9 Commits
Author SHA1 Message Date
moons-14 85a4458376 nix update
NixOS CI / Validate flake (push) Has been cancelled
NixOS CI / Build ${{ matrix.host }} (push) Has been cancelled
NixOS CI / Report main status (push) Has been cancelled
2026-07-21 18:37:22 +09:00
moons-14 b60a840a3d update 2026-07-21 18:34:15 +09:00
moons-14 e1c9beb362 remove nix pkg oci 2026-07-21 18:34:14 +09:00
moons-14 45957d0b40 waylock fingerprint 2026-07-21 18:34:05 +09:00
moons-14 455512ec8a zed 2026-07-21 18:34:04 +09:00
moons-14 754af0a68a Merge pull request #39 from moons-14/renovate/actions-checkout-7.x
chore(deps): update actions/checkout action to v7.0.1
2026-07-21 18:28:54 +09:00
moons-14 475b1432d0 Merge pull request #40 from moons-14/renovate/renovatebot-github-action-46.x
chore(deps): update renovatebot/github-action action to v46.1.20
2026-07-21 18:28:41 +09:00
Renovate Bot e51480e692 chore(deps): update renovatebot/github-action action to v46.1.20 2026-07-20 19:41:45 +00:00
Renovate Bot e09d2d525f chore(deps): update actions/checkout action to v7.0.1 2026-07-20 19:41:42 +00:00
13 changed files with 70 additions and 220 deletions
+2 -2
View File
@@ -21,7 +21,7 @@ jobs:
hosts: ${{ steps.hosts.outputs.hosts }}
steps:
- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install Nix
@@ -51,7 +51,7 @@ jobs:
host: ${{ fromJSON(needs.validate.outputs.hosts) }}
steps:
- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install Nix
-64
View File
@@ -1,64 +0,0 @@
name: Publish Nix cache
on:
push:
branches:
- main
workflow_dispatch:
permissions:
contents: write
packages: write
concurrency:
group: publish-nixcache-${{ github.ref }}
cancel-in-progress: false
jobs:
publish:
name: Build and publish uncached paths
runs-on: ubuntu-latest
timeout-minutes: 180
steps:
- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: true
- name: Install Nix
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
with:
extra_nix_config: |
experimental-features = nix-command flakes
accept-flake-config = true
access-tokens = github.com=${{ github.token }}
- name: Configure cache signing
env:
NIX_SIGNING_KEY: ${{ secrets.NIX_SIGNING_KEY }}
run: |
set -euo pipefail
test -n "$NIX_SIGNING_KEY" || {
echo "NIX_SIGNING_KEY is required; refusing to publish unsigned cache paths." >&2
exit 1
}
signing_key="$RUNNER_TEMP/nixcache-signing-key"
umask 077
printf '%s' "$NIX_SIGNING_KEY" > "$signing_key"
nix key convert-secret-to-public < "$signing_key" > nixcache-public-key.txt
echo "NIXCACHE_SIGNING_KEY_FILE=$signing_key" >> "$GITHUB_ENV"
- name: Commit cache public key
run: |
set -euo pipefail
if git diff --quiet -- nixcache-public-key.txt; then
exit 0
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add nixcache-public-key.txt
git commit -m "chore: publish Nix cache signing key"
git push
- name: Build and publish uncached store paths
env:
GITHUB_TOKEN: ${{ github.token }}
NIXCACHE_REPO: ${{ github.repository }}
NIXCACHE_CONFIG_DIR: .
run: |
set -euo pipefail
nixcache_source="$(nix flake archive --json --no-write-lock-file github:cmspam/nixcache-oci/fb6006b5575da494dbbfc582e841d976ec06be6e | jq -r .path)"
source "$nixcache_source/lib/cache-builder.sh"
full_pipeline
+2 -2
View File
@@ -16,12 +16,12 @@ jobs:
timeout-minutes: 60
steps:
- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# Use a PAT or GitHub App token so Renovate PRs trigger the other workflows.
- name: Run Renovate
uses: renovatebot/github-action@22e0a16091fc706b04affe6ae53d5e3358ac4023 # v46.1.19
uses: renovatebot/github-action@3064367f740a1a91cca218698a63902689cce200 # v46.1.20
with:
renovate-version: 43.262.1
token: ${{ secrets.RENOVATE_TOKEN }}
-21
View File
@@ -179,27 +179,6 @@ sudo nixos-rebuild switch --flake .#<host> # Apply config
sudo nixos-rebuild build --flake .#<host> # Build without applying
```
## Nix Binary Cache
All normal hosts run `nixcache-oci` as a local proxy for
`ghcr.io/moons-14/dotfiles/nix-cache`. The `Publish Nix cache` workflow builds
the flake on pushes to `main` and uploads only store paths that were built by
the runner rather than substituted from an existing cache. Nix still uses the
official cache and configured Cachix caches for all other paths.
The cache must remain public and signed:
1. Generate a signing key outside this repository and save its contents as the
`NIX_SIGNING_KEY` GitHub Actions secret.
2. Run the `Publish Nix cache` workflow. It commits `nixcache-public-key.txt`,
which clients trust on their next configuration rebuild.
3. In GitHub Packages, make the `nix-cache` container package public.
```sh
nix key generate-secret > /tmp/nixcache-signing-key
# Copy the contents into the NIX_SIGNING_KEY GitHub Actions secret, then delete the local file.
```
## Inspired
- [Zaney/zaneyos](https://gitlab.com/Zaney/zaneyos)
Generated
+51 -72
View File
@@ -109,11 +109,11 @@
]
},
"locked": {
"lastModified": 1784366441,
"narHash": "sha256-LRnL+bLyHwyaOVwM3p1UZOAeFlwsWAXdhmbJCIXX2e4=",
"lastModified": 1784620218,
"narHash": "sha256-XldpYvdtXF8ms+2k5XHywUroi3ultvNmx7TcaDz7faI=",
"owner": "ilysenko",
"repo": "codex-desktop-linux",
"rev": "cc610ca3f66a2aeacbcb9436c15ce5a8a84866d7",
"rev": "8e8cad33d6d040e3723ddc1c9b434a3aae186a25",
"type": "github"
},
"original": {
@@ -124,11 +124,11 @@
},
"crane": {
"locked": {
"lastModified": 1783203018,
"narHash": "sha256-G6R9IT/xwFuu+CYBWDUAok6AdC4ERC4ZfPPFtEpxnZE=",
"lastModified": 1784407669,
"narHash": "sha256-gcFMcRjw0ZSn380Rx2QLlU1goUQeSrKX/DF12omI6+o=",
"owner": "ipetkov",
"repo": "crane",
"rev": "80db5bdc391be8a1794f6d8a2d56e3a84ebcede2",
"rev": "1316b7d278ad77a16aec024b71d971366e123bec",
"type": "github"
},
"original": {
@@ -500,11 +500,11 @@
"rust-overlay": "rust-overlay"
},
"locked": {
"lastModified": 1783496806,
"narHash": "sha256-6B6CQUk1dPc8l/+otaGiYbuX8qeX/0VmSUQ+qSn0/uA=",
"lastModified": 1784568171,
"narHash": "sha256-t17AqLEhPG6m27ipkp8mJd8Ug0XkdANFDVsgyIFBZcQ=",
"owner": "nix-community",
"repo": "lanzaboote",
"rev": "6183ac79eadb079a1e72fa2c60915601be669100",
"rev": "f4b0aef3dba28677a5ca4b3416827aade60b5a0b",
"type": "github"
},
"original": {
@@ -524,11 +524,11 @@
"treefmt-nix": "treefmt-nix"
},
"locked": {
"lastModified": 1784363791,
"narHash": "sha256-p9LRSnyqaiaOItDf3rMjWxlPsmLO7YhgBg4zd6nB0lA=",
"lastModified": 1784615936,
"narHash": "sha256-DzPXJmiePXn0+G6t5/H8nqTNX/AT7KlzVrpL5LZe8OE=",
"owner": "numtide",
"repo": "llm-agents.nix",
"rev": "a76249be5f5c1ce95c3a0e74930cb015d66718a0",
"rev": "ba8c89d5b4836d46f7bdbffd2df34c66dadef725",
"type": "github"
},
"original": {
@@ -547,11 +547,11 @@
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
},
"locked": {
"lastModified": 1784189744,
"narHash": "sha256-D8oh9imibOynWAOUnvgG3w2EKDYqf8OTTaLCcTA4ePg=",
"lastModified": 1784578694,
"narHash": "sha256-UQtzks2t8ycyki7NCaSsp3Dy7Hcw5iCzPX5txnU5744=",
"owner": "sodiboo",
"repo": "niri-flake",
"rev": "f4b479398c967d2c8d5a38b6d2c87283ae5078c4",
"rev": "4d9088bdc07d20963be29821d5cf491edd9c8d25",
"type": "github"
},
"original": {
@@ -580,11 +580,11 @@
"niri-unstable": {
"flake": false,
"locked": {
"lastModified": 1783522755,
"narHash": "sha256-dI0HkX1djETia7cD/Y64h8BNIsSOfTRMzfNum2J6UhE=",
"lastModified": 1784570726,
"narHash": "sha256-9EMn69JBcFWFgUM7f0VBAX+jBby5b9H3M59U75+5yI4=",
"owner": "YaLTeR",
"repo": "niri",
"rev": "0777769e719b7c9b7c980d4ea66288bfbb4da5b3",
"rev": "7f26c3ee804fb6ed458ef7fb0e3c794f14e0b3bc",
"type": "github"
},
"original": {
@@ -621,11 +621,11 @@
]
},
"locked": {
"lastModified": 1783864904,
"narHash": "sha256-BQxN5UMg9FOevAsgBRwPxfxlh51Puj+dNn/8Dsi3sPM=",
"lastModified": 1784440659,
"narHash": "sha256-Q5kNLlWngt7TaIIZoxDKWMHjiSaNRVqr70FqWCRRfr4=",
"owner": "nix-community",
"repo": "nix-index-database",
"rev": "1111b9bc836afb7e31a7014e8d1272de9b1c917d",
"rev": "4f8d52a3598b0dc7db7a5e7b419e3edd9d1ecfdb",
"type": "github"
},
"original": {
@@ -634,26 +634,6 @@
"type": "github"
}
},
"nixcache-oci": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1784221638,
"narHash": "sha256-dBzaw2Itm5Rg7YTvlI+LU6d2yTZXlpbVLARO2RmTvHw=",
"owner": "cmspam",
"repo": "nixcache-oci",
"rev": "fb6006b5575da494dbbfc582e841d976ec06be6e",
"type": "github"
},
"original": {
"owner": "cmspam",
"repo": "nixcache-oci",
"type": "github"
}
},
"nixos-hardware": {
"inputs": {
"nixpkgs": "nixpkgs_4"
@@ -754,11 +734,11 @@
},
"nixpkgs-unstable": {
"locked": {
"lastModified": 1784282293,
"narHash": "sha256-IpX7tmVJi9seHg5M4Wuexy78bQDlbntVk1HcT9kFts4=",
"lastModified": 1784555310,
"narHash": "sha256-/FCliTPgiuV1owejZFNx3Ch9irdvkOfOFl+HHZ+DrtM=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "a47c123a609287a012dfc44d281de2dd4ed13394",
"rev": "421eebfd0ec7bccd4abe826ce62d7e6e83129493",
"type": "github"
},
"original": {
@@ -786,11 +766,11 @@
},
"nixpkgs_3": {
"locked": {
"lastModified": 1784120854,
"narHash": "sha256-KesHgItiZPgGX740axSiQLcIQ8D24MDqNpkKYWIek8k=",
"lastModified": 1784497964,
"narHash": "sha256-vlHUuqAcbcH2RKmHbPiuQzbv1pnzzavXnI62RD0bqCU=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "753cc8a3a87467296ddd1fa93f0cc3e81120ee46",
"rev": "241313f4e8e508cb9b13278c2b0fa25b9ca27163",
"type": "github"
},
"original": {
@@ -831,11 +811,11 @@
},
"nixpkgs_6": {
"locked": {
"lastModified": 1784280462,
"narHash": "sha256-DtoqIqM7VkR6NxAkcLpMwmi02USwWb3JdmNGLyhthc0=",
"lastModified": 1784432872,
"narHash": "sha256-n3gKTBIV4ZA5VQpUakffBe3KGu4+mhPoA34rrqS0GkA=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "293d6abedf0478e681a4dfcfcb35b30fc796a32f",
"rev": "fd1462031fdee08f65fd0b4c6b64e22239a77870",
"type": "github"
},
"original": {
@@ -923,11 +903,11 @@
]
},
"locked": {
"lastModified": 1784368151,
"narHash": "sha256-Bv8j+kJ25s5ztuuFG5OeBF+KNQeM0CXTCe6TLa+T5dg=",
"lastModified": 1784598073,
"narHash": "sha256-WCp9VCEIZpzuab3pOrfynX79DKok2qvtg1Pe+QMFKcs=",
"owner": "noctalia-dev",
"repo": "noctalia",
"rev": "ba42f397e5ba5881b00552dfa91513823ae000f5",
"rev": "448f8f56173667095fd79c972e033c523fcbd5a2",
"type": "github"
},
"original": {
@@ -970,11 +950,11 @@
]
},
"locked": {
"lastModified": 1783008725,
"narHash": "sha256-jGiy6+sxjNWXSjp25uoJuNfyH9zBK1PEDY0lVoL4ibQ=",
"lastModified": 1784288435,
"narHash": "sha256-ReRHaLgr/uVqdD8afFSn+myXIfpHeOhP0yYe0TJqAA8=",
"owner": "cachix",
"repo": "git-hooks.nix",
"rev": "bca82caa46d5ec0f5d422c61fb1e30bc51313cbe",
"rev": "43b3c1ab9d40fb1dbb008f451988a91e375825e9",
"type": "github"
},
"original": {
@@ -996,7 +976,6 @@
"niri-flake": "niri-flake",
"nix-hazkey": "nix-hazkey",
"nix-index-database": "nix-index-database",
"nixcache-oci": "nixcache-oci",
"nixos-hardware": "nixos-hardware",
"nixos-wsl": "nixos-wsl",
"nixpkgs": "nixpkgs_6",
@@ -1020,11 +999,11 @@
]
},
"locked": {
"lastModified": 1783488441,
"narHash": "sha256-jmWf+H3iC/0z7/mmvTovaJx1E/LME1QyHkyk+AFfJPk=",
"lastModified": 1784438913,
"narHash": "sha256-NYF7ZM5ip0u+w1pBFDpIGEbrbgN/wpnLFAmBkWkYMXw=",
"owner": "oxalica",
"repo": "rust-overlay",
"rev": "7dc3a177a239ed879c5581a80f6dc246c7e102f1",
"rev": "afacd6819d3765a05814ee8e3de74c77d42ac799",
"type": "github"
},
"original": {
@@ -1035,11 +1014,11 @@
},
"services-flake": {
"locked": {
"lastModified": 1783213527,
"narHash": "sha256-yIVKacNpTvEY+xQf2MzNn6jerRrazrkXxTwmwTK4N7M=",
"lastModified": 1784537427,
"narHash": "sha256-sW3zOg8UKikCe82BkipILqM2d03Zp+dkJvBeyBfQlZQ=",
"owner": "juspay",
"repo": "services-flake",
"rev": "1c9142a3d74abc53aed62687106ee15e873dc3ff",
"rev": "ee44cc299c872762cbc80490b3b596f235bf69ca",
"type": "github"
},
"original": {
@@ -1313,11 +1292,11 @@
]
},
"locked": {
"lastModified": 1780220602,
"narHash": "sha256-eynAfOmbmxJnkp7YewvCEbShNnnYJ9gLLqkzsYtBPeM=",
"lastModified": 1784369104,
"narHash": "sha256-47cxbcZODibHv3rELFQ9vZly0vUNkND/atn/U7HLeb0=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "db947814a175b7ca6ded66e21383d938df01c227",
"rev": "df3c0640565d04a0261253cdd89fce78ec50168a",
"type": "github"
},
"original": {
@@ -1351,11 +1330,11 @@
"systems": "systems_7"
},
"locked": {
"lastModified": 1784335781,
"narHash": "sha256-qkfiMa+Cxbu6qeco0Lni4IFE+JS3/c1HpnFWxGbc1OU=",
"lastModified": 1784575271,
"narHash": "sha256-8lVGfvf6bkLW4C/3H9RYTkTBhmN7ooAliMkL+UE8YmU=",
"owner": "vicinaehq",
"repo": "vicinae",
"rev": "b6bb83ed42d67f81cc3b289246510a52485d40eb",
"rev": "630036e784de647bcf18aedab7007ec5c4f5b2d0",
"type": "github"
},
"original": {
@@ -1374,11 +1353,11 @@
"vicinae": "vicinae_2"
},
"locked": {
"lastModified": 1783009133,
"narHash": "sha256-Non+frT3WG0TN60zCq63m8+d7yNmCCMaI363kZaDmPM=",
"lastModified": 1784504910,
"narHash": "sha256-fzPBEJZiRvc/FNMdpbdcfaZzF01U4IQenHW9IQFzhos=",
"owner": "vicinaehq",
"repo": "extensions",
"rev": "afb84fe4b5253777ff82db8e19e6cc0c9b7f811f",
"rev": "ca74eede9a778a9373c8f5fd221b0a5026dcd1ef",
"type": "github"
},
"original": {
-6
View File
@@ -92,12 +92,6 @@
inputs.nixpkgs.follows = "nixpkgs";
};
# Binary cache
nixcache-oci = {
url = "github:cmspam/nixcache-oci";
inputs.nixpkgs.follows = "nixpkgs";
};
# Systems
systems.url = "github:nix-systems/default-linux";
+7
View File
@@ -15,5 +15,12 @@ in
services.systemd-lock-handler.enable = true;
security.pam.services.swaylock.fprintAuth = true;
# PAM authentication is serial. Let a supplied password succeed before
# starting fprintd, whose scan otherwise blocks password verification until
# its timeout expires. Submit an empty password to start fingerprint
# authentication in upstream swaylock.
security.pam.services.swaylock.rules.auth.fprintd.order =
config.security.pam.services.swaylock.rules.auth.unix.order + 50;
};
}
+8 -4
View File
@@ -16,6 +16,10 @@ in
config = lib.mkIf cfg.enable {
programs.zed-editor = {
enable = true;
extensions = [
"catppuccin"
"nix"
];
mutableUserSettings = false;
userSettings = {
@@ -46,13 +50,13 @@ in
dark = "Zed (Default)";
};
ui_font_size = 18;
buffer_font_size = 20;
ui_font_size = 17;
buffer_font_size = 16;
theme = {
mode = "dark";
light = "Dracula";
dark = "Dracula";
light = "Catppuccin Latte";
dark = "Catppuccin Mocha";
};
};
};
-1
View File
@@ -2,7 +2,6 @@
imports = [
./container.nix
./kde.nix
./nixcache-oci.nix
./quem-guest.nix
];
}
@@ -1,17 +0,0 @@
{
lib,
config,
...
}:
let
cfg = config.my.features.services.nixcacheOci;
in
{
options.my.features.services.nixcacheOci = {
enable = lib.mkEnableOption "Nix binary cache backed by public GHCR";
};
config = lib.mkIf cfg.enable {
my.system.nixcacheOci.enable = true;
};
}
-3
View File
@@ -1,4 +1,3 @@
{ inputs, ... }:
{
imports = [
./audio.nix
@@ -12,7 +11,6 @@
./locale.nix
./network
./nix.nix
./nixcache-oci.nix
./power.nix
./quem.nix
./secure-boot.nix
@@ -20,6 +18,5 @@
./user
./version.nix
./secret.nix
inputs.nixcache-oci.nixosModules.default
];
}
-27
View File
@@ -1,27 +0,0 @@
{
lib,
config,
...
}:
let
cfg = config.my.system.nixcacheOci;
publicKeyFile = ../../nixcache-public-key.txt;
publicKey =
if builtins.pathExists publicKeyFile then
lib.strings.trim (builtins.readFile publicKeyFile)
else
"";
in
{
options.my.system.nixcacheOci = {
enable = lib.mkEnableOption "Nix binary cache backed by the public GitHub Container Registry";
};
config = lib.mkIf cfg.enable {
services.nixcache-proxy = {
enable = true;
repo = "moons-14/dotfiles";
inherit publicKey;
};
};
}
-1
View File
@@ -5,6 +5,5 @@
shell.enable = true;
};
identity.sshDefaultKey.enable = true;
services.nixcacheOci.enable = true;
};
}