diff --git a/AGENTS.md b/AGENTS.md index cf1ed42..7f6f2a0 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -271,7 +271,11 @@ Configured substituters: - `https://cache.nixos.org` - `https://nix-community.cachix.org` -- `https://cache.toyvo.dev` +- `https://cache.toyvo.dev` — served by nix-serve on the nas out of its local + store. Automatically excluded from substituters on the machine serving it + (`nixcfg.nix.excludeOwnCache`, defaults to `services.nix-serve.enable`), and + the nas resolves the domain to the router's LAN IP so trusted-user/CI builds + that pick it up from the flake's `nixConfig` don't hairpin the WAN. ## Git Hooks diff --git a/configurations/nixos/nas/configuration.nix b/configurations/nixos/nas/configuration.nix index 8b85944..0d83c1b 100644 --- a/configurations/nixos/nas/configuration.nix +++ b/configurations/nixos/nas/configuration.nix @@ -97,6 +97,11 @@ in hardware.cpu.amd.updateMicrocode = true; networking = { hostName = "nas"; + # Resolve the cache domain via the router over LAN. The nas itself is + # excluded from using it as a substituter (nixcfg.nix.excludeOwnCache), + # but trusted users and CI can still pick it up from this flake's public + # nixConfig, and the WAN path back in (hairpin) is broken. + hosts."${homelab.router.ip}" = [ "cache.toyvo.dev" ]; firewall = { allowedTCPPorts = [ 80 diff --git a/flake.nix b/flake.nix index deb139c..76d5b6b 100644 --- a/flake.nix +++ b/flake.nix @@ -1,19 +1,6 @@ { description = "Collin Diekvoss Nix Configurations and NUR packages"; - nixConfig = { - extra-substituters = [ - "https://cache.nixos.org" - "https://nix-community.cachix.org" - "https://cache.toyvo.dev" - ]; - extra-trusted-public-keys = [ - "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" - "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" - "cache.toyvo.dev:6bv4Qc2/SVaWnWzDOUcoB4pT3i3l4wcM+WrhRBFb7E4=" - ]; - }; - inputs = { apple-silicon-support.url = "github:tpwrules/nixos-apple-silicon"; catppuccin.url = "github:catppuccin/nix"; diff --git a/modules/home/programs/editors/zed-settings.json b/modules/home/programs/editors/zed-settings.json index 60107fc..2d5be37 100644 --- a/modules/home/programs/editors/zed-settings.json +++ b/modules/home/programs/editors/zed-settings.json @@ -62,7 +62,7 @@ "edit_predictions": { "provider": "open_ai_compatible_api", "open_ai_compatible_api": { - "api_url": "https://opencode.ai/zen/go/v1/completions", + "api_url": "https://opencode.ai/zen/v1/completions", "model": "deepseek-v4-flash-free", "prompt_format": "infer", "max_output_tokens": 512 diff --git a/modules/home/session.nix b/modules/home/session.nix index 2d88cf8..cd8ccc9 100644 --- a/modules/home/session.nix +++ b/modules/home/session.nix @@ -3,10 +3,14 @@ lib, pkgs, system, + osConfig ? null, ... }: let cfg = config.nixcfg.session; + # Machines serving cache.toyvo.dev via nix-serve should not substitute from + # it; everything it publishes is already in the local store. + hostServesCache = osConfig != null && (osConfig.services.nix-serve.enable or false); in { options = { @@ -64,7 +68,9 @@ in xdg.configFile = { "nix/nix.conf".text = '' experimental-features = nix-command flakes pipe-operators - substituters = https://cache.nixos.org https://nix-community.cachix.org https://cache.toyvo.dev + substituters = https://cache.nixos.org https://nix-community.cachix.org${ + lib.optionalString (!hostServesCache) " https://cache.toyvo.dev" + } trusted-public-keys = cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY= nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs= cache.toyvo.dev:6bv4Qc2/SVaWnWzDOUcoB4pT3i3l4wcM+WrhRBFb7E4= ''; "nixpkgs/config.nix".text = '' diff --git a/modules/home/users/toyvo.nix b/modules/home/users/toyvo.nix index 4e81f5e..8d8f6ed 100644 --- a/modules/home/users/toyvo.nix +++ b/modules/home/users/toyvo.nix @@ -255,6 +255,7 @@ in ''; "shell-secrets.env".content = '' OPENCODE_API_KEY=${config.sops.placeholder.opencode_api_key} + ZED_OPEN_AI_COMPATIBLE_EDIT_PREDICTION_API_KEY=${config.sops.placeholder.opencode_api_key} ''; }; }; diff --git a/modules/os/nix.nix b/modules/os/nix.nix index 3f4d87e..19b5785 100644 --- a/modules/os/nix.nix +++ b/modules/os/nix.nix @@ -6,9 +6,29 @@ }: let cfg = config.nixcfg.nix; + # cache.toyvo.dev is served by nix-serve out of the serving machine's own + # local nix store, so substituting from it there can never yield anything -- + # and resolving it loops out to the WAN and back (hairpin). + cacheSubstituters = [ + "https://cache.nixos.org" + "https://nix-community.cachix.org" + ] + ++ lib.optional (!cfg.excludeOwnCache) "https://cache.toyvo.dev"; in { - options.nixcfg.nix.enable = lib.mkEnableOption "nix configuration"; + options.nixcfg.nix = { + enable = lib.mkEnableOption "nix configuration"; + excludeOwnCache = lib.mkOption { + type = lib.types.bool; + default = config.services.nix-serve.enable or false; + defaultText = lib.literalExpression "config.services.nix-serve.enable or false"; + description = '' + Exclude cache.toyvo.dev from substituters. Defaults to true on machines + that serve the cache via nix-serve, since everything it publishes is + already in the local nix store. + ''; + }; + }; config = lib.mkIf cfg.enable { nix = { @@ -18,12 +38,8 @@ in "flakes" "pipe-operators" ]; - substituters = config.nix.settings.trusted-substituters; - trusted-substituters = [ - "https://cache.nixos.org" - "https://nix-community.cachix.org" - "https://cache.toyvo.dev" - ]; + substituters = cacheSubstituters; + trusted-substituters = cacheSubstituters; trusted-public-keys = [ "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="