1 Commits
Author SHA1 Message Date
Renovate Bot 4715a24c80 chore(deps): lock file maintenance flake inputs
renovate/stability-days Updates have not met minimum release age requirement
CI / flake (pull_request) Failing after 1m47s
2026-06-29 11:02:10 +00:00
62 changed files with 223 additions and 332 deletions
+1 -1
View File
@@ -1,4 +1,4 @@
modules/firmware/*
system/modules/firmware/*
# vim swap files
*.swp
+20 -49
View File
@@ -7,51 +7,22 @@ single flake.
Defined in the host table in [`flake.nix`](./flake.nix):
| Configuration | System | Machine |
| --------------------- | ---------------- | ----------------------------------------------------------------------------------------------------------- |
| `lyrathorpe-mbp` | `aarch64-linux` | MacBook Pro (Apple Silicon, Asahi) |
| `lyrathorpe-t400` | `x86_64-linux` | ThinkPad T400 — [install notes](./hosts/T400/README.md) |
| `lyrathorpe-macpro31` | `x86_64-linux` | Mac Pro 3,1, desktop — [install notes](./hosts/MacPro31/README.md) |
| `emmathorpe-edaas` | `x86_64-linux` | Work WSL box (NixOS-WSL) |
| `lyrathorpe-rpi5` | `aarch64-linux` | Raspberry Pi 5 headless server: Docker host + nginx reverse proxy — [install notes](./hosts/RPi5/README.md) |
| `lyrathorpe-mac` | `aarch64-darwin` | macOS (nix-darwin) |
| Configuration | System | Machine |
| --------------------- | ---------------- | -------------------------------------------------------------------------------------------------------------------- |
| `lyrathorpe-mbp` | `aarch64-linux` | MacBook Pro (Apple Silicon, Asahi) |
| `lyrathorpe-t400` | `x86_64-linux` | ThinkPad T400 — [install notes](./system/machine/T400/README.md) |
| `lyrathorpe-macpro31` | `x86_64-linux` | Mac Pro 3,1, desktop — [install notes](./system/machine/MacPro31/README.md) |
| `emmathorpe-edaas` | `x86_64-linux` | Work WSL box (NixOS-WSL) |
| `lyrathorpe-rpi5` | `aarch64-linux` | Raspberry Pi 5 headless server: Docker host + nginx reverse proxy — [install notes](./system/machine/RPi5/README.md) |
| `lyrathorpe-mac` | `aarch64-darwin` | macOS (nix-darwin) |
Shared layers: `home` (home-manager: shell, git, editor),
`modules/common-nixos.nix` (all NixOS hosts: fonts, nix-ld, caches),
`modules/workstation.nix` (physical graphical hosts: audio, thermald,
earlyoom, fwupd), `modules/laptop.nix` (laptops: Wi-Fi, Bluetooth, power,
lid), and `modules/ssh.nix` (key-only sshd). The x86 hosts also pull
Shared layers: `lyrathorpe/home` (home-manager: shell, git, editor),
`system/modules/common-nixos.nix` (all NixOS hosts: fonts, nix-ld, caches),
`system/modules/workstation.nix` (physical graphical hosts: audio, thermald,
earlyoom, fwupd), `system/modules/laptop.nix` (laptops: Wi-Fi, Bluetooth, power,
lid), and `system/modules/ssh.nix` (key-only sshd). The x86 hosts also pull
`nixos-hardware` profiles.
## Users
Identity is data, kept separate from the reusable modules:
- [`users/registry.nix`](./users/registry.nix) — one entry per user (display
name, email, supplementary groups, authorized + signing keys). This is the
single source of identity; no user data is hardcoded in the modules.
- Each host's table entry declares a `users` set keyed by username; every entry
lists that user's home-module composition (the shared `./home` bundle plus any
per-user modules, e.g. [`users/emmathorpe/work.nix`](./users/emmathorpe/work.nix))
and optional per-host-user system bits such as `linger`.
- `mkHost` builds each account from the registry and injects the matching
identity into that user's home config as the `identity` module arg. A host can
therefore declare any number of users.
### Portable home (off-NixOS / external consumers)
The home config is also exposed for use beyond these hosts:
- `homeConfigurations."<user>@<system>"` — a standalone home-manager profile
(the portable subset: shell + git + editor + claude) that can be activated on a
machine this flake does **not** manage:
`home-manager switch --flake .#"lyrathorpe@x86_64-linux"`. The desktop/sway
modules are intentionally excluded (they rely on a NixOS-provided Sway/Firefox
binary).
- `homeModules` — the reusable modules exported so another flake can import them
(`inputs.<this>.homeModules.default`). Consumers must supply the module args
these expect: `inputs` always, `identity` for git/desktop, `portable` for sway.
## Applying
```sh
@@ -64,25 +35,25 @@ darwin-rebuild switch --flake .#lyrathorpe-mac
## Shell environment & keybindings
- Interactive shell features (zsh, tmux, git, ssh, CLI tools, auto-tmux):
[`home/README.md`](./home/README.md).
[`lyrathorpe/home/README.md`](./lyrathorpe/home/README.md).
- All Sway / tmux / foot / zsh keyboard shortcuts:
[`home/KEYBINDINGS.md`](./home/KEYBINDINGS.md).
[`lyrathorpe/home/KEYBINDINGS.md`](./lyrathorpe/home/KEYBINDINGS.md).
## Login / greeter
Graphical (Sway) hosts log in through a Wayland greeter — `greetd` running
ReGreet inside the `cage` kiosk compositor — implemented in
[`modules/sway.nix`](./modules/sway.nix), gated on
[`lyrathorpe/swaywm.nix`](./lyrathorpe/swaywm.nix), gated on
`features.swayDesktop.enable` (the option is declared in
[`modules/features.nix`](./modules/features.nix), so headless hosts
can leave it off without importing `modules/sway.nix`). The greeter is forced to Dvorak
[`system/modules/features.nix`](./system/modules/features.nix), so headless hosts
can leave it off without importing `swaywm.nix`). The greeter is forced to Dvorak
to match the console and Sway session. Headless hosts (the WSL work box and the
Raspberry Pi server) keep plain TTY login. The target account needs a password
(`passwd <user>`) before it can log in.
## MacBook (Asahi) firmware
The MBP host references `modules/firmware/` for Apple peripheral
The MBP host references `system/modules/firmware/` for Apple peripheral
firmware (Wi-Fi/Bluetooth). These blobs are **committed** (tracked) even though
`.gitignore` lists the directory: the flake is `git+file`, so it only sees
tracked files — untracking them breaks `lyrathorpe-mbp` evaluation (and the CI
@@ -92,7 +63,7 @@ redistributable; the repo is private.
To refresh them, copy the firmware extracted during the Asahi install (from
`/etc/nixos/firmware`, or re-extract per the
[Asahi NixOS docs](https://github.com/tpwrules/nixos-apple-silicon)) into
`modules/firmware/` and commit with `git add -f`.
`system/modules/firmware/` and commit with `git add -f`.
## Development
Generated
+3 -3
View File
@@ -258,11 +258,11 @@
]
},
"locked": {
"lastModified": 1782734462,
"narHash": "sha256-0HguXu/4KDgCL1mehqwhQXD96hbR85HS+o0zh73E8AQ=",
"lastModified": 1782374867,
"narHash": "sha256-wgU8MdUzSH2ccq85xo80pP1PAFW+e5kzx6rofVO1Jsk=",
"owner": "nix-community",
"repo": "nixos-apple-silicon",
"rev": "12e3b92363d21fcc550b500370d73a0747484e43",
"rev": "bf99497876c07bb945d5fc536916cdee4f3b9eb6",
"type": "github"
},
"original": {
+78 -130
View File
@@ -23,7 +23,7 @@
# Provides mkFlake: the systems/perSystem scaffolding used below.
flake-parts.url = "github:hercules-ci/flake-parts";
flake-parts.inputs.nixpkgs-lib.follows = "nixpkgs";
# Declarative Firefox add-ons (e.g. the Catppuccin theme); see modules/users.nix.
# Declarative Firefox add-ons (e.g. the Catppuccin theme); see lyrathorpe/user.nix.
firefox-addons = {
url = "gitlab:rycee/nur-expressions?dir=pkgs/firefox-addons";
inputs.nixpkgs.follows = "nixpkgs";
@@ -46,7 +46,7 @@
url = "github:cachix/git-hooks.nix";
inputs.nixpkgs.follows = "nixpkgs";
};
# Declarative Neovim (the editor; see home/editor.nix). Release
# Declarative Neovim (the editor; see lyrathorpe/home/editor.nix). Release
# branch matched to the pinned nixpkgs (26.05); follows our nixpkgs to keep a
# single nixpkgs in the closure. editor.nix sets programs.nixvim.nixpkgs.source
# to this same input so the home module doesn't warn about the pin.
@@ -97,9 +97,6 @@
"lens-desktop"
];
# Per-user identity, keyed by username. See README "Users".
userRegistry = import ./users/registry.nix;
# nixpkgs + nix-daemon settings shared by NixOS and Darwin hosts.
commonModule = {
nixpkgs.overlays = overlays;
@@ -115,9 +112,9 @@
# Shared scaffolding for every NixOS host: common user, settings, home-manager.
baseModules = [
./modules/users.nix
./modules/common-nixos.nix
./modules/features.nix
./lyrathorpe/user.nix
./system/modules/common-nixos.nix
./system/modules/features.nix
commonModule
home-manager.nixosModules.home-manager
{
@@ -129,13 +126,18 @@
}
];
# Build one NixOS host. `users` is an attrset keyed by username (home
# modules + optional per-user system bits). See README "Users".
# mkHost :: { system, username, fullName, modules, homeModules } -> nixosSystem
# Builds one machine by appending its host-specific modules to the shared
# baseModules. The user identity (username/fullName) is threaded through
# specialArgs so user.nix and the home modules stay host-agnostic, and the
# home-manager profile is keyed by the host's username.
mkHost =
{
system,
username,
fullName,
modules,
users,
homeModules,
# Host form factor. Laptops inherit the default; a desktop host sets
# `portable = false` to drop mobile components (battery block,
# brightness keys) from the home-manager Sway config.
@@ -146,7 +148,8 @@
specialArgs = {
inherit
inputs
userRegistry
username
fullName
portable
;
};
@@ -154,15 +157,16 @@
baseModules
++ modules
++ [
{ _module.args.hostUsers = users; }
{
home-manager.extraSpecialArgs = { inherit inputs portable; };
home-manager.users = lib.mapAttrs (name: spec: {
imports = spec.homeModules;
_module.args.identity = userRegistry.${name} // {
username = name;
};
}) users;
home-manager.extraSpecialArgs = {
inherit
inputs
username
fullName
portable
;
};
home-manager.users.${username}.imports = homeModules;
}
];
};
@@ -181,17 +185,19 @@
}
];
# Darwin counterpart of mkHost: single-user (macOS owns the account),
# identity still from the registry. See README "Users".
# mkDarwinHost :: { system, username, fullName, modules, homeModules } -> darwinSystem
# Darwin counterpart of mkHost. macOS already owns the login user, so we
# only attach the platform and home-manager; no NixOS user module here.
mkDarwinHost =
{
system,
username,
fullName,
modules,
homeModules,
}:
nix-darwin.lib.darwinSystem {
specialArgs = { inherit inputs username; };
specialArgs = { inherit inputs username fullName; };
modules =
darwinBaseModules
++ modules
@@ -200,41 +206,40 @@
nixpkgs.hostPlatform = system;
# macOS owns the account; point home-manager at its home dir.
users.users.${username}.home = "/Users/${username}";
home-manager.extraSpecialArgs = { inherit inputs; };
home-manager.users.${username} = {
imports = homeModules;
_module.args.identity = userRegistry.${username} // {
inherit username;
};
};
home-manager.extraSpecialArgs = { inherit inputs username fullName; };
home-manager.users.${username}.imports = homeModules;
}
];
};
# Host table — one entry per machine, realised into a nixosConfiguration
# of the same name below. See README "Hosts" / "Users".
# Host table — declarative registry of every machine. To add a host:
# give it a name, its `system`, the owning user, and the module lists.
# mapAttrs below turns each entry into a nixosConfiguration of the same name.
hosts = {
lyrathorpe-mbp = {
system = "aarch64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
modules = [
./hosts/MBP-Asahi/configuration.nix
./modules/laptop.nix
./system/machine/MBP-Asahi/configuration.nix
./system/modules/laptop.nix
nixos-apple-silicon.nixosModules.default
./modules/sway.nix
./lyrathorpe/swaywm.nix
];
users.lyrathorpe.homeModules = [
./home
./users/lyrathorpe/home.nix
./home/desktop.nix
homeModules = [
./lyrathorpe/home
./lyrathorpe/home/desktop.nix
];
};
lyrathorpe-t400 = {
system = "x86_64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
modules = [
./hosts/T400/configuration.nix
./modules/laptop.nix
./modules/ssh.nix
./system/machine/T400/configuration.nix
./system/modules/laptop.nix
./system/modules/ssh.nix
# No t400-specific profile exists; compose the generic ThinkPad +
# laptop/SSD/Intel building blocks (tp_smapi/acpi_call for battery
# thresholds, SSD + microcode defaults).
@@ -242,82 +247,78 @@
inputs.nixos-hardware.nixosModules.common-pc-laptop
inputs.nixos-hardware.nixosModules.common-pc-laptop-ssd
inputs.nixos-hardware.nixosModules.common-cpu-intel
./modules/sway.nix
./lyrathorpe/swaywm.nix
];
users.lyrathorpe.homeModules = [
./home
./users/lyrathorpe/home.nix
./home/desktop.nix
homeModules = [
./lyrathorpe/home
./lyrathorpe/home/desktop.nix
];
};
lyrathorpe-macpro31 = {
system = "x86_64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
portable = false;
modules = [
./hosts/MacPro31/configuration.nix
./modules/desktop.nix
./modules/ssh.nix
./system/machine/MacPro31/configuration.nix
./system/modules/desktop.nix
./system/modules/ssh.nix
inputs.nixos-hardware.nixosModules.common-pc-ssd
inputs.nixos-hardware.nixosModules.common-cpu-intel
./modules/sway.nix
./lyrathorpe/swaywm.nix
];
users.lyrathorpe.homeModules = [
./home
./users/lyrathorpe/home.nix
./home/desktop.nix
homeModules = [
./lyrathorpe/home
./lyrathorpe/home/desktop.nix
];
};
emmathorpe-edaas = {
system = "x86_64-linux";
username = "emmathorpe";
fullName = "Emma Thorpe";
modules = [
./hosts/EDaaS/configuration.nix
./system/machine/EDaaS/configuration.nix
nixos-wsl.nixosModules.default
./modules/sway.nix
./lyrathorpe/swaywm.nix
];
homeModules = [
./lyrathorpe/home
./lyrathorpe/home/work.nix
];
users.emmathorpe = {
homeModules = [
./home
./users/emmathorpe/work.nix
];
# Keep the systemd --user instance alive without a login session so
# the renovate-review home timer fires on schedule.
linger = true;
};
};
lyrathorpe-rpi5 = {
system = "aarch64-linux";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
portable = false;
# Headless server: Docker host + nginx reverse proxy. No sway.nix
# Headless server: Docker host + nginx reverse proxy. No swaywm.nix
# (no desktop); the raspberry-pi-5 profile supplies kernel/firmware,
# ssh.nix adds key-only sshd.
modules = [
./hosts/RPi5/configuration.nix
./system/machine/RPi5/configuration.nix
inputs.nixos-hardware.nixosModules.raspberry-pi-5
./modules/ssh.nix
];
users.lyrathorpe.homeModules = [
./home
./users/lyrathorpe/home.nix
./system/modules/ssh.nix
];
homeModules = [ ./lyrathorpe/home ];
};
};
# Darwin host table — macOS machines built via mkDarwinHost. The shared
# ./home bundle (shell, git, editor) is reused directly; the Linux-only
# ./lyrathorpe/home modules (shell, git, editor) are reused; the Linux-only
# desktop/sway modules are intentionally left out.
darwinHosts = {
lyrathorpe-mac = {
system = "aarch64-darwin";
username = "lyrathorpe";
fullName = "Lyra Thorpe";
modules = [
./hosts/Darwin/configuration.nix
./system/machine/Darwin/configuration.nix
];
homeModules = [
./home
./users/lyrathorpe/home.nix
./lyrathorpe/home
];
};
};
@@ -408,59 +409,6 @@
# Realise the host tables: each entry becomes a {nixos,darwin}Configuration.
flake.nixosConfigurations = lib.mapAttrs (_name: mkHost) hosts;
flake.darwinConfigurations = lib.mapAttrs (_name: mkDarwinHost) darwinHosts;
# Reusable home modules, exported for use off these hosts. See README
# "Portable home" for the consumer module-arg expectations.
flake.homeModules = {
default = ./home;
shell = ./home/shell.nix;
git = ./home/git.nix;
editor = ./home/editor.nix;
claude = ./home/claude.nix;
desktop = ./home/desktop.nix;
sway = ./home/sway.nix;
};
# Standalone home-manager configs (portable bundle) for machines not
# managed by this flake. See README "Portable home".
flake.homeConfigurations =
let
mkHome =
{
system,
name,
}:
home-manager.lib.homeManagerConfiguration {
pkgs = import nixpkgs {
inherit system overlays;
config.allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) unfreePackages;
};
extraSpecialArgs = {
inherit inputs;
portable = true;
identity = userRegistry.${name} // {
username = name;
};
};
modules = [
./home
{
home.username = name;
home.homeDirectory = "/home/${name}";
}
];
};
in
{
"lyrathorpe@x86_64-linux" = mkHome {
system = "x86_64-linux";
name = "lyrathorpe";
};
"lyrathorpe@aarch64-linux" = mkHome {
system = "aarch64-linux";
name = "lyrathorpe";
};
};
}
);
}
@@ -1,6 +1,6 @@
# Catppuccin Mocha palette. Raw 6-digit hex (no leading "#"); consumers add a
# "#" where their format needs it. Shared by the Sway desktop theming
# (home/sway.nix) and the ReGreet greeter (modules/sway.nix) so the two stay in sync.
# (home/sway.nix) and the ReGreet greeter (swaywm.nix) so the two stay in sync.
{
base = "1e1e2e";
mantle = "181825";
+14 -16
View File
@@ -15,10 +15,8 @@ Keyboard shortcuts have their own reference: [`KEYBINDINGS.md`](./KEYBINDINGS.md
| GUI apps, GTK/Firefox theming, cursor | [`desktop.nix`](./desktop.nix) (graphical hosts only) |
Shared by every host via [`default.nix`](./default.nix); the work box also layers
[`work.nix`](../users/emmathorpe/work.nix) on top (its own ssh config, extra
packages, and the C#/Helm language servers). The committer identity (name, email,
signing key) comes from the user registry
([`../users/registry.nix`](../users/registry.nix)), not this module.
[`work.nix`](./work.nix) on top (work email, its own ssh config, extra packages,
and the C#/Helm language servers).
---
@@ -57,7 +55,7 @@ signing key) comes from the user registry
| `hyperfine` / `sd` | command-line benchmarking; saner find-and-replace than sed |
**Theming:** `fzf`, `bat`, `btop`, `lazygit` and `git`'s `delta` pager are all
Catppuccin Mocha, driven from the shared `../lib/catppuccin-mocha.nix` palette / the
Catppuccin Mocha, driven from the shared `../catppuccin-mocha.nix` palette / the
catppuccin upstream themes.
**Env & defaults:** `xdg.enable` on; `PAGER`/`MANPAGER` (bat) set in `default.nix`
@@ -149,17 +147,17 @@ current (`gc`/`fetch.writeCommitGraph`) so `lg` stays fast.
| `lg` | graph log, all branches |
| `cz` `cc` | `git cz <sub>` (e.g. `git cz c`) and `git cc` → commitizen prompt |
| Behaviour | |
| -------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Pulls | rebase, with autostash + autosquash |
| Fetch | prune deleted remote branches |
| Conflicts | `zdiff3` (shows the common ancestor) |
| Diffs | histogram algorithm, colour-moved |
| `rerere` | remembers + replays conflict resolutions |
| Commit editor | full diff shown (`commit.verbose`) |
| Misc | branches sorted by date, `column.ui = auto`, `help.autocorrect = prompt`, `push.autoSetupRemote` |
| Global ignores | `result`, `result-*`, `.direnv`, `*.swp`, `.DS_Store` |
| Signing | SSH commit + tag signing (`mkDefault`, so a host without the key in its agent can disable it). Name, email and signing key all come from the per-user `identity` (the user registry, `../users/registry.nix`). |
| Behaviour | |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Pulls | rebase, with autostash + autosquash |
| Fetch | prune deleted remote branches |
| Conflicts | `zdiff3` (shows the common ancestor) |
| Diffs | histogram algorithm, colour-moved |
| `rerere` | remembers + replays conflict resolutions |
| Commit editor | full diff shown (`commit.verbose`) |
| Misc | branches sorted by date, `column.ui = auto`, `help.autocorrect = prompt`, `push.autoSetupRemote` |
| Global ignores | `result`, `result-*`, `.direnv`, `*.swp`, `.DS_Store` |
| Signing | SSH commit + tag signing (`mkDefault`, so a host without the key in its agent can disable it). Personal email `iam@emmathe.dev`; the work box overrides email + signing. |
## ssh
@@ -1,13 +1,12 @@
# Graphical desktop layer: GUI apps, Wayland session env, and cursor theme.
# Imported only on hosts that run Sway (MBP, T400, Mac Pro); never pulled onto
# the headless WSL host. Login (and the Sway session launch) is handled by the
# greetd/ReGreet greeter -- see ../modules/sway.nix -- so there is no tty1
# autostart.
# greetd/ReGreet greeter -- see ../swaywm.nix -- so there is no tty1 autostart.
{
pkgs,
config,
inputs,
identity,
username,
...
}:
{
@@ -90,7 +89,7 @@
};
# Firefox is themed at the browser level (it does not follow the GTK theme).
# The system installs the binary (programs.firefox in ../modules/users.nix); here
# The system installs the binary (programs.firefox in ../user.nix); here
# home-manager owns only the profile, hence package = null. Apply the
# Catppuccin Mocha theme add-on (only the mauve accent is packaged upstream;
# the rest of the desktop uses blue) and make content + UI dark.
@@ -102,7 +101,7 @@
# stateVersion<26.05 default-change warning (the new XDG path depends on
# Firefox's own profile support).
configPath = ".mozilla/firefox";
profiles.${identity.username} = {
profiles.${username} = {
id = 0;
isDefault = true;
extensions = {
+15 -10
View File
@@ -1,13 +1,13 @@
# Version control: git + delta + commitizen + lazygit. Committer identity comes
# from the per-user `identity` arg (the registry). See README "Users".
# Version control: git + delta pager + commitizen + lazygit. The work host
# layers commit signing and an email override on top (see work.nix).
{
pkgs,
lib,
identity,
fullName,
...
}:
let
ctp = import ../lib/catppuccin-mocha.nix;
ctp = import ../catppuccin-mocha.nix;
in
{
home.packages = [
@@ -18,9 +18,10 @@ in
enable = true;
package = pkgs.gitFull;
settings = {
user.name = identity.fullName;
# mkDefault so a host-specific module can still override it.
user.email = lib.mkDefault identity.email;
user.name = fullName;
# Personal identity. mkDefault so the work module overrides it on the work
# host (and to merge cleanly with that plain definition there).
user.email = lib.mkDefault "iam@emmathe.dev";
push.autoSetupRemote = true;
init.defaultBranch = "main";
@@ -76,10 +77,14 @@ in
cc = "!cz commit";
};
# SSH signing, key from the registry. mkDefault so a host lacking the key
# in its agent can set gpgsign = false instead of failing every commit.
# SSH commit signing. This personal key is the default; the work module
# (work.nix) overrides it with the work key on the EDaaS host, the same way
# user.email is overridden -- so mkDefault here lets that plain definition
# win instead of conflicting. gpgsign is mkDefault too, so a host without
# the key in its ssh-agent can override it to false rather than fail every
# commit.
gpg.format = "ssh";
user.signingkey = lib.mkDefault identity.signingKey;
user.signingkey = lib.mkDefault "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA";
commit.gpgsign = lib.mkDefault true;
tag.gpgsign = lib.mkDefault true;
};
+4 -1
View File
@@ -8,7 +8,7 @@
}:
let
# Shared Catppuccin Mocha palette: raw 6-hex strings, no leading "#".
ctp = import ../lib/catppuccin-mocha.nix;
ctp = import ../catppuccin-mocha.nix;
in
{
imports = [
@@ -341,6 +341,9 @@ in
IdentityFile = "~/.ssh/code.emmathe.dev";
IdentitiesOnly = true;
};
"dockerpi.inf.cbg.emmaisvery.gay" = {
User = "emmathorpe";
};
};
};
+6 -5
View File
@@ -2,7 +2,7 @@
# Imported via ./desktop.nix, so only graphical hosts get it.
#
# The compositor binary, PAM and the polkit *daemon* come from the system-level
# programs.sway (see ../modules/sway.nix); package = null below reuses it instead of
# programs.sway (see ../swaywm.nix); package = null below reuses it instead of
# pulling a second Sway. The polkit authentication *agent* (the thing that draws
# the GUI auth dialog) is a user service started here. home-manager owns the user
# config (~/.config/sway) and wires the systemd user session (sway-session.target),
@@ -20,7 +20,7 @@ let
# Catppuccin Mocha (shared with the ReGreet greeter). Raw hex; prefix "#"
# where a consumer needs it -- Sway/i3status/dunst want "#", foot/swaylock do
# not.
ctp = import ../lib/catppuccin-mocha.nix;
ctp = import ../catppuccin-mocha.nix;
# Focused-window screenshot -> swappy editor (the dotfiles' grimshot.sh logic).
# Full store paths so it needs nothing on PATH.
@@ -334,12 +334,13 @@ in
];
};
# Night light. Manual location (no geoclue dependency); warmer at night,
# neutral by day. Coordinates come from the per-user module (e.g.
# users/lyrathorpe/home.nix), not this shared module.
# Night light. Manual location (no geoclue dependency); adjust the coordinates
# to taste. Warmer at night, neutral by day.
services.gammastep = {
enable = true;
provider = "manual";
latitude = 51.5;
longitude = -0.13; # London-ish; set to your actual location
temperature = {
day = 6500;
night = 3700;
@@ -1,5 +1,5 @@
# Work (EDaaS/WSL) home profile: corporate toolchain + tmux tweaks. Git identity
# comes from the registry (users/registry.nix), not here.
# Home-manager module for the work (EDaaS/WSL) profile: corporate git signing,
# work toolchain packages and tmux tweaks. Imported only by the work host.
{ pkgs, lib, ... }:
{
@@ -12,6 +12,15 @@
# programs.ssh (shell.nix) take it over. The ssh-agent below still runs.
programs.ssh.enable = lib.mkForce false;
programs.git = {
settings = {
commit.gpgsign = true;
tag.gpgsign = true;
gpg.format = "ssh";
user.signingkey = "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAJMVgeRKnfX1G8coU3nAobI485aeUpGTMqH7+zbKI8o emma.thorpe@cloud.com";
user.email = "emma.thorpe@citrix.com";
};
};
home.packages = [
pkgs.kubectl
pkgs.argo-rollouts
@@ -57,7 +66,7 @@
};
# LSP servers only relevant to work: C# (omnisharp) and Helm charts (helm_ls).
# The shared editor (home/editor.nix) carries the universal ones;
# The shared editor (lyrathorpe/home/editor.nix) carries the universal ones;
# these are gated to this host so the heavy omnisharp closure stays off the
# personal machines. Tree-sitter grammars (highlighting) remain global there.
programs.nixvim.plugins.lsp.servers = {
+2 -2
View File
@@ -7,8 +7,8 @@
let
cfg = config.features.swayDesktop;
# Catppuccin Mocha (shared with the Sway desktop, see home/sway.nix).
ctp = import ../lib/catppuccin-mocha.nix;
# Catppuccin Mocha (shared with the Sway desktop, see lyrathorpe/home/sway.nix).
ctp = import ./catppuccin-mocha.nix;
in
{
# The features.swayDesktop.enable option is declared in
+31
View File
@@ -0,0 +1,31 @@
{
config,
pkgs,
lib,
username,
fullName,
...
}:
{
programs.zsh.enable = true;
users.users.${username} = {
isNormalUser = true;
home = "/home/${username}";
description = fullName;
extraGroups = [
"wheel"
"docker"
];
openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA"
];
shell = pkgs.zsh;
};
programs.firefox = lib.mkIf (config.features.swayDesktop.enable == true) {
enable = true;
};
programs.thunderbird = lib.mkIf (config.features.swayDesktop.enable == true) {
enable = true;
};
}
-11
View File
@@ -1,11 +0,0 @@
# Key-only sshd hardening, imported by hosts that run sshd (T400, Mac Pro,
# RPi5). Authorized keys are owned per-user by the registry (modules/users.nix),
# not here.
{ ... }:
{
services.openssh.settings = {
PasswordAuthentication = false; # keys only
KbdInteractiveAuthentication = false; # no keyboard-interactive fallback
PermitRootLogin = "no";
};
}
-38
View File
@@ -1,38 +0,0 @@
# System user accounts, built from the registry (users/registry.nix) for the
# host's `hostUsers` set. See README "Users".
{
config,
pkgs,
lib,
hostUsers,
userRegistry,
...
}:
{
programs.zsh.enable = true;
users.users = lib.mapAttrs (
name: spec:
let
id = userRegistry.${name};
in
{
isNormalUser = true;
home = "/home/${name}";
description = id.fullName;
inherit (id) extraGroups;
openssh.authorizedKeys.keys = id.sshAuthorizedKeys;
shell = pkgs.zsh;
}
# linger opt-in (host table); left unmanaged when unset.
// lib.optionalAttrs (spec ? linger) { inherit (spec) linger; }
) hostUsers;
programs.firefox = lib.mkIf (config.features.swayDesktop.enable == true) {
enable = true;
};
programs.thunderbird = lib.mkIf (config.features.swayDesktop.enable == true) {
enable = true;
};
}
@@ -1,5 +1,5 @@
# Default nix-darwin host. Minimal macOS baseline; the user environment
# (shell, git, editor) is carried by the shared ./home modules,
# (shell, git, editor) is carried by the shared ./lyrathorpe/home modules,
# the same ones used by the Linux hosts. nixpkgs.hostPlatform is set by
# mkDarwinHost in flake.nix.
{ pkgs, username, ... }:
@@ -62,11 +62,12 @@
features.swayDesktop.enable = false;
# NOTE: this user's systemd --user lingering -- so the home-manager renovate
# timer fires without an open login session -- is enabled from the host table
# in flake.nix (users.emmathorpe.linger = true) and applied by
# modules/users.nix.
# Keep this user's systemd --user instance running without an open login
# session, so the home-manager user timer (renovate-review.nix) fires on
# schedule even when no terminal is attached. On WSL the timer still only runs
# while the distro itself is up; Persistent=true catches up a missed run at
# next start.
users.users.emmathorpe.linger = true;
# programs.nix-ld is enabled for all NixOS hosts in common-nixos.nix.
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions
@@ -42,7 +42,7 @@
# - ATI Radeon HD 2600 XT -> "radeon" (older) or "amdgpu" KMS
# - NVIDIA GeForce 8800 GT -> "nouveau" KMS
# These come up automatically via the in-tree drivers + KMS, and the graphics
# stack itself is enabled by modules/sway.nix. If a card needs to be forced, add it
# stack itself is enabled by swaywm.nix. If a card needs to be forced, add it
# here, e.g. `services.xserver.videoDrivers = [ "radeon" ];` (or "nouveau"),
# and/or `boot.initrd.kernelModules = [ "radeon" ];` in
# hardware-configuration.nix for early KMS.
@@ -15,7 +15,7 @@
# (which selects by the local hostname) resolves without an explicit -H flag.
networking.hostName = "lyrathorpe-rpi5";
# Headless server: the Sway desktop is intentionally not set up. modules/sway.nix is
# Headless server: the Sway desktop is intentionally not set up. swaywm.nix is
# not imported and features.swayDesktop.enable defaults to false (declared in
# system/modules/features.nix), so this host keeps plain TTY/SSH login.
@@ -2,7 +2,7 @@
# shared ./workstation.nix base and swaps the mobile Wi-Fi backend for wired
# NetworkManager. A desktop host also sets `portable = false` in its host-table
# entry (flake.nix), which drops the battery block and brightness keybindings
# from the Sway bar -- see home/sway.nix.
# from the Sway bar -- see lyrathorpe/home/sway.nix.
{ ... }:
{
imports = [ ./workstation.nix ];
@@ -2,9 +2,9 @@
# baseModules in flake.nix). Declaring the flags here -- rather than inside the
# module that implements them -- means a host can read or set a flag without
# importing the (often large) implementation module. In particular,
# features.swayDesktop.enable is read by modules/users.nix on every host, but a
# features.swayDesktop.enable is read by lyrathorpe/user.nix on every host, but a
# headless host (e.g. the Pi) must be able to leave it at its default without
# pulling in modules/sway.nix. The implementation lives in modules/sway.nix,
# pulling in lyrathorpe/swaywm.nix. The implementation lives in swaywm.nix,
# gated on this flag.
{ lib, ... }:
{
@@ -2,7 +2,7 @@
# flake.nix. Shared graphical-workstation settings live in ./workstation.nix;
# the only laptop-specific bit is the Wi-Fi backend. Mobile home-manager
# components (battery block, brightness keys) are gated by the `portable` flag
# threaded through mkHost -- see home/sway.nix.
# threaded through mkHost -- see lyrathorpe/home/sway.nix.
{ ... }:
{
imports = [ ./workstation.nix ];
+19
View File
@@ -0,0 +1,19 @@
# Key-only SSH hardening, imported by the hosts that run sshd (T400, Mac Pro).
# The host config still does `services.openssh.enable = true` and opens port 22
# next to where it documents the listening service; this module only tightens
# the policy and installs the authorized key, so a host opting into sshd cannot
# accidentally ship password/root login.
{ username, ... }:
{
services.openssh.settings = {
PasswordAuthentication = false; # keys only
KbdInteractiveAuthentication = false; # no keyboard-interactive fallback
PermitRootLogin = "no";
};
# The key permitted to log in as the primary user. Add more entries here as
# new client machines are provisioned.
users.users.${username}.openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA"
];
}
-17
View File
@@ -1,17 +0,0 @@
# Lyra's personal home extras, imported on her hosts (not the work box). Keeps
# personal data out of the shared home/ modules. See README "Users".
{ pkgs, lib, ... }:
{
# Personal ssh host shortcut.
programs.ssh.settings."dockerpi.inf.cbg.emmaisvery.gay" = {
User = "emmathorpe";
};
# Night-light location for gammastep (the service itself is enabled by
# home/sway.nix on graphical hosts). Linux-guarded so Darwin, which imports
# this module but has no gammastep, skips it.
services.gammastep = lib.mkIf pkgs.stdenv.hostPlatform.isLinux {
latitude = 51.5;
longitude = -0.13;
};
}
-28
View File
@@ -1,28 +0,0 @@
# User identity registry -- pure data, keyed by username. See README "Users".
# (`identity.username` is injected by mkHost, so it is not repeated here.)
{
lyrathorpe = {
fullName = "Lyra Thorpe";
email = "iam@emmathe.dev";
extraGroups = [
"wheel"
"docker"
];
sshAuthorizedKeys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA"
];
signingKey = "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA";
};
emmathorpe = {
fullName = "Emma Thorpe";
email = "emma.thorpe@citrix.com";
extraGroups = [
"wheel"
"docker"
];
# No personal key on file yet; add one if SSH login as emmathorpe is wanted.
sshAuthorizedKeys = [ ];
signingKey = "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAJMVgeRKnfX1G8coU3nAobI485aeUpGTMqH7+zbKI8o emma.thorpe@cloud.com";
};
}