Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
63 lines
2.4 KiB
Nix
63 lines
2.4 KiB
Nix
# Options shared by every NixOS host (laptops and the WSL box). Imported via
|
|
# baseModules in flake.nix. Host- and platform-specific settings stay in the
|
|
# per-machine configs; laptop-only settings live in ./laptop.nix.
|
|
{ pkgs, ... }:
|
|
{
|
|
time.timeZone = "Europe/London";
|
|
i18n.defaultLocale = "en_GB.UTF-8";
|
|
|
|
# Store hygiene. auto-optimise-store hard-links identical files in the store
|
|
# after each build (cheap dedupe; NOT a garbage collector -- there is
|
|
# deliberately no automatic GC timer). The larger download buffer avoids
|
|
# "buffer full" stalls when fetching big NARs over a fast link.
|
|
nix.settings.auto-optimise-store = true;
|
|
nix.settings.download-buffer-size = 134217728; # 128 MiB
|
|
|
|
# Extra binary cache for the nix-community toolchain (home-manager, nixvim,
|
|
# treefmt, ...). Merges with any host-specific caches (e.g. the Asahi cache on
|
|
# the MBP) rather than replacing them.
|
|
nix.settings.substituters = [ "https://nix-community.cachix.org" ];
|
|
nix.settings.trusted-public-keys = [
|
|
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
|
|
];
|
|
|
|
# Run dynamically-linked foreign binaries (VS Code remote server, prebuilt
|
|
# toolchains, language-server downloads) on every NixOS host, not just WSL.
|
|
programs.nix-ld.enable = true;
|
|
|
|
# Minimal system-level CLI available before the home-manager profile loads
|
|
# (e.g. early boot / rescue). User-level tooling lives in home-manager.
|
|
environment.systemPackages = with pkgs; [
|
|
git
|
|
fastfetch
|
|
];
|
|
|
|
# Fonts on every host. The Nerd Font carries the powerline/Nerd glyphs the
|
|
# tmux statusline uses (foot names it explicitly in home/sway.nix); Noto sans +
|
|
# colour emoji prevent tofu in terminals/TUIs/Firefox -- important on the WSL
|
|
# box, which does not pull the graphical hosts' default Noto stack. The Mac
|
|
# installs the Nerd Font via the Darwin config.
|
|
fonts.packages = with pkgs; [
|
|
nerd-fonts.jetbrains-mono
|
|
noto-fonts
|
|
noto-fonts-color-emoji
|
|
];
|
|
# Map the generic fontconfig families so anything asking for "monospace" gets
|
|
# the Nerd Font (with emoji fallback), not DejaVu.
|
|
fonts.fontconfig.defaultFonts = {
|
|
monospace = [
|
|
"JetBrainsMono Nerd Font"
|
|
"Noto Color Emoji"
|
|
];
|
|
sansSerif = [
|
|
"Noto Sans"
|
|
"Noto Color Emoji"
|
|
];
|
|
serif = [
|
|
"Noto Serif"
|
|
"Noto Color Emoji"
|
|
];
|
|
emoji = [ "Noto Color Emoji" ];
|
|
};
|
|
}
|