dotfiles
~/.config and some config for my linux box
NixOS + home-manager flake for la2410. All commands below run from the repo root:
cd ~/git/sargit/dotfiles
Apply changes
doas nixos-rebuild switch --flake .#la2410
New files must be git added first, or the flake can't see them.
Other modes:
doas nixos-rebuild test --flake .#la2410 # activate now, but don't add a boot entry
doas nixos-rebuild boot --flake .#la2410 # only use it from the next boot
nixos-rebuild build --flake .#la2410 # just build it, leaves ./result
Update
nix flake update # bump all inputs (nixpkgs, home-manager, sops-nix)
nix flake update nixpkgs # bump just one
doas nixos-rebuild switch --flake .#la2410
git commit flake.lock -m "update"
Run nix flake update as yourself, not with doas, so flake.lock stays owned by you.
To move to a new NixOS release (e.g. 26.11), change the nixos-26.05 and release-26.05 branches in flake.nix, then update as above. Leave system.stateVersion alone.
Roll back
doas nixos-rebuild switch --rollback
nixos-rebuild list-generations
Or pick an older generation in the GRUB menu at boot.
Clean up
doas nix-collect-garbage --delete-older-than 14d
nix-collect-garbage --delete-older-than 14d # your user profile
nix store optimise
Find and try packages
nix search nixpkgs <name>
nix shell nixpkgs#<pkg> # temporary shell with it
nix run nixpkgs#<pkg> # run it once
To install a package permanently, add it to environment.systemPackages in hosts/la2410/configuration.nix and rebuild.
Private /etc/hosts entries (sops)
Private hosts are stored encrypted in hosts/la2410/secrets.yaml, decrypted with the machine's SSH host key. Public ones go straight into networking.extraHosts.
Edit them:
doas env SOPS_AGE_KEY_CMD="nix run nixpkgs#ssh-to-age -- -private-key -i /etc/ssh/ssh_host_ed25519_key" \
nix run nixpkgs#sops -- hosts/la2410/secrets.yaml
Add lines under private-hosts: |, save, then rebuild.
If the SSH host key ever changes (reinstall), get the new age key, put it in .sops.yaml, and re-encrypt with the old key still available:
nix run nixpkgs#ssh-to-age -- -i /etc/ssh/ssh_host_ed25519_key.pub
doas env SOPS_AGE_KEY_CMD="..." nix run nixpkgs#sops -- updatekeys hosts/la2410/secrets.yaml
Debugging a failed build
doas nixos-rebuild switch --flake .#la2410 --show-trace
journalctl -b -p err # errors this boot
systemctl --failed