Compare commits

...

104 Commits

Author SHA1 Message Date
tux
8a6ac1a533 feat(hosts): add zcode and persist state directories 2026-09-18 23:12:01 +05:30
tux
c009f2be73 chore: persist ly save.txt file 2026-09-18 20:33:04 +05:30
tux
8ef160a991 feat(hosts): add coder and persist coderv2 dir 2026-09-18 20:32:30 +05:30
tux
c179b45ac1 feat(services): add coder nixos module 2026-09-18 19:22:58 +05:30
tux
ac750098b1 feat(overlays): add davinci-resolve source override 2026-09-18 17:37:19 +05:30
tux
75ecf511e6 chore: update flake inputs 2026-09-18 17:35:47 +05:30
tux
e48e2903ac feat(desktop): update serpantinum configuration 2026-09-18 02:13:28 +05:30
tux
69882de18a feat(desktop): enable voxtype on-demand loading 2026-09-18 01:51:16 +05:30
tux
e1632cb506 feat(desktop): switch to brave-origin 2026-09-18 01:14:18 +05:30
tux
43b3be09e5 chore: persist claude, orca and gh dirs 2026-09-17 22:47:13 +05:30
tux
f960a5eb04 feat(sirius): add galaxy-buds-client 2026-09-17 21:55:09 +05:30
tux
23dfd5b998 feat(flake): add llm-agents input and packages 2026-09-17 21:54:02 +05:30
tux
2b3e4661b3 feat(packages): add omasnap 2026-09-17 21:31:29 +05:30
tux
cdce741599 chore: add .config/nix to persist dir 2026-09-17 16:52:01 +05:30
tux
e520cf6767 feat(opencode): add zai-coding-plan 2026-09-16 19:58:29 +05:30
tux
30e33cb768 feat(desktop): add agent settings to zed 2026-09-16 15:21:26 +05:30
tux
dc750c6bfe feat(config): switch default models to deepseek-v4.1 2026-09-16 15:20:59 +05:30
tux
80469632b1 feat(core): enable all terminfo 2026-09-16 12:48:45 +05:30
tux
9bb2e1f11d style(desktop): update cursor size 2026-09-15 14:37:35 +05:30
tux
3b9774a20d feat(desktop): add cursor trail to kitty 2026-09-15 05:39:48 +05:30
tux
932bf56972 docs: update README 2026-09-13 02:28:42 +05:30
tux
dedda22aea chore: add serpantinum to persist dir 2026-09-12 18:12:11 +05:30
tux
ef09a8a5d4 style(desktop): update kitty foreground color 2026-09-12 17:42:48 +05:30
tux
51c6925364 feat(shell): add hm-override script 2026-09-12 17:29:59 +05:30
tux
dbd2353273 feat(desktop): add kitty module 2026-09-12 17:18:06 +05:30
tux
b6aa11fb56 chore: update flake inputs 2026-09-11 06:43:14 +05:30
tux
f08e67c36e chore(flake): update trok and tfolio flake inputs 2026-09-11 06:43:03 +05:30
tux
bd977c0941 refactor(vicinae): update configuration and extensions 2026-09-11 04:23:47 +05:30
tux
e6ffe8698f refactor(distrobox): drop waydroid configuration 2026-09-11 02:35:04 +05:30
tux
ac3a0404bc feat(core): add nix-ld nixos module 2026-09-11 02:08:13 +05:30
tux
cba375a888 chore(vicinae): remove broken extensions 2026-09-11 02:06:54 +05:30
tux
acb825e1db feat(obs-studio): enable obs-advanced-masks plugin 2026-09-11 02:06:17 +05:30
tux
344d8bdd4a style: format code 2026-09-11 01:59:55 +05:30
tux
49a341d6b3 feat(serpantinum): enable idle configuration 2026-09-10 15:36:02 +05:30
tux
9c77654697 chore: add rustup to persist dir 2026-09-10 00:38:27 +05:30
tux
dacbe6bc24 chore: update tnvim flake input 2026-09-10 00:38:13 +05:30
tux
33a1e9da9c chore: add zed to persist dir 2026-09-10 00:13:56 +05:30
tux
c6b12d6ff9 feat(discord): enable extra plugins 2026-09-09 02:51:44 +05:30
tux
3f6fb2e504 chore: add serpantinum to persist dir 2026-09-08 23:46:03 +05:30
tux
8026816b8f Merge pull request #2 from tuxdotrs/dev
refactor modules and configurations following dendritic pattern
2026-09-08 16:47:29 +05:30
tux
060ecbe7da docs(readme): update host specifications and components 2026-09-08 16:35:07 +05:30
tux
a01bd43ec9 refactor(serpantinum): flatten right widgets list 2026-09-08 15:52:06 +05:30
tux
54049a60ec chore: update folio flake input 2026-09-08 15:49:16 +05:30
tux
30929f3a7b feat(services): add and enable tfolio module 2026-09-08 05:48:24 +05:30
tux
9f190436e9 chore: update trok flake input 2026-09-07 23:36:01 +05:30
tux
884dd188c3 feat(services): add and enable trok module 2026-09-07 20:39:58 +05:30
tux
ea526e6f88 refactor(shell): configure clean vim shell alias 2026-09-07 18:47:41 +05:30
tux
edb3678ddd feat: add serpantinum shell 2026-09-07 18:47:07 +05:30
tux
b87e0889e0 chore: update flake inputs 2026-09-04 16:16:07 +05:30
tux
7a7ba68016 feat(gaming): configure lutris 2026-09-03 16:25:34 +05:30
tux
4f5db036b6 chore(flake): switch nix-on-droid to upstream 2026-09-02 00:09:59 +05:30
tux
85fa1f78d0 chore(zsh): configure PATH and stui shortcut 2026-09-01 22:05:51 +05:30
tux
b578e3b462 feat: enable hyprland module 2026-09-01 21:56:34 +05:30
tux
d0c1416f16 feat(ai-harness): add ponytail plugin 2026-08-30 23:14:26 +05:30
tux
91942539d7 chore: update flake inputs 2026-08-30 23:06:50 +05:30
tux
40276742bb feat(ghostty): enable cursor shader animation 2026-08-24 21:14:15 +05:30
tux
915c30c804 feat(desktop): replace tpanel with tshell 2026-08-24 21:13:46 +05:30
tux
7f0d55c597 feat(opencode): add flake input and overlay 2026-08-22 16:58:23 +05:30
tux
ba22699df3 chore(hosts): add .bun to persist dir 2026-08-22 14:21:35 +05:30
tux
c9a56d4a22 chore: update tpanel flake input 2026-08-22 14:19:47 +05:30
tux
42e073ea63 chore: update flake inputs 2026-08-21 20:37:38 +05:30
tux
033007490f chore: update flake inputs 2026-08-19 00:54:36 +05:30
tux
9e2559b1b7 feat(hosts): add impala to system packages 2026-08-18 23:54:09 +05:30
tux
8c755a5aa1 feat(hosts): add voxtype to persist dir 2026-08-13 17:17:10 +05:30
tux
69c2254f00 feat(desktop): add voxtype module 2026-08-13 17:14:29 +05:30
tux
31f4218115 feat(audio): include alsa-utils and pavucontrol 2026-08-13 04:15:04 +05:30
tux
7614a68027 feat(arcturus): enable hermes-agent service 2026-08-12 20:51:18 +05:30
tux
c0a6af4e97 feat(services): add hermes-agent nixos module 2026-08-12 20:51:07 +05:30
tux
a522f73de5 refactor(flake): move hosts module to flake 2026-08-12 16:39:35 +05:30
tux
cc2766509e refactor(hosts): streamline host and node builders 2026-08-12 16:35:52 +05:30
tux
95cd68aac2 feat(arcturus): enable copyparty 2026-08-12 15:54:26 +05:30
tux
967b4f118b feat(services): add copyparty nixos module 2026-08-12 15:53:59 +05:30
tux
f0d42515c4 refactor: remove unused arguments 2026-08-12 05:42:52 +05:30
tux
f7a96f76f7 chore: update flake inputs 2026-08-12 05:34:24 +05:30
tux
ec2e9e0721 feat(hosts): add deploy-rs nodes and checks 2026-08-12 05:34:16 +05:30
tux
9269257065 feat(vega): add core system utilities 2026-08-12 03:50:02 +05:30
tux
8ec633a0f0 fix(droid): use custom nix-on-droid branch 2026-08-12 03:40:22 +05:30
tux
e48e2cda51 refactor(droid): rename module namespace to nixondroid 2026-08-12 03:38:23 +05:30
tux
fbd006ae4c refactor(hosts): scope networking to vega host 2026-08-11 21:08:50 +05:30
tux
67c44b336c refactor(hosts): consolidate host configurations 2026-08-11 20:45:37 +05:30
tux
93dcaeb05e feat(droid): add nix-on-droid support and vega host 2026-08-11 18:59:16 +05:30
tux
0f842359b3 chore: update flake inputs 2026-08-11 14:04:09 +05:30
tux
9e37341838 feat(sirius): enable cardwire service 2026-08-10 22:30:45 +05:30
tux
4b828d974f feat(canopus): replace supergfxd with cardwire 2026-08-10 21:59:03 +05:30
tux
cf52a84c81 fix(boot): ensure machine-id is persisted 2026-08-10 20:44:46 +05:30
tux
c5d8729a28 chore: update flake inputs 2026-08-10 02:57:21 +05:30
tux
d083b69cd6 feat: add gitea module 2026-08-09 20:15:40 +05:30
tux
7a9ad6fd6c feat(services): add pangolin proxy configuration 2026-08-09 19:00:26 +05:30
tux
b060e4ccb6 refactor(services): standardize default service ports 2026-08-09 18:21:56 +05:30
tux
9242347eaf refactor(services): standardize host and proxy options 2026-08-09 18:18:26 +05:30
tux
f801c6c88c refactor(hosts): move vaultwarden to arcturus 2026-08-09 17:21:02 +05:30
tux
b071fe502c docs(pangolin): update pangolin option descriptions 2026-08-09 17:05:55 +05:30
tux
41a5c5be1a refactor(networking): update netbird client port 2026-08-09 17:03:02 +05:30
tux
6379ff4662 feat: add pangolin and newt modules 2026-08-09 17:02:38 +05:30
tux
819c54d46f feat: add uptime-kuma module 2026-08-08 15:34:44 +05:30
tux
162b822870 feat(core): add nix-index-database module 2026-08-07 16:41:03 +05:30
tux
8410655614 feat(canopus): add galaxy-buds-client 2026-08-07 16:16:40 +05:30
tux
1e6cf52067 perf(hardware): optimize fan curves 2026-08-07 15:27:20 +05:30
tux
2d06406284 refactor(services): standardize service module options 2026-08-07 05:46:00 +05:30
tux
0275c70cd0 refactor(desktop): update qt and gtk theme settings 2026-08-07 05:08:18 +05:30
tux
59c9d27342 fix(lazygit): fix model version and json output parsing 2026-08-07 04:58:11 +05:30
tux
7f43037522 refactor(services): standardize service module options 2026-08-07 04:56:47 +05:30
tux
82493de787 feat: add vaultwarden module 2026-08-07 04:18:07 +05:30
tux
f0ba54b168 chore: update flake inputs 2026-08-07 04:11:58 +05:30
115 changed files with 5383 additions and 3026 deletions

204
README.md
View File

@@ -15,196 +15,48 @@
## Table of Contents
- [Hosts](#hosts)
- [Installation](#installation)
- [Components](#components)
- [Showcase](#showcase)
- [Pain](#spent-weeks-on-this-system-configuration-)
- [Pain](#spent-months-on-this-system-configuration-)
## Hosts
| | Hostname | Board | CPU | RAM | GPU | Purpose |
| --- | ---------- | ----------------- | ------------------ | ----- | ------------------------- | -------------------------------------------------------------------------------- |
| 🖥️ | `sirius` | MSI X570-A Pro | Ryzen 7 5700X3D | 64GB | RTX 3080 TI + RTX 3060 TI | Triple-monitor desktop running Windows Subsystem for Linux. |
| 💻 | `canopus` | Asus Zephyrus G15 | Ryzen 9 5900HS | 16GB | RTX 3060 | Optimized for productivity on the go and some gaming. |
| ☁️ | `homelab` | Minisforum MS-A1 | Ryzen 7 8700G | 32GB | Radeon 780M | WIP |
| ☁️ | `arcturus` | KVM | 4 Core | 8GB | | Primary server responsible for exposing my homelab applications to the internet. |
| ☁️ | `alpha` | KVM | 4 Core | 4GB | | Monitors uptime and health status of all services across the infrastructure. |
| 🥔 | `vega` | Raspberry Pi 3B+ | Cortex A53 | 1GB | | Running AdGuard Home for network-wide ad blocking. |
| 📱 | `capella` | Samsung S25 Ultra | Snapdragon 8 Elite | 12GB | Adreno 830 | Primary mobile for daily usage. (Locked) |
| 📱 | `rigel` | Motorola Edge 30 | Snapdragon 778G+ | 8GB | Adreno 642L | Secondary mobile for some fun. (Rooted) |
| ☁️ | `node` | ASRock B565D4 | Ryzen 9 5950X | 128GB | | Running Ethereum and BSC nodes. |
## Installation
> [!NOTE]
> This will get your base system ready, but keep in mind that many things might not work correctly — such as monitor resolution, font size, and more.
### Prerequisites
Boot into the NixOS bootable USB before proceeding with the installation steps.
### Installation Steps
#### 1. Clone the repository
```bash
git clone https://github.com/tuxdotrs/nix-config.git
cd nix-config
```
#### 2. Gain root privileges
```bash
sudo su
```
#### 3. Set up disk partitioning
Install the required tools:
```bash
nix-shell -p disko neovim
```
Partition your disk using disko. **This will wipe your drive.** Replace `DISK_PATH` with your actual disk path (e.g., `/dev/vda` or `/dev/nvme0n1`):
```bash
disko --mode disko ./hosts/canopus/disko.nix --arg device '"DISK_PATH"'
```
#### 4. Configure your disk
Edit the configuration file:
```bash
nvim ./hosts/canopus/default.nix
```
In the imports statement, replace:
```nix
(import ./disko.nix {device = "/dev/nvme0n1";})
```
with:
```nix
(import ./disko.nix {device = "DISK_PATH";})
```
Make sure to replace `DISK_PATH` with your actual disk path.
#### 5. Generate hardware configuration
```bash
nixos-generate-config --no-filesystems --root /mnt
```
Copy the generated hardware configuration to the repository:
```bash
cp /mnt/etc/nixos/hardware-configuration.nix ./hosts/canopus/hardware.nix
```
#### 6. Install NixOS
```bash
nixos-install --root /mnt --flake .#canopus
```
#### 7. Enter into the new system
```bash
nixos-enter --root /mnt
```
#### 8. Set up directories and permissions
```bash
mkdir -p /persist/home
chown -R tux:users /persist/home
```
#### 9. Set passwords
Set the root password:
```bash
passwd root
```
Set the user password:
```bash
passwd tux
```
#### 10. Reboot
```bash
reboot
```
Your NixOS system should now boot into a beautiful DE.
| --- | ---------- | ----------------- | ------------------ | ---- | ------------------------- | --------------------------------------------------------------------- |
| 🖥️ | `sirius` | MSI X570-A Pro | Ryzen 7 5700X3D | 64GB | RTX 3080 TI + RTX 3060 TI | Triple-monitor desktop for work, gaming, and media consumption. |
| 💻 | `canopus` | Asus Zephyrus G15 | Ryzen 9 5900HS | 16GB | RTX 3060 | Portable workstation for work, gaming, and media on the go. |
| ☁️ | `arcturus` | Minisforum MS-A1 | Ryzen 7 8700G | 32GB | Radeon 780M | Homelab server for self-hosted services and infrastructure workloads. |
| ☁️ | `alpha` | KVM | 2 Core | 4GB | | Public-facing server for exposing homelab services to the internet. |
| 📱 | `vega` | Samsung S25 Ultra | Snapdragon 8 Elite | 12GB | Adreno 830 | Primary mobile for daily usage. (Locked) |
| 📱 | `capella` | Motorola Edge 30 | Snapdragon 778G+ | 8GB | Adreno 642L | Secondary mobile for tinkering and experimentation. (Rooted) |
## Components
| | Wayland | Xorg |
| ------------- | -------- | ---------------- |
| DM | ly | ly |
| WM/DE | Hyprland | AwesomeWM |
| Compositor | Hyprland | Picom (Jonaburg) |
| Bar | tPanel | Wibar |
| Hotkeys | Hyprland | Awful |
| Launcher | tPanel | Rofi |
| Notifications | tPanel | Naughty |
| Terminal | Wezterm | Wezterm |
| Editor | Neovim | Neovim |
| ------------- | -------- | ---- |
| DM | ly | - |
| WM/DE | Hyprland | - |
| Compositor | Hyprland | - |
| Bar | Tshell | - |
| Hotkeys | Hyprland | - |
| Launcher | Tshell | - |
| Notifications | Tshell | - |
| Terminal | Wezterm | - |
| Editor | Neovim | - |
## Showcase
### Desktop Hyprland
| **Desktop** | **Tshell** |
| :-------------------------------------------------------------------------------------------------------------------------: | :-----------------------------------------------------------------------------------------------------------------------: |
| <img src="https://raw.githubusercontent.com/tuxdotrs/nix-config/refs/heads/main/assets/hyprland/desktop.png" width="100%"> | <img src="https://raw.githubusercontent.com/tuxdotrs/nix-config/refs/heads/main/assets/hyprland/tPanel.png" width="100%"> |
| **Workflow** | **Neovim** |
| <img src="https://raw.githubusercontent.com/tuxdotrs/nix-config/refs/heads/main/assets/hyprland/workflow.png" width="100%"> | <img src="https://github.com/user-attachments/assets/f881c672-8d77-43ec-b637-df5004c7d11f" width="100%"> |
| **Floating Terminal** | **Lazygit** |
| <img src="https://github.com/user-attachments/assets/3339ecf8-3264-4179-a093-337c844592a6" width="100%"> | <img src="https://github.com/user-attachments/assets/6df15881-fc2b-41b1-af3b-124fe0599b94" width="100%"> |
| **Telescope** | **Firefox** |
| <img src="https://github.com/user-attachments/assets/03be05bc-8ede-4d6e-a341-2761d89b7288" width="100%"> | <img src="https://github.com/user-attachments/assets/6f12173b-2480-404e-b01a-599115a886c0" width="100%"> |
![Desktop](https://raw.githubusercontent.com/tuxdotrs/nix-config/refs/heads/main/assets/hyprland/desktop.png)
### tPanel
![tPanel](https://raw.githubusercontent.com/tuxdotrs/nix-config/refs/heads/main/assets/hyprland/tPanel.png)
### Workflow
![Workflow](https://raw.githubusercontent.com/tuxdotrs/nix-config/refs/heads/main/assets/hyprland/workflow.png)
## Showcase
### Desktop AwesomeWM
![2024-08-08_18-33](https://github.com/user-attachments/assets/1cdcc387-0f68-486c-a76c-a36ad2acb78d)
![2024-08-08_18-18](https://github.com/user-attachments/assets/f3fc4da5-6c0d-4cda-934d-b68ca6494e02)
### Neovim
![2024-08-08_18-16](https://github.com/user-attachments/assets/f881c672-8d77-43ec-b637-df5004c7d11f)
### Floating Terminal
![2024-08-08_18-16_1](https://github.com/user-attachments/assets/3339ecf8-3264-4179-a093-337c844592a6)
### Lazygit
![2024-08-08_18-16_2](https://github.com/user-attachments/assets/6df15881-fc2b-41b1-af3b-124fe0599b94)
### Telescope
![2024-08-08_18-16_3](https://github.com/user-attachments/assets/03be05bc-8ede-4d6e-a341-2761d89b7288)
### Firefox
![2024-08-08_18-26](https://github.com/user-attachments/assets/6f12173b-2480-404e-b01a-599115a886c0)
## Spent weeks on this system configuration 😢
## Spent months on this system configuration 😢
<div align="center">
<img src="https://user-images.githubusercontent.com/97862450/265550523-2f66a8b6-4347-40af-89c6-12db3a61cc7c.jpeg" width="60%">

1553
flake.lock generated

File diff suppressed because it is too large Load Diff

View File

@@ -24,8 +24,18 @@
inputs.nixpkgs.follows = "nixpkgs";
};
tpanel = {
url = "github:tuxdotrs/tpanel";
tshell = {
url = "github:tuxdotrs/tshell";
inputs.nixpkgs.follows = "nixpkgs";
};
trok = {
url = "github:tuxdotrs/trok";
inputs.nixpkgs.follows = "nixpkgs";
};
tfolio = {
url = "git+ssh://git@github.com/tuxdotrs/tfolio.git";
inputs.nixpkgs.follows = "nixpkgs";
};
@@ -49,6 +59,22 @@
inputs.nixpkgs.follows = "nixpkgs";
};
nix-index-database = {
url = "github:nix-community/nix-index-database";
inputs.nixpkgs.follows = "nixpkgs";
};
cardwire = {
url = "github:opengamingcollective/cardwire";
inputs.nixpkgs.follows = "nixpkgs";
};
nix-on-droid = {
url = "github:nix-community/nix-on-droid/master";
inputs.nixpkgs.follows = "nixpkgs";
inputs.home-manager.follows = "home-manager";
};
import-tree.url = "github:vic/import-tree";
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-25.11-small";
@@ -63,5 +89,11 @@
nixcord.url = "github:kaylorben/nixcord";
nur.url = "github:nix-community/nur";
lanzaboote.url = "github:nix-community/lanzaboote/v1.1.0";
copyparty.url = "github:9001/copyparty";
hermes-agent.url = "github:NousResearch/hermes-agent";
voxtype.url = "github:peteonrails/voxtype/v0.7.5";
opencode.url = "github:anomalyco/opencode";
serpantinum.url = "github:ilyamiro/serpantinum";
llm-agents.url = "github:numtide/llm-agents.nix";
};
}

33
modules/droid/core/hm.nix Normal file
View File

@@ -0,0 +1,33 @@
{
inputs,
config,
...
}: {
flake.modules.nixOnDroid.core = {
hostName,
userName,
userEmail,
...
}: {
home-manager = {
backupFileExtension = "bak";
useGlobalPkgs = true;
useUserPackages = true;
extraSpecialArgs = {
inherit
inputs
hostName
userName
userEmail
;
};
config = {
imports = [
config.flake.modules.homeManager.shell
config.flake.modules.homeManager.${hostName}
];
};
};
};
}

View File

@@ -0,0 +1,7 @@
{
flake.modules.nixOnDroid.core = {
nix.extraOptions = ''
experimental-features = nix-command flakes
'';
};
}

View File

@@ -0,0 +1,106 @@
{
flake.modules.nixOnDroid.networking = {
config,
lib,
pkgs,
...
}: let
# utility functions
concatLines = list: builtins.concatStringsSep "\n" list;
prefixLines = mapper: list: concatLines (map mapper list);
# could be put in the config
configPath = "ssh/sshd_config";
keysFolder = "/etc/ssh";
authorizedKeysFolder = "/etc/ssh/authorized_keys.d";
supportedKeysTypes = [
"rsa"
"ed25519"
];
sshd-start-bin = "sshd-start";
# real config
cfg = config.tnix.networking.openssh;
pathOfKeyOf = type: "${keysFolder}/ssh_host_${type}_key";
generateKeyOf = type: ''
${lib.getExe' pkgs.openssh "ssh-keygen"} \
-t "${type}" \
-f "${pathOfKeyOf type}" \
-N ""
'';
generateKeyWhenNeededOf = type: ''
if [ ! -f ${pathOfKeyOf type} ]; then
mkdir --parents ${keysFolder}
${generateKeyOf type}
fi
'';
sshd-start = pkgs.writeScriptBin sshd-start-bin ''
#!${pkgs.runtimeShell}
${prefixLines generateKeyWhenNeededOf supportedKeysTypes}
mkdir --parents "${authorizedKeysFolder}"
echo "${lib.concatStringsSep "\n" cfg.authorizedKeys}" > ${authorizedKeysFolder}/${config.user.userName}
echo "Starting sshd in non-daemonized way on port ${lib.concatMapStrings toString cfg.ports}"
${lib.getExe' pkgs.openssh "sshd"} \
-f "/etc/${configPath}" \
-D # don't detach into a daemon process
'';
in {
options.tnix.networking.openssh = {
enable = lib.mkEnableOption ''
Whether to enable the OpenSSH secure shell daemon, which
allows secure remote logins.
'';
ports = lib.mkOption {
type = lib.types.listOf lib.types.port;
default = [22];
description = ''
Specifies on which ports the SSH daemon listens.
'';
};
authorizedKeys = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [];
description = ''
Specify a list of public keys to be added to the authorized_keys file.
'';
};
};
config = lib.mkIf cfg.enable {
environment.etc = {
"${configPath}".text = ''
${prefixLines (port: "Port ${toString port}") cfg.ports}
AuthorizedKeysFile ${authorizedKeysFolder}/%u
LogLevel VERBOSE
'';
};
environment.packages = [
sshd-start
pkgs.openssh
];
build.activationAfter.sshd = ''
SERVER_PID=$(${lib.getExe' pkgs.procps "ps"} -a | ${lib.getExe' pkgs.toybox "grep"} sshd || true)
if [ -z "$SERVER_PID" ]; then
$DRY_RUN_CMD ${lib.getExe sshd-start}
fi
'';
};
};
}

View File

@@ -1,4 +1,3 @@
{ inputs, ... }:
{
{inputs, ...}: {
imports = [inputs.flake-parts.flakeModules.modules];
}

118
modules/flake/hosts.nix Normal file
View File

@@ -0,0 +1,118 @@
{
self,
inputs,
config,
...
}: let
mkNixOSHost = hostName: {
userName ? "tux",
userEmail ? "t@tux.rs",
system ? "x86_64-linux",
unstable ? true,
}: let
nixpkgs =
if unstable
then inputs.nixpkgs
else inputs.nixpkgs-stable;
in
nixpkgs.lib.nixosSystem {
inherit system;
specialArgs = {
inherit
hostName
userName
userEmail
system
;
};
modules = [
config.flake.modules.nixos.core
config.flake.modules.nixos.${hostName}
];
};
mkDroidHost = hostName: {
userName ? "nix-on-droid",
userEmail ? "t@tux.rs",
system ? "aarch64-linux",
unstable ? true,
}: let
nixpkgs =
if unstable
then inputs.nixpkgs
else inputs.nixpkgs-stable;
in
inputs.nix-on-droid.lib.nixOnDroidConfiguration {
pkgs = import nixpkgs {
inherit system;
config = {
allowUnfree = true;
joypixels.acceptLicense = true;
};
overlays = builtins.attrValues inputs.self.overlays;
};
extraSpecialArgs = {
inherit
hostName
userName
userEmail
;
};
modules = [
config.flake.modules.nixOnDroid.core
config.flake.modules.nixOnDroid.${hostName}
];
};
mkNixOSNode = hostName: {system ? "x86_64-linux"}: {
hostname = hostName;
profiles.system = {
user = "root";
path = inputs.deploy-rs.lib.${system}.activate.nixos self.nixosConfigurations.${hostName};
};
};
activateNixOnDroid = system: configuration:
inputs.deploy-rs.lib.${system}.activate.custom configuration.activationPackage
"${configuration.activationPackage}/activate";
mkDroidNode = hostName: {system ? "aarch64-linux"}: {
hostname = hostName;
profiles.system = {
sshUser = "nix-on-droid";
user = "nix-on-droid";
magicRollback = true;
sshOpts = [
"-p"
"8033"
];
path = activateNixOnDroid system self.nixOnDroidConfigurations.${hostName};
};
};
in {
flake = {
nixosConfigurations = builtins.mapAttrs mkNixOSHost {
sirius = {};
canopus = {};
arcturus = {};
alpha = {};
vps = {};
};
nixOnDroidConfigurations = builtins.mapAttrs mkDroidHost {
vega = {};
};
deploy.nodes =
builtins.mapAttrs (hostName: _: mkNixOSNode hostName {}) self.nixosConfigurations
// builtins.mapAttrs (hostName: _: mkDroidNode hostName {}) self.nixOnDroidConfigurations;
};
perSystem = {
checks =
builtins.mapAttrs (
_: hostConfig: hostConfig.config.system.build.toplevel
)
self.nixosConfigurations;
};
}

View File

@@ -1,18 +1,32 @@
{
inputs,
...
}:
{
{inputs, ...}: {
flake.overlays = {
modifications = final: prev: {
omasnap = prev.callPackage ../../packages/omasnap.nix {};
tnvim = inputs.tnvim.packages.${prev.stdenv.hostPlatform.system}.default;
tpanel = inputs.tpanel.packages.${prev.stdenv.hostPlatform.system}.default;
tshell = inputs.tshell.packages.${prev.stdenv.hostPlatform.system}.default;
trok = inputs.trok.packages.${prev.stdenv.hostPlatform.system}.default;
tfolio = inputs.tfolio.packages.${prev.stdenv.hostPlatform.system}.default;
cyber-tux = inputs.cyber-tux.packages.${prev.stdenv.hostPlatform.system}.default;
ags = inputs.tpanel.packages.${prev.stdenv.hostPlatform.system}.ags.default;
wezterm-git = inputs.wezterm-flake.packages.${prev.stdenv.hostPlatform.system}.default;
hyprland-git = inputs.hyprland.packages.${prev.stdenv.hostPlatform.system};
awww = inputs.awww.packages.${prev.stdenv.hostPlatform.system}.awww;
vicinae-extensions = inputs.vicinae-extensions.packages.${prev.stdenv.hostPlatform.system};
voxtype = inputs.voxtype.packages.${prev.stdenv.hostPlatform.system};
opencode-git = inputs.opencode.packages.${prev.stdenv.hostPlatform.system}.default;
nix-index-small =
inputs.nix-index-database.packages.${prev.stdenv.hostPlatform.system}.nix-index-with-small-db;
davinci-resolve = prev.davinci-resolve.override {
runCommandLocal = name: env: cmd:
if prev.lib.hasSuffix "-src.zip" name
then
prev.runCommandLocal name (env
// {
outputHash = "sha256-+3SB32EHpH9/0hM3h8CrO6f7V4ZAmxUFh3P8m6QDeO0=";
})
cmd
else prev.runCommandLocal name env cmd;
};
};
stable-packages = final: _prev: {
@@ -23,14 +37,18 @@
};
nur = inputs.nur.overlays.default;
copyparty = inputs.copyparty.overlays.default;
llm-agents = inputs.llm-agents.overlays.shared-nixpkgs;
};
perSystem =
{ system, ... }:
{
_module.args.pkgs = import inputs.nixpkgs {
perSystem = {system, ...}: let
pkgs = import inputs.nixpkgs {
inherit system;
overlays = builtins.attrValues inputs.self.overlays;
};
in {
_module.args.pkgs = pkgs;
packages.omasnap = pkgs.omasnap;
};
}

View File

@@ -1,5 +1,4 @@
{ inputs, ... }:
{
{inputs, ...}: {
imports = [
inputs.treefmt-nix.flakeModule
];
@@ -9,7 +8,7 @@
projectRootFile = "flake.nix";
flakeCheck = true;
programs = {
nixfmt.enable = true;
alejandra.enable = true;
};
};
};

View File

@@ -1,7 +1,5 @@
{
flake.modules.homeManager.core =
{ userName, ... }:
{
flake.modules.homeManager.core = {userName, ...}: {
programs.home-manager.enable = true;
systemd.user.startServices = "sd-switch";

View File

@@ -1,12 +1,9 @@
{ inputs, ... }:
{
flake.modules.homeManager.core =
{
{inputs, ...}: {
flake.modules.homeManager.core = {
lib,
osConfig ? {},
...
}:
{
}: {
nixpkgs = lib.mkIf (!(osConfig.home-manager.useGlobalPkgs or false)) {
config = {
allowUnfree = true;

View File

@@ -1,12 +1,10 @@
{
flake.modules.homeManager.desktop =
{
flake.modules.homeManager.desktop = {
pkgs,
config,
...
}:
let
configDir = "${config.xdg.configHome}/BraveSoftware/Brave-Browser";
}: let
configDir = "${config.xdg.configHome}/BraveSoftware/Brave-Origin";
extensionJson = ext: {
name = "${configDir}/External Extensions/${ext.id}.json";
@@ -22,17 +20,18 @@
{id = "bfnaelmomeimhlpmgjnjophhpkkoljpa";} # Phantom
{id = "eimadpbcbfnmbkopoojfekhnkhdbieeh";} # DarkReader
];
in
{
in {
programs.chromium = {
enable = true;
package = pkgs.brave;
package = pkgs.brave-origin;
commandLineArgs = [
"--disable-features=WebRtcAllowInputVolumeAdjustment"
"--force-device-scale-factor=1.0"
];
};
home.packages = [pkgs.brave];
home.file = builtins.listToAttrs (map extensionJson extensions);
};
}

View File

@@ -1,7 +1,9 @@
{
flake.modules.homeManager.desktop =
{ inputs, userName, ... }:
{
flake.modules.homeManager.desktop = {
inputs,
userName,
...
}: {
imports = [
inputs.nixcord.homeModules.nixcord
];
@@ -18,11 +20,22 @@
frameless = true;
plugins = {
hideMedia.enable = true;
anonymiseFileNames.enable = true;
copyFileContents.enable = true;
noTypingAnimation.enable = true;
readAllNotificationsButton.enable = true;
silentTyping.enable = true;
validUser.enable = true;
biggerStreamPreview.enable = true;
ignoreActivities = {
enable = true;
ignorePlaying = true;
ignoreWatching = true;
};
sortFriendRequests = {
enable = true;
showDates = true;
};
};
};
dorion = {

View File

@@ -1,11 +1,9 @@
{
flake.modules.homeManager.desktop =
{
flake.modules.homeManager.desktop = {
pkgs,
userName,
...
}:
{
}: {
programs.firefox = {
enable = true;

View File

@@ -13,6 +13,8 @@
font-size = 12;
font-family = "JetBrainsMono Nerd Font";
theme = "poimandres";
custom-shader = "shaders/cursor_warp.glsl";
custom-shader-animation = "always";
};
themes = {

View File

@@ -1,17 +1,19 @@
{
flake.modules.homeManager.desktop =
{ config, pkgs, ... }:
{
flake.modules.homeManager.desktop = {
config,
pkgs,
...
}: {
# TODO: Hyprland 0.55 switched to Lua-based configuration.
# Until the Home Manager module is updated, we symlink our config instead.
# wayland.windowManager.hyprland = {
# enable = true;
# package = null;
# portalPackage = null;
# xwayland.enable = true;
# systemd.variables = [ "--all" ];
# };
# HM module is updated but I'm too lazy at this point so we symlink our config instead.
wayland.windowManager.hyprland = {
enable = true;
package = null;
portalPackage = null;
xwayland.enable = true;
configType = "hyprlang";
systemd.variables = ["--all"];
};
home.file = {
".config/hypr/config".source =
@@ -28,6 +30,7 @@
hyprshot
wl-clipboard
wl-screenrec
omasnap
(writeShellScriptBin "hypr-screenshot" ''
hyprshot -m region -r ppm - | satty --filename -
'')

View File

@@ -0,0 +1,86 @@
{
flake.modules.homeManager.desktop = {pkgs, ...}: {
programs.kitty = {
enable = true;
package = pkgs.kitty;
font = {
name = "JetBrainsMono Nerd Font";
size = 12.0;
};
shellIntegration.enableZshIntegration = true;
settings = {
background_opacity = "1.0";
enable_audio_bell = false;
confirm_os_window_close = 0;
cursor_trail = 3;
# Window
window_padding_width = 10;
foreground = "#f1f1f1";
background = "#0f0f0f";
# Borders
active_border_color = "#3d59a1";
inactive_border_color = "#101014";
bell_border_color = "#fffac2";
# Colors
color0 = "#0f0f0f";
color8 = "#a6accd";
color1 = "#d0679d";
color9 = "#d0679d";
color2 = "#5de4c7";
color10 = "#5de4c7";
color3 = "#fffac2";
color11 = "#fffac2";
color4 = "#89ddff";
color12 = "#add7ff";
color5 = "#fcc5e9";
color13 = "#fae4fc";
color6 = "#add7ff";
color14 = "#89ddff";
color7 = "#ffffff";
color15 = "#ffffff";
# Cursor
cursor = "#ffffff";
cursor_text_color = "#0f0f0f";
# Selection
selection_foreground = "none";
selection_background = "#28344a";
# URLs
url_color = "#5de4c7";
# Tab bar
tab_bar_edge = "bottom";
tab_bar_style = "fade";
tab_fade = "1";
active_tab_foreground = "#3d59a1";
active_tab_background = "#16161e";
active_tab_font_style = "bold";
inactive_tab_foreground = "#787c99";
inactive_tab_background = "#16161e";
inactive_tab_font_style = "bold";
tab_bar_background = "#101014";
};
};
};
}

View File

@@ -1,17 +1,13 @@
{ inputs, ... }:
{
flake.modules.homeManager.desktop =
{
{inputs, ...}: {
flake.modules.homeManager.desktop = {
config,
pkgs,
lib,
...
}:
with lib;
let
with lib; let
cfg = config.tnix.services.lan-mouse;
in
{
in {
imports = [inputs.lan-mouse.homeManagerModules.default];
options.tnix.services.lan-mouse = {
@@ -28,7 +24,6 @@
};
config = mkIf cfg.enable {
programs.lan-mouse = {
enable = true;
systemd = true;

View File

@@ -1,17 +1,13 @@
{ inputs, ... }:
{
flake.modules.homeManager.desktop =
{
{inputs, ...}: {
flake.modules.homeManager.desktop = {
config,
pkgs,
lib,
...
}:
with lib;
let
with lib; let
cfg = config.tnix.desktop.mangowm;
in
{
in {
imports = [
inputs.mango.hmModules.mango
];

View File

@@ -1,13 +1,10 @@
{
flake.modules.homeManager.desktop =
{ pkgs, ... }:
{
flake.modules.homeManager.desktop = {pkgs, ...}: {
programs.mpv = {
enable = true;
scripts = (
with pkgs.mpvScripts;
[
with pkgs.mpvScripts; [
modernz
thumbfast
mpris

View File

@@ -0,0 +1,77 @@
{inputs, ...}: {
flake.modules.nixos.desktop = {
imports = [
inputs.serpantinum.nixosModules.default
];
programs.serpantinum.enable = true;
};
flake.modules.homeManager.desktop = {pkgs, ...}: {
imports = [
inputs.serpantinum.homeManagerModules.default
];
home.packages = with pkgs; [pulseaudioFull];
programs.serpantinum = {
enable = true;
systemd.enable = true;
settings = {
wallpaperDir = "/home/tux/Wallpapers";
general = {
language = "en";
weatherUnit = "metric";
weatherInterval = 30;
avatarPath = "/home/tux/Wallpapers/tux.png";
muteSfx = true;
};
bar = {
position = "top";
style = "modular";
time = {
format = "hh:mm:ss A";
};
width = 5;
workspaceCount = 7;
modules = {
left = [
"left"
"workspaces"
"sysmon"
"wifi"
];
center = ["vis"];
right = [
"media"
"vol"
"bat"
"tray"
"timedate"
];
};
};
theme = {
fontFamily = "JetBrains Mono SemiBold";
borderRadius = 12;
matugen = true;
};
notifications = {
dnd = false;
position = "top right";
sound = true;
};
idle = {
enabled = true;
manualInhibit = true;
};
};
};
};
}

View File

@@ -1,32 +1,30 @@
{
flake.modules.homeManager.desktop =
{ pkgs, ... }:
{
flake.modules.homeManager.desktop = {pkgs, ...}: {
home.pointerCursor = {
enable = true;
package = pkgs.bibata-cursors;
name = "Bibata-Modern-Ice";
size = 28;
size = 24;
};
qt = {
enable = true;
style = {
name = "Breeze";
package = pkgs.kdePackages.breeze;
};
style.name = "adwaita-dark";
};
gtk = {
enable = true;
theme = {
name = "Materia-dark";
package = pkgs.materia-theme;
name = "adw-gtk3-dark";
package = pkgs.adw-gtk3;
};
iconTheme = {
package = pkgs.tela-icon-theme;
name = "Tela-black";
};
};
# Make GTK4/libadwaita apps prefer dark too (they ignore gtk.theme).
dconf.settings."org/gnome/desktop/interface".color-scheme = "prefer-dark";
};
}

View File

@@ -1,10 +1,5 @@
{
flake.modules.homeManager.desktop =
{
pkgs,
...
}:
{
flake.modules.homeManager.desktop = {pkgs, ...}: {
programs.vicinae = {
enable = true;
systemd = {
@@ -14,20 +9,16 @@
useLayerShell = true;
extensions = with pkgs.vicinae-extensions; [
# @TODO broken in upstream repo
# bluetooth
nix
ssh
awww-switcher
process-manager
pulseaudio
wifi-commander
port-killer
silverbullet
];
settings = {
close_on_focus_loss = true;
close_on_focus_loss = false;
consider_preedit = true;
pop_to_root_on_close = true;
favicon_service = "twenty";

View File

@@ -0,0 +1,26 @@
{inputs, ...}: {
flake.modules.homeManager.desktop = {pkgs, ...}: {
imports = [
inputs.voxtype.homeManagerModules.default
];
programs.voxtype = {
enable = true;
package = pkgs.voxtype.onnx-cuda;
engine = "parakeet";
model.path = "/home/tux/.local/share/voxtype/models/parakeet-tdt-0.6b-v3";
service.enable = true;
settings = {
hotkey.enabled = false;
whisper = {
language = "en";
on_demand_loading = true;
};
parakeet = {
on_demand_loading = true;
};
};
};
};
}

View File

@@ -1,7 +1,5 @@
{
flake.modules.homeManager.desktop =
{ pkgs, ... }:
{
flake.modules.homeManager.desktop = {pkgs, ...}: {
programs.wezterm = {
enable = true;
package = pkgs.wezterm-git;

View File

@@ -29,6 +29,25 @@
diagnostics = false;
metrics = false;
};
agent = {
dock = "right";
favorite_models = [];
model_parameters = [];
};
collaboration_panel = {
button = false;
};
agent_servers = {
opencode = {
default_config_options = {
model = "opencode-go/deepseek-v4.1-flash";
};
type = "registry";
};
};
};
};
};

View File

@@ -0,0 +1,8 @@
{
flake.modules.homeManager.desktop = {osConfig, ...}: {
programs.lutris = {
enable = true;
steamPackage = osConfig.programs.steam.package;
};
};
}

View File

@@ -1,11 +1,9 @@
{
flake.modules.homeManager.shell =
{
flake.modules.homeManager.shell = {
userName,
userEmail,
...
}:
{
}: {
programs.git = {
enable = true;
signing = {

View File

@@ -0,0 +1,7 @@
{
flake.modules.homeManager.shell = {
programs.gh = {
enable = true;
};
};
}

View File

@@ -87,26 +87,25 @@
title = "AI Generated Commit Messages";
key = "CommitMsg";
command = ''
bash -c "
# Check for staged changes
diff=\$(git diff --cached | head -n 10)
if [ -z \"\$diff\" ]; then
echo \"No changes in staging. Add changes first.\"
bash -lc '
diff=$(git diff --cached)
if [ -z "$diff" ]; then
echo "No changes in staging. Add changes first."
exit 1
fi
SELECTED_TYPE=\"{{.Form.Type}}\"
COMMITS_TO_SUGGEST=8
SELECTED_TYPE="{{.Form.Type}}"
COMMITS_TO_SUGGEST=4
opencode run -m \"google/gemini-2.5-flash-lite\" \"
opencode run --format json --model=google/gemini-3.5-flash-lite --variant=none "
You are an expert at writing Git commits. Your job is to write commit messages that follow the Conventional Commits format.
The user has selected: \$SELECTED_TYPE
The user has selected: $SELECTED_TYPE
Your task is to:
1. Analyze the code changes
2. Determine the most appropriate commit type (if user selected 'ai-defined')
3. Determine an appropriate scope (component/area affected)
2. Determine the most appropriate commit type if user selected ai-defined
3. Determine an appropriate scope, component, or area affected
4. Decide if this is a breaking change
5. Write clear, concise commit messages
@@ -120,48 +119,36 @@
- test: Adding missing tests or correcting existing tests
- build: Changes that affect the build system or external dependencies
- ci: Changes to CI configuration files and scripts
- chore: Other changes that don't modify src or test files
- chore: Other changes that do not modify src or test files
- revert: Reverts a previous commit
Follow these guidelines:
- Structure: <type>(<scope>): <description>
- If user selected 'ai-defined', analyze the changes and pick the most suitable type
- If user selected a specific type, use that type: \$SELECTED_TYPE
- Add scope in parentheses if applicable (e.g., auth, api, ui, config)
- Use exclamation mark (!) after type/scope for breaking changes: type(scope)!: description
- Use lowercase for description (except proper nouns)
- Use imperative mood (\\\"add\\\", not \\\"added\\\")
- If user selected ai-defined, analyze the changes and pick the most suitable type
- If user selected a specific type, use that type: $SELECTED_TYPE
- Add scope in parentheses if applicable, for example auth, api, ui, config
- Use exclamation mark after type or scope for breaking changes: type(scope)!: description
- Use lowercase for description except proper nouns
- Use imperative mood: add, not added
- Keep description under 50 characters when possible
- No period at the end of subject line
Examples:
- feat(auth): add OAuth login support
- fix(api): handle null response in user endpoint
- docs(readme): update installation instructions
- style(ui): improve button spacing consistency
- refactor(database): simplify query builder logic
- test(auth): add unit tests for login flow
- build(deps): upgrade React to version 18
- ci(github): fix deployment workflow
- chore(config): update ESLint rules
- perf(api)!: optimize database queries
IMPORTANT:
- Generate exactly \$COMMITS_TO_SUGGEST different commit message options
- If user selected 'ai-defined', you can use different types for different options
- Generate exactly $COMMITS_TO_SUGGEST different commit message options
- If user selected ai-defined, you can use different types for different options
- If user selected a specific type, all messages must use that type
- Only return commit messages, no explanations
- Do not use markdown code blocks
- One message per line
Previous commits for context:
\$(git log --oneline -10)
$(git log --oneline -10)
Changes to analyze:
\$(git diff --cached --stat)
\$(git diff --cached)
\"
"
$(git diff --cached --stat)
$diff
" | JQ_TEXT=text jq -r "select(.type == env.JQ_TEXT) | .part.text? // empty"
'
'';
}
];

View File

@@ -1,7 +1,5 @@
{
flake.modules.homeManager.shell =
{ pkgs, ... }:
{
flake.modules.homeManager.shell = {pkgs, ...}: {
home.packages = with pkgs; [
systemctl-tui
zip
@@ -11,6 +9,78 @@
jq
dig
lsof
trok
(writeShellScriptBin "hm-override" ''
#!/usr/bin/env bash
set -euo pipefail
usage() {
echo "Usage:"
echo " $0 <filename> Override symlink"
echo " $0 <filename> --restore Restore symlink"
echo " $0 <filename> -r Restore symlink"
exit 1
}
if [[ $# -lt 1 || $# -gt 2 ]]; then
usage
fi
FILE="$1"
LINK_BACKUP="''${FILE}.backup-link"
# Restore
if [[ "''${2:-}" == "--restore" || "''${2:-}" == "-r" ]]; then
if [[ ! -f "$LINK_BACKUP" ]]; then
echo "Error: no backup symlink found: $LINK_BACKUP"
exit 1
fi
TARGET="$(cat "$LINK_BACKUP")"
# Remove the temporary override.
rm -f "$FILE"
# Restore the original symlink.
ln -s "$TARGET" "$FILE"
# Remove the temporary symlink target backup.
rm "$LINK_BACKUP"
echo "Restored: $FILE -> $TARGET"
exit 0
fi
# Override mode
if [[ ! -L "$FILE" ]]; then
echo "Error: $FILE is not a symlink"
exit 1
fi
if [[ -e "$LINK_BACKUP" ]]; then
echo "Error: backup already exists: $LINK_BACKUP"
echo "Restore the existing override before running again."
exit 1
fi
# Remember the original symlink target.
TARGET="$(readlink "$FILE")"
printf '%s\n' "$TARGET" > "$LINK_BACKUP"
# Copy the contents before removing the symlink.
cp "$FILE" "$FILE.tmp"
# Replace the symlink with a regular writable file.
rm "$FILE"
mv "$FILE.tmp" "$FILE"
chmod u+w "$FILE"
echo "Overridden: $FILE"
echo "Original: $FILE -> $TARGET"
'')
];
};
}

View File

@@ -1,7 +1,5 @@
{
flake.modules.homeManager.shell =
{ pkgs, ... }:
{
flake.modules.homeManager.shell = {pkgs, ...}: {
home.file = {
".config/nvim" = {
recursive = true;
@@ -14,8 +12,6 @@
enable = true;
defaultEditor = true;
};
vim.enable = true;
};
home = {

View File

@@ -1,12 +1,13 @@
{
flake.modules.homeManager.shell = {
flake.modules.homeManager.shell = {pkgs, ...}: {
programs.opencode = {
enable = true;
package = pkgs.opencode-git;
tui = {
theme = "system";
};
settings = {
model = "opencode-go/kimi-k3";
model = "opencode-go/deepseek-v4.1-flash";
provider = {
google = {
options = {
@@ -23,8 +24,14 @@
apiKey = "{file:/run/secrets/opencode-go-api-key}";
};
};
zai-coding-plan = {
options = {
apiKey = "{file:/run/secrets/zai-coding-plan-api-key}";
};
};
};
plugin = ["@dietrichgebert/ponytail"];
};
};
};
}

View File

@@ -1,58 +1,47 @@
{
flake.modules.homeManager.shell =
{ pkgs, ... }:
let
flake.modules.homeManager.shell = {pkgs, ...}: let
bg = "default";
fg = "default";
bg2 = "brightblack";
fg2 = "white";
color = c: "#{@${c}}";
indicator =
let
indicator = let
accent = color "indicator_color";
content = " ";
in
"#[reverse,fg=${accent}]#{?client_prefix,${content},}";
in "#[reverse,fg=${accent}]#{?client_prefix,${content},}";
current_window =
let
current_window = let
accent = color "main_accent";
index = "#[reverse,fg=${accent},bg=${fg}] #I ";
name = "#[fg=${bg2},bg=${fg2}] #W ";
# flags = "#{?window_flags,#{window_flags}, }";
in
"${index}${name}";
in "${index}${name}";
window_status =
let
window_status = let
accent = color "window_color";
index = "#[reverse,fg=${accent},bg=${fg}] #I ";
name = "#[fg=${bg2},bg=${fg2}] #W ";
# flags = "#{?window_flags,#{window_flags}, }";
in
"${index}${name}";
in "${index}${name}";
battery =
let
battery = let
percentage = pkgs.writeShellScript "percentage" (
if pkgs.stdenv.isDarwin then
''
if pkgs.stdenv.isDarwin
then ''
echo $(pmset -g batt | grep -o "[0-9]\+%" | tr '%' ' ')
''
else
''
else ''
path="/org/freedesktop/UPower/devices/DisplayDevice"
echo $(${pkgs.upower}/bin/upower -i $path | grep -o "[0-9]\+%" | tr '%' ' ')
''
);
state = pkgs.writeShellScript "state" (
if pkgs.stdenv.isDarwin then
''
if pkgs.stdenv.isDarwin
then ''
echo $(pmset -g batt | awk '{print $4}')
''
else
''
else ''
path="/org/freedesktop/UPower/devices/DisplayDevice"
echo $(${pkgs.upower}/bin/upower -i $path | grep state | awk '{print $2}')
''
@@ -77,31 +66,25 @@
elif [ $percentage -ge 0 ]; then echo "red"
fi
'';
in
"#[fg=#(${color})]#(${icon}) #[fg=${fg}]#(${percentage})%";
in "#[fg=#(${color})]#(${icon}) #[fg=${fg}]#(${percentage})%";
pwd =
let
pwd = let
accent = color "main_accent";
icon = "#[fg=${accent}] ";
format = "#[fg=${fg}]#{b:pane_current_path}";
in
"${icon}${format}";
in "${icon}${format}";
git =
let
git = let
icon = pkgs.writeShellScript "branch" ''
git -C "$1" branch && echo " "
'';
branch = pkgs.writeShellScript "branch" ''
git -C "$1" rev-parse --abbrev-ref HEAD
'';
in
"#[fg=magenta]#(${icon} #{pane_current_path})#(${branch} #{pane_current_path})";
in "#[fg=magenta]#(${icon} #{pane_current_path})#(${branch} #{pane_current_path})";
separator = "#[fg=${fg}]|";
in
{
in {
programs.tmux = {
enable = true;
baseIndex = 1;

View File

@@ -1,8 +1,5 @@
{ lib, ... }:
{
flake.modules.homeManager.shell =
{ pkgs, ... }:
{
{lib, ...}: {
flake.modules.homeManager.shell = {pkgs, ...}: {
programs.zsh = {
enable = true;
history = {
@@ -21,6 +18,10 @@
bindkey "^A" vi-beginning-of-line
bindkey "^E" vi-end-of-line
bindkey '^R' fzf-history-widget
PATH=$PATH:~/.cargo/bin:~/.local/bin
alias stui='systemctl-tui'
alias vim='nvim --clean'
'';
};
};

View File

@@ -1,17 +1,23 @@
{ config, ... }:
{
flake.modules.nixos.alpha =
{
inputs,
config,
...
}: {
flake.modules.nixos.alpha = {
hostName,
userName,
...
}@innerArgs:
{
imports = with config.flake.modules.nixos; [
} @ innerArgs: {
imports = with config.flake.modules.nixos;
[
boot
networking
virtualisation
services
]
++ [
inputs.trok.nixosModules.default
inputs.tfolio.nixosModules.default
];
tnix = {
@@ -34,26 +40,35 @@
};
networking = {
openssh.enable = true;
openssh = {
enable = true;
ports = [
23
];
};
netbird-client.enable = true;
};
services = {
nginx = {
pangolin = {
enable = true;
domain = "lab.tux.rs";
domain = "pangolin.lab.tux.rs";
baseDomain = "lab.tux.rs";
environmentFile = innerArgs.config.sops.secrets."pangolin".path;
};
uptime-kuma = {
enable = true;
domain = "status.lab.tux.rs";
};
mediaflow-proxy = {
enable = true;
port = 8888;
environment = {
APP__SERVER__HOST = "0.0.0.0";
APP__SERVER__PORT = "8888";
environmentFile = innerArgs.config.sops.secrets."mediaflow-proxy".path;
};
environmentFile = innerArgs.config.sops.secrets."mediaflow-proxy".path;
trok = {
enable = true;
};
};
@@ -83,6 +98,11 @@
owner = userName;
};
zai-coding-plan-api-key = {
sopsFile = ./secrets.yaml;
owner = userName;
};
netbird-key = {
sopsFile = ./secrets.yaml;
owner = userName;
@@ -103,6 +123,10 @@
mediaflow-proxy = {
sopsFile = ./secrets.yaml;
};
pangolin = {
sopsFile = ./secrets.yaml;
};
};
# --- Networking ---
@@ -112,6 +136,8 @@
firewall.enable = false;
};
services.tfolio.enable = true;
system.stateVersion = "26.05";
};
}

View File

@@ -1,30 +0,0 @@
{
inputs,
config,
...
}:
let
hostName = "alpha";
userName = "tux";
userEmail = "t@tux.rs";
system = "x86_64-linux";
unstable = true;
nixpkgs = if unstable then inputs.nixpkgs else inputs.nixpkgs-stable;
in
{
flake.nixosConfigurations."${hostName}" = nixpkgs.lib.nixosSystem {
inherit system;
specialArgs = {
inherit
hostName
userName
userEmail
system
;
};
modules = [
config.flake.modules.nixos.core
config.flake.modules.nixos.${hostName}
];
};
}

View File

@@ -1,12 +1,12 @@
{ inputs, ... }:
{
flake.modules.nixos.alpha =
{ config, lib, ... }:
let
{inputs, ...}: {
flake.modules.nixos.alpha = {
config,
lib,
...
}: let
hasOptinPersistence = config.tnix.boot.impermanence.enable;
isLegacy = config.tnix.boot.legacy.enable;
in
{
in {
imports = [
inputs.disko.nixosModules.disko
];
@@ -16,7 +16,8 @@
type = "disk";
content = {
type = "gpt";
partitions = {
partitions =
{
ESP = {
size = "1G";
type = "EF00";
@@ -36,7 +37,8 @@
content = {
type = "btrfs";
# Base subvolumes that always exist
subvolumes = {
subvolumes =
{
"/root" = {
mountOptions = [
"compress=zstd"

View File

@@ -1,12 +1,10 @@
{
flake.modules.nixos.alpha =
{
flake.modules.nixos.alpha = {
lib,
modulesPath,
system,
...
}:
{
}: {
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];

View File

@@ -1,4 +1,3 @@
{ ... }:
{
flake.modules.homeManager.alpha = {
home.stateVersion = "26.05";

View File

@@ -2,12 +2,14 @@ tux-password: ENC[AES256_GCM,data:tvx3nMoIuQSotxHDWLs7UesnyWY3u3EwkqAIzCw3Z2AJse
gemini-api-key: ENC[AES256_GCM,data:Bo3Z5Jhce0UOBn77I2AcrXYbBgPLDx0eOjPC8J63E/VWNhMPbbxb,iv:iWOsTACOMcK3oqq848WnJ5Ku3tYy1aadmLB4IMgoyqg=,tag:BPzlXoP8/iJaj8c/YFCWyg==,type:str]
openrouter-api-key: ENC[AES256_GCM,data:D+/ImUTg7UvBTh0fMlWMZ0O/GsQS/R4Hz+CO4l42R6mn+zk+udvw79BctXdWWyrFf2ZNOTJ/99QTtWOUOvHISWaEJogXyb+93g==,iv:c7OtgBu1Zaf7lA4InIsKOAPbAvTl3gaO7QGCFNx21Bo=,tag:KXiASj/qC1YzK6DUox57ug==,type:str]
opencode-go-api-key: ENC[AES256_GCM,data:ipKkNcRqBERIQ6f6yFzVm999s+UwJys4elHWhzpL441RfOaG9MmRWMcD+wRLJ7DSWFjYu6uUPF7TKez8J6abWeKDgg==,iv:FDSYE3R8zKVxWiP2S/sCVcwEu3fEXg/hCeqCRSF+c6g=,tag:5RDuMFGMoN6xwAYj0HiyjQ==,type:str]
zai-coding-plan-api-key: ENC[AES256_GCM,data:HrNfR+Ux/Iyt4qkD1uXzDFQb+l0ltMMrbRahEG3pofFbw98VXfRFbhspcxh9vEyqkw==,iv:lzkLxPV7Q38dn0IEgtchVMrvnVBz4e5q282704x/hmU=,tag:IKzE6Tp6D93nJHoEvCPGBQ==,type:str]
netbird-key: ENC[AES256_GCM,data:NilfyafnGhFVYD6q4+jJQxlhXNdNC8BQ1CZfu8a5wc693Y1h,iv:Rpl0OpkQdBMPpIJ08t9Z0AjDAW6c97pFZKO1KPu8ipY=,tag:du3d0SQWuqJtJSwhSgJE4g==,type:str]
cloudflare-credentials:
email: ENC[AES256_GCM,data:K9L6H4dqNNgbCFg=,iv:jirDJb+Y2sXrup6/doRmOdd8tV7zLnttcgG75r4Fs04=,tag:XeyMVC+Q9TEuTxSfOeR2Uw==,type:str]
dns-api-token: ENC[AES256_GCM,data:aLZqasMaxpv08KuGqhe66J/jHqEnMNdZrYtIurv01xk2/5OW//PaHQ==,iv:7tZYpOT27n/RWaj1CqiZbhA/g3aKbxjdkMA6SuW/YpQ=,tag:oetxyD9XMrihSLyDvl7qfw==,type:str]
aiostreams: ENC[AES256_GCM,data:HeV4NONoqTti/4GBpzYaUEGgrSpDfCfcGJ3kbZAUtg5hm1zQCcelx3N4b/woSjaNZrDj98P5R3oZUkgVfv0RS2PKdJc3EdLaPFwXcuJ+W0U373sryU85uIIZi4BvQ4LyCCpuclPU5dgQmb9rzbIvhlu/ftfpKJsRbH2bUgMMo2nohMWUtg==,iv:V60U/omnN+09cSOQGvwwN8DC6/D++MB0axQyzIG97zo=,tag:vwNbXRj3CS+okb0NSwxgYw==,type:str]
mediaflow-proxy: ENC[AES256_GCM,data:jk2eYyOmO3XpqFNo3jucB/VvL6pWBGrquYi/OpIwvSPqjbo=,iv:DIsqykv77/TlLhT9uIPGJRBlCQHVdhcuYlc56qQGZgk=,tag:phMXArjIrNNI51U9hpaUzg==,type:str]
pangolin: ENC[AES256_GCM,data:G6TscTsWsyvBM/L2boxpDIrczV0cycQNT51mOf0vPKOHdifdBxT6Q3PY+Ms5arc=,iv:qh655lwIcD89D8ufIzJWYrDqPKGCrGMUXsgcFYwm9zY=,tag:kGlGzaOADZyY6gsLuI6EHw==,type:str]
sops:
age:
- enc: |
@@ -28,7 +30,7 @@ sops:
4TkObqH8ddGpbd7cX5a/wboTjYuEdAviWxjK2oBPgtcFc1f03X3tmA==
-----END AGE ENCRYPTED FILE-----
recipient: age1mzxxxzhy3us3rd960ufqv7vlxj5cnug86md6x69llg9ujzw2pqws057llf
lastmodified: "2026-07-13T15:24:16Z"
mac: ENC[AES256_GCM,data:5NOOqdtJJj0ph3apCwaokiRySW9QIlmR01I7fFZDT2sNHqrJSgVVN8U5WtOnM1S61ID7MRxGLpSegU9M8lPnZd2WmhGIlactJjoSTE9+Xy5hj4m9mdWW0TZg9w4qmyIo8o8DuoDa2LiyilT97XaMnvoDz2ZqWcJxi44URLmk9o0=,iv:czkDfHv9eg1VzyMUT48W4OmmeSaUu6TzeYcyYSBu/+w=,tag:140ldPXqetX3733QnoOU0g==,type:str]
lastmodified: "2026-09-16T14:21:00Z"
mac: ENC[AES256_GCM,data:Aqg1cboHKW5QrJooVIqgbHTFg9EpTEnfCv/RRSp0efzyXvDrR7eG5WTvJPE9IbrmS190yvOlT0fw1Bhzyr8kiyoO71sbyUessw5IMUGcLP+m2FNtt8osc7fSTGseojv3MXBndOMDEOpT+Clv6hbv/rr5eGbb05oK6rW97/pDDfU=,iv:s/9PAHHQ0mHQJosKGclSnumHqm6CG3fDVKD5eT4Q1Y0=,tag:3pgycAwYUz9aEOy4/aW30Q==,type:str]
unencrypted_suffix: _unencrypted
version: 3.13.1
version: 3.13.3

View File

@@ -1,12 +1,10 @@
{ config, ... }:
{
flake.modules.nixos.arcturus =
{
{config, ...}: {
flake.modules.nixos.arcturus = {
pkgs,
hostName,
userName,
...
}@innerArgs:
{
} @ innerArgs: {
imports = with config.flake.modules.nixos; [
boot
networking
@@ -24,7 +22,10 @@
home = {
directories = [
"Distrobox"
".bun"
".rustup"
".config/sops"
".config/nix"
".local/share/nvim"
".local/share/opencode"
".local/share/zsh"
@@ -42,13 +43,50 @@
networking = {
openssh.enable = true;
netbird-client.enable = true;
newt = {
enable = true;
environmentFile = innerArgs.config.sops.secrets.newt.path;
};
};
services = {
hermes-agent = {
enable = true;
environmentFiles = [innerArgs.config.sops.secrets.hermes.path];
};
cyber-tux = {
enable = true;
environmentFile = innerArgs.config.sops.secrets.discord-token.path;
};
vaultwarden = {
enable = true;
domain = "bw.lab.tux.rs";
configurePangolin = true;
};
copyparty = {
enable = true;
domain = "files.lab.tux.rs";
accounts.${userName}.passwordFile = innerArgs.config.sops.secrets.copyparty.path;
volumes = {
"/" = {
path = "/var/lib/copyparty/data";
access = {
r = "*";
rwmdgGha = [userName];
};
};
};
configurePangolin = true;
};
coder = {
enable = true;
domain = "coder.lab.tux.rs";
configurePangolin = true;
};
};
virtualisation = {
@@ -82,10 +120,29 @@
owner = userName;
};
zai-coding-plan-api-key = {
sopsFile = ./secrets.yaml;
owner = userName;
};
netbird-key = {
sopsFile = ./secrets.yaml;
owner = userName;
};
newt = {
sopsFile = ./secrets.yaml;
owner = userName;
};
copyparty = {
sopsFile = ./secrets.yaml;
owner = innerArgs.config.services.copyparty.user;
};
hermes = {
sopsFile = ./secrets.yaml;
};
};
# --- Networking ---
@@ -109,6 +166,10 @@
firewall.enable = false;
};
environment.systemPackages = with pkgs; [
impala
];
system.stateVersion = "26.05";
};
}

View File

@@ -1,30 +0,0 @@
{
inputs,
config,
...
}:
let
hostName = "arcturus";
userName = "tux";
userEmail = "t@tux.rs";
system = "x86_64-linux";
unstable = true;
nixpkgs = if unstable then inputs.nixpkgs else inputs.nixpkgs-stable;
in
{
flake.nixosConfigurations."${hostName}" = nixpkgs.lib.nixosSystem {
inherit system;
specialArgs = {
inherit
hostName
userName
userEmail
system
;
};
modules = [
config.flake.modules.nixos.core
config.flake.modules.nixos.${hostName}
];
};
}

View File

@@ -1,11 +1,11 @@
{ inputs, ... }:
{
flake.modules.nixos.arcturus =
{ config, lib, ... }:
let
{inputs, ...}: {
flake.modules.nixos.arcturus = {
config,
lib,
...
}: let
hasOptinPersistence = config.tnix.boot.impermanence.enable;
in
{
in {
imports = [
inputs.disko.nixosModules.disko
];
@@ -35,7 +35,8 @@
content = {
type = "btrfs";
# Base subvolumes that always exist
subvolumes = {
subvolumes =
{
"/root" = {
mountOptions = [
"compress=zstd"

View File

@@ -1,13 +1,10 @@
{ config, ... }:
{
flake.modules.nixos.arcturus =
{
{config, ...}: {
flake.modules.nixos.arcturus = {
lib,
pkgs,
system,
...
}@innerArgs:
{
} @ innerArgs: {
imports = with config.flake.modules.nixos; [
hardware
];

View File

@@ -1,4 +1,3 @@
{ ... }:
{
flake.modules.homeManager.arcturus = {
home.stateVersion = "26.05";

View File

@@ -3,11 +3,14 @@ discord-token: ENC[AES256_GCM,data:uzxkrNRRplL/1MfvPZ/EL+I8UACuZQBHZ95BSHuxW0nBj
gemini-api-key: ENC[AES256_GCM,data:gLZSoYTdKY+rwIpYiXvN9n9PGkUD6q8Oe7dHnYkjEjwDf5qpjubg,iv:ySoNgQWTu9DjvbashF4ulyYP8fJUl4yrCTeBQ0jrGmw=,tag:FctubsQv50AP78JvTb9bpQ==,type:str]
openrouter-api-key: ENC[AES256_GCM,data:6xONCl9lqOoO7b4CEyCz9607tICDUAkpglRjGS5nYq2ppg2UKqYTrWD1BGCA5Xfs/CWskniVhoNG3vscjKiYCCh9gbM6aqdmTQ==,iv:7Iwc9t00HOOBjA7URXcUO41badqYyJCkFHM/uPkLFxY=,tag:Cl39kitr2e0//HVwAdsdUQ==,type:str]
opencode-go-api-key: ENC[AES256_GCM,data:dmeRKn7TWHnqvpyPQpcEG6yHTb2bRby/rh10ytL0jHj5R+lRmNVdmqUF92GTznY9vEaB6ZYCJecWhpm8g4upNfOWBg==,iv:9UMJpAlD8gpcNiN+liu3nawoAZQKapEg7sCp561N9E8=,tag:OZlASpOa5BQaQwFWjoLCRw==,type:str]
zai-coding-plan-api-key: ENC[AES256_GCM,data:lLegmS/RIo7JoBoAyVdcS++rXS8W62cwz+zVsv4dPnlfjGFO/nVlI5InqC34sPxLRQ==,iv:BRC7eYVmdZuWwb+2k2FrnlJih63HXrcvhVp/K5t5td8=,tag:aP8x+Xcnkz2t0hn7erCkKw==,type:str]
netbird-key: ENC[AES256_GCM,data:q6eKisca04qn/CvALrvXF79MsToDhvLRLv2JTiUBAZglCC9m,iv:jj0/ZD7IDgopprTVUgSfJmdAJmUP3iqewU3dqssGYbk=,tag:6IPRdCm2FGdlTEIX7jt3qA==,type:str]
copyparty: ENC[AES256_GCM,data:QXt8IgTekg9rzFyuzpg=,iv:vJYfHqCiheq290K9TGACHNHyOWzIn60j1Kz502SE27w=,tag:ECt7Wavlqw1V6zgXiRZtUg==,type:str]
newt: ENC[AES256_GCM,data:r5Rd81ZrzrIYbXtFkypbJltoGCOYrW6P4IpwGCtaH7lqCg7wD/WMboMx13HN4Mm0J4qbBpDakpfVv9qUTrisYP1xwpKkmY1kqPlFWRZN8hzuuNS2Tv3qUjavTp5XGotVPLHj1Cg/cwGcf8EAssYTwTy7H0PgdQKwqigQD1f1s/j4iXQ=,iv:1xP38/Ayt1xvn2fJGa5zgOrVNOw2J5taG1Orx6uNgZI=,tag:H9JXu9gzyyvTPWgXaoTsiw==,type:str]
hermes: ENC[AES256_GCM,data:9A2T2LIeVGo805k5E8wPHmqfjqQ6Dp7srQrVXHLsJRk+9N9bo2pMZUvAZm9FI89zPyK7tMnmLd56Jwf+W+mmQqbupnmN66jxOxOaB0MQ9/6/1oNHvaii337ed6fviLy6hx24pEOpY3OXwSEdNftwJqzc7YXLZK3UX8thhDDdxd0TSj3VUBd0ZHDWd4NpsgtjRRyVDBjHsnF0vzSZXtomithnHqeVHpp/jWPc+ZGrpnVvU8wxNMGLlDtr4A==,iv:dYCaTygVp1hqunPmBcNaYr7JxrdxfH1pcBE6B5HMgzk=,tag:/fddnR3n6+erzWF+m/bgGQ==,type:str]
sops:
age:
- recipient: age14vktfes95f33vuefwnmuvryas7az04u76dsgyhfvsx73czkvmp2q7njkl4
enc: |
- enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA3Qkh0cmdHNGJTYmFNUFZW
c244RjlyNjlrSWh1bG1IRFFFeFZZVzhaYVdBCmd1N3JNS0IzWDlUMUJSM0pYdi9L
@@ -15,8 +18,8 @@ sops:
Z3hhRitmdEwxbzcrS0cwNTZVK1lXYlUKSFfKk7JGzxRq9weL4NKJqfmAige2O+1T
59PvEFKvvkGb6ajkzwTw0lB3UFzly6FuTnbSLY9r+oT9AMbxLoKdcQ==
-----END AGE ENCRYPTED FILE-----
- recipient: age1huqa3hc7wcxk4dpelrzny437nzrx4fnll3d8g9ahznzk268yju5qufapxy
enc: |
recipient: age14vktfes95f33vuefwnmuvryas7az04u76dsgyhfvsx73czkvmp2q7njkl4
- enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBOYlZiak1CSW1NSGt5QTRi
RjlUeG5EODVkTVJDY1RrZXJ6OU5NQ0RIOG5jCnJxZ1R6MmlGWXY2SmtaY1pQSWdZ
@@ -24,7 +27,8 @@ sops:
V3h4dUZLcktrTUZvUm44eVZOWEl4VmMKMTvajoWcktb4jVIP4HyzQiR41Wg8Gdqi
TLKEYsPQgOJ7s8P9gw2uPUY6HRz86CtiC6EbO27u0+8BbI85x1QScg==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2026-05-10T00:36:06Z"
mac: ENC[AES256_GCM,data:nD0exblrbheP1C5lK8V17V/gkHJO6s6yVjXtQWcUOLVGrzkPSxkymYBHUFMTLVyYQNLCVMc8AHkuHVuJ1tBfXNll1f6/SGtfaBQcOLct70U7nFxd/XybTUlscNp2KafJWy/n4ZUfNDbfrWN1R463CN/M50jGqJPDWYuP9ah2JcI=,iv:izQUT/+HQqJZ48X5bXobFSaWcdcXQ/7eh+SCd9i4YYo=,tag:FJlR2wI4rWQ/SDfQGtQ7AQ==,type:str]
recipient: age1huqa3hc7wcxk4dpelrzny437nzrx4fnll3d8g9ahznzk268yju5qufapxy
lastmodified: "2026-09-16T14:20:26Z"
mac: ENC[AES256_GCM,data:I33KZL3u+7jfOFu0qn4LVx2nACiURSd6RcEn0ojfT62yC/TcXlGGu4QeN1Dx4Nta77n/h8RzDTcZtiUJylLhiVBmqyMOoNaBOmLDJ+P1L7weYLoWMoaDP7IWyzttGkNTgvyv2nW5IxbdcTZwrcSlPtdupsJeNy76ATHO+eUsvGQ=,iv:FvQKGH5Vzm36huGDnMr15wQL9vsH2hsAhvu0BE/NfEI=,tag:fzAzzgmv3vjWs1VYhh4GeA==,type:str]
unencrypted_suffix: _unencrypted
version: 3.12.2
version: 3.13.3

View File

@@ -1,13 +1,10 @@
{ config, ... }:
{
flake.modules.nixos.canopus =
{
{config, ...}: {
flake.modules.nixos.canopus = {
pkgs,
hostName,
userName,
...
}:
{
}: {
imports = with config.flake.modules.nixos; [
boot
networking
@@ -27,27 +24,46 @@
directories = [
"Distrobox"
".steam"
".bun"
".rustup"
".cache/awww"
".cache/serpantinum"
".config/BraveSoftware"
".config/zed"
".config/Vencord"
".config/vesktop"
".config/sops"
".config/nix"
".config/coderv2"
".config/obs-studio"
".config/easyeffects"
".config/DankMaterialShell"
".local/share/Steam"
".local/share/lutris"
".local/share/net.lutris.Lutris"
".local/share/nvim"
".local/share/opencode"
".local/share/zsh"
".local/share/zoxide"
".local/share/voxtype"
".local/state/lazygit"
".local/share/vicinae"
".local/share/TelegramDesktop"
".local/share/GalaxyBudsClient"
".local/state/serpantinum"
".local/share/zed"
".claude"
".orca"
".config/orca"
".zcode"
".config/ZCode"
];
files = [
".wakatime.cfg"
".claude.json"
".config/gh/hosts.yml"
];
};
};
@@ -65,6 +81,8 @@
waydroid.enable = true;
distrobox.enable = true;
};
programs.nix-ld.enable = true;
};
sops.secrets = {
@@ -88,6 +106,11 @@
owner = userName;
};
zai-coding-plan-api-key = {
sopsFile = ./secrets.yaml;
owner = userName;
};
netbird-key = {
sopsFile = ./secrets.yaml;
owner = userName;
@@ -123,6 +146,12 @@
environment.systemPackages = with pkgs; [
davinci-resolve
telegram-desktop
galaxy-buds-client
impala
llm-agents.claude-code
llm-agents.orca
llm-agents.zcode
coder
];
# !!! DO NOT CHANGE THIS !!!

View File

@@ -1,30 +0,0 @@
{
inputs,
config,
...
}:
let
hostName = "canopus";
userName = "tux";
userEmail = "t@tux.rs";
system = "x86_64-linux";
unstable = true;
nixpkgs = if unstable then inputs.nixpkgs else inputs.nixpkgs-stable;
in
{
flake.nixosConfigurations."${hostName}" = nixpkgs.lib.nixosSystem {
inherit system;
specialArgs = {
inherit
hostName
userName
userEmail
system
;
};
modules = [
config.flake.modules.nixos.core
config.flake.modules.nixos.${hostName}
];
};
}

View File

@@ -1,11 +1,11 @@
{ inputs, ... }:
{
flake.modules.nixos.canopus =
{ config, lib, ... }:
let
{inputs, ...}: {
flake.modules.nixos.canopus = {
config,
lib,
...
}: let
hasOptinPersistence = config.tnix.boot.impermanence.enable;
in
{
in {
imports = [
inputs.disko.nixosModules.disko
];
@@ -43,7 +43,8 @@
content = {
type = "btrfs";
# Base subvolumes that always exist
subvolumes = {
subvolumes =
{
"/root" = {
mountOptions = [
"compress=zstd"

View File

@@ -1,19 +1,22 @@
{ inputs, config, ... }:
{
flake.modules.nixos.canopus =
{
inputs,
config,
...
}: {
flake.modules.nixos.canopus = {
lib,
pkgs,
system,
...
}@innerArgs:
{
imports =
with config.flake.modules.nixos;
} @ innerArgs: {
imports = with config.flake.modules.nixos;
[
hardware
]
++ [ inputs.nixos-hardware.nixosModules.asus-zephyrus-ga503 ];
++ [
inputs.nixos-hardware.nixosModules.asus-zephyrus-ga503
inputs.cardwire.nixosModules.default
];
boot.kernelParams = ["nvidia-drm.modeset=1"];
boot.initrd.availableKernelModules = [
@@ -43,16 +46,13 @@
power-profiles-daemon.enable = true;
upower.enable = true;
supergfxd = {
cardwire = {
enable = true;
settings = {
mode = "Hybrid";
vfio_enable = false;
vfio_save = false;
always_reboot = false;
no_logind = false;
logout_timeout_s = 180;
hotplug_type = "None";
auto_apply_gpu_state = true;
experimental_nvidia_block = true;
battery_auto_switch = true;
battery_auto_switch_mode = "hybrid";
};
};
@@ -93,42 +93,42 @@
balanced: [
(
fan: CPU,
pwm: (2, 22, 45, 68, 91, 153, 153, 153),
temp: (55, 62, 66, 70, 74, 78, 78, 78),
enabled: false,
pwm: (20, 40, 60, 85, 110, 140, 170, 200),
temp: (45, 55, 62, 68, 74, 80, 86, 92),
enabled: true,
),
(
fan: GPU,
pwm: (2, 25, 48, 71, 94, 165, 165, 165),
temp: (55, 62, 66, 70, 74, 78, 78, 78),
enabled: false,
pwm: (20, 40, 60, 85, 110, 140, 170, 200),
temp: (45, 55, 62, 68, 74, 80, 86, 92),
enabled: true,
),
],
performance: [
(
fan: CPU,
pwm: (35, 68, 79, 91, 114, 175, 175, 175),
temp: (58, 62, 66, 70, 74, 78, 78, 78),
enabled: false,
pwm: (35, 60, 90, 120, 150, 180, 220, 255),
temp: (45, 55, 62, 68, 74, 80, 86, 92),
enabled: true,
),
(
fan: GPU,
pwm: (35, 71, 84, 94, 119, 188, 188, 188),
temp: (58, 62, 66, 70, 74, 78, 78, 78),
enabled: false,
pwm: (35, 60, 90, 120, 150, 180, 220, 255),
temp: (45, 55, 62, 68, 74, 80, 86, 92),
enabled: true,
),
],
quiet: [
(
fan: CPU,
pwm: (2, 12, 22, 35, 45, 58, 79, 79),
temp: (55, 62, 66, 70, 74, 78, 82, 82),
pwm: (0, 10, 20, 35, 55, 80, 110, 140),
temp: (45, 55, 62, 68, 74, 80, 86, 92),
enabled: true,
),
(
fan: GPU,
pwm: (2, 12, 25, 35, 48, 61, 84, 84),
temp: (55, 62, 66, 70, 74, 78, 82, 82),
pwm: (0, 10, 20, 35, 55, 80, 110, 140),
temp: (45, 55, 62, 68, 74, 80, 86, 92),
enabled: true,
),
],

View File

@@ -1,5 +1,4 @@
{ config, ... }:
{
{config, ...}: {
flake.modules.homeManager.canopus = {pkgs, ...}: {
imports = with config.flake.modules.homeManager; [
desktop
@@ -27,8 +26,7 @@
enable = true;
settings = {
authorized_fingerprints = {
"f4:4b:17:61:f7:01:a4:a2:e1:c7:8c:1c:7a:f3:8b:87:14:3d:05:3d:a0:8b:cc:e7:88:d8:d8:d2:a4:c2:75:8b" =
"sirius";
"f4:4b:17:61:f7:01:a4:a2:e1:c7:8c:1c:7a:f3:8b:87:14:3d:05:3d:a0:8b:cc:e7:88:d8:d8:d2:a4:c2:75:8b" = "sirius";
};
};
};

View File

@@ -2,12 +2,12 @@ tux-password: ENC[AES256_GCM,data:Xb4/JMAZCBnBheDCJdRRGXLnMJ1ej8HbN+AUqA/+2sdYES
gemini-api-key: ENC[AES256_GCM,data:Q6+actg0oyUWiUJVy/9yZmea1QyGu2o8LfMsuAVFD6k7kp0dYIrl,iv:ukyouqrHxzVpBBE98KL6PW8P3j+seemm/e0Gl1urUcM=,tag:Z7MM3dJ414CmdxE72cdzNA==,type:str]
openrouter-api-key: ENC[AES256_GCM,data:SalhWKR6artX/kOVKZGpKSmrgsQDU/heshrdkK3wotOZ3BRn/ZqZRBldvl1JPSenMAMvE2LWUdmBQmwG/id7L7JL1O/+lUHIQw==,iv:hLlHayFJgUkWOirVLfqP0pGRBZAqGKe+EE2yG1ELGNk=,tag:0qoo0tb+xWjjQXr4n1qGmw==,type:str]
opencode-go-api-key: ENC[AES256_GCM,data:zbeTcaXJZFVfYnM/7sgblJFU9WfeosX/44KsXvrzKwiLPfGLLYYo9AFaCvWzzG6jHuSZC5OYrBWfOZv4+3omfCgglQ==,iv:LscUQE+PNhXGim9PSqc9nZIZichWSgAn/zsNxQ/HM/o=,tag:MaBCobnRM42fopiibibe5Q==,type:str]
zai-coding-plan-api-key: ENC[AES256_GCM,data:osUoFOvBgu+PtNiTIDIm3JoxsBJnQ9I8zY//9oeTpJxIvMctSWYnT4GYP4oI5mClZg==,iv:z5qxUPomGF1avLyk8PrAS3t+34ZGlQMRjbxVJ4JH9Cc=,tag:Qbz/LYAMXejXU4RS3RUPqA==,type:str]
netbird-key: ENC[AES256_GCM,data:swmaa+RjxeUmEl8hS2riGrW4lP5jdks9HM3x57/FLpOuqFtR,iv:MrpVjiocrPi+dBGPk7pwgSUNlJ1eryRpMjC8+jkU+T0=,tag:j6sqpQ02apqc6FwkdDvk9g==,type:str]
vicinae-json: ENC[AES256_GCM,data:FarBf6l8pl3hF7kGKPIWztUhwiKoQXmyTufCuJ120K/bPh1Bfiyi+ETt4DLYOGI6FJXfpVz4BbZOA29bXTLhVPxH0QtyBu/F5uEqA015b/c8VevDJSyy9huR13qO9ksLbMBt8RfWbAd9j26t7A1C8/mMyiJOEXCCTV9CEIW3xWrsYmhwsT8RYM+PwrPSeN1gQXHSMyRUjf/kOdJoda8+iXpLfjo4II4r2ELpbqi8QxhrRdsJsoOfAymFM784NtlTjE+h6S4TMehmoF/9ARif6I5SGQ0WfIKt/8orTGCPllL+NupLziSnpIGRGSybdArD+o5NCw59GOAbVRADxq8rCESwEkq3cF+hm8HabfYbiQ==,iv:Y/hXLFTJT3gNF3B6tgKoAh7njVuneoUzjVTlsCZiySw=,tag:2hfrwph6IccJdRu/yGu3XA==,type:str]
sops:
age:
- recipient: age14vktfes95f33vuefwnmuvryas7az04u76dsgyhfvsx73czkvmp2q7njkl4
enc: |
- enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBqS2RZdVJaNTlRamZPMkll
MDRVSVl1b2x2LzZpdlBrdmZtdyt3UE15RldRCldXUXE2a1BFeHg5NGNPbW5IMDht
@@ -15,8 +15,8 @@ sops:
bThQTFdZU29ISm93TWcwVk5ZTkhRWm8KCcprmLGhahgDkXCBpzjctHgao+gc+rKC
xLIwheUyFJOGK+ixqcdoZ/PC0kY68hVLt1YzLAyxFi4Ur1wltPrNug==
-----END AGE ENCRYPTED FILE-----
- recipient: age1x36yr8h993srfj29sfpzt4wyz52nztvncpmhgmfs0j26qvfecq3qvcm0an
enc: |
recipient: age14vktfes95f33vuefwnmuvryas7az04u76dsgyhfvsx73czkvmp2q7njkl4
- enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBGVW13WFE1Ylh3Uk1HNU1i
bU9kRzFqTmhkQlRzMlRkM0VhMlNmMDUyK25NCkZYUStxM2tScGozRXJGekxGa1RX
@@ -24,7 +24,8 @@ sops:
V1N3eUVjZ0VZRjBZdXRPNng3Y3JoUTAKQau9CG9XfvM+5JZVRwaJr/o/sXMaJiy2
wo2YcDb+4vfT4Wr+/8J3ccQgbLRZH916X5ZPL+A+nFyVXVKOCl3ENg==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2026-05-12T06:33:00Z"
mac: ENC[AES256_GCM,data:htDJdEx34Q5NG8vwbBimnFENZawbLZ4FC0DkyG6J5RYP0BFnycKcKGsYR87SvIjcJZXvfZ0e6fXdtc78dd6I0sQtrQ7aNn4Iktbu/AkPmntsBwpIjVI99X9zUyQB87go/oX15yuyt8loB6ds2RkL/pfFsgLbFc10JHsBy+WcEzI=,iv:HvY+5LYzyHpRm8XCSKrN8ra/LJT9v23TPSsZg/4QVNU=,tag:k+d45+zgBYq4vlWmmc8ZkQ==,type:str]
recipient: age1x36yr8h993srfj29sfpzt4wyz52nztvncpmhgmfs0j26qvfecq3qvcm0an
lastmodified: "2026-09-16T14:20:36Z"
mac: ENC[AES256_GCM,data:mhJvvn/+VBfNrP1pXRweLSNVlHq9/DLDcKQv8k9ZVsEcd077ifEAqduOXVKXcXDM0VTuBzArw9hmih+kZbCHoUZAQrk8LF7FC4a4FFwXG9p45uKWbUloTuq5w3MCxyU8IoyiAufZcWUlYFQjZ8K4n8N0bVrGQGHogemnrBXTUIo=,iv:H3tKQOuIe/pEIp0pUWCSar8VDompXNZ4BZfD1Wg4pb0=,tag:lyPR4Prlal1bpSRLmGfy7A==,type:str]
unencrypted_suffix: _unencrypted
version: 3.12.2
version: 3.13.3

View File

@@ -1,13 +1,10 @@
{ config, ... }:
{
flake.modules.nixos.sirius =
{
{config, ...}: {
flake.modules.nixos.sirius = {
pkgs,
hostName,
userName,
...
}:
{
}: {
imports = with config.flake.modules.nixos; [
boot
networking
@@ -27,28 +24,47 @@
directories = [
"Distrobox"
".steam"
".bun"
".rustup"
".cache/awww"
".cache/serpantinum"
".config/BraveSoftware"
".config/zed"
".config/Vencord"
".config/vesktop"
".config/sops"
".config/nix"
".config/coderv2"
".config/obs-studio"
".config/easyeffects"
".config/DankMaterialShell"
".local/share/Steam"
".local/share/lutris"
".local/share/net.lutris.Lutris"
".local/share/nvim"
".local/share/opencode"
".local/share/zsh"
".local/share/zoxide"
".local/share/voxtype"
".local/state/lazygit"
".local/share/vicinae"
".local/share/TelegramDesktop"
".local/share/GalaxyBudsClient"
".local/state/serpantinum"
".local/share/zed"
".claude"
".orca"
".config/orca"
".zcode"
".config/ZCode"
];
files = [
".wakatime.cfg"
".config/lan-mouse/lan-mouse.pem"
".claude.json"
".config/gh/hosts.yml"
];
};
};
@@ -66,6 +82,8 @@
waydroid.enable = true;
distrobox.enable = true;
};
programs.nix-ld.enable = true;
};
sops.secrets = {
@@ -89,6 +107,11 @@
owner = userName;
};
zai-coding-plan-api-key = {
sopsFile = ./secrets.yaml;
owner = userName;
};
netbird-key = {
sopsFile = ./secrets.yaml;
owner = userName;
@@ -124,6 +147,12 @@
environment.systemPackages = with pkgs; [
davinci-resolve
telegram-desktop
galaxy-buds-client
impala
llm-agents.claude-code
llm-agents.orca
llm-agents.zcode
coder
];
# !!! DO NOT CHANGE THIS !!!

View File

@@ -1,30 +0,0 @@
{
inputs,
config,
...
}:
let
hostName = "sirius";
userName = "tux";
userEmail = "t@tux.rs";
system = "x86_64-linux";
unstable = true;
nixpkgs = if unstable then inputs.nixpkgs else inputs.nixpkgs-stable;
in
{
flake.nixosConfigurations."${hostName}" = nixpkgs.lib.nixosSystem {
inherit system;
specialArgs = {
inherit
hostName
userName
userEmail
system
;
};
modules = [
config.flake.modules.nixos.core
config.flake.modules.nixos.${hostName}
];
};
}

View File

@@ -1,11 +1,11 @@
{ inputs, ... }:
{
flake.modules.nixos.sirius =
{ config, lib, ... }:
let
{inputs, ...}: {
flake.modules.nixos.sirius = {
config,
lib,
...
}: let
hasOptinPersistence = config.tnix.boot.impermanence.enable;
in
{
in {
imports = [
inputs.disko.nixosModules.disko
];
@@ -43,7 +43,8 @@
content = {
type = "btrfs";
# Base subvolumes that always exist
subvolumes = {
subvolumes =
{
"/root" = {
mountOptions = [
"compress=zstd"

View File

@@ -1,15 +1,20 @@
{ config, ... }:
{
flake.modules.nixos.sirius =
{
inputs,
config,
...
}: {
flake.modules.nixos.sirius = {
lib,
pkgs,
system,
...
}@innerArgs:
{
imports = with config.flake.modules.nixos; [
} @ innerArgs: {
imports = with config.flake.modules.nixos;
[
hardware
]
++ [
inputs.cardwire.nixosModules.default
];
boot.kernelParams = ["nvidia-drm.modeset=1"];
@@ -38,6 +43,11 @@
services = {
xserver.videoDrivers = ["nvidia"];
power-profiles-daemon.enable = true;
cardwire = {
enable = true;
settings.auto_apply_gpu_state = true;
};
};
networking.useDHCP = lib.mkDefault true;

View File

@@ -1,5 +1,4 @@
{ config, ... }:
{
{config, ...}: {
flake.modules.homeManager.sirius = {
imports = with config.flake.modules.homeManager; [
desktop

View File

@@ -2,12 +2,12 @@ tux-password: ENC[AES256_GCM,data:JWQVd2MYX2U4UP4II62ixG9hWI5MtgHAFhl8aCmyrYPl1H
gemini-api-key: ENC[AES256_GCM,data:Y9YgXp/tB3Q1Rb5YMsZLgWCq+bdeIjsXAVeO3Yh7nZ8MwDH7d5De,iv:FIXxJCn6JDYsHIoNn8f8Un3z9ZPVbxdjR48Ux88poRg=,tag:bMJ4i69HTspnhzsrsxkbrw==,type:str]
openrouter-api-key: ENC[AES256_GCM,data:HfZgZz4NyCLLM9woTZp2I6JGOlVcFblw2OMjx8k0TG5ZU2ycBCF6bKqp3wFibUxXcHy+nIfjI82fkLeSyIaGILRLYCJCc8BHKw==,iv:umUcn8MRaj7JXo6IFrGMXOu+jsFSCEikMxsQxfaFS/Q=,tag:l2s61C4EpJoKv8cc9nYGFA==,type:str]
opencode-go-api-key: ENC[AES256_GCM,data:BGERcZg5Jpnznc4cXeYFMhPk9kKBkd9GvIuQBV9TW3JE1utgrLLYK6mKNCQqrEStRFiO2jUUnBm3opUNL4SuEHFLpw==,iv:fgFAwx6z9yruK27PvAJX/Q2CS9gU+LJ5zMUK/f/rzpo=,tag:BPu3M+jppPB8sLoLmfuY/Q==,type:str]
zai-coding-plan-api-key: ENC[AES256_GCM,data:u5RHaBq5WHit+GjcKYnr6vN7jkputBtt3G0lCNBciMgBnBzIcZd/JjJcNaKXfbal5w==,iv:x+mG1aoct7yfm4Hvu1mMqBq8MiF8UZbQ8SFjA99qTIw=,tag:9cEIO2tuhqE6df2M2N/R+g==,type:str]
netbird-key: ENC[AES256_GCM,data:qXAnRnLM2TlzpOvWG4exJv0+pUvpe0FpRN5xOWx3+KNt+yhq,iv:X+yl4o1RSYMCMWdVXo1hpzy+6IdKXUpsKPtYNSiHiCY=,tag:I8HbnD5iw6EJ1TdsNrhvfw==,type:str]
vicinae-json: ENC[AES256_GCM,data:JjxolEgS6uakqR4eHOx3VyrOO5kaL4dj1jcEiLWsrktCU32UB7OmP1kJEVomA1rZjODpFHL89+FRpcNFspTFrc365WlANE81RLg/M2Ja1MiLYaDFNcBGtqMX9Yc1muor53Xl7t+rTSvDIj1oE1L7xPPcjCLfwC5QDzJjCBWj9FhCxnU5BwvoJNv9vgA6xnkzAOYSPZK/ihULMD0DxyqOUEa5ECGX62OPM9Gbr7jEviaItYzOOxaRs/yQVqizodGGl/BcK6fPqvOYSxip9ABYRVSI9ZvysY7ofAkeX91ardPwVG5VvEYfxZwBvGFjV7ZfTzVkK+BiUUNrvciAETHqwkjHftPpfJjxWsgLr8lbOA==,iv:HjDE/sqVDnxeww7r2upxH57rc1+LpuMKnhhyGXoc1Ms=,tag:d2kZeWkg17eVoNACIQ3Q9A==,type:str]
sops:
age:
- recipient: age14vktfes95f33vuefwnmuvryas7az04u76dsgyhfvsx73czkvmp2q7njkl4
enc: |
- enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBQNGdHcDc4bTFkR0EyZlUr
eXovR1lyeTZJTDg5R281MFFuMHVwOXZXYzNvCkpIT1g3K05WUUswaEVjVVJWQkJq
@@ -15,8 +15,8 @@ sops:
Z0JwWWR0STUybjVhSXdDR3NiKzV1eDQK22HmMuyqYaR/eGuALkAPB1Y5bN2KwIt3
pamM8vbnjB//hXoyrv4vsoDk9WzLGFGjgiw2qsM2HQgzQqtrwF1/1A==
-----END AGE ENCRYPTED FILE-----
- recipient: age1maxsx5tq2h3d92rfyl8ekcdan5gu5cpch4qs3c56cu7qag02xgvs3h0gqc
enc: |
recipient: age14vktfes95f33vuefwnmuvryas7az04u76dsgyhfvsx73czkvmp2q7njkl4
- enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA1N3ZBd1pHODFtZkZxaHNP
OXlXUzVFS0ZIam1IWVkxNldOdTEwY0s4aUNZCjVlcnF1aXJxUUlQSXhteXJ6OU1W
@@ -24,7 +24,8 @@ sops:
M3JocWZJeXFxenhXOENBVWpvNkd3bm8KqhNLzCyEAI643jGWpZF/uTchHmBj8ozU
HtpOzKsshif66D0XOHeJQfQamJI4TyKsj3Sk3j9rstsLmN2lxTRGHg==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2026-05-10T00:35:50Z"
mac: ENC[AES256_GCM,data:u27zQ1PPnWy5Parbh/1DkVP3ICmHnLZJKaLbN3dZEVONgqOWi32LV3t0iNhtLWwVnzFPBusRWahQiqAkUdnQtrXF0OtjPCpLuIw86xB75QPGbet0GZlLNb8/xPshChZe4v520csdJMWiy3vYeKrk8LxMSViAGhmhYK2a5NbGhzI=,iv:/9vePmvCNqoP0kx24fP3HfCjS2FkjBmI5B+SycvKKW4=,tag:gE1/DnLolwhoyfMJYejGIQ==,type:str]
recipient: age1maxsx5tq2h3d92rfyl8ekcdan5gu5cpch4qs3c56cu7qag02xgvs3h0gqc
lastmodified: "2026-09-16T14:20:48Z"
mac: ENC[AES256_GCM,data:i2I6vo/tKTLq44Tu6vI2Cqp0EqQPbwuuRM2WUflD58UCr7huXIKnKrxmB1Hz/fdmpZPiCZ2dSlmOh733fKFclRmpHJLScYRX4+lFXEzToYExZlybVergxC6Cr4IaiB+A/HZIkW6iKK/ULr2mtXYNCqQgDQw8BgJuV2M/bAMM/V4=,iv:9akzmVH4CMMdDS5aukeLOxncMLKfvQCw2BYl36WAfOM=,tag:4F26bqEI8fEtNugqjHCUOg==,type:str]
unencrypted_suffix: _unencrypted
version: 3.12.2
version: 3.13.3

View File

@@ -0,0 +1,51 @@
{config, ...}: {
flake.modules.nixOnDroid.vega = {
pkgs,
userEmail,
...
}: {
imports = with config.flake.modules.nixOnDroid; [
networking
];
# @TODO: Broken currently
# android-integration.am.enable = true;
# android-integration.termux-open-url.enable = true;
# android-integration.xdg-open.enable = true;
# android-integration.termux-setup-storage.enable = true;
# android-integration.termux-reload-settings.enable = true;
terminal.font = let
firacode = pkgs.nerd-fonts.fira-code;
fontPath = "share/fonts/truetype/NerdFonts/FiraCode/FiraCodeNerdFont-Regular.ttf";
in "${firacode}/${fontPath}";
time.timeZone = "Asia/Kolkata";
tnix.networking.openssh = {
enable = true;
ports = [8033];
authorizedKeys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIL+OzPUe2ECPC929DqpkM39tl/vdNAXfsRnmrGfR+X3D ${userEmail}"
];
};
user = {
uid = 10481;
gid = 10481;
shell = "${pkgs.zsh}/bin/zsh";
};
environment.etcBackupExtension = ".backup";
environment.motd = "";
environment.packages = with pkgs; [
ncurses
procps
util-linux
rsync
gnutar
];
system.stateVersion = "24.05";
};
}

View File

@@ -0,0 +1,8 @@
{lib, ...}: {
flake.modules.homeManager.vega = {
# @TODO: Broken currently - By default it's enabled by neovim module
programs.vim.enable = lib.mkForce false;
home.stateVersion = "26.05";
};
}

View File

@@ -1,11 +1,5 @@
{ config, ... }:
{
flake.modules.nixos.vps =
{
hostName,
...
}:
{
{config, ...}: {
flake.modules.nixos.vps = {hostName, ...}: {
imports = with config.flake.modules.nixos; [
boot
networking

View File

@@ -1,30 +0,0 @@
{
inputs,
config,
...
}:
let
hostName = "vps";
userName = "tux";
userEmail = "t@tux.rs";
system = "x86_64-linux";
unstable = true;
nixpkgs = if unstable then inputs.nixpkgs else inputs.nixpkgs-stable;
in
{
flake.nixosConfigurations."${hostName}" = nixpkgs.lib.nixosSystem {
inherit system;
specialArgs = {
inherit
hostName
userName
userEmail
system
;
};
modules = [
config.flake.modules.nixos.core
config.flake.modules.nixos.${hostName}
];
};
}

View File

@@ -1,12 +1,12 @@
{ inputs, ... }:
{
flake.modules.nixos.vps =
{ config, lib, ... }:
let
{inputs, ...}: {
flake.modules.nixos.vps = {
config,
lib,
...
}: let
hasOptinPersistence = config.tnix.boot.impermanence.enable;
isLegacy = config.tnix.boot.legacy.enable;
in
{
in {
imports = [
inputs.disko.nixosModules.disko
];
@@ -16,7 +16,8 @@
type = "disk";
content = {
type = "gpt";
partitions = {
partitions =
{
ESP = {
size = "1G";
type = "EF00";
@@ -36,7 +37,8 @@
content = {
type = "btrfs";
# Base subvolumes that always exist
subvolumes = {
subvolumes =
{
"/root" = {
mountOptions = [
"compress=zstd"

View File

@@ -1,12 +1,10 @@
{
flake.modules.nixos.vps =
{
flake.modules.nixos.vps = {
lib,
modulesPath,
system,
...
}:
{
}: {
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];

View File

@@ -1,4 +1,3 @@
{ ... }:
{
flake.modules.homeManager.vps = {
home.stateVersion = "26.05";

View File

@@ -1,16 +1,12 @@
{ inputs, ... }:
{
flake.modules.nixos.boot =
{
{inputs, ...}: {
flake.modules.nixos.boot = {
config,
lib,
userName,
...
}:
let
}: let
cfg = config.tnix.boot;
in
{
in {
imports = [
inputs.impermanence.nixosModules.impermanence
];
@@ -46,25 +42,30 @@
fileSystems."/persist".neededForBoot = true;
environment.persistence."/persist" = {
hideMounts = true;
directories = [
directories =
[
"/var/log"
"/var/lib"
"/etc/NetworkManager/system-connections"
]
++ cfg.impermanence.directories;
files = [
files =
[
"/etc/machine-id"
"/etc/ssh/ssh_host_ed25519_key"
"/etc/ssh/ssh_host_ed25519_key.pub"
"/etc/ssh/ssh_host_rsa_key"
"/etc/ssh/ssh_host_rsa_key.pub"
"/etc/ly/save.txt"
]
++ cfg.impermanence.files;
};
home-manager.users.${userName} = {
home.persistence."/persist" = {
directories = [
directories =
[
"Downloads"
"Music"
"Wallpapers"

View File

@@ -1,16 +1,19 @@
{
flake.modules.nixos.boot =
{ config, lib, ... }:
let
flake.modules.nixos.boot = {
config,
lib,
...
}: let
cfg = config.tnix.boot;
in
{
in {
options.tnix.boot.legacy = {
enable = lib.mkEnableOption "legacy boot (GRUB) instead of systemd-boot";
};
config = lib.mkMerge [
{
boot.binfmt.emulatedSystems = ["aarch64-linux"];
boot.loader = {
timeout = 1;
efi.canTouchEfiVariables = true;

View File

@@ -1,7 +1,5 @@
{
flake.modules.nixos.boot =
{ pkgs, ... }:
{
flake.modules.nixos.boot = {pkgs, ...}: {
boot = {
consoleLogLevel = 0;
initrd.verbose = false;

View File

@@ -1,16 +1,12 @@
{ inputs, ... }:
{
flake.modules.nixos.boot =
{
{inputs, ...}: {
flake.modules.nixos.boot = {
config,
lib,
pkgs,
...
}:
let
}: let
cfg = config.tnix.boot;
in
{
in {
imports = [inputs.lanzaboote.nixosModules.lanzaboote];
options.tnix.boot.secure-boot = {

View File

@@ -0,0 +1,5 @@
{
flake.modules.nixos.core = {...}: {
environment.enableAllTerminfo = true;
};
}

View File

@@ -1,13 +1,14 @@
{ inputs, config, ... }:
{
flake.modules.nixos.core =
{
inputs,
config,
...
}: {
flake.modules.nixos.core = {
hostName,
userName,
userEmail,
...
}:
{
}: {
imports = [
inputs.home-manager.nixosModules.home-manager
];

View File

@@ -1,11 +1,9 @@
{
flake.modules.nixos.core =
{
flake.modules.nixos.core = {
config,
userName,
...
}:
{
}: {
programs.nh = {
enable = true;

View File

@@ -0,0 +1,12 @@
{inputs, ...}: {
flake.modules.nixos.core = {pkgs, ...}: {
imports = [
inputs.nix-index-database.nixosModules.default
];
programs = {
nix-index.package = pkgs.nix-index-small;
nix-index-database.comma.enable = true;
};
};
}

View File

@@ -0,0 +1,18 @@
{...}: {
flake.modules.nixos.core = {
config,
lib,
...
}:
with lib; let
cfg = config.tnix.programs.nix-ld;
in {
options.tnix.programs.nix-ld = {
enable = mkEnableOption "nix-ld";
};
config = mkIf cfg.enable {
programs.nix-ld.enable = true;
};
};
}

View File

@@ -1,7 +1,5 @@
{
flake.modules.nixos.core =
{ userName, ... }:
{
flake.modules.nixos.core = {userName, ...}: {
nix = {
channel.enable = false;
@@ -15,6 +13,11 @@
optimise.automatic = true;
settings = {
extra-platforms = [
"aarch64-linux"
"arm-linux"
];
experimental-features = [
"nix-command"
"flakes"

View File

@@ -1,5 +1,4 @@
{ inputs, ... }:
{
{inputs, ...}: {
flake.modules.nixos.core = {
nixpkgs = {
config = {

View File

@@ -1,7 +1,5 @@
{
flake.modules.nixos.core =
{ pkgs, ... }:
{
flake.modules.nixos.core = {
security = {
sudo.wheelNeedsPassword = false;
};

View File

@@ -1,17 +1,13 @@
{ inputs, ... }:
{
flake.modules.nixos.core =
{
{inputs, ...}: {
flake.modules.nixos.core = {
config,
pkgs,
...
}:
let
}: let
isEd25519 = k: k.type == "ed25519";
getKeyPath = k: k.path;
keys = builtins.filter isEd25519 config.services.openssh.hostKeys;
in
{
in {
imports = [inputs.sops-nix.nixosModules.sops];
sops.age = {

View File

@@ -33,6 +33,10 @@
"wezterm.cachix.org-1:kAbhjYUC9qvblTE+s7S+kl5XM1zVa4skO+E/1IDWdH0="
"cache.nixos-cuda.org:74DUi4Ye579gUqzH4ziL9IyiJBlDpMRn9MBN8oNan9M="
];
extra-substituters = ["https://cache.numtide.com"];
extra-trusted-public-keys = [
"niks3.numtide.com-1:DTx8wZduET09hRmMtKdQDxNNthLQETkc/yaX7M4qK0g="
];
};
};
}

View File

@@ -1,17 +1,14 @@
{
flake.modules.nixos.core =
{
flake.modules.nixos.core = {
pkgs,
lib,
config,
userName,
userEmail,
...
}:
let
}: let
hasPasswordSecret = lib.hasAttrByPath ["sops" "secrets" "tux-password"] config;
in
{
in {
programs.zsh.enable = true;
time.timeZone = "Asia/Kolkata";

View File

@@ -1,7 +1,5 @@
{
flake.modules.nixos.desktop =
{ pkgs, ... }:
{
flake.modules.nixos.desktop = {pkgs, ...}: {
fonts.packages = with pkgs.nerd-fonts; [
fira-code
jetbrains-mono

View File

@@ -1,7 +1,5 @@
{
flake.modules.nixos.desktop =
{ pkgs, ... }:
{
flake.modules.nixos.desktop = {pkgs, ...}: {
programs.gpu-screen-recorder = {
enable = true;
};

View File

@@ -1,7 +1,5 @@
{
flake.modules.nixos.desktop =
{ pkgs, ... }:
{
flake.modules.nixos.desktop = {pkgs, ...}: {
programs.hyprland = {
enable = true;
package = pkgs.hyprland-git.hyprland;

View File

@@ -1,15 +1,9 @@
{
inputs,
...
}:
{
flake.modules.nixos.desktop =
{
{inputs, ...}: {
flake.modules.nixos.desktop = {
pkgs,
lib,
...
}:
{
}: {
imports = [
inputs.mango.nixosModules.mango
];

View File

@@ -1,7 +1,5 @@
{
flake.modules.nixos.desktop =
{ pkgs, ... }:
{
flake.modules.nixos.desktop = {pkgs, ...}: {
environment.systemPackages = with pkgs; [brightnessctl];
};
}

View File

@@ -1,7 +1,5 @@
{
flake.modules.nixos.desktop =
{ pkgs, ... }:
{
flake.modules.nixos.desktop = {pkgs, ...}: {
programs.obs-studio = {
enable = true;
enableVirtualCamera = true;
@@ -9,6 +7,7 @@
obs-vaapi
wlrobs
obs-source-record
obs-advanced-masks
];
};
};

View File

@@ -1,7 +1,5 @@
{
flake.modules.nixos.desktop =
{ pkgs, ... }:
{
flake.modules.nixos.desktop = {pkgs, ...}: {
services = {
gvfs.enable = true;
tumbler.enable = true;

View File

@@ -1,7 +0,0 @@
{
flake.modules.nixos.desktop =
{ pkgs, ... }:
{
environment.systemPackages = with pkgs; [ tpanel ];
};
}

View File

@@ -0,0 +1,5 @@
{
flake.modules.nixos.desktop = {pkgs, ...}: {
environment.systemPackages = with pkgs; [tshell];
};
}

View File

@@ -1,7 +1,5 @@
{
flake.modules.nixos.gaming =
{ pkgs, ... }:
{
flake.modules.nixos.gaming = {pkgs, ...}: {
programs.steam = {
enable = true;
protontricks.enable = true;

View File

@@ -1,5 +1,5 @@
{
flake.modules.nixos.hardware = {
flake.modules.nixos.hardware = {pkgs, ...}: {
security.rtkit.enable = true;
services.pipewire = {
@@ -9,5 +9,10 @@
pulse.enable = true;
wireplumber.enable = true;
};
environment.systemPackages = with pkgs; [
alsa-utils
pavucontrol
];
};
}

View File

@@ -1,16 +1,13 @@
{
flake.modules.nixos.networking =
{
flake.modules.nixos.networking = {
config,
lib,
hostName,
...
}:
with lib;
let
with lib; let
cfg = config.tnix.networking.netbird-client;
in
{
in {
options.tnix.networking.netbird-client = {
enable = mkEnableOption "Enable netbird client";
};
@@ -18,7 +15,7 @@
config = mkIf cfg.enable {
services.netbird.clients = {
${hostName} = {
port = 51820;
port = 61820;
login = {
enable = true;
setupKeyFile = config.sops.secrets.netbird-key.path;

View File

@@ -0,0 +1,27 @@
{
flake.modules.nixos.networking = {
config,
lib,
...
}:
with lib; let
cfg = config.tnix.networking.newt;
in {
options.tnix.networking.newt = {
enable = mkEnableOption "Newt";
environmentFile = mkOption {
type = types.nullOr types.path;
default = null;
description = "Environment file with secrets passed to Newt";
};
};
config = mkIf cfg.enable {
services.newt = {
enable = true;
environmentFile = cfg.environmentFile;
};
};
};
}

View File

@@ -1,19 +1,16 @@
{
flake.modules.nixos.networking =
{
flake.modules.nixos.networking = {
config,
lib,
...
}:
with lib;
let
with lib; let
cfg = config.tnix.networking.openssh;
# Sops needs acess to the keys before the persist dirs are even mounted; so
# just persisting the keys won't work, we must point at /persist
hasOptinPersistence = config.tnix.boot.impermanence.enable;
in
{
in {
options.tnix.networking.openssh = {
enable = mkEnableOption "Enable OpenSSH server";

View File

@@ -1,21 +1,51 @@
{
flake.modules.nixos.services =
{
flake.modules.nixos.services = {
config,
lib,
...
}:
with lib;
let
with lib; let
cfg = config.tnix.services.aiostreams;
in
{
port = toString cfg.port;
acmeHost = config.tnix.services.nginx.domain;
in {
options.tnix.services.aiostreams = {
enable = mkEnableOption "Enable AIOStreams";
enable = mkEnableOption "AIOStreams";
host = mkOption {
type = types.str;
default = "127.0.0.1";
description = "Host on which AIOStreams listens";
};
port = mkOption {
type = types.int;
type = types.port;
default = 3000;
description = "Port on which AIOStreams listens";
};
domain = mkOption {
type = types.str;
default = "";
description = "Domain on which AIOStreams is available";
};
configureNginx = mkOption {
type = types.bool;
default = false;
description = "Whether to configure Nginx as a reverse proxy for AIOStreams";
};
configurePangolin = mkOption {
type = types.bool;
default = false;
description = "Whether to configure Pangolin as a reverse proxy for AIOStreams";
};
image = mkOption {
type = types.str;
default = "ghcr.io/viren070/aiostreams:latest";
description = "Container image to use";
};
dataDir = mkOption {
@@ -24,41 +54,69 @@
description = "Directory to store persistent AIOStreams data";
};
environment = mkOption {
type = with types; attrsOf str;
default = { };
};
environmentFile = mkOption {
type = with types; path;
default = "";
type = types.nullOr types.path;
default = null;
description = "Environment file with secrets passed to the container";
};
};
config = mkIf cfg.enable {
virtualisation.oci-containers.containers.aiostreams = {
autoStart = true;
image = "ghcr.io/viren070/aiostreams:latest";
ports = [
"${toString cfg.port}:3000"
assertions = [
{
assertion = cfg.domain != "";
message = "tnix.services.aiostreams.domain must be set when tnix.services.aiostreams.enable is true.";
}
];
environment = cfg.environment;
environmentFiles = [ cfg.environmentFile ];
virtualisation.oci-containers.containers.aiostreams = {
image = cfg.image;
ports = [
"${cfg.host}:${port}:3000"
];
environment = {
ADDON_ID = cfg.domain;
BASE_URL = "https://${cfg.domain}";
};
environmentFiles = optional (cfg.environmentFile != null) cfg.environmentFile;
volumes = [
"${cfg.dataDir}:/app/data"
];
};
services.nginx.virtualHosts = {
"${cfg.environment.ADDON_ID}" = {
forceSSL = true;
useACMEHost = "lab.tux.rs";
locations = {
"/" = {
proxyPass = "http://localhost:${toString cfg.port}";
services = {
nginx.virtualHosts.${cfg.domain} = mkIf cfg.configureNginx {
forceSSL = acmeHost != "";
useACMEHost = mkIf (acmeHost != "") acmeHost;
locations."/" = {
proxyPass = "http://${cfg.host}:${port}";
proxyWebsockets = true;
};
};
newt.blueprint.proxy-resources = mkIf cfg.configurePangolin {
aiostreams = {
auth = {
sso-enabled = false;
};
full-domain = cfg.domain;
name = "aiostreams";
protocol = "http";
targets = [
{
hostname = "localhost";
method = "http";
port = cfg.port;
healthcheck = {
hostname = "localhost";
port = cfg.port;
scheme = "http";
method = "GET";
path = "/";
};
}
];
};
};
};
};

View File

@@ -0,0 +1,95 @@
{
flake.modules.nixos.services = {
config,
lib,
options,
...
}:
with lib; let
cfg = config.tnix.services.coder;
port = toString cfg.port;
in {
options.tnix.services.coder = {
enable = mkEnableOption "Coder";
host = mkOption {
type = types.str;
default = "127.0.0.1";
description = "Host on which Coder listens";
};
port = mkOption {
type = types.port;
default = 1116;
description = "Port on which Coder listens";
};
environment = options.services.coder.environment;
domain = mkOption {
type = types.str;
default = "";
description = "Domain on which Coder is available";
};
configureNginx = mkOption {
type = types.bool;
default = false;
description = "Whether to configure Nginx as a reverse proxy for Coder";
};
configurePangolin = mkOption {
type = types.bool;
default = false;
description = "Whether to configure Pangolin as a reverse proxy for Coder";
};
};
config = mkIf cfg.enable {
users.users.coder.extraGroups = ["docker"];
services = {
coder = {
enable = true;
accessUrl = "https://${cfg.domain}";
listenAddress = "${cfg.host}:${port}";
environment = cfg.environment;
};
nginx.virtualHosts.${cfg.domain} = mkIf cfg.configureNginx {
forceSSL = acmeHost != "";
useACMEHost = mkIf (acmeHost != "") acmeHost;
locations."/" = {
proxyPass = "http://${cfg.host}:${port}";
proxyWebsockets = true;
};
};
newt.blueprint.proxy-resources = mkIf cfg.configurePangolin {
gitea = {
auth = {
sso-enabled = false;
};
full-domain = cfg.domain;
name = "coder";
protocol = "http";
targets = [
{
hostname = "localhost";
method = "http";
port = cfg.port;
healthcheck = {
hostname = "localhost";
port = cfg.port;
scheme = "http";
method = "GET";
path = "/";
};
}
];
};
};
};
};
};
}

View File

@@ -0,0 +1,115 @@
{inputs, ...}: {
flake.modules.nixos.services = {
config,
lib,
pkgs,
options,
...
}:
with lib; let
cfg = config.tnix.services.copyparty;
port = toString cfg.port;
acmeHost = config.tnix.services.nginx.domain;
in {
imports = [
inputs.copyparty.nixosModules.default
];
options.tnix.services.copyparty = {
enable = mkEnableOption "Copyparty";
host = mkOption {
type = types.str;
default = "127.0.0.1";
description = "Host on which Copyparty listens";
};
port = mkOption {
type = types.port;
default = 1115;
description = "Port on which Copyparty listens";
};
domain = mkOption {
type = types.str;
default = "";
description = "Domain on which Copyparty is available";
};
accounts = options.services.copyparty.accounts;
volumes = options.services.copyparty.volumes;
configureNginx = mkOption {
type = types.bool;
default = false;
description = "Whether to configure Nginx as a reverse proxy for Copyparty";
};
configurePangolin = mkOption {
type = types.bool;
default = false;
description = "Whether to configure Pangolin as a reverse proxy for Copyparty";
};
};
config = mkIf cfg.enable {
assertions = [
{
assertion = cfg.domain != "";
message = "tnix.services.copyparty.domain must be set when tnix.services.copyparty.enable is true.";
}
];
services = {
copyparty = {
enable = true;
settings = {
i = cfg.host;
p = cfg.port;
no-reload = true;
ignored-flag = false;
};
accounts = cfg.accounts;
volumes = cfg.volumes;
package = pkgs.copyparty.override {
extraPackages = [pkgs.exiftool];
};
};
nginx.virtualHosts.${cfg.domain} = mkIf cfg.configureNginx {
forceSSL = acmeHost != "";
useACMEHost = mkIf (acmeHost != "") acmeHost;
locations."/" = {
proxyPass = "http://${cfg.host}:${port}";
proxyWebsockets = true;
};
};
newt.blueprint.proxy-resources = mkIf cfg.configurePangolin {
copyparty = {
auth = {
sso-enabled = false;
};
full-domain = cfg.domain;
name = "copyparty";
protocol = "http";
targets = [
{
hostname = "localhost";
method = "http";
port = cfg.port;
healthcheck = {
hostname = "localhost";
port = cfg.port;
scheme = "http";
method = "GET";
path = "/";
};
}
];
};
};
};
};
};
}

View File

@@ -1,16 +1,13 @@
{
flake.modules.nixos.services =
{
flake.modules.nixos.services = {
config,
lib,
pkgs,
...
}:
with lib;
let
with lib; let
cfg = config.tnix.services.cyber-tux;
in
{
in {
options.tnix.services.cyber-tux = {
enable = mkEnableOption "CyberTux Discord bot";
@@ -29,7 +26,7 @@
dataDir = mkOption {
type = types.path;
default = "/var/lib/cyber-tux";
description = "Directory where CyberTux stores its data.";
description = "Directory where CyberTux stores its data (must be under /var/lib).";
};
environmentFile = mkOption {
@@ -41,7 +38,8 @@
config = mkIf cfg.enable {
systemd.services.cyber-tux = {
description = "CyberTux Discord bot";
after = [ "network.target" ];
after = ["network-online.target"];
wants = ["network-online.target"];
wantedBy = ["multi-user.target"];
serviceConfig = {

Some files were not shown because too many files have changed in this diff Show More