## Summary
Follow-up cleanups from the post-refactor audit (issues #50–#53). All behaviour-preserving except the work-host changes (kube-tmux + Lens removal).
## Changes
- **#51** `refactor(ssh)` — move `services.openssh.enable` + `firewall.allowedTCPPorts = [ 22 ]` into `modules/ssh.nix`; drop the duplicated lines from T400, MacPro31, RPi5.
- **#50** `fix/feat(work)` — load kube-tmux from a pinned `flake = false` input (it is not in nixpkgs) and reference `${inputs.kube-tmux}/kube.tmux` directly, so the status line no longer depends on a manual `$HOME/code/kube-tmux` checkout. (Supersedes the interim file-existence guard.)
- **#52** `chore` — gitignore the untracked `tf-inspect/` scratch project.
- **#53** `chore` — remove the unused Lens package entirely (`pkgs.lens` + its unfree entry; `unfreePackages` is now just `claude-code`), fix the `nil`→`nil_ls` LSP doc, remove the redundant `.editorconfig` block, name the RPi5 Docker subnet in a `let` binding.
## Deferred (from #53, noted in the commit)
- `.gitignore` firmware entry — documented behaviour, low value, left as-is.
- Per-eval `nixpkgs-unstable` overlay import — inherently per-system; no clean single-import hoist.
## Verification
- `nix flake check` passes (treefmt, deadnix, statix, pre-commit, all hosts + Darwin + homeConfigurations).
- Derivation-path diff vs `main`: `lyrathorpe-mbp`, `lyrathorpe-t400`, `lyrathorpe-macpro31`, `lyrathorpe-rpi5` are byte-identical (confirms #51 and the subnet `let` binding change nothing). Only `emmathorpe-edaas` differs — the kube-tmux input (#50) and the Lens removal (#53).
Closes #50, #51, #52, #53.
---------
Co-authored-by: Emma Thorpe <emma.thorpe@citrix.com>
Reviewed-on: #54
Mac Pro 3,1 (Early 2008) — install notes
Flake host: lyrathorpe-macpro31. Desktop (portable = false, imports
../../modules/desktop.nix). Files: configuration.nix,
hardware-configuration.nix.
Hardware configuration
hardware-configuration.nix here is the real config generated by
nixos-generate-config on the machine. Root is an LVM logical volume
(/dev/mapper/MacPro-Root, ext4); the ESP (vfat) and swap are referenced by
UUID. The initrd carries dm-snapshot for the LVM root. Regenerate and commit
if the disk layout changes.
Bootloader
The Mac Pro 3,1 has 64-bit EFI, so it uses systemd-boot (no GRUB/CSM
shim). canTouchEfiVariables = false because Apple's firmware does not reliably
accept efibootmgr NVRAM writes.
Apple-EFI quirk: if the firmware boot picker does not show NixOS after install, either
- uncomment
boot.loader.efi.efiInstallAsRemovable = true;inconfiguration.nix(installs the fallback\EFI\BOOT\BOOTX64.EFI), and/or - "bless" the ESP from macOS.
Partition the disk GPT with an ESP (vfat).
Graphics
The stock card varies between units — ATI Radeon HD 2600 XT or NVIDIA GeForce 8800 GT. No proprietary driver is hardcoded; Sway relies on in-tree KMS:
- ATI Radeon HD 2600 XT →
radeon(oramdgpu) KMS - NVIDIA GeForce 8800 GT →
nouveauKMS
These come up automatically. If a card needs forcing, set
services.xserver.videoDrivers and/or add the module to
boot.initrd.kernelModules for early KMS (see the comment in
configuration.nix).
Networking
Wired Ethernet via NetworkManager (from desktop.nix) — the Mac Pro has two
gigabit ports.
Login
Graphical login via a Wayland greeter — greetd running ReGreet inside the
cage kiosk compositor — configured centrally in lyrathorpe/swaywm.nix for
every Sway host (gated on features.swayDesktop.enable). The greeter is forced
to the Dvorak layout to match the console and Sway session. Set the user
password (passwd lyrathorpe) after install, or the greeter cannot
authenticate. Requires working KMS (radeon/nouveau — see Graphics).
Apply
sudo nixos-rebuild switch --flake .#lyrathorpe-macpro31