Commit Graph
100 Commits
Author SHA1 Message Date
kyle 6ff6c997fd ollama -> vulkan 2026-06-24 11:23:23 -07:00
kyle 240ab7d50a nix maintainers lacking 2026-06-23 17:49:15 -07:00
kyle 6a8bbc4da5 flake update 2026-06-23 16:58:56 -07:00
kyle b3a52dc12b move ffmpeg to light 2026-05-28 06:40:07 -07:00
kyle 6670b1cf50 add platformio 2026-05-05 13:21:17 -07:00
kyle 18bcf5d1e7 update lector 2026-04-14 15:06:55 -07:00
kyle a99542aa50 add sox
claude code uses this for voice input
2026-04-14 14:59:58 -07:00
kyle dfc21b359c use firefox as default 2026-04-07 11:58:40 -07:00
kyle 4c29c7dabf flake updates 2026-04-07 10:00:54 -07:00
kyle 2cb9704dac discord 2026-04-07 09:27:29 -07:00
kyle 2b5a691ecf add chromium to packages
need for webusb things
2026-04-06 08:36:42 -07:00
kyleandClaude Opus 4.6 77e69e0b86 Set mutableUsers to false so hashedPassword is enforced on every rebuild
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-04 17:19:55 -07:00
kyle d4963c571a ollama 2026-04-04 16:19:16 -07:00
kyle 3b59f3cae4 wireless tools for i3blocks 2026-04-04 16:19:16 -07:00
kyleandClaude Opus 4.6 768e9a61dc Add svc host: NixOS config for TornadoVPS edge node
BIOS boot with GRUB on /dev/xvda, MCP agent via systemd,
mc-proxy and MCNS as containers via MCP agent.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-04 15:21:01 -07:00
kyleandClaude Opus 4.6 e1600e19e7 Use hashed password instead of initial plaintext password for kyle user
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 11:57:37 -07:00
kyleandClaude Opus 4.6 6fd8ab61ed Fix orion build: remove nonexistent "crypted" LUKS device reference
The LUKS device is named "luks-5c5e94fc-..." in hardware-configuration.nix
which already has the FIDO2 options. The "crypted" reference caused a build
error. Also fix duplicate attribute definitions and unnecessary config wrapper.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 11:30:04 -07:00
kyleandClaude Opus 4.6 6733e92d1f Update CA cert after Metacrypt re-initialization
New root CA cert issued during Metacrypt vault rebuild. Same key
usage (Certificate Sign, CRL Sign), new validity period (2026-2046).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 10:07:54 -07:00
kyleandClaude Opus 4.6 adca98065f Update CA cert with CRL Sign key usage
Same key, added CRL Sign to key usage extensions. Distributed to
all nodes and NixOS system trust store.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 09:54:05 -07:00
kyleandClaude Opus 4.6 3be5613120 Fix deprecated NixOS options for 25.11
- Use nixpkgs.hostPlatform module instead of deprecated system arg to lib.nixosSystem
- Rename services.logind.powerKey to services.logind.settings.Login.HandlePowerKey

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 09:53:25 -07:00
kyle b6aa8346f5 update mcp 2026-04-03 09:37:36 -07:00
kyleandClaude Opus 4.6 47b4e533ff Document UID 850 as permanent — never change
Rootless podman deeply caches the UID in storage, subuid mappings,
and systemd sessions. Changing it destroys all container state.
Reference: log/2026-04-03-uid-incident.md

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 09:30:37 -07:00
kyleandClaude Opus 4.6 5d82e27ba4 Add fallback DNS resolvers to all nodes
All nodes now list 1.1.1.1 and 8.8.8.8 as fallback nameservers after
MCNS. When MCNS is down, internal names (.svc.mcp.metacircular.net)
fail but external DNS (google.com, github.com, etc.) keeps working.

Lesson from 2026-04-03 incident: without fallbacks, MCNS failure
caused total DNS blackout including external services, forcing
Tailscale to be disabled to restore any DNS resolution.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 09:30:09 -07:00
kyleandClaude Opus 4.6 5a381d314e Pin mcp user UID/GID to 850
UID 995 conflicted with sshd on orion. Pin to 850 (the 800-899 range
is unused on all nodes and well below NixOS auto-assign range).
Pin GID to 850 as well for consistency.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 01:38:45 -07:00
kyleandClaude Opus 4.6 53addc0ed1 Remove pinned UID for mcp user
UID 995 conflicted with sshd on orion. Let NixOS auto-assign the UID
for the mcp system user. Use systemd's %U specifier for XDG_RUNTIME_DIR
instead of the hardcoded UID.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 01:33:37 -07:00
kyleandClaude Opus 4.6 755450e72e fix orion: remove bogus "crypted" LUKS device reference
The FIDO2 crypttab options are already on the correct UUID-named device
in hardware-configuration.nix; the "crypted" name only applies to
disko-provisioned hosts (rift).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 01:00:19 -07:00
kyleandClaude Opus 4.6 5fd00af73c fix orion: remove duplicate top-level networking/services attrs
The module used explicit `config = { ... }` but also had duplicate
networking.nameservers and services.resolved.domains at the top level,
causing a NixOS module evaluation error. Merged the Tailscale nameserver
into the config block and removed the duplicates.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 00:03:58 -07:00
kyleandClaude Opus 4.6 6a65e73200 Remove mcp-master systemd unit (now containerized)
The master runs as an MCP-managed container, deployed via
mcp deploy mcp-master --direct. The systemd unit was a temporary
bootstrap mechanism.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-02 22:56:08 -07:00
kyleandClaude Opus 4.6 b26478d47b Add mcp-master systemd service
Runs the MCP v2 master as a systemd service on rift. Uses
ConditionPathExists so the unit is a no-op on worker nodes
(like orion) that import mcp.nix but don't have the binary.

Starts after mcp-agent.service. Security hardened like the agent
but with ProtectHome=true (master doesn't need /run/user).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-02 20:43:38 -07:00
kyle dba2fb00eb update mc packages 2026-04-02 20:43:38 -07:00
kyle 246674369d updated packages 2026-04-02 20:33:24 -07:00
kyle 63bb945506 add opencode to full desktop packages 2026-04-02 17:10:04 -07:00
kyle 9be8f2d8d1 syncthing should run as a user 2026-04-02 16:07:59 -07:00
kyle 9972422fe6 package cleanup 2026-04-02 12:53:17 -07:00
kyle 9310dc0041 add new framework config 2026-04-02 12:43:06 -07:00
kyleandClaude Opus 4.6 de5178747d add straylight emergency recovery script
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-02 00:23:04 -07:00
kyleandClaude Opus 4.6 453947ac7b fix straylight /home LUKS: use initrd instead of crypttab
Replace fragile environment.etc.crypttab.text with
boot.initrd.luks.devices for the second SSD, matching
the pattern used for the root drive.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-02 00:12:14 -07:00
kyle a8e43936cf pass #2
following random blogs doesn't always work
2026-04-01 23:53:00 -07:00
kyle 0e9f6d890e straylight hardware 2026-04-01 20:32:08 -07:00
kyle 33f364f12f update mcr 2026-04-01 19:41:41 -07:00
kyle 8ac759b1cf update mcr (for mcrctl) 2026-04-01 18:58:52 -07:00
kyle 0f1f0dcc78 Adding straylight. 2026-04-01 12:39:44 -07:00
kyle fdd7104504 update kte and lector 2026-03-31 14:22:05 -07:00
kyle 101151cdb8 exfatprogs 2026-03-30 22:12:54 -07:00
kyle 16f1d0829c add easytag 2026-03-30 20:36:18 -07:00
kyle 5a0c22f0f7 update mcp 2026-03-30 17:46:40 -07:00
kyle 2abcc39539 really undunst 2026-03-30 17:33:26 -07:00
kyle 316b00cda3 update mcp 2026-03-30 17:32:00 -07:00
kyle 194e36c5de ntfy support 2026-03-30 14:59:35 -07:00
kyle c268ff48b4 adding gvfs 2026-03-30 13:28:15 -07:00
kyle c26f5b9a87 ignore power key on vade 2026-03-30 13:04:53 -07:00
kyle ab66200fe1 update sgard 2026-03-30 09:54:22 -07:00
kyle 62e56188b2 dumbo 2026-03-30 09:19:19 -07:00
kyle e538aa083b moving deja-dup 2026-03-30 09:17:38 -07:00
kyle 7ac4f2e3f2 enable dconf 2026-03-30 09:16:49 -07:00
kyle 66900d9ce6 add deja-dup 2026-03-30 08:23:04 -07:00
kyle efeefb51b3 update mcp 2026-03-29 19:12:03 -07:00
kyle 95e6315ddf update mcp 2026-03-29 18:55:42 -07:00
kyle c2882fcd8b allow mcp to read systemd logs 2026-03-29 18:00:48 -07:00
kyle 07a9463097 update mcp 2026-03-29 17:51:19 -07:00
kyle c9e061d319 update mcp 2026-03-29 17:38:15 -07:00
kyle 5a7164bd20 update mcp 2026-03-29 17:37:45 -07:00
kyle 8f49ba4cf2 update mcp 2026-03-29 17:37:45 -07:00
kyle 4827c6aa20 update mcp 2026-03-29 17:37:45 -07:00
kyle 6238a33b60 Updating README. 2026-03-29 14:58:38 -07:00
kyle d145c69932 update mcp 2026-03-28 19:24:40 -07:00
kyle 947f895bc5 update mcp 2026-03-28 18:24:06 -07:00
kyle 495d715ed7 update mcp 2026-03-28 18:05:28 -07:00
kyle ec01be81d3 update mcp 2026-03-28 17:20:47 -07:00
kyleandClaude Opus 4.6 34b2a01f1a Use /srv/mcp/mcp-agent binary instead of Nix flake input
The agent binary is now managed by the operator (scp + install to
/srv/mcp/mcp-agent), not by the Nix flake. This allows agent upgrades
without a full NixOS rebuild.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-28 16:12:51 -07:00
kyleandClaude Opus 4.6 59ac363c45 Trust WNTRMUTE CA for podman registry connections
Podman/skopeo don't use the system CA bundle for registry TLS — they
use /etc/containers/certs.d/<host:port>/ca.crt. Add the WNTRMUTE CA
there so podman push/pull to MCR works without --tls-verify=false.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-28 16:01:47 -07:00
kyle 2b8d2b980c update mcp 2026-03-28 16:01:46 -07:00
kyle a4104eb602 Update MCP to v0.6.0+1 (uptime fix) 2026-03-27 22:57:05 -07:00
kyle a34b3e96f7 dos2unix 2026-03-27 22:39:27 -07:00
kyle 47f9e48346 add tools for dealing with corrupt (color) text 2026-03-27 22:26:53 -07:00
kyle d70a0d667c update mc tools 2026-03-27 21:56:33 -07:00
kyle de314be83e update mcp 2026-03-27 21:14:23 -07:00
kyle 42a503db62 add skopeo 2026-03-27 16:56:50 -07:00
kyle 30c8f5f2fb update mcp 2026-03-27 16:50:48 -07:00
kyle 6915023d4f update mcp 2026-03-27 16:16:31 -07:00
kyle 094ccfd29d update mcp 2026-03-27 15:06:10 -07:00
kyle cdbdee5b48 mcp 2026-03-27 14:37:47 -07:00
kyle 83684ddb1c bind dns tools 2026-03-27 13:59:11 -07:00
kyleandClaude Opus 4.6 74a79cd369 Rework Makefile with install/link/update targets and auto-generation
Add gen-update-targets.sh to parse flake.nix and generate grouped
update targets (update-kyle, update-mc). Makefile now has install
(copy) and link (symlink) targets for rebuild-nixos. Also fix mc
flake input URLs to use /mc/ org path.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-27 01:49:58 -07:00
kyle c394eec89f adding mc tooling 2026-03-26 22:59:09 -07:00
kyleandClaude Opus 4.6 c0e0cefad3 Fix MCP flake URL: use git+https to match other inputs
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 22:53:06 -07:00
kyle 60ee30045b Update README. 2026-03-26 22:51:49 -07:00
kyleandClaude Opus 4.6 baf09e8b1f Add MCP to Nix packages and wire agent to Nix-managed binary
- Add mcp flake input (git+ssh://git@git.wntrmute.dev/mc/mcp.git)
- Add mcp CLI to mcpkg.nix system packages (installed on all machines)
- Update mcp.nix to use Nix-managed mcp-agent binary path instead of
  hardcoded /usr/local/bin/mcp-agent

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 22:48:40 -07:00
kyle 67ced96f4d update lector 2026-03-26 21:59:37 -07:00
kyleandClaude Opus 4.6 a1c59deb0b Disable Tailscale DNS management on vade to fix DNS timeout
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 21:54:00 -07:00
kyle c0d16c97e0 revert dns bugs 2026-03-26 21:38:05 -07:00
kyleandClaude Opus 4.6 8c9d8f4ff5 Fix DNS: restore Tailscale catch-all removal service
The previous commit removed the systemd service that stripped Tailscale's
~. DNS catch-all, breaking all DNS resolution — even when Tailscale is
disconnected. Restore it as fix-tailscale-dns, which restricts tailscale0
to only route ~scylla-hammerhead.ts.net queries.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 21:32:15 -07:00
kyle 0e54bd5fe7 Use /etc/hosts for internal Metacircular names (Tailscale DNS workaround) 2026-03-26 15:41:30 -07:00
kyle ad3b6b949b Fix: add pkgs to vade module arguments 2026-03-26 15:37:53 -07:00
kyle c8b271d6b9 Fix DNS routing: override Tailscale catch-all for mcp.metacircular.net 2026-03-26 15:35:47 -07:00
kyle e7d244c606 Disable ProtectHome for mcp-agent (blocks /run/user for podman) 2026-03-26 14:40:54 -07:00
kyle 7f0a978e86 Relax mcp-agent sandbox for rootless podman compatibility 2026-03-26 14:34:50 -07:00
kyle bac757c22e Allow mcp-agent access to /run/user for rootless podman 2026-03-26 14:31:33 -07:00
kyle 57cab0c88a Pin mcp UID, fix XDG_RUNTIME_DIR for podman access 2026-03-26 14:08:57 -07:00
kyle 71e6907a3c Add PATH to mcp-agent service for podman access 2026-03-26 14:04:52 -07:00