feat(hosts): make config multi-host and add vps host

Parametrize networking, users, and containers modules under
myNetworking/myUsers/myContainers so both hosts share the same logic
instead of duplicating it, and split desktop/server module imports
into modules/profiles/. Adds hosts/vps (not installed yet, hardware
config and bootloader device are placeholders) to run Traefik,
Headscale, Headplane, and Gitea via a combined Docker Compose stack.

Wires up agenix for secrets and migrates miku-homelab's WireGuard
private key off a plain filesystem path into an encrypted
secrets/miku-homelab-wg.age. The vps side of that tunnel still needs
its own key generated and encrypted after install.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
emmatherockandClaude Sonnet 5 committed 2026-08-12 00:07:55 -03:00
1 parent 26bfa56268
commit 42e60a3bb5
13 files changed
+695 -184

No files matched your search

+17 -1
View File
@@ -23,9 +23,13 @@
vscode-server.url = "github:nix-community/nixos-vscode-server";
llm-agents.url = "github:numtide/llm-agents.nix";
nix-vscode-extensions.url = "github:nix-community/nix-vscode-extensions";
agenix = {
url = "github:ryantm/agenix";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = { self, nixpkgs, apple-fonts, home-manager, plasma-manager, sidra, vscode-server, nix-vscode-extensions, ... }@inputs: {
outputs = { self, nixpkgs, apple-fonts, home-manager, plasma-manager, sidra, vscode-server, nix-vscode-extensions, agenix, ... }@inputs: {
nixosConfigurations = {
miku-homelab = nixpkgs.lib.nixosSystem {
system = "x86_64-linux";
@@ -36,6 +40,7 @@
home-manager.nixosModules.home-manager
inputs.nix-flatpak.nixosModules.nix-flatpak
vscode-server.nixosModules.default
agenix.nixosModules.default
{
nixpkgs.overlays = [
inputs.nix-vscode-extensions.overlays.default
@@ -53,6 +58,17 @@
}
];
};
vps = nixpkgs.lib.nixosSystem {
system = "x86_64-linux";
specialArgs = { inherit inputs; };
modules = [
./hosts/vps
vscode-server.nixosModules.default
agenix.nixosModules.default
];
};
};
};
nixConfig = {