molly's nixos config #
NixOS configurations for two x86_64-linux machines, managed from a single flake.
The canonical repository lives on Tangled: https://tangled.org/molly.computer/nixos.
hosts #
| host | role | notes |
|---|---|---|
| chi | Framework 12 laptop | Desktop; Niri compositor, Noctalia shell, Stylix theming from the wallpaper |
| halo | Strix Halo server | Headless; Tangled knot/spindle, Podman containers, sops-managed secrets |
layout #
flake.nix — flake inputs and both nixosConfigurations
modules/common.nix — settings shared by chi and halo (locale, firewall, nix)
hosts/chi/ — Framework 12 config, desktop modules, generated hardware config
hosts/halo/ — server config and its separate Home Manager config
home/ — Home Manager modules for chi (shell, apps, niri, opencode, …)
pkgs/ — locally packaged software (jagex-launcher)
secrets/ — SOPS-encrypted credentials only; never store plaintext here
docs/secrets.md — sops-nix key locations, editing, and rotation notes
wallpapers/ — wallpapers; the default also seeds the Stylix theme
notes.md — setup details, opencode integration, and misc notes
hosts/*/hardware-configuration.nix is generated by nixos-generate-config and
is intentionally excluded from the formatter. Keep it byte-identical unless the
hardware itself changes.
deploying #
# chi (local)
sudo nixos-rebuild switch --flake .#chi
# halo (from chi; the SSH host alias comes from Home Manager)
sudo nixos-rebuild switch --flake .#halo \
--target-host halo \
--use-remote-sudo
Preview a change with dry-activate or build instead of switch. Halo must
be deployed at least once after a secret changes so /run/secrets/halo/* is
rematerialized before consumers restart.
checks #
nix fmt
nix flake check
nix eval --raw .#nixosConfigurations.chi.config.system.build.toplevel.drvPath
nix eval --raw .#nixosConfigurations.halo.config.system.build.toplevel.drvPath
The formatter is treefmt with Alejandra, Statix, and deadnix. nix flake check
only runs the formatting check, so evaluate both hosts separately after touching
flake.nix, flake.lock, modules/common.nix, or shared inputs.
jagex-launcher #
The RuneScape launcher is not part of the default user profile. Run it from its own shell instead:
nix-shell pkgs/jagex-launcher
jagex-launcher
The package wraps a bundled AppImage, so it cannot self-update from the
read-only Nix store; bump pkgs/jagex-launcher/package.nix when a new build is
available.
secrets #
Secrets use sops-nix with age:
- chi key:
~/.config/sops/age/keys.txt - halo key:
/var/lib/sops-nix/keys.txt
Only the age recipients in .sops.yaml and encrypted files under secrets/
belong in Git; keep both private keys backed up outside the repository. Edit
credentials with sops secrets/halo.yaml. See docs/secrets.md
for the full workflow.
opencode #
OpenCode on chi is restricted to the route.daze.lol gateway
(enabled_providers = ["route"]). Its provider block, subagent models, and the
model list live in home/opencode.nix. A small plugin
(home/opencode/plugins/route-models.js) queries the gateway's /v1/models
endpoint at startup and adds any newly published models automatically.
API keys are never written to the store; the opencode wrapper reads them from
the login keyring at launch with secret-tool. See notes.md for
more on the agent tooling.
containers #
Halo's Podman/Compose application definitions currently live outside this
repository under /home/molly/. PDS already consumes its sops-managed
environment; the remaining services are planned to move here as declarative
modules later.
updating inputs #
Update deliberately, review the lockfile, then rerun formatting, flake checks, and both host evaluations before deploying:
nix flake update
nix flake check
notes #
See notes.md for tablet support, agent tooling, pulling this
config onto a new system, and other miscellaneous notes.