Core Module
Documents shared NixOS core modules used across hosts.
Purpose
modules/nixos/core/ contains reusable host-level defaults and feature modules.
It also defines top-level baseline options under core.* that control this shared behavior for most hosts.
Options
core.activation.enable
| Type | boolean |
| Default | config.core.enable |
| Example | true |
Whether to enable report diff on activation.
core.audio.enable
| Type | boolean |
| Default | !config.host.device.isHeadless |
| Example | true |
Whether to enable Enable audio support.
core.auto-upgrade.enable
| Type | boolean |
| Default | true |
| Example | true |
Whether to enable auto-upgrade.
core.auto-upgrade.hostName
| Type | string |
| Default | config.networking.hostName |
The hostName to use for auto-upgrade
core.bluetooth.enable
| Type | boolean |
| Default | !config.host.device.isHeadless |
| Example | true |
Whether to enable Enable Bluetooth support.
core.containers.enable
| Type | boolean |
| Default | false |
| Example | true |
Whether to enable container support.
core.defaultGroups
| Type | list of string |
| Default | [ ] |
Additional groups to add all users to by default.
core.display-manager.enable
| Type | boolean |
| Default | false |
| Example | true |
Whether to enable display manager configuration.
core.enable
| Type | boolean |
| Default | true |
| Example | true |
Whether to enable Enable core features.
core.gaming.enable
| Type | boolean |
| Default | false |
| Example | true |
Whether to enable Enable gaming features.
core.hm-helper._1password.enableCli
| Type | boolean |
| Default | anyoneHasPackage pkgs._1password-cli |
| Example | true |
Whether to enable Enable 1Password Cli support.
core.hm-helper._1password.enableGUI
| Type | boolean |
| Default | anyoneHasPackage pkgs._1password-gui |
| Example | true |
Whether to enable Enable 1Password GUI support.
core.hm-helper.enable
| Type | boolean |
| Default | config ? home-manager |
| Example | true |
Whether to enable Home Manager helper functions.
core.hm-helper.ff2mpv.enable
| Type | boolean |
| Default | anyoneHasPackage pkgs.ff2mpv-rust |
| Example | true |
Whether to enable Enable ff2mpv native messaging host for Firefox..
core.hm-helper.hmUsers
| Type | list of string |
| Default | [ ] |
List of Home Manager users that also exist in config.users.users.
core.hm-helper.kde-connect.enable
| Type | boolean |
| Default | anyoneHasOption (user: user.services.kdeconnect.enable) |
| Example | true |
Whether to enable Enable KDE Connect firewall rules if any user has KDE Connect enabled..
core.hm-helper.nautilus.enable
| Type | boolean |
| Default | anyoneHasPackage pkgs.nautilus |
| Example | true |
Whether to enable Enable Nautilus extensions and integration helpers..
core.locale.enable
| Type | boolean |
| Default | true |
| Example | true |
Whether to enable locale configuration.
core.network.enable
| Type | boolean |
| Default | !config.host.device.isVirtual |
| Example | true |
Whether to enable Enable network support.
core.networking.enable
| Type | boolean |
| Default | config.core.enable |
| Example | true |
Whether to enable opinionated networking defaults.
core.networking.tailscale.enable
| Type | boolean |
| Default | false |
| Example | true |
Whether to enable tailscale configuration.
core.openssh.enable
| Type | boolean |
| Default | true |
| Example | true |
Whether to enable OpenSSH server and client opinionated configuration.
core.openssh.hostPrivateKeyPath
| Type | string |
| Default | "/var/lib/provisioning/ssh/ssh_host_ed25519_key" |
Canonical path of the provisioned ed25519 host private key used by OpenSSH, SOPS age decryption, and server-to-server SSH.
core.printing.enable
| Type | boolean |
| Default | config.host.device.role != "server" && !config.host.device.isVirtual |
| Example | true |
Whether to enable printing support.
core.remote.enable
| Type | boolean |
| Default | false |
| Example | true |
Whether to enable remote features.
core.remote.remoteDesktop
| Type | submodule |
| Default | { } |
This option has no description.
core.remote.remoteDesktop.enable
| Type | boolean |
| Default | false |
| Example | true |
Whether to enable remote desktop.
core.remote.remoteDesktop.startCommand
| Type | string |
| Default | "gnome-session" |
Command to start remote desktop session.
core.remote.streaming
| Type | submodule |
| Default | { } |
This option has no description.
core.remote.streaming.enable
| Type | boolean |
| Default | false |
| Example | true |
Whether to enable remote streaming.
core.security.enable
| Type | boolean |
| Default | true |
| Example | true |
Whether to enable security features.
core.security.userLimit
| Type | unsigned integer, meaning >=0 |
| Default | 131072 |
The maximum number of open files per user.
This is used to set the limits for both PAM and systemd.
core.sops.enable
| Type | boolean |
| Default | config.core.enable |
| Example | true |
Whether to enable SOPS auto configuration.
core.sops.hostSecretsFile
| Type | absolute path |
| Default | "/nix/store/jq8636fkq2anq8f33kfqa816d0nrqw4m-source/hosts/secrets.yaml" |
Where the SOPS secret file of this host is located in the flake.
core.stylix.enable
| Type | boolean |
| Default | !config.host.device.isHeadless |
| Example | true |
Whether to enable Stylix configuration.
core.virtualisation.bridgeInterface
| Type | string |
| Default | "br0" |
Bridge interface used for libvirt networking.
core.virtualisation.cpuCores
| Type | signed integer |
| Default | 24 |
Total CPU core/thread count used for isolation helpers. Must be >= 4.
core.virtualisation.enable
| Type | boolean |
| Default | false |
| Example | true |
Whether to enable virtualisation support.
core.virtualisation.externalInterface
| Type | string |
| Default | "eth0" |
Physical interface attached to bridge.
core.virtualisation.gpu.audio
| Type | string |
| Default | "10de:1bef" |
PCI address for passthrough GPU audio device.
core.virtualisation.gpu.video
| Type | string |
| Default | "10de:1b06" |
PCI address for passthrough GPU video device.
core.virtualisation.isolatedGuests
| Type | list of string |
| Default | [ "win11" "win11-gaming" ] |
List of guests to apply isolation helpers to.
core.virtualisation.vmUsers
| Type | list of string |
| Default | [ ] |
Users that should receive kvm and libvirtd group membership for VM management.
core.wsl.enable
| Type | boolean |
| Default | false |
| Example | true |
Whether to enable WSL specific configurations, optimisations, and fixes.
core.wsl.user
| Type | string |
The default user to use for WSL.
Architecture / Services / Scope
Baseline Behaviour
When core.enable is true, module applies shared defaults from modules/nixos/core/default.nix:
- sets
services.dbus.implementation = "broker", - enables PipeWire audio stack and disables PulseAudio when
core.audio.enableis on, - enables Bluetooth stack, Blueman, and persisted Bluetooth state when
core.bluetooth.enableis on, - enables NetworkManager and adds
networkto shared default groups whencore.network.enableis on, and - on non-headless hosts, adds
videoandi2cgroups and enablesdleyna,gnome-keyring,udisks2,colord,xserver.updateDbusEnvironment, andpolkit.
Audio baseline also enables security.rtkit, adds audio, pipewire, and rtkit groups, installs udev rules for rtc0 and hpet, and sets PAM limits for realtime audio workloads.
Bluetooth baseline unblocks rfkill during activation and persists /var/lib/bluetooth.
Usage Example
{ ... }: {
core = {
enable = true;
audio.enable = true;
bluetooth.enable = true;
network.enable = true;
};
}
References
- Activation
- Auto Upgrade
- Containers
- Display Manager
- Gaming
- Generators
- Default Groups
- Locale
- Nix
- OpenSSH
- Printing
- Remote Access
- Security
- SOPS
- Stylix
- Virtualisation
- WSL
Operational Notes / Assumptions
These modules are imported through modules/nixos/core/default.nix. Most feature pages document their own core.<name> option namespaces, while some baseline modules such as Nix apply unconditionally once imported.