refactor(flake): add user registry and multi-user host support

Separate user identity (data) from the reusable modules, and let a host
declare any number of users instead of exactly one.

- users/registry.nix: per-user identity (name, email, groups, authorized
  and signing keys) as the single source of identity; no user data is
  hardcoded in the modules.
- mkHost takes a `users` set keyed by username; per-user identity is
  injected into each home config via the `identity` module arg
  (extraSpecialArgs is per-host, so it cannot carry per-user data).
- modules/users.nix builds accounts from the registry; modules/ssh.nix no
  longer defines authorized keys (the registry owns them); home/git.nix
  and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops
  its now-redundant git identity override.
- Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the
  former lyrathorpe/ and system/ layout.
- Add standalone homeConfigurations (the portable subset: shell, git,
  editor, claude) and an exported homeModules output for use on machines
  not managed by this flake, or as an input to other flakes.

Behaviour-preserving for existing hosts: lyrathorpe-mbp and
emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400,
lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a
repeated authorized_keys entry. Fixes the SSH authorized-key leak (one
user's key was applied to every account), the hardcoded default git
identity, and the hardcoded EDaaS linger setting.
This commit is contained in:
Emma Thorpe
2026-06-29 12:27:52 +01:00
parent 906fae7e7b
commit 10cc6cceed
59 changed files with 286 additions and 175 deletions
+40
View File
@@ -0,0 +1,40 @@
# Raspberry Pi 5 (aarch64) headless server. Two roles, split into submodules:
# ./docker.nix (Docker host with a network socket) and ./reverse-proxy.nix
# (native nginx). The raspberry-pi-5 nixos-hardware profile (kernel, firmware,
# device tree) and key-only sshd (../../modules/ssh.nix) are layered on in the
# flake host table. Install notes: see ./README.md.
{ ... }:
{
imports = [
./hardware-configuration.nix
./docker.nix
./reverse-proxy.nix
];
# Match the flake's nixosConfigurations attribute name so `nh os switch`
# (which selects by the local hostname) resolves without an explicit -H flag.
networking.hostName = "lyrathorpe-rpi5";
# Headless server: the Sway desktop is intentionally not set up. modules/sway.nix is
# not imported and features.swayDesktop.enable defaults to false (declared in
# system/modules/features.nix), so this host keeps plain TTY/SSH login.
# Raspberry Pi boots via U-Boot + extlinux, not GRUB/systemd-boot. The
# raspberry-pi-5 nixos-hardware profile supplies the kernel, firmware and
# device tree.
boot.loader.grub.enable = false;
boot.loader.generic-extlinux-compatible.enable = true;
# Remote administration. Key-only policy and the authorized key come from
# ../../modules/ssh.nix; here we just enable the daemon and open the port.
services.openssh.enable = true;
# Default-deny inbound. Open only SSH here; the Docker and nginx submodules
# open their own ports (Docker via a source-restricted nftables rule, nginx
# via 80/443). List-valued, so these merge with the submodule definitions.
networking.firewall.enable = true;
networking.firewall.allowedTCPPorts = [ 22 ];
# See `man configuration.nix` / the stateVersion docs before changing.
system.stateVersion = "26.05";
}