Files
2026-10-09 00:07:16 +01:00

163 lines
5.1 KiB
Markdown

# nix-clanker-vm
Nix flake + [Home Manager](https://github.com/nix-community/home-manager)
configuration for this host: a Debian VM running **standalone Nix**
(non-NixOS).
## Overview
- Declarative, reproducible user environment managed by Home Manager.
- A self-contained `tinfoil-proxy` package flake (Go).
- System-wide Nix settings applied separately via `install.sh`.
## Prerequisites
- x86_64 Linux.
- Nix with `nix-command` and `flakes` enabled (see `config/nix.conf`).
- `home-manager` available on `PATH`.
- `sudo` access for the system-wide `/etc/nix/nix.conf` step.
## Quick start
```sh
git clone <your-repo-url> ~/nix
cd ~/nix
sudo ./install.sh # install /etc/nix/nix.conf (backs up)
home-manager switch --flake .#user # apply the Home Manager config
```
## Repository layout
| Path | Purpose |
| ------------------------- | -------------------------------------------------------------- |
| `flake.nix` | Root flake: packages and the Home Manager configuration. |
| `home/default.nix` | Home Manager config for user `user` (packages, programs, the `tinfoil-proxy` user service). |
| `config/` | Source files linked into `~/.config` (nix, starship, opencode incl. the Tinfoil provider). |
| `tinfoil-proxy/` | Self-contained flake packaging `tinfoil-proxy` (Go). |
| `install.sh` | Applies `config/nix.conf` to `/etc/nix/nix.conf` (sudo). |
| `flake.lock` | Pinned input revisions (tracked for reproducibility). |
## Managing packages
Packages are declared in `home.packages` in `home/default.nix`. To add one,
append it to the list and re-apply:
```nix
home.packages = [
pkgs.ripgrep # example: add whatever you need
];
```
```sh
home-manager switch --flake .#user
```
To remove a package, delete its entry and re-run the same command. The
authoritative, always-current list lives in `home/default.nix`.
For one-off, ad-hoc use outside the managed environment:
```sh
nix shell nixpkgs#<package>
```
## Managing configuration
Home Manager drives configuration through three mechanisms in
`home/default.nix`:
- **Files linked from this repo** via `home.file`. Add an entry to link a
file from `config/` into your home directory:
```nix
home.file.".config/foo/foo.conf".source = ../config/foo.conf;
```
- **Program modules** via `programs.<name>` (e.g. `programs.bash`,
`programs.fish`, `programs.tmux`, `programs.starship`). Enable or
customize a module here instead of editing dotfiles by hand.
- **Environment variables** via `home.sessionVariables`.
Apply any change with:
```sh
home-manager switch --flake .#user
```
## Customization
The config is host-specific. Current values and where to change them:
| Setting | File | Current value |
| ---------------- | ------------------- | --------------- |
| Username | `flake.nix` | `"user"` |
| Username | `home/default.nix` | `"user"` |
| Home directory | `home/default.nix` | `"/home/user"` |
| System | `flake.nix` | `"x86_64-linux"`|
| System | `tinfoil-proxy/flake.nix` | `"x86_64-linux"` |
- **Change the username**: update `username` in `flake.nix` and both
`home.username` / `home.homeDirectory` in `home/default.nix`. The Home
Manager flake attribute name is derived from `username`, so the apply
command becomes `home-manager switch --flake .#<newuser>`.
- **Change the system**: update `system` in `flake.nix` and in
`tinfoil-proxy/flake.nix`.
## The `tinfoil-proxy` package
`tinfoil-proxy/` is an independent flake that packages the Go program
`tinfoil-proxy` (a verified local HTTP proxy to a Tinfoil secure enclave).
Version, source hash, and vendor hash live in `tinfoil-proxy/package.nix`.
```sh
nix build ./tinfoil-proxy
```
## Tinfoil models in OpenCode
The managed OpenCode config (`config/opencode.jsonc`) defines a `tinfoil`
provider that points at the local proxy on `http://127.0.0.1:3301/v1`. Every
request is checked against Tinfoil's attestation transparency log before it
reaches a secure enclave.
The proxy is installed as a systemd user service and starts automatically
(linger is enabled, so it also starts at boot):
```sh
systemctl --user status tinfoil-proxy
```
To authenticate:
1. Get an API key from the [Tinfoil dashboard](https://dash.tinfoil.sh).
2. Export it in your shell. It is read via `{env:TINFOIL_API_KEY}`, so it is
never stored in this repo or the Nix store:
```sh
export TINFOIL_API_KEY=tk_...
```
3. Start OpenCode, run `/models`, and pick a model under **Tinfoil**.
The available models are listed in `config/opencode.jsonc`; update that file
and re-apply to change them.
## Maintenance
Update pinned inputs and re-apply:
```sh
nix flake update
home-manager switch --flake .#user
```
A `warning: Git tree '...' is dirty` message is expected while you have
uncommitted changes; it does not affect the build.
## License
Licensed under the [GNU Affero General Public License v3.0](LICENSE)
(AGPL-3.0-only).