Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
62 lines
2.1 KiB
Markdown
62 lines
2.1 KiB
Markdown
# Mac Pro 3,1 (Early 2008) — install notes
|
|
|
|
Flake host: `lyrathorpe-macpro31`. Desktop (`portable = false`, imports
|
|
`../../modules/desktop.nix`). Files: `configuration.nix`,
|
|
`hardware-configuration.nix`.
|
|
|
|
## Hardware configuration
|
|
|
|
`hardware-configuration.nix` here is the real config generated by
|
|
`nixos-generate-config` on the machine. Root is an **LVM** logical volume
|
|
(`/dev/mapper/MacPro-Root`, ext4); the ESP (vfat) and swap are referenced by
|
|
UUID. The initrd carries `dm-snapshot` for the LVM root. Regenerate and commit
|
|
if the disk layout changes.
|
|
|
|
## Bootloader
|
|
|
|
The Mac Pro 3,1 has **64-bit EFI**, so it uses **systemd-boot** (no GRUB/CSM
|
|
shim). `canTouchEfiVariables = false` because Apple's firmware does not reliably
|
|
accept `efibootmgr` NVRAM writes.
|
|
|
|
Apple-EFI quirk: if the firmware boot picker does not show NixOS after install,
|
|
either
|
|
|
|
- uncomment `boot.loader.efi.efiInstallAsRemovable = true;` in
|
|
`configuration.nix` (installs the fallback `\EFI\BOOT\BOOTX64.EFI`), and/or
|
|
- "bless" the ESP from macOS.
|
|
|
|
Partition the disk GPT with an ESP (vfat).
|
|
|
|
## Graphics
|
|
|
|
The stock card varies between units — **ATI Radeon HD 2600 XT** or **NVIDIA
|
|
GeForce 8800 GT**. No proprietary driver is hardcoded; Sway relies on in-tree KMS:
|
|
|
|
- ATI Radeon HD 2600 XT → `radeon` (or `amdgpu`) KMS
|
|
- NVIDIA GeForce 8800 GT → `nouveau` KMS
|
|
|
|
These come up automatically. If a card needs forcing, set
|
|
`services.xserver.videoDrivers` and/or add the module to
|
|
`boot.initrd.kernelModules` for early KMS (see the comment in
|
|
`configuration.nix`).
|
|
|
|
## Networking
|
|
|
|
Wired Ethernet via NetworkManager (from `desktop.nix`) — the Mac Pro has two
|
|
gigabit ports.
|
|
|
|
## Login
|
|
|
|
Graphical login via a Wayland greeter — `greetd` running ReGreet inside the
|
|
`cage` kiosk compositor — configured centrally in `lyrathorpe/swaywm.nix` for
|
|
every Sway host (gated on `features.swayDesktop.enable`). The greeter is forced
|
|
to the Dvorak layout to match the console and Sway session. Set the user
|
|
password (`passwd lyrathorpe`) after install, or the greeter cannot
|
|
authenticate. Requires working KMS (radeon/nouveau — see Graphics).
|
|
|
|
## Apply
|
|
|
|
```sh
|
|
sudo nixos-rebuild switch --flake .#lyrathorpe-macpro31
|
|
```
|