likely broken
README.md

molly's nixos config #

NixOS configurations for two x86_64-linux machines, managed from a single flake.

The canonical repository lives on Tangled: https://tangled.org/molly.computer/nixos.

hosts #

host role notes
chi Framework 12 laptop Desktop; Niri compositor, Noctalia shell, Stylix theming from the wallpaper
halo Strix Halo server Headless; Tangled knot/spindle, Podman containers, sops-managed secrets

layout #

flake.nix            — flake inputs and both nixosConfigurations
modules/common.nix   — settings shared by chi and halo (locale, firewall, nix)
hosts/chi/           — Framework 12 config, desktop modules, generated hardware config
hosts/halo/          — server config and its separate Home Manager config
home/                — Home Manager modules for chi (shell, apps, niri, opencode, …)
pkgs/                — locally packaged software (jagex-launcher)
secrets/             — SOPS-encrypted credentials only; never store plaintext here
docs/secrets.md      — sops-nix key locations, editing, and rotation notes
wallpapers/          — wallpapers; the default also seeds the Stylix theme
notes.md             — setup details, opencode integration, and misc notes

hosts/*/hardware-configuration.nix is generated by nixos-generate-config and is intentionally excluded from the formatter. Keep it byte-identical unless the hardware itself changes.

deploying #

# chi (local)
sudo nixos-rebuild switch --flake .#chi

# halo (from chi; the SSH host alias comes from Home Manager)
sudo nixos-rebuild switch --flake .#halo \
  --target-host halo \
  --use-remote-sudo

Preview a change with dry-activate or build instead of switch. Halo must be deployed at least once after a secret changes so /run/secrets/halo/* is rematerialized before consumers restart.

checks #

nix fmt
nix flake check
nix eval --raw .#nixosConfigurations.chi.config.system.build.toplevel.drvPath
nix eval --raw .#nixosConfigurations.halo.config.system.build.toplevel.drvPath

The formatter is treefmt with Alejandra, Statix, and deadnix. nix flake check only runs the formatting check, so evaluate both hosts separately after touching flake.nix, flake.lock, modules/common.nix, or shared inputs.

jagex-launcher #

The RuneScape launcher is not part of the default user profile. Run it from its own shell instead:

nix-shell pkgs/jagex-launcher
jagex-launcher

The package wraps a bundled AppImage, so it cannot self-update from the read-only Nix store; bump pkgs/jagex-launcher/package.nix when a new build is available.

secrets #

Secrets use sops-nix with age:

  • chi key: ~/.config/sops/age/keys.txt
  • halo key: /var/lib/sops-nix/keys.txt

Only the age recipients in .sops.yaml and encrypted files under secrets/ belong in Git; keep both private keys backed up outside the repository. Edit credentials with sops secrets/halo.yaml. See docs/secrets.md for the full workflow.

opencode #

OpenCode on chi is restricted to the route.daze.lol gateway (enabled_providers = ["route"]). Its provider block, subagent models, and the model list live in home/opencode.nix. A small plugin (home/opencode/plugins/route-models.js) queries the gateway's /v1/models endpoint at startup and adds any newly published models automatically.

API keys are never written to the store; the opencode wrapper reads them from the login keyring at launch with secret-tool. See notes.md for more on the agent tooling.

containers #

Halo's Podman/Compose application definitions currently live outside this repository under /home/molly/. PDS already consumes its sops-managed environment; the remaining services are planned to move here as declarative modules later.

updating inputs #

Update deliberately, review the lockfile, then rerun formatting, flake checks, and both host evaluations before deploying:

nix flake update
nix flake check

notes #

See notes.md for tablet support, agent tooling, pulling this config onto a new system, and other miscellaneous notes.