- add disko input; jupiter partitions/formats OS disk declaratively - hardware-configuration.nix carries kernel modules only (disko owns fileSystems) - data disk stays a plain unformatted mount, out of disko - vbox unchanged (virtualbox-image supplies its own disk) - README: nixos-anywhere remote install + daily rebuild loop Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
homelab
Flake-based NixOS config. Host: jupiter (ZimaBlade, NAS + services).
Structure
flake.nix # inputs (nixpkgs, disko) + nixosConfigurations
jupiter/configuration.nix # real host: imports + bootloader + data mount
jupiter/disk-config.nix # disko: OS-disk partitions + filesystems
jupiter/hardware-configuration.nix # PLACEHOLDER — kernel modules, regenerate on target
jupiter/services.nix # shared: users, ssh, samba, containers, caddy
jupiter/vm.nix # VirtualBox test image (jupiter-vbox)
Two configs from one service definition: jupiter (real host, disko-partitioned)
and jupiter-vbox (test OVA). Both import services.nix.
Test in VirtualBox (no hardware needed)
nix build .#nixosConfigurations.jupiter-vbox.config.system.build.virtualBoxOVA
VBoxManage import result/*.ova --vsys 0 --vmname jupiter-vbox
VBoxManage startvm jupiter-vbox --type headless
Login darman / test. Forward ports with VBoxManage modifyvm ... --natpf1.
First install on the ZimaBlade — nixos-anywhere + disko
Wipes the OS disk and installs the flake over SSH. No USB needed if the box already runs Linux (ZimaOS) reachable by root SSH — nixos-anywhere kexecs into an installer, partitions via disko, installs.
⚠️ The OS disk in
disk-config.nixis WIPED. Setdeviceto the OS disk ONLY (by-id). Back up / physically identify the NAS data disk first — it must NOT appear in disko.lsblk -o NAME,SERIAL,SIZE,MODELto identify.
- Set the real OS disk id in
jupiter/disk-config.nix(ls -l /dev/disk/by-id), and the data-disk mount inconfiguration.nix. - Add your SSH pubkey to
users.users.darman.openssh.authorizedKeys.keys. - Wire the samba secret (see Notes) — real password, not the VM's plaintext.
- Run from your laptop:
nix run github:nix-community/nixos-anywhere -- \ --flake .#jupiter \ --generate-hardware-config nixos-generate-config ./jupiter/hardware-configuration.nix \ --target-host root@<zimablade-ip>--generate-hardware-configpulls the target's real kernel modules into the placeholder for you. Commit the result. Reboot into NixOS.
Manual alternative (USB ISO): boot installer, disko the disk, then
nixos-install --flake .#jupiter.
Rebuild after changes (the daily loop)
# from laptop, build + activate on jupiter over SSH:
nixos-rebuild switch --flake .#jupiter \
--target-host darman@jupiter --use-remote-sudo
Rollback: nixos-rebuild switch --rollback, or pick a prior generation at boot.
Adding a service
Copy the whoami block in oci-containers.containers, swap image/ports/volumes.
Native NixOS module exists for many apps (Nextcloud, Jellyfin, Grafana...) —
prefer services.<app> over a container when available. Add a caddy
virtualHosts block to expose it.
Notes
- Backend is Podman with
dockerCompat—dockerCLI works, no daemon. - Samba keeps its own password DB.
services.sambanever sets it; a systemd oneshot (samba-smbpasswd) provisions it from/etc/samba/smb-password. Real host: supply that file via sops-nix / agenix, never commit plaintext. - Data disk: plain
fileSystems."/mnt/data"in configuration.nix — kept out of disko so it is never formatted. Reference byby-id/by-uuid. system.stateVersion=26.05, install-time schema. Do NOT bump on upgrades.- Terraform is not used: a single bare-metal box has no provider API. disko + nixos-anywhere cover provisioning natively.