From 28be191d007b834c828d9a9a2e19a708fbb27aa8 Mon Sep 17 00:00:00 2001 From: Johnathan Corgan Date: Tue, 25 Aug 2026 20:56:24 +0100 Subject: [PATCH] Record the NixOS module and overlay in the changelog Arjen's flake module landed on master as part of a6567f9 and never got a changelog entry here; the only copy of the text was in the release branch's own [0.5.0] section, written when the release content was prepared. That made the two sections disagree by a bullet in each direction and left a shipped feature undescribed on the branch it shipped from. The entry is verbatim from the release branch, including its statement that nothing here exercises the flake. --- CHANGELOG.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 522f54c7..4be426b3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -234,6 +234,17 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 #### Packaging & deployment +- A NixOS module and an overlay are exposed from the flake, so a flake consumer + enables the daemon with one line rather than hand-rolling a systemd unit. + `overlays.default` adds `pkgs.fips`, and `nixosModules.default` provides + `services.fips.*`: `enable`, `package`, `configFile`, `openFirewall` (UDP 2121 + and TCP 8443) and `dns.enable`, which routes `.fips` to `[::1]:5354` through + systemd-resolved declaratively rather than with setup and teardown scripts. + `packaging/nixos/README.md` documents it with a full consumer `flake.nix`. + Contributed by Arjen. **Unexercised here**: no CI job builds the flake and no + Nix toolchain is present on the machine this release was assembled on, so the + module is untested outside its author's environment. + - `fipsctl address [npub|hostname]` prints a node's `fd00::/8` mesh address and nothing else, without contacting the daemon. With no argument it derives the local node's address from `fips.key` in the default key directory, falling