diff --git a/README.md b/README.md
index beb5187..1506d98 100644
--- a/README.md
+++ b/README.md
@@ -2,84 +2,55 @@
- # adam0's infrastructure
+ # adam0's infra
- NixOS and Home Manager flake for my system and user environment.
+ The Nix flake that keeps my desktop, laptop, and homelab server reproducible.
[](https://github.com/adam01110/infra)
[](https://nixos.org)
[](https://nixos.wiki/wiki/Flakes)
- [](https://github.com/nix-community/home-manager)
+ [](https://github.com/nix-community/home-manager)
[](https://github.com/danth/stylix)
[](https://github.com/Mic92/sops-nix)
[](https://github.com/nix-community/disko)
- [Overview](#overview) - [Layout](#layout) - [Usage](#usage) - [Secrets](#secrets) - [Customization](#customization) - [Tooling](#tooling)
+ [What This Is](#what-this-is) - [Machines](#machines) - [Layout](#layout)
-This repository contains my NixOS and Home Manager setup. It uses `flake-parts`, `flake-file`, and `import-tree` to expose NixOS modules, Home Manager modules, overlays, packages, Disko layouts, and development tooling from `modules/`.
+This is my personal infrastructure repo. It is mostly here so I can rebuild my own machines without trying to remember every package, service, kernel tweak, browser preference, shell setting, and desktop detail by hand.
-## Overview
+It is not meant to be a starter template. Some parts are reusable, but a lot of it is deliberately shaped around my hardware, my domains, my secrets layout, and the way I like my desktop to feel.
-- Public flake outputs are generated from `modules/` through `inputs.import-tree ./modules`.
-- NixOS modules live under `modules/nix`, `modules/services`, `modules/profiles`, and top-level module files such as `modules/users.nix`.
-- Home Manager modules live under `modules/programs`, `modules/desktop`, and shared profile modules.
-- Desktop modules cover `Hyprland`, `UWSM`, `tuigreet`, `Noctalia Shell`, `Stylix`, XDG portals, MIME defaults, and TUI/GUI integration.
-- Local packages, preview helpers, adapters, and overlays live under `modules/pkgs`. Shared helpers live under `lib/`.
+## What This Is
-## Layout
-
-| Path | Purpose |
-| --- | --- |
-| `assets/` | README images, user avatar, and shared static assets |
-| `lib/` | Small helper libraries for environment, MIME, Hyprland, Stylix, Starship, and Yazi config |
-| `modules/desktop/` | Hyprland, Noctalia, UWSM, greetd, XDG, clipboard, tablet, and desktop integration modules |
-| `modules/development/` | Dev shell and treefmt configuration |
-| `modules/nix/` | Core flake, Nix, Home Manager, SOPS, kernel, firmware, and input wiring |
-| `modules/pkgs/` | Local packages and package overlays |
-| `modules/profiles/` | Shared system and Home Manager profiles, partitioning, locale, theming, and tuning |
-| `modules/programs/` | CLI, TUI, GUI, Git, GPG, SSH, GTK, Java, and Nix-LD modules |
-| `modules/services/` | NixOS service modules for audio, networking, power, storage, containers, and system tuning |
-| `vars.nix` | Shared identity, Git metadata, locale, and regional defaults |
-
-## Usage
-
-From the repository root:
-
-```bash
-# Enter the development shell
-nix develop
-
-# Format and lint the repository
-nix fmt
+- A multi-host NixOS flake for my `desktop`, `laptop`, and `euclid` server.
+- Home Manager configuration for the user-facing parts of my setup.
+- A Hyprland desktop built around UWSM, tuigreet, Noctalia Shell, Stylix, Zen Browser, themed apps, and a lot of small quality-of-life modules.
+- A homelab/server stack for services like Authentik, Traefik, WireGuard, CrowdSec, databases, notifications, and media-related tooling.
+- Local packages, overlays, preview helpers, and small libraries that make the rest of the tree less repetitive.
-# Regenerate flake.nix after changing flake-file inputs
-nix run .#write-flake
-```
+The repo is wired with `flake-parts`, `flake-file`, and `import-tree`, so most of the structure is discovered from `modules/` instead of being manually listed in one giant flake file.
-## Secrets
+## Machines
-- Runtime secrets live in a local `secrets.yml` at the project root (gitignored).
-- Recipient rules live in `.sops.yaml` for one user PGP key and three host Age keys.
-- SOPS Nix is shared between NixOS and Home Manager through `modules/nix/sops.nix`.
-
-Edit flow:
-
-```bash
-sops secrets.yml
-```
-
-## Customization
-
-- Edit shared identity, locale, and Git metadata in `vars.nix`.
-- Add NixOS behavior through `modules/nix`, `modules/services`, and `modules/profiles`.
-- Add user-facing tools through `modules/programs` and `modules/desktop`.
-- Add local packages and overlays under `modules/pkgs`.
+| Host | What it is |
+| --- | --- |
+| `desktop` | Main workstation |
+| `laptop` | Portable system |
+| `euclid` | Homelab server |
-## Tooling
+## Layout
-- `treefmt-nix` wires `alejandra`, `deadnix`, `statix`, `nixf-diagnose`, `keep-sorted`, `shellcheck`, `shfmt`, `stylua`, `rumdl-format`, and `yamllint`.
-- `flake-file` owns the generated root `flake.nix`; update inputs in modules and regenerate with `nix run .#write-flake`.
-- `import-tree` auto-discovers the module tree so most new modules only need to export the relevant flake attributes.
-- The default dev shell currently provides `sops` and `tokei`.
+| Path | Purpose |
+| --- | --- |
+| `assets/` | README images and shared static assets |
+| `lib/` | Small helper libraries for Hyprland, Stylix, MIME, Starship, Yazi, and environment handling |
+| `modules/hosts/` | The actual machine entrypoints |
+| `modules/desktop/` | Hyprland, Noctalia, greetd, UWSM, portals, clipboard, tablet, MangoHud, and desktop glue |
+| `modules/programs/` | CLI, TUI, GUI, browser, Git, GPG, SSH, GTK, Java, and Nix-LD modules |
+| `modules/services/` | Audio, networking, power, storage, containers, homelab services, and system tuning |
+| `modules/profiles/` | Shared base, personal, server, gaming, partitioning, locale, and theming profiles |
+| `modules/pkgs/` | Local packages, adapters, previews, and overlays |
+| `modules/nix/` | Flake inputs, Nix settings, Home Manager, SOPS, kernel, firmware, and boot-related modules |
+| `vars.nix` | Shared identity, Git metadata, locale, and domain defaults |
diff --git a/modules/hosts/euclid/default.nix b/modules/hosts/euclid/default.nix
index d09f18e..3eadbfc 100644
--- a/modules/hosts/euclid/default.nix
+++ b/modules/hosts/euclid/default.nix
@@ -110,6 +110,8 @@
wants = ["podman.socket"];
};
+ # Public Git SSH port for the Tangled knot container.
+ networking.firewall.allowedTCPPorts = [2223];
networking.firewall.allowedUDPPorts = [7359];
# Primary nvme disk for disko partitioning.
diff --git a/modules/profiles/server.nix b/modules/profiles/server.nix
index e7af6a1..6012200 100644
--- a/modules/profiles/server.nix
+++ b/modules/profiles/server.nix
@@ -26,6 +26,8 @@
disko.devices = (self.diskoConfigurations.btrfs config.disko.selectedDisk).disko.devices;
+ boot.kernel.sysctl."vm.overcommit_memory" = 1;
+
powerManagement.cpuFreqGovernor = "performance";
# Shell config exists before TTY/SSH login.
diff --git a/modules/programs/gui/discord/themes/snippets.css b/modules/programs/gui/discord/themes/snippets.css
index 66e3125..5c09594 100644
--- a/modules/programs/gui/discord/themes/snippets.css
+++ b/modules/programs/gui/discord/themes/snippets.css
@@ -202,3 +202,77 @@ time[datetime]:hover::after {
#slate-toolbar::before {
border-top: 8px solid var(--background-base-low);
}
+
+/* Fix vc text being cut off. */
+.callContainer_cb9592::after {
+ display: none !important;
+}
+.wrapper_cb9592::after {
+ content: "vc";
+ display: block;
+ color: var(--label-color);
+ font-weight: var(--label-font-weight);
+ position: absolute;
+ top: -10px;
+ left: 8px;
+ background-color: var(--background-base-low);
+ padding: 0 4px;
+ z-index: 100;
+ font-size: 16px;
+ transition: color var(--border-hover-transition);
+}
+.wrapper_cb9592:hover.wrapper_cb9592::after {
+ color: var(--label-hover-color);
+}
+
+/* Fix background blur. */
+[class="layers__960e4 layers__160d8"] {
+ backdrop-filter: blur(8px) !important;
+}
+
+/* Fix menus background. */
+.menu_c1e9c4::before {
+ width: calc(100% - 2px);
+ height: calc(100% - 2px);
+}
+.submenu_c1e9c4.menu_c1e9c4::before {
+ width: calc(100% - 18px) !important;
+}
+
+/* Report popup hover effect fix. */
+.root__49fc1.small__49fc1.fullscreenOnMobile__49fc1.rootWithShadow__49fc1 {
+ border: var(--border-thickness) solid var(--border-subtle) !important;
+ transition: border-color var(--border-hover-transition) !important;
+
+ &:hover {
+ border-color: var(--border-hover) !important;
+ }
+}
+
+/* Fix panel labels colors */
+.wrapper_cb9592,
+.guilds__5e434,
+.panels__5e434,
+.sidebarList__5e434,
+.subtitleContainer_f75fb0,
+.messagesWrapper__36d07,
+.channelTextArea_f75fb0,
+.content_f75fb0 > .membersWrap_c8ffbb,
+.container_c8ffbb,
+.container__133bf > .container__9293f,
+.peopleColumn__133bf,
+.nowPlayingColumn__133bf,
+.container__01ae2 > .container__9293f,
+.callContainer_cb9592 {
+ &::after {
+ background: hsl(from var(--bg-4) h s l / 1);
+ }
+}
+.divider__908e2 .content__908e2 {
+ background: var(--border-subtle);
+}
+
+/* Fix vc top border thickness. */
+.callContainer_cb9592 {
+ border-top-width: 2px !important;
+}
diff --git a/modules/programs/gui/zen/chrome.nix b/modules/programs/gui/zen/chrome.nix
index 2181a44..e379994 100644
--- a/modules/programs/gui/zen/chrome.nix
+++ b/modules/programs/gui/zen/chrome.nix
@@ -19,6 +19,7 @@
inputs,
lib,
pkgs,
+ vars,
# keep-sorted end
...
}: let
@@ -28,6 +29,8 @@
inherit (pkgs.stdenv.hostPlatform) system;
+ inherit (vars) groundDomain;
+
# Convert the stylix base16 scheme into a format accepted by nix-userstyles.
palette = stylixPalette config;
in {
@@ -94,6 +97,7 @@
"searchix"
"spotify-web"
"stack-overflow"
+ "tangled"
"twitch"
"web.dev"
"wiki.nixos.org"
@@ -105,7 +109,7 @@
{
name = "anonymous-overflow";
- sites = [''domain("anonymous-overflow.zezura.xyz")''];
+ sites = [''domain("anonymous-overflow.${groundDomain}")''];
}
];
diff --git a/modules/programs/gui/zen/extensions.nix b/modules/programs/gui/zen/extensions.nix
index 90090d8..d3480e4 100644
--- a/modules/programs/gui/zen/extensions.nix
+++ b/modules/programs/gui/zen/extensions.nix
@@ -27,6 +27,7 @@
modrinthify
pronoundb
return-youtube-dislikes
+ terms-of-service-didnt-read
translate-web-pages
violentmonkey
wikiwand-wikipedia-modernized
@@ -46,9 +47,12 @@
);
in
(mkExtensionSettings {
+ # keep-sorted start
+ "@crw-extension-firefox" = "consumer-rights-wiki";
+ "helloyanis@ageverif-bypass" = "age-verification-bypass";
"{76ef94a4-e3d0-4c6f-961a-d38a429a332b}" = "ttv-lol-pro";
"{microslop@4o4}" = "microslop";
- "@crw-extension-firefox" = "consumer-rights-wiki";
+ # keep-sorted end
})
// {
"magnolia@12.34" = {
diff --git a/modules/programs/ssh.nix b/modules/programs/ssh.nix
index 66d9fa7..4b2b94b 100644
--- a/modules/programs/ssh.nix
+++ b/modules/programs/ssh.nix
@@ -20,6 +20,13 @@
IdentityFile = "~/.ssh/git";
};
+ knot = {
+ HostName = "knot.${groundDomain}";
+ IdentityFile = "~/.ssh/git";
+ Port = 2223;
+ User = "git";
+ };
+
euclid = {
HostKeyAlias = "euclid.${groundDomain}";
HostName = "127.0.0.1";
diff --git a/modules/services/traefik.nix b/modules/services/traefik.nix
index 661e435..91d7d04 100644
--- a/modules/services/traefik.nix
+++ b/modules/services/traefik.nix
@@ -22,6 +22,7 @@
"traefik/mail" = {};
"traefik/porkbun_api_key" = {};
+
"traefik/porkbun_secret_api_key" = {};
# keep-sorted end
};