summaryrefslogtreecommitdiff
path: root/hostnix
AgeCommit message (Collapse)Author
2026-07-16mojo: make upgradeJoe Mou
2026-07-16mojo: Install uv, llama-cppJoe Mou
2026-04-20mojo: Obsidian w/ auto-syncJoe Mou
2026-04-20mojo: Document onActivation.cleanupJoe Mou
Sometimes seems to work with uninstall, but generally doesn't.
2026-04-15mojo: Set up sunshineJoe Mou
There appear to be some issues: - Remap Super/Alt on client - Mouse pointer disappears - Scroll not working - Letterboxing
2026-04-15mojo: Fix for fzf.vimJoe Mou
Also install fd and rg so those vim fzf commands work
2026-04-15mojo: Lazy darwin-rebuildJoe Mou
Perhaps less secure but we're running this command a whole lot.
2026-04-15mojo: Disable onActivation.cleanupJoe Mou
Every activation fails with trying to uninstall sunshine's dependencies, for some reason.
2026-04-15mojo: Basic appsJoe Mou
2026-04-15mojo: Refine Claude Code directory accessJoe Mou
Give access to .dotfiles, fix ~/src subdirectories, and check that we don't allow access to everything.
2026-04-15mojo: RefactorJoe Mou
2026-04-14mojo: Integrity check casksJoe Mou
2026-04-14mojo: Karabiner-ElementsJoe Mou
Cannot use nix-darwin because of https://github.com/nix-darwin/nix-darwin/issues/1041 Anyway since it uses kernel extensions, etc, this might be better via the cask. Since Karabiner-Elements creates a virtual device, it should be configured before LinearMouse. Unlike LinearMouse, reverse scrolling works with iPad continuity too
2026-04-13Remove old iPad from SyncthingJoe Mou
2026-04-13Add mojo to gitJoe Mou
2026-04-13Add iPad Air to SyncthingJoe Mou
2026-04-13Update app deployment scriptsJoe Mou
2026-04-13Restore grow light automations, remove SAD lampJoe Mou
2026-04-13mojo: Ghostery ad blockerJoe Mou
2026-04-13mojo: Set up bashJoe Mou
2026-04-13mojo: Install direnv & nix-direnvJoe Mou
Rollback nixpkgs for https://github.com/NixOS/nixpkgs/issues/507531
2026-04-13mojo: Claude Code sandbox-exec wrapperJoe Mou
From https://github.com/neko-kai/claude-code-sandbox
2026-04-13Homebrew with a few initial mas (App Store) appsJoe Mou
2026-04-13make upgradeJoe Mou
2026-03-17Initial nix-darwin flake for mojoJoe Mou
2026-02-04HA: Remove grow light automation, control SAD lamp with buttonJoe Mou
2026-02-04HA: Check fridge doorJoe Mou
Some other minor adjustments to entity naming, fan, and grow light.
2026-02-04Deploy cgithubJoe Mou
Use a disposable domain until thinking more about authentication.
2026-02-04Wildcard SAN for *.elmo.mou.foJoe Mou
2026-02-04cgit clone URLJoe Mou
2026-01-05nixpkgs updateJoe Mou
$ nix flake update --override-input nixpkgs github:NixOS/nixpkgs/ea156c6c3a5b67b0120f92f664853914a58d3b05 Avoid cgit issue until fix lands on stable: https://github.com/NixOS/nixpkgs/pull/477185
2026-01-05HA: Enable ZigbeeJoe Mou
2026-01-05HA: Reararnge smart plugsJoe Mou
- More reliable smart plug on panel light - SAD lamp timer
2025-12-31Configure OIDC for Home AssistantJoe Mou
Replaces unmaintained header authentication behind oauth2-proxy. Add OIDC client for Home Assistant: - Callback URLs: https://ha.mou.fo/auth/oidc/callback - Public Client To link OIDC credentials with the existing joe user, temporarily set: auth_oidc.features.automatic_user_linking = true; See https://github.com/christiaangoossens/hass-oidc-auth/blob/main/docs/configuration.md#migrating-from-ha-usernamepassword-users-to-oidc-users Must login through either: - https://ha.mou.fo/auth/oidc/welcome - https://ha.mou.fo/auth/oidc/redirect Injecting directly into the landing login page is pending https://github.com/christiaangoossens/hass-oidc-auth/issues/19
2025-12-31Replace Zitadel with Pocket IDJoe Mou
Much simpler to configure and use.
2025-12-29Simplify and document JellyfinJoe Mou
2025-12-28Add doughboyJoe Mou
2025-12-24Upgrade to NixOS 25.11Joe Mou
The auth_header Home Assistant custom component has been removed. For now we use the last package from: https://github.com/NixOS/nixpkgs/blob/7f88a8b9efaf0e08e63e3806b2b3f42fd83fde91/pkgs/servers/home-assistant/custom-components/auth-header/package.nix
2025-12-24Do not override nix.settings.build-dirJoe Mou
NixOS 25.11 contains Nix 2.30 which now builds to /nix/var/nix/builds, which is not space constrained like the previous default of /tmp. To perform the upgrade to NixOS 25.11, we first must unset our build-dir from a world writable directory. See https://github.com/nixos/nix/issues/13701
2025-12-24make upgradeJoe Mou
2025-12-24Fix HA automation for minutes instead of hoursJoe Mou
2025-12-24yakatak serviceJoe Mou
Getting the right permissions set on the socket is quite awkward. Perhaps listening on a port would have been preferable. systemd socket activation would require us to support file descriptor handoff (which would need to be changed in Nitro).
2025-12-24make upgradeJoe Mou
2025-09-02make upgrade, remove broadcom_sta WiFiJoe Mou
broadcom_sta WiFi driver is considered insecure. We weren't using WiFi anyway, so remove it. It may be possible to use Broadcom open source drivers for our BCM4360, but these may only support newer hardware. Also use allowUnfreePredicate to explicitly whitelist packages.
2025-09-02Minimal n8n serving (no HTTPS)Joe Mou
2025-09-02Avoid nixpkgs.config.packageOverridesJoe Mou
Apparently packageOverrides are deprecated by overlays. Overlays apparently can "increase eval time". If intel-vaapi-driver is a "leaf" package then we can use the overridden package instance without replacing it in nixpkgs. It seems like the only place this package should be referenced is from hardware.graphics.extraPackages, and not as a dependency of other packages. See https://discourse.nixos.org/t/overriding-a-package/59565
2025-09-02Properly set nix build-dirJoe Mou
We had been setting TMPDIR for nix-daemon, but nixos-rebuild does not use that. Use the newer build-dir setting instead. See https://github.com/NixOS/nixpkgs/issues/293114#issuecomment-2663470083
2025-09-02make upgradeJoe Mou
2025-07-01Unattended local backupsJoe Mou
Needs /var/secrets/restic to be manually provisioned. Based on ~/.dotfiles/restic/run, as a starting point. Backing up /srv/Attic is huge (100s of GBs), redundant (same hard drive), and slow (hours). It probably makes sense to mirror it instead. The repo password is stored on the same hard drive in plaintext, which means our repo is not secure at rest. This is a bigger issue with the initial setup without full disk encryption, so we choose not to address it; however, this does expose all backups whereas previously just this server was exposed. The most important remaining tasks are to mirror the restic backups remotely, and to automate on a timer.
2025-06-27Configure ytdl-subJoe Mou
Not a big fan. It's obtuse to configure, the implementation is complicated (relative to just using the yt-dlp CLI), and difficult to debug. We would probably still need some additional automation to get the file layout we want. It might be more straightforward to just write our own automation on top of yt-dlp.