Skip to content

nas

The nas host uses os, nix-ld, zfs, user and openssh. knixl writes one file for it. The Nix below is the golden test output, so it is exactly what knixl emits.

hosts/nas.kdl
host "nas" {
system "x86_64-linux"
os {
state-version "25.11"
boot-loader "systemd-boot"
efi-can-touch-variables #true
kernel-package "linuxPackages_6_18"
timezone "Europe/London"
locale "en_GB.UTF-8"
mutable-users #false
sysctl "net.ipv4.ip_forward"=1 "vm.swappiness"=10
kernel-module "br_netfilter"
sysctl "net.bridge.bridge-nf-call-iptables"=1
tmpfiles-rule "/var/lib/bench" type="d" mode="0755" user="wes" group="users"
tmpfiles-rule "/tmp/scratch" type="d" mode="1777" age="10d"
session-variable "KDIR"="/var/lib/bench/kdir"
experimental-feature "nix-command"
experimental-feature "flakes"
trusted-user "wes"
nix-setting "max-jobs"=4
system-package "vim"
system-package "git"
}
nix-ld {
library "stdenv.cc.cc.lib"
library "zlib"
library "zstd"
library "elfutils"
}
zfs "8425e349" {
auto-scrub #true
extra-pool "tank"
arc-max-bytes 8589934592
force-import-root #false
}
user "wes" {
description "Wes Mason"
group "wheel"
ssh-key "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAExampleKeyForGoldenTest wes@nas"
hashed-password "$6$rounds=100000$exampleSaltForGoldenTest$exampleHashDigestValueForTheGoldenTestOnly0123456789abcdefghij."
}
openssh {
port 22
port 2222
permit-root "prohibit-password"
}
}
generated/hosts/nas.nix
# Generated by knixl 1.5.2 from hosts/nas.kdl
# Do NOT edit. Regenerate from the KDL source.
# Overrides: add a sibling module and use lib.mkForce / lib.mkAfter.
{
config,
lib,
pkgs,
...
}:
{
nixpkgs.hostPlatform = "x86_64-linux";
networking.hostName = "nas";
system.stateVersion = "25.11";
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = true;
boot.kernelPackages = pkgs.linuxPackages_6_18;
boot.kernel.sysctl = {
"net.bridge.bridge-nf-call-iptables" = 1;
"net.ipv4.ip_forward" = 1;
"vm.swappiness" = 10;
};
boot.kernelModules = [
"br_netfilter"
];
systemd.tmpfiles.rules = [
"d /var/lib/bench 0755 wes users - -"
"d /tmp/scratch 1777 - - 10d -"
];
time.timeZone = "Europe/London";
i18n.defaultLocale = "en_GB.UTF-8";
users.mutableUsers = false;
nix.settings.experimental-features = [
"nix-command"
"flakes"
];
nix.settings.trusted-users = [
"wes"
];
nix.settings.max-jobs = 4;
environment.systemPackages = [
pkgs.vim
pkgs.git
];
environment.sessionVariables = {
KDIR = "/var/lib/bench/kdir";
};
programs.nix-ld.enable = true;
programs.nix-ld.libraries = [
pkgs.stdenv.cc.cc.lib
pkgs.zlib
pkgs.zstd
pkgs.elfutils
];
networking.hostId = "8425e349";
boot.supportedFilesystems.zfs = true;
boot.zfs.extraPools = [
"tank"
];
services.zfs.autoScrub.enable = true;
boot.extraModprobeConfig = "options zfs zfs_arc_max=8589934592";
boot.zfs.forceImportRoot = false;
users.users."wes".isNormalUser = true;
users.users."wes".extraGroups = [
"wheel"
];
users.users."wes".openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAExampleKeyForGoldenTest wes@nas"
];
users.users."wes".description = "Wes Mason";
users.users."wes".hashedPassword =
"$6$rounds=100000$exampleSaltForGoldenTest$exampleHashDigestValueForTheGoldenTestOnly0123456789abcdefghij.";
services.openssh.enable = true;
services.openssh.settings.PasswordAuthentication = false;
services.openssh.settings.KbdInteractiveAuthentication = false;
services.openssh.ports = [
22
2222
];
services.openssh.settings.PermitRootLogin = "prohibit-password";
}