# AZ-NIX-CLIENTS A NixOS flake that manages AzIntec client hosts. Two host species live in this repo: developer workstations (e.g. `AZ-LT-NIX`) and the thin-client fleet (`AZ-TC-NN`). ## Language **Thin Client**: A NixOS client host in the `AZ-TC-NN` fleet — a mini-PC running KDE Plasma that authenticates against Active Directory, provides a pre-configured RDP shortcut to a terminal server, and runs a pinned browser for one web app. Replaces a Windows 11 workstation. _Avoid_: kiosk, terminal, workstation **Workstation**: A NixOS host used for interactive development work (e.g. `AZ-LT-NIX`). Not a Thin Client — these hosts use the m3ta-home profile system and are not in the production fleet. _Avoid_: desktop, laptop, client **Terminal Server**: The remote Windows RDS host (or farm) that Thin Clients connect to via RDP. Kerberos SSO is expected to flow from the client login to this server. _Avoid_: RDP server, remote desktop, RD server **Web App**: The single browser-based application that Thin Clients open at session start. Kerberos SSO is expected for this app. _Avoid_: portal, intranet, app **Domain User**: An identity provided by Active Directory via `sssd`. Logs into the Thin Client at the SDDM login screen; credentials flow to RDP and the web app via Kerberos. _Avoid_: AD user, network user, SSO user **Hardware Class**: One of the 2–3 mini-PC SKUs the fleet is composed of (e.g. Dell OptiPlex Micro, Lenovo ThinkCentre Tiny). Each class has its own hardware module under the thin-client role. _Avoid_: SKU, model, hardware type **Fleet Host**: A single physical Thin Client, identified by `AZ-TC-NN` (two-digit number). Each fleet host has a tiny `default.nix` that imports the thin-client role and declares its hardware class and hostname. _Avoid_: node, device, machine