refactor(flake): add user registry and multi-user host support
Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
This commit is contained in:
@@ -23,7 +23,7 @@
|
||||
# Provides mkFlake: the systems/perSystem scaffolding used below.
|
||||
flake-parts.url = "github:hercules-ci/flake-parts";
|
||||
flake-parts.inputs.nixpkgs-lib.follows = "nixpkgs";
|
||||
# Declarative Firefox add-ons (e.g. the Catppuccin theme); see lyrathorpe/user.nix.
|
||||
# Declarative Firefox add-ons (e.g. the Catppuccin theme); see modules/users.nix.
|
||||
firefox-addons = {
|
||||
url = "gitlab:rycee/nur-expressions?dir=pkgs/firefox-addons";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
@@ -46,7 +46,7 @@
|
||||
url = "github:cachix/git-hooks.nix";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
# Declarative Neovim (the editor; see lyrathorpe/home/editor.nix). Release
|
||||
# Declarative Neovim (the editor; see home/editor.nix). Release
|
||||
# branch matched to the pinned nixpkgs (26.05); follows our nixpkgs to keep a
|
||||
# single nixpkgs in the closure. editor.nix sets programs.nixvim.nixpkgs.source
|
||||
# to this same input so the home module doesn't warn about the pin.
|
||||
@@ -97,6 +97,12 @@
|
||||
"lens-desktop"
|
||||
];
|
||||
|
||||
# Identity registry: who each user is (name, email, keys, groups), keyed
|
||||
# by username. Threaded into the system layer as the `userRegistry`
|
||||
# specialArg and into each user's home config as the `identity` module
|
||||
# arg. See users/registry.nix, modules/users.nix, home/git.nix.
|
||||
userRegistry = import ./users/registry.nix;
|
||||
|
||||
# nixpkgs + nix-daemon settings shared by NixOS and Darwin hosts.
|
||||
commonModule = {
|
||||
nixpkgs.overlays = overlays;
|
||||
@@ -112,9 +118,9 @@
|
||||
|
||||
# Shared scaffolding for every NixOS host: common user, settings, home-manager.
|
||||
baseModules = [
|
||||
./lyrathorpe/user.nix
|
||||
./system/modules/common-nixos.nix
|
||||
./system/modules/features.nix
|
||||
./modules/users.nix
|
||||
./modules/common-nixos.nix
|
||||
./modules/features.nix
|
||||
commonModule
|
||||
home-manager.nixosModules.home-manager
|
||||
{
|
||||
@@ -126,18 +132,19 @@
|
||||
}
|
||||
];
|
||||
|
||||
# mkHost :: { system, username, fullName, modules, homeModules } -> nixosSystem
|
||||
# mkHost :: { system, modules, users, portable } -> nixosSystem
|
||||
# Builds one machine by appending its host-specific modules to the shared
|
||||
# baseModules. The user identity (username/fullName) is threaded through
|
||||
# specialArgs so user.nix and the home modules stay host-agnostic, and the
|
||||
# home-manager profile is keyed by the host's username.
|
||||
# baseModules. `users` is an attrset keyed by username; each value carries
|
||||
# that user's home-module list and optional per-host-user system bits
|
||||
# (e.g. linger). Per-user identity is injected into each home config via
|
||||
# the `identity` module arg (extraSpecialArgs is per-host, so it cannot
|
||||
# carry per-user data); the system layer reads the global `userRegistry`
|
||||
# restricted to this host's `hostUsers` set.
|
||||
mkHost =
|
||||
{
|
||||
system,
|
||||
username,
|
||||
fullName,
|
||||
modules,
|
||||
homeModules,
|
||||
users,
|
||||
# Host form factor. Laptops inherit the default; a desktop host sets
|
||||
# `portable = false` to drop mobile components (battery block,
|
||||
# brightness keys) from the home-manager Sway config.
|
||||
@@ -148,8 +155,7 @@
|
||||
specialArgs = {
|
||||
inherit
|
||||
inputs
|
||||
username
|
||||
fullName
|
||||
userRegistry
|
||||
portable
|
||||
;
|
||||
};
|
||||
@@ -157,16 +163,15 @@
|
||||
baseModules
|
||||
++ modules
|
||||
++ [
|
||||
{ _module.args.hostUsers = users; }
|
||||
{
|
||||
home-manager.extraSpecialArgs = {
|
||||
inherit
|
||||
inputs
|
||||
username
|
||||
fullName
|
||||
portable
|
||||
;
|
||||
};
|
||||
home-manager.users.${username}.imports = homeModules;
|
||||
home-manager.extraSpecialArgs = { inherit inputs portable; };
|
||||
home-manager.users = lib.mapAttrs (name: spec: {
|
||||
imports = spec.homeModules;
|
||||
_module.args.identity = userRegistry.${name} // {
|
||||
username = name;
|
||||
};
|
||||
}) users;
|
||||
}
|
||||
];
|
||||
};
|
||||
@@ -185,19 +190,20 @@
|
||||
}
|
||||
];
|
||||
|
||||
# mkDarwinHost :: { system, username, fullName, modules, homeModules } -> darwinSystem
|
||||
# mkDarwinHost :: { system, username, modules, homeModules } -> darwinSystem
|
||||
# Darwin counterpart of mkHost. macOS already owns the login user, so we
|
||||
# only attach the platform and home-manager; no NixOS user module here.
|
||||
# Stays single-user (macOS owns the account); identity is still sourced
|
||||
# from the registry so the shared home modules behave as on NixOS.
|
||||
mkDarwinHost =
|
||||
{
|
||||
system,
|
||||
username,
|
||||
fullName,
|
||||
modules,
|
||||
homeModules,
|
||||
}:
|
||||
nix-darwin.lib.darwinSystem {
|
||||
specialArgs = { inherit inputs username fullName; };
|
||||
specialArgs = { inherit inputs username; };
|
||||
modules =
|
||||
darwinBaseModules
|
||||
++ modules
|
||||
@@ -206,40 +212,44 @@
|
||||
nixpkgs.hostPlatform = system;
|
||||
# macOS owns the account; point home-manager at its home dir.
|
||||
users.users.${username}.home = "/Users/${username}";
|
||||
home-manager.extraSpecialArgs = { inherit inputs username fullName; };
|
||||
home-manager.users.${username}.imports = homeModules;
|
||||
home-manager.extraSpecialArgs = { inherit inputs; };
|
||||
home-manager.users.${username} = {
|
||||
imports = homeModules;
|
||||
_module.args.identity = userRegistry.${username} // {
|
||||
inherit username;
|
||||
};
|
||||
};
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
# Host table — declarative registry of every machine. To add a host:
|
||||
# give it a name, its `system`, the owning user, and the module lists.
|
||||
# mapAttrs below turns each entry into a nixosConfiguration of the same name.
|
||||
# give it a name, its `system`, its `users` set (each user's home-module
|
||||
# list, plus optional per-host-user bits like linger), and the system
|
||||
# `modules`. mapAttrs below turns each entry into a nixosConfiguration of
|
||||
# the same name. Per-user home configs compose ./home (the shared bundle)
|
||||
# with any per-user modules (e.g. ./users/emmathorpe/work.nix).
|
||||
hosts = {
|
||||
lyrathorpe-mbp = {
|
||||
system = "aarch64-linux";
|
||||
username = "lyrathorpe";
|
||||
fullName = "Lyra Thorpe";
|
||||
modules = [
|
||||
./system/machine/MBP-Asahi/configuration.nix
|
||||
./system/modules/laptop.nix
|
||||
./hosts/MBP-Asahi/configuration.nix
|
||||
./modules/laptop.nix
|
||||
nixos-apple-silicon.nixosModules.default
|
||||
./lyrathorpe/swaywm.nix
|
||||
./modules/sway.nix
|
||||
];
|
||||
homeModules = [
|
||||
./lyrathorpe/home
|
||||
./lyrathorpe/home/desktop.nix
|
||||
users.lyrathorpe.homeModules = [
|
||||
./home
|
||||
./home/desktop.nix
|
||||
];
|
||||
};
|
||||
|
||||
lyrathorpe-t400 = {
|
||||
system = "x86_64-linux";
|
||||
username = "lyrathorpe";
|
||||
fullName = "Lyra Thorpe";
|
||||
modules = [
|
||||
./system/machine/T400/configuration.nix
|
||||
./system/modules/laptop.nix
|
||||
./system/modules/ssh.nix
|
||||
./hosts/T400/configuration.nix
|
||||
./modules/laptop.nix
|
||||
./modules/ssh.nix
|
||||
# No t400-specific profile exists; compose the generic ThinkPad +
|
||||
# laptop/SSD/Intel building blocks (tp_smapi/acpi_call for battery
|
||||
# thresholds, SSD + microcode defaults).
|
||||
@@ -247,78 +257,76 @@
|
||||
inputs.nixos-hardware.nixosModules.common-pc-laptop
|
||||
inputs.nixos-hardware.nixosModules.common-pc-laptop-ssd
|
||||
inputs.nixos-hardware.nixosModules.common-cpu-intel
|
||||
./lyrathorpe/swaywm.nix
|
||||
./modules/sway.nix
|
||||
];
|
||||
homeModules = [
|
||||
./lyrathorpe/home
|
||||
./lyrathorpe/home/desktop.nix
|
||||
users.lyrathorpe.homeModules = [
|
||||
./home
|
||||
./home/desktop.nix
|
||||
];
|
||||
};
|
||||
|
||||
lyrathorpe-macpro31 = {
|
||||
system = "x86_64-linux";
|
||||
username = "lyrathorpe";
|
||||
fullName = "Lyra Thorpe";
|
||||
portable = false;
|
||||
modules = [
|
||||
./system/machine/MacPro31/configuration.nix
|
||||
./system/modules/desktop.nix
|
||||
./system/modules/ssh.nix
|
||||
./hosts/MacPro31/configuration.nix
|
||||
./modules/desktop.nix
|
||||
./modules/ssh.nix
|
||||
inputs.nixos-hardware.nixosModules.common-pc-ssd
|
||||
inputs.nixos-hardware.nixosModules.common-cpu-intel
|
||||
./lyrathorpe/swaywm.nix
|
||||
./modules/sway.nix
|
||||
];
|
||||
homeModules = [
|
||||
./lyrathorpe/home
|
||||
./lyrathorpe/home/desktop.nix
|
||||
users.lyrathorpe.homeModules = [
|
||||
./home
|
||||
./home/desktop.nix
|
||||
];
|
||||
};
|
||||
|
||||
emmathorpe-edaas = {
|
||||
system = "x86_64-linux";
|
||||
username = "emmathorpe";
|
||||
fullName = "Emma Thorpe";
|
||||
modules = [
|
||||
./system/machine/EDaaS/configuration.nix
|
||||
./hosts/EDaaS/configuration.nix
|
||||
nixos-wsl.nixosModules.default
|
||||
./lyrathorpe/swaywm.nix
|
||||
];
|
||||
homeModules = [
|
||||
./lyrathorpe/home
|
||||
./lyrathorpe/home/work.nix
|
||||
./modules/sway.nix
|
||||
];
|
||||
users.emmathorpe = {
|
||||
homeModules = [
|
||||
./home
|
||||
./users/emmathorpe/work.nix
|
||||
];
|
||||
# Keep the systemd --user instance alive without a login session so
|
||||
# the renovate-review home timer fires on schedule.
|
||||
linger = true;
|
||||
};
|
||||
};
|
||||
|
||||
lyrathorpe-rpi5 = {
|
||||
system = "aarch64-linux";
|
||||
username = "lyrathorpe";
|
||||
fullName = "Lyra Thorpe";
|
||||
portable = false;
|
||||
# Headless server: Docker host + nginx reverse proxy. No swaywm.nix
|
||||
# Headless server: Docker host + nginx reverse proxy. No sway.nix
|
||||
# (no desktop); the raspberry-pi-5 profile supplies kernel/firmware,
|
||||
# ssh.nix adds key-only sshd.
|
||||
modules = [
|
||||
./system/machine/RPi5/configuration.nix
|
||||
./hosts/RPi5/configuration.nix
|
||||
inputs.nixos-hardware.nixosModules.raspberry-pi-5
|
||||
./system/modules/ssh.nix
|
||||
./modules/ssh.nix
|
||||
];
|
||||
homeModules = [ ./lyrathorpe/home ];
|
||||
users.lyrathorpe.homeModules = [ ./home ];
|
||||
};
|
||||
};
|
||||
|
||||
# Darwin host table — macOS machines built via mkDarwinHost. The shared
|
||||
# ./lyrathorpe/home modules (shell, git, editor) are reused; the Linux-only
|
||||
# ./home bundle (shell, git, editor) is reused directly; the Linux-only
|
||||
# desktop/sway modules are intentionally left out.
|
||||
darwinHosts = {
|
||||
lyrathorpe-mac = {
|
||||
system = "aarch64-darwin";
|
||||
username = "lyrathorpe";
|
||||
fullName = "Lyra Thorpe";
|
||||
modules = [
|
||||
./system/machine/Darwin/configuration.nix
|
||||
./hosts/Darwin/configuration.nix
|
||||
];
|
||||
homeModules = [
|
||||
./lyrathorpe/home
|
||||
./home
|
||||
];
|
||||
};
|
||||
};
|
||||
@@ -409,6 +417,70 @@
|
||||
# Realise the host tables: each entry becomes a {nixos,darwin}Configuration.
|
||||
flake.nixosConfigurations = lib.mapAttrs (_name: mkHost) hosts;
|
||||
flake.darwinConfigurations = lib.mapAttrs (_name: mkDarwinHost) darwinHosts;
|
||||
|
||||
# Reusable home modules, exported so this config can be consumed off these
|
||||
# hosts -- by a standalone home-manager on a non-NixOS machine, or as an
|
||||
# input to someone else's flake. `default` is the portable bundle
|
||||
# (shell + git + editor + claude). Consumers must supply the module args
|
||||
# these expect: `inputs` always; `identity` (see users/registry.nix) for
|
||||
# git/desktop; `portable` for sway. `desktop`/`sway` additionally require
|
||||
# a NixOS host that provides the Sway/Firefox binary -- they are not
|
||||
# standalone-portable.
|
||||
flake.homeModules = {
|
||||
default = ./home;
|
||||
shell = ./home/shell.nix;
|
||||
git = ./home/git.nix;
|
||||
editor = ./home/editor.nix;
|
||||
claude = ./home/claude.nix;
|
||||
desktop = ./home/desktop.nix;
|
||||
sway = ./home/sway.nix;
|
||||
};
|
||||
|
||||
# Standalone home-manager configurations: the portable bundle built for a
|
||||
# machine NOT managed by this flake (`home-manager switch --flake
|
||||
# .#"<user>@<system>"`). Only the portable subset is exposed; the desktop
|
||||
# suite stays NixOS-only. homeConfigurations are not per-system, so the
|
||||
# system is encoded in the attribute name, and home.username/homeDirectory
|
||||
# are set explicitly (the NixOS module sets them automatically; standalone
|
||||
# does not).
|
||||
flake.homeConfigurations =
|
||||
let
|
||||
mkHome =
|
||||
{
|
||||
system,
|
||||
name,
|
||||
}:
|
||||
home-manager.lib.homeManagerConfiguration {
|
||||
pkgs = import nixpkgs {
|
||||
inherit system overlays;
|
||||
config.allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) unfreePackages;
|
||||
};
|
||||
extraSpecialArgs = {
|
||||
inherit inputs;
|
||||
portable = true;
|
||||
identity = userRegistry.${name} // {
|
||||
username = name;
|
||||
};
|
||||
};
|
||||
modules = [
|
||||
./home
|
||||
{
|
||||
home.username = name;
|
||||
home.homeDirectory = "/home/${name}";
|
||||
}
|
||||
];
|
||||
};
|
||||
in
|
||||
{
|
||||
"lyrathorpe@x86_64-linux" = mkHome {
|
||||
system = "x86_64-linux";
|
||||
name = "lyrathorpe";
|
||||
};
|
||||
"lyrathorpe@aarch64-linux" = mkHome {
|
||||
system = "aarch64-linux";
|
||||
name = "lyrathorpe";
|
||||
};
|
||||
};
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user