lyrathorpeandEmma Thorpe 128deca2e3
CI / flake (push) Successful in 3m26s
refactor(flake): user registry, multi-user hosts, and portable home outputs (#49)
## Summary

Separates user identity (data) from the reusable Nix modules and lets a host declare any number of users, replacing the previous one-user-per-host structure. Also restructures the tree and exposes the home config for use off these hosts.

## Changes

- **User registry** (`users/registry.nix`): per-user identity (name, email, groups, authorized + signing keys) as the single source of truth; no user data hardcoded in modules.
- **Multi-user `mkHost`**: a host declares a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg.
- **Restructured layout**: `users/`, `home/`, `modules/`, `hosts/`, `lib/` replace the former `lyrathorpe/` and `system/` trees.
- **Portable outputs**: standalone `homeConfigurations."<user>@<system>"` (the portable subset — shell, git, editor, claude) plus an exported `homeModules` for use on machines not managed by this flake, or as an input to other flakes.
- Docs (`README.md`, `home/README.md`) and `.gitignore` updated for the new paths.

## Fixes

- Closes #46 — shared user module authorized one user's SSH key for every account.
- Closes #47 — git committer identity hardcoded as defaults instead of per-user.
- Closes #48 — EDaaS systemd linger hardcoded to a literal username.

## Verification

- `nix flake check` passes: treefmt, deadnix, statix, pre-commit, and evaluation of all NixOS hosts + Darwin + homeConfigurations.
- Derivation-path comparison vs `main`: `lyrathorpe-mbp` and `emmathorpe-edaas` are byte-identical; `lyrathorpe-t400`, `lyrathorpe-macpro31` and `lyrathorpe-rpi5` differ only by de-duplicating a repeated `authorized_keys` entry (confirmed with nix-diff — no other change).
- Standalone `homeConfigurations."lyrathorpe@x86_64-linux".activationPackage` builds.

## Notes

- `emmathorpe` has no personal authorized key yet (it previously inherited Lyra's key via the bug in #46); the registry entry is intentionally empty — add a real key if SSH login as `emmathorpe` is wanted (moot on the WSL host).
- A two-repo (public dotfiles / private systems) split is deferred by design; this internal restructure is the prerequisite for it.

---------

Co-authored-by: Emma Thorpe <emma.thorpe@citrix.com>
Reviewed-on: #49
2026-06-29 13:06:23 +01:00

nixfiles

NixOS / nix-darwin / home-manager configuration for all hosts, built from a single flake.

Hosts

Defined in the host table in flake.nix:

Configuration System Machine
lyrathorpe-mbp aarch64-linux MacBook Pro (Apple Silicon, Asahi)
lyrathorpe-t400 x86_64-linux ThinkPad T400 — install notes
lyrathorpe-macpro31 x86_64-linux Mac Pro 3,1, desktop — install notes
emmathorpe-edaas x86_64-linux Work WSL box (NixOS-WSL)
lyrathorpe-rpi5 aarch64-linux Raspberry Pi 5 headless server: Docker host + nginx reverse proxy — install notes
lyrathorpe-mac aarch64-darwin macOS (nix-darwin)

Shared layers: home (home-manager: shell, git, editor), modules/common-nixos.nix (all NixOS hosts: fonts, nix-ld, caches), modules/workstation.nix (physical graphical hosts: audio, thermald, earlyoom, fwupd), modules/laptop.nix (laptops: Wi-Fi, Bluetooth, power, lid), and modules/ssh.nix (key-only sshd). The x86 hosts also pull nixos-hardware profiles.

Users

Identity is data, kept separate from the reusable modules:

  • users/registry.nix — one entry per user (display name, email, supplementary groups, authorized + signing keys). This is the single source of identity; no user data is hardcoded in the modules.
  • Each host's table entry declares a users set keyed by username; every entry lists that user's home-module composition (the shared ./home bundle plus any per-user modules, e.g. users/emmathorpe/work.nix) and optional per-host-user system bits such as linger.
  • mkHost builds each account from the registry and injects the matching identity into that user's home config as the identity module arg. A host can therefore declare any number of users.

Portable home (off-NixOS / external consumers)

The home config is also exposed for use beyond these hosts:

  • homeConfigurations."<user>@<system>" — a standalone home-manager profile (the portable subset: shell + git + editor + claude) that can be activated on a machine this flake does not manage: home-manager switch --flake .#"lyrathorpe@x86_64-linux". The desktop/sway modules are intentionally excluded (they rely on a NixOS-provided Sway/Firefox binary).
  • homeModules — the reusable modules exported so another flake can import them (inputs.<this>.homeModules.default). Consumers must supply the module args these expect: inputs always, identity for git/desktop, portable for sway.

Applying

# NixOS
sudo nixos-rebuild switch --flake .#<configuration>
# Darwin
darwin-rebuild switch --flake .#lyrathorpe-mac

Shell environment & keybindings

Login / greeter

Graphical (Sway) hosts log in through a Wayland greeter — greetd running ReGreet inside the cage kiosk compositor — implemented in modules/sway.nix, gated on features.swayDesktop.enable (the option is declared in modules/features.nix, so headless hosts can leave it off without importing modules/sway.nix). The greeter is forced to Dvorak to match the console and Sway session. Headless hosts (the WSL work box and the Raspberry Pi server) keep plain TTY login. The target account needs a password (passwd <user>) before it can log in.

MacBook (Asahi) firmware

The MBP host references modules/firmware/ for Apple peripheral firmware (Wi-Fi/Bluetooth). These blobs are committed (tracked) even though .gitignore lists the directory: the flake is git+file, so it only sees tracked files — untracking them breaks lyrathorpe-mbp evaluation (and the CI host-eval) because the config can't find the firmware. They are not redistributable; the repo is private.

To refresh them, copy the firmware extracted during the Asahi install (from /etc/nixos/firmware, or re-extract per the Asahi NixOS docs) into modules/firmware/ and commit with git add -f.

Development

A dev shell and a formatting/lint gate are wired through the flake:

  • nix develop — shell with deadnix, statix, treefmt, and the git pre-commit hooks (installed automatically on first entry).
  • nix fmt — formats the tree via treefmt (nixfmt + shfmt + prettier; generated files and flake.lock are excluded).
  • nix flake check — runs formatting, deadnix, statix, the pre-commit hooks, and evaluates every host. .editorconfig carries the base style; statix.toml disables the two house-style lints (repeated_keys, empty_pattern).

CI

.gitea/workflows/ci.yaml runs nix flake check (formatting, deadnix, statix, the pre-commit hooks) and evaluates every NixOS and Darwin host configuration on push/PR.

S
Description
No description provided
Readme
52 MiB
Languages
Nix 100%