From dda91c58a576df0b1dd4b058b644117c37f4f591 Mon Sep 17 00:00:00 2001 From: Joshua Barrett Date: Tue, 23 Jun 2026 10:27:18 -0400 Subject: [PATCH] added angrr to help clean things up --- modules/nixos/nix.nix | 39 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 39 insertions(+) diff --git a/modules/nixos/nix.nix b/modules/nixos/nix.nix index e673917..44265d4 100644 --- a/modules/nixos/nix.nix +++ b/modules/nixos/nix.nix @@ -7,6 +7,45 @@ with lib; { config = { nixpkgs.config.allowUnfree = true; + # Yet more theft from orual. This seems about right. + services.angrr = { + enable = true; + settings = { + temporary-root-policies = { + direnv = { + path-regex = "/\\.direnv/"; + period = "14d"; + }; + result = { + path-regex = "/result[^/]*$"; + period = "3d"; + }; + }; + profile-policies = { + system = { + keep-booted-system = true; + keep-current-system = true; + keep-latest-n = 10; + keep-since = "14d"; + profile-paths = [ + "/nix/var/nix/profiles/system" + ]; + }; + user = { + enable = true; + keep-booted-system = true; + keep-current-system = true; + keep-latest-n = 2; + keep-since = "1d"; + profile-paths = [ + "~/.local/state/nix/profiles/profile" + "/nix/var/nix/profiles/per-user/root/profile" + ]; + }; + }; + }; + }; + nix = { gc = { automatic = true; -- 2.51.2