Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
34 lines
1.5 KiB
Nix
34 lines
1.5 KiB
Nix
# Claude Code, configured declaratively via home-manager. Wanted on every host.
|
|
#
|
|
# The STATIC config is managed here: the global CLAUDE.md (persona/context), the
|
|
# custom output style, and the auto-memory directory. settings.json is
|
|
# deliberately left UNMANAGED -- Claude Code rewrites it at runtime (interactive
|
|
# permission grants, /config), and a read-only /nix/store symlink would break
|
|
# those writes.
|
|
#
|
|
# Memory is the source of truth in this repo (./claude/memory). It is symlinked
|
|
# read-only into ~/.claude/memory, so the runtime "save a memory" path no longer
|
|
# writes there -- recall still works, but new/changed memories must be added to
|
|
# this repo and rebuilt. CLAUDE.md instructs Claude to do exactly that.
|
|
{ ... }:
|
|
{
|
|
programs.claude-code = {
|
|
enable = true;
|
|
# package defaults to pkgs.claude-code (tracked to unstable via the flake
|
|
# overlay); installs the CLI on every host.
|
|
|
|
# ~/.claude/CLAUDE.md -- global instructions / persona / memory workflow.
|
|
context = ./claude/CLAUDE.md;
|
|
};
|
|
|
|
home.file = {
|
|
# Custom output style. The module has no option for output-styles/, so place
|
|
# it directly; selection (settings.json `outputStyle`) stays mutable.
|
|
".claude/output-styles/soviet-engineer.md".source = ./claude/output-styles/soviet-engineer.md;
|
|
|
|
# Auto-memory directory, Nix-managed (read-only). Edit ./claude/memory in
|
|
# this repo and rebuild to change what Claude remembers.
|
|
".claude/memory".source = ./claude/memory;
|
|
};
|
|
}
|