diff --git a/configuration.nix b/configuration.nix new file mode 100644 index 0000000..4e654e4 --- /dev/null +++ b/configuration.nix @@ -0,0 +1,23 @@ +_: { + hardware.raspberry-pi.firmware.enable = true; + hardware.enableRedistributableFirmware = true; + + # Enable the OpenSSH daemon + services.openssh = { + enable = true; + # Require SSH keys for login (disable passwords) + settings.PasswordAuthentication = false; + }; + + # Define a user account + users.users.jonathan = { + isNormalUser = true; + extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user. + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFGgP6NnoYmgtork7XWkIy/k9lFs91y718S8Ez0PsagC Jonathan@Berrisch.biz" + ]; + }; + + # Allow passwordless sudo for the wheel group (convenient for headless setup) + # security.sudo.wheelNeedsPassword = false; +} diff --git a/flake.lock b/flake.lock new file mode 100644 index 0000000..087f2fe --- /dev/null +++ b/flake.lock @@ -0,0 +1,49 @@ +{ + "nodes": { + "nixos-hardware": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1790722812, + "narHash": "sha256-XwFt1uLyaBCQU1/nUeGqeBnqNXPVgGRnz20YVYdmF6Y=", + "owner": "NixOS", + "repo": "nixos-hardware", + "rev": "06f9ecaea5f64b6ff61cf42cb32f21621c4fa14a", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "master", + "repo": "nixos-hardware", + "type": "github" + } + }, + "nixpkgs": { + "locked": { + "lastModified": 1790822859, + "narHash": "sha256-69xHQhAeMAD2wDXO7T2pcOZIF9Sga2W+JkmY2a11Ops=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "c59305bab2065cfecc4944690d9eedbb56f3a9fa", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "root": { + "inputs": { + "nixos-hardware": "nixos-hardware", + "nixpkgs": "nixpkgs" + } + } + }, + "root": "root", + "version": 7 +} diff --git a/flake.nix b/flake.nix new file mode 100644 index 0000000..5644c37 --- /dev/null +++ b/flake.nix @@ -0,0 +1,26 @@ +{ + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; + nixos-hardware = { + url = "github:NixOS/nixos-hardware/master"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + }; + + outputs = { nixpkgs, nixos-hardware, ... }: { + nixosConfigurations.voron = nixpkgs.lib.nixosSystem { + system = "aarch64-linux"; + modules = [ + "${nixpkgs}/nixos/modules/installer/sd-card/sd-image-aarch64.nix" + nixos-hardware.nixosModules.raspberry-pi-5 + ({ lib, ... }: { + system.stateVersion = "26.05"; + # The pinned Raspberry Pi kernel does not build the ZFS module. + boot.supportedFilesystems.zfs = lib.mkForce false; + hardware.raspberry-pi.firmware.uboot.enable = true; + }) + ./configuration.nix + ]; + }; + }; +}