Parametrize networking, users, and containers modules under
myNetworking/myUsers/myContainers so both hosts share the same logic
instead of duplicating it, and split desktop/server module imports
into modules/profiles/. Adds hosts/vps (not installed yet, hardware
config and bootloader device are placeholders) to run Traefik,
Headscale, Headplane, and Gitea via a combined Docker Compose stack.
Wires up agenix for secrets and migrates miku-homelab's WireGuard
private key off a plain filesystem path into an encrypted
secrets/miku-homelab-wg.age. The vps side of that tunnel still needs
its own key generated and encrypted after install.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Configure a wg-miku-homelab interface peering with the external VPS
endpoint, and allow ports 80/443 through the firewall alongside the
existing service ports.
Add the plasma-manager flake input and wire it into home-manager,
along with a custom breeze-enhanced KWin decoration package, KDE
config (fonts, cursor theme, window rules), and .desktop entries
for OBS/volctl/Warudo shortcut scripts.
Flatpak >=1.18.0 leaks the NixOS host environment into the sandbox,
breaking glycin-svg icon loading (e.g. OpenDeck). Pin services.flatpak.package
to a nixpkgs-flatpak input locked to a revision with Flatpak 1.16.6, scoped
to the Flatpak service only, until flatpak/flatpak#6721 lands in nixpkgs.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>