Files
dotfiles/system-config
alex ed063ab1fe feat(desktop): consolidate declarative workstation profile
Capture desktop-specific system, session, Noctalia, and Pi integration alongside shared laptop support. Retire obsolete X11 configuration and make package ownership explicit for repeatable Decman deployments.
2026-08-24 20:20:58 +02:00
..
2026-08-13 23:03:55 +02:00

system-config

A small, declarative Arch configuration managed by Decman.

Design

  • Concerns live in packages/: each concern has a native (*-repo.txt) and AUR (*-aur.txt) list.
  • Hosts live in hosts.py: a host composes package concerns and explicit system state. desktop() owns this desktop's boot, storage, NVIDIA, input, SDDM, network-policy, and user-session configuration.
  • System files live in config/system/: shared files go in common/; hardware, sleep/logind, and boot policy go in the relevant host directory.
  • State lives in manifests/: units follow the same concern and host scopes as packages.
  • Python glue lives in modules/: package and system-state adapters only.

Decman owns the listed system files and selected durable home configuration. yadm owns remaining portable dotfiles; application state, browser profiles, NetworkManager connection profiles, and project build output remain unmanaged.

System policy

  • config/system/common/pacman/pacman.conf enables only the official core, extra, and multilib repositories. No debug repository is enabled.
  • config/system/common/makepkg/makepkg.conf sets OPTIONS with !debug, so newly built packages do not produce debug packages.
  • config/system/common/locale/ owns locale generation and system locale.
  • config/system/common/keyboard/ owns console and X11 keyboard policy.
  • config/system/laptop/sleep.conf.d/ owns sleep policy; the logind drop-in remains in config/system/laptop/systemd/.
  • config/system/laptop/power/tlp.conf owns laptop power policy. TLP reads /etc/tlp.conf after drop-ins, so a whole-file policy is required here.
  • config/system/{laptop,desktop}/boot/mkinitcpio.conf owns encrypted-root and resume initramfs hooks for each host; its module rebuilds the initramfs after a change.
  • config/system/laptop/refind/ owns the laptop ESP rEFInd configuration and encrypted-root kernel options. It is intentionally laptop-only.
  • config/system/laptop/iwlwifi.conf retains the Wi-Fi 6 stability workaround; NetworkManager owns Wi-Fi power saving for battery use.
  • config/user/{common,laptop,desktop}/ owns selected active user dotfiles. Host-specific Hyprland and Noctalia variants are selected by host composition.
  • EnvyControl's generated NVIDIA blacklist and udev files are intentionally unmanaged so GPU modes can be switched outside of Decman.

Changing the debug policy does not uninstall debug packages already installed; remove those explicitly in a separate reviewed package change.

Package concerns

Scope Concerns
Shared core, wayland, fonts, development, productivity, media, research, network, services
Laptop hardware, legacy; hardware units
Desktop shared concerns, common/hardware, and a reviewable desktop/local set; host state is in config/system/desktop/

Every package must have a named purpose. Add a new concern when an existing one does not explain a package. System and user units use the same naming: manifests/common/<concern>-{system,user}.txt or manifests/laptop/<concern>-system.txt.

Commands

cd ~/system-config
./scripts/verify.py
sudo decman --source source.py --dry-run --no-hooks
sudo decman --source source.py --no-hooks

verify.py proves that every currently explicit package appears exactly once in the active laptop profile. The ignored dependency lists prevent Decman's orphan cleanup from removing dependencies during adoption.

After intentional package changes, regenerate and review concern lists:

./scripts/split_packages.py
./scripts/refresh_orphan_guards.py
./scripts/verify.py
git diff