diff --git a/jeschli/1systems/bolide/config.nix b/jeschli/1systems/bolide/config.nix
index 5cb6ef568..d859833ac 100644
--- a/jeschli/1systems/bolide/config.nix
+++ b/jeschli/1systems/bolide/config.nix
@@ -12,7 +12,8 @@ in
       ./hardware-configuration.nix
       <stockholm/jeschli>
       <stockholm/jeschli/2configs/urxvt.nix>
-    #  <stockholm/jeschli/2configs/emacs.nix>
+      <stockholm/jeschli/2configs/i3.nix>
+      <stockholm/jeschli/2configs/emacs.nix>
     ];
 
   krebs.build.host = config.krebs.hosts.bolide;
@@ -56,6 +57,7 @@ in
   };
   nixpkgs.config.allowUnfree = true;
   environment.systemPackages = with pkgs; [
+    rofi
     wget vim
   # system helper
     ag
@@ -78,13 +80,14 @@ in
     chromium
     google-chrome
   # programming languages
+    vscode
     go
     gcc9
     ccls
     unstable.clang_8
     ghc
-    python35
-    python35Packages.pip
+    python37
+    python37Packages.pip
   # go tools
     golint
     gotools
@@ -98,42 +101,13 @@ in
     zathura
   ];
 
- # Some programs need SUID wrappers, can be configured further or are
- # started in user sessions.
- # programs.bash.enableCompletion = true;
- # programs.mtr.enable = true;
- # programs.gnupg.agent = { enable = true; enableSSHSupport = true; };
-
- # List services that you want to enable:
 
  # Enable the OpenSSH daemon.
- services.openssh.enable = true;
+  services.openssh.enable = true;
 
+  services.xserver.videoDrivers = [ "nvidia" ];
 
-  services.xserver = {
-
-    enable = true;
-
-    desktopManager = {
-      xfce.enable = true;
-      gnome3.enable = true;
-    };
-#    # Don't install feh into systemPackages
-#    # refs <nixpkgs/nixos/modules/services/x11/desktop-managers>
-#    desktopManager.session = lib.mkForce [];
-#
-#    enable = true;
-#    display = 11;
-#    tty = 11;
-#
-#    dpi = 96;
-
-    videoDrivers = [ "nvidia" ];
-  };
-
-  services.xserver.windowManager.i3.enable = true;
-
-  users.extraUsers.jeschli = {
+users.extraUsers.jeschli = {
     isNormalUser = true;
     extraGroups = ["docker" "vboxusers" "audio"];
     uid = 1000;
diff --git a/jeschli/1systems/brauerei/config.nix b/jeschli/1systems/brauerei/config.nix
index aabb4b7ba..860c5d11c 100644
--- a/jeschli/1systems/brauerei/config.nix
+++ b/jeschli/1systems/brauerei/config.nix
@@ -1,6 +1,5 @@
 { config, pkgs, lib, ... }:
 let
-  xmonad-jeschli = pkgs.callPackage <stockholm/jeschli/5pkgs/simple/xmonad-jeschli> { inherit config; };
   mainUser = config.krebs.build.user.name;
   unstable = import <nixpkgs-unstable> { config = { allowUnfree = true; }; };
 in
@@ -9,6 +8,7 @@ in
     <stockholm/jeschli>
     ./hardware-configuration.nix
     <home-manager/nixos>
+    <stockholm/jeschli/2configs/emacs.nix>
     <stockholm/jeschli/2configs/urxvt.nix>
     <stockholm/jeschli/2configs/steam.nix>
     <stockholm/jeschli/2configs/virtualbox.nix>
@@ -117,29 +117,29 @@ in
   # programs.mtr.enable = true;
   programs.gnupg.agent = { enable = true; enableSSHSupport = true; };
 
-  home-manager.useUserPackages = true;
-  home-manager.users.jeschli = {
-    home.stateVersion = "19.03";
-  };
+#  home-manager.useUserPackages = true;
+#  home-manager.users.jeschli = {
+#    home.stateVersion = "19.03";
+#  };
 #  home-manager.enable = true;
 
-  home-manager.users.jeschli.home.file = {
-     ".emacs.d" = {
-       source = pkgs.fetchFromGitHub {
-         owner = "jeschli";
-         repo = "emacs.d";
-         rev = "8ed6c40";
-         sha256 = "1q2y478srwp9f58l8cixnd2wj51909gp1z68k8pjlbjy2mrvibs0";
-       };
-       recursive = true;
-     };
-  };
+#  home-manager.users.jeschli.home.file = {
+#     ".emacs.d" = {
+#       source = pkgs.fetchFromGitHub {
+#         owner = "jeschli";
+#         repo = "emacs.d";
+#         rev = "8ed6c40";
+#         sha256 = "1q2y478srwp9f58l8cixnd2wj51909gp1z68k8pjlbjy2mrvibs0";
+#       };
+#       recursive = true;
+#     };
+#  };
 
   # List services that you want to enable:
 
   # Enable the OpenSSH daemon.
   services.openssh.enable = true;
-  services.emacs.enable = true;
+#  services.emacs.enable = true;
 
   virtualisation.docker.enable = true;
 
@@ -151,16 +151,6 @@ in
       gnome3.enable = true;
     };
 
-    windowManager = {
-      session = [{
-        name = "xmonad";
-        start = ''
-          ${xmonad-jeschli}/bin/xmonad &
-          waitPID=$!
-        '';
-        }
-      ];
-    };
   };
 
   services.xserver.windowManager.i3.enable = true;
diff --git a/jeschli/1systems/reagenzglas/config.nix b/jeschli/1systems/reagenzglas/config.nix
new file mode 100644
index 000000000..2eefb23fb
--- /dev/null
+++ b/jeschli/1systems/reagenzglas/config.nix
@@ -0,0 +1,85 @@
+{ config, pkgs, ... }:
+with pkgs;
+let
+  rebuild_script = pkgs.writeTextFile {
+    name="rebuild";
+    text=''
+      #!/usr/bin/env sh
+      set -eu
+      sudo cp -r /etc/nixos ~/old-nixos
+      sudo cp -r $HOME/nixos /etc/
+      sudo nixos-rebuild switch 
+      '';
+    executable=true;
+  };
+in
+{
+  imports =
+    [
+    <stockholm/jeschli>
+    <stockholm/jeschli/2configs/emacs.nix>
+       ./desktop.nix
+       ./i3-configuration.nix
+       ./hardware-configuration.nix
+    ];
+
+  # EFI systemd boot loader
+  boot.loader.systemd-boot.enable = true;
+
+  # Wireless network with network manager
+  krebs.build.host = config.krebs.hosts.brauerei;
+  # networking.hostName = "nixos"; # Define your hostname.
+  networking.networkmanager.enable = true;
+
+  # Allow unfree
+  nixpkgs.config.allowUnfree = true;
+
+  # Select internationalisation properties.
+  i18n = {
+    consoleKeyMap = "us";
+    defaultLocale = "en_US.UTF-8";
+  };
+
+  # Set your time zone.
+  time.timeZone = "Europe/Berlin";
+
+  # List packages installed in system profile. To search, run:
+  # $ nix search wget
+  environment.systemPackages = with pkgs; [
+    wget vim git
+    firefox
+    rofi
+  ];
+
+  # How I rebuild the system
+  environment.shellAliases = {
+    rebuild = rebuild_script;
+  };
+
+  # Define a user account. Don't forget to set a password with ‘passwd’.
+  users.users.ombi = {
+     isNormalUser = true;
+     extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user.
+  };
+
+  users.users.jeschli = {
+     isNormalUser = true;
+  };
+
+  services.xserver.synaptics.enable = true;
+
+  #Enable ssh daemon
+  services.openssh.enable = true;
+
+  users.users.root.openssh.authorizedKeys.keys = [
+    "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDM1xtX/SF2IzfAIzrXvH4HsW05eTBX8U8MYlEPadq0DS/nHC45hW2PSEUOVsH0UhBRAB+yClVLyN+JAYsuOoQacQqAVq9R7HAoFITdYTMJCxVs4urSRv0pWwTopRIh1rlI+Q0QfdMoeVtO2ZKG3KoRM+APDy2dsX8LTtWjXmh/ZCtpGl1O8TZtz2ZyXyv9OVDPnQiFwPU3Jqs2Z036c+kwxWlxYc55FRuqwRtQ48c/ilPMu+ZvQ22j1Ch8lNuliyAg1b8pZdOkMJF3R8b46IQ8FEqkr3L1YQygYw2M50B629FPgHgeGPMz3mVd+5lzP+okbhPJjMrUqZAUwbMGwGzZ ombi@nixos"
+    "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKFXgtbgeivxlMKkoEJ4ANhtR+LRMSPrsmL4U5grFUME jeschli@nixos"
+  ];
+
+  # This value determines the NixOS release with which your system is to be
+  # compatible, in order to avoid breaking some software such as database
+  # servers. You should change this only after NixOS release notes say you
+  # should.
+  system.stateVersion = "19.03"; # Did you read the comment?
+
+}
diff --git a/jeschli/1systems/reagenzglas/desktop.nix b/jeschli/1systems/reagenzglas/desktop.nix
new file mode 100644
index 000000000..0c4298109
--- /dev/null
+++ b/jeschli/1systems/reagenzglas/desktop.nix
@@ -0,0 +1,25 @@
+# Configuration for the desktop environment
+
+{ config, lib, pkgs, ... }:
+{
+  # Configure basic X-server stuff:
+  services.xserver = {
+    enable = true;
+    xkbOptions = "caps:super";
+    exportConfiguration = true;
+    
+    displayManager.slim.enable = true;
+  };
+
+  # Configure fonts
+  fonts = {
+    fonts = with pkgs; [
+      corefonts
+      font-awesome-ttf
+      noto-fonts-cjk
+      noto-fonts-emoji
+      powerline-fonts
+      helvetica-neue-lt-std
+    ];
+  };
+}
diff --git a/jeschli/1systems/reagenzglas/hardware-configuration.nix b/jeschli/1systems/reagenzglas/hardware-configuration.nix
new file mode 100644
index 000000000..55f5532d6
--- /dev/null
+++ b/jeschli/1systems/reagenzglas/hardware-configuration.nix
@@ -0,0 +1,37 @@
+# Do not modify this file!  It was generated by ‘nixos-generate-config’
+# and may be overwritten by future invocations.  Please make changes
+# to /etc/nixos/configuration.nix instead.
+{ config, lib, pkgs, ... }:
+
+{
+  imports =
+    [ <nixpkgs/nixos/modules/installer/scan/not-detected.nix>
+    ];
+
+  boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "nvme" "usb_storage" "sd_mod" "rtsx_pci_sdmmc" ];
+  boot.initrd.kernelModules = [ "dm-snapshot" ];
+  boot.initrd.luks.devices = [
+  {
+    name = "root";
+    device = "/dev/nvme0n1p8";
+    preLVM = true;
+  }
+  ];
+  boot.kernelModules = [ "kvm-intel" ];
+  boot.extraModulePackages = [ ];
+
+  fileSystems."/" =
+    { device = "/dev/disk/by-uuid/4d01936e-c876-42c3-962a-d4a20ad0e2e0";
+      fsType = "ext4";
+    };
+
+  fileSystems."/boot" =
+    { device = "/dev/disk/by-uuid/D455-E4CC";
+      fsType = "vfat";
+    };
+
+  swapDevices = [ ];
+
+  nix.maxJobs = lib.mkDefault 8;
+  powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
+}
diff --git a/jeschli/1systems/reagenzglas/i3-configuration.nix b/jeschli/1systems/reagenzglas/i3-configuration.nix
new file mode 100644
index 000000000..c9968c17a
--- /dev/null
+++ b/jeschli/1systems/reagenzglas/i3-configuration.nix
@@ -0,0 +1,176 @@
+{pkgs, environment, config, lib, ... }:
+
+with pkgs;
+
+let
+  i3_config_file = pkgs.writeText "config" ''
+    set $mod Mod4
+    
+    font pango:monospace 8
+    
+    #font pango:DejaVu Sans Mono 8
+    
+    # Before i3 v4.8, we used to recommend this one as the default:
+    # font -misc-fixed-medium-r-normal--13-120-75-75-C-70-iso10646-1
+    # The font above is very space-efficient, that is, it looks good, sharp and
+    # clear in small sizes. However, its unicode glyph coverage is limited, the old
+    # X core fonts rendering does not support right-to-left and this being a bitmap
+    # font, it doesn’t scale on retina/hidpi displays.
+    
+    # Use Mouse+$mod to drag floating windows to their wanted position
+    floating_modifier $mod
+    
+    # start a terminal
+    bindsym $mod+Return exec i3-sensible-terminal
+    
+    # kill focused window
+    bindsym $mod+Shift+q kill
+    
+    # start dmenu (a program launcher)
+    # bindsym $mod+d exec dmenu_run
+
+    # start dmenu (a program launcher)
+    bindsym $mod+d exec ${pkgs.rofi}/bin/rofi -modi drun#run -combi-modi drun#run -show combi -show-icons -display-combi run
+ 
+    # There also is the (new) i3-dmenu-desktop which only displays applications
+    # shipping a .desktop file. It is a wrapper around dmenu, so you need that
+    # installed.
+    # bindsym $mod+d exec --no-startup-id i3-dmenu-desktop
+    
+    # change focus
+    bindsym $mod+j focus left
+    bindsym $mod+k focus down
+    bindsym $mod+l focus up
+    bindsym $mod+semicolon focus right
+    
+    # alternatively, you can use the cursor keys:
+    bindsym $mod+Left focus left
+    bindsym $mod+Down focus down
+    bindsym $mod+Up focus up
+    bindsym $mod+Right focus right
+    
+    # move focused window
+    bindsym $mod+Shift+j move left
+    bindsym $mod+Shift+k move down
+    bindsym $mod+Shift+l move up
+    bindsym $mod+Shift+colon move right
+    
+    # alternatively, you can use the cursor keys:
+    bindsym $mod+Shift+Left move left
+    bindsym $mod+Shift+Down move down
+    bindsym $mod+Shift+Up move up
+    bindsym $mod+Shift+Right move right
+    
+    # split in horizontal orientation
+    bindsym $mod+h split h
+    
+    # split in vertical orientation
+    bindsym $mod+v split v
+    
+    # enter fullscreen mode for the focused container
+    bindsym $mod+f fullscreen toggle
+    
+    # change container layout (stacked, tabbed, toggle split)
+    bindsym $mod+s layout stacking
+    bindsym $mod+w layout tabbed
+    bindsym $mod+e layout toggle split
+    
+    # toggle tiling / floating
+    bindsym $mod+Shift+space floating toggle
+    
+    # change focus between tiling / floating windows
+    bindsym $mod+space focus mode_toggle
+    
+    # focus the parent container
+    bindsym $mod+a focus parent
+    
+    # focus the child container
+    #bindsym $mod+d focus child
+    
+    # Define names for default workspaces for which we configure key bindings later on.
+    # We use variables to avoid repeating the names in multiple places.
+    set $ws1 "1"
+    set $ws2 "2"
+    set $ws3 "3"
+    set $ws4 "4"
+    set $ws5 "5"
+    set $ws6 "6"
+    set $ws7 "7"
+    set $ws8 "8"
+    set $ws9 "9"
+    set $ws10 "10"
+    
+    # switch to workspace
+    bindsym $mod+1 workspace $ws1
+    bindsym $mod+2 workspace $ws2
+    bindsym $mod+3 workspace $ws3
+    bindsym $mod+4 workspace $ws4
+    bindsym $mod+5 workspace $ws5
+    bindsym $mod+6 workspace $ws6
+    bindsym $mod+7 workspace $ws7
+    bindsym $mod+8 workspace $ws8
+    bindsym $mod+9 workspace $ws9
+    bindsym $mod+0 workspace $ws10
+    
+    # move focused container to workspace
+    bindsym $mod+Shift+1 move container to workspace $ws1
+    bindsym $mod+Shift+2 move container to workspace $ws2
+    bindsym $mod+Shift+3 move container to workspace $ws3
+    bindsym $mod+Shift+4 move container to workspace $ws4
+    bindsym $mod+Shift+5 move container to workspace $ws5
+    bindsym $mod+Shift+6 move container to workspace $ws6
+    bindsym $mod+Shift+7 move container to workspace $ws7
+    bindsym $mod+Shift+8 move container to workspace $ws8
+    bindsym $mod+Shift+9 move container to workspace $ws9
+    bindsym $mod+Shift+0 move container to workspace $ws10
+    
+    # reload the configuration file
+    bindsym $mod+Shift+c reload
+    # restart i3 inplace (preserves your layout/session, can be used to upgrade i3)
+    bindsym $mod+Shift+r restart
+    # exit i3 (logs you out of your X session)
+    bindsym $mod+Shift+e exec "i3-nagbar -t warning -m 'You pressed the exit shortcut. Do you really want to exit i3? This will end your X session.' -B 'Yes, exit i3' 'i3-msg exit'"
+    
+    # resize window (you can also use the mouse for that)
+    mode "resize" {
+            # These bindings trigger as soon as you enter the resize mode
+    
+            # Pressing left will shrink the window’s width.
+            # Pressing right will grow the window’s width.
+            # Pressing up will shrink the window’s height.
+            # Pressing down will grow the window’s height.
+            bindsym j resize shrink width 10 px or 10 ppt
+            bindsym k resize grow height 10 px or 10 ppt
+            bindsym l resize shrink height 10 px or 10 ppt
+            bindsym semicolon resize grow width 10 px or 10 ppt
+    
+            # same bindings, but for the arrow keys
+            bindsym Left resize shrink width 10 px or 10 ppt
+            bindsym Down resize grow height 10 px or 10 ppt
+            bindsym Up resize shrink height 10 px or 10 ppt
+            bindsym Right resize grow width 10 px or 10 ppt
+    
+            # back to normal: Enter or Escape or $mod+r
+            bindsym Return mode "default"
+            bindsym Escape mode "default"
+            bindsym $mod+r mode "default"
+    }
+    
+    bindsym $mod+r mode "resize"
+    
+    # Start i3bar to display a workspace bar (plus the system information i3status
+    # finds out, if available)
+    bar {
+            status_command i3status
+    }
+  ''; 
+
+in {
+
+  services.xserver.windowManager.i3 = {
+    enable = true;
+    package = pkgs.i3;
+    configFile = i3_config_file;
+  };
+
+}
diff --git a/jeschli/2configs/IM.nix b/jeschli/2configs/IM.nix
index 288134fa2..2366726fb 100644
--- a/jeschli/2configs/IM.nix
+++ b/jeschli/2configs/IM.nix
@@ -29,6 +29,7 @@ in {
       jeschli.pubkey
       jeschli-bln.pubkey
       jeschli-brauerei.pubkey
+      jeschli-bolide.pubkey
     ];
     packages = [ tmux ];
   };
diff --git a/jeschli/2configs/emacs-org-agenda.nix b/jeschli/2configs/emacs-org-agenda.nix
new file mode 100644
index 000000000..ded90ea1a
--- /dev/null
+++ b/jeschli/2configs/emacs-org-agenda.nix
@@ -0,0 +1,2025 @@
+let
+  modifiedBerndHansen = ''
+;; Based on http://doc.norang.ca/org-mode.html
+;; Organize your life in plain text
+;; TODO: minimize this section
+(if (boundp 'org-mode-user-lisp-path)
+    (add-to-list 'load-path org-mode-user-lisp-path)
+  (add-to-list 'load-path (expand-file-name "~/git/org-mode/lisp")))
+
+(add-to-list 'auto-mode-alist '("\\.\\(org\\|org_archive\\|txt\\)$" . org-mode))
+(require 'org)
+
+(add-to-list 'org-modules 'org-habit)
+
+;;
+;; Standard key bindings
+(global-set-key "\C-cl" 'org-store-link)
+(global-set-key "\C-ca" 'org-agenda)
+(global-set-key "\C-cb" 'org-iswitchb)
+
+;; The following setting is different from the document so that you
+;; can override the document org-agenda-files by setting your
+;; org-agenda-files in the variable org-user-agenda-files
+;;
+;; (if (boundp 'org-user-agenda-files)
+;;     (setq org-agenda-files org-user-agenda-files)
+;;   (setq org-agenda-files (quote ("~/git/org"))))
+
+;; Custom Key Bindings
+(global-set-key (kbd "<f12>") 'org-agenda)
+(global-set-key (kbd "<S-f5>") 'bh/widen)
+(global-set-key (kbd "<f9> <f9>") 'bh/show-org-agenda)
+(global-set-key (kbd "<f9> b") 'bbdb)
+(global-set-key (kbd "<f9> c") 'calendar)
+(global-set-key (kbd "<f9> f") 'boxquote-insert-file)
+(global-set-key (kbd "<f9> g") 'gnus)
+(global-set-key (kbd "<f9> h") 'bh/hide-other)
+(global-set-key (kbd "<f9> n") 'bh/toggle-next-task-display)
+
+(global-set-key (kbd "<f9> I") 'bh/punch-in)
+(global-set-key (kbd "<f9> O") 'bh/punch-out)
+
+(global-set-key (kbd "<f9> o") 'bh/make-org-scratch)
+
+(global-set-key (kbd "<f9> r") 'boxquote-region)
+(global-set-key (kbd "<f9> s") 'bh/switch-to-scratch)
+
+(global-set-key (kbd "<f9> t") 'bh/insert-inactive-timestamp)
+(global-set-key (kbd "<f9> T") 'bh/toggle-insert-inactive-timestamp)
+
+(global-set-key (kbd "<f9> v") 'visible-mode)
+(global-set-key (kbd "<f9> l") 'org-toggle-link-display)
+(global-set-key (kbd "<f9> SPC") 'bh/clock-in-last-task)
+(global-set-key (kbd "C-<f9>") 'previous-buffer)
+(global-set-key (kbd "M-<f9>") 'org-toggle-inline-images)
+(global-set-key (kbd "C-x n r") 'narrow-to-region)
+(global-set-key (kbd "C-<f10>") 'next-buffer)
+(global-set-key (kbd "<f11>") 'org-clock-goto)
+(global-set-key (kbd "C-<f11>") 'org-clock-in)
+(global-set-key (kbd "C-s-<f12>") 'bh/save-then-publish)
+(global-set-key (kbd "C-c c") 'org-capture)
+
+(defun bh/hide-other ()
+  (interactive)
+  (save-excursion
+    (org-back-to-heading 'invisible-ok)
+    (hide-other)
+    (org-cycle)
+    (org-cycle)
+    (org-cycle)))
+
+(defun bh/set-truncate-lines ()
+  "Toggle value of truncate-lines and refresh window display."
+  (interactive)
+  (setq truncate-lines (not truncate-lines))
+  ;; now refresh window display (an idiom from simple.el):
+  (save-excursion
+    (set-window-start (selected-window)
+                      (window-start (selected-window)))))
+
+(defun bh/make-org-scratch ()
+  (interactive)
+  (find-file "/tmp/publish/scratch.org")
+  (gnus-make-directory "/tmp/publish"))
+
+(defun bh/switch-to-scratch ()
+  (interactive)
+  (switch-to-buffer "*scratch*"))
+
+(setq org-todo-keywords
+      (quote ((sequence "TODO(t)" "NEXT(n)" "|" "DONE(d)")
+              (sequence "WAITING(w@/!)" "HOLD(h@/!)" "|" "CANCELLED(c@/!)" "PHONE" "MEETING"))))
+
+(setq org-todo-keyword-faces
+      (quote (("TODO" :foreground "red" :weight bold)
+              ("NEXT" :foreground "blue" :weight bold)
+              ("DONE" :foreground "forest green" :weight bold)
+              ("WAITING" :foreground "orange" :weight bold)
+              ("HOLD" :foreground "magenta" :weight bold)
+              ("CANCELLED" :foreground "forest green" :weight bold)
+              ("MEETING" :foreground "forest green" :weight bold)
+              ("PHONE" :foreground "forest green" :weight bold))))
+
+(setq org-use-fast-todo-selection t)
+
+(setq org-treat-S-cursor-todo-selection-as-state-change nil)
+
+(setq org-todo-state-tags-triggers
+      (quote (("CANCELLED" ("CANCELLED" . t))
+              ("WAITING" ("WAITING" . t))
+              ("HOLD" ("WAITING") ("HOLD" . t))
+              (done ("WAITING") ("HOLD"))
+              ("TODO" ("WAITING") ("CANCELLED") ("HOLD"))
+              ("NEXT" ("WAITING") ("CANCELLED") ("HOLD"))
+              ("DONE" ("WAITING") ("CANCELLED") ("HOLD")))))
+
+(setq org-directory "~/git/org")
+(setq org-default-notes-file "~/git/org/refile.org")
+
+;; I use C-c c to start capture mode
+(global-set-key (kbd "C-c c") 'org-capture)
+
+;; Capture templates for: TODO tasks, Notes, appointments, phone calls, meetings, and org-protocol
+(setq org-capture-templates
+      (quote (("t" "todo" entry (file "~/git/org/refile.org")
+               "* TODO %?\n%U\n%a\n" :clock-in t :clock-resume t)
+              ("r" "respond" entry (file "~/git/org/refile.org")
+               "* NEXT Respond to %:from on %:subject\nSCHEDULED: %t\n%U\n%a\n" :clock-in t :clock-resume t :immediate-finish t)
+              ("n" "note" entry (file "~/git/org/refile.org")
+               "* %? :NOTE:\n%U\n%a\n" :clock-in t :clock-resume t)
+              ("j" "Journal" entry (file+datetree "~/git/org/diary.org")
+               "* %?\n%U\n" :clock-in t :clock-resume t)
+              ("w" "org-protocol" entry (file "~/git/org/refile.org")
+               "* TODO Review %c\n%U\n" :immediate-finish t)
+              ("m" "Meeting" entry (file "~/git/org/refile.org")
+               "* MEETING with %? :MEETING:\n%U" :clock-in t :clock-resume t)
+              ("p" "Phone call" entry (file "~/git/org/refile.org")
+               "* PHONE %? :PHONE:\n%U" :clock-in t :clock-resume t)
+              ("h" "Habit" entry (file "~/git/org/refile.org")
+               "* NEXT %?\n%U\n%a\nSCHEDULED: %(format-time-string \"%<<%Y-%m-%d %a .+1d/3d>>\")\n:PROPERTIES:\n:STYLE: habit\n:REPEAT_TO_STATE: NEXT\n:END:\n"))))
+
+;; Remove empty LOGBOOK drawers on clock out
+(defun bh/remove-empty-drawer-on-clock-out ()
+  (interactive)
+  (save-excursion
+    (beginning-of-line 0)
+    (org-remove-empty-drawer-at "LOGBOOK" (point))))
+
+(add-hook 'org-clock-out-hook 'bh/remove-empty-drawer-on-clock-out 'append)
+
+; Targets include this file and any file contributing to the agenda - up to 9 levels deep
+(setq org-refile-targets (quote ((nil :maxlevel . 9)
+                                 (org-agenda-files :maxlevel . 9))))
+
+; Use full outline paths for refile targets - we file directly with IDO
+(setq org-refile-use-outline-path t)
+
+; Targets complete directly with IDO
+(setq org-outline-path-complete-in-steps nil)
+
+; Allow refile to create parent tasks with confirmation
+(setq org-refile-allow-creating-parent-nodes (quote confirm))
+
+; Use IDO for both buffer and file completion and ido-everywhere to t
+(setq org-completion-use-ido t)
+(setq ido-everywhere t)
+(setq ido-max-directory-size 100000)
+(ido-mode (quote both))
+; Use the current window when visiting files and buffers with ido
+(setq ido-default-file-method 'selected-window)
+(setq ido-default-buffer-method 'selected-window)
+; Use the current window for indirect buffer display
+(setq org-indirect-buffer-display 'current-window)
+
+;;;; Refile settings
+; Exclude DONE state tasks from refile targets
+(defun bh/verify-refile-target ()
+  "Exclude todo keywords with a done state from refile targets"
+  (not (member (nth 2 (org-heading-components)) org-done-keywords)))
+
+(setq org-refile-target-verify-function 'bh/verify-refile-target)
+
+;; Do not dim blocked tasks
+(setq org-agenda-dim-blocked-tasks nil)
+
+;; Compact the block agenda view
+(setq org-agenda-compact-blocks t)
+
+;; Custom agenda command definitions
+(setq org-agenda-custom-commands
+      (quote (("N" "Notes" tags "NOTE"
+               ((org-agenda-overriding-header "Notes")
+                (org-tags-match-list-sublevels t)))
+              ("h" "Habits" tags-todo "STYLE=\"habit\""
+               ((org-agenda-overriding-header "Habits")
+                (org-agenda-sorting-strategy
+                 '(todo-state-down effort-up category-keep))))
+              (" " "Agenda"
+               ((agenda "" nil)
+                (tags "REFILE"
+                      ((org-agenda-overriding-header "Tasks to Refile")
+                       (org-tags-match-list-sublevels nil)))
+                (tags-todo "-CANCELLED/!"
+                           ((org-agenda-overriding-header "Stuck Projects")
+                            (org-agenda-skip-function 'bh/skip-non-stuck-projects)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "-HOLD-CANCELLED/!"
+                           ((org-agenda-overriding-header "Projects")
+                            (org-agenda-skip-function 'bh/skip-non-projects)
+                            (org-tags-match-list-sublevels 'indented)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "-CANCELLED/!NEXT"
+                           ((org-agenda-overriding-header (concat "Project Next Tasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-projects-and-habits-and-single-tasks)
+                            (org-tags-match-list-sublevels t)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-with-date bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-sorting-strategy
+                             '(todo-state-down effort-up category-keep))))
+                (tags-todo "-REFILE-CANCELLED-WAITING-HOLD/!"
+                           ((org-agenda-overriding-header (concat "Project Subtasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-non-project-tasks)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-with-date bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "-REFILE-CANCELLED-WAITING-HOLD/!"
+                           ((org-agenda-overriding-header (concat "Standalone Tasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-project-tasks)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-with-date bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "-CANCELLED+WAITING|HOLD/!"
+                           ((org-agenda-overriding-header (concat "Waiting and Postponed Tasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-non-tasks)
+                            (org-tags-match-list-sublevels nil)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)))
+                (tags "-REFILE/"
+                      ((org-agenda-overriding-header "Tasks to Archive")
+                       (org-agenda-skip-function 'bh/skip-non-archivable-tasks)
+                       (org-tags-match-list-sublevels nil))))
+               nil)
+              ("1" "Agenda (@buero|@vpn|WORK)"
+               ((agenda "" nil)
+                (tags "REFILE"
+                      ((org-agenda-overriding-header "Tasks to Refile")
+                       (org-tags-match-list-sublevels nil)))
+                (tags-todo "@buero|@vpn|WORK-CANCELLED/!"
+                           ((org-agenda-overriding-header "Stuck Projects")
+                            (org-agenda-skip-function 'bh/skip-non-stuck-projects)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "@buero|@vpn|WORK-HOLD-CANCELLED/!"
+                           ((org-agenda-overriding-header "Projects")
+                            (org-agenda-skip-function 'bh/skip-non-projects)
+                            (org-tags-match-list-sublevels 'indented)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "@buero|@vpn|WORK-CANCELLED/!NEXT"
+                           ((org-agenda-overriding-header (concat "Project Next Tasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-projects-and-habits-and-single-tasks)
+                            (org-tags-match-list-sublevels t)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-with-date bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-sorting-strategy
+                             '(todo-state-down effort-up category-keep))))
+                (tags-todo "@buero|@vpn|WORK-REFILE-CANCELLED-WAITING-HOLD/!"
+                           ((org-agenda-overriding-header (concat "Project Subtasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-non-project-tasks)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-with-date bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "@buero|@vpn|WORK-REFILE-CANCELLED-WAITING-HOLD/!"
+                           ((org-agenda-overriding-header (concat "Standalone Tasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-project-tasks)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-with-date bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "@buero|@vpn|WORK-CANCELLED+WAITING|HOLD/!"
+                           ((org-agenda-overriding-header (concat "Waiting and Postponed Tasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-non-tasks)
+                            (org-tags-match-list-sublevels nil)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)))
+                (tags "@buero|@vpn|WORK-REFILE/"
+                      ((org-agenda-overriding-header "Tasks to Archive")
+                       (org-agenda-skip-function 'bh/skip-non-archivable-tasks)
+                       (org-tags-match-list-sublevels nil))))
+               nil)
+               ("2" "Agenda (@inet|@home))"
+               ((agenda "" nil)
+                (tags "REFILE"
+                      ((org-agenda-overriding-header "Tasks to Refile")
+                       (org-tags-match-list-sublevels nil)))
+                (tags-todo "@inet|@home-CANCELLED/!"
+                           ((org-agenda-overriding-header "Stuck Projects")
+                            (org-agenda-skip-function 'bh/skip-non-stuck-projects)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "@inet|@home-HOLD-CANCELLED/!"
+                           ((org-agenda-overriding-header "Projects")
+                            (org-agenda-skip-function 'bh/skip-non-projects)
+                            (org-tags-match-list-sublevels 'indented)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "@inet|@home-CANCELLED/!NEXT"
+                           ((org-agenda-overriding-header (concat "Project Next Tasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-projects-and-habits-and-single-tasks)
+                            (org-tags-match-list-sublevels t)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-with-date bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-sorting-strategy
+                             '(todo-state-down effort-up category-keep))))
+                (tags-todo "@inet|@home-REFILE-CANCELLED-WAITING-HOLD/!"
+                           ((org-agenda-overriding-header (concat "Project Subtasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-non-project-tasks)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-with-date bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "@inet|@home-REFILE-CANCELLED-WAITING-HOLD/!"
+                           ((org-agenda-overriding-header (concat "Standalone Tasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-project-tasks)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-with-date bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-sorting-strategy
+                             '(category-keep))))
+                (tags-todo "@inet|@home-CANCELLED+WAITING|HOLD/!"
+                           ((org-agenda-overriding-header (concat "Waiting and Postponed Tasks"
+                                                                  (if bh/hide-scheduled-and-waiting-next-tasks
+                                                                      ""
+                                                                    " (including WAITING and SCHEDULED tasks)")))
+                            (org-agenda-skip-function 'bh/skip-non-tasks)
+                            (org-tags-match-list-sublevels nil)
+                            (org-agenda-todo-ignore-scheduled bh/hide-scheduled-and-waiting-next-tasks)
+                            (org-agenda-todo-ignore-deadlines bh/hide-scheduled-and-waiting-next-tasks)))
+                (tags "@inet|@home-REFILE/"
+                      ((org-agenda-overriding-header "Tasks to Archive")
+                       (org-agenda-skip-function 'bh/skip-non-archivable-tasks)
+                       (org-tags-match-list-sublevels nil))))
+               nil)
+              )))
+
+(defun bh/org-auto-exclude-function (tag)
+  "Automatic task exclusion in the agenda with / RET"
+  (and (cond
+        ((string= tag "hold")
+         t)
+        ((string= tag "farm")
+         t))
+       (concat "-" tag)))
+
+(setq org-agenda-auto-exclude-function 'bh/org-auto-exclude-function)
+
+;;
+;; Resume clocking task when emacs is restarted
+(org-clock-persistence-insinuate)
+;;
+;; Show lot of clocking history so it's easy to pick items off the C-F11 list
+(setq org-clock-history-length 23)
+;; Resume clocking task on clock-in if the clock is open
+(setq org-clock-in-resume t)
+;; Change tasks to NEXT when clocking in
+(setq org-clock-in-switch-to-state 'bh/clock-in-to-next)
+;; Separate drawers for clocking and logs
+(setq org-drawers (quote ("PROPERTIES" "LOGBOOK")))
+;; Save clock data and state changes and notes in the LOGBOOK drawer
+(setq org-clock-into-drawer t)
+;; Sometimes I change tasks I'm clocking quickly - this removes clocked tasks with 0:00 duration
+(setq org-clock-out-remove-zero-time-clocks t)
+;; Clock out when moving task to a done state
+(setq org-clock-out-when-done t)
+;; Save the running clock and all clock history when exiting Emacs, load it on startup
+(setq org-clock-persist t)
+;; Do not prompt to resume an active clock
+(setq org-clock-persist-query-resume nil)
+;; Enable auto clock resolution for finding open clocks
+(setq org-clock-auto-clock-resolution (quote when-no-clock-is-running))
+;; Include current clocking task in clock reports
+(setq org-clock-report-include-clocking-task t)
+
+(setq bh/keep-clock-running nil)
+
+(defun bh/clock-in-to-next (kw)
+  "Switch a task from TODO to NEXT when clocking in.
+Skips capture tasks, projects, and subprojects.
+Switch projects and subprojects from NEXT back to TODO"
+  (when (not (and (boundp 'org-capture-mode) org-capture-mode))
+    (cond
+     ((and (member (org-get-todo-state) (list "TODO"))
+           (bh/is-task-p))
+      "NEXT")
+     ((and (member (org-get-todo-state) (list "NEXT"))
+           (bh/is-project-p))
+      "TODO"))))
+
+(defun bh/find-project-task ()
+  "Move point to the parent (project) task if any"
+  (save-restriction
+    (widen)
+    (let ((parent-task (save-excursion (org-back-to-heading 'invisible-ok) (point))))
+      (while (org-up-heading-safe)
+        (when (member (nth 2 (org-heading-components)) org-todo-keywords-1)
+          (setq parent-task (point))))
+      (goto-char parent-task)
+      parent-task)))
+
+(defun bh/punch-in (arg)
+  "Start continuous clocking and set the default task to the
+selected task.  If no task is selected set the Organization task
+as the default task."
+  (interactive "p")
+  (setq bh/keep-clock-running t)
+  (if (equal major-mode 'org-agenda-mode)
+      ;;
+      ;; We're in the agenda
+      ;;
+      (let* ((marker (org-get-at-bol 'org-hd-marker))
+             (tags (org-with-point-at marker (org-get-tags-at))))
+        (if (and (eq arg 4) tags)
+            (org-agenda-clock-in '(16))
+          (bh/clock-in-organization-task-as-default)))
+    ;;
+    ;; We are not in the agenda
+    ;;
+    (save-restriction
+      (widen)
+      ; Find the tags on the current task
+      (if (and (equal major-mode 'org-mode) (not (org-before-first-heading-p)) (eq arg 4))
+          (org-clock-in '(16))
+        (bh/clock-in-organization-task-as-default)))))
+
+(defun bh/punch-out ()
+  (interactive)
+  (setq bh/keep-clock-running nil)
+  (when (org-clock-is-active)
+    (org-clock-out))
+  (org-agenda-remove-restriction-lock))
+
+(defun bh/clock-in-default-task ()
+  (save-excursion
+    (org-with-point-at org-clock-default-task
+      (org-clock-in))))
+
+(defun bh/clock-in-parent-task ()
+  "Move point to the parent (project) task if any and clock in"
+  (let ((parent-task))
+    (save-excursion
+      (save-restriction
+        (widen)
+        (while (and (not parent-task) (org-up-heading-safe))
+          (when (member (nth 2 (org-heading-components)) org-todo-keywords-1)
+            (setq parent-task (point))))
+        (if parent-task
+            (org-with-point-at parent-task
+              (org-clock-in))
+          (when bh/keep-clock-running
+            (bh/clock-in-default-task)))))))
+
+(defvar bh/organization-task-id "eb155a82-92b2-4f25-a3c6-0304591af2f9")
+
+(defun bh/clock-in-organization-task-as-default ()
+  (interactive)
+  (org-with-point-at (org-id-find bh/organization-task-id 'marker)
+    (org-clock-in '(16))))
+
+(defun bh/clock-out-maybe ()
+  (when (and bh/keep-clock-running
+             (not org-clock-clocking-in)
+             (marker-buffer org-clock-default-task)
+             (not org-clock-resolving-clocks-due-to-idleness))
+    (bh/clock-in-parent-task)))
+
+(add-hook 'org-clock-out-hook 'bh/clock-out-maybe 'append)
+
+(require 'org-id)
+(defun bh/clock-in-task-by-id (id)
+  "Clock in a task by id"
+  (org-with-point-at (org-id-find id 'marker)
+    (org-clock-in nil)))
+
+(defun bh/clock-in-last-task (arg)
+  "Clock in the interrupted task if there is one
+Skip the default task and get the next one.
+A prefix arg forces clock in of the default task."
+  (interactive "p")
+  (let ((clock-in-to-task
+         (cond
+          ((eq arg 4) org-clock-default-task)
+          ((and (org-clock-is-active)
+                (equal org-clock-default-task (cadr org-clock-history)))
+           (caddr org-clock-history))
+          ((org-clock-is-active) (cadr org-clock-history))
+          ((equal org-clock-default-task (car org-clock-history)) (cadr org-clock-history))
+          (t (car org-clock-history)))))
+    (widen)
+    (org-with-point-at clock-in-to-task
+      (org-clock-in nil))))
+
+(setq org-time-stamp-rounding-minutes (quote (1 1)))
+
+(setq org-agenda-clock-consistency-checks
+      (quote (:max-duration "4:00"
+              :min-duration 0
+              :max-gap 0
+              :gap-ok-around ("4:00"))))
+
+;; Sometimes I change tasks I'm clocking quickly - this removes clocked tasks with 0:00 duration
+(setq org-clock-out-remove-zero-time-clocks t)
+
+;; Agenda clock report parameters
+(setq org-agenda-clockreport-parameter-plist
+      (quote (:link t :maxlevel 5 :fileskip0 t :compact t :narrow 80)))
+
+; Set default column view headings: Task Effort Clock_Summary
+(setq org-columns-default-format "%80ITEM(Task) %10Effort(Effort){:} %10CLOCKSUM")
+
+; global Effort estimate values
+; global STYLE property values for completion
+(setq org-global-properties (quote (("Effort_ALL" . "0:15 0:30 0:45 1:00 2:00 3:00 4:00 5:00 6:00 0:00")
+                                    ("STYLE_ALL" . "habit"))))
+
+;; Agenda log mode items to display (closed and state changes by default)
+(setq org-agenda-log-mode-items (quote (closed state)))
+
+; Tags with fast selection keys
+(setq org-tag-alist (quote ((:startgroup)
+                            ("@errand" . ?E)
+                            ("@buero" . ?B)
+                            ("@omw" . ?O)
+                            ("@vpn" . ?V)
+                            ("@inet" . ?I)
+                            ("@home" . ?H)
+                            (:endgroup)
+                            ("WAITING" . ?w)
+                            ("HOLD" . ?h)
+                            ("PERSONAL" . ?p)
+                            ("WORK" . ?w)
+                            ("ORG" . ?o)
+                            ("crypt" . ?e)
+                            ("NOTE" . ?n)
+                            ("CANCELLED" . ?c)
+                            ("FLAGGED" . ??))))
+
+; Allow setting single tags without the menu
+(setq org-fast-tag-selection-single-key (quote expert))
+
+; For tag searches ignore tasks with scheduled and deadline dates
+(setq org-agenda-tags-todo-honor-ignore-options t)
+
+(require 'bbdb)
+(require 'bbdb-com)
+
+(global-set-key (kbd "<f9> p") 'bh/phone-call)
+
+;;
+;; Phone capture template handling with BBDB lookup
+;; Adapted from code by Gregory J. Grubbs
+(defun bh/phone-call ()
+  "Return name and company info for caller from bbdb lookup"
+  (interactive)
+  (let* (name rec caller)
+    (setq name (completing-read "Who is calling? "
+                                (bbdb-hashtable)
+                                'bbdb-completion-predicate
+                                'confirm))
+    (when (> (length name) 0)
+      ; Something was supplied - look it up in bbdb
+      (setq rec
+            (or (first
+                 (or (bbdb-search (bbdb-records) name nil nil)
+                     (bbdb-search (bbdb-records) nil name nil)))
+                name)))
+
+    ; Build the bbdb link if we have a bbdb record, otherwise just return the name
+    (setq caller (cond ((and rec (vectorp rec))
+                        (let ((name (bbdb-record-name rec))
+                              (company (bbdb-record-company rec)))
+                          (concat "[[bbdb:"
+                                  name "]["
+                                  name "]]"
+                                  (when company
+                                    (concat " - " company)))))
+                       (rec)
+                       (t "NameOfCaller")))
+    (insert caller)))
+
+(setq org-agenda-span 'day)
+
+(setq org-stuck-projects (quote ("" nil nil "")))
+
+(defun bh/is-project-p ()
+  "Any task with a todo keyword subtask"
+  (save-restriction
+    (widen)
+    (let ((has-subtask)
+          (subtree-end (save-excursion (org-end-of-subtree t)))
+          (is-a-task (member (nth 2 (org-heading-components)) org-todo-keywords-1)))
+      (save-excursion
+        (forward-line 1)
+        (while (and (not has-subtask)
+                    (< (point) subtree-end)
+                    (re-search-forward "^\*+ " subtree-end t))
+          (when (member (org-get-todo-state) org-todo-keywords-1)
+            (setq has-subtask t))))
+      (and is-a-task has-subtask))))
+
+(defun bh/is-project-subtree-p ()
+  "Any task with a todo keyword that is in a project subtree.
+Callers of this function already widen the buffer view."
+  (let ((task (save-excursion (org-back-to-heading 'invisible-ok)
+                              (point))))
+    (save-excursion
+      (bh/find-project-task)
+      (if (equal (point) task)
+          nil
+        t))))
+
+(defun bh/is-task-p ()
+  "Any task with a todo keyword and no subtask"
+  (save-restriction
+    (widen)
+    (let ((has-subtask)
+          (subtree-end (save-excursion (org-end-of-subtree t)))
+          (is-a-task (member (nth 2 (org-heading-components)) org-todo-keywords-1)))
+      (save-excursion
+        (forward-line 1)
+        (while (and (not has-subtask)
+                    (< (point) subtree-end)
+                    (re-search-forward "^\*+ " subtree-end t))
+          (when (member (org-get-todo-state) org-todo-keywords-1)
+            (setq has-subtask t))))
+      (and is-a-task (not has-subtask)))))
+
+(defun bh/is-subproject-p ()
+  "Any task which is a subtask of another project"
+  (let ((is-subproject)
+        (is-a-task (member (nth 2 (org-heading-components)) org-todo-keywords-1)))
+    (save-excursion
+      (while (and (not is-subproject) (org-up-heading-safe))
+        (when (member (nth 2 (org-heading-components)) org-todo-keywords-1)
+          (setq is-subproject t))))
+    (and is-a-task is-subproject)))
+
+(defun bh/list-sublevels-for-projects-indented ()
+  "Set org-tags-match-list-sublevels so when restricted to a subtree we list all subtasks.
+  This is normally used by skipping functions where this variable is already local to the agenda."
+  (if (marker-buffer org-agenda-restrict-begin)
+      (setq org-tags-match-list-sublevels 'indented)
+    (setq org-tags-match-list-sublevels nil))
+  nil)
+
+(defun bh/list-sublevels-for-projects ()
+  "Set org-tags-match-list-sublevels so when restricted to a subtree we list all subtasks.
+  This is normally used by skipping functions where this variable is already local to the agenda."
+  (if (marker-buffer org-agenda-restrict-begin)
+      (setq org-tags-match-list-sublevels t)
+    (setq org-tags-match-list-sublevels nil))
+  nil)
+
+(defvar bh/hide-scheduled-and-waiting-next-tasks t)
+
+(defun bh/toggle-next-task-display ()
+  (interactive)
+  (setq bh/hide-scheduled-and-waiting-next-tasks (not bh/hide-scheduled-and-waiting-next-tasks))
+  (when  (equal major-mode 'org-agenda-mode)
+    (org-agenda-redo))
+  (message "%s WAITING and SCHEDULED NEXT Tasks" (if bh/hide-scheduled-and-waiting-next-tasks "Hide" "Show")))
+
+(defun bh/skip-stuck-projects ()
+  "Skip trees that are not stuck projects"
+  (save-restriction
+    (widen)
+    (let ((next-headline (save-excursion (or (outline-next-heading) (point-max)))))
+      (if (bh/is-project-p)
+          (let* ((subtree-end (save-excursion (org-end-of-subtree t)))
+                 (has-next ))
+            (save-excursion
+              (forward-line 1)
+              (while (and (not has-next) (< (point) subtree-end) (re-search-forward "^\\*+ NEXT " subtree-end t))
+                (unless (member "WAITING" (org-get-tags-at))
+                  (setq has-next t))))
+            (if has-next
+                nil
+              next-headline)) ; a stuck project, has subtasks but no next task
+        nil))))
+
+(defun bh/skip-non-stuck-projects ()
+  "Skip trees that are not stuck projects"
+  ;; (bh/list-sublevels-for-projects-indented)
+  (save-restriction
+    (widen)
+    (let ((next-headline (save-excursion (or (outline-next-heading) (point-max)))))
+      (if (bh/is-project-p)
+          (let* ((subtree-end (save-excursion (org-end-of-subtree t)))
+                 (has-next ))
+            (save-excursion
+              (forward-line 1)
+              (while (and (not has-next) (< (point) subtree-end) (re-search-forward "^\\*+ NEXT " subtree-end t))
+                (unless (member "WAITING" (org-get-tags-at))
+                  (setq has-next t))))
+            (if has-next
+                next-headline
+              nil)) ; a stuck project, has subtasks but no next task
+        next-headline))))
+
+(defun bh/skip-non-projects ()
+  "Skip trees that are not projects"
+  ;; (bh/list-sublevels-for-projects-indented)
+  (if (save-excursion (bh/skip-non-stuck-projects))
+      (save-restriction
+        (widen)
+        (let ((subtree-end (save-excursion (org-end-of-subtree t))))
+          (cond
+           ((bh/is-project-p)
+            nil)
+           ((and (bh/is-project-subtree-p) (not (bh/is-task-p)))
+            nil)
+           (t
+            subtree-end))))
+    (save-excursion (org-end-of-subtree t))))
+
+(defun bh/skip-non-tasks ()
+  "Show non-project tasks.
+Skip project and sub-project tasks, habits, and project related tasks."
+  (save-restriction
+    (widen)
+    (let ((next-headline (save-excursion (or (outline-next-heading) (point-max)))))
+      (cond
+       ((bh/is-task-p)
+        nil)
+       (t
+        next-headline)))))
+
+(defun bh/skip-project-trees-and-habits ()
+  "Skip trees that are projects"
+  (save-restriction
+    (widen)
+    (let ((subtree-end (save-excursion (org-end-of-subtree t))))
+      (cond
+       ((bh/is-project-p)
+        subtree-end)
+       ((org-is-habit-p)
+        subtree-end)
+       (t
+        nil)))))
+
+(defun bh/skip-projects-and-habits-and-single-tasks ()
+  "Skip trees that are projects, tasks that are habits, single non-project tasks"
+  (save-restriction
+    (widen)
+    (let ((next-headline (save-excursion (or (outline-next-heading) (point-max)))))
+      (cond
+       ((org-is-habit-p)
+        next-headline)
+       ((and bh/hide-scheduled-and-waiting-next-tasks
+             (member "WAITING" (org-get-tags-at)))
+        next-headline)
+       ((bh/is-project-p)
+        next-headline)
+       ((and (bh/is-task-p) (not (bh/is-project-subtree-p)))
+        next-headline)
+       (t
+        nil)))))
+
+(defun bh/skip-project-tasks-maybe ()
+  "Show tasks related to the current restriction.
+When restricted to a project, skip project and sub project tasks, habits, NEXT tasks, and loose tasks.
+When not restricted, skip project and sub-project tasks, habits, and project related tasks."
+  (save-restriction
+    (widen)
+    (let* ((subtree-end (save-excursion (org-end-of-subtree t)))
+           (next-headline (save-excursion (or (outline-next-heading) (point-max))))
+           (limit-to-project (marker-buffer org-agenda-restrict-begin)))
+      (cond
+       ((bh/is-project-p)
+        next-headline)
+       ((org-is-habit-p)
+        subtree-end)
+       ((and (not limit-to-project)
+             (bh/is-project-subtree-p))
+        subtree-end)
+       ((and limit-to-project
+             (bh/is-project-subtree-p)
+             (member (org-get-todo-state) (list "NEXT")))
+        subtree-end)
+       (t
+        nil)))))
+
+(defun bh/skip-project-tasks ()
+  "Show non-project tasks.
+Skip project and sub-project tasks, habits, and project related tasks."
+  (save-restriction
+    (widen)
+    (let* ((subtree-end (save-excursion (org-end-of-subtree t))))
+      (cond
+       ((bh/is-project-p)
+        subtree-end)
+       ((org-is-habit-p)
+        subtree-end)
+       ((bh/is-project-subtree-p)
+        subtree-end)
+       (t
+        nil)))))
+
+(defun bh/skip-non-project-tasks ()
+  "Show project tasks.
+Skip project and sub-project tasks, habits, and loose non-project tasks."
+  (save-restriction
+    (widen)
+    (let* ((subtree-end (save-excursion (org-end-of-subtree t)))
+           (next-headline (save-excursion (or (outline-next-heading) (point-max)))))
+      (cond
+       ((bh/is-project-p)
+        next-headline)
+       ((org-is-habit-p)
+        subtree-end)
+       ((and (bh/is-project-subtree-p)
+             (member (org-get-todo-state) (list "NEXT")))
+        subtree-end)
+       ((not (bh/is-project-subtree-p))
+        subtree-end)
+       (t
+        nil)))))
+
+(defun bh/skip-projects-and-habits ()
+  "Skip trees that are projects and tasks that are habits"
+  (save-restriction
+    (widen)
+    (let ((subtree-end (save-excursion (org-end-of-subtree t))))
+      (cond
+       ((bh/is-project-p)
+        subtree-end)
+       ((org-is-habit-p)
+        subtree-end)
+       (t
+        nil)))))
+
+(defun bh/skip-non-subprojects ()
+  "Skip trees that are not projects"
+  (let ((next-headline (save-excursion (outline-next-heading))))
+    (if (bh/is-subproject-p)
+        nil
+      next-headline)))
+
+(setq org-archive-mark-done nil)
+(setq org-archive-location "%s_archive::* Archived Tasks")
+
+(defun bh/skip-non-archivable-tasks ()
+  "Skip trees that are not available for archiving"
+  (save-restriction
+    (widen)
+    ;; Consider only tasks with done todo headings as archivable candidates
+    (let ((next-headline (save-excursion (or (outline-next-heading) (point-max))))
+          (subtree-end (save-excursion (org-end-of-subtree t))))
+      (if (member (org-get-todo-state) org-todo-keywords-1)
+          (if (member (org-get-todo-state) org-done-keywords)
+              (let* ((daynr (string-to-number (format-time-string "%d" (current-time))))
+                     (a-month-ago (* 60 60 24 (+ daynr 1)))
+                     (last-month (format-time-string "%Y-%m-" (time-subtract (current-time) (seconds-to-time a-month-ago))))
+                     (this-month (format-time-string "%Y-%m-" (current-time)))
+                     (subtree-is-current (save-excursion
+                                           (forward-line 1)
+                                           (and (< (point) subtree-end)
+                                                (re-search-forward (concat last-month "\\|" this-month) subtree-end t)))))
+                (if subtree-is-current
+                    subtree-end ; Has a date in this month or last month, skip it
+                  nil))  ; available to archive
+            (or subtree-end (point-max)))
+        next-headline))))
+(setq org-alphabetical-lists t)
+
+;; Explicitly load required exporters
+(require 'ox-html)
+(require 'ox-latex)
+(require 'ox-ascii)
+
+(setq org-ditaa-jar-path "~/git/org-mode/contrib/scripts/ditaa.jar")
+(setq org-plantuml-jar-path "~/java/plantuml.jar")
+
+(add-hook 'org-babel-after-execute-hook 'bh/display-inline-images 'append)
+
+; Make babel results blocks lowercase
+(setq org-babel-results-keyword "results")
+
+(defun bh/display-inline-images ()
+  (condition-case nil
+      (org-display-inline-images)
+    (error nil)))
+
+(org-babel-do-load-languages
+ (quote org-babel-load-languages)
+ (quote ((emacs-lisp . t)
+         (dot . t)
+         (ditaa . t)
+         (R . t)
+         (python . t)
+         (ruby . t)
+         (gnuplot . t)
+         (clojure . t)
+         (shell . t)
+         (ledger . t)
+         (org . t)
+         (plantuml . t)
+         (latex . t))))
+
+; Do not prompt to confirm evaluation
+; This may be dangerous - make sure you understand the consequences
+; of setting this -- see the docstring for details
+(setq org-confirm-babel-evaluate nil)
+
+; Use fundamental mode when editing plantuml blocks with C-c '
+(add-to-list 'org-src-lang-modes (quote ("plantuml" . fundamental)))
+
+;; Don't enable this because it breaks access to emacs from my Android phone
+(setq org-startup-with-inline-images nil)
+
+; experimenting with docbook exports - not finished
+(setq org-export-docbook-xsl-fo-proc-command "fop %s %s")
+(setq org-export-docbook-xslt-proc-command "xsltproc --output %s /usr/share/xml/docbook/stylesheet/nwalsh/fo/docbook.xsl %s")
+;
+; Inline images in HTML instead of producting links to the image
+(setq org-html-inline-images t)
+; Do not use sub or superscripts - I currently don't need this functionality in my documents
+(setq org-export-with-sub-superscripts nil)
+; Use org.css from the norang website for export document stylesheets
+(setq org-html-head-extra "<link rel=\"stylesheet\" href=\"http://doc.norang.ca/org.css\" type=\"text/css\" />")
+(setq org-html-head-include-default-style nil)
+; Do not generate internal css formatting for HTML exports
+(setq org-export-htmlize-output-type (quote css))
+; Export with LaTeX fragments
+(setq org-export-with-LaTeX-fragments t)
+; Increase default number of headings to export
+(setq org-export-headline-levels 6)
+
+; List of projects
+; norang       - http://www.norang.ca/
+; doc          - http://doc.norang.ca/
+; org-mode-doc - http://doc.norang.ca/org-mode.html and associated files
+; org          - miscellaneous todo lists for publishing
+(setq org-publish-project-alist
+      ;
+      ; http://www.norang.ca/  (norang website)
+      ; norang-org are the org-files that generate the content
+      ; norang-extra are images and css files that need to be included
+      ; norang is the top-level project that gets published
+      (quote (("norang-org"
+               :base-directory "~/git/www.norang.ca"
+               :publishing-directory "/ssh:www-data@www:~/www.norang.ca/htdocs"
+               :recursive t
+               :table-of-contents nil
+               :base-extension "org"
+               :publishing-function org-html-publish-to-html
+               :style-include-default nil
+               :section-numbers nil
+               :table-of-contents nil
+               :html-head "<link rel=\"stylesheet\" href=\"norang.css\" type=\"text/css\" />"
+               :author-info nil
+               :creator-info nil)
+              ("norang-extra"
+               :base-directory "~/git/www.norang.ca/"
+               :publishing-directory "/ssh:www-data@www:~/www.norang.ca/htdocs"
+               :base-extension "css\\|pdf\\|png\\|jpg\\|gif"
+               :publishing-function org-publish-attachment
+               :recursive t
+               :author nil)
+              ("norang"
+               :components ("norang-org" "norang-extra"))
+              ;
+              ; http://doc.norang.ca/  (norang website)
+              ; doc-org are the org-files that generate the content
+              ; doc-extra are images and css files that need to be included
+              ; doc is the top-level project that gets published
+              ("doc-org"
+               :base-directory "~/git/doc.norang.ca/"
+               :publishing-directory "/ssh:www-data@www:~/doc.norang.ca/htdocs"
+               :recursive nil
+               :section-numbers nil
+               :table-of-contents nil
+               :base-extension "org"
+               :publishing-function (org-html-publish-to-html org-org-publish-to-org)
+               :style-include-default nil
+               :html-head "<link rel=\"stylesheet\" href=\"/org.css\" type=\"text/css\" />"
+               :author-info nil
+               :creator-info nil)
+              ("doc-extra"
+               :base-directory "~/git/doc.norang.ca/"
+               :publishing-directory "/ssh:www-data@www:~/doc.norang.ca/htdocs"
+               :base-extension "css\\|pdf\\|png\\|jpg\\|gif"
+               :publishing-function org-publish-attachment
+               :recursive nil
+               :author nil)
+              ("doc"
+               :components ("doc-org" "doc-extra"))
+              ("doc-private-org"
+               :base-directory "~/git/doc.norang.ca/private"
+               :publishing-directory "/ssh:www-data@www:~/doc.norang.ca/htdocs/private"
+               :recursive nil
+               :section-numbers nil
+               :table-of-contents nil
+               :base-extension "org"
+               :publishing-function (org-html-publish-to-html org-org-publish-to-org)
+               :style-include-default nil
+               :html-head "<link rel=\"stylesheet\" href=\"/org.css\" type=\"text/css\" />"
+               :auto-sitemap t
+               :sitemap-filename "index.html"
+               :sitemap-title "Norang Private Documents"
+               :sitemap-style "tree"
+               :author-info nil
+               :creator-info nil)
+              ("doc-private-extra"
+               :base-directory "~/git/doc.norang.ca/private"
+               :publishing-directory "/ssh:www-data@www:~/doc.norang.ca/htdocs/private"
+               :base-extension "css\\|pdf\\|png\\|jpg\\|gif"
+               :publishing-function org-publish-attachment
+               :recursive nil
+               :author nil)
+              ("doc-private"
+               :components ("doc-private-org" "doc-private-extra"))
+              ;
+              ; Miscellaneous pages for other websites
+              ; org are the org-files that generate the content
+              ("org-org"
+               :base-directory "~/git/org/"
+               :publishing-directory "/ssh:www-data@www:~/org"
+               :recursive t
+               :section-numbers nil
+               :table-of-contents nil
+               :base-extension "org"
+               :publishing-function org-html-publish-to-html
+               :style-include-default nil
+               :html-head "<link rel=\"stylesheet\" href=\"/org.css\" type=\"text/css\" />"
+               :author-info nil
+               :creator-info nil)
+              ;
+              ; http://doc.norang.ca/  (norang website)
+              ; org-mode-doc-org this document
+              ; org-mode-doc-extra are images and css files that need to be included
+              ; org-mode-doc is the top-level project that gets published
+              ; This uses the same target directory as the 'doc' project
+              ("org-mode-doc-org"
+               :base-directory "~/git/org-mode-doc/"
+               :publishing-directory "/ssh:www-data@www:~/doc.norang.ca/htdocs"
+               :recursive t
+               :section-numbers nil
+               :table-of-contents nil
+               :base-extension "org"
+               :publishing-function (org-html-publish-to-html)
+               :plain-source t
+               :htmlized-source t
+               :style-include-default nil
+               :html-head "<link rel=\"stylesheet\" href=\"/org.css\" type=\"text/css\" />"
+               :author-info nil
+               :creator-info nil)
+              ("org-mode-doc-extra"
+               :base-directory "~/git/org-mode-doc/"
+               :publishing-directory "/ssh:www-data@www:~/doc.norang.ca/htdocs"
+               :base-extension "css\\|pdf\\|png\\|jpg\\|gif\\|org"
+               :publishing-function org-publish-attachment
+               :recursive t
+               :author nil)
+              ("org-mode-doc"
+               :components ("org-mode-doc-org" "org-mode-doc-extra"))
+              ;
+              ; http://doc.norang.ca/  (norang website)
+              ; org-mode-doc-org this document
+              ; org-mode-doc-extra are images and css files that need to be included
+              ; org-mode-doc is the top-level project that gets published
+              ; This uses the same target directory as the 'doc' project
+              ("tmp-org"
+               :base-directory "/tmp/publish/"
+               :publishing-directory "/ssh:www-data@www:~/www.norang.ca/htdocs/tmp"
+               :recursive t
+               :section-numbers nil
+               :table-of-contents nil
+               :base-extension "org"
+               :publishing-function (org-html-publish-to-html org-org-publish-to-org)
+               :html-head "<link rel=\"stylesheet\" href=\"http://doc.norang.ca/org.css\" type=\"text/css\" />"
+               :plain-source t
+               :htmlized-source t
+               :style-include-default nil
+               :auto-sitemap t
+               :sitemap-filename "index.html"
+               :sitemap-title "Test Publishing Area"
+               :sitemap-style "tree"
+               :author-info t
+               :creator-info t)
+              ("tmp-extra"
+               :base-directory "/tmp/publish/"
+               :publishing-directory "/ssh:www-data@www:~/www.norang.ca/htdocs/tmp"
+               :base-extension "css\\|pdf\\|png\\|jpg\\|gif"
+               :publishing-function org-publish-attachment
+               :recursive t
+               :author nil)
+              ("tmp"
+               :components ("tmp-org" "tmp-extra")))))
+
+; I'm lazy and don't want to remember the name of the project to publish when I modify
+; a file that is part of a project.  So this function saves the file, and publishes
+; the project that includes this file
+;
+; It's bound to C-S-F12 so I just edit and hit C-S-F12 when I'm done and move on to the next thing
+(defun bh/save-then-publish (&optional force)
+  (interactive "P")
+  (save-buffer)
+  (org-save-all-org-buffers)
+  (let ((org-html-head-extra)
+        (org-html-validation-link "<a href=\"http://validator.w3.org/check?uri=referer\">Validate XHTML 1.0</a>"))
+    (org-publish-current-project force)))
+
+(global-set-key (kbd "C-s-<f12>") 'bh/save-then-publish)
+
+(setq org-latex-listings t)
+
+(setq org-html-xml-declaration (quote (("html" . "")
+                                       ("was-html" . "<?xml version=\"1.0\" encoding=\"%s\"?>")
+                                       ("php" . "<?php echo \"<?xml version=\\\"1.0\\\" encoding=\\\"%s\\\" ?>\"; ?>"))))
+
+(setq org-export-allow-BIND t)
+
+; Erase all reminders and rebuilt reminders for today from the agenda
+(defun bh/org-agenda-to-appt ()
+  (interactive)
+  (setq appt-time-msg-list nil)
+  (org-agenda-to-appt))
+
+; Rebuild the reminders everytime the agenda is displayed
+(add-hook 'org-finalize-agenda-hook 'bh/org-agenda-to-appt 'append)
+
+; This is at the end of my .emacs - so appointments are set up when Emacs starts
+(bh/org-agenda-to-appt)
+
+; Activate appointments so we get notifications
+(appt-activate t)
+
+; If we leave Emacs running overnight - reset the appointments one minute after midnight
+(run-at-time "24:01" nil 'bh/org-agenda-to-appt)
+
+;; Enable abbrev-mode
+(add-hook 'org-mode-hook (lambda () (abbrev-mode 1)))
+
+;; Skeletons
+;;
+;; sblk - Generic block #+begin_FOO .. #+end_FOO
+(define-skeleton skel-org-block
+  "Insert an org block, querying for type."
+  "Type: "
+  "#+begin_" str "\n"
+  _ - \n
+  "#+end_" str "\n")
+
+(define-abbrev org-mode-abbrev-table "sblk" "" 'skel-org-block)
+
+;; splantuml - PlantUML Source block
+(define-skeleton skel-org-block-plantuml
+  "Insert a org plantuml block, querying for filename."
+  "File (no extension): "
+  "#+begin_src plantuml :file " str ".png :cache yes\n"
+  _ - \n
+  "#+end_src\n")
+
+(define-abbrev org-mode-abbrev-table "splantuml" "" 'skel-org-block-plantuml)
+
+(define-skeleton skel-org-block-plantuml-activity
+  "Insert a org plantuml block, querying for filename."
+  "File (no extension): "
+  "#+begin_src plantuml :file " str "-act.png :cache yes :tangle " str "-act.txt\n"
+  (bh/plantuml-reset-counters)
+  "@startuml\n"
+  "skinparam activity {\n"
+  "BackgroundColor<<New>> Cyan\n"
+  "}\n\n"
+  "title " str " - \n"
+  "note left: " str "\n"
+  "(*) --> \"" str "\"\n"
+  "--> (*)\n"
+  _ - \n
+  "@enduml\n"
+  "#+end_src\n")
+
+(defvar bh/plantuml-if-count 0)
+
+(defun bh/plantuml-if ()
+  (incf bh/plantuml-if-count)
+  (number-to-string bh/plantuml-if-count))
+
+(defvar bh/plantuml-loop-count 0)
+
+(defun bh/plantuml-loop ()
+  (incf bh/plantuml-loop-count)
+  (number-to-string bh/plantuml-loop-count))
+
+(defun bh/plantuml-reset-counters ()
+  (setq bh/plantuml-if-count 0
+        bh/plantuml-loop-count 0)
+  "")
+
+(define-abbrev org-mode-abbrev-table "sact" "" 'skel-org-block-plantuml-activity)
+
+(define-skeleton skel-org-block-plantuml-activity-if
+  "Insert a org plantuml block activity if statement"
+  ""
+  "if \"\" then\n"
+  "  -> [condition] ==IF" (setq ifn (bh/plantuml-if)) "==\n"
+  "  --> ==IF" ifn "M1==\n"
+  "  -left-> ==IF" ifn "M2==\n"
+  "else\n"
+  "end if\n"
+  "--> ==IF" ifn "M2==")
+
+(define-abbrev org-mode-abbrev-table "sif" "" 'skel-org-block-plantuml-activity-if)
+
+(define-skeleton skel-org-block-plantuml-activity-for
+  "Insert a org plantuml block activity for statement"
+  "Loop for each: "
+  "--> ==LOOP" (setq loopn (bh/plantuml-loop)) "==\n"
+  "note left: Loop" loopn ": For each " str "\n"
+  "--> ==ENDLOOP" loopn "==\n"
+  "note left: Loop" loopn ": End for each " str "\n" )
+
+(define-abbrev org-mode-abbrev-table "sfor" "" 'skel-org-block-plantuml-activity-for)
+
+(define-skeleton skel-org-block-plantuml-sequence
+  "Insert a org plantuml activity diagram block, querying for filename."
+  "File appends (no extension): "
+  "#+begin_src plantuml :file " str "-seq.png :cache yes :tangle " str "-seq.txt\n"
+  "@startuml\n"
+  "title " str " - \n"
+  "actor CSR as \"Customer Service Representative\"\n"
+  "participant CSMO as \"CSM Online\"\n"
+  "participant CSMU as \"CSM Unix\"\n"
+  "participant NRIS\n"
+  "actor Customer"
+  _ - \n
+  "@enduml\n"
+  "#+end_src\n")
+
+(define-abbrev org-mode-abbrev-table "sseq" "" 'skel-org-block-plantuml-sequence)
+
+;; sdot - Graphviz DOT block
+(define-skeleton skel-org-block-dot
+  "Insert a org graphviz dot block, querying for filename."
+  "File (no extension): "
+  "#+begin_src dot :file " str ".png :cache yes :cmdline -Kdot -Tpng\n"
+  "graph G {\n"
+  _ - \n
+  "}\n"
+  "#+end_src\n")
+
+(define-abbrev org-mode-abbrev-table "sdot" "" 'skel-org-block-dot)
+
+;; sditaa - Ditaa source block
+(define-skeleton skel-org-block-ditaa
+  "Insert a org ditaa block, querying for filename."
+  "File (no extension): "
+  "#+begin_src ditaa :file " str ".png :cache yes\n"
+  _ - \n
+  "#+end_src\n")
+
+(define-abbrev org-mode-abbrev-table "sditaa" "" 'skel-org-block-ditaa)
+
+;; selisp - Emacs Lisp source block
+(define-skeleton skel-org-block-elisp
+  "Insert a org emacs-lisp block"
+  ""
+  "#+begin_src emacs-lisp\n"
+  _ - \n
+  "#+end_src\n")
+
+(define-abbrev org-mode-abbrev-table "selisp" "" 'skel-org-block-elisp)
+
+(defun bh/org-todo (arg)
+  (interactive "p")
+  (if (equal arg 4)
+      (save-restriction
+        (bh/narrow-to-org-subtree)
+        (org-show-todo-tree nil))
+    (bh/narrow-to-org-subtree)
+    (org-show-todo-tree nil)))
+
+(global-set-key (kbd "<S-f5>") 'bh/widen)
+
+(defun bh/widen ()
+  (interactive)
+  (if (equal major-mode 'org-agenda-mode)
+      (progn
+        (org-agenda-remove-restriction-lock)
+        (when org-agenda-sticky
+          (org-agenda-redo)))
+    (widen)))
+
+(add-hook 'org-agenda-mode-hook
+          '(lambda () (org-defkey org-agenda-mode-map "W" (lambda () (interactive) (setq bh/hide-scheduled-and-waiting-next-tasks t) (bh/widen))))
+          'append)
+
+(defun bh/restrict-to-file-or-follow (arg)
+  "Set agenda restriction to 'file or with argument invoke follow mode.
+I don't use follow mode very often but I restrict to file all the time
+so change the default 'F' binding in the agenda to allow both"
+  (interactive "p")
+  (if (equal arg 4)
+      (org-agenda-follow-mode)
+    (widen)
+    (bh/set-agenda-restriction-lock 4)
+    (org-agenda-redo)
+    (beginning-of-buffer)))
+
+(add-hook 'org-agenda-mode-hook
+          '(lambda () (org-defkey org-agenda-mode-map "F" 'bh/restrict-to-file-or-follow))
+          'append)
+
+(defun bh/narrow-to-org-subtree ()
+  (widen)
+  (org-narrow-to-subtree)
+  (save-restriction
+    (org-agenda-set-restriction-lock)))
+
+(defun bh/narrow-to-subtree ()
+  (interactive)
+  (if (equal major-mode 'org-agenda-mode)
+      (progn
+        (org-with-point-at (org-get-at-bol 'org-hd-marker)
+          (bh/narrow-to-org-subtree))
+        (when org-agenda-sticky
+          (org-agenda-redo)))
+    (bh/narrow-to-org-subtree)))
+
+(add-hook 'org-agenda-mode-hook
+          '(lambda () (org-defkey org-agenda-mode-map "N" 'bh/narrow-to-subtree))
+          'append)
+
+(defun bh/narrow-up-one-org-level ()
+  (widen)
+  (save-excursion
+    (outline-up-heading 1 'invisible-ok)
+    (bh/narrow-to-org-subtree)))
+
+(defun bh/get-pom-from-agenda-restriction-or-point ()
+  (or (and (marker-position org-agenda-restrict-begin) org-agenda-restrict-begin)
+      (org-get-at-bol 'org-hd-marker)
+      (and (equal major-mode 'org-mode) (point))
+      org-clock-marker))
+
+(defun bh/narrow-up-one-level ()
+  (interactive)
+  (if (equal major-mode 'org-agenda-mode)
+      (progn
+        (org-with-point-at (bh/get-pom-from-agenda-restriction-or-point)
+          (bh/narrow-up-one-org-level))
+        (org-agenda-redo))
+    (bh/narrow-up-one-org-level)))
+
+(add-hook 'org-agenda-mode-hook
+          '(lambda () (org-defkey org-agenda-mode-map "U" 'bh/narrow-up-one-level))
+          'append)
+
+(defun bh/narrow-to-org-project ()
+  (widen)
+  (save-excursion
+    (bh/find-project-task)
+    (bh/narrow-to-org-subtree)))
+
+(defun bh/narrow-to-project ()
+  (interactive)
+  (if (equal major-mode 'org-agenda-mode)
+      (progn
+        (org-with-point-at (bh/get-pom-from-agenda-restriction-or-point)
+          (bh/narrow-to-org-project)
+          (save-excursion
+            (bh/find-project-task)
+            (org-agenda-set-restriction-lock)))
+        (org-agenda-redo)
+        (beginning-of-buffer))
+    (bh/narrow-to-org-project)
+    (save-restriction
+      (org-agenda-set-restriction-lock))))
+
+(add-hook 'org-agenda-mode-hook
+          '(lambda () (org-defkey org-agenda-mode-map "P" 'bh/narrow-to-project))
+          'append)
+
+(defvar bh/project-list nil)
+
+(defun bh/view-next-project ()
+  (interactive)
+  (let (num-project-left current-project)
+    (unless (marker-position org-agenda-restrict-begin)
+      (goto-char (point-min))
+      ; Clear all of the existing markers on the list
+      (while bh/project-list
+        (set-marker (pop bh/project-list) nil))
+      (re-search-forward "Tasks to Refile")
+      (forward-visible-line 1))
+
+    ; Build a new project marker list
+    (unless bh/project-list
+      (while (< (point) (point-max))
+        (while (and (< (point) (point-max))
+                    (or (not (org-get-at-bol 'org-hd-marker))
+                        (org-with-point-at (org-get-at-bol 'org-hd-marker)
+                          (or (not (bh/is-project-p))
+                              (bh/is-project-subtree-p)))))
+          (forward-visible-line 1))
+        (when (< (point) (point-max))
+          (add-to-list 'bh/project-list (copy-marker (org-get-at-bol 'org-hd-marker)) 'append))
+        (forward-visible-line 1)))
+
+    ; Pop off the first marker on the list and display
+    (setq current-project (pop bh/project-list))
+    (when current-project
+      (org-with-point-at current-project
+        (setq bh/hide-scheduled-and-waiting-next-tasks nil)
+        (bh/narrow-to-project))
+      ; Remove the marker
+      (setq current-project nil)
+      (org-agenda-redo)
+      (beginning-of-buffer)
+      (setq num-projects-left (length bh/project-list))
+      (if (> num-projects-left 0)
+          (message "%s projects left to view" num-projects-left)
+        (beginning-of-buffer)
+        (setq bh/hide-scheduled-and-waiting-next-tasks t)
+        (error "All projects viewed.")))))
+
+(add-hook 'org-agenda-mode-hook
+          '(lambda () (org-defkey org-agenda-mode-map "V" 'bh/view-next-project))
+          'append)
+
+(setq org-show-entry-below (quote ((default))))
+
+(add-hook 'org-agenda-mode-hook
+          '(lambda () (org-defkey org-agenda-mode-map "\C-c\C-x<" 'bh/set-agenda-restriction-lock))
+          'append)
+
+(defun bh/set-agenda-restriction-lock (arg)
+  "Set restriction lock to current task subtree or file if prefix is specified"
+  (interactive "p")
+  (let* ((pom (bh/get-pom-from-agenda-restriction-or-point))
+         (tags (org-with-point-at pom (org-get-tags-at))))
+    (let ((restriction-type (if (equal arg 4) 'file 'subtree)))
+      (save-restriction
+        (cond
+         ((and (equal major-mode 'org-agenda-mode) pom)
+          (org-with-point-at pom
+            (org-agenda-set-restriction-lock restriction-type))
+          (org-agenda-redo))
+         ((and (equal major-mode 'org-mode) (org-before-first-heading-p))
+          (org-agenda-set-restriction-lock 'file))
+         (pom
+          (org-with-point-at pom
+            (org-agenda-set-restriction-lock restriction-type))))))))
+
+;; Limit restriction lock highlighting to the headline only
+(setq org-agenda-restriction-lock-highlight-subtree nil)
+
+;; Always hilight the current agenda line
+(add-hook 'org-agenda-mode-hook
+          '(lambda () (hl-line-mode 1))
+          'append)
+
+;; Keep tasks with dates on the global todo lists
+(setq org-agenda-todo-ignore-with-date nil)
+
+;; Keep tasks with deadlines on the global todo lists
+(setq org-agenda-todo-ignore-deadlines nil)
+
+;; Keep tasks with scheduled dates on the global todo lists
+(setq org-agenda-todo-ignore-scheduled nil)
+
+;; Keep tasks with timestamps on the global todo lists
+(setq org-agenda-todo-ignore-timestamp nil)
+
+;; Remove completed deadline tasks from the agenda view
+(setq org-agenda-skip-deadline-if-done t)
+
+;; Remove completed scheduled tasks from the agenda view
+(setq org-agenda-skip-scheduled-if-done t)
+
+;; Remove completed items from search results
+(setq org-agenda-skip-timestamp-if-done t)
+
+(setq org-agenda-include-diary nil)
+(setq org-agenda-diary-file "~/git/org/diary.org")
+
+(setq org-agenda-insert-diary-extract-time t)
+
+;; Include agenda archive files when searching for things
+(setq org-agenda-text-search-extra-files (quote (agenda-archives)))
+
+;; Show all future entries for repeating tasks
+(setq org-agenda-repeating-timestamp-show-all t)
+
+;; Show all agenda dates - even if they are empty
+(setq org-agenda-show-all-dates t)
+
+;; Sorting order for tasks on the agenda
+(setq org-agenda-sorting-strategy
+      (quote ((agenda habit-down time-up user-defined-up effort-up category-keep)
+              (todo category-up effort-up)
+              (tags category-up effort-up)
+              (search category-up))))
+
+;; Start the weekly agenda on Monday
+(setq org-agenda-start-on-weekday 1)
+
+;; Enable display of the time grid so we can see the marker for the current time
+;; modified like in
+;; https://stackoverflow.com/questions/47778775/wrong-type-argument-when-using-org-agenda
+(setq org-agenda-time-grid (quote
+                             ((daily today remove-match)
+                              (0900 1100 1300 1500 1700)
+                              "......" "----------------")))
+
+;; Display tags farther right
+(setq org-agenda-tags-column -102)
+
+;;
+;; Agenda sorting functions
+;;
+(setq org-agenda-cmp-user-defined 'bh/agenda-sort)
+
+(defun bh/agenda-sort (a b)
+  "Sorting strategy for agenda items.
+Late deadlines first, then scheduled, then non-late deadlines"
+  (let (result num-a num-b)
+    (cond
+     ; time specific items are already sorted first by org-agenda-sorting-strategy
+
+     ; non-deadline and non-scheduled items next
+     ((bh/agenda-sort-test 'bh/is-not-scheduled-or-deadline a b))
+
+     ; deadlines for today next
+     ((bh/agenda-sort-test 'bh/is-due-deadline a b))
+
+     ; late deadlines next
+     ((bh/agenda-sort-test-num 'bh/is-late-deadline '> a b))
+
+     ; scheduled items for today next
+     ((bh/agenda-sort-test 'bh/is-scheduled-today a b))
+
+     ; late scheduled items next
+     ((bh/agenda-sort-test-num 'bh/is-scheduled-late '> a b))
+
+     ; pending deadlines last
+     ((bh/agenda-sort-test-num 'bh/is-pending-deadline '< a b))
+
+     ; finally default to unsorted
+     (t (setq result nil)))
+    result))
+
+(defmacro bh/agenda-sort-test (fn a b)
+  "Test for agenda sort"
+  `(cond
+    ; if both match leave them unsorted
+    ((and (apply ,fn (list ,a))
+          (apply ,fn (list ,b)))
+     (setq result nil))
+    ; if a matches put a first
+    ((apply ,fn (list ,a))
+     (setq result -1))
+    ; otherwise if b matches put b first
+    ((apply ,fn (list ,b))
+     (setq result 1))
+    ; if none match leave them unsorted
+    (t nil)))
+
+(defmacro bh/agenda-sort-test-num (fn compfn a b)
+  `(cond
+    ((apply ,fn (list ,a))
+     (setq num-a (string-to-number (match-string 1 ,a)))
+     (if (apply ,fn (list ,b))
+         (progn
+           (setq num-b (string-to-number (match-string 1 ,b)))
+           (setq result (if (apply ,compfn (list num-a num-b))
+                            -1
+                          1)))
+       (setq result -1)))
+    ((apply ,fn (list ,b))
+     (setq result 1))
+    (t nil)))
+
+(defun bh/is-not-scheduled-or-deadline (date-str)
+  (and (not (bh/is-deadline date-str))
+       (not (bh/is-scheduled date-str))))
+
+(defun bh/is-due-deadline (date-str)
+  (string-match "Deadline:" date-str))
+
+(defun bh/is-late-deadline (date-str)
+  (string-match "\\([0-9]*\\) d\. ago:" date-str))
+
+(defun bh/is-pending-deadline (date-str)
+  (string-match "In \\([^-]*\\)d\.:" date-str))
+
+(defun bh/is-deadline (date-str)
+  (or (bh/is-due-deadline date-str)
+      (bh/is-late-deadline date-str)
+      (bh/is-pending-deadline date-str)))
+
+(defun bh/is-scheduled (date-str)
+  (or (bh/is-scheduled-today date-str)
+      (bh/is-scheduled-late date-str)))
+
+(defun bh/is-scheduled-today (date-str)
+  (string-match "Scheduled:" date-str))
+
+(defun bh/is-scheduled-late (date-str)
+  (string-match "Sched\.\\(.*\\)x:" date-str))
+
+;; Use sticky agenda's so they persist
+(setq org-agenda-sticky t)
+
+;; The following setting is different from the document so that you
+;; can override the document path by setting your path in the variable
+;; org-mode-user-contrib-lisp-path
+;;
+(if (boundp 'org-mode-user-contrib-lisp-path)
+    (add-to-list 'load-path org-mode-user-contrib-lisp-path)
+  (add-to-list 'load-path (expand-file-name "~/git/org-mode/contrib/lisp")))
+
+(require 'org-checklist)
+
+(setq org-enforce-todo-dependencies t)
+
+(setq org-hide-leading-stars nil)
+
+(setq org-startup-indented t)
+
+(setq org-cycle-separator-lines 0)
+
+(setq org-blank-before-new-entry (quote ((heading)
+                                         (plain-list-item . auto))))
+
+(setq org-insert-heading-respect-content nil)
+
+(setq org-reverse-note-order nil)
+
+(setq org-show-following-heading t)
+(setq org-show-hierarchy-above t)
+(setq org-show-siblings (quote ((default))))
+
+(setq org-special-ctrl-a/e t)
+(setq org-special-ctrl-k t)
+(setq org-yank-adjusted-subtrees t)
+
+(setq org-id-method (quote uuidgen))
+
+(setq org-deadline-warning-days 30)
+
+(setq org-table-export-default-format "orgtbl-to-csv")
+
+(setq org-link-frame-setup (quote ((vm . vm-visit-folder)
+                                   (gnus . org-gnus-no-new-news)
+                                   (file . find-file))))
+
+; Use the current window for C-c ' source editing
+(setq org-src-window-setup 'current-window)
+
+(setq org-log-done (quote time))
+(setq org-log-into-drawer t)
+(setq org-log-state-notes-insert-after-drawers nil)
+
+(setq org-clock-sound "/usr/local/lib/tngchime.wav")
+
+; Enable habit tracking (and a bunch of other modules)
+(setq org-modules (quote (org-bbdb
+                          org-bibtex
+                          org-crypt
+                          org-gnus
+                          org-id
+                          org-info
+                          org-jsinfo
+                          org-habit
+                          org-inlinetask
+                          org-irc
+                          org-mew
+                          org-mhe
+                          org-protocol
+                          org-rmail
+                          org-vm
+                          org-wl
+                          org-w3m)))
+
+; position the habit graph on the agenda to the right of the default
+(setq org-habit-graph-column 50)
+
+(run-at-time "06:00" 86400 '(lambda () (setq org-habit-show-habits t)))
+
+(global-auto-revert-mode t)
+
+(require 'org-crypt)
+; Encrypt all entries before saving
+(org-crypt-use-before-save-magic)
+(setq org-tags-exclude-from-inheritance (quote ("crypt")))
+; GPG key to use for encryption
+(setq org-crypt-key "F0B66B40")
+
+(setq org-crypt-disable-auto-save nil)
+
+(setq org-use-speed-commands t)
+(setq org-speed-commands-user (quote (("0" . ignore)
+                                      ("1" . ignore)
+                                      ("2" . ignore)
+                                      ("3" . ignore)
+                                      ("4" . ignore)
+                                      ("5" . ignore)
+                                      ("6" . ignore)
+                                      ("7" . ignore)
+                                      ("8" . ignore)
+                                      ("9" . ignore)
+
+                                      ("a" . ignore)
+                                      ("d" . ignore)
+                                      ("h" . bh/hide-other)
+                                      ("i" progn
+                                       (forward-char 1)
+                                       (call-interactively 'org-insert-heading-respect-content))
+                                      ("k" . org-kill-note-or-show-branches)
+                                      ("l" . ignore)
+                                      ("m" . ignore)
+                                      ("q" . bh/show-org-agenda)
+                                      ("r" . ignore)
+                                      ("s" . org-save-all-org-buffers)
+                                      ("w" . org-refile)
+                                      ("x" . ignore)
+                                      ("y" . ignore)
+                                      ("z" . org-add-note)
+
+                                      ("A" . ignore)
+                                      ("B" . ignore)
+                                      ("E" . ignore)
+                                      ("F" . bh/restrict-to-file-or-follow)
+                                      ("G" . ignore)
+                                      ("H" . ignore)
+                                      ("J" . org-clock-goto)
+                                      ("K" . ignore)
+                                      ("L" . ignore)
+                                      ("M" . ignore)
+                                      ("N" . bh/narrow-to-org-subtree)
+                                      ("P" . bh/narrow-to-org-project)
+                                      ("Q" . ignore)
+                                      ("R" . ignore)
+                                      ("S" . ignore)
+                                      ("T" . bh/org-todo)
+                                      ("U" . bh/narrow-up-one-org-level)
+                                      ("V" . ignore)
+                                      ("W" . bh/widen)
+                                      ("X" . ignore)
+                                      ("Y" . ignore)
+                                      ("Z" . ignore))))
+
+(defun bh/show-org-agenda ()
+  (interactive)
+  (if org-agenda-sticky
+      (switch-to-buffer "*Org Agenda( )*")
+    (switch-to-buffer "*Org Agenda*"))
+  (delete-other-windows))
+
+(require 'org-protocol)
+
+(setq require-final-newline t)
+
+(defvar bh/insert-inactive-timestamp t)
+
+(defun bh/toggle-insert-inactive-timestamp ()
+  (interactive)
+  (setq bh/insert-inactive-timestamp (not bh/insert-inactive-timestamp))
+  (message "Heading timestamps are %s" (if bh/insert-inactive-timestamp "ON" "OFF")))
+
+(defun bh/insert-inactive-timestamp ()
+  (interactive)
+  (org-insert-time-stamp nil t t nil nil nil))
+
+(defun bh/insert-heading-inactive-timestamp ()
+  (save-excursion
+    (when bh/insert-inactive-timestamp
+      (org-return)
+      (org-cycle)
+      (bh/insert-inactive-timestamp))))
+
+(add-hook 'org-insert-heading-hook 'bh/insert-heading-inactive-timestamp 'append)
+
+(setq org-export-with-timestamps nil)
+
+(setq org-return-follows-link t)
+
+(custom-set-faces
+  ;; custom-set-faces was added by Custom.
+  ;; If you edit it by hand, you could mess it up, so be careful.
+  ;; Your init file should contain only one such instance.
+  ;; If there is more than one, they won't work right.
+ '(org-mode-line-clock ((t (:foreground "red" :box (:line-width -1 :style released-button)))) t))
+
+(defun bh/prepare-meeting-notes ()
+  "Prepare meeting notes for email
+   Take selected region and convert tabs to spaces, mark TODOs with leading >>>, and copy to kill ring for pasting"
+  (interactive)
+  (let (prefix)
+    (save-excursion
+      (save-restriction
+        (narrow-to-region (region-beginning) (region-end))
+        (untabify (point-min) (point-max))
+        (goto-char (point-min))
+        (while (re-search-forward "^\\( *-\\\) \\(TODO\\|DONE\\): " (point-max) t)
+          (replace-match (concat (make-string (length (match-string 1)) ?>) " " (match-string 2) ": ")))
+        (goto-char (point-min))
+        (kill-ring-save (point-min) (point-max))))))
+
+(setq org-remove-highlights-with-change t)
+
+(add-to-list 'Info-default-directory-list "~/git/org-mode/doc")
+
+(setq org-read-date-prefer-future 'time)
+
+(setq org-list-demote-modify-bullet (quote (("+" . "-")
+                                            ("*" . "-")
+                                            ("1." . "-")
+                                            ("1)" . "-")
+                                            ("A)" . "-")
+                                            ("B)" . "-")
+                                            ("a)" . "-")
+                                            ("b)" . "-")
+                                            ("A." . "-")
+                                            ("B." . "-")
+                                            ("a." . "-")
+                                            ("b." . "-"))))
+
+(setq org-tags-match-list-sublevels t)
+
+(setq org-agenda-persistent-filter t)
+
+(setq org-link-mailto-program (quote (compose-mail "%a" "%s")))
+
+(add-to-list 'load-path (expand-file-name "~/.emacs.d"))
+(require 'smex)
+(smex-initialize)
+
+(global-set-key (kbd "M-x") 'smex)
+(global-set-key (kbd "C-x x") 'smex)
+(global-set-key (kbd "M-X") 'smex-major-mode-commands)
+
+;; Bookmark handling
+;;
+(global-set-key (kbd "<C-f6>") '(lambda () (interactive) (bookmark-set "SAVED")))
+
+(require 'org-mime)
+
+(setq org-agenda-skip-additional-timestamps-same-entry t)
+
+(setq org-table-use-standard-references (quote from))
+
+(setq org-file-apps (quote ((auto-mode . emacs)
+                            ("\\.mm\\'" . system)
+                            ("\\.x?html?\\'" . system)
+                            ("\\.pdf\\'" . system))))
+
+; Overwrite the current window with the agenda
+(setq org-agenda-window-setup 'current-window)
+
+(setq org-clone-delete-id t)
+
+(setq org-cycle-include-plain-lists t)
+
+(setq org-src-fontify-natively t)
+
+(setq org-structure-template-alist
+      (quote (("s" "#+begin_src ?\n\n#+end_src" "<src lang=\"?\">\n\n</src>")
+              ("e" "#+begin_example\n?\n#+end_example" "<example>\n?\n</example>")
+              ("q" "#+begin_quote\n?\n#+end_quote" "<quote>\n?\n</quote>")
+              ("v" "#+begin_verse\n?\n#+end_verse" "<verse>\n?\n</verse>")
+              ("c" "#+begin_center\n?\n#+end_center" "<center>\n?\n</center>")
+              ("l" "#+begin_latex\n?\n#+end_latex" "<literal style=\"latex\">\n?\n</literal>")
+              ("L" "#+latex: " "<literal style=\"latex\">?</literal>")
+              ("h" "#+begin_html\n?\n#+end_html" "<literal style=\"html\">\n?\n</literal>")
+              ("H" "#+html: " "<literal style=\"html\">?</literal>")
+              ("a" "#+begin_ascii\n?\n#+end_ascii")
+              ("A" "#+ascii: ")
+              ("i" "#+index: ?" "#+index: ?")
+              ("I" "#+include %file ?" "<include file=%file markup=\"?\">"))))
+
+(defun bh/mark-next-parent-tasks-todo ()
+  "Visit each parent task and change NEXT states to TODO"
+  (let ((mystate (or (and (fboundp 'org-state)
+                          state)
+                     (nth 2 (org-heading-components)))))
+    (when mystate
+      (save-excursion
+        (while (org-up-heading-safe)
+          (when (member (nth 2 (org-heading-components)) (list "NEXT"))
+            (org-todo "TODO")))))))
+
+(add-hook 'org-after-todo-state-change-hook 'bh/mark-next-parent-tasks-todo 'append)
+(add-hook 'org-clock-in-hook 'bh/mark-next-parent-tasks-todo 'append)
+
+(setq org-startup-folded t)
+
+(add-hook 'message-mode-hook 'orgstruct++-mode 'append)
+(add-hook 'message-mode-hook 'turn-on-auto-fill 'append)
+(add-hook 'message-mode-hook 'bbdb-define-all-aliases 'append)
+(add-hook 'message-mode-hook 'orgtbl-mode 'append)
+; (add-hook 'message-mode-hook 'turn-on-flyspell 'append) ; aspell needs nix fix
+(add-hook 'message-mode-hook
+          '(lambda () (setq fill-column 72))
+          'append)
+
+;; flyspell mode for spell checking everywhere
+; (add-hook 'org-mode-hook 'turn-on-flyspell 'append) ; aspell needs nix fix
+
+;; Disable keys in org-mode
+;;    C-c [
+;;    C-c ]
+;;    C-c ;
+;;    C-c C-x C-q  cancelling the clock (we never want this)
+(add-hook 'org-mode-hook
+          '(lambda ()
+             ;; Undefine C-c [ and C-c ] since this breaks my
+             ;; org-agenda files when directories are include It
+             ;; expands the files in the directories individually
+             (org-defkey org-mode-map "\C-c[" 'undefined)
+             (org-defkey org-mode-map "\C-c]" 'undefined)
+             (org-defkey org-mode-map "\C-c;" 'undefined)
+             (org-defkey org-mode-map "\C-c\C-x\C-q" 'undefined))
+          'append)
+
+(add-hook 'org-mode-hook
+          (lambda ()
+            (local-set-key (kbd "C-c M-o") 'bh/mail-subtree))
+          'append)
+
+(defun bh/mail-subtree ()
+  (interactive)
+  (org-mark-subtree)
+  (org-mime-subtree))
+
+(setq org-src-preserve-indentation nil)
+(setq org-edit-src-content-indentation 0)
+
+(setq org-catch-invisible-edits 'error)
+
+(setq org-export-coding-system 'utf-8)
+(prefer-coding-system 'utf-8)
+(set-charset-priority 'unicode)
+(setq default-process-coding-system '(utf-8-unix . utf-8-unix))
+
+(setq org-time-clocksum-format
+      '(:hours "%d" :require-hours t :minutes ":%02d" :require-minutes t))
+
+(setq org-id-link-to-org-use-id 'create-if-interactive-and-no-custom-id)
+
+(setq org-emphasis-alist (quote (("*" bold "<b>" "</b>")
+                                 ("/" italic "<i>" "</i>")
+                                 ("_" underline "<span style=\"text-decoration:underline;\">" "</span>")
+                                 ("=" org-code "<code>" "</code>" verbatim)
+                                 ("~" org-verbatim "<code>" "</code>" verbatim))))
+
+(setq org-use-sub-superscripts nil)
+
+(setq org-odd-levels-only nil)
+
+(run-at-time "00:59" 3600 'org-save-all-org-buffers)
+
+;; --- ombi's extension
+
+;; found on https://www.reddit.com/r/emacs/comments/8yrklz/using_outlinemode_with_org_agenda/
+(add-hook
+ 'org-agenda-mode-hook
+ (lambda ()
+   (setq-local outline-regexp "^[A-Z]")
+   (setq-local outline-heading-end-regexp ".$")
+   ;; Any prefix you'd like, though C-' is usually unoccupied.
+   (setq-local outline-minor-mode-prefix (kbd "C-'"))
+   (local-set-key "a" 'outline-toggle-children)
+   (outline-minor-mode +1)
+   (local-set-key outline-minor-mode-prefix outline-mode-prefix-map)))
+'';
+in
+  modifiedBerndHansen
diff --git a/jeschli/2configs/emacs.nix b/jeschli/2configs/emacs.nix
index 4f5b690f2..bc9cfdb4b 100644
--- a/jeschli/2configs/emacs.nix
+++ b/jeschli/2configs/emacs.nix
@@ -1,6 +1,8 @@
 { config, pkgs, ... }:
 
 let
+  orgAgendaView = import ./emacs-org-agenda.nix;
+
   packageRepos = ''
     (require 'package) ;; You might already have this line
     (let* ((no-ssl (and (memq system-type '(windows-nt ms-dos))
@@ -28,6 +30,7 @@ let
   '';
 
   goMode = ''
+    (setq godoc-and-godef-command "go doc") ;godoc has no cli support any more, thats go doc now
     (add-to-list 'exec-path "~/go/bin")
     (add-hook 'go-mode-hook
     (lambda ()
@@ -42,6 +45,10 @@ let
     (ido-mode t)
   '';
 
+  magit = ''
+    (global-set-key (kbd "C-x g") 'magit-status) ; "Most Magit commands are commonly invoked from the status buffer"
+  '';
+
   windowCosmetics = ''
     (menu-bar-mode -1)
     (tool-bar-mode -1)                  ; Disable the button bar atop screen
@@ -65,12 +72,53 @@ let
     (setq org-link-frame-setup '((file . find-file))) ; open link in same frame.
     (if (boundp 'org-user-agenda-files)
       (setq org-agenda-files org-user-agenda-files)
-      (setq org-agenda-files (quote ("~/projects/notes")))
+      (setq org-agenda-files (quote ("~/projects/notes_privat")))
     )
   '';
 
   theme = ''
     (load-theme 'monokai-alt t)
+    (load-theme 'whiteboard t)
+    (disable-theme 'monokai-alt)
+    (disable-theme 'whiteboard)
+
+    (defun mh/load-whiteboard-theme ()
+      "load whiteboard theme"
+      (interactive)
+      (message "whiteboard loaded")
+      (disable-theme 'monokai-alt)
+      (enable-theme 'whiteboard)
+    )
+
+    (defun mh/load-monokai-theme ()
+      "load monokai theme"
+      (interactive)
+      (message "monokai loaded")
+      (disable-theme 'whiteboard)
+      (enable-theme 'monokai-alt)
+    )
+
+    (global-set-key "\C-ctw" 'mh/load-whiteboard-theme)
+    (global-set-key "\C-ctm" 'mh/load-monokai-theme)
+  '';
+
+  # Configuration for rust development
+  # inspired by
+  # https://github.com/bbatsov/prelude/blob/master/modules/prelude-rust.el
+  #
+  # This requires rls and racer to be installed on the system
+  rustDevelopment = ''
+    (add-hook 'rust-mode-hook #'racer-mode)
+    (add-hook 'rust-mode-hook (lambda()
+      (local-set-key (kbd "C-c C-d") 'racer-describe)
+      (local-set-key (kbd "C-c .") 'racer-find-definition)
+      (local-set-key (kbd "C-c ,") 'pop-tag-mark))
+    )
+    (add-hook 'racer-mode-hook #'eldoc-mode)
+    (add-hook 'racer-mode-hook #'company-mode)
+    (require 'rust-mode)
+    (define-key rust-mode-map (kbd "TAB") #'company-indent-or-complete-common)
+    (setq company-tooltip-align-annotations t)
   '';
 
   recentFiles = ''
@@ -79,27 +127,75 @@ let
     (global-set-key "\C-x\ \C-r" 'recentf-open-files)
   '';
 
+  myFunctionKeys = ''
+    (fset 'kill-actual-buffer
+      [?\C-x ?k return])
+
+    (defun mh/open-term-and-rename (name)
+      "open a new bash and rename it"
+      (interactive "sName of new terminal: ")
+      (term "/run/current-system/sw/bin/bash")
+      (rename-buffer name)
+    )
+    (global-set-key (kbd "M-<f8>") 'kill-actual-buffer)
+
+    (global-set-key (kbd "<f5>") 'mh/open-term-and-rename)
+    (global-set-key (kbd "<f6>") 'other-window)
+    (global-set-key (kbd "<f7>") 'split-window-right)
+    (global-set-key (kbd "<f8>") 'delete-other-windows)
+  '';
+
+
+
   dotEmacs = pkgs.writeText "dot-emacs" ''
+    ${packageRepos}
+
     ${evilMode}
     ${goMode}
     ${ido}
-    ${packageRepos}
+    ${magit}
     ${orgMode}
     ${recentFiles}
+    ${rustDevelopment}
     ${theme}
     ${windowCosmetics}
+
+    ${orgAgendaView}
+    ${myFunctionKeys}
   '';
 
   emacsWithCustomPackages = (pkgs.emacsPackagesNgGen pkgs.emacs).emacsWithPackages (epkgs: [
+#testing
+    epkgs.melpaPackages.gitlab
+
+# emacs convenience
     epkgs.melpaPackages.ag
+    epkgs.melpaPackages.company
+    epkgs.melpaPackages.direnv
     epkgs.melpaPackages.evil
+    epkgs.melpaPackages.google-this
+    epkgs.melpaPackages.monokai-alt-theme
+
+# development
     epkgs.melpaStablePackages.magit
     epkgs.melpaPackages.nix-mode
     epkgs.melpaPackages.go-mode
     epkgs.melpaPackages.haskell-mode
-    epkgs.melpaPackages.google-this
-    epkgs.melpaPackages.monokai-alt-theme
+# rust
     epkgs.melpaPackages.rust-mode
+    epkgs.melpaPackages.flycheck-rust
+    epkgs.melpaPackages.racer
+
+# python
+    epkgs.melpaPackages.elpy
+
+# org-mode
+    epkgs.elpaPackages.bbdb
+    epkgs.orgPackages.org-plus-contrib
+    epkgs.melpaPackages.smex
+    epkgs.melpaPackages.org-mime
+
+    epkgs.elpaPackages.which-key
   ]);
 
   myEmacs = pkgs.writeDashBin "my-emacs" ''
diff --git a/jeschli/2configs/i3.nix b/jeschli/2configs/i3.nix
new file mode 100644
index 000000000..f062daec3
--- /dev/null
+++ b/jeschli/2configs/i3.nix
@@ -0,0 +1,248 @@
+{pkgs, environment, config, lib, ... }:
+
+with pkgs;
+
+let
+
+  i3_conf_file =  pkgs.writeText "config" ''
+
+  # i3 config file (v4)
+  # doc: https://i3wm.org/docs/userguide.html
+
+  set $mod Mod4
+
+  # Font for window titles. Will also be used by the bar unless a different font
+  # is used in the bar {} block below.
+  font pango:monospace 8
+
+  # Use Mouse+$mod to drag floating windows to their wanted position
+  floating_modifier $mod
+
+  # start a terminal
+  bindsym $mod+Return exec i3-sensible-terminal
+
+  # kill focused window
+  bindsym $mod+Shift+q kill
+
+  # start rofi program launcher
+  bindsym $mod+d exec ${pkgs.rofi}/bin/rofi -modi drun#run -combi-modi drun#run -show combi -show-icons -display-combi run
+  # Switch windows with rofi
+  bindsym $mod+x exec ${pkgs.rofi}/bin/rofi -modi window -show window -auto-select
+
+  # There also is the (new) i3-dmenu-desktop which only displays applications
+  # shipping a .desktop file. It is a wrapper around dmenu, so you need that
+  # installed.
+  # bindsym $mod+d exec --no-startup-id i3-dmenu-desktop
+
+  # change focus
+  bindsym $mod+j focus left
+  bindsym $mod+k focus down
+  bindsym $mod+l focus up
+  bindsym $mod+semicolon focus right
+
+  # alternatively, you can use the cursor keys:
+  bindsym $mod+Left focus left
+  bindsym $mod+Down focus down
+  bindsym $mod+Up focus up
+  bindsym $mod+Right focus right
+
+  # move focused window
+  bindsym $mod+Shift+j move left
+  bindsym $mod+Shift+k move down
+  bindsym $mod+Shift+l move up
+  bindsym $mod+Shift+semicolon move right
+
+  # alternatively, you can use the cursor keys:
+  bindsym $mod+Shift+Left move left
+  bindsym $mod+Shift+Down move down
+  bindsym $mod+Shift+Up move up
+  bindsym $mod+Shift+Right move right
+
+  # split in horizontal orientation
+  bindsym $mod+h split h
+
+  # split in vertical orientation
+  bindsym $mod+v split v
+
+  # enter fullscreen mode for the focused container
+  bindsym $mod+f fullscreen toggle
+
+  # change container layout (stacked, tabbed, toggle split)
+  bindsym $mod+s layout stacking
+  bindsym $mod+w layout tabbed
+  bindsym $mod+e layout toggle split
+
+  # toggle tiling / floating
+  bindsym $mod+Shift+space floating toggle
+
+  # change focus between tiling / floating windows
+  bindsym $mod+space focus mode_toggle
+
+  # focus the parent container
+  bindsym $mod+a focus parent
+
+  # focus the child container
+  #bindsym $mod+d focus child
+
+  # Define names for default workspaces for which we configure key bindings later on.
+  # We use variables to avoid repeating the names in multiple places.
+  set $ws1 "1"
+  set $ws2 "2"
+  set $ws3 "3: Emacs"
+  set $ws4 "4"
+  set $ws5 "5"
+  set $ws6 "6"
+  set $ws7 "7"
+  set $ws8 "8"
+  set $ws9 "9"
+  set $ws10 "10"
+
+  assign [class="emacs"] $ws3
+
+  # switch to workspace
+  bindsym $mod+1 workspace $ws1
+  bindsym $mod+2 workspace $ws2
+  bindsym $mod+3 workspace $ws3
+  bindsym $mod+4 workspace $ws4
+  bindsym $mod+5 workspace $ws5
+  bindsym $mod+6 workspace $ws6
+  bindsym $mod+7 workspace $ws7
+  bindsym $mod+8 workspace $ws8
+  bindsym $mod+9 workspace $ws9
+  bindsym $mod+0 workspace $ws10
+
+  # move focused container to workspace
+  bindsym $mod+Shift+1 move container to workspace $ws1
+  bindsym $mod+Shift+2 move container to workspace $ws2
+  bindsym $mod+Shift+3 move container to workspace $ws3
+  bindsym $mod+Shift+4 move container to workspace $ws4
+  bindsym $mod+Shift+5 move container to workspace $ws5
+  bindsym $mod+Shift+6 move container to workspace $ws6
+  bindsym $mod+Shift+7 move container to workspace $ws7
+  bindsym $mod+Shift+8 move container to workspace $ws8
+  bindsym $mod+Shift+9 move container to workspace $ws9
+  bindsym $mod+Shift+0 move container to workspace $ws10
+
+  # reload the configuration file
+  bindsym $mod+Shift+c reload
+  # restart i3 inplace (preserves your layout/session, can be used to upgrade i3)
+  bindsym $mod+Shift+r restart
+  # exit i3 (logs you out of your X session)
+  bindsym $mod+Shift+e exec "i3-nagbar -t warning -m 'You pressed the exit shortcut. Do you really want to exit i3? This will end your X session.' -B 'Yes, exit i3' 'i3-msg exit'"
+
+  # resize window (you can also use the mouse for that)
+  mode "resize" {
+          # These bindings trigger as soon as you enter the resize mode
+
+          # Pressing left will shrink the window’s width.
+          # Pressing right will grow the window’s width.
+          # Pressing up will shrink the window’s height.
+          # Pressing down will grow the window’s height.
+          bindsym j resize shrink width 10 px or 10 ppt
+          bindsym k resize grow height 10 px or 10 ppt
+          bindsym l resize shrink height 10 px or 10 ppt
+          bindsym semicolon resize grow width 10 px or 10 ppt
+
+          # same bindings, but for the arrow keys
+          bindsym Left resize shrink width 10 px or 10 ppt
+          bindsym Down resize grow height 10 px or 10 ppt
+          bindsym Up resize shrink height 10 px or 10 ppt
+          bindsym Right resize grow width 10 px or 10 ppt
+
+          # back to normal: Enter or Escape or $mod+r
+          bindsym Return mode "default"
+          bindsym Escape mode "default"
+          bindsym $mod+r mode "default"
+  }
+
+  bindsym $mod+r mode "resize"
+
+    bar {
+        status_command i3status
+        position top
+    }
+
+    #######################
+    #                     #
+    #       AUTORUNS      #
+    #                     #
+    #######################
+    # Start firefox
+    exec --no-startup-id ${pkgs.firefox}/bin/firefox --new-instance --setDefaultBrowser
+
+    # Start my-emacs server
+    exec --no-startup-id my-emacs-daemon
+  '';
+
+in {
+
+  #######################
+  #                     #
+  #     AUTORANDR       #
+  #                     #
+  #######################
+
+  # Start autorandr on display change
+  services.autorandr = {
+    enable = true;
+    defaultTarget = "mobile";
+  };
+
+  # What to execute after resolution has been changed
+  environment.etc."xdg/autorandr/postswitch" = {
+    text = '' sleep 4 && i3-msg "restart" '';
+
+  };
+
+  # Start autorandr once on startup
+  systemd.user.services.boot-autorandr = {
+    description = "Autorandr service";
+    partOf = [ "graphical-session.target" ];
+    wantedBy = [ "graphical-session.target" ];
+    serviceConfig = {
+      ExecStart = "${pkgs.autorandr}/bin/autorandr -c";
+      Type = "oneshot";
+    };
+  };
+
+
+
+  #######################
+  #                     #
+  #       XSERVER       #
+  #                     #
+  #######################
+services.xserver.enable = true;
+
+  # Enable i3 Window Manager
+  services.xserver.windowManager.i3 = {
+    enable = true;
+    package = pkgs.i3;
+    configFile = i3_conf_file;
+   };
+
+
+  # ${pkgs.xorg.xhost}/bin/xhost +SI:localuser:${cfg.user.name}
+  # ${pkgs.xorg.xhost}/bin/xhost -LOCAL:
+  services.xserver.windowManager.default = "i3";
+  services.xserver.desktopManager.xterm.enable = false;
+
+
+  # Enable the X11 windowing system.
+  services.xserver.displayManager.lightdm.enable = true;
+
+  # Allow users in video group to change brightness
+  hardware.brightnessctl.enable = true;
+
+  environment.systemPackages = with pkgs; [
+    rofi     # Dmenu replacement
+    acpilight # Replacement for xbacklight
+    arandr # Xrandr gui
+    feh
+    wirelesstools # To get wireless statistics
+    acpi
+    xorg.xhost
+    xorg.xauth
+  ];
+
+}
diff --git a/jeschli/5pkgs/simple/xmonad-jeschli/default.nix b/jeschli/5pkgs/simple/xmonad-jeschli/default.nix
deleted file mode 100644
index 8066984be..000000000
--- a/jeschli/5pkgs/simple/xmonad-jeschli/default.nix
+++ /dev/null
@@ -1,300 +0,0 @@
-{ pkgs, ... }:
-pkgs.writeHaskellPackage "xmonad-jeschli" {
-  executables.xmonad = {
-    extra-depends = [
-      "containers"
-      "extra"
-      "unix"
-      "X11"
-      "xmonad"
-      "xmonad-contrib"
-      "xmonad-stockholm"
-    ];
-    text = /* haskell */ ''
-{-# LANGUAGE DeriveDataTypeable #-} -- for XS
-{-# LANGUAGE FlexibleContexts #-} -- for xmonad'
-{-# LANGUAGE LambdaCase #-}
-{-# LANGUAGE ScopedTypeVariables #-}
-
-
-module Main where
-
-import Control.Exception
-import Control.Monad.Extra (whenJustM)
-import Graphics.X11.ExtraTypes.XF86
-import Text.Read (readEither)
-import XMonad
-import System.Environment (getArgs, withArgs, getEnv, getEnvironment, lookupEnv)
-import System.Exit (exitFailure)
-import System.IO (hPutStrLn, stderr)
-import System.Posix.Process (executeFile)
-import XMonad.Actions.DynamicWorkspaces ( addWorkspacePrompt, renameWorkspace
-                                        , removeEmptyWorkspace)
-import XMonad.Actions.GridSelect
-import XMonad.Actions.CycleWS (toggleWS)
---import XMonad.Actions.CopyWindow ( copy )
-import XMonad.Layout.NoBorders ( smartBorders )
-import qualified XMonad.StackSet as W
-import Data.Map (Map)
-import qualified Data.Map as Map
--- TODO import XMonad.Layout.WorkspaceDir
-import XMonad.Hooks.UrgencyHook (SpawnUrgencyHook(..), withUrgencyHook)
--- import XMonad.Layout.Tabbed
---import XMonad.Layout.MouseResizableTile
-import XMonad.Layout.Reflect (reflectVert)
-import XMonad.Layout.FixedColumn (FixedColumn(..))
-import XMonad.Hooks.Place (placeHook, smart)
-import XMonad.Hooks.FloatNext (floatNextHook)
-import XMonad.Hooks.SetWMName
-import XMonad.Actions.PerWorkspaceKeys (chooseAction)
-import XMonad.Layout.PerWorkspace (onWorkspace)
---import XMonad.Layout.BinarySpacePartition
-
---import XMonad.Actions.Submap
-import XMonad.Stockholm.Pager
-import XMonad.Stockholm.Rhombus
-import XMonad.Stockholm.Shutdown
-
-
-amixerPath :: FilePath
-amixerPath = "${pkgs.alsaUtils}/bin/amixer"
-
-urxvtcPath :: FilePath
-urxvtcPath = "${pkgs.rxvt_unicode}/bin/urxvtc"
-
-myFont :: String
-myFont = "-schumacher-*-*-*-*-*-*-*-*-*-*-*-iso10646-*"
-
-main :: IO ()
-main = getArgs >>= \case
-    [] -> mainNoArgs
-    ["--shutdown"] -> shutdown
-    args -> hPutStrLn stderr ("bad arguments: " <> show args) >> exitFailure
-
-mainNoArgs :: IO ()
-mainNoArgs = do
-    handleShutdownEvent <- newShutdownEventHandler
-    xmonad
-        -- $ withUrgencyHookC dzenUrgencyHook { args = ["-bg", "magenta", "-fg", "magenta", "-h", "2"], duration = 500000 }
-        --                   urgencyConfig { remindWhen = Every 1 }
-        -- $ withUrgencyHook borderUrgencyHook "magenta"
-        -- $ withUrgencyHookC BorderUrgencyHook { urgencyBorderColor = "magenta" } urgencyConfig { suppressWhen = Never }
-        $ withUrgencyHook (SpawnUrgencyHook "echo emit Urgency ")
-        $ def
-            { terminal          = urxvtcPath
-            , modMask           = mod4Mask
-            , keys              = myKeys
-            , workspaces        = ["comms", "org", "dev"]
-            , layoutHook        = smartBorders $ FixedColumn 1 20 80 10 ||| Full
-            -- , handleEventHook   = myHandleEventHooks <+> handleTimerEvent
-            --, handleEventHook   = handleTimerEvent
-            , manageHook        = placeHook (smart (1,0)) <+> floatNextHook
-            , startupHook = do
-                setWMName "LG3D"
-                whenJustM (liftIO (lookupEnv "XMONAD_STARTUP_HOOK"))
-                          (\path -> forkFile path [] Nothing)
-            , normalBorderColor  = "#1c1c1c"
-            , focusedBorderColor = "#f000b0"
-            , handleEventHook = handleShutdownEvent
-            }
-
-
-getWorkspaces0 :: IO [String]
-getWorkspaces0 =
-    try (getEnv "XMONAD_WORKSPACES0_FILE") >>= \case
-      Left e -> warn (displaySomeException e)
-      Right p -> try (readFile p) >>= \case
-        Left e -> warn (displaySomeException e)
-        Right x -> case readEither x of
-          Left e -> warn e
-          Right y -> return y
-  where
-    warn msg = hPutStrLn stderr ("getWorkspaces0: " ++ msg) >> return []
-
-displaySomeException :: SomeException -> String
-displaySomeException = displayException
-
-
-forkFile :: FilePath -> [String] -> Maybe [(String, String)] -> X ()
-forkFile path args env =
-    xfork (executeFile path False args env) >> return ()
-
-spawnRootTerm :: X ()
-spawnRootTerm =
-    forkFile
-        urxvtcPath
-        ["-name", "root-urxvt", "-e", "/run/wrappers/bin/su", "-"]
-        Nothing
-
-spawnTermAt :: String -> X ()
-spawnTermAt ws = do
-    env <- liftIO getEnvironment
-    let env' = ("XMONAD_SPAWN_WORKSPACE", ws) : env
-    forkFile urxvtcPath [] (Just env')
-
-
-myKeys :: XConfig Layout -> Map (KeyMask, KeySym) (X ())
-myKeys conf = Map.fromList $
-    [ ((_4  , xK_Escape ), forkFile "/run/wrappers/bin/slock" [] Nothing)
-    , ((_4S , xK_c      ), kill)
-
-   , ((_4  , xK_p      ), spawn "${pkgs.writeDash "my-dmenu" ''
-      export PATH=$PATH:${pkgs.dmenu}/bin
-      exec dmenu_run "$@"
-   ''}")
-    , ((_4  , xK_x      ), chooseAction spawnTermAt)
-    , ((_4C , xK_x      ), spawnRootTerm)
-
-    --, ((_4  , xK_F1     ), withFocused jojo)
-    --, ((_4  , xK_F1     ), printAllGeometries)
-
-    , ((0   , xK_Print   ), gets windowset >>= allWorkspaceNames >>= pager pagerConfig (windows . W.view) )
-    , ((_S  , xK_Print   ), gets windowset >>= allWorkspaceNames >>= pager pagerConfig (windows . W.shift) )
-    , ((_C  , xK_Print   ), toggleWS)
-
-    -- %! Rotate through the available layout algorithms
-    , ((_4  , xK_space  ), sendMessage NextLayout)
-    , ((_4S , xK_space  ), setLayout $ XMonad.layoutHook conf) -- reset layout
-
-    ---- BinarySpacePartition
-    --, ((_4  , xK_l), sendMessage $ ExpandTowards R)
-    --, ((_4  , xK_h), sendMessage $ ExpandTowards L)
-    --, ((_4  , xK_j), sendMessage $ ExpandTowards D)
-    --, ((_4  , xK_k), sendMessage $ ExpandTowards U)
-    --, ((_4S , xK_l), sendMessage $ ShrinkFrom R)
-    --, ((_4S , xK_h), sendMessage $ ShrinkFrom L)
-    --, ((_4S , xK_j), sendMessage $ ShrinkFrom D)
-    --, ((_4S , xK_k), sendMessage $ ShrinkFrom U)
-    --, ((_4  , xK_n), sendMessage Rotate)
-    --, ((_4S , xK_n), sendMessage Swap)
-
-    ---- mouseResizableTile
-    --, ((_4    , xK_u), sendMessage ShrinkSlave)
-    --, ((_4    , xK_i), sendMessage ExpandSlave)
-
-    -- move focus up or down the window stack
-    --, ((_4  , xK_m      ), windows W.focusMaster)
-    , ((_4  , xK_j      ), windows W.focusDown)
-    , ((_4  , xK_k      ), windows W.focusUp)
-
-    -- modifying the window order
-    , ((_4S , xK_m      ), windows W.swapMaster)
-    , ((_4S , xK_j      ), windows W.swapDown)
-    , ((_4S , xK_k      ), windows W.swapUp)
-
-    -- resizing the master/slave ratio
-    , ((_4  , xK_h      ), sendMessage Shrink) -- %! Shrink the master area
-    , ((_4  , xK_l      ), sendMessage Expand) -- %! Expand the master area
-
-    -- floating layer support
-    , ((_4  , xK_t      ), withFocused $ windows . W.sink)  -- make tiling
-
-    -- increase or decrease number of windows in the master area
-    , ((_4  , xK_comma  ), sendMessage $ IncMasterN 1)
-    , ((_4  , xK_period ), sendMessage $ IncMasterN (-1))
-
-    , ((_4  , xK_a      ), addWorkspacePrompt def)
-    , ((_4  , xK_r      ), renameWorkspace def)
-    , ((_4  , xK_Delete ), removeEmptyWorkspace)
-
-    , ((_4  , xK_Return ), toggleWS)
-    --,  (0   , xK_Print   ) & \k -> (k, gridselectWorkspace wsGSConfig { gs_navigate = makeGSNav k } W.view)
-    --,  (_4  , xK_v      ) & \k -> (k, gridselectWorkspace wsGSConfig { gs_navigate = makeGSNav k } W.view)
-    --,  (_4S , xK_v      ) & \k -> (k, gridselectWorkspace wsGSConfig { gs_navigate = makeGSNav k } W.shift)
-    --,  (_4  , xK_b      ) & \k -> (k, goToSelected        wGSConfig  { gs_navigate = makeGSNav k })
-    , ((noModMask, xF86XK_AudioLowerVolume), amixer ["sset", "Master", "5%-"])
-    , ((noModMask, xF86XK_AudioRaiseVolume), amixer ["sset", "Master", "5%+"])
-    , ((noModMask, xF86XK_AudioMute), amixer ["sset", "Master", "toggle"])
-    ]
-    where
-    _4 = mod4Mask
-    _C = controlMask
-    _S = shiftMask
-    _M = mod1Mask
-    _4C = _4 .|. _C
-    _4S = _4 .|. _S
-    _4M = _4 .|. _M
-    _4CM = _4 .|. _C .|. _M
-    _4SM = _4 .|. _S .|. _M
-
-    amixer args = forkFile amixerPath args Nothing
-
-
-pagerConfig :: PagerConfig
-pagerConfig = def
-    { pc_font           = myFont
-    , pc_cellwidth      = 100
-    --, pc_cellheight     = 36 -- TODO automatically keep screen aspect
-    --, pc_borderwidth    = 1
-    --, pc_matchcolor     = "#f0b000"
-    , pc_matchmethod    = MatchPrefix
-    --, pc_colors         = pagerWorkspaceColors
-    , pc_windowColors   = windowColors
-    }
-    where
-    windowColors _ _ _ True _ = ("#ef4242","#ff2323")
-    windowColors wsf m c u wf = do
-        let y = defaultWindowColors wsf m c u wf
-        if m == False && wf == True
-            then ("#402020", snd y)
-            else y
-
-horseConfig :: RhombusConfig
-horseConfig = def
-    { rc_font           = myFont
-    , rc_cellwidth      = 64
-    --, rc_cellheight     = 36 -- TODO automatically keep screen aspect
-    --, rc_borderwidth    = 1
-    --, rc_matchcolor     = "#f0b000"
-    , rc_matchmethod    = MatchPrefix
-    --, rc_colors         = pagerWorkspaceColors
-    --, rc_paint          = myPaint
-    }
-
-wGSConfig :: GSConfig Window
-wGSConfig = def
-    { gs_cellheight = 20
-    , gs_cellwidth = 192
-    , gs_cellpadding = 5
-    , gs_font = myFont
-    , gs_navigate = navNSearch
-    }
-
--- wsGSConfig = def
---     { gs_cellheight = 20
---     , gs_cellwidth = 64
---     , gs_cellpadding = 5
---     , gs_font = myFont
---     , gs_navigate = navNSearch
---     }
-
--- custom navNSearch
---makeGSNav :: (KeyMask, KeySym) -> TwoD a (Maybe a)
---makeGSNav esc = nav
---    where
---    nav = makeXEventhandler $ shadowWithKeymap keyMap navNSearchDefaultHandler
---    keyMap = Map.fromList
---        [ (esc              , cancel)
---        , ((0,xK_Escape)    , cancel)
---        , ((0,xK_Return)    , select)
---        , ((0,xK_Left)      , move (-1, 0) >> nav)
---        , ((0,xK_Right)     , move ( 1, 0) >> nav)
---        , ((0,xK_Down)      , move ( 0, 1) >> nav)
---        , ((0,xK_Up)        , move ( 0,-1) >> nav)
---        , ((0,xK_BackSpace) , transformSearchString (\s -> if (s == "") then "" else init s) >> nav)
---        ]
---    -- The navigation handler ignores unknown key symbols, therefore we const
---    navNSearchDefaultHandler (_,s,_) = do
---        transformSearchString (++ s)
---        nav
-
-
-(&) :: a -> (a -> c) -> c
-(&) = flip ($)
-
-allWorkspaceNames :: W.StackSet i l a sid sd -> X [i]
-allWorkspaceNames ws =
-    return $ map W.tag (W.hidden ws) ++ [W.tag $ W.workspace $ W.current ws]
-  '';
-  };
-}
diff --git a/krebs/3modules/bepasty-server.nix b/krebs/3modules/bepasty-server.nix
index 94a509520..4892a8723 100644
--- a/krebs/3modules/bepasty-server.nix
+++ b/krebs/3modules/bepasty-server.nix
@@ -164,7 +164,7 @@ let
             client_max_body_size 32M;
             '';
           locations = {
-            "/".extraConfig = "proxy_set_header Host $http_host;";
+            "/".extraConfig = "proxy_set_header Host $host;";
             "/".proxyPass = "http://unix:${server.workDir}/gunicorn-${name}.sock";
             "/static/".extraConfig = ''
               alias ${bepasty}/lib/${python.libPrefix}/site-packages/bepasty/static/;
diff --git a/krebs/3modules/ci.nix b/krebs/3modules/ci.nix
index 244de1a0d..cbf24effe 100644
--- a/krebs/3modules/ci.nix
+++ b/krebs/3modules/ci.nix
@@ -27,7 +27,7 @@ let
   hostname = config.networking.hostName;
   getJobs = pkgs.writeDash "get_jobs" ''
     set -efu
-    ${pkgs.nix}/bin/nix-build --no-out-link --quiet -Q ./ci.nix >&2
+    ${pkgs.nix}/bin/nix-build --no-out-link --quiet --show-trace -Q ./ci.nix >&2
     json="$(${pkgs.nix}/bin/nix-instantiate --quiet -Q --eval --strict --json ./ci.nix)"
     echo "$json" | ${pkgs.jq}/bin/jq -r 'to_entries[] | [.key, .value] | @tsv' \
       | while read -r host builder; do
diff --git a/krebs/3modules/default.nix b/krebs/3modules/default.nix
index 10a33d5d7..c770391c7 100644
--- a/krebs/3modules/default.nix
+++ b/krebs/3modules/default.nix
@@ -104,6 +104,7 @@ let
     { krebs = import ./lass   { inherit config; }; }
     { krebs = import ./makefu { inherit config; }; }
     { krebs = import ./mb { inherit config; }; }
+    { krebs = import ./nin    { inherit config; }; }
     { krebs = import ./external/palo.nix { inherit config; }; }
     { krebs = import ./tv     { inherit config; }; }
     {
diff --git a/krebs/3modules/external/default.nix b/krebs/3modules/external/default.nix
index f12dda097..1546cac62 100644
--- a/krebs/3modules/external/default.nix
+++ b/krebs/3modules/external/default.nix
@@ -426,20 +426,19 @@ in {
           ip4.addr = "10.243.29.175";
           aliases = [ "qubasa.r" ];
           tinc.pubkey = ''
-              -----BEGIN PUBLIC KEY-----
-              MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA6ioASTOx6Vndp316u89Z
-              f+9WgfyVGw9deP2pQjoHnsPjBqRrsDCQGFO/U1ILQn0AWskQpHWHRir7Q6cI90jm
-              8MqqGVymVFbeYbrOLHLjp+2fle9iU9DfST4O76TQwF/3elLf3tpGFS8EB+qF3Ig7
-              aVOf5TuHPWWj6VtGTuWW9I8MsPnNykyRstlWXEztIs2zQrc0cO1IGd1QVarDGqTs
-              KR4Zm7PvF7U193NzPLaH6jcdjF37FETLrNxAu88M+YnvXBp4oRHeJmvBloazpH0v
-              aSb3+vNRlViMSlf9ImpAHlFRyvYYDAWlIY0nyeNUJna1ImGloSStLtBAhFAwc65j
-              kmrXeK3TVAoGZQOvSbjFmI/nBgfHEOnz/9aRVHGUNoQ/nAM6UhALFEZV6sdjX6W4
-              3p670DEO5fiI3fqqErkscbv8zSEjfmxV4YGMXVMw8Ub87fGwQEF17uDLeqD0k9AB
-              7umwrWP53YffauAqinma0I6RcLRVRfJ2vhyBH1mKwAAW55WU6DpBTydy46kxy/Oz
-              k9Cnxw7oMydUAAdnf5Axgs+dcx43lnXvGsoHi4lZycYhqtPe2YI152HAbGfmrixV
-              Slzh8aiinBkLYW2VzJNTRmHvB3njjeua4/guXwe00G7MIs3UDMIieJNcVxb+E07v
-              vF2rqhqU9b+1MQRhIPsBf4cCAwEAAQ==
-              -----END PUBLIC KEY-----
+            -----BEGIN RSA PUBLIC KEY-----
+            MIICCgKCAgEA65g1Xql+S+Dd90uDpSVxzGRTL8n4DHc1p9T8u9h7ioytC9B+e2dQ
+            RU/y3gdJ0gXxrbth36MhTANuUonnqpHvsWwUDCQRbxLEFh8avlzLsecWvwrIt3zL
+            102EaVurRySUa83D6TK8ZsDa2+ADY7tEzfFMJhT53g7MpBNIeOquB0rR6hVYBbHc
+            3B+QtwdM8dx1gO/5+FsPYhJbR7ARczYHsj7Eyb8NbdzthEO0ICDgwzmcXTJfVHGR
+            qfT7DUolXsu7uSPMLB+Pe/leI7XcQ2VFukpVGP0fZv0mSMxavFlcFVkLgdbAEd2H
+            DPEBEcJpLR4Hw3HlO1kPPufaUdoeNhUmTkIp76mkCbanS1P/aFNFFcVB+a/+tpdK
+            z5pG8K3qANg5txp6sAatPchvkeQelIg11lvT9luc+nFsTEW6Ky5nDLo60luZVFnn
+            i1bdVeOojXR0u7M2gMqQZcSuscvy8APe48S8vPsqoiob1l/r77B7iNrWDwH8IutW
+            u8fpC64CbhlR76Orp3xTZPmJQCRT8XYpKDDoq5Z7prdlAEz3U6wEfVckVv+f1dmU
+            odG0zDTsmyKhkWWmZbPgPrOEUvAVoSpSLSQQxPR+UHArlgYe+2dAf8IHYqrgmhuO
+            D4Lga4nNwTyVbCZ8vUu5b/lnGCLpNcVj22WVQTdAJzNsCVTdIM2V5hcCAwEAAQ==
+            -----END RSA PUBLIC KEY-----
           '';
         };
       };
diff --git a/krebs/3modules/jeschli/default.nix b/krebs/3modules/jeschli/default.nix
index 9f5b1bd6a..c6a4b40eb 100644
--- a/krebs/3modules/jeschli/default.nix
+++ b/krebs/3modules/jeschli/default.nix
@@ -129,6 +129,31 @@ in {
       };
     };
 
+    reagenzglas = {
+      nets = {
+        retiolum = {
+          ip4.addr = "10.243.27.32";
+          aliases = [
+            "reagenzglas.r"
+          ];
+          tinc.pubkey = ''
+            -----BEGIN RSA PUBLIC KEY-----
+            MIICCgKCAgEAon6oMki2GuJah9c1jNj0CupIPNo765AxtpSkut1PvoydAVYWZMO0
+            /UQgrvoDQPq3VQU98LHhtQVjmfmcxmxIK3mWoM356P9TGsheOspTcVP4HCMoWZoF
+            QpgpQs1RNuG/nAAcoVHnTqFeFt6oWsykESIWj5jFV5XA+KanyLFThi8aWPumJgOV
+            W0AR4+0eECMjBXCV0yRaug4cnFKwLtTQ993AP6Di+5iyh8H39wuASUA/USfMItyX
+            KEPCT1LPVu2JKsLE/aQEqX1ra3qVJ+SzSPKvOJGKNjcN0e84TuqGrh6cmEDcT/hd
+            MNZisdPvWA8UwXZfsT/TOGyd8MBqgGxWS6JSFHXy9enyjvS+rws8U0IySlnAIEoi
+            mXi0leXXDHSQBUnLgDwx4yAJ2R63bUr0pvVd9NBvS9CYHH3TETuwxtMsd3Djm1tu
+            9/GxN78N+dTHCwOFw/RFOGKCDuM2v1P0f56SdcADqiziuVn+Sj/WPL7rM7qLkySv
+            jAqY7q5PUjcz/tltJUJwIHaV3sSB6+zOKhSPhGE5ASr4dYEnxiTSD2YE7fj3+WKK
+            ShG3cpjOwgW0/Ut88zIs7zQxfHj5ZML+Gh2E2LN5nb7StMBWafgvq58eTKbMCKbx
+            ev7cFjOOV86sCjqtt5LVSi7TPAtolnmLyxzM+s/eZoLYITh+Zo8UERMCAwEAAQ==
+            -----END RSA PUBLIC KEY-----
+          '';
+        };
+      };
+    };
   };
   users = {
     jeschli = {
@@ -144,5 +169,8 @@ in {
    jeschli-bolide = {
      pubkey = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDGnLjnFw3OYJJy/ID9RCWHTtnVcKRfROIj1tJdJZoOWzGMY+kgyCN/WNBg7JJtCW22yU5O3ftSdN851URCBZ6FgYmcvURBxUOKPlyX5EoxUrrnbmtxJM9+OIT3Dt2RWfrqX6aEQ57nwe/qIFKo9UaoedB/FOzsw1f3U5zBxVuWVRQrsnPxkbPWHmPAGB4CvL897tb83uecDexmGZpLe/0dN4768i2nYaSwrNL+HtqZCvkEqEmnfHlmqqXhiuq83q8su/WSXAtDbUVucG3frgOir14YCbrWKf59+MugxhYOEYBqp+KME5+niFGoulg+NBW/HzH6U+DiH4RFBJhCu1Gr jeschli@bolide";
    };
+   jeschli-reagenzglas = {
+     pubkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKFXgtbgeivxlMKkoEJ4ANhtR+LRMSPrsmL4U5grFUME jeschli@nixos";
+   };
   };
 }
diff --git a/krebs/3modules/nin/default.nix b/krebs/3modules/nin/default.nix
new file mode 100644
index 000000000..1531a2c89
--- /dev/null
+++ b/krebs/3modules/nin/default.nix
@@ -0,0 +1,111 @@
+{ config, ... }:
+
+with import <stockholm/lib>;
+
+{
+  hosts = mapAttrs (_: recursiveUpdate {
+    owner = config.krebs.users.nin;
+    ci = true;
+  }) {
+    hiawatha = {
+      cores = 2;
+      nets = {
+        retiolum = {
+          ip4.addr = "10.243.132.96";
+          ip6.addr = "42:0000:0000:0000:0000:0000:0000:2342";
+          aliases = [
+            "hiawatha.r"
+          ];
+          tinc.pubkey = ''
+            -----BEGIN RSA PUBLIC KEY-----
+            MIIBCgKCAQEAucIe5yLzKJ8F982XRpZT6CvyXuPrtnNTmw/E/T6Oyq88m/OVHh6o
+            Viho1XAlJZZwqNniItD0AQB98uFB3+3yA7FepnwwC+PEceIfBG4bTDNyYD3ZCsAB
+            iWpmRar9SQ7LFnoZ6X2lYaJkUD9afmvXqJJLR5MClnRQo5OSqXaFdp7ryWinHP7E
+            UkPSNByu4LbQ9CnBEW8mmCVZSBLb8ezxg3HpJSigmUcJgiDBJ6aj22BsZ5L+j1Sr
+            lvUuaCr8WOS41AYsD5dbTYk7EG42tU5utrOS6z5yHmhbA5r8Ro2OFi/R3Td68BIJ
+            yw/m8sfItBCvjJSMEpKHEDfGMBCfQKltCwIDAQAB
+            -----END RSA PUBLIC KEY-----
+          '';
+        };
+      };
+      ssh.privkey.path = <secrets/ssh.id_ed25519>;
+      ssh.pubkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFizK5kauDlnjm/IzyzLi+W4hLKqjSWMkfuxzLwg6egx";
+    };
+     axon= {
+      cores = 2;
+      nets = {
+        retiolum = {
+          ip4.addr = "10.243.134.66";
+          ip6.addr = "42:0000:0000:0000:0000:0000:0000:1379";
+          aliases = [
+            "axon.r"
+          ];
+          tinc.pubkey = ''
+          -----BEGIN RSA PUBLIC KEY-----
+          MIIECgKCBAEA89h5SLDQL/ENM//3SMzNkVnW4dBdg1GOXs/SdRCTcgygJC0TzsAo
+          glfQhfS+OhFSC/mXAjP8DnN7Ys6zXzMfJgH7TgVRJ8tCo5ETehICA19hMjMFINLj
+          KZhhthPuX7u2Jr4uDMQ0eLJnKVHF4PmHnkA+JGcOqO7VSkgcqPvqPMnJFcMkGWvH
+          L3KAz1KGPHZWrAB2NBDrD/bOZj4L39nS4nJIYVOraP7ze1GTTC7s/0CnZj3qwS5j
+          VdUYgAR+bdxlWm1B1PPOjkslP6UOklQQK4SjK3ceLYb2yM7BVICeznjWCbkbMACY
+          PUSvdxyiD7nZcLvuM3cJ1M45zUK+tAHHDB5FFUUAZ+YY/Xml4+JOINekpQdGQqkN
+          X4VsdRGKpjqi+OXNP4ktDcVkl8uALmNR6TFfAEwQJdjgcMxgJGW9PkqvPl3Mqgoh
+          m89lHPpO0Cpf40o6lZRG42gH1OR7Iy1M234uA08a3eFf+IQutHaOBt/Oi0YeiaQp
+          OtJHmWtpsQRz24/m+uroSUtKZ63sESli28G1jP73Qv7CiB8KvSX0Z4zKJOV/CyaT
+          LLguAyeWdNLtVg4bGRd7VExoWA+Rd9YKHCiE5duhETZk0Hb9WZmgPdM7A0RBb+1H
+          /F9BPKSZFl2e42VEsy8yNmBqO8lL7DVbAjLhtikTpPLcyjNeqN99a8jFX4c5nhIK
+          MVsSLKsmNGQq+dylXMbErsGu3P/OuCZ4mRkC32Kp4qwJ+JMrJc8+ZbhKl6Fhwu0w
+          7DwwoUaRoMqtr2AwR+X67eJsYiOVo5EkqBo6DrWIM6mO2GrWHg5LTBIShn08q/Nm
+          ofPK2TmLdfqBycUR0kRCCPVi82f9aElmg3pzzPJnLAn9JLL43q6l+sefvtr9sTs3
+          1co6m8k5mO8zTb8BCmX2nFMkCopuHeF1nQ33y6woq0D8WsXHfHtbPwN9eYRVrbBF
+          29YBp5E+Q1pQB+0rJ4A5N1I3VUKhDGKc72pbQc8cYoAbDXA+RKYbsFOra5z585dt
+          4HQXpwj3a/JGJYRT6FVbJp4p8PjwAtN9VkpXNl4//3lXQdDD6aQ6ssXaKxVAp2Xj
+          FjPjx6J6ok4mRvofKNAREt4eZUdDub34bff6G0zI7Vls9t4ul0uHsJ6+ic3CG+Yl
+          buLfOkDp4hVCAlMPQ2NJfWKSggoVao7OTBPTMB3NiM56YOPptfZgu2ttDRTyuQ7p
+          hrOwutxoy/abH3hA8bWj1+C23vDtQ2gj0r16SWxpPdb3sselquzKp9NIvtyRVfnG
+          yYZTWRHg9mahMC2P0/wWAQVjKb0LnTib4lSe21uqFkWzp+3/Uu+hiwP5xGez/NIi
+          ahyL7t0D9r9y+i1RPjYWypgyR568fiGheQIDAQAB
+          -----END RSA PUBLIC KEY-----
+          '';
+        };
+      };
+      ssh.privkey.path = <secrets/ssh.id_ed25519>;
+      ssh.pubkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF4ubHA2pQzV4tQq9D1zRTD1xOSR6xZM3z6te+5A1ekc";
+    };
+    onondaga = {
+      cores = 1;
+      nets = {
+        retiolum = {
+          ip4.addr = "10.243.132.55";
+          ip6.addr = "42:0000:0000:0000:0000:0000:0000:1357";
+          aliases = [
+            "onondaga.r"
+            "cgit.onondaga.r"
+          ];
+          tinc.pubkey = ''
+            -----BEGIN RSA PUBLIC KEY-----
+            MIIBCgKCAQEAqj6NPhRVsr8abz9FFx9+ld3amfxN7SRNccbksUOqkufGS0vaupFR
+            OWsgj4Qmt3lQ82YVt5yjx0FZHkAsenCEKM3kYoIb4nipT0e1MWkQ7plVveMfGkiu
+            htaJ1aCbI2Adxfmk4YbyAr8k3G+Zl9t7gTikBRh7cf5PMiu2JhGUZHzx9urR0ieH
+            xyashZFjl4TtIy4q6QTiyST9kfzteh8k7CJ72zfYkdHl9dPlr5Nk22zH9xPkyzmO
+            kCNeknuDqKeTT9erNtRLk6pjEcyutt0y2/Uq6iZ38z5qq9k4JzcMuQ3YPpNy8bxn
+            hVuk2qBu6kBTUW3iLchoh0d4cfFLWLx1SQIDAQAB
+            -----END RSA PUBLIC KEY-----
+          '';
+        };
+      };
+      ssh.privkey.path = <secrets/ssh.id_ed25519>;
+      ssh.pubkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGmQk7AXsYLzjUrOjsuhZ3+gT7FjhPtjwxv5XnuU8GJO";
+    };
+
+  };
+  users = {
+    nin = {
+      mail = "nin@axon.r";
+      pubkey = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCl4jHl2dya9Tecot7AcHuk57FiPN0lo8eDa03WmTOCCU7gEJLgpi/zwLxY/K4eXsDgOt8LJwddicgruX2WgIYD3LnwtuN40/U9QqqdBIv/5sYZTcShAK2jyPj0vQJlVUpL7DLxxRH+t4lWeRw/1qaAAVt9jEVbzT5RH233E6+SbXxfnQDhDwOXwD1qfM10BOGh63iYz8/loXG1meb+pkv3HTf5/D7x+/y1XvWRPKuJ2Ml33p2pE3cTd+Tie1O8CREr45I9JOIOKUDQk1klFL5NNXnaQ9h1FRCsnQuoGztoBq8ed6XXL/b8mQ0lqJMxHIoCuDN/HBZYJ0z+1nh8X6XH nin@axon";
+    };
+    nin_h = {
+      mail = "nin@hiawatha.r";
+      pubkey = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDicZLUPEVNX7SgqYWcjPo0UESRizEfIvVVbiwa1aApA8x25u/5R3sevcgbIpLHYKDMl5tebny9inr6G2zqB6oq/pocQjHxrPnuLzqjvqeSpbjQjlNWJ9GaHT5koTXZHdkEXGL0vfv1SRDNWUiK0rNymr3GXab4DyrnRnuNl/G1UtLf4Zka94YUD0SSPdS9y6knnRrUWKjGMFBZEbNSgHqMGATPQP9VDwKHIO2OWGfiBAJ4nj/MWj+BxHDleCMY9zbym8yY7p/0PLaUe9eIyLC8MftJ5suuMmASlj+UGWgnqUxWxsMHax9y7CTAc23r1NNCXN5LC6/facGt0rEQrdrTizBgOA1FSHAPCl5f0DBEgWBrRuygEcAueuGWvI8/uvtvQQZLhosDbXEfs/3vm2xoYBe7wH4NZHm+d2LqgIcPXehH9hVQsl6pczngTCJt0Q/6tIMffjhDHeYf6xbe/n3AqFT0PylUSvOw/H5iHws3R6rxtgnOio7yTJ4sq0NMzXCtBY6LYPGnkwf0oKsgB8KavZVnxzF8B1TD4nNi0a7ma7bd1LMzI/oGE6i8kDMROgisIECOcoe8YYJZXIne/wimhhRKZAsd+VrKUo4SzNIavCruCodGAVh2vfrqRJD+HD/aWH7Vr1fCEexquaxeKpRtKGIPW9LRCcEsTilqpZdAiw== nin@hiawatha";
+    };
+  };
+}
diff --git a/krebs/5pkgs/haskell/email-header.nix b/krebs/5pkgs/haskell/email-header.nix
index 8b7165860..572a8029c 100644
--- a/krebs/5pkgs/haskell/email-header.nix
+++ b/krebs/5pkgs/haskell/email-header.nix
@@ -10,22 +10,11 @@ with import <stockholm/lib>;
       rev = "7b179bd31192ead8afe7a0b6e34bcad4039deaa8";
       sha256 = "12j2n3sbvzjnw99gga7kkdygm8n3qx2lh8q26ad6a53xm5whnz59";
     };
-    "18.09" = {
-      version = "0.4.1-tv1";
-      rev = "refs/tags/v${cfg.version}";
-      sha256 = "11xjivpj495r2ss9aqljnpzzycb57cm4sr7yzmf939rzwsd3ib0x";
-    };
-    "19.03" = {
-      version = "0.4.1-tv1";
-      rev = "refs/tags/v${cfg.version}";
-      sha256 = "11xjivpj495r2ss9aqljnpzzycb57cm4sr7yzmf939rzwsd3ib0x";
-    };
-    "19.09" = {
-      version = "0.4.1-tv1";
-      rev = "refs/tags/v${cfg.version}";
-      sha256 = "11xjivpj495r2ss9aqljnpzzycb57cm4sr7yzmf939rzwsd3ib0x";
-    };
-  }.${versions.majorMinor version};
+  }.${versions.majorMinor version} or {
+    version = "0.4.1-tv1";
+    rev = "refs/tags/v${cfg.version}";
+    sha256 = "11xjivpj495r2ss9aqljnpzzycb57cm4sr7yzmf939rzwsd3ib0x";
+  };
 
 in mkDerivation {
   pname = "email-header";
diff --git a/krebs/5pkgs/simple/bitlbee-discord/default.nix b/krebs/5pkgs/simple/bitlbee-discord/default.nix
deleted file mode 100644
index c01b87d6b..000000000
--- a/krebs/5pkgs/simple/bitlbee-discord/default.nix
+++ /dev/null
@@ -1,29 +0,0 @@
-{ fetchurl, fetchFromGitHub, stdenv, bitlbee, autoreconfHook, pkgconfig, glib }:
-
-with stdenv.lib;
-stdenv.mkDerivation rec {
-  name = "bitlbee-discord-2017-12-27";
-
-  src = fetchFromGitHub {
-    rev = "6a03db169ad44fee55609ecd16e19f3c0f99a182";
-    owner = "sm00th";
-    repo = "bitlbee-discord";
-    sha256 = "1ci9a12c6zg8d6i9f95pq6dal79cp4klmmsyj8ag2gin90kl3x95";
-  };
-
-  nativeBuildInputs = [ autoreconfHook pkgconfig ];
-  buildInputs = [ bitlbee glib ];
-
-  preConfigure = ''
-    export BITLBEE_PLUGINDIR=$out/lib/bitlbee
-    ./autogen.sh
-  '';
-
-  meta = {
-    description = "Bitlbee plugin for Discord";
-
-    homepage = https://github.com/sm00th/bitlbee-discord;
-    license = licenses.gpl2Plus;
-    platforms = stdenv.lib.platforms.linux;
-  };
-}
diff --git a/krebs/5pkgs/simple/go-shortener/default.nix b/krebs/5pkgs/simple/go-shortener/default.nix
index 4d1bef2be..5e734553b 100644
--- a/krebs/5pkgs/simple/go-shortener/default.nix
+++ b/krebs/5pkgs/simple/go-shortener/default.nix
@@ -1,11 +1,11 @@
-{ stdenv, makeWrapper, lib, buildEnv, fetchgit, nodejs-8_x, pkgs }:
+{ stdenv, makeWrapper, lib, buildEnv, fetchgit, nodejs-12_x, pkgs }:
 
 with lib;
 
 let
   nodeEnv = import <nixpkgs/pkgs/development/node-packages/node-env.nix> {
     inherit (pkgs) stdenv python2 utillinux runCommand writeTextFile;
-    nodejs = nodejs-8_x;
+    nodejs = nodejs-12_x;
     libtool = if pkgs.stdenv.isDarwin then pkgs.darwin.cctools else null;
   };
 
@@ -34,7 +34,7 @@ in stdenv.mkDerivation {
   ];
 
   buildInputs = [
-    nodejs-8_x
+    nodejs-12_x
     makeWrapper
   ];
 
@@ -43,7 +43,7 @@ in stdenv.mkDerivation {
 
     cp index.js $out/
     cat > $out/go << EOF
-      ${nodejs-8_x}/bin/node $out/index.js
+      ${nodejs-12_x}/bin/node $out/index.js
     EOF
     chmod +x $out/go
 
diff --git a/krebs/5pkgs/simple/newsbot-js/default.nix b/krebs/5pkgs/simple/newsbot-js/default.nix
index cc362b86a..055e6b476 100644
--- a/krebs/5pkgs/simple/newsbot-js/default.nix
+++ b/krebs/5pkgs/simple/newsbot-js/default.nix
@@ -1,11 +1,11 @@
-{ stdenv, makeWrapper, lib, buildEnv, fetchgit, nodejs-8_x, pkgs, icu }:
+{ stdenv, makeWrapper, lib, buildEnv, fetchgit, nodejs-12_x, pkgs, icu }:
 
 with lib;
 
 let
   nodeEnv = import <nixpkgs/pkgs/development/node-packages/node-env.nix> {
     inherit (pkgs) stdenv python2 utillinux runCommand writeTextFile;
-    nodejs = nodejs-8_x;
+    nodejs = nodejs-12_x;
     libtool = if pkgs.stdenv.isDarwin then pkgs.darwin.cctools else null;
   };
 
@@ -36,7 +36,7 @@ in stdenv.mkDerivation {
   ];
 
   buildInputs = [
-    nodejs-8_x
+    nodejs-12_x
     makeWrapper
   ];
 
@@ -45,7 +45,7 @@ in stdenv.mkDerivation {
 
     cp newsbot.js $out/
     cat > $out/newsbot << EOF
-      ${nodejs-8_x}/bin/node $out/newsbot.js
+      ${nodejs-12_x}/bin/node $out/newsbot.js
     EOF
     chmod +x $out/newsbot
 
diff --git a/krebs/nixpkgs.json b/krebs/nixpkgs.json
index f1dd0bf6d..b43fb07fc 100644
--- a/krebs/nixpkgs.json
+++ b/krebs/nixpkgs.json
@@ -1,7 +1,7 @@
 {
   "url": "https://github.com/NixOS/nixpkgs-channels",
-  "rev": "021d733ea3f87b8c9232020b4e606d08eaca160b",
-  "date": "2019-09-20T08:20:21+02:00",
-  "sha256": "13600nzrakvg2hsfg5yr7x0jp9m762nvjyddf07q60d3m7vx9jxy",
+  "rev": "88bbb3c809699f44bf844094a2cd7874e0ea4a39",
+  "date": "2019-10-09T11:39:27+02:00",
+  "sha256": "0vqwws2hhsx1g4kdhm2sz9m71n0jvjvhgv9ia7fjz679s3341032",
   "fetchSubmodules": false
 }
diff --git a/krebs/update-nixpkgs.sh b/krebs/update-nixpkgs.sh
index 08354357a..9b5d7ccd8 100755
--- a/krebs/update-nixpkgs.sh
+++ b/krebs/update-nixpkgs.sh
@@ -3,7 +3,7 @@ dir=$(dirname $0)
 oldrev=$(cat $dir/nixpkgs.json | jq -r .rev | sed 's/\(.\{7\}\).*/\1/')
 nix-shell -p nix-prefetch-git --run 'nix-prefetch-git \
   --url https://github.com/NixOS/nixpkgs-channels \
-  --rev refs/heads/nixos-19.03' \
+  --rev refs/heads/nixos-19.09' \
 > $dir/nixpkgs.json
 newrev=$(cat $dir/nixpkgs.json | jq -r .rev | sed 's/\(.\{7\}\).*/\1/')
 git commit $dir/nixpkgs.json -m "nixpkgs: $oldrev -> $newrev"
diff --git a/lass/1systems/daedalus/config.nix b/lass/1systems/daedalus/config.nix
index df8868034..2c1be473a 100644
--- a/lass/1systems/daedalus/config.nix
+++ b/lass/1systems/daedalus/config.nix
@@ -58,7 +58,7 @@ with import <stockholm/lib>;
       krebs.per-user.bitcoin.packages = [
         pkgs.electrum
         pkgs.electron-cash
-        pkgs.altcoins.litecoin
+        pkgs.litecoin
       ];
       users.extraUsers = {
         bitcoin = {
diff --git a/lass/1systems/prism/config.nix b/lass/1systems/prism/config.nix
index 845cf943c..13e865c6e 100644
--- a/lass/1systems/prism/config.nix
+++ b/lass/1systems/prism/config.nix
@@ -65,6 +65,13 @@ with import <stockholm/lib>;
           config.krebs.users.makefu.pubkey
         ];
       };
+      users.users.nin = {
+        uid = genid "nin";
+        isNormalUser = true;
+        openssh.authorizedKeys.keys = [
+          config.krebs.users.nin.pubkey
+        ];
+      };
       users.extraUsers.dritter = {
         uid = genid_uint31 "dritter";
         isNormalUser = true;
@@ -117,6 +124,26 @@ with import <stockholm/lib>;
         localAddress = "10.233.2.2";
       };
     }
+    {
+      #onondaga
+      systemd.services."container@onondaga".reloadIfChanged = mkForce false;
+      containers.onondaga = {
+        config = { ... }: {
+          imports = [ <stockholm/lass/2configs/rebuild-on-boot.nix> ];
+          environment.systemPackages = [ pkgs.git ];
+          services.openssh.enable = true;
+          users.users.root.openssh.authorizedKeys.keys = [
+            config.krebs.users.lass.pubkey
+            config.krebs.users.nin.pubkey
+          ];
+        };
+        autoStart = true;
+        enableTun = true;
+        privateNetwork = true;
+        hostAddress = "10.233.2.5";
+        localAddress = "10.233.2.6";
+      };
+    }
     <stockholm/lass/2configs/exim-smarthost.nix>
     <stockholm/lass/2configs/ts3.nix>
     <stockholm/lass/2configs/privoxy-retiolum.nix>
@@ -157,7 +184,7 @@ with import <stockholm/lib>;
       imports = [
         <stockholm/lass/2configs/realwallpaper.nix>
       ];
-      services.nginx.virtualHosts."lassul.us".locations."/wallpaper.png".extraConfig = ''
+      services.nginx.virtualHosts."lassul.us".locations."= /wallpaper.png".extraConfig = ''
         alias /var/realwallpaper/realwallpaper.png;
       '';
     }
@@ -352,7 +379,7 @@ with import <stockholm/lib>;
 
       services.nginx.virtualHosts."lassul.us".locations."^~ /transmission".extraConfig = ''
         if ($scheme != "https") {
-          rewrite ^ https://$host$uri permanent;
+          rewrite ^ https://$host$request_uri permanent;
         }
         auth_basic "Restricted Content";
         auth_basic_user_file ${pkgs.writeText "transmission-user-pass" ''
diff --git a/lass/1systems/yellow/config.nix b/lass/1systems/yellow/config.nix
index cda0d0a33..d049bdee6 100644
--- a/lass/1systems/yellow/config.nix
+++ b/lass/1systems/yellow/config.nix
@@ -47,7 +47,7 @@ with import <stockholm/lib>;
     };
     virtualHosts.default = {
       default = true;
-      locations."/Nginx-Fancyindex-Theme-dark" = {
+      locations."=/Nginx-Fancyindex-Theme-dark" = {
         extraConfig = ''
           alias ${pkgs.fetchFromGitHub {
             owner = "Naereen";
diff --git a/lass/2configs/radio.nix b/lass/2configs/radio.nix
index b4efd42fc..7e1433fde 100644
--- a/lass/2configs/radio.nix
+++ b/lass/2configs/radio.nix
@@ -230,11 +230,11 @@ in {
         proxy_set_header X-Real-IP $remote_addr;
         proxy_pass http://localhost:8000;
       '';
-      locations."/recent".extraConfig = ''
+      locations."= /recent".extraConfig = ''
         alias /tmp/played;
       '';
     };
-    virtualHosts."lassul.us".locations."/the_playlist".extraConfig = let
+    virtualHosts."lassul.us".locations."= /the_playlist".extraConfig = let
       html = pkgs.writeText "index.html" ''
         <!DOCTYPE html>
         <html lang="en">
diff --git a/lass/2configs/websites/lassulus.nix b/lass/2configs/websites/lassulus.nix
index 526909e8a..f04f312d0 100644
--- a/lass/2configs/websites/lassulus.nix
+++ b/lass/2configs/websites/lassulus.nix
@@ -21,29 +21,6 @@ in {
 
   krebs.tinc_graphs.enable = true;
 
-  users.users.lass-stuff = {
-    uid = genid_uint31 "lass-stuff";
-    description = "lassul.us blog cgi stuff";
-    home = "/var/empty";
-  };
-
-  services.phpfpm.poolConfigs."lass-stuff" = ''
-    listen = /var/run/lass-stuff.socket
-    user = lass-stuff
-    group = nginx
-    pm = dynamic
-    pm.max_children = 5
-    pm.start_servers = 1
-    pm.min_spare_servers = 1
-    pm.max_spare_servers = 1
-    listen.owner = lass-stuff
-    listen.group = nginx
-    php_admin_value[error_log] = 'stderr'
-    php_admin_flag[log_errors] = on
-    catch_workers_output = yes
-    security.limit_extensions =
-  '';
-
   users.groups.lasscert.members = [
     "dovecot2"
     "ejabberd"
@@ -60,48 +37,33 @@ in {
     locations."= /retiolum-hosts.tar.bz2".extraConfig = ''
       alias ${config.krebs.tinc.retiolum.hostsArchive};
     '';
+    locations."= /hosts".extraConfig = ''
+      alias ${pkgs.krebs-hosts_combined};
+    '';
     locations."= /retiolum.hosts".extraConfig = ''
       alias ${pkgs.krebs-hosts-retiolum};
     '';
     locations."= /wireguard-key".extraConfig = ''
       alias ${pkgs.writeText "prism.wg" config.krebs.hosts.prism.nets.wiregrill.wireguard.pubkey};
     '';
-    locations."/tinc".extraConfig = ''
+    locations."/tinc/".extraConfig = ''
       alias ${config.krebs.tinc_graphs.workingDir}/external;
     '';
-    locations."/krebspage".extraConfig = ''
+    locations."= /krebspage".extraConfig = ''
       default_type "text/html";
       alias ${pkgs.krebspage}/index.html;
     '';
-    # TODO make this work!
-    locations."= /ddate".extraConfig = let
-      script = pkgs.writeBash "test" ''
-        echo "hello world"
-      '';
-      #script = pkgs.exec "ddate-wrapper" {
-      #  filename = "${pkgs.ddate}/bin/ddate";
-      #  argv = [];
-      #};
-    in ''
-      gzip off;
-      fastcgi_pass unix:/var/run/lass-stuff.socket;
-      include ${pkgs.nginx}/conf/fastcgi_params;
-      fastcgi_param DOCUMENT_ROOT /var/empty;
-      fastcgi_param SCRIPT_FILENAME ${script};
-      fastcgi_param SCRIPT_NAME ${script};
-    '';
-
-    locations."/init".extraConfig = let
+    locations."= /init".extraConfig = let
       initscript = pkgs.init.override {
         pubkey = config.krebs.users.lass.pubkey;
       };
     in ''
       alias ${initscript};
     '';
-    locations."/pub".extraConfig = ''
+    locations."= /pub".extraConfig = ''
       alias ${pkgs.writeText "pub" config.krebs.users.lass.pubkey};
     '';
-    locations."/pub1".extraConfig = ''
+    locations."= /pub1".extraConfig = ''
       alias ${pkgs.writeText "pub" config.krebs.users.lass-mors.pubkey};
     '';
   };
diff --git a/lass/2configs/websites/util.nix b/lass/2configs/websites/util.nix
index a807f7160..bffa1036b 100644
--- a/lass/2configs/websites/util.nix
+++ b/lass/2configs/websites/util.nix
@@ -60,21 +60,23 @@ rec {
           expires max;
         '';
       };
-      services.phpfpm.poolConfigs."${domain}" = ''
-        listen = /srv/http/${domain}/phpfpm.pool
-        user = nginx
-        group = nginx
-        pm = dynamic
-        pm.max_children = 25
-        pm.start_servers = 5
-        pm.min_spare_servers = 3
-        pm.max_spare_servers = 20
-        listen.owner = nginx
-        listen.group = nginx
-        php_admin_value[error_log] = 'stderr'
-        php_admin_flag[log_errors] = on
-        catch_workers_output = yes
-      '';
+      services.phpfpm.pools."${domain}" = {
+        user = "nginx";
+        group = "nginx";
+        extraConfig = ''
+          listen = /srv/http/${domain}/phpfpm.pool
+          pm = dynamic
+          pm.max_children = 25
+          pm.start_servers = 5
+          pm.min_spare_servers = 3
+          pm.max_spare_servers = 20
+          listen.owner = nginx
+          listen.group = nginx
+          php_admin_value[error_log] = 'stderr'
+          php_admin_flag[log_errors] = on
+          catch_workers_output = yes
+        '';
+      };
     };
 
   serveOwncloud = domains:
@@ -169,22 +171,24 @@ rec {
           access_log off;
         '';
       };
-      services.phpfpm.poolConfigs."${domain}" = ''
-        listen = /srv/http/${domain}/phpfpm.pool
-        user = nginx
-        group = nginx
-        pm = dynamic
-        pm.max_children = 32
-        pm.max_requests = 500
-        pm.start_servers = 2
-        pm.min_spare_servers = 2
-        pm.max_spare_servers = 5
-        listen.owner = nginx
-        listen.group = nginx
-        php_admin_value[error_log] = 'stderr'
-        php_admin_flag[log_errors] = on
-        catch_workers_output = yes
-      '';
+      services.phpfpm.pools."${domain}" = {
+        user = "nginx";
+        group = "nginx";
+        extraConfig = ''
+          listen = /srv/http/${domain}/phpfpm.pool
+          pm = dynamic
+          pm.max_children = 32
+          pm.max_requests = 500
+          pm.start_servers = 2
+          pm.min_spare_servers = 2
+          pm.max_spare_servers = 5
+          listen.owner = nginx
+          listen.group = nginx
+          php_admin_value[error_log] = 'stderr'
+          php_admin_flag[log_errors] = on
+          catch_workers_output = yes
+        '';
+      };
     };
 
   serveWordpress = domains:
@@ -220,21 +224,23 @@ rec {
           expires max;
         '';
       };
-      services.phpfpm.poolConfigs."${domain}" = ''
-        listen = /srv/http/${domain}/phpfpm.pool
-        user = nginx
-        group = nginx
-        pm = dynamic
-        pm.max_children = 25
-        pm.start_servers = 5
-        pm.min_spare_servers = 3
-        pm.max_spare_servers = 20
-        listen.owner = nginx
-        listen.group = nginx
-        php_admin_value[error_log] = 'stderr'
-        php_admin_flag[log_errors] = on
-        catch_workers_output = yes
-      '';
+      services.phpfpm.pools."${domain}" = {
+        user = "nginx";
+        group = "nginx";
+        extraConfig = ''
+          listen = /srv/http/${domain}/phpfpm.pool
+          pm = dynamic
+          pm.max_children = 25
+          pm.start_servers = 5
+          pm.min_spare_servers = 3
+          pm.max_spare_servers = 20
+          listen.owner = nginx
+          listen.group = nginx
+          php_admin_value[error_log] = 'stderr'
+          php_admin_flag[log_errors] = on
+          catch_workers_output = yes
+        '';
+      };
     };
 
 }
diff --git a/lass/3modules/autowifi.nix b/lass/3modules/autowifi.nix
index 930d99727..b84569df8 100644
--- a/lass/3modules/autowifi.nix
+++ b/lass/3modules/autowifi.nix
@@ -13,7 +13,7 @@ in {
     };
   };
 
-  config = {
+  config = lib.mkIf cfg.enable {
     systemd.services.autowifi = {
       description = "Automatic wifi connector";
       wantedBy = [ "multi-user.target" ];
diff --git a/nin/0tests/dummysecrets/hashedPasswords.nix b/nin/0tests/dummysecrets/hashedPasswords.nix
new file mode 100644
index 000000000..0967ef424
--- /dev/null
+++ b/nin/0tests/dummysecrets/hashedPasswords.nix
@@ -0,0 +1 @@
+{}
diff --git a/nin/0tests/dummysecrets/ssh.id_ed25519 b/nin/0tests/dummysecrets/ssh.id_ed25519
new file mode 100644
index 000000000..e69de29bb
diff --git a/nin/1systems/axon/config.nix b/nin/1systems/axon/config.nix
new file mode 100644
index 000000000..5e81afdbd
--- /dev/null
+++ b/nin/1systems/axon/config.nix
@@ -0,0 +1,132 @@
+# Edit this configuration file to define what should be installed on
+# your system.  Help is available in the configuration.nix(5) man page
+# and in the NixOS manual (accessible by running ‘nixos-help’).
+
+{ config, lib, pkgs, ... }:
+
+with lib;
+
+{
+  imports = [
+    <stockholm/nin>
+    <nixpkgs/nixos/modules/installer/scan/not-detected.nix>
+    #../2configs/copyq.nix
+    <stockholm/nin/2configs/ableton.nix>
+    <stockholm/nin/2configs/games.nix>
+    <stockholm/nin/2configs/git.nix>
+    <stockholm/nin/2configs/retiolum.nix>
+    <stockholm/nin/2configs/termite.nix>
+  ];
+
+  krebs.build.host = config.krebs.hosts.axon;
+
+  boot.initrd.availableKernelModules = [ "xhci_pci" "ehci_pci" "ahci" "sd_mod" "sr_mod" "rtsx_pci_sdmmc" ];
+  boot.kernelModules = [ "kvm-intel" ];
+  boot.extraModulePackages = [ ];
+
+  fileSystems."/" =
+    { device = "/dev/pool/root";
+      fsType = "ext4";
+    };
+
+  fileSystems."/tmp" =
+    { device = "tmpfs";
+      fsType = "tmpfs";
+    };
+
+  fileSystems."/boot" =
+    { device = "/dev/sda1";
+      fsType = "ext2";
+    };
+
+  boot.initrd.luks.devices.crypted.device = "/dev/sda2";
+  boot.initrd.luks.cryptoModules = [ "aes" "sha512" "sha1" "xts" ];
+
+  swapDevices = [ ];
+
+  nix.maxJobs = lib.mkDefault 4;
+  # Use the GRUB 2 boot loader.
+  boot.loader.grub.enable = true;
+  boot.loader.grub.version = 2;
+  # Define on which hard drive you want to install Grub.
+  boot.loader.grub.device = "/dev/sda";
+
+  # Enable the OpenSSH daemon.
+  services.openssh.enable = true;
+
+  # Enable CUPS to print documents.
+  # services.printing.enable = true;
+
+  # nin config
+  time.timeZone = "Europe/Berlin";
+  services.xserver = {
+    enable = true;
+
+    displayManager.lightdm.enable = true;
+  };
+
+  networking.networkmanager.enable = true;
+  #networking.wireless.enable = true;
+
+  hardware.pulseaudio = {
+    enable = true;
+    systemWide = true;
+  };
+
+  hardware.bluetooth.enable = true;
+
+  hardware.opengl.driSupport32Bit = true;
+
+  #nixpkgs.config.steam.java = true;
+
+  environment.systemPackages = with pkgs; [
+    atom
+    chromium
+    firefox
+    git
+    htop
+    keepassx
+    lmms
+    networkmanagerapplet
+    openvpn
+    python
+    ruby
+    steam
+    taskwarrior
+    thunderbird
+    vim
+    virtmanager
+  ];
+
+  nixpkgs.config = {
+
+    allowUnfree = true;
+
+  };
+
+  #services.logind.extraConfig = "HandleLidSwitch=ignore";
+
+  services.xserver.synaptics = {
+    enable = true;
+  };
+
+  services.xserver.displayManager.sessionCommands = ''
+    ${pkgs.xorg.xhost}/bin/xhost + local:
+  '';
+
+  services.xserver.desktopManager.xfce = let
+    xbindConfig = pkgs.writeText "xbindkeysrc" ''
+      "${pkgs.pass}/bin/passmenu --type"
+        Control + p
+  '';
+  in {
+  enable = true;
+      extraSessionCommands = ''
+      ${pkgs.xbindkeys}/bin/xbindkeys -f ${xbindConfig}
+    '';
+  };
+
+ # The NixOS release to be compatible with for stateful data such as databases.
+  system.stateVersion = "17.03";
+
+}
diff --git a/nin/1systems/hiawatha/config.nix b/nin/1systems/hiawatha/config.nix
new file mode 100644
index 000000000..a09eed958
--- /dev/null
+++ b/nin/1systems/hiawatha/config.nix
@@ -0,0 +1,126 @@
+# Edit this configuration file to define what should be installed on
+# your system.  Help is available in the configuration.nix(5) man page
+# and in the NixOS manual (accessible by running ‘nixos-help’).
+
+{ config, lib, pkgs, ... }:
+
+with lib;
+
+{
+  imports = [
+    <stockholm/nin>
+    <nixpkgs/nixos/modules/installer/scan/not-detected.nix>
+    #../2configs/copyq.nix
+    <stockholm/nin/2configs/games.nix>
+    <stockholm/nin/2configs/git.nix>
+    <stockholm/nin/2configs/retiolum.nix>
+    <stockholm/nin/2configs/termite.nix>
+  ];
+
+  krebs.build.host = config.krebs.hosts.hiawatha;
+
+  boot.initrd.availableKernelModules = [ "xhci_pci" "ehci_pci" "ahci" "sd_mod" "sr_mod" "rtsx_pci_sdmmc" ];
+  boot.kernelModules = [ "kvm-intel" ];
+  boot.extraModulePackages = [ ];
+
+  fileSystems."/" =
+    { device = "/dev/disk/by-uuid/b83f8830-84f3-4282-b10e-015c4b76bd9e";
+      fsType = "ext4";
+    };
+
+  fileSystems."/tmp" =
+    { device = "tmpfs";
+      fsType = "tmpfs";
+    };
+
+  fileSystems."/home" =
+    { device = "/dev/fam/home";
+    };
+
+
+  fileSystems."/boot" =
+    { device = "/dev/disk/by-uuid/2f319b08-2560-401d-b53c-2abd28f1a010";
+      fsType = "ext2";
+    };
+
+  boot.initrd.luks.devices = [ { name = "luksroot"; device = "/dev/sda2"; } ];
+  boot.initrd.luks.cryptoModules = [ "aes" "sha512" "sha1" "xts" ];
+
+  swapDevices = [ ];
+
+  nix.maxJobs = lib.mkDefault 4;
+  # Use the GRUB 2 boot loader.
+  boot.loader.grub.enable = true;
+  boot.loader.grub.version = 2;
+  # Define on which hard drive you want to install Grub.
+  boot.loader.grub.device = "/dev/sda";
+
+  # Enable the OpenSSH daemon.
+  services.openssh.enable = true;
+
+  # Enable CUPS to print documents.
+  # services.printing.enable = true;
+
+  fileSystems."/home/nin/.local/share/Steam" = {
+    device = "/dev/fam/steam";
+  };
+
+  # nin config
+  time.timeZone = "Europe/Berlin";
+  services.xserver.enable = true;
+
+  networking.networkmanager.enable = true;
+  #networking.wireless.enable = true;
+
+  hardware.pulseaudio = {
+    enable = true;
+    systemWide = true;
+  };
+
+  hardware.bluetooth.enable = true;
+
+  hardware.opengl.driSupport32Bit = true;
+
+  #nixpkgs.config.steam.java = true;
+
+  environment.systemPackages = with pkgs; [
+    firefox
+    git
+    lmms
+    networkmanagerapplet
+    python
+    steam
+    thunderbird
+    vim
+    virtmanager
+  ];
+
+  nixpkgs.config = {
+
+    allowUnfree = true;
+
+  };
+
+  #services.logind.extraConfig = "HandleLidSwitch=ignore";
+
+  services.xserver.synaptics = {
+    enable = true;
+  };
+
+
+  services.xserver.desktopManager.xfce = let
+    xbindConfig = pkgs.writeText "xbindkeysrc" ''
+      "${pkgs.pass}/bin/passmenu --type"
+        Control + p
+  '';
+  in {
+    enable = true;
+      extraSessionCommands = ''
+      ${pkgs.xbindkeys}/bin/xbindkeys -f ${xbindConfig}
+    '';
+  };
+
+ # The NixOS release to be compatible with for stateful data such as databases.
+  system.stateVersion = "17.03";
+
+}
diff --git a/nin/1systems/onondaga/config.nix b/nin/1systems/onondaga/config.nix
new file mode 100644
index 000000000..3cd0773ae
--- /dev/null
+++ b/nin/1systems/onondaga/config.nix
@@ -0,0 +1,23 @@
+# Edit this configuration file to define what should be installed on
+# your system.  Help is available in the configuration.nix(5) man page
+# and in the NixOS manual (accessible by running ‘nixos-help’).
+
+{ config, lib, pkgs, ... }:
+
+{
+  imports = [
+    <stockholm/nin>
+    <stockholm/nin/2configs/retiolum.nix>
+    <stockholm/nin/2configs/weechat.nix>
+    <stockholm/nin/2configs/git.nix>
+  ];
+
+  krebs.build.host = config.krebs.hosts.onondaga;
+
+  boot.isContainer = true;
+  networking.useDHCP = false;
+
+  time.timeZone = "Europe/Amsterdam";
+
+  services.openssh.enable = true;
+}
diff --git a/nin/2configs/ableton.nix b/nin/2configs/ableton.nix
new file mode 100644
index 000000000..343a9089d
--- /dev/null
+++ b/nin/2configs/ableton.nix
@@ -0,0 +1,20 @@
+{ config, pkgs, ... }: let
+  mainUser = config.users.extraUsers.nin;
+in {
+  users.users= {
+    ableton = {
+      isNormalUser = true;
+      extraGroups = [
+        "audio"
+        "video"
+      ];
+      packages = [
+        pkgs.wine
+        pkgs.winetricks
+      ];
+    };
+  };
+  security.sudo.extraConfig = ''
+    ${mainUser.name} ALL=(ableton) NOPASSWD: ALL
+  '';
+}
diff --git a/nin/2configs/copyq.nix b/nin/2configs/copyq.nix
new file mode 100644
index 000000000..0616c4025
--- /dev/null
+++ b/nin/2configs/copyq.nix
@@ -0,0 +1,38 @@
+{ config, pkgs, ... }:
+with import <stockholm/lib>;
+let
+  copyqConfig = pkgs.writeDash "copyq-config" ''
+    ${pkgs.copyq}/bin/copyq config check_clipboard true
+    ${pkgs.copyq}/bin/copyq config check_selection true
+    ${pkgs.copyq}/bin/copyq config copy_clipboard true
+    ${pkgs.copyq}/bin/copyq config copy_selection true
+
+    ${pkgs.copyq}/bin/copyq config activate_closes true
+    ${pkgs.copyq}/bin/copyq config clipboard_notification_lines 0
+    ${pkgs.copyq}/bin/copyq config clipboard_tab clipboard
+    ${pkgs.copyq}/bin/copyq config disable_tray true
+    ${pkgs.copyq}/bin/copyq config hide_tabs true
+    ${pkgs.copyq}/bin/copyq config hide_toolbar true
+    ${pkgs.copyq}/bin/copyq config item_popup_interval true
+    ${pkgs.copyq}/bin/copyq config maxitems 1000
+    ${pkgs.copyq}/bin/copyq config move true
+    ${pkgs.copyq}/bin/copyq config text_wrap true
+  '';
+in {
+  systemd.user.services.copyq = {
+    after = [ "graphical.target" ];
+    wants = [ "graphical.target" ];
+    wantedBy = [ "default.target" ];
+    environment = {
+      DISPLAY = ":0";
+    };
+    serviceConfig = {
+      SyslogIdentifier = "copyq";
+      ExecStart = "${pkgs.copyq}/bin/copyq";
+      ExecStartPost = copyqConfig;
+      Restart = "always";
+      RestartSec = "2s";
+      StartLimitBurst = 0;
+    };
+  };
+}
diff --git a/nin/2configs/default.nix b/nin/2configs/default.nix
new file mode 100644
index 000000000..250383ca8
--- /dev/null
+++ b/nin/2configs/default.nix
@@ -0,0 +1,173 @@
+{ config, lib, pkgs, ... }:
+
+with import <stockholm/lib>;
+{
+  imports = [
+    ../2configs/vim.nix
+    <stockholm/krebs/2configs/binary-cache/nixos.nix>
+    <stockholm/krebs/2configs/binary-cache/prism.nix>
+    {
+      users.extraUsers =
+        mapAttrs (_: h: { hashedPassword = h; })
+                 (import <secrets/hashedPasswords.nix>);
+    }
+    {
+      users.users = {
+        root = {
+          openssh.authorizedKeys.keys = [
+            config.krebs.users.nin.pubkey
+            config.krebs.users.nin_h.pubkey
+          ];
+        };
+        nin = {
+          name = "nin";
+          uid = 1337;
+          home = "/home/nin";
+          group = "users";
+          createHome = true;
+          useDefaultShell = true;
+          extraGroups = [
+            "audio"
+            "fuse"
+          ];
+          openssh.authorizedKeys.keys = [
+            config.krebs.users.nin.pubkey
+            config.krebs.users.nin_h.pubkey
+          ];
+        };
+      };
+    }
+    {
+      environment.variables = {
+        NIX_PATH = mkForce "secrets=/var/src/stockholm/null:/var/src";
+      };
+    }
+    (let ca-bundle = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"; in {
+      environment.variables = {
+        CURL_CA_BUNDLE = ca-bundle;
+        GIT_SSL_CAINFO = ca-bundle;
+        SSL_CERT_FILE = ca-bundle;
+      };
+    })
+  ];
+
+  networking.hostName = config.krebs.build.host.name;
+  nix.maxJobs = config.krebs.build.host.cores;
+
+  krebs = {
+    enable = true;
+    dns.search-domain = "r";
+    build = {
+      user = config.krebs.users.nin;
+    };
+  };
+
+  nix.useSandbox = true;
+
+  users.mutableUsers = false;
+
+  services.timesyncd.enable = true;
+
+  #why is this on in the first place?
+  services.nscd.enable = false;
+
+  boot.tmpOnTmpfs = true;
+  # see tmpfiles.d(5)
+  systemd.tmpfiles.rules = [
+    "d /tmp 1777 root root - -"
+  ];
+
+  # multiple-definition-problem when defining environment.variables.EDITOR
+  environment.extraInit = ''
+    EDITOR=vim
+  '';
+
+  nixpkgs.config.allowUnfree = true;
+
+  environment.shellAliases = {
+    gs = "git status";
+  };
+
+  environment.systemPackages = with pkgs; [
+  #stockholm
+    git
+    gnumake
+    jq
+    proot
+    pavucontrol
+    populate
+    p7zip
+    termite
+    unzip
+    unrar
+    hashPassword
+  ];
+
+  programs.bash = {
+    enableCompletion = true;
+    interactiveShellInit = ''
+      HISTCONTROL='erasedups:ignorespace'
+      HISTSIZE=65536
+      HISTFILESIZE=$HISTSIZE
+
+      shopt -s checkhash
+      shopt -s histappend histreedit histverify
+      shopt -s no_empty_cmd_completion
+      complete -d cd
+    '';
+    promptInit = ''
+      if test $UID = 0; then
+        PS1='\[\033[1;31m\]$PWD\[\033[0m\] '
+      elif test $UID = 1337; then
+        PS1='\[\033[1;32m\]$PWD\[\033[0m\] '
+      else
+        PS1='\[\033[1;33m\]\u@$PWD\[\033[0m\] '
+      fi
+      if test -n "$SSH_CLIENT"; then
+        PS1='\[\033[35m\]\h'" $PS1"
+      fi
+    '';
+  };
+
+  services.openssh = {
+    enable = true;
+    hostKeys = [
+      # XXX bits here make no science
+      { bits = 8192; type = "ed25519"; path = "/etc/ssh/ssh_host_ed25519_key"; }
+    ];
+  };
+
+  services.journald.extraConfig = ''
+    SystemMaxUse=1G
+    RuntimeMaxUse=128M
+  '';
+
+  krebs.iptables = {
+    enable = true;
+    tables = {
+      nat.PREROUTING.rules = [
+        { predicate = "! -i retiolum -p tcp -m tcp --dport 22"; target = "REDIRECT --to-ports 0"; precedence = 100; }
+        { predicate = "-p tcp -m tcp --dport 45621"; target = "REDIRECT --to-ports 22"; precedence = 99; }
+      ];
+      nat.OUTPUT.rules = [
+        { predicate = "-o lo -p tcp -m tcp --dport 45621"; target = "REDIRECT --to-ports 22"; precedence = 100; }
+      ];
+      filter.INPUT.policy = "DROP";
+      filter.FORWARD.policy = "DROP";
+      filter.INPUT.rules = [
+        { predicate = "-m conntrack --ctstate RELATED,ESTABLISHED"; target = "ACCEPT"; precedence = 10001; }
+        { predicate = "-p icmp"; target = "ACCEPT"; precedence = 10000; }
+        { predicate = "-p ipv6-icmp"; target = "ACCEPT"; v4 = false;  precedence = 10000; }
+        { predicate = "-i lo"; target = "ACCEPT"; precedence = 9999; }
+        { predicate = "-p tcp --dport 22"; target = "ACCEPT"; precedence = 9998; }
+        { predicate = "-p tcp -i retiolum"; target = "REJECT --reject-with tcp-reset"; precedence = -10000; }
+        { predicate = "-p udp -i retiolum"; target = "REJECT --reject-with icmp-port-unreachable"; v6 = false; precedence = -10000; }
+        { predicate = "-i retiolum"; target = "REJECT --reject-with icmp-proto-unreachable"; v6 = false; precedence = -10000; }
+      ];
+    };
+  };
+
+  networking.dhcpcd.extraConfig = ''
+    noipv4ll
+  '';
+}
diff --git a/nin/2configs/games.nix b/nin/2configs/games.nix
new file mode 100644
index 000000000..15e17238d
--- /dev/null
+++ b/nin/2configs/games.nix
@@ -0,0 +1,70 @@
+{ config, pkgs, ... }:
+
+let
+  mainUser = config.users.extraUsers.mainUser;
+  vdoom = pkgs.writeDash "vdoom" ''
+    ${pkgs.zandronum}/bin/zandronum \
+      -fov 120 \
+      "$@"
+  '';
+  doom = pkgs.writeDash "doom" ''
+    DOOM_DIR=''${DOOM_DIR:-~/doom/}
+    ${vdoom} \
+      -file $DOOM_DIR/lib/brutalv20.pk3 \
+      "$@"
+  '';
+  doom1 = pkgs.writeDashBin "doom1" ''
+    DOOM_DIR=''${DOOM_DIR:-~/doom/}
+    ${doom} -iwad $DOOM_DIR/wads/stock/doom.wad "$@"
+  '';
+  doom2 = pkgs.writeDashBin "doom2" ''
+    DOOM_DIR=''${DOOM_DIR:-~/doom/}
+    ${doom} -iwad $DOOM_DIR/wads/stock/doom2.wad "$@"
+  '';
+  vdoom1 = pkgs.writeDashBin "vdoom1" ''
+    DOOM_DIR=''${DOOM_DIR:-~/doom/}
+    ${vdoom} -iwad $DOOM_DIR/wads/stock/doom.wad "$@"
+  '';
+  vdoom2 = pkgs.writeDashBin "vdoom2" ''
+    DOOM_DIR=''${DOOM_DIR:-~/doom/}
+    ${vdoom} -iwad $DOOM_DIR/wads/stock/doom2.wad "$@"
+  '';
+
+  doomservercfg = pkgs.writeText "doomserver.cfg" ''
+    skill 7
+    #survival true
+    #sv_maxlives 4
+    #sv_norespawn true
+    #sv_weapondrop true
+    no_jump true
+    #sv_noweaponspawn true
+    sv_sharekeys true
+    sv_survivalcountdowntime 1
+    sv_noteamselect true
+    sv_updatemaster false
+    #sv_coop_loseinventory true
+    #cl_startasspectator false
+    #lms_spectatorview false
+  '';
+
+  vdoomserver = pkgs.writeDashBin "vdoomserver" ''
+    DOOM_DIR=''${DOOM_DIR:-~/doom/}
+
+    ${pkgs.zandronum}/bin/zandronum-server \
+    +exec ${doomservercfg} \
+    "$@"
+  '';
+
+in {
+  environment.systemPackages = with pkgs; [
+    dwarf_fortress
+    doom1
+    doom2
+    vdoom1
+    vdoom2
+    vdoomserver
+  ];
+
+  hardware.pulseaudio.support32Bit = true;
+
+}
diff --git a/nin/2configs/git.nix b/nin/2configs/git.nix
new file mode 100644
index 000000000..aed4a9f48
--- /dev/null
+++ b/nin/2configs/git.nix
@@ -0,0 +1,60 @@
+{ config, lib, pkgs, ... }:
+
+with import <stockholm/lib>;
+
+let
+
+  out = {
+    services.nginx.enable = true;
+    krebs.git = {
+      enable = true;
+      cgit = {
+        settings = {
+          root-title = "public repositories at ${config.krebs.build.host.name}";
+          root-desc = "keep calm and engage";
+        };
+      };
+      repos = mapAttrs (_: s: removeAttrs s ["collaborators"]) repos;
+      rules = rules;
+    };
+
+    krebs.iptables.tables.filter.INPUT.rules = [
+      { predicate = "-i retiolum -p tcp --dport 80"; target = "ACCEPT"; }
+    ];
+  };
+
+  repos = public-repos;
+
+  rules = concatMap make-rules (attrValues repos);
+
+  public-repos = mapAttrs make-public-repo {
+    stockholm = {
+      cgit.desc = "take all the computers hostage, they'll love you!";
+    };
+  };
+
+  make-public-repo = name: { cgit ? {}, ... }: {
+    inherit cgit name;
+    public = true;
+  };
+
+  make-rules =
+    with git // config.krebs.users;
+    repo:
+      singleton {
+        user = [ nin nin_h ];
+        repo = [ repo ];
+        perm = push "refs/*" [ non-fast-forward create delete merge ];
+      } ++
+      optional repo.public {
+        user = attrValues config.krebs.users;
+        repo = [ repo ];
+        perm = fetch;
+      } ++
+      optional (length (repo.collaborators or []) > 0) {
+        user = repo.collaborators;
+        repo = [ repo ];
+        perm = fetch;
+      };
+
+in out
diff --git a/nin/2configs/im.nix b/nin/2configs/im.nix
new file mode 100644
index 000000000..b078dbd53
--- /dev/null
+++ b/nin/2configs/im.nix
@@ -0,0 +1,19 @@
+{ config, lib, pkgs, ... }:
+with import <stockholm/lib>;
+{
+  environment.systemPackages = with pkgs; [
+    (pkgs.writeDashBin "im" ''
+      export PATH=${makeSearchPath "bin" (with pkgs; [
+        tmux
+        gnugrep
+        weechat
+      ])}
+      ssh chat@onondaga
+      if tmux list-sessions -F\#S | grep -q '^im''$'; then
+        exec tmux attach -t im
+      else
+        exec tmux new -s im weechat
+      fi
+    '')
+  ];
+}
diff --git a/nin/2configs/retiolum.nix b/nin/2configs/retiolum.nix
new file mode 100644
index 000000000..821e3cc00
--- /dev/null
+++ b/nin/2configs/retiolum.nix
@@ -0,0 +1,28 @@
+{ ... }:
+
+{
+
+  krebs.iptables = {
+    tables = {
+      filter.INPUT.rules = [
+        { predicate = "-i retiolum -p tcp --dport smtp"; target = "ACCEPT"; }
+        { predicate = "-p tcp --dport tinc"; target = "ACCEPT"; }
+        { predicate = "-p udp --dport tinc"; target = "ACCEPT"; }
+      ];
+    };
+  };
+
+  krebs.tinc.retiolum = {
+    enable = true;
+    connectTo = [
+      "prism"
+      "pigstarter"
+      "gum"
+      "flap"
+    ];
+  };
+
+  nixpkgs.config.packageOverrides = pkgs: {
+    tinc = pkgs.tinc_pre;
+  };
+}
diff --git a/nin/2configs/skype.nix b/nin/2configs/skype.nix
new file mode 100644
index 000000000..621dfae82
--- /dev/null
+++ b/nin/2configs/skype.nix
@@ -0,0 +1,27 @@
+{ config, lib, pkgs, ... }:
+
+let
+  mainUser = config.users.extraUsers.nin;
+  inherit (import <stockholm/lib>) genid;
+
+in {
+  users.extraUsers = {
+    skype = {
+      name = "skype";
+      uid = genid "skype";
+      description = "user for running skype";
+      home = "/home/skype";
+      useDefaultShell = true;
+      extraGroups = [ "audio" "video" ];
+      createHome = true;
+    };
+  };
+
+  krebs.per-user.skype.packages = [
+    pkgs.skype
+  ];
+
+  security.sudo.extraConfig = ''
+    ${mainUser.name} ALL=(skype) NOPASSWD: ALL
+  '';
+}
diff --git a/nin/2configs/termite.nix b/nin/2configs/termite.nix
new file mode 100644
index 000000000..942446b01
--- /dev/null
+++ b/nin/2configs/termite.nix
@@ -0,0 +1,22 @@
+{ config, pkgs, ... }:
+
+{
+  environment.systemPackages = [
+    pkgs.termite
+  ];
+
+  krebs.per-user.nin.packages = let
+    termitecfg = pkgs.writeTextFile {
+      name = "termite-config";
+      destination = "/etc/xdg/termite/config";
+      text = ''
+        [colors]
+        foreground = #d0d7d0
+        background = #000000
+      '';
+    };
+  in [
+    termitecfg
+  ];
+
+}
diff --git a/nin/2configs/vim.nix b/nin/2configs/vim.nix
new file mode 100644
index 000000000..7b5d37611
--- /dev/null
+++ b/nin/2configs/vim.nix
@@ -0,0 +1,355 @@
+{ config, lib, pkgs, ... }:
+
+with import <stockholm/lib>;
+let
+  out = {
+    environment.systemPackages = [
+      vim
+      pkgs.pythonPackages.flake8
+    ];
+
+    environment.etc.vimrc.source = vimrc;
+
+    environment.variables.EDITOR = mkForce "vim";
+    environment.variables.VIMINIT = ":so /etc/vimrc";
+  };
+
+  vimrc = pkgs.writeText "vimrc" ''
+    set nocompatible
+
+    set autoindent
+    set backspace=indent,eol,start
+    set backup
+    set backupdir=${dirs.backupdir}/
+    set directory=${dirs.swapdir}//
+    set hlsearch
+    set incsearch
+    set laststatus=2
+    set mouse=a
+    set noruler
+    set pastetoggle=<INS>
+    set runtimepath=${extra-runtimepath},$VIMRUNTIME
+    set shortmess+=I
+    set showcmd
+    set showmatch
+    set ttimeoutlen=0
+    set undodir=${dirs.undodir}
+    set undofile
+    set undolevels=1000000
+    set undoreload=1000000
+    set viminfo='20,<1000,s100,h,n${files.viminfo}
+    set visualbell
+    set wildignore+=*.o,*.class,*.hi,*.dyn_hi,*.dyn_o
+    set wildmenu
+    set wildmode=longest,full
+
+    set et ts=2 sts=2 sw=2
+
+    filetype plugin indent on
+
+    set t_Co=256
+    colorscheme hack
+    syntax on
+
+    au Syntax * syn match Garbage containedin=ALL /\s\+$/
+            \ | syn match TabStop containedin=ALL /\t\+/
+            \ | syn keyword Todo containedin=ALL TODO
+
+    au BufRead,BufNewFile *.hs so ${hs.vim}
+
+    au BufRead,BufNewFile *.nix so ${nix.vim}
+
+    au BufRead,BufNewFile /dev/shm/* set nobackup nowritebackup noswapfile
+
+    "Syntastic config
+    let g:syntastic_python_checkers=['flake8']
+
+    nmap <esc>q :buffer 
+    nmap <M-q> :buffer 
+
+    cnoremap <C-A> <Home>
+
+    noremap  <C-c> :q<cr>
+    vnoremap < <gv
+    vnoremap > >gv
+
+    nnoremap <esc>[5^  :tabp<cr>
+    nnoremap <esc>[6^  :tabn<cr>
+    nnoremap <esc>[5@  :tabm -1<cr>
+    nnoremap <esc>[6@  :tabm +1<cr>
+
+    nnoremap <f1> :tabp<cr>
+    nnoremap <f2> :tabn<cr>
+    inoremap <f1> <esc>:tabp<cr>
+    inoremap <f2> <esc>:tabn<cr>
+
+    " <C-{Up,Down,Right,Left>
+    noremap <esc>Oa <nop> | noremap! <esc>Oa <nop>
+    noremap <esc>Ob <nop> | noremap! <esc>Ob <nop>
+    noremap <esc>Oc <nop> | noremap! <esc>Oc <nop>
+    noremap <esc>Od <nop> | noremap! <esc>Od <nop>
+    " <[C]S-{Up,Down,Right,Left>
+    noremap <esc>[a <nop> | noremap! <esc>[a <nop>
+    noremap <esc>[b <nop> | noremap! <esc>[b <nop>
+    noremap <esc>[c <nop> | noremap! <esc>[c <nop>
+    noremap <esc>[d <nop> | noremap! <esc>[d <nop>
+    vnoremap u <nop>
+  '';
+
+  extra-runtimepath = concatMapStringsSep "," (pkg: "${pkg.rtp}") [
+    pkgs.vimPlugins.Syntastic
+    pkgs.vimPlugins.undotree
+    pkgs.vimPlugins.airline
+    (pkgs.vimUtils.buildVimPlugin {
+      name = "file-line-1.0";
+      src = pkgs.fetchgit {
+        url = git://github.com/bogado/file-line;
+        rev = "refs/tags/1.0";
+        sha256 = "0z47zq9rqh06ny0q8lpcdsraf3lyzn9xvb59nywnarf3nxrk6hx0";
+      };
+    })
+    ((rtp: rtp // { inherit rtp; }) (pkgs.writeTextFile (let
+      name = "hack";
+    in {
+      name = "vim-color-${name}-1.0.2";
+      destination = "/colors/${name}.vim";
+      text = /* vim */ ''
+        set background=dark
+        hi clear
+        if exists("syntax_on")
+          syntax clear
+        endif
+
+        let colors_name = ${toJSON name}
+
+        hi Normal       ctermbg=235
+        hi Comment      ctermfg=242
+        hi Constant     ctermfg=062
+        hi Identifier   ctermfg=068
+        hi Function     ctermfg=041
+        hi Statement    ctermfg=167
+        hi PreProc      ctermfg=167
+        hi Type         ctermfg=041
+        hi Delimiter    ctermfg=251
+        hi Special      ctermfg=062
+
+        hi Garbage      ctermbg=088
+        hi TabStop      ctermbg=016
+        hi Todo         ctermfg=174 ctermbg=NONE
+
+        hi NixCode      ctermfg=148
+        hi NixData      ctermfg=149
+        hi NixQuote     ctermfg=150
+
+        hi diffNewFile  ctermfg=207
+        hi diffFile     ctermfg=207
+        hi diffLine     ctermfg=207
+        hi diffSubname  ctermfg=207
+        hi diffAdded    ctermfg=010
+        hi diffRemoved  ctermfg=009
+      '';
+    })))
+    ((rtp: rtp // { inherit rtp; }) (pkgs.writeTextFile (let
+      name = "vim";
+    in {
+      name = "vim-syntax-${name}-1.0.0";
+      destination = "/syntax/${name}.vim";
+      text = /* vim */ ''
+        ${concatMapStringsSep "\n" (s: /* vim */ ''
+          syn keyword vimColor${s} ${s}
+            \ containedin=ALLBUT,vimComment,vimLineComment
+          hi vimColor${s} ctermfg=${s}
+        '') (map (i: lpad 3 "0" (toString i)) (range 0 255))}
+      '';
+    })))
+    ((rtp: rtp // { inherit rtp; }) (pkgs.writeTextFile (let
+      name = "showsyntax";
+    in {
+      name = "vim-plugin-${name}-1.0.0";
+      destination = "/plugin/${name}.vim";
+      text = /* vim */ ''
+        if exists('g:loaded_showsyntax')
+          finish
+        endif
+        let g:loaded_showsyntax = 0
+
+        fu! ShowSyntax()
+          let id = synID(line("."), col("."), 1)
+          let name = synIDattr(id, "name")
+          let transName = synIDattr(synIDtrans(id),"name")
+          if name != transName
+            let name .= " (" . transName . ")"
+          endif
+          echo "Syntax: " . name
+        endfu
+
+        command! -n=0 -bar ShowSyntax :call ShowSyntax()
+      '';
+    })))
+  ];
+
+  dirs = {
+    backupdir = "$HOME/.cache/vim/backup";
+    swapdir   = "$HOME/.cache/vim/swap";
+    undodir   = "$HOME/.cache/vim/undo";
+  };
+  files = {
+    viminfo   = "$HOME/.cache/vim/info";
+  };
+
+  mkdirs = let
+    dirOf = s: let out = concatStringsSep "/" (init (splitString "/" s));
+               in assert out != ""; out;
+    alldirs = attrValues dirs ++ map dirOf (attrValues files);
+  in unique (sort lessThan alldirs);
+
+  vim = pkgs.writeDashBin "vim" ''
+    set -efu
+    (umask 0077; exec ${pkgs.coreutils}/bin/mkdir -p ${toString mkdirs})
+    exec ${pkgs.vim}/bin/vim "$@"
+  '';
+
+
+  hs.vim = pkgs.writeText "hs.vim" ''
+    syn region String start=+\[[[:alnum:]]*|+ end=+|]+
+
+    hi link ConId Identifier
+    hi link VarId Identifier
+    hi link hsDelimiter Delimiter
+  '';
+
+  nix.vim = pkgs.writeText "nix.vim" ''
+    setf nix
+
+    " Ref <nix/src/libexpr/lexer.l>
+    syn match NixID    /[a-zA-Z\_][a-zA-Z0-9\_\'\-]*/
+    syn match NixINT   /\<[0-9]\+\>/
+    syn match NixPATH  /[a-zA-Z0-9\.\_\-\+]*\(\/[a-zA-Z0-9\.\_\-\+]\+\)\+/
+    syn match NixHPATH /\~\(\/[a-zA-Z0-9\.\_\-\+]\+\)\+/
+    syn match NixSPATH /<[a-zA-Z0-9\.\_\-\+]\+\(\/[a-zA-Z0-9\.\_\-\+]\+\)*>/
+    syn match NixURI   /[a-zA-Z][a-zA-Z0-9\+\-\.]*:[a-zA-Z0-9\%\/\?\:\@\&\=\+\$\,\-\_\.\!\~\*\']\+/
+    syn region NixSTRING
+      \ matchgroup=NixSTRING
+      \ start='"'
+      \ skip='\\"'
+      \ end='"'
+    syn region NixIND_STRING
+      \ matchgroup=NixIND_STRING
+      \ start="'''"
+      \ skip="'''\('\|[$]\|\\[nrt]\)"
+      \ end="'''"
+
+    syn match NixOther /[():/;=.,?\[\]]/
+
+    syn match NixCommentMatch /\(^\|\s\)#.*/
+    syn region NixCommentRegion start="/\*" end="\*/"
+
+    hi link NixCode Statement
+    hi link NixData Constant
+    hi link NixComment Comment
+
+    hi link NixCommentMatch NixComment
+    hi link NixCommentRegion NixComment
+    hi link NixID NixCode
+    hi link NixINT NixData
+    hi link NixPATH NixData
+    hi link NixHPATH NixData
+    hi link NixSPATH NixData
+    hi link NixURI NixData
+    hi link NixSTRING NixData
+    hi link NixIND_STRING NixData
+
+    hi link NixEnter NixCode
+    hi link NixOther NixCode
+    hi link NixQuote NixData
+
+    syn cluster nix_has_dollar_curly contains=@nix_ind_strings,@nix_strings
+    syn cluster nix_ind_strings contains=NixIND_STRING
+    syn cluster nix_strings contains=NixSTRING
+
+    ${concatStringsSep "\n" (mapAttrsToList (lang: { extraStart ? null }: let
+      startAlts = filter isString [
+        ''/\* ${lang} \*/''
+        extraStart
+      ];
+      sigil = ''\(${concatStringsSep ''\|'' startAlts}\)[ \t\r\n]*'';
+    in /* vim */ ''
+      syn include @nix_${lang}_syntax syntax/${lang}.vim
+      unlet b:current_syntax
+
+      syn match nix_${lang}_sigil
+        \ X${replaceStrings ["X"] ["\\X"] sigil}\ze\('''\|"\)X
+        \ nextgroup=nix_${lang}_region_IND_STRING,nix_${lang}_region_STRING
+        \ transparent
+
+      syn region nix_${lang}_region_STRING
+        \ matchgroup=NixSTRING
+        \ start='"'
+        \ skip='\\"'
+        \ end='"'
+        \ contained
+        \ contains=@nix_${lang}_syntax
+        \ transparent
+
+      syn region nix_${lang}_region_IND_STRING
+        \ matchgroup=NixIND_STRING
+        \ start="'''"
+        \ skip="'''\('\|[$]\|\\[nrt]\)"
+        \ end="'''"
+        \ contained
+        \ contains=@nix_${lang}_syntax
+        \ transparent
+
+      syn cluster nix_ind_strings
+        \ add=nix_${lang}_region_IND_STRING
+
+      syn cluster nix_strings
+        \ add=nix_${lang}_region_STRING
+
+      syn cluster nix_has_dollar_curly
+        \ add=@nix_${lang}_syntax
+    '') {
+      c = {};
+      cabal = {};
+      haskell = {};
+      sh.extraStart = ''write\(Ba\|Da\)sh[^ \t\r\n]*[ \t\r\n]*"[^"]*"'';
+      vim.extraStart =
+        ''write[^ \t\r\n]*[ \t\r\n]*"\(\([^"]*\.\)\?vimrc\|[^"]*\.vim\)"'';
+    })}
+
+    " Clear syntax that interferes with nixINSIDE_DOLLAR_CURLY.
+    syn clear shVarAssign
+
+    syn region nixINSIDE_DOLLAR_CURLY
+      \ matchgroup=NixEnter
+      \ start="[$]{"
+      \ end="}"
+      \ contains=TOP
+      \ containedin=@nix_has_dollar_curly
+      \ transparent
+
+    syn region nix_inside_curly
+      \ matchgroup=NixEnter
+      \ start="{"
+      \ end="}"
+      \ contains=TOP
+      \ containedin=nixINSIDE_DOLLAR_CURLY,nix_inside_curly
+      \ transparent
+
+    syn match NixQuote /'''\([''$']\|\\.\)/he=s+2
+      \ containedin=@nix_ind_strings
+      \ contained
+
+    syn match NixQuote /\\./he=s+1
+      \ containedin=@nix_strings
+      \ contained
+
+    syn sync fromstart
+
+    let b:current_syntax = "nix"
+
+    set isk=@,48-57,_,192-255,-,'
+    set bg=dark
+  '';
+in
+out
diff --git a/nin/2configs/weechat.nix b/nin/2configs/weechat.nix
new file mode 100644
index 000000000..6c0fb313e
--- /dev/null
+++ b/nin/2configs/weechat.nix
@@ -0,0 +1,21 @@
+{ config, lib, pkgs, ... }:
+
+let
+  inherit (import <stockholm/lib>) genid;
+in {
+  krebs.per-user.chat.packages = with pkgs; [
+    mosh
+    weechat
+    tmux
+  ];
+
+  users.extraUsers.chat = {
+    home = "/home/chat";
+    uid = genid "chat";
+    useDefaultShell = true;
+    createHome = true;
+    openssh.authorizedKeys.keys = [
+      config.krebs.users.nin.pubkey
+    ];
+  };
+}
diff --git a/nin/default.nix b/nin/default.nix
new file mode 100644
index 000000000..c31d6d949
--- /dev/null
+++ b/nin/default.nix
@@ -0,0 +1,7 @@
+_:
+{
+  imports = [
+    ../krebs
+    ./2configs
+  ];
+}
diff --git a/nin/krops.nix b/nin/krops.nix
new file mode 100644
index 000000000..52aeb8470
--- /dev/null
+++ b/nin/krops.nix
@@ -0,0 +1,35 @@
+{ name }: let
+  inherit (import ../krebs/krops.nix { inherit name; })
+    krebs-source
+    lib
+    pkgs
+  ;
+
+  source = { test }: lib.evalSource [
+    (krebs-source { test = test; })
+    {
+      nixos-config.symlink = "stockholm/nin/1systems/${name}/config.nix";
+      secrets = if test then {
+        file = toString ./0tests/dummysecrets;
+      } else {
+        pass = {
+          dir = "${lib.getEnv "HOME"}/.password-store";
+          name = "hosts/${name}";
+        };
+      };
+    }
+  ];
+
+in {
+  # usage: $(nix-build --no-out-link --argstr name HOSTNAME -A deploy)
+  deploy = pkgs.krops.writeDeploy "${name}-deploy" {
+    source = source { test = false; };
+    target = "root@${name}/var/src";
+  };
+
+  # usage: $(nix-build --no-out-link --argstr name HOSTNAME --argstr target PATH -A test)
+  test = { target }: pkgs.krops.writeTest "${name}-test" {
+    inherit target;
+    source = source { test = true; };
+  };
+}