nix-clanker-vm
Nix flake + Home Manager configuration for this host: a Debian VM running standalone Nix (non-NixOS).
Overview
- Declarative, reproducible user environment managed by Home Manager.
- A self-contained
tinfoil-proxypackage flake (Go). - System-wide Nix settings applied separately via
install.sh.
Prerequisites
- x86_64 Linux.
- Nix with
nix-commandandflakesenabled (seeconfig/nix.conf). home-manageravailable onPATH.sudoaccess for the system-wide/etc/nix/nix.confstep.
Quick start
git clone <your-repo-url> ~/nix
cd ~/nix
sudo ./install.sh # install /etc/nix/nix.conf (backs up)
home-manager switch --flake .#user # apply the Home Manager config
Repository layout
| Path | Purpose |
|---|---|
flake.nix |
Root flake: packages and the Home Manager configuration. |
home/default.nix |
Home Manager config for user user (packages, programs, the tinfoil-proxy user service). |
config/ |
Source files linked into ~/.config (nix, starship, opencode incl. the Tinfoil provider). |
tinfoil-proxy/ |
Self-contained flake packaging tinfoil-proxy (Go). |
install.sh |
Applies config/nix.conf to /etc/nix/nix.conf (sudo). |
flake.lock |
Pinned input revisions (tracked for reproducibility). |
Managing packages
Packages are declared in home.packages in home/default.nix. To add one,
append it to the list and re-apply:
home.packages = [
pkgs.ripgrep # example: add whatever you need
];
home-manager switch --flake .#user
To remove a package, delete its entry and re-run the same command. The
authoritative, always-current list lives in home/default.nix.
For one-off, ad-hoc use outside the managed environment:
nix shell nixpkgs#<package>
Managing configuration
Home Manager drives configuration through three mechanisms in
home/default.nix:
-
Files linked from this repo via
home.file. Add an entry to link a file fromconfig/into your home directory:home.file.".config/foo/foo.conf".source = ../config/foo.conf; -
Program modules via
programs.<name>(e.g.programs.bash,programs.fish,programs.tmux,programs.starship). Enable or customize a module here instead of editing dotfiles by hand. -
Environment variables via
home.sessionVariables.
Apply any change with:
home-manager switch --flake .#user
Customization
The config is host-specific. Current values and where to change them:
| Setting | File | Current value |
|---|---|---|
| Username | flake.nix |
"user" |
| Username | home/default.nix |
"user" |
| Home directory | home/default.nix |
"/home/user" |
| System | flake.nix |
"x86_64-linux" |
| System | tinfoil-proxy/flake.nix |
"x86_64-linux" |
- Change the username: update
usernameinflake.nixand bothhome.username/home.homeDirectoryinhome/default.nix. The Home Manager flake attribute name is derived fromusername, so the apply command becomeshome-manager switch --flake .#<newuser>. - Change the system: update
systeminflake.nixand intinfoil-proxy/flake.nix.
The tinfoil-proxy package
tinfoil-proxy/ is an independent flake that packages the Go program
tinfoil-proxy (a verified local HTTP proxy to a Tinfoil secure enclave).
Version, source hash, and vendor hash live in tinfoil-proxy/package.nix.
nix build ./tinfoil-proxy
Tinfoil models in OpenCode
The managed OpenCode config (config/opencode.jsonc) defines a tinfoil
provider that points at the local proxy on http://127.0.0.1:3301/v1. Every
request is checked against Tinfoil's attestation transparency log before it
reaches a secure enclave.
The proxy is installed as a systemd user service and starts automatically (linger is enabled, so it also starts at boot):
systemctl --user status tinfoil-proxy
To authenticate:
-
Get an API key from the Tinfoil dashboard.
-
Export it in your shell. It is read via
{env:TINFOIL_API_KEY}, so it is never stored in this repo or the Nix store:export TINFOIL_API_KEY=tk_... -
Start OpenCode, run
/models, and pick a model under Tinfoil.
The available models are listed in config/opencode.jsonc; update that file
and re-apply to change them.
Maintenance
Update pinned inputs and re-apply:
nix flake update
home-manager switch --flake .#user
A warning: Git tree '...' is dirty message is expected while you have
uncommitted changes; it does not affect the build.
License
Licensed under the GNU Affero General Public License v3.0 (AGPL-3.0-only).