# Your machine: bootloader, hostname, users, services. # The distro itself comes from nomarchy.nixosModules.nomarchy — override # any of its defaults here with plain NixOS options (they use mkDefault), # or via the nomarchy.system.* toggles. # # Source of truth for install and flake-init: nomarchy-install copies this # file and only patches placeholders + the __NOMARCHY_INSTALLER__ region. { pkgs, username, ... }: { boot.loader.systemd-boot.enable = true; boot.loader.efi.canTouchEfiVariables = true; networking.hostName = "my-nomarchy"; time.timeZone = "UTC"; i18n.defaultLocale = "en_US.UTF-8"; # One keyboard layout everywhere: xkb is the source of truth; the distro # defaults (console.useXkbConfig + systemd initrd) derive the virtual # console and the LUKS passphrase prompt from it. Match home.nix # nomarchy.keyboard.*. services.xserver.xkb.layout = "us"; services.xserver.xkb.variant = ""; # Your login user — `username` flows in from flake.nix automatically. # The installer adds initialHashedPassword here; flake-init: set a password # (or users.mutableUsers) before first boot if needed. users.users.${username} = { isNormalUser = true; extraGroups = [ "wheel" "networkmanager" "video" "input" ]; }; # __NOMARCHY_INSTALLER_BEGIN__ # Installer fills this region (power, hardware, snapper, resume, autoLogin). # Flake-init: leave empty and use the commented catalog below, or enable # snapper when on BTRFS with a /.snapshots subvolume: # nomarchy.system.snapper.enable = true; # __NOMARCHY_INSTALLER_END__ # ── Overrides (uncomment to change) ───────────────────────────────── # nomarchy.system.greeter.enable = false; # bring your own login manager # environment.systemPackages = [ pkgs.htop ]; # ── Opt-in features — uncomment and tweak to enable ───────────────── # nomarchy.system.power = { # active power management (laptops) # enable = true; # backend = "ppd"; # "ppd" (default) or "tlp" # laptop = true; # required by batteryChargeLimit # batteryChargeLimit = 80; # cap charging for longevity # thermal.enable = true; # thermald (Intel CPUs) # }; # # nomarchy.system.autoTimezone.enable = true; # clock follows your location # # (geoclue); travelling updates the # # time on its own. Unsets time.timeZone # # above. Easier toggled from System menu. # # nomarchy.hardware = { # enablement above nixos-hardware (installer-detected) # intel.enable = true; # GuC/HuC firmware; installer sets this on Intel # intel.computeRuntime = true; # OpenCL/oneVPL GPU compute (opt-in) # amd.enable = true; # amd-pstate + radeonsi VA-API; installer-set on AMD # amd.rocm.enable = true; # ROCm GPU compute (multi-GB, opt-in) # amd.rocm.gfxOverride = "11.0.0"; # HSA override for an unlisted iGPU # fingerprint.enable = true; # fprintd; installer-set when a reader is detected # fingerprint.pam = true; # pin the fingerprint on/off instead of letting the # # System › Fingerprint toggle own it (this line WINS # # over the menu — leave it commented to use the menu) # fingerprint.parallel = false; # sequential prompt instead of password-or-finger # npu.enable = true; # on-die NPU driver (experimental; userspace runtime BYO) # latestKernel = true; # newest kernel for very-new hardware (drivers not yet in the default) # camera.hideIrSensor = true; # dual-sensor webcam: hide the IR node so apps get the color cam # # (installer-set when a paired RGB+IR webcam is detected) # i2c.enable = true; # /dev/i2c-* (RGB, sensors); ddcci is distro-default for external brightness # i2c.ddcci = true; # already mkDefault true — set false to opt out # }; # # nomarchy.services.tailscale.enable = true; # mesh VPN — connect from System › VPN # # (login user is operator, no sudo) # nomarchy.services.syncthing.enable = true; # file sync — GUI at http://127.0.0.1:8384 # nomarchy.services.podman.enable = true; # rootless containers (docker → podman) # nomarchy.services.flatpak.enable = true; # Flatpak + the Flathub remote # nomarchy.services.pika.enable = true; # Pika Backup (GUI Borg backups) # nomarchy.services.steam.enable = true; # Steam (32-bit libs, controllers, ports) # nomarchy.services.libvirt.enable = true; # libvirt/KVM + virt-manager GUI # nomarchy.services.obs.enable = true; # OBS Studio + v4l2loopback virtual camera # nomarchy.services.docker.enable = true; # Docker rootful (not alongside podman) # nomarchy.services.kdeconnect.enable = true;# KDE Connect phone integration (opens ports) # nomarchy.services.gamemode.enable = true; # Feral GameMode performance daemon # nomarchy.services.adb.enable = true; # Android adb/fastboot tools # nomarchy.services.wireshark.enable = true; # Wireshark GUI (wireshark group, no root) # nomarchy.services.ollama.enable = true; # local LLM runtime (127.0.0.1:11434) # nomarchy.services.printing.enable = true; # CUPS + Avahi network printer discovery # nomarchy.services.openrgb.enable = true; # RGB peripheral/motherboard lighting daemon # nomarchy.services.restic = { # scheduled (daily) restic backup # enable = true; # repository = "/mnt/backup/restic"; # path or URL (sftp:/b2:/…) # passwordFile = "/etc/nomarchy/restic-password"; # absolute path, NOT in the flake # paths = [ "/home" ]; # }; system.stateVersion = "26.05"; }