This repository manages NixOS systems with multiple hosts and user profiles.
The configuration is organized into three main layers:
- modules/ - System-level configuration (desktop env, hardware, security, services)
- home-manager/ - User-level configuration (packages, theming, desktop settings)
- hosts/ - Per-host specific configuration
/etc/nixos/
├── flake.nix # Main entry point with mkNixSystem helper
├── modules/
│ ├── default.nix # systemOptions definitions & imports
│ ├── desktopEnvironment/ # Niri compositor & DMS shell
│ ├── hardware/ # Graphics, audio, fingerprint, etc.
│ ├── packages/ # System packages
│ ├── security/ # Security hardening
│ └── services/ # System services
├── home-manager/
│ ├── default.nix # Main home-manager entry point
│ ├── profiles/{work,play,root}.nix # User profiles
│ ├── packages/ # nixvim, git, kitty, zathura, etc.
│ │ ├── nixvim/ # Neovim configuration
│ │ ├── shell/ # bash + starship
│ │ └── ... # Other package configs
│ ├── system-options/ # Profile & owner options
│ ├── desktopEnvironment/ # Niri & DMS settings
│ │ ├── dms/ # DMS colors, plugins, dsearch
│ │ └── niri/ # Niri keybinds & window rules
│ ├── theming/ # GTK & Qt themes
│ └── xdg/ # XDG directories & MIME types
└── hosts/{hostname}/
├── configuration.nix # Host system config (enables systemOptions)
├── hardware-configuration.nix # Hardware-specific config
├── environment.nix # Kernel & environment settings
└── home.nix # User definitions (imports profiles)
Hosts:
- **v-desktop, v-laptop** - AMD/Intel workstations (v-owner)
- **e-desktop, e-laptop** - NVIDIA/Intel workstations (e-owner, full services)
- **server-nu** - Router, AdGuard, reverse proxy, dynamic DNS
- **server-mu** - SSH bastion, Nextcloud, Minecraft
- **anton** - llama-swap inference (Vulkan, R9700 "antonino"): dense models + heretic variants
- **son-of-anton** - llama-swap inference (ROCm, Strix Halo 128GB): MoE models + always-on router
- **oracle** - LiteLLM proxy + MCP gateway, SearXNG, temple-server (aarch64)
All hosts have access to systemOptions defined in modules/default.nix:
systemOptions = {
owner.e.enable = true; # Owner identification
deviceType.laptop.enable = true; # Device type
graphics.amd.enable = true; # Graphics drivers
};This determines which graphics drivers are enabled, whether custom security settings should be applied, whether to apply chromebook specific patches, etc.
Users are organized into work, play, or root profiles:
# home-manager/profiles/work.nix
{ lib, ... }:
{
imports = [
../packages
../desktopEnvironment
../theming
../xdg
];
Profile = "work";
}- Work: clang-tools, slack, tools for nuclear physics data analysis
- Play: signal-desktop, mangohud, android-tools, mumble, gaming tools
- Root: Minimal profile without desktop environment configurations
Set this option per-user in
hosts/{hostname}/home.nixvia profile import.
- Compositor: niri (scrollable tiling Wayland)
- Shell: DankMaterialShell (DMS)
- Greeter: DMS greeter
- Config:
home-manager/desktopEnvironment/
- Shell: bash
- Prompt: Starship
- Terminal: Kitty
- Editor: Neovim (configured via nixvim)
Configuration in
home-manager/packages/shell/.
Colors managed via base16.nix with schemes from pkgs.base16-schemes on a per-profile basis.
scheme = "${pkgs.base16-schemes}/share/themes/kanagawa.yaml";nixos-generate-config --show-hardware-config > hosts/new-host/hardware-configuration.nixCreate hosts/new-host/configuration.nix with systemOptions, then add to flake.nix:
nixosConfigurations.new-host = mkNixSystem { hostname = "new-host"; };Add option to modules/default.nix
2.
Create module in modules/
3.
Enable in host's configuration.nix
Edit home-manager/packages/default.nix.
Edit home-manager/packages/shell/default.nix for bash aliases.
e-desktop serves its nix store as a binary cache so other hosts can pull pre-built packages instead of compiling from source. This is especially useful for git-versioned packages like niri, quickshell, and DMS.
- Server:
nix-serve-ngon e-desktop, exposed via Caddy reverse proxy on server-nu - Clients: All other hosts are configured as substituters via
systemOptions.services.binaryCache.consume - URL:
https://cache.ethanwtodd.com
The fleet distributes inference and gateway services across dedicated hosts:
- son-of-anton (AMD Strix Halo 128GB): llama-swap with ROCm backend; deepseek-v4-flash (always-resident) and gemma-4-12b-router
- anton — AMD R9700 32GB ("antonino") — llama-swap with Vulkan backend; dense models (qwen3.6-27b, gemma-4-31b) and heretic variants
- oracle (aarch64) hosts the gateway and tooling:
- LiteLLM proxy, single entry point:
https://llm.ethanwtodd.com/v1 - MCP gateway at
https://llm.ethanwtodd.com/mcp/(auth viaAuthorization: Bearer <key>), aggregating stdio servers:fetch(URL retrieval),searxng(web search),nixos(Nix/NixOS lookups),arxiv, andcontext7 - SearXNG metasearch, localhost-only, backing the searxng MCP
- temple-server (renco agent)
- LiteLLM proxy, single entry point:
opencode (e-workstations via home-manager/packages/opencode) — coding
CLI/TUI pointed at the LiteLLM endpoint, default model Qwen3.6-27b.
MCP servers are served via the remote LiteLLM MCP gateway at
https://llm.ethanwtodd.com/mcp/, aggregating fetch, searxng, nixos,
arxiv, and context7. The wrapper sources LITELLM_MASTER_KEY from the
agenix secret at launch.
Opencode dispatches to specialized subagents for specific tasks:
| Agent | Model | Role |
|---|---|---|
| code-reviewer | qwen3.6-27b-coding |
Reviews code for bugs, security, performance, and maintainability. Read-only. |
| security-auditor | deepseek-v4-flash-max |
Deep security audit for auth, crypto, secrets, and user input. Read-only. |
| debugger | deepseek-v4-flash-high |
Systematic root-cause analysis for broken or unclear behavior. |
| architect | deepseek-v4-flash-high |
High-level design decisions, module boundaries, and API contracts. Read-only. |
| test-writer | qwen3.6-27b-coding |
Generates comprehensive tests after feature or bug-fix implementation. |
| refactorer | deepseek-v4-flash-max |
Improves code structure without changing behavior. |
| docs-writer | qwen3.6-27b-coding |
Writes documentation, docstrings, and READMEs. |
The fleet is deployed with Colmena.
The hive (colmena / colmenaHive flake outputs) reuses each host's NixOS
modules, so it never drifts from nixosConfigurations.
e-desktop is the build host — it builds every closure and pushes the result,
so the servers and laptops never compile.
colmena apply --on @server # build on e-desktop, push to the 4 servers
colmena apply-local # rebuild the local workstation (e-desktop / e-laptop)
colmena apply --on anton # a single node- Scope: the 6 e-owner nodes (v-devices excluded for now).
The headless servers are
pushed over SSH; the two workstations deploy locally (
apply-local, which also sidesteps e-laptop's dynamic IP). - Auth: a key-only
deployuser (systemOptions.services.deploy.enable) with scoped NOPASSWD sudo (only the activation commands) and nix trusted-user. Connections jump through theserver-mubastion via the*-deploySSH aliases, so deploys work on- and off-LAN. - Bootstrap: the
deployuser is created by this config, so a brand-new server must be switched once by other means before Colmena can take it over.
init-dev-env # General development
init-latex-env # LaTeX
init-geant4-env # Geant4 physics simulation
init-analysis-env # ROOT analysis using custom library- Switch from nix-colors to base16.nix since that is actually maintained
- Move geant4 development environment into its own repo as a flake
- Expose nixvim configuration as a runnable package (
nix run) - Set up multi-model LLM infrastructure with llama-swap + LiteLLM
- Add opencode AI assistant with fleet model access
- Create proper headless compositor sessions for remote access (Sunshine/Moonlight)
- Add screenshots to README
- Create live USB system configuration (with Calamares installer)