Files
millerson-overlay.nix/README.md
Alexander Miroshnichenko d74788a4cb feat(packages): Add marmel autonomous coding agent
Pin Na1w/marmel to commit fd551ae. Upstream publishes no tags or
releases, so the version uses the shape nix-update generates for a
tagless repository, keeping `nix-update --version=branch=main` usable.

The test suite runs green (325 lib tests plus all integration suites)
with two accommodations, both documented in the derivation:

- Export SSL_CERT_FILE from nixpkgs cacert. rustls refuses to construct
  a reqwest::Client without a system trust store, which failed 38 tests
  with "No CA certificates were loaded from the system".
- Serialise the test harness. The lib suite shares process-global worker
  registries and steer/abort buses, so manager-loop tests fail
  nondeterministically on parallel threads: one unchanged derivation
  produced 3 failures, then 1 failure, then 0 with --test-threads=1.
  No test is skipped or filtered.

Annotated example configs are installed to share/doc/marmel/examples/.
Role prompts are embedded via include_str!, so there is no runtime data
directory. Upstream README states MIT but ships no LICENSE file and no
Cargo.toml license field.
2026-09-14 12:31:39 +03:00

8.5 KiB

millerson.name Nix Overlay

A custom Nix overlay and flake providing additional packages not found in upstream nixpkgs, built using numtide/blueprint for streamlined flake development.

Features

  • Custom packages - Additional software packaged for Nix
  • Two overlay strategies - Choose between binary-cache-friendly or dependency-sharing overlays
  • Blueprint-based - Uses modern Nix flake patterns with numtide/blueprint

Available Packages

Package Description Category
awg-tool CLI for AmneziaWG self-hosting — generates 1.0/1.5/2.0/3.0 obfuscation parameters, exports .conf and vpn:// configs, installs servers over SSH Networking
aionui Free, open-source, Cowork app with AI Agents AI Coding Agents
container-use Containerized environments for coding agents AI Coding Agents
desloppify Multi-language codebase health scanner and technical debt tracker for AI agents AI Coding Agents
ds4 DeepSeek 4 Flash and PRO local inference engine for ROCm (Strix Halo) AI Inference
freebuff The world's strongest free coding agent AI Coding Agents
freetoken Local MoE-offload LLM inference runtime with OpenAI- and Anthropic-compatible APIs AI Inference
graphify Turn any folder of code, docs, papers, images, or videos into a queryable knowledge graph AI Coding Agents
haivemind Multi-model AI consensus, aggregation, and fusion runner for popular AI CLIs AI Coding Agents
hipengine ROCm-native local LLM inference engine with torch-free runtime for AMD RDNA GPUs AI Inference
marmel Autonomous agentic coding assistant with Manager + specialist subagent orchestration over any OpenAI-compatible LLM backend AI Coding Agents
mcp-gateway Universal Model Context Protocol gateway that sits between AI client and MCP tools/servers MCP Servers
nftables-analyzer Analyze nftables firewall rules and evaluate traffic queries Networking
nftablesbuilder Web interface to manage nftables rules with drag-and-drop rule creation Networking
skillsmcp MCP server that exposes Agent Skills to AI agents via the Model Context Protocol MCP Servers
kubernetes-mcp-server Model Context Protocol (MCP) server for Kubernetes and OpenShift MCP Servers
llama-cpp llama.cpp pinned to build b9645, built for Strix Halo (gfx1151) with ROCm + Vulkan backends AI Inference
loop Corporate messenger for your team Communication
radar Modern Kubernetes visibility — topology, event timeline, service traffic, resource browsing, Helm management, and GitOps support Kubernetes
omniroute Unified AI router with 160+ providers, auto fallback, MCP/A2A, OpenAI-compatible APIs AI LLM Gateway
relay-free-llm RESTful API to route user prompts to various AI model providers with automatic failover and intent-based routing AI LLM Gateway
stakpak DevOps AI agent that generates infrastructure code, debugs Kubernetes, configures CI/CD, and automates deployments AI Agents
traycer Open-source AI orchestration app for agentic coding AI Coding Agents

Usage

As a Flake

Add to your flake.nix inputs:

inputs.millerson-nix-overlay.url = "git+https://git.millerson.name/alex/millerson-overlay.nix.git";

Then use in your outputs:

outputs = { nixpkgs, millerson-nix-overlay, ... }: {
  nixosConfigurations.your-host = nixpkgs.lib.nixosSystem {
    system = "x86_64-linux";
    modules = [
      millerson-nix-overlay.nixosModules.default
      # ... your other modules
    ];
  };
};

As an Overlay

Option 1: Default Overlay (Binary Cache Friendly)

Uses the packages built against this flake's nixpkgs revision. Binary cache hits work best when using the same nixpkgs revision.

nixpkgs.overlays = [ millerson-nix-overlay.overlays.default ];

Option 2: Shared Nixpkgs Overlay (Dependency Sharing)

Builds packages against your system's nixpkgs, sharing dependencies with the rest of your system. No second nixpkgs evaluation, but binary cache only hits when your nixpkgs revision matches ours.

nixpkgs.overlays = [ millerson-nix-overlay.overlays.shared-nixpkgs ];

Installing Packages

With flakes enabled:

# Try a package
nix run git+https://git.millerson.name/alex/millerson-overlay.nix.git#mcp-gateway

# Install permanently
nix profile install git+https://git.millerson.name/alex/millerson-overlay.nix.git#mcp-gateway

nftablesbuilder Runtime Notes

nftablesbuilder is a web interface for managing nftables. It consists of a root-launcher (nftablesbuilder) that spawns the unprivileged webserver binary and pipes encrypted commands between it and the nft binary.

Before running it you must:

  1. Copy the settings template to /etc/nftablesbuilder (the only fixed path):
    nix build .#nftablesbuilder
    cp result/share/nftablesbuilder/settings.example /etc/nftablesbuilder
    
    Adjust paths inside (html, webserver, nft, savepath, TLS files).
  2. Create a TLS key/certificate pair at the paths referenced by tlskey/tlscert (e.g. openssl req -x509 -newkey rsa:2048 -nodes ...).
  3. Run the launcher as root (it needs to write /etc/nftables.conf and run nft); the web interface listens on https://<server>:1969.

Note: upstream publishes the GUI only as a prebuilt tarball on nftablesbuilder.eu (served with a self-signed certificate, hence the curlOpts = "-k" in the derivation); the source repository is missing the settings crate, which this overlay patches in.

Development

Prerequisites

  • Nix with flakes enabled
  • treefmt-nix for formatting (optional)

Building Packages

# Build all packages for current system
nix build .#packages

# Build specific package
nix build .#mcp-gateway

# Enter development shell
nix develop

Project Structure

nix-overlay/
├── flake.nix                    # Flake definition
├── treefmt.toml                 # Code formatting configuration (nixfmt)
├── overlays/                    # Overlay implementations
│   ├── default.nix             # Binary-cache-friendly overlay
│   └── shared-nixpkgs.nix      # Dependency-sharing overlay
├── packages/                    # Package definitions
│   ├── awg-tool/               # AmneziaWG parameter generation and SSH deployment CLI
│   ├── aionui/                 # AionUi - AI Cowork desktop app
│   ├── container-use/          # Containerized environments for coding agents
│   ├── default/                # Meta-package listing all packages
│   ├── desloppify/             # Codebase health scanner for AI agents
│   ├── ds4/                    # DeepSeek V4 Flash/PRO inference engine (ROCm)
│   ├── flake-inputs/           # Utility for caching flake inputs
│   ├── freebuff/               # Free coding agent (Codebuff)
│   ├── freetoken/             # Local MoE inference runtime (NVIDIA CUDA)
│   ├── graphify/               # Knowledge graph generator for code folders
│   ├── haivemind/              # Multi-model AI consensus runner
│   ├── hipengine/              # ROCm-native LLM inference engine for AMD GPUs
│   ├── kubernetes-mcp-server/  # MCP server for Kubernetes and OpenShift
│   ├── loop/                   # Corporate messenger for your team
│   ├── mcp-gateway/            # MCP protocol gateway
│   ├── omniroute/              # Unified AI router with 160+ providers
│   ├── radar/                  # Kubernetes UI (topology, timeline, Helm, GitOps)
│   ├── relay-free-llm/        # AI model provider routing gateway
│   ├── skillsmcp/              # MCP server for Agent Skills
│   ├── stakpak/                # DevOps AI agent for infrastructure automation
│   └── traycer/                 # AI orchestration desktop app (agentic coding)
└── README.md

Adding New Packages

  1. Create a new directory under packages/<package-name>/
  2. Add a package.nix with the package definition
  3. Create a default.nix that imports package.nix with proper arguments
  4. The package will be automatically picked up by blueprint

Example structure:

packages/my-package/
├── default.nix    # Import wrapper
└── package.nix    # Actual package definition

License

See LICENSE file for details.

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.