nix #
NixOS configurations for personal machines, managed with flakes and Home Manager.
Layout #
├── flake.nix # Flake entry point — defines both NixOS configurations
├── home.nix # Shared Home Manager module (imported by all hosts)
├── hyprland.nix # Shared Hyprland config
├── thick-black-cannon/ # Host: thick-black-cannon
│ ├── configuration.nix # NixOS config
│ └── home.nix # Home Manager config
├── 13-inch-thin-cannon/ # Host: 13-inch-thin-cannon
│ ├── configuration.nix # NixOS config
│ └── home.nix # Home Manager config
└── .tangled/workflows/ # Spindle CI pipelines
Testing #
nix flake check
This evaluates and builds both NixOS configurations. Add --no-build to skip
building (eval-only).
The repository avoids NUR because its community-maintained packages receive a
different level of review and provenance assurance than the pinned nixpkgs
packages used here. This reduces supply-chain and malware risk. Firefox
policies and profile settings remain managed in modules/firefox.nix; the
NUR-only packaged add-ons are not installed by the declarative profile.
Applying #
sudo nixos-rebuild switch --flake .#"<hostname>"
Provision the file_magic account password as an agenix-encrypted yescrypt hash:
just set-file-magic-password
This password is intentionally not accepted over SSH: the installed host uses
key-only SSH authentication. It remains useful for local console login and
sudo/PAM authentication. The target does not change sshd settings.
If password SSH is required, enable it explicitly in the installed host:
services.openssh.settings = {
PasswordAuthentication = true;
KbdInteractiveAuthentication = true;
};
Prefer enabling this only on a trusted network or WireGuard interface. SSH
keys, preferably FIDO2-backed ed25519-sk keys, provide a better remote-login
security boundary than passwords.
Set AGE_RECIPIENT to the target host's SSH public key when provisioning from
another machine. For a fresh install, provision after the target has generated
its host key; encrypting to the build machine's host key will leave the target
unable to decrypt the secret.
13-Inch ISO #
Build and test the self-contained installer from the repository root:
just iso # build result/iso/*.iso
just ovmf # refresh test firmware
just test-iso # live -> install -> installed boot
just up # full build and test lifecycle
The ISO contains the flake and install closure. On real hardware, boot it and
run the disko-install command printed by the installer, then run
persist-config before rebooting. See Applying above for the canonical
password-provisioning command. The production host keeps SSH password login
disabled until explicitly changed for a test or local provisioning step.
CI #
CI is provided by Tangled Spindle.
Pipelines are defined in .tangled/workflows/ and run nix flake check on
every push and pull request to main.