nix and nixos configs
Nix 64%
Shell 20%
Just 6%
HCL 6%
3%
Makefile 1%
Smarty <1%

README.md

nix #

NixOS configurations for personal machines, managed with flakes and Home Manager.

Layout #

├── flake.nix              # Flake entry point — defines both NixOS configurations
├── home.nix               # Shared Home Manager module (imported by all hosts)
├── hyprland.nix           # Shared Hyprland config
├── thick-black-cannon/    # Host: thick-black-cannon
│   ├── configuration.nix  #   NixOS config
│   └── home.nix           #   Home Manager config
├── 13-inch-thin-cannon/   # Host: 13-inch-thin-cannon
│   ├── configuration.nix  #   NixOS config
│   └── home.nix           #   Home Manager config
└── .tangled/workflows/    # Spindle CI pipelines

Testing #

nix flake check

This evaluates and builds both NixOS configurations. Add --no-build to skip building (eval-only).

The repository avoids NUR because its community-maintained packages receive a different level of review and provenance assurance than the pinned nixpkgs packages used here. This reduces supply-chain and malware risk. Firefox policies and profile settings remain managed in modules/firefox.nix; the NUR-only packaged add-ons are not installed by the declarative profile.

Applying #

sudo nixos-rebuild switch --flake .#"<hostname>"

Provision the file_magic account password as an agenix-encrypted yescrypt hash:

just set-file-magic-password

This password is intentionally not accepted over SSH: the installed host uses key-only SSH authentication. It remains useful for local console login and sudo/PAM authentication. The target does not change sshd settings.

If password SSH is required, enable it explicitly in the installed host:

services.openssh.settings = {
  PasswordAuthentication = true;
  KbdInteractiveAuthentication = true;
};

Prefer enabling this only on a trusted network or WireGuard interface. SSH keys, preferably FIDO2-backed ed25519-sk keys, provide a better remote-login security boundary than passwords.

Set AGE_RECIPIENT to the target host's SSH public key when provisioning from another machine. For a fresh install, provision after the target has generated its host key; encrypting to the build machine's host key will leave the target unable to decrypt the secret.

13-Inch ISO #

Build and test the self-contained installer from the repository root:

just iso       # build result/iso/*.iso
just ovmf      # refresh test firmware
just test-iso  # live -> install -> installed boot
just up        # full build and test lifecycle

The ISO contains the flake and install closure. On real hardware, boot it and run the disko-install command printed by the installer, then run persist-config before rebooting. See Applying above for the canonical password-provisioning command. The production host keeps SSH password login disabled until explicitly changed for a test or local provisioning step.

CI #

CI is provided by Tangled Spindle. Pipelines are defined in .tangled/workflows/ and run nix flake check on every push and pull request to main.