ark #
NixOS and home-manager configurations, packages and modules.
Source of truth #
Ark is the canonical flake. Keep host changes here rather than rebuilding from
an old nixcfg checkout or a migration worktree.
Valefar's configuration is hosts/valefar/; on the host this repo is checked out
(branch terra) at ~/.config/nixos, and /etc/nixos only holds a pointer note.
Its RustFS credentials stay encrypted in secrets/rustfs-credentials.env.age; its
service refuses to start unless /rustfs is mounted. Keep the existing system
generation for rollback.
Build on an x86_64 Linux machine: some inputs use Linux import-from-derivation, so evaluating these hosts on macOS can fail with a platform mismatch.
nix build --no-write-lock-file --no-link --print-out-paths \
.#nixosConfigurations.valefar.config.system.build.toplevel
nix eval --no-write-lock-file --raw \
.#nixosConfigurations.focalor.config.system.build.toplevel.drvPath
After reviewing the build and service changes, deploy Valefar from this checkout:
NH_FLAKE="$PWD" ./deploy.nu valefar --only-deploy --target-build
The default is a live switch, not a reboot. That is only safe when the kernel and
the nvidia driver are unchanged: a live switch swaps the userspace driver under the
already-loaded kernel module and breaks the GPU (and skews zfs). Compare first, and
use --boot plus a planned reboot (VMs and services go down) when either moves:
nix store diff-closures /run/current-system "$new" | rg 'linux-6|nvidia|zfs'
After a reboot into a new generation, if you pinned the old one as a fallback with
bootctl set-default, run sudo bootctl set-default '' once it is healthy. A left-over
EFI default overrides the loader.conf nixos writes, so later deploys would still
boot the pinned generation.
A failed agenix secret does not fail the switch. After deploying, check that every
secret in hosts/valefar/secrets.nix exists under /run/agenix; a missing
pia-wireguard-auth.env leaves the two PIA containers failing to start.
Valefar services outside this repo #
- Bonsai 2 27B (
hosts/valefar/bonsai.nix, packageterra.llama-cpp-bonsai):bonsai2.serviceserves it on127.0.0.1:8899and a socket exposes it on the LAN and tailnet addresses without an API key, since the host firewall is off. The weights are not in the store:~/models/bonsai2-27b/Ternary-Bonsai-2-27B-PTQ1_0-mtp-lean.gguf(sudoingX's MTP graft; the other quants are in/storage/models/bonsai2-27b/). - VM disks (niri, dawn) are Proxmox state in
/etc/pve, not nix. Both live on theHBAdrivestorage (/storage). storagezpool is two partitions of one disk (sdb) striped together, so there is no redundancy; only therustfspool is on a different disk.
The Yoga laptop runs Fedora, not NixOS. Its current desktop dotfiles are unmanaged; do not apply Valefar's NixOS configuration there. Moving them to home-manager is a separate change.