This commit is contained in:
2026-07-27 20:55:05 +09:00
parent a8e9a4dce5
commit fcd0d75537
46 changed files with 226 additions and 112 deletions
+10 -4
View File
@@ -7,10 +7,13 @@
profiles = [ profiles = [
"base" "base"
"interface.gui" "interface.cli"
"platform.thinkpad" "interface.gnome"
"interface.niri"
"networking.tailscale-client"
"platform.thinkpad-x1"
"security.secrets"
"workload.personal" "workload.personal"
"workload.tailscale.client"
]; ];
}; };
@@ -22,7 +25,10 @@
profiles = [ profiles = [
"base" "base"
"interface.cli-minimal" "interface.cli"
"security.secrets"
]; ];
units = [ "systems.fingerprint" ];
}; };
} }
+6
View File
@@ -0,0 +1,6 @@
{
homebrew = {
enable = true;
casks = [ "google-chrome" ];
};
}
+2 -2
View File
@@ -1,4 +1,4 @@
{ pkgs, ... }: { lib, pkgs, ... }:
{ lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
home.packages = [ pkgs.google-chrome ]; home.packages = [ pkgs.google-chrome ];
} }
+6
View File
@@ -0,0 +1,6 @@
{
homebrew = {
enable = true;
casks = [ "vesktop" ];
};
}
+2 -1
View File
@@ -1,3 +1,4 @@
{ { lib, pkgs, ... }:
lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
programs.vesktop.enable = true; programs.vesktop.enable = true;
} }
+6
View File
@@ -0,0 +1,6 @@
{
homebrew = {
enable = true;
casks = [ "drawio" ];
};
}
+4
View File
@@ -0,0 +1,4 @@
{ lib, pkgs, ... }:
lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
home.packages = [ pkgs.drawio ];
}
+6
View File
@@ -0,0 +1,6 @@
{
homebrew = {
enable = true;
casks = [ "slack" ];
};
}
+2 -2
View File
@@ -1,4 +1,4 @@
{ pkgs, ... }: { lib, pkgs, ... }:
{ lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
home.packages = [ pkgs.slack ]; home.packages = [ pkgs.slack ];
} }
+6
View File
@@ -0,0 +1,6 @@
{
homebrew = {
enable = true;
casks = [ "zoom" ];
};
}
+2 -2
View File
@@ -1,4 +1,4 @@
{ pkgs, ... }: { lib, pkgs, ... }:
{ lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
home.packages = [ pkgs.zoom-us ]; home.packages = [ pkgs.zoom-us ];
} }
+53
View File
@@ -0,0 +1,53 @@
# Profiles
Profiles are host-selectable compositions of independently owned units. They
describe why a group of units is enabled; application, service, system, and
hardware configuration remains in its owning unit.
## Layers
| Namespace | Purpose | Compatibility |
| ------------ | ------------------------------------------------------- | --------------- |
| `base` | Invariants required by every host | NixOS and macOS |
| `interface` | Command-line and graphical ways to operate a host | Per-profile |
| `platform` | NixOS foundation and physical or virtual hardware shape | NixOS |
| `workload` | Optional activities performed on a host | Per-profile |
| `networking` | Network roles and topology | Per-profile |
| `security` | Optional security and secret-management policies | Per-profile |
`base` intentionally contains only `systems.nix`. A unit belongs there only
when removing it from any supported host would make that host invalid.
## Compatibility
| Profile | Supported host class |
| ------------------------------------ | ------------------------------------- |
| `base` | NixOS, macOS |
| `interface.cli` | NixOS, macOS with Home Manager |
| `interface.linux-desktop` | NixOS with Home Manager |
| `interface.gnome` | NixOS with Home Manager |
| `interface.niri` | NixOS with Home Manager |
| `platform.nixos` | NixOS |
| `platform.desktop` | Physical NixOS desktop |
| `platform.laptop` | Physical NixOS laptop |
| `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS |
| `platform.vm` | QEMU NixOS guest |
| `workload.development` | NixOS, macOS with Home Manager |
| `workload.personal` | NixOS, macOS with Home Manager |
| `workload.remote-access` | NixOS, macOS |
| `workload.server` | NixOS, macOS with Home Manager |
| `networking.tailscale-client` | NixOS, macOS |
| `networking.tailscale-subnet-router` | NixOS |
| `security.secrets` | NixOS, macOS |
| `security.secure-boot` | NixOS |
| `security.tpm-storage` | NixOS with a host-defined LUKS device |
Select independent concerns independently in `hosts/default.nix`. For example,
a NixOS laptop can combine `base`, `platform.thinkpad-x1`,
`interface.cli`, and `interface.niri`, while a macOS host can combine
`base`, `interface.cli`, and cross-platform workloads. A graphical profile does
not implicitly select a CLI profile or personal applications.
`security.tpm-storage` deliberately does not own a disk identifier. A host that
selects it must define `boot.initrd.luks.devices.cryptroot.device` in its
machine-specific NixOS module.
+2 -10
View File
@@ -1,13 +1,5 @@
{ {
description = "base system configuration"; description = "Host-independent Nix foundation required everywhere";
includes = [ includes = [ "systems.nix" ];
"systems.boot.base"
"systems.disko"
"systems.hardware"
"systems.locale"
"systems.networking.base"
"systems.nix"
"systems.sops"
];
} }
@@ -1,4 +0,0 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.tio ];
}
@@ -1,10 +0,0 @@
{
description = "interactive command-line environment";
includes = [
"profiles.interface.cli-minimal"
"applications.vim"
"applications.yazi"
"applications.zellij"
];
}
@@ -12,6 +12,7 @@
jq jq
nurl nurl
ripgrep ripgrep
tio
unrar unrar
unzip unzip
wget wget
@@ -1,5 +1,5 @@
{ {
description = "minimal command-line environment"; description = "Cross-platform interactive command-line environment";
includes = [ includes = [
"applications.btop" "applications.btop"
@@ -9,6 +9,9 @@
"applications.nh" "applications.nh"
"applications.nix-index" "applications.nix-index"
"applications.ssh" "applications.ssh"
"applications.vim"
"applications.yazi"
"applications.zellij"
"applications.zoxide" "applications.zoxide"
"applications.zsh" "applications.zsh"
]; ];
@@ -0,0 +1,8 @@
{
description = "GNOME desktop session for NixOS";
includes = [
"profiles.interface.linux-desktop"
"applications.gnome"
];
}
-23
View File
@@ -1,23 +0,0 @@
{
description = "NixOS graphical desktop environment";
includes = [
"profiles.interface.cli-interactive"
"applications.1password"
"applications.fcitx5"
"applications.ghostty"
"applications.gnome"
"applications.gtk"
"applications.kde"
"applications.nautilus"
"applications.niri"
"applications.noctalia"
"applications.vicinae"
"hardwares.graphics"
"services.ly"
"services.swayidle"
"services.swaylock"
"systems.audio"
"systems.fonts"
];
}
@@ -0,0 +1,14 @@
{
description = "Shared NixOS graphical desktop foundation";
includes = [
"applications.fcitx5"
"applications.ghostty"
"applications.gtk"
"applications.nautilus"
"applications.vicinae"
"hardwares.graphics"
"systems.audio"
"systems.fonts"
];
}
+12
View File
@@ -0,0 +1,12 @@
{
description = "niri desktop session for NixOS";
includes = [
"profiles.interface.linux-desktop"
"applications.niri"
"applications.noctalia"
"services.ly"
"services.swayidle"
"services.swaylock"
];
}
@@ -0,0 +1,5 @@
{
description = "Tailscale client for NixOS and macOS";
includes = [ "services.tailscale" ];
}
@@ -0,0 +1,5 @@
{
description = "Tailscale subnet router for NixOS";
includes = [ "services.tailscale" ];
}
+6 -2
View File
@@ -1,5 +1,9 @@
{ {
description = "UEFI desktop platform"; description = "Physical NixOS desktop";
includes = [ "systems.boot.uefi" ]; includes = [
"profiles.platform.nixos"
"systems.boot.uefi"
"systems.hardware"
];
} }
+3 -3
View File
@@ -1,11 +1,11 @@
{ {
description = "laptop platform configuration"; description = "Physical NixOS laptop";
includes = [ includes = [
"profiles.platform.nixos"
"hardwares.bluetooth" "hardwares.bluetooth"
"hardwares.ipu6-camera"
"systems.boot.uefi" "systems.boot.uefi"
"systems.fingerprint" "systems.hardware"
"systems.networking.wifi" "systems.networking.wifi"
"systems.power" "systems.power"
]; ];
+9
View File
@@ -0,0 +1,9 @@
{
description = "Foundation shared by all NixOS platforms";
includes = [
"systems.boot.base"
"systems.locale"
"systems.networking.base"
];
}
@@ -0,0 +1,10 @@
{
description = "Intel ThinkPad X1 laptop hardware";
includes = [
"profiles.platform.laptop"
"hardwares.intel-driver"
"hardwares.ipu6-camera"
"systems.fingerprint"
];
}
@@ -1,8 +0,0 @@
{
description = "ThinkPad laptop platform";
includes = [
"profiles.platform.laptop"
"hardwares.intel-driver"
];
}
+2 -3
View File
@@ -1,9 +1,8 @@
{ {
description = "virtual-machine platform"; description = "QEMU NixOS guest";
includes = [ includes = [
"profiles.platform.nixos"
"hardwares.qemu-guest" "hardwares.qemu-guest"
"systems.boot.nfs"
"systems.boot.uefi"
]; ];
} }
@@ -0,0 +1,5 @@
{
description = "Cross-platform SOPS and age secret management";
includes = [ "systems.sops" ];
}
@@ -0,0 +1,5 @@
{
description = "Secure Boot for NixOS";
includes = [ "systems.boot.secure-boot" ];
}
@@ -0,0 +1,5 @@
{
description = "TPM-backed LUKS unlock for NixOS";
includes = [ "systems.boot.storage-crypto" ];
}
+8 -11
View File
@@ -1,13 +1,10 @@
{ lib, pkgs, ... }: { pkgs, ... }:
{ {
home.packages = home.packages = with pkgs; [
with pkgs; bind
[ bun
bind nil
bun python312
nil uv
python312 ];
uv
]
++ lib.optionals stdenv.hostPlatform.isLinux [ drawio ];
} }
@@ -1,5 +1,5 @@
{ {
description = "software development workload"; description = "Cross-platform software development environment";
includes = [ includes = [
"applications.arduino" "applications.arduino"
@@ -7,6 +7,7 @@
"applications.codex" "applications.codex"
"applications.codex-desktop" "applications.codex-desktop"
"applications.docker" "applications.docker"
"applications.drawio"
"applications.grok" "applications.grok"
"applications.java" "applications.java"
"applications.opencode" "applications.opencode"
+3 -1
View File
@@ -1,9 +1,11 @@
{ {
description = "personal communication and browser workload"; description = "Cross-platform personal desktop applications";
includes = [ includes = [
"applications.1password"
"applications.chrome" "applications.chrome"
"applications.discord" "applications.discord"
"applications.kde"
"applications.slack" "applications.slack"
"applications.zoom" "applications.zoom"
]; ];
@@ -0,0 +1,5 @@
{
description = "Cross-platform remote shell access";
includes = [ "services.openssh" ];
}
@@ -1,5 +0,0 @@
{
description = "remote-access workload";
includes = [ "services.openssh" ];
}
@@ -1,8 +0,0 @@
{
description = "secure boot and TPM-backed storage";
includes = [
"systems.boot.secure-boot"
"systems.boot.storage-crypto"
];
}
+1 -1
View File
@@ -1,5 +1,5 @@
{ {
description = "server workload"; description = "Cross-platform container and remote-access server";
includes = [ includes = [
"applications.docker" "applications.docker"
@@ -1,5 +0,0 @@
{
description = "Tailscale client";
includes = [ "services.tailscale" ];
}
@@ -1,5 +0,0 @@
{
description = "Tailscale subnet-router server";
includes = [ "services.tailscale" ];
}
+6
View File
@@ -0,0 +1,6 @@
{
security.pam.services.sudo_local = {
touchIdAuth = true;
reattach = true;
};
}