summaryrefslogtreecommitdiff
path: root/hosts/oixos/default.nix
blob: 416e2f210d6511581b924908642bf07b8da3ff86 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
{
  systemState,
  user,
  hostname,
}:
{
  pkgs,
  config,
  inputs,
  lib,
  ...
}:
{
  imports = [
    inputs.disko.nixosModules.disko
    ./disko.nix
    ./hardware-configuration.nix
  ];

  boot.loader.grub = {
    efiSupport = true;
    efiInstallAsRemovable = true;
  };

  networking.hostName = hostname;
  networking.useDHCP = true;

  services.openssh = {
    enable = true;
    # settings = {
    #   PermitRootLogin = "prohibit-password";
    #   PasswordAuthentication = false;
    # };
  };

  # users.users.beeb5k = {
  #   isNormalUser = true;
  #   extraGroups = [ "wheel" ];
  #
  #   openssh.authorizedKeys.keys = [
  #     "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGTMc0gNGM6vI8s9CrW+fYlW4ppRTKRCELOve3Izj1VD beeb5k"
  #   ];
  # };

  services.cloud-init.enable = true;

  users.users.root.openssh.authorizedKeys.keys = [
    "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGTMc0gNGM6vI8s9CrW+fYlW4ppRTKRCELOve3Izj1VD beeb5k"
  ];

  environment.systemPackages = with pkgs; [
    git
  ];

  # security.sudo.wheelNeedsPassword = false;

  nixpkgs.hostPlatform = "aarch64-linux";

  system.stateVersion = systemState;
}