From 2cd28c2a6aa98b8ec33e6fceca3b08e5130b4c87 Mon Sep 17 00:00:00 2001 From: Leah Amelia Chen Date: Fri, 16 Jan 2026 15:06:56 +0800 Subject: [PATCH] flake: restructure --- flake.nix | 63 +++++-------------- overlay.nix | 62 +++++++++++-------- systems/fettuccine/configuration.nix | 43 +++++++++++++ systems/fettuccine/default.nix | 40 ++---------- systems/focaccia/configuration.nix | 76 +++++++++++++++++++++++ systems/focaccia/default.nix | 89 +++++---------------------- systems/pappardelle/configuration.nix | 15 +++++ systems/pappardelle/default.nix | 14 ++--- 8 files changed, 212 insertions(+), 190 deletions(-) create mode 100644 systems/fettuccine/configuration.nix create mode 100644 systems/focaccia/configuration.nix create mode 100644 systems/pappardelle/configuration.nix diff --git a/flake.nix b/flake.nix index 19eeab1..c844de6 100644 --- a/flake.nix +++ b/flake.nix @@ -55,60 +55,25 @@ outputs = inputs: - let - inherit (inputs.nixpkgs) lib; - packages' = - pkgs': - pkgs'.lib.packagesFromDirectoryRecursive { - inherit (pkgs') callPackage; - directory = ./packages; - }; - specialArgs = { inherit inputs; }; - in inputs.flake-parts.lib.mkFlake { inherit inputs; } { - systems = lib.systems.flakeExposed; + systems = [ + "x86_64-linux" + "x86_64-darwin" + ]; + + imports = [ + ./overlay.nix + ./systems/fettuccine + ./systems/pappardelle + ./systems/focaccia + ]; flake = { - overlays.default = final: prev: packages' prev // import ./overlay.nix final prev; - - # Personal computers - nixosConfigurations.fettuccine = lib.nixosSystem { - modules = [ ./systems/fettuccine ]; - inherit specialArgs; - }; - - nixosConfigurations.pappardelle = lib.nixosSystem { - modules = [ ./systems/pappardelle ]; - inherit specialArgs; - }; - - # Servers - nixosConfigurations.focaccia = lib.nixosSystem { - modules = [ ./systems/focaccia ]; - inherit specialArgs; - }; - hjemModules = { hjem-ext = import ./modules/hjem-ext; hjem-ctp = import ./modules/hjem-ctp; }; - # deploy-rs Nodes - deploy.nodes.focaccia = { - sshOpts = [ - "-p" - "42069" - ]; - hostname = "focaccia.pluie.me"; - profiles = { - system = { - path = inputs.deploy-rs.lib.x86_64-linux.activate.nixos inputs.self.nixosConfigurations.focaccia; - user = "root"; - sshUser = "root"; - }; - }; - }; - # This is highly advised, and will prevent many possible mistakes checks = builtins.mapAttrs ( _: deployLib: deployLib.deployChecks inputs.self.deploy @@ -118,6 +83,7 @@ perSystem = { pkgs, + lib, system, ... }: @@ -128,7 +94,10 @@ config.allowUnfree = true; }; - packages = packages' pkgs; + packages = lib.packagesFromDirectoryRecursive { + inherit (pkgs) callPackage; + directory = ./packages; + }; devShells.default = pkgs.mkShellNoCC { packages = with pkgs; [ diff --git a/overlay.nix b/overlay.nix index 6915aaa..a3f0151 100644 --- a/overlay.nix +++ b/overlay.nix @@ -1,27 +1,41 @@ # May lord have mercy on my soul -final: prev: { - jujutsu = prev.jujutsu.overrideAttrs { - patches = (prev.patches or [ ]) ++ [ - # HACK: I am so sick and tired of not being able to push to Nixpkgs - # because some edgy fucking idiot thought that it's a good idea to not - # specify an email address in a commit - # - # See https://github.com/NixOS/nixpkgs/pull/453871 - # See https://github.com/jj-vcs/jj/issues/5723 - (prev.fetchpatch2 { - url = "https://github.com/pluiedev/jj/commit/daa88d4dd485ed0c188023d2af8f811fd4db4a14.patch"; - hash = "sha256-F8fp+LXQwuFVVVnYHJAEaQ9dFr6z9tdCkmcKDC39mM8="; - }) - ]; - doCheck = false; - }; +{ + self, + ... +}: +{ + flake.overlays.default = + final: prev: + let + inherit (prev.stdenv.hostPlatform) system; - # TODO: Remove when nixpkgs#473189 is available in unstable - vicinae = final.runCommand "vicinae-patched" { } '' - mkdir -p $out - cp -r ${prev.vicinae}/* $out - substituteInPlace $out/share/systemd/user/vicinae.service \ - --replace-fail "/bin/kill" "${final.lib.getExe' final.coreutils "kill"}" \ - --replace-fail "vicinae" "$out/bin/vicinae" - ''; + myPkgs = prev.lib.optionalAttrs (builtins.hasAttr system self.packages) self.packages.${system}; + in + myPkgs + // { + jujutsu = prev.jujutsu.overrideAttrs { + patches = (prev.patches or [ ]) ++ [ + # HACK: I am so sick and tired of not being able to push to Nixpkgs + # because some edgy fucking idiot thought that it's a good idea to not + # specify an email address in a commit + # + # See https://github.com/NixOS/nixpkgs/pull/453871 + # See https://github.com/jj-vcs/jj/issues/5723 + (prev.fetchpatch2 { + url = "https://github.com/pluiedev/jj/commit/daa88d4dd485ed0c188023d2af8f811fd4db4a14.patch"; + hash = "sha256-F8fp+LXQwuFVVVnYHJAEaQ9dFr6z9tdCkmcKDC39mM8="; + }) + ]; + doCheck = false; + }; + + # TODO: Remove when nixpkgs#473189 is available in unstable + vicinae = final.runCommand "vicinae-patched" { } '' + mkdir -p $out + cp -r ${prev.vicinae}/* $out + substituteInPlace $out/share/systemd/user/vicinae.service \ + --replace-fail "/bin/kill" "${final.lib.getExe' final.coreutils "kill"}" \ + --replace-fail "vicinae" "$out/bin/vicinae" + ''; + }; } diff --git a/systems/fettuccine/configuration.nix b/systems/fettuccine/configuration.nix new file mode 100644 index 0000000..57f0d79 --- /dev/null +++ b/systems/fettuccine/configuration.nix @@ -0,0 +1,43 @@ +{ + config, + lib, + inputs, + ... +}: +{ + imports = with inputs.nixos-hardware.nixosModules; [ + ../laptop.nix + ./hardware-configuration.nix + asus-zephyrus-gu603h + ]; + + networking.hostName = "fettuccine"; + + users.users.leah.enable = true; + + # Disable Nvidia's HDMI audio + boot.blacklistedKernelModules = [ "snd_hda_codec_hdmi" ]; + + # Allow CUDA + nixpkgs.config.cudaSupport = true; + + hardware = { + bluetooth.enable = true; + + nvidia = { + # PCI bus IDs are already conveniently set by nixos-hardware + prime.offload.enable = lib.mkForce true; + + # Beta can sometimes be more stable than, well, stable + package = config.boot.kernelPackages.nvidiaPackages.beta; + }; + }; + + # Nix can sometimes overload my poor, poor laptop CPU + # so much that it can freeze my entire system. Amazing. + # Please don't do that. + nix.daemonCPUSchedPolicy = "idle"; + + # This is an ASUS computer after all + services.asusd.enable = true; +} diff --git a/systems/fettuccine/default.nix b/systems/fettuccine/default.nix index 57f0d79..3709ad5 100644 --- a/systems/fettuccine/default.nix +++ b/systems/fettuccine/default.nix @@ -1,43 +1,11 @@ { - config, - lib, inputs, + lib, ... }: { - imports = with inputs.nixos-hardware.nixosModules; [ - ../laptop.nix - ./hardware-configuration.nix - asus-zephyrus-gu603h - ]; - - networking.hostName = "fettuccine"; - - users.users.leah.enable = true; - - # Disable Nvidia's HDMI audio - boot.blacklistedKernelModules = [ "snd_hda_codec_hdmi" ]; - - # Allow CUDA - nixpkgs.config.cudaSupport = true; - - hardware = { - bluetooth.enable = true; - - nvidia = { - # PCI bus IDs are already conveniently set by nixos-hardware - prime.offload.enable = lib.mkForce true; - - # Beta can sometimes be more stable than, well, stable - package = config.boot.kernelPackages.nvidiaPackages.beta; - }; + flake.nixosConfigurations.fettuccine = lib.nixosSystem { + modules = [ ./configuration.nix ]; + specialArgs = { inherit inputs; }; }; - - # Nix can sometimes overload my poor, poor laptop CPU - # so much that it can freeze my entire system. Amazing. - # Please don't do that. - nix.daemonCPUSchedPolicy = "idle"; - - # This is an ASUS computer after all - services.asusd.enable = true; } diff --git a/systems/focaccia/configuration.nix b/systems/focaccia/configuration.nix new file mode 100644 index 0000000..a568977 --- /dev/null +++ b/systems/focaccia/configuration.nix @@ -0,0 +1,76 @@ +{ + imports = [ + ../common.nix + ./hardware-configuration.nix + ./networking.nix + ../../modules/nixos/hysteria.nix + ]; + + networking = { + hostName = "focaccia"; + domain = "pluie.me"; + firewall = { + allowedUDPPorts = [ 53 ]; + allowedTCPPorts = [ + 80 + 443 + ]; + }; + }; + + users.users.leah = { + enable = true; + isNormalUser = true; + description = "Leah C"; + extraGroups = [ + "wheel" # 1984 powers + ]; + home = "/home/leah"; + + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKbsavGX9rGRx5R+7ovLn+r7D/w3zkbqCik4bS31moSz" + ]; + }; + + services.openssh = { + enable = true; + ports = [ 42069 ]; + settings.PermitRootLogin = "prohibit-password"; + }; + + programs.mosh = { + enable = true; + openFirewall = true; + }; + + users.users.root.openssh.authorizedKeys.keys = [ + ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKbsavGX9rGRx5R+7ovLn+r7D/w3zkbqCik4bS31moSz'' + ]; + + boot.kernel.sysctl = { + "net.core.rmem_max" = 16777216; + "net.core.wmem_max" = 16777216; + }; + + services.hysteria = { + enable = true; + settings = { + listen = ":53"; + acme = { + domains = [ "focaccia.pluie.me" ]; + email = "srv@acc.pluie.me"; + }; + auth = { + type = "password"; + password._secret = "/var/lib/hysteria/passwd"; + }; + masquerade = { + type = "proxy"; + proxy = { + url = "https://news.ycombinator.com/"; + rewriteHost = true; + }; + }; + }; + }; +} diff --git a/systems/focaccia/default.nix b/systems/focaccia/default.nix index 707d53f..d2ca40a 100644 --- a/systems/focaccia/default.nix +++ b/systems/focaccia/default.nix @@ -1,85 +1,26 @@ { + self, + inputs, lib, - utils, ... }: -let - settings = { - - }; -in { - imports = [ - ../common.nix - ./hardware-configuration.nix - ./networking.nix - ../../modules/nixos/hysteria.nix - ]; - - networking = { - hostName = "focaccia"; - domain = "pluie.me"; - firewall = { - allowedUDPPorts = [ 53 ]; - allowedTCPPorts = [ - 80 - 443 - ]; - }; + flake.nixosConfigurations.focaccia = lib.nixosSystem { + modules = [ ./configuration.nix ]; + specialArgs = { inherit inputs; }; }; - users.users.leah = { - enable = true; - isNormalUser = true; - description = "Leah C"; - extraGroups = [ - "wheel" # 1984 powers + flake.deploy.nodes.focaccia = { + sshOpts = [ + "-p" + "42069" ]; - home = "/home/leah"; - - openssh.authorizedKeys.keys = [ - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKbsavGX9rGRx5R+7ovLn+r7D/w3zkbqCik4bS31moSz" - ]; - }; - - services.openssh = { - enable = true; - ports = [ 42069 ]; - settings.PermitRootLogin = "prohibit-password"; - }; - - programs.mosh = { - enable = true; - openFirewall = true; - }; - - users.users.root.openssh.authorizedKeys.keys = [ - ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKbsavGX9rGRx5R+7ovLn+r7D/w3zkbqCik4bS31moSz'' - ]; - - boot.kernel.sysctl = { - "net.core.rmem_max" = 16777216; - "net.core.wmem_max" = 16777216; - }; - - services.hysteria = { - enable = true; - settings = { - listen = ":53"; - acme = { - domains = [ "focaccia.pluie.me" ]; - email = "srv@acc.pluie.me"; - }; - auth = { - type = "password"; - password._secret = "/var/lib/hysteria/passwd"; - }; - masquerade = { - type = "proxy"; - proxy = { - url = "https://news.ycombinator.com/"; - rewriteHost = true; - }; + hostname = "focaccia.pluie.me"; + profiles = { + system = { + path = inputs.deploy-rs.lib.x86_64-linux.activate.nixos self.nixosConfigurations.focaccia; + user = "root"; + sshUser = "root"; }; }; }; diff --git a/systems/pappardelle/configuration.nix b/systems/pappardelle/configuration.nix new file mode 100644 index 0000000..edbbbdf --- /dev/null +++ b/systems/pappardelle/configuration.nix @@ -0,0 +1,15 @@ +{ + inputs, + ... +}: +{ + imports = with inputs.nixos-hardware.nixosModules; [ + ../laptop.nix + ./hardware-configuration.nix + lenovo-ideapad-14iah10 + ]; + + hardware.bluetooth.enable = true; + networking.hostName = "pappardelle"; + users.users.leah.enable = true; +} diff --git a/systems/pappardelle/default.nix b/systems/pappardelle/default.nix index edbbbdf..d6ae83b 100644 --- a/systems/pappardelle/default.nix +++ b/systems/pappardelle/default.nix @@ -1,15 +1,11 @@ { inputs, + lib, ... }: { - imports = with inputs.nixos-hardware.nixosModules; [ - ../laptop.nix - ./hardware-configuration.nix - lenovo-ideapad-14iah10 - ]; - - hardware.bluetooth.enable = true; - networking.hostName = "pappardelle"; - users.users.leah.enable = true; + flake.nixosConfigurations.pappardelle = lib.nixosSystem { + modules = [ ./configuration.nix ]; + specialArgs = { inherit inputs; }; + }; } -- 2.51.2