[READ-ONLY] Mirror of https://github.com/trueberryless/nix. My nix config github.com/clemensschlipfinger/general-grievous-nix
README.md

nix #

Built with Nix Netlify Status

This is a project with my nix configuration for a MacBook (darwin).

Installation #

Download Nix with Determinate Systems and decline the --determinate option with "no" (you will be prompted):

curl -fsSL https://install.determinate.systems/nix | sh -s -- install

Install homebrew separately with this command:

/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"

Since git is configured with this repo, I recommend that you just download the ZIP of the repo and unpack locally, save it to ~/.config/nix/ and execute:

sudo nix run nix-darwin --extra-experimental-features nix-command --extra-experimental-features flakes -- switch --flake ~/.config/nix#shai-hulud

After that command, nix-darwin is installed and you can run this command to rebuild your config:

sudo darwin-rebuild switch --flake ~/.config/nix

Afterwards, this alias will be available to rebuild your config:

nix-switch

Manual configs #

After applying the config, make sure to finish the setup manually:

SSH Keys #

Create the SSH keys for GitHub and Tangled:

  • ~/.ssh/github.pub (and its private key)
  • ~/.ssh/tangled.pub (and its private key)

GitHub CLI Authentication #

Login to gh, so the git-ucommit script is authenticated:

gh auth login

Delta bot (optional) #

Delta manages its own checkouts under $NIX_CONFIG_PATH/.delta/. To have Delta's git and gh act as trueberryless-bot:

  1. Create the bot SSH key and add its public key to the bot account as a Signing key (GitHub > trueberryless-bot settings > SSH and GPG keys > New SSH key > Key type: Signing key):

    ssh-keygen -t ed25519 -C 'trueberryless-bot@users.noreply.github.com' -f ~/.ssh/github-bot
    cat ~/.ssh/github-bot.pub
    
  2. Provision a classic PAT with the repo scope, owned by the bot (GitHub > trueberryless-bot settings > Developer settings > Tokens (classic) > Generate new token > select repo).

    The repo scope is required because the bot acts on your repos (as a collaborator), and fine-grained PATs can only access repos owned by the bot's own account. The token is read by .zshrc inside Delta worktrees and set as GH_TOKEN:

    mkdir -p ~/.config/delta
    printf '%s\n' 'YOUR_BOT_PAT' > ~/.config/delta/bot-token
    chmod 600 ~/.config/delta/bot-token
    

    The reason the token is read from a file: gh on macOS resolves the keychain by service name (gh:github.com) and can return the other account's token when two accounts share a host. GH_TOKEN overrides stored credentials, so this guarantees the bot token is used inside Delta checkouts.

macOS Privacy #

Navigate to System Settings > Privacy & Security and grant the following:

  • Automation: randwall needs to control Finder and System Events.
  • Accessibility: Raycast and ClipBook
  • Full Disk Access: iTerm2 to prevent permission errors when managing dots in ~/.local or ~/Library.

Troubleshooting #

dotfiles #

If your home-manager configuration files are not getting applied, the issue could be some messed up permissions of your .local folder, check them with:

ls -ld ~/.local

If those are not owned by you but maybe root instead, change the permissions and run the rebuild again:

sudo chown -R trueberryless:staff ~/.local

alias #

Be careful which user runs commands and which config file these users will use to get available aliases. The nix-switch alias in this repo includes the sudo elevation inherently. You do not need to prepend sudo to it. If you switch to the root user entirely, you will lose access to these aliases as the root user uses a different .zshrc file and does not load your user's ~/.alias file managed by home-manager.

Resources #

I want to express my heartfelt gratitude to everyone who contributes to the Nix ecosystem.

Blog posts and documentation #

Repositories #