23 changed files with 396 additions and 447 deletions
+15 -27
View File
@@ -1,21 +1,15 @@
# Flake CI. Formatting (treefmt) runs on *every* PR; the heavier Nix work # Flake CI: full `nix flake check` (formatting + deadnix + statix + pre-commit)
# (deadnix/statix/pre-commit lints + per-host evaluation) runs only when the # plus an explicit per-host evaluation pass for granular output.
# change can affect it.
name: CI name: CI
# Deliberately no `paths:` filter. This job is a required status check on main, # Deliberately no `paths:` filter. This job is a required status check on main,
# and a path-filtered workflow is *skipped* (never runs) for PRs that touch no # and a path-filtered workflow is *skipped* (never runs) for PRs that touch no
# matching file -- which leaves the required check pending forever and blocks the # matching file -- which leaves the required check pending forever and blocks the
# merge (e.g. a .renovaterc.json-only change). So the workflow always runs and # merge (e.g. a .renovaterc.json-only change). So the workflow always runs and
# always reports. # always reports. To avoid burning a full Nix evaluation on changes that can't
# # affect it, the "detect" step below diffs the PR and the heavy steps run only
# Two tiers of checks: # when a .nix file, flake.lock, or this workflow changed; otherwise they skip and
# * Formatting always runs. treefmt covers Markdown, YAML, and JSON as well as # the job still passes. The required check is therefore always green-reportable.
# Nix and shell, so a docs- or config-only PR must be format-checked too. It
# is cheap (no host evaluation).
# * The heavy steps (full `nix flake check` + host evals) run only when a .nix
# file, flake.lock, or this workflow changed; otherwise they skip and the job
# still passes, keeping the required check green-reportable.
on: on:
push: push:
branches: [main] branches: [main]
@@ -31,10 +25,11 @@ jobs:
# Full history so the detect step can diff the PR against its base. # Full history so the detect step can diff the PR against its base.
fetch-depth: 0 fetch-depth: 0
# Decide whether the *heavy* Nix steps need to run. On a pull_request, diff # Decide whether the Nix steps need to run. On a pull_request, diff the PR
# against the base for files that can affect them: any .nix, the lockfile, # against its base and look for files that can affect the flake: any .nix,
# or this workflow. On any other event (push to main) always run. The # the lockfile, or this workflow. On any other event (push to main) always
# formatting step below is unaffected -- it always runs. # run. The job itself always succeeds, so the required status check is
# reported even when the heavy steps are skipped.
- name: Detect Nix-relevant changes - name: Detect Nix-relevant changes
id: detect id: detect
run: | run: |
@@ -50,16 +45,16 @@ jobs:
echo "Changed files:" echo "Changed files:"
echo "$changed" echo "$changed"
if echo "$changed" | grep -Eq '(\.nix$|^flake\.lock$|^\.gitea/workflows/ci\.yaml$)'; then if echo "$changed" | grep -Eq '(\.nix$|^flake\.lock$|^\.gitea/workflows/ci\.yaml$)'; then
echo "Nix-relevant changes found: running heavy checks." echo "Nix-relevant changes found: running checks."
echo "run=true" >> "$GITHUB_OUTPUT" echo "run=true" >> "$GITHUB_OUTPUT"
else else
echo "No Nix-relevant changes: heavy checks skip (formatting still runs)." echo "No Nix-relevant changes: skipping checks (job still passes)."
echo "run=false" >> "$GITHUB_OUTPUT" echo "run=false" >> "$GITHUB_OUTPUT"
fi fi
# Nix drives the formatting check, so install it unconditionally.
- name: Install Nix - name: Install Nix
uses: cachix/install-nix-action@a49548c11d9846ad46ecc0115273879b045f001c # v31 if: steps.detect.outputs.run == 'true'
uses: cachix/install-nix-action@8aa03977d8d733052d78f4e008a241fd1dbf36b3 # v31
with: with:
extra_nix_config: | extra_nix_config: |
experimental-features = nix-command flakes experimental-features = nix-command flakes
@@ -67,13 +62,6 @@ jobs:
substituters = https://cache.nixos.org https://nix-community.cachix.org substituters = https://cache.nixos.org https://nix-community.cachix.org
trusted-public-keys = cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY= nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs= trusted-public-keys = cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY= nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=
# Always run: treefmt formats Markdown/YAML/JSON (docs + config) as well as
# Nix and shell, so documentation-only PRs are format-checked too. This is
# the cheap gate (no host evaluation) and pre-builds the `formatting`
# derivation that the flake check below reuses from cache.
- name: Formatting check
run: nix build --print-build-logs '.#checks.x86_64-linux.formatting'
# Runs every flake check: treefmt formatting, deadnix, statix, and the # Runs every flake check: treefmt formatting, deadnix, statix, and the
# pre-commit hooks (so a --no-verify commit can't ship unlinted). # pre-commit hooks (so a --no-verify commit can't ship unlinted).
- name: Flake check - name: Flake check
-63
View File
@@ -1,63 +0,0 @@
# Working on this flake
Project notes for changes to this repository. Persona and memory rules live in
the user-global config; this file is about the flake's checks and conventions.
## Before you commit: run the formatter
Formatting and linting are driven by the flake. CI (`.gitea/workflows/ci.yaml`)
runs `nix flake check`, which fails the build if any file is unformatted or trips
a lint. From the repo root:
- `nix fmt` — format the whole tree (writes changes).
- `nix flake check` — run every check read-only (what CI runs).
- `nix develop` — dev shell; its `shellHook` installs the git pre-commit hooks so
the same gates run on `git commit`.
Never commit with `--no-verify`. A bypassed commit ships unformatted content and
turns CI red on the next push to `main` (see "Docs are checked too").
## What gets checked
Defined in `flake.nix` (the `treefmt`, `pre-commit`, and `checks` blocks) and
`statix.toml`:
| Check | Tool | Covers |
| ------------ | --------------------------------- | ------------------------------------------------------- |
| `formatting` | treefmt → `nixfmt` | all `*.nix` |
| `formatting` | treefmt → `shfmt` | shell scripts |
| `formatting` | treefmt → `prettier` | **Markdown, YAML, JSON** (incl. `README.md`, this file) |
| `deadnix` | deadnix | dead Nix bindings (`--no-lambda-pattern-names`) |
| `statix` | statix | Nix antipatterns (config in `statix.toml`) |
| pre-commit | nixfmt-rfc-style, deadnix, statix | the same gates, run on commit |
Excluded from formatting: `*/hardware-configuration.nix` (generated by
`nixos-generate-config`) and `flake.lock`. Editor defaults (indent, EOL, final
newline) are in `.editorconfig`; note Markdown keeps trailing whitespace, which
encodes hard line breaks.
## Docs are checked too
prettier formats `*.md`, so **documentation edits must be run through `nix fmt`**
exactly like code. prettier re-aligns Markdown tables in particular; hand-editing
a table almost always leaves it non-conformant and fails the `formatting` check.
The CI `formatting` step runs on **every** PR — including docs- and config-only
changes — so a Markdown/YAML/JSON edit is format-checked before merge, not just
after it lands on `main`. (The heavier `deadnix`/`statix`/`pre-commit` lints and
the per-host evaluation still run only when a `.nix` file, `flake.lock`, or the
workflow changed; see `.gitea/workflows/ci.yaml`.) Run `nix fmt` before you
commit and the formatting check stays green.
## Host evaluation
CI also evaluates every `nixosConfigurations` / `darwinConfigurations` host's
toplevel (eval only, no build) on an x86_64 runner, so eval errors fail cheaply.
Reproduce locally:
```sh
nix eval --raw ".#nixosConfigurations.<host>.config.system.build.toplevel.drvPath"
```
Host lists are discovered from the flake, so adding or removing a host needs no
change to the workflow.
+32 -99
View File
@@ -12,67 +12,16 @@ Defined in the host table in [`flake.nix`](./flake.nix):
| `lyrathorpe-mbp` | `aarch64-linux` | MacBook Pro (Apple Silicon, Asahi) | | `lyrathorpe-mbp` | `aarch64-linux` | MacBook Pro (Apple Silicon, Asahi) |
| `lyrathorpe-t400` | `x86_64-linux` | ThinkPad T400 — [install notes](./hosts/T400/README.md) | | `lyrathorpe-t400` | `x86_64-linux` | ThinkPad T400 — [install notes](./hosts/T400/README.md) |
| `lyrathorpe-macpro31` | `x86_64-linux` | Mac Pro 3,1, desktop — [install notes](./hosts/MacPro31/README.md) | | `lyrathorpe-macpro31` | `x86_64-linux` | Mac Pro 3,1, desktop — [install notes](./hosts/MacPro31/README.md) |
| `emmathorpe-edaas` | `x86_64-linux` | Work WSL box (NixOS-WSL) — [notes](./hosts/EDaaS/README.md) | | `emmathorpe-edaas` | `x86_64-linux` | Work WSL box (NixOS-WSL) |
| `lyrathorpe-rpi5` | `aarch64-linux` | Raspberry Pi 5 headless server: Docker host + nginx reverse proxy — [install notes](./hosts/RPi5/README.md) | | `lyrathorpe-rpi5` | `aarch64-linux` | Raspberry Pi 5 headless server: Docker host + nginx reverse proxy — [install notes](./hosts/RPi5/README.md) |
| `lyrathorpe-mac` | `aarch64-darwin` | macOS (nix-darwin) — [notes](./hosts/Darwin/README.md) | | `lyrathorpe-mac` | `aarch64-darwin` | macOS (nix-darwin) |
Shared layers: `home` (home-manager: shell, git, editor), Shared layers: `home` (home-manager: shell, git, editor),
`modules/common-nixos.nix` (all NixOS hosts: fonts, nix-ld, caches), `modules/common-nixos.nix` (all NixOS hosts: fonts, nix-ld, caches),
`modules/workstation.nix` (physical graphical hosts: audio, thermald, `modules/workstation.nix` (physical graphical hosts: audio, thermald,
earlyoom, fwupd), `modules/laptop.nix` (laptops: Wi-Fi, Bluetooth, power, earlyoom, fwupd), `modules/laptop.nix` (laptops: Wi-Fi, Bluetooth, power,
lid), `modules/desktop.nix` (wired desktops: NetworkManager), and lid), and `modules/ssh.nix` (key-only sshd). The x86 hosts also pull
`modules/ssh.nix` (key-only sshd). The x86 hosts also pull `nixos-hardware` `nixos-hardware` profiles.
profiles. The full module catalogue is below.
## Repository layout
```
flake.nix # inputs, mkHost/mkDarwinHost, the host tables, dev shell + checks
flake.lock # pinned input revisions (Renovate keeps this fresh)
modules/ # reusable NixOS system modules (see "Module catalogue")
home/ # home-manager profile: shell, git, editor, claude, desktop, sway
users/ # identity registry + per-user home extras (see "Users")
hosts/<Name>/ # per-machine config: configuration.nix + hardware-configuration.nix
lib/ # small pure helpers (currently the Catppuccin Mocha palette)
.gitea/workflows/ # CI (nix flake check + per-host eval)
statix.toml # lint config (house-style lints disabled)
.editorconfig # base whitespace style
tf-inspect/ # UNRELATED scratch project (gitignored, its own git repo);
# RouterOS / home-services Terraform, not part of this flake
```
Each `nixosConfiguration` / `darwinConfiguration` is assembled in `flake.nix`
from three layers: the shared `baseModules` (or `darwinBaseModules`), the
per-form-factor and `nixos-hardware` modules listed in the host table, and the
per-machine `hosts/<Name>/configuration.nix`. Home-manager is wired in as a
system module; each user's home is composed from the `homeModules` list in that
host's table entry.
## Module catalogue
Reusable NixOS modules under [`modules/`](./modules). "Imported by" says how a
module reaches a host: **baseModules** (every NixOS host, via `flake.nix`),
**host table** (listed explicitly per host in `flake.nix`), or **transitively**
(pulled in by another module's `imports`).
| Module | Imported by | What it does / when to use it |
| ------------------ | --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `common-nixos.nix` | baseModules (all NixOS) | Timezone/locale, store hygiene (auto-optimise, big download buffer, **no** auto-GC), the nix-community binary cache, `nix-ld`, base CLI (`git`, `fastfetch`), and the fleet-wide font stack. |
| `users.nix` | baseModules (all NixOS) | Builds `users.users` from the registry for the host's `hostUsers`; enables zsh; enables Firefox + Thunderbird **only** when `features.swayDesktop.enable` is on. Applies per-user `linger`. |
| `features.nix` | baseModules (all NixOS) | Declares feature-flag options (currently `features.swayDesktop.enable`) so any host can read/set them without importing the heavy implementation module. |
| `workstation.nix` | transitively (via laptop/desktop) | Form-factor-agnostic base for physical graphical hosts: turns on `swayDesktop`, Dvorak console, PipeWire, firewall (default-deny), fstrim, earlyoom, fwupd, thermald (x86), redistributable fw. |
| `laptop.nix` | host table (MBP, T400) | `imports` workstation.nix, then adds the portable bits: iwd Wi-Fi, lid suspend/lock, Bluetooth + blueman. |
| `desktop.nix` | host table (Mac Pro) | `imports` workstation.nix, then swaps Wi-Fi for wired NetworkManager. Pair with `portable = false` in the host table. |
| `sway.nix` | host table (graphical hosts) | Implementation of `features.swayDesktop`: the system Sway package, the greetd/ReGreet (cage) greeter forced to Dvorak, xdg-portal, Wayland utility packages. Home-side Sway config is in `home/sway.nix`. |
| `ssh.nix` | host table (T400, Mac Pro, RPi5) | Enables sshd, opens port 22, enforces a key-only policy (no password / keyboard-interactive, no root). Authorized keys come from the registry via `users.nix`. |
| `firmware/` | referenced by MBP host config | Committed Apple peripheral firmware blobs for the Asahi MBP (see "MacBook (Asahi) firmware"). |
Form-factor decision: a **laptop** imports `laptop.nix` (default
`portable = true`); a **wired desktop** imports `desktop.nix` and sets
`portable = false`; a **headless server** imports neither (leaves
`features.swayDesktop.enable` at its default `false`) and adds only what it
serves. `portable` is threaded through to `home/sway.nix`, which drops the
battery block and brightness keys on desktops.
## Users ## Users
@@ -89,16 +38,6 @@ Identity is data, kept separate from the reusable modules:
identity into that user's home config as the `identity` module arg. A host can identity into that user's home config as the `identity` module arg. A host can
therefore declare any number of users. therefore declare any number of users.
Per-user home extras live under `users/<name>/`:
- [`users/lyrathorpe/home.nix`](./users/lyrathorpe/home.nix) — personal extras
(an ssh host shortcut, gammastep coordinates); imported on Lyra's hosts.
- [`users/emmathorpe/work.nix`](./users/emmathorpe/work.nix) — the work
toolchain (kubectl/helm/az/etc.), work-only LSP servers, and the corporate ssh
handling; imports
[`users/emmathorpe/renovate-review.nix`](./users/emmathorpe/renovate-review.nix),
the daily headless Renovate-PR review timer (EDaaS only).
### Portable home (off-NixOS / external consumers) ### Portable home (off-NixOS / external consumers)
The home config is also exposed for use beyond these hosts: The home config is also exposed for use beyond these hosts:
@@ -113,6 +52,33 @@ The home config is also exposed for use beyond these hosts:
(`inputs.<this>.homeModules.default`). Consumers must supply the module args (`inputs.<this>.homeModules.default`). Consumers must supply the module args
these expect: `inputs` always, `identity` for git/desktop, `portable` for sway. these expect: `inputs` always, `identity` for git/desktop, `portable` for sway.
## Directory authentication (SSSD → Authentik LDAP)
Every NixOS host authenticates users against the Authentik LDAP outpost via
SSSD, implemented in [`modules/sssd.nix`](./modules/sssd.nix) and enabled by
default through the `services.authentikLdap.enable` option (added to
`baseModules`). The **EDaaS** WSL box opts out
(`services.authentikLdap.enable = false`) as a work-managed environment; the
macOS host is unaffected (SSSD is Linux-only).
- Connects over LDAPS to `ldap.lyrapup.pet:636`, search base
`dc=ldap,dc=goauthentik,dc=io`, binding as
`cn=sssd-bind,ou=users,dc=ldap,dc=goauthentik,dc=io`.
- The schema mappings match Authentik's non-standard object classes
(`goauthentik.io/ldap/user`, `goauthentik.io/ldap/group`) over the POSIX
attributes (`uid`, `uidNumber`, `gidNumber`, `homeDirectory`).
- Home directories are created on first login (`pam_mkhomedir`).
### Secrets (agenix)
The LDAP bind credential is an [agenix](https://github.com/ryantm/agenix)
secret, decrypted at activation with each host's SSH host key. The decrypted
plaintext is a full `sssd.conf` drop-in delivered to
`/etc/sssd/conf.d/01-ldap-authtok.conf`, so the password never enters the Nix
store. Owner setup (host recipient keys, encrypting the bind password, DNS for
`ldap.lyrapup.pet`, rebuild) is documented in
[`secrets/README.md`](./secrets/README.md).
## Applying ## Applying
```sh ```sh
@@ -122,36 +88,6 @@ sudo nixos-rebuild switch --flake .#<configuration>
darwin-rebuild switch --flake .#lyrathorpe-mac darwin-rebuild switch --flake .#lyrathorpe-mac
``` ```
On a host whose `networking.hostName` matches its flake attribute (the WSL box
and the Pi are set up this way), `nh os switch` resolves the configuration from
the hostname with no `--flake`/`-H` flag.
## Adding a new host
1. **Create `hosts/<Name>/`.** Add `configuration.nix` with the host-specific
bits only: `networking.hostName`, bootloader (firmware-specific — it is
deliberately not set in the shared modules), and any per-machine hardware
quirks. Keep anything reusable in `modules/` instead.
2. **Hardware config.** Generate `hardware-configuration.nix` on the real
machine with `nixos-generate-config` and commit it. If the machine does not
exist yet, commit a clearly-labelled placeholder so the host still evaluates
in CI (see the existing T400 / RPi5 placeholders), and replace it at install.
These files are excluded from the formatter and linters.
3. **Add a host-table entry in `flake.nix`.** Under `hosts` (NixOS) or
`darwinHosts` (macOS), set `system`, the `modules` list (host config + form
factor + any `nixos-hardware` profiles), and the `users` map (each user's
`homeModules`). Choose the form factor per the decision note above; a headless
host imports neither `laptop.nix` nor `desktop.nix`.
4. **Users.** If the host introduces a new person, add them to
`users/registry.nix` first; otherwise reference an existing username.
5. **Verify.** `nix flake check` formats, lints, and evaluates every host —
including the new one — so a broken entry fails locally before CI. Then
`sudo nixos-rebuild switch --flake .#<configuration>` on the machine.
No change to CI is needed: the host-eval step discovers hosts from the flake
(`attrNames` of the configuration sets), so a new entry is picked up
automatically.
## Shell environment & keybindings ## Shell environment & keybindings
- Interactive shell features (zsh, tmux, git, ssh, CLI tools, auto-tmux): - Interactive shell features (zsh, tmux, git, ssh, CLI tools, auto-tmux):
@@ -202,7 +138,4 @@ A dev shell and a formatting/lint gate are wired through the flake:
[`.gitea/workflows/ci.yaml`](./.gitea/workflows/ci.yaml) runs `nix flake check` [`.gitea/workflows/ci.yaml`](./.gitea/workflows/ci.yaml) runs `nix flake check`
(formatting, `deadnix`, `statix`, the pre-commit hooks) and evaluates every (formatting, `deadnix`, `statix`, the pre-commit hooks) and evaluates every
NixOS and Darwin host configuration on push/PR. It always runs (no `paths:` NixOS and Darwin host configuration on push/PR.
filter) so the required check never hangs pending; the heavy Nix steps are
skipped when a PR touches no `.nix`/lockfile/workflow file, and the job still
reports green.
Generated
+65 -43
View File
@@ -3,16 +3,16 @@
"brew-src": { "brew-src": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1783446865, "lastModified": 1781226006,
"narHash": "sha256-nCrPEbQjgnSAOVWTxRXD9Yi6P3oECdtZISYcQCFI9Fs=", "narHash": "sha256-w4ZTuOnhYiDxjaynrMTASzp802QblBWmo3wpB8wVN4Y=",
"owner": "Homebrew", "owner": "Homebrew",
"repo": "brew", "repo": "brew",
"rev": "655769712a9a9499563d9685a8488f349354492d", "rev": "109191be4988470b51a60a5ef1998520aa24c01b",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "Homebrew", "owner": "Homebrew",
"ref": "6.0.9", "ref": "6.0.1",
"repo": "brew", "repo": "brew",
"type": "github" "type": "github"
} }
@@ -25,11 +25,11 @@
}, },
"locked": { "locked": {
"dir": "pkgs/firefox-addons", "dir": "pkgs/firefox-addons",
"lastModified": 1783828963, "lastModified": 1782014564,
"narHash": "sha256-eTytzcUJCaDUZ3/9EF0+V3fvlikQMQBwiX1Sx4Gy+No=", "narHash": "sha256-F/royQHyJAyKWKrV8AaG4Yf1yjzxa+PFk5xvTdvBrzk=",
"owner": "rycee", "owner": "rycee",
"repo": "nur-expressions", "repo": "nur-expressions",
"rev": "8d61e9afde605cd6c22dab68b83d7a71f0a6c5b2", "rev": "d6668e34bbce788459883a1097bf0ee170f49c61",
"type": "gitlab" "type": "gitlab"
}, },
"original": { "original": {
@@ -93,11 +93,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1782949081, "lastModified": 1778716662,
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=", "narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=",
"owner": "hercules-ci", "owner": "hercules-ci",
"repo": "flake-parts", "repo": "flake-parts",
"rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e", "rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -130,16 +130,17 @@
"git-hooks": { "git-hooks": {
"inputs": { "inputs": {
"flake-compat": "flake-compat", "flake-compat": "flake-compat",
"gitignore": "gitignore",
"nixpkgs": [ "nixpkgs": [
"nixpkgs" "nixpkgs"
] ]
}, },
"locked": { "locked": {
"lastModified": 1783008725, "lastModified": 1781733627,
"narHash": "sha256-jGiy6+sxjNWXSjp25uoJuNfyH9zBK1PEDY0lVoL4ibQ=", "narHash": "sha256-U3yTuGBnmXvXoQI3qkpfEDsn9RovQPAjN7ndRco+3u0=",
"owner": "cachix", "owner": "cachix",
"repo": "git-hooks.nix", "repo": "git-hooks.nix",
"rev": "bca82caa46d5ec0f5d422c61fb1e30bc51313cbe", "rev": "3bbec39bc90eadfa031e6f3b77272f3f60803e39",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -148,6 +149,27 @@
"type": "github" "type": "github"
} }
}, },
"gitignore": {
"inputs": {
"nixpkgs": [
"git-hooks",
"nixpkgs"
]
},
"locked": {
"lastModified": 1709087332,
"narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=",
"owner": "hercules-ci",
"repo": "gitignore.nix",
"rev": "637db329424fd7e46cf4185293b9cc8c88c95394",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "gitignore.nix",
"type": "github"
}
},
"home-manager": { "home-manager": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
@@ -155,11 +177,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1783740085, "lastModified": 1781981105,
"narHash": "sha256-qajyHfZY29G2oEQk+uHxmsJcRoBUBXP9maTpFlwP/dI=", "narHash": "sha256-/1nNBbA7PrSQpTc9Qazkhl4kIPg+TNl0CjxS3UQJKlw=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "3cd22efe6471dc7365c822bd9ad73a21e55f38fb", "rev": "7bfff44b465909f69a442701293bc0badcf476dc",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -192,11 +214,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1783744694, "lastModified": 1781772065,
"narHash": "sha256-2cp6N3rrwnGYLTx9l6N+NI+kwrCWxvJUbj5WJhvB29A=", "narHash": "sha256-xIbRSwDB1GBAUsWsQZUjudGfAGQt3BOpsWaO/ugVa4w=",
"owner": "nix-darwin", "owner": "nix-darwin",
"repo": "nix-darwin", "repo": "nix-darwin",
"rev": "c3e90c89649b07d1a96e4b9dd6cd0d6e44b91a74", "rev": "adda04f0bf4819575b1978c2f8d78401b3c2be12",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -211,11 +233,11 @@
"brew-src": "brew-src" "brew-src": "brew-src"
}, },
"locked": { "locked": {
"lastModified": 1783875858, "lastModified": 1781389246,
"narHash": "sha256-+yYNOkj/bkVQmwKH0hewqwBwAEoh4Gq2BmQPIP1jNrg=", "narHash": "sha256-ORqLAo/hoJdsZC7UPAuEHev6S0+XIqKEC7vjo5prz1k=",
"owner": "zhaofengli", "owner": "zhaofengli",
"repo": "nix-homebrew", "repo": "nix-homebrew",
"rev": "60641da8324e6a1af716a0340d901ccb131c91ef", "rev": "de7953a08ed4bb9245be043e468561c17b89130d",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -231,11 +253,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1783864904, "lastModified": 1782030356,
"narHash": "sha256-BQxN5UMg9FOevAsgBRwPxfxlh51Puj+dNn/8Dsi3sPM=", "narHash": "sha256-h4WpMr455AfRub0FXBaon6Vcpe0waUyJ4GivIW6oyd4=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nix-index-database", "repo": "nix-index-database",
"rev": "1111b9bc836afb7e31a7014e8d1272de9b1c917d", "rev": "3017088b49efd404f78e3b104f553b97e4af786b",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -252,11 +274,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1783669315, "lastModified": 1781520503,
"narHash": "sha256-DjIkyK48jWUxYCCoTDS9L5PgGg6/RFRSRXW2dSFpJg8=", "narHash": "sha256-XuqQQG1qRyc3o8ld937sDLQNx+QrGV852KJ0dNglJDg=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nixos-apple-silicon", "repo": "nixos-apple-silicon",
"rev": "9e46a0edd8a6d96538d146a4bb4477e7fae8b1a0", "rev": "43043ad207529650f9fa68e1705f7cf9c08bfdeb",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -272,11 +294,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1783792734, "lastModified": 1781622756,
"narHash": "sha256-50rvY9GdFvpYDcMLcD/4cWSi0hVxArT5wsGlVsHy8eY=", "narHash": "sha256-JrPh4M6S7aPsEE9tOENuZrxC6o2szSLlK+t4+nLke9s=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixos-hardware", "repo": "nixos-hardware",
"rev": "8efb4337e857949f4cfac86d12ef1066f417f31f", "rev": "08018c72174a4df5657f8d94178ac69fb9c243e5",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -293,11 +315,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1783897948, "lastModified": 1781182279,
"narHash": "sha256-wusXpttNJn7SvUMvGLpNuJgcwIIkMwlWNnasPPxpftg=", "narHash": "sha256-V5EQQbDnmdiXGQXrEF1PEL7QYsFqfH8N1E89Z5ONwFk=",
"owner": "nix-community", "owner": "nix-community",
"repo": "NixOS-WSL", "repo": "NixOS-WSL",
"rev": "7348d3f38ab1bd6abe156a923fab6f43656b168f", "rev": "5675822ba756e6e56f8f6a5a76e90e0da2ece94d",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -308,11 +330,11 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1783703440, "lastModified": 1781216227,
"narHash": "sha256-O3/YajjWo001VUIgD8BwaRdSNLUFe7nZ1qV5TwhRBcw=", "narHash": "sha256-9mUW6gNwoN2SWc/l0fW4svPNOulXLl8ijqKyeSOGgJE=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "8f0500b9660505dc3cb647775fe9a978a74b5283", "rev": "a0374025a863d007d98e3297f6aa46cc3141c2f0",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -324,11 +346,11 @@
}, },
"nixpkgs-unstable": { "nixpkgs-unstable": {
"locked": { "locked": {
"lastModified": 1783776592, "lastModified": 1781577229,
"narHash": "sha256-UgCQzxeWI75XM8G+hPrPh+MKzEPjG3SpAj7dtqSbksA=", "narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "e7a3ca8092b61ff85b6a45bf863ea2b2d6a661b3", "rev": "567a49d1913ce81ac6e9582e3553dd90a955875f",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -347,11 +369,11 @@
"systems": "systems" "systems": "systems"
}, },
"locked": { "locked": {
"lastModified": 1782919967, "lastModified": 1781971008,
"narHash": "sha256-pRwjfB5HQJ3m8J8bOR43pPHtHI7VUJSqwLA3P06cOY0=", "narHash": "sha256-T2u2RQZWKvD1J+TgcxjiJr8IymBr/PrUNeAGhMZFZU4=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nixvim", "repo": "nixvim",
"rev": "667c8471f4a0fb24d702d1a61af8609f1a5f1ba6", "rev": "7afca458f064f166d3a9c98db3b41a984fe46492",
"type": "github" "type": "github"
}, },
"original": { "original": {
+11
View File
@@ -46,6 +46,15 @@
url = "github:cachix/git-hooks.nix"; url = "github:cachix/git-hooks.nix";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
# agenix: age-encrypted secrets, decrypted at activation with each host's
# SSH host key. Provides the SSSD LDAP bind credential (secrets/, see
# modules/sssd.nix). The darwin module is intentionally unused (SSSD is
# Linux-only).
agenix = {
url = "github:ryantm/agenix";
inputs.nixpkgs.follows = "nixpkgs";
inputs.home-manager.follows = "home-manager";
};
# Declarative Neovim (the editor; see home/editor.nix). Release # Declarative Neovim (the editor; see home/editor.nix). Release
# branch matched to the pinned nixpkgs (26.05); follows our nixpkgs to keep a # branch matched to the pinned nixpkgs (26.05); follows our nixpkgs to keep a
# single nixpkgs in the closure. editor.nix sets programs.nixvim.nixpkgs.source # single nixpkgs in the closure. editor.nix sets programs.nixvim.nixpkgs.source
@@ -123,7 +132,9 @@
./modules/users.nix ./modules/users.nix
./modules/common-nixos.nix ./modules/common-nixos.nix
./modules/features.nix ./modules/features.nix
./modules/sssd.nix
commonModule commonModule
inputs.agenix.nixosModules.default
home-manager.nixosModules.home-manager home-manager.nixosModules.home-manager
{ {
home-manager.useGlobalPkgs = true; home-manager.useGlobalPkgs = true;
+2 -5
View File
@@ -1,14 +1,11 @@
- [User name](user_name.md) — address the user as Lyra - [User name](user_name.md) — address the user as Lyra
- [Soviet engineer persona](persona_soviet_engineer.md) — terse, dry, pragmatic; no emojis; technical accuracy over voice - [Soviet engineer persona](persona_soviet_engineer.md) — terse, dry, pragmatic; no emojis; technical accuracy over voice
- [Git conventions](git_conventions.md) — never commit to main, always a branch; Conventional Commits branches and messages; inspect repo style first; commit at logical checkpoints - [Git conventions](git_conventions.md) — never commit to main, always a branch; Conventional Commits branches and messages; inspect repo style first; commit at logical checkpoints
- [Git network ops](git_network_ops.md) — GitHub and Gitea (code.emmathe.dev) both pushable in-sandbox (sandbox off, agent key); raise Gitea PRs via tea CLI - [Git network ops](git_network_ops.md) — GitHub pushable in-sandbox (agent key; just sandbox off); Gitea code.emmathe.dev needs hand-off
- [Git commit signing](git_commit_signing.md) — signs in-sandbox via ssh-agent (allowAllUnixSockets + inlined pubkey); sig=N without allowedSignersFile is cosmetic, still signed - [Git commit signing](git_commit_signing.md) — signs in-sandbox via ssh-agent (allowAllUnixSockets + inlined pubkey)
- [Git check state first](git_check_state.md) — always check branch/status/divergence before git work; Lyra edits repos between sessions - [Git check state first](git_check_state.md) — always check branch/status/divergence before git work; Lyra edits repos between sessions
- [Keep docs updated](docs_keep_updated.md) — update docs in the same pass as code/config changes; stale docs are a defect - [Keep docs updated](docs_keep_updated.md) — update docs in the same pass as code/config changes; stale docs are a defect
- [SIBO Workabout MX project](sibo_workabout_mx_scanner.md) — RE + barcode-inventory project state; scanner is an OO DYL object (oscanner), blocked on on-device ordinal capture; resume via code/inventory/CONTINUATION.md
- [Jira tooling](jira_tooling.md) — comments are Markdown not wiki; transitions may need assignee; link direction; WSP transition IDs - [Jira tooling](jira_tooling.md) — comments are Markdown not wiki; transitions may need assignee; link direction; WSP transition IDs
- [Jira WSP fields](jira_wsp_fields.md) — WSP field map: issue-type IDs, required Bug fields with allowed values/IDs, Task shortcut, relevant components
- [Review and comments workflow](workflow_review_and_comments.md) — show PR body and non-trivial Jira comments before posting; terse IaC code comments; PR body content rules - [Review and comments workflow](workflow_review_and_comments.md) — show PR body and non-trivial Jira comments before posting; terse IaC code comments; PR body content rules
- [Sandbox prompts](feedback_sandbox_prompts.md) — don't prompt for sandbox-disable or routine read-only shell ops; broaden permissions instead - [Sandbox prompts](feedback_sandbox_prompts.md) — don't prompt for sandbox-disable or routine read-only shell ops; broaden permissions instead
- [Dev clusters disposable](dev_clusters_disposable.md) — Lyra's dev clusters are recreatable; mutate/break freely, no confirmation needed - [Dev clusters disposable](dev_clusters_disposable.md) — Lyra's dev clusters are recreatable; mutate/break freely, no confirmation needed
- [Nix shell tooling](nix_shell_tooling.md) — any nixpkgs tool runs ad hoc via `nix run`/`nix shell nixpkgs#<pkg>`; a missing command is never a dead end
+1 -3
View File
@@ -1,6 +1,6 @@
--- ---
name: git-commit-signing name: git-commit-signing
description: "Commits sign in-sandbox via ssh-agent (allowAllUnixSockets + inlined pubkey); local verify shows sig=N without an allowedSignersFile but the commit IS signed." description: "Commits sign in-sandbox via ssh-agent — needs `allowAllUnixSockets: true` in settings, plus pubkey inlined in user.signingkey."
metadata: metadata:
node_type: memory node_type: memory
type: feedback type: feedback
@@ -19,6 +19,4 @@ Lyra's git is configured to SSH-sign commits (`commit.gpgsign=true`, `gpg.format
**How to apply:** Commit normally with `git commit`. If signing fails with `Couldn't load public key`, check (a) `git config --get user.signingkey` starts with `key::ssh-ed25519 AAAA...` (not literal `$(...)`), (b) `ssh-add -l` from in-sandbox lists keys (if it says "Operation not permitted", the sandbox config didn't take effect — restart Claude Code), (c) the ssh-agent on the host actually has the key loaded (`ssh-add -l` outside the sandbox). Do NOT use `--no-gpg-sign` to bypass — the repo's `ReleaseWorkflow-Commit` check enforces signed commits. **How to apply:** Commit normally with `git commit`. If signing fails with `Couldn't load public key`, check (a) `git config --get user.signingkey` starts with `key::ssh-ed25519 AAAA...` (not literal `$(...)`), (b) `ssh-add -l` from in-sandbox lists keys (if it says "Operation not permitted", the sandbox config didn't take effect — restart Claude Code), (c) the ssh-agent on the host actually has the key loaded (`ssh-add -l` outside the sandbox). Do NOT use `--no-gpg-sign` to bypass — the repo's `ReleaseWorkflow-Commit` check enforces signed commits.
**Verifying — the recurring trap:** `git log --show-signature` and the `%G?` format both report `N` and print `error: gpg.ssh.allowedSignersFile needs to be configured and exist for ssh signature verification`. This does NOT mean the commit is unsigned — it means git has no local allowed-signers file to check it against. The signature is present. Confirm the real state with `git cat-file commit <ref> | grep -i '^gpgsig'`: an `-----BEGIN SSH SIGNATURE-----` block means signed. So `N` here is cosmetic, not a signing failure — do not "fix" it by re-committing. To make local verification actually pass, set `gpg.ssh.allowedSignersFile` to a file mapping the signer to the pubkey (a line like `emma.thorpe@cloud.com ssh-ed25519 AAAA...`); Gitea/CI verifies server-side regardless.
Related: [[git-network-ops]], [[git-conventions]]. Related: [[git-network-ops]], [[git-conventions]].
+3 -3
View File
@@ -1,6 +1,6 @@
--- ---
name: git-network-ops name: git-network-ops
description: Push/pull is remote-specific — both GitHub and Gitea (code.emmathe.dev) are agent-pushable in-sandbox (sandbox off); raise Gitea PRs with the tea CLI. description: Push/pull is remote-specific — GitHub is agent-pushable in-sandbox; Gitea (code.emmathe.dev) needs hand-off to Lyra.
metadata: metadata:
node_type: memory node_type: memory
type: feedback type: feedback
@@ -11,8 +11,8 @@ Whether a network op can run depends on which key the remote needs:
**GitHub remotes (e.g. csg-citrix-storefront/\*): pushable in-sandbox by the agent.** ssh-agent holds the decrypted `~/.ssh/id_ed25519` (`emma.thorpe@cloud.com`), which is authorized on GitHub. Only requirement now is `dangerouslyDisableSandbox: true` (network); plain `git push`/`ls-remote` works. Probe non-mutatively with `git ls-remote` first. (Historically also needed `ssh -F /dev/null` to dodge a broken NixOS-WSL system ssh_config include — that's fixed in nixfiles via `programs.ssh.systemd-ssh-proxy.enable = false`, merged and rebuilt 2026-06, so the workaround is no longer needed.) **GitHub remotes (e.g. csg-citrix-storefront/\*): pushable in-sandbox by the agent.** ssh-agent holds the decrypted `~/.ssh/id_ed25519` (`emma.thorpe@cloud.com`), which is authorized on GitHub. Only requirement now is `dangerouslyDisableSandbox: true` (network); plain `git push`/`ls-remote` works. Probe non-mutatively with `git ls-remote` first. (Historically also needed `ssh -F /dev/null` to dodge a broken NixOS-WSL system ssh_config include — that's fixed in nixfiles via `programs.ssh.systemd-ssh-proxy.enable = false`, merged and rebuilt 2026-06, so the workaround is no longer needed.)
**Gitea (`code.emmathe.dev`, e.g. nixfiles): pushable in-sandbox by the agent (as of 2026-07-14).** The ssh-agent now holds the `code.emmathe.dev` key (`git@code.emmathe.dev`), so `git push` works with `dangerouslyDisableSandbox: true` — it needs the agent socket plus `~/.ssh/known_hosts`, both reachable with sandbox off. Probe with `git ls-remote` first. Raise PRs with the `tea` CLI, which is installed and logged in to `code.emmathe.dev` (user `lyrathorpe`): `tea pr create --login code.emmathe.dev --repo lyrathorpe/nixfiles --base main --head <branch> --title "..." --description "..."`. Only fall back to hand-off if `ssh-add -l` (sandbox off) does NOT list the `code.emmathe.dev` key — then it dropped from the agent and Lyra must re-add it (`ssh-add ~/.ssh/code.emmathe.dev`, passphrase-protected). **Gitea (`code.emmathe.dev`, e.g. nixfiles): hand off to Lyra.** Needs `~/.ssh/code.emmathe.dev`, which is passphrase-protected and NOT in the agent, so `git push`/`pull`/`fetch` there will fail/hang. Pause, give Lyra the exact command (she runs `ssh-add ~/.ssh/code.emmathe.dev` once, then pushes).
**Fine to run locally:** `git branch`, `git rebase`, `git reset`, `git status`, `git log`, `git diff`. `git commit` works in-sandbox via ssh-agent signing — see [[git-commit-signing]]. **Fine to run locally:** `git branch`, `git rebase`, `git reset`, `git status`, `git log`, `git diff`. `git commit` works in-sandbox via ssh-agent signing — see [[git-commit-signing]].
**How to apply:** Both remotes → do it with sandbox off; probe with `git ls-remote` first, and raise Gitea PRs via `tea`. Hand off only if the Gitea key is missing from the agent. Related: [[git-conventions]]. **How to apply:** Check the remote host before a network op. GitHub → just do it (sandbox off). Gitea → hand off. Related: [[git-conventions]].
-32
View File
@@ -1,32 +0,0 @@
---
name: jira-wsp-fields
description: WSP Jira project field map — issue-type IDs, required Bug fields with allowed values/IDs, and the Task shortcut for fast ticket creation
metadata:
type: reference
---
Field map for the **WSP (Workspace Platform)** Jira project, to create tickets without trial-and-error. Site `citrix.atlassian.net`, cloudId `70cbc59a-06d2-4508-a9a6-61f1dbc2057f`, project key `WSP`, project id `10061`. See also [[jira-tooling]].
**Issue-type IDs:** Epic `10000`, Story `10004`, Task `10008`, Bug `10123`, Sub-task `10009`.
**Fast path — use Task, not Bug.** A `Task` requires only `summary` (project/issuetype auto, reporter defaults to caller). A `Bug` requires six extra fields (below), so only pick Bug when it must be a Bug. The sibling infra/remediation tickets in WSP are Tasks.
**Bug required fields** (enforced by the create validator; note `createmeta` omits `versions` but the API rejects without it):
| Field | Key | Shape | Allowed values (value = id) |
| ------------------- | ------------------- | -------------------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| Severity | `customfield_10061` | `{"value":"S2"}` | S1=10643, S2=10644, S3=10645, S4=10646 |
| Affects Environment | `customfield_10116` | `{"value":"Production"}` | Production=11031, Staging=11032, Integration=11033, Development=11034, Test=11035 |
| Defect Source | `customfield_10138` | `{"value":"Internal - Manual"}` | Internal - Manual=12699, Internal - Automation=12700, Customer=12702, Security Review=12704 |
| Regression | `customfield_10141` | `{"value":"No"}` | Yes - Previous Build=12705, Yes - Previous Release=12706, No=12707 |
| Components | `components` | `[{"name":"Workspace Configuration"}]` | 109 options; relevant ones below |
| Affects versions | `versions` | `[{"name":"<version>"}]` | not in requiredFieldsOnly createmeta — fetch current list from full createmeta or project versions before setting |
Select customfields (`...customfieldtypes:select`) accept `{"value":"..."}` or `{"id":"..."}`. Components/versions accept `[{"name":...}]` or `[{"id":...}]`.
**Relevant Components (name=id):** Workspace Configuration=12052, Workspace-Platform=12060, Multicluster Platform=12023, WSP Core Ingress=12037, Microservice Infrastructure=12020, Infrastructure=34375, Custom Domain Proxy=12021, Custom Domain Ingress Manager=11968, Custom Domain Infrastructure=11975, StoreFrontConfiguration=12042, StoreFront=12050, Test Infrastructure=12012, WSP Release Infrastructure=12011.
**Other create notes:** pass `description`/`commentBody` with `contentFormat: markdown`; set labels via `additional_fields {"labels":[...]}`; attach to an epic with the top-level `parent` param (`parent: "WSP-32494"` works for epic→Task). WSP transition IDs live in [[jira-tooling]].
Example Bug `additional_fields`:
`{"customfield_10061":{"value":"S2"},"customfield_10116":{"value":"Production"},"customfield_10138":{"value":"Internal - Manual"},"customfield_10141":{"value":"No"},"components":[{"name":"Workspace Configuration"}],"versions":[{"name":"<version>"}],"labels":["..."]}`
-23
View File
@@ -1,23 +0,0 @@
---
name: nix-shell-tooling
description: "Any nixpkgs tool can be run ad hoc via nix run / nix shell — a missing command is never a dead end during development"
metadata:
node_type: memory
type: feedback
originSessionId: dfb56b58-518b-4daf-b531-7119bb4a9534
---
Any tool in nixpkgs can be run without installing it into the environment. If a
command is missing during development, pull it from nixpkgs on the fly instead
of working around its absence or reporting the tool as unavailable.
**Why:** Lyra runs NixOS; the ambient PATH is deliberately minimal, but the full
nixpkgs set is always one command away. "command not found" is not a blocker.
**How to apply:**
- One-off run: `nix run nixpkgs#<pkg> -- <args>` (e.g. `nix run nixpkgs#jq -- .`).
- Tools on PATH for a session: `nix shell nixpkgs#<pkg> [nixpkgs#<pkg2> ...]`,
then run commands normally.
- Legacy form also works: `nix-shell -p <pkg> --run '<cmd>'`.
- Prefer this over hand-rolling a substitute for a tool that exists in nixpkgs.
@@ -1,25 +0,0 @@
---
name: sibo-workabout-mx-scanner
description: State of the Psion Workabout MX reverse-engineering / barcode-inventory project and how to resume it
metadata:
node_type: memory
type: project
originSessionId: 74de014e-9cf4-47f6-92f4-c34197ac1858
---
Long-running project (July 2026) reverse-engineering the **Psion Workabout MX** (SIBO OS, NEC V30MX, TopSpeed C) to build a barcode **inventory demo** (scan UPC → DBF database file; add stock, consume by a quantity unit) and, alongside, **complete device programming documentation**. Repo: Gitea **lyrathorpe/sibo-playground**, working branch **`feat/inventory-phase1-scan`** (unmerged). Gitea needs hand-off / the contents API for pushes — see [[git-network-ops]]; [[git-conventions]] for branch/PR rules.
**Committed on the branch (durable, survive reboot):**
- `docs/reference/00-08` + index — the SIBO/MX programming reference (building apps, system/OS, I/O devices, PLIB core, file system & DBF, UI, hardware, and RE'd boot/OS-call internals).
- `code/inventory/` — app scaffold: `upc.c/.h` (UPC-A check-digit validation, correct), `bcode.c/.h`, `scan.c` (Phase-1 diagnostics), `README.md`, **`SCANNER-API.md`** (all scanner findings), **`CONTINUATION.md`** (the on-device debugging procedure to finish).
- `docs/mx-re/toolchain-and-plan.md` — the RE toolchain.
- The **ROM `w2mx_v7.20f_eng.bin`** and the full **SDK + HDK** (manuals as `docs/*.txt`; headers/libs/`bar*.ldd` under `code/SIBOSDK/`; HDK under `code/HDK/`) are on the branch. `/tmp/claude/sibo/` working files (ROM slices, MAME rom dir, Ghidra/decomp output) are transient and reproducible from the toolchain doc.
**Scanner — key result:** the integral laser is driven as an **OO library object** in `SCANNER.DYL` (category token **`oscanner`**) via `p_getlibh``p_newsend`/`f_newsend``p_send`, over **LIBMANAGER (INT 0x84)** / **MESSMANAGER (INT 0x83)** — NOT raw device I/O. Confirmed on the physical device: `p_open("WL2:D")` + control ops **6** then **7** (`p_iow(chan,6); p_iow(chan,7)`) fire the laser to a good decode (green LED). Default Symbol2 11-byte param block: `04 3f 01 15 06 04 1e 80 0d 0a 06` (decoded output is CR/LF-terminated). Dead ends (do not retry): raw `TTY:D` reads, and the wand `BAR:` / `bar*.ldd` decoders (probe expansion slots → `-41`).
**Blocked on / next step:** the OO **message ordinals + parameter structs** for init / set-params / trigger / read. OLIB assigns ordinals dynamically across the class hierarchy (base classes in `olib`/`hwim`), so they resolve only at runtime — capture them with the **SIBO Debugger on the physical device** (remote debug over serial; it supports breakpoints inside DYLs). MAME cannot inject a barcode, so the last mile must be on hardware. Full step-by-step is in `code/inventory/CONTINUATION.md`.
**RE toolchain (reproducible):** the ROM is MAME machine **`psionwamx`**; run its debugger headless via `xvfb-run -a mame psionwamx -rompath roms -debug -debugscript CMDS -sound none -seconds_to_run N` (MAME lua input injection into the keyboard matrix does NOT work headless — a known limitation). Static: **radare2** (16-bit x86). Decompile: **Ghidra headless** (processor `x86:LE:16:Real Mode`, a Java GhidraScript — Ghidra 12 has no bundled Python). Get MAME/radare2/Ghidra via `nix-shell -p ...`. Details in `docs/mx-re/toolchain-and-plan.md`.
**Fallback to deliver value now:** Phase 2 (the DBF inventory: add stock, consume by quantity) can be built with keyboard UPC entry against `docs/reference/05-filesystem-dbf.md`, dropping the scanner in behind the same interface once retrieval is finished. [[docs-keep-updated]]
-51
View File
@@ -1,51 +0,0 @@
# macOS (nix-darwin) — `lyrathorpe-mac`
Flake host: `lyrathorpe-mac` (`aarch64-darwin`). Apple Silicon Mac managed by
**nix-darwin** from this same flake. Built via `mkDarwinHost` (single-user —
macOS owns the account; identity still comes from the registry). Files:
`configuration.nix`.
## What this host is
A macOS workstation. The interactive user environment (shell, git, editor,
Claude) is the **shared `../../home` bundle** — the same modules the Linux hosts
use — so the terminal experience matches. The Linux-only `desktop.nix`/`sway.nix`
are intentionally left out. This host config covers the macOS-specific layer:
system packages, Homebrew, and macOS UI defaults.
## Package sourcing
- **nixpkgs** (`environment.systemPackages`) for CLI tooling and libraries.
- **Homebrew**, owned declaratively by `nix-homebrew` (Rosetta enabled for
x86_64 formulae). The `brews`/`casks` lists are **authoritative**:
`onActivation.cleanup = "zap"` uninstalls anything not declared. GUI apps are
casks (nixpkgs darwin GUI support is unreliable); a few version-pinned
toolchains and the PWA host stay on brew for continuity.
- **Mac App Store** apps are **not** declarative: nix-darwin 26.05 runs
activation as root, and `mas` cannot reach the App Store session from root.
Install them by hand with `mas install <id>` from a GUI Terminal (the `mas`
CLI is in `environment.systemPackages`).
## macOS integration
- `security.pam.services.sudo_local`**Touch ID for sudo** (and
`darwin-rebuild`'s sudo prompt), kept in `sudo_local` so it survives OS
updates. `reattach` pulls in `pam_reattach` so Touch ID works inside tmux
(which the terminals auto-start).
- `system.defaults` — declarative dock / finder / global / trackpad preferences,
applied on activation and reversible. This is the main reason to run nix-darwin
beyond package management.
- The JetBrainsMono Nerd Font is installed to `/Library/Fonts`; set it in
iTerm2 (Settings → Profiles → Text → Font) so the tmux statusline glyphs
render.
## stateVersion
`system.stateVersion = 5` (the nix-darwin state version, an integer — not a
NixOS release string). Read `darwin-rebuild changelog` before changing it.
## Apply
```sh
darwin-rebuild switch --flake .#lyrathorpe-mac
```
-53
View File
@@ -1,53 +0,0 @@
# Work WSL box — `emmathorpe-edaas`
Flake host: `emmathorpe-edaas` (`x86_64-linux`). NixOS running under
**NixOS-WSL** on the corporate Windows machine. Headless: no Sway desktop
(`features.swayDesktop.enable = false`), plain WSL shell login. Files:
`configuration.nix`.
## What this host is
The day-to-day work environment. It layers the corporate Kubernetes / Helm /
Terraform / cloud toolchain and a couple of work-only editor language servers on
top of the shared home profile. The system config here is thin — it is mostly
WSL plumbing; the user-facing tooling lives in
[`../../users/emmathorpe/work.nix`](../../users/emmathorpe/work.nix).
## WSL specifics
- `wsl.enable`, default user `emmathorpe`, Windows PATH interop and start-menu
launchers on. `/etc/hosts` generation is off (`generateHosts = false`).
- **Docker Desktop integration**, not the native daemon as the primary path:
`wsl.extraBin` shims the coreutils/`groupadd`/`usermod` binaries Docker
Desktop's `wsl-distro-proxy` expects, and `docker-desktop-proxy.script` is
patched to the real proxy path. The native `virtualisation.docker` is also
enabled (with `enableOnBoot` + `autoPrune`).
- `programs.ssh.systemd-ssh-proxy.enable = false` — the NixOS-WSL store is a
read-only VHD owned by `nobody`, and OpenSSH rejects the generated
`ssh-proxy` Include as "Bad owner or permissions", which would break ssh/git
for every command. The vsock proxy it provides is unused under WSL.
- `networking.hostName = "emmathorpe-edaas"` matches the flake attribute so
`nh os switch` resolves without `-H`.
## Renovate review timer
The host-table entry sets `users.emmathorpe.linger = true` so the user's
`systemd --user` instance stays alive without an open login session. That keeps
the daily headless **Renovate PR review** timer firing — defined in
[`../../users/emmathorpe/renovate-review.nix`](../../users/emmathorpe/renovate-review.nix)
(imported only from `work.nix`, so it exists on this machine alone). See that
file's header for the auth (Vertex AI ADC), triage policy, and caveats.
## stateVersion
`system.stateVersion = "24.11"` — the release this box was first installed on.
Leave it; it freezes stateful defaults and is not meant to track the current
nixpkgs.
## Apply
```sh
sudo nixos-rebuild switch --flake .#emmathorpe-edaas
# or, since the hostname matches the attribute:
nh os switch
```
+5
View File
@@ -62,6 +62,11 @@
features.swayDesktop.enable = false; features.swayDesktop.enable = false;
# Opt out of fleet-wide SSSD/Authentik LDAP auth: this is a work-managed WSL
# box, not part of the personal directory. Every other NixOS host inherits the
# default-true from modules/sssd.nix.
services.authentikLdap.enable = false;
# NOTE: this user's systemd --user lingering -- so the home-manager renovate # NOTE: this user's systemd --user lingering -- so the home-manager renovate
# timer fires without an open login session -- is enabled from the host table # timer fires without an open login session -- is enabled from the host table
# in flake.nix (users.emmathorpe.linger = true) and applied by # in flake.nix (users.emmathorpe.linger = true) and applied by
-4
View File
@@ -27,10 +27,6 @@
]; ];
}; };
# Explicit rather than relying on the module default (which upstream will stop
# defaulting to true; the eval warns otherwise).
hardware.asahi.enable = true;
# Apple peripheral firmware (Wi-Fi/Bluetooth). The directory is gitignored and # Apple peripheral firmware (Wi-Fi/Bluetooth). The directory is gitignored and
# populated out-of-band -- see README. # populated out-of-band -- see README.
hardware.asahi.peripheralFirmwareDirectory = ../../modules/firmware; hardware.asahi.peripheralFirmwareDirectory = ../../modules/firmware;
+1 -1
View File
@@ -48,7 +48,7 @@ gigabit ports.
## Login ## Login
Graphical login via a Wayland greeter — `greetd` running ReGreet inside the Graphical login via a Wayland greeter — `greetd` running ReGreet inside the
`cage` kiosk compositor — configured centrally in `../../modules/sway.nix` for `cage` kiosk compositor — configured centrally in `lyrathorpe/swaywm.nix` for
every Sway host (gated on `features.swayDesktop.enable`). The greeter is forced every Sway host (gated on `features.swayDesktop.enable`). The greeter is forced
to the Dvorak layout to match the console and Sway session. Set the user to the Dvorak layout to match the console and Sway session. Set the user
password (`passwd lyrathorpe`) after install, or the greeter cannot password (`passwd lyrathorpe`) after install, or the greeter cannot
+2 -3
View File
@@ -15,7 +15,7 @@ Headless `aarch64-linux` server with two roles:
```sh ```sh
nixos-generate-config --root /mnt nixos-generate-config --root /mnt
# copy /mnt/etc/nixos/hardware-configuration.nix over # copy /mnt/etc/nixos/hardware-configuration.nix over
# hosts/RPi5/hardware-configuration.nix in this repo, then commit # system/machine/RPi5/hardware-configuration.nix in this repo, then commit
``` ```
`hardware-configuration.nix` in this directory is a **placeholder** committed `hardware-configuration.nix` in this directory is a **placeholder** committed
only so the host evaluates in CI. The machine will not boot correctly until it only so the host evaluates in CI. The machine will not boot correctly until it
@@ -28,8 +28,7 @@ Headless `aarch64-linux` server with two roles:
nh os switch nh os switch
``` ```
4. Give the login user a password (`passwd lyrathorpe`) and confirm the key in 4. Give the login user a password (`passwd lyrathorpe`) and confirm the key in
the user registry (`../../users/registry.nix`, applied by `system/modules/ssh.nix` is the one you will connect with.
`../../modules/ssh.nix`) is the one you will connect with.
## Docker socket (security) ## Docker socket (security)
+1 -1
View File
@@ -35,7 +35,7 @@ change and `radeon` stays idle.
## Login ## Login
Graphical login via a Wayland greeter — `greetd` running ReGreet inside the Graphical login via a Wayland greeter — `greetd` running ReGreet inside the
`cage` kiosk compositor — configured centrally in `../../modules/sway.nix` for `cage` kiosk compositor — configured centrally in `lyrathorpe/swaywm.nix` for
every Sway host (gated on `features.swayDesktop.enable`). The greeter is forced every Sway host (gated on `features.swayDesktop.enable`). The greeter is forced
to the Dvorak layout to match the console and Sway session. Set the user to the Dvorak layout to match the console and Sway session. Set the user
password (`passwd lyrathorpe`) after install, or the greeter cannot password (`passwd lyrathorpe`) after install, or the greeter cannot
+130
View File
@@ -0,0 +1,130 @@
# Authentik LDAP authentication for NixOS hosts.
#
# Wires SSSD (System Security Services Daemon) to the Authentik LDAP outpost so
# every Linux host authenticates users against the same directory that backs the
# SSO stack. Enabled by default on every NixOS host via baseModules; the EDaaS
# WSL box opts out (services.authentikLdap.enable = false) because it is a
# work-managed Windows-hosted environment.
#
# The Authentik LDAP provider exposes NON-standard object classes/attributes
# (goauthentik.io/ldap/user, goauthentik.io/ldap/group) alongside the POSIX
# attributes (uid, uidNumber, gidNumber, homeDirectory), so the schema mappings
# below are explicit rather than relying on an RFC2307 default.
#
# The bind password is NOT inlined: services.sssd.config renders to the world-
# readable Nix store, so the credential is delivered out-of-band by agenix as an
# sssd.conf drop-in under /etc/sssd/conf.d/ (SSSD merges conf.d/*.conf after the
# main file). See secrets/README.md.
{
config,
lib,
...
}:
let
cfg = config.services.authentikLdap;
# Directory coordinates for the Authentik LDAP provider.
ldapUri = "ldaps://ldap.lyrapup.pet:636";
searchBase = "dc=ldap,dc=goauthentik,dc=io";
bindDn = "cn=sssd-bind,ou=users,dc=ldap,dc=goauthentik,dc=io";
in
{
options.services.authentikLdap.enable =
lib.mkEnableOption "SSSD authentication against the Authentik LDAP outpost"
// {
default = true;
};
config = lib.mkIf cfg.enable {
services.sssd = {
enable = true;
# Non-secret sssd.conf. The bind password is injected separately via the
# agenix conf.d drop-in (ldap_default_authtok lives there, not here) to
# keep it out of the Nix store.
config = ''
[sssd]
config_file_version = 2
services = nss, pam
domains = default
[nss]
# Do not walk the whole directory for `getent passwd` etc.
filter_users = root
filter_groups = root
[pam]
[domain/default]
# --- Providers --------------------------------------------------------
id_provider = ldap
auth_provider = ldap
chpass_provider = none
access_provider = permit
# --- Connection -------------------------------------------------------
ldap_uri = ${ldapUri}
ldap_search_base = ${searchBase}
ldap_default_bind_dn = ${bindDn}
ldap_default_authtok_type = password
# ldap_default_authtok is supplied by the agenix drop-in in conf.d.
# --- TLS (LDAPS on 636; no StartTLS) ---------------------------------
ldap_id_use_start_tls = false
ldap_tls_reqcert = demand
# --- Schema: Authentik LDAP provider ---------------------------------
# Authentik returns DN-valued group membership (member/memberOf), so
# rfc2307bis (not rfc2307) is the correct base schema.
ldap_schema = rfc2307bis
# Users: goauthentik.io/ldap/user, keyed by uid; POSIX attrs are
# standard names (uidNumber/gidNumber/homeDirectory).
ldap_user_object_class = goauthentik.io/ldap/user
ldap_user_name = uid
ldap_user_uid_number = uidNumber
ldap_user_gid_number = gidNumber
ldap_user_home_directory = homeDirectory
ldap_user_gecos = displayName
ldap_user_shell = loginShell
# Groups: goauthentik.io/ldap/group, keyed by cn.
ldap_group_object_class = goauthentik.io/ldap/group
ldap_group_name = cn
ldap_group_gid_number = gidNumber
ldap_group_member = member
# --- Behaviour --------------------------------------------------------
cache_credentials = true
enumerate = false
'';
};
# agenix delivers the bind password as an sssd.conf drop-in. The decrypted
# plaintext IS a valid conf.d snippet:
#
# [domain/default]
# ldap_default_authtok = <the bind password>
#
# SSSD requires conf.d files to be root-owned and 0600 or it ignores them.
age.secrets.ldap-bind = {
file = ../secrets/ldap-bind.age;
path = "/etc/sssd/conf.d/01-ldap-authtok.conf";
owner = "root";
group = "root";
mode = "0600";
};
# Restart SSSD when the credential drop-in changes. agenix writes secrets in
# a system activation script that runs before systemd (re)starts services on
# a `switch`, so the file is present by the time sssd starts; the trigger
# picks up rotations of the bind password.
systemd.services.sssd.restartTriggers = [ config.age.secrets.ldap-bind.path ];
# Create home directories on first login for LDAP users (they have no
# locally-provisioned home). NixOS wires nss + the SSSD PAM stack when
# services.sssd.enable is true; mkHomeDir adds pam_mkhomedir to it.
security.pam.services.login.makeHomeDir = true;
security.pam.services.sshd.makeHomeDir = true;
};
}
+92
View File
@@ -0,0 +1,92 @@
# Secrets (agenix)
Encrypted secrets for the fleet, managed with [agenix](https://github.com/ryantm/agenix).
Each secret is an age-encrypted file (`*.age`) encrypted to a set of recipient
public keys declared in [`secrets.nix`](./secrets.nix). A host decrypts its
secrets at activation using its SSH **host** key
(`/etc/ssh/ssh_host_ed25519_key`), so every host that must read a secret has to
be listed as a recipient for it.
`secrets.nix` is read only by the `agenix` CLI. It is never imported into the
NixOS evaluation.
## Secrets in this repo
| File | Purpose | Recipients |
| --------------- | ----------------------------------------------------------------------- | ----------------------------------- |
| `ldap-bind.age` | SSSD → Authentik LDAP bind credential, as an `sssd.conf` drop-in snippet | all SSSD-enabled hosts (not EDaaS) |
Consumed by [`modules/sssd.nix`](../modules/sssd.nix) via
`age.secrets.ldap-bind.path`, which places the decrypted snippet at
`/etc/sssd/conf.d/01-ldap-authtok.conf`.
> **`ldap-bind.age` is not committed yet.** Only `ldap-bind.age.PLACEHOLDER`
> ships in this change (real host recipient keys and the real password were not
> available when it was written). Follow the steps below to create the real
> secret, then delete the `.PLACEHOLDER`.
## Owner setup checklist
Run these once (per new host or when the bind password rotates):
### 1. Collect host recipient keys
On each SSSD-enabled host (all Linux hosts **except** EDaaS):
```sh
cat /etc/ssh/ssh_host_ed25519_key.pub
```
Paste each value into the matching placeholder in `secrets.nix`, replacing the
`AAAA_PLACEHOLDER_REPLACE_ME_*` strings. (Optionally uncomment and set `admin`
to an operator user key so the secret can be edited off-host.)
### 2. Encrypt the bind password
The plaintext must be a **full sssd.conf drop-in snippet**, because SSSD cannot
read `ldap_default_authtok` from a separate file — it only merges `conf.d/*.conf`.
The content is exactly:
```ini
[domain/default]
ldap_default_authtok = <the sssd-bind service-account password>
```
Use the password of the `sssd-bind` (Terraform: `sssd-bind`) Authentik LDAP
service account. Then, from the repo root:
```sh
# Requires the agenix CLI: `nix run github:ryantm/agenix -- -e secrets/ldap-bind.age`
cd secrets
agenix -e ldap-bind.age
```
An `$EDITOR` opens; paste the two-line snippet above, save, quit. agenix writes
the encrypted `ldap-bind.age`. Commit it and delete `ldap-bind.age.PLACEHOLDER`.
### 3. Rekey after changing recipients
If you add/remove hosts in `secrets.nix`, re-encrypt every secret to the new
recipient set:
```sh
cd secrets
agenix -r
```
### 4. DNS
`ldap.lyrapup.pet` must resolve to the Authentik LDAP outpost and serve LDAPS on
port 636 with a certificate the hosts trust (`ldap_tls_reqcert = demand`). If the
cert is not from a system-trusted CA, add it to the hosts' trust store
(`security.pki.certificateFiles`) or relax `ldap_tls_reqcert` in
`modules/sssd.nix`.
### 5. Rebuild
```sh
sudo nixos-rebuild switch --flake .#<host>
```
Verify with `getent passwd <ldap-user>` and `id <ldap-user>`.
+21
View File
@@ -0,0 +1,21 @@
THIS IS A PLACEHOLDER, NOT A REAL AGE SECRET.
The real secrets/ldap-bind.age is produced by the repo owner with `agenix -e`
(see secrets/README.md) and is a binary age-encrypted blob. It is intentionally
NOT committed here because:
* the real host age recipients are not available to the author of this change
(they are each host's /etc/ssh/ssh_host_ed25519_key.pub), and
* fabricating an encrypted blob or fake host keys would be misleading.
Committing this file as `ldap-bind.age` would let modules/sssd.nix reference
`../secrets/ldap-bind.age` and evaluate, but SSSD would fail to decrypt it at
runtime. Do ONE of the following before deploying:
1. Preferred: generate the real secret (secrets/README.md), commit it as
secrets/ldap-bind.age, and delete this .PLACEHOLDER file.
The decrypted plaintext must be a valid sssd.conf drop-in (NOT the bare
password):
[domain/default]
ldap_default_authtok = <the sssd-bind service-account password>
+15
View File
@@ -0,0 +1,15 @@
let
lyrathorpe-mbp = "ssh-ed25519 AAAA_PLACEHOLDER_REPLACE_ME_mbp";
lyrathorpe-t400 = "ssh-ed25519 AAAA_PLACEHOLDER_REPLACE_ME_t400";
lyrathorpe-macpro31 = "ssh-ed25519 AAAA_PLACEHOLDER_REPLACE_ME_macpro31";
lyrathorpe-rpi5 = "ssh-ed25519 AAAA_PLACEHOLDER_REPLACE_ME_rpi5";
sssdHosts = [
lyrathorpe-mbp
lyrathorpe-t400
lyrathorpe-macpro31
lyrathorpe-rpi5
];
in
{
"ldap-bind.age".publicKeys = sssdHosts;
}
-11
View File
@@ -51,17 +51,6 @@
home.shellAliases = { home.shellAliases = {
docker = "/run/current-system/sw/bin/docker"; docker = "/run/current-system/sw/bin/docker";
}; };
# Source the (nix-unmanaged) Jenkins credentials file into every zsh, so the
# JENKINS_UCE_/JENKINS_STF_ tokens are exported for all shells and anything they
# launch -- the Jenkins MCP servers read them via ${JENKINS_*} expansion.
# envExtra lands in ~/.zshenv, which zsh sources for login, interactive, and
# non-interactive shells alike. Guarded so a missing file never breaks a shell;
# the file holds secrets, so it is kept out of the world-readable nix store.
programs.zsh.envExtra = ''
[ -f "$HOME/.jenkinsenv" ] && . "$HOME/.jenkinsenv"
[ -f "$HOME/.splunkenv" ] && . "$HOME/.splunkenv"
'';
programs.tmux = { programs.tmux = {
# kube context/namespace in the status line. kube-tmux is pinned as a flake # kube context/namespace in the status line. kube-tmux is pinned as a flake
# input (it is not in nixpkgs), so the script is always present in the store. # input (it is not in nixpkgs), so the script is always present in the store.