Adopt Home Manager; manage starship, nix.conf, and opencode config

This commit is contained in:
2026-10-08 22:17:14 +00:00
commit 40abf86655
12 changed files with 465 additions and 0 deletions
+13
View File
@@ -0,0 +1,13 @@
# nix build outputs
result
result-*
# direnv / dev tooling
.direnv/
# editors / OS junk
*.swp
*.swo
.DS_Store
# keep flake.lock tracked (reproducibility)
+49
View File
@@ -0,0 +1,49 @@
# nix-clanker-vm
Nix configuration for this host (a Debian VM with standalone Nix).
## What's here
- `flake.nix` — root flake: aggregates packages and the Home Manager config.
- `tinfoil-proxy/` — self-contained flake packaging `tinfoil-proxy` (Go).
- `home/` — Home Manager configuration (user `user`): bash, shell env,
starship (declarative init), user-level nix.conf, installed packages
(opencode), managed opencode config.
- `config/nix.conf` — source of truth for Nix settings (`sandbox`, flakes).
- `config/starship.toml` — the host's starship preset (nerd-font-symbols).
- `config/opencode.jsonc` — global opencode config, managed via `home.file`.
- `install.sh` — applies `config/nix.conf` system-wide (sudo, backs up).
## Apply
```sh
sudo ./install.sh # update /etc/nix/nix.conf
home-manager --flake ~/nix#user switch
```
The user-level `~/.config/nix/nix.conf` is managed by Home Manager via
`home.file` in `home/default.nix`; the shell environment is owned by
`programs.bash` (plus `hm-session-vars.sh`).
## Build
```sh
nix build ~/nix
nix build ~/nix/tinfoil-proxy
```
## Push to Codeberg
```sh
git remote add origin git@codeberg.org:kawaiipunk/nix-clanker-vm.git
git branch -M main
git push -u origin main
```
## Notes
- `sandbox = true` is a restricted setting; when supplied from the user-level
config it is ignored with a warning (the daemon enforces it from
`/etc/nix/nix.conf`). This is cosmetic.
- Existing pre-Home-Manager dotfiles were moved to `~/.bashrc.backup` and
`~/.profile.backup` during the first switch.
+2
View File
@@ -0,0 +1,2 @@
sandbox = true
experimental-features = nix-command flakes
+3
View File
@@ -0,0 +1,3 @@
{
"$schema": "https://opencode.ai/config.json"
}
+175
View File
@@ -0,0 +1,175 @@
[aws]
symbol = " "
[buf]
symbol = " "
[c]
symbol = " "
[cmake]
symbol = " "
[conda]
symbol = " "
[crystal]
symbol = " "
[dart]
symbol = " "
[directory]
read_only = " 󰌾"
[docker_context]
symbol = " "
[elixir]
symbol = " "
[elm]
symbol = " "
[fennel]
symbol = " "
[fossil_branch]
symbol = " "
[git_branch]
symbol = " "
[git_commit]
tag_symbol = '  '
[golang]
symbol = " "
[guix_shell]
symbol = " "
[haskell]
symbol = " "
[haxe]
symbol = " "
[hg_branch]
symbol = " "
[hostname]
ssh_symbol = " "
[java]
symbol = " "
[julia]
symbol = " "
[kotlin]
symbol = " "
[lua]
symbol = " "
[memory_usage]
symbol = "󰍛 "
[meson]
symbol = "󰔷 "
[nim]
symbol = "󰆥 "
[nix_shell]
symbol = " "
[nodejs]
symbol = " "
[ocaml]
symbol = " "
[os.symbols]
Alpaquita = " "
Alpine = " "
AlmaLinux = " "
Amazon = " "
Android = " "
Arch = " "
Artix = " "
CachyOS = " "
CentOS = " "
Debian = " "
DragonFly = " "
Emscripten = " "
EndeavourOS = " "
Fedora = " "
FreeBSD = " "
Garuda = "󰛓 "
Gentoo = " "
HardenedBSD = "󰞌 "
Illumos = "󰈸 "
Kali = " "
Linux = " "
Mabox = " "
Macos = " "
Manjaro = " "
Mariner = " "
MidnightBSD = " "
Mint = " "
NetBSD = " "
NixOS = " "
Nobara = " "
OpenBSD = "󰈺 "
openSUSE = " "
OracleLinux = "󰌷 "
Pop = " "
Raspbian = " "
Redhat = " "
RedHatEnterprise = " "
RockyLinux = " "
Redox = "󰀘 "
Solus = "󰠳 "
SUSE = " "
Ubuntu = " "
Unknown = " "
Void = " "
Windows = "󰍲 "
[package]
symbol = "󰏗 "
[perl]
symbol = " "
[php]
symbol = " "
[pijul_channel]
symbol = " "
[python]
symbol = " "
[rlang]
symbol = "󰟔 "
[ruby]
symbol = " "
[rust]
symbol = "󱘗 "
[scala]
symbol = " "
[swift]
symbol = " "
[zig]
symbol = " "
[gradle]
symbol = " "
Generated
+79
View File
@@ -0,0 +1,79 @@
{
"nodes": {
"home-manager": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1791484883,
"narHash": "sha256-iKxFHJrg7Sltwhq3ssCZYQ4CFEDVvReVVuVuO9dj3sE=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "dfadbe5162d5e86bc0808badec8f346f81b4b3f0",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "home-manager",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1791366222,
"narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "39ad350a0602fa0a58a544344e3e9187526ea45c",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_2": {
"locked": {
"lastModified": 1791366222,
"narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "39ad350a0602fa0a58a544344e3e9187526ea45c",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"root": {
"inputs": {
"home-manager": "home-manager",
"nixpkgs": "nixpkgs",
"tinfoil-proxy": "tinfoil-proxy"
}
},
"tinfoil-proxy": {
"inputs": {
"nixpkgs": "nixpkgs_2"
},
"locked": {
"path": "./tinfoil-proxy",
"type": "path"
},
"original": {
"path": "./tinfoil-proxy",
"type": "path"
},
"parent": []
}
},
"root": "root",
"version": 7
}
+29
View File
@@ -0,0 +1,29 @@
{
description = "nix config for nix-clanker-vm";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
home-manager = {
url = "github:nix-community/home-manager";
inputs.nixpkgs.follows = "nixpkgs";
};
tinfoil-proxy.url = "path:./tinfoil-proxy";
};
outputs = { self, nixpkgs, home-manager, tinfoil-proxy }:
let
system = "x86_64-linux";
pkgs = nixpkgs.legacyPackages.${system};
username = "user";
in {
packages.${system} = {
default = tinfoil-proxy.packages.${system}.default;
tinfoil-proxy = tinfoil-proxy.packages.${system}.default;
};
homeConfigurations.${username} = home-manager.lib.homeManagerConfiguration {
inherit pkgs;
modules = [ ./home ];
};
};
}
+25
View File
@@ -0,0 +1,25 @@
{ config, pkgs, ... }:
{
home.username = "user";
home.homeDirectory = "/home/user";
home.stateVersion = "26.05";
home.packages = [
pkgs.opencode
];
home.file = {
".config/starship.toml".source = ../config/starship.toml;
".config/nix/nix.conf".source = ../config/nix.conf;
".config/opencode/opencode.jsonc".source = ../config/opencode.jsonc;
};
home.sessionVariables = {
NIX_SHELL_PRESERVE_PROMPT = "true";
};
programs.bash.enable = true;
programs.starship.enable = true;
programs.home-manager.enable = true;
}
Executable
+22
View File
@@ -0,0 +1,22 @@
#!/usr/bin/env bash
# Install this repo's system nix.conf into place. Idempotent.
#
# sudo ./install.sh update /etc/nix/nix.conf (backs up the current one)
#
# The user-level ~/.config/nix/nix.conf is managed declaratively by Home
# Manager (see home/default.nix).
set -euo pipefail
repo_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
conf_file="$repo_dir/config/nix.conf"
target=/etc/nix/nix.conf
if [ ! -d "$(dirname "$target")" ]; then
sudo mkdir -p "$(dirname "$target")"
fi
if [ -f "$target" ] && ! cmp -s "$conf_file" "$target"; then
sudo cp -a "$target" "$target.bak.$(date +%Y%m%d%H%M%S)"
fi
sudo cp "$conf_file" "$target"
echo "installed $target"
+27
View File
@@ -0,0 +1,27 @@
{
"nodes": {
"nixpkgs": {
"locked": {
"lastModified": 1791366222,
"narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "39ad350a0602fa0a58a544344e3e9187526ea45c",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"root": {
"inputs": {
"nixpkgs": "nixpkgs"
}
}
},
"root": "root",
"version": 7
}
+13
View File
@@ -0,0 +1,13 @@
{
description = "tinfoil-proxy";
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
outputs = { self, nixpkgs }:
let
system = "x86_64-linux";
pkgs = import nixpkgs { inherit system; };
in {
packages.${system}.default = pkgs.callPackage ./package.nix { };
};
}
+28
View File
@@ -0,0 +1,28 @@
{
lib,
buildGoModule,
fetchFromGitHub,
go_1_27,
}:
buildGoModule.override { go = go_1_27; } (finalAttrs: {
pname = "tinfoil-proxy";
version = "0.2.3";
src = fetchFromGitHub {
owner = "tinfoilsh";
repo = "tinfoil-proxy";
tag = "v${finalAttrs.version}";
hash = "sha256-+HBPiWYmQjqWiquoMnwbNJGqZahgt7bGODQksHOR+pU=";
};
vendorHash = "sha256-+NxbJXXNFa8KEcvJF3fvRAjnPwS4vI/cB5zTrQW7+Bk=";
meta = {
description = "Verified local HTTP proxy to a Tinfoil secure enclave";
homepage = "https://github.com/tinfoilsh/tinfoil-proxy";
changelog = "https://github.com/tinfoilsh/tinfoil-proxy/releases/tag/v${finalAttrs.version}";
license = lib.licenses.asl20;
mainProgram = "tinfoil-proxy";
};
})