refactor(flake): add user registry and multi-user host support

Separate user identity (data) from the reusable modules, and let a host
declare any number of users instead of exactly one.

- users/registry.nix: per-user identity (name, email, groups, authorized
  and signing keys) as the single source of identity; no user data is
  hardcoded in the modules.
- mkHost takes a `users` set keyed by username; per-user identity is
  injected into each home config via the `identity` module arg
  (extraSpecialArgs is per-host, so it cannot carry per-user data).
- modules/users.nix builds accounts from the registry; modules/ssh.nix no
  longer defines authorized keys (the registry owns them); home/git.nix
  and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops
  its now-redundant git identity override.
- Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the
  former lyrathorpe/ and system/ layout.
- Add standalone homeConfigurations (the portable subset: shell, git,
  editor, claude) and an exported homeModules output for use on machines
  not managed by this flake, or as an input to other flakes.

Behaviour-preserving for existing hosts: lyrathorpe-mbp and
emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400,
lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a
repeated authorized_keys entry. Fixes the SSH authorized-key leak (one
user's key was applied to every account), the hardcoded default git
identity, and the hardcoded EDaaS linger setting.
This commit is contained in:
Emma Thorpe
2026-06-29 12:27:52 +01:00
parent 906fae7e7b
commit 10cc6cceed
59 changed files with 286 additions and 175 deletions
+46
View File
@@ -0,0 +1,46 @@
# MacBook Pro (Apple Silicon, Asahi NixOS). Shared laptop options live in
# ../../modules/laptop.nix; only host-specific settings are here.
{ pkgs, ... }:
{
imports = [
./hardware-configuration.nix
];
# UEFI boot via systemd-boot. Asahi manages the EFI vars from macOS, so do not
# touch them from NixOS.
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = false;
networking.hostName = "Lyra-Asahi";
# Audio (PipeWire) and the swaylock PAM stack are inherited from
# workstation.nix. hardware.enableRedistributableFirmware is also set there;
# it is harmless here since Asahi supplies its own peripheral firmware below.
# Binary cache for the Asahi kernel/build artifacts, so the MBP pulls prebuilt
# outputs instead of compiling the Asahi kernel locally.
nix.settings = {
substituters = [ "https://nixos-apple-silicon.cachix.org" ];
trusted-public-keys = [
"nixos-apple-silicon.cachix.org-1:8psDu5SA5dAD7qA0zMy5UT292TxeEPzIz8VVEr2Js20="
];
};
# Apple peripheral firmware (Wi-Fi/Bluetooth). The directory is gitignored and
# populated out-of-band -- see README.
hardware.asahi.peripheralFirmwareDirectory = ../../modules/firmware;
environment.systemPackages = with pkgs; [
asahi-bless
asahi-nvram
asahi-btsync
asahi-wifisync
unzip
ppp
iptables
];
# See `man configuration.nix` / the stateVersion docs before changing.
system.stateVersion = "25.05";
}
@@ -0,0 +1,39 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
imports =
[ (modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [ "uas" "sdhci_pci" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "/dev/disk/by-uuid/217a7427-d799-4e0d-af4e-378db3b27467";
fsType = "ext4";
};
boot.initrd.luks.devices."cryptroot".device = "/dev/disk/by-uuid/4ec1a31b-a7ba-41bb-9bbc-4833cfc732b0";
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/420E-1902";
fsType = "vfat";
options = [ "fmask=0022" "dmask=0022" ];
};
swapDevices = [ {device = "/swapfile"; size = 8192;} ];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.wlan0.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "aarch64-linux";
}