Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Core Module

Documents shared NixOS core modules used across hosts.

Purpose

modules/nixos/core/ contains reusable host-level defaults and feature modules.

It also defines top-level baseline options under core.* that control this shared behavior for most hosts.

Options

core.activation.enable

Typeboolean
Defaultconfig.core.enable
Exampletrue

Whether to enable report diff on activation.


core.audio.enable

Typeboolean
Default!config.host.device.isHeadless
Exampletrue

Whether to enable Enable audio support.


core.auto-upgrade.enable

Typeboolean
Defaulttrue
Exampletrue

Whether to enable auto-upgrade.


core.auto-upgrade.hostName

Typestring
Defaultconfig.networking.hostName

The hostName to use for auto-upgrade


core.bluetooth.enable

Typeboolean
Default!config.host.device.isHeadless
Exampletrue

Whether to enable Enable Bluetooth support.


core.containers.enable

Typeboolean
Defaultfalse
Exampletrue

Whether to enable container support.


core.defaultGroups

Typelist of string
Default[ ]

Additional groups to add all users to by default.


core.display-manager.enable

Typeboolean
Defaultfalse
Exampletrue

Whether to enable display manager configuration.


core.enable

Typeboolean
Defaulttrue
Exampletrue

Whether to enable Enable core features.


core.gaming.enable

Typeboolean
Defaultfalse
Exampletrue

Whether to enable Enable gaming features.


core.hm-helper._1password.enableCli

Typeboolean
DefaultanyoneHasPackage pkgs._1password-cli
Exampletrue

Whether to enable Enable 1Password Cli support.


core.hm-helper._1password.enableGUI

Typeboolean
DefaultanyoneHasPackage pkgs._1password-gui
Exampletrue

Whether to enable Enable 1Password GUI support.


core.hm-helper.enable

Typeboolean
Defaultconfig ? home-manager
Exampletrue

Whether to enable Home Manager helper functions.


core.hm-helper.ff2mpv.enable

Typeboolean
DefaultanyoneHasPackage pkgs.ff2mpv-rust
Exampletrue

Whether to enable Enable ff2mpv native messaging host for Firefox..


core.hm-helper.hmUsers

Typelist of string
Default[ ]

List of Home Manager users that also exist in config.users.users.


core.hm-helper.kde-connect.enable

Typeboolean
DefaultanyoneHasOption (user: user.services.kdeconnect.enable)
Exampletrue

Whether to enable Enable KDE Connect firewall rules if any user has KDE Connect enabled..


core.hm-helper.nautilus.enable

Typeboolean
DefaultanyoneHasPackage pkgs.nautilus
Exampletrue

Whether to enable Enable Nautilus extensions and integration helpers..


core.locale.enable

Typeboolean
Defaulttrue
Exampletrue

Whether to enable locale configuration.


core.network.enable

Typeboolean
Default!config.host.device.isVirtual
Exampletrue

Whether to enable Enable network support.


core.networking.enable

Typeboolean
Defaultconfig.core.enable
Exampletrue

Whether to enable opinionated networking defaults.


core.networking.tailscale.enable

Typeboolean
Defaultfalse
Exampletrue

Whether to enable tailscale configuration.


core.openssh.enable

Typeboolean
Defaulttrue
Exampletrue

Whether to enable OpenSSH server and client opinionated configuration.


core.openssh.hostPrivateKeyPath

Typestring
Default"/var/lib/provisioning/ssh/ssh_host_ed25519_key"

Canonical path of the provisioned ed25519 host private key used by OpenSSH, SOPS age decryption, and server-to-server SSH.


core.printing.enable

Typeboolean
Defaultconfig.host.device.role != "server" && !config.host.device.isVirtual
Exampletrue

Whether to enable printing support.


core.remote.enable

Typeboolean
Defaultfalse
Exampletrue

Whether to enable remote features.


core.remote.remoteDesktop

Typesubmodule
Default{ }

This option has no description.


core.remote.remoteDesktop.enable

Typeboolean
Defaultfalse
Exampletrue

Whether to enable remote desktop.


core.remote.remoteDesktop.startCommand

Typestring
Default"gnome-session"

Command to start remote desktop session.


core.remote.streaming

Typesubmodule
Default{ }

This option has no description.


core.remote.streaming.enable

Typeboolean
Defaultfalse
Exampletrue

Whether to enable remote streaming.


core.security.enable

Typeboolean
Defaulttrue
Exampletrue

Whether to enable security features.


core.security.userLimit

Typeunsigned integer, meaning >=0
Default131072

The maximum number of open files per user.

This is used to set the limits for both PAM and systemd.


core.sops.enable

Typeboolean
Defaultconfig.core.enable
Exampletrue

Whether to enable SOPS auto configuration.


core.sops.hostSecretsFile

Typeabsolute path
Default"/nix/store/jq8636fkq2anq8f33kfqa816d0nrqw4m-source/hosts/secrets.yaml"

Where the SOPS secret file of this host is located in the flake.


core.stylix.enable

Typeboolean
Default!config.host.device.isHeadless
Exampletrue

Whether to enable Stylix configuration.


core.virtualisation.bridgeInterface

Typestring
Default"br0"

Bridge interface used for libvirt networking.


core.virtualisation.cpuCores

Typesigned integer
Default24

Total CPU core/thread count used for isolation helpers. Must be >= 4.


core.virtualisation.enable

Typeboolean
Defaultfalse
Exampletrue

Whether to enable virtualisation support.


core.virtualisation.externalInterface

Typestring
Default"eth0"

Physical interface attached to bridge.


core.virtualisation.gpu.audio

Typestring
Default"10de:1bef"

PCI address for passthrough GPU audio device.


core.virtualisation.gpu.video

Typestring
Default"10de:1b06"

PCI address for passthrough GPU video device.


core.virtualisation.isolatedGuests

Typelist of string
Default[ "win11" "win11-gaming" ]

List of guests to apply isolation helpers to.


core.virtualisation.vmUsers

Typelist of string
Default[ ]

Users that should receive kvm and libvirtd group membership for VM management.


core.wsl.enable

Typeboolean
Defaultfalse
Exampletrue

Whether to enable WSL specific configurations, optimisations, and fixes.


core.wsl.user

Typestring

The default user to use for WSL.


Architecture / Services / Scope

Baseline Behaviour

When core.enable is true, module applies shared defaults from modules/nixos/core/default.nix:

  • sets services.dbus.implementation = "broker",
  • enables PipeWire audio stack and disables PulseAudio when core.audio.enable is on,
  • enables Bluetooth stack, Blueman, and persisted Bluetooth state when core.bluetooth.enable is on,
  • enables NetworkManager and adds network to shared default groups when core.network.enable is on, and
  • on non-headless hosts, adds video and i2c groups and enables dleyna, gnome-keyring, udisks2, colord, xserver.updateDbusEnvironment, and polkit.

Audio baseline also enables security.rtkit, adds audio, pipewire, and rtkit groups, installs udev rules for rtc0 and hpet, and sets PAM limits for realtime audio workloads.

Bluetooth baseline unblocks rfkill during activation and persists /var/lib/bluetooth.

Usage Example

{ ... }: {
  core = {
    enable = true;
    audio.enable = true;
    bluetooth.enable = true;
    network.enable = true;
  };
}

References

Operational Notes / Assumptions

These modules are imported through modules/nixos/core/default.nix. Most feature pages document their own core.<name> option namespaces, while some baseline modules such as Nix apply unconditionally once imported.