Compare commits

..
1 Commits
Author SHA1 Message Date
Alexander Heldt f7e18a0978 manatee: Add services homepage with auto-discovery
Add a homepage module that generates a static landing page served on
port 80 via nginx. Each service module registers itself via the shared
mod.homepage.services option, so enabling a module automatically adds
it to the page.
2026-02-28 21:46:44 +01:00
85 changed files with 857 additions and 2652 deletions
Generated
+102 -308
View File
@@ -43,11 +43,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1787400831, "lastModified": 1770895474,
"narHash": "sha256-H3MEkFDZf+UH+QrVgW8TdKrssPFltF8fBg/rh0J1zIc=", "narHash": "sha256-JBcrq1Y0uw87VZdYsByVbv+GBuT6ECaCNb9txLX9UuU=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "aquamarine", "repo": "aquamarine",
"rev": "7ce889cb78b97979b83a4648509fc3ef405c3286", "rev": "a494d50d32b5567956b558437ceaa58a380712f7",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -85,11 +85,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1781152676, "lastModified": 1769524058,
"narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=", "narHash": "sha256-zygdD6X1PcVNR2PsyK4ptzrVEiAdbMqLos7utrMDEWE=",
"owner": "nix-community", "owner": "nix-community",
"repo": "disko", "repo": "disko",
"rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1", "rev": "71a3fc97d80881e91710fe721f1158d3b96ae14d",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -106,11 +106,11 @@
"nixpkgs-stable": "nixpkgs-stable" "nixpkgs-stable": "nixpkgs-stable"
}, },
"locked": { "locked": {
"lastModified": 1787018211, "lastModified": 1771057865,
"narHash": "sha256-6l9VDWVP2ePuI/8zSXLY4+50BKJpd1IF1REYKsUoxls=", "narHash": "sha256-Suny75DfQS3Mqd8ihiDZNsRs4CfRC3GiQDMmaFPj2qM=",
"owner": "nix-community", "owner": "nix-community",
"repo": "emacs-overlay", "repo": "emacs-overlay",
"rev": "a65bcf36c4d8aa4c5ff51d571f2a2c2555681dad", "rev": "56690eb79372e49054b0c2b87780fe3f86be7616",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -169,57 +169,25 @@
"type": "github" "type": "github"
} }
}, },
"flake-utils_2": { "gitignore": {
"inputs": { "inputs": {
"systems": "systems_4" "nixpkgs": [
"hyprland",
"pre-commit-hooks",
"nixpkgs"
]
}, },
"locked": { "locked": {
"lastModified": 1731533236, "lastModified": 1709087332,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=",
"owner": "numtide", "owner": "hercules-ci",
"repo": "flake-utils", "repo": "gitignore.nix",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", "rev": "637db329424fd7e46cf4185293b9cc8c88c95394",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "numtide", "owner": "hercules-ci",
"repo": "flake-utils", "repo": "gitignore.nix",
"type": "github"
}
},
"flake-utils_3": {
"inputs": {
"systems": "systems_6"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"flake-utils_4": {
"inputs": {
"systems": "systems_7"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github" "type": "github"
} }
}, },
@@ -251,11 +219,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786999651, "lastModified": 1771037579,
"narHash": "sha256-MTGMFlLDTklsXhCp4r5GXB4VAVadPdalXLvUjd/K7h0=", "narHash": "sha256-NX5XuhGcsmk0oEII2PEtMRgvh2KaAv3/WWQsOpxAgR4=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "353742587cbaf079b3caee743115d037bc51fea6", "rev": "05e6dc0f6ed936f918cb6f0f21f1dad1e4c53150",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -280,11 +248,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464181, "lastModified": 1753964049,
"narHash": "sha256-2alOMkLjXANh7unkZnYnCF2K2rApZaOLMoQ3o+VX2CY=", "narHash": "sha256-lIqabfBY7z/OANxHoPeIrDJrFyYy9jAM4GQLzZ2feCM=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "hyprcursor", "repo": "hyprcursor",
"rev": "e4ed7c08123df5af460a0a70961380cbfb872f76", "rev": "44e91d467bdad8dcf8bbd2ac7cf49972540980a5",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -309,11 +277,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464367, "lastModified": 1770511807,
"narHash": "sha256-k58p4wbzIXWyRWrW84pP8tD+iaZSSYiiM+fr0Auk4oU=", "narHash": "sha256-suKmSbSk34uPOJDTg/GbPrKEJutzK08vj0VoTvAFBCA=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "hyprgraphics", "repo": "hyprgraphics",
"rev": "7c895c44e3ca6d28ed68ddd80ec02b02b925e7fc", "rev": "7c75487edd43a71b61adb01cae8326d277aab683",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -341,11 +309,11 @@
"xdph": "xdph" "xdph": "xdph"
}, },
"locked": { "locked": {
"lastModified": 1787612295, "lastModified": 1771026735,
"narHash": "sha256-K7sUeS1tKTSDu+aQK0ZwCxJCls+JzDj1qeTJRGk+CV8=", "narHash": "sha256-vIzZ1Pb1o9xOXwGTdr09vRwGFgD/II6ZnGpnCfl8zz8=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "Hyprland", "repo": "Hyprland",
"rev": "0bd11c7a04a63d2785abd53363f09d552175d67d", "rev": "e80f705d76d4dbe836e0f57aadea994a624ac63e",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -361,11 +329,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1782811467, "lastModified": 1770889987,
"narHash": "sha256-JP0D8r8o9+jnYk0/B5O722La+oZeC5iNQ3lonKFTmbQ=", "narHash": "sha256-JPbwE1Yg5t9zrMcOyDQwl1Pd8e0J1dtZf3kGnC7udwQ=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "contrib", "repo": "contrib",
"rev": "3dcbce715ae8b93107fa8632db15bf976862a573", "rev": "8fdd69edefed16c9ab395b433a1c3323d5633f30",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -407,11 +375,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464504, "lastModified": 1767023960,
"narHash": "sha256-7sHwM86KILQyHDHDuE2SDBlQ2jvZ0EW3hY7sW009/cg=", "narHash": "sha256-R2HgtVS1G3KSIKAQ77aOZ+Q0HituOmPgXW9nBNkpp3Q=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "hyprland-guiutils", "repo": "hyprland-guiutils",
"rev": "4c30cf3097ea963c0e250749ee0c59f8b08816d6", "rev": "c2e906261142f5dd1ee0bfc44abba23e2754c660",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -432,11 +400,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1772460177, "lastModified": 1765214753,
"narHash": "sha256-/6G/MsPvtn7bc4Y32pserBT/Z4SUUdBd4XYJpOEKVR4=", "narHash": "sha256-P9zdGXOzToJJgu5sVjv7oeOGPIIwrd9hAUAP3PsmBBs=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "hyprland-protocols", "repo": "hyprland-protocols",
"rev": "1cb6db5fd6bb8aee419f4457402fa18293ace917", "rev": "3f3860b869014c00e8b9e0528c7b4ddc335c21ab",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -461,11 +429,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464129, "lastModified": 1767983607,
"narHash": "sha256-339AkTlpMYSIvFuG0rnR+8Yg4/AZKeJalshJavlnKfg=", "narHash": "sha256-8C2co8NYfR4oMOUEsPROOJ9JHrv9/ktbJJ6X1WsTbXc=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "hyprlang", "repo": "hyprlang",
"rev": "9508458be316a0d70d37ebed1ab725ccd10411ff", "rev": "d4037379e6057246b408bbcf796cf3e9838af5b2",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -513,11 +481,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1785930473, "lastModified": 1764592794,
"narHash": "sha256-DitTu625BhEYpZjtjxtGpjrEJwPwW+X/+jJvhSZNSJM=", "narHash": "sha256-7CcO+wbTJ1L1NBQHierHzheQGPWwkIQug/w+fhTAVuU=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "hyprtoolkit", "repo": "hyprtoolkit",
"rev": "af515b69dfbe366dc7873aa1475cb2f4db3ebad7", "rev": "5cfe0743f0e608e1462972303778d8a0859ee63e",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -538,11 +506,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786903207, "lastModified": 1770139857,
"narHash": "sha256-QTwMqLLONRhv9iz6CVeuX6BqQNQCIqI8hL/cPYlR/24=", "narHash": "sha256-bCqxcXjavgz5KBJ/1CBLqnagMMf9JvU1m9HmYVASKoc=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "hyprutils", "repo": "hyprutils",
"rev": "6cf50415e06dc6bd9f1252f1b745eac6b4a1cc39", "rev": "9038eec033843c289b06b83557a381a2648d8fa5",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -563,11 +531,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464033, "lastModified": 1770501770,
"narHash": "sha256-QM8Qe4/L8lpdVN4bgwahmi+jyyc4fisseDMe4afcDxA=", "narHash": "sha256-NWRM6+YxTRv+bT9yvlhhJ2iLae1B1pNH3mAL5wi2rlQ=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "hyprwayland-scanner", "repo": "hyprwayland-scanner",
"rev": "62e62c1ca23da17612c6890d4ad2064f575643db", "rev": "0bd8b6cde9ec27d48aad9e5b4deefb3746909d40",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -592,11 +560,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464294, "lastModified": 1770203293,
"narHash": "sha256-ZQsZ2WvBdkboCIyh8LStDPdAIARmxzn0XMNxxoOhjPE=", "narHash": "sha256-PR/KER+yiHabFC/h1Wjb+9fR2Uy0lWM3Qld7jPVaWkk=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "hyprwire", "repo": "hyprwire",
"rev": "4ce7cd6b6128c1ac41caf23c58a30a26b327f9dd", "rev": "37bc90eed02b0c8b5a77a0b00867baf3005cfb98",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -605,27 +573,6 @@
"type": "github" "type": "github"
} }
}, },
"komga-bookmanager": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1772988002,
"narHash": "sha256-42Arpp+ShJorA9uR1nNlKuMoDx3y+cHg2BxQUW1fo7U=",
"ref": "main",
"rev": "bd5ae71978bb60eda28a010956825983dd931e2a",
"revCount": 18,
"type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/komga-bookmanager.git"
},
"original": {
"ref": "main",
"type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/komga-bookmanager.git"
}
},
"komga-comictracker": { "komga-comictracker": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
@@ -633,11 +580,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1773858923, "lastModified": 1771079752,
"narHash": "sha256-JOm+qe+loPxpjpTn2fN5QuqeGLDqYc1QevNeZZuEkdE=", "narHash": "sha256-4Pw8MhQUVWcTH3fg31sP19k+qgHDxqSKtSoDU/CYf/Y=",
"ref": "main", "ref": "main",
"rev": "2ab63ae85af1e2009e4bce10940e8db56827d942", "rev": "2b5cc59e3d4dba439a9a5f0d1fc2c30d9bdf45e1",
"revCount": 67, "revCount": 32,
"type": "git", "type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/komga-comictracker.git" "url": "ssh://gitea@git.ppp.pm:1122/alex/komga-comictracker.git"
}, },
@@ -647,7 +594,7 @@
"url": "ssh://gitea@git.ppp.pm:1122/alex/komga-comictracker.git" "url": "ssh://gitea@git.ppp.pm:1122/alex/komga-comictracker.git"
} }
}, },
"komga-reading-stats": { "naviterm": {
"inputs": { "inputs": {
"flake-utils": "flake-utils", "flake-utils": "flake-utils",
"nixpkgs": [ "nixpkgs": [
@@ -655,33 +602,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1782065297, "lastModified": 1770485744,
"narHash": "sha256-/pRul59iTUd3Oz8fJNEeB0A2qXfNCMai5LwYlpLTkvY=", "narHash": "sha256-ZJGHKtEWhpXyONjy6/popJz0uL2MXmknGr9Vr1B6BAk=",
"ref": "main",
"rev": "1975a872f6587813e9f3741bdab29d9dc1573bc3",
"revCount": 43,
"type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/komga-reading-stats.git"
},
"original": {
"ref": "main",
"type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/komga-reading-stats.git"
}
},
"naviterm": {
"inputs": {
"flake-utils": "flake-utils_2",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1785952180,
"narHash": "sha256-iDuEHW+ll+wdKEfbhFaQQ0vsE0/Nl+TS1osI947cv5w=",
"owner": "detoxify92", "owner": "detoxify92",
"repo": "naviterm", "repo": "naviterm",
"rev": "82ec8adc0a9dbb781ddae409bb19269936559f7f", "rev": "b311af7ae0ab095657264b5fe4a43b9118207584",
"type": "gitlab" "type": "gitlab"
}, },
"original": { "original": {
@@ -695,17 +620,16 @@
"nixpkgs": "nixpkgs" "nixpkgs": "nixpkgs"
}, },
"locked": { "locked": {
"lastModified": 1773920367, "lastModified": 1770930949,
"narHash": "sha256-ADGQjlsFzT9POglBkBJZcFqg3go4d+J3E4GS4WlxENY=", "narHash": "sha256-ulX/6yOI9fmiiDqNjn59oLsVkABRo0M2Wkr2w8Ric64=",
"owner": "viperML", "owner": "viperML",
"repo": "nh", "repo": "nh",
"rev": "b00a24b39944efd4ec7944f02e0bd9113d991767", "rev": "b37b9a6ca31741282873dd8e335f66aad54f6326",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "viperML", "owner": "viperML",
"repo": "nh", "repo": "nh",
"rev": "b00a24b39944efd4ec7944f02e0bd9113d991767",
"type": "github" "type": "github"
} }
}, },
@@ -730,14 +654,14 @@
"nixpkgs": [ "nixpkgs": [
"nixpkgs" "nixpkgs"
], ],
"systems": "systems_5" "systems": "systems_4"
}, },
"locked": { "locked": {
"lastModified": 1786782246, "lastModified": 1771059595,
"narHash": "sha256-D8uy48k++htZCZF13wZJ9jcxFmI6G7uId1pSj0wD7rw=", "narHash": "sha256-avvMQpGX/erjzPI10bN5uHDD08er5QC+pBypQisUNHs=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nix-jetbrains-plugins", "repo": "nix-jetbrains-plugins",
"rev": "35359b4f515f165bb2a11c5de793a282daa78c03", "rev": "fb4b27d169c7fbfc92c9dfec971e9c87506cb8f0",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -747,15 +671,12 @@
} }
}, },
"nixos-hardware": { "nixos-hardware": {
"inputs": {
"nixpkgs": "nixpkgs_2"
},
"locked": { "locked": {
"lastModified": 1786867632, "lastModified": 1770882871,
"narHash": "sha256-ez+ubZlA1RtdjCB18a6zJ9M4u8qoPDy08EcnsW5M3Xw=", "narHash": "sha256-nw5g+xl3veea+maxJ2/81tMEA/rPq9aF1H5XF35X+OE=",
"owner": "nixos", "owner": "nixos",
"repo": "nixos-hardware", "repo": "nixos-hardware",
"rev": "ff17823245ab9ff7bcae6acf950bd89cba82c38c", "rev": "af04cb78aa85b2a4d1c15fc7270347e0d0eda97b",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -767,11 +688,11 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1772822230, "lastModified": 1770770419,
"narHash": "sha256-yf3iYLGbGVlIthlQIk5/4/EQDZNNEmuqKZkQssMljuw=", "narHash": "sha256-iKZMkr6Cm9JzWlRYW/VPoL0A9jVKtZYiU4zSrVeetIs=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "71caefce12ba78d84fe618cf61644dce01cf3a96", "rev": "6c5e707c6b5339359a9a9e215c5e66d6d802fd7a",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -783,40 +704,27 @@
}, },
"nixpkgs-stable": { "nixpkgs-stable": {
"locked": { "locked": {
"lastModified": 1786943417, "lastModified": 1767313136,
"narHash": "sha256-b4qgjdFtlz5TAZ1Hi7DFJeqX3sjaDUnrwr9OO+O1rM0=", "narHash": "sha256-16KkgfdYqjaeRGBaYsNrhPRRENs0qzkQVUooNHtoy2w=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "0dd31db7e6dbf9ce05697c4545f6fe01accec994", "rev": "ac62194c3917d5f474c1a844b6fd6da2db95077d",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "NixOS", "owner": "NixOS",
"ref": "nixos-26.05", "ref": "nixos-25.05",
"repo": "nixpkgs", "repo": "nixpkgs",
"type": "github" "type": "github"
} }
}, },
"nixpkgs_2": { "nixpkgs_2": {
"locked": { "locked": {
"lastModified": 1767892417, "lastModified": 1771008912,
"narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=", "narHash": "sha256-gf2AmWVTs8lEq7z/3ZAsgnZDhWIckkb+ZnAo5RzSxJg=",
"rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba",
"type": "tarball",
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre924538.3497aa5c9457/nixexprs.tar.xz"
},
"original": {
"type": "tarball",
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
}
},
"nixpkgs_3": {
"locked": {
"lastModified": 1786862985,
"narHash": "sha256-FBJRXmbGXiSUDvYEbfLYRkckayyZ6SK1UEqhCrIZ2Cs=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "e5bdc4a41d4c072fe1e3787eaa0320a384741d44", "rev": "a82ccc39b39b621151d6732718e3e250109076fa",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -850,17 +758,18 @@
"pre-commit-hooks": { "pre-commit-hooks": {
"inputs": { "inputs": {
"flake-compat": "flake-compat", "flake-compat": "flake-compat",
"gitignore": "gitignore",
"nixpkgs": [ "nixpkgs": [
"hyprland", "hyprland",
"nixpkgs" "nixpkgs"
] ]
}, },
"locked": { "locked": {
"lastModified": 1784288435, "lastModified": 1770726378,
"narHash": "sha256-ReRHaLgr/uVqdD8afFSn+myXIfpHeOhP0yYe0TJqAA8=", "narHash": "sha256-kck+vIbGOaM/dHea7aTBxdFYpeUl/jHOy5W3eyRvVx8=",
"owner": "cachix", "owner": "cachix",
"repo": "git-hooks.nix", "repo": "git-hooks.nix",
"rev": "43b3c1ab9d40fb1dbb008f451988a91e375825e9", "rev": "5eaaedde414f6eb1aea8b8525c466dc37bba95ae",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -869,28 +778,6 @@
"type": "github" "type": "github"
} }
}, },
"puppy-tracker": {
"inputs": {
"flake-utils": "flake-utils_3",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1785677859,
"narHash": "sha256-ZXWSL0F1ZDzeLSXFGvRom89nOEq80gXghc+ky/qA/l8=",
"ref": "main",
"rev": "f9894abfc9cd9c2a5dacb9fe3609b58f5d407392",
"revCount": 69,
"type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/puppy-tracker.git"
},
"original": {
"ref": "main",
"type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/puppy-tracker.git"
}
},
"root": { "root": {
"inputs": { "inputs": {
"agenix": "agenix", "agenix": "agenix",
@@ -899,45 +786,18 @@
"home-manager": "home-manager_2", "home-manager": "home-manager_2",
"hyprland": "hyprland", "hyprland": "hyprland",
"hyprland-contrib": "hyprland-contrib", "hyprland-contrib": "hyprland-contrib",
"komga-bookmanager": "komga-bookmanager",
"komga-comictracker": "komga-comictracker", "komga-comictracker": "komga-comictracker",
"komga-reading-stats": "komga-reading-stats",
"naviterm": "naviterm", "naviterm": "naviterm",
"nh": "nh", "nh": "nh",
"nix-gc-env": "nix-gc-env", "nix-gc-env": "nix-gc-env",
"nix-jetbrains-plugins": "nix-jetbrains-plugins", "nix-jetbrains-plugins": "nix-jetbrains-plugins",
"nixos-hardware": "nixos-hardware", "nixos-hardware": "nixos-hardware",
"nixpkgs": "nixpkgs_3", "nixpkgs": "nixpkgs_2",
"pppdotpm-site": "pppdotpm-site", "pppdotpm-site": "pppdotpm-site",
"puppy-tracker": "puppy-tracker",
"solo-referee": "solo-referee",
"todo": "todo",
"whib-backend": "whib-backend", "whib-backend": "whib-backend",
"whib-frontend": "whib-frontend" "whib-frontend": "whib-frontend"
} }
}, },
"solo-referee": {
"inputs": {
"flake-utils": "flake-utils_4",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1785015267,
"narHash": "sha256-NHaaFMznPus9jABGXlSHo++bYcbQeBnxvYPt/CzBEHg=",
"ref": "main",
"rev": "42af5dc48d1e2466a6b09273c7c96dfe2ab13c0b",
"revCount": 10,
"type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/solo-referee.git"
},
"original": {
"ref": "main",
"type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/solo-referee.git"
}
},
"systems": { "systems": {
"locked": { "locked": {
"lastModified": 1681028828, "lastModified": 1681028828,
@@ -998,72 +858,6 @@
"type": "github" "type": "github"
} }
}, },
"systems_5": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"systems_6": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"systems_7": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"todo": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1787045443,
"narHash": "sha256-zgpME9KjeRyp2teHkuJUrOUIsWUd1QrCRxUy7GuS41w=",
"ref": "main",
"rev": "3bef06edde9fed897ce7f4c0c3c1b93945fd1e03",
"revCount": 28,
"type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/todo.git"
},
"original": {
"ref": "main",
"type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/todo.git"
}
},
"whib-backend": { "whib-backend": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
@@ -1071,11 +865,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1780482259, "lastModified": 1739029248,
"narHash": "sha256-buOczAkw78U+g7DYcB7nMabTGzQoN15HtVE3y0kIt3I=", "narHash": "sha256-ux/Udy0Mhs66P/EQQ8S+xIuXRm9UHEYwSy12IZtlbnA=",
"ref": "master", "ref": "master",
"rev": "b9ee418d14d6cb500506f9ef0cb9d54a8e78afa9", "rev": "222a8f6dde2e9270f6390b5e1e83c7ae1ea48290",
"revCount": 373, "revCount": 371,
"type": "git", "type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/whib.git" "url": "ssh://gitea@git.ppp.pm:1122/alex/whib.git"
}, },
@@ -1092,11 +886,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1780483645, "lastModified": 1761508816,
"narHash": "sha256-Nr0WTh72uBCSO5jCcvHPE+4dqAPn07HZ5U1lAE4/3II=", "narHash": "sha256-adV/lyxcmuopyuzZ49v46Yt0gft+ioEL4yl1S+vUbus=",
"ref": "master", "ref": "master",
"rev": "14f98eced1ccf1e62493ad65eb38502b38db5cba", "rev": "ab10bf50cb6b023a1b99f91c7e8d550231135eef",
"revCount": 224, "revCount": 223,
"type": "git", "type": "git",
"url": "ssh://gitea@git.ppp.pm:1122/alex/whib-react.git" "url": "ssh://gitea@git.ppp.pm:1122/alex/whib-react.git"
}, },
@@ -1134,11 +928,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786988229, "lastModified": 1761431178,
"narHash": "sha256-frEFLVRj8xXvBBDs44IRiqHo6R2PxsRpluygL7abjjI=", "narHash": "sha256-xzjC1CV3+wpUQKNF+GnadnkeGUCJX+vgaWIZsnz9tzI=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "xdg-desktop-portal-hyprland", "repo": "xdg-desktop-portal-hyprland",
"rev": "59d429bf45aed4e2209043c0c36565ad8e2859a5", "rev": "4b8801228ff958d028f588f0c2b911dbf32297f9",
"type": "github" "type": "github"
}, },
"original": { "original": {
+1 -31
View File
@@ -12,7 +12,7 @@
}; };
nh = { nh = {
url = "github:viperML/nh/b00a24b39944efd4ec7944f02e0bd9113d991767"; url = "github:viperML/nh";
}; };
nix-gc-env.url = "github:Julow/nix-gc-env"; nix-gc-env.url = "github:Julow/nix-gc-env";
@@ -74,36 +74,6 @@
# url = "path:/home/alex/code/own/komga-comictracker"; # url = "path:/home/alex/code/own/komga-comictracker";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
komga-bookmanager = {
url = "git+ssh://gitea@git.ppp.pm:1122/alex/komga-bookmanager.git?ref=main";
# url = "path:/home/alex/code/own/komga-bookmanager";
inputs.nixpkgs.follows = "nixpkgs";
};
komga-reading-stats = {
url = "git+ssh://gitea@git.ppp.pm:1122/alex/komga-reading-stats.git?ref=main";
# url = "path:/home/alex/code/own/komga-reading-stats";
inputs.nixpkgs.follows = "nixpkgs";
};
puppy-tracker = {
url = "git+ssh://gitea@git.ppp.pm:1122/alex/puppy-tracker.git?ref=main";
# url = "path:/home/alex/code/puppy-tracker";
inputs.nixpkgs.follows = "nixpkgs";
};
solo-referee = {
url = "git+ssh://gitea@git.ppp.pm:1122/alex/solo-referee.git?ref=main";
# url = "path:/home/alex/code/solo-referee";
inputs.nixpkgs.follows = "nixpkgs";
};
todo = {
url = "git+ssh://gitea@git.ppp.pm:1122/alex/todo.git?ref=main";
# url = "git+file:///home/alex/code/todo?ref=main";
inputs.nixpkgs.follows = "nixpkgs";
};
}; };
outputs = outputs =
+1
View File
@@ -2,6 +2,7 @@
{ {
imports = [ imports = [
../../config-manager/default.nix ../../config-manager/default.nix
../../shared-modules/syncthing.nix
./hardware-configuration.nix ./hardware-configuration.nix
./modules ./modules
]; ];
+2
View File
@@ -13,6 +13,8 @@ in
ssh.enable = true; ssh.enable = true;
git.enable = true; git.enable = true;
nginx.enable = true; nginx.enable = true;
syncthing.enable = true;
restic.enable = true;
}; };
}; };
} }
@@ -46,12 +46,6 @@ in
package = wrapped; package = wrapped;
# Pin the legacy profile location. The default changed to the XDG path
# (`$XDG_CONFIG_HOME/mozilla/firefox`) for stateVersion >= "26.05";
# keep the old `~/.mozilla/firefox` so the existing profile isn't
# stranded (migrating would require moving the profile dir by hand).
configPath = ".mozilla/firefox";
profiles = { profiles = {
alex = { alex = {
id = 0; id = 0;
@@ -0,0 +1,74 @@
{ lib, config, ... }:
let
enabled = config.mod.restic.enable;
in
{
options = {
mod.restic = {
enable = lib.mkEnableOption "Enable restic";
};
};
config = lib.mkIf enabled {
fileSystems."/home/alex/backup" = {
device = "/dev/disk/by-uuid/34601701-65e6-4b2c-ac4d-8bef3dfd743f";
fsType = "ext4";
options = [ "nofail" ];
};
services = {
restic.backups = {
"sync-to-external" = {
initialize = true;
passwordFile = config.age.secrets.restic-password.path;
paths = [ "/home/alex/sync" ];
repository = "/home/alex/backup/restic";
timerConfig = {
OnCalendar = "*-*-* 0/12:00:00"; # Every 12th hour, i.e. twice a day
Persistent = true;
};
pruneOpts = [
"--keep-daily 1"
"--keep-weekly 7"
"--keep-yearly 12"
];
};
"sync-to-cloud" = {
initialize = true;
passwordFile = config.age.secrets.restic-password.path;
environmentFile = config.age.secrets.restic-cloud-sync-key.path;
repositoryFile = config.age.secrets.restic-cloud-sync-repository.path;
paths = [ "/home/alex/sync" ];
exclude = [ "/home/alex/sync/reading-material" ];
timerConfig = {
OnCalendar = "*-*-* 0/12:00:00"; # Every 12th hour, i.e. twice a day
Persistent = true;
};
pruneOpts = [
"--keep-daily 1"
"--keep-weekly 7"
"--keep-yearly 12"
];
};
};
};
age = {
secrets = {
"restic-password".file = ../../../../secrets/backwards/restic-password.age;
"restic-cloud-sync-key".file = ../../../../secrets/backwards/restic-cloud-sync-key.age;
"restic-cloud-sync-repository".file =
../../../../secrets/backwards/restic-cloud-sync-repository.age;
};
};
};
}
+17 -18
View File
@@ -21,32 +21,31 @@ in
home-manager.users.alex = { home-manager.users.alex = {
programs.ssh = { programs.ssh = {
enable = true; enable = true;
enableDefaultConfig = false;
settings = { matchBlocks = {
"manatee" = { "manatee" = {
HostName = "manatee"; hostname = "manatee";
User = "alex"; user = "alex";
IdentityFile = "/home/alex/.ssh/alex.backwards-manatee"; identityFile = "/home/alex/.ssh/alex.backwards-manatee";
Port = 1122; port = 1122;
}; };
"git.ppp.pm" = { "git.ppp.pm" = {
HostName = "git.ppp.pm"; hostname = "git.ppp.pm";
IdentityFile = "/home/alex/.ssh/alex.backwards-git.ppp.pm"; identityFile = "/home/alex/.ssh/alex.backwards-git.ppp.pm";
}; };
"*" = { "*" = {
ForwardAgent = false; forwardAgent = false;
AddKeysToAgent = "no"; addKeysToAgent = "no";
Compression = false; compression = false;
ServerAliveInterval = 0; serverAliveInterval = 0;
ServerAliveCountMax = 3; serverAliveCountMax = 3;
HashKnownHosts = false; hashKnownHosts = false;
UserKnownHostsFile = "~/.ssh/known_hosts"; userKnownHostsFile = "~/.ssh/known_hosts";
ControlMaster = "no"; controlMaster = "no";
ControlPath = "~/.ssh/master-%r@%n:%p"; controlPath = "~/.ssh/master-%r@%n:%p";
ControlPersist = "no"; controlPersist = "no";
}; };
}; };
}; };
@@ -0,0 +1,109 @@
{ lib, config, ... }:
let
enabled = config.mod.syncthing.enable;
in
{
options = {
mod.syncthing = {
enable = lib.mkEnableOption "Enable syncthing module";
};
};
config = lib.mkIf enabled {
services.syncthing = {
enable = true;
openDefaultPorts = true;
cert = config.age.secrets.syncthing-cert.path;
key = config.age.secrets.syncthing-key.path;
user = "alex";
group = "users";
dataDir = "/home/alex/sync";
guiAddress = "0.0.0.0:8384";
settings = {
gui = {
user = "syncthing";
password = "$2a$12$J/h/JOUiW24ZXsLYLEl2kOZUS1LftxANi0OlZxLy8Dst3/jpBd0v2";
insecureSkipHostcheck = false;
};
devices = {
phone.id = config.lib.syncthing.phone;
pinwheel.id = config.lib.syncthing.pinwheel;
tablet.id = config.lib.syncthing.tablet;
};
folders = {
org = {
path = "/home/alex/sync/org";
devices = [
"phone"
"pinwheel"
];
versioning = {
type = "staggered";
params = {
maxage = "2592000"; # 30 days
};
};
};
personal = {
path = "/home/alex/sync/personal";
devices = [ "pinwheel" ];
versioning = {
type = "staggered";
params = {
maxAge = "2592000"; # 30 days
};
};
};
work = {
path = "/home/alex/sync/work";
devices = [ "pinwheel" ];
versioning = {
type = "staggered";
params = {
maxAge = "2592000"; # 30 days
};
};
};
books = {
path = "/home/alex/sync/reading-material/books";
devices = [ "pinwheel" ];
versioning = {
type = "staggered";
params = {
maxAge = "2592000"; # 30 days
};
};
};
"phone-gps" = {
path = "/home/alex/sync/phone-gps";
devices = [ "phone" ];
versioning = {
type = "staggered";
params = {
maxage = "2592000"; # 30 days
};
};
};
};
};
};
age = {
secrets = {
"syncthing-cert".file = ../../../../secrets/backwards/syncthing-cert.age;
"syncthing-key".file = ../../../../secrets/backwards/syncthing-key.age;
};
};
};
}
-5
View File
@@ -79,16 +79,11 @@
{ device = config.disko.devices.disk.root.device; } { device = config.disko.devices.disk.root.device; }
{ device = config.disko.devices.disk.disk1.device; } { device = config.disko.devices.disk.disk1.device; }
{ device = config.disko.devices.disk.disk2.device; } { device = config.disko.devices.disk.disk2.device; }
{ device = config.disko.devices.disk.disk3.device; }
{ device = config.disko.devices.disk.disk4.device; }
]; ];
}; };
services.zfs.autoScrub.enable = true; services.zfs.autoScrub.enable = true;
# Don't force-import the pool if it appears in use elsewhere; safer default in 26.11+.
boot.zfs.forceImportRoot = false;
networking.hostId = "0a9474e7"; # Required by ZFS networking.hostId = "0a9474e7"; # Required by ZFS
disko.devices = { disko.devices = {
disk = { disk = {
-2
View File
@@ -15,8 +15,6 @@
home.packages = [ home.packages = [
pkgs.streamrip pkgs.streamrip
pkgs.claude-code
pkgs.wl-clipboard
]; ];
home.stateVersion = "24.11"; home.stateVersion = "24.11";
@@ -10,13 +10,11 @@ in
}; };
config = lib.mkIf enabled { config = lib.mkIf enabled {
mod.homepage.services = [ mod.homepage.services = [{
{
name = "Audiobookshelf"; name = "Audiobookshelf";
port = 8000; port = 8000;
description = "Audiobooks & podcasts"; description = "Audiobooks & podcasts";
} }];
];
users.users.audiobookshelf = { users.users.audiobookshelf = {
isSystemUser = true; isSystemUser = true;
@@ -0,0 +1,40 @@
{ lib, config, ... }:
let
enabled = config.mod.calibre-web.enable;
in
{
options = {
mod.calibre-web = {
enable = lib.mkEnableOption "add calibre-web module";
};
};
config = lib.mkIf enabled {
mod.homepage.services = [{
name = "Calibre-Web";
port = 8083;
description = "E-book library";
}];
services = {
calibre-web = {
enable = true;
user = "storage";
group = "storage";
listen = {
ip = "0.0.0.0";
port = 8083;
};
dataDir = "/mnt/media/public/books";
options = {
calibreLibrary = "/mnt/media/public/books";
enableBookUploading = true;
};
};
};
};
}
-52
View File
@@ -20,58 +20,6 @@
"--http-timeout=60" "--http-timeout=60"
]; ];
}; };
"komga.ppp.pm" = {
dnsProvider = "hetzner";
environmentFile = config.age.secrets.hetzner-dns.path;
group = "nginx";
extraLegoFlags = [
"--dns.resolvers=1.1.1.1:53,8.8.8.8:53"
"--dns.propagation-wait=60s"
"--dns-timeout=60"
"--http-timeout=60"
];
};
"romm.ppp.pm" = {
dnsProvider = "hetzner";
environmentFile = config.age.secrets.hetzner-dns.path;
group = "nginx";
extraLegoFlags = [
"--dns.resolvers=1.1.1.1:53,8.8.8.8:53"
"--dns.propagation-wait=60s"
"--dns-timeout=60"
"--http-timeout=60"
];
};
"puppy.ppp.pm" = {
dnsProvider = "hetzner";
environmentFile = config.age.secrets.hetzner-dns.path;
group = "nginx";
extraLegoFlags = [
"--dns.resolvers=1.1.1.1:53,8.8.8.8:53"
"--dns.propagation-wait=60s"
"--dns-timeout=60"
"--http-timeout=60"
];
};
"todo.ppp.pm" = {
dnsProvider = "hetzner";
environmentFile = config.age.secrets.hetzner-dns.path;
group = "nginx";
extraLegoFlags = [
"--dns.resolvers=1.1.1.1:53,8.8.8.8:53"
"--dns.propagation-wait=60s"
"--dns-timeout=60"
"--http-timeout=60"
];
};
}; };
}; };
+2 -8
View File
@@ -12,23 +12,17 @@ in
ssh.enable = true; ssh.enable = true;
git.enable = true; git.enable = true;
tmux.enable = true;
nginx.enable = true; nginx.enable = true;
syncthing.enable = true; syncthing.enable = true;
restic.enable = true;
transmission.enable = true; transmission.enable = true;
calibre-web.enable = true;
audiobookshelf.enable = true; audiobookshelf.enable = true;
jellyfin.enable = true; jellyfin.enable = true;
immich.enable = false; immich.enable = true;
navidrome.enable = true; navidrome.enable = true;
komga.enable = true; komga.enable = true;
romm.enable = true;
homepage.enable = true; homepage.enable = true;
disk-smart.enable = true;
puppy-tracker.enable = true;
solo-referee.enable = true;
todo.enable = true;
}; };
}; };
} }
@@ -1,159 +0,0 @@
{
pkgs,
lib,
config,
...
}:
let
enabled = config.mod.disk-smart.enable;
disks = [
{ path = "/dev/disk/by-id/ata-ST8000VN004-3CP101_WWZ8QCG4"; name = "seagate_8tb_1"; label = "Seagate 8TB #1"; }
{ path = "/dev/disk/by-id/ata-ST8000VN004-3CP101_WWZ8QDJ5"; name = "seagate_8tb_2"; label = "Seagate 8TB #2"; }
{ path = "/dev/disk/by-id/ata-TOSHIBA_MG10ACA20TE_85K2A0UCF4MJ"; name = "toshiba_20tb_1"; label = "Toshiba 20TB #1"; }
{ path = "/dev/disk/by-id/ata-TOSHIBA_MG10ACA20TE_85K2A0V6F4MJ"; name = "toshiba_20tb_2"; label = "Toshiba 20TB #2"; }
];
outputDir = "/var/lib/disk-smart";
collectScript = pkgs.writeShellScript "disk-smart-collect" ''
set -euo pipefail
export PATH="${lib.makeBinPath [ pkgs.smartmontools pkgs.jq pkgs.coreutils ]}"
mkdir -p ${outputDir}
result="{"
${lib.concatMapStringsSep "\n" (disk: ''
raw=$(smartctl -j -A -H ${disk.path} 2>/dev/null || true)
temp=$(echo "$raw" | jq -r '.temperature.current // empty')
power_on=$(echo "$raw" | jq -r '.power_on_time.hours // empty')
smart_status=$(echo "$raw" | jq -r '.smart_status.passed // empty')
reallocated=$(echo "$raw" | jq -r '[.ata_smart_attributes.table[] | select(.name == "Reallocated_Sector_Ct")][0].raw.value // empty')
pending=$(echo "$raw" | jq -r '[.ata_smart_attributes.table[] | select(.name == "Current_Pending_Sector")][0].raw.value // empty')
result="$result\"${disk.name}\":{\"temperature\":$temp,\"power_on_hours\":$power_on,\"smart_passed\":$smart_status,\"reallocated_sectors\":$reallocated,\"pending_sectors\":$pending},"
'') disks}
# Remove trailing comma, close object
result="''${result%,}}"
echo "$result" | jq . > ${outputDir}/smart.json.tmp
mv ${outputDir}/smart.json.tmp ${outputDir}/smart.json
'';
indent = prefix: s:
lib.concatMapStringsSep "\n"
(line: if line == "" then line else prefix + line)
(lib.splitString "\n" s);
mkSensor = disk: ''
- name: "${disk.label} Temperature"
value_template: "{{ value_json.${disk.name}.temperature }}"
unit_of_measurement: "°C"
device_class: temperature
state_class: measurement
- name: "${disk.label} Power On Hours"
value_template: "{{ value_json.${disk.name}.power_on_hours }}"
unit_of_measurement: "h"
state_class: total_increasing
- name: "${disk.label} SMART Passed"
value_template: "{{ value_json.${disk.name}.smart_passed }}"
- name: "${disk.label} Reallocated Sectors"
value_template: "{{ value_json.${disk.name}.reallocated_sectors }}"
state_class: measurement
- name: "${disk.label} Pending Sectors"
value_template: "{{ value_json.${disk.name}.pending_sectors }}"
state_class: measurement
'';
sensorYaml = indent " " (lib.concatMapStrings mkSensor disks);
sectorEntities = lib.concatMap (disk: [
"sensor.${disk.name}_reallocated_sectors"
"sensor.${disk.name}_pending_sectors"
]) disks;
sectorEntitiesYaml = lib.concatMapStringsSep "\n"
(id: " - ${id}") sectorEntities;
smartPassedEntities = map (disk: "sensor.${disk.name}_smart_passed") disks;
smartPassedEntitiesYaml = lib.concatMapStringsSep "\n"
(id: " - ${id}") smartPassedEntities;
in
{
options = {
mod.disk-smart = {
enable = lib.mkEnableOption "Enable disk SMART monitoring module";
};
};
config = lib.mkIf enabled {
mod.home-assistant.extraConfig = ''
rest:
- resource: http://127.0.0.1:9633/smart.json
scan_interval: 60
sensor:
${sensorYaml}
automation disk_smart:
- alias: "Disk sector count increased"
trigger:
- platform: state
entity_id:
${sectorEntitiesYaml}
condition:
- condition: template
value_template: "{{ trigger.from_state.state | int(-1) >= 0 and trigger.to_state.state | int(0) > trigger.from_state.state | int(0) }}"
action:
- service: notify.mobile_app_pixel_9_pro
data:
title: "Disk SMART warning"
message: "{{ trigger.to_state.attributes.friendly_name }} increased from {{ trigger.from_state.state }} to {{ trigger.to_state.state }}"
- alias: "Disk SMART check failed"
trigger:
- platform: state
entity_id:
${smartPassedEntitiesYaml}
condition:
- condition: template
value_template: "{{ trigger.to_state.state | lower == 'false' }}"
action:
- service: notify.mobile_app_pixel_9_pro
data:
title: "Disk SMART FAILURE"
message: "{{ trigger.to_state.attributes.friendly_name }} reports SMART failure drive is likely failing"
'';
systemd.services.disk-smart-collect = {
description = "Collect disk SMART data";
serviceConfig = {
Type = "oneshot";
ExecStart = collectScript;
};
};
systemd.timers.disk-smart-collect = {
description = "Periodically collect disk SMART data";
wantedBy = [ "timers.target" ];
timerConfig = {
OnBootSec = "1min";
OnUnitActiveSec = "1min";
};
};
services.nginx.virtualHosts."127.0.0.1" = {
listen = [
{ addr = "127.0.0.1"; port = 9633; }
];
locations."= /smart.json" = {
alias = "${outputDir}/smart.json";
extraConfig = ''
default_type application/json;
'';
};
};
};
}
@@ -6,42 +6,8 @@
}: }:
let let
nginxEnabled = config.mod.nginx.enable; nginxEnabled = config.mod.nginx.enable;
cfg = config.mod.home-assistant;
configFile = pkgs.writeText "ha-configuration.yaml" '' script = pkgs.writeShellScript "bt-reset" ''
# Loads default set of integrations. Do not remove.
default_config:
http:
use_x_forwarded_for: true
trusted_proxies:
- 127.0.0.1
# Load frontend themes from the themes folder
frontend:
themes: !include_dir_merge_named themes
automation: !include automations.yaml
script: !include scripts.yaml
scene: !include scenes.yaml
recorder:
purge_keep_days: 365
alert:
fridge_door:
name: Fridge is open
done_message: Fride is closed
entity_id: binary_sensor.kyldorr
state: "on"
repeat: 2
skip_first: true
notifiers:
- mobile_app_pixel_9_pro
${cfg.extraConfig}'';
btResetScript = pkgs.writeShellScript "bt-reset" ''
set -euo pipefail set -euo pipefail
export PATH="${ export PATH="${
lib.makeBinPath [ lib.makeBinPath [
@@ -96,37 +62,8 @@ ${cfg.extraConfig}'';
''; '';
in in
{ {
options = {
mod.home-assistant = {
extraConfig = lib.mkOption {
type = lib.types.lines;
default = "";
description = "Extra YAML to append to Home Assistant's configuration.yaml";
};
};
};
config = {
mod.homepage.services = [
{
name = "Home Assistant";
port = 8123;
description = "Home automation";
}
];
hardware.bluetooth.enable = true; hardware.bluetooth.enable = true;
# Give up and enter a `failed` state (visible in `systemctl --failed`) if the
# container restarts more than 5 times in 5 minutes, instead of crash-looping
# forever. The window is deliberately long: a slow crash-loop (~5s per attempt)
# stays under systemd's default 5-starts-per-10s limit and would otherwise
# retry indefinitely.
systemd.services.podman-homeassistant = {
startLimitIntervalSec = 300;
startLimitBurst = 5;
};
virtualisation.oci-containers = { virtualisation.oci-containers = {
backend = "podman"; backend = "podman";
@@ -135,7 +72,6 @@ in
volumes = [ volumes = [
"/home/alex/.config/home-assistant:/config" "/home/alex/.config/home-assistant:/config"
"${configFile}:/config/configuration.yaml:ro"
# Pass in bluetooth # Pass in bluetooth
"/run/dbus:/run/dbus:ro" "/run/dbus:/run/dbus:ro"
]; ];
@@ -196,7 +132,7 @@ in
serviceConfig = { serviceConfig = {
Type = "oneshot"; Type = "oneshot";
ExecStart = btResetScript; ExecStart = script;
Restart = "on-failure"; Restart = "on-failure";
RestartSec = "10s"; RestartSec = "10s";
@@ -218,13 +154,13 @@ in
user = { user = {
timers = { timers = {
"update-hetzner-dns" = { "update-hetzner-ha-dns" = {
unitConfig = { unitConfig = {
Description = "updates Hetzner DNS records"; Description = "updates Hetzner DNS for home-assistant";
}; };
timerConfig = { timerConfig = {
Unit = "update-hetzner-dns.service"; Unit = "update-hetzner-ha-dns.service";
OnCalendar = "*-*-* *:00/30:00"; OnCalendar = "*-*-* *:00/30:00";
Persistent = true; Persistent = true;
}; };
@@ -234,9 +170,9 @@ in
}; };
services = { services = {
"update-hetzner-dns" = { "update-hetzner-ha-dns" = {
unitConfig = { unitConfig = {
Description = "updates Hetzner DNS records"; Description = "updates Hetzner DNS for home-assistant";
}; };
serviceConfig = { serviceConfig = {
@@ -246,28 +182,26 @@ in
path = [ path = [
pkgs.curl pkgs.curl
pkgs.coreutils pkgs.coreutils # For `cat`
pkgs.jq pkgs.jq
]; ];
script = '' script = ''
SUBDOMAINS="ha komga romm puppy todo" LAST_IP_FILE="/tmp/hetzner-dns-ha-ip"
INTERFACE="enp3s0" INTERFACE="enp3s0"
CURRENT_IP=$(curl -s --fail --interface "$INTERFACE" ifconfig.me) CURRENT_IP=$(curl -s --fail --interface "$INTERFACE" ifconfig.me)
for SUBDOMAIN in $SUBDOMAINS; do
LAST_IP_FILE="/tmp/hetzner-dns-''${SUBDOMAIN}-ip"
LAST_IP="" LAST_IP=""
if [[ -f "$LAST_IP_FILE" ]]; then if [[ -f "$LAST_IP_FILE" ]]; then
LAST_IP=$(cat "$LAST_IP_FILE") LAST_IP=$(cat "$LAST_IP_FILE")
fi fi
if [[ "$CURRENT_IP" == "$LAST_IP" ]]; then if [[ "$CURRENT_IP" == "$LAST_IP" ]]; then
echo "$SUBDOMAIN: IP unchanged, NOOP update." echo "IP unchanged, NOOP update."
exit 0
else else
echo "$SUBDOMAIN: Updating IP" echo "Updating IP"
JSON_BODY=$(jq -n --arg ip "$CURRENT_IP" '{records: [{value: $ip}]}') JSON_BODY=$(jq -n --arg ip "$CURRENT_IP" '{records: [{value: $ip}]}')
@@ -277,10 +211,9 @@ in
-H "Authorization: Bearer $HETZNER_API_TOKEN" \ -H "Authorization: Bearer $HETZNER_API_TOKEN" \
-H "Content-Type: application/json" \ -H "Content-Type: application/json" \
-d "$JSON_BODY" \ -d "$JSON_BODY" \
"https://api.hetzner.cloud/v1/zones/ppp.pm/rrsets/''${SUBDOMAIN}/A/actions/set_records" \ "https://api.hetzner.cloud/v1/zones/ppp.pm/rrsets/ha/A/actions/set_records" \
&& echo $CURRENT_IP > $LAST_IP_FILE && echo $CURRENT_IP > $LAST_IP_FILE
fi fi
done
''; '';
}; };
}; };
@@ -296,5 +229,4 @@ in
}; };
}; };
}; };
};
} }
+6 -18
View File
@@ -9,13 +9,8 @@ let
nginxEnabled = config.mod.nginx.enable; nginxEnabled = config.mod.nginx.enable;
services = config.mod.homepage.services; services = config.mod.homepage.services;
serviceToCard = serviceToCard = svc: ''
svc: <a class="card" href="http://manatee:${toString svc.port}">
let
href = if svc.url != null then svc.url else "http://manatee:${toString svc.port}";
in
''
<a class="card" href="${href}">
<div class="name">${svc.name}</div> <div class="name">${svc.name}</div>
<div class="desc">${svc.description}</div> <div class="desc">${svc.description}</div>
<div class="port">:${toString svc.port}</div> <div class="port">:${toString svc.port}</div>
@@ -82,20 +77,13 @@ in
mod.homepage = { mod.homepage = {
enable = lib.mkEnableOption "Enable homepage module"; enable = lib.mkEnableOption "Enable homepage module";
services = lib.mkOption { services = lib.mkOption {
type = lib.types.listOf ( type = lib.types.listOf (lib.types.submodule {
lib.types.submodule {
options = { options = {
name = lib.mkOption { type = lib.types.str; }; name = lib.mkOption { type = lib.types.str; };
port = lib.mkOption { type = lib.types.port; }; port = lib.mkOption { type = lib.types.port; };
description = lib.mkOption { type = lib.types.str; }; description = lib.mkOption { type = lib.types.str; };
url = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = "Link target for the card; defaults to http://manatee:<port>.";
}; };
}; });
}
);
default = [ ]; default = [ ];
description = "Services to display on the homepage"; description = "Services to display on the homepage";
}; };
@@ -107,7 +95,7 @@ in
listen = [ listen = [
{ {
addr = "0.0.0.0"; addr = "0.0.0.0";
port = 9999; port = 80;
} }
]; ];
root = page; root = page;
@@ -116,6 +104,6 @@ in
}; };
}; };
networking.firewall.allowedTCPPorts = [ 9999 ]; networking.firewall.allowedTCPPorts = [ 80 ];
}; };
} }
+2 -4
View File
@@ -10,13 +10,11 @@ in
}; };
config = lib.mkIf enabled { config = lib.mkIf enabled {
mod.homepage.services = [ mod.homepage.services = [{
{
name = "Immich"; name = "Immich";
port = 2283; port = 2283;
description = "Photo library"; description = "Photo library";
} }];
];
users.users.immich = { users.users.immich = {
isSystemUser = true; isSystemUser = true;
+2 -4
View File
@@ -47,13 +47,11 @@ in
}; };
}; };
mod.homepage.services = [ mod.homepage.services = [{
{
name = "Jellyfin"; name = "Jellyfin";
port = 8096; port = 8096;
description = "Media streaming"; description = "Media streaming";
} }];
];
networking = { networking = {
firewall.allowedTCPPorts = [ 8096 ]; firewall.allowedTCPPorts = [ 8096 ];
+2 -66
View File
@@ -16,11 +16,7 @@ in
}; };
}; };
imports = [ imports = [ inputs.komga-comictracker.nixosModules.default ];
inputs.komga-comictracker.nixosModules.default
inputs.komga-bookmanager.nixosModules.default
inputs.komga-reading-stats.nixosModules.default
];
config = lib.mkIf enabled { config = lib.mkIf enabled {
mod.homepage.services = [ mod.homepage.services = [
@@ -34,16 +30,6 @@ in
port = 8888; port = 8888;
description = "Comic reader"; description = "Comic reader";
} }
{
name = "Komga Book Manager";
port = 8686;
description = "Book manager";
}
{
name = "Komga Reading Stats";
port = 8787;
description = "Reading stats";
}
]; ];
users.users.komga = { users.users.komga = {
@@ -61,7 +47,6 @@ in
server.port = 8002; server.port = 8002;
komga."cors.allowed-origins" = [ komga."cors.allowed-origins" = [
"http://manatee:8888" "http://manatee:8888"
"https://komga.ppp.pm"
]; ];
}; };
@@ -83,71 +68,22 @@ in
tryFiles = "$uri $uri/ /komga-reader.html"; tryFiles = "$uri $uri/ /komga-reader.html";
}; };
}; };
virtualHosts."komga.ppp.pm" = {
forceSSL = true;
useACMEHost = "komga.ppp.pm";
locations."/" = {
proxyPass = "http://127.0.0.1:8002";
proxyWebsockets = true;
};
};
}; };
networking.firewall.allowedTCPPorts = [ 8888 ]; networking.firewall.allowedTCPPorts = [ 8888 ];
programs.comictracker = { programs.comictracker = {
enable = true; enable = true;
komgaUrl = "http://127.0.0.1:8002"; komgaUrl = "http://manatee:8002";
komgaLibraryId = "0NVZH5AK3RPE1";
secretsFile = config.age.secrets.komga-comicbooktracker-credentials.path; secretsFile = config.age.secrets.komga-comicbooktracker-credentials.path;
}; };
services.komga-book-manager = {
enable = true;
port = 8686;
group = "storage";
komgaUrl = "http://127.0.0.1:8002";
credentialsFile = config.age.secrets.komga-bookmanager-credentials.path;
libraryRoot = "/mnt/media/public/books";
libraryId = "0PNE1NEPY6995";
};
services.komga-reading-stats = {
enable = true;
host = "0.0.0.0";
port = 8787;
origin = "http://manatee:8787";
anthropicApiKeyFile = config.age.secrets.komga-reading-stats-claude-api-key.path;
claudeModel = "claude-sonnet-4-6";
komga = {
url = "http://127.0.0.1:8002";
apiKeyFile = config.age.secrets.komga-reading-stats-komga-api-key.path;
};
};
age.secrets = { age.secrets = {
"komga-comicbooktracker-credentials" = { "komga-comicbooktracker-credentials" = {
file = ../../../../secrets/manatee/komga-comicbooktracker-credentials.age; file = ../../../../secrets/manatee/komga-comicbooktracker-credentials.age;
owner = "alex"; owner = "alex";
group = "users"; group = "users";
}; };
"komga-bookmanager-credentials" = {
file = ../../../../secrets/manatee/komga-bookmanager-credentials.age;
owner = "alex";
group = "users";
};
"komga-reading-stats-claude-api-key" = {
file = ../../../../secrets/manatee/komga-reading-stats-claude-api-key.age;
};
"komga-reading-stats-komga-api-key" = {
file = ../../../../secrets/manatee/komga-reading-stats-komga-api-key.age;
};
}; };
}; };
} }
@@ -834,7 +834,6 @@
let fitMode = 'width'; let fitMode = 'width';
let naturalW = 0, naturalH = 0; let naturalW = 0, naturalH = 0;
let pageMode = 'single'; // 'single' or 'double' let pageMode = 'single'; // 'single' or 'double'
let isPdf = false; // current book is a PDF (rendered client-side via pdf.js)
const el = id => document.getElementById(id); const el = id => document.getElementById(id);
const $loginScreen = el('login-screen'); const $loginScreen = el('login-screen');
@@ -884,56 +883,6 @@
img.src = url; img.src = url;
} }
// ══════════════════════════════════════════════
// PDF SUPPORT (pdf.js, lazy-loaded)
//
// Komga serves PDF pages as raw application/pdf (one single-page
// PDF per /pages/{n} request), which an <img> can't decode. For
// PDF books we fetch that mini-PDF and rasterize it to a canvas
// with pdf.js, then feed it through the same zoom/pan/double-page
// machinery as image pages.
// ══════════════════════════════════════════════
const PDFJS_VERSION = '3.11.174';
let pdfjsReady = null;
function ensurePdfjs() {
if (window.pdfjsLib) return Promise.resolve();
if (pdfjsReady) return pdfjsReady;
pdfjsReady = new Promise((resolve, reject) => {
const s = document.createElement('script');
s.src = `https://cdnjs.cloudflare.com/ajax/libs/pdf.js/${PDFJS_VERSION}/pdf.min.js`;
s.onload = () => {
window.pdfjsLib.GlobalWorkerOptions.workerSrc =
`https://cdnjs.cloudflare.com/ajax/libs/pdf.js/${PDFJS_VERSION}/pdf.worker.min.js`;
resolve();
};
s.onerror = () => { pdfjsReady = null; reject(new Error('pdf.js failed to load')); };
document.head.appendChild(s);
});
return pdfjsReady;
}
// Fetch page `pageNum` (a single-page PDF) and render it to a fresh
// offscreen canvas at a resolution that stays crisp when zoomed.
async function renderPdfPage(pageNum) {
const url = serverUrl.replace(/\/$/, '') + `/api/v1/books/${currentBook.id}/pages/${pageNum}`;
const buf = await fetch(url, { headers: { 'Authorization': authHeader } }).then(r => r.arrayBuffer());
const doc = await window.pdfjsLib.getDocument({ data: buf }).promise;
try {
const page = await doc.getPage(1);
const base = page.getViewport({ scale: 1 });
const scale = Math.min(4, Math.max(1, 2000 / base.width));
const viewport = page.getViewport({ scale });
const canvas = document.createElement('canvas');
canvas.width = Math.ceil(viewport.width);
canvas.height = Math.ceil(viewport.height);
await page.render({ canvasContext: canvas.getContext('2d'), viewport }).promise;
return canvas;
} finally {
doc.destroy();
}
}
// ══════════════════════════════════════════════ // ══════════════════════════════════════════════
// LOGIN // LOGIN
// ══════════════════════════════════════════════ // ══════════════════════════════════════════════
@@ -1190,7 +1139,6 @@
async function openBook(book) { async function openBook(book) {
currentBook = book; currentBook = book;
currentPage = 1; currentPage = 1;
isPdf = book.media?.mediaType === 'application/pdf';
document.querySelectorAll('.list-item').forEach(e => e.classList.remove('active')); document.querySelectorAll('.list-item').forEach(e => e.classList.remove('active'));
try { try {
@@ -1202,16 +1150,6 @@
if (bd.readProgress && !bd.readProgress.completed) currentPage = bd.readProgress.page || 1; if (bd.readProgress && !bd.readProgress.completed) currentPage = bd.readProgress.page || 1;
} catch(e) {} } catch(e) {}
if (isPdf) {
try {
await ensurePdfjs();
} catch(e) {
console.error(e);
$readerPlaceholder.querySelector('p').textContent = 'Failed to load the PDF renderer (needs network for pdf.js).';
return;
}
}
$readerPlaceholder.style.display = 'none'; $readerPlaceholder.style.display = 'none';
$imageContainer.style.display = 'block'; $imageContainer.style.display = 'block';
$readerControls.style.display = 'flex'; $readerControls.style.display = 'flex';
@@ -1252,8 +1190,6 @@
currentPage = pageNum; currentPage = pageNum;
$loadingOverlay.style.display = 'flex'; $loadingOverlay.style.display = 'flex';
if (isPdf) { loadPdfPage(pageNum); return; }
if (pageMode === 'double') { if (pageMode === 'double') {
const leftPage = currentPage; const leftPage = currentPage;
const rightPage = currentPage + 1 <= totalPages ? currentPage + 1 : null; const rightPage = currentPage + 1 <= totalPages ? currentPage + 1 : null;
@@ -1320,69 +1256,6 @@
} }
} }
function loadPdfPage(pageNum) {
if (pageMode === 'double') {
const leftPage = currentPage;
const rightPage = currentPage + 1 <= totalPages ? currentPage + 1 : null;
$pageIndicator.textContent = rightPage
? `${leftPage}-${rightPage} / ${totalPages}`
: `${leftPage} / ${totalPages}`;
const jobs = [renderPdfPage(leftPage)];
if (rightPage) jobs.push(renderPdfPage(rightPage));
Promise.all(jobs)
.then(canvases => {
const left = canvases[0];
const right = canvases[1] || null;
const lw = left.width, lh = left.height;
const rw = right ? right.width : 0;
const rh = right ? right.height : 0;
const canvasW = lw + (right ? rw : 0);
const canvasH = Math.max(lh, rh || 0);
$comicCanvas.width = canvasW;
$comicCanvas.height = canvasH;
const ctx = $comicCanvas.getContext('2d');
ctx.fillStyle = '#0a0a0c';
ctx.fillRect(0, 0, canvasW, canvasH);
ctx.drawImage(left, 0, (canvasH - lh) / 2);
if (right) ctx.drawImage(right, lw, (canvasH - rh) / 2);
const prevW = naturalW;
naturalW = canvasW;
naturalH = canvasH;
showElement($comicCanvas);
if (!prevW) applyFitMode(); else centerAtCurrentScale();
$loadingOverlay.style.display = 'none';
updateReadProgress(rightPage || leftPage);
})
.catch(() => { $loadingOverlay.style.display = 'none'; });
} else {
$pageIndicator.textContent = `${currentPage} / ${totalPages}`;
renderPdfPage(currentPage)
.then(canvas => {
$comicCanvas.width = canvas.width;
$comicCanvas.height = canvas.height;
$comicCanvas.getContext('2d').drawImage(canvas, 0, 0);
const prevW = naturalW;
naturalW = canvas.width;
naturalH = canvas.height;
showElement($comicCanvas);
if (!prevW) applyFitMode(); else centerAtCurrentScale();
$loadingOverlay.style.display = 'none';
updateReadProgress(currentPage);
})
.catch(() => { $loadingOverlay.style.display = 'none'; });
}
}
function pageStep() { function pageStep() {
return pageMode === 'double' ? 2 : 1; return pageMode === 'double' ? 2 : 1;
} }
+2 -4
View File
@@ -15,13 +15,11 @@ in
}; };
config = { config = {
mod.homepage.services = lib.mkIf navidromeEnabled [ mod.homepage.services = lib.mkIf navidromeEnabled [{
{
name = "Navidrome"; name = "Navidrome";
port = 4533; port = 4533;
description = "Music streaming"; description = "Music streaming";
} }];
];
services = lib.mkIf navidromeEnabled { services = lib.mkIf navidromeEnabled {
navidrome = { navidrome = {
@@ -1,63 +0,0 @@
{
inputs,
lib,
config,
...
}:
let
enabled = config.mod.puppy-tracker.enable;
nginxEnabled = config.mod.nginx.enable;
port = 8089;
in
{
options = {
mod.puppy-tracker = {
enable = lib.mkEnableOption "Enable puppy-tracker module";
};
};
imports = [
inputs.puppy-tracker.nixosModules.default
];
config = lib.mkIf enabled {
mod.homepage.services = [
{
name = "Puppy Tracker";
port = port;
description = "Sleep, meals, pees, poos";
# Login needs HTTPS (Secure cookies), so link to the public vhost.
url = "https://puppy.ppp.pm";
}
];
services.puppy-tracker = {
enable = true;
inherit port;
openFirewall = true;
# Served publicly over HTTPS via the nginx vhost below.
secureCookies = true;
# Shared registration secret; the file holds `PUPPY_INVITE_CODE=...`.
inviteCodeFile = config.age.secrets."puppy-tracker-invite-code".path;
};
services.nginx = lib.mkIf nginxEnabled {
virtualHosts."puppy.ppp.pm" = {
forceSSL = true;
useACMEHost = "puppy.ppp.pm";
# Photo uploads are up to 15 MB; give nginx headroom over its 1 MB default.
extraConfig = ''
client_max_body_size 20m;
'';
locations."/" = {
proxyPass = "http://127.0.0.1:${toString port}";
};
};
};
age.secrets."puppy-tracker-invite-code".file =
../../../../secrets/manatee/puppy-tracker-invite-code.age;
};
}
-210
View File
@@ -1,210 +0,0 @@
{
pkgs,
lib,
config,
...
}:
let
enabled = config.mod.restic.enable;
# Where the consistent, restic-ready copies of service state are staged.
# Lives on the external backup disk. root-only (0700): these dumps contain
# credentials (HA .storage, secrets.yaml, session tokens, the romm database).
stateDir = "/mnt/backup/public/state";
# Produce consistent, restore-ready copies of every service's state under
# ${stateDir}. Runs as root before the state backups. SQLite DBs are copied
# via the online-backup API (safe on a live, WAL-mode DB); the romm MariaDB is
# dumped logically with mariadb-dump --single-transaction. Rebuildable caches
# and indexes are skipped to keep the offsite copy lean.
stateDumpScript = pkgs.writeShellScript "state-backup-dump" ''
export PATH=${
lib.makeBinPath [
pkgs.sqlite
pkgs.rsync
pkgs.podman
pkgs.coreutils
pkgs.findutils
]
}
set -euo pipefail
umask 077
STATE=${lib.escapeShellArg stateDir}
install -d -m700 "$STATE"
# snapshot SRC DEST [extra rsync excludes...]
# Copies plain files with rsync (excluding live DBs, their WAL/SHM sidecars
# and logs), then makes a consistent online copy of each *.db / *.sqlite.
snapshot() {
local src="$1" dst="$2"
shift 2
if [ ! -e "$src" ]; then
echo "state-backup: skip (missing) $src"
return 0
fi
install -d -m700 "$dst"
rsync -a --delete \
--exclude='*.sqlite' --exclude='*.sqlite-shm' --exclude='*.sqlite-wal' \
--exclude='*.db' --exclude='*.db-shm' --exclude='*.db-wal' \
--exclude='*.log' --exclude='*.log.*' \
--exclude='__pycache__/' \
"$@" \
"$src/" "$dst/"
while IFS= read -r db; do
local rel="''${db#"$src"/}"
install -d -m700 "$dst/$(dirname "$rel")"
sqlite3 "$db" ".backup '$dst/$rel'"
done < <(find "$src" -maxdepth 4 -type f \( -name '*.sqlite' -o -name '*.db' \))
}
# --- romm: logical MariaDB dump + user assets (saves/states/screenshots) ---
# Cover art under resources/ is intentionally skipped (refetched from
# metadata providers); redis is a rebuildable cache.
if podman exec romm-db true 2>/dev/null; then
install -d -m700 "$STATE/romm"
podman exec romm-db sh -c \
'exec mariadb-dump --user="$MARIADB_USER" --password="$MARIADB_PASSWORD" --single-transaction --no-tablespaces "$MARIADB_DATABASE"' \
> "$STATE/romm/romm.sql"
rsync -a --delete /var/lib/romm/assets/ "$STATE/romm/assets/"
else
echo "state-backup: skip (romm-db not running)"
fi
# --- komga: only database.sqlite matters (read progress, users, collections).
# tasks.sqlite is transient and the lucene/ index is rebuilt on demand. ---
if [ -e /var/lib/komga/database.sqlite ]; then
install -d -m700 "$STATE/komga"
sqlite3 /var/lib/komga/database.sqlite ".backup '$STATE/komga/database.sqlite'"
fi
# --- home-assistant: config, credentials and integrations, plus the two live
# SQLite DBs. Recorder history (home-assistant_v2.db) is included per choice.
# deps/ and tts/ are reinstalled/regenerated; logs are dropped. ---
HA=/home/alex/.config/home-assistant
if [ -e "$HA" ]; then
install -d -m700 "$STATE/home-assistant"
rsync -a --delete \
--exclude='home-assistant_v2.db' --exclude='home-assistant_v2.db-shm' --exclude='home-assistant_v2.db-wal' \
--exclude='zigbee.db' --exclude='zigbee.db-shm' --exclude='zigbee.db-wal' \
--exclude='*.log' --exclude='*.log.*' --exclude='*.log.fault' \
--exclude='deps/' --exclude='tts/' --exclude='__pycache__/' \
"$HA/" "$STATE/home-assistant/"
for db in home-assistant_v2.db zigbee.db; do
if [ -e "$HA/$db" ]; then
sqlite3 "$HA/$db" ".backup '$STATE/home-assistant/$db'"
fi
done
fi
# --- remaining NixOS services: generic snapshot, skipping rebuildable caches ---
snapshot /var/lib/navidrome "$STATE/navidrome" --exclude='cache/'
snapshot /var/lib/jellyfin "$STATE/jellyfin" --exclude='transcodes/' --exclude='cache/' --exclude='metadata/' --exclude='log/' --exclude='data/subtitles/'
snapshot /var/lib/audiobookshelf "$STATE/audiobookshelf" --exclude='metadata/'
snapshot /var/lib/puppy-tracker "$STATE/puppy-tracker"
snapshot /var/lib/solo-referee "$STATE/solo-referee"
snapshot /var/lib/todo "$STATE/todo"
snapshot /var/lib/komga-book-manager "$STATE/komga-book-manager"
snapshot /var/lib/komga-reading-stats "$STATE/komga-reading-stats"
echo "state-backup: dump complete"
'';
# Retention shared by all jobs.
pruneOpts = [
"--keep-daily 1"
"--keep-weekly 7"
"--keep-yearly 12"
];
in
{
options.mod.restic.enable = lib.mkEnableOption "Enable restic";
config = lib.mkIf enabled {
fileSystems."/mnt/backup" = {
device = "/dev/disk/by-uuid/34601701-65e6-4b2c-ac4d-8bef3dfd743f";
fsType = "ext4";
options = [ "nofail" ];
};
services.restic.backups = {
"sync-to-external" = {
initialize = true;
passwordFile = config.age.secrets.restic-password.path;
paths = [ "/mnt/sync/public" ];
repository = "/mnt/backup/restic";
timerConfig = {
OnCalendar = "*-*-* 0/12:00:00";
Persistent = true;
};
inherit pruneOpts;
};
"sync-to-cloud" = {
initialize = true;
passwordFile = config.age.secrets.restic-password.path;
environmentFile = config.age.secrets.restic-cloud-sync-key.path;
repositoryFile = config.age.secrets.restic-cloud-sync-repository.path;
paths = [ "/mnt/sync/public" ];
timerConfig = {
OnCalendar = "*-*-* 0/12:00:00";
Persistent = true;
};
inherit pruneOpts;
};
# Service state (databases etc.). No timer of their own: the state-backup
# orchestrator below runs the dump once and then triggers these in order,
# so both back up the same consistent staging dir without racing it.
"state-to-external" = {
initialize = true;
passwordFile = config.age.secrets.restic-password.path;
paths = [ stateDir ];
repository = "/mnt/backup/restic";
timerConfig = null;
inherit pruneOpts;
};
"state-to-cloud" = {
initialize = true;
passwordFile = config.age.secrets.restic-password.path;
environmentFile = config.age.secrets.restic-cloud-sync-key.path;
repositoryFile = config.age.secrets.restic-cloud-sync-repository.path;
paths = [ stateDir ];
timerConfig = null;
inherit pruneOpts;
};
};
# Dump service state, then push it to the external disk and the cloud, in
# that order. A "-" prefix means a failure of one restic target does not
# block the other; a failed dump (no prefix) aborts before either runs.
systemd.services.state-backup = {
description = "Dump service state and back it up (external + cloud)";
after = [ "podman.service" ];
serviceConfig = {
Type = "oneshot";
ExecStart = [
"${stateDumpScript}"
"-${pkgs.systemd}/bin/systemctl start --wait restic-backups-state-to-external.service"
"-${pkgs.systemd}/bin/systemctl start --wait restic-backups-state-to-cloud.service"
];
};
};
systemd.timers.state-backup = {
description = "Timer for service-state backups";
wantedBy = [ "timers.target" ];
timerConfig = {
OnCalendar = "*-*-* 0/12:00:00";
Persistent = true;
};
};
age.secrets = {
"restic-password".file = ../../../../secrets/manatee/restic-password.age;
"restic-cloud-sync-key".file = ../../../../secrets/manatee/restic-cloud-sync-key.age;
"restic-cloud-sync-repository".file = ../../../../secrets/manatee/restic-cloud-sync-repository.age;
};
};
}
-230
View File
@@ -1,230 +0,0 @@
{
pkgs,
lib,
config,
...
}:
let
enabled = config.mod.romm.enable;
nginxEnabled = config.mod.nginx.enable;
configFile = pkgs.writeText "romm-config.yml" ''
filesystem:
skip_hash_calculation: false
exclude:
roms:
single_file:
extensions:
- xml
- txt
- nfo
- dat
- jpg
- png
names:
- '._*'
- 'Thumbs.db'
- '.DS_Store'
'';
# Give up and enter a `failed` state (visible in `systemctl --failed`) if a
# container restarts more than 5 times in 5 minutes, instead of crash-looping
# forever. The window is deliberately long: a slow crash-loop (~5s per attempt)
# stays under systemd's default 5-starts-per-10s limit and would otherwise
# retry indefinitely.
crashLoopGuard = {
startLimitIntervalSec = 300;
startLimitBurst = 5;
};
in
{
options = {
mod.romm = {
enable = lib.mkEnableOption "Enable romm module";
};
};
config = lib.mkIf enabled {
mod.homepage.services = [
{
name = "RomM";
port = 8085;
description = "ROM library manager";
}
];
systemd.tmpfiles.rules = [
"d /var/lib/romm 0755 root root -"
"d /var/lib/romm/db 0755 root root -"
"d /var/lib/romm/redis 0755 999 1000 -"
"d /var/lib/romm/resources 0755 root root -"
"d /var/lib/romm/assets 0755 root root -"
];
systemd.services.podman-romm = crashLoopGuard;
systemd.services.podman-romm-db = crashLoopGuard;
systemd.services.podman-romm-redis = crashLoopGuard;
systemd.services.romm-net = {
description = "Create Podman network for RomM";
after = [ "podman.service" ];
requires = [ "podman.service" ];
before = [
"podman-romm.service"
"podman-romm-db.service"
"podman-romm-redis.service"
];
requiredBy = [
"podman-romm.service"
"podman-romm-db.service"
"podman-romm-redis.service"
];
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
ExecStart = pkgs.writeShellScript "romm-net-create" ''
${pkgs.podman}/bin/podman network exists romm-net \
|| ${pkgs.podman}/bin/podman network create romm-net
'';
ExecStop = "${pkgs.podman}/bin/podman network rm -f romm-net";
};
};
virtualisation.oci-containers = {
backend = "podman";
containers.romm-db = {
image = "mariadb:latest";
environment = {
MARIADB_DATABASE = "romm";
MARIADB_USER = "romm";
};
environmentFiles = [
config.age.secrets.romm-db-password.path
];
volumes = [
"/var/lib/romm/db:/var/lib/mysql"
];
extraOptions = [
"--network=romm-net"
];
};
containers.romm-redis = {
image = "redis:alpine";
volumes = [
"/var/lib/romm/redis:/data"
];
extraOptions = [
"--network=romm-net"
"--user=root"
];
};
containers.romm = {
image = "rommapp/romm:latest";
dependsOn = [
"romm-db"
"romm-redis"
];
environment = {
DB_HOST = "romm-db";
DB_PORT = "3306";
DB_NAME = "romm";
DB_USER = "romm";
REDIS_HOST = "romm-redis";
REDIS_PORT = "6379";
ROMM_AUTH_ENABLED = "true";
};
environmentFiles = [
config.age.secrets.romm-auth-secret-key.path
config.age.secrets.romm-db-password.path
config.age.secrets.romm-metadata-api-keys.path
];
ports = [
"127.0.0.1:8086:8080"
];
volumes = [
"${configFile}:/romm/config/config.yml:ro"
"/mnt/media/public/games:/romm/library"
"/var/lib/romm/resources:/romm/resources"
"/var/lib/romm/assets:/romm/assets"
];
extraOptions = [
"--network=romm-net"
];
};
};
services.nginx = lib.mkIf nginxEnabled {
virtualHosts."romm-local" = {
listen = [
{
addr = "0.0.0.0";
port = 8085;
}
];
extraConfig = ''
client_max_body_size 0;
'';
locations."/" = {
proxyPass = "http://127.0.0.1:8086";
proxyWebsockets = true;
};
};
virtualHosts."romm.ppp.pm" = {
forceSSL = true;
useACMEHost = "romm.ppp.pm";
extraConfig = ''
client_max_body_size 0;
'';
locations."/" = {
proxyPass = "http://127.0.0.1:8086";
proxyWebsockets = true;
};
};
};
boot.kernel.sysctl."net.ipv4.ip_forward" = 1;
networking.firewall.allowedTCPPorts = [ 8085 ];
age.secrets = {
"romm-auth-secret-key" = {
file = ../../../../secrets/manatee/romm-auth-secret-key.age;
owner = "root";
group = "root";
};
"romm-db-password" = {
file = ../../../../secrets/manatee/romm-db-password.age;
owner = "root";
group = "root";
};
"romm-metadata-api-keys" = {
file = ../../../../secrets/manatee/romm-metadata-api-keys.age;
owner = "root";
group = "root";
};
};
};
}
@@ -1,46 +0,0 @@
{
inputs,
lib,
config,
...
}:
let
enabled = config.mod.solo-referee.enable;
port = 8090;
in
{
options = {
mod.solo-referee = {
enable = lib.mkEnableOption "Enable solo-referee module";
};
};
imports = [
inputs.solo-referee.nixosModules.default
];
config = lib.mkIf enabled {
mod.homepage.services = [
{
name = "Solo Referee";
port = port;
description = "Solo-RPG tool with Claude as GM";
# url omitted → homepage links to http://manatee:${port}.
}
];
services.solo-referee = {
enable = true;
inherit port;
# Reachable on the LAN / Tailscale at manatee:${port}; no public vhost.
address = "0.0.0.0";
openFirewall = true;
# Anthropic API key kept out of the store; the file holds
# `ANTHROPIC_API_KEY=...`. Without it the offline stub GM runs.
apiKeyFile = config.age.secrets."solo-referee-api-key".path;
};
age.secrets."solo-referee-api-key".file =
../../../../secrets/manatee/solo-referee-api-key.age;
};
}
+1 -2
View File
@@ -21,9 +21,8 @@ in
home-manager.users.alex = { home-manager.users.alex = {
programs.ssh = { programs.ssh = {
enable = true; enable = true;
enableDefaultConfig = false;
settings = { matchBlocks = {
"git.ppp.pm" = { "git.ppp.pm" = {
hostname = "git.ppp.pm"; hostname = "git.ppp.pm";
identityFile = "/home/alex/.ssh/alex.manatee-git.ppp.pm"; identityFile = "/home/alex/.ssh/alex.manatee-git.ppp.pm";
+2 -39
View File
@@ -10,13 +10,11 @@ in
}; };
config = lib.mkIf enabled { config = lib.mkIf enabled {
mod.homepage.services = [ mod.homepage.services = [{
{
name = "Syncthing"; name = "Syncthing";
port = 8384; port = 8384;
description = "File sync"; description = "File sync";
} }];
];
services.syncthing = { services.syncthing = {
enable = true; enable = true;
@@ -39,7 +37,6 @@ in
}; };
devices = { devices = {
phone.id = config.lib.syncthing.phone;
pinwheel.id = config.lib.syncthing.pinwheel; pinwheel.id = config.lib.syncthing.pinwheel;
}; };
@@ -47,7 +44,6 @@ in
org = { org = {
path = "/mnt/sync/public/org"; path = "/mnt/sync/public/org";
devices = [ devices = [
"phone"
"pinwheel" "pinwheel"
]; ];
versioning = { versioning = {
@@ -57,39 +53,6 @@ in
}; };
}; };
}; };
personal = {
path = "/mnt/sync/public/personal";
devices = [ "pinwheel" ];
versioning = {
type = "staggered";
params = {
maxage = "2592000"; # 30 days
};
};
};
work = {
path = "/mnt/sync/public/work";
devices = [ "pinwheel" ];
versioning = {
type = "staggered";
params = {
maxage = "2592000"; # 30 days
};
};
};
"phone-gps" = {
path = "/mnt/sync/public/phone-gps";
devices = [ "phone" ];
versioning = {
type = "staggered";
params = {
maxage = "2592000"; # 30 days
};
};
};
}; };
}; };
}; };
-71
View File
@@ -1,71 +0,0 @@
{
pkgs,
lib,
config,
...
}:
let
enabled = config.mod.tmux.enable;
in
{
options = {
mod.tmux = {
enable = lib.mkEnableOption "enable tmux module";
};
};
config = lib.mkIf enabled {
home-manager.users.alex = {
programs.tmux = {
enable = true;
baseIndex = 1;
keyMode = "vi";
# Allow vi mode to be enabled instantly
escapeTime = 0;
plugins = [ pkgs.tmuxPlugins.sensible ];
extraConfig = ''
set -g renumber-windows on
# https://old.reddit.com/r/tmux/comments/mesrci/tmux_2_doesnt_seem_to_use_256_colors/
set -g default-terminal "xterm-256color"
set -ga terminal-overrides ",*256col*:Tc"
set -ga terminal-overrides ',*:Ss=\E[%p1%d q:Se=\E[ q'
set-environment -g COLORTERM "truecolor"
set-option -g allow-rename off
# Remove date/time etc. on the right side
set -g status-right ""
bind r source-file ~/.config/tmux/tmux.conf \; display "Config reloaded"
# Remove accidental `suspend-client` triggers
unbind C-z
bind | split-window -h -c "#{pane_current_path}"
bind - split-window -v -c "#{pane_current_path}"
# Move panes shortcuts
bind h select-pane -L
bind j select-pane -D
bind k select-pane -U
bind l select-pane -R
# Resize panes
bind -r H resize-pane -L 5
bind -r J resize-pane -D 5
bind -r K resize-pane -U 5
bind -r L resize-pane -R 5
# Move windows
bind -r Left swap-window -t -1 \; select-window -t -1
bind -r Right swap-window -t +1 \; select-window -t +1
'';
};
};
};
}
-58
View File
@@ -1,58 +0,0 @@
{
inputs,
lib,
config,
...
}:
let
enabled = config.mod.todo.enable;
nginxEnabled = config.mod.nginx.enable;
port = 8091;
in
{
options = {
mod.todo = {
enable = lib.mkEnableOption "Enable todo module";
};
};
imports = [
inputs.todo.nixosModules.default
];
config = lib.mkIf enabled {
mod.homepage.services = [
{
name = "Todo";
port = port;
description = "Offline-first todo";
# Login needs HTTPS (Secure cookies), so link to the public vhost.
url = "https://todo.ppp.pm";
}
];
services.todo = {
enable = true;
address = "127.0.0.1";
inherit port;
# Served publicly over HTTPS via the nginx vhost below.
secureCookies = true;
tokenFile = config.age.secrets."todo-token".path;
# sessionSecretFile is left unset: the app generates one in its state dir
# (/var/lib/todo) on first boot, mode 0600.
};
services.nginx = lib.mkIf nginxEnabled {
virtualHosts."todo.ppp.pm" = {
forceSSL = true;
useACMEHost = "todo.ppp.pm";
locations."/" = {
proxyPass = "http://127.0.0.1:${toString port}";
};
};
};
age.secrets."todo-token".file = ../../../../secrets/manatee/todo-token.age;
};
}
@@ -15,13 +15,11 @@ in
}; };
config = lib.mkIf enabled { config = lib.mkIf enabled {
mod.homepage.services = [ mod.homepage.services = [{
{
name = "Transmission"; name = "Transmission";
port = 9091; port = 9091;
description = "Torrent client"; description = "Torrent client";
} }];
];
services = { services = {
transmission = { transmission = {
+1 -1
View File
@@ -16,6 +16,7 @@
home.packages = [ home.packages = [
inputs.whib-backend.packages.${pkgs.stdenv.hostPlatform.system}.whib-import inputs.whib-backend.packages.${pkgs.stdenv.hostPlatform.system}.whib-import
# pkgs.beekeeper-studio # pkgs.beekeeper-studio
pkgs.bitwarden-desktop
pkgs.gimp pkgs.gimp
pkgs.zip pkgs.zip
pkgs.unzip pkgs.unzip
@@ -26,7 +27,6 @@
pkgs.onlyoffice-desktopeditors pkgs.onlyoffice-desktopeditors
pkgs.wdisplays pkgs.wdisplays
pkgs.vlc pkgs.vlc
pkgs.opencode
]; ];
home.stateVersion = "23.05"; home.stateVersion = "23.05";
-67
View File
@@ -1,67 +0,0 @@
{
pkgs,
lib,
config,
...
}:
let
enabled = config.mod.ai.enable;
# Shared statusline: show the logged-in account email.
statusLine = {
type = "command";
command = "jq -r '.oauthAccount.emailAddress' \"$CLAUDE_CONFIG_DIR/.claude.json\"";
};
# PostToolUse hook: echoes a JSON payload that injects a comment-policy
# reminder as additional context after every Write/Edit.
commentPolicyPayload = builtins.toJSON {
suppressOutput = true;
hookSpecificOutput = {
hookEventName = "PostToolUse";
additionalContext = "Comment policy: default to ZERO code comments. Review what you just wrote and delete any comment that narrates the change, restates the code, states the obvious, is tangential, or explains design/why rationale -- put that reasoning in your chat reply instead, never in the code. Never use em dashes or en dashes anywhere in file content; use a plain ASCII hyphen or reword.";
};
};
settings = builtins.toJSON {
inherit statusLine;
theme = "dark";
editorMode = "vim";
hooks = {
PostToolUse = [
{
matcher = "Write|Edit";
hooks = [
{
type = "command";
command = "echo ${lib.escapeShellArg commentPolicyPayload}";
}
];
}
];
};
};
in
{
options = {
mod.ai = {
enable = lib.mkEnableOption "enable ai module";
};
};
config = lib.mkIf enabled {
home-manager.users.alex = {
home.packages = [
pkgs.claude-code
];
programs.zsh.shellAliases = {
wclaude = "CLAUDE_CONFIG_DIR=$HOME/.claude-personal claude";
pclaude = "CLAUDE_CONFIG_DIR=$HOME/.claude-work claude";
};
home.file.".claude-work/settings.json".text = settings;
home.file.".claude-personal/settings.json".text = settings;
};
};
}
+1 -8
View File
@@ -28,14 +28,7 @@ in
wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled { wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled {
settings = { settings = {
bind = [ bind = [ "$mod, SPACE, exec, ${bmr}" ];
{
_args = [
"SUPER + SPACE"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${bmr}")'')
];
}
];
}; };
}; };
}; };
+1 -3
View File
@@ -14,7 +14,7 @@ in
nix-index.enable = false; nix-index.enable = false;
greetd.enable = true; greetd.enable = true;
hyprland.enable = true; hyprland.enable = true;
hyprlock.enable = true; swaylock.enable = true;
physlock.enable = false; physlock.enable = false;
power.enable = true; power.enable = true;
@@ -42,8 +42,6 @@ in
}; };
vm.enable = true; vm.enable = true;
scripts.enable = true; scripts.enable = true;
ai.enable = true;
}; };
}; };
} }
+4 -1
View File
@@ -58,7 +58,7 @@
#+END_SRC #+END_SRC
*** This makes emacsclient startup faster in TUI-mode *** This makes emacsclient startup faster in TUI-mode
#+BEGIN_SRC emacs-lisp #+BEGIN_SRC emacs-lisp
(setq-default xterm-query-timeout 0.1) (setq-default xterm-query-timeout nil)
#+END_SRC #+END_SRC
*** Disable startup messages *** Disable startup messages
#+BEGIN_SRC emacs-lisp #+BEGIN_SRC emacs-lisp
@@ -588,6 +588,9 @@ Setup prefix for keybindings.
) )
) )
(use-package eglot-booster
:after eglot
:config (eglot-booster-mode))
#+END_SRC #+END_SRC
** Go ** Go
#+BEGIN_SRC emacs-lisp #+BEGIN_SRC emacs-lisp
+13
View File
@@ -12,6 +12,18 @@ let
epkgs.flymake-go-staticcheck epkgs.flymake-go-staticcheck
epkgs.tree-sitter-langs epkgs.tree-sitter-langs
epkgs.treesit-grammars.with-all-grammars epkgs.treesit-grammars.with-all-grammars
(epkgs.trivialBuild {
pname = "eglot-booster";
version = "main-2024-04-11";
src = pkgs.fetchFromGitHub {
owner = "jdtsmith";
repo = "eglot-booster";
rev = "e19dd7ea81bada84c66e8bdd121408d9c0761fe6";
hash = "sha256-vF34ZoUUj8RENyH9OeKGSPk34G6KXZhEZozQKEcRNhs=";
};
})
]; ];
}; };
@@ -38,6 +50,7 @@ in
ec ec
emacs emacs
pkgs.wl-clipboard pkgs.wl-clipboard
pkgs.emacs-lsp-booster
pkgs.nixd pkgs.nixd
]; ];
}; };
@@ -53,12 +53,6 @@ in
package = wrapped; package = wrapped;
# Pin the legacy profile location. The default changed to the XDG path
# (`$XDG_CONFIG_HOME/mozilla/firefox`) for stateVersion >= "26.05";
# keep the old `~/.mozilla/firefox` so the existing profile isn't
# stranded (migrating would require moving the profile dir by hand).
configPath = ".mozilla/firefox";
profiles = { profiles = {
alex = { alex = {
id = 0; id = 0;
+1 -6
View File
@@ -33,12 +33,7 @@ in
wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled { wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled {
settings = { settings = {
bind = [ bind = [
{ "$mod, RETURN, exec, ${pkgs.foot}/bin/foot"
_args = [
"SUPER + RETURN"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${pkgs.foot}/bin/foot")'')
];
}
]; ];
}; };
}; };
+1 -68
View File
@@ -6,38 +6,6 @@
}: }:
let let
enabled = config.mod.git.enable; enabled = config.mod.git.enable;
# Wrapper around `ssh-keygen` used as git's SSH signing program. Before a
# signing operation it ensures the passphrase-protected signing key is loaded
# into the agent — `ssh-keygen -Y sign` reads the key from disk and re-prompts
# every commit otherwise, since `AddKeysToAgent` only ever caches auth keys.
# Loading it once (through the GUI askpass) lets later commits reuse the
# cached key from the agent. Verification and every other op pass straight
# through to the real ssh-keygen untouched.
sshSignWrapper = pkgs.writeShellApplication {
name = "git-ssh-sign";
runtimeInputs = [
pkgs.openssh
pkgs.gawk
pkgs.gnugrep
];
text = ''
key="${config.age.secrets."alex.pinwheel-github.com-signing".path}"
case " $* " in
*" -Y sign "*)
fp=""
fp="$(ssh-keygen -lf "$key.pub" 2>/dev/null | awk '{print $2}')" || true
if [ -n "$fp" ] && ! ssh-add -l 2>/dev/null | grep -qF "$fp"; then
# </dev/null detaches stdin so ssh-add uses SSH_ASKPASS (the GUI).
ssh-add "$key" </dev/null || true
fi
;;
esac
exec ssh-keygen "$@"
'';
};
in in
{ {
options = { options = {
@@ -47,7 +15,7 @@ in
}; };
config = lib.mkIf enabled { config = lib.mkIf enabled {
home-manager.users.alex = { lib, ... }: { home-manager.users.alex = {
programs.git = { programs.git = {
enable = true; enable = true;
@@ -55,31 +23,11 @@ in
{ path = ./gitconfig; } { path = ./gitconfig; }
]; ];
signing = {
key = config.age.secrets."alex.pinwheel-github.com-signing.pub".path;
signByDefault = true;
};
settings = { settings = {
rerere.enable = true; rerere.enable = true;
# Tells Git to use SSH instead of the default GPG
gpg.format = "ssh";
# Sign via a wrapper that loads the signing key into the agent on
# first use, so subsequent signed commits reuse the cached key
# instead of re-prompting for the passphrase every time.
gpg.ssh.program = "${sshSignWrapper}/bin/git-ssh-sign";
}; };
}; };
home.file.".ssh/config".target = ".ssh/config_source";
home.activation.sshConfig = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
run cat ~/.ssh/config_source > ~/.ssh/config
run chmod 600 ~/.ssh/config
'';
home.packages = [ pkgs.tig ]; home.packages = [ pkgs.tig ];
home.file.".tigrc".text = '' home.file.".tigrc".text = ''
@@ -87,20 +35,5 @@ in
set main-view-line-number-interval = 1 set main-view-line-number-interval = 1
''; '';
}; };
age.secrets = {
"alex.pinwheel-github.com-signing" = {
file = ../../../../secrets/pinwheel/alex.pinwheel-github.com-signing.age;
path = "/home/alex/.ssh/alex.pinwheel-github.com-signing";
owner = "alex";
group = "users";
};
"alex.pinwheel-github.com-signing.pub" = {
file = ../../../../secrets/pinwheel/alex.pinwheel-github.com-signing.pub.age;
path = "/home/alex/.ssh/alex.pinwheel-github.com-signing.pub";
owner = "alex";
group = "users";
};
};
}; };
} }
+1 -1
View File
@@ -18,7 +18,7 @@ in
home-manager.users.alex = { home-manager.users.alex = {
home.packages = [ home.packages = [
pkgs.gleam pkgs.gleam
pkgs.beamPackages.erlang pkgs.erlang
]; ];
}; };
}; };
+1 -1
View File
@@ -22,7 +22,7 @@ in
let let
session = { session = {
user = "alex"; user = "alex";
command = "uwsm start hyprland-uwsm.desktop"; command = "${pkgs.hyprland}/bin/Hyprland";
}; };
in in
{ {
+71 -264
View File
@@ -8,8 +8,6 @@
let let
enabled = config.mod.hyprland.enable; enabled = config.mod.hyprland.enable;
mod = "SUPER";
monitorScript = pkgs.writeShellScript "hyprland-monitor-handler" '' monitorScript = pkgs.writeShellScript "hyprland-monitor-handler" ''
INTERNAL="eDP-1" INTERNAL="eDP-1"
EXTERNAL_MONITORS="HDMI-A-1 DP-3" EXTERNAL_MONITORS="HDMI-A-1 DP-3"
@@ -28,51 +26,39 @@ let
} }
bind_workspaces() { bind_workspaces() {
local external batch="" local external
if external=$(get_active_external); then if external=$(get_active_external); then
# External monitor connected: move workspaces 1-5 to external, 6-10 to internal # External monitor connected: 1-5 on external, 6-10 on internal
for ws in 1 2 3 4 5; do for ws in 1 2 3 4 5; do
batch="$batch dispatch hl.dsp.workspace.move({ monitor = \"$external\", workspace = $ws });" $HYPRCTL keyword workspace "$ws, monitor:$external, default:true"
done done
for ws in 6 7 8 9 10; do for ws in 6 7 8 9 10; do
batch="$batch dispatch hl.dsp.workspace.move({ monitor = \"$INTERNAL\", workspace = $ws });" $HYPRCTL keyword workspace "$ws, monitor:$INTERNAL, default:true"
done done
else else
# No external monitor: move all workspaces to internal # No external monitor: all workspaces on internal
for ws in 1 2 3 4 5 6 7 8 9 10; do for ws in 1 2 3 4 5 6 7 8 9 10; do
batch="$batch dispatch hl.dsp.workspace.move({ monitor = \"$INTERNAL\", workspace = $ws });" $HYPRCTL keyword workspace "$ws, monitor:$INTERNAL, default:true"
done done
fi fi
$HYPRCTL --batch "$batch"
} }
handle_event() { handle_event() {
case $1 in case $1 in
monitoradded*|monitorremoved*) monitoradded*|monitorremoved*)
sleep 0.5 sleep 0.5 # Give monitor time to initialize
bind_workspaces bind_workspaces
;; ;;
esac esac
} }
# Start the event listener first so monitoradded events emitted during # Bind workspaces on startup
# session startup are not lost in the gap before we begin reading them.
${pkgs.socat}/bin/socat -U - UNIX-CONNECT:"$XDG_RUNTIME_DIR/hypr/$HYPRLAND_INSTANCE_SIGNATURE/.socket2.sock" | while read -r line; do
handle_event "$line"
done &
LISTENER_PID=$!
# Give socat a moment to actually connect before the initial bind.
sleep 0.2
bind_workspaces bind_workspaces
# Re-bind once more after the DRM subsystem has had time to enumerate ${pkgs.socat}/bin/socat -U - UNIX-CONNECT:"$XDG_RUNTIME_DIR/hypr/$HYPRLAND_INSTANCE_SIGNATURE/.socket2.sock" | while read -r line; do
# external connectors, in case they were not yet present at session start. handle_event "$line"
(sleep 3; bind_workspaces) & done
wait $LISTENER_PID
''; '';
in in
{ {
@@ -85,7 +71,6 @@ in
config = lib.mkIf enabled { config = lib.mkIf enabled {
programs.hyprland = { programs.hyprland = {
enable = true; enable = true;
withUWSM = true;
package = inputs.hyprland.packages.${pkgs.stdenv.hostPlatform.system}.hyprland; package = inputs.hyprland.packages.${pkgs.stdenv.hostPlatform.system}.hyprland;
portalPackage = portalPackage =
inputs.hyprland.packages.${pkgs.stdenv.hostPlatform.system}.xdg-desktop-portal-hyprland; inputs.hyprland.packages.${pkgs.stdenv.hostPlatform.system}.xdg-desktop-portal-hyprland;
@@ -98,12 +83,40 @@ in
home-manager.users.alex = { home-manager.users.alex = {
wayland.windowManager.hyprland = { wayland.windowManager.hyprland = {
enable = true; enable = true;
systemd.enable = false;
configType = "lua"; extraConfig = ''
exec-once=waybar
exec-once=hyprctl setcursor Adwaita 24
env = GDK_DPI_SCALE,1.5
env = HYPRCURSOR_THEME,Adwaita
env = HYPRCURSOR_SIZE,24
monitor=eDP-1, 1920x1200, auto-center-down, 1
monitor=HDMI-A-1, 2560x1440@100, auto-center-up, 1
monitor=DP-3, 2560x1440@60, auto-center-up, 1
workspace = w[tv1], gapsout:0, gapsin:0
workspace = f[1], gapsout:0, gapsin:0
windowrule = border_size 0, match:float 0, match:workspace w[tv1]
windowrule = rounding 0, match:float 0, match:workspace w[tv1]
windowrule = border_size 0, match:float 0, match:workspace f[1]
windowrule = rounding 0, match:float 0, match:workspace f[1]
# https://wiki.archlinux.org/title/Hyprland#Jetbrains_apps_focus_issues
windowrule = match:xwayland true, no_initial_focus on
exec-once=dbus-update-activation-environment --systemd WAYLAND_DISPLAY XDG_CURRENT_DESKTOP
'';
settings = { settings = {
config = { "$mod" = "SUPER";
xwayland.force_zero_scaling = true;
animations.enabled = false;
xwayland = {
force_zero_scaling = true;
};
input = { input = {
kb_layout = "se"; kb_layout = "se";
@@ -115,7 +128,7 @@ in
accel_profile = "flat"; accel_profile = "flat";
touchpad = { touchpad = {
natural_scroll = false; natural_scroll = false;
tap_and_drag = false; tap-and-drag = false;
}; };
}; };
@@ -130,149 +143,12 @@ in
gaps_in = 0; # gaps between windows gaps_in = 0; # gaps between windows
gaps_out = 0; # gaps between windows and monitor edges gaps_out = 0; # gaps between windows and monitor edges
col = { "col.active_border" = "rgba(${config.lib.colors.foreground}ff)";
active_border = "rgba(${config.lib.colors.foreground}ff)"; "col.inactive_border" = "rgba(${config.lib.colors.background}ff)";
inactive_border = "rgba(${config.lib.colors.background}ff)";
};
}; };
dwindle.force_split = 2; dwindle = {
force_split = 2;
misc = {
disable_hyprland_logo = true;
disable_splash_rendering = true;
};
animations.enabled = false;
};
monitor = [
{
output = "eDP-1";
mode = "1920x1200";
position = "auto-center-down";
scale = "1";
}
{
output = "HDMI-A-1";
mode = "2560x1440@100";
position = "auto-center-up";
scale = "1";
}
{
output = "DP-3";
mode = "2560x1440@60";
position = "auto-center-up";
scale = "1";
}
];
# Static defaults only: a workspace can only have one `monitor` in
# hl.workspace_rule (later calls overwrite it, unlike hyprlang's
# rule list). The hyprland-monitors service re-dispatches these to
# whichever external monitor is actually connected at startup and
# on hotplug, so this only matters for the brief window before it
# runs.
workspace_rule = [
{
workspace = "1";
monitor = "HDMI-A-1";
default = true;
}
{
workspace = "2";
monitor = "HDMI-A-1";
}
{
workspace = "3";
monitor = "HDMI-A-1";
}
{
workspace = "4";
monitor = "HDMI-A-1";
}
{
workspace = "5";
monitor = "HDMI-A-1";
}
{
workspace = "6";
monitor = "eDP-1";
default = true;
}
{
workspace = "7";
monitor = "eDP-1";
}
{
workspace = "8";
monitor = "eDP-1";
}
{
workspace = "9";
monitor = "eDP-1";
}
{
workspace = "10";
monitor = "eDP-1";
}
{
workspace = "w[tv1]";
gaps_out = 0;
gaps_in = 0;
}
{
workspace = "f[1]";
gaps_out = 0;
gaps_in = 0;
}
];
window_rule = [
{
name = "no-gaps-wtv1";
match = {
float = false;
workspace = "w[tv1]";
};
border_size = 0;
rounding = 0;
}
{
name = "no-gaps-f1";
match = {
float = false;
workspace = "f[1]";
};
border_size = 0;
rounding = 0;
}
{
# https://wiki.archlinux.org/title/Hyprland#Jetbrains_apps_focus_issues
name = "xwayland-no-initial-focus";
match.xwayland = true;
no_initial_focus = true;
}
];
env = [
{ _args = [ "GDK_DPI_SCALE" "1.5" ]; }
{ _args = [ "HYPRCURSOR_THEME" "Adwaita" ]; }
{ _args = [ "HYPRCURSOR_SIZE" "24" ]; }
];
on = {
_args = [
"hyprland.start"
(lib.generators.mkLuaInline ''
function()
hl.exec_cmd("uwsm app -- waybar")
hl.exec_cmd("uwsm app -- hyprctl setcursor Adwaita 24")
end
'')
];
}; };
bind = bind =
@@ -284,23 +160,10 @@ in
in in
builtins.toString n; builtins.toString n;
focusWs = x: { select = builtins.genList (x: "$mod, ${ws x}, workspace, ${builtins.toString (x + 1)}") 10;
_args = [ move = builtins.genList (
"${mod} + ${ws x}" x: "$mod SHIFT, ${ws x}, movetoworkspacesilent, ${builtins.toString (x + 1)}"
(lib.generators.mkLuaInline "hl.dsp.focus({ workspace = ${builtins.toString (x + 1)} })") ) 10;
];
};
moveToWs = x: {
_args = [
"${mod} + SHIFT + ${ws x}"
(lib.generators.mkLuaInline
"hl.dsp.window.move({ workspace = ${builtins.toString (x + 1)}, follow = false })"
)
];
};
select = builtins.genList focusWs 10;
move = builtins.genList moveToWs 10;
magnifier = pkgs.writeShellScript "magnifier" '' magnifier = pkgs.writeShellScript "magnifier" ''
CURRENT=$(${pkgs.hyprland}/bin/hyprctl getoption cursor:zoom_factor -j | ${pkgs.jq}/bin/jq .float) CURRENT=$(${pkgs.hyprland}/bin/hyprctl getoption cursor:zoom_factor -j | ${pkgs.jq}/bin/jq .float)
@@ -323,87 +186,31 @@ in
select select
++ move ++ move
++ [ ++ [
{ "$mod, ESCAPE, killactive"
_args = [
"${mod} + ESCAPE"
(lib.generators.mkLuaInline "hl.dsp.window.close()")
];
}
{ "$mod, f, fullscreen, 1"
_args = [ "$mod SHIFT, f, togglefloating, active"
"${mod} + f"
(lib.generators.mkLuaInline ''hl.dsp.window.fullscreen({ mode = "maximized" })'')
];
}
{
_args = [
"${mod} + SHIFT + f"
(lib.generators.mkLuaInline ''hl.dsp.window.float({ action = "toggle" })'')
];
}
{ "$mod, h, movefocus, l"
_args = [ "$mod, j, movefocus, d"
"${mod} + h" "$mod, k, movefocus, u"
(lib.generators.mkLuaInline ''hl.dsp.focus({ direction = "left" })'') "$mod, l, movefocus, r"
];
}
{
_args = [
"${mod} + j"
(lib.generators.mkLuaInline ''hl.dsp.focus({ direction = "down" })'')
];
}
{
_args = [
"${mod} + k"
(lib.generators.mkLuaInline ''hl.dsp.focus({ direction = "up" })'')
];
}
{
_args = [
"${mod} + l"
(lib.generators.mkLuaInline ''hl.dsp.focus({ direction = "right" })'')
];
}
{ "$mod CONTROL, 1, exec, ${magnifier} --increase"
_args = [ "$mod CONTROL, 2, exec, ${magnifier} --decrease"
"${mod} + CONTROL + 1" "$mod CONTROL, 3, exec, ${magnifier} --reset"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${magnifier} --increase")'')
]; ];
}
{
_args = [
"${mod} + CONTROL + 2"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${magnifier} --decrease")'')
];
}
{
_args = [
"${mod} + CONTROL + 3"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${magnifier} --reset")'')
];
}
# mouse movements: hyprland's lua API has no separate `bindm`, bindm = [
# mouse binds are plain `hl.bind` with `{ mouse = true }`. # mouse movements
{ "$mod, mouse:272, movewindow" # left click
_args = [ "$mod, mouse:273, resizewindow" # right click
"${mod} + mouse:272" # left click
(lib.generators.mkLuaInline "hl.dsp.window.drag()")
{ mouse = true; }
];
}
{
_args = [
"${mod} + mouse:273" # right click
(lib.generators.mkLuaInline "hl.dsp.window.resize()")
{ mouse = true; }
];
}
]; ];
misc = {
disable_hyprland_logo = true;
disable_splash_rendering = true;
};
}; };
}; };
-104
View File
@@ -1,104 +0,0 @@
{
pkgs,
lib,
config,
...
}:
let
enabled = config.mod.hyprlock.enable;
hyprlandEnabled = config.mod.hyprland.enable;
in
{
options = {
mod.hyprlock = {
enable = lib.mkEnableOption "enable hyprlock module";
dpmsTimeout = lib.mkOption {
description = "timeout in seconds before DPMS is turned on";
type = lib.types.str;
default = "10";
};
};
};
config = lib.mkIf enabled {
home-manager.users.alex = {
programs.hyprlock = {
enable = true;
settings = {
general = {
hide_cursor = true;
};
background = [
{
color = "rgb(000000)";
}
];
input-field = [
{
size = "250, 50";
position = "0, 0";
halign = "center";
valign = "center";
outline_thickness = 2;
dots_center = true;
fade_on_empty = false;
placeholder_text = "";
}
];
};
};
wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled {
settings = {
bind =
let
pause-music = "${pkgs.playerctl}/bin/playerctl -a pause";
dpmsTimeout = config.mod.hyprlock.dpmsTimeout;
dpmsOff = pkgs.writeShellScript "dpms-off" ''
${pkgs.hyprland}/bin/hyprctl dispatch 'hl.dsp.dpms({ action = "off" })'
'';
dpmsOn = pkgs.writeShellScript "dpms-on" ''
${pkgs.hyprland}/bin/hyprctl dispatch 'hl.dsp.dpms({ action = "on" })'
'';
dpms-lock = pkgs.writeShellScript "dpms-lock" ''
${pkgs.swayidle}/bin/swayidle \
timeout ${dpmsTimeout} ${dpmsOff} \
resume ${dpmsOn} &
${pkgs.hyprlock}/bin/hyprlock; ${pkgs.procps}/bin/pkill swayidle
'';
in
[
{
_args = [
"SUPER + x"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${pause-music}; ${dpms-lock}")'')
];
}
{
_args = [
"SUPER + SHIFT + x"
(lib.generators.mkLuaInline
''hl.dsp.exec_cmd("${pause-music}; ${pkgs.hyprlock}/bin/hyprlock & sleep 0.5; systemctl suspend")''
)
];
}
];
};
};
};
security = {
polkit.enable = true;
pam.services.hyprlock = {};
};
};
}
@@ -1,6 +1,6 @@
{ pkgs, ... }: { pkgs, ... }:
{ {
home-manager.users.alex = { home-manager.users.alex = {
home.packages = [ pkgs.typescript-language-server ]; home.packages = [ pkgs.nodePackages.typescript-language-server ];
}; };
} }
+3 -12
View File
@@ -9,23 +9,14 @@ let
in in
{ {
users.users.alex.extraGroups = [ "video" ]; users.users.alex.extraGroups = [ "video" ];
programs.light.enable = true;
home-manager.users.alex = { home-manager.users.alex = {
wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled { wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled {
settings = { settings = {
bind = [ bind = [
{ ", XF86MonBrightnessUp, exec, ${pkgs.light}/bin/light -A 5"
_args = [ ", XF86MonBrightnessDown, exec, ${pkgs.light}/bin/light -U 5"
"XF86MonBrightnessUp"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${pkgs.brightnessctl}/bin/brightnessctl set +5%")'')
];
}
{
_args = [
"XF86MonBrightnessDown"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${pkgs.brightnessctl}/bin/brightnessctl set 5%-")'')
];
}
]; ];
}; };
}; };
+7 -14
View File
@@ -16,23 +16,16 @@ in
let let
prev = "${pkgs.playerctl}/bin/playerctl -p naviterm,spotify previous"; prev = "${pkgs.playerctl}/bin/playerctl -p naviterm,spotify previous";
next = "${pkgs.playerctl}/bin/playerctl -p naviterm,spotify next"; next = "${pkgs.playerctl}/bin/playerctl -p naviterm,spotify next";
mkExec = key: cmd: {
_args = [
key
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${cmd}")'')
];
};
in in
[ [
(mkExec "XF86AudioPrev" prev) ", XF86AudioPrev, exec, ${prev}"
(mkExec "XF86AudioNext" next) ", XF86AudioNext, exec, ${next}"
(mkExec "XF86AudioPlay" "${pkgs.playerctl}/bin/playerctl -p naviterm,spotify play-pause") ", XF86AudioPlay, exec, ${pkgs.playerctl}/bin/playerctl -p naviterm,spotify play-pause"
(mkExec "XF86AudioPause" "${pkgs.playerctl}/bin/playerctl -p naviterm,spoitfy play-pause") ", XF86AudioPause, exec, ${pkgs.playerctl}/bin/playerctl -p naviterm,spoitfy play-pause"
(mkExec "SUPER + ALT + LEFT" prev) "$mod ALT, LEFT, exec, ${prev}"
(mkExec "SUPER + ALT + RIGHT" next) "$mod ALT, RIGHT, exec, ${next}"
(mkExec "SUPER + ALT + DOWN" "${pkgs.playerctl}/bin/playerctl -p naviterm,spotify play-pause") "$mod ALT, DOWN, exec, ${pkgs.playerctl}/bin/playerctl -p naviterm,spotify play-pause"
]; ];
}; };
}; };
+2 -14
View File
@@ -38,20 +38,8 @@ in
in in
[ [
# will lock the screen with `physlock`, see `lockOn.suspend # will lock the screen with `physlock`, see `lockOn.suspend
{ "$mod SHIFT, x, exec, ${pause-music}; systemctl suspend"
_args = [ "$mod, x, exec, ${pause-music}; ${config.security.wrapperDir}/physlock -d -s -m"
"SUPER + SHIFT + x"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${pause-music}; systemctl suspend")'')
];
}
{
_args = [
"SUPER + x"
(lib.generators.mkLuaInline
''hl.dsp.exec_cmd("${pause-music}; ${config.security.wrapperDir}/physlock -d -s -m")''
)
];
}
]; ];
}; };
}; };
+3 -3
View File
@@ -80,12 +80,12 @@ in
path = [ path = [
pkgs.coreutils # For `cat` pkgs.coreutils # For `cat`
pkgs.libnotify pkgs.libnotify
pkgs.hyprlock pkgs.swaylock
]; ];
script = script =
let let
pause-music = "${pkgs.playerctl}/bin/playerctl -a pause"; pause-music = "${pkgs.playerctl}/bin/playerctl -p spotify pause";
in in
'' ''
BATTERY_CAPACITY=$(cat /sys/class/power_supply/${lowbat.battery}/capacity) BATTERY_CAPACITY=$(cat /sys/class/power_supply/${lowbat.battery}/capacity)
@@ -103,7 +103,7 @@ in
BATTERY_STATUS=$(cat /sys/class/power_supply/${lowbat.battery}/status) BATTERY_STATUS=$(cat /sys/class/power_supply/${lowbat.battery}/status)
if [[ $BATTERY_STATUS = "Discharging" ]]; then if [[ $BATTERY_STATUS = "Discharging" ]]; then
${pause-music}; ${pkgs.hyprlock}/bin/hyprlock & sleep 0.5; systemctl suspend ${pause-music}; ${pkgs.swaylock}/bin/swaylock -f; systemctl suspend
fi fi
fi fi
''; '';
+2 -12
View File
@@ -19,18 +19,8 @@ in
wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled { wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled {
settings = { settings = {
bind = [ bind = [
{ "$mod, Print, exec, ${area}"
_args = [ "$mod CTRL, Print, exec, ${screen}"
"SUPER + Print"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${area}")'')
];
}
{
_args = [
"SUPER + CTRL + Print"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${screen}")'')
];
}
]; ];
}; };
}; };
+4 -11
View File
@@ -38,19 +38,12 @@ in
MUTED=$(${pkgs.wireplumber}/bin/wpctl get-volume @DEFAULT_AUDIO_SOURCE@ | grep MUTED | wc -l) MUTED=$(${pkgs.wireplumber}/bin/wpctl get-volume @DEFAULT_AUDIO_SOURCE@ | grep MUTED | wc -l)
echo $MUTED > /sys/class/leds/platform::micmute/brightness echo $MUTED > /sys/class/leds/platform::micmute/brightness
''; '';
mkExec = key: cmd: {
_args = [
key
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${cmd}")'')
];
};
in in
[ [
(mkExec "XF86AudioRaiseVolume" "${pkgs.wireplumber}/bin/wpctl set-volume -l 1.5 @DEFAULT_AUDIO_SINK@ 2%+") ", XF86AudioRaiseVolume, exec, ${pkgs.wireplumber}/bin/wpctl set-volume -l 1.5 @DEFAULT_AUDIO_SINK@ 2%+"
(mkExec "XF86AudioLowerVolume" "${pkgs.wireplumber}/bin/wpctl set-volume @DEFAULT_AUDIO_SINK@ 2%-") ", XF86AudioLowerVolume, exec, ${pkgs.wireplumber}/bin/wpctl set-volume @DEFAULT_AUDIO_SINK@ 2%-"
(mkExec "XF86AudioMute" "${toggle-output-mute}") ", XF86AudioMute, exec, ${toggle-output-mute}"
(mkExec "XF86AudioMicMute" "${toggle-input-mute}") ", XF86AudioMicMute, exec, ${toggle-input-mute}"
]; ];
}; };
}; };
+28 -62
View File
@@ -1,92 +1,58 @@
{ pkgs, ... }: { pkgs, ... }:
{ {
# Enable gnome-keyring at system level for PAM integration
services.gnome.gnome-keyring.enable = true;
# Use openssh's own ssh-agent — gcr's ssh-agent stalls signing RSA keys.
services.gnome.gcr-ssh-agent.enable = false;
programs.ssh.startAgent = true;
# Create the setuid `fusermount3` wrapper that `sshfs` execs to mount. The
# `programs.fuse` module used to install this unconditionally; newer nixpkgs
# gates it behind this option (default off), so opt in explicitly.
programs.fuse.enable = true;
home-manager.users.alex = { home-manager.users.alex = {
services.gnome-keyring = {
enable = true;
components = [ "secrets" ];
};
home.sessionVariables = {
# gnome-keyring's PAM hooks export SSH_AUTH_SOCK pointing at a dead gcr
# socket (gcr-ssh-agent is disabled above), which shadows openssh's own
# agent and silently breaks passphrase caching. Force it back to the
# openssh agent started by `programs.ssh.startAgent`.
SSH_AUTH_SOCK = "$XDG_RUNTIME_DIR/ssh-agent";
# Route passphrase prompts through seahorse's GUI askpass instead of the
# terminal. `prefer` uses the GUI even when a tty is attached (ssh only
# falls back to askpass with no controlling terminal otherwise).
SSH_ASKPASS = "${pkgs.seahorse}/libexec/seahorse/ssh-askpass";
SSH_ASKPASS_REQUIRE = "prefer";
};
programs.ssh = { programs.ssh = {
enable = true; enable = true;
enableDefaultConfig = false; enableDefaultConfig = false;
settings = { matchBlocks = {
"manatee" = { "manatee" = {
HostName = "manatee"; hostname = "manatee";
User = "alex"; user = "alex";
IdentityFile = "/home/alex/.ssh/alex.pinwheel-manatee"; identityFile = "/home/alex/.ssh/alex.pinwheel-manatee";
Port = 1122; port = 1122;
}; };
"backwards" = { "backwards" = {
HostName = "backwards"; hostname = "backwards";
User = "alex"; user = "alex";
IdentityFile = "/home/alex/.ssh/alex.pinwheel-backwards"; identityFile = "/home/alex/.ssh/alex.pinwheel-backwards";
Port = 1122; port = 1122;
}; };
"tadpole" = { "tadpole" = {
HostName = "65.21.106.222"; hostname = "65.21.106.222";
User = "alex"; user = "alex";
IdentityFile = "/home/alex/.ssh/alex.pinwheel-tadpole"; identityFile = "/home/alex/.ssh/alex.pinwheel-tadpole";
Port = 1122; port = 1122;
}; };
"github.com" = { "github.com" = {
HostName = "github.com"; hostname = "github.com";
IdentityFile = "/home/alex/.ssh/alex.pinwheel-github.com"; identityFile = "/home/alex/.ssh/alex.pinwheel-github.com";
}; };
"git.ppp.pm" = { "git.ppp.pm" = {
HostName = "git.ppp.pm"; hostname = "git.ppp.pm";
IdentityFile = "/home/alex/.ssh/alex.pinwheel-git.ppp.pm"; identityFile = "/home/alex/.ssh/alex.pinwheel-git.ppp.pm";
}; };
"*" = { "*" = {
ForwardAgent = false; forwardAgent = false;
AddKeysToAgent = "yes"; addKeysToAgent = "no";
Compression = false; compression = false;
ServerAliveInterval = 0; serverAliveInterval = 0;
ServerAliveCountMax = 3; serverAliveCountMax = 3;
HashKnownHosts = false; hashKnownHosts = false;
UserKnownHostsFile = "~/.ssh/known_hosts"; userKnownHostsFile = "~/.ssh/known_hosts";
ControlMaster = "no"; controlMaster = "no";
ControlPath = "~/.ssh/master-%r@%n:%p"; controlPath = "~/.ssh/master-%r@%n:%p";
ControlPersist = "no"; controlPersist = "no";
}; };
}; };
}; };
home.packages = [ home.packages = [ pkgs.sshfs ];
pkgs.sshfs
pkgs.seahorse # GUI for managing gnome-keyring
];
}; };
age.secrets = { age.secrets = {
@@ -0,0 +1,69 @@
{
pkgs,
lib,
config,
...
}:
let
enabled = config.mod.swaylock.enable;
hyprlandEnabled = config.mod.hyprland.enable;
in
{
options = {
mod.swaylock = {
enable = lib.mkEnableOption "enable swaylock module";
dpmsTimeout = lib.mkOption {
description = "timeout in seconds before DPMS is turned on";
type = lib.types.str;
default = "10";
};
};
};
config = lib.mkIf enabled {
home-manager.users.alex = {
programs.swaylock = {
enable = true;
settings = {
color = "000000";
indicator-idle-visible = false;
show-failed-attempts = true;
};
};
wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled {
settings = {
bind =
let
pause-music = "${pkgs.playerctl}/bin/playerctl -p spotify pause";
dpmsTimeout = config.mod.swaylock.dpmsTimeout;
dpms-lock = pkgs.writeShellScript "dpms-lock" ''
${pkgs.swayidle}/bin/swayidle \
timeout ${dpmsTimeout} "${pkgs.hyprland}/bin/hyprctl dispatch dpms off" \
resume "${pkgs.hyprland}/bin/hyprctl dispatch dpms on" &
${pkgs.swaylock}/bin/swaylock && ${pkgs.procps}/bin/pkill swayidle
'';
in
[
"$mod, x, exec, ${pause-music}; ${dpms-lock}"
"$mod SHIFT, x, exec, ${pause-music}; ${pkgs.swaylock}/bin/swaylock -f; systemctl suspend"
];
};
};
};
security = {
polkit.enable = true;
pam.services.swaylock.text = ''
# PAM configuration file for the swaylock screen locker. By default, it includes
# the 'login' configuration file (see /etc/pam.d/login)
auth include login
'';
};
};
}
+15 -2
View File
@@ -15,6 +15,7 @@
settings = { settings = {
devices = { devices = {
phone.id = config.lib.syncthing.phone; phone.id = config.lib.syncthing.phone;
backwards.id = config.lib.syncthing.backwards;
manatee.id = config.lib.syncthing.manatee; manatee.id = config.lib.syncthing.manatee;
}; };
@@ -23,6 +24,7 @@
path = "/home/alex/sync/org"; path = "/home/alex/sync/org";
devices = [ devices = [
"phone" "phone"
"backwards"
"manatee" "manatee"
]; ];
versioning = { versioning = {
@@ -35,7 +37,7 @@
personal = { personal = {
path = "/home/alex/sync/personal"; path = "/home/alex/sync/personal";
devices = [ "manatee" ]; devices = [ "backwards" ];
versioning = { versioning = {
type = "staggered"; type = "staggered";
params = { params = {
@@ -46,7 +48,18 @@
work = { work = {
path = "/home/alex/sync/work"; path = "/home/alex/sync/work";
devices = [ "manatee" ]; devices = [ "backwards" ];
versioning = {
type = "staggered";
params = {
maxAge = "2592000"; # 30 days
};
};
};
books = {
path = "/home/alex/sync/reading-material/books";
devices = [ "backwards" ];
versioning = { versioning = {
type = "staggered"; type = "staggered";
params = { params = {
+1 -17
View File
@@ -1,23 +1,7 @@
{ pkgs, ... }: { ... }:
{ {
services.tailscale.enable = true; services.tailscale.enable = true;
# Pinned to 1.96.5. 1.98.0 regressed split-DNS handling under work-vpn: the
# netmap's "resolve <tailnet>.ts.net locally via MagicDNS" hint is dropped
# when translated into systemd-resolved config, so *.ts.net queries get sent
# to a public resolver (199.247.155.53) that the corporate VPN's port-53
# egress filter blocks.
services.tailscale.package = pkgs.tailscale.overrideAttrs (_: rec {
version = "1.96.5";
src = pkgs.fetchFromGitHub {
owner = "tailscale";
repo = "tailscale";
tag = "v${version}";
hash = "sha256-vYYb+2OtuXftjGGG0zWJesHccrClB8YZpclv9KzNN/c=";
};
vendorHash = "sha256-rhuWEEN+CtumVxOw6Dy/IRxWIrZ2x6RJb6ULYwXCQc4=";
});
networking.firewall = { networking.firewall = {
checkReversePath = "loose"; checkReversePath = "loose";
allowedUDPPorts = [ 41641 ]; allowedUDPPorts = [ 41641 ];
+1 -1
View File
@@ -18,7 +18,7 @@
# https://old.reddit.com/r/tmux/comments/mesrci/tmux_2_doesnt_seem_to_use_256_colors/ # https://old.reddit.com/r/tmux/comments/mesrci/tmux_2_doesnt_seem_to_use_256_colors/
set -g default-terminal "xterm-256color" set -g default-terminal "xterm-256color"
set -ga terminal-overrides ",*256col*:Tc" set -ga terminal-overrides ",*256col*:Tc"
set -ga terminal-overrides ',*:Ss=\E[%p1%d q:Se=\E[ q' set -ga terminal-overrides "*:Ss=\E[%p1%d q:Se=\E[ q"
set-environment -g COLORTERM "truecolor" set-environment -g COLORTERM "truecolor"
set-option -g allow-rename off set-option -g allow-rename off
@@ -208,7 +208,6 @@ in
}; };
battery = { battery = {
"bat" = "BAT0";
"interval" = 60; "interval" = 60;
"format" = "<span font='10' rise='1000'>{icon}</span> {capacity}%"; "format" = "<span font='10' rise='1000'>{icon}</span> {capacity}%";
"format-time" = "{H}h {M}min"; "format-time" = "{H}h {M}min";
+1 -6
View File
@@ -78,12 +78,7 @@ in
wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled { wayland.windowManager.hyprland = lib.mkIf hyprlandEnabled {
settings = { settings = {
bind = [ bind = [
{ "$mod, RETURN, exec, ${pkgs.wezterm}/bin/wezterm"
_args = [
"SUPER + RETURN"
(lib.generators.mkLuaInline ''hl.dsp.exec_cmd("${pkgs.wezterm}/bin/wezterm")'')
];
}
]; ];
}; };
}; };
-49
View File
@@ -12,52 +12,6 @@ let
in in
{ {
home-manager.users.alex = { home-manager.users.alex = {
# Ensure bashInteractive is first in PATH inside nix devshells.
# stdenv provides a non-interactive bash that breaks Copilot shell commands.
# Adding bashInteractive to home.packages alone isn't enough because devshell
# packages are prepended to PATH. This precmd hook runs after direnv's hook
# and re-prepends bashInteractive so it takes priority.
programs.zsh.initContent = ''
_ensure_bash_interactive() {
[[ "$PATH" == "${pkgs.bashInteractive}/bin:"* ]] || export PATH="${pkgs.bashInteractive}/bin:$PATH"
}
precmd_functions+=(_ensure_bash_interactive)
# Source the zsh-specific rc file that nix-direnv emits ($DIRENV_ZSH_RC)
# so devshell completions and zsh setup are picked up. direnv itself only
# exports env vars, so without this hook the zsh side of the devshell is
# never loaded. Guarded by LAST_LOADED_DIRENV_ZSH_RC so we don't re-source
# it on every precmd.
_nix_direnv_bridge_hook() {
if [[ -n "$DIRENV_ZSH_RC" && "$LAST_LOADED_DIRENV_ZSH_RC" != "$DIRENV_ZSH_RC" ]]; then
if [[ -f "$DIRENV_ZSH_RC" ]]; then
source "$DIRENV_ZSH_RC"
export LAST_LOADED_DIRENV_ZSH_RC="$DIRENV_ZSH_RC"
echo " direnv zsh loaded..."
fi
fi
}
autoload -Uz add-zsh-hook
add-zsh-hook precmd _nix_direnv_bridge_hook
'';
# Configure IntelliJ to exclude .direnv from indexing
home.activation.intellijIgnoreDirenv = ''
for idea_config in $HOME/.config/JetBrains/IntelliJIdea*; do
if [ -d "$idea_config" ]; then
$DRY_RUN_CMD mkdir -p "$idea_config/options"
$DRY_RUN_CMD tee "$idea_config/options/filetypes.xml" > /dev/null <<'EOF'
<application>
<component name="FileTypeManager" version="18">
<ignoreFiles list="*.pyc;*.pyo;*.rbc;*.yarb;*~;.DS_Store;.git;.hg;.svn;CVS;__pycache__;_svn;vssver.scc;vssver2.scc;.direnv" />
</component>
</application>
EOF
fi
done
'';
home.sessionVariables = { home.sessionVariables = {
GITHUB_ACTOR = "Alexander Heldt"; GITHUB_ACTOR = "Alexander Heldt";
GITHUB_TOKEN = "$(${pkgs.coreutils}/bin/cat ${config.age.secrets.work-github-token.path})"; GITHUB_TOKEN = "$(${pkgs.coreutils}/bin/cat ${config.age.secrets.work-github-token.path})";
@@ -71,7 +25,6 @@ EOF
"IdeaVIM" "IdeaVIM"
"com.github.copilot" "com.github.copilot"
]) ])
pkgs.bashInteractive
(pkgs.google-cloud-sdk.withExtraComponents [ (pkgs.google-cloud-sdk.withExtraComponents [
pkgs.google-cloud-sdk.components.gke-gcloud-auth-plugin pkgs.google-cloud-sdk.components.gke-gcloud-auth-plugin
@@ -82,8 +35,6 @@ EOF
pkgs.postman pkgs.postman
pkgs.grpcurl pkgs.grpcurl
pkgs.slack
# for `radio` # for `radio`
pkgs.go-mockery pkgs.go-mockery
pkgs.golangci-lint pkgs.golangci-lint
-8
View File
@@ -56,14 +56,6 @@ in
initContent = lib.strings.concatStringsSep "\n" [ initContent = lib.strings.concatStringsSep "\n" [
"export KEYTIMEOUT=1" "export KEYTIMEOUT=1"
# Point every interactive shell at openssh's ssh-agent. home-manager's
# session vars set this too, but hm-session-vars runs once and is then
# inherited — so a tmux server that outlives this change (or started
# with the stale gcr socket) hands new panes a dead SSH_AUTH_SOCK.
# Re-exporting the fixed path per-shell keeps every pane on the same
# agent, so each key is only ever prompted for once per session.
''export SSH_AUTH_SOCK="$XDG_RUNTIME_DIR/ssh-agent"''
"bindkey -v '^?' backward-delete-char" "bindkey -v '^?' backward-delete-char"
"bindkey '^a' beginning-of-line" "bindkey '^a' beginning-of-line"
"bindkey '^e' end-of-line" "bindkey '^e' end-of-line"
+14 -16
View File
@@ -21,25 +21,24 @@ in
home-manager.users.alex = { home-manager.users.alex = {
programs.ssh = { programs.ssh = {
enable = true; enable = true;
enableDefaultConfig = false;
settings = { matchBlocks = {
"git.ppp.pm" = { "git.ppp.pm" = {
HostName = "git.ppp.pm"; hostname = "git.ppp.pm";
IdentityFile = "/home/alex/.ssh/alex.tadpole-git.ppp.pm"; identityFile = "/home/alex/.ssh/alex.tadpole-git.ppp.pm";
}; };
"*" = { "*" = {
ForwardAgent = false; forwardAgent = false;
AddKeysToAgent = "no"; addKeysToAgent = "no";
Compression = false; compression = false;
ServerAliveInterval = 0; serverAliveInterval = 0;
ServerAliveCountMax = 3; serverAliveCountMax = 3;
HashKnownHosts = false; hashKnownHosts = false;
UserKnownHostsFile = "~/.ssh/known_hosts"; userKnownHostsFile = "~/.ssh/known_hosts";
ControlMaster = "no"; controlMaster = "no";
ControlPath = "~/.ssh/master-%r@%n:%p"; controlPath = "~/.ssh/master-%r@%n:%p";
ControlPersist = "no"; controlPersist = "no";
}; };
}; };
}; };
@@ -49,7 +48,6 @@ in
mode = "0755"; mode = "0755";
text = '' text = ''
#!${pkgs.bash}/bin/bash #!${pkgs.bash}/bin/bash
[ "$1" = "alex" ] || exit 0
for file in ${authorizedKeysPath}/*; do for file in ${authorizedKeysPath}/*; do
${pkgs.coreutils}/bin/cat "$file" ${pkgs.coreutils}/bin/cat "$file"
done done
@@ -73,7 +71,7 @@ in
KbdInteractiveAuthentication = false; KbdInteractiveAuthentication = false;
}; };
authorizedKeysCommand = "/etc/ssh/authorized_keys_command %u"; authorizedKeysCommand = "/etc/ssh/authorized_keys_command";
authorizedKeysCommandUser = "root"; authorizedKeysCommandUser = "root";
}; };
}; };
@@ -0,0 +1,7 @@
age-encryption.org/v1
-> ssh-ed25519 Pu0HWg rTAkGJbth0WCE8KM50fHaCyXeO/NrmWXiDT/JH9ciAI
kTMVbJRwOSh9Da1O9YYx21/7IdfZrb2OhoOJxNEIKSg
-> ssh-ed25519 +oNaHQ DtMpPTuAjS1GyK2WalNJzErEE1mCos/R5aZyMnun+UQ
B81FnJ5z70HzI6yvqiy6Lhr2X9ZjEi5dhM6u47flujA
--- r9HCFWVU5LBiRBdRwOA1+IRBY1/I/1UeukGtFz7BxWE
TÔK%£žWÔ*&˜İ-&àÛÕ8)|×áॣù Œ¯è07µ¾ªŒúÍòl»ÁQò0†ÒßÔ––ÆÂ]¬¬Û¸”mP”^~ç/þ#†šõæ"ëÀš+ž)ÕY¾n¼@ã჌R§“¨_pÓÂFÜÛ%᤼#
@@ -0,0 +1,7 @@
age-encryption.org/v1
-> ssh-ed25519 Pu0HWg tZ6zAXOBdiWyyUeOZZ66w1ij8xuHY98fvClPn8/jQVs
AVp3Y04vSbnkurqjAouiDojd5IMFVCYyldXv0v4n9W4
-> ssh-ed25519 +oNaHQ KK44MdrfQLZK44eYWpLiTFm3d/bx6WTsHm98MkvhQTw
CYJJWbpHbLQHvzTWLbujg1AZ3KvgCshVUrolPE1hUho
--- aBOxH3rbMriVBctdVGdQXFH/KYWLbweGzda5sN4HJOA
íNo´Ç¡O>š‡æãõ\IÉ#0¬‰õ+Y8ƒvàCS#éO›žÖeGè;-T“d®,V@3” 䛸þ]`Ç\b²Dõ+„ö6½öšð䘤nŠ%‡NÈ’
+7
View File
@@ -0,0 +1,7 @@
age-encryption.org/v1
-> ssh-ed25519 Pu0HWg qmcWFPndrhXlpjBtSsVNARAOHM9UNtfcEvtSGx/BLHY
EdnzUWju9g61idxWmDaaxSZ6ZiVvhFLOKH3hY1Kyk8s
-> ssh-ed25519 +oNaHQ CMBvVWHwVsY89rbdYvVoVeoZlIXLJoIN8xsoqqBnSiA
+xogVU/MBezQzq1rbIOqT5PGNYqM8o0Pmojk2npqT4U
--- mdhPf3weI9cOcaAh9j/CVB+KRfPSRuT678oueeJjdCk
ZñmݹÿÅÓº*ˆŒ9kÀw¶N¯Zh&ÈGô ßkÞÀºÆŸþŸA#ª“lù u¤Qôïù—›ÛîTÔŸ×˜Ž²Ž,ßCV3†Ä µ”
Binary file not shown.
Binary file not shown.
@@ -1,7 +0,0 @@
age-encryption.org/v1
-> ssh-ed25519 wkRvNA GW8mvnaXpspxr78xV0fKhXwHVvReyjvDc0v7uPwhuBI
Rne8JZYVhrTTesSFpRQ/IOZlFIMoX9Wmv5n1Ed7Ehv8
-> ssh-ed25519 +oNaHQ d7utzodGQ7LsD2Uht1rbT8Qq9BZp3PkJS9EDhajCjnk
qd2Vj+1TQrjEKkSVAf0cXcCdkgeN/Jbp4UrBSp3cKYQ
--- JQr5UQlutONqnTeoT/mIVZL8ME7ipUDK8zDfNcN3uhU
ø5-VŸÌ²ÂòÀ-®ªÁÅ'^žô5kú.t(d1‡)É'<u%
@@ -1,7 +0,0 @@
age-encryption.org/v1
-> ssh-ed25519 wkRvNA 5bEWAlzS34w3tMqMCTRqFoni4MKyQCcaBdEQ96BccVk
85rIfjpzL/cNx5SlpKeOUzsMl0rwvCdPgrZ0jlXE1nQ
-> ssh-ed25519 +oNaHQ d2ZZ/XQ5fgT8FMwhyfWHB5FESXM0Y9tlE1KcWwQV7HY
bCj5fLqN2zfPBcnXaJAYJYA+PXTPAdLZVy2FinZvUTM
--- vxopGi8/YrgI/VceX807yk7edWrdYgjmGYG9Zp/cuQA
žFc˜ÖÂ|ª67Ñ~uðáúÉ€Wê–ÿ’eïó‰ÍVMj5‹ÜG?³JâË_pîcf57^ƒŒ¥r@g&?„¬4ŠþÎðˆÉ‘@ƒN…œsjZ¡Šé^-âyB{\ºÔñ3«ˆýT)³ž¯uÝ\Wa\àìB)@d ™vrì8q.kÚ™˜
@@ -1,7 +0,0 @@
age-encryption.org/v1
-> ssh-ed25519 wkRvNA ykXbxHlehL+AucBCiS7NKNOWjHm51ZTbfgM7fPU+QDo
FtPBWg91yWq90n4PkzdwpIq+DnwL+nwUNzH3mQP4lgg
-> ssh-ed25519 +oNaHQ fCNig/NdBmbZqicNhSnYKz7Rmc7S2JpN+sQ50o+QFg0
AQiKSjZMsjuJGsnZWjSNePrbXBQ/f1zhNCXLznbZk1w
--- zjW49MAgjerHuHqMrSSDpgkWLD40eMSr+ZkKZ0Y9pJo
؇¯O¹Þ°}Œ/¨ïd°° ü‹ªŠÒ°ø@²ÆuJðÍz§bíïü:Yñ‚fýúë›
@@ -1,7 +0,0 @@
age-encryption.org/v1
-> ssh-ed25519 wkRvNA 1U7rIOHezvIpeb7QBkwz+NOgagrPDltkFtWY2N/hdE4
9rLqhxhc4c7cGB9hDPy9r0y5QbDp0CcYFwIWczB0mlU
-> ssh-ed25519 +oNaHQ w9QggF6DOTSMUC5n+7OKpFOM8iDSQakgx/10pIhM9ws
GOk7OQpLh5OjyZTiJQxd7hhN93EcSMnMxueNh6AwCOk
--- mzQrbeaXCVPu0MqNC0iAMLCiZbopyfYanwhsgDjFbZE
¡&ÈEÆÝ¼žÊÆ öfh(tJn´Ð†ç$^åkì[ Cå )ÉŸN¾UÚW¿üt/ræ7'NU
@@ -1,7 +0,0 @@
age-encryption.org/v1
-> ssh-ed25519 wkRvNA T7nivShTgBPRAWTTOUYWfCWNAFlQ5e6rlB92XV/xRVM
JJrxtTSteza0sCOJVz4z8y/8npX3hWhfo8y85UFAU80
-> ssh-ed25519 +oNaHQ DuAtW/id53RC4G4EKWr2y1G8K7UbI5r1vGf1ICG5pC8
xkkGeHOjMmuJ0mKnziUALSEJpV/fVUX5oOBiTptuapo
--- aVjxHPHDuWLhSPMKG5wE67YIzR18LKihrcPqYC+8bnM
…Ób”áõˆ–3qÆó|À7܇È}žÀœŠMí ;† [ LH% Úr‰ævdTíþY….¯t¾Ì©zFÒ*©3-±D¾ð:¾Š©Y>ûòÀþõò“Tn2Fž¡HJŽM_¶éŒ{$ÑOUšä˜º,ìÝÑ•”k*l¢D¥^ÏTd+®† 
Binary file not shown.
-7
View File
@@ -1,7 +0,0 @@
age-encryption.org/v1
-> ssh-ed25519 wkRvNA eL6ZQuNPvdO0gHEW5IObuLQzcOFpOaxzw/wcYvuxfUs
M88b5Ex9I3XY29oYML73BM/0TLo+e4pGG008M2VloKM
-> ssh-ed25519 +oNaHQ hIzDhww0WePNFVdvTwGL9wsOWN9r0ZiUmYkjb82KeQg
DwwCiFXFbYQV64JuRc8pc997CY+2rZxC8cRdTvHPSqA
--- u37YqZsBBtrxZ0Wmw6QJWgazNbqW00GVsQgyRxE41Gc
-bpP ÷W.²ˆ-»:ˆNÕûc¦~‡géHu\¸MaX·prACæU)¾lÓá:—+Û\X\í<N¸ J`"­Þðo»éDÆtOÂ8²å…
Binary file not shown.
Binary file not shown.
@@ -1,8 +0,0 @@
age-encryption.org/v1
-> ssh-ed25519 wkRvNA 5d22LU+2Mn6fq8SHOCwDht/ebnI2uOk6WKf+t1kwwCM
hCGnLoCy1PX5PJx2IjQnyESmtKM6wVQmyS6aHNhkb1g
-> ssh-ed25519 +oNaHQ gPUMsavbGVPOuvTtNgoDuzrT+q0I7Wbkd6QK5z4oUGc
M3HhrugFlNQkL7WxF1qrW+ocGRqOXid32AVVYLSSxPI
--- TGURCDEIuSFCfXBHxzFHA2svHES7Ubagy1uYjbWCO7g
gá¿Ó†Ò™±£Qâö
oF[H:t aÆr3úZ0ßx @:˜0Ó´¡µÂI[Õ\í=º@eâPíW€Ã†§rX,¶âÈÇ*sš$c:FlÎÙ ±z|B# päZ4ns[Ó×%\ìP±­;ÞR㣧ô$9¤7íÏÔAŠœÖ0©.xç°¾9©,ýt+ ¥ šf±AÉ)mV
Binary file not shown.
-8
View File
@@ -1,8 +0,0 @@
age-encryption.org/v1
-> ssh-ed25519 wkRvNA 11epAkGKr0IpXqtWGQ73rZUsiWQRlL++fc2B2TvQ90M
lSKGeNiL82UIyhg1wrY9ylltFcITDffJLgA6j02eS2M
-> ssh-ed25519 +oNaHQ pg1rC56bQRxO2Eb5onV8TkeB/Wsc7HhvufBfslkK+gA
znYqNOBhQX9bx5k07vVTHye/RLxOAkQ2dCagZWyWBkQ
--- Dxthx4NFJfe26jFnXH/3NYILME+tlO2FUsSVGCP4ucY
°]œê&Ì¥ü…²+/ªÖ×Dš‘ô[6HIÂe>™“‚¾Û¡1Ak¬’ä4ZHG
T}o8×f<Û¦r<Â
Binary file not shown.
Binary file not shown.
+7 -6
View File
@@ -1,7 +1,8 @@
age-encryption.org/v1 age-encryption.org/v1
-> ssh-ed25519 vxPbZg GMTnaun91WNPRFQYkN7xPqdALyMQpXCOq6jj4Q4O1Q0 -> ssh-ed25519 vxPbZg bCF+MdTMA8jH26XEosgyd5N0RsTa9WT/VAIZGsVemHg
OyA/Zk7KQlbSyJlXETFh4JZ57S92oXULa9/mgC019PE 1DNCO2mpsJ68osmFZIzAlY6kjoxCbThpSI4XNEyUNjY
-> ssh-ed25519 +oNaHQ C0K34MjLZDIKv6ci2efBxv1nfvuHKn9OCj26DxjtmBo -> ssh-ed25519 +oNaHQ L91QfGk0r81Df5fHWHdrvXJ54FJ+3S30vus/h4v/H2k
tMG+KxpFX2K8F34iNxDBpb2epd94QPFWo8X/mY67LEI Vi/5VdJhl72cwLiD2qxbmQiKD0RPb4vv6VddGWrPvF4
--- FBMSSr82MYSwER9O8dEs3o2vy/+rc29DxUuziFZqYzw --- F8ff4nu9K9cXId34L2RMBzH4vE3efIuzISN1spbvDHo
l'c(êˆ6 ônnxgA7j"%ÎIÂ'¢{úH¯˜@Þ™vä°ÔêyŸåJûT°©ˆ¼)ÇÃ…¿nSÝ&ìÉš¦e;õ 4zNº½„K U¤Á€,d”Cñæ®®U;Dc«.x` Wû[u E´Ñ KÙŒ¬Ë­âey¾z’ÛŸ%Œ]­Ÿ…˜m®s÷«¥úb°U×qX{¸±‹!©(u‹|ø!œ_‘}˜íÿ<ùÓ#ù–ÞºˆžXU^¸üs”W­´wñNÐÆU×ù¥D
ú˜
+5 -14
View File
@@ -17,8 +17,6 @@ in {
"pinwheel/alex.pinwheel-tadpole.pub.age".publicKeys = [ pinwheel tadpole alex ]; "pinwheel/alex.pinwheel-tadpole.pub.age".publicKeys = [ pinwheel tadpole alex ];
"pinwheel/alex.pinwheel-github.com.age".publicKeys = [ pinwheel alex ]; "pinwheel/alex.pinwheel-github.com.age".publicKeys = [ pinwheel alex ];
"pinwheel/alex.pinwheel-github.com.pub.age".publicKeys = [ pinwheel alex ]; "pinwheel/alex.pinwheel-github.com.pub.age".publicKeys = [ pinwheel alex ];
"pinwheel/alex.pinwheel-github.com-signing.age".publicKeys = [ pinwheel alex ];
"pinwheel/alex.pinwheel-github.com-signing.pub.age".publicKeys = [ pinwheel alex ];
"pinwheel/alex.pinwheel-git.ppp.pm.age".publicKeys = [ pinwheel alex ]; "pinwheel/alex.pinwheel-git.ppp.pm.age".publicKeys = [ pinwheel alex ];
"pinwheel/alex.pinwheel-git.ppp.pm.pub.age".publicKeys = [ pinwheel alex ]; "pinwheel/alex.pinwheel-git.ppp.pm.pub.age".publicKeys = [ pinwheel alex ];
@@ -36,23 +34,16 @@ in {
"manatee/syncthing-key.age".publicKeys = [ manatee alex ]; "manatee/syncthing-key.age".publicKeys = [ manatee alex ];
"manatee/hetzner-dns.age".publicKeys = [ manatee alex ]; "manatee/hetzner-dns.age".publicKeys = [ manatee alex ];
"manatee/komga-comicbooktracker-credentials.age".publicKeys = [ manatee alex]; "manatee/komga-comicbooktracker-credentials.age".publicKeys = [ manatee alex];
"manatee/komga-bookmanager-credentials.age".publicKeys = [ manatee alex];
"manatee/komga-reading-stats-claude-api-key.age".publicKeys = [ manatee alex];
"manatee/komga-reading-stats-komga-api-key.age".publicKeys = [ manatee alex];
"manatee/romm-auth-secret-key.age".publicKeys = [ manatee alex ];
"manatee/romm-db-password.age".publicKeys = [ manatee alex ];
"manatee/romm-metadata-api-keys.age".publicKeys = [ manatee alex ];
"manatee/puppy-tracker-invite-code.age".publicKeys = [ manatee alex ];
"manatee/solo-referee-api-key.age".publicKeys = [ manatee alex ];
"manatee/todo-token.age".publicKeys = [ manatee alex ];
"manatee/restic-password.age".publicKeys = [ manatee alex ];
"manatee/restic-cloud-sync-key.age".publicKeys = [ manatee alex ];
"manatee/restic-cloud-sync-repository.age".publicKeys = [ manatee alex ];
"backwards/root.backwards.age".publicKeys = [ backwards alex ]; "backwards/root.backwards.age".publicKeys = [ backwards alex ];
"backwards/root.backwards.pub.age".publicKeys = [ backwards alex ]; "backwards/root.backwards.pub.age".publicKeys = [ backwards alex ];
"backwards/alex.backwards-manatee.age".publicKeys = [ backwards alex ]; "backwards/alex.backwards-manatee.age".publicKeys = [ backwards alex ];
"backwards/alex.backwards-manatee.pub.age".publicKeys = [ backwards manatee alex ]; "backwards/alex.backwards-manatee.pub.age".publicKeys = [ backwards manatee alex ];
"backwards/syncthing-cert.age".publicKeys = [ backwards alex ];
"backwards/syncthing-key.age".publicKeys = [ backwards alex ];
"backwards/restic-password.age".publicKeys = [ backwards alex ];
"backwards/restic-cloud-sync-key.age".publicKeys = [ backwards alex ];
"backwards/restic-cloud-sync-repository.age".publicKeys = [ backwards alex ];
"backwards/alex.backwards-git.ppp.pm.age".publicKeys = [ backwards alex ]; "backwards/alex.backwards-git.ppp.pm.age".publicKeys = [ backwards alex ];
"backwards/alex.backwards-git.ppp.pm.pub.age".publicKeys = [ backwards alex ]; "backwards/alex.backwards-git.ppp.pm.pub.age".publicKeys = [ backwards alex ];
"backwards/wireless-network-secrets.age".publicKeys = [ backwards alex ]; "backwards/wireless-network-secrets.age".publicKeys = [ backwards alex ];
+1
View File
@@ -4,6 +4,7 @@
phone = "WLDQC7C-EFOW5HM-R3PULLO-ZMADECF-6FK73FD-FRK5NF4-J6UB7DY-7B4DFQR"; phone = "WLDQC7C-EFOW5HM-R3PULLO-ZMADECF-6FK73FD-FRK5NF4-J6UB7DY-7B4DFQR";
pinwheel = "AKS5L2A-NFCG5GV-3U5SSSZ-PLOX6BQ-ZL5ALXI-D7OK4KE-R2JPWRJ-B6AQJQ7"; pinwheel = "AKS5L2A-NFCG5GV-3U5SSSZ-PLOX6BQ-ZL5ALXI-D7OK4KE-R2JPWRJ-B6AQJQ7";
manatee = "6YDVLXR-NZV6XKD-ASWPZQS-WKBRHAD-52JV5HU-JEPQ32G-6RGY7KJ-OVBO7AM"; manatee = "6YDVLXR-NZV6XKD-ASWPZQS-WKBRHAD-52JV5HU-JEPQ32G-6RGY7KJ-OVBO7AM";
backwards = "XRSQ4NZ-LHCZS6H-R3A75S5-W4FH7F4-3DGA5X2-SOPYWOP-A2WRKGC-IPXH4AM";
tablet = "5BEPSWB-BN4MDZM-7W3ITMP-KJ53J6M-WJMLWEF-GTDJTWI-C4C5SPQ-SFS3DAY"; tablet = "5BEPSWB-BN4MDZM-7W3ITMP-KJ53J6M-WJMLWEF-GTDJTWI-C4C5SPQ-SFS3DAY";
}; };
}; };