mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-07 00:54:09 +09:00
Compare commits
242
Commits
6f4f048f4c
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
37705972ea | ||
|
|
08210abf01 | ||
|
|
eadfa9b331 | ||
|
|
0f3b6c59a2 | ||
|
|
c6fe17de3f | ||
|
|
ac60dc343b | ||
|
|
ebef49064c | ||
|
|
691926aa4f | ||
|
|
37e2184d36 | ||
|
|
52e5fcd47f | ||
|
|
fe785b1fc3 | ||
|
|
b8532ff1b4 | ||
|
|
3a20fe9a09 | ||
|
|
ef7ff60537 | ||
|
|
53f4d2475b | ||
|
|
7d670b03b2 | ||
|
|
2d9154614b | ||
|
|
56bc3161d7 | ||
|
|
10f4d99cb7 | ||
|
|
12badacf46 | ||
|
|
937be12e33 | ||
|
|
8761cbfe40 | ||
|
|
e789b5a16f | ||
|
|
008f704b23 | ||
|
|
11c1e24ccd | ||
|
|
ad8337bfbb | ||
|
|
cf23e1ef63 | ||
|
|
4652d911ee | ||
|
|
c7db764fe2 | ||
|
|
63f49d58f8 | ||
|
|
8189373575 | ||
|
|
d4721d1d22 | ||
|
|
cc3798a7b2 | ||
|
|
0ff78c6848 | ||
|
|
c53a0c0bed | ||
|
|
e3d61e8b6d | ||
|
|
fda29cd08d | ||
|
|
db0a440da4 | ||
|
|
76f5dce9c0 | ||
|
|
3b61457718 | ||
|
|
c9f1584797 | ||
|
|
d51948c307 | ||
|
|
9a38e9f614 | ||
|
|
2cb7e76ca1 | ||
|
|
749410e032 | ||
|
|
d43f19c20a | ||
|
|
32a3067cb0 | ||
|
|
6e60bd8886 | ||
|
|
bcf7ef56cf | ||
|
|
63e2008423 | ||
|
|
3b8147ff46 | ||
|
|
c84f257149 | ||
|
|
6347292c1d | ||
|
|
2a82433754 | ||
|
|
847ee17b29 | ||
|
|
95f74aabcd | ||
|
|
717572ae24 | ||
|
|
8086c9a7f3 | ||
|
|
eba23455d4 | ||
|
|
b3b1031364 | ||
|
|
366ff54403 | ||
|
|
456e9946f4 | ||
|
|
c104404e5b | ||
|
|
cb41932fec | ||
|
|
fa4b7ca404 | ||
|
|
847d33e83b | ||
|
|
b2c700e1e4 | ||
|
|
c1540d8764 | ||
|
|
5b8c3b1415 | ||
|
|
6743569789 | ||
|
|
70253fc451 | ||
|
|
5107b80173 | ||
|
|
2bdea522cb | ||
|
|
c113d0d46d | ||
|
|
fa50be8feb | ||
|
|
33ebef4a1e | ||
|
|
94048ef8d5 | ||
|
|
c7627fa1b0 | ||
|
|
d68da620ac | ||
|
|
5f0df47775 | ||
|
|
119342e564 | ||
|
|
1f066e8937 | ||
|
|
0a440e3da8 | ||
|
|
bdf93ac6bb | ||
|
|
9ae5da4d30 | ||
|
|
872436b170 | ||
|
|
c14325e29c | ||
|
|
45bc66e25f | ||
|
|
78ee2d41ec | ||
|
|
0b1ae13048 | ||
|
|
458b0a2cdb | ||
|
|
01179f3dc6 | ||
|
|
42949fc06c | ||
|
|
a7f514c0f9 | ||
|
|
9bed1c3e25 | ||
|
|
791b6baa83 | ||
|
|
349f49e496 | ||
|
|
3166c12448 | ||
|
|
4c459e4aa7 | ||
|
|
9b9141dd84 | ||
|
|
16e3fda275 | ||
|
|
ca36b07839 | ||
|
|
5ebcbb4abf | ||
|
|
f8fd8a3d99 | ||
|
|
16742d2fd7 | ||
|
|
15da7affaa | ||
|
|
548647fec7 | ||
|
|
bcbd08c225 | ||
|
|
a0ae83d24e | ||
|
|
33e09f8e93 | ||
|
|
eff32fddcd | ||
|
|
8ce3a6082a | ||
|
|
a8246261ad | ||
|
|
8b51b5c55f | ||
|
|
e24d85da56 | ||
|
|
01ead9a385 | ||
|
|
328f11d0ed | ||
|
|
d877ffc76c | ||
|
|
fe40adaeee | ||
|
|
991dde5305 | ||
|
|
96ce4d768c | ||
|
|
30b1480e50 | ||
|
|
71011d7bd1 | ||
|
|
9cced59e58 | ||
|
|
20a601402e | ||
|
|
1b4a5fa5a2 | ||
|
|
5fb55f2e6a | ||
|
|
2a3f7ee6ff | ||
|
|
247db71f2d | ||
|
|
a44a83a587 | ||
|
|
1f1d46ea2a | ||
|
|
29c4815b88 | ||
|
|
28a46d9990 | ||
|
|
403971eef6 | ||
|
|
c62468396d | ||
|
|
9145b36412 | ||
|
|
f574b1d1e7 | ||
|
|
cf088a6998 | ||
|
|
e4eb1802d7 | ||
|
|
a7c6a1507c | ||
|
|
49141e3478 | ||
|
|
cc91ad88b0 | ||
|
|
bb1f81a598 | ||
|
|
c0fdd9b4ef | ||
|
|
aafcc1555d | ||
|
|
245f22e094 | ||
|
|
15ca59e43c | ||
|
|
3627587bc7 | ||
|
|
d90aed6903 | ||
|
|
3e57b6c4c1 | ||
|
|
bdca6fb2fb | ||
|
|
98397cf152 | ||
|
|
3162bc0eba | ||
|
|
c3bb2f4d43 | ||
|
|
5edbc6cbb4 | ||
|
|
bf28275b40 | ||
|
|
92b4bc7b8d | ||
|
|
9bbef37010 | ||
|
|
e708ceee26 | ||
|
|
7604dfb0e3 | ||
|
|
02f97f73df | ||
|
|
cde17e6a68 | ||
|
|
64fe5020d0 | ||
|
|
843dd0cbf4 | ||
|
|
0060fdae15 | ||
|
|
6402cdcf3a | ||
|
|
118d91f1d5 | ||
|
|
b261f4aec7 | ||
|
|
b146081ba8 | ||
|
|
6f19ea8f23 | ||
|
|
aaa4542f25 | ||
|
|
d3ce44ff63 | ||
|
|
fb3254daa1 | ||
|
|
e69203ce4c | ||
|
|
e84fa82710 | ||
|
|
d5e4c90710 | ||
|
|
d67d53644e | ||
|
|
f1dd96945a | ||
|
|
aceb3d4808 | ||
|
|
ac874a849e | ||
|
|
519f7dd54d | ||
|
|
233ba91309 | ||
|
|
e6c80ad5d6 | ||
|
|
847d7ee6dd | ||
|
|
5e12c1d953 | ||
|
|
dfc4dc79d6 | ||
|
|
5deab38d3c | ||
|
|
3c674e34c1 | ||
|
|
506602d7e1 | ||
|
|
6b4253e1d4 | ||
|
|
a3660b5733 | ||
|
|
894b18bd10 | ||
|
|
08effb9e29 | ||
|
|
605e63acdb | ||
|
|
12c9d5241b | ||
|
|
ac44bdf22f | ||
|
|
421ede5d57 | ||
|
|
7204e3e8f6 | ||
|
|
f696ed6b93 | ||
|
|
d1891382ea | ||
|
|
4a7516939c | ||
|
|
176cd60d68 | ||
|
|
7c66c15da5 | ||
|
|
dddb7e07ab | ||
|
|
9ede34fcfd | ||
|
|
855b8c55cf | ||
|
|
a51e9584b0 | ||
|
|
3dae1d26ef | ||
|
|
06cd9516b3 | ||
|
|
f3098f2674 | ||
|
|
2f9c8f3d33 | ||
|
|
82d00fb574 | ||
|
|
ad6dff2f6a | ||
|
|
54b84c0544 | ||
|
|
c3dbcda528 | ||
|
|
480a1c3194 | ||
|
|
37d4a4a7c5 | ||
|
|
e68e2f536f | ||
|
|
36f01a084f | ||
|
|
e9ab8c2caa | ||
|
|
7ef25c5e63 | ||
|
|
d6026a5bfc | ||
|
|
b477446f5c | ||
|
|
ee9ce66d55 | ||
|
|
ecabb8b630 | ||
|
|
831ae7bbc2 | ||
|
|
8dc9452d95 | ||
|
|
c566f426ec | ||
|
|
e56af06b04 | ||
|
|
acb5ed3449 | ||
|
|
9f40aadab3 | ||
|
|
55e1e0b5b4 | ||
|
|
aef1338d79 | ||
|
|
5bbf1d42e9 | ||
|
|
f02eeac2a3 | ||
|
|
e23e0058bd | ||
|
|
e474c38aff | ||
|
|
04e4bdaeff | ||
|
|
c02d6936fa | ||
|
|
3f35a54e0a | ||
|
|
601c94a5d8 | ||
|
|
7e8bd33c89 |
@@ -0,0 +1,27 @@
|
|||||||
|
# Reference: https://github.com/ryoppippi/dotfiles/blob/main/.github/workflows/nix-build.yaml
|
||||||
|
name: Check NixOS configurations
|
||||||
|
description: Build every NixOS configuration and the Registry tests
|
||||||
|
runs:
|
||||||
|
using: composite
|
||||||
|
steps:
|
||||||
|
- name: Build every NixOS configuration
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
mapfile -t hosts < <(
|
||||||
|
nix eval --raw .#nixosConfigurations \
|
||||||
|
--apply 'configs: builtins.concatStringsSep "\n" (builtins.attrNames configs)'
|
||||||
|
)
|
||||||
|
|
||||||
|
installables=(.#checks.x86_64-linux.registry)
|
||||||
|
for host in "${hosts[@]}"; do
|
||||||
|
installables+=(".#nixosConfigurations.${host}.config.system.build.toplevel")
|
||||||
|
done
|
||||||
|
|
||||||
|
nix build \
|
||||||
|
--keep-going \
|
||||||
|
--no-link \
|
||||||
|
--print-build-logs \
|
||||||
|
--show-trace \
|
||||||
|
"${installables[@]}"
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
# Reference: https://github.com/ryoppippi/dotfiles/blob/main/.github/actions/setup-nix/action.yaml
|
||||||
|
name: Setup Nix
|
||||||
|
description: Install Nix and cache the Nix store
|
||||||
|
runs:
|
||||||
|
using: composite
|
||||||
|
steps:
|
||||||
|
- name: Allow unprivileged user namespaces
|
||||||
|
if: runner.os == 'Linux'
|
||||||
|
shell: bash
|
||||||
|
run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 2>/dev/null || true
|
||||||
|
- name: Install Nix
|
||||||
|
uses: nixbuild/nix-quick-install-action@9f63be77f412a248c9d9a65a4c82cf066cdf8f0c # v35
|
||||||
|
with:
|
||||||
|
nix_conf: |
|
||||||
|
accept-flake-config = true
|
||||||
|
max-jobs = auto
|
||||||
|
- name: Cache Nix store
|
||||||
|
uses: nix-community/cache-nix-action@7df957e333c1e5da7721f60227dbba6d06080569 # v7.0.2
|
||||||
|
with:
|
||||||
|
primary-key: nix-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('flake.lock') }}
|
||||||
|
restore-prefixes-first-match: nix-${{ runner.os }}-${{ runner.arch }}-
|
||||||
|
gc-max-store-size-linux: 4G
|
||||||
@@ -0,0 +1,51 @@
|
|||||||
|
# Reference: https://github.com/ryoppippi/dotfiles/blob/main/.github/workflows/nix-build.yaml
|
||||||
|
name: "CI: NixOS"
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
|
paths:
|
||||||
|
- flake.nix
|
||||||
|
- flake.lock
|
||||||
|
- "flake/**"
|
||||||
|
- "hosts/**"
|
||||||
|
- "libs/**"
|
||||||
|
- "modules/**"
|
||||||
|
- "overlays/**"
|
||||||
|
- "shells/**"
|
||||||
|
- "tests/**"
|
||||||
|
- ".github/actions/check-nixos/**"
|
||||||
|
- ".github/actions/setup-nix/**"
|
||||||
|
- ".github/workflows/nixos.yaml"
|
||||||
|
pull_request:
|
||||||
|
paths:
|
||||||
|
- flake.nix
|
||||||
|
- flake.lock
|
||||||
|
- "flake/**"
|
||||||
|
- "hosts/**"
|
||||||
|
- "libs/**"
|
||||||
|
- "modules/**"
|
||||||
|
- "overlays/**"
|
||||||
|
- "shells/**"
|
||||||
|
- "tests/**"
|
||||||
|
- ".github/actions/check-nixos/**"
|
||||||
|
- ".github/actions/setup-nix/**"
|
||||||
|
- ".github/workflows/nixos.yaml"
|
||||||
|
workflow_dispatch:
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}-${{ github.ref }}
|
||||||
|
cancel-in-progress: true
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
jobs:
|
||||||
|
check:
|
||||||
|
name: Check all NixOS configurations
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
timeout-minutes: 120
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
||||||
|
- name: Setup Nix
|
||||||
|
uses: ./.github/actions/setup-nix
|
||||||
|
- name: Check NixOS configurations
|
||||||
|
uses: ./.github/actions/check-nixos
|
||||||
@@ -0,0 +1,48 @@
|
|||||||
|
# Reference: https://github.com/ryoppippi/dotfiles/blob/main/.github/workflows/update-flake.yaml
|
||||||
|
name: "Bot: Update flake inputs"
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: "0 6 * * *"
|
||||||
|
workflow_dispatch:
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}
|
||||||
|
cancel-in-progress: false
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
pull-requests: write
|
||||||
|
jobs:
|
||||||
|
update:
|
||||||
|
name: Update and validate flake inputs
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
timeout-minutes: 120
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
||||||
|
- name: Setup Nix
|
||||||
|
uses: ./.github/actions/setup-nix
|
||||||
|
- name: Update flake inputs
|
||||||
|
id: update
|
||||||
|
run: |
|
||||||
|
nix flake update
|
||||||
|
if git diff --quiet -- flake.lock; then
|
||||||
|
echo 'changed=false' >> "$GITHUB_OUTPUT"
|
||||||
|
else
|
||||||
|
echo 'changed=true' >> "$GITHUB_OUTPUT"
|
||||||
|
fi
|
||||||
|
- name: Check updated NixOS configurations
|
||||||
|
if: steps.update.outputs.changed == 'true'
|
||||||
|
uses: ./.github/actions/check-nixos
|
||||||
|
- name: Create update pull request
|
||||||
|
if: steps.update.outputs.changed == 'true'
|
||||||
|
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
|
||||||
|
with:
|
||||||
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
add-paths: flake.lock
|
||||||
|
branch: automation/update-flake-lock
|
||||||
|
delete-branch: true
|
||||||
|
commit-message: "flake: update inputs"
|
||||||
|
title: "flake: update inputs"
|
||||||
|
body: |
|
||||||
|
Automated update of `flake.lock`.
|
||||||
|
|
||||||
|
The updated inputs passed the Registry tests and a build of every NixOS configuration.
|
||||||
+3
-2
@@ -23,10 +23,11 @@
|
|||||||
!/images/
|
!/images/
|
||||||
!/secrets/
|
!/secrets/
|
||||||
|
|
||||||
|
!/windows/
|
||||||
|
|
||||||
!/hosts/
|
!/hosts/
|
||||||
|
|
||||||
!/libs/
|
!/libs/
|
||||||
|
|
||||||
!/modules/
|
!/modules/
|
||||||
|
|
||||||
!/tests/
|
!/tests/
|
||||||
|
!/skills/
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ keys:
|
|||||||
- &host_x1g13 age12g85cuvg4kjfr79lqf5fx2k0d82tchrgv88xgkt7ukk2cfcsw98s2rjyat
|
- &host_x1g13 age12g85cuvg4kjfr79lqf5fx2k0d82tchrgv88xgkt7ukk2cfcsw98s2rjyat
|
||||||
- &host_ops age18rtm2dq2r62zvnhwdq0gkm24hu85r7zyleyk3jqv22zpdtw064eq7ay7dl
|
- &host_ops age18rtm2dq2r62zvnhwdq0gkm24hu85r7zyleyk3jqv22zpdtw064eq7ay7dl
|
||||||
- &host_internal-app-01 age1mcp5gma7y0k59equhzqfsnn0ed335ljjtn0k08ua77htlxf0x54qsravch
|
- &host_internal-app-01 age1mcp5gma7y0k59equhzqfsnn0ed335ljjtn0k08ua77htlxf0x54qsravch
|
||||||
|
- &host_galleria age1wh7r9wnvyrgt5efjvg2324khsf4w6e9atpmz2udr4uw7frhnvvwquzcu72
|
||||||
creation_rules:
|
creation_rules:
|
||||||
- path_regex: ^secrets/common/[^/]+\.ya?ml$
|
- path_regex: ^secrets/common/[^/]+\.ya?ml$
|
||||||
key_groups:
|
key_groups:
|
||||||
@@ -11,6 +12,7 @@ creation_rules:
|
|||||||
- *host_x1g13
|
- *host_x1g13
|
||||||
- *host_ops
|
- *host_ops
|
||||||
- *host_internal-app-01
|
- *host_internal-app-01
|
||||||
|
- *host_galleria
|
||||||
- path_regex: ^secrets/hosts/x1g13/[^/]+\.ya?ml$
|
- path_regex: ^secrets/hosts/x1g13/[^/]+\.ya?ml$
|
||||||
key_groups:
|
key_groups:
|
||||||
- age:
|
- age:
|
||||||
|
|||||||
@@ -24,60 +24,76 @@ makes any statement here stale, update `AGENTS.md` in the same change.
|
|||||||
| `overlays/` | Package replacements and additions |
|
| `overlays/` | Package replacements and additions |
|
||||||
| `shells/` | Development shells |
|
| `shells/` | Development shells |
|
||||||
| `flake/` | Supporting flake outputs such as formatters, checks, and Git hooks |
|
| `flake/` | Supporting flake outputs such as formatters, checks, and Git hooks |
|
||||||
|
| `skills/` | Repository-specific Codex workflows that enforce this contract for recurring changes |
|
||||||
|
|
||||||
|
Before adding or materially extending an application or service, read and
|
||||||
|
follow `skills/add-application-or-service/SKILL.md`. `AGENTS.md` remains the
|
||||||
|
authoritative contract when the skill and repository ever disagree.
|
||||||
|
|
||||||
Use **unit** as the generic internal term for a Registry-managed component and
|
Use **unit** as the generic internal term for a Registry-managed component and
|
||||||
**profile** for a unit that composes multiple units. Do not introduce a
|
**profile** for a unit that composes multiple units. Do not introduce a
|
||||||
`features/` layer. Window managers and desktop environments such as niri and
|
`features/` layer. Window managers and desktop environments such as niri and
|
||||||
GNOME belong in `modules/applications/`; do not create a separate `desktop/`
|
labwc belong in `modules/applications/`; do not create a separate `desktop/`
|
||||||
module category.
|
module category.
|
||||||
|
|
||||||
Before adding configuration, decide whether it is owned by an application,
|
Before adding configuration, decide whether it is owned by an application,
|
||||||
system foundation, service, hardware family, user, profile, or individual host.
|
system foundation, service, hardware family, user, profile, or individual host.
|
||||||
Prefer the following placements:
|
Prefer the following placements:
|
||||||
|
|
||||||
| Configuration | Placement |
|
| Configuration | Placement |
|
||||||
| ---------------------------------------------------- | ------------------------------------------------------- |
|
| ---------------------------------------------------- | --------------------------------------------------------- |
|
||||||
| Nix settings shared by every system host | `modules/systems/nix/common.nix` |
|
| Nix settings shared by every system host | `modules/systems/nix/common.nix` |
|
||||||
| NixOS-only boot configuration | `modules/systems/boot/.../nixos.nix` |
|
| NixOS-only boot configuration | `modules/systems/boot/.../nixos.nix` |
|
||||||
| Disko NixOS module and CLI | `modules/systems/disko/` |
|
| Disko NixOS module and CLI | `modules/systems/disko/` |
|
||||||
| macOS Dock defaults | `modules/systems/dock/darwin.nix` |
|
| macOS-wide input, document, and dialog defaults | `modules/systems/macos-defaults/darwin.nix` |
|
||||||
| macOS trackpad defaults | `modules/systems/trackpad/darwin.nix` |
|
| macOS Dock defaults | `modules/systems/dock/darwin.nix` |
|
||||||
| Ghostty-specific configuration | `modules/applications/ghostty/` |
|
| macOS trackpad defaults | `modules/systems/trackpad/darwin.nix` |
|
||||||
| niri-specific configuration | `modules/applications/niri/` |
|
| Finder-specific preferences | `modules/applications/finder/darwin.nix` |
|
||||||
| Desktop applications shared by GNOME and niri | `modules/profiles/interface/linux-desktop/meta.nix` |
|
| Ghostty-specific configuration | `modules/applications/ghostty/` |
|
||||||
| Applications and services specific to niri | `modules/profiles/interface/niri/meta.nix` |
|
| niri-specific configuration | `modules/applications/niri/` |
|
||||||
| GNOME itself | `modules/applications/gnome/` |
|
| Desktop applications shared by labwc and niri | `modules/profiles/interface/linux-desktop/meta.nix` |
|
||||||
| A Linux package plus its macOS Homebrew cask | `modules/applications/<name>/home.nix` and `darwin.nix` |
|
| Applications and services specific to niri | `modules/profiles/interface/niri/meta.nix` |
|
||||||
| Docker daemon and Docker group membership | `modules/services/docker/nixos.nix` |
|
| labwc and its session configuration | `modules/applications/labwc/` |
|
||||||
| The laptop unit composition | `modules/profiles/platform/laptop/meta.nix` |
|
| A Linux package plus its macOS Homebrew cask | `modules/applications/<name>/home.nix` and `darwin.nix` |
|
||||||
| The Intel ThinkPad X1 composition | `modules/profiles/platform/thinkpad-x1/meta.nix` |
|
| Docker daemon and Docker group membership | `modules/services/docker/nixos.nix` |
|
||||||
| The development-environment unit composition | `modules/profiles/workload/development/meta.nix` |
|
| The laptop unit composition | `modules/profiles/platform/laptop/meta.nix` |
|
||||||
| Cross-platform fingerprint selection | `modules/profiles/security/fingerprint/meta.nix` |
|
| The Intel ThinkPad X1 composition | `modules/profiles/platform/thinkpad-x1/meta.nix` |
|
||||||
| A user's OS- and Home Manager-specific configuration | `modules/users/<name>/` |
|
| The Intel/NVIDIA desktop composition | `modules/profiles/platform/intel-nvidia-desktop/meta.nix` |
|
||||||
| Host-specific monitor layout | `hosts/<name>/home.nix` |
|
| NVIDIA GPU driver configuration | `modules/hardwares/nvidia/` |
|
||||||
| Generated host disk UUIDs | `hosts/<name>/hardware-configuration.nix` |
|
| The development-environment unit composition | `modules/profiles/workload/development/meta.nix` |
|
||||||
| Package replacement or addition | `overlays/` |
|
| Cross-platform fingerprint selection | `modules/profiles/security/fingerprint/meta.nix` |
|
||||||
| Formatter, checks, or Git hooks | `flake/` |
|
| A user's OS- and Home Manager-specific configuration | `modules/users/<name>/` |
|
||||||
|
| Host-specific monitor layout | `hosts/<name>/home.nix` |
|
||||||
|
| Generated host disk UUIDs | `hosts/<name>/hardware-configuration.nix` |
|
||||||
|
| Package replacement or addition | `overlays/` |
|
||||||
|
| Formatter, checks, or Git hooks | `flake/` |
|
||||||
|
|
||||||
## Unit Discovery and Identity
|
## Unit Discovery and Identity
|
||||||
|
|
||||||
A directory below `modules/` is a unit if, and only if, it directly contains at
|
A directory below `modules/` is a unit if, and only if, it contains at least one
|
||||||
least one reserved file. Directories used only for classification, such as
|
reserved root file or reserved Home Manager fragment. Directories used only for
|
||||||
`modules/applications/` or `modules/profiles/interface/`, are namespaces rather
|
classification, such as `modules/applications/` or
|
||||||
than units when they have no reserved file of their own.
|
`modules/profiles/interface/`, are namespaces rather than units when they have
|
||||||
|
no reserved fragment of their own.
|
||||||
|
|
||||||
The Registry recognizes exactly these five reserved filenames:
|
The Registry recognizes exactly these eight reserved paths relative to a unit:
|
||||||
|
|
||||||
| File | Target and responsibility |
|
| File | Target and responsibility |
|
||||||
| ------------ | -------------------------------------------------------------------------------- |
|
| ----------------- | -------------------------------------------------------------------------------- |
|
||||||
| `common.nix` | System-side configuration fragment shared by NixOS and nix-darwin |
|
| `common.nix` | System-side configuration fragment shared by NixOS and nix-darwin |
|
||||||
| `nixos.nix` | NixOS-only configuration fragment |
|
| `nixos.nix` | NixOS-only system configuration fragment |
|
||||||
| `darwin.nix` | nix-darwin-only configuration fragment |
|
| `darwin.nix` | nix-darwin-only system configuration fragment |
|
||||||
| `home.nix` | Home Manager configuration fragment |
|
| `home.nix` | Home Manager fragment shared by NixOS and nix-darwin |
|
||||||
| `meta.nix` | Registry descriptor for dependencies, external modules, and descriptive metadata |
|
| `home/common.nix` | Home Manager fragment shared by NixOS and nix-darwin |
|
||||||
|
| `home/nixos.nix` | Home Manager fragment loaded only on NixOS |
|
||||||
|
| `home/darwin.nix` | Home Manager fragment loaded only on nix-darwin |
|
||||||
|
| `meta.nix` | Registry descriptor for dependencies, external modules, and descriptive metadata |
|
||||||
|
|
||||||
`common.nix` is never applied to Home Manager. OS-independent Home Manager
|
Root `common.nix` is never applied to Home Manager. `home.nix` and
|
||||||
configuration still belongs in `home.nix`.
|
`home/common.nix` have identical dispatch semantics; use either or both when a
|
||||||
|
useful file split exists. The `home/` directory is a reserved fragment directory
|
||||||
|
of its parent unit when it contains `common.nix`, `nixos.nix`, or `darwin.nix`;
|
||||||
|
it is not discovered as a child unit in that case.
|
||||||
|
|
||||||
The Registry derives a unit ID from the path relative to `modules/`, joining
|
The Registry derives a unit ID from the path relative to `modules/`, joining
|
||||||
path components with dots. Category names remain plural. It also derives the
|
path components with dots. Category names remain plural. It also derives the
|
||||||
@@ -133,10 +149,13 @@ of the following are valid units:
|
|||||||
# Home Manager only
|
# Home Manager only
|
||||||
modules/applications/ghostty/
|
modules/applications/ghostty/
|
||||||
├── home.nix
|
├── home.nix
|
||||||
|
├── home/
|
||||||
|
│ ├── nixos.nix
|
||||||
|
│ └── darwin.nix
|
||||||
└── settings.nix
|
└── settings.nix
|
||||||
|
|
||||||
# NixOS only
|
# NixOS only
|
||||||
modules/applications/gnome/
|
modules/services/docker/
|
||||||
└── nixos.nix
|
└── nixos.nix
|
||||||
|
|
||||||
# nix-darwin only
|
# nix-darwin only
|
||||||
@@ -160,16 +179,16 @@ modules/systems/nix/
|
|||||||
└── common.nix
|
└── common.nix
|
||||||
```
|
```
|
||||||
|
|
||||||
If a unit has no `home.nix`, do not generate or apply a Home Manager module for
|
Each fragment is optional and registered independently. A unit may therefore
|
||||||
it. The same rule applies independently to `common.nix`, `nixos.nix`, and
|
contain only `home/nixos.nix` or `home/darwin.nix`; it does not need a
|
||||||
`darwin.nix`.
|
placeholder `home.nix` or `home/common.nix`.
|
||||||
|
|
||||||
### Configuration fragments
|
### Configuration fragments
|
||||||
|
|
||||||
`common.nix`, `nixos.nix`, `darwin.nix`, and `home.nix` are configuration
|
Every reserved path except `meta.nix` is a configuration fragment to which the
|
||||||
fragments to which the Registry adds the enable condition. They return the
|
Registry adds the enable condition. These fragments return the configuration
|
||||||
configuration for their class directly and must not define top-level `imports`,
|
for their class directly and must not define top-level `imports`, `options`, or
|
||||||
`options`, or `config` attributes:
|
`config` attributes:
|
||||||
|
|
||||||
```nix
|
```nix
|
||||||
# modules/services/docker/nixos.nix
|
# modules/services/docker/nixos.nix
|
||||||
@@ -204,9 +223,9 @@ fragment.
|
|||||||
|
|
||||||
### Helper files and directories
|
### Helper files and directories
|
||||||
|
|
||||||
Every filename other than the five reserved names is an ordinary helper,
|
Every path other than the eight reserved paths is an ordinary helper, regardless
|
||||||
regardless of its extension. The Registry neither discovers nor automatically
|
of its extension. The Registry neither discovers nor automatically imports
|
||||||
imports helper files such as `settings.nix`, `keybindings.nix`, `packages.nix`,
|
helper files such as `settings.nix`, `keybindings.nix`, `packages.nix`,
|
||||||
`colors.nix`, `rules.nix`, or `helpers.nix`. Import a helper explicitly from the
|
`colors.nix`, `rules.nix`, or `helpers.nix`. Import a helper explicitly from the
|
||||||
reserved fragment that uses it:
|
reserved fragment that uses it:
|
||||||
|
|
||||||
@@ -249,9 +268,10 @@ modules/applications/niri/
|
|||||||
```
|
```
|
||||||
|
|
||||||
Here `parts/` is not a unit because it directly contains no reserved file. A
|
Here `parts/` is not a unit because it directly contains no reserved file. A
|
||||||
helper directory that directly contains `home.nix` or another reserved file is
|
helper directory that directly contains a root reserved file is itself
|
||||||
itself discovered as a unit, so never use reserved filenames inside a directory
|
discovered as a unit, so never use reserved filenames inside a directory that
|
||||||
that is intended to contain helpers only.
|
is intended to contain helpers only. The reserved `home/` fragment directory is
|
||||||
|
the sole exception to ordinary recursive child-unit discovery.
|
||||||
|
|
||||||
### Registry metadata
|
### Registry metadata
|
||||||
|
|
||||||
@@ -298,7 +318,6 @@ use fully qualified unit IDs:
|
|||||||
"applications.noctalia"
|
"applications.noctalia"
|
||||||
"services.ly"
|
"services.ly"
|
||||||
"services.swayidle"
|
"services.swayidle"
|
||||||
"services.swaylock"
|
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
@@ -314,10 +333,11 @@ the application to work. A profile owns the user's choice to adopt several
|
|||||||
otherwise independent applications together. For example, the niri application
|
otherwise independent applications together. For example, the niri application
|
||||||
includes the Wayland foundation as a technical dependency. The
|
includes the Wayland foundation as a technical dependency. The
|
||||||
`profiles.interface.linux-desktop` profile selects Ghostty and Nautilus because
|
`profiles.interface.linux-desktop` profile selects Ghostty and Nautilus because
|
||||||
both GNOME and niri use them, while the cross-platform `profiles.interface.gui`
|
both labwc and niri use them, while the cross-platform `profiles.interface.gui`
|
||||||
profile selects Vicinae for graphical hosts. `profiles.interface.niri` selects
|
profile selects Vicinae for graphical hosts. The labwc and niri profiles select
|
||||||
only the niri-specific shell and services. Ghostty and Vicinae must not depend
|
their compositor, Noctalia, and the session services they require. Ghostty and
|
||||||
on niri, and niri-specific keybindings remain owned by the niri unit.
|
Vicinae must not depend on either compositor, and compositor-specific
|
||||||
|
keybindings remain owned by the corresponding application unit.
|
||||||
|
|
||||||
## Profiles
|
## Profiles
|
||||||
|
|
||||||
@@ -331,23 +351,31 @@ modules/profiles/
|
|||||||
├── base/
|
├── base/
|
||||||
├── interface/
|
├── interface/
|
||||||
│ ├── cli/
|
│ ├── cli/
|
||||||
|
│ ├── minimal/
|
||||||
│ ├── gui/
|
│ ├── gui/
|
||||||
│ ├── macos/
|
│ ├── macos/
|
||||||
│ ├── linux-desktop/
|
│ ├── linux-desktop/
|
||||||
│ ├── gnome/
|
│ ├── labwc/
|
||||||
│ └── niri/
|
│ └── niri/
|
||||||
├── networking/
|
├── networking/
|
||||||
│ ├── tailscale-client/
|
│ ├── tailscale-client/
|
||||||
│ └── tailscale-subnet-router/
|
│ └── tailscale-subnet-router/
|
||||||
├── platform/
|
├── platform/
|
||||||
│ ├── nixos/
|
│ ├── nixos/
|
||||||
|
│ ├── intel-nvidia-desktop/
|
||||||
│ ├── laptop/
|
│ ├── laptop/
|
||||||
│ ├── thinkpad-x1/
|
│ ├── thinkpad-x1/
|
||||||
│ ├── desktop/
|
│ ├── desktop/
|
||||||
│ └── vm/
|
│ └── vm/
|
||||||
├── workload/
|
├── workload/
|
||||||
|
│ ├── camera/
|
||||||
|
│ ├── deploy-rs-target/
|
||||||
│ ├── development/
|
│ ├── development/
|
||||||
|
│ ├── game/
|
||||||
|
│ ├── machine-learning/
|
||||||
|
│ ├── network-lab/
|
||||||
│ ├── personal/
|
│ ├── personal/
|
||||||
|
│ ├── photography/
|
||||||
│ ├── server/
|
│ ├── server/
|
||||||
│ └── remote-access/
|
│ └── remote-access/
|
||||||
└── security/
|
└── security/
|
||||||
@@ -365,18 +393,24 @@ do not retain compatibility aliases.
|
|||||||
|
|
||||||
The profile layers have these responsibilities:
|
The profile layers have these responsibilities:
|
||||||
|
|
||||||
- `base` contains only invariants required by every supported host. It currently
|
- `base` contains only invariants required by every supported host. It includes
|
||||||
includes only `systems.nix`; optional secrets, interface, hardware, and
|
`systems.nix` and the universal Atuin, tealdeer, trippy, and xh CLI tools;
|
||||||
workloads do not belong there.
|
optional secrets, interface, hardware, and workloads do not belong there.
|
||||||
- `interface` describes how the host is operated. `interface.cli` is shared by
|
- `interface` describes how the host is operated. `interface.minimal` is shared
|
||||||
NixOS and macOS and includes `tio`. `interface.gui` owns cross-platform
|
by NixOS and macOS and provides the remote-administration CLI baseline,
|
||||||
graphical interface applications such as Vicinae. `interface.macos` owns the
|
including SSH, Nano, htop, Git, Zellij, and Zsh. `interface.cli` includes that
|
||||||
macOS Dock and trackpad defaults and includes `interface.gui`.
|
baseline and adds the full interactive command-line environment, including
|
||||||
`interface.linux-desktop` owns the common GNOME/niri desktop selection,
|
the configured Neovim, Yazi, and `tio`. `interface.gui` owns
|
||||||
including Ghostty and Nautilus, and also includes `interface.gui`. GNOME and
|
cross-platform graphical interface applications such as Vicinae.
|
||||||
|
`interface.macos` owns the macOS Finder, Dock, trackpad, and shared default
|
||||||
|
preferences and includes `interface.gui`.
|
||||||
|
`interface.linux-desktop` owns the common labwc/niri desktop selection,
|
||||||
|
including Ghostty and Nautilus, and also includes `interface.gui`. Labwc and
|
||||||
niri remain independently selectable and do not imply CLI or personal
|
niri remain independently selectable and do not imply CLI or personal
|
||||||
workloads.
|
workloads.
|
||||||
- `platform` describes NixOS foundations and physical or virtual form factors.
|
- `platform` describes NixOS foundations and physical or virtual form factors.
|
||||||
|
`platform.nixos` selects the shared network foundation and `services.clatd`;
|
||||||
|
VM, laptop, and desktop platform profiles inherit both.
|
||||||
macOS does not need an empty symmetric platform profile.
|
macOS does not need an empty symmetric platform profile.
|
||||||
- `workload` describes optional host uses. `workload.development` and
|
- `workload` describes optional host uses. `workload.development` and
|
||||||
`workload.personal` are cross-platform profiles, not `*-linux` variants.
|
`workload.personal` are cross-platform profiles, not `*-linux` variants.
|
||||||
@@ -429,8 +463,10 @@ mechanism, and do not design the repository around `import-tree`. Registry logic
|
|||||||
has these responsibilities:
|
has these responsibilities:
|
||||||
|
|
||||||
1. Recursively visit directories below `modules/`.
|
1. Recursively visit directories below `modules/`.
|
||||||
2. Check only the five reserved filenames directly within each directory.
|
2. Check the five reserved root filenames and the three reserved filenames
|
||||||
3. Register a directory as a unit when at least one reserved file exists there.
|
directly inside the unit's `home/` fragment directory.
|
||||||
|
3. Register a directory as a unit when at least one reserved fragment exists
|
||||||
|
there, including a unit that has only a reserved `home/` fragment.
|
||||||
4. Derive the unit ID from the path relative to `modules/`.
|
4. Derive the unit ID from the path relative to `modules/`.
|
||||||
5. Record only class fragments that exist.
|
5. Record only class fragments that exist.
|
||||||
6. Evaluate `meta.nix` as a descriptor only when it exists.
|
6. Evaluate `meta.nix` as a descriptor only when it exists.
|
||||||
@@ -439,7 +475,8 @@ has these responsibilities:
|
|||||||
9. Enable included units from `meta.includes`.
|
9. Enable included units from `meta.includes`.
|
||||||
10. Raise a clear evaluation error for a reference to a missing unit ID.
|
10. Raise a clear evaluation error for a reference to a missing unit ID.
|
||||||
11. Apply only the fragments appropriate to the current host class.
|
11. Apply only the fragments appropriate to the current host class.
|
||||||
12. Pass `home.nix` to Home Manager only for hosts that enable Home Manager.
|
12. Pass `home.nix`, `home/common.nix`, and the matching OS-specific Home
|
||||||
|
Manager fragment only for hosts that enable Home Manager.
|
||||||
|
|
||||||
A unit record may conceptually look like this; the implementation need not use
|
A unit record may conceptually look like this; the implementation need not use
|
||||||
this exact representation:
|
this exact representation:
|
||||||
@@ -454,6 +491,9 @@ this exact representation:
|
|||||||
nixos = null;
|
nixos = null;
|
||||||
darwin = null;
|
darwin = null;
|
||||||
home = ./applications/ghostty/home.nix;
|
home = ./applications/ghostty/home.nix;
|
||||||
|
homeCommon = null;
|
||||||
|
homeNixos = ./applications/ghostty/home/nixos.nix;
|
||||||
|
homeDarwin = ./applications/ghostty/home/darwin.nix;
|
||||||
};
|
};
|
||||||
|
|
||||||
meta = { };
|
meta = { };
|
||||||
@@ -510,9 +550,26 @@ A host registry may use a specification like this:
|
|||||||
|
|
||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.minimal"
|
||||||
"platform.vm"
|
"platform.vm"
|
||||||
"workload.remote-access"
|
"workload.remote-access"
|
||||||
|
"workload.deploy-rs-target"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
netsrv-01 = {
|
||||||
|
system = "x86_64-linux";
|
||||||
|
stateVersion = "26.05";
|
||||||
|
user = "moons";
|
||||||
|
path = ./netsrv-01;
|
||||||
|
|
||||||
|
profiles = [
|
||||||
|
"base"
|
||||||
|
"interface.minimal"
|
||||||
|
"platform.vm"
|
||||||
|
"workload.remote-access"
|
||||||
|
"workload.deploy-rs-target"
|
||||||
|
"workload.server"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -524,7 +581,7 @@ A host registry may use a specification like this:
|
|||||||
|
|
||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.minimal"
|
||||||
"platform.vm"
|
"platform.vm"
|
||||||
"workload.server"
|
"workload.server"
|
||||||
];
|
];
|
||||||
@@ -549,7 +606,7 @@ A host registry may use a specification like this:
|
|||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.cli"
|
||||||
"interface.gnome"
|
"interface.labwc"
|
||||||
"interface.niri"
|
"interface.niri"
|
||||||
"platform.thinkpad-x1"
|
"platform.thinkpad-x1"
|
||||||
"security.fingerprint"
|
"security.fingerprint"
|
||||||
@@ -566,7 +623,7 @@ A host registry may use a specification like this:
|
|||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.cli"
|
||||||
"interface.gnome"
|
"interface.labwc"
|
||||||
"interface.niri"
|
"interface.niri"
|
||||||
"networking.tailscale-client"
|
"networking.tailscale-client"
|
||||||
"platform.thinkpad-x1"
|
"platform.thinkpad-x1"
|
||||||
@@ -574,11 +631,37 @@ A host registry may use a specification like this:
|
|||||||
"security.secrets"
|
"security.secrets"
|
||||||
"security.secure-boot"
|
"security.secure-boot"
|
||||||
"security.tpm-storage"
|
"security.tpm-storage"
|
||||||
|
"workload.camera"
|
||||||
"workload.development"
|
"workload.development"
|
||||||
|
"workload.network-lab"
|
||||||
"workload.personal"
|
"workload.personal"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
galleria = {
|
||||||
|
system = "x86_64-linux";
|
||||||
|
stateVersion = "26.05";
|
||||||
|
user = "moons";
|
||||||
|
path = ./galleria;
|
||||||
|
|
||||||
|
profiles = [
|
||||||
|
"base"
|
||||||
|
"interface.cli"
|
||||||
|
"interface.labwc"
|
||||||
|
"interface.niri"
|
||||||
|
"platform.intel-nvidia-desktop"
|
||||||
|
"security.secrets"
|
||||||
|
"security.secure-boot"
|
||||||
|
"security.tpm-storage"
|
||||||
|
"workload.development"
|
||||||
|
"workload.game"
|
||||||
|
"workload.machine-learning"
|
||||||
|
"workload.network-lab"
|
||||||
|
"workload.personal"
|
||||||
|
"workload.photography"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
m2 = {
|
m2 = {
|
||||||
system = "aarch64-darwin";
|
system = "aarch64-darwin";
|
||||||
stateVersion = "26.05";
|
stateVersion = "26.05";
|
||||||
@@ -598,15 +681,25 @@ A host registry may use a specification like this:
|
|||||||
```
|
```
|
||||||
|
|
||||||
The current role assignment is intentional: nix-example is the development VM;
|
The current role assignment is intentional: nix-example is the development VM;
|
||||||
ops is the remote-access VM with host-specific static networking;
|
ops is the minimal-interface remote-access VM with host-specific static
|
||||||
internal-app-01 is the container server VM; and installer builds the minimal
|
networking; netsrv-01 is the deploy-rs-managed container server VM;
|
||||||
installation ISO without Home Manager. x1g9 is a full NixOS desktop with niri,
|
internal-app-01 is the minimal-interface container server VM;
|
||||||
GNOME, ly, the shared Linux desktop applications, and the personal workload.
|
nix-builder is the minimal-interface remote Nix build VM with dedicated build
|
||||||
|
and store disks; and installer builds the minimal installation ISO without Home
|
||||||
|
Manager. x1g9 is a full NixOS desktop with niri,
|
||||||
|
labwc, ly, the shared Linux desktop applications, and the personal workload.
|
||||||
x1g13 is the secure NixOS development and personal ThinkPad, with the same
|
x1g13 is the secure NixOS development and personal ThinkPad, with the same
|
||||||
desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk
|
desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk
|
||||||
unlock. m2 is the daily-use macOS development and personal machine with the
|
unlock. galleria is the Intel/NVIDIA physical desktop shared with Windows; it
|
||||||
macOS interface defaults. Keep the desktop sessions independently selectable,
|
uses dedicated NixOS partitions, LUKS, Secure Boot, and TPM-backed disk unlock.
|
||||||
and keep the development and personal profiles usable across NixOS and Darwin.
|
It selects `workload.photography` for AI-enabled darktable. The application
|
||||||
|
chooses CUDA support from the NVIDIA hardware unit's enable state and keeps
|
||||||
|
the default CUDA targets, including RTX 3060 Ti support, to reuse binary caches.
|
||||||
|
galleria and x1g13 select `workload.network-lab` for containerlab, Docker, and
|
||||||
|
the NanoKVM-USB desktop client with serial-port access.
|
||||||
|
m2 is the daily-use macOS development and personal machine with the macOS
|
||||||
|
interface defaults. Keep the desktop sessions independently selectable, and
|
||||||
|
keep the development and personal profiles usable across NixOS and Darwin.
|
||||||
|
|
||||||
Treat entries in `profiles` and the exceptional `applications` field as IDs
|
Treat entries in `profiles` and the exceptional `applications` field as IDs
|
||||||
relative to their respective category roots. Add the category prefixes during
|
relative to their respective category roots. Add the category prefixes during
|
||||||
@@ -636,6 +729,15 @@ configuration fragments. For example:
|
|||||||
|
|
||||||
```text
|
```text
|
||||||
hosts/
|
hosts/
|
||||||
|
├── nix-builder/
|
||||||
|
│ ├── disko.nix
|
||||||
|
│ ├── hardware-configuration.nix
|
||||||
|
│ └── nixos.nix
|
||||||
|
├── netsrv-01/
|
||||||
|
│ ├── disko.nix
|
||||||
|
│ ├── hardware-configuration.nix
|
||||||
|
│ ├── networking.nix
|
||||||
|
│ └── nixos.nix
|
||||||
├── installer/
|
├── installer/
|
||||||
│ └── nixos.nix
|
│ └── nixos.nix
|
||||||
├── internal-app-01/
|
├── internal-app-01/
|
||||||
@@ -647,6 +749,11 @@ hosts/
|
|||||||
├── ops/
|
├── ops/
|
||||||
│ ├── nixos.nix
|
│ ├── nixos.nix
|
||||||
│ └── hardware-configuration.nix
|
│ └── hardware-configuration.nix
|
||||||
|
├── galleria/
|
||||||
|
│ ├── disk-identifiers.nix
|
||||||
|
│ ├── disko.nix
|
||||||
|
│ ├── hardware-configuration.nix
|
||||||
|
│ └── nixos.nix
|
||||||
├── x1g9/
|
├── x1g9/
|
||||||
│ ├── nixos.nix
|
│ ├── nixos.nix
|
||||||
│ └── hardware-configuration.nix
|
│ └── hardware-configuration.nix
|
||||||
@@ -660,16 +767,24 @@ hosts/
|
|||||||
```
|
```
|
||||||
|
|
||||||
`hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the
|
`hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the
|
||||||
normal top-level Nix module `imports`. `hosts/x1g13/nixos.nix` loads its
|
normal top-level Nix module `imports`. `hosts/nix-builder/nixos.nix` and
|
||||||
generated hardware configuration and host-local `disko.nix` the same way. Do
|
`hosts/x1g13/nixos.nix` load their generated hardware configuration and
|
||||||
not confuse these host imports with the prohibition on top-level `imports` in
|
host-local `disko.nix` the same way. The nix-builder Disko definition mounts its
|
||||||
unit configuration fragments.
|
existing VM filesystems by stable QEMU SCSI IDs and does not take destructive
|
||||||
|
ownership of them. Do not confuse these host imports with the prohibition on
|
||||||
|
top-level `imports` in unit configuration fragments. `hosts/galleria/disko.nix`
|
||||||
|
manages only the two dedicated NixOS partitions by PARTUUID and deliberately
|
||||||
|
excludes the Windows disk, Windows partitions, and the Windows EFI System
|
||||||
|
Partition.
|
||||||
|
|
||||||
Derive the system class from the host's `system`:
|
Derive the system class from the host's `system`:
|
||||||
|
|
||||||
- A Linux NixOS host receives `common.nix` and `nixos.nix`.
|
- A Linux NixOS host receives `common.nix` and `nixos.nix`.
|
||||||
- A nix-darwin host receives `common.nix` and `darwin.nix`.
|
- A nix-darwin host receives `common.nix` and `darwin.nix`.
|
||||||
- A host with integrated Home Manager additionally receives `home.nix`.
|
- A NixOS host with integrated Home Manager additionally receives `home.nix`,
|
||||||
|
`home/common.nix`, and `home/nixos.nix`.
|
||||||
|
- A nix-darwin host with integrated Home Manager additionally receives
|
||||||
|
`home.nix`, `home/common.nix`, and `home/darwin.nix`.
|
||||||
|
|
||||||
Home Manager is additive, not a system class mutually exclusive with NixOS or
|
Home Manager is additive, not a system class mutually exclusive with NixOS or
|
||||||
nix-darwin. Normal machine configurations combine NixOS or nix-darwin with Home
|
nix-darwin. Normal machine configurations combine NixOS or nix-darwin with Home
|
||||||
@@ -698,16 +813,16 @@ When implementing or modifying modules:
|
|||||||
unit's enable option from a class fragment.
|
unit's enable option from a class fragment.
|
||||||
- Do not assume any non-reserved file is discovered or loaded automatically.
|
- Do not assume any non-reserved file is discovered or loaded automatically.
|
||||||
- Do not require an `_` prefix for helper or private files.
|
- Do not require an `_` prefix for helper or private files.
|
||||||
- Do not create unused `common.nix`, `nixos.nix`, `darwin.nix`, `home.nix`, or
|
- Do not create unused reserved fragments, including placeholder files under the
|
||||||
`meta.nix` files.
|
reserved `home/` fragment directory.
|
||||||
- Do not override a path-derived unit ID from `meta.nix`.
|
- Do not override a path-derived unit ID from `meta.nix`.
|
||||||
- Keep technical application dependencies separate from the applications a
|
- Keep technical application dependencies separate from the applications a
|
||||||
personal environment chooses to combine in a profile.
|
personal environment chooses to combine in a profile.
|
||||||
- Keep cross-platform profile names semantic. Put Linux package installation in
|
- Keep cross-platform profile names semantic. Put Linux package installation in
|
||||||
an application's `home.nix` and the corresponding macOS Homebrew cask in its
|
an application's `home.nix` and the corresponding macOS Homebrew cask in its
|
||||||
`darwin.nix`; do not create a thin `*-linux` profile for that difference.
|
`darwin.nix`; do not create a thin `*-linux` profile for that difference.
|
||||||
- Keep shared GNOME/niri selections in `profiles.interface.linux-desktop` and
|
- Keep shared labwc/niri selections in `profiles.interface.linux-desktop` and
|
||||||
session-specific applications or services in the respective GNOME or niri
|
session-specific applications or services in the respective labwc or niri
|
||||||
profile.
|
profile.
|
||||||
- Keep `modules/profiles/README.md`, the profile directories, and host profile
|
- Keep `modules/profiles/README.md`, the profile directories, and host profile
|
||||||
selections synchronized whenever any of them changes.
|
selections synchronized whenever any of them changes.
|
||||||
@@ -763,11 +878,13 @@ For profile changes, additionally:
|
|||||||
`homebrew.casks` selection as well as module evaluation.
|
`homebrew.casks` selection as well as module evaluation.
|
||||||
- Preserve the intended host roles: nix-example remains the development VM;
|
- Preserve the intended host roles: nix-example remains the development VM;
|
||||||
ops remains the statically networked remote-access VM; internal-app-01 remains
|
ops remains the statically networked remote-access VM; internal-app-01 remains
|
||||||
the container server VM; installer remains the Home Manager-free installation
|
the container server VM; netsrv-01 remains the deploy-rs-managed container
|
||||||
ISO; x1g9 provides niri, GNOME, ly, and the personal application set; x1g13
|
server VM; installer remains the Home Manager-free installation ISO; x1g9
|
||||||
|
provides niri, labwc, ly, and the personal application set; x1g13
|
||||||
additionally provides the development, Tailscale client, secrets, Secure Boot,
|
additionally provides the development, Tailscale client, secrets, Secure Boot,
|
||||||
and TPM storage roles; m2 remains the daily-use development and personal
|
and TPM storage roles; galleria remains the Intel/NVIDIA dual-boot desktop
|
||||||
machine.
|
with LUKS, Secure Boot, and TPM storage; m2 remains the daily-use development
|
||||||
|
and personal machine.
|
||||||
|
|
||||||
## Commit and Pull Request Guidelines
|
## Commit and Pull Request Guidelines
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,153 @@
|
|||||||
|
# NixOSインストール手順(SOPSなし・ディスク暗号化なし)
|
||||||
|
|
||||||
|
この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を
|
||||||
|
使用しないホスト向けの、独立したインストール手順である。
|
||||||
|
|
||||||
|
SOPSとディスク暗号化を使用する場合は、[暗号化ありの手順](install.md)を参照。
|
||||||
|
|
||||||
|
## 事前準備
|
||||||
|
|
||||||
|
1. [ISOビルド](iso-build.md)を参照してISOを作成
|
||||||
|
2. USBに書き込んで対象マシンでブート
|
||||||
|
|
||||||
|
## ネットワーク接続
|
||||||
|
|
||||||
|
### 有線LAN
|
||||||
|
|
||||||
|
DHCPで自動設定される。
|
||||||
|
|
||||||
|
### Wi-Fi(有線が使えない場合)
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmcli device wifi connect <SSID> --ask
|
||||||
|
```
|
||||||
|
|
||||||
|
## SSH接続
|
||||||
|
|
||||||
|
コンソールに表示されたIPアドレスに接続:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh root@<ip-address>
|
||||||
|
```
|
||||||
|
|
||||||
|
## インストール手順
|
||||||
|
|
||||||
|
### 1. dotfilesのクローン
|
||||||
|
|
||||||
|
```bash
|
||||||
|
git clone [email protected]:moons-14/dotfiles.git ~/dotfiles
|
||||||
|
cd ~/dotfiles
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2. ホスト設定の作成
|
||||||
|
|
||||||
|
`hosts/<hostname>/nixos.nix`を作成し、`hosts/default.nix`にホストと使用する
|
||||||
|
プロファイルを登録する。ホスト固有の設定だけをホストディレクトリに置き、
|
||||||
|
再利用可能な設定は適切なunitまたはprofileに置く。
|
||||||
|
|
||||||
|
### 3. インストール先ディスクの確認
|
||||||
|
|
||||||
|
```bash
|
||||||
|
lsblk -o NAME,PATH,SIZE,MODEL,SERIAL,TYPE,FSTYPE,MOUNTPOINTS
|
||||||
|
ls -l /dev/disk/by-id/
|
||||||
|
```
|
||||||
|
|
||||||
|
以降の操作では指定したディスクの既存データが消去される。対象を必ず確認し、
|
||||||
|
可能であれば`/dev/sda`や`/dev/nvme0n1`ではなく、安定した
|
||||||
|
`/dev/disk/by-id/...`パスを使用する。
|
||||||
|
|
||||||
|
### 4. Disko設定の作成
|
||||||
|
|
||||||
|
`hosts/<hostname>/disko.nix`を作成する:
|
||||||
|
|
||||||
|
```nix
|
||||||
|
_:
|
||||||
|
{
|
||||||
|
disko.enableConfig = true;
|
||||||
|
|
||||||
|
disko.devices.disk.main = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/disk/by-id/<target-disk>";
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
ESP = {
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
root = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
`<target-disk>`を手順3で確認した実際のディスクIDに置き換える。指定した
|
||||||
|
ディスクの既存データは消去される。
|
||||||
|
|
||||||
|
### 5. パーティション作成とマウント
|
||||||
|
|
||||||
|
```bash
|
||||||
|
disko --mode destroy,format,mount hosts/<hostname>/disko.nix
|
||||||
|
```
|
||||||
|
|
||||||
|
Diskoの実行結果を確認する:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
findmnt /mnt
|
||||||
|
findmnt /mnt/boot
|
||||||
|
```
|
||||||
|
|
||||||
|
### 6. ハードウェア設定の生成
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \
|
||||||
|
> ~/dotfiles/hosts/<hostname>/hardware-configuration.nix
|
||||||
|
```
|
||||||
|
|
||||||
|
### 7. ホストモジュールから設定を読み込む
|
||||||
|
|
||||||
|
`hosts/<hostname>/nixos.nix`で、生成したハードウェア設定とDisko設定を読み込む:
|
||||||
|
|
||||||
|
```nix
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
./hardware-configuration.nix
|
||||||
|
./disko.nix
|
||||||
|
];
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 8. NixOSインストール
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nixos-install --flake ~/dotfiles#<hostname>
|
||||||
|
```
|
||||||
|
|
||||||
|
SOPSを使用しないため、age鍵の登録、シークレットの再暗号化、SSHホストキーの
|
||||||
|
事前生成とコピーは不要である。OpenSSHを有効にしたホストでは、SSHホストキーは
|
||||||
|
通常の初回起動時に生成される。
|
||||||
|
|
||||||
|
### 9. 再起動
|
||||||
|
|
||||||
|
```bash
|
||||||
|
reboot
|
||||||
|
```
|
||||||
|
|
||||||
|
## インストール後の確認
|
||||||
|
|
||||||
|
- 正しいディスクから起動できるか
|
||||||
|
- `/`と`/boot`が意図したファイルシステムからマウントされているか
|
||||||
|
- ネットワークと、設定している場合はSSH接続が利用できるか
|
||||||
+32
-44
@@ -1,4 +1,10 @@
|
|||||||
# NixOSインストール手順
|
# NixOSインストール手順(SOPS・ディスク暗号化あり)
|
||||||
|
|
||||||
|
この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を
|
||||||
|
使用するホスト向けである。
|
||||||
|
|
||||||
|
どちらも使用しない場合は、
|
||||||
|
[SOPSなし・ディスク暗号化なしの手順](install-simple.md)を参照。
|
||||||
|
|
||||||
## 事前準備
|
## 事前準備
|
||||||
|
|
||||||
@@ -83,54 +89,36 @@ sops updatekeys secrets/hosts/<hostname>/*.yaml
|
|||||||
|
|
||||||
新しいホスト用の`hosts/<hostname>/disko.nix`を作成。
|
新しいホスト用の`hosts/<hostname>/disko.nix`を作成。
|
||||||
|
|
||||||
#### シンプル構成(暗号化なし)
|
LUKS暗号化とbtrfsの構成は`hosts/x1g13/disko.nix`を参照。
|
||||||
|
|
||||||
```nix
|
|
||||||
_:
|
|
||||||
{
|
|
||||||
disko.enableConfig = true;
|
|
||||||
|
|
||||||
disko.devices.disk.main = {
|
|
||||||
type = "disk";
|
|
||||||
device = "/dev/sda";
|
|
||||||
content = {
|
|
||||||
type = "gpt";
|
|
||||||
partitions = {
|
|
||||||
ESP = {
|
|
||||||
size = "512M";
|
|
||||||
type = "EF00";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "vfat";
|
|
||||||
mountpoint = "/boot";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
root = {
|
|
||||||
size = "100%";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "ext4";
|
|
||||||
mountpoint = "/";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
#### LUKS暗号化 + btrfs
|
|
||||||
|
|
||||||
`hosts/x1g13/disko.nix`を参照。
|
|
||||||
|
|
||||||
### 7. ディスクのパーティション
|
### 7. ディスクのパーティション
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/dotfiles
|
cd ~/dotfiles
|
||||||
nix run github:nix-community/disko -- --mode disko hosts/<hostname>/disko.nix
|
disko --mode destroy,format,mount hosts/<hostname>/disko.nix
|
||||||
```
|
```
|
||||||
|
|
||||||
### 8. ホストキーのコピー
|
### 8. ハードウェア設定の生成
|
||||||
|
|
||||||
|
対象マシンのハードウェア設定を生成し、新しいホストのディレクトリへ直接保存:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \
|
||||||
|
> ~/dotfiles/hosts/<hostname>/hardware-configuration.nix
|
||||||
|
```
|
||||||
|
|
||||||
|
`hosts/<hostname>/nixos.nix`から生成した設定とDisko設定を読み込む:
|
||||||
|
|
||||||
|
```nix
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
./hardware-configuration.nix
|
||||||
|
./disko.nix
|
||||||
|
];
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 9. ホストキーのコピー
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
mkdir -p /mnt/etc/ssh
|
mkdir -p /mnt/etc/ssh
|
||||||
@@ -138,13 +126,13 @@ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/
|
|||||||
chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key
|
chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key
|
||||||
```
|
```
|
||||||
|
|
||||||
### 9. NixOSインストール
|
### 10. NixOSインストール
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
nixos-install --flake ~/dotfiles#<hostname>
|
nixos-install --flake ~/dotfiles#<hostname>
|
||||||
```
|
```
|
||||||
|
|
||||||
### 10. 再起動
|
### 11. 再起動
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
reboot
|
reboot
|
||||||
|
|||||||
@@ -0,0 +1,119 @@
|
|||||||
|
# iOS Simulator 初期セットアップ
|
||||||
|
|
||||||
|
この手順は `m2` の macOS 環境で、stable Xcode と最新の stable iOS Simulator Runtime を使える状態にするためのもの。
|
||||||
|
|
||||||
|
## 前提
|
||||||
|
|
||||||
|
- `m2` が `workload.development` profile を有効にしていること
|
||||||
|
- Mac App Store に Apple Account でサインイン済みであること
|
||||||
|
- dotfiles を最新化していること
|
||||||
|
|
||||||
|
Xcode 本体は `applications.xcode` が Mac App Store 版を管理する。Simulator Runtime は Apple が管理する mutable state のため、Nix store には入れず専用 dev shell から導入する。
|
||||||
|
|
||||||
|
## 1. macOS 設定を反映する
|
||||||
|
|
||||||
|
リポジトリ直下で nix-darwin の設定を反映する。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo darwin-rebuild switch --flake .#m2
|
||||||
|
```
|
||||||
|
|
||||||
|
これにより `/Applications/Xcode.app` に stable Xcode がインストールされる。
|
||||||
|
|
||||||
|
Xcode のインストールで Mac App Store の認証エラーになる場合は、App Store を一度開いてサインイン状態を確認してから再実行する。
|
||||||
|
|
||||||
|
## 2. iOS Simulator Runtime を導入する
|
||||||
|
|
||||||
|
初回セットアップは次の1コマンドで行う。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nix develop .#ios -c ios-simulator-install
|
||||||
|
```
|
||||||
|
|
||||||
|
`ios-simulator-install` は次を順に実行する。
|
||||||
|
|
||||||
|
1. `/Applications/Xcode.app` が存在することを確認
|
||||||
|
2. `xcode-select` の Developer Directory を stable Xcode に切り替え
|
||||||
|
3. Xcode の first-launch components を導入
|
||||||
|
4. 利用可能な新しい hardware support components を確認
|
||||||
|
5. 選択中の Xcode に対応する最新の iOS Simulator Runtime をダウンロードしてインストール
|
||||||
|
6. Xcode のバージョンとインストール済み Simulator Runtime を表示
|
||||||
|
|
||||||
|
途中で `sudo` の認証を求められる場合がある。
|
||||||
|
|
||||||
|
## 3. インストールを確認する
|
||||||
|
|
||||||
|
```bash
|
||||||
|
xcodebuild -version
|
||||||
|
xcode-select -p
|
||||||
|
xcrun simctl list runtimes
|
||||||
|
xcrun simctl list devices available
|
||||||
|
```
|
||||||
|
|
||||||
|
`xcode-select -p` は次を指していること。
|
||||||
|
|
||||||
|
```text
|
||||||
|
/Applications/Xcode.app/Contents/Developer
|
||||||
|
```
|
||||||
|
|
||||||
|
`xcrun simctl list runtimes` に iOS runtime が表示されればセットアップ完了。
|
||||||
|
|
||||||
|
## 4. Simulator を起動する
|
||||||
|
|
||||||
|
```bash
|
||||||
|
open -a Simulator
|
||||||
|
```
|
||||||
|
|
||||||
|
Simulator の Device メニューから、インストール済み runtime で利用可能な iPhone を選択する。
|
||||||
|
|
||||||
|
## Runtime の更新
|
||||||
|
|
||||||
|
Xcode を stable の新しいバージョンへ更新した後は、同じコマンドを再実行する。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nix develop .#ios -c ios-simulator-install
|
||||||
|
```
|
||||||
|
|
||||||
|
Xcode の選択、first-launch components、hardware support、iOS Simulator Runtime の状態をまとめて更新できる。
|
||||||
|
|
||||||
|
## トラブルシューティング
|
||||||
|
|
||||||
|
### Xcode が見つからない
|
||||||
|
|
||||||
|
次のエラーが出る場合、先に nix-darwin の設定を反映する。
|
||||||
|
|
||||||
|
```text
|
||||||
|
Xcode is not installed at /Applications/Xcode.app.
|
||||||
|
```
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo darwin-rebuild switch --flake .#m2
|
||||||
|
```
|
||||||
|
|
||||||
|
### Simulator Runtime が見えない
|
||||||
|
|
||||||
|
まず runtime 一覧を確認する。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
xcrun simctl list runtimes
|
||||||
|
```
|
||||||
|
|
||||||
|
iOS runtime がない場合は再度インストーラーを実行する。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nix develop .#ios -c ios-simulator-install
|
||||||
|
```
|
||||||
|
|
||||||
|
### Command Line Tools 側を参照している
|
||||||
|
|
||||||
|
```bash
|
||||||
|
xcode-select -p
|
||||||
|
```
|
||||||
|
|
||||||
|
が `/Library/Developer/CommandLineTools` を指している場合でも、`ios-simulator-install` が `/Applications/Xcode.app/Contents/Developer` へ切り替える。
|
||||||
|
|
||||||
|
手動で直す場合は次を実行する。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo xcode-select --switch /Applications/Xcode.app/Contents/Developer
|
||||||
|
```
|
||||||
+72
-12
@@ -1,26 +1,86 @@
|
|||||||
# カスタムISOビルド
|
# カスタムインストーラー ISO
|
||||||
|
|
||||||
|
`hosts/installer` から、NixOS 26.05 ベースの `x86_64-linux` 用インストーラー
|
||||||
|
ISO を作成する。installer ホストは Home Manager を使用せず、`base` プロファイルと
|
||||||
|
ホスト固有のインストール支援設定だけを含む。
|
||||||
|
|
||||||
## ビルド
|
## ビルド
|
||||||
|
|
||||||
|
flake 対応の Nix が利用できる環境で、リポジトリのルートから実行する。
|
||||||
|
`x86_64-linux` 以外のマシンで実行する場合は、対応する Linux リモートビルダーが
|
||||||
|
必要になる。
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
nix build .#nixosConfigurations.installer.config.system.build.isoImage
|
nix build .#nixosConfigurations.installer.config.system.build.isoImage
|
||||||
```
|
```
|
||||||
|
|
||||||
## ISO書き込み
|
生成された ISO は次の場所にある。
|
||||||
|
|
||||||
|
```text
|
||||||
|
result/iso/nixos-minimal-*-x86_64-linux.iso
|
||||||
|
```
|
||||||
|
|
||||||
|
ファイル名に含まれる NixOS のバージョンとリビジョンは、`flake.lock` の更新に応じて
|
||||||
|
変わる。生成物を確認するには次を実行する。
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# USBデバイスの確認
|
ls -lh result/iso/*.iso
|
||||||
lsblk
|
sha256sum result/iso/*.iso
|
||||||
|
```
|
||||||
|
|
||||||
# 書き込み(/dev/sdXは実際のデバイスに置き換える)
|
## USB メモリへの書き込み
|
||||||
sudo dd if=./result/nixos-minimal-*.iso of=/dev/sdX bs=4M status=progress
|
|
||||||
|
書き込み先はパーティション(例: `/dev/sdX1`)ではなく、USB デバイス全体
|
||||||
|
(例: `/dev/sdX`)を指定する。この操作は指定したデバイスの内容を上書きするため、
|
||||||
|
サイズ、モデル、マウント先を確認する。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
lsblk -p -o NAME,SIZE,TYPE,MODEL,MOUNTPOINTS
|
||||||
|
```
|
||||||
|
|
||||||
|
USB のマウント済みパーティションをアンマウントしてから、`/dev/sdX` と
|
||||||
|
`/dev/sdX1` を確認した実際のデバイス名に置き換えて書き込む。パーティションが
|
||||||
|
複数ある場合は、それぞれをアンマウントする。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo umount /dev/sdX1
|
||||||
|
sudo dd if=result/iso/nixos-minimal-*-x86_64-linux.iso \
|
||||||
|
of=/dev/sdX bs=4M conv=fsync status=progress
|
||||||
sync
|
sync
|
||||||
```
|
```
|
||||||
|
|
||||||
## ISOの特徴
|
書き込み完了後、USB を安全に取り外して対象マシンから起動する。
|
||||||
|
|
||||||
- SSH鍵認証でrootログイン可能
|
## 起動後の接続
|
||||||
- 有線LANはDHCPで自動設定
|
|
||||||
- WiFiは`nmcli`で手動設定可能
|
有線 LAN は DHCP で自動設定される。Wi-Fi を使用する場合は、インストーラーの
|
||||||
- disko/sops/ageなどのツールを内蔵
|
コンソールで NetworkManager を使って接続する。
|
||||||
- ブート時にIPアドレスとヘルプを表示
|
|
||||||
|
```bash
|
||||||
|
nmcli device wifi list
|
||||||
|
nmcli device wifi connect <SSID> --ask
|
||||||
|
```
|
||||||
|
|
||||||
|
起動時にコンソールへ IPv4 アドレスと簡易ヘルプが表示される。表示されたアドレスへ
|
||||||
|
登録済みの SSH 鍵で接続する。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh root@<ip-address>
|
||||||
|
```
|
||||||
|
|
||||||
|
root のパスワードログインとキーボード対話認証は無効で、
|
||||||
|
`hosts/installer/nixos.nix` に登録された公開鍵だけが利用できる。
|
||||||
|
以降の作業は、構成に応じて次の手順を参照する:
|
||||||
|
|
||||||
|
- [SOPSなし・ディスク暗号化なし](install-simple.md)
|
||||||
|
- [SOPS・ディスク暗号化あり](install.md)
|
||||||
|
|
||||||
|
## ISO に含まれる主な設定とツール
|
||||||
|
|
||||||
|
- Nix flakes と `nix-command`
|
||||||
|
- NetworkManager、OpenSSH、起動時の IP アドレス表示
|
||||||
|
- `disko`、`parted`、`cryptsetup`、`btrfs-progs`、`efibootmgr`
|
||||||
|
- `sops`、`age`、`ssh-to-age`
|
||||||
|
- `age-plugin-yubikey`、`yubikey-manager`、`pcsc-tools` と `pcscd`
|
||||||
|
- `sbctl`、`tpm2-tools`
|
||||||
|
- `git`、`rsync`、`vim`、`wget`、`curl`、`jq`、`pciutils`、`util-linux`
|
||||||
|
|||||||
Generated
+837
-245
File diff suppressed because it is too large
Load Diff
@@ -23,6 +23,11 @@
|
|||||||
# Desktop
|
# Desktop
|
||||||
niri-flake.url = "github:sodiboo/niri-flake";
|
niri-flake.url = "github:sodiboo/niri-flake";
|
||||||
|
|
||||||
|
nix-hazkey = {
|
||||||
|
url = "github:aster-void/nix-hazkey";
|
||||||
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
};
|
||||||
|
|
||||||
stylix = {
|
stylix = {
|
||||||
url = "github:nix-community/stylix";
|
url = "github:nix-community/stylix";
|
||||||
inputs.nixpkgs.follows = "nixpkgs";
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
@@ -30,7 +35,7 @@
|
|||||||
|
|
||||||
# Terminal
|
# Terminal
|
||||||
ghostty = {
|
ghostty = {
|
||||||
url = "github:moons-14/ghostty";
|
url = "github:ghostty-org/ghostty";
|
||||||
};
|
};
|
||||||
|
|
||||||
# Shell / Launcher
|
# Shell / Launcher
|
||||||
@@ -86,6 +91,13 @@
|
|||||||
url = "github:ilysenko/codex-desktop-linux";
|
url = "github:ilysenko/codex-desktop-linux";
|
||||||
};
|
};
|
||||||
|
|
||||||
|
codex-session-usage.url = "github:moons-14/codex-session-usage";
|
||||||
|
|
||||||
|
skills = {
|
||||||
|
url = "github:mattpocock/skills";
|
||||||
|
flake = false;
|
||||||
|
};
|
||||||
|
|
||||||
# Index / Search
|
# Index / Search
|
||||||
nix-index-database = {
|
nix-index-database = {
|
||||||
url = "github:nix-community/nix-index-database";
|
url = "github:nix-community/nix-index-database";
|
||||||
@@ -94,6 +106,15 @@
|
|||||||
|
|
||||||
# Systems
|
# Systems
|
||||||
systems.url = "github:nix-systems/default";
|
systems.url = "github:nix-systems/default";
|
||||||
|
|
||||||
|
browser-previews = {
|
||||||
|
url = "github:nix-community/browser-previews";
|
||||||
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
};
|
||||||
|
|
||||||
|
nani-translate-linux.url = "git+https://github.com/zunoser/nani-translate-linux.git";
|
||||||
|
|
||||||
|
containerlab.url = "github:srl-labs/containerlab";
|
||||||
};
|
};
|
||||||
|
|
||||||
outputs =
|
outputs =
|
||||||
|
|||||||
+43
-10
@@ -1,15 +1,14 @@
|
|||||||
{
|
{
|
||||||
nix-example = {
|
nix-builder = {
|
||||||
system = "x86_64-linux";
|
system = "x86_64-linux";
|
||||||
stateVersion = "26.05";
|
stateVersion = "26.05";
|
||||||
user = "moons";
|
user = "moons";
|
||||||
path = ./nix-example;
|
path = ./nix-builder;
|
||||||
|
|
||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.minimal"
|
||||||
"platform.vm"
|
"platform.vm"
|
||||||
"workload.development"
|
|
||||||
"workload.remote-access"
|
"workload.remote-access"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
@@ -22,22 +21,25 @@
|
|||||||
|
|
||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.minimal"
|
||||||
"platform.vm"
|
"platform.vm"
|
||||||
"workload.remote-access"
|
"workload.remote-access"
|
||||||
|
"workload.deploy-rs-target"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
internal-app-01 = {
|
netsrv-01 = {
|
||||||
system = "x86_64-linux";
|
system = "x86_64-linux";
|
||||||
stateVersion = "26.05";
|
stateVersion = "26.05";
|
||||||
user = "moons";
|
user = "moons";
|
||||||
path = ./internal-app-01;
|
path = ./netsrv-01;
|
||||||
|
|
||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.minimal"
|
||||||
"platform.vm"
|
"platform.vm"
|
||||||
|
"workload.remote-access"
|
||||||
|
"workload.deploy-rs-target"
|
||||||
"workload.server"
|
"workload.server"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
@@ -61,7 +63,7 @@
|
|||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.cli"
|
||||||
"interface.gnome"
|
"interface.labwc"
|
||||||
"interface.niri"
|
"interface.niri"
|
||||||
"platform.thinkpad-x1"
|
"platform.thinkpad-x1"
|
||||||
"security.fingerprint"
|
"security.fingerprint"
|
||||||
@@ -79,7 +81,7 @@
|
|||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.cli"
|
||||||
"interface.gnome"
|
"interface.labwc"
|
||||||
"interface.niri"
|
"interface.niri"
|
||||||
"networking.tailscale-client"
|
"networking.tailscale-client"
|
||||||
"platform.thinkpad-x1"
|
"platform.thinkpad-x1"
|
||||||
@@ -88,8 +90,38 @@
|
|||||||
"security.secure-boot"
|
"security.secure-boot"
|
||||||
"security.tpm-storage"
|
"security.tpm-storage"
|
||||||
"workload.development"
|
"workload.development"
|
||||||
|
"workload.game"
|
||||||
|
"workload.network-lab"
|
||||||
"workload.personal"
|
"workload.personal"
|
||||||
];
|
];
|
||||||
|
|
||||||
|
};
|
||||||
|
|
||||||
|
galleria = {
|
||||||
|
system = "x86_64-linux";
|
||||||
|
stateVersion = "26.05";
|
||||||
|
user = "moons";
|
||||||
|
path = ./galleria;
|
||||||
|
|
||||||
|
profiles = [
|
||||||
|
"base"
|
||||||
|
"interface.cli"
|
||||||
|
"interface.labwc"
|
||||||
|
"interface.niri"
|
||||||
|
"networking.tailscale-client"
|
||||||
|
"platform.intel-nvidia-desktop"
|
||||||
|
"security.secrets"
|
||||||
|
"security.secure-boot"
|
||||||
|
"security.tpm-storage"
|
||||||
|
"security.fingerprint"
|
||||||
|
"workload.development"
|
||||||
|
"workload.game"
|
||||||
|
"workload.machine-learning"
|
||||||
|
"workload.network-lab"
|
||||||
|
"workload.personal"
|
||||||
|
"workload.photography"
|
||||||
|
"workload.camera"
|
||||||
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
m2 = {
|
m2 = {
|
||||||
@@ -105,6 +137,7 @@
|
|||||||
"security.fingerprint"
|
"security.fingerprint"
|
||||||
# "security.secrets"
|
# "security.secrets"
|
||||||
"workload.development"
|
"workload.development"
|
||||||
|
"workload.game"
|
||||||
"workload.personal"
|
"workload.personal"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,91 @@
|
|||||||
|
_:
|
||||||
|
let
|
||||||
|
espPart = "/dev/disk/by-partuuid/008b04ef-9c06-4049-bffb-3906f5c3a9c1";
|
||||||
|
nixosPart = "/dev/disk/by-partuuid/04295552-cbb8-4511-ac1e-1171ec20f8d1";
|
||||||
|
|
||||||
|
btrfsMountOptions = [
|
||||||
|
"compress=zstd"
|
||||||
|
"noatime"
|
||||||
|
"ssd"
|
||||||
|
"space_cache=v2"
|
||||||
|
];
|
||||||
|
in
|
||||||
|
{
|
||||||
|
disko.enableConfig = true;
|
||||||
|
|
||||||
|
# These are deliberately partition paths, not the whole Windows disk. Disko
|
||||||
|
# must never own or destroy the disk's GPT or any Windows partition.
|
||||||
|
disko.devices.disk = {
|
||||||
|
esp = {
|
||||||
|
type = "disk";
|
||||||
|
device = espPart;
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
mountOptions = [ "umask=0077" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
nixos = {
|
||||||
|
type = "disk";
|
||||||
|
device = nixosPart;
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "luks";
|
||||||
|
name = "cryptroot";
|
||||||
|
askPassword = true;
|
||||||
|
settings.allowDiscards = true;
|
||||||
|
|
||||||
|
extraFormatArgs = [
|
||||||
|
"--type"
|
||||||
|
"luks2"
|
||||||
|
"--pbkdf"
|
||||||
|
"argon2id"
|
||||||
|
"--label"
|
||||||
|
"NixOS-LUKS"
|
||||||
|
];
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "btrfs";
|
||||||
|
extraArgs = [
|
||||||
|
"-f"
|
||||||
|
"-L"
|
||||||
|
"NixOS"
|
||||||
|
];
|
||||||
|
|
||||||
|
subvolumes = {
|
||||||
|
"@root" = {
|
||||||
|
mountpoint = "/";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@home" = {
|
||||||
|
mountpoint = "/home";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@nix" = {
|
||||||
|
mountpoint = "/nix";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@log" = {
|
||||||
|
mountpoint = "/var/log";
|
||||||
|
mountOptions = btrfsMountOptions;
|
||||||
|
};
|
||||||
|
|
||||||
|
"@swap" = {
|
||||||
|
mountpoint = "/.swapvol";
|
||||||
|
mountOptions = [ "noatime" ];
|
||||||
|
swap.swapfile.size = "32G";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||||
|
# and may be overwritten by future invocations. Please make changes
|
||||||
|
# to /etc/nixos/configuration.nix instead.
|
||||||
|
{
|
||||||
|
config,
|
||||||
|
lib,
|
||||||
|
modulesPath,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
(modulesPath + "/installer/scan/not-detected.nix")
|
||||||
|
];
|
||||||
|
|
||||||
|
boot.initrd.availableKernelModules = [
|
||||||
|
"xhci_pci"
|
||||||
|
"ahci"
|
||||||
|
"nvme"
|
||||||
|
"usbhid"
|
||||||
|
"usb_storage"
|
||||||
|
"sd_mod"
|
||||||
|
];
|
||||||
|
boot.initrd.kernelModules = [ ];
|
||||||
|
boot.kernelModules = [ "kvm-intel" ];
|
||||||
|
boot.extraModulePackages = [ ];
|
||||||
|
|
||||||
|
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||||
|
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
|
||||||
|
}
|
||||||
@@ -0,0 +1,51 @@
|
|||||||
|
{
|
||||||
|
lib,
|
||||||
|
config,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
{
|
||||||
|
# This desktop is permanently connected to AC power.
|
||||||
|
systemd.user.services.swayidle.Service.Environment = [
|
||||||
|
"SWAYIDLE_ASSUME_AC=1"
|
||||||
|
];
|
||||||
|
|
||||||
|
services.kanshi = {
|
||||||
|
enable = true;
|
||||||
|
|
||||||
|
settings = [
|
||||||
|
{
|
||||||
|
profile = {
|
||||||
|
name = "galleria";
|
||||||
|
|
||||||
|
outputs = [
|
||||||
|
{
|
||||||
|
criteria = "HDMI-A-1";
|
||||||
|
status = "enable";
|
||||||
|
position = "0,0";
|
||||||
|
scale = 1.5;
|
||||||
|
}
|
||||||
|
{
|
||||||
|
criteria = "DP-1";
|
||||||
|
status = "enable";
|
||||||
|
position = "2560,0";
|
||||||
|
}
|
||||||
|
{
|
||||||
|
criteria = "DP-2";
|
||||||
|
status = "enable";
|
||||||
|
position = "5120,0";
|
||||||
|
scale = 1.5;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
home.file.".wallpapers" = {
|
||||||
|
source = lib.mkForce (
|
||||||
|
config.lib.file.mkOutOfStoreSymlink "${config.home.homeDirectory}/Pictures/wallpapers"
|
||||||
|
);
|
||||||
|
|
||||||
|
recursive = lib.mkForce false;
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
{ inputs, pkgs, ... }:
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
./hardware-configuration.nix
|
||||||
|
./disko.nix
|
||||||
|
];
|
||||||
|
|
||||||
|
boot.initrd.luks.devices.cryptroot.device =
|
||||||
|
"/dev/disk/by-partuuid/04295552-cbb8-4511-ac1e-1171ec20f8d1";
|
||||||
|
|
||||||
|
# Keep Windows data and recovery partitions out of UDisks-based file
|
||||||
|
# managers. The shared EFI System Partition stays available as /boot.
|
||||||
|
services.udev.extraRules = ''
|
||||||
|
ENV{ID_PART_ENTRY_UUID}=="0480f887-d1f9-489d-b8fe-78549ced1938", ENV{UDISKS_IGNORE}="1"
|
||||||
|
ENV{ID_PART_ENTRY_UUID}=="6c70041b-3f65-4eb1-8b08-18ed20001877", ENV{UDISKS_IGNORE}="1"
|
||||||
|
'';
|
||||||
|
|
||||||
|
environment.systemPackages = with inputs.browser-previews.packages.${pkgs.system}; [
|
||||||
|
google-chrome-beta
|
||||||
|
];
|
||||||
|
}
|
||||||
+24
-24
@@ -31,6 +31,7 @@
|
|||||||
users.users.root.openssh.authorizedKeys.keys = [
|
users.users.root.openssh.authorizedKeys.keys = [
|
||||||
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIKhxDkucmeCor6CKoXAua7DgDSzuXrZOtpdkyzQxz5+aAAAABHNzaDo= moons@moons14.com"
|
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIKhxDkucmeCor6CKoXAua7DgDSzuXrZOtpdkyzQxz5+aAAAABHNzaDo= moons@moons14.com"
|
||||||
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIN6hZJyng/5LgFKPjR6uZAd/00UkO0vN0uQOoIvfSELdAAAABHNzaDo= moons@moons14.com"
|
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIN6hZJyng/5LgFKPjR6uZAd/00UkO0vN0uQOoIvfSELdAAAABHNzaDo= moons@moons14.com"
|
||||||
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPLwReAiwhXoO34S2+MrvqUhi8IWp4IzUq4OSp3niJdq"
|
||||||
];
|
];
|
||||||
|
|
||||||
environment.systemPackages = with pkgs; [
|
environment.systemPackages = with pkgs; [
|
||||||
@@ -51,6 +52,11 @@
|
|||||||
parted
|
parted
|
||||||
cryptsetup
|
cryptsetup
|
||||||
btrfs-progs
|
btrfs-progs
|
||||||
|
efibootmgr
|
||||||
|
pciutils
|
||||||
|
sbctl
|
||||||
|
tpm2-tools
|
||||||
|
util-linux
|
||||||
];
|
];
|
||||||
|
|
||||||
services.pcscd.enable = true;
|
services.pcscd.enable = true;
|
||||||
@@ -70,6 +76,12 @@
|
|||||||
║ ║
|
║ ║
|
||||||
║ Installation Workflow: ║
|
║ Installation Workflow: ║
|
||||||
║ ║
|
║ ║
|
||||||
|
║ Choose a guide after cloning: ║
|
||||||
|
║ Simple: docs/install-simple.md ║
|
||||||
|
║ SOPS + LUKS: docs/install.md ║
|
||||||
|
║ ║
|
||||||
|
║ The workflow below is for SOPS + LUKS: ║
|
||||||
|
║ ║
|
||||||
║ 1. Clone dotfiles: ║
|
║ 1. Clone dotfiles: ║
|
||||||
║ git clone git@github.com:moons-14/dotfiles.git ~/dotfiles║
|
║ git clone git@github.com:moons-14/dotfiles.git ~/dotfiles║
|
||||||
║ ║
|
║ ║
|
||||||
@@ -97,37 +109,25 @@
|
|||||||
║ # See hosts/x1g13/disko.nix for reference ║
|
║ # See hosts/x1g13/disko.nix for reference ║
|
||||||
║ ║
|
║ ║
|
||||||
║ 7. Partition disk with disko: ║
|
║ 7. Partition disk with disko: ║
|
||||||
║ nix run github:nix-community/disko -- \ ║
|
║ disko --mode destroy,format,mount \ ║
|
||||||
║ --mode disko hosts/<host>/disko.nix ║
|
║ hosts/<host>/disko.nix ║
|
||||||
║ ║
|
║ ║
|
||||||
║ 8. Copy host key to installed system: ║
|
║ 8. Generate hardware configuration: ║
|
||||||
|
║ nixos-generate-config --no-filesystems --root /mnt \ ║
|
||||||
|
║ --show-hardware-config > \ ║
|
||||||
|
║ ~/dotfiles/hosts/<host>/hardware-configuration.nix ║
|
||||||
|
║ # Import hardware-configuration.nix and disko.nix ║
|
||||||
|
║ # from hosts/<host>/nixos.nix ║
|
||||||
|
║ ║
|
||||||
|
║ 9. Copy host key to installed system: ║
|
||||||
║ mkdir -p /mnt/etc/ssh ║
|
║ mkdir -p /mnt/etc/ssh ║
|
||||||
║ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ ║
|
║ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ ║
|
||||||
║ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ║
|
║ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ║
|
||||||
║ ║
|
║ ║
|
||||||
║ 9. Install NixOS: ║
|
║ 10. Install NixOS: ║
|
||||||
║ nixos-install --flake ~/dotfiles#<host> ║
|
║ nixos-install --flake ~/dotfiles#<host> ║
|
||||||
║ ║
|
║ ║
|
||||||
║ Disko Configuration Examples: ║
|
║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║
|
||||||
║ ║
|
|
||||||
║ Simple (no encryption): ║
|
|
||||||
║ disko.devices.disk.main = { ║
|
|
||||||
║ type = "disk"; ║
|
|
||||||
║ device = "/dev/sda"; ║
|
|
||||||
║ content = { ║
|
|
||||||
║ type = "gpt"; ║
|
|
||||||
║ partitions = { ║
|
|
||||||
║ ESP = { size = "512M"; type = "EF00"; ║
|
|
||||||
║ content = { type = "filesystem"; ║
|
|
||||||
║ format = "vfat"; mountpoint = "/boot"; }; }; ║
|
|
||||||
║ root = { size = "100%"; ║
|
|
||||||
║ content = { type = "filesystem"; ║
|
|
||||||
║ format = "ext4"; mountpoint = "/"; }; }; ║
|
|
||||||
║ }; ║
|
|
||||||
║ }; ║
|
|
||||||
║ }; ║
|
|
||||||
║ ║
|
|
||||||
║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║
|
|
||||||
║ - Use partuuid for device path ║
|
║ - Use partuuid for device path ║
|
||||||
║ - Set askPassword = true for LUKS ║
|
║ - Set askPassword = true for LUKS ║
|
||||||
║ - Configure btrfs subvolumes ║
|
║ - Configure btrfs subvolumes ║
|
||||||
|
|||||||
@@ -1,36 +0,0 @@
|
|||||||
# Do not modify this file! It was generated by `nixos-generate-config` and may
|
|
||||||
# be overwritten by future invocations.
|
|
||||||
{ lib, modulesPath, ... }:
|
|
||||||
{
|
|
||||||
imports = [ (modulesPath + "/profiles/qemu-guest.nix") ];
|
|
||||||
|
|
||||||
boot.initrd.availableKernelModules = [
|
|
||||||
"ata_piix"
|
|
||||||
"uhci_hcd"
|
|
||||||
"virtio_pci"
|
|
||||||
"virtio_scsi"
|
|
||||||
"sd_mod"
|
|
||||||
"sr_mod"
|
|
||||||
];
|
|
||||||
boot.initrd.kernelModules = [ ];
|
|
||||||
boot.kernelModules = [ ];
|
|
||||||
boot.extraModulePackages = [ ];
|
|
||||||
|
|
||||||
fileSystems."/" = {
|
|
||||||
device = "/dev/disk/by-uuid/1b12ab98-2537-4207-a3f4-bb8ba7b53b00";
|
|
||||||
fsType = "ext4";
|
|
||||||
};
|
|
||||||
|
|
||||||
fileSystems."/boot" = {
|
|
||||||
device = "/dev/disk/by-uuid/8365-C778";
|
|
||||||
fsType = "vfat";
|
|
||||||
options = [
|
|
||||||
"fmask=0077"
|
|
||||||
"dmask=0077"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
swapDevices = [ ];
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
|
||||||
}
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
{
|
|
||||||
imports = [ ./hardware-configuration.nix ];
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
_: {
|
||||||
|
disko.enableConfig = true;
|
||||||
|
|
||||||
|
disko.devices.disk.main = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
ESP = {
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
root = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
# QEMU hardware baseline. Replace this with the output of
|
||||||
|
# `nixos-generate-config` after provisioning the VM if its hardware differs.
|
||||||
|
{
|
||||||
|
lib,
|
||||||
|
modulesPath,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
(modulesPath + "/profiles/qemu-guest.nix")
|
||||||
|
];
|
||||||
|
|
||||||
|
boot.initrd.availableKernelModules = [
|
||||||
|
"ata_piix"
|
||||||
|
"uhci_hcd"
|
||||||
|
"virtio_pci"
|
||||||
|
"virtio_scsi"
|
||||||
|
"sd_mod"
|
||||||
|
"sr_mod"
|
||||||
|
];
|
||||||
|
boot.initrd.kernelModules = [ ];
|
||||||
|
boot.kernelModules = [ ];
|
||||||
|
boot.extraModulePackages = [ ];
|
||||||
|
|
||||||
|
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||||
|
}
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
{
|
||||||
|
networking = {
|
||||||
|
interfaces = {
|
||||||
|
ens18 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.65.11";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens19 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.66.10";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens20 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.77.21";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
defaultGateway = {
|
||||||
|
address = "10.50.66.1";
|
||||||
|
interface = "ens19";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{
|
||||||
|
imports = [
|
||||||
|
./hardware-configuration.nix
|
||||||
|
./disko.nix
|
||||||
|
./networking.nix
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -0,0 +1,66 @@
|
|||||||
|
_:
|
||||||
|
let
|
||||||
|
osDisk = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
disko.enableConfig = true;
|
||||||
|
|
||||||
|
# The VM disks already contain live filesystems. Model each existing
|
||||||
|
# filesystem without giving Disko ownership of their partitioning or data.
|
||||||
|
disko.devices.disk = {
|
||||||
|
boot = {
|
||||||
|
type = "disk";
|
||||||
|
device = "${osDisk}-part1";
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
mountOptions = [ "umask=0077" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
root = {
|
||||||
|
type = "disk";
|
||||||
|
device = "${osDisk}-part2";
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
nix-build = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi1";
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/var/lib/nix-build";
|
||||||
|
mountOptions = [ "noatime" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
nix-store = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi2";
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/nix/store";
|
||||||
|
mountOptions = [ "noatime" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
fileSystems."/nix/store".neededForBoot = true;
|
||||||
|
nix.settings.build-dir = "/var/lib/nix-build";
|
||||||
|
services.fstrim.enable = true;
|
||||||
|
}
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
{
|
||||||
|
config,
|
||||||
|
pkgs,
|
||||||
|
primaryUser,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
let
|
||||||
|
homeDirectory = "/home/${primaryUser}";
|
||||||
|
fleetDirectory = "${homeDirectory}/srv/nix-fleet";
|
||||||
|
stateDirectory = "/var/lib/nix-fleet";
|
||||||
|
sourceDirectory = "${stateDirectory}/source";
|
||||||
|
|
||||||
|
git = "${pkgs.git}/bin/git";
|
||||||
|
nix = "${config.nix.package}/bin/nix";
|
||||||
|
rsync = "${pkgs.rsync}/bin/rsync";
|
||||||
|
|
||||||
|
cleanCheckoutConditions = [
|
||||||
|
"${git} -C ${fleetDirectory} diff --quiet"
|
||||||
|
"${git} -C ${fleetDirectory} diff --cached --quiet"
|
||||||
|
];
|
||||||
|
in
|
||||||
|
{
|
||||||
|
systemd.services.nix-fleet-converge = {
|
||||||
|
description = "Update inputs, build the fleet, and deploy changed hosts";
|
||||||
|
wants = [ "network-online.target" ];
|
||||||
|
after = [ "network-online.target" ];
|
||||||
|
|
||||||
|
environment = {
|
||||||
|
HOME = homeDirectory;
|
||||||
|
NIX_CONFIG = ''
|
||||||
|
accept-flake-config = true
|
||||||
|
max-jobs = 4
|
||||||
|
cores = 3
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
serviceConfig = {
|
||||||
|
Type = "oneshot";
|
||||||
|
User = primaryUser;
|
||||||
|
Restart = "on-failure";
|
||||||
|
RestartSec = "5min";
|
||||||
|
StateDirectory = "nix-fleet";
|
||||||
|
StateDirectoryMode = "0750";
|
||||||
|
WorkingDirectory = stateDirectory;
|
||||||
|
UMask = "0077";
|
||||||
|
ExecCondition = cleanCheckoutConditions;
|
||||||
|
EnvironmentFile = "${fleetDirectory}/.env";
|
||||||
|
|
||||||
|
# Work in a disposable copy so updating the dotfiles lock never dirties
|
||||||
|
# the operator's nix-fleet checkout.
|
||||||
|
ExecStart = [
|
||||||
|
"${git} -C ${fleetDirectory} pull --ff-only"
|
||||||
|
"${rsync} --archive --delete --exclude=.git/ --exclude=.direnv/ --exclude=.env --exclude=result --exclude=result-* ${fleetDirectory}/ ${sourceDirectory}/"
|
||||||
|
"${nix} flake update --flake ${sourceDirectory} dotfiles"
|
||||||
|
"${nix} run ${sourceDirectory}#converge -- ${sourceDirectory} ${stateDirectory}"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
systemd.timers.nix-fleet-converge = {
|
||||||
|
description = "Periodically converge the NixOS fleet";
|
||||||
|
wantedBy = [ "timers.target" ];
|
||||||
|
timerConfig = {
|
||||||
|
OnBootSec = "2min";
|
||||||
|
OnUnitInactiveSec = "5min";
|
||||||
|
RandomizedDelaySec = "30s";
|
||||||
|
Persistent = true;
|
||||||
|
Unit = "nix-fleet-converge.service";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# Only an actual successful deployment touches gc-request. This starts the
|
||||||
|
# builder's root nh-clean unit; remote host stores are never cleaned here.
|
||||||
|
systemd.paths.nix-fleet-gc = {
|
||||||
|
description = "Garbage-collect superseded fleet builds on nix-builder";
|
||||||
|
wantedBy = [ "multi-user.target" ];
|
||||||
|
pathConfig = {
|
||||||
|
PathChanged = "${stateDirectory}/gc-request";
|
||||||
|
Unit = "nh-clean.service";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||||
|
# and may be overwritten by future invocations. Please make changes
|
||||||
|
# to /etc/nixos/configuration.nix instead.
|
||||||
|
{ lib, modulesPath, ... }:
|
||||||
|
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
(modulesPath + "/profiles/qemu-guest.nix")
|
||||||
|
];
|
||||||
|
|
||||||
|
boot.initrd.availableKernelModules = [
|
||||||
|
"ata_piix"
|
||||||
|
"uhci_hcd"
|
||||||
|
"virtio_pci"
|
||||||
|
"virtio_scsi"
|
||||||
|
"sd_mod"
|
||||||
|
"sr_mod"
|
||||||
|
];
|
||||||
|
boot.initrd.kernelModules = [ ];
|
||||||
|
boot.kernelModules = [ ];
|
||||||
|
boot.extraModulePackages = [ ];
|
||||||
|
|
||||||
|
swapDevices = [ ];
|
||||||
|
|
||||||
|
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||||
|
}
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
{
|
||||||
|
lib,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
|
||||||
|
nix.settings = {
|
||||||
|
build-dir = "/var/lib/nix-build";
|
||||||
|
|
||||||
|
secret-key-files = [
|
||||||
|
"/var/lib/secrets/nix-cache-signing-key"
|
||||||
|
];
|
||||||
|
|
||||||
|
auto-optimise-store = lib.mkForce false;
|
||||||
|
keep-outputs = false;
|
||||||
|
keep-derivations = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
services.harmonia.cache = {
|
||||||
|
enable = true;
|
||||||
|
|
||||||
|
signKeyPaths = [
|
||||||
|
"/var/lib/secrets/nix-cache-signing-key"
|
||||||
|
];
|
||||||
|
|
||||||
|
settings = {
|
||||||
|
bind = "[::]:5000";
|
||||||
|
priority = 30;
|
||||||
|
workers = 4;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
networking.firewall.allowedTCPPorts = [
|
||||||
|
5000
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
{
|
||||||
|
networking = {
|
||||||
|
interfaces = {
|
||||||
|
ens18 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.65.10";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens19 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.77.10";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens20 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.68.10";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
defaultGateway = {
|
||||||
|
address = "10.50.68.1";
|
||||||
|
interface = "ens20";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{
|
||||||
|
imports = [
|
||||||
|
./fleet-automation.nix
|
||||||
|
./disko.nix
|
||||||
|
./hardware-configuration.nix
|
||||||
|
./harmonia.nix
|
||||||
|
./networking.nix
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -1,36 +0,0 @@
|
|||||||
# Do not modify this file! It was generated by `nixos-generate-config` and may
|
|
||||||
# be overwritten by future invocations.
|
|
||||||
{ lib, modulesPath, ... }:
|
|
||||||
{
|
|
||||||
imports = [ (modulesPath + "/profiles/qemu-guest.nix") ];
|
|
||||||
|
|
||||||
boot.initrd.availableKernelModules = [
|
|
||||||
"ata_piix"
|
|
||||||
"uhci_hcd"
|
|
||||||
"virtio_pci"
|
|
||||||
"virtio_scsi"
|
|
||||||
"sd_mod"
|
|
||||||
"sr_mod"
|
|
||||||
];
|
|
||||||
boot.initrd.kernelModules = [ ];
|
|
||||||
boot.kernelModules = [ ];
|
|
||||||
boot.extraModulePackages = [ ];
|
|
||||||
|
|
||||||
fileSystems."/" = {
|
|
||||||
device = "/dev/disk/by-uuid/8f0eaec6-5dc9-4821-aa8d-fb6809b5a5bf";
|
|
||||||
fsType = "ext4";
|
|
||||||
};
|
|
||||||
|
|
||||||
fileSystems."/boot" = {
|
|
||||||
device = "/dev/disk/by-uuid/201C-961B";
|
|
||||||
fsType = "vfat";
|
|
||||||
options = [
|
|
||||||
"fmask=0077"
|
|
||||||
"dmask=0077"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
swapDevices = [ ];
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
|
||||||
}
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
{
|
|
||||||
imports = [ ./hardware-configuration.nix ];
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
_: {
|
||||||
|
disko.enableConfig = true;
|
||||||
|
|
||||||
|
disko.devices.disk.main = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
ESP = {
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
root = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -1,8 +1,16 @@
|
|||||||
# Do not modify this file! It was generated by `nixos-generate-config` and may
|
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||||
# be overwritten by future invocations.
|
# and may be overwritten by future invocations. Please make changes
|
||||||
{ lib, modulesPath, ... }:
|
# to /etc/nixos/configuration.nix instead.
|
||||||
{
|
{
|
||||||
imports = [ (modulesPath + "/profiles/qemu-guest.nix") ];
|
lib,
|
||||||
|
modulesPath,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
(modulesPath + "/profiles/qemu-guest.nix")
|
||||||
|
];
|
||||||
|
|
||||||
boot.initrd.availableKernelModules = [
|
boot.initrd.availableKernelModules = [
|
||||||
"ata_piix"
|
"ata_piix"
|
||||||
@@ -16,21 +24,5 @@
|
|||||||
boot.kernelModules = [ ];
|
boot.kernelModules = [ ];
|
||||||
boot.extraModulePackages = [ ];
|
boot.extraModulePackages = [ ];
|
||||||
|
|
||||||
fileSystems."/" = {
|
|
||||||
device = "/dev/disk/by-uuid/69fa2193-1e4f-438a-8898-5de8a3f36e5b";
|
|
||||||
fsType = "ext4";
|
|
||||||
};
|
|
||||||
|
|
||||||
fileSystems."/boot" = {
|
|
||||||
device = "/dev/disk/by-uuid/D09B-4277";
|
|
||||||
fsType = "vfat";
|
|
||||||
options = [
|
|
||||||
"fmask=0077"
|
|
||||||
"dmask=0077"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
swapDevices = [ ];
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,40 @@
|
|||||||
|
{
|
||||||
|
networking = {
|
||||||
|
interfaces = {
|
||||||
|
ens18 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.65.100";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens19 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.80.10";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens20 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.77.20";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
defaultGateway = {
|
||||||
|
address = "10.50.80.1";
|
||||||
|
interface = "ens19";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
+5
-49
@@ -1,51 +1,7 @@
|
|||||||
{
|
{
|
||||||
imports = [ ./hardware-configuration.nix ];
|
imports = [
|
||||||
|
./hardware-configuration.nix
|
||||||
networking = {
|
./networking.nix
|
||||||
useDHCP = false;
|
./disko.nix
|
||||||
|
];
|
||||||
interfaces = {
|
|
||||||
ens18 = {
|
|
||||||
useDHCP = false;
|
|
||||||
ipv4.addresses = [
|
|
||||||
{
|
|
||||||
address = "10.50.128.20";
|
|
||||||
prefixLength = 24;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
ens19 = {
|
|
||||||
useDHCP = false;
|
|
||||||
ipv4.addresses = [
|
|
||||||
{
|
|
||||||
address = "10.50.7.101";
|
|
||||||
prefixLength = 24;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
ens20 = {
|
|
||||||
useDHCP = false;
|
|
||||||
ipv4.routes = [
|
|
||||||
{
|
|
||||||
address = "10.50.64.0";
|
|
||||||
prefixLength = 24;
|
|
||||||
via = "10.50.82.1";
|
|
||||||
}
|
|
||||||
];
|
|
||||||
ipv4.addresses = [
|
|
||||||
{
|
|
||||||
address = "10.50.82.10";
|
|
||||||
prefixLength = 24;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
defaultGateway = {
|
|
||||||
address = "10.50.128.1";
|
|
||||||
interface = "ens18";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
}
|
||||||
|
|||||||
+19
-6
@@ -1,9 +1,22 @@
|
|||||||
{
|
{
|
||||||
programs.niri.settings.outputs."eDP-1" = {
|
services.kanshi = {
|
||||||
scale = 1.2;
|
enable = true;
|
||||||
position = {
|
|
||||||
x = 0;
|
settings = [
|
||||||
y = 0;
|
{
|
||||||
};
|
profile = {
|
||||||
|
name = "x1g13";
|
||||||
|
|
||||||
|
outputs = [
|
||||||
|
{
|
||||||
|
criteria = "eDP-1";
|
||||||
|
status = "enable";
|
||||||
|
position = "0,0";
|
||||||
|
scale = 1.5;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
}
|
||||||
|
];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
+8
-2
@@ -74,7 +74,10 @@ let
|
|||||||
let
|
let
|
||||||
homePath = hostFile spec "home.nix";
|
homePath = hostFile spec "home.nix";
|
||||||
homeModules = [
|
homeModules = [
|
||||||
(registry.mkModule { class = "home"; })
|
(registry.mkModule {
|
||||||
|
class = "home";
|
||||||
|
systemClass = "nixos";
|
||||||
|
})
|
||||||
(registry.mkSelectionModule selected)
|
(registry.mkSelectionModule selected)
|
||||||
{ home.stateVersion = spec.stateVersion; }
|
{ home.stateVersion = spec.stateVersion; }
|
||||||
]
|
]
|
||||||
@@ -96,7 +99,10 @@ let
|
|||||||
let
|
let
|
||||||
homePath = hostFile spec "home.nix";
|
homePath = hostFile spec "home.nix";
|
||||||
homeModules = [
|
homeModules = [
|
||||||
(registry.mkModule { class = "home"; })
|
(registry.mkModule {
|
||||||
|
class = "home";
|
||||||
|
systemClass = "darwin";
|
||||||
|
})
|
||||||
(registry.mkSelectionModule selected)
|
(registry.mkSelectionModule selected)
|
||||||
{ home.stateVersion = spec.stateVersion; }
|
{ home.stateVersion = spec.stateVersion; }
|
||||||
]
|
]
|
||||||
|
|||||||
+77
-15
@@ -4,7 +4,7 @@
|
|||||||
modulesRoot,
|
modulesRoot,
|
||||||
}:
|
}:
|
||||||
let
|
let
|
||||||
reservedFiles = {
|
rootFragmentFiles = {
|
||||||
common = "common.nix";
|
common = "common.nix";
|
||||||
nixos = "nixos.nix";
|
nixos = "nixos.nix";
|
||||||
darwin = "darwin.nix";
|
darwin = "darwin.nix";
|
||||||
@@ -12,6 +12,14 @@ let
|
|||||||
meta = "meta.nix";
|
meta = "meta.nix";
|
||||||
};
|
};
|
||||||
|
|
||||||
|
homeFragmentFiles = {
|
||||||
|
homeCommon = "common.nix";
|
||||||
|
homeNixos = "nixos.nix";
|
||||||
|
homeDarwin = "darwin.nix";
|
||||||
|
};
|
||||||
|
|
||||||
|
fragmentFileNames = rootFragmentFiles // lib.mapAttrs (_: name: "home/${name}") homeFragmentFiles;
|
||||||
|
|
||||||
isFile = kind: kind == "regular" || kind == "symlink";
|
isFile = kind: kind == "regular" || kind == "symlink";
|
||||||
|
|
||||||
ensure =
|
ensure =
|
||||||
@@ -103,13 +111,17 @@ let
|
|||||||
);
|
);
|
||||||
|
|
||||||
makeUnit =
|
makeUnit =
|
||||||
relativePath: entries:
|
relativePath: entries: homeEntries:
|
||||||
let
|
let
|
||||||
directory = pathFor relativePath;
|
directory = pathFor relativePath;
|
||||||
id = lib.concatStringsSep "." relativePath;
|
id = lib.concatStringsSep "." relativePath;
|
||||||
fragments = lib.mapAttrs (
|
rootFragments = lib.mapAttrs (
|
||||||
_class: fileName: if entryIsFile entries fileName then directory + "/${fileName}" else null
|
_class: fileName: if entryIsFile entries fileName then directory + "/${fileName}" else null
|
||||||
) reservedFiles;
|
) rootFragmentFiles;
|
||||||
|
homeFragments = lib.mapAttrs (
|
||||||
|
_class: fileName: if entryIsFile homeEntries fileName then directory + "/home/${fileName}" else null
|
||||||
|
) homeFragmentFiles;
|
||||||
|
fragments = rootFragments // homeFragments;
|
||||||
baseUnit = {
|
baseUnit = {
|
||||||
inherit
|
inherit
|
||||||
id
|
id
|
||||||
@@ -138,11 +150,22 @@ let
|
|||||||
let
|
let
|
||||||
directory = pathFor relativePath;
|
directory = pathFor relativePath;
|
||||||
entries = builtins.readDir directory;
|
entries = builtins.readDir directory;
|
||||||
hasReservedFile = lib.any (fileName: entryIsFile entries fileName) (
|
homeEntries =
|
||||||
builtins.attrValues reservedFiles
|
if relativePath != [ ] && (entries.home or null) == "directory" then
|
||||||
|
builtins.readDir (directory + "/home")
|
||||||
|
else
|
||||||
|
{ };
|
||||||
|
hasRootFragment = lib.any (fileName: entryIsFile entries fileName) (
|
||||||
|
builtins.attrValues rootFragmentFiles
|
||||||
);
|
);
|
||||||
childDirectories = lib.filter (name: entries.${name} == "directory") (builtins.attrNames entries);
|
hasHomeFragment = lib.any (fileName: entryIsFile homeEntries fileName) (
|
||||||
current = lib.optional hasReservedFile (makeUnit relativePath entries);
|
builtins.attrValues homeFragmentFiles
|
||||||
|
);
|
||||||
|
hasFragment = hasRootFragment || hasHomeFragment;
|
||||||
|
childDirectories = lib.filter (
|
||||||
|
name: entries.${name} == "directory" && !(name == "home" && hasHomeFragment)
|
||||||
|
) (builtins.attrNames entries);
|
||||||
|
current = lib.optional hasFragment (makeUnit relativePath entries homeEntries);
|
||||||
children = lib.concatMap (name: walk (relativePath ++ [ name ])) childDirectories;
|
children = lib.concatMap (name: walk (relativePath ++ [ name ])) childDirectories;
|
||||||
in
|
in
|
||||||
current ++ children;
|
current ++ children;
|
||||||
@@ -208,12 +231,44 @@ let
|
|||||||
"common"
|
"common"
|
||||||
"darwin"
|
"darwin"
|
||||||
];
|
];
|
||||||
home = [ "home" ];
|
home = {
|
||||||
|
nixos = [
|
||||||
|
"home"
|
||||||
|
"homeCommon"
|
||||||
|
"homeNixos"
|
||||||
|
];
|
||||||
|
darwin = [
|
||||||
|
"home"
|
||||||
|
"homeCommon"
|
||||||
|
"homeDarwin"
|
||||||
|
];
|
||||||
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
fragmentClassesFor =
|
||||||
|
{
|
||||||
|
class,
|
||||||
|
systemClass,
|
||||||
|
}:
|
||||||
|
ensure (builtins.hasAttr class fragmentClasses) "unsupported module class '${class}'" (
|
||||||
|
if class == "home" then
|
||||||
|
ensure
|
||||||
|
(builtins.elem systemClass [
|
||||||
|
"nixos"
|
||||||
|
"darwin"
|
||||||
|
])
|
||||||
|
"the home module class requires systemClass to be 'nixos' or 'darwin'"
|
||||||
|
fragmentClasses.home.${systemClass}
|
||||||
|
else
|
||||||
|
ensure (
|
||||||
|
systemClass == null
|
||||||
|
) "systemClass is only supported for the home module class" fragmentClasses.${class}
|
||||||
|
);
|
||||||
|
|
||||||
applyFragment =
|
applyFragment =
|
||||||
{
|
{
|
||||||
config,
|
config,
|
||||||
|
fragmentName,
|
||||||
fragmentPath,
|
fragmentPath,
|
||||||
options,
|
options,
|
||||||
specialArgs,
|
specialArgs,
|
||||||
@@ -244,8 +299,7 @@ let
|
|||||||
);
|
);
|
||||||
resultValue = if builtins.isFunction fragment then fragment fragmentArgs else fragment;
|
resultValue = if builtins.isFunction fragment then fragment fragmentArgs else fragment;
|
||||||
result =
|
result =
|
||||||
ensure (builtins.isAttrs resultValue)
|
ensure (builtins.isAttrs resultValue) "${unit.id}: ${fragmentName} must return an attribute set"
|
||||||
"${unit.id}: ${builtins.baseNameOf fragmentPath} must return an attribute set"
|
|
||||||
resultValue;
|
resultValue;
|
||||||
forbiddenKeys = lib.filter (name: builtins.hasAttr name result) [
|
forbiddenKeys = lib.filter (name: builtins.hasAttr name result) [
|
||||||
"imports"
|
"imports"
|
||||||
@@ -254,14 +308,20 @@ let
|
|||||||
];
|
];
|
||||||
in
|
in
|
||||||
ensure (forbiddenKeys == [ ])
|
ensure (forbiddenKeys == [ ])
|
||||||
"${unit.id}: ${builtins.baseNameOf fragmentPath} is a configuration fragment and cannot define top-level ${lib.concatStringsSep ", " forbiddenKeys}"
|
"${unit.id}: ${fragmentName} is a configuration fragment and cannot define top-level ${lib.concatStringsSep ", " forbiddenKeys}"
|
||||||
result;
|
result;
|
||||||
|
|
||||||
externalImports = class: lib.concatMap (unit: unit.meta.imports.${class}) discoveredUnits;
|
externalImports = class: lib.concatMap (unit: unit.meta.imports.${class}) discoveredUnits;
|
||||||
|
|
||||||
mkModule =
|
mkModule =
|
||||||
{ class }:
|
{
|
||||||
ensure (builtins.hasAttr class fragmentClasses) "unsupported module class '${class}'" (
|
class,
|
||||||
|
systemClass ? null,
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
selectedFragmentClasses = fragmentClassesFor { inherit class systemClass; };
|
||||||
|
in
|
||||||
|
builtins.seq selectedFragmentClasses (
|
||||||
builtins.seq dependencyValidation (
|
builtins.seq dependencyValidation (
|
||||||
{
|
{
|
||||||
config,
|
config,
|
||||||
@@ -277,6 +337,7 @@ let
|
|||||||
map (
|
map (
|
||||||
fragmentClass:
|
fragmentClass:
|
||||||
let
|
let
|
||||||
|
fragmentName = fragmentFileNames.${fragmentClass};
|
||||||
fragmentPath = unit.fragments.${fragmentClass};
|
fragmentPath = unit.fragments.${fragmentClass};
|
||||||
in
|
in
|
||||||
if fragmentPath == null then
|
if fragmentPath == null then
|
||||||
@@ -285,13 +346,14 @@ let
|
|||||||
lib.mkIf (enabled config unit) (applyFragment {
|
lib.mkIf (enabled config unit) (applyFragment {
|
||||||
inherit
|
inherit
|
||||||
config
|
config
|
||||||
|
fragmentName
|
||||||
fragmentPath
|
fragmentPath
|
||||||
options
|
options
|
||||||
specialArgs
|
specialArgs
|
||||||
unit
|
unit
|
||||||
;
|
;
|
||||||
})
|
})
|
||||||
) fragmentClasses.${class}
|
) selectedFragmentClasses
|
||||||
)
|
)
|
||||||
) discoveredUnits;
|
) discoveredUnits;
|
||||||
in
|
in
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
_: {
|
||||||
|
programs._1password-gui.enable = true;
|
||||||
|
programs._1password.enable = true;
|
||||||
|
}
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
{
|
|
||||||
# The macOS app must live in /Applications for its background integrations,
|
|
||||||
# including the SSH agent, to work correctly.
|
|
||||||
homebrew = {
|
|
||||||
enable = true;
|
|
||||||
casks = [ "1password" ];
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
{ pkgs, ... }:
|
|
||||||
{
|
|
||||||
home.packages = [
|
|
||||||
pkgs._1password-cli
|
|
||||||
]
|
|
||||||
++ pkgs.lib.optionals pkgs.stdenv.hostPlatform.isLinux [ pkgs._1password-gui ];
|
|
||||||
}
|
|
||||||
@@ -1,11 +1,8 @@
|
|||||||
{ primaryUser, lib, ... }:
|
{ primaryUser, lib, ... }:
|
||||||
{
|
{
|
||||||
programs._1password.enable = true;
|
programs._1password-gui.polkitPolicyOwners = [ primaryUser ];
|
||||||
programs._1password-gui = {
|
|
||||||
enable = true;
|
|
||||||
polkitPolicyOwners = [ primaryUser ];
|
|
||||||
};
|
|
||||||
|
|
||||||
|
# 1Password SSH Agentと競合するagentを無効化
|
||||||
programs.ssh.startAgent = lib.mkForce false;
|
programs.ssh.startAgent = lib.mkForce false;
|
||||||
programs.gnupg.agent.enableSSHSupport = lib.mkForce false;
|
programs.gnupg.agent.enableSSHSupport = lib.mkForce false;
|
||||||
services.gnome.gcr-ssh-agent.enable = lib.mkForce false;
|
services.gnome.gcr-ssh-agent.enable = lib.mkForce false;
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
{
|
||||||
|
homebrew.casks = [ "activitywatch" ];
|
||||||
|
|
||||||
|
launchd.agents.activitywatch = {
|
||||||
|
command = "/usr/bin/open -gja ActivityWatch";
|
||||||
|
serviceConfig.RunAtLoad = true;
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
services.activitywatch = {
|
||||||
|
enable = true;
|
||||||
|
|
||||||
|
watchers.aw-awatcher = {
|
||||||
|
package = pkgs.awatcher;
|
||||||
|
executable = "awatcher";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
{
|
||||||
|
description = "ActivityWatch automated time tracker";
|
||||||
|
}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{
|
||||||
|
programs.atuin = {
|
||||||
|
enable = true;
|
||||||
|
|
||||||
|
enableZshIntegration = true;
|
||||||
|
enableBashIntegration = true;
|
||||||
|
enableFishIntegration = true;
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.baobab ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.celluloid ];
|
||||||
|
|
||||||
|
xdg.mimeApps = {
|
||||||
|
enable = true;
|
||||||
|
defaultApplicationPackages = [ pkgs.celluloid ];
|
||||||
|
defaultApplications = builtins.listToAttrs (
|
||||||
|
map
|
||||||
|
(mime: {
|
||||||
|
name = mime;
|
||||||
|
value = [ "io.github.celluloid_player.Celluloid.desktop" ];
|
||||||
|
})
|
||||||
|
[
|
||||||
|
"video/3gpp"
|
||||||
|
"video/3gpp2"
|
||||||
|
"video/mp2t"
|
||||||
|
"video/mp4"
|
||||||
|
"video/mpeg"
|
||||||
|
"video/ogg"
|
||||||
|
"video/quicktime"
|
||||||
|
"video/webm"
|
||||||
|
"video/x-flv"
|
||||||
|
"video/x-m4v"
|
||||||
|
"video/x-matroska"
|
||||||
|
"video/x-msvideo"
|
||||||
|
"video/x-ms-wmv"
|
||||||
|
]
|
||||||
|
);
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
{ lib, pkgs, ... }:
|
|
||||||
lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
|
|
||||||
home.packages = [ pkgs.google-chrome ];
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
{
|
||||||
|
config,
|
||||||
|
lib,
|
||||||
|
pkgs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
chrome = pkgs.google-chrome.overrideAttrs (old: {
|
||||||
|
nativeBuildInputs = (old.nativeBuildInputs or [ ]) ++ [ pkgs.makeWrapper ];
|
||||||
|
|
||||||
|
postFixup = (old.postFixup or "") + ''
|
||||||
|
wrapProgram $out/bin/google-chrome-stable \
|
||||||
|
--set LIBVA_DRIVER_NAME nvidia \
|
||||||
|
--set NVD_BACKEND direct
|
||||||
|
'';
|
||||||
|
});
|
||||||
|
|
||||||
|
features = [
|
||||||
|
"MiddleClickAutoscroll"
|
||||||
|
"AcceleratedVideoDecoder"
|
||||||
|
"AcceleratedVideoDecodeLinuxGL"
|
||||||
|
"PlatformHEVCDecoderSupport"
|
||||||
|
]
|
||||||
|
++ lib.optional config.my.hardwares.nvidia.enable "VaapiOnNvidiaGPUs";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
programs.google-chrome = {
|
||||||
|
enable = true;
|
||||||
|
package = if config.my.hardwares.nvidia.enable then chrome else pkgs.google-chrome;
|
||||||
|
|
||||||
|
commandLineArgs = [
|
||||||
|
"--enable-features=${lib.concatStringsSep "," features}"
|
||||||
|
"--use-gl=angle"
|
||||||
|
"--use-angle=gl"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
xdg.mimeApps = {
|
||||||
|
enable = true;
|
||||||
|
|
||||||
|
defaultApplications = {
|
||||||
|
"text/html" = "google-chrome.desktop";
|
||||||
|
"x-scheme-handler/http" = "google-chrome.desktop";
|
||||||
|
"x-scheme-handler/https" = "google-chrome.desktop";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -1,25 +0,0 @@
|
|||||||
{ pkgs, ... }:
|
|
||||||
let
|
|
||||||
chromeLauncher = pkgs.makeDesktopItem {
|
|
||||||
name = "google-chrome";
|
|
||||||
desktopName = "Google Chrome";
|
|
||||||
genericName = "Web Browser";
|
|
||||||
exec = "${pkgs.google-chrome}/bin/google-chrome-stable --enable-features=TouchpadOverscrollHistoryNavigation %U";
|
|
||||||
icon = "google-chrome";
|
|
||||||
terminal = false;
|
|
||||||
categories = [
|
|
||||||
"Network"
|
|
||||||
"WebBrowser"
|
|
||||||
];
|
|
||||||
startupNotify = true;
|
|
||||||
};
|
|
||||||
in
|
|
||||||
{
|
|
||||||
environment.systemPackages = [ chromeLauncher ];
|
|
||||||
|
|
||||||
xdg.mime.defaultApplications = {
|
|
||||||
"text/html" = "google-chrome.desktop";
|
|
||||||
"x-scheme-handler/http" = "google-chrome.desktop";
|
|
||||||
"x-scheme-handler/https" = "google-chrome.desktop";
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,10 +1,5 @@
|
|||||||
{ inputs, ... }:
|
_: {
|
||||||
{
|
|
||||||
description = "Codex Desktop for Linux";
|
description = "Codex Desktop for Linux";
|
||||||
|
|
||||||
includes = [ "applications.codex" ];
|
includes = [ "applications.codex" ];
|
||||||
|
|
||||||
imports.nixos = [
|
|
||||||
inputs.codex-desktop-linux.nixosModules.default
|
|
||||||
];
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,37 +1,10 @@
|
|||||||
{
|
{
|
||||||
inputs,
|
inputs,
|
||||||
lib,
|
|
||||||
pkgs,
|
pkgs,
|
||||||
...
|
...
|
||||||
}:
|
}:
|
||||||
let
|
|
||||||
codexCliPackage = inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.codex;
|
|
||||||
codexDesktopPackage =
|
|
||||||
inputs.codex-desktop-linux.packages.${pkgs.stdenv.hostPlatform.system}.codex-desktop-computer-use-ui;
|
|
||||||
launcher = pkgs.makeDesktopItem {
|
|
||||||
name = "codex";
|
|
||||||
desktopName = "Codex";
|
|
||||||
genericName = "ChatGPT Desktop";
|
|
||||||
comment = "Run Codex Desktop";
|
|
||||||
exec = "env CODEX_CLI_PATH=${lib.getExe' codexCliPackage "codex"} BAMF_DESKTOP_FILE_HINT=codex.desktop CHROME_DESKTOP=codex.desktop ${lib.getExe' codexDesktopPackage "codex-desktop"} %u";
|
|
||||||
icon = "codex-desktop";
|
|
||||||
terminal = false;
|
|
||||||
categories = [ "Development" ];
|
|
||||||
startupNotify = true;
|
|
||||||
startupWMClass = "codex-desktop";
|
|
||||||
actions.new-window = {
|
|
||||||
name = "New Window";
|
|
||||||
exec = "env CODEX_CLI_PATH=${lib.getExe' codexCliPackage "codex"} BAMF_DESKTOP_FILE_HINT=codex.desktop CHROME_DESKTOP=codex.desktop CODEX_MULTI_LAUNCH=1 ${lib.getExe' codexDesktopPackage "codex-desktop"} --new-instance";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
in
|
|
||||||
{
|
{
|
||||||
programs.codexDesktopLinux = {
|
environment.systemPackages = [
|
||||||
enable = true;
|
inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.chatgpt
|
||||||
package = codexDesktopPackage;
|
];
|
||||||
cliPackage = codexCliPackage;
|
|
||||||
computerUseUi.enable = true;
|
|
||||||
};
|
|
||||||
|
|
||||||
environment.systemPackages = [ launcher ];
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,52 @@
|
|||||||
|
{
|
||||||
|
lib,
|
||||||
|
pkgs,
|
||||||
|
inputs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
codexSessionUsage = inputs.codex-session-usage.packages.${pkgs.stdenv.hostPlatform.system}.default;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
home.packages = [ codexSessionUsage ];
|
||||||
|
|
||||||
|
xdg.dataFile = {
|
||||||
|
"vicinae/scripts/codex-session-usage/start" = {
|
||||||
|
executable = true;
|
||||||
|
text = ''
|
||||||
|
#!${lib.getExe pkgs.bash}
|
||||||
|
# @vicinae.schemaVersion 1
|
||||||
|
# @vicinae.title Start Codex Session Usage
|
||||||
|
# @vicinae.description Start the local Codex session usage dashboard
|
||||||
|
# @vicinae.mode compact
|
||||||
|
# @vicinae.icon 📊
|
||||||
|
# @vicinae.argument1 { "type": "text", "placeholder": "Port (optional)", "optional": true }
|
||||||
|
|
||||||
|
if [[ -z "$1" ]]; then
|
||||||
|
exec ${lib.getExe codexSessionUsage} start
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "$1" =~ ^[0-9]+$ ]] && (( 10#$1 >= 1 && 10#$1 <= 65535 )); then
|
||||||
|
exec ${lib.getExe codexSessionUsage} start --port "$1"
|
||||||
|
fi
|
||||||
|
|
||||||
|
printf '%s\n' 'Port must be an integer between 1 and 65535.' >&2
|
||||||
|
exit 2
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
"vicinae/scripts/codex-session-usage/stop" = {
|
||||||
|
executable = true;
|
||||||
|
text = ''
|
||||||
|
#!${lib.getExe pkgs.bash}
|
||||||
|
# @vicinae.schemaVersion 1
|
||||||
|
# @vicinae.title Stop Codex Session Usage
|
||||||
|
# @vicinae.description Stop the local Codex session usage dashboard
|
||||||
|
# @vicinae.mode compact
|
||||||
|
# @vicinae.icon 📊
|
||||||
|
|
||||||
|
exec ${lib.getExe codexSessionUsage} stop
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
model = "gpt-5.6-sol"
|
||||||
|
model_reasoning_effort = "medium"
|
||||||
|
|
||||||
|
approval_policy = "on-request"
|
||||||
|
approvals_reviewer = "auto_review"
|
||||||
|
sandbox_mode = "workspace-write"
|
||||||
|
web_search = "cached"
|
||||||
|
|
||||||
|
[sandbox_workspace_write]
|
||||||
|
network_access = false
|
||||||
|
|
||||||
|
[projects."/home/moons/dotfiles"]
|
||||||
|
trust_level = "trusted"
|
||||||
@@ -1,6 +1,36 @@
|
|||||||
{ inputs, pkgs, ... }:
|
|
||||||
{
|
{
|
||||||
home.packages = [
|
config,
|
||||||
inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.codex
|
inputs,
|
||||||
];
|
lib,
|
||||||
|
pkgs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
configDirectory =
|
||||||
|
if config.home.preferXdgDirectories then
|
||||||
|
"${config.xdg.configHome}/codex"
|
||||||
|
else
|
||||||
|
"${config.home.homeDirectory}/.codex";
|
||||||
|
configFile = "${configDirectory}/config.toml";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
programs.codex = {
|
||||||
|
enable = true;
|
||||||
|
package = inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.codex;
|
||||||
|
|
||||||
|
skills = {
|
||||||
|
grilling = inputs.skills + "/skills/productivity/grilling";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# Keep the repository copy as an initial value. Codex may mutate the live
|
||||||
|
# file between activations; each Home Manager switch resets it from here.
|
||||||
|
home.activation.resetCodexConfig = {
|
||||||
|
after = [ "writeBoundary" ];
|
||||||
|
before = [ ];
|
||||||
|
data = ''
|
||||||
|
${pkgs.coreutils}/bin/mkdir -p ${lib.escapeShellArg configDirectory}
|
||||||
|
${pkgs.coreutils}/bin/install -m 0600 ${./config.toml} ${lib.escapeShellArg configFile}
|
||||||
|
'';
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
{ inputs, ... }:
|
||||||
|
{
|
||||||
|
description = "Container-based networking labs";
|
||||||
|
|
||||||
|
includes = [ "services.docker" ];
|
||||||
|
|
||||||
|
imports.nixos = [ inputs.containerlab.nixosModules.default ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
pkgs,
|
||||||
|
primaryUser,
|
||||||
|
}:
|
||||||
|
{
|
||||||
|
programs.containerlab.enable = true;
|
||||||
|
|
||||||
|
users.users.${primaryUser}.extraGroups = [ "clab_admins" ];
|
||||||
|
|
||||||
|
programs.containerlab.package =
|
||||||
|
inputs.containerlab.packages.${pkgs.stdenv.hostPlatform.system}.default.overrideAttrs
|
||||||
|
(_old: {
|
||||||
|
vendorHash = "sha256-QIJDPSO/504oYSeHzCSmdt7CtU/P/v74oub2feDXWXY=";
|
||||||
|
});
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
osConfig,
|
||||||
|
pkgs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
unstable = import inputs.nixpkgs-unstable {
|
||||||
|
inherit (pkgs.stdenv.hostPlatform) system;
|
||||||
|
# Keep default CUDA targets so dependencies match the CUDA binary cache.
|
||||||
|
config = pkgs.config // {
|
||||||
|
cudaSupport = osConfig.my.hardwares.nvidia.enable;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
in
|
||||||
|
{
|
||||||
|
home.packages = [
|
||||||
|
(unstable.darktable.override {
|
||||||
|
withAi = true;
|
||||||
|
})
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -2,5 +2,9 @@
|
|||||||
programs.direnv = {
|
programs.direnv = {
|
||||||
enable = true;
|
enable = true;
|
||||||
nix-direnv.enable = true;
|
nix-direnv.enable = true;
|
||||||
|
|
||||||
|
config.global = {
|
||||||
|
warn_timeout = "10s";
|
||||||
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,4 +1,108 @@
|
|||||||
{ lib, pkgs, ... }:
|
{
|
||||||
lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
|
inputs,
|
||||||
programs.vesktop.enable = true;
|
pkgs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
unstable = inputs.nixpkgs-unstable.legacyPackages.${pkgs.stdenv.hostPlatform.system};
|
||||||
|
in
|
||||||
|
{
|
||||||
|
programs.vesktop = {
|
||||||
|
enable = true;
|
||||||
|
package = unstable.vesktop;
|
||||||
|
|
||||||
|
settings = {
|
||||||
|
discordBranch = "stable";
|
||||||
|
|
||||||
|
hardwareAcceleration = true;
|
||||||
|
hardwareVideoAcceleration = true;
|
||||||
|
|
||||||
|
tray = true;
|
||||||
|
minimizeToTray = true;
|
||||||
|
|
||||||
|
# Discord Rich Presence
|
||||||
|
arRPC = true;
|
||||||
|
|
||||||
|
openLinksWithElectron = false;
|
||||||
|
|
||||||
|
# Keep WebRTC on the public interface selected by the default route.
|
||||||
|
# Secondary private interfaces can otherwise stall voice at DTLS.
|
||||||
|
webRTCIPHandlingPolicy = "default_public_interface_only";
|
||||||
|
|
||||||
|
spellCheckLanguages = [
|
||||||
|
"ja-JP"
|
||||||
|
"en-US"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
vencord = {
|
||||||
|
useSystem = false;
|
||||||
|
|
||||||
|
settings = {
|
||||||
|
autoUpdate = true;
|
||||||
|
autoUpdateNotification = false;
|
||||||
|
|
||||||
|
useQuickCss = false;
|
||||||
|
|
||||||
|
cloud.settingsSync = false;
|
||||||
|
|
||||||
|
notifications = {
|
||||||
|
position = "bottom-right";
|
||||||
|
useNative = "not-focused";
|
||||||
|
timeout = 5000;
|
||||||
|
logLimit = 50;
|
||||||
|
};
|
||||||
|
|
||||||
|
plugins = {
|
||||||
|
# プライバシー・安全性
|
||||||
|
NoTrack.enabled = true;
|
||||||
|
ClearURLs.enabled = true;
|
||||||
|
|
||||||
|
# 設定・セッション
|
||||||
|
BetterSettings.enabled = true;
|
||||||
|
BetterSessions.enabled = true;
|
||||||
|
|
||||||
|
# 画像・添付ファイル
|
||||||
|
FixImagesQuality.enabled = true;
|
||||||
|
ImageZoom.enabled = true;
|
||||||
|
ViewIcons.enabled = true;
|
||||||
|
CopyFileContents.enabled = true;
|
||||||
|
|
||||||
|
# メッセージ操作
|
||||||
|
QuickReply.enabled = true;
|
||||||
|
SendTimestamps.enabled = true;
|
||||||
|
FullSearchContext.enabled = true;
|
||||||
|
MessageLinkEmbeds.enabled = true;
|
||||||
|
Unindent.enabled = true;
|
||||||
|
ValidReply.enabled = true;
|
||||||
|
|
||||||
|
# 通知・誤操作対策
|
||||||
|
ReadAllNotificationsButton.enabled = true;
|
||||||
|
NoReplyMention.enabled = true;
|
||||||
|
NotificationVolume.enabled = true;
|
||||||
|
|
||||||
|
# UI・パフォーマンス
|
||||||
|
NoTypingAnimation.enabled = true;
|
||||||
|
FavoriteEmojiFirst.enabled = true;
|
||||||
|
KeepCurrentChannel.enabled = true;
|
||||||
|
|
||||||
|
# サーバー・権限確認
|
||||||
|
PermissionsViewer.enabled = true;
|
||||||
|
MemberCount.enabled = true;
|
||||||
|
|
||||||
|
# ボイス・アクティビティ
|
||||||
|
CallTimer.enabled = true;
|
||||||
|
GameActivityToggle.enabled = true;
|
||||||
|
|
||||||
|
# Vesktop向け
|
||||||
|
WebKeybinds.enabled = true;
|
||||||
|
WebScreenShareFixes.enabled = true;
|
||||||
|
|
||||||
|
# Message history
|
||||||
|
MessageLogger.enabled = true;
|
||||||
|
ShowHiddenChannels.enabled = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,17 +0,0 @@
|
|||||||
{ pkgs, ... }:
|
|
||||||
let
|
|
||||||
oxker = pkgs.oxker.overrideAttrs (oldAttrs: {
|
|
||||||
checkFlags =
|
|
||||||
(oldAttrs.checkFlags or [ ])
|
|
||||||
++ pkgs.lib.optionals pkgs.stdenv.hostPlatform.isDarwin [
|
|
||||||
"--skip=ui::draw_blocks::help::tests::test_draw_blocks_help_custom_keymap_one_two_definition"
|
|
||||||
"--skip=ui::draw_blocks::help::tests::test_draw_blocks_help_custom_keymap_two_definition"
|
|
||||||
];
|
|
||||||
});
|
|
||||||
in
|
|
||||||
{
|
|
||||||
home.packages = [
|
|
||||||
pkgs.docker-client
|
|
||||||
oxker
|
|
||||||
];
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [
|
||||||
|
pkgs.docker-client
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [
|
||||||
|
pkgs.oxker
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
{ lib, pkgs, ... }:
|
{ pkgs, ... }:
|
||||||
lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
|
{
|
||||||
home.packages = [ pkgs.drawio ];
|
home.packages = [ pkgs.drawio ];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.easyeffects ];
|
||||||
|
}
|
||||||
@@ -1,69 +0,0 @@
|
|||||||
[Hotkey]
|
|
||||||
# トリガーキーを押すたびに切り替える
|
|
||||||
EnumerateWithTriggerKeys=False
|
|
||||||
# 一時的に第1入力メソッドに切り替える
|
|
||||||
AltTriggerKeys=
|
|
||||||
# 切り替え時は第1入力メソッドをスキップする
|
|
||||||
EnumerateSkipFirst=False
|
|
||||||
# Time limit in milliseconds for triggering modifier key shortcuts
|
|
||||||
ModifierOnlyKeyTimeout=250
|
|
||||||
|
|
||||||
[Hotkey/TriggerKeys]
|
|
||||||
1=Zenkaku_Hankaku
|
|
||||||
|
|
||||||
[Hotkey/ActivateKeys]
|
|
||||||
0=Henkan
|
|
||||||
|
|
||||||
[Hotkey/DeactivateKeys]
|
|
||||||
0=Muhenkan
|
|
||||||
|
|
||||||
[Hotkey/PrevPage]
|
|
||||||
0=Up
|
|
||||||
|
|
||||||
[Hotkey/NextPage]
|
|
||||||
0=Down
|
|
||||||
|
|
||||||
[Hotkey/PrevCandidate]
|
|
||||||
0=Shift+Tab
|
|
||||||
|
|
||||||
[Hotkey/NextCandidate]
|
|
||||||
0=Tab
|
|
||||||
|
|
||||||
[Hotkey/TogglePreedit]
|
|
||||||
0=Control+Alt+P
|
|
||||||
|
|
||||||
[Behavior]
|
|
||||||
# デフォルトで有効にする
|
|
||||||
ActiveByDefault=False
|
|
||||||
# フォーカス時に状態をリセット
|
|
||||||
resetStateWhenFocusIn=No
|
|
||||||
# 入力状態を共有する
|
|
||||||
ShareInputState=No
|
|
||||||
# アプリケーションにプリエディットを表示する
|
|
||||||
PreeditEnabledByDefault=True
|
|
||||||
# 入力メソッドを切り替える際に入力メソッドの情報を表示する
|
|
||||||
ShowInputMethodInformation=True
|
|
||||||
# フォーカスを変更する際に入力メソッドの情報を表示する
|
|
||||||
showInputMethodInformationWhenFocusIn=False
|
|
||||||
# 入力メソッドの情報をコンパクトに表示する
|
|
||||||
CompactInputMethodInformation=True
|
|
||||||
# 第1入力メソッドの情報を表示する
|
|
||||||
ShowFirstInputMethodInformation=True
|
|
||||||
# デフォルトのページサイズ
|
|
||||||
DefaultPageSize=5
|
|
||||||
# XKB オプションより優先する
|
|
||||||
OverrideXkbOption=False
|
|
||||||
# カスタム XKB オプション
|
|
||||||
CustomXkbOption=
|
|
||||||
# Force Enabled Addons
|
|
||||||
EnabledAddons=
|
|
||||||
# Force Disabled Addons
|
|
||||||
DisabledAddons=
|
|
||||||
# Preload input method to be used by default
|
|
||||||
PreloadInputMethod=True
|
|
||||||
# パスワード欄に入力メソッドを許可する
|
|
||||||
AllowInputMethodForPassword=False
|
|
||||||
# パスワード入力時にプリエディットテキストを表示する
|
|
||||||
ShowPreeditForPassword=False
|
|
||||||
# ユーザーデータを保存する間隔(分)
|
|
||||||
AutoSavePeriod=30
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
{
|
|
||||||
home.file.".config/fcitx5/config" = {
|
|
||||||
recursive = true;
|
|
||||||
source = ./config;
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,82 @@
|
|||||||
|
{ inputs, pkgs, ... }:
|
||||||
|
{
|
||||||
|
|
||||||
|
services.hazkey = {
|
||||||
|
enable = true;
|
||||||
|
server.package =
|
||||||
|
inputs.nix-hazkey.packages.${pkgs.stdenv.hostPlatform.system}.hazkey-server.override
|
||||||
|
{ enableVulkan = true; };
|
||||||
|
};
|
||||||
|
|
||||||
|
i18n.inputMethod = {
|
||||||
|
enable = true;
|
||||||
|
type = "fcitx5";
|
||||||
|
|
||||||
|
fcitx5 = {
|
||||||
|
waylandFrontend = true;
|
||||||
|
|
||||||
|
addons = with pkgs; [
|
||||||
|
fcitx5-gtk
|
||||||
|
kdePackages.fcitx5-qt
|
||||||
|
qt6Packages.fcitx5-configtool
|
||||||
|
];
|
||||||
|
|
||||||
|
settings = {
|
||||||
|
inputMethod = {
|
||||||
|
GroupOrder."0" = "Default";
|
||||||
|
|
||||||
|
"Groups/0" = {
|
||||||
|
Name = "Default";
|
||||||
|
"Default Layout" = "jp";
|
||||||
|
DefaultIM = "hazkey";
|
||||||
|
};
|
||||||
|
|
||||||
|
"Groups/0/Items/0" = {
|
||||||
|
Name = "keyboard-jp";
|
||||||
|
};
|
||||||
|
|
||||||
|
"Groups/0/Items/1" = {
|
||||||
|
Name = "hazkey";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
globalOptions = {
|
||||||
|
Hotkey = {
|
||||||
|
EnumerateWithTriggerKeys = false;
|
||||||
|
EnumerateSkipFirst = false;
|
||||||
|
ModifierOnlyKeyTimeout = 250;
|
||||||
|
};
|
||||||
|
|
||||||
|
"Hotkey/TriggerKeys"."1" = "Zenkaku_Hankaku";
|
||||||
|
"Hotkey/ActivateKeys"."0" = "Henkan";
|
||||||
|
"Hotkey/DeactivateKeys"."0" = "Muhenkan";
|
||||||
|
"Hotkey/PrevPage"."0" = "Up";
|
||||||
|
"Hotkey/NextPage"."0" = "Down";
|
||||||
|
"Hotkey/PrevCandidate"."0" = "Shift+Tab";
|
||||||
|
"Hotkey/NextCandidate"."0" = "Tab";
|
||||||
|
"Hotkey/TogglePreedit"."0" = "Control+Alt+P";
|
||||||
|
|
||||||
|
Behavior = {
|
||||||
|
ActiveByDefault = false;
|
||||||
|
resetStateWhenFocusIn = "No";
|
||||||
|
ShareInputState = "No";
|
||||||
|
PreeditEnabledByDefault = true;
|
||||||
|
ShowInputMethodInformation = true;
|
||||||
|
showInputMethodInformationWhenFocusIn = false;
|
||||||
|
CompactInputMethodInformation = true;
|
||||||
|
ShowFirstInputMethodInformation = true;
|
||||||
|
DefaultPageSize = 5;
|
||||||
|
OverrideXkbOption = false;
|
||||||
|
CustomXkbOption = "";
|
||||||
|
EnabledAddons = "";
|
||||||
|
DisabledAddons = "";
|
||||||
|
PreloadInputMethod = true;
|
||||||
|
AllowInputMethodForPassword = false;
|
||||||
|
ShowPreeditForPassword = false;
|
||||||
|
AutoSavePeriod = 30;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
{ inputs, ... }:
|
||||||
|
{
|
||||||
|
description = "Fcitx 5 input method framework with Hazkey Japanese input";
|
||||||
|
|
||||||
|
imports.home = [ inputs.nix-hazkey.homeModules.hazkey ];
|
||||||
|
}
|
||||||
@@ -1,34 +0,0 @@
|
|||||||
{ pkgs, ... }:
|
|
||||||
{
|
|
||||||
i18n.inputMethod = {
|
|
||||||
enable = true;
|
|
||||||
type = "fcitx5";
|
|
||||||
|
|
||||||
fcitx5 = {
|
|
||||||
waylandFrontend = true;
|
|
||||||
addons = with pkgs; [
|
|
||||||
fcitx5-mozc-ut
|
|
||||||
fcitx5-gtk
|
|
||||||
kdePackages.fcitx5-qt
|
|
||||||
qt6Packages.fcitx5-configtool
|
|
||||||
];
|
|
||||||
|
|
||||||
settings.inputMethod = {
|
|
||||||
GroupOrder."0" = "Default";
|
|
||||||
"Groups/0" = {
|
|
||||||
Name = "Default";
|
|
||||||
"Default Layout" = "jp";
|
|
||||||
DefaultIM = "mozc";
|
|
||||||
};
|
|
||||||
"Groups/0/Items/0" = {
|
|
||||||
Name = "keyboard-jp";
|
|
||||||
Layout = "";
|
|
||||||
};
|
|
||||||
"Groups/0/Items/1" = {
|
|
||||||
Name = "mozc";
|
|
||||||
Layout = "";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.ffmpeg ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
{
|
||||||
|
system.defaults.finder = {
|
||||||
|
AppleShowAllExtensions = true;
|
||||||
|
AppleShowAllFiles = false;
|
||||||
|
ShowPathbar = true;
|
||||||
|
ShowStatusBar = true;
|
||||||
|
_FXShowPosixPathInTitle = true;
|
||||||
|
_FXSortFoldersFirst = true;
|
||||||
|
FXDefaultSearchScope = "SCcf";
|
||||||
|
FXPreferredViewStyle = "Nlsv";
|
||||||
|
NewWindowTarget = "Home";
|
||||||
|
FXEnableExtensionChangeWarning = true;
|
||||||
|
FXRemoveOldTrashItems = true;
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
{
|
||||||
|
programs.gamemode = {
|
||||||
|
enable = true;
|
||||||
|
enableRenice = true;
|
||||||
|
|
||||||
|
settings = {
|
||||||
|
general = {
|
||||||
|
softrealtime = "auto";
|
||||||
|
renice = 10;
|
||||||
|
};
|
||||||
|
custom = {
|
||||||
|
start = "notify-send -a 'Gamemode' 'Optimizations activated'";
|
||||||
|
end = "notify-send -a 'Gamemode' 'Optimizations deactivated'";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
{
|
||||||
|
programs.gamescope = {
|
||||||
|
enable = true;
|
||||||
|
capSysNice = true;
|
||||||
|
};
|
||||||
|
}
|
||||||
+3
-32
@@ -1,28 +1,12 @@
|
|||||||
{
|
_: {
|
||||||
inputs,
|
|
||||||
lib,
|
|
||||||
pkgs,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
let
|
|
||||||
isDarwin = pkgs.stdenv.hostPlatform.isDarwin;
|
|
||||||
isLinux = pkgs.stdenv.hostPlatform.isLinux;
|
|
||||||
package =
|
|
||||||
if isLinux then
|
|
||||||
inputs.ghostty.packages.${pkgs.stdenv.hostPlatform.system}.ghostty-releasefast
|
|
||||||
else
|
|
||||||
null;
|
|
||||||
in
|
|
||||||
{
|
|
||||||
programs.ghostty = {
|
programs.ghostty = {
|
||||||
enable = true;
|
enable = true;
|
||||||
inherit package;
|
|
||||||
systemd.enable = isLinux;
|
|
||||||
|
|
||||||
settings = {
|
settings = {
|
||||||
theme = "dracula";
|
theme = "dracula";
|
||||||
background-blur-radius = 20;
|
background-blur-radius = 20;
|
||||||
background-opacity = 0.9;
|
background-opacity = 0.9;
|
||||||
|
background-opacity-cells = true;
|
||||||
font-family = "BlexMono Nerd Font Mono";
|
font-family = "BlexMono Nerd Font Mono";
|
||||||
mouse-hide-while-typing = true;
|
mouse-hide-while-typing = true;
|
||||||
window-decoration = "auto";
|
window-decoration = "auto";
|
||||||
@@ -40,6 +24,7 @@ in
|
|||||||
"ctrl+shift+minus=decrease_font_size:1"
|
"ctrl+shift+minus=decrease_font_size:1"
|
||||||
];
|
];
|
||||||
|
|
||||||
|
quick-terminal-screen = "mouse";
|
||||||
quick-terminal-position = "top";
|
quick-terminal-position = "top";
|
||||||
quick-terminal-size = "98%,100%";
|
quick-terminal-size = "98%,100%";
|
||||||
quick-terminal-autohide = false;
|
quick-terminal-autohide = false;
|
||||||
@@ -50,19 +35,5 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
# Global Ghostty keybindings are handled by the running app. Start it hidden
|
|
||||||
# at login so Option+T and Option+Space work before opening a terminal.
|
|
||||||
launchd.agents.ghostty-global-keybindings = lib.mkIf isDarwin {
|
|
||||||
enable = true;
|
|
||||||
config = {
|
|
||||||
ProgramArguments = [
|
|
||||||
"/usr/bin/open"
|
|
||||||
"-gja"
|
|
||||||
"Ghostty"
|
|
||||||
];
|
|
||||||
RunAtLoad = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
xdg.configFile."ghostty/themes/dracula".source = ./dracula.theme;
|
xdg.configFile."ghostty/themes/dracula".source = ./dracula.theme;
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
_: {
|
||||||
|
# Global Ghostty keybindings are handled by the running app. Start it hidden
|
||||||
|
# at login so Option+T and Option+Space work before opening a terminal.
|
||||||
|
launchd.agents.ghostty-global-keybindings = {
|
||||||
|
enable = true;
|
||||||
|
config = {
|
||||||
|
ProgramArguments = [
|
||||||
|
"/usr/bin/open"
|
||||||
|
"-gja"
|
||||||
|
"Ghostty"
|
||||||
|
];
|
||||||
|
RunAtLoad = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
programs.ghostty.package = null;
|
||||||
|
}
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
{ inputs, system, ... }: {
|
||||||
|
programs.ghostty = {
|
||||||
|
# Labwc's Close action correctly targets one xdg-toplevel, but Ghostty's
|
||||||
|
# systemd service runs every window in one GTK single-instance process.
|
||||||
|
# If that process exits while handling the request, every Ghostty window
|
||||||
|
# disappears together. Keep each launcher invocation independent instead.
|
||||||
|
systemd.enable = false;
|
||||||
|
package = inputs.ghostty.packages.${system}.default;
|
||||||
|
|
||||||
|
settings.gtk-single-instance = false;
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -38,8 +38,6 @@ in
|
|||||||
|
|
||||||
ignores = [
|
ignores = [
|
||||||
".direnv/"
|
".direnv/"
|
||||||
".envrc"
|
|
||||||
"!.envrc.example"
|
|
||||||
];
|
];
|
||||||
|
|
||||||
signing = {
|
signing = {
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.gnome-disk-utility ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.gnome-text-editor ];
|
||||||
|
|
||||||
|
dconf.settings."org/gnome/TextEditor" = {
|
||||||
|
style-variant = "follow";
|
||||||
|
wrap-text = true;
|
||||||
|
spellcheck = true;
|
||||||
|
restore-session = true;
|
||||||
|
show-line-numbers = false;
|
||||||
|
show-right-margin = false;
|
||||||
|
show-map = false;
|
||||||
|
highlight-current-line = false;
|
||||||
|
auto-indent = false;
|
||||||
|
discover-settings = false;
|
||||||
|
enable-snippets = false;
|
||||||
|
keybindings = "default";
|
||||||
|
};
|
||||||
|
|
||||||
|
xdg.mimeApps = {
|
||||||
|
enable = true;
|
||||||
|
defaultApplicationPackages = [ pkgs.gnome-text-editor ];
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -1,56 +0,0 @@
|
|||||||
{ pkgs, lib, ... }:
|
|
||||||
lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
|
|
||||||
dconf.settings = {
|
|
||||||
"org/gnome/desktop/sound" = {
|
|
||||||
event-sounds = false;
|
|
||||||
input-feedback-sounds = false;
|
|
||||||
};
|
|
||||||
"org/gnome/desktop/wm/keybindings" = {
|
|
||||||
close = [ "<Super>q" ];
|
|
||||||
show-desktop = [ ];
|
|
||||||
};
|
|
||||||
"org/gnome/settings-daemon/plugins/media-keys" = {
|
|
||||||
home = [ ];
|
|
||||||
screensaver = [ "<Super>l" ];
|
|
||||||
custom-keybindings = [
|
|
||||||
"/org/gnome/settings-daemon/plugins/media-keys/custom-keybindings/custom0/"
|
|
||||||
"/org/gnome/settings-daemon/plugins/media-keys/custom-keybindings/custom1/"
|
|
||||||
"/org/gnome/settings-daemon/plugins/media-keys/custom-keybindings/custom2/"
|
|
||||||
"/org/gnome/settings-daemon/plugins/media-keys/custom-keybindings/custom3/"
|
|
||||||
"/org/gnome/settings-daemon/plugins/media-keys/custom-keybindings/custom4/"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
"org/gnome/settings-daemon/plugins/media-keys/custom-keybindings/custom0" = {
|
|
||||||
name = "Open Terminal";
|
|
||||||
command = "ghostty";
|
|
||||||
binding = "<Super>t";
|
|
||||||
};
|
|
||||||
"org/gnome/settings-daemon/plugins/media-keys/custom-keybindings/custom1" = {
|
|
||||||
name = "Run Application";
|
|
||||||
command = "vicinae toggle";
|
|
||||||
binding = "<Super>d";
|
|
||||||
};
|
|
||||||
"org/gnome/settings-daemon/plugins/media-keys/custom-keybindings/custom2" = {
|
|
||||||
name = "Open File Manager";
|
|
||||||
command = "nautilus --new-window";
|
|
||||||
binding = "<Super>e";
|
|
||||||
};
|
|
||||||
"org/gnome/settings-daemon/plugins/media-keys/custom-keybindings/custom3" = {
|
|
||||||
name = "Clipboard History";
|
|
||||||
command = "vicinae vicinae://extensions/vicinae/clipboard/history";
|
|
||||||
binding = "<Super>v";
|
|
||||||
};
|
|
||||||
"org/gnome/settings-daemon/plugins/media-keys/custom-keybindings/custom4" = {
|
|
||||||
name = "Log Out";
|
|
||||||
command = "gnome-session-quit --logout --no-prompt";
|
|
||||||
binding = "<Super><Shift>e";
|
|
||||||
};
|
|
||||||
"org/gnome/shell".favorite-apps = [
|
|
||||||
"google-chrome.desktop"
|
|
||||||
"code.desktop"
|
|
||||||
"com.mitchellh.ghostty.desktop"
|
|
||||||
"slack.desktop"
|
|
||||||
"vesktop.desktop"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
{ pkgs, lib, ... }:
|
|
||||||
{
|
|
||||||
services.desktopManager.gnome.enable = true;
|
|
||||||
services.displayManager.gdm.enable = lib.mkForce false;
|
|
||||||
|
|
||||||
environment.systemPackages = [
|
|
||||||
pkgs.gnome-tweaks
|
|
||||||
pkgs.gnome-extension-manager
|
|
||||||
];
|
|
||||||
}
|
|
||||||
@@ -1,9 +1,6 @@
|
|||||||
{ inputs, pkgs, ... }:
|
{ inputs, pkgs, ... }:
|
||||||
let
|
|
||||||
grok = inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.grok.overrideAttrs (_: {
|
|
||||||
versionCheckProgram = "${placeholder "out"}/libexec/grok/grok-launcher";
|
|
||||||
});
|
|
||||||
in
|
|
||||||
{
|
{
|
||||||
home.packages = [ grok ];
|
home.packages = [
|
||||||
|
inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.grok
|
||||||
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -15,4 +15,8 @@
|
|||||||
name = "Papirus-Dark";
|
name = "Papirus-Dark";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
dconf.settings."org/gnome/desktop/wm/preferences" = {
|
||||||
|
button-layout = ":minimize,maximize,close";
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,4 +2,5 @@
|
|||||||
programs.dconf.enable = true;
|
programs.dconf.enable = true;
|
||||||
programs.seahorse.enable = true;
|
programs.seahorse.enable = true;
|
||||||
services.gnome.gnome-keyring.enable = true;
|
services.gnome.gnome-keyring.enable = true;
|
||||||
|
security.pam.services.ly.enableGnomeKeyring = true;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.htop ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.python314Packages.huggingface-hub ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,224 @@
|
|||||||
|
{ lib, pkgs, ... }:
|
||||||
|
let
|
||||||
|
systemctl = lib.getExe' pkgs.systemd "systemctl";
|
||||||
|
|
||||||
|
keybind = key: actionAttrs: {
|
||||||
|
"@key" = key;
|
||||||
|
action = actionAttrs;
|
||||||
|
};
|
||||||
|
|
||||||
|
action =
|
||||||
|
key: name:
|
||||||
|
keybind key {
|
||||||
|
"@name" = name;
|
||||||
|
};
|
||||||
|
|
||||||
|
execute =
|
||||||
|
key: command:
|
||||||
|
keybind key {
|
||||||
|
"@name" = "Execute";
|
||||||
|
"@command" = command;
|
||||||
|
};
|
||||||
|
|
||||||
|
snapToEdge =
|
||||||
|
key: direction:
|
||||||
|
keybind key {
|
||||||
|
"@name" = "SnapToEdge";
|
||||||
|
"@direction" = direction;
|
||||||
|
"@combine" = "yes";
|
||||||
|
};
|
||||||
|
|
||||||
|
confirmAction = key: message: name: {
|
||||||
|
"@key" = key;
|
||||||
|
action = {
|
||||||
|
"@name" = "If";
|
||||||
|
prompt."@message" = message;
|
||||||
|
"then".action."@name" = name;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
menuExecute = label: command: {
|
||||||
|
inherit label;
|
||||||
|
action = {
|
||||||
|
name = "Execute";
|
||||||
|
inherit command;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
showMenu = button: menu: {
|
||||||
|
"@button" = button;
|
||||||
|
"@action" = "Press";
|
||||||
|
action = {
|
||||||
|
"@name" = "ShowMenu";
|
||||||
|
"@menu" = menu;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
menuAction = label: name: {
|
||||||
|
inherit label;
|
||||||
|
action.name = name;
|
||||||
|
};
|
||||||
|
in
|
||||||
|
{
|
||||||
|
wayland.windowManager.labwc = {
|
||||||
|
enable = true;
|
||||||
|
# NixOS owns the package so Home Manager only generates the user config.
|
||||||
|
package = null;
|
||||||
|
|
||||||
|
systemd = {
|
||||||
|
enable = true;
|
||||||
|
|
||||||
|
variables = [
|
||||||
|
"DISPLAY"
|
||||||
|
"WAYLAND_DISPLAY"
|
||||||
|
"XDG_CURRENT_DESKTOP"
|
||||||
|
"XDG_SESSION_TYPE"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
menu = [
|
||||||
|
{
|
||||||
|
menuId = "root-menu";
|
||||||
|
items = [
|
||||||
|
(menuExecute "ターミナル" "ghostty")
|
||||||
|
(menuExecute "Vicinae" "vicinae toggle")
|
||||||
|
(menuExecute "ファイル" "nautilus --new-window")
|
||||||
|
|
||||||
|
{ separator = true; }
|
||||||
|
|
||||||
|
(menuAction "Reconfigure" "Reconfigure")
|
||||||
|
(menuAction "Exit" "Exit")
|
||||||
|
];
|
||||||
|
}
|
||||||
|
];
|
||||||
|
|
||||||
|
rc = {
|
||||||
|
|
||||||
|
keyboard = {
|
||||||
|
default = true;
|
||||||
|
numlock = "on";
|
||||||
|
keybind = [
|
||||||
|
# labwc window management
|
||||||
|
(action "W-q" "Close")
|
||||||
|
(action "W-f" "ToggleMaximize")
|
||||||
|
(action "W-c" "Iconify")
|
||||||
|
(action "W-Up" "Lower")
|
||||||
|
(action "W-Down" "Raise")
|
||||||
|
(action "W-Left" "NextWindow")
|
||||||
|
(action "W-Right" "PreviousWindow")
|
||||||
|
(snapToEdge "W-C-Left" "left")
|
||||||
|
(snapToEdge "W-C-Right" "right")
|
||||||
|
(snapToEdge "W-C-Up" "up")
|
||||||
|
(snapToEdge "W-C-Down" "down")
|
||||||
|
(confirmAction "W-S-e" "Exit labwc?" "Exit")
|
||||||
|
(execute "Print" "screenshot region")
|
||||||
|
(execute "C-Print" "screenshot output")
|
||||||
|
(execute "A-Print" "screenshot all")
|
||||||
|
|
||||||
|
# spawn applications (sync with niri modules/applications/niri/home.nix)
|
||||||
|
(execute "W-t" "ghostty")
|
||||||
|
(execute "W-d" "vicinae toggle")
|
||||||
|
(execute "W-s" "noctalia msg panel-toggle launcher")
|
||||||
|
(execute "W-e" "nautilus --new-window")
|
||||||
|
(execute "W-l" "loginctl lock-session")
|
||||||
|
(execute "W-v" "vicinae vicinae://launch/clipboard/history")
|
||||||
|
(execute "W-j" "nani-translate-primary")
|
||||||
|
(execute "W-S-j" "nani-translate-ocr")
|
||||||
|
(execute "W-C-j" "${lib.getExe' pkgs.xdg-utils "xdg-open"} naniapp://translate")
|
||||||
|
(execute "W-space" "ghostty +toggle-quick-terminal")
|
||||||
|
(execute "W-p" "wdisplays")
|
||||||
|
|
||||||
|
# Function keys (sync with niri modules/applications/niri/home.nix)
|
||||||
|
(execute "XF86AudioRaiseVolume" "noctalia msg volume-up")
|
||||||
|
(execute "XF86AudioLowerVolume" "noctalia msg volume-down")
|
||||||
|
(execute "XF86AudioMute" "noctalia msg volume-mute")
|
||||||
|
(execute "XF86AudioMicMute" "noctalia msg mic-mute")
|
||||||
|
(execute "XF86MonBrightnessUp" "noctalia msg brightness-up")
|
||||||
|
(execute "XF86MonBrightnessDown" "noctalia msg brightness-down")
|
||||||
|
(execute "XF86Favorites" "noctalia msg caffeine-toggle")
|
||||||
|
(execute "XF86AudioPlay" "playerctl play-pause")
|
||||||
|
(execute "XF86AudioPause" "playerctl play-pause")
|
||||||
|
(execute "XF86AudioStop" "playerctl stop")
|
||||||
|
(execute "XF86AudioPrev" "playerctl previous")
|
||||||
|
(execute "XF86AudioNext" "playerctl next")
|
||||||
|
(execute "XF86Display" "wdisplays")
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
core = {
|
||||||
|
decoration = "client";
|
||||||
|
gap = 10;
|
||||||
|
autoEnableOutputs = "yes";
|
||||||
|
reuseOutputMode = "yes";
|
||||||
|
};
|
||||||
|
|
||||||
|
theme = {
|
||||||
|
name = "Dracula";
|
||||||
|
cornerRadius = 8;
|
||||||
|
dropShadows = "yes";
|
||||||
|
dropShadowsOnTiled = "yes";
|
||||||
|
};
|
||||||
|
|
||||||
|
windowSwitcher = {
|
||||||
|
"@preview" = "yes";
|
||||||
|
"@outlines" = "yes";
|
||||||
|
osd = {
|
||||||
|
"@style" = "thumbnail";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
focus = {
|
||||||
|
followMouse = "yes";
|
||||||
|
followMouseRequiresMovement = "yes";
|
||||||
|
raiseOnFocus = "no";
|
||||||
|
};
|
||||||
|
|
||||||
|
desktops = {
|
||||||
|
"@number" = 1;
|
||||||
|
"@popupTime" = 500;
|
||||||
|
"@prefix" = "Workspace";
|
||||||
|
};
|
||||||
|
|
||||||
|
mouse = {
|
||||||
|
default = true;
|
||||||
|
|
||||||
|
context = {
|
||||||
|
"@name" = "Desktop";
|
||||||
|
|
||||||
|
mousebind = [
|
||||||
|
(showMenu "Right" "root-menu")
|
||||||
|
(showMenu "Middle" "client-list-combined-menu")
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
libinput.device = [
|
||||||
|
{
|
||||||
|
"@category" = "touchpad";
|
||||||
|
naturalScroll = "yes";
|
||||||
|
tap = "yes";
|
||||||
|
tapAndDrag = "yes";
|
||||||
|
dragLock = "yes";
|
||||||
|
clickMethod = "clickfinger";
|
||||||
|
scrollMethod = "twoFinger";
|
||||||
|
scrollFactor = "4.0";
|
||||||
|
disableWhileTyping = "yes";
|
||||||
|
}
|
||||||
|
{
|
||||||
|
"@category" = "non-touch";
|
||||||
|
pointerSpeed = "-0.1";
|
||||||
|
accelProfile = "flat";
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
environment = [
|
||||||
|
"XKB_DEFAULT_LAYOUT=jp"
|
||||||
|
"XKB_DEFAULT_OPTIONS=ctrl:nocaps"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
xdg.configFile."labwc/shutdown".text = lib.mkAfter ''
|
||||||
|
${systemctl} --user stop graphical-session.target
|
||||||
|
'';
|
||||||
|
}
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
{
|
||||||
|
description = "labwc Wayland stacking compositor";
|
||||||
|
|
||||||
|
includes = [
|
||||||
|
"systems.wayland"
|
||||||
|
"applications.screenshot"
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -0,0 +1,57 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
lib,
|
||||||
|
pkgs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
unstable = inputs.nixpkgs-unstable.legacyPackages.${pkgs.stdenv.hostPlatform.system};
|
||||||
|
in
|
||||||
|
{
|
||||||
|
programs.labwc = {
|
||||||
|
enable = true;
|
||||||
|
package = unstable.labwc;
|
||||||
|
};
|
||||||
|
|
||||||
|
xdg.portal.config.labwc.default = [
|
||||||
|
"wlr"
|
||||||
|
"gtk"
|
||||||
|
];
|
||||||
|
|
||||||
|
# xdg-desktop-portal-wlr implements screencasting for wlroots compositors.
|
||||||
|
# Keep it with Labwc: Niri uses xdg-desktop-portal-gnome instead.
|
||||||
|
xdg.portal.wlr = {
|
||||||
|
enable = true;
|
||||||
|
settings.screencast = {
|
||||||
|
chooser_type = "dmenu";
|
||||||
|
chooser_cmd = "${pkgs.fuzzel}/bin/fuzzel --dmenu";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# NixOS decides whether a graphical session manages graphical-session.target
|
||||||
|
# itself by checking XDG_CURRENT_DESKTOP against a hard-coded list. Labwc is
|
||||||
|
# currently absent from that list, so NixOS starts
|
||||||
|
# nixos-fake-graphical-session.target before Labwc is ready.
|
||||||
|
#
|
||||||
|
# This configuration uses Home Manager's Labwc systemd integration, which
|
||||||
|
# imports the Wayland environment and starts labwc-session.target correctly.
|
||||||
|
# Mark the Labwc session as systemd-aware before the display-manager wrapper
|
||||||
|
# performs its hard-coded check. Otherwise services such as Fcitx5 can start
|
||||||
|
# before WAYLAND_DISPLAY is available.
|
||||||
|
#
|
||||||
|
# Despite the services.xserver namespace, this session wrapper is also used
|
||||||
|
# for Wayland sessions by display managers such as Ly.
|
||||||
|
services.xserver.displayManager.sessionCommands = lib.mkAfter ''
|
||||||
|
case ":''${XDG_CURRENT_DESKTOP:-}:" in
|
||||||
|
*:labwc:*)
|
||||||
|
case ":$XDG_CURRENT_DESKTOP:" in
|
||||||
|
*:X-NIXOS-SYSTEMD-AWARE:*)
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
export XDG_CURRENT_DESKTOP="$XDG_CURRENT_DESKTOP:X-NIXOS-SYSTEMD-AWARE"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
'';
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.loupe ];
|
||||||
|
|
||||||
|
xdg.mimeApps = {
|
||||||
|
enable = true;
|
||||||
|
defaultApplicationPackages = [ pkgs.loupe ];
|
||||||
|
|
||||||
|
defaultApplications = {
|
||||||
|
"image/avif" = [ "org.gnome.Loupe.desktop" ];
|
||||||
|
"image/bmp" = [ "org.gnome.Loupe.desktop" ];
|
||||||
|
"image/gif" = [ "org.gnome.Loupe.desktop" ];
|
||||||
|
"image/heic" = [ "org.gnome.Loupe.desktop" ];
|
||||||
|
"image/heif" = [ "org.gnome.Loupe.desktop" ];
|
||||||
|
"image/jpeg" = [ "org.gnome.Loupe.desktop" ];
|
||||||
|
"image/jxl" = [ "org.gnome.Loupe.desktop" ];
|
||||||
|
"image/png" = [ "org.gnome.Loupe.desktop" ];
|
||||||
|
"image/svg+xml" = [ "org.gnome.Loupe.desktop" ];
|
||||||
|
"image/webp" = [ "org.gnome.Loupe.desktop" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
_: {
|
||||||
|
programs.mangohud.enable = true;
|
||||||
|
}
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
{
|
||||||
|
homebrew = {
|
||||||
|
enable = true;
|
||||||
|
casks = [ "prismlauncher" ];
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
{ pkgs, ... }: {
|
||||||
|
home.packages = [ pkgs.packwiz ];
|
||||||
|
|
||||||
|
programs.prismlauncher = {
|
||||||
|
enable = true;
|
||||||
|
|
||||||
|
package = null;
|
||||||
|
|
||||||
|
settings = {
|
||||||
|
UseSystemLocale = true;
|
||||||
|
|
||||||
|
# Minecraftのバージョンに応じてJavaを切り替える。
|
||||||
|
AutomaticJavaSwitch = true;
|
||||||
|
|
||||||
|
IgnoreJavaCompatibility = false;
|
||||||
|
|
||||||
|
# 軽量~中規模構成のグローバル既定値。
|
||||||
|
MinMemAlloc = 512;
|
||||||
|
MaxMemAlloc = 4096;
|
||||||
|
LowMemWarning = true;
|
||||||
|
|
||||||
|
# 通常はコンソールを隠し、異常時だけ表示する。
|
||||||
|
ShowConsole = false;
|
||||||
|
ShowConsoleOnError = true;
|
||||||
|
LogPrePostOutput = true;
|
||||||
|
ConsoleMaxLines = 100000;
|
||||||
|
ConsoleOverflowStop = true;
|
||||||
|
|
||||||
|
# Mod管理。
|
||||||
|
ModMetadataDisabled = false;
|
||||||
|
ModDependenciesDisabled = false;
|
||||||
|
SkipModpackUpdatePrompt = false;
|
||||||
|
ShowModIncompat = true;
|
||||||
|
DownloadGameFilesDuringInstanceCreation = true;
|
||||||
|
|
||||||
|
# プレイ時間。
|
||||||
|
RecordGameTime = true;
|
||||||
|
ShowGameTime = true;
|
||||||
|
ShowGlobalGameTime = true;
|
||||||
|
|
||||||
|
MetaRefreshOnLaunch = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
_: {
|
||||||
|
programs.prismlauncher.settings = {
|
||||||
|
AutomaticJavaDownload = true;
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.prismlauncher ];
|
||||||
|
|
||||||
|
programs.prismlauncher.settings = {
|
||||||
|
EnableFeralGamemode = true;
|
||||||
|
};
|
||||||
|
}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user