CI / flake (push) Successful in 3m30s
## Summary
Follow-up cleanups from the post-refactor audit (issues #50–#53). All behaviour-preserving except the work-host changes (kube-tmux + Lens removal).
## Changes
- **#51** `refactor(ssh)` — move `services.openssh.enable` + `firewall.allowedTCPPorts = [ 22 ]` into `modules/ssh.nix`; drop the duplicated lines from T400, MacPro31, RPi5.
- **#50** `fix/feat(work)` — load kube-tmux from a pinned `flake = false` input (it is not in nixpkgs) and reference `${inputs.kube-tmux}/kube.tmux` directly, so the status line no longer depends on a manual `$HOME/code/kube-tmux` checkout. (Supersedes the interim file-existence guard.)
- **#52** `chore` — gitignore the untracked `tf-inspect/` scratch project.
- **#53** `chore` — remove the unused Lens package entirely (`pkgs.lens` + its unfree entry; `unfreePackages` is now just `claude-code`), fix the `nil`→`nil_ls` LSP doc, remove the redundant `.editorconfig` block, name the RPi5 Docker subnet in a `let` binding.
## Deferred (from #53, noted in the commit)
- `.gitignore` firmware entry — documented behaviour, low value, left as-is.
- Per-eval `nixpkgs-unstable` overlay import — inherently per-system; no clean single-import hoist.
## Verification
- `nix flake check` passes (treefmt, deadnix, statix, pre-commit, all hosts + Darwin + homeConfigurations).
- Derivation-path diff vs `main`: `lyrathorpe-mbp`, `lyrathorpe-t400`, `lyrathorpe-macpro31`, `lyrathorpe-rpi5` are byte-identical (confirms #51 and the subnet `let` binding change nothing). Only `emmathorpe-edaas` differs — the kube-tmux input (#50) and the Lens removal (#53).
Closes #50, #51, #52, #53.
---------
Co-authored-by: Emma Thorpe <emma.thorpe@citrix.com>
Reviewed-on: #54
74 lines
2.2 KiB
Nix
74 lines
2.2 KiB
Nix
# Work (EDaaS/WSL) home profile: corporate toolchain + tmux tweaks. Git identity
|
|
# comes from the registry (users/registry.nix), not here.
|
|
{
|
|
pkgs,
|
|
lib,
|
|
inputs,
|
|
...
|
|
}:
|
|
|
|
{
|
|
# Host-scoped extras for this machine only (the EDaaS/WSL host).
|
|
imports = [
|
|
./renovate-review.nix # daily headless Renovate PR review (systemd user timer)
|
|
];
|
|
|
|
# The work box keeps its own (corporate) ~/.ssh/config; don't let the personal
|
|
# programs.ssh (shell.nix) take it over. The ssh-agent below still runs.
|
|
programs.ssh.enable = lib.mkForce false;
|
|
|
|
home.packages = [
|
|
pkgs.kubectl
|
|
pkgs.argo-rollouts
|
|
pkgs.tenv
|
|
pkgs.kubernetes-helm
|
|
pkgs.azure-cli
|
|
pkgs.kubelogin
|
|
pkgs.curl
|
|
pkgs.notation
|
|
pkgs.powershell
|
|
pkgs.nuget
|
|
pkgs.gedit
|
|
pkgs.python3
|
|
pkgs.gnumake
|
|
pkgs.gcc
|
|
pkgs.libiconv
|
|
pkgs.autoconf
|
|
pkgs.automake
|
|
pkgs.pkg-config
|
|
pkgs.wget
|
|
pkgs.google-cloud-sdk
|
|
# Day-to-day Kubernetes / Helm / Terraform accelerators for this box.
|
|
pkgs.k9s # cluster TUI
|
|
pkgs.kubectx # kubectx + kubens (context/namespace switch)
|
|
pkgs.stern # multi-pod log tail
|
|
pkgs.dyff # semantic YAML/manifest diffs (Helm release drift)
|
|
pkgs.tflint # Terraform linter (catches what terraformls won't)
|
|
pkgs.terraform-docs # generate Terraform module docs
|
|
pkgs.yq-go # jq for YAML
|
|
];
|
|
services.ssh-agent.enable = true;
|
|
home.shellAliases = {
|
|
docker = "/run/current-system/sw/bin/docker";
|
|
};
|
|
programs.tmux = {
|
|
# kube context/namespace in the status line. kube-tmux is pinned as a flake
|
|
# input (it is not in nixpkgs), so the script is always present in the store.
|
|
extraConfig = ''
|
|
set -g status-right "#(${pkgs.bash}/bin/bash ${inputs.kube-tmux}/kube.tmux 250 red black)"
|
|
'';
|
|
};
|
|
programs.go = {
|
|
enable = true;
|
|
};
|
|
|
|
# LSP servers only relevant to work: C# (omnisharp) and Helm charts (helm_ls).
|
|
# The shared editor (home/editor.nix) carries the universal ones;
|
|
# these are gated to this host so the heavy omnisharp closure stays off the
|
|
# personal machines. Tree-sitter grammars (highlighting) remain global there.
|
|
programs.nixvim.plugins.lsp.servers = {
|
|
omnisharp.enable = true;
|
|
helm_ls.enable = true;
|
|
};
|
|
}
|