nix #
This is a project with my nix configuration for a MacBook (darwin).
Installation #
Download Nix with Determinate Systems and decline the --determinate option with "no" (you will be prompted):
curl -fsSL https://install.determinate.systems/nix | sh -s -- install
Install homebrew separately with this command:
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
Since git is configured with this repo, I recommend that you just download the ZIP of the repo and unpack locally, save it to ~/.config/nix/ and execute:
sudo nix run nix-darwin --extra-experimental-features nix-command --extra-experimental-features flakes -- switch --flake ~/.config/nix#shai-hulud
After that command, nix-darwin is installed and you can run this command to rebuild your config:
sudo darwin-rebuild switch --flake ~/.config/nix
Afterwards, this alias will be available to rebuild your config:
nix-switch
Manual configs #
After applying the config, make sure to finish the setup manually:
SSH Keys #
Create the SSH keys for GitHub and Tangled:
~/.ssh/github.pub(and its private key)~/.ssh/tangled.pub(and its private key)
GitHub CLI Authentication #
Login to gh, so the git-ucommit script is authenticated:
gh auth login
Delta bot (optional) #
Delta manages its own checkouts under $NIX_CONFIG_PATH/.delta/. To have Delta's
git and gh act as trueberryless-bot:
-
Create the bot SSH key and add its public key to the bot account as a Signing key (GitHub > trueberryless-bot settings > SSH and GPG keys > New SSH key > Key type: Signing key):
ssh-keygen -t ed25519 -C 'trueberryless-bot@users.noreply.github.com' -f ~/.ssh/github-bot cat ~/.ssh/github-bot.pub -
Provision a classic PAT with the
reposcope, owned by the bot (GitHub > trueberryless-bot settings > Developer settings > Tokens (classic) > Generate new token > selectrepo).The
reposcope is required because the bot acts on your repos (as a collaborator), and fine-grained PATs can only access repos owned by the bot's own account. The token is read by.zshrcinside Delta worktrees and set asGH_TOKEN:mkdir -p ~/.config/delta printf '%s\n' 'YOUR_BOT_PAT' > ~/.config/delta/bot-token chmod 600 ~/.config/delta/bot-tokenThe reason the token is read from a file:
ghon macOS resolves the keychain by service name (gh:github.com) and can return the other account's token when two accounts share a host.GH_TOKENoverrides stored credentials, so this guarantees the bot token is used inside Delta checkouts.
macOS Privacy #
Navigate to System Settings > Privacy & Security and grant the following:
- Automation:
randwallneeds to controlFinderandSystem Events. - Accessibility:
RaycastandClipBook - Full Disk Access:
iTerm2to prevent permission errors when managing dots in~/.localor~/Library.
Troubleshooting #
dotfiles #
If your home-manager configuration files are not getting applied, the issue could be some messed up permissions of your .local folder, check them with:
ls -ld ~/.local
If those are not owned by you but maybe root instead, change the permissions and run the rebuild again:
sudo chown -R trueberryless:staff ~/.local
alias #
Be careful which user runs commands and which config file these users will use to get available aliases. The nix-switch alias in this repo includes the sudo elevation inherently. You do not need to prepend sudo to it. If you switch to the root user entirely, you will lose access to these aliases as the root user uses a different .zshrc file and does not load your user's ~/.alias file managed by home-manager.
Resources #
I want to express my heartfelt gratitude to everyone who contributes to the Nix ecosystem.
Blog posts and documentation #
- NixOS & Flakes Book - An unofficial book for beginners - Ryan Yin
- Blog: "Managing dotfiles on macOS with Nix" - Davis Haupt