feat: declare locked NixOS development host

Declare dev, scoped sudo/SSH, workspace ownership, Git and Neovim. Lock Nixpkgs, Home Manager and the unmodified dotfiles. Deploy user files declaratively and preserve a writable Lazy lockfile.

Nix formatting and pure flake evaluation pass. Full build, empty-home deployment tests and activation of this reproducibility correction are still pending; the previous account baseline is live.
This commit is contained in:
Coding Agent
2026-09-04 23:03:22 +00:00
commit 69bc45bbf0
10 changed files with 330 additions and 0 deletions
+26
View File
@@ -0,0 +1,26 @@
{ inputs, modulesPath, ... }:
{
imports = [
# Keep the image's EC2 boot, storage, metadata, SSH and SSM integration.
"${modulesPath}/virtualisation/amazon-image.nix"
./users.nix
./tools.nix
./neovim.nix
];
nixpkgs.hostPlatform = "x86_64-linux";
nix = {
channel.enable = false;
settings.experimental-features = [
"nix-command"
"flakes"
];
};
system.configurationRevision = inputs.self.rev or inputs.self.dirtyRev or null;
# Initial data/default compatibility, not the desired package release.
system.stateVersion = "26.05";
}