Compare commits

...
31 Commits
Author SHA1 Message Date
samw 89328c7160 25.11 -> 26.05 2026-09-13 04:29:30 +01:00
samw b9365a827d add fd 2026-09-13 04:27:33 +01:00
samw 571202560a fmt 2026-09-13 04:27:33 +01:00
samw 275f56dd55 goodbye zinc, hello gallium 2026-09-13 04:27:33 +01:00
samw 344f52c05b ssh: connection sharing thing 2026-07-02 11:13:49 +01:00
samw a6a4f5660b git: unpushed alias 2026-07-02 11:13:49 +01:00
samw edcb288716 flake: add kallax 2026-06-07 16:00:37 +01:00
samw 327962567f macs: add smerge to path 2026-04-05 17:13:50 +01:00
samw 5e5bacfd14 wezterm: enable 2026-03-26 18:23:57 +00:00
samw 433c96eca4 me: add gallium ssh key 2026-03-15 16:58:52 +00:00
samw 746b05f91c macs: only source brew if exists 2026-03-15 16:58:39 +00:00
samw ad60d86c53 ssh: squish warning 2026-02-27 18:22:24 +00:00
samw ac362b6667 macs: squish home manager warning (again?) 2026-02-05 01:04:38 +00:00
samw 072ff7acdc hx: fix rust-analyzer, remove basedpyright (it's in upstream) 2025-12-29 17:53:25 +01:00
samw edefea64ee helix: show hidden files, rendering tweaks 2025-12-16 14:37:22 +00:00
samw 1ede986cc1 fzf: show hidden 2025-12-16 14:37:22 +00:00
samw aebb5dcd08 fmt 2025-12-05 16:34:49 +00:00
samw 7a1df05022 vscode: updates for 25.11 2025-12-05 16:34:45 +00:00
samw 97d3c6f0af iterm: ok whatever 2025-12-05 16:29:06 +00:00
samw c4953a227a git: add mergiraf 2025-12-05 16:29:06 +00:00
samw 84d4741d98 various updates 2025-12-05 16:29:06 +00:00
samw 924177bd4c use nixos-x rather than release-x, pin unstable 2025-12-05 16:26:08 +00:00
samw b15ba6c14c direnv: increase warning time 2025-12-05 16:16:40 +00:00
samw d90384b2de starship: add direnv 2025-12-05 15:55:32 +00:00
samw 31b30027ce update to 25.11 2025-12-05 15:54:38 +00:00
samw 7c56f42779 nix: use nixfmt-rfc-style 2025-12-05 15:48:11 +00:00
samw ef681a3ba8 squash 2025-12-05 15:44:22 +00:00
samw cee2d8e6bc fix warnings 2025-12-05 15:44:12 +00:00
samw b3fedf3584 fzf: get files from fd to respect gitignore when ctrl-ting 2025-12-05 15:43:35 +00:00
samw 1e8b5ebb0d phosphorus: add 2025-12-05 15:42:39 +00:00
samw f89e0bcec7 helix: add and configure 2025-12-05 15:41:53 +00:00
21 changed files with 1909 additions and 621 deletions
Generated
+17 -20
View File
@@ -2,19 +2,16 @@
"nodes": { "nodes": {
"devshell": { "devshell": {
"inputs": { "inputs": {
"flake-utils": [
"flake-utils"
],
"nixpkgs": [ "nixpkgs": [
"nixpkgs" "nixpkgs"
] ]
}, },
"locked": { "locked": {
"lastModified": 1713532798, "lastModified": 1764011051,
"narHash": "sha256-wtBhsdMJA3Wa32Wtm1eeo84GejtI43pMrFrmwLXrsEc=", "narHash": "sha256-M7SZyPZiqZUR/EiiBJnmyUbOi5oE/03tCeFrTiUZchI=",
"owner": "numtide", "owner": "numtide",
"repo": "devshell", "repo": "devshell",
"rev": "12e914740a25ea1891ec619bb53cf5e6ca922e40", "rev": "17ed8d9744ebe70424659b0ef74ad6d41fc87071",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -28,11 +25,11 @@
"systems": "systems" "systems": "systems"
}, },
"locked": { "locked": {
"lastModified": 1710146030, "lastModified": 1731533236,
"narHash": "sha256-SZ5L6eA7HJ/nmkzGG7/ISclqe6oZdOZTNoesiInkXPQ=", "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide", "owner": "numtide",
"repo": "flake-utils", "repo": "flake-utils",
"rev": "b1d9ab70662946ef0850d488da1c9019f3a9752a", "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -48,43 +45,43 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1756245065, "lastModified": 1789267039,
"narHash": "sha256-aAZNbGcWrVRZgWgkQbkabSGcDVRDMgON4BipMy69gvI=", "narHash": "sha256-LWiBv9yAYFi2LPbUhDGHPGKYskJQjj2fw12OlyO1uQo=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "54b2879ce622d44415e727905925e21b8f833a98", "rev": "ec172013fa62135f58fb58dd17ae9651e8f39727",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "nix-community", "owner": "nix-community",
"ref": "release-25.05", "ref": "release-26.05",
"repo": "home-manager", "repo": "home-manager",
"type": "github" "type": "github"
} }
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1756494058, "lastModified": 1789114715,
"narHash": "sha256-Yxg5zKIM450FAq7ihT6wkbuJ+Fl3KjbSpPjwFhSgMGc=", "narHash": "sha256-ugpsyk3NM2s87vXfUiIIiibbJ4Pp0JPS5p/3mfs+q+c=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "2788026c663a210beeb81e85f93ca5e86243fb3c", "rev": "21a67dc470149f337cecafbe965d8d252a390518",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "nixos", "owner": "nixos",
"ref": "release-25.05", "ref": "nixos-26.05",
"repo": "nixpkgs", "repo": "nixpkgs",
"type": "github" "type": "github"
} }
}, },
"nixpkgs-unstable": { "nixpkgs-unstable": {
"locked": { "locked": {
"lastModified": 1713995654, "lastModified": 1764951420,
"narHash": "sha256-S+4C0H9w7H9tSv1RviD/otsTmf1ECuxJMJ/j1t9gjPE=", "narHash": "sha256-oLJXP0fb5hyUvHGKAWdtjhl1/4ivxXy3HsuMMTTxrd8=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "ce6da85c2dc9e659bef799c2ed053771e1bb8ee3", "rev": "0b784f7c32b9bbab8a599ccc6b4acc58f42d6f4f",
"type": "github" "type": "github"
}, },
"original": { "original": {
+145 -90
View File
@@ -2,106 +2,161 @@
description = "Samw's home environment, as managed by nix/home-manager."; description = "Samw's home environment, as managed by nix/home-manager.";
inputs = { inputs = {
# Nixpkgs # Nixpkgs
nixpkgs = {url = "github:nixos/nixpkgs/release-25.05";}; nixpkgs = {
nixpkgs-unstable = {url = "github:nixos/nixpkgs";}; # N.B. we use the nixos-x branch as this is updated *after* successful hydra builds
# rather than release-x. See https://wiki.nixos.org/wiki/Channel_branches
url = "github:nixos/nixpkgs/nixos-26.05";
};
nixpkgs-unstable = {
url = "github:nixos/nixpkgs";
};
# Other modules # Other modules
home-manager = { home-manager = {
url = "github:nix-community/home-manager/release-25.05"; url = "github:nix-community/home-manager/release-26.05";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
flake-utils.url = "github:numtide/flake-utils"; flake-utils.url = "github:numtide/flake-utils";
devshell = { devshell = {
url = "github:numtide/devshell"; url = "github:numtide/devshell";
inputs.flake-utils.follows = "flake-utils";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
}; };
outputs = inputs: let outputs =
overlays = [ inputs:
# Add our own local packages let
(final: prev: { overlays = [
# Make my local packages available as pkgs.mypkgs.<foo> # Add our own local packages
mypkgs = prev.callPackage ./pkgs {}; (final: prev: {
}) # Make my local packages available as pkgs.mypkgs.<foo>
# more up to date ssh-tpm-agent. Can probably ditch this post-24.05 mypkgs = prev.callPackage ./pkgs { };
(final: prev: { })
ssh-tpm-agent = (import inputs.nixpkgs-unstable { system = prev.system; }).ssh-tpm-agent; # more up to date ssh-tpm-agent. Can probably ditch this post-24.05
}) (final: prev: {
]; ssh-tpm-agent = (import inputs.nixpkgs-unstable { system = prev.system; }).ssh-tpm-agent;
in (rec { })
profiles = import ./home/profiles.nix; ];
lib = { in
mkHome = { (
profiles, rec {
system, profiles = import ./home/profiles.nix;
username ? "samw", lib = {
}: mkHome =
inputs.home-manager.lib.homeManagerConfiguration { {
pkgs = (import inputs.nixpkgs { profiles,
inherit system; system,
config.allowUnfree = true; # Yes I know it's bad for me username ? "samw",
}); }:
modules = [ inputs.home-manager.lib.homeManagerConfiguration {
{ home = { pkgs = (
inherit username; import inputs.nixpkgs {
homeDirectory = inherit system;
if (inputs.nixpkgs.lib.systems.elaborate system).isDarwin config.allowUnfree = true; # Yes I know it's bad for me
then "/Users/${username}" }
else "/home/${username}"; );
stateVersion = "21.11"; modules = [
};}] ++ profiles ++ [ {
{nixpkgs.overlays = overlays;} home = {
# See comment in home/default.nix. inherit username;
({ pkgs, ... }: { homeDirectory =
nix = { if (inputs.nixpkgs.lib.systems.elaborate system).isDarwin then
enable = true; "/Users/${username}"
package = pkgs.nix; else
settings.experimental-features = "nix-command flakes"; "/home/${username}";
settings.max-jobs = "auto"; # Gotta go fast (build derivations in parallel) stateVersion = "21.11";
# Pin the nixpkgs registry to our locked nixpkgs. This means that we };
# get the same packages via e.g. nix shell as we have at the system }
# level, so less duplication overall and no more fetching that 30MB src ]
# every time you run nix shell. ++ profiles
registry.nixpkgs.flake = inputs.nixpkgs; ++ [
}; { nixpkgs.overlays = overlays; }
}) # See comment in home/default.nix.
]; (
extraSpecialArgs = {inherit system;}; { pkgs, ... }:
}; {
}; nix = {
enable = true;
package = pkgs.nix;
settings.experimental-features = "nix-command flakes";
settings.max-jobs = "auto"; # Gotta go fast (build derivations in parallel)
# Pin the nixpkgs registry to our locked nixpkgs. This means that we
# get the same packages via e.g. nix shell as we have at the system
# level, so less duplication overall and no more fetching that 30MB src
# every time you run nix shell.
registry.nixpkgs.flake = inputs.nixpkgs;
registry.nixpkgs-unstable.to = {
owner = "nixos";
repo = "nixpkgs";
type = "github";
};
};
}
)
];
extraSpecialArgs = { inherit system; };
};
};
# Standalone home-manager configurations # Standalone home-manager configurations
homeConfigurations = { homeConfigurations = {
zinc = lib.mkHome { gallium = lib.mkHome {
system = "aarch64-darwin"; system = "aarch64-darwin";
profiles = with profiles; [default dev dev-gui sensitive mac]; profiles = with profiles; [
default
dev
dev-gui
sensitive
mac
];
};
luroy = lib.mkHome {
system = "x86_64-linux";
profiles = with profiles; [
default
dev
];
};
kallax = lib.mkHome {
system = "x86_64-linux";
profiles = with profiles; [default dev];
};
phosphorus = lib.mkHome {
system = "aarch64-darwin";
profiles = with profiles; [
default
dev
sensitive
mac
];
};
}; };
luroy = lib.mkHome { }
system = "x86_64-linux"; # Per-system things
profiles = with profiles; [default dev]; // (inputs.flake-utils.lib.eachDefaultSystem (
}; system:
}; let
} pkgs = import inputs.nixpkgs {
# Per-system things inherit system;
// (inputs.flake-utils.lib.eachDefaultSystem (system: let overlays = overlays ++ [ inputs.devshell.overlays.default ];
pkgs = import inputs.nixpkgs { };
inherit system; platform = pkgs.lib.systems.elaborate system;
overlays = overlays ++ [inputs.devshell.overlays.default]; in
}; {
platform = pkgs.lib.systems.elaborate system; # Flake interface to my local packages.
in { # - `callPackage` puts some junk in mypkgs (`override` and
# Flake interface to my local packages. # `overrideDerivation`) so we filter out anything that isn't a derivation
# - `callPackage` puts some junk in mypkgs (`override` and # - We also filter out any packages that aren't supported on the current
# `overrideDerivation`) so we filter out anything that isn't a derivation # platform.
# - We also filter out any packages that aren't supported on the current packages =
# platform. with pkgs.lib;
packages = with pkgs.lib; (filterAttrs (_: v: (isDerivation v && meta.availableOn platform v)) pkgs.mypkgs); (filterAttrs (_: v: (isDerivation v && meta.availableOn platform v)) pkgs.mypkgs);
formatter = pkgs.alejandra; formatter = pkgs.nixfmt-tree;
# A devshell with useful utils # A devshell with useful utils
devShells.default = pkgs.devshell.mkShell { devShells.default = pkgs.devshell.mkShell {
packages = [ packages = [
inputs.home-manager.packages.${system}.default inputs.home-manager.packages.${system}.default
]; ];
}; };
}))); }
))
);
} }
+4 -1
View File
@@ -1 +1,4 @@
{pkgs, ...}: {home.packages = with pkgs; [awscli2];} { pkgs, ... }:
{
home.packages = with pkgs; [ awscli2 ];
}
File diff suppressed because it is too large Load Diff
+37 -23
View File
@@ -1,23 +1,25 @@
{ {
pkgs, pkgs,
... ...
}: let }:
packages = pkgs.callPackage ./packages.nix {}; let
in { packages = pkgs.callPackage ./packages.nix { };
in
{
home.packages = packages.all; home.packages = packages.all;
home.sessionVariables = { home.sessionVariables = {
EDITOR = "vim"; # is overriden to nvim in vim.nix if needed EDITOR = "vim"; # is overriden to nvim in vim.nix if needed
WORDCHARS = "\${WORDCHARS//[\\/.=]/}"; # ctrl-w on paths without make angery WORDCHARS = "\${WORDCHARS//[\\/.=]/}"; # ctrl-w on paths without make angery
}; };
/* /*
# For some reason this doesn't play nice when using home manager config from inside # For some reason this doesn't play nice when using home manager config from inside
# a nixos configuration. # a nixos configuration.
nix = { nix = {
enable = true; enable = true;
package = pkgs.nix; package = pkgs.nix;
settings.experimental-features = "nix-command flakes"; settings.experimental-features = "nix-command flakes";
settings.max-jobs = "auto"; # Gotta go fast (build derivations in parallel) settings.max-jobs = "auto"; # Gotta go fast (build derivations in parallel)
}; };
*/ */
programs = { programs = {
home-manager.enable = true; home-manager.enable = true;
@@ -55,9 +57,6 @@ in {
# Don't honk at me constantly # Don't honk at me constantly
unsetopt beep unsetopt beep
''; '';
envExtra = ''
export FZF_DEFAULT_COMMAND='${pkgs.fd}/bin/fd --type f --strip-cwd-prefix'
'';
syntaxHighlighting.enable = true; syntaxHighlighting.enable = true;
plugins = [ plugins = [
{ {
@@ -77,34 +76,49 @@ in {
enable = true; enable = true;
settings = { settings = {
add_newline = false; add_newline = false;
format = "$username$hostname$shlvl$directory$git_branch$git_commit$git_state$git_metrics$git_status$hg_branch$docker_context$golang$kotlin$nodejs$python$rust$terraform$nix_shell$memory_usage$aws$gcloud$openstack$azure$env_var$crystal$custom$sudo$cmd_duration$line_break$jobs$status$shell$character"; direnv.disabled = false;
format = "$all";
username.format = "[$user]($style) "; username.format = "[$user]($style) ";
hostname.format = "[$hostname]($style) "; hostname.format = "[$hostname]($style) ";
directory = {truncation_length = -1;}; directory = {
truncation_length = -1;
};
git_branch.format = "[$symbol$branch]($style) "; git_branch.format = "[$symbol$branch]($style) ";
python.format = "[py \${pyenv_prefix}(\${version} )(\\($virtualenv\\) )]($style)"; python.symbol = "py ";
nodejs.format = "[js ($version )]($style)"; nodejs.symbol = "js ";
nix_shell.format = "[nix $state( \\($name\\))]($style) "; nix_shell.symbol = "nix ";
rust.symbol = "rs ";
direnv.symbol = "de ";
}; };
}; };
direnv = { direnv = {
enable = true; enable = true;
nix-direnv.enable = true; nix-direnv.enable = true;
config.global.warn_timeout = "30s";
}; };
fzf = { fzf = {
enable = true; enable = true;
defaultCommand = "${pkgs.ripgrep}/bin/rg --files"; # Include hidden files/folders (-H) but exclude .git
defaultCommand = "${pkgs.fd}/bin/fd -H --type f -E .git";
fileWidgetCommand = "${pkgs.fd}/bin/fd -H --type f -E .git";
}; };
ssh = { ssh = {
enable = true; enable = true;
includes = ["~/.ssh/config.local"]; enableDefaultConfig = false;
matchBlocks."*" = { package = pkgs.openssh; # Use modern ssh
includes = [ "~/.ssh/config.local" ];
settings."Host *" = {
user = "samw"; user = "samw";
serverAliveInterval = 30; serverAliveInterval = 30;
serverAliveCountMax = 10; serverAliveCountMax = 10;
compression = true;
controlMaster = "autoask";
controlPath = "~/.ssh/master-%r@%n:%p";
# Close socket once last connection closes
controlPersist = "no";
}; };
}; };
}; };
+7 -1
View File
@@ -1 +1,7 @@
{pkgs, ...}: {home.packages = with pkgs; [docker colima];} { pkgs, ... }:
{
home.packages = with pkgs; [
docker
colima
];
}
+50 -38
View File
@@ -1,48 +1,60 @@
{pkgs, ...}: { { pkgs, ... }:
home.packages = with pkgs; [ git-open tea ]; {
home.packages = with pkgs; [
git-open
tea
];
programs.delta = {
# Better diffs
enable = true;
enableGitIntegration = true;
options = {
line-numbers = true;
};
};
programs.git = { programs.git = {
enable = true; enable = true;
lfs.enable = true; lfs.enable = true;
userName = "Sam Willcocks"; settings = {
userEmail = "sam@wlcx.cc"; user.name = "Sam Willcocks";
user.email = "sam@wlcx.cc";
alias = {
a = "add";
ap = "add -p";
br = "branch";
c = "commit";
ca = "commit --amend";
can = "commit --amend --no-edit";
cm = "commit -m";
co = "checkout";
d = "diff";
dc = "diff --cached";
l = "log";
lp = "log --patch";
p = "push";
pf = "push --force-with-lease";
r = "rebase";
rc = "rebase --continue";
ra = "rebase --autostash";
rai = "rebase --autostash --interactive";
rs = "restore --staged";
st = "status";
sw = "switch";
swc = "switch --create";
unp = "log --branches --not --remotes --no-walk --decorate --oneline";
delta = { gone = ''! git fetch -p && git for-each-ref --format '%(refname:short) %(upstream:track)' │ awk '$2 == "[gone]" {print $1}' | xargs -r git branch -D'';
# Better diffs };
enable = true;
options = {line-numbers = true;};
};
aliases = {
a = "add";
ap = "add -p";
br = "branch";
c = "commit";
ca = "commit --amend";
can = "commit --amend --no-edit";
cm = "commit -m";
co = "checkout";
d = "diff";
dc = "diff --cached";
l = "log";
lp = "log --patch";
p = "push";
pf = "push --force-with-lease";
r = "rebase";
rc = "rebase --continue";
ra = "rebase --autostash";
rai = "rebase --autostash --interactive";
rs = "restore --staged";
st = "status";
sw = "switch";
swc = "switch --create";
gone = ''
! git fetch -p && git for-each-ref --format '%(refname:short) %(upstream:track)' │ awk '$2 == "[gone]" {print $1}' | xargs -r git branch -D'';
};
extraConfig = {
branch.sort = "-committerdate"; branch.sort = "-committerdate";
push.default = "current"; push.default = "current";
init.defaultBranch = "main"; init.defaultBranch = "main";
merge = {
conflictStyle = "diff3";
mergiraf = {
name = "mergiraf";
driver = "${pkgs.mergiraf}/bin/mergiraf merge --git %O %A %B -s %S -x %X -y %Y -p %P -l %L";
};
};
}; };
includes = [ includes = [
# Always include local gitconfig if it's there # Always include local gitconfig if it's there
+3 -2
View File
@@ -1,4 +1,5 @@
{pkgs, lib, ...}: { { pkgs, lib, ... }:
{
programs.gpg = { programs.gpg = {
enable = true; enable = true;
mutableKeys = false; mutableKeys = false;
@@ -19,7 +20,7 @@
]; ];
# make yubikey work on macos? lolgpg # make yubikey work on macos? lolgpg
# https://github.com/NixOS/nixpkgs/issues/155629 # https://github.com/NixOS/nixpkgs/issues/155629
scdaemonSettings = (lib.optionalAttrs pkgs.stdenv.isDarwin {disable-ccid = true;}); scdaemonSettings = (lib.optionalAttrs pkgs.stdenv.isDarwin { disable-ccid = true; });
}; };
# Shouldn't have an effect on macos, on linux we need to specify a pinentry # Shouldn't have an effect on macos, on linux we need to specify a pinentry
+45
View File
@@ -0,0 +1,45 @@
{ ... }:
{
programs.helix = {
enable = true;
settings = {
theme = "monokai_pro";
editor = {
"soft-wrap".enable = true;
"file-picker".hidden = false; # Show hidden files (yes it's counter-intuitive)
gutters = [
"diagnostics"
"line-numbers"
"spacer"
"diff"
];
whitespace.render = {
space = "none";
tab = "all";
nbsp = "all";
nnbsp = "all";
newline = "none";
};
};
};
languages = {
language-server.rust-analyzer.config = {
# Don't get lost in .direnv etc and chew 100% cpu forever
files.excludeDirs = [
".git"
".cargo"
".direnv"
];
};
language = [
{
name = "python";
language-servers = [
"ty"
"basedpyright"
];
}
];
};
};
}
+22 -7
View File
@@ -1,15 +1,30 @@
{ {
pkgs, pkgs,
lib,
... ...
}: { }:
{
# Mac specific packages. # Mac specific packages.
# TODO: have this in a central packages place rather than here # TODO: have this in a central packages place rather than here
home.packages = with pkgs; [pngpaste mypkgs.qrclip]; home.packages = with pkgs; [
pngpaste
mypkgs.qrclip
];
home.sessionPath = [
"/Applications/Sublime Merge.app/Contents/SharedSupport/bin"
];
# Use secretive for SSH agent # Use secretive for SSH agent
programs.ssh.matchBlocks.all = lib.mkIf pkgs.stdenv.isDarwin { programs.ssh.settings."Host *".IdentityAgent = "~/Library/Containers/com.maxgoedjen.Secretive.SecretAgent/Data/socket.ssh";
host = "*"; programs.zsh.sessionVariables = {
extraOptions."IdentityAgent" = "~/Library/Containers/com.maxgoedjen.Secretive.SecretAgent/Data/socket.ssh"; SSH_AUTH_SOCK = "$HOME/Library/Containers/com.maxgoedjen.Secretive.SecretAgent/Data/socket.ssh";
# Make connection muxing permission work.
# Openssh by default will only use SSH_ASKPASS if it sees DISPLAY/WAYLAND_DISPLAY, so we have to force it
SSH_ASKPASS_REQUIRE = "force";
# A nice applescript permission dialog
SSH_ASKPASS = (pkgs.fetchurl {
url = "https://raw.githubusercontent.com/theseal/ssh-askpass/refs/heads/master/ssh-askpass";
hash= "sha256-bQUuGS3Mb+i4Kt+1mDP203s2W1jlRcpl/7uXA7TUZ+o=";
executable = true;
});
}; };
programs.zsh.initExtra = "eval $(/opt/homebrew/bin/brew shellenv)"; programs.zsh.initContent = "[ -e /opt/homebrew/bin/brew ] && eval $(/opt/homebrew/bin/brew shellenv)";
} }
+21 -4
View File
@@ -1,9 +1,11 @@
{pkgs}: { pkgs }:
with pkgs; rec { with pkgs;
rec {
# The stuff you want installed everywhere. The necessities. # The stuff you want installed everywhere. The necessities.
base = [ base = [
bat # cat replacement, aliased to cat in home-manager bat # cat replacement, aliased to cat in home-manager
file file
fd
git git
htop htop
lsof lsof
@@ -12,13 +14,28 @@ with pkgs; rec {
unzip unzip
vim vim
wget wget
helix
]; ];
# Networking shit # Networking shit
net = [dig iperf3 nmap socat tcpdump whois]; net = [
dig
iperf3
mtr
nmap
socat
tcpdump
];
# development tools # development tools
dev = [jq nixfmt gh glab hexyl helix]; dev = [
jq
nixfmt-rfc-style
gh
glab
hexyl
attic-client
];
all = base ++ net ++ dev; all = base ++ net ++ dev;
} }
+7 -4
View File
@@ -1,9 +1,12 @@
{pkgs, ...}: { { pkgs, ... }:
home.packages = with pkgs; [yubikey-manager]; {
home.packages = with pkgs; [ yubikey-manager ];
programs.password-store = { programs.password-store = {
enable = true; enable = true;
settings = {PASSWORD_STORE_DIR = "$HOME/.password-store";}; settings = {
package = pkgs.pass.withExtensions (exts: [exts.pass-otp]); PASSWORD_STORE_DIR = "$HOME/.password-store";
};
package = pkgs.pass.withExtensions (exts: [ exts.pass-otp ]);
}; };
programs.zsh.shellAliases = { programs.zsh.shellAliases = {
p = "pass"; p = "pass";
+52 -13
View File
@@ -2,22 +2,53 @@
# The basics that you'll want everywhere # The basics that you'll want everywhere
default = ./default.nix; default = ./default.nix;
# A machine for development # A machine for development
dev = {...}: { dev =
imports = [./git.nix ./vim.nix ./vim-dev]; { ... }:
}; {
imports = [
./git.nix
./vim.nix
./vim-dev
./helix.nix
];
};
# A machine for dev with a GUI # A machine for dev with a GUI
# TODO: detect this automatically somehow? # TODO: detect this automatically somehow?
dev-gui = {...}: { dev-gui =
imports = [./vscode.nix]; { ... }:
}; {
imports = [ ./vscode.nix ];
programs.wezterm = {
enable = true;
extraConfig = ''
return {
color_scheme = "GruvboxDarkHard",
keys = {
{
key = 'd',
mods = 'SUPER',
action = wezterm.action.SplitVertical{domain='CurrentPaneDomain'},
},
{
key = 'D',
mods = 'SUPER | SHIFT',
action = wezterm.action.SplitHorizontal{domain='CurrentPaneDomain'},
},
},
}
'';
};
};
tpmssh = ./tpmssh.nix; tpmssh = ./tpmssh.nix;
# Sensitive stuff # Sensitive stuff
sensitive = {...}: { sensitive =
imports = [ { ... }:
./passwords.nix {
./gpg.nix imports = [
]; ./passwords.nix
}; ./gpg.nix
];
};
# A MacOS machine # A MacOS machine
mac = ./macs.nix; mac = ./macs.nix;
# A machine you want to do docker stuff on # A machine you want to do docker stuff on
@@ -25,5 +56,13 @@
# A machine you want to do aws stuff on # A machine you want to do aws stuff on
aws = ./aws.nix; aws = ./aws.nix;
# A server # A server
server = {...}: {imports = [./default.nix ./git.nix ./vim.nix];}; server =
{ ... }:
{
imports = [
./default.nix
./git.nix
./vim.nix
];
};
} }
+14 -6
View File
@@ -1,5 +1,6 @@
# Enable tpm-ssh-agent in a systemd user service # Enable tpm-ssh-agent in a systemd user service
{pkgs, config, ...}: { { pkgs, config, ... }:
{
home.packages = [ pkgs.ssh-tpm-agent ]; home.packages = [ pkgs.ssh-tpm-agent ];
home.sessionVariables = { home.sessionVariables = {
SSH_AUTH_SOCK = "$(${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent --print-socket)"; SSH_AUTH_SOCK = "$(${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent --print-socket)";
@@ -22,11 +23,18 @@
Environment = '' Environment = ''
SSH_AUTH_SOCK="%t/ssh-tpm-agent.sock" SSH_AUTH_SOCK="%t/ssh-tpm-agent.sock"
''; '';
ExecStart = "${pkgs.writeShellScriptBin "start-ssh-tpm-agent" (if config.services.gpg-agent.enableSshSupport then '' ExecStart = "${
${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent -A $(${config.programs.gpg.package}/bin/gpgconf --list-dirs agent-ssh-socket) pkgs.writeShellScriptBin "start-ssh-tpm-agent" (
'' else '' if config.services.gpg-agent.enableSshSupport then
${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent ''
'')}/bin/start-ssh-tpm-agent"; ${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent -A $(${config.programs.gpg.package}/bin/gpgconf --list-dirs agent-ssh-socket)
''
else
''
${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent
''
)
}/bin/start-ssh-tpm-agent";
PassEnvironment = "SSH_AGENT_PID"; PassEnvironment = "SSH_AGENT_PID";
SuccessExitStatus = 2; SuccessExitStatus = 2;
Type = "simple"; Type = "simple";
+10 -5
View File
@@ -3,14 +3,19 @@
lib, lib,
system, system,
... ...
}: { }:
home.packages = with pkgs; [nil]; {
programs.neovim.plugins = with pkgs.vimPlugins; home.packages = with pkgs; [
nil
nixd
];
programs.neovim.plugins =
with pkgs.vimPlugins;
[ [
# More fancy shit # More fancy shit
nvim-treesitter nvim-treesitter
trouble-nvim trouble-nvim
# Language server/completions # Language server/completions
nvim-lspconfig nvim-lspconfig
nvim-cmp nvim-cmp
cmp-nvim-lsp cmp-nvim-lsp
@@ -32,7 +37,7 @@
] ]
# delve is unsupported on aarch64-linux and golangci-lint is broken on darwin # delve is unsupported on aarch64-linux and golangci-lint is broken on darwin
# (see https://github.com/NixOS/nixpkgs/issues/168984). # (see https://github.com/NixOS/nixpkgs/issues/168984).
++ lib.optionals (system != "aarch64-linux" && !pkgs.stdenv.isDarwin) [vim-go]; ++ lib.optionals (system != "aarch64-linux" && !pkgs.stdenv.isDarwin) [ vim-go ];
programs.neovim.extraConfig = '' programs.neovim.extraConfig = ''
lua <<EOF lua <<EOF
${builtins.readFile ./dev.lua} ${builtins.readFile ./dev.lua}
+11
View File
@@ -54,6 +54,10 @@ require'lspconfig'.nil_ls.setup{
on_attach = on_attach, on_attach = on_attach,
capabilities = capabilities, capabilities = capabilities,
} }
require'lspconfig'.nixd.setup{
on_attach = on_attach,
capabilities = capabilities,
}
require'lspconfig'.rust_analyzer.setup{ require'lspconfig'.rust_analyzer.setup{
on_attach = on_attach, on_attach = on_attach,
capabilities = capabilities, capabilities = capabilities,
@@ -71,6 +75,13 @@ require'lspconfig'.rust_analyzer.setup{
description = 'Open documentation for the symbol under the cursor in default browser', description = 'Open documentation for the symbol under the cursor in default browser',
}, },
}, },
settings = {
["rust-analyzer"] = {
procMacro = {
enable = false,
},
},
},
} }
require'lspconfig'.dhall_lsp_server.setup{ require'lspconfig'.dhall_lsp_server.setup{
on_attach = on_attach, on_attach = on_attach,
+11 -5
View File
@@ -4,29 +4,35 @@
pkgs, pkgs,
lib, lib,
... ...
}: { }:
{
home.sessionVariables.EDITOR = lib.mkForce "nvim"; home.sessionVariables.EDITOR = lib.mkForce "nvim";
home.packages = with pkgs; [ripgrep]; home.packages = with pkgs; [ ripgrep ];
programs.neovim = { programs.neovim = {
enable = true; enable = true;
viAlias = true; viAlias = true;
vimAlias = true; vimAlias = true;
# defaults changed from true in 26.05
withRuby = false;
withPython3 = false;
plugins = with pkgs.vimPlugins; [ plugins = with pkgs.vimPlugins; [
# Basic stuff # Basic stuff
vim-sensible vim-sensible
vim-noctu # 16color colorscheme vim-noctu # 16color colorscheme
gruvbox-nvim gruvbox-nvim
fzfWrapper # The basic "built in" fzf stuff fzf-wrapper # The basic "built in" fzf stuff
fzf-vim # The fancier opt in fzf stuff fzf-vim # The fancier opt in fzf stuff
# The only language plugin you always need... because if it's running nixos you # The only language plugin you always need... because if it's running nixos you
# *will* be editing nix files! # *will* be editing nix files!
vim-nix vim-nix
# Git stuff # Git stuff
fugitive vim-fugitive
vim-gitgutter vim-gitgutter
# More stuff idk # More stuff idk
emmet-vim emmet-vim
vim-sleuth # guess whitespace settings from file vim-sleuth # guess whitespace settings from file
]; ];
extraConfig = '' extraConfig = ''
lua <<EOF lua <<EOF
+8 -6
View File
@@ -1,19 +1,21 @@
{pkgs, ...}: { { pkgs, ... }:
programs.vscode = { {
programs.vscodium = {
enable = true; enable = true;
package = pkgs.vscodium;
mutableExtensionsDir = false; mutableExtensionsDir = false;
extensions = with pkgs.vscode-extensions; [ profiles.default.extensions = with pkgs.vscode-extensions; [
matklad.rust-analyzer rust-lang.rust-analyzer
jdinhlife.gruvbox jdinhlife.gruvbox
jnoortheen.nix-ide jnoortheen.nix-ide
editorconfig.editorconfig editorconfig.editorconfig
]; ];
userSettings = { profiles.default.userSettings = {
"update.mode" = "none"; "update.mode" = "none";
"window.autoDetectColorScheme" = true; "window.autoDetectColorScheme" = true;
"workbench.preferredDarkColorTheme" = "Gruvbox Dark Hard"; "workbench.preferredDarkColorTheme" = "Gruvbox Dark Hard";
"workbench.preferredLightColorTheme" = "Gruvbox Light Hard";
"files.trimTrailingWhitespace" = true; "files.trimTrailingWhitespace" = true;
"emmet.includeLanguages"."django-html" = "html";
# Don't try to write to the nix-managed .ssh/config # Don't try to write to the nix-managed .ssh/config
"remote.SSH.configFile" = "~/.ssh/config.local"; "remote.SSH.configFile" = "~/.ssh/config.local";
"editor.rulers" = [ 90 ]; "editor.rulers" = [ 90 ];
+1
View File
@@ -5,5 +5,6 @@
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIMvrgrLnE+AQBOBRiBoTFkbWaYTvqaBzIp4OfDiXUij" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIMvrgrLnE+AQBOBRiBoTFkbWaYTvqaBzIp4OfDiXUij"
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDQdGzwYiallvWXIHgSAf2GOwMJKA8bxPmwyuO+vsd1HwB65hMRPCpKS+FNLIpkrADNnuhGS3xGCGSSuQ+zAu/g= zinc-se-main@secretive.zinc.local" "ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDQdGzwYiallvWXIHgSAf2GOwMJKA8bxPmwyuO+vsd1HwB65hMRPCpKS+FNLIpkrADNnuhGS3xGCGSSuQ+zAu/g= zinc-se-main@secretive.zinc.local"
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBNLrJyUXmiFWb9vhlTWZLYr64IsKut+c9TGqq3/uwPDeF4X0Qb2jzxqXfQcDSztjR09JHbC8BOqfpYYT9LHahIo= YubiKey #13340583 PIV Slot 9a" "ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBNLrJyUXmiFWb9vhlTWZLYr64IsKut+c9TGqq3/uwPDeF4X0Qb2jzxqXfQcDSztjR09JHbC8BOqfpYYT9LHahIo= YubiKey #13340583 PIV Slot 9a"
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBC/kJYueV9cBlyPsYhC0Q2HQR+E6MswwUF6hwXrkbb4JPNn9bD2PM2GjXQe0rz6KWPr4LYkbGTo9zbRQg3d2MTE= gallium-se-main@secretive.gallium.local"
]; ];
} }
+3 -2
View File
@@ -1,4 +1,5 @@
# TODO: auto import everything # TODO: auto import everything
{pkgs, ...}: { { pkgs, ... }:
qrclip = pkgs.callPackage ./qrclip {}; {
qrclip = pkgs.callPackage ./qrclip { };
} }
+10 -7
View File
@@ -2,11 +2,14 @@
pkgs, pkgs,
lib, lib,
stdenv, stdenv,
}: let }:
zbar = pkgs.zbar.override {enableVideo = false;}; let
zbar = pkgs.zbar.override { enableVideo = false; };
in in
(pkgs.writeShellScriptBin "qrclip" '' (pkgs.writeShellScriptBin "qrclip" ''
set -eo pipefail set -eo pipefail
${pkgs.pngpaste}/bin/pngpaste - | ${zbar}/bin/zbarimg --raw -q1 - ${pkgs.pngpaste}/bin/pngpaste - | ${zbar}/bin/zbarimg --raw -q1 -
'') '')
// {meta.platforms = lib.platforms.darwin;} // {
meta.platforms = lib.platforms.darwin;
}