Skip to content

Commit ca02cd4

Browse files
committed
sync
1 parent be247f7 commit ca02cd4

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

45 files changed

+606
-689
lines changed

flake.lock

Lines changed: 119 additions & 145 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

src/nixos/machines/flexy/config/security.nix

Lines changed: 0 additions & 44 deletions
This file was deleted.

src/nixos/machines/ignucius/config/setup.nix

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,11 @@ in {
5353
services.xserver.desktopManager.gnome.enable = true;
5454
programs.dconf.enable = true; # Needed for home-manager to not fail deployment (https://github.com/nix-community/home-manager/issues/3113)
5555
services.xserver.displayManager.gdm.autoSuspend = false;
56+
environment.variables = {
57+
# Required by moonlight for XWayland check bypass
58+
QT_QPA_PLATFORM = "wayland";
59+
};
60+
5661

5762
# Fingerprint
5863
services.fprintd.enable = true;

src/nixos/machines/morph/config/bootloader.nix

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@
33
# Bootloader management of MORPH
44

55
{
6-
boot.lanzaboote.enable = false; # Whether to use NixOS's implementation of secure-boot
7-
boot.loader.systemd-boot.enable = true;
6+
boot.lanzaboote.enable = true; # Whether to use NixOS's implementation of secure-boot
7+
boot.loader.systemd-boot.enable = false;
88

99
boot.loader.efi.canTouchEfiVariables = true;
1010
}

src/nixos/machines/morph/config/kernel.nix

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,10 +9,6 @@ in {
99
# FIXME-SECURITY(Krey): Hardened kernel causes lot of issues, pending custom kernel
1010
boot.kernelPackages = mkForce pkgs.linuxPackages;
1111

12-
# SECURITY(Krey): Blocked by applications
13-
# * anime-game-launcher
14-
security.unprivilegedUsernsClone = true;
15-
1612
# Kernel Modules
1713
boot.kernelModules = [
1814
"kvm-intel" # Use KVM

src/nixos/machines/morph/config/security.nix

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,10 +21,10 @@ in {
2121
];
2222

2323
# SECURITY(Krey): Currently a necessary malware to keep the CPU functional.. Such is the curse of i686/amd64 systems
24-
hardware.cpu.amd.updateMicrocode = mkForce true;
24+
hardware.cpu.intel.updateMicrocode = mkForce true;
2525

26-
# NOTE(Krey): System designed to not need this, but it's required for the RX 570 to initialize for some fucking reason
27-
hardware.enableRedistributableFirmware = mkForce true;
26+
# NOTE(Krey): System designed to not need this
27+
hardware.enableRedistributableFirmware = mkForce false;
2828
}
2929
];
3030
}

src/nixos/machines/morph/config/setup.nix

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,6 @@ in {
1414
nix.distributedBuilds = true; # Perform distributed builds if requested
1515

1616
services.openssh.enable = true;
17-
services.sunshine.enable = true;
1817
services.tor.enable = true;
1918
# FIXME(Krey): Kernel Panic on wake-up
2019
services.autosuspend.enable = false;
@@ -23,6 +22,7 @@ in {
2322
idle_time = 120; # How long would it take to suspend if all wakeups are inactive
2423
};
2524
services.autosuspend.checks.ActiveConnection.ports = builtins.concatStringsSep "," [ "22" ]; # Do Not Suspend On Active SSH Connection
25+
services.sunshine.enable = true;
2626

2727
users.users.root.openssh.authorizedKeys.keys = mkIf config.services.openssh.enable [
2828
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOzh6FRxWUemwVeIDsr681fgJ2Q2qCnwJbvFe4xD15ve [email protected]" # Allow root access for the Super Administrator (KREYREN)

src/nixos/machines/morph/default.nix

Lines changed: 1 addition & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -7,15 +7,8 @@
77
imports = [
88
self.nixosModules.default # Load NiXium's Global configuration
99

10-
# Machines
11-
self.nixosModules.machine-morph
12-
# self.nixosModules.machine-mracek
13-
# self.nixosModules.machine-sinnenfreude
14-
# self.nixosModules.machine-tupac
15-
1610
# Users
1711
self.nixosModules.users-kreyren
18-
self.homeManagerModules."kreyren@morph"
1912

2013
# Files
2114
./config/bootloader.nix
@@ -34,8 +27,8 @@
3427
./services/binfmt.nix
3528
./services/distributedBuilds.nix
3629
./services/openssh.nix
37-
./services/sunshine
3830
./services/tor.nix
31+
./services/sunshine
3932
];
4033
};
4134

src/nixos/machines/mracek/default.nix

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -7,12 +7,6 @@
77
imports = [
88
self.nixosModules.default # Load NiXium's Global configuration
99

10-
# Machines
11-
self.nixosModules.machine-morph
12-
self.nixosModules.machine-mracek
13-
self.nixosModules.machine-sinnenfreude
14-
self.nixosModules.machine-tupac
15-
1610
# Files
1711
./services/binfmt.nix
1812
./services/distributedBuilds.nix
Lines changed: 19 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -1,20 +1,21 @@
11
-----BEGIN AGE ENCRYPTED FILE-----
2-
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IHdlK3M2dyBuemh1
3-
TmdYaEZGKytZdW1YZVdmcmVoeHFZc0c2Q2MyZml3RVVsSmg2RjFNCnVqTVRXSCt0
4-
dGtIUWFJNEo4eVA3c1ZmcVBTZmxBQmVLbGhRVFZsdXhrY2sKLT4gc3NoLWVkMjU1
5-
MTkgU0t3L3p3IFFrSjhtZlJ0WVZYRWpjZUF2YnRCQjVLZ01DTXFIUm4wWVVCblgr
6-
SDNaRVkKRDgrYmptdnQ2WmluZ2RXRVVraXYwN2grTEc4aUQwZTg1cXNzTWljVG5o
7-
MAotPiBnJSRdZS1ncmVhc2UKeWNDQ2NZSkQ0b1BFZ243R3E3YW13cXl2NUVndVha
8-
Rm5kaGI3ZE9SVUR3SmdCTlVGdVhGb0hOb29LVU9hdEZldgoyelpxUXNuS3RuQzc3
9-
aWVTNS8rQXcwM3IKLS0tIFpVVmUwZU9FT29KMlp0cEwzNGlucmZJNWJaNC9xZjhF
10-
U1k3NlRmMjhvNlkKIbFPmweTyrWtVQd8NjTK6tLCMQN8VHWyIauQq8tcKfpZeTvR
11-
P1F0aSAm3US6xpOoZ+/26rQvjygS9Yp8f+QpsWMgWNr27HUFfQmMTr8wdGwnX+QZ
12-
RJPOaB8E7OON/IquyY4cr8c+8zN7Uy6uvePae5sy/4HaAZp4o7fePg4wfOesEV/9
13-
pGVFhah4nZulZgMY0UM43eIbPM4+66HxTUuZG6euxLt/yAT07m8W+fhiNfNZGMLy
14-
YQFRMig5qlvkJklJZja9uJXDcHPRONl/AgKmCe3/mlN5D5e+7Z00bwpLsp0yi0ea
15-
xNP7H/62w1NpNgmN2LotiKEXfhE+5HiX3+jRKp/UMH8D4DTyBrDo6ntPx3volPAD
16-
U2PYggHrF8gG9rfLYj3g6PC7RJbM5jH8ig9UoBciXCBF4MtRozaVwxey/0sMadoU
17-
TLkRvGNb01TJ3kQ1eDHy+1ZBmopECidA/ixVZvB4rWf8bC2BzyF4XWlDLcb8+hxR
18-
QdvQeEYBKE09bbYrP3ucVfBICasl9Me9CCnoeGTtLTna2QsSq+7BwUpH3/9DUozq
19-
/ICBfBmOQiKqYiU/RbqVPAm5LRXMPF4=
2+
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IHdlK3M2dyBFV0lP
3+
Tlo0M0dkcExHemxDbHYyZ3ZxczhndEx1L0VUWVlwbFdpQ2RwQmprCkR6K0tjSjY1
4+
R1owdVNPZGhCVHJ5bC96bVNVY1g0b1pqb2xOblhnaUJnSW8KLT4gc3NoLWVkMjU1
5+
MTkgU0t3L3p3IGJheTN2SXcybUgzZzRtWndXcWJOTjc5ck5KWGdCcThPYnFPMXVu
6+
a280QlUKSHozZjFvTk5IV2NnaDJ3cUh3QkpnK2tmMzhWWHl1SEpEckdmYjQxZzZN
7+
WQotPiBYIzMiLWdyZWFzZSBdIC41eCsmXkooCkhYdDhIRlpqZnZjb0FZai9HWEJN
8+
aDZpeUcxUjZ1WEJxZENqWjdmb1N6S3Z6ZHU3SnlybzczcWxIMnU5RlFrZ2MKNzFp
9+
MkpyblhqUFhCcExMbDhKUjBxdjBwRHp5dXlTNUo1dWJ2QmFjSlgwODlCRUVERHI3
10+
amcyeVBOL2J5VHcKLS0tIHgvMDJhSE9iYmxyMDF3RmVQVWNuYWQwNGYvTzlkK1JT
11+
cGxqdVpUTnFyQW8KiTEWBP9QE6aD0tSNdfXyvmkKk08w7JgGZOt5re11AExJa3zd
12+
b7HaaQe7I5zPCw94Es5IZMTYzVibQmRmwItxULEaS0rKDJrD/Ujwv0omg+XV3Ngg
13+
ppXKLHWCK1Tqw0xpVZ0yOZCH/jU62mGLQHjFJzFlxhsZPGtHJxgJqc+QCgr1zDDK
14+
BySk53T63VoI746yi3luVHTI0lSIxgjCq+6Ed5n7i4jeaMH575WSrnMmxJu+0qN3
15+
e+2gNk1N/crCwsqyWjRgycdrDujr2SW4mar+N7dcKflYUMe5vQM64ZMVP/rnn3yt
16+
up/+qX3IDsL+54Hc10p7y4jJgWo8n45lijzOtgLvD/r0mSWRoHVh2vPublr6ebnI
17+
9CVBkYIcfti5bz4MbDbG6ErX7E0mrBldYyR726mQRqtaJJaIaAGbZ8Wv3mbDb1dr
18+
w6pV6MSj6KKaoEBz6bK/Pr/zvF5Q/K3LvW3m+eegIbsI2f/6QILmONVBmbtsTNZe
19+
BYk+m0HJoqm+OPJTyXTgzoW1U9jLAMh+ZPhrhpBQ86HbNgAVH5v/72hSSmi1gpBi
20+
pm9b0t9B8u2xNYaLnfwPmfYpqgNP7BE=
2021
-----END AGE ENCRYPTED FILE-----

0 commit comments

Comments
 (0)