No description
  • Nix 95%
  • Shell 5%
Find a file
steffen 29b17f1a99
All checks were successful
CI / flake-check (push) Successful in 26s
CI / build-hosts (push) Successful in 22s
CI / build-hosts-displaylink (push) Successful in 11s
CI / build-home (push) Successful in 19m50s
faster hm build time
2026-10-08 17:22:56 +02:00
.forgejo forgejo modernization + cleanup 2026-10-08 16:12:59 +02:00
hosts forgejo modernization + cleanup 2026-10-08 16:12:59 +02:00
modules removed redundant cache, give lydia sudo & enable git 2026-08-08 19:21:05 +02:00
overlays updated flake, chanked final.stdenv.hostPlatform.system 2026-09-23 13:53:10 +02:00
pkgs fix(nextcloud-sync): use temp HOME for netrc instead of --netrc-file 2026-03-15 08:43:53 +01:00
users faster hm build time 2026-10-08 17:22:56 +02:00
.gitignore not working migration - hyprland lua fix needed 2026-06-05 09:10:08 +02:00
.sops.yaml reworked l13g2 for lydia 2026-10-08 10:11:44 +02:00
CLAUDE.md forgejo modernization + cleanup 2026-10-08 16:12:59 +02:00
flake.lock reworked l13g2 for lydia 2026-10-08 10:11:44 +02:00
flake.nix forgejo modernization + cleanup 2026-10-08 16:12:59 +02:00
README.md forgejo modernization + cleanup 2026-10-08 16:12:59 +02:00

nixos-config

Personal NixOS configuration for three machines, built on top of synix by sid.

Repository: git.portuus.de/steffen/nix-config (Forgejo, SSH-Remote forgejo@git.portuus.de:steffen/nix-config.git).

Hosts

Host Machine
X670E AMD desktop
L13G2 ThinkPad L13 Gen 2
pro5 ThinkPad AMD laptop

Struktur

flake.nix                        # Inputs, Outputs, nixosConfigurations, homeConfigurations
hosts/
  X670E/                         # Desktop: boot, hardware, packages, services, users
  L13G2/                         # Laptop: boot, hardware, packages, services, users
  pro5/                          # Laptop: boot, hardware, packages, services, users
modules/
  nixos/
    common/                      # Overlays für nixpkgs
    displaylink.nix              # custom.displaylink.enable
    keychron.nix                 # custom.keychron.enable
    pi.nix                       # Raspberry Pi USB Boot
    picotech.nix                 # custom.picotech.enable
    printing.nix                 # custom.printing.enable (CUPS + Avahi)
  home/
    hypridle/                    # Idle-Management (Lock, Dimming, DPMS)
    nextcloud-sync/              # services.nextcloud-sync.*
    wallpaper-rotate/            # Wallpaper-Rotation
overlays/                        # synix, local, modifications, unstable, old-stable
pkgs/                            # Lokale Derivations (pkgs.local.*)
users/steffen/
  default.nix                    # NixOS User-Definition (normalUsers)
  pubkeys/                       # SSH Public Keys pro Host
  home/
    default.nix                  # Globale HM-Config (git, nixvim, gpg, stateVersion)
    hyprland/                    # Hyprland WM, Waybar, Stylix, Pakete, Programme
    hosts/
      X670E/                     # Desktop-spezifisch: Virtualisierung, Gaming, Creative
      L13G2/                     # Laptop-spezifisch: Waybar Battery-Modul
      pro5/                      # Laptop-spezifisch
users/lydia/home/                # Home-Manager-Config für lydia (lydia@L13G2)
.forgejo/workflows/              # CI (ci.yml) und CVE-Scan (security.yml)

Wichtige Inputs

Input Zweck
nixpkgs NixOS 26.05 (Stable)
nixpkgs-unstable Unstable-Kanal via pkgs.unstable.*
nixpkgs-old-stable 25.11 via pkgs.old-stable.*
synix Gemeinsame Module, Overlays und Lib-Erweiterungen
home-manager Home Manager release-26.05
nixvim Neovim-Konfiguration als Nix-Modul
stylix System-weites Theming (Colorscheme: Oxocarbon)
sops-nix Secrets-Management via age
nix-flatpak Flatpak-Pakete deklarativ verwalten
comfyui-nix ComfyUI für AI-Bildgenerierung

Befehle

# System bauen (ohne switchen)
nixos-rebuild build --flake .#X670E
nixos-rebuild build --flake .#L13G2
nixos-rebuild build --flake .#pro5

# Home Manager bauen
home-manager build --flake .#steffen@X670E
home-manager build --flake .#steffen@L13G2
home-manager build --flake .#steffen@pro5

# Flake validieren (inkl. pre-commit-check)
nix flake check

# Nur die Lint-Hooks (nixfmt, statix, shellcheck, yamllint, actionlint)
nix build --no-link .#checks.x86_64-linux.pre-commit-check

# DevShell mit installierten Git-Hooks
nix develop

# System anwenden (nur wenn explizit gewünscht)
sudo nixos-rebuild switch --flake .#X670E
home-manager switch --flake .#steffen@X670E

CI

Forgejo Actions auf dem Runner portuus-nix (Host-Executor auf portuus):

  • .forgejo/workflows/ci.yml: bei Push auf main und bei Pull Requests nix flake check, danach Builds von X670E, L13G2-no-displaylink, steffen@X670E und steffen@L13G2. L13G2 mit DisplayLink wird ebenfalls gebaut, darf aber fehlschlagen (der Treiber braucht einen manuellen Download).
  • .forgejo/workflows/security.yml: wöchentlicher CVE-Scan (vulnix, nvd-Diff zum letzten Scan) für X670E, L13G2-no-displaylink und pro5; schlägt bei neuen CVEs mit CVSS >= 9.0 fehl.

Secrets

Secrets werden mit sops-nix und einem age-Key verwaltet. Verschlüsselte Secrets liegen in hosts/<host>/secrets/secrets.yaml und users/steffen/home/secrets/secrets.yaml. Private Keys niemals committen.

Danksagung

Großes Dankeschön an sid für synix — das Fundament dieser Config. synix liefert die geteilten NixOS- und Home-Manager-Module, Overlays, Pakete und eine lib-Erweiterung auf der diese Konfiguration aufbaut.