Compare commits

10 Commits
Author SHA1 Message Date
poslop 1422f3ce5c Merge remote-tracking branch 'origin/dev' 2026-08-28 14:31:46 +00:00
poslop a6bea2a0e6 Merge branch 'dev' of https://git.archfox.org/poslop/rice-flakes into dev 2026-08-28 14:29:58 +00:00
poslop cce057cb6c agenix: use stdenv.hostPlatform.system, fixes eval warning 2026-08-28 14:29:46 +00:00
poslop 89b08bad3f Merge branch 'dev' of https://git.archfox.org/poslop/rice-flakes into dev 2026-08-28 09:23:09 -05:00
poslop 4f777a9b96 hermes: glm-5.3-flash delegation, drop auxiliary block; flake.lock bump (live system state) 2026-08-28 09:23:08 -05:00
poslop 041a8a36af remove write test file 2026-08-28 14:22:26 +00:00
poslop f885cd0e55 Merge branch 'dev' of https://git.archfox.org/poslop/rice-flakes into dev 2026-08-28 14:22:06 +00:00
poslop 5e0bcc53ff write test 2026-08-28 09:21:45 -05:00
poslop 3d15148c77 roles: add role-based host composition in flake
- mkHost now takes a role list, roles resolve to ./roles/<name>.nix
- roles/core.nix = shared baseline (modules/)
- roles/k3s-server.nix = core + k3s (goyplex-vm)
- roles/hermes.nix = core + hermes (hermes-vm)
- host configuration.nix trimmed to hardware + boot + stateVersion
- optional hosts/<name>/custom.nix loads last for per-host overrides
- new hosts: one flake line + hosts/<name>/ dir
2026-08-28 14:13:43 +00:00
poslop 35b065ec49 Merge pull request 'Dev' (#2) from dev into master
Reviewed-on: #2
2026-07-23 12:48:53 -05:00
11 changed files with 92 additions and 52 deletions
Generated
+24 -24
View File
@@ -41,11 +41,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464219, "lastModified": 1787400831,
"narHash": "sha256-WKqWL8r7CyTDYueTr2ffJ9ya50dellv6IR1JX5PghDY=", "narHash": "sha256-H3MEkFDZf+UH+QrVgW8TdKrssPFltF8fBg/rh0J1zIc=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "aquamarine", "repo": "aquamarine",
"rev": "f3d1804205e8158c15595cdda1b566f93349ffae", "rev": "7ce889cb78b97979b83a4648509fc3ef405c3286",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -124,11 +124,11 @@
"uv2nix": "uv2nix" "uv2nix": "uv2nix"
}, },
"locked": { "locked": {
"lastModified": 1787314587, "lastModified": 1787852122,
"narHash": "sha256-oeFJlEoFybqKkbuWT4mW8PRauusjt3y44ZJXAcA7TPY=", "narHash": "sha256-QFOvSx7laGYIIPq+LNNEyrqxfSmXOrv+4Y80nKbXkjA=",
"owner": "NousResearch", "owner": "NousResearch",
"repo": "hermes-agent", "repo": "hermes-agent",
"rev": "fcbd1076a93841fa88855acce810e342a5b78101", "rev": "0dfba37b11ff2ca908ae2df85b55f4f4c9b7fd8b",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -144,11 +144,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1787194407, "lastModified": 1787500880,
"narHash": "sha256-hMgbN6InoW+S5G/cqGrVwHUmOJcGIT/yUg1Xe6y7t8Q=", "narHash": "sha256-UrAlku7KST0DT+j1bdVGYI8tCz23PWL88uGMer3IZ2U=",
"owner": "feel-co", "owner": "feel-co",
"repo": "hjem", "repo": "hjem",
"rev": "7cd7f1c567beaf5527781e0b51647a98acde54e6", "rev": "d248f0e4f7abd6e1f0eb9ace778dd7928481943e",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -297,11 +297,11 @@
"xdph": "xdph" "xdph": "xdph"
}, },
"locked": { "locked": {
"lastModified": 1787311583, "lastModified": 1787842129,
"narHash": "sha256-EXpfUX7oLzqwd+m/T1TvH/rHwnTNtZL+TZ5wiCwklMo=", "narHash": "sha256-+C4MYYZsT+JdgZj70g7ERYm4zjJRwRnwy7o1QHPW5eg=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "Hyprland", "repo": "Hyprland",
"rev": "0f97a22d1172d8fbd77834ec932383ed18110edb", "rev": "3b1aa6be7b8d672c7180ea616f9eca1992e227c3",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -474,11 +474,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464080, "lastModified": 1786903207,
"narHash": "sha256-W1hxvumEM57yV+QwsZ4QdAHEqOkr7e4S8VAkLX60qDE=", "narHash": "sha256-QTwMqLLONRhv9iz6CVeuX6BqQNQCIqI8hL/cPYlR/24=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "hyprutils", "repo": "hyprutils",
"rev": "c157fe1e3092b980cc69315a6631f89aff09dcce", "rev": "6cf50415e06dc6bd9f1252f1b745eac6b4a1cc39",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -575,11 +575,11 @@
}, },
"nixpkgs_3": { "nixpkgs_3": {
"locked": { "locked": {
"lastModified": 1786247143, "lastModified": 1787360063,
"narHash": "sha256-8S3Kcxs7D4UtxJxSJZz0m14CGhuW0MxfrIwJxeGWGnQ=", "narHash": "sha256-dt4WdcvsA8/RCe+VZZwqU0X+XMM3wBbGCWA0/sFWzGo=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "279b4a8275f032c566576b3f181fa0f27197f588", "rev": "2c423e03bbafcff28bfadc6781a4a8257f205cb5",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -591,11 +591,11 @@
}, },
"nixpkgs_4": { "nixpkgs_4": {
"locked": { "locked": {
"lastModified": 1787135253, "lastModified": 1787736819,
"narHash": "sha256-RD2kNWCG+Bjo6h+JVjWVNntZs2GtRoeY2xHjts/FNkA=", "narHash": "sha256-cV5xEJJK3BvhU8rEd4mC9UsmDi5qscv/kzGPhBRC5WA=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "ffb3c9b700e759be2ef13237c9d8f953b32a1e46", "rev": "9fbb54b33e91ee4ca368e35a78e0613c720600b3",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -791,11 +791,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464334, "lastModified": 1786988229,
"narHash": "sha256-/TBQT5rhBB2Dm4HoZzhGDaCwYmRTs3W3DPhMXFWc/BU=", "narHash": "sha256-frEFLVRj8xXvBBDs44IRiqHo6R2PxsRpluygL7abjjI=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "xdg-desktop-portal-hyprland", "repo": "xdg-desktop-portal-hyprland",
"rev": "9f0e9ff02739cd538d39bd706422dc50e9ca60dd", "rev": "59d429bf45aed4e2209043c0c36565ad8e2859a5",
"type": "github" "type": "github"
}, },
"original": { "original": {
+21 -7
View File
@@ -27,26 +27,40 @@
let let
system = "x86_64-linux"; system = "x86_64-linux";
username = "poslop"; username = "poslop";
lib = nixpkgs.lib;
# mkHost <hostname> <role list>
# roles resolve to ./roles/<name>.nix; list entries may also be
# inline attrsets or paths, which load after (and override) roles.
# hosts/<host>/custom.nix, if present, always loads last.
mkHost = mkHost =
host: modules: name: roles:
nixpkgs.lib.nixosSystem { nixpkgs.lib.nixosSystem {
modules = [ { nixpkgs.hostPlatform = system; } ] ++ modules; modules =
[ { nixpkgs.hostPlatform = system; } ]
++ [ ./hosts/${name}/configuration.nix ]
++ map (
role:
if builtins.isString role then ./roles/${role}.nix else role
) roles
++ lib.optional (builtins.pathExists ./hosts/${name}/custom.nix)
./hosts/${name}/custom.nix;
specialArgs = { specialArgs = {
inherit inherit
self self
inputs inputs
username username
host
; ;
host = name;
}; };
}; };
in in
{ {
nixosConfigurations = { nixosConfigurations = {
nixos-vm2 = mkHost "nixos-vm2" [ ./hosts/nixos-vm2/configuration.nix ]; nixos-vm2 = mkHost "nixos-vm2" [ "core" ];
qemu-vm = mkHost "qemu-vm" [ ./hosts/qemu-vm/configuration.nix ]; qemu-vm = mkHost "qemu-vm" [ "core" ];
goyplex-vm = mkHost "goyplex-vm" [ ./hosts/goyplex-vm/configuration.nix ]; goyplex-vm = mkHost "goyplex-vm" [ "k3s-server" ];
hermes-vm = mkHost "hermes-vm" [ ./hosts/hermes-vm/configuration.nix ]; hermes-vm = mkHost "hermes-vm" [ "hermes" ];
}; };
}; };
} }
+4 -3
View File
@@ -1,10 +1,11 @@
{ pkgs, ... }: {
pkgs,
...
}:
{ {
imports = [ imports = [
./hardware-configuration.nix ./hardware-configuration.nix
../../modules
../../modules/k3s/k3s.nix
]; ];
boot.loader.systemd-boot.enable = true; boot.loader.systemd-boot.enable = true;
+4 -3
View File
@@ -1,10 +1,11 @@
{ pkgs, ... }: {
pkgs,
...
}:
{ {
imports = [ imports = [
./hardware-configuration.nix ./hardware-configuration.nix
../../modules/core
../../modules/hermes
]; ];
boot.loader.systemd-boot.enable = true; boot.loader.systemd-boot.enable = true;
-1
View File
@@ -5,7 +5,6 @@
{ {
imports = [ imports = [
./hardware-configuration.nix ./hardware-configuration.nix
../../modules
]; ];
boot.loader.grub.enable = true; boot.loader.grub.enable = true;
-1
View File
@@ -5,7 +5,6 @@
{ {
imports = [ imports = [
./hardware-configuration.nix ./hardware-configuration.nix
../../modules
]; ];
boot.loader.grub.enable = true; boot.loader.grub.enable = true;
+18 -12
View File
@@ -1,7 +1,6 @@
{ {
inputs, inputs,
config, config,
lib,
pkgs, pkgs,
... ...
}: }:
@@ -42,7 +41,17 @@
mcp_reload_confirm = "false"; mcp_reload_confirm = "false";
}; };
gateway = {
multiplex_profiles = true;
};
delegation = {
model = "z-ai/glm-5.3-flash";
provider = "nous";
};
memory = { memory = {
provider = "holographic";
memory_enabled = true; memory_enabled = true;
user_profile_enabled = true; user_profile_enabled = true;
}; };
@@ -51,11 +60,6 @@
credits_notices = true; credits_notices = true;
}; };
delegation = {
model = "us.anthropic.claude-sonnet-5";
provider = "bedrock";
};
discord = { discord = {
group_sessions_per_user = false; group_sessions_per_user = false;
reactions = false; reactions = false;
@@ -63,12 +67,13 @@
}; };
}; };
# Hermes serve (desktop app JSON-RPC backend, headless)
# Port 9120 avoids conflict with the gateway's API server on 9119.
systemd.services.hermes-serve = { systemd.services.hermes-serve = {
description = "Hermes Agent Serve (desktop remote backend)"; description = "Hermes Agent Serve (desktop remote backend)";
wantedBy = [ "multi-user.target" ]; wantedBy = [ "multi-user.target" ];
after = [ "hermes-agent.service" "network-online.target" ]; after = [
"hermes-agent.service"
"network-online.target"
];
wants = [ "network-online.target" ]; wants = [ "network-online.target" ];
requires = [ "hermes-agent.service" ]; requires = [ "hermes-agent.service" ];
@@ -90,12 +95,13 @@
''; '';
}; };
# Hermes dashboard (web UI for browser access)
# Port 9121, full web dashboard with login page.
systemd.services.hermes-dashboard = { systemd.services.hermes-dashboard = {
description = "Hermes Agent Dashboard (web UI)"; description = "Hermes Agent Dashboard (web UI)";
wantedBy = [ "multi-user.target" ]; wantedBy = [ "multi-user.target" ];
after = [ "hermes-agent.service" "network-online.target" ]; after = [
"hermes-agent.service"
"network-online.target"
];
wants = [ "network-online.target" ]; wants = [ "network-online.target" ];
requires = [ "hermes-agent.service" ]; requires = [ "hermes-agent.service" ];
+1 -1
View File
@@ -10,6 +10,6 @@
age.secrets."hermes-env".file = ./hermes-env.age; age.secrets."hermes-env".file = ./hermes-env.age;
hjem.users.${username}.packages = with pkgs; [ hjem.users.${username}.packages = with pkgs; [
inputs.agenix.packages."${system}".default inputs.agenix.packages."${pkgs.stdenv.hostPlatform.system}".default
]; ];
} }
+6
View File
@@ -0,0 +1,6 @@
{
# shared baseline: core system + home manager config
imports = [
../modules
];
}
+7
View File
@@ -0,0 +1,7 @@
{
# hermes agent host: core + hermes container + secrets
imports = [
./core.nix
../modules/hermes
];
}
+7
View File
@@ -0,0 +1,7 @@
{
# k3s server node (goyplex-vm): k3s + manifests + firewall
imports = [
./core.nix
../modules/k3s/k3s.nix
];
}