❄️ My Nix OS configuration files.
  • Nix 96.6%
  • Lua 3.4%
Find a file
2026-10-05 04:21:01 +07:00
.pi migrate Forgejo runner configuration 2026-10-05 04:21:01 +07:00
home-manager migrate Forgejo runner configuration 2026-10-05 04:21:01 +07:00
hosts migrate Forgejo runner configuration 2026-10-05 04:21:01 +07:00
modules Initial commit: NixOS + Home Manager flake 2026-09-09 20:14:23 +07:00
overlays Initial commit: NixOS + Home Manager flake 2026-09-09 20:14:23 +07:00
pkgs migrate Forgejo runner configuration 2026-10-05 04:21:01 +07:00
secrets migrate Forgejo runner configuration 2026-10-05 04:21:01 +07:00
.gitignore Stop tracking flake.lock, remove nixos-wsl input 2026-09-14 13:26:00 +07:00
.pre-commit-config.yaml Initial commit: NixOS + Home Manager flake 2026-09-09 20:14:23 +07:00
.sops.yaml Initial commit: NixOS + Home Manager flake 2026-09-09 20:14:23 +07:00
AGENTS.md refactor nix configuration and agent guidance 2026-09-29 19:43:19 +07:00
flake.nix refactor nix configuration and agent guidance 2026-09-29 19:43:19 +07:00
LICENSE Initial commit: NixOS + Home Manager flake 2026-09-09 20:14:23 +07:00
README.md refactor nix configuration and agent guidance 2026-09-29 19:43:19 +07:00
shell.nix Initial commit: NixOS + Home Manager flake 2026-09-09 20:14:23 +07:00

NixOS configuration

Personal NixOS + Home Manager flake for two machines. Secrets use sops-nix.

Hosts

  • ideapad — laptop with AMD graphics, btrfs/LUKS, TPM2, Lanzaboote Secure Boot and niri.
  • homelab — Proxmox VM with the self-hosted stack (nginx, Forgejo, Vaultwarden, Authelia, OpenCloud, Open WebUI and media services).

Layout

Path Purpose
hosts/<name>/ Host-specific NixOS configuration
hosts/common/ Shared NixOS modules
home-manager/bagoont/ User and per-host configuration
home-manager/common/ Reusable user modules
modules/ Publishable parameterized modules
pkgs/, overlays/ Local packages and overlays
secrets/ Encrypted sops/age secrets

Development

Entering the repository with direnv loads shell.nix (run direnv allow once). It provides pre-commit, mcp-nixos and forgejo-mcp.

nix fmt -- <changed-files>                         # format with alejandra
nix fmt -- --check <changed-files>                 # check formatting
nix flake check                                    # evaluate flake checks
nixos-rebuild dry-build --flake .#ideapad          # or .#homelab

Nix evaluation sees only Git-tracked files. Add new files before running checks. Do not run activation commands from automation; use switch only when deliberately applying a reviewed configuration on the target host.

ideapad: one-time Secure Boot setup

The machine-specific configuration enables Lanzaboote, TPM2 and encrypted disks. After configuring firmware keys, use sbctl create-keys and sbctl enroll-keys --microsoft as appropriate. Enroll each declared LUKS device with systemd-cryptenroll --tpm2-device=auto /dev/disk/by-uuid/<luks-uuid>. Keep the LUKS passphrase as a fallback and verify boot before enabling Secure Boot.