summaryrefslogtreecommitdiff
path: root/machines/enzo/default.nix
diff options
context:
space:
mode:
Diffstat (limited to 'machines/enzo/default.nix')
-rw-r--r--machines/enzo/default.nix91
1 files changed, 91 insertions, 0 deletions
diff --git a/machines/enzo/default.nix b/machines/enzo/default.nix
new file mode 100644
index 0000000..65adef6
--- /dev/null
+++ b/machines/enzo/default.nix
@@ -0,0 +1,91 @@
+# enzo — laptop. Gets the shared common/ base plus laptop-only settings.
+{ inputs, pkgs, ... }:
+
+{
+ imports = [
+ # enzo's own minimal desktop (not the shared profiles/desktop.nix). Add
+ # ../../profiles/dev.nix or apps.nix here, or one-off packages below, as needed.
+ ./desktop.nix
+
+ inputs.disko.nixosModules.disko
+ ./disko.nix
+ ./hardware-configuration.nix
+ ];
+
+ networking.hostName = "enzo";
+
+ # Set this to the NixOS release the laptop is first installed from, then
+ # leave it. (See the comment in machines/kusanagi/default.nix.)
+ system.stateVersion = "26.05";
+
+ # --- User account (hwebs) ---
+ # (Desktop groups audio/input come from ./desktop.nix.)
+ users.users.hwebs = {
+ isNormalUser = true;
+ description = "Henry Webster";
+ extraGroups = [
+ "networkmanager"
+ "wheel"
+ ];
+ packages = with pkgs; [
+ git
+ neovim
+ tmux
+ btop
+ ripgrep
+ unzip
+ xclip
+ bc
+ psmisc
+ usbutils
+ stow
+ nushell
+ ];
+ };
+
+ nix.settings.trusted-users = [
+ "root"
+ "hwebs"
+ ];
+
+ # --- Disk encryption / hibernation / swap ---
+ # systemd in initrd is required for TPM2 unlock and clean hibernate resume.
+ boot.initrd.systemd.enable = true;
+
+ # TPM2 auto-unlock. Enroll the key WITH A PIN post-install:
+ # sudo systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=7 \
+ # --tpm2-with-pin=yes /dev/nvme0n1p2
+ # The original LUKS passphrase stays as a fallback keyslot. disko already
+ # declares boot.initrd.luks.devices."crypted".device.
+ boot.initrd.luks.devices."crypted".crypttabExtraOpts = [ "tpm2-device=auto" ];
+
+ # zram for everyday paging; the encrypted LVM swap from disko.nix is the
+ # hibernation target (boot.resumeDevice comes from disko's resumeDevice=true).
+ zramSwap.enable = true;
+
+ # Suspend-to-RAM on lid close, auto-hibernate after a delay so a dying battery
+ # doesn't lose the session. Everyday resume needs only the login password; the
+ # LUKS PIN appears only on cold boot / hibernate resume.
+ services.logind.settings.Login.HandleLidSwitch = "suspend-then-hibernate";
+ systemd.sleep.settings.Sleep.HibernateDelaySec = "60min";
+
+ # btrfs + SSD upkeep.
+ services.btrfs.autoScrub.enable = true;
+ services.fstrim.enable = true;
+
+ # --- Laptop power management ---
+ # power-profiles-daemon integrates with GNOME's power settings. If you prefer
+ # finer-grained control, disable this and enable services.tlp instead.
+ services.power-profiles-daemon.enable = true;
+ powerManagement.enable = true;
+
+ # Backlight control from the CLI / keybinds (programs.light was removed from
+ # nixpkgs; acpilight provides the udev rules and brightnessctl the CLI).
+ hardware.acpilight.enable = true;
+ environment.systemPackages = [ pkgs.brightnessctl ];
+
+ # --- GPU ---
+ # TODO: adjust for the laptop's actual GPU once known. For an Intel iGPU add
+ # intel-media-driver to hardware.graphics.extraPackages; for a discrete AMD
+ # GPU you may want ROCm as in machines/kusanagi/default.nix.
+}