Add central Nix builder and binary cache

This commit is contained in:
2026-08-31 08:07:48 +09:00
parent fda29cd08d
commit ec3770502d
21 changed files with 438 additions and 39 deletions
+10
View File
@@ -39,10 +39,12 @@ required on every supported host.
| `workload.development` | NixOS, macOS with Home Manager |
| `workload.game` | NixOS, macOS |
| `workload.machine-learning` | NixOS with Home Manager |
| `workload.nix-builder` | NixOS central build and binary-cache VM |
| `workload.personal` | NixOS, macOS with Home Manager |
| `workload.remote-access` | NixOS, macOS |
| `workload.camera` | NixOS |
| `workload.server` | NixOS, macOS with Home Manager |
| `networking.homelab-cache-client` | NixOS, macOS with access to nix-builder |
| `networking.tailscale-client` | NixOS, macOS |
| `networking.tailscale-subnet-router` | NixOS |
| `security.fingerprint` | NixOS, macOS |
@@ -63,6 +65,14 @@ support does not implicitly select an interface or workload.
`workload.machine-learning` provides the Hugging Face Hub CLI for hosts used
to download and publish machine learning models and datasets.
`workload.nix-builder` provides the central build policy, persistent fleet GC
roots, deploy-rs tooling, SOPS integration, and Harmonia binary cache. Network
reachability and remote shell access remain independent host selections.
`networking.homelab-cache-client` adds the internal Harmonia substituter and
its trusted public key. It requires the public key generated during
`hosts/nix-builder/README.md` bootstrap.
`workload.personal` provides Pear Desktop on both NixOS and macOS. Home Manager
enables performance improvements, synced lyrics, tracker blocking, the album
color theme, and custom output-device selection while preserving user-owned
@@ -0,0 +1,5 @@
{
description = "Use the homelab Harmonia binary cache";
includes = [ "systems.nix.homelab-cache" ];
}
@@ -0,0 +1,6 @@
{
sops.secrets."users/moons/hashedPassword" = {
sopsFile = ../../../secrets/common/system.yaml;
neededForUsers = true;
};
}
@@ -0,0 +1,10 @@
{
description = "Central Nix builder, deploy controller, and binary cache";
includes = [
"applications.nix-fleet"
"services.harmonia"
"systems.nix.build-server"
"systems.sops"
];
}