Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
41 lines
1.7 KiB
Nix
41 lines
1.7 KiB
Nix
# Raspberry Pi 5 (aarch64) headless server. Two roles, split into submodules:
|
|
# ./docker.nix (Docker host with a network socket) and ./reverse-proxy.nix
|
|
# (native nginx). The raspberry-pi-5 nixos-hardware profile (kernel, firmware,
|
|
# device tree) and key-only sshd (../../modules/ssh.nix) are layered on in the
|
|
# flake host table. Install notes: see ./README.md.
|
|
{ ... }:
|
|
{
|
|
imports = [
|
|
./hardware-configuration.nix
|
|
./docker.nix
|
|
./reverse-proxy.nix
|
|
];
|
|
|
|
# Match the flake's nixosConfigurations attribute name so `nh os switch`
|
|
# (which selects by the local hostname) resolves without an explicit -H flag.
|
|
networking.hostName = "lyrathorpe-rpi5";
|
|
|
|
# Headless server: the Sway desktop is intentionally not set up. modules/sway.nix is
|
|
# not imported and features.swayDesktop.enable defaults to false (declared in
|
|
# system/modules/features.nix), so this host keeps plain TTY/SSH login.
|
|
|
|
# Raspberry Pi boots via U-Boot + extlinux, not GRUB/systemd-boot. The
|
|
# raspberry-pi-5 nixos-hardware profile supplies the kernel, firmware and
|
|
# device tree.
|
|
boot.loader.grub.enable = false;
|
|
boot.loader.generic-extlinux-compatible.enable = true;
|
|
|
|
# Remote administration. Key-only policy and the authorized key come from
|
|
# ../../modules/ssh.nix; here we just enable the daemon and open the port.
|
|
services.openssh.enable = true;
|
|
|
|
# Default-deny inbound. Open only SSH here; the Docker and nginx submodules
|
|
# open their own ports (Docker via a source-restricted nftables rule, nginx
|
|
# via 80/443). List-valued, so these merge with the submodule definitions.
|
|
networking.firewall.enable = true;
|
|
networking.firewall.allowedTCPPorts = [ 22 ];
|
|
|
|
# See `man configuration.nix` / the stateVersion docs before changing.
|
|
system.stateVersion = "26.05";
|
|
}
|