nix #
This is a project with my nix configuration for a MacBook (darwin).
Installation #
Download Nix with Determinate Systems and decline the --determinate option with "no" (you will be prompted):
curl -fsSL https://install.determinate.systems/nix | sh -s -- install
Install homebrew separately with this command:
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
Since git is configured with this repo, I recommend that you just download the ZIP of the repo and unpack locally, save it to ~/.config/nix/ and execute:
sudo nix run nix-darwin --extra-experimental-features nix-command --extra-experimental-features flakes -- switch --flake ~/.config/nix#shai-hulud
After that command, nix-darwin is installed and you can run this command to rebuild your config:
sudo darwin-rebuild switch --flake ~/.config/nix
Afterwards, this alias will be available to rebuild your config:
nix-switch
Manual configs #
After applying the config, make sure to finish the setup manually:
SSH Keys #
Create the SSH keys for GitHub and Tangled:
~/.ssh/github.pub(and its private key)~/.ssh/tangled.pub(and its private key)
GitHub CLI Authentication #
Login to gh, so the git-ucommit script is authenticated:
gh auth login
GitHub bot (Claude Code) #
Claude Code runs every git and gh command as trueberryless-bot, in any
directory, while your own terminal stays trueberryless. Set it up once:
-
Create the bot SSH key and add its public key to the bot account as a Signing key:
ssh-keygen -t ed25519 -C 'trueberryless-bot@users.noreply.github.com' -f ~/.ssh/github-bot -
Create a classic PAT with the
repoandworkflowscopes on the bot account, then:mkdir -p -m 700 ~/.config/github-bot printf '%s
' 'YOUR_BOT_PAT' > ~/.config/github-bot/token chmod 600 ~/.config/github-bot/token
[`modules/claude-code.nix`](/modules/claude-code.nix) installs Claude Code managed
settings (`/Library/Application Support/ClaudeCode/managed-settings.d/50-github-bot.json`)
whose `env` block sets:
- `GIT_CONFIG_*`: bot name, email and signing key, plus a GitHub credential helper
that reads the bot token and rewrites SSH GitHub remotes to HTTPS. This is git's
highest-priority config scope, so it overrides `~/.gitconfig` and repo-local config.
- `GH_CONFIG_DIR=~/.config/github-bot/gh`: a bot-only `gh` config whose `hosts.yml`
is regenerated from the token on every switch (rerun `nix-switch` after rotating it).
It also links [`dotfiles/claude/CLAUDE.md`](/dotfiles/claude/CLAUDE.md) to
`~/.claude/CLAUDE.md` and every file in [`dotfiles/claude/rules`](/dotfiles/claude/rules)
into `~/.claude/rules/`, including the path-scoped code style rules in
`rules/code-style/` that load only when Claude reads matching files. Claude pushes directly to repos where the bot is a
collaborator and otherwise forks as the bot and opens the PR from the fork.
Check it from a Claude Code session with `gh api user --jq .login`.
### macOS Privacy
Navigate to _System Settings > Privacy & Security_ and grant the following:
- _Automation_: `randwall` needs to control `Finder` and `System Events`.
- _Accessibility_: `Raycast` and `ClipBook`
- _Full Disk Access_: `iTerm2` to prevent permission errors when managing dots in `~/.local` or `~/Library`.
## Troubleshooting
### dotfiles
If your home-manager configuration files are not getting applied, the issue could be some messed up permissions of your `.local` folder, check them with:
```bash
ls -ld ~/.local
If those are not owned by you but maybe root instead, change the permissions and run the rebuild again:
sudo chown -R trueberryless:staff ~/.local
alias #
Be careful which user runs commands and which config file these users will use to get available aliases. The nix-switch alias in this repo includes the sudo elevation inherently. You do not need to prepend sudo to it. If you switch to the root user entirely, you will lose access to these aliases as the root user uses a different .zshrc file and does not load your user's ~/.alias file managed by home-manager.
Resources #
I want to express my heartfelt gratitude to everyone who contributes to the Nix ecosystem.
Blog posts and documentation #
- NixOS & Flakes Book - An unofficial book for beginners - Ryan Yin
- Blog: "Managing dotfiles on macOS with Nix" - Davis Haupt