Files
nixfiles/hosts/MacPro31/README.md
lyrathorpeandEmma Thorpe 128deca2e3
CI / flake (push) Successful in 3m26s
refactor(flake): user registry, multi-user hosts, and portable home outputs (#49)
## Summary

Separates user identity (data) from the reusable Nix modules and lets a host declare any number of users, replacing the previous one-user-per-host structure. Also restructures the tree and exposes the home config for use off these hosts.

## Changes

- **User registry** (`users/registry.nix`): per-user identity (name, email, groups, authorized + signing keys) as the single source of truth; no user data hardcoded in modules.
- **Multi-user `mkHost`**: a host declares a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg.
- **Restructured layout**: `users/`, `home/`, `modules/`, `hosts/`, `lib/` replace the former `lyrathorpe/` and `system/` trees.
- **Portable outputs**: standalone `homeConfigurations."<user>@<system>"` (the portable subset — shell, git, editor, claude) plus an exported `homeModules` for use on machines not managed by this flake, or as an input to other flakes.
- Docs (`README.md`, `home/README.md`) and `.gitignore` updated for the new paths.

## Fixes

- Closes #46 — shared user module authorized one user's SSH key for every account.
- Closes #47 — git committer identity hardcoded as defaults instead of per-user.
- Closes #48 — EDaaS systemd linger hardcoded to a literal username.

## Verification

- `nix flake check` passes: treefmt, deadnix, statix, pre-commit, and evaluation of all NixOS hosts + Darwin + homeConfigurations.
- Derivation-path comparison vs `main`: `lyrathorpe-mbp` and `emmathorpe-edaas` are byte-identical; `lyrathorpe-t400`, `lyrathorpe-macpro31` and `lyrathorpe-rpi5` differ only by de-duplicating a repeated `authorized_keys` entry (confirmed with nix-diff — no other change).
- Standalone `homeConfigurations."lyrathorpe@x86_64-linux".activationPackage` builds.

## Notes

- `emmathorpe` has no personal authorized key yet (it previously inherited Lyra's key via the bug in #46); the registry entry is intentionally empty — add a real key if SSH login as `emmathorpe` is wanted (moot on the WSL host).
- A two-repo (public dotfiles / private systems) split is deferred by design; this internal restructure is the prerequisite for it.

---------

Co-authored-by: Emma Thorpe <emma.thorpe@citrix.com>
Reviewed-on: #49
2026-06-29 13:06:23 +01:00

2.1 KiB

Mac Pro 3,1 (Early 2008) — install notes

Flake host: lyrathorpe-macpro31. Desktop (portable = false, imports ../../modules/desktop.nix). Files: configuration.nix, hardware-configuration.nix.

Hardware configuration

hardware-configuration.nix here is the real config generated by nixos-generate-config on the machine. Root is an LVM logical volume (/dev/mapper/MacPro-Root, ext4); the ESP (vfat) and swap are referenced by UUID. The initrd carries dm-snapshot for the LVM root. Regenerate and commit if the disk layout changes.

Bootloader

The Mac Pro 3,1 has 64-bit EFI, so it uses systemd-boot (no GRUB/CSM shim). canTouchEfiVariables = false because Apple's firmware does not reliably accept efibootmgr NVRAM writes.

Apple-EFI quirk: if the firmware boot picker does not show NixOS after install, either

  • uncomment boot.loader.efi.efiInstallAsRemovable = true; in configuration.nix (installs the fallback \EFI\BOOT\BOOTX64.EFI), and/or
  • "bless" the ESP from macOS.

Partition the disk GPT with an ESP (vfat).

Graphics

The stock card varies between units — ATI Radeon HD 2600 XT or NVIDIA GeForce 8800 GT. No proprietary driver is hardcoded; Sway relies on in-tree KMS:

  • ATI Radeon HD 2600 XT → radeon (or amdgpu) KMS
  • NVIDIA GeForce 8800 GT → nouveau KMS

These come up automatically. If a card needs forcing, set services.xserver.videoDrivers and/or add the module to boot.initrd.kernelModules for early KMS (see the comment in configuration.nix).

Networking

Wired Ethernet via NetworkManager (from desktop.nix) — the Mac Pro has two gigabit ports.

Login

Graphical login via a Wayland greeter — greetd running ReGreet inside the cage kiosk compositor — configured centrally in lyrathorpe/swaywm.nix for every Sway host (gated on features.swayDesktop.enable). The greeter is forced to the Dvorak layout to match the console and Sway session. Set the user password (passwd lyrathorpe) after install, or the greeter cannot authenticate. Requires working KMS (radeon/nouveau — see Graphics).

Apply

sudo nixos-rebuild switch --flake .#lyrathorpe-macpro31