Personal NixOS configuration managing multiple machines using Nix Flakes and flake-parts.
| Host | Role | Hardware | Status |
|---|---|---|---|
| galactica | Main server (media, databases, backups) | Intel i5-1340P, 12c/16t, 32GB, ~45TB | Online |
| basestar | Public-facing services (*.arsfeld.dev) |
ARM Neoverse-N1, 4c, 24GB (Oracle Cloud) | Online |
| router | Network router | Intel N5105, 4c, 8GB | Offline |
| r2s | Backup router + home automation | Rockchip RK3328 ARM, 4c, 1GB | Offline |
| pegasus | Secondary server | Intel i5-4430, 4c, 16GB, ~18TB | Online |
| Host | Role | Status |
|---|---|---|
| octopi | OctoPrint | Offline |
| raspi3 | Raspberry Pi 3 | Offline |
| cylon-link | Valve Steam Link, always-on helper | Online |
| Host | Role | Hardware | Status |
|---|---|---|---|
| raider | Desktop (GNOME, gaming, dev) | i5-12500H, RX 6650 XT, 32GB, ~4TB | Online |
| blackbird | ASUS ROG Zephyrus G14 laptop | - | Active |
See HARDWARE.md for detailed disk and CPU specs.
Hosts are grouped into deployment tiers (defined in flake-modules/hosts.nix as tiers):
| Tier | Hosts | Meaning |
|---|---|---|
| tier1 | galactica, basestar, raider | Always on, should always be deployed |
Tiers are exposed as @tier selectors, so you can deploy a whole tier at once:
just deploy @tier1 # deploy all tier-1 hosts- Modular Architecture - Opt-in constellation modules for services, media, backups, observability, and more
- Auto-Discovery - Hosts and modules loaded automatically via haumea
- Service Registry - Centralized port assignments, auth bypass, Tailscale exposure, and CORS config
- Container Orchestration - Podman/Docker-based media stack with declarative volume and network config
- DNS & Routing -
*.arsfeld.one(internal via cloudflared),*.arsfeld.dev(public),*.bat-boa.ts.net(Tailscale) - Automated Deployments - Two-phase nix-fast-build pipeline (parallel eval, build, niks3 push, then parallel activation), nixos-rebuild fallback
- Secret Management - sops-nix with per-host and shared secrets
- Binary Caching - niks3 coordinator with a Cloudflare R2 read path (
cache.arsfeld.dev) - Infrastructure as Code - Oracle Cloud tenancy and Cloudflare DNS zones managed via OpenTofu, written in Nix with terranix (see CLAUDE.md)
- Remote Builders - aarch64 builds via basestar host
- Declarative Everything - Including disk partitioning (disko)
- CI/CD - GitHub Actions builds all hosts, pushes to niks3, weekly flake updates
# Enter development shell
nix develop
# Deploy to one or more hosts
just deploy galactica
just deploy galactica basestar
# Build locally without deploying
just build <hostname>
# Fresh install on new hardware
just install <hostname> <target-ip>
# Format all Nix files
just fmt
# Plan/apply the Oracle Cloud + Cloudflare DNS infrastructure
just tf plan
just tf applyflake.nix # Flake entry point (nixpkgs-25.11, flake-parts)
flake-modules/ # Flake-parts modules
lib.nix # Core utilities, haumea loaders, overlays
hosts.nix # Auto-discovers hosts from hosts/ directories
deploy.nix # deployTargets: per-host system closures
dev.nix # Development shell
checks.nix # Pre-commit hooks, formatter
images.nix # SD card, kexec, and installer ISO images
hosts/ # Per-host configurations (auto-discovered)
modules/ # All NixOS modules (auto-loaded by haumea)
constellation/ # Opt-in feature modules
services/ # Service group modules (media, home apps, network)
media/ # Media stack (config, gateway, components)
home/ # Home Manager configurations
packages/ # Custom Nix derivations (auto-loaded by haumea)
secrets/ # Encrypted secrets (sops/*.yaml)
Hosts compose their configuration by enabling modules via constellation.<module>.enable = true:
| Module | Purpose |
|---|---|
common |
Base config: Nix settings, caches, SSH, Tailscale, Avahi |
users |
User accounts, SSH keys, sudo |
sops |
sops-nix secret management |
docker / podman |
Container runtimes |
backup |
Automated rustic/restic backups |
gnome / cosmic / niri |
Desktop environments |
gaming |
Gaming environment (Steam, etc.) |
development |
Dev tools (Docker, Node, Python, Go, Rust) |
virtualization / project-vms |
KVM/libvirt VMs |
home-assistant |
Home automation |
vpn-exit-nodes |
Tailscale exit nodes via AirVPN/Gluetun |
observability-hub |
Central Prometheus/Loki hub |
metrics-client / logs-client / netdata-client |
Observability agents |
media-sync / tablet-sync |
File synchronization |
opencloud / email |
Cloud storage, email |
- Nix Flakes + flake-parts - Reproducible, modular configurations
- nix-fast-build - Parallel evaluation and build for deploys
- Home Manager - User environment management
- sops-nix - Secret management
- disko - Declarative disk partitioning
- haumea - Automatic module/package discovery
- niks3 - S3-backed binary cache with reference-tracking GC
- Tailscale - VPN mesh network
- OpenTofu + terranix - Oracle Cloud and Cloudflare DNS as Nix code
- CLAUDE.md - Development and deployment instructions
- HARDWARE.md - Hardware inventory and specs
Personal use. Feel free to take inspiration for your own configurations.