diff --git a/AGENTS.md b/AGENTS.md index 71b84e5..0ebcff8 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -373,6 +373,7 @@ modules/profiles/ │ ├── development/ │ ├── game/ │ ├── machine-learning/ +│ ├── network-lab/ │ ├── personal/ │ ├── photography/ │ ├── server/ @@ -632,6 +633,7 @@ A host registry may use a specification like this: "security.tpm-storage" "workload.camera" "workload.development" + "workload.network-lab" "workload.personal" ]; }; @@ -654,6 +656,7 @@ A host registry may use a specification like this: "workload.development" "workload.game" "workload.machine-learning" + "workload.network-lab" "workload.personal" "workload.photography" ]; @@ -692,6 +695,7 @@ uses dedicated NixOS partitions, LUKS, Secure Boot, and TPM-backed disk unlock. It selects `workload.photography` for AI-enabled darktable. The application chooses CUDA support from the NVIDIA hardware unit's enable state and keeps the default CUDA targets, including RTX 3060 Ti support, to reuse binary caches. +galleria and x1g13 select `workload.network-lab` for containerlab and Docker. m2 is the daily-use macOS development and personal machine with the macOS interface defaults. Keep the desktop sessions independently selectable, and keep the development and personal profiles usable across NixOS and Darwin. diff --git a/flake.lock b/flake.lock index 5a0773c..d8c698e 100644 --- a/flake.lock +++ b/flake.lock @@ -239,6 +239,24 @@ "type": "github" } }, + "containerlab": { + "inputs": { + "nixpkgs": "nixpkgs_4" + }, + "locked": { + "lastModified": 1788902093, + "narHash": "sha256-BUwJClTgVrx1gOXFw89cUWFCB3jen3dd94DdlGusODc=", + "owner": "srl-labs", + "repo": "containerlab", + "rev": "72564c13516d19b81474a2b486cfc8e6b9c3ffc3", + "type": "github" + }, + "original": { + "owner": "srl-labs", + "repo": "containerlab", + "type": "github" + } + }, "crane": { "locked": { "lastModified": 1784407669, @@ -582,7 +600,7 @@ "inputs": { "flake-compat": "flake-compat_2", "home-manager": "home-manager_2", - "nixpkgs": "nixpkgs_4", + "nixpkgs": "nixpkgs_5", "systems": "systems_4", "zig": "zig", "zon2nix": "zon2nix" @@ -627,7 +645,7 @@ "git-hooks-nix": { "inputs": { "flake-compat": "flake-compat_3", - "nixpkgs": "nixpkgs_5" + "nixpkgs": "nixpkgs_6" }, "locked": { "lastModified": 1788267358, @@ -791,7 +809,7 @@ "inputs": { "bun2nix": "bun2nix_2", "flake-parts": "flake-parts_4", - "nixpkgs": "nixpkgs_6", + "nixpkgs": "nixpkgs_7", "systems": "systems_5", "treefmt-nix": "treefmt-nix_3" }, @@ -827,7 +845,7 @@ }, "nani-translate-linux": { "inputs": { - "nixpkgs": "nixpkgs_7" + "nixpkgs": "nixpkgs_8" }, "locked": { "lastModified": 1786578029, @@ -847,7 +865,7 @@ "inputs": { "niri-stable": "niri-stable", "niri-unstable": "niri-unstable", - "nixpkgs": "nixpkgs_8", + "nixpkgs": "nixpkgs_9", "nixpkgs-stable": "nixpkgs-stable", "xwayland-satellite-stable": "xwayland-satellite-stable", "xwayland-satellite-unstable": "xwayland-satellite-unstable" @@ -978,7 +996,7 @@ }, "nixos-hardware": { "inputs": { - "nixpkgs": "nixpkgs_9" + "nixpkgs": "nixpkgs_10" }, "locked": { "lastModified": 1788335262, @@ -998,7 +1016,7 @@ "nixos-wsl": { "inputs": { "flake-compat": "flake-compat_5", - "nixpkgs": "nixpkgs_10" + "nixpkgs": "nixpkgs_11" }, "locked": { "lastModified": 1784642409, @@ -1109,6 +1127,19 @@ } }, "nixpkgs_10": { + "locked": { + "lastModified": 1767892417, + "narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=", + "rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba", + "type": "tarball", + "url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre924538.3497aa5c9457/nixexprs.tar.xz" + }, + "original": { + "type": "tarball", + "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz" + } + }, + "nixpkgs_11": { "locked": { "lastModified": 1783776592, "narHash": "sha256-UgCQzxeWI75XM8G+hPrPh+MKzEPjG3SpAj7dtqSbksA=", @@ -1124,7 +1155,7 @@ "type": "github" } }, - "nixpkgs_11": { + "nixpkgs_12": { "locked": { "lastModified": 1788405554, "narHash": "sha256-r2f1oUwixlgq9zOdYLqJLfS/lWBT60/IITjhTKI59JU=", @@ -1140,7 +1171,7 @@ "type": "github" } }, - "nixpkgs_12": { + "nixpkgs_13": { "locked": { "lastModified": 1787900134, "narHash": "sha256-5GWj0FI2uOwKNpXkmpWrSFDe1rCaNBCUQ8d+HDtFQPI=", @@ -1153,7 +1184,7 @@ "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.zst" } }, - "nixpkgs_13": { + "nixpkgs_14": { "locked": { "lastModified": 1770107345, "narHash": "sha256-tbS0Ebx2PiA1FRW8mt8oejR0qMXmziJmPaU1d4kYY9g=", @@ -1169,7 +1200,7 @@ "type": "github" } }, - "nixpkgs_14": { + "nixpkgs_15": { "locked": { "lastModified": 1787900134, "narHash": "sha256-VYXO0XZlgj06dxJZRhrD3WoSsvq/c7+/Akyoa22pefw=", @@ -1218,6 +1249,22 @@ } }, "nixpkgs_4": { + "locked": { + "lastModified": 1787900134, + "narHash": "sha256-VYXO0XZlgj06dxJZRhrD3WoSsvq/c7+/Akyoa22pefw=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "83199d0d373dd3ac2b9a1996b1d0263f76ab7a4c", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_5": { "locked": { "lastModified": 1787424095, "narHash": "sha256-SpMiSe9OSfWseGAupsdcED3He9mTYTbGMtWb7EVt6pE=", @@ -1230,7 +1277,7 @@ "url": "https://channels.nixos.org/nixpkgs-unstable/nixexprs.tar.zst" } }, - "nixpkgs_5": { + "nixpkgs_6": { "locked": { "lastModified": 1787631388, "narHash": "sha256-vMiXptXarfSdJb1Gkc+FYVOAibuBRj7qxGa8z68q1Uw=", @@ -1246,7 +1293,7 @@ "type": "github" } }, - "nixpkgs_6": { + "nixpkgs_7": { "locked": { "lastModified": 1788372231, "narHash": "sha256-7aqErvrAEz/5OcPA5p3M+tVOqeYc4oJXkNIPXfCqxAw=", @@ -1262,7 +1309,7 @@ "type": "github" } }, - "nixpkgs_7": { + "nixpkgs_8": { "locked": { "lastModified": 1785454630, "narHash": "sha256-LQy14TZp77TwbQf40gg1V3jo8FwJG0jGDkAH+zRHqg8=", @@ -1278,7 +1325,7 @@ "type": "github" } }, - "nixpkgs_8": { + "nixpkgs_9": { "locked": { "lastModified": 1785828668, "narHash": "sha256-8fsyqeO+mJqvIzeO4xIpgJe/f7MTbbVTEC6RT6WSXNs=", @@ -1294,19 +1341,6 @@ "type": "github" } }, - "nixpkgs_9": { - "locked": { - "lastModified": 1767892417, - "narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=", - "rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba", - "type": "tarball", - "url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre924538.3497aa5c9457/nixexprs.tar.xz" - }, - "original": { - "type": "tarball", - "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz" - } - }, "nixvim": { "inputs": { "flake-parts": "flake-parts_5", @@ -1332,7 +1366,7 @@ }, "noctalia": { "inputs": { - "nixpkgs": "nixpkgs_12" + "nixpkgs": "nixpkgs_13" }, "locked": { "lastModified": 1788556054, @@ -1423,6 +1457,7 @@ "browser-previews": "browser-previews", "codex-desktop-linux": "codex-desktop-linux", "codex-session-usage": "codex-session-usage", + "containerlab": "containerlab", "disko": "disko", "flake-parts": "flake-parts_3", "ghostty": "ghostty", @@ -1437,7 +1472,7 @@ "nix-index-database": "nix-index-database", "nixos-hardware": "nixos-hardware", "nixos-wsl": "nixos-wsl", - "nixpkgs": "nixpkgs_11", + "nixpkgs": "nixpkgs_12", "nixpkgs-unstable": "nixpkgs-unstable", "nixvim": "nixvim", "noctalia": "noctalia", @@ -1884,7 +1919,7 @@ }, "treefmt-nix_4": { "inputs": { - "nixpkgs": "nixpkgs_13" + "nixpkgs": "nixpkgs_14" }, "locked": { "lastModified": 1786901030, @@ -1902,7 +1937,7 @@ }, "vicinae": { "inputs": { - "nixpkgs": "nixpkgs_14", + "nixpkgs": "nixpkgs_15", "numen": "numen", "soulver-cpp": "soulver-cpp", "systems": "systems_9" diff --git a/flake.nix b/flake.nix index a5899d4..01e74ff 100644 --- a/flake.nix +++ b/flake.nix @@ -114,6 +114,7 @@ nani-translate-linux.url = "git+https://github.com/zunoser/nani-translate-linux.git"; + containerlab.url = "github:srl-labs/containerlab"; }; outputs = diff --git a/hosts/default.nix b/hosts/default.nix index dbebd81..defb308 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -91,6 +91,7 @@ "security.tpm-storage" "workload.development" "workload.game" + "workload.network-lab" "workload.personal" ]; @@ -116,6 +117,7 @@ "workload.development" "workload.game" "workload.machine-learning" + "workload.network-lab" "workload.personal" "workload.photography" "workload.camera" diff --git a/modules/applications/containerlab/meta.nix b/modules/applications/containerlab/meta.nix new file mode 100644 index 0000000..4336572 --- /dev/null +++ b/modules/applications/containerlab/meta.nix @@ -0,0 +1,8 @@ +{ inputs, ... }: +{ + description = "Container-based networking labs"; + + includes = [ "services.docker" ]; + + imports.nixos = [ inputs.containerlab.nixosModules.default ]; +} diff --git a/modules/applications/containerlab/nixos.nix b/modules/applications/containerlab/nixos.nix new file mode 100644 index 0000000..ab40348 --- /dev/null +++ b/modules/applications/containerlab/nixos.nix @@ -0,0 +1,3 @@ +{ + programs.containerlab.enable = true; +} diff --git a/modules/profiles/README.md b/modules/profiles/README.md index c4f050b..f46bd93 100644 --- a/modules/profiles/README.md +++ b/modules/profiles/README.md @@ -41,6 +41,7 @@ required on every supported host. | `workload.development` | NixOS, macOS with Home Manager | | `workload.game` | NixOS, macOS | | `workload.machine-learning` | NixOS with Home Manager | +| `workload.network-lab` | NixOS | | `workload.personal` | NixOS, macOS with Home Manager | | `workload.photography` | NixOS with Home Manager | | `workload.remote-access` | NixOS, macOS | @@ -74,6 +75,9 @@ Neovim, Yazi, and the remaining interactive command-line tools. `workload.machine-learning` provides the Hugging Face Hub CLI for hosts used to download and publish machine learning models and datasets. +`workload.network-lab` provides containerlab using its upstream NixOS module +and the Docker service. It is selected by galleria and x1g13. + `workload.photography` provides darktable with AI support from the locked unstable package set. Its ONNX Runtime uses CUDA when the NVIDIA hardware unit is enabled, and CPU inference otherwise. Keep the default CUDA capabilities diff --git a/modules/profiles/workload/network-lab/meta.nix b/modules/profiles/workload/network-lab/meta.nix new file mode 100644 index 0000000..7264d6d --- /dev/null +++ b/modules/profiles/workload/network-lab/meta.nix @@ -0,0 +1,5 @@ +{ + description = "Container-based network lab environment"; + + includes = [ "applications.containerlab" ]; +}