nas
The nas host uses os, nix-ld, zfs, user and openssh. knixl writes one file for it. The Nix below is the golden test output, so it is exactly what knixl emits.
host "nas" { system "x86_64-linux"
os { state-version "25.11" boot-loader "systemd-boot" efi-can-touch-variables #true kernel-package "linuxPackages_6_18" timezone "Europe/London" locale "en_GB.UTF-8" mutable-users #false sysctl "net.ipv4.ip_forward"=1 "vm.swappiness"=10 kernel-module "br_netfilter" sysctl "net.bridge.bridge-nf-call-iptables"=1 tmpfiles-rule "/var/lib/bench" type="d" mode="0755" user="wes" group="users" tmpfiles-rule "/tmp/scratch" type="d" mode="1777" age="10d" session-variable "KDIR"="/var/lib/bench/kdir" experimental-feature "nix-command" experimental-feature "flakes" trusted-user "wes" nix-setting "max-jobs"=4 system-package "vim" system-package "git" }
nix-ld { library "stdenv.cc.cc.lib" library "zlib" library "zstd" library "elfutils" }
zfs "8425e349" { auto-scrub #true extra-pool "tank" arc-max-bytes 8589934592 force-import-root #false }
user "wes" { description "Wes Mason" group "wheel" ssh-key "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAExampleKeyForGoldenTest wes@nas" hashed-password "$6$rounds=100000$exampleSaltForGoldenTest$exampleHashDigestValueForTheGoldenTestOnly0123456789abcdefghij." }
openssh { port 22 port 2222 permit-root "prohibit-password" }}Generated
Section titled “Generated”# Generated by knixl 1.5.2 from hosts/nas.kdl# Do NOT edit. Regenerate from the KDL source.# Overrides: add a sibling module and use lib.mkForce / lib.mkAfter.{ config, lib, pkgs, ...}:{ nixpkgs.hostPlatform = "x86_64-linux"; networking.hostName = "nas"; system.stateVersion = "25.11"; boot.loader.systemd-boot.enable = true; boot.loader.efi.canTouchEfiVariables = true; boot.kernelPackages = pkgs.linuxPackages_6_18; boot.kernel.sysctl = { "net.bridge.bridge-nf-call-iptables" = 1; "net.ipv4.ip_forward" = 1; "vm.swappiness" = 10; }; boot.kernelModules = [ "br_netfilter" ]; systemd.tmpfiles.rules = [ "d /var/lib/bench 0755 wes users - -" "d /tmp/scratch 1777 - - 10d -" ]; time.timeZone = "Europe/London"; i18n.defaultLocale = "en_GB.UTF-8"; users.mutableUsers = false; nix.settings.experimental-features = [ "nix-command" "flakes" ]; nix.settings.trusted-users = [ "wes" ]; nix.settings.max-jobs = 4; environment.systemPackages = [ pkgs.vim pkgs.git ]; environment.sessionVariables = { KDIR = "/var/lib/bench/kdir"; }; programs.nix-ld.enable = true; programs.nix-ld.libraries = [ pkgs.stdenv.cc.cc.lib pkgs.zlib pkgs.zstd pkgs.elfutils ]; networking.hostId = "8425e349"; boot.supportedFilesystems.zfs = true; boot.zfs.extraPools = [ "tank" ]; services.zfs.autoScrub.enable = true; boot.extraModprobeConfig = "options zfs zfs_arc_max=8589934592"; boot.zfs.forceImportRoot = false; users.users."wes".isNormalUser = true; users.users."wes".extraGroups = [ "wheel" ]; users.users."wes".openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAExampleKeyForGoldenTest wes@nas" ]; users.users."wes".description = "Wes Mason"; users.users."wes".hashedPassword = "$6$rounds=100000$exampleSaltForGoldenTest$exampleHashDigestValueForTheGoldenTestOnly0123456789abcdefghij."; services.openssh.enable = true; services.openssh.settings.PasswordAuthentication = false; services.openssh.settings.KbdInteractiveAuthentication = false; services.openssh.ports = [ 22 2222 ]; services.openssh.settings.PermitRootLogin = "prohibit-password";}