From c9a1d2da80bca0a85e8c18f6d2db71c4d1127eda Mon Sep 17 00:00:00 2001 From: Collin Williams <96917990+bluedragon1221@users.noreply.github.com> Date: Thu, 29 Jan 2026 20:15:19 -0600 Subject: Spring Cleaning - create new module, `system`, that consumes the `boot` module and takes in the more system-interested services from the `services` module - touch up left over services (which are more self-hosting interested) - touch up yo and yoshi configs --- modules/boot/nixos/default.nix | 81 ------------------------------------------ 1 file changed, 81 deletions(-) delete mode 100644 modules/boot/nixos/default.nix (limited to 'modules/boot/nixos/default.nix') diff --git a/modules/boot/nixos/default.nix b/modules/boot/nixos/default.nix deleted file mode 100644 index 49cca5e..0000000 --- a/modules/boot/nixos/default.nix +++ /dev/null @@ -1,81 +0,0 @@ -{ - pkgs, - config, - lib, - ... -}: let - cfg = config.collinux.boot; -in { - imports = [ - ./plymouth.nix - ]; - - boot = - { - bcache.enable = false; # why is this default on? I DON'T CARE ABOUT bcache - initrd = { - verbose = false; - systemd.enable = true; - checkJournalingFS = false; - }; - loader = { - systemd-boot = lib.optionalAttrs (cfg.systemd-boot.enable && !cfg.secureBoot.enable) { - enable = true; - configurationLimit = 3; - }; - efi.canTouchEfiVariables = true; - timeout = cfg.timeout; # hold space to show boot menu - }; - - # from hardened.nix - blacklistedKernelModules = [ - # Obscure network protocols - "ax25" - "netrom" - "rose" - - # Old or rare or insufficiently audited filesystems - "adfs" - "affs" - "bfs" - "befs" - "cramfs" - "efs" - # "erofs" # necessary for system.etc.overlay - "exofs" - "freevxfs" - "f2fs" - "hfs" - "hpfs" - "jfs" - "minix" - "nilfs2" - "ntfs" - "omfs" - "qnx4" - "qnx6" - "sysv" - "ufs" - ]; - } - // (lib.optionalAttrs cfg.secureBoot.enable { - lanzaboote = { - enable = true; - pkiBundle = "/var/lib/sbctl"; - }; - }); - - system.etc.overlay = { - enable = true; - mutable = true; # would love this to be false, but we're not there yet - }; - system.nixos-init.enable = true; - - # store journald logs in memory - services.journald.extraConfig = '' - Storage=volatile - RuntimeMaxUse=100M - ''; - - environment.systemPackages = [pkgs.efibootmgr] ++ lib.optional cfg.secureBoot.enable pkgs.sbctl; -} -- cgit v1.3.1