Commit graph

113 commits

Author SHA1 Message Date
220d1f651c heather: replace k3s with docker+arion+caddy+syncthing
- remove k3s.nix (1.3GB overhead unjustified for single-node)
- add docker.nix (docker + arion CLI, mikl in docker group)
- add caddy.nix (edge proxy, TLS via ACME staging, host-based routing)
- add syncthing.nix (sync daemon + strelaysrv via systemd, /srv/syncthing)
- add arion-compose.nix (forgejo first, others stubbed as TODO)
- add arion flake input + nixos module
- default.nix: wire up arion project as systemd service (serviceName=heather)

Architecture: Caddy (host) terminates TLS, routes to host services (syncthing)
and docker containers (arion, 127.0.0.1:PORT). Named volumes everywhere except
silverbullet (bind /srv/syncthing/herbarium).
2026-07-12 12:23:05 +03:00
c8b87ffcf1 git: use canonical git-lfs filter strings to fix 3.7 warning 2026-07-12 01:28:20 +03:00
2cbca9a665 heather: add root rescue ssh key (mikl.keys) to avoid lockout 2026-07-11 22:57:29 +03:00
411a8ba689 heather/common: passwordless sudo for mikl + fix deprecated options
- common/default.nix: add mikl to wheel + security.sudo.wheelNeedsPassword=false.
  Without this, root is unreachable on a fresh NixOS-yc image (no root password,
  no rescue channel) — nixos-rebuild switch is impossible. Mirrors the
  NOPASSWD:ALL that old YC boxes got via cloud-config user-data.
- home/server.nix: programs.git.extraConfig -> .settings, programs.git.delta
  -> programs.delta with enableGitIntegration=true (deprecated warnings).
- image.nix: boot.loader.grub.timeout -> boot.loader.timeout (renamed option).
2026-07-11 22:55:00 +03:00
79260cec6f heather: switch to make-disk-image (qcow2 for YC), drop disko
- Rename muscari -> heather (YC VM). rosemary reserved for future EU server.
- Add hosts/heather/image.nix: YC guest profile + qcow2 build target based on
  nixos/lib/make-disk-image.nix (the nixpkgs-standard cloud image builder).
  partitionTableType=legacy (MBR + single ext4 root, label nixos), GRUB in MBR
  on /dev/vda, virtio drivers, console=ttyS0, cloud-init (Ec2 datasource) so
  poppy ssh key auto-lands from YC metadata, growPartition.
- Drop disko flake input + disk-config.nix (was only for nixos-anywhere runtime
  install; replaced by make-disk-image build-time approach, no kexec).
- Add home/server.nix: minimal headless home for NixOS hosts (no ollama/
  texliveFull/kitty/syncthing/pass). flake mkNixos uses it instead of full ./home.
- k3s.nix: drop dead firewall block (firewall off in image.nix -> trustedInterfaces
  was a no-op). Cilium manages pod networking via BPF.
- image.baseName=heather, configurationLimit=1, remove virtio dups (qemu-guest
  profile already provides most).
- Fix sha256 pin on forgejo mikl.keys (was stale, would break fetchurl).
- home/zsh.nix: source yandex-cloud yc completion.
2026-07-11 21:13:38 +03:00
c21268fb9b fix: use homebrew node instead of nix read-only nodejs
- nodejs from nixpkgs is read-only, breaks pi-coding-agent internal npm install
- Use homebrew node (writable) for proper npm/pnpm global installs
- Remove pi-node hardcoded path hack from PATH
2026-07-10 23:20:02 +03:00
5ac51e1f7f feat: add nodejs for pi-coding-agent runtime 2026-07-10 23:12:52 +03:00
e2e05923e0 feat(poppy): add tea (Forgejo/Gitea CLI) to brews 2026-07-10 23:11:09 +03:00
723b0112a3 refactor: use home.sessionPath instead of hardcoded PATH
- Replace hardcoded PATH with home.sessionPath for proper ordering
- Use ${config.home.homeDirectory} and ${config.home.username} for portability
- Add PNPM_HOME for pnpm global packages
- Remove hardcoded node version path (install pi via pnpm i -g)
2026-07-10 16:28:07 +03:00
03f3a2c156 fix: add /nix/var/nix/profiles/default/bin to PATH for nix command 2026-07-10 16:22:41 +03:00
ee93330eea fix: remove duplicate PATH export from zsh, use sessionVariables only 2026-07-10 16:17:40 +03:00
9c299b26ca chore: disable zsh history file, use atuin exclusively 2026-07-10 16:05:25 +03:00
5e1a7a173b docs: update bootstrap with correct repo paths 2026-07-10 15:59:00 +03:00
1b1069996f fix: add system paths to PATH for mv, nix, darwin-rebuild etc. 2026-07-10 15:54:21 +03:00
e6ed1d8c3b feat: add atuin for encrypted shell history 2026-07-10 15:49:47 +03:00
dee3e58978 fix: correct pass git repository path 2026-07-10 15:43:24 +03:00
a269b2856f dock: add Activity Monitor after kitty 2026-07-04 01:11:39 +03:00
3e57916a3f system: disable system sound effects (screenshots, volume feedback) 2026-07-04 01:03:53 +03:00
2b5dce5727 kitty: copy app to ~/Applications/ for Spotlight indexing; update Dock path 2026-07-04 00:54:10 +03:00
a689d23a8e ssh: use single 'poppy' key for all hosts (others don't exist yet) 2026-07-04 00:51:00 +03:00
ab376d21aa cleanup: remove k8s/sops env vars (muscari-specific), dedupe tree, update AGENTS.md 2026-07-04 00:47:38 +03:00
f4a516aa5c feat(poppy): add automatic Rosetta 2 installation for Intel apps 2026-07-04 00:25:13 +03:00
a465daa9c7 refactor: migrate user from michaotic to mikl 2026-07-03 21:41:42 +03:00
514090fced docs: add AGENTS.md for AI agents 2026-07-02 21:48:36 +03:00
475a103fad feat: replace markedit with mark-text; clean up temp.txt 2026-07-02 15:31:48 +03:00
02bfb2735b feat: add apps.md, comment out aseprite (compile on first build) 2026-07-02 14:54:19 +03:00
5d1f0f59cb fix: remove pureref (not available on aarch64-darwin) 2026-07-02 14:45:54 +03:00
2a74d64f74 fix: use environment.systemPackages (not home.packages) in nix-darwin 2026-07-02 14:45:34 +03:00
ec0e60a835 refactor: rename homebrew.nix to apps.nix (add nix GUI pkgs, cleanup=none) 2026-07-02 14:45:15 +03:00
fdabb69c73 docs: add anki sync server to muscari TODO 2026-07-02 13:29:15 +03:00
87cdc4ea21 fix: syncthing 2.x uses 'serve' subcommand instead of -no-browser 2026-07-02 13:09:40 +03:00
5cdc1d9ad6 fix: import syncthing.nix in default.nix 2026-07-02 13:06:57 +03:00
7479bb07a1 feat: add syncthing via nix (with existing config) 2026-07-02 13:06:05 +03:00
754024d915 docs: add ssh.md (keys, FIDO2, recovery) 2026-07-02 02:02:05 +03:00
77cc3cfba1 refactor: remove duplicate gpg-agent config (keep only in pass.nix) 2026-07-02 01:18:32 +03:00
2a395c6814 refactor: separate ssh-agent from gpg-agent 2026-07-02 01:11:51 +03:00
2164f618f4 feat: add gita (multi-repo git manager) + aliases 2026-07-01 23:49:38 +03:00
2ca3aa219d fix: remove broken passOrigins activation (builtins.toFile limitation) 2026-07-01 23:31:54 +03:00
6b3982f156 refactor: remove credential helper (we use SSH) 2026-07-01 23:31:14 +03:00
55a2181d58 docs: add todos for git remotes and pass-store sync 2026-07-01 18:53:33 +03:00
df2d756a08 refactor: separate pass (package) from pass-store (git remotes) 2026-07-01 18:45:06 +03:00
eec7efabd1 feat: add ssh.nix with matchBlocks, pass origins (forgejo+github+solmoe) 2026-07-01 18:43:33 +03:00
e9ddbc5d0e fix: use nested attribute for credential config 2026-07-01 17:19:25 +03:00
203630ca60 fix: merge extraConfig into settings (deprecated extraConfig) 2026-07-01 17:16:42 +03:00
666f10ad06 feat: complete git.nix with LFS, credentials, gpg, aliases 2026-07-01 17:16:04 +03:00
c293fc929e docs: add bootstrap guide for fresh macOS setup 2026-07-01 17:12:55 +03:00
f142bdc1da fix: temporarily remove broken activation script 2026-07-01 16:43:46 +03:00
43e6ca3e99 test: no unicode in pass activation 2026-07-01 16:42:29 +03:00
3a0dbcca71 fix: simpler activation without pkgs interpolation 2026-07-01 16:41:01 +03:00
06433e4d9f fix: use mikl@iscg.dev for GPG and git (was michaotic) 2026-07-01 16:37:59 +03:00