6 Commits
Author SHA1 Message Date
Renovate Bot 20606d09c7 chore(deps): lock file maintenance 2026-07-18 19:01:25 +00:00
moons-14 b2283ba328 nix cache
NixOS CI / Validate flake (push) Has been cancelled
Publish Nix cache / Build and publish uncached paths (push) Has been cancelled
NixOS CI / Build ${{ matrix.host }} (push) Has been cancelled
NixOS CI / Report main status (push) Has been cancelled
2026-07-18 20:09:04 +09:00
moons-14 1e38d17dba grok
NixOS CI / Validate flake (push) Has been cancelled
NixOS CI / Build ${{ matrix.host }} (push) Has been cancelled
NixOS CI / Report main status (push) Has been cancelled
2026-07-18 19:52:38 +09:00
moons-14 e67dd6a791 grok 2026-07-18 19:07:47 +09:00
moons-14 0c6b2f41b9 vicinae
NixOS CI / Validate flake (push) Has been cancelled
NixOS CI / Build ${{ matrix.host }} (push) Has been cancelled
NixOS CI / Report main status (push) Has been cancelled
2026-07-18 19:05:30 +09:00
moons-14 1091e790db Merge pull request #35 from moons-14/renovate/lock-file-maintenance-nix-flake-inputs
chore(deps): lock file maintenance
2026-07-18 19:04:08 +09:00
14 changed files with 230 additions and 44 deletions
+64
View File
@@ -0,0 +1,64 @@
name: Publish Nix cache
on:
push:
branches:
- main
workflow_dispatch:
permissions:
contents: write
packages: write
concurrency:
group: publish-nixcache-${{ github.ref }}
cancel-in-progress: false
jobs:
publish:
name: Build and publish uncached paths
runs-on: ubuntu-latest
timeout-minutes: 180
steps:
- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: true
- name: Install Nix
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
with:
extra_nix_config: |
experimental-features = nix-command flakes
accept-flake-config = true
access-tokens = github.com=${{ github.token }}
- name: Configure cache signing
env:
NIX_SIGNING_KEY: ${{ secrets.NIX_SIGNING_KEY }}
run: |
set -euo pipefail
test -n "$NIX_SIGNING_KEY" || {
echo "NIX_SIGNING_KEY is required; refusing to publish unsigned cache paths." >&2
exit 1
}
signing_key="$RUNNER_TEMP/nixcache-signing-key"
umask 077
printf '%s' "$NIX_SIGNING_KEY" > "$signing_key"
nix key convert-secret-to-public < "$signing_key" > nixcache-public-key.txt
echo "NIXCACHE_SIGNING_KEY_FILE=$signing_key" >> "$GITHUB_ENV"
- name: Commit cache public key
run: |
set -euo pipefail
if git diff --quiet -- nixcache-public-key.txt; then
exit 0
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add nixcache-public-key.txt
git commit -m "chore: publish Nix cache signing key"
git push
- name: Build and publish uncached store paths
env:
GITHUB_TOKEN: ${{ github.token }}
NIXCACHE_REPO: ${{ github.repository }}
NIXCACHE_CONFIG_DIR: .
run: |
set -euo pipefail
nixcache_source="$(nix flake archive --json --no-write-lock-file github:cmspam/nixcache-oci/fb6006b5575da494dbbfc582e841d976ec06be6e | jq -r .path)"
source "$nixcache_source/lib/cache-builder.sh"
full_pipeline
+21
View File
@@ -179,6 +179,27 @@ sudo nixos-rebuild switch --flake .#<host> # Apply config
sudo nixos-rebuild build --flake .#<host> # Build without applying
```
## Nix Binary Cache
All normal hosts run `nixcache-oci` as a local proxy for
`ghcr.io/moons-14/dotfiles/nix-cache`. The `Publish Nix cache` workflow builds
the flake on pushes to `main` and uploads only store paths that were built by
the runner rather than substituted from an existing cache. Nix still uses the
official cache and configured Cachix caches for all other paths.
The cache must remain public and signed:
1. Generate a signing key outside this repository and save its contents as the
`NIX_SIGNING_KEY` GitHub Actions secret.
2. Run the `Publish Nix cache` workflow. It commits `nixcache-public-key.txt`,
which clients trust on their next configuration rebuild.
3. In GitHub Packages, make the `nix-cache` container package public.
```sh
nix key generate-secret > /tmp/nixcache-signing-key
# Copy the contents into the NIX_SIGNING_KEY GitHub Actions secret, then delete the local file.
```
## Inspired
- [Zaney/zaneyos](https://gitlab.com/Zaney/zaneyos)
Generated
+60 -39
View File
@@ -109,11 +109,11 @@
]
},
"locked": {
"lastModified": 1784217612,
"narHash": "sha256-3eDYR0AXcEtEyPzwNik4vUl5/V2LwANjroECkaEHGAw=",
"lastModified": 1784389652,
"narHash": "sha256-LRnL+bLyHwyaOVwM3p1UZOAeFlwsWAXdhmbJCIXX2e4=",
"owner": "ilysenko",
"repo": "codex-desktop-linux",
"rev": "481fc5e116d22c4b56b275d3b530a885434b6b89",
"rev": "bf6e6be58f7fbf1ea90a2a27ebbff12c4989e5a1",
"type": "github"
},
"original": {
@@ -397,11 +397,11 @@
"nixpkgs": "nixpkgs_2"
},
"locked": {
"lastModified": 1783008725,
"narHash": "sha256-jGiy6+sxjNWXSjp25uoJuNfyH9zBK1PEDY0lVoL4ibQ=",
"lastModified": 1784288435,
"narHash": "sha256-ReRHaLgr/uVqdD8afFSn+myXIfpHeOhP0yYe0TJqAA8=",
"owner": "cachix",
"repo": "git-hooks.nix",
"rev": "bca82caa46d5ec0f5d422c61fb1e30bc51313cbe",
"rev": "43b3c1ab9d40fb1dbb008f451988a91e375825e9",
"type": "github"
},
"original": {
@@ -455,11 +455,11 @@
]
},
"locked": {
"lastModified": 1783740085,
"narHash": "sha256-qajyHfZY29G2oEQk+uHxmsJcRoBUBXP9maTpFlwP/dI=",
"lastModified": 1784350909,
"narHash": "sha256-ZWyzLbS1yKUTeFJLmdVuWNnHttL333/ldJbEE+KzCrM=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "3cd22efe6471dc7365c822bd9ad73a21e55f38fb",
"rev": "4ce190229c73d44536caa7072f6308fb2d8feeb3",
"type": "github"
},
"original": {
@@ -524,11 +524,11 @@
"treefmt-nix": "treefmt-nix"
},
"locked": {
"lastModified": 1784195636,
"narHash": "sha256-5X0Ivp0ClcTUH8nAqLhxWuWxgZ6QTd+s+xOpgQqucgk=",
"lastModified": 1784363791,
"narHash": "sha256-p9LRSnyqaiaOItDf3rMjWxlPsmLO7YhgBg4zd6nB0lA=",
"owner": "numtide",
"repo": "llm-agents.nix",
"rev": "45b0a359630126c84b1685bacf986cf7ddbb57a7",
"rev": "a76249be5f5c1ce95c3a0e74930cb015d66718a0",
"type": "github"
},
"original": {
@@ -547,11 +547,11 @@
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
},
"locked": {
"lastModified": 1784189744,
"narHash": "sha256-D8oh9imibOynWAOUnvgG3w2EKDYqf8OTTaLCcTA4ePg=",
"lastModified": 1784380193,
"narHash": "sha256-XnpNipcSNWg+l9aHV/Ha3W1ot/r5FC7OT3//zZ9Vjbs=",
"owner": "sodiboo",
"repo": "niri-flake",
"rev": "f4b479398c967d2c8d5a38b6d2c87283ae5078c4",
"rev": "26e0cddf2447ab5ec0824b1c9a076aa1480fc57a",
"type": "github"
},
"original": {
@@ -634,16 +634,36 @@
"type": "github"
}
},
"nixcache-oci": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1784393281,
"narHash": "sha256-dlj3uQdaSpJzCxATrfGRlEX3i0UMbk2H0eVJdO2hTZY=",
"owner": "cmspam",
"repo": "nixcache-oci",
"rev": "7db80f3bc7e63645f655e6c66578088ffe4a1f97",
"type": "github"
},
"original": {
"owner": "cmspam",
"repo": "nixcache-oci",
"type": "github"
}
},
"nixos-hardware": {
"inputs": {
"nixpkgs": "nixpkgs_4"
},
"locked": {
"lastModified": 1784100666,
"narHash": "sha256-HF/mrw5NYQfKFZgkfV2h1UL5/E3ccfsE2XJ1AbbLLJ0=",
"lastModified": 1784310968,
"narHash": "sha256-rkSPTePrKqs4dg+i7ZFCq93+HrClac6oSwXX927SVjA=",
"owner": "NixOS",
"repo": "nixos-hardware",
"rev": "fccfa9031a85b78a437f2f153c1f6449f3bc3185",
"rev": "779c32a00155994c86cde8213a8dd4df139d4355",
"type": "github"
},
"original": {
@@ -734,11 +754,11 @@
},
"nixpkgs-unstable": {
"locked": {
"lastModified": 1784115452,
"narHash": "sha256-BoYPdqk6jlKXy+DyUzyGV/CtRGfAhk2MmIgBhsemTGI=",
"lastModified": 1784364478,
"narHash": "sha256-CdItYNdYUlm7NxqMVyQKqT2IxTwvapiPuRLWOyHTrbY=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "35d3407a3816f3b341d8cf1d60abaf2b7b8166ac",
"rev": "20535e48e12c86043b577b8518234ff5dbb26957",
"type": "github"
},
"original": {
@@ -766,11 +786,11 @@
},
"nixpkgs_3": {
"locked": {
"lastModified": 1784120854,
"narHash": "sha256-KesHgItiZPgGX740axSiQLcIQ8D24MDqNpkKYWIek8k=",
"lastModified": 1784356753,
"narHash": "sha256-12KrbMiWLcf8m7pCvAtZh1ZrgF85ZXDXvfR/fWTKy84=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "753cc8a3a87467296ddd1fa93f0cc3e81120ee46",
"rev": "61b7c44c4073f0b827768aff0049561b5110ea5a",
"type": "github"
},
"original": {
@@ -811,11 +831,11 @@
},
"nixpkgs_6": {
"locked": {
"lastModified": 1784160687,
"narHash": "sha256-iYL/bixrb6FlHFu/gIuBYzq6c6lM5AAXsXNSWXtIgQc=",
"lastModified": 1784280462,
"narHash": "sha256-DtoqIqM7VkR6NxAkcLpMwmi02USwWb3JdmNGLyhthc0=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "4382ed2b7a6839d4280a9b386db49cbc5907414d",
"rev": "293d6abedf0478e681a4dfcfcb35b30fc796a32f",
"type": "github"
},
"original": {
@@ -903,11 +923,11 @@
]
},
"locked": {
"lastModified": 1784228267,
"narHash": "sha256-h05DrwpzaUnxSc09F8p+VVzITzcbiorB6dmGjjQLzyU=",
"lastModified": 1784390676,
"narHash": "sha256-d6YSbdMQM3A3+X0BU7NFX506U/CaRgyh2Jwe9WhiBg0=",
"owner": "noctalia-dev",
"repo": "noctalia",
"rev": "b86e4a0964744915ed2970d28fc86580b6332696",
"rev": "5a20c9cf0ecc398c9391aa52ac075a0401f720c9",
"type": "github"
},
"original": {
@@ -976,6 +996,7 @@
"niri-flake": "niri-flake",
"nix-hazkey": "nix-hazkey",
"nix-index-database": "nix-index-database",
"nixcache-oci": "nixcache-oci",
"nixos-hardware": "nixos-hardware",
"nixos-wsl": "nixos-wsl",
"nixpkgs": "nixpkgs_6",
@@ -1310,11 +1331,11 @@
"nixpkgs": "nixpkgs_7"
},
"locked": {
"lastModified": 1780220602,
"narHash": "sha256-eynAfOmbmxJnkp7YewvCEbShNnnYJ9gLLqkzsYtBPeM=",
"lastModified": 1784369104,
"narHash": "sha256-47cxbcZODibHv3rELFQ9vZly0vUNkND/atn/U7HLeb0=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "db947814a175b7ca6ded66e21383d938df01c227",
"rev": "df3c0640565d04a0261253cdd89fce78ec50168a",
"type": "github"
},
"original": {
@@ -1330,11 +1351,11 @@
"systems": "systems_7"
},
"locked": {
"lastModified": 1784226203,
"narHash": "sha256-wyjmwA0i0t0KBH/LPNFh/NMvMYsHgflkQMn+JOWGd4k=",
"lastModified": 1784388228,
"narHash": "sha256-/5fGvMWlLlyd5ibK7y1dqIK1MTpLABj3v1M0r/VArww=",
"owner": "vicinaehq",
"repo": "vicinae",
"rev": "6ff786a409d440015a94456d9583b9e60d979aa3",
"rev": "c55e85716e3e7a68f4b0f6ef6299d02a49623c7c",
"type": "github"
},
"original": {
@@ -1353,11 +1374,11 @@
"vicinae": "vicinae_2"
},
"locked": {
"lastModified": 1783009133,
"narHash": "sha256-Non+frT3WG0TN60zCq63m8+d7yNmCCMaI363kZaDmPM=",
"lastModified": 1784400781,
"narHash": "sha256-awe35tis3VZCfQVhivpduehT/5IV5LHmOsd2YSxECRQ=",
"owner": "vicinaehq",
"repo": "extensions",
"rev": "afb84fe4b5253777ff82db8e19e6cc0c9b7f811f",
"rev": "67beba7a8e79b817552e4a95f835b8cc697ca08b",
"type": "github"
},
"original": {
+6
View File
@@ -92,6 +92,12 @@
inputs.nixpkgs.follows = "nixpkgs";
};
# Binary cache
nixcache-oci = {
url = "github:cmspam/nixcache-oci";
inputs.nixpkgs.follows = "nixpkgs";
};
# Systems
systems.url = "github:nix-systems/default-linux";
+5 -1
View File
@@ -6,6 +6,10 @@
}:
let
cfg = config.my.applications.grok;
grok = pkgs.llm-agents.grok.overrideAttrs (_old: {
versionCheckProgram = "${placeholder "out"}/libexec/grok/grok-launcher";
});
in
{
options.my.applications.grok = {
@@ -14,7 +18,7 @@ in
config = lib.mkIf cfg.enable {
environment.systemPackages = [
pkgs.llm-agents.grok # Grok AI CLI
grok
];
};
}
+1 -1
View File
@@ -34,7 +34,7 @@ in
Service = {
Type = "forking";
ExecStart = "${lib.getExe pkgs.swaylock} -f";
ExecStart = "${lib.getExe pkgs.swaylock} -f -i %h/.wallpapers/28.jpg";
Restart = "on-failure";
RestartSec = 0;
};
+1 -3
View File
@@ -14,8 +14,6 @@ in
config = lib.mkIf cfg.enable {
services.systemd-lock-handler.enable = true;
# Screen unlocking deliberately uses passwords only. Fingerprints remain
# available to explicitly enabled PAM services such as sudo and polkit.
security.pam.services.swaylock.fprintAuth = false;
security.pam.services.swaylock.fprintAuth = true;
};
}
+5
View File
@@ -53,6 +53,11 @@ in
extensions = with inputs.vicinae-extensions.packages.${pkgs.stdenv.hostPlatform.system}; [
nix
power-profile
niri
zoxide-recent-directories
ssh
port-killer
noctalia-shell-wallpaper-selector
];
};
}
+18
View File
@@ -12,6 +12,24 @@ in
};
config = lib.mkIf cfg.enable {
home-manager.sharedModules = [
{
xdg.userDirs = {
enable = true;
createDirectories = true;
desktop = "$HOME/Desktop";
documents = "$HOME/Documents";
download = "$HOME/Downloads";
music = "$HOME/Music";
pictures = "$HOME/Pictures";
projects = "$HOME/Projects";
publicShare = "$HOME/Public";
templates = "$HOME/Templates";
videos = "$HOME/Videos";
};
}
];
my.applications = {
gnome.enable = true;
gtk.enable = true;
+1
View File
@@ -2,6 +2,7 @@
imports = [
./container.nix
./kde.nix
./nixcache-oci.nix
./quem-guest.nix
];
}
@@ -0,0 +1,17 @@
{
lib,
config,
...
}:
let
cfg = config.my.features.services.nixcacheOci;
in
{
options.my.features.services.nixcacheOci = {
enable = lib.mkEnableOption "Nix binary cache backed by public GHCR";
};
config = lib.mkIf cfg.enable {
my.system.nixcacheOci.enable = true;
};
}
+3
View File
@@ -1,3 +1,4 @@
{ inputs, ... }:
{
imports = [
./audio.nix
@@ -11,6 +12,7 @@
./locale.nix
./network
./nix.nix
./nixcache-oci.nix
./power.nix
./quem.nix
./secure-boot.nix
@@ -18,5 +20,6 @@
./user
./version.nix
./secret.nix
inputs.nixcache-oci.nixosModules.default
];
}
+27
View File
@@ -0,0 +1,27 @@
{
lib,
config,
...
}:
let
cfg = config.my.system.nixcacheOci;
publicKeyFile = ../../nixcache-public-key.txt;
publicKey =
if builtins.pathExists publicKeyFile then
lib.strings.trim (builtins.readFile publicKeyFile)
else
"";
in
{
options.my.system.nixcacheOci = {
enable = lib.mkEnableOption "Nix binary cache backed by the public GitHub Container Registry";
};
config = lib.mkIf cfg.enable {
services.nixcache-proxy = {
enable = true;
repo = "moons-14/dotfiles";
inherit publicKey;
};
};
}
+1
View File
@@ -5,5 +5,6 @@
shell.enable = true;
};
identity.sshDefaultKey.enable = true;
services.nixcacheOci.enable = true;
};
}