minimal profile

This commit is contained in:
2026-09-03 20:31:06 +09:00
parent 8761cbfe40
commit 937be12e33
10 changed files with 72 additions and 40 deletions
+16 -11
View File
@@ -351,6 +351,7 @@ modules/profiles/
├── base/
├── interface/
│ ├── cli/
│ ├── minimal/
│ ├── gui/
│ ├── macos/
│ ├── linux-desktop/
@@ -393,11 +394,14 @@ The profile layers have these responsibilities:
- `base` contains only invariants required by every supported host. It includes
`systems.nix` and the universal Atuin, tealdeer, trippy, and xh CLI tools;
optional secrets, interface, hardware, and workloads do not belong there.
- `interface` describes how the host is operated. `interface.cli` is shared by
NixOS and macOS and includes `tio`. `interface.gui` owns cross-platform
graphical interface applications such as Vicinae. `interface.macos` owns the
macOS Finder, Dock, trackpad, and shared default preferences and includes
`interface.gui`.
- `interface` describes how the host is operated. `interface.minimal` is shared
by NixOS and macOS and provides the remote-administration CLI baseline,
including SSH, Nano, htop, Git, Zellij, and Zsh. `interface.cli` includes that
baseline and adds the full interactive command-line environment, including
the configured Neovim, Yazi, and `tio`. `interface.gui` owns
cross-platform graphical interface applications such as Vicinae.
`interface.macos` owns the macOS Finder, Dock, trackpad, and shared default
preferences and includes `interface.gui`.
`interface.linux-desktop` owns the common labwc/niri desktop selection,
including Ghostty and Nautilus, and also includes `interface.gui`. Labwc and
niri remain independently selectable and do not imply CLI or personal
@@ -542,7 +546,7 @@ A host registry may use a specification like this:
profiles = [
"base"
"interface.cli"
"interface.minimal"
"platform.vm"
"workload.remote-access"
];
@@ -556,7 +560,7 @@ A host registry may use a specification like this:
profiles = [
"base"
"interface.cli"
"interface.minimal"
"platform.vm"
"workload.server"
];
@@ -653,10 +657,11 @@ A host registry may use a specification like this:
```
The current role assignment is intentional: nix-example is the development VM;
ops is the remote-access VM with host-specific static networking;
internal-app-01 is the container server VM; nix-builder is the remote Nix build
VM with dedicated build and store disks; and installer builds the minimal
installation ISO without Home Manager. x1g9 is a full NixOS desktop with niri,
ops is the minimal-interface remote-access VM with host-specific static
networking; internal-app-01 is the minimal-interface container server VM;
nix-builder is the minimal-interface remote Nix build VM with dedicated build
and store disks; and installer builds the minimal installation ISO without Home
Manager. x1g9 is a full NixOS desktop with niri,
labwc, ly, the shared Linux desktop applications, and the personal workload.
x1g13 is the secure NixOS development and personal ThinkPad, with the same
desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk
+2 -2
View File
@@ -7,7 +7,7 @@
profiles = [
"base"
"interface.cli"
"interface.minimal"
"platform.vm"
"workload.remote-access"
];
@@ -21,7 +21,7 @@
profiles = [
"base"
"interface.cli"
"interface.minimal"
"platform.vm"
"workload.remote-access"
];
+4
View File
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.htop ];
}
+4
View File
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.nano ];
}
+15
View File
@@ -31,5 +31,20 @@ lib.mkMerge [
IdentityAgent %d/.1password/agent.sock
'';
};
home.activation.generateSshKey = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
key="$HOME/.ssh/id_ed25519"
if [ ! -f "$key" ]; then
umask 077
mkdir -p "$HOME/.ssh"
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
echo "Generated SSH key at $key"
fi
'';
};
}
]
+6
View File
@@ -24,6 +24,7 @@ required on every supported host.
| Profile | Supported host class |
| ------------------------------------ | --------------------------------------------- |
| `base` | NixOS, macOS |
| `interface.minimal` | NixOS, macOS with Home Manager |
| `interface.cli` | NixOS, macOS with Home Manager |
| `interface.gui` | NixOS, macOS with Home Manager |
| `interface.macos` | macOS |
@@ -61,6 +62,11 @@ selects labwc. A daily-use macOS development machine can combine
`interface.macos`, `workload.development`, and `workload.personal`. Hardware
support does not implicitly select an interface or workload.
`interface.minimal` provides SSH client access and key generation, Nano, htop,
btop, fastfetch, unzip, wget, Direnv, Git, GnuPG, nh, Zellij, and Zsh for remote
administration. `interface.cli` includes that baseline and adds the configured
Neovim, Yazi, and the remaining interactive command-line tools.
`workload.machine-learning` provides the Hugging Face Hub CLI for hosts used
to download and publish machine learning models and datasets.
-19
View File
@@ -8,36 +8,17 @@
dust
eza
fd
fastfetch
fzf
htop
jq
lsof
nurl
ripgrep
tio
unrar
unzip
wget
]
++ lib.optionals stdenv.isLinux [
lm_sensors
psmisc
strace
];
home.activation.generateSshKey = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
key="$HOME/.ssh/id_ed25519"
if [ ! -f "$key" ]; then
umask 077
mkdir -p "$HOME/.ssh"
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
echo "Generated SSH key at $key"
fi
'';
};
}
+1 -8
View File
@@ -2,17 +2,10 @@
description = "Cross-platform interactive command-line environment";
includes = [
"applications.btop"
"applications.direnv"
"applications.git"
"applications.gnupg"
"applications.nh"
"profiles.interface.minimal"
"applications.nix-index"
"applications.ssh"
"applications.vim"
"applications.yazi"
"applications.zellij"
"applications.zoxide"
"applications.zsh"
];
}
@@ -0,0 +1,8 @@
{ pkgs, ... }:
{
home.packages = with pkgs; [
fastfetch
unzip
wget
];
}
@@ -0,0 +1,16 @@
{
description = "Minimal cross-platform command-line environment for remote administration";
includes = [
"applications.btop"
"applications.direnv"
"applications.git"
"applications.gnupg"
"applications.htop"
"applications.nano"
"applications.nh"
"applications.ssh"
"applications.zellij"
"applications.zsh"
];
}