Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
1.5 KiB
name, description, metadata
| name | description | metadata | ||||||
|---|---|---|---|---|---|---|---|---|
| git-network-ops | Push/pull is remote-specific — GitHub is agent-pushable in-sandbox; Gitea (code.emmathe.dev) needs hand-off to Lyra. |
|
Whether a network op can run depends on which key the remote needs:
GitHub remotes (e.g. csg-citrix-storefront/*): pushable in-sandbox by the agent. ssh-agent holds the decrypted ~/.ssh/id_ed25519 (emma.thorpe@cloud.com), which is authorized on GitHub. Only requirement now is dangerouslyDisableSandbox: true (network); plain git push/ls-remote works. Probe non-mutatively with git ls-remote first. (Historically also needed ssh -F /dev/null to dodge a broken NixOS-WSL system ssh_config include — that's fixed in nixfiles via programs.ssh.systemd-ssh-proxy.enable = false, merged and rebuilt 2026-06, so the workaround is no longer needed.)
Gitea (code.emmathe.dev, e.g. nixfiles): hand off to Lyra. Needs ~/.ssh/code.emmathe.dev, which is passphrase-protected and NOT in the agent, so git push/pull/fetch there will fail/hang. Pause, give Lyra the exact command (she runs ssh-add ~/.ssh/code.emmathe.dev once, then pushes).
Fine to run locally: git branch, git rebase, git reset, git status, git log, git diff. git commit works in-sandbox via ssh-agent signing — see git-commit-signing.
How to apply: Check the remote host before a network op. GitHub → just do it (sandbox off). Gitea → hand off. Related: git-conventions.