + disk layout + bootloader + shared services. { imports = [ ./hardware-configuration.nix ./disk-config.nix # disko: OS-disk partitions + filesystems ./secrets.nix # sops-nix: samba password etc. ./services.nix ]; # ---- Boot ---- # systemd-boot for UEFI. If ZimaBlade boots legacy/BIOS, switch to grub. boot.loader.systemd-boot.enable = true; boot.loader.efi.canTouchEfiVariables = true; # Root lives on the ZimaBlade eMMC (mmcblk0). nixos-generate-config runs in # the RAM installer and does NOT detect these, so pin them here (merged with # hardware-configuration.nix) or stage-1 can't mount root and the box panics. boot.initrd.availableKernelModules = [ "mmc_block" "sdhci_pci" "sdhci_acpi" ]; # Trust wheel users so `nixos-rebuild --target-host darman@…` can push a # laptop-built (unsigned) closure without a signature error. nix.settings.trusted-users = [ "root" "@wheel" ]; # Warm reboot hangs at firmware reset on this board (cold power-cycle works). # Force the PCI-chipset reset method. If a warm `reboot` still hangs, try the # next value: acpi -> bios -> cold -> efi. boot.kernelParams = [ "reboot=pci" ]; # ---- NAS data array ---- # Existing ext4 on the mdadm RAID0 over sda+sdb (md0, 29.1T). # Mounted, NOT formatted; kept out of disko so it is never wiped. # ⚠️ RAID0 = no redundancy: either 16TB disk failing loses ALL data. boot.swraid.enable = true; # assemble the mdadm array at boot fileSystems."/mnt/data" = { # fs UUID (stable) — the array may enumerate as /dev/md127, so avoid /dev/md0. device = "/dev/disk/by-uuid/dadbff6f-652e-49b2-bfed-eb1308ab8b78"; fsType = "ext4"; options = [ "nofail" ]; # don't block boot if the array is degraded/absent }; }