This repository has been archived on 2026-07-30. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
nixos/AGENTS.md
beatzaplentyandClaude Sonnet 4.6 e62e9c9a6a
Check NixOS configurations / eval-hosts (pull_request) Successful in 10m40s
chore: full sweep — docs sync, SSH key module extraction, NFS dedup, dead code removal
Documentation fixes:
- README/AGENTS: rename tailscale-exit-node → tailscale-router, add ha-server
  build type and proxmox-ha-server-{1,2} host table rows, add baremetal to
  platform list, remove references to non-existent flake-target-refactor-spec.md
  and remove-sensetive-info-refactor.md
- docs/auto-installer.md: fix lxc-tailscale-exit-node → lxc-tailscale-router,
  add pxe-minimal to the flake outputs list
- variables.nix: fix domainControllerIp comment — IPA is the authoritative DNS
  at .253 (Pi-hole is gone), not a forwarding intermediary

Code deduplication:
- Extract duplicate SSH host-key preservation activation scripts from
  modules/platforms/lxc.nix and modules/platforms/proxmox.nix into a shared
  modules/common/preserve-ssh-host-key.nix; both platforms now import it
- Replace 8-line hand-enumerated NFS export lists in server.nix and ha-server.nix
  with a mkNfsExports helper that generates exports from vars.nfsShares — adding
  a share to variables.nix now propagates to both exporters automatically

Dead code removal:
- modules/common/configuration.nix: remove leftover NixOS skeleton comments
  (hardware-configuration import, grub lines) that were never used
- modules/docker/enable-service.nix: remove commented-out listenOptions and
  daemon.settings blocks
- hosts/server/host.nix, hosts/nix-cache/host.nix: remove #DOCKER_HOST comments

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-28 15:18:06 +10:00

2.0 KiB

AGENTS.md

Repo purpose

This repository contains flake-based NixOS configurations for Wayne's LAN servers and workstation.

The flake exposes NixOS configurations named <platform>-<buildtype> (platforms: linode, proxmox, lxc, baremetal; build types: minimal, nix-cache, server, docker, gui, pxe-boot, tailscale-router, tor-relay, ha-server), generated from modules/platforms/* and modules/build-types/* by the mkTarget function in flake.nix. Not every combination is built — pxe-boot has no linode variant, ha-server only exists on proxmox, and tor-relay only exists on lxc. See README.md for the full current target list; treat flake.nix as the source of truth since this list can drift.

Do not deploy, switch, reboot, repartition, format disks, or run destructive install commands from this repository unless explicitly asked.

Safety rules

  • Never run nixos-rebuild switch, boot, test, nixos-install, parted, mkfs, mkswap, swapon, mount, or destructive disk commands in Codex.
  • Validation work should be limited to evaluation, linting, formatting checks, and nix build --dry-run --no-link.
  • Do not add secrets, tokens, private keys, password hashes, or live credentials to the repo.
  • Treat flake.nix, Home Manager config, and Nix config files as public.
  • If you find committed tokens or hashes, flag them immediately and recommend rotation/removal.

Expected commands

Use these commands when validating changes:

bash scripts/codex-setup.sh
bash scripts/codex-maintenance.sh

With no flags, codex-maintenance.sh scopes fmt-check/statix/eval to files changed against a base ref — this is what CI runs on every push/PR. For the full sweep (every host, every package — slow; CI never runs this), use bash scripts/codex-maintenance.sh --full-check (add --dry-run for build planning on top of whichever scope is active).

Host evaluation is safe when limited to drvPath checks:

nix eval .#nixosConfigurations.<host>.config.system.build.toplevel.drvPath --raw