Files
nixfiles/hosts/RPi5/README.md
T
lyrathorpeandEmma Thorpe 128deca2e3
CI / flake (push) Successful in 3m26s
refactor(flake): user registry, multi-user hosts, and portable home outputs (#49)
## Summary

Separates user identity (data) from the reusable Nix modules and lets a host declare any number of users, replacing the previous one-user-per-host structure. Also restructures the tree and exposes the home config for use off these hosts.

## Changes

- **User registry** (`users/registry.nix`): per-user identity (name, email, groups, authorized + signing keys) as the single source of truth; no user data hardcoded in modules.
- **Multi-user `mkHost`**: a host declares a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg.
- **Restructured layout**: `users/`, `home/`, `modules/`, `hosts/`, `lib/` replace the former `lyrathorpe/` and `system/` trees.
- **Portable outputs**: standalone `homeConfigurations."<user>@<system>"` (the portable subset — shell, git, editor, claude) plus an exported `homeModules` for use on machines not managed by this flake, or as an input to other flakes.
- Docs (`README.md`, `home/README.md`) and `.gitignore` updated for the new paths.

## Fixes

- Closes #46 — shared user module authorized one user's SSH key for every account.
- Closes #47 — git committer identity hardcoded as defaults instead of per-user.
- Closes #48 — EDaaS systemd linger hardcoded to a literal username.

## Verification

- `nix flake check` passes: treefmt, deadnix, statix, pre-commit, and evaluation of all NixOS hosts + Darwin + homeConfigurations.
- Derivation-path comparison vs `main`: `lyrathorpe-mbp` and `emmathorpe-edaas` are byte-identical; `lyrathorpe-t400`, `lyrathorpe-macpro31` and `lyrathorpe-rpi5` differ only by de-duplicating a repeated `authorized_keys` entry (confirmed with nix-diff — no other change).
- Standalone `homeConfigurations."lyrathorpe@x86_64-linux".activationPackage` builds.

## Notes

- `emmathorpe` has no personal authorized key yet (it previously inherited Lyra's key via the bug in #46); the registry entry is intentionally empty — add a real key if SSH login as `emmathorpe` is wanted (moot on the WSL host).
- A two-repo (public dotfiles / private systems) split is deferred by design; this internal restructure is the prerequisite for it.

---------

Co-authored-by: Emma Thorpe <emma.thorpe@citrix.com>
Reviewed-on: #49
2026-06-29 13:06:23 +01:00

2.5 KiB

Raspberry Pi 5 (lyrathorpe-rpi5)

Headless aarch64-linux server with two roles:

  • Docker host — daemon exposed over the network (docker.nix).
  • nginx reverse proxy — declarative virtualHosts (reverse-proxy.nix).

Install

  1. Flash a NixOS aarch64 SD image (or USB) and boot the Pi. The raspberry-pi-5 profile from nixos-hardware (wired in the flake host table) supplies the kernel, firmware and device tree; boot is U-Boot + extlinux.
  2. Partition/mount the target, then regenerate the hardware config on the device and replace the committed placeholder:
    nixos-generate-config --root /mnt
    # copy /mnt/etc/nixos/hardware-configuration.nix over
    # system/machine/RPi5/hardware-configuration.nix in this repo, then commit
    
    hardware-configuration.nix in this directory is a placeholder committed only so the host evaluates in CI. The machine will not boot correctly until it is replaced with the generated one.
  3. Set the host name to match the flake attribute (already done in configuration.nix: lyrathorpe-rpi5) and build:
    sudo nixos-rebuild switch --flake .#lyrathorpe-rpi5
    # or, once the hostname is live:
    nh os switch
    
  4. Give the login user a password (passwd lyrathorpe) and confirm the key in system/modules/ssh.nix is the one you will connect with.

Docker socket (security)

The daemon listens on plain TCP 2375, no TLS, no auth. Access is root-equivalent on this host. The only protection is the nftables rule in docker.nix, which accepts 2375 only from the trusted LAN subnet (10.187.1.0/24 by default — change it to match your network). Do not widen that subnet to anything untrusted.

From a LAN client:

export DOCKER_HOST=tcp://lyrathorpe-rpi5:2375
docker info

The secure upgrade path is mutual TLS on 2376 (--tlsverify with a CA and client certs); it needs out-of-band cert provisioning and is intentionally not wired here.

Adding a reverse-proxy site

Each proxied service is a Nix entry in reverse-proxy.nix:

services.nginx.virtualHosts."app.example.lan" = {
  # enableACME = true; forceSSL = true;   # once a DNS name + cert exist
  locations."/" = {
    proxyPass = "http://127.0.0.1:8080";  # e.g. a local container
    proxyWebsockets = true;
  };
};

The example vhost is HTTP-only by design. Turn on enableACME/forceSSL per-vhost once the host has a real DNS name and the ACME challenge can be met; 443 is already open in the firewall.