26 lines
489 B
Nix
26 lines
489 B
Nix
{ lib, ... }:
|
|
{
|
|
time.timeZone = "America/New_York";
|
|
|
|
networking = {
|
|
hostId = "5f8a1c2e";
|
|
firewall = {
|
|
enable = true;
|
|
allowedTCPPorts = [ 80 ];
|
|
};
|
|
useNetworkd = true;
|
|
};
|
|
|
|
# Raspberry Pi 4 uses U-Boot / extlinux, not systemd-boot
|
|
boot.useSystemdBoot = lib.mkForce false;
|
|
|
|
sops = {
|
|
defaultSopsFile = ./secrets.yaml;
|
|
age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
|
|
};
|
|
|
|
services.tang.enable = true;
|
|
|
|
system.stateVersion = "25.11";
|
|
}
|