diff --git a/claude-md/machines/default.md b/claude-md/machines/default.md new file mode 100644 index 0000000..f9f9af4 --- /dev/null +++ b/claude-md/machines/default.md @@ -0,0 +1,9 @@ +## Environment + +- No passwordless root. There is no stored root password — if something needs + `sudo`, ask me and I will run it or type the password myself. +- Ask before installing system packages. Project-local dependencies are fine. +- This is a personal workstation, not a sandbox: treat destructive or + outward-facing actions as needing confirmation, and prefer reversible steps. +- Dev servers may bind localhost; nothing needs to be reachable from the LAN + unless I say so. diff --git a/claude-md/machines/yolo.md b/claude-md/machines/yolo.md new file mode 100644 index 0000000..1690bb0 --- /dev/null +++ b/claude-md/machines/yolo.md @@ -0,0 +1,11 @@ +## Environment + +- Root password: `$SANDBOX_PASSWORD`, already exported from `~/.env.claude` in every shell. Use `printf '%s\n' "$SANDBOX_PASSWORD" | sudo -S `. Never echo or print the value. +- Can install packages as needed using sudo +- This machine communicates with external services — treat it as a networked environment +- **This is a VM accessed from other devices.** When starting any dev server / web service / preview, always bind to `0.0.0.0` (e.g. `vite --host 0.0.0.0`, `--host`, `HOST=0.0.0.0`) — never localhost-only — so it's reachable. Report the LAN-IP URL, not the `localhost` one. + +## Persistent Configuration + +- Environment file: `~/.env.claude` (auto-loaded in shell sessions) +- For Claude sessions, source it manually if needed: `source ~/.env.claude` diff --git a/entry/CLAUDE.md b/entry/CLAUDE.md index 4d88a25..b9d4f9a 100644 --- a/entry/CLAUDE.md +++ b/entry/CLAUDE.md @@ -1,14 +1,6 @@ # Global Context -## Environment -- Root password: `$SANDBOX_PASSWORD`, already exported from `~/.env.claude` in every shell. Use `printf '%s\n' "$SANDBOX_PASSWORD" | sudo -S `. Never echo or print the value. -- Can install packages as needed using sudo -- This machine communicates with external services — treat it as a networked environment -- **This is a VM accessed from other devices.** When starting any dev server / web service / preview, always bind to `0.0.0.0` (e.g. `vite --host 0.0.0.0`, `--host`, `HOST=0.0.0.0`) — never localhost-only — so it's reachable. Report the LAN-IP URL, not the `localhost` one. - -## Persistent Configuration -- Environment file: `~/.env.claude` (auto-loaded in shell sessions) -- For Claude sessions, source it manually if needed: `source ~/.env.claude` +@~/.claude/machine.md ## Browser automation - Use the `agent-browser` CLI (headless, via Bash) for anything browser-shaped: checking pages, dev servers, screenshots, form flows, console/eval. `agent-browser --help` lists commands; `snapshot` gives an accessibility tree with refs for AI use. @@ -24,7 +16,7 @@ just a URL — never start crit or any per-review server for code diffs. - Global hooks do the plumbing: SessionStart injects the review URL and full instructions in any rev-known repo, and a Stop hook prompts to (re)arm the - comment watcher (`~/tea/yolo/rev/scripts/rev-watch.sh `, background). + comment watcher (`~/tea/rev/scripts/rev-watch.sh `, background). Follow the injected instructions; there is nothing to set up. - The watcher is plumbing: arm and re-arm it silently, never announce its state (armed, exited, re-armed) in chat. diff --git a/nix/home.nix b/nix/home.nix index 6fb080f..b871c90 100644 --- a/nix/home.nix +++ b/nix/home.nix @@ -3,17 +3,45 @@ # # inputs.agent-skills.url = "git+https://git.naps.pt/yolo/agent-skills.git"; # # in home.nix imports: inputs.agent-skills.homeModules.default +# # and pick a machine profile: +# programs.agentSkills.machine = "yolo"; # # recursive=true links each FILE individually, so machine-local skills can still # live alongside the managed ones in the same dir (a whole-dir symlink would not). { agent-skills }: -{ ... }: +{ config, lib, ... }: +let + cfg = config.programs.agentSkills; +in { - home.file = { - ".claude/skills" = { source = "${agent-skills}/skills"; recursive = true; }; - ".agents/skills" = { source = "${agent-skills}/skills"; recursive = true; }; - ".claude/commands" = { source = "${agent-skills}/commands"; recursive = true; }; - ".claude/hooks" = { source = "${agent-skills}/hooks"; recursive = true; }; + options.programs.agentSkills.machine = lib.mkOption { + type = lib.types.str; + default = "default"; + example = "yolo"; + description = '' + Which claude-md/machines/.md to link as ~/.claude/machine.md. + The shared entry file @imports it, so it always has to resolve; the + "default" profile is the conservative one (no passwordless root). + ''; + }; + + config.home.file = { + ".claude/skills" = { + source = "${agent-skills}/skills"; + recursive = true; + }; + ".agents/skills" = { + source = "${agent-skills}/skills"; + recursive = true; + }; + ".claude/commands" = { + source = "${agent-skills}/commands"; + recursive = true; + }; + ".claude/hooks" = { + source = "${agent-skills}/hooks"; + recursive = true; + }; # CLAUDE.md fragments land in ~/.claude root, pulled in by `@name.md` imports. # Listed one by one: recursive on ~/.claude would fight every other tool @@ -21,6 +49,9 @@ ".claude/writing.md".source = "${agent-skills}/claude-md/writing.md"; ".claude/operating.md".source = "${agent-skills}/claude-md/operating.md"; + # Per-machine section: what this box permits (sudo, network exposure). + ".claude/machine.md".source = "${agent-skills}/claude-md/machines/${cfg.machine}.md"; + # Path-scoped: loads only when Claude reads a matching source file. ".claude/rules/code-comments.md".source = "${agent-skills}/claude-md/code-comments.md"; ".claude/RTK.md".source = "${agent-skills}/claude-md/RTK.md"; @@ -28,7 +59,6 @@ # Entry files: machine-local sections + @imports of the fragments above. ".claude/CLAUDE.md".source = "${agent-skills}/entry/CLAUDE.md"; ".codex/AGENTS.md".source = "${agent-skills}/entry/codex-AGENTS.md"; - }; } # Hook wiring lives in ~/.claude/settings.json, which this module does not own.