minimal profile

This commit is contained in:
2026-09-03 20:31:06 +09:00
parent 8761cbfe40
commit 937be12e33
10 changed files with 72 additions and 40 deletions
+16 -11
View File
@@ -351,6 +351,7 @@ modules/profiles/
├── base/ ├── base/
├── interface/ ├── interface/
│ ├── cli/ │ ├── cli/
│ ├── minimal/
│ ├── gui/ │ ├── gui/
│ ├── macos/ │ ├── macos/
│ ├── linux-desktop/ │ ├── linux-desktop/
@@ -393,11 +394,14 @@ The profile layers have these responsibilities:
- `base` contains only invariants required by every supported host. It includes - `base` contains only invariants required by every supported host. It includes
`systems.nix` and the universal Atuin, tealdeer, trippy, and xh CLI tools; `systems.nix` and the universal Atuin, tealdeer, trippy, and xh CLI tools;
optional secrets, interface, hardware, and workloads do not belong there. optional secrets, interface, hardware, and workloads do not belong there.
- `interface` describes how the host is operated. `interface.cli` is shared by - `interface` describes how the host is operated. `interface.minimal` is shared
NixOS and macOS and includes `tio`. `interface.gui` owns cross-platform by NixOS and macOS and provides the remote-administration CLI baseline,
graphical interface applications such as Vicinae. `interface.macos` owns the including SSH, Nano, htop, Git, Zellij, and Zsh. `interface.cli` includes that
macOS Finder, Dock, trackpad, and shared default preferences and includes baseline and adds the full interactive command-line environment, including
`interface.gui`. the configured Neovim, Yazi, and `tio`. `interface.gui` owns
cross-platform graphical interface applications such as Vicinae.
`interface.macos` owns the macOS Finder, Dock, trackpad, and shared default
preferences and includes `interface.gui`.
`interface.linux-desktop` owns the common labwc/niri desktop selection, `interface.linux-desktop` owns the common labwc/niri desktop selection,
including Ghostty and Nautilus, and also includes `interface.gui`. Labwc and including Ghostty and Nautilus, and also includes `interface.gui`. Labwc and
niri remain independently selectable and do not imply CLI or personal niri remain independently selectable and do not imply CLI or personal
@@ -542,7 +546,7 @@ A host registry may use a specification like this:
profiles = [ profiles = [
"base" "base"
"interface.cli" "interface.minimal"
"platform.vm" "platform.vm"
"workload.remote-access" "workload.remote-access"
]; ];
@@ -556,7 +560,7 @@ A host registry may use a specification like this:
profiles = [ profiles = [
"base" "base"
"interface.cli" "interface.minimal"
"platform.vm" "platform.vm"
"workload.server" "workload.server"
]; ];
@@ -653,10 +657,11 @@ A host registry may use a specification like this:
``` ```
The current role assignment is intentional: nix-example is the development VM; The current role assignment is intentional: nix-example is the development VM;
ops is the remote-access VM with host-specific static networking; ops is the minimal-interface remote-access VM with host-specific static
internal-app-01 is the container server VM; nix-builder is the remote Nix build networking; internal-app-01 is the minimal-interface container server VM;
VM with dedicated build and store disks; and installer builds the minimal nix-builder is the minimal-interface remote Nix build VM with dedicated build
installation ISO without Home Manager. x1g9 is a full NixOS desktop with niri, and store disks; and installer builds the minimal installation ISO without Home
Manager. x1g9 is a full NixOS desktop with niri,
labwc, ly, the shared Linux desktop applications, and the personal workload. labwc, ly, the shared Linux desktop applications, and the personal workload.
x1g13 is the secure NixOS development and personal ThinkPad, with the same x1g13 is the secure NixOS development and personal ThinkPad, with the same
desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk
+2 -2
View File
@@ -7,7 +7,7 @@
profiles = [ profiles = [
"base" "base"
"interface.cli" "interface.minimal"
"platform.vm" "platform.vm"
"workload.remote-access" "workload.remote-access"
]; ];
@@ -21,7 +21,7 @@
profiles = [ profiles = [
"base" "base"
"interface.cli" "interface.minimal"
"platform.vm" "platform.vm"
"workload.remote-access" "workload.remote-access"
]; ];
+4
View File
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.htop ];
}
+4
View File
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.nano ];
}
+15
View File
@@ -31,5 +31,20 @@ lib.mkMerge [
IdentityAgent %d/.1password/agent.sock IdentityAgent %d/.1password/agent.sock
''; '';
}; };
home.activation.generateSshKey = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
key="$HOME/.ssh/id_ed25519"
if [ ! -f "$key" ]; then
umask 077
mkdir -p "$HOME/.ssh"
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
echo "Generated SSH key at $key"
fi
'';
};
} }
] ]
+6
View File
@@ -24,6 +24,7 @@ required on every supported host.
| Profile | Supported host class | | Profile | Supported host class |
| ------------------------------------ | --------------------------------------------- | | ------------------------------------ | --------------------------------------------- |
| `base` | NixOS, macOS | | `base` | NixOS, macOS |
| `interface.minimal` | NixOS, macOS with Home Manager |
| `interface.cli` | NixOS, macOS with Home Manager | | `interface.cli` | NixOS, macOS with Home Manager |
| `interface.gui` | NixOS, macOS with Home Manager | | `interface.gui` | NixOS, macOS with Home Manager |
| `interface.macos` | macOS | | `interface.macos` | macOS |
@@ -61,6 +62,11 @@ selects labwc. A daily-use macOS development machine can combine
`interface.macos`, `workload.development`, and `workload.personal`. Hardware `interface.macos`, `workload.development`, and `workload.personal`. Hardware
support does not implicitly select an interface or workload. support does not implicitly select an interface or workload.
`interface.minimal` provides SSH client access and key generation, Nano, htop,
btop, fastfetch, unzip, wget, Direnv, Git, GnuPG, nh, Zellij, and Zsh for remote
administration. `interface.cli` includes that baseline and adds the configured
Neovim, Yazi, and the remaining interactive command-line tools.
`workload.machine-learning` provides the Hugging Face Hub CLI for hosts used `workload.machine-learning` provides the Hugging Face Hub CLI for hosts used
to download and publish machine learning models and datasets. to download and publish machine learning models and datasets.
-19
View File
@@ -8,36 +8,17 @@
dust dust
eza eza
fd fd
fastfetch
fzf fzf
htop
jq jq
lsof lsof
nurl nurl
ripgrep ripgrep
tio tio
unrar unrar
unzip
wget
] ]
++ lib.optionals stdenv.isLinux [ ++ lib.optionals stdenv.isLinux [
lm_sensors lm_sensors
psmisc psmisc
strace strace
]; ];
home.activation.generateSshKey = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
key="$HOME/.ssh/id_ed25519"
if [ ! -f "$key" ]; then
umask 077
mkdir -p "$HOME/.ssh"
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
echo "Generated SSH key at $key"
fi
'';
};
} }
+1 -8
View File
@@ -2,17 +2,10 @@
description = "Cross-platform interactive command-line environment"; description = "Cross-platform interactive command-line environment";
includes = [ includes = [
"applications.btop" "profiles.interface.minimal"
"applications.direnv"
"applications.git"
"applications.gnupg"
"applications.nh"
"applications.nix-index" "applications.nix-index"
"applications.ssh"
"applications.vim" "applications.vim"
"applications.yazi" "applications.yazi"
"applications.zellij"
"applications.zoxide" "applications.zoxide"
"applications.zsh"
]; ];
} }
@@ -0,0 +1,8 @@
{ pkgs, ... }:
{
home.packages = with pkgs; [
fastfetch
unzip
wget
];
}
@@ -0,0 +1,16 @@
{
description = "Minimal cross-platform command-line environment for remote administration";
includes = [
"applications.btop"
"applications.direnv"
"applications.git"
"applications.gnupg"
"applications.htop"
"applications.nano"
"applications.nh"
"applications.ssh"
"applications.zellij"
"applications.zsh"
];
}