2 Commits
Author SHA1 Message Date
moons-14 9bb95535cf fingerprint 2026-07-27 20:57:15 +09:00
moons-14 fcd0d75537 feat 2026-07-27 20:55:05 +09:00
47 changed files with 255 additions and 126 deletions
Generated
+32 -20
View File
@@ -729,6 +729,22 @@
}
},
"nixpkgs_10": {
"locked": {
"lastModified": 1770107345,
"narHash": "sha256-tbS0Ebx2PiA1FRW8mt8oejR0qMXmziJmPaU1d4kYY9g=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "4533d9293756b63904b7238acb84ac8fe4c8c2c4",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_11": {
"locked": {
"lastModified": 1772542754,
"narHash": "sha256-WGV2hy+VIeQsYXpsLjdr4GvHv5eECMISX1zKLTedhdg=",
@@ -744,7 +760,7 @@
"type": "github"
}
},
"nixpkgs_11": {
"nixpkgs_12": {
"locked": {
"lastModified": 1778869304,
"narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=",
@@ -868,18 +884,15 @@
},
"nixpkgs_9": {
"locked": {
"lastModified": 1770107345,
"narHash": "sha256-tbS0Ebx2PiA1FRW8mt8oejR0qMXmziJmPaU1d4kYY9g=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "4533d9293756b63904b7238acb84ac8fe4c8c2c4",
"type": "github"
"lastModified": 1784796856,
"narHash": "sha256-vwxWgF+Gj276WznzGb1LxGsK/39HaQwgQXiU3EkC844=",
"rev": "e2587caef70cea85dd97d7daab492899902dbf5d",
"type": "tarball",
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1040357.e2587caef70c/nixexprs.tar.xz"
},
"original": {
"owner": "nixos",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"type": "github"
"type": "tarball",
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
}
},
"nixvim": {
@@ -907,20 +920,19 @@
},
"noctalia": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
"nixpkgs": "nixpkgs_9"
},
"locked": {
"lastModified": 1785099099,
"narHash": "sha256-hwmc/ov72HfpuZvLX7KvaHFw3cI4KTD+O5znR9a7pcI=",
"lastModified": 1785150509,
"narHash": "sha256-9YohBD2ceAWQYoT/1/QZIuaqi99hgbiUgBWyV3z6/xM=",
"owner": "noctalia-dev",
"repo": "noctalia",
"rev": "02a846f5c947da00f3d4acdf7cf00f056d92fe3d",
"rev": "cf5c9a28fc27facf42309a558c075259e512ba66",
"type": "github"
},
"original": {
"owner": "noctalia-dev",
"ref": "cachix",
"repo": "noctalia",
"type": "github"
}
@@ -1058,7 +1070,7 @@
},
"soulver-cpp": {
"inputs": {
"nixpkgs": "nixpkgs_11",
"nixpkgs": "nixpkgs_12",
"nixpkgs-libxml2": "nixpkgs-libxml2"
},
"locked": {
@@ -1316,7 +1328,7 @@
},
"treefmt-nix_2": {
"inputs": {
"nixpkgs": "nixpkgs_9"
"nixpkgs": "nixpkgs_10"
},
"locked": {
"lastModified": 1784369104,
@@ -1334,7 +1346,7 @@
},
"vicinae": {
"inputs": {
"nixpkgs": "nixpkgs_10",
"nixpkgs": "nixpkgs_11",
"soulver-cpp": "soulver-cpp",
"systems": "systems_7"
},
+9 -5
View File
@@ -7,10 +7,10 @@
profiles = [
"base"
"interface.gui"
"platform.thinkpad"
"workload.personal"
"workload.tailscale.client"
"interface.cli"
"platform.thinkpad-x1"
"security.fingerprint"
"security.secrets"
];
};
@@ -22,7 +22,11 @@
profiles = [
"base"
"interface.cli-minimal"
"interface.cli"
"security.fingerprint"
"security.secrets"
"workload.development"
"workload.personal"
];
};
}
+6
View File
@@ -0,0 +1,6 @@
{
homebrew = {
enable = true;
casks = [ "google-chrome" ];
};
}
+2 -2
View File
@@ -1,4 +1,4 @@
{ pkgs, ... }:
{
{ lib, pkgs, ... }:
lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
home.packages = [ pkgs.google-chrome ];
}
+6
View File
@@ -0,0 +1,6 @@
{
homebrew = {
enable = true;
casks = [ "vesktop" ];
};
}
+2 -1
View File
@@ -1,3 +1,4 @@
{
{ lib, pkgs, ... }:
lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
programs.vesktop.enable = true;
}
+6
View File
@@ -0,0 +1,6 @@
{
homebrew = {
enable = true;
casks = [ "drawio" ];
};
}
+4
View File
@@ -0,0 +1,4 @@
{ lib, pkgs, ... }:
lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
home.packages = [ pkgs.drawio ];
}
+6
View File
@@ -0,0 +1,6 @@
{
homebrew = {
enable = true;
casks = [ "slack" ];
};
}
+2 -2
View File
@@ -1,4 +1,4 @@
{ pkgs, ... }:
{
{ lib, pkgs, ... }:
lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
home.packages = [ pkgs.slack ];
}
+6
View File
@@ -0,0 +1,6 @@
{
homebrew = {
enable = true;
casks = [ "zoom" ];
};
}
+2 -2
View File
@@ -1,4 +1,4 @@
{ pkgs, ... }:
{
{ lib, pkgs, ... }:
lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
home.packages = [ pkgs.zoom-us ];
}
+54
View File
@@ -0,0 +1,54 @@
# Profiles
Profiles are host-selectable compositions of independently owned units. They
describe why a group of units is enabled; application, service, system, and
hardware configuration remains in its owning unit.
## Layers
| Namespace | Purpose | Compatibility |
| ------------ | ------------------------------------------------------- | --------------- |
| `base` | Invariants required by every host | NixOS and macOS |
| `interface` | Command-line and graphical ways to operate a host | Per-profile |
| `platform` | NixOS foundation and physical or virtual hardware shape | NixOS |
| `workload` | Optional activities performed on a host | Per-profile |
| `networking` | Network roles and topology | Per-profile |
| `security` | Optional security and secret-management policies | Per-profile |
`base` intentionally contains only `systems.nix`. A unit belongs there only
when removing it from any supported host would make that host invalid.
## Compatibility
| Profile | Supported host class |
| ------------------------------------ | ------------------------------------- |
| `base` | NixOS, macOS |
| `interface.cli` | NixOS, macOS with Home Manager |
| `interface.linux-desktop` | NixOS with Home Manager |
| `interface.gnome` | NixOS with Home Manager |
| `interface.niri` | NixOS with Home Manager |
| `platform.nixos` | NixOS |
| `platform.desktop` | Physical NixOS desktop |
| `platform.laptop` | Physical NixOS laptop |
| `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS |
| `platform.vm` | QEMU NixOS guest |
| `workload.development` | NixOS, macOS with Home Manager |
| `workload.personal` | NixOS, macOS with Home Manager |
| `workload.remote-access` | NixOS, macOS |
| `workload.server` | NixOS, macOS with Home Manager |
| `networking.tailscale-client` | NixOS, macOS |
| `networking.tailscale-subnet-router` | NixOS |
| `security.fingerprint` | NixOS, macOS |
| `security.secrets` | NixOS, macOS |
| `security.secure-boot` | NixOS |
| `security.tpm-storage` | NixOS with a host-defined LUKS device |
Select independent concerns independently in `hosts/default.nix`. For example,
a minimal NixOS laptop can combine `base`, `platform.thinkpad-x1`, and
`interface.cli`, while a daily-use macOS development machine can add
`workload.development` and `workload.personal`. Hardware support does not
implicitly select an interface or workload.
`security.tpm-storage` deliberately does not own a disk identifier. A host that
selects it must define `boot.initrd.luks.devices.cryptroot.device` in its
machine-specific NixOS module.
+2 -10
View File
@@ -1,13 +1,5 @@
{
description = "base system configuration";
description = "Host-independent Nix foundation required everywhere";
includes = [
"systems.boot.base"
"systems.disko"
"systems.hardware"
"systems.locale"
"systems.networking.base"
"systems.nix"
"systems.sops"
];
includes = [ "systems.nix" ];
}
@@ -1,4 +0,0 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.tio ];
}
@@ -1,10 +0,0 @@
{
description = "interactive command-line environment";
includes = [
"profiles.interface.cli-minimal"
"applications.vim"
"applications.yazi"
"applications.zellij"
];
}
@@ -12,6 +12,7 @@
jq
nurl
ripgrep
tio
unrar
unzip
wget
@@ -1,5 +1,5 @@
{
description = "minimal command-line environment";
description = "Cross-platform interactive command-line environment";
includes = [
"applications.btop"
@@ -9,6 +9,9 @@
"applications.nh"
"applications.nix-index"
"applications.ssh"
"applications.vim"
"applications.yazi"
"applications.zellij"
"applications.zoxide"
"applications.zsh"
];
@@ -0,0 +1,8 @@
{
description = "GNOME desktop session for NixOS";
includes = [
"profiles.interface.linux-desktop"
"applications.gnome"
];
}
-23
View File
@@ -1,23 +0,0 @@
{
description = "NixOS graphical desktop environment";
includes = [
"profiles.interface.cli-interactive"
"applications.1password"
"applications.fcitx5"
"applications.ghostty"
"applications.gnome"
"applications.gtk"
"applications.kde"
"applications.nautilus"
"applications.niri"
"applications.noctalia"
"applications.vicinae"
"hardwares.graphics"
"services.ly"
"services.swayidle"
"services.swaylock"
"systems.audio"
"systems.fonts"
];
}
@@ -0,0 +1,14 @@
{
description = "Shared NixOS graphical desktop foundation";
includes = [
"applications.fcitx5"
"applications.ghostty"
"applications.gtk"
"applications.nautilus"
"applications.vicinae"
"hardwares.graphics"
"systems.audio"
"systems.fonts"
];
}
+12
View File
@@ -0,0 +1,12 @@
{
description = "niri desktop session for NixOS";
includes = [
"profiles.interface.linux-desktop"
"applications.niri"
"applications.noctalia"
"services.ly"
"services.swayidle"
"services.swaylock"
];
}
@@ -0,0 +1,5 @@
{
description = "Tailscale client for NixOS and macOS";
includes = [ "services.tailscale" ];
}
@@ -0,0 +1,5 @@
{
description = "Tailscale subnet router for NixOS";
includes = [ "services.tailscale" ];
}
+6 -2
View File
@@ -1,5 +1,9 @@
{
description = "UEFI desktop platform";
description = "Physical NixOS desktop";
includes = [ "systems.boot.uefi" ];
includes = [
"profiles.platform.nixos"
"systems.boot.uefi"
"systems.hardware"
];
}
+3 -3
View File
@@ -1,11 +1,11 @@
{
description = "laptop platform configuration";
description = "Physical NixOS laptop";
includes = [
"profiles.platform.nixos"
"hardwares.bluetooth"
"hardwares.ipu6-camera"
"systems.boot.uefi"
"systems.fingerprint"
"systems.hardware"
"systems.networking.wifi"
"systems.power"
];
+9
View File
@@ -0,0 +1,9 @@
{
description = "Foundation shared by all NixOS platforms";
includes = [
"systems.boot.base"
"systems.locale"
"systems.networking.base"
];
}
@@ -1,8 +1,9 @@
{
description = "ThinkPad laptop platform";
description = "Intel ThinkPad X1 laptop hardware";
includes = [
"profiles.platform.laptop"
"hardwares.intel-driver"
"hardwares.ipu6-camera"
];
}
+2 -3
View File
@@ -1,9 +1,8 @@
{
description = "virtual-machine platform";
description = "QEMU NixOS guest";
includes = [
"profiles.platform.nixos"
"hardwares.qemu-guest"
"systems.boot.nfs"
"systems.boot.uefi"
];
}
@@ -0,0 +1,5 @@
{
description = "Fingerprint authentication for NixOS and macOS";
includes = [ "systems.fingerprint" ];
}
@@ -0,0 +1,5 @@
{
description = "Cross-platform SOPS and age secret management";
includes = [ "systems.sops" ];
}
@@ -0,0 +1,5 @@
{
description = "Secure Boot for NixOS";
includes = [ "systems.boot.secure-boot" ];
}
@@ -0,0 +1,5 @@
{
description = "TPM-backed LUKS unlock for NixOS";
includes = [ "systems.boot.storage-crypto" ];
}
+8 -11
View File
@@ -1,13 +1,10 @@
{ lib, pkgs, ... }:
{ pkgs, ... }:
{
home.packages =
with pkgs;
[
bind
bun
nil
python312
uv
]
++ lib.optionals stdenv.hostPlatform.isLinux [ drawio ];
home.packages = with pkgs; [
bind
bun
nil
python312
uv
];
}
@@ -1,5 +1,5 @@
{
description = "software development workload";
description = "Cross-platform software development environment";
includes = [
"applications.arduino"
@@ -7,6 +7,7 @@
"applications.codex"
"applications.codex-desktop"
"applications.docker"
"applications.drawio"
"applications.grok"
"applications.java"
"applications.opencode"
+3 -1
View File
@@ -1,9 +1,11 @@
{
description = "personal communication and browser workload";
description = "Cross-platform personal desktop applications";
includes = [
"applications.1password"
"applications.chrome"
"applications.discord"
"applications.kde"
"applications.slack"
"applications.zoom"
];
@@ -0,0 +1,5 @@
{
description = "Cross-platform remote shell access";
includes = [ "services.openssh" ];
}
@@ -1,5 +0,0 @@
{
description = "remote-access workload";
includes = [ "services.openssh" ];
}
@@ -1,8 +0,0 @@
{
description = "secure boot and TPM-backed storage";
includes = [
"systems.boot.secure-boot"
"systems.boot.storage-crypto"
];
}
+1 -1
View File
@@ -1,5 +1,5 @@
{
description = "server workload";
description = "Cross-platform container and remote-access server";
includes = [
"applications.docker"
@@ -1,5 +0,0 @@
{
description = "Tailscale client";
includes = [ "services.tailscale" ];
}
@@ -1,5 +0,0 @@
{
description = "Tailscale subnet-router server";
includes = [ "services.tailscale" ];
}
+6
View File
@@ -0,0 +1,6 @@
{
security.pam.services.sudo_local = {
touchIdAuth = true;
reattach = true;
};
}