Skip to content

Commit f188cdd

Browse files
authored
Merge branch 'main' into feat/nono-claude-code-sandbox
2 parents 5c08a9e + e9cdfea commit f188cdd

4 files changed

Lines changed: 97 additions & 11 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,24 @@ on:
66
branches: main
77

88
jobs:
9+
eval:
10+
runs-on: ubuntu-latest
11+
steps:
12+
- uses: actions/checkout@v4
13+
- uses: cachix/install-nix-action@v31
14+
with:
15+
github_access_token: ${{ secrets.GITHUB_TOKEN }}
16+
- name: Check all configurations evaluate
17+
run: |
18+
for host in glyph spore zeta; do
19+
echo "Evaluating $host..."
20+
nix eval .#nixosConfigurations.$host.config.system.build.toplevel.drvPath
21+
done
22+
echo "Evaluating Rhizome..."
23+
nix eval .#darwinConfigurations.Rhizome.system.drvPath
24+
925
build:
26+
needs: eval
1027
strategy:
1128
fail-fast: false
1229
matrix:

‎CLAUDE.md‎

Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,15 @@ nixos-rebuild switch --flake .#hostname # Linux
4747
nixos-rebuild switch --flake .#spore --target-host root@spore --build-host localhost
4848
```
4949

50+
**Checking changes before committing:**
51+
```bash
52+
# NixOS hosts:
53+
nix-flake eval nixosConfigurations.hostname.config.system.build.toplevel.drvPath
54+
# macOS hosts:
55+
nix-flake eval darwinConfigurations.Rhizome.system.drvPath
56+
```
57+
Evaluates a host's configuration without building it. Catches option conflicts and type errors fast — run this after editing any NixOS module or host config.
58+
5059
**Flake management:**
5160
```bash
5261
nix flake update --commit-lock-file
@@ -73,6 +82,22 @@ Secrets are organized using the principle of least privilege:
7382
- Each host only has access to its own secrets plus admin keys
7483
- Global secrets (if any) are defined in `lib/secrets/default.nix`
7584

85+
**agenix workflow:**
86+
```bash
87+
# Edit an existing secret (must be on a host with access, or have the deploy key):
88+
agenix -e hosts/spore/secrets/some-secret.age
89+
90+
# Add a new secret:
91+
# 1. Add an entry to lib/secrets/<host>.nix with the appropriate publicKeys
92+
# 2. Run: agenix -e hosts/<host>/secrets/<name>.age
93+
# 3. Reference it in the host config via age.secrets.<name>.file
94+
95+
# Rekey all secrets after adding a new host key:
96+
agenix --rekey
97+
```
98+
- Keys are defined in `lib/keys.nix` — each host's key is read from `hosts/<host>/key.pub`
99+
- A new host must have its key added to `lib/keys.nix` and any relevant secrets files before it can decrypt them
100+
76101
## Package and Overlay Management
77102

78103
Custom packages and overlays are organized for clarity:
@@ -84,6 +109,19 @@ Custom packages and overlays are organized for clarity:
84109
## Branching
85110

86111
- Branches should be scoped to a single host whenever possible. This keeps deploys independent and reduces risk of cross-host breakage.
112+
- Branch naming: `host/type-short-slug` for host-scoped changes, `type-short-slug` for top-level changes.
113+
- `host/` is the hostname (e.g. `glyph/`, `spore/`, `Rhizome/`, `zeta/`)
114+
- `type` is one of `feat`, `fix`, `chore`, `refactor`
115+
- The slug should be succinct — 2 to 4 words max (e.g. `fix-gc-options`, not `fix-gc-options-from-base-module-conflicting-definitions`)
116+
- Examples: `spore/fix-gc-options`, `Rhizome/feat-launchd-service`, `chore-update-flake-inputs`, `feat-add-ci-eval`
117+
- Always pass the branch name explicitly to `gt create` — if omitted, Graphite auto-generates one from the commit message and may prepend a user prefix:
118+
```bash
119+
gt create spore/fix-gc-options --message "fix(spore): ..."
120+
```
121+
122+
**Submitting PRs:**
123+
- Title format: `type: short description` — e.g. `fix: spore gc options`, `chore: update CLAUDE.md`, `feat: add ci eval job`
124+
- Description should include a brief summary of what changed and what to test/verify
87125

88126
## Nix Commands
89127

@@ -97,6 +135,37 @@ Never use `nix <subcommand> .#<output>` — the `#` causes permission prompt fai
97135
| `nix run nixpkgs#foo` | `nixpkgs-run foo` |
98136
| `nix shell nixpkgs#foo` | `nixpkgs-shell foo` |
99137

138+
## Common Patterns
139+
140+
**Amending the current branch:**
141+
Use `gt modify` instead of `git commit --amend` to keep the Graphite stack consistent:
142+
```bash
143+
git add <files>
144+
gt modify --no-edit # amend without changing message
145+
gt modify -m "new message" # amend with new message
146+
```
147+
148+
**`lib.mkForce` vs `lib.mkDefault`:**
149+
- `lib.mkForce value` — host wins over any module default. Use when a host must diverge from a shared module.
150+
- `lib.mkDefault value` — module loses to any host override. Use in shared modules to set a default that hosts can freely override without `mkForce`.
151+
152+
**Overriding a shared base module option in a host config:**
153+
Use `lib.mkForce` when a host needs to diverge from a value set in a shared module (e.g. `modules/base/`). Without it, Nix will error on conflicting definitions.
154+
```nix
155+
# modules/base/gc.nix sets nix.gc.dates = "weekly"
156+
# hosts/spore/default.nix overrides it:
157+
nix.gc.dates = lib.mkForce "daily";
158+
```
159+
160+
## Environment Awareness
161+
162+
- Before running commands like `ssh`, `nixos-rebuild`, or anything that targets a specific host, check which host Claude Code is running on (`hostname`) to avoid targeting the current machine unintentionally.
163+
- The current host is typically `glyph` (NixOS desktop) or `Rhizome` (macOS laptop).
164+
165+
## Learning and Memory
166+
167+
- After arriving at a working solution through trial and error, proactively ask whether the finding should be recorded in CLAUDE.md (or Basic Memory) for future sessions.
168+
100169
## Code style
101170

102171
- All files should end with a newline.

‎flake.lock‎

Lines changed: 9 additions & 9 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎hosts/spore/default.nix‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -52,8 +52,8 @@
5252

5353
# Stricter GC due to limited disk space (30 GB)
5454
nix.gc = {
55-
dates = "daily";
56-
options = "--delete-older-than 7d";
55+
dates = lib.mkForce "daily";
56+
options = lib.mkForce "--delete-older-than 7d";
5757
};
5858

5959
nix.settings = {

0 commit comments

Comments
 (0)