No description
  • JavaScript 87.5%
  • HTML 6.9%
  • Nix 2.8%
  • CSS 2.6%
  • Nushell 0.1%
  • Other 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
yuuhikaze 57e96b7ea6 fix(librewolf): remove leftover hm user engines from search list
SearXNG and Invidious were user engines baked into the profile cache by
the removed home-manager search block; they need to be in the policy
Remove list, not just the LibreWolf config engines.
2026-09-30 09:57:48 -05:00
.tern feat: yobidashi Discord control plane for the companion stack 2026-07-30 10:52:36 -05:00
docs fix(librewolf): enforce search engines via policies 2026-09-30 09:53:11 -05:00
docs-html docs(mailserver): authorize relay in root SPF record 2026-09-27 18:35:25 -05:00
hosts feat(smartd): monitor disk health with mail alerts 2026-09-27 13:52:42 -05:00
modules/features fix(librewolf): remove leftover hm user engines from search list 2026-09-30 09:57:48 -05:00
resources fix(minecraft): fix Yuushya 26.2 resource pack rendering issues 2026-07-21 11:57:03 -05:00
scripts feat(screenshot): add zoomable screenshot popup on Print+p 2026-09-14 15:02:41 -05:00
talos-config feat(ci/gitops): wire up full GitOps pipeline with ArgoCD and Forgejo Actions 2026-05-18 09:20:16 -05:00
values feat(graftcp): add graftcp package and gt alias 2026-09-19 19:12:04 -05:00
.gitignore chore: ignore .tern/store.db 2026-07-23 00:14:48 -05:00
.pre-commit-config.yaml feat: add pre-commit hook with nixfmt auto-formatting 2026-07-08 09:44:13 -05:00
CLAUDE.md docs(claude): correct secure boot key path 2026-09-27 18:35:25 -05:00
flake.lock chore(ani-cli): bump nixpkgs input 2026-09-30 09:36:42 -05:00
flake.nix feat(logging): cap journal size and enable logrotate 2026-09-27 18:35:08 -05:00
LICENSE chore: adds LICENSE 2025-10-06 19:14:33 -05:00
README.md docs: replace local paths with git URLs 2026-07-23 08:12:14 -05:00

NixOS

This is the configuration that runs every machine I own — a server, two workstations, and a phone — all wired together over WireGuard and managed from a single Nix flake. Everything you see here, from the boot chain to the window manager to the file-sharing service that backs up my phone, is described declaratively in this repository.

The Fleet

Four hosts make up the network:

  • server (10.100.0.1): the always-on machine, hosting every self-hosted service plus the Incus and Kubernetes platforms
  • desktop (10.100.0.2): the home workstation, doubling as a GPU box for local LLM work
  • laptop (10.100.0.3): the same workstation experience, on the move
  • pixel7: a Pixel 7 running GrapheneOS built straight from this repo, with Syncthing keeping it in step with the server

The hosts form a peer-to-peer WireGuard mesh on 10.100.0.0/24, with the server acting as the relay hub for anything that doesn't have a direct path.

What Runs Where

On the server

  • Traefik as the front door, terminating TLS with a wildcard ACME certificate for *.yhkze.net
  • OpenCloud for file sync, paired with Collabora Online for in-browser editing
  • Authelia + LLDAP providing single sign-on across protected services
  • A full mailserver — Postfix, Dovecot, OpenDKIM, SPF, DMARC — all declared in one module
  • A private F-Droid repo and a GrapheneOS OTA server for the phone
  • Incus clustered across all three hosts, with Ceph RBD as a shared storage pool so VMs can migrate between machines
  • A Kubernetes platform (Talos + Cilium + Longhorn + OpenBao + ArgoCD) running on VMs, with workloads exposed through the host's Traefik
  • A Grafana observability stack collecting node metrics and journald logs from every host

On the workstations

A daily-driver Linux desktop, kept consistent between the desktop and the laptop:

  • Hyprland Wayland compositor, with Stylix providing system-wide theming derived from a single color scheme
  • A hybrid dotfiles approach — native home-manager where it fits, out-of-store symlinks for tools that bring their own DSL (e.g. Neovim)
  • A set of creative, gaming, and AI tooling shared between both hosts via values/packages/workstation.nix

On the phone

The Pixel 7 runs GrapheneOS built declaratively with robotnix, with the privileged F-Droid extension pointed at the private repo, SeedVault backups landing in OpenCloud over WebDAV, and OTA updates served from the server.

Foundations

Several design choices underpin the configuration:

  • Dendritic modules. Each feature lives in a single file under modules/features/, bundling its service configuration, packages, firewall rules, persistence declarations, SOPS secret bindings, and home-manager fragments. Modules are auto-imported, and host applicability is controlled through exclusion lists declared in flake.nix, so the modules themselves remain free of host-specific conditionals.
  • Impermanence. The root filesystem is a tmpfs that resets on every boot. Persistent paths must be declared explicitly, which keeps the set of stateful locations auditable at a glance.
  • Secure Boot. Lanzaboote and sbctl provide a verified boot chain on every host, with the signing keys stored on the persistent partition.
  • SOPS-nix. Each host carries its own age-encrypted secrets.yaml, decrypted at activation time and bound to systemd units via restartUnits for automatic reloads.
  • Unified rebuild workflow. A single Nushell script handles local rebuilds, remote rebuilds over SSH, and closure pushes from the current machine.

Repository Layout

flake.nix              host definitions and feature-exclusion lists
hosts/{host}/          entry point, packages, disko config, encrypted secrets
modules/features/      auto-imported, self-contained feature modules
values/                shared package sets, central network details
talos-config/          Talos machine configs and patches for k8s-master/k8s-worker
scripts/               nushell ops scripts (rebuild, impermanence rollback, ...)
docs/                  documentation source — start at docs/index.md
docs-html/             rendered docs (built by tern)

GitOps (separate repos):

git.yhkze.net/sysadmin/gitops-manifests    Helm charts for K8s services (monitoring, openbao, ...)
git.yhkze.net/sysadmin/gitops-apps         ArgoCD Application definitions

Documentation

Everything technical lives in docs/: the initial setup guide, the Lanzaboote Secure Boot walkthrough, per-service deep-dives for the server, workstation tool notes, the GrapheneOS phone setup, and the Structurizr architecture diagrams.

Docs are written in Markdown under docs/ and rendered to docs-html/ with tern:

nix develop path:. --command tern

Browse it on: https://yhkze.net/nixos!

Deploying

If you'd like to try any of this on your own hardware, the install walkthrough — from BIOS prep through nixos-anywhere, LUKS bootstrap, and the first SOPS unlock — lives at docs/setup.md.

Once a host is up, day-to-day rebuilds go through a single script:

rebuild            # rebuild the current host
rebuild <ip>       # sync changes, then rebuild a remote host over SSH
rebuild push <ip>  # build locally and push the closure over SSH

Showcase