Cross-platform dotfiles managed with Nix, Nix Darwin, and Home Manager. Supports macOS and Linux with host-specific configurations.
- Nix (multi-user/daemon install, with flakes
enabled — or just run
./install.sh, which handles both)
On a bare machine (installs Nix, clones the repo, applies the configuration):
curl -fsSL https://raw.githubusercontent.com/mpriscella/dotfiles/main/install.sh | bashOn a machine that already has Nix:
nix run github:mpriscella/dotfiles#installOr manually (the clone path matters: programs.nh sets NH_FLAKE to
~/workspace/mpriscella/dotfiles, so nh finds the flake from any directory
only if the checkout is there):
git clone https://github.com/mpriscella/dotfiles.git ~/workspace/mpriscella/dotfiles
cd ~/workspace/mpriscella/dotfiles
nix develop
# macOS (nix-darwin)
darwin-rebuild switch --flake .#<hostname>
# Linux (home-manager only)
home-manager switch --flake .#<configuration-name># Apply configuration changes
darwin-rebuild switch --flake .#<hostname> # macOS
home-manager switch --flake .#<configuration> # Linux
# Test before applying
home-manager build --flake .#<configuration>
nix flake check
# Update dependencies
nix flake update
# Enter development shell
nix develop
# Format Nix code (scope paths to avoid recursing into nvim cache dirs)
nix fmt flake.nix home-manager nix-darwin| Topic | Description |
|---|---|
| Nix Flakes | Flake structure, configurations, and switching between setups |
| Secrets Management | sops-nix setup, adding secrets, and token rotation |
| GPG Signing | GPG key generation and Git commit signing |
| Infrastructure | Terraform, Helm, and Kubernetes YAML in Neovim |
| Zig | Toolchain management and pinning Zig per project (zig-overlay) |
| Slidev | Per-deck markdownlint/prettier config for Slidev projects |
Flake templates live in mpriscella/nix-templates.
A flake registry alias (nix.registry.templates in home-manager/home.nix)
shortens usage to:
nix flake init -t templates#<template>To see the available templates:
nix flake show templates| Configuration | System | Username |
|---|---|---|
macbook-pro-m5 |
aarch64-darwin | mpriscella |
| Configuration | System | Username |
|---|---|---|
linux |
x86_64-linux | mpriscella |
linux-arm |
aarch64-linux | mpriscella |
A deliberately small profile: Neovim and its language servers, fish, starship,
git, and jj — no secrets, no GPG signing, no cloud tooling. install.sh picks
it automatically when $CODESPACES is set.
| Configuration | System | Username |
|---|---|---|
codespaces |
x86_64-linux | codespace |
codespaces-arm |
aarch64-linux | codespace |
The username must match the container's user. The GitHub-provided Codespaces
images run as codespace; a devcontainer that runs as vscode or node needs
its own entry in flake.nix.
Nothing here changes the container's login shell — that stays bash. Instead
install.sh appends a marked block to ~/.bashrc that puts ~/.nix-profile/bin
on PATH and then execs fish for interactive shells. Without it the VS Code
terminal starts bash interactive-but-not-login, which never reads the profile
hook the single-user Nix installer wrote to ~/.profile, so nothing the
configuration installs is callable. Delete the block for plain bash; bash
started from fish stays bash.
.
├── flake.nix # Flake definition and configurations
├── home-manager/ # Home Manager modules
│ ├── home.nix # Main home configuration
│ ├── codespaces.nix # Minimal profile for Codespaces / dev containers
│ ├── modules/ # Cross-profile modules (neovim, php)
│ └── programs/ # Program-specific configs
├── nix-darwin/ # nix-darwin system configuration
├── config/ # Application configs (nvim, ghostty, etc.)
├── agents/ # Claude Code subagent definitions
├── skills/ # Claude Code skill definitions
├── secrets/ # Encrypted secrets (sops)
└── docs/ # Documentation