LUCAZEAU Alexandre 2023-10-23 09:43:50 +02:00
{ pkgs, config, ... }: {
imports = [
# ./himalaya.nix
home.stateVersion = "23.05";
home.username = "alexandre";
home.homeDirectory = "/home/alexandre";
home.keyboard = {
layout = "fr";
variant = "bepo";
xdg.configFile = {
"i3/config".source = ./configs/i3config;

# Edit this configuration file to define what should be installed on
# your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running nixos-help).
{ config, lib, pkgs, ... }:
imports =
[ # Include the results of the hardware scan.
# modules/starship.nix
# modules/powermanagement.nix
boot = {
loader.systemd-boot.enable = true;
loader.efi.canTouchEfiVariables = true;
plymouth.enable = true;
tmp.cleanOnBoot = true;
kernelParams = [ "i915.enable_fbc=1" ];
boot.initrd.luks.fido2Support = true;
boot.initrd.luks.devices."/dev/sda2".device = "/dev/sda2";
boot.initrd.luks.devices."/dev/sda2".fido2.credential = "a67d17616bf2568727498dffa95205df943383ab3a2f9798606532d5791a155a37dd52dae2262619c1da2be7562ec9dd94888c71a9326fea70dfe16214b5ea8ec0143b010000";
hardware = {
# Enable microcode updates for Intel CPU = true;
# Enable Kernel same-page merging
ksm.enable = true;
# Enable all the firmware
enableAllFirmware = true;
# Enable all the firmware with a license allowing redistribution. (i.e. free firmware and firmware-linux-nonfree)
enableRedistributableFirmware = true;
# Enable OpenGL drivers
opengl.enable = true;
opengl.extraPackages = with pkgs; [
pulseaudio = {
enable = true;
# Set your time zone.
time.timeZone = "Europe/Paris";
nixpkgs.config.allowUnfree = true;
i18n.defaultLocale = "fr_FR.UTF-8";
console = {
font = "Lat2-Terminus16";
keyMap = "fr";
fonts = {
fontDir.enable = true;
enableGhostscriptFonts = true;
fonts = with pkgs; [
programs = {
fish.enable = true;
fish.interactiveShellInit = ''
set -gx EDITOR nvim
ssh = {
setXAuthLocation = true;
forwardX11 = true;
programs.thunar.enable = true;
programs.thunar.plugins = with pkgs.xfce; [
# Enable sound.
sound.enable = true;
system.stateVersion = "23.05"; # Did you read the comment?
users = {
groups.ntp = {};
defaultUserShell = "/run/current-system/sw/bin/fish";
extraUsers.alexandre = {
isNormalUser = true;
home = "/home/alexandre";
description = "alexandre";
extraGroups = [ "wheel" "networkmanager" "docker" "libvirtd" "scanner" "plocate" "lp" ];
# hashedPassword = "$6$7m77oPQxa$W9YnRLo1X2eqztBHwpoH8diHGkBno5O39AMyL9Qm8y8I6uW63H2Nwx4p239OG5zhOxA8J1lZvHTQ3hKPSP9mT/";
environment.systemPackages = with pkgs; [
environment.variables.EDITOR = "nvim";
nix.settings.experimental-features = [ "nix-command" "flakes" ];

# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
imports =
[ (modulesPath + "/installer/scan/not-detected.nix")
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "usb_storage" "sd_mod" "sr_mod" ];
boot.initrd.kernelModules = [ "dm-snapshot" ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "/dev/disk/by-uuid/b670bb55-7e29-4477-8f58-118c42598f40";
fsType = "ext4";
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/0BEC-722D";
fsType = "vfat";
swapDevices =
[ { device = "/dev/disk/by-uuid/d52b6afe-cb3f-4e92-8e4b-5394a0bef647"; }
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.enp0s31f6.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
powerManagement.cpuFreqGovernor = lib.mkDefault "powersave"; = lib.mkDefault config.hardware.enableRedistributableFirmware;
boot.initrd.luks.devices = {
"partitions" = {
device = "/dev/sda2";
preLVM = true; # You may want to set this to false if you need to start a network service first

{ config, pkgs, ... }:
services = {
avahi = {
enable = true;
openFirewall = true;
printing.enable = true;
clamav = {
daemon.enable = true;
updater.enable = true;
locate = {
enable = true;
locate = pkgs.plocate;
interval = "hourly";
localuser = null;
redshift = {
enable = true;
brightness = {
# Note the string values below.
day = "1";
night = "1";
temperature = {
day = 5500;
night = 3700;
geoclue2.appConfig.redshift.isAllowed = true;
automatic-timezoned.enable = true;
xserver = {
enable = true;
autorun = true;
windowManager.i3.enable = true;
displayManager.defaultSession = "none+i3";
layout = "fr";
xkbOptions = "eurosign:e";
openssh = {
enable = true;
settings.PermitRootLogin = "no";
ntp.enable = true;
tlp.enable = true;
fstrim.enable = true;

{ config, pkgs, theme, ... }:
programs.firefox = {
enable = true;
package = pkgs.wrapFirefox pkgs.firefox-unwrapped {
extraPolicies = {
CaptivePortal = false;
DisableFirefoxStudies = true;
DisablePocket = true;
DisableTelemetry = true;
DisableFirefoxAccounts = false;
NoDefaultBookmarks = true;
OfferToSaveLogins = true;
OfferToSaveLoginsDefault = true;
PasswordManagerEnabled = true;
FirefoxHome = {
Search = true;
Pocket = false;
Snippets = false;
TopSites = false;
Highlights = false;
UserMessaging = {
ExtensionRecommendations = false;
SkipOnboarding = true;
profiles = {
alexandre = {
id = 0;
name = "alexandre";
search = {
force = true;
default = "Google";
engines = {
"Nix Packages" = {
urls = [{
template = "";
params = [
{ name = "type"; value = "packages"; }
{ name = "query"; value = "{searchTerms}"; }
icon = "${pkgs.nixos-icons}/share/icons/hicolor/scalable/apps/nix-snowflake.svg";
definedAliases = [ "@np" ];
"NixOS Wiki" = {
urls = [{ template = "{searchTerms}"; }];
iconUpdateURL = "";
updateInterval = 24 * 60 * 60 * 1000;
definedAliases = [ "@nw" ];
"Wikipedia (en)".metaData.alias = "@wiki";
"Google".metaData.hidden = false;
"".metaData.hidden = true;
"Bing".metaData.hidden = true;
"eBay".metaData.hidden = true;
extensions = with pkgs.nur.repos.rycee.firefox-addons; [
settings = {
"general.smoothScroll" = true;
# extraConfig = ''
# user_pref("full-screen-api.ignore-widgets", true);
# user_pref("media.ffmpeg.vaapi.enabled", true);
# user_pref("media.rdd-vpx.enabled", true);
# '';

{ pkgs, config, ... }: { { config, pkgs, ... }:
imports = [ imports = [
./packages.nix ./firefox.nix
# ./himalaya.nix
]; ];
home.stateVersion = "23.05"; # Home Manager needs a bit of information about you and the paths it should
# manage.
home.username = "alexandre"; home.username = "alexandre";
home.homeDirectory = "/home/alexandre"; home.homeDirectory = "/home/alexandre";
home.keyboard = {
layout = "fr"; # This value determines the Home Manager release that your configuration is
variant = "bepo"; # compatible with. This helps avoid breakage when a new Home Manager release
# introduces backwards incompatible changes.
# You should not change this value, even if you update Home Manager. If you do
# want to update the value, then make sure to first check the Home Manager
# release notes.
home.stateVersion = "23.05"; # Please read the comment before changing.
# The home.packages option allows you to install Nix packages into your
# environment.
home.packages = [
# # Adds the 'hello' command to your environment. It prints a friendly
# # "Hello, world!" when run.
# pkgs.hello
# # It is sometimes useful to fine-tune packages, for example, by applying
# # overrides. You can do that directly here, just don't forget the
# # parentheses. Maybe you want to install Nerd Fonts with a limited number of
# # fonts?
# (pkgs.nerdfonts.override { fonts = [ "FantasqueSansMono" ]; })
# # You can also create simple shell scripts directly inside your
# # configuration. For example, this adds a command 'my-hello' to your
# # environment:
# (pkgs.writeShellScriptBin "my-hello" ''
# echo "Hello, ${config.home.username}!"
# '')
# Home Manager is pretty good at managing dotfiles. The primary way to manage
# plain files is through 'home.file'.
home.file = {
# # Building this configuration will create a copy of 'dotfiles/screenrc' in
# # the Nix store. Activating the configuration will then make '~/.screenrc' a
# # symlink to the Nix store copy.
# ".screenrc".source = dotfiles/screenrc;
# # You can also set the file content immediately.
# ".gradle/".text = ''
# org.gradle.console=verbose
# org.gradle.daemon.idletimeout=3600000
# '';
}; };
xdg.configFile = {
"i3/config".source = ./configs/i3config; # You can also manage environment variables but you will have to manually
# source
# ~/.nix-profile/etc/profile.d/
# or
# /etc/profiles/per-user/alexandre/etc/profile.d/
# if you don't want to manage your shell through Home Manager.
home.sessionVariables = {
# EDITOR = "emacs";
}; };
# Let Home Manager install and manage itself.
programs.home-manager.enable = true;
} }

# Edit this configuration file to define what should be installed on # Edit this configuration file to define what should be installed on
# your system. Help is available in the configuration.nix(5) man page # your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running nixos-help). # and in the NixOS manual (accessible by running `nixos-help`).
{ config, lib, pkgs, ... }: { config, pkgs, ... }:
{ {
imports = imports =
[ # Include the results of the hardware scan. [ # Include the results of the hardware scan.
./hardware-configuration.nix ./hardware-configuration.nix
./services.nix ./services.nix
./network.nix ./extra_hw.nix
# modules/starship.nix
# modules/powermanagement.nix
]; ];
boot = { boot = {
loader.systemd-boot.enable = true; loader.systemd-boot.enable = true;
loader.efi.canTouchEfiVariables = true; loader.grub.efiSupport = true;
loader.grub.efiInstallAsRemovable = true;
loader.grub.device = "nodev";
plymouth.enable = true; plymouth.enable = true;
tmp.cleanOnBoot = true; tmp.cleanOnBoot = true ;
kernelParams = [ "i915.enable_fbc=1" ]; kernelParams = [ "i915.enable_fbc=1" ];
}; };
boot.initrd.luks.fido2Support = true;
boot.initrd.luks.devices."/dev/sda2".device = "/dev/sda2";
boot.initrd.luks.devices."/dev/sda2".fido2.credential = "a67d17616bf2568727498dffa95205df943383ab3a2f9798606532d5791a155a37dd52dae2262619c1da2be7562ec9dd94888c71a9326fea70dfe16214b5ea8ec0143b010000";
hardware = { networking = {
# Enable microcode updates for Intel CPU hostName = "d2nix"; # Define your hostname. = true; networkmanager.enable = true;
# Enable Kernel same-page merging firewall.enable = true;
ksm.enable = true;
# Enable all the firmware
enableAllFirmware = true;
# Enable all the firmware with a license allowing redistribution. (i.e. free firmware and firmware-linux-nonfree)
enableRedistributableFirmware = true;
# Enable OpenGL drivers
opengl.enable = true;
opengl.extraPackages = with pkgs; [
pulseaudio = {
enable = true;
}; };
# Set your time zone. # Set your time zone.
time.timeZone = "Europe/Paris"; time.timeZone = "Europe/Paris";
nixpkgs.config.allowUnfree = true;
i18n.defaultLocale = "fr_FR.UTF-8"; i18n.defaultLocale = "fr_FR.UTF-8";
console = { console = {
font = "Lat2-Terminus16"; font = "Lat2-Terminus16";
keyMap = "fr"; keyMap = "fr";
}; };
fonts = { fonts = {
fontDir.enable = true; fontDir.enable = true;
enableGhostscriptFonts = true; enableGhostscriptFonts = true;
fonts = with pkgs; [ fonts = with pkgs; [
corefonts corefonts
vistafonts vistafonts
inconsolata inconsolata
terminus_font terminus_font
proggyfonts proggyfonts
@ -78,30 +52,15 @@
source-code-pro source-code-pro
source-sans-pro source-sans-pro
source-serif-pro source-serif-pro
]; ];
}; };
programs = { #sound.enable = true;
fish.enable = true;
fish.interactiveShellInit = ''
set -gx EDITOR nvim
ssh = {
setXAuthLocation = true;
forwardX11 = true;
programs.thunar.enable = true;
programs.thunar.plugins = with pkgs.xfce; [ # Define a user account. Don't forget to set a password with passwd.
# Enable sound.
sound.enable = true;
system.stateVersion = "23.05"; # Did you read the comment?
users = { users = {
groups.ntp = {}; groups.ntp = {};
defaultUserShell = "/run/current-system/sw/bin/fish"; defaultUserShell = "/run/current-system/sw/bin/fish";
@ -110,18 +69,109 @@
home = "/home/alexandre"; home = "/home/alexandre";
description = "alexandre"; description = "alexandre";
extraGroups = [ "wheel" "networkmanager" "docker" "libvirtd" "scanner" "plocate" "lp" ]; extraGroups = [ "wheel" "networkmanager" "docker" "libvirtd" "scanner" "plocate" "lp" ];
# hashedPassword = "$6$7m77oPQxa$W9YnRLo1X2eqztBHwpoH8diHGkBno5O39AMyL9Qm8y8I6uW63H2Nwx4p239OG5zhOxA8J1lZvHTQ3hKPSP9mT/"; packages = with pkgs; [
}; firefox
}; gitAndTools.gitFull
environment.systemPackages = with pkgs; [
]; ];
extraUsers.oem = {
isNormalUser = true;
home = "/home/oem";
description = "oem";
extraGroups = [ "wheel" "networkmanager" ];
environment.variables.EDITOR = "nvim"; environment.variables = {
EDITOR = "nvim";
BROWSER = "firefox";
LESS = "--quit-if-one-screen --RAW-CONTROL-CHARS";
TERMINAL = "xfce4-terminal";
PRIVATE_BROWSER = "firefox -private";
security = {
rtkit.enable = true; # for pipewire
apparmor.enable = true;
pam = {
u2f = {
enable = true;
control = "requisite";
services = {
login.u2fAuth = true;
lightdm.u2fAuth = true;
gdm.u2fAuth = true;
nix.settings.experimental-features = [ "nix-command" "flakes" ]; nix.settings.experimental-features = [ "nix-command" "flakes" ];
nixpkgs.config = {
allowUnfree = true;
}; = true;
nix.gc = {
automatic = true;
dates = "weekly";
persistent = true;
options = "--delete-older-than 10d";
programs = {
htop = {
enable = true;
settings.show_cpu_temperature = 1;
fish = {
enable = true;
interactiveShellInit = ''
set -gx EDITOR nvim
shellAliases = {
ll = "ls -l";
ls = "lsd";
cat = "bat";
sysrs = "sudo nixos-rebuild switch";
sysup = "sudo nixos-rebuild switch --upgrade";
sysclean = "sudo nix-collect-garbage -d; and sudo nix-store --optimise";
# nvim = "nvim -u ~/.config/nvim/init.lua";
environment.systemPackages = with pkgs; [
# Some programs need SUID wrappers, can be configured further or are
# started in user sessions.
# programs.gnupg.agent = {
# enable = true;
# enableSSHSupport = true;
# };
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions
# on your system were taken. It's perfectly fine and recommended to leave
# this value at the release version of the first install of this system.
# Before changing this value read the documentation for this option
# (e.g. man configuration.nix or on
system.stateVersion = "23.05"; # Did you read the comment?
nixpkgs.config.packageOverrides = pkgs: {
nur = import (builtins.fetchTarball "") {
inherit pkgs;
} }

{ config, pkgs, ... }:
hardware = { = true;
enableAllFirmware = true;
pulseaudio.enable = false;
bluetooth = {
enable = true;
settings = {
General = {
Enable = "Source,Sink,Media,Socket";
logitech = {
wireless.enable = true;
wireless.enableGraphical = true;
opengl = {
enable = true;
extraPackages = with pkgs; [
intel-media-driver # LIBVA_DRIVER_NAME=iHD
vaapiIntel # LIBVA_DRIVER_NAME=i965 (older but works better for Firefox/Chromium)
# Video acceleration
nixpkgs.config.packageOverrides = pkgs: {
vaapiIntel = pkgs.vaapiIntel.override { enableHybridCodec = true; };

[ (modulesPath + "/installer/scan/not-detected.nix") [ (modulesPath + "/installer/scan/not-detected.nix")
]; ];
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "usb_storage" "sd_mod" "sr_mod" ]; boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usb_storage" "usbhid" "sd_mod" "sr_mod" "vfat" "nls_cp437" "nls_iso8859-1" ];
boot.initrd.kernelModules = [ "dm-snapshot" ]; boot.initrd.kernelModules = [ "dm-snapshot" "coretemp" ];
boot.kernelModules = [ "kvm-intel" ]; boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ]; boot.extraModulePackages = [ ];
fileSystems."/" = fileSystems."/" =
{ device = "/dev/disk/by-uuid/b670bb55-7e29-4477-8f58-118c42598f40"; { device = "/dev/disk/by-uuid/8eea016d-9dd3-4149-8e5c-014d7d90695f";
fsType = "ext4"; fsType = "ext4";
}; };
fileSystems."/boot" = fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/0BEC-722D"; { device = "/dev/disk/by-uuid/0382-3D00";
fsType = "vfat"; fsType = "vfat";
}; };
swapDevices = swapDevices =
[ { device = "/dev/disk/by-uuid/d52b6afe-cb3f-4e92-8e4b-5394a0bef647"; } [ { device = "/dev/disk/by-uuid/1ffd2601-020f-4635-923b-4053676070d7"; }
]; ];
# boot.initrd.luks.yubikeySupport = true;
boot.initrd.luks.devices = {
"partitions" = {
device = "/dev/sda2";
preLVM = true;
crypttabExtraOpts = ["fido2-device=auto"];
boot.initrd.systemd.enable = true;
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking # Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's # (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction # still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`. # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true; networking.useDHCP = lib.mkDefault true;
# networking.interfaces.enp0s31f6.useDHCP = lib.mkDefault true; # networking.interfaces.enp0s31f6.useDHCP = lib.mkDefault true;
# networking.interfaces.wlp0s20f0u10.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
powerManagement.cpuFreqGovernor = lib.mkDefault "powersave"; powerManagement.cpuFreqGovernor = lib.mkDefault "powersave"; = lib.mkDefault config.hardware.enableRedistributableFirmware; = lib.mkDefault config.hardware.enableRedistributableFirmware;
boot.initrd.luks.devices = {
"partitions" = {
device = "/dev/sda2";
preLVM = true; # You may want to set this to false if you need to start a network service first
} }

{ config, pkgs, ... }:
# Enable touchpad support (enabled default in most desktopManager).
# services.xserver.libinput.enable = true;

{ config, pkgs, ... }: { config, pkgs, ... }:
{ {
services = { services = {
avahi = { avahi = {
enable = true; enable = true;
openFirewall = true; openFirewall = true;
}; };
printing.enable = true;
clamav = { clamav = {
daemon.enable = true; daemon.enable = true;
updater.enable = true; updater.enable = true;
}; };
ntp = {
enable = true;
thermald = {
enable = true;
fstrim = {
enable = true;
locate = { locate = {
enable = true; enable = true;
locate = pkgs.plocate; locate = pkgs.plocate;
interval = "hourly"; interval = "hourly";
localuser = null; localuser = null;
}; };
redshift = {
pipewire = {
enable = true; enable = true;
brightness = { alsa.enable = true;
# Note the string values below. alsa.support32Bit = true;
day = "1"; pulse.enable = true;
night = "1";
}; };
temperature = {
day = 5500; # Enable the X11 windowing system.
night = 3700;
geoclue2.appConfig.redshift.isAllowed = true;
automatic-timezoned.enable = true;
xserver = { xserver = {
enable = true; enable = true;
autorun = true; # Configure keymap in X11
windowManager.i3.enable = true;
displayManager.defaultSession = "none+i3";
layout = "fr"; layout = "fr";
xkbOptions = "eurosign:e"; xkbOptions = "eurosign:e,caps:escape";
# Enable the GNOME Desktop Environment.
displayManager.gdm.enable = true;
desktopManager.gnome.enable = true;
}; };
openssh = { udev.extraRules = ''
enable = true; ACTION=="remove", ENV{ID_VENDOR_ID}=="1050", ENV{ID_MODEL_ID}=="0407", ENV{DISPLAY}=":0", ENV{XAUTHORITY}="/home/alexandre/.Xauthority" RUN+="${pkgs.sudo}/bin/sudo -u alexandre ${pkgs.xdg-utils}/bin/xdg-screensaver lock"
settings.PermitRootLogin = "no"; '';
ntp.enable = true;
tlp.enable = true;
fstrim.enable = true;
}; };
} }