home: zfs: import some disks when plugged-in
[julm/julm-nix.git] / hosts / aubergine.nix
index 8a36dbbac0065aedd406889f8960bedb125cb48c..1d0a526de07db7686eaa1dcd29339415c4d57ba1 100644 (file)
@@ -6,16 +6,18 @@
     ../nixos/profiles/lang-fr.nix
     #../nixos/profiles/tor.nix
     ../nixos/profiles/networking/remote.nix
+    ../nixos/profiles/home.nix
     aubergine/hardware.nix
     aubergine/nebula.nix
     aubergine/networking.nix
+    aubergine/printing.nix
     aubergine/nginx.nix
     aubergine/backup.nix
     aubergine/sftp.nix
   ];
 
   # Lower kernel's security for better performances
-  boot.kernelParams = [ "mitigations=off" ];
+  security.kernel.mitigations = "off";
 
   home-manager.users.julm = {
     imports = [ ../homes/julm.nix ];
       hashedPassword = lib.readFile aubergine/users/julm/login/hashedPassword.clear;
       extraGroups = [
         "adbusers"
+        "audio"
         "dialout"
         "networkmanager"
         "tor"
+        "video"
         "wheel"
+        "wireshark"
       ];
       createHome = true;
       openssh.authorizedKeys.keys = map lib.readFile [
         ../users/root/ssh/losurdo.pub
         ../users/julm/ssh/losurdo.pub
         ../users/julm/ssh/oignon.pub
+        ../users/julm/ssh/pumpkin.pub
         ../users/julm/ssh/redmi.pub
       ];
     };
@@ -74,7 +80,8 @@
         #"ssh://nix-ssh@oignon.wg?priority=30"
       ];
       trusted-public-keys = map lib.readFile [
-        ../users/root/nix/oignon.pub
+        #../users/root/nix/oignon.pub
+        #../users/root/nix/pumpkin.pub
       ];
     };
     nixPath = lib.mkForce [ "nixpkgs=${inputs.nixpkgs}" ];
@@ -89,6 +96,7 @@
       ../users/julm/ssh/losurdo.pub
       ../users/sevy/ssh/patate.pub
       ../users/julm/ssh/oignon.pub
+      ../users/julm/ssh/pumpkin.pub
     ];
   };