Sakhalin — Fedora Workstation + Determinate Nix
Sakhalin is intended to become a Fedora Workstation family machine. Fedora owns its packages, desktop, and networking; Determinate Nix provides Nix and standalone Home Manager manages the small shared user configuration.
Bootstrap
After Fedora is installed, run as vincent:
bash imperative/sakhalin/bootstrap.sh
The script installs Nix when necessary, obtains ~/src/home, deploys generated
/etc/hosts, /etc/nix/nix.custom.conf, and /etc/wireguard/wg0.conf, enables
wg-quick@wg0, and activates vincent@sakhalin through Home Manager.
WireGuard is enabled but not started by the bootstrap. Restore the preserved
private key with mode 0600, then start it:
sudo install -m 0600 /path/to/private.key /etc/wireguard/private.key
sudo systemctl start wg-quick@wg0.service
Routine updates
make host/sakhalin/build
make host/sakhalin/switch
host/sakhalin/switch deploys the generated host files with sudo, then switches
Home Manager. It does not start WireGuard.
Managed configuration
systems/sakhalin/gen-configs.nixgenerates the small Fedora host-file set.systems/sakhalin/home.nixomits the NixOS-only mail services for the standalone profile.- WireGuard private-key material remains outside the repository and Nix store.