likely broken
nixos AGENTS.md
2.3 kB
Markdown
at main

Repository Instructions #

Configuration Boundaries #

  • flake.nix exposes two x86_64-linux systems: chi is the Framework 12 desktop/laptop and halo is the headless Strix Halo server.
  • modules/common.nix affects both hosts. hosts/chi/ and home/ own chi; halo uses hosts/halo/configuration.nix plus the separate hosts/halo/home.nix Home Manager config.
  • Halo's existing Podman/Compose application definitions live outside this repository under /home/molly/; do not assume container services are declarative here.
  • hosts/*/hardware-configuration.nix is generated by nixos-generate-config and deliberately excluded from treefmt. Keep it byte-identical unless the hardware configuration itself must change.
  • system.stateVersion and home.stateVersion are compatibility pins, not release-version markers. Do not bump them during routine input updates.

Verification #

  • Format and lint with nix fmt, then run nix flake check. The formatter is treefmt with Alejandra, Statix, and deadnix.
  • nix flake check does not evaluate both complete host configurations; CI separately runs nix eval --raw .#nixosConfigurations.chi.config.system.build.toplevel.drvPath.
  • CI also runs nix eval --raw .#nixosConfigurations.halo.config.system.build.toplevel.drvPath.
  • Evaluate both hosts after changing flake.nix, flake.lock, modules/common.nix, or shared inputs. For a host-only change, the affected host evaluation is the focused check.
  • Update inputs deliberately with nix flake update; review flake.lock, then rerun formatting, flake checks, and both host evaluations before deployment.

Secrets And Packages #

  • Only encrypted SOPS YAML belongs under secrets/. Edit halo secrets with sops secrets/halo.yaml; age private keys stay at ~/.config/sops/age/keys.txt on chi and /var/lib/sops-nix/keys.txt on halo, outside Git.
  • After changing a halo secret, deploy halo before restarting its consumer so /run/secrets/halo/* is rematerialized.

Deployment #

  • Do not run activation commands unless deployment was explicitly requested. Use build or dry-activate instead of switch for a preview.
  • Deploy chi locally with sudo nixos-rebuild switch --flake .#chi.
  • Deploy halo from chi with sudo nixos-rebuild switch --flake .#halo --target-host halo --use-remote-sudo.