A fully automated replicable nixos configuration set
This repo is deprecated. See my new config at flake
A fully automated replicable nixos configuration flake that provides re-usable modules, and pre-configured system configuration.
/boot
. Support hibernate.Download and boot in customized LiveCD, and then:
sudo install-script
Follow the instructions and there you go. Above installation script will automatically install ThinkPad X1 Carbon 7th Gen specified configuration, but it should be fine for modern laptops.
If you are on a NVMe SSD, use sudo install-script -n
instead.
If you are outside of Mainland China, please edit the configuration.nix
to use official binary cache only instead of TUNA's. You may also need to adapt the binaryCaches
setting in system/options.nix
to your own network.
See wiki page for details.
As for me, I am on my best to ensure that the system is convenient to use and secure. But here are some concerns:
services.fstrim.enable
is set to true
which means that attacker may be able to perceive the data usage of the fully encrypted disk./
partition encryption in order to eliminate the twice keying in of the LUKS passphrase.I have kept "stealing" in mind while I am writing the whole configuration. Use nix flake show 'github:LEXUGE/nixos'
to see what are available. For example,
github:LEXUGE/nixos/dd59c772a9bd0503da3c775427bbfed64d6dfc61
│ ├───ash-profile: NixOS module
│ └───x-os: NixOS module
ash-profile
is my user space configuration (stuff like zsh, git, emacs config, etc).x-os
my universal core system config.
Also, you can check out related flake repos (netkit.nix, std) which I use a lot here as well.I use GitHub Actions here to build LiveCD actions third times a week (with all flake inputs up-to-date). This means by using the latest ISO image, you are likely to copy a trunk of stuff directly from CD (which is good because you don't need to download them!). After every successful build, my telegram bot would post newly-built release to the CI telegram channel. To save storage that others could otherwise use, only last three images are kept.
Thanks to following repositories: