Compare commits

...
63 Commits
Author SHA1 Message Date
samw 344f52c05b ssh: connection sharing thing 2026-07-02 11:13:49 +01:00
samw a6a4f5660b git: unpushed alias 2026-07-02 11:13:49 +01:00
samw edcb288716 flake: add kallax 2026-06-07 16:00:37 +01:00
samw 327962567f macs: add smerge to path 2026-04-05 17:13:50 +01:00
samw 5e5bacfd14 wezterm: enable 2026-03-26 18:23:57 +00:00
samw 433c96eca4 me: add gallium ssh key 2026-03-15 16:58:52 +00:00
samw 746b05f91c macs: only source brew if exists 2026-03-15 16:58:39 +00:00
samw ad60d86c53 ssh: squish warning 2026-02-27 18:22:24 +00:00
samw ac362b6667 macs: squish home manager warning (again?) 2026-02-05 01:04:38 +00:00
samw 072ff7acdc hx: fix rust-analyzer, remove basedpyright (it's in upstream) 2025-12-29 17:53:25 +01:00
samw edefea64ee helix: show hidden files, rendering tweaks 2025-12-16 14:37:22 +00:00
samw 1ede986cc1 fzf: show hidden 2025-12-16 14:37:22 +00:00
samw aebb5dcd08 fmt 2025-12-05 16:34:49 +00:00
samw 7a1df05022 vscode: updates for 25.11 2025-12-05 16:34:45 +00:00
samw 97d3c6f0af iterm: ok whatever 2025-12-05 16:29:06 +00:00
samw c4953a227a git: add mergiraf 2025-12-05 16:29:06 +00:00
samw 84d4741d98 various updates 2025-12-05 16:29:06 +00:00
samw 924177bd4c use nixos-x rather than release-x, pin unstable 2025-12-05 16:26:08 +00:00
samw b15ba6c14c direnv: increase warning time 2025-12-05 16:16:40 +00:00
samw d90384b2de starship: add direnv 2025-12-05 15:55:32 +00:00
samw 31b30027ce update to 25.11 2025-12-05 15:54:38 +00:00
samw 7c56f42779 nix: use nixfmt-rfc-style 2025-12-05 15:48:11 +00:00
samw ef681a3ba8 squash 2025-12-05 15:44:22 +00:00
samw cee2d8e6bc fix warnings 2025-12-05 15:44:12 +00:00
samw b3fedf3584 fzf: get files from fd to respect gitignore when ctrl-ting 2025-12-05 15:43:35 +00:00
samw 1e8b5ebb0d phosphorus: add 2025-12-05 15:42:39 +00:00
samw f89e0bcec7 helix: add and configure 2025-12-05 15:41:53 +00:00
samw 6e55465310 25.11 updates, hope it works on 2505 lol 2025-10-07 17:26:18 +01:00
samw 9d1d445fbc add helix 2025-10-07 16:45:31 +01:00
samw 38715744d0 update to 25.05 2025-08-29 20:29:45 +01:00
samw c12f8e2d07 vim: fix trouble 2025-05-13 01:02:40 +01:00
samw 78f926a1a1 flake: 24.05->24.11 2025-05-13 00:57:14 +01:00
samw 5b373b9a57 tpmssh: fix socket 2024-10-05 16:45:57 +01:00
samw 700b56d41a fix 2024-09-28 23:19:25 +01:00
samw 665403ee0f maybe don't clobber sessionvariables 2024-09-28 20:06:13 +01:00
samw c0978d2186 add tpmssh 2024-09-28 19:57:44 +01:00
samw b3b9941c9b remove boron 2024-09-28 19:19:59 +01:00
samw 8fd2a4fb6e shell: shorten/expand homemanager/nixos-rebuild aliases 2024-09-26 13:33:21 +01:00
samw cc24d247b1 vim: replace pylsp with basedpyright 2024-09-25 21:41:59 +01:00
samw c38a6da542 gpg: fix pinentry 2024-09-22 14:32:13 +01:00
samw 36ae4c738d update to 24.05 2024-06-08 22:42:24 +01:00
samw 7f90b53891 zsh: squash warning 2024-04-24 23:12:13 +01:00
samw 58e331678d flake: update 2024-04-24 23:10:02 +01:00
samw 9f821584d5 add nix shell alias 2024-04-24 22:56:53 +01:00
samw 786d7d1b06 update to 23.11 2024-03-30 21:25:55 +00:00
samw c5c4e59f04 s/exa/eza 2024-03-30 21:23:53 +00:00
samw 007d0203bc git: add lfs 2023-11-27 19:09:30 +00:00
samw eb0ee2cdce flake: update nixpkgs 2023-10-03 17:49:51 +01:00
samw 39c4a76673 gpg: disable agent on darwin 2023-10-03 17:48:06 +01:00
samw 7eaf129278 zsh: make fzf respect gitignore 2023-10-03 10:48:58 +01:00
samw 57ca6b2305 pkgs: add dig/whois 2023-08-25 17:05:16 +01:00
samw a2cab93005 gpg: ssh support 2023-08-25 17:05:16 +01:00
samw 604cf1b75d Fine iterm have your changes dammit 2023-08-18 13:07:08 +02:00
samw 2941017589 friendship ended with rnix, now nil is my best friend 2023-08-18 13:07:08 +02:00
samw 6b46199500 gpg: enable agent 2023-07-17 01:32:22 +01:00
samw 0fbb31defe gpg: enable ccid on not-darwin 2023-07-17 01:03:11 +01:00
samw a44510a299 git: add tea cli 2023-07-15 15:02:11 +01:00
samw 94453d9b7f flake: update inputs to fix vscode breakage 2023-06-16 12:41:27 +01:00
samw cf1a0cbee2 update to 23.05 2023-06-03 19:38:11 +08:00
samw b0ae82d147 vim: add open on *hub plugin 2023-06-03 19:25:26 +08:00
samw b4dedbbea3 Fix EDITOR=nvim on nixos 23.05 2023-05-28 20:58:01 +08:00
samw 7cff2f9d50 vscode: auto color scheme, rulers, ssh 2023-04-21 14:42:58 +01:00
samw 780b0969ed vim: switch snippy for vsnip 2023-04-17 14:25:34 +01:00
21 changed files with 2504 additions and 542 deletions
Generated
+43 -28
View File
@@ -2,19 +2,16 @@
"nodes": {
"devshell": {
"inputs": {
"flake-utils": [
"flake-utils"
],
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1671489820,
"narHash": "sha256-qoei5HDJ8psd1YUPD7DhbHdhLIT9L2nadscp4Qk37uk=",
"lastModified": 1764011051,
"narHash": "sha256-M7SZyPZiqZUR/EiiBJnmyUbOi5oE/03tCeFrTiUZchI=",
"owner": "numtide",
"repo": "devshell",
"rev": "5aa3a8039c68b4bf869327446590f4cdf90bb634",
"rev": "17ed8d9744ebe70424659b0ef74ad6d41fc87071",
"type": "github"
},
"original": {
@@ -24,12 +21,15 @@
}
},
"flake-utils": {
"inputs": {
"systems": "systems"
},
"locked": {
"lastModified": 1667395993,
"narHash": "sha256-nuEHfE/LcWyuSWnS8t12N1wc105Qtau+/OdUAjtQ0rA=",
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "5aed5285a952e0b949eb3ba02c12fa4fcfef535f",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
@@ -42,36 +42,50 @@
"inputs": {
"nixpkgs": [
"nixpkgs"
],
"utils": "utils"
]
},
"locked": {
"lastModified": 1672244468,
"narHash": "sha256-xaZb8AZqoXRCSqPusCk4ouf+fUNP8UJdafmMTF1Ltlw=",
"lastModified": 1764866045,
"narHash": "sha256-0GsEtXV9OquDQ1VclQfP16cU5VZh7NEVIOjSH4UaJuM=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "89a8ba0b5b43b3350ff2e3ef37b66736b2ef8706",
"rev": "f63d0fe9d81d36e5fc95497217a72e02b8b7bcab",
"type": "github"
},
"original": {
"owner": "nix-community",
"ref": "release-22.11",
"ref": "release-25.11",
"repo": "home-manager",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1678101631,
"narHash": "sha256-vuuvWBNGhNSPPbFCjp2XZmBqJOvsFF1T0hyleRnHZlc=",
"lastModified": 1764831616,
"narHash": "sha256-OtzF5wBvO0jgW1WW1rQU9cMGx7zuvkF7CAVJ1ypzkxA=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "934e613c31cf7af0624dcf088b9e2d9b802d0717",
"rev": "c97c47f2bac4fa59e2cbdeba289686ae615f8ed4",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixos-25.11",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs-unstable": {
"locked": {
"lastModified": 1764951420,
"narHash": "sha256-oLJXP0fb5hyUvHGKAWdtjhl1/4ivxXy3HsuMMTTxrd8=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "0b784f7c32b9bbab8a599ccc6b4acc58f42d6f4f",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "release-22.11",
"repo": "nixpkgs",
"type": "github"
}
@@ -81,21 +95,22 @@
"devshell": "devshell",
"flake-utils": "flake-utils",
"home-manager": "home-manager",
"nixpkgs": "nixpkgs"
"nixpkgs": "nixpkgs",
"nixpkgs-unstable": "nixpkgs-unstable"
}
},
"utils": {
"systems": {
"locked": {
"lastModified": 1667395993,
"narHash": "sha256-nuEHfE/LcWyuSWnS8t12N1wc105Qtau+/OdUAjtQ0rA=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "5aed5285a952e0b949eb3ba02c12fa4fcfef535f",
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
}
+84 -29
View File
@@ -2,52 +2,77 @@
description = "Samw's home environment, as managed by nix/home-manager.";
inputs = {
# Nixpkgs
nixpkgs = {url = "github:nixos/nixpkgs/release-22.11";};
nixpkgs = {
# N.B. we use the nixos-x branch as this is updated *after* successful hydra builds
# rather than release-x. See https://wiki.nixos.org/wiki/Channel_branches
url = "github:nixos/nixpkgs/nixos-25.11";
};
nixpkgs-unstable = {
url = "github:nixos/nixpkgs";
};
# Other modules
home-manager = {
url = "github:nix-community/home-manager/release-22.11";
url = "github:nix-community/home-manager/release-25.11";
inputs.nixpkgs.follows = "nixpkgs";
};
flake-utils.url = "github:numtide/flake-utils";
devshell = {
url = "github:numtide/devshell";
inputs.flake-utils.follows = "flake-utils";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = inputs: let
outputs =
inputs:
let
overlays = [
# Add our own local packages
(final: prev: rec {
(final: prev: {
# Make my local packages available as pkgs.mypkgs.<foo>
mypkgs = prev.callPackage ./pkgs { };
})
# more up to date ssh-tpm-agent. Can probably ditch this post-24.05
(final: prev: {
ssh-tpm-agent = (import inputs.nixpkgs-unstable { system = prev.system; }).ssh-tpm-agent;
})
];
in (rec {
in
(
rec {
profiles = import ./home/profiles.nix;
lib = {
mkHome = {
mkHome =
{
profiles,
system,
username ? "samw",
}:
inputs.home-manager.lib.homeManagerConfiguration {
pkgs = (import inputs.nixpkgs {
pkgs = (
import inputs.nixpkgs {
inherit system;
config.allowUnfree = true; # Yes I know it's bad for me
});
}
);
modules = [
{ home = {
{
home = {
inherit username;
homeDirectory =
if (inputs.nixpkgs.lib.systems.elaborate system).isDarwin
then "/Users/${username}"
else "/home/${username}";
if (inputs.nixpkgs.lib.systems.elaborate system).isDarwin then
"/Users/${username}"
else
"/home/${username}";
stateVersion = "21.11";
};}] ++ profiles ++ [
};
}
]
++ profiles
++ [
{ nixpkgs.overlays = overlays; }
# See comment in home/default.nix.
({ pkgs, ... }: {
(
{ pkgs, ... }:
{
nix = {
enable = true;
package = pkgs.nix;
@@ -58,8 +83,14 @@
# level, so less duplication overall and no more fetching that 30MB src
# every time you run nix shell.
registry.nixpkgs.flake = inputs.nixpkgs;
registry.nixpkgs-unstable.to = {
owner = "nixos";
repo = "nixpkgs";
type = "github";
};
})
};
}
)
];
extraSpecialArgs = { inherit system; };
};
@@ -67,41 +98,65 @@
# Standalone home-manager configurations
homeConfigurations = {
boron = lib.mkHome {
system = "aarch64-darwin";
profiles = with profiles; [default dev dev-gui sensitive mac docker aws];
username = "samuel.willcocks";
};
zinc = lib.mkHome {
system = "aarch64-darwin";
profiles = with profiles; [default dev dev-gui sensitive mac];
profiles = with profiles; [
default
dev
dev-gui
sensitive
mac
];
};
luroy = lib.mkHome {
system = "x86_64-linux";
profiles = with profiles; [
default
dev
];
};
kallax = lib.mkHome {
system = "x86_64-linux";
profiles = with profiles; [default dev];
};
phosphorus = lib.mkHome {
system = "aarch64-darwin";
profiles = with profiles; [
default
dev
sensitive
mac
];
};
};
}
# Per-system things
// (inputs.flake-utils.lib.eachDefaultSystem (system: let
// (inputs.flake-utils.lib.eachDefaultSystem (
system:
let
pkgs = import inputs.nixpkgs {
inherit system;
overlays = overlays ++ [inputs.devshell.overlay];
overlays = overlays ++ [ inputs.devshell.overlays.default ];
};
platform = pkgs.lib.systems.elaborate system;
in {
in
{
# Flake interface to my local packages.
# - `callPackage` puts some junk in mypkgs (`override` and
# `overrideDerivation`) so we filter out anything that isn't a derivation
# - We also filter out any packages that aren't supported on the current
# platform.
packages = with pkgs.lib; (filterAttrs (_: v: (isDerivation v && meta.availableOn platform v)) pkgs.mypkgs);
formatter = pkgs.alejandra;
packages =
with pkgs.lib;
(filterAttrs (_: v: (isDerivation v && meta.availableOn platform v)) pkgs.mypkgs);
formatter = pkgs.nixfmt-tree;
# A devshell with useful utils
devShells.default = pkgs.devshell.mkShell {
packages = [
inputs.home-manager.defaultPackage.${system}
inputs.home-manager.packages.${system}.default
];
};
})));
}
))
);
}
+4 -1
View File
@@ -1 +1,4 @@
{pkgs, ...}: {home.packages = with pkgs; [awscli2];}
{ pkgs, ... }:
{
home.packages = with pkgs; [ awscli2 ];
}
File diff suppressed because it is too large Load Diff
+38 -21
View File
@@ -1,15 +1,15 @@
{
pkgs,
lib,
...
}: let
}:
let
packages = pkgs.callPackage ./packages.nix { };
in {
in
{
home.packages = packages.all;
home.sessionVariables = {
"PATH" = "$HOME/.local/bin:$PATH";
"EDITOR" = "vim";
"WORDCHARS" = "\${WORDCHARS//[\\/.=]/}"; # ctrl-w on paths without make angery
EDITOR = "vim"; # is overriden to nvim in vim.nix if needed
WORDCHARS = "\${WORDCHARS//[\\/.=]/}"; # ctrl-w on paths without make angery
};
/*
# For some reason this doesn't play nice when using home manager config from inside
@@ -38,13 +38,16 @@ in {
g = "git";
cat = "bat";
ip = "ip --color=auto";
hmswitch = ''home-manager switch --flake ".#$(hostname -s)"'';
nrswitch = "nixos-rebuild --use-remote-sudo switch --flake '.#'";
ns = "nix shell nixpkgs#";
hm = ''home-manager --flake ".#$(hostname -s)"'';
hms = ''home-manager --flake ".#$(hostname -s)" switch'';
nr = "nixos-rebuild --sudo --flake '.#'";
nrs = "nixos-rebuild --sudo --flake '.#' switch";
da = "direnv allow .";
dr = "direnv reload";
};
# Extra .zshrc stuff
initExtra = ''
initContent = ''
# zstyle ':completion:*' menu select # fancy interactive autocomplete
zstyle ':completion:*' matcher-list 'm:{a-z}={A-Za-z}' # tabcomplete lower to upper case
@@ -54,7 +57,7 @@ in {
# Don't honk at me constantly
unsetopt beep
'';
enableSyntaxHighlighting = true;
syntaxHighlighting.enable = true;
plugins = [
{
name = "fzf-tab";
@@ -67,42 +70,56 @@ in {
];
};
exa = {
enable = true;
enableAliases = true;
};
eza.enable = true;
starship = {
enable = true;
settings = {
add_newline = false;
format = "$username$hostname$shlvl$directory$git_branch$git_commit$git_state$git_metrics$git_status$hg_branch$docker_context$golang$kotlin$nodejs$python$rust$terraform$nix_shell$memory_usage$aws$gcloud$openstack$azure$env_var$crystal$custom$sudo$cmd_duration$line_break$jobs$status$shell$character";
direnv.disabled = false;
format = "$all";
username.format = "[$user]($style) ";
hostname.format = "[$hostname]($style) ";
directory = {truncation_length = -1;};
directory = {
truncation_length = -1;
};
git_branch.format = "[$symbol$branch]($style) ";
python.format = "[py \${pyenv_prefix}(\${version} )(\\($virtualenv\\) )]($style)";
nodejs.format = "[js ($version )]($style)";
nix_shell.format = "[nix $state( \\($name\\))]($style) ";
python.symbol = "py ";
nodejs.symbol = "js ";
nix_shell.symbol = "nix ";
rust.symbol = "rs ";
direnv.symbol = "de ";
};
};
direnv = {
enable = true;
nix-direnv.enable = true;
config.global.warn_timeout = "30s";
};
fzf = {
enable = true;
defaultCommand = "${pkgs.ripgrep}/bin/rg --files";
# Include hidden files/folders (-H) but exclude .git
defaultCommand = "${pkgs.fd}/bin/fd -H --type f -E .git";
fileWidgetCommand = "${pkgs.fd}/bin/fd -H --type f -E .git";
};
ssh = {
enable = true;
enableDefaultConfig = false;
package = pkgs.openssh; # Use modern ssh
includes = [ "~/.ssh/config.local" ];
matchBlocks."*" = {
user = "samw";
serverAliveInterval = 30;
serverAliveCountMax = 10;
matchBlocks."*".user = "samw";
compression = true;
controlMaster = "autoask";
controlPath = "~/.ssh/master-%r@%n:%p";
# Close socket once last connection closes
controlPersist = "no";
};
};
};
}
+7 -1
View File
@@ -1 +1,7 @@
{pkgs, ...}: {home.packages = with pkgs; [docker colima];}
{ pkgs, ... }:
{
home.packages = with pkgs; [
docker
colima
];
}
+27 -14
View File
@@ -1,17 +1,24 @@
{pkgs, ...}: {
home.packages = [pkgs.git-open];
programs.git = {
enable = true;
userName = "Sam Willcocks";
userEmail = "sam@wlcx.cc";
delta = {
{ pkgs, ... }:
{
home.packages = with pkgs; [
git-open
tea
];
programs.delta = {
# Better diffs
enable = true;
options = {line-numbers = true;};
enableGitIntegration = true;
options = {
line-numbers = true;
};
aliases = {
};
programs.git = {
enable = true;
lfs.enable = true;
settings = {
user.name = "Sam Willcocks";
user.email = "sam@wlcx.cc";
alias = {
a = "add";
ap = "add -p";
br = "branch";
@@ -34,14 +41,20 @@
st = "status";
sw = "switch";
swc = "switch --create";
unp = "log --branches --not --remotes --no-walk --decorate --oneline";
gone = ''
! git fetch -p && git for-each-ref --format '%(refname:short) %(upstream:track)' awk '$2 == "[gone]" {print $1}' | xargs -r git branch -D'';
gone = ''! git fetch -p && git for-each-ref --format '%(refname:short) %(upstream:track)' awk '$2 == "[gone]" {print $1}' | xargs -r git branch -D'';
};
extraConfig = {
branch.sort = "-committerdate";
push.default = "current";
init.defaultBranch = "main";
merge = {
conflictStyle = "diff3";
mergiraf = {
name = "mergiraf";
driver = "${pkgs.mergiraf}/bin/mergiraf merge --git %O %A %B -s %S -x %X -y %Y -p %P -l %L";
};
};
};
includes = [
# Always include local gitconfig if it's there
+10 -2
View File
@@ -1,4 +1,5 @@
{pkgs, ...}: {
{ pkgs, lib, ... }:
{
programs.gpg = {
enable = true;
mutableKeys = false;
@@ -19,6 +20,13 @@
];
# make yubikey work on macos? lolgpg
# https://github.com/NixOS/nixpkgs/issues/155629
scdaemonSettings = {disable-ccid = true;};
scdaemonSettings = (lib.optionalAttrs pkgs.stdenv.isDarwin { disable-ccid = true; });
};
# Shouldn't have an effect on macos, on linux we need to specify a pinentry
services.gpg-agent = {
enable = !pkgs.stdenv.isDarwin;
enableSshSupport = true;
pinentry.package = pkgs.pinentry-all;
};
}
+37
View File
@@ -0,0 +1,37 @@
{ ... }:
{
programs.helix = {
enable = true;
settings = {
theme = "monokai_pro";
editor = {
"soft-wrap".enable = true;
"file-picker".hidden = false; # Show hidden files (yes it's counter-intuitive)
gutters = ["diagnostics" "line-numbers" "spacer" "diff"];
whitespace.render = {
space = "none";
tab = "all";
nbsp = "all";
nnbsp = "all";
newline = "none";
};
};
};
languages = {
language-server.rust-analyzer.config = {
# Don't get lost in .direnv etc and chew 100% cpu forever
files.excludeDirs = [
".git"
".cargo"
".direnv"
];
};
language = [
{
name = "python";
language-servers = [ "ty" "basedpyright" ];
}
];
};
};
}
+24 -4
View File
@@ -2,14 +2,34 @@
pkgs,
lib,
...
}: {
}:
{
# Mac specific packages.
# TODO: have this in a central packages place rather than here
home.packages = with pkgs; [pngpaste mypkgs.qrclip];
home.packages = with pkgs; [
pngpaste
mypkgs.qrclip
];
home.sessionPath = [
"/Applications/Sublime Merge.app/Contents/SharedSupport/bin"
];
# Use secretive for SSH agent
programs.ssh.matchBlocks.all = lib.mkIf pkgs.stdenv.isDarwin {
host = "*";
extraOptions."IdentityAgent" = "~/Library/Containers/com.maxgoedjen.Secretive.SecretAgent/Data/socket.ssh";
extraOptions."IdentityAgent" =
"~/Library/Containers/com.maxgoedjen.Secretive.SecretAgent/Data/socket.ssh";
};
programs.zsh.initExtra = "eval $(/opt/homebrew/bin/brew shellenv)";
programs.zsh.sessionVariables = {
SSH_AUTH_SOCK = "$HOME/Library/Containers/com.maxgoedjen.Secretive.SecretAgent/Data/socket.ssh";
# Make connection muxing permission work.
# Openssh by default will only use SSH_ASKPASS if it sees DISPLAY/WAYLAND_DISPLAY, so we have to force it
SSH_ASKPASS_REQUIRE = "force";
# A nice applescript permission dialog
SSH_ASKPASS = (pkgs.fetchurl {
url = "https://raw.githubusercontent.com/theseal/ssh-askpass/refs/heads/master/ssh-askpass";
hash= "sha256-bQUuGS3Mb+i4Kt+1mDP203s2W1jlRcpl/7uXA7TUZ+o=";
executable = true;
});
};
programs.zsh.initContent = "[ -e /opt/homebrew/bin/brew ] && eval $(/opt/homebrew/bin/brew shellenv)";
}
+19 -3
View File
@@ -1,5 +1,6 @@
{ pkgs }:
with pkgs; rec {
with pkgs;
rec {
# The stuff you want installed everywhere. The necessities.
base = [
bat # cat replacement, aliased to cat in home-manager
@@ -12,13 +13,28 @@ with pkgs; rec {
unzip
vim
wget
helix
];
# Networking shit
net = [iperf3 nmap socat tcpdump];
net = [
dig
iperf3
mtr
nmap
socat
tcpdump
];
# development tools
dev = [jq nixfmt gh glab hexyl];
dev = [
jq
nixfmt-rfc-style
gh
glab
hexyl
attic-client
];
all = base ++ net ++ dev;
}
+5 -2
View File
@@ -1,8 +1,11 @@
{pkgs, ...}: {
{ pkgs, ... }:
{
home.packages = with pkgs; [ yubikey-manager ];
programs.password-store = {
enable = true;
settings = {PASSWORD_STORE_DIR = "$HOME/.password-store";};
settings = {
PASSWORD_STORE_DIR = "$HOME/.password-store";
};
package = pkgs.pass.withExtensions (exts: [ exts.pass-otp ]);
};
programs.zsh.shellAliases = {
+45 -5
View File
@@ -2,16 +2,48 @@
# The basics that you'll want everywhere
default = ./default.nix;
# A machine for development
dev = {...}: {
imports = [./git.nix ./vim.nix ./vim-dev];
dev =
{ ... }:
{
imports = [
./git.nix
./vim.nix
./vim-dev
./helix.nix
];
};
# A machine for dev with a GUI
# TODO: detect this automatically somehow?
dev-gui = {...}: {
dev-gui =
{ ... }:
{
imports = [ ./vscode.nix ];
programs.wezterm = {
enable = true;
extraConfig = ''
return {
color_scheme = "GruvboxDarkHard",
keys = {
{
key = 'd',
mods = 'SUPER',
action = wezterm.action.SplitVertical{domain='CurrentPaneDomain'},
},
{
key = 'D',
mods = 'SUPER | SHIFT',
action = wezterm.action.SplitHorizontal{domain='CurrentPaneDomain'},
},
},
}
'';
};
};
tpmssh = ./tpmssh.nix;
# Sensitive stuff
sensitive = {...}: {
sensitive =
{ ... }:
{
imports = [
./passwords.nix
./gpg.nix
@@ -24,5 +56,13 @@
# A machine you want to do aws stuff on
aws = ./aws.nix;
# A server
server = {...}: {imports = [./default.nix ./git.nix ./vim.nix];};
server =
{ ... }:
{
imports = [
./default.nix
./git.nix
./vim.nix
];
};
}
+43
View File
@@ -0,0 +1,43 @@
# Enable tpm-ssh-agent in a systemd user service
{ pkgs, config, ... }:
{
home.packages = [ pkgs.ssh-tpm-agent ];
home.sessionVariables = {
SSH_AUTH_SOCK = "$(${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent --print-socket)";
};
systemd.user.sockets.ssh-tpm-agent = {
Install.WantedBy = [ "sockets.target" ];
Socket = {
ListenStream = "%t/ssh-tpm-agent.sock";
SocketMode = "0600";
Service = "ssh-tpm-agent.service";
};
};
systemd.user.services.ssh-tpm-agent = {
Unit = {
Requires = [ "ssh-tpm-agent.socket" ];
ConditionEnvironment = "!SSH_AGENT_PID";
};
Service = {
Environment = ''
SSH_AUTH_SOCK="%t/ssh-tpm-agent.sock"
'';
ExecStart = "${
pkgs.writeShellScriptBin "start-ssh-tpm-agent" (
if config.services.gpg-agent.enableSshSupport then
''
${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent -A $(${config.programs.gpg.package}/bin/gpgconf --list-dirs agent-ssh-socket)
''
else
''
${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent
''
)
}/bin/start-ssh-tpm-agent";
PassEnvironment = "SSH_AGENT_PID";
SuccessExitStatus = 2;
Type = "simple";
};
};
}
+12 -4
View File
@@ -3,8 +3,14 @@
lib,
system,
...
}: {
programs.neovim.plugins = with pkgs.vimPlugins;
}:
{
home.packages = with pkgs; [
nil
nixd
];
programs.neovim.plugins =
with pkgs.vimPlugins;
[
# More fancy shit
nvim-treesitter
@@ -13,8 +19,8 @@
nvim-lspconfig
nvim-cmp
cmp-nvim-lsp
nvim-snippy
cmp-snippy
cmp-vsnip
vim-vsnip
# Language specific
go-nvim
rust-vim
@@ -26,6 +32,8 @@
kotlin-vim
Jenkinsfile-vim-syntax
html5-vim
# Useful stuff
vim-gh-line
]
# delve is unsupported on aarch64-linux and golangci-lint is broken on darwin
# (see https://github.com/NixOS/nixpkgs/issues/168984).
+12 -12
View File
@@ -15,7 +15,7 @@ cmp.setup({
-- Use snippy for completion
snippet = {
expand = function(args)
require('snippy').expand_snippet(args.body)
vim.fn["vsnip#anonymous"](args.body)
end,
},
-- Disable completions if we're in a comment
@@ -49,19 +49,12 @@ require'lspconfig'.gopls.setup{
on_attach = on_attach,
capabilities = capabilities,
}
require'lspconfig'.pylsp.setup{
require'lspconfig'.basedpyright.setup{}
require'lspconfig'.nil_ls.setup{
on_attach = on_attach,
capabilities = capabilities,
handlers = {
["textDocument/publishDiagnostics"] = vim.lsp.with(
vim.lsp.diagnostic.on_publish_diagnostics, {
-- Disable virtual_text
virtual_text = false
}
),
}
}
require'lspconfig'.rnix.setup{
require'lspconfig'.nixd.setup{
on_attach = on_attach,
capabilities = capabilities,
}
@@ -82,6 +75,13 @@ require'lspconfig'.rust_analyzer.setup{
description = 'Open documentation for the symbol under the cursor in default browser',
},
},
settings = {
["rust-analyzer"] = {
procMacro = {
enable = false,
},
},
},
}
require'lspconfig'.dhall_lsp_server.setup{
on_attach = on_attach,
@@ -108,7 +108,7 @@ require('go').setup()
-- Diags with Trouble
require('trouble').setup {
icons = false,
icons = {},
signs = {
error = "E",
warning = "W",
+7 -7
View File
@@ -1,13 +1,13 @@
# This module sets up a "full" neovim install with plugins and unicorns. It
# also makes neovim the default editor and aliases vim to nvim.
# Vim with some niceties. If you're spending any time in vim you'll want this.
# For a full-fat vim with all the bells and whistles, see vim-dev
{
pkgs,
lib,
strings,
...
}: {
home.sessionVariables = {"EDITOR" = "nvim";};
home.packages = with pkgs; [rnix-lsp ripgrep];
}:
{
home.sessionVariables.EDITOR = lib.mkForce "nvim";
home.packages = with pkgs; [ ripgrep ];
programs.neovim = {
enable = true;
viAlias = true;
@@ -27,7 +27,7 @@
vim-gitgutter
# More stuff idk
emmet-vim
vim-sleuth # guess whitespace settings from file
vim-sleuth # guess whitespace settings from file
];
extraConfig = ''
lua <<EOF
+12 -5
View File
@@ -1,18 +1,25 @@
{pkgs, ...}: {
{ pkgs, ... }:
{
programs.vscode = {
enable = true;
package = pkgs.vscodium;
mutableExtensionsDir = false;
extensions = with pkgs.vscode-extensions; [
matklad.rust-analyzer
profiles.default.extensions = with pkgs.vscode-extensions; [
rust-lang.rust-analyzer
jdinhlife.gruvbox
jnoortheen.nix-ide
editorconfig.editorconfig
];
userSettings = {
profiles.default.userSettings = {
"update.mode" = "none";
"workbench.colorTheme" = "Gruvbox Dark Hard";
"window.autoDetectColorScheme" = true;
"workbench.preferredDarkColorTheme" = "Gruvbox Dark Hard";
"workbench.preferredLightColorTheme" = "Gruvbox Light Hard";
"files.trimTrailingWhitespace" = true;
"emmet.includeLanguages"."django-html" = "html";
# Don't try to write to the nix-managed .ssh/config
"remote.SSH.configFile" = "~/.ssh/config.local";
"editor.rulers" = [ 90 ];
};
};
}
+1
View File
@@ -5,5 +5,6 @@
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIMvrgrLnE+AQBOBRiBoTFkbWaYTvqaBzIp4OfDiXUij"
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDQdGzwYiallvWXIHgSAf2GOwMJKA8bxPmwyuO+vsd1HwB65hMRPCpKS+FNLIpkrADNnuhGS3xGCGSSuQ+zAu/g= zinc-se-main@secretive.zinc.local"
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBNLrJyUXmiFWb9vhlTWZLYr64IsKut+c9TGqq3/uwPDeF4X0Qb2jzxqXfQcDSztjR09JHbC8BOqfpYYT9LHahIo= YubiKey #13340583 PIV Slot 9a"
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBC/kJYueV9cBlyPsYhC0Q2HQR+E6MswwUF6hwXrkbb4JPNn9bD2PM2GjXQe0rz6KWPr4LYkbGTo9zbRQg3d2MTE= gallium-se-main@secretive.gallium.local"
];
}
+2 -1
View File
@@ -1,4 +1,5 @@
# TODO: auto import everything
{pkgs, ...}: {
{ pkgs, ... }:
{
qrclip = pkgs.callPackage ./qrclip { };
}
+5 -2
View File
@@ -2,11 +2,14 @@
pkgs,
lib,
stdenv,
}: let
}:
let
zbar = pkgs.zbar.override { enableVideo = false; };
in
(pkgs.writeShellScriptBin "qrclip" ''
set -eo pipefail
${pkgs.pngpaste}/bin/pngpaste - | ${zbar}/bin/zbarimg --raw -q1 -
'')
// {meta.platforms = lib.platforms.darwin;}
// {
meta.platforms = lib.platforms.darwin;
}