diff --git a/flake.lock b/flake.lock index 2d8e428..11d0d66 100644 --- a/flake.lock +++ b/flake.lock @@ -19,7 +19,9 @@ "agenix": { "inputs": { "darwin": [], - "home-manager": "home-manager", + "home-manager": [ + "home-manager" + ], "nixpkgs": [ "nixpkgs" ], @@ -39,29 +41,6 @@ "type": "github" } }, - "alejandra": { - "inputs": { - "fenix": "fenix", - "flakeCompat": "flakeCompat", - "nixpkgs": [ - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1660592437, - "narHash": "sha256-xFumnivtVwu5fFBOrTxrv6fv3geHKF04RGP23EsDVaI=", - "owner": "kamadorueda", - "repo": "alejandra", - "rev": "e7eac49074b70814b542fee987af2987dd0520b5", - "type": "github" - }, - "original": { - "owner": "kamadorueda", - "ref": "3.0.0", - "repo": "alejandra", - "type": "github" - } - }, "claude-code": { "inputs": { "nixpkgs": "nixpkgs", @@ -102,34 +81,12 @@ } }, "fenix": { - "inputs": { - "nixpkgs": [ - "alejandra", - "nixpkgs" - ], - "rust-analyzer-src": "rust-analyzer-src" - }, - "locked": { - "lastModified": 1657607339, - "narHash": "sha256-HaqoAwlbVVZH2n4P3jN2FFPMpVuhxDy1poNOR7kzODc=", - "owner": "nix-community", - "repo": "fenix", - "rev": "b814c83d9e6aa5a28d0cf356ecfdafb2505ad37d", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "fenix", - "type": "github" - } - }, - "fenix_2": { "inputs": { "nixpkgs": [ "tangled-core", "nixpkgs" ], - "rust-analyzer-src": "rust-analyzer-src_2" + "rust-analyzer-src": "rust-analyzer-src" }, "locked": { "lastModified": 1780397302, @@ -248,22 +205,6 @@ "type": "github" } }, - "flakeCompat": { - "flake": false, - "locked": { - "lastModified": 1650374568, - "narHash": "sha256-Z+s0J8/r907g149rllvwhb4pKi8Wam5ij0st8PwAh+E=", - "owner": "edolstra", - "repo": "flake-compat", - "rev": "b4a34015c698c7793d592d66adbab377907a2be8", - "type": "github" - }, - "original": { - "owner": "edolstra", - "repo": "flake-compat", - "type": "github" - } - }, "foundryvtt": { "inputs": { "nixpkgs": [ @@ -287,7 +228,7 @@ "ghostty": { "inputs": { "flake-compat": "flake-compat", - "home-manager": "home-manager_2", + "home-manager": "home-manager", "nixpkgs": "nixpkgs_2", "systems": "systems_3", "zig": "zig", @@ -343,27 +284,6 @@ } }, "home-manager": { - "inputs": { - "nixpkgs": [ - "agenix", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1745494811, - "narHash": "sha256-YZCh2o9Ua1n9uCvrvi5pRxtuVNml8X2a03qIFfRKpFs=", - "owner": "nix-community", - "repo": "home-manager", - "rev": "abfad3d2958c9e6300a883bd443512c55dfeb1be", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "home-manager", - "type": "github" - } - }, - "home-manager_2": { "inputs": { "nixpkgs": [ "ghostty", @@ -384,7 +304,7 @@ "type": "github" } }, - "home-manager_3": { + "home-manager_2": { "inputs": { "nixpkgs": [ "nixpkgs" @@ -404,7 +324,7 @@ "type": "github" } }, - "home-manager_4": { + "home-manager_3": { "inputs": { "nixpkgs": [ "impermanence", @@ -464,7 +384,7 @@ }, "impermanence": { "inputs": { - "home-manager": "home-manager_4", + "home-manager": "home-manager_3", "nixpkgs": "nixpkgs_3" }, "locked": { @@ -807,12 +727,11 @@ "root": { "inputs": { "agenix": "agenix", - "alejandra": "alejandra", "claude-code": "claude-code", "disko": "disko", "foundryvtt": "foundryvtt", "ghostty": "ghostty", - "home-manager": "home-manager_3", + "home-manager": "home-manager_2", "impermanence": "impermanence", "nix-cachyos-kernel": "nix-cachyos-kernel", "nix-flatpak": "nix-flatpak", @@ -827,23 +746,6 @@ } }, "rust-analyzer-src": { - "flake": false, - "locked": { - "lastModified": 1657557289, - "narHash": "sha256-PRW+nUwuqNTRAEa83SfX+7g+g8nQ+2MMbasQ9nt6+UM=", - "owner": "rust-lang", - "repo": "rust-analyzer", - "rev": "caf23f29144b371035b864a1017dbc32573ad56d", - "type": "github" - }, - "original": { - "owner": "rust-lang", - "ref": "nightly", - "repo": "rust-analyzer", - "type": "github" - } - }, - "rust-analyzer-src_2": { "flake": false, "locked": { "lastModified": 1780337665, @@ -984,7 +886,7 @@ "tangled-core": { "inputs": { "actor-typeahead-src": "actor-typeahead-src", - "fenix": "fenix_2", + "fenix": "fenix", "fetch-tangled": "fetch-tangled", "flake-compat": "flake-compat_3", "gomod2nix": "gomod2nix", diff --git a/flake.nix b/flake.nix index d17847f..150a99d 100644 --- a/flake.nix +++ b/flake.nix @@ -8,8 +8,6 @@ The starlight on the Western Seas. nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; # chaotic.url = "github:chaotic-cx/nyx/nyxpkgs-unstable"; # Discontinued as of 2025-12-08 nix-cachyos-kernel.url = "github:xddxdd/nix-cachyos-kernel/release"; # CachyOS kernel replacement - alejandra.url = "github:kamadorueda/alejandra/3.0.0"; - alejandra.inputs.nixpkgs.follows = "nixpkgs"; home-manager.url = "github:nix-community/home-manager"; home-manager.inputs.nixpkgs.follows = "nixpkgs"; nix-flatpak.url = "github:gmodena/nix-flatpak"; @@ -59,6 +57,7 @@ The starlight on the Western Seas. agenix = { url = "github:ryantm/agenix"; inputs.nixpkgs.follows = "nixpkgs"; + inputs.home-manager.follows = "home-manager"; inputs.darwin.follows = ""; # Save resources on Linux }; tangled-core.url = "git+https://tangled.org/@tangled.org/core"; @@ -71,7 +70,6 @@ The starlight on the Western Seas. self, nixpkgs, home-manager, - alejandra, # chaotic, # Removed - discontinued nix-cachyos-kernel, nix-flatpak, diff --git a/hosts/jupiter.nix b/hosts/jupiter.nix index 4d8de6f..74e3aab 100644 --- a/hosts/jupiter.nix +++ b/hosts/jupiter.nix @@ -181,7 +181,9 @@ in { "xhci_pci" "virtio_scsi" ]; - systemd.enable = false; + # Scripted initrd is removed in 26.11; was explicitly false (reason unrecorded). + # TODO: untested - verify the next manual reboot of jupiter comes back up. + systemd.enable = true; }; }; services.openssh.enable = true; diff --git a/hosts/profiles/usb.nix b/hosts/profiles/usb.nix index 109eded..432b5ff 100644 --- a/hosts/profiles/usb.nix +++ b/hosts/profiles/usb.nix @@ -19,7 +19,6 @@ # teq.nixos.impermanence.label_boot = label_boot; nix.optimise.automatic = true; nix.optimise.dates = ["03:45"]; - nix.settings.auto-optimise-store = true; nix.gc = { automatic = true; dates = "daily"; @@ -30,6 +29,7 @@ max-free = ${toString (1024 * 1024 * 1024)} ''; isoImage.edition = "plasma6"; + boot.zfs.forceImportRoot = false; # 26.11 default; live ISO has no ZFS root services.openssh.settings.PermitRootLogin = lib.mkForce "yes"; # Live installer convention # Avoid nixpkgs entry conflict between installer channel and flake-input registry home-manager.sharedModules = [{nix.registry = lib.mkForce {};}]; diff --git a/modules/home-manager/nixcfg.nix b/modules/home-manager/nixcfg.nix index b066ccc..716d905 100644 --- a/modules/home-manager/nixcfg.nix +++ b/modules/home-manager/nixcfg.nix @@ -65,7 +65,6 @@ in { settings = { # nix-path = mkForce "nixpkgs=/etc/nix/inputs/nixpkgs"; nix-path = mkDefault config.nix.nixPath; # Workaround for https://github.com/NixOS/nix/issues/9574 - auto-optimise-store = mkDefault true; bash-prompt-prefix = mkDefault "(nix:$name)\040"; experimental-features = mkDefault [ "nix-command" @@ -90,15 +89,12 @@ in { builders-use-substitutes = mkDefault true; substituters = mkDefault caches.substituters; trusted-substituters = mkDefault caches.substituters; - extra-substituters = mkDefault caches.extraSubstituters; - extra-trusted-substituters = mkDefault caches.extraSubstituters; trusted-users = mkForce [ "root" "teq" "@wheel" ]; trusted-public-keys = mkDefault caches.trustedPublicKeys; - extra-trusted-public-keys = mkDefault caches.extraTrustedPublicKeys; }; }; }; diff --git a/modules/nixos/by-category/build-server.nix b/modules/nixos/by-category/build-server.nix index 31be12f..b68aff7 100644 --- a/modules/nixos/by-category/build-server.nix +++ b/modules/nixos/by-category/build-server.nix @@ -40,8 +40,8 @@ in { pushRemotes = lib.mkOption { type = lib.types.listOf lib.types.str; - default = ["origin" "tangled"]; - description = "Remotes to push the lockfile commit to. First is required, rest are best-effort."; + default = ["tangled" "origin"]; + description = "Remotes to push the lockfile commit to. First is required (autoUpgrade pulls from it), rest are best-effort mirrors."; }; sshIdentity = lib.mkOption { diff --git a/modules/nixos/nixcfg.nix b/modules/nixos/nixcfg.nix index f0cbcb7..957f615 100644 --- a/modules/nixos/nixcfg.nix +++ b/modules/nixos/nixcfg.nix @@ -7,7 +7,7 @@ ... }: with lib; let - flakeInputs = filterAttrs (_: isType "flake") inputs; + flakeInputs = filterAttrs (_: isType "flake") (removeAttrs inputs ["self"]); caches = import ../shared-caches.nix; defaultLang = "en_US.UTF-8"; inherit (lib) mkDefault; @@ -20,14 +20,13 @@ in { blocklist = lib.mkEnableOption "Enable host blocklist defaults."; }; config = lib.mkIf config.teq.nixos.enable ({ - system.stateVersion = "24.05"; # https://nixos.wiki/wiki/FAQ/When_do_I_update_stateVersion + system.stateVersion = lib.mkOverride 1100 "24.05"; # Weak fallback; hosts/profiles (e.g. the ISO) may mkDefault their own. https://nixos.wiki/wiki/FAQ/When_do_I_update_stateVersion nixpkgs = { config = { # allowBroken = true; allowUnfree = true; # allowUnsupportedSystem = true; permittedInsecurePackages = [ - "openssl-1.1.1w" # vesktop's build-time pnpm; runtime closure is unaffected. Drop after # the next nixpkgs bump moves vesktop's pnpmDeps off 10.29.2. "pnpm-10.29.2" @@ -65,16 +64,23 @@ in { dates = mkDefault "weekly"; # Not present in home-manager options = mkDefault "--delete-older-than 1w"; }; + # Scheduled optimisation instead of per-write auto-optimise-store (faster builds) + optimise = { + automatic = mkDefault true; + dates = mkDefault ["weekly"]; + }; # Free up to 1GiB whenever there is less than 100MiB left. - extraOptions = mkDefault '' - min-free = ${toString (100 * 1024 * 1024)} - max-free = ${toString (1024 * 1024 * 1024)} - ''; + extraOptions = mkDefault ('' + min-free = ${toString (100 * 1024 * 1024)} + max-free = ${toString (1024 * 1024 * 1024)} + '' + # Secret must contain a full line: access-tokens = github.com= + + lib.optionalString (options ? age) '' + !include ${config.age.secrets."gh".path} + ''); settings = { - access-tokens = lib.mkIf (options ? age) config.age.secrets."gh".path; # nix-path = mkForce "nixpkgs=/etc/nix/inputs/nixpkgs"; nix-path = mkDefault config.nix.nixPath; # Workaround for https://github.com/NixOS/nix/issues/9574 - auto-optimise-store = mkDefault true; bash-prompt-prefix = mkDefault "(nix:$name)\040"; experimental-features = mkDefault [ "nix-command" @@ -99,20 +105,18 @@ in { builders-use-substitutes = mkDefault true; substituters = caches.substituters; trusted-substituters = caches.substituters; - extra-trusted-substituters = caches.extraSubstituters; trusted-users = mkForce [ "root" "teq" "@wheel" ]; trusted-public-keys = caches.trustedPublicKeys; - extra-trusted-public-keys = caches.extraTrustedPublicKeys; }; }; # `enable` only when self has a clean revision — never clobber a host with local edits. system.autoUpgrade = { enable = mkDefault ((inputs.self.rev or "dirty") != "dirty"); - flake = mkDefault "github:Teqed/nixos-config"; + flake = mkDefault "git+https://tangled.org/@quilling.dev/nixos-config"; # Primary remote; GitHub is a best-effort mirror flags = mkDefault ["-L" "--refresh"]; randomizedDelaySec = mkDefault "30min"; dates = mkDefault "04:00"; @@ -152,6 +156,10 @@ in { } # Only when the agenix module is imported // lib.optionalAttrs (options ? age) { - age.secrets."gh".file = ../../secrets/gh.age; + age.secrets."gh" = { + file = ../../secrets/gh.age; + mode = "0440"; + group = "wheel"; # Readable by nix clients (access-tokens is client-side) + }; }); } diff --git a/modules/shared-caches.nix b/modules/shared-caches.nix index a4e1fb6..3232873 100644 --- a/modules/shared-caches.nix +++ b/modules/shared-caches.nix @@ -21,28 +21,4 @@ "nixpkgs-unfree.cachix.org-1:hqvoInulhbV4nJ9yJOEr+4wxhDV4xq2d1DK7S6Nj6rs=" "ghostty.cachix.org-1:QB389yTa6gTyneehvqG58y0WnHjQOqgnA+wBnpWWxns=" ]; - - extraSubstituters = [ - "https://yazi.cachix.org" # Yazi file manager - "https://devenv.cachix.org" # devenv - "https://tranquil.cachix.org" # Tranquil PDS - "https://digitallyinduced.cachix.org" # IHP framework - "https://ghc-nix.cachix.org" # GHC builds - "https://ic-hs-test.cachix.org" # Internet Computer - "https://kaleidogen.cachix.org" # Specific project - "https://static-haskell-nix.cachix.org" # Static Haskell - "https://tttool.cachix.org" # TipToi tool - ]; - - extraTrustedPublicKeys = [ - "yazi.cachix.org-1:Dcdz63NZKfvUCbDGngQDAZq6kOroIrFoyO064uvLh8k=" - "devenv.cachix.org-1:w1cLUi8dv3hnoSPGAuibQv+f9TZLr6cv/Hm9XgU50cw=" - "tranquil.cachix.org-1:PoO+mGL6a6LcJiPakMDHN4E218/ei/7v2sxeDtNkSRg=" - "digitallyinduced.cachix.org-1:y+wQvrnxQ+PdEsCt91rmvv39qRCYzEgGQaldK26hCKE=" - "ghc-nix.cachix.org-1:ziC/I4BPqeA4VbtOFpFpu6D1t6ymFvRWke/lc2+qjcg=" - "ic-hs-test.cachix.org-1:8Ct2qPYnI4jZSyE+wJ0aR5laqaE2VRedzyX7JplSsHI=" - "kaleidogen.cachix.org-1:Ib2KIGCtrU/QFt1MRQdLpx5QMBv9++CrZsUfXle7m/Q=" - "static-haskell-nix.cachix.org-1:Q17HawmAwaM1/BfIxaEDKAxwTOyRVhPG5Ji9K3+FvUU=" - "tttool.cachix.org-1:e/5HpIa6ZqwatH07kmO7di1p9K+AMrgkNHl/OGUUMzU=" - ]; } diff --git a/secrets/gh.age b/secrets/gh.age index 9544cf0..f9f53af 100644 --- a/secrets/gh.age +++ b/secrets/gh.age @@ -1,9 +1,9 @@ age-encryption.org/v1 --> ssh-ed25519 YfkjLA JbDAxPEyKQBbxpDJQETWYbw2ntYdfyo2Oi5ZZeWquCY -XjLDwi6n8JCZ/8lRgUnofEguUAlHlCj5McBG15lK6ks --> ssh-ed25519 bjrAAA 8m93UtCna2WrKJXaeC4wBL8ONoIR1HLSP1ZihpqHhV8 -dWv4PVoLspgGjSw6ILEK13Bz2tiyqsfNwH39ZZoZzCU --> ssh-ed25519 WLgeeA Y4gnZ1i9/FLX8Lhy/i/j1hut9gfshs01kFjH0nJURAE -llxahUKpsQqUcYnGsv2ldhi/C8khF93zHvpgzxChdjA ---- RJU/44nJJTgrOrLAxHLFn6ZPoFGpumNotWp6lRPG5/U -��b6U$���&ٲݱf�NߏK�h�n���f��B�DW�:4��D���'�6�*�͗���З�S�5�%�_�F�?�b���w�{E�s�o��5��oӮ�A��v�����-��B�>5&J�e�l \ No newline at end of file +-> ssh-ed25519 YfkjLA qLiaqZeklHaMgvr1QdMHxrSLXGYbJVD5hz3jzBRIPnU +ELcOULdYLCAoMwQQR3tDS0XdAdOaRL25fNiNMEXyuL4 +-> ssh-ed25519 bjrAAA 8ZsDGubwtHtuKqiwsMQ9BYqKk/gV8PI6qe67X2eyZGU +BA7jvHQG0Ntb7ytJZZZeo9XeYr9Y1RX0FEbKJ/B+gbk +-> ssh-ed25519 WLgeeA IS9HDesEZRKJMg2TJ1LZOiwF4E5lgob/I9SOI8cLxhg +Ggff9S+glg+6eOcDpytVmdlWfhuol7MqFXHIR+oeQEw +--- Xuh+tXklAcITpyL6ECTwB1YIRoRRa5OTTq7FB1YwDso +ĥ��}iI.'�t��l/�[���U3�<�.Jy\`� ���f�S����[5D �`��y~�T庑 ��_hQ�~{ˑ���)����g��A��_��-�cT9��L��M��ɓ���IG��AJ_��u O��?�*���{�P$Q0����e�� \ No newline at end of file