Personal NixOS, Home Manager and nix-on-droid configurations evaluated directly from npins-pinned sources. A small Flake remains available as an optional compatibility boundary.
- Lix - A delicious Nix fork
- npins - Source pinning for traditional Nix evaluation
- nix-packages - My personal collection of reusable Nix packages
- vaultix - Secret management
- preservation - Opt-in state preservation
- disko - Declarative disk partitioning
- lanzaboote - Secure boot
- devenv - Developer environments
- Cachix - Binary cache for CI and local machines
- RS-Key - Security key. FIDO/OpenPGP firmware for RP2350
lib/: Shared evaluation context and host inventorynixos/: NixOS system configurations and their evaluation entrypointhome-manager/: Home Manager configurations used standalone and through NixOS, with the standalone evaluation entrypoint indefault.nixnix-on-droid/: nix-on-droid configurations, with the evaluation entrypoint indefault.nixmodules/: Reusable Nix modules (NixOS, Home Manager)ci/jobs.nix: Explicit build matrixnpins/: Pinned upstream sourcespkgs/: Custom packagesoverlays/: Nixpkgs overlayssecrets/: Encrypted secrets, Vaultix metadata and local editing wrapperstools/: Repository maintenance tools
Hostnames follow <category>-<brand>-<model>[-<suffix>]. The last segment only appears when there are multiple machines of the same model.
Laptop-Legion-R7000: Main laptopServer-IdeaPad-G480: Home serverRouter-RaspberryPi-4B-1: Raspberry Pi 4B router
Phone-Redmi-K50Pro: Personal phonePad-Vivo-3Pro: Tablet
The build matrix is generated from the explicit list in ci/jobs.nix. NixOS hosts
come from lib/machines.nix; Home Manager configurations are generated for those
same hosts; Android devices are listed by nix-on-droid/default.nix.
Format tracked Nix and Prettier-supported files:
nix run -f ./tools/formatter.nix x86_64-linux.formatThe optional Flake boundary also exposes this as nix fmt.
CI: gitleaks secret scan, dedicated formatting check (nix fmt), workflow linting (actionlint), Flake compatibility checks, traditional evaluator checks, and Vaultix CLI wrapper builds- Build: covers every NixOS toplevel, Home Manager activation and nix-on-droid activation; runs only when a commit touches build-related paths (
workflow_dispatchforces a full run); aarch64 machines build on arm64 runners - Build outputs are pushed to
curious.cachix.org, so local builds and activations pull reusable paths directly Update npins sources: weekly npins update PR- Dependabot: weekly updates for GitHub Actions