Fills in the real vps host key (replacing the install placeholder) and
registers vps-wg.age for agenix. Also adds Emma's NixOS-machine SSH key
as an admin decrypt key and to the vps host's authorizedKeys.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Replaces the placeholder with the actual output of
nixos-generate-config from the installed VPS (real disk UUIDs,
qemu-guest profile, virtio kernel modules).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
modules/system/packages.nix now exposes myPackages.extra so hosts can
add their own tools on top of the always-installed core set, instead
of hardcoding every host's packages in one shared list.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Parametrize networking, users, and containers modules under
myNetworking/myUsers/myContainers so both hosts share the same logic
instead of duplicating it, and split desktop/server module imports
into modules/profiles/. Adds hosts/vps (not installed yet, hardware
config and bootloader device are placeholders) to run Traefik,
Headscale, Headplane, and Gitea via a combined Docker Compose stack.
Wires up agenix for secrets and migrates miku-homelab's WireGuard
private key off a plain filesystem path into an encrypted
secrets/miku-homelab-wg.age. The vps side of that tunnel still needs
its own key generated and encrypted after install.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>