12 Commits

Author SHA1 Message Date
Tom Alexander
ffbd3847e7 Fix lexical binding issue loading python language server. 2026-09-13 23:47:20 -04:00
Tom Alexander
4a6cbfad67 Use lexical binding in elisp files.
This silences a warning for each of these files. Lexical binding will become the default in a future version of emacs.
2026-09-12 21:00:26 -04:00
Tom Alexander
450478cff4 I changed bhyverc to use pci slot 10 for network, so update the network interface. 2026-09-12 17:27:33 -04:00
Tom Alexander
82d460e08e Update packages. 2026-09-12 17:27:33 -04:00
Tom Alexander
24853ba6a2 Add secret for private images pulled in tekton steps. 2026-09-12 17:26:41 -04:00
Tom Alexander
f2bde9ffea Disable installing documentation. 2026-09-07 15:41:38 -04:00
Tom Alexander
0d6001d655 Add parted to debugging role on kubernetes.
This is to support expanding the storage.
2026-09-07 13:24:39 -04:00
Tom Alexander
a0e8a74906 Update packages. 2026-09-05 19:07:41 -04:00
Tom Alexander
e719948a3e Switch to quad9 for DNS.
Mullvad is shutting down their public DNS.

ref: https://mullvad.net/en/blog/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead
2026-09-05 09:46:36 -04:00
Tom Alexander
3f281f1980 Clean up nix_builder directories at the start of a build. 2026-09-03 22:21:07 -04:00
Tom Alexander
6ed4aa08f6 Add a role for mitmproxy. 2026-08-29 09:40:21 -04:00
Tom Alexander
9bfa21368b Update to Linux 7.2.
This is to pull in the drivers for the mt7927 wireless chipset in my desktop. Normally, I would keep the rest of my machines on LTS but since Linux 7 significantly changed the kernel preemption, maintaining two configs would be more trouble than it is worth.
2026-08-29 06:50:47 -04:00
50 changed files with 122 additions and 54 deletions

View File

@@ -64,6 +64,7 @@ in
./roles/media
./roles/memtest86
./roles/minimal_base
./roles/mitmproxy
./roles/network
./roles/nix_index
./roles/nix_repl
@@ -272,6 +273,7 @@ in
}
);
})
(disableTests "ada") # test failing with http url is not idempotent.
];
# This option defines the first version of NixOS you have installed on this particular machine,

View File

@@ -170,11 +170,11 @@
"rust-overlay": "rust-overlay_2"
},
"locked": {
"lastModified": 1785893730,
"narHash": "sha256-K3pjEDafWrpfC1dc14icLxx9tWx4c/dfKTeiDYoZU7Q=",
"lastModified": 1788488145,
"narHash": "sha256-s1UY+kbLtb+5ye4GnE/HKh0idUQ0iiIkMMtGI7cDRHk=",
"ref": "refs/heads/main",
"rev": "83f05b36778dd90d4e15e0d020685d9388cbaea1",
"revCount": 39,
"rev": "8b28dfb583e094f52fd6ab70c709cc1981d8853d",
"revCount": 46,
"type": "git",
"url": "https://code.fizz.buzz/talexander/nix_builder.git"
},
@@ -185,11 +185,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1787498568,
"narHash": "sha256-9i/VTdusq/+NM/tz+J1Re+ojkMB8MBf0QshnYfzHz30=",
"lastModified": 1788752844,
"narHash": "sha256-VaWGJ6+cIYN2erfSecbRV+4ljI185Ty2wUrXyvQbgOw=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "56c02bc00adcf003215cc4bd996d6efaf4cff188",
"rev": "dc5d91f840324650bac8c379428c7037a416959a",
"type": "github"
},
"original": {

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -118,6 +118,7 @@
me.lvfs.enable = true;
me.media.enable = true;
me.memtest.enable = true;
me.mitmproxy.enable = true;
me.network.enable = true;
me.nix_index.enable = true;
me.nix_repl.enable = true;

View File

@@ -111,6 +111,7 @@
me.lvfs.enable = true;
me.media.enable = true;
me.memtest.enable = true;
me.mitmproxy.enable = true;
me.network.enable = true;
me.nix_index.enable = true;
me.nix_repl.enable = true;

View File

@@ -72,5 +72,9 @@ in
git_fix_author
rsync_clone
];
# Disable installing documentation.
documentation.doc.enable = false;
documentation.nixos.enable = false;
};
}

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(setq gc-cons-threshold (* 128 1024 1024)) ;; 128MiB Increase garbage collection threshold for performance (default 800000)
;; Increase amount of data read from processes, default 4k
(when (version<= "27.0" emacs-version)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package diminish)
;; Eglot recommends pulling the latest of the standard libraries it

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
;; ========== Function to reload current file =================
(defun reload-file ()
@@ -11,10 +12,9 @@
"Run a command using the current buffer as stdin and replacing its contents if the command succeeds with the stdout from the command. This is useful for code formatters."
(let (
(stdout-buffer (generate-new-buffer "tmp-stdout" t))
(full-cmd (append '(call-process-region nil nil cmd nil stdout-buffer nil) args))
)
(unwind-protect
(let ((exit-status (eval full-cmd)))
(let ((exit-status (apply #'call-process-region nil nil cmd nil (list stdout-buffer nil) nil args)))
(if (eq exit-status 0)
(save-excursion
(replace-buffer-contents stdout-buffer)
@@ -31,10 +31,9 @@
"Run a command using the current buffer as stdin and replacing its contents if the command succeeds with the stdout from the command. This is useful for code formatters. This version only replaces the buffer contents if the command output some text."
(let (
(stdout-buffer (generate-new-buffer "tmp-stdout" t))
(full-cmd (append '(call-process-region nil nil cmd nil stdout-buffer nil) args))
)
(unwind-protect
(let ((exit-status (eval full-cmd)))
(let ((exit-status (apply #'call-process-region nil nil cmd nil (list stdout-buffer nil) nil args)))
(if (eq exit-status 0)
(if (> (buffer-size stdout-buffer) 0)
(save-excursion
@@ -55,10 +54,9 @@
(let (
(default-directory (or dir default-directory))
(stdout-buffer (generate-new-buffer "tmp-stdout" t))
(full-cmd (append '(call-process cmd nil (list stdout-buffer nil) nil) args))
)
(unwind-protect
(let ((exit-status (condition-case nil (eval full-cmd) (file-missing nil))))
(let ((exit-status (condition-case nil (apply #'call-process cmd nil (list stdout-buffer nil) nil args) (file-missing nil))))
(if (eq exit-status 0)
(progn
(with-current-buffer stdout-buffer

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
;; Add your keys here, as such
;; Disable the suspend frame hotkeys

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
;; Set theme
(load-theme 'tango-dark t)
(set-face-attribute 'default nil :background "black")

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(package-initialize)
(use-package use-package
:custom

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package eglot
;; This is an emacs built-in but we're pulling the latest version
:pin gnu

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'util-tree-sitter)
(use-package bash-ts-mode

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(use-package cmake-mode

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(defun d2-format-buffer ()
"Run prettier."
(interactive)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package dockerfile-ts-mode
:pin manual
:mode (

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(defun lua-format-buffer ()
"Run stylua."
(interactive)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package markdown-mode
:ensure t
:commands (markdown-mode gfm-mode)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package nftables-mode
:commands nftables-mode
)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'color)
(let ((bg (face-attribute 'default :background)))
(use-package org

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(require 'common-lsp)
(require 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(defun xml-fmt ()
"Run xmllint --format."
(run-command-on-buffer "xmllint" "--format" "-")

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(defun yaml-format-buffer ()
"Run prettier."
(interactive)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(use-package flymake
:pin manual
:ensure nil

View File

@@ -1,3 +1,5 @@
;; -*- lexical-binding: t; -*-
;; (add-to-list 'major-mode-remap-alist '(c-mode . c-ts-mode))
(use-package treesit
@@ -13,6 +15,8 @@
;; :custom
;; (treesit-font-lock-level 3)
(setq treesit-font-lock-level 4)
;; (setq treesit-auto-install-grammar t)
;; (setq treesit-enabled-modes t)
)
(provide 'util-tree-sitter)

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(defun my/minibuffer-delete (arg)
"When looking for files, go up an entire directory with the backspace button if theres no text after the directory."
(interactive "p")

View File

@@ -1,3 +1,4 @@
;; -*- lexical-binding: t; -*-
(add-to-list 'load-path (concat user-emacs-directory "elisp"))
(require 'base)

View File

@@ -20,7 +20,7 @@
config = lib.mkIf (config.me.firefox.enable && config.me.graphical) {
programs.firefox = {
enable = true;
package = (pkgs.wrapFirefox (pkgs.firefox-unwrapped.override { pipewireSupport = true; }) { });
package = (pkgs.wrapFirefox (pkgs.firefox-unwrapped.override { withPipewire = true; }) { });
languagePacks = [ "en-US" ];
preferences = {
# "identity.sync.tokenserver.uri": "https://ffsync.fizz.buzz/token/1.0/sync/1.5";

View File

@@ -100,6 +100,7 @@
IFS=$'\n\t'
DIR="$( cd "$( dirname "''${BASH_SOURCE[0]}" )" && pwd )"
NIX_REMOTE='local?root=/.disk/root' RUST_BACKTRACE=1 RUST_LOG=nix_builder=DEBUG ${nix_builder.packages.x86_64-linux.default}/bin/nix-builder clean --config ${./files/nix_builder.toml}
NIX_REMOTE='local?root=/.disk/root' RUST_BACKTRACE=1 RUST_LOG=nix_builder=DEBUG ${nix_builder.packages.x86_64-linux.default}/bin/nix-builder build --config ${./files/nix_builder.toml} ${builtins.concatStringsSep " " build_flags}
'';
restartIfChanged = false;

View File

@@ -14,30 +14,12 @@ let
full = {
PREEMPT_DYNAMIC = yes;
PREEMPT = yes;
PREEMPT_VOLUNTARY = lib.mkForce no;
PREEMPT_LAZY = lib.mkForce no;
PREEMPT_NONE = no;
};
lazy = {
PREEMPT_DYNAMIC = yes;
PREEMPT = no;
PREEMPT_VOLUNTARY = lib.mkForce no;
PREEMPT_LAZY = yes;
PREEMPT_NONE = no;
};
voluntary = {
PREEMPT_DYNAMIC = no;
PREEMPT = no;
PREEMPT_VOLUNTARY = yes;
PREEMPT_LAZY = lib.mkForce no;
PREEMPT_NONE = no;
};
none = {
PREEMPT_DYNAMIC = no;
PREEMPT = no;
PREEMPT_VOLUNTARY = lib.mkForce no;
PREEMPT_LAZY = lib.mkForce no;
PREEMPT_NONE = yes;
};
};
tick_hz =
@@ -99,16 +81,14 @@ let
TRANSPARENT_HUGEPAGE_MADVISE = yes;
};
};
common_config =
with lib.kernel;
{
# Google's BBRv3 TCP congestion Control
TCP_CONG_BBR = yes;
DEFAULT_BBR = yes;
};
common_config = with lib.kernel; {
# Google's BBRv3 TCP congestion Control
TCP_CONG_BBR = yes;
DEFAULT_BBR = yes;
};
flavors = {
server = lib.mkMerge [
preemption_type.none
preemption_type.lazy
tick_hz."300"
performance_governor.default
tick_rate.tickless
@@ -142,7 +122,8 @@ in
kernel.version = lib.mkOption {
type = lib.types.str;
default = "linux"; # LTS
# default = "linux"; # LTS
default = "linux_7_2"; # LTS
example = "linux_6_18";
description = "What version of the kernl should we use.";
};

View File

@@ -0,0 +1,25 @@
{
config,
lib,
pkgs,
...
}:
{
imports = [ ];
options.me = {
mitmproxy.enable = lib.mkOption {
type = lib.types.bool;
default = false;
example = true;
description = "Whether we want to install mitmproxy.";
};
};
config = lib.mkIf config.me.mitmproxy.enable {
environment.systemPackages = with pkgs; [
mitmproxy
];
};
}

View File

@@ -6,6 +6,8 @@
}:
# Alternative DNS servers:
# "194.242.2.2#doh.mullvad.net"
# "2a07:e340::2#doh.mullvad.net"
# "1.0.0.1#cloudflare-dns.com"
# "1.1.1.1#cloudflare-dns.com"
# "2606:4700:4700::1001#cloudflare-dns.com"
@@ -14,6 +16,10 @@
# "8.8.8.8#dns.google"
# "2001:4860:4860::8844#dns.google"
# "2001:4860:4860::8888#dns.google"
# "9.9.9.10#dns10.quad9.net"
# "149.112.112.10#dns10.quad9.net"
# "2620:fe::10#dns10.quad9.net"
# "2620:fe::fe:10#dns10.quad9.net"
let
patchScriptBin =
@@ -39,8 +45,10 @@ in
networking.dhcpcd.enable = lib.mkDefault false;
networking.useDHCP = lib.mkDefault false;
networking.nameservers = [
"194.242.2.2#doh.mullvad.net"
"2a07:e340::2#doh.mullvad.net"
"9.9.9.10#dns10.quad9.net"
"149.112.112.10#dns10.quad9.net"
"2620:fe::10#dns10.quad9.net"
"2620:fe::fe:10#dns10.quad9.net"
];
services.resolved = {
enable = true;

View File

@@ -64,6 +64,10 @@
};
nix.settings.auto-optimise-store = !config.me.buildingPortable;
# Disable installing documentation.
documentation.doc.enable = false;
documentation.nixos.enable = false;
environment.persistence."/persist" = lib.mkIf (config.me.mountPersistence) {
hideMounts = true;
directories = [

View File

@@ -164,11 +164,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1784120854,
"narHash": "sha256-KesHgItiZPgGX740axSiQLcIQ8D24MDqNpkKYWIek8k=",
"lastModified": 1788752844,
"narHash": "sha256-VaWGJ6+cIYN2erfSecbRV+4ljI185Ty2wUrXyvQbgOw=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "753cc8a3a87467296ddd1fa93f0cc3e81120ee46",
"rev": "dc5d91f840324650bac8c379428c7037a416959a",
"type": "github"
},
"original": {

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -20,7 +20,7 @@
config = {
networking =
let
interface = "enp0s2";
interface = "enp0s10";
in
{
# Generate with `head -c4 /dev/urandom | od -A none -t x4`

View File

@@ -134,6 +134,18 @@ let
"nix-pull-through-cache" = {
"CACHE_GET_TOKEN" = (builtins.readFile "${./secrets/nix-pull-through-cache/auth/CACHE_GET_TOKEN}");
};
"registry-credentials" =
(generate_docker_secret {
username = builtins.readFile "${./secrets/flux-system/registry-credentials/username}";
password = builtins.readFile "${./secrets/flux-system/registry-credentials/password}";
email = builtins.readFile "${./secrets/flux-system/registry-credentials/email}";
address = builtins.readFile "${./secrets/flux-system/registry-credentials/address}";
})
// {
# "__annotations" = {
# "tekton.dev/docker-0" = "https://harbor.fizz.buzz";
# };
};
};
};
encrypted_secrets = (

View File

@@ -25,6 +25,7 @@
gptfdisk # cgdisk
arp-scan # To find devices on the network
ldns # for drill
parted
];
# This can make debugging easier by rejecting packets instead of dropping them:

View File

@@ -21,7 +21,7 @@
assertions = [
{
# Kubernetes should only upgrade 1 minor version at a time, so this assert is here to prevent unwittingly jumping versions.
assertion = lib.hasPrefix "1.36." pkgs.kubernetes.version;
assertion = lib.hasPrefix "1.37." pkgs.kubernetes.version;
message = "Unexpected Kubernetes package version: ${pkgs.kubernetes.version}";
}
];