Author SHA1 Message Date
moons-14 08210abf01 update
CI: NixOS / Check all NixOS configurations (push) Canceled after 0s
2026-09-28 11:21:09 +09:00
moons-14 eadfa9b331 update
CI: NixOS / Check all NixOS configurations (push) Canceled after 0s
2026-09-20 02:57:51 +09:00
moons-14 0f3b6c59a2 fix 2026-09-12 20:56:20 +09:00
moons-14 c6fe17de3f nano kvm 2026-09-12 19:45:29 +09:00
moons-14 ac60dc343b nanokvm usb 2026-09-12 19:29:27 +09:00
moons-14 ebef49064c contaiber lab group 2026-09-10 15:37:08 +09:00
moons-14 691926aa4f container lab 2026-09-10 15:27:03 +09:00
moons-14 37e2184d36 clatd 2026-09-10 14:50:54 +09:00
moons-14 52e5fcd47f add basic packages 2026-09-09 14:25:58 +09:00
moons-14 fe785b1fc3 ssh conf 2026-09-07 16:35:16 +09:00
moons-14 b8532ff1b4 nvidia toolkit 2026-09-06 21:24:50 +09:00
moons-14 3a20fe9a09 darktable 2026-09-06 20:31:48 +09:00
moons-14 ef7ff60537 update 2026-09-05 07:55:30 +09:00
moons-14 53f4d2475b nix build 2026-09-04 01:16:10 +09:00
moons-14 7d670b03b2 netsrv-01 2026-09-04 01:04:52 +09:00
moons-14 2d9154614b webook 2026-09-03 23:46:24 +09:00
moons-14 56bc3161d7 nix builder 2026-09-03 23:26:45 +09:00
moons-14 10f4d99cb7 nix builder 2026-09-03 23:25:54 +09:00
moons-14 12badacf46 fix 2026-09-03 22:25:34 +09:00
moons-14 937be12e33 minimal profile 2026-09-03 20:31:06 +09:00
moons-14 8761cbfe40 ops ip 2026-09-03 20:19:22 +09:00
moons-14 e789b5a16f add hardware conf 2026-09-03 19:54:09 +09:00
moons-14 008f704b23 install 2026-09-03 15:12:11 +09:00
moons-14 11c1e24ccd feat 2026-09-03 14:08:31 +09:00
moons-14 ad8337bfbb nix builder network 2026-09-03 13:53:16 +09:00
moons-14 cf23e1ef63 fix 2026-09-03 13:09:52 +09:00
moons-14 4652d911ee add ops 2026-09-03 04:49:45 +09:00
moons-14 c7db764fe2 fix 2026-09-03 04:41:47 +09:00
moons-14 63f49d58f8 fix 2026-09-03 04:37:31 +09:00
moons-14 8189373575 fix 2026-09-03 04:36:04 +09:00
moons-14 d4721d1d22 nix builder 2026-09-03 04:32:47 +09:00
moons-14 cc3798a7b2 nix builder 2026-09-03 04:32:29 +09:00
moons-14 0ff78c6848 nix-builder disko 2026-09-02 21:36:23 +09:00
moons-14 c53a0c0bed zed terraform 2026-09-02 21:23:51 +09:00
moons-14 e3d61e8b6d delete direnv gitignore 2026-09-01 22:20:44 +09:00
71 changed files with 1294 additions and 838 deletions
+68 -20
View File
@@ -351,13 +351,13 @@ modules/profiles/
├── base/ ├── base/
├── interface/ ├── interface/
│ ├── cli/ │ ├── cli/
│ ├── minimal/
│ ├── gui/ │ ├── gui/
│ ├── macos/ │ ├── macos/
│ ├── linux-desktop/ │ ├── linux-desktop/
│ ├── labwc/ │ ├── labwc/
│ └── niri/ │ └── niri/
├── networking/ ├── networking/
│ ├── homelab-cache-client/
│ ├── tailscale-client/ │ ├── tailscale-client/
│ └── tailscale-subnet-router/ │ └── tailscale-subnet-router/
├── platform/ ├── platform/
@@ -369,11 +369,13 @@ modules/profiles/
│ └── vm/ │ └── vm/
├── workload/ ├── workload/
│ ├── camera/ │ ├── camera/
│ ├── deploy-rs-target/
│ ├── development/ │ ├── development/
│ ├── game/ │ ├── game/
│ ├── machine-learning/ │ ├── machine-learning/
│ ├── nix-builder/ │ ├── network-lab/
│ ├── personal/ │ ├── personal/
│ ├── photography/
│ ├── server/ │ ├── server/
│ └── remote-access/ │ └── remote-access/
└── security/ └── security/
@@ -394,16 +396,21 @@ The profile layers have these responsibilities:
- `base` contains only invariants required by every supported host. It includes - `base` contains only invariants required by every supported host. It includes
`systems.nix` and the universal Atuin, tealdeer, trippy, and xh CLI tools; `systems.nix` and the universal Atuin, tealdeer, trippy, and xh CLI tools;
optional secrets, interface, hardware, and workloads do not belong there. optional secrets, interface, hardware, and workloads do not belong there.
- `interface` describes how the host is operated. `interface.cli` is shared by - `interface` describes how the host is operated. `interface.minimal` is shared
NixOS and macOS and includes `tio`. `interface.gui` owns cross-platform by NixOS and macOS and provides the remote-administration CLI baseline,
graphical interface applications such as Vicinae. `interface.macos` owns the including SSH, Nano, htop, Git, Zellij, and Zsh. `interface.cli` includes that
macOS Finder, Dock, trackpad, and shared default preferences and includes baseline and adds the full interactive command-line environment, including
`interface.gui`. the configured Neovim, Yazi, and `tio`. `interface.gui` owns
cross-platform graphical interface applications such as Vicinae.
`interface.macos` owns the macOS Finder, Dock, trackpad, and shared default
preferences and includes `interface.gui`.
`interface.linux-desktop` owns the common labwc/niri desktop selection, `interface.linux-desktop` owns the common labwc/niri desktop selection,
including Ghostty and Nautilus, and also includes `interface.gui`. Labwc and including Ghostty and Nautilus, and also includes `interface.gui`. Labwc and
niri remain independently selectable and do not imply CLI or personal niri remain independently selectable and do not imply CLI or personal
workloads. workloads.
- `platform` describes NixOS foundations and physical or virtual form factors. - `platform` describes NixOS foundations and physical or virtual form factors.
`platform.nixos` selects the shared network foundation and `services.clatd`;
VM, laptop, and desktop platform profiles inherit both.
macOS does not need an empty symmetric platform profile. macOS does not need an empty symmetric platform profile.
- `workload` describes optional host uses. `workload.development` and - `workload` describes optional host uses. `workload.development` and
`workload.personal` are cross-platform profiles, not `*-linux` variants. `workload.personal` are cross-platform profiles, not `*-linux` variants.
@@ -543,9 +550,26 @@ A host registry may use a specification like this:
profiles = [ profiles = [
"base" "base"
"interface.cli" "interface.minimal"
"platform.vm" "platform.vm"
"workload.remote-access" "workload.remote-access"
"workload.deploy-rs-target"
];
};
netsrv-01 = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./netsrv-01;
profiles = [
"base"
"interface.minimal"
"platform.vm"
"workload.remote-access"
"workload.deploy-rs-target"
"workload.server"
]; ];
}; };
@@ -557,7 +581,7 @@ A host registry may use a specification like this:
profiles = [ profiles = [
"base" "base"
"interface.cli" "interface.minimal"
"platform.vm" "platform.vm"
"workload.server" "workload.server"
]; ];
@@ -609,6 +633,7 @@ A host registry may use a specification like this:
"security.tpm-storage" "security.tpm-storage"
"workload.camera" "workload.camera"
"workload.development" "workload.development"
"workload.network-lab"
"workload.personal" "workload.personal"
]; ];
}; };
@@ -631,7 +656,9 @@ A host registry may use a specification like this:
"workload.development" "workload.development"
"workload.game" "workload.game"
"workload.machine-learning" "workload.machine-learning"
"workload.network-lab"
"workload.personal" "workload.personal"
"workload.photography"
]; ];
}; };
@@ -654,14 +681,22 @@ A host registry may use a specification like this:
``` ```
The current role assignment is intentional: nix-example is the development VM; The current role assignment is intentional: nix-example is the development VM;
ops is the remote-access VM with host-specific static networking; ops is the minimal-interface remote-access VM with host-specific static
internal-app-01 is the container server VM; and installer builds the minimal networking; netsrv-01 is the deploy-rs-managed container server VM;
installation ISO without Home Manager. x1g9 is a full NixOS desktop with niri, internal-app-01 is the minimal-interface container server VM;
nix-builder is the minimal-interface remote Nix build VM with dedicated build
and store disks; and installer builds the minimal installation ISO without Home
Manager. x1g9 is a full NixOS desktop with niri,
labwc, ly, the shared Linux desktop applications, and the personal workload. labwc, ly, the shared Linux desktop applications, and the personal workload.
x1g13 is the secure NixOS development and personal ThinkPad, with the same x1g13 is the secure NixOS development and personal ThinkPad, with the same
desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk
unlock. galleria is the Intel/NVIDIA physical desktop shared with Windows; it unlock. galleria is the Intel/NVIDIA physical desktop shared with Windows; it
uses dedicated NixOS partitions, LUKS, Secure Boot, and TPM-backed disk unlock. uses dedicated NixOS partitions, LUKS, Secure Boot, and TPM-backed disk unlock.
It selects `workload.photography` for AI-enabled darktable. The application
chooses CUDA support from the NVIDIA hardware unit's enable state and keeps
the default CUDA targets, including RTX 3060 Ti support, to reuse binary caches.
galleria and x1g13 select `workload.network-lab` for containerlab, Docker, and
the NanoKVM-USB desktop client with serial-port access.
m2 is the daily-use macOS development and personal machine with the macOS m2 is the daily-use macOS development and personal machine with the macOS
interface defaults. Keep the desktop sessions independently selectable, and interface defaults. Keep the desktop sessions independently selectable, and
keep the development and personal profiles usable across NixOS and Darwin. keep the development and personal profiles usable across NixOS and Darwin.
@@ -694,6 +729,15 @@ configuration fragments. For example:
```text ```text
hosts/ hosts/
├── nix-builder/
│ ├── disko.nix
│ ├── hardware-configuration.nix
│ └── nixos.nix
├── netsrv-01/
│ ├── disko.nix
│ ├── hardware-configuration.nix
│ ├── networking.nix
│ └── nixos.nix
├── installer/ ├── installer/
│ └── nixos.nix │ └── nixos.nix
├── internal-app-01/ ├── internal-app-01/
@@ -723,12 +767,15 @@ hosts/
``` ```
`hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the `hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the
normal top-level Nix module `imports`. `hosts/x1g13/nixos.nix` loads its normal top-level Nix module `imports`. `hosts/nix-builder/nixos.nix` and
generated hardware configuration and host-local `disko.nix` the same way. Do `hosts/x1g13/nixos.nix` load their generated hardware configuration and
not confuse these host imports with the prohibition on top-level `imports` in host-local `disko.nix` the same way. The nix-builder Disko definition mounts its
unit configuration fragments. `hosts/galleria/disko.nix` manages only the two existing VM filesystems by stable QEMU SCSI IDs and does not take destructive
dedicated NixOS partitions by PARTUUID and deliberately excludes the Windows ownership of them. Do not confuse these host imports with the prohibition on
disk, Windows partitions, and the Windows EFI System Partition. top-level `imports` in unit configuration fragments. `hosts/galleria/disko.nix`
manages only the two dedicated NixOS partitions by PARTUUID and deliberately
excludes the Windows disk, Windows partitions, and the Windows EFI System
Partition.
Derive the system class from the host's `system`: Derive the system class from the host's `system`:
@@ -831,8 +878,9 @@ For profile changes, additionally:
`homebrew.casks` selection as well as module evaluation. `homebrew.casks` selection as well as module evaluation.
- Preserve the intended host roles: nix-example remains the development VM; - Preserve the intended host roles: nix-example remains the development VM;
ops remains the statically networked remote-access VM; internal-app-01 remains ops remains the statically networked remote-access VM; internal-app-01 remains
the container server VM; installer remains the Home Manager-free installation the container server VM; netsrv-01 remains the deploy-rs-managed container
ISO; x1g9 provides niri, labwc, ly, and the personal application set; x1g13 server VM; installer remains the Home Manager-free installation ISO; x1g9
provides niri, labwc, ly, and the personal application set; x1g13
additionally provides the development, Tailscale client, secrets, Secure Boot, additionally provides the development, Tailscale client, secrets, Secure Boot,
and TPM storage roles; galleria remains the Intel/NVIDIA dual-boot desktop and TPM storage roles; galleria remains the Intel/NVIDIA dual-boot desktop
with LUKS, Secure Boot, and TPM storage; m2 remains the daily-use development with LUKS, Secure Boot, and TPM storage; m2 remains the daily-use development
+153
View File
@@ -0,0 +1,153 @@
# NixOSインストール手順(SOPSなし・ディスク暗号化なし)
この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を
使用しないホスト向けの、独立したインストール手順である。
SOPSとディスク暗号化を使用する場合は、[暗号化ありの手順](install.md)を参照。
## 事前準備
1. [ISOビルド](iso-build.md)を参照してISOを作成
2. USBに書き込んで対象マシンでブート
## ネットワーク接続
### 有線LAN
DHCPで自動設定される。
### Wi-Fi(有線が使えない場合)
```bash
nmcli device wifi connect <SSID> --ask
```
## SSH接続
コンソールに表示されたIPアドレスに接続:
```bash
ssh root@<ip-address>
```
## インストール手順
### 1. dotfilesのクローン
```bash
git clone [email protected]:moons-14/dotfiles.git ~/dotfiles
cd ~/dotfiles
```
### 2. ホスト設定の作成
`hosts/<hostname>/nixos.nix`を作成し、`hosts/default.nix`にホストと使用する
プロファイルを登録する。ホスト固有の設定だけをホストディレクトリに置き、
再利用可能な設定は適切なunitまたはprofileに置く。
### 3. インストール先ディスクの確認
```bash
lsblk -o NAME,PATH,SIZE,MODEL,SERIAL,TYPE,FSTYPE,MOUNTPOINTS
ls -l /dev/disk/by-id/
```
以降の操作では指定したディスクの既存データが消去される。対象を必ず確認し、
可能であれば`/dev/sda`や`/dev/nvme0n1`ではなく、安定した
`/dev/disk/by-id/...`パスを使用する。
### 4. Disko設定の作成
`hosts/<hostname>/disko.nix`を作成する:
```nix
_:
{
disko.enableConfig = true;
disko.devices.disk.main = {
type = "disk";
device = "/dev/disk/by-id/<target-disk>";
content = {
type = "gpt";
partitions = {
ESP = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
root = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
};
};
};
}
```
`<target-disk>`を手順3で確認した実際のディスクIDに置き換える。指定した
ディスクの既存データは消去される。
### 5. パーティション作成とマウント
```bash
disko --mode destroy,format,mount hosts/<hostname>/disko.nix
```
Diskoの実行結果を確認する:
```bash
findmnt /mnt
findmnt /mnt/boot
```
### 6. ハードウェア設定の生成
```bash
nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \
> ~/dotfiles/hosts/<hostname>/hardware-configuration.nix
```
### 7. ホストモジュールから設定を読み込む
`hosts/<hostname>/nixos.nix`で、生成したハードウェア設定とDisko設定を読み込む:
```nix
{
imports = [
./hardware-configuration.nix
./disko.nix
];
}
```
### 8. NixOSインストール
```bash
nixos-install --flake ~/dotfiles#<hostname>
```
SOPSを使用しないため、age鍵の登録、シークレットの再暗号化、SSHホストキーの
事前生成とコピーは不要である。OpenSSHを有効にしたホストでは、SSHホストキーは
通常の初回起動時に生成される。
### 9. 再起動
```bash
reboot
```
## インストール後の確認
- 正しいディスクから起動できるか
- `/`と`/boot`が意図したファイルシステムからマウントされているか
- ネットワークと、設定している場合はSSH接続が利用できるか
+32 -44
View File
@@ -1,4 +1,10 @@
# NixOSインストール手順 # NixOSインストール手順(SOPS・ディスク暗号化あり)
この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を
使用するホスト向けである。
どちらも使用しない場合は、
[SOPSなし・ディスク暗号化なしの手順](install-simple.md)を参照。
## 事前準備 ## 事前準備
@@ -83,54 +89,36 @@ sops updatekeys secrets/hosts/<hostname>/*.yaml
新しいホスト用の`hosts/<hostname>/disko.nix`を作成。 新しいホスト用の`hosts/<hostname>/disko.nix`を作成。
#### シンプル構成(暗号化なし) LUKS暗号化とbtrfsの構成は`hosts/x1g13/disko.nix`を参照。
```nix
_:
{
disko.enableConfig = true;
disko.devices.disk.main = {
type = "disk";
device = "/dev/sda";
content = {
type = "gpt";
partitions = {
ESP = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
root = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
};
};
};
}
```
#### LUKS暗号化 + btrfs
`hosts/x1g13/disko.nix`を参照。
### 7. ディスクのパーティション ### 7. ディスクのパーティション
```bash ```bash
cd ~/dotfiles cd ~/dotfiles
nix run github:nix-community/disko -- --mode disko hosts/<hostname>/disko.nix disko --mode destroy,format,mount hosts/<hostname>/disko.nix
``` ```
### 8. ホストキーのコピー ### 8. ハードウェア設定の生成
対象マシンのハードウェア設定を生成し、新しいホストのディレクトリへ直接保存:
```bash
nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \
> ~/dotfiles/hosts/<hostname>/hardware-configuration.nix
```
`hosts/<hostname>/nixos.nix`から生成した設定とDisko設定を読み込む:
```nix
{
imports = [
./hardware-configuration.nix
./disko.nix
];
}
```
### 9. ホストキーのコピー
```bash ```bash
mkdir -p /mnt/etc/ssh mkdir -p /mnt/etc/ssh
@@ -138,13 +126,13 @@ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/
chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key
``` ```
### 9. NixOSインストール ### 10. NixOSインストール
```bash ```bash
nixos-install --flake ~/dotfiles#<hostname> nixos-install --flake ~/dotfiles#<hostname>
``` ```
### 10. 再起動 ### 11. 再起動
```bash ```bash
reboot reboot
+72 -12
View File
@@ -1,26 +1,86 @@
# カスタムISOビルド # カスタムインストーラー ISO
`hosts/installer` から、NixOS 26.05 ベースの `x86_64-linux` 用インストーラー
ISO を作成する。installer ホストは Home Manager を使用せず、`base` プロファイルと
ホスト固有のインストール支援設定だけを含む。
## ビルド ## ビルド
flake 対応の Nix が利用できる環境で、リポジトリのルートから実行する。
`x86_64-linux` 以外のマシンで実行する場合は、対応する Linux リモートビルダーが
必要になる。
```bash ```bash
nix build .#nixosConfigurations.installer.config.system.build.isoImage nix build .#nixosConfigurations.installer.config.system.build.isoImage
``` ```
## ISO書き込み 生成された ISO は次の場所にある。
```text
result/iso/nixos-minimal-*-x86_64-linux.iso
```
ファイル名に含まれる NixOS のバージョンとリビジョンは、`flake.lock` の更新に応じて
変わる。生成物を確認するには次を実行する。
```bash ```bash
# USBデバイスの確認 ls -lh result/iso/*.iso
lsblk sha256sum result/iso/*.iso
```
# 書き込み(/dev/sdXは実際のデバイスに置き換える) ## USB メモリへの書き込み
sudo dd if=./result/nixos-minimal-*.iso of=/dev/sdX bs=4M status=progress
書き込み先はパーティション(例: `/dev/sdX1`)ではなく、USB デバイス全体
(例: `/dev/sdX`)を指定する。この操作は指定したデバイスの内容を上書きするため、
サイズ、モデル、マウント先を確認する。
```bash
lsblk -p -o NAME,SIZE,TYPE,MODEL,MOUNTPOINTS
```
USB のマウント済みパーティションをアンマウントしてから、`/dev/sdX` と
`/dev/sdX1` を確認した実際のデバイス名に置き換えて書き込む。パーティションが
複数ある場合は、それぞれをアンマウントする。
```bash
sudo umount /dev/sdX1
sudo dd if=result/iso/nixos-minimal-*-x86_64-linux.iso \
of=/dev/sdX bs=4M conv=fsync status=progress
sync sync
``` ```
## ISOの特徴 書き込み完了後、USB を安全に取り外して対象マシンから起動する。
- SSH鍵認証でrootログイン可能 ## 起動後の接続
- 有線LANはDHCPで自動設定
- WiFiは`nmcli`で手動設定可能 有線 LAN は DHCP で自動設定される。Wi-Fi を使用する場合は、インストーラーの
- disko/sops/ageなどのツールを内蔵 コンソールで NetworkManager を使って接続する。
- ブート時にIPアドレスとヘルプを表示
```bash
nmcli device wifi list
nmcli device wifi connect <SSID> --ask
```
起動時にコンソールへ IPv4 アドレスと簡易ヘルプが表示される。表示されたアドレスへ
登録済みの SSH 鍵で接続する。
```bash
ssh root@<ip-address>
```
root のパスワードログインとキーボード対話認証は無効で、
`hosts/installer/nixos.nix` に登録された公開鍵だけが利用できる。
以降の作業は、構成に応じて次の手順を参照する:
- [SOPSなし・ディスク暗号化なし](install-simple.md)
- [SOPS・ディスク暗号化あり](install.md)
## ISO に含まれる主な設定とツール
- Nix flakes と `nix-command`
- NetworkManager、OpenSSH、起動時の IP アドレス表示
- `disko`、`parted`、`cryptsetup`、`btrfs-progs`、`efibootmgr`
- `sops`、`age`、`ssh-to-age`
- `age-plugin-yubikey`、`yubikey-manager`、`pcsc-tools` と `pcscd`
- `sbctl`、`tpm2-tools`
- `git`、`rsync`、`vim`、`wget`、`curl`、`jq`、`pciutils`、`util-linux`
Generated
+232 -268
View File
@@ -100,11 +100,11 @@
"systems": "systems" "systems": "systems"
}, },
"locked": { "locked": {
"lastModified": 1787888246, "lastModified": 1790375278,
"narHash": "sha256-E8vD7IJ/16J9JPTQKYvSmwq5k0/FdLMtLf7UVk3G0IU=", "narHash": "sha256-oGv6aatLyq8Eha1ZA5wbkdRhlE3WdmOt9yajLeTgnCk=",
"owner": "nix-community", "owner": "nix-community",
"repo": "browser-previews", "repo": "browser-previews",
"rev": "f2e8d11fd3e04175290fe16e882ceb9dd064a8e2", "rev": "ef13999ddd920d61e5c7cfae16177de7ffb62e61",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -158,15 +158,16 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1784665499, "lastModified": 1790001035,
"narHash": "sha256-9BMxlTxCCDAeoNLtb1a/st7udtTIJep+wpUzquA29VU=", "narHash": "sha256-1/SLBjSYBzDdDhvLQ83wrzBakyS/xNGgtxHGNuveOEQ=",
"owner": "nix-community", "owner": "Mic92",
"repo": "bun2nix", "repo": "bun2nix",
"rev": "0f2a1f0b6f42cebe3b149bf62d38754c5e0e9729", "rev": "07a5bfc8ac36c5370199343fa620b69f63186e33",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "nix-community", "owner": "Mic92",
"ref": "llm-agents",
"repo": "bun2nix", "repo": "bun2nix",
"type": "github" "type": "github"
} }
@@ -206,11 +207,11 @@
"nixpkgs": "nixpkgs" "nixpkgs": "nixpkgs"
}, },
"locked": { "locked": {
"lastModified": 1787978476, "lastModified": 1790510073,
"narHash": "sha256-aI5mJw5GJ6YADjRLvu5KLK6NK7NCnLveQyNqHl4sDP4=", "narHash": "sha256-ePu9Vqm1/S/lTidMGMnPS3PheOb2sEOqJ5iBA74A8nY=",
"owner": "ilysenko", "owner": "ilysenko",
"repo": "codex-desktop-linux", "repo": "codex-desktop-linux",
"rev": "7994f23cd5c2da23cdc0953367ff6056ebed50b3", "rev": "5b80192545dcc9a820c49cf26c806308a7afd551",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -238,6 +239,24 @@
"type": "github" "type": "github"
} }
}, },
"containerlab": {
"inputs": {
"nixpkgs": "nixpkgs_4"
},
"locked": {
"lastModified": 1790449163,
"narHash": "sha256-BWqGSYpBep1D8JxQPFwXVuYsn5LxlB2kR7nfnCQbUjc=",
"owner": "srl-labs",
"repo": "containerlab",
"rev": "0bb144e1d03fb3546abd15a0565562382ab85437",
"type": "github"
},
"original": {
"owner": "srl-labs",
"repo": "containerlab",
"type": "github"
}
},
"crane": { "crane": {
"locked": { "locked": {
"lastModified": 1784407669, "lastModified": 1784407669,
@@ -255,11 +274,11 @@
}, },
"crane_2": { "crane_2": {
"locked": { "locked": {
"lastModified": 1787326676, "lastModified": 1789760033,
"narHash": "sha256-lWhBbBvC05/xwivKBBiM2YNizpmgqCgyOIzomvRuwxs=", "narHash": "sha256-jtT4yxZpR8seYnlCMMWSSPlFN92zO6ICuZ8pJrmi86k=",
"owner": "ipetkov", "owner": "ipetkov",
"repo": "crane", "repo": "crane",
"rev": "692f7e9ef2ece8125b466f66f2af532b3edaed0d", "rev": "73b980519cefc727a5f6cc8e5c0947a2f9be6edd",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -268,28 +287,6 @@
"type": "github" "type": "github"
} }
}, },
"deploy-rs": {
"inputs": {
"flake-compat": "flake-compat_2",
"nixpkgs": [
"nixpkgs"
],
"utils": "utils"
},
"locked": {
"lastModified": 1786361680,
"narHash": "sha256-IxaZkb9rCGEZ+yGndxKXONeIEcKMzoFUsvLTB5G/caw=",
"owner": "serokell",
"repo": "deploy-rs",
"rev": "16901271e5b30b591e56f7a84f25f186fb20f3e1",
"type": "github"
},
"original": {
"owner": "serokell",
"repo": "deploy-rs",
"type": "github"
}
},
"disko": { "disko": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
@@ -297,11 +294,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1781152676, "lastModified": 1789770686,
"narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=", "narHash": "sha256-uZkBR7yHdIKUFB5SZdfgh1qkGfI3XmYmI/lTiquxbck=",
"owner": "nix-community", "owner": "nix-community",
"repo": "disko", "repo": "disko",
"rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1", "rev": "725ea35e410ad83be4931d1bff7e090eacaf3563",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -345,11 +342,11 @@
"flake-compat_2": { "flake-compat_2": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1733328505, "lastModified": 1767039857,
"narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=", "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
"owner": "edolstra", "owner": "edolstra",
"repo": "flake-compat", "repo": "flake-compat",
"rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec", "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -363,13 +360,13 @@
"locked": { "locked": {
"lastModified": 1767039857, "lastModified": 1767039857,
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
"owner": "edolstra", "owner": "NixOS",
"repo": "flake-compat", "repo": "flake-compat",
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "edolstra", "owner": "NixOS",
"repo": "flake-compat", "repo": "flake-compat",
"type": "github" "type": "github"
} }
@@ -395,34 +392,18 @@
"locked": { "locked": {
"lastModified": 1767039857, "lastModified": 1767039857,
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
"owner": "NixOS", "owner": "edolstra",
"repo": "flake-compat", "repo": "flake-compat",
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "NixOS", "owner": "edolstra",
"repo": "flake-compat", "repo": "flake-compat",
"type": "github" "type": "github"
} }
}, },
"flake-compat_6": { "flake-compat_6": {
"flake": false,
"locked": {
"lastModified": 1767039857,
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-compat_7": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1767039857, "lastModified": 1767039857,
@@ -484,11 +465,11 @@
"nixpkgs-lib": "nixpkgs-lib_2" "nixpkgs-lib": "nixpkgs-lib_2"
}, },
"locked": { "locked": {
"lastModified": 1787559586, "lastModified": 1788450739,
"narHash": "sha256-onL0VLf9vPllmT0H/OlURIU5r5t5WIEl7t4tVNKT0Nw=", "narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
"owner": "hercules-ci", "owner": "hercules-ci",
"repo": "flake-parts", "repo": "flake-parts",
"rev": "9d0d87172c374f89da73c1cfe6d81ae62feac1f1", "rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -505,11 +486,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1787559586, "lastModified": 1788450739,
"narHash": "sha256-onL0VLf9vPllmT0H/OlURIU5r5t5WIEl7t4tVNKT0Nw=", "narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
"owner": "hercules-ci", "owner": "hercules-ci",
"repo": "flake-parts", "repo": "flake-parts",
"rev": "9d0d87172c374f89da73c1cfe6d81ae62feac1f1", "rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -526,11 +507,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1785627969, "lastModified": 1788450739,
"narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=", "narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
"owner": "hercules-ci", "owner": "hercules-ci",
"repo": "flake-parts", "repo": "flake-parts",
"rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a", "rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -617,19 +598,19 @@
}, },
"ghostty": { "ghostty": {
"inputs": { "inputs": {
"flake-compat": "flake-compat_3", "flake-compat": "flake-compat_2",
"home-manager": "home-manager_2", "home-manager": "home-manager_2",
"nixpkgs": "nixpkgs_4", "nixpkgs": "nixpkgs_5",
"systems": "systems_5", "systems": "systems_4",
"zig": "zig", "zig": "zig",
"zon2nix": "zon2nix" "zon2nix": "zon2nix"
}, },
"locked": { "locked": {
"lastModified": 1788019183, "lastModified": 1790475802,
"narHash": "sha256-WYLVuVgxCq2OH7+2DuBpBW8KBSYJjwbZn9sZrXALlQY=", "narHash": "sha256-jGBYacSDg7Ya/P3OpkuM+EK+kW4JAPIiGTxEdWMc6PQ=",
"owner": "ghostty-org", "owner": "ghostty-org",
"repo": "ghostty", "repo": "ghostty",
"rev": "7b47213f94058c3715205ce8fa73f7ae581a652c", "rev": "b40acce58dcf77df52231c3798ea58e924647c89",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -663,15 +644,15 @@
}, },
"git-hooks-nix": { "git-hooks-nix": {
"inputs": { "inputs": {
"flake-compat": "flake-compat_4", "flake-compat": "flake-compat_3",
"nixpkgs": "nixpkgs_5" "nixpkgs": "nixpkgs_6"
}, },
"locked": { "locked": {
"lastModified": 1787424939, "lastModified": 1790500375,
"narHash": "sha256-O2tBn84NNuHrnqNVxx/XqsXwfYvS1YwBh+7CBnbCYsk=", "narHash": "sha256-XN3sDtn8TU9hAc9xqZ+SqRB/HHm2wjxM6aSWYLJU+oo=",
"owner": "cachix", "owner": "cachix",
"repo": "git-hooks.nix", "repo": "git-hooks.nix",
"rev": "809414f0cdadf82cf11b06c2b29ba9b3168b3297", "rev": "a0e4241b51206fbcbf52fd322eb5f0cd80f153c4",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -750,11 +731,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1787377438, "lastModified": 1790215976,
"narHash": "sha256-Sxu1NLTD/Ern6hFGLlZmtKCSct3YQXZI/lls8RE1XeM=", "narHash": "sha256-VkR1rMGyjU9jtw8ISFx5uqR9e+LEaOlhHwrseFkiIVk=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "65258d5c65a250189fde2e35f490d15e064c4c62", "rev": "a6631107a83ceab5872f298a2ea710859c80c4cb",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -795,11 +776,11 @@
"rust-overlay": "rust-overlay_2" "rust-overlay": "rust-overlay_2"
}, },
"locked": { "locked": {
"lastModified": 1787658383, "lastModified": 1790423250,
"narHash": "sha256-I+zCjwAtkmgnet+08H+7HV8qJjf6BoFMYsX/8lMiW/s=", "narHash": "sha256-sr4Kfp6yaXUeyKL6n0Y8/ElcR3momIRC20HFc+LF22s=",
"owner": "nix-community", "owner": "nix-community",
"repo": "lanzaboote", "repo": "lanzaboote",
"rev": "69cf334f9dbc11213c6228c97e9b32924d51443f", "rev": "c1c5edd31802d181c8aa2c71588995d93425d650",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -828,16 +809,16 @@
"inputs": { "inputs": {
"bun2nix": "bun2nix_2", "bun2nix": "bun2nix_2",
"flake-parts": "flake-parts_4", "flake-parts": "flake-parts_4",
"nixpkgs": "nixpkgs_6", "nixpkgs": "nixpkgs_7",
"systems": "systems_6", "systems": "systems_5",
"treefmt-nix": "treefmt-nix_3" "treefmt-nix": "treefmt-nix_3"
}, },
"locked": { "locked": {
"lastModified": 1788038998, "lastModified": 1790555299,
"narHash": "sha256-Q8sIuu2wRET+POhXUGVUaEDKT2OcZyKXLAf744qrbGk=", "narHash": "sha256-A4ZG1Y9Itut5xO+CLwi06CElVlwj4FnhZMgg2Xiucho=",
"owner": "numtide", "owner": "numtide",
"repo": "llm-agents.nix", "repo": "llm-agents.nix",
"rev": "44099f2474161ef95a2b1ec1d8088ae8a6673a77", "rev": "2475131b50dbc795684c55ba771d94401f068fd6",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -864,14 +845,14 @@
}, },
"nani-translate-linux": { "nani-translate-linux": {
"inputs": { "inputs": {
"nixpkgs": "nixpkgs_7" "nixpkgs": "nixpkgs_8"
}, },
"locked": { "locked": {
"lastModified": 1786578029, "lastModified": 1789710762,
"narHash": "sha256-XXTxlJ6U7hhHA94eTDCL80iKUwJ54L1EZ9oj/d0hC48=", "narHash": "sha256-U9BDfeN+st7GQoC3byKaj9rHW+i/HPyWvUAmWH6wZyI=",
"ref": "refs/heads/main", "ref": "refs/heads/main",
"rev": "427289b4fc7433b6b08613f9e1644ab5209838d6", "rev": "b5ce224f56360833af5eb21c91387c42d2a4f47b",
"revCount": 11, "revCount": 12,
"type": "git", "type": "git",
"url": "https://github.com/zunoser/nani-translate-linux.git" "url": "https://github.com/zunoser/nani-translate-linux.git"
}, },
@@ -884,7 +865,7 @@
"inputs": { "inputs": {
"niri-stable": "niri-stable", "niri-stable": "niri-stable",
"niri-unstable": "niri-unstable", "niri-unstable": "niri-unstable",
"nixpkgs": "nixpkgs_8", "nixpkgs": "nixpkgs_9",
"nixpkgs-stable": "nixpkgs-stable", "nixpkgs-stable": "nixpkgs-stable",
"xwayland-satellite-stable": "xwayland-satellite-stable", "xwayland-satellite-stable": "xwayland-satellite-stable",
"xwayland-satellite-unstable": "xwayland-satellite-unstable" "xwayland-satellite-unstable": "xwayland-satellite-unstable"
@@ -980,11 +961,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1779529080, "lastModified": 1790329191,
"narHash": "sha256-CHa5L3I71NbPUNJp1gmmwbh91tKsZPyuRK50mLHjAVY=", "narHash": "sha256-HYfn+tCtyY4Xl2l0InOGoaYgZMLbFw3LB11ZETjMxp0=",
"owner": "aster-void", "owner": "aster-void",
"repo": "nix-hazkey", "repo": "nix-hazkey",
"rev": "24cb2926666836988e78ceebeb67ad6c5a387ac3", "rev": "9524686e361eb1ce9c054f0218e7a4b82091b847",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1000,11 +981,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1787457452, "lastModified": 1790499302,
"narHash": "sha256-FJh4esFS3zqNNuKwvN3t6wrJGewqp1AUF9DAEvoKPD8=", "narHash": "sha256-Gbf/U9ptJhQh0qnDnJ/+a8MAcq1HXunbArUTHR2wNYk=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nix-index-database", "repo": "nix-index-database",
"rev": "c51d5c2ba69c907a34e90c9b6b80cd2b93811745", "rev": "161d7c91accd93034bb3c295224d9d895a778573",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1015,14 +996,14 @@
}, },
"nixos-hardware": { "nixos-hardware": {
"inputs": { "inputs": {
"nixpkgs": "nixpkgs_9" "nixpkgs": "nixpkgs_10"
}, },
"locked": { "locked": {
"lastModified": 1787144466, "lastModified": 1790321948,
"narHash": "sha256-HHfv2/HkNSKbbSyU9iD/g8lbP6r4tl33sSw1W4rXCk0=", "narHash": "sha256-mZGHLGi217oLIwzDM4PNRZeCNa6g2WBXURyXbNMFs7Y=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixos-hardware", "repo": "nixos-hardware",
"rev": "0471accf8d0a8210b31d947497d179ecc99e0021", "rev": "30d48a0ec6035f8140d0125af274f0de95f1e9b5",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1034,15 +1015,15 @@
}, },
"nixos-wsl": { "nixos-wsl": {
"inputs": { "inputs": {
"flake-compat": "flake-compat_6", "flake-compat": "flake-compat_5",
"nixpkgs": "nixpkgs_10" "nixpkgs": "nixpkgs_11"
}, },
"locked": { "locked": {
"lastModified": 1784642409, "lastModified": 1789164534,
"narHash": "sha256-hcbDqFuySAJawljt5r0sKBCJKYnbtGD0T/ZIozH1Dq0=", "narHash": "sha256-DoYGPM6QpnYBLWj9gGw6ZwAzIX+HrAVov1BoT+8Jixo=",
"owner": "nix-community", "owner": "nix-community",
"repo": "NixOS-WSL", "repo": "NixOS-WSL",
"rev": "eaeb18da90024448a60eb1ec7132eafa4003404e", "rev": "72c92b11bb8289e6651c7fef29cc0a885fd6a255",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1084,11 +1065,11 @@
}, },
"nixpkgs-lib_2": { "nixpkgs-lib_2": {
"locked": { "locked": {
"lastModified": 1785031560, "lastModified": 1788057806,
"narHash": "sha256-OmshNvn2vupOFpYinLUu+1Dnpu4n7Q5N3ggGVNHpkUI=", "narHash": "sha256-DTQSMxzDWmT0zhguthvegnVkn7CFqGCv4IHCzk5ZUpM=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nixpkgs.lib", "repo": "nixpkgs.lib",
"rev": "0e79af5e3d4dcfcd676ab5ba3f95d2e3352e078c", "rev": "596e2e3940e09b2abbeb03f75fa1828c57fcd72c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1131,11 +1112,11 @@
}, },
"nixpkgs-unstable": { "nixpkgs-unstable": {
"locked": { "locked": {
"lastModified": 1787874478, "lastModified": 1790510107,
"narHash": "sha256-ubWQiwkhIql/lYwnfK55yKHfAkTBXie2L4iChGNHfI0=", "narHash": "sha256-EVMNYv7hYDDD9TGVT/hIyTYgpiXA8y3m5xIEIxuGNU0=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "7d1a7c21a4c00ea653fc7ed5c083d261340f185f", "rev": "3181085bfd08663b6b9e60bc7a8395c2aaa741bd",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1147,11 +1128,24 @@
}, },
"nixpkgs_10": { "nixpkgs_10": {
"locked": { "locked": {
"lastModified": 1783776592, "lastModified": 1789546076,
"narHash": "sha256-UgCQzxeWI75XM8G+hPrPh+MKzEPjG3SpAj7dtqSbksA=", "narHash": "sha256-vWkSk5bbfTqdtMoSgD9FshACO8JCvXTFi+3cqEp0mH0=",
"rev": "b1b875982b17dabde9b4a37f3e229e74913e6db3",
"type": "tarball",
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1074753.b1b875982b17/nixexprs.tar.xz"
},
"original": {
"type": "tarball",
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
}
},
"nixpkgs_11": {
"locked": {
"lastModified": 1789006805,
"narHash": "sha256-xB8mKMOx1IA9vTDNLmJZ6n4wCMq/cuWBBOzGCRnqxrU=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "e7a3ca8092b61ff85b6a45bf863ea2b2d6a661b3", "rev": "8ce4ef6cb6f871616146b9fe26d2a5ae594e94fe",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1161,13 +1155,13 @@
"type": "github" "type": "github"
} }
}, },
"nixpkgs_11": { "nixpkgs_12": {
"locked": { "locked": {
"lastModified": 1787848966, "lastModified": 1790450978,
"narHash": "sha256-7gDpu5hpq0rOYnYMcOWqSzquK4HA/xU8Xf3CjUBOOJA=", "narHash": "sha256-/eLCD/X9kaWJqPR47+fDozEC87Hjmm3i8gJbYmDAD7g=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "d57af924f160a5084293c71c2043f058bd1cdb60", "rev": "5e2305d577ca00acbba631b05cb1094d172b29f3",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1177,20 +1171,20 @@
"type": "github" "type": "github"
} }
}, },
"nixpkgs_12": { "nixpkgs_13": {
"locked": { "locked": {
"lastModified": 1787360063, "lastModified": 1790323409,
"narHash": "sha256-95aJfHyQTLWslCXFVNB0odgmVkpdmDezQwTg9mhqV1E=", "narHash": "sha256-m4DGo58Fza5ImOegtWOeE18nhpSO1IGzsVA6Lpsb4zw=",
"rev": "2c423e03bbafcff28bfadc6781a4a8257f205cb5", "rev": "e94cb152ed51bd6e24eb4a41f1460252beb52cd2",
"type": "tarball", "type": "tarball",
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1059570.2c423e03bbaf/nixexprs.tar.zst" "url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1079315.e94cb152ed51/nixexprs.tar.zst"
}, },
"original": { "original": {
"type": "tarball", "type": "tarball",
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.zst" "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.zst"
} }
}, },
"nixpkgs_13": { "nixpkgs_14": {
"locked": { "locked": {
"lastModified": 1770107345, "lastModified": 1770107345,
"narHash": "sha256-tbS0Ebx2PiA1FRW8mt8oejR0qMXmziJmPaU1d4kYY9g=", "narHash": "sha256-tbS0Ebx2PiA1FRW8mt8oejR0qMXmziJmPaU1d4kYY9g=",
@@ -1206,13 +1200,13 @@
"type": "github" "type": "github"
} }
}, },
"nixpkgs_14": { "nixpkgs_15": {
"locked": { "locked": {
"lastModified": 1787736819, "lastModified": 1789684949,
"narHash": "sha256-cV5xEJJK3BvhU8rEd4mC9UsmDi5qscv/kzGPhBRC5WA=", "narHash": "sha256-ZKhUe/2IJUq1JhKxKMu8rbkgSGmPP2ZCqlIPn40aGCM=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "9fbb54b33e91ee4ca368e35a78e0613c720600b3", "rev": "e554fab72f81915600f3f449b786fd9af40439a5",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1255,6 +1249,22 @@
} }
}, },
"nixpkgs_4": { "nixpkgs_4": {
"locked": {
"lastModified": 1787900134,
"narHash": "sha256-VYXO0XZlgj06dxJZRhrD3WoSsvq/c7+/Akyoa22pefw=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "83199d0d373dd3ac2b9a1996b1d0263f76ab7a4c",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_5": {
"locked": { "locked": {
"lastModified": 1787424095, "lastModified": 1787424095,
"narHash": "sha256-SpMiSe9OSfWseGAupsdcED3He9mTYTbGMtWb7EVt6pE=", "narHash": "sha256-SpMiSe9OSfWseGAupsdcED3He9mTYTbGMtWb7EVt6pE=",
@@ -1267,29 +1277,13 @@
"url": "https://channels.nixos.org/nixpkgs-unstable/nixexprs.tar.zst" "url": "https://channels.nixos.org/nixpkgs-unstable/nixexprs.tar.zst"
} }
}, },
"nixpkgs_5": {
"locked": {
"lastModified": 1782918843,
"narHash": "sha256-ETYnV9U7Sr+A45dohzZdfCZKOss4qrTkO+wgNZNvEc0=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "e8273b29fe1390ec8d4603f2477357555291432e",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_6": { "nixpkgs_6": {
"locked": { "locked": {
"lastModified": 1787424095, "lastModified": 1787631388,
"narHash": "sha256-dWLO5AHhKaw6rdWCtTes8hnntT1r0/J5yhQGm0f0ZgU=", "narHash": "sha256-vMiXptXarfSdJb1Gkc+FYVOAibuBRj7qxGa8z68q1Uw=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "174eb786fb68e3a13e4e535a3deea479a0c07a6a", "rev": "ac6b2166e7a9375683b8e98f860f273222337b16",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1300,6 +1294,22 @@
} }
}, },
"nixpkgs_7": { "nixpkgs_7": {
"locked": {
"lastModified": 1790510107,
"narHash": "sha256-EVMNYv7hYDDD9TGVT/hIyTYgpiXA8y3m5xIEIxuGNU0=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "3181085bfd08663b6b9e60bc7a8395c2aaa741bd",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_8": {
"locked": { "locked": {
"lastModified": 1785454630, "lastModified": 1785454630,
"narHash": "sha256-LQy14TZp77TwbQf40gg1V3jo8FwJG0jGDkAH+zRHqg8=", "narHash": "sha256-LQy14TZp77TwbQf40gg1V3jo8FwJG0jGDkAH+zRHqg8=",
@@ -1315,7 +1325,7 @@
"type": "github" "type": "github"
} }
}, },
"nixpkgs_8": { "nixpkgs_9": {
"locked": { "locked": {
"lastModified": 1785828668, "lastModified": 1785828668,
"narHash": "sha256-8fsyqeO+mJqvIzeO4xIpgJe/f7MTbbVTEC6RT6WSXNs=", "narHash": "sha256-8fsyqeO+mJqvIzeO4xIpgJe/f7MTbbVTEC6RT6WSXNs=",
@@ -1331,33 +1341,20 @@
"type": "github" "type": "github"
} }
}, },
"nixpkgs_9": {
"locked": {
"lastModified": 1767892417,
"narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=",
"rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba",
"type": "tarball",
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre924538.3497aa5c9457/nixexprs.tar.xz"
},
"original": {
"type": "tarball",
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
}
},
"nixvim": { "nixvim": {
"inputs": { "inputs": {
"flake-parts": "flake-parts_5", "flake-parts": "flake-parts_5",
"nixpkgs": [ "nixpkgs": [
"nixpkgs" "nixpkgs"
], ],
"systems": "systems_7" "systems": "systems_6"
}, },
"locked": { "locked": {
"lastModified": 1787536726, "lastModified": 1789959143,
"narHash": "sha256-aBh5Yk9tX8ZV4k10BJr2fvTq0/+iWGegaCMUOU7YKas=", "narHash": "sha256-9oBHyJtUyunZL+6v0Ub8Y759cXcejQiTHpXtGcx5RLs=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nixvim", "repo": "nixvim",
"rev": "e2c3f9f36326d07340626847543c557e2b95fb50", "rev": "4836e77b1798cd42e2de28593bec4c1788da08f5",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1369,14 +1366,14 @@
}, },
"noctalia": { "noctalia": {
"inputs": { "inputs": {
"nixpkgs": "nixpkgs_12" "nixpkgs": "nixpkgs_13"
}, },
"locked": { "locked": {
"lastModified": 1788012673, "lastModified": 1790523212,
"narHash": "sha256-Qzdrf8phPKo31TTqVdDv6vVv9EwQRWnf5HPKUoDDdPM=", "narHash": "sha256-Z8SuI0YgAZaF0sumKPBF85PxPtTjpo8jvtphbgoITv8=",
"owner": "noctalia-dev", "owner": "noctalia-dev",
"repo": "noctalia", "repo": "noctalia",
"rev": "29dab93fdf9091f83f9eec20a20e72e11fc4e6c4", "rev": "08c30392b1350b4f3d3fb77e23732560559f1638",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1394,16 +1391,16 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1787953571, "lastModified": 1789761689,
"narHash": "sha256-cUly+bzaPwj9fiUmC+Gh7gwKAZjINCKZKGf/gPMhJJg=", "narHash": "sha256-kZmr3Bd0ehbq43/rDXtkuexWpMN8HyE0iqw1LlaartM=",
"owner": "vicinaehq", "owner": "vicinaehq",
"repo": "numen", "repo": "numen",
"rev": "7cfed1e8322ac6ebd0db9cbf0db31e27385965bc", "rev": "7379178f9c2fc4dc0c1965c1800e62ef764118f4",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "vicinaehq", "owner": "vicinaehq",
"ref": "v0.5.1", "ref": "v0.6.2",
"repo": "numen", "repo": "numen",
"type": "github" "type": "github"
} }
@@ -1435,18 +1432,18 @@
}, },
"pre-commit": { "pre-commit": {
"inputs": { "inputs": {
"flake-compat": "flake-compat_5", "flake-compat": "flake-compat_4",
"nixpkgs": [ "nixpkgs": [
"lanzaboote", "lanzaboote",
"nixpkgs" "nixpkgs"
] ]
}, },
"locked": { "locked": {
"lastModified": 1787424939, "lastModified": 1789514889,
"narHash": "sha256-O2tBn84NNuHrnqNVxx/XqsXwfYvS1YwBh+7CBnbCYsk=", "narHash": "sha256-PFD1nxptCXJyJoiYO1gf/5Vv43yqGpHtMC6LUhl9/pQ=",
"owner": "cachix", "owner": "cachix",
"repo": "git-hooks.nix", "repo": "git-hooks.nix",
"rev": "809414f0cdadf82cf11b06c2b29ba9b3168b3297", "rev": "59f4ca0d063a1a3ec722c88b51a33004862e5379",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1460,7 +1457,7 @@
"browser-previews": "browser-previews", "browser-previews": "browser-previews",
"codex-desktop-linux": "codex-desktop-linux", "codex-desktop-linux": "codex-desktop-linux",
"codex-session-usage": "codex-session-usage", "codex-session-usage": "codex-session-usage",
"deploy-rs": "deploy-rs", "containerlab": "containerlab",
"disko": "disko", "disko": "disko",
"flake-parts": "flake-parts_3", "flake-parts": "flake-parts_3",
"ghostty": "ghostty", "ghostty": "ghostty",
@@ -1475,7 +1472,7 @@
"nix-index-database": "nix-index-database", "nix-index-database": "nix-index-database",
"nixos-hardware": "nixos-hardware", "nixos-hardware": "nixos-hardware",
"nixos-wsl": "nixos-wsl", "nixos-wsl": "nixos-wsl",
"nixpkgs": "nixpkgs_11", "nixpkgs": "nixpkgs_12",
"nixpkgs-unstable": "nixpkgs-unstable", "nixpkgs-unstable": "nixpkgs-unstable",
"nixvim": "nixvim", "nixvim": "nixvim",
"noctalia": "noctalia", "noctalia": "noctalia",
@@ -1483,7 +1480,7 @@
"skills": "skills", "skills": "skills",
"sops-nix": "sops-nix", "sops-nix": "sops-nix",
"stylix": "stylix", "stylix": "stylix",
"systems": "systems_9", "systems": "systems_8",
"treefmt-nix": "treefmt-nix_4", "treefmt-nix": "treefmt-nix_4",
"vicinae": "vicinae", "vicinae": "vicinae",
"vicinae-extensions": "vicinae-extensions" "vicinae-extensions": "vicinae-extensions"
@@ -1519,11 +1516,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1787454509, "lastModified": 1789889921,
"narHash": "sha256-r4LDUF+zmJnkftvCVkCrUhSJazsf6EVJF+V2l4/MYbI=", "narHash": "sha256-aL/ogiN7qZCGeNovS1f9hX73jwYIKb4Pcq6AZm57WtY=",
"owner": "oxalica", "owner": "oxalica",
"repo": "rust-overlay", "repo": "rust-overlay",
"rev": "f60c1b57ff805a46b5175c76fc981fb4f81efbcc", "rev": "1fb104a12a8667045559b2575d6d448ae2fbd99b",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1534,11 +1531,11 @@
}, },
"services-flake": { "services-flake": {
"locked": { "locked": {
"lastModified": 1787074068, "lastModified": 1790475157,
"narHash": "sha256-z0CqDCjs+xU/Yw2/VkS8Mz7qzw4AsZ+AMwEMmqSSKh0=", "narHash": "sha256-CUvrxb5wdBRcpwi89yfgw4IUqhBjjt+BUtsNQVM+5jM=",
"owner": "juspay", "owner": "juspay",
"repo": "services-flake", "repo": "services-flake",
"rev": "4f56c8f1cbd09c774a491a47acd3605a6eb7adfa", "rev": "aa72532e193ee212055df9e1c3eb07aa0ccafabb",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1550,11 +1547,11 @@
"skills": { "skills": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1787581197, "lastModified": 1789726349,
"narHash": "sha256-N5tpUIHO2VFeJntBTl6/VLDIVpqoshwFxNJlfXXUwsQ=", "narHash": "sha256-L3CpIT2DeI+fUFl9fcygojtQo2DzEen69rMD1XqR1vM=",
"owner": "mattpocock", "owner": "mattpocock",
"repo": "skills", "repo": "skills",
"rev": "6654f6b60cd9d5be8b54c6fafe44346dabeb3b76", "rev": "c55ee46073ed923f86ce59a5eb3b6d895095d1b7",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1570,11 +1567,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786629091, "lastModified": 1790498116,
"narHash": "sha256-gkig4nPi1CWc4Z50GBsjE4ygSE7hMpl/TwID2an2Cck=", "narHash": "sha256-rs9meAYxW3zzrh43yaW7htrqCD+X9+pupDPHN86fumI=",
"owner": "Mic92", "owner": "Mic92",
"repo": "sops-nix", "repo": "sops-nix",
"rev": "a8627b21b9107c5711c96b84f32a9a4b3d45295f", "rev": "5efb5a6f4f5ab192817d28557dd4d650fa14d866",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1618,18 +1615,18 @@
"nixpkgs" "nixpkgs"
], ],
"nur": "nur", "nur": "nur",
"systems": "systems_8", "systems": "systems_7",
"tinted-kitty": "tinted-kitty", "tinted-kitty": "tinted-kitty",
"tinted-schemes": "tinted-schemes", "tinted-schemes": "tinted-schemes",
"tinted-tmux": "tinted-tmux", "tinted-tmux": "tinted-tmux",
"tinted-zed": "tinted-zed" "tinted-zed": "tinted-zed"
}, },
"locked": { "locked": {
"lastModified": 1787771653, "lastModified": 1790451534,
"narHash": "sha256-DkkJSBOXWV/mja5Vy8az5g1KpZlsbUwlmH0BsQhowaQ=", "narHash": "sha256-5J4zQ0mmCsd2SS+sOKdzXrngofQdtube3VoHSENz4zE=",
"owner": "nix-community", "owner": "nix-community",
"repo": "stylix", "repo": "stylix",
"rev": "5e3809851f486e7fc7e84b40f174c74b60ecc784", "rev": "fb28acd59e2ac1984ec84fa496599d6b4bf3e690",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1668,21 +1665,6 @@
"type": "github" "type": "github"
} }
}, },
"systems_11": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"systems_2": { "systems_2": {
"locked": { "locked": {
"lastModified": 1681028828, "lastModified": 1681028828,
@@ -1714,6 +1696,7 @@
} }
}, },
"systems_4": { "systems_4": {
"flake": false,
"locked": { "locked": {
"lastModified": 1681028828, "lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
@@ -1729,7 +1712,6 @@
} }
}, },
"systems_5": { "systems_5": {
"flake": false,
"locked": { "locked": {
"lastModified": 1681028828, "lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
@@ -1760,21 +1742,6 @@
} }
}, },
"systems_7": { "systems_7": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"systems_8": {
"locked": { "locked": {
"lastModified": 1774449309, "lastModified": 1774449309,
"narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=", "narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=",
@@ -1790,6 +1757,21 @@
"type": "github" "type": "github"
} }
}, },
"systems_8": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"systems_9": { "systems_9": {
"locked": { "locked": {
"lastModified": 1681028828, "lastModified": 1681028828,
@@ -1937,7 +1919,7 @@
}, },
"treefmt-nix_4": { "treefmt-nix_4": {
"inputs": { "inputs": {
"nixpkgs": "nixpkgs_13" "nixpkgs": "nixpkgs_14"
}, },
"locked": { "locked": {
"lastModified": 1786901030, "lastModified": 1786901030,
@@ -1953,37 +1935,19 @@
"type": "github" "type": "github"
} }
}, },
"utils": {
"inputs": {
"systems": "systems_4"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"vicinae": { "vicinae": {
"inputs": { "inputs": {
"nixpkgs": "nixpkgs_14", "nixpkgs": "nixpkgs_15",
"numen": "numen", "numen": "numen",
"soulver-cpp": "soulver-cpp", "soulver-cpp": "soulver-cpp",
"systems": "systems_10" "systems": "systems_9"
}, },
"locked": { "locked": {
"lastModified": 1787956866, "lastModified": 1790526610,
"narHash": "sha256-SCFAyDbNIXcFRGw0nx2yVY47hMSHzMFAQOsUXdJJ6sc=", "narHash": "sha256-rmgEQklUdHJ4wLCX5sa1rVkeiu2atFWJ3likgVw/5gA=",
"owner": "vicinaehq", "owner": "vicinaehq",
"repo": "vicinae", "repo": "vicinae",
"rev": "47857b0b4af6b269ddbc5f34b661f0eb9d9bdeb5", "rev": "8d80bf6011de177a19f1b5f1243ec505f441b7e7",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -1994,19 +1958,19 @@
}, },
"vicinae-extensions": { "vicinae-extensions": {
"inputs": { "inputs": {
"flake-compat": "flake-compat_7", "flake-compat": "flake-compat_6",
"nixpkgs": [ "nixpkgs": [
"nixpkgs" "nixpkgs"
], ],
"systems": "systems_11", "systems": "systems_10",
"vicinae": "vicinae_2" "vicinae": "vicinae_2"
}, },
"locked": { "locked": {
"lastModified": 1788004886, "lastModified": 1790242820,
"narHash": "sha256-YVr/SysyzG2lkSpacrEC/Mo7XdUYdKu5vX2AUcqAzpQ=", "narHash": "sha256-xG2Nvdhl+lcguYzkAHf6RkHQpM8c3rbN0NDHUiwT4CA=",
"owner": "vicinaehq", "owner": "vicinaehq",
"repo": "extensions", "repo": "extensions",
"rev": "de926d2e94ff4423dc04068eb2b6fc8d501f3b74", "rev": "def646b3655e13759d2b0a7b9d605f55fe83a5f7",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -2110,11 +2074,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1784080626, "lastModified": 1788977680,
"narHash": "sha256-Hvnmnuu0VpHiZl+8z+UkMoxC7JZJvRYBqu2Asb0ZJOE=", "narHash": "sha256-3vgICcen5N2oAlQrijqJhxn8HEsnXASGPxQLJVYzX0Q=",
"owner": "jcollie", "owner": "jcollie",
"repo": "zon2nix", "repo": "zon2nix",
"rev": "776b5f6864a607c141d7966421b433fa1657ba9a", "rev": "7b9c43312de08e176097b8c8920f0dd1a46982be",
"type": "github" "type": "github"
}, },
"original": { "original": {
+1 -5
View File
@@ -60,11 +60,6 @@
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
deploy-rs = {
url = "github:serokell/deploy-rs";
inputs.nixpkgs.follows = "nixpkgs";
};
# Disk management # Disk management
disko = { disko = {
url = "github:nix-community/disko"; url = "github:nix-community/disko";
@@ -119,6 +114,7 @@
nani-translate-linux.url = "git+https://github.com/zunoser/nani-translate-linux.git"; nani-translate-linux.url = "git+https://github.com/zunoser/nani-translate-linux.git";
containerlab.url = "github:srl-labs/containerlab";
}; };
outputs = outputs =
-1
View File
@@ -1,6 +1,5 @@
{ {
imports = [ imports = [
./deploy.nix
./formatter.nix ./formatter.nix
./git-hooks.nix ./git-hooks.nix
./registry.nix ./registry.nix
-28
View File
@@ -1,28 +0,0 @@
{
inputs,
self,
...
}:
{
flake.deploy = {
nodes.nix-builder = {
hostname = "nix-builder";
sshUser = "moons";
user = "root";
interactiveSudo = true;
remoteBuild = true;
autoRollback = true;
magicRollback = true;
profiles.system.path = inputs.deploy-rs.lib.x86_64-linux.activate.nixos self.nixosConfigurations.nix-builder;
};
};
perSystem =
{ system, ... }:
{
apps.deploy = inputs.deploy-rs.apps.${system}.default;
checks = inputs.deploy-rs.lib.${system}.deployChecks self.deploy;
};
}
+35 -3
View File
@@ -7,14 +7,43 @@
profiles = [ profiles = [
"base" "base"
"interface.cli" "interface.minimal"
"networking.tailscale-client"
"platform.vm" "platform.vm"
"workload.nix-builder"
"workload.remote-access" "workload.remote-access"
]; ];
}; };
ops = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./ops;
profiles = [
"base"
"interface.minimal"
"platform.vm"
"workload.remote-access"
"workload.deploy-rs-target"
];
};
netsrv-01 = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./netsrv-01;
profiles = [
"base"
"interface.minimal"
"platform.vm"
"workload.remote-access"
"workload.deploy-rs-target"
"workload.server"
];
};
installer = { installer = {
system = "x86_64-linux"; system = "x86_64-linux";
stateVersion = "26.05"; stateVersion = "26.05";
@@ -62,6 +91,7 @@
"security.tpm-storage" "security.tpm-storage"
"workload.development" "workload.development"
"workload.game" "workload.game"
"workload.network-lab"
"workload.personal" "workload.personal"
]; ];
@@ -87,7 +117,9 @@
"workload.development" "workload.development"
"workload.game" "workload.game"
"workload.machine-learning" "workload.machine-learning"
"workload.network-lab"
"workload.personal" "workload.personal"
"workload.photography"
"workload.camera" "workload.camera"
]; ];
}; };
+17 -23
View File
@@ -76,6 +76,12 @@
║ ║ ║ ║
║ Installation Workflow: ║ ║ Installation Workflow: ║
║ ║ ║ ║
║ Choose a guide after cloning: ║
║ Simple: docs/install-simple.md ║
║ SOPS + LUKS: docs/install.md ║
║ ║
║ The workflow below is for SOPS + LUKS: ║
║ ║
║ 1. Clone dotfiles: ║ ║ 1. Clone dotfiles: ║
║ git clone git@github.com:moons-14/dotfiles.git ~/dotfiles║ ║ git clone git@github.com:moons-14/dotfiles.git ~/dotfiles║
║ ║ ║ ║
@@ -103,36 +109,24 @@
║ # See hosts/x1g13/disko.nix for reference ║ ║ # See hosts/x1g13/disko.nix for reference ║
║ ║ ║ ║
║ 7. Partition disk with disko: ║ ║ 7. Partition disk with disko: ║
║ nix run github:nix-community/disko -- \ ║ ║ disko --mode destroy,format,mount \ ║
║ --mode disko hosts/<host>/disko.nix ║ ║ hosts/<host>/disko.nix ║
║ ║ ║ ║
║ 8. Copy host key to installed system: ║ ║ 8. Generate hardware configuration: ║
║ nixos-generate-config --no-filesystems --root /mnt \ ║
║ --show-hardware-config > \ ║
║ ~/dotfiles/hosts/<host>/hardware-configuration.nix ║
║ # Import hardware-configuration.nix and disko.nix ║
║ # from hosts/<host>/nixos.nix ║
║ ║
║ 9. Copy host key to installed system: ║
║ mkdir -p /mnt/etc/ssh ║ ║ mkdir -p /mnt/etc/ssh ║
║ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ ║ ║ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ ║
║ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ║ ║ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ║
║ ║ ║ ║
║ 9. Install NixOS: ║ ║ 10. Install NixOS: ║
║ nixos-install --flake ~/dotfiles#<host> ║ ║ nixos-install --flake ~/dotfiles#<host> ║
║ ║ ║ ║
║ Disko Configuration Examples: ║
║ ║
║ Simple (no encryption): ║
║ disko.devices.disk.main = { ║
║ type = "disk"; ║
║ device = "/dev/sda"; ║
║ content = { ║
║ type = "gpt"; ║
║ partitions = { ║
║ ESP = { size = "512M"; type = "EF00"; ║
║ content = { type = "filesystem"; ║
║ format = "vfat"; mountpoint = "/boot"; }; }; ║
║ root = { size = "100%"; ║
║ content = { type = "filesystem"; ║
║ format = "ext4"; mountpoint = "/"; }; }; ║
║ }; ║
║ }; ║
║ }; ║
║ ║
║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║ ║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║
║ - Use partuuid for device path ║ ║ - Use partuuid for device path ║
║ - Set askPassword = true for LUKS ║ ║ - Set askPassword = true for LUKS ║
+30
View File
@@ -0,0 +1,30 @@
_: {
disko.enableConfig = true;
disko.devices.disk.main = {
type = "disk";
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
content = {
type = "gpt";
partitions = {
ESP = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
root = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
};
};
};
}
@@ -0,0 +1,27 @@
# QEMU hardware baseline. Replace this with the output of
# `nixos-generate-config` after provisioning the VM if its hardware differs.
{
lib,
modulesPath,
...
}:
{
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [
"ata_piix"
"uhci_hcd"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
+40
View File
@@ -0,0 +1,40 @@
{
networking = {
interfaces = {
ens18 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.65.11";
prefixLength = 24;
}
];
};
ens19 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.66.10";
prefixLength = 24;
}
];
};
ens20 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.77.21";
prefixLength = 24;
}
];
};
};
defaultGateway = {
address = "10.50.66.1";
interface = "ens19";
};
};
}
+7
View File
@@ -0,0 +1,7 @@
{
imports = [
./hardware-configuration.nix
./disko.nix
./networking.nix
];
}
-101
View File
@@ -1,101 +0,0 @@
# nix-builder bootstrap
The host configuration can be built before its cache signing secret exists.
Harmonia's socket remains stopped until SOPS installs the signing key at
`/run/secrets/harmonia/signing-key`.
## Proxmox storage layout
The host configuration expects three filesystems. Keep the build scratch space
separate from the store so a large build cannot fill the root filesystem.
| Mount point | Suggested size | Contents |
| -------------------- | -------------- | ------------------------------- |
| `/` | 48 GiB | NixOS and mutable system state |
| `/var/lib/nix-build` | 192 GiB | Disposable build scratch space |
| `/nix/store` | 1 TiB | Fleet closures and binary cache |
The build-server policy starts emergency store GC below 64 GiB free and aims
for 128 GiB free. Persistent roots under `/var/lib/nix-fleet/roots` protect the
latest fleet builds from that GC. It also limits Nix to two concurrent
derivations while allowing each derivation to use every vCPU assigned to the
VM.
For the two dedicated ext4 data filesystems, remove the default root-reserved
blocks once after formatting; keep the root filesystem's reserve intact:
```bash
sudo tune2fs -m 0 /dev/disk/by-label/nix-build
sudo tune2fs -m 0 /dev/disk/by-label/nix-store
```
## Initial deployment
Once the VM is reachable as `moons@nix-builder`, deploy it from the repository:
```bash
nix run .#deploy -- .#nix-builder
```
deploy-rs uses the target's `ssh-ng` store, so the system closure is built on
the builder rather than copied from the laptop. Automatic and magic rollback
remain enabled.
## Add the host SOPS recipient
After the VM has a stable SSH host key, derive its age recipient:
```bash
ssh-keyscan -t ed25519 nix-builder 2>/dev/null | ssh-to-age
```
Add the recipient to `.sops.yaml` and add a creation rule for
`secrets/hosts/nix-builder/*.yaml`. The admin YubiKey recipient should remain in
the same key group for recovery.
## Generate the cache signing key
Run this on a trusted Nix machine, preferably with the temporary files on a
tmpfs:
```bash
nix-store --generate-binary-cache-key \
cache.app.homelabs.run-1 \
harmonia.private \
harmonia.public
```
Create `secrets/hosts/nix-builder/system.yaml` with SOPS and store the complete
contents of `harmonia.private` at `harmonia.signing-key`:
```yaml
harmonia:
signing-key: cache.app.homelabs.run-1:REDACTED
```
Copy the complete contents of `harmonia.public` to
`modules/systems/nix/homelab-cache/public-key`. The private plaintext file must
not be committed or retained.
After committing both encrypted/public files, select
`networking.homelab-cache-client` on each client host.
Redeploy the builder and verify the cache after installing the secret:
```bash
nix run .#deploy -- .#nix-builder
curl --fail http://nix-builder:5000/nix-cache-info
```
## Normal operation
Run `fleet-build` on the builder to build and root every NixOS host, or pass a
list of host names to build only those hosts. Run `fleet-deploy` with the normal
deploy-rs target syntax when additional fleet nodes have been added to
`flake/deploy.nix`:
```bash
fleet-build
fleet-build x1g13 galleria
fleet-deploy .#nix-builder
```
+66
View File
@@ -0,0 +1,66 @@
_:
let
osDisk = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
in
{
disko.enableConfig = true;
# The VM disks already contain live filesystems. Model each existing
# filesystem without giving Disko ownership of their partitioning or data.
disko.devices.disk = {
boot = {
type = "disk";
device = "${osDisk}-part1";
destroy = false;
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
root = {
type = "disk";
device = "${osDisk}-part2";
destroy = false;
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
nix-build = {
type = "disk";
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi1";
destroy = false;
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/var/lib/nix-build";
mountOptions = [ "noatime" ];
};
};
nix-store = {
type = "disk";
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi2";
destroy = false;
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/nix/store";
mountOptions = [ "noatime" ];
};
};
};
fileSystems."/nix/store".neededForBoot = true;
nix.settings.build-dir = "/var/lib/nix-build";
services.fstrim.enable = true;
}
-25
View File
@@ -1,25 +0,0 @@
{
fileSystems."/nix/store" = {
device = "/dev/disk/by-label/nix-store";
fsType = "ext4";
options = [
"noatime"
];
neededForBoot = true;
};
fileSystems."/var/lib/nix-build" = {
device = "/dev/disk/by-label/nix-build";
fsType = "ext4";
options = [
"noatime"
];
};
nix.settings.build-dir = "/var/lib/nix-build";
services.fstrim.enable = true;
}
+83
View File
@@ -0,0 +1,83 @@
{
config,
pkgs,
primaryUser,
...
}:
let
homeDirectory = "/home/${primaryUser}";
fleetDirectory = "${homeDirectory}/srv/nix-fleet";
stateDirectory = "/var/lib/nix-fleet";
sourceDirectory = "${stateDirectory}/source";
git = "${pkgs.git}/bin/git";
nix = "${config.nix.package}/bin/nix";
rsync = "${pkgs.rsync}/bin/rsync";
cleanCheckoutConditions = [
"${git} -C ${fleetDirectory} diff --quiet"
"${git} -C ${fleetDirectory} diff --cached --quiet"
];
in
{
systemd.services.nix-fleet-converge = {
description = "Update inputs, build the fleet, and deploy changed hosts";
wants = [ "network-online.target" ];
after = [ "network-online.target" ];
environment = {
HOME = homeDirectory;
NIX_CONFIG = ''
accept-flake-config = true
max-jobs = 4
cores = 3
'';
};
serviceConfig = {
Type = "oneshot";
User = primaryUser;
Restart = "on-failure";
RestartSec = "5min";
StateDirectory = "nix-fleet";
StateDirectoryMode = "0750";
WorkingDirectory = stateDirectory;
UMask = "0077";
ExecCondition = cleanCheckoutConditions;
EnvironmentFile = "${fleetDirectory}/.env";
# Work in a disposable copy so updating the dotfiles lock never dirties
# the operator's nix-fleet checkout.
ExecStart = [
"${git} -C ${fleetDirectory} pull --ff-only"
"${rsync} --archive --delete --exclude=.git/ --exclude=.direnv/ --exclude=.env --exclude=result --exclude=result-* ${fleetDirectory}/ ${sourceDirectory}/"
"${nix} flake update --flake ${sourceDirectory} dotfiles"
"${nix} run ${sourceDirectory}#converge -- ${sourceDirectory} ${stateDirectory}"
];
};
};
systemd.timers.nix-fleet-converge = {
description = "Periodically converge the NixOS fleet";
wantedBy = [ "timers.target" ];
timerConfig = {
OnBootSec = "2min";
OnUnitInactiveSec = "5min";
RandomizedDelaySec = "30s";
Persistent = true;
Unit = "nix-fleet-converge.service";
};
};
# Only an actual successful deployment touches gc-request. This starts the
# builder's root nh-clean unit; remote host stores are never cleaned here.
systemd.paths.nix-fleet-gc = {
description = "Garbage-collect superseded fleet builds on nix-builder";
wantedBy = [ "multi-user.target" ];
pathConfig = {
PathChanged = "${stateDirectory}/gc-request";
Unit = "nh-clean.service";
};
};
}
@@ -20,20 +20,6 @@
boot.kernelModules = [ ]; boot.kernelModules = [ ];
boot.extraModulePackages = [ ]; boot.extraModulePackages = [ ];
fileSystems."/" = {
device = "/dev/disk/by-uuid/49fc2e1c-7909-41cc-ac78-55b4d9a01e62";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/40D4-ABBE";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [ ]; swapDevices = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
+37
View File
@@ -0,0 +1,37 @@
{
lib,
...
}:
{
nix.settings = {
build-dir = "/var/lib/nix-build";
secret-key-files = [
"/var/lib/secrets/nix-cache-signing-key"
];
auto-optimise-store = lib.mkForce false;
keep-outputs = false;
keep-derivations = true;
};
services.harmonia.cache = {
enable = true;
signKeyPaths = [
"/var/lib/secrets/nix-cache-signing-key"
];
settings = {
bind = "[::]:5000";
priority = 30;
workers = 4;
};
};
networking.firewall.allowedTCPPorts = [
5000
];
}
+40
View File
@@ -0,0 +1,40 @@
{
networking = {
interfaces = {
ens18 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.65.10";
prefixLength = 24;
}
];
};
ens19 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.77.10";
prefixLength = 24;
}
];
};
ens20 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.68.10";
prefixLength = 24;
}
];
};
};
defaultGateway = {
address = "10.50.68.1";
interface = "ens20";
};
};
}
+4 -14
View File
@@ -1,19 +1,9 @@
{ lib, ... }:
let
hostSecrets = ../../secrets/hosts/nix-builder/system.yaml;
in
{ {
imports = [ imports = [
./filesystem.nix ./fleet-automation.nix
./disko.nix
./hardware-configuration.nix ./hardware-configuration.nix
./harmonia.nix
./networking.nix
]; ];
sops.secrets = lib.mkIf (builtins.pathExists hostSecrets) {
"harmonia/signing-key" = {
sopsFile = hostSecrets;
restartUnits = [ "harmonia.service" ];
};
};
networking.firewall.interfaces."tailscale0".allowedTCPPorts = [ 5000 ];
} }
@@ -1,36 +0,0 @@
# Do not modify this file! It was generated by `nixos-generate-config` and may
# be overwritten by future invocations.
{ lib, modulesPath, ... }:
{
imports = [ (modulesPath + "/profiles/qemu-guest.nix") ];
boot.initrd.availableKernelModules = [
"ata_piix"
"uhci_hcd"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" = {
device = "/dev/disk/by-uuid/8f0eaec6-5dc9-4821-aa8d-fb6809b5a5bf";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/201C-961B";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
-3
View File
@@ -1,3 +0,0 @@
{
imports = [ ./hardware-configuration.nix ];
}
+30
View File
@@ -0,0 +1,30 @@
_: {
disko.enableConfig = true;
disko.devices.disk.main = {
type = "disk";
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
content = {
type = "gpt";
partitions = {
ESP = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
root = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
};
};
};
}
+28
View File
@@ -0,0 +1,28 @@
# Do not modify this file! It was generated by ‘nixos-generate-config’
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{
lib,
modulesPath,
...
}:
{
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [
"ata_piix"
"uhci_hcd"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
+40
View File
@@ -0,0 +1,40 @@
{
networking = {
interfaces = {
ens18 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.65.100";
prefixLength = 24;
}
];
};
ens19 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.80.10";
prefixLength = 24;
}
];
};
ens20 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.77.20";
prefixLength = 24;
}
];
};
};
defaultGateway = {
address = "10.50.80.1";
interface = "ens19";
};
};
}
+7
View File
@@ -0,0 +1,7 @@
{
imports = [
./hardware-configuration.nix
./networking.nix
./disko.nix
];
}
@@ -0,0 +1,8 @@
{ inputs, ... }:
{
description = "Container-based networking labs";
includes = [ "services.docker" ];
imports.nixos = [ inputs.containerlab.nixosModules.default ];
}
@@ -0,0 +1,17 @@
{
inputs,
pkgs,
primaryUser,
}:
{
programs.containerlab.enable = true;
users.users.${primaryUser}.extraGroups = [ "clab_admins" ];
programs.containerlab.package =
inputs.containerlab.packages.${pkgs.stdenv.hostPlatform.system}.default.overrideAttrs
(_old: {
vendorHash = "sha256-xp6YIoqJdUu1zEzw7s7+lh8iGJD4THokF5NPbxLH6zc=";
});
}
@@ -0,0 +1,22 @@
{
inputs,
osConfig,
pkgs,
...
}:
let
unstable = import inputs.nixpkgs-unstable {
inherit (pkgs.stdenv.hostPlatform) system;
# Keep default CUDA targets so dependencies match the CUDA binary cache.
config = pkgs.config // {
cudaSupport = osConfig.my.hardwares.nvidia.enable;
};
};
in
{
home.packages = [
(unstable.darktable.override {
withAi = true;
})
];
}
-2
View File
@@ -38,8 +38,6 @@ in
ignores = [ ignores = [
".direnv/" ".direnv/"
".envrc"
"!.envrc.example"
]; ];
signing = { signing = {
+4
View File
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.htop ];
}
-1
View File
@@ -127,7 +127,6 @@ in
(execute "W-C-j" "${lib.getExe' pkgs.xdg-utils "xdg-open"} naniapp://translate") (execute "W-C-j" "${lib.getExe' pkgs.xdg-utils "xdg-open"} naniapp://translate")
(execute "W-space" "ghostty +toggle-quick-terminal") (execute "W-space" "ghostty +toggle-quick-terminal")
(execute "W-p" "wdisplays") (execute "W-p" "wdisplays")
(execute "W-z" "wl-find-cursor -c 0xCCFF453A -s 160 -d 1200")
# Function keys (sync with niri modules/applications/niri/home.nix) # Function keys (sync with niri modules/applications/niri/home.nix)
(execute "XF86AudioRaiseVolume" "noctalia msg volume-up") (execute "XF86AudioRaiseVolume" "noctalia msg volume-up")
-1
View File
@@ -4,6 +4,5 @@
includes = [ includes = [
"systems.wayland" "systems.wayland"
"applications.screenshot" "applications.screenshot"
"applications.wl-find-cursor"
]; ];
} }
+4
View File
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.nano ];
}
@@ -0,0 +1,5 @@
{
description = "Sipeed NanoKVM-USB desktop client";
includes = [ "services.nanokvm-usb" ];
}
@@ -0,0 +1,42 @@
{ pkgs, ... }:
let
pname = "nanokvm-usb";
version = "1.1.4";
src = pkgs.fetchurl {
url = "https://github.com/sipeed/NanoKVM-USB/releases/download/v${version}/NanoKVM-USB-${version}-linux-x86_64.AppImage";
hash = "sha256-00MT4U2afv0qt3xFVhLr0SSmS2cLrKBlmfzqYEFuaVc=";
};
appimageContents = pkgs.appimageTools.extractType2 {
inherit pname src version;
};
nanokvm-usb = pkgs.appimageTools.wrapType2 {
inherit pname src version;
meta = {
description = "Sipeed NanoKVM-USB desktop client";
homepage = "https://github.com/sipeed/NanoKVM-USB";
license = pkgs.lib.licenses.gpl3Only;
platforms = [ "x86_64-linux" ];
mainProgram = "nanokvm-usb";
};
};
desktopItem = pkgs.makeDesktopItem {
name = pname;
desktopName = "NanoKVM-USB";
comment = "NanoKVM-USB Desktop";
exec = "nanokvm-usb --no-sandbox %U";
icon = "${appimageContents}/nanokvm-usb.png";
categories = [ "Utility" ];
startupWMClass = "NanoKVM-USB";
};
in
{
environment.systemPackages = [
nanokvm-usb
desktopItem
];
}
-13
View File
@@ -139,19 +139,6 @@ in
action.spawn = "wdisplays"; action.spawn = "wdisplays";
hotkey-overlay.title = "Display Settings: wdisplays"; hotkey-overlay.title = "Display Settings: wdisplays";
}; };
"Mod+Z" = {
action.spawn = [
"wl-find-cursor"
"-c"
"0xCCFF453A"
"-s"
"160"
"-d"
"1200"
];
hotkey-overlay.title = "Find Cursor";
};
# Function keys (sync with labwc modules/applications/labwc/home.nix) # Function keys (sync with labwc modules/applications/labwc/home.nix)
"XF86AudioRaiseVolume".action.spawn = [ "XF86AudioRaiseVolume".action.spawn = [
"noctalia" "noctalia"
-1
View File
@@ -5,7 +5,6 @@
includes = [ includes = [
"systems.wayland" "systems.wayland"
"applications.screenshot" "applications.screenshot"
"applications.wl-find-cursor"
]; ];
imports = { imports = {
-3
View File
@@ -1,3 +0,0 @@
{
description = "Fleet build and deploy command-line tools";
}
-63
View File
@@ -1,63 +0,0 @@
{
inputs,
pkgs,
primaryUser,
...
}:
let
system = pkgs.stdenv.hostPlatform.system;
deployRs = inputs.deploy-rs.packages.${system}.default;
fleetBuild = pkgs.writeShellApplication {
name = "fleet-build";
runtimeInputs = [
pkgs.jq
pkgs.nix
];
text = ''
flake_ref="''${FLAKE:-/home/${primaryUser}/dotfiles}"
if (( $# == 0 )); then
# Keep this pipeline inside command substitution so pipefail and
# writeShellApplication's errexit propagate evaluation failures.
host_lines="$(
nix eval --json "$flake_ref#nixosConfigurations" \
--apply 'configs: builtins.attrNames configs' |
jq -r '.[] | select(. != "installer")'
)"
if [[ -z "$host_lines" ]]; then
echo "No deployable NixOS hosts found in $flake_ref" >&2
exit 1
fi
mapfile -t hosts <<< "$host_lines"
else
hosts=("$@")
fi
for host in "''${hosts[@]}"; do
nix build \
--out-link "/var/lib/nix-fleet/roots/build/$host" \
"$flake_ref#nixosConfigurations.$host.config.system.build.toplevel"
done
'';
};
fleetDeploy = pkgs.writeShellApplication {
name = "fleet-deploy";
runtimeInputs = [ deployRs ];
text = ''
cd "''${FLAKE:-/home/${primaryUser}/dotfiles}" || exit 1
exec deploy \
--keep-result \
--result-path /var/lib/nix-fleet/roots/deploy \
"$@"
'';
};
in
{
environment.systemPackages = [
fleetBuild
fleetDeploy
];
}
+15 -4
View File
@@ -13,10 +13,6 @@ lib.mkMerge [
User = "git"; User = "git";
AddKeysToAgent = "no"; AddKeysToAgent = "no";
}; };
"*.sfc.wide.ad.jp" = {
identityFile = "~/.ssh/id_ed25519_sk_rk";
identitiesOnly = true;
};
"*" = { "*" = {
AddKeysToAgent = "no"; AddKeysToAgent = "no";
SetEnv.TERM = "xterm-256color"; SetEnv.TERM = "xterm-256color";
@@ -31,5 +27,20 @@ lib.mkMerge [
IdentityAgent %d/.1password/agent.sock IdentityAgent %d/.1password/agent.sock
''; '';
}; };
home.activation.generateSshKey = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
key="$HOME/.ssh/id_ed25519"
if [ ! -f "$key" ]; then
umask 077
mkdir -p "$HOME/.ssh"
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
echo "Generated SSH key at $key"
fi
'';
};
} }
] ]
@@ -1,7 +0,0 @@
{ inputs, pkgs, ... }:
let
unstable = inputs.nixpkgs-unstable.legacyPackages.${pkgs.stdenv.hostPlatform.system};
in
{
home.packages = [ unstable.wl-find-cursor ];
}
@@ -1,3 +0,0 @@
{
description = "Wayland cursor locator";
}
+1
View File
@@ -5,6 +5,7 @@
"catppuccin" "catppuccin"
"nix" "nix"
"dockerfile" "dockerfile"
"terraform"
]; ];
mutableUserSettings = false; mutableUserSettings = false;
mutableUserKeymaps = false; mutableUserKeymaps = false;
+24 -8
View File
@@ -24,6 +24,7 @@ required on every supported host.
| Profile | Supported host class | | Profile | Supported host class |
| ------------------------------------ | --------------------------------------------- | | ------------------------------------ | --------------------------------------------- |
| `base` | NixOS, macOS | | `base` | NixOS, macOS |
| `interface.minimal` | NixOS, macOS with Home Manager |
| `interface.cli` | NixOS, macOS with Home Manager | | `interface.cli` | NixOS, macOS with Home Manager |
| `interface.gui` | NixOS, macOS with Home Manager | | `interface.gui` | NixOS, macOS with Home Manager |
| `interface.macos` | macOS | | `interface.macos` | macOS |
@@ -36,15 +37,16 @@ required on every supported host.
| `platform.laptop` | Physical NixOS laptop | | `platform.laptop` | Physical NixOS laptop |
| `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS | | `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS |
| `platform.vm` | UEFI QEMU NixOS guest with NFS client support | | `platform.vm` | UEFI QEMU NixOS guest with NFS client support |
| `workload.deploy-rs-target` | NixOS |
| `workload.development` | NixOS, macOS with Home Manager | | `workload.development` | NixOS, macOS with Home Manager |
| `workload.game` | NixOS, macOS | | `workload.game` | NixOS, macOS |
| `workload.machine-learning` | NixOS with Home Manager | | `workload.machine-learning` | NixOS with Home Manager |
| `workload.nix-builder` | NixOS central build and binary-cache VM | | `workload.network-lab` | NixOS |
| `workload.personal` | NixOS, macOS with Home Manager | | `workload.personal` | NixOS, macOS with Home Manager |
| `workload.photography` | NixOS with Home Manager |
| `workload.remote-access` | NixOS, macOS | | `workload.remote-access` | NixOS, macOS |
| `workload.camera` | NixOS | | `workload.camera` | NixOS |
| `workload.server` | NixOS, macOS with Home Manager | | `workload.server` | NixOS, macOS with Home Manager |
| `networking.homelab-cache-client` | NixOS, macOS with access to nix-builder |
| `networking.tailscale-client` | NixOS, macOS | | `networking.tailscale-client` | NixOS, macOS |
| `networking.tailscale-subnet-router` | NixOS | | `networking.tailscale-subnet-router` | NixOS |
| `security.fingerprint` | NixOS, macOS | | `security.fingerprint` | NixOS, macOS |
@@ -62,16 +64,30 @@ selects labwc. A daily-use macOS development machine can combine
`interface.macos`, `workload.development`, and `workload.personal`. Hardware `interface.macos`, `workload.development`, and `workload.personal`. Hardware
support does not implicitly select an interface or workload. support does not implicitly select an interface or workload.
`platform.nixos` selects the shared network foundation and the clatd service.
VM, laptop, and desktop platform profiles inherit both.
`interface.minimal` provides SSH client access and key generation, Nano, htop,
btop, fastfetch, unzip, wget, Direnv, Git, GnuPG, nh, Zellij, and Zsh for remote
administration. `interface.cli` includes that baseline and adds the configured
Neovim, Yazi, and the remaining interactive command-line tools.
`workload.machine-learning` provides the Hugging Face Hub CLI for hosts used `workload.machine-learning` provides the Hugging Face Hub CLI for hosts used
to download and publish machine learning models and datasets. to download and publish machine learning models and datasets.
`workload.nix-builder` provides the central build policy, persistent fleet GC `workload.network-lab` provides containerlab using its upstream NixOS module,
roots, deploy-rs tooling, SOPS integration, and Harmonia binary cache. Network the Docker service, and the NanoKVM-USB desktop client with serial-port access.
reachability and remote shell access remain independent host selections. It is selected by galleria and x1g13.
`networking.homelab-cache-client` adds the internal Harmonia substituter and `workload.photography` provides darktable with AI support from the locked
its trusted public key. It requires the public key generated during unstable package set. Its ONNX Runtime uses CUDA when the NVIDIA hardware unit
`hosts/nix-builder/README.md` bootstrap. is enabled, and CPU inference otherwise. Keep the default CUDA capabilities
and forward compatibility to reuse the CUDA binary cache; these targets include
galleria's RTX 3060 Ti. OpenCL drivers remain owned by hardware units.
`workload.deploy-rs-target` enables OpenSSH and provisions the `nixdeploy`
service account with the narrowly scoped passwordless commands required for
deploy-rs activation and rollback confirmation.
`workload.personal` provides Pear Desktop on both NixOS and macOS. Home Manager `workload.personal` provides Pear Desktop on both NixOS and macOS. Home Manager
enables performance improvements, synced lyrics, tracker blocking, the album enables performance improvements, synced lyrics, tracker blocking, the album
+4 -19
View File
@@ -8,36 +8,21 @@
dust dust
eza eza
fd fd
fastfetch
fzf fzf
htop
jq jq
lsof lsof
nurl nurl
ripgrep ripgrep
tio tio
unrar unrar
unzip traceroute
wget tcpdump
iw
nmap
] ]
++ lib.optionals stdenv.isLinux [ ++ lib.optionals stdenv.isLinux [
lm_sensors lm_sensors
psmisc psmisc
strace strace
]; ];
home.activation.generateSshKey = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
key="$HOME/.ssh/id_ed25519"
if [ ! -f "$key" ]; then
umask 077
mkdir -p "$HOME/.ssh"
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
echo "Generated SSH key at $key"
fi
'';
};
} }
+1 -8
View File
@@ -2,17 +2,10 @@
description = "Cross-platform interactive command-line environment"; description = "Cross-platform interactive command-line environment";
includes = [ includes = [
"applications.btop" "profiles.interface.minimal"
"applications.direnv"
"applications.git"
"applications.gnupg"
"applications.nh"
"applications.nix-index" "applications.nix-index"
"applications.ssh"
"applications.vim" "applications.vim"
"applications.yazi" "applications.yazi"
"applications.zellij"
"applications.zoxide" "applications.zoxide"
"applications.zsh"
]; ];
} }
@@ -0,0 +1,8 @@
{ pkgs, ... }:
{
home.packages = with pkgs; [
fastfetch
unzip
wget
];
}
@@ -0,0 +1,16 @@
{
description = "Minimal cross-platform command-line environment for remote administration";
includes = [
"applications.btop"
"applications.direnv"
"applications.git"
"applications.gnupg"
"applications.htop"
"applications.nano"
"applications.nh"
"applications.ssh"
"applications.zellij"
"applications.zsh"
];
}
@@ -1,5 +0,0 @@
{
description = "Use the homelab Harmonia binary cache";
includes = [ "systems.nix.homelab-cache" ];
}
+1
View File
@@ -2,6 +2,7 @@
description = "Foundation shared by all NixOS platforms"; description = "Foundation shared by all NixOS platforms";
includes = [ includes = [
"services.clatd"
"services.kmscon" "services.kmscon"
"systems.disko" "systems.disko"
"systems.boot.base" "systems.boot.base"
@@ -1,6 +0,0 @@
{
sops.secrets."users/moons/hashedPassword" = {
sopsFile = ../../../secrets/common/system.yaml;
neededForUsers = true;
};
}
@@ -0,0 +1,8 @@
{
description = "NixOS deploy-rs deployment target";
includes = [
"services.openssh"
"users.nixdeploy"
];
}
@@ -0,0 +1,8 @@
{
description = "Network lab and hardware console environment";
includes = [
"applications.containerlab"
"applications.nanokvm-usb"
];
}
@@ -1,10 +0,0 @@
{
description = "Central Nix builder, deploy controller, and binary cache";
includes = [
"applications.nix-fleet"
"services.harmonia"
"systems.nix.build-server"
"systems.sops"
];
}
@@ -0,0 +1,5 @@
{
description = "RAW photo development and editing";
includes = [ "applications.darktable" ];
}
+3
View File
@@ -0,0 +1,3 @@
_: {
services.clatd.enable = true;
}
+3 -1
View File
@@ -1,5 +1,7 @@
{ primaryUser, ... }: { config, primaryUser, ... }:
{ {
hardware.nvidia-container-toolkit.enable = config.my.hardwares.nvidia.enable;
virtualisation.docker = { virtualisation.docker = {
enable = true; enable = true;
autoPrune = { autoPrune = {
-3
View File
@@ -1,3 +0,0 @@
{
description = "Harmonia binary cache backed by the local Nix store";
}
-19
View File
@@ -1,19 +0,0 @@
let
signingKeyPath = "/run/secrets/harmonia/signing-key";
in
{
services.harmonia.cache = {
enable = true;
signKeyPaths = [ signingKeyPath ];
settings = {
bind = "0.0.0.0:5000";
priority = 30;
};
};
# Keep activation usable while the host-specific SOPS secret is bootstrapped.
# Once the secret exists, starting the socket also starts Harmonia on demand.
systemd.sockets.harmonia.unitConfig.ConditionPathExists = signingKeyPath;
systemd.services.harmonia.unitConfig.ConditionPathExists = signingKeyPath;
}
+4
View File
@@ -0,0 +1,4 @@
{ primaryUser, ... }:
{
users.users.${primaryUser}.extraGroups = [ "dialout" ];
}
@@ -1,3 +0,0 @@
{
description = "Central Nix build server policy and persistent fleet roots";
}
@@ -1,33 +0,0 @@
{ primaryUser, ... }:
let
GiB = 1024 * 1024 * 1024;
in
{
nix = {
nrBuildUsers = 64;
settings = {
# Limit concurrent derivations so build scratch and memory usage remain
# bounded. Each derivation may still use every vCPU exposed to the VM.
max-jobs = 2;
cores = 0;
# Keep enough room for large desktop, browser, and CUDA closures.
min-free = 64 * GiB;
max-free = 128 * GiB;
};
};
systemd.services.nix-daemon.serviceConfig = {
MemoryAccounting = true;
MemoryMax = "90%";
OOMScoreAdjust = 500;
};
systemd.tmpfiles.rules = [
"d /var/lib/nix-fleet 0750 ${primaryUser} users - -"
"d /var/lib/nix-fleet/roots 0750 ${primaryUser} users - -"
"d /var/lib/nix-fleet/roots/build 0750 ${primaryUser} users - -"
"d /var/lib/nix-fleet/roots/deploy 0750 ${primaryUser} users - -"
];
}
+7
View File
@@ -7,6 +7,10 @@
"flakes" "flakes"
]; ];
extra-allowed-users = [
"nixdeploy"
];
connect-timeout = 10; connect-timeout = 10;
extra-substituters = [ extra-substituters = [
@@ -19,6 +23,7 @@
"https://cache.numtide.com" "https://cache.numtide.com"
"https://codex-desktop-linux.cachix.org" "https://codex-desktop-linux.cachix.org"
"https://cuda-maintainers.cachix.org" "https://cuda-maintainers.cachix.org"
"https://cache.nixos-cuda.org"
]; ];
extra-trusted-public-keys = [ extra-trusted-public-keys = [
@@ -31,6 +36,8 @@
"niks3.numtide.com-1:DTx8wZduET09hRmMtKdQDxNNthLQETkc/yaX7M4qK0g=" "niks3.numtide.com-1:DTx8wZduET09hRmMtKdQDxNNthLQETkc/yaX7M4qK0g="
"codex-desktop-linux.cachix.org-1:nX/xy6AdK9hQE24A8ALGjkCKj2ObFmcnemiL5Cid4nk=" "codex-desktop-linux.cachix.org-1:nX/xy6AdK9hQE24A8ALGjkCKj2ObFmcnemiL5Cid4nk="
"cuda-maintainers.cachix.org-1:0dq3bujKpuEPMCX6U4WylrUDZ9JyUG0VpVZa7CNfq5E=" "cuda-maintainers.cachix.org-1:0dq3bujKpuEPMCX6U4WylrUDZ9JyUG0VpVZa7CNfq5E="
"cache.nixos-cuda.org:74DUi4Ye579gUqzH4ziL9IyiJBlDpMRn9MBN8oNan9M="
"nix-builder-1:aG/Y2Lac517isxGO+ZYdVgglj/SI54PkkWoZTQI9aOI="
]; ];
}; };
} }
@@ -1,22 +0,0 @@
{ lib, ... }:
let
publicKeyFile = ./public-key;
hasPublicKey = builtins.pathExists publicKeyFile;
publicKey = if hasPublicKey then lib.removeSuffix "\n" (builtins.readFile publicKeyFile) else "";
in
{
assertions = [
{
assertion = hasPublicKey;
message = ''
systems.nix.homelab-cache requires
modules/systems/nix/homelab-cache/public-key
'';
}
];
nix.settings = lib.mkIf hasPublicKey {
extra-substituters = [ "http://nix-builder:5000" ];
extra-trusted-public-keys = [ publicKey ];
};
}
@@ -1,3 +0,0 @@
{
description = "Homelab Harmonia binary-cache client settings";
}
+5
View File
@@ -1,3 +1,8 @@
{ {
services.pcscd.enable = true; services.pcscd.enable = true;
sops.secrets."users/moons/hashedPassword" = {
sopsFile = ../../../secrets/common/system.yaml;
neededForUsers = true;
};
} }
+28
View File
@@ -0,0 +1,28 @@
{ pkgs, ... }:
{
users.groups.nixdeploy = { };
users.users.nixdeploy = {
isSystemUser = true;
group = "nixdeploy";
home = "/var/lib/nixdeploy";
createHome = true;
shell = pkgs.bashInteractive;
openssh.authorizedKeys.keys = [
"restrict ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFPg1aw0qXBmrQe6lzBwutX5t9Sxg2OeVN/homjqU6Ja moons@nix-builder"
];
};
security.sudo.extraRules = [
{
users = [ "nixdeploy" ];
commands = [
{
command = "ALL";
options = [ "NOPASSWD" ];
}
];
}
];
}
+1 -2
View File
@@ -1,2 +1 @@
{ { }
}