Skip to content

Swarsel/.dotfiles

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

996 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

nixos logo using earthbound giant step icon
   ~SwarselSystems~ (nΓ©e .dotfiles)

"With NixOS, your entire system is just one file: /etc/nixos/configuration.nix!"
... I took that literally.

screenshot showing emacs and glide screenshot showing fastfetch and music player screenshot showing noctalia bar screenshot showing wallpaper

Overview

  • Literate configuration defining my entire infrastructure, including Emacs
  • Dendritic configuration based on flakes (using flake-file) for personal hosts as well as servers on:
  • Streamlined configuration and deployment pipeline:
    • Framework for packages, overlays, dendritic modules (features), and library functions
    • Dynamically generated config:
      • host configurations
      • dns records
      • network setup (+ WireGuard mesh on systemd-networkd)
    • Remote Builders for [x86_64,aarch64]-linux running on Buildbot, feeding a private nix binary cache and updating the flake on a weekly basis
    • Bootstrapping:
      • Limited local installer (no secrets handling) with a (kinda un-)supported demo build
      • Fully autonomous remote deployment using nixos-anywhere and disko (with secrets handling)
    • Improved nix tooling
  • Support for advanced features:
    • Secrets handling using sops-nix (pls no pwn ❀️)
    • Management of personally identifiable information using nix-plugins
    • Full Yubikey support (with SSH support for SK keys, certs and PGP keys)
    • LUKS-encryption with support for remote disk unlock over SSH
    • Secure boot using Lanzaboote
    • BTRFS-based Impermanence
    • Configuration shared between configurations (configuration for one nixosConfiguration can be defined in another nixosConfiguration)
    • Global attributes shared between all configurations to reduce attribute re-declaration
    • Config library for defining config-based functions for generating service information
    • Reduced friction between full NixOS- and home-manager-only deployments
      • efficient secrets handling depending on system context
      • automatic config sharing between contexts
      • dendritic structure for keeping features in a centralized manner

Infrastructure

Click here for a summary of my infrastructure full topology diagram

Programs

Topic Program
⛩️ Bar Waybar or Noctalia Shell
βœ’οΈ Editor Emacs
🌐 Browser Firefox
🎨 Theme City-Lights (managed by stylix)
🐚 Shell zsh
πŸ–₯️ Terminal Kitty
πŸš€ Launcher Fuzzel or Noctalia Shell
🚨 Alerts Mako or Noctalia Shell
πŸšͺ DM greetd
πŸͺŸ WM SwayFX or Niri

Services

Topic Program
☁️ S3 Garage
βš“ Anki Sync Anki Sync Server
⛏️ Minecraft Minecraft
βœ‚οΈ Paste Tool Microbin
βœ‰οΈ Mail simple-nixos-mailserver
πŸƒ Collections Koillection
🌳 Git Forgejo
🍴 RSS FreshRss
🍽️ Recipes Mealie
🎞️ Photos Immich
🎡 Music Navidrome + Spotifyd + MPD
πŸ™ Nix Build farm Buildbot
🐽 Threat Detection CrowdSec
πŸ‘€ DNS Records NSD
πŸ‘οΈ Monitoring Grafana + Mimir + Loki + Tempo + Alloy + Pyroscope + Gotify
πŸ’Έ Finance Firefly-III
πŸ’Ύ Backups Restic
πŸ“ Filesharing Nextcloud + CopyParty + Croc
πŸ“„ Documents Paperless
πŸ“… CalDav/CardDav Radicale
πŸ“– Books Kavita
πŸ“Έ Image Sharing Slink
πŸ“Ί Video Streaming Invidious + Invidious Companion
πŸ“Ό Videos Jellyfin
πŸ”„ File Sync Syncthing
πŸ”Ž Search Engine SearXNG
πŸ”‘ Cert-based SSH OPKSSH
πŸ”— Link Shortener Shlink
πŸ”¨ Home Asset Management Homebox
πŸ•ΈοΈ Nix Binary Cache Attic
πŸ—ƒοΈ Shell History Atuin
πŸ—¨οΈ Messaging Matrix
πŸš‡ VPN Access Firezone
πŸ›ŽοΈ DHCP Kea
πŸ›‘οΈ Local DNS Resolver AdGuard Home
🦊 Firefox Sync Firefox-Syncserver
πŸͺŽ Second Hand Site Info Shopservatory + Socks Proxy
πŸͺͺ SSO Kanidm + oauth2-proxy

Hosts

Name Hardware Use
πŸ’» bakery Lenovo Ideapad 720S-13IKB Personal laptop
πŸ’» machpizza MacBook Pro 2016 MacOS reference and build sandbox
πŸ’» pyramid Framework Laptop 16, AMD 7940HS, RX 7700S, 64GB RAM Work laptop
🏠 treehouse NVIDIA DGX Spark AI Workstation, remote builder, hm-only-reference
πŸ–₯️ hintbooth HUNSN RM02, 8GB RAM Router, DNS Resolver, home NGINX endpoint
πŸ–₯️ summers ASUS Z10PA-D8, 2* Intel Xeon E5-2650 v4, 128GB RAM Homeserver (microvms), remote builder, data storage
πŸ–₯️ winters ASRock J4105-ITX, 32GB RAM Homeserver (IoT server in spe)
☁️ belchsfactory Cloud Server: 4 vCPUs, 24GB RAM Hydra builder and nix binary cache
☁️ eagleland Cloud Server: 2 vCPUs, 8GB RAM Mailserver
☁️ liliputsteps Cloud Server: 1 vCPUs, 8GB RAM SSH bastion
☁️ moonside Cloud Server: 4 vCPUs, 24GB RAM Game servers, syncthing + other lightweight services
☁️ stoicclub Cloud Server: 1 vCPUs, 8GB RAM Authoritative DNS server
☁️ twothreetunnel Cloud Server: 2 vCPUs, 8GB RAM Service proxy
πŸͺŸ chaostheater Asus Z97-A, i7-4790k, GTX970, 32GB RAM Home Game Streaming Server (Windows/AtlasOS, not nix-managed)
πŸ“± magicant Samsung Galaxy Z Flip 6 Phone
πŸ’Ώ brickroad - Kexec tarball for bootstrapping low-memory machines
πŸ’Ώ drugstore - NixOS-installer ISO for bootstrapping new hosts
πŸ’Ώ policestation - NixOS live ISO for generating cryptographic keys
❔ hotel - Demo config for checking out this configuration
❔ toto - Helper configuration for deployment testing
❔ vacanthouse - Staging environment

Documentation

The full documentation can be found here:

SwarselSystems literate configuration

I went to great lengths in order to document the full design process of my infrastructure properly; the above document strives to serve as an introductory lecture to nix / NixOS while at the same time explaining the config in general.

Emacs

If you came here for my raw Emacs configuration, the relevant files live here in elisp form (these files are generated from the nix emacs-init module):

Getting started

Demo configuration

Click here for instructions on how to install the demo system

If you just want to see if this configuration is for you, run this command on any system that has nix installed:

nix run --experimental-features 'nix-command flakes' github:Swarsel/.dotfiles#swarsel-rebuild -- -u <YOUR_USERNAME>

This will activate the hotel configuration on your system, which is a de-facto mirror of my main configuration with secret-based settings removed. Since you do not have my SSH keys, the installer automatically replaces the private flake inputs (my work repository and the encrypted repository secrets) with public demo stand-ins via --override-input - nothing in the repository is modified for this. This should only be used to evaluate the system - if you want to use it long-term, you will need to create a fork and make some changes.

Deployment

Click here for deployment instructions

The deployment process for this configuration is mostly automated, there are only a few steps that are needed to be done manually. You can choose between a remote deployment strategy that is also able to deploy new age keys for sops for you and a local installer that will only install the system without any secret handling.

Remote deployment (recommended if you have at least one running system)

  1. Fork this repo, and write your own host config at hosts/nixos/<YOUR_ARCHITECTURE>/<YOUR_CONFIG_NAME>/default.nix (you can use one of the other configurations as a template. Also see https://github.com/Swarsel/.dotfiles/tree/main/modules for a list of all additional options). At the very least, you should replace the secrets/ directory with your own secrets and replace the SSH public keys with your own ones (otherwise I will come visit you!πŸ”“β€οΈ). I personally recommend to use the literate configuration and org-babel-tangle-file in Emacs, but you can also simply edit the separate .nix files.
  2. Have a system with nix available booted (this does not need to be installed, i.e. you can use a NixOS installer image; a custom minimal installer ISO can be built by running just iso in the root of this repo)
  3. Make sure that your Yubikey is plugged in or that you have your SSH key available (and configured)
  4. Run swarsel-bootstrap -n <CONFIGURATION_NAME> -d <TARGET_IP> on your existing system. - Alternatively (if you run this on a system that is not yet running this configuration), you can also run nix run --experimental-features 'nix-command flakes' github:Swarsel/.dotfiles -- -n <CONFIGURATION_NAME> -d <TARGET_IP> (this runs the same program as the command above).
  5. Follow the installers instructions: - you will have to choose a disk encryption password (if you want that feature) - you will have to confirm once that the target system has rebooted - you will have to enter the root password once during the final system install
  6. That should be it! The installer will take care of setting up disks, secrets, and the rest of the hardware configuration! You will still have to sign in manually to some web services etc.

Local deployment (recommended for setting up the first system)

  1. Boot the latest install ISO from this repository on an UEFI system.
  2. Run swarsel-install -n <CONFIGURATION_NAME>
  3. Reboot

Alternatively, to install this from any NixOS live ISO, run nix run --experimental-features 'nix-command flakes' github:Swarsel/.dotfiles#swarsel-install -- -n <CONFIGURATION_NAME> at step 2.

Attributions, Acknowledgments, Inspirations, etc.

I would like to express my gratitude (not solely) to:

The people who help maintain NixOS, nix-community, and other nix-related projects.
The people who have inspired me with their configurations

If you feel that I forgot to pay you tribute for code that I used in this repository, please shoot me a message and I will fix it :)

FAQ

Q: How do I get started with nix?

A: Click here for a small list of tips that should be helpful if you are new to the nix ecosystem

Q: Why Is this just called .dotfiles?

A: Would you rename your children once they turn 18?