<feed xmlns='http://www.w3.org/2005/Atom'>
<title>nixos-config/machines/kusanagi/default.nix, branch main</title>
<subtitle>my nixos setup</subtitle>
<id>https://git.hwebs.info/nixos-config/atom?h=main</id>
<link rel='self' href='https://git.hwebs.info/nixos-config/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/'/>
<updated>2026-08-04T23:36:13Z</updated>
<entry>
<title>kusanagi: constrain ollama resources</title>
<updated>2026-08-04T23:36:13Z</updated>
<author>
<name>Henry J Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T22:54:11Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=790f353742ecf73eb71944d5f6c17ecfaad6a75c'/>
<id>urn:sha1:790f353742ecf73eb71944d5f6c17ecfaad6a75c</id>
<content type='text'>
laguna-xs-2.1 is large enough to nearly fill the workstation's display GPU at the previous 64k context and 1h keep-alive. That let Ollama keep a very large resident set around after requests and could destabilize the no-swap desktop session.

Unload models quicker, limit parallelism/queueing, reserve VRAM for the compositor, and cap the service cgroup so runaway requests fail before the desktop does.

Assisted-by: pi:gpt-5.5
</content>
</entry>
<entry>
<title>networking: expose Ollama and mDNS on Wi-Fi LAN</title>
<updated>2026-08-04T22:14:09Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T22:10:10Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=a4c50351f5d55438a102d48c63dcbb62f9ef5e8d'/>
<id>urn:sha1:a4c50351f5d55438a102d48c63dcbb62f9ef5e8d</id>
<content type='text'>
Serve Ollama on kusanagi's Wi-Fi LAN while removing the blanket tailscale0 firewall trust so tailnet traffic follows explicit host firewall rules instead of inheriting every listening service.

Add shared LAN networking for both hosts: allow ping, publish and resolve .local names with Avahi, and scope mDNS to each machine's declared Wi-Fi interface.

Assisted-by: OpenAI:gpt-5
</content>
</entry>
<entry>
<title>kusanagi/ollama: double default context, add 1h keep-alive</title>
<updated>2026-08-04T21:05:20Z</updated>
<author>
<name>Henry J Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T05:02:54Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=df960b2ed92f9e45fc4984d19ab65c55074bb1d7'/>
<id>urn:sha1:df960b2ed92f9e45fc4984d19ab65c55074bb1d7</id>
<content type='text'>
The 12B model at 32k context uses only 7.7 GB of the 7900 XT's 20 GB, so
there is ample VRAM headroom for 64k with the q8_0 KV cache — agentic
coding tools are context-hungry and 32k is the practical bottleneck.
The keep-alive stops the default 5-minute idle unload from adding a
reload stall to every resumed session on a single-user workstation.

Update flake to get newer packages.

Assisted-by: Claude Code:claude-fable-5
</content>
</entry>
<entry>
<title>kusanagi/ollama: fix boot race with amdgpu, drop misdiagnosed HSA override</title>
<updated>2026-08-04T03:51:26Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T03:51:26Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=9acf89a3af3fd4c354fcd887397b0c035bb21494'/>
<id>urn:sha1:9acf89a3af3fd4c354fcd887397b0c035bb21494</id>
<content type='text'>
The recurring "ollama runs 100% on CPU" regressions were a boot-order
race, not a gfx-target mismatch: ollama.service only ordered after
network.target, and at boot it started between /dev/kfd and the 7900
XT's render node appearing. ollama probes GPUs once at startup, found
none, and silently fell back to CPU until the next manual restart —
which is why the previous HSA_OVERRIDE_GFX_VERSION commit "worked": the
deploy restarted the service on a long-running system, and the restart
was the actual cure.

The card is a 7900 XT (Navi 31), natively gfx1100 — verified that
discovery with no overrides finds it fine and drops only the
unsupported Raphael iGPU (gfx1036). Remove HSA_OVERRIDE_GFX_VERSION and
HIP_VISIBLE_DEVICES (ollama itself warns overriding visible devices can
break discovery).

Real fix: systemd-tag the kfd/renderD* char devices via udev (they get
no device units otherwise) and order ollama after them, so discovery
only runs once the GPU exists.

Assisted-by: claude-code:claude-fable-5
</content>
</entry>
<entry>
<title>profiles: extract shared sandbox profile for enzo + kusanagi</title>
<updated>2026-08-04T03:12:32Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T03:00:49Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=3df910d75fa98a7d0291e6b8c6889905c6088f64'/>
<id>urn:sha1:3df910d75fa98a7d0291e6b8c6889905c6088f64</id>
<content type='text'>
Move the yokai agent-sandbox account (user, ikai group, /srv/git drop dir,
scoped sudo de-escalation, and the local-clones workflow docs) out of
machines/enzo into a shared profiles/sandbox.nix that both machines import.

The only per-machine value is the human owner allowed to drop into the
sandbox, exposed as a `sandbox.owner` string option so the profile stays
username-agnostic (enzo: hwebs, kusanagi: henz). kusanagi gains the sandbox
it didn't have before; enzo's inline block collapses to one setting.

Assisted-by: claude-code:claude-opus-4-8
</content>
</entry>
<entry>
<title>kusanagi/ollama: fix ROCm GPU fallback to CPU for Gemma</title>
<updated>2026-08-04T02:39:51Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T02:38:08Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=71e36370770acc7498748a890cd0365b3d351027'/>
<id>urn:sha1:71e36370770acc7498748a890cd0365b3d351027</id>
<content type='text'>
The RDNA3 card reports as gfx1101/gfx1102/gfx11-generic, which the ROCm
build bundled with ollama-rocm has no kernels for, so ollama found no
usable device and ran 100% on CPU after the nixpkgs bump. Force it to
present as gfx1100 via HSA_OVERRIDE_GFX_VERSION.

Also set OLLAMA_FLASH_ATTENTION=1 so the existing q8_0 KV cache actually
engages instead of silently falling back to f16 and inflating VRAM use.

Assisted-by: Claude-code:Opus-4.8
</content>
</entry>
<entry>
<title>migration away from x-clip</title>
<updated>2026-08-03T18:01:21Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-03T17:59:24Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=9ca21e94b8ade285e749d54441c7d9115da5b522'/>
<id>urn:sha1:9ca21e94b8ade285e749d54441c7d9115da5b522</id>
<content type='text'>
- replace x-clip with wl-clipboard for wayland machines
- add TODOs I noticed while editing

Assisted-by: Claude Code:claude-opus-4-8
</content>
</entry>
<entry>
<title>kusanagi: remove non-working hiberation</title>
<updated>2026-08-01T15:18:25Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-01T15:16:21Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=eb80a670dfcc78afd2a9459eb5515027b78cc736'/>
<id>urn:sha1:eb80a670dfcc78afd2a9459eb5515027b78cc736</id>
<content type='text'>
Assisted-by: Claude:Opus-4.8
</content>
</entry>
<entry>
<title>enzo/kusanagi: idle suspend via swayidle</title>
<updated>2026-07-31T03:47:58Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-07-31T03:47:58Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=ac7152a1c531e611955861e3fc736e8f55039721'/>
<id>urn:sha1:ac7152a1c531e611955861e3fc736e8f55039721</id>
<content type='text'>
Bare niri has no power daemon watching for inactivity, so neither box
slept on its own. Add a user swayidle service bound to
graphical-session.target that fires after 15 min of no input:

  - enzo: suspend-then-hibernate (matches the existing lid-switch policy)
  - kusanagi: plain suspend-to-RAM, plus Wake-on-LAN on enp9s0 so it can
    be woken remotely while the Kavita/Immich/Ollama/NFS servers sleep

Assisted-by: Claude:claude-opus-4-8
</content>
</entry>
<entry>
<title>refactor: shared desktop profile for enzo + kusanagi</title>
<updated>2026-07-31T00:14:09Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-07-31T00:14:09Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=ae5ecbb4199844b2b7883d99cd04ef468a03247d'/>
<id>urn:sha1:ae5ecbb4199844b2b7883d99cd04ef468a03247d</id>
<content type='text'>
profiles/desktop.nix becomes a username-agnostic shared base (niri, dconf, the
dark-theme portal fix, greetd, pipewire base, gpg agent, graphics, Firefox with
blank-home/no-bookmarks prefs, common desktop tools, font base). Both hosts now
import it.

Per-host desktop config splits into machines/&lt;host&gt;/desktop.nix:
- enzo: Adwaita cursor + monospace, HiDPI console font, yambar, hwebs groups.
- kusanagi (new file): GNOME/X11, printing/avahi/udisks2, pro-audio
  (rtkit/jack/32-bit), gpg ssh support, richer fonts, Bibata cursor, henz
  desktop groups, waybar/nm-applet.

Shared profile is username-agnostic (enzo=hwebs, kusanagi=henz): shared desktop
tools moved to environment.systemPackages, per-user groups stay in machine
files. Firefox now owned by the shared profile, so its redundant enable is
dropped from profiles/apps.nix. Dark theme + Firefox tweaks now apply to both
hosts. Both configurations build.

Assisted-by: Claude:claude-opus-4-8
</content>
</entry>
</feed>
