chiasson-nix
My personal NixOS + Home Manager flake. flake.nix feeds ./modules through flake-parts and import-tree so config stays in small files instead of one monster module.
How to work on it: conventions.md.
Hosts
| Host | What it is |
|---|---|
t2mbp |
Intel MacBook with T2 chip — Niri/DMS, t2linux + fan daemon |
14900k |
Main x86 desktop — same GUI stack, also cross-builds aarch64 and exports NFS for Jellyfin |
ideapad |
Lenovo IdeaPad Duet 3 (Chromebook, lenovo-wormdingler) — Mobile NixOS on Snapdragon, Niri/DMS, touch/tablet bits in _private/ |
uConsole |
Clockwork Pi uConsole (Pi 5 CM) — Niri/DMS, built with nixos-raspberrypi + oom-hardware |
nix-server |
Headless x86 VM — Attic, Gitea, Immich, SwiftShare, Personal-Website, DDRM, Portainer, … |
r5500 |
Headless media box — Jellyfin, *arr, qBittorrent, Dispatcharr; library on NFS from nix-server |
Each machine: modules/hosts/<name>/default.nix → nixosConfigurations.<name>, real config in *Configuration + optional _private/ and _services/.
Features at a glance
- Users catalog — one catalog in
modules/system/users.nix, pick who exists on a host withchiasson.users.enabled = [ "example" ], override per host. Home Manager wires itself from the same list. - SSH + Bitwarden (rbw) keys — one ed25519 keypair per catalog user, private key in Bitwarden, public key in
modules/ssh/inventory.nix. Outbound SSH uses a.pubfilter against the rbw agent; inboundauthorized_keysare generated from the same inventory. Full wiring in conventions.md. - Wisdom modules — Home Manager slices in
modules/wisdom/auto-catalog vialib.wisdomCatalogExtraModules(defined inmodules/desktop/options.nix). The baselinewisdommodule handles git identity + shared tools; all otherwisdom*exports are pulled in once per user throughdesktopHomeBase→chiasson.users.extraModules.olivier. Hosts only flipchiasson.home.<category>.<slice>.enable— no manual imports inhome.nix. Categories includeapps(spotify, discord, localsend),browsers(chrome, edge, zen, …),editors(cursor, vscode, obsidian, …),shells(bash, fish, oh-my-posh, yazi),desktop(gtk-qt-theming, screenshot), andterminals(kitty). Trivial single-package slices can be written with thelib.wisdomSlicehelper instead of repeating theroot/cfg+mkIfboilerplate. - Wallpapers from a dedicated repo —
modules/desktop/wallpapers.nixpinsinputs.wallpapersinto the store and exposes it asCHIASSON_NIX_WALLPAPERSand/etc/wallpapers. Overridechiasson.desktop.wallpapers.sourceif needed. - Private host data — import-tree skips
_private/globally, so machine-only files (firmware quirks, display configs, service tweaks) live next to the host module without leaking elsewhere.
Deploy / rebuild
Remote builds use the builder user (systemDeployBuilder, wired through client-services on desktops/laptops/tablets).
Fleet deploy is Navi — config in modules/deploy/navi.nix, outputs flake.navi / flake.naviHive.
nix develop # devShell has navi + just + hints
just # list local helpers like `sync-dms`
navi apply --on <host>
navi apply-local --node 14900k --sudo # this machine, if hostname matches
navi tui # interactive fleet dashboard
Plain rebuild still works: sudo nixos-rebuild switch --flake .#<host>.
Repo layout
modules/
hosts/<host>/ # per-machine composition
system/ # nixosModules.system aggregate
desktop/ # GUI stack (niri, hyprland, plasma, DMS)
wisdom/ # HM modules (exports still named wisdom*)
ssh/ # inbound NixOS + outbound HM
deploy/ # navi hive
patches/ # one-off patches (yt-dlp, t2fanrd, …)
Machine-only stuff lives in hosts/<host>/_private/ — import-tree skips _private/ globally, so those files only get pulled in where you import them.