Files
dotfiles/README.md
T
2026-10-06 06:40:37 +05:00

94 lines
2.6 KiB
Markdown

# dotfiles
~/.config and some config for my linux box
NixOS + home-manager flake for `la2410`. All commands below run from the repo root:
```bash
cd ~/git/sargit/dotfiles
```
## Apply changes
```bash
doas nixos-rebuild switch --flake .#la2410
```
New files must be `git add`ed first, or the flake can't see them.
Other modes:
```bash
doas nixos-rebuild test --flake .#la2410 # activate now, but don't add a boot entry
doas nixos-rebuild boot --flake .#la2410 # only use it from the next boot
nixos-rebuild build --flake .#la2410 # just build it, leaves ./result
```
## Update
```bash
nix flake update # bump all inputs (nixpkgs, home-manager, sops-nix)
nix flake update nixpkgs # bump just one
doas nixos-rebuild switch --flake .#la2410
git commit flake.lock -m "update"
```
Run `nix flake update` as yourself, not with doas, so `flake.lock` stays owned by you.
To move to a new NixOS release (e.g. 26.11), change the `nixos-26.05` and `release-26.05` branches in `flake.nix`, then update as above. Leave `system.stateVersion` alone.
## Roll back
```bash
doas nixos-rebuild switch --rollback
nixos-rebuild list-generations
```
Or pick an older generation in the GRUB menu at boot.
## Clean up
```bash
doas nix-collect-garbage --delete-older-than 14d
nix-collect-garbage --delete-older-than 14d # your user profile
nix store optimise
```
## Find and try packages
```bash
nix search nixpkgs <name>
nix shell nixpkgs#<pkg> # temporary shell with it
nix run nixpkgs#<pkg> # run it once
```
To install a package permanently, add it to `environment.systemPackages` in `hosts/la2410/configuration.nix` and rebuild.
## Private /etc/hosts entries (sops)
Private hosts are stored encrypted in `hosts/la2410/secrets.yaml`, decrypted with the machine's SSH host key. Public ones go straight into `networking.extraHosts`.
Edit them:
```bash
doas env SOPS_AGE_KEY_CMD="nix run nixpkgs#ssh-to-age -- -private-key -i /etc/ssh/ssh_host_ed25519_key" \
nix run nixpkgs#sops -- hosts/la2410/secrets.yaml
```
Add lines under `private-hosts: |`, save, then rebuild.
If the SSH host key ever changes (reinstall), get the new age key, put it in `.sops.yaml`, and re-encrypt with the old key still available:
```bash
nix run nixpkgs#ssh-to-age -- -i /etc/ssh/ssh_host_ed25519_key.pub
doas env SOPS_AGE_KEY_CMD="..." nix run nixpkgs#sops -- updatekeys hosts/la2410/secrets.yaml
```
## Debugging a failed build
```bash
doas nixos-rebuild switch --flake .#la2410 --show-trace
journalctl -b -p err # errors this boot
systemctl --failed
```