{pkgs, ...}: { imports = [ ./disko-config.nix ./hardware-configuration.nix ]; # Bootloader. boot.loader.grub = { efiSupport = true; efiInstallAsRemovable = true; }; networking.hostName = "m3-hermes"; networking.hostId = "a1b2c3d4"; # TODO: Generate unique hostId networking.networkmanager.enable = true; # Matrix homeserver pin: DNS on this host resolves exclusively via the # Netbird-managed resolver (see /etc/resolv.conf → wt0). When the Netbird # nameserver group is unreachable, matrix.m3ta.dev fails to resolve and the # gateway cannot log in (observed 2026-08-16). Pinning the public IP of # m3-atlas (TLS termination for matrix.m3ta.dev) makes the Matrix connection # independent of Netbird DNS health. Update here if the m3-atlas public IP # ever changes. networking.hosts = { "152.53.85.162" = ["matrix.m3ta.dev"]; }; time.timeZone = "Europe/Berlin"; i18n.defaultLocale = "en_US.UTF-8"; environment.systemPackages = with pkgs; [ neovim git tea ghostty.terminfo uv ]; services.openssh = { enable = true; settings = { PermitRootLogin = "no"; PasswordAuthentication = false; }; }; security.sudo.extraRules = [ { users = ["hermes"]; commands = [ { command = "/run/current-system/sw/bin/podman"; options = ["NOPASSWD"]; } ]; } ]; services.fstrim = { enable = true; interval = "weekly"; }; # Firewall: outbound only, SSH inbound networking.firewall = { enable = true; allowedTCPPorts = [22]; # SSH only allowedUDPPorts = []; allowPing = false; }; system.stateVersion = "25.05"; }