mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-06 08:48:11 +09:00
Compare commits
35
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
08210abf01 | ||
|
|
eadfa9b331 | ||
|
|
0f3b6c59a2 | ||
|
|
c6fe17de3f | ||
|
|
ac60dc343b | ||
|
|
ebef49064c | ||
|
|
691926aa4f | ||
|
|
37e2184d36 | ||
|
|
52e5fcd47f | ||
|
|
fe785b1fc3 | ||
|
|
b8532ff1b4 | ||
|
|
3a20fe9a09 | ||
|
|
ef7ff60537 | ||
|
|
53f4d2475b | ||
|
|
7d670b03b2 | ||
|
|
2d9154614b | ||
|
|
56bc3161d7 | ||
|
|
10f4d99cb7 | ||
|
|
12badacf46 | ||
|
|
937be12e33 | ||
|
|
8761cbfe40 | ||
|
|
e789b5a16f | ||
|
|
008f704b23 | ||
|
|
11c1e24ccd | ||
|
|
ad8337bfbb | ||
|
|
cf23e1ef63 | ||
|
|
4652d911ee | ||
|
|
c7db764fe2 | ||
|
|
63f49d58f8 | ||
|
|
8189373575 | ||
|
|
d4721d1d22 | ||
|
|
cc3798a7b2 | ||
|
|
0ff78c6848 | ||
|
|
c53a0c0bed | ||
|
|
e3d61e8b6d |
@@ -351,13 +351,13 @@ modules/profiles/
|
|||||||
├── base/
|
├── base/
|
||||||
├── interface/
|
├── interface/
|
||||||
│ ├── cli/
|
│ ├── cli/
|
||||||
|
│ ├── minimal/
|
||||||
│ ├── gui/
|
│ ├── gui/
|
||||||
│ ├── macos/
|
│ ├── macos/
|
||||||
│ ├── linux-desktop/
|
│ ├── linux-desktop/
|
||||||
│ ├── labwc/
|
│ ├── labwc/
|
||||||
│ └── niri/
|
│ └── niri/
|
||||||
├── networking/
|
├── networking/
|
||||||
│ ├── homelab-cache-client/
|
|
||||||
│ ├── tailscale-client/
|
│ ├── tailscale-client/
|
||||||
│ └── tailscale-subnet-router/
|
│ └── tailscale-subnet-router/
|
||||||
├── platform/
|
├── platform/
|
||||||
@@ -369,11 +369,13 @@ modules/profiles/
|
|||||||
│ └── vm/
|
│ └── vm/
|
||||||
├── workload/
|
├── workload/
|
||||||
│ ├── camera/
|
│ ├── camera/
|
||||||
|
│ ├── deploy-rs-target/
|
||||||
│ ├── development/
|
│ ├── development/
|
||||||
│ ├── game/
|
│ ├── game/
|
||||||
│ ├── machine-learning/
|
│ ├── machine-learning/
|
||||||
│ ├── nix-builder/
|
│ ├── network-lab/
|
||||||
│ ├── personal/
|
│ ├── personal/
|
||||||
|
│ ├── photography/
|
||||||
│ ├── server/
|
│ ├── server/
|
||||||
│ └── remote-access/
|
│ └── remote-access/
|
||||||
└── security/
|
└── security/
|
||||||
@@ -394,16 +396,21 @@ The profile layers have these responsibilities:
|
|||||||
- `base` contains only invariants required by every supported host. It includes
|
- `base` contains only invariants required by every supported host. It includes
|
||||||
`systems.nix` and the universal Atuin, tealdeer, trippy, and xh CLI tools;
|
`systems.nix` and the universal Atuin, tealdeer, trippy, and xh CLI tools;
|
||||||
optional secrets, interface, hardware, and workloads do not belong there.
|
optional secrets, interface, hardware, and workloads do not belong there.
|
||||||
- `interface` describes how the host is operated. `interface.cli` is shared by
|
- `interface` describes how the host is operated. `interface.minimal` is shared
|
||||||
NixOS and macOS and includes `tio`. `interface.gui` owns cross-platform
|
by NixOS and macOS and provides the remote-administration CLI baseline,
|
||||||
graphical interface applications such as Vicinae. `interface.macos` owns the
|
including SSH, Nano, htop, Git, Zellij, and Zsh. `interface.cli` includes that
|
||||||
macOS Finder, Dock, trackpad, and shared default preferences and includes
|
baseline and adds the full interactive command-line environment, including
|
||||||
`interface.gui`.
|
the configured Neovim, Yazi, and `tio`. `interface.gui` owns
|
||||||
|
cross-platform graphical interface applications such as Vicinae.
|
||||||
|
`interface.macos` owns the macOS Finder, Dock, trackpad, and shared default
|
||||||
|
preferences and includes `interface.gui`.
|
||||||
`interface.linux-desktop` owns the common labwc/niri desktop selection,
|
`interface.linux-desktop` owns the common labwc/niri desktop selection,
|
||||||
including Ghostty and Nautilus, and also includes `interface.gui`. Labwc and
|
including Ghostty and Nautilus, and also includes `interface.gui`. Labwc and
|
||||||
niri remain independently selectable and do not imply CLI or personal
|
niri remain independently selectable and do not imply CLI or personal
|
||||||
workloads.
|
workloads.
|
||||||
- `platform` describes NixOS foundations and physical or virtual form factors.
|
- `platform` describes NixOS foundations and physical or virtual form factors.
|
||||||
|
`platform.nixos` selects the shared network foundation and `services.clatd`;
|
||||||
|
VM, laptop, and desktop platform profiles inherit both.
|
||||||
macOS does not need an empty symmetric platform profile.
|
macOS does not need an empty symmetric platform profile.
|
||||||
- `workload` describes optional host uses. `workload.development` and
|
- `workload` describes optional host uses. `workload.development` and
|
||||||
`workload.personal` are cross-platform profiles, not `*-linux` variants.
|
`workload.personal` are cross-platform profiles, not `*-linux` variants.
|
||||||
@@ -543,9 +550,26 @@ A host registry may use a specification like this:
|
|||||||
|
|
||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.minimal"
|
||||||
"platform.vm"
|
"platform.vm"
|
||||||
"workload.remote-access"
|
"workload.remote-access"
|
||||||
|
"workload.deploy-rs-target"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
netsrv-01 = {
|
||||||
|
system = "x86_64-linux";
|
||||||
|
stateVersion = "26.05";
|
||||||
|
user = "moons";
|
||||||
|
path = ./netsrv-01;
|
||||||
|
|
||||||
|
profiles = [
|
||||||
|
"base"
|
||||||
|
"interface.minimal"
|
||||||
|
"platform.vm"
|
||||||
|
"workload.remote-access"
|
||||||
|
"workload.deploy-rs-target"
|
||||||
|
"workload.server"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -557,7 +581,7 @@ A host registry may use a specification like this:
|
|||||||
|
|
||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.minimal"
|
||||||
"platform.vm"
|
"platform.vm"
|
||||||
"workload.server"
|
"workload.server"
|
||||||
];
|
];
|
||||||
@@ -609,6 +633,7 @@ A host registry may use a specification like this:
|
|||||||
"security.tpm-storage"
|
"security.tpm-storage"
|
||||||
"workload.camera"
|
"workload.camera"
|
||||||
"workload.development"
|
"workload.development"
|
||||||
|
"workload.network-lab"
|
||||||
"workload.personal"
|
"workload.personal"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
@@ -631,7 +656,9 @@ A host registry may use a specification like this:
|
|||||||
"workload.development"
|
"workload.development"
|
||||||
"workload.game"
|
"workload.game"
|
||||||
"workload.machine-learning"
|
"workload.machine-learning"
|
||||||
|
"workload.network-lab"
|
||||||
"workload.personal"
|
"workload.personal"
|
||||||
|
"workload.photography"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -654,14 +681,22 @@ A host registry may use a specification like this:
|
|||||||
```
|
```
|
||||||
|
|
||||||
The current role assignment is intentional: nix-example is the development VM;
|
The current role assignment is intentional: nix-example is the development VM;
|
||||||
ops is the remote-access VM with host-specific static networking;
|
ops is the minimal-interface remote-access VM with host-specific static
|
||||||
internal-app-01 is the container server VM; and installer builds the minimal
|
networking; netsrv-01 is the deploy-rs-managed container server VM;
|
||||||
installation ISO without Home Manager. x1g9 is a full NixOS desktop with niri,
|
internal-app-01 is the minimal-interface container server VM;
|
||||||
|
nix-builder is the minimal-interface remote Nix build VM with dedicated build
|
||||||
|
and store disks; and installer builds the minimal installation ISO without Home
|
||||||
|
Manager. x1g9 is a full NixOS desktop with niri,
|
||||||
labwc, ly, the shared Linux desktop applications, and the personal workload.
|
labwc, ly, the shared Linux desktop applications, and the personal workload.
|
||||||
x1g13 is the secure NixOS development and personal ThinkPad, with the same
|
x1g13 is the secure NixOS development and personal ThinkPad, with the same
|
||||||
desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk
|
desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk
|
||||||
unlock. galleria is the Intel/NVIDIA physical desktop shared with Windows; it
|
unlock. galleria is the Intel/NVIDIA physical desktop shared with Windows; it
|
||||||
uses dedicated NixOS partitions, LUKS, Secure Boot, and TPM-backed disk unlock.
|
uses dedicated NixOS partitions, LUKS, Secure Boot, and TPM-backed disk unlock.
|
||||||
|
It selects `workload.photography` for AI-enabled darktable. The application
|
||||||
|
chooses CUDA support from the NVIDIA hardware unit's enable state and keeps
|
||||||
|
the default CUDA targets, including RTX 3060 Ti support, to reuse binary caches.
|
||||||
|
galleria and x1g13 select `workload.network-lab` for containerlab, Docker, and
|
||||||
|
the NanoKVM-USB desktop client with serial-port access.
|
||||||
m2 is the daily-use macOS development and personal machine with the macOS
|
m2 is the daily-use macOS development and personal machine with the macOS
|
||||||
interface defaults. Keep the desktop sessions independently selectable, and
|
interface defaults. Keep the desktop sessions independently selectable, and
|
||||||
keep the development and personal profiles usable across NixOS and Darwin.
|
keep the development and personal profiles usable across NixOS and Darwin.
|
||||||
@@ -694,6 +729,15 @@ configuration fragments. For example:
|
|||||||
|
|
||||||
```text
|
```text
|
||||||
hosts/
|
hosts/
|
||||||
|
├── nix-builder/
|
||||||
|
│ ├── disko.nix
|
||||||
|
│ ├── hardware-configuration.nix
|
||||||
|
│ └── nixos.nix
|
||||||
|
├── netsrv-01/
|
||||||
|
│ ├── disko.nix
|
||||||
|
│ ├── hardware-configuration.nix
|
||||||
|
│ ├── networking.nix
|
||||||
|
│ └── nixos.nix
|
||||||
├── installer/
|
├── installer/
|
||||||
│ └── nixos.nix
|
│ └── nixos.nix
|
||||||
├── internal-app-01/
|
├── internal-app-01/
|
||||||
@@ -723,12 +767,15 @@ hosts/
|
|||||||
```
|
```
|
||||||
|
|
||||||
`hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the
|
`hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the
|
||||||
normal top-level Nix module `imports`. `hosts/x1g13/nixos.nix` loads its
|
normal top-level Nix module `imports`. `hosts/nix-builder/nixos.nix` and
|
||||||
generated hardware configuration and host-local `disko.nix` the same way. Do
|
`hosts/x1g13/nixos.nix` load their generated hardware configuration and
|
||||||
not confuse these host imports with the prohibition on top-level `imports` in
|
host-local `disko.nix` the same way. The nix-builder Disko definition mounts its
|
||||||
unit configuration fragments. `hosts/galleria/disko.nix` manages only the two
|
existing VM filesystems by stable QEMU SCSI IDs and does not take destructive
|
||||||
dedicated NixOS partitions by PARTUUID and deliberately excludes the Windows
|
ownership of them. Do not confuse these host imports with the prohibition on
|
||||||
disk, Windows partitions, and the Windows EFI System Partition.
|
top-level `imports` in unit configuration fragments. `hosts/galleria/disko.nix`
|
||||||
|
manages only the two dedicated NixOS partitions by PARTUUID and deliberately
|
||||||
|
excludes the Windows disk, Windows partitions, and the Windows EFI System
|
||||||
|
Partition.
|
||||||
|
|
||||||
Derive the system class from the host's `system`:
|
Derive the system class from the host's `system`:
|
||||||
|
|
||||||
@@ -831,8 +878,9 @@ For profile changes, additionally:
|
|||||||
`homebrew.casks` selection as well as module evaluation.
|
`homebrew.casks` selection as well as module evaluation.
|
||||||
- Preserve the intended host roles: nix-example remains the development VM;
|
- Preserve the intended host roles: nix-example remains the development VM;
|
||||||
ops remains the statically networked remote-access VM; internal-app-01 remains
|
ops remains the statically networked remote-access VM; internal-app-01 remains
|
||||||
the container server VM; installer remains the Home Manager-free installation
|
the container server VM; netsrv-01 remains the deploy-rs-managed container
|
||||||
ISO; x1g9 provides niri, labwc, ly, and the personal application set; x1g13
|
server VM; installer remains the Home Manager-free installation ISO; x1g9
|
||||||
|
provides niri, labwc, ly, and the personal application set; x1g13
|
||||||
additionally provides the development, Tailscale client, secrets, Secure Boot,
|
additionally provides the development, Tailscale client, secrets, Secure Boot,
|
||||||
and TPM storage roles; galleria remains the Intel/NVIDIA dual-boot desktop
|
and TPM storage roles; galleria remains the Intel/NVIDIA dual-boot desktop
|
||||||
with LUKS, Secure Boot, and TPM storage; m2 remains the daily-use development
|
with LUKS, Secure Boot, and TPM storage; m2 remains the daily-use development
|
||||||
|
|||||||
@@ -0,0 +1,153 @@
|
|||||||
|
# NixOSインストール手順(SOPSなし・ディスク暗号化なし)
|
||||||
|
|
||||||
|
この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を
|
||||||
|
使用しないホスト向けの、独立したインストール手順である。
|
||||||
|
|
||||||
|
SOPSとディスク暗号化を使用する場合は、[暗号化ありの手順](install.md)を参照。
|
||||||
|
|
||||||
|
## 事前準備
|
||||||
|
|
||||||
|
1. [ISOビルド](iso-build.md)を参照してISOを作成
|
||||||
|
2. USBに書き込んで対象マシンでブート
|
||||||
|
|
||||||
|
## ネットワーク接続
|
||||||
|
|
||||||
|
### 有線LAN
|
||||||
|
|
||||||
|
DHCPで自動設定される。
|
||||||
|
|
||||||
|
### Wi-Fi(有線が使えない場合)
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmcli device wifi connect <SSID> --ask
|
||||||
|
```
|
||||||
|
|
||||||
|
## SSH接続
|
||||||
|
|
||||||
|
コンソールに表示されたIPアドレスに接続:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh root@<ip-address>
|
||||||
|
```
|
||||||
|
|
||||||
|
## インストール手順
|
||||||
|
|
||||||
|
### 1. dotfilesのクローン
|
||||||
|
|
||||||
|
```bash
|
||||||
|
git clone [email protected]:moons-14/dotfiles.git ~/dotfiles
|
||||||
|
cd ~/dotfiles
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2. ホスト設定の作成
|
||||||
|
|
||||||
|
`hosts/<hostname>/nixos.nix`を作成し、`hosts/default.nix`にホストと使用する
|
||||||
|
プロファイルを登録する。ホスト固有の設定だけをホストディレクトリに置き、
|
||||||
|
再利用可能な設定は適切なunitまたはprofileに置く。
|
||||||
|
|
||||||
|
### 3. インストール先ディスクの確認
|
||||||
|
|
||||||
|
```bash
|
||||||
|
lsblk -o NAME,PATH,SIZE,MODEL,SERIAL,TYPE,FSTYPE,MOUNTPOINTS
|
||||||
|
ls -l /dev/disk/by-id/
|
||||||
|
```
|
||||||
|
|
||||||
|
以降の操作では指定したディスクの既存データが消去される。対象を必ず確認し、
|
||||||
|
可能であれば`/dev/sda`や`/dev/nvme0n1`ではなく、安定した
|
||||||
|
`/dev/disk/by-id/...`パスを使用する。
|
||||||
|
|
||||||
|
### 4. Disko設定の作成
|
||||||
|
|
||||||
|
`hosts/<hostname>/disko.nix`を作成する:
|
||||||
|
|
||||||
|
```nix
|
||||||
|
_:
|
||||||
|
{
|
||||||
|
disko.enableConfig = true;
|
||||||
|
|
||||||
|
disko.devices.disk.main = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/disk/by-id/<target-disk>";
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
ESP = {
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
root = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
`<target-disk>`を手順3で確認した実際のディスクIDに置き換える。指定した
|
||||||
|
ディスクの既存データは消去される。
|
||||||
|
|
||||||
|
### 5. パーティション作成とマウント
|
||||||
|
|
||||||
|
```bash
|
||||||
|
disko --mode destroy,format,mount hosts/<hostname>/disko.nix
|
||||||
|
```
|
||||||
|
|
||||||
|
Diskoの実行結果を確認する:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
findmnt /mnt
|
||||||
|
findmnt /mnt/boot
|
||||||
|
```
|
||||||
|
|
||||||
|
### 6. ハードウェア設定の生成
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \
|
||||||
|
> ~/dotfiles/hosts/<hostname>/hardware-configuration.nix
|
||||||
|
```
|
||||||
|
|
||||||
|
### 7. ホストモジュールから設定を読み込む
|
||||||
|
|
||||||
|
`hosts/<hostname>/nixos.nix`で、生成したハードウェア設定とDisko設定を読み込む:
|
||||||
|
|
||||||
|
```nix
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
./hardware-configuration.nix
|
||||||
|
./disko.nix
|
||||||
|
];
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 8. NixOSインストール
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nixos-install --flake ~/dotfiles#<hostname>
|
||||||
|
```
|
||||||
|
|
||||||
|
SOPSを使用しないため、age鍵の登録、シークレットの再暗号化、SSHホストキーの
|
||||||
|
事前生成とコピーは不要である。OpenSSHを有効にしたホストでは、SSHホストキーは
|
||||||
|
通常の初回起動時に生成される。
|
||||||
|
|
||||||
|
### 9. 再起動
|
||||||
|
|
||||||
|
```bash
|
||||||
|
reboot
|
||||||
|
```
|
||||||
|
|
||||||
|
## インストール後の確認
|
||||||
|
|
||||||
|
- 正しいディスクから起動できるか
|
||||||
|
- `/`と`/boot`が意図したファイルシステムからマウントされているか
|
||||||
|
- ネットワークと、設定している場合はSSH接続が利用できるか
|
||||||
+32
-44
@@ -1,4 +1,10 @@
|
|||||||
# NixOSインストール手順
|
# NixOSインストール手順(SOPS・ディスク暗号化あり)
|
||||||
|
|
||||||
|
この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を
|
||||||
|
使用するホスト向けである。
|
||||||
|
|
||||||
|
どちらも使用しない場合は、
|
||||||
|
[SOPSなし・ディスク暗号化なしの手順](install-simple.md)を参照。
|
||||||
|
|
||||||
## 事前準備
|
## 事前準備
|
||||||
|
|
||||||
@@ -83,54 +89,36 @@ sops updatekeys secrets/hosts/<hostname>/*.yaml
|
|||||||
|
|
||||||
新しいホスト用の`hosts/<hostname>/disko.nix`を作成。
|
新しいホスト用の`hosts/<hostname>/disko.nix`を作成。
|
||||||
|
|
||||||
#### シンプル構成(暗号化なし)
|
LUKS暗号化とbtrfsの構成は`hosts/x1g13/disko.nix`を参照。
|
||||||
|
|
||||||
```nix
|
|
||||||
_:
|
|
||||||
{
|
|
||||||
disko.enableConfig = true;
|
|
||||||
|
|
||||||
disko.devices.disk.main = {
|
|
||||||
type = "disk";
|
|
||||||
device = "/dev/sda";
|
|
||||||
content = {
|
|
||||||
type = "gpt";
|
|
||||||
partitions = {
|
|
||||||
ESP = {
|
|
||||||
size = "512M";
|
|
||||||
type = "EF00";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "vfat";
|
|
||||||
mountpoint = "/boot";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
root = {
|
|
||||||
size = "100%";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "ext4";
|
|
||||||
mountpoint = "/";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
#### LUKS暗号化 + btrfs
|
|
||||||
|
|
||||||
`hosts/x1g13/disko.nix`を参照。
|
|
||||||
|
|
||||||
### 7. ディスクのパーティション
|
### 7. ディスクのパーティション
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd ~/dotfiles
|
cd ~/dotfiles
|
||||||
nix run github:nix-community/disko -- --mode disko hosts/<hostname>/disko.nix
|
disko --mode destroy,format,mount hosts/<hostname>/disko.nix
|
||||||
```
|
```
|
||||||
|
|
||||||
### 8. ホストキーのコピー
|
### 8. ハードウェア設定の生成
|
||||||
|
|
||||||
|
対象マシンのハードウェア設定を生成し、新しいホストのディレクトリへ直接保存:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \
|
||||||
|
> ~/dotfiles/hosts/<hostname>/hardware-configuration.nix
|
||||||
|
```
|
||||||
|
|
||||||
|
`hosts/<hostname>/nixos.nix`から生成した設定とDisko設定を読み込む:
|
||||||
|
|
||||||
|
```nix
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
./hardware-configuration.nix
|
||||||
|
./disko.nix
|
||||||
|
];
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### 9. ホストキーのコピー
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
mkdir -p /mnt/etc/ssh
|
mkdir -p /mnt/etc/ssh
|
||||||
@@ -138,13 +126,13 @@ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/
|
|||||||
chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key
|
chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key
|
||||||
```
|
```
|
||||||
|
|
||||||
### 9. NixOSインストール
|
### 10. NixOSインストール
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
nixos-install --flake ~/dotfiles#<hostname>
|
nixos-install --flake ~/dotfiles#<hostname>
|
||||||
```
|
```
|
||||||
|
|
||||||
### 10. 再起動
|
### 11. 再起動
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
reboot
|
reboot
|
||||||
|
|||||||
+72
-12
@@ -1,26 +1,86 @@
|
|||||||
# カスタムISOビルド
|
# カスタムインストーラー ISO
|
||||||
|
|
||||||
|
`hosts/installer` から、NixOS 26.05 ベースの `x86_64-linux` 用インストーラー
|
||||||
|
ISO を作成する。installer ホストは Home Manager を使用せず、`base` プロファイルと
|
||||||
|
ホスト固有のインストール支援設定だけを含む。
|
||||||
|
|
||||||
## ビルド
|
## ビルド
|
||||||
|
|
||||||
|
flake 対応の Nix が利用できる環境で、リポジトリのルートから実行する。
|
||||||
|
`x86_64-linux` 以外のマシンで実行する場合は、対応する Linux リモートビルダーが
|
||||||
|
必要になる。
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
nix build .#nixosConfigurations.installer.config.system.build.isoImage
|
nix build .#nixosConfigurations.installer.config.system.build.isoImage
|
||||||
```
|
```
|
||||||
|
|
||||||
## ISO書き込み
|
生成された ISO は次の場所にある。
|
||||||
|
|
||||||
|
```text
|
||||||
|
result/iso/nixos-minimal-*-x86_64-linux.iso
|
||||||
|
```
|
||||||
|
|
||||||
|
ファイル名に含まれる NixOS のバージョンとリビジョンは、`flake.lock` の更新に応じて
|
||||||
|
変わる。生成物を確認するには次を実行する。
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# USBデバイスの確認
|
ls -lh result/iso/*.iso
|
||||||
lsblk
|
sha256sum result/iso/*.iso
|
||||||
|
```
|
||||||
|
|
||||||
# 書き込み(/dev/sdXは実際のデバイスに置き換える)
|
## USB メモリへの書き込み
|
||||||
sudo dd if=./result/nixos-minimal-*.iso of=/dev/sdX bs=4M status=progress
|
|
||||||
|
書き込み先はパーティション(例: `/dev/sdX1`)ではなく、USB デバイス全体
|
||||||
|
(例: `/dev/sdX`)を指定する。この操作は指定したデバイスの内容を上書きするため、
|
||||||
|
サイズ、モデル、マウント先を確認する。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
lsblk -p -o NAME,SIZE,TYPE,MODEL,MOUNTPOINTS
|
||||||
|
```
|
||||||
|
|
||||||
|
USB のマウント済みパーティションをアンマウントしてから、`/dev/sdX` と
|
||||||
|
`/dev/sdX1` を確認した実際のデバイス名に置き換えて書き込む。パーティションが
|
||||||
|
複数ある場合は、それぞれをアンマウントする。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo umount /dev/sdX1
|
||||||
|
sudo dd if=result/iso/nixos-minimal-*-x86_64-linux.iso \
|
||||||
|
of=/dev/sdX bs=4M conv=fsync status=progress
|
||||||
sync
|
sync
|
||||||
```
|
```
|
||||||
|
|
||||||
## ISOの特徴
|
書き込み完了後、USB を安全に取り外して対象マシンから起動する。
|
||||||
|
|
||||||
- SSH鍵認証でrootログイン可能
|
## 起動後の接続
|
||||||
- 有線LANはDHCPで自動設定
|
|
||||||
- WiFiは`nmcli`で手動設定可能
|
有線 LAN は DHCP で自動設定される。Wi-Fi を使用する場合は、インストーラーの
|
||||||
- disko/sops/ageなどのツールを内蔵
|
コンソールで NetworkManager を使って接続する。
|
||||||
- ブート時にIPアドレスとヘルプを表示
|
|
||||||
|
```bash
|
||||||
|
nmcli device wifi list
|
||||||
|
nmcli device wifi connect <SSID> --ask
|
||||||
|
```
|
||||||
|
|
||||||
|
起動時にコンソールへ IPv4 アドレスと簡易ヘルプが表示される。表示されたアドレスへ
|
||||||
|
登録済みの SSH 鍵で接続する。
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh root@<ip-address>
|
||||||
|
```
|
||||||
|
|
||||||
|
root のパスワードログインとキーボード対話認証は無効で、
|
||||||
|
`hosts/installer/nixos.nix` に登録された公開鍵だけが利用できる。
|
||||||
|
以降の作業は、構成に応じて次の手順を参照する:
|
||||||
|
|
||||||
|
- [SOPSなし・ディスク暗号化なし](install-simple.md)
|
||||||
|
- [SOPS・ディスク暗号化あり](install.md)
|
||||||
|
|
||||||
|
## ISO に含まれる主な設定とツール
|
||||||
|
|
||||||
|
- Nix flakes と `nix-command`
|
||||||
|
- NetworkManager、OpenSSH、起動時の IP アドレス表示
|
||||||
|
- `disko`、`parted`、`cryptsetup`、`btrfs-progs`、`efibootmgr`
|
||||||
|
- `sops`、`age`、`ssh-to-age`
|
||||||
|
- `age-plugin-yubikey`、`yubikey-manager`、`pcsc-tools` と `pcscd`
|
||||||
|
- `sbctl`、`tpm2-tools`
|
||||||
|
- `git`、`rsync`、`vim`、`wget`、`curl`、`jq`、`pciutils`、`util-linux`
|
||||||
|
|||||||
Generated
+232
-268
@@ -100,11 +100,11 @@
|
|||||||
"systems": "systems"
|
"systems": "systems"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787888246,
|
"lastModified": 1790375278,
|
||||||
"narHash": "sha256-E8vD7IJ/16J9JPTQKYvSmwq5k0/FdLMtLf7UVk3G0IU=",
|
"narHash": "sha256-oGv6aatLyq8Eha1ZA5wbkdRhlE3WdmOt9yajLeTgnCk=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "browser-previews",
|
"repo": "browser-previews",
|
||||||
"rev": "f2e8d11fd3e04175290fe16e882ceb9dd064a8e2",
|
"rev": "ef13999ddd920d61e5c7cfae16177de7ffb62e61",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -158,15 +158,16 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1784665499,
|
"lastModified": 1790001035,
|
||||||
"narHash": "sha256-9BMxlTxCCDAeoNLtb1a/st7udtTIJep+wpUzquA29VU=",
|
"narHash": "sha256-1/SLBjSYBzDdDhvLQ83wrzBakyS/xNGgtxHGNuveOEQ=",
|
||||||
"owner": "nix-community",
|
"owner": "Mic92",
|
||||||
"repo": "bun2nix",
|
"repo": "bun2nix",
|
||||||
"rev": "0f2a1f0b6f42cebe3b149bf62d38754c5e0e9729",
|
"rev": "07a5bfc8ac36c5370199343fa620b69f63186e33",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "nix-community",
|
"owner": "Mic92",
|
||||||
|
"ref": "llm-agents",
|
||||||
"repo": "bun2nix",
|
"repo": "bun2nix",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
@@ -206,11 +207,11 @@
|
|||||||
"nixpkgs": "nixpkgs"
|
"nixpkgs": "nixpkgs"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787978476,
|
"lastModified": 1790510073,
|
||||||
"narHash": "sha256-aI5mJw5GJ6YADjRLvu5KLK6NK7NCnLveQyNqHl4sDP4=",
|
"narHash": "sha256-ePu9Vqm1/S/lTidMGMnPS3PheOb2sEOqJ5iBA74A8nY=",
|
||||||
"owner": "ilysenko",
|
"owner": "ilysenko",
|
||||||
"repo": "codex-desktop-linux",
|
"repo": "codex-desktop-linux",
|
||||||
"rev": "7994f23cd5c2da23cdc0953367ff6056ebed50b3",
|
"rev": "5b80192545dcc9a820c49cf26c806308a7afd551",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -238,6 +239,24 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"containerlab": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": "nixpkgs_4"
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1790449163,
|
||||||
|
"narHash": "sha256-BWqGSYpBep1D8JxQPFwXVuYsn5LxlB2kR7nfnCQbUjc=",
|
||||||
|
"owner": "srl-labs",
|
||||||
|
"repo": "containerlab",
|
||||||
|
"rev": "0bb144e1d03fb3546abd15a0565562382ab85437",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "srl-labs",
|
||||||
|
"repo": "containerlab",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
"crane": {
|
"crane": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1784407669,
|
"lastModified": 1784407669,
|
||||||
@@ -255,11 +274,11 @@
|
|||||||
},
|
},
|
||||||
"crane_2": {
|
"crane_2": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787326676,
|
"lastModified": 1789760033,
|
||||||
"narHash": "sha256-lWhBbBvC05/xwivKBBiM2YNizpmgqCgyOIzomvRuwxs=",
|
"narHash": "sha256-jtT4yxZpR8seYnlCMMWSSPlFN92zO6ICuZ8pJrmi86k=",
|
||||||
"owner": "ipetkov",
|
"owner": "ipetkov",
|
||||||
"repo": "crane",
|
"repo": "crane",
|
||||||
"rev": "692f7e9ef2ece8125b466f66f2af532b3edaed0d",
|
"rev": "73b980519cefc727a5f6cc8e5c0947a2f9be6edd",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -268,28 +287,6 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"deploy-rs": {
|
|
||||||
"inputs": {
|
|
||||||
"flake-compat": "flake-compat_2",
|
|
||||||
"nixpkgs": [
|
|
||||||
"nixpkgs"
|
|
||||||
],
|
|
||||||
"utils": "utils"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1786361680,
|
|
||||||
"narHash": "sha256-IxaZkb9rCGEZ+yGndxKXONeIEcKMzoFUsvLTB5G/caw=",
|
|
||||||
"owner": "serokell",
|
|
||||||
"repo": "deploy-rs",
|
|
||||||
"rev": "16901271e5b30b591e56f7a84f25f186fb20f3e1",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "serokell",
|
|
||||||
"repo": "deploy-rs",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"disko": {
|
"disko": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
@@ -297,11 +294,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1781152676,
|
"lastModified": 1789770686,
|
||||||
"narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=",
|
"narHash": "sha256-uZkBR7yHdIKUFB5SZdfgh1qkGfI3XmYmI/lTiquxbck=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "disko",
|
"repo": "disko",
|
||||||
"rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1",
|
"rev": "725ea35e410ad83be4931d1bff7e090eacaf3563",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -345,11 +342,11 @@
|
|||||||
"flake-compat_2": {
|
"flake-compat_2": {
|
||||||
"flake": false,
|
"flake": false,
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1733328505,
|
"lastModified": 1767039857,
|
||||||
"narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=",
|
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
|
||||||
"owner": "edolstra",
|
"owner": "edolstra",
|
||||||
"repo": "flake-compat",
|
"repo": "flake-compat",
|
||||||
"rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec",
|
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -363,13 +360,13 @@
|
|||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1767039857,
|
"lastModified": 1767039857,
|
||||||
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
|
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
|
||||||
"owner": "edolstra",
|
"owner": "NixOS",
|
||||||
"repo": "flake-compat",
|
"repo": "flake-compat",
|
||||||
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
|
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "edolstra",
|
"owner": "NixOS",
|
||||||
"repo": "flake-compat",
|
"repo": "flake-compat",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
@@ -395,34 +392,18 @@
|
|||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1767039857,
|
"lastModified": 1767039857,
|
||||||
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
|
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
|
||||||
"owner": "NixOS",
|
"owner": "edolstra",
|
||||||
"repo": "flake-compat",
|
"repo": "flake-compat",
|
||||||
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
|
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "NixOS",
|
"owner": "edolstra",
|
||||||
"repo": "flake-compat",
|
"repo": "flake-compat",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"flake-compat_6": {
|
"flake-compat_6": {
|
||||||
"flake": false,
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1767039857,
|
|
||||||
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
|
|
||||||
"owner": "edolstra",
|
|
||||||
"repo": "flake-compat",
|
|
||||||
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "edolstra",
|
|
||||||
"repo": "flake-compat",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"flake-compat_7": {
|
|
||||||
"flake": false,
|
"flake": false,
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1767039857,
|
"lastModified": 1767039857,
|
||||||
@@ -484,11 +465,11 @@
|
|||||||
"nixpkgs-lib": "nixpkgs-lib_2"
|
"nixpkgs-lib": "nixpkgs-lib_2"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787559586,
|
"lastModified": 1788450739,
|
||||||
"narHash": "sha256-onL0VLf9vPllmT0H/OlURIU5r5t5WIEl7t4tVNKT0Nw=",
|
"narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
|
||||||
"owner": "hercules-ci",
|
"owner": "hercules-ci",
|
||||||
"repo": "flake-parts",
|
"repo": "flake-parts",
|
||||||
"rev": "9d0d87172c374f89da73c1cfe6d81ae62feac1f1",
|
"rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -505,11 +486,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787559586,
|
"lastModified": 1788450739,
|
||||||
"narHash": "sha256-onL0VLf9vPllmT0H/OlURIU5r5t5WIEl7t4tVNKT0Nw=",
|
"narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
|
||||||
"owner": "hercules-ci",
|
"owner": "hercules-ci",
|
||||||
"repo": "flake-parts",
|
"repo": "flake-parts",
|
||||||
"rev": "9d0d87172c374f89da73c1cfe6d81ae62feac1f1",
|
"rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -526,11 +507,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1785627969,
|
"lastModified": 1788450739,
|
||||||
"narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=",
|
"narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
|
||||||
"owner": "hercules-ci",
|
"owner": "hercules-ci",
|
||||||
"repo": "flake-parts",
|
"repo": "flake-parts",
|
||||||
"rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a",
|
"rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -617,19 +598,19 @@
|
|||||||
},
|
},
|
||||||
"ghostty": {
|
"ghostty": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"flake-compat": "flake-compat_3",
|
"flake-compat": "flake-compat_2",
|
||||||
"home-manager": "home-manager_2",
|
"home-manager": "home-manager_2",
|
||||||
"nixpkgs": "nixpkgs_4",
|
"nixpkgs": "nixpkgs_5",
|
||||||
"systems": "systems_5",
|
"systems": "systems_4",
|
||||||
"zig": "zig",
|
"zig": "zig",
|
||||||
"zon2nix": "zon2nix"
|
"zon2nix": "zon2nix"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1788019183,
|
"lastModified": 1790475802,
|
||||||
"narHash": "sha256-WYLVuVgxCq2OH7+2DuBpBW8KBSYJjwbZn9sZrXALlQY=",
|
"narHash": "sha256-jGBYacSDg7Ya/P3OpkuM+EK+kW4JAPIiGTxEdWMc6PQ=",
|
||||||
"owner": "ghostty-org",
|
"owner": "ghostty-org",
|
||||||
"repo": "ghostty",
|
"repo": "ghostty",
|
||||||
"rev": "7b47213f94058c3715205ce8fa73f7ae581a652c",
|
"rev": "b40acce58dcf77df52231c3798ea58e924647c89",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -663,15 +644,15 @@
|
|||||||
},
|
},
|
||||||
"git-hooks-nix": {
|
"git-hooks-nix": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"flake-compat": "flake-compat_4",
|
"flake-compat": "flake-compat_3",
|
||||||
"nixpkgs": "nixpkgs_5"
|
"nixpkgs": "nixpkgs_6"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787424939,
|
"lastModified": 1790500375,
|
||||||
"narHash": "sha256-O2tBn84NNuHrnqNVxx/XqsXwfYvS1YwBh+7CBnbCYsk=",
|
"narHash": "sha256-XN3sDtn8TU9hAc9xqZ+SqRB/HHm2wjxM6aSWYLJU+oo=",
|
||||||
"owner": "cachix",
|
"owner": "cachix",
|
||||||
"repo": "git-hooks.nix",
|
"repo": "git-hooks.nix",
|
||||||
"rev": "809414f0cdadf82cf11b06c2b29ba9b3168b3297",
|
"rev": "a0e4241b51206fbcbf52fd322eb5f0cd80f153c4",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -750,11 +731,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787377438,
|
"lastModified": 1790215976,
|
||||||
"narHash": "sha256-Sxu1NLTD/Ern6hFGLlZmtKCSct3YQXZI/lls8RE1XeM=",
|
"narHash": "sha256-VkR1rMGyjU9jtw8ISFx5uqR9e+LEaOlhHwrseFkiIVk=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "home-manager",
|
"repo": "home-manager",
|
||||||
"rev": "65258d5c65a250189fde2e35f490d15e064c4c62",
|
"rev": "a6631107a83ceab5872f298a2ea710859c80c4cb",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -795,11 +776,11 @@
|
|||||||
"rust-overlay": "rust-overlay_2"
|
"rust-overlay": "rust-overlay_2"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787658383,
|
"lastModified": 1790423250,
|
||||||
"narHash": "sha256-I+zCjwAtkmgnet+08H+7HV8qJjf6BoFMYsX/8lMiW/s=",
|
"narHash": "sha256-sr4Kfp6yaXUeyKL6n0Y8/ElcR3momIRC20HFc+LF22s=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "lanzaboote",
|
"repo": "lanzaboote",
|
||||||
"rev": "69cf334f9dbc11213c6228c97e9b32924d51443f",
|
"rev": "c1c5edd31802d181c8aa2c71588995d93425d650",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -828,16 +809,16 @@
|
|||||||
"inputs": {
|
"inputs": {
|
||||||
"bun2nix": "bun2nix_2",
|
"bun2nix": "bun2nix_2",
|
||||||
"flake-parts": "flake-parts_4",
|
"flake-parts": "flake-parts_4",
|
||||||
"nixpkgs": "nixpkgs_6",
|
"nixpkgs": "nixpkgs_7",
|
||||||
"systems": "systems_6",
|
"systems": "systems_5",
|
||||||
"treefmt-nix": "treefmt-nix_3"
|
"treefmt-nix": "treefmt-nix_3"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1788038998,
|
"lastModified": 1790555299,
|
||||||
"narHash": "sha256-Q8sIuu2wRET+POhXUGVUaEDKT2OcZyKXLAf744qrbGk=",
|
"narHash": "sha256-A4ZG1Y9Itut5xO+CLwi06CElVlwj4FnhZMgg2Xiucho=",
|
||||||
"owner": "numtide",
|
"owner": "numtide",
|
||||||
"repo": "llm-agents.nix",
|
"repo": "llm-agents.nix",
|
||||||
"rev": "44099f2474161ef95a2b1ec1d8088ae8a6673a77",
|
"rev": "2475131b50dbc795684c55ba771d94401f068fd6",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -864,14 +845,14 @@
|
|||||||
},
|
},
|
||||||
"nani-translate-linux": {
|
"nani-translate-linux": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": "nixpkgs_7"
|
"nixpkgs": "nixpkgs_8"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1786578029,
|
"lastModified": 1789710762,
|
||||||
"narHash": "sha256-XXTxlJ6U7hhHA94eTDCL80iKUwJ54L1EZ9oj/d0hC48=",
|
"narHash": "sha256-U9BDfeN+st7GQoC3byKaj9rHW+i/HPyWvUAmWH6wZyI=",
|
||||||
"ref": "refs/heads/main",
|
"ref": "refs/heads/main",
|
||||||
"rev": "427289b4fc7433b6b08613f9e1644ab5209838d6",
|
"rev": "b5ce224f56360833af5eb21c91387c42d2a4f47b",
|
||||||
"revCount": 11,
|
"revCount": 12,
|
||||||
"type": "git",
|
"type": "git",
|
||||||
"url": "https://github.com/zunoser/nani-translate-linux.git"
|
"url": "https://github.com/zunoser/nani-translate-linux.git"
|
||||||
},
|
},
|
||||||
@@ -884,7 +865,7 @@
|
|||||||
"inputs": {
|
"inputs": {
|
||||||
"niri-stable": "niri-stable",
|
"niri-stable": "niri-stable",
|
||||||
"niri-unstable": "niri-unstable",
|
"niri-unstable": "niri-unstable",
|
||||||
"nixpkgs": "nixpkgs_8",
|
"nixpkgs": "nixpkgs_9",
|
||||||
"nixpkgs-stable": "nixpkgs-stable",
|
"nixpkgs-stable": "nixpkgs-stable",
|
||||||
"xwayland-satellite-stable": "xwayland-satellite-stable",
|
"xwayland-satellite-stable": "xwayland-satellite-stable",
|
||||||
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
|
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
|
||||||
@@ -980,11 +961,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1779529080,
|
"lastModified": 1790329191,
|
||||||
"narHash": "sha256-CHa5L3I71NbPUNJp1gmmwbh91tKsZPyuRK50mLHjAVY=",
|
"narHash": "sha256-HYfn+tCtyY4Xl2l0InOGoaYgZMLbFw3LB11ZETjMxp0=",
|
||||||
"owner": "aster-void",
|
"owner": "aster-void",
|
||||||
"repo": "nix-hazkey",
|
"repo": "nix-hazkey",
|
||||||
"rev": "24cb2926666836988e78ceebeb67ad6c5a387ac3",
|
"rev": "9524686e361eb1ce9c054f0218e7a4b82091b847",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1000,11 +981,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787457452,
|
"lastModified": 1790499302,
|
||||||
"narHash": "sha256-FJh4esFS3zqNNuKwvN3t6wrJGewqp1AUF9DAEvoKPD8=",
|
"narHash": "sha256-Gbf/U9ptJhQh0qnDnJ/+a8MAcq1HXunbArUTHR2wNYk=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "nix-index-database",
|
"repo": "nix-index-database",
|
||||||
"rev": "c51d5c2ba69c907a34e90c9b6b80cd2b93811745",
|
"rev": "161d7c91accd93034bb3c295224d9d895a778573",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1015,14 +996,14 @@
|
|||||||
},
|
},
|
||||||
"nixos-hardware": {
|
"nixos-hardware": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": "nixpkgs_9"
|
"nixpkgs": "nixpkgs_10"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787144466,
|
"lastModified": 1790321948,
|
||||||
"narHash": "sha256-HHfv2/HkNSKbbSyU9iD/g8lbP6r4tl33sSw1W4rXCk0=",
|
"narHash": "sha256-mZGHLGi217oLIwzDM4PNRZeCNa6g2WBXURyXbNMFs7Y=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixos-hardware",
|
"repo": "nixos-hardware",
|
||||||
"rev": "0471accf8d0a8210b31d947497d179ecc99e0021",
|
"rev": "30d48a0ec6035f8140d0125af274f0de95f1e9b5",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1034,15 +1015,15 @@
|
|||||||
},
|
},
|
||||||
"nixos-wsl": {
|
"nixos-wsl": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"flake-compat": "flake-compat_6",
|
"flake-compat": "flake-compat_5",
|
||||||
"nixpkgs": "nixpkgs_10"
|
"nixpkgs": "nixpkgs_11"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1784642409,
|
"lastModified": 1789164534,
|
||||||
"narHash": "sha256-hcbDqFuySAJawljt5r0sKBCJKYnbtGD0T/ZIozH1Dq0=",
|
"narHash": "sha256-DoYGPM6QpnYBLWj9gGw6ZwAzIX+HrAVov1BoT+8Jixo=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "NixOS-WSL",
|
"repo": "NixOS-WSL",
|
||||||
"rev": "eaeb18da90024448a60eb1ec7132eafa4003404e",
|
"rev": "72c92b11bb8289e6651c7fef29cc0a885fd6a255",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1084,11 +1065,11 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs-lib_2": {
|
"nixpkgs-lib_2": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1785031560,
|
"lastModified": 1788057806,
|
||||||
"narHash": "sha256-OmshNvn2vupOFpYinLUu+1Dnpu4n7Q5N3ggGVNHpkUI=",
|
"narHash": "sha256-DTQSMxzDWmT0zhguthvegnVkn7CFqGCv4IHCzk5ZUpM=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "nixpkgs.lib",
|
"repo": "nixpkgs.lib",
|
||||||
"rev": "0e79af5e3d4dcfcd676ab5ba3f95d2e3352e078c",
|
"rev": "596e2e3940e09b2abbeb03f75fa1828c57fcd72c",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1131,11 +1112,11 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs-unstable": {
|
"nixpkgs-unstable": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787874478,
|
"lastModified": 1790510107,
|
||||||
"narHash": "sha256-ubWQiwkhIql/lYwnfK55yKHfAkTBXie2L4iChGNHfI0=",
|
"narHash": "sha256-EVMNYv7hYDDD9TGVT/hIyTYgpiXA8y3m5xIEIxuGNU0=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "7d1a7c21a4c00ea653fc7ed5c083d261340f185f",
|
"rev": "3181085bfd08663b6b9e60bc7a8395c2aaa741bd",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1147,11 +1128,24 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs_10": {
|
"nixpkgs_10": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1783776592,
|
"lastModified": 1789546076,
|
||||||
"narHash": "sha256-UgCQzxeWI75XM8G+hPrPh+MKzEPjG3SpAj7dtqSbksA=",
|
"narHash": "sha256-vWkSk5bbfTqdtMoSgD9FshACO8JCvXTFi+3cqEp0mH0=",
|
||||||
|
"rev": "b1b875982b17dabde9b4a37f3e229e74913e6db3",
|
||||||
|
"type": "tarball",
|
||||||
|
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1074753.b1b875982b17/nixexprs.tar.xz"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"type": "tarball",
|
||||||
|
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"nixpkgs_11": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1789006805,
|
||||||
|
"narHash": "sha256-xB8mKMOx1IA9vTDNLmJZ6n4wCMq/cuWBBOzGCRnqxrU=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "e7a3ca8092b61ff85b6a45bf863ea2b2d6a661b3",
|
"rev": "8ce4ef6cb6f871616146b9fe26d2a5ae594e94fe",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1161,13 +1155,13 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixpkgs_11": {
|
"nixpkgs_12": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787848966,
|
"lastModified": 1790450978,
|
||||||
"narHash": "sha256-7gDpu5hpq0rOYnYMcOWqSzquK4HA/xU8Xf3CjUBOOJA=",
|
"narHash": "sha256-/eLCD/X9kaWJqPR47+fDozEC87Hjmm3i8gJbYmDAD7g=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "d57af924f160a5084293c71c2043f058bd1cdb60",
|
"rev": "5e2305d577ca00acbba631b05cb1094d172b29f3",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1177,20 +1171,20 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixpkgs_12": {
|
"nixpkgs_13": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787360063,
|
"lastModified": 1790323409,
|
||||||
"narHash": "sha256-95aJfHyQTLWslCXFVNB0odgmVkpdmDezQwTg9mhqV1E=",
|
"narHash": "sha256-m4DGo58Fza5ImOegtWOeE18nhpSO1IGzsVA6Lpsb4zw=",
|
||||||
"rev": "2c423e03bbafcff28bfadc6781a4a8257f205cb5",
|
"rev": "e94cb152ed51bd6e24eb4a41f1460252beb52cd2",
|
||||||
"type": "tarball",
|
"type": "tarball",
|
||||||
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1059570.2c423e03bbaf/nixexprs.tar.zst"
|
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1079315.e94cb152ed51/nixexprs.tar.zst"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"type": "tarball",
|
"type": "tarball",
|
||||||
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.zst"
|
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.zst"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixpkgs_13": {
|
"nixpkgs_14": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1770107345,
|
"lastModified": 1770107345,
|
||||||
"narHash": "sha256-tbS0Ebx2PiA1FRW8mt8oejR0qMXmziJmPaU1d4kYY9g=",
|
"narHash": "sha256-tbS0Ebx2PiA1FRW8mt8oejR0qMXmziJmPaU1d4kYY9g=",
|
||||||
@@ -1206,13 +1200,13 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixpkgs_14": {
|
"nixpkgs_15": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787736819,
|
"lastModified": 1789684949,
|
||||||
"narHash": "sha256-cV5xEJJK3BvhU8rEd4mC9UsmDi5qscv/kzGPhBRC5WA=",
|
"narHash": "sha256-ZKhUe/2IJUq1JhKxKMu8rbkgSGmPP2ZCqlIPn40aGCM=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "9fbb54b33e91ee4ca368e35a78e0613c720600b3",
|
"rev": "e554fab72f81915600f3f449b786fd9af40439a5",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1255,6 +1249,22 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixpkgs_4": {
|
"nixpkgs_4": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1787900134,
|
||||||
|
"narHash": "sha256-VYXO0XZlgj06dxJZRhrD3WoSsvq/c7+/Akyoa22pefw=",
|
||||||
|
"owner": "NixOS",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "83199d0d373dd3ac2b9a1996b1d0263f76ab7a4c",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "NixOS",
|
||||||
|
"ref": "nixos-unstable",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"nixpkgs_5": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787424095,
|
"lastModified": 1787424095,
|
||||||
"narHash": "sha256-SpMiSe9OSfWseGAupsdcED3He9mTYTbGMtWb7EVt6pE=",
|
"narHash": "sha256-SpMiSe9OSfWseGAupsdcED3He9mTYTbGMtWb7EVt6pE=",
|
||||||
@@ -1267,29 +1277,13 @@
|
|||||||
"url": "https://channels.nixos.org/nixpkgs-unstable/nixexprs.tar.zst"
|
"url": "https://channels.nixos.org/nixpkgs-unstable/nixexprs.tar.zst"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixpkgs_5": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1782918843,
|
|
||||||
"narHash": "sha256-ETYnV9U7Sr+A45dohzZdfCZKOss4qrTkO+wgNZNvEc0=",
|
|
||||||
"owner": "NixOS",
|
|
||||||
"repo": "nixpkgs",
|
|
||||||
"rev": "e8273b29fe1390ec8d4603f2477357555291432e",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "NixOS",
|
|
||||||
"ref": "nixpkgs-unstable",
|
|
||||||
"repo": "nixpkgs",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixpkgs_6": {
|
"nixpkgs_6": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787424095,
|
"lastModified": 1787631388,
|
||||||
"narHash": "sha256-dWLO5AHhKaw6rdWCtTes8hnntT1r0/J5yhQGm0f0ZgU=",
|
"narHash": "sha256-vMiXptXarfSdJb1Gkc+FYVOAibuBRj7qxGa8z68q1Uw=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "174eb786fb68e3a13e4e535a3deea479a0c07a6a",
|
"rev": "ac6b2166e7a9375683b8e98f860f273222337b16",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1300,6 +1294,22 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixpkgs_7": {
|
"nixpkgs_7": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1790510107,
|
||||||
|
"narHash": "sha256-EVMNYv7hYDDD9TGVT/hIyTYgpiXA8y3m5xIEIxuGNU0=",
|
||||||
|
"owner": "NixOS",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "3181085bfd08663b6b9e60bc7a8395c2aaa741bd",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "NixOS",
|
||||||
|
"ref": "nixpkgs-unstable",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"nixpkgs_8": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1785454630,
|
"lastModified": 1785454630,
|
||||||
"narHash": "sha256-LQy14TZp77TwbQf40gg1V3jo8FwJG0jGDkAH+zRHqg8=",
|
"narHash": "sha256-LQy14TZp77TwbQf40gg1V3jo8FwJG0jGDkAH+zRHqg8=",
|
||||||
@@ -1315,7 +1325,7 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixpkgs_8": {
|
"nixpkgs_9": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1785828668,
|
"lastModified": 1785828668,
|
||||||
"narHash": "sha256-8fsyqeO+mJqvIzeO4xIpgJe/f7MTbbVTEC6RT6WSXNs=",
|
"narHash": "sha256-8fsyqeO+mJqvIzeO4xIpgJe/f7MTbbVTEC6RT6WSXNs=",
|
||||||
@@ -1331,33 +1341,20 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixpkgs_9": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1767892417,
|
|
||||||
"narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=",
|
|
||||||
"rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba",
|
|
||||||
"type": "tarball",
|
|
||||||
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre924538.3497aa5c9457/nixexprs.tar.xz"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"type": "tarball",
|
|
||||||
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixvim": {
|
"nixvim": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"flake-parts": "flake-parts_5",
|
"flake-parts": "flake-parts_5",
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
"nixpkgs"
|
"nixpkgs"
|
||||||
],
|
],
|
||||||
"systems": "systems_7"
|
"systems": "systems_6"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787536726,
|
"lastModified": 1789959143,
|
||||||
"narHash": "sha256-aBh5Yk9tX8ZV4k10BJr2fvTq0/+iWGegaCMUOU7YKas=",
|
"narHash": "sha256-9oBHyJtUyunZL+6v0Ub8Y759cXcejQiTHpXtGcx5RLs=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "nixvim",
|
"repo": "nixvim",
|
||||||
"rev": "e2c3f9f36326d07340626847543c557e2b95fb50",
|
"rev": "4836e77b1798cd42e2de28593bec4c1788da08f5",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1369,14 +1366,14 @@
|
|||||||
},
|
},
|
||||||
"noctalia": {
|
"noctalia": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": "nixpkgs_12"
|
"nixpkgs": "nixpkgs_13"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1788012673,
|
"lastModified": 1790523212,
|
||||||
"narHash": "sha256-Qzdrf8phPKo31TTqVdDv6vVv9EwQRWnf5HPKUoDDdPM=",
|
"narHash": "sha256-Z8SuI0YgAZaF0sumKPBF85PxPtTjpo8jvtphbgoITv8=",
|
||||||
"owner": "noctalia-dev",
|
"owner": "noctalia-dev",
|
||||||
"repo": "noctalia",
|
"repo": "noctalia",
|
||||||
"rev": "29dab93fdf9091f83f9eec20a20e72e11fc4e6c4",
|
"rev": "08c30392b1350b4f3d3fb77e23732560559f1638",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1394,16 +1391,16 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787953571,
|
"lastModified": 1789761689,
|
||||||
"narHash": "sha256-cUly+bzaPwj9fiUmC+Gh7gwKAZjINCKZKGf/gPMhJJg=",
|
"narHash": "sha256-kZmr3Bd0ehbq43/rDXtkuexWpMN8HyE0iqw1LlaartM=",
|
||||||
"owner": "vicinaehq",
|
"owner": "vicinaehq",
|
||||||
"repo": "numen",
|
"repo": "numen",
|
||||||
"rev": "7cfed1e8322ac6ebd0db9cbf0db31e27385965bc",
|
"rev": "7379178f9c2fc4dc0c1965c1800e62ef764118f4",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "vicinaehq",
|
"owner": "vicinaehq",
|
||||||
"ref": "v0.5.1",
|
"ref": "v0.6.2",
|
||||||
"repo": "numen",
|
"repo": "numen",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
@@ -1435,18 +1432,18 @@
|
|||||||
},
|
},
|
||||||
"pre-commit": {
|
"pre-commit": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"flake-compat": "flake-compat_5",
|
"flake-compat": "flake-compat_4",
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
"lanzaboote",
|
"lanzaboote",
|
||||||
"nixpkgs"
|
"nixpkgs"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787424939,
|
"lastModified": 1789514889,
|
||||||
"narHash": "sha256-O2tBn84NNuHrnqNVxx/XqsXwfYvS1YwBh+7CBnbCYsk=",
|
"narHash": "sha256-PFD1nxptCXJyJoiYO1gf/5Vv43yqGpHtMC6LUhl9/pQ=",
|
||||||
"owner": "cachix",
|
"owner": "cachix",
|
||||||
"repo": "git-hooks.nix",
|
"repo": "git-hooks.nix",
|
||||||
"rev": "809414f0cdadf82cf11b06c2b29ba9b3168b3297",
|
"rev": "59f4ca0d063a1a3ec722c88b51a33004862e5379",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1460,7 +1457,7 @@
|
|||||||
"browser-previews": "browser-previews",
|
"browser-previews": "browser-previews",
|
||||||
"codex-desktop-linux": "codex-desktop-linux",
|
"codex-desktop-linux": "codex-desktop-linux",
|
||||||
"codex-session-usage": "codex-session-usage",
|
"codex-session-usage": "codex-session-usage",
|
||||||
"deploy-rs": "deploy-rs",
|
"containerlab": "containerlab",
|
||||||
"disko": "disko",
|
"disko": "disko",
|
||||||
"flake-parts": "flake-parts_3",
|
"flake-parts": "flake-parts_3",
|
||||||
"ghostty": "ghostty",
|
"ghostty": "ghostty",
|
||||||
@@ -1475,7 +1472,7 @@
|
|||||||
"nix-index-database": "nix-index-database",
|
"nix-index-database": "nix-index-database",
|
||||||
"nixos-hardware": "nixos-hardware",
|
"nixos-hardware": "nixos-hardware",
|
||||||
"nixos-wsl": "nixos-wsl",
|
"nixos-wsl": "nixos-wsl",
|
||||||
"nixpkgs": "nixpkgs_11",
|
"nixpkgs": "nixpkgs_12",
|
||||||
"nixpkgs-unstable": "nixpkgs-unstable",
|
"nixpkgs-unstable": "nixpkgs-unstable",
|
||||||
"nixvim": "nixvim",
|
"nixvim": "nixvim",
|
||||||
"noctalia": "noctalia",
|
"noctalia": "noctalia",
|
||||||
@@ -1483,7 +1480,7 @@
|
|||||||
"skills": "skills",
|
"skills": "skills",
|
||||||
"sops-nix": "sops-nix",
|
"sops-nix": "sops-nix",
|
||||||
"stylix": "stylix",
|
"stylix": "stylix",
|
||||||
"systems": "systems_9",
|
"systems": "systems_8",
|
||||||
"treefmt-nix": "treefmt-nix_4",
|
"treefmt-nix": "treefmt-nix_4",
|
||||||
"vicinae": "vicinae",
|
"vicinae": "vicinae",
|
||||||
"vicinae-extensions": "vicinae-extensions"
|
"vicinae-extensions": "vicinae-extensions"
|
||||||
@@ -1519,11 +1516,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787454509,
|
"lastModified": 1789889921,
|
||||||
"narHash": "sha256-r4LDUF+zmJnkftvCVkCrUhSJazsf6EVJF+V2l4/MYbI=",
|
"narHash": "sha256-aL/ogiN7qZCGeNovS1f9hX73jwYIKb4Pcq6AZm57WtY=",
|
||||||
"owner": "oxalica",
|
"owner": "oxalica",
|
||||||
"repo": "rust-overlay",
|
"repo": "rust-overlay",
|
||||||
"rev": "f60c1b57ff805a46b5175c76fc981fb4f81efbcc",
|
"rev": "1fb104a12a8667045559b2575d6d448ae2fbd99b",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1534,11 +1531,11 @@
|
|||||||
},
|
},
|
||||||
"services-flake": {
|
"services-flake": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787074068,
|
"lastModified": 1790475157,
|
||||||
"narHash": "sha256-z0CqDCjs+xU/Yw2/VkS8Mz7qzw4AsZ+AMwEMmqSSKh0=",
|
"narHash": "sha256-CUvrxb5wdBRcpwi89yfgw4IUqhBjjt+BUtsNQVM+5jM=",
|
||||||
"owner": "juspay",
|
"owner": "juspay",
|
||||||
"repo": "services-flake",
|
"repo": "services-flake",
|
||||||
"rev": "4f56c8f1cbd09c774a491a47acd3605a6eb7adfa",
|
"rev": "aa72532e193ee212055df9e1c3eb07aa0ccafabb",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1550,11 +1547,11 @@
|
|||||||
"skills": {
|
"skills": {
|
||||||
"flake": false,
|
"flake": false,
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787581197,
|
"lastModified": 1789726349,
|
||||||
"narHash": "sha256-N5tpUIHO2VFeJntBTl6/VLDIVpqoshwFxNJlfXXUwsQ=",
|
"narHash": "sha256-L3CpIT2DeI+fUFl9fcygojtQo2DzEen69rMD1XqR1vM=",
|
||||||
"owner": "mattpocock",
|
"owner": "mattpocock",
|
||||||
"repo": "skills",
|
"repo": "skills",
|
||||||
"rev": "6654f6b60cd9d5be8b54c6fafe44346dabeb3b76",
|
"rev": "c55ee46073ed923f86ce59a5eb3b6d895095d1b7",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1570,11 +1567,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1786629091,
|
"lastModified": 1790498116,
|
||||||
"narHash": "sha256-gkig4nPi1CWc4Z50GBsjE4ygSE7hMpl/TwID2an2Cck=",
|
"narHash": "sha256-rs9meAYxW3zzrh43yaW7htrqCD+X9+pupDPHN86fumI=",
|
||||||
"owner": "Mic92",
|
"owner": "Mic92",
|
||||||
"repo": "sops-nix",
|
"repo": "sops-nix",
|
||||||
"rev": "a8627b21b9107c5711c96b84f32a9a4b3d45295f",
|
"rev": "5efb5a6f4f5ab192817d28557dd4d650fa14d866",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1618,18 +1615,18 @@
|
|||||||
"nixpkgs"
|
"nixpkgs"
|
||||||
],
|
],
|
||||||
"nur": "nur",
|
"nur": "nur",
|
||||||
"systems": "systems_8",
|
"systems": "systems_7",
|
||||||
"tinted-kitty": "tinted-kitty",
|
"tinted-kitty": "tinted-kitty",
|
||||||
"tinted-schemes": "tinted-schemes",
|
"tinted-schemes": "tinted-schemes",
|
||||||
"tinted-tmux": "tinted-tmux",
|
"tinted-tmux": "tinted-tmux",
|
||||||
"tinted-zed": "tinted-zed"
|
"tinted-zed": "tinted-zed"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787771653,
|
"lastModified": 1790451534,
|
||||||
"narHash": "sha256-DkkJSBOXWV/mja5Vy8az5g1KpZlsbUwlmH0BsQhowaQ=",
|
"narHash": "sha256-5J4zQ0mmCsd2SS+sOKdzXrngofQdtube3VoHSENz4zE=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "stylix",
|
"repo": "stylix",
|
||||||
"rev": "5e3809851f486e7fc7e84b40f174c74b60ecc784",
|
"rev": "fb28acd59e2ac1984ec84fa496599d6b4bf3e690",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1668,21 +1665,6 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"systems_11": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1681028828,
|
|
||||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"repo": "default",
|
|
||||||
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"repo": "default",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"systems_2": {
|
"systems_2": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1681028828,
|
"lastModified": 1681028828,
|
||||||
@@ -1714,6 +1696,7 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"systems_4": {
|
"systems_4": {
|
||||||
|
"flake": false,
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1681028828,
|
"lastModified": 1681028828,
|
||||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||||
@@ -1729,7 +1712,6 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"systems_5": {
|
"systems_5": {
|
||||||
"flake": false,
|
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1681028828,
|
"lastModified": 1681028828,
|
||||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||||
@@ -1760,21 +1742,6 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"systems_7": {
|
"systems_7": {
|
||||||
"locked": {
|
|
||||||
"lastModified": 1681028828,
|
|
||||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"repo": "default",
|
|
||||||
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"repo": "default",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"systems_8": {
|
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1774449309,
|
"lastModified": 1774449309,
|
||||||
"narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=",
|
"narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=",
|
||||||
@@ -1790,6 +1757,21 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"systems_8": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1681028828,
|
||||||
|
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||||
|
"owner": "nix-systems",
|
||||||
|
"repo": "default",
|
||||||
|
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "nix-systems",
|
||||||
|
"repo": "default",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
"systems_9": {
|
"systems_9": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1681028828,
|
"lastModified": 1681028828,
|
||||||
@@ -1937,7 +1919,7 @@
|
|||||||
},
|
},
|
||||||
"treefmt-nix_4": {
|
"treefmt-nix_4": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": "nixpkgs_13"
|
"nixpkgs": "nixpkgs_14"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1786901030,
|
"lastModified": 1786901030,
|
||||||
@@ -1953,37 +1935,19 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"utils": {
|
|
||||||
"inputs": {
|
|
||||||
"systems": "systems_4"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1731533236,
|
|
||||||
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"vicinae": {
|
"vicinae": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": "nixpkgs_14",
|
"nixpkgs": "nixpkgs_15",
|
||||||
"numen": "numen",
|
"numen": "numen",
|
||||||
"soulver-cpp": "soulver-cpp",
|
"soulver-cpp": "soulver-cpp",
|
||||||
"systems": "systems_10"
|
"systems": "systems_9"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1787956866,
|
"lastModified": 1790526610,
|
||||||
"narHash": "sha256-SCFAyDbNIXcFRGw0nx2yVY47hMSHzMFAQOsUXdJJ6sc=",
|
"narHash": "sha256-rmgEQklUdHJ4wLCX5sa1rVkeiu2atFWJ3likgVw/5gA=",
|
||||||
"owner": "vicinaehq",
|
"owner": "vicinaehq",
|
||||||
"repo": "vicinae",
|
"repo": "vicinae",
|
||||||
"rev": "47857b0b4af6b269ddbc5f34b661f0eb9d9bdeb5",
|
"rev": "8d80bf6011de177a19f1b5f1243ec505f441b7e7",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -1994,19 +1958,19 @@
|
|||||||
},
|
},
|
||||||
"vicinae-extensions": {
|
"vicinae-extensions": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"flake-compat": "flake-compat_7",
|
"flake-compat": "flake-compat_6",
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
"nixpkgs"
|
"nixpkgs"
|
||||||
],
|
],
|
||||||
"systems": "systems_11",
|
"systems": "systems_10",
|
||||||
"vicinae": "vicinae_2"
|
"vicinae": "vicinae_2"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1788004886,
|
"lastModified": 1790242820,
|
||||||
"narHash": "sha256-YVr/SysyzG2lkSpacrEC/Mo7XdUYdKu5vX2AUcqAzpQ=",
|
"narHash": "sha256-xG2Nvdhl+lcguYzkAHf6RkHQpM8c3rbN0NDHUiwT4CA=",
|
||||||
"owner": "vicinaehq",
|
"owner": "vicinaehq",
|
||||||
"repo": "extensions",
|
"repo": "extensions",
|
||||||
"rev": "de926d2e94ff4423dc04068eb2b6fc8d501f3b74",
|
"rev": "def646b3655e13759d2b0a7b9d605f55fe83a5f7",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -2110,11 +2074,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1784080626,
|
"lastModified": 1788977680,
|
||||||
"narHash": "sha256-Hvnmnuu0VpHiZl+8z+UkMoxC7JZJvRYBqu2Asb0ZJOE=",
|
"narHash": "sha256-3vgICcen5N2oAlQrijqJhxn8HEsnXASGPxQLJVYzX0Q=",
|
||||||
"owner": "jcollie",
|
"owner": "jcollie",
|
||||||
"repo": "zon2nix",
|
"repo": "zon2nix",
|
||||||
"rev": "776b5f6864a607c141d7966421b433fa1657ba9a",
|
"rev": "7b9c43312de08e176097b8c8920f0dd1a46982be",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
|
|||||||
@@ -60,11 +60,6 @@
|
|||||||
inputs.nixpkgs.follows = "nixpkgs";
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
};
|
};
|
||||||
|
|
||||||
deploy-rs = {
|
|
||||||
url = "github:serokell/deploy-rs";
|
|
||||||
inputs.nixpkgs.follows = "nixpkgs";
|
|
||||||
};
|
|
||||||
|
|
||||||
# Disk management
|
# Disk management
|
||||||
disko = {
|
disko = {
|
||||||
url = "github:nix-community/disko";
|
url = "github:nix-community/disko";
|
||||||
@@ -119,6 +114,7 @@
|
|||||||
|
|
||||||
nani-translate-linux.url = "git+https://github.com/zunoser/nani-translate-linux.git";
|
nani-translate-linux.url = "git+https://github.com/zunoser/nani-translate-linux.git";
|
||||||
|
|
||||||
|
containerlab.url = "github:srl-labs/containerlab";
|
||||||
};
|
};
|
||||||
|
|
||||||
outputs =
|
outputs =
|
||||||
|
|||||||
@@ -1,6 +1,5 @@
|
|||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
./deploy.nix
|
|
||||||
./formatter.nix
|
./formatter.nix
|
||||||
./git-hooks.nix
|
./git-hooks.nix
|
||||||
./registry.nix
|
./registry.nix
|
||||||
|
|||||||
@@ -1,28 +0,0 @@
|
|||||||
{
|
|
||||||
inputs,
|
|
||||||
self,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
{
|
|
||||||
flake.deploy = {
|
|
||||||
nodes.nix-builder = {
|
|
||||||
hostname = "nix-builder";
|
|
||||||
sshUser = "moons";
|
|
||||||
user = "root";
|
|
||||||
|
|
||||||
interactiveSudo = true;
|
|
||||||
remoteBuild = true;
|
|
||||||
autoRollback = true;
|
|
||||||
magicRollback = true;
|
|
||||||
|
|
||||||
profiles.system.path = inputs.deploy-rs.lib.x86_64-linux.activate.nixos self.nixosConfigurations.nix-builder;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
perSystem =
|
|
||||||
{ system, ... }:
|
|
||||||
{
|
|
||||||
apps.deploy = inputs.deploy-rs.apps.${system}.default;
|
|
||||||
checks = inputs.deploy-rs.lib.${system}.deployChecks self.deploy;
|
|
||||||
};
|
|
||||||
}
|
|
||||||
+35
-3
@@ -7,14 +7,43 @@
|
|||||||
|
|
||||||
profiles = [
|
profiles = [
|
||||||
"base"
|
"base"
|
||||||
"interface.cli"
|
"interface.minimal"
|
||||||
"networking.tailscale-client"
|
|
||||||
"platform.vm"
|
"platform.vm"
|
||||||
"workload.nix-builder"
|
|
||||||
"workload.remote-access"
|
"workload.remote-access"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
ops = {
|
||||||
|
system = "x86_64-linux";
|
||||||
|
stateVersion = "26.05";
|
||||||
|
user = "moons";
|
||||||
|
path = ./ops;
|
||||||
|
|
||||||
|
profiles = [
|
||||||
|
"base"
|
||||||
|
"interface.minimal"
|
||||||
|
"platform.vm"
|
||||||
|
"workload.remote-access"
|
||||||
|
"workload.deploy-rs-target"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
netsrv-01 = {
|
||||||
|
system = "x86_64-linux";
|
||||||
|
stateVersion = "26.05";
|
||||||
|
user = "moons";
|
||||||
|
path = ./netsrv-01;
|
||||||
|
|
||||||
|
profiles = [
|
||||||
|
"base"
|
||||||
|
"interface.minimal"
|
||||||
|
"platform.vm"
|
||||||
|
"workload.remote-access"
|
||||||
|
"workload.deploy-rs-target"
|
||||||
|
"workload.server"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
installer = {
|
installer = {
|
||||||
system = "x86_64-linux";
|
system = "x86_64-linux";
|
||||||
stateVersion = "26.05";
|
stateVersion = "26.05";
|
||||||
@@ -62,6 +91,7 @@
|
|||||||
"security.tpm-storage"
|
"security.tpm-storage"
|
||||||
"workload.development"
|
"workload.development"
|
||||||
"workload.game"
|
"workload.game"
|
||||||
|
"workload.network-lab"
|
||||||
"workload.personal"
|
"workload.personal"
|
||||||
];
|
];
|
||||||
|
|
||||||
@@ -87,7 +117,9 @@
|
|||||||
"workload.development"
|
"workload.development"
|
||||||
"workload.game"
|
"workload.game"
|
||||||
"workload.machine-learning"
|
"workload.machine-learning"
|
||||||
|
"workload.network-lab"
|
||||||
"workload.personal"
|
"workload.personal"
|
||||||
|
"workload.photography"
|
||||||
"workload.camera"
|
"workload.camera"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|||||||
+17
-23
@@ -76,6 +76,12 @@
|
|||||||
║ ║
|
║ ║
|
||||||
║ Installation Workflow: ║
|
║ Installation Workflow: ║
|
||||||
║ ║
|
║ ║
|
||||||
|
║ Choose a guide after cloning: ║
|
||||||
|
║ Simple: docs/install-simple.md ║
|
||||||
|
║ SOPS + LUKS: docs/install.md ║
|
||||||
|
║ ║
|
||||||
|
║ The workflow below is for SOPS + LUKS: ║
|
||||||
|
║ ║
|
||||||
║ 1. Clone dotfiles: ║
|
║ 1. Clone dotfiles: ║
|
||||||
║ git clone git@github.com:moons-14/dotfiles.git ~/dotfiles║
|
║ git clone git@github.com:moons-14/dotfiles.git ~/dotfiles║
|
||||||
║ ║
|
║ ║
|
||||||
@@ -103,36 +109,24 @@
|
|||||||
║ # See hosts/x1g13/disko.nix for reference ║
|
║ # See hosts/x1g13/disko.nix for reference ║
|
||||||
║ ║
|
║ ║
|
||||||
║ 7. Partition disk with disko: ║
|
║ 7. Partition disk with disko: ║
|
||||||
║ nix run github:nix-community/disko -- \ ║
|
║ disko --mode destroy,format,mount \ ║
|
||||||
║ --mode disko hosts/<host>/disko.nix ║
|
║ hosts/<host>/disko.nix ║
|
||||||
║ ║
|
║ ║
|
||||||
║ 8. Copy host key to installed system: ║
|
║ 8. Generate hardware configuration: ║
|
||||||
|
║ nixos-generate-config --no-filesystems --root /mnt \ ║
|
||||||
|
║ --show-hardware-config > \ ║
|
||||||
|
║ ~/dotfiles/hosts/<host>/hardware-configuration.nix ║
|
||||||
|
║ # Import hardware-configuration.nix and disko.nix ║
|
||||||
|
║ # from hosts/<host>/nixos.nix ║
|
||||||
|
║ ║
|
||||||
|
║ 9. Copy host key to installed system: ║
|
||||||
║ mkdir -p /mnt/etc/ssh ║
|
║ mkdir -p /mnt/etc/ssh ║
|
||||||
║ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ ║
|
║ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ ║
|
||||||
║ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ║
|
║ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ║
|
||||||
║ ║
|
║ ║
|
||||||
║ 9. Install NixOS: ║
|
║ 10. Install NixOS: ║
|
||||||
║ nixos-install --flake ~/dotfiles#<host> ║
|
║ nixos-install --flake ~/dotfiles#<host> ║
|
||||||
║ ║
|
║ ║
|
||||||
║ Disko Configuration Examples: ║
|
|
||||||
║ ║
|
|
||||||
║ Simple (no encryption): ║
|
|
||||||
║ disko.devices.disk.main = { ║
|
|
||||||
║ type = "disk"; ║
|
|
||||||
║ device = "/dev/sda"; ║
|
|
||||||
║ content = { ║
|
|
||||||
║ type = "gpt"; ║
|
|
||||||
║ partitions = { ║
|
|
||||||
║ ESP = { size = "512M"; type = "EF00"; ║
|
|
||||||
║ content = { type = "filesystem"; ║
|
|
||||||
║ format = "vfat"; mountpoint = "/boot"; }; }; ║
|
|
||||||
║ root = { size = "100%"; ║
|
|
||||||
║ content = { type = "filesystem"; ║
|
|
||||||
║ format = "ext4"; mountpoint = "/"; }; }; ║
|
|
||||||
║ }; ║
|
|
||||||
║ }; ║
|
|
||||||
║ }; ║
|
|
||||||
║ ║
|
|
||||||
║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║
|
║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║
|
||||||
║ - Use partuuid for device path ║
|
║ - Use partuuid for device path ║
|
||||||
║ - Set askPassword = true for LUKS ║
|
║ - Set askPassword = true for LUKS ║
|
||||||
|
|||||||
@@ -0,0 +1,30 @@
|
|||||||
|
_: {
|
||||||
|
disko.enableConfig = true;
|
||||||
|
|
||||||
|
disko.devices.disk.main = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
ESP = {
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
root = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
# QEMU hardware baseline. Replace this with the output of
|
||||||
|
# `nixos-generate-config` after provisioning the VM if its hardware differs.
|
||||||
|
{
|
||||||
|
lib,
|
||||||
|
modulesPath,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
(modulesPath + "/profiles/qemu-guest.nix")
|
||||||
|
];
|
||||||
|
|
||||||
|
boot.initrd.availableKernelModules = [
|
||||||
|
"ata_piix"
|
||||||
|
"uhci_hcd"
|
||||||
|
"virtio_pci"
|
||||||
|
"virtio_scsi"
|
||||||
|
"sd_mod"
|
||||||
|
"sr_mod"
|
||||||
|
];
|
||||||
|
boot.initrd.kernelModules = [ ];
|
||||||
|
boot.kernelModules = [ ];
|
||||||
|
boot.extraModulePackages = [ ];
|
||||||
|
|
||||||
|
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||||
|
}
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
{
|
||||||
|
networking = {
|
||||||
|
interfaces = {
|
||||||
|
ens18 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.65.11";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens19 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.66.10";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens20 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.77.21";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
defaultGateway = {
|
||||||
|
address = "10.50.66.1";
|
||||||
|
interface = "ens19";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{
|
||||||
|
imports = [
|
||||||
|
./hardware-configuration.nix
|
||||||
|
./disko.nix
|
||||||
|
./networking.nix
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -1,101 +0,0 @@
|
|||||||
# nix-builder bootstrap
|
|
||||||
|
|
||||||
The host configuration can be built before its cache signing secret exists.
|
|
||||||
Harmonia's socket remains stopped until SOPS installs the signing key at
|
|
||||||
`/run/secrets/harmonia/signing-key`.
|
|
||||||
|
|
||||||
## Proxmox storage layout
|
|
||||||
|
|
||||||
The host configuration expects three filesystems. Keep the build scratch space
|
|
||||||
separate from the store so a large build cannot fill the root filesystem.
|
|
||||||
|
|
||||||
| Mount point | Suggested size | Contents |
|
|
||||||
| -------------------- | -------------- | ------------------------------- |
|
|
||||||
| `/` | 48 GiB | NixOS and mutable system state |
|
|
||||||
| `/var/lib/nix-build` | 192 GiB | Disposable build scratch space |
|
|
||||||
| `/nix/store` | 1 TiB | Fleet closures and binary cache |
|
|
||||||
|
|
||||||
The build-server policy starts emergency store GC below 64 GiB free and aims
|
|
||||||
for 128 GiB free. Persistent roots under `/var/lib/nix-fleet/roots` protect the
|
|
||||||
latest fleet builds from that GC. It also limits Nix to two concurrent
|
|
||||||
derivations while allowing each derivation to use every vCPU assigned to the
|
|
||||||
VM.
|
|
||||||
|
|
||||||
For the two dedicated ext4 data filesystems, remove the default root-reserved
|
|
||||||
blocks once after formatting; keep the root filesystem's reserve intact:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
sudo tune2fs -m 0 /dev/disk/by-label/nix-build
|
|
||||||
sudo tune2fs -m 0 /dev/disk/by-label/nix-store
|
|
||||||
```
|
|
||||||
|
|
||||||
## Initial deployment
|
|
||||||
|
|
||||||
Once the VM is reachable as `moons@nix-builder`, deploy it from the repository:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
nix run .#deploy -- .#nix-builder
|
|
||||||
```
|
|
||||||
|
|
||||||
deploy-rs uses the target's `ssh-ng` store, so the system closure is built on
|
|
||||||
the builder rather than copied from the laptop. Automatic and magic rollback
|
|
||||||
remain enabled.
|
|
||||||
|
|
||||||
## Add the host SOPS recipient
|
|
||||||
|
|
||||||
After the VM has a stable SSH host key, derive its age recipient:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
ssh-keyscan -t ed25519 nix-builder 2>/dev/null | ssh-to-age
|
|
||||||
```
|
|
||||||
|
|
||||||
Add the recipient to `.sops.yaml` and add a creation rule for
|
|
||||||
`secrets/hosts/nix-builder/*.yaml`. The admin YubiKey recipient should remain in
|
|
||||||
the same key group for recovery.
|
|
||||||
|
|
||||||
## Generate the cache signing key
|
|
||||||
|
|
||||||
Run this on a trusted Nix machine, preferably with the temporary files on a
|
|
||||||
tmpfs:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
nix-store --generate-binary-cache-key \
|
|
||||||
cache.app.homelabs.run-1 \
|
|
||||||
harmonia.private \
|
|
||||||
harmonia.public
|
|
||||||
```
|
|
||||||
|
|
||||||
Create `secrets/hosts/nix-builder/system.yaml` with SOPS and store the complete
|
|
||||||
contents of `harmonia.private` at `harmonia.signing-key`:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
harmonia:
|
|
||||||
signing-key: cache.app.homelabs.run-1:REDACTED
|
|
||||||
```
|
|
||||||
|
|
||||||
Copy the complete contents of `harmonia.public` to
|
|
||||||
`modules/systems/nix/homelab-cache/public-key`. The private plaintext file must
|
|
||||||
not be committed or retained.
|
|
||||||
|
|
||||||
After committing both encrypted/public files, select
|
|
||||||
`networking.homelab-cache-client` on each client host.
|
|
||||||
|
|
||||||
Redeploy the builder and verify the cache after installing the secret:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
nix run .#deploy -- .#nix-builder
|
|
||||||
curl --fail http://nix-builder:5000/nix-cache-info
|
|
||||||
```
|
|
||||||
|
|
||||||
## Normal operation
|
|
||||||
|
|
||||||
Run `fleet-build` on the builder to build and root every NixOS host, or pass a
|
|
||||||
list of host names to build only those hosts. Run `fleet-deploy` with the normal
|
|
||||||
deploy-rs target syntax when additional fleet nodes have been added to
|
|
||||||
`flake/deploy.nix`:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
fleet-build
|
|
||||||
fleet-build x1g13 galleria
|
|
||||||
fleet-deploy .#nix-builder
|
|
||||||
```
|
|
||||||
@@ -0,0 +1,66 @@
|
|||||||
|
_:
|
||||||
|
let
|
||||||
|
osDisk = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
disko.enableConfig = true;
|
||||||
|
|
||||||
|
# The VM disks already contain live filesystems. Model each existing
|
||||||
|
# filesystem without giving Disko ownership of their partitioning or data.
|
||||||
|
disko.devices.disk = {
|
||||||
|
boot = {
|
||||||
|
type = "disk";
|
||||||
|
device = "${osDisk}-part1";
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
mountOptions = [ "umask=0077" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
root = {
|
||||||
|
type = "disk";
|
||||||
|
device = "${osDisk}-part2";
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
nix-build = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi1";
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/var/lib/nix-build";
|
||||||
|
mountOptions = [ "noatime" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
nix-store = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi2";
|
||||||
|
destroy = false;
|
||||||
|
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/nix/store";
|
||||||
|
mountOptions = [ "noatime" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
fileSystems."/nix/store".neededForBoot = true;
|
||||||
|
nix.settings.build-dir = "/var/lib/nix-build";
|
||||||
|
services.fstrim.enable = true;
|
||||||
|
}
|
||||||
@@ -1,25 +0,0 @@
|
|||||||
{
|
|
||||||
fileSystems."/nix/store" = {
|
|
||||||
device = "/dev/disk/by-label/nix-store";
|
|
||||||
fsType = "ext4";
|
|
||||||
|
|
||||||
options = [
|
|
||||||
"noatime"
|
|
||||||
];
|
|
||||||
|
|
||||||
neededForBoot = true;
|
|
||||||
};
|
|
||||||
|
|
||||||
fileSystems."/var/lib/nix-build" = {
|
|
||||||
device = "/dev/disk/by-label/nix-build";
|
|
||||||
fsType = "ext4";
|
|
||||||
|
|
||||||
options = [
|
|
||||||
"noatime"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
nix.settings.build-dir = "/var/lib/nix-build";
|
|
||||||
|
|
||||||
services.fstrim.enable = true;
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
{
|
||||||
|
config,
|
||||||
|
pkgs,
|
||||||
|
primaryUser,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
let
|
||||||
|
homeDirectory = "/home/${primaryUser}";
|
||||||
|
fleetDirectory = "${homeDirectory}/srv/nix-fleet";
|
||||||
|
stateDirectory = "/var/lib/nix-fleet";
|
||||||
|
sourceDirectory = "${stateDirectory}/source";
|
||||||
|
|
||||||
|
git = "${pkgs.git}/bin/git";
|
||||||
|
nix = "${config.nix.package}/bin/nix";
|
||||||
|
rsync = "${pkgs.rsync}/bin/rsync";
|
||||||
|
|
||||||
|
cleanCheckoutConditions = [
|
||||||
|
"${git} -C ${fleetDirectory} diff --quiet"
|
||||||
|
"${git} -C ${fleetDirectory} diff --cached --quiet"
|
||||||
|
];
|
||||||
|
in
|
||||||
|
{
|
||||||
|
systemd.services.nix-fleet-converge = {
|
||||||
|
description = "Update inputs, build the fleet, and deploy changed hosts";
|
||||||
|
wants = [ "network-online.target" ];
|
||||||
|
after = [ "network-online.target" ];
|
||||||
|
|
||||||
|
environment = {
|
||||||
|
HOME = homeDirectory;
|
||||||
|
NIX_CONFIG = ''
|
||||||
|
accept-flake-config = true
|
||||||
|
max-jobs = 4
|
||||||
|
cores = 3
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
serviceConfig = {
|
||||||
|
Type = "oneshot";
|
||||||
|
User = primaryUser;
|
||||||
|
Restart = "on-failure";
|
||||||
|
RestartSec = "5min";
|
||||||
|
StateDirectory = "nix-fleet";
|
||||||
|
StateDirectoryMode = "0750";
|
||||||
|
WorkingDirectory = stateDirectory;
|
||||||
|
UMask = "0077";
|
||||||
|
ExecCondition = cleanCheckoutConditions;
|
||||||
|
EnvironmentFile = "${fleetDirectory}/.env";
|
||||||
|
|
||||||
|
# Work in a disposable copy so updating the dotfiles lock never dirties
|
||||||
|
# the operator's nix-fleet checkout.
|
||||||
|
ExecStart = [
|
||||||
|
"${git} -C ${fleetDirectory} pull --ff-only"
|
||||||
|
"${rsync} --archive --delete --exclude=.git/ --exclude=.direnv/ --exclude=.env --exclude=result --exclude=result-* ${fleetDirectory}/ ${sourceDirectory}/"
|
||||||
|
"${nix} flake update --flake ${sourceDirectory} dotfiles"
|
||||||
|
"${nix} run ${sourceDirectory}#converge -- ${sourceDirectory} ${stateDirectory}"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
systemd.timers.nix-fleet-converge = {
|
||||||
|
description = "Periodically converge the NixOS fleet";
|
||||||
|
wantedBy = [ "timers.target" ];
|
||||||
|
timerConfig = {
|
||||||
|
OnBootSec = "2min";
|
||||||
|
OnUnitInactiveSec = "5min";
|
||||||
|
RandomizedDelaySec = "30s";
|
||||||
|
Persistent = true;
|
||||||
|
Unit = "nix-fleet-converge.service";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# Only an actual successful deployment touches gc-request. This starts the
|
||||||
|
# builder's root nh-clean unit; remote host stores are never cleaned here.
|
||||||
|
systemd.paths.nix-fleet-gc = {
|
||||||
|
description = "Garbage-collect superseded fleet builds on nix-builder";
|
||||||
|
wantedBy = [ "multi-user.target" ];
|
||||||
|
pathConfig = {
|
||||||
|
PathChanged = "${stateDirectory}/gc-request";
|
||||||
|
Unit = "nh-clean.service";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -20,20 +20,6 @@
|
|||||||
boot.kernelModules = [ ];
|
boot.kernelModules = [ ];
|
||||||
boot.extraModulePackages = [ ];
|
boot.extraModulePackages = [ ];
|
||||||
|
|
||||||
fileSystems."/" = {
|
|
||||||
device = "/dev/disk/by-uuid/49fc2e1c-7909-41cc-ac78-55b4d9a01e62";
|
|
||||||
fsType = "ext4";
|
|
||||||
};
|
|
||||||
|
|
||||||
fileSystems."/boot" = {
|
|
||||||
device = "/dev/disk/by-uuid/40D4-ABBE";
|
|
||||||
fsType = "vfat";
|
|
||||||
options = [
|
|
||||||
"fmask=0077"
|
|
||||||
"dmask=0077"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
swapDevices = [ ];
|
swapDevices = [ ];
|
||||||
|
|
||||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||||
|
|||||||
@@ -0,0 +1,37 @@
|
|||||||
|
{
|
||||||
|
lib,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
|
||||||
|
nix.settings = {
|
||||||
|
build-dir = "/var/lib/nix-build";
|
||||||
|
|
||||||
|
secret-key-files = [
|
||||||
|
"/var/lib/secrets/nix-cache-signing-key"
|
||||||
|
];
|
||||||
|
|
||||||
|
auto-optimise-store = lib.mkForce false;
|
||||||
|
keep-outputs = false;
|
||||||
|
keep-derivations = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
services.harmonia.cache = {
|
||||||
|
enable = true;
|
||||||
|
|
||||||
|
signKeyPaths = [
|
||||||
|
"/var/lib/secrets/nix-cache-signing-key"
|
||||||
|
];
|
||||||
|
|
||||||
|
settings = {
|
||||||
|
bind = "[::]:5000";
|
||||||
|
priority = 30;
|
||||||
|
workers = 4;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
networking.firewall.allowedTCPPorts = [
|
||||||
|
5000
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
{
|
||||||
|
networking = {
|
||||||
|
interfaces = {
|
||||||
|
ens18 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.65.10";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens19 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.77.10";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens20 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.68.10";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
defaultGateway = {
|
||||||
|
address = "10.50.68.1";
|
||||||
|
interface = "ens20";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -1,19 +1,9 @@
|
|||||||
{ lib, ... }:
|
|
||||||
let
|
|
||||||
hostSecrets = ../../secrets/hosts/nix-builder/system.yaml;
|
|
||||||
in
|
|
||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
./filesystem.nix
|
./fleet-automation.nix
|
||||||
|
./disko.nix
|
||||||
./hardware-configuration.nix
|
./hardware-configuration.nix
|
||||||
|
./harmonia.nix
|
||||||
|
./networking.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
sops.secrets = lib.mkIf (builtins.pathExists hostSecrets) {
|
|
||||||
"harmonia/signing-key" = {
|
|
||||||
sopsFile = hostSecrets;
|
|
||||||
restartUnits = [ "harmonia.service" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
networking.firewall.interfaces."tailscale0".allowedTCPPorts = [ 5000 ];
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,36 +0,0 @@
|
|||||||
# Do not modify this file! It was generated by `nixos-generate-config` and may
|
|
||||||
# be overwritten by future invocations.
|
|
||||||
{ lib, modulesPath, ... }:
|
|
||||||
{
|
|
||||||
imports = [ (modulesPath + "/profiles/qemu-guest.nix") ];
|
|
||||||
|
|
||||||
boot.initrd.availableKernelModules = [
|
|
||||||
"ata_piix"
|
|
||||||
"uhci_hcd"
|
|
||||||
"virtio_pci"
|
|
||||||
"virtio_scsi"
|
|
||||||
"sd_mod"
|
|
||||||
"sr_mod"
|
|
||||||
];
|
|
||||||
boot.initrd.kernelModules = [ ];
|
|
||||||
boot.kernelModules = [ ];
|
|
||||||
boot.extraModulePackages = [ ];
|
|
||||||
|
|
||||||
fileSystems."/" = {
|
|
||||||
device = "/dev/disk/by-uuid/8f0eaec6-5dc9-4821-aa8d-fb6809b5a5bf";
|
|
||||||
fsType = "ext4";
|
|
||||||
};
|
|
||||||
|
|
||||||
fileSystems."/boot" = {
|
|
||||||
device = "/dev/disk/by-uuid/201C-961B";
|
|
||||||
fsType = "vfat";
|
|
||||||
options = [
|
|
||||||
"fmask=0077"
|
|
||||||
"dmask=0077"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
swapDevices = [ ];
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
|
||||||
}
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
{
|
|
||||||
imports = [ ./hardware-configuration.nix ];
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
_: {
|
||||||
|
disko.enableConfig = true;
|
||||||
|
|
||||||
|
disko.devices.disk.main = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
ESP = {
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
root = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||||
|
# and may be overwritten by future invocations. Please make changes
|
||||||
|
# to /etc/nixos/configuration.nix instead.
|
||||||
|
{
|
||||||
|
lib,
|
||||||
|
modulesPath,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
imports = [
|
||||||
|
(modulesPath + "/profiles/qemu-guest.nix")
|
||||||
|
];
|
||||||
|
|
||||||
|
boot.initrd.availableKernelModules = [
|
||||||
|
"ata_piix"
|
||||||
|
"uhci_hcd"
|
||||||
|
"virtio_pci"
|
||||||
|
"virtio_scsi"
|
||||||
|
"sd_mod"
|
||||||
|
"sr_mod"
|
||||||
|
];
|
||||||
|
boot.initrd.kernelModules = [ ];
|
||||||
|
boot.kernelModules = [ ];
|
||||||
|
boot.extraModulePackages = [ ];
|
||||||
|
|
||||||
|
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
||||||
|
}
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
{
|
||||||
|
networking = {
|
||||||
|
interfaces = {
|
||||||
|
ens18 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.65.100";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens19 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.80.10";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
ens20 = {
|
||||||
|
useDHCP = false;
|
||||||
|
ipv4.addresses = [
|
||||||
|
{
|
||||||
|
address = "10.50.77.20";
|
||||||
|
prefixLength = 24;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
defaultGateway = {
|
||||||
|
address = "10.50.80.1";
|
||||||
|
interface = "ens19";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{
|
||||||
|
imports = [
|
||||||
|
./hardware-configuration.nix
|
||||||
|
./networking.nix
|
||||||
|
./disko.nix
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
{ inputs, ... }:
|
||||||
|
{
|
||||||
|
description = "Container-based networking labs";
|
||||||
|
|
||||||
|
includes = [ "services.docker" ];
|
||||||
|
|
||||||
|
imports.nixos = [ inputs.containerlab.nixosModules.default ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
pkgs,
|
||||||
|
primaryUser,
|
||||||
|
}:
|
||||||
|
{
|
||||||
|
programs.containerlab.enable = true;
|
||||||
|
|
||||||
|
users.users.${primaryUser}.extraGroups = [ "clab_admins" ];
|
||||||
|
|
||||||
|
programs.containerlab.package =
|
||||||
|
inputs.containerlab.packages.${pkgs.stdenv.hostPlatform.system}.default.overrideAttrs
|
||||||
|
(_old: {
|
||||||
|
vendorHash = "sha256-xp6YIoqJdUu1zEzw7s7+lh8iGJD4THokF5NPbxLH6zc=";
|
||||||
|
});
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
osConfig,
|
||||||
|
pkgs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
unstable = import inputs.nixpkgs-unstable {
|
||||||
|
inherit (pkgs.stdenv.hostPlatform) system;
|
||||||
|
# Keep default CUDA targets so dependencies match the CUDA binary cache.
|
||||||
|
config = pkgs.config // {
|
||||||
|
cudaSupport = osConfig.my.hardwares.nvidia.enable;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
in
|
||||||
|
{
|
||||||
|
home.packages = [
|
||||||
|
(unstable.darktable.override {
|
||||||
|
withAi = true;
|
||||||
|
})
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -38,8 +38,6 @@ in
|
|||||||
|
|
||||||
ignores = [
|
ignores = [
|
||||||
".direnv/"
|
".direnv/"
|
||||||
".envrc"
|
|
||||||
"!.envrc.example"
|
|
||||||
];
|
];
|
||||||
|
|
||||||
signing = {
|
signing = {
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.htop ];
|
||||||
|
}
|
||||||
@@ -127,7 +127,6 @@ in
|
|||||||
(execute "W-C-j" "${lib.getExe' pkgs.xdg-utils "xdg-open"} naniapp://translate")
|
(execute "W-C-j" "${lib.getExe' pkgs.xdg-utils "xdg-open"} naniapp://translate")
|
||||||
(execute "W-space" "ghostty +toggle-quick-terminal")
|
(execute "W-space" "ghostty +toggle-quick-terminal")
|
||||||
(execute "W-p" "wdisplays")
|
(execute "W-p" "wdisplays")
|
||||||
(execute "W-z" "wl-find-cursor -c 0xCCFF453A -s 160 -d 1200")
|
|
||||||
|
|
||||||
# Function keys (sync with niri modules/applications/niri/home.nix)
|
# Function keys (sync with niri modules/applications/niri/home.nix)
|
||||||
(execute "XF86AudioRaiseVolume" "noctalia msg volume-up")
|
(execute "XF86AudioRaiseVolume" "noctalia msg volume-up")
|
||||||
|
|||||||
@@ -4,6 +4,5 @@
|
|||||||
includes = [
|
includes = [
|
||||||
"systems.wayland"
|
"systems.wayland"
|
||||||
"applications.screenshot"
|
"applications.screenshot"
|
||||||
"applications.wl-find-cursor"
|
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = [ pkgs.nano ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
{
|
||||||
|
description = "Sipeed NanoKVM-USB desktop client";
|
||||||
|
|
||||||
|
includes = [ "services.nanokvm-usb" ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
let
|
||||||
|
pname = "nanokvm-usb";
|
||||||
|
version = "1.1.4";
|
||||||
|
|
||||||
|
src = pkgs.fetchurl {
|
||||||
|
url = "https://github.com/sipeed/NanoKVM-USB/releases/download/v${version}/NanoKVM-USB-${version}-linux-x86_64.AppImage";
|
||||||
|
hash = "sha256-00MT4U2afv0qt3xFVhLr0SSmS2cLrKBlmfzqYEFuaVc=";
|
||||||
|
};
|
||||||
|
|
||||||
|
appimageContents = pkgs.appimageTools.extractType2 {
|
||||||
|
inherit pname src version;
|
||||||
|
};
|
||||||
|
|
||||||
|
nanokvm-usb = pkgs.appimageTools.wrapType2 {
|
||||||
|
inherit pname src version;
|
||||||
|
|
||||||
|
meta = {
|
||||||
|
description = "Sipeed NanoKVM-USB desktop client";
|
||||||
|
homepage = "https://github.com/sipeed/NanoKVM-USB";
|
||||||
|
license = pkgs.lib.licenses.gpl3Only;
|
||||||
|
platforms = [ "x86_64-linux" ];
|
||||||
|
mainProgram = "nanokvm-usb";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
desktopItem = pkgs.makeDesktopItem {
|
||||||
|
name = pname;
|
||||||
|
desktopName = "NanoKVM-USB";
|
||||||
|
comment = "NanoKVM-USB Desktop";
|
||||||
|
exec = "nanokvm-usb --no-sandbox %U";
|
||||||
|
icon = "${appimageContents}/nanokvm-usb.png";
|
||||||
|
categories = [ "Utility" ];
|
||||||
|
startupWMClass = "NanoKVM-USB";
|
||||||
|
};
|
||||||
|
in
|
||||||
|
{
|
||||||
|
environment.systemPackages = [
|
||||||
|
nanokvm-usb
|
||||||
|
desktopItem
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -139,19 +139,6 @@ in
|
|||||||
action.spawn = "wdisplays";
|
action.spawn = "wdisplays";
|
||||||
hotkey-overlay.title = "Display Settings: wdisplays";
|
hotkey-overlay.title = "Display Settings: wdisplays";
|
||||||
};
|
};
|
||||||
"Mod+Z" = {
|
|
||||||
action.spawn = [
|
|
||||||
"wl-find-cursor"
|
|
||||||
"-c"
|
|
||||||
"0xCCFF453A"
|
|
||||||
"-s"
|
|
||||||
"160"
|
|
||||||
"-d"
|
|
||||||
"1200"
|
|
||||||
];
|
|
||||||
hotkey-overlay.title = "Find Cursor";
|
|
||||||
};
|
|
||||||
|
|
||||||
# Function keys (sync with labwc modules/applications/labwc/home.nix)
|
# Function keys (sync with labwc modules/applications/labwc/home.nix)
|
||||||
"XF86AudioRaiseVolume".action.spawn = [
|
"XF86AudioRaiseVolume".action.spawn = [
|
||||||
"noctalia"
|
"noctalia"
|
||||||
|
|||||||
@@ -5,7 +5,6 @@
|
|||||||
includes = [
|
includes = [
|
||||||
"systems.wayland"
|
"systems.wayland"
|
||||||
"applications.screenshot"
|
"applications.screenshot"
|
||||||
"applications.wl-find-cursor"
|
|
||||||
];
|
];
|
||||||
|
|
||||||
imports = {
|
imports = {
|
||||||
|
|||||||
@@ -1,3 +0,0 @@
|
|||||||
{
|
|
||||||
description = "Fleet build and deploy command-line tools";
|
|
||||||
}
|
|
||||||
@@ -1,63 +0,0 @@
|
|||||||
{
|
|
||||||
inputs,
|
|
||||||
pkgs,
|
|
||||||
primaryUser,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
let
|
|
||||||
system = pkgs.stdenv.hostPlatform.system;
|
|
||||||
deployRs = inputs.deploy-rs.packages.${system}.default;
|
|
||||||
|
|
||||||
fleetBuild = pkgs.writeShellApplication {
|
|
||||||
name = "fleet-build";
|
|
||||||
runtimeInputs = [
|
|
||||||
pkgs.jq
|
|
||||||
pkgs.nix
|
|
||||||
];
|
|
||||||
text = ''
|
|
||||||
flake_ref="''${FLAKE:-/home/${primaryUser}/dotfiles}"
|
|
||||||
|
|
||||||
if (( $# == 0 )); then
|
|
||||||
# Keep this pipeline inside command substitution so pipefail and
|
|
||||||
# writeShellApplication's errexit propagate evaluation failures.
|
|
||||||
host_lines="$(
|
|
||||||
nix eval --json "$flake_ref#nixosConfigurations" \
|
|
||||||
--apply 'configs: builtins.attrNames configs' |
|
|
||||||
jq -r '.[] | select(. != "installer")'
|
|
||||||
)"
|
|
||||||
if [[ -z "$host_lines" ]]; then
|
|
||||||
echo "No deployable NixOS hosts found in $flake_ref" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
mapfile -t hosts <<< "$host_lines"
|
|
||||||
else
|
|
||||||
hosts=("$@")
|
|
||||||
fi
|
|
||||||
|
|
||||||
for host in "''${hosts[@]}"; do
|
|
||||||
nix build \
|
|
||||||
--out-link "/var/lib/nix-fleet/roots/build/$host" \
|
|
||||||
"$flake_ref#nixosConfigurations.$host.config.system.build.toplevel"
|
|
||||||
done
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
fleetDeploy = pkgs.writeShellApplication {
|
|
||||||
name = "fleet-deploy";
|
|
||||||
runtimeInputs = [ deployRs ];
|
|
||||||
text = ''
|
|
||||||
cd "''${FLAKE:-/home/${primaryUser}/dotfiles}" || exit 1
|
|
||||||
|
|
||||||
exec deploy \
|
|
||||||
--keep-result \
|
|
||||||
--result-path /var/lib/nix-fleet/roots/deploy \
|
|
||||||
"$@"
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
in
|
|
||||||
{
|
|
||||||
environment.systemPackages = [
|
|
||||||
fleetBuild
|
|
||||||
fleetDeploy
|
|
||||||
];
|
|
||||||
}
|
|
||||||
@@ -13,10 +13,6 @@ lib.mkMerge [
|
|||||||
User = "git";
|
User = "git";
|
||||||
AddKeysToAgent = "no";
|
AddKeysToAgent = "no";
|
||||||
};
|
};
|
||||||
"*.sfc.wide.ad.jp" = {
|
|
||||||
identityFile = "~/.ssh/id_ed25519_sk_rk";
|
|
||||||
identitiesOnly = true;
|
|
||||||
};
|
|
||||||
"*" = {
|
"*" = {
|
||||||
AddKeysToAgent = "no";
|
AddKeysToAgent = "no";
|
||||||
SetEnv.TERM = "xterm-256color";
|
SetEnv.TERM = "xterm-256color";
|
||||||
@@ -31,5 +27,20 @@ lib.mkMerge [
|
|||||||
IdentityAgent %d/.1password/agent.sock
|
IdentityAgent %d/.1password/agent.sock
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|
||||||
|
home.activation.generateSshKey = {
|
||||||
|
after = [ "writeBoundary" ];
|
||||||
|
before = [ ];
|
||||||
|
data = ''
|
||||||
|
key="$HOME/.ssh/id_ed25519"
|
||||||
|
if [ ! -f "$key" ]; then
|
||||||
|
umask 077
|
||||||
|
mkdir -p "$HOME/.ssh"
|
||||||
|
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
|
||||||
|
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
|
||||||
|
echo "Generated SSH key at $key"
|
||||||
|
fi
|
||||||
|
'';
|
||||||
|
};
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|||||||
@@ -1,7 +0,0 @@
|
|||||||
{ inputs, pkgs, ... }:
|
|
||||||
let
|
|
||||||
unstable = inputs.nixpkgs-unstable.legacyPackages.${pkgs.stdenv.hostPlatform.system};
|
|
||||||
in
|
|
||||||
{
|
|
||||||
home.packages = [ unstable.wl-find-cursor ];
|
|
||||||
}
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
{
|
|
||||||
description = "Wayland cursor locator";
|
|
||||||
}
|
|
||||||
@@ -5,6 +5,7 @@
|
|||||||
"catppuccin"
|
"catppuccin"
|
||||||
"nix"
|
"nix"
|
||||||
"dockerfile"
|
"dockerfile"
|
||||||
|
"terraform"
|
||||||
];
|
];
|
||||||
mutableUserSettings = false;
|
mutableUserSettings = false;
|
||||||
mutableUserKeymaps = false;
|
mutableUserKeymaps = false;
|
||||||
|
|||||||
@@ -24,6 +24,7 @@ required on every supported host.
|
|||||||
| Profile | Supported host class |
|
| Profile | Supported host class |
|
||||||
| ------------------------------------ | --------------------------------------------- |
|
| ------------------------------------ | --------------------------------------------- |
|
||||||
| `base` | NixOS, macOS |
|
| `base` | NixOS, macOS |
|
||||||
|
| `interface.minimal` | NixOS, macOS with Home Manager |
|
||||||
| `interface.cli` | NixOS, macOS with Home Manager |
|
| `interface.cli` | NixOS, macOS with Home Manager |
|
||||||
| `interface.gui` | NixOS, macOS with Home Manager |
|
| `interface.gui` | NixOS, macOS with Home Manager |
|
||||||
| `interface.macos` | macOS |
|
| `interface.macos` | macOS |
|
||||||
@@ -36,15 +37,16 @@ required on every supported host.
|
|||||||
| `platform.laptop` | Physical NixOS laptop |
|
| `platform.laptop` | Physical NixOS laptop |
|
||||||
| `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS |
|
| `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS |
|
||||||
| `platform.vm` | UEFI QEMU NixOS guest with NFS client support |
|
| `platform.vm` | UEFI QEMU NixOS guest with NFS client support |
|
||||||
|
| `workload.deploy-rs-target` | NixOS |
|
||||||
| `workload.development` | NixOS, macOS with Home Manager |
|
| `workload.development` | NixOS, macOS with Home Manager |
|
||||||
| `workload.game` | NixOS, macOS |
|
| `workload.game` | NixOS, macOS |
|
||||||
| `workload.machine-learning` | NixOS with Home Manager |
|
| `workload.machine-learning` | NixOS with Home Manager |
|
||||||
| `workload.nix-builder` | NixOS central build and binary-cache VM |
|
| `workload.network-lab` | NixOS |
|
||||||
| `workload.personal` | NixOS, macOS with Home Manager |
|
| `workload.personal` | NixOS, macOS with Home Manager |
|
||||||
|
| `workload.photography` | NixOS with Home Manager |
|
||||||
| `workload.remote-access` | NixOS, macOS |
|
| `workload.remote-access` | NixOS, macOS |
|
||||||
| `workload.camera` | NixOS |
|
| `workload.camera` | NixOS |
|
||||||
| `workload.server` | NixOS, macOS with Home Manager |
|
| `workload.server` | NixOS, macOS with Home Manager |
|
||||||
| `networking.homelab-cache-client` | NixOS, macOS with access to nix-builder |
|
|
||||||
| `networking.tailscale-client` | NixOS, macOS |
|
| `networking.tailscale-client` | NixOS, macOS |
|
||||||
| `networking.tailscale-subnet-router` | NixOS |
|
| `networking.tailscale-subnet-router` | NixOS |
|
||||||
| `security.fingerprint` | NixOS, macOS |
|
| `security.fingerprint` | NixOS, macOS |
|
||||||
@@ -62,16 +64,30 @@ selects labwc. A daily-use macOS development machine can combine
|
|||||||
`interface.macos`, `workload.development`, and `workload.personal`. Hardware
|
`interface.macos`, `workload.development`, and `workload.personal`. Hardware
|
||||||
support does not implicitly select an interface or workload.
|
support does not implicitly select an interface or workload.
|
||||||
|
|
||||||
|
`platform.nixos` selects the shared network foundation and the clatd service.
|
||||||
|
VM, laptop, and desktop platform profiles inherit both.
|
||||||
|
|
||||||
|
`interface.minimal` provides SSH client access and key generation, Nano, htop,
|
||||||
|
btop, fastfetch, unzip, wget, Direnv, Git, GnuPG, nh, Zellij, and Zsh for remote
|
||||||
|
administration. `interface.cli` includes that baseline and adds the configured
|
||||||
|
Neovim, Yazi, and the remaining interactive command-line tools.
|
||||||
|
|
||||||
`workload.machine-learning` provides the Hugging Face Hub CLI for hosts used
|
`workload.machine-learning` provides the Hugging Face Hub CLI for hosts used
|
||||||
to download and publish machine learning models and datasets.
|
to download and publish machine learning models and datasets.
|
||||||
|
|
||||||
`workload.nix-builder` provides the central build policy, persistent fleet GC
|
`workload.network-lab` provides containerlab using its upstream NixOS module,
|
||||||
roots, deploy-rs tooling, SOPS integration, and Harmonia binary cache. Network
|
the Docker service, and the NanoKVM-USB desktop client with serial-port access.
|
||||||
reachability and remote shell access remain independent host selections.
|
It is selected by galleria and x1g13.
|
||||||
|
|
||||||
`networking.homelab-cache-client` adds the internal Harmonia substituter and
|
`workload.photography` provides darktable with AI support from the locked
|
||||||
its trusted public key. It requires the public key generated during
|
unstable package set. Its ONNX Runtime uses CUDA when the NVIDIA hardware unit
|
||||||
`hosts/nix-builder/README.md` bootstrap.
|
is enabled, and CPU inference otherwise. Keep the default CUDA capabilities
|
||||||
|
and forward compatibility to reuse the CUDA binary cache; these targets include
|
||||||
|
galleria's RTX 3060 Ti. OpenCL drivers remain owned by hardware units.
|
||||||
|
|
||||||
|
`workload.deploy-rs-target` enables OpenSSH and provisions the `nixdeploy`
|
||||||
|
service account with the narrowly scoped passwordless commands required for
|
||||||
|
deploy-rs activation and rollback confirmation.
|
||||||
|
|
||||||
`workload.personal` provides Pear Desktop on both NixOS and macOS. Home Manager
|
`workload.personal` provides Pear Desktop on both NixOS and macOS. Home Manager
|
||||||
enables performance improvements, synced lyrics, tracker blocking, the album
|
enables performance improvements, synced lyrics, tracker blocking, the album
|
||||||
|
|||||||
@@ -8,36 +8,21 @@
|
|||||||
dust
|
dust
|
||||||
eza
|
eza
|
||||||
fd
|
fd
|
||||||
fastfetch
|
|
||||||
fzf
|
fzf
|
||||||
htop
|
|
||||||
jq
|
jq
|
||||||
lsof
|
lsof
|
||||||
nurl
|
nurl
|
||||||
ripgrep
|
ripgrep
|
||||||
tio
|
tio
|
||||||
unrar
|
unrar
|
||||||
unzip
|
traceroute
|
||||||
wget
|
tcpdump
|
||||||
|
iw
|
||||||
|
nmap
|
||||||
]
|
]
|
||||||
++ lib.optionals stdenv.isLinux [
|
++ lib.optionals stdenv.isLinux [
|
||||||
lm_sensors
|
lm_sensors
|
||||||
psmisc
|
psmisc
|
||||||
strace
|
strace
|
||||||
];
|
];
|
||||||
|
|
||||||
home.activation.generateSshKey = {
|
|
||||||
after = [ "writeBoundary" ];
|
|
||||||
before = [ ];
|
|
||||||
data = ''
|
|
||||||
key="$HOME/.ssh/id_ed25519"
|
|
||||||
if [ ! -f "$key" ]; then
|
|
||||||
umask 077
|
|
||||||
mkdir -p "$HOME/.ssh"
|
|
||||||
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
|
|
||||||
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
|
|
||||||
echo "Generated SSH key at $key"
|
|
||||||
fi
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,17 +2,10 @@
|
|||||||
description = "Cross-platform interactive command-line environment";
|
description = "Cross-platform interactive command-line environment";
|
||||||
|
|
||||||
includes = [
|
includes = [
|
||||||
"applications.btop"
|
"profiles.interface.minimal"
|
||||||
"applications.direnv"
|
|
||||||
"applications.git"
|
|
||||||
"applications.gnupg"
|
|
||||||
"applications.nh"
|
|
||||||
"applications.nix-index"
|
"applications.nix-index"
|
||||||
"applications.ssh"
|
|
||||||
"applications.vim"
|
"applications.vim"
|
||||||
"applications.yazi"
|
"applications.yazi"
|
||||||
"applications.zellij"
|
|
||||||
"applications.zoxide"
|
"applications.zoxide"
|
||||||
"applications.zsh"
|
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
home.packages = with pkgs; [
|
||||||
|
fastfetch
|
||||||
|
unzip
|
||||||
|
wget
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
{
|
||||||
|
description = "Minimal cross-platform command-line environment for remote administration";
|
||||||
|
|
||||||
|
includes = [
|
||||||
|
"applications.btop"
|
||||||
|
"applications.direnv"
|
||||||
|
"applications.git"
|
||||||
|
"applications.gnupg"
|
||||||
|
"applications.htop"
|
||||||
|
"applications.nano"
|
||||||
|
"applications.nh"
|
||||||
|
"applications.ssh"
|
||||||
|
"applications.zellij"
|
||||||
|
"applications.zsh"
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
{
|
|
||||||
description = "Use the homelab Harmonia binary cache";
|
|
||||||
|
|
||||||
includes = [ "systems.nix.homelab-cache" ];
|
|
||||||
}
|
|
||||||
@@ -2,6 +2,7 @@
|
|||||||
description = "Foundation shared by all NixOS platforms";
|
description = "Foundation shared by all NixOS platforms";
|
||||||
|
|
||||||
includes = [
|
includes = [
|
||||||
|
"services.clatd"
|
||||||
"services.kmscon"
|
"services.kmscon"
|
||||||
"systems.disko"
|
"systems.disko"
|
||||||
"systems.boot.base"
|
"systems.boot.base"
|
||||||
|
|||||||
@@ -1,6 +0,0 @@
|
|||||||
{
|
|
||||||
sops.secrets."users/moons/hashedPassword" = {
|
|
||||||
sopsFile = ../../../secrets/common/system.yaml;
|
|
||||||
neededForUsers = true;
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
{
|
||||||
|
description = "NixOS deploy-rs deployment target";
|
||||||
|
|
||||||
|
includes = [
|
||||||
|
"services.openssh"
|
||||||
|
"users.nixdeploy"
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
{
|
||||||
|
description = "Network lab and hardware console environment";
|
||||||
|
|
||||||
|
includes = [
|
||||||
|
"applications.containerlab"
|
||||||
|
"applications.nanokvm-usb"
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
{
|
|
||||||
description = "Central Nix builder, deploy controller, and binary cache";
|
|
||||||
|
|
||||||
includes = [
|
|
||||||
"applications.nix-fleet"
|
|
||||||
"services.harmonia"
|
|
||||||
"systems.nix.build-server"
|
|
||||||
"systems.sops"
|
|
||||||
];
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
{
|
||||||
|
description = "RAW photo development and editing";
|
||||||
|
|
||||||
|
includes = [ "applications.darktable" ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
_: {
|
||||||
|
services.clatd.enable = true;
|
||||||
|
}
|
||||||
@@ -1,5 +1,7 @@
|
|||||||
{ primaryUser, ... }:
|
{ config, primaryUser, ... }:
|
||||||
{
|
{
|
||||||
|
hardware.nvidia-container-toolkit.enable = config.my.hardwares.nvidia.enable;
|
||||||
|
|
||||||
virtualisation.docker = {
|
virtualisation.docker = {
|
||||||
enable = true;
|
enable = true;
|
||||||
autoPrune = {
|
autoPrune = {
|
||||||
|
|||||||
@@ -1,3 +0,0 @@
|
|||||||
{
|
|
||||||
description = "Harmonia binary cache backed by the local Nix store";
|
|
||||||
}
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
let
|
|
||||||
signingKeyPath = "/run/secrets/harmonia/signing-key";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
services.harmonia.cache = {
|
|
||||||
enable = true;
|
|
||||||
signKeyPaths = [ signingKeyPath ];
|
|
||||||
|
|
||||||
settings = {
|
|
||||||
bind = "0.0.0.0:5000";
|
|
||||||
priority = 30;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
# Keep activation usable while the host-specific SOPS secret is bootstrapped.
|
|
||||||
# Once the secret exists, starting the socket also starts Harmonia on demand.
|
|
||||||
systemd.sockets.harmonia.unitConfig.ConditionPathExists = signingKeyPath;
|
|
||||||
systemd.services.harmonia.unitConfig.ConditionPathExists = signingKeyPath;
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{ primaryUser, ... }:
|
||||||
|
{
|
||||||
|
users.users.${primaryUser}.extraGroups = [ "dialout" ];
|
||||||
|
}
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
{
|
|
||||||
description = "Central Nix build server policy and persistent fleet roots";
|
|
||||||
}
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
{ primaryUser, ... }:
|
|
||||||
let
|
|
||||||
GiB = 1024 * 1024 * 1024;
|
|
||||||
in
|
|
||||||
{
|
|
||||||
nix = {
|
|
||||||
nrBuildUsers = 64;
|
|
||||||
|
|
||||||
settings = {
|
|
||||||
# Limit concurrent derivations so build scratch and memory usage remain
|
|
||||||
# bounded. Each derivation may still use every vCPU exposed to the VM.
|
|
||||||
max-jobs = 2;
|
|
||||||
cores = 0;
|
|
||||||
|
|
||||||
# Keep enough room for large desktop, browser, and CUDA closures.
|
|
||||||
min-free = 64 * GiB;
|
|
||||||
max-free = 128 * GiB;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
systemd.services.nix-daemon.serviceConfig = {
|
|
||||||
MemoryAccounting = true;
|
|
||||||
MemoryMax = "90%";
|
|
||||||
OOMScoreAdjust = 500;
|
|
||||||
};
|
|
||||||
|
|
||||||
systemd.tmpfiles.rules = [
|
|
||||||
"d /var/lib/nix-fleet 0750 ${primaryUser} users - -"
|
|
||||||
"d /var/lib/nix-fleet/roots 0750 ${primaryUser} users - -"
|
|
||||||
"d /var/lib/nix-fleet/roots/build 0750 ${primaryUser} users - -"
|
|
||||||
"d /var/lib/nix-fleet/roots/deploy 0750 ${primaryUser} users - -"
|
|
||||||
];
|
|
||||||
}
|
|
||||||
@@ -7,6 +7,10 @@
|
|||||||
"flakes"
|
"flakes"
|
||||||
];
|
];
|
||||||
|
|
||||||
|
extra-allowed-users = [
|
||||||
|
"nixdeploy"
|
||||||
|
];
|
||||||
|
|
||||||
connect-timeout = 10;
|
connect-timeout = 10;
|
||||||
|
|
||||||
extra-substituters = [
|
extra-substituters = [
|
||||||
@@ -19,6 +23,7 @@
|
|||||||
"https://cache.numtide.com"
|
"https://cache.numtide.com"
|
||||||
"https://codex-desktop-linux.cachix.org"
|
"https://codex-desktop-linux.cachix.org"
|
||||||
"https://cuda-maintainers.cachix.org"
|
"https://cuda-maintainers.cachix.org"
|
||||||
|
"https://cache.nixos-cuda.org"
|
||||||
];
|
];
|
||||||
|
|
||||||
extra-trusted-public-keys = [
|
extra-trusted-public-keys = [
|
||||||
@@ -31,6 +36,8 @@
|
|||||||
"niks3.numtide.com-1:DTx8wZduET09hRmMtKdQDxNNthLQETkc/yaX7M4qK0g="
|
"niks3.numtide.com-1:DTx8wZduET09hRmMtKdQDxNNthLQETkc/yaX7M4qK0g="
|
||||||
"codex-desktop-linux.cachix.org-1:nX/xy6AdK9hQE24A8ALGjkCKj2ObFmcnemiL5Cid4nk="
|
"codex-desktop-linux.cachix.org-1:nX/xy6AdK9hQE24A8ALGjkCKj2ObFmcnemiL5Cid4nk="
|
||||||
"cuda-maintainers.cachix.org-1:0dq3bujKpuEPMCX6U4WylrUDZ9JyUG0VpVZa7CNfq5E="
|
"cuda-maintainers.cachix.org-1:0dq3bujKpuEPMCX6U4WylrUDZ9JyUG0VpVZa7CNfq5E="
|
||||||
|
"cache.nixos-cuda.org:74DUi4Ye579gUqzH4ziL9IyiJBlDpMRn9MBN8oNan9M="
|
||||||
|
"nix-builder-1:aG/Y2Lac517isxGO+ZYdVgglj/SI54PkkWoZTQI9aOI="
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,22 +0,0 @@
|
|||||||
{ lib, ... }:
|
|
||||||
let
|
|
||||||
publicKeyFile = ./public-key;
|
|
||||||
hasPublicKey = builtins.pathExists publicKeyFile;
|
|
||||||
publicKey = if hasPublicKey then lib.removeSuffix "\n" (builtins.readFile publicKeyFile) else "";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
assertions = [
|
|
||||||
{
|
|
||||||
assertion = hasPublicKey;
|
|
||||||
message = ''
|
|
||||||
systems.nix.homelab-cache requires
|
|
||||||
modules/systems/nix/homelab-cache/public-key
|
|
||||||
'';
|
|
||||||
}
|
|
||||||
];
|
|
||||||
|
|
||||||
nix.settings = lib.mkIf hasPublicKey {
|
|
||||||
extra-substituters = [ "http://nix-builder:5000" ];
|
|
||||||
extra-trusted-public-keys = [ publicKey ];
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
{
|
|
||||||
description = "Homelab Harmonia binary-cache client settings";
|
|
||||||
}
|
|
||||||
@@ -1,3 +1,8 @@
|
|||||||
{
|
{
|
||||||
services.pcscd.enable = true;
|
services.pcscd.enable = true;
|
||||||
|
|
||||||
|
sops.secrets."users/moons/hashedPassword" = {
|
||||||
|
sopsFile = ../../../secrets/common/system.yaml;
|
||||||
|
neededForUsers = true;
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,28 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
{
|
||||||
|
users.groups.nixdeploy = { };
|
||||||
|
|
||||||
|
users.users.nixdeploy = {
|
||||||
|
isSystemUser = true;
|
||||||
|
group = "nixdeploy";
|
||||||
|
home = "/var/lib/nixdeploy";
|
||||||
|
createHome = true;
|
||||||
|
shell = pkgs.bashInteractive;
|
||||||
|
openssh.authorizedKeys.keys = [
|
||||||
|
"restrict ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFPg1aw0qXBmrQe6lzBwutX5t9Sxg2OeVN/homjqU6Ja moons@nix-builder"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
security.sudo.extraRules = [
|
||||||
|
{
|
||||||
|
users = [ "nixdeploy" ];
|
||||||
|
|
||||||
|
commands = [
|
||||||
|
{
|
||||||
|
command = "ALL";
|
||||||
|
options = [ "NOPASSWD" ];
|
||||||
|
}
|
||||||
|
];
|
||||||
|
}
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -1,2 +1 @@
|
|||||||
{
|
{ }
|
||||||
}
|
|
||||||
|
|||||||
Reference in New Issue
Block a user