Resolve all statix and nixpkgs-fmt warnings repo-wide
Check NixOS configurations / eval-hosts (push) Failing after 11m17s

Zero W20 (repeated attribute keys), W10 (empty { ... }: variadic
pattern, use _: instead), and W04 (a = x.a instead of inherit)
warnings remain anywhere in the tree, and nixpkgs-fmt --check is
clean on all 46 .nix files.

Repeated-key merges go as deep as statix actually flags per file
(e.g. boot.loader.* nested under boot.loader = { ... } once the
outer boot.* merge exposed it as its own repeat) — every merge is a
pure attribute-path restructuring with no value changes, verified by
comparing config.system.build.toplevel.drvPath before/after for a
representative host per changed module plus a full 19-host + 4-package
eval sweep.

One indentation slip caught and fixed during this pass: nesting
modules/installer/common.nix's environment.etc."auto-install.sh".text
under an environment = { ... } block initially normalized the
script's shebang/set line indentation, which actually changes the
rendered file (Nix's '' string dedent treats it as real content, not
cosmetic whitespace) — reproduced the original's exact indentation
and reverified the rendered script is byte-identical to before.

modules/services/zfs/auto-mount-volumes.nix picked up formatting too;
worth noting it isn't imported by anything in this flake at all.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01La55Nsss8jZ7ZuzUV9mfot
This commit is contained in:
2026-07-20 03:47:42 +10:00
co-authored by Claude Sonnet 5
parent 0f7ab6fe7f
commit 9bfd804f7a
24 changed files with 367 additions and 314 deletions
+2 -2
View File
@@ -1,6 +1,6 @@
{ ... }:
_:
{
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = true;
}
}
+38 -25
View File
@@ -19,23 +19,47 @@
boot.loader.grub.useOSProber = true;
services.xserver.enable = true;
services.xserver.displayManager.lightdm.enable = true;
services.xserver.desktopManager.cinnamon.enable = true;
services = {
xserver = {
enable = true;
services.xserver.xkb = {
layout = "au";
variant = "";
displayManager = {
lightdm.enable = true;
sessionCommands = ''
eval $(gnome-keyring-daemon --start --components=secrets,ssh)
export SSH_AUTH_SOCK
'';
};
desktopManager.cinnamon.enable = true;
xkb = {
layout = "au";
variant = "";
};
};
printing.enable = true;
pipewire = {
enable = true;
alsa.enable = true;
alsa.support32Bit = true;
pulse.enable = true;
};
xrdp = {
enable = true;
defaultWindowManager = "cinnamon-session";
openFirewall = true;
};
gnome.gnome-keyring.enable = true;
};
services.printing.enable = true;
security.rtkit.enable = true;
services.pipewire = {
enable = true;
alsa.enable = true;
alsa.support32Bit = true;
pulse.enable = true;
security = {
rtkit.enable = true;
pam.services.login.enableGnomeKeyring = true;
};
# The networkmanager group only exists when NM is actually enabled — the
@@ -45,16 +69,5 @@
programs.firefox.enable = true;
services.xrdp.enable = true;
services.xrdp.defaultWindowManager = "cinnamon-session";
services.xrdp.openFirewall = true;
nixpkgs.config.allowUnfree = true;
services.gnome.gnome-keyring.enable = true;
security.pam.services.login.enableGnomeKeyring = true;
services.xserver.displayManager.sessionCommands = ''
eval $(gnome-keyring-daemon --start --components=secrets,ssh)
export SSH_AUTH_SOCK
'';
}
+22 -20
View File
@@ -95,28 +95,32 @@ in
ipxe
];
services.nginx = {
enable = true;
services = {
nginx = {
enable = true;
virtualHosts."pxe-boot" = {
default = true;
root = httpRoot;
locations."/" = {
extraConfig = ''
autoindex on;
'';
virtualHosts."pxe-boot" = {
default = true;
root = httpRoot;
locations."/" = {
extraConfig = ''
autoindex on;
'';
};
};
};
};
# TFTP is only used to deliver the initial iPXE bootloader. After iPXE
# starts, all further assets are fetched via nginx over HTTP.
services.atftpd = {
enable = true;
root = tftpRoot;
extraOptions = [
"--verbose=5"
];
# TFTP is only used to deliver the initial iPXE bootloader. After iPXE
# starts, all further assets are fetched via nginx over HTTP.
atftpd = {
enable = true;
root = tftpRoot;
extraOptions = [
"--verbose=5"
];
};
openssh.settings.PermitRootLogin = "yes";
};
systemd.tmpfiles.rules = [
@@ -149,8 +153,6 @@ in
};
};
services.openssh.settings.PermitRootLogin = "yes";
networking.firewall.allowedTCPPorts = [ 80 ];
networking.firewall.allowedUDPPorts = [ 69 ];
}
+17 -11
View File
@@ -33,17 +33,23 @@
# or docs/ for the sops workflow). hashedPassword/hashedPasswordFile need
# neededForUsers so they're available before the normal secret-activation
# step, since user creation happens very early in boot.
sops.defaultSopsFile = ../../secrets/common.yaml;
sops.secrets."root-hashedPassword".neededForUsers = true;
sops.secrets."nixos-hashedPassword".neededForUsers = true;
sops.secrets."nix-github-token" = { };
sops = {
defaultSopsFile = ../../secrets/common.yaml;
secrets = {
"root-hashedPassword".neededForUsers = true;
"nixos-hashedPassword".neededForUsers = true;
"nix-github-token" = { };
};
# nix.conf doesn't support a *File-style option for access-tokens, so the
# token is rendered into a runtime-only file (never touches the Nix store)
# and pulled in via nix.conf's native !include directive.
templates."nix-github-token.conf".content = ''
access-tokens = github.com=${config.sops.placeholder."nix-github-token"}
'';
};
# nix.conf doesn't support a *File-style option for access-tokens, so the
# token is rendered into a runtime-only file (never touches the Nix store)
# and pulled in via nix.conf's native !include directive.
sops.templates."nix-github-token.conf".content = ''
access-tokens = github.com=${config.sops.placeholder."nix-github-token"}
'';
nix.extraOptions = ''
!include ${config.sops.templates."nix-github-token.conf".path}
'';
@@ -62,7 +68,7 @@
];
hashedPasswordFile = config.sops.secrets."nixos-hashedPassword".path;
openssh.authorizedKeys.keys = [
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCq/Q5LvIXlZwO2kdeAN5nLGZ59nZB7JHYMEszHxmNtGMzv1lM31jiPNsr0z2EKVZhE7OOfa2IF9rhWYD7JUA9G0yzdZ4WTXFNGVVOJoOVH6vAF3XCxoVilOEwTc7h2Wiy+rzd0B28/3spffzQQWJhY6GRQVa8j+6xAGF60Fcvl1vLosYT9Bn2ZbK4TCWOwAn2jqXIieGpZdn/UNZbGOeKRiCvhktDfMAzuQzN/9jMu/oF4pkPn2X1UrsQdNlvp0Ci8md612MozIpncQJyAF1ADhunr3sMx0isUXiqD29R5DS4TftpekqLNLak+zcxFa8N7DcRNp3DcKfJvyTkwQrR4r+b7lFLYOLHLagSso9CzeW/paAS2q9I5SBm/2DtE1diLLg2jZikYcstsu/G5RgvbzbKqjiaMwTdXC3AMvDxQrs7U5pDRZFzoofG3cpODbTm+uy3m0kP70z0M1K45UbDG0p+itnTu9x40JbQEgefbx38AItNvAIx1A8HO4I1VX28= wayne@stream"
vars.adminSshKey
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICMJhrfFayLBG+gWtO6oAvgambw5nWWgztiTFEaaaVRH debian@surface"
];
};
+19 -16
View File
@@ -10,9 +10,25 @@ in
./aliases.nix
];
home.username = vars.primaryUser;
home.homeDirectory = "/home/${vars.primaryUser}";
home.stateVersion = "25.11"; # match your NixOS stateVersion
home = {
username = vars.primaryUser;
homeDirectory = "/home/${vars.primaryUser}";
stateVersion = "25.11"; # match your NixOS stateVersion
# Optional: packages
packages = with pkgs; [
git
vim
tmux
nano
sshfs
];
# Optional: set environment vars
sessionVariables = {
EDITOR = "nano";
};
};
programs.home-manager.enable = true; # mandatory to activate HM
@@ -23,19 +39,6 @@ in
# modules/common/configuration.nix instead (covers the daemon for every
# user, not just this one).
# Optional: packages
home.packages = with pkgs; [
git
vim
tmux
nano
sshfs
];
# Optional: set environment vars
home.sessionVariables = {
EDITOR = "nano";
};
# systemd.user.services.mount-proxmox-iso = {
# Unit = {
# Description = "Mount Proxmox ISO dir via SSHFS";
+2 -2
View File
@@ -1,4 +1,4 @@
{ ... }:
_:
{
i18n.defaultLocale = "en_AU.UTF-8";
@@ -15,4 +15,4 @@
LC_TIME = "en_AU.UTF-8";
};
}
}
+2 -2
View File
@@ -1,4 +1,4 @@
{ ... }:
_:
{
disko.devices = {
@@ -57,4 +57,4 @@
};
};
};
}
}
+17 -17
View File
@@ -1,23 +1,23 @@
{ pkgs, ... }:
{
# virtualisation.docker.enable = true;
# virtualisation.docker.enable = true;
virtualisation.docker = {
enable = true;
package = pkgs.docker;
# listenOptions = [
# "unix:///var/run/docker.sock"
# "tcp://0.0.0.0:2375"
#];
enable = true;
package = pkgs.docker;
# listenOptions = [
# "unix:///var/run/docker.sock"
# "tcp://0.0.0.0:2375"
#];
# daemon.settings = {
# metrics-addr = "0.0.0.0:9323";
# experimental = true;
# };
};
# daemon.settings = {
# metrics-addr = "0.0.0.0:9323";
# experimental = true;
# };
};
environment.systemPackages = with pkgs; [
docker-compose
docker-buildx
];
}
environment.systemPackages = with pkgs; [
docker-compose
docker-buildx
];
}
+51 -49
View File
@@ -1,63 +1,65 @@
{ config, lib, pkgs, vars, ... }:
{
fileSystems."/mnt/docker/config" = {
device = "${vars.nfsServerHost}:${vars.storageRoot}/docker/config";
fsType = "nfs";
fileSystems = {
"/mnt/docker/config" = {
device = "${vars.nfsServerHost}:${vars.storageRoot}/docker/config";
fsType = "nfs";
options = [
"nfsvers=4.2"
"_netdev"
"x-systemd.automount"
"noatime"
];
};
options = [
"nfsvers=4.2"
"_netdev"
"x-systemd.automount"
"noatime"
];
};
fileSystems."/mnt/docker/databases" = {
device = "${vars.nfsServerHost}:${vars.storageRoot}/docker/databases";
fsType = "nfs";
"/mnt/docker/databases" = {
device = "${vars.nfsServerHost}:${vars.storageRoot}/docker/databases";
fsType = "nfs";
options = [
"nfsvers=4.2"
"_netdev"
"x-systemd.automount"
"noatime"
];
};
options = [
"nfsvers=4.2"
"_netdev"
"x-systemd.automount"
"noatime"
];
};
fileSystems."/mnt/docker/volumes" = {
device = "${vars.nfsServerHost}:${vars.storageRoot}/docker/volumes";
fsType = "nfs";
"/mnt/docker/volumes" = {
device = "${vars.nfsServerHost}:${vars.storageRoot}/docker/volumes";
fsType = "nfs";
options = [
"nfsvers=4.2"
"_netdev"
"x-systemd.automount"
"noatime"
];
};
options = [
"nfsvers=4.2"
"_netdev"
"x-systemd.automount"
"noatime"
];
};
fileSystems."/mnt/nextcloud-data" = {
device = "${vars.nfsServerHost}:${vars.storageRoot}/docker/nextcloud-data";
fsType = "nfs";
"/mnt/nextcloud-data" = {
device = "${vars.nfsServerHost}:${vars.storageRoot}/docker/nextcloud-data";
fsType = "nfs";
options = [
"nfsvers=4.2"
"_netdev"
"x-systemd.automount"
"noatime"
];
};
options = [
"nfsvers=4.2"
"_netdev"
"x-systemd.automount"
"noatime"
];
};
fileSystems."/mnt/raspi-backup" = {
device = "${vars.nfsServerHost}:${vars.storageRoot}/raspi/volumes";
fsType = "nfs";
"/mnt/raspi-backup" = {
device = "${vars.nfsServerHost}:${vars.storageRoot}/raspi/volumes";
fsType = "nfs";
options = [
"nfsvers=4.2"
"_netdev"
"x-systemd.automount"
"noatime"
];
options = [
"nfsvers=4.2"
"_netdev"
"x-systemd.automount"
"noatime"
];
};
};
}
+28 -22
View File
@@ -5,36 +5,42 @@
{
imports =
[ (modulesPath + "/profiles/qemu-guest.nix")
[
(modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [ "virtio_pci" "virtio_scsi" "ahci" "sd_mod" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
boot.loader.grub.device = "/dev/sda";
boot = {
initrd.availableKernelModules = [ "virtio_pci" "virtio_scsi" "ahci" "sd_mod" ];
initrd.kernelModules = [ ];
kernelModules = [ ];
extraModulePackages = [ ];
# Enable LISH
kernelParams = [ "console=ttyS0,19200n8" ];
loader = {
grub = {
device = "/dev/sda";
extraConfig = ''
serial --speed=19200 --unit=0 --word=8 --parity=no --stop=1;
terminal_input serial;
terminal_output serial;
'';
forceInstall = true;
# device = "nodev";
};
timeout = 10;
};
};
fileSystems."/" =
{ device = "/dev/sda";
{
device = "/dev/sda";
fsType = "ext4";
};
swapDevices =
[ { device = "/dev/sdb"; }
];
# Enable LISH
boot.kernelParams = [ "console=ttyS0,19200n8" ];
boot.loader.grub.extraConfig = ''
serial --speed=19200 --unit=0 --word=8 --parity=no --stop=1;
terminal_input serial;
terminal_output serial;
'';
boot.loader.grub.forceInstall = true;
# boot.loader.grub.device = "nodev";
boot.loader.timeout = 10;
[{ device = "/dev/sdb"; }];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
@@ -5,13 +5,16 @@
{
imports =
[ (modulesPath + "/profiles/qemu-guest.nix")
[
(modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-amd" ];
boot.extraModulePackages = [ ];
boot = {
initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
initrd.kernelModules = [ ];
kernelModules = [ "kvm-amd" ];
extraModulePackages = [ ];
};
# boot.loader.grub.device = "/dev/sda2"; # or "nodev" for efi only
# fileSystems."/" =
+17 -15
View File
@@ -5,22 +5,24 @@
# sudo install -d -m 0700 /root/.ssh
# sudo install -m 0600 ./nixremote /root/.ssh/nixremote
# sudo ssh -i /root/.ssh/nixremote nixremote@nix-cache nix-store --version
nix.distributedBuilds = true;
nix = {
distributedBuilds = true;
nix.buildMachines = [
{
hostName = vars.nixCacheHost;
sshUser = vars.remoteBuilderUser;
sshKey = "/root/.ssh/${vars.remoteBuilderUser}";
system = pkgs.stdenv.hostPlatform.system;
maxJobs = 4;
speedFactor = 2;
supportedFeatures = [ "nixos-test" "benchmark" "big-parallel" "kvm" ];
}
];
buildMachines = [
{
hostName = vars.nixCacheHost;
sshUser = vars.remoteBuilderUser;
sshKey = "/root/.ssh/${vars.remoteBuilderUser}";
inherit (pkgs.stdenv.hostPlatform) system;
maxJobs = 4;
speedFactor = 2;
supportedFeatures = [ "nixos-test" "benchmark" "big-parallel" "kvm" ];
}
];
nix.settings = {
builders-use-substitutes = true;
max-jobs = "auto";
settings = {
builders-use-substitutes = true;
max-jobs = "auto";
};
};
}
+14 -12
View File
@@ -9,19 +9,23 @@
# sudo chmod 0600 /etc/nix/cache-priv.pem
# sudo chmod 0644 /etc/nix/cache-pub.pem
# cat /etc/nix/cache-pub.pem
services.nix-serve = {
enable = true;
secretKeyFile = "/etc/nix/cache-priv.pem";
};
services = {
nix-serve = {
enable = true;
secretKeyFile = "/etc/nix/cache-priv.pem";
};
services.nginx = {
enable = true;
recommendedProxySettings = true;
virtualHosts.${vars.nixCacheHost} = {
locations."/" = {
proxyPass = "http://${config.services.nix-serve.bindAddress}:${toString config.services.nix-serve.port}";
nginx = {
enable = true;
recommendedProxySettings = true;
virtualHosts.${vars.nixCacheHost} = {
locations."/" = {
proxyPass = "http://${config.services.nix-serve.bindAddress}:${toString config.services.nix-serve.port}";
};
};
};
openssh.enable = true;
};
networking.firewall.allowedTCPPorts = [ 80 ];
@@ -40,8 +44,6 @@
openssh.authorizedKeys.keys = vars.remoteBuilderAuthorizedKeys;
};
services.openssh.enable = true;
nix.settings = {
trusted-users = [ "root" vars.remoteBuilderUser ];
experimental-features = [ "nix-command" "flakes" ];
+28 -22
View File
@@ -1,30 +1,36 @@
{ lib, ... }:
{
boot.isContainer = true;
boot = {
isContainer = true;
boot.loader.grub.enable = false;
boot.loader.systemd-boot.enable = false;
loader = {
grub.enable = false;
systemd-boot.enable = false;
# LXC containers share the host kernel — Proxmox starts them by exec'ing
# /sbin/init directly, no bootloader/initrd involved. Without this, that
# file doesn't correctly launch the current generation, so even a
# correctly-installed system can fail to come up after reboot.
boot.loader.initScript.enable = true;
# LXC containers share the host kernel — Proxmox starts them by exec'ing
# /sbin/init directly, no bootloader/initrd involved. Without this, that
# file doesn't correctly launch the current generation, so even a
# correctly-installed system can fail to come up after reboot.
initScript.enable = true;
};
};
# boot.isContainer disables services.udev (see nixpkgs'
# virtualisation/container-config.nix), and NetworkManager depends on a
# running udevd to enumerate/classify devices. That leaves NM unable to
# reliably manage the container's veth interface, which is what broke
# DHCP-hostname registration in Pi-hole. systemd-networkd talks to the
# kernel over rtnetlink directly and doesn't have that dependency.
networking.networkmanager.enable = lib.mkForce false;
networking.useNetworkd = true;
networking = {
# boot.isContainer disables services.udev (see nixpkgs'
# virtualisation/container-config.nix), and NetworkManager depends on a
# running udevd to enumerate/classify devices. That leaves NM unable to
# reliably manage the container's veth interface, which is what broke
# DHCP-hostname registration in Pi-hole. systemd-networkd talks to the
# kernel over rtnetlink directly and doesn't have that dependency.
networkmanager.enable = lib.mkForce false;
useNetworkd = true;
# container-config.nix also defaults this to true, which assumes a
# systemd-nspawn-style host bind-mount of /etc/resolv.conf. Real Proxmox
# LXC doesn't do that (nixpkgs' own virtualisation/proxmox-lxc.nix module
# forces this false for the same reason), so leaving it true silently
# breaks DNS instead of falling back to networkd/DHCP-provided servers.
networking.useHostResolvConf = lib.mkForce false;
# container-config.nix also defaults this to true, which assumes a
# systemd-nspawn-style host bind-mount of /etc/resolv.conf. Real Proxmox
# LXC doesn't do that (nixpkgs' own virtualisation/proxmox-lxc.nix module
# forces this false for the same reason), so leaving it true silently
# breaks DNS instead of falling back to networkd/DHCP-provided servers.
useHostResolvConf = lib.mkForce false;
};
}
+5 -5
View File
@@ -1,5 +1,5 @@
{ ... }:
{
services.rpcbind.enable = true;
}
_:
{
services.rpcbind.enable = true;
}
+9 -9
View File
@@ -1,12 +1,12 @@
{ pkgs, boot, ... }:
{
boot.postBootCommands = ''
echo "=== STARTING ZPOOL IMPORT ==="
${pkgs.zfs_unstable}/bin/zpool import -a -N -d /dev/disk/by-path
${pkgs.zfs_unstable}/bin/zpool status
${pkgs.zfs_unstable}/bin/zfs mount -a
${pkgs.zfs_unstable}/bin/zfs list
echo "=== ZPOOL IMPORT COMPLETE ==="
'';
}
boot.postBootCommands = ''
echo "=== STARTING ZPOOL IMPORT ==="
${pkgs.zfs_unstable}/bin/zpool import -a -N -d /dev/disk/by-path
${pkgs.zfs_unstable}/bin/zpool status
${pkgs.zfs_unstable}/bin/zfs mount -a
${pkgs.zfs_unstable}/bin/zfs list
echo "=== ZPOOL IMPORT COMPLETE ==="
'';
}
+14 -9
View File
@@ -1,16 +1,21 @@
{ pkgs, ... }:
{
boot.supportedFilesystems = [ "zfs" ];
boot.zfs.forceImportRoot = false;
boot.zfs.package = pkgs.zfs_unstable;
services.zfs = {
{
boot = {
supportedFilesystems = [ "zfs" ];
zfs = {
forceImportRoot = false;
package = pkgs.zfs_unstable;
devNodes = "/dev/disk/by-id";
};
};
services.zfs = {
autoScrub.enable = true;
autoSnapshot.enable = true;
trim.enable = true;
};
#systemd.services.zfs-import-cache.enable = true;
systemd.services.zfs-mount.enable = true;
boot.zfs.devNodes = "/dev/disk/by-id";
}
#systemd.services.zfs-import-cache.enable = true;
systemd.services.zfs-mount.enable = true;
}
+3 -3
View File
@@ -1,5 +1,5 @@
{ ... }:
_:
{
services.tailscale.enable = true;
}
services.tailscale.enable = true;
}
+4 -4
View File
@@ -1,7 +1,7 @@
{ ... }:
_:
{
services.logrotate = {
services.logrotate = {
enable = true;
settings = {
@@ -15,6 +15,6 @@
copytruncate = true;
};
};
};
};
}
}