Files
nixfiles/hosts/T400
lyrathorpeandEmma Thorpe 128deca2e3
CI / flake (push) Successful in 3m26s
refactor(flake): user registry, multi-user hosts, and portable home outputs (#49)
## Summary

Separates user identity (data) from the reusable Nix modules and lets a host declare any number of users, replacing the previous one-user-per-host structure. Also restructures the tree and exposes the home config for use off these hosts.

## Changes

- **User registry** (`users/registry.nix`): per-user identity (name, email, groups, authorized + signing keys) as the single source of truth; no user data hardcoded in modules.
- **Multi-user `mkHost`**: a host declares a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg.
- **Restructured layout**: `users/`, `home/`, `modules/`, `hosts/`, `lib/` replace the former `lyrathorpe/` and `system/` trees.
- **Portable outputs**: standalone `homeConfigurations."<user>@<system>"` (the portable subset — shell, git, editor, claude) plus an exported `homeModules` for use on machines not managed by this flake, or as an input to other flakes.
- Docs (`README.md`, `home/README.md`) and `.gitignore` updated for the new paths.

## Fixes

- Closes #46 — shared user module authorized one user's SSH key for every account.
- Closes #47 — git committer identity hardcoded as defaults instead of per-user.
- Closes #48 — EDaaS systemd linger hardcoded to a literal username.

## Verification

- `nix flake check` passes: treefmt, deadnix, statix, pre-commit, and evaluation of all NixOS hosts + Darwin + homeConfigurations.
- Derivation-path comparison vs `main`: `lyrathorpe-mbp` and `emmathorpe-edaas` are byte-identical; `lyrathorpe-t400`, `lyrathorpe-macpro31` and `lyrathorpe-rpi5` differ only by de-duplicating a repeated `authorized_keys` entry (confirmed with nix-diff — no other change).
- Standalone `homeConfigurations."lyrathorpe@x86_64-linux".activationPackage` builds.

## Notes

- `emmathorpe` has no personal authorized key yet (it previously inherited Lyra's key via the bug in #46); the registry entry is intentionally empty — add a real key if SSH login as `emmathorpe` is wanted (moot on the WSL host).
- A two-repo (public dotfiles / private systems) split is deferred by design; this internal restructure is the prerequisite for it.

---------

Co-authored-by: Emma Thorpe <emma.thorpe@citrix.com>
Reviewed-on: #49
2026-06-29 13:06:23 +01:00
..

ThinkPad T400 — install notes

Flake host: lyrathorpe-t400. Files: configuration.nix, the boot-*.nix variants, and hardware-configuration.nix.

Hardware configuration

hardware-configuration.nix here is a hand-written placeholder. On the real machine, run nixos-generate-config, replace the file, and commit it. It assumes by-label partitions — root nixos (ext4) and swap — so either label them at install time or swap in the generated UUIDs.

Bootloader — import the module matching the flashed firmware

configuration.nix imports exactly one boot module. Default is boot-bios.nix; switch by commenting it out and uncommenting the relevant alternative.

Firmware Module Notes
Stock Lenovo BIOS, or coreboot + SeaBIOS payload boot-bios.nix GRUB on the MBR. Set device to the real install disk (/dev/sda by default). MBR/legacy layout.
coreboot + GRUB payload boot-coreboot-grub.nix GRUB is config-only (device = "nodev"); NixOS does not write to a disk. Your coreboot grub.cfg (in the flash chip) must search for and configfile the on-disk /boot/grub/grub.cfg, or chainload the disk's GRUB.
coreboot + Tianocore/edk2 (UEFI) payload boot-coreboot-uefi.nix systemd-boot. canTouchEfiVariables = true (coreboot honours NVRAM writes). The module declares its own ESP (/boot vfat, label ESP) — when you regenerate hardware-configuration.nix, do not let it also define /boot. Create + label an ESP vfat partition (GPT).

Graphics

This unit has the optional discrete ATI Mobility Radeon HD 3470 (RV620). The open radeon KMS driver is loaded in the initrd for early modesetting; firmware comes from enableRedistributableFirmware.

The T400 has switchable graphics (discrete ATI + Intel GMA 4500MHD). Select Discrete in the firmware's graphics setting so only the ATI is live. If you run Integrated instead, the Intel i915 driver takes over with no config change and radeon stays idle.

Login

Graphical login via a Wayland greeter — greetd running ReGreet inside the cage kiosk compositor — configured centrally in lyrathorpe/swaywm.nix for every Sway host (gated on features.swayDesktop.enable). The greeter is forced to the Dvorak layout to match the console and Sway session. Set the user password (passwd lyrathorpe) after install, or the greeter cannot authenticate. Requires working radeon/i915 KMS (see Graphics).

Apply

sudo nixos-rebuild switch --flake .#lyrathorpe-t400