The successor to my Arch dotfiles https://pages.hu-tao.dev/hutao/nixos-dotfiles/docs/
  • Nix 24.6%
  • Python 22.7%
  • HTML 12.2%
  • Shell 10.3%
  • Lua 10%
  • Other 20.2%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Ivan 05c600692d
All checks were successful
CI / Evaluate the installer image (push) Successful in 1m4s
CI / Format and lint (push) Successful in 1m12s
Pages / Build the handbook (push) Successful in 50s
chore: nix flake update
2026-10-01 21:55:05 +03:00
.forgejo/workflows feat(ci): publish the handbook to pages.hu-tao.dev 2026-09-25 20:44:32 +03:00
.github/workflows fix(ci): evaluate only the installer image 2026-09-24 11:59:17 +03:00
assets feat(caelestia): take the Limine and SDDM backgrounds from the wallpaper 2026-09-27 11:12:36 +03:00
docs Merge branch 'feat/vercel-ai-gateway' 2026-09-30 13:16:38 +03:00
dotfiles fix(home): let GCM answer for git.hu-tao.dev, not the stale cache 2026-09-30 11:20:21 +03:00
home feat(home): hide the sidebar panel header in Firefox and Floorp 2026-09-29 21:18:39 +03:00
hosts fix(hutao-desktop): correct the hardware comments 2026-09-25 20:38:11 +03:00
lib refactor(desktop): one file per service under modules/desktop 2026-09-11 16:52:14 +03:00
modules feat(sops): add the Vercel AI Gateway key 2026-09-30 10:41:55 +03:00
nvim feat(nvim): markdown-preview.nvim in caelestia's colours 2026-09-29 16:18:51 +03:00
pkgs feat(caelestia): take the Limine and SDDM backgrounds from the wallpaper 2026-09-27 11:12:36 +03:00
secrets feat(sops): add the Vercel AI Gateway key 2026-09-30 10:41:55 +03:00
vm docs: cut comments to intent only 2026-09-03 14:41:18 +03:00
.editorconfig build(ci): enforce one lint list locally and in GitHub Actions 2026-09-01 22:21:14 +03:00
.gitattributes refactor(assets): move third-party art under assets/third-party 2026-09-23 23:30:42 +03:00
.gitignore feat(docs): add the handbook, an mdBook in docs/ 2026-09-25 20:44:18 +03:00
.gitleaks.toml style: cut the comments back to intent 2026-09-04 10:58:39 +03:00
.markdownlint.yaml build(ci): enforce one lint list locally and in GitHub Actions 2026-09-01 22:21:14 +03:00
.pre-commit-config.yaml feat(ci): build the handbook in pre-commit 2026-09-25 20:44:32 +03:00
.shellcheckrc build(ci): enforce one lint list locally and in GitHub Actions 2026-09-01 22:21:14 +03:00
.sops.yaml fix: set proper sops keys 2026-09-03 08:06:21 +00:00
AGENTS.md docs(agents): keep the handbook in step at the end of every task 2026-09-25 21:36:47 +03:00
flake.lock chore: nix flake update 2026-10-01 21:55:05 +03:00
flake.nix chore(flake): take caelestia-tab from main 2026-09-28 00:14:28 +03:00
install.sh docs(readme): keep the short version, point at the handbook 2026-09-25 20:44:32 +03:00
palette.nix feat(caelestia): pick the scheme in caelestia, recolour the desktop live 2026-09-26 19:25:43 +03:00
README.md docs(handbook): the CaelestiaFox setup and the shell restart on rebuild 2026-09-26 23:53:34 +03:00
statix.toml build(ci): enforce one lint list locally and in GitHub Actions 2026-09-01 22:21:14 +03:00
verify.sh docs: cut comments to intent only 2026-09-03 14:41:18 +03:00

nixos-dotfiles

CI Icon Pages Icon Handbook Icon NixOS Icon

NixOS config on nixos-unstable for a laptop and a desktop: LVM-on-LUKS, immutable users from sops, Hyprland + caelestia, Limine.

The user layer is dotfiles/ and the neovim config is nvim/, both in this repo, symlinked into $HOME by home-manager. No stow, and no flake input to bump: a config change and the system change that needs it are one commit.

.
├── flake.nix              # the hosts, the installer ISO, the VM, deploy-rs nodes
├── hosts/
│   ├── common/            # what every real machine gets: boot, sops, tailscale, …
│   ├── hutao-laptop/      # IdeaPad 1 15AMN7
│   ├── hutao-desktop/     # the HDD, the printer, Sunshine
│   ├── hutao-vm/          # the desktop layer under QEMU
│   └── installer/         # the ISO install.sh runs from
├── modules/
│   ├── desktop/           # the desktop environment, shared by every host
│   ├── sops.nix           # every secret, declared
│   ├── disk-layout.nix    # disko: ESP + LUKS → LVM
│   └── firewall.nix tailscale.nix syncthing.nix users.nix system.nix flatpak.nix
├── home/                  # home-manager: the dotfiles walk, one file per app
├── dotfiles/  nvim/       # the user layer itself
├── palette.nix            # the picked caelestia scheme, for what needs a rebuild
├── pkgs/                  # greeter, cursors, folder icons, app icons, CaelestiaFox
├── secrets/               # sops-encrypted values + a plaintext example
├── install.sh             # partition, encrypt, install, from the ISO
├── vm/                    # the install rehearsal
├── docs/                  # the handbook, mdBook source in docs/src/
└── AGENTS.md              # for agents: keep docs/ in step with every change

The handbook

This README is the short version. The long version (what each layer holds, how the colours flow, every secret and why, installing from nothing) is in docs/, published at https://pages.hu-tao.dev/hutao/nixos-dotfiles/docs/.

nix run .#docs
Chapter For
Hosts and layers where a change goes, and what each machine has
The user layer the dotfiles walk, its patches, what stays writable
Colours pick a scheme in caelestia, and what follows it
Secrets every key, its shape, and the build-time check
Network and the tailnet one open port, Tailscale, MagicDNS, Syncthing
The laptop as a third monitor Sunshine, Moonlight, and the disconnect watcher
Installing a machine install.sh, step by step, and new hardware
Rebuilding and deploying nixos-rebuild and deploy-rs over Tailscale
Known hazards what will hurt if forgotten

Those links go to the source, which renders in Forgejo, diagrams included.

Quick start

Command Does
sudo nixos-rebuild switch --flake .#hutao-desktop rebuild the machine you are at
nix develop -c deploy .#hutao-laptop deploy to the laptop over Tailscale, with rollback
nix run .#vm boot the desktop layer in QEMU (hutao / vm)
nix develop -c pre-commit run --all-files lint, exactly as CI does
SOPS_AGE_KEY_FILE=~/.sops-nix/key.txt nix develop -c sops secrets/secrets.yaml edit the secrets
nix build .#installer-iso build the installer ISO
vm/install-test.sh all rehearse a full install against a blank virtual disk
nix run .#docs serve the handbook with live reload

Every key modules/sops.nix declares must be in secrets/secrets.yaml before anything builds; install.sh checks the full list before it touches a disk. See Secrets.