{ config, pkgs, ... }: { # Boot configuration boot.loader.systemd-boot.enable = true; boot.loader.efi.canTouchEfiVariables = true; # Timezone time.timeZone = "Europe/Berlin"; i18n.defaultLocale = "en_US.UTF-8"; # Security & sudo security.sudo.enable = true; security.sudo.wheelNeedsPassword = false; # SSH configuration services.openssh = { enable = true; settings = { PermitRootLogin = "no"; PasswordAuthentication = false; }; }; # User configuration users.users.danlin = { isNormalUser = true; extraGroups = [ "wheel" ]; hashedPassword = "$6$tvQ8UVAZIOm4g8PI$u1HBwK1xVINiNFOm.MtbvGsXb8R5SvBHqdJpTLcvDHJcdWa4GcB/R3txARlu.s/bLhtnwoKSKUksQ5ETwyQ5u."; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+xf0lrobmWxml003CyjzEEZqUf2qbEv6vEGMGNUBAX danlin@MacBook-Pro-von-Daniel.fritz.box" ]; }; # Base system packages environment.systemPackages = with pkgs; [ neovim rclone htop curl wget apacheHttpd # Provides htpasswd for registry password management ]; # QEMU guest agent (for VM integration when running as guest) services.qemuGuest.enable = true; # Automatic updates — pull the committed config from Gitea and rebuild. # Jeder Host baut sein eigenes Flake-Attribut (= networking.hostName). system.autoUpgrade = { enable = true; flake = "git+https://git.home.lindenfelser.de/danlin/infra-nix.git?ref=main#${config.networking.hostName}"; # nixpkgs beim Build auf die aktuelle Spitze von nixos-25.11 ziehen, # statt den in main gepinnten flake.lock zu verwenden — so kommen # wöchentlich frische Pakete ohne separaten Lock-Commit. flags = [ "--override-input" "nixpkgs" "github:NixOS/nixpkgs/nixos-25.11" ]; dates = "Sun 04:00"; randomizedDelaySec = "30min"; # Kernel/Init-Updates greifen nur nach Reboot — nachts im Fenster erlauben. allowReboot = true; rebootWindow = { lower = "04:00"; upper = "06:00"; }; }; }