diff --git a/configuration.nix b/configuration.nix index 01445ad..da84b13 100644 --- a/configuration.nix +++ b/configuration.nix @@ -1,29 +1,5 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page, on -# https://search.nixos.org/options and in the NixOS manual (`nixos-help`). - -# NixOS-WSL specific options are documented on the NixOS-WSL repository: -# https://github.com/nix-community/NixOS-WSL - -{ ... }: { - imports = [ - # WSL has no hardware configuration - #./hardware-configuration.nix - #./boot.nix - ./networking.nix - #./gui.nix - ./users.nix - ./packages.nix - ./services.nix - # include NixOS-WSL modules - - ]; - wsl = { - enable = true; - defaultUser = "noah"; - wslConf.network.hostname = "touma-wsl-nixos"; - }; - +{ ... }: +{ # Set your time zone. time.timeZone = "America/Chicago"; @@ -35,11 +11,6 @@ # useXkbConfig = true; # use xkb.options in tty. # }; - # Copy the NixOS configuration file and link it from the resulting system - # (/run/current-system/configuration.nix). This is useful in case you - # accidentally delete configuration.nix. - system.copySystemConfiguration = true; - # Automatic doc cache generation documentation.man.generateCaches = true; diff --git a/flake.lock b/flake.lock index 64ae2c8..23c3280 100644 --- a/flake.lock +++ b/flake.lock @@ -1,5 +1,107 @@ { "nodes": { + "agenix": { + "inputs": { + "darwin": "darwin", + "home-manager": "home-manager", + "nixpkgs": "nixpkgs", + "systems": "systems" + }, + "locked": { + "lastModified": 1762618334, + "narHash": "sha256-wyT7Pl6tMFbFrs8Lk/TlEs81N6L+VSybPfiIgzU8lbQ=", + "owner": "ryantm", + "repo": "agenix", + "rev": "fcdea223397448d35d9b31f798479227e80183f6", + "type": "github" + }, + "original": { + "owner": "ryantm", + "repo": "agenix", + "type": "github" + } + }, + "darwin": { + "inputs": { + "nixpkgs": [ + "agenix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1744478979, + "narHash": "sha256-dyN+teG9G82G+m+PX/aSAagkC+vUv0SgUw3XkPhQodQ=", + "owner": "lnl7", + "repo": "nix-darwin", + "rev": "43975d782b418ebf4969e9ccba82466728c2851b", + "type": "github" + }, + "original": { + "owner": "lnl7", + "ref": "master", + "repo": "nix-darwin", + "type": "github" + } + }, + "determinate-nixd-aarch64-darwin": { + "flake": false, + "locked": { + "narHash": "sha256-g1r0dPwlUi1h96c4BuHzv9M2lWDqRy9bPDW9tRSq35I=", + "type": "file", + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/macOS" + }, + "original": { + "type": "file", + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/macOS" + } + }, + "determinate-nixd-aarch64-linux": { + "flake": false, + "locked": { + "narHash": "sha256-xn324irXG/EpUdUfUGFrlJNg23JN2cVArd5LsFPjGKc=", + "type": "file", + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/aarch64-linux" + }, + "original": { + "type": "file", + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/aarch64-linux" + } + }, + "determinate-nixd-x86_64-linux": { + "flake": false, + "locked": { + "narHash": "sha256-VPM5FOGwEjl56b7Edvg3sduvauPHCyXZ11fN9hcUdTU=", + "type": "file", + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/x86_64-linux" + }, + "original": { + "type": "file", + "url": "https://install.determinate.systems/determinate-nixd/tag/v3.13.2/x86_64-linux" + } + }, + "determinite": { + "inputs": { + "determinate-nixd-aarch64-darwin": "determinate-nixd-aarch64-darwin", + "determinate-nixd-aarch64-linux": "determinate-nixd-aarch64-linux", + "determinate-nixd-x86_64-linux": "determinate-nixd-x86_64-linux", + "nix": "nix", + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1763536872, + "narHash": "sha256-QCYGGghBya+qsY59f1zzgYzxEzz+N9S7YRkVWDIDbgo=", + "rev": "f4e598cbb10021c93f73dd4c0cf01ec791ea53f9", + "revCount": 315, + "type": "tarball", + "url": "https://api.flakehub.com/f/pinned/DeterminateSystems/determinate/3.13.2/019a9b01-c0c6-7e1c-959e-98ac5b7675de/source.tar.gz" + }, + "original": { + "type": "tarball", + "url": "https://flakehub.com/f/DeterminateSystems/determinate/3" + } + }, "flake-compat": { "flake": false, "locked": { @@ -16,6 +118,85 @@ "type": "github" } }, + "flake-compat_2": { + "flake": false, + "locked": { + "lastModified": 1765121682, + "narHash": "sha256-4VBOP18BFeiPkyhy9o4ssBNQEvfvv1kXkasAYd0+rrA=", + "owner": "edolstra", + "repo": "flake-compat", + "rev": "65f23138d8d09a92e30f1e5c87611b23ef451bf3", + "type": "github" + }, + "original": { + "owner": "edolstra", + "repo": "flake-compat", + "type": "github" + } + }, + "flake-compat_3": { + "flake": false, + "locked": { + "lastModified": 1696426674, + "narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=", + "owner": "edolstra", + "repo": "flake-compat", + "rev": "0f9255e01c2351cc7d116c072cb317785dd33b33", + "type": "github" + }, + "original": { + "owner": "edolstra", + "repo": "flake-compat", + "type": "github" + } + }, + "flake-parts": { + "inputs": { + "nixpkgs-lib": [ + "determinite", + "nix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1748821116, + "narHash": "sha256-F82+gS044J1APL0n4hH50GYdPRv/5JWm34oCJYmVKdE=", + "rev": "49f0870db23e8c1ca0b5259734a02cd9e1e371a1", + "revCount": 377, + "type": "tarball", + "url": "https://api.flakehub.com/f/pinned/hercules-ci/flake-parts/0.1.377%2Brev-49f0870db23e8c1ca0b5259734a02cd9e1e371a1/01972f28-554a-73f8-91f4-d488cc502f08/source.tar.gz" + }, + "original": { + "type": "tarball", + "url": "https://flakehub.com/f/hercules-ci/flake-parts/0.1" + } + }, + "git-hooks-nix": { + "inputs": { + "flake-compat": "flake-compat", + "gitignore": [ + "determinite", + "nix" + ], + "nixpkgs": [ + "determinite", + "nix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1747372754, + "narHash": "sha256-2Y53NGIX2vxfie1rOW0Qb86vjRZ7ngizoo+bnXU9D9k=", + "rev": "80479b6ec16fefd9c1db3ea13aeb038c60530f46", + "revCount": 1026, + "type": "tarball", + "url": "https://api.flakehub.com/f/pinned/cachix/git-hooks.nix/0.1.1026%2Brev-80479b6ec16fefd9c1db3ea13aeb038c60530f46/0196d79a-1b35-7b8e-a021-c894fb62163d/source.tar.gz" + }, + "original": { + "type": "tarball", + "url": "https://flakehub.com/f/cachix/git-hooks.nix/0.1.941" + } + }, "gitignore": { "inputs": { "nixpkgs": [ @@ -38,6 +219,27 @@ } }, "home-manager": { + "inputs": { + "nixpkgs": [ + "agenix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1745494811, + "narHash": "sha256-YZCh2o9Ua1n9uCvrvi5pRxtuVNml8X2a03qIFfRKpFs=", + "owner": "nix-community", + "repo": "home-manager", + "rev": "abfad3d2958c9e6300a883bd443512c55dfeb1be", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "home-manager", + "type": "github" + } + }, + "home-manager_2": { "inputs": { "nixpkgs": [ "nixpkgs" @@ -58,19 +260,92 @@ "type": "github" } }, + "nix": { + "inputs": { + "flake-parts": "flake-parts", + "git-hooks-nix": "git-hooks-nix", + "nixpkgs": "nixpkgs_2", + "nixpkgs-23-11": "nixpkgs-23-11", + "nixpkgs-regression": "nixpkgs-regression" + }, + "locked": { + "lastModified": 1763534330, + "narHash": "sha256-gTuB2qBdSKCKnZwENTqScs/pPBaZQOv6zZ1KJvV/ohk=", + "rev": "be871f9baf5366a220b5f25634eebab6f452a017", + "revCount": 23278, + "type": "tarball", + "url": "https://api.flakehub.com/f/pinned/DeterminateSystems/nix-src/3.13.2/019a9af6-3d7b-71bc-bccd-8b18e147ad77/source.tar.gz" + }, + "original": { + "type": "tarball", + "url": "https://flakehub.com/f/DeterminateSystems/nix-src/%2A" + } + }, + "nixos-wsl": { + "inputs": { + "flake-compat": "flake-compat_2", + "nixpkgs": "nixpkgs_3" + }, + "locked": { + "lastModified": 1765483419, + "narHash": "sha256-w6wznH1lBzlSH3+pWDkE+L6xA0F02drFAzu2E7PD/Jo=", + "owner": "nix-community", + "repo": "NixOS-WSL", + "rev": "0c040f28b44b18e0d4240e027096078e34dbb029", + "type": "github" + }, + "original": { + "owner": "nix-community", + "ref": "main", + "repo": "NixOS-WSL", + "type": "github" + } + }, "nixpkgs": { "locked": { - "lastModified": 1764522689, - "narHash": "sha256-SqUuBFjhl/kpDiVaKLQBoD8TLD+/cTUzzgVFoaHrkqY=", - "owner": "nixos", + "lastModified": 1754028485, + "narHash": "sha256-IiiXB3BDTi6UqzAZcf2S797hWEPCRZOwyNThJIYhUfk=", + "owner": "NixOS", "repo": "nixpkgs", - "rev": "8bb5646e0bed5dbd3ab08c7a7cc15b75ab4e1d0f", + "rev": "59e69648d345d6e8fef86158c555730fa12af9de", "type": "github" }, "original": { - "owner": "nixos", - "ref": "nixos-25.11", + "owner": "NixOS", + "ref": "nixos-25.05", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs-23-11": { + "locked": { + "lastModified": 1717159533, + "narHash": "sha256-oamiKNfr2MS6yH64rUn99mIZjc45nGJlj9eGth/3Xuw=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "a62e6edd6d5e1fa0329b8653c801147986f8d446", + "type": "github" + }, + "original": { + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "a62e6edd6d5e1fa0329b8653c801147986f8d446", + "type": "github" + } + }, + "nixpkgs-regression": { + "locked": { + "lastModified": 1643052045, + "narHash": "sha256-uGJ0VXIhWKGXxkeNnq4TvV3CIOkUJ3PAoLZ3HMzNVMw=", + "owner": "NixOS", "repo": "nixpkgs", + "rev": "215d4d0fd80ca5163643b03a33fde804a29cc1e2", + "type": "github" + }, + "original": { + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "215d4d0fd80ca5163643b03a33fde804a29cc1e2", "type": "github" } }, @@ -91,6 +366,52 @@ } }, "nixpkgs_2": { + "locked": { + "lastModified": 1761597516, + "narHash": "sha256-wxX7u6D2rpkJLWkZ2E932SIvDJW8+ON/0Yy8+a5vsDU=", + "rev": "daf6dc47aa4b44791372d6139ab7b25269184d55", + "revCount": 811874, + "type": "tarball", + "url": "https://api.flakehub.com/f/pinned/NixOS/nixpkgs/0.2505.811874%2Brev-daf6dc47aa4b44791372d6139ab7b25269184d55/019a3494-3498-707e-9086-1fb81badc7fe/source.tar.gz" + }, + "original": { + "type": "tarball", + "url": "https://flakehub.com/f/NixOS/nixpkgs/0.2505" + } + }, + "nixpkgs_3": { + "locked": { + "lastModified": 1764950072, + "narHash": "sha256-BmPWzogsG2GsXZtlT+MTcAWeDK5hkbGRZTeZNW42fwA=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "f61125a668a320878494449750330ca58b78c557", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_4": { + "locked": { + "lastModified": 1764522689, + "narHash": "sha256-SqUuBFjhl/kpDiVaKLQBoD8TLD+/cTUzzgVFoaHrkqY=", + "owner": "nixos", + "repo": "nixpkgs", + "rev": "8bb5646e0bed5dbd3ab08c7a7cc15b75ab4e1d0f", + "type": "github" + }, + "original": { + "owner": "nixos", + "ref": "nixos-25.11", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_5": { "locked": { "lastModified": 1730768919, "narHash": "sha256-8AKquNnnSaJRXZxc5YmF/WfmxiHX6MMZZasRP6RRQkE=", @@ -108,9 +429,9 @@ }, "pre-commit-hooks": { "inputs": { - "flake-compat": "flake-compat", + "flake-compat": "flake-compat_3", "gitignore": "gitignore", - "nixpkgs": "nixpkgs_2" + "nixpkgs": "nixpkgs_5" }, "locked": { "lastModified": 1742649964, @@ -128,11 +449,29 @@ }, "root": { "inputs": { - "home-manager": "home-manager", - "nixpkgs": "nixpkgs", + "agenix": "agenix", + "determinite": "determinite", + "home-manager": "home-manager_2", + "nixos-wsl": "nixos-wsl", + "nixpkgs": "nixpkgs_4", "nixpkgs-unstable": "nixpkgs-unstable", "pre-commit-hooks": "pre-commit-hooks" } + }, + "systems": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } } }, "root": "root", diff --git a/flake.nix b/flake.nix index 6943782..237fa4a 100644 --- a/flake.nix +++ b/flake.nix @@ -1,38 +1,90 @@ { - description = "Home Manager configuration of noah"; + description = "Home Manager configuration for noah"; inputs = { # Specify the source of Home Manager and Nixpkgs. nixpkgs.url = "github:nixos/nixpkgs/nixos-25.11"; nixpkgs-unstable.url = "github:nixos/nixpkgs/nixos-unstable"; + nixos-wsl.url = "github:nix-community/NixOS-WSL/main"; + determinite = { + url = "https://flakehub.com/f/DeterminateSystems/determinate/3"; + inputs.nixpkgs.follows = "nixpkgs"; + }; home-manager = { url = "github:nix-community/home-manager/release-25.11"; inputs.nixpkgs.follows = "nixpkgs"; }; pre-commit-hooks.url = "github:cachix/git-hooks.nix"; + agenix.url = "github:ryantm/agenix"; }; - outputs = { self, nixpkgs, nixpkgs-unstable, home-manager, pre-commit-hooks, ... }@inputs: + outputs = + { + self, + nixpkgs, + nixpkgs-unstable, + nixos-wsl, + determinite, + home-manager, + pre-commit-hooks, + agenix, + ... + }@inputs: let - system = "aarch64-darwin"; - pkgs = nixpkgs.legacyPackages.${system}; - unstable-pkgs = nixpkgs-unstable.legacyPackages.${system}; - supportedSystems = [ "x86_64-linux" "aarch64-linux" "x86_64-darwin" "aarch64-darwin" ]; + supportedSystems = [ + "x86_64-linux" + "aarch64-linux" + "x86_64-darwin" + "aarch64-darwin" + ]; forAllSystems = nixpkgs.lib.genAttrs supportedSystems; + basicSystem = + { + system ? "x86_64-linux", + modules ? [ ], + unstable ? false, + ... + }: + inputs.nixpkgs.lib.nixosSystem { + inherit system; + specialArgs = + { + inherit inputs; + } + // nixpkgs.lib.optionalAttrs unstable { + unstable = nixpkgs-unstable.legacyPackages.${system}; + }; + modules = [ + determinite.nixosModules.default + ./configuration.nix + agenix.nixosModules.default + home-manager.nixosModules.home-manager + { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + home-manager.users.noah = ./home.nix; + home-manager.extraSpecialArgs = + { + inherit inputs; + } + // nixpkgs.lib.optionalAttrs unstable { + unstable = nixpkgs-unstable.legacyPackages.${system}; + }; + } + ] ++ modules; + }; in { - homeConfigurations."noah" = home-manager.lib.homeManagerConfiguration { - inherit pkgs; - - # Specify your home configuration modules here, for example, - # the path to your home.nix. - modules = [ ./noah-home.nix ]; - - # Optionally use extraSpecialArgs - # to pass through arguments to home.nix - extraSpecialArgs = { - unstable = unstable-pkgs; - }; + # incomplete + nixosConfigurations.odin = basicSystem { + unstable = true; + }; + nixosConfigurations.touma-wsl = basicSystem { + unstable = true; + modules = [ + ./host-specific/touma-wsl.nix + nixos-wsl.nixosModules.default + ]; }; checks = forAllSystems (system: { pre-commit-check = inputs.pre-commit-hooks.lib.${system}.run { @@ -40,7 +92,7 @@ # If your hooks are intrusive, avoid running on each commit with a default_states like this: # default_stages = ["manual" "push"]; hooks = { - nixpkgs-fmt.enable = true; + nixfmt-rfc-style.enable = true; nil.enable = true; luacheck.enable = true; }; @@ -49,8 +101,11 @@ devShells = forAllSystems (system: { default = nixpkgs.legacyPackages.${system}.mkShell { inherit (self.checks.${system}.pre-commit-check) shellHook; - buildInputs = self.checks.${system}.pre-commit-check.enabledPackages; + buildInputs = [ + nixpkgs.legacyPackages.${system}.nixfmt-rfc-style + ] ++ self.checks.${system}.pre-commit-check.enabledPackages; }; }); + formatter = forAllSystems (system: inputs.nixpkgs.legacyPackages.${system}.nixfmt-rfc-style); }; } diff --git a/gui.nix b/gui.nix index 4263c39..f032c1e 100644 --- a/gui.nix +++ b/gui.nix @@ -1,6 +1,5 @@ -{ pkgs, ... }: -let unstable = import { }; -in { +{ pkgs, unstable, ... }: +{ # Enable the X11 windowing system. services.xserver.enable = true; @@ -66,7 +65,12 @@ in { # i3, for when I need XOrg services.xserver.windowManager.i3 = { enable = true; - extraPackages = with pkgs; [ dmenu i3status i3lock i3blocks ]; + extraPackages = with pkgs; [ + dmenu + i3status + i3lock + i3blocks + ]; }; xdg.portal = { diff --git a/home.nix b/home.nix index 7b3432d..4c69e2b 100644 --- a/home.nix +++ b/home.nix @@ -1,7 +1,4 @@ -{ pkgs, ... }: -let - unstable = import { }; -in +{ pkgs, unstable, ... }: { home.packages = with pkgs; [ # main tool @@ -101,7 +98,10 @@ in ]; nix = { - settings.experimental-features = [ "nix-command" "flakes" ]; + settings.experimental-features = [ + "nix-command" + "flakes" + ]; }; programs.fish = { @@ -114,7 +114,12 @@ in defaultEditor = true; withNodeJs = true; withPython3 = true; - extraPackages = with pkgs; [ unstable.fzf unstable.ripgrep luarocks unstable.tree-sitter ]; + extraPackages = with pkgs; [ + unstable.fzf + unstable.ripgrep + luarocks + unstable.tree-sitter + ]; }; programs.helix.enable = true; programs.jujutsu = { diff --git a/host-specific/touma-wsl.nix b/host-specific/touma-wsl.nix new file mode 100644 index 0000000..b9123c5 --- /dev/null +++ b/host-specific/touma-wsl.nix @@ -0,0 +1,22 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page, on +# https://search.nixos.org/options and in the NixOS manual (`nixos-help`). + +# NixOS-WSL specific options are documented on the NixOS-WSL repository: +# https://github.com/nix-community/NixOS-WSL + +{ ... }: +{ + imports = [ + # WSL has no hardware configuration + ../networking.nix + ../users.nix + ../packages.nix + ../services.nix + ]; + wsl = { + enable = true; + defaultUser = "noah"; + wslConf.network.hostname = "touma-wsl-nixos"; + }; +} diff --git a/networking.nix b/networking.nix index fcbfc77..c5ad5b7 100644 --- a/networking.nix +++ b/networking.nix @@ -1,9 +1,5 @@ -{ ... }: { - #networking.hostName = "touma-wsl-nixos"; - - #systemd.network.enable = true; - #networking.useNetworkd = true; - #services.resolved.enable = false; +{ ... }: +{ services.avahi = { enable = true; diff --git a/users.nix b/users.nix index 944eed7..490ce63 100644 --- a/users.nix +++ b/users.nix @@ -1,15 +1,9 @@ { pkgs, lib, ... }: let - home-manager = builtins.fetchTarball - "https://github.com/nix-community/home-manager/archive/release-25.11.tar.gz"; + home-manager = builtins.fetchTarball "https://github.com/nix-community/home-manager/archive/release-25.11.tar.gz"; in { - imports = [ - # Import home-manager first, it's required for other modules - (import "${home-manager}/nixos") - ]; - # Declarative only optoins. # I don't want to allow ad-hoc modifying users on the system. # Users must be declared either as part of a package or in this file. @@ -19,23 +13,23 @@ in users.users.noah = { isNormalUser = true; shell = pkgs.fish; - extraGroups = [ "wheel" "video" "nas" ]; # Enable ‘sudo’ for the user. + extraGroups = [ + "wheel" + "video" + "nas" + ]; # Enable ‘sudo’ for the user. hashedPasswordFile = "/etc/nixos/noah-password"; - openssh.authorizedKeys.keys = - lib.strings.splitString "\n" (builtins.readFile (builtins.fetchurl { - url = "https://meta.sr.ht/~chiefnoah.keys"; - name = "chiefnoah.keys"; - # Update this with: - # `curl https://meta.sr.ht/~chiefnoah.keys | sha256sum` - sha256 = "b07f29019f0fcf2d7e217637fce6c7f9476468cc47cb8eaf36a0cd646aa4a8a7"; - })); + openssh.authorizedKeys.keys = lib.strings.splitString "\n" ( + builtins.readFile ( + builtins.fetchurl { + url = "https://meta.sr.ht/~chiefnoah.keys"; + name = "chiefnoah.keys"; + # Update this with: + # `curl https://meta.sr.ht/~chiefnoah.keys | sha256sum` + sha256 = "b07f29019f0fcf2d7e217637fce6c7f9476468cc47cb8eaf36a0cd646aa4a8a7"; + } + ) + ); }; users.groups.nas.gid = 1001; - # I manage my home with home-manager - # Don't store packages in ~/.nix-profile, use /etc/profiles so we can build-vm - home-manager.useUserPackages = true; - # No more NIX_PATH, use system pkgs - home-manager.useGlobalPkgs = true; - - home-manager.users.noah = import ./home.nix; }