Compare commits

..

86 Commits

Author SHA1 Message Date
alex 5d46cbde3f bd: update sync.remote
CI / check (push) Has been cancelled
2026-09-14 12:31:44 +03:00
alex 3ee46a6824 chore(beads): File marmel racy-test and nix build .#packages follow-ups 2026-09-14 12:31:39 +03:00
alex d74788a4cb feat(packages): Add marmel autonomous coding agent
Pin Na1w/marmel to commit fd551ae. Upstream publishes no tags or
releases, so the version uses the shape nix-update generates for a
tagless repository, keeping `nix-update --version=branch=main` usable.

The test suite runs green (325 lib tests plus all integration suites)
with two accommodations, both documented in the derivation:

- Export SSL_CERT_FILE from nixpkgs cacert. rustls refuses to construct
  a reqwest::Client without a system trust store, which failed 38 tests
  with "No CA certificates were loaded from the system".
- Serialise the test harness. The lib suite shares process-global worker
  registries and steer/abort buses, so manager-loop tests fail
  nondeterministically on parallel threads: one unchanged derivation
  produced 3 failures, then 1 failure, then 0 with --test-threads=1.
  No test is skipped or filtered.

Annotated example configs are installed to share/doc/marmel/examples/.
Role prompts are embedded via include_str!, so there is no runtime data
directory. Upstream README states MIT but ships no LICENSE file and no
Cargo.toml license field.
2026-09-14 12:31:39 +03:00
alex 4ec88a70ed chore(beads): close flake.lock refresh task 2026-09-14 01:18:53 +03:00
alex 3f868775af chore(flake): refresh nixpkgs inputs to 2026-09-11
Bump nixpkgs and nixpkgs-latest from 2026-05/2026-08 to current
nixos-unstable (2026-09-11); both inputs now resolve to the same rev.
Re-validated every package against the new inputs.

Fallout fixed:
- freetoken: upstream pins torch>=2.11,<2.12 and triton==3.6.0, but the new
  nixpkgs only ships torch 2.13 / triton 3.7. Add a nixpkgs-torch211 input
  pinned at the previous revision and build freetoken against it, keeping
  the CUDA 12.9 / torch 2.11 stack unchanged.
- graphify: nixpkgs' pybloomfilter3 0.7.3 ships sdist metadata that still
  says 0.7.2, tripping pythonMetadataCheckPhase; skip that check only.

All 22 packages build and `nix flake check --no-build` passes.
2026-09-14 01:18:49 +03:00
alex b5dfa1b08d chore(beads): close package-update task and record llama-cpp follow-up
CI / check (push) Has been cancelled
2026-09-13 21:17:57 +03:00
alex b9e759a2c1 chore(packages): bump packages to latest upstream versions
Update every package to its newest upstream release/commit:
- aionui 2.1.50 -> 2.2.2
- awg-tool 0.2.2 -> 0.3.0
- ds4 -> 0-unstable-2026-09-12
- freebuff 0.0.142 -> 0.0.174
- graphify 0.9.35 -> 0.9.61
- hipengine 0.3.0 -> 0.5.0
- mcp-gateway 3.4.0 -> 3.5.1
- omniroute 3.8.49 -> 3.8.50
- radar 1.9.1 -> 1.13.1
- relay-free-llm -> 0-unstable-2026-08-31
- traycer 1.1.10 -> 1.3.0

Refresh all source/dependency hashes (src, cargoHash, vendorHash,
npmDepsHash, bun FODs) and keep treefmt clean.

Packaging fixes required by the bumps:
- graphify: relax the setuptools>=83 build-backend pin (nixpkgs ships
  setuptools 80.x; the PEP 639 metadata needs only >=77).
- hipengine: add a llguidance 1.8.0 override (nixpkgs ships 1.7.x).
- omniroute: use npmDepsFetcherVersion 2; the v1 fetcher drops packages
  whose lockfile entries lack resolved URLs, breaking npm's cache check.
- radar: fix a frontend npmDepsHash/vendorHash swap from nix-update.

Packages already at latest are untouched: container-use, desloppify,
freetoken, kubernetes-mcp-server, loop, nftables-analyzer,
nftablesbuilder, stakpak, haivemind, skillsmcp. llama-cpp stays pinned
at b9645 and is tracked separately (manual HIP flag re-validation).
2026-09-13 21:06:04 +03:00
alex f9a45d14af chore(beads): close llama-cpp package issue
CI / check (push) Has been cancelled
2026-09-13 13:38:07 +03:00
alex 73f782d523 feat(packages): add llama-cpp b9645 for Strix Halo (ROCm + Vulkan)
Pin upstream llama.cpp b9645 and build it against the nixpkgs-latest
input (the flake's pinned nixpkgs only carries the pre-tools/ui b8983).
ROCm deps come from rocmPackages.gfx1151, so clr/rocBLAS/hipBLAS are
built for gfx1151 only; clr's own build is arch-independent, so its
store path stays substitutable. Vulkan on, CPU variants with znver5 /
AVX-512, web UI and npm toolchain dropped.

Ported from nixos-config's llm-engine.nix with two fixes: npmConfigHook
hard-fails when npmDeps is null, so nodejs and the hook are stripped
from nativeBuildInputs, and CMAKE_HIP_FLAGS is appended to
cmakeFlagsArray because the cmake hook word-splits plain cmakeFlags.

Verified on the Radeon 8060S (gfx1151): llama-bench loads both ROCm and
Vulkan backends and completes pp16/tg8 runs.
2026-09-13 13:33:30 +03:00
alex 3af2506bfd chore: Add logs/ to .gitignore
CI / check (push) Has been cancelled
2026-09-13 11:55:55 +03:00
alex f1d11c9ca8 chore(beads): file freetoken accel-extras follow-up issue
CI / check (push) Has been cancelled
2026-08-30 20:59:02 +03:00
alex ab88b09ceb feat(packages): add freetoken 0.1.2 NVIDIA MoE inference runtime
CI / check (push) Has been cancelled
Package FreeToken (FlashML-org/FreeToken) — edge-native MoE serving
engine with OpenAI/Anthropic-compatible APIs, serving the `ft` CLI.

- torch-bin 2.11 (CUDA 12.9 wheel build) satisfies the torch>=2.11,<2.12
  pin; extensions link the same cudaPackages.cuda_cudart via a synthetic
  CUDA_HOME (cudart headers + nvcc crt/ headers, no nvcc needed).
- flashlib==0.3.0 vendored from the PyPI wheel (Triton-only; freetoken
  never imports the CuTeDSL GEMM backends, so nvidia-cutlass-dsl is
  omitted via pythonRemoveDeps).
- apache-tvm-ffi overridden to the pinned 0.1.13.post3 with a vendored
  cython 3.3.0 (build needs >=3.2.8, nixpkgs has 3.2.4); pytest skipped
  (upstream runs pytest-xdist with GPU tests).
- Unfree (CUDA EULA) is self-scoped: the package re-imports nixpkgs with
  config.allowUnfree so no flake-level or user config change is needed.
- Optional accel extras (flashinfer/sglang-kernel) and the kernel-cache
  wheel are not packaged; runtime falls back to pure-Triton kernels.
- Verified: nix build .#freetoken, ft --version, python imports check,
  extension RPATHs.
2026-08-30 20:51:15 +03:00
alex e827a10680 fix(haivemind): clear blank Textual Select
CI / check (push) Has been cancelled
Textual 8 treats Select.BLANK as False, causing ConfigScreen to crash.
2026-08-20 14:37:26 +03:00
alex b8cb8908e7 fix(haivemind): restore deferred startup
CI / check (push) Has been cancelled
Start engine only after MainScreen mounts, while preserving explicit MainScreen widget lookup.
2026-08-20 14:22:54 +03:00
alex e8b2dfda36 fix(haivemind): query MainScreen instance directly instead of app default screen
CI / check (push) Has been cancelled
App.query_one searches the app's default screen (_default), but #chat-log/#health-bar/etc. live on the pushed MainScreen. Every HaivemindApp handler failed with NoMatches at runtime. Hold a reference to the MainScreen instance and query it directly so widget lookup no longer depends on which screen is active.
2026-08-20 13:38:39 +03:00
alex 42016cda27 fix(haivemind): start engine after MainScreen mounts
CI / check (push) Has been cancelled
2026-08-20 10:35:03 +03:00
alex 2c5e64039a fix(haivemind): start engine after MainScreen mounts to avoid NoMatches on #chat-log
Upstream haivemind_tui.py started the engine synchronously in HaivemindApp.on_mount while MainScreen mounts asynchronously, causing ProbeStart handler to query #chat-log on the default screen (NoMatches). Move the start_run trigger into MainScreen.on_mount so it runs only once the screen is active.
2026-08-20 10:33:57 +03:00
alex 7e7b884cc6 feat: add awg-tool package
CI / check (push) Has been cancelled
Rust CLI for AmneziaWG self-hosting from Vadim-Khristenko/awg-containers-and-tools: generates 1.0/1.5/2.0/3.0 obfuscation parameters, exports .conf and vpn:// configs, installs servers over SSH.
2026-08-08 21:13:31 +03:00
alex af91bad87b chore: close haivemind issue
CI / check (push) Has been cancelled
2026-08-08 19:36:56 +03:00
alex 7d89dac788 feat: add haivemind package 2026-08-08 19:36:35 +03:00
alex 824232aaa7 docs: note that no Dolt remote is configured
CI / check (push) Has been cancelled
2026-08-07 16:19:02 +03:00
alex f6d8485817 chore: note push-blocked state on nix-overlay-2gf
CI / check (push) Has been cancelled
2026-08-07 16:16:54 +03:00
alex 1f3f0f468b chore: update all packages to latest versions
CI / check (push) Has been cancelled
- aionui 2.1.4 -> 2.1.50
- desloppify 0.9.15 -> 1.0
- ds4 -> 2026-08-05 (b030961)
- freebuff 0.0.85 -> 0.0.142 (binary moved to GitHub releases)
- graphify 0.7.10 -> 0.9.35 (license Apache-2.0, fix sed patterns for versioned deps)
- hipengine 0.2.2 -> 0.3.0 (console script renamed to hipengine)
- kubernetes-mcp-server 0.0.62 -> 0.0.66 (requires go >= 1.26.3)
- mcp-gateway 2.11.0 -> 3.4.0 (requires rustc >= 1.95)
- omniroute 3.8.28 -> 3.8.49
- radar 1.6.1 -> 1.9.1 (drop obsolete lockfile sed patch)
- relay-free-llm -> 96e6c48, cerebras-cloud-sdk 1.67.0 -> 1.91.0
- stakpak 0.3.86 -> 0.3.88

Add nixpkgs-latest input for toolchains newer than the pinned nixpkgs.
2026-08-07 16:04:10 +03:00
alex 3d3213d61b feat: add traycer desktop package
CI / check (push) Has been cancelled
Traycer is an open-source AI orchestration desktop app (Electron).
Packaged from the upstream AppImage via appimageTools.wrapType2,
matching the existing loop package pattern.
2026-08-07 12:15:21 +03:00
alex eba219c8e1 Add agent skills
CI / check (push) Has been cancelled
- Add caveman and karpathy-guidelines skills
2026-08-07 10:55:29 +03:00
alex 3ddbedc2cc feat(packages): add nftablesbuilder package
CI / check (push) Has been cancelled
Web interface to manage nftables rules with drag-and-drop rule creation.

Upstream source is incomplete (missing settings crate, no GUI build
tooling), so the package builds the Rust workspace from the pinned
commit with a patched-in settings crate (schema recovered from official
release artifacts) and reuses the prebuilt GUI from the hash-pinned
release tarball on nftablesbuilder.eu.
2026-08-07 08:38:15 +03:00
alex 24079b7694 feat(packages): add nftables-analyzer package
CI / check (push) Has been cancelled
2026-08-07 07:50:21 +03:00
alex f27894bb2f bd init: initialize beads issue tracking 2026-08-07 07:48:02 +03:00
alex 4bc5df11c4 feat(packages): add ds4 package with ROCm/Strix Halo backend
CI / check (push) Has been cancelled
Add antirez/ds4 — DeepSeek V4 Flash/PRO local inference engine built
with the ROCm strix-halo target for AMD Radeon 8060S (gfx1151).
Wires up all 8 ROCm transitive dependencies (clr, hipblas, hipblas-common,
hipblaslt, hipcub, rocblas, rocprim, rocwmma) via explicit include/lib paths.
2026-06-19 23:06:42 +03:00
alex 6afcc00165 feat(packages): add omniroute package
CI / check (push) Has been cancelled
Add OmniRoute v3.8.28 - a unified AI router aggregating 160+ providers
with auto fallback, MCP/A2A support, and OpenAI-compatible APIs.

Uses a hybrid approach: GitHub source for dependency resolution via
fetchNpmDeps, combined with pre-built dist/ from the npm tarball to
avoid the complex Next.js build in the Nix sandbox.
2026-06-19 09:39:05 +03:00
alex 744d2419e6 feat(packages): add relay-free-llm package
Add RelayFreeLLM, a RESTful API gateway that routes prompts to multiple
AI providers (Gemini, Cerebras, Groq, Mistral, etc.) with failover and
intent-based routing. Includes local cerebras-cloud-sdk build since it is
not yet in nixpkgs.
2026-06-19 08:49:29 +03:00
alex 8d8f56664d fix(packages): correct pname typo, add missing category, add sed warning, fix indent
- graphify: fix pname typo graphifyy -> graphify
- container-use: add missing passthru.category
- radar: add brittleness warning on postPatch sed block
- freebuff: fix extractNpmPkg indentation
2026-06-17 14:11:20 +03:00
alex eae85ce989 chore: remove goose-cli package and cleanup configuration
CI / check (push) Has been cancelled
2026-06-16 22:01:18 +03:00
alex 4bf6faa2a7 chore: remove goose-cli package and cleanup configuration
- Delete packages/goose-cli/ (librusty_v8 pre-built binary dependency)
- Remove global nixpkgs.config.allowUnfree from flake.nix
  (goose-cli was the only package requiring unfree binaries)
- Add .claude/ to .gitignore
- Update README.md and AGENTS.md to remove all goose-cli references
2026-06-16 21:41:30 +03:00
alex bbd20d955d feat(loop): extract desktop file and icons from AppImage
CI / check (push) Has been cancelled
- Use appimageTools.extractType2 to access embedded assets
- Install loop-desktop.desktop and rewrite Exec=AppRun → Exec=loop
- Copy hicolor icons (16–1024px) from AppImage tree
2026-06-09 13:17:16 +03:00
alex 5ec513fe8c refactor(loop): switch from tar.gz to AppImage packaging
CI / check (push) Has been cancelled
- Use appimageTools.wrapType2 instead of manual stdenv.mkDerivation
- Source: loop-desktop-6.0.3-linux-x86_64.AppImage
- Simplify dependencies via extraPkgs (gtk3, glib)
2026-06-09 11:16:33 +03:00
Hermes Agent a0abf62d0d feat: add stakpak package (v0.3.86)
CI / check (push) Has been cancelled
Stakpak is a DevOps AI agent that generates infrastructure code,
debugs Kubernetes, configures CI/CD, and automates deployments.

- Source: github.com/stakpak/agent v0.3.86
- Rust workspace (14 crates), default binary: stakpak
- Dependencies: openssl (transitive via native-tls), pkg-config
- License: Apache-2.0
2026-06-07 19:42:25 +00:00
alex 37dd6d3295 fix(loop): Replace deprecated xorg dependencies with standalone packages
CI / check (push) Has been cancelled
Replace deprecated xorg.* references with their standalone package
names to eliminate build warnings about renamed packages.
2026-05-30 19:50:29 +03:00
alex cb5ace4837 fix(loop): update homepage URL to loop.ru
CI / check (push) Has been cancelled
2026-05-29 20:27:01 +03:00
alex cf676f951c fix(loop): keep only --ozone-platform=x11, remove --no-sandbox
CI / check (push) Has been cancelled
User confirmed that --no-sandbox is unnecessary and that the app
crashes without --ozone-platform=x11. Keep the minimal working
wrapper flags.
2026-05-29 20:24:49 +03:00
alex bede48c22e fix(loop): remove forced X11, keep --no-sandbox
CI / check (push) Has been cancelled
Revert the --ozone-platform=x11 flag since the user prefers native
Wayland. The flag was added to work around a zxdg_exporter_v1
Wayland protocol crash in Electron, but forcing X11 is not
acceptable for Wayland users. Keep --no-sandbox for NixOS store
compatibility.
2026-05-29 20:23:03 +03:00
alex 3a86fe84f4 fix(loop): force X11 ozone platform and disable sandbox
CI / check (push) Has been cancelled
- Add --ozone-platform=x11 to wrapper to fix Wayland crash
  (zxdg_exporter_v1 protocol error causing SIGTRAP on Wayland)
- Add --no-sandbox since chrome-sandbox lacks SUID on NixOS
2026-05-29 20:20:07 +03:00
alex d23dc7ab22 fix(loop): add runtime fixes for gsettings and GPU libraries
CI / check (push) Has been cancelled
- Add LD_LIBRARY_PATH to wrapper so Electron GPU process finds bundled libEGL.so.1
- Add glib.bin to buildInputs and wrap gsettings into PATH
- Create versioned symlinks for bundled libEGL.so and libGLESv2.so
- Clean up formatting in package inputs
2026-05-29 20:04:32 +03:00
alex 3b597af162 feat(loop): Add Loop corporate messenger package
CI / check (push) Has been cancelled
Add Loop v6.0.3 - a corporate messenger distributed as a pre-built x86-64 binary.
Uses autoPatchelfHook and wrapGAppsHook3 for NixOS compatibility.
2026-05-29 19:51:21 +03:00
alex 37af68cfd0 docs(AGENTS): add sequential-thinking MCP and caveman skill requirements
CI / check (push) Has been cancelled
- Require sequentialthinking MCP for all planning/problem-solving
- Add caveman mode for compressed user-facing communication
- Clarify karpathy-guidelines usage for task execution quality
2026-05-27 22:06:38 +03:00
alex 6f18e72272 docs(AGENTS): add mandatory beads workflow section before any work
CI / check (push) Has been cancelled
Make bd usage explicit with a "Before Starting Any Work" section,
updated example workflow, and strengthened quick reference rules.
This prevents agents from using TodoWrite or other non-bd tracking.
2026-05-27 22:01:26 +03:00
alex bcf607c209 feat(hipengine): add ROCm-native LLM inference engine (v0.2.2)
CI / check (push) Has been cancelled
2026-05-27 21:56:18 +03:00
alex 7f0cec1a35 fix(aionui): Use production-only deps for runtime, hoist transitive deps
CI / check (push) Has been cancelled
Replace full node_modules copy with production-only FOD (mirrors
the upstream Dockerfile pattern), reducing package output from
~6.9 GB to ~1.3 GB.

Hoist @sentry/node to top-level node_modules so Electron's
require() resolution can find it. Bun nests transitive deps
inside .bun/ but Electron resolves from the realpath, requiring
the dependency to be accessible from the walked-up directory
chain.
2026-05-27 14:35:57 +03:00
alex 02947027ba feat(aionui): Add AionUi AI cowork desktop app (v2.1.4)
CI / check (push) Has been cancelled
Build AionUi from source using bun for dependency fetching and
electron-vite for TypeScript compilation. Native addons
(better-sqlite3, sharp) are compiled against nixpkgs node-gyp.

The package uses a fixed-output derivation for bun install,
electron-vite for the build, and wraps the result with nixpkgs
electron for a fully self-contained runtime.

Also includes desktop entry and icon generation.
2026-05-27 13:48:18 +03:00
alex efc1ad85e2 chore(beads): update issues
CI / check (push) Has been cancelled
2026-05-17 16:03:47 +03:00
alex c805ff1d69 chore(radar): update to v1.6.1 2026-05-17 16:03:33 +03:00
alex e3adb2e906 docs(AGENTS): add required skills section for nix, nix-flakes, karpathy-guidelines
CI / check (push) Has been cancelled
2026-05-17 15:55:36 +03:00
alex bb3c53b40b refactor(freebuff): run engine directly from nix-store
CI / check (push) Has been cancelled
Remove unnecessary copy to ~/.config/manicode/. The patched ELF
binary and tree-sitter.wasm stay in the nix store alongside a minimal
JS launcher that spawns the engine with terminal cleanup handling.
2026-05-12 11:48:46 +03:00
alex 6c5fdd7331 fix(freebuff): patch pre-built binary with patchelf for NixOS compatibility
- Download and extract the engine binary from codebuff.com releases
- Use patchelf to set correct glibc interpreter path
- Create wrapper launcher that copies patched binary to user config
- Pre-fetch all npm dependencies (no network needed in sandbox)
- Set dontStrip/dontPatchelf to prevent fixupPhase corruption
2026-05-12 09:31:40 +03:00
alex c7029a0d34 docs(README): add missing packages to project structure section 2026-05-11 20:55:16 +03:00
alex a7ddc90e17 feat: add freebuff package (Codebuff AI coding agent)
CI / check (push) Has been cancelled
Add freebuff v0.0.85 from npm registry — a pure JS CLI tool for
AI-assisted coding. Pre-fetches all transitive npm dependencies to
work within the Nix sandbox (no network access during build).
2026-05-11 20:04:22 +03:00
alex 52971ae66b Merge pull request 'refactor/radar-native-build' (#1) from refactor/radar-native-build into main
CI / check (push) Has been cancelled
Reviewed-on: #1
2026-05-11 18:55:51 +03:00
alex cbaa6b6bca fix(radar): inject correct build version via ldflags
CI / check (pull_request) Has been cancelled
Version was showing as "dev" instead of "v1.5.14" because ldflags
targeted the wrong variable. Changed from internal/version.Current
to main.version which is the variable actually used by cmd/explorer.
2026-05-11 18:49:47 +03:00
alex 3b0bc435c4 refactor(radar): build from source instead of prebuilt binary
Replace fetchurl + prebuilt binary with buildGoModule + buildNpmPackage
to compile radar natively from source. Frontend (React/Vite) is built
as a separate derivation, then embedded into the Go binary via go:embed.

Also patches the npm lockfile to add missing resolved URLs for
workspace packages that lacked them, enabling proper dependency fetching.

Closes nix-overlay-qlc
2026-05-11 18:09:02 +03:00
alex 0d6b74045e Update package.nix
CI / check (push) Has been cancelled
2026-05-11 11:31:25 +03:00
alex ca9a8050df chore(beads): update issue status for nix-overlay-2lr
CI / check (push) Has been cancelled
2026-05-11 11:30:02 +03:00
alex d065d8cdde feat(radar): add radar Kubernetes UI package v1.5.10
CI / check (push) Has been cancelled
Add radar v1.5.10 — a modern Kubernetes visibility tool providing
topology, event timeline, service traffic, resource browsing, Helm
management, and GitOps support.

Uses pre-built binary from GitHub releases.

Closes: nix-overlay-2lr
2026-05-11 00:29:28 +03:00
alex 7581781b3b bd init: initialize beads issue tracking 2026-05-10 22:28:02 +03:00
alex c35e6bff5d docs(agents): note that blueprint package discovery requires git staging
CI / check (push) Has been cancelled
Blueprint reads packages from the git index, not the working directory.
New packages must be staged with 'git add' before they appear in flake
outputs. Add this to both the Blueprint Framework section and the
'Adding a New Package' workflow.
2026-05-10 16:59:24 +03:00
alex c9e6af2956 feat(packages): add desloppify v0.9.15
Add desloppify, a multi-language codebase health scanner and technical
debt tracker for AI agents. Includes all [full] optional dependencies
(tree-sitter, bandit, pillow, pyyaml, defusedxml) for complete
functionality out of the box.
2026-05-10 16:53:40 +03:00
alex d8f7f602ed feat(packages): add graphify v0.7.10
CI / check (push) Has been cancelled
Add graphify, a tool that turns any folder of code, docs, papers, images,
or videos into a queryable knowledge graph for AI coding assistants.

Includes tree-sitter grammar filtering to use only grammars available in
nixpkgs, with missing grammars falling back to runtime downloads.
2026-05-08 21:18:08 +03:00
alex 4a06f35ec2 fix(goose-cli): resolve bindgen and test failures in Nix sandbox
CI / check (push) Has been cancelled
- Added stdenv and BINDGEN_EXTRA_CLANG_ARGS to fix libclang header
  resolution for llama-cpp-sys-2 bindgen (stdio.h not found)
- Added cmake to nativeBuildInputs (required by llama-cpp-sys-2 build)
- Added cacert and SSL_CERT_FILE to fix reqwest CA certificate errors
  in tests (No CA certificates were loaded from the system)
- All 191 tests now pass in the sandbox
2026-05-08 20:13:34 +03:00
alex 492ffc200a Remove kubernetes-mcp-server task file
Also add .tasks/ to .gitignore
2026-05-08 19:47:11 +03:00
alex 67b8add3d1 feat(packages): add kubernetes-mcp-server v0.0.62
Model Context Protocol (MCP) server for Kubernetes and OpenShift.
Native Go implementation that interacts directly with the Kubernetes
API server without external dependencies like kubectl or helm.

- Added package.nix using buildGoModule (CGO_ENABLED=0, static build)
- Added default.nix wrapper for blueprint auto-discovery
- Updated README.md with the new package entry
- Added task requirements document in tasks/kubernetes-mcp-server.md
2026-05-08 19:43:55 +03:00
alex 0fd5c71709 fix: resolve code quality issues, add CI, and improve maintainability
- Remove useless nixConfig block (cache.nixos.org is default)
- Remove manual container-use override; let blueprint auto-discover it
- Add nixosModules.default so README example works
- Fix default launcher: use correct parameterized flake URL
- Replace deprecated sha256 with hash in goose-cli fetchers
- Fix LIBCLANG_PATH to include /lib subdirectory for libclang.so
- Drop --release from goose-cli tests (faster, more debug info)
- Use builtins.toFile in flake-inputs to avoid ARG_MAX risk
- Add lib.warn when overlay has no packages for a system
- Add passthru.updateScript to goose-cli, container-use, skillsmcp
- Fix skillsmcp version to 0.2.0+unstable (pinned to commit, not tag)
- Replace with lib; with explicit references in all meta blocks
- Add update.py script for goose-cli (referenced in AGENTS.md)
- Expand .gitignore with result-* and .direnv/
- Add GitHub Actions CI workflow (nix flake check + build)
2026-05-08 06:02:12 +03:00
alex 87c44ba6da fix(mcp-gateway): use nix store binary path in systemd ExecStart
Expand $out in the heredoc so ExecStart points to the actual binary
in the nix store, not %h/.config/mcp-gateway/mcp-gateway.
2026-05-06 20:02:24 +03:00
alex d45b4242c8 fix(mcp-gateway): fix postInstall heredoc syntax
Use mkdir + cat instead of install with /dev/stdout to avoid build hang.
2026-05-06 19:50:53 +03:00
alex ea9cf8b588 feat(mcp-gateway): add systemd user unit file to package
Install mcp-gateway.service to $out/lib/systemd/user/ so it can be
activated via systemd.user.packages. The service runs:
  mcp-gateway --config ~/.config/mcp-gateway/gateway.yaml serve
2026-05-06 18:38:47 +03:00
alex 743e6afde3 fix(mcp-gateway): change to user systemd service
Use systemd.user.services instead of systemd.services, default config
to ~/.config/mcp-gateway/gateway.yaml, and wantedBy default.target.
2026-05-06 18:23:22 +03:00
alex e327504f4e feat(mcp-gateway): add NixOS module with systemd service
Provides services.mcp-gateway module for easy systemd integration:
  config.services.mcp-gateway = {
    enable = true;
    configFile = "/etc/mcp-gateway/gateway.yaml";
  };
2026-05-06 18:21:18 +03:00
alex 9fb3eebd8a fix(container-use): add cu symlink to main binary 2026-05-06 14:17:40 +03:00
alex ce5e6a53f7 feat: add container-use package and fix goose-cli libclang dependency
- Add dagger/container-use (v0.4.2) for containerized coding agent environments
- Fix goose-cli build by adding llvmPackages.libclang for bindgen
- Clean up skillsmcp package (remove custom fastmcp override, use nixos-unstable)
- Remove broken update.py script from goose-cli
- Add treefmt.toml for consistent formatting
- Update README with all current packages
2026-05-06 13:42:42 +03:00
alex c68a821a00 fix: improve package quality and fix goose-cli build
- Add meta.platforms to all packages for proper platform detection
- Add passthru.category to mcp-gateway for consistency
- Fix meta style inconsistency in mcp-gateway (lib.licenses → licenses)
- Fix pythonImportsCheck in skillsmcp to actually validate the import
- Remove empty maintainers list from skillsmcp
- Add libclang to goose-cli nativeBuildInputs (fixes bindgen/llama-cpp-sys-2 build)
- Add treefmt.toml with nixfmt formatter configuration
- Add nixConfig.extra-substituters for binary cache support
- Delete broken goose-cli/update.py (referenced missing scripts/updater.py)
- Document nix-update usage in AGENTS.md for package updates
- Fix stale project structure diagram in README
2026-05-06 12:54:26 +03:00
alex 83ab7d0a19 chore: add .qwen to gitignore and disable checks for mcp-gateway
Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
2026-05-06 12:24:14 +03:00
alex ff54fedb91 docs: add mcp-gateway to README
Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
2026-05-06 11:45:45 +03:00
alex a4c31e0e99 fix: correct cargoHash for mcp-gateway
Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
2026-05-06 11:42:13 +03:00
alex 11d05e83f9 feat: add mcp-gateway package
Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
2026-05-06 11:39:57 +03:00
alex e2062a2248 Add Git workflow instructions to AGENTS.md
Include guidance on using conventional-commit and
git-advanced-workflows skills. Update the package addition example to
reference the conventional-commit skill instead of raw git commands.
2026-05-06 11:03:30 +03:00
alex 69a34cb819 Add skillsmcp MCP server package
Update documentation in README.md and AGENTS.md
Refresh flake.lock for nixpkgs and flake-parts
Disable fastmcp checks to avoid version conflicts
2026-05-06 10:15:17 +03:00
alex fb5db6e302 Initialize Nix overlay repository with blueprint, goose-cli, and docs
Add the complete overlay structure using numtide/blueprint with:
- Two overlay strategies (default and shared-nixpkgs)
- goose-cli package with custom librusty_v8 fetcher
- Interactive package launcher via fzf
- Flake input caching utility
- Comprehensive README and AGENTS.md documentation
2026-04-29 16:04:58 +03:00
alex 216f59f65b Initial commit 2026-04-29 14:18:42 +03:00
81 changed files with 9185 additions and 7 deletions
+48
View File
@@ -0,0 +1,48 @@
# caveman
Talk like smart caveman. Same brain, fewer tokens.
## What it does
Compress every model response to caveman-style prose. Drops articles, filler, pleasantries, and hedging. Keeps every technical detail, code block, error string, and symbol exact. Cuts 65% of output tokens (measured) with full accuracy preserved. Mode persists for the whole session until changed or stopped.
Six intensity levels:
| Level | What change |
|-------|-------------|
| `lite` | Drop filler/hedging. Sentences stay full. Professional but tight. |
| `full` | Default. Drop articles, fragments OK, short synonyms. |
| `ultra` | Bare fragments. Abbreviations (DB, auth, fn). Arrows for causality. |
| `wenyan-lite` | Classical Chinese register, light compression. |
| `wenyan-full` | Maximum 文言文. 80-90% character reduction. |
| `wenyan-ultra` | Extreme classical compression. |
Auto-clarity rule: caveman drops to normal prose for security warnings, irreversible-action confirmations, multi-step sequences where fragment ambiguity risks misread, and when user repeats a question. Resumes after the clear part.
## How to invoke
```
/caveman # full mode (default)
/caveman lite # lighter compression
/caveman ultra # extreme compression
/caveman wenyan # classical Chinese
stop caveman # back to normal prose
```
## Example output
Question: "Why does my React component re-render?"
Normal prose:
> Your component re-renders because you create a new object reference each render. Wrapping it in `useMemo` will fix the issue.
Caveman (full):
> New object ref each render. Inline object prop = new ref = re-render. Wrap in `useMemo`.
Caveman (ultra):
> Inline obj prop → new ref → re-render. `useMemo`.
## See also
- [`SKILL.md`](./SKILL.md) — full LLM-facing instructions
- [Caveman README](../../README.md) — repo overview, install, benchmarks
+88
View File
@@ -0,0 +1,88 @@
---
name: caveman
description: >
Ultra-compressed communication mode. Cuts output tokens 65% (measured) by speaking like caveman
while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra,
wenyan-lite, wenyan-full, wenyan-ultra.
Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens",
"be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.
---
Respond terse like smart caveman. All technical substance stay. Only fluff die.
## Persistence
ACTIVE EVERY RESPONSE. No revert after many turns. No filler drift. Still active if unsure. Off only: "stop caveman" / "normal mode".
Default: **full**. Switch: `/caveman lite|full|ultra|wenyan-lite|wenyan-full|wenyan-ultra|off`.
## Rules
Drop: articles (a/an/the), filler (just/really/basically/actually/simply), pleasantries (sure/certainly/of course/happy to), hedging. Fragments OK. Short synonyms (big not extensive, fix not "implement a solution for"). No tool-call narration, no decorative tables/emoji, no dumping long raw error logs unless asked — quote shortest decisive line. Standard well-known tech acronyms OK (DB/API/HTTP); never invent new abbreviations (cfg/impl/req/res/fn) — tokenizer split them same as full word: zero token saved, reader still decode. Full word cheaper AND clearer. No causal arrows (→) either — own token, save nothing. Technical terms exact. Code blocks unchanged. Errors quoted exact.
Never drop not/never/no/only/except — flip meaning worse than any token saved. Numbers, units exact.
Tool calls: fire direct. No preamble, plan, or progress note before or between calls. After result: next call direct or final answer — never announce next call. Text before call only to clarify, warn security/irreversible, or resolve ambiguity.
Preserve user's dominant language exactly — reply in the language user writes, never switch regardless of example text or multilingual context elsewhere. Compress the style, not the language. Every emitted line in that language — openings, pre-tool status lines, all — not just final reply. ALWAYS keep technical terms, code, API names, CLI commands, commit-type keywords (feat/fix/...), and exact error strings verbatim — unless user explicitly ask for translation.
'Drop articles' = article languages only. Where small markers carry case/role (particles, postpositions), keep them — grammar, not filler; compress politeness/filler instead.
No self-reference. Never name or announce the style. No "caveman mode on", "me caveman think", no third-person caveman tags. Output caveman-only — never normal answer plus "Caveman:" recap. Exception: user explicitly ask what the mode is.
Pattern: `[thing] [action] [reason]. [next step].`
Not: "Sure! I'd be happy to help you with that. The issue you're experiencing is likely caused by..."
Yes: "Bug in auth middleware. Token expiry check use `<` not `<=`. Fix:"
## Intensity
| Level | What change |
|-------|------------|
| **lite** | No filler/hedging. Keep articles + full sentences. Professional but tight |
| **full** | Drop articles, fragments OK, short synonyms. Classic caveman. No tool-call narration, no decorative tables/emoji, no long raw error-log dumps unless asked. Standard acronyms OK; no invented abbreviations |
| **ultra** | Strip conjunctions when cause-then-effect stay unambiguous. One word when one word enough. State each fact once. NO prose abbreviations (cfg/impl/req/res/fn/auth), NO arrows (X → Y) — measured zero token saving under tokenizer, cost decode clarity. Code symbols, function names, API names, error strings: never touch |
| **wenyan-lite** | Semi-classical. Drop filler/hedging but keep grammar structure, classical register |
| **wenyan-full** | Maximum classical terseness. Fully 文言文. 80-90% character reduction — chars, not tokens. Classical sentence patterns, verbs precede objects, subjects often omitted, classical particles (之/乃/為/其) |
| **wenyan-ultra** | Extreme abbreviation while keeping classical Chinese feel. Maximum compression, ultra terse |
Example — "Why React component re-render?"
- lite: "Your component re-renders because you create a new object reference each render. Wrap it in `useMemo`."
- full: "New object ref each render. Inline object prop = new ref = re-render. Wrap in `useMemo`."
- ultra: "Inline obj prop, new ref, re-render. `useMemo`."
- wenyan-lite: "組件頻重繪,以每繪新生對象參照故。以 useMemo 包之。"
- wenyan-full: "每繪新生對象參照,故重繪;以 useMemo 包之則免。"
- wenyan-ultra: "新參照則重繪。useMemo 包之。"
Example — "Explain database connection pooling."
- lite: "Connection pooling reuses open connections instead of creating new ones per request. Avoids repeated handshake overhead."
- full: "Pool reuse open DB connections. No new connection per request. Skip handshake overhead."
- ultra: "Pool reuse open DB connections. No per-request handshake."
- wenyan-full: "池蓄已開之連,不逐請而新開,省握手之費。"
- wenyan-ultra: "池蓄連,免逐請新開,省握手。"
Classical chars = wenyan modes only. Never swap a word to a classical char to shrink at non-wenyan levels.
## Auto-Clarity
Drop caveman when:
- Security warnings
- Irreversible action confirmations
- Multi-step sequences where fragment order or omitted conjunctions risk misread
- Compression itself creates technical ambiguity (e.g., `"migrate table drop column backup first"` — order unclear without articles/conjunctions)
- User asks to clarify or repeats question
Resume caveman after clear part done.
Example shows FORMAT only — write warning in session language, not example's.
Example — destructive op:
> **Warning:** This will permanently delete all rows in the `users` table and cannot be undone.
> ```sql
> DROP TABLE users;
> ```
> Caveman resume. Verify backup exist first.
## Boundaries
Persisted outside chat: write normal prose — code, comments, commits, docs, issue/PR/MR text, memory files, third-party messages (/caveman-compress exempt). "stop caveman" or "normal mode": revert. Level persist until changed or session end.
@@ -0,0 +1,67 @@
---
name: karpathy-guidelines
description: Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.
license: MIT
---
# Karpathy Guidelines
Behavioral guidelines to reduce common LLM coding mistakes, derived from [Andrej Karpathy's observations](https://x.com/karpathy/status/2015883857489522876) on LLM coding pitfalls.
**Tradeoff:** These guidelines bias toward caution over speed. For trivial tasks, use judgment.
## 1. Think Before Coding
**Don't assume. Don't hide confusion. Surface tradeoffs.**
Before implementing:
- State your assumptions explicitly. If uncertain, ask.
- If multiple interpretations exist, present them - don't pick silently.
- If a simpler approach exists, say so. Push back when warranted.
- If something is unclear, stop. Name what's confusing. Ask.
## 2. Simplicity First
**Minimum code that solves the problem. Nothing speculative.**
- No features beyond what was asked.
- No abstractions for single-use code.
- No "flexibility" or "configurability" that wasn't requested.
- No error handling for impossible scenarios.
- If you write 200 lines and it could be 50, rewrite it.
Ask yourself: "Would a senior engineer say this is overcomplicated?" If yes, simplify.
## 3. Surgical Changes
**Touch only what you must. Clean up only your own mess.**
When editing existing code:
- Don't "improve" adjacent code, comments, or formatting.
- Don't refactor things that aren't broken.
- Match existing style, even if you'd do it differently.
- If you notice unrelated dead code, mention it - don't delete it.
When your changes create orphans:
- Remove imports/variables/functions that YOUR changes made unused.
- Don't remove pre-existing dead code unless asked.
The test: Every changed line should trace directly to the user's request.
## 4. Goal-Driven Execution
**Define success criteria. Loop until verified.**
Transform tasks into verifiable goals:
- "Add validation" → "Write tests for invalid inputs, then make them pass"
- "Fix the bug" → "Write a test that reproduces it, then make it pass"
- "Refactor X" → "Ensure tests pass before and after"
For multi-step tasks, state a brief plan:
```
1. [Step] → verify: [check]
2. [Step] → verify: [check]
3. [Step] → verify: [check]
```
Strong success criteria let you loop independently. Weak criteria ("make it work") require constant clarification.
+73
View File
@@ -0,0 +1,73 @@
# Dolt database (managed by Dolt, not git)
dolt/
embeddeddolt/
# Runtime files
bd.sock
bd.sock.startlock
sync-state.json
last-touched
.exclusive-lock
# Daemon runtime (lock, log, pid)
daemon.*
# Interactions log (runtime, not versioned)
interactions.jsonl
# Push state (runtime, per-machine)
push-state.json
# Lock files (various runtime locks)
*.lock
# Credential key (encryption key for federation peer auth — never commit)
.beads-credential-key
# Local version tracking (prevents upgrade notification spam after git ops)
.local_version
# Worktree redirect file (contains relative path to main repo's .beads/)
# Must not be committed as paths would be wrong in other clones
redirect
# Sync state (local-only, per-machine)
# These files are machine-specific and should not be shared across clones
.sync.lock
export-state/
export-state.json
# Ephemeral store (SQLite - wisps/molecules, intentionally not versioned)
ephemeral.sqlite3
ephemeral.sqlite3-journal
ephemeral.sqlite3-wal
ephemeral.sqlite3-shm
# Dolt server management (auto-started by bd)
dolt-server.pid
dolt-server.log
dolt-server.lock
dolt-server.port
dolt-server.activity
# Corrupt backup directories (created by bd doctor --fix recovery)
*.corrupt.backup/
# Backup data (auto-exported JSONL, local-only)
backup/
# Per-project environment file (Dolt connection config, GH#2520)
.env
# Legacy files (from pre-Dolt versions)
*.db
*.db?*
*.db-journal
*.db-wal
*.db-shm
db.sqlite
bd.db
# NOTE: Do NOT add negation patterns here.
# They would override fork protection in .git/info/exclude.
# Config files (metadata.json, config.yaml) are tracked by git by default
# since no pattern above ignores them.
+81
View File
@@ -0,0 +1,81 @@
# Beads - AI-Native Issue Tracking
Welcome to Beads! This repository uses **Beads** for issue tracking - a modern, AI-native tool designed to live directly in your codebase alongside your code.
## What is Beads?
Beads is issue tracking that lives in your repo, making it perfect for AI coding agents and developers who want their issues close to their code. No web UI required - everything works through the CLI and integrates seamlessly with git.
**Learn more:** [github.com/steveyegge/beads](https://github.com/steveyegge/beads)
## Quick Start
### Essential Commands
```bash
# Create new issues
bd create "Add user authentication"
# View all issues
bd list
# View issue details
bd show <issue-id>
# Update issue status
bd update <issue-id> --claim
bd update <issue-id> --status done
# Sync with Dolt remote
bd dolt push
```
### Working with Issues
Issues in Beads are:
- **Git-native**: Stored in Dolt database with version control and branching
- **AI-friendly**: CLI-first design works perfectly with AI coding agents
- **Branch-aware**: Issues can follow your branch workflow
- **Always in sync**: Auto-syncs with your commits
## Why Beads?
✨ **AI-Native Design**
- Built specifically for AI-assisted development workflows
- CLI-first interface works seamlessly with AI coding agents
- No context switching to web UIs
🚀 **Developer Focused**
- Issues live in your repo, right next to your code
- Works offline, syncs when you push
- Fast, lightweight, and stays out of your way
🔧 **Git Integration**
- Automatic sync with git commits
- Branch-aware issue tracking
- Dolt-native three-way merge resolution
## Get Started with Beads
Try Beads in your own projects:
```bash
# Install Beads
curl -sSL https://raw.githubusercontent.com/steveyegge/beads/main/scripts/install.sh | bash
# Initialize in your repo
bd init
# Create your first issue
bd create "Try out Beads"
```
## Learn More
- **Documentation**: [github.com/steveyegge/beads/docs](https://github.com/steveyegge/beads/tree/main/docs)
- **Quick Start Guide**: Run `bd quickstart`
- **Examples**: [github.com/steveyegge/beads/examples](https://github.com/steveyegge/beads/tree/main/examples)
---
*Beads: Issue tracking that moves at the speed of thought* ⚡
+56
View File
@@ -0,0 +1,56 @@
# Beads Configuration File
# This file configures default behavior for all bd commands in this repository
# All settings can also be set via environment variables (BD_* prefix)
# or overridden with command-line flags
# Issue prefix for this repository (used by bd init)
# If not set, bd init will auto-detect from directory name
# Example: issue-prefix: "myproject" creates issues like "myproject-1", "myproject-2", etc.
# issue-prefix: ""
# Use no-db mode: JSONL-only, no Dolt database
# When true, bd will use .beads/issues.jsonl as the source of truth
# no-db: false
# Enable JSON output by default
# json: false
# Feedback title formatting for mutating commands (create/update/close/dep/edit)
# 0 = hide titles, N > 0 = truncate to N characters
# output:
# title-length: 255
# Default actor for audit trails (overridden by BEADS_ACTOR or --actor)
# actor: ""
# Export events (audit trail) to .beads/events.jsonl on each flush/sync
# When enabled, new events are appended incrementally using a high-water mark.
# Use 'bd export --events' to trigger manually regardless of this setting.
# events-export: false
# Multi-repo configuration (experimental - bd-307)
# Allows hydrating from multiple repositories and routing writes to the correct database
# repos:
# primary: "." # Primary repo (where this database lives)
# additional: # Additional repos to hydrate from (read-only)
# - ~/beads-planning # Personal planning repo
# - ~/work-planning # Work planning repo
# JSONL backup (periodic export for off-machine recovery)
# Auto-enabled when a git remote exists. Override explicitly:
# backup:
# enabled: false # Disable auto-backup entirely
# interval: 15m # Minimum time between auto-exports
# git-push: false # Disable git push (export locally only)
# git-repo: "" # Separate git repo for backups (default: project repo)
# Integration settings (access with 'bd config get/set')
# These are stored in the database, not in this file:
# - jira.url
# - jira.project
# - linear.url
# - linear.api-key
# - github.org
# - github.repo
sync.remote: "git+ssh://git@git.millerson.name:22002/alex/millerson-overlay.nix.git"
+24
View File
@@ -0,0 +1,24 @@
#!/usr/bin/env sh
# --- BEGIN BEADS INTEGRATION v1.0.3 ---
# This section is managed by beads. Do not remove these markers.
if command -v bd >/dev/null 2>&1; then
export BD_GIT_HOOK=1
_bd_timeout=${BEADS_HOOK_TIMEOUT:-300}
if command -v timeout >/dev/null 2>&1; then
timeout "$_bd_timeout" bd hooks run post-checkout "$@"
_bd_exit=$?
if [ $_bd_exit -eq 124 ]; then
echo >&2 "beads: hook 'post-checkout' timed out after ${_bd_timeout}s — continuing without beads"
_bd_exit=0
fi
else
bd hooks run post-checkout "$@"
_bd_exit=$?
fi
if [ $_bd_exit -eq 3 ]; then
echo >&2 "beads: database not initialized — skipping hook 'post-checkout'"
_bd_exit=0
fi
if [ $_bd_exit -ne 0 ]; then exit $_bd_exit; fi
fi
# --- END BEADS INTEGRATION v1.0.3 ---
+24
View File
@@ -0,0 +1,24 @@
#!/usr/bin/env sh
# --- BEGIN BEADS INTEGRATION v1.0.3 ---
# This section is managed by beads. Do not remove these markers.
if command -v bd >/dev/null 2>&1; then
export BD_GIT_HOOK=1
_bd_timeout=${BEADS_HOOK_TIMEOUT:-300}
if command -v timeout >/dev/null 2>&1; then
timeout "$_bd_timeout" bd hooks run post-merge "$@"
_bd_exit=$?
if [ $_bd_exit -eq 124 ]; then
echo >&2 "beads: hook 'post-merge' timed out after ${_bd_timeout}s — continuing without beads"
_bd_exit=0
fi
else
bd hooks run post-merge "$@"
_bd_exit=$?
fi
if [ $_bd_exit -eq 3 ]; then
echo >&2 "beads: database not initialized — skipping hook 'post-merge'"
_bd_exit=0
fi
if [ $_bd_exit -ne 0 ]; then exit $_bd_exit; fi
fi
# --- END BEADS INTEGRATION v1.0.3 ---
+24
View File
@@ -0,0 +1,24 @@
#!/usr/bin/env sh
# --- BEGIN BEADS INTEGRATION v1.0.3 ---
# This section is managed by beads. Do not remove these markers.
if command -v bd >/dev/null 2>&1; then
export BD_GIT_HOOK=1
_bd_timeout=${BEADS_HOOK_TIMEOUT:-300}
if command -v timeout >/dev/null 2>&1; then
timeout "$_bd_timeout" bd hooks run pre-commit "$@"
_bd_exit=$?
if [ $_bd_exit -eq 124 ]; then
echo >&2 "beads: hook 'pre-commit' timed out after ${_bd_timeout}s — continuing without beads"
_bd_exit=0
fi
else
bd hooks run pre-commit "$@"
_bd_exit=$?
fi
if [ $_bd_exit -eq 3 ]; then
echo >&2 "beads: database not initialized — skipping hook 'pre-commit'"
_bd_exit=0
fi
if [ $_bd_exit -ne 0 ]; then exit $_bd_exit; fi
fi
# --- END BEADS INTEGRATION v1.0.3 ---
+24
View File
@@ -0,0 +1,24 @@
#!/usr/bin/env sh
# --- BEGIN BEADS INTEGRATION v1.0.3 ---
# This section is managed by beads. Do not remove these markers.
if command -v bd >/dev/null 2>&1; then
export BD_GIT_HOOK=1
_bd_timeout=${BEADS_HOOK_TIMEOUT:-300}
if command -v timeout >/dev/null 2>&1; then
timeout "$_bd_timeout" bd hooks run pre-push "$@"
_bd_exit=$?
if [ $_bd_exit -eq 124 ]; then
echo >&2 "beads: hook 'pre-push' timed out after ${_bd_timeout}s — continuing without beads"
_bd_exit=0
fi
else
bd hooks run pre-push "$@"
_bd_exit=$?
fi
if [ $_bd_exit -eq 3 ]; then
echo >&2 "beads: database not initialized — skipping hook 'pre-push'"
_bd_exit=0
fi
if [ $_bd_exit -ne 0 ]; then exit $_bd_exit; fi
fi
# --- END BEADS INTEGRATION v1.0.3 ---
+24
View File
@@ -0,0 +1,24 @@
#!/usr/bin/env sh
# --- BEGIN BEADS INTEGRATION v1.0.3 ---
# This section is managed by beads. Do not remove these markers.
if command -v bd >/dev/null 2>&1; then
export BD_GIT_HOOK=1
_bd_timeout=${BEADS_HOOK_TIMEOUT:-300}
if command -v timeout >/dev/null 2>&1; then
timeout "$_bd_timeout" bd hooks run prepare-commit-msg "$@"
_bd_exit=$?
if [ $_bd_exit -eq 124 ]; then
echo >&2 "beads: hook 'prepare-commit-msg' timed out after ${_bd_timeout}s — continuing without beads"
_bd_exit=0
fi
else
bd hooks run prepare-commit-msg "$@"
_bd_exit=$?
fi
if [ $_bd_exit -eq 3 ]; then
echo >&2 "beads: database not initialized — skipping hook 'prepare-commit-msg'"
_bd_exit=0
fi
if [ $_bd_exit -ne 0 ]; then exit $_bd_exit; fi
fi
# --- END BEADS INTEGRATION v1.0.3 ---
+18
View File
@@ -0,0 +1,18 @@
{"_type":"issue","id":"nix-overlay-4g1","title":"Add marmel package","description":"Package Na1w/marmel (binary: marmel, cargo crate: marmennill), an autonomous agentic coding assistant.\n\nDecisions from grilling session:\n- attr/pname/mainProgram = marmel\n- version = unstable-2026-09-13 (tagless upstream; matches nix-update --version=branch=main output shape)\n- rev = fd551ae3198d427b0f0df3429f88764c49095b23, updateScript = nix-update --version=branch=main\n- license = mit (upstream README claims MIT; no LICENSE file, no Cargo.toml license field)\n- platforms = unix\n- category = AI Coding Agents\n- doCheck = true, triage sandbox-hostile PTY/Landlock tests by name; fall back to doCheck=false with comment only if suite is unsandboxable\n- install annotated example configs to share/doc/marmel/examples/\n- verification: nix build .#marmel, nix run .#marmel -- --help, nix eval version, nix flake check, nix build .#packages, README table row\n\nKnown build risk: aws-lc-sys (via rustls-platform-verifier) is a CMake/NASM C build; add only the build inputs the build actually demands.","status":"open","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-09-14T08:56:39Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-14T08:56:39Z","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-89n","title":"Refresh flake.lock nixpkgs inputs","description":"Update nixpkgs and nixpkgs-latest flake inputs (pinned 2026-05 and 2026-08) to current nixos-unstable, then re-validate package builds.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-13T18:40:17Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T22:18:53Z","started_at":"2026-09-13T18:40:18Z","closed_at":"2026-09-13T22:18:53Z","close_reason":"nixpkgs/nixpkgs-latest bumped to 2026-09-11, freetoken pinned to nixpkgs-torch211, all 22 packages build and flake check passes.","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-cfk","title":"Update all packages to latest upstream versions","description":"Bump every package in packages/ to its latest available upstream version, refresh hashes (src, cargoHash, vendorHash, npm deps, bun2nix, appimage, etc.), verify builds, and update README. Packages: aionui, awg-tool, container-use, desloppify, ds4, freebuff, freetoken, graphify, haivemind, hipengine, kubernetes-mcp-server, llama-cpp, loop, mcp-gateway, nftables-analyzer, nftablesbuilder, omniroute, radar, relay-free-llm, skillsmcp, stakpak, traycer.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-13T13:59:31Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T18:06:08Z","started_at":"2026-09-13T13:59:35Z","closed_at":"2026-09-13T18:06:08Z","close_reason":"All packages bumped to latest upstream; treefmt clean and nix flake check --no-build passes.","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-05o","title":"Add llama-cpp package (build 9645) to overlay","description":"Port the pinned llama.cpp b9645 derivation from nixos-config/modules/llm-engine.nix into packages/llama-cpp/ (default.nix + package.nix). ROCm + Vulkan enabled, znver5 CPU flags, strix-halo gfx1151 orientation. Must build via nix build .#llama-cpp.","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-13T09:22:26Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T10:33:35Z","started_at":"2026-09-13T09:22:28Z","closed_at":"2026-09-13T10:33:35Z","close_reason":"llama-cpp b9645 packaged in packages/llama-cpp, built and smoke-tested on gfx1151 (ROCm + Vulkan)","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-6y6","title":"Add Loop corporate messenger package","description":"Add Loop - Corporate messenger for your team. Distributed as x86-64 binary from https://artifacts.wilix.dev/repository/loop-files/loop-6.0.3/loop-desktop-6.0.3-linux-x64.tar.gz","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-29T16:41:37Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-29T16:51:32Z","started_at":"2026-05-29T16:42:02Z","closed_at":"2026-05-29T16:51:32Z","close_reason":"Closed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-cdt","title":"radar-1.6.1","description":"update package radar to v1.6.1","status":"closed","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-05-17T12:41:54Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-17T13:03:38Z","closed_at":"2026-05-17T13:03:38Z","close_reason":"Closed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-27z","title":"freebuff","description":"В данный nixos overlay репозиторй необходимо добавить новый пакет https://www.npmjs.com/package/freebuff .\nИспользуй mcp: nixos, karpathy-guidelines и Sequential Thinking для планирования шаг за шагом задачи. Управление тасками используй beads. Разбей задачу на подзадачи, используя beads с указанием parent task.\n\nRequired Skills\ncaveman,karpathy-guidelines,nix,nix-flakes","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T16:11:44Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T17:03:53Z","started_at":"2026-05-11T16:17:34Z","closed_at":"2026-05-11T17:03:53Z","close_reason":"Closed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc.5","title":"Update package metadata and updateScript","description":"Remove binaryNativeCode sourceProvenance, update meta, adjust updateScript for source build","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T13:51:22Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T15:01:06Z","started_at":"2026-05-11T14:59:33Z","closed_at":"2026-05-11T15:01:06Z","close_reason":"Closed","dependencies":[{"issue_id":"nix-overlay-qlc.5","depends_on_id":"nix-overlay-qlc","type":"parent-child","created_at":"2026-05-11T16:51:21Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc.4","title":"Test build and verify functionality","description":"Build radar from source and verify it runs correctly","status":"closed","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-05-11T13:51:11Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T14:59:55Z","closed_at":"2026-05-11T14:59:55Z","close_reason":"Closed","dependencies":[{"issue_id":"nix-overlay-qlc.4","depends_on_id":"nix-overlay-qlc","type":"parent-child","created_at":"2026-05-11T16:51:10Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc.3","title":"Handle go:embed frontend assets","description":"Ensure frontend assets are copied to internal/static/dist before Go build so go:embed works correctly","status":"closed","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-05-11T13:51:02Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T14:59:55Z","closed_at":"2026-05-11T14:59:55Z","close_reason":"Closed","dependencies":[{"issue_id":"nix-overlay-qlc.3","depends_on_id":"nix-overlay-qlc","type":"parent-child","created_at":"2026-05-11T16:51:02Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc.2","title":"Configure npm dependencies for frontend build","description":"Set up npmDependencies hash for the Vite/React frontend build within buildGoModule","status":"closed","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-05-11T13:50:53Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T14:59:55Z","closed_at":"2026-05-11T14:59:55Z","close_reason":"Closed","dependencies":[{"issue_id":"nix-overlay-qlc.2","depends_on_id":"nix-overlay-qlc","type":"parent-child","created_at":"2026-05-11T16:50:52Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc.1","title":"Update radar default.nix to use buildGoModule","description":"Change package.nix from stdenv.mkDerivation with fetchurl to buildGoModule pattern","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T13:50:42Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T14:59:55Z","started_at":"2026-05-11T13:51:49Z","closed_at":"2026-05-11T14:59:55Z","close_reason":"Closed","dependencies":[{"issue_id":"nix-overlay-qlc.1","depends_on_id":"nix-overlay-qlc","type":"parent-child","created_at":"2026-05-11T16:50:41Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc","title":"Rebuild radar package from source instead of prebuilt binary","description":"Current radar package uses prebuilt binary from GitHub releases. Need to rebuild from source using nix native tooling (buildGoModule + npm for frontend). Build pipeline: 1) npm run build for frontend, 2) copy assets to internal/static/dist, 3) CGO_ENABLED=0 go build with embedded assets.","status":"closed","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-05-11T13:50:27Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T15:01:06Z","closed_at":"2026-05-11T15:01:06Z","close_reason":"Closed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-y8r","title":"nix-overlay-2lr-3 · Approach 3: ручной npm cache + buildGoModule [parent:nix-overlay-2lr]","notes":"BLOCKED: fetchNpmDeps v2 не загружает workspace-scoped пакеты (@vitejs/plugin-react ENOTCACHED) даже с makeCacheWritable=true. Все 3 подхода заблокированы одним ограничением — fetchNpmDeps v2 не поддерживает npm workspaces корректно, вопреки release notes.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T09:38:34Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T11:14:40Z","started_at":"2026-05-11T10:23:41Z","closed_at":"2026-05-11T11:14:40Z","dependencies":[{"issue_id":"nix-overlay-y8r","depends_on_id":"nix-overlay-2lr","type":"parent-child","created_at":"2026-05-11T12:42:18Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-dcx","title":"nix-overlay-2lr-2 · Approach 2: bun2nix генерация пакетов [parent:nix-overlay-2lr]","notes":"Skipping bun2nix — требует staging branch, неочевидная поддержка npm lockfiles. Проще перейти к Approach 3 (ручной stdenv.mkDerivation с nodejs/npm).","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T09:38:06Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T10:23:18Z","started_at":"2026-05-11T10:21:04Z","closed_at":"2026-05-11T10:23:18Z","dependencies":[{"issue_id":"nix-overlay-dcx","depends_on_id":"nix-overlay-2lr","type":"parent-child","created_at":"2026-05-11T12:42:12Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-3ik","title":"nix-overlay-2lr-1 · Approach 1: buildNpmPackage + buildGoModule с npmDepsFetcherVersion=2 [parent:nix-overlay-2lr]","notes":"fetchNpmDeps v2 не resolves workspace-scoped packages (@vitejs/plugin-react ENOTCACHED). Approach blocked — same issue as previous attempt. Moving to Approach 2 (bun2nix).","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T09:37:43Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T10:20:38Z","started_at":"2026-05-11T09:39:05Z","closed_at":"2026-05-11T10:20:38Z","dependencies":[{"issue_id":"nix-overlay-3ik","depends_on_id":"nix-overlay-2lr","type":"parent-child","created_at":"2026-05-11T12:41:54Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-2lr","title":"radar","description":"Используй karpathy-guidelines и Sequential Thinking для планирования шаг за шагом добавления нового пакета https://github.com/skyhook-io/radar.git в данный NIXOS overlay-репозиторий. Разбей задачу на подзадачи, используя beads. В написании кода используй mcp: nixos, refContext и context7.\n\n\n\n## Required Skills\ncaveman,karpathy-guidelines,nix,nix-flakes","notes":"Все 3 подхода провалены. fetchNpmDeps v2 НЕ работает с npm workspaces вопреки release notes - ENOTCACHED для workspace-scoped пакетов (@vitejs/plugin-react). Ручной сбор node_modules без npm ci слишком сложен (требует reimplement fetchNpmDeps). Текущее решение: pre-built binary из GitHub Releases. Нужно дождаться исправления fetchNpmDeps v2 в nixpkgs или upstream поддержки standalone lockfile для web/.","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-10T19:28:56Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T11:24:40Z","started_at":"2026-05-10T19:30:31Z","closed_at":"2026-05-11T11:24:40Z","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-k38","title":"Bump llama-cpp pin b9645 -\u003e b10944","description":"packages/llama-cpp pins ggml-org/llama.cpp to b9645 and intentionally removes passthru.updateScript. Upstream latest is b10944. The nixpkgs llama-cpp skeleton and custom HIP/cmake flags (gfx1151 Strix Halo) target b9645; a bump needs re-validating flags (e.g. hipBLASLt/rocWMMA/unified-memory) and a full ROCm rebuild. Do manually per the comment in package.nix.","status":"open","priority":3,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-09-13T18:05:55Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T18:05:55Z","dependency_count":0,"dependent_count":0,"comment_count":0}
+7
View File
@@ -0,0 +1,7 @@
{
"database": "dolt",
"backend": "dolt",
"dolt_mode": "embedded",
"dolt_database": "nix_overlay",
"project_id": "bf9206b6-9430-479c-bc02-786cff5dbffc"
}
+26
View File
@@ -0,0 +1,26 @@
{
"hooks": {
"PreCompact": [
{
"hooks": [
{
"command": "bd prime",
"type": "command"
}
],
"matcher": ""
}
],
"SessionStart": [
{
"hooks": [
{
"command": "bd prime",
"type": "command"
}
],
"matcher": ""
}
]
}
}
+20
View File
@@ -0,0 +1,20 @@
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: cachix/install-nix-action@v27
with:
nix_path: nixpkgs=channel:nixos-unstable
- name: Flake check (formatting + evaluation)
run: nix flake check
- name: Build all packages (best-effort, may time out)
run: nix build .#packages || true
+13
View File
@@ -0,0 +1,13 @@
.qoder
.qwen
.claude/
result
result-*
.direnv/
.tasks/
# Beads / Dolt files (added by bd init)
.dolt/
*.db
.beads-credential-key
logs/
+431
View File
@@ -0,0 +1,431 @@
# AGENTS.md - Instructions for AI Agents
This file provides guidance to AI agents (such as Claude, GPT, Goose, etc.) when working with this Nix overlay repository.
## Project Overview
This is a **Nix flake overlay** repository that provides additional packages for Nix/NixOS users. It uses [numtide/blueprint](https://github.com/numtide/blueprint) as its foundation, which simplifies flake development by providing sensible defaults and automatic package discovery.
**Repository URL**: `git+https://git.millerson.name/alex/millerson-overlay.nix.git`
## Key Concepts
1. Don't assume. Don't hide confusion. Surface tradeoffs.
2. Minimum code that solves the problem. Nothing speculative.
3. Touch only what you must. Clean up only your own mess.
4. Define success criteria. Loop until verified.
## Before Starting Any Work
**MANDATORY** — Before writing code, running builds, or making any changes:
1. **Run `bd prime`** — Get full workflow context and available commands
2. **Check for existing issues** — Run `bd ready` to find available work
3. **Claim the task** — Use `bd update <id> --claim` before starting
4. **Track via `bd` ONLY** — NEVER use TodoWrite, TaskCreate, or markdown TODO lists. All task tracking goes through `bd`.
Violating this rule means the agent is working outside the project's workflow. Stop and re-claim via `bd` first.
### Required Skills
Always use these skills when working with this repository:
- **nix** - For nixpkgs package lookups, option searches, and NixOS/Home Manager queries
- **nix-flakes** - For reproducible builds, flake management, and devShell operations
- **karpathy-guidelines** - For high-quality task execution best practices
### Required MCP Server
- **sequentialthinking** — MUST be used for ANY planning, problem-solving, or decision-making.
Invoke `sequentialthinking` MCP before:
- Designing implementation approaches
- Debugging non-obvious issues
- Evaluating trade-offs between approaches
- Breaking down complex tasks
- When you're uncertain about the best path forward
Do NOT skip deliberative thinking. Surface reasoning through sequentialthinking before acting.
### Communication: Caveman Mode
Use **caveman** skill for all user-facing communication. Responses should be:
- Ultra-compressed — cut token waste, keep technical substance
- Direct — no filler, no hedging, no "I'd recommend"
- Action-oriented — state what was done and what's next
Trigger: `skill: "caveman"` before responding to the user.
### Blueprint Framework
This project uses `numtide/blueprint` which:
- Automatically discovers packages in the `packages/` directory
- Provides `perSystem` outputs for multi-system builds
- Handles formatting, checking, and devShell generation
- Exposes `mkPackagesFor` function to build packages against any nixpkgs instance
**Important**: Blueprint's package discovery reads from the git index, not the working directory. New package directories must be staged with `git add` before they appear in flake outputs. Unstaged files are invisible to `nix build`, `nix flake show`, and `nix run`.
### Two Overlay Strategies
1. **`overlays.default`** - Binary-cache-friendly
- Uses packages built against this flake's nixpkgs revision
- Better for binary cache hits when using the same nixpkgs
2. **`overlays.shared-nixpkgs`** - Dependency-sharing
- Builds packages against the consumer's nixpkgs (`final`)
- Shares dependencies with the rest of the system
- No second nixpkgs evaluation
- Trade-off: binary cache only hits when consumer's nixpkgs matches ours
## Repository Structure
```
nix-overlay/
├── flake.nix # Main flake definition with inputs and outputs
├── overlays/
│ ├── default.nix # Overlay using pre-built packages (binary cache friendly)
│ └── shared-nixpkgs.nix # Overlay building against consumer's nixpkgs
├── packages/
│ ├── default/ # Meta-package listing all visible packages
│ │ ├── default.nix
│ │ └── package.nix
│ └── flake-inputs/ # Utility to cache all flake inputs
│ └── default.nix
├── README.md # User-facing documentation
├── AGENTS.md # This file - AI agent instructions
├── LICENSE
└── flake.lock
```
## Package Definition Pattern
### Standard Package Structure
Each package should follow this structure:
```
packages/<package-name>/
├── default.nix # Wrapper that receives blueprint args (pkgs, perSystem, etc.)
└── package.nix # Actual package definition using pkgs.callPackage pattern
```
### `default.nix` Pattern
```nix
{
pkgs,
perSystem,
...
}:
pkgs.callPackage ./package.nix {
# Pass any extra arguments here
}
```
### `package.nix` Pattern
```nix
{
lib,
stdenv,
# ... package-specific dependencies
}:
stdenv.mkDerivation rec {
pname = "my-package";
version = "1.0.0";
src = fetchFromGitHub {
owner = "user";
repo = "repo";
rev = "v${version}";
hash = "sha256-...";
};
# ... build instructions
meta = with lib; {
description = "Brief description";
homepage = "https://...";
license = licenses.mit;
maintainers = with maintainers; [ ];
platforms = platforms.all;
mainProgram = "program-name";
};
}
```
### Rust Packages
For Rust packages, use `rustPlatform.buildRustPackage`:
```nix
{
lib,
rustPlatform,
fetchFromGitHub,
...
}:
rustPlatform.buildRustPackage rec {
pname = "my-rust-app";
version = "1.0.0";
src = fetchFromGitHub { ... };
cargoHash = "sha256-...";
# ... build instructions
meta = { ... };
}
```
## Adding a New Package
When adding a new package:
1. **Create the directory**: `mkdir -p packages/<package-name>`
2. **Create `package.nix`** with the actual derivation
3. **Create `default.nix`** as a wrapper:
```nix
{ pkgs, ... }:
pkgs.callPackage ./package.nix { }
```
3.5. **Stage the package**: `git add packages/<package-name>/`
Blueprint discovers packages from the git index, not the working directory.
Without this step, the package won't appear in flake outputs.
4. **Test the package**:
```bash
nix build .#<package-name>
nix run .#<package-name>
```
5. **Update README.md** to document the new package in the Available Packages table
6. **Set appropriate metadata**:
- `meta.description` - Required, shown in package listings
- `meta.mainProgram` - Set for packages providing a CLI executable
- `meta.passthru.category` - Optional, used for organization (e.g., "AI Coding Agents")
- `meta.passthru.hideFromDocs` - Set to `true` to exclude from documentation
## Common Tasks
### Updating a Package Version
1. Update `version` in `package.nix`
2. Update `src.hash` (use `nix-prefetch-github` or let Nix tell you the correct hash)
3. Update `cargoHash` for Rust packages (build will fail and tell you the correct hash)
4. Test: `nix build .#<package-name>`
5. Update README if needed
### Testing Changes
```bash
# Build specific package
nix build .#mcp-gateway
# Build all packages for current system
nix build .#packages
# Enter dev shell
nix develop
# Check formatting
nix flake check
```
### Working with Overlays
When modifying overlay behavior:
- **`overlays/default.nix`**: Receives `packages` from blueprint outputs, maps them to `final.stdenv.hostPlatform.system`
- **`overlays/shared-nixpkgs.nix`**: Receives `mkPackagesFor`, uses it to build against consumer's `final`
## Important Notes
### Do's
- ✅ Use `pkgs.callPackage` pattern for package definitions
- ✅ Set proper `meta` attributes (description, license, homepage)
- ✅ Test packages with `nix build` before committing
- ✅ Use `passthru.category` for organizational grouping
- ✅ Follow Nixpkgs conventions for package naming and structure
### Don'ts
- ❌ Don't modify `flake.lock` manually - use `nix flake update`
- ❌ Don't hardcode system-specific paths or assumptions
- ❌ Don't forget to set `meta.mainProgram` for CLI tools
- ❌ Don't use `with pkgs;` at top level (can cause scope issues)
- ❌ Don't commit packages that don't build
## Debugging Tips
### Package Doesn't Build
1. Check the error message carefully
2. Verify all dependencies are listed
3. Check if the source hash is correct
4. For Rust packages, verify `cargoHash` matches
### Overlay Not Working
1. Verify the overlay is correctly imported
2. Check if the package exists in `packages` output
3. For `shared-nixpkgs`, ensure `mkPackagesFor` is available
### Binary Cache Issues
- The `default` overlay is more likely to get cache hits
- The `shared-nixpkgs` overlay builds from source unless nixpkgs revisions match
## Resources
- [Nixpkgs Manual](https://nixos.org/manual/nixpkgs/stable/)
- [Blueprint Documentation](https://github.com/numtide/blueprint)
- [Nix Flake Patterns](https://github.com/NixOS/flake-patterns)
- [Rust in Nixpkgs](https://nixos.org/manual/nixpkgs/stable/#rust)
## Updating Packages
Use [nix-update](https://github.com/Mic92/nix-update) to bump versions and update hashes:
```bash
# Update a package to the latest version
nix-update <package-name>
# Update to a specific version
nix-update <package-name> --version <version>
# Update a package pinned to a commit hash (e.g. skillsmcp)
nix-update <package-name> --version=branch=main
```
After updating, always test the build:
```bash
nix build .#<package-name>
```
### Package-Specific Notes
- **mcp-gateway**: Standard Rust package, `nix-update` handles version + cargoHash
- **skillsmcp**: Pinned to a commit hash; use `--version=branch=main` or specify the target commit with `--commit`
## Git Workflow
### Committing Completed Work
Every completed job or feature must be committed to the git repository.
When preparing git commits, always use the `conventional-commit` skill to create proper commit messages following conventional commit conventions.
This ensures:
- Clean git history with proper commit message formatting
- No work is left uncommitted
- Consistent commit message style across the project
### Advanced Git Operations
For advanced Git workflows (rebasing, cherry-picking, bisect, worktrees, reflog, history recovery), use the `git-advanced-workflows` skill.
This skill provides:
- Master advanced Git workflows including rebasing, cherry-picking, bisect, worktrees, and reflog
- Maintain clean history and recover from any situation
- Manage complex Git histories, collaborate on feature branches, or troubleshoot repository issues
## Example Workflow: Adding a New Package
```bash
# 0. Claim the task via beads (MANDATORY before any work)
bd ready # Find available work
bd show <id> # Review task details
bd update <id> --claim # Claim the task
# 1. Create package directory
mkdir -p packages/my-tool
# 2. Create package.nix (use appropriate template above)
# 3. Create default.nix wrapper
cat > packages/my-tool/default.nix << 'EOF'
{ pkgs, ... }:
pkgs.callPackage ./package.nix { }
EOF
# 3.5. Stage for Blueprint discovery
git add packages/my-tool/
# 4. Test build
nix build .#my-tool
# 5. If build fails, fix issues, then retry
# 6. Update README.md with new package info
# 7. Commit changes using conventional-commit skill
git add packages/my-tool README.md
# Then invoke: skill: "conventional-commit"
# 8. Close the task via beads
bd close <id> # Mark task as complete
```
<!-- BEGIN BEADS INTEGRATION v:1 profile:minimal hash:ca08a54f -->
## Beads Issue Tracker
This project uses **bd (beads)** for issue tracking. Run `bd prime` to see full workflow context and commands.
### Quick Reference
```bash
bd prime # ALWAYS run first — get full context and command reference
bd ready # Find available work
bd show <id> # View issue details
bd update <id> --claim # Claim work (do this BEFORE starting any task)
bd close <id> # Complete work (do this AFTER pushing changes)
bd remember # Save persistent knowledge (use instead of MEMORY.md files)
```
### Rules
- **Use `bd` for ALL task tracking** — do NOT use TodoWrite, TaskCreate, or markdown TODO lists
- **Run `bd prime` BEFORE starting any work** — this provides session context and close protocol
- **Run `bd remember` for persistent knowledge** — do NOT use MEMORY.md files
- **If you forgot to claim** — stop working and claim via `bd` immediately
## Session Completion
**When ending a work session**, you MUST complete ALL steps below. Work is NOT complete until `git push` succeeds.
**MANDATORY WORKFLOW:**
1. **File issues for remaining work** - Create issues for anything that needs follow-up
2. **Run quality gates** (if code changed) - Tests, linters, builds
3. **Update issue status** - Close finished work, update in-progress items
4. **PUSH TO REMOTE** - This is MANDATORY:
```bash
git pull --rebase
bd dolt push
git push
git status # MUST show "up to date with origin"
```
Note: no Dolt remote is configured for this workspace, so `bd dolt push`
prints `No remote is configured — skipping.` and exits. That is expected,
NOT a failure. Beads state is versioned locally in `.beads/` and synced to
the shared repository via `git push` — the `git status` check above is the
real completion gate.
5. **Clean up** - Clear stashes, prune remote branches
6. **Verify** - All changes committed AND pushed
7. **Hand off** - Provide context for next session
**CRITICAL RULES:**
- Work is NOT complete until `git push` succeeds
- NEVER stop before pushing - that leaves work stranded locally
- NEVER say "ready to push when you are" - YOU must push
- If push fails, resolve and retry until it succeeds
<!-- END BEADS INTEGRATION -->
+69
View File
@@ -0,0 +1,69 @@
# Project Instructions for AI Agents
This file provides instructions and context for AI coding agents working on this project.
<!-- BEGIN BEADS INTEGRATION v:1 profile:minimal hash:ca08a54f -->
## Beads Issue Tracker
This project uses **bd (beads)** for issue tracking. Run `bd prime` to see full workflow context and commands.
### Quick Reference
```bash
bd ready # Find available work
bd show <id> # View issue details
bd update <id> --claim # Claim work
bd close <id> # Complete work
```
### Rules
- Use `bd` for ALL task tracking — do NOT use TodoWrite, TaskCreate, or markdown TODO lists
- Run `bd prime` for detailed command reference and session close protocol
- Use `bd remember` for persistent knowledge — do NOT use MEMORY.md files
## Session Completion
**When ending a work session**, you MUST complete ALL steps below. Work is NOT complete until `git push` succeeds.
**MANDATORY WORKFLOW:**
1. **File issues for remaining work** - Create issues for anything that needs follow-up
2. **Run quality gates** (if code changed) - Tests, linters, builds
3. **Update issue status** - Close finished work, update in-progress items
4. **PUSH TO REMOTE** - This is MANDATORY:
```bash
git pull --rebase
bd dolt push
git push
git status # MUST show "up to date with origin"
```
5. **Clean up** - Clear stashes, prune remote branches
6. **Verify** - All changes committed AND pushed
7. **Hand off** - Provide context for next session
**CRITICAL RULES:**
- Work is NOT complete until `git push` succeeds
- NEVER stop before pushing - that leaves work stranded locally
- NEVER say "ready to push when you are" - YOU must push
- If push fails, resolve and retry until it succeeds
<!-- END BEADS INTEGRATION -->
## Build & Test
_Add your build and test commands here_
```bash
# Example:
# npm install
# npm test
```
## Architecture Overview
_Add a brief overview of your project architecture_
## Conventions & Patterns
_Add your project-specific conventions here_
-7
View File
@@ -1,7 +0,0 @@
This repository is being used as a Dolt remote.
ref=refs/dolt/data
head=d617fee02881f9fcdd34e80762b9052ba12a55b6
timestamp=2026-10-04T16:54:24Z
+232
View File
@@ -0,0 +1,232 @@
GNU GENERAL PUBLIC LICENSE
Version 3, 29 June 2007
Copyright © 2007 Free Software Foundation, Inc. <https://fsf.org/>
Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed.
Preamble
The GNU General Public License is a free, copyleft license for software and other kinds of works.
The licenses for most software and other practical works are designed to take away your freedom to share and change the works. By contrast, the GNU General Public License is intended to guarantee your freedom to share and change all versions of a program--to make sure it remains free software for all its users. We, the Free Software Foundation, use the GNU General Public License for most of our software; it applies also to any other work released this way by its authors. You can apply it to your programs, too.
When we speak of free software, we are referring to freedom, not price. Our General Public Licenses are designed to make sure that you have the freedom to distribute copies of free software (and charge for them if you wish), that you receive source code or can get it if you want it, that you can change the software or use pieces of it in new free programs, and that you know you can do these things.
To protect your rights, we need to prevent others from denying you these rights or asking you to surrender the rights. Therefore, you have certain responsibilities if you distribute copies of the software, or if you modify it: responsibilities to respect the freedom of others.
For example, if you distribute copies of such a program, whether gratis or for a fee, you must pass on to the recipients the same freedoms that you received. You must make sure that they, too, receive or can get the source code. And you must show them these terms so they know their rights.
Developers that use the GNU GPL protect your rights with two steps: (1) assert copyright on the software, and (2) offer you this License giving you legal permission to copy, distribute and/or modify it.
For the developers' and authors' protection, the GPL clearly explains that there is no warranty for this free software. For both users' and authors' sake, the GPL requires that modified versions be marked as changed, so that their problems will not be attributed erroneously to authors of previous versions.
Some devices are designed to deny users access to install or run modified versions of the software inside them, although the manufacturer can do so. This is fundamentally incompatible with the aim of protecting users' freedom to change the software. The systematic pattern of such abuse occurs in the area of products for individuals to use, which is precisely where it is most unacceptable. Therefore, we have designed this version of the GPL to prohibit the practice for those products. If such problems arise substantially in other domains, we stand ready to extend this provision to those domains in future versions of the GPL, as needed to protect the freedom of users.
Finally, every program is threatened constantly by software patents. States should not allow patents to restrict development and use of software on general-purpose computers, but in those that do, we wish to avoid the special danger that patents applied to a free program could make it effectively proprietary. To prevent this, the GPL assures that patents cannot be used to render the program non-free.
The precise terms and conditions for copying, distribution and modification follow.
TERMS AND CONDITIONS
0. Definitions.
“This License” refers to version 3 of the GNU General Public License.
“Copyright” also means copyright-like laws that apply to other kinds of works, such as semiconductor masks.
“The Program” refers to any copyrightable work licensed under this License. Each licensee is addressed as “you”. “Licensees” and “recipients” may be individuals or organizations.
To “modify” a work means to copy from or adapt all or part of the work in a fashion requiring copyright permission, other than the making of an exact copy. The resulting work is called a “modified version” of the earlier work or a work “based on” the earlier work.
A “covered work” means either the unmodified Program or a work based on the Program.
To “propagate” a work means to do anything with it that, without permission, would make you directly or secondarily liable for infringement under applicable copyright law, except executing it on a computer or modifying a private copy. Propagation includes copying, distribution (with or without modification), making available to the public, and in some countries other activities as well.
To “convey” a work means any kind of propagation that enables other parties to make or receive copies. Mere interaction with a user through a computer network, with no transfer of a copy, is not conveying.
An interactive user interface displays “Appropriate Legal Notices” to the extent that it includes a convenient and prominently visible feature that (1) displays an appropriate copyright notice, and (2) tells the user that there is no warranty for the work (except to the extent that warranties are provided), that licensees may convey the work under this License, and how to view a copy of this License. If the interface presents a list of user commands or options, such as a menu, a prominent item in the list meets this criterion.
1. Source Code.
The “source code” for a work means the preferred form of the work for making modifications to it. “Object code” means any non-source form of a work.
A “Standard Interface” means an interface that either is an official standard defined by a recognized standards body, or, in the case of interfaces specified for a particular programming language, one that is widely used among developers working in that language.
The “System Libraries” of an executable work include anything, other than the work as a whole, that (a) is included in the normal form of packaging a Major Component, but which is not part of that Major Component, and (b) serves only to enable use of the work with that Major Component, or to implement a Standard Interface for which an implementation is available to the public in source code form. A “Major Component”, in this context, means a major essential component (kernel, window system, and so on) of the specific operating system (if any) on which the executable work runs, or a compiler used to produce the work, or an object code interpreter used to run it.
The “Corresponding Source” for a work in object code form means all the source code needed to generate, install, and (for an executable work) run the object code and to modify the work, including scripts to control those activities. However, it does not include the work's System Libraries, or general-purpose tools or generally available free programs which are used unmodified in performing those activities but which are not part of the work. For example, Corresponding Source includes interface definition files associated with source files for the work, and the source code for shared libraries and dynamically linked subprograms that the work is specifically designed to require, such as by intimate data communication or control flow between those subprograms and other parts of the work.
The Corresponding Source need not include anything that users can regenerate automatically from other parts of the Corresponding Source.
The Corresponding Source for a work in source code form is that same work.
2. Basic Permissions.
All rights granted under this License are granted for the term of copyright on the Program, and are irrevocable provided the stated conditions are met. This License explicitly affirms your unlimited permission to run the unmodified Program. The output from running a covered work is covered by this License only if the output, given its content, constitutes a covered work. This License acknowledges your rights of fair use or other equivalent, as provided by copyright law.
You may make, run and propagate covered works that you do not convey, without conditions so long as your license otherwise remains in force. You may convey covered works to others for the sole purpose of having them make modifications exclusively for you, or provide you with facilities for running those works, provided that you comply with the terms of this License in conveying all material for which you do not control copyright. Those thus making or running the covered works for you must do so exclusively on your behalf, under your direction and control, on terms that prohibit them from making any copies of your copyrighted material outside their relationship with you.
Conveying under any other circumstances is permitted solely under the conditions stated below. Sublicensing is not allowed; section 10 makes it unnecessary.
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
No covered work shall be deemed part of an effective technological measure under any applicable law fulfilling obligations under article 11 of the WIPO copyright treaty adopted on 20 December 1996, or similar laws prohibiting or restricting circumvention of such measures.
When you convey a covered work, you waive any legal power to forbid circumvention of technological measures to the extent such circumvention is effected by exercising rights under this License with respect to the covered work, and you disclaim any intention to limit operation or modification of the work as a means of enforcing, against the work's users, your or third parties' legal rights to forbid circumvention of technological measures.
4. Conveying Verbatim Copies.
You may convey verbatim copies of the Program's source code as you receive it, in any medium, provided that you conspicuously and appropriately publish on each copy an appropriate copyright notice; keep intact all notices stating that this License and any non-permissive terms added in accord with section 7 apply to the code; keep intact all notices of the absence of any warranty; and give all recipients a copy of this License along with the Program.
You may charge any price or no price for each copy that you convey, and you may offer support or warranty protection for a fee.
5. Conveying Modified Source Versions.
You may convey a work based on the Program, or the modifications to produce it from the Program, in the form of source code under the terms of section 4, provided that you also meet all of these conditions:
a) The work must carry prominent notices stating that you modified it, and giving a relevant date.
b) The work must carry prominent notices stating that it is released under this License and any conditions added under section 7. This requirement modifies the requirement in section 4 to “keep intact all notices”.
c) You must license the entire work, as a whole, under this License to anyone who comes into possession of a copy. This License will therefore apply, along with any applicable section 7 additional terms, to the whole of the work, and all its parts, regardless of how they are packaged. This License gives no permission to license the work in any other way, but it does not invalidate such permission if you have separately received it.
d) If the work has interactive user interfaces, each must display Appropriate Legal Notices; however, if the Program has interactive interfaces that do not display Appropriate Legal Notices, your work need not make them do so.
A compilation of a covered work with other separate and independent works, which are not by their nature extensions of the covered work, and which are not combined with it such as to form a larger program, in or on a volume of a storage or distribution medium, is called an “aggregate” if the compilation and its resulting copyright are not used to limit the access or legal rights of the compilation's users beyond what the individual works permit. Inclusion of a covered work in an aggregate does not cause this License to apply to the other parts of the aggregate.
6. Conveying Non-Source Forms.
You may convey a covered work in object code form under the terms of sections 4 and 5, provided that you also convey the machine-readable Corresponding Source under the terms of this License, in one of these ways:
a) Convey the object code in, or embodied in, a physical product (including a physical distribution medium), accompanied by the Corresponding Source fixed on a durable physical medium customarily used for software interchange.
b) Convey the object code in, or embodied in, a physical product (including a physical distribution medium), accompanied by a written offer, valid for at least three years and valid for as long as you offer spare parts or customer support for that product model, to give anyone who possesses the object code either (1) a copy of the Corresponding Source for all the software in the product that is covered by this License, on a durable physical medium customarily used for software interchange, for a price no more than your reasonable cost of physically performing this conveying of source, or (2) access to copy the Corresponding Source from a network server at no charge.
c) Convey individual copies of the object code with a copy of the written offer to provide the Corresponding Source. This alternative is allowed only occasionally and noncommercially, and only if you received the object code with such an offer, in accord with subsection 6b.
d) Convey the object code by offering access from a designated place (gratis or for a charge), and offer equivalent access to the Corresponding Source in the same way through the same place at no further charge. You need not require recipients to copy the Corresponding Source along with the object code. If the place to copy the object code is a network server, the Corresponding Source may be on a different server (operated by you or a third party) that supports equivalent copying facilities, provided you maintain clear directions next to the object code saying where to find the Corresponding Source. Regardless of what server hosts the Corresponding Source, you remain obligated to ensure that it is available for as long as needed to satisfy these requirements.
e) Convey the object code using peer-to-peer transmission, provided you inform other peers where the object code and Corresponding Source of the work are being offered to the general public at no charge under subsection 6d.
A separable portion of the object code, whose source code is excluded from the Corresponding Source as a System Library, need not be included in conveying the object code work.
A “User Product” is either (1) a “consumer product”, which means any tangible personal property which is normally used for personal, family, or household purposes, or (2) anything designed or sold for incorporation into a dwelling. In determining whether a product is a consumer product, doubtful cases shall be resolved in favor of coverage. For a particular product received by a particular user, “normally used” refers to a typical or common use of that class of product, regardless of the status of the particular user or of the way in which the particular user actually uses, or expects or is expected to use, the product. A product is a consumer product regardless of whether the product has substantial commercial, industrial or non-consumer uses, unless such uses represent the only significant mode of use of the product.
“Installation Information” for a User Product means any methods, procedures, authorization keys, or other information required to install and execute modified versions of a covered work in that User Product from a modified version of its Corresponding Source. The information must suffice to ensure that the continued functioning of the modified object code is in no case prevented or interfered with solely because modification has been made.
If you convey an object code work under this section in, or with, or specifically for use in, a User Product, and the conveying occurs as part of a transaction in which the right of possession and use of the User Product is transferred to the recipient in perpetuity or for a fixed term (regardless of how the transaction is characterized), the Corresponding Source conveyed under this section must be accompanied by the Installation Information. But this requirement does not apply if neither you nor any third party retains the ability to install modified object code on the User Product (for example, the work has been installed in ROM).
The requirement to provide Installation Information does not include a requirement to continue to provide support service, warranty, or updates for a work that has been modified or installed by the recipient, or for the User Product in which it has been modified or installed. Access to a network may be denied when the modification itself materially and adversely affects the operation of the network or violates the rules and protocols for communication across the network.
Corresponding Source conveyed, and Installation Information provided, in accord with this section must be in a format that is publicly documented (and with an implementation available to the public in source code form), and must require no special password or key for unpacking, reading or copying.
7. Additional Terms.
“Additional permissions” are terms that supplement the terms of this License by making exceptions from one or more of its conditions. Additional permissions that are applicable to the entire Program shall be treated as though they were included in this License, to the extent that they are valid under applicable law. If additional permissions apply only to part of the Program, that part may be used separately under those permissions, but the entire Program remains governed by this License without regard to the additional permissions.
When you convey a copy of a covered work, you may at your option remove any additional permissions from that copy, or from any part of it. (Additional permissions may be written to require their own removal in certain cases when you modify the work.) You may place additional permissions on material, added by you to a covered work, for which you have or can give appropriate copyright permission.
Notwithstanding any other provision of this License, for material you add to a covered work, you may (if authorized by the copyright holders of that material) supplement the terms of this License with terms:
a) Disclaiming warranty or limiting liability differently from the terms of sections 15 and 16 of this License; or
b) Requiring preservation of specified reasonable legal notices or author attributions in that material or in the Appropriate Legal Notices displayed by works containing it; or
c) Prohibiting misrepresentation of the origin of that material, or requiring that modified versions of such material be marked in reasonable ways as different from the original version; or
d) Limiting the use for publicity purposes of names of licensors or authors of the material; or
e) Declining to grant rights under trademark law for use of some trade names, trademarks, or service marks; or
f) Requiring indemnification of licensors and authors of that material by anyone who conveys the material (or modified versions of it) with contractual assumptions of liability to the recipient, for any liability that these contractual assumptions directly impose on those licensors and authors.
All other non-permissive additional terms are considered “further restrictions” within the meaning of section 10. If the Program as you received it, or any part of it, contains a notice stating that it is governed by this License along with a term that is a further restriction, you may remove that term. If a license document contains a further restriction but permits relicensing or conveying under this License, you may add to a covered work material governed by the terms of that license document, provided that the further restriction does not survive such relicensing or conveying.
If you add terms to a covered work in accord with this section, you must place, in the relevant source files, a statement of the additional terms that apply to those files, or a notice indicating where to find the applicable terms.
Additional terms, permissive or non-permissive, may be stated in the form of a separately written license, or stated as exceptions; the above requirements apply either way.
8. Termination.
You may not propagate or modify a covered work except as expressly provided under this License. Any attempt otherwise to propagate or modify it is void, and will automatically terminate your rights under this License (including any patent licenses granted under the third paragraph of section 11).
However, if you cease all violation of this License, then your license from a particular copyright holder is reinstated (a) provisionally, unless and until the copyright holder explicitly and finally terminates your license, and (b) permanently, if the copyright holder fails to notify you of the violation by some reasonable means prior to 60 days after the cessation.
Moreover, your license from a particular copyright holder is reinstated permanently if the copyright holder notifies you of the violation by some reasonable means, this is the first time you have received notice of violation of this License (for any work) from that copyright holder, and you cure the violation prior to 30 days after your receipt of the notice.
Termination of your rights under this section does not terminate the licenses of parties who have received copies or rights from you under this License. If your rights have been terminated and not permanently reinstated, you do not qualify to receive new licenses for the same material under section 10.
9. Acceptance Not Required for Having Copies.
You are not required to accept this License in order to receive or run a copy of the Program. Ancillary propagation of a covered work occurring solely as a consequence of using peer-to-peer transmission to receive a copy likewise does not require acceptance. However, nothing other than this License grants you permission to propagate or modify any covered work. These actions infringe copyright if you do not accept this License. Therefore, by modifying or propagating a covered work, you indicate your acceptance of this License to do so.
10. Automatic Licensing of Downstream Recipients.
Each time you convey a covered work, the recipient automatically receives a license from the original licensors, to run, modify and propagate that work, subject to this License. You are not responsible for enforcing compliance by third parties with this License.
An “entity transaction” is a transaction transferring control of an organization, or substantially all assets of one, or subdividing an organization, or merging organizations. If propagation of a covered work results from an entity transaction, each party to that transaction who receives a copy of the work also receives whatever licenses to the work the party's predecessor in interest had or could give under the previous paragraph, plus a right to possession of the Corresponding Source of the work from the predecessor in interest, if the predecessor has it or can get it with reasonable efforts.
You may not impose any further restrictions on the exercise of the rights granted or affirmed under this License. For example, you may not impose a license fee, royalty, or other charge for exercise of rights granted under this License, and you may not initiate litigation (including a cross-claim or counterclaim in a lawsuit) alleging that any patent claim is infringed by making, using, selling, offering for sale, or importing the Program or any portion of it.
11. Patents.
A “contributor” is a copyright holder who authorizes use under this License of the Program or a work on which the Program is based. The work thus licensed is called the contributor's “contributor version”.
A contributor's “essential patent claims” are all patent claims owned or controlled by the contributor, whether already acquired or hereafter acquired, that would be infringed by some manner, permitted by this License, of making, using, or selling its contributor version, but do not include claims that would be infringed only as a consequence of further modification of the contributor version. For purposes of this definition, “control” includes the right to grant patent sublicenses in a manner consistent with the requirements of this License.
Each contributor grants you a non-exclusive, worldwide, royalty-free patent license under the contributor's essential patent claims, to make, use, sell, offer for sale, import and otherwise run, modify and propagate the contents of its contributor version.
In the following three paragraphs, a “patent license” is any express agreement or commitment, however denominated, not to enforce a patent (such as an express permission to practice a patent or covenant not to sue for patent infringement). To “grant” such a patent license to a party means to make such an agreement or commitment not to enforce a patent against the party.
If you convey a covered work, knowingly relying on a patent license, and the Corresponding Source of the work is not available for anyone to copy, free of charge and under the terms of this License, through a publicly available network server or other readily accessible means, then you must either (1) cause the Corresponding Source to be so available, or (2) arrange to deprive yourself of the benefit of the patent license for this particular work, or (3) arrange, in a manner consistent with the requirements of this License, to extend the patent license to downstream recipients. “Knowingly relying” means you have actual knowledge that, but for the patent license, your conveying the covered work in a country, or your recipient's use of the covered work in a country, would infringe one or more identifiable patents in that country that you have reason to believe are valid.
If, pursuant to or in connection with a single transaction or arrangement, you convey, or propagate by procuring conveyance of, a covered work, and grant a patent license to some of the parties receiving the covered work authorizing them to use, propagate, modify or convey a specific copy of the covered work, then the patent license you grant is automatically extended to all recipients of the covered work and works based on it.
A patent license is “discriminatory” if it does not include within the scope of its coverage, prohibits the exercise of, or is conditioned on the non-exercise of one or more of the rights that are specifically granted under this License. You may not convey a covered work if you are a party to an arrangement with a third party that is in the business of distributing software, under which you make payment to the third party based on the extent of your activity of conveying the work, and under which the third party grants, to any of the parties who would receive the covered work from you, a discriminatory patent license (a) in connection with copies of the covered work conveyed by you (or copies made from those copies), or (b) primarily for and in connection with specific products or compilations that contain the covered work, unless you entered into that arrangement, or that patent license was granted, prior to 28 March 2007.
Nothing in this License shall be construed as excluding or limiting any implied license or other defenses to infringement that may otherwise be available to you under applicable patent law.
12. No Surrender of Others' Freedom.
If conditions are imposed on you (whether by court order, agreement or otherwise) that contradict the conditions of this License, they do not excuse you from the conditions of this License. If you cannot convey a covered work so as to satisfy simultaneously your obligations under this License and any other pertinent obligations, then as a consequence you may not convey it at all. For example, if you agree to terms that obligate you to collect a royalty for further conveying from those to whom you convey the Program, the only way you could satisfy both those terms and this License would be to refrain entirely from conveying the Program.
13. Use with the GNU Affero General Public License.
Notwithstanding any other provision of this License, you have permission to link or combine any covered work with a work licensed under version 3 of the GNU Affero General Public License into a single combined work, and to convey the resulting work. The terms of this License will continue to apply to the part which is the covered work, but the special requirements of the GNU Affero General Public License, section 13, concerning interaction through a network will apply to the combination as such.
14. Revised Versions of this License.
The Free Software Foundation may publish revised and/or new versions of the GNU General Public License from time to time. Such new versions will be similar in spirit to the present version, but may differ in detail to address new problems or concerns.
Each version is given a distinguishing version number. If the Program specifies that a certain numbered version of the GNU General Public License “or any later version” applies to it, you have the option of following the terms and conditions either of that numbered version or of any later version published by the Free Software Foundation. If the Program does not specify a version number of the GNU General Public License, you may choose any version ever published by the Free Software Foundation.
If the Program specifies that a proxy can decide which future versions of the GNU General Public License can be used, that proxy's public statement of acceptance of a version permanently authorizes you to choose that version for the Program.
Later license versions may give you additional or different permissions. However, no additional obligations are imposed on any author or copyright holder as a result of your choosing to follow a later version.
15. Disclaimer of Warranty.
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
16. Limitation of Liability.
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
17. Interpretation of Sections 15 and 16.
If the disclaimer of warranty and limitation of liability provided above cannot be given local legal effect according to their terms, reviewing courts shall apply local law that most closely approximates an absolute waiver of all civil liability in connection with the Program, unless a warranty or assumption of liability accompanies a copy of the Program in return for a fee.
END OF TERMS AND CONDITIONS
How to Apply These Terms to Your New Programs
If you develop a new program, and you want it to be of the greatest possible use to the public, the best way to achieve this is to make it free software which everyone can redistribute and change under these terms.
To do so, attach the following notices to the program. It is safest to attach them to the start of each source file to most effectively state the exclusion of warranty; and each file should have at least the “copyright” line and a pointer to where the full notice is found.
nix-overlay
Copyright (C) 2026 alex
This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
You should have received a copy of the GNU General Public License along with this program. If not, see <https://www.gnu.org/licenses/>.
Also add information on how to contact you by electronic and paper mail.
If the program does terminal interaction, make it output a short notice like this when it starts in an interactive mode:
nix-overlay Copyright (C) 2026 alex
This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
This is free software, and you are welcome to redistribute it under certain conditions; type `show c' for details.
The hypothetical commands `show w' and `show c' should show the appropriate parts of the General Public License. Of course, your program's commands might be different; for a GUI interface, you would use an “about box”.
You should also get your employer (if you work as a programmer) or school, if any, to sign a “copyright disclaimer” for the program, if necessary. For more information on this, and how to apply and follow the GNU GPL, see <https://www.gnu.org/licenses/>.
The GNU General Public License does not permit incorporating your program into proprietary programs. If your program is a subroutine library, you may consider it more useful to permit linking proprietary applications with the library. If this is what you want to do, use the GNU Lesser General Public License instead of this License. But first, please read <https://www.gnu.org/philosophy/why-not-lgpl.html>.
+193
View File
@@ -0,0 +1,193 @@
# millerson.name Nix Overlay
A custom Nix overlay and flake providing additional packages not found in upstream nixpkgs, built using [numtide/blueprint](https://github.com/numtide/blueprint) for streamlined flake development.
## Features
- **Custom packages** - Additional software packaged for Nix
- **Two overlay strategies** - Choose between binary-cache-friendly or dependency-sharing overlays
- **Blueprint-based** - Uses modern Nix flake patterns with `numtide/blueprint`
## Available Packages
| Package | Description | Category |
|---------|-------------|----------|
| `awg-tool` | CLI for AmneziaWG self-hosting — generates 1.0/1.5/2.0/3.0 obfuscation parameters, exports .conf and vpn:// configs, installs servers over SSH | Networking |
| `aionui` | Free, open-source, Cowork app with AI Agents | AI Coding Agents |
| `container-use` | Containerized environments for coding agents | AI Coding Agents |
| `desloppify` | Multi-language codebase health scanner and technical debt tracker for AI agents | AI Coding Agents |
| `ds4` | DeepSeek 4 Flash and PRO local inference engine for ROCm (Strix Halo) | AI Inference |
| `freebuff` | The world's strongest free coding agent | AI Coding Agents |
| `freetoken` | Local MoE-offload LLM inference runtime with OpenAI- and Anthropic-compatible APIs | AI Inference |
| `graphify` | Turn any folder of code, docs, papers, images, or videos into a queryable knowledge graph | AI Coding Agents |
| `haivemind` | Multi-model AI consensus, aggregation, and fusion runner for popular AI CLIs | AI Coding Agents |
| `hipengine` | ROCm-native local LLM inference engine with torch-free runtime for AMD RDNA GPUs | AI Inference |
| `marmel` | Autonomous agentic coding assistant with Manager + specialist subagent orchestration over any OpenAI-compatible LLM backend | AI Coding Agents |
| `mcp-gateway` | Universal Model Context Protocol gateway that sits between AI client and MCP tools/servers | MCP Servers |
| `nftables-analyzer` | Analyze nftables firewall rules and evaluate traffic queries | Networking |
| `nftablesbuilder` | Web interface to manage nftables rules with drag-and-drop rule creation | Networking |
| `skillsmcp` | MCP server that exposes Agent Skills to AI agents via the Model Context Protocol | MCP Servers |
| `kubernetes-mcp-server` | Model Context Protocol (MCP) server for Kubernetes and OpenShift | MCP Servers |
| `llama-cpp` | llama.cpp pinned to build b9645, built for Strix Halo (gfx1151) with ROCm + Vulkan backends | AI Inference |
| `loop` | Corporate messenger for your team | Communication |
| `radar` | Modern Kubernetes visibility — topology, event timeline, service traffic, resource browsing, Helm management, and GitOps support | Kubernetes |
| `omniroute` | Unified AI router with 160+ providers, auto fallback, MCP/A2A, OpenAI-compatible APIs | AI LLM Gateway |
| `relay-free-llm` | RESTful API to route user prompts to various AI model providers with automatic failover and intent-based routing | AI LLM Gateway |
| `stakpak` | DevOps AI agent that generates infrastructure code, debugs Kubernetes, configures CI/CD, and automates deployments | AI Agents |
| `traycer` | Open-source AI orchestration app for agentic coding | AI Coding Agents |
## Usage
### As a Flake
Add to your `flake.nix` inputs:
```nix
inputs.millerson-nix-overlay.url = "git+https://git.millerson.name/alex/millerson-overlay.nix.git";
```
Then use in your outputs:
```nix
outputs = { nixpkgs, millerson-nix-overlay, ... }: {
nixosConfigurations.your-host = nixpkgs.lib.nixosSystem {
system = "x86_64-linux";
modules = [
millerson-nix-overlay.nixosModules.default
# ... your other modules
];
};
};
```
### As an Overlay
#### Option 1: Default Overlay (Binary Cache Friendly)
Uses the packages built against this flake's nixpkgs revision. Binary cache hits work best when using the same nixpkgs revision.
```nix
nixpkgs.overlays = [ millerson-nix-overlay.overlays.default ];
```
#### Option 2: Shared Nixpkgs Overlay (Dependency Sharing)
Builds packages against your system's nixpkgs, sharing dependencies with the rest of your system. No second nixpkgs evaluation, but binary cache only hits when your nixpkgs revision matches ours.
```nix
nixpkgs.overlays = [ millerson-nix-overlay.overlays.shared-nixpkgs ];
```
### Installing Packages
With flakes enabled:
```bash
# Try a package
nix run git+https://git.millerson.name/alex/millerson-overlay.nix.git#mcp-gateway
# Install permanently
nix profile install git+https://git.millerson.name/alex/millerson-overlay.nix.git#mcp-gateway
```
### nftablesbuilder Runtime Notes
`nftablesbuilder` is a web interface for managing nftables. It consists of a
root-launcher (`nftablesbuilder`) that spawns the unprivileged `webserver`
binary and pipes encrypted commands between it and the `nft` binary.
Before running it you must:
1. Copy the settings template to `/etc/nftablesbuilder` (the only fixed path):
```bash
nix build .#nftablesbuilder
cp result/share/nftablesbuilder/settings.example /etc/nftablesbuilder
```
Adjust paths inside (html, webserver, nft, savepath, TLS files).
2. Create a TLS key/certificate pair at the paths referenced by
`tlskey`/`tlscert` (e.g. `openssl req -x509 -newkey rsa:2048 -nodes ...`).
3. Run the launcher as root (it needs to write `/etc/nftables.conf` and run
`nft`); the web interface listens on `https://<server>:1969`.
Note: upstream publishes the GUI only as a prebuilt tarball on
nftablesbuilder.eu (served with a self-signed certificate, hence the
`curlOpts = "-k"` in the derivation); the source repository is missing the
`settings` crate, which this overlay patches in.
## Development
### Prerequisites
- Nix with flakes enabled
- [treefmt-nix](https://github.com/numtide/treefmt-nix) for formatting (optional)
### Building Packages
```bash
# Build all packages for current system
nix build .#packages
# Build specific package
nix build .#mcp-gateway
# Enter development shell
nix develop
```
### Project Structure
```
nix-overlay/
├── flake.nix # Flake definition
├── treefmt.toml # Code formatting configuration (nixfmt)
├── overlays/ # Overlay implementations
│ ├── default.nix # Binary-cache-friendly overlay
│ └── shared-nixpkgs.nix # Dependency-sharing overlay
├── packages/ # Package definitions
│ ├── awg-tool/ # AmneziaWG parameter generation and SSH deployment CLI
│ ├── aionui/ # AionUi - AI Cowork desktop app
│ ├── container-use/ # Containerized environments for coding agents
│ ├── default/ # Meta-package listing all packages
│ ├── desloppify/ # Codebase health scanner for AI agents
│ ├── ds4/ # DeepSeek V4 Flash/PRO inference engine (ROCm)
│ ├── flake-inputs/ # Utility for caching flake inputs
│ ├── freebuff/ # Free coding agent (Codebuff)
│ ├── freetoken/ # Local MoE inference runtime (NVIDIA CUDA)
│ ├── graphify/ # Knowledge graph generator for code folders
│ ├── haivemind/ # Multi-model AI consensus runner
│ ├── hipengine/ # ROCm-native LLM inference engine for AMD GPUs
│ ├── kubernetes-mcp-server/ # MCP server for Kubernetes and OpenShift
│ ├── loop/ # Corporate messenger for your team
│ ├── mcp-gateway/ # MCP protocol gateway
│ ├── omniroute/ # Unified AI router with 160+ providers
│ ├── radar/ # Kubernetes UI (topology, timeline, Helm, GitOps)
│ ├── relay-free-llm/ # AI model provider routing gateway
│ ├── skillsmcp/ # MCP server for Agent Skills
│ ├── stakpak/ # DevOps AI agent for infrastructure automation
│ └── traycer/ # AI orchestration desktop app (agentic coding)
└── README.md
```
### Adding New Packages
1. Create a new directory under `packages/<package-name>/`
2. Add a `package.nix` with the package definition
3. Create a `default.nix` that imports `package.nix` with proper arguments
4. The package will be automatically picked up by blueprint
Example structure:
```
packages/my-package/
├── default.nix # Import wrapper
└── package.nix # Actual package definition
```
## License
See [LICENSE](LICENSE) file for details.
## Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
Generated
+174
View File
@@ -0,0 +1,174 @@
{
"nodes": {
"blueprint": {
"inputs": {
"nixpkgs": [
"nixpkgs"
],
"systems": [
"systems"
]
},
"locked": {
"lastModified": 1776249299,
"narHash": "sha256-Dt9t1TGRmJFc0xVYhttNBD6QsAgHOHCArqGa0AyjrJY=",
"owner": "numtide",
"repo": "blueprint",
"rev": "56131e8628f173d24a27f6d27c0215eff57e40dd",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "blueprint",
"type": "github"
}
},
"bun2nix": {
"inputs": {
"flake-parts": [
"flake-parts"
],
"nixpkgs": [
"nixpkgs"
],
"systems": [
"systems"
],
"treefmt-nix": [
"treefmt-nix"
]
},
"locked": {
"lastModified": 1777369708,
"narHash": "sha256-1xW7cRZNsFNPQD+cE0fwnLVStnDth0HSoASEIFeT7uI=",
"owner": "nix-community",
"repo": "bun2nix",
"rev": "e659e1cc4b8e1b21d0aa85f1c481f9db61ecfa98",
"type": "github"
},
"original": {
"owner": "nix-community",
"ref": "staging-2.1.0",
"repo": "bun2nix",
"type": "github"
}
},
"flake-parts": {
"inputs": {
"nixpkgs-lib": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1777988971,
"narHash": "sha256-qIoWPDs+0/8JecyYgE3gpKQxW/4bLW/gp45vow9ioCQ=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "0678d8986be1661af6bb555f3489f2fdfc31f6ff",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "flake-parts",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1789149629,
"narHash": "sha256-H6GwaZzZf+4npqv0tph94w9tZddSjFjmQrVsW0z78uk=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "eaad089433ca2bb662274377d33df3d0e51ef28b",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs-latest": {
"locked": {
"lastModified": 1789149629,
"narHash": "sha256-H6GwaZzZf+4npqv0tph94w9tZddSjFjmQrVsW0z78uk=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "eaad089433ca2bb662274377d33df3d0e51ef28b",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs-torch211": {
"locked": {
"lastModified": 1777954456,
"narHash": "sha256-hGdgeU2Nk87RAuZyYjyDjFL6LK7dAZN5RE9+hrDTkDU=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1",
"type": "github"
}
},
"root": {
"inputs": {
"blueprint": "blueprint",
"bun2nix": "bun2nix",
"flake-parts": "flake-parts",
"nixpkgs": "nixpkgs",
"nixpkgs-latest": "nixpkgs-latest",
"nixpkgs-torch211": "nixpkgs-torch211",
"systems": "systems",
"treefmt-nix": "treefmt-nix"
}
},
"systems": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"treefmt-nix": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1775636079,
"narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "treefmt-nix",
"type": "github"
}
}
},
"root": "root",
"version": 7
}
+61
View File
@@ -0,0 +1,61 @@
{
description = "Various packages for Nix";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
# Newer nixpkgs whose toolchains are required by some packages:
# rustc >= 1.95 (mcp-gateway >= 3.4.0), go >= 1.26.3 (kubernetes-mcp-server >= 0.0.66).
nixpkgs-latest.url = "github:NixOS/nixpkgs/nixos-unstable";
# freetoken pins torch>=2.11,<2.12 and triton==3.6.0; current
# nixos-unstable only ships torch 2.13 / triton 3.7. Keep the previous
# nixpkgs revision for freetoken so its CUDA 12.9 / torch 2.11 stack is
# unchanged.
nixpkgs-torch211.url = "github:NixOS/nixpkgs/549bd84d6279f9852cae6225e372cc67fb91a4c1";
systems.url = "github:nix-systems/default";
blueprint = {
url = "github:numtide/blueprint";
inputs.nixpkgs.follows = "nixpkgs";
inputs.systems.follows = "systems";
};
treefmt-nix = {
url = "github:numtide/treefmt-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
flake-parts = {
url = "github:hercules-ci/flake-parts";
inputs.nixpkgs-lib.follows = "nixpkgs";
};
bun2nix = {
# TODO(#4001): drop the branch pin once catalog support
# (nix-community/bun2nix#86) reaches the default branch.
url = "github:nix-community/bun2nix/staging-2.1.0";
inputs.nixpkgs.follows = "nixpkgs";
inputs.systems.follows = "systems";
inputs.treefmt-nix.follows = "treefmt-nix";
inputs.flake-parts.follows = "flake-parts";
};
};
outputs =
{ self, ... }@inputs:
let
blueprintOutputs = inputs.blueprint {
inherit inputs;
};
in
blueprintOutputs
// {
overlays = {
default = import ./overlays {
inherit (blueprintOutputs) packages;
};
shared-nixpkgs = import ./overlays/shared-nixpkgs.nix {
inherit (blueprintOutputs) mkPackagesFor;
};
};
nixosModules.default = {
nixpkgs.overlays = [ self.overlays.default ];
};
};
}
+10
View File
@@ -0,0 +1,10 @@
{
packages,
}:
final: _prev: {
millerson-nix-overlay =
packages.${final.stdenv.hostPlatform.system}
or (final.lib.warn "millerson-overlay: no packages for system ${final.stdenv.hostPlatform.system}"
{ }
);
}
+10
View File
@@ -0,0 +1,10 @@
{
mkPackagesFor,
}:
# Builds the packages/ tree against the consumer's `final`, so deps are
# shared with the rest of their system and no second nixpkgs is
# evaluated. Trade-off vs overlays.default: the binary cache only hits
# when the consumer's nixpkgs revision matches ours.
final: _prev: {
millerson-nix-overlay = mkPackagesFor final;
}
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+230
View File
@@ -0,0 +1,230 @@
{
lib,
stdenv,
fetchFromGitHub,
bun,
nodejs,
node-gyp,
electron,
autoPatchelfHook,
makeWrapper,
copyDesktopItems,
imagemagick,
python3,
cacert,
}:
let
version = "2.2.2";
src = fetchFromGitHub {
owner = "iOfficeAI";
repo = "AionUi";
rev = "v${version}";
hash = "sha256-HyDzlUOg0OAGNhNveG/5Ba2UbgoR4VTQsbUGUzGmKd4=";
};
# FOD 1: All dependencies (dev + prod) for the build phase.
bunBuildDeps = stdenv.mkDerivation {
name = "aionui-build-deps-${version}";
inherit src;
nativeBuildInputs = [
bun
cacert
];
outputHashAlgo = "sha256";
outputHashMode = "recursive";
outputHash = "sha256-+vLK5f1rhcXAhHz0v1LkMbcBjBLFCHVTWbdamZIjOwY=";
dontPatchShebangs = true;
dontFixup = true;
SSL_CERT_FILE = "${cacert}/etc/ssl/certs/ca-bundle.crt";
buildPhase = ''
export HOME=$TMPDIR
bun install --frozen-lockfile --ignore-scripts
'';
installPhase = ''
mkdir -p $out
cp -r node_modules $out/
cp -r packages $out/
cp tsconfig.json $out/
'';
};
# FOD 2: Production-only dependencies for the runtime output.
# Mirrors the Dockerfile's `bun install --production --ignore-scripts`.
bunProdDeps = stdenv.mkDerivation {
name = "aionui-prod-deps-${version}";
inherit src;
nativeBuildInputs = [
bun
cacert
];
outputHashAlgo = "sha256";
outputHashMode = "recursive";
outputHash = "sha256-CzVH9zQsssdkCX/BpUxQw1wnJQKzLYWWXZt3sn7eBFI=";
dontPatchShebangs = true;
dontFixup = true;
SSL_CERT_FILE = "${cacert}/etc/ssl/certs/ca-bundle.crt";
buildPhase = ''
export HOME=$TMPDIR
bun install --frozen-lockfile --production --ignore-scripts
'';
installPhase = ''
mkdir -p $out
cp -r node_modules $out/
'';
};
in
stdenv.mkDerivation rec {
pname = "aionui";
inherit version src;
nativeBuildInputs = [
bun
nodejs
node-gyp
autoPatchelfHook
makeWrapper
copyDesktopItems
imagemagick
python3
];
buildInputs = [
stdenv.cc.cc.lib
];
buildPhase = ''
runHook preBuild
export HOME=$TMPDIR
# Use the full dependency set for the build
ln -sf ${bunBuildDeps}/node_modules .
# ── Build better-sqlite3 native addon ──────────────────────
echo "Building better-sqlite3 from source..."
BT3_SRC=$TMPDIR/bts3-src
BT3_OUT=$TMPDIR/bts3-out
mkdir -p "$BT3_SRC" "$BT3_OUT"
cp -rL node_modules/better-sqlite3/* "$BT3_SRC/"
chmod -R u+w "$BT3_SRC"
(
cd "$BT3_SRC"
export npm_config_nodedir=${nodejs}
node-gyp rebuild
mkdir -p "$BT3_OUT/build/Release"
cp build/Release/better_sqlite3.node "$BT3_OUT/build/Release/" 2>/dev/null || true
)
# ── electron-vite build ───────────────────────────────────
echo "Running electron-vite build..."
${nodejs}/bin/node node_modules/.bin/electron-vite build \
--config packages/desktop/electron.vite.config.ts
# ── Bundle MCP servers ────────────────────────────────────
echo "Building MCP servers..."
${nodejs}/bin/node scripts/build-mcp-servers.js
runHook postBuild
'';
installPhase = ''
runHook preInstall
mkdir -p $out/{bin,lib/aionui}
# ── Built output ──────────────────────────────────────────
cp -r out $out/lib/aionui/
cp -r public $out/lib/aionui/
cp package.json $out/lib/aionui/
# ── Production-only node_modules (mirrors Dockerfile) ─────
cp -a ${bunProdDeps}/node_modules $out/lib/aionui/node_modules
chmod -R u+w $out/lib/aionui/node_modules
# Remove workspace symlink – @aionui/web-host is bundled by
# electron-vite (excluded from externalizeDepsPlugin), so the
# symlink to packages/web-host is not needed at runtime.
rm -f $out/lib/aionui/node_modules/@aionui/web-host
# @sentry/electron requires @sentry/node at runtime, but bun
# nests it inside .bun/ rather than hoisting to top-level.
# Electron's require() walks up from the resolved realpath
# and needs it accessible either at top-level or via the
# symlink target's node_modules. We ensure top-level access.
if [ ! -e $out/lib/aionui/node_modules/@sentry/node ]; then
SRC=$(echo $out/lib/aionui/node_modules/.bun/@sentry+node@*/node_modules/@sentry/node)
if [ -d "$SRC" ]; then
ln -sf "$(realpath --relative-to=$out/lib/aionui/node_modules/@sentry "$SRC")" \
$out/lib/aionui/node_modules/@sentry/node
fi
fi
# Inject compiled better-sqlite3 .node into the runtime tree
if [ -f "$TMPDIR/bts3-out/build/Release/better_sqlite3.node" ]; then
rm -rf $out/lib/aionui/node_modules/better-sqlite3
cp -rL ${bunProdDeps}/node_modules/better-sqlite3 $out/lib/aionui/node_modules/better-sqlite3 2>/dev/null || true
chmod -R u+w $out/lib/aionui/node_modules/better-sqlite3
mkdir -p $out/lib/aionui/node_modules/better-sqlite3/build/Release
cp "$TMPDIR/bts3-out/build/Release/better_sqlite3.node" \
$out/lib/aionui/node_modules/better-sqlite3/build/Release/
fi
# ── Desktop entry ─────────────────────────────────────────
mkdir -p $out/share/applications
cat > $out/share/applications/aionui.desktop << EOF
[Desktop Entry]
Name=AionUi
Comment=Free, open-source Cowork app with AI Agents
Exec=$out/bin/aionui
Icon=aionui
Terminal=false
Type=Application
Categories=Office;Utility;
EOF
mkdir -p $out/share/icons/hicolor/256x256/apps
if [ -f resources/app.png ]; then
convert resources/app.png -resize 256x256 \
$out/share/icons/hicolor/256x256/apps/aionui.png
fi
# ── Launcher ──────────────────────────────────────────────
makeWrapper ${electron}/bin/electron $out/bin/aionui \
--add-flags "$out/lib/aionui"
runHook postInstall
'';
dontStrip = true;
autoPatchelfIgnoreMissingDeps = true;
desktopItems = [ "aionui.desktop" ];
doCheck = false;
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#aionui"
];
};
meta = with lib; {
description = "Free, open-source, Cowork app with AI Agents";
homepage = "https://github.com/iOfficeAI/AionUi";
changelog = "https://github.com/iOfficeAI/AionUi/releases/tag/v${version}";
license = licenses.asl20;
sourceProvenance = with sourceTypes; [ fromSource ];
mainProgram = "aionui";
platforms = platforms.linux;
};
}
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+51
View File
@@ -0,0 +1,51 @@
{
lib,
rustPlatform,
fetchFromGitHub,
cmake,
perl,
}:
rustPlatform.buildRustPackage rec {
pname = "awg-tool";
version = "0.3.0";
src = fetchFromGitHub {
owner = "Vadim-Khristenko";
repo = "awg-containers-and-tools";
rev = "v${version}";
hash = "sha256-IRi2LPTDLT6qfuolCUHSJWaXTg5pt/kqVlosxqCMQDs=";
};
# awg-core builds ssh2 with vendored-openssl, which compiles libssh2
# (via cmake) and OpenSSL (via perl Configure) from source.
nativeBuildInputs = [
cmake
perl
];
cargoHash = "sha256-7sDpdjvA3kAHtwQ2qmpRPQywmyQBXZzM2ClfLKbGoKc=";
# Upstream tests exercise Docker/SSH targets; unit tests are already
# covered by the upstream CI before a release is cut.
doCheck = false;
passthru = {
category = "Networking";
updateScript = [
"nix-update"
"--flake"
".#awg-tool"
];
};
meta = with lib; {
description = "CLI for AmneziaWG self-hosting — generates 1.0/1.5/2.0/3.0 obfuscation parameters, exports .conf and vpn:// configs, installs servers over SSH";
homepage = "https://github.com/Vadim-Khristenko/awg-containers-and-tools";
changelog = "https://github.com/Vadim-Khristenko/awg-containers-and-tools/releases/tag/v${version}";
license = licenses.mit;
sourceProvenance = with sourceTypes; [ fromSource ];
mainProgram = "awg-tool";
platforms = platforms.linux;
};
}
+1
View File
@@ -0,0 +1 @@
{ pkgs, ... }: pkgs.callPackage ./package.nix { }
+53
View File
@@ -0,0 +1,53 @@
{
lib,
buildGoModule,
fetchFromGitHub,
}:
buildGoModule rec {
pname = "container-use";
version = "0.4.2";
src = fetchFromGitHub {
owner = "dagger";
repo = "container-use";
rev = "v${version}";
hash = "sha256-YKgS142a9SL1ZEjS+VArxwUzQX961zwlGuHW43AMxQA=";
};
vendorHash = "sha256-M7YhEm9Gmjv2gxB2r7AS5JLLThEkvtJfLBrB+cvsN5c=";
env.CGO_ENABLED = 0;
subPackages = [ "cmd/container-use" ];
# Tests require network access to container registries and a running
# Docker engine, neither of which are available in the Nix sandbox
doCheck = false;
postInstall = ''
ln -s $out/bin/container-use $out/bin/cu
'';
ldflags = [
"-s -w -X main.version=v${version}"
];
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#container-use"
];
};
meta = {
description = "Containerized environments for coding agents";
homepage = "https://github.com/dagger/container-use";
changelog = "https://github.com/dagger/container-use/releases/tag/v${version}";
license = lib.licenses.asl20;
mainProgram = "container-use";
platforms = lib.platforms.linux ++ lib.platforms.darwin;
};
}
+21
View File
@@ -0,0 +1,21 @@
{
pkgs,
perSystem,
...
}:
let
allPackages = perSystem.self;
# Filter to visible, runnable packages
visibleNames = builtins.filter (
name: name != "default" && !(allPackages.${name}.passthru.hideFromDocs or false)
) (builtins.attrNames allPackages);
# Build "name\tdescription" lines
packageLines = map (name: "${name}\t${allPackages.${name}.meta.description or ""}") visibleNames;
packageList = builtins.concatStringsSep "\n" packageLines;
flakeUrl = "git+https://git.millerson.name/alex/millerson-overlay.nix.git";
in
pkgs.callPackage ./package.nix { inherit packageList flakeUrl; }
+61
View File
@@ -0,0 +1,61 @@
{
lib,
writeShellApplication,
fzf,
nix,
util-linux,
packageList,
flakeUrl,
}:
let
packageListFile = builtins.toFile "millerson-overlay-packages.tsv" packageList;
in
writeShellApplication {
name = "millerson-overlay-launcher";
runtimeInputs = [
fzf
nix
util-linux # column
];
text = ''
# Format for fzf: "name description" (tab-aligned)
entries=$(column -t -s $'\t' < "${packageListFile}")
if [[ -z $entries ]]; then
echo "No packages found" >&2
exit 1
fi
# Let user pick with fzf
selected=$(echo "$entries" | fzf \
--header="Select an pkg to run (ESC to cancel)" \
--preview-window=hidden \
--no-multi \
--height=~40% \
--layout=reverse) || exit 0
# Extract package name (first word)
pkg_name=$(echo "$selected" | awk '{print $1}')
if [[ -z $pkg_name ]]; then
exit 0
fi
echo "→ Running: nix run ${flakeUrl}#$pkg_name"
exec nix run "${flakeUrl}#$pkg_name"
'';
meta = {
description = "Interactive fzf launcher for millerson-overlay.nix packages";
license = lib.licenses.mit;
mainProgram = "millerson-overlay-launcher";
platforms = lib.platforms.all;
};
passthru = {
hideFromDocs = true;
};
}
+1
View File
@@ -0,0 +1 @@
{ pkgs, ... }: pkgs.callPackage ./package.nix { }
+54
View File
@@ -0,0 +1,54 @@
{
lib,
python3Packages,
fetchFromGitHub,
}:
python3Packages.buildPythonApplication rec {
pname = "desloppify";
version = "1.0";
pyproject = true;
src = fetchFromGitHub {
owner = "peteromallet";
repo = "desloppify";
rev = "v${version}";
hash = "sha256-USFofGy0SUZV0oeh5x5KAWeFReD45GxlyYqpmc23NFM=";
};
build-system = with python3Packages; [
setuptools
];
# Include all [full] optional dependencies for complete functionality.
# Upstream has no base dependencies - all features are behind optional extras.
dependencies = with python3Packages; [
tree-sitter
tree-sitter-language-pack
defusedxml
bandit
pillow
pyyaml
];
doCheck = false;
pythonImportsCheck = [ "desloppify" ];
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#desloppify"
];
};
meta = {
description = "Multi-language codebase health scanner and technical debt tracker for AI agents";
homepage = "https://github.com/peteromallet/desloppify";
changelog = "https://github.com/peteromallet/desloppify/releases/tag/v${version}";
license = lib.licenses.unfreeRedistributable;
mainProgram = "desloppify";
platforms = lib.platforms.all;
};
}
+1
View File
@@ -0,0 +1 @@
{ pkgs, ... }: pkgs.callPackage ./package.nix { }
+102
View File
@@ -0,0 +1,102 @@
{
lib,
stdenv,
fetchFromGitHub,
gnumake,
rocmPackages,
autoPatchelfHook,
}:
stdenv.mkDerivation {
pname = "ds4";
version = "0-unstable-2026-09-12";
src = fetchFromGitHub {
owner = "antirez";
repo = "ds4";
rev = "bd66c402070042bf0a79ad6ece8242de4c93680c";
hash = "sha256-F/MKv3/0Oj8DLa+q6jMtv0wFDgUvii+Xo2f1dPBDg6A=";
};
nativeBuildInputs = [
gnumake
rocmPackages.hipcc
autoPatchelfHook
];
buildInputs = [
rocmPackages.clr
rocmPackages.hipblas
rocmPackages.hipblas-common
rocmPackages.hipblaslt
rocmPackages.hipcub
rocmPackages.rocblas
rocmPackages.rocprim
rocmPackages.rocwmma
];
# STRIXHALO.md: rocwmma/internal/ headers may be missing in distro packages.
# nixpkgs builds rocwmma from source so all headers (including internal/) are present.
# ROCM_ARCH defaults to gfx1151 (Strix Halo / Radeon 8060S) in the upstream Makefile.
buildPhase = ''
runHook preBuild
make strix-halo -j"$NIX_BUILD_CORES" \
HIPCC="${rocmPackages.hipcc}/bin/hipcc" \
ROCM_CFLAGS="-O3 -ffast-math -g -fno-finite-math-only -pthread -D__HIP_PLATFORM_AMD__ -Wno-unused-command-line-argument --offload-arch=gfx1151 \
-I${rocmPackages.clr}/include \
-I${rocmPackages.hipblas}/include \
-I${rocmPackages.hipblas-common}/include \
-I${rocmPackages.hipblaslt}/include \
-I${rocmPackages.hipcub}/include \
-I${rocmPackages.rocblas}/include \
-I${rocmPackages.rocprim}/include \
-I${rocmPackages.rocwmma}/include" \
ROCM_LDLIBS="-lm -pthread \
-L${rocmPackages.hipblas}/lib -lhipblas \
-L${rocmPackages.hipblaslt}/lib -lhipblaslt \
-L${rocmPackages.rocblas}/lib -lrocblas \
-L${rocmPackages.clr}/lib -lamdhip64"
runHook postBuild
'';
installPhase = ''
runHook preInstall
mkdir -p $out/bin
cp ds4 ds4-server ds4-bench ds4-eval ds4-agent $out/bin/
runHook postInstall
'';
passthru = {
category = "AI Inference";
updateScript = [
"nix-update"
"--flake"
"--version=branch=main"
".#ds4"
];
};
meta = {
description = "DeepSeek 4 Flash and PRO local inference engine for ROCm (Strix Halo)";
longDescription = ''
DS4 is a self-contained local inference engine specifically built for
DeepSeek V4 Flash and PRO. It bundles a CLI, HTTP server, and native
coding agent. This package is built with the ROCm backend for AMD
Strix Halo GPUs (gfx1151, Radeon 8060S).
Runtime requirements (from STRIXHALO.md):
- User must be in 'render' and 'video' groups for /dev/kfd and DRM access
- GPU-visible memory must be increased via kernel parameters:
amd_iommu=off amdgpu.gttsize=126976 ttm.pages_limit=32505856 ttm.page_pool_size=32505856
'';
homepage = "https://github.com/antirez/ds4";
changelog = "https://github.com/antirez/ds4/commits/main";
license = lib.licenses.mit;
platforms = [ "x86_64-linux" ];
mainProgram = "ds4";
};
}
+15
View File
@@ -0,0 +1,15 @@
{
inputs,
pkgs,
...
}:
# A derivation that references all flake inputs to ensure they get cached
let
inputsList = pkgs.lib.concatMapStringsSep " " (name: inputs.${name}) (builtins.attrNames inputs);
in
pkgs.runCommand "flake-inputs" { } ''
cat ${builtins.toFile "flake-inputs-list" inputsList} > $out
''
// {
passthru.hideFromDocs = true;
}
+1
View File
@@ -0,0 +1 @@
{ pkgs, ... }: pkgs.callPackage ./package.nix { glibc = pkgs.stdenv.cc.libc; }
+153
View File
@@ -0,0 +1,153 @@
{
lib,
stdenv,
fetchurl,
nodejs,
makeWrapper,
patchelf,
glibc,
}:
let
version = "0.0.174";
freebuffSrc = fetchurl {
url = "https://registry.npmjs.org/freebuff/-/freebuff-${version}.tgz";
hash = "sha256-o767MqjDbhiu+Zy3Jc/43kBNIgLVLEgqC7D3GwtU0hg=";
};
pkgTar = fetchurl {
url = "https://registry.npmjs.org/tar/-/tar-7.5.15.tgz";
hash = "sha256-hl60jJtM1W2THQyGZj8G72GEG8QvVrHvNnr7EU1liBw=";
};
pkgFsMinipass = fetchurl {
url = "https://registry.npmjs.org/@isaacs/fs-minipass/-/fs-minipass-4.0.1.tgz";
hash = "sha256-esKG48zMHqiYDnniA53va7l9MYLheVHNkJTwQA7ZgjY=";
};
pkgChownr = fetchurl {
url = "https://registry.npmjs.org/chownr/-/chownr-3.0.0.tgz";
hash = "sha256-TCT12qYwFCJS2oneZV998JDqR5RQqIJYl3UdeDIbE2A=";
};
pkgMinipass = fetchurl {
url = "https://registry.npmjs.org/minipass/-/minipass-7.1.3.tgz";
hash = "sha256-UqxhvnQ3VeP9yY5WAIbQ1KHix/02Qzh3kts44yLSfRI=";
};
pkgMinizlib = fetchurl {
url = "https://registry.npmjs.org/minizlib/-/minizlib-3.1.0.tgz";
hash = "sha256-mb8uKWGBct1x8GVHN0kMaPcbx+I3nUc+OPn+8tvs4uM=";
};
pkgYallist = fetchurl {
url = "https://registry.npmjs.org/yallist/-/yallist-5.0.0.tgz";
hash = "sha256-fJ1D26t8qzsxM7Dmpa8UAUSCKFMWs57J9QjvrdnrzpU=";
};
binarySrc = fetchurl {
url = "https://github.com/CodebuffAI/codebuff-community/releases/download/freebuff-v${version}/freebuff-linux-x64.tar.gz";
hash = "sha256-W/+lPhdHxq0a5TWY/JodAuP2hLpCGlLU7E8SoNe+OYA=";
};
in
stdenv.mkDerivation rec {
pname = "freebuff";
version = "0.0.174";
src = freebuffSrc;
nativeBuildInputs = [
makeWrapper
patchelf
];
dontStrip = true;
dontPatchelf = true;
installPhase = ''
runHook preInstall
# Extract and patch the pre-built binary for NixOS compatibility
mkdir -p "$out/bin" /tmp/fb-engine
tar xzf "${binarySrc}" -C /tmp/fb-engine --strip-components=0
cp /tmp/fb-engine/freebuff "$out/bin/freebuff-engine"
chmod 755 "$out/bin/freebuff-engine"
patchelf \
--set-interpreter "${glibc}/lib/ld-linux-x86-64.so.2" \
--set-rpath "${glibc}/lib:" \
"$out/bin/freebuff-engine"
if [ -f /tmp/fb-engine/tree-sitter.wasm ]; then
cp /tmp/fb-engine/tree-sitter.wasm "$out/bin/"
fi
rm -rf /tmp/fb-engine
# Extract npm dependencies from pre-fetched tarballs
extractNpmPkg() {
local src="$1" target="$2"
mkdir -p "$target"
tar xzf "$src" -C "$target" --strip-components=1
}
mkdir -p "$out/lib/node_modules/tar"
mkdir -p "$out/lib/node_modules/chownr"
mkdir -p "$out/lib/node_modules/minipass"
mkdir -p "$out/lib/node_modules/minizlib"
mkdir -p "$out/lib/node_modules/yallist"
mkdir -p "$out/lib/node_modules/@isaacs/fs-minipass"
extractNpmPkg "${pkgTar}" "$out/lib/node_modules/tar"
extractNpmPkg "${pkgChownr}" "$out/lib/node_modules/chownr"
extractNpmPkg "${pkgMinipass}" "$out/lib/node_modules/minipass"
extractNpmPkg "${pkgMinizlib}" "$out/lib/node_modules/minizlib"
extractNpmPkg "${pkgYallist}" "$out/lib/node_modules/yallist"
extractNpmPkg "${pkgFsMinipass}" "$out/lib/node_modules/@isaacs/fs-minipass"
# Launcher: run the patched engine directly from nix-store
cat > "$out/bin/launcher.js" << LAUNCHER_EOF
#!/usr/bin/env node
const { spawn } = require('child_process');
const TERMINAL_RESET = '\x1b[?1049l\x1b[?1000l\x1b[?1002l\x1b[?1003l\x1b[?1006l\x1b[?2004l\x1b[?25h';
const engine = '${placeholder "out"}/bin/freebuff-engine';
function reset() {
try { if (process.stdin.isTTY && process.stdin.setRawMode) process.stdin.setRawMode(false); } catch(e){}
try { if (process.stdout.isTTY) process.stdout.write(TERMINAL_RESET); } catch(e){}
}
const child = spawn(engine, process.argv.slice(2), { stdio: 'inherit' });
child.on('exit', (code, signal) => { reset(); process.exit(signal ? 1 : code || 0); });
child.on('error', (e) => { console.error('Failed to start freebuff:', e.message); process.exit(1); });
LAUNCHER_EOF
makeWrapper "${nodejs}/bin/node" "$out/bin/freebuff" \
--set NODE_PATH "$out/lib/node_modules" \
--add-flags "$out/bin/launcher.js"
runHook postInstall
'';
doCheck = false;
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#freebuff"
];
};
meta = with lib; {
description = "The world's strongest free coding agent";
homepage = "https://codebuff.com";
license = licenses.mit;
mainProgram = "freebuff";
platforms = platforms.linux;
};
}
+10
View File
@@ -0,0 +1,10 @@
{
pkgs,
inputs,
...
}:
# freetoken pins torch>=2.11,<2.12 and triton==3.6.0, but current
# nixos-unstable ships torch 2.13 + triton 3.7 and no older torch. Build it
# with the pinned nixpkgs-torch211 revision (CUDA 12.9 / torch-bin 2.11).
inputs.nixpkgs-torch211.legacyPackages.${pkgs.stdenv.hostPlatform.system}.callPackage ./package.nix
{ }
+51
View File
@@ -0,0 +1,51 @@
{
lib,
buildPythonPackage,
fetchurl,
# dependencies
numpy,
numba,
# torch-bin (CUDA wheel build) and triton-bin are passed by the caller;
# the python scope defaults are the source-built torch (CPU-only) and
# triton — using them would duplicate torch/triton in the closure.
torch,
triton,
tqdm,
}:
buildPythonPackage rec {
pname = "flashlib";
version = "0.3.0";
format = "wheel";
src = fetchurl {
url = "https://files.pythonhosted.org/packages/e5/b8/4c085892462e521bb9f2d943ff34fa219e3a5a206798f3c96a983538039f/flashlib-0.3.0-py3-none-any.whl";
hash = "sha256-kDeRHzFf7zyfRFMmFZc2Ory4OGiBOtGyWKsTCLNP0Ro=";
};
# freetoken pins flashlib==0.3.0 (not in nixpkgs) and only uses its Triton
# kernels (flashlib.kernels.slot_cache). nvidia-cutlass-dsl — needed only by
# the CuTeDSL GEMM backends in flashlib.linalg, which drag in cuda-python and
# nvdisasm binary wheels — is deliberately not packaged (and removed from
# the wheel metadata so the runtime deps check passes).
pythonRemoveDeps = [ "nvidia-cutlass-dsl" ];
dependencies = [
numpy
numba
torch
triton
tqdm
];
# flashlib is CPU-safe at import time: CuteDSL imports are lazy and hardware
# detection (flashlib._hw) is cuda-optional.
pythonImportsCheck = [ "flashlib" ];
meta = {
description = "High-performance ML primitives — Triton and CuteDSL kernels for NVIDIA GPUs";
homepage = "https://pypi.org/project/flashlib/";
license = lib.licenses.asl20;
platforms = lib.platforms.linux;
};
}
+191
View File
@@ -0,0 +1,191 @@
{
lib,
pkgs,
fetchFromGitHub,
}:
let
# FreeToken is an NVIDIA-GPU inference engine: setup.py builds two C++
# extensions that link the CUDA runtime, and the runtime needs a
# CUDA-enabled torch. CUDA libraries carry the unfree "CUDA EULA" license,
# so this package re-imports the flake's nixpkgs with allowUnfree enabled —
# scoped to freetoken only, leaving the rest of the overlay unchanged.
nixpkgsUnfree = import pkgs.path {
inherit (pkgs.stdenv.hostPlatform) system;
config.allowUnfree = true;
};
py = nixpkgsUnfree.python3Packages;
# torch>=2.11,<2.12: torch-bin 2.11 is this nixpkgs' CUDA build (it links
# the cuda12.9-* libraries). The extensions must link the same libcudart
# instance torch-bin links, so CUDA_HOME below is built from the matching
# cudaPackages.cuda_cudart.
cudart = nixpkgsUnfree.cudaPackages.cuda_cudart;
# cuda_runtime_api.h includes crt/host_defines.h & co., which ship with
# nvcc's header set, not with cudart.
nvccHeaders = nixpkgsUnfree.cudaPackages.cuda_nvcc;
# setup.py requires CUDA_HOME containing CUDA headers and libcudart.
# Single-output cudart provides ${cudart}/include and ${cudart}/lib; the
# crt/ headers come from nvcc; lib64/ is added for torch's cpp_extension,
# lib/ is picked up by setup.py's cuda-home/lib fallback.
cudaHome = nixpkgsUnfree.runCommand "freetoken-cuda-home" { } ''
mkdir -p $out/include $out/lib64
ln -s ${cudart}/include/* $out/include/
ln -s ${nvccHeaders}/include/crt $out/include/crt
ln -s ${cudart}/lib $out/lib
for f in ${cudart}/lib/*.so*; do
ln -s "$f" "$out/lib64/$(basename "$f")"
done
'';
# flashlib==0.3.0, pinned by freetoken, is not in nixpkgs. torch and triton
# come from the prebuilt wheel builds (torch-bin / triton-bin), the same
# instances torch-bin propagates — the scope defaults (source-built torch
# and triton) would put two tritons/torches into the closure.
flashlib = py.callPackage ./flashlib.nix {
torch = py.torch-bin;
triton = py.triton-bin;
};
# freetoken pins apache-tvm-ffi==0.1.13.post3; nixpkgs has 0.1.10.
# 0.1.13 needs cython>=3.2.8 (nixpkgs: 3.2.4), so build it with a newer
# cython, scoped to this package only.
apache-tvm-ffi =
(py.apache-tvm-ffi.override {
cython = py.cython.overridePythonAttrs (old: rec {
version = "3.3.0";
src = fetchFromGitHub {
owner = "cython";
repo = "cython";
tag = version;
hash = "sha256-gIEqq8DAJF197gH1cMuq5JxI4rV/VHS70vg8hywXDqw=";
};
});
}).overridePythonAttrs
(old: {
version = "0.1.13.post3";
src = fetchFromGitHub {
owner = "apache";
repo = "tvm-ffi";
tag = "v0.1.13-post3";
fetchSubmodules = true;
hash = "sha256-AN7AqBl62T8DqnRt7KRvGjqo/c0SJ66QZrCQQ5yicHw=";
};
# 0.1.13 runs its suite with pytest-xdist (pyproject addopts = [ "-n"
# "auto" ]) and touches GPUs; the nixpkgs check inputs have neither
# xdist nor a GPU. The imports check still runs (and passes).
dontUsePytestCheck = true;
});
in
py.buildPythonApplication (finalAttrs: {
pname = "freetoken";
version = "0.1.2";
pyproject = true;
src = fetchFromGitHub {
owner = "FlashML-org";
repo = "FreeToken";
tag = "v${finalAttrs.version}";
hash = "sha256-0MhuubuTjNvtQZxisC2cg1dJeR+A6wZ901H5FRv+l+c=";
};
# setup.py imports torch.utils.cpp_extension at build time and compiles two
# C++ extensions (freetoken.kernel._pinned_tensor and _cpu_moe) that link
# libcudart from CUDA_HOME. ninja is required by BuildExtension.
build-system = with py; [
ninja
setuptools
torch-bin
wheel
];
nativeBuildInputs = [ nixpkgsUnfree.autoPatchelfHook ];
# cudart: RPATH target for the built extensions (autoPatchelf finds
# libcudart.so.12 here); libtorch comes from torch-bin via dependencies.
buildInputs = [ cudart ];
env.CUDA_HOME = cudaHome;
dependencies = with py; [
apache-tvm-ffi
einops
fastapi
flashlib
gguf
huggingface-hub
# freetoken's floor is modelscope>=1.37 (nixpkgs has 1.36.2); the only
# API used is modelscope.snapshot_download (server/args.py), which is
# stable across both.
modelscope
msgpack
numpy
openai
partial-json-parser
prompt-toolkit
pydantic
pyzmq
safetensors
torch-bin
# triton==3.6.0 pin, satisfied with the wheel build (triton-bin) — the
# same instance torch-bin propagates, keeping one triton in the closure.
triton-bin
tqdm
transformers
uvicorn
];
# Tests need an NVIDIA GPU and real model checkpoints (pytest markers
# slow/needs_weights) — impossible in the build sandbox.
doCheck = false;
pythonImportsCheck = [ "freetoken" ];
# Wheel metadata constraints that nixpkgs packages do not match:
# - gguf is versioned by upstream git rev in nixpkgs ("8951") rather than
# PyPI semver; the reader API freetoken uses is stable.
# - modelscope floor is 1.37 (nixpkgs: 1.36.2); only the stable
# snapshot_download API is used.
pythonRelaxDeps = [
"gguf"
"modelscope"
];
passthru = {
category = "AI Inference";
updateScript = [
"nix-update"
"--flake"
".#freetoken"
];
};
meta = {
description = "Local MoE-offload LLM inference runtime with OpenAI- and Anthropic-compatible APIs";
longDescription = ''
FreeToken is an edge-native MoE serving engine for running
frontier-scale open-weight models on consumer NVIDIA GPUs (RTX
30/40/50 series). It treats GPUs, CPUs and host memory as one elastic
inference platform, with semantic-aware KV/expert caching and runtime
VRAM re-allocation between caches. It serves OpenAI- and
Anthropic-compatible APIs.
Nix packaging notes:
- Built against this nixpkgs' CUDA 12.9 stack (torch-bin 2.11 +
cudaPackages.cuda_cudart) instead of upstream's cu130 wheels; CUDA
12.9 supports the same GPU range, including RTX 50 (sm_120).
- The optional native accel extras (flashinfer, sglang-kernel) and the
freetoken-kernel-cache companion wheel are not packaged; the runtime
falls back to its pure-Triton kernels where those would be used.
- Requires an NVIDIA GPU at runtime.
'';
homepage = "https://github.com/FlashML-org/FreeToken";
changelog = "https://github.com/FlashML-org/FreeToken/releases/tag/v${finalAttrs.version}";
# Upstream code is Apache-2.0, but this derivation links CUDA libraries
# under the unfree CUDA EULA (same as nixpkgs' torch-bin).
license = lib.licenses.unfree;
platforms = [ "x86_64-linux" ];
mainProgram = "ft";
};
})
+19
View File
@@ -0,0 +1,19 @@
{
pkgs,
...
}:
# nixpkgs' pybloomfilter3 0.7.3 (a datasketch dependency) ships sdist metadata
# that still says 0.7.2, which makes pythonMetadataCheckPhase fail even though
# the build succeeds. Skip only that check.
let
python = pkgs.python3.override {
packageOverrides = self: super: {
pybloomfilter3 = super.pybloomfilter3.overridePythonAttrs (_: {
dontCheckPythonMetadata = true;
});
};
};
in
python.pkgs.callPackage ./package.nix {
python3Packages = python.pkgs;
}
+92
View File
@@ -0,0 +1,92 @@
{
lib,
python3Packages,
fetchFromGitHub,
}:
python3Packages.buildPythonApplication rec {
pname = "graphify";
version = "0.9.61";
pyproject = true;
src = fetchFromGitHub {
owner = "safishamsi";
repo = "graphify";
rev = "v${version}";
hash = "sha256-9AEbHmqqZv/fBioUMNv60KAb/FpvWpwC6QhGSdBxISs=";
};
build-system = with python3Packages; [
setuptools
];
# Only tree-sitter grammars available in nixpkgs are included.
# Missing grammars will be downloaded by tree-sitter at runtime on demand.
dependencies = with python3Packages; [
networkx
datasketch
rapidfuzz
tree-sitter
tree-sitter-python
tree-sitter-javascript
tree-sitter-rust
tree-sitter-c-sharp
tree-sitter-sql
];
# Remove unavailable tree-sitter grammars from pyproject.toml.
# Since 0.9.35 upstream pins versions ("tree-sitter-X>=v,<v"), and GNU sed
# mishandles `"` inside bracket expressions, match the name followed by
# either `>` (versioned) or `"` (bare) via alternation. This also avoids
# prefix collisions (e.g. tree-sitter-c vs tree-sitter-c-sharp).
postPatch = ''
# relax the build-backend pin: nixpkgs' setuptools is older than 83, but
# the PEP 639 license metadata graphify relies on needs only >=77.
sed -i 's/setuptools>=83\.[0-9.]*/setuptools/' pyproject.toml
sed -i \
-e '/tree-sitter-typescript>\|tree-sitter-typescript"/d' \
-e '/tree-sitter-go>\|tree-sitter-go"/d' \
-e '/tree-sitter-java>\|tree-sitter-java"/d' \
-e '/tree-sitter-groovy>\|tree-sitter-groovy"/d' \
-e '/tree-sitter-c>\|tree-sitter-c"/d' \
-e '/tree-sitter-cpp>\|tree-sitter-cpp"/d' \
-e '/tree-sitter-ruby>\|tree-sitter-ruby"/d' \
-e '/tree-sitter-kotlin>\|tree-sitter-kotlin"/d' \
-e '/tree-sitter-scala>\|tree-sitter-scala"/d' \
-e '/tree-sitter-php>\|tree-sitter-php"/d' \
-e '/tree-sitter-swift>\|tree-sitter-swift"/d' \
-e '/tree-sitter-lua>\|tree-sitter-lua"/d' \
-e '/tree-sitter-zig>\|tree-sitter-zig"/d' \
-e '/tree-sitter-powershell>\|tree-sitter-powershell"/d' \
-e '/tree-sitter-elixir>\|tree-sitter-elixir"/d' \
-e '/tree-sitter-objc>\|tree-sitter-objc"/d' \
-e '/tree-sitter-julia>\|tree-sitter-julia"/d' \
-e '/tree-sitter-verilog>\|tree-sitter-verilog"/d' \
-e '/tree-sitter-fortran>\|tree-sitter-fortran"/d' \
-e '/tree-sitter-bash>\|tree-sitter-bash"/d' \
-e '/tree-sitter-json>\|tree-sitter-json"/d' \
pyproject.toml
'';
doCheck = false;
pythonImportsCheck = [ "graphify" ];
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#graphify"
"--version=branch=main"
];
};
meta = {
description = "AI coding assistant skill - turn any folder of code, docs, papers, images, or videos into a queryable knowledge graph";
homepage = "https://github.com/Graphify-Labs/graphify";
changelog = "https://github.com/Graphify-Labs/graphify/releases/tag/v${version}";
license = lib.licenses.asl20;
mainProgram = "graphify";
platforms = lib.platforms.all;
};
}
+1
View File
@@ -0,0 +1 @@
{ pkgs, ... }: pkgs.callPackage ./package.nix { }
+459
View File
@@ -0,0 +1,459 @@
--- a/haivemind_tui.py
+++ b/haivemind_tui.py
@@ -1197,0 +1198,8 @@
+ def on_mount(self) -> None:
+ app = self.app
+ if (
+ getattr(app, "_prompt", None) is not None
+ and getattr(app, "_config", None) is not None
+ ):
+ app.start_run(app._prompt, app._config)
+
@@ -1220,13 +1220,13 @@
self._engine: HaivemindEngine | None = None
self._run_started = False
self._run_start_time: float = 0.0
+ self._main_screen = None
def on_mount(self) -> None:
- self.push_screen(MainScreen())
+ self._main_screen = MainScreen()
+ self.push_screen(self._main_screen)
self.set_interval(0.15, self._tick_spinner)
- if self._prompt is not None and self._config is not None:
- self.start_run(self._prompt, self._config)
- else:
+ if self._prompt is None or self._config is None:
self.push_screen(ConfigScreen())
def start_run(self, prompt: str, config: HaivemindConfig) -> None:
@@ -1303,7 +1303,7 @@
def _tick_spinner(self) -> None:
_advance_spinner()
try:
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
if "streaming" in hbar._model_status.values():
hbar._refresh()
except NoMatches:
@@ -1315,20 +1315,20 @@
def _on_probe_start(self) -> None:
import time as _time
self._run_start_time = _time.time()
- chat = self.query_one("#chat-log", ChatLog)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
chat.add_summary("[bold yellow]Probing models...[/]")
if self._config is not None:
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
hbar.set_models(self._config.models)
- header = self.query_one("#header-bar", HeaderBar)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
header.consensus_info = "probing"
header.progress_pct = 0.0
@on(ProbeResult)
def _on_probe_result(self, event: ProbeResult) -> None:
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
hbar.set_status(event.model, "done" if event.ok else "failed")
- chat = self.query_one("#chat-log", ChatLog)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
if event.ok:
color = hbar.model_color(event.model)
chat.add_summary(f"[{color}][probe] ok: {event.model}[/]")
@@ -1339,44 +1339,44 @@
@on(ProbeDone)
def _on_probe_done(self, event: ProbeDone) -> None:
- chat = self.query_one("#chat-log", ChatLog)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
chat.add_summary(
f"[bold yellow]Probe complete:[/] {len(event.healthy)} healthy, "
f"{len(event.failures)} failed"
)
- header = self.query_one("#header-bar", HeaderBar)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
header.consensus_info = ""
if event.healthy:
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
hbar.set_models(event.healthy)
- theatre = self.query_one("#theatre-container", TheatrePanel)
+ theatre = self._main_screen.query_one("#theatre-container", TheatrePanel)
theatre.update_layout(event.healthy, hbar._model_colors)
@on(RoundStart)
def _on_round_start(self, event: RoundStart) -> None:
- chat = self.query_one("#chat-log", ChatLog)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
chat.add_summary(f"\n[bold cyan]\u2500\u2500 Round {event.round_idx}/{event.total} \u2500\u2500[/]")
- header = self.query_one("#header-bar", HeaderBar)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
header.round_info = f"hAIvemind \u2502 Round {event.round_idx}/{event.total}"
header.consensus_info = ""
try:
- theatre = self.query_one("#theatre-container", TheatrePanel)
+ theatre = self._main_screen.query_one("#theatre-container", TheatrePanel)
theatre.clear_all()
except NoMatches:
pass
@on(ModelStart)
def _on_model_start(self, event: ModelStart) -> None:
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
hbar.set_status(event.model, "streaming")
- header = self.query_one("#header-bar", HeaderBar)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
total = len(hbar._model_status) if hbar._model_status else 0
done_count = sum(
1 for s in hbar._model_status.values() if s in ("streaming", "done")
)
header.model_info = f"Models: {done_count}/{total}"
try:
- theatre = self.query_one("#theatre-container", TheatrePanel)
+ theatre = self._main_screen.query_one("#theatre-container", TheatrePanel)
active = [
m for m, s in hbar._model_status.items() if s != "dropped"
]
@@ -1386,27 +1386,27 @@
@on(ModelStream)
def _on_model_stream(self, event: ModelStream) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
color = hbar.model_color(event.model)
t = event.fragment.strip()
if t:
chat.add_summary(f"[{color}][{event.model}][/] {t}")
try:
- theatre = self.query_one("#theatre-container", TheatrePanel)
+ theatre = self._main_screen.query_one("#theatre-container", TheatrePanel)
theatre.stream_to_model(event.model, event.fragment)
except NoMatches:
pass
@on(ModelDone)
def _on_model_done(self, event: ModelDone) -> None:
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
ar = event.agent_round
if ar.error and ar.error not in ("stderr",):
hbar.set_status(event.model, "failed")
else:
hbar.set_status(event.model, "done")
- chat = self.query_one("#chat-log", ChatLog)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
color = hbar.model_color(event.model)
if ar.has_valid_draft:
chat.add_summary(
@@ -1419,14 +1419,14 @@
@on(ModelDropped)
def _on_model_dropped(self, event: ModelDropped) -> None:
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
hbar.set_status(event.model, "dropped")
- chat = self.query_one("#chat-log", ChatLog)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
chat.add_summary(
f"[red]\u26a0 {event.model} dropped:[/] {event.reason}"
)
try:
- theatre = self.query_one("#theatre-container", TheatrePanel)
+ theatre = self._main_screen.query_one("#theatre-container", TheatrePanel)
remaining = [
m for m, s in hbar._model_status.items() if s != "dropped"
]
@@ -1436,7 +1436,7 @@
@on(RoundDone)
def _on_round_done(self, event: RoundDone) -> None:
- chat = self.query_one("#chat-log", ChatLog)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
dur = event.record.get("duration_s", 0)
chat.add_summary(
f"[dim]\u2500\u2500 end round {event.round_idx} ({dur}s) \u2500\u2500[/]"
@@ -1446,15 +1446,15 @@
best_sim = _compute_best_similarity(drafts)
threshold = self._config.threshold if self._config else 0.75
pct = min(1.0, best_sim / threshold) if threshold > 0 else 0.0
- header = self.query_one("#header-bar", HeaderBar)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
header.progress_pct = pct
header.consensus_info = f"sim: {best_sim:.2f}"
@on(Consensus)
def _on_consensus(self, event: Consensus) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- header = self.query_one("#header-bar", HeaderBar)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
total_models = len(hbar._model_status) if hbar._model_status else 0
import time as _time
elapsed = (
@@ -1493,9 +1493,9 @@
@on(Fallback)
def _on_fallback(self, event: Fallback) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- header = self.query_one("#header-bar", HeaderBar)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
total_models = len(hbar._model_status) if hbar._model_status else 0
header.consensus_info = "fallback"
header.progress_pct = 0.0
@@ -1518,30 +1518,30 @@
@on(EngineError)
def _on_engine_error(self, event: EngineError) -> None:
- chat = self.query_one("#chat-log", ChatLog)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
chat.add_summary(f"[red]Error:[/] {event.message}")
- header = self.query_one("#header-bar", HeaderBar)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
header.consensus_info = "error"
@on(EngineLog)
def _on_engine_log(self, event: EngineLog) -> None:
- chat = self.query_one("#chat-log", ChatLog)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
chat.add_summary(event.message)
@on(MoaRefStart)
def _on_moa_ref_start(self, event: MoaRefStart) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
hbar.set_status(event.model, "streaming")
color = hbar.model_color(event.model)
chat.add_summary(f"[{color}]\U0001f4e1 [ref] {event.model} analyzing...[/]")
- header = self.query_one("#header-bar", HeaderBar)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
header.round_info = "hAIvemind \u2502 MoA \u2502 References"
@on(MoaRefDone)
def _on_moa_ref_done(self, event: MoaRefDone) -> None:
- hbar = self.query_one("#health-bar", ModelHealthBar)
- chat = self.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
color = hbar.model_color(event.model)
if event.err and not event.raw.strip():
hbar.set_status(event.model, "failed")
@@ -1552,32 +1552,32 @@
@on(MoaRefStream)
def _on_moa_ref_stream(self, event: MoaRefStream) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
color = hbar.model_color(event.model)
t = event.fragment.strip()
if t:
chat.add_summary(f"[{color}][ref:{event.model}][/] {t}")
try:
- theatre = self.query_one("#theatre-container", TheatrePanel)
+ theatre = self._main_screen.query_one("#theatre-container", TheatrePanel)
theatre.stream_to_model(event.model, event.fragment)
except NoMatches:
pass
@on(MoaAggStart)
def _on_moa_agg_start(self, event: MoaAggStart) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
hbar.set_status(event.model, "streaming")
color = hbar.model_color(event.model)
chat.add_summary(f"\n[bold {color}]\U0001f9e0 [aggregator] {event.model} synthesizing...[/]")
- header = self.query_one("#header-bar", HeaderBar)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
header.round_info = "hAIvemind \u2502 MoA \u2502 Aggregating"
@on(MoaAggDone)
def _on_moa_agg_done(self, event: MoaAggDone) -> None:
- hbar = self.query_one("#health-bar", ModelHealthBar)
- chat = self.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
color = hbar.model_color(event.model)
if event.raw.strip():
hbar.set_status(event.model, "done")
@@ -1588,14 +1588,14 @@
@on(MoaAggStream)
def _on_moa_agg_stream(self, event: MoaAggStream) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
color = hbar.model_color(event.model)
t = event.fragment.strip()
if t:
chat.add_summary(f"[{color}][agg:{event.model}][/] {t}")
try:
- theatre = self.query_one("#theatre-container", TheatrePanel)
+ theatre = self._main_screen.query_one("#theatre-container", TheatrePanel)
theatre.stream_to_model(event.model, event.fragment)
except NoMatches:
pass
@@ -1604,18 +1604,18 @@
@on(FusionPanelStart)
def _on_fusion_panel_start(self, event: FusionPanelStart) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
hbar.set_status(event.model, "streaming")
color = hbar.model_color(event.model)
chat.add_summary(f"[{color}]\U0001f52c [panel] {event.model} analyzing...[/]")
- header = self.query_one("#header-bar", HeaderBar)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
header.round_info = "hAIvemind \u2502 Fusion \u2502 Panel"
@on(FusionPanelDone)
def _on_fusion_panel_done(self, event: FusionPanelDone) -> None:
- hbar = self.query_one("#health-bar", ModelHealthBar)
- chat = self.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
color = hbar.model_color(event.model)
if event.err and not event.raw.strip():
hbar.set_status(event.model, "failed")
@@ -1626,32 +1626,32 @@
@on(FusionPanelStream)
def _on_fusion_panel_stream(self, event: FusionPanelStream) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
color = hbar.model_color(event.model)
t = event.fragment.strip()
if t:
chat.add_summary(f"[{color}][panel:{event.model}][/] {t}")
try:
- theatre = self.query_one("#theatre-container", TheatrePanel)
+ theatre = self._main_screen.query_one("#theatre-container", TheatrePanel)
theatre.stream_to_model(event.model, event.fragment)
except NoMatches:
pass
@on(FusionJudgeStart)
def _on_fusion_judge_start(self, event: FusionJudgeStart) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
hbar.set_status(event.model, "streaming")
color = hbar.model_color(event.model)
chat.add_summary(f"\n[bold {color}]\u2696\ufe0f [judge] {event.model} analyzing...[/]")
- header = self.query_one("#header-bar", HeaderBar)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
header.round_info = "hAIvemind \u2502 Fusion \u2502 Judging"
@on(FusionJudgeDone)
def _on_fusion_judge_done(self, event: FusionJudgeDone) -> None:
- hbar = self.query_one("#health-bar", ModelHealthBar)
- chat = self.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
color = hbar.model_color(event.model)
if event.raw.strip():
hbar.set_status(event.model, "done")
@@ -1662,32 +1662,32 @@
@on(FusionJudgeStream)
def _on_fusion_judge_stream(self, event: FusionJudgeStream) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
color = hbar.model_color(event.model)
t = event.fragment.strip()
if t:
chat.add_summary(f"[{color}][judge:{event.model}][/] {t}")
try:
- theatre = self.query_one("#theatre-container", TheatrePanel)
+ theatre = self._main_screen.query_one("#theatre-container", TheatrePanel)
theatre.stream_to_model(event.model, event.fragment)
except NoMatches:
pass
@on(FusionSynthStart)
def _on_fusion_synth_start(self, event: FusionSynthStart) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
hbar.set_status(event.model, "streaming")
color = hbar.model_color(event.model)
chat.add_summary(f"\n[bold {color}]\u270d\ufe0f [synth] {event.model} writing final answer...[/]")
- header = self.query_one("#header-bar", HeaderBar)
+ header = self._main_screen.query_one("#header-bar", HeaderBar)
header.round_info = "hAIvemind \u2502 Fusion \u2502 Synthesizing"
@on(FusionSynthDone)
def _on_fusion_synth_done(self, event: FusionSynthDone) -> None:
- hbar = self.query_one("#health-bar", ModelHealthBar)
- chat = self.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
color = hbar.model_color(event.model)
if event.raw.strip():
hbar.set_status(event.model, "done")
@@ -1698,14 +1698,14 @@
@on(FusionSynthStream)
def _on_fusion_synth_stream(self, event: FusionSynthStream) -> None:
- chat = self.query_one("#chat-log", ChatLog)
- hbar = self.query_one("#health-bar", ModelHealthBar)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
+ hbar = self._main_screen.query_one("#health-bar", ModelHealthBar)
color = hbar.model_color(event.model)
t = event.fragment.strip()
if t:
chat.add_summary(f"[{color}][synth:{event.model}][/] {t}")
try:
- theatre = self.query_one("#theatre-container", TheatrePanel)
+ theatre = self._main_screen.query_one("#theatre-container", TheatrePanel)
theatre.stream_to_model(event.model, event.fragment)
except NoMatches:
pass
@@ -1720,7 +1720,7 @@
def action_toggle_theatre(self) -> None:
try:
- tc = self.query_one("#theatre-container")
+ tc = self._main_screen.query_one("#theatre-container")
if tc.has_class("visible"):
tc.remove_class("visible")
else:
@@ -1734,13 +1734,13 @@
def action_clear_theatre(self) -> None:
try:
- theatre = self.query_one("#theatre-container", TheatrePanel)
+ theatre = self._main_screen.query_one("#theatre-container", TheatrePanel)
theatre.clear_all()
except NoMatches:
pass
def action_show_artifacts(self) -> None:
- chat = self.query_one("#chat-log", ChatLog)
+ chat = self._main_screen.query_one("#chat-log", ChatLog)
if self._engine and self._engine.run_dir:
chat.add_summary(f"[bold]Artifacts:[/] {self._engine.run_dir}")
else:
+62
View File
@@ -0,0 +1,62 @@
{
lib,
fetchFromGitHub,
python3Packages,
}:
python3Packages.buildPythonApplication rec {
pname = "haivemind";
version = "0.1.0";
pyproject = true;
src = fetchFromGitHub {
owner = "dev-boz";
repo = "haivemind";
rev = "ce4a0437d41f57638b71a17e2ff3af524d5a1b6e";
hash = "sha256-x7NM2wHwi11i07jHTL9NgYJkzzlP+tOmJy027itRtWs=";
};
build-system = with python3Packages; [
setuptools
];
dependencies = with python3Packages; [
textual
];
patches = [
./fix-chat-log-race.patch
];
postPatch = ''
substituteInPlace haivemind_tui.py \
--replace-fail "sel.value = Select.BLANK" "sel.clear()" \
--replace-fail "v is Select.BLANK" "v is Select.NULL"
'';
doCheck = false;
pythonImportsCheck = [
"haivemind"
"haivemind_tui"
"haivemind_curses"
];
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#haivemind"
"--version=branch=main"
];
};
meta = with lib; {
description = "Multi-model AI consensus, aggregation, and fusion runner for popular AI CLIs";
homepage = "https://github.com/dev-boz/haivemind";
changelog = "https://github.com/dev-boz/haivemind/commits/main";
license = licenses.mit;
mainProgram = "haivemind";
platforms = platforms.all;
};
}
+30
View File
@@ -0,0 +1,30 @@
{
pkgs,
...
}:
# hipEngine >= 0.5.0 requires llguidance >= 1.8,<2; nixpkgs only provides
# 1.7.x. Override nixpkgs' llguidance to 1.8.0 and hand the resulting
# interpreter/package set to the package.
let
python = pkgs.python3.override {
packageOverrides = self: super: {
llguidance = super.llguidance.overridePythonAttrs (old: rec {
version = "1.8.0";
src = pkgs.fetchFromGitHub {
owner = "guidance-ai";
repo = "llguidance";
tag = "v${version}";
hash = "sha256-/rHTefKTq5ch38NqbcLYTXBJwkW+WzG5OFvignDIie4=";
};
cargoDeps = pkgs.rustPlatform.fetchCargoVendor {
pname = "llguidance";
inherit src version;
hash = "sha256-aa9R+6xgFVGAD3snHbkPRF5jMYwC3DFNjXcUtaOzDbU=";
};
});
};
};
in
python.pkgs.callPackage ./package.nix {
python3Packages = python.pkgs;
}
+55
View File
@@ -0,0 +1,55 @@
{
lib,
python3Packages,
fetchFromGitHub,
}:
python3Packages.buildPythonApplication rec {
pname = "hipengine";
version = "0.5.0";
pyproject = true;
src = fetchFromGitHub {
owner = "shisa-ai";
repo = "hipEngine";
rev = "v${version}";
hash = "sha256-xjVpdr2avDKA2IoXA9W5Q/c6cT+G/BxrTDzjP5Tm+3Y=";
};
build-system = with python3Packages; [
hatchling
];
dependencies = with python3Packages; [
fastapi
jinja2
llguidance
numpy
safetensors
tokenizers
uvicorn
];
doCheck = false;
pythonImportsCheck = [ "hipengine" ];
passthru = {
category = "AI Inference";
updateScript = [
"nix-update"
"--flake"
".#hipengine"
];
};
meta = {
description = "ROCm-native local LLM inference engine with a torch-free runtime hot path for AMD RDNA GPUs";
homepage = "https://github.com/shisa-ai/hipEngine";
changelog = "https://github.com/shisa-ai/hipEngine/releases/tag/v${version}";
license = lib.licenses.agpl3Plus;
platforms = lib.platforms.linux;
# Upstream replaced the hipengine-server console script with
# a top-level `hipengine` command (e.g. `hipengine serve`).
mainProgram = "hipengine";
};
}
@@ -0,0 +1,11 @@
{
pkgs,
inputs,
...
}:
# kubernetes-mcp-server >= 0.0.66 requires go >= 1.26.3, which the flake's
# pinned nixpkgs does not provide yet. Build with the newer nixpkgs-latest input.
let
latestPkgs = inputs.nixpkgs-latest.legacyPackages.${pkgs.stdenv.hostPlatform.system};
in
latestPkgs.callPackage ./package.nix { }
@@ -0,0 +1,50 @@
{
lib,
buildGoModule,
fetchFromGitHub,
}:
buildGoModule rec {
pname = "kubernetes-mcp-server";
version = "0.0.66";
src = fetchFromGitHub {
owner = "containers";
repo = "kubernetes-mcp-server";
rev = "v${version}";
hash = "sha256-vnJxSCfnpvOZJXQpKrCAW4QKt5R2PJDYQevA7O1uXZg=";
};
vendorHash = "sha256-gbqoT4X+wVOEktHm7jaAH9vHrUBrYgR8OjyFz1ljP6k=";
env.CGO_ENABLED = 0;
subPackages = [ "cmd/kubernetes-mcp-server" ];
# Tests require access to a live Kubernetes cluster
doCheck = false;
ldflags = [
"-s"
"-w"
];
passthru = {
category = "MCP Servers";
updateScript = [
"nix-update"
"--flake"
".#kubernetes-mcp-server"
];
};
meta = with lib; {
description = "Model Context Protocol (MCP) server for Kubernetes and OpenShift";
homepage = "https://github.com/containers/kubernetes-mcp-server";
changelog = "https://github.com/containers/kubernetes-mcp-server/releases/tag/v${version}";
license = licenses.asl20;
sourceProvenance = with sourceTypes; [ fromSource ];
mainProgram = "kubernetes-mcp-server";
platforms = platforms.all;
};
}
+17
View File
@@ -0,0 +1,17 @@
{
pkgs,
inputs,
...
}:
# llama.cpp b9645 is newer than the flake's pinned nixpkgs (llama-cpp b8983,
# pre-tools/ui) and needs its UI/ROCm layout, so build against the
# nixpkgs-latest input — same pattern as mcp-gateway/kubernetes-mcp-server.
let
latestPkgs = inputs.nixpkgs-latest.legacyPackages.${pkgs.stdenv.hostPlatform.system};
in
latestPkgs.callPackage ./package.nix {
# Strix Halo: build the ROCm dependencies (clr, rocBLAS, hipBLAS) for gfx1151
# only instead of every supported arch. clr's own build is arch-independent,
# so its store path is unchanged and stays substitutable.
rocmPackages = latestPkgs.rocmPackages.gfx1151;
}
+117
View File
@@ -0,0 +1,117 @@
{
lib,
# Build skeleton: nixpkgs' own llama-cpp derivation (b-tag layout, cmake/npm
# plumbing), retargeted at the pinned tag below.
llama-cpp,
fetchFromGitHub,
rocmPackages,
# nixpkgs-latest's nodejs/npm hooks: referenced only to strip them from
# nativeBuildInputs (the npm/web UI build is disabled below).
nodejs_latest,
npmHooks,
# Strix Halo (Radeon 8060S). clr/rocBLAS/hipBLAS come prefixed for this arch
# by the scoped rocmPackages in ./default.nix.
rocmGpuTargets ? [ "gfx1151" ],
}:
let
# Upstream release tag. Bump with:
# nix flake prefetch github:ggml-org/llama.cpp/b<NNNN>
# then update buildNumber and the src hash.
buildNumber = "9645";
# HIP flags from the llm-engine.nix bring-up config. The -I paths for
# hipBLASLt/rocWMMA are dropped because this tag's HIP backend links
# hipBLAS/rocBLAS only; GGML_HIPBLASLT and GGML_CUDA_ENABLE_UNIFIED_MEMORY
# are also unused by b9645 (cmake warns and ignores them).
hipFlags = lib.concatStringsSep " " [
"-mllvm"
"-amdgpu-early-inline-all=true"
"-mllvm"
"-amdgpu-function-calls=false"
"-mprefer-vector-width=512"
"-famd-opt"
"-mllvm"
"-inline-threshold=600"
"-mllvm"
"-unroll-threshold=150"
];
in
(llama-cpp.override {
inherit rocmPackages rocmGpuTargets;
rocmSupport = true;
vulkanSupport = true;
cudaSupport = false;
}).overrideAttrs
(old: {
version = buildNumber;
src = fetchFromGitHub {
owner = "ggml-org";
repo = "llama.cpp";
tag = "b${buildNumber}";
# Tarball hash (this tag has no submodules).
hash = "sha256-ntRwfI2/yVqi3QjQfO0ZajMFSD8r/6XPiuy0X2BhwVk=";
};
# The embedded web UI is disabled via cmakeFlags, so none of the npm
# machinery is needed: no dependency tree, and npmConfigHook hard-fails
# when npmDeps is null, so it (and nodejs) must come off the inputs.
npmDeps = null;
npmRoot = null;
npmDepsHash = null;
nativeBuildInputs = builtins.filter (x: x != nodejs_latest && x != npmHooks.npmConfigHook) (
old.nativeBuildInputs or [ ]
);
# The release tarball has no .git; upstream wants the build id in COMMIT.
postPatch = ''
echo ${buildNumber} > COMMIT
'';
# Replaces the base derivation's npm build step. CMAKE_HIP_FLAGS holds
# several space-separated flags, so it must be appended as an array element:
# plain cmakeFlags scalars are word-split by the cmake hook.
preConfigure = ''
prependToVar cmakeFlags "-DLLAMA_BUILD_COMMIT:STRING=$(cat COMMIT)"
cmakeFlagsArray+=("-DCMAKE_HIP_FLAGS=${hipFlags}")
'';
cmakeFlags =
builtins.filter (f: !(builtins.isString f && builtins.match ".*LLAMA_BUILD_NUMBER.*" f != null)) (
old.cmakeFlags or [ ]
)
++ [
"-DCMAKE_C_FLAGS=-march=znver5"
"-DCMAKE_CXX_FLAGS=-march=znver5"
"-DGGML_CPU=ON"
"-DGGML_AVX=ON"
"-DGGML_AVX_VNNI=ON"
"-DGGML_AVX2=ON"
"-DGGML_BMI2=ON"
"-DGGML_AVX512=ON"
"-DGGML_AVX512_VNNI=ON"
"-DGGML_AVX512_VBMI=ON"
"-DGGML_AVX512_BF16=ON"
"-DGGML_FMA=ON"
"-DGGML_F16C=ON"
"-DHIP_PLATFORM=amd"
"-DGGML_CUDA_FORCE_CUBLAS=OFF"
"-DGGML_HIPBLASLT=ON"
"-DGGML_HIP_NO_VMM=ON"
"-DGGML_HIP_GRAPHS=ON"
"-DGGML_CUDA_ENABLE_UNIFIED_MEMORY=ON"
"-DGGML_HIP_ROCWMMA_FATTN=OFF"
"-DGGML_HIP_MMQ_MFMA=ON"
"-DGGML_CUDA_FA_ALL_QUANTS=ON"
"-DCMAKE_BUILD_TYPE=Release"
"-DLLAMA_BUILD_NUMBER:STRING=${buildNumber}"
(lib.cmakeBool "LLAMA_BUILD_UI" false)
(lib.cmakeBool "LLAMA_USE_PREBUILT_UI" false)
];
# The base's update script tracks nixpkgs' llama-cpp attr, not this pin.
passthru = builtins.removeAttrs (old.passthru or { }) [ "updateScript" ] // {
category = "AI Inference";
};
})
+1
View File
@@ -0,0 +1 @@
{ pkgs, ... }: pkgs.callPackage ./package.nix { }
+56
View File
@@ -0,0 +1,56 @@
{
lib,
appimageTools,
fetchurl,
}:
let
version = "6.0.3";
src = fetchurl {
url = "https://artifacts.wilix.dev/repository/loop-files/loop-${version}/loop-desktop-${version}-linux-x86_64.AppImage";
hash = "sha256-zGWKlY6XwuL0e2mDpB/1t0UnW73bhCPcg6XkBJBCEFY=";
};
appimageContents = appimageTools.extractType2 {
pname = "loop";
inherit version src;
};
in
appimageTools.wrapType2 {
pname = "loop";
inherit version src;
extraPkgs = pkgsWith: [
pkgsWith.gtk3
pkgsWith.glib
];
extraInstallCommands = ''
mkdir -p $out/share/applications
install -m 444 ${appimageContents}/loop-desktop.desktop $out/share/applications/loop.desktop
substituteInPlace $out/share/applications/loop.desktop \
--replace-fail 'Exec=AppRun %U' 'Exec=loop %U'
mkdir -p $out/share/icons/hicolor
cp -r ${appimageContents}/usr/share/icons/hicolor/* $out/share/icons/hicolor/
'';
passthru = {
category = "Communication";
updateScript = [
"nix-update"
"--flake"
".#loop"
];
};
meta = {
description = "Corporate messenger for your team";
homepage = "https://loop.ru";
license = lib.licenses.unfree;
maintainers = [ ];
platforms = [ "x86_64-linux" ];
mainProgram = "loop";
sourceProvenance = [ lib.sourceTypes.binaryNativeCode ];
};
}
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+76
View File
@@ -0,0 +1,76 @@
{
lib,
rustPlatform,
fetchFromGitHub,
cacert,
}:
rustPlatform.buildRustPackage rec {
pname = "marmel";
# Upstream publishes no git tags or releases, so this is pinned to a commit.
# The version shape matches what `nix-update --version=branch=main` generates
# for a tagless repository.
version = "unstable-2026-09-13";
src = fetchFromGitHub {
owner = "Na1w";
repo = "marmel";
rev = "fd551ae3198d427b0f0df3429f88764c49095b23";
hash = "sha256-nghvUF0EdqTGWT6GMG5oW1iK76r9vgvYeUj98hNraIo=";
};
cargoHash = "sha256-sUSsxcj4m4uJ28RKdJWKsb+MlVW6GkWjZdhKPFKlE/Y=";
nativeCheckInputs = [ cacert ];
# The test suite builds `reqwest::Client`s, and rustls rejects construction
# outright when no system trust store is found ("No CA certificates were
# loaded from the system"). The sandbox has no /etc/ssl, so point the tests
# at nixpkgs' bundle. Build-time only; the installed binary still uses the
# host's trust store at runtime.
preCheck = ''
export SSL_CERT_FILE=${cacert}/etc/ssl/certs/ca-bundle.crt
'';
# Serialise the test harness. The lib suite shares process-global worker
# registries and steer/abort buses (src/orchestrator/workers.rs,
# src/orchestrator/bus.rs, src/orchestrator/preemption.rs), so the
# manager-loop tests fail nondeterministically when the harness runs them on
# parallel threads: rebuilding one unchanged derivation yielded 3 failures,
# then 1 failure, then 0 with serial threads. All 325 tests still run — none
# are skipped or filtered. Drop this flag once upstream makes that state
# per-instance.
cargoTestFlags = [
"--"
"--test-threads=1"
];
# Role prompts are embedded with `include_str!`, so the binary needs no
# runtime data files. The annotated example configs are the de-facto
# first-run documentation, since a backend URL and model are mandatory.
postInstall = ''
install -Dm644 marmel.toml.example $out/share/doc/${pname}/examples/marmel.toml.example
install -Dm644 marmel.toml.cloud $out/share/doc/${pname}/examples/marmel.toml.cloud
'';
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#marmel"
"--version=branch=main"
];
};
meta = {
description = "Autonomous agentic coding assistant with Manager + specialist subagent orchestration over any OpenAI-compatible LLM backend";
homepage = "https://github.com/Na1w/marmel";
# Upstream README states MIT, but the repository ships no LICENSE file and
# Cargo.toml has no license field.
license = lib.licenses.mit;
sourceProvenance = with lib.sourceTypes; [ fromSource ];
mainProgram = "marmel";
platforms = lib.platforms.unix;
};
}
+11
View File
@@ -0,0 +1,11 @@
{
pkgs,
inputs,
...
}:
# mcp-gateway >= 3.4.0 requires rustc >= 1.95, which the flake's pinned
# nixpkgs does not provide yet. Build with the newer nixpkgs-latest input.
let
latestPkgs = inputs.nixpkgs-latest.legacyPackages.${pkgs.stdenv.hostPlatform.system};
in
latestPkgs.callPackage ./package.nix { }
+60
View File
@@ -0,0 +1,60 @@
{
lib,
rustPlatform,
fetchFromGitHub,
pkg-config,
openssl,
}:
rustPlatform.buildRustPackage rec {
pname = "mcp-gateway";
version = "3.5.1";
src = fetchFromGitHub {
owner = "MikkoParkkola";
repo = "mcp-gateway";
rev = "v${version}";
hash = "sha256-fcH2einyG9bNNLKZPomAlfGonNw0rw+TuwlYw38531E=";
};
cargoHash = "sha256-3QI7s5IpxbW9nvnk3X3xuUopNQJZftANN5BtbQNhKrY=";
nativeBuildInputs = [ pkg-config ];
buildInputs = [
openssl
];
doCheck = false;
postInstall = ''
mkdir -p $out/lib/systemd/user
cat > $out/lib/systemd/user/mcp-gateway.service << EOF
[Unit]
Description=MCP Gateway
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
ExecStart=$out/bin/mcp-gateway --config %h/.config/mcp-gateway/gateway.yaml serve
Restart=on-failure
RestartSec=5
[Install]
WantedBy=default.target
EOF
'';
passthru.category = "MCP Servers";
meta = with lib; {
description = "Universal Model Context Protocol gateway that sits between AI client and MCP tools/servers";
homepage = "https://github.com/MikkoParkkola/mcp-gateway";
changelog = "https://github.com/MikkoParkkola/mcp-gateway/releases/tag/v${version}";
license = licenses.mit;
sourceProvenance = with sourceTypes; [ fromSource ];
mainProgram = "mcp-gateway";
platforms = platforms.all;
};
}
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+54
View File
@@ -0,0 +1,54 @@
{
lib,
python3Packages,
fetchFromGitHub,
}:
python3Packages.buildPythonApplication rec {
pname = "nftables-analyzer";
version = "0.1.0-unstable-2025-11-27";
src = fetchFromGitHub {
owner = "reinaldosaraiva";
repo = "nftables-analyzer";
rev = "5fc78d0c9ce173e3baa80a5655bcadb1b2f78493";
hash = "sha256-PlEIArUPSSOtVrdUEamZBr1YQnm+GJpl5Xxgk0tHrdw=";
};
sourceRoot = "source/backend";
pyproject = true;
build-system = with python3Packages; [
hatchling
];
dependencies = with python3Packages; [
typer
rich
pydantic
fastapi
uvicorn
python-multipart
];
doCheck = false;
pythonImportsCheck = [ "nftables_analyzer" ];
passthru = {
category = "Networking";
updateScript = [
"nix-update"
"--flake"
".#nftables-analyzer"
];
};
meta = with lib; {
description = "Analyze nftables firewall rules and evaluate traffic queries";
homepage = "https://github.com/reinaldosaraiva/nftables-analyzer";
license = licenses.mit;
mainProgram = "nftables-analyzer";
platforms = platforms.all;
};
}
+2273
View File
File diff suppressed because it is too large Load Diff
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+69
View File
@@ -0,0 +1,69 @@
{
lib,
rustPlatform,
fetchFromGitHub,
fetchurl,
pkg-config,
openssl,
}:
rustPlatform.buildRustPackage rec {
pname = "nftablesbuilder";
# Pinned to a commit rather than a release tag because upstream
# publishes releases only as tarballs on nftablesbuilder.eu.
version = "0.1.0-unstable-2026-01-27";
src = fetchFromGitHub {
owner = "AiseBouma";
repo = "NftablesBuilder";
rev = "f414e921c2857556cdb4d602ed832a32a6951d25";
hash = "sha256-5qwyVXLrUxOk7poVdUyi/yJUq1CYMffruvAO0ONO+cI=";
};
# Upstream source is incomplete: both crates depend on a `settings`
# crate (path = "../settings") that was never committed, and the GUI
# has no build tooling (raw TSX, no package.json). This patch adds
# the missing settings crate (schema recovered from the official
# release artifacts) plus a workspace Cargo.toml.
patches = [ ./settings-workspace.patch ];
cargoLock.lockFile = ./Cargo.lock;
# Prebuilt GUI from the official release tarball, since the GUI cannot
# be built from source. Upstream serves releases with a self-signed
# TLS certificate, hence curlOpts = "-k"; the hash still pins content.
guiSrc = fetchurl {
url = "https://nftablesbuilder.eu/releases/latest/nftablesbuilder.tar.gz";
sha256 = "sha256-vHyuKVH4OtXEisWeDo+b3gHg3TzdXUSfMbaNpfQOrns=";
curlOpts = "-k";
};
nativeBuildInputs = [ pkg-config ];
buildInputs = [ openssl ];
installPhase = ''
runHook preInstall
binDir=$(dirname "$(find target -type f -name nftablesbuilder -path '*/release/*' | head -1)")
install -Dm755 $binDir/nftablesbuilder $out/bin/nftablesbuilder
install -Dm755 $binDir/webserver $out/libexec/nftablesbuilder/webserver
mkdir -p $out/share/nftablesbuilder
tar -xzf $guiSrc -C $out/share/nftablesbuilder --strip-components=4 nftablesbuilder/root/opt/nftablesbuilder/html
install -Dm644 ${./settings.example} $out/share/nftablesbuilder/settings.example
runHook postInstall
'';
passthru = {
category = "Networking";
};
meta = with lib; {
description = "Web interface to manage nftables rules";
homepage = "https://github.com/AiseBouma/NftablesBuilder";
license = licenses.mit;
mainProgram = "nftablesbuilder";
platforms = platforms.linux;
};
}
File diff suppressed because it is too large Load Diff
+17
View File
@@ -0,0 +1,17 @@
[connection]
port = 1969
[paths]
savepath = "/var/lib/nftablesbuilder"
htmlpath = "/run/current-system/sw/share/nftablesbuilder/html"
[files]
nft = "/run/current-system/sw/bin/nft"
test = "/tmp/nftables.conf"
conf = "/etc/nftables.conf"
webserver = "/run/current-system/sw/libexec/nftablesbuilder/webserver"
tlskey = "/var/lib/nftablesbuilder/nftables.key"
tlscert = "/var/lib/nftablesbuilder/nftables.crt"
[commands]
reload = "systemctl reload nftables"
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+92
View File
@@ -0,0 +1,92 @@
{
lib,
buildNpmPackage,
fetchFromGitHub,
fetchurl,
nodejs_22,
makeBinaryWrapper,
}:
let
version = "3.8.50";
npmTarball = fetchurl {
url = "https://registry.npmjs.org/omniroute/-/omniroute-${version}.tgz";
hash = "sha256-c4xYrx+q6MV+tkOpOdEZH41+CD2Sle9haH0r/wSHjCk=";
};
in
buildNpmPackage (finalAttrs: {
pname = "omniroute";
inherit version;
src = fetchFromGitHub {
owner = "diegosouzapw";
repo = "OmniRoute";
rev = "v${finalAttrs.version}";
hash = "sha256-+2FMc9wrvPtQS3+mGsBVvKrd5RprYe/r/GJvjAVMBpc=";
};
nodejs = nodejs_22;
# Upstream's package-lock omits `resolved` URLs for some entries, which the
# v1 fetcher drops from the cache (npm then fails with ENOTCACHED).
npmDepsFetcherVersion = 2;
npmDepsHash = "sha256-wa5vQMYugA8E7lXOh4lgNH7JNbKOinNaW6Zk8Mw2e8k=";
# Skip Next.js build (requires network for Google Fonts).
# Pre-built dist/ is copied from the npm tarball in preConfigure.
dontNpmBuild = true;
nativeBuildInputs = [
makeBinaryWrapper
];
npmInstallFlags = [ "--ignore-scripts" ];
npmRebuildFlags = [ "--ignore-scripts" ];
env = {
HOME = "$TMPDIR";
};
preConfigure = ''
mkdir -p _npm_tmp
tar xzf ${npmTarball} -C _npm_tmp
cp -r _npm_tmp/package/dist .
rm -rf _npm_tmp
'';
installPhase = ''
runHook preInstall
mkdir -p $out/lib/node_modules/omniroute
cp -r . $out/lib/node_modules/omniroute/
mkdir -p $out/bin
makeWrapper "${nodejs_22}/bin/node" "$out/bin/omniroute" \
--add-flags "$out/lib/node_modules/omniroute/bin/omniroute.mjs"
makeWrapper "${nodejs_22}/bin/node" "$out/bin/omniroute-reset-password" \
--add-flags "$out/lib/node_modules/omniroute/bin/reset-password.mjs"
runHook postInstall
'';
passthru = {
category = "AI LLM Gateway";
updateScript = [
"nix-update"
"--flake"
".#omniroute"
];
};
meta = {
description = "Unified AI router with 160+ providers, RTK+Caveman compression, auto fallback, MCP/A2A, OpenAI-compatible APIs";
homepage = "https://github.com/diegosouzapw/OmniRoute";
changelog = "https://github.com/diegosouzapw/OmniRoute/releases/tag/v${finalAttrs.version}";
license = lib.licenses.mit;
mainProgram = "omniroute";
platforms = lib.platforms.all;
};
})
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+99
View File
@@ -0,0 +1,99 @@
{
lib,
buildGoModule,
buildNpmPackage,
fetchFromGitHub,
}:
let
version = "1.13.1";
src = fetchFromGitHub {
owner = "skyhook-io";
repo = "radar";
rev = "v${version}";
hash = "sha256-jRcX7wv+uHxH2hoYSoLEjcVnuRGAnrTt4tbwZozDb7Y=";
};
# Build the frontend as a separate derivation.
# The lockfile has some workspace packages without resolved URLs,
# so we patch them in postPatch before fetching dependencies.
frontend = buildNpmPackage {
pname = "radar-frontend";
inherit version src;
sourceRoot = "source";
# Upstream lockfile ships complete resolved/integrity fields for all
# packages since v1.9.x, so no lockfile patching is needed anymore.
npmDepsHash = "sha256-TuSBPGktl6s1adHWbP81+TOEZufo5y2gwiUnfiaLoOc=";
npmDepsFetcherVersion = 2;
makeCacheWritable = true;
doCheck = false;
# Build the web workspace and install its output
buildPhase = ''
runHook preBuild
cd web
HOME=$TMPDIR ../node_modules/.bin/vite build
cd ..
runHook postBuild
'';
installPhase = ''
runHook preInstall
mkdir -p $out
cp -r web/dist/* $out/
runHook postInstall
'';
};
in
buildGoModule {
pname = "radar";
inherit version src;
vendorHash = "sha256-sFlj1sE+ciXQauReWm3mLQZK21lqTaU4cAj06flpx30=";
# Copy pre-built frontend assets before Go compilation for go:embed
preBuild = ''
mkdir -p internal/static/dist
cp -r ${frontend}/* internal/static/dist/
'';
env.CGO_ENABLED = 0;
ldflags = [
"-s"
"-w"
"-X main.version=v${version}"
];
subPackages = [ "cmd/explorer" ];
doCheck = false;
postInstall = ''
ln -s $out/bin/explorer $out/bin/radar
'';
passthru = {
category = "Kubernetes";
inherit frontend;
updateScript = [
"nix-update"
"--flake"
".#radar"
];
};
meta = with lib; {
description = "Modern Kubernetes visibility — topology, event timeline, service traffic, resource browsing, Helm management, and GitOps support";
homepage = "https://github.com/skyhook-io/radar";
changelog = "https://github.com/skyhook-io/radar/releases/tag/v${version}";
license = licenses.asl20;
mainProgram = "radar";
platforms = platforms.linux;
};
}
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+107
View File
@@ -0,0 +1,107 @@
{
lib,
python3Packages,
fetchFromGitHub,
fetchurl,
makeWrapper,
}:
let
cerebras-cloud-sdk = python3Packages.buildPythonPackage rec {
pname = "cerebras-cloud-sdk";
version = "1.91.0";
pyproject = true;
src = fetchurl {
url = "https://files.pythonhosted.org/packages/0c/98/767ab62618be157b5fb21bce980ad5c8ebe155e32aff38521e511054e5c3/cerebras_cloud_sdk-1.91.0.tar.gz";
hash = "sha256-b0GT/sCIkR/+gpzlaCUQ+GEgzTUyyvToVAvzO1n9t+s=";
};
build-system = with python3Packages; [
hatchling
hatch-fancy-pypi-readme
];
postPatch = ''
sed -i 's/hatchling==[0-9.]*/hatchling/' pyproject.toml
'';
dependencies = with python3Packages; [
anyio
distro
httpx
pydantic
sniffio
typing-extensions
];
doCheck = false;
meta = {
description = "Python SDK for Cerebras AI platform";
homepage = "https://github.com/CerebrasAI/cerebras-cloud-sdk-python";
license = lib.licenses.asl20;
};
};
pyDeps = with python3Packages; [
fastapi
uvicorn
google-genai
cerebras-cloud-sdk
groq
mistralai
requests
python-dotenv
pydantic
httpx
];
in
python3Packages.buildPythonApplication {
pname = "relay-free-llm";
version = "0-unstable-2026-08-31";
format = "other";
src = fetchFromGitHub {
owner = "msmarkgu";
repo = "RelayFreeLLM";
rev = "9a1aabe1905ac1d6b3d48ac492089a0ea9668388";
hash = "sha256-DjHaskOW28g9BEI1TbMwuDgcEH4++VEMmXUzpqZ9KMc=";
};
nativeBuildInputs = [ makeWrapper ];
propagatedBuildInputs = pyDeps;
installPhase = ''
runHook preInstall
mkdir -p $out/lib/relay-free-llm
cp -r src $out/lib/relay-free-llm/
runHook postInstall
'';
postInstall = ''
makeWrapper ${python3Packages.python.interpreter} $out/bin/relay-free-llm \
--add-flags "-m src.server" \
--prefix PYTHONPATH : "$out/lib/relay-free-llm:$PYTHONPATH"
'';
doCheck = false;
passthru = {
category = "AI LLM Gateway";
updateScript = [
"nix-update"
"--flake"
".#relay-free-llm"
"--version=branch=main"
];
};
meta = {
description = "RESTful API to route user prompts to various AI model providers";
homepage = "https://github.com/msmarkgu/RelayFreeLLM";
license = lib.licenses.mit;
mainProgram = "relay-free-llm";
platforms = lib.platforms.all;
};
}
+1
View File
@@ -0,0 +1 @@
{ pkgs, ... }: pkgs.callPackage ./package.nix { }
+53
View File
@@ -0,0 +1,53 @@
{
lib,
python3Packages,
fetchFromGitHub,
}:
python3Packages.buildPythonApplication {
pname = "skillsmcp";
# Pinned to a commit rather than a release tag because upstream
# has not yet published a tagged release containing all features.
version = "0.2.0+unstable";
pyproject = true;
src = fetchFromGitHub {
owner = "aviddiviner";
repo = "skillsmcp";
rev = "4b1d1b0ad270ef5b8cb3c9024c276ccaf512c6d9";
hash = "sha256-xS2XEaAmIdYgNTVwJPfpcrQfqhcppO7FEguPwhfKgW4=";
};
build-system = with python3Packages; [
hatchling
];
dependencies = [
python3Packages.fastmcp
python3Packages.pyyaml
];
# Tests fail due to version-string expectations baked into the upstream
# source (pinned to a commit rather than a release tag). The import
# check below still verifies the module loads correctly.
doCheck = false;
pythonImportsCheck = [ "skillsmcp" ];
passthru = {
category = "MCP Servers";
updateScript = [
"nix-update"
"--flake"
".#skillsmcp"
"--version=branch=main"
];
};
meta = {
description = "MCP server that exposes Agent Skills to AI agents via the Model Context Protocol";
homepage = "https://github.com/aviddiviner/skillsmcp";
license = lib.licenses.mit;
mainProgram = "skillsmcp";
platforms = lib.platforms.all;
};
}
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+41
View File
@@ -0,0 +1,41 @@
{
lib,
rustPlatform,
fetchFromGitHub,
pkg-config,
openssl,
}:
rustPlatform.buildRustPackage rec {
pname = "stakpak";
version = "0.3.88";
src = fetchFromGitHub {
owner = "stakpak";
repo = "agent";
rev = "v${version}";
hash = "sha256-rTqRxfAFQChA5fjW5VVxGThH0X7OodF1SdviMd3dK78=";
};
cargoHash = "sha256-jf0PqcoNtfdcDNayPNVNeWNaa0acuUJeb3CYLKN6VeA=";
nativeBuildInputs = [ pkg-config ];
buildInputs = [
openssl
];
doCheck = false;
passthru.category = "AI Agents";
meta = with lib; {
description = "DevOps AI agent that generates infrastructure code, debugs Kubernetes, configures CI/CD, and automates deployments";
homepage = "https://stakpak.io";
changelog = "https://github.com/stakpak/agent/releases/tag/v${version}";
license = licenses.asl20;
sourceProvenance = with sourceTypes; [ fromSource ];
mainProgram = "stakpak";
platforms = platforms.all;
};
}
+1
View File
@@ -0,0 +1 @@
{ pkgs, ... }: pkgs.callPackage ./package.nix { }
+56
View File
@@ -0,0 +1,56 @@
{
lib,
appimageTools,
fetchurl,
}:
let
version = "1.3.0";
src = fetchurl {
url = "https://github.com/traycerai/traycer/releases/download/desktop-v${version}/traycer-desktop-linux-x86_64.AppImage";
hash = "sha256-iDpbpDpd0OeRGTKwUVRYiIpRSltnAIb59W+yIfH8HFU=";
};
appimageContents = appimageTools.extractType2 {
pname = "traycer";
inherit version src;
};
in
appimageTools.wrapType2 {
pname = "traycer";
inherit version src;
extraPkgs = pkgsWith: [
pkgsWith.gtk3
pkgsWith.glib
];
extraInstallCommands = ''
mkdir -p $out/share/applications
install -m 444 ${appimageContents}/traycer-desktop.desktop $out/share/applications/traycer.desktop
substituteInPlace $out/share/applications/traycer.desktop \
--replace-fail 'Exec=AppRun --no-sandbox %U' 'Exec=traycer --no-sandbox %U'
mkdir -p $out/share/icons/hicolor
cp -r ${appimageContents}/usr/share/icons/hicolor/* $out/share/icons/hicolor/
'';
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#traycer"
];
};
meta = {
description = "Open-source AI orchestration app for agentic coding";
homepage = "https://github.com/traycerai/traycer";
license = lib.licenses.mit;
maintainers = [ ];
platforms = [ "x86_64-linux" ];
mainProgram = "traycer";
sourceProvenance = [ lib.sourceTypes.binaryNativeCode ];
};
}
+11
View File
@@ -0,0 +1,11 @@
{
"version": 1,
"skills": {
"karpathy-guidelines": {
"source": "szkocot/andrej-karpathy-skills",
"sourceType": "github",
"skillPath": "skills/karpathy-guidelines/SKILL.md",
"computedHash": "41e8ca055bbde13d240776a14a076a59614057200340c243130a76ba4e64cac8"
}
}
}
+6
View File
@@ -0,0 +1,6 @@
[global]
excluded = ["flake.lock"]
[formatter.nix]
command = "nixfmt"
includes = ["*.nix"]