diff --git a/AGENTS.md b/AGENTS.md index b163b8e..f283c1d 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -368,6 +368,7 @@ modules/profiles/ │ └── vm/ ├── workload/ │ ├── camera/ +│ ├── deploy-rs-target/ │ ├── development/ │ ├── game/ │ ├── machine-learning/ diff --git a/hosts/nix-builder/nixos.nix b/hosts/nix-builder/nixos.nix index 801bc3e..80217ba 100644 --- a/hosts/nix-builder/nixos.nix +++ b/hosts/nix-builder/nixos.nix @@ -2,5 +2,6 @@ imports = [ ./disko.nix ./hardware-configuration.nix + ./harmonia.nix ]; } diff --git a/modules/profiles/README.md b/modules/profiles/README.md index b06e023..0529f9c 100644 --- a/modules/profiles/README.md +++ b/modules/profiles/README.md @@ -36,6 +36,7 @@ required on every supported host. | `platform.laptop` | Physical NixOS laptop | | `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS | | `platform.vm` | UEFI QEMU NixOS guest with NFS client support | +| `workload.deploy-rs-target` | NixOS | | `workload.development` | NixOS, macOS with Home Manager | | `workload.game` | NixOS, macOS | | `workload.machine-learning` | NixOS with Home Manager | @@ -63,6 +64,10 @@ support does not implicitly select an interface or workload. `workload.machine-learning` provides the Hugging Face Hub CLI for hosts used to download and publish machine learning models and datasets. +`workload.deploy-rs-target` enables OpenSSH and provisions the `nixdeploy` +service account with the narrowly scoped passwordless commands required for +deploy-rs activation and rollback confirmation. + `workload.personal` provides Pear Desktop on both NixOS and macOS. Home Manager enables performance improvements, synced lyrics, tracker blocking, the album color theme, and custom output-device selection while preserving user-owned diff --git a/modules/systems/nix/common.nix b/modules/systems/nix/common.nix index 885b83a..8f1bdbd 100644 --- a/modules/systems/nix/common.nix +++ b/modules/systems/nix/common.nix @@ -7,6 +7,10 @@ "flakes" ]; + extra-allowed-users = [ + "nixdeploy" + ]; + connect-timeout = 10; extra-substituters = [ @@ -31,6 +35,7 @@ "niks3.numtide.com-1:DTx8wZduET09hRmMtKdQDxNNthLQETkc/yaX7M4qK0g=" "codex-desktop-linux.cachix.org-1:nX/xy6AdK9hQE24A8ALGjkCKj2ObFmcnemiL5Cid4nk=" "cuda-maintainers.cachix.org-1:0dq3bujKpuEPMCX6U4WylrUDZ9JyUG0VpVZa7CNfq5E=" + "nix-builder-1:nix-builder-1:aG/Y2Lac517isxGO+ZYdVgglj/SI54PkkWoZTQI9aOI=" ]; }; }