From 40abf86655eab0ae7e267b1cbf31520c22932c8a Mon Sep 17 00:00:00 2001 From: kawaiipunk Date: Thu, 8 Oct 2026 22:17:14 +0000 Subject: [PATCH] Adopt Home Manager; manage starship, nix.conf, and opencode config --- .gitignore | 13 +++ README.md | 49 +++++++++++ config/nix.conf | 2 + config/opencode.jsonc | 3 + config/starship.toml | 175 ++++++++++++++++++++++++++++++++++++++ flake.lock | 79 +++++++++++++++++ flake.nix | 29 +++++++ home/default.nix | 25 ++++++ install.sh | 22 +++++ tinfoil-proxy/flake.lock | 27 ++++++ tinfoil-proxy/flake.nix | 13 +++ tinfoil-proxy/package.nix | 28 ++++++ 12 files changed, 465 insertions(+) create mode 100644 .gitignore create mode 100644 README.md create mode 100644 config/nix.conf create mode 100644 config/opencode.jsonc create mode 100644 config/starship.toml create mode 100644 flake.lock create mode 100644 flake.nix create mode 100644 home/default.nix create mode 100755 install.sh create mode 100644 tinfoil-proxy/flake.lock create mode 100644 tinfoil-proxy/flake.nix create mode 100644 tinfoil-proxy/package.nix diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..360fcad --- /dev/null +++ b/.gitignore @@ -0,0 +1,13 @@ +# nix build outputs +result +result-* + +# direnv / dev tooling +.direnv/ + +# editors / OS junk +*.swp +*.swo +.DS_Store + +# keep flake.lock tracked (reproducibility) \ No newline at end of file diff --git a/README.md b/README.md new file mode 100644 index 0000000..6065cb1 --- /dev/null +++ b/README.md @@ -0,0 +1,49 @@ +# nix-clanker-vm + +Nix configuration for this host (a Debian VM with standalone Nix). + +## What's here + +- `flake.nix` — root flake: aggregates packages and the Home Manager config. +- `tinfoil-proxy/` — self-contained flake packaging `tinfoil-proxy` (Go). +- `home/` — Home Manager configuration (user `user`): bash, shell env, + starship (declarative init), user-level nix.conf, installed packages + (opencode), managed opencode config. +- `config/nix.conf` — source of truth for Nix settings (`sandbox`, flakes). +- `config/starship.toml` — the host's starship preset (nerd-font-symbols). +- `config/opencode.jsonc` — global opencode config, managed via `home.file`. +- `install.sh` — applies `config/nix.conf` system-wide (sudo, backs up). + +## Apply + +```sh +sudo ./install.sh # update /etc/nix/nix.conf +home-manager --flake ~/nix#user switch +``` + +The user-level `~/.config/nix/nix.conf` is managed by Home Manager via +`home.file` in `home/default.nix`; the shell environment is owned by +`programs.bash` (plus `hm-session-vars.sh`). + +## Build + +```sh +nix build ~/nix +nix build ~/nix/tinfoil-proxy +``` + +## Push to Codeberg + +```sh +git remote add origin git@codeberg.org:kawaiipunk/nix-clanker-vm.git +git branch -M main +git push -u origin main +``` + +## Notes + +- `sandbox = true` is a restricted setting; when supplied from the user-level + config it is ignored with a warning (the daemon enforces it from + `/etc/nix/nix.conf`). This is cosmetic. +- Existing pre-Home-Manager dotfiles were moved to `~/.bashrc.backup` and + `~/.profile.backup` during the first switch. \ No newline at end of file diff --git a/config/nix.conf b/config/nix.conf new file mode 100644 index 0000000..e25689a --- /dev/null +++ b/config/nix.conf @@ -0,0 +1,2 @@ +sandbox = true +experimental-features = nix-command flakes \ No newline at end of file diff --git a/config/opencode.jsonc b/config/opencode.jsonc new file mode 100644 index 0000000..c3eb6a5 --- /dev/null +++ b/config/opencode.jsonc @@ -0,0 +1,3 @@ +{ + "$schema": "https://opencode.ai/config.json" +} \ No newline at end of file diff --git a/config/starship.toml b/config/starship.toml new file mode 100644 index 0000000..8d51b6f --- /dev/null +++ b/config/starship.toml @@ -0,0 +1,175 @@ +[aws] +symbol = " " + +[buf] +symbol = " " + +[c] +symbol = " " + +[cmake] +symbol = " " + +[conda] +symbol = " " + +[crystal] +symbol = " " + +[dart] +symbol = " " + +[directory] +read_only = " 󰌾" + +[docker_context] +symbol = " " + +[elixir] +symbol = " " + +[elm] +symbol = " " + +[fennel] +symbol = " " + +[fossil_branch] +symbol = " " + +[git_branch] +symbol = " " + +[git_commit] +tag_symbol = '  ' + +[golang] +symbol = " " + +[guix_shell] +symbol = " " + +[haskell] +symbol = " " + +[haxe] +symbol = " " + +[hg_branch] +symbol = " " + +[hostname] +ssh_symbol = " " + +[java] +symbol = " " + +[julia] +symbol = " " + +[kotlin] +symbol = " " + +[lua] +symbol = " " + +[memory_usage] +symbol = "󰍛 " + +[meson] +symbol = "󰔷 " + +[nim] +symbol = "󰆥 " + +[nix_shell] +symbol = " " + +[nodejs] +symbol = " " + +[ocaml] +symbol = " " + +[os.symbols] +Alpaquita = " " +Alpine = " " +AlmaLinux = " " +Amazon = " " +Android = " " +Arch = " " +Artix = " " +CachyOS = " " +CentOS = " " +Debian = " " +DragonFly = " " +Emscripten = " " +EndeavourOS = " " +Fedora = " " +FreeBSD = " " +Garuda = "󰛓 " +Gentoo = " " +HardenedBSD = "󰞌 " +Illumos = "󰈸 " +Kali = " " +Linux = " " +Mabox = " " +Macos = " " +Manjaro = " " +Mariner = " " +MidnightBSD = " " +Mint = " " +NetBSD = " " +NixOS = " " +Nobara = " " +OpenBSD = "󰈺 " +openSUSE = " " +OracleLinux = "󰌷 " +Pop = " " +Raspbian = " " +Redhat = " " +RedHatEnterprise = " " +RockyLinux = " " +Redox = "󰀘 " +Solus = "󰠳 " +SUSE = " " +Ubuntu = " " +Unknown = " " +Void = " " +Windows = "󰍲 " + +[package] +symbol = "󰏗 " + +[perl] +symbol = " " + +[php] +symbol = " " + +[pijul_channel] +symbol = " " + +[python] +symbol = " " + +[rlang] +symbol = "󰟔 " + +[ruby] +symbol = " " + +[rust] +symbol = "󱘗 " + +[scala] +symbol = " " + +[swift] +symbol = " " + +[zig] +symbol = " " + +[gradle] +symbol = " " diff --git a/flake.lock b/flake.lock new file mode 100644 index 0000000..76f3d86 --- /dev/null +++ b/flake.lock @@ -0,0 +1,79 @@ +{ + "nodes": { + "home-manager": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1791484883, + "narHash": "sha256-iKxFHJrg7Sltwhq3ssCZYQ4CFEDVvReVVuVuO9dj3sE=", + "owner": "nix-community", + "repo": "home-manager", + "rev": "dfadbe5162d5e86bc0808badec8f346f81b4b3f0", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "home-manager", + "type": "github" + } + }, + "nixpkgs": { + "locked": { + "lastModified": 1791366222, + "narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "39ad350a0602fa0a58a544344e3e9187526ea45c", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixpkgs-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_2": { + "locked": { + "lastModified": 1791366222, + "narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "39ad350a0602fa0a58a544344e3e9187526ea45c", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixpkgs-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "root": { + "inputs": { + "home-manager": "home-manager", + "nixpkgs": "nixpkgs", + "tinfoil-proxy": "tinfoil-proxy" + } + }, + "tinfoil-proxy": { + "inputs": { + "nixpkgs": "nixpkgs_2" + }, + "locked": { + "path": "./tinfoil-proxy", + "type": "path" + }, + "original": { + "path": "./tinfoil-proxy", + "type": "path" + }, + "parent": [] + } + }, + "root": "root", + "version": 7 +} diff --git a/flake.nix b/flake.nix new file mode 100644 index 0000000..9e18d82 --- /dev/null +++ b/flake.nix @@ -0,0 +1,29 @@ +{ + description = "nix config for nix-clanker-vm"; + + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable"; + home-manager = { + url = "github:nix-community/home-manager"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + tinfoil-proxy.url = "path:./tinfoil-proxy"; + }; + + outputs = { self, nixpkgs, home-manager, tinfoil-proxy }: + let + system = "x86_64-linux"; + pkgs = nixpkgs.legacyPackages.${system}; + username = "user"; + in { + packages.${system} = { + default = tinfoil-proxy.packages.${system}.default; + tinfoil-proxy = tinfoil-proxy.packages.${system}.default; + }; + + homeConfigurations.${username} = home-manager.lib.homeManagerConfiguration { + inherit pkgs; + modules = [ ./home ]; + }; + }; +} \ No newline at end of file diff --git a/home/default.nix b/home/default.nix new file mode 100644 index 0000000..4f263bc --- /dev/null +++ b/home/default.nix @@ -0,0 +1,25 @@ +{ config, pkgs, ... }: + +{ + home.username = "user"; + home.homeDirectory = "/home/user"; + home.stateVersion = "26.05"; + + home.packages = [ + pkgs.opencode + ]; + + home.file = { + ".config/starship.toml".source = ../config/starship.toml; + ".config/nix/nix.conf".source = ../config/nix.conf; + ".config/opencode/opencode.jsonc".source = ../config/opencode.jsonc; + }; + + home.sessionVariables = { + NIX_SHELL_PRESERVE_PROMPT = "true"; + }; + + programs.bash.enable = true; + programs.starship.enable = true; + programs.home-manager.enable = true; +} \ No newline at end of file diff --git a/install.sh b/install.sh new file mode 100755 index 0000000..5f94a7f --- /dev/null +++ b/install.sh @@ -0,0 +1,22 @@ +#!/usr/bin/env bash +# Install this repo's system nix.conf into place. Idempotent. +# +# sudo ./install.sh update /etc/nix/nix.conf (backs up the current one) +# +# The user-level ~/.config/nix/nix.conf is managed declaratively by Home +# Manager (see home/default.nix). + +set -euo pipefail + +repo_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +conf_file="$repo_dir/config/nix.conf" +target=/etc/nix/nix.conf + +if [ ! -d "$(dirname "$target")" ]; then + sudo mkdir -p "$(dirname "$target")" +fi +if [ -f "$target" ] && ! cmp -s "$conf_file" "$target"; then + sudo cp -a "$target" "$target.bak.$(date +%Y%m%d%H%M%S)" +fi +sudo cp "$conf_file" "$target" +echo "installed $target" \ No newline at end of file diff --git a/tinfoil-proxy/flake.lock b/tinfoil-proxy/flake.lock new file mode 100644 index 0000000..3e40045 --- /dev/null +++ b/tinfoil-proxy/flake.lock @@ -0,0 +1,27 @@ +{ + "nodes": { + "nixpkgs": { + "locked": { + "lastModified": 1791366222, + "narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "39ad350a0602fa0a58a544344e3e9187526ea45c", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixpkgs-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "root": { + "inputs": { + "nixpkgs": "nixpkgs" + } + } + }, + "root": "root", + "version": 7 +} diff --git a/tinfoil-proxy/flake.nix b/tinfoil-proxy/flake.nix new file mode 100644 index 0000000..55bcc82 --- /dev/null +++ b/tinfoil-proxy/flake.nix @@ -0,0 +1,13 @@ +{ + description = "tinfoil-proxy"; + + inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable"; + + outputs = { self, nixpkgs }: + let + system = "x86_64-linux"; + pkgs = import nixpkgs { inherit system; }; + in { + packages.${system}.default = pkgs.callPackage ./package.nix { }; + }; +} diff --git a/tinfoil-proxy/package.nix b/tinfoil-proxy/package.nix new file mode 100644 index 0000000..e05b01d --- /dev/null +++ b/tinfoil-proxy/package.nix @@ -0,0 +1,28 @@ +{ + lib, + buildGoModule, + fetchFromGitHub, + go_1_27, +}: + +buildGoModule.override { go = go_1_27; } (finalAttrs: { + pname = "tinfoil-proxy"; + version = "0.2.3"; + + src = fetchFromGitHub { + owner = "tinfoilsh"; + repo = "tinfoil-proxy"; + tag = "v${finalAttrs.version}"; + hash = "sha256-+HBPiWYmQjqWiquoMnwbNJGqZahgt7bGODQksHOR+pU="; + }; + + vendorHash = "sha256-+NxbJXXNFa8KEcvJF3fvRAjnPwS4vI/cB5zTrQW7+Bk="; + + meta = { + description = "Verified local HTTP proxy to a Tinfoil secure enclave"; + homepage = "https://github.com/tinfoilsh/tinfoil-proxy"; + changelog = "https://github.com/tinfoilsh/tinfoil-proxy/releases/tag/v${finalAttrs.version}"; + license = lib.licenses.asl20; + mainProgram = "tinfoil-proxy"; + }; +})