Further changes
This commit is contained in:
@@ -1,53 +1,162 @@
|
||||
# nix-clanker-vm
|
||||
|
||||
Nix configuration for this host (a Debian VM with standalone Nix).
|
||||
Nix flake + [Home Manager](https://github.com/nix-community/home-manager)
|
||||
configuration for this host: a Debian VM running **standalone Nix**
|
||||
(non-NixOS).
|
||||
|
||||
## What's here
|
||||
## Overview
|
||||
|
||||
- `flake.nix` — root flake: aggregates packages and the Home Manager config.
|
||||
- `tinfoil-proxy/` — self-contained flake packaging `tinfoil-proxy` (Go).
|
||||
- `home/` — Home Manager configuration (user `user`): bash, shell env,
|
||||
starship (declarative init), user-level nix.conf, installed packages
|
||||
(opencode), managed opencode config.
|
||||
- `config/nix.conf` — source of truth for Nix settings (`sandbox`, flakes).
|
||||
- `config/starship.toml` — the host's starship preset (nerd-font-symbols).
|
||||
- `config/opencode.jsonc` — global opencode config, managed via `home.file`.
|
||||
- `install.sh` — applies `config/nix.conf` system-wide (sudo, backs up).
|
||||
- Declarative, reproducible user environment managed by Home Manager.
|
||||
- A self-contained `tinfoil-proxy` package flake (Go).
|
||||
- System-wide Nix settings applied separately via `install.sh`.
|
||||
|
||||
## Apply
|
||||
## Prerequisites
|
||||
|
||||
- x86_64 Linux.
|
||||
- Nix with `nix-command` and `flakes` enabled (see `config/nix.conf`).
|
||||
- `home-manager` available on `PATH`.
|
||||
- `sudo` access for the system-wide `/etc/nix/nix.conf` step.
|
||||
|
||||
## Quick start
|
||||
|
||||
```sh
|
||||
sudo ./install.sh # update /etc/nix/nix.conf
|
||||
home-manager --flake ~/nix#user switch
|
||||
git clone <your-repo-url> ~/nix
|
||||
cd ~/nix
|
||||
|
||||
sudo ./install.sh # install /etc/nix/nix.conf (backs up)
|
||||
home-manager switch --flake .#user # apply the Home Manager config
|
||||
```
|
||||
|
||||
The user-level `~/.config/nix/nix.conf` is managed by Home Manager via
|
||||
`home.file` in `home/default.nix`; the shell environment is owned by
|
||||
`programs.bash` (plus `hm-session-vars.sh`).
|
||||
## Repository layout
|
||||
|
||||
## Build
|
||||
| Path | Purpose |
|
||||
| ------------------------- | -------------------------------------------------------------- |
|
||||
| `flake.nix` | Root flake: packages and the Home Manager configuration. |
|
||||
| `home/default.nix` | Home Manager config for user `user` (packages, programs, the `tinfoil-proxy` user service). |
|
||||
| `config/` | Source files linked into `~/.config` (nix, starship, opencode incl. the Tinfoil provider). |
|
||||
| `tinfoil-proxy/` | Self-contained flake packaging `tinfoil-proxy` (Go). |
|
||||
| `install.sh` | Applies `config/nix.conf` to `/etc/nix/nix.conf` (sudo). |
|
||||
| `flake.lock` | Pinned input revisions (tracked for reproducibility). |
|
||||
|
||||
## Managing packages
|
||||
|
||||
Packages are declared in `home.packages` in `home/default.nix`. To add one,
|
||||
append it to the list and re-apply:
|
||||
|
||||
```nix
|
||||
home.packages = [
|
||||
pkgs.ripgrep # example: add whatever you need
|
||||
];
|
||||
```
|
||||
|
||||
```sh
|
||||
nix build ~/nix
|
||||
nix build ~/nix/tinfoil-proxy
|
||||
home-manager switch --flake .#user
|
||||
```
|
||||
|
||||
## Push to Codeberg
|
||||
To remove a package, delete its entry and re-run the same command. The
|
||||
authoritative, always-current list lives in `home/default.nix`.
|
||||
|
||||
For one-off, ad-hoc use outside the managed environment:
|
||||
|
||||
```sh
|
||||
git remote add origin git@codeberg.org:kawaiipunk/nix-clanker-vm.git
|
||||
git branch -M main
|
||||
git push -u origin main
|
||||
nix shell nixpkgs#<package>
|
||||
```
|
||||
|
||||
## Notes
|
||||
## Managing configuration
|
||||
|
||||
- `sandbox = true` is a restricted setting; when supplied from the user-level
|
||||
config it is ignored with a warning (the daemon enforces it from
|
||||
`/etc/nix/nix.conf`). This is cosmetic.
|
||||
- Existing pre-Home-Manager dotfiles are no longer kept as backups; the shell is
|
||||
fully owned by `programs.bash` + `programs.starship` (session vars from
|
||||
`hm-session-vars.sh`).
|
||||
- `/etc/profile.d/zzbubbles.sh` is a stale, unmanaged start-of-day script that
|
||||
duplicates starship init and references a removed `/home/runner` path. Remove
|
||||
it once (sudo): `sudo rm /etc/profile.d/zzbubbles.sh`.
|
||||
Home Manager drives configuration through three mechanisms in
|
||||
`home/default.nix`:
|
||||
|
||||
- **Files linked from this repo** via `home.file`. Add an entry to link a
|
||||
file from `config/` into your home directory:
|
||||
|
||||
```nix
|
||||
home.file.".config/foo/foo.conf".source = ../config/foo.conf;
|
||||
```
|
||||
|
||||
- **Program modules** via `programs.<name>` (e.g. `programs.bash`,
|
||||
`programs.fish`, `programs.tmux`, `programs.starship`). Enable or
|
||||
customize a module here instead of editing dotfiles by hand.
|
||||
|
||||
- **Environment variables** via `home.sessionVariables`.
|
||||
|
||||
Apply any change with:
|
||||
|
||||
```sh
|
||||
home-manager switch --flake .#user
|
||||
```
|
||||
|
||||
## Customization
|
||||
|
||||
The config is host-specific. Current values and where to change them:
|
||||
|
||||
| Setting | File | Current value |
|
||||
| ---------------- | ------------------- | --------------- |
|
||||
| Username | `flake.nix` | `"user"` |
|
||||
| Username | `home/default.nix` | `"user"` |
|
||||
| Home directory | `home/default.nix` | `"/home/user"` |
|
||||
| System | `flake.nix` | `"x86_64-linux"`|
|
||||
| System | `tinfoil-proxy/flake.nix` | `"x86_64-linux"` |
|
||||
|
||||
- **Change the username**: update `username` in `flake.nix` and both
|
||||
`home.username` / `home.homeDirectory` in `home/default.nix`. The Home
|
||||
Manager flake attribute name is derived from `username`, so the apply
|
||||
command becomes `home-manager switch --flake .#<newuser>`.
|
||||
- **Change the system**: update `system` in `flake.nix` and in
|
||||
`tinfoil-proxy/flake.nix`.
|
||||
|
||||
## The `tinfoil-proxy` package
|
||||
|
||||
`tinfoil-proxy/` is an independent flake that packages the Go program
|
||||
`tinfoil-proxy` (a verified local HTTP proxy to a Tinfoil secure enclave).
|
||||
Version, source hash, and vendor hash live in `tinfoil-proxy/package.nix`.
|
||||
|
||||
```sh
|
||||
nix build ./tinfoil-proxy
|
||||
```
|
||||
|
||||
## Tinfoil models in OpenCode
|
||||
|
||||
The managed OpenCode config (`config/opencode.jsonc`) defines a `tinfoil`
|
||||
provider that points at the local proxy on `http://127.0.0.1:3301/v1`. Every
|
||||
request is checked against Tinfoil's attestation transparency log before it
|
||||
reaches a secure enclave.
|
||||
|
||||
The proxy is installed as a systemd user service and starts automatically
|
||||
(linger is enabled, so it also starts at boot):
|
||||
|
||||
```sh
|
||||
systemctl --user status tinfoil-proxy
|
||||
```
|
||||
|
||||
To authenticate:
|
||||
|
||||
1. Get an API key from the [Tinfoil dashboard](https://dash.tinfoil.sh).
|
||||
2. Export it in your shell. It is read via `{env:TINFOIL_API_KEY}`, so it is
|
||||
never stored in this repo or the Nix store:
|
||||
|
||||
```sh
|
||||
export TINFOIL_API_KEY=tk_...
|
||||
```
|
||||
|
||||
3. Start OpenCode, run `/models`, and pick a model under **Tinfoil**.
|
||||
|
||||
The available models are listed in `config/opencode.jsonc`; update that file
|
||||
and re-apply to change them.
|
||||
|
||||
## Maintenance
|
||||
|
||||
Update pinned inputs and re-apply:
|
||||
|
||||
```sh
|
||||
nix flake update
|
||||
home-manager switch --flake .#user
|
||||
```
|
||||
|
||||
A `warning: Git tree '...' is dirty` message is expected while you have
|
||||
uncommitted changes; it does not affect the build.
|
||||
|
||||
## License
|
||||
|
||||
Licensed under the [GNU Affero General Public License v3.0](LICENSE)
|
||||
(AGPL-3.0-only).
|
||||
|
||||
Reference in New Issue
Block a user