163 lines
5.1 KiB
Markdown
163 lines
5.1 KiB
Markdown
# nix-clanker-vm
|
|
|
|
Nix flake + [Home Manager](https://github.com/nix-community/home-manager)
|
|
configuration for this host: a Debian VM running **standalone Nix**
|
|
(non-NixOS).
|
|
|
|
## Overview
|
|
|
|
- Declarative, reproducible user environment managed by Home Manager.
|
|
- A self-contained `tinfoil-proxy` package flake (Go).
|
|
- System-wide Nix settings applied separately via `install.sh`.
|
|
|
|
## Prerequisites
|
|
|
|
- x86_64 Linux.
|
|
- Nix with `nix-command` and `flakes` enabled (see `config/nix.conf`).
|
|
- `home-manager` available on `PATH`.
|
|
- `sudo` access for the system-wide `/etc/nix/nix.conf` step.
|
|
|
|
## Quick start
|
|
|
|
```sh
|
|
git clone <your-repo-url> ~/nix
|
|
cd ~/nix
|
|
|
|
sudo ./install.sh # install /etc/nix/nix.conf (backs up)
|
|
home-manager switch --flake .#user # apply the Home Manager config
|
|
```
|
|
|
|
## Repository layout
|
|
|
|
| Path | Purpose |
|
|
| ------------------------- | -------------------------------------------------------------- |
|
|
| `flake.nix` | Root flake: packages and the Home Manager configuration. |
|
|
| `home/default.nix` | Home Manager config for user `user` (packages, programs, the `tinfoil-proxy` user service). |
|
|
| `config/` | Source files linked into `~/.config` (nix, starship, opencode incl. the Tinfoil provider). |
|
|
| `tinfoil-proxy/` | Self-contained flake packaging `tinfoil-proxy` (Go). |
|
|
| `install.sh` | Applies `config/nix.conf` to `/etc/nix/nix.conf` (sudo). |
|
|
| `flake.lock` | Pinned input revisions (tracked for reproducibility). |
|
|
|
|
## Managing packages
|
|
|
|
Packages are declared in `home.packages` in `home/default.nix`. To add one,
|
|
append it to the list and re-apply:
|
|
|
|
```nix
|
|
home.packages = [
|
|
pkgs.ripgrep # example: add whatever you need
|
|
];
|
|
```
|
|
|
|
```sh
|
|
home-manager switch --flake .#user
|
|
```
|
|
|
|
To remove a package, delete its entry and re-run the same command. The
|
|
authoritative, always-current list lives in `home/default.nix`.
|
|
|
|
For one-off, ad-hoc use outside the managed environment:
|
|
|
|
```sh
|
|
nix shell nixpkgs#<package>
|
|
```
|
|
|
|
## Managing configuration
|
|
|
|
Home Manager drives configuration through three mechanisms in
|
|
`home/default.nix`:
|
|
|
|
- **Files linked from this repo** via `home.file`. Add an entry to link a
|
|
file from `config/` into your home directory:
|
|
|
|
```nix
|
|
home.file.".config/foo/foo.conf".source = ../config/foo.conf;
|
|
```
|
|
|
|
- **Program modules** via `programs.<name>` (e.g. `programs.bash`,
|
|
`programs.fish`, `programs.tmux`, `programs.starship`). Enable or
|
|
customize a module here instead of editing dotfiles by hand.
|
|
|
|
- **Environment variables** via `home.sessionVariables`.
|
|
|
|
Apply any change with:
|
|
|
|
```sh
|
|
home-manager switch --flake .#user
|
|
```
|
|
|
|
## Customization
|
|
|
|
The config is host-specific. Current values and where to change them:
|
|
|
|
| Setting | File | Current value |
|
|
| ---------------- | ------------------- | --------------- |
|
|
| Username | `flake.nix` | `"user"` |
|
|
| Username | `home/default.nix` | `"user"` |
|
|
| Home directory | `home/default.nix` | `"/home/user"` |
|
|
| System | `flake.nix` | `"x86_64-linux"`|
|
|
| System | `tinfoil-proxy/flake.nix` | `"x86_64-linux"` |
|
|
|
|
- **Change the username**: update `username` in `flake.nix` and both
|
|
`home.username` / `home.homeDirectory` in `home/default.nix`. The Home
|
|
Manager flake attribute name is derived from `username`, so the apply
|
|
command becomes `home-manager switch --flake .#<newuser>`.
|
|
- **Change the system**: update `system` in `flake.nix` and in
|
|
`tinfoil-proxy/flake.nix`.
|
|
|
|
## The `tinfoil-proxy` package
|
|
|
|
`tinfoil-proxy/` is an independent flake that packages the Go program
|
|
`tinfoil-proxy` (a verified local HTTP proxy to a Tinfoil secure enclave).
|
|
Version, source hash, and vendor hash live in `tinfoil-proxy/package.nix`.
|
|
|
|
```sh
|
|
nix build ./tinfoil-proxy
|
|
```
|
|
|
|
## Tinfoil models in OpenCode
|
|
|
|
The managed OpenCode config (`config/opencode.jsonc`) defines a `tinfoil`
|
|
provider that points at the local proxy on `http://127.0.0.1:3301/v1`. Every
|
|
request is checked against Tinfoil's attestation transparency log before it
|
|
reaches a secure enclave.
|
|
|
|
The proxy is installed as a systemd user service and starts automatically
|
|
(linger is enabled, so it also starts at boot):
|
|
|
|
```sh
|
|
systemctl --user status tinfoil-proxy
|
|
```
|
|
|
|
To authenticate:
|
|
|
|
1. Get an API key from the [Tinfoil dashboard](https://dash.tinfoil.sh).
|
|
2. Export it in your shell. It is read via `{env:TINFOIL_API_KEY}`, so it is
|
|
never stored in this repo or the Nix store:
|
|
|
|
```sh
|
|
export TINFOIL_API_KEY=tk_...
|
|
```
|
|
|
|
3. Start OpenCode, run `/models`, and pick a model under **Tinfoil**.
|
|
|
|
The available models are listed in `config/opencode.jsonc`; update that file
|
|
and re-apply to change them.
|
|
|
|
## Maintenance
|
|
|
|
Update pinned inputs and re-apply:
|
|
|
|
```sh
|
|
nix flake update
|
|
home-manager switch --flake .#user
|
|
```
|
|
|
|
A `warning: Git tree '...' is dirty` message is expected while you have
|
|
uncommitted changes; it does not affect the build.
|
|
|
|
## License
|
|
|
|
Licensed under the [GNU Affero General Public License v3.0](LICENSE)
|
|
(AGPL-3.0-only).
|