Compare commits

...

20 Commits

Author SHA1 Message Date
3bcd4c3c13 chore: update lockfile 2026-05-06 19:41:05 +02:00
d975d49844 fix(nvim): allow unfree nvim plugins 2026-05-06 19:41:00 +02:00
1ead7fe7be chore: update lockfile 2026-04-30 18:33:01 +02:00
7dd2fc7e59 chore: update lockfile 2026-04-30 18:28:53 +02:00
95ffe7b908 refactor: derive host name solely from host directory name 2026-04-30 17:20:02 +02:00
ce02cc5538 fix(desktops): resolve xdg portal error on 'work' host 2026-04-30 15:31:07 +02:00
0dbc007a90 feat(database): add redis to database module 2026-04-30 15:07:10 +02:00
57e0d49278 fix(nvim): add missing dependencies 2026-04-30 15:06:51 +02:00
ee44b26147 feat(ai): add 'ai-tools' 'skills' submodule 2026-04-29 18:37:43 +02:00
675306ec91 refactor: modularize 'ai-tools' 2026-04-29 18:37:42 +02:00
a829f160fb fix(gnome): don't use monospace font for 'dconf' 2026-04-29 18:37:07 +02:00
4cfe0387e2 chore: update 'nvim' flake dependencies 2026-04-29 18:37:06 +02:00
2efccdb4de feat(hydra): add hydra-repl filetype integration 2026-04-26 19:07:55 +02:00
8aafaf7d35 chore: disable 'mcp-nixos' temporarily (failed test) 2026-04-26 19:07:55 +02:00
dce57f907a chore(ai): enable 'claude-code' on 'andromache,astyanax' hosts 2026-04-26 19:07:55 +02:00
1bda05280e refactor(desktops): give all desktop modules own subdirectory 2026-04-26 19:07:55 +02:00
d39071da06 refactor(desktops): extract 'logind' module 2026-04-26 19:07:55 +02:00
781f379aff refactor: simplify zk file completion 2026-04-26 19:07:55 +02:00
2203b48cde fix: scope markdown file name echo to zk 2026-04-26 19:07:55 +02:00
35f6f7890f chore: add 'nodejs_24' dependency to 'nvim' flake 2026-04-26 19:07:55 +02:00
40 changed files with 400 additions and 246 deletions

View File

@@ -0,0 +1,35 @@
local hydra_repl = "hydra-repl"
if not vim.fn.executable(hydra_repl) then
return
end
local function send(lines)
vim.system({ hydra_repl, table.concat(lines, "\n") })
end
local function get_paragraph(buf)
local start_ = vim.fn.search("^$", "bnW")
local end_ = vim.fn.search("^$", "nW") - 1
if end_ < vim.api.nvim_win_get_cursor(0)[1] then
end_ = vim.api.nvim_buf_line_count(buf)
end
return vim.api.nvim_buf_get_lines(buf, start_, end_, false)
end
local function get_selection(buf)
return vim.api.nvim_buf_get_lines(buf, vim.fn.line("'<") - 1, vim.fn.line("'>"), false)
end
vim.api.nvim_create_autocmd("FileType", {
pattern = "javascript",
callback = function(e)
if vim.fn.fnamemodify(vim.api.nvim_buf_get_name(e.buf), ":e") ~= "hydra" then
return
end
local buf = e.buf
vim.keymap.set("n", "<CR>", function() send(get_paragraph(buf)) end, { buffer = buf, desc = "hydra: send block" })
vim.keymap.set("v", "<CR>", function() send(get_selection(buf)) end, { buffer = buf, desc = "hydra: send selection" })
end,
})

View File

@@ -13,11 +13,16 @@ nm <leader>ww <plug>(wiki-index)
" nm <leader>s <plug>(wiki-link-follow-split) " nm <leader>s <plug>(wiki-link-follow-split)
" nm <leader>v <plug>(wiki-link-follow-vsplit) " nm <leader>v <plug>(wiki-link-follow-vsplit)
autocmd BufEnter *.md if expand('%:t') =~ '_' | echo 'hierarchical relation' | endif function! ZKContextualEcho()
autocmd BufEnter *.md if expand('%:t') =~ '--' | echo 'relation' | endif let l:name = expand('%:t')
autocmd BufEnter *.md if expand('%:t') =~ '<>' | echo 'dichotomy' | endif if l:name =~ '_' | echo 'hierarchical relation'
autocmd BufEnter *.md if expand('%:t') =~ 'my-' | echo 'personal file' | endif elseif l:name =~ '--' | echo 'relation'
autocmd BufEnter *.md if expand('%:t') =~ 'project_' | echo 'project file' | endif elseif l:name =~ '<>' | echo 'dichotomy'
elseif l:name =~ 'my-' | echo 'personal file'
elseif l:name =~ 'project_' | echo 'project file'
endif
endfunction
execute 'autocmd BufEnter' g:zk_path . '/*.md' 'call ZKContextualEcho()'
" Only load wiki.vim for zk directory " Only load wiki.vim for zk directory
let g:wiki_index_name='index' let g:wiki_index_name='index'

View File

@@ -42,11 +42,11 @@
}, },
"nixCats": { "nixCats": {
"locked": { "locked": {
"lastModified": 1774835836, "lastModified": 1777273601,
"narHash": "sha256-6ok7iv/9R82vl6MYe3Lwyyb6S5bmW2PxEZtmjzlqyPs=", "narHash": "sha256-xBUa8Tl9V7IXI+VmLEuDc81La/EhoSn1C3EVSnJ3cfU=",
"owner": "BirdeeHub", "owner": "BirdeeHub",
"repo": "nixCats-nvim", "repo": "nixCats-nvim",
"rev": "ebb9f279a55ca60ff4e37e4accf6518dc627aa8d", "rev": "f69ea013e328841a7def7037ed59788a76be8816",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -73,11 +73,11 @@
}, },
"nixpkgs_2": { "nixpkgs_2": {
"locked": { "locked": {
"lastModified": 1775608838, "lastModified": 1777270315,
"narHash": "sha256-2ySoGH+SAi34U0PeuQgABC0WiH9LQ3tkyHTiE93KUeg=", "narHash": "sha256-yKB4G6cKsQsWN7M6rZGk6gkJPDNPIzT05y4qzRyCDlI=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "9a01fad67a57e44e1b3e1d905c6881bcfb209e8a", "rev": "6368eda62c9775c38ef7f714b2555a741c20c72d",
"type": "github" "type": "github"
}, },
"original": { "original": {

View File

@@ -45,7 +45,23 @@
inherit (nixCats) utils; inherit (nixCats) utils;
luaPath = ./.; luaPath = ./.;
forEachSystem = utils.eachSystem nixpkgs.lib.platforms.all; forEachSystem = utils.eachSystem nixpkgs.lib.platforms.all;
extra_pkg_config = { }; extra_pkg_config = {
allowUnfreePredicate =
pkg:
builtins.elem (nixpkgs.lib.getName pkg) [
"vim-sandwich"
"jupytext.nvim"
"eyeliner.nvim"
"context_filetype.vim"
"editorconfig-vim"
"unicode.vim"
"quarto-nvim"
"vim-openscad"
"lsp_lines.nvim"
"nvim-highlight-colors"
"nvim-lint"
];
};
mkDependencyOverlays = system: [ mkDependencyOverlays = system: [
(utils.standardPluginOverlay inputs) (utils.standardPluginOverlay inputs)
@@ -71,9 +87,11 @@
{ {
lspsAndRuntimeDeps = with pkgs; { lspsAndRuntimeDeps = with pkgs; {
general = [ general = [
nodejs_24
black black
clang clang
clang-tools clang-tools
curl # → plenary-nvim, mcp-hub
delta delta
emmet-language-server emmet-language-server
eslint_d eslint_d
@@ -87,6 +105,8 @@
mcp-hub mcp-hub
nixd nixd
nixfmt nixfmt
prettier
typescript-language-server
ormolu ormolu
prettierd prettierd
rust-analyzer rust-analyzer
@@ -95,6 +115,7 @@
stylelint stylelint
stylua stylua
tree-sitter tree-sitter
tailwindcss-language-server
typescript-language-server typescript-language-server
vscode-langservers-extracted vscode-langservers-extracted
vtsls vtsls

View File

@@ -9,5 +9,6 @@ vim.filetype.add({
["%.env.*"] = "dotenv", ["%.env.*"] = "dotenv",
["%.pl$"] = "prolog", ["%.pl$"] = "prolog",
[".*.containerfile.*"] = "dockerfile", [".*.containerfile.*"] = "dockerfile",
["%.hydra$"] = "javascript",
}, },
}) })

View File

@@ -13,13 +13,19 @@ local function get_markdown_files(base)
return items return items
end end
function source:get_keyword_pattern()
return "[%w%./%-]*"
end
function source:complete(params, callback) function source:complete(params, callback)
local cursor_before_line = params.context.cursor_before_line local cursor_before_line = params.context.cursor_before_line
local cursor_after_line = params.context.cursor_after_line or "" local cursor_after_line = params.context.cursor_after_line or ""
local trigger = cursor_before_line:match("%[[^%]]*%]%(([^)]*)$") if not cursor_before_line:match("%[[^%]]*%]%(") then
callback({})
return
end
if trigger ~= nil then
local items = get_markdown_files(".") local items = get_markdown_files(".")
local next_char = cursor_after_line:sub(1, 1) local next_char = cursor_after_line:sub(1, 1)
@@ -32,9 +38,6 @@ function source:complete(params, callback)
end end
callback(items) callback(items)
else
callback({})
end
end end
function source:get_trigger_characters() function source:get_trigger_characters()

78
flake.lock generated
View File

@@ -38,11 +38,11 @@
"base16-helix": { "base16-helix": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1760703920, "lastModified": 1776754714,
"narHash": "sha256-m82fGUYns4uHd+ZTdoLX2vlHikzwzdu2s2rYM2bNwzw=", "narHash": "sha256-E3OAK27smtATTmX45uoTSRsVD+Y+ZiVVfgM/tjpbtYg=",
"owner": "tinted-theming", "owner": "tinted-theming",
"repo": "base16-helix", "repo": "base16-helix",
"rev": "d646af9b7d14bff08824538164af99d0c521b185", "rev": "4d508123037e7851ad36ebf7d9c48b0e9e1eb581",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -121,11 +121,11 @@
}, },
"locked": { "locked": {
"dir": "pkgs/firefox-addons", "dir": "pkgs/firefox-addons",
"lastModified": 1777176175, "lastModified": 1778040175,
"narHash": "sha256-l/0TJCLEarrsyHIKNhAjI4+7lkyGsFqojyx1X1h64Ks=", "narHash": "sha256-SSXJp3BMjO2LrW/VLjNdGGcjd3RFEyV4FemYA6OGrYw=",
"owner": "rycee", "owner": "rycee",
"repo": "nur-expressions", "repo": "nur-expressions",
"rev": "515c8c1296021efe49ba1b1318ff27a43e93442b", "rev": "3bd76b0f41e65661866bddcac57ebe83aeadb581",
"type": "gitlab" "type": "gitlab"
}, },
"original": { "original": {
@@ -138,11 +138,11 @@
"firefox-gnome-theme": { "firefox-gnome-theme": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1775176642, "lastModified": 1776136500,
"narHash": "sha256-2veEED0Fg7Fsh81tvVDNYR6SzjqQxa7hbi18Jv4LWpM=", "narHash": "sha256-r0gN2brVWA351zwMV0Flmlcd6SGMvYqFbvC3DfKFM8Y=",
"owner": "rafaelmardojai", "owner": "rafaelmardojai",
"repo": "firefox-gnome-theme", "repo": "firefox-gnome-theme",
"rev": "179704030c5286c729b5b0522037d1d51341022c", "rev": "0f8ba203d475587f477e7ae12661bd8459e225b7",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -342,11 +342,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1777196875, "lastModified": 1778009629,
"narHash": "sha256-6M/rTHxFRdKJ6WZYxrCl68qIyh3BvjWBmYC7Vufolbg=", "narHash": "sha256-nUoQtf4Zq7DRYJrfv904hjrxjAlWVP6a1pNNFKx3FCg=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "38bf0202cae280174cbb80fc24a63978f16333f7", "rev": "00ed86e58bb6979a7921859fd1615d19382eac5c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -415,11 +415,11 @@
}, },
"nixCats": { "nixCats": {
"locked": { "locked": {
"lastModified": 1774835836, "lastModified": 1777273601,
"narHash": "sha256-6ok7iv/9R82vl6MYe3Lwyyb6S5bmW2PxEZtmjzlqyPs=", "narHash": "sha256-xBUa8Tl9V7IXI+VmLEuDc81La/EhoSn1C3EVSnJ3cfU=",
"owner": "BirdeeHub", "owner": "BirdeeHub",
"repo": "nixCats-nvim", "repo": "nixCats-nvim",
"rev": "ebb9f279a55ca60ff4e37e4accf6518dc627aa8d", "rev": "f69ea013e328841a7def7037ed59788a76be8816",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -451,11 +451,11 @@
}, },
"nixos-hardware": { "nixos-hardware": {
"locked": { "locked": {
"lastModified": 1776983936, "lastModified": 1777917524,
"narHash": "sha256-ZOQyNqSvJ8UdrrqU1p7vaFcdL53idK+LOM8oRWEWh6o=", "narHash": "sha256-k+LVe9YaO2BEPB9AaCtTtOMCeGi4dxDo6gt4Un3qoPY=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixos-hardware", "repo": "nixos-hardware",
"rev": "2096f3f411ce46e88a79ae4eafcfc9df8ed41c61", "rev": "df7783100babf59001340a7a874ba3824e441ecb",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -467,11 +467,11 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1776877367, "lastModified": 1777954456,
"narHash": "sha256-EHq1/OX139R1RvBzOJ0aMRT3xnWyqtHBRUBuO1gFzjI=", "narHash": "sha256-hGdgeU2Nk87RAuZyYjyDjFL6LK7dAZN5RE9+hrDTkDU=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "0726a0ecb6d4e08f6adced58726b95db924cef57", "rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -509,11 +509,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1775228139, "lastModified": 1777598946,
"narHash": "sha256-ebbeHmg+V7w8050bwQOuhmQHoLOEOfqKzM1KgCTexK4=", "narHash": "sha256-X239dAGaU1+gfDj8jKH8GzlqKMcxaVfXOio+uzBOkeE=",
"owner": "nix-community", "owner": "nix-community",
"repo": "NUR", "repo": "NUR",
"rev": "601971b9c89e0304561977f2c28fa25e73aa7132", "rev": "5d55af01c0f86be583931fe99207fc56c14134b3",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -665,11 +665,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1776771786, "lastModified": 1777944972,
"narHash": "sha256-DRFGPfFV6hbrfO9a1PH1FkCi7qR5FgjSqsQGGvk1rdI=", "narHash": "sha256-VfGRo1qTBKOe3s2gOv8LSoA6Fk19PvBlwQ1ECN0Evn8=",
"owner": "Mic92", "owner": "Mic92",
"repo": "sops-nix", "repo": "sops-nix",
"rev": "bef289e2248991f7afeb95965c82fbcd8ff72598", "rev": "c591bf665727040c6cc5cb409079acb22dcce33c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -714,11 +714,11 @@
"tinted-zed": "tinted-zed" "tinted-zed": "tinted-zed"
}, },
"locked": { "locked": {
"lastModified": 1776893932, "lastModified": 1777835090,
"narHash": "sha256-AFD5cf9eNqXq1brHS63xeZy2xKZMgG9J86XJ9I2eLn8=", "narHash": "sha256-VLH8zPweblCOvpnQXp4fVs7f6Q79YhXF5XFKlOrvIFk=",
"owner": "danth", "owner": "danth",
"repo": "stylix", "repo": "stylix",
"rev": "84971726c7ef0bb3669a5443e151cc226e65c518", "rev": "7989a1054b01153212dede6005abfd1576b8328c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -776,11 +776,11 @@
"tinted-schemes": { "tinted-schemes": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1772661346, "lastModified": 1777041405,
"narHash": "sha256-4eu3LqB9tPqe0Vaqxd4wkZiBbthLbpb7llcoE/p5HT0=", "narHash": "sha256-BAGZ7ObFV/9Z61OJZun7ifPyhkuHqNuW1QIhQ8LuzCo=",
"owner": "tinted-theming", "owner": "tinted-theming",
"repo": "schemes", "repo": "schemes",
"rev": "13b5b0c299982bb361039601e2d72587d6846294", "rev": "5f868b3a338b6904c47f3833b9c411be641983a8",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -792,11 +792,11 @@
"tinted-tmux": { "tinted-tmux": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1772934010, "lastModified": 1777169200,
"narHash": "sha256-x+6+4UvaG+RBRQ6UaX+o6DjEg28u4eqhVRM9kpgJGjQ=", "narHash": "sha256-h7dDbIzP5hDr9v97w9PL6jdAgXawmj6krcH+959rqpU=",
"owner": "tinted-theming", "owner": "tinted-theming",
"repo": "tinted-tmux", "repo": "tinted-tmux",
"rev": "c3529673a5ab6e1b6830f618c45d9ce1bcdd829d", "rev": "f798c2dce44ef815bb6b8f05a82135c7942d35ac",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -808,11 +808,11 @@
"tinted-zed": { "tinted-zed": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1772909925, "lastModified": 1777463218,
"narHash": "sha256-jx/5+pgYR0noHa3hk2esin18VMbnPSvWPL5bBjfTIAU=", "narHash": "sha256-Bhkozqtq3BKLqWTlmKm8uAptfX4aRGI8QX3eEL54Vpc=",
"owner": "tinted-theming", "owner": "tinted-theming",
"repo": "base16-zed", "repo": "base16-zed",
"rev": "b4d3a1b3bcbd090937ef609a0a3b37237af974df", "rev": "5768d08ed2e7944a26a958868cdb073cb8856dae",
"type": "github" "type": "github"
}, },
"original": { "original": {

View File

@@ -76,7 +76,10 @@
nixpkgs.lib.nixosSystem { nixpkgs.lib.nixosSystem {
modules = [ modules = [
./hosts/${host} ./hosts/${host}
{ nixpkgs.hostPlatform = (myUtils.hostMeta ./hosts/${host}).system; } {
nixpkgs.hostPlatform = (myUtils.hostMeta ./hosts/${host}).system;
host.name = host;
}
]; ];
specialArgs = { specialArgs = {
inherit inherit

View File

@@ -47,7 +47,10 @@
printing.enable = true; printing.enable = true;
modeling.enable = true; modeling.enable = true;
}; };
ai-tools.opencode.enable = true; ai-tools = {
claude-code.enable = true;
opencode.enable = true;
};
browser.primary = "librewolf"; browser.primary = "librewolf";
cloud.hetzner.enable = true; cloud.hetzner.enable = true;
comms.signal.enable = true; comms.signal.enable = true;

View File

@@ -43,7 +43,10 @@
}; };
modules."3d".printing.enable = true; modules."3d".printing.enable = true;
ai-tools.opencode.enable = true; ai-tools = {
claude-code.enable = true;
opencode.enable = true;
};
browser.primary = "librewolf"; browser.primary = "librewolf";
cloud.hetzner.enable = true; cloud.hetzner.enable = true;
comms.signal.enable = true; comms.signal.enable = true;

View File

@@ -73,8 +73,11 @@
tirith.enable = true; tirith.enable = true;
opencode.enable = true; opencode.enable = true;
}; };
database.mssql.enable = true; database = {
database.postgresql.enable = true; mssql.enable = true;
postgresql.enable = true;
redis.enable = true;
};
git.github.enable = true; git.github.enable = true;
git.gitlab.enable = true; git.gitlab.enable = true;
secrets.vault.enable = true; secrets.vault.enable = true;

View File

@@ -0,0 +1,60 @@
{
lib,
config,
pkgs,
...
}:
let
cfg = config.ai-tools.claude-code;
rtk-version = "0.18.1";
in
{
options.ai-tools.claude-code.enable = lib.mkEnableOption "claude code with rtk and ccline";
config = lib.mkIf cfg.enable {
programs.claude-code.enable = true;
home.packages = with pkgs; [
(stdenv.mkDerivation {
name = "ccline";
src = fetchurl {
url = "https://github.com/Haleclipse/CCometixLine/releases/download/v1.0.8/ccline-linux-x64.tar.gz";
hash = "sha256-Joe3Dd6uSMGi66QT6xr2oY/Tz8rA5RuKa6ckBVJIzI0=";
};
unpackPhase = "tar xzf $src";
installPhase = ''
mkdir -p $out/bin
cp ccline $out/bin/
chmod +x $out/bin/ccline
'';
meta = {
description = "CCometixLine Linux x64 CLI (Claude Code statusline)";
homepage = "https://github.com/Haleclipse/CCometixLine";
license = lib.licenses.mit;
platforms = [ "x86_64-linux" ];
};
})
(stdenv.mkDerivation {
name = "rtk-${rtk-version}";
version = rtk-version;
src = fetchurl {
url = "https://github.com/rtk-ai/rtk/releases/download/v${rtk-version}/rtk-x86_64-unknown-linux-gnu.tar.gz";
hash = "sha256-XoTia5K8b00OzcKYCufwx8ApkAS31DxUCpGSU0jFs2Q=";
};
unpackPhase = "tar xzf $src";
installPhase = ''
mkdir -p $out/bin
cp rtk $out/bin/
chmod +x $out/bin/rtk
'';
meta = {
description = "RTK - AI coding tool enhancer";
homepage = "https://www.rtk-ai.app";
license = lib.licenses.mit;
platforms = [ "x86_64-linux" ];
};
})
mcp-nixos
];
};
}

View File

@@ -1,116 +1,8 @@
{ {
lib, imports = [
config, ./claude-code.nix
pkgs, ./opencode.nix
... ./skills.nix
}: ./tirith.nix
let
cfg = config.ai-tools;
rtk-version = "0.18.1";
in
{
options.ai-tools = {
claude-code.enable = lib.mkEnableOption "claude code with rtk and ccline";
tirith.enable = lib.mkEnableOption "tirith shell security guard";
opencode.enable = lib.mkEnableOption "opencode";
};
config = lib.mkMerge [
(lib.mkIf cfg.claude-code.enable {
home.packages = with pkgs; [
claude-code
(pkgs.stdenv.mkDerivation {
name = "ccline";
src = pkgs.fetchurl {
url = "https://github.com/Haleclipse/CCometixLine/releases/download/v1.0.8/ccline-linux-x64.tar.gz";
hash = "sha256-Joe3Dd6uSMGi66QT6xr2oY/Tz8rA5RuKa6ckBVJIzI0=";
};
unpackPhase = ''
tar xzf $src
'';
installPhase = ''
mkdir -p $out/bin
cp ccline $out/bin/
chmod +x $out/bin/ccline
'';
meta = with pkgs.lib; {
description = "CCometixLine Linux x64 CLI (Claude Code statusline)";
homepage = "https://github.com/Haleclipse/CCometixLine";
license = licenses.mit;
platforms = [ "x86_64-linux" ];
};
})
(pkgs.stdenv.mkDerivation {
name = "rtk-${rtk-version}";
version = rtk-version;
src = pkgs.fetchurl {
url = "https://github.com/rtk-ai/rtk/releases/download/v${rtk-version}/rtk-x86_64-unknown-linux-gnu.tar.gz";
hash = "sha256-XoTia5K8b00OzcKYCufwx8ApkAS31DxUCpGSU0jFs2Q=";
};
unpackPhase = ''
tar xzf $src
'';
installPhase = ''
mkdir -p $out/bin
cp rtk $out/bin/
chmod +x $out/bin/rtk
'';
meta = with pkgs.lib; {
description = "RTK - AI coding tool enhancer";
homepage = "https://www.rtk-ai.app";
license = licenses.mit;
platforms = [ "x86_64-linux" ];
};
})
mcp-nixos
];
})
(lib.mkIf cfg.tirith.enable {
home.packages = with pkgs; [
tirith
];
})
(lib.mkIf (cfg.tirith.enable && cfg.claude-code.enable) {
home.file.".claude/hooks/tirith-check.py" = {
source = ./tirith-check.py;
executable = true;
};
home.activation.tirith-claude-code = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
${pkgs.tirith}/bin/tirith setup claude-code --with-mcp --scope user --force 2>/dev/null || true
'';
})
(lib.mkIf cfg.opencode.enable {
home.packages = with pkgs; [
opencode
];
home.file.".config/opencode/opencode.json".text = builtins.toJSON {
"$schema" = "https://opencode.ai/config.json";
permission = {
external_directory = {
"/run/secrets/" = "deny";
"~/.config/sops/age/keys.txt" = "deny";
"~/.ssh/id_rsa" = "deny";
"~/.ssh/id_ed25519" = "deny";
"~/.ssh/id_ecdsa" = "deny";
"~/.ssh/id_dsa" = "deny";
"/etc/ssh/ssh_host_rsa_key" = "deny";
"/etc/ssh/ssh_host_ed25519_key" = "deny";
"/etc/ssh/ssh_host_ecdsa_key" = "deny";
"/etc/ssh/ssh_host_dsa_key" = "deny";
};
command = {
sops = "deny";
};
};
plugin = [ "@mohak34/opencode-notifier@latest" ];
};
})
]; ];
} }

View File

@@ -0,0 +1,40 @@
{
lib,
config,
pkgs,
...
}:
let
cfg = config.ai-tools.opencode;
in
{
options.ai-tools.opencode = {
enable = lib.mkEnableOption "opencode";
};
config = lib.mkIf cfg.enable {
home.packages = [ pkgs.opencode ];
home.file.".config/opencode/opencode.json".text = builtins.toJSON {
"$schema" = "https://opencode.ai/config.json";
permission = {
external_directory = {
"/run/secrets/" = "deny";
"~/.config/sops/age/keys.txt" = "deny";
"~/.ssh/id_rsa" = "deny";
"~/.ssh/id_ed25519" = "deny";
"~/.ssh/id_ecdsa" = "deny";
"~/.ssh/id_dsa" = "deny";
"/etc/ssh/ssh_host_rsa_key" = "deny";
"/etc/ssh/ssh_host_ed25519_key" = "deny";
"/etc/ssh/ssh_host_ecdsa_key" = "deny";
"/etc/ssh/ssh_host_dsa_key" = "deny";
};
command = {
sops = "deny";
};
};
plugin = [ "@mohak34/opencode-notifier@latest" ];
};
};
}

View File

@@ -0,0 +1,49 @@
{
lib,
config,
pkgs,
...
}:
let
cfg = config.ai-tools.claude-code;
skillType = lib.types.submodule {
options = {
owner = lib.mkOption { type = lib.types.str; };
repo = lib.mkOption { type = lib.types.str; };
rev = lib.mkOption { type = lib.types.str; };
hash = lib.mkOption { type = lib.types.str; };
skill = lib.mkOption { type = lib.types.str; };
};
};
fetchSkill =
skill:
let
src = pkgs.fetchFromGitHub {
inherit (skill)
owner
repo
rev
hash
;
};
in
{
name = ".claude/skills/${skill.skill}";
value = {
source = "${src}/${skill.skill}";
recursive = true;
};
};
in
{
options.ai-tools.claude-code.skills = lib.mkOption {
type = lib.types.listOf skillType;
default = [ ];
};
config = lib.mkIf cfg.enable {
home.file = builtins.listToAttrs (map fetchSkill cfg.skills);
};
}

View File

@@ -0,0 +1,30 @@
{
lib,
config,
pkgs,
...
}:
let
cfg = config.ai-tools.tirith;
in
{
options.ai-tools.tirith = {
enable = lib.mkEnableOption "tirith shell security guard";
};
config = lib.mkMerge [
(lib.mkIf cfg.enable {
home.packages = [ pkgs.tirith ];
})
(lib.mkIf (cfg.enable && config.ai-tools.claude-code.enable) {
home.file.".claude/hooks/tirith-check.py" = {
source = ./tirith-check.py;
executable = true;
};
home.activation.tirith-claude-code = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
${pkgs.tirith}/bin/tirith setup claude-code --with-mcp --scope user --force 2>/dev/null || true
'';
})
];
}

View File

@@ -9,14 +9,18 @@
options.database = { options.database = {
mssql.enable = lib.mkEnableOption "MSSQL"; mssql.enable = lib.mkEnableOption "MSSQL";
postgresql.enable = lib.mkEnableOption "PostgreSQL"; postgresql.enable = lib.mkEnableOption "PostgreSQL";
redis.enable = lib.mkEnableOption "Redis";
}; };
config = lib.mkMerge [ config = lib.mkMerge [
(lib.mkIf config.database.mssql.enable { (lib.mkIf config.database.mssql.enable {
home.packages = [ (config.nixgl.wrap pkgs.dbeaver-bin) ]; home.packages = with pkgs; [ (config.nixgl.wrap dbeaver-bin) ];
}) })
(lib.mkIf config.database.postgresql.enable { (lib.mkIf config.database.postgresql.enable {
home.packages = [ (config.nixgl.wrap pkgs.pgadmin4-desktopmode) ]; home.packages = with pkgs; [ (config.nixgl.wrap pgadmin4-desktopmode) ];
})
(lib.mkIf config.database.postgresql.enable {
home.packages = with pkgs; [ redis ];
}) })
]; ];
} }

View File

@@ -41,7 +41,7 @@ in
clock-show-weekday = true; clock-show-weekday = true;
color-scheme = "prefer-dark"; color-scheme = "prefer-dark";
enable-hot-corners = false; enable-hot-corners = false;
font-name = font; # font-name = font;
locate-pointer = true; locate-pointer = true;
monospace-font-name = font; monospace-font-name = font;
}; };

View File

@@ -51,9 +51,7 @@ in
../../modules/yubikey ../../modules/yubikey
]; ];
home-manager.users.${config.host.username} = import ../../home/hosts/andromache; home-manager.users.${config.host.username} = import ../../home/hosts/${config.host.name};
ssh.authorizedHosts = [ "astyanax" ];
secrets.nixSigningKey.enable = true; secrets.nixSigningKey.enable = true;

View File

@@ -1,7 +1,7 @@
{ {
host = { host = {
username = "h"; username = "h";
name = "andromache";
highRam = true; highRam = true;
admin = true;
}; };
} }

View File

@@ -47,9 +47,7 @@ in
../../modules/yubikey ../../modules/yubikey
]; ];
home-manager.users.${config.host.username} = import ../../home/hosts/astyanax; home-manager.users.${config.host.username} = import ../../home/hosts/${config.host.name};
ssh.authorizedHosts = [ "andromache" ];
secrets.nixSigningKey.enable = true; secrets.nixSigningKey.enable = true;

View File

@@ -1,7 +1,7 @@
{ {
host = { host = {
username = "h"; username = "h";
name = "astyanax";
highRam = true; highRam = true;
admin = true;
}; };
} }

View File

@@ -11,13 +11,6 @@
../../modules/ssh ../../modules/ssh
]; ];
ssh = {
authorizedHosts = [
"andromache"
"astyanax"
];
};
boot = { boot = {
kernelParams = [ kernelParams = [
"console=ttyS1,115200n8" "console=ttyS1,115200n8"

View File

@@ -1,6 +1,5 @@
{ {
host = { host = {
username = "h"; username = "h";
name = "eetion-02";
}; };
} }

View File

@@ -15,13 +15,6 @@
tailscale.enable = true; tailscale.enable = true;
ssh = {
authorizedHosts = [
"andromache"
"astyanax"
];
};
boot.loader = { boot.loader = {
grub.enable = false; grub.enable = false;
generic-extlinux-compatible.enable = true; generic-extlinux-compatible.enable = true;

View File

@@ -1,6 +1,5 @@
{ {
host = { host = {
username = "h"; username = "h";
name = "eetion";
}; };
} }

View File

@@ -18,13 +18,6 @@
]; ];
networking.hostName = config.host.name; networking.hostName = config.host.name;
ssh = {
authorizedHosts = [
"andromache"
"astyanax"
];
};
docker.enable = true; docker.enable = true;
fileSystems."/" = { fileSystems."/" = {

View File

@@ -1,6 +1,5 @@
{ {
host = { host = {
username = "username"; username = "username";
name = "hecuba";
}; };
} }

View File

@@ -1,6 +1,5 @@
{ {
host = { host = {
username = "h"; username = "h";
name = "vm";
}; };
} }

View File

@@ -21,11 +21,6 @@ in
name = "orange-pi"; name = "orange-pi";
}; };
ssh.authorizedHosts = [
"andromache"
"astyanax"
];
nix.settings.experimental-features = [ nix.settings.experimental-features = [
"nix-command" "nix-command"
"flakes" "flakes"

View File

@@ -21,11 +21,6 @@ in
name = "raspberry-pi"; name = "raspberry-pi";
}; };
ssh.authorizedHosts = [
"andromache"
"astyanax"
];
boot.kernelParams = [ boot.kernelParams = [
"console=ttyS1,115200n8" "console=ttyS1,115200n8"
]; ];

View File

@@ -6,6 +6,7 @@ let
in in
{ {
config = { config = {
nixpkgs.allowedUnfree = [ "claude-code" ];
secrets.groups.opencode = [ "api-key" ]; secrets.groups.opencode = [ "api-key" ];
sops.templates."opencode/auth.json" = { sops.templates."opencode/auth.json" = {

View File

@@ -24,5 +24,10 @@
type = lib.types.bool; type = lib.types.bool;
default = false; default = false;
}; };
admin = lib.mkOption {
type = lib.types.bool;
default = false;
};
}; };
} }

View File

@@ -0,0 +1,7 @@
{
services.logind.settings.Login = {
HandleLidSwitch = "suspend";
IdleAction = "suspend";
IdleActionSec = 1800;
};
}

View File

@@ -9,6 +9,8 @@ let
cfg = config.desktop; cfg = config.desktop;
in in
{ {
imports = [ ../logind.nix ];
options.desktop = { options.desktop = {
ly = { ly = {
enable = lib.mkOption { enable = lib.mkOption {
@@ -35,15 +37,23 @@ in
]; ];
}; };
# error:
# Failed assertions:
# - h profile: xdg.portal: since you installed Home Manager via its NixOS module and
# 'home-manager.useUserPackages' is enabled, you need to add
#
# environment.pathsToLink = [ `/share/applications` `/share/xdg-desktop-portal` ];
#
# to your NixOS configuration so that the portal definitions and DE
# provided configurations get linked.
environment.pathsToLink = [
"/share/applications"
"/share/xdg-desktop-portal"
];
services = { services = {
gnome.gnome-keyring.enable = false; gnome.gnome-keyring.enable = false;
dbus.enable = true; dbus.enable = true;
logind.settings.Login = {
HandleLidSwitch = "suspend";
IdleAction = "suspend";
IdleActionSec = 1800;
};
displayManager.ly = lib.mkIf cfg.ly.enable { displayManager.ly = lib.mkIf cfg.ly.enable {
enable = true; enable = true;
}; };

View File

@@ -1,7 +1,12 @@
{ lib, config, ... }: {
lib,
config,
...
}:
let let
inherit (config.host) username; inherit (config.host) username;
adminHosts = (import ../../utils { inherit lib; }).adminHosts ../../hosts;
in in
{ {
options.ssh = { options.ssh = {
@@ -19,6 +24,6 @@ in
keyFile = ../../hosts/${hostname}/ssh_user.pub; keyFile = ../../hosts/${hostname}/ssh_user.pub;
in in
lib.optionals (builtins.pathExists keyFile) (lib.splitString "\n" (builtins.readFile keyFile)) lib.optionals (builtins.pathExists keyFile) (lib.splitString "\n" (builtins.readFile keyFile))
) config.ssh.authorizedHosts ) ((builtins.filter (h: h != config.host.name) adminHosts) ++ config.ssh.authorizedHosts)
); );
} }

View File

@@ -1,12 +1,8 @@
{ lib }: { lib }:
let let
hosts = import ./hosts.nix; fs = import ./fs.nix { inherit lib; };
hosts = import ./hosts.nix { inherit lib; };
secrets = import ./secrets.nix { inherit lib; }; secrets = import ./secrets.nix { inherit lib; };
in in
{ fs // hosts // secrets
dirNames =
path: builtins.attrNames (lib.filterAttrs (_: type: type == "directory") (builtins.readDir path));
}
// hosts
// secrets

6
utils/fs.nix Normal file
View File

@@ -0,0 +1,6 @@
{ lib }:
{
dirNames =
path: builtins.attrNames (lib.filterAttrs (_: t: t == "directory") (builtins.readDir path));
}

View File

@@ -1,3 +1,8 @@
{ lib }:
let
fs = import ./fs.nix { inherit lib; };
in
{ {
hostMeta = hostMeta =
hostDir: hostDir:
@@ -5,4 +10,10 @@
import (hostDir + "/meta.nix") import (hostDir + "/meta.nix")
else else
throw "meta.nix required in ${hostDir}"; throw "meta.nix required in ${hostDir}";
adminHosts =
hostsPath:
builtins.filter (host: ((import (hostsPath + "/${host}/host.nix")).host.admin or false)) (
fs.dirNames hostsPath
);
} }