My unified nix flake for all configuration management.
- Nix 60%
- Rust 16.5%
- Shell 9.2%
- Python 8.1%
- TypeScript 2.6%
- Other 3.6%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
dragon's inline Collie setup (user unit, managed .env, linger) moves into lib/modules/nixos/collie.nix so a second NixOS host can run the same bridge. dragon sets `phoneFrontDoor`, which emits the PUBLIC_HOSTS / ALLOWED_ORIGINS / PUBLIC_URL lines a lead needs. beefcake leaves it unset, because a member publishes no front door. It binds its tailnet ip and opens 8787 on tailscale0 only. Collie's Linux release binary from install.sh is not an option on beefcake: it is built for a generic glibc layout, and the flake package already pins the version dragon runs, so the crew stays level by construction. Linger for daniel on beefcake: the existing comment there warns against lingering session-less service users. daniel is not one of those; the herdr server already runs under daniel's live user manager. The headscale ACL is deliberately unchanged. dragon reaches beefcake:* already, and beefcake only needs to reach the lead once, to enroll, which an `ssh -R` tunnel covers, as it did for the work Mac. Tested: dragon's evaluated collie.service text is byte-identical before and after, and its .env carries the same settings, so dragon's switch does not restart its bridge. beefcake-guest evaluates with the member .env, 8787 in tailscale0's allowed ports, and daniel lingering. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JN999mSVBbHUyyC2SVvN9d |
||
| .forgejo/workflows | ||
| .helix | ||
| dotfiles | ||
| issues | ||
| lib | ||
| packages | ||
| prototypes/beefcake-impermanence | ||
| secrets | ||
| .envrc | ||
| .gitignore | ||
| .sops.yaml | ||
| AGENTS.md | ||
| CLAUDE.md | ||
| flake.lock | ||
| flake.nix | ||
| readme.md | ||
| run-claude-sandbox.sh | ||