My own NixOS configurations
- Clone this repository to any location you want.
git clone https://github.com/MaikoTan/nixos-config.git /usr/nixos-config-
Create partitions for NixOS if you haven't done so.
-
Run the following command to install NixOS.
nixos-install --option experimental-features 'nix-command flakes' --flake "/usr/nixos-config#<hostname>"- If you are not using first-time installation, run the following command to
switch to the new configuration.
- If you encounter network issues, you may also try the mirror with option
--mirror.
- If you encounter network issues, you may also try the mirror with option
nixos-rebuild switch --option experimental-features 'nix-command flakes' --flake ".#<hostname>"- Reboot your system.
reboot- Run the following command to update the system.
./switch.fishIf you have changed anything managed by dconf, make sure to run the following
command (in fish shell) to update the dconf config.
./build.fishflake.nix— Flake entry: machine definitions, overlays, devShellmachines/<hostname>/— Machine-specific configs (config.nix+ generatedhardware.nix)profiles/— Composition layer: which modules to enable per machine typemodules/— Reusable NixOS modules (option + config pattern, enabled viamaiko.*options)modules/home-manager/— User-level configuration (fish, vscode, dconf, plasma)secrets/— SOPS-encrypted secrets (age)
Secrets are managed with sops-nix using age keys.
- User key:
~/.config/sops/age/keys.txt - Host key:
/var/lib/sops-nix/age/keys.txt
Add or edit a secret:
sops secrets/<file>.yaml
# after changing recipients in .sops.yaml, rekey the file
sops updatekeys secrets/<file>.yamlReference it in a machine config (every secret must set sopsFile explicitly):
sops.secrets.mySecret = {
sopsFile = ../../secrets/<file>.yaml;
key = "my_secret_key";
};- List all generations.
nixos-rebuild list-generationsThis project is licensed under MIT License.