Migration
This is my new public git source viewer. Source coming soon. Please contact with concerns/bugs.
Contact me
hosts/RyanMac/configuration.nix
3d323731bc263a72c8429f79186f8d9d0c704213
· 9.5 KB · 365 lines
raw
| 1 | { config, pkgs, inputs, lib, ... }: |
| 2 | let |
| 3 | username = "ryan"; |
| 4 | |
| 5 | defaultBrowser = "zen"; |
| 6 | |
| 7 | thirdPartyTaps = { |
| 8 | "netbirdio/homebrew-tap" = inputs.homebrew-netbird; |
| 9 | "FelixKratz/homebrew-formulae" = inputs.homebrew-felixkratz; |
| 10 | }; |
| 11 | |
| 12 | pinnedNixpkgs = pkgs.writeText "flake-registry.json" (builtins.toJSON { |
| 13 | version = 2; |
| 14 | flakes = [ |
| 15 | { |
| 16 | from = { type = "indirect"; id = "nixpkgs"; }; |
| 17 | to = { |
| 18 | type = "path"; |
| 19 | path = inputs.nixpkgs.outPath; |
| 20 | lastModified = inputs.nixpkgs.lastModified; |
| 21 | narHash = inputs.nixpkgs.narHash; |
| 22 | }; |
| 23 | } |
| 24 | ]; |
| 25 | }); |
| 26 | |
| 27 | manualHotkeys = { |
| 28 | "64" = { |
| 29 | enabled = true; |
| 30 | }; |
| 31 | }; |
| 32 | |
| 33 | in { |
| 34 | # Modules |
| 35 | imports = [ |
| 36 | inputs.nix-homebrew.darwinModules.nix-homebrew |
| 37 | ../../modules/darwin/random-wallpaper |
| 38 | ../../modules/darwin/yabai |
| 39 | ]; |
| 40 | |
| 41 | # Define the system's user and home dir location |
| 42 | users.users."${username}" = { |
| 43 | name = "${username}"; |
| 44 | home = "/Users/${username}"; |
| 45 | }; |
| 46 | |
| 47 | system.primaryUser = "${username}"; |
| 48 | |
| 49 | # Set the hostname for this machine |
| 50 | networking.hostName = "RyanMac"; |
| 51 | |
| 52 | # Install the wallpaper engine |
| 53 | local.randomWallpaper = { |
| 54 | enable = true; |
| 55 | directory = "${../../files/Wallpapers}"; |
| 56 | }; |
| 57 | |
| 58 | # Configure yabai |
| 59 | local.yabai = { |
| 60 | enable = true; |
| 61 | defaultPadding = 10; |
| 62 | defaultTopPadding = 40; |
| 63 | displayTopPadding = { |
| 64 | "37D8832A-2D66-02CA-B9F7-8F30A301B230" = 10; # macOS retina display |
| 65 | }; |
| 66 | extraSymbolicHotkeys = manualHotkeys; |
| 67 | }; |
| 68 | |
| 69 | # Configure JankyBorders |
| 70 | services.jankyborders = { |
| 71 | enable = true; |
| 72 | style = "round"; |
| 73 | width = 6.0; |
| 74 | hidpi = true; |
| 75 | ax_focus = true; |
| 76 | active_color = "gradient(top_left=0xee33ccff,bottom_right=0xee00ff99)"; |
| 77 | inactive_color = "0xaa595959"; |
| 78 | }; |
| 79 | |
| 80 | # Install the /etc/nix/flake-registry.json file we made above |
| 81 | environment.etc."nix/flake-registry.json".source = pinnedNixpkgs; |
| 82 | |
| 83 | # Install RyanCA Root |
| 84 | security.pki.certificateFiles = [ |
| 85 | ../../files/CACerts/RyanCA.crt |
| 86 | ]; |
| 87 | |
| 88 | # Virby linux builder |
| 89 | services.virby = { |
| 90 | enable = true; |
| 91 | cores = 4; |
| 92 | diskSize = "50GiB"; |
| 93 | onDemand = { |
| 94 | enable = true; |
| 95 | ttl = 30; |
| 96 | }; |
| 97 | rosetta = true; |
| 98 | }; |
| 99 | |
| 100 | nix = { |
| 101 | enable = true; |
| 102 | settings = { |
| 103 | flake-registry = "/etc/nix/flake-registry.json"; |
| 104 | extra-substituters = [ |
| 105 | "https://virby-nix-darwin.cachix.org" |
| 106 | ]; |
| 107 | extra-trusted-public-keys = [ |
| 108 | "virby-nix-darwin.cachix.org-1:z9GiEZeBU5bEeoDQjyfHPMGPBaIQJOOvYOOjGMKIlLo=" |
| 109 | ]; |
| 110 | "extra-experimental-features" = [ "nix-command" "flakes" ]; |
| 111 | }; |
| 112 | }; |
| 113 | |
| 114 | # Determines the nix-darwin release compatibility |
| 115 | system.stateVersion = 6; |
| 116 | |
| 117 | # System profile programs |
| 118 | programs = { |
| 119 | zsh.enable = true; |
| 120 | }; |
| 121 | |
| 122 | # Install homebrew itself |
| 123 | nix-homebrew = { |
| 124 | enable = true; |
| 125 | enableRosetta = true; |
| 126 | user = "${username}"; |
| 127 | mutableTaps = false; |
| 128 | taps = { |
| 129 | "homebrew/homebrew-core" = inputs.homebrew-core; |
| 130 | "homebrew/homebrew-cask" = inputs.homebrew-cask; |
| 131 | } // thirdPartyTaps; |
| 132 | trust.taps = builtins.attrNames thirdPartyTaps; |
| 133 | }; |
| 134 | |
| 135 | # Install homebrew casks/apps |
| 136 | homebrew = { |
| 137 | enable = true; |
| 138 | |
| 139 | onActivation = { |
| 140 | #extraFlags = [ "--force-cleanup" ]; |
| 141 | }; |
| 142 | |
| 143 | global.brewfile = true; |
| 144 | |
| 145 | taps = builtins.attrNames config.nix-homebrew.taps; |
| 146 | |
| 147 | brews = [ ]; |
| 148 | |
| 149 | casks = [ |
| 150 | "utm" |
| 151 | "ghostty" |
| 152 | "zen" |
| 153 | "ungoogled-chromium" |
| 154 | "tailscale-app" |
| 155 | "netbird-ui" |
| 156 | "ubersicht" |
| 157 | "hammerspoon" |
| 158 | "gimp" |
| 159 | "kdenlive" |
| 160 | "rustdesk" |
| 161 | "vorssaint" |
| 162 | "obs" |
| 163 | ]; |
| 164 | }; |
| 165 | |
| 166 | # Keyboard shortcuts using skhd |
| 167 | services.skhd = { |
| 168 | enable = true; |
| 169 | skhdConfig = '' |
| 170 | alt - d : osascript -e 'tell application "System Events" to key code 49 using {command down}' |
| 171 | alt - return : osascript -e 'tell application "Ghostty"' -e 'new window' -e 'activate' -e 'end tell' |
| 172 | ''; |
| 173 | }; |
| 174 | |
| 175 | # System configuration |
| 176 | time.timeZone = "America/New_York"; |
| 177 | |
| 178 | power.sleep = { |
| 179 | display = 10; |
| 180 | computer = 30; |
| 181 | }; |
| 182 | |
| 183 | system.defaults = { |
| 184 | NSGlobalDomain = { |
| 185 | # 24 hour time |
| 186 | AppleICUForce24HourTime = true; |
| 187 | |
| 188 | # Dark Mode |
| 189 | AppleInterfaceStyle = "Dark"; |
| 190 | |
| 191 | # Key repeat rate |
| 192 | KeyRepeat = 2; |
| 193 | InitialKeyRepeat = 35; |
| 194 | |
| 195 | # Swap F1-12 to be default |
| 196 | "com.apple.keyboard.fnState" = true; |
| 197 | |
| 198 | # Disable Keyboard bullcrap |
| 199 | NSAutomaticCapitalizationEnabled = false; |
| 200 | NSAutomaticDashSubstitutionEnabled = false; |
| 201 | NSAutomaticPeriodSubstitutionEnabled = false; |
| 202 | NSAutomaticQuoteSubstitutionEnabled = false; |
| 203 | NSAutomaticSpellingCorrectionEnabled = false; |
| 204 | ApplePressAndHoldEnabled = false; |
| 205 | }; |
| 206 | |
| 207 | # screensaver/power settings |
| 208 | screensaver = { |
| 209 | askForPassword = true; |
| 210 | askForPasswordDelay = 0; |
| 211 | }; |
| 212 | |
| 213 | # Control center stuff |
| 214 | controlcenter = { |
| 215 | BatteryShowPercentage = true; |
| 216 | Bluetooth = true; |
| 217 | }; |
| 218 | |
| 219 | # Clock settings |
| 220 | menuExtraClock = { |
| 221 | Show24Hour = true; |
| 222 | ShowDate = 1; # Always |
| 223 | ShowDayOfWeek = true; |
| 224 | ShowSeconds = true; |
| 225 | }; |
| 226 | |
| 227 | # Screen capture settings |
| 228 | screencapture = { |
| 229 | target = "clipboard"; |
| 230 | type = "png"; |
| 231 | }; |
| 232 | |
| 233 | # finder good settings |
| 234 | finder = { |
| 235 | AppleShowAllExtensions = true; |
| 236 | AppleShowAllFiles = true; |
| 237 | ShowPathbar = true; |
| 238 | FXEnableExtensionChangeWarning = false; |
| 239 | _FXShowPosixPathInTitle = true; |
| 240 | NewWindowTarget = "Home"; |
| 241 | ShowExternalHardDrivesOnDesktop = false; |
| 242 | ShowHardDrivesOnDesktop = false; |
| 243 | ShowMountedServersOnDesktop = false; |
| 244 | ShowRemovableMediaOnDesktop = false; |
| 245 | ShowStatusBar = true; |
| 246 | }; |
| 247 | |
| 248 | spaces = { |
| 249 | "spans-displays" = false; # independent spaces per display |
| 250 | }; |
| 251 | |
| 252 | # Login Window Settings |
| 253 | loginwindow = { |
| 254 | GuestEnabled = false; |
| 255 | DisableConsoleAccess = true; |
| 256 | }; |
| 257 | |
| 258 | # dock settings |
| 259 | dock = { |
| 260 | magnification = true; |
| 261 | largesize = 96; |
| 262 | tilesize = 32; |
| 263 | minimize-to-application = false; |
| 264 | orientation = "bottom"; |
| 265 | autohide = true; |
| 266 | mru-spaces = false; # Disable auto-rearrange spaces |
| 267 | persistent-apps = [ |
| 268 | { app = "/Applications/Zen.app"; } |
| 269 | #{ app = "/System/Applications/Launchpad.app"; } |
| 270 | { app = "/System/Applications/Messages.app"; } |
| 271 | { app = "/System/Applications/Facetime.app"; } |
| 272 | { app = "/System/Applications/Calendar.app"; } |
| 273 | { app = "/System/Applications/App Store.app"; } |
| 274 | { app = "/System/Applications/System Settings.app"; } |
| 275 | { app = "/Applications/Ghostty.app"; } |
| 276 | { app = "/Applications/UTM.app"; } |
| 277 | ]; |
| 278 | persistent-others = [ |
| 279 | { folder = { path = "/Users/${username}/Downloads"; showas = "grid"; arrangement = "date-created"; }; } |
| 280 | { folder = { path = "/Users/${username}/Applications"; showas = "grid"; arrangement = "name"; }; } |
| 281 | ]; |
| 282 | show-recents = false; |
| 283 | }; |
| 284 | |
| 285 | # Custom preferences |
| 286 | CustomUserPreferences = { |
| 287 | NSGlobalDomain = { |
| 288 | # Always show menu bar |
| 289 | AppleMenuBarVisibleInFullscreen = true; |
| 290 | |
| 291 | # Hide the menubar by default |
| 292 | "_HIHideMenuBar" = true; |
| 293 | |
| 294 | # Option + L lock |
| 295 | NSUserKeyEquivalents = { |
| 296 | "Lock Screen" = "~l"; |
| 297 | }; |
| 298 | }; |
| 299 | |
| 300 | "com.apple.desktopservices" = { |
| 301 | DSDontWriteNetworkStores = true; |
| 302 | DSDontWriteUSBStores = true; |
| 303 | }; |
| 304 | |
| 305 | "com.apple.WindowManager" = { |
| 306 | EnableStandardClickToShowDesktop = false; |
| 307 | StandardHideDesktopIcons = false; |
| 308 | }; |
| 309 | |
| 310 | "com.apple.screensaver" = { |
| 311 | askForPassword = true; |
| 312 | askForPasswordDelay = 2; |
| 313 | }; |
| 314 | |
| 315 | "com.apple.AdLib" = { |
| 316 | allowApplePersonalizedAdvertising = false; |
| 317 | }; |
| 318 | |
| 319 | "com.apple.Accessibility" = { |
| 320 | ReduceMotionEnabled = 1; |
| 321 | }; |
| 322 | }; |
| 323 | universalaccess.reduceMotion = true; |
| 324 | }; |
| 325 | |
| 326 | # Post-Activation scripts |
| 327 | system.activationScripts.postActivation.text = '' |
| 328 | echo "Configuring NTP servers..." |
| 329 | systemsetup -setnetworktimeserver pool.ntp.org > /dev/null 2>&1 || true |
| 330 | systemsetup -setusingnetworktime on > /dev/null 2>&1 || true |
| 331 | |
| 332 | ryancasum="$(${pkgs.openssl}/bin/openssl x509 -in "${../../files/CACerts/RyanCA.crt}" -noout -fingerprint -sha1 | sed 's/.*=//; s/://g')" |
| 333 | if ! /usr/bin/security find-certificate -a -Z "/Library/Keychains/System.keychain" | tr -d ':' | grep -iq "$ryancasum"; then |
| 334 | echo "Installing RyanCA Certificate..." |
| 335 | /usr/bin/security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain ${../../files/CACerts/RyanCA.crt} |
| 336 | fi |
| 337 | |
| 338 | echo "Reloading Preferences DB..." |
| 339 | sudo -iu ${username} /System/Library/PrivateFrameworks/SystemAdministration.framework/Resources/activateSettings -u |
| 340 | |
| 341 | echo "Setting default browser" |
| 342 | ${pkgs.defaultbrowser}/bin/defaultbrowser ${defaultBrowser} |
| 343 | |
| 344 | echo "Adding Keyboard brightness controls to Control Center..." |
| 345 | sudo -iu ${username} defaults -currentHost write com.apple.controlcenter KeyboardBrightness -int 25 |
| 346 | |
| 347 | # this is fragile so it goes at the bottom |
| 348 | echo "Reloading skhd..." |
| 349 | sudo -iu ${username} ${pkgs.skhd}/bin/skhd -r || echo "Failed to reload skhd; continuing anyway..." |
| 350 | |
| 351 | # Notes if we are running for the first time and writes a message for actions that may need to be done on macOS or linux |
| 352 | MARK="/opt/.nix-complete" |
| 353 | if [ ! -f "$MARK" ]; then |
| 354 | echo "o0o0o0o0o0o MacOS Initial Deploy Notes o0o0o0o0o0o" |
| 355 | echo "--------------------------------------------------" |
| 356 | echo "The following actions must be taken since they are not configurable by Nix. This must be done only ONCE." |
| 357 | echo "" |
| 358 | echo "1. Create 9 spaces." |
| 359 | echo "2. Set keyboard autofill settings" |
| 360 | echo "--------------------------------------------------" |
| 361 | fi |
| 362 | touch "$MARK" |
| 363 | ''; |
| 364 | |
| 365 | } |