This repository has no description
Nix 66%
14%
CSS 6%
Rust 5%
Nushell 3%
Go 3%
Go Template 2%
JavaScript 1%
HCL <1%
Shell <1%

README.md

ark #

NixOS and home-manager configurations, packages and modules.

Source of truth #

Ark is the canonical flake. Keep host changes here rather than rebuilding from an old nixcfg checkout or a migration worktree.

Valefar's configuration is hosts/valefar/; on the host this repo is checked out (branch terra) at ~/.config/nixos, and /etc/nixos only holds a pointer note. Its RustFS credentials stay encrypted in secrets/rustfs-credentials.env.age; its service refuses to start unless /rustfs is mounted. Keep the existing system generation for rollback.

Build on an x86_64 Linux machine: some inputs use Linux import-from-derivation, so evaluating these hosts on macOS can fail with a platform mismatch.

nix build --no-write-lock-file --no-link --print-out-paths \
  .#nixosConfigurations.valefar.config.system.build.toplevel
nix eval --no-write-lock-file --raw \
  .#nixosConfigurations.focalor.config.system.build.toplevel.drvPath

After reviewing the build and service changes, deploy Valefar from this checkout:

NH_FLAKE="$PWD" ./deploy.nu valefar --only-deploy --target-build

The default is a live switch, not a reboot. That is only safe when the kernel and the nvidia driver are unchanged: a live switch swaps the userspace driver under the already-loaded kernel module and breaks the GPU (and skews zfs). Compare first, and use --boot plus a planned reboot (VMs and services go down) when either moves:

nix store diff-closures /run/current-system "$new" | rg 'linux-6|nvidia|zfs'

After a reboot into a new generation, if you pinned the old one as a fallback with bootctl set-default, run sudo bootctl set-default '' once it is healthy. A left-over EFI default overrides the loader.conf nixos writes, so later deploys would still boot the pinned generation.

A failed agenix secret does not fail the switch. After deploying, check that every secret in hosts/valefar/secrets.nix exists under /run/agenix; a missing pia-wireguard-auth.env leaves the two PIA containers failing to start.

Valefar services outside this repo #

  • Bonsai 2 27B (hosts/valefar/bonsai.nix, package terra.llama-cpp-bonsai): bonsai2.service serves it on 127.0.0.1:8899 and a socket exposes it on the LAN and tailnet addresses without an API key, since the host firewall is off. The weights are not in the store: ~/models/bonsai2-27b/Ternary-Bonsai-2-27B-PTQ1_0-mtp-lean.gguf (sudoingX's MTP graft; the other quants are in /storage/models/bonsai2-27b/).
  • VM disks (niri, dawn) are Proxmox state in /etc/pve, not nix. Both live on the HBAdrive storage (/storage).
  • storage zpool is two partitions of one disk (sdb) striped together, so there is no redundancy; only the rustfs pool is on a different disk.

The Yoga laptop runs Fedora, not NixOS. Its current desktop dotfiles are unmanaged; do not apply Valefar's NixOS configuration there. Moving them to home-manager is a separate change.