{
  description = "tlater.net host configuration";

  inputs = {
    nixpkgs.url = "github:nixos/nixpkgs/nixos-22.05";
    nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
    deploy-rs.url = "github:serokell/deploy-rs";
    sops-nix = {
      url = "github:Mic92/sops-nix";
      inputs.nixpkgs.follows = "nixpkgs";
    };
    nvfetcher = {
      url = "github:berberman/nvfetcher";
      inputs.nixpkgs.follows = "nixpkgs";
    };
    tlaternet-webserver = {
      url = "git+https://gitea.tlater.net/tlaternet/tlaternet.git";
      inputs.nixpkgs.follows = "nixpkgs";
    };
  };

  outputs = {
    self,
    nixpkgs,
    nixpkgs-unstable,
    sops-nix,
    nvfetcher,
    deploy-rs,
    tlaternet-webserver,
  }: let
    system = "x86_64-linux";
  in {
    ##################
    # Configurations #
    ##################
    nixosConfigurations = {
      # The actual system definition
      tlaternet = self.lib.makeNixosSystem {
        inherit system;
        extraModules = [(import ./configuration/hardware-specific/linode)];
      };
    };

    ############################
    # Deployment configuration #
    ############################
    deploy.nodes.tlaternet = {
      hostname = "tlater.net";

      profiles.system = {
        user = "root";
        path = deploy-rs.lib.${system}.activate.nixos self.nixosConfigurations.tlaternet;
      };

      sshUser = "tlater";
      sshOpts = ["-p" "2222" "-o" "ForwardAgent=yes"];
      fastConnection = true;
    };

    #########
    # Tests #
    #########
    checks = builtins.mapAttrs (system: deployLib: deployLib.deployChecks self.deploy) deploy-rs.lib;

    ####################
    # Helper functions #
    ####################
    lib = import ./lib {
      inherit nixpkgs nixpkgs-unstable sops-nix tlaternet-webserver;
      lib = nixpkgs.lib;
    };

    ###################
    # Utility scripts #
    ###################
    packages.${system} = let
      inherit (nixpkgs.legacyPackages.${system}) writeShellScript;
    in {
      default = self.packages.${system}.run-vm;

      run-vm = let
        vm = self.lib.makeNixosSystem {
          inherit system;
          extraModules = [(import ./configuration/hardware-specific/vm.nix)];
        };

        qemuNetOpts = self.lib.makeQemuNetOpts {
          "2222" = "2222";
          "3080" = "80";
          "3443" = "443";
          "8448" = "8448"; # Matrix
          "21025" = "21025"; # Starbound
        };
      in
        writeShellScript "run-vm" ''
          export QEMU_OPTS="-m 3941 -smp 2 -display curses"
          export QEMU_NET_OPTS="${qemuNetOpts}"
          "${vm.config.system.build.vm}/bin/run-tlaternet-vm"
        '';

      update-nextcloud-apps = let
        nvfetcher-bin = "${nvfetcher.defaultPackage.${system}}/bin/nvfetcher";
      in
        writeShellScript "update-nextcloud-apps" ''
          cd "$(git rev-parse --show-toplevel)/pkgs"
          ${nvfetcher-bin} -o _sources_nextcloud -c nextcloud-apps.toml
        '';
    };

    apps.${system} = let
      inherit (nixpkgs.legacyPackages.${system}) writeShellScript;
    in {
      default = {
        type = "app";
        program = builtins.toString self.packages.${system}.run-vm;
      };

      update-nextcloud-apps = {
        type = "app";
        program = builtins.toString self.packages.${system}.update-nextcloud-apps;
      };
    };

    ###########################
    # Development environment #
    ###########################
    devShells.${system}.default = nixpkgs.legacyPackages.${system}.mkShell {
      sopsPGPKeyDirs = ["./keys/hosts/" "./keys/users/"];
      nativeBuildInputs = [
        sops-nix.packages.${system}.sops-import-keys-hook
      ];

      packages = [
        sops-nix.packages.${system}.sops-init-gpg-key
        deploy-rs.packages.${system}.default
      ];
    };
  };
}