{ pkgs, lib, ... }: with lib; with lib.metacfg; { imports = [ ./hardware-configuration.nix ]; services.spice-autorandr.enable = true; services.spice-vdagentd.enable = true; metacfg = { base.enable = true; gui.enable = true; nix-ld.enable = true; nix.enable = true; podman.enable = true; secureboot.enable = false; tools = { direnv.enable = true; #git.enable = true; }; user.extraGroups = [ "docker" "dialout" ]; }; environment.systemPackages = with pkgs; [ azure-cli desktop-file-utils kubectl kubectx k9s attic-client piper ]; security.tpm2.enable = false; security.tpm2.abrmd.enable = false; services.ratbagd.enable = true; services.resolved.enable = true; services.resolved.dnssec = "allow-downgrade"; services.resolved.extraConfig = '' ResolveUnicastSingleLabel=yes ''; virtualisation = { docker.enable = true; podman.dockerCompat = false; }; system.autoUpgrade = { enable = true; operation = "boot"; allowReboot = false; }; systemd.user.extraConfig = "DefaultLimitNOFILE=32768"; security.pam.loginLimits = [ { domain = "*"; item = "nofile"; type = "-"; value = "32768"; } { domain = "*"; item = "memlock"; type = "-"; value = "32768"; } ]; system.stateVersion = "23.11"; }