<feed xmlns='http://www.w3.org/2005/Atom'>
<title>nixos-config/machines, branch kusanagi-ollama-lan-firewall</title>
<subtitle>my nixos setup</subtitle>
<id>https://git.hwebs.info/nixos-config/atom?h=kusanagi-ollama-lan-firewall</id>
<link rel='self' href='https://git.hwebs.info/nixos-config/atom?h=kusanagi-ollama-lan-firewall'/>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/'/>
<updated>2026-08-04T22:05:42Z</updated>
<entry>
<title>common: parameterize LAN discovery interface</title>
<updated>2026-08-04T22:05:42Z</updated>
<author>
<name>yokai</name>
<email>accounts.8ef6c@simplelogin.com</email>
</author>
<published>2026-08-04T22:05:42Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=a7adbd5063fe7ab428d8174cb9b31bec2c6133d6'/>
<id>urn:sha1:a7adbd5063fe7ab428d8174cb9b31bec2c6133d6</id>
<content type='text'>
Let the shared LAN discovery module use each host's Wi-Fi interface instead of assuming kusanagi's wlp8s0 everywhere. Set kusanagi to wlp8s0 and enzo to wlp1s0.

Reuse the same setting for kusanagi's Ollama LAN firewall rule so the service opening stays tied to the declared LAN interface.

Assisted-by: OpenAI:gpt-5
</content>
</entry>
<entry>
<title>common: share LAN discovery settings</title>
<updated>2026-08-04T21:58:39Z</updated>
<author>
<name>yokai</name>
<email>accounts.8ef6c@simplelogin.com</email>
</author>
<published>2026-08-04T21:58:39Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=b47ca1475decf1a98f10231f0cbeebfb75e7f6ea'/>
<id>urn:sha1:b47ca1475decf1a98f10231f0cbeebfb75e7f6ea</id>
<content type='text'>
Move ping and Avahi/mDNS configuration into a shared LAN discovery module so kusanagi and enzo both publish their .local names, resolve each other on the LAN, and answer ping.

Keep mDNS scoped to the shared Wi-Fi interface instead of using Avahi's global firewall helper.

Assisted-by: OpenAI:gpt-5
</content>
</entry>
<entry>
<title>enzo: enable mDNS resolution for *.local LAN names</title>
<updated>2026-08-04T21:49:01Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T21:38:36Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=b9fd1ff561be58fa9d0fa03180a1a239e47550b5'/>
<id>urn:sha1:b9fd1ff561be58fa9d0fa03180a1a239e47550b5</id>
<content type='text'>
Kusanagi already advertises its hostname via Avahi, but enzo had no
multicast DNS resolver configured so kusanagi.local never resolved from
the laptop. Add avahi with nssmdns4 so the NSS host lookup chain
delegates to mDNS before giving up.

Assisted-by: pi-coding-agent:gpt-5.2
(cherry picked from commit beb8eedfb712fd31c456096a2426d92cb3a7fcff)
</content>
</entry>
<entry>
<title>kusanagi/mdns: publish workstation on wifi LAN</title>
<updated>2026-08-04T21:45:39Z</updated>
<author>
<name>yokai</name>
<email>accounts.8ef6c@simplelogin.com</email>
</author>
<published>2026-08-04T21:45:39Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=ab57d8eae597938e63f06ff9b356548bcd8ce0bd'/>
<id>urn:sha1:ab57d8eae597938e63f06ff9b356548bcd8ce0bd</id>
<content type='text'>
Advertise kusanagi.local via Avahi on the Wi-Fi interface so LAN clients can use a stable local name instead of the current IP address.

Keep Avahi's firewall hole scoped to wlp8s0 by disabling the module's global openFirewall helper and opening UDP 5353 on that interface explicitly.

Assisted-by: OpenAI:gpt-5
</content>
</entry>
<entry>
<title>kusanagi/ollama: expose service on wifi LAN</title>
<updated>2026-08-04T21:31:11Z</updated>
<author>
<name>yokai</name>
<email>accounts.8ef6c@simplelogin.com</email>
</author>
<published>2026-08-04T21:31:11Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=04889e646cc83865ac1da1cdfc42e5a956c2cf30'/>
<id>urn:sha1:04889e646cc83865ac1da1cdfc42e5a956c2cf30</id>
<content type='text'>
Bind Ollama on all interfaces but open its API only on kusanagi's Wi-Fi interface, so LAN clients can reach it without relying on Tailscale exposure.

Remove the blanket tailscale0 trust from the shared firewall so tailnet traffic follows explicit host firewall rules instead of inheriting access to every listening service.

Assisted-by: OpenAI:gpt-5
</content>
</entry>
<entry>
<title>kusanagi/ollama: double default context, add 1h keep-alive</title>
<updated>2026-08-04T21:05:20Z</updated>
<author>
<name>Henry J Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T05:02:54Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=df960b2ed92f9e45fc4984d19ab65c55074bb1d7'/>
<id>urn:sha1:df960b2ed92f9e45fc4984d19ab65c55074bb1d7</id>
<content type='text'>
The 12B model at 32k context uses only 7.7 GB of the 7900 XT's 20 GB, so
there is ample VRAM headroom for 64k with the q8_0 KV cache — agentic
coding tools are context-hungry and 32k is the practical bottleneck.
The keep-alive stops the default 5-minute idle unload from adding a
reload stall to every resumed session on a single-user workstation.

Update flake to get newer packages.

Assisted-by: Claude Code:claude-fable-5
</content>
</entry>
<entry>
<title>kusanagi/ollama: fix boot race with amdgpu, drop misdiagnosed HSA override</title>
<updated>2026-08-04T03:51:26Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T03:51:26Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=9acf89a3af3fd4c354fcd887397b0c035bb21494'/>
<id>urn:sha1:9acf89a3af3fd4c354fcd887397b0c035bb21494</id>
<content type='text'>
The recurring "ollama runs 100% on CPU" regressions were a boot-order
race, not a gfx-target mismatch: ollama.service only ordered after
network.target, and at boot it started between /dev/kfd and the 7900
XT's render node appearing. ollama probes GPUs once at startup, found
none, and silently fell back to CPU until the next manual restart —
which is why the previous HSA_OVERRIDE_GFX_VERSION commit "worked": the
deploy restarted the service on a long-running system, and the restart
was the actual cure.

The card is a 7900 XT (Navi 31), natively gfx1100 — verified that
discovery with no overrides finds it fine and drops only the
unsupported Raphael iGPU (gfx1036). Remove HSA_OVERRIDE_GFX_VERSION and
HIP_VISIBLE_DEVICES (ollama itself warns overriding visible devices can
break discovery).

Real fix: systemd-tag the kfd/renderD* char devices via udev (they get
no device units otherwise) and order ollama after them, so discovery
only runs once the GPU exists.

Assisted-by: claude-code:claude-fable-5
</content>
</entry>
<entry>
<title>profiles: extract shared sandbox profile for enzo + kusanagi</title>
<updated>2026-08-04T03:12:32Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T03:00:49Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=3df910d75fa98a7d0291e6b8c6889905c6088f64'/>
<id>urn:sha1:3df910d75fa98a7d0291e6b8c6889905c6088f64</id>
<content type='text'>
Move the yokai agent-sandbox account (user, ikai group, /srv/git drop dir,
scoped sudo de-escalation, and the local-clones workflow docs) out of
machines/enzo into a shared profiles/sandbox.nix that both machines import.

The only per-machine value is the human owner allowed to drop into the
sandbox, exposed as a `sandbox.owner` string option so the profile stays
username-agnostic (enzo: hwebs, kusanagi: henz). kusanagi gains the sandbox
it didn't have before; enzo's inline block collapses to one setting.

Assisted-by: claude-code:claude-opus-4-8
</content>
</entry>
<entry>
<title>kusanagi/ollama: fix ROCm GPU fallback to CPU for Gemma</title>
<updated>2026-08-04T02:39:51Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T02:38:08Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=71e36370770acc7498748a890cd0365b3d351027'/>
<id>urn:sha1:71e36370770acc7498748a890cd0365b3d351027</id>
<content type='text'>
The RDNA3 card reports as gfx1101/gfx1102/gfx11-generic, which the ROCm
build bundled with ollama-rocm has no kernels for, so ollama found no
usable device and ran 100% on CPU after the nixpkgs bump. Force it to
present as gfx1100 via HSA_OVERRIDE_GFX_VERSION.

Also set OLLAMA_FLASH_ATTENTION=1 so the existing q8_0 KV cache actually
engages instead of silently falling back to f16 and inflating VRAM use.

Assisted-by: Claude-code:Opus-4.8
</content>
</entry>
<entry>
<title>enzo: add yokai sandbox user for coding agents</title>
<updated>2026-08-04T00:44:07Z</updated>
<author>
<name>Henry J. Webster</name>
<email>hwebs@hwebs.info</email>
</author>
<published>2026-08-04T00:44:07Z</published>
<link rel='alternate' type='text/html' href='https://git.hwebs.info/nixos-config/commit/?id=e9b9671d238bb3de779c0dbf4a518b41280be778'/>
<id>urn:sha1:e9b9671d238bb3de779c0dbf4a518b41280be778</id>
<content type='text'>
Add a bare `yokai` user (primary group `ikai`) for running coding agents
under a separate UID, isolated from hwebs's files and secrets. yokai has
no privileged group memberships and its own $HOME.

- systemd.tmpfiles creates /srv/git (2770 root:ikai) as a drop dir for the
  agent's local clones, outside ~ so /home/hwebs stays a sealed 700.
- security.sudo lets hwebs drop to yokai without a password (de-escalation
  only, scoped to runAs=yokai; root stays gated).
- hwebs joins the ikai group.

Extensive comments document the local-clones model: yokai owns its clone,
hwebs never runs git inside it, and commits are exchanged by fetching (or
via bundles) and landed on main with squash/rebase/interactive + signing.

Assisted-by: claude-code:claude-opus-4-8
</content>
</entry>
</feed>
