Adopt the convention that a Module's option path mirrors its directory under modules/, with an index file naming the directory's own segment. - Group agent Modules under modules.agents.*: claude-code (whole directory), pi (flattened to a file), skills (renamed from agent-skills), and gitea-axi under an agents/tools/ subgroup. The agents/ and tools/ folders are pure namespace prefixes with no aggregator enable. - Nest hypridle and hyprlock under modules.desktop.hyprland.*, with hyprland.nix as the index, and update the desktop aggregator. - Remove the obsolete example Module. - Record the convention in CONTEXT.md and ADR 0004, and update the neogaia host, the two live CLAUDE.md gotchas, and the skills Module's intentional Enable-convention exception comment.
71 lines
2.2 KiB
Nix
71 lines
2.2 KiB
Nix
{
|
|
config,
|
|
lib,
|
|
pkgs,
|
|
...
|
|
}:
|
|
# Claude Code for the primary user, configured through home-manager, which ships
|
|
# the package and manages ~/.claude. Login credentials are left unmanaged so they
|
|
# survive rebuilds.
|
|
let
|
|
cfg = config.modules.claude-code;
|
|
user = config.user.name;
|
|
in
|
|
{
|
|
options.modules.claude-code.enable = lib.mkEnableOption ''
|
|
Claude Code, Anthropic's CLI, configured via home-manager.
|
|
|
|
Enabling this also widens sudo's credential cache, keying it per user rather
|
|
than per terminal and holding it for 60 minutes, so that a single
|
|
authentication covers commands the agent issues. No command is made
|
|
passwordless, but any process running as the primary user can spend the
|
|
cached credential while it lasts. Suitable for a single-user machine'';
|
|
|
|
config = lib.mkIf cfg.enable {
|
|
# Keying sudo's credential cache per user rather than per terminal lets one
|
|
# authentication cover commands issued by processes holding no terminal of
|
|
# their own. Any process running as this user can spend that credential
|
|
# until it lapses, so this suits a single-user machine.
|
|
security.sudo.extraConfig = ''
|
|
Defaults timestamp_type=global
|
|
Defaults timestamp_timeout=60
|
|
'';
|
|
|
|
home-manager.users.${user} = {
|
|
# jq parses the tool input handed to the sudo guard hook.
|
|
home.packages = [ pkgs.jq ];
|
|
|
|
programs.claude-code = {
|
|
enable = true;
|
|
|
|
# Global agent instructions, rendered to ~/.claude/CLAUDE.md.
|
|
context = ./CLAUDE.md;
|
|
|
|
# One directory per skill, symlinked under ~/.claude/skills.
|
|
skills = ./skills;
|
|
|
|
# Installed under ~/.claude/hooks, referenced by the settings below.
|
|
hooks."agent-sudo-guard.sh" = builtins.readFile ./hooks/agent-sudo-guard.sh;
|
|
|
|
settings = {
|
|
model = "opus";
|
|
hooks = {
|
|
PreToolUse = [
|
|
{
|
|
matcher = "Bash";
|
|
hooks = [
|
|
{
|
|
type = "command";
|
|
command = "~/.claude/hooks/agent-sudo-guard.sh";
|
|
timeout = 10;
|
|
}
|
|
];
|
|
}
|
|
];
|
|
};
|
|
};
|
|
};
|
|
};
|
|
};
|
|
}
|