aboutsummaryrefslogtreecommitdiff
path: root/modules/boot/nixos/default.nix
diff options
context:
space:
mode:
authorCollin Williams <96917990+bluedragon1221@users.noreply.github.com>2026-01-29 20:15:19 -0600
committerCollin Williams <96917990+bluedragon1221@users.noreply.github.com>2026-01-30 08:38:21 -0600
commitc9a1d2da80bca0a85e8c18f6d2db71c4d1127eda (patch)
tree9da79e318ff0533a3708aee85a0b6a6d7f1d1036 /modules/boot/nixos/default.nix
parentc81952cbcb6c6f1b41c2b6e2a366891991cceaee (diff)
Spring Cleaning
- create new module, `system`, that consumes the `boot` module and takes in the more system-interested services from the `services` module - touch up left over services (which are more self-hosting interested) - touch up yo and yoshi configs
Diffstat (limited to 'modules/boot/nixos/default.nix')
-rw-r--r--modules/boot/nixos/default.nix81
1 files changed, 0 insertions, 81 deletions
diff --git a/modules/boot/nixos/default.nix b/modules/boot/nixos/default.nix
deleted file mode 100644
index 49cca5e..0000000
--- a/modules/boot/nixos/default.nix
+++ /dev/null
@@ -1,81 +0,0 @@
-{
- pkgs,
- config,
- lib,
- ...
-}: let
- cfg = config.collinux.boot;
-in {
- imports = [
- ./plymouth.nix
- ];
-
- boot =
- {
- bcache.enable = false; # why is this default on? I DON'T CARE ABOUT bcache
- initrd = {
- verbose = false;
- systemd.enable = true;
- checkJournalingFS = false;
- };
- loader = {
- systemd-boot = lib.optionalAttrs (cfg.systemd-boot.enable && !cfg.secureBoot.enable) {
- enable = true;
- configurationLimit = 3;
- };
- efi.canTouchEfiVariables = true;
- timeout = cfg.timeout; # hold space to show boot menu
- };
-
- # from hardened.nix
- blacklistedKernelModules = [
- # Obscure network protocols
- "ax25"
- "netrom"
- "rose"
-
- # Old or rare or insufficiently audited filesystems
- "adfs"
- "affs"
- "bfs"
- "befs"
- "cramfs"
- "efs"
- # "erofs" # necessary for system.etc.overlay
- "exofs"
- "freevxfs"
- "f2fs"
- "hfs"
- "hpfs"
- "jfs"
- "minix"
- "nilfs2"
- "ntfs"
- "omfs"
- "qnx4"
- "qnx6"
- "sysv"
- "ufs"
- ];
- }
- // (lib.optionalAttrs cfg.secureBoot.enable {
- lanzaboote = {
- enable = true;
- pkiBundle = "/var/lib/sbctl";
- };
- });
-
- system.etc.overlay = {
- enable = true;
- mutable = true; # would love this to be false, but we're not there yet
- };
- system.nixos-init.enable = true;
-
- # store journald logs in memory
- services.journald.extraConfig = ''
- Storage=volatile
- RuntimeMaxUse=100M
- '';
-
- environment.systemPackages = [pkgs.efibootmgr] ++ lib.optional cfg.secureBoot.enable pkgs.sbctl;
-}