Commit graph

96 commits

Author SHA1 Message Date
483454bf17 heather: rotate sync.iscg.dev basicauth password
Старый хеш был скопирован с iscg-dev, пароль неизвестен. Новый пароль
в mindful-стиле. Сгенерирован через caddy hash-password (bcrypt cost 14).
2026-07-12 18:05:22 +03:00
6324d3b676 heather: make strelaysrv private (pools="")
Relay больше не регистрируется в public pool relays.syncthing.net.
Чужие syncthing-устройства не подключаются, трафик не возим.
Свои устройства могут использовать relay://heather:22067 если прописан в config.
2026-07-12 17:55:52 +03:00
4eb5a1e61c heather: switch caddy to production ACME (DNS moved to heather) 2026-07-12 13:21:25 +03:00
ebf74814bf heather: fix arion volumes declaration + syncthing configDir perms
- arion-compose: project.name (required) + docker-compose.volumes (correct
  option, was docker-compose.raw.volumes which didn't exist)
- syncthing: tmpfiles for /var/lib/syncthing (configDir) owned by mikl,
  fixes 'mkdir /var/lib/syncthing: permission denied' when running as non-default user
2026-07-12 12:39:26 +03:00
220d1f651c heather: replace k3s with docker+arion+caddy+syncthing
- remove k3s.nix (1.3GB overhead unjustified for single-node)
- add docker.nix (docker + arion CLI, mikl in docker group)
- add caddy.nix (edge proxy, TLS via ACME staging, host-based routing)
- add syncthing.nix (sync daemon + strelaysrv via systemd, /srv/syncthing)
- add arion-compose.nix (forgejo first, others stubbed as TODO)
- add arion flake input + nixos module
- default.nix: wire up arion project as systemd service (serviceName=heather)

Architecture: Caddy (host) terminates TLS, routes to host services (syncthing)
and docker containers (arion, 127.0.0.1:PORT). Named volumes everywhere except
silverbullet (bind /srv/syncthing/herbarium).
2026-07-12 12:23:05 +03:00
2cbca9a665 heather: add root rescue ssh key (mikl.keys) to avoid lockout 2026-07-11 22:57:29 +03:00
411a8ba689 heather/common: passwordless sudo for mikl + fix deprecated options
- common/default.nix: add mikl to wheel + security.sudo.wheelNeedsPassword=false.
  Without this, root is unreachable on a fresh NixOS-yc image (no root password,
  no rescue channel) — nixos-rebuild switch is impossible. Mirrors the
  NOPASSWD:ALL that old YC boxes got via cloud-config user-data.
- home/server.nix: programs.git.extraConfig -> .settings, programs.git.delta
  -> programs.delta with enableGitIntegration=true (deprecated warnings).
- image.nix: boot.loader.grub.timeout -> boot.loader.timeout (renamed option).
2026-07-11 22:55:00 +03:00
79260cec6f heather: switch to make-disk-image (qcow2 for YC), drop disko
- Rename muscari -> heather (YC VM). rosemary reserved for future EU server.
- Add hosts/heather/image.nix: YC guest profile + qcow2 build target based on
  nixos/lib/make-disk-image.nix (the nixpkgs-standard cloud image builder).
  partitionTableType=legacy (MBR + single ext4 root, label nixos), GRUB in MBR
  on /dev/vda, virtio drivers, console=ttyS0, cloud-init (Ec2 datasource) so
  poppy ssh key auto-lands from YC metadata, growPartition.
- Drop disko flake input + disk-config.nix (was only for nixos-anywhere runtime
  install; replaced by make-disk-image build-time approach, no kexec).
- Add home/server.nix: minimal headless home for NixOS hosts (no ollama/
  texliveFull/kitty/syncthing/pass). flake mkNixos uses it instead of full ./home.
- k3s.nix: drop dead firewall block (firewall off in image.nix -> trustedInterfaces
  was a no-op). Cilium manages pod networking via BPF.
- image.baseName=heather, configurationLimit=1, remove virtio dups (qemu-guest
  profile already provides most).
- Fix sha256 pin on forgejo mikl.keys (was stale, would break fetchurl).
- home/zsh.nix: source yandex-cloud yc completion.
2026-07-11 21:13:38 +03:00
c21268fb9b fix: use homebrew node instead of nix read-only nodejs
- nodejs from nixpkgs is read-only, breaks pi-coding-agent internal npm install
- Use homebrew node (writable) for proper npm/pnpm global installs
- Remove pi-node hardcoded path hack from PATH
2026-07-10 23:20:02 +03:00
e2e05923e0 feat(poppy): add tea (Forgejo/Gitea CLI) to brews 2026-07-10 23:11:09 +03:00
a269b2856f dock: add Activity Monitor after kitty 2026-07-04 01:11:39 +03:00
3e57916a3f system: disable system sound effects (screenshots, volume feedback) 2026-07-04 01:03:53 +03:00
2b5dce5727 kitty: copy app to ~/Applications/ for Spotlight indexing; update Dock path 2026-07-04 00:54:10 +03:00
f4a516aa5c feat(poppy): add automatic Rosetta 2 installation for Intel apps 2026-07-04 00:25:13 +03:00
a465daa9c7 refactor: migrate user from michaotic to mikl 2026-07-03 21:41:42 +03:00
475a103fad feat: replace markedit with mark-text; clean up temp.txt 2026-07-02 15:31:48 +03:00
02bfb2735b feat: add apps.md, comment out aseprite (compile on first build) 2026-07-02 14:54:19 +03:00
5d1f0f59cb fix: remove pureref (not available on aarch64-darwin) 2026-07-02 14:45:54 +03:00
2a74d64f74 fix: use environment.systemPackages (not home.packages) in nix-darwin 2026-07-02 14:45:34 +03:00
ec0e60a835 refactor: rename homebrew.nix to apps.nix (add nix GUI pkgs, cleanup=none) 2026-07-02 14:45:15 +03:00
55a2181d58 docs: add todos for git remotes and pass-store sync 2026-07-01 18:53:33 +03:00
7b8682f3d9 feat: remove bitwarden, add pass-sync aliases (git push/pull/status) 2026-07-01 15:41:06 +03:00
93bc0d0c02 revert: remove MarkEdit theme/MTE extensions config 2026-07-01 14:37:55 +03:00
9b54c129a2 fix: use full paths in MarkEdit activation script 2026-07-01 14:35:19 +03:00
dcddd60c32 feat: configure MarkEdit catppuccin theme via activation script 2026-07-01 14:33:31 +03:00
b2e3092c2e fix: remove TrackpadTwoFingerDoubleTapGesture (boolean type) 2026-07-01 13:42:18 +03:00
47a4d83fce fix: move duti activation script from home to poppy host 2026-07-01 13:39:46 +03:00
3ca861bd33 feat: add markedit and duti for default apps management 2026-07-01 13:38:25 +03:00
b3c3a865e1 fix: remove unsupported TrackpadScroll 2026-07-01 13:09:21 +03:00
5501fb5a31 fix: remove unsupported TrackpadHorizScroll 2026-07-01 13:09:06 +03:00
8f936fb4ac fix: remove unsupported TrackpadHandResting 2026-07-01 13:08:58 +03:00
23076d8010 fix: remove unsupported trackpad/finder/nsglobal options 2026-07-01 13:08:42 +03:00
2afdb54dcb fix: remove unsupported FXPreferredGroupBy 2026-07-01 13:06:39 +03:00
f844365d30 fix: remove unsupported AppleMiniaturizeOnDoubleClick 2026-07-01 13:06:27 +03:00
7475e188dd fix: move AppleMenuBarVisibleInFullscreen back to CustomUserPreferences 2026-07-01 13:06:16 +03:00
038196166e fix: remove unsupported AppleLanguages option 2026-07-01 13:05:30 +03:00
eb0a6135bc fix: remove unsupported AppleAntiAliasingThreshold option 2026-07-01 13:05:10 +03:00
65319be12b feat: sync all current macOS system defaults from running system 2026-07-01 13:04:51 +03:00
c3e687c07b feat: add pnpm with pi-coding-agent, remove tw93/tap and mole 2026-07-01 01:13:15 +03:00
176508bc74 fix: add backupFileExtension, remove typewhisper from taps 2026-06-29 19:19:30 +03:00
e358c2cb15 refactor: split poppy config into homebrew.nix, system.nix, default.nix 2026-06-29 16:33:53 +03:00
cecb47ceb9 fix: add homebrew config to prevent cask deletion 2026-06-29 00:43:51 +03:00
5c14cf0539 refactor: use michaotic username throughout, add cli/kitty/zsh configs and docs 2026-06-28 23:54:14 +03:00
1f960a53a5 muscari: add NixOS host config adapted from nix-config-legacy
Migrated muscari from nix-config-legacy (preserved for reference per
garden.md) to new multi-host flake structure.

Includes:
- hosts/muscari/default.nix: hostname, GRUB (BIOS), firewall
  (22/80/443), SSH keys via forgejo .keys endpoint with sha256 pinning,
  stateVersion 25.11
- hosts/muscari/disk-config.nix: disko config — 512M ESP + ext4 root,
  device = /dev/vda (YC standard-v3 single virtio disk)
- hosts/muscari/k3s.nix: k3s single-node with --flannel-backend=none
  (Cilium to be installed separately via Helm)

Architecture decisions (unchanged from legacy):
- Bootloader: GRUB (VM is in Legacy BIOS mode — see PREREQUISITES.md
  check 5+11 in projects/servers/muscari/)
- Filesystem: ext4 root + vfat ESP (ESP unused in BIOS but ready if
  ever switched to UEFI)
- Build deps: nixpkgs/nixos-25.11

Verification (after commit):
- nix flake show: nixosConfigurations.{muscari,rosemary} OK
- muscari.networking.hostName = "muscari"
- muscari.boot.loader.grub.enable = true
- muscari.boot.loader.systemd-boot.enable = false
- muscari.services.k3s.enable = true
- fileSystems derived correctly from disko
- poppy (darwin) and rosemary (NixOS) configs untouched

Session: verify plan
2026-06-27 03:14:16 +03:00
mikl
c95e4a1488 inline common-darwin into poppy (only one darwin host for now)
- merged common-darwin/default.nix content into hosts/poppy/default.nix
- removed hosts/common-darwin/
- removed ./hosts/common-darwin import from mkDarwin in flake.nix

linux hosts/common/ stays — already 2 linux hosts (muscari + rosemary)
2026-06-26 23:39:58 +03:00
mikl
42fdbeb1a0 initial scaffold: multi-host flake (poppy, muscari, rosemary)
- flake.nix with mkNixos + mkDarwin dispatchers
- hosts/common/{default.nix} (NixOS shared)
- hosts/common-darwin/{default.nix} (darwin shared)
- hosts/poppy/ (M1 MacBook Air, nix-darwin)
- hosts/muscari/ (k3s server, placeholder)
- hosts/rosemary/ (backup VM, placeholder)
- home/default.nix (home-manager for mikl)
- README.md, garden.md (host naming scheme: plants)
- secrets/.gitkeep

old muscari-only config moved to nix-config-legacy/
2026-06-26 23:28:31 +03:00