this repository contains the nixOS and home-manager configuration for my systems.
- nixOS and home-manager configurations for three hosts:
bastion: my desktop and primary workstationvoyager: my laptopquasar: my home server
- feature-based configuration through den aspects
baseprovides shared system and user configuration.workstationadds the graphical desktop, applications, audio, gaming, and related services.serveradds the homelab services used byquasar.
- remote deployments through deploy-rs
- secret management through sops-nix and age
- CI through odu, omnix, github actions, and cachix
- custom packages, modules, services, scripts, and nix library functions
the workstation configuration uses niri, noctalia, fish, neovim, foot, firefox nightly, and tailscale.
modules/features: shared, workstation, server, network, GPU, and AI aspectsmodules/hosts: host definitions, hardware reports, and file-system configurationmodules/users: user aspects and user-specific configurationpackages: custom flake packageslib: nix functions used by the configurationsecrets: sops-nix encrypted files
flake-file generates flake.nix from declarations next to the modules that use them. import-tree loads the modules and packages.
show 62 packages
| package | version | description | upstream |
|---|---|---|---|
betterbird |
153.1.0esr-bb7 |
Fine-tuned version of Mozilla Thunderbird | source |
codebase-memory-mcp |
0.10.8 |
MCP server that builds and queries a semantic graph of your codebase | source |
cua-driver |
0.23.2 |
Cross-platform MCP server for computer-use automation | source |
cyber-mux |
0.5.0 |
Cross-multiplexer pane control for AI-agent tooling | source |
docker-axi |
0-unstable-2026-07-09 |
Agent-facing Docker CLI for safe, token-efficient workflows | source |
gh-axi |
0.1.35 |
GitHub CLI wrapper optimized for autonomous agents | source |
gws-axi |
0.22.0 |
Agent-ergonomic CLI for Google Workspace | source |
himalaya-tui |
0.1.0-unstable-2026-08-16 |
TUI to manage emails | source |
input-custom |
1.2 |
Input fonts with configurable selection, spacing, and letter forms | source |
kagi-mcp |
1.0.6 |
MCP server for Kagi search and summarization | source |
karakeep-cli |
0.33.2 |
Command-line interface for Karakeep | source |
karakeep-mcp |
0.33.1 |
MCP server for Karakeep | source |
kubernetes-axi |
0-unstable-2026-07-11 |
Agent-facing Kubernetes CLI for safe, token-efficient workflows | source |
mcp-remote |
0.8.3 |
Remote proxy for Model Context Protocol clients | source |
minicava |
0-unstable-2023-01-28 |
A miniature cava sound visualizer | source |
moondeck-buddy |
1.9.2 |
Helper to work with moonlight on a steamdeck | source |
moshi |
0.3.16 |
Daemon and CLI that bridges AI coding agents to the Moshi mobile app | source |
nix-inspect |
unversioned |
lists the nix store packages represented in the current PATH | — |
nostalgy |
5.0.5 |
Keyboard-oriented message filing and folder navigation for Thunderbird | source |
orca |
1.4.193 |
ADE for working with a fleet of parallel coding agents | source |
papra-cli |
0.2.5 |
Command-line interface for the Papra document management platform | source |
paseo |
0.7.0 |
Control AI coding agents from the command line | source |
pg-axi |
0.1.2 |
Agent-facing PostgreSQL CLI for safe, token-efficient workflows | source |
pi-acp |
0.0.33 |
ACP adapter for the pi coding agent | source |
pitty |
0.5.20 |
OpenTUI frontend for the Pi coding agent | source |
plex-pass |
1.43.3.10896-cb3ebc72d |
Media library streaming server | source |
plex-pass-raw |
1.43.3.10896-cb3ebc72d |
Media library streaming server | source |
portop |
0.0.5 |
TUI for inspecting and controlling processes that use network ports | source |
reboot-to-windows |
1.5 |
desktop launcher that reboots directly into windows | source |
repowise |
0.47.0 |
Codebase intelligence layer for AI coding agents | source |
secretspec |
0.19.1 |
Declarative secrets, every environment, any provider | source |
strava-mcp |
1.2.1 |
MCP server for the Strava API | source |
super-productivity-mcp |
1.6.0 |
MCP server for managing Super Productivity through AI assistants | source |
sysdvr |
6.3 |
Nintendo Switch game streaming client | source |
tbkeys-lite |
2.4.3 |
Custom Thunderbird keybindings with managed storage support | source |
voxtype-full |
1.0.1 |
Push-to-talk voice-to-text for Wayland | source |
workspace-mcp |
1.25.2 |
Google Workspace MCP server and CLI | source |
wt-herdr |
0-unstable-2026-06-14 |
herdr agent orchestration for worktrunk worktrees | source |
show 7 cockpit packages
| package | version | description | upstream |
|---|---|---|---|
cockpit-benchmark |
2.1.3 |
Cockpit UI for benchmarking storage | source |
cockpit-docker |
0-unstable-2024-03-02 |
Cockpit UI for docker containers | source |
cockpit-file-sharing |
4.6.1-2 |
Cockpit UI for managing shares | source |
cockpit-machines |
356 |
Cockpit UI for virtual machines | source |
cockpit-podman |
129 |
Cockpit UI for podman containers | source |
cockpit-tailscale |
0.0.6 |
Cockpit UI for tailscale | source |
cockpit-zfs-manager |
0-unstable-2024-01-09 |
Cockpit UI for managing ZFS | source |
show 17 home assistant packages
| package | version | description | upstream |
|---|---|---|---|
home-assistant-components-bermuda |
0.8.7 |
Bermuda Bluetooth/BLE Triangulation / Trilateration for HomeAssistant | source |
home-assistant-components-browser-mod |
3.2.2 |
A Home Assistant integration to turn your browser into a controllable entity and media player | source |
home-assistant-components-dwains-dashboard |
3.10.0 |
An fully auto generating Home Assistant UI dashboard for desktop, tablet and mobile by Dwains for desktop, tablet, mobile | source |
home-assistant-components-iphonedetect |
2.5.0 |
A custom component for Home Assistant to detect iPhones connected to local LAN, even if the phone is in deep sleep | source |
home-assistant-components-node-red |
4.2.3 |
Companion Component for node-red-contrib-home-assistant-websocket to help integrate Node-RED with Home Assistant Core | source |
home-assistant-components-pirate-weather |
1.9.2 |
Replacement for the default Dark Sky Home Assistant integration using Pirate Weather | source |
home-assistant-components-spotcast |
4.0.1 |
Home assistant custom component to start Spotify playback on an idle chromecast device as well as control spotify connect devices | source |
home-assistant-components-tuya-local |
2026.8.1 |
Local support for Tuya devices in Home Assistant | source |
home-assistant-components-var |
0.15.5 |
A custom Home Assistant component for declaring and setting generic variable entities dynamically. | source |
home-assistant-lovelace-bubble-card |
3.3.0 |
Bubble Card is a minimalist card collection for Home Assistant with a nice pop-up touch. | source |
home-assistant-lovelace-card-tools |
11 |
A collection of tools for other lovelace plugins to use | source |
home-assistant-lovelace-config-template-card |
1.3.6 |
Templatable Lovelace Configurations | source |
home-assistant-lovelace-custom-brand-icons |
2026.08.5 |
Custom brand icons for Home Assistant | source |
home-assistant-lovelace-ha-firemote |
4.1.9 |
Apple TV, Amazon Fire TV, Fire streaming stick, Chromecast, NVIDIA Shield, onn., Roku, Xiaomi Mi, and Android TV remote control card for Home Assistant | source |
home-assistant-lovelace-horizon-card |
1.5.3 |
Sun Card successor: Visualize the position of the Sun over the horizon. | source |
home-assistant-lovelace-layout-card |
2.4.7 |
Get more control over the placement of lovelace cards. | source |
home-assistant-lovelace-waze-travel-time |
0-unstable-2020-05-15 |
Home Assistant Lovelace card for Waze Travel Time Sensor | source |
probably not as-is. this configuration matches my hardware, network, services, and preferences.
you can still use its aspects, modules, and packages as examples for your own configuration.
the flake's devShell provides the repository tools and the nrs rebuild alias.
# rebuild the current host
nrs
# rebuild a named host
nh os switch .#bastion
# deploy a host through deploy-rs
nix run .#deploy quasar
# run the local CI pipeline
nix run .#ci
# format the repository
nix fmt
# regenerate flake.nix after a flake-file declaration changes
nix run .#write-flake
# regenerate noctalia's config after making changes via the ui
nix run .#write-noctaliathis repository uses sops-nix and age for deployment secrets.
the SOPS rules encrypt secrets for the required user, yubikey, host, and github actions recipients.
these screenshots show the current niri desktop as of august 2026.


