nix-clanker-vm

Nix flake + Home Manager configuration for this host: a Debian VM running standalone Nix (non-NixOS).

Overview

  • Declarative, reproducible user environment managed by Home Manager.
  • A self-contained tinfoil-proxy package flake (Go).
  • System-wide Nix settings applied separately via install.sh.

Prerequisites

  • x86_64 Linux.
  • Nix with nix-command and flakes enabled (see config/nix.conf).
  • home-manager available on PATH.
  • sudo access for the system-wide /etc/nix/nix.conf step.

Quick start

git clone <your-repo-url> ~/nix
cd ~/nix

sudo ./install.sh                    # install /etc/nix/nix.conf (backs up)
home-manager switch --flake .#user   # apply the Home Manager config

Repository layout

Path Purpose
flake.nix Root flake: packages and the Home Manager configuration.
home/default.nix Home Manager config for user user (packages, programs, the tinfoil-proxy user service).
config/ Source files linked into ~/.config (nix, starship, opencode incl. the Tinfoil provider).
tinfoil-proxy/ Self-contained flake packaging tinfoil-proxy (Go).
install.sh Applies config/nix.conf to /etc/nix/nix.conf (sudo).
flake.lock Pinned input revisions (tracked for reproducibility).

Managing packages

Packages are declared in home.packages in home/default.nix. To add one, append it to the list and re-apply:

home.packages = [
  pkgs.ripgrep   # example: add whatever you need
];
home-manager switch --flake .#user

To remove a package, delete its entry and re-run the same command. The authoritative, always-current list lives in home/default.nix.

For one-off, ad-hoc use outside the managed environment:

nix shell nixpkgs#<package>

Managing configuration

Home Manager drives configuration through three mechanisms in home/default.nix:

  • Files linked from this repo via home.file. Add an entry to link a file from config/ into your home directory:

    home.file.".config/foo/foo.conf".source = ../config/foo.conf;
    
  • Program modules via programs.<name> (e.g. programs.bash, programs.fish, programs.tmux, programs.starship). Enable or customize a module here instead of editing dotfiles by hand.

  • Environment variables via home.sessionVariables.

Apply any change with:

home-manager switch --flake .#user

Customization

The config is host-specific. Current values and where to change them:

Setting File Current value
Username flake.nix "user"
Username home/default.nix "user"
Home directory home/default.nix "/home/user"
System flake.nix "x86_64-linux"
System tinfoil-proxy/flake.nix "x86_64-linux"
  • Change the username: update username in flake.nix and both home.username / home.homeDirectory in home/default.nix. The Home Manager flake attribute name is derived from username, so the apply command becomes home-manager switch --flake .#<newuser>.
  • Change the system: update system in flake.nix and in tinfoil-proxy/flake.nix.

The tinfoil-proxy package

tinfoil-proxy/ is an independent flake that packages the Go program tinfoil-proxy (a verified local HTTP proxy to a Tinfoil secure enclave). Version, source hash, and vendor hash live in tinfoil-proxy/package.nix.

nix build ./tinfoil-proxy

Tinfoil models in OpenCode

The managed OpenCode config (config/opencode.jsonc) defines a tinfoil provider that points at the local proxy on http://127.0.0.1:3301/v1. Every request is checked against Tinfoil's attestation transparency log before it reaches a secure enclave.

The proxy is installed as a systemd user service and starts automatically (linger is enabled, so it also starts at boot):

systemctl --user status tinfoil-proxy

To authenticate:

  1. Get an API key from the Tinfoil dashboard.

  2. Export it in your shell. It is read via {env:TINFOIL_API_KEY}, so it is never stored in this repo or the Nix store:

    export TINFOIL_API_KEY=tk_...
    
  3. Start OpenCode, run /models, and pick a model under Tinfoil.

The available models are listed in config/opencode.jsonc; update that file and re-apply to change them.

Maintenance

Update pinned inputs and re-apply:

nix flake update
home-manager switch --flake .#user

A warning: Git tree '...' is dirty message is expected while you have uncommitted changes; it does not affect the build.

License

Licensed under the GNU Affero General Public License v3.0 (AGPL-3.0-only).

S
Description
No description provided
Readme AGPL-3.0
52 KiB
Languages
Nix 82.6%
Shell 17.4%