The installation-CD profile enables zfs so you can install onto it, but the pinned nixpkgs ships a broken zfs-kernel that fails to evaluate, breaking `nix flake check` and ISO builds. Force-disable zfs in the ISO (a desktop installer doesn't need ZFS-root); use the official NixOS ISO for ZFS installs. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
570 lines
17 KiB
Nix
570 lines
17 KiB
Nix
# Omnixient NixOS Live ISO Configuration
|
||
# This creates a bootable ISO image with Omnixient pre-installed
|
||
|
||
{
|
||
config,
|
||
pkgs,
|
||
lib,
|
||
modulesPath,
|
||
settings,
|
||
...
|
||
}:
|
||
|
||
{
|
||
imports = [
|
||
# Include the basic ISO image module (without Calamares to avoid conflicts)
|
||
"${modulesPath}/installer/cd-dvd/installation-cd-minimal.nix"
|
||
|
||
# Omnixient modules (lib must be first to provide helpers)
|
||
./modules/lib.nix
|
||
./modules/core.nix
|
||
./modules/colors.nix
|
||
./modules/security.nix
|
||
./modules/fastfetch.nix
|
||
./modules/walker.nix
|
||
./modules/scripts.nix
|
||
./modules/menus.nix
|
||
./modules/desktop/hyprland.nix
|
||
./modules/packages.nix
|
||
# development.nix moved to the development pack (omni.packs.development),
|
||
# which the ISO doesn't load — it ran the minimal preset (coding off), so
|
||
# the module was inactive here anyway.
|
||
./modules/themes/tokyo-night.nix # Default theme for ISO
|
||
./modules/users.nix
|
||
./modules/services.nix
|
||
./modules/hardware
|
||
|
||
# Pre-create the home-manager activation script's expected
|
||
# directory tree on first boot. Without this the live ISO
|
||
# would crash `home-manager-user.service` exactly the way the
|
||
# main host did before commit efafd8c — this module is also
|
||
# imported by lib/mksystem.nix so the bootstrap stays
|
||
# consistent across both code paths.
|
||
./modules/home-manager-bootstrap.nix
|
||
];
|
||
|
||
# ISO-specific configuration
|
||
isoImage = {
|
||
# ISO image settings
|
||
volumeID = "OMNI_${lib.toUpper config.system.nixos.label}";
|
||
|
||
# Boot configuration
|
||
makeEfiBootable = true;
|
||
makeUsbBootable = true;
|
||
|
||
# Include additional files
|
||
includeSystemBuildDependencies = false;
|
||
|
||
# Squeeze a few % extra out of squashfs (zstd 22 vs default
|
||
# 19). Slower to compress but saves ~80-120 MB on a ~4 GB
|
||
# image. Decompression speed at boot is identical.
|
||
squashfsCompression = "zstd -Xcompression-level 22";
|
||
|
||
# Boot splash (optional)
|
||
splashImage = if builtins.pathExists ./assets/logo.png then ./assets/logo.png else null;
|
||
|
||
# Desktop entry for installer
|
||
contents = [
|
||
{
|
||
source = pkgs.writeText "omni-install.desktop" ''
|
||
[Desktop Entry]
|
||
Name=Install Omnixient
|
||
Comment=Install Omnixient NixOS to your computer
|
||
Exec=gnome-terminal -- sudo omni-installer
|
||
Icon=system-software-install
|
||
Terminal=false
|
||
Type=Application
|
||
Categories=System;
|
||
StartupNotify=true
|
||
'';
|
||
target = "etc/xdg/autostart/omni-install.desktop";
|
||
}
|
||
];
|
||
};
|
||
|
||
# System configuration for live ISO
|
||
system.stateVersion = settings.stateVersion;
|
||
|
||
# Allow unfree packages
|
||
nixpkgs.config.allowUnfree = true;
|
||
|
||
# ISO size diet — overrides for the main host config so we don't
|
||
# blow past the "fits on a 4 GB USB" target. The main host
|
||
# configurations keep their full font and doc sets; these mkForce
|
||
# blocks only apply to the ISO build.
|
||
|
||
# Drop the 10-font Nerd Font set from modules/packages.nix down
|
||
# to one (jetbrains-mono — referenced by waybar/alacritty). Drop
|
||
# CJK fonts (~500 MB of Chinese/Japanese/Korean glyphs nobody on
|
||
# a US-locale live ISO needs). Keep the basics: noto for general
|
||
# text, emoji for unicode, jetbrains-mono in both regular and
|
||
# nerd flavours for terminal/editor, font-awesome for waybar
|
||
# icons.
|
||
fonts.packages = lib.mkForce (
|
||
with pkgs;
|
||
[
|
||
nerd-fonts.jetbrains-mono # waybar icons + terminal
|
||
jetbrains-mono # editor / IDE
|
||
noto-fonts-color-emoji # unicode emoji
|
||
font-awesome # waybar fontawesome glyphs
|
||
# noto-fonts and liberation_ttf dropped to fit the 3.6 GiB
|
||
# USB. Body text falls back to jetbrains-mono which is fine
|
||
# for an installer session.
|
||
]
|
||
);
|
||
|
||
# Drop documentation outputs (~700 MB + change). cachix-doc
|
||
# pulls in 696 MB of Haskell ghc-doc on its own; doc.enable is
|
||
# the upstream switch that opts every package into shipping its
|
||
# HTML/info manuals into the live system path.
|
||
documentation = {
|
||
doc.enable = lib.mkForce false;
|
||
info.enable = lib.mkForce false;
|
||
nixos.enable = lib.mkForce false;
|
||
# man pages stay enabled — they are tiny and useful in the
|
||
# live session for `man nixos-install` etc.
|
||
};
|
||
|
||
# ISO image filename
|
||
image.fileName = "omni-${config.system.nixos.label}-${pkgs.stdenv.hostPlatform.system}.iso";
|
||
|
||
# Enable flakes
|
||
nix = {
|
||
settings = {
|
||
experimental-features = [
|
||
"nix-command"
|
||
"flakes"
|
||
];
|
||
auto-optimise-store = true;
|
||
|
||
# Binary caches
|
||
substituters = [
|
||
"https://cache.nixos.org"
|
||
"https://nix-community.cachix.org"
|
||
"https://hyprland.cachix.org"
|
||
];
|
||
trusted-public-keys = [
|
||
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
|
||
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
|
||
"hyprland.cachix.org-1:a7pgxzMz7+chwVL3/pzj6jIBMioiJM7ypFP8PwtkuGc="
|
||
];
|
||
};
|
||
};
|
||
|
||
# Networking
|
||
networking = {
|
||
hostName = "omni-live";
|
||
networkmanager.enable = true;
|
||
networkmanager.wifi.backend = "iwd";
|
||
wireless.iwd.enable = true;
|
||
|
||
# Enable firewall but allow common services for live session
|
||
firewall = {
|
||
enable = true;
|
||
allowedTCPPorts = [
|
||
22
|
||
80
|
||
443
|
||
3000
|
||
8080
|
||
];
|
||
};
|
||
};
|
||
|
||
# Pre-configured WiFi for live session auto-connect.
|
||
networking.networkmanager.ensureProfiles.profiles.live-wifi = {
|
||
connection = {
|
||
id = "Cathare";
|
||
type = "wifi";
|
||
autoconnect = "true";
|
||
autoconnect-priority = "100";
|
||
};
|
||
wifi = {
|
||
ssid = "Cathare";
|
||
mode = "infrastructure";
|
||
};
|
||
wifi-security = {
|
||
key-mgmt = "wpa-psk";
|
||
psk = "DruidLife";
|
||
};
|
||
ipv4.method = "auto";
|
||
ipv6.method = "auto";
|
||
};
|
||
|
||
# Timezone and locale
|
||
time.timeZone = "UTC"; # Will be configured during installation
|
||
i18n = {
|
||
defaultLocale = "en_US.UTF-8";
|
||
extraLocaleSettings = {
|
||
LC_ADDRESS = "en_US.UTF-8";
|
||
LC_IDENTIFICATION = "en_US.UTF-8";
|
||
LC_MEASUREMENT = "en_US.UTF-8";
|
||
LC_MONETARY = "en_US.UTF-8";
|
||
LC_NAME = "en_US.UTF-8";
|
||
LC_NUMERIC = "en_US.UTF-8";
|
||
LC_PAPER = "en_US.UTF-8";
|
||
LC_TELEPHONE = "en_US.UTF-8";
|
||
LC_TIME = "en_US.UTF-8";
|
||
};
|
||
};
|
||
|
||
# Sound configuration
|
||
services.pulseaudio.enable = false;
|
||
security.rtkit.enable = true;
|
||
services.pipewire = {
|
||
enable = true;
|
||
alsa.enable = true;
|
||
alsa.support32Bit = true;
|
||
pulse.enable = true;
|
||
jack.enable = true;
|
||
};
|
||
|
||
# Override display manager configuration for ISO
|
||
services = {
|
||
# Disable greetd from main config
|
||
greetd.enable = lib.mkForce false;
|
||
|
||
# Enable auto-login for live session
|
||
getty.autologinUser = "nixos";
|
||
|
||
# Keep X11 disabled - pure Wayland
|
||
xserver.enable = lib.mkForce false;
|
||
};
|
||
|
||
# Live user configuration is handled by modules/users.nix
|
||
# The nixos user will be created automatically since omni.user = "nixos"
|
||
# Remove any conflicting password settings
|
||
users.users.nixos = {
|
||
initialPassword = lib.mkForce ""; # Empty password for live session
|
||
password = lib.mkForce null;
|
||
hashedPassword = lib.mkForce null;
|
||
hashedPasswordFile = lib.mkForce null;
|
||
initialHashedPassword = lib.mkForce null;
|
||
};
|
||
|
||
# Disable firefox from home.nix for the live ISO — its closure
|
||
# adds 321 MB. Users can `nix-shell -p firefox` if they need a
|
||
# browser during the live session.
|
||
home-manager.users.nixos.programs.firefox.enable = lib.mkForce false;
|
||
|
||
# Replace papirus-icon-theme (444 MB) with the already-present
|
||
# adwaita-icon-theme (~50 MB) to fit the 3.6 GiB USB target.
|
||
# Papirus is purely cosmetic; adwaita provides full icon
|
||
# coverage for GTK apps, thunar, etc. The installed system can
|
||
# switch back to papirus via `omni.theme` after install.
|
||
nixpkgs.overlays = [
|
||
(_self: super: {
|
||
# Swap papirus (444 MB) for adwaita (already present, ~50 MB)
|
||
papirus-icon-theme = super.adwaita-icon-theme;
|
||
# Stub out packages that have no use on a live installer
|
||
# session — saves ~175 MB of closure to fit the 3.6 GiB USB.
|
||
rclone = super.hello; # cloud sync (88 MB)
|
||
mesa-demos = super.hello; # glxgears/glxinfo (62 MB)
|
||
cachix = super.hello; # binary cache tool (25 MB)
|
||
# Intel OpenCL compute runtime (292 MB via IGC). Display
|
||
# works fine without it via mesa/i915; only GPU compute
|
||
# (which nobody uses on a live installer) needs it.
|
||
intel-compute-runtime = super.hello;
|
||
})
|
||
];
|
||
|
||
# Auto-start Hyprland on tty1 for the live session user.
|
||
# Uses programs.bash.interactiveShellInit instead of profile.d because
|
||
# getty autologin spawns a non-login shell, so /etc/profile.d/ is
|
||
# never sourced.
|
||
programs.bash.interactiveShellInit = ''
|
||
if [[ "$(tty)" == "/dev/tty1" && "$USER" == "nixos" && -z "$WAYLAND_DISPLAY" ]]; then
|
||
export XDG_SESSION_TYPE=wayland
|
||
export XDG_SESSION_DESKTOP=Hyprland
|
||
export XDG_CURRENT_DESKTOP=Hyprland
|
||
exec ${pkgs.hyprland}/bin/Hyprland
|
||
fi
|
||
'';
|
||
|
||
# Sudo configuration for live user
|
||
security.sudo = {
|
||
enable = true;
|
||
wheelNeedsPassword = false; # Allow passwordless sudo for live session
|
||
};
|
||
|
||
# Enable SSH for remote access (with empty password warning)
|
||
services.openssh = {
|
||
enable = true;
|
||
settings = {
|
||
PermitRootLogin = "no";
|
||
PasswordAuthentication = lib.mkForce true; # Override core.nix setting for ISO
|
||
PermitEmptyPasswords = lib.mkForce true; # For live session only
|
||
};
|
||
};
|
||
|
||
# Omnixient configuration for ISO
|
||
omni = {
|
||
enable = true;
|
||
user = "nixos"; # Live session user
|
||
theme = "tokyo-night";
|
||
desktop.enable = true;
|
||
displayManager = "gdm"; # Override default for live session
|
||
|
||
# `minimal` preset for the live ISO. The `everything` preset
|
||
# pulls in vscode, libreoffice, slack, discord, steam, docker,
|
||
# virt-manager, etc. — together adding 6-8 GB to the ISO and
|
||
# blowing past the "fits on a 4 GB USB" target. The live
|
||
# session is a tour-of-omni + installer, not a full dev box;
|
||
# users get the full feature set after they install.
|
||
preset = "minimal";
|
||
|
||
# Security configuration (relaxed for live session)
|
||
security = {
|
||
enable = true;
|
||
fingerprint.enable = false;
|
||
fido2.enable = false;
|
||
systemHardening = {
|
||
enable = false; # Disable hardening for live session compatibility
|
||
faillock.enable = false;
|
||
};
|
||
};
|
||
|
||
# Package configuration
|
||
packages = {
|
||
# Don't exclude anything for the live session showcase
|
||
exclude = [ ];
|
||
};
|
||
};
|
||
|
||
# Additional ISO packages — kept lean to fit on a 4 GB USB.
|
||
# Drops:
|
||
# - gnome-disk-utility, nautilus, gnome-terminal: omni already
|
||
# ships kitty/alacritty + thunar via the desktop module, so
|
||
# these GNOME duplicates are dead weight (~500 MB).
|
||
# - vim: nvim (via lazyvim-nix) is the editor; nano is kept as
|
||
# a tiny fallback for users uncomfortable with modal editors.
|
||
# - neofetch: omni already includes fastfetch via its module.
|
||
environment.systemPackages = with pkgs; [
|
||
# Installation tools
|
||
gparted
|
||
|
||
# Text editors for configuration
|
||
nano
|
||
|
||
# Network tools
|
||
wget
|
||
curl
|
||
|
||
# System information
|
||
lshw
|
||
|
||
# NOTE: firefox was dropped to meet the 4 GB USB target.
|
||
# Its closure adds ~321 MB which pushes the compressed ISO
|
||
# past 3.6 GB. Users can `nix-shell -p firefox` in the live
|
||
# session if they need a browser for docs during install.
|
||
|
||
# Omnixient installer script
|
||
(pkgs.writeShellScriptBin "omni-installer" ''
|
||
#!/usr/bin/env bash
|
||
set -e
|
||
|
||
echo "🚀 Omnixient NixOS Installer"
|
||
echo "========================="
|
||
echo ""
|
||
echo "This will guide you through installing Omnixient NixOS to your computer."
|
||
echo ""
|
||
echo "⚠️ WARNING: This will modify your disk partitions!"
|
||
echo ""
|
||
|
||
read -p "Do you want to continue? (y/N): " -n 1 -r
|
||
echo
|
||
|
||
if [[ ! $REPLY =~ ^[Yy]$ ]]; then
|
||
echo "Installation cancelled."
|
||
exit 1
|
||
fi
|
||
|
||
# Launch the graphical installer
|
||
echo "🖥️ Launching graphical installer..."
|
||
echo " Follow the on-screen instructions to install Omnixient."
|
||
echo ""
|
||
|
||
# Use Calamares if available, otherwise provide manual instructions
|
||
if command -v calamares &> /dev/null; then
|
||
sudo calamares
|
||
else
|
||
echo "📝 Manual Installation Instructions:"
|
||
echo ""
|
||
echo "1. Partition your disk with gparted or fdisk"
|
||
echo "2. Mount your root partition to /mnt"
|
||
echo "3. Generate hardware configuration:"
|
||
echo " sudo nixos-generate-config --root /mnt"
|
||
echo ""
|
||
echo "4. Download Omnixient configuration:"
|
||
echo " cd /mnt/etc/nixos"
|
||
echo " sudo git clone https://git.atitlan.io/aiolabs/omnixient.git ."
|
||
echo ""
|
||
echo "5. Edit configuration.nix to set your username and theme"
|
||
echo ""
|
||
echo "6. Install NixOS:"
|
||
echo " sudo nixos-install --flake /mnt/etc/nixos#omni"
|
||
echo ""
|
||
echo "7. Reboot and enjoy Omnixient!"
|
||
|
||
read -p "Press Enter to open gparted for disk partitioning..."
|
||
sudo gparted
|
||
fi
|
||
'')
|
||
|
||
# Demo scripts
|
||
(pkgs.writeShellScriptBin "omni-demo" ''
|
||
#!/usr/bin/env bash
|
||
echo "🎨 Omnixient Live Demo"
|
||
echo "=================="
|
||
echo ""
|
||
echo "Welcome to Omnixient NixOS Live Session!"
|
||
echo ""
|
||
echo "Available commands:"
|
||
echo " omni-installer - Install Omnixient to your computer"
|
||
echo " omni-info - Show system information"
|
||
echo " omni-theme - Change theme (temporary for live session)"
|
||
echo " omni-demo - Show this demo"
|
||
echo ""
|
||
echo "Key features to try:"
|
||
echo " • Hyprland window manager with modern animations"
|
||
echo " • Multiple themes (tokyo-night, catppuccin, gruvbox, etc.)"
|
||
echo " • Development tools and environments"
|
||
echo " • Multimedia and productivity applications"
|
||
echo ""
|
||
echo "To install Omnixient permanently, run: omni-installer"
|
||
echo ""
|
||
'')
|
||
];
|
||
|
||
# Services for live session
|
||
services = {
|
||
# Enable printing support
|
||
printing.enable = true;
|
||
|
||
# Enable Bluetooth
|
||
blueman.enable = true;
|
||
|
||
# Enable location services
|
||
geoclue2.enable = true;
|
||
|
||
# Enable automatic time synchronization
|
||
timesyncd.enable = true;
|
||
};
|
||
|
||
# Hardware support — `enableRedistributableFirmware` instead of
|
||
# `enableAllFirmware` to keep the ISO under 4 GB. The "all"
|
||
# variant pulls in non-redistributable blobs that add ~2-3 GB
|
||
# for relatively niche wifi/bluetooth chips. Most modern hardware
|
||
# works with the redistributable set; users on edge-case wifi
|
||
# can opt in via `hardware.enableAllFirmware = true` after
|
||
# install.
|
||
hardware = {
|
||
enableRedistributableFirmware = true;
|
||
|
||
# Graphics drivers
|
||
graphics = {
|
||
enable = true;
|
||
enable32Bit = true;
|
||
};
|
||
|
||
# Bluetooth
|
||
bluetooth = {
|
||
enable = true;
|
||
powerOnBoot = true;
|
||
};
|
||
};
|
||
|
||
# Boot configuration for ISO
|
||
boot = {
|
||
# Explicit filesystem support. zfs is force-disabled: the upstream
|
||
# installation-CD profile enables it (to allow installing onto ZFS),
|
||
# but the pinned nixpkgs ships a broken zfs-kernel that fails to
|
||
# evaluate. An Omnixient desktop installer doesn't need ZFS-root support,
|
||
# so we drop it rather than ship a broken/stale module. (Use the
|
||
# official NixOS ISO if you need to install onto ZFS.)
|
||
supportedFilesystems = {
|
||
btrfs = true;
|
||
ext4 = true;
|
||
xfs = true;
|
||
ntfs = true;
|
||
exfat = true;
|
||
zfs = lib.mkForce false;
|
||
};
|
||
|
||
# Include lots of modules for hardware compatibility
|
||
initrd.availableKernelModules = [
|
||
# Storage
|
||
"ahci"
|
||
"xhci_pci"
|
||
"nvme"
|
||
"usb_storage"
|
||
"sd_mod"
|
||
"rtsx_pci_sdmmc"
|
||
# Graphics
|
||
"amdgpu"
|
||
"radeon"
|
||
"nouveau"
|
||
"i915"
|
||
# Network
|
||
"r8169"
|
||
"e1000e"
|
||
"iwlwifi"
|
||
"ath9k"
|
||
"ath10k_pci"
|
||
"rtw88_8822ce"
|
||
];
|
||
|
||
# Kernel parameters for better hardware compatibility
|
||
kernelParams = [
|
||
"boot.shell_on_fail"
|
||
"i915.modeset=1"
|
||
"nouveau.modeset=1"
|
||
"radeon.modeset=1"
|
||
"amdgpu.modeset=1"
|
||
];
|
||
|
||
# Latest kernel for better hardware support (MT7925
|
||
# bluetooth, newer AMD GPUs, etc.).
|
||
kernelPackages = pkgs.linuxPackages_latest;
|
||
|
||
# Plymouth disabled for ISO to avoid potential issues
|
||
plymouth.enable = false;
|
||
};
|
||
|
||
# Auto-login is configured above in services.displayManager
|
||
|
||
# Automatically start Omnixient demo on login
|
||
environment.loginShellInit = ''
|
||
# Show demo information on first login
|
||
if [ -f /home/nixos/.first-login ]; then
|
||
omni-demo
|
||
rm /home/nixos/.first-login
|
||
fi
|
||
'';
|
||
|
||
# Create first-login marker
|
||
system.activationScripts.createFirstLoginMarker = ''
|
||
touch /home/nixos/.first-login
|
||
chown nixos:users /home/nixos/.first-login
|
||
'';
|
||
|
||
# Disable some services that might cause issues in live session
|
||
systemd.services = {
|
||
# Disable networkd-wait-online to speed up boot
|
||
systemd-networkd-wait-online.enable = false;
|
||
|
||
# Disable some hardware services that might not be needed
|
||
fwupd.enable = false;
|
||
};
|
||
|
||
# Memory and performance optimizations for live session
|
||
boot.kernel.sysctl = {
|
||
# Use more aggressive memory reclaim
|
||
"vm.swappiness" = 10;
|
||
"vm.vfs_cache_pressure" = 50;
|
||
|
||
# Network optimizations
|
||
"net.core.default_qdisc" = "fq";
|
||
"net.ipv4.tcp_congestion_control" = "bbr";
|
||
};
|
||
}
|