nixOS/configuration.nix
Sergei Poljanski 554487a136
hostel-wifi: hardened profile for untrusted networks (disabled by default)
Add modules/hostel-wifi.nix: per-SSID MAC randomization (iwd), disable
mDNS/LLMNR/NetBIOS, reject hostile IPv6 RAs, firewall LAN-side probing,
an nftables killswitch target allowing only tunnel egress + captive-portal
endpoints, NTS-secured time via chrony, and a captive-portal helper.
Import left commented out; toggle via 'untrusted on|off'.
2026-06-02 14:07:38 +03:00

33 lines
1.1 KiB
Nix

# NixOS Configuration
# Main entry point - imports modular configuration files
{ config, pkgs, lib, ... }:
{
imports = [
./hardware-configuration.nix
./modules/boot.nix
./modules/networking.nix
./modules/locale.nix
./modules/desktop.nix
./modules/users.nix
./modules/packages.nix
./modules/shell.nix
./modules/programs.nix
./modules/wireguard.nix
./modules/security.nix
./modules/power.nix
./modules/xray.nix
./modules/ollama.nix
./modules/gaming.nix
# ./modules/hostel-wifi.nix # disabled 2026-05-08 — re-enable when needed
];
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions
# on your system were taken. It's perfectly fine and recommended to leave
# this value at the release version of the first install of this system.
# Before changing this value read the documentation for this option
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
system.stateVersion = "25.11";
}