94 lines
2.6 KiB
Markdown
94 lines
2.6 KiB
Markdown
# dotfiles
|
|
|
|
~/.config and some config for my linux box
|
|
|
|
NixOS + home-manager flake for `la2410`. All commands below run from the repo root:
|
|
|
|
```bash
|
|
cd ~/git/sargit/dotfiles
|
|
```
|
|
|
|
## Apply changes
|
|
|
|
```bash
|
|
doas nixos-rebuild switch --flake .#la2410
|
|
```
|
|
|
|
New files must be `git add`ed first, or the flake can't see them.
|
|
|
|
Other modes:
|
|
|
|
```bash
|
|
doas nixos-rebuild test --flake .#la2410 # activate now, but don't add a boot entry
|
|
doas nixos-rebuild boot --flake .#la2410 # only use it from the next boot
|
|
nixos-rebuild build --flake .#la2410 # just build it, leaves ./result
|
|
```
|
|
|
|
## Update
|
|
|
|
```bash
|
|
nix flake update # bump all inputs (nixpkgs, home-manager, sops-nix)
|
|
nix flake update nixpkgs # bump just one
|
|
doas nixos-rebuild switch --flake .#la2410
|
|
git commit flake.lock -m "update"
|
|
```
|
|
|
|
Run `nix flake update` as yourself, not with doas, so `flake.lock` stays owned by you.
|
|
|
|
To move to a new NixOS release (e.g. 26.11), change the `nixos-26.05` and `release-26.05` branches in `flake.nix`, then update as above. Leave `system.stateVersion` alone.
|
|
|
|
## Roll back
|
|
|
|
```bash
|
|
doas nixos-rebuild switch --rollback
|
|
nixos-rebuild list-generations
|
|
```
|
|
|
|
Or pick an older generation in the GRUB menu at boot.
|
|
|
|
## Clean up
|
|
|
|
```bash
|
|
doas nix-collect-garbage --delete-older-than 14d
|
|
nix-collect-garbage --delete-older-than 14d # your user profile
|
|
nix store optimise
|
|
```
|
|
|
|
## Find and try packages
|
|
|
|
```bash
|
|
nix search nixpkgs <name>
|
|
nix shell nixpkgs#<pkg> # temporary shell with it
|
|
nix run nixpkgs#<pkg> # run it once
|
|
```
|
|
|
|
To install a package permanently, add it to `environment.systemPackages` in `hosts/la2410/configuration.nix` and rebuild.
|
|
|
|
## Private /etc/hosts entries (sops)
|
|
|
|
Private hosts are stored encrypted in `hosts/la2410/secrets.yaml`, decrypted with the machine's SSH host key. Public ones go straight into `networking.extraHosts`.
|
|
|
|
Edit them:
|
|
|
|
```bash
|
|
doas env SOPS_AGE_KEY_CMD="nix run nixpkgs#ssh-to-age -- -private-key -i /etc/ssh/ssh_host_ed25519_key" \
|
|
nix run nixpkgs#sops -- hosts/la2410/secrets.yaml
|
|
```
|
|
|
|
Add lines under `private-hosts: |`, save, then rebuild.
|
|
|
|
If the SSH host key ever changes (reinstall), get the new age key, put it in `.sops.yaml`, and re-encrypt with the old key still available:
|
|
|
|
```bash
|
|
nix run nixpkgs#ssh-to-age -- -i /etc/ssh/ssh_host_ed25519_key.pub
|
|
doas env SOPS_AGE_KEY_CMD="..." nix run nixpkgs#sops -- updatekeys hosts/la2410/secrets.yaml
|
|
```
|
|
|
|
## Debugging a failed build
|
|
|
|
```bash
|
|
doas nixos-rebuild switch --flake .#la2410 --show-trace
|
|
journalctl -b -p err # errors this boot
|
|
systemctl --failed
|
|
```
|