Five ready-to-eval consumer flakes plus two doc-friendly alias directories. Read the per-directory README first.
| Path | Audience | Notes |
|---|---|---|
minimal/ |
Checked headless starter | Canonical flake behind the doc-friendly personal-dev/ alias. |
personal-dev/ |
Rust-first README alias | README-only pointer to minimal/; VM name personal-dev. |
graphics-workstation/ |
Desktop VM with Wayland + audio + USBIP | Requires a Wayland compositor on the host. |
multi-env/ (demo) |
Two isolated envs (work + personal) | Demonstrates per-env isolation and route preflight. |
multi-env/ (multi-env-daemon-experimental) |
Two isolated envs + network-knob variant | Exercises per-env mtu / mssClamp / lan.allowEastWest plus the site-level allowUnsafeEastWest acknowledgement. |
with-observability/ |
Single workload VM + auto-declared observability stack | Grafana/Prometheus/Loki/Tempo on a dedicated obs env. |
with-entra-id/ |
Checked Entra-ID composition | Canonical flake behind the doc-friendly work-entra/ alias. |
work-entra/ |
Rust-first README alias | README-only pointer to with-entra-id/; VM name work-entra. |
personal-dev/ and work-entra/ intentionally do not ship a
flake.nix. They are lightweight alias READMEs so the docs can use
stable VM names while CI keeps one checked flake per scenario
(minimal/ and with-entra-id/).
Examples that are primarily meant to evaluate the in-tree framework
via d2b.url = "path:../.." do not commit a flake.lock
(currently minimal/, graphics-workstation/, multi-env/, and
with-observability/). Even when an example spells out shared inputs
such as nixpkgs, microvm, or home-manager, the point is still to
exercise the local checkout; a committed lock would be stale by
construction and tests/static.sh regenerates a local lock on first
eval anyway.
Examples that pull in an external sibling flake (with-entra-id/
consumes github:vicondoa/entrablau.nix) do commit their
flake.lock for reproducibility — the lock is the only way to ensure
the example builds bit-identically across machines.
Every checked example's flake.nix uses d2b.url = "path:../.."
so it can be evaluated against the in-tree framework without a
network round-trip. When you copy any of these layouts into your own
repo, swap that for a real flake ref — github:vicondoa/d2b
(track main) or a tagged release.
../templates/default/—nix flake initscaffold with sentinel TODOs + assertion gates.../README.md— framework-level Rust-first quick start, threat model, and option index.../docs/— reference docs (manifest schema, CLI contract, security runbook).