refactor(flake): add user registry and multi-user host support

Separate user identity (data) from the reusable modules, and let a host
declare any number of users instead of exactly one.

- users/registry.nix: per-user identity (name, email, groups, authorized
  and signing keys) as the single source of identity; no user data is
  hardcoded in the modules.
- mkHost takes a `users` set keyed by username; per-user identity is
  injected into each home config via the `identity` module arg
  (extraSpecialArgs is per-host, so it cannot carry per-user data).
- modules/users.nix builds accounts from the registry; modules/ssh.nix no
  longer defines authorized keys (the registry owns them); home/git.nix
  and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops
  its now-redundant git identity override.
- Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the
  former lyrathorpe/ and system/ layout.
- Add standalone homeConfigurations (the portable subset: shell, git,
  editor, claude) and an exported homeModules output for use on machines
  not managed by this flake, or as an input to other flakes.

Behaviour-preserving for existing hosts: lyrathorpe-mbp and
emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400,
lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a
repeated authorized_keys entry. Fixes the SSH authorized-key leak (one
user's key was applied to every account), the hardcoded default git
identity, and the hardcoded EDaaS linger setting.
This commit is contained in:
Emma Thorpe
2026-06-29 12:27:52 +01:00
parent 906fae7e7b
commit 10cc6cceed
59 changed files with 286 additions and 175 deletions
+146 -74
View File
@@ -23,7 +23,7 @@
# Provides mkFlake: the systems/perSystem scaffolding used below.
flake-parts.url = "github:hercules-ci/flake-parts";
flake-parts.inputs.nixpkgs-lib.follows = "nixpkgs";
# Declarative Firefox add-ons (e.g. the Catppuccin theme); see lyrathorpe/user.nix.
# Declarative Firefox add-ons (e.g. the Catppuccin theme); see modules/users.nix.
firefox-addons = {
url = "gitlab:rycee/nur-expressions?dir=pkgs/firefox-addons";
inputs.nixpkgs.follows = "nixpkgs";
@@ -46,7 +46,7 @@
url = "github:cachix/git-hooks.nix";
inputs.nixpkgs.follows = "nixpkgs";
};
# Declarative Neovim (the editor; see lyrathorpe/home/editor.nix). Release
# Declarative Neovim (the editor; see home/editor.nix). Release
# branch matched to the pinned nixpkgs (26.05); follows our nixpkgs to keep a
# single nixpkgs in the closure. editor.nix sets programs.nixvim.nixpkgs.source
# to this same input so the home module doesn't warn about the pin.
@@ -97,6 +97,12 @@
"lens-desktop"
];
# Identity registry: who each user is (name, email, keys, groups), keyed
# by username. Threaded into the system layer as the `userRegistry`
# specialArg and into each user's home config as the `identity` module
# arg. See users/registry.nix, modules/users.nix, home/git.nix.
userRegistry = import ./users/registry.nix;
# nixpkgs + nix-daemon settings shared by NixOS and Darwin hosts.
commonModule = {
nixpkgs.overlays = overlays;
@@ -112,9 +118,9 @@
# Shared scaffolding for every NixOS host: common user, settings, home-manager.
baseModules = [
./lyrathorpe/user.nix
./system/modules/common-nixos.nix
./system/modules/features.nix
./modules/users.nix
./modules/common-nixos.nix
./modules/features.nix
commonModule
home-manager.nixosModules.home-manager
{
@@ -126,18 +132,19 @@
}
];
# mkHost :: { system, username, fullName, modules, homeModules } -> nixosSystem
# mkHost :: { system, modules, users, portable } -> nixosSystem
# Builds one machine by appending its host-specific modules to the shared
# baseModules. The user identity (username/fullName) is threaded through
# specialArgs so user.nix and the home modules stay host-agnostic, and the
# home-manager profile is keyed by the host's username.
# baseModules. `users` is an attrset keyed by username; each value carries
# that user's home-module list and optional per-host-user system bits
# (e.g. linger). Per-user identity is injected into each home config via
# the `identity` module arg (extraSpecialArgs is per-host, so it cannot
# carry per-user data); the system layer reads the global `userRegistry`
# restricted to this host's `hostUsers` set.
mkHost =
{
system,
username,
fullName,
modules,
homeModules,
users,
# Host form factor. Laptops inherit the default; a desktop host sets
# `portable = false` to drop mobile components (battery block,
# brightness keys) from the home-manager Sway config.
@@ -148,8 +155,7 @@
specialArgs = {
inherit
inputs
username
fullName
userRegistry
portable
;
};
@@ -157,16 +163,15 @@
baseModules
++ modules
++ [
{ _module.args.hostUsers = users; }
{
home-manager.extraSpecialArgs = {
inherit
inputs
username
fullName
portable
;
};
home-manager.users.${username}.imports = homeModules;
home-manager.extraSpecialArgs = { inherit inputs portable; };
home-manager.users = lib.mapAttrs (name: spec: {
imports = spec.homeModules;
_module.args.identity = userRegistry.${name} // {
username = name;
};
}) users;
}
];
};
@@ -185,19 +190,20 @@
}
];
# mkDarwinHost :: { system, username, fullName, modules, homeModules } -> darwinSystem
# mkDarwinHost :: { system, username, modules, homeModules } -> darwinSystem
# Darwin counterpart of mkHost. macOS already owns the login user, so we
# only attach the platform and home-manager; no NixOS user module here.
# Stays single-user (macOS owns the account); identity is still sourced
# from the registry so the shared home modules behave as on NixOS.
mkDarwinHost =
{
system,
username,
fullName,
modules,
homeModules,
}:
nix-darwin.lib.darwinSystem {
specialArgs = { inherit inputs username fullName; };
specialArgs = { inherit inputs username; };
modules =
darwinBaseModules
++ modules
@@ -206,40 +212,44 @@
nixpkgs.hostPlatform = system;
# macOS owns the account; point home-manager at its home dir.
users.users.${username}.home = "/Users/${username}";
home-manager.extraSpecialArgs = { inherit inputs username fullName; };
home-manager.users.${username}.imports = homeModules;
home-manager.extraSpecialArgs = { inherit inputs; };
home-manager.users.${username} = {
imports = homeModules;
_module.args.identity = userRegistry.${username} // {
inherit username;
};
};
}
];
};
# Host table — declarative registry of every machine. To add a host:
# give it a name, its `system`, the owning user, and the module lists.
# mapAttrs below turns each entry into a nixosConfiguration of the same name.
# give it a name, its `system`, its `users` set (each user's home-module
# list, plus optional per-host-user bits like linger), and the system
# `modules`. mapAttrs below turns each entry into a nixosConfiguration of
# the same name. Per-user home configs compose ./home (the shared bundle)
# with any per-user modules (e.g. ./users/emmathorpe/work.nix).
hosts = {
lyrathorpe-mbp = {
system = "aarch64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
modules = [
./system/machine/MBP-Asahi/configuration.nix
./system/modules/laptop.nix
./hosts/MBP-Asahi/configuration.nix
./modules/laptop.nix
nixos-apple-silicon.nixosModules.default
./lyrathorpe/swaywm.nix
./modules/sway.nix
];
homeModules = [
./lyrathorpe/home
./lyrathorpe/home/desktop.nix
users.lyrathorpe.homeModules = [
./home
./home/desktop.nix
];
};
lyrathorpe-t400 = {
system = "x86_64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
modules = [
./system/machine/T400/configuration.nix
./system/modules/laptop.nix
./system/modules/ssh.nix
./hosts/T400/configuration.nix
./modules/laptop.nix
./modules/ssh.nix
# No t400-specific profile exists; compose the generic ThinkPad +
# laptop/SSD/Intel building blocks (tp_smapi/acpi_call for battery
# thresholds, SSD + microcode defaults).
@@ -247,78 +257,76 @@
inputs.nixos-hardware.nixosModules.common-pc-laptop
inputs.nixos-hardware.nixosModules.common-pc-laptop-ssd
inputs.nixos-hardware.nixosModules.common-cpu-intel
./lyrathorpe/swaywm.nix
./modules/sway.nix
];
homeModules = [
./lyrathorpe/home
./lyrathorpe/home/desktop.nix
users.lyrathorpe.homeModules = [
./home
./home/desktop.nix
];
};
lyrathorpe-macpro31 = {
system = "x86_64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
portable = false;
modules = [
./system/machine/MacPro31/configuration.nix
./system/modules/desktop.nix
./system/modules/ssh.nix
./hosts/MacPro31/configuration.nix
./modules/desktop.nix
./modules/ssh.nix
inputs.nixos-hardware.nixosModules.common-pc-ssd
inputs.nixos-hardware.nixosModules.common-cpu-intel
./lyrathorpe/swaywm.nix
./modules/sway.nix
];
homeModules = [
./lyrathorpe/home
./lyrathorpe/home/desktop.nix
users.lyrathorpe.homeModules = [
./home
./home/desktop.nix
];
};
emmathorpe-edaas = {
system = "x86_64-linux";
username = "emmathorpe";
fullName = "Emma Thorpe";
modules = [
./system/machine/EDaaS/configuration.nix
./hosts/EDaaS/configuration.nix
nixos-wsl.nixosModules.default
./lyrathorpe/swaywm.nix
];
homeModules = [
./lyrathorpe/home
./lyrathorpe/home/work.nix
./modules/sway.nix
];
users.emmathorpe = {
homeModules = [
./home
./users/emmathorpe/work.nix
];
# Keep the systemd --user instance alive without a login session so
# the renovate-review home timer fires on schedule.
linger = true;
};
};
lyrathorpe-rpi5 = {
system = "aarch64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
portable = false;
# Headless server: Docker host + nginx reverse proxy. No swaywm.nix
# Headless server: Docker host + nginx reverse proxy. No sway.nix
# (no desktop); the raspberry-pi-5 profile supplies kernel/firmware,
# ssh.nix adds key-only sshd.
modules = [
./system/machine/RPi5/configuration.nix
./hosts/RPi5/configuration.nix
inputs.nixos-hardware.nixosModules.raspberry-pi-5
./system/modules/ssh.nix
./modules/ssh.nix
];
homeModules = [ ./lyrathorpe/home ];
users.lyrathorpe.homeModules = [ ./home ];
};
};
# Darwin host table — macOS machines built via mkDarwinHost. The shared
# ./lyrathorpe/home modules (shell, git, editor) are reused; the Linux-only
# ./home bundle (shell, git, editor) is reused directly; the Linux-only
# desktop/sway modules are intentionally left out.
darwinHosts = {
lyrathorpe-mac = {
system = "aarch64-darwin";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
modules = [
./system/machine/Darwin/configuration.nix
./hosts/Darwin/configuration.nix
];
homeModules = [
./lyrathorpe/home
./home
];
};
};
@@ -409,6 +417,70 @@
# Realise the host tables: each entry becomes a {nixos,darwin}Configuration.
flake.nixosConfigurations = lib.mapAttrs (_name: mkHost) hosts;
flake.darwinConfigurations = lib.mapAttrs (_name: mkDarwinHost) darwinHosts;
# Reusable home modules, exported so this config can be consumed off these
# hosts -- by a standalone home-manager on a non-NixOS machine, or as an
# input to someone else's flake. `default` is the portable bundle
# (shell + git + editor + claude). Consumers must supply the module args
# these expect: `inputs` always; `identity` (see users/registry.nix) for
# git/desktop; `portable` for sway. `desktop`/`sway` additionally require
# a NixOS host that provides the Sway/Firefox binary -- they are not
# standalone-portable.
flake.homeModules = {
default = ./home;
shell = ./home/shell.nix;
git = ./home/git.nix;
editor = ./home/editor.nix;
claude = ./home/claude.nix;
desktop = ./home/desktop.nix;
sway = ./home/sway.nix;
};
# Standalone home-manager configurations: the portable bundle built for a
# machine NOT managed by this flake (`home-manager switch --flake
# .#"<user>@<system>"`). Only the portable subset is exposed; the desktop
# suite stays NixOS-only. homeConfigurations are not per-system, so the
# system is encoded in the attribute name, and home.username/homeDirectory
# are set explicitly (the NixOS module sets them automatically; standalone
# does not).
flake.homeConfigurations =
let
mkHome =
{
system,
name,
}:
home-manager.lib.homeManagerConfiguration {
pkgs = import nixpkgs {
inherit system overlays;
config.allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) unfreePackages;
};
extraSpecialArgs = {
inherit inputs;
portable = true;
identity = userRegistry.${name} // {
username = name;
};
};
modules = [
./home
{
home.username = name;
home.homeDirectory = "/home/${name}";
}
];
};
in
{
"lyrathorpe@x86_64-linux" = mkHome {
system = "x86_64-linux";
name = "lyrathorpe";
};
"lyrathorpe@aarch64-linux" = mkHome {
system = "aarch64-linux";
name = "lyrathorpe";
};
};
}
);
}