dotfiles-NixOS
The one declarative host. nix owns the packages, PATH and the login-shell declaration (nixos-rebuild + home-manager); bootstrap.sh installs nothing and only wires the links.
Highlights
- nixos-rebuild
- home-manager
- declarative
- installs nothing
How it fits
The OS-native layer — Package manager, paths, clipboard — what changes with the OS. It builds on Core, which is vendored into its core/ directory. See the three-layer model for how the layers compose.
Getting started
git clone https://github.com/dotgibson/dotfiles-NixOS ~/dotfiles-NixOS
# import ~/dotfiles-NixOS/nix/nixos.nix from configuration.nix, then:
sudo nixos-rebuild switch
home-manager switch # the package set, PATH and tpm
cd ~/dotfiles-NixOS
./bootstrap.sh # only now, the links
exec zshOrder matters: nix first, bootstrap last. bootstrap.sh never escalates and never runs chsh. Flags: --dry-run (preview, change nothing), --links-only (skip the report-only host probe), --only / --skip module selection.
What actually bites
- Two owners, one boundary — nix/ owns the package set, PATH, tpm and the login-shell declaration; bootstrap.sh owns every link and the zsh entry. The fleet's only PROVISIONER=declarative host — packages-check is a stub by design.
- Don't let home-manager claim the links — nix/home.nix must not declare home.file or programs.zsh for anything the driver links — two owners of one path and home-manager activation deadlocks.
- The shell is declared, not chsh'd — nix/nixos.nix enables programs.zsh (which puts zsh in /etc/shells) and carries the users.users.<you>.shell = pkgs.zsh line for you to set; the bootstrap prints that declaration at the end instead of changing the shell itself.
- Channels or flakes — nix/README.md tracks the nixos-25.05 and home-manager release-25.05 channels; flake users skip the channel step and import the same modules.