Dotfiles, managed using Nix
  • Nix 76.6%
  • TypeScript 13%
  • Python 5.7%
  • Shell 3%
  • Nushell 1.7%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Kreato e6946207cb
kreato: probe llama-server endpoints instead of hardcoding 127.0.0.1
Both the OpenCode plugin and the prime-agent extension assumed the local
llama-server lived on 127.0.0.1:8080. Make them try a list of endpoints
at startup and keep the first one that answers /v1/models:

  localhost:8080  ->  nyx:8080

The winning host is reused for the provider base URL, so the same config
works whether llama-server runs locally or remotely on nyx. Selection
happens once per process; if nothing answers, no models register and
/reload picks it up later, as before.

Also switch the static opencode provider baseURL to localhost. The plugin
now overrides it at runtime, so the Nix value is only a fallback.
2026-09-10 22:25:58 +03:00
.github/workflows Update .github/workflows/update-nixpkgs.yaml 2026-09-10 07:56:27 +00:00
hosts hosts/myx/doh: change to 1.1.1.1 2026-09-05 21:12:19 +03:00
modules refactor(modules): use stdenv.hostPlatform and split darwin casks out 2026-09-01 15:55:54 +03:00
overlays nyx: pin typed JSON response fix 2026-09-05 04:37:02 +03:00
patches nyx: fix rmpc compat (config pragmas, mopidy-mpd binarylimit/readpicture) 2026-09-05 02:49:01 +03:00
pkgs/prime-agent prime-agent: update to 0.9.3 2026-09-10 22:17:13 +03:00
scripts baseline 2026-09-01 13:34:52 +03:00
userConfigurations kreato: probe llama-server endpoints instead of hardcoding 127.0.0.1 2026-09-10 22:25:58 +03:00
workers/hermes-asu feat(hermes): auto-configure ASU endpoint, rewrite README, add worker store proxy 2026-05-10 02:59:16 +03:00
.gitignore chore(gitignore): ignore nix build result symlinks 2026-09-01 14:11:16 +03:00
AGENTS.md baseline 2026-09-01 13:34:52 +03:00
flake.lock nyx: refresh ihtc TC builder 2026-09-06 20:17:48 +03:00
flake.nix nyx: enable ihtc TC eBPF backend 2026-09-05 20:48:26 +03:00
LICENSE init 2024-11-10 04:37:05 +03:00
README.md refactor: replace spoofdpi with ihtc for DPI circumvention 2026-06-01 02:05:23 +03:00

NixOwOS logo

declarative systems with Nix

This repository contains declarative configurations for macOS (via nix-darwin + home-manager) and OpenWrt routers (via openwrt-imagebuilder), packaged as a Nix flake.

Highlights

  • macOS: Apple Silicon setup with nix-darwin, home-manager, and nixvim.
  • Shells: Zsh and Nushell with Starship; handy aliases; optional "work profile" gating via WORK_PROFILE.
  • Editor: Neovim via nixvim (Catppuccin theme, Treesitter, LSP completion, lualine, nvim-tree, dashboard). Optional Neovide GUI.
  • macOS services: Autokbisw (keyboard language switcher), Colima (Docker on macOS), ihtc (DPI circumvention proxy with re-fragmentation); all toggleable.
  • Window management: Yabai + skhd + sketchybar wiring available (disabled by default).
  • OpenWrt router: Hermes image for Mercusys MR90X v1 with automated upgrades via luci-app-attendedsysupgrade.
  • PPPoE recovery: Automatic WAN recovery after sysupgrade when PPPoE auth fails.
  • ASU Worker: Cloudflare Worker that emulates the OpenWrt ASU API, serving prebuilt firmware metadata from GitHub Releases.
  • System tweaks: Touch ID for sudo, Rosetta AVX advertise, curated fonts, timezone from options.

Repository layout

.
├── flake.nix                 # Entry point and inputs
├── hosts/akiri/              # macOS host config
├── hosts/hermes/             # OpenWrt router image + recovery scripts
├── userConfigurations/       # Home-manager user configs
└── workers/                  # Cloudflare Workers (Hermes ASU shim)

macOS (akiri)

Prerequisites

  • Install Nix or Lix (see the official guide at nix.dev).
  • macOS on Apple Silicon (arm64).
    • Could work with Intel (x86_64) but not tested.

1Password secrets (optional)

Some provider API keys are managed via OpNix + 1Password Service Accounts. If you skip this setup, the relevant provider simply won't be available — everything else works fine.

Setup (one-time):

  1. Create a 1Password item: op://Nix/OpenCode/crof-api-key containing the crof API key
  2. Create a 1Password Service Account with read access to the Nix vault
  3. Provision the token:
    nix run github:brizzbuzz/opnix -- token set
    
  4. Rebuild:
    darwin-rebuild switch --flake .#akiri
    

Toggle via userConfigurations/<user>/options.nix:

programs.opnix.enable = true;  # set to false to disable

Install and switch

Clone to ~/.config/nix-darwin:

git clone <this-repo> ~/.config/nix-darwin
cd ~/.config/nix-darwin

First-time switch (if nix-darwin is not yet installed):

# If flakes aren't enabled yet, add the extra flags:
nix --extra-experimental-features 'nix-command flakes' run nix-darwin -- switch --flake ~/.config/nix-darwin#akiri

Subsequent rebuilds:

darwin-rebuild switch --flake ~/.config/nix-darwin#akiri
# or, from this directory:
darwin-rebuild switch --flake .#akiri
# or, if you use nushell:
rebuild

Update flake inputs and rebuild:

nix flake update
darwin-rebuild switch --flake .#akiri
# or, if you use nushell:
rebuild

Rollback the last activation if needed:

darwin-rebuild switch --flake .#akiri --rollback

OpenWrt (hermes)

Hermes is an OpenWrt image for the Mercusys MR90X v1 router, built with openwrt-imagebuilder.

Building the image

nix build .#hermes

The firmware binary will be in result/.

Flashing

Flash the *-sysupgrade.bin file via the router's web interface or sysupgrade command.

Automated upgrades

The image includes luci-app-attendedsysupgrade preconfigured to use the custom Hermes ASU endpoint, enabling one-click firmware upgrades from LuCI.

Hermes ASU Worker

A Cloudflare Worker that emulates the OpenWrt ASU API, serving prebuilt firmware metadata from GitHub Releases instead of building images on demand.

Why

The official ASU service builds firmware dynamically. For a single-device setup with prebuilt images from CI, this worker provides a lightweight shim that:

  • Returns ASU-compatible JSON for LuCI's attended sysupgrade
  • Proxies firmware downloads with proper CORS headers
  • Caches metadata from GitHub Releases

Deploying

cd workers/hermes-asu
bun install
bunx wrangler deploy

Configure the metadata URL and cache TTL in wrangler.toml:

[vars]
HERMES_METADATA_URL = "https://github.com/<user>/<repo>/releases/latest/download/hermes-latest.json"
HERMES_CACHE_TTL_SECONDS = "300"

Endpoints

  • GET /health - Health check
  • GET /json/v1/overview.json - ASU overview
  • GET /api/v1/overview - LuCI-compatible overview alias
  • GET /json/v1/releases/<version>/targets/<target>/<profile>.json - Profile metadata
  • POST /api/v1/build - Request firmware (returns immediate 200 with prebuilt image)
  • GET /api/v1/build/<hash> - Poll build status
  • GET /store/<bin_dir>/<image> - Proxy firmware download

Feature toggles and customization

macOS host options

Edit hosts/akiri/options.nix:

  • Basics: hostName, userName, time.timeZone, security.sudo.touchIdAuth
  • ihtc (DPI circumvention):
    • services.ihtc.enable, services.ihtc.port, services.ihtc.patterns
  • Services:
    • services.autokbisw.enable, services.autokbisw.startOnLogin
    • services.colima.enable, services.colima.startOnLogin
  • Homebrew: homebrew.enable, homebrew.autoUpdate, homebrew.declarative
  • Window management: yabai.enable, yabai.skhd.enable, yabai.sketchybar.enable
User options

Edit userConfigurations/<user>/options.nix:

  • programs.zsh.enable
  • programs.nushell.enable
  • programs.starship.enable
  • programs.nixvim.enable
  • programs.neovide.enable
OpenWrt options

Edit hosts/hermes/default.nix:

  • Change profiles.identifyProfile for a different router
  • Modify packages.nix to add/remove OpenWrt packages
  • Adjust recovery script timeouts via uci-defaults

Notable configurations

  • Touch ID for sudo: enabled in hosts/akiri/system.nix.
  • Nix settings: flakes enabled, weekly GC (Sunday 00:00), automatic optimisation.
  • Fonts: JetBrains Mono Nerd Font, Hack Nerd Font, Curie.
  • Rosetta: ROSETTA_ADVERTISE_AVX=1 for AVX support under Rosetta.
  • Apps as .app: integrates mac-app-util to improve macOS app handling for Nix-installed apps.

Helpful shell bits (Nushell)

Defined in userConfigurations/kreato/nushell/config.nu:

  • rebuild: darwin-rebuild switch --flake .#akiri.
  • clean-gc: sudo nix-collect-garbage --delete-old.
  • shell <pkg>: nix shell helper with unfree allowed for ephemeral sessions.
  • ksh: Launches an ephemeral Fedora pod in Kubernetes with flexible flags.
  • Work profile: set WORK_PROFILE=true to use separate SSH known_hosts and Git SSH options.

License

This project is licensed under AGPL-3.0. See LICENSE.