Author SHA1 Message Date
moons-14 08210abf01 update
CI: NixOS / Check all NixOS configurations (push) Canceled after 0s
2026-09-28 11:21:09 +09:00
moons-14 eadfa9b331 update
CI: NixOS / Check all NixOS configurations (push) Canceled after 0s
2026-09-20 02:57:51 +09:00
moons-14 0f3b6c59a2 fix 2026-09-12 20:56:20 +09:00
moons-14 c6fe17de3f nano kvm 2026-09-12 19:45:29 +09:00
moons-14 ac60dc343b nanokvm usb 2026-09-12 19:29:27 +09:00
moons-14 ebef49064c contaiber lab group 2026-09-10 15:37:08 +09:00
moons-14 691926aa4f container lab 2026-09-10 15:27:03 +09:00
moons-14 37e2184d36 clatd 2026-09-10 14:50:54 +09:00
moons-14 52e5fcd47f add basic packages 2026-09-09 14:25:58 +09:00
moons-14 fe785b1fc3 ssh conf 2026-09-07 16:35:16 +09:00
moons-14 b8532ff1b4 nvidia toolkit 2026-09-06 21:24:50 +09:00
moons-14 3a20fe9a09 darktable 2026-09-06 20:31:48 +09:00
moons-14 ef7ff60537 update 2026-09-05 07:55:30 +09:00
moons-14 53f4d2475b nix build 2026-09-04 01:16:10 +09:00
moons-14 7d670b03b2 netsrv-01 2026-09-04 01:04:52 +09:00
moons-14 2d9154614b webook 2026-09-03 23:46:24 +09:00
moons-14 56bc3161d7 nix builder 2026-09-03 23:26:45 +09:00
moons-14 10f4d99cb7 nix builder 2026-09-03 23:25:54 +09:00
moons-14 12badacf46 fix 2026-09-03 22:25:34 +09:00
moons-14 937be12e33 minimal profile 2026-09-03 20:31:06 +09:00
moons-14 8761cbfe40 ops ip 2026-09-03 20:19:22 +09:00
moons-14 e789b5a16f add hardware conf 2026-09-03 19:54:09 +09:00
moons-14 008f704b23 install 2026-09-03 15:12:11 +09:00
moons-14 11c1e24ccd feat 2026-09-03 14:08:31 +09:00
moons-14 ad8337bfbb nix builder network 2026-09-03 13:53:16 +09:00
moons-14 cf23e1ef63 fix 2026-09-03 13:09:52 +09:00
moons-14 4652d911ee add ops 2026-09-03 04:49:45 +09:00
moons-14 c7db764fe2 fix 2026-09-03 04:41:47 +09:00
moons-14 63f49d58f8 fix 2026-09-03 04:37:31 +09:00
moons-14 8189373575 fix 2026-09-03 04:36:04 +09:00
moons-14 d4721d1d22 nix builder 2026-09-03 04:32:47 +09:00
moons-14 cc3798a7b2 nix builder 2026-09-03 04:32:29 +09:00
moons-14 0ff78c6848 nix-builder disko 2026-09-02 21:36:23 +09:00
moons-14 c53a0c0bed zed terraform 2026-09-02 21:23:51 +09:00
moons-14 e3d61e8b6d delete direnv gitignore 2026-09-01 22:20:44 +09:00
moons-14 fda29cd08d update 2026-08-30 06:48:50 +09:00
moons-14 db0a440da4 update Python to 3.14 2026-08-30 05:52:30 +09:00
moons-14 76f5dce9c0 update CodexBar to 0.56.0 2026-08-30 05:52:23 +09:00
moons-14 3b61457718 remove obsolete Codex skill alias 2026-08-30 05:52:16 +09:00
moons-14 c9f1584797 replace Codex Desktop with ChatGPT 2026-08-30 05:52:06 +09:00
moons-14 d51948c307 hugging face 2026-08-29 16:29:42 +09:00
moons-14 9a38e9f614 gpu settings 2026-08-29 16:14:32 +09:00
moons-14 2cb7e76ca1 nix s9 camera 2026-08-27 12:09:55 +09:00
moons-14 749410e032 fix 2026-08-26 21:35:17 +09:00
moons-14 d43f19c20a nix builder 2026-08-26 17:28:09 +09:00
moons-14 32a3067cb0 hardware configuration 2026-08-26 15:53:44 +09:00
moons-14 6e60bd8886 add nix-builder 2026-08-26 13:21:37 +09:00
moons-14 bcf7ef56cf update 2026-08-25 09:24:58 +09:00
moons-14 63e2008423 chrome video play 2026-08-24 02:14:30 +09:00
moons-14 3b8147ff46 codex setting 2026-08-23 14:06:05 +09:00
moons-14 c84f257149 ffmpeg and yt-dlp 2026-08-23 14:04:36 +09:00
moons-14 6347292c1d projects 2026-08-21 05:44:16 +09:00
moons-14 2a82433754 fix(vesktop): restrict WebRTC to public default interface (#67) 2026-08-21 05:31:13 +09:00
moons-14 847ee17b29 linuxPackages 2026-08-21 05:08:30 +09:00
moons-14 95f74aabcd feat 2026-08-21 05:08:30 +09:00
moons-14 717572ae24 feat 2026-08-21 05:08:30 +09:00
moons-14 8086c9a7f3 fix(vesktop): avoid DTLS stalls with multiple interfaces (#66)
* fix(vesktop): add WebRTC IP handling support

* fix(vesktop): constrain WebRTC interface selection
2026-08-21 04:31:24 +09:00
moons-14 eba23455d4 noctalia 2026-08-21 02:32:23 +09:00
moons-14 b3b1031364 fix 2026-08-20 06:18:23 +09:00
moons-14 366ff54403 allow suspend 2026-08-18 10:19:12 +09:00
moons-14 456e9946f4 flake update 2026-08-18 06:56:34 +09:00
moons-14 c104404e5b remove handy 2026-08-18 06:56:28 +09:00
moons-14 cb41932fec add installer keys 2026-08-18 06:29:01 +09:00
moons-14 fa4b7ca404 codex mutable config 2026-08-18 06:25:46 +09:00
moons-14 847d33e83b simplify codex home configuration 2026-08-18 06:12:20 +09:00
moons-14 b2c700e1e4 remove niri window overview bindings 2026-08-18 06:10:56 +09:00
moons-14 c1540d8764 remove noctalia patches 2026-08-18 06:10:43 +09:00
moons-14 5b8c3b1415 remove labwc patch 2026-08-18 06:10:29 +09:00
moons-14 6743569789 remove window-overview 2026-08-18 06:09:11 +09:00
moons-14 70253fc451 evremap 2026-08-18 05:16:18 +09:00
moons-14 5107b80173 feat(ssh): use available SSH agent socket 2026-08-18 05:00:21 +09:00
moons-14 2bdea522cb feat(niri): toggle floating windows with middle click 2026-08-18 05:00:13 +09:00
moons-14 c113d0d46d feat(x1g9): remap VXE mouse buttons 2026-08-18 05:00:05 +09:00
moons-14 fa50be8feb vicinae chrome integuration 2026-08-18 04:41:31 +09:00
moons-14 33ebef4a1e niri keybind 2026-08-18 04:21:16 +09:00
moons-14 94048ef8d5 wallpaper 2026-08-18 04:20:59 +09:00
moons-14 c7627fa1b0 darwin: add stable Xcode and iOS simulator shell (#65)
* darwin: add xcode ios simulator shell

* docs: add iOS simulator setup
2026-08-14 20:35:13 +09:00
moons-14 d68da620ac oh my openagent 2026-08-10 03:25:01 +09:00
moons-14 5f0df47775 codex 2026-08-09 19:54:35 +09:00
moons-14 119342e564 codex 2026-08-09 19:12:02 +09:00
moons-14 1f066e8937 codex 2026-08-09 18:51:09 +09:00
moons-14 0a440e3da8 update codex session usage 2026-08-09 18:13:03 +09:00
moons-14 bdf93ac6bb codex agents prompt 2026-08-09 15:58:40 +09:00
moons-14 9ae5da4d30 zed docker file extension 2026-08-09 15:40:11 +09:00
moons-14 872436b170 skill 2026-08-08 13:14:29 +09:00
moons-14 c14325e29c Update flake.lock 2026-08-08 06:46:59 +09:00
moons-14 45bc66e25f codex prompt 2026-08-08 06:45:22 +09:00
moons-14 78ee2d41ec codex usage vicinae 2026-08-08 05:51:40 +09:00
moons-14 0b1ae13048 window-overview 2026-08-08 04:15:35 +09:00
moons-14 458b0a2cdb galleria tailscale 2026-08-08 00:16:33 +09:00
moons-14 01179f3dc6 desktop: disable system sleep 2026-08-07 22:00:03 +09:00
moons-14 42949fc06c zed: enable Copilot edit predictions 2026-08-07 21:59:57 +09:00
moons-14 a7f514c0f9 opencode: install package through Home Manager 2026-08-07 21:59:47 +09:00
moons-14 9bed1c3e25 zed: add vim keymaps 2026-08-07 21:58:25 +09:00
moons-14 791b6baa83 mod + v toggle 2026-08-07 20:33:44 +09:00
moons-14 349f49e496 fix 2026-08-07 20:33:33 +09:00
moons-14 3166c12448 codex 2026-08-07 18:34:49 +09:00
moons-14 4c459e4aa7 codex back vesion 2026-08-07 18:34:17 +09:00
moons-14 9b9141dd84 lock codex version 2026-08-07 17:30:50 +09:00
moons-14 16e3fda275 ghostty single instance 2026-08-07 14:44:48 +09:00
moons-14 ca36b07839 Display OFF 2026-08-07 06:28:27 +09:00
moons-14 5ebcbb4abf labwc 2026-08-06 17:22:00 +09:00
moons-14 f8fd8a3d99 wallpaper engine 2026-08-06 17:13:02 +09:00
moons-14 16742d2fd7 window overlay 2026-08-05 06:21:26 +09:00
moons-14 15da7affaa window-overview 2026-08-05 05:53:23 +09:00
moons-14 548647fec7 window switch 2026-08-05 05:27:40 +09:00
moons-14 bcbd08c225 wallpaper vicinae 2026-08-05 05:04:22 +09:00
moons-14 a0ae83d24e feat 2026-08-05 04:37:32 +09:00
110 changed files with 2281 additions and 1406 deletions
+73 -18
View File
@@ -351,6 +351,7 @@ modules/profiles/
├── base/
├── interface/
│ ├── cli/
│ ├── minimal/
│ ├── gui/
│ ├── macos/
│ ├── linux-desktop/
@@ -367,8 +368,14 @@ modules/profiles/
│ ├── desktop/
│ └── vm/
├── workload/
│ ├── camera/
│ ├── deploy-rs-target/
│ ├── development/
│ ├── game/
│ ├── machine-learning/
│ ├── network-lab/
│ ├── personal/
│ ├── photography/
│ ├── server/
│ └── remote-access/
└── security/
@@ -389,16 +396,21 @@ The profile layers have these responsibilities:
- `base` contains only invariants required by every supported host. It includes
`systems.nix` and the universal Atuin, tealdeer, trippy, and xh CLI tools;
optional secrets, interface, hardware, and workloads do not belong there.
- `interface` describes how the host is operated. `interface.cli` is shared by
NixOS and macOS and includes `tio`. `interface.gui` owns cross-platform
graphical interface applications such as Vicinae. `interface.macos` owns the
macOS Finder, Dock, trackpad, and shared default preferences and includes
`interface.gui`.
- `interface` describes how the host is operated. `interface.minimal` is shared
by NixOS and macOS and provides the remote-administration CLI baseline,
including SSH, Nano, htop, Git, Zellij, and Zsh. `interface.cli` includes that
baseline and adds the full interactive command-line environment, including
the configured Neovim, Yazi, and `tio`. `interface.gui` owns
cross-platform graphical interface applications such as Vicinae.
`interface.macos` owns the macOS Finder, Dock, trackpad, and shared default
preferences and includes `interface.gui`.
`interface.linux-desktop` owns the common labwc/niri desktop selection,
including Ghostty and Nautilus, and also includes `interface.gui`. Labwc and
niri remain independently selectable and do not imply CLI or personal
workloads.
- `platform` describes NixOS foundations and physical or virtual form factors.
`platform.nixos` selects the shared network foundation and `services.clatd`;
VM, laptop, and desktop platform profiles inherit both.
macOS does not need an empty symmetric platform profile.
- `workload` describes optional host uses. `workload.development` and
`workload.personal` are cross-platform profiles, not `*-linux` variants.
@@ -538,9 +550,26 @@ A host registry may use a specification like this:
profiles = [
"base"
"interface.cli"
"interface.minimal"
"platform.vm"
"workload.remote-access"
"workload.deploy-rs-target"
];
};
netsrv-01 = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./netsrv-01;
profiles = [
"base"
"interface.minimal"
"platform.vm"
"workload.remote-access"
"workload.deploy-rs-target"
"workload.server"
];
};
@@ -552,7 +581,7 @@ A host registry may use a specification like this:
profiles = [
"base"
"interface.cli"
"interface.minimal"
"platform.vm"
"workload.server"
];
@@ -602,7 +631,9 @@ A host registry may use a specification like this:
"security.secrets"
"security.secure-boot"
"security.tpm-storage"
"workload.camera"
"workload.development"
"workload.network-lab"
"workload.personal"
];
};
@@ -624,7 +655,10 @@ A host registry may use a specification like this:
"security.tpm-storage"
"workload.development"
"workload.game"
"workload.machine-learning"
"workload.network-lab"
"workload.personal"
"workload.photography"
];
};
@@ -647,14 +681,22 @@ A host registry may use a specification like this:
```
The current role assignment is intentional: nix-example is the development VM;
ops is the remote-access VM with host-specific static networking;
internal-app-01 is the container server VM; and installer builds the minimal
installation ISO without Home Manager. x1g9 is a full NixOS desktop with niri,
ops is the minimal-interface remote-access VM with host-specific static
networking; netsrv-01 is the deploy-rs-managed container server VM;
internal-app-01 is the minimal-interface container server VM;
nix-builder is the minimal-interface remote Nix build VM with dedicated build
and store disks; and installer builds the minimal installation ISO without Home
Manager. x1g9 is a full NixOS desktop with niri,
labwc, ly, the shared Linux desktop applications, and the personal workload.
x1g13 is the secure NixOS development and personal ThinkPad, with the same
desktop sessions plus Tailscale client, SOPS, Secure Boot, and TPM-backed disk
unlock. galleria is the Intel/NVIDIA physical desktop shared with Windows; it
uses dedicated NixOS partitions, LUKS, Secure Boot, and TPM-backed disk unlock.
It selects `workload.photography` for AI-enabled darktable. The application
chooses CUDA support from the NVIDIA hardware unit's enable state and keeps
the default CUDA targets, including RTX 3060 Ti support, to reuse binary caches.
galleria and x1g13 select `workload.network-lab` for containerlab, Docker, and
the NanoKVM-USB desktop client with serial-port access.
m2 is the daily-use macOS development and personal machine with the macOS
interface defaults. Keep the desktop sessions independently selectable, and
keep the development and personal profiles usable across NixOS and Darwin.
@@ -687,6 +729,15 @@ configuration fragments. For example:
```text
hosts/
├── nix-builder/
│ ├── disko.nix
│ ├── hardware-configuration.nix
│ └── nixos.nix
├── netsrv-01/
│ ├── disko.nix
│ ├── hardware-configuration.nix
│ ├── networking.nix
│ └── nixos.nix
├── installer/
│ └── nixos.nix
├── internal-app-01/
@@ -716,12 +767,15 @@ hosts/
```
`hosts/x1g9/nixos.nix` explicitly loads `hardware-configuration.nix` with the
normal top-level Nix module `imports`. `hosts/x1g13/nixos.nix` loads its
generated hardware configuration and host-local `disko.nix` the same way. Do
not confuse these host imports with the prohibition on top-level `imports` in
unit configuration fragments. `hosts/galleria/disko.nix` manages only the two
dedicated NixOS partitions by PARTUUID and deliberately excludes the Windows
disk, Windows partitions, and the Windows EFI System Partition.
normal top-level Nix module `imports`. `hosts/nix-builder/nixos.nix` and
`hosts/x1g13/nixos.nix` load their generated hardware configuration and
host-local `disko.nix` the same way. The nix-builder Disko definition mounts its
existing VM filesystems by stable QEMU SCSI IDs and does not take destructive
ownership of them. Do not confuse these host imports with the prohibition on
top-level `imports` in unit configuration fragments. `hosts/galleria/disko.nix`
manages only the two dedicated NixOS partitions by PARTUUID and deliberately
excludes the Windows disk, Windows partitions, and the Windows EFI System
Partition.
Derive the system class from the host's `system`:
@@ -824,8 +878,9 @@ For profile changes, additionally:
`homebrew.casks` selection as well as module evaluation.
- Preserve the intended host roles: nix-example remains the development VM;
ops remains the statically networked remote-access VM; internal-app-01 remains
the container server VM; installer remains the Home Manager-free installation
ISO; x1g9 provides niri, labwc, ly, and the personal application set; x1g13
the container server VM; netsrv-01 remains the deploy-rs-managed container
server VM; installer remains the Home Manager-free installation ISO; x1g9
provides niri, labwc, ly, and the personal application set; x1g13
additionally provides the development, Tailscale client, secrets, Secure Boot,
and TPM storage roles; galleria remains the Intel/NVIDIA dual-boot desktop
with LUKS, Secure Boot, and TPM storage; m2 remains the daily-use development
+153
View File
@@ -0,0 +1,153 @@
# NixOSインストール手順(SOPSなし・ディスク暗号化なし)
この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を
使用しないホスト向けの、独立したインストール手順である。
SOPSとディスク暗号化を使用する場合は、[暗号化ありの手順](install.md)を参照。
## 事前準備
1. [ISOビルド](iso-build.md)を参照してISOを作成
2. USBに書き込んで対象マシンでブート
## ネットワーク接続
### 有線LAN
DHCPで自動設定される。
### Wi-Fi(有線が使えない場合)
```bash
nmcli device wifi connect <SSID> --ask
```
## SSH接続
コンソールに表示されたIPアドレスに接続:
```bash
ssh root@<ip-address>
```
## インストール手順
### 1. dotfilesのクローン
```bash
git clone [email protected]:moons-14/dotfiles.git ~/dotfiles
cd ~/dotfiles
```
### 2. ホスト設定の作成
`hosts/<hostname>/nixos.nix`を作成し、`hosts/default.nix`にホストと使用する
プロファイルを登録する。ホスト固有の設定だけをホストディレクトリに置き、
再利用可能な設定は適切なunitまたはprofileに置く。
### 3. インストール先ディスクの確認
```bash
lsblk -o NAME,PATH,SIZE,MODEL,SERIAL,TYPE,FSTYPE,MOUNTPOINTS
ls -l /dev/disk/by-id/
```
以降の操作では指定したディスクの既存データが消去される。対象を必ず確認し、
可能であれば`/dev/sda`や`/dev/nvme0n1`ではなく、安定した
`/dev/disk/by-id/...`パスを使用する。
### 4. Disko設定の作成
`hosts/<hostname>/disko.nix`を作成する:
```nix
_:
{
disko.enableConfig = true;
disko.devices.disk.main = {
type = "disk";
device = "/dev/disk/by-id/<target-disk>";
content = {
type = "gpt";
partitions = {
ESP = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
root = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
};
};
};
}
```
`<target-disk>`を手順3で確認した実際のディスクIDに置き換える。指定した
ディスクの既存データは消去される。
### 5. パーティション作成とマウント
```bash
disko --mode destroy,format,mount hosts/<hostname>/disko.nix
```
Diskoの実行結果を確認する:
```bash
findmnt /mnt
findmnt /mnt/boot
```
### 6. ハードウェア設定の生成
```bash
nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \
> ~/dotfiles/hosts/<hostname>/hardware-configuration.nix
```
### 7. ホストモジュールから設定を読み込む
`hosts/<hostname>/nixos.nix`で、生成したハードウェア設定とDisko設定を読み込む:
```nix
{
imports = [
./hardware-configuration.nix
./disko.nix
];
}
```
### 8. NixOSインストール
```bash
nixos-install --flake ~/dotfiles#<hostname>
```
SOPSを使用しないため、age鍵の登録、シークレットの再暗号化、SSHホストキーの
事前生成とコピーは不要である。OpenSSHを有効にしたホストでは、SSHホストキーは
通常の初回起動時に生成される。
### 9. 再起動
```bash
reboot
```
## インストール後の確認
- 正しいディスクから起動できるか
- `/`と`/boot`が意図したファイルシステムからマウントされているか
- ネットワークと、設定している場合はSSH接続が利用できるか
+32 -44
View File
@@ -1,4 +1,10 @@
# NixOSインストール手順
# NixOSインストール手順(SOPS・ディスク暗号化あり)
この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を
使用するホスト向けである。
どちらも使用しない場合は、
[SOPSなし・ディスク暗号化なしの手順](install-simple.md)を参照。
## 事前準備
@@ -83,54 +89,36 @@ sops updatekeys secrets/hosts/<hostname>/*.yaml
新しいホスト用の`hosts/<hostname>/disko.nix`を作成。
#### シンプル構成(暗号化なし)
```nix
_:
{
disko.enableConfig = true;
disko.devices.disk.main = {
type = "disk";
device = "/dev/sda";
content = {
type = "gpt";
partitions = {
ESP = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
root = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
};
};
};
}
```
#### LUKS暗号化 + btrfs
`hosts/x1g13/disko.nix`を参照。
LUKS暗号化とbtrfsの構成は`hosts/x1g13/disko.nix`を参照。
### 7. ディスクのパーティション
```bash
cd ~/dotfiles
nix run github:nix-community/disko -- --mode disko hosts/<hostname>/disko.nix
disko --mode destroy,format,mount hosts/<hostname>/disko.nix
```
### 8. ホストキーのコピー
### 8. ハードウェア設定の生成
対象マシンのハードウェア設定を生成し、新しいホストのディレクトリへ直接保存:
```bash
nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \
> ~/dotfiles/hosts/<hostname>/hardware-configuration.nix
```
`hosts/<hostname>/nixos.nix`から生成した設定とDisko設定を読み込む:
```nix
{
imports = [
./hardware-configuration.nix
./disko.nix
];
}
```
### 9. ホストキーのコピー
```bash
mkdir -p /mnt/etc/ssh
@@ -138,13 +126,13 @@ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/
chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key
```
### 9. NixOSインストール
### 10. NixOSインストール
```bash
nixos-install --flake ~/dotfiles#<hostname>
```
### 10. 再起動
### 11. 再起動
```bash
reboot
+119
View File
@@ -0,0 +1,119 @@
# iOS Simulator 初期セットアップ
この手順は `m2` の macOS 環境で、stable Xcode と最新の stable iOS Simulator Runtime を使える状態にするためのもの。
## 前提
- `m2` が `workload.development` profile を有効にしていること
- Mac App Store に Apple Account でサインイン済みであること
- dotfiles を最新化していること
Xcode 本体は `applications.xcode` が Mac App Store 版を管理する。Simulator Runtime は Apple が管理する mutable state のため、Nix store には入れず専用 dev shell から導入する。
## 1. macOS 設定を反映する
リポジトリ直下で nix-darwin の設定を反映する。
```bash
sudo darwin-rebuild switch --flake .#m2
```
これにより `/Applications/Xcode.app` に stable Xcode がインストールされる。
Xcode のインストールで Mac App Store の認証エラーになる場合は、App Store を一度開いてサインイン状態を確認してから再実行する。
## 2. iOS Simulator Runtime を導入する
初回セットアップは次の1コマンドで行う。
```bash
nix develop .#ios -c ios-simulator-install
```
`ios-simulator-install` は次を順に実行する。
1. `/Applications/Xcode.app` が存在することを確認
2. `xcode-select` の Developer Directory を stable Xcode に切り替え
3. Xcode の first-launch components を導入
4. 利用可能な新しい hardware support components を確認
5. 選択中の Xcode に対応する最新の iOS Simulator Runtime をダウンロードしてインストール
6. Xcode のバージョンとインストール済み Simulator Runtime を表示
途中で `sudo` の認証を求められる場合がある。
## 3. インストールを確認する
```bash
xcodebuild -version
xcode-select -p
xcrun simctl list runtimes
xcrun simctl list devices available
```
`xcode-select -p` は次を指していること。
```text
/Applications/Xcode.app/Contents/Developer
```
`xcrun simctl list runtimes` に iOS runtime が表示されればセットアップ完了。
## 4. Simulator を起動する
```bash
open -a Simulator
```
Simulator の Device メニューから、インストール済み runtime で利用可能な iPhone を選択する。
## Runtime の更新
Xcode を stable の新しいバージョンへ更新した後は、同じコマンドを再実行する。
```bash
nix develop .#ios -c ios-simulator-install
```
Xcode の選択、first-launch components、hardware support、iOS Simulator Runtime の状態をまとめて更新できる。
## トラブルシューティング
### Xcode が見つからない
次のエラーが出る場合、先に nix-darwin の設定を反映する。
```text
Xcode is not installed at /Applications/Xcode.app.
```
```bash
sudo darwin-rebuild switch --flake .#m2
```
### Simulator Runtime が見えない
まず runtime 一覧を確認する。
```bash
xcrun simctl list runtimes
```
iOS runtime がない場合は再度インストーラーを実行する。
```bash
nix develop .#ios -c ios-simulator-install
```
### Command Line Tools 側を参照している
```bash
xcode-select -p
```
が `/Library/Developer/CommandLineTools` を指している場合でも、`ios-simulator-install` が `/Applications/Xcode.app/Contents/Developer` へ切り替える。
手動で直す場合は次を実行する。
```bash
sudo xcode-select --switch /Applications/Xcode.app/Contents/Developer
```
+72 -12
View File
@@ -1,26 +1,86 @@
# カスタムISOビルド
# カスタムインストーラー ISO
`hosts/installer` から、NixOS 26.05 ベースの `x86_64-linux` 用インストーラー
ISO を作成する。installer ホストは Home Manager を使用せず、`base` プロファイルと
ホスト固有のインストール支援設定だけを含む。
## ビルド
flake 対応の Nix が利用できる環境で、リポジトリのルートから実行する。
`x86_64-linux` 以外のマシンで実行する場合は、対応する Linux リモートビルダーが
必要になる。
```bash
nix build .#nixosConfigurations.installer.config.system.build.isoImage
```
## ISO書き込み
生成された ISO は次の場所にある。
```text
result/iso/nixos-minimal-*-x86_64-linux.iso
```
ファイル名に含まれる NixOS のバージョンとリビジョンは、`flake.lock` の更新に応じて
変わる。生成物を確認するには次を実行する。
```bash
# USBデバイスの確認
lsblk
ls -lh result/iso/*.iso
sha256sum result/iso/*.iso
```
# 書き込み(/dev/sdXは実際のデバイスに置き換える)
sudo dd if=./result/nixos-minimal-*.iso of=/dev/sdX bs=4M status=progress
## USB メモリへの書き込み
書き込み先はパーティション(例: `/dev/sdX1`)ではなく、USB デバイス全体
(例: `/dev/sdX`)を指定する。この操作は指定したデバイスの内容を上書きするため、
サイズ、モデル、マウント先を確認する。
```bash
lsblk -p -o NAME,SIZE,TYPE,MODEL,MOUNTPOINTS
```
USB のマウント済みパーティションをアンマウントしてから、`/dev/sdX` と
`/dev/sdX1` を確認した実際のデバイス名に置き換えて書き込む。パーティションが
複数ある場合は、それぞれをアンマウントする。
```bash
sudo umount /dev/sdX1
sudo dd if=result/iso/nixos-minimal-*-x86_64-linux.iso \
of=/dev/sdX bs=4M conv=fsync status=progress
sync
```
## ISOの特徴
書き込み完了後、USB を安全に取り外して対象マシンから起動する。
- SSH鍵認証でrootログイン可能
- 有線LANはDHCPで自動設定
- WiFiは`nmcli`で手動設定可能
- disko/sops/ageなどのツールを内蔵
- ブート時にIPアドレスとヘルプを表示
## 起動後の接続
有線 LAN は DHCP で自動設定される。Wi-Fi を使用する場合は、インストーラーの
コンソールで NetworkManager を使って接続する。
```bash
nmcli device wifi list
nmcli device wifi connect <SSID> --ask
```
起動時にコンソールへ IPv4 アドレスと簡易ヘルプが表示される。表示されたアドレスへ
登録済みの SSH 鍵で接続する。
```bash
ssh root@<ip-address>
```
root のパスワードログインとキーボード対話認証は無効で、
`hosts/installer/nixos.nix` に登録された公開鍵だけが利用できる。
以降の作業は、構成に応じて次の手順を参照する:
- [SOPSなし・ディスク暗号化なし](install-simple.md)
- [SOPS・ディスク暗号化あり](install.md)
## ISO に含まれる主な設定とツール
- Nix flakes と `nix-command`
- NetworkManager、OpenSSH、起動時の IP アドレス表示
- `disko`、`parted`、`cryptsetup`、`btrfs-progs`、`efibootmgr`
- `sops`、`age`、`ssh-to-age`
- `age-plugin-yubikey`、`yubikey-manager`、`pcsc-tools` と `pcscd`
- `sbctl`、`tpm2-tools`
- `git`、`rsync`、`vim`、`wget`、`curl`、`jq`、`pciutils`、`util-linux`
Generated
+625 -304
View File
File diff suppressed because it is too large Load Diff
+8 -6
View File
@@ -38,12 +38,6 @@
url = "github:ghostty-org/ghostty";
};
# Speech to text
handy = {
url = "github:cjpais/Handy";
inputs.nixpkgs.follows = "nixpkgs";
};
# Shell / Launcher
vicinae.url = "github:vicinaehq/vicinae";
@@ -97,6 +91,13 @@
url = "github:ilysenko/codex-desktop-linux";
};
codex-session-usage.url = "github:moons-14/codex-session-usage";
skills = {
url = "github:mattpocock/skills";
flake = false;
};
# Index / Search
nix-index-database = {
url = "github:nix-community/nix-index-database";
@@ -113,6 +114,7 @@
nani-translate-linux.url = "git+https://github.com/zunoser/nani-translate-linux.git";
containerlab.url = "github:srl-labs/containerlab";
};
outputs =
+17 -8
View File
@@ -1,15 +1,14 @@
{
nix-example = {
nix-builder = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./nix-example;
path = ./nix-builder;
profiles = [
"base"
"interface.cli"
"interface.minimal"
"platform.vm"
"workload.development"
"workload.remote-access"
];
};
@@ -22,22 +21,25 @@
profiles = [
"base"
"interface.cli"
"interface.minimal"
"platform.vm"
"workload.remote-access"
"workload.deploy-rs-target"
];
};
internal-app-01 = {
netsrv-01 = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./internal-app-01;
path = ./netsrv-01;
profiles = [
"base"
"interface.cli"
"interface.minimal"
"platform.vm"
"workload.remote-access"
"workload.deploy-rs-target"
"workload.server"
];
};
@@ -89,8 +91,10 @@
"security.tpm-storage"
"workload.development"
"workload.game"
"workload.network-lab"
"workload.personal"
];
};
galleria = {
@@ -104,6 +108,7 @@
"interface.cli"
"interface.labwc"
"interface.niri"
"networking.tailscale-client"
"platform.intel-nvidia-desktop"
"security.secrets"
"security.secure-boot"
@@ -111,7 +116,11 @@
"security.fingerprint"
"workload.development"
"workload.game"
"workload.machine-learning"
"workload.network-lab"
"workload.personal"
"workload.photography"
"workload.camera"
];
};
+5
View File
@@ -4,6 +4,11 @@
...
}:
{
# This desktop is permanently connected to AC power.
systemd.user.services.swayidle.Service.Environment = [
"SWAYIDLE_ASSUME_AC=1"
];
services.kanshi = {
enable = true;
+7
View File
@@ -8,6 +8,13 @@
boot.initrd.luks.devices.cryptroot.device =
"/dev/disk/by-partuuid/04295552-cbb8-4511-ac1e-1171ec20f8d1";
# Keep Windows data and recovery partitions out of UDisks-based file
# managers. The shared EFI System Partition stays available as /boot.
services.udev.extraRules = ''
ENV{ID_PART_ENTRY_UUID}=="0480f887-d1f9-489d-b8fe-78549ced1938", ENV{UDISKS_IGNORE}="1"
ENV{ID_PART_ENTRY_UUID}=="6c70041b-3f65-4eb1-8b08-18ed20001877", ENV{UDISKS_IGNORE}="1"
'';
environment.systemPackages = with inputs.browser-previews.packages.${pkgs.system}; [
google-chrome-beta
];
+19 -24
View File
@@ -31,6 +31,7 @@
users.users.root.openssh.authorizedKeys.keys = [
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIKhxDkucmeCor6CKoXAua7DgDSzuXrZOtpdkyzQxz5+aAAAABHNzaDo= moons@moons14.com"
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIN6hZJyng/5LgFKPjR6uZAd/00UkO0vN0uQOoIvfSELdAAAABHNzaDo= moons@moons14.com"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPLwReAiwhXoO34S2+MrvqUhi8IWp4IzUq4OSp3niJdq"
];
environment.systemPackages = with pkgs; [
@@ -75,6 +76,12 @@
║ ║
║ Installation Workflow: ║
║ ║
║ Choose a guide after cloning: ║
║ Simple: docs/install-simple.md ║
║ SOPS + LUKS: docs/install.md ║
║ ║
║ The workflow below is for SOPS + LUKS: ║
║ ║
║ 1. Clone dotfiles: ║
║ git clone git@github.com:moons-14/dotfiles.git ~/dotfiles║
║ ║
@@ -102,37 +109,25 @@
║ # See hosts/x1g13/disko.nix for reference ║
║ ║
║ 7. Partition disk with disko: ║
║ nix run github:nix-community/disko -- \ ║
║ --mode disko hosts/<host>/disko.nix ║
║ disko --mode destroy,format,mount \ ║
║ hosts/<host>/disko.nix ║
║ ║
║ 8. Copy host key to installed system: ║
║ 8. Generate hardware configuration: ║
║ nixos-generate-config --no-filesystems --root /mnt \ ║
║ --show-hardware-config > \ ║
║ ~/dotfiles/hosts/<host>/hardware-configuration.nix ║
║ # Import hardware-configuration.nix and disko.nix ║
║ # from hosts/<host>/nixos.nix ║
║ ║
║ 9. Copy host key to installed system: ║
║ mkdir -p /mnt/etc/ssh ║
║ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ ║
║ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ║
║ ║
║ 9. Install NixOS: ║
║ 10. Install NixOS: ║
║ nixos-install --flake ~/dotfiles#<host> ║
║ ║
║ Disko Configuration Examples: ║
║ ║
║ Simple (no encryption): ║
║ disko.devices.disk.main = { ║
║ type = "disk"; ║
║ device = "/dev/sda"; ║
║ content = { ║
║ type = "gpt"; ║
║ partitions = { ║
║ ESP = { size = "512M"; type = "EF00"; ║
║ content = { type = "filesystem"; ║
║ format = "vfat"; mountpoint = "/boot"; }; }; ║
║ root = { size = "100%"; ║
║ content = { type = "filesystem"; ║
║ format = "ext4"; mountpoint = "/"; }; }; ║
║ }; ║
║ }; ║
║ }; ║
║ ║
║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║
║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║
║ - Use partuuid for device path ║
║ - Set askPassword = true for LUKS ║
║ - Configure btrfs subvolumes ║
@@ -1,36 +0,0 @@
# Do not modify this file! It was generated by `nixos-generate-config` and may
# be overwritten by future invocations.
{ lib, modulesPath, ... }:
{
imports = [ (modulesPath + "/profiles/qemu-guest.nix") ];
boot.initrd.availableKernelModules = [
"ata_piix"
"uhci_hcd"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" = {
device = "/dev/disk/by-uuid/1b12ab98-2537-4207-a3f4-bb8ba7b53b00";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/8365-C778";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
-3
View File
@@ -1,3 +0,0 @@
{
imports = [ ./hardware-configuration.nix ];
}
+30
View File
@@ -0,0 +1,30 @@
_: {
disko.enableConfig = true;
disko.devices.disk.main = {
type = "disk";
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
content = {
type = "gpt";
partitions = {
ESP = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
root = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
};
};
};
}
@@ -0,0 +1,27 @@
# QEMU hardware baseline. Replace this with the output of
# `nixos-generate-config` after provisioning the VM if its hardware differs.
{
lib,
modulesPath,
...
}:
{
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [
"ata_piix"
"uhci_hcd"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
+40
View File
@@ -0,0 +1,40 @@
{
networking = {
interfaces = {
ens18 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.65.11";
prefixLength = 24;
}
];
};
ens19 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.66.10";
prefixLength = 24;
}
];
};
ens20 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.77.21";
prefixLength = 24;
}
];
};
};
defaultGateway = {
address = "10.50.66.1";
interface = "ens19";
};
};
}
+7
View File
@@ -0,0 +1,7 @@
{
imports = [
./hardware-configuration.nix
./disko.nix
./networking.nix
];
}
+66
View File
@@ -0,0 +1,66 @@
_:
let
osDisk = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
in
{
disko.enableConfig = true;
# The VM disks already contain live filesystems. Model each existing
# filesystem without giving Disko ownership of their partitioning or data.
disko.devices.disk = {
boot = {
type = "disk";
device = "${osDisk}-part1";
destroy = false;
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
root = {
type = "disk";
device = "${osDisk}-part2";
destroy = false;
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
nix-build = {
type = "disk";
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi1";
destroy = false;
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/var/lib/nix-build";
mountOptions = [ "noatime" ];
};
};
nix-store = {
type = "disk";
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi2";
destroy = false;
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/nix/store";
mountOptions = [ "noatime" ];
};
};
};
fileSystems."/nix/store".neededForBoot = true;
nix.settings.build-dir = "/var/lib/nix-build";
services.fstrim.enable = true;
}
+83
View File
@@ -0,0 +1,83 @@
{
config,
pkgs,
primaryUser,
...
}:
let
homeDirectory = "/home/${primaryUser}";
fleetDirectory = "${homeDirectory}/srv/nix-fleet";
stateDirectory = "/var/lib/nix-fleet";
sourceDirectory = "${stateDirectory}/source";
git = "${pkgs.git}/bin/git";
nix = "${config.nix.package}/bin/nix";
rsync = "${pkgs.rsync}/bin/rsync";
cleanCheckoutConditions = [
"${git} -C ${fleetDirectory} diff --quiet"
"${git} -C ${fleetDirectory} diff --cached --quiet"
];
in
{
systemd.services.nix-fleet-converge = {
description = "Update inputs, build the fleet, and deploy changed hosts";
wants = [ "network-online.target" ];
after = [ "network-online.target" ];
environment = {
HOME = homeDirectory;
NIX_CONFIG = ''
accept-flake-config = true
max-jobs = 4
cores = 3
'';
};
serviceConfig = {
Type = "oneshot";
User = primaryUser;
Restart = "on-failure";
RestartSec = "5min";
StateDirectory = "nix-fleet";
StateDirectoryMode = "0750";
WorkingDirectory = stateDirectory;
UMask = "0077";
ExecCondition = cleanCheckoutConditions;
EnvironmentFile = "${fleetDirectory}/.env";
# Work in a disposable copy so updating the dotfiles lock never dirties
# the operator's nix-fleet checkout.
ExecStart = [
"${git} -C ${fleetDirectory} pull --ff-only"
"${rsync} --archive --delete --exclude=.git/ --exclude=.direnv/ --exclude=.env --exclude=result --exclude=result-* ${fleetDirectory}/ ${sourceDirectory}/"
"${nix} flake update --flake ${sourceDirectory} dotfiles"
"${nix} run ${sourceDirectory}#converge -- ${sourceDirectory} ${stateDirectory}"
];
};
};
systemd.timers.nix-fleet-converge = {
description = "Periodically converge the NixOS fleet";
wantedBy = [ "timers.target" ];
timerConfig = {
OnBootSec = "2min";
OnUnitInactiveSec = "5min";
RandomizedDelaySec = "30s";
Persistent = true;
Unit = "nix-fleet-converge.service";
};
};
# Only an actual successful deployment touches gc-request. This starts the
# builder's root nh-clean unit; remote host stores are never cleaned here.
systemd.paths.nix-fleet-gc = {
description = "Garbage-collect superseded fleet builds on nix-builder";
wantedBy = [ "multi-user.target" ];
pathConfig = {
PathChanged = "${stateDirectory}/gc-request";
Unit = "nh-clean.service";
};
};
}
@@ -0,0 +1,26 @@
# Do not modify this file! It was generated by ‘nixos-generate-config’
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ lib, modulesPath, ... }:
{
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [
"ata_piix"
"uhci_hcd"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
swapDevices = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
+37
View File
@@ -0,0 +1,37 @@
{
lib,
...
}:
{
nix.settings = {
build-dir = "/var/lib/nix-build";
secret-key-files = [
"/var/lib/secrets/nix-cache-signing-key"
];
auto-optimise-store = lib.mkForce false;
keep-outputs = false;
keep-derivations = true;
};
services.harmonia.cache = {
enable = true;
signKeyPaths = [
"/var/lib/secrets/nix-cache-signing-key"
];
settings = {
bind = "[::]:5000";
priority = 30;
workers = 4;
};
};
networking.firewall.allowedTCPPorts = [
5000
];
}
+40
View File
@@ -0,0 +1,40 @@
{
networking = {
interfaces = {
ens18 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.65.10";
prefixLength = 24;
}
];
};
ens19 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.77.10";
prefixLength = 24;
}
];
};
ens20 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.68.10";
prefixLength = 24;
}
];
};
};
defaultGateway = {
address = "10.50.68.1";
interface = "ens20";
};
};
}
+9
View File
@@ -0,0 +1,9 @@
{
imports = [
./fleet-automation.nix
./disko.nix
./hardware-configuration.nix
./harmonia.nix
./networking.nix
];
}
@@ -1,36 +0,0 @@
# Do not modify this file! It was generated by `nixos-generate-config` and may
# be overwritten by future invocations.
{ lib, modulesPath, ... }:
{
imports = [ (modulesPath + "/profiles/qemu-guest.nix") ];
boot.initrd.availableKernelModules = [
"ata_piix"
"uhci_hcd"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" = {
device = "/dev/disk/by-uuid/8f0eaec6-5dc9-4821-aa8d-fb6809b5a5bf";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/201C-961B";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
-3
View File
@@ -1,3 +0,0 @@
{
imports = [ ./hardware-configuration.nix ];
}
+30
View File
@@ -0,0 +1,30 @@
_: {
disko.enableConfig = true;
disko.devices.disk.main = {
type = "disk";
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
content = {
type = "gpt";
partitions = {
ESP = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
root = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
};
};
};
}
+12 -20
View File
@@ -1,8 +1,16 @@
# Do not modify this file! It was generated by `nixos-generate-config` and may
# be overwritten by future invocations.
{ lib, modulesPath, ... }:
# Do not modify this file! It was generated by ‘nixos-generate-config’
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{
imports = [ (modulesPath + "/profiles/qemu-guest.nix") ];
lib,
modulesPath,
...
}:
{
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [
"ata_piix"
@@ -16,21 +24,5 @@
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" = {
device = "/dev/disk/by-uuid/69fa2193-1e4f-438a-8898-5de8a3f36e5b";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/D09B-4277";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
+40
View File
@@ -0,0 +1,40 @@
{
networking = {
interfaces = {
ens18 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.65.100";
prefixLength = 24;
}
];
};
ens19 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.80.10";
prefixLength = 24;
}
];
};
ens20 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.77.20";
prefixLength = 24;
}
];
};
};
defaultGateway = {
address = "10.50.80.1";
interface = "ens19";
};
};
}
+5 -49
View File
@@ -1,51 +1,7 @@
{
imports = [ ./hardware-configuration.nix ];
networking = {
useDHCP = false;
interfaces = {
ens18 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.128.20";
prefixLength = 24;
}
];
};
ens19 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.7.101";
prefixLength = 24;
}
];
};
ens20 = {
useDHCP = false;
ipv4.routes = [
{
address = "10.50.64.0";
prefixLength = 24;
via = "10.50.82.1";
}
];
ipv4.addresses = [
{
address = "10.50.82.10";
prefixLength = 24;
}
];
};
};
defaultGateway = {
address = "10.50.128.1";
interface = "ens18";
};
};
imports = [
./hardware-configuration.nix
./networking.nix
./disko.nix
];
}
+30 -2
View File
@@ -1,9 +1,37 @@
_: {
{
config,
lib,
pkgs,
...
}:
let
chrome = pkgs.google-chrome.overrideAttrs (old: {
nativeBuildInputs = (old.nativeBuildInputs or [ ]) ++ [ pkgs.makeWrapper ];
postFixup = (old.postFixup or "") + ''
wrapProgram $out/bin/google-chrome-stable \
--set LIBVA_DRIVER_NAME nvidia \
--set NVD_BACKEND direct
'';
});
features = [
"MiddleClickAutoscroll"
"AcceleratedVideoDecoder"
"AcceleratedVideoDecodeLinuxGL"
"PlatformHEVCDecoderSupport"
]
++ lib.optional config.my.hardwares.nvidia.enable "VaapiOnNvidiaGPUs";
in
{
programs.google-chrome = {
enable = true;
package = if config.my.hardwares.nvidia.enable then chrome else pkgs.google-chrome;
commandLineArgs = [
"--enable-features=MiddleClickAutoscroll"
"--enable-features=${lib.concatStringsSep "," features}"
"--use-gl=angle"
"--use-angle=gl"
];
};
+1 -6
View File
@@ -1,10 +1,5 @@
{ inputs, ... }:
{
_: {
description = "Codex Desktop for Linux";
includes = [ "applications.codex" ];
imports.nixos = [
inputs.codex-desktop-linux.nixosModules.default
];
}
+3 -11
View File
@@ -4,15 +4,7 @@
...
}:
{
programs.codexDesktopLinux = {
enable = true;
cliPackage = inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.codex;
remoteControl.enable = true;
remoteMobileControl.enable = true;
computerUseUi.enable = false;
linuxFeatures = [
"appshots"
"open-target-discovery"
];
};
environment.systemPackages = [
inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.chatgpt
];
}
@@ -0,0 +1,52 @@
{
lib,
pkgs,
inputs,
...
}:
let
codexSessionUsage = inputs.codex-session-usage.packages.${pkgs.stdenv.hostPlatform.system}.default;
in
{
home.packages = [ codexSessionUsage ];
xdg.dataFile = {
"vicinae/scripts/codex-session-usage/start" = {
executable = true;
text = ''
#!${lib.getExe pkgs.bash}
# @vicinae.schemaVersion 1
# @vicinae.title Start Codex Session Usage
# @vicinae.description Start the local Codex session usage dashboard
# @vicinae.mode compact
# @vicinae.icon 📊
# @vicinae.argument1 { "type": "text", "placeholder": "Port (optional)", "optional": true }
if [[ -z "$1" ]]; then
exec ${lib.getExe codexSessionUsage} start
fi
if [[ "$1" =~ ^[0-9]+$ ]] && (( 10#$1 >= 1 && 10#$1 <= 65535 )); then
exec ${lib.getExe codexSessionUsage} start --port "$1"
fi
printf '%s\n' 'Port must be an integer between 1 and 65535.' >&2
exit 2
'';
};
"vicinae/scripts/codex-session-usage/stop" = {
executable = true;
text = ''
#!${lib.getExe pkgs.bash}
# @vicinae.schemaVersion 1
# @vicinae.title Stop Codex Session Usage
# @vicinae.description Stop the local Codex session usage dashboard
# @vicinae.mode compact
# @vicinae.icon 📊
exec ${lib.getExe codexSessionUsage} stop
'';
};
};
}
+13
View File
@@ -0,0 +1,13 @@
model = "gpt-5.6-sol"
model_reasoning_effort = "medium"
approval_policy = "on-request"
approvals_reviewer = "auto_review"
sandbox_mode = "workspace-write"
web_search = "cached"
[sandbox_workspace_write]
network_access = false
[projects."/home/moons/dotfiles"]
trust_level = "trusted"
+34 -4
View File
@@ -1,6 +1,36 @@
{ inputs, pkgs, ... }:
{
home.packages = [
inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.codex
];
config,
inputs,
lib,
pkgs,
...
}:
let
configDirectory =
if config.home.preferXdgDirectories then
"${config.xdg.configHome}/codex"
else
"${config.home.homeDirectory}/.codex";
configFile = "${configDirectory}/config.toml";
in
{
programs.codex = {
enable = true;
package = inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.codex;
skills = {
grilling = inputs.skills + "/skills/productivity/grilling";
};
};
# Keep the repository copy as an initial value. Codex may mutate the live
# file between activations; each Home Manager switch resets it from here.
home.activation.resetCodexConfig = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
${pkgs.coreutils}/bin/mkdir -p ${lib.escapeShellArg configDirectory}
${pkgs.coreutils}/bin/install -m 0600 ${./config.toml} ${lib.escapeShellArg configFile}
'';
};
}
@@ -0,0 +1,8 @@
{ inputs, ... }:
{
description = "Container-based networking labs";
includes = [ "services.docker" ];
imports.nixos = [ inputs.containerlab.nixosModules.default ];
}
@@ -0,0 +1,17 @@
{
inputs,
pkgs,
primaryUser,
}:
{
programs.containerlab.enable = true;
users.users.${primaryUser}.extraGroups = [ "clab_admins" ];
programs.containerlab.package =
inputs.containerlab.packages.${pkgs.stdenv.hostPlatform.system}.default.overrideAttrs
(_old: {
vendorHash = "sha256-xp6YIoqJdUu1zEzw7s7+lh8iGJD4THokF5NPbxLH6zc=";
});
}
@@ -0,0 +1,22 @@
{
inputs,
osConfig,
pkgs,
...
}:
let
unstable = import inputs.nixpkgs-unstable {
inherit (pkgs.stdenv.hostPlatform) system;
# Keep default CUDA targets so dependencies match the CUDA binary cache.
config = pkgs.config // {
cudaSupport = osConfig.my.hardwares.nvidia.enable;
};
};
in
{
home.packages = [
(unstable.darktable.override {
withAi = true;
})
];
}
+14 -1
View File
@@ -1,6 +1,15 @@
_: {
{
inputs,
pkgs,
...
}:
let
unstable = inputs.nixpkgs-unstable.legacyPackages.${pkgs.stdenv.hostPlatform.system};
in
{
programs.vesktop = {
enable = true;
package = unstable.vesktop;
settings = {
discordBranch = "stable";
@@ -16,6 +25,10 @@ _: {
openLinksWithElectron = false;
# Keep WebRTC on the public interface selected by the default route.
# Secondary private interfaces can otherwise stall voice at DTLS.
webRTCIPHandlingPolicy = "default_public_interface_only";
spellCheckLanguages = [
"ja-JP"
"en-US"
+4
View File
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.ffmpeg ];
}
+7 -1
View File
@@ -1,6 +1,12 @@
{ inputs, system, ... }: {
programs.ghostty = {
systemd.enable = true;
# Labwc's Close action correctly targets one xdg-toplevel, but Ghostty's
# systemd service runs every window in one GTK single-instance process.
# If that process exits while handling the request, every Ghostty window
# disappears together. Keep each launcher invocation independent instead.
systemd.enable = false;
package = inputs.ghostty.packages.${system}.default;
settings.gtk-single-instance = false;
};
}
-2
View File
@@ -38,8 +38,6 @@ in
ignores = [
".direnv/"
".envrc"
"!.envrc.example"
];
signing = {
-8
View File
@@ -1,8 +0,0 @@
{
homebrew.casks = [ "handy" ];
launchd.agents.handy = {
command = "/usr/bin/open -gja Handy --args --start-hidden";
serviceConfig.RunAtLoad = true;
};
}
-74
View File
@@ -1,74 +0,0 @@
{
config,
inputs,
lib,
pkgs,
...
}:
let
handy = inputs.handy.packages.${pkgs.stdenv.hostPlatform.system}.handy;
settingsFile = "${config.xdg.configHome}/com.pais.handy/settings_store.json";
in
{
home.packages = [
handy
pkgs.wtype
];
# Handy has no disabled-shortcut setting. Empty bindings are rejected before
# registration, leaving niri and labwc as the sole owners of Ctrl+Space.
home.activation.disableHandyGlobalShortcuts = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
settingsFile=${lib.escapeShellArg settingsFile}
mkdir -p "$(dirname "$settingsFile")"
if [ -f "$settingsFile" ]; then
${lib.getExe pkgs.jq} \
'.settings.bindings.transcribe.current_binding = ""
| .settings.bindings.transcribe_with_post_process.current_binding = ""' \
"$settingsFile" > "$settingsFile.tmp"
else
${lib.getExe pkgs.jq} -n '
{
settings: {
bindings: {
transcribe: {
id: "transcribe",
name: "Transcribe",
description: "Converts your speech into text.",
default_binding: "ctrl+space",
current_binding: ""
},
transcribe_with_post_process: {
id: "transcribe_with_post_process",
name: "Transcribe with Post-Processing",
description: "Converts your speech into text and applies AI post-processing.",
default_binding: "ctrl+shift+space",
current_binding: ""
}
}
}
}
' > "$settingsFile.tmp"
fi
mv "$settingsFile.tmp" "$settingsFile"
'';
};
systemd.user.services.handy = {
Unit = {
Description = "Handy speech-to-text";
After = [ "graphical-session.target" ];
PartOf = [ "graphical-session.target" ];
};
Service = {
ExecStart = "${lib.getExe handy} --start-hidden";
Restart = "on-failure";
RestartSec = 5;
};
Install.WantedBy = [ "graphical-session.target" ];
};
}
-3
View File
@@ -1,3 +0,0 @@
{
description = "Handy offline speech-to-text";
}
+4
View File
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.htop ];
}
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.python314Packages.huggingface-hub ];
}
+2 -6
View File
@@ -102,8 +102,6 @@ in
(action "W-q" "Close")
(action "W-f" "ToggleMaximize")
(action "W-c" "Iconify")
(action "W-Tab" "NextWindow")
(action "W-S-Tab" "PreviousWindow")
(action "W-Up" "Lower")
(action "W-Down" "Raise")
(action "W-Left" "NextWindow")
@@ -123,14 +121,12 @@ in
(execute "W-s" "noctalia msg panel-toggle launcher")
(execute "W-e" "nautilus --new-window")
(execute "W-l" "loginctl lock-session")
(execute "W-v" "vicinae vicinae://launch/clipboard/history?toggle=true")
(execute "W-v" "vicinae vicinae://launch/clipboard/history")
(execute "W-j" "nani-translate-primary")
(execute "W-S-j" "normcap-translate")
(execute "W-S-j" "nani-translate-ocr")
(execute "W-C-j" "${lib.getExe' pkgs.xdg-utils "xdg-open"} naniapp://translate")
(execute "W-space" "ghostty +toggle-quick-terminal")
(execute "W-p" "wdisplays")
(execute "W-z" "wl-find-cursor -c 0xCCFF453A -s 160 -d 1200")
(execute "C-space" "handy --toggle-transcription")
# Function keys (sync with niri modules/applications/niri/home.nix)
(execute "XF86AudioRaiseVolume" "noctalia msg volume-up")
-1
View File
@@ -4,6 +4,5 @@
includes = [
"systems.wayland"
"applications.screenshot"
"applications.wl-find-cursor"
];
}
+1 -6
View File
@@ -6,16 +6,11 @@
}:
let
unstable = inputs.nixpkgs-unstable.legacyPackages.${pkgs.stdenv.hostPlatform.system};
labwc = unstable.labwc.overrideAttrs (oldAttrs: {
patches = (oldAttrs.patches or [ ]) ++ [
./patches/remove-ext-workspace-output-on-destroy.patch
];
});
in
{
programs.labwc = {
enable = true;
package = labwc;
package = unstable.labwc;
};
xdg.portal.config.labwc.default = [
@@ -1,28 +0,0 @@
From: Codex <[email protected]>
Subject: [PATCH] output: remove destroyed output from ext-workspace group
The DRM backend destroys and recreates outputs when a session is paused and
resumed. Remove the output from the ext-workspace group before wlroots
finishes it, otherwise the group's output_bind listener remains attached and
wlr_output_finish() aborts.
---
src/output.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/src/output.c b/src/output.c
index 2eab8ec..f19c3ff 100644
--- a/src/output.c
+++ b/src/output.c
@@ -277,6 +277,9 @@ handle_output_destroy(struct wl_listener *listener, void *data)
struct seat *seat = &server.seat;
regions_evacuate_output(output);
regions_destroy(seat, &output->regions);
+ wlr_ext_workspace_group_handle_v1_output_leave(
+ server.workspaces.ext_group, output->wlr_output);
+
if (seat->overlay.active.output == output) {
overlay_finish(seat);
}
--
2.51.0
@@ -1,167 +0,0 @@
# shellcheck shell=bash
set -o errexit -o nounset -o pipefail
playlist_file="$1"
default_id="$2"
configuration_id="$3"
shift 3
state_dir="${XDG_RUNTIME_DIR:?}/linux-wallpaperengine"
state_file="$state_dir/current"
usage() {
printf '%s\n' \
'Usage: wallpaperengine-wallpaper COMMAND [ID]' \
'' \
'Commands:' \
' select ID Select a declaratively configured ID for this session' \
' next Select the next configured ID' \
' previous Select the previous configured ID' \
' list List configured IDs and mark the selected one' \
' current Print the selected ID' \
' restart Restart the selected wallpaper' \
' stop Stop Wallpaper Engine for this session'
}
load_playlist() {
mapfile -t wallpaper_ids < <(awk '/^[0-9]+$/ && !seen[$0]++' "$playlist_file")
if [ "${#wallpaper_ids[@]}" -eq 0 ]; then
echo "wallpaperengine-wallpaper: no wallpaper IDs are configured in settings.nix" >&2
exit 1
fi
}
contains_id() {
local candidate="$1"
local id
for id in "${wallpaper_ids[@]}"; do
[ "$id" = "$candidate" ] && return 0
done
return 1
}
current_id() {
local saved_configuration=""
local saved_id=""
local -a saved_state=()
if [ -s "$state_file" ]; then
mapfile -t saved_state <"$state_file"
saved_configuration="${saved_state[0]:-}"
saved_id="${saved_state[1]:-}"
fi
if [ "$saved_configuration" = "$configuration_id" ] && contains_id "$saved_id"; then
printf '%s\n' "$saved_id"
else
printf '%s\n' "$default_id"
fi
}
select_id() {
local id="$1"
if ! contains_id "$id"; then
echo "wallpaperengine-wallpaper: ID is not declared in settings.nix: $id" >&2
exit 2
fi
mkdir -p "$state_dir"
printf '%s\n%s\n' "$configuration_id" "$id" >"$state_file"
systemctl --user restart linux-wallpaperengine.service
}
cycle() {
local step="$1"
local current
local index=0
local next_index
current=$(current_id)
for i in "${!wallpaper_ids[@]}"; do
if [ "${wallpaper_ids[$i]}" = "$current" ]; then
index="$i"
break
fi
done
next_index=$(((index + step + ${#wallpaper_ids[@]}) % ${#wallpaper_ids[@]}))
select_id "${wallpaper_ids[$next_index]}"
}
load_playlist
command="${1:-}"
if [ -z "$command" ]; then
usage
exit 2
fi
shift
case "$command" in
select)
[ "$#" -eq 1 ] || {
usage >&2
exit 2
}
select_id "$1"
;;
next)
[ "$#" -eq 0 ] || {
usage >&2
exit 2
}
cycle 1
;;
previous)
[ "$#" -eq 0 ] || {
usage >&2
exit 2
}
cycle -1
;;
list)
[ "$#" -eq 0 ] || {
usage >&2
exit 2
}
current=$(current_id)
for id in "${wallpaper_ids[@]}"; do
if [ "$id" = "$current" ]; then
printf '* %s\n' "$id"
else
printf ' %s\n' "$id"
fi
done
;;
current)
[ "$#" -eq 0 ] || {
usage >&2
exit 2
}
current_id
;;
restart)
[ "$#" -eq 0 ] || {
usage >&2
exit 2
}
systemctl --user restart linux-wallpaperengine.service
;;
stop)
[ "$#" -eq 0 ] || {
usage >&2
exit 2
}
systemctl --user stop linux-wallpaperengine.service
;;
help | -h | --help)
usage
;;
*)
usage >&2
exit 2
;;
esac
@@ -1,57 +0,0 @@
# shellcheck shell=bash
set -o errexit -o nounset -o pipefail
playlist_file="$1"
default_id="$2"
configuration_id="$3"
assets_dir="$4"
workshop_dir="$5"
scaling="$6"
shift 6
state_file="${XDG_RUNTIME_DIR:?}/linux-wallpaperengine/current"
wallpaper_id="$default_id"
saved_configuration=""
saved_id=""
saved_state=()
outputs=()
if [ -s "$state_file" ]; then
mapfile -t saved_state <"$state_file"
saved_configuration="${saved_state[0]:-}"
saved_id="${saved_state[1]:-}"
if [ "$saved_configuration" = "$configuration_id" ] &&
awk -v id="$saved_id" '$0 == id { found = 1 } END { exit !found }' "$playlist_file"; then
wallpaper_id="$saved_id"
fi
fi
wallpaper_path="$workshop_dir/$wallpaper_id"
if [ ! -d "$wallpaper_path" ]; then
echo "linux-wallpaperengine: missing declared wallpaper: $wallpaper_path" >&2
exit 1
fi
if [ ! -d "$assets_dir" ]; then
echo "linux-wallpaperengine: missing Wallpaper Engine assets: $assets_dir" >&2
exit 1
fi
mapfile -t outputs < <(wlr-randr --json | jq -r '.[] | select(.enabled == true) | .name')
if [ "${#outputs[@]}" -eq 0 ]; then
echo "linux-wallpaperengine: no enabled Wayland outputs were detected" >&2
exit 1
fi
engine_args=("$@" --assets-dir "$assets_dir")
for output in "${outputs[@]}"; do
engine_args+=(
--screen-root "$output"
--bg "$wallpaper_path"
--scaling "$scaling"
)
done
exec linux-wallpaperengine "${engine_args[@]}"
@@ -1,158 +0,0 @@
{
config,
lib,
pkgs,
...
}:
let
settings = import ../settings.nix;
inherit (settings)
assetsDirectory
fps
mute
scaling
selectedWallpaperId
switchIntervalSeconds
wallpaperIds
workshopDirectory
;
resolveHomePath =
path:
if lib.hasPrefix "~/" path then
"${config.home.homeDirectory}/${lib.removePrefix "~/" path}"
else if lib.hasPrefix "/" path then
path
else
"${config.home.homeDirectory}/${path}";
hasWallpapers = wallpaperIds != [ ];
defaultWallpaperId =
if selectedWallpaperId != null then
selectedWallpaperId
else if hasWallpapers then
lib.head wallpaperIds
else
"";
configurationId = builtins.hashString "sha256" (builtins.toJSON settings);
resolvedAssetsDirectory = resolveHomePath assetsDirectory;
resolvedWorkshopDirectory = resolveHomePath workshopDirectory;
playlist = pkgs.writeText "linux-wallpaperengine-playlist" (
lib.concatMapStringsSep "\n" (id: id) wallpaperIds + "\n"
);
engineArguments = lib.optional mute "--silent" ++ [
"--fps"
(toString fps)
];
controller = pkgs.writeShellApplication {
name = "wallpaperengine-wallpaper";
runtimeInputs = [
pkgs.coreutils
pkgs.gawk
pkgs.systemd
];
text = ''
exec ${lib.getExe pkgs.bash} ${./controller.sh} \
${lib.escapeShellArg playlist} \
${lib.escapeShellArg defaultWallpaperId} \
${lib.escapeShellArg configurationId} \
"$@"
'';
};
launcher = pkgs.writeShellApplication {
name = "linux-wallpaperengine-launcher";
runtimeInputs = [
pkgs.coreutils
pkgs.gawk
pkgs.jq
pkgs.linux-wallpaperengine
pkgs.wlr-randr
];
text = ''
exec ${lib.getExe pkgs.bash} ${./launcher.sh} \
${lib.escapeShellArg playlist} \
${lib.escapeShellArg defaultWallpaperId} \
${lib.escapeShellArg configurationId} \
${lib.escapeShellArg resolvedAssetsDirectory} \
${lib.escapeShellArg resolvedWorkshopDirectory} \
${lib.escapeShellArg scaling} \
${lib.escapeShellArgs engineArguments}
'';
};
in
assert lib.assertMsg (lib.all (
id: builtins.isString id && builtins.match "[0-9]+" id != null
) wallpaperIds) "linux-wallpaperengine: wallpaperIds must contain only numeric strings";
assert lib.assertMsg (
lib.unique wallpaperIds == wallpaperIds
) "linux-wallpaperengine: wallpaperIds must not contain duplicates";
assert lib.assertMsg (
selectedWallpaperId == null || builtins.elem selectedWallpaperId wallpaperIds
) "linux-wallpaperengine: selectedWallpaperId must be null or a member of wallpaperIds";
assert lib.assertMsg (
switchIntervalSeconds == null || (builtins.isInt switchIntervalSeconds && switchIntervalSeconds > 0)
) "linux-wallpaperengine: switchIntervalSeconds must be null or a positive integer";
assert lib.assertMsg (
builtins.isInt fps && fps > 0
) "linux-wallpaperengine: fps must be a positive integer";
assert lib.assertMsg (
builtins.isString assetsDirectory && assetsDirectory != ""
) "linux-wallpaperengine: assetsDirectory must be a non-empty string";
assert lib.assertMsg (
builtins.isString workshopDirectory && workshopDirectory != ""
) "linux-wallpaperengine: workshopDirectory must be a non-empty string";
assert lib.assertMsg (builtins.elem scaling [
"default"
"fill"
"fit"
"stretch"
]) "linux-wallpaperengine: scaling must be default, fill, fit, or stretch";
{
home.packages = [
controller
pkgs.linux-wallpaperengine
];
systemd.user.services = lib.optionalAttrs hasWallpapers {
linux-wallpaperengine = {
Unit = {
Description = "Linux Wallpaper Engine";
After = [ "graphical-session.target" ];
PartOf = [ "graphical-session.target" ];
};
Service = {
ExecStart = lib.getExe launcher;
Restart = "on-abnormal";
};
Install.WantedBy = [ "graphical-session.target" ];
};
linux-wallpaperengine-switch = {
Unit.Description = "Switch Linux Wallpaper Engine wallpaper";
Service = {
Type = "oneshot";
ExecStart = "${lib.getExe controller} next";
};
};
};
systemd.user.timers =
lib.optionalAttrs
(hasWallpapers && builtins.length wallpaperIds > 1 && switchIntervalSeconds != null)
{
linux-wallpaperengine-switch = {
Unit = {
Description = "Periodically switch Linux Wallpaper Engine wallpaper";
PartOf = [ "graphical-session.target" ];
};
Timer = {
OnActiveSec = "${toString switchIntervalSeconds}s";
OnUnitActiveSec = "${toString switchIntervalSeconds}s";
Unit = "linux-wallpaperengine-switch.service";
};
Install.WantedBy = [ "graphical-session.target" ];
};
};
}
@@ -1,3 +0,0 @@
{
description = "Wallpaper Engine backgrounds for Linux";
}
@@ -1,23 +0,0 @@
{
assetsDirectory = "~/.local/share/Steam/steamapps/common/wallpaper_engine/assets";
workshopDirectory = "~/.local/share/Steam/steamapps/workshop/content/431960";
wallpaperIds = [
"2833810156"
"2834355367"
"2836628501"
"2845095254"
"2859848175"
"2861661119"
"2982896307"
];
# null selects the first ID above.
selectedWallpaperId = null;
# Set a number such as 300 to rotate through multiple IDs.
switchIntervalSeconds = 300;
fps = 30;
mute = true;
scaling = "fill";
}
+74 -1
View File
@@ -1,5 +1,78 @@
_: {
{ pkgs, ... }:
let
tessdataBest = pkgs.runCommand "tessdata-best-jpn-eng-chi-sim" { } ''
mkdir -p "$out"
ln -s ${
pkgs.fetchurl {
url = "https://github.com/tesseract-ocr/tessdata_best/raw/main/jpn.traineddata";
hash = "sha256-Nr35rII/WRHmJMMNBVPokLirx8MaZbPvFNqUNljEC3k=";
}
} "$out/jpn.traineddata"
ln -s ${
pkgs.fetchurl {
url = "https://github.com/tesseract-ocr/tessdata_best/raw/main/eng.traineddata";
hash = "sha256-goCu0Hgv4nJXpo6hD+fvMkyg+Nhb0v0UXRwrVgvLZro=";
}
} "$out/eng.traineddata"
ln -s ${
pkgs.fetchurl {
url = "https://github.com/tesseract-ocr/tessdata_best/raw/main/chi_sim.traineddata";
hash = "sha256-T+8tEwbI6HYW1NPkxsZ/r11EvjNCKQz48vD246p+c1s=";
}
} "$out/chi_sim.traineddata"
'';
tesseract = pkgs.tesseract5.override {
tessdata = tessdataBest;
};
naniTranslatePrimary = pkgs.writeShellApplication {
name = "nani-translate-primary";
runtimeInputs = with pkgs; [
jq
wl-clipboard
xdg-utils
];
text = ''
selected_text="$(wl-paste --primary --no-newline)" || exit 0
[ -n "$selected_text" ] || exit 0
encoded_text="$(printf '%s' "$selected_text" | jq -sRr @uri)"
exec xdg-open "naniapp://translate?source=$encoded_text"
'';
};
naniTranslateOcr = pkgs.writeShellApplication {
name = "nani-translate-ocr";
runtimeInputs = with pkgs; [
grim
jq
slurp
tesseract
xdg-utils
];
text = ''
geometry="$(slurp)" || exit 0
captured_text="$(
grim -g "$geometry" - \
| tesseract stdin stdout -l jpn+eng+chi_sim --oem 1 --psm 6
)"
[ -n "$captured_text" ] || exit 0
encoded_text="$(printf '%s' "$captured_text" | jq -sRr @uri)"
exec xdg-open "naniapp://translate?source=$encoded_text"
'';
};
in
{
programs.naniTranslateLinux.enable = true;
xdg.mimeApps.defaultApplications."x-scheme-handler/naniapp" = "nani.desktop";
home.packages = [
naniTranslatePrimary
naniTranslateOcr
];
}
+4
View File
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.nano ];
}
@@ -0,0 +1,5 @@
{
description = "Sipeed NanoKVM-USB desktop client";
includes = [ "services.nanokvm-usb" ];
}
@@ -0,0 +1,42 @@
{ pkgs, ... }:
let
pname = "nanokvm-usb";
version = "1.1.4";
src = pkgs.fetchurl {
url = "https://github.com/sipeed/NanoKVM-USB/releases/download/v${version}/NanoKVM-USB-${version}-linux-x86_64.AppImage";
hash = "sha256-00MT4U2afv0qt3xFVhLr0SSmS2cLrKBlmfzqYEFuaVc=";
};
appimageContents = pkgs.appimageTools.extractType2 {
inherit pname src version;
};
nanokvm-usb = pkgs.appimageTools.wrapType2 {
inherit pname src version;
meta = {
description = "Sipeed NanoKVM-USB desktop client";
homepage = "https://github.com/sipeed/NanoKVM-USB";
license = pkgs.lib.licenses.gpl3Only;
platforms = [ "x86_64-linux" ];
mainProgram = "nanokvm-usb";
};
};
desktopItem = pkgs.makeDesktopItem {
name = pname;
desktopName = "NanoKVM-USB";
comment = "NanoKVM-USB Desktop";
exec = "nanokvm-usb --no-sandbox %U";
icon = "${appimageContents}/nanokvm-usb.png";
categories = [ "Utility" ];
startupWMClass = "NanoKVM-USB";
};
in
{
environment.systemPackages = [
nanokvm-usb
desktopItem
];
}
+1 -9
View File
@@ -162,14 +162,6 @@ in
"file://${config.home.homeDirectory}/Desktop Desktop"
"file://${config.home.homeDirectory}/Pictures Pictures"
"file://${config.home.homeDirectory}/Downloads Downloads"
"file://${config.home.homeDirectory}/projects projects"
"file://${config.home.homeDirectory}/Projects Projects"
];
home.activation.createProjectsDirectory = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
$DRY_RUN_CMD mkdir -p "$HOME/projects"
'';
};
}
+16 -38
View File
@@ -1,28 +1,14 @@
{ lib, pkgs, ... }:
let
keybindings = import ./keybindings.nix;
naniTranslatePrimary = pkgs.writeShellApplication {
name = "nani-translate-primary";
runtimeInputs = with pkgs; [
jq
wl-clipboard
xdg-utils
];
text = ''
selected_text="$(wl-paste --primary --no-newline)" || exit 0
[ -n "$selected_text" ] || exit 0
encoded_text="$(printf '%s' "$selected_text" | jq -sRr @uri)"
exec xdg-open "naniapp://translate?source=$encoded_text"
'';
};
in
{
home.packages = [ naniTranslatePrimary ];
programs.niri.settings = {
binds = keybindings // {
# niri window or focus move
"Mod+MouseMiddle".action.toggle-window-floating = [ ];
"Mod+Shift+Left" = {
action.focus-monitor-left = [ ];
hotkey-overlay.title = "Focus Monitor Left";
@@ -40,6 +26,18 @@ in
hotkey-overlay.title = "Focus Monitor Down";
};
# Use the modifier combinations in the opposite direction from Niri's defaults.
"Mod+WheelScrollDown".action.focus-column-right = [ ];
"Mod+WheelScrollUp".action.focus-column-left = [ ];
"Mod+Shift+WheelScrollDown" = {
cooldown-ms = 150;
action.focus-workspace-down = [ ];
};
"Mod+Shift+WheelScrollUp" = {
cooldown-ms = 150;
action.focus-workspace-up = [ ];
};
"Mod+Shift+Ctrl+Left" = {
action.move-window-to-monitor-left = [ ];
hotkey-overlay.title = "Move Window to Monitor Left";
@@ -108,7 +106,7 @@ in
"Mod+V" = {
action.spawn = [
"vicinae"
"vicinae://launch/clipboard/history?toggle=true"
"vicinae://launch/clipboard/history"
];
hotkey-overlay.title = "Clipboard History";
};
@@ -119,7 +117,7 @@ in
};
"Mod+Shift+J" = {
repeat = false;
action.spawn = [ "normcap-translate" ];
action.spawn = [ "nani-translate-ocr" ];
hotkey-overlay.title = "OCR and Translate with Nani";
};
"Mod+Ctrl+J" = {
@@ -141,26 +139,6 @@ in
action.spawn = "wdisplays";
hotkey-overlay.title = "Display Settings: wdisplays";
};
"Mod+Z" = {
action.spawn = [
"wl-find-cursor"
"-c"
"0xCCFF453A"
"-s"
"160"
"-d"
"1200"
];
hotkey-overlay.title = "Find Cursor";
};
"Ctrl+Space" = {
action.spawn = [
"handy"
"--toggle-transcription"
];
hotkey-overlay.title = "Toggle Handy Transcription";
};
# Function keys (sync with labwc modules/applications/labwc/home.nix)
"XF86AudioRaiseVolume".action.spawn = [
"noctalia"
-1
View File
@@ -5,7 +5,6 @@
includes = [
"systems.wayland"
"applications.screenshot"
"applications.wl-find-cursor"
];
imports = {
+3 -3
View File
@@ -1,6 +1,6 @@
{ lib, pkgs }:
let
version = "0.46.0";
version = "0.56.0";
architecture =
if pkgs.stdenv.hostPlatform.isx86_64 then
"x86_64"
@@ -10,8 +10,8 @@ let
throw "CodexBar CLI is only packaged for x86_64-linux and aarch64-linux";
hash =
{
x86_64 = "sha256-yMrOpu1WIv2sGVgvY9qf2XCoX2AXMSqR2b8bQDRU6os=";
aarch64 = "sha256-pCp3NOlxFN6zeH67W04WGSPbUae+ktzR5vEunWqu00g=";
x86_64 = "sha256-hzCnAyiizm8ZDfE1ONEP6S2Pdnskclm+XdDBBhEYVqE=";
aarch64 = "sha256-vfcgDEFpORPymcRYmlqvsjhV4pU7lNC8Vd9FDPI9UjM=";
}
.${architecture};
in
+3 -11
View File
@@ -13,14 +13,6 @@ let
--replace-fail "@codexbarPath@" "${lib.getExe codexbar}"
'';
noctaliaPatched =
inputs.noctalia.packages.${pkgs.stdenv.hostPlatform.system}.default.overrideAttrs
(oldAttrs: {
patches = (oldAttrs.patches or [ ]) ++ [
./patches/window-switcher-labwc.patch
];
});
wallpapers = pkgs.fetchFromGitHub {
owner = "moons-14";
repo = "wallpapers";
@@ -50,7 +42,7 @@ in
programs.noctalia = {
enable = true;
package = noctaliaPatched;
package = inputs.noctalia.packages.${pkgs.stdenv.hostPlatform.system}.default;
systemd.enable = true;
@@ -165,7 +157,7 @@ in
network-connection = {
type = "custom_button";
glyph = "access-point";
actions.left = "nm-connection-editor";
actions.left = "exec nm-connection-editor";
};
tray = {
type = "tray";
@@ -186,7 +178,7 @@ in
"google-chrome"
"code"
"dev.zed.Zed"
"codex-desktop"
"chatgpt"
"vesktop"
];
show_all_outputs = true;
@@ -1,79 +0,0 @@
diff --git a/src/shell/switcher/window_switcher.cpp b/src/shell/switcher/window_switcher.cpp
--- a/src/shell/switcher/window_switcher.cpp
+++ b/src/shell/switcher/window_switcher.cpp
@@ -286,12 +286,19 @@ indexLiveToplevelsByWindowId(const CompositorPlatform& platform, std::unordered_
continue;
}
- const auto mappedId = platform.compositorWindowIdForToplevelInfo(info);
- if (!mappedId.has_value() || mappedId->empty()) {
- continue;
+ std::string key;
+ if (const auto mappedId = platform.compositorWindowIdForToplevelInfo(info);
+ mappedId.has_value() && !mappedId->empty()) {
+ key = canonicalWindowId(*mappedId);
}
- const std::string key = canonicalWindowId(*mappedId);
+
+ // Generic wlroots compositors such as labwc do not provide a
+ // compositor-specific window ID. The wlr toplevel handle is stable
+ // for the lifetime of the window and is sufficient for switcher identity.
+ if (key.empty() && wlrHandle != 0) {
+ key = "toplevel:" + std::to_string(wlrHandle);
+ }
if (key.empty()) {
continue;
}
diff --git a/src/shell/bar/widgets/taskbar_widget.cpp b/src/shell/bar/widgets/taskbar_widget.cpp
--- a/src/shell/bar/widgets/taskbar_widget.cpp
+++ b/src/shell/bar/widgets/taskbar_widget.cpp
@@ -5,6 +5,7 @@
#include "compositors/workspace_backend.h"
#include "config/config_service.h"
#include "core/deferred_call.h"
+#include "core/process/process.h"
#include "i18n/i18n.h"
#include "render/core/color.h"
#include "render/core/renderer.h"
@@ -36,6 +37,18 @@
namespace {
+ [[nodiscard]] bool launchTaskbarOverview(const std::string& appId) {
+ constexpr const char* command = "noctalia-taskbar-overview";
+ if (appId.empty() || !process::commandExists(command)) {
+ return false;
+ }
+ return process::runAsync({
+ command,
+ "--app-id",
+ appId.c_str(),
+ });
+ }
+
// Integer centering; optional odd spare pixel on the end side (right/bottom).
[[nodiscard]] float centeredOffset(float extent, float content, float inset = 0.0F, bool oddSpareOnEnd = true) {
const float inner = std::max(0.0F, extent - inset * 2.0F);
@@ -373,6 +386,12 @@ void TaskbarWidget::activateOrLaunchPinned(const TaskModel& task) {
return;
}
+ const std::string overviewAppId =
+ !task.appId.empty() ? task.appId : (!task.desktopEntryId.empty() ? task.desktopEntryId : task.idLower);
+ if (launchTaskbarOverview(overviewAppId)) {
+ return;
+ }
+
const std::string cycleKey = !task.desktopEntryId.empty() ? task.desktopEntryId : task.idLower;
std::size_t& cursor = m_groupedAppCycleCursor[cycleKey];
if (cursor >= windows.size()) {
@@ -792,6 +811,9 @@ void TaskbarWidget::create() {
}
if (data.button == BTN_LEFT) {
if (!cycleCandidates.empty()) {
+ if (cycleCandidates.size() > 1 && launchTaskbarOverview(current->appId)) {
+ return;
+ }
std::size_t& cursor = m_groupedAppCycleCursor[cycleKey];
if (cursor >= cycleCandidates.size()) {
cursor = 0;
@@ -1,44 +0,0 @@
{ pkgs, ... }:
let
normcap = pkgs.normcap.override {
tesseract4 = pkgs.tesseract4.override {
enableLanguages = [
"chi_sim"
"jpn"
"eng"
];
};
};
normcapTranslate = pkgs.writeShellApplication {
name = "normcap-translate";
runtimeInputs = [
normcap
pkgs.jq
pkgs.xdg-utils
];
text = ''
captured_text="$(
normcap \
--cli-mode \
--screenshot-handler grim \
--show-introduction False \
--update False \
--detect-codes False \
--notification False \
-l jpn eng chi_sim
)" || exit 0
[ -n "$captured_text" ] || exit 0
encoded_text="$(printf '%s' "$captured_text" | jq -sRr @uri)"
exec xdg-open "naniapp://translate?source=$encoded_text"
'';
};
in
{
home.packages = [
normcap
normcapTranslate
];
}
-7
View File
@@ -1,7 +0,0 @@
{
description = "NormCap OCR screen capture";
includes = [
"applications.nani"
];
}
+14
View File
@@ -2,5 +2,19 @@
{
home.packages = [
inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.opencode
inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system}.oh-my-opencode
];
home.file.".omo/omo.jsonc".text = builtins.toJSON {
agents = {
sisyphus.model = "openai/gpt-5.6-sol";
hephaestus.model = "openai/gpt-5.6-terra";
prometheus.model = "openai/gpt-5.6-terra";
oracle.model = "openai/gpt-5.6-terra";
momus.model = "openai/gpt-5.6-terra";
librarian.model = "openai/gpt-5.6-luna";
explore.model = "openai/gpt-5.6-luna";
atlas.model = "openai/gpt-5.6-luna";
};
};
}
+18 -4
View File
@@ -13,10 +13,6 @@ lib.mkMerge [
User = "git";
AddKeysToAgent = "no";
};
"*.sfc.wide.ad.jp" = {
identityFile = "~/.ssh/id_ed25519_sk_rk";
identitiesOnly = true;
};
"*" = {
AddKeysToAgent = "no";
SetEnv.TERM = "xterm-256color";
@@ -24,9 +20,27 @@ lib.mkMerge [
};
extraConfig = ''
Match exec "test -n \"$SSH_AUTH_SOCK\" && test -S \"$SSH_AUTH_SOCK\""
IdentityAgent $SSH_AUTH_SOCK
Match exec "test -S %d/.1password/agent.sock"
IdentityAgent %d/.1password/agent.sock
'';
};
home.activation.generateSshKey = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
key="$HOME/.ssh/id_ed25519"
if [ ! -f "$key" ]; then
umask 077
mkdir -p "$HOME/.ssh"
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
echo "Generated SSH key at $key"
fi
'';
};
}
]
@@ -10,6 +10,8 @@ in
programs.vicinae = {
enable = true;
enableChromeIntegration = false;
settings = {
font.size = 11;
close_on_focus_loss = true;
@@ -8,9 +8,6 @@ let
in
{
programs.vicinae = {
package = pkgs.vicinae;
systemd = {
enable = true;
autoStart = true;
@@ -1,7 +0,0 @@
{ inputs, pkgs, ... }:
let
unstable = inputs.nixpkgs-unstable.legacyPackages.${pkgs.stdenv.hostPlatform.system};
in
{
home.packages = [ unstable.wl-find-cursor ];
}
@@ -1,3 +0,0 @@
{
description = "Wayland cursor locator";
}
+8
View File
@@ -0,0 +1,8 @@
{
homebrew = {
enable = true;
masApps = {
Xcode = 497799835;
};
};
}
+4
View File
@@ -0,0 +1,4 @@
{ pkgs, ... }:
{
home.packages = [ pkgs.yt-dlp ];
}
+7
View File
@@ -4,8 +4,12 @@
extensions = [
"catppuccin"
"nix"
"dockerfile"
"terraform"
];
mutableUserSettings = false;
mutableUserKeymaps = false;
userKeymaps = import ./keymaps.nix;
userSettings = {
agent = {
@@ -36,6 +40,9 @@
light = "Catppuccin Latte";
dark = "Catppuccin Mocha";
};
edit_predictions = {
provider = "copilot";
};
};
};
}
+38
View File
@@ -0,0 +1,38 @@
[
{
context = "Editor && vim_mode == normal";
bindings = {
# This selected native-equivalent subset preserves Zed's Vim defaults for
# K, gd, grr, gri, gra, gO, ]d, [d, zM, zR, [b, and ]b.
"g r t" = "editor::GoToTypeDefinition";
"space space" = "pane::AlternateFile";
"space r n" = "editor::Rename";
"space c a" = "editor::ToggleCodeActions";
"space c f" = "editor::Format";
"space d l" = "editor::Hover";
"space e" = "project_panel::Toggle";
"space t t" = "terminal_panel::Toggle";
"space b c" = "pane::CloseActiveItem";
"space f f" = "file_finder::Toggle";
"space f g" = "pane::DeploySearch";
"space f b" = "tab_switcher::ToggleAll";
"space f s" = "outline::Toggle";
"space f shift-s" = "project_symbols::Toggle";
"space x x" = "diagnostics::Deploy";
};
}
{
# Keep normal-mode editor navigation out of terminals and other panels.
context = "Editor && vim_mode == normal && !menu";
bindings = {
"ctrl-h" = "workspace::ActivatePaneLeft";
"ctrl-j" = "workspace::ActivatePaneDown";
"ctrl-k" = "workspace::ActivatePaneUp";
"ctrl-l" = "workspace::ActivatePaneRight";
"ctrl-left" = "workspace::ActivatePaneLeft";
"ctrl-down" = "workspace::ActivatePaneDown";
"ctrl-up" = "workspace::ActivatePaneUp";
"ctrl-right" = "workspace::ActivatePaneRight";
};
}
]
+1 -4
View File
@@ -5,10 +5,7 @@
modesetting.enable = true;
open = true;
powerManagement = {
enable = true;
kernelSuspendNotifier = true;
};
powerManagement.enable = true;
moduleParams.nvidia.NVreg_TemporaryFilePath = "/var/tmp";
+31 -7
View File
@@ -24,6 +24,7 @@ required on every supported host.
| Profile | Supported host class |
| ------------------------------------ | --------------------------------------------- |
| `base` | NixOS, macOS |
| `interface.minimal` | NixOS, macOS with Home Manager |
| `interface.cli` | NixOS, macOS with Home Manager |
| `interface.gui` | NixOS, macOS with Home Manager |
| `interface.macos` | macOS |
@@ -36,10 +37,15 @@ required on every supported host.
| `platform.laptop` | Physical NixOS laptop |
| `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS |
| `platform.vm` | UEFI QEMU NixOS guest with NFS client support |
| `workload.deploy-rs-target` | NixOS |
| `workload.development` | NixOS, macOS with Home Manager |
| `workload.game` | NixOS, macOS |
| `workload.machine-learning` | NixOS with Home Manager |
| `workload.network-lab` | NixOS |
| `workload.personal` | NixOS, macOS with Home Manager |
| `workload.photography` | NixOS with Home Manager |
| `workload.remote-access` | NixOS, macOS |
| `workload.camera` | NixOS |
| `workload.server` | NixOS, macOS with Home Manager |
| `networking.tailscale-client` | NixOS, macOS |
| `networking.tailscale-subnet-router` | NixOS |
@@ -58,18 +64,36 @@ selects labwc. A daily-use macOS development machine can combine
`interface.macos`, `workload.development`, and `workload.personal`. Hardware
support does not implicitly select an interface or workload.
`platform.nixos` selects the shared network foundation and the clatd service.
VM, laptop, and desktop platform profiles inherit both.
`interface.minimal` provides SSH client access and key generation, Nano, htop,
btop, fastfetch, unzip, wget, Direnv, Git, GnuPG, nh, Zellij, and Zsh for remote
administration. `interface.cli` includes that baseline and adds the configured
Neovim, Yazi, and the remaining interactive command-line tools.
`workload.machine-learning` provides the Hugging Face Hub CLI for hosts used
to download and publish machine learning models and datasets.
`workload.network-lab` provides containerlab using its upstream NixOS module,
the Docker service, and the NanoKVM-USB desktop client with serial-port access.
It is selected by galleria and x1g13.
`workload.photography` provides darktable with AI support from the locked
unstable package set. Its ONNX Runtime uses CUDA when the NVIDIA hardware unit
is enabled, and CPU inference otherwise. Keep the default CUDA capabilities
and forward compatibility to reuse the CUDA binary cache; these targets include
galleria's RTX 3060 Ti. OpenCL drivers remain owned by hardware units.
`workload.deploy-rs-target` enables OpenSSH and provisions the `nixdeploy`
service account with the narrowly scoped passwordless commands required for
deploy-rs activation and rollback confirmation.
`workload.personal` provides Pear Desktop on both NixOS and macOS. Home Manager
enables performance improvements, synced lyrics, tracker blocking, the album
color theme, and custom output-device selection while preserving user-owned
settings such as the selected device.
`workload.personal` also provides Handy for offline speech-to-text. It starts
hidden when the graphical session begins. On niri and labwc, `Ctrl+Space` is
owned by the compositor and invokes Handy's `--toggle-transcription` command;
Handy's own shortcut bindings are disabled on NixOS so it does not monitor
keyboard events under Wayland. Handy uses the Homebrew cask and starts at login
on macOS.
`workload.personal` provides ActivityWatch for local activity tracking. On
NixOS, its server and Wayland-compatible watcher run as Home Manager user
services. On macOS, the Homebrew cask starts at login.
+4 -19
View File
@@ -8,36 +8,21 @@
dust
eza
fd
fastfetch
fzf
htop
jq
lsof
nurl
ripgrep
tio
unrar
unzip
wget
traceroute
tcpdump
iw
nmap
]
++ lib.optionals stdenv.isLinux [
lm_sensors
psmisc
strace
];
home.activation.generateSshKey = {
after = [ "writeBoundary" ];
before = [ ];
data = ''
key="$HOME/.ssh/id_ed25519"
if [ ! -f "$key" ]; then
umask 077
mkdir -p "$HOME/.ssh"
${pkgs.openssh}/bin/ssh-keygen -t ed25519 -N "" -f "$key" \
-C "moons@$(${pkgs.hostname}/bin/hostname || echo host)"
echo "Generated SSH key at $key"
fi
'';
};
}
+1 -8
View File
@@ -2,17 +2,10 @@
description = "Cross-platform interactive command-line environment";
includes = [
"applications.btop"
"applications.direnv"
"applications.git"
"applications.gnupg"
"applications.nh"
"profiles.interface.minimal"
"applications.nix-index"
"applications.ssh"
"applications.vim"
"applications.yazi"
"applications.zellij"
"applications.zoxide"
"applications.zsh"
];
}
@@ -4,8 +4,6 @@
pkgs.playerctl
];
programs.noctalia.settings.wallpaper.enabled = false;
xdg.userDirs = {
enable = true;
createDirectories = true;
@@ -17,5 +15,6 @@
publicShare = "$HOME/Public";
templates = "$HOME/Templates";
videos = "$HOME/Videos";
projects = "$HOME/Projects";
};
}
@@ -11,15 +11,15 @@
"applications.ghostty"
"applications.gtk"
"applications.loupe"
"applications.linux-wallpaperengine"
"applications.nautilus"
"applications.normcap"
"applications.nani"
"applications.papers"
"applications.qalculate-gtk"
"applications.resources"
"applications.vlc"
"hardwares.graphics"
"services.gvfs"
"services.evremap"
"services.polkit-gnome"
"systems.audio"
"systems.fonts"
@@ -0,0 +1,8 @@
{ pkgs, ... }:
{
home.packages = with pkgs; [
fastfetch
unzip
wget
];
}
@@ -0,0 +1,16 @@
{
description = "Minimal cross-platform command-line environment for remote administration";
includes = [
"applications.btop"
"applications.direnv"
"applications.git"
"applications.gnupg"
"applications.htop"
"applications.nano"
"applications.nh"
"applications.ssh"
"applications.zellij"
"applications.zsh"
];
}
@@ -3,6 +3,7 @@
# every system sleep path; screen blanking while locked is handled by
# services.swayidle in the graphical session.
systemd.sleep.settings.Sleep = {
AllowSuspend = true;
AllowHibernation = false;
AllowHybridSleep = false;
AllowSuspendThenHibernate = false;
+1
View File
@@ -2,6 +2,7 @@
description = "Foundation shared by all NixOS platforms";
includes = [
"services.clatd"
"services.kmscon"
"systems.disko"
"systems.boot.base"
@@ -0,0 +1,5 @@
{
description = "Camera capture and virtual camera tools";
includes = [ "systems.boot.v4l2loopback" ];
}
@@ -0,0 +1,8 @@
{ pkgs, ... }:
{
environment.systemPackages = with pkgs; [
gphoto2
ffmpeg
v4l-utils
];
}
@@ -0,0 +1,8 @@
{
description = "NixOS deploy-rs deployment target";
includes = [
"services.openssh"
"users.nixdeploy"
];
}
@@ -4,7 +4,7 @@
bind
bun
nil
python312
python314
uv
];
}
@@ -6,6 +6,7 @@
"applications.claude"
"applications.codex"
"applications.codex-desktop"
"applications.codex-session-usage"
"applications.docker"
"applications.drawio"
"applications.ghostty"
@@ -13,6 +14,7 @@
"applications.java"
"applications.opencode"
"applications.vscode"
"applications.xcode"
"applications.zed"
];
}
@@ -0,0 +1,5 @@
{
description = "Machine learning tools";
includes = [ "applications.huggingface-cli" ];
}
@@ -0,0 +1,8 @@
{
description = "Network lab and hardware console environment";
includes = [
"applications.containerlab"
"applications.nanokvm-usb"
];
}
+2 -1
View File
@@ -6,8 +6,8 @@
"applications.activitywatch"
"applications.chrome"
"applications.discord"
"applications.ffmpeg"
"applications.gnome-text-editor"
"applications.handy"
"applications.kde"
"applications.moonlight"
"applications.slack"
@@ -15,5 +15,6 @@
"applications.obs"
"applications.nani"
"applications.thunderbird"
"applications.yt-dlp"
];
}
@@ -0,0 +1,5 @@
{
description = "RAW photo development and editing";
includes = [ "applications.darktable" ];
}
+3
View File
@@ -0,0 +1,3 @@
_: {
services.clatd.enable = true;
}
+3 -1
View File
@@ -1,5 +1,7 @@
{ primaryUser, ... }:
{ config, primaryUser, ... }:
{
hardware.nvidia-container-toolkit.enable = config.my.hardwares.nvidia.enable;
virtualisation.docker = {
enable = true;
autoPrune = {
+20
View File
@@ -0,0 +1,20 @@
{
services.evremap = {
enable = true;
settings = {
device_name = "VXE VXE Mouse 1K Dongle Mouse";
remap = [
{
input = [ "BTN_SIDE" ];
output = [ "KEY_LEFTMETA" ];
}
{
input = [ "BTN_EXTRA" ];
output = [ "BTN_SIDE" ];
}
];
};
};
}

Some files were not shown because too many files have changed in this diff Show More