diff --git a/AGENTS.md b/AGENTS.md index 265287a..4f88908 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -6,7 +6,8 @@ NixOS + Home Manager flake (v2)。flake-parts ベース。 ```sh nix flake update # flake の更新 -nix fmt # フォーマット +nix fmt # フォーマット (treefmt: nixfmt, deadnix, statix, shfmt, shellcheck, prettier, yamlfmt, taplo, oxfmt) +nix develop .#dotnix # 開発シェル (pre-commit hooks, sops, age 入り) sudo nixos-rebuild build --flake .# # ビルド確認 sudo nixos-rebuild switch --flake .# # 適用 ``` @@ -21,22 +22,34 @@ sudo nixos-rebuild switch --flake .# # 適用 - home-manager の `sharedModules` 内で `lib.hm.*` を使う場合は、そのモジュール関数の引数で `lib` を受け取る必要がある(NixOSモジュールの `lib` とは別スコープ) - `useGlobalPkgs = true` なので、home-manager 内で `nixpkgs.config` を設定しない(NixOSレベルで一括設定) - `allowUnfree` は `hosts/default.nix` でグローバルに設定済み。各モジュールで個別設定しない +- pre-commit hooks が `git-hooks.nix` で設定済み(treefmt, gitleaks, deadnix, statix, shellcheck)。dev shell で自動有効化 + +## Secrets + +- **sops-nix** + **age** + **YubiKey** で秘密管理 +- `.sops.yaml` で暗号化ルール定義、`secrets/` に暗号化済み YAML を配置 +- `modules/system/sops.nix` で sops-nix を import、`services.pcscd` (YubiKey用) を有効化 +- `modules/system/secret.nix` で `sops.secrets` を宣言 +- 平文の秘密をコミットしない(gitleaks が pre-commit で検出) ## Architecture ``` flake.nix -└── hosts/default.nix # mkSystem でホスト構成を生成 - ├── modules/ # 全モジュール(常にインポートされる) - │ ├── applications/ # アプリケーション設定 - │ ├── system/ # システム設定 - │ ├── drivers/ # ドライバ設定 - │ ├── features/ # 機能バンドル(application/systemを束ねる) - │ └── integrations/ # home-manager 統合 - └── profiles/ # ホストごとに有効化するfeaturesの組み合わせ - ├── interfaces/ # 操作インターフェース (CLI/GUI) - ├── platforms/ # ハードウェア (desktop/laptop/vm) - └── workloads/ # 用途 (dev/personal/srv) +├── hosts/default.nix # mkSystem でホスト構成を生成 +│ ├── modules/ # 全モジュール(常にインポートされる) +│ │ ├── applications/ # アプリケーション設定 +│ │ ├── system/ # システム設定 +│ │ ├── drivers/ # ドライバ設定 +│ │ ├── features/ # 機能バンドル(application/systemを束ねる) +│ │ └── integrations/ # home-manager 統合 +│ └── profiles/ # ホストごとに有効化するfeaturesの組み合わせ +│ ├── interfaces/ # 操作インターフェース (CLI/GUI) +│ ├── platforms/ # ハードウェア (desktop/laptop/thinkpad/vm) +│ └── workloads/ # 用途 (dev/personal/srv/remote/secure-storage) +├── overlays/ # nixpkgs オーバーレイ +├── shells/ # devShells (dotnix) +└── flake/ # formatter.nix, git-hooks.nix ``` ### 評価の流れ @@ -54,7 +67,7 @@ profile (featuresの有効化) OS全体に影響する設定。`config.my.system.*` namespace。 -- boot, hardware, network, user, locale, fonts, power, secure-boot, gc, version +- audio, boot, camera, disko, fingerprint, fonts, gc, hardware, locale, network, nix, power, secure-boot, sops, user, version, secret - 常にインポートされるが、`enable` オプションで実効性を制御 - home-manager の設定は含めない @@ -65,6 +78,10 @@ OS全体に影響する設定。`config.my.system.*` namespace。 - NixOS設定のみ、または NixOS + Home Manager の両方 - Complex Module は system.nix と home.nix に分離 +### `modules/drivers/` — ドライバ設定 + +ハードウェア固有のドライバ。`config.my.drivers.*` namespace。 + ### `modules/features/` — 機能バンドル application や system より抽象度の高い「機能」単位で、複数の application/system を束ねて有効化する層。`config.my.features.*` namespace。 @@ -77,17 +94,17 @@ application や system より抽象度の高い「機能」単位で、複数の **features がやらないこと:** -- 個別アプリケーションの詳細設定(それは applications 層の責務) +- 個別アプリケーションの詳細設定(これは applications 層の責務) ### `profiles/` — ホスト構成 features の `enable` を指定するだけの薄い層。ロジックは書かない。 -| カテゴリ | 役割 | 例 | -| ------------- | -------------------- | --------------------------------- | -| `interfaces/` | 操作インターフェース | cli-minimal, cli-interactive, gui | -| `platforms/` | ハードウェア固有設定 | desktop, laptop, thinkpad, vm | -| `workloads/` | 用途・ワークロード | dev, personal, srv | +| カテゴリ | 役割 | 例 | +| ------------- | -------------------- | ------------------------------------------ | +| `interfaces/` | 操作インターフェース | cli-minimal, cli-interactive, gui | +| `platforms/` | ハードウェア固有設定 | desktop, laptop, thinkpad, vm | +| `workloads/` | 用途・ワークロード | dev, personal, srv, remote, secure-storage | profiles は継承可能: @@ -117,6 +134,8 @@ nix-example = mkSystem { `specialArgs` で `inputs`, `username`, `unstable`, `host` が全モジュールに渡される。 +**注意:** `installer` ホストは `mkSystem` を使わず直接 `nixosSystem` で定義(インストーラ用)。 + ## Module Patterns ### Simple Module(NixOS のみ) @@ -393,8 +412,10 @@ features の有効化のみを記述: - **nixpkgs channel**: `nixos-26.05` (stable) + `nixpkgs-unstable` - **unstable パッケージ**: `specialArgs.unstable` 経由で参照(`unstable.`) -- **llm-agents**: `inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.` で参照 +- **llm-agents**: `inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.` で参照。overlay も `hosts/default.nix` でグローバルに適用 - **nixvim**: `nixpkgs.source = pkgs.path` と `nixpkgs.config.allowUnfree = true` を vim/home/default.nix で設定 -- **home-manager**: `useGlobalPkgs = true`, `useUserPackages = true` +- **home-manager**: `useGlobalPkgs = true`, `useUserPackages = true`, `backupFileExtension = "backup"` - **hostname**: `specialArgs.host` から `modules/system/network/default.nix` で `networking.hostName` に設定 - **stateVersion**: `config.my.stateVersions.nixos` / `config.my.stateVersions.homeManager` で管理(`modules/system/version.nix`) +- **disko**: `modules/system/disko.nix` で disk パーティション管理。ホスト固有の `disko.nix` を import +- **stylix**: `inputs.stylix` でテーマ管理 diff --git a/README.md b/README.md new file mode 100644 index 0000000..bf8ae74 --- /dev/null +++ b/README.md @@ -0,0 +1,191 @@ +# dotfiles + +My NixOS + Home Manager configurations built with flake-parts. + +## Overview + +- **OS**: NixOS 26.05 (stable) + nixpkgs-unstable +- **Window Manager**: Niri (Wayland) +- **Shell**: Zsh +- **Terminal**: Ghostty +- **Editor**: Neovim (nixvim), VSCode +- **Launcher**: Vicinae +- **Theme**: Stylix (Dracula) +- **Secrets**: sops-nix + age + YubiKey + +## Hosts + +| Host | Description | Profiles | +| ------------- | --------------- | -------------------------------------------- | +| `x1g13` | ThinkPad laptop | gui, thinkpad, dev, personal, secure-storage | +| `nix-example` | VM | cli-interactive, vm, dev, remote | +| `installer` | NixOS installer | (standalone) | + +## Directory Structure + +``` +. +├── flake.nix # Flake inputs and outputs +├── flake/ +│ ├── formatter.nix # treefmt configuration (nixfmt, deadnix, statix, etc.) +│ └── git-hooks.nix # pre-commit hooks +├── hosts/ +│ ├── default.nix # mkSystem helper and host definitions +│ ├── x1g13/ # ThinkPad host config +│ ├── nix-example/ # VM host config +│ └── installer/ # Installer ISO config +├── modules/ +│ ├── applications/ # Application configs (NixOS + Home Manager) +│ │ ├── niri/ # Wayland compositor +│ │ ├── ghostty/ # Terminal emulator +│ │ ├── vim/ # Neovim (nixvim) +│ │ ├── vscode/ # VSCode +│ │ ├── zsh/ # Shell +│ │ ├── zellij/ # Terminal multiplexer +│ │ ├── git/ # Git config +│ │ ├── docker.nix # Container runtime +│ │ ├── tailscale.nix # VPN +│ │ ├── claude/ # Claude Code +│ │ ├── opencode.nix # OpenCode +│ │ └── ... # chrome, discord, zoom, slack, etc. +│ ├── system/ # NixOS system configs +│ │ ├── audio.nix # PipeWire +│ │ ├── boot/ # Bootloader (systemd-boot, lanzaboote) +│ │ ├── disko.nix # Disk partitioning +│ │ ├── fonts.nix # Fonts +│ │ ├── network/ # Networking +│ │ ├── sops.nix # Secrets management +│ │ ├── user/ # User accounts +│ │ └── ... +│ ├── features/ # Feature bundles (abstraction layer) +│ │ ├── application/ # browser, communication +│ │ ├── boot/ # UEFI +│ │ ├── cli/ # base, interactive, shell +│ │ ├── connect/ # WiFi, Bluetooth +│ │ ├── dev/ # agent, nix, python, bun, java, arduino +│ │ ├── gui/ # desktop, terminal, audio, editor, capture +│ │ ├── identity/ # SSH key, fingerprint +│ │ ├── network/ # Tailscale +│ │ ├── services/ # container, KDE +│ │ └── storage/ # disko +│ ├── drivers/ # Hardware drivers (Intel) +│ └── integrations/ # Home Manager integration +├── profiles/ +│ ├── interfaces/ # cli-minimal, cli-interactive, gui +│ ├── platforms/ # desktop, laptop, thinkpad, vm +│ └── workloads/ # dev, personal, srv, remote, secure-storage +├── overlays/ # nixpkgs overlays +├── shells/ # devShells (pre-commit hooks, sops, age) +├── secrets/ # Encrypted secrets (sops) +└── docs/ # Documentation +``` + +## Architecture + +``` +profile (enable features) + → features (bundle applications/system + add packages) + → applications (system.nix + home.nix) + → system (NixOS config) +``` + +### Module Patterns + +**Simple Module** — Single file for NixOS-only or Home Manager-only configs: + +```nix +{ lib, config, ... }: +let cfg = config.my.system.audio; +in { + options.my.system.audio.enable = lib.mkEnableOption "Audio"; + config = lib.mkIf cfg.enable { ... }; +} +``` + +**Complex Module** — Directory with `default.nix`, `system.nix`, `home.nix`: + +``` +modules/applications// +├── default.nix # Master enable + imports +├── system.nix # NixOS config +└── home.nix # Home Manager config (sharedModules) +``` + +**Feature Module** — Bundles multiple applications/system modules: + +```nix +{ lib, config, ... }: +let cfg = config.my.features.gui.desktop; +in { + options.my.features.gui.desktop.enable = lib.mkEnableOption "Desktop"; + config = lib.mkIf cfg.enable { + my.applications = { niri.enable = true; gtk.enable = true; ... }; + }; +} +``` + +**Profile** — Thin layer that only enables features: + +```nix +{ + my.features = { + gui.desktop.enable = true; + dev.agent.enable = true; + }; +} +``` + +## Packages + +### CLI + +- **Shell**: Zsh with zoxide, direnv +- **Terminal multiplexer**: Zellij +- **Editor**: Neovim (nixvim) +- **Tools**: ripgrep, curl, wget, htop, btop, fastfetch, unzip, unrar + +### GUI + +- **Compositor**: Niri +- **Terminal**: Ghostty, Alacritty +- **Editor**: VSCode +- **Browser**: Chrome +- **Launcher**: Vicinae +- **File manager**: Nautilus +- **Communication**: Discord, Zoom, Slack + +### Development + +- **AI agents**: Claude Code, Codex, OpenCode, Grok +- **Languages**: Python, Bun (JavaScript/TypeScript), Java, Arduino +- **Container**: Docker +- **Nix**: nh, nixfmt, deadnix, statix + +### System + +- **VPN**: Tailscale +- **Secrets**: sops-nix, age +- **Boot**: systemd-boot, lanzaboote (Secure Boot) +- **Disk**: disko +- **Theme**: Stylix + +## Commands + +```sh +nix flake update # Update flake inputs +nix fmt # Format code +nix develop .#dotnix # Enter dev shell +sudo nixos-rebuild switch --flake .# # Apply config +sudo nixos-rebuild build --flake .# # Build without applying +``` + +## Inspired + +- [Zaney/zaneyos](https://gitlab.com/Zaney/zaneyos) +- [fa0311/.zshrc](https://gist.github.com/fa0311/d37d53ff39c73c54c883379e8e3732df) +- [AsianLovesLinux/Niri](https://github.com/AsianLovesLinux/Niri) +- [natsukium/dotfiles](https://github.com/natsukium/dotfiles) +- [dracula](https://github.com/dracula) +- [akazdayo/nix-configs](https://github.com/akazdayo/nix-configs) +- [yutakobayashidev/dotnix](https://github.com/yutakobayashidev/dotnix) +- [kawaemon/dotfiles](https://github.com/kawaemon/dotfiles) diff --git a/modules/applications/ghostty/config b/modules/applications/ghostty/config index 0e55901..e58b323 100644 --- a/modules/applications/ghostty/config +++ b/modules/applications/ghostty/config @@ -27,5 +27,14 @@ keybind = ctrl+shift+semicolon=increase_font_size:1 keybind = ctrl+shift+minus=increase_font_size:1 +# quick terminal +keybind = global:super+space=toggle_quick_terminal +quick-terminal-position = top +quick-terminal-size = 100% +gtk-quick-terminal-layer = overlay +quick-terminal-keyboard-interactivity = exclusive +quick-terminal-autohide = false +quit-after-last-window-closed = false + shell-integration-features = ssh-terminfo,ssh-env diff --git a/modules/applications/ghostty/home.nix b/modules/applications/ghostty/home.nix index dda43d8..dd9ab26 100644 --- a/modules/applications/ghostty/home.nix +++ b/modules/applications/ghostty/home.nix @@ -12,18 +12,70 @@ in }; config.home-manager.sharedModules = [ - { - config = lib.mkIf cfg.enable { - home.file.".config/ghostty/config" = { - recursive = true; - source = ./config; - }; + ( + { lib, ... }: + { + config = lib.mkIf cfg.enable { + programs.ghostty = { + enable = true; - home.file.".config/ghostty/themes/dracula" = { - recursive = true; - source = ./dracula.theme; + systemd.enable = true; + + settings = { + theme = "dracula"; + + background-blur-radius = 20; + background-opacity = 0.9; + + font-family = "BlexMono Nerd Font Mono"; + + mouse-hide-while-typing = true; + + window-decoration = "auto"; + + keybind = [ + # Copy/Paste + "performable:ctrl+shift+c=copy_to_clipboard" + "ctrl+shift+v=paste_from_clipboard" + + # Create new tab + "ctrl+shift+t=new_tab" + + # Move tabs + "ctrl+alt+left_bracket=previous_tab" + "ctrl+alt+right_bracket=next_tab" + + # Close window + "ctrl+alt+q=close_window" + + # Font size + "ctrl+shift+semicolon=increase_font_size:1" + "ctrl+shift+minus=decrease_font_size:1" + + # Quick terminal + "global:super+space=toggle_quick_terminal" + ]; + + # Quick terminal + quick-terminal-position = "top"; + + quick-terminal-size = "100%"; + + gtk-quick-terminal-layer = "overlay"; + + quick-terminal-keyboard-interactivity = "exclusive"; + + quick-terminal-autohide = false; + + quit-after-last-window-closed = false; + + shell-integration-features = "ssh-terminfo,ssh-env"; + }; + }; + + xdg.configFile."ghostty/themes/dracula".source = ./dracula.theme; }; - }; - } + } + ) ]; } diff --git a/modules/applications/niri/home.nix b/modules/applications/niri/home.nix index a893e63..3c254f9 100644 --- a/modules/applications/niri/home.nix +++ b/modules/applications/niri/home.nix @@ -69,13 +69,6 @@ in ]; hotkey-overlay.title = "Run an Application: vicinae"; }; - "Mod+Space" = { - action.spawn = [ - "vicinae" - "toggle" - ]; - hotkey-overlay.title = "Run an Application: vicinae"; - }; "Mod+E" = { action.spawn = [ "nautilus"