From ea0f18c678ac71383de14943a0c2f76775867cb4 Mon Sep 17 00:00:00 2001 From: 0xrsydn Date: Wed, 22 Oct 2025 13:54:08 +0700 Subject: [PATCH] chore: update AGENTS.md --- AGENTS.md | 32 ++++++++++---------------------- modules/home/rsydn/base.nix | 1 + 2 files changed, 11 insertions(+), 22 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 70c4c94..b8dfdae 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -1,35 +1,23 @@ # Repository Guidelines ## Project Structure & Module Organization -- `flake.nix` defines shared helpers plus Darwin (`macbook-pro`) and NixOS (`dev-vm`) hosts; `flake.lock` pins inputs. -- `modules/darwin/` holds macOS system modules; `modules/nixos/` mirrors that for Linux (base `system.nix` imports `users.nix`, `network.nix`, `ssh.nix`, `containerization.nix`). -- Host overlays live under `modules/nixos/hosts/`—e.g., `dev-vm.nix` adds virtio tooling and host-only packages. -- User configuration is in `modules/home/rsydn/` with subdirectories for `programs/`, `shell/`, and `devtools/`; Darwin layers on `shell/nushell.nix` while Linux sticks to `shell/fish.nix`. -- Secrets stay in `secrets/*.sops.yaml`; decrypted files appear under `~/.config/secrets/` at activation and must not be committed. +This flake manages both macOS (`macbook-pro`) and NixOS (`dev-vm`) hosts. `flake.nix` collects shared modules while `flake.lock` pins inputs. Platform modules live in `modules/darwin/` and `modules/nixos/`; the Linux base `system.nix` pulls in `users.nix`, `network.nix`, `ssh.nix`, and `containerization.nix`. Host overlays such as `modules/nixos/hosts/dev-vm.nix` add virtio tooling or per-machine packages. User-facing configuration sits under `modules/home/rsydn/` with `programs/`, `shell/`, and `devtools/`; Darwin layers `shell/nushell.nix` and Linux sticks to `shell/fish.nix`. Secrets remain encrypted in `secrets/*.sops.yaml` and appear at runtime under `~/.config/secrets/`. ## Build, Test & Development Commands -- `nix develop` – enter the flake dev shell with `git`, `nixfmt-classic`, SOPS/Age helpers. -- `nix fmt` – format all Nix sources; run before commits touching modules or overlays. -- `XDG_CACHE_HOME=$PWD/.cache nix flake check` – lint and eval every host without polluting the global cache. -- `darwin-rebuild --dry-run --flake .#macbook-pro` / `darwin-rebuild switch --flake .#macbook-pro` – preview or apply macOS changes. -- `nix build .#nixosConfigurations.dev-vm.config.system.build.toplevel` – make sure the Linux VM evaluates and builds before switching. +- `nix develop` – enter the dev shell with `git`, `nixfmt-classic`, and SOPS tooling prewired. +- `nix fmt` – format every Nix file; run before committing module or overlay changes. +- `XDG_CACHE_HOME=$PWD/.cache nix flake check` – evaluate all hosts without polluting the global cache. +- `darwin-rebuild --dry-run --flake .#macbook-pro` → `darwin-rebuild switch --flake .#macbook-pro` – preview then apply macOS updates. +- `nix build .#nixosConfigurations.dev-vm.config.system.build.toplevel` – validate the Linux VM closure before switching. ## Coding Style & Naming Conventions -- Use two-space indentation, trailing commas, and lower-kebab filenames (`shell/nushell.nix`). -- Declare custom options under the `rsydn.*` namespace (e.g., `rsydn.containerization`, `rsydn.devTools`). -- Prefer declarative package toggles and shared modules over ad-hoc host tweaks; keep host-specific overrides in `hosts/`. +Use two-space indentation, trailing commas, and lower-kebab filenames (e.g. `shell/nushell.nix`). Declare custom options in the `rsydn.*` namespace and prefer shared modules over ad-hoc host tweaks. ## Testing Guidelines -- Treat `nix flake check` as mandatory before PRs or `switch` operations. -- Capture key activation output: `darwin-rebuild --dry-run` for macOS, `nix build .#nixosConfigurations.dev-vm…` for the VM, and attach summaries in reviews. -- Co-locate regression tests with the option/module they guard using the `.nix` pattern when practical. +Treat `nix flake check` as mandatory gatekeeping. Capture activation output (`darwin-rebuild --dry-run`, `nix build .#nixosConfigurations.dev-vm…`) and attach summaries to reviews. Co-locate regression tests next to their modules with the `.nix` pattern. ## Commit & Pull Request Guidelines -- Write short, imperative subjects (`add dev-vm virtualization module`); keep each commit scoped to one change. -- In PRs, list validation steps (`nix flake check`, host-specific builds) and link related issues or TODOs. -- Provide screenshots or terminal snippets when altering shell prompts, Tailscale/SSH flows, or other UX-facing pieces. +Keep commit subjects short and imperative (`add dev-vm virtualization module`) and scope each commit narrowly. PRs should list validation commands, link issues or TODOs, and include screenshots or terminal snippets when modifying prompts, Tailscale, or SSH flows. ## Security & Configuration Tips -- Age keys live at `~/.config/sops/age/keys.txt`; regenerate via Home Manager if missing. -- Access secrets by reading the managed files (`open ~/.config/secrets/openai-api-key | str trim`) and scope them with `with-env` instead of exporting globally. -- Tailscale and OpenSSH run by default on Linux; rotate auth keys regularly and audit `services.tailscale.extraUpFlags` when enabling exit nodes. +Age keys live at `~/.config/sops/age/keys.txt`; regenerate via Home Manager if missing. Read secrets from the managed files (`open ~/.config/secrets/openai-api-key | str trim`) and scope them with `with-env`. Tailscale and OpenSSH run by default on Linux; rotate keys regularly and audit `services.tailscale.extraUpFlags` before enabling exit nodes. diff --git a/modules/home/rsydn/base.nix b/modules/home/rsydn/base.nix index 66951cb..d705d72 100644 --- a/modules/home/rsydn/base.nix +++ b/modules/home/rsydn/base.nix @@ -33,6 +33,7 @@ lazydocker lazygit lorri + nil pandoc ripgrep tmux