{ pkgs, ... }: # Shared base for all hosts: user, SSH hardening, nix settings, packages. { # ---- User ---- users.users.darman = { isNormalUser = true; description = "darman"; extraGroups = [ "wheel" "networkmanager" ]; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGZpkPVhzi1zG5JI9hWyUgdyvNIQbp4ts4jw3idpMhhN erik@laptop" ]; }; # Costs a password prompt on every `./scripts/deploy switch` (nixos-rebuild # --use-remote-sudo). Worth it: darman's key is the only thing between the # public internet and root on neptun. The password is darman_password from # each host's sops file. security.sudo.wheelNeedsPassword = true; # ---- SSH (key-only) ---- services.openssh = { enable = true; settings = { PasswordAuthentication = false; PermitRootLogin = "no"; }; }; # ---- Nix ---- nix.settings = { experimental-features = [ "nix-command" "flakes" ]; # trust wheel so `nixos-rebuild --target-host darman@…` can push closures. trusted-users = [ "root" "@wheel" ]; # authentik (services/identity/authentik.nix) comes from authentik-nix, # which cache.nixos.org doesn't carry — without this it's ~400 local # derivations (npm, rust, python). NOTE: the closure is built on whatever # machine runs ./scripts/deploy, so the LAPTOP needs these two lines too, # in /etc/nix/nix.custom.conf (Determinate Nix rewrites nix.conf). extra-substituters = [ "https://nix-community.cachix.org" ]; extra-trusted-public-keys = [ "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" ]; }; nix.gc = { automatic = true; dates = "weekly"; options = "--delete-older-than 30d"; }; environment.systemPackages = with pkgs; [ vim git htop tmux curl ]; # ---- Locale / firewall base ---- time.timeZone = "Europe/Berlin"; i18n.defaultLocale = "en_US.UTF-8"; # Firewall on, ssh always allowed. Service modules add their own ports # (samba via openFirewall, caddy 80/443, tailscale trusts tailscale0). networking.firewall.enable = true; networking.firewall.allowedTCPPorts = [ 22 ]; }