{ pkgs, ... }: { nix = { settings = { experimental-features = [ "nix-command" "flakes" ]; auto-optimise-store = true; }; gc = { automatic = true; dates = "weekly"; options = "--delete-older-than 30d"; }; }; boot.tmp.cleanOnBoot = true; time.timeZone = "Europe/Moscow"; i18n.defaultLocale = "ru_RU.UTF-8"; i18n.supportedLocales = [ "ru_RU.UTF-8/UTF-8" "en_US.UTF-8/UTF-8" ]; users.users.ada = { isNormalUser = true; shell = pkgs.bashInteractive; extraGroups = [ "wheel" "docker" ]; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIWNsUQmppB6cQccXX1ZaBbFIcmM6RmghsTVbG9TgoZB ada@ada-x1" ]; }; services.openssh = { enable = true; settings = { PasswordAuthentication = false; KbdInteractiveAuthentication = false; PermitRootLogin = "no"; PubkeyAuthentication = true; }; }; security.sudo.extraRules = [ { users = [ "ada" ]; commands = [ { command = "/run/current-system/sw/bin/nixos-rebuild"; options = [ "NOPASSWD" ]; } ]; } ]; environment.systemPackages = with pkgs; [ git restic resticprofile htop ]; systemd.tmpfiles.rules = [ "d /opt/services 0755 ada users - -" "Z /opt/services - ada users - -" "d /opt/data 0755 ada users - -" "d /opt/configs 0755 ada users - -" ]; }