heather/common: passwordless sudo for mikl + fix deprecated options

- common/default.nix: add mikl to wheel + security.sudo.wheelNeedsPassword=false.
  Without this, root is unreachable on a fresh NixOS-yc image (no root password,
  no rescue channel) — nixos-rebuild switch is impossible. Mirrors the
  NOPASSWD:ALL that old YC boxes got via cloud-config user-data.
- home/server.nix: programs.git.extraConfig -> .settings, programs.git.delta
  -> programs.delta with enableGitIntegration=true (deprecated warnings).
- image.nix: boot.loader.grub.timeout -> boot.loader.timeout (renamed option).
This commit is contained in:
mikl 2026-07-11 22:55:00 +03:00
parent 79260cec6f
commit 411a8ba689
5 changed files with 19 additions and 5 deletions

View file

@ -36,6 +36,7 @@
trash-cli # rm с корзиной trash-cli # rm с корзиной
texliveFull # LaTeX (~4GB, для математики) texliveFull # LaTeX (~4GB, для математики)
gita # manage multiple git repos gita # manage multiple git repos
ffmpeg_7 # видео-конвертация (remux/перекодирование)
]; ];
# TODO: global npm/pnpm packages not managed by nix for now # TODO: global npm/pnpm packages not managed by nix for now

View file

@ -74,13 +74,15 @@
enable = true; enable = true;
userName = "mikl"; userName = "mikl";
userEmail = "mikl@iscg.dev"; userEmail = "mikl@iscg.dev";
extraConfig = { settings = {
init.defaultBranch = "main"; init.defaultBranch = "main";
pull.rebase = true; pull.rebase = true;
push.autoSetupRemote = true; push.autoSetupRemote = true;
diff.pager = "delta";
}; };
delta.enable = true; };
programs.delta = {
enable = true;
enableGitIntegration = true;
}; };
# --- Zsh: минимульный, без pure-prompt и fastfetch (это десктоп-флёр) --- # --- Zsh: минимульный, без pure-prompt и fastfetch (это десктоп-флёр) ---

View file

@ -13,6 +13,16 @@
isNormalUser = true; isNormalUser = true;
shell = pkgs.zsh; shell = pkgs.zsh;
home = "/home/mikl"; home = "/home/mikl";
extraGroups = [ "wheel" ]; # для passwordless sudo (см. ниже)
};
# Passwordless sudo для mikl на NixOS-серверах.
# На старых YC-боксах это приходило через cloud-config user-data
# (NOPASSWD:ALL); в NixOS задаём декларативно. Без этого админить
# сервер вслепую (kubectl, journalctl, nixos-rebuild) невозможно.
security.sudo = {
enable = true;
wheelNeedsPassword = false;
}; };
environment.systemPackages = [ environment.systemPackages = [

View file

@ -43,7 +43,7 @@ with lib;
boot.loader.grub.enable = mkDefault true; boot.loader.grub.enable = mkDefault true;
boot.loader.grub.device = "/dev/vda"; boot.loader.grub.device = "/dev/vda";
boot.loader.grub.configurationLimit = 1; # только текущее, но механизм выбора есть boot.loader.grub.configurationLimit = 1; # только текущее, но механизм выбора есть
boot.loader.grub.timeout = 0; boot.loader.timeout = 0;
boot.loader.systemd-boot.enable = mkForce false; boot.loader.systemd-boot.enable = mkForce false;
boot.loader.efi.canTouchEfiVariables = mkForce false; boot.loader.efi.canTouchEfiVariables = mkForce false;
@ -89,7 +89,7 @@ with lib;
image.baseName = "heather"; image.baseName = "heather";
image.extension = "qcow2"; image.extension = "qcow2";
system.nixos.tags = [ "yandex-cloud" ]; system.nixos.tags = [ "yandex-cloud" ];
system.build.image = import (modulesPath + "/lib/make-disk-image.nix") { system.build.image = import (modulesPath + "/../lib/make-disk-image.nix") {
name = "heather-image"; name = "heather-image";
inherit (config.image) baseName; inherit (config.image) baseName;
partitionTableType = "legacy"; # MBR + single ext4 root partitionTableType = "legacy"; # MBR + single ext4 root

View file

@ -36,6 +36,7 @@
"amneziavpn" "amneziavpn"
"element" "element"
"prismlauncher" "prismlauncher"
"losslesscut" # lossless-нарезка/remux видео (GUI на базе ffmpeg)
]; ];
}; };