The nixos-hardware "common-*" profiles the installer selects cover the
basics (microcode, the Intel/AMD VA-API media stack, weekly fstrim), and
power.nix adds thermald + power-profiles-daemon. This adds the gap above
them, generically and detected at install time.
New modules/nixos/hardware.nix exposes a vendor-keyed nomarchy.hardware.*
surface — broadly-beneficial bits default ON when the vendor is detected
(opt-out), heavy/experimental bits behind opt-in toggles:
- intel.enable -> GuC/HuC (i915.enable_guc=3); intel.computeRuntime
(opt-in: intel-compute-runtime + vpl-gpu-rt)
- amd.enable -> amd_pstate=active + radeonsi VA-API env; amd.rocm.enable
+ amd.rocm.gfxOverride (opt-in: ROCm HIP/OpenCL)
- fingerprint.enable -> fprintd; fingerprint.pam (opt-in: login + sudo)
- npu.enable (opt-in/experimental) -> the in-kernel driver
(amdxdna/intel_vpu) keyed by vendor; userspace runtime is BYO
hardware-db.sh now detects Intel/AMD, a fingerprint reader (libfprint USB
vendor IDs) and an NPU (Intel VPU / AMD XDNA PCI IDs), emitting NOMARCHY
lines the installer bakes into system.nix — safe defaults active, opt-ins
commented. Audited against the commons to avoid double-setting.
Verified: flake check green; a toggles-on build has amd_pstate=active +
i915.enable_guc=3 in kernel-params and ships fprintd.service; detection
runs correctly on the (AMD Ryzen-AI) dev machine. On-hardware verification
of the AMD/NPU/Intel-compute runtime bits is still pending.
Docs: template commented examples, README option table, ROADMAP status.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
70 lines
4.0 KiB
Nix
70 lines
4.0 KiB
Nix
# Your machine: bootloader, hostname, users, services.
|
|
# The distro itself comes from nomarchy.nixosModules.nomarchy — override
|
|
# any of its defaults here with plain NixOS options (they use mkDefault),
|
|
# or via the nomarchy.system.* toggles.
|
|
{ pkgs, username, ... }:
|
|
|
|
{
|
|
boot.loader.systemd-boot.enable = true;
|
|
boot.loader.efi.canTouchEfiVariables = true;
|
|
|
|
networking.hostName = "my-nomarchy";
|
|
time.timeZone = "UTC";
|
|
i18n.defaultLocale = "en_US.UTF-8";
|
|
|
|
# Your login user — `username` flows in from flake.nix automatically.
|
|
users.users.${username} = {
|
|
isNormalUser = true;
|
|
extraGroups = [ "wheel" "networkmanager" "video" "input" ];
|
|
};
|
|
|
|
# ── Overrides (uncomment to change) ─────────────────────────────────
|
|
# nomarchy.system.greeter.enable = false; # bring your own login manager
|
|
# environment.systemPackages = [ pkgs.htop ];
|
|
|
|
# ── Opt-in features — uncomment and tweak to enable ─────────────────
|
|
# nomarchy.system.power = { # active power management (laptops)
|
|
# enable = true;
|
|
# backend = "ppd"; # "ppd" (default) or "tlp"
|
|
# laptop = true; # required by batteryChargeLimit
|
|
# batteryChargeLimit = 80; # cap charging for longevity
|
|
# thermal.enable = true; # thermald (Intel CPUs)
|
|
# };
|
|
#
|
|
# nomarchy.hardware = { # enablement above nixos-hardware (installer-detected)
|
|
# intel.enable = true; # GuC/HuC firmware; installer sets this on Intel
|
|
# intel.computeRuntime = true; # OpenCL/oneVPL GPU compute (opt-in)
|
|
# amd.enable = true; # amd-pstate + radeonsi VA-API; installer-set on AMD
|
|
# amd.rocm.enable = true; # ROCm GPU compute (multi-GB, opt-in)
|
|
# amd.rocm.gfxOverride = "11.0.0"; # HSA override for an unlisted iGPU
|
|
# fingerprint.enable = true; # fprintd; installer-set when a reader is detected
|
|
# fingerprint.pam = true; # use the fingerprint for login + sudo
|
|
# npu.enable = true; # on-die NPU driver (experimental; userspace runtime BYO)
|
|
# };
|
|
#
|
|
# nomarchy.services.tailscale.enable = true; # mesh VPN — then `sudo tailscale up`
|
|
# nomarchy.services.syncthing.enable = true; # file sync — GUI at http://127.0.0.1:8384
|
|
# nomarchy.services.podman.enable = true; # rootless containers (docker → podman)
|
|
# nomarchy.services.flatpak.enable = true; # Flatpak + the Flathub remote
|
|
# nomarchy.services.pika.enable = true; # Pika Backup (GUI Borg backups)
|
|
# nomarchy.services.steam.enable = true; # Steam (32-bit libs, controllers, ports)
|
|
# nomarchy.services.libvirt.enable = true; # libvirt/KVM + virt-manager GUI
|
|
# nomarchy.services.obs.enable = true; # OBS Studio + v4l2loopback virtual camera
|
|
# nomarchy.services.docker.enable = true; # Docker rootful (not alongside podman)
|
|
# nomarchy.services.kdeconnect.enable = true;# KDE Connect phone integration (opens ports)
|
|
# nomarchy.services.gamemode.enable = true; # Feral GameMode performance daemon
|
|
# nomarchy.services.adb.enable = true; # Android adb/fastboot tools
|
|
# nomarchy.services.wireshark.enable = true; # Wireshark GUI (wireshark group, no root)
|
|
# nomarchy.services.ollama.enable = true; # local LLM runtime (127.0.0.1:11434)
|
|
# nomarchy.services.printing.enable = true; # CUPS + Avahi network printer discovery
|
|
# nomarchy.services.openrgb.enable = true; # RGB peripheral/motherboard lighting daemon
|
|
# nomarchy.services.restic = { # scheduled (daily) restic backup
|
|
# enable = true;
|
|
# repository = "/mnt/backup/restic"; # path or URL (sftp:/b2:/…)
|
|
# passwordFile = "/etc/nomarchy/restic-password"; # absolute path, NOT in the flake
|
|
# paths = [ "/home" ];
|
|
# };
|
|
|
|
system.stateVersion = "26.05";
|
|
}
|