# dotfiles ~/.config and some config for my linux box NixOS + home-manager flake for `la2410`. All commands below run from the repo root: ```bash cd ~/git/sargit/dotfiles ``` ## Apply changes ```bash doas nixos-rebuild switch --flake .#la2410 ``` New files must be `git add`ed first, or the flake can't see them. Other modes: ```bash doas nixos-rebuild test --flake .#la2410 # activate now, but don't add a boot entry doas nixos-rebuild boot --flake .#la2410 # only use it from the next boot nixos-rebuild build --flake .#la2410 # just build it, leaves ./result ``` ## Update ```bash nix flake update # bump all inputs (nixpkgs, home-manager, sops-nix) nix flake update nixpkgs # bump just one doas nixos-rebuild switch --flake .#la2410 git commit flake.lock -m "update" ``` Run `nix flake update` as yourself, not with doas, so `flake.lock` stays owned by you. To move to a new NixOS release (e.g. 26.11), change the `nixos-26.05` and `release-26.05` branches in `flake.nix`, then update as above. Leave `system.stateVersion` alone. ## Roll back ```bash doas nixos-rebuild switch --rollback nixos-rebuild list-generations ``` Or pick an older generation in the GRUB menu at boot. ## Clean up ```bash doas nix-collect-garbage --delete-older-than 14d nix-collect-garbage --delete-older-than 14d # your user profile nix store optimise ``` ## Find and try packages ```bash nix search nixpkgs nix shell nixpkgs# # temporary shell with it nix run nixpkgs# # run it once ``` To install a package permanently, add it to `environment.systemPackages` in `hosts/la2410/configuration.nix` and rebuild. ## Private /etc/hosts entries (sops) Private hosts are stored encrypted in `hosts/la2410/secrets.yaml`, decrypted with the machine's SSH host key. Public ones go straight into `networking.extraHosts`. Edit them: ```bash doas env SOPS_AGE_KEY_CMD="nix run nixpkgs#ssh-to-age -- -private-key -i /etc/ssh/ssh_host_ed25519_key" \ nix run nixpkgs#sops -- hosts/la2410/secrets.yaml ``` Add lines under `private-hosts: |`, save, then rebuild. If the SSH host key ever changes (reinstall), get the new age key, put it in `.sops.yaml`, and re-encrypt with the old key still available: ```bash nix run nixpkgs#ssh-to-age -- -i /etc/ssh/ssh_host_ed25519_key.pub doas env SOPS_AGE_KEY_CMD="..." nix run nixpkgs#sops -- updatekeys hosts/la2410/secrets.yaml ``` ## Debugging a failed build ```bash doas nixos-rebuild switch --flake .#la2410 --show-trace journalctl -b -p err # errors this boot systemctl --failed ```