Migration This is my new public git source viewer. Source coming soon. Please contact with concerns/bugs. Contact me

hosts/RyanMac/configuration.nix

b7d807c39733ce101c55286d6428c19fb31c1ef3 · 9.5 KB · 365 lines raw

1 { config, pkgs, inputs, lib, ... }:
2 let
3 username = "ryan";
4
5 defaultBrowser = "zen";
6
7 thirdPartyTaps = {
8 "netbirdio/homebrew-tap" = inputs.homebrew-netbird;
9 "FelixKratz/homebrew-formulae" = inputs.homebrew-felixkratz;
10 };
11
12 pinnedNixpkgs = pkgs.writeText "flake-registry.json" (builtins.toJSON {
13 version = 2;
14 flakes = [
15 {
16 from = { type = "indirect"; id = "nixpkgs"; };
17 to = {
18 type = "path";
19 path = inputs.nixpkgs.outPath;
20 lastModified = inputs.nixpkgs.lastModified;
21 narHash = inputs.nixpkgs.narHash;
22 };
23 }
24 ];
25 });
26
27 manualHotkeys = {
28 "64" = {
29 enabled = true;
30 };
31 };
32
33 in {
34 # Modules
35 imports = [
36 inputs.nix-homebrew.darwinModules.nix-homebrew
37 ../../modules/darwin/random-wallpaper
38 ../../modules/darwin/yabai
39 ];
40
41 # Define the system's user and home dir location
42 users.users."${username}" = {
43 name = "${username}";
44 home = "/Users/${username}";
45 };
46
47 system.primaryUser = "${username}";
48
49 # Set the hostname for this machine
50 networking.hostName = "RyanMac";
51
52 # Install the wallpaper engine
53 local.randomWallpaper = {
54 enable = true;
55 directory = "${../../files/Wallpapers}";
56 };
57
58 # Configure yabai
59 local.yabai = {
60 enable = true;
61 defaultPadding = 10;
62 defaultTopPadding = 40;
63 displayTopPadding = {
64 "37D8832A-2D66-02CA-B9F7-8F30A301B230" = 10; # macOS retina display
65 };
66 extraSymbolicHotkeys = manualHotkeys;
67 };
68
69 # Configure JankyBorders
70 services.jankyborders = {
71 enable = true;
72 style = "round";
73 width = 6.0;
74 hidpi = true;
75 ax_focus = true;
76 active_color = "gradient(top_left=0xee33ccff,bottom_right=0xee00ff99)";
77 inactive_color = "0xaa595959";
78 };
79
80 # Install the /etc/nix/flake-registry.json file we made above
81 environment.etc."nix/flake-registry.json".source = pinnedNixpkgs;
82
83 # Install RyanCA Root
84 security.pki.certificateFiles = [
85 ../../files/CACerts/RyanCA.crt
86 ];
87
88 # Virby linux builder
89 services.virby = {
90 enable = true;
91 cores = 4;
92 diskSize = "50GiB";
93 onDemand = {
94 enable = true;
95 ttl = 30;
96 };
97 rosetta = true;
98 };
99
100 nix = {
101 enable = true;
102 settings = {
103 flake-registry = "/etc/nix/flake-registry.json";
104 extra-substituters = [
105 "https://virby-nix-darwin.cachix.org"
106 ];
107 extra-trusted-public-keys = [
108 "virby-nix-darwin.cachix.org-1:z9GiEZeBU5bEeoDQjyfHPMGPBaIQJOOvYOOjGMKIlLo="
109 ];
110 "extra-experimental-features" = [ "nix-command" "flakes" ];
111 };
112 };
113
114 # Determines the nix-darwin release compatibility
115 system.stateVersion = 6;
116
117 # System profile programs
118 programs = {
119 zsh.enable = true;
120 };
121
122 # Install homebrew itself
123 nix-homebrew = {
124 enable = true;
125 enableRosetta = true;
126 user = "${username}";
127 mutableTaps = false;
128 taps = {
129 "homebrew/homebrew-core" = inputs.homebrew-core;
130 "homebrew/homebrew-cask" = inputs.homebrew-cask;
131 } // thirdPartyTaps;
132 trust.taps = builtins.attrNames thirdPartyTaps;
133 };
134
135 # Install homebrew casks/apps
136 homebrew = {
137 enable = true;
138
139 onActivation = {
140 #extraFlags = [ "--force-cleanup" ];
141 };
142
143 global.brewfile = true;
144
145 taps = builtins.attrNames config.nix-homebrew.taps;
146
147 brews = [ ];
148
149 casks = [
150 "utm"
151 "ghostty"
152 "zen"
153 "ungoogled-chromium"
154 "tailscale-app"
155 "netbird-ui"
156 "ubersicht"
157 "hammerspoon"
158 "gimp"
159 "kdenlive"
160 "rustdesk"
161 "vorssaint"
162 "obs"
163 ];
164 };
165
166 # Keyboard shortcuts using skhd
167 services.skhd = {
168 enable = true;
169 skhdConfig = ''
170 alt - d : osascript -e 'tell application "System Events" to key code 49 using {command down}'
171 alt - return : osascript -e 'tell application "Ghostty"' -e 'new window' -e 'activate' -e 'end tell'
172 '';
173 };
174
175 # System configuration
176 time.timeZone = "America/New_York";
177
178 power.sleep = {
179 display = 10;
180 computer = 30;
181 };
182
183 system.defaults = {
184 NSGlobalDomain = {
185 # 24 hour time
186 AppleICUForce24HourTime = true;
187
188 # Dark Mode
189 AppleInterfaceStyle = "Dark";
190
191 # Key repeat rate
192 KeyRepeat = 2;
193 InitialKeyRepeat = 35;
194
195 # Swap F1-12 to be default
196 "com.apple.keyboard.fnState" = true;
197
198 # Disable Keyboard bullcrap
199 NSAutomaticCapitalizationEnabled = false;
200 NSAutomaticDashSubstitutionEnabled = false;
201 NSAutomaticPeriodSubstitutionEnabled = false;
202 NSAutomaticQuoteSubstitutionEnabled = false;
203 NSAutomaticSpellingCorrectionEnabled = false;
204 ApplePressAndHoldEnabled = false;
205 };
206
207 # screensaver/power settings
208 screensaver = {
209 askForPassword = true;
210 askForPasswordDelay = 0;
211 };
212
213 # Control center stuff
214 controlcenter = {
215 BatteryShowPercentage = true;
216 Bluetooth = true;
217 };
218
219 # Clock settings
220 menuExtraClock = {
221 Show24Hour = true;
222 ShowDate = 1; # Always
223 ShowDayOfWeek = true;
224 ShowSeconds = true;
225 };
226
227 # Screen capture settings
228 screencapture = {
229 target = "clipboard";
230 type = "png";
231 };
232
233 # finder good settings
234 finder = {
235 AppleShowAllExtensions = true;
236 AppleShowAllFiles = true;
237 ShowPathbar = true;
238 FXEnableExtensionChangeWarning = false;
239 _FXShowPosixPathInTitle = true;
240 NewWindowTarget = "Home";
241 ShowExternalHardDrivesOnDesktop = false;
242 ShowHardDrivesOnDesktop = false;
243 ShowMountedServersOnDesktop = false;
244 ShowRemovableMediaOnDesktop = false;
245 ShowStatusBar = true;
246 };
247
248 spaces = {
249 "spans-displays" = false; # independent spaces per display
250 };
251
252 # Login Window Settings
253 loginwindow = {
254 GuestEnabled = false;
255 DisableConsoleAccess = true;
256 };
257
258 # dock settings
259 dock = {
260 magnification = true;
261 largesize = 96;
262 tilesize = 32;
263 minimize-to-application = false;
264 orientation = "bottom";
265 autohide = true;
266 mru-spaces = false; # Disable auto-rearrange spaces
267 persistent-apps = [
268 { app = "/Applications/Zen.app"; }
269 #{ app = "/System/Applications/Launchpad.app"; }
270 { app = "/System/Applications/Messages.app"; }
271 { app = "/System/Applications/Facetime.app"; }
272 { app = "/System/Applications/Calendar.app"; }
273 { app = "/System/Applications/App Store.app"; }
274 { app = "/System/Applications/System Settings.app"; }
275 { app = "/Applications/Ghostty.app"; }
276 { app = "/Applications/UTM.app"; }
277 ];
278 persistent-others = [
279 { folder = { path = "/Users/${username}/Downloads"; showas = "grid"; arrangement = "date-created"; }; }
280 { folder = { path = "/Users/${username}/Applications"; showas = "grid"; arrangement = "name"; }; }
281 ];
282 show-recents = false;
283 };
284
285 # Custom preferences
286 CustomUserPreferences = {
287 NSGlobalDomain = {
288 # Always show menu bar
289 AppleMenuBarVisibleInFullscreen = true;
290
291 # Hide the menubar by default
292 "_HIHideMenuBar" = true;
293
294 # Option + L lock
295 NSUserKeyEquivalents = {
296 "Lock Screen" = "~l";
297 };
298 };
299
300 "com.apple.desktopservices" = {
301 DSDontWriteNetworkStores = true;
302 DSDontWriteUSBStores = true;
303 };
304
305 "com.apple.WindowManager" = {
306 EnableStandardClickToShowDesktop = false;
307 StandardHideDesktopIcons = false;
308 };
309
310 "com.apple.screensaver" = {
311 askForPassword = true;
312 askForPasswordDelay = 2;
313 };
314
315 "com.apple.AdLib" = {
316 allowApplePersonalizedAdvertising = false;
317 };
318
319 "com.apple.Accessibility" = {
320 ReduceMotionEnabled = 1;
321 };
322 };
323 universalaccess.reduceMotion = true;
324 };
325
326 # Post-Activation scripts
327 system.activationScripts.postActivation.text = ''
328 echo "Configuring NTP servers..."
329 systemsetup -setnetworktimeserver pool.ntp.org > /dev/null 2>&1 || true
330 systemsetup -setusingnetworktime on > /dev/null 2>&1 || true
331
332 ryancasum="$(${pkgs.openssl}/bin/openssl x509 -in "${../../files/CACerts/RyanCA.crt}" -noout -fingerprint -sha1 | sed 's/.*=//; s/://g')"
333 if ! /usr/bin/security find-certificate -a -Z "/Library/Keychains/System.keychain" | tr -d ':' | grep -iq "$ryancasum"; then
334 echo "Installing RyanCA Certificate..."
335 /usr/bin/security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain ${../../files/CACerts/RyanCA.crt}
336 fi
337
338 echo "Reloading Preferences DB..."
339 sudo -iu ${username} /System/Library/PrivateFrameworks/SystemAdministration.framework/Resources/activateSettings -u
340
341 echo "Setting default browser"
342 ${pkgs.defaultbrowser}/bin/defaultbrowser ${defaultBrowser}
343
344 echo "Adding Keyboard brightness controls to Control Center..."
345 sudo -iu ${username} defaults -currentHost write com.apple.controlcenter KeyboardBrightness -int 25
346
347 # this is fragile so it goes at the bottom
348 echo "Reloading skhd..."
349 sudo -iu ${username} ${pkgs.skhd}/bin/skhd -r || echo "Failed to reload skhd; continuing anyway..."
350
351 # Notes if we are running for the first time and writes a message for actions that may need to be done on macOS or linux
352 MARK="/opt/.nix-complete"
353 if [ ! -f "$MARK" ]; then
354 echo "o0o0o0o0o0o MacOS Initial Deploy Notes o0o0o0o0o0o"
355 echo "--------------------------------------------------"
356 echo "The following actions must be taken since they are not configurable by Nix. This must be done only ONCE."
357 echo ""
358 echo "1. Create 9 spaces."
359 echo "2. Set keyboard autofill settings"
360 echo "--------------------------------------------------"
361 fi
362 touch "$MARK"
363 '';
364
365 }