Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
72 commits
Select commit Hold shift + click to select a range
755cad6
Use regreet and playmouth
Jun 23, 2026
6381119
Flake update
Jun 23, 2026
ead8d3f
Set sk-keys everywhere, remove tech-key
Jun 24, 2026
40ad8e1
plymouth + greeter
Jun 24, 2026
f01e80c
keyring shit
Jun 24, 2026
9dd6028
lel
Jun 24, 2026
4e90c44
Fix warnings
Jun 24, 2026
c18e8b1
Automate zfs-key-encryption
Jun 24, 2026
04e2928
fix
Jun 26, 2026
863fe48
add sops and ssh_config
Jun 26, 2026
6e2eb3f
update sops
Jun 26, 2026
43f88b4
Flatten structure
Jun 26, 2026
315802e
minors
RAPSNX Jun 27, 2026
6f85b68
remove opacity
RAPSNX Jun 28, 2026
d0eb46e
update ssh
RAPSNX Jun 28, 2026
c75d4eb
Improve keybinds
RAPSNX Jun 28, 2026
228d77b
nix flake update
RAPSNX Jun 28, 2026
bae470b
WIP
RAPSNX Jun 28, 2026
20e5d3d
set local bin and disable cgo
RAPSNX Jul 5, 2026
9eefe6c
add tmux
RAPSNX Jul 5, 2026
add4993
WIP
RAPSNX Jun 28, 2026
d3d2796
lel
RAPSNX Jul 5, 2026
95c663d
renable superior keymap
RAPSNX Jul 5, 2026
9b3af83
Enable tflow
RAPSNX Jul 5, 2026
c55fb8f
remove tflow
RAPSNX Jul 6, 2026
8c35360
WIP: portal-fuckup
RAPSNX Jul 6, 2026
ba6bc26
Disable sops!
RAPSNX Jul 6, 2026
43f7853
Introduce configOnly for hypr
RAPSNX Jul 7, 2026
ebd06f6
Update tasks
RAPSNX Jul 7, 2026
574af3b
Introduce sway
RAPSNX Jul 7, 2026
52ca2db
adjust rate
RAPSNX Jul 8, 2026
8b5a94f
disable
RAPSNX Jul 17, 2026
4b3fe35
update
RAPSNX Jul 17, 2026
b9952ab
remove tflowe
RAPSNX Jul 18, 2026
d9b9906
WIP: test windows session
RAPSNX Jul 19, 2026
ee15bbd
WIP: update kanshi
RAPSNX Jul 19, 2026
bb4bfbd
Update display config
RAPSNX Jul 19, 2026
4e78582
update
RAPSNX Jul 19, 2026
8fb672d
Remove niri + sway
RAPSNX Jul 19, 2026
3721e8a
Adapt zion
RAPSNX Jul 19, 2026
7e549e6
add tools
RAPSNX Jul 19, 2026
4ec24ff
fix keybings
RAPSNX Jul 19, 2026
1f78a92
some stuff
RAPSNX Jul 22, 2026
ecb2d93
add niri
RAPSNX Jul 22, 2026
059447f
sway: add basic module with migrated Hyprland keybinds
RAPSNX Jul 22, 2026
b011e5c
sway: migrate gaps/border/input/window-rules parity from Hyprland
RAPSNX Jul 22, 2026
72ed97b
addons: shared swayidle/swaylock idle-lock for sway and niri
RAPSNX Jul 22, 2026
426ba13
niri: migrate gaps/border/corners/input/window-rules parity from Hypr…
RAPSNX Jul 22, 2026
61f6a86
kanshi: add sway support alongside Hyprland
RAPSNX Jul 22, 2026
cc81b64
firefly: wire autostart lists for sway and niri
RAPSNX Jul 22, 2026
24dabc5
ignore
RAPSNX Jul 22, 2026
c61662f
waybar: add sway/niri workspace and mode modules
RAPSNX Jul 22, 2026
8fda719
addons: fix swayidle DPMS command breaking systemd unit parsing
RAPSNX Jul 22, 2026
b333a7f
sway: restore scratchy scratchpad and add catppuccin border colors
RAPSNX Jul 22, 2026
a3ad891
niri: restore scratchy as a real hide/show toggle
RAPSNX Jul 22, 2026
c8b8630
alacrity kungfui
RAPSNX Jul 23, 2026
e53cbb6
boot
RAPSNX Jul 23, 2026
4e8f348
alacritty: fix hint regex Unicode/DFA compile error; kanshi: drop cus…
RAPSNX Jul 26, 2026
328fc3e
Merge remote-tracking branch 'origin/zionos' into zionos
RAPSNX Jul 26, 2026
1f77b22
hyprland: statically pin workspaces 1-2/3-4 to Dell/Samsung; kanshi: …
RAPSNX Jul 26, 2026
97f2770
boot: restore mkDefault on loader.timeout to fix CI conflict on vinox
RAPSNX Jul 26, 2026
82dcfcc
fix: resolve PR review issues
RAPSNX Jul 26, 2026
105d4a9
lel
RAPSNX Jul 26, 2026
da61480
add gaming
RAPSNX Jul 26, 2026
2dc9201
remove sops
RAPSNX Jul 26, 2026
66724ef
ssh
RAPSNX Jul 26, 2026
c3dd204
lul
RAPSNX Jul 26, 2026
1bb4f92
gaming
RAPSNX Jul 26, 2026
b0d1a7c
Update docs
RAPSNX Jul 26, 2026
9488075
nix update
RAPSNX Jul 27, 2026
e35f240
Update monitors
RAPSNX Jul 27, 2026
cb7a017
update roles
RAPSNX Jul 28, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -2,3 +2,4 @@
result
.pre-commit-config.yaml
/.codex
/.claude
7 changes: 4 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -45,9 +45,9 @@ nh home switch -c nix@firefly .
# nix build installer iso
nix build .#nixosConfigurations.vinox.config.system.build.isoImage

# nh remote switch
nh os switch --hostname kubex . -d always --target-host kubex
nh os switch --hostname nixberry . -d always --target-host <IP>
# nh remote switch / update
nh os boot --hostname kubex . -d always --target-host kubex
nh os boot --hostname nixberry . -d always --target-host <IP>

# nix remote switch
nixos-rebuild switch --flake .#kubex --target-host 192.168.55.10 --sudo
Expand Down Expand Up @@ -78,6 +78,7 @@ sudo nixos-install --flake .#zion

## :open_book: Docs

- [Gaming and Battle.net](./docs/gaming.md)
- [Hyprland - Keymap](./docs/hyprland.md#keymap)
- [NVIM - Keymap](https://github.com/RAPSNX/neonix/tree/main/docs/keymap.md)

Expand Down
1 change: 1 addition & 0 deletions dev-shells.nix
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ in
deadnix
nixfmt
nix-inspect
nix-tree
;

inherit
Expand Down
93 changes: 0 additions & 93 deletions docs/firefly.md

This file was deleted.

3 changes: 0 additions & 3 deletions docs/bootstrap.md → docs/guides/bootstrap.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,3 @@
### PWAs
Manually installed `PWAs` in `Chromium`:
- todoist

## Firefly
Look into [./firefly.md](Firefly bootstrap)
31 changes: 31 additions & 0 deletions docs/guides/dual-boot.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# Dual-boot
If reinstall / install `zion` or a workstation with dual-boot, follow this order:

1. Install `Windows` first, create the correct partitions while running the installer.
Ensure that the bootloader partition is big enough.
2. Next boot into `NixOS` live and install `NixOS` with the bootloader partition from windows.
// TODO: Add / Update this to use directly `nixos-install`?

# Dual-boot entry lost
When updating the `BIOS` the `nvram` gets cleared, resulting in a lost boot entry for `NixOS`.
This can not be fixed by simply boot into live-system and rebuild the bootloader like written in the public docs.
Follow this procedure to recreate the `nvram` boot-entry again:

1. Boot into `NixOS` live system using the `vinox` iso.
2. Mount and `chroot` into the main system.

```bash
sudo -i # Sudo is needed for every action

mount /dev/nvme0n1p{X} /mnt # mount root system
mount /dev/nvme0n1p{X} /mnt/boot # mount bootloader

nixos-enter
NIXOS_INSTALL_BOOTLOADER=1 /nix/var/nix/profiles/system/bin/switch-to-configuration boot # not sure if this is needed

sudo efibootmgr --create \
--disk /dev/nvme0n1 \ # Disk not partition
--part 1 \
--label "NixOS" \
--loader '\EFI\systemd\systemd-bootx64.efi' \ # Mind the backslashes
```
Empty file added docs/guides/flake-update.md
Empty file.
58 changes: 58 additions & 0 deletions docs/guides/gaming.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
# Gaming and Battle.net

`hostConfig.roles.gaming.enable` installs Steam, Lutris, UMU, Gamescope, and
GameMode. Steam owns the Proton 11+ runtime; Home Manager links that runtime to
UMU so it can launch Lutris games without downloading a second copy.

## One-time Steam Runtime setup

Run these commands as `rap` after enabling the gaming role. Steam Runtime 4.0
is Steam tool `4183110` and is required by Proton 11+.

```sh
steam steam://install/4183110
```

Wait for Steam to finish the download, then verify the runtime exists:

```sh
runtime="$HOME/.local/share/Steam/steamapps/common/SteamLinuxRuntime_4"
test -f "$runtime/toolmanifest.vdf" && test -f "$runtime/mtree.txt.gz" \
&& echo "Steam Runtime 4 is ready"
```

Remove any incomplete runtime that UMU created before activating the Home
Manager link:

```sh
rm -rf "$HOME/.local/share/umu/steamrt4"
```

From this repository, apply the system and home configurations:

```sh
nh os switch .
nh home switch .
```

Start a new graphical session, then confirm that UMU resolves to Steam's
runtime:

```sh
readlink -f "$HOME/.local/share/umu/steamrt4"
```

The command should print
`$HOME/.local/share/Steam/steamapps/common/SteamLinuxRuntime_4`.

## Battle.net

Open Lutris, select **+** → **Search the Lutris website for installers**, and
install the standard Battle.net entry into a new Lutris-managed directory such
as `~/Games/battlenet`. Do not run the Battle.net installer manually with
`wine` or set `WINEPREFIX` yourself.

If UMU reports an HTTP 403 while checking for runtime updates, the valid linked
Steam runtime is still used. A `FileNotFoundError` for
`steamrt4/toolmanifest.vdf` means the Steam Runtime bootstrap or Home Manager
link is incomplete.
11 changes: 11 additions & 0 deletions docs/guides/new-host.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# Setup new host

Create host directory with `hardware-configuration.nix` & `default.nix`, configuring NixOS modules via the `system`
option.

## Github action

There are Github Actions, to check and build every host against a `PR`.
For each new host there needs to be config for the pipeline.

# TODO(docs): Add workdevice manual steps, ppa hyprland and uwsm
134 changes: 134 additions & 0 deletions docs/hosts/firefly.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,134 @@
# Backups

1. Firefox profile

```bash
# TODO: Add this to home.nix
rsync -av --update ~/.mozilla/firefox/default ~/Nextcloud/Home/Backups/firefox_profile/
```

2. Check atuin `key` match with the key in vault.

# Install device
1. Install `nix` (May disable any VPN)

```bash
Verify command on nixos.org/download
sh <(curl --proto '=https' --tlsv1.2 -L https://nixos.org/nix/install) --daemon
```

2. Clone dotfiles
1. Change username `home.nix`, if necessary.
3. Switch config via `devshells` target.

```bash
nix develop
switch-firefly
```

4. Create compositor desktop files.

`firefly` uses `roles.desktop.hyprland.configOnly = true`, so Home Manager only writes Hyprland configuration. Hyprland itself must come from the cppiber PPA and the display manager must start the APT/PPA binary directly.

```bash
echo "[Desktop Entry]
Name=Hyprland
Comment=An intelligent dynamic tiling Wayland compositor
Exec=/usr/bin/Hyprland
Type=Application" | sudo tee /usr/share/wayland-sessions/hyprland.desktop
```

`firefly` also has `roles.desktop.niri.enable = true` (PoC), backed by [niri-flake](https://github.com/sodiboo/niri-flake)'s `homeModules.niri`. Unlike Hyprland, there is no APT/PPA package for niri, so this module lets Home Manager install and manage niri itself (`programs.niri.package`, default `niri-stable` from niri-flake) in addition to generating `~/.config/niri/config.kdl` from `programs.niri.settings` (validated at build time via `niri validate`).

niri-flake has its own binary cache to avoid building niri from source. Since `firefly` doesn't use the NixOS module (which wires the cache in automatically), add it once manually:

```bash
cachix use niri
```

The display manager launches session files without the user's shell `PATH`, so the `Exec` line must use the absolute path into the Home Manager profile (`niri-session` handles systemd/portal integration, unlike calling the raw `niri` binary). `DesktopNames=niri` sets `XDG_CURRENT_DESKTOP`, which portals/theming rely on to detect the session:

```bash
echo "[Desktop Entry]
Name=Niri
Comment=A scrollable-tiling Wayland compositor
Exec=/home/$(whoami)/.nix-profile/bin/niri-session
Type=Application
DesktopNames=niri" | sudo tee /usr/share/wayland-sessions/niri.desktop
```

`niri --session` (invoked by `niri-session`) is systemd-integrated, like Hyprland — it expects `niri.service`/`niri-shutdown.target` user units to exist so GDM can track the session. Those ship inside the niri package itself, but only get linked into `~/.config/systemd/user/` automatically on NixOS; the `roles.desktop.niri` Home Manager module links them explicitly for non-NixOS hosts like `firefly` (see `modules/home/desktops/niri/default.nix`). Without that, GDM logs `Failed to start niri.service: Unit niri.service not found.` and silently falls back to another session.

5. Copy user-certificate to firefox

```bash
# TODO: Add this to home.nix (as activation script for example)
ln -sf ~/.pki/nssdb/* ~/.mozilla/firefox/default/
```

## Manual things

### Disable gpg-agent
```
systemctl --user mask --now gpg-agent.service gpg-agent.socket \
gpg-agent-ssh.socket gpg-agent-extra.socket gpg-agent-browser.socket
```

### Chromium

Extension: `Open in firefox`:

**Other Settings**

- Enable Reverse Mode

**Automation Rules**

Comma-separated list of URLs:
```
*://*.google.com/*, *://chat.ske.eu01.stackit.cloud/*
```


### GTK Theme

`nwg-look` is used to configure theme in multiple locations.
Run it, ensure to remove the check of `GTK4` files in preferences.
Set `widgets -> colorScheme -> prefer dark`.

```bash
dconf read /org/gnome/desktop/interface/gtk-theme # Read the actual name
```

## Installed via APT

Those programs are installed via apt, since they do not work within `nix`.

```bash
sudo add-apt-repository ppa:cppiber/hyprland
sudo apt update
sudo apt -y install \
hyprland \
xdg-desktop-portal \
xdg-desktop-portal-hyprland \
xdg-desktop-portal-gtk \
mumble \
swaylock \
podman
```

Home Manager must not manage Hyprland or portal packages on `firefly`. Verify the active setup after switching:

```bash
readlink -f "$(command -v Hyprland)"
systemctl --user cat xdg-desktop-portal*.service
systemctl --user show-environment | grep NIX_XDG_DESKTOP_PORTAL_DIR
find ~/.config/xdg-desktop-portal ~/.nix-profile/share/xdg-desktop-portal -maxdepth 3 -type f 2>/dev/null
```

Expected results:

- `Hyprland` resolves to `/usr/bin/Hyprland`.
- Portal services come from the host packages, not Home Manager-generated user units.
- `NIX_XDG_DESKTOP_PORTAL_DIR` is absent from the user systemd environment.
- The `find` command does not show Home Manager-generated portal config under `~/.config/xdg-desktop-portal` or Nix profile portal definitions under `~/.nix-profile/share/xdg-desktop-portal`.
7 changes: 7 additions & 0 deletions docs/k3s.md → docs/hosts/kubex.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,13 @@ sudo zpool create -f \
raidz2 /dev/sda /dev/sdb /dev/sdc /dev/sdd
```

The `k3s` role includes a `wait-for-zfs-pool.service` unit that imports `kubex-main`
if needed, then loads its encryption key from `rap@nixberry` before `k3s.service`
starts.

Because the unit runs non-interactively, `kubex` is configured for passwordless sudo
for members of the `wheel` group.

## Copy kubeconfig

```bash
Expand Down
Loading
Loading