Adopt Home Manager; manage starship, nix.conf, and opencode config
This commit is contained in:
+13
@@ -0,0 +1,13 @@
|
||||
# nix build outputs
|
||||
result
|
||||
result-*
|
||||
|
||||
# direnv / dev tooling
|
||||
.direnv/
|
||||
|
||||
# editors / OS junk
|
||||
*.swp
|
||||
*.swo
|
||||
.DS_Store
|
||||
|
||||
# keep flake.lock tracked (reproducibility)
|
||||
@@ -0,0 +1,49 @@
|
||||
# nix-clanker-vm
|
||||
|
||||
Nix configuration for this host (a Debian VM with standalone Nix).
|
||||
|
||||
## What's here
|
||||
|
||||
- `flake.nix` — root flake: aggregates packages and the Home Manager config.
|
||||
- `tinfoil-proxy/` — self-contained flake packaging `tinfoil-proxy` (Go).
|
||||
- `home/` — Home Manager configuration (user `user`): bash, shell env,
|
||||
starship (declarative init), user-level nix.conf, installed packages
|
||||
(opencode), managed opencode config.
|
||||
- `config/nix.conf` — source of truth for Nix settings (`sandbox`, flakes).
|
||||
- `config/starship.toml` — the host's starship preset (nerd-font-symbols).
|
||||
- `config/opencode.jsonc` — global opencode config, managed via `home.file`.
|
||||
- `install.sh` — applies `config/nix.conf` system-wide (sudo, backs up).
|
||||
|
||||
## Apply
|
||||
|
||||
```sh
|
||||
sudo ./install.sh # update /etc/nix/nix.conf
|
||||
home-manager --flake ~/nix#user switch
|
||||
```
|
||||
|
||||
The user-level `~/.config/nix/nix.conf` is managed by Home Manager via
|
||||
`home.file` in `home/default.nix`; the shell environment is owned by
|
||||
`programs.bash` (plus `hm-session-vars.sh`).
|
||||
|
||||
## Build
|
||||
|
||||
```sh
|
||||
nix build ~/nix
|
||||
nix build ~/nix/tinfoil-proxy
|
||||
```
|
||||
|
||||
## Push to Codeberg
|
||||
|
||||
```sh
|
||||
git remote add origin git@codeberg.org:kawaiipunk/nix-clanker-vm.git
|
||||
git branch -M main
|
||||
git push -u origin main
|
||||
```
|
||||
|
||||
## Notes
|
||||
|
||||
- `sandbox = true` is a restricted setting; when supplied from the user-level
|
||||
config it is ignored with a warning (the daemon enforces it from
|
||||
`/etc/nix/nix.conf`). This is cosmetic.
|
||||
- Existing pre-Home-Manager dotfiles were moved to `~/.bashrc.backup` and
|
||||
`~/.profile.backup` during the first switch.
|
||||
@@ -0,0 +1,2 @@
|
||||
sandbox = true
|
||||
experimental-features = nix-command flakes
|
||||
@@ -0,0 +1,3 @@
|
||||
{
|
||||
"$schema": "https://opencode.ai/config.json"
|
||||
}
|
||||
@@ -0,0 +1,175 @@
|
||||
[aws]
|
||||
symbol = " "
|
||||
|
||||
[buf]
|
||||
symbol = " "
|
||||
|
||||
[c]
|
||||
symbol = " "
|
||||
|
||||
[cmake]
|
||||
symbol = " "
|
||||
|
||||
[conda]
|
||||
symbol = " "
|
||||
|
||||
[crystal]
|
||||
symbol = " "
|
||||
|
||||
[dart]
|
||||
symbol = " "
|
||||
|
||||
[directory]
|
||||
read_only = " "
|
||||
|
||||
[docker_context]
|
||||
symbol = " "
|
||||
|
||||
[elixir]
|
||||
symbol = " "
|
||||
|
||||
[elm]
|
||||
symbol = " "
|
||||
|
||||
[fennel]
|
||||
symbol = " "
|
||||
|
||||
[fossil_branch]
|
||||
symbol = " "
|
||||
|
||||
[git_branch]
|
||||
symbol = " "
|
||||
|
||||
[git_commit]
|
||||
tag_symbol = ' '
|
||||
|
||||
[golang]
|
||||
symbol = " "
|
||||
|
||||
[guix_shell]
|
||||
symbol = " "
|
||||
|
||||
[haskell]
|
||||
symbol = " "
|
||||
|
||||
[haxe]
|
||||
symbol = " "
|
||||
|
||||
[hg_branch]
|
||||
symbol = " "
|
||||
|
||||
[hostname]
|
||||
ssh_symbol = " "
|
||||
|
||||
[java]
|
||||
symbol = " "
|
||||
|
||||
[julia]
|
||||
symbol = " "
|
||||
|
||||
[kotlin]
|
||||
symbol = " "
|
||||
|
||||
[lua]
|
||||
symbol = " "
|
||||
|
||||
[memory_usage]
|
||||
symbol = " "
|
||||
|
||||
[meson]
|
||||
symbol = " "
|
||||
|
||||
[nim]
|
||||
symbol = " "
|
||||
|
||||
[nix_shell]
|
||||
symbol = " "
|
||||
|
||||
[nodejs]
|
||||
symbol = " "
|
||||
|
||||
[ocaml]
|
||||
symbol = " "
|
||||
|
||||
[os.symbols]
|
||||
Alpaquita = " "
|
||||
Alpine = " "
|
||||
AlmaLinux = " "
|
||||
Amazon = " "
|
||||
Android = " "
|
||||
Arch = " "
|
||||
Artix = " "
|
||||
CachyOS = " "
|
||||
CentOS = " "
|
||||
Debian = " "
|
||||
DragonFly = " "
|
||||
Emscripten = " "
|
||||
EndeavourOS = " "
|
||||
Fedora = " "
|
||||
FreeBSD = " "
|
||||
Garuda = " "
|
||||
Gentoo = " "
|
||||
HardenedBSD = " "
|
||||
Illumos = " "
|
||||
Kali = " "
|
||||
Linux = " "
|
||||
Mabox = " "
|
||||
Macos = " "
|
||||
Manjaro = " "
|
||||
Mariner = " "
|
||||
MidnightBSD = " "
|
||||
Mint = " "
|
||||
NetBSD = " "
|
||||
NixOS = " "
|
||||
Nobara = " "
|
||||
OpenBSD = " "
|
||||
openSUSE = " "
|
||||
OracleLinux = " "
|
||||
Pop = " "
|
||||
Raspbian = " "
|
||||
Redhat = " "
|
||||
RedHatEnterprise = " "
|
||||
RockyLinux = " "
|
||||
Redox = " "
|
||||
Solus = " "
|
||||
SUSE = " "
|
||||
Ubuntu = " "
|
||||
Unknown = " "
|
||||
Void = " "
|
||||
Windows = " "
|
||||
|
||||
[package]
|
||||
symbol = " "
|
||||
|
||||
[perl]
|
||||
symbol = " "
|
||||
|
||||
[php]
|
||||
symbol = " "
|
||||
|
||||
[pijul_channel]
|
||||
symbol = " "
|
||||
|
||||
[python]
|
||||
symbol = " "
|
||||
|
||||
[rlang]
|
||||
symbol = " "
|
||||
|
||||
[ruby]
|
||||
symbol = " "
|
||||
|
||||
[rust]
|
||||
symbol = " "
|
||||
|
||||
[scala]
|
||||
symbol = " "
|
||||
|
||||
[swift]
|
||||
symbol = " "
|
||||
|
||||
[zig]
|
||||
symbol = " "
|
||||
|
||||
[gradle]
|
||||
symbol = " "
|
||||
Generated
+79
@@ -0,0 +1,79 @@
|
||||
{
|
||||
"nodes": {
|
||||
"home-manager": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1791484883,
|
||||
"narHash": "sha256-iKxFHJrg7Sltwhq3ssCZYQ4CFEDVvReVVuVuO9dj3sE=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "dfadbe5162d5e86bc0808badec8f346f81b4b3f0",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1791366222,
|
||||
"narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "39ad350a0602fa0a58a544344e3e9187526ea45c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixpkgs-unstable",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_2": {
|
||||
"locked": {
|
||||
"lastModified": 1791366222,
|
||||
"narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "39ad350a0602fa0a58a544344e3e9187526ea45c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixpkgs-unstable",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"root": {
|
||||
"inputs": {
|
||||
"home-manager": "home-manager",
|
||||
"nixpkgs": "nixpkgs",
|
||||
"tinfoil-proxy": "tinfoil-proxy"
|
||||
}
|
||||
},
|
||||
"tinfoil-proxy": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_2"
|
||||
},
|
||||
"locked": {
|
||||
"path": "./tinfoil-proxy",
|
||||
"type": "path"
|
||||
},
|
||||
"original": {
|
||||
"path": "./tinfoil-proxy",
|
||||
"type": "path"
|
||||
},
|
||||
"parent": []
|
||||
}
|
||||
},
|
||||
"root": "root",
|
||||
"version": 7
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
description = "nix config for nix-clanker-vm";
|
||||
|
||||
inputs = {
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
||||
home-manager = {
|
||||
url = "github:nix-community/home-manager";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
tinfoil-proxy.url = "path:./tinfoil-proxy";
|
||||
};
|
||||
|
||||
outputs = { self, nixpkgs, home-manager, tinfoil-proxy }:
|
||||
let
|
||||
system = "x86_64-linux";
|
||||
pkgs = nixpkgs.legacyPackages.${system};
|
||||
username = "user";
|
||||
in {
|
||||
packages.${system} = {
|
||||
default = tinfoil-proxy.packages.${system}.default;
|
||||
tinfoil-proxy = tinfoil-proxy.packages.${system}.default;
|
||||
};
|
||||
|
||||
homeConfigurations.${username} = home-manager.lib.homeManagerConfiguration {
|
||||
inherit pkgs;
|
||||
modules = [ ./home ];
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
{ config, pkgs, ... }:
|
||||
|
||||
{
|
||||
home.username = "user";
|
||||
home.homeDirectory = "/home/user";
|
||||
home.stateVersion = "26.05";
|
||||
|
||||
home.packages = [
|
||||
pkgs.opencode
|
||||
];
|
||||
|
||||
home.file = {
|
||||
".config/starship.toml".source = ../config/starship.toml;
|
||||
".config/nix/nix.conf".source = ../config/nix.conf;
|
||||
".config/opencode/opencode.jsonc".source = ../config/opencode.jsonc;
|
||||
};
|
||||
|
||||
home.sessionVariables = {
|
||||
NIX_SHELL_PRESERVE_PROMPT = "true";
|
||||
};
|
||||
|
||||
programs.bash.enable = true;
|
||||
programs.starship.enable = true;
|
||||
programs.home-manager.enable = true;
|
||||
}
|
||||
Executable
+22
@@ -0,0 +1,22 @@
|
||||
#!/usr/bin/env bash
|
||||
# Install this repo's system nix.conf into place. Idempotent.
|
||||
#
|
||||
# sudo ./install.sh update /etc/nix/nix.conf (backs up the current one)
|
||||
#
|
||||
# The user-level ~/.config/nix/nix.conf is managed declaratively by Home
|
||||
# Manager (see home/default.nix).
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
repo_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
conf_file="$repo_dir/config/nix.conf"
|
||||
target=/etc/nix/nix.conf
|
||||
|
||||
if [ ! -d "$(dirname "$target")" ]; then
|
||||
sudo mkdir -p "$(dirname "$target")"
|
||||
fi
|
||||
if [ -f "$target" ] && ! cmp -s "$conf_file" "$target"; then
|
||||
sudo cp -a "$target" "$target.bak.$(date +%Y%m%d%H%M%S)"
|
||||
fi
|
||||
sudo cp "$conf_file" "$target"
|
||||
echo "installed $target"
|
||||
Generated
+27
@@ -0,0 +1,27 @@
|
||||
{
|
||||
"nodes": {
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1791366222,
|
||||
"narHash": "sha256-o0N4g6uSOIppU7CGToNvGlMf5vC+B6O6ukFHKY/TKOY=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "39ad350a0602fa0a58a544344e3e9187526ea45c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixpkgs-unstable",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"root": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs"
|
||||
}
|
||||
}
|
||||
},
|
||||
"root": "root",
|
||||
"version": 7
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
{
|
||||
description = "tinfoil-proxy";
|
||||
|
||||
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
||||
|
||||
outputs = { self, nixpkgs }:
|
||||
let
|
||||
system = "x86_64-linux";
|
||||
pkgs = import nixpkgs { inherit system; };
|
||||
in {
|
||||
packages.${system}.default = pkgs.callPackage ./package.nix { };
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
{
|
||||
lib,
|
||||
buildGoModule,
|
||||
fetchFromGitHub,
|
||||
go_1_27,
|
||||
}:
|
||||
|
||||
buildGoModule.override { go = go_1_27; } (finalAttrs: {
|
||||
pname = "tinfoil-proxy";
|
||||
version = "0.2.3";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "tinfoilsh";
|
||||
repo = "tinfoil-proxy";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-+HBPiWYmQjqWiquoMnwbNJGqZahgt7bGODQksHOR+pU=";
|
||||
};
|
||||
|
||||
vendorHash = "sha256-+NxbJXXNFa8KEcvJF3fvRAjnPwS4vI/cB5zTrQW7+Bk=";
|
||||
|
||||
meta = {
|
||||
description = "Verified local HTTP proxy to a Tinfoil secure enclave";
|
||||
homepage = "https://github.com/tinfoilsh/tinfoil-proxy";
|
||||
changelog = "https://github.com/tinfoilsh/tinfoil-proxy/releases/tag/v${finalAttrs.version}";
|
||||
license = lib.licenses.asl20;
|
||||
mainProgram = "tinfoil-proxy";
|
||||
};
|
||||
})
|
||||
Reference in New Issue
Block a user