# nix-clanker-vm Nix flake + [Home Manager](https://github.com/nix-community/home-manager) configuration for this host: a Debian VM running **standalone Nix** (non-NixOS). ## Overview - Declarative, reproducible user environment managed by Home Manager. - A self-contained `tinfoil-proxy` package flake (Go). - System-wide Nix settings applied separately via `install.sh`. ## Prerequisites - x86_64 Linux. - Nix with `nix-command` and `flakes` enabled (see `config/nix.conf`). - `home-manager` available on `PATH`. - `sudo` access for the system-wide `/etc/nix/nix.conf` step. ## Quick start ```sh git clone ~/nix cd ~/nix sudo ./install.sh # install /etc/nix/nix.conf (backs up) home-manager switch --flake .#user # apply the Home Manager config ``` ## Repository layout | Path | Purpose | | ------------------------- | -------------------------------------------------------------- | | `flake.nix` | Root flake: packages and the Home Manager configuration. | | `home/default.nix` | Home Manager config for user `user` (packages, programs, the `tinfoil-proxy` user service). | | `config/` | Source files linked into `~/.config` (nix, starship, opencode incl. the Tinfoil provider). | | `tinfoil-proxy/` | Self-contained flake packaging `tinfoil-proxy` (Go). | | `install.sh` | Applies `config/nix.conf` to `/etc/nix/nix.conf` (sudo). | | `flake.lock` | Pinned input revisions (tracked for reproducibility). | ## Managing packages Packages are declared in `home.packages` in `home/default.nix`. To add one, append it to the list and re-apply: ```nix home.packages = [ pkgs.ripgrep # example: add whatever you need ]; ``` ```sh home-manager switch --flake .#user ``` To remove a package, delete its entry and re-run the same command. The authoritative, always-current list lives in `home/default.nix`. For one-off, ad-hoc use outside the managed environment: ```sh nix shell nixpkgs# ``` ## Managing configuration Home Manager drives configuration through three mechanisms in `home/default.nix`: - **Files linked from this repo** via `home.file`. Add an entry to link a file from `config/` into your home directory: ```nix home.file.".config/foo/foo.conf".source = ../config/foo.conf; ``` - **Program modules** via `programs.` (e.g. `programs.bash`, `programs.fish`, `programs.tmux`, `programs.starship`). Enable or customize a module here instead of editing dotfiles by hand. - **Environment variables** via `home.sessionVariables`. Apply any change with: ```sh home-manager switch --flake .#user ``` ## Customization The config is host-specific. Current values and where to change them: | Setting | File | Current value | | ---------------- | ------------------- | --------------- | | Username | `flake.nix` | `"user"` | | Username | `home/default.nix` | `"user"` | | Home directory | `home/default.nix` | `"/home/user"` | | System | `flake.nix` | `"x86_64-linux"`| | System | `tinfoil-proxy/flake.nix` | `"x86_64-linux"` | - **Change the username**: update `username` in `flake.nix` and both `home.username` / `home.homeDirectory` in `home/default.nix`. The Home Manager flake attribute name is derived from `username`, so the apply command becomes `home-manager switch --flake .#`. - **Change the system**: update `system` in `flake.nix` and in `tinfoil-proxy/flake.nix`. ## The `tinfoil-proxy` package `tinfoil-proxy/` is an independent flake that packages the Go program `tinfoil-proxy` (a verified local HTTP proxy to a Tinfoil secure enclave). Version, source hash, and vendor hash live in `tinfoil-proxy/package.nix`. ```sh nix build ./tinfoil-proxy ``` ## Tinfoil models in OpenCode The managed OpenCode config (`config/opencode.jsonc`) defines a `tinfoil` provider that points at the local proxy on `http://127.0.0.1:3301/v1`. Every request is checked against Tinfoil's attestation transparency log before it reaches a secure enclave. The proxy is installed as a systemd user service and starts automatically (linger is enabled, so it also starts at boot): ```sh systemctl --user status tinfoil-proxy ``` To authenticate: 1. Get an API key from the [Tinfoil dashboard](https://dash.tinfoil.sh). 2. Export it in your shell. It is read via `{env:TINFOIL_API_KEY}`, so it is never stored in this repo or the Nix store: ```sh export TINFOIL_API_KEY=tk_... ``` 3. Start OpenCode, run `/models`, and pick a model under **Tinfoil**. The available models are listed in `config/opencode.jsonc`; update that file and re-apply to change them. ## Maintenance Update pinned inputs and re-apply: ```sh nix flake update home-manager switch --flake .#user ``` A `warning: Git tree '...' is dirty` message is expected while you have uncommitted changes; it does not affect the build. ## License Licensed under the [GNU Affero General Public License v3.0](LICENSE) (AGPL-3.0-only).