No description
Flake lock file updates:
• Updated input 'nixpkgs':
'github:nixos/nixpkgs/481cf557888e05d3128a76f14c76397b7d7cc869?narHash=sha256-G/iC4t/9j/52i/nm%2B0/4ybBmAF4hzR8CNHC75qEhjHo%3D' (2025-10-21)
→ 'github:nixos/nixpkgs/78e34d1667d32d8a0ffc3eba4591ff256e80576e?narHash=sha256-vY2OLVg5ZTobdroQKQQSipSIkHlxOTrIF1fsMzPh8w8%3D' (2025-10-26)
• Updated input 'nixpkgsMaster':
'github:NixOS/nixpkgs/d05426b82736631cf0a4dc8bceef1e52a4326dd7?narHash=sha256-XS7PTk22esg%2BHHg5OSF6%2BjgR6X/2WbzHj1CC8aS0x9E%3D' (2025-10-23)
→ 'github:NixOS/nixpkgs/8865b77677eb576ce1dbcb90b7a1ae95a774a6cd?narHash=sha256-rIne9pcxSoaLCxcyICguhH3SUzE9lep464L7zRGBbZk%3D' (2025-10-27)
• Updated input 'nur':
'github:nix-community/NUR/1d182e3ee8a3a55dc50ff907877294652606a152?narHash=sha256-YF83M84JXliUtQjVsOeXMOtZNnhmTRd9YwH8aVUu1Io%3D' (2025-10-23)
→ 'github:nix-community/NUR/378c5c7b0b2471b59b71e42b229ea5e68050235d?narHash=sha256-0UtnyehKLys0HWhctZEjKN7zDe%2BML0HCDdqdfHk221o%3D' (2025-10-27)
• Updated input 'nur/nixpkgs':
'github:nixos/nixpkgs/01f116e4df6a15f4ccdffb1bcd41096869fb385c?narHash=sha256-f/QCJM/YhrV/lavyCVz8iU3rlZun6d%2BdAiC3H%2BCDle4%3D' (2025-10-22)
→ 'github:nixos/nixpkgs/6a08e6bb4e46ff7fcbb53d409b253f6bad8a28ce?narHash=sha256-Q/uhWNvd7V7k1H1ZPMy/vkx3F8C13ZcdrKjO7Jv7v0c%3D' (2025-10-25)
|
||
|---|---|---|
| .git-crypt | ||
| custom-utils | ||
| hosts | ||
| modules | ||
| nix-cache | ||
| pkgs | ||
| users | ||
| .editorconfig | ||
| .envrc | ||
| .gitattributes | ||
| .gitignore | ||
| .sops.yaml | ||
| flake.lock | ||
| flake.nix | ||
| justfile | ||
| README.md | ||
jalr's NixOS Configuration
Install a new host
This installs nixos on host somehost:
NixOS Anywhere
nix run github:nix-community/nixos-anywhere -- --flake .#<somehost> root@<somehost>
The traditional way
nix-shell -p nixUnstable --run 'nixos-install --flake https://gitlab.jalr.de/jalr/nixos-configuration#somehost --no-channel-copy'
Build a configuration
nix build .#nixosConfigurations.iron.config.system.build.toplevel
setting up sops
Get the host key and convert it.
ssh-keyscan -t ed25519 $host | ssh-to-age
Then add the key to .sops.yaml
If the key changed, you might want to run
sops updatekeys hosts/$host/secrets.yaml
nix repl
start an interactive environment for evaluating Nix expressions
$ nix repl
nix-repl> a=builtins.getFlake (toString ./.)
$ nix repl
nix-repl> :lf .#
Import GPG public key
gpg --card-edit
gpg/card> fetch
gpg --edit-key $key
gpg> trust
Your decision? 5
Debugging boot issues
- Add
rd.systemd.debug_shellkernel parameter - Press CTRL+ALT+F9 to switch to root shell