NixOS configurations built with Den and flake-parts for three x86_64-linux hosts:
frostmourne, palantir, and sonic. Alex is an integrated Home Manager user
on Palantir and Sonic. Frostmourne declares Alex and Niko as home-less Den users.
Home Manager is host-integrated rather than emitted as a separate output.
modules/aspects/contains concern-owned Den aspects. Profiles are thin aspects composed withincludes.modules/entities/hosts/defines the three host identity entities and their host-local details. Palantir and Sonic declare Alex as a Home Manager user; Frostmourne declares Alex and Niko without Home Manager.- Colocated
_directories hold subordinate package expressions, assets, and generated host data owned by their parent aspect. - Den has one entity system,
x86_64-linux. flake-parts derives itssystemsvalue fromconfig.den.systems.
Use native NixOS and Home Manager options. An aspect should compute a package
lexically (usually with pkgs.callPackage ./_package { }) and pass that value to
its consumer. Directory names do not create package outputs.
flake.nix is generated by flake-file, committed, and must not be edited by
hand. Aspect-owned declaration modules are authoritative for inputs and
nixConfig.
After changing a declaration, regenerate with:
nix run .#write-flakeThe generated file must be byte-identical after a second regeneration; the
exported flake-file staleness check enforces this policy. Review generated input,
cache, and follow changes before updating flake.lock. Never put secrets in a
generated option.
If the generated root is missing or cannot evaluate, restore the last committed
flake.nix or bootstrap the pinned writer, then regenerate:
nix-shell https://github.com/denful/flake-file/archive/v0.6.0.tar.gz -A flake-file.sh --run bootstrap
nix run .#write-flakeDo not enable lock pruning or flattening.
The public output policy is exact:
nixosConfigurations:frostmourne,palantir,sonicpackages.x86_64-linux:amd-debug-tools,btop,clipy,gh-fork-cleanup,hermes-link,jj-starship,kitty-same-cwd,lazyjournal,monolisa,supermaven-jj-git-shim,waldl,wallpapers,warmcam, andxurl- flake-file also exports generator packages
write-flake,write-inputs, andwrite-lock devShells.x86_64-linux.default, the x86_64-linux formatter, and checkscheck-flake-file,treefmt,deploy-schema,deploy-activate,vm-smoke-frostmourne,vm-smoke-palantir, andvm-smoke-sonic- explicit deploy nodes for the same three hosts There is no extra public package-set or output family, and no non-x86_64-linux output system.
nh os switch # build and activate the current host
nix flake update # update locked inputs
nh clean # collect garbage and optimise the store
deploy HOSTNAME # deploy an explicit remote nodeFor a first Determinate Nix migration where its cache is not already trusted:
sudo nixos-rebuild switch --flake .#HOSTNAME \
--option extra-substituters https://install.determinate.systems \
--option extra-trusted-public-keys cache.flakehub.com-3:hJuILl5sVK4iKm86JzgdXW12Y2Hwd5G07qKtHTOcDCM=Secrets remain encrypted with SOPS/age. Persistent state is opt-in through the platform aspects; disk layouts remain declarative with Disko.
Devenv and ji zsh hooks are generated with their pinned packages at build time. Their prompt-time behavior remains dynamic. Nix permits four simultaneous builds with four cores each and 32 substitutions; its daemon has CPU and IO weights of 50. These weights affect contention, not a hard resource cap.
DMS defaults to balanced on AC and power-saver on battery. Existing writable
DMS settings are preserved: select Balanced under the AC power profile in
DMS settings, equivalent to "acProfileName": "1", and retain
"batteryProfileName": "0".
Sonic uses 256 MiB background and 1 GiB foreground dirty-page thresholds, zero ratio thresholds, and a five-second writeback interval. Other hosts retain the battery aspect's writeback interval.
A desktop host selects exactly one shell aspect: desktop.noctalia (Noctalia
v5 with Noctalia Greeter) or desktop.dms (DankMaterialShell with Dank
Greeter). Switch by swapping the include in the host entity and rebuilding.
Both shells run under Hyprland and Niri; Noctalia Greeter preselects Hyprland
when the host includes it. The first rebuild onto Noctalia needs its cache
passed explicitly:
nh os switch -- --option extra-substituters https://noctalia.cachix.org \
--option extra-trusted-public-keys noctalia.cachix.org-1:pCOR47nnMEo5thcxNDtzWpOxNFQsBRglJzxWPp3dkU4=Noctalia's config.toml, Settings overrides (settings.toml), and its
Hyprland and Niri fragments live in modules/aspects/desktop/noctalia/_config/.
mutable on links them into ~/.dotfiles, so Settings changes land in the
repo; mutable off returns them to store copies, and Settings changes are
rejected until mutable mode is back on.