Skip to content

Repository files navigation

CI Update Dependencies Deploy Check

About

Personal NixOS, nix-darwin, and home-manager configuration built on snowfall-lib. Manages multiple systems across three architectures with declarative, role-based configuration, multi-user "family" hosts with adult/child profiles, encrypted secrets, and opt-in persistence.

Features

Structure & Tooling

  • Modular organization with snowfall-lib and role-based composition
  • Custom Neovim setup via nixvim (AI assistants, multi-language support)
  • Multiple terminals (ghostty, kitty, alacritty, foot) and shells (fish, zsh)

System Management

  • Multi-user "family" hosts: every account (including the primary) declared uniformly via nix-config.users, with adult/child profiles driving group presets, sudo, and per-person identities
  • Declarative disk layout with disko (BTRFS + LUKS encryption)
  • Opt-in persistence through impermanence + blank snapshot
  • SOPS-nix secrets management with per-host age keys
  • Remote deployment via deploy-rs, fresh installs via nixos-anywhere

Desktop

  • Hyprland (hypridle, hyprlock, hyprpaper, pyprland) and GNOME desktop environments
  • Profile-based GNOME: full power-user desktop for adults vs. a locked-down child desktop — minimal extensions, hidden Settings, no WiFi/Bluetooth toggling, app grid disabled, restricted app dock
  • Stylix system-wide theming with Catppuccin color scheme
  • Waybar, swaync, rofi, wlogout, kanshi

Homelab

  • Home Assistant with 9 sub-modules (climate, heatpump, inverter, zigbee2mqtt, telegram, weather, plugs, night-schedule, zones)
  • Media stack: Jellyfin, Sonarr, Radarr, Prowlarr, qBittorrent, MiniDLNA
  • k3s (Kubernetes), Podman, Tailscale VPN, nginx, Minecraft server
  • Restic backup with client-server architecture

macOS

  • nix-darwin with Homebrew integration
  • Colima/Lima/Rancher virtualization

Infrastructure

  • MikroTik RouterOS managed via terranix/OpenTofu
  • CI/CD: GitHub Actions (flake check, system builds, deploy check, security scan, weekly auto-update)
  • Custom live ISO for NixOS installation

Configurations

Hostname Architecture Hardware Role OS State
desktop x86_64-linux Intel i7-2600K, GTX 560 Ti, 32GB Desktop NixOS Active
homebook x86_64-linux Shared family laptop (TBD) Homebook — multi-user (adult + child) NixOS Scaffold
server aarch64-linux Raspberry Pi 4 Model B, 8GB Home Server NixOS Active
vm x86_64-linux Vagrant VM Desktop (test) NixOS Active
workbook aarch64-darwin Apple Silicon MacBook Work macOS Active
minimal x86_64-install-iso Any Installer NixOS ISO -

Architecture

.
├── systems/          # System configs: desktop, server, vm, workbook, minimal
├── homes/            # Home-manager configs: alexander@{desktop,homebook,vm}, dima@homebook (child), oleksandrsy@workbook
├── modules/
│   ├── nixos/        # NixOS modules (roles, services, desktops, hardware, disks, cli, security)
│   ├── home/         # Home-manager modules (roles, desktops, cli, development, browsers, media)
│   └── darwin/       # nix-darwin modules (roles, system, services, cli)
├── packages/         # Custom packages: nvim (nixvim), install ISO, wallpapers
├── overlays/         # Nixpkgs overlays
├── lib/              # Library: module helpers, context detection, deploy config, network utils
├── infra/            # Infrastructure-as-code: MikroTik router (terranix/OpenTofu)
└── scripts/          # Bootstrap and utility scripts

All modules use the nix-config namespace (config.nix-config.*). Roles compose related modules: e.g., home-server enables server + media-server + smart-home + gaming-server + backup.

See docs/architecture.md for the full role hierarchy, library functions, and flake inputs.

Usage

Getting Started

git clone git@github.com:aleks-sidorenko/nix-config.git ~/.nix-config
cd ~/.nix-config

Prerequisites: Nix installed, git. For secrets management: pass configured, PGP key available.

Local Deploy

# NixOS system configuration (uses hostname to find flake)
nh os switch

# Home-manager user configuration (uses hostname + username)
nh home switch

# Alternative without nh
sudo nixos-rebuild switch --flake .

Remote Deploy

just deploy <hostname>                     # Deploy (remote build by default)
just deploy <hostname> --dry-run           # Preview changes
just deploy router                         # Deploy MikroTik router config

Build Installer ISO

just iso-build            # Build minimal NixOS installer ISO (-> ./result/iso/)
just iso-write /dev/sdX   # Write the built ISO to a USB device
just iso /dev/sdX         # Build + write in one step

For the full build → flash → boot → login walkthrough and fresh installations on new hardware, see docs/bootstrap.md.

Secrets

Secrets are encrypted with SOPS using age keys derived from each host's SSH key.

just secrets-list                          # List all secrets
just secrets-edit nixos                    # Edit NixOS secrets
just secrets-edit home                     # Edit home-manager secrets

Secrets files:

  • modules/nixos/secrets.yaml - system secrets (user passwords, API keys, WiFi)
  • modules/home/secrets.yaml - user secrets
  • infra/router/secrets.yaml - router secrets

To add a new host's key, see docs/bootstrap.md.

Maintenance

just update                                # Update flake inputs
just cleanup                               # Garbage collect old generations
just lint                                  # statix + deadnix (read-only)
just lint-fix                              # Auto-fix linting issues
just flake-check                           # nix flake check
just info                                  # Show system info
just disk-usage                            # Show nix store usage

Development

# Typical workflow
just format                                # Format nix files
just check                                 # Verify code quality (CI-friendly)
just build                                 # Test build without switching
just deploy <hostname>                     # Deploy

CI runs on push/PR to master: flake check, formatting, security scan (Trivy). Full system and home-manager builds run on master branch only. Flake inputs are auto-updated weekly.

Companion flakes

Reusable components are maintained as standalone flakes and consumed as inputs here:

Flake Description
nix-nvim Configurable Neovim distribution built with nixvim
nix-routeros MikroTik RouterOS management with terranix
nix-wallpapers Vendored wallpaper collection (hermetic, no hash drift)

Documentation

Document Description
docs/architecture.md Repository structure, role hierarchy, library functions, flake inputs
docs/bootstrap.md Fresh installation, bootstrap process, disk formatting, RPi4 setup
docs/homelab.md Homelab services overview, network layout
docs/router.md MikroTik router management with terranix/OpenTofu
docs/references.md Inspirations, NixOS resources, credits

Credits

See docs/references.md for inspirations, resources, and wallpaper credits.

License

MIT — see LICENSE.

Releases

Packages

Contributors

Languages