12 Commits
Author SHA1 Message Date
m3ta-chiron 7adfc8d808 chore: updates 2026-08-02 14:07:24 +02:00
m3ta-chiron 858ed2000e fix: LLM-Agents overlay 2026-08-02 09:45:21 +02:00
m3ta-chiron ef421306dd chore: flake update 2026-08-01 11:06:19 +02:00
m3ta-chiron 58fecf72df feat: migrate host Hyprland overrides to Lua 2026-08-01 10:53:09 +02:00
m3ta-chiron 4b65a6c3b1 chore: flake update 2026-07-30 14:31:49 +02:00
m3ta-chiron 43ce336675 +qmd 2026-07-30 06:46:23 +02:00
m3ta-chiron 673a1908d2 chore: flake update 2026-07-25 14:54:22 +02:00
m3ta-chiron e761d91ab5 chore: update + fix pnpm upstream bug 2026-07-10 15:19:44 +02:00
m3ta-chiron 4d1c4a859b chore: flake update 2026-07-07 19:49:53 +02:00
m3ta-chiron 08c0773472 chore: update 2026-07-05 18:42:20 +02:00
m3ta-chiron 02773fcc0b flake update 2026-07-03 08:28:30 +02:00
m3ta-chiron 8041f5306e hermes rollback because of matrix gateway problem 2026-06-27 12:01:52 +02:00
20 changed files with 623 additions and 737 deletions
+46 -2
View File
@@ -533,6 +533,17 @@
},
"path": "skills/changelog"
},
"crunch-jobs": {
"entry": "skills/crunch-jobs/SKILL.md",
"licenseFiles": [],
"metadata": {
"description": "Use when: (1) The user asks to be reminded at a specific time, (2) Schedule recurring notifications, (3) Set up AI-powered scheduled jobs (summarize, review, report), (4) Run custom pipeline scripts on a schedule with voice output. Triggers: remind me, erinnere mich, schedule, cron, daily, weekly, täglich, jeden Montag, crunch, talk at, notify me at, voice reminder.",
"name": "crunch-jobs",
"requires": [],
"tags": []
},
"path": "skills/crunch-jobs"
},
"doc-translator": {
"entry": "skills/doc-translator/SKILL.md",
"licenseFiles": [],
@@ -555,6 +566,17 @@
},
"path": "skills/excalidraw"
},
"m3ta-brain": {
"entry": "skills/m3ta-brain/SKILL.md",
"licenseFiles": [],
"metadata": {
"description": "Shared Obsidian vault for human-agent collaboration. Use when: (1) Loading project context at session start (auto-recall), (2) Writing session summaries, decisions, project updates, or learning notes, (3) Searching for past decisions or project state, (4) Running nightly/weekly digest passes, (5) Creating or updating person profiles, (6) Any reference to 'the vault', 'shared brain', 'our context', 'what did we decide'. Triggers: m3ta-brain, shared brain, vault, session summary, decision note, project update, memory candidate, brain vault, auto-recall, digest, nightly pass.",
"name": "m3ta-brain",
"requires": [],
"tags": []
},
"path": "skills/m3ta-brain"
},
"mem0-memory": {
"entry": "skills/mem0-memory/SKILL.md",
"licenseFiles": [],
@@ -643,6 +665,17 @@
},
"path": "skills/reflection"
},
"shared-brain-vault": {
"entry": "skills/shared-brain-vault/SKILL.md",
"licenseFiles": [],
"metadata": {
"description": "Build and maintain a Git-synced Obsidian vault as shared working memory between user and AI agents. Use when: (1) Writing session summaries or project updates, (2) Recording decisions or learnings, (3) Adding people/profiles to the vault, (4) Populating or restructuring the vault, (5) Setting up multi-agent vault access, (6) Answering 'what did we decide' or 'where do we stand on X'. Triggers: 'shared brain', 'm3ta-brain', 'session summary', 'vault update', 'decision note', 'project status', 'what did we decide'.",
"name": "shared-brain-vault",
"requires": [],
"tags": []
},
"path": "skills/shared-brain-vault"
},
"skill-creator": {
"entry": "skills/skill-creator/SKILL.md",
"licenseFiles": [],
@@ -665,6 +698,17 @@
},
"path": "skills/systematic-debugging"
},
"voice-notify": {
"entry": "skills/voice-notify/SKILL.md",
"licenseFiles": [],
"metadata": {
"description": "Use when: (1) A long-running task (build, test, migration, cruncher job) completes, (2) The user asks to be notified audibly, (3) An agent finishes delegated work and should announce results, (4) Important errors or completions need immediate attention. Triggers: talk, voice, notify, audio, abbrechen, notify me, let me know when done, cruncher, job complete.",
"name": "voice-notify",
"requires": [],
"tags": []
},
"path": "skills/voice-notify"
},
"xlsx": {
"entry": "skills/xlsx/SKILL.md",
"licenseFiles": [],
@@ -679,9 +723,9 @@
},
"tools": {}
},
"narHash": "sha256:640f5c15e9124526564a5438952c3231d9fa3cbab6a4e6b1cecdf4cd280c7847",
"narHash": "sha256:c119e6197eb556c9c00a13a88d2e8f42d740c724262b2b0e2ac6fb05456fe621",
"ref": null,
"rev": "920c00313ae242bd93275c30131b9ab1e52ee2fb",
"rev": "83284d752d2ac325d4bf3ab7b38acad1c2fffe3a",
"root": ".",
"type": "git",
"url": "https://code.m3ta.dev/m3tam3re/AGENTS",
Generated
+267 -361
View File
File diff suppressed because it is too large Load Diff
+9 -11
View File
@@ -17,12 +17,16 @@
};
nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable";
nixpkgs-stable.url = "github:nixos/nixpkgs/nixos-25.11";
nixpkgs-45570c2.url = "github:nixos/nixpkgs/45570c299dc2b63c8c574c4cd77f0b92f7e2766e";
nixpkgs-locked.url = "github:nixos/nixpkgs/2744d988fa116fc6d46cdfa3d1c936d0abd7d121";
nixpkgs-9e58ed7.url = "github:nixos/nixpkgs/9e58ed7ba759d81c98f033b7f5eba21ca68f53b0";
# nixpkgs-45570c2.url = "github:nixos/nixpkgs/45570c299dc2b63c8c574c4cd77f0b92f7e2766e";
# nixpkgs-locked.url = "github:nixos/nixpkgs/2744d988fa116fc6d46cdfa3d1c936d0abd7d121";
# nixpkgs-9e58ed7.url = "github:nixos/nixpkgs/9e58ed7ba759d81c98f033b7f5eba21ca68f53b0";
nixpkgs-master.url = "github:nixos/nixpkgs/master";
m3ta-nixpkgs.url = "git+ssh://gitea@code.m3ta.dev/m3tam3re/nixpkgs";
m3ta-nixpkgs = {
url = "git+ssh://gitea@code.m3ta.dev/m3tam3re/nixpkgs";
# url = "path:/home/m3tam3re/p/NIX/nixpkgs";
};
llm-agents.url = "github:numtide/llm-agents.nix";
nur = {
@@ -47,12 +51,7 @@
inputs.nixpkgs.follows = "nixpkgs";
};
hermes-agent.url = "github:NousResearch/hermes-agent/v2026.6.19";
rustfs = {
url = "github:rustfs/rustfs-flake";
inputs.nixpkgs.follows = "nixpkgs";
};
hermes-agent.url = "github:NousResearch/hermes-agent/v2026.7.20";
};
outputs = {
@@ -105,7 +104,6 @@
inputs.disko.nixosModules.disko
agenix.nixosModules.default
m3ta-nixpkgs.nixosModules.default
inputs.rustfs.nixosModules.rustfs
];
};
m3-kratos = nixpkgs.lib.nixosSystem {
+5 -8
View File
@@ -34,12 +34,12 @@
#outputs.overlays.additions
#outputs.overlays.modifications
outputs.overlays.stable-packages
outputs.overlays.locked-packages
outputs.overlays.pinned-packages
# outputs.overlays.locked-packages
# outputs.overlays.pinned-packages
outputs.overlays.master-packages
inputs.m3ta-nixpkgs.overlays.default
inputs.m3ta-nixpkgs.overlays.modifications
# inputs.m3ta-nixpkgs.overlays.modifications
(outputs.lib.mkLlmAgentsOverlay system)
# You can also add overlays exported from other flakes:
# neovim-nightly-overlay.overlays.default
@@ -68,11 +68,8 @@
"m3tam3re"
]; # Set users that are allowed to use the flake command
};
gc = {
automatic = true;
dates = "weekly";
options = "--delete-older-than 30d";
};
# Garbage collection is handled by programs.nh.clean on each host.
# Keep nix.gc.automatic disabled to avoid dueling GC timers.
optimise.automatic = true;
registry =
(lib.mapAttrs (_: flake: {inherit flake;}))
+92 -20
View File
@@ -7,7 +7,20 @@
lib,
...
}:
with lib; {
with lib; let
lua = lib.generators.mkLuaInline;
startupCommand = command: {
_args = [
"hyprland.start"
(lua ''
function()
hl.exec_cmd(${builtins.toJSON command})
end
'')
];
};
in {
config = mkMerge [
# ── XDG / MIME defaults ──
{
@@ -41,28 +54,87 @@ with lib; {
wayland.windowManager.hyprland = {
enable = true;
settings = {
exec-once = ["tuxedo-backlight"];
on = [
(startupCommand "tuxedo-backlight")
];
monitor = [
"eDP-1,preferred,0x0,1.25"
"HDMI-A-1,1920x1080@120,2560x0,1"
{
output = "eDP-1";
mode = "preferred";
position = "0x0";
scale = 1.25;
}
{
output = "HDMI-A-1";
mode = "1920x1080@120";
position = "2560x0";
scale = 1;
}
];
workspace = [
"1, monitor:eDP-1, default:true"
"2, monitor:eDP-1"
"3, monitor:eDP-1"
"4, monitor:HDMI-A-1"
"5, monitor:HDMI-A-1,border:false,rounding:false"
"6, monitor:HDMI-A-1"
workspace_rule = [
{
workspace = "1";
monitor = "eDP-1";
default = true;
}
{
workspace = "2";
monitor = "eDP-1";
}
{
workspace = "3";
monitor = "eDP-1";
}
{
workspace = "4";
monitor = "HDMI-A-1";
}
{
workspace = "5";
monitor = "HDMI-A-1";
no_border = true;
no_rounding = true;
}
{
workspace = "6";
monitor = "HDMI-A-1";
}
];
windowrule = [
"match:class dev.zed.Zed, workspace 1"
"match:class Msty, workspace 1"
"match:class ^(com.obsproject.Studio)$, workspace 2"
"match:class ^(brave-browser)$, workspace 4, opacity 1.0"
"match:class ^(vivaldi-stable)$, workspace 4, opacity 1.0"
"match:class ^steam_app_\\d+$, fullscreen on"
"match:class ^steam_app_\\d+$, workspace 5"
"match:class ^steam_app_\\d+$, idle_inhibit focus"
window_rule = [
{
match.class = "dev.zed.Zed";
workspace = "1";
}
{
match.class = "Msty";
workspace = "1";
}
{
match.class = "^(com.obsproject.Studio)$";
workspace = "2";
}
{
match.class = "^(brave-browser)$";
workspace = "4";
opacity = "1.0";
}
{
match.class = "^(vivaldi-stable)$";
workspace = "4";
opacity = "1.0";
}
{
match.class = "^steam_app_\\d+$";
fullscreen = true;
}
{
match.class = "^steam_app_\\d+$";
workspace = "5";
}
{
match.class = "^steam_app_\\d+$";
idle_inhibit = "focus";
}
];
};
};
+1 -2
View File
@@ -2,7 +2,6 @@
imports = [
./containers
./greetd.nix
./hermes-agent.nix
./netbird.nix
#./n8n.nix
./mem0.nix
@@ -30,7 +29,7 @@
gvfs.enable = true;
trezord.enable = true;
gnome.gnome-keyring.enable = true;
qdrant.enable = true;
# qdrant.enable = true;
# qdrant = {
# enable = true;
# settings = {
-195
View File
@@ -1,195 +0,0 @@
{config, ...}: let
# Default ElevenLabs voice: Bella (German-capable female)
elevenlabsVoiceId = "hpp4J3VqNfWAUOO0d1Us";
in {
services.hermes-agent = {
enable = true;
addToSystemPackages = true;
# Secrets via agenix
environmentFiles = [config.age.secrets."hermes-env".path];
# Non-secret environment variables
environment = {
GLM_BASE_URL = "https://api.z.ai/api/coding/paas/v4/";
};
settings = {
# ── Model ──────────────────────────────────────────────────────────
model = {
default = "gpt-5.5";
provider = "openai-codex";
};
fallback_providers = [
{
provider = "zai";
model = "glm-5.1";
}
{
provider = "minimax";
model = "MiniMax-M2.7";
}
];
credential_pool_strategies = {
zai = "fill_first";
};
toolsets = ["all"];
# ── Agent ──────────────────────────────────────────────────────────
agent = {
max_turns = 90;
gateway_timeout = 1800;
tool_use_enforcement = "auto";
};
# ── Terminal ───────────────────────────────────────────────────────
terminal = {
backend = "ssh";
modal_mode = "auto";
cwd = ".";
timeout = 180;
persistent_shell = true;
};
# ── Browser ────────────────────────────────────────────────────────
browser = {
inactivity_timeout = 120;
command_timeout = 30;
cloud_provider = "local";
};
# ── Checkpoints / Compression ──────────────────────────────────────
checkpoints = {
enabled = true;
max_snapshots = 50;
};
file_read_max_chars = 100000;
compression = {
enabled = true;
threshold = 0.5;
target_ratio = 0.2;
protect_last_n = 20;
};
# ── Display ────────────────────────────────────────────────────────
display = {
compact = false;
personality = "kawaii";
resume_display = "full";
busy_input_mode = "interrupt";
inline_diffs = true;
skin = "default";
tool_progress = "all";
};
# ── TTS / STT / Voice ──────────────────────────────────────────────
tts = {
provider = "elevenlabs";
elevenlabs = {
voice_id = elevenlabsVoiceId;
model_id = "eleven_multilingual_v2";
};
};
stt = {
enabled = true;
provider = "local";
local = {model = "base";};
};
voice = {
record_key = "ctrl+b";
max_recording_seconds = 120;
silence_threshold = 200;
silence_duration = 3.0;
};
# ── Memory ─────────────────────────────────────────────────────────
memory = {
memory_enabled = true;
user_profile_enabled = true;
memory_char_limit = 2200;
user_char_limit = 1375;
};
# ── Delegation ─────────────────────────────────────────────────────
delegation = {
max_iterations = 50;
};
# ── Discord ────────────────────────────────────────────────────────
discord = {
require_mention = true;
auto_thread = true;
reactions = true;
};
# ── Approvals / Security ───────────────────────────────────────────
approvals = {
mode = "manual";
timeout = 60;
};
security = {
redact_secrets = true;
tirith_enabled = true;
tirith_fail_open = true;
};
# ── Cron / Session ─────────────────────────────────────────────────
cron = {wrap_response = true;};
session_reset = {
mode = "both";
idle_minutes = 1440;
at_hour = 4;
};
# ── Web ────────────────────────────────────────────────────────────
web = {backend = "exa";};
# ── Platform Toolsets ──────────────────────────────────────────────
platform_toolsets = {
cli = [
"browser"
"clarify"
"code_execution"
"cronjob"
"delegation"
"file"
"image_gen"
"memory"
"session_search"
"skills"
"terminal"
"todo"
"tts"
"vision"
"web"
];
telegram = [
"browser"
"clarify"
"code_execution"
"cronjob"
"delegation"
"file"
"image_gen"
"memory"
"session_search"
"skills"
"terminal"
"todo"
"tts"
"vision"
"web"
];
};
};
};
}
+1 -2
View File
@@ -18,8 +18,7 @@
kestra-env = {file = ../../secrets/kestra-env.age;};
littlelink-m3tam3re = {file = ../../secrets/littlelink-m3tam3re.age;};
minio-root-cred = {file = ../../secrets/minio-root-cred.age;};
rustfs-access-key = {file = ../../secrets/rustfs-access-key.age;};
rustfs-secret-key = {file = ../../secrets/rustfs-secret-key.age;};
rustfs-env = {file = ../../secrets/rustfs-env.age;};
n8n-env = {file = ../../secrets/n8n-env.age;};
netbird-auth-secret = {
file = ../../secrets/netbird-auth-secret.age;
+10 -13
View File
@@ -6,21 +6,18 @@
}: {
services.rustfs = {
enable = true;
package = inputs.rustfs.packages.${pkgs.stdenv.hostPlatform.system}.default;
environmentFile = config.age.secrets.rustfs-env.path;
settings = {
# Reuse existing MinIO data directory
RUSTFS_VOLUMES = "/var/storage/s3";
# Reuse existing MinIO data directory
volumes = "/var/storage/s3";
# Keep same ports as MinIO to avoid changing Traefik and client configs
RUSTFS_ADDRESS = ":3008";
RUSTFS_CONSOLE_ENABLE = "true";
RUSTFS_CONSOLE_ADDRESS = ":3007";
# Keep same ports as MinIO to avoid changing Traefik and client configs
address = ":3008";
consoleEnable = true;
consoleAddress = ":3007";
# Credentials via agenix
accessKeyFile = config.age.secrets.rustfs-access-key.path;
secretKeyFile = config.age.secrets.rustfs-secret-key.path;
logLevel = "info";
RUST_LOG = "info";
};
};
# Traefik configuration — same routes as before
@@ -79,6 +79,7 @@ in {
tea
nix
python3Minimal
qmd
uv
zellij
];
+5 -2
View File
@@ -1,7 +1,11 @@
# Edit this configuration file to define what should be installed on
# your system. Help is available in the configuration.nix(5) man page, on
# https://search.nixos.org/options and in the NixOS manual (`nixos-help`).
{pkgs, ...}: {
{
config,
pkgs,
...
}: {
imports = [
# Include the results of the hardware scan.
./hardware-configuration.nix
@@ -15,7 +19,6 @@
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = true;
boot.initrd.kernelModules = ["amdgpu"];
boot.kernelPackages = pkgs.linuxPackages_7_0;
services.xserver.videoDrivers = ["amdgpu"];
security.polkit.enable = true;
security.pam.services.gdm.enableGnomeKeyring = true;
+86 -30
View File
@@ -7,7 +7,14 @@
lib,
...
}:
with lib; {
with lib; let
mkEnvVar = name: value: {
_args = [
name
value
];
};
in {
imports = [
];
@@ -47,40 +54,89 @@ with lib; {
enable = true;
settings = {
monitor = [
"DP-1,2560x1440@144,0x0,1"
"DP-2,2560x1440@144,2560x0,1"
{
output = "DP-1";
mode = "2560x1440@144";
position = "0x0";
scale = 1;
}
{
output = "DP-2";
mode = "2560x1440@144";
position = "2560x0";
scale = 1;
}
];
workspace = [
"1, monitor:DP-1, default:true"
"2, monitor:DP-1"
"3, monitor:DP-1"
"4, monitor:DP-2"
"5, monitor:DP-2"
"6, monitor:DP-2"
"7, monitor:DP-2"
workspace_rule = [
{
workspace = "1";
monitor = "DP-1";
default = true;
}
{
workspace = "2";
monitor = "DP-1";
}
{
workspace = "3";
monitor = "DP-1";
}
{
workspace = "4";
monitor = "DP-2";
}
{
workspace = "5";
monitor = "DP-2";
}
{
workspace = "6";
monitor = "DP-2";
}
{
workspace = "7";
monitor = "DP-2";
}
];
# m3ta-home sets QT_QPA_PLATFORMTHEME=gtk3 globally for Hyprland.
# m3ta-home sets QT_QPA_PLATFORMTHEME to gtk3 globally for Hyprland.
# ksnip crashes with duplicate GDK type registration under that Qt GTK
# platform theme, so use qtct for Qt apps on this host instead.
env = mkForce [
"XCURSOR_SIZE,32"
"HYPRCURSOR_THEME,Bibata-Modern-Ice"
"WLR_NO_HARDWARE_CURSORS,1"
"XDG_CURRENT_DESKTOP,Hyprland"
"XDG_SESSION_TYPE,wayland"
"XDG_SESSION_DESKTOP,Hyprland"
"XKB_DEFAULT_LAYOUT,de"
"NIXOS_OZONE_WL,1"
"QT_QPA_PLATFORM,wayland;xcb"
"QT_QPA_PLATFORMTHEME,qt5ct"
"QT_QPA_PLATFORMTHEME_QT6,qt6ct"
"env" = mkForce [
(mkEnvVar "XCURSOR_SIZE" "32")
(mkEnvVar "HYPRCURSOR_THEME" "Bibata-Modern-Ice")
(mkEnvVar "WLR_NO_HARDWARE_CURSORS" "1")
(mkEnvVar "XDG_CURRENT_DESKTOP" "Hyprland")
(mkEnvVar "XDG_SESSION_TYPE" "wayland")
(mkEnvVar "XDG_SESSION_DESKTOP" "Hyprland")
(mkEnvVar "XKB_DEFAULT_LAYOUT" "de")
(mkEnvVar "NIXOS_OZONE_WL" "1")
(mkEnvVar "QT_QPA_PLATFORM" "wayland;xcb")
(mkEnvVar "QT_QPA_PLATFORMTHEME" "qt5ct")
(mkEnvVar "QT_QPA_PLATFORMTHEME_QT6" "qt6ct")
];
windowrule = [
"match:class dev.zed.Zed, workspace 1"
"match:class ^(com.obsproject.Studio)$, workspace 2"
"match:class ^(brave-browser)$, workspace 4, opacity 1.0"
"match:class ^(vivaldi-stable)$, workspace 4, opacity 1.0"
"match:class ^steam_app_\\d+$, idle_inhibit focus"
window_rule = [
{
match.class = "dev.zed.Zed";
workspace = "1";
}
{
match.class = "^(com.obsproject.Studio)$";
workspace = "2";
}
{
match.class = "^(brave-browser)$";
workspace = "4";
opacity = "1.0";
}
{
match.class = "^(vivaldi-stable)$";
workspace = "4";
opacity = "1.0";
}
{
match.class = "^steam_app_\\d+$";
idle_inhibit = "focus";
}
];
};
};
+4 -4
View File
@@ -1,9 +1,9 @@
{pkgs, ...}: {
imports = [
./containers
./greetd.nix
# ./greetd.nix
./mem0.nix
# ./n8n.nix
./n8n.nix
./netbird.nix
./postgres.nix
./sound.nix
@@ -20,7 +20,7 @@
gvfs.enable = true;
trezord.enable = true;
gnome.gnome-keyring.enable = true;
qdrant.enable = true;
# qdrant.enable = true;
avahi = {
enable = true;
nssmdns4 = true;
@@ -30,6 +30,6 @@
userServices = true;
};
};
# displayManager.gdm.enable = true;
displayManager.gdm.enable = true;
};
}
+1 -1
View File
@@ -1,6 +1,6 @@
{lib, ...}: {
services.n8n = {
enable = false;
enable = true;
openFirewall = true;
environment = {
N8N_SECURE_COOKIE = "false";
+68 -21
View File
@@ -7,7 +7,7 @@
# This one contains whatever you want to overlay
# You can change versions, add patches, set compilation flags, anything really.
# https://nixos.wiki/wiki/Overlays
modifications = final: prev: {
modifications = _final: _prev: {
# n8n = import ./mods/n8n.nix {inherit prev;};
# brave = prev.brave.override {
@@ -25,12 +25,12 @@
# });
};
temp-packages = final: _prev: {
temp = import inputs.nixpkgs-9e9486b {
system = final.stdenv.hostPlatform.system;
config.allowUnfree = true;
};
};
# temp-packages = final: _prev: {
# temp = import inputs.nixpkgs-9e9486b {
# system = final.stdenv.hostPlatform.system;
# config.allowUnfree = true;
# };
# };
stable-packages = final: _prev: {
stable = import inputs.nixpkgs-stable {
@@ -39,19 +39,19 @@
};
};
pinned-packages = final: _prev: {
pinned = import inputs.nixpkgs-9472de4 {
system = final.stdenv.hostPlatform.system;
config.allowUnfree = true;
};
};
# pinned-packages = final: _prev: {
# pinned = import inputs.nixpkgs-9472de4 {
# system = final.stdenv.hostPlatform.system;
# config.allowUnfree = true;
# };
# };
locked-packages = final: _prev: {
locked = import inputs.nixpkgs-locked {
system = final.stdenv.hostPlatform.system;
config.allowUnfree = true;
};
};
# locked-packages = final: _prev: {
# locked = import inputs.nixpkgs-locked {
# system = final.stdenv.hostPlatform.system;
# config.allowUnfree = true;
# };
# };
master-packages = final: _prev: {
master = import inputs.nixpkgs-master {
@@ -63,6 +63,53 @@
# Factory: not a proper overlay itself — takes system to avoid the infinite
# recursion that occurs when accessing final/prev.system while the fixed-point
# is still being computed. Exposed via outputs.lib, not outputs.overlays.
mkLlmAgentsOverlay = system: _final: _prev:
inputs.llm-agents.packages.${system} or {};
#
# Use llm-agents' shared-nixpkgs overlay so packages with optional GPU support
# (notably qmd) are built against this system's pkgs/config. Using the flake's
# pre-built `packages.${system}` set pins them to llm-agents' own nixpkgs,
# where allowUnfree is false; qmd.override { cudaSupport = true; } then fails
# on CUDA EULA packages during the m3-ares NVIDIA specialisation build.
#
# Keep the exposed top-level package names aligned with llm-agents' filtered
# flake packages, but take the package values from the shared package set.
# Filters out internal helpers (marked `passthru.hideFromDocs = true`
# upstream) that would otherwise clobber nixpkgs attributes. Most critically
# this excludes `buildNpmPackage` — llm-agents' buildNpmPackage is a guarded
# re-export whose `__functor`/`override` interaction with makeOverridable
# breaks any package (e.g. nixpkgs' webcord) that calls
# `buildNpmPackage.override { nodejs = ...; }`. See numtide/llm-agents.nix
# commit 40490259 and the wrapper at packages/buildNpmPackage/package.nix.
mkLlmAgentsOverlay = system: final: prev: let
sharedPackages = (inputs.llm-agents.overlays.shared-nixpkgs final prev).llm-agents or {};
exposedPackageNames =
builtins.filter
(name: inputs.nixpkgs.lib.hasAttrByPath [name] sharedPackages)
(builtins.attrNames (inputs.llm-agents.packages.${system} or {}));
exposedPackages =
builtins.listToAttrs
(map (name: {
inherit name;
value = sharedPackages.${name};
})
exposedPackageNames);
in
builtins.removeAttrs exposedPackages [
# Internal helpers from packages/* marked hideFromDocs upstream:
"antigravity"
"auto-claude"
"buildNpmPackage" # ← the culprit; breaks webcord's `buildNpmPackage.override { nodejs = ...; }`
"bun2nix"
"darwinOpenptyHook"
"default" # fzf launcher; collides with nothing in nixpkgs but kept out for hygiene
"dolt" # collides with nixpkgs.dolt (Dolt database); not used in this config
"flake-inputs"
"forge"
"formatelf"
"formatter" # collides conceptually with pkgs.formatter; not used here
"go-bin"
"unpinCargoMsrvHook"
"unpinGoModVersionHook"
"versionCheckHomeHook"
"wrapBuddy"
];
}
+1 -2
View File
@@ -23,8 +23,7 @@ in {
"secrets/kestra-config.age".publicKeys = systems ++ users;
"secrets/kestra-env.age".publicKeys = systems ++ users;
"secrets/minio-root-cred.age".publicKeys = systems ++ users;
"secrets/rustfs-access-key.age".publicKeys = systems ++ users;
"secrets/rustfs-secret-key.age".publicKeys = systems ++ users;
"secrets/rustfs-env.age".publicKeys = systems ++ users;
"secrets/n8n-env.age".publicKeys = systems ++ users;
"secrets/netbird-auth-secret.age".publicKeys = systems ++ users;
"secrets/netbird-db-password.age".publicKeys = systems ++ users;
Binary file not shown.
-31
View File
@@ -1,31 +0,0 @@
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IDROTEtydyBnRjhF
SHhTS2YrOHF1OWM1Zm04elkzVWpST0hhN0RhOWZBZGpBYmNTVnk4Cm9SMm5NcWdV
Rnh0TVpqTlFSaGtaMnBrSGorUEhDd1RibWs1VUt5RGtqaVEKLT4gc3NoLWVkMjU1
MTkgNWt3Y3NBIFV5OWhMU204L25nR3ZLOWl1a1ppZkUvcTNJTDhlNmE3eXpJMjRL
NWdsWDQKNGhVYUhwRWRndjFYVEVIT3N2WE1WVncyV1Q1Q1BoNkhraVU5Q2s4UmtB
OAotPiBzc2gtZWQyNTUxOSA5ZDRZSVEgVkRwdGtHVTlTMUVMOFZrdUNHZHc5UWo3
WWtRaXJPY0p2QWZOUEtjWDVCYwpYQmh3ejdLOWdmM3dZbWJuRU1EYlRYZ2tJL3VY
OURUKzhRY2dtcVRQZnBnCi0+IHNzaC1lZDI1NTE5IDNCY3IxdyAyOFI4YllyWlox
V09BbERmRm4yd1Y5dlh0UGphK05DMGpsWXJQTmwrVlRVCjdqNE4yVHFKWFV3NXlr
bm40M1BpNGNNNDdJOXMyak5EUWdMa0hrb3lJY3cKLT4gc3NoLWVkMjU1MTkgYzRO
UWxBICsxb3poQit6VGRtWmZXUWUxMmRGWUN6RGVOeUxEZjdvZldTTE5XSFpDRVkK
bFNWLzFpazJLM0Q2R0NKU2FaS25ldEQ1RUZQM2RpektaT1NhRnJtS0JFcwotPiBz
c2gtcnNhIERRbEU3dwpFMVdKYnhiTWF4MCtJMFNHVGtOZGNBdlVDYWRRR252dVd6
NW1vNFRtbENLbHB2cHo1aE43M3RiZGh1QkVQVzBECjlvRnhYbjlpWWFFTEFFc1cw
NjFVSENsVWJHdWdGV3ZEY2tOcXkvUm9SSFE4VWw5eHVUSnV6SmxCRU9TNUdpRjMK
aGNhdHcvay85N0ZQNksydEhkcXNkc0h6dkRMRXlzUCtNNGM1V2tXb28wQ05valBH
TUdJa3V1bEdYRUZveFNwbwpIbWRnZmtQMDREd08rRkx3OERwRVZZNVlnSXlNNlFH
SkFoQWVEN1NzL0lqeVkvZllPdUkvbWZkU2NxNjQyYTIvCnJ4QmZ1SlpGNkp3UXFD
SUdFMFY5RWVadTd5QmM1U2tIZ3dLQ2ZZKzF0WTE3K09aN3FYWUVBYkErVlNpblNU
QzgKNENEZStFeitaYmE5Q1MyQ0lWSFlZb2hJdlBVNkhUUjBFWkxsWmZqdHNYb3Fk
VVJMMzg2V2xWdnNCNndGSWdpbAoyUHZ1WXR5UG04ZmZOdVluU2J6VUhKZ0xMZ0lS
R3YrY3RIRHJCby8yVWxIMWpGNWlJK1h4eXdRUXExT3pleWc3CnRmQVl1Yk1IUUFJ
blNoUGxVUUlVOG9FSE5CMDVidmZhSWJmWTFsY0lFcWpZU213cmcxNzFvb29XaklC
MnhpSkwKCi0+IHNzaC1lZDI1NTE5IENTTXloZyBOMDNYdGlvL3Y5QUp2YlNlUDZu
RXFyTkFWbFFsN1oweEErSS9Ccmh0WmwwClpzTWw1aXNqVXdaTVFrTTJ6Y0FWbVpR
TXk4cTNUUElkeGF1VUZ0U3RWcEEKLT4gTyUkcSZASGstZ3JlYXNlCnYwSGdsbE5h
d2JLOAotLS0gcjB3WU1rNDhBY1VxalpBNVJRSTJFZ0NhWEZlSW15UHphMnRHTjBj
aGptRQpiZ/2f41GnSHdg+EXeRwxHOHc/RNfEwlKhEB/Weq8tQ2Xf/jJ21WiWsTIm
g7Sq9EO6JyYMTJ/qlccpytfkU/qkouyR+z3prQcP7NWTcg==
-----END AGE ENCRYPTED FILE-----
+26
View File
@@ -0,0 +1,26 @@
age-encryption.org/v1
-> ssh-ed25519 4NLKrw 4yocYUNwOH2fkSzRbkhJ1DN58fiFHKGQlQY8ljkgykM
68DuFPNFjyD2+avOMlOlRQm3bs43Bk84MIXygS35MtE
-> ssh-ed25519 5kwcsA cC38K7vS4JlkGtSEPn7D6x2m9H08XK4vuhWysJcFNG0
kKbUBKEfUUkhmnr3g5/Bz8chDouySQf3Mk/+LyNNQls
-> ssh-ed25519 9d4YIQ w3u2BX/R0lVgy35DoFtxUM6f/nYkcNVeAoPDNDSX5yU
XOo2/yrO2r2mn2FTcR+dviKVClU94Pi8Wri17emUsoI
-> ssh-ed25519 3Bcr1w 8ncD6gl8tHVOYO83VW4dXI3XVUNXdfbFoZutCGGykxw
r7k0ltk9XK5q9+gyLwqzaajYbTRgsj3rALJTCnQ0Lyg
-> ssh-ed25519 c4NQlA A8WnqWlC8ljCaQVMa6wJIfe4uA3OQ/q9vJRAF56ovVE
xwh0RE9S+z5Rf+PCW0L/flKy506HRel0dVJJVzyO1M8
-> ssh-rsa DQlE7w
f5iiDuIUPzKToC7cCUtQUQzkxKPkYsDuHHM+9BHsQmwSOT91Z0J1F4udOlEqUcuE
kUMCbHvhFEQnzfKruEH3+tRnW1YWtqTzhgvW1MvY/gv8PihekM+TSjB/mxwYSC88
yp3NhNxxonBdIjTUcgYBGijWQjPVCuggZcseqyy+h37rQCUNG6whacU7Q+ELbtTW
ssfofJrKU7l8uBpNuM3ULMK4ZzM9IurZQyqt43n++y21G1hCKVkf7g6q0IQ94SL1
y6yGyx2JGNnFO8e57vggmAtyFMMv+660plF0bg1pyQfFdmKHrPXmVHFURdQixhrg
dZhcOq1WZIjNE/SALmZj8NkNxCIjne0oIE94RNq1lj7sRFolbyaYTjfa3lnmsjsl
0s7y3QR1igJozNc0InR6koal1/WzykfXDqNwxFNyknfaGT75ZtsXJ8PC2mLbqxvC
YKYHOBledBfLASMFHeJjXx1b+X1X1DzllY51Z2p1c4BeWxuheNCd2zPiCLfzPk0w
-> ssh-ed25519 CSMyhg /KgSvWyP3WRBq8uKV8VacXZEeGna+HmH3f+4lrJKnBc
PlGjwoekR9PhGTxvxbl81BKkVl4z2JqCH+L68qfoyow
--- CeX80TFkreEFbDMeAGswnT0Y+CVfI9kTdosSCj49Hlk
T½"±–q<E/gíÑ|`.#®8Z2F­ÇD1îËÀ•õ¢+:~Úæ
Í)ü.;/TwzƒHtË ¥agX0ˆß;½ÖOiè)sÑ઒‹„FéõU>aÍê„™çú=ëäG–-séÌA¢“
-32
View File
@@ -1,32 +0,0 @@
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IDROTEtydyBQd3FZ
dUFYOFhoUGdBejZKYjRnVmNvYU85LzdJS1lVZFNRS3pTeS9hT0c4Cndwc3pHdStQ
N1QvU0NSbGJhNEJCOE83eThhSFBrbDJPU0tDbmhIM3lwcjQKLT4gc3NoLWVkMjU1
MTkgNWt3Y3NBIHdaS3UvRUdFb3pITmZGdTNEaUtXdnlUMWFuNk5ZcFV0VVIwNllN
S2c5Rm8KV0x3Z2NjcUdLWmFEUExDT2EwbjFhQ2Y2TXNoaUc1d052RnJmM3VOSDVr
VQotPiBzc2gtZWQyNTUxOSA5ZDRZSVEgOG1URGlNekltV0YyQ2Y2NFdPL2tSWDlG
UnNLc2wrSllNWFd6aU9LWGN3YwpXUEthT3NNVHZJMUJndiswUVNFNWZjZnBDS3ZH
dXBJV1FSNEpPRGxQd0JrCi0+IHNzaC1lZDI1NTE5IDNCY3IxdyAvSTlFMitYZFVQ
ZER6ZDI5OEorTE5TRTdlcllPSmpkUjU5SkV2N0xQY1JBCmJPNFN5NEovdHBVVDRl
T0czS0g2dEgyTXhIMmtJVFRONDQ3enpLbFhJT3MKLT4gc3NoLWVkMjU1MTkgYzRO
UWxBIDBUV2RYajBTMkZ4WnV4ZUVCeHFZay9vRGR2dkcxaXBPOWxsZ05IZm1KVDAK
am56blp1ajlzc0NSYjY5NFdGNlNzQ0NNQzZPeVRtWTc1Z0lEYzc2TGNFMAotPiBz
c2gtcnNhIERRbEU3dwpOMGowMWFoRzhsTGp0U0RqeHUyckZvQU9EVkQxUXE1b0U0
N2hPU2NZY2huNm5kREg5SExCZGYzaTUwdWs4MjlsCjhONjVOWnZDZjFRU2k2K2Uz
dnVmWVd5MCt6bFk4UVU3UEdsWXZMOHlZMktzWWR4SFJ6Vzh4dDFpYWNYRVQ2UmsK
aW5iODV0WDYyQWN4K1ROZUVjdE40MGlxZDlXdnZVRVZBc04zdVRaOE9RTUJPUWxa
YnJjZEg3OGcxNHVEVkR0MgpGUWh6NHV4WTcxUEZwUU52QkdsOE5hZy9XWFpjQUFP
bDZzUjd3ZXFTTmpDN3ViZ0dpL3BOTFpBL3k2aUs3Qm9HCkVDeXZ2M0dQcWJwaXdm
N2E1R2pjcWY2V1dYaEFNMVc3MG9ndDRLd0tVdkxHSUxwL2REazE2Unc1Z3JjUHJh
NDgKamVqZjdkU0hCTVhqcjRsL1NtYkxxd3BId0lsRTRRUTNrZ05mcE1ZRkFSUlBW
VVdkd2VSNzJMQVJEM2QyVkMzSQoxRGVOOUtzdGVOMTBLVk8zN2xjT3lvYm0vSXpQ
VElTaS84SUxIekVybGYxV0ttZldVWHhyVVEvdzRFK3RibVFGCjV3bzltRjFTb0pu
bGJQaTJ1Mlgxd0hNN2VvS0p3eDd4WHNkaTkwV3MwWTdLWUxnNzJjLzBBZzZsck5h
Zk1UUDcKCi0+IHNzaC1lZDI1NTE5IENTTXloZyByQ1cwWm50UTY1bkp2NWZFeFVU
T0htZDFWUUFsdlBSOVVNY3RTZnNwdjE0CjBySlExb1dnTGJKZy9MT25Oa2hZdDJZ
Um9PZWlpOVA5bTBRM2wvVHJJaG8KLT4gWS1ncmVhc2UgWydtCnF4dzJjR2luMHBS
S2p3bUE2bVl2R2FaQ2hRK3greGMKLS0tIDhSdFFGaGlGRVV2VFZKcTNWYnNtbUQr
blprSjUyMjJwQkhBbVBCTmVhQ0kKUITtRYOYPDGGQlKrEp/JVUP8jTcptZxVaVcd
AmxviaG76EuXQeK/VgrGKoi+bZwHbpCbXBT2H8DBuSPgXdG3aQDQn2QgZylMnhmM
wzU=
-----END AGE ENCRYPTED FILE-----