- JavaScript 87.5%
- HTML 6.9%
- Nix 2.8%
- CSS 2.6%
- Nushell 0.1%
- Other 0.1%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
SearXNG and Invidious were user engines baked into the profile cache by the removed home-manager search block; they need to be in the policy Remove list, not just the LibreWolf config engines. |
||
| .tern | ||
| docs | ||
| docs-html | ||
| hosts | ||
| modules/features | ||
| resources | ||
| scripts | ||
| talos-config | ||
| values | ||
| .gitignore | ||
| .pre-commit-config.yaml | ||
| CLAUDE.md | ||
| flake.lock | ||
| flake.nix | ||
| LICENSE | ||
| README.md | ||
NixOS
This is the configuration that runs every machine I own — a server, two workstations, and a phone — all wired together over WireGuard and managed from a single Nix flake. Everything you see here, from the boot chain to the window manager to the file-sharing service that backs up my phone, is described declaratively in this repository.
The Fleet
Four hosts make up the network:
- server (
10.100.0.1): the always-on machine, hosting every self-hosted service plus the Incus and Kubernetes platforms - desktop (
10.100.0.2): the home workstation, doubling as a GPU box for local LLM work - laptop (
10.100.0.3): the same workstation experience, on the move - pixel7: a Pixel 7 running GrapheneOS built straight from this repo, with Syncthing keeping it in step with the server
The hosts form a peer-to-peer WireGuard mesh on 10.100.0.0/24, with the
server acting as the relay hub for anything that doesn't have a direct path.
What Runs Where
On the server
- Traefik as the front door, terminating TLS with a wildcard ACME certificate for
*.yhkze.net - OpenCloud for file sync, paired with Collabora Online for in-browser editing
- Authelia + LLDAP providing single sign-on across protected services
- A full mailserver — Postfix, Dovecot, OpenDKIM, SPF, DMARC — all declared in one module
- A private F-Droid repo and a GrapheneOS OTA server for the phone
- Incus clustered across all three hosts, with Ceph RBD as a shared storage pool so VMs can migrate between machines
- A Kubernetes platform (Talos + Cilium + Longhorn + OpenBao + ArgoCD) running on VMs, with workloads exposed through the host's Traefik
- A Grafana observability stack collecting node metrics and journald logs from every host
On the workstations
A daily-driver Linux desktop, kept consistent between the desktop and the laptop:
- Hyprland Wayland compositor, with Stylix providing system-wide theming derived from a single color scheme
- A hybrid dotfiles approach — native home-manager where it fits, out-of-store symlinks for tools that bring their own DSL (e.g. Neovim)
- A set of creative, gaming, and AI tooling shared between both hosts via
values/packages/workstation.nix
On the phone
The Pixel 7 runs GrapheneOS built declaratively with robotnix, with the privileged F-Droid extension pointed at the private repo, SeedVault backups landing in OpenCloud over WebDAV, and OTA updates served from the server.
Foundations
Several design choices underpin the configuration:
- Dendritic modules. Each feature lives in a single file under
modules/features/, bundling its service configuration, packages, firewall rules, persistence declarations, SOPS secret bindings, and home-manager fragments. Modules are auto-imported, and host applicability is controlled through exclusion lists declared inflake.nix, so the modules themselves remain free of host-specific conditionals. - Impermanence. The root filesystem is a tmpfs that resets on every boot. Persistent paths must be declared explicitly, which keeps the set of stateful locations auditable at a glance.
- Secure Boot. Lanzaboote and
sbctlprovide a verified boot chain on every host, with the signing keys stored on the persistent partition. - SOPS-nix. Each host carries its own age-encrypted
secrets.yaml, decrypted at activation time and bound to systemd units viarestartUnitsfor automatic reloads. - Unified rebuild workflow. A single Nushell script handles local rebuilds, remote rebuilds over SSH, and closure pushes from the current machine.
Repository Layout
flake.nix host definitions and feature-exclusion lists
hosts/{host}/ entry point, packages, disko config, encrypted secrets
modules/features/ auto-imported, self-contained feature modules
values/ shared package sets, central network details
talos-config/ Talos machine configs and patches for k8s-master/k8s-worker
scripts/ nushell ops scripts (rebuild, impermanence rollback, ...)
docs/ documentation source — start at docs/index.md
docs-html/ rendered docs (built by tern)
GitOps (separate repos):
git.yhkze.net/sysadmin/gitops-manifests Helm charts for K8s services (monitoring, openbao, ...)
git.yhkze.net/sysadmin/gitops-apps ArgoCD Application definitions
Documentation
Everything technical lives in docs/: the initial setup guide, the Lanzaboote Secure Boot walkthrough, per-service deep-dives for the server, workstation tool notes, the GrapheneOS phone setup, and the Structurizr architecture diagrams.
Docs are written in Markdown under docs/ and rendered to docs-html/
with tern:
nix develop path:. --command tern
Browse it on: https://yhkze.net/nixos!
Deploying
If you'd like to try any of this on your own hardware, the install
walkthrough — from BIOS prep through nixos-anywhere, LUKS bootstrap, and
the first SOPS unlock — lives at docs/setup.md.
Once a host is up, day-to-day rebuilds go through a single script:
rebuild # rebuild the current host
rebuild <ip> # sync changes, then rebuild a remote host over SSH
rebuild push <ip> # build locally and push the closure over SSH