Archived
Check NixOS configurations / eval-hosts (pull_request) Successful in 10m40s
Documentation fixes:
- README/AGENTS: rename tailscale-exit-node → tailscale-router, add ha-server
build type and proxmox-ha-server-{1,2} host table rows, add baremetal to
platform list, remove references to non-existent flake-target-refactor-spec.md
and remove-sensetive-info-refactor.md
- docs/auto-installer.md: fix lxc-tailscale-exit-node → lxc-tailscale-router,
add pxe-minimal to the flake outputs list
- variables.nix: fix domainControllerIp comment — IPA is the authoritative DNS
at .253 (Pi-hole is gone), not a forwarding intermediary
Code deduplication:
- Extract duplicate SSH host-key preservation activation scripts from
modules/platforms/lxc.nix and modules/platforms/proxmox.nix into a shared
modules/common/preserve-ssh-host-key.nix; both platforms now import it
- Replace 8-line hand-enumerated NFS export lists in server.nix and ha-server.nix
with a mkNfsExports helper that generates exports from vars.nfsShares — adding
a share to variables.nix now propagates to both exporters automatically
Dead code removal:
- modules/common/configuration.nix: remove leftover NixOS skeleton comments
(hardware-configuration import, grub lines) that were never used
- modules/docker/enable-service.nix: remove commented-out listenOptions and
daemon.settings blocks
- hosts/server/host.nix, hosts/nix-cache/host.nix: remove #DOCKER_HOST comments
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
53 lines
2.0 KiB
Markdown
53 lines
2.0 KiB
Markdown
# AGENTS.md
|
|
|
|
## Repo purpose
|
|
|
|
This repository contains flake-based NixOS configurations for Wayne's LAN
|
|
servers and workstation.
|
|
|
|
The flake exposes NixOS configurations named `<platform>-<buildtype>`
|
|
(platforms: `linode`, `proxmox`, `lxc`, `baremetal`; build types: `minimal`,
|
|
`nix-cache`, `server`, `docker`, `gui`, `pxe-boot`, `tailscale-router`,
|
|
`tor-relay`, `ha-server`), generated from `modules/platforms/*` and
|
|
`modules/build-types/*` by the `mkTarget` function in `flake.nix`. Not every
|
|
combination is built — `pxe-boot` has no `linode` variant, `ha-server` only
|
|
exists on `proxmox`, and `tor-relay` only exists on `lxc`. See `README.md`
|
|
for the full current target list; treat `flake.nix` as the source of truth
|
|
since this list can drift.
|
|
|
|
Do not deploy, switch, reboot, repartition, format disks, or run destructive
|
|
install commands from this repository unless explicitly asked.
|
|
|
|
## Safety rules
|
|
|
|
- Never run `nixos-rebuild switch`, `boot`, `test`, `nixos-install`, `parted`,
|
|
`mkfs`, `mkswap`, `swapon`, `mount`, or destructive disk commands in Codex.
|
|
- Validation work should be limited to evaluation, linting, formatting checks,
|
|
and `nix build --dry-run --no-link`.
|
|
- Do not add secrets, tokens, private keys, password hashes, or live credentials
|
|
to the repo.
|
|
- Treat `flake.nix`, Home Manager config, and Nix config files as public.
|
|
- If you find committed tokens or hashes, flag them immediately and recommend
|
|
rotation/removal.
|
|
|
|
## Expected commands
|
|
|
|
Use these commands when validating changes:
|
|
|
|
```bash
|
|
bash scripts/codex-setup.sh
|
|
bash scripts/codex-maintenance.sh
|
|
```
|
|
|
|
With no flags, `codex-maintenance.sh` scopes fmt-check/statix/eval to files
|
|
changed against a base ref — this is what CI runs on every push/PR. For the
|
|
full sweep (every host, every package — slow; CI never runs this), use
|
|
`bash scripts/codex-maintenance.sh --full-check` (add `--dry-run` for build
|
|
planning on top of whichever scope is active).
|
|
|
|
Host evaluation is safe when limited to drvPath checks:
|
|
|
|
```bash
|
|
nix eval .#nixosConfigurations.<host>.config.system.build.toplevel.drvPath --raw
|
|
```
|