1 Commits
Author SHA1 Message Date
Renovate Bot 20606d09c7 chore(deps): lock file maintenance 2026-07-18 19:01:25 +00:00
18 changed files with 243 additions and 159 deletions
+2 -2
View File
@@ -21,7 +21,7 @@ jobs:
hosts: ${{ steps.hosts.outputs.hosts }} hosts: ${{ steps.hosts.outputs.hosts }}
steps: steps:
- name: Checkout repository - name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with: with:
persist-credentials: false persist-credentials: false
- name: Install Nix - name: Install Nix
@@ -51,7 +51,7 @@ jobs:
host: ${{ fromJSON(needs.validate.outputs.hosts) }} host: ${{ fromJSON(needs.validate.outputs.hosts) }}
steps: steps:
- name: Checkout repository - name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with: with:
persist-credentials: false persist-credentials: false
- name: Install Nix - name: Install Nix
+64
View File
@@ -0,0 +1,64 @@
name: Publish Nix cache
on:
push:
branches:
- main
workflow_dispatch:
permissions:
contents: write
packages: write
concurrency:
group: publish-nixcache-${{ github.ref }}
cancel-in-progress: false
jobs:
publish:
name: Build and publish uncached paths
runs-on: ubuntu-latest
timeout-minutes: 180
steps:
- name: Checkout repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: true
- name: Install Nix
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
with:
extra_nix_config: |
experimental-features = nix-command flakes
accept-flake-config = true
access-tokens = github.com=${{ github.token }}
- name: Configure cache signing
env:
NIX_SIGNING_KEY: ${{ secrets.NIX_SIGNING_KEY }}
run: |
set -euo pipefail
test -n "$NIX_SIGNING_KEY" || {
echo "NIX_SIGNING_KEY is required; refusing to publish unsigned cache paths." >&2
exit 1
}
signing_key="$RUNNER_TEMP/nixcache-signing-key"
umask 077
printf '%s' "$NIX_SIGNING_KEY" > "$signing_key"
nix key convert-secret-to-public < "$signing_key" > nixcache-public-key.txt
echo "NIXCACHE_SIGNING_KEY_FILE=$signing_key" >> "$GITHUB_ENV"
- name: Commit cache public key
run: |
set -euo pipefail
if git diff --quiet -- nixcache-public-key.txt; then
exit 0
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add nixcache-public-key.txt
git commit -m "chore: publish Nix cache signing key"
git push
- name: Build and publish uncached store paths
env:
GITHUB_TOKEN: ${{ github.token }}
NIXCACHE_REPO: ${{ github.repository }}
NIXCACHE_CONFIG_DIR: .
run: |
set -euo pipefail
nixcache_source="$(nix flake archive --json --no-write-lock-file github:cmspam/nixcache-oci/fb6006b5575da494dbbfc582e841d976ec06be6e | jq -r .path)"
source "$nixcache_source/lib/cache-builder.sh"
full_pipeline
+2 -2
View File
@@ -16,12 +16,12 @@ jobs:
timeout-minutes: 60 timeout-minutes: 60
steps: steps:
- name: Checkout repository - name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with: with:
persist-credentials: false persist-credentials: false
# Use a PAT or GitHub App token so Renovate PRs trigger the other workflows. # Use a PAT or GitHub App token so Renovate PRs trigger the other workflows.
- name: Run Renovate - name: Run Renovate
uses: renovatebot/github-action@3064367f740a1a91cca218698a63902689cce200 # v46.1.20 uses: renovatebot/github-action@22e0a16091fc706b04affe6ae53d5e3358ac4023 # v46.1.19
with: with:
renovate-version: 43.262.1 renovate-version: 43.262.1
token: ${{ secrets.RENOVATE_TOKEN }} token: ${{ secrets.RENOVATE_TOKEN }}
+21
View File
@@ -179,6 +179,27 @@ sudo nixos-rebuild switch --flake .#<host> # Apply config
sudo nixos-rebuild build --flake .#<host> # Build without applying sudo nixos-rebuild build --flake .#<host> # Build without applying
``` ```
## Nix Binary Cache
All normal hosts run `nixcache-oci` as a local proxy for
`ghcr.io/moons-14/dotfiles/nix-cache`. The `Publish Nix cache` workflow builds
the flake on pushes to `main` and uploads only store paths that were built by
the runner rather than substituted from an existing cache. Nix still uses the
official cache and configured Cachix caches for all other paths.
The cache must remain public and signed:
1. Generate a signing key outside this repository and save its contents as the
`NIX_SIGNING_KEY` GitHub Actions secret.
2. Run the `Publish Nix cache` workflow. It commits `nixcache-public-key.txt`,
which clients trust on their next configuration rebuild.
3. In GitHub Packages, make the `nix-cache` container package public.
```sh
nix key generate-secret > /tmp/nixcache-signing-key
# Copy the contents into the NIX_SIGNING_KEY GitHub Actions secret, then delete the local file.
```
## Inspired ## Inspired
- [Zaney/zaneyos](https://gitlab.com/Zaney/zaneyos) - [Zaney/zaneyos](https://gitlab.com/Zaney/zaneyos)
Generated
+75 -54
View File
@@ -109,11 +109,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1784659912, "lastModified": 1784389652,
"narHash": "sha256-OhdIvgX/LjGvCMbZ5ZbZYY9+akQbbbLKLm0dV+S2vgE=", "narHash": "sha256-LRnL+bLyHwyaOVwM3p1UZOAeFlwsWAXdhmbJCIXX2e4=",
"owner": "ilysenko", "owner": "ilysenko",
"repo": "codex-desktop-linux", "repo": "codex-desktop-linux",
"rev": "db60ae2c31aad4c2efdc3767136918f705b66423", "rev": "bf6e6be58f7fbf1ea90a2a27ebbff12c4989e5a1",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -124,11 +124,11 @@
}, },
"crane": { "crane": {
"locked": { "locked": {
"lastModified": 1784407669, "lastModified": 1783203018,
"narHash": "sha256-gcFMcRjw0ZSn380Rx2QLlU1goUQeSrKX/DF12omI6+o=", "narHash": "sha256-G6R9IT/xwFuu+CYBWDUAok6AdC4ERC4ZfPPFtEpxnZE=",
"owner": "ipetkov", "owner": "ipetkov",
"repo": "crane", "repo": "crane",
"rev": "1316b7d278ad77a16aec024b71d971366e123bec", "rev": "80db5bdc391be8a1794f6d8a2d56e3a84ebcede2",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -500,11 +500,11 @@
"rust-overlay": "rust-overlay" "rust-overlay": "rust-overlay"
}, },
"locked": { "locked": {
"lastModified": 1784568171, "lastModified": 1783496806,
"narHash": "sha256-t17AqLEhPG6m27ipkp8mJd8Ug0XkdANFDVsgyIFBZcQ=", "narHash": "sha256-6B6CQUk1dPc8l/+otaGiYbuX8qeX/0VmSUQ+qSn0/uA=",
"owner": "nix-community", "owner": "nix-community",
"repo": "lanzaboote", "repo": "lanzaboote",
"rev": "f4b0aef3dba28677a5ca4b3416827aade60b5a0b", "rev": "6183ac79eadb079a1e72fa2c60915601be669100",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -524,11 +524,11 @@
"treefmt-nix": "treefmt-nix" "treefmt-nix": "treefmt-nix"
}, },
"locked": { "locked": {
"lastModified": 1784615936, "lastModified": 1784363791,
"narHash": "sha256-DzPXJmiePXn0+G6t5/H8nqTNX/AT7KlzVrpL5LZe8OE=", "narHash": "sha256-p9LRSnyqaiaOItDf3rMjWxlPsmLO7YhgBg4zd6nB0lA=",
"owner": "numtide", "owner": "numtide",
"repo": "llm-agents.nix", "repo": "llm-agents.nix",
"rev": "ba8c89d5b4836d46f7bdbffd2df34c66dadef725", "rev": "a76249be5f5c1ce95c3a0e74930cb015d66718a0",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -547,11 +547,11 @@
"xwayland-satellite-unstable": "xwayland-satellite-unstable" "xwayland-satellite-unstable": "xwayland-satellite-unstable"
}, },
"locked": { "locked": {
"lastModified": 1784578694, "lastModified": 1784380193,
"narHash": "sha256-UQtzks2t8ycyki7NCaSsp3Dy7Hcw5iCzPX5txnU5744=", "narHash": "sha256-XnpNipcSNWg+l9aHV/Ha3W1ot/r5FC7OT3//zZ9Vjbs=",
"owner": "sodiboo", "owner": "sodiboo",
"repo": "niri-flake", "repo": "niri-flake",
"rev": "4d9088bdc07d20963be29821d5cf491edd9c8d25", "rev": "26e0cddf2447ab5ec0824b1c9a076aa1480fc57a",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -580,11 +580,11 @@
"niri-unstable": { "niri-unstable": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1784570726, "lastModified": 1783522755,
"narHash": "sha256-9EMn69JBcFWFgUM7f0VBAX+jBby5b9H3M59U75+5yI4=", "narHash": "sha256-dI0HkX1djETia7cD/Y64h8BNIsSOfTRMzfNum2J6UhE=",
"owner": "YaLTeR", "owner": "YaLTeR",
"repo": "niri", "repo": "niri",
"rev": "7f26c3ee804fb6ed458ef7fb0e3c794f14e0b3bc", "rev": "0777769e719b7c9b7c980d4ea66288bfbb4da5b3",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -621,11 +621,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1784440659, "lastModified": 1783864904,
"narHash": "sha256-Q5kNLlWngt7TaIIZoxDKWMHjiSaNRVqr70FqWCRRfr4=", "narHash": "sha256-BQxN5UMg9FOevAsgBRwPxfxlh51Puj+dNn/8Dsi3sPM=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nix-index-database", "repo": "nix-index-database",
"rev": "4f8d52a3598b0dc7db7a5e7b419e3edd9d1ecfdb", "rev": "1111b9bc836afb7e31a7014e8d1272de9b1c917d",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -634,6 +634,26 @@
"type": "github" "type": "github"
} }
}, },
"nixcache-oci": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1784393281,
"narHash": "sha256-dlj3uQdaSpJzCxATrfGRlEX3i0UMbk2H0eVJdO2hTZY=",
"owner": "cmspam",
"repo": "nixcache-oci",
"rev": "7db80f3bc7e63645f655e6c66578088ffe4a1f97",
"type": "github"
},
"original": {
"owner": "cmspam",
"repo": "nixcache-oci",
"type": "github"
}
},
"nixos-hardware": { "nixos-hardware": {
"inputs": { "inputs": {
"nixpkgs": "nixpkgs_4" "nixpkgs": "nixpkgs_4"
@@ -659,11 +679,11 @@
"nixpkgs": "nixpkgs_5" "nixpkgs": "nixpkgs_5"
}, },
"locked": { "locked": {
"lastModified": 1784642409, "lastModified": 1784058842,
"narHash": "sha256-hcbDqFuySAJawljt5r0sKBCJKYnbtGD0T/ZIozH1Dq0=", "narHash": "sha256-3u3tvbCIAid3Mv7RrJx13jusIEQC/HeKYhO/SUSxR3A=",
"owner": "nix-community", "owner": "nix-community",
"repo": "NixOS-WSL", "repo": "NixOS-WSL",
"rev": "eaeb18da90024448a60eb1ec7132eafa4003404e", "rev": "24c8dc8e0f2170e1a377be24dfadc7d9d21dc1ad",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -734,11 +754,11 @@
}, },
"nixpkgs-unstable": { "nixpkgs-unstable": {
"locked": { "locked": {
"lastModified": 1784555310, "lastModified": 1784364478,
"narHash": "sha256-/FCliTPgiuV1owejZFNx3Ch9irdvkOfOFl+HHZ+DrtM=", "narHash": "sha256-CdItYNdYUlm7NxqMVyQKqT2IxTwvapiPuRLWOyHTrbY=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "421eebfd0ec7bccd4abe826ce62d7e6e83129493", "rev": "20535e48e12c86043b577b8518234ff5dbb26957",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -766,11 +786,11 @@
}, },
"nixpkgs_3": { "nixpkgs_3": {
"locked": { "locked": {
"lastModified": 1784497964, "lastModified": 1784356753,
"narHash": "sha256-vlHUuqAcbcH2RKmHbPiuQzbv1pnzzavXnI62RD0bqCU=", "narHash": "sha256-12KrbMiWLcf8m7pCvAtZh1ZrgF85ZXDXvfR/fWTKy84=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "241313f4e8e508cb9b13278c2b0fa25b9ca27163", "rev": "61b7c44c4073f0b827768aff0049561b5110ea5a",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -811,11 +831,11 @@
}, },
"nixpkgs_6": { "nixpkgs_6": {
"locked": { "locked": {
"lastModified": 1784432872, "lastModified": 1784280462,
"narHash": "sha256-n3gKTBIV4ZA5VQpUakffBe3KGu4+mhPoA34rrqS0GkA=", "narHash": "sha256-DtoqIqM7VkR6NxAkcLpMwmi02USwWb3JdmNGLyhthc0=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "fd1462031fdee08f65fd0b4c6b64e22239a77870", "rev": "293d6abedf0478e681a4dfcfcb35b30fc796a32f",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -903,11 +923,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1784661212, "lastModified": 1784390676,
"narHash": "sha256-WrEIHa/yAmGoL7Mr3zV5CWliZM8UxnSn7zCm2O6ZAgs=", "narHash": "sha256-d6YSbdMQM3A3+X0BU7NFX506U/CaRgyh2Jwe9WhiBg0=",
"owner": "noctalia-dev", "owner": "noctalia-dev",
"repo": "noctalia", "repo": "noctalia",
"rev": "8b1949fa78defc12c54407c6e55bf4cf63c05d6d", "rev": "5a20c9cf0ecc398c9391aa52ac075a0401f720c9",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -950,11 +970,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1784288435, "lastModified": 1783008725,
"narHash": "sha256-ReRHaLgr/uVqdD8afFSn+myXIfpHeOhP0yYe0TJqAA8=", "narHash": "sha256-jGiy6+sxjNWXSjp25uoJuNfyH9zBK1PEDY0lVoL4ibQ=",
"owner": "cachix", "owner": "cachix",
"repo": "git-hooks.nix", "repo": "git-hooks.nix",
"rev": "43b3c1ab9d40fb1dbb008f451988a91e375825e9", "rev": "bca82caa46d5ec0f5d422c61fb1e30bc51313cbe",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -976,6 +996,7 @@
"niri-flake": "niri-flake", "niri-flake": "niri-flake",
"nix-hazkey": "nix-hazkey", "nix-hazkey": "nix-hazkey",
"nix-index-database": "nix-index-database", "nix-index-database": "nix-index-database",
"nixcache-oci": "nixcache-oci",
"nixos-hardware": "nixos-hardware", "nixos-hardware": "nixos-hardware",
"nixos-wsl": "nixos-wsl", "nixos-wsl": "nixos-wsl",
"nixpkgs": "nixpkgs_6", "nixpkgs": "nixpkgs_6",
@@ -999,11 +1020,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1784438913, "lastModified": 1783488441,
"narHash": "sha256-NYF7ZM5ip0u+w1pBFDpIGEbrbgN/wpnLFAmBkWkYMXw=", "narHash": "sha256-jmWf+H3iC/0z7/mmvTovaJx1E/LME1QyHkyk+AFfJPk=",
"owner": "oxalica", "owner": "oxalica",
"repo": "rust-overlay", "repo": "rust-overlay",
"rev": "afacd6819d3765a05814ee8e3de74c77d42ac799", "rev": "7dc3a177a239ed879c5581a80f6dc246c7e102f1",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1014,11 +1035,11 @@
}, },
"services-flake": { "services-flake": {
"locked": { "locked": {
"lastModified": 1784537427, "lastModified": 1783213527,
"narHash": "sha256-sW3zOg8UKikCe82BkipILqM2d03Zp+dkJvBeyBfQlZQ=", "narHash": "sha256-yIVKacNpTvEY+xQf2MzNn6jerRrazrkXxTwmwTK4N7M=",
"owner": "juspay", "owner": "juspay",
"repo": "services-flake", "repo": "services-flake",
"rev": "ee44cc299c872762cbc80490b3b596f235bf69ca", "rev": "1c9142a3d74abc53aed62687106ee15e873dc3ff",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1292,11 +1313,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1784369104, "lastModified": 1780220602,
"narHash": "sha256-47cxbcZODibHv3rELFQ9vZly0vUNkND/atn/U7HLeb0=", "narHash": "sha256-eynAfOmbmxJnkp7YewvCEbShNnnYJ9gLLqkzsYtBPeM=",
"owner": "numtide", "owner": "numtide",
"repo": "treefmt-nix", "repo": "treefmt-nix",
"rev": "df3c0640565d04a0261253cdd89fce78ec50168a", "rev": "db947814a175b7ca6ded66e21383d938df01c227",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1330,11 +1351,11 @@
"systems": "systems_7" "systems": "systems_7"
}, },
"locked": { "locked": {
"lastModified": 1784575271, "lastModified": 1784388228,
"narHash": "sha256-8lVGfvf6bkLW4C/3H9RYTkTBhmN7ooAliMkL+UE8YmU=", "narHash": "sha256-/5fGvMWlLlyd5ibK7y1dqIK1MTpLABj3v1M0r/VArww=",
"owner": "vicinaehq", "owner": "vicinaehq",
"repo": "vicinae", "repo": "vicinae",
"rev": "630036e784de647bcf18aedab7007ec5c4f5b2d0", "rev": "c55e85716e3e7a68f4b0f6ef6299d02a49623c7c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1353,11 +1374,11 @@
"vicinae": "vicinae_2" "vicinae": "vicinae_2"
}, },
"locked": { "locked": {
"lastModified": 1784504910, "lastModified": 1784400781,
"narHash": "sha256-fzPBEJZiRvc/FNMdpbdcfaZzF01U4IQenHW9IQFzhos=", "narHash": "sha256-awe35tis3VZCfQVhivpduehT/5IV5LHmOsd2YSxECRQ=",
"owner": "vicinaehq", "owner": "vicinaehq",
"repo": "extensions", "repo": "extensions",
"rev": "ca74eede9a778a9373c8f5fd221b0a5026dcd1ef", "rev": "67beba7a8e79b817552e4a95f835b8cc697ca08b",
"type": "github" "type": "github"
}, },
"original": { "original": {
+6
View File
@@ -92,6 +92,12 @@
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
# Binary cache
nixcache-oci = {
url = "github:cmspam/nixcache-oci";
inputs.nixpkgs.follows = "nixpkgs";
};
# Systems # Systems
systems.url = "github:nix-systems/default-linux"; systems.url = "github:nix-systems/default-linux";
-1
View File
@@ -38,7 +38,6 @@
./vscode ./vscode
./wayland.nix ./wayland.nix
./yazi.nix ./yazi.nix
./zed
./zellij ./zellij
./zoom.nix ./zoom.nix
./zoxide.nix ./zoxide.nix
-7
View File
@@ -15,12 +15,5 @@ in
services.systemd-lock-handler.enable = true; services.systemd-lock-handler.enable = true;
security.pam.services.swaylock.fprintAuth = true; security.pam.services.swaylock.fprintAuth = true;
# PAM authentication is serial. Let a supplied password succeed before
# starting fprintd, whose scan otherwise blocks password verification until
# its timeout expires. Submit an empty password to start fingerprint
# authentication in upstream swaylock.
security.pam.services.swaylock.rules.auth.fprintd.order =
config.security.pam.services.swaylock.rules.auth.unix.order + 50;
}; };
} }
+6
View File
@@ -19,13 +19,19 @@ in
# modules do not each append their own portal backends. # modules do not each append their own portal backends.
xdg.portal = { xdg.portal = {
enable = true; enable = true;
wlr.enable = true;
extraPortals = [ extraPortals = [
pkgs.xdg-desktop-portal-gnome pkgs.xdg-desktop-portal-gnome
pkgs.xdg-desktop-portal-gtk pkgs.xdg-desktop-portal-gtk
pkgs.xdg-desktop-portal-wlr
]; ];
xdgOpenUsePortal = true; xdgOpenUsePortal = true;
config = { config = {
common.default = [ "gtk" ]; common.default = [ "gtk" ];
niri.default = lib.mkForce [
"wlr"
"gtk"
];
gnome.default = [ gnome.default = [
"gnome" "gnome"
"gtk" "gtk"
-21
View File
@@ -1,21 +0,0 @@
{
lib,
config,
...
}:
let
cfg = config.my.applications.zed;
in
{
imports = [
./home.nix
];
options.my.applications.zed = {
enable = lib.mkEnableOption "Zed code editor";
};
config = lib.mkIf cfg.enable {
my.applications.zed.homeManager.enable = lib.mkDefault true;
};
}
-66
View File
@@ -1,66 +0,0 @@
{
lib,
config,
...
}:
let
cfg = config.my.applications.zed.homeManager;
in
{
options.my.applications.zed.homeManager = {
enable = lib.mkEnableOption "Zed home-manager configuration";
};
config.home-manager.sharedModules = [
{
config = lib.mkIf cfg.enable {
programs.zed-editor = {
enable = true;
extensions = [
"catppuccin"
"nix"
];
mutableUserSettings = false;
userSettings = {
agent = {
flexible = true;
favorite_models = [ ];
model_parameters = [ ];
};
project_panel.dock = "left";
telemetry = {
diagnostics = false;
metrics = false;
};
vim_mode = true;
agent_servers = {
github-copilot-cli.type = "registry";
codex-acp.type = "registry";
claude-acp.type = "registry";
};
icon_theme = {
mode = "dark";
light = "Zed (Default)";
dark = "Zed (Default)";
};
ui_font_size = 17;
buffer_font_size = 16;
theme = {
mode = "dark";
light = "Catppuccin Latte";
dark = "Catppuccin Mocha";
};
};
};
};
}
];
}
+16 -1
View File
@@ -1,10 +1,19 @@
{ {
pkgs,
lib, lib,
config, config,
... ...
}: }:
let let
cfg = config.my.applications.zoom; cfg = config.my.applications.zoom;
zoomX11 = pkgs.zoom-us.overrideAttrs (old: {
nativeBuildInputs = (old.nativeBuildInputs or [ ]) ++ [ pkgs.makeWrapper ];
postFixup = (old.postFixup or "") + ''
wrapProgram $out/bin/zoom \
--set QT_QPA_PLATFORM xcb
'';
});
in in
{ {
options.my.applications.zoom = { options.my.applications.zoom = {
@@ -12,6 +21,12 @@ in
}; };
config = lib.mkIf cfg.enable { config = lib.mkIf cfg.enable {
programs.zoom-us.enable = true; home-manager.sharedModules = [
{
home.packages = with pkgs; [
zoomX11 # Video conferencing application with XWayland startup for GNOME stability
];
}
];
}; };
} }
+2 -5
View File
@@ -4,13 +4,10 @@ let
in in
{ {
options.my.features.gui.editor = { options.my.features.gui.editor = {
enable = lib.mkEnableOption "GUI code editors (VSCode and Zed)"; enable = lib.mkEnableOption "GUI code editor (VSCode)";
}; };
config = lib.mkIf cfg.enable { config = lib.mkIf cfg.enable {
my.applications = { my.applications.vscode.enable = true;
vscode.enable = true;
zed.enable = true;
};
}; };
} }
+1
View File
@@ -2,6 +2,7 @@
imports = [ imports = [
./container.nix ./container.nix
./kde.nix ./kde.nix
./nixcache-oci.nix
./quem-guest.nix ./quem-guest.nix
]; ];
} }
@@ -0,0 +1,17 @@
{
lib,
config,
...
}:
let
cfg = config.my.features.services.nixcacheOci;
in
{
options.my.features.services.nixcacheOci = {
enable = lib.mkEnableOption "Nix binary cache backed by public GHCR";
};
config = lib.mkIf cfg.enable {
my.system.nixcacheOci.enable = true;
};
}
+3
View File
@@ -1,3 +1,4 @@
{ inputs, ... }:
{ {
imports = [ imports = [
./audio.nix ./audio.nix
@@ -11,6 +12,7 @@
./locale.nix ./locale.nix
./network ./network
./nix.nix ./nix.nix
./nixcache-oci.nix
./power.nix ./power.nix
./quem.nix ./quem.nix
./secure-boot.nix ./secure-boot.nix
@@ -18,5 +20,6 @@
./user ./user
./version.nix ./version.nix
./secret.nix ./secret.nix
inputs.nixcache-oci.nixosModules.default
]; ];
} }
+27
View File
@@ -0,0 +1,27 @@
{
lib,
config,
...
}:
let
cfg = config.my.system.nixcacheOci;
publicKeyFile = ../../nixcache-public-key.txt;
publicKey =
if builtins.pathExists publicKeyFile then
lib.strings.trim (builtins.readFile publicKeyFile)
else
"";
in
{
options.my.system.nixcacheOci = {
enable = lib.mkEnableOption "Nix binary cache backed by the public GitHub Container Registry";
};
config = lib.mkIf cfg.enable {
services.nixcache-proxy = {
enable = true;
repo = "moons-14/dotfiles";
inherit publicKey;
};
};
}
+1
View File
@@ -5,5 +5,6 @@
shell.enable = true; shell.enable = true;
}; };
identity.sshDefaultKey.enable = true; identity.sshDefaultKey.enable = true;
services.nixcacheOci.enable = true;
}; };
} }