Adopt Home Manager; manage starship, nix.conf, and opencode config
This commit is contained in:
+13
@@ -0,0 +1,13 @@
|
|||||||
|
# nix build outputs
|
||||||
|
result
|
||||||
|
result-*
|
||||||
|
|
||||||
|
# direnv / dev tooling
|
||||||
|
.direnv/
|
||||||
|
|
||||||
|
# editors / OS junk
|
||||||
|
*.swp
|
||||||
|
*.swo
|
||||||
|
.DS_Store
|
||||||
|
|
||||||
|
# keep flake.lock tracked (reproducibility)
|
||||||
@@ -0,0 +1,49 @@
|
|||||||
|
# nix-clanker-vm
|
||||||
|
|
||||||
|
Nix configuration for this host (a Debian VM with standalone Nix).
|
||||||
|
|
||||||
|
## What's here
|
||||||
|
|
||||||
|
- `flake.nix` — root flake: aggregates packages and the Home Manager config.
|
||||||
|
- `tinfoil-proxy/` — self-contained flake packaging `tinfoil-proxy` (Go).
|
||||||
|
- `home/` — Home Manager configuration (user `user`): bash, shell env,
|
||||||
|
starship (declarative init), user-level nix.conf, installed packages
|
||||||
|
(opencode), managed opencode config.
|
||||||
|
- `config/nix.conf` — source of truth for Nix settings (`sandbox`, flakes).
|
||||||
|
- `config/starship.toml` — the host's starship preset (nerd-font-symbols).
|
||||||
|
- `config/opencode.jsonc` — global opencode config, managed via `home.file`.
|
||||||
|
- `install.sh` — applies `config/nix.conf` system-wide (sudo, backs up).
|
||||||
|
|
||||||
|
## Apply
|
||||||
|
|
||||||
|
```sh
|
||||||
|
sudo ./install.sh # update /etc/nix/nix.conf
|
||||||
|
home-manager --flake ~/nix#user switch
|
||||||
|
```
|
||||||
|
|
||||||
|
The user-level `~/.config/nix/nix.conf` is managed by Home Manager via
|
||||||
|
`home.file` in `home/default.nix`; the shell environment is owned by
|
||||||
|
`programs.bash` (plus `hm-session-vars.sh`).
|
||||||
|
|
||||||
|
## Build
|
||||||
|
|
||||||
|
```sh
|
||||||
|
nix build ~/nix
|
||||||
|
nix build ~/nix/tinfoil-proxy
|
||||||
|
```
|
||||||
|
|
||||||
|
## Push to Codeberg
|
||||||
|
|
||||||
|
```sh
|
||||||
|
git remote add origin git@codeberg.org:kawaiipunk/nix-clanker-vm.git
|
||||||
|
git branch -M main
|
||||||
|
git push -u origin main
|
||||||
|
```
|
||||||
|
|
||||||
|
## Notes
|
||||||
|
|
||||||
|
- `sandbox = true` is a restricted setting; when supplied from the user-level
|
||||||
|
config it is ignored with a warning (the daemon enforces it from
|
||||||
|
`/etc/nix/nix.conf`). This is cosmetic.
|
||||||
|
- Existing pre-Home-Manager dotfiles were moved to `~/.bashrc.backup` and
|
||||||
|
`~/.profile.backup` during the first switch.
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
sandbox = true
|
||||||
|
experimental-features = nix-command flakes
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://opencode.ai/config.json"
|
||||||
|
}
|
||||||
@@ -0,0 +1,175 @@
|
|||||||
|
[aws]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[buf]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[c]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[cmake]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[conda]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[crystal]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[dart]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[directory]
|
||||||
|
read_only = " "
|
||||||
|
|
||||||
|
[docker_context]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[elixir]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[elm]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[fennel]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[fossil_branch]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[git_branch]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[git_commit]
|
||||||
|
tag_symbol = ' '
|
||||||
|
|
||||||
|
[golang]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[guix_shell]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[haskell]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[haxe]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[hg_branch]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[hostname]
|
||||||
|
ssh_symbol = " "
|
||||||
|
|
||||||
|
[java]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[julia]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[kotlin]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[lua]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[memory_usage]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[meson]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[nim]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[nix_shell]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[nodejs]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[ocaml]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[os.symbols]
|
||||||
|
Alpaquita = " "
|
||||||
|
Alpine = " "
|
||||||
|
AlmaLinux = " "
|
||||||
|
Amazon = " "
|
||||||
|
Android = " "
|
||||||
|
Arch = " "
|
||||||
|
Artix = " "
|
||||||
|
CachyOS = " "
|
||||||
|
CentOS = " "
|
||||||
|
Debian = " "
|
||||||
|
DragonFly = " "
|
||||||
|
Emscripten = " "
|
||||||
|
EndeavourOS = " "
|
||||||
|
Fedora = " "
|
||||||
|
FreeBSD = " "
|
||||||
|
Garuda = " "
|
||||||
|
Gentoo = " "
|
||||||
|
HardenedBSD = " "
|
||||||
|
Illumos = " "
|
||||||
|
Kali = " "
|
||||||
|
Linux = " "
|
||||||
|
Mabox = " "
|
||||||
|
Macos = " "
|
||||||
|
Manjaro = " "
|
||||||
|
Mariner = " "
|
||||||
|
MidnightBSD = " "
|
||||||
|
Mint = " "
|
||||||
|
NetBSD = " "
|
||||||
|
NixOS = " "
|
||||||
|
Nobara = " "
|
||||||
|
OpenBSD = " "
|
||||||
|
openSUSE = " "
|
||||||
|
OracleLinux = " "
|
||||||
|
Pop = " "
|
||||||
|
Raspbian = " "
|
||||||
|
Redhat = " "
|
||||||
|
RedHatEnterprise = " "
|
||||||
|
RockyLinux = " "
|
||||||
|
Redox = " "
|
||||||
|
Solus = " "
|
||||||
|
SUSE = " "
|
||||||
|
Ubuntu = " "
|
||||||
|
Unknown = " "
|
||||||
|
Void = " "
|
||||||
|
Windows = " "
|
||||||
|
|
||||||
|
[package]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[perl]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[php]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[pijul_channel]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[python]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[rlang]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[ruby]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[rust]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[scala]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[swift]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[zig]
|
||||||
|
symbol = " "
|
||||||
|
|
||||||
|
[gradle]
|
||||||
|
symbol = " "
|
||||||
Generated
+79
@@ -0,0 +1,79 @@
|
|||||||
|
{
|
||||||
|
"nodes": {
|
||||||
|
"home-manager": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"nixpkgs"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1791484883,
|
||||||
|
"narHash": "sha256-iKxFHJrg7Sltwhq3ssCZYQ4CFEDVvReVVuVuO9dj3sE=",
|
||||||
|
"owner": "nix-community",
|
||||||
|
"repo": "home-manager",
|
||||||
|
"rev": "dfadbe5162d5e86bc0808badec8f346f81b4b3f0",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "nix-community",
|
||||||
|
"repo": "home-manager",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"nixpkgs": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1791366222,
|
||||||
|
"narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=",
|
||||||
|
"owner": "NixOS",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "39ad350a0602fa0a58a544344e3e9187526ea45c",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "NixOS",
|
||||||
|
"ref": "nixpkgs-unstable",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"nixpkgs_2": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1791366222,
|
||||||
|
"narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=",
|
||||||
|
"owner": "NixOS",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "39ad350a0602fa0a58a544344e3e9187526ea45c",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "NixOS",
|
||||||
|
"ref": "nixpkgs-unstable",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"root": {
|
||||||
|
"inputs": {
|
||||||
|
"home-manager": "home-manager",
|
||||||
|
"nixpkgs": "nixpkgs",
|
||||||
|
"tinfoil-proxy": "tinfoil-proxy"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"tinfoil-proxy": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": "nixpkgs_2"
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"path": "./tinfoil-proxy",
|
||||||
|
"type": "path"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"path": "./tinfoil-proxy",
|
||||||
|
"type": "path"
|
||||||
|
},
|
||||||
|
"parent": []
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"root": "root",
|
||||||
|
"version": 7
|
||||||
|
}
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
{
|
||||||
|
description = "nix config for nix-clanker-vm";
|
||||||
|
|
||||||
|
inputs = {
|
||||||
|
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
||||||
|
home-manager = {
|
||||||
|
url = "github:nix-community/home-manager";
|
||||||
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
};
|
||||||
|
tinfoil-proxy.url = "path:./tinfoil-proxy";
|
||||||
|
};
|
||||||
|
|
||||||
|
outputs = { self, nixpkgs, home-manager, tinfoil-proxy }:
|
||||||
|
let
|
||||||
|
system = "x86_64-linux";
|
||||||
|
pkgs = nixpkgs.legacyPackages.${system};
|
||||||
|
username = "user";
|
||||||
|
in {
|
||||||
|
packages.${system} = {
|
||||||
|
default = tinfoil-proxy.packages.${system}.default;
|
||||||
|
tinfoil-proxy = tinfoil-proxy.packages.${system}.default;
|
||||||
|
};
|
||||||
|
|
||||||
|
homeConfigurations.${username} = home-manager.lib.homeManagerConfiguration {
|
||||||
|
inherit pkgs;
|
||||||
|
modules = [ ./home ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
{ config, pkgs, ... }:
|
||||||
|
|
||||||
|
{
|
||||||
|
home.username = "user";
|
||||||
|
home.homeDirectory = "/home/user";
|
||||||
|
home.stateVersion = "26.05";
|
||||||
|
|
||||||
|
home.packages = [
|
||||||
|
pkgs.opencode
|
||||||
|
];
|
||||||
|
|
||||||
|
home.file = {
|
||||||
|
".config/starship.toml".source = ../config/starship.toml;
|
||||||
|
".config/nix/nix.conf".source = ../config/nix.conf;
|
||||||
|
".config/opencode/opencode.jsonc".source = ../config/opencode.jsonc;
|
||||||
|
};
|
||||||
|
|
||||||
|
home.sessionVariables = {
|
||||||
|
NIX_SHELL_PRESERVE_PROMPT = "true";
|
||||||
|
};
|
||||||
|
|
||||||
|
programs.bash.enable = true;
|
||||||
|
programs.starship.enable = true;
|
||||||
|
programs.home-manager.enable = true;
|
||||||
|
}
|
||||||
Executable
+22
@@ -0,0 +1,22 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Install this repo's system nix.conf into place. Idempotent.
|
||||||
|
#
|
||||||
|
# sudo ./install.sh update /etc/nix/nix.conf (backs up the current one)
|
||||||
|
#
|
||||||
|
# The user-level ~/.config/nix/nix.conf is managed declaratively by Home
|
||||||
|
# Manager (see home/default.nix).
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
repo_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
|
conf_file="$repo_dir/config/nix.conf"
|
||||||
|
target=/etc/nix/nix.conf
|
||||||
|
|
||||||
|
if [ ! -d "$(dirname "$target")" ]; then
|
||||||
|
sudo mkdir -p "$(dirname "$target")"
|
||||||
|
fi
|
||||||
|
if [ -f "$target" ] && ! cmp -s "$conf_file" "$target"; then
|
||||||
|
sudo cp -a "$target" "$target.bak.$(date +%Y%m%d%H%M%S)"
|
||||||
|
fi
|
||||||
|
sudo cp "$conf_file" "$target"
|
||||||
|
echo "installed $target"
|
||||||
Generated
+27
@@ -0,0 +1,27 @@
|
|||||||
|
{
|
||||||
|
"nodes": {
|
||||||
|
"nixpkgs": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1791366222,
|
||||||
|
"narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=",
|
||||||
|
"owner": "NixOS",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "39ad350a0602fa0a58a544344e3e9187526ea45c",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "NixOS",
|
||||||
|
"ref": "nixpkgs-unstable",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"root": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": "nixpkgs"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"root": "root",
|
||||||
|
"version": 7
|
||||||
|
}
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{
|
||||||
|
description = "tinfoil-proxy";
|
||||||
|
|
||||||
|
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
||||||
|
|
||||||
|
outputs = { self, nixpkgs }:
|
||||||
|
let
|
||||||
|
system = "x86_64-linux";
|
||||||
|
pkgs = import nixpkgs { inherit system; };
|
||||||
|
in {
|
||||||
|
packages.${system}.default = pkgs.callPackage ./package.nix { };
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
{
|
||||||
|
lib,
|
||||||
|
buildGoModule,
|
||||||
|
fetchFromGitHub,
|
||||||
|
go_1_27,
|
||||||
|
}:
|
||||||
|
|
||||||
|
buildGoModule.override { go = go_1_27; } (finalAttrs: {
|
||||||
|
pname = "tinfoil-proxy";
|
||||||
|
version = "0.2.3";
|
||||||
|
|
||||||
|
src = fetchFromGitHub {
|
||||||
|
owner = "tinfoilsh";
|
||||||
|
repo = "tinfoil-proxy";
|
||||||
|
tag = "v${finalAttrs.version}";
|
||||||
|
hash = "sha256-+HBPiWYmQjqWiquoMnwbNJGqZahgt7bGODQksHOR+pU=";
|
||||||
|
};
|
||||||
|
|
||||||
|
vendorHash = "sha256-+NxbJXXNFa8KEcvJF3fvRAjnPwS4vI/cB5zTrQW7+Bk=";
|
||||||
|
|
||||||
|
meta = {
|
||||||
|
description = "Verified local HTTP proxy to a Tinfoil secure enclave";
|
||||||
|
homepage = "https://github.com/tinfoilsh/tinfoil-proxy";
|
||||||
|
changelog = "https://github.com/tinfoilsh/tinfoil-proxy/releases/tag/v${finalAttrs.version}";
|
||||||
|
license = lib.licenses.asl20;
|
||||||
|
mainProgram = "tinfoil-proxy";
|
||||||
|
};
|
||||||
|
})
|
||||||
Reference in New Issue
Block a user