Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
35 lines
1.5 KiB
Nix
35 lines
1.5 KiB
Nix
# Base home-manager profile, shared by every host (graphical or headless).
|
|
# Graphical hosts additionally import ./desktop.nix; the work host imports
|
|
# ./work.nix. See the host table in flake.nix.
|
|
{ ... }:
|
|
{
|
|
imports = [
|
|
./shell.nix
|
|
./git.nix
|
|
./editor.nix
|
|
./claude.nix
|
|
];
|
|
|
|
# Manage the XDG base-directory layout and ~/.config files. Tools above
|
|
# (bat themes, gh config, ...) write under xdg.configHome; enabling this
|
|
# makes the paths explicit and consistent across hosts. No regression: the
|
|
# defaults match the conventional ~/.config, ~/.cache, ~/.local/share.
|
|
xdg.enable = true;
|
|
|
|
# Editor ($EDITOR and $VISUAL) comes from nixvim's defaultEditor (editor.nix).
|
|
# Round out the rest of the standard env. desktop.nix adds its own Wayland
|
|
# session vars; home-manager merges the two attrsets, so these do not clash.
|
|
home.sessionVariables = {
|
|
PAGER = "less -FRX"; # -F quit-if-one-screen, -R raw colour, -X no clear
|
|
# Render man pages through bat (themed): col strips backspace overstrike,
|
|
# bat -l man -p highlights without its own pager decorations.
|
|
MANPAGER = "sh -c 'col -bx | bat -l man -p'";
|
|
};
|
|
|
|
# Pinned to the release first installed on these hosts, NOT the current
|
|
# nixpkgs (26.05). stateVersion freezes stateful defaults (file locations,
|
|
# service data formats) to that release; bumping it silently migrates that
|
|
# state and can break it. Leave it -- it is intentional, not stale.
|
|
home.stateVersion = "25.05";
|
|
}
|