diff --git a/flake.nix b/flake.nix index d1931f8..07d0501 100644 --- a/flake.nix +++ b/flake.nix @@ -301,6 +301,15 @@ ./machines/atalanta ]; }; + beef = nix-darwin.lib.darwinSystem { + system = "aarch64-darwin"; + specialArgs = { inherit inputs outputs; }; + modules = [ + home-manager.darwinModules.home-manager + agenix.darwinModules.default + ./machines/beef + ]; + }; }; # Service manifest for infra dashboard diff --git a/machines/atalanta/default.nix b/machines/atalanta/default.nix index caca1c0..2bab8f6 100644 --- a/machines/atalanta/default.nix +++ b/machines/atalanta/default.nix @@ -7,56 +7,9 @@ imports = [ ./home-manager.nix ../../modules/shared/machine.nix + ../../modules/darwin/defaults.nix ]; - # Set host platform for Apple Silicon - nixpkgs = { - hostPlatform = "aarch64-darwin"; - config = { - allowUnfree = true; - }; - overlays = [ - inputs.nur.overlays.default - (final: prev: { - unstable = import inputs.nixpkgs-unstable { - system = final.stdenv.hostPlatform.system; - config.allowUnfree = true; - }; - - zmx-binary = prev.callPackage ../../packages/zmx.nix { }; - - # direnv fish tests are killed (SIGKILL) in the Nix sandbox on Darwin - # since the libarchive 3.8.4->3.8.6 bump; skip until upstream fixes it. - # https://github.com/NixOS/nixpkgs/issues/507531 - direnv = prev.direnv.overrideAttrs (_: { - doCheck = false; - }); - }) - ]; - }; - - # Enable nix-darwin - nix.settings.experimental-features = [ - "nix-command" - "flakes" - ]; - - # switch to lix - nix.package = pkgs.lixPackageSets.latest.lix; - - # Auto GC old generations and optimise store - nix.gc = { - automatic = true; - interval = { - Weekday = 0; - Hour = 2; - Minute = 0; - }; - options = "--delete-older-than 14d"; - }; - nix.optimise.automatic = true; - - # Set hostname networking.hostName = "atalanta"; atelier.machine = { @@ -65,16 +18,6 @@ tailscaleHost = "atalanta"; }; - # Define user - users.users.kierank = { - name = "kierank"; - home = "/Users/kierank"; - }; - - system.primaryUser = "kierank"; - - ids.gids.nixbld = 350; - # Homebrew casks managed declaratively homebrew = { enable = true; @@ -116,16 +59,6 @@ inputs.soapdump.packages.${pkgs.stdenv.hostPlatform.system}.default ]; - programs.direnv.enable = true; - - # Disable system /etc/zshrc to avoid double compinit. - # Home-manager handles history, direnv, completion, and keybindings. - environment.etc."zshrc".enable = false; - - # import the secret - age.identityPaths = [ - "/Users/kierank/.ssh/id_rsa" - ]; age.secrets = { wakatime = { file = ../../secrets/wakatime.age; @@ -136,7 +69,6 @@ file = ../../secrets/bluesky.age; owner = "kierank"; }; - "bore/auth-token" = { file = ../../secrets/bore/auth-token.age; owner = "kierank"; @@ -147,27 +79,6 @@ }; }; - environment.variables = { - EDITOR = "nvim"; - SYSTEMD_EDITOR = "nvim"; - VISUAL = "nvim"; - }; - - # nothing but finder in the doc - system.defaults.dock = { - persistent-apps = [ ]; - - tilesize = 47; - mru-spaces = false; - show-recents = false; - autohide = true; - showhidden = true; - autohide-delay = 0.0; - autohide-time-modifier = 0.0; - magnification = true; - largesize = 52; - }; - # Regenerate sudoers entry with correct hash after every rebuild system.activationScripts.yabai-sudoers.text = '' YABAI="${pkgs.yabai}/bin/yabai" @@ -182,178 +93,5 @@ harddisk = 10; }; - # allow using apple watch or touch id for sudo - security.pam.services.sudo_local.touchIdAuth = true; - security.pam.services.sudo_local.watchIdAuth = true; - - system.defaults = { - finder.FXPreferredViewStyle = "Nlsv"; - finder.AppleShowAllExtensions = true; - finder.ShowPathbar = true; - finder.ShowStatusBar = false; - finder.FXDefaultSearchScope = "SCcf"; - finder._FXShowPosixPathInTitle = true; - finder.FXEnableExtensionChangeWarning = false; - trackpad.Clicking = true; - trackpad.TrackpadRightClick = true; - # expand the save dialogs - NSGlobalDomain.NSNavPanelExpandedStateForSaveMode = true; - NSGlobalDomain.NSNavPanelExpandedStateForSaveMode2 = true; - LaunchServices.LSQuarantine = false; # disables "Are you sure?" for new apps - loginwindow.GuestEnabled = false; - - NSGlobalDomain."com.apple.trackpad.scaling" = 0.875; - NSGlobalDomain.AppleInterfaceStyle = "Dark"; - NSGlobalDomain.NSAutomaticCapitalizationEnabled = false; - NSGlobalDomain.NSAutomaticDashSubstitutionEnabled = false; - NSGlobalDomain.NSAutomaticPeriodSubstitutionEnabled = false; - NSGlobalDomain.NSAutomaticQuoteSubstitutionEnabled = false; - NSGlobalDomain.NSAutomaticSpellingCorrectionEnabled = false; - NSGlobalDomain.ApplePressAndHoldEnabled = false; - - CustomSystemPreferences = { - "com.apple.DiskArbitration.diskarbitrationd" = { - DADisableEjectNotification = true; - }; - }; - - CustomUserPreferences = { - "com.apple.ImageCapture" = { - disableHotPlug = true; - }; - "com.apple.menuextra.clock" = { - FlashDateSeparators = false; - ShowDate = 0; - ShowDayOfWeek = true; - }; - "NSGlobalDomain" = { - # old imac purple tint - AppleIconAppearanceCustomTintColor = "0.358236 0.479976 0.941252 0.780139"; - AppleIconAppearanceTintColor = "Other"; - NSColorSimulateHardwareAccent = 1; - NSColorSimulatedHardwareEnclosureNumber = 7; - NSStatusItemSpacing = 12; - NSStatusItemSelectionPadding = 12; - }; - "com.apple.screencapture" = { - disable-shadow = true; - location = "~/Downloads"; - type = "png"; - }; - "com.apple.finder" = { - SidebarShowingiCloudDesktop = false; - ShowRecentTags = false; - ShowExternalHardDrivesOnDesktop = true; - ShowHardDrivesOnDesktop = false; - ShowRemovableMediaOnDesktop = true; - NewWindowTarget = "PfHm"; - }; - "com.apple.driver.AppleBluetoothMultitouch.mouse" = { - MouseButtonMode = "TwoButton"; - }; - "com.apple.WindowManager" = { - EnableTiledWindowMargins = false; - }; - "com.apple.desktopservices" = { - # Avoid creating .DS_Store files on network or USB volumes - DSDontWriteNetworkStores = true; - DSDontWriteUSBStores = true; - }; - "com.apple.AdLib" = { - allowApplePersonalizedAdvertising = false; - }; - "com.apple.SoftwareUpdate" = { - AutomaticCheckEnabled = true; - # Check for software updates daily, not just once per week - ScheduleFrequency = 1; - # Download newly available updates in background - AutomaticDownload = 1; - # Install System data files & security updates - CriticalUpdateInstall = 1; - }; - # keybindings - # Script to export symbolic hotkey configs from MacOS - # https://gist.github.com/sawadashota/8e7ce32234e0f07a03e955f22ec4c0f9 - # Screenshot selected area to file with Cmd+Option+Shift+4 - "com.apple.symbolichotkeys" = { - AppleSymbolicHotKeys = { - # Screenshot selected area with Option+Cmd+Shift+4 - "30" = { - enabled = true; - value = { - parameters = [ - 52 - 21 - 1703936 - ]; - type = "standard"; - }; - }; - # Screenshot selected area to clipboard with Cmd+Shift+4 - "31" = { - enabled = true; - value = { - parameters = [ - 52 - 21 - 1179648 - ]; - type = "standard"; - }; - }; - # Fullscreen screenshot Option+Cmd+Shift+3 - "28" = { - enabled = true; - value = { - parameters = [ - 51 - 20 - 1703936 - ]; - type = "standard"; - }; - }; - # Fullscreen screenshot to clipboard Cmd+Shift+3 - "29" = { - enabled = true; - value = { - parameters = [ - 51 - 20 - 1179648 - ]; - type = "standard"; - }; - }; - # Spotlight - Cmd+Space (disabled for Raycast) - "64" = { - enabled = false; - value = { - parameters = [ - 32 - 49 - 1048576 - ]; - type = "standard"; - }; - }; - # Finder search - Option+Cmd+Space (disabled for Raycast) - "65" = { - enabled = false; - value = { - parameters = [ - 32 - 49 - 1572864 - ]; - type = "standard"; - }; - }; - }; - }; - }; - }; - - # Used for backwards compatibility, please read the changelog before changing system.stateVersion = 4; } diff --git a/machines/beef/default.nix b/machines/beef/default.nix new file mode 100644 index 0000000..250e2a5 --- /dev/null +++ b/machines/beef/default.nix @@ -0,0 +1,67 @@ +{ + inputs, + pkgs, + ... +}: +{ + imports = [ + ./home-manager.nix + ../../modules/shared/machine.nix + ../../modules/darwin/defaults.nix + ]; + + networking.hostName = "beef"; + + atelier.machine = { + enable = true; + type = "client"; + tailscaleHost = "beef"; + }; + + environment.systemPackages = [ + pkgs.nixd + pkgs.nil + pkgs.nixfmt + inputs.agenix.packages.aarch64-darwin.default + pkgs.nodejs_22 + pkgs.unstable.bun + pkgs.python3 + pkgs.go + pkgs.gopls + pkgs.gotools + pkgs.go-tools + pkgs.cargo + pkgs.jdk + pkgs.ruby + pkgs.cmake + pkgs.unstable.biome + pkgs.unstable.zola + pkgs.mill + pkgs.clang-tools + pkgs.ninja + pkgs.calc + pkgs.nh + ]; + + age.secrets = { + wakatime = { + file = ../../secrets/wakatime.age; + path = "/Users/kierank/.wakatime.cfg"; + owner = "kierank"; + }; + bluesky = { + file = ../../secrets/bluesky.age; + owner = "kierank"; + }; + "bore/auth-token" = { + file = ../../secrets/bore/auth-token.age; + owner = "kierank"; + }; + pbnj = { + file = ../../secrets/pbnj.age; + owner = "kierank"; + }; + }; + + system.stateVersion = 6; +} diff --git a/machines/beef/home-manager.nix b/machines/beef/home-manager.nix new file mode 100644 index 0000000..a4aab57 --- /dev/null +++ b/machines/beef/home-manager.nix @@ -0,0 +1,20 @@ +{ + inputs, + outputs, + ... +}: +{ + imports = [ + inputs.home-manager.darwinModules.home-manager + ]; + + home-manager = { + useGlobalPkgs = true; + extraSpecialArgs = { + inherit inputs outputs; + }; + users = { + kierank = import ./home; + }; + }; +} diff --git a/machines/beef/home/default.nix b/machines/beef/home/default.nix new file mode 100644 index 0000000..c183b59 --- /dev/null +++ b/machines/beef/home/default.nix @@ -0,0 +1,87 @@ +{ + inputs, + pkgs, + osConfig, + ... +}: +{ + imports = [ + (inputs.import-tree ../../../modules/home) + ]; + + home = { + username = "kierank"; + homeDirectory = "/Users/kierank"; + packages = [ + inputs.nixvim.packages.${pkgs.stdenv.hostPlatform.system}.default + pkgs.libiconv + ]; + sessionVariables = { + LIBRARY_PATH = "${pkgs.libiconv}/lib"; + }; + }; + + atelier = { + shell.enable = true; + terminal.ghostty = { + enable = true; + windowDecoration = true; + }; + apps.helix.enable = true; + bore = { + enable = true; + authTokenFile = osConfig.age.secrets."bore/auth-token".path; + }; + pbnj = { + enable = true; + host = "https://pbnj.dunkirk.sh"; + authKeyFile = osConfig.age.secrets.pbnj.path; + }; + ssh = { + enable = true; + zmx = { + enable = true; + hosts = [ + "t.*" + "p.*" + "e.*" + ]; + }; + hosts = { + "t.*" = { + hostname = "150.136.15.177"; + }; + "e.*" = { + hostname = "ember"; + }; + "p.*" = { + hostname = "100.105.247.54"; + }; + terebithia = { + hostname = "150.136.15.177"; + zmx = true; + }; + terebithia-raw = { + hostname = "terebithia"; + }; + prattle = { + hostname = "100.105.247.54"; + zmx = true; + }; + herald = { + hostname = "herald.dunkirk.sh"; + port = 2223; + }; + }; + extraConfig = '' + IdentityFile ~/.ssh/id_rsa + ''; + }; + }; + + programs.zsh.initContent = '' + export PATH="$HOME/.cargo/bin:$PATH" + ''; + + home.stateVersion = "25.05"; +} diff --git a/modules/darwin/defaults.nix b/modules/darwin/defaults.nix new file mode 100644 index 0000000..6469f63 --- /dev/null +++ b/modules/darwin/defaults.nix @@ -0,0 +1,228 @@ +{ + inputs, + pkgs, + ... +}: +{ + # Common nix-darwin settings for all macOS machines + + nixpkgs = { + hostPlatform = "aarch64-darwin"; + config.allowUnfree = true; + overlays = [ + inputs.nur.overlays.default + (final: prev: { + unstable = import inputs.nixpkgs-unstable { + system = final.stdenv.hostPlatform.system; + config.allowUnfree = true; + }; + + zmx-binary = prev.callPackage ../../packages/zmx.nix { }; + + # direnv fish tests are killed (SIGKILL) in the Nix sandbox on Darwin + # since the libarchive 3.8.4->3.8.6 bump; skip until upstream fixes it. + # https://github.com/NixOS/nixpkgs/issues/507531 + direnv = prev.direnv.overrideAttrs (_: { + doCheck = false; + }); + }) + ]; + }; + + nix.settings.experimental-features = [ + "nix-command" + "flakes" + ]; + + nix.package = pkgs.lixPackageSets.latest.lix; + + nix.gc = { + automatic = true; + interval = { + Weekday = 0; + Hour = 2; + Minute = 0; + }; + options = "--delete-older-than 14d"; + }; + nix.optimise.automatic = true; + + users.users.kierank = { + name = "kierank"; + home = "/Users/kierank"; + }; + + system.primaryUser = "kierank"; + + ids.gids.nixbld = 350; + + programs.direnv.enable = true; + + # Disable system /etc/zshrc to avoid double compinit. + # Home-manager handles history, direnv, completion, and keybindings. + environment.etc."zshrc".enable = false; + + age.identityPaths = [ + "/Users/kierank/.ssh/id_rsa" + ]; + + environment.variables = { + EDITOR = "nvim"; + SYSTEMD_EDITOR = "nvim"; + VISUAL = "nvim"; + }; + + # Allow using Apple Watch or Touch ID for sudo + security.pam.services.sudo_local.touchIdAuth = true; + security.pam.services.sudo_local.watchIdAuth = true; + + # Common macOS defaults + system.defaults = { + dock = { + persistent-apps = [ ]; + tilesize = 47; + mru-spaces = false; + show-recents = false; + autohide = true; + showhidden = true; + autohide-delay = 0.0; + autohide-time-modifier = 0.0; + magnification = true; + largesize = 52; + }; + + finder = { + FXPreferredViewStyle = "Nlsv"; + AppleShowAllExtensions = true; + ShowPathbar = true; + ShowStatusBar = false; + FXDefaultSearchScope = "SCcf"; + _FXShowPosixPathInTitle = true; + FXEnableExtensionChangeWarning = false; + }; + + trackpad = { + Clicking = true; + TrackpadRightClick = true; + }; + + NSGlobalDomain = { + NSNavPanelExpandedStateForSaveMode = true; + NSNavPanelExpandedStateForSaveMode2 = true; + "com.apple.trackpad.scaling" = 0.875; + AppleInterfaceStyle = "Dark"; + NSAutomaticCapitalizationEnabled = false; + NSAutomaticDashSubstitutionEnabled = false; + NSAutomaticPeriodSubstitutionEnabled = false; + NSAutomaticQuoteSubstitutionEnabled = false; + NSAutomaticSpellingCorrectionEnabled = false; + ApplePressAndHoldEnabled = false; + }; + + LaunchServices.LSQuarantine = false; + loginwindow.GuestEnabled = false; + + CustomSystemPreferences = { + "com.apple.DiskArbitration.diskarbitrationd" = { + DADisableEjectNotification = true; + }; + }; + + CustomUserPreferences = { + "com.apple.ImageCapture" = { + disableHotPlug = true; + }; + "com.apple.menuextra.clock" = { + FlashDateSeparators = false; + ShowDate = 0; + ShowDayOfWeek = true; + }; + "NSGlobalDomain" = { + AppleIconAppearanceCustomTintColor = "0.358236 0.479976 0.941252 0.780139"; + AppleIconAppearanceTintColor = "Other"; + NSColorSimulateHardwareAccent = 1; + NSColorSimulatedHardwareEnclosureNumber = 7; + NSStatusItemSpacing = 12; + NSStatusItemSelectionPadding = 12; + }; + "com.apple.screencapture" = { + disable-shadow = true; + location = "~/Downloads"; + type = "png"; + }; + "com.apple.finder" = { + SidebarShowingiCloudDesktop = false; + ShowRecentTags = false; + ShowExternalHardDrivesOnDesktop = true; + ShowHardDrivesOnDesktop = false; + ShowRemovableMediaOnDesktop = true; + NewWindowTarget = "PfHm"; + }; + "com.apple.driver.AppleBluetoothMultitouch.mouse" = { + MouseButtonMode = "TwoButton"; + }; + "com.apple.WindowManager" = { + EnableTiledWindowMargins = false; + }; + "com.apple.desktopservices" = { + DSDontWriteNetworkStores = true; + DSDontWriteUSBStores = true; + }; + "com.apple.AdLib" = { + allowApplePersonalizedAdvertising = false; + }; + "com.apple.SoftwareUpdate" = { + AutomaticCheckEnabled = true; + ScheduleFrequency = 1; + AutomaticDownload = 1; + CriticalUpdateInstall = 1; + }; + "com.apple.symbolichotkeys" = { + AppleSymbolicHotKeys = { + "30" = { + enabled = true; + value = { + parameters = [ 52 21 1703936 ]; + type = "standard"; + }; + }; + "31" = { + enabled = true; + value = { + parameters = [ 52 21 1179648 ]; + type = "standard"; + }; + }; + "28" = { + enabled = true; + value = { + parameters = [ 51 20 1703936 ]; + type = "standard"; + }; + }; + "29" = { + enabled = true; + value = { + parameters = [ 51 20 1179648 ]; + type = "standard"; + }; + }; + "64" = { + enabled = false; + value = { + parameters = [ 32 49 1048576 ]; + type = "standard"; + }; + }; + "65" = { + enabled = false; + value = { + parameters = [ 32 49 1572864 ]; + type = "standard"; + }; + }; + }; + }; + }; + }; +}