Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1df7bec2d7 | ||
|
|
87318cd04d |
@@ -1,63 +0,0 @@
|
|||||||
# Working on this flake
|
|
||||||
|
|
||||||
Project notes for changes to this repository. Persona and memory rules live in
|
|
||||||
the user-global config; this file is about the flake's checks and conventions.
|
|
||||||
|
|
||||||
## Before you commit: run the formatter
|
|
||||||
|
|
||||||
Formatting and linting are driven by the flake. CI (`.gitea/workflows/ci.yaml`)
|
|
||||||
runs `nix flake check`, which fails the build if any file is unformatted or trips
|
|
||||||
a lint. From the repo root:
|
|
||||||
|
|
||||||
- `nix fmt` — format the whole tree (writes changes).
|
|
||||||
- `nix flake check` — run every check read-only (what CI runs).
|
|
||||||
- `nix develop` — dev shell; its `shellHook` installs the git pre-commit hooks so
|
|
||||||
the same gates run on `git commit`.
|
|
||||||
|
|
||||||
Never commit with `--no-verify`. A bypassed commit ships unformatted content and
|
|
||||||
turns CI red on the next push to `main` (see "Docs are checked too").
|
|
||||||
|
|
||||||
## What gets checked
|
|
||||||
|
|
||||||
Defined in `flake.nix` (the `treefmt`, `pre-commit`, and `checks` blocks) and
|
|
||||||
`statix.toml`:
|
|
||||||
|
|
||||||
| Check | Tool | Covers |
|
|
||||||
| ------------ | --------------------------------- | ------------------------------------------------------- |
|
|
||||||
| `formatting` | treefmt → `nixfmt` | all `*.nix` |
|
|
||||||
| `formatting` | treefmt → `shfmt` | shell scripts |
|
|
||||||
| `formatting` | treefmt → `prettier` | **Markdown, YAML, JSON** (incl. `README.md`, this file) |
|
|
||||||
| `deadnix` | deadnix | dead Nix bindings (`--no-lambda-pattern-names`) |
|
|
||||||
| `statix` | statix | Nix antipatterns (config in `statix.toml`) |
|
|
||||||
| pre-commit | nixfmt-rfc-style, deadnix, statix | the same gates, run on commit |
|
|
||||||
|
|
||||||
Excluded from formatting: `*/hardware-configuration.nix` (generated by
|
|
||||||
`nixos-generate-config`) and `flake.lock`. Editor defaults (indent, EOL, final
|
|
||||||
newline) are in `.editorconfig`; note Markdown keeps trailing whitespace, which
|
|
||||||
encodes hard line breaks.
|
|
||||||
|
|
||||||
## Docs are checked too — the common trap
|
|
||||||
|
|
||||||
prettier formats `*.md`, so **documentation edits must be run through `nix fmt`**
|
|
||||||
exactly like code. prettier re-aligns Markdown tables in particular; hand-editing
|
|
||||||
a table almost always leaves it non-conformant and fails the `formatting` check.
|
|
||||||
|
|
||||||
Beware a false green: the CI `detect` step skips the heavy checks on a pull
|
|
||||||
request that touches **no** `.nix`, `flake.lock`, or the workflow file — so a
|
|
||||||
docs-only PR reports success without ever running prettier. The failure then
|
|
||||||
surfaces on the push-to-`main` run (which always runs the full check) or on the
|
|
||||||
next unrelated PR that does touch Nix. Run `nix flake check` locally before
|
|
||||||
merging a docs change, regardless of what the PR check shows.
|
|
||||||
|
|
||||||
## Host evaluation
|
|
||||||
|
|
||||||
CI also evaluates every `nixosConfigurations` / `darwinConfigurations` host's
|
|
||||||
toplevel (eval only, no build) on an x86_64 runner, so eval errors fail cheaply.
|
|
||||||
Reproduce locally:
|
|
||||||
|
|
||||||
```sh
|
|
||||||
nix eval --raw ".#nixosConfigurations.<host>.config.system.build.toplevel.drvPath"
|
|
||||||
```
|
|
||||||
|
|
||||||
Host lists are discovered from the flake, so adding or removing a host needs no
|
|
||||||
change to the workflow.
|
|
||||||
@@ -55,17 +55,17 @@ module reaches a host: **baseModules** (every NixOS host, via `flake.nix`),
|
|||||||
**host table** (listed explicitly per host in `flake.nix`), or **transitively**
|
**host table** (listed explicitly per host in `flake.nix`), or **transitively**
|
||||||
(pulled in by another module's `imports`).
|
(pulled in by another module's `imports`).
|
||||||
|
|
||||||
| Module | Imported by | What it does / when to use it |
|
| Module | Imported by | What it does / when to use it |
|
||||||
| -------------------- | --------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
| ------------------ | --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
| `common-nixos.nix` | baseModules (all NixOS) | Timezone/locale, store hygiene (auto-optimise, big download buffer, **no** auto-GC), the nix-community binary cache, `nix-ld`, base CLI (`git`, `fastfetch`), and the fleet-wide font stack. |
|
| `common-nixos.nix` | baseModules (all NixOS) | Timezone/locale, store hygiene (auto-optimise, big download buffer, **no** auto-GC), the nix-community binary cache, `nix-ld`, base CLI (`git`, `fastfetch`), and the fleet-wide font stack. |
|
||||||
| `users.nix` | baseModules (all NixOS) | Builds `users.users` from the registry for the host's `hostUsers`; enables zsh; enables Firefox + Thunderbird **only** when `features.swayDesktop.enable` is on. Applies per-user `linger`. |
|
| `users.nix` | baseModules (all NixOS) | Builds `users.users` from the registry for the host's `hostUsers`; enables zsh; enables Firefox + Thunderbird **only** when `features.swayDesktop.enable` is on. Applies per-user `linger`. |
|
||||||
| `features.nix` | baseModules (all NixOS) | Declares feature-flag options (currently `features.swayDesktop.enable`) so any host can read/set them without importing the heavy implementation module. |
|
| `features.nix` | baseModules (all NixOS) | Declares feature-flag options (currently `features.swayDesktop.enable`) so any host can read/set them without importing the heavy implementation module. |
|
||||||
| `workstation.nix` | transitively (via laptop/desktop) | Form-factor-agnostic base for physical graphical hosts: turns on `swayDesktop`, Dvorak console, PipeWire, firewall (default-deny), fstrim, earlyoom, fwupd, thermald (x86), redistributable fw. |
|
| `workstation.nix` | transitively (via laptop/desktop) | Form-factor-agnostic base for physical graphical hosts: turns on `swayDesktop`, Dvorak console, PipeWire, firewall (default-deny), fstrim, earlyoom, fwupd, thermald (x86), redistributable fw. |
|
||||||
| `laptop.nix` | host table (MBP, T400) | `imports` workstation.nix, then adds the portable bits: iwd Wi-Fi, lid suspend/lock, Bluetooth + blueman. |
|
| `laptop.nix` | host table (MBP, T400) | `imports` workstation.nix, then adds the portable bits: iwd Wi-Fi, lid suspend/lock, Bluetooth + blueman. |
|
||||||
| `desktop.nix` | host table (Mac Pro) | `imports` workstation.nix, then swaps Wi-Fi for wired NetworkManager. Pair with `portable = false` in the host table. |
|
| `desktop.nix` | host table (Mac Pro) | `imports` workstation.nix, then swaps Wi-Fi for wired NetworkManager. Pair with `portable = false` in the host table. |
|
||||||
| `sway.nix` | host table (graphical hosts) | Implementation of `features.swayDesktop`: the system Sway package, the greetd/ReGreet (cage) greeter forced to Dvorak, xdg-portal, Wayland utility packages. Home-side Sway config is in `home/sway.nix`. |
|
| `sway.nix` | host table (graphical hosts) | Implementation of `features.swayDesktop`: the system Sway package, the greetd/ReGreet (cage) greeter forced to Dvorak, xdg-portal, Wayland utility packages. Home-side Sway config is in `home/sway.nix`. |
|
||||||
| `ssh.nix` | host table (T400, Mac Pro, RPi5) | Enables sshd, opens port 22, enforces a key-only policy (no password / keyboard-interactive, no root). Authorized keys come from the registry via `users.nix`. |
|
| `ssh.nix` | host table (T400, Mac Pro, RPi5) | Enables sshd, opens port 22, enforces a key-only policy (no password / keyboard-interactive, no root). Authorized keys come from the registry via `users.nix`. |
|
||||||
| `firmware/` | referenced by MBP host config | Committed Apple peripheral firmware blobs for the Asahi MBP (see "MacBook (Asahi) firmware"). |
|
| `firmware/` | referenced by MBP host config | Committed Apple peripheral firmware blobs for the Asahi MBP (see "MacBook (Asahi) firmware"). |
|
||||||
|
|
||||||
Form-factor decision: a **laptop** imports `laptop.nix` (default
|
Form-factor decision: a **laptop** imports `laptop.nix` (default
|
||||||
`portable = true`); a **wired desktop** imports `desktop.nix` and sets
|
`portable = true`); a **wired desktop** imports `desktop.nix` and sets
|
||||||
|
|||||||
@@ -9,4 +9,3 @@
|
|||||||
- [Review and comments workflow](workflow_review_and_comments.md) — show PR body and non-trivial Jira comments before posting; terse IaC code comments; PR body content rules
|
- [Review and comments workflow](workflow_review_and_comments.md) — show PR body and non-trivial Jira comments before posting; terse IaC code comments; PR body content rules
|
||||||
- [Sandbox prompts](feedback_sandbox_prompts.md) — don't prompt for sandbox-disable or routine read-only shell ops; broaden permissions instead
|
- [Sandbox prompts](feedback_sandbox_prompts.md) — don't prompt for sandbox-disable or routine read-only shell ops; broaden permissions instead
|
||||||
- [Dev clusters disposable](dev_clusters_disposable.md) — Lyra's dev clusters are recreatable; mutate/break freely, no confirmation needed
|
- [Dev clusters disposable](dev_clusters_disposable.md) — Lyra's dev clusters are recreatable; mutate/break freely, no confirmation needed
|
||||||
- [Nix shell tooling](nix_shell_tooling.md) — any nixpkgs tool runs ad hoc via `nix run`/`nix shell nixpkgs#<pkg>`; a missing command is never a dead end
|
|
||||||
|
|||||||
@@ -1,23 +0,0 @@
|
|||||||
---
|
|
||||||
name: nix-shell-tooling
|
|
||||||
description: "Any nixpkgs tool can be run ad hoc via nix run / nix shell — a missing command is never a dead end during development"
|
|
||||||
metadata:
|
|
||||||
node_type: memory
|
|
||||||
type: feedback
|
|
||||||
originSessionId: dfb56b58-518b-4daf-b531-7119bb4a9534
|
|
||||||
---
|
|
||||||
|
|
||||||
Any tool in nixpkgs can be run without installing it into the environment. If a
|
|
||||||
command is missing during development, pull it from nixpkgs on the fly instead
|
|
||||||
of working around its absence or reporting the tool as unavailable.
|
|
||||||
|
|
||||||
**Why:** Lyra runs NixOS; the ambient PATH is deliberately minimal, but the full
|
|
||||||
nixpkgs set is always one command away. "command not found" is not a blocker.
|
|
||||||
|
|
||||||
**How to apply:**
|
|
||||||
|
|
||||||
- One-off run: `nix run nixpkgs#<pkg> -- <args>` (e.g. `nix run nixpkgs#jq -- .`).
|
|
||||||
- Tools on PATH for a session: `nix shell nixpkgs#<pkg> [nixpkgs#<pkg2> ...]`,
|
|
||||||
then run commands normally.
|
|
||||||
- Legacy form also works: `nix-shell -p <pkg> --run '<cmd>'`.
|
|
||||||
- Prefer this over hand-rolling a substitute for a tool that exists in nixpkgs.
|
|
||||||
Reference in New Issue
Block a user