mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-06 05:18:12 +09:00
Compare commits
35
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
08210abf01 | ||
|
|
eadfa9b331 | ||
|
|
0f3b6c59a2 | ||
|
|
c6fe17de3f | ||
|
|
ac60dc343b | ||
|
|
ebef49064c | ||
|
|
691926aa4f | ||
|
|
37e2184d36 | ||
|
|
52e5fcd47f | ||
|
|
fe785b1fc3 | ||
|
|
b8532ff1b4 | ||
|
|
3a20fe9a09 | ||
|
|
ef7ff60537 | ||
|
|
53f4d2475b | ||
|
|
7d670b03b2 | ||
|
|
2d9154614b | ||
|
|
56bc3161d7 | ||
|
|
10f4d99cb7 | ||
|
|
12badacf46 | ||
|
|
937be12e33 | ||
|
|
8761cbfe40 | ||
|
|
e789b5a16f | ||
|
|
008f704b23 | ||
|
|
11c1e24ccd | ||
|
|
ad8337bfbb | ||
|
|
cf23e1ef63 | ||
|
|
4652d911ee | ||
|
|
c7db764fe2 | ||
|
|
63f49d58f8 | ||
|
|
8189373575 | ||
|
|
d4721d1d22 | ||
|
|
cc3798a7b2 | ||
|
|
0ff78c6848 | ||
|
|
c53a0c0bed | ||
|
|
e3d61e8b6d |
@@ -351,6 +351,7 @@ modules/profiles/
|
||||
├── base/
|
||||
├── interface/
|
||||
│ ├── cli/
|
||||
│ ├── minimal/
|
||||
│ ├── gui/
|
||||
│ ├── macos/
|
||||
│ ├── linux-desktop/
|
||||
@@ -368,10 +369,13 @@ modules/profiles/
|
||||
│ └── vm/
|
||||
├── workload/
|
||||
│ ├── camera/
|
||||
│ ├── deploy-rs-target/
|
||||
│ ├── development/
|
||||
│ ├── game/
|
||||
│ ├── machine-learning/
|
||||
│ ├── network-lab/
|
||||
│ ├── personal/
|
||||
│ ├── photography/
|
||||
│ ├── server/
|
||||
│ └── remote-access/
|
||||
└── security/
|
||||
@@ -392,16 +396,21 @@ The profile layers have these responsibilities:
|
||||
- `base` contains only invariants required by every supported host. It includes
|
||||
`systems.nix` and the universal Atuin, tealdeer, trippy, and xh CLI tools;
|
||||
optional secrets, interface, hardware, and workloads do not belong there.
|
||||
- `interface` describes how the host is operated. `interface.cli` is shared by
|
||||
NixOS and macOS and includes `tio`. `interface.gui` owns cross-platform
|
||||
graphical interface applications such as Vicinae. `interface.macos` owns the
|
||||
macOS Finder, Dock, trackpad, and shared default preferences and includes
|
||||
`interface.gui`.
|
||||
- `interface` describes how the host is operated. `interface.minimal` is shared
|
||||
by NixOS and macOS and provides the remote-administration CLI baseline,
|
||||
including SSH, Nano, htop, Git, Zellij, and Zsh. `interface.cli` includes that
|
||||
baseline and adds the full interactive command-line environment, including
|
||||
the configured Neovim, Yazi, and `tio`. `interface.gui` owns
|
||||
cross-platform graphical interface applications such as Vicinae.
|
||||
`interface.macos` owns the macOS Finder, Dock, trackpad, and shared default
|
||||
preferences and includes `interface.gui`.
|
||||
`interface.linux-desktop` owns the common labwc/niri desktop selection,
|
||||
including Ghostty and Nautilus, and also includes `interface.gui`. Labwc and
|
||||
niri remain independently selectable and do not imply CLI or personal
|
||||
workloads.
|
||||
- `platform` describes NixOS foundations and physical or virtual form factors.
|
||||
`platform.nixos` selects the shared network foundation and `services.clatd`;
|
||||
VM, laptop, and desktop platform profiles inherit both.
|
||||
macOS does not need an empty symmetric platform profile.
|
||||
- `workload` describes optional host uses. `workload.development` and
|
||||
`workload.personal` are cross-platform profiles, not `*-linux` variants.
|
||||
@@ -541,9 +550,26 @@ A host registry may use a specification like this:
|
||||
|
||||
profiles = [
|
||||
"base"
|
||||
"interface.cli"
|
||||
"interface.minimal"
|
||||
"platform.vm"
|
||||
"workload.remote-access"
|
||||
"workload.deploy-rs-target"
|
||||
];
|
||||
};
|
||||
|
||||
netsrv-01 = {
|
||||
system = "x86_64-linux";
|
||||
stateVersion = "26.05";
|
||||
user = "moons";
|
||||
path = ./netsrv-01;
|
||||
|
||||
profiles = [
|
||||
"base"
|
||||
"interface.minimal"
|
||||
"platform.vm"
|
||||
"workload.remote-access"
|
||||
"workload.deploy-rs-target"
|
||||
"workload.server"
|
||||
];
|
||||
};
|
||||
|
||||
@@ -555,7 +581,7 @@ A host registry may use a specification like this:
|
||||
|
||||
profiles = [
|
||||
"base"
|
||||
"interface.cli"
|
||||
"interface.minimal"
|
||||
"platform.vm"
|
||||
"workload.server"
|
||||
];
|
||||
@@ -607,6 +633,7 @@ A host registry may use a specification like this:
|
||||
"security.tpm-storage"
|
||||
"workload.camera"
|
||||
"workload.development"
|
||||
"workload.network-lab"
|
||||
"workload.personal"
|
||||
];
|
||||
};
|
||||
@@ -629,7 +656,9 @@ A host registry may use a specification like this:
|
||||
"workload.development"
|
||||
"workload.game"
|
||||
"workload.machine-learning"
|
||||
"workload.network-lab"
|
||||
"workload.personal"
|
||||
"workload.photography"
|
||||
];
|
||||
};
|
||||
|
||||
@@ -652,14 +681,22 @@ A host registry may use a specification like this:
|
||||
```
|
||||
|
||||
The current role assignment is intentional: nix-example is the development VM;
|
||||
ops is the remote-access VM with host-specific static networking;
|
||||
internal-app-01 is the container server VM; and installer builds the minimal
|
||||
installation ISO without Home Manager. x1g9 is a full NixOS desktop with niri,
|
||||
ops is the minimal-interface remote-access VM with host-specific static
|
||||
networking; netsrv-01 is the deploy-rs-managed container server VM;
|
||||
internal-app-01 is the minimal-interface container server VM;
|
||||
nix-builder is the minimal-interface remote Nix build VM with dedicated build
|
||||
and store disks; and installer builds the minimal installation ISO without Home
|
||||
Manager. x1g9 is a full NixOS desktop with niri,
|
||||
labwc, ly, the shared Linux desktop applications, and the personal workload.
|
||||
x1g13 is the secure NixOS development and personal ThinkPad, with the same
|
||||
desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk
|
||||
unlock. galleria is the Intel/NVIDIA physical desktop shared with Windows; it
|
||||
uses dedicated NixOS partitions, LUKS, Secure Boot, and TPM-backed disk unlock.
|
||||
It selects `workload.photography` for AI-enabled darktable. The application
|
||||
chooses CUDA support from the NVIDIA hardware unit's enable state and keeps
|
||||
the default CUDA targets, including RTX 3060 Ti support, to reuse binary caches.
|
||||
galleria and x1g13 select `workload.network-lab` for containerlab, Docker, and
|
||||
the NanoKVM-USB desktop client with serial-port access.
|
||||
m2 is the daily-use macOS development and personal machine with the macOS
|
||||
interface defaults. Keep the desktop sessions independently selectable, and
|
||||
keep the development and personal profiles usable across NixOS and Darwin.
|
||||
@@ -692,6 +729,15 @@ configuration fragments. For example:
|
||||
|
||||
```text
|
||||
hosts/
|
||||
├── nix-builder/
|
||||
│ ├── disko.nix
|
||||
│ ├── hardware-configuration.nix
|
||||
│ └── nixos.nix
|
||||
├── netsrv-01/
|
||||
│ ├── disko.nix
|
||||
│ ├── hardware-configuration.nix
|
||||
│ ├── networking.nix
|
||||
│ └── nixos.nix
|
||||
├── installer/
|
||||
│ └── nixos.nix
|
||||
├── internal-app-01/
|
||||
@@ -721,12 +767,15 @@ hosts/
|
||||
```
|
||||
|
||||
`hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the
|
||||
normal top-level Nix module `imports`. `hosts/x1g13/nixos.nix` loads its
|
||||
generated hardware configuration and host-local `disko.nix` the same way. Do
|
||||
not confuse these host imports with the prohibition on top-level `imports` in
|
||||
unit configuration fragments. `hosts/galleria/disko.nix` manages only the two
|
||||
dedicated NixOS partitions by PARTUUID and deliberately excludes the Windows
|
||||
disk, Windows partitions, and the Windows EFI System Partition.
|
||||
normal top-level Nix module `imports`. `hosts/nix-builder/nixos.nix` and
|
||||
`hosts/x1g13/nixos.nix` load their generated hardware configuration and
|
||||
host-local `disko.nix` the same way. The nix-builder Disko definition mounts its
|
||||
existing VM filesystems by stable QEMU SCSI IDs and does not take destructive
|
||||
ownership of them. Do not confuse these host imports with the prohibition on
|
||||
top-level `imports` in unit configuration fragments. `hosts/galleria/disko.nix`
|
||||
manages only the two dedicated NixOS partitions by PARTUUID and deliberately
|
||||
excludes the Windows disk, Windows partitions, and the Windows EFI System
|
||||
Partition.
|
||||
|
||||
Derive the system class from the host's `system`:
|
||||
|
||||
@@ -829,8 +878,9 @@ For profile changes, additionally:
|
||||
`homebrew.casks` selection as well as module evaluation.
|
||||
- Preserve the intended host roles: nix-example remains the development VM;
|
||||
ops remains the statically networked remote-access VM; internal-app-01 remains
|
||||
the container server VM; installer remains the Home Manager-free installation
|
||||
ISO; x1g9 provides niri, labwc, ly, and the personal application set; x1g13
|
||||
the container server VM; netsrv-01 remains the deploy-rs-managed container
|
||||
server VM; installer remains the Home Manager-free installation ISO; x1g9
|
||||
provides niri, labwc, ly, and the personal application set; x1g13
|
||||
additionally provides the development, Tailscale client, secrets, Secure Boot,
|
||||
and TPM storage roles; galleria remains the Intel/NVIDIA dual-boot desktop
|
||||
with LUKS, Secure Boot, and TPM storage; m2 remains the daily-use development
|
||||
|
||||
@@ -0,0 +1,153 @@
|
||||
# NixOSインストール手順(SOPSなし・ディスク暗号化なし)
|
||||
|
||||
この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を
|
||||
使用しないホスト向けの、独立したインストール手順である。
|
||||
|
||||
SOPSとディスク暗号化を使用する場合は、[暗号化ありの手順](install.md)を参照。
|
||||
|
||||
## 事前準備
|
||||
|
||||
1. [ISOビルド](iso-build.md)を参照してISOを作成
|
||||
2. USBに書き込んで対象マシンでブート
|
||||
|
||||
## ネットワーク接続
|
||||
|
||||
### 有線LAN
|
||||
|
||||
DHCPで自動設定される。
|
||||
|
||||
### Wi-Fi(有線が使えない場合)
|
||||
|
||||
```bash
|
||||
nmcli device wifi connect <SSID> --ask
|
||||
```
|
||||
|
||||
## SSH接続
|
||||
|
||||
コンソールに表示されたIPアドレスに接続:
|
||||
|
||||
```bash
|
||||
ssh root@<ip-address>
|
||||
```
|
||||
|
||||
## インストール手順
|
||||
|
||||
### 1. dotfilesのクローン
|
||||
|
||||
```bash
|
||||
git clone [email protected]:moons-14/dotfiles.git ~/dotfiles
|
||||
cd ~/dotfiles
|
||||
```
|
||||
|
||||
### 2. ホスト設定の作成
|
||||
|
||||
`hosts/<hostname>/nixos.nix`を作成し、`hosts/default.nix`にホストと使用する
|
||||
プロファイルを登録する。ホスト固有の設定だけをホストディレクトリに置き、
|
||||
再利用可能な設定は適切なunitまたはprofileに置く。
|
||||
|
||||
### 3. インストール先ディスクの確認
|
||||
|
||||
```bash
|
||||
lsblk -o NAME,PATH,SIZE,MODEL,SERIAL,TYPE,FSTYPE,MOUNTPOINTS
|
||||
ls -l /dev/disk/by-id/
|
||||
```
|
||||
|
||||
以降の操作では指定したディスクの既存データが消去される。対象を必ず確認し、
|
||||
可能であれば`/dev/sda`や`/dev/nvme0n1`ではなく、安定した
|
||||
`/dev/disk/by-id/...`パスを使用する。
|
||||
|
||||
### 4. Disko設定の作成
|
||||
|
||||
`hosts/<hostname>/disko.nix`を作成する:
|
||||
|
||||
```nix
|
||||
_:
|
||||
{
|
||||
disko.enableConfig = true;
|
||||
|
||||
disko.devices.disk.main = {
|
||||
type = "disk";
|
||||
device = "/dev/disk/by-id/<target-disk>";
|
||||
content = {
|
||||
type = "gpt";
|
||||
partitions = {
|
||||
ESP = {
|
||||
size = "512M";
|
||||
type = "EF00";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "vfat";
|
||||
mountpoint = "/boot";
|
||||
};
|
||||
};
|
||||
root = {
|
||||
size = "100%";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "ext4";
|
||||
mountpoint = "/";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
```
|
||||
|
||||
`<target-disk>`を手順3で確認した実際のディスクIDに置き換える。指定した
|
||||
ディスクの既存データは消去される。
|
||||
|
||||
### 5. パーティション作成とマウント
|
||||
|
||||
```bash
|
||||
disko --mode destroy,format,mount hosts/<hostname>/disko.nix
|
||||
```
|
||||
|
||||
Diskoの実行結果を確認する:
|
||||
|
||||
```bash
|
||||
findmnt /mnt
|
||||
findmnt /mnt/boot
|
||||
```
|
||||
|
||||
### 6. ハードウェア設定の生成
|
||||
|
||||
```bash
|
||||
nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \
|
||||
> ~/dotfiles/hosts/<hostname>/hardware-configuration.nix
|
||||
```
|
||||
|
||||
### 7. ホストモジュールから設定を読み込む
|
||||
|
||||
`hosts/<hostname>/nixos.nix`で、生成したハードウェア設定とDisko設定を読み込む:
|
||||
|
||||
```nix
|
||||
{
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
./disko.nix
|
||||
];
|
||||
}
|
||||
```
|
||||
|
||||
### 8. NixOSインストール
|
||||
|
||||
```bash
|
||||
nixos-install --flake ~/dotfiles#<hostname>
|
||||
```
|
||||
|
||||
SOPSを使用しないため、age鍵の登録、シークレットの再暗号化、SSHホストキーの
|
||||
事前生成とコピーは不要である。OpenSSHを有効にしたホストでは、SSHホストキーは
|
||||
通常の初回起動時に生成される。
|
||||
|
||||
### 9. 再起動
|
||||
|
||||
```bash
|
||||
reboot
|
||||
```
|
||||
|
||||
## インストール後の確認
|
||||
|
||||
- 正しいディスクから起動できるか
|
||||
- `/`と`/boot`が意図したファイルシステムからマウントされているか
|
||||
- ネットワークと、設定している場合はSSH接続が利用できるか
|
||||
+32
-44
@@ -1,4 +1,10 @@
|
||||
# NixOSインストール手順
|
||||
# NixOSインストール手順(SOPS・ディスク暗号化あり)
|
||||
|
||||
この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を
|
||||
使用するホスト向けである。
|
||||
|
||||
どちらも使用しない場合は、
|
||||
[SOPSなし・ディスク暗号化なしの手順](install-simple.md)を参照。
|
||||
|
||||
## 事前準備
|
||||
|
||||
@@ -83,54 +89,36 @@ sops updatekeys secrets/hosts/<hostname>/*.yaml
|
||||
|
||||
新しいホスト用の`hosts/<hostname>/disko.nix`を作成。
|
||||
|
||||
#### シンプル構成(暗号化なし)
|
||||
|
||||
```nix
|
||||
_:
|
||||
{
|
||||
disko.enableConfig = true;
|
||||
|
||||
disko.devices.disk.main = {
|
||||
type = "disk";
|
||||
device = "/dev/sda";
|
||||
content = {
|
||||
type = "gpt";
|
||||
partitions = {
|
||||
ESP = {
|
||||
size = "512M";
|
||||
type = "EF00";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "vfat";
|
||||
mountpoint = "/boot";
|
||||
};
|
||||
};
|
||||
root = {
|
||||
size = "100%";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "ext4";
|
||||
mountpoint = "/";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
```
|
||||
|
||||
#### LUKS暗号化 + btrfs
|
||||
|
||||
`hosts/x1g13/disko.nix`を参照。
|
||||
LUKS暗号化とbtrfsの構成は`hosts/x1g13/disko.nix`を参照。
|
||||
|
||||
### 7. ディスクのパーティション
|
||||
|
||||
```bash
|
||||
cd ~/dotfiles
|
||||
nix run github:nix-community/disko -- --mode disko hosts/<hostname>/disko.nix
|
||||
disko --mode destroy,format,mount hosts/<hostname>/disko.nix
|
||||
```
|
||||
|
||||
### 8. ホストキーのコピー
|
||||
### 8. ハードウェア設定の生成
|
||||
|
||||
対象マシンのハードウェア設定を生成し、新しいホストのディレクトリへ直接保存:
|
||||
|
||||
```bash
|
||||
nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \
|
||||
> ~/dotfiles/hosts/<hostname>/hardware-configuration.nix
|
||||
```
|
||||
|
||||
`hosts/<hostname>/nixos.nix`から生成した設定とDisko設定を読み込む:
|
||||
|
||||
```nix
|
||||
{
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
./disko.nix
|
||||
];
|
||||
}
|
||||
```
|
||||
|
||||
### 9. ホストキーのコピー
|
||||
|
||||
```bash
|
||||
mkdir -p /mnt/etc/ssh
|
||||
@@ -138,13 +126,13 @@ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/
|
||||
chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key
|
||||
```
|
||||
|
||||
### 9. NixOSインストール
|
||||
### 10. NixOSインストール
|
||||
|
||||
```bash
|
||||
nixos-install --flake ~/dotfiles#<hostname>
|
||||
```
|
||||
|
||||
### 10. 再起動
|
||||
### 11. 再起動
|
||||
|
||||
```bash
|
||||
reboot
|
||||
|
||||
+72
-12
@@ -1,26 +1,86 @@
|
||||
# カスタムISOビルド
|
||||
# カスタムインストーラー ISO
|
||||
|
||||
`hosts/installer` から、NixOS 26.05 ベースの `x86_64-linux` 用インストーラー
|
||||
ISO を作成する。installer ホストは Home Manager を使用せず、`base` プロファイルと
|
||||
ホスト固有のインストール支援設定だけを含む。
|
||||
|
||||
## ビルド
|
||||
|
||||
flake 対応の Nix が利用できる環境で、リポジトリのルートから実行する。
|
||||
`x86_64-linux` 以外のマシンで実行する場合は、対応する Linux リモートビルダーが
|
||||
必要になる。
|
||||
|
||||
```bash
|
||||
nix build .#nixosConfigurations.installer.config.system.build.isoImage
|
||||
```
|
||||
|
||||
## ISO書き込み
|
||||
生成された ISO は次の場所にある。
|
||||
|
||||
```text
|
||||
result/iso/nixos-minimal-*-x86_64-linux.iso
|
||||
```
|
||||
|
||||
ファイル名に含まれる NixOS のバージョンとリビジョンは、`flake.lock` の更新に応じて
|
||||
変わる。生成物を確認するには次を実行する。
|
||||
|
||||
```bash
|
||||
# USBデバイスの確認
|
||||
lsblk
|
||||
ls -lh result/iso/*.iso
|
||||
sha256sum result/iso/*.iso
|
||||
```
|
||||
|
||||
# 書き込み(/dev/sdXは実際のデバイスに置き換える)
|
||||
sudo dd if=./result/nixos-minimal-*.iso of=/dev/sdX bs=4M status=progress
|
||||
## USB メモリへの書き込み
|
||||
|
||||
書き込み先はパーティション(例: `/dev/sdX1`)ではなく、USB デバイス全体
|
||||
(例: `/dev/sdX`)を指定する。この操作は指定したデバイスの内容を上書きするため、
|
||||
サイズ、モデル、マウント先を確認する。
|
||||
|
||||
```bash
|
||||
lsblk -p -o NAME,SIZE,TYPE,MODEL,MOUNTPOINTS
|
||||
```
|
||||
|
||||
USB のマウント済みパーティションをアンマウントしてから、`/dev/sdX` と
|
||||
`/dev/sdX1` を確認した実際のデバイス名に置き換えて書き込む。パーティションが
|
||||
複数ある場合は、それぞれをアンマウントする。
|
||||
|
||||
```bash
|
||||
sudo umount /dev/sdX1
|
||||
sudo dd if=result/iso/nixos-minimal-*-x86_64-linux.iso \
|
||||
of=/dev/sdX bs=4M conv=fsync status=progress
|
||||
sync
|
||||
```
|
||||
|
||||
## ISOの特徴
|
||||
書き込み完了後、USB を安全に取り外して対象マシンから起動する。
|
||||
|
||||
- SSH鍵認証でrootログイン可能
|
||||
- 有線LANはDHCPで自動設定
|
||||
- WiFiは`nmcli`で手動設定可能
|
||||
- disko/sops/ageなどのツールを内蔵
|
||||
- ブート時にIPアドレスとヘルプを表示
|
||||
## 起動後の接続
|
||||
|
||||
有線 LAN は DHCP で自動設定される。Wi-Fi を使用する場合は、インストーラーの
|
||||
コンソールで NetworkManager を使って接続する。
|
||||
|
||||
```bash
|
||||
nmcli device wifi list
|
||||
nmcli device wifi connect <SSID> --ask
|
||||
```
|
||||
|
||||
起動時にコンソールへ IPv4 アドレスと簡易ヘルプが表示される。表示されたアドレスへ
|
||||
登録済みの SSH 鍵で接続する。
|
||||
|
||||
```bash
|
||||
ssh root@<ip-address>
|
||||
```
|
||||
|
||||
root のパスワードログインとキーボード対話認証は無効で、
|
||||
`hosts/installer/nixos.nix` に登録された公開鍵だけが利用できる。
|
||||
以降の作業は、構成に応じて次の手順を参照する:
|
||||
|
||||
- [SOPSなし・ディスク暗号化なし](install-simple.md)
|
||||
- [SOPS・ディスク暗号化あり](install.md)
|
||||
|
||||
## ISO に含まれる主な設定とツール
|
||||
|
||||
- Nix flakes と `nix-command`
|
||||
- NetworkManager、OpenSSH、起動時の IP アドレス表示
|
||||
- `disko`、`parted`、`cryptsetup`、`btrfs-progs`、`efibootmgr`
|
||||
- `sops`、`age`、`ssh-to-age`
|
||||
- `age-plugin-yubikey`、`yubikey-manager`、`pcsc-tools` と `pcscd`
|
||||
- `sbctl`、`tpm2-tools`
|
||||
- `git`、`rsync`、`vim`、`wget`、`curl`、`jq`、`pciutils`、`util-linux`
|
||||
|
||||
Generated
+197
-161
@@ -100,11 +100,11 @@
|
||||
"systems": "systems"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787888246,
|
||||
"narHash": "sha256-E8vD7IJ/16J9JPTQKYvSmwq5k0/FdLMtLf7UVk3G0IU=",
|
||||
"lastModified": 1790375278,
|
||||
"narHash": "sha256-oGv6aatLyq8Eha1ZA5wbkdRhlE3WdmOt9yajLeTgnCk=",
|
||||
"owner": "nix-community",
|
||||
"repo": "browser-previews",
|
||||
"rev": "f2e8d11fd3e04175290fe16e882ceb9dd064a8e2",
|
||||
"rev": "ef13999ddd920d61e5c7cfae16177de7ffb62e61",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -158,15 +158,16 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1784665499,
|
||||
"narHash": "sha256-9BMxlTxCCDAeoNLtb1a/st7udtTIJep+wpUzquA29VU=",
|
||||
"owner": "nix-community",
|
||||
"lastModified": 1790001035,
|
||||
"narHash": "sha256-1/SLBjSYBzDdDhvLQ83wrzBakyS/xNGgtxHGNuveOEQ=",
|
||||
"owner": "Mic92",
|
||||
"repo": "bun2nix",
|
||||
"rev": "0f2a1f0b6f42cebe3b149bf62d38754c5e0e9729",
|
||||
"rev": "07a5bfc8ac36c5370199343fa620b69f63186e33",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-community",
|
||||
"owner": "Mic92",
|
||||
"ref": "llm-agents",
|
||||
"repo": "bun2nix",
|
||||
"type": "github"
|
||||
}
|
||||
@@ -206,11 +207,11 @@
|
||||
"nixpkgs": "nixpkgs"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787978476,
|
||||
"narHash": "sha256-aI5mJw5GJ6YADjRLvu5KLK6NK7NCnLveQyNqHl4sDP4=",
|
||||
"lastModified": 1790510073,
|
||||
"narHash": "sha256-ePu9Vqm1/S/lTidMGMnPS3PheOb2sEOqJ5iBA74A8nY=",
|
||||
"owner": "ilysenko",
|
||||
"repo": "codex-desktop-linux",
|
||||
"rev": "7994f23cd5c2da23cdc0953367ff6056ebed50b3",
|
||||
"rev": "5b80192545dcc9a820c49cf26c806308a7afd551",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -238,6 +239,24 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"containerlab": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_4"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1790449163,
|
||||
"narHash": "sha256-BWqGSYpBep1D8JxQPFwXVuYsn5LxlB2kR7nfnCQbUjc=",
|
||||
"owner": "srl-labs",
|
||||
"repo": "containerlab",
|
||||
"rev": "0bb144e1d03fb3546abd15a0565562382ab85437",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "srl-labs",
|
||||
"repo": "containerlab",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"crane": {
|
||||
"locked": {
|
||||
"lastModified": 1784407669,
|
||||
@@ -255,11 +274,11 @@
|
||||
},
|
||||
"crane_2": {
|
||||
"locked": {
|
||||
"lastModified": 1787326676,
|
||||
"narHash": "sha256-lWhBbBvC05/xwivKBBiM2YNizpmgqCgyOIzomvRuwxs=",
|
||||
"lastModified": 1789760033,
|
||||
"narHash": "sha256-jtT4yxZpR8seYnlCMMWSSPlFN92zO6ICuZ8pJrmi86k=",
|
||||
"owner": "ipetkov",
|
||||
"repo": "crane",
|
||||
"rev": "692f7e9ef2ece8125b466f66f2af532b3edaed0d",
|
||||
"rev": "73b980519cefc727a5f6cc8e5c0947a2f9be6edd",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -275,11 +294,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1781152676,
|
||||
"narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=",
|
||||
"lastModified": 1789770686,
|
||||
"narHash": "sha256-uZkBR7yHdIKUFB5SZdfgh1qkGfI3XmYmI/lTiquxbck=",
|
||||
"owner": "nix-community",
|
||||
"repo": "disko",
|
||||
"rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1",
|
||||
"rev": "725ea35e410ad83be4931d1bff7e090eacaf3563",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -446,11 +465,11 @@
|
||||
"nixpkgs-lib": "nixpkgs-lib_2"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787559586,
|
||||
"narHash": "sha256-onL0VLf9vPllmT0H/OlURIU5r5t5WIEl7t4tVNKT0Nw=",
|
||||
"lastModified": 1788450739,
|
||||
"narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"rev": "9d0d87172c374f89da73c1cfe6d81ae62feac1f1",
|
||||
"rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -467,11 +486,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787559586,
|
||||
"narHash": "sha256-onL0VLf9vPllmT0H/OlURIU5r5t5WIEl7t4tVNKT0Nw=",
|
||||
"lastModified": 1788450739,
|
||||
"narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"rev": "9d0d87172c374f89da73c1cfe6d81ae62feac1f1",
|
||||
"rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -488,11 +507,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1785627969,
|
||||
"narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=",
|
||||
"lastModified": 1788450739,
|
||||
"narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a",
|
||||
"rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -581,17 +600,17 @@
|
||||
"inputs": {
|
||||
"flake-compat": "flake-compat_2",
|
||||
"home-manager": "home-manager_2",
|
||||
"nixpkgs": "nixpkgs_4",
|
||||
"nixpkgs": "nixpkgs_5",
|
||||
"systems": "systems_4",
|
||||
"zig": "zig",
|
||||
"zon2nix": "zon2nix"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1788019183,
|
||||
"narHash": "sha256-WYLVuVgxCq2OH7+2DuBpBW8KBSYJjwbZn9sZrXALlQY=",
|
||||
"lastModified": 1790475802,
|
||||
"narHash": "sha256-jGBYacSDg7Ya/P3OpkuM+EK+kW4JAPIiGTxEdWMc6PQ=",
|
||||
"owner": "ghostty-org",
|
||||
"repo": "ghostty",
|
||||
"rev": "7b47213f94058c3715205ce8fa73f7ae581a652c",
|
||||
"rev": "b40acce58dcf77df52231c3798ea58e924647c89",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -626,14 +645,14 @@
|
||||
"git-hooks-nix": {
|
||||
"inputs": {
|
||||
"flake-compat": "flake-compat_3",
|
||||
"nixpkgs": "nixpkgs_5"
|
||||
"nixpkgs": "nixpkgs_6"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787424939,
|
||||
"narHash": "sha256-O2tBn84NNuHrnqNVxx/XqsXwfYvS1YwBh+7CBnbCYsk=",
|
||||
"lastModified": 1790500375,
|
||||
"narHash": "sha256-XN3sDtn8TU9hAc9xqZ+SqRB/HHm2wjxM6aSWYLJU+oo=",
|
||||
"owner": "cachix",
|
||||
"repo": "git-hooks.nix",
|
||||
"rev": "809414f0cdadf82cf11b06c2b29ba9b3168b3297",
|
||||
"rev": "a0e4241b51206fbcbf52fd322eb5f0cd80f153c4",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -712,11 +731,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787377438,
|
||||
"narHash": "sha256-Sxu1NLTD/Ern6hFGLlZmtKCSct3YQXZI/lls8RE1XeM=",
|
||||
"lastModified": 1790215976,
|
||||
"narHash": "sha256-VkR1rMGyjU9jtw8ISFx5uqR9e+LEaOlhHwrseFkiIVk=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "65258d5c65a250189fde2e35f490d15e064c4c62",
|
||||
"rev": "a6631107a83ceab5872f298a2ea710859c80c4cb",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -757,11 +776,11 @@
|
||||
"rust-overlay": "rust-overlay_2"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787658383,
|
||||
"narHash": "sha256-I+zCjwAtkmgnet+08H+7HV8qJjf6BoFMYsX/8lMiW/s=",
|
||||
"lastModified": 1790423250,
|
||||
"narHash": "sha256-sr4Kfp6yaXUeyKL6n0Y8/ElcR3momIRC20HFc+LF22s=",
|
||||
"owner": "nix-community",
|
||||
"repo": "lanzaboote",
|
||||
"rev": "69cf334f9dbc11213c6228c97e9b32924d51443f",
|
||||
"rev": "c1c5edd31802d181c8aa2c71588995d93425d650",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -790,16 +809,16 @@
|
||||
"inputs": {
|
||||
"bun2nix": "bun2nix_2",
|
||||
"flake-parts": "flake-parts_4",
|
||||
"nixpkgs": "nixpkgs_6",
|
||||
"nixpkgs": "nixpkgs_7",
|
||||
"systems": "systems_5",
|
||||
"treefmt-nix": "treefmt-nix_3"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1788038998,
|
||||
"narHash": "sha256-Q8sIuu2wRET+POhXUGVUaEDKT2OcZyKXLAf744qrbGk=",
|
||||
"lastModified": 1790555299,
|
||||
"narHash": "sha256-A4ZG1Y9Itut5xO+CLwi06CElVlwj4FnhZMgg2Xiucho=",
|
||||
"owner": "numtide",
|
||||
"repo": "llm-agents.nix",
|
||||
"rev": "44099f2474161ef95a2b1ec1d8088ae8a6673a77",
|
||||
"rev": "2475131b50dbc795684c55ba771d94401f068fd6",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -826,14 +845,14 @@
|
||||
},
|
||||
"nani-translate-linux": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_7"
|
||||
"nixpkgs": "nixpkgs_8"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1786578029,
|
||||
"narHash": "sha256-XXTxlJ6U7hhHA94eTDCL80iKUwJ54L1EZ9oj/d0hC48=",
|
||||
"lastModified": 1789710762,
|
||||
"narHash": "sha256-U9BDfeN+st7GQoC3byKaj9rHW+i/HPyWvUAmWH6wZyI=",
|
||||
"ref": "refs/heads/main",
|
||||
"rev": "427289b4fc7433b6b08613f9e1644ab5209838d6",
|
||||
"revCount": 11,
|
||||
"rev": "b5ce224f56360833af5eb21c91387c42d2a4f47b",
|
||||
"revCount": 12,
|
||||
"type": "git",
|
||||
"url": "https://github.com/zunoser/nani-translate-linux.git"
|
||||
},
|
||||
@@ -846,7 +865,7 @@
|
||||
"inputs": {
|
||||
"niri-stable": "niri-stable",
|
||||
"niri-unstable": "niri-unstable",
|
||||
"nixpkgs": "nixpkgs_8",
|
||||
"nixpkgs": "nixpkgs_9",
|
||||
"nixpkgs-stable": "nixpkgs-stable",
|
||||
"xwayland-satellite-stable": "xwayland-satellite-stable",
|
||||
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
|
||||
@@ -942,11 +961,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1779529080,
|
||||
"narHash": "sha256-CHa5L3I71NbPUNJp1gmmwbh91tKsZPyuRK50mLHjAVY=",
|
||||
"lastModified": 1790329191,
|
||||
"narHash": "sha256-HYfn+tCtyY4Xl2l0InOGoaYgZMLbFw3LB11ZETjMxp0=",
|
||||
"owner": "aster-void",
|
||||
"repo": "nix-hazkey",
|
||||
"rev": "24cb2926666836988e78ceebeb67ad6c5a387ac3",
|
||||
"rev": "9524686e361eb1ce9c054f0218e7a4b82091b847",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -962,11 +981,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787457452,
|
||||
"narHash": "sha256-FJh4esFS3zqNNuKwvN3t6wrJGewqp1AUF9DAEvoKPD8=",
|
||||
"lastModified": 1790499302,
|
||||
"narHash": "sha256-Gbf/U9ptJhQh0qnDnJ/+a8MAcq1HXunbArUTHR2wNYk=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nix-index-database",
|
||||
"rev": "c51d5c2ba69c907a34e90c9b6b80cd2b93811745",
|
||||
"rev": "161d7c91accd93034bb3c295224d9d895a778573",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -977,14 +996,14 @@
|
||||
},
|
||||
"nixos-hardware": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_9"
|
||||
"nixpkgs": "nixpkgs_10"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787144466,
|
||||
"narHash": "sha256-HHfv2/HkNSKbbSyU9iD/g8lbP6r4tl33sSw1W4rXCk0=",
|
||||
"lastModified": 1790321948,
|
||||
"narHash": "sha256-mZGHLGi217oLIwzDM4PNRZeCNa6g2WBXURyXbNMFs7Y=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixos-hardware",
|
||||
"rev": "0471accf8d0a8210b31d947497d179ecc99e0021",
|
||||
"rev": "30d48a0ec6035f8140d0125af274f0de95f1e9b5",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -997,14 +1016,14 @@
|
||||
"nixos-wsl": {
|
||||
"inputs": {
|
||||
"flake-compat": "flake-compat_5",
|
||||
"nixpkgs": "nixpkgs_10"
|
||||
"nixpkgs": "nixpkgs_11"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1784642409,
|
||||
"narHash": "sha256-hcbDqFuySAJawljt5r0sKBCJKYnbtGD0T/ZIozH1Dq0=",
|
||||
"lastModified": 1789164534,
|
||||
"narHash": "sha256-DoYGPM6QpnYBLWj9gGw6ZwAzIX+HrAVov1BoT+8Jixo=",
|
||||
"owner": "nix-community",
|
||||
"repo": "NixOS-WSL",
|
||||
"rev": "eaeb18da90024448a60eb1ec7132eafa4003404e",
|
||||
"rev": "72c92b11bb8289e6651c7fef29cc0a885fd6a255",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1046,11 +1065,11 @@
|
||||
},
|
||||
"nixpkgs-lib_2": {
|
||||
"locked": {
|
||||
"lastModified": 1785031560,
|
||||
"narHash": "sha256-OmshNvn2vupOFpYinLUu+1Dnpu4n7Q5N3ggGVNHpkUI=",
|
||||
"lastModified": 1788057806,
|
||||
"narHash": "sha256-DTQSMxzDWmT0zhguthvegnVkn7CFqGCv4IHCzk5ZUpM=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nixpkgs.lib",
|
||||
"rev": "0e79af5e3d4dcfcd676ab5ba3f95d2e3352e078c",
|
||||
"rev": "596e2e3940e09b2abbeb03f75fa1828c57fcd72c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1093,11 +1112,11 @@
|
||||
},
|
||||
"nixpkgs-unstable": {
|
||||
"locked": {
|
||||
"lastModified": 1787874478,
|
||||
"narHash": "sha256-ubWQiwkhIql/lYwnfK55yKHfAkTBXie2L4iChGNHfI0=",
|
||||
"lastModified": 1790510107,
|
||||
"narHash": "sha256-EVMNYv7hYDDD9TGVT/hIyTYgpiXA8y3m5xIEIxuGNU0=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "7d1a7c21a4c00ea653fc7ed5c083d261340f185f",
|
||||
"rev": "3181085bfd08663b6b9e60bc7a8395c2aaa741bd",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1109,11 +1128,24 @@
|
||||
},
|
||||
"nixpkgs_10": {
|
||||
"locked": {
|
||||
"lastModified": 1783776592,
|
||||
"narHash": "sha256-UgCQzxeWI75XM8G+hPrPh+MKzEPjG3SpAj7dtqSbksA=",
|
||||
"lastModified": 1789546076,
|
||||
"narHash": "sha256-vWkSk5bbfTqdtMoSgD9FshACO8JCvXTFi+3cqEp0mH0=",
|
||||
"rev": "b1b875982b17dabde9b4a37f3e229e74913e6db3",
|
||||
"type": "tarball",
|
||||
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1074753.b1b875982b17/nixexprs.tar.xz"
|
||||
},
|
||||
"original": {
|
||||
"type": "tarball",
|
||||
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
|
||||
}
|
||||
},
|
||||
"nixpkgs_11": {
|
||||
"locked": {
|
||||
"lastModified": 1789006805,
|
||||
"narHash": "sha256-xB8mKMOx1IA9vTDNLmJZ6n4wCMq/cuWBBOzGCRnqxrU=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "e7a3ca8092b61ff85b6a45bf863ea2b2d6a661b3",
|
||||
"rev": "8ce4ef6cb6f871616146b9fe26d2a5ae594e94fe",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1123,13 +1155,13 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_11": {
|
||||
"nixpkgs_12": {
|
||||
"locked": {
|
||||
"lastModified": 1787848966,
|
||||
"narHash": "sha256-7gDpu5hpq0rOYnYMcOWqSzquK4HA/xU8Xf3CjUBOOJA=",
|
||||
"lastModified": 1790450978,
|
||||
"narHash": "sha256-/eLCD/X9kaWJqPR47+fDozEC87Hjmm3i8gJbYmDAD7g=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "d57af924f160a5084293c71c2043f058bd1cdb60",
|
||||
"rev": "5e2305d577ca00acbba631b05cb1094d172b29f3",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1139,20 +1171,20 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_12": {
|
||||
"nixpkgs_13": {
|
||||
"locked": {
|
||||
"lastModified": 1787360063,
|
||||
"narHash": "sha256-95aJfHyQTLWslCXFVNB0odgmVkpdmDezQwTg9mhqV1E=",
|
||||
"rev": "2c423e03bbafcff28bfadc6781a4a8257f205cb5",
|
||||
"lastModified": 1790323409,
|
||||
"narHash": "sha256-m4DGo58Fza5ImOegtWOeE18nhpSO1IGzsVA6Lpsb4zw=",
|
||||
"rev": "e94cb152ed51bd6e24eb4a41f1460252beb52cd2",
|
||||
"type": "tarball",
|
||||
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1059570.2c423e03bbaf/nixexprs.tar.zst"
|
||||
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1079315.e94cb152ed51/nixexprs.tar.zst"
|
||||
},
|
||||
"original": {
|
||||
"type": "tarball",
|
||||
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.zst"
|
||||
}
|
||||
},
|
||||
"nixpkgs_13": {
|
||||
"nixpkgs_14": {
|
||||
"locked": {
|
||||
"lastModified": 1770107345,
|
||||
"narHash": "sha256-tbS0Ebx2PiA1FRW8mt8oejR0qMXmziJmPaU1d4kYY9g=",
|
||||
@@ -1168,13 +1200,13 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_14": {
|
||||
"nixpkgs_15": {
|
||||
"locked": {
|
||||
"lastModified": 1787736819,
|
||||
"narHash": "sha256-cV5xEJJK3BvhU8rEd4mC9UsmDi5qscv/kzGPhBRC5WA=",
|
||||
"lastModified": 1789684949,
|
||||
"narHash": "sha256-ZKhUe/2IJUq1JhKxKMu8rbkgSGmPP2ZCqlIPn40aGCM=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "9fbb54b33e91ee4ca368e35a78e0613c720600b3",
|
||||
"rev": "e554fab72f81915600f3f449b786fd9af40439a5",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1217,6 +1249,22 @@
|
||||
}
|
||||
},
|
||||
"nixpkgs_4": {
|
||||
"locked": {
|
||||
"lastModified": 1787900134,
|
||||
"narHash": "sha256-VYXO0XZlgj06dxJZRhrD3WoSsvq/c7+/Akyoa22pefw=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "83199d0d373dd3ac2b9a1996b1d0263f76ab7a4c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixos-unstable",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_5": {
|
||||
"locked": {
|
||||
"lastModified": 1787424095,
|
||||
"narHash": "sha256-SpMiSe9OSfWseGAupsdcED3He9mTYTbGMtWb7EVt6pE=",
|
||||
@@ -1229,29 +1277,13 @@
|
||||
"url": "https://channels.nixos.org/nixpkgs-unstable/nixexprs.tar.zst"
|
||||
}
|
||||
},
|
||||
"nixpkgs_5": {
|
||||
"locked": {
|
||||
"lastModified": 1782918843,
|
||||
"narHash": "sha256-ETYnV9U7Sr+A45dohzZdfCZKOss4qrTkO+wgNZNvEc0=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "e8273b29fe1390ec8d4603f2477357555291432e",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixpkgs-unstable",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_6": {
|
||||
"locked": {
|
||||
"lastModified": 1787424095,
|
||||
"narHash": "sha256-dWLO5AHhKaw6rdWCtTes8hnntT1r0/J5yhQGm0f0ZgU=",
|
||||
"lastModified": 1787631388,
|
||||
"narHash": "sha256-vMiXptXarfSdJb1Gkc+FYVOAibuBRj7qxGa8z68q1Uw=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "174eb786fb68e3a13e4e535a3deea479a0c07a6a",
|
||||
"rev": "ac6b2166e7a9375683b8e98f860f273222337b16",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1262,6 +1294,22 @@
|
||||
}
|
||||
},
|
||||
"nixpkgs_7": {
|
||||
"locked": {
|
||||
"lastModified": 1790510107,
|
||||
"narHash": "sha256-EVMNYv7hYDDD9TGVT/hIyTYgpiXA8y3m5xIEIxuGNU0=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "3181085bfd08663b6b9e60bc7a8395c2aaa741bd",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixpkgs-unstable",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_8": {
|
||||
"locked": {
|
||||
"lastModified": 1785454630,
|
||||
"narHash": "sha256-LQy14TZp77TwbQf40gg1V3jo8FwJG0jGDkAH+zRHqg8=",
|
||||
@@ -1277,7 +1325,7 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_8": {
|
||||
"nixpkgs_9": {
|
||||
"locked": {
|
||||
"lastModified": 1785828668,
|
||||
"narHash": "sha256-8fsyqeO+mJqvIzeO4xIpgJe/f7MTbbVTEC6RT6WSXNs=",
|
||||
@@ -1293,19 +1341,6 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_9": {
|
||||
"locked": {
|
||||
"lastModified": 1767892417,
|
||||
"narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=",
|
||||
"rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba",
|
||||
"type": "tarball",
|
||||
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre924538.3497aa5c9457/nixexprs.tar.xz"
|
||||
},
|
||||
"original": {
|
||||
"type": "tarball",
|
||||
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
|
||||
}
|
||||
},
|
||||
"nixvim": {
|
||||
"inputs": {
|
||||
"flake-parts": "flake-parts_5",
|
||||
@@ -1315,11 +1350,11 @@
|
||||
"systems": "systems_6"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787536726,
|
||||
"narHash": "sha256-aBh5Yk9tX8ZV4k10BJr2fvTq0/+iWGegaCMUOU7YKas=",
|
||||
"lastModified": 1789959143,
|
||||
"narHash": "sha256-9oBHyJtUyunZL+6v0Ub8Y759cXcejQiTHpXtGcx5RLs=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nixvim",
|
||||
"rev": "e2c3f9f36326d07340626847543c557e2b95fb50",
|
||||
"rev": "4836e77b1798cd42e2de28593bec4c1788da08f5",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1331,14 +1366,14 @@
|
||||
},
|
||||
"noctalia": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_12"
|
||||
"nixpkgs": "nixpkgs_13"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1788012673,
|
||||
"narHash": "sha256-Qzdrf8phPKo31TTqVdDv6vVv9EwQRWnf5HPKUoDDdPM=",
|
||||
"lastModified": 1790523212,
|
||||
"narHash": "sha256-Z8SuI0YgAZaF0sumKPBF85PxPtTjpo8jvtphbgoITv8=",
|
||||
"owner": "noctalia-dev",
|
||||
"repo": "noctalia",
|
||||
"rev": "29dab93fdf9091f83f9eec20a20e72e11fc4e6c4",
|
||||
"rev": "08c30392b1350b4f3d3fb77e23732560559f1638",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1356,16 +1391,16 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787953571,
|
||||
"narHash": "sha256-cUly+bzaPwj9fiUmC+Gh7gwKAZjINCKZKGf/gPMhJJg=",
|
||||
"lastModified": 1789761689,
|
||||
"narHash": "sha256-kZmr3Bd0ehbq43/rDXtkuexWpMN8HyE0iqw1LlaartM=",
|
||||
"owner": "vicinaehq",
|
||||
"repo": "numen",
|
||||
"rev": "7cfed1e8322ac6ebd0db9cbf0db31e27385965bc",
|
||||
"rev": "7379178f9c2fc4dc0c1965c1800e62ef764118f4",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "vicinaehq",
|
||||
"ref": "v0.5.1",
|
||||
"ref": "v0.6.2",
|
||||
"repo": "numen",
|
||||
"type": "github"
|
||||
}
|
||||
@@ -1404,11 +1439,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787424939,
|
||||
"narHash": "sha256-O2tBn84NNuHrnqNVxx/XqsXwfYvS1YwBh+7CBnbCYsk=",
|
||||
"lastModified": 1789514889,
|
||||
"narHash": "sha256-PFD1nxptCXJyJoiYO1gf/5Vv43yqGpHtMC6LUhl9/pQ=",
|
||||
"owner": "cachix",
|
||||
"repo": "git-hooks.nix",
|
||||
"rev": "809414f0cdadf82cf11b06c2b29ba9b3168b3297",
|
||||
"rev": "59f4ca0d063a1a3ec722c88b51a33004862e5379",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1422,6 +1457,7 @@
|
||||
"browser-previews": "browser-previews",
|
||||
"codex-desktop-linux": "codex-desktop-linux",
|
||||
"codex-session-usage": "codex-session-usage",
|
||||
"containerlab": "containerlab",
|
||||
"disko": "disko",
|
||||
"flake-parts": "flake-parts_3",
|
||||
"ghostty": "ghostty",
|
||||
@@ -1436,7 +1472,7 @@
|
||||
"nix-index-database": "nix-index-database",
|
||||
"nixos-hardware": "nixos-hardware",
|
||||
"nixos-wsl": "nixos-wsl",
|
||||
"nixpkgs": "nixpkgs_11",
|
||||
"nixpkgs": "nixpkgs_12",
|
||||
"nixpkgs-unstable": "nixpkgs-unstable",
|
||||
"nixvim": "nixvim",
|
||||
"noctalia": "noctalia",
|
||||
@@ -1480,11 +1516,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787454509,
|
||||
"narHash": "sha256-r4LDUF+zmJnkftvCVkCrUhSJazsf6EVJF+V2l4/MYbI=",
|
||||
"lastModified": 1789889921,
|
||||
"narHash": "sha256-aL/ogiN7qZCGeNovS1f9hX73jwYIKb4Pcq6AZm57WtY=",
|
||||
"owner": "oxalica",
|
||||
"repo": "rust-overlay",
|
||||
"rev": "f60c1b57ff805a46b5175c76fc981fb4f81efbcc",
|
||||
"rev": "1fb104a12a8667045559b2575d6d448ae2fbd99b",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1495,11 +1531,11 @@
|
||||
},
|
||||
"services-flake": {
|
||||
"locked": {
|
||||
"lastModified": 1787074068,
|
||||
"narHash": "sha256-z0CqDCjs+xU/Yw2/VkS8Mz7qzw4AsZ+AMwEMmqSSKh0=",
|
||||
"lastModified": 1790475157,
|
||||
"narHash": "sha256-CUvrxb5wdBRcpwi89yfgw4IUqhBjjt+BUtsNQVM+5jM=",
|
||||
"owner": "juspay",
|
||||
"repo": "services-flake",
|
||||
"rev": "4f56c8f1cbd09c774a491a47acd3605a6eb7adfa",
|
||||
"rev": "aa72532e193ee212055df9e1c3eb07aa0ccafabb",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1511,11 +1547,11 @@
|
||||
"skills": {
|
||||
"flake": false,
|
||||
"locked": {
|
||||
"lastModified": 1787581197,
|
||||
"narHash": "sha256-N5tpUIHO2VFeJntBTl6/VLDIVpqoshwFxNJlfXXUwsQ=",
|
||||
"lastModified": 1789726349,
|
||||
"narHash": "sha256-L3CpIT2DeI+fUFl9fcygojtQo2DzEen69rMD1XqR1vM=",
|
||||
"owner": "mattpocock",
|
||||
"repo": "skills",
|
||||
"rev": "6654f6b60cd9d5be8b54c6fafe44346dabeb3b76",
|
||||
"rev": "c55ee46073ed923f86ce59a5eb3b6d895095d1b7",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1531,11 +1567,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1786629091,
|
||||
"narHash": "sha256-gkig4nPi1CWc4Z50GBsjE4ygSE7hMpl/TwID2an2Cck=",
|
||||
"lastModified": 1790498116,
|
||||
"narHash": "sha256-rs9meAYxW3zzrh43yaW7htrqCD+X9+pupDPHN86fumI=",
|
||||
"owner": "Mic92",
|
||||
"repo": "sops-nix",
|
||||
"rev": "a8627b21b9107c5711c96b84f32a9a4b3d45295f",
|
||||
"rev": "5efb5a6f4f5ab192817d28557dd4d650fa14d866",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1586,11 +1622,11 @@
|
||||
"tinted-zed": "tinted-zed"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787771653,
|
||||
"narHash": "sha256-DkkJSBOXWV/mja5Vy8az5g1KpZlsbUwlmH0BsQhowaQ=",
|
||||
"lastModified": 1790451534,
|
||||
"narHash": "sha256-5J4zQ0mmCsd2SS+sOKdzXrngofQdtube3VoHSENz4zE=",
|
||||
"owner": "nix-community",
|
||||
"repo": "stylix",
|
||||
"rev": "5e3809851f486e7fc7e84b40f174c74b60ecc784",
|
||||
"rev": "fb28acd59e2ac1984ec84fa496599d6b4bf3e690",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1883,7 +1919,7 @@
|
||||
},
|
||||
"treefmt-nix_4": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_13"
|
||||
"nixpkgs": "nixpkgs_14"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1786901030,
|
||||
@@ -1901,17 +1937,17 @@
|
||||
},
|
||||
"vicinae": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_14",
|
||||
"nixpkgs": "nixpkgs_15",
|
||||
"numen": "numen",
|
||||
"soulver-cpp": "soulver-cpp",
|
||||
"systems": "systems_9"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1787956866,
|
||||
"narHash": "sha256-SCFAyDbNIXcFRGw0nx2yVY47hMSHzMFAQOsUXdJJ6sc=",
|
||||
"lastModified": 1790526610,
|
||||
"narHash": "sha256-rmgEQklUdHJ4wLCX5sa1rVkeiu2atFWJ3likgVw/5gA=",
|
||||
"owner": "vicinaehq",
|
||||
"repo": "vicinae",
|
||||
"rev": "47857b0b4af6b269ddbc5f34b661f0eb9d9bdeb5",
|
||||
"rev": "8d80bf6011de177a19f1b5f1243ec505f441b7e7",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -1930,11 +1966,11 @@
|
||||
"vicinae": "vicinae_2"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1788004886,
|
||||
"narHash": "sha256-YVr/SysyzG2lkSpacrEC/Mo7XdUYdKu5vX2AUcqAzpQ=",
|
||||
"lastModified": 1790242820,
|
||||
"narHash": "sha256-xG2Nvdhl+lcguYzkAHf6RkHQpM8c3rbN0NDHUiwT4CA=",
|
||||
"owner": "vicinaehq",
|
||||
"repo": "extensions",
|
||||
"rev": "de926d2e94ff4423dc04068eb2b6fc8d501f3b74",
|
||||
"rev": "def646b3655e13759d2b0a7b9d605f55fe83a5f7",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -2038,11 +2074,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1784080626,
|
||||
"narHash": "sha256-Hvnmnuu0VpHiZl+8z+UkMoxC7JZJvRYBqu2Asb0ZJOE=",
|
||||
"lastModified": 1788977680,
|
||||
"narHash": "sha256-3vgICcen5N2oAlQrijqJhxn8HEsnXASGPxQLJVYzX0Q=",
|
||||
"owner": "jcollie",
|
||||
"repo": "zon2nix",
|
||||
"rev": "776b5f6864a607c141d7966421b433fa1657ba9a",
|
||||
"rev": "7b9c43312de08e176097b8c8920f0dd1a46982be",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
|
||||
@@ -114,6 +114,7 @@
|
||||
|
||||
nani-translate-linux.url = "git+https://github.com/zunoser/nani-translate-linux.git";
|
||||
|
||||
containerlab.url = "github:srl-labs/containerlab";
|
||||
};
|
||||
|
||||
outputs =
|
||||
|
||||
+35
-1
@@ -7,12 +7,43 @@
|
||||
|
||||
profiles = [
|
||||
"base"
|
||||
"interface.cli"
|
||||
"interface.minimal"
|
||||
"platform.vm"
|
||||
"workload.remote-access"
|
||||
];
|
||||
};
|
||||
|
||||
ops = {
|
||||
system = "x86_64-linux";
|
||||
stateVersion = "26.05";
|
||||
user = "moons";
|
||||
path = ./ops;
|
||||
|
||||
profiles = [
|
||||
"base"
|
||||
"interface.minimal"
|
||||
"platform.vm"
|
||||
"workload.remote-access"
|
||||
"workload.deploy-rs-target"
|
||||
];
|
||||
};
|
||||
|
||||
netsrv-01 = {
|
||||
system = "x86_64-linux";
|
||||
stateVersion = "26.05";
|
||||
user = "moons";
|
||||
path = ./netsrv-01;
|
||||
|
||||
profiles = [
|
||||
"base"
|
||||
"interface.minimal"
|
||||
"platform.vm"
|
||||
"workload.remote-access"
|
||||
"workload.deploy-rs-target"
|
||||
"workload.server"
|
||||
];
|
||||
};
|
||||
|
||||
installer = {
|
||||
system = "x86_64-linux";
|
||||
stateVersion = "26.05";
|
||||
@@ -60,6 +91,7 @@
|
||||
"security.tpm-storage"
|
||||
"workload.development"
|
||||
"workload.game"
|
||||
"workload.network-lab"
|
||||
"workload.personal"
|
||||
];
|
||||
|
||||
@@ -85,7 +117,9 @@
|
||||
"workload.development"
|
||||
"workload.game"
|
||||
"workload.machine-learning"
|
||||
"workload.network-lab"
|
||||
"workload.personal"
|
||||
"workload.photography"
|
||||
"workload.camera"
|
||||
];
|
||||
};
|
||||
|
||||
+18
-24
@@ -76,6 +76,12 @@
|
||||
║ ║
|
||||
║ Installation Workflow: ║
|
||||
║ ║
|
||||
║ Choose a guide after cloning: ║
|
||||
║ Simple: docs/install-simple.md ║
|
||||
║ SOPS + LUKS: docs/install.md ║
|
||||
║ ║
|
||||
║ The workflow below is for SOPS + LUKS: ║
|
||||
║ ║
|
||||
║ 1. Clone dotfiles: ║
|
||||
║ git clone git@github.com:moons-14/dotfiles.git ~/dotfiles║
|
||||
║ ║
|
||||
@@ -103,37 +109,25 @@
|
||||
║ # See hosts/x1g13/disko.nix for reference ║
|
||||
║ ║
|
||||
║ 7. Partition disk with disko: ║
|
||||
║ nix run github:nix-community/disko -- \ ║
|
||||
║ --mode disko hosts/<host>/disko.nix ║
|
||||
║ disko --mode destroy,format,mount \ ║
|
||||
║ hosts/<host>/disko.nix ║
|
||||
║ ║
|
||||
║ 8. Copy host key to installed system: ║
|
||||
║ 8. Generate hardware configuration: ║
|
||||
║ nixos-generate-config --no-filesystems --root /mnt \ ║
|
||||
║ --show-hardware-config > \ ║
|
||||
║ ~/dotfiles/hosts/<host>/hardware-configuration.nix ║
|
||||
║ # Import hardware-configuration.nix and disko.nix ║
|
||||
║ # from hosts/<host>/nixos.nix ║
|
||||
║ ║
|
||||
║ 9. Copy host key to installed system: ║
|
||||
║ mkdir -p /mnt/etc/ssh ║
|
||||
║ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ ║
|
||||
║ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ║
|
||||
║ ║
|
||||
║ 9. Install NixOS: ║
|
||||
║ 10. Install NixOS: ║
|
||||
║ nixos-install --flake ~/dotfiles#<host> ║
|
||||
║ ║
|
||||
║ Disko Configuration Examples: ║
|
||||
║ ║
|
||||
║ Simple (no encryption): ║
|
||||
║ disko.devices.disk.main = { ║
|
||||
║ type = "disk"; ║
|
||||
║ device = "/dev/sda"; ║
|
||||
║ content = { ║
|
||||
║ type = "gpt"; ║
|
||||
║ partitions = { ║
|
||||
║ ESP = { size = "512M"; type = "EF00"; ║
|
||||
║ content = { type = "filesystem"; ║
|
||||
║ format = "vfat"; mountpoint = "/boot"; }; }; ║
|
||||
║ root = { size = "100%"; ║
|
||||
║ content = { type = "filesystem"; ║
|
||||
║ format = "ext4"; mountpoint = "/"; }; }; ║
|
||||
║ }; ║
|
||||
║ }; ║
|
||||
║ }; ║
|
||||
║ ║
|
||||
║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║
|
||||
║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║
|
||||
║ - Use partuuid for device path ║
|
||||
║ - Set askPassword = true for LUKS ║
|
||||
║ - Configure btrfs subvolumes ║
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
_: {
|
||||
disko.enableConfig = true;
|
||||
|
||||
disko.devices.disk.main = {
|
||||
type = "disk";
|
||||
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
||||
content = {
|
||||
type = "gpt";
|
||||
partitions = {
|
||||
ESP = {
|
||||
size = "512M";
|
||||
type = "EF00";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "vfat";
|
||||
mountpoint = "/boot";
|
||||
};
|
||||
};
|
||||
root = {
|
||||
size = "100%";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "ext4";
|
||||
mountpoint = "/";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
# QEMU hardware baseline. Replace this with the output of
|
||||
# `nixos-generate-config` after provisioning the VM if its hardware differs.
|
||||
{
|
||||
lib,
|
||||
modulesPath,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
imports = [
|
||||
(modulesPath + "/profiles/qemu-guest.nix")
|
||||
];
|
||||
|
||||
boot.initrd.availableKernelModules = [
|
||||
"ata_piix"
|
||||
"uhci_hcd"
|
||||
"virtio_pci"
|
||||
"virtio_scsi"
|
||||
"sd_mod"
|
||||
"sr_mod"
|
||||
];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
networking = {
|
||||
interfaces = {
|
||||
ens18 = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.65.11";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
ens19 = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.66.10";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
ens20 = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.77.21";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
defaultGateway = {
|
||||
address = "10.50.66.1";
|
||||
interface = "ens19";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,7 @@
|
||||
{
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
./disko.nix
|
||||
./networking.nix
|
||||
];
|
||||
}
|
||||
@@ -0,0 +1,66 @@
|
||||
_:
|
||||
let
|
||||
osDisk = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
||||
in
|
||||
{
|
||||
disko.enableConfig = true;
|
||||
|
||||
# The VM disks already contain live filesystems. Model each existing
|
||||
# filesystem without giving Disko ownership of their partitioning or data.
|
||||
disko.devices.disk = {
|
||||
boot = {
|
||||
type = "disk";
|
||||
device = "${osDisk}-part1";
|
||||
destroy = false;
|
||||
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "vfat";
|
||||
mountpoint = "/boot";
|
||||
mountOptions = [ "umask=0077" ];
|
||||
};
|
||||
};
|
||||
|
||||
root = {
|
||||
type = "disk";
|
||||
device = "${osDisk}-part2";
|
||||
destroy = false;
|
||||
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "ext4";
|
||||
mountpoint = "/";
|
||||
};
|
||||
};
|
||||
|
||||
nix-build = {
|
||||
type = "disk";
|
||||
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi1";
|
||||
destroy = false;
|
||||
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "ext4";
|
||||
mountpoint = "/var/lib/nix-build";
|
||||
mountOptions = [ "noatime" ];
|
||||
};
|
||||
};
|
||||
|
||||
nix-store = {
|
||||
type = "disk";
|
||||
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi2";
|
||||
destroy = false;
|
||||
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "ext4";
|
||||
mountpoint = "/nix/store";
|
||||
mountOptions = [ "noatime" ];
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
fileSystems."/nix/store".neededForBoot = true;
|
||||
nix.settings.build-dir = "/var/lib/nix-build";
|
||||
services.fstrim.enable = true;
|
||||
}
|
||||
@@ -1,25 +0,0 @@
|
||||
{
|
||||
fileSystems."/nix/store" = {
|
||||
device = "/dev/disk/by-label/nix-store";
|
||||
fsType = "ext4";
|
||||
|
||||
options = [
|
||||
"noatime"
|
||||
];
|
||||
|
||||
neededForBoot = true;
|
||||
};
|
||||
|
||||
fileSystems."/var/lib/nix-build" = {
|
||||
device = "/dev/disk/by-label/nix-build";
|
||||
fsType = "ext4";
|
||||
|
||||
options = [
|
||||
"noatime"
|
||||
];
|
||||
};
|
||||
|
||||
nix.settings.build-dir = "/var/lib/nix-build";
|
||||
|
||||
services.fstrim.enable = true;
|
||||
}
|
||||
@@ -0,0 +1,83 @@
|
||||
{
|
||||
config,
|
||||
pkgs,
|
||||
primaryUser,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
homeDirectory = "/home/${primaryUser}";
|
||||
fleetDirectory = "${homeDirectory}/srv/nix-fleet";
|
||||
stateDirectory = "/var/lib/nix-fleet";
|
||||
sourceDirectory = "${stateDirectory}/source";
|
||||
|
||||
git = "${pkgs.git}/bin/git";
|
||||
nix = "${config.nix.package}/bin/nix";
|
||||
rsync = "${pkgs.rsync}/bin/rsync";
|
||||
|
||||
cleanCheckoutConditions = [
|
||||
"${git} -C ${fleetDirectory} diff --quiet"
|
||||
"${git} -C ${fleetDirectory} diff --cached --quiet"
|
||||
];
|
||||
in
|
||||
{
|
||||
systemd.services.nix-fleet-converge = {
|
||||
description = "Update inputs, build the fleet, and deploy changed hosts";
|
||||
wants = [ "network-online.target" ];
|
||||
after = [ "network-online.target" ];
|
||||
|
||||
environment = {
|
||||
HOME = homeDirectory;
|
||||
NIX_CONFIG = ''
|
||||
accept-flake-config = true
|
||||
max-jobs = 4
|
||||
cores = 3
|
||||
'';
|
||||
};
|
||||
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
User = primaryUser;
|
||||
Restart = "on-failure";
|
||||
RestartSec = "5min";
|
||||
StateDirectory = "nix-fleet";
|
||||
StateDirectoryMode = "0750";
|
||||
WorkingDirectory = stateDirectory;
|
||||
UMask = "0077";
|
||||
ExecCondition = cleanCheckoutConditions;
|
||||
EnvironmentFile = "${fleetDirectory}/.env";
|
||||
|
||||
# Work in a disposable copy so updating the dotfiles lock never dirties
|
||||
# the operator's nix-fleet checkout.
|
||||
ExecStart = [
|
||||
"${git} -C ${fleetDirectory} pull --ff-only"
|
||||
"${rsync} --archive --delete --exclude=.git/ --exclude=.direnv/ --exclude=.env --exclude=result --exclude=result-* ${fleetDirectory}/ ${sourceDirectory}/"
|
||||
"${nix} flake update --flake ${sourceDirectory} dotfiles"
|
||||
"${nix} run ${sourceDirectory}#converge -- ${sourceDirectory} ${stateDirectory}"
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
systemd.timers.nix-fleet-converge = {
|
||||
description = "Periodically converge the NixOS fleet";
|
||||
wantedBy = [ "timers.target" ];
|
||||
timerConfig = {
|
||||
OnBootSec = "2min";
|
||||
OnUnitInactiveSec = "5min";
|
||||
RandomizedDelaySec = "30s";
|
||||
Persistent = true;
|
||||
Unit = "nix-fleet-converge.service";
|
||||
};
|
||||
};
|
||||
|
||||
# Only an actual successful deployment touches gc-request. This starts the
|
||||
# builder's root nh-clean unit; remote host stores are never cleaned here.
|
||||
systemd.paths.nix-fleet-gc = {
|
||||
description = "Garbage-collect superseded fleet builds on nix-builder";
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
pathConfig = {
|
||||
PathChanged = "${stateDirectory}/gc-request";
|
||||
Unit = "nh-clean.service";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -20,20 +20,6 @@
|
||||
boot.kernelModules = [ ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
fileSystems."/" = {
|
||||
device = "/dev/disk/by-uuid/49fc2e1c-7909-41cc-ac78-55b4d9a01e62";
|
||||
fsType = "ext4";
|
||||
};
|
||||
|
||||
fileSystems."/boot" = {
|
||||
device = "/dev/disk/by-uuid/40D4-ABBE";
|
||||
fsType = "vfat";
|
||||
options = [
|
||||
"fmask=0077"
|
||||
"dmask=0077"
|
||||
];
|
||||
};
|
||||
|
||||
swapDevices = [ ];
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
|
||||
@@ -0,0 +1,37 @@
|
||||
{
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
|
||||
nix.settings = {
|
||||
build-dir = "/var/lib/nix-build";
|
||||
|
||||
secret-key-files = [
|
||||
"/var/lib/secrets/nix-cache-signing-key"
|
||||
];
|
||||
|
||||
auto-optimise-store = lib.mkForce false;
|
||||
keep-outputs = false;
|
||||
keep-derivations = true;
|
||||
};
|
||||
|
||||
services.harmonia.cache = {
|
||||
enable = true;
|
||||
|
||||
signKeyPaths = [
|
||||
"/var/lib/secrets/nix-cache-signing-key"
|
||||
];
|
||||
|
||||
settings = {
|
||||
bind = "[::]:5000";
|
||||
priority = 30;
|
||||
workers = 4;
|
||||
};
|
||||
};
|
||||
|
||||
networking.firewall.allowedTCPPorts = [
|
||||
5000
|
||||
];
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
networking = {
|
||||
interfaces = {
|
||||
ens18 = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.65.10";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
ens19 = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.77.10";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
ens20 = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.68.10";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
defaultGateway = {
|
||||
address = "10.50.68.1";
|
||||
interface = "ens20";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -1,6 +1,9 @@
|
||||
{
|
||||
imports = [
|
||||
./filesystem.nix
|
||||
./fleet-automation.nix
|
||||
./disko.nix
|
||||
./hardware-configuration.nix
|
||||
./harmonia.nix
|
||||
./networking.nix
|
||||
];
|
||||
}
|
||||
|
||||
@@ -1,36 +0,0 @@
|
||||
# Do not modify this file! It was generated by `nixos-generate-config` and may
|
||||
# be overwritten by future invocations.
|
||||
{ lib, modulesPath, ... }:
|
||||
{
|
||||
imports = [ (modulesPath + "/profiles/qemu-guest.nix") ];
|
||||
|
||||
boot.initrd.availableKernelModules = [
|
||||
"ata_piix"
|
||||
"uhci_hcd"
|
||||
"virtio_pci"
|
||||
"virtio_scsi"
|
||||
"sd_mod"
|
||||
"sr_mod"
|
||||
];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
fileSystems."/" = {
|
||||
device = "/dev/disk/by-uuid/8f0eaec6-5dc9-4821-aa8d-fb6809b5a5bf";
|
||||
fsType = "ext4";
|
||||
};
|
||||
|
||||
fileSystems."/boot" = {
|
||||
device = "/dev/disk/by-uuid/201C-961B";
|
||||
fsType = "vfat";
|
||||
options = [
|
||||
"fmask=0077"
|
||||
"dmask=0077"
|
||||
];
|
||||
};
|
||||
|
||||
swapDevices = [ ];
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
}
|
||||
@@ -1,3 +0,0 @@
|
||||
{
|
||||
imports = [ ./hardware-configuration.nix ];
|
||||
}
|
||||
@@ -0,0 +1,30 @@
|
||||
_: {
|
||||
disko.enableConfig = true;
|
||||
|
||||
disko.devices.disk.main = {
|
||||
type = "disk";
|
||||
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
||||
content = {
|
||||
type = "gpt";
|
||||
partitions = {
|
||||
ESP = {
|
||||
size = "512M";
|
||||
type = "EF00";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "vfat";
|
||||
mountpoint = "/boot";
|
||||
};
|
||||
};
|
||||
root = {
|
||||
size = "100%";
|
||||
content = {
|
||||
type = "filesystem";
|
||||
format = "ext4";
|
||||
mountpoint = "/";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{
|
||||
lib,
|
||||
modulesPath,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
imports = [
|
||||
(modulesPath + "/profiles/qemu-guest.nix")
|
||||
];
|
||||
|
||||
boot.initrd.availableKernelModules = [
|
||||
"ata_piix"
|
||||
"uhci_hcd"
|
||||
"virtio_pci"
|
||||
"virtio_scsi"
|
||||
"sd_mod"
|
||||
"sr_mod"
|
||||
];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
networking = {
|
||||
interfaces = {
|
||||
ens18 = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.65.100";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
ens19 = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.80.10";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
ens20 = {
|
||||
useDHCP = false;
|
||||
ipv4.addresses = [
|
||||
{
|
||||
address = "10.50.77.20";
|
||||
prefixLength = 24;
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
defaultGateway = {
|
||||
address = "10.50.80.1";
|
||||
interface = "ens19";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,7 @@
|
||||
{
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
./networking.nix
|
||||
./disko.nix
|
||||
];
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
{ inputs, ... }:
|
||||
{
|
||||
description = "Container-based networking labs";
|
||||
|
||||
includes = [ "services.docker" ];
|
||||
|
||||
imports.nixos = [ inputs.containerlab.nixosModules.default ];
|
||||
}
|
||||
@@ -0,0 +1,17 @@
|
||||
{
|
||||
inputs,
|
||||
pkgs,
|
||||
primaryUser,
|
||||
}:
|
||||
{
|
||||
programs.containerlab.enable = true;
|
||||
|
||||
users.users.${primaryUser}.extraGroups = [ "clab_admins" ];
|
||||
|
||||
programs.containerlab.package =
|
||||
inputs.containerlab.packages.${pkgs.stdenv.hostPlatform.system}.default.overrideAttrs
|
||||
(_old: {
|
||||
vendorHash = "sha256-xp6YIoqJdUu1zEzw7s7+lh8iGJD4THokF5NPbxLH6zc=";
|
||||
});
|
||||
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
{
|
||||
inputs,
|
||||
osConfig,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
let
|
||||
unstable = import inputs.nixpkgs-unstable {
|
||||
inherit (pkgs.stdenv.hostPlatform) system;
|
||||
# Keep default CUDA targets so dependencies match the CUDA binary cache.
|
||||
config = pkgs.config // {
|
||||
cudaSupport = osConfig.my.hardwares.nvidia.enable;
|
||||
};
|
||||
};
|
||||
in
|
||||
{
|
||||
home.packages = [
|
||||
(unstable.darktable.override {
|
||||
withAi = true;
|
||||
})
|
||||
];
|
||||
}
|
||||
@@ -38,8 +38,6 @@ in
|
||||
|
||||
ignores = [
|
||||
".direnv/"
|
||||
".envrc"
|
||||
"!.envrc.example"
|
||||
];
|
||||
|
||||
signing = {
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
home.packages = [ pkgs.htop ];
|
||||
}
|
||||
@@ -127,7 +127,6 @@ in
|
||||
(execute "W-C-j" "${lib.getExe' pkgs.xdg-utils "xdg-open"} naniapp://translate")
|
||||
(execute "W-space" "ghostty +toggle-quick-terminal")
|
||||
(execute "W-p" "wdisplays")
|
||||
(execute "W-z" "wl-find-cursor -c 0xCCFF453A -s 160 -d 1200")
|
||||
|
||||
# Function keys (sync with niri modules/applications/niri/home.nix)
|
||||
(execute "XF86AudioRaiseVolume" "noctalia msg volume-up")
|
||||
|
||||
@@ -4,6 +4,5 @@
|
||||
includes = [
|
||||
"systems.wayland"
|
||||
"applications.screenshot"
|
||||
"applications.wl-find-cursor"
|
||||
];
|
||||
}
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
home.packages = [ pkgs.nano ];
|
||||
}
|
||||
@@ -0,0 +1,5 @@
|
||||
{
|
||||
description = "Sipeed NanoKVM-USB desktop client";
|
||||
|
||||
includes = [ "services.nanokvm-usb" ];
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
{ pkgs, ... }:
|
||||
let
|
||||
pname = "nanokvm-usb";
|
||||
version = "1.1.4";
|
||||
|
||||
src = pkgs.fetchurl {
|
||||
url = "https://github.com/sipeed/NanoKVM-USB/releases/download/v${version}/NanoKVM-USB-${version}-linux-x86_64.AppImage";
|
||||
hash = "sha256-00MT4U2afv0qt3xFVhLr0SSmS2cLrKBlmfzqYEFuaVc=";
|
||||
};
|
||||
|
||||
appimageContents = pkgs.appimageTools.extractType2 {
|
||||
inherit pname src version;
|
||||
};
|
||||
|
||||
nanokvm-usb = pkgs.appimageTools.wrapType2 {
|
||||
inherit pname src version;
|
||||
|
||||
meta = {
|
||||
description = "Sipeed NanoKVM-USB desktop client";
|
||||
homepage = "https://github.com/sipeed/NanoKVM-USB";
|
||||
license = pkgs.lib.licenses.gpl3Only;
|
||||
platforms = [ "x86_64-linux" ];
|
||||
mainProgram = "nanokvm-usb";
|
||||
};
|
||||
};
|
||||
|
||||
desktopItem = pkgs.makeDesktopItem {
|
||||
name = pname;
|
||||
desktopName = "NanoKVM-USB";
|
||||
comment = "NanoKVM-USB Desktop";
|
||||
exec = "nanokvm-usb --no-sandbox %U";
|
||||
icon = "${appimageContents}/nanokvm-usb.png";
|
||||
categories = [ "Utility" ];
|
||||
startupWMClass = "NanoKVM-USB";
|
||||
};
|
||||
in
|
||||
{
|
||||
environment.systemPackages = [
|
||||
nanokvm-usb
|
||||
desktopItem
|
||||
];
|
||||
}
|
||||
@@ -139,19 +139,6 @@ in
|
||||
action.spawn = "wdisplays";
|
||||
hotkey-overlay.title = "Display Settings: wdisplays";
|
||||
};
|
||||
"Mod+Z" = {
|
||||
action.spawn = [
|
||||
"wl-find-cursor"
|
||||
"-c"
|
||||
"0xCCFF453A"
|
||||
"-s"
|
||||
"160"
|
||||
"-d"
|
||||
"1200"
|
||||
];
|
||||
hotkey-overlay.title = "Find Cursor";
|
||||
};
|
||||
|
||||
# Function keys (sync with labwc modules/applications/labwc/home.nix)
|
||||
"XF86AudioRaiseVolume".action.spawn = [
|
||||
"noctalia"
|
||||
|
||||
@@ -5,7 +5,6 @@
|
||||
includes = [
|
||||
"systems.wayland"
|
||||
"applications.screenshot"
|
||||
"applications.wl-find-cursor"
|
||||
];
|
||||
|
||||
imports = {
|
||||
|
||||
@@ -13,10 +13,6 @@ lib.mkMerge [
|
||||
User = "git";
|
||||
AddKeysToAgent = "no";
|
||||
};
|
||||
"*.sfc.wide.ad.jp" = {
|
||||
identityFile = "~/.ssh/id_ed25519_sk_rk";
|
||||
identitiesOnly = true;
|
||||
};
|
||||
"*" = {
|
||||
AddKeysToAgent = "no";
|
||||
SetEnv.TERM = "xterm-256color";
|
||||
@@ -31,5 +27,20 @@ lib.mkMerge [
|
||||
IdentityAgent %d/.1password/agent.sock
|
||||
'';
|
||||
};
|
||||
|
||||
home.activation.generateSshKey = {
|
||||
after = [ "writeBoundary" ];
|
||||
before = [ ];
|
||||
data = ''
|
||||
key="$HOME/.ssh/id_ed25519"
|
||||
if [ ! -f "$key" ]; then
|
||||
umask 077
|
||||
mkdir -p "$HOME/.ssh"
|
||||
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
|
||||
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
|
||||
echo "Generated SSH key at $key"
|
||||
fi
|
||||
'';
|
||||
};
|
||||
}
|
||||
]
|
||||
|
||||
@@ -1,7 +0,0 @@
|
||||
{ inputs, pkgs, ... }:
|
||||
let
|
||||
unstable = inputs.nixpkgs-unstable.legacyPackages.${pkgs.stdenv.hostPlatform.system};
|
||||
in
|
||||
{
|
||||
home.packages = [ unstable.wl-find-cursor ];
|
||||
}
|
||||
@@ -1,3 +0,0 @@
|
||||
{
|
||||
description = "Wayland cursor locator";
|
||||
}
|
||||
@@ -5,6 +5,7 @@
|
||||
"catppuccin"
|
||||
"nix"
|
||||
"dockerfile"
|
||||
"terraform"
|
||||
];
|
||||
mutableUserSettings = false;
|
||||
mutableUserKeymaps = false;
|
||||
|
||||
@@ -24,6 +24,7 @@ required on every supported host.
|
||||
| Profile | Supported host class |
|
||||
| ------------------------------------ | --------------------------------------------- |
|
||||
| `base` | NixOS, macOS |
|
||||
| `interface.minimal` | NixOS, macOS with Home Manager |
|
||||
| `interface.cli` | NixOS, macOS with Home Manager |
|
||||
| `interface.gui` | NixOS, macOS with Home Manager |
|
||||
| `interface.macos` | macOS |
|
||||
@@ -36,10 +37,13 @@ required on every supported host.
|
||||
| `platform.laptop` | Physical NixOS laptop |
|
||||
| `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS |
|
||||
| `platform.vm` | UEFI QEMU NixOS guest with NFS client support |
|
||||
| `workload.deploy-rs-target` | NixOS |
|
||||
| `workload.development` | NixOS, macOS with Home Manager |
|
||||
| `workload.game` | NixOS, macOS |
|
||||
| `workload.machine-learning` | NixOS with Home Manager |
|
||||
| `workload.network-lab` | NixOS |
|
||||
| `workload.personal` | NixOS, macOS with Home Manager |
|
||||
| `workload.photography` | NixOS with Home Manager |
|
||||
| `workload.remote-access` | NixOS, macOS |
|
||||
| `workload.camera` | NixOS |
|
||||
| `workload.server` | NixOS, macOS with Home Manager |
|
||||
@@ -60,9 +64,31 @@ selects labwc. A daily-use macOS development machine can combine
|
||||
`interface.macos`, `workload.development`, and `workload.personal`. Hardware
|
||||
support does not implicitly select an interface or workload.
|
||||
|
||||
`platform.nixos` selects the shared network foundation and the clatd service.
|
||||
VM, laptop, and desktop platform profiles inherit both.
|
||||
|
||||
`interface.minimal` provides SSH client access and key generation, Nano, htop,
|
||||
btop, fastfetch, unzip, wget, Direnv, Git, GnuPG, nh, Zellij, and Zsh for remote
|
||||
administration. `interface.cli` includes that baseline and adds the configured
|
||||
Neovim, Yazi, and the remaining interactive command-line tools.
|
||||
|
||||
`workload.machine-learning` provides the Hugging Face Hub CLI for hosts used
|
||||
to download and publish machine learning models and datasets.
|
||||
|
||||
`workload.network-lab` provides containerlab using its upstream NixOS module,
|
||||
the Docker service, and the NanoKVM-USB desktop client with serial-port access.
|
||||
It is selected by galleria and x1g13.
|
||||
|
||||
`workload.photography` provides darktable with AI support from the locked
|
||||
unstable package set. Its ONNX Runtime uses CUDA when the NVIDIA hardware unit
|
||||
is enabled, and CPU inference otherwise. Keep the default CUDA capabilities
|
||||
and forward compatibility to reuse the CUDA binary cache; these targets include
|
||||
galleria's RTX 3060 Ti. OpenCL drivers remain owned by hardware units.
|
||||
|
||||
`workload.deploy-rs-target` enables OpenSSH and provisions the `nixdeploy`
|
||||
service account with the narrowly scoped passwordless commands required for
|
||||
deploy-rs activation and rollback confirmation.
|
||||
|
||||
`workload.personal` provides Pear Desktop on both NixOS and macOS. Home Manager
|
||||
enables performance improvements, synced lyrics, tracker blocking, the album
|
||||
color theme, and custom output-device selection while preserving user-owned
|
||||
|
||||
@@ -8,36 +8,21 @@
|
||||
dust
|
||||
eza
|
||||
fd
|
||||
fastfetch
|
||||
fzf
|
||||
htop
|
||||
jq
|
||||
lsof
|
||||
nurl
|
||||
ripgrep
|
||||
tio
|
||||
unrar
|
||||
unzip
|
||||
wget
|
||||
traceroute
|
||||
tcpdump
|
||||
iw
|
||||
nmap
|
||||
]
|
||||
++ lib.optionals stdenv.isLinux [
|
||||
lm_sensors
|
||||
psmisc
|
||||
strace
|
||||
];
|
||||
|
||||
home.activation.generateSshKey = {
|
||||
after = [ "writeBoundary" ];
|
||||
before = [ ];
|
||||
data = ''
|
||||
key="$HOME/.ssh/id_ed25519"
|
||||
if [ ! -f "$key" ]; then
|
||||
umask 077
|
||||
mkdir -p "$HOME/.ssh"
|
||||
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
|
||||
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
|
||||
echo "Generated SSH key at $key"
|
||||
fi
|
||||
'';
|
||||
};
|
||||
}
|
||||
|
||||
@@ -2,17 +2,10 @@
|
||||
description = "Cross-platform interactive command-line environment";
|
||||
|
||||
includes = [
|
||||
"applications.btop"
|
||||
"applications.direnv"
|
||||
"applications.git"
|
||||
"applications.gnupg"
|
||||
"applications.nh"
|
||||
"profiles.interface.minimal"
|
||||
"applications.nix-index"
|
||||
"applications.ssh"
|
||||
"applications.vim"
|
||||
"applications.yazi"
|
||||
"applications.zellij"
|
||||
"applications.zoxide"
|
||||
"applications.zsh"
|
||||
];
|
||||
}
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
home.packages = with pkgs; [
|
||||
fastfetch
|
||||
unzip
|
||||
wget
|
||||
];
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
{
|
||||
description = "Minimal cross-platform command-line environment for remote administration";
|
||||
|
||||
includes = [
|
||||
"applications.btop"
|
||||
"applications.direnv"
|
||||
"applications.git"
|
||||
"applications.gnupg"
|
||||
"applications.htop"
|
||||
"applications.nano"
|
||||
"applications.nh"
|
||||
"applications.ssh"
|
||||
"applications.zellij"
|
||||
"applications.zsh"
|
||||
];
|
||||
}
|
||||
@@ -2,6 +2,7 @@
|
||||
description = "Foundation shared by all NixOS platforms";
|
||||
|
||||
includes = [
|
||||
"services.clatd"
|
||||
"services.kmscon"
|
||||
"systems.disko"
|
||||
"systems.boot.base"
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
{
|
||||
description = "NixOS deploy-rs deployment target";
|
||||
|
||||
includes = [
|
||||
"services.openssh"
|
||||
"users.nixdeploy"
|
||||
];
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
{
|
||||
description = "Network lab and hardware console environment";
|
||||
|
||||
includes = [
|
||||
"applications.containerlab"
|
||||
"applications.nanokvm-usb"
|
||||
];
|
||||
}
|
||||
@@ -0,0 +1,5 @@
|
||||
{
|
||||
description = "RAW photo development and editing";
|
||||
|
||||
includes = [ "applications.darktable" ];
|
||||
}
|
||||
@@ -0,0 +1,3 @@
|
||||
_: {
|
||||
services.clatd.enable = true;
|
||||
}
|
||||
@@ -1,5 +1,7 @@
|
||||
{ primaryUser, ... }:
|
||||
{ config, primaryUser, ... }:
|
||||
{
|
||||
hardware.nvidia-container-toolkit.enable = config.my.hardwares.nvidia.enable;
|
||||
|
||||
virtualisation.docker = {
|
||||
enable = true;
|
||||
autoPrune = {
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
{ primaryUser, ... }:
|
||||
{
|
||||
users.users.${primaryUser}.extraGroups = [ "dialout" ];
|
||||
}
|
||||
@@ -7,6 +7,10 @@
|
||||
"flakes"
|
||||
];
|
||||
|
||||
extra-allowed-users = [
|
||||
"nixdeploy"
|
||||
];
|
||||
|
||||
connect-timeout = 10;
|
||||
|
||||
extra-substituters = [
|
||||
@@ -19,6 +23,7 @@
|
||||
"https://cache.numtide.com"
|
||||
"https://codex-desktop-linux.cachix.org"
|
||||
"https://cuda-maintainers.cachix.org"
|
||||
"https://cache.nixos-cuda.org"
|
||||
];
|
||||
|
||||
extra-trusted-public-keys = [
|
||||
@@ -31,6 +36,8 @@
|
||||
"niks3.numtide.com-1:DTx8wZduET09hRmMtKdQDxNNthLQETkc/yaX7M4qK0g="
|
||||
"codex-desktop-linux.cachix.org-1:nX/xy6AdK9hQE24A8ALGjkCKj2ObFmcnemiL5Cid4nk="
|
||||
"cuda-maintainers.cachix.org-1:0dq3bujKpuEPMCX6U4WylrUDZ9JyUG0VpVZa7CNfq5E="
|
||||
"cache.nixos-cuda.org:74DUi4Ye579gUqzH4ziL9IyiJBlDpMRn9MBN8oNan9M="
|
||||
"nix-builder-1:aG/Y2Lac517isxGO+ZYdVgglj/SI54PkkWoZTQI9aOI="
|
||||
];
|
||||
};
|
||||
}
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
users.groups.nixdeploy = { };
|
||||
|
||||
users.users.nixdeploy = {
|
||||
isSystemUser = true;
|
||||
group = "nixdeploy";
|
||||
home = "/var/lib/nixdeploy";
|
||||
createHome = true;
|
||||
shell = pkgs.bashInteractive;
|
||||
openssh.authorizedKeys.keys = [
|
||||
"restrict ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFPg1aw0qXBmrQe6lzBwutX5t9Sxg2OeVN/homjqU6Ja moons@nix-builder"
|
||||
];
|
||||
};
|
||||
|
||||
security.sudo.extraRules = [
|
||||
{
|
||||
users = [ "nixdeploy" ];
|
||||
|
||||
commands = [
|
||||
{
|
||||
command = "ALL";
|
||||
options = [ "NOPASSWD" ];
|
||||
}
|
||||
];
|
||||
}
|
||||
];
|
||||
}
|
||||
@@ -1,2 +1 @@
|
||||
{
|
||||
}
|
||||
{ }
|
||||
|
||||
Reference in New Issue
Block a user