2 Commits
Author SHA1 Message Date
Renovate Bot 8e9a46f998 chore(deps): lock file maintenance flake inputs
renovate/stability-days Updates have not met minimum release age requirement
CI / flake (pull_request) Failing after 1m31s
2026-06-29 13:02:10 +00:00
lyrathorpeandEmma Thorpe 128deca2e3 refactor(flake): user registry, multi-user hosts, and portable home outputs (#49)
CI / flake (push) Successful in 3m26s
## Summary

Separates user identity (data) from the reusable Nix modules and lets a host declare any number of users, replacing the previous one-user-per-host structure. Also restructures the tree and exposes the home config for use off these hosts.

## Changes

- **User registry** (`users/registry.nix`): per-user identity (name, email, groups, authorized + signing keys) as the single source of truth; no user data hardcoded in modules.
- **Multi-user `mkHost`**: a host declares a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg.
- **Restructured layout**: `users/`, `home/`, `modules/`, `hosts/`, `lib/` replace the former `lyrathorpe/` and `system/` trees.
- **Portable outputs**: standalone `homeConfigurations."<user>@<system>"` (the portable subset — shell, git, editor, claude) plus an exported `homeModules` for use on machines not managed by this flake, or as an input to other flakes.
- Docs (`README.md`, `home/README.md`) and `.gitignore` updated for the new paths.

## Fixes

- Closes #46 — shared user module authorized one user's SSH key for every account.
- Closes #47 — git committer identity hardcoded as defaults instead of per-user.
- Closes #48 — EDaaS systemd linger hardcoded to a literal username.

## Verification

- `nix flake check` passes: treefmt, deadnix, statix, pre-commit, and evaluation of all NixOS hosts + Darwin + homeConfigurations.
- Derivation-path comparison vs `main`: `lyrathorpe-mbp` and `emmathorpe-edaas` are byte-identical; `lyrathorpe-t400`, `lyrathorpe-macpro31` and `lyrathorpe-rpi5` differ only by de-duplicating a repeated `authorized_keys` entry (confirmed with nix-diff — no other change).
- Standalone `homeConfigurations."lyrathorpe@x86_64-linux".activationPackage` builds.

## Notes

- `emmathorpe` has no personal authorized key yet (it previously inherited Lyra's key via the bug in #46); the registry entry is intentionally empty — add a real key if SSH login as `emmathorpe` is wanted (moot on the WSL host).
- A two-repo (public dotfiles / private systems) split is deferred by design; this internal restructure is the prerequisite for it.

---------

Co-authored-by: Emma Thorpe <emma.thorpe@citrix.com>
Reviewed-on: #49
2026-06-29 13:06:23 +01:00
62 changed files with 332 additions and 223 deletions
+1 -1
View File
@@ -1,4 +1,4 @@
system/modules/firmware/* modules/firmware/*
# vim swap files # vim swap files
*.swp *.swp
+45 -16
View File
@@ -8,21 +8,50 @@ single flake.
Defined in the host table in [`flake.nix`](./flake.nix): Defined in the host table in [`flake.nix`](./flake.nix):
| Configuration | System | Machine | | Configuration | System | Machine |
| --------------------- | ---------------- | -------------------------------------------------------------------------------------------------------------------- | | --------------------- | ---------------- | ----------------------------------------------------------------------------------------------------------- |
| `lyrathorpe-mbp` | `aarch64-linux` | MacBook Pro (Apple Silicon, Asahi) | | `lyrathorpe-mbp` | `aarch64-linux` | MacBook Pro (Apple Silicon, Asahi) |
| `lyrathorpe-t400` | `x86_64-linux` | ThinkPad T400 — [install notes](./system/machine/T400/README.md) | | `lyrathorpe-t400` | `x86_64-linux` | ThinkPad T400 — [install notes](./hosts/T400/README.md) |
| `lyrathorpe-macpro31` | `x86_64-linux` | Mac Pro 3,1, desktop — [install notes](./system/machine/MacPro31/README.md) | | `lyrathorpe-macpro31` | `x86_64-linux` | Mac Pro 3,1, desktop — [install notes](./hosts/MacPro31/README.md) |
| `emmathorpe-edaas` | `x86_64-linux` | Work WSL box (NixOS-WSL) | | `emmathorpe-edaas` | `x86_64-linux` | Work WSL box (NixOS-WSL) |
| `lyrathorpe-rpi5` | `aarch64-linux` | Raspberry Pi 5 headless server: Docker host + nginx reverse proxy — [install notes](./system/machine/RPi5/README.md) | | `lyrathorpe-rpi5` | `aarch64-linux` | Raspberry Pi 5 headless server: Docker host + nginx reverse proxy — [install notes](./hosts/RPi5/README.md) |
| `lyrathorpe-mac` | `aarch64-darwin` | macOS (nix-darwin) | | `lyrathorpe-mac` | `aarch64-darwin` | macOS (nix-darwin) |
Shared layers: `lyrathorpe/home` (home-manager: shell, git, editor), Shared layers: `home` (home-manager: shell, git, editor),
`system/modules/common-nixos.nix` (all NixOS hosts: fonts, nix-ld, caches), `modules/common-nixos.nix` (all NixOS hosts: fonts, nix-ld, caches),
`system/modules/workstation.nix` (physical graphical hosts: audio, thermald, `modules/workstation.nix` (physical graphical hosts: audio, thermald,
earlyoom, fwupd), `system/modules/laptop.nix` (laptops: Wi-Fi, Bluetooth, power, earlyoom, fwupd), `modules/laptop.nix` (laptops: Wi-Fi, Bluetooth, power,
lid), and `system/modules/ssh.nix` (key-only sshd). The x86 hosts also pull lid), and `modules/ssh.nix` (key-only sshd). The x86 hosts also pull
`nixos-hardware` profiles. `nixos-hardware` profiles.
## Users
Identity is data, kept separate from the reusable modules:
- [`users/registry.nix`](./users/registry.nix) — one entry per user (display
name, email, supplementary groups, authorized + signing keys). This is the
single source of identity; no user data is hardcoded in the modules.
- Each host's table entry declares a `users` set keyed by username; every entry
lists that user's home-module composition (the shared `./home` bundle plus any
per-user modules, e.g. [`users/emmathorpe/work.nix`](./users/emmathorpe/work.nix))
and optional per-host-user system bits such as `linger`.
- `mkHost` builds each account from the registry and injects the matching
identity into that user's home config as the `identity` module arg. A host can
therefore declare any number of users.
### Portable home (off-NixOS / external consumers)
The home config is also exposed for use beyond these hosts:
- `homeConfigurations."<user>@<system>"` — a standalone home-manager profile
(the portable subset: shell + git + editor + claude) that can be activated on a
machine this flake does **not** manage:
`home-manager switch --flake .#"lyrathorpe@x86_64-linux"`. The desktop/sway
modules are intentionally excluded (they rely on a NixOS-provided Sway/Firefox
binary).
- `homeModules` — the reusable modules exported so another flake can import them
(`inputs.<this>.homeModules.default`). Consumers must supply the module args
these expect: `inputs` always, `identity` for git/desktop, `portable` for sway.
## Applying ## Applying
```sh ```sh
@@ -35,25 +64,25 @@ darwin-rebuild switch --flake .#lyrathorpe-mac
## Shell environment & keybindings ## Shell environment & keybindings
- Interactive shell features (zsh, tmux, git, ssh, CLI tools, auto-tmux): - Interactive shell features (zsh, tmux, git, ssh, CLI tools, auto-tmux):
[`lyrathorpe/home/README.md`](./lyrathorpe/home/README.md). [`home/README.md`](./home/README.md).
- All Sway / tmux / foot / zsh keyboard shortcuts: - All Sway / tmux / foot / zsh keyboard shortcuts:
[`lyrathorpe/home/KEYBINDINGS.md`](./lyrathorpe/home/KEYBINDINGS.md). [`home/KEYBINDINGS.md`](./home/KEYBINDINGS.md).
## Login / greeter ## Login / greeter
Graphical (Sway) hosts log in through a Wayland greeter — `greetd` running Graphical (Sway) hosts log in through a Wayland greeter — `greetd` running
ReGreet inside the `cage` kiosk compositor — implemented in ReGreet inside the `cage` kiosk compositor — implemented in
[`lyrathorpe/swaywm.nix`](./lyrathorpe/swaywm.nix), gated on [`modules/sway.nix`](./modules/sway.nix), gated on
`features.swayDesktop.enable` (the option is declared in `features.swayDesktop.enable` (the option is declared in
[`system/modules/features.nix`](./system/modules/features.nix), so headless hosts [`modules/features.nix`](./modules/features.nix), so headless hosts
can leave it off without importing `swaywm.nix`). The greeter is forced to Dvorak can leave it off without importing `modules/sway.nix`). The greeter is forced to Dvorak
to match the console and Sway session. Headless hosts (the WSL work box and the to match the console and Sway session. Headless hosts (the WSL work box and the
Raspberry Pi server) keep plain TTY login. The target account needs a password Raspberry Pi server) keep plain TTY login. The target account needs a password
(`passwd <user>`) before it can log in. (`passwd <user>`) before it can log in.
## MacBook (Asahi) firmware ## MacBook (Asahi) firmware
The MBP host references `system/modules/firmware/` for Apple peripheral The MBP host references `modules/firmware/` for Apple peripheral
firmware (Wi-Fi/Bluetooth). These blobs are **committed** (tracked) even though firmware (Wi-Fi/Bluetooth). These blobs are **committed** (tracked) even though
`.gitignore` lists the directory: the flake is `git+file`, so it only sees `.gitignore` lists the directory: the flake is `git+file`, so it only sees
tracked files — untracking them breaks `lyrathorpe-mbp` evaluation (and the CI tracked files — untracking them breaks `lyrathorpe-mbp` evaluation (and the CI
@@ -63,7 +92,7 @@ redistributable; the repo is private.
To refresh them, copy the firmware extracted during the Asahi install (from To refresh them, copy the firmware extracted during the Asahi install (from
`/etc/nixos/firmware`, or re-extract per the `/etc/nixos/firmware`, or re-extract per the
[Asahi NixOS docs](https://github.com/tpwrules/nixos-apple-silicon)) into [Asahi NixOS docs](https://github.com/tpwrules/nixos-apple-silicon)) into
`system/modules/firmware/` and commit with `git add -f`. `modules/firmware/` and commit with `git add -f`.
## Development ## Development
Generated
+3 -3
View File
@@ -258,11 +258,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1782374867, "lastModified": 1782734462,
"narHash": "sha256-wgU8MdUzSH2ccq85xo80pP1PAFW+e5kzx6rofVO1Jsk=", "narHash": "sha256-0HguXu/4KDgCL1mehqwhQXD96hbR85HS+o0zh73E8AQ=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nixos-apple-silicon", "repo": "nixos-apple-silicon",
"rev": "bf99497876c07bb945d5fc536916cdee4f3b9eb6", "rev": "12e3b92363d21fcc550b500370d73a0747484e43",
"type": "github" "type": "github"
}, },
"original": { "original": {
+127 -75
View File
@@ -23,7 +23,7 @@
# Provides mkFlake: the systems/perSystem scaffolding used below. # Provides mkFlake: the systems/perSystem scaffolding used below.
flake-parts.url = "github:hercules-ci/flake-parts"; flake-parts.url = "github:hercules-ci/flake-parts";
flake-parts.inputs.nixpkgs-lib.follows = "nixpkgs"; flake-parts.inputs.nixpkgs-lib.follows = "nixpkgs";
# Declarative Firefox add-ons (e.g. the Catppuccin theme); see lyrathorpe/user.nix. # Declarative Firefox add-ons (e.g. the Catppuccin theme); see modules/users.nix.
firefox-addons = { firefox-addons = {
url = "gitlab:rycee/nur-expressions?dir=pkgs/firefox-addons"; url = "gitlab:rycee/nur-expressions?dir=pkgs/firefox-addons";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
@@ -46,7 +46,7 @@
url = "github:cachix/git-hooks.nix"; url = "github:cachix/git-hooks.nix";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
# Declarative Neovim (the editor; see lyrathorpe/home/editor.nix). Release # Declarative Neovim (the editor; see home/editor.nix). Release
# branch matched to the pinned nixpkgs (26.05); follows our nixpkgs to keep a # branch matched to the pinned nixpkgs (26.05); follows our nixpkgs to keep a
# single nixpkgs in the closure. editor.nix sets programs.nixvim.nixpkgs.source # single nixpkgs in the closure. editor.nix sets programs.nixvim.nixpkgs.source
# to this same input so the home module doesn't warn about the pin. # to this same input so the home module doesn't warn about the pin.
@@ -97,6 +97,9 @@
"lens-desktop" "lens-desktop"
]; ];
# Per-user identity, keyed by username. See README "Users".
userRegistry = import ./users/registry.nix;
# nixpkgs + nix-daemon settings shared by NixOS and Darwin hosts. # nixpkgs + nix-daemon settings shared by NixOS and Darwin hosts.
commonModule = { commonModule = {
nixpkgs.overlays = overlays; nixpkgs.overlays = overlays;
@@ -112,9 +115,9 @@
# Shared scaffolding for every NixOS host: common user, settings, home-manager. # Shared scaffolding for every NixOS host: common user, settings, home-manager.
baseModules = [ baseModules = [
./lyrathorpe/user.nix ./modules/users.nix
./system/modules/common-nixos.nix ./modules/common-nixos.nix
./system/modules/features.nix ./modules/features.nix
commonModule commonModule
home-manager.nixosModules.home-manager home-manager.nixosModules.home-manager
{ {
@@ -126,18 +129,13 @@
} }
]; ];
# mkHost :: { system, username, fullName, modules, homeModules } -> nixosSystem # Build one NixOS host. `users` is an attrset keyed by username (home
# Builds one machine by appending its host-specific modules to the shared # modules + optional per-user system bits). See README "Users".
# baseModules. The user identity (username/fullName) is threaded through
# specialArgs so user.nix and the home modules stay host-agnostic, and the
# home-manager profile is keyed by the host's username.
mkHost = mkHost =
{ {
system, system,
username,
fullName,
modules, modules,
homeModules, users,
# Host form factor. Laptops inherit the default; a desktop host sets # Host form factor. Laptops inherit the default; a desktop host sets
# `portable = false` to drop mobile components (battery block, # `portable = false` to drop mobile components (battery block,
# brightness keys) from the home-manager Sway config. # brightness keys) from the home-manager Sway config.
@@ -148,8 +146,7 @@
specialArgs = { specialArgs = {
inherit inherit
inputs inputs
username userRegistry
fullName
portable portable
; ;
}; };
@@ -157,16 +154,15 @@
baseModules baseModules
++ modules ++ modules
++ [ ++ [
{ _module.args.hostUsers = users; }
{ {
home-manager.extraSpecialArgs = { home-manager.extraSpecialArgs = { inherit inputs portable; };
inherit home-manager.users = lib.mapAttrs (name: spec: {
inputs imports = spec.homeModules;
username _module.args.identity = userRegistry.${name} // {
fullName username = name;
portable
;
}; };
home-manager.users.${username}.imports = homeModules; }) users;
} }
]; ];
}; };
@@ -185,19 +181,17 @@
} }
]; ];
# mkDarwinHost :: { system, username, fullName, modules, homeModules } -> darwinSystem # Darwin counterpart of mkHost: single-user (macOS owns the account),
# Darwin counterpart of mkHost. macOS already owns the login user, so we # identity still from the registry. See README "Users".
# only attach the platform and home-manager; no NixOS user module here.
mkDarwinHost = mkDarwinHost =
{ {
system, system,
username, username,
fullName,
modules, modules,
homeModules, homeModules,
}: }:
nix-darwin.lib.darwinSystem { nix-darwin.lib.darwinSystem {
specialArgs = { inherit inputs username fullName; }; specialArgs = { inherit inputs username; };
modules = modules =
darwinBaseModules darwinBaseModules
++ modules ++ modules
@@ -206,40 +200,41 @@
nixpkgs.hostPlatform = system; nixpkgs.hostPlatform = system;
# macOS owns the account; point home-manager at its home dir. # macOS owns the account; point home-manager at its home dir.
users.users.${username}.home = "/Users/${username}"; users.users.${username}.home = "/Users/${username}";
home-manager.extraSpecialArgs = { inherit inputs username fullName; }; home-manager.extraSpecialArgs = { inherit inputs; };
home-manager.users.${username}.imports = homeModules; home-manager.users.${username} = {
imports = homeModules;
_module.args.identity = userRegistry.${username} // {
inherit username;
};
};
} }
]; ];
}; };
# Host table — declarative registry of every machine. To add a host: # Host table — one entry per machine, realised into a nixosConfiguration
# give it a name, its `system`, the owning user, and the module lists. # of the same name below. See README "Hosts" / "Users".
# mapAttrs below turns each entry into a nixosConfiguration of the same name.
hosts = { hosts = {
lyrathorpe-mbp = { lyrathorpe-mbp = {
system = "aarch64-linux"; system = "aarch64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
modules = [ modules = [
./system/machine/MBP-Asahi/configuration.nix ./hosts/MBP-Asahi/configuration.nix
./system/modules/laptop.nix ./modules/laptop.nix
nixos-apple-silicon.nixosModules.default nixos-apple-silicon.nixosModules.default
./lyrathorpe/swaywm.nix ./modules/sway.nix
]; ];
homeModules = [ users.lyrathorpe.homeModules = [
./lyrathorpe/home ./home
./lyrathorpe/home/desktop.nix ./users/lyrathorpe/home.nix
./home/desktop.nix
]; ];
}; };
lyrathorpe-t400 = { lyrathorpe-t400 = {
system = "x86_64-linux"; system = "x86_64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
modules = [ modules = [
./system/machine/T400/configuration.nix ./hosts/T400/configuration.nix
./system/modules/laptop.nix ./modules/laptop.nix
./system/modules/ssh.nix ./modules/ssh.nix
# No t400-specific profile exists; compose the generic ThinkPad + # No t400-specific profile exists; compose the generic ThinkPad +
# laptop/SSD/Intel building blocks (tp_smapi/acpi_call for battery # laptop/SSD/Intel building blocks (tp_smapi/acpi_call for battery
# thresholds, SSD + microcode defaults). # thresholds, SSD + microcode defaults).
@@ -247,78 +242,82 @@
inputs.nixos-hardware.nixosModules.common-pc-laptop inputs.nixos-hardware.nixosModules.common-pc-laptop
inputs.nixos-hardware.nixosModules.common-pc-laptop-ssd inputs.nixos-hardware.nixosModules.common-pc-laptop-ssd
inputs.nixos-hardware.nixosModules.common-cpu-intel inputs.nixos-hardware.nixosModules.common-cpu-intel
./lyrathorpe/swaywm.nix ./modules/sway.nix
]; ];
homeModules = [ users.lyrathorpe.homeModules = [
./lyrathorpe/home ./home
./lyrathorpe/home/desktop.nix ./users/lyrathorpe/home.nix
./home/desktop.nix
]; ];
}; };
lyrathorpe-macpro31 = { lyrathorpe-macpro31 = {
system = "x86_64-linux"; system = "x86_64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
portable = false; portable = false;
modules = [ modules = [
./system/machine/MacPro31/configuration.nix ./hosts/MacPro31/configuration.nix
./system/modules/desktop.nix ./modules/desktop.nix
./system/modules/ssh.nix ./modules/ssh.nix
inputs.nixos-hardware.nixosModules.common-pc-ssd inputs.nixos-hardware.nixosModules.common-pc-ssd
inputs.nixos-hardware.nixosModules.common-cpu-intel inputs.nixos-hardware.nixosModules.common-cpu-intel
./lyrathorpe/swaywm.nix ./modules/sway.nix
]; ];
homeModules = [ users.lyrathorpe.homeModules = [
./lyrathorpe/home ./home
./lyrathorpe/home/desktop.nix ./users/lyrathorpe/home.nix
./home/desktop.nix
]; ];
}; };
emmathorpe-edaas = { emmathorpe-edaas = {
system = "x86_64-linux"; system = "x86_64-linux";
username = "emmathorpe";
fullName = "Emma Thorpe";
modules = [ modules = [
./system/machine/EDaaS/configuration.nix ./hosts/EDaaS/configuration.nix
nixos-wsl.nixosModules.default nixos-wsl.nixosModules.default
./lyrathorpe/swaywm.nix ./modules/sway.nix
]; ];
users.emmathorpe = {
homeModules = [ homeModules = [
./lyrathorpe/home ./home
./lyrathorpe/home/work.nix ./users/emmathorpe/work.nix
]; ];
# Keep the systemd --user instance alive without a login session so
# the renovate-review home timer fires on schedule.
linger = true;
};
}; };
lyrathorpe-rpi5 = { lyrathorpe-rpi5 = {
system = "aarch64-linux"; system = "aarch64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
portable = false; portable = false;
# Headless server: Docker host + nginx reverse proxy. No swaywm.nix # Headless server: Docker host + nginx reverse proxy. No sway.nix
# (no desktop); the raspberry-pi-5 profile supplies kernel/firmware, # (no desktop); the raspberry-pi-5 profile supplies kernel/firmware,
# ssh.nix adds key-only sshd. # ssh.nix adds key-only sshd.
modules = [ modules = [
./system/machine/RPi5/configuration.nix ./hosts/RPi5/configuration.nix
inputs.nixos-hardware.nixosModules.raspberry-pi-5 inputs.nixos-hardware.nixosModules.raspberry-pi-5
./system/modules/ssh.nix ./modules/ssh.nix
];
users.lyrathorpe.homeModules = [
./home
./users/lyrathorpe/home.nix
]; ];
homeModules = [ ./lyrathorpe/home ];
}; };
}; };
# Darwin host table — macOS machines built via mkDarwinHost. The shared # Darwin host table — macOS machines built via mkDarwinHost. The shared
# ./lyrathorpe/home modules (shell, git, editor) are reused; the Linux-only # ./home bundle (shell, git, editor) is reused directly; the Linux-only
# desktop/sway modules are intentionally left out. # desktop/sway modules are intentionally left out.
darwinHosts = { darwinHosts = {
lyrathorpe-mac = { lyrathorpe-mac = {
system = "aarch64-darwin"; system = "aarch64-darwin";
username = "lyrathorpe"; username = "lyrathorpe";
fullName = "Lyra Thorpe";
modules = [ modules = [
./system/machine/Darwin/configuration.nix ./hosts/Darwin/configuration.nix
]; ];
homeModules = [ homeModules = [
./lyrathorpe/home ./home
./users/lyrathorpe/home.nix
]; ];
}; };
}; };
@@ -409,6 +408,59 @@
# Realise the host tables: each entry becomes a {nixos,darwin}Configuration. # Realise the host tables: each entry becomes a {nixos,darwin}Configuration.
flake.nixosConfigurations = lib.mapAttrs (_name: mkHost) hosts; flake.nixosConfigurations = lib.mapAttrs (_name: mkHost) hosts;
flake.darwinConfigurations = lib.mapAttrs (_name: mkDarwinHost) darwinHosts; flake.darwinConfigurations = lib.mapAttrs (_name: mkDarwinHost) darwinHosts;
# Reusable home modules, exported for use off these hosts. See README
# "Portable home" for the consumer module-arg expectations.
flake.homeModules = {
default = ./home;
shell = ./home/shell.nix;
git = ./home/git.nix;
editor = ./home/editor.nix;
claude = ./home/claude.nix;
desktop = ./home/desktop.nix;
sway = ./home/sway.nix;
};
# Standalone home-manager configs (portable bundle) for machines not
# managed by this flake. See README "Portable home".
flake.homeConfigurations =
let
mkHome =
{
system,
name,
}:
home-manager.lib.homeManagerConfiguration {
pkgs = import nixpkgs {
inherit system overlays;
config.allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) unfreePackages;
};
extraSpecialArgs = {
inherit inputs;
portable = true;
identity = userRegistry.${name} // {
username = name;
};
};
modules = [
./home
{
home.username = name;
home.homeDirectory = "/home/${name}";
}
];
};
in
{
"lyrathorpe@x86_64-linux" = mkHome {
system = "x86_64-linux";
name = "lyrathorpe";
};
"lyrathorpe@aarch64-linux" = mkHome {
system = "aarch64-linux";
name = "lyrathorpe";
};
};
} }
); );
} }
+7 -5
View File
@@ -15,8 +15,10 @@ Keyboard shortcuts have their own reference: [`KEYBINDINGS.md`](./KEYBINDINGS.md
| GUI apps, GTK/Firefox theming, cursor | [`desktop.nix`](./desktop.nix) (graphical hosts only) | | GUI apps, GTK/Firefox theming, cursor | [`desktop.nix`](./desktop.nix) (graphical hosts only) |
Shared by every host via [`default.nix`](./default.nix); the work box also layers Shared by every host via [`default.nix`](./default.nix); the work box also layers
[`work.nix`](./work.nix) on top (work email, its own ssh config, extra packages, [`work.nix`](../users/emmathorpe/work.nix) on top (its own ssh config, extra
and the C#/Helm language servers). packages, and the C#/Helm language servers). The committer identity (name, email,
signing key) comes from the user registry
([`../users/registry.nix`](../users/registry.nix)), not this module.
--- ---
@@ -55,7 +57,7 @@ and the C#/Helm language servers).
| `hyperfine` / `sd` | command-line benchmarking; saner find-and-replace than sed | | `hyperfine` / `sd` | command-line benchmarking; saner find-and-replace than sed |
**Theming:** `fzf`, `bat`, `btop`, `lazygit` and `git`'s `delta` pager are all **Theming:** `fzf`, `bat`, `btop`, `lazygit` and `git`'s `delta` pager are all
Catppuccin Mocha, driven from the shared `../catppuccin-mocha.nix` palette / the Catppuccin Mocha, driven from the shared `../lib/catppuccin-mocha.nix` palette / the
catppuccin upstream themes. catppuccin upstream themes.
**Env & defaults:** `xdg.enable` on; `PAGER`/`MANPAGER` (bat) set in `default.nix` **Env & defaults:** `xdg.enable` on; `PAGER`/`MANPAGER` (bat) set in `default.nix`
@@ -148,7 +150,7 @@ current (`gc`/`fetch.writeCommitGraph`) so `lg` stays fast.
| `cz` `cc` | `git cz <sub>` (e.g. `git cz c`) and `git cc` → commitizen prompt | | `cz` `cc` | `git cz <sub>` (e.g. `git cz c`) and `git cc` → commitizen prompt |
| Behaviour | | | Behaviour | |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | -------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Pulls | rebase, with autostash + autosquash | | Pulls | rebase, with autostash + autosquash |
| Fetch | prune deleted remote branches | | Fetch | prune deleted remote branches |
| Conflicts | `zdiff3` (shows the common ancestor) | | Conflicts | `zdiff3` (shows the common ancestor) |
@@ -157,7 +159,7 @@ current (`gc`/`fetch.writeCommitGraph`) so `lg` stays fast.
| Commit editor | full diff shown (`commit.verbose`) | | Commit editor | full diff shown (`commit.verbose`) |
| Misc | branches sorted by date, `column.ui = auto`, `help.autocorrect = prompt`, `push.autoSetupRemote` | | Misc | branches sorted by date, `column.ui = auto`, `help.autocorrect = prompt`, `push.autoSetupRemote` |
| Global ignores | `result`, `result-*`, `.direnv`, `*.swp`, `.DS_Store` | | Global ignores | `result`, `result-*`, `.direnv`, `*.swp`, `.DS_Store` |
| Signing | SSH commit + tag signing (`mkDefault`, so a host without the key in its agent can disable it). Personal email `iam@emmathe.dev`; the work box overrides email + signing. | | Signing | SSH commit + tag signing (`mkDefault`, so a host without the key in its agent can disable it). Name, email and signing key all come from the per-user `identity` (the user registry, `../users/registry.nix`). |
## ssh ## ssh
@@ -1,12 +1,13 @@
# Graphical desktop layer: GUI apps, Wayland session env, and cursor theme. # Graphical desktop layer: GUI apps, Wayland session env, and cursor theme.
# Imported only on hosts that run Sway (MBP, T400, Mac Pro); never pulled onto # Imported only on hosts that run Sway (MBP, T400, Mac Pro); never pulled onto
# the headless WSL host. Login (and the Sway session launch) is handled by the # the headless WSL host. Login (and the Sway session launch) is handled by the
# greetd/ReGreet greeter -- see ../swaywm.nix -- so there is no tty1 autostart. # greetd/ReGreet greeter -- see ../modules/sway.nix -- so there is no tty1
# autostart.
{ {
pkgs, pkgs,
config, config,
inputs, inputs,
username, identity,
... ...
}: }:
{ {
@@ -89,7 +90,7 @@
}; };
# Firefox is themed at the browser level (it does not follow the GTK theme). # Firefox is themed at the browser level (it does not follow the GTK theme).
# The system installs the binary (programs.firefox in ../user.nix); here # The system installs the binary (programs.firefox in ../modules/users.nix); here
# home-manager owns only the profile, hence package = null. Apply the # home-manager owns only the profile, hence package = null. Apply the
# Catppuccin Mocha theme add-on (only the mauve accent is packaged upstream; # Catppuccin Mocha theme add-on (only the mauve accent is packaged upstream;
# the rest of the desktop uses blue) and make content + UI dark. # the rest of the desktop uses blue) and make content + UI dark.
@@ -101,7 +102,7 @@
# stateVersion<26.05 default-change warning (the new XDG path depends on # stateVersion<26.05 default-change warning (the new XDG path depends on
# Firefox's own profile support). # Firefox's own profile support).
configPath = ".mozilla/firefox"; configPath = ".mozilla/firefox";
profiles.${username} = { profiles.${identity.username} = {
id = 0; id = 0;
isDefault = true; isDefault = true;
extensions = { extensions = {
+10 -15
View File
@@ -1,13 +1,13 @@
# Version control: git + delta pager + commitizen + lazygit. The work host # Version control: git + delta + commitizen + lazygit. Committer identity comes
# layers commit signing and an email override on top (see work.nix). # from the per-user `identity` arg (the registry). See README "Users".
{ {
pkgs, pkgs,
lib, lib,
fullName, identity,
... ...
}: }:
let let
ctp = import ../catppuccin-mocha.nix; ctp = import ../lib/catppuccin-mocha.nix;
in in
{ {
home.packages = [ home.packages = [
@@ -18,10 +18,9 @@ in
enable = true; enable = true;
package = pkgs.gitFull; package = pkgs.gitFull;
settings = { settings = {
user.name = fullName; user.name = identity.fullName;
# Personal identity. mkDefault so the work module overrides it on the work # mkDefault so a host-specific module can still override it.
# host (and to merge cleanly with that plain definition there). user.email = lib.mkDefault identity.email;
user.email = lib.mkDefault "iam@emmathe.dev";
push.autoSetupRemote = true; push.autoSetupRemote = true;
init.defaultBranch = "main"; init.defaultBranch = "main";
@@ -77,14 +76,10 @@ in
cc = "!cz commit"; cc = "!cz commit";
}; };
# SSH commit signing. This personal key is the default; the work module # SSH signing, key from the registry. mkDefault so a host lacking the key
# (work.nix) overrides it with the work key on the EDaaS host, the same way # in its agent can set gpgsign = false instead of failing every commit.
# user.email is overridden -- so mkDefault here lets that plain definition
# win instead of conflicting. gpgsign is mkDefault too, so a host without
# the key in its ssh-agent can override it to false rather than fail every
# commit.
gpg.format = "ssh"; gpg.format = "ssh";
user.signingkey = lib.mkDefault "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA"; user.signingkey = lib.mkDefault identity.signingKey;
commit.gpgsign = lib.mkDefault true; commit.gpgsign = lib.mkDefault true;
tag.gpgsign = lib.mkDefault true; tag.gpgsign = lib.mkDefault true;
}; };
+1 -4
View File
@@ -8,7 +8,7 @@
}: }:
let let
# Shared Catppuccin Mocha palette: raw 6-hex strings, no leading "#". # Shared Catppuccin Mocha palette: raw 6-hex strings, no leading "#".
ctp = import ../catppuccin-mocha.nix; ctp = import ../lib/catppuccin-mocha.nix;
in in
{ {
imports = [ imports = [
@@ -341,9 +341,6 @@ in
IdentityFile = "~/.ssh/code.emmathe.dev"; IdentityFile = "~/.ssh/code.emmathe.dev";
IdentitiesOnly = true; IdentitiesOnly = true;
}; };
"dockerpi.inf.cbg.emmaisvery.gay" = {
User = "emmathorpe";
};
}; };
}; };
+5 -6
View File
@@ -2,7 +2,7 @@
# Imported via ./desktop.nix, so only graphical hosts get it. # Imported via ./desktop.nix, so only graphical hosts get it.
# #
# The compositor binary, PAM and the polkit *daemon* come from the system-level # The compositor binary, PAM and the polkit *daemon* come from the system-level
# programs.sway (see ../swaywm.nix); package = null below reuses it instead of # programs.sway (see ../modules/sway.nix); package = null below reuses it instead of
# pulling a second Sway. The polkit authentication *agent* (the thing that draws # pulling a second Sway. The polkit authentication *agent* (the thing that draws
# the GUI auth dialog) is a user service started here. home-manager owns the user # the GUI auth dialog) is a user service started here. home-manager owns the user
# config (~/.config/sway) and wires the systemd user session (sway-session.target), # config (~/.config/sway) and wires the systemd user session (sway-session.target),
@@ -20,7 +20,7 @@ let
# Catppuccin Mocha (shared with the ReGreet greeter). Raw hex; prefix "#" # Catppuccin Mocha (shared with the ReGreet greeter). Raw hex; prefix "#"
# where a consumer needs it -- Sway/i3status/dunst want "#", foot/swaylock do # where a consumer needs it -- Sway/i3status/dunst want "#", foot/swaylock do
# not. # not.
ctp = import ../catppuccin-mocha.nix; ctp = import ../lib/catppuccin-mocha.nix;
# Focused-window screenshot -> swappy editor (the dotfiles' grimshot.sh logic). # Focused-window screenshot -> swappy editor (the dotfiles' grimshot.sh logic).
# Full store paths so it needs nothing on PATH. # Full store paths so it needs nothing on PATH.
@@ -334,13 +334,12 @@ in
]; ];
}; };
# Night light. Manual location (no geoclue dependency); adjust the coordinates # Night light. Manual location (no geoclue dependency); warmer at night,
# to taste. Warmer at night, neutral by day. # neutral by day. Coordinates come from the per-user module (e.g.
# users/lyrathorpe/home.nix), not this shared module.
services.gammastep = { services.gammastep = {
enable = true; enable = true;
provider = "manual"; provider = "manual";
latitude = 51.5;
longitude = -0.13; # London-ish; set to your actual location
temperature = { temperature = {
day = 6500; day = 6500;
night = 3700; night = 3700;
@@ -1,5 +1,5 @@
# Default nix-darwin host. Minimal macOS baseline; the user environment # Default nix-darwin host. Minimal macOS baseline; the user environment
# (shell, git, editor) is carried by the shared ./lyrathorpe/home modules, # (shell, git, editor) is carried by the shared ./home modules,
# the same ones used by the Linux hosts. nixpkgs.hostPlatform is set by # the same ones used by the Linux hosts. nixpkgs.hostPlatform is set by
# mkDarwinHost in flake.nix. # mkDarwinHost in flake.nix.
{ pkgs, username, ... }: { pkgs, username, ... }:
@@ -62,12 +62,11 @@
features.swayDesktop.enable = false; features.swayDesktop.enable = false;
# Keep this user's systemd --user instance running without an open login # NOTE: this user's systemd --user lingering -- so the home-manager renovate
# session, so the home-manager user timer (renovate-review.nix) fires on # timer fires without an open login session -- is enabled from the host table
# schedule even when no terminal is attached. On WSL the timer still only runs # in flake.nix (users.emmathorpe.linger = true) and applied by
# while the distro itself is up; Persistent=true catches up a missed run at # modules/users.nix.
# next start.
users.users.emmathorpe.linger = true;
# programs.nix-ld is enabled for all NixOS hosts in common-nixos.nix. # programs.nix-ld is enabled for all NixOS hosts in common-nixos.nix.
# This value determines the NixOS release from which the default # This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions # settings for stateful data, like file locations and database versions
@@ -42,7 +42,7 @@
# - ATI Radeon HD 2600 XT -> "radeon" (older) or "amdgpu" KMS # - ATI Radeon HD 2600 XT -> "radeon" (older) or "amdgpu" KMS
# - NVIDIA GeForce 8800 GT -> "nouveau" KMS # - NVIDIA GeForce 8800 GT -> "nouveau" KMS
# These come up automatically via the in-tree drivers + KMS, and the graphics # These come up automatically via the in-tree drivers + KMS, and the graphics
# stack itself is enabled by swaywm.nix. If a card needs to be forced, add it # stack itself is enabled by modules/sway.nix. If a card needs to be forced, add it
# here, e.g. `services.xserver.videoDrivers = [ "radeon" ];` (or "nouveau"), # here, e.g. `services.xserver.videoDrivers = [ "radeon" ];` (or "nouveau"),
# and/or `boot.initrd.kernelModules = [ "radeon" ];` in # and/or `boot.initrd.kernelModules = [ "radeon" ];` in
# hardware-configuration.nix for early KMS. # hardware-configuration.nix for early KMS.
@@ -15,7 +15,7 @@
# (which selects by the local hostname) resolves without an explicit -H flag. # (which selects by the local hostname) resolves without an explicit -H flag.
networking.hostName = "lyrathorpe-rpi5"; networking.hostName = "lyrathorpe-rpi5";
# Headless server: the Sway desktop is intentionally not set up. swaywm.nix is # Headless server: the Sway desktop is intentionally not set up. modules/sway.nix is
# not imported and features.swayDesktop.enable defaults to false (declared in # not imported and features.swayDesktop.enable defaults to false (declared in
# system/modules/features.nix), so this host keeps plain TTY/SSH login. # system/modules/features.nix), so this host keeps plain TTY/SSH login.
@@ -1,6 +1,6 @@
# Catppuccin Mocha palette. Raw 6-digit hex (no leading "#"); consumers add a # Catppuccin Mocha palette. Raw 6-digit hex (no leading "#"); consumers add a
# "#" where their format needs it. Shared by the Sway desktop theming # "#" where their format needs it. Shared by the Sway desktop theming
# (home/sway.nix) and the ReGreet greeter (swaywm.nix) so the two stay in sync. # (home/sway.nix) and the ReGreet greeter (modules/sway.nix) so the two stay in sync.
{ {
base = "1e1e2e"; base = "1e1e2e";
mantle = "181825"; mantle = "181825";
-31
View File
@@ -1,31 +0,0 @@
{
config,
pkgs,
lib,
username,
fullName,
...
}:
{
programs.zsh.enable = true;
users.users.${username} = {
isNormalUser = true;
home = "/home/${username}";
description = fullName;
extraGroups = [
"wheel"
"docker"
];
openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA"
];
shell = pkgs.zsh;
};
programs.firefox = lib.mkIf (config.features.swayDesktop.enable == true) {
enable = true;
};
programs.thunderbird = lib.mkIf (config.features.swayDesktop.enable == true) {
enable = true;
};
}
@@ -2,7 +2,7 @@
# shared ./workstation.nix base and swaps the mobile Wi-Fi backend for wired # shared ./workstation.nix base and swaps the mobile Wi-Fi backend for wired
# NetworkManager. A desktop host also sets `portable = false` in its host-table # NetworkManager. A desktop host also sets `portable = false` in its host-table
# entry (flake.nix), which drops the battery block and brightness keybindings # entry (flake.nix), which drops the battery block and brightness keybindings
# from the Sway bar -- see lyrathorpe/home/sway.nix. # from the Sway bar -- see home/sway.nix.
{ ... }: { ... }:
{ {
imports = [ ./workstation.nix ]; imports = [ ./workstation.nix ];
@@ -2,9 +2,9 @@
# baseModules in flake.nix). Declaring the flags here -- rather than inside the # baseModules in flake.nix). Declaring the flags here -- rather than inside the
# module that implements them -- means a host can read or set a flag without # module that implements them -- means a host can read or set a flag without
# importing the (often large) implementation module. In particular, # importing the (often large) implementation module. In particular,
# features.swayDesktop.enable is read by lyrathorpe/user.nix on every host, but a # features.swayDesktop.enable is read by modules/users.nix on every host, but a
# headless host (e.g. the Pi) must be able to leave it at its default without # headless host (e.g. the Pi) must be able to leave it at its default without
# pulling in lyrathorpe/swaywm.nix. The implementation lives in swaywm.nix, # pulling in modules/sway.nix. The implementation lives in modules/sway.nix,
# gated on this flag. # gated on this flag.
{ lib, ... }: { lib, ... }:
{ {
@@ -2,7 +2,7 @@
# flake.nix. Shared graphical-workstation settings live in ./workstation.nix; # flake.nix. Shared graphical-workstation settings live in ./workstation.nix;
# the only laptop-specific bit is the Wi-Fi backend. Mobile home-manager # the only laptop-specific bit is the Wi-Fi backend. Mobile home-manager
# components (battery block, brightness keys) are gated by the `portable` flag # components (battery block, brightness keys) are gated by the `portable` flag
# threaded through mkHost -- see lyrathorpe/home/sway.nix. # threaded through mkHost -- see home/sway.nix.
{ ... }: { ... }:
{ {
imports = [ ./workstation.nix ]; imports = [ ./workstation.nix ];
+11
View File
@@ -0,0 +1,11 @@
# Key-only sshd hardening, imported by hosts that run sshd (T400, Mac Pro,
# RPi5). Authorized keys are owned per-user by the registry (modules/users.nix),
# not here.
{ ... }:
{
services.openssh.settings = {
PasswordAuthentication = false; # keys only
KbdInteractiveAuthentication = false; # no keyboard-interactive fallback
PermitRootLogin = "no";
};
}
+2 -2
View File
@@ -7,8 +7,8 @@
let let
cfg = config.features.swayDesktop; cfg = config.features.swayDesktop;
# Catppuccin Mocha (shared with the Sway desktop, see lyrathorpe/home/sway.nix). # Catppuccin Mocha (shared with the Sway desktop, see home/sway.nix).
ctp = import ./catppuccin-mocha.nix; ctp = import ../lib/catppuccin-mocha.nix;
in in
{ {
# The features.swayDesktop.enable option is declared in # The features.swayDesktop.enable option is declared in
+38
View File
@@ -0,0 +1,38 @@
# System user accounts, built from the registry (users/registry.nix) for the
# host's `hostUsers` set. See README "Users".
{
config,
pkgs,
lib,
hostUsers,
userRegistry,
...
}:
{
programs.zsh.enable = true;
users.users = lib.mapAttrs (
name: spec:
let
id = userRegistry.${name};
in
{
isNormalUser = true;
home = "/home/${name}";
description = id.fullName;
inherit (id) extraGroups;
openssh.authorizedKeys.keys = id.sshAuthorizedKeys;
shell = pkgs.zsh;
}
# linger opt-in (host table); left unmanaged when unset.
// lib.optionalAttrs (spec ? linger) { inherit (spec) linger; }
) hostUsers;
programs.firefox = lib.mkIf (config.features.swayDesktop.enable == true) {
enable = true;
};
programs.thunderbird = lib.mkIf (config.features.swayDesktop.enable == true) {
enable = true;
};
}
-19
View File
@@ -1,19 +0,0 @@
# Key-only SSH hardening, imported by the hosts that run sshd (T400, Mac Pro).
# The host config still does `services.openssh.enable = true` and opens port 22
# next to where it documents the listening service; this module only tightens
# the policy and installs the authorized key, so a host opting into sshd cannot
# accidentally ship password/root login.
{ username, ... }:
{
services.openssh.settings = {
PasswordAuthentication = false; # keys only
KbdInteractiveAuthentication = false; # no keyboard-interactive fallback
PermitRootLogin = "no";
};
# The key permitted to log in as the primary user. Add more entries here as
# new client machines are provisioned.
users.users.${username}.openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA"
];
}
@@ -1,5 +1,5 @@
# Home-manager module for the work (EDaaS/WSL) profile: corporate git signing, # Work (EDaaS/WSL) home profile: corporate toolchain + tmux tweaks. Git identity
# work toolchain packages and tmux tweaks. Imported only by the work host. # comes from the registry (users/registry.nix), not here.
{ pkgs, lib, ... }: { pkgs, lib, ... }:
{ {
@@ -12,15 +12,6 @@
# programs.ssh (shell.nix) take it over. The ssh-agent below still runs. # programs.ssh (shell.nix) take it over. The ssh-agent below still runs.
programs.ssh.enable = lib.mkForce false; programs.ssh.enable = lib.mkForce false;
programs.git = {
settings = {
commit.gpgsign = true;
tag.gpgsign = true;
gpg.format = "ssh";
user.signingkey = "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAJMVgeRKnfX1G8coU3nAobI485aeUpGTMqH7+zbKI8o emma.thorpe@cloud.com";
user.email = "emma.thorpe@citrix.com";
};
};
home.packages = [ home.packages = [
pkgs.kubectl pkgs.kubectl
pkgs.argo-rollouts pkgs.argo-rollouts
@@ -66,7 +57,7 @@
}; };
# LSP servers only relevant to work: C# (omnisharp) and Helm charts (helm_ls). # LSP servers only relevant to work: C# (omnisharp) and Helm charts (helm_ls).
# The shared editor (lyrathorpe/home/editor.nix) carries the universal ones; # The shared editor (home/editor.nix) carries the universal ones;
# these are gated to this host so the heavy omnisharp closure stays off the # these are gated to this host so the heavy omnisharp closure stays off the
# personal machines. Tree-sitter grammars (highlighting) remain global there. # personal machines. Tree-sitter grammars (highlighting) remain global there.
programs.nixvim.plugins.lsp.servers = { programs.nixvim.plugins.lsp.servers = {
+17
View File
@@ -0,0 +1,17 @@
# Lyra's personal home extras, imported on her hosts (not the work box). Keeps
# personal data out of the shared home/ modules. See README "Users".
{ pkgs, lib, ... }:
{
# Personal ssh host shortcut.
programs.ssh.settings."dockerpi.inf.cbg.emmaisvery.gay" = {
User = "emmathorpe";
};
# Night-light location for gammastep (the service itself is enabled by
# home/sway.nix on graphical hosts). Linux-guarded so Darwin, which imports
# this module but has no gammastep, skips it.
services.gammastep = lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
latitude = 51.5;
longitude = -0.13;
};
}
+28
View File
@@ -0,0 +1,28 @@
# User identity registry -- pure data, keyed by username. See README "Users".
# (`identity.username` is injected by mkHost, so it is not repeated here.)
{
lyrathorpe = {
fullName = "Lyra Thorpe";
email = "iam@emmathe.dev";
extraGroups = [
"wheel"
"docker"
];
sshAuthorizedKeys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA"
];
signingKey = "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA";
};
emmathorpe = {
fullName = "Emma Thorpe";
email = "emma.thorpe@citrix.com";
extraGroups = [
"wheel"
"docker"
];
# No personal key on file yet; add one if SSH login as emmathorpe is wanted.
sshAuthorizedKeys = [ ];
signingKey = "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAJMVgeRKnfX1G8coU3nAobI485aeUpGTMqH7+zbKI8o emma.thorpe@cloud.com";
};
}