blob: b82827798e5721069a6f2712ffc63a3cd88715bd (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
|
{ config, lib, pkgs, ... }:
# Everything in here needs to work on linux or darwin, with or without a desktop
# environment
{
imports = [
../modules/shell.nix
# ../modules/development.nix
../modules/emacs.nix
../modules/vim.nix
../modules/tarsnap.nix
../modules/twitter.nix
../modules/lib/cloneRepo.nix
];
home.username = "grfn";
home.homeDirectory = "/home/grfn";
programs.password-store.enable = true;
grfn.impure.clonedRepos.passwordStore = {
github = "glittershark/pass";
path = ".local/share/password-store";
};
home.packages = with pkgs; [
# System utilities
bat
htop
killall
bind
zip
unzip
tree
nmap
bc
pv
# Security
gnupg
keybase
openssl
# Nix things
nixfmt
nix-prefetch-github
nixpkgs-review
cachix
(writeShellScriptBin "rebuild-mugwump" ''
set -eo pipefail
cd ~/code/depot
nix build -f . users.aspen.system.system.mugwumpSystem -o /tmp/mugwump
nix copy -f . users.aspen.system.system.mugwumpSystem \
--to ssh://mugwump
system=$(readlink -ef /tmp/mugwump)
ssh mugwump sudo nix-env -p /nix/var/nix/profiles/system --set $system
ssh mugwump sudo $system/bin/switch-to-configuration switch
rm /tmp/mugwump
'')
(writeShellScriptBin "rebuild-roswell" ''
set -eo pipefail
cd ~/code/depot
nix build -f . users.aspen.system.system.roswellSystem -o /tmp/roswell
nix copy -f . users.aspen.system.system.roswellSystem \
--to ssh://roswell
system=$(readlink -ef /tmp/roswell)
ssh roswell sudo nix-env -p /nix/var/nix/profiles/system --set $system
ssh roswell sudo $system/bin/switch-to-configuration switch
rm /tmp/roswell
'')
(writeShellScriptBin "rebuild-home" ''
set -eo pipefail
cd ~/code/depot
nix build -f . users.aspen.system.home.$(hostname)Home -o /tmp/home
/tmp/home/activate
'')
];
programs.ssh = {
enable = true;
matchBlocks = {
"home" = {
host = "home.gws.fyi";
forwardAgent = true;
};
"cerberus" = {
host = "cerberus";
hostname = "172.16.0.3";
forwardAgent = true;
user = "griffin";
};
"mugwump" = {
host = "mugwump";
hostname = "172.16.0.5";
forwardAgent = true;
};
"roswell" = {
host = "roswell";
forwardAgent = true;
};
};
};
programs.direnv = {
enable = true;
enableBashIntegration = true;
enableZshIntegration = true;
};
}
|