Skip to content

Repository files navigation

bphenriques's fleet

Nix Flakes selfhost-nix NixOS Install License: MIT

Hi! 👋 This is how I manage my fleet with NixOS, including a self-hosted homelab running many services with SSO, a reverse proxy, monitoring, and automated off-site encrypted backups (see selfhost-nix and compute's architecture). I hope this helps you!

Hosts

Host Platform Description
laptop NixOS Personal laptop
compute NixOS Compute headless server
storage NixOS Headless NAS
ai NixOS Headless AI inference
share-vm NixOS microVM Private file sharing service exposed only via Tailscale Funnel
cv-vm NixOS microVM Public landing page exposed only via Cloudflare Tunnel
agent-vm NixOS microVM Private AI assistant
phone-android Android Termux client
inky Raspberry Pi Raspberry Pi Zero 2W connected to Inky Screen and speakers

Nix Stack

Layout:

  • hosts/: per-host configurations (hardware, services, users)
  • modules/: personal NixOS/home-manager modules (the selfhost.* framework lives in selfhost-nix)
  • profiles/: shared opinionated configuration that sets standard options (imported by hosts)
  • packages/: custom packages and scripts
  • lib/: custom helpers and builders
  • apps/: runnable scripts (installation, post-install)

Key dependencies:

  • disko for declarative disk partitioning
  • stylix for consistent theming
  • sops-nix for secrets
  • nixos-anywhere for remote installations
  • selfhost-nix personal flake that does the heavy-lifting when it comes to self-hosting (reverse Proxy, OIDC, and secrets)
  • dotfiles-private private dependency to store private information (SOPS secrets, personal information, and wallpapers)
  • infra that setups my Cloudflare account through IaC.

Not using flake-utils or impermanence intentionally.

dot cli

Using a personal wrapper to manage both local and remote machines called dot:

dot . s              # build, preview changes, and apply to the current host
dot . b              # build and preview changes without applying
dot . u              # update flake inputs
dot . c              # show changelog between last two local profiles
dot compute s        # deploy to the compute host remotely
dot compute c        # show changelog for the compute host

AI Disclaimer

AI was used from January 2026 onwards, starting with the compute host to learn and iterate faster. I drive the architecture, review and verify the changes.

Acknowledgements

Thanks to everyone sharing dotfiles, maintaining the Arch Wiki and NixOS Wiki, and helping in the NixOS community.