From 5171a10079674ef5bc45a7b8ebf2971c38e3ee28 Mon Sep 17 00:00:00 2001 From: Jack O'Sullivan Date: Mon, 24 Aug 2026 00:10:18 +0100 Subject: [PATCH] nixpkgs: Refresh channels and inputs Rebase the fork branches and refresh nixpkgs, home-manager, and the approved ancillary inputs. Update kernel and release metadata, adapt removed package and Home Assistant options, and keep Determinate Nix on its tested nixpkgs revision to avoid duplicate Boost patches. Retire Sharry and its public endpoint because copyparty replaces it. Document the GitHub mirror gate and require real devshell and system builds in the upgrade validation workflow. --- .agents/skills/upgrade-nixpkgs/SKILL.md | 6 + docs/README.md | 2 +- docs/architecture.md | 2 +- docs/nixpkgs-upgrade.md | 17 +- docs/sites/colony/shill/README.md | 2 +- .../colony/shill/containers/colony-psql.md | 4 +- .../colony/shill/containers/middleman.md | 1 - docs/sites/colony/shill/containers/object.md | 8 +- flake.lock | 338 +++++------------- flake.nix | 9 +- home-manager/modules/gui/default.nix | 8 +- lib/constants.nix | 2 +- lib/default.nix | 2 +- .../vms/shill/containers/middleman/vhosts.nix | 9 - .../colony/vms/shill/containers/object.nix | 68 ---- .../home/palace/vms/sfh/containers/hass.nix | 11 +- nixos/default.nix | 2 +- nixos/modules/common.nix | 4 +- secrets/object/sharry.conf.age | 18 - 19 files changed, 133 insertions(+), 380 deletions(-) delete mode 100644 secrets/object/sharry.conf.age diff --git a/.agents/skills/upgrade-nixpkgs/SKILL.md b/.agents/skills/upgrade-nixpkgs/SKILL.md index 39831f7..5bb0a58 100644 --- a/.agents/skills/upgrade-nixpkgs/SKILL.md +++ b/.agents/skills/upgrade-nixpkgs/SKILL.md @@ -22,6 +22,12 @@ Key reminders (see the doc for the full steps): and the `flake.nix` stable pins must agree on one release. - **Re-verify the patch stack against freshly fetched upstream**, not stale refs — enumerate it with `git log`; don't assume a remembered list. +- After pushing the rebased fork branches, **wait for the GitHub mirror to catch up** before + refreshing flake pins. The `nixpkgs-mine*` inputs fetch from GitHub, not the fork's primary + remote; verify both GitHub branch tips match the pushed local tips first. - After refreshing the pins, update `lib/constants.nix` to the current explicit LTS and latest kernel package attributes, and update the `lib/default.nix` version overlay's `YY.MM` prefix to the current month. Change its codename only when the stable channel advances. +- After the cheap evaluations pass, build the actual devshell and one representative NixOS system + (prefer the local box). `nix flake check --no-build` does not expose dependency build failures; + this is especially important when updating build-tool inputs such as Determinate Nix. diff --git a/docs/README.md b/docs/README.md index 214f450..31e7165 100644 --- a/docs/README.md +++ b/docs/README.md @@ -47,7 +47,7 @@ colony (physical VM host, ams1) │ ├── colony-psql (shared PostgreSQL) │ ├── chatterbox (Matrix Synapse + bridges) │ ├── jackflix (media stack) -│ ├── object (MinIO, Harmonia Nix cache, Sharry, HedgeDoc, wastebin) +│ ├── object (MinIO, Harmonia Nix cache, HedgeDoc, wastebin) │ ├── toot (Bluesky PDS; Mastodon disabled) │ ├── waffletail (Tailscale subnet router / exit node) │ ├── qclk (WireGuard management appliance) diff --git a/docs/architecture.md b/docs/architecture.md index 1fef459..44dc2e2 100644 --- a/docs/architecture.md +++ b/docs/architecture.md @@ -175,7 +175,7 @@ descriptions) see [`reference/nixos-options.md`](reference/nixos-options.md). | Module | Provides | |---|---| -| `common` | Baseline for all boxes: imports the impermanence, ragenix (age), sharry, copyparty and harmonia NixOS modules; pins `system.stateVersion`; `doas` instead of `sudo`; immutable users; nix settings (flakes, `ca-derivations`, the `nix-cache.nul.ie` substituter); declares the `my` option root. | +| `common` | Baseline for all boxes: imports the impermanence, ragenix (age), copyparty and harmonia NixOS modules; pins `system.stateVersion`; `doas` instead of `sudo`; immutable users; nix settings (flakes, `ca-derivations`, the `nix-cache.nul.ie` substituter); declares the `my` option root. | | `user` | `my.user` — the primary user: `users.users` + matching `home-manager.users` entry, wheel/doas, SSH authorized key from `.keys/me.pub`, shell taken from the home config, home persistence under tmproot. | | `build` | `my.build` — alternate build targets via `extendModules`: `my.buildAs.devVM` (QEMU dev VM), `iso`, `container`, `kexecTree`, `netbootTree`/`netbootArchive`; `my.build.isDevVM` marker; `allHardware` profile toggle. | | `dynamic-motd` | `my.dynamic-motd` — runs a script via `pam_exec` to generate the MOTD on login/ssh. | diff --git a/docs/nixpkgs-upgrade.md b/docs/nixpkgs-upgrade.md index f98d952..bca0949 100644 --- a/docs/nixpkgs-upgrade.md +++ b/docs/nixpkgs-upgrade.md @@ -72,6 +72,12 @@ For **both** branches — `devplayer0` onto `upstream/nixos-unstable`, and `devp conflicted. 6. ⏸ **Push:** only after confirmation. `git push --force-with-lease origin devplayer0 devplayer0-stable` (force needed — rebase rewrites history). +7. Wait for the GitHub mirror used by the flake inputs to catch up with the primary fork remote. + Compare the local branch tips with + `git ls-remote https://github.com/devplayer0/nixpkgs.git refs/heads/devplayer0 + refs/heads/devplayer0-stable` and do not continue until both match. Updating sooner can leave + `nixpkgs-mine` and `nixpkgs-mine-stable` pinned to the pre-rebase commits even though the push + succeeded. ## Phase 3 — Update the pinned inputs @@ -126,7 +132,7 @@ Don't blanket-update. Walk the other inputs deliberately: 1. List inputs and locked revisions from `flake.lock` (or `nix flake metadata`). 2. For each meaningful input (`libnetRepo`, `devshell`, `determinate-nix`, `ragenix`, `deploy-rs`, - `impermanence`, and the packaged apps like `boardie`, `harmonia`, `copyparty`, `sharry`, …), + `impermanence`, and the packaged apps like `boardie`, `harmonia`, and `copyparty`), compare the locked revision to upstream and summarize notable changes (breaking changes, relevant fixes). Many inputs `follows` `nixpkgs-unstable` and already moved in Phase 3. 3. Propose a per-input update list with reasons; update the approved ones with targeted @@ -137,7 +143,14 @@ Don't blanket-update. Walk the other inputs deliberately: 1. `nix flake check --no-build` (broad eval; reproduces CI's cheap checks). 2. `check-system ` on a representative box, and one exercising the stable channel if the boxes mix channels. This must exercise the refreshed kernel constants on both channels. -3. Report eval/build results honestly. On failure, surface the error and stop rather than papering +3. Build the actual devshell with + `nix build --no-link --print-out-paths .#devShells.x86_64-linux.default`. Evaluation does not + build its dependencies, so it cannot catch packaging conflicts introduced by inputs such as + Determinate Nix. +4. After the evaluations pass, run `build-system ` for one representative NixOS box. Prefer + the local box when it is managed by this flake: its full closure is likely to exercise the most + relevant packages, home-manager configuration and upgraded kernel. Build only; do not switch. +5. Report eval/build results honestly. On failure, surface the error and stop rather than papering over it. ## Wrap-up diff --git a/docs/sites/colony/shill/README.md b/docs/sites/colony/shill/README.md index 55ed8e1..58fc2eb 100644 --- a/docs/sites/colony/shill/README.md +++ b/docs/sites/colony/shill/README.md @@ -53,7 +53,7 @@ their current addresses. Each container has its own page: | [`colony-psql`](containers/colony-psql.md) | Shared PostgreSQL (14) | | [`chatterbox`](containers/chatterbox.md) | Matrix Synapse + bridges | | [`jackflix`](containers/jackflix.md) | Media stack | -| [`object`](containers/object.md) | MinIO, Harmonia Nix cache, Sharry, HedgeDoc, wastebin | +| [`object`](containers/object.md) | MinIO, Harmonia Nix cache, HedgeDoc, wastebin | | [`toot`](containers/toot.md) | Bluesky PDS (Mastodon disabled) | | [`waffletail`](containers/waffletail.md) | Tailscale subnet router / exit node | | [`qclk`](containers/qclk.md) | WireGuard management appliance | diff --git a/docs/sites/colony/shill/containers/colony-psql.md b/docs/sites/colony/shill/containers/colony-psql.md index 0983a4b..2b20f6b 100644 --- a/docs/sites/colony/shill/containers/colony-psql.md +++ b/docs/sites/colony/shill/containers/colony-psql.md @@ -15,7 +15,7 @@ database, the containers (and the `git` VM) connect here over the `ctrs` network the ident map. - **netdata** with the Python PostgreSQL collector. - Consumers wait for the database to accept connections with the `lib.my.systemdAwaitPostgres` - helper (e.g. `sharry`, `atticd`, `mastodon-init-db`, and `middleman`'s nginx as a DNS + helper (e.g. `atticd`, `mastodon-init-db`, and `middleman`'s nginx as a DNS bootstrap hack). ## Network assignments @@ -27,7 +27,7 @@ use as the database hostname. ## Consumers -- [object](object.md) — `sharry` and `hedgedoc` (and `atticd` when enabled) over +- [object](object.md) — `hedgedoc` (and `atticd` when enabled) over `colony-psql:5432` - [toot](toot.md) — Mastodon's database (Mastodon currently disabled) - [chatterbox](chatterbox.md) — the mautrix bridges (WhatsApp, Messenger, Instagram) via diff --git a/docs/sites/colony/shill/containers/middleman.md b/docs/sites/colony/shill/containers/middleman.md index 79be915..04f592b 100644 --- a/docs/sites/colony/shill/containers/middleman.md +++ b/docs/sites/colony/shill/containers/middleman.md @@ -71,7 +71,6 @@ all vhosts are `onlySSL`, kTLS and HTTP/2. "SSO" = gated behind nginx-sso (`gene | `jackflix.nul.ie` | `jackflix-ctr:8096` | Jellyfin; `/socket` websockets; `/` redirects to `/web/` | | `toot.nul.ie` | `toot-ctr:80` | Mastodon — **upstream currently disabled**, see [toot](toot.md) | | `pds.nul.ie` | `toot-ctr:3000` | Bluesky PDS ([toot](toot.md)); websockets | -| `share.nul.ie` | `object-ctr:9090` | Sharry ([object](object.md)); websockets | | `stuff.nul.ie` | `jackflix-ctr:3923` | copyparty | | `public.nul.ie` (+ alias `p.nul.ie`) | static `/mnt/media/public` | fancyindex file listing; `addSSL` so plain HTTP also works | | `mc-map.nul.ie` | `simpcraft-oci:8100` | Minecraft map (OCI container on [`whale2`](../../whale2.md#game-servers)) | diff --git a/docs/sites/colony/shill/containers/object.md b/docs/sites/colony/shill/containers/object.md index 4ca16c7..db245c7 100644 --- a/docs/sites/colony/shill/containers/object.md +++ b/docs/sites/colony/shill/containers/object.md @@ -1,7 +1,6 @@ # object -Object storage and the Nix binary cache, plus a few small self-hosted web apps (Sharry, -HedgeDoc, wastebin). +Object storage and the Nix binary cache, plus HedgeDoc and wastebin. - **Source:** [`shill/containers/object.nix`](../../../../../nixos/boxes/colony/vms/shill/containers/object.nix) - **Host:** NixOS container on [`shill`](../README.md) (bind-mounts `/mnt/minio` and @@ -14,7 +13,6 @@ HedgeDoc, wastebin). | --- | --- | --- | | MinIO | `9000` (S3) / `9001` (console) | S3-compatible object storage, `s3.nul.ie` + `*.s3.nul.ie` (virtual-host style via `MINIO_DOMAIN`), console at `minio.nul.ie`; region `eu-central-1`; data on the `/mnt/minio` XFS volume | | Harmonia | `5000` | Nix binary cache at `nix-cache.nul.ie` — `harmonia-dev` cache serves `shill`'s `/nix/store` out of a dedicated store view rooted at `/var/lib/harmonia` (bind-mounted from `/mnt/nix-cache`), signed with the `nix-cache.key` secret; a `harmonia` user with authorized keys exists for cache pushes | -| Sharry | `9090` | file sharing at `share.nul.ie`; Postgres on [colony-psql](colony-psql.md), files stored in the `share` MinIO bucket; fixed `dev` account + invite signup; mail via `mail.nul.ie`; configured share-size limit | | HedgeDoc | `3000` | collaborative markdown notes at `md.nul.ie`; Postgres on [colony-psql](colony-psql.md); anonymous edits but no anonymous notes, email login, no open email registration | | wastebin | `8088` | pastebin at `pb.nul.ie` | | atticd | `8069` | **currently disabled** (`services.atticd.enable = false`) — an alternative Nix cache that would store locally and sit behind `nix-cache.nul.ie`; config (including the `object/atticd.env` secret) is kept around | @@ -29,10 +27,10 @@ See the consolidated [network assignments](../../../../networking.md#box-assignm ## Backing services -- [colony-psql](colony-psql.md) — Sharry and HedgeDoc databases (atticd too, when enabled). +- [colony-psql](colony-psql.md) — HedgeDoc's database (atticd too, when enabled). - MinIO buckets back other boxes' services: Gitea LFS/packages (with the `middleman` MIME hack for Docker manifests), Mastodon's `mastodon` bucket and the Bluesky PDS `pds` bucket on - [toot](toot.md), and Sharry's `share` bucket. + [toot](toot.md). ## Notable config files diff --git a/flake.lock b/flake.lock index 5347a3d..50d6436 100644 --- a/flake.lock +++ b/flake.lock @@ -75,11 +75,11 @@ ] }, "locked": { - "lastModified": 1781351267, - "narHash": "sha256-86HFs1K+LRlx8t4AjaMdU5qlg4O7kLz1VlnNapKZIuY=", + "lastModified": 1787524125, + "narHash": "sha256-P48TOQdIbB0PKMn4FTk6X0utbf0LemNlJ+bFcSbveGA=", "owner": "9001", "repo": "copyparty", - "rev": "90639de9840d7dcc2d9000026fe547f666c1d550", + "rev": "9de090265f8d063056320f41d984830839017a2f", "type": "github" }, "original": { @@ -90,11 +90,11 @@ }, "crane": { "locked": { - "lastModified": 1780532242, - "narHash": "sha256-D+BsdpxmtUwtqGoY0IXPhHgTlmqgcZKCEo1oMyn7ep0=", + "lastModified": 1787326676, + "narHash": "sha256-lWhBbBvC05/xwivKBBiM2YNizpmgqCgyOIzomvRuwxs=", "owner": "ipetkov", "repo": "crane", - "rev": "59a82a1222dd3b2080b5cc52a1a2e8d5f1b77f37", + "rev": "692f7e9ef2ece8125b466f66f2af532b3edaed0d", "type": "github" }, "original": { @@ -150,11 +150,11 @@ "utils": "utils" }, "locked": { - "lastModified": 1781023725, - "narHash": "sha256-Gt+qFANcrDRjl3xzidLYrAUQCd3808iuAsLwZbYYAEU=", + "lastModified": 1786361680, + "narHash": "sha256-IxaZkb9rCGEZ+yGndxKXONeIEcKMzoFUsvLTB5G/caw=", "owner": "serokell", "repo": "deploy-rs", - "rev": "2ce9051767ee4d1a3c43b52ba327431783bfd463", + "rev": "16901271e5b30b591e56f7a84f25f186fb20f3e1", "type": "github" }, "original": { @@ -167,19 +167,17 @@ "inputs": { "flake-parts": "flake-parts", "git-hooks-nix": "git-hooks-nix", - "nixpkgs": [ - "nixpkgs-unstable" - ], + "nixpkgs": "nixpkgs_4", "nixpkgs-23-11": "nixpkgs-23-11", "nixpkgs-regression": "nixpkgs-regression" }, "locked": { - "lastModified": 1785428605, - "narHash": "sha256-wfaiSRLM1wDb4MV+NEzbyheK9Y03/oe56NR2I84UF7E=", - "rev": "0ff46631f69584c9f76792cae595ea253bd482c3", - "revCount": 26288, + "lastModified": 1787334067, + "narHash": "sha256-wmwgSBcAGJe/e+FrLwJxlghYV12F7UkIodm0j6cosYg=", + "rev": "c407745c8b9b616bebf7288697699c45794e31ac", + "revCount": 27248, "type": "tarball", - "url": "https://api.flakehub.com/f/pinned/DeterminateSystems/nix-src/3.21.9/019fb409-4d6e-7243-8a88-23ceee2520e9/source.tar.gz" + "url": "https://api.flakehub.com/f/pinned/DeterminateSystems/nix-src/3.22.2/01a02595-e77f-7e43-a616-5bbc77a2dc07/source.tar.gz" }, "original": { "type": "tarball", @@ -205,25 +203,6 @@ "type": "github" } }, - "devshell-tools": { - "inputs": { - "flake-utils": "flake-utils_10", - "nixpkgs": "nixpkgs_5" - }, - "locked": { - "lastModified": 1710099997, - "narHash": "sha256-WmBKTLdth6I/D+0//9enbIXohGsBjepbjIAm9pCYj0U=", - "owner": "eikek", - "repo": "devshell-tools", - "rev": "e82faf976d318b3829f6f7f6785db6f3c7b65267", - "type": "github" - }, - "original": { - "owner": "eikek", - "repo": "devshell-tools", - "type": "github" - } - }, "devshell_2": { "inputs": { "flake-utils": "flake-utils_3", @@ -282,15 +261,15 @@ "flake-compat_2": { "flake": false, "locked": { - "lastModified": 1696426674, - "narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=", - "owner": "edolstra", + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", + "owner": "NixOS", "repo": "flake-compat", - "rev": "0f9255e01c2351cc7d116c072cb317785dd33b33", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", "type": "github" }, "original": { - "owner": "edolstra", + "owner": "NixOS", "repo": "flake-compat", "type": "github" } @@ -303,12 +282,12 @@ ] }, "locked": { - "lastModified": 1748821116, - "narHash": "sha256-F82+gS044J1APL0n4hH50GYdPRv/5JWm34oCJYmVKdE=", - "rev": "49f0870db23e8c1ca0b5259734a02cd9e1e371a1", - "revCount": 377, + "lastModified": 1782949081, + "narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=", + "rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e", + "revCount": 480, "type": "tarball", - "url": "https://api.flakehub.com/f/pinned/hercules-ci/flake-parts/0.1.377%2Brev-49f0870db23e8c1ca0b5259734a02cd9e1e371a1/01972f28-554a-73f8-91f4-d488cc502f08/source.tar.gz" + "url": "https://api.flakehub.com/f/pinned/hercules-ci/flake-parts/0.1.480%2Brev-17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e/019f2195-dee5-7233-9747-eca0c27f7406/source.tar.gz" }, "original": { "type": "tarball", @@ -354,57 +333,6 @@ "type": "github" } }, - "flake-utils_10": { - "inputs": { - "systems": "systems_10" - }, - "locked": { - "lastModified": 1709126324, - "narHash": "sha256-q6EQdSeUZOG26WelxqkmR7kArjgWCdw5sfJVHPH/7j8=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "d465f4819400de7c8d874d50b982301f28a84605", - "type": "github" - }, - "original": { - "owner": "numtide", - "repo": "flake-utils", - "type": "github" - } - }, - "flake-utils_11": { - "inputs": { - "systems": "systems_11" - }, - "locked": { - "lastModified": 1705309234, - "narHash": "sha256-uNRRNRKmJyCRC/8y1RqBkqWBLM034y4qN7EprSdmgyA=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "1ef2e671c3b0c19053962c07dbda38332dcebf26", - "type": "github" - }, - "original": { - "owner": "numtide", - "repo": "flake-utils", - "type": "github" - } - }, - "flake-utils_12": { - "locked": { - "lastModified": 1667395993, - "narHash": "sha256-nuEHfE/LcWyuSWnS8t12N1wc105Qtau+/OdUAjtQ0rA=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "5aed5285a952e0b949eb3ba02c12fa4fcfef535f", - "type": "github" - }, - "original": { - "owner": "numtide", - "repo": "flake-utils", - "type": "github" - } - }, "flake-utils_2": { "inputs": { "systems": "systems_2" @@ -543,21 +471,18 @@ "git-hooks-nix": { "inputs": { "flake-compat": "flake-compat_2", - "gitignore": [ - "determinate-nix" - ], "nixpkgs": [ "determinate-nix", "nixpkgs" ] }, "locked": { - "lastModified": 1747372754, - "narHash": "sha256-2Y53NGIX2vxfie1rOW0Qb86vjRZ7ngizoo+bnXU9D9k=", - "rev": "80479b6ec16fefd9c1db3ea13aeb038c60530f46", - "revCount": 1026, + "lastModified": 1784288435, + "narHash": "sha256-ReRHaLgr/uVqdD8afFSn+myXIfpHeOhP0yYe0TJqAA8=", + "rev": "43b3c1ab9d40fb1dbb008f451988a91e375825e9", + "revCount": 1231, "type": "tarball", - "url": "https://api.flakehub.com/f/pinned/cachix/git-hooks.nix/0.1.1026%2Brev-80479b6ec16fefd9c1db3ea13aeb038c60530f46/0196d79a-1b35-7b8e-a021-c894fb62163d/source.tar.gz" + "url": "https://api.flakehub.com/f/pinned/cachix/git-hooks.nix/0.1.1231%2Brev-43b3c1ab9d40fb1dbb008f451988a91e375825e9/019f7135-8fdf-76f0-b1a1-d2c67e91af8d/source.tar.gz" }, "original": { "type": "tarball", @@ -574,11 +499,11 @@ "treefmt-nix": "treefmt-nix" }, "locked": { - "lastModified": 1781128165, - "narHash": "sha256-97WpKZkaNAL5g7MtASLwqnrJrvrLpQRr6cXWiRNLiXQ=", + "lastModified": 1787502072, + "narHash": "sha256-K5sKCAV3kPbUW0evsqpWrlQRsa2t0jfkduSZ+lRWAA8=", "owner": "nix-community", "repo": "harmonia", - "rev": "f0dd1094cdc8d72e038cf9347cacfa9272a8f72d", + "rev": "7c1ef262e324bbf61201fe92a73849eb3d6fd9e2", "type": "github" }, "original": { @@ -595,11 +520,11 @@ ] }, "locked": { - "lastModified": 1781402797, - "narHash": "sha256-pBdDca7xv1nuP0kj+gC5g5AcR/DV+9Zy3CS6uDOMdJ4=", + "lastModified": 1781447016, + "narHash": "sha256-bxZ8XTdUFQRWsh6rZn7fCui/SV4ox7dUAiSg4zYJuDg=", "owner": "devplayer0", "repo": "hass-west-wood", - "rev": "3e6ef7a9084e4053c82dea20127a775e7bcf77a5", + "rev": "fd43bede6e1175d9118c42507b737041b8923787", "type": "github" }, "original": { @@ -637,11 +562,11 @@ ] }, "locked": { - "lastModified": 1781319724, - "narHash": "sha256-ZGuxexEMo4Xv28KJ0dX/m/PHN4oZIOnxHZpNTyrvx4M=", + "lastModified": 1787377438, + "narHash": "sha256-Sxu1NLTD/Ern6hFGLlZmtKCSct3YQXZI/lls8RE1XeM=", "owner": "nix-community", "repo": "home-manager", - "rev": "8355f0a16b2dbb06a97959a918af5b239bbe05ae", + "rev": "65258d5c65a250189fde2e35f490d15e064c4c62", "type": "github" }, "original": { @@ -657,11 +582,11 @@ ] }, "locked": { - "lastModified": 1781305496, - "narHash": "sha256-g8Vv4Qfc7n+lgov97REu3X6BeJtvYY0hlSUZR1GrGQQ=", + "lastModified": 1787487906, + "narHash": "sha256-zIdM+8teujHm5hc5MIPDnV7k2UeOOT/pFyFtWjOCwsY=", "owner": "nix-community", "repo": "home-manager", - "rev": "c87a39aa979acc4848016d2220c6238390d84779", + "rev": "cfba7ad5886b342b8dd63ba74354b3853ea4cfc9", "type": "github" }, "original": { @@ -674,7 +599,7 @@ "home-manager": [ "home-manager-unstable" ], - "nixpkgs": "nixpkgs_4" + "nixpkgs": "nixpkgs_5" }, "locked": { "lastModified": 1769548169, @@ -693,11 +618,11 @@ "libnetRepo": { "flake": false, "locked": { - "lastModified": 1776595118, - "narHash": "sha256-6bIEi8q5hXCHU9nApTbQXvpljMWldg3QipCD+jkOGK8=", + "lastModified": 1781446676, + "narHash": "sha256-b3rJDKxzsf7p4wI698iBi2PInDPRH3KwjdqOk/SahKk=", "owner": "oddlama", "repo": "nixos-extra-modules", - "rev": "84207afebb794be7b53cfc9768730f37c64f4a13", + "rev": "f097b474fcb5db7dfd52263c055c9e6caeb13d62", "type": "github" }, "original": { @@ -709,11 +634,11 @@ "nix": { "flake": false, "locked": { - "lastModified": 1780652321, - "narHash": "sha256-o/6YXRB6AbeL4SYtSHlJ9oEROl6Wmf7yheJNa3fAv2I=", + "lastModified": 1787394889, + "narHash": "sha256-qtDusLx9yn0aME9D9Oe5QhFnmDUaARwMJo/vt4+DtIU=", "owner": "nixos", "repo": "nix", - "rev": "d1f04a798cf4276da59567c07a3bf4a628669288", + "rev": "88b09c64fbea076a0376830d98e5331f70ed31a3", "type": "github" }, "original": { @@ -777,11 +702,11 @@ }, "nixpkgs-mine": { "locked": { - "lastModified": 1781356656, - "narHash": "sha256-Ygkl3ZBJ434/WhwdK1FyvPMeHvNPAopg3KE/1HtcJuk=", + "lastModified": 1787523184, + "narHash": "sha256-wdRy2OJNSEceZoyDyAXWWw7sroxQZlY/d3FyeOU3QxA=", "owner": "devplayer0", "repo": "nixpkgs", - "rev": "a15e20705db295f621cb5bb63613f03a9373323f", + "rev": "9eaacb6680b6f10067acd4b10c61ef4c4d643fb6", "type": "github" }, "original": { @@ -793,11 +718,11 @@ }, "nixpkgs-mine-stable": { "locked": { - "lastModified": 1781356876, - "narHash": "sha256-s8ed+zuk5wrbyhtDQpkxycAcLmhQH9umGRuVRBNKUbU=", + "lastModified": 1787523195, + "narHash": "sha256-NI87OKi5hXSZlIgh5Gwjjca52MAJnwRaU/+Su99fMqg=", "owner": "devplayer0", "repo": "nixpkgs", - "rev": "2eb8bacf9f641d4510fc43ba7fc0eea7dfdf5b24", + "rev": "2a058ae98b603146eae51e6a268854ce0ad035a1", "type": "github" }, "original": { @@ -825,11 +750,11 @@ }, "nixpkgs-stable": { "locked": { - "lastModified": 1780902259, - "narHash": "sha256-q8yYEC5f1mFlQO9RGna4LTc9QrcvWunX6FYp83munkQ=", + "lastModified": 1787414105, + "narHash": "sha256-WncT27+3BOkgTaJZLnCsf3LcYf9RXMuR9ONSN4rzQ7s=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "bd0ff2d3eac24699c3664d5966b9ef36f388e2ca", + "rev": "a9e6d84f9c2f9012f5fe7d964a7851352300e61a", "type": "github" }, "original": { @@ -840,11 +765,11 @@ }, "nixpkgs-unstable": { "locked": { - "lastModified": 1781074563, - "narHash": "sha256-md8WlXOlfnIeHeOScMTTHFyf2d6iaTwPl2apR5EQ3P4=", + "lastModified": 1787360063, + "narHash": "sha256-dt4WdcvsA8/RCe+VZZwqU0X+XMM3wBbGCWA0/sFWzGo=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "9ae611a455b90cf061d8f332b977e387bda8e1ca", + "rev": "2c423e03bbafcff28bfadc6781a4a8257f205cb5", "type": "github" }, "original": { @@ -884,6 +809,22 @@ } }, "nixpkgs_4": { + "locked": { + "lastModified": 1784160687, + "narHash": "sha256-iYL/bixrb6FlHFu/gIuBYzq6c6lM5AAXsXNSWXtIgQc=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "4382ed2b7a6839d4280a9b386db49cbc5907414d", + "type": "github" + }, + "original": { + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "4382ed2b7a6839d4280a9b386db49cbc5907414d", + "type": "github" + } + }, + "nixpkgs_5": { "locked": { "lastModified": 1768564909, "narHash": "sha256-Kell/SpJYVkHWMvnhqJz/8DqQg2b6PguxVWOuadbHCc=", @@ -899,38 +840,6 @@ "type": "github" } }, - "nixpkgs_5": { - "locked": { - "lastModified": 1709309926, - "narHash": "sha256-VZFBtXGVD9LWTecGi6eXrE0hJ/mVB3zGUlHImUs2Qak=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "79baff8812a0d68e24a836df0a364c678089e2c7", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixos-23.11", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_6": { - "locked": { - "lastModified": 1674990008, - "narHash": "sha256-4zOyp+hFW2Y7imxIpZqZGT8CEqKmDjwgfD6BzRUE0mQ=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "d2bbcbe6c626d339b25a4995711f07625b508214", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixpkgs-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, "openwrt-feeds": { "inputs": { "nixpkgs": [ @@ -963,11 +872,11 @@ "systems": "systems_7" }, "locked": { - "lastModified": 1787302424, - "narHash": "sha256-fg9pKzO6OeQhe/bY2CpHb6QnHq57P/icwQz35GF/R/8=", + "lastModified": 1787474509, + "narHash": "sha256-jL5RS/TbKk7HxjsGyFWeceHveyRgM8btvfY9Z77P9jM=", "owner": "astro", "repo": "nix-openwrt-imagebuilder", - "rev": "276c1dd6346f50231392e97b3a9987c9dd57da28", + "rev": "4371439b1e4e582266fc38345d1a01db1f8db6d6", "type": "github" }, "original": { @@ -1044,8 +953,7 @@ "nixpkgs-unstable": "nixpkgs-unstable", "openwrt-feeds": "openwrt-feeds", "openwrt-imagebuilder": "openwrt-imagebuilder", - "ragenix": "ragenix", - "sharry": "sharry" + "ragenix": "ragenix" } }, "rust-overlay": { @@ -1056,11 +964,11 @@ ] }, "locked": { - "lastModified": 1761791894, - "narHash": "sha256-myRIDh+PxaREz+z9LzbqBJF+SnTFJwkthKDX9zMyddY=", + "lastModified": 1787454509, + "narHash": "sha256-r4LDUF+zmJnkftvCVkCrUhSJazsf6EVJF+V2l4/MYbI=", "owner": "oxalica", "repo": "rust-overlay", - "rev": "59c45eb69d9222a4362673141e00ff77842cd219", + "rev": "f60c1b57ff805a46b5175c76fc981fb4f81efbcc", "type": "github" }, "original": { @@ -1069,48 +977,6 @@ "type": "github" } }, - "sbt": { - "inputs": { - "flake-utils": "flake-utils_12", - "nixpkgs": "nixpkgs_6" - }, - "locked": { - "lastModified": 1698464090, - "narHash": "sha256-Pnej7WZIPomYWg8f/CZ65sfW85IfIUjYhphMMg7/LT0=", - "owner": "zaninime", - "repo": "sbt-derivation", - "rev": "6762cf2c31de50efd9ff905cbcc87239995a4ef9", - "type": "github" - }, - "original": { - "owner": "zaninime", - "repo": "sbt-derivation", - "type": "github" - } - }, - "sharry": { - "inputs": { - "devshell-tools": "devshell-tools", - "flake-utils": "flake-utils_11", - "nixpkgs": [ - "nixpkgs-unstable" - ], - "sbt": "sbt" - }, - "locked": { - "lastModified": 1741328331, - "narHash": "sha256-OtsHm9ykxfAOMRcgFDsqFBBy5Wu0ag7eq1qmTIluVcw=", - "owner": "eikek", - "repo": "sharry", - "rev": "6203b90f9a76357d75c108a27ad00f323d45c1d0", - "type": "github" - }, - "original": { - "owner": "eikek", - "repo": "sharry", - "type": "github" - } - }, "systems": { "locked": { "lastModified": 1681028828, @@ -1126,36 +992,6 @@ "type": "github" } }, - "systems_10": { - "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" - } - }, - "systems_11": { - "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" - } - }, "systems_2": { "locked": { "lastModified": 1681028828, @@ -1284,11 +1120,11 @@ ] }, "locked": { - "lastModified": 1780220602, - "narHash": "sha256-eynAfOmbmxJnkp7YewvCEbShNnnYJ9gLLqkzsYtBPeM=", + "lastModified": 1786901030, + "narHash": "sha256-WSFCsDSE5ffgD2MqzkM2CYjeFiKhRF/dJUN8uedb6YE=", "owner": "numtide", "repo": "treefmt-nix", - "rev": "db947814a175b7ca6ded66e21383d938df01c227", + "rev": "27b3b12a8e6375f28ebe122f07d230ca5459bbfa", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix index 2fc8a82..b5d90ff 100644 --- a/flake.nix +++ b/flake.nix @@ -35,10 +35,11 @@ home-manager-stable.inputs.nixpkgs.follows = "nixpkgs-stable"; # Determinate Nix, used as the common Nix implementation across systems, homes, the devshell and - # CI (see lib.my.c.nix). We build it ourselves against our pinned nixpkgs (FlakeHub's cache needs - # auth), so it flows through our own Harmonia cache like everything else. + # CI (see lib.my.c.nix). We build it ourselves (FlakeHub's cache needs auth), so it flows through + # our own Harmonia cache like everything else. Keep its tested nixpkgs pin: its packaging carries + # compatibility patches that can conflict with newer nixpkgs patches. determinate-nix.url = "https://flakehub.com/f/DeterminateSystems/nix-src/*"; - determinate-nix.inputs.nixpkgs.follows = "nixpkgs-unstable"; + determinate-nix.inputs.nixpkgs.url = "github:NixOS/nixpkgs/4382ed2b7a6839d4280a9b386db49cbc5907414d"; # Stuff used by the flake for build / deployment # ragenix.url = "github:yaxitech/ragenix"; @@ -68,8 +69,6 @@ openwrt-feeds.inputs.openwrt-imagebuilder.follows = "openwrt-imagebuilder"; # Packages not in nixpkgs - sharry.url = "github:eikek/sharry"; - sharry.inputs.nixpkgs.follows = "nixpkgs-unstable"; borgthin.url = "github:devplayer0/borg"; # TODO: Update borgthin so this works # borgthin.inputs.nixpkgs.follows = "nixpkgs-mine"; diff --git a/home-manager/modules/gui/default.nix b/home-manager/modules/gui/default.nix index 0162ceb..b3bae8f 100644 --- a/home-manager/modules/gui/default.nix +++ b/home-manager/modules/gui/default.nix @@ -423,12 +423,12 @@ in gtk = { enable = true; theme = { - name = "Numix"; - package = pkgs.numix-gtk-theme; + name = "Adwaita"; + package = pkgs.gnome-themes-extra; }; gtk4.theme = { - name = "Numix"; - package = pkgs.numix-gtk-theme; + name = "Adwaita"; + package = pkgs.gnome-themes-extra; }; iconTheme = { name = "Numix"; diff --git a/lib/constants.nix b/lib/constants.nix index f1d97fc..5df1f42 100644 --- a/lib/constants.nix +++ b/lib/constants.nix @@ -30,7 +30,7 @@ rec { kernel = { lts = pkgs: pkgs.linuxKernel.packages.linux_6_18; - latest = pkgs: pkgs.linuxKernel.packages.linux_7_0; + latest = pkgs: pkgs.linuxKernel.packages.linux_7_2; }; nginx = rec { diff --git a/lib/default.nix b/lib/default.nix index 5df2631..92fa44c 100644 --- a/lib/default.nix +++ b/lib/default.nix @@ -253,7 +253,7 @@ rec { in { trivial = prev.trivial // { - release = "26.06:u-${prev.trivial.release}"; + release = "26.08:u-${prev.trivial.release}"; codeName = "Irritating"; revisionWithDefault = default: self.rev or default; versionSuffix = ".${date}.${revCode self}:u-${revCode pkgsFlake}"; diff --git a/nixos/boxes/colony/vms/shill/containers/middleman/vhosts.nix b/nixos/boxes/colony/vms/shill/containers/middleman/vhosts.nix index 958e184..fbbe5a9 100644 --- a/nixos/boxes/colony/vms/shill/containers/middleman/vhosts.nix +++ b/nixos/boxes/colony/vms/shill/containers/middleman/vhosts.nix @@ -336,15 +336,6 @@ in useACMEHost = pubDomain; }; - "share.${pubDomain}" = { - locations."/" = { - proxyPass = "http://object-ctr.${domain}:9090"; - proxyWebsockets = true; - extraConfig = proxyHeaders; - }; - useACMEHost = pubDomain; - }; - "stuff.${pubDomain}" = { locations."/" = { proxyPass = "http://jackflix-ctr.${domain}:3923"; diff --git a/nixos/boxes/colony/vms/shill/containers/object.nix b/nixos/boxes/colony/vms/shill/containers/object.nix index 29e9a76..c699fdd 100644 --- a/nixos/boxes/colony/vms/shill/containers/object.nix +++ b/nixos/boxes/colony/vms/shill/containers/object.nix @@ -47,10 +47,6 @@ in key = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFdHbZErWLmTPO/aEWB1Fup/aGMf31Un5Wk66FJwTz/8"; files = { "object/minio.env" = {}; - "object/sharry.conf" = { - owner = "sharry"; - group = "sharry"; - }; "object/minio-client-config.json" = { owner = config.my.user.config.name; group = config.my.user.config.group; @@ -65,7 +61,6 @@ in firewall = { tcp.allowed = [ 9000 9001 - config.services.sharry.config.bind.port 8069 5000 config.services.hedgedoc.settings.port @@ -122,8 +117,6 @@ in }; }; - sharry = awaitPostgres; - atticd = mkMerge [ awaitPostgres { @@ -175,66 +168,6 @@ in dataDir = [ "/mnt/minio" ]; }; - sharry = { - enable = true; - configOverridesFile = config.age.secrets."object/sharry.conf".path; - - config = { - base-url = "https://share.${lib.my.c.pubDomain}"; - bind.address = "::"; - alias-member-enabled = true; - webapp = { - chunk-size = "64M"; - }; - backend = { - auth = { - fixed = { - enabled = true; - user = "dev"; - }; - internal = { - enabled = true; - order = 50; - }; - }; - jdbc = { - url = "jdbc:postgresql://colony-psql:5432/sharry"; - user = "sharry"; - }; - files = { - default-store = "minio"; - stores = { - database.enabled = false; - minio = { - enabled = true; - type = "s3"; - endpoint = "https://s3.nul.ie"; - access-key = "share"; - bucket = "share"; - }; - }; - }; - compute-checksum.parallel = 4; - signup.mode = "invite"; - share = { - max-size = "128G"; - max-validity = "3650 days"; - }; - mail = { - enabled = true; - smtp = { - host = "mail.nul.ie"; - port = 587; - user = "sharry@nul.ie"; - ssl-type = "starttls"; - default-from = "Sharry "; - timeout = "30 seconds"; - }; - }; - }; - }; - }; - atticd = { enable = false; environmentFile = config.age.secrets."object/atticd.env".path; @@ -308,7 +241,6 @@ in forwardPorts = [ { from = "host"; host.port = 9000; guest.port = 9000; } { from = "host"; host.port = 9001; guest.port = 9001; } - { from = "host"; guest.port = config.services.sharry.config.bind.port; } ]; }; }) diff --git a/nixos/boxes/home/palace/vms/sfh/containers/hass.nix b/nixos/boxes/home/palace/vms/sfh/containers/hass.nix index 8317345..e3b5061 100644 --- a/nixos/boxes/home/palace/vms/sfh/containers/hass.nix +++ b/nixos/boxes/home/palace/vms/sfh/containers/hass.nix @@ -47,8 +47,9 @@ in inherit (lib) mkMerge mkIf mkForce; inherit (lib.my) networkdAssignment; + hassPort = 8123; hassCli = pkgs.writeShellScriptBin "hass-cli" '' - export HASS_SERVER="http://localhost:${toString config.services.home-assistant.config.http.server_port}" + export HASS_SERVER="http://localhost:${toString hassPort}" export HASS_TOKEN="$(< ${config.age.secrets."hass/cli-token.txt".path})" exec ${pkgs.home-assistant-cli}/bin/hass-cli "$@" ''; @@ -69,7 +70,7 @@ in }; firewall = { - tcp.allowed = [ "http" 1883 ]; + tcp.allowed = [ "http" hassPort 1883 ]; }; }; @@ -166,8 +167,6 @@ in home-assistant = let - cfg = config.services.home-assistant; - pyirishrail = ps: ps.buildPythonPackage rec { pname = "pyirishrail"; version = "0.0.2"; @@ -217,7 +216,6 @@ in ]; configWritable = false; - openFirewall = true; config = { default_config = {}; homeassistant = { @@ -227,9 +225,10 @@ in country = "IE"; time_zone = "Europe/Dublin"; external_url = "https://hass.${pubDomain}"; - internal_url = "http://hass-ctr.${domain}:${toString cfg.config.http.server_port}"; + internal_url = "http://hass-ctr.${domain}:${toString hassPort}"; }; http = { + server_port = hassPort; use_x_forwarded_for = true; trusted_proxies = with allAssignments.middleman.internal; [ ipv4.address diff --git a/nixos/default.nix b/nixos/default.nix index 90b49bf..3543cb1 100644 --- a/nixos/default.nix +++ b/nixos/default.nix @@ -191,7 +191,7 @@ let # Routes the custom modules into `baseModules` so the NixOS manual documents them. The old # infinite-recursion is gone, but enabling this makes every system build regenerate the # manual, and it documents everything the modules transitively import — including third-party - # modules that aren't doc-clean (e.g. `services.sharry`). Prefer the generated + # modules that aren't doc-clean. Prefer the generated # `nixos.optionsDoc` reference (`docs/reference/nixos-options.md`) instead. docCustom = mkBoolOpt' false "Whether to document nixfiles' custom NixOS modules."; diff --git a/nixos/modules/common.nix b/nixos/modules/common.nix index dbc1cd1..246195b 100644 --- a/nixos/modules/common.nix +++ b/nixos/modules/common.nix @@ -11,7 +11,6 @@ in imports = [ inputs.impermanence.nixosModules.default inputs.ragenix.nixosModules.age - inputs.sharry.nixosModules.default inputs.copyparty.nixosModules.default inputs.harmonia.nixosModules.harmonia ]; @@ -77,7 +76,6 @@ in nixpkgs = { overlays = [ inputs.deploy-rs.overlays.default - inputs.sharry.overlays.default # TODO: Re-enable when borgthin is updated # inputs.borgthin.overlays.default inputs.boardie.overlays.default @@ -169,7 +167,7 @@ in services = { # TODO: Remove if-else when 26.11 releases - kmscon = if (config.system.nixos.release == "26.06:u-26.11") then { + kmscon = if (config.system.nixos.release == "26.08:u-26.11") then { enable = mkDefault false; config = { hwaccel = config.hardware.graphics.enable; diff --git a/secrets/object/sharry.conf.age b/secrets/object/sharry.conf.age deleted file mode 100644 index 772a2b9..0000000 --- a/secrets/object/sharry.conf.age +++ /dev/null @@ -1,18 +0,0 @@ ------BEGIN AGE ENCRYPTED FILE----- -YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IGhrYnR2ZyBCeHA4 -Y0hkSGZSNkMxNTY0SUVEQ3FXK0V5QUdVK2hXUFloVW1hVERHK2xFCm4xd1JJWXpH -a1J2QTVvUyt4OXdzWWtMMEo4NFZ3ZkY0YXdydXpOVCtya1UKLT4gWDI1NTE5IHhI -TW5FTHdpYjNwclVsajBUS3ZRSXpER0pKaEFiWFU3Q3cyT0RZT1VnQXcKZFNOODJu -d3RiS0p0b3JmRlZ5M0JCRDB0MzNoUkRWamdkNXZQUzB1RHZoQQotPiAvR15OXkZR -eS1ncmVhc2UKVjhxR0dVVHNWWHdxVFkyd1lPMnN5NXp6Ky9MOHlpNnpIeEExVUhO -dEtXNG9DRFY2OWNlWnFIb1c3MjNLS2V6ZAppTEo3RmZHbzRPQVA3b2xkdmZZCi0t -LSA4RmE0OVlPbUhqWDdwVHNvS0JRcm9XQXl6SFVEYXRnWS81SzNxV1NBWjY4CoYX -xS977tMXj6AbcEZvzRgJfLFoFVRGajoa+QwQyLfkZ6wkI/BQQbgSDOR2s6JEB5Fy -RIoJAB7iZoApj+Ctc4W23qif8gdMedp576VRaDSIo8CC+R6FQlf9s+1MHay8Z+ge -TjWV3xO/70eVYjPc2u/NvejZruBQc52X/yWxnZOrOl2QRDe3dzn9PHiawXdun1bl -qZlhaMaR449BPl3eadTrm4l6IybRSRqIgTWgkEOCUqdrVuBtb1HbqTf2FB9/rD41 -BblBV0q/UGx9kUxetgPiu8Wa1hjepSeSglJ9SeKAlH0PC3q+F9tYirphrxFrLGiK -e7aV4Ukpqi0T5vpCkkwm7wF3uTZnmPDz7cWvYbIw1T12N3pV/pxrjigTpqB91svC -jlMQCCtdyEojfUb+tlLlNjvkAbvwZHrc8nBCyuvTuzc2vaUnf6VTaJxGG97tUIyY -brkp5b+mDaU= ------END AGE ENCRYPTED FILE-----