Declarative NixOS configuration -- Claude Code-native developer workstations with kernel-level sandboxing, multi-host architecture, and reproducible AI toolchain