CI / flake (push) Successful in 3m26s
## Summary Separates user identity (data) from the reusable Nix modules and lets a host declare any number of users, replacing the previous one-user-per-host structure. Also restructures the tree and exposes the home config for use off these hosts. ## Changes - **User registry** (`users/registry.nix`): per-user identity (name, email, groups, authorized + signing keys) as the single source of truth; no user data hardcoded in modules. - **Multi-user `mkHost`**: a host declares a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg. - **Restructured layout**: `users/`, `home/`, `modules/`, `hosts/`, `lib/` replace the former `lyrathorpe/` and `system/` trees. - **Portable outputs**: standalone `homeConfigurations."<user>@<system>"` (the portable subset — shell, git, editor, claude) plus an exported `homeModules` for use on machines not managed by this flake, or as an input to other flakes. - Docs (`README.md`, `home/README.md`) and `.gitignore` updated for the new paths. ## Fixes - Closes #46 — shared user module authorized one user's SSH key for every account. - Closes #47 — git committer identity hardcoded as defaults instead of per-user. - Closes #48 — EDaaS systemd linger hardcoded to a literal username. ## Verification - `nix flake check` passes: treefmt, deadnix, statix, pre-commit, and evaluation of all NixOS hosts + Darwin + homeConfigurations. - Derivation-path comparison vs `main`: `lyrathorpe-mbp` and `emmathorpe-edaas` are byte-identical; `lyrathorpe-t400`, `lyrathorpe-macpro31` and `lyrathorpe-rpi5` differ only by de-duplicating a repeated `authorized_keys` entry (confirmed with nix-diff — no other change). - Standalone `homeConfigurations."lyrathorpe@x86_64-linux".activationPackage` builds. ## Notes - `emmathorpe` has no personal authorized key yet (it previously inherited Lyra's key via the bug in #46); the registry entry is intentionally empty — add a real key if SSH login as `emmathorpe` is wanted (moot on the WSL host). - A two-repo (public dotfiles / private systems) split is deferred by design; this internal restructure is the prerequisite for it. --------- Co-authored-by: Emma Thorpe <emma.thorpe@citrix.com> Reviewed-on: #49
115 lines
5.7 KiB
Markdown
115 lines
5.7 KiB
Markdown
# nixfiles
|
|
|
|
NixOS / nix-darwin / home-manager configuration for all hosts, built from a
|
|
single flake.
|
|
|
|
## Hosts
|
|
|
|
Defined in the host table in [`flake.nix`](./flake.nix):
|
|
|
|
| Configuration | System | Machine |
|
|
| --------------------- | ---------------- | ----------------------------------------------------------------------------------------------------------- |
|
|
| `lyrathorpe-mbp` | `aarch64-linux` | MacBook Pro (Apple Silicon, Asahi) |
|
|
| `lyrathorpe-t400` | `x86_64-linux` | ThinkPad T400 — [install notes](./hosts/T400/README.md) |
|
|
| `lyrathorpe-macpro31` | `x86_64-linux` | Mac Pro 3,1, desktop — [install notes](./hosts/MacPro31/README.md) |
|
|
| `emmathorpe-edaas` | `x86_64-linux` | Work WSL box (NixOS-WSL) |
|
|
| `lyrathorpe-rpi5` | `aarch64-linux` | Raspberry Pi 5 headless server: Docker host + nginx reverse proxy — [install notes](./hosts/RPi5/README.md) |
|
|
| `lyrathorpe-mac` | `aarch64-darwin` | macOS (nix-darwin) |
|
|
|
|
Shared layers: `home` (home-manager: shell, git, editor),
|
|
`modules/common-nixos.nix` (all NixOS hosts: fonts, nix-ld, caches),
|
|
`modules/workstation.nix` (physical graphical hosts: audio, thermald,
|
|
earlyoom, fwupd), `modules/laptop.nix` (laptops: Wi-Fi, Bluetooth, power,
|
|
lid), and `modules/ssh.nix` (key-only sshd). The x86 hosts also pull
|
|
`nixos-hardware` profiles.
|
|
|
|
## Users
|
|
|
|
Identity is data, kept separate from the reusable modules:
|
|
|
|
- [`users/registry.nix`](./users/registry.nix) — one entry per user (display
|
|
name, email, supplementary groups, authorized + signing keys). This is the
|
|
single source of identity; no user data is hardcoded in the modules.
|
|
- Each host's table entry declares a `users` set keyed by username; every entry
|
|
lists that user's home-module composition (the shared `./home` bundle plus any
|
|
per-user modules, e.g. [`users/emmathorpe/work.nix`](./users/emmathorpe/work.nix))
|
|
and optional per-host-user system bits such as `linger`.
|
|
- `mkHost` builds each account from the registry and injects the matching
|
|
identity into that user's home config as the `identity` module arg. A host can
|
|
therefore declare any number of users.
|
|
|
|
### Portable home (off-NixOS / external consumers)
|
|
|
|
The home config is also exposed for use beyond these hosts:
|
|
|
|
- `homeConfigurations."<user>@<system>"` — a standalone home-manager profile
|
|
(the portable subset: shell + git + editor + claude) that can be activated on a
|
|
machine this flake does **not** manage:
|
|
`home-manager switch --flake .#"lyrathorpe@x86_64-linux"`. The desktop/sway
|
|
modules are intentionally excluded (they rely on a NixOS-provided Sway/Firefox
|
|
binary).
|
|
- `homeModules` — the reusable modules exported so another flake can import them
|
|
(`inputs.<this>.homeModules.default`). Consumers must supply the module args
|
|
these expect: `inputs` always, `identity` for git/desktop, `portable` for sway.
|
|
|
|
## Applying
|
|
|
|
```sh
|
|
# NixOS
|
|
sudo nixos-rebuild switch --flake .#<configuration>
|
|
# Darwin
|
|
darwin-rebuild switch --flake .#lyrathorpe-mac
|
|
```
|
|
|
|
## Shell environment & keybindings
|
|
|
|
- Interactive shell features (zsh, tmux, git, ssh, CLI tools, auto-tmux):
|
|
[`home/README.md`](./home/README.md).
|
|
- All Sway / tmux / foot / zsh keyboard shortcuts:
|
|
[`home/KEYBINDINGS.md`](./home/KEYBINDINGS.md).
|
|
|
|
## Login / greeter
|
|
|
|
Graphical (Sway) hosts log in through a Wayland greeter — `greetd` running
|
|
ReGreet inside the `cage` kiosk compositor — implemented in
|
|
[`modules/sway.nix`](./modules/sway.nix), gated on
|
|
`features.swayDesktop.enable` (the option is declared in
|
|
[`modules/features.nix`](./modules/features.nix), so headless hosts
|
|
can leave it off without importing `modules/sway.nix`). The greeter is forced to Dvorak
|
|
to match the console and Sway session. Headless hosts (the WSL work box and the
|
|
Raspberry Pi server) keep plain TTY login. The target account needs a password
|
|
(`passwd <user>`) before it can log in.
|
|
|
|
## MacBook (Asahi) firmware
|
|
|
|
The MBP host references `modules/firmware/` for Apple peripheral
|
|
firmware (Wi-Fi/Bluetooth). These blobs are **committed** (tracked) even though
|
|
`.gitignore` lists the directory: the flake is `git+file`, so it only sees
|
|
tracked files — untracking them breaks `lyrathorpe-mbp` evaluation (and the CI
|
|
host-eval) because the config can't find the firmware. They are not
|
|
redistributable; the repo is private.
|
|
|
|
To refresh them, copy the firmware extracted during the Asahi install (from
|
|
`/etc/nixos/firmware`, or re-extract per the
|
|
[Asahi NixOS docs](https://github.com/tpwrules/nixos-apple-silicon)) into
|
|
`modules/firmware/` and commit with `git add -f`.
|
|
|
|
## Development
|
|
|
|
A dev shell and a formatting/lint gate are wired through the flake:
|
|
|
|
- `nix develop` — shell with `deadnix`, `statix`, `treefmt`, and the git
|
|
`pre-commit` hooks (installed automatically on first entry).
|
|
- `nix fmt` — formats the tree via `treefmt` (nixfmt + shfmt + prettier;
|
|
generated files and `flake.lock` are excluded).
|
|
- `nix flake check` — runs formatting, `deadnix`, `statix`, the pre-commit
|
|
hooks, and evaluates every host. `.editorconfig` carries the base style;
|
|
`statix.toml` disables the two house-style lints (`repeated_keys`,
|
|
`empty_pattern`).
|
|
|
|
## CI
|
|
|
|
[`.gitea/workflows/ci.yaml`](./.gitea/workflows/ci.yaml) runs `nix flake check`
|
|
(formatting, `deadnix`, `statix`, the pre-commit hooks) and evaluates every
|
|
NixOS and Darwin host configuration on push/PR.
|