8 Commits
Author SHA1 Message Date
John Lancaster cf418ca7a0 root version of jsl-zsh 2026-07-03 21:46:31 -05:00
John Lancaster 8ae74a9bc9 silencing warning 2026-07-03 21:22:50 -05:00
John Lancaster b74133985c pruning zsh 2026-07-03 21:16:00 -05:00
John Lancaster 2de7650f3d jsl-zsh in ghostty 2026-07-03 20:52:31 -05:00
John Lancaster 41f33653a7 central time zone on LXCs 2026-07-02 20:20:12 -05:00
John Lancaster 460d8908bb jsl-zsh working as a login shell 2026-07-02 20:11:49 -05:00
John Lancaster 621a61fb9e trusting ubuntu key by default 2026-07-02 08:38:42 -05:00
John Lancaster 3f3d847134 extra principals for SSH host certs 2026-07-02 08:38:06 -05:00
7 changed files with 224 additions and 140 deletions
+17 -3
View File
@@ -5,7 +5,7 @@ let
in in
{ {
flake.modules.nixos.janus-ca = flake.modules.nixos.janus-ca =
{ config, lib, ... }: { config, pkgs, lib, ... }:
let let
cfg = config.janus-ca; cfg = config.janus-ca;
johnHome = lib.attrByPath [ "users" "users" username "home" ] "/home/${username}" config; johnHome = lib.attrByPath [ "users" "users" username "home" ] "/home/${username}" config;
@@ -58,11 +58,15 @@ in
nixos.docker nixos.docker
nixos.login-text nixos.login-text
nixos.mtls nixos.mtls
{ ({ lib, pkgs, ... }: {
networking.hostName = hostname; networking.hostName = hostname;
sops.defaultSopsFile = ../../../keys/secrets.yaml; sops.defaultSopsFile = ../../../keys/secrets.yaml;
step-ssh-host = { step-ssh-host = {
hostname = hostname; hostname = hostname;
extraPrincipals = [
"192.168.1.244"
"fded:fb16:653e:25da:be24:11ff:fea0:753f"
];
}; };
mtls = { mtls = {
enable = true; enable = true;
@@ -73,13 +77,23 @@ in
]; ];
}; };
users.users."${username}" = {
shell = lib.mkForce (
lib.getExe inputs.self.packages.${pkgs.stdenv.hostPlatform.system}.jsl-zsh
);
};
# users.users."${username}".openssh.authorizedKeys.keys = [
# "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMOkGLo4N/L3RYvaIZ1FmePlxa1HK0fMciZxKtRhN58F root@janus"
# ];
home-manager.users."${username}" = { home-manager.users."${username}" = {
imports = with inputs.self.modules.homeManager; [ imports = with inputs.self.modules.homeManager; [
mysops mysops
]; ];
docker.enable = true; docker.enable = true;
}; };
} })
]; ];
}; };
} }
+31 -17
View File
@@ -1,24 +1,38 @@
{ inputs, ... }: { inputs, ... }:
{ {
flake.modules.nixos.lxc = { pkgs, lib, ...}: { flake.modules.nixos.lxc = { pkgs, lib, ...}:
imports = with inputs.self.modules.nixos; [ let
({ modulesPath, ... }: { imports = [ "${modulesPath}/virtualisation/proxmox-lxc.nix" ]; }) selfPackages = inputs.self.packages.${pkgs.stdenv.hostPlatform.system};
]; rootShellPath = lib.getExe' selfPackages.jsl-zsh-tty "jsl-zsh-tty";
nixpkgs.hostPlatform = lib.mkForce "x86_64-linux"; in
system.stateVersion = "25.11"; {
nix.settings.experimental-features = [ "nix-command" "flakes" ]; imports = with inputs.self.modules.nixos; [
environment.systemPackages = with pkgs; [ git zsh ]; ({ modulesPath, ... }: { imports = [ "${modulesPath}/virtualisation/proxmox-lxc.nix" ]; })
];
nixpkgs.hostPlatform = lib.mkForce "x86_64-linux";
system.stateVersion = "25.11";
time.timeZone = "US/Central";
nix.settings.experimental-features = [ "nix-command" "flakes" ];
environment.systemPackages = with pkgs; [
git
zsh
selfPackages.jsl-zsh-tty
];
environment.shells = lib.mkAfter [
rootShellPath
];
users.users.root.shell = lib.mkForce rootShellPath;
# security.sudo-rs.enable = true; # security.sudo-rs.enable = true;
programs.nix-ld.enable = true; programs.nix-ld.enable = true;
nix.optimise.automatic = true; nix.optimise.automatic = true;
nix.gc = { nix.gc = {
automatic = true; automatic = true;
dates = "weekly"; dates = "weekly";
options = "--delete-older-than 30d"; options = "--delete-older-than 30d";
};
programs.bash.enable = true;
}; };
programs.bash.enable = true;
};
# Generic bootstrapping lxc, use a specific host file for more # Generic bootstrapping lxc, use a specific host file for more
flake.nixosConfigurations.lxc = inputs.nixpkgs.lib.nixosSystem { flake.nixosConfigurations.lxc = inputs.nixpkgs.lib.nixosSystem {
+1 -1
View File
@@ -39,7 +39,7 @@
enableZshIntegration = true; enableZshIntegration = true;
package = ghosttyX11; package = ghosttyX11;
settings = { settings = {
command = "TERM=xterm-256color ${lib.getExe pkgs.zsh}"; command = "TERM=xterm-256color ${lib.getExe inputs.self.packages.${pkgs.stdenv.hostPlatform.system}.jsl-zsh}";
font-size = 12; font-size = 12;
font-family = "Source Code Pro"; font-family = "Source Code Pro";
theme = "Catppuccin Mocha"; theme = "Catppuccin Mocha";
+60
View File
@@ -50,5 +50,65 @@
''; '';
}; };
}).wrapper; }).wrapper;
packages.starship-ascii = (inputs.wrappers.wrapperModules.starship.apply {
inherit pkgs;
settings = {
add_newline = false;
format = "$username$hostname$directory$git_branch$git_status$cmd_duration$line_break$character";
username = {
show_always = true;
format = "[$user]($style)";
style_user = "bold blue";
style_root = "bold red";
};
hostname = {
disabled = false;
ssh_only = false;
format = "[@$hostname]($style) ";
style = "bold blue";
};
directory = {
truncation_length = 3;
truncate_to_repo = true;
format = "[ in $path]($style) ";
style = "bold cyan";
};
git_branch = {
symbol = "on ";
format = "[$symbol$branch]($style) ";
style = "bold yellow";
};
git_status = {
format = "([$all_status$ahead_behind]($style) )";
style = "bold red";
ahead = "ahead:$count ";
behind = "behind:$count ";
diverged = "diverged:$ahead_count/$behind_count ";
up_to_date = "";
};
cmd_duration = {
min_time = 2000;
show_notifications = false;
format = "took [$duration]($style) ";
style = "bold green";
};
line_break.disabled = false;
character = {
success_symbol = "[\\$](bold green) ";
error_symbol = "[\\$](bold red) ";
vicmd_symbol = "[\\$](bold yellow) ";
};
};
}).wrapper;
}; };
} }
+99 -110
View File
@@ -23,127 +23,116 @@ let
in in
{ {
flake.modules = { flake.modules = {
nixos.zsh = { pkgs, ... }: { nixos.zsh = { pkgs, ... }:
users.users."${username}".shell = pkgs.zsh; let
programs.zsh.enable = true; selfPackages = inputs.self.packages.${pkgs.stdenv.hostPlatform.system};
# Already being imported by the john.nix module in
# home-manager.sharedModules = [ {
# inputs.self.modules.homeManager.zsh users.users."${username}".shell = selfPackages.jsl-zsh;
# ]; programs.zsh.enable = true;
}; };
homeManager.zsh = { pkgs, config, ... }: { homeManager.zsh = { pkgs, config, ... }:
programs.zsh = { let
enable = true; selfPackages = inputs.self.packages.${pkgs.stdenv.hostPlatform.system};
package = inputs.self.packages.${pkgs.stdenv.hostPlatform.system}.jsl-zsh; in
enableCompletion = true; {
autosuggestion.enable = true; programs.zsh = {
# syntaxHighlighting.enable = true;
initContent = ''
HOST=$(hostname -s)
${homeEndKeyBindings}
'';
dotDir = "${config.xdg.configHome}/zsh";
history = {
append = true;
ignoreAllDups = true;
ignorePatterns = [
"history"
"ls"
"eza"
"clear"
];
save = historySize;
size = historySize;
share = true;
};
oh-my-zsh = {
enable = true; enable = true;
# theme = "risto"; package = selfPackages.jsl-zsh;
theme = "agnoster"; dotDir = "${config.xdg.configHome}/zsh";
plugins = [
"sudo"
"dotenv"
"git"
"ssh"
"ssh-agent"
];
}; };
}; };
};
}; };
perSystem = { config, self', pkgs, lib, ... }: { perSystem = { config, self', pkgs, lib, ... }:
packages.jsl-zsh = let
let ignorePatterns = [
ignorePatterns = [ "ls" "eza" "history" "clear"
"ls" "eza" "history" "clear" ];
]; integrationPackages = with pkgs; [
aliasStr = lib.concatStringsSep "\n" ( fzf
lib.mapAttrsToList (k: v: "alias -- ${lib.escapeShellArg k}=${lib.escapeShellArg v}") { zoxide
ls = "eza"; ];
ll = "eza -l"; extraToolPackages = with pkgs; [
la = "eza -a"; lazygit
lt = "eza --tree"; lazydocker
lla = "eza -la"; devenv
ds = "gdu -i /snap /"; self'.packages.shell-tools
ld = "lazydocker"; self'.packages.neovim-min
}); ];
in aliasStr = lib.concatStringsSep "\n" (
(inputs.wrappers.wrapperModules.zsh.apply { lib.mapAttrsToList (k: v: "alias -- ${lib.escapeShellArg k}=${lib.escapeShellArg v}") {
inherit pkgs; ls = "eza";
binName = "jsl-zsh"; ll = "eza -l";
env = { la = "eza -a";
LANG = "en_US.UTF-8"; lt = "eza --tree";
COLORTERM = "truecolor"; lla = "eza -la";
DEVENV_SHELL_TYPE = "zsh"; ds = "gdu -i /snap /";
}; ld = "lazydocker";
settings = { });
completion = {
enable = true; mkJslZsh = { binName, starshipPackage }:
extraCompletions = true; let
caseInsensitive = true; loginBootstrapPath = lib.makeBinPath (integrationPackages ++ [ starshipPackage ] ++ extraToolPackages);
fuzzySearch = true; in
(inputs.wrappers.wrapperModules.zsh.apply {
inherit pkgs binName;
env = {
LANG = "en_US.UTF-8";
COLORTERM = "truecolor";
DEVENV_SHELL_TYPE = "zsh";
}; };
autoSuggestions = { settings = {
enable = true; completion = {
strategy = [ "history" "completion" ];
};
history = {
append = true;
expanded = true;
share = true;
ignoreAllDups = true;
ignoreSpace = true;
};
integrations = {
fzf.enable = true;
starship = {
enable = true; enable = true;
package = self'.packages.starship; extraCompletions = true;
caseInsensitive = true;
fuzzySearch = true;
};
autoSuggestions = {
enable = true;
strategy = [ "history" "completion" ];
};
history = {
append = true;
expanded = true;
share = true;
ignoreAllDups = true;
ignoreSpace = true;
}; };
zoxide.enable = true;
}; };
}; extraRC = ''
extraRC = '' ${homeEndKeyBindings}
${homeEndKeyBindings}
HISTFILE=$HOME/.config/zsh/.zsh_history # Login shells may reset PATH before integrations run.
SAVEHIST=${toString historySize} export PATH=${lib.escapeShellArg loginBootstrapPath}:$PATH
HISTORY_IGNORE=${lib.escapeShellArg "(${lib.concatStringsSep "|" ignorePatterns})"}
HOSTNAME=$(hostname -s) source <(fzf --zsh)
${aliasStr} eval "$(zoxide init zsh)"
eval "$(starship init zsh)"
eval "$(devenv hook zsh)" HISTFILE=$HOME/.config/zsh/.zsh_history
''; SAVEHIST=${toString historySize}
extraPackages = with pkgs; [ HISTORY_IGNORE=${lib.escapeShellArg "(${lib.concatStringsSep "|" ignorePatterns})"}
lazygit
lazydocker HOSTNAME=$(hostname -s)
devenv ${aliasStr}
self'.packages.shell-tools
self'.packages.neovim-min eval "$(devenv hook zsh)"
]; '';
}).wrapper; extraPackages = extraToolPackages;
}; }).wrapper;
in
{
packages.jsl-zsh = mkJslZsh {
binName = "jsl-zsh";
starshipPackage = self'.packages.starship;
};
packages.jsl-zsh-tty = mkJslZsh {
binName = "jsl-zsh-tty";
starshipPackage = self'.packages.starship-ascii;
};
};
} }
+12 -2
View File
@@ -5,6 +5,12 @@
provisionerPasswordPath = config.sops.secrets."janus/admin_jwk".path; provisionerPasswordPath = config.sops.secrets."janus/admin_jwk".path;
sshKeyPath = "/etc/ssh/ssh_host_ed25519_key"; sshKeyPath = "/etc/ssh/ssh_host_ed25519_key";
sshCertPath = "${sshKeyPath}-cert.pub"; sshCertPath = "${sshKeyPath}-cert.pub";
mkPrincipalArgs = principals:
lib.concatMapStringsSep " " (principal: ''--principal "${principal}"'') principals;
principalArgs = mkPrincipalArgs ([
cfg.hostname
"${cfg.hostname}.john-stream.com"
] ++ cfg.extraPrincipals);
in in
{ {
# NixOS Options # NixOS Options
@@ -18,6 +24,11 @@
type = lib.types.str; type = lib.types.str;
default = "admin"; default = "admin";
}; };
extraPrincipals = lib.mkOption {
description = "Additional SSH host certificate principals to include per host";
type = with lib.types; listOf str;
default = [ ];
};
}; };
imports = with inputs.self.modules.nixos; [ ssh ]; imports = with inputs.self.modules.nixos; [ ssh ];
@@ -39,8 +50,7 @@
--host --sign \ --host --sign \
--provisioner "${cfg.provisioner}" \ --provisioner "${cfg.provisioner}" \
--provisioner-password-file "${provisionerPasswordPath}" \ --provisioner-password-file "${provisionerPasswordPath}" \
--principal "${cfg.hostname}" \ ${principalArgs} \
--principal "${cfg.hostname}.john-stream.com" \
"${cfg.hostname}" "${sshKeyPath}.pub" "${cfg.hostname}" "${sshKeyPath}.pub"
'') '')
(writeShellScriptBin "ssh-host-cert-check" "${lib.getExe' pkgs.openssh "ssh-keygen"} -Lf ${sshCertPath}") (writeShellScriptBin "ssh-host-cert-check" "${lib.getExe' pkgs.openssh "ssh-keygen"} -Lf ${sshCertPath}")
+4 -7
View File
@@ -1,4 +1,4 @@
{ self, inputs, lib, ... }: { self, inputs, ... }:
let let
username = "john"; username = "john";
baseUserModules = self.factory.user { baseUserModules = self.factory.user {
@@ -14,13 +14,13 @@ in
key = ""; key = "";
keygrip = [ ]; keygrip = [ ];
authorizedKeys = [ authorizedKeys = [
# "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIAUa4dcg1TWc4pW++uodyhX4eOqrX/QYIxFWtEP7HFJ john@john-pc-ubuntu" # Shared keys for every host can go here.
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMOkGLo4N/L3RYvaIZ1FmePlxa1HK0fMciZxKtRhN58F root@janus" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIAUa4dcg1TWc4pW++uodyhX4eOqrX/QYIxFWtEP7HFJ john@john-pc-ubuntu"
]; ];
}; };
flake.modules = { flake.modules = {
nixos."${username}" = { ... }: { nixos."${username}" = { config, pkgs, ... }: {
imports = [ imports = [
baseUserModules.nixos."${username}" baseUserModules.nixos."${username}"
]; ];
@@ -38,9 +38,6 @@ in
inputs.self.modules.homeManager.ssh inputs.self.modules.homeManager.ssh
inputs.self.modules.homeManager.git inputs.self.modules.homeManager.git
]; ];
# home.packages = [
# inputs.self.packages.${pkgs.stdenv.hostPlatform.system}.shell-tools
# ];
xdg.enable = true; xdg.enable = true;
programs.git.settings.user.name = name; programs.git.settings.user.name = name;
programs.git.settings.user.email = email; programs.git.settings.user.email = email;