jackos1998 0aade09d7e nixos/portcullis: Add initial config
New bare-metal box headed for Nikhef, intended to take over most of
estuary's colony edge routing. This is the bootstrap config only: the
hardware, the single-NVMe ESP + LVM layout, and enough networking to
boot and be reachable.

It is being staged at home before it is racked, so it has no colony
assignments yet. Every 2.5G port takes DHCP and whichever one is
patched in brings the box up; kea registers the DHCP hostname, so the
deploy node points at portcullis.dyn.h.nul.ie until there is a real
colony FQDN for it.

The host key was adopted from the installer session and seeded onto
the persist volume before first boot, so my.secrets.key could be set
up front -- which makes portcullis a recipient of the user-passwd
secret that my.user declares for every box.

Documented with a box page, a row in the colony site index, and a note
in the colony section of networking.md that the topology is expected
to change once portcullis takes over from estuary.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 01:30:59 +01:00
2026-08-19 01:30:59 +01:00
2026-07-22 18:44:03 +01:00
2026-08-19 01:30:59 +01:00
2026-08-02 00:12:57 +01:00
2023-11-17 20:25:58 +00:00

nixfiles

Personal Nix flake managing every box I run: hosted servers, home infrastructure, routers, a remote site, VPSes and personal workstations. It is built around a custom module system layered on top of NixOS and home-manager rather than the stock per-host nixosConfigurations pattern.

For the module-system internals, see docs/architecture.md; for day-to-day commands, deployment and secrets, see docs/deployment.md. This README is the map of what is actually deployed; the per-box details live under docs/ (start at docs/README.md).

Note: This documentation (the README and everything under docs/) is a work in progress and was agent-generated from the repository. It may be incomplete or out of date — treat the Nix configuration as the source of truth.

The boxes at a glance

Boxes are grouped by deployment/location. Each group has its own directory under docs/ with a README.md overview and one page per box.

Group What it is
colony Hosted dedicated server in Amsterdam (ams1). A VM host running the public-facing infrastructure: routing, web, git, media, object storage, chat, game servers.
home Home network: a VM host (palace), the home routers, storage, Home Assistant, and a workstation — plus the hand-configured switches and wireless APs tying it together.
remote Edge VPSes (britway, britnet) and the remote kelder site.
mobile The tower laptop.

The custom installer image is documented at docs/misc/installer.md. The general topics — the module system, network and deployment — live next to the index: docs/architecture.md, docs/networking.md and docs/deployment.md. The generated custom-module option reference is at docs/reference/nixos-options.md.

The high-level site diagrams and box hierarchy live in docs/README.md. Networking is largely defined by per-box assignments plus the AS211024 L2 VXLAN mesh; see docs/networking.md for the full picture and docs/architecture.md for the implementation mechanics.

Repo layout

README.md           <- you are here
nixos/
  boxes/            per-box configuration
    colony/         colony host + its VMs (vms/) + shill's containers
    home/           palace host + its VMs, routing-common, plus stream, castle
    britway/        London VPS
    kelder/         remote box + its containers
    tower/          laptop
    britnet.nix     Birmingham VPS
  installer.nix     installer-image configuration
  modules/          shared NixOS modules (my.* options); registered in _list.nix
home-manager/       home-manager modules + configs
lib/                lib.my helpers, constants (lib.my.c), net/dns helpers
pkgs/               custom packages (overlays.default)
secrets/            age-encrypted secrets (ragenix)
devshell/           devshell commands (build/deploy/check/ssh helpers)
ci/                 CI helpers (binary-cache push, docs generators)
docs/               deployment documentation (index at docs/README.md)

A box is wired into the flake by adding its config file to the configs list in flake.nix. See the top-level evaluation for how evalModules turns these into nixosConfigurations, homeConfigurations and deploy nodes.

S
Description
Configs for all (well almost all) my systems
Readme 8.7 MiB
2026-08-18 23:21:31 +01:00
Languages
Nix 85.4%
Python 7.9%
Shell 3.2%
HTML 2.3%
JavaScript 1.2%