NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

commit cc6ab431037cba77c880c91dec92916c900b42c7
parent 3fb6fc67c642c628b17a2944f617bad6851504a3
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Thu,  8 Oct 2026 18:32:47 +0100

feat(theme): Stylix — Rosé Pine Dawn for GRUB and the console

Diffstat:
Mflake.lock | 279+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Mflake.nix | 6++++++
Mmodules/features/desktop/niri.nix | 18++++++++++++++++++
Amodules/features/theme.nix | 40++++++++++++++++++++++++++++++++++++++++
Mmodules/home/cheats/niri.md | 17++++++++++++++++-
Mmodules/hosts/laptop/configuration.nix | 13++++++++++++-
6 files changed, 371 insertions(+), 2 deletions(-)

diff --git a/flake.lock b/flake.lock @@ -33,6 +33,74 @@ "type": "github" } }, + "base16": { + "inputs": { + "fromYaml": "fromYaml" + }, + "locked": { + "lastModified": 1755819240, + "narHash": "sha256-qcMhnL7aGAuFuutH4rq9fvAhCpJWVHLcHVZLtPctPlo=", + "owner": "SenchoPens", + "repo": "base16.nix", + "rev": "75ed5e5e3fce37df22e49125181fa37899c3ccd6", + "type": "github" + }, + "original": { + "owner": "SenchoPens", + "repo": "base16.nix", + "type": "github" + } + }, + "base16-fish": { + "flake": false, + "locked": { + "lastModified": 1765809053, + "narHash": "sha256-XCUQLoLfBJ8saWms2HCIj4NEN+xNsWBlU1NrEPcQG4s=", + "owner": "tomyun", + "repo": "base16-fish", + "rev": "86cbea4dca62e08fb7fd83a70e96472f92574782", + "type": "github" + }, + "original": { + "owner": "tomyun", + "repo": "base16-fish", + "rev": "86cbea4dca62e08fb7fd83a70e96472f92574782", + "type": "github" + } + }, + "base16-helix": { + "flake": false, + "locked": { + "lastModified": 1776754714, + "narHash": "sha256-E3OAK27smtATTmX45uoTSRsVD+Y+ZiVVfgM/tjpbtYg=", + "owner": "tinted-theming", + "repo": "base16-helix", + "rev": "4d508123037e7851ad36ebf7d9c48b0e9e1eb581", + "type": "github" + }, + "original": { + "owner": "tinted-theming", + "repo": "base16-helix", + "type": "github" + } + }, + "base16-vim": { + "flake": false, + "locked": { + "lastModified": 1732806396, + "narHash": "sha256-e0bpPySdJf0F68Ndanwm+KWHgQiZ0s7liLhvJSWDNsA=", + "owner": "tinted-theming", + "repo": "base16-vim", + "rev": "577fe8125d74ff456cf942c733a85d769afe58b7", + "type": "github" + }, + "original": { + "owner": "tinted-theming", + "repo": "base16-vim", + "rev": "577fe8125d74ff456cf942c733a85d769afe58b7", + "type": "github" + } + }, "bun2nix": { "inputs": { "flake-parts": [ @@ -115,6 +183,22 @@ "type": "github" } }, + "firefox-gnome-theme": { + "flake": false, + "locked": { + "lastModified": 1783570805, + "narHash": "sha256-ptl5aRlCv9/uRSv2u8Hq8UFVFeZ6Q/bT049bpqNgc3w=", + "owner": "rafaelmardojai", + "repo": "firefox-gnome-theme", + "rev": "5602ed62d638142c1ab31dccd01dfbfb28841225", + "type": "github" + }, + "original": { + "owner": "rafaelmardojai", + "repo": "firefox-gnome-theme", + "type": "github" + } + }, "flake-compat": { "flake": false, "locked": { @@ -188,6 +272,62 @@ "type": "github" } }, + "flake-parts_3": { + "inputs": { + "nixpkgs-lib": [ + "stylix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1782949081, + "narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "flake-parts", + "type": "github" + } + }, + "fromYaml": { + "flake": false, + "locked": { + "lastModified": 1731966426, + "narHash": "sha256-lq95WydhbUTWig/JpqiB7oViTcHFP8Lv41IGtayokA8=", + "owner": "SenchoPens", + "repo": "fromYaml", + "rev": "106af9e2f715e2d828df706c386a685698f3223b", + "type": "github" + }, + "original": { + "owner": "SenchoPens", + "repo": "fromYaml", + "type": "github" + } + }, + "gnome-shell": { + "flake": false, + "locked": { + "host": "gitlab.gnome.org", + "lastModified": 1776175984, + "narHash": "sha256-RJFlFW8GiMei6oqUGrMkGEvVqOH8U7Q8abc1yK4VKD8=", + "owner": "GNOME", + "repo": "gnome-shell", + "rev": "e0fdc4c13250e9a9b8ea9594c83925274f4a5dca", + "type": "gitlab" + }, + "original": { + "host": "gitlab.gnome.org", + "owner": "GNOME", + "ref": "50.1", + "repo": "gnome-shell", + "type": "gitlab" + } + }, "home-manager": { "inputs": { "nixpkgs": [ @@ -678,6 +818,31 @@ "type": "github" } }, + "nur": { + "inputs": { + "flake-parts": [ + "stylix", + "flake-parts" + ], + "nixpkgs": [ + "stylix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1785549842, + "narHash": "sha256-DCwBZmGsySF7oKGTRgEv2HvpxVXkHT+38VhTM76k0B4=", + "owner": "nix-community", + "repo": "NUR", + "rev": "a9f987b57594e845e3e5cdd423b9a70846d70308", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "NUR", + "type": "github" + } + }, "nvf": { "inputs": { "flake-compat": "flake-compat_2", @@ -755,6 +920,7 @@ "nixpkgs": "nixpkgs_3", "nvf": "nvf", "sops-nix": "sops-nix", + "stylix": "stylix", "wrapper-modules": "wrapper-modules" } }, @@ -778,6 +944,39 @@ "type": "github" } }, + "stylix": { + "inputs": { + "base16": "base16", + "base16-fish": "base16-fish", + "base16-helix": "base16-helix", + "base16-vim": "base16-vim", + "firefox-gnome-theme": "firefox-gnome-theme", + "flake-parts": "flake-parts_3", + "gnome-shell": "gnome-shell", + "nixpkgs": [ + "nixpkgs" + ], + "nur": "nur", + "systems": "systems_3", + "tinted-kitty": "tinted-kitty", + "tinted-schemes": "tinted-schemes", + "tinted-tmux": "tinted-tmux", + "tinted-zed": "tinted-zed" + }, + "locked": { + "lastModified": 1790880877, + "narHash": "sha256-j42XqSKOAtuqtfHiElyHre2YS/h3Y3q1DjFnKODN1/k=", + "owner": "nix-community", + "repo": "stylix", + "rev": "7c065d1ed05381fceb2403b963c5ad150f32fe39", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "stylix", + "type": "github" + } + }, "systems": { "locked": { "lastModified": 1689347949, @@ -808,6 +1007,86 @@ "type": "github" } }, + "systems_3": { + "locked": { + "lastModified": 1774449309, + "narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=", + "owner": "nix-systems", + "repo": "default", + "rev": "c29398b59d2048c4ab79345812849c9bd15e9150", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "ref": "future-26.11", + "repo": "default", + "type": "github" + } + }, + "tinted-kitty": { + "flake": false, + "locked": { + "lastModified": 1735730497, + "narHash": "sha256-4KtB+FiUzIeK/4aHCKce3V9HwRvYaxX+F1edUrfgzb8=", + "owner": "tinted-theming", + "repo": "tinted-kitty", + "rev": "de6f888497f2c6b2279361bfc790f164bfd0f3fa", + "type": "github" + }, + "original": { + "owner": "tinted-theming", + "repo": "tinted-kitty", + "type": "github" + } + }, + "tinted-schemes": { + "flake": false, + "locked": { + "lastModified": 1785153830, + "narHash": "sha256-fNdfCTeCXU3tZG3TMincd+u68qBHQgCr2Ljr/M1mWP0=", + "owner": "tinted-theming", + "repo": "schemes", + "rev": "9bd28ed313560db3c5b605c63bc4e309e78e3fc8", + "type": "github" + }, + "original": { + "owner": "tinted-theming", + "repo": "schemes", + "type": "github" + } + }, + "tinted-tmux": { + "flake": false, + "locked": { + "lastModified": 1785031658, + "narHash": "sha256-mZp9O2LjzdMzlqQF3l3fjqsuPBzXy+1qTfBEUGjTlpk=", + "owner": "tinted-theming", + "repo": "tinted-tmux", + "rev": "5d2c67f61ea7af36f16865ab6d541cdba41dc257", + "type": "github" + }, + "original": { + "owner": "tinted-theming", + "repo": "tinted-tmux", + "type": "github" + } + }, + "tinted-zed": { + "flake": false, + "locked": { + "lastModified": 1785030526, + "narHash": "sha256-klZf8UviewRkxuu74Bhbq6tqy7oxebQC7UVRWbbtQxU=", + "owner": "tinted-theming", + "repo": "base16-zed", + "rev": "16f5a8adf4a6b1310d0a61ab172de963e8f76a02", + "type": "github" + }, + "original": { + "owner": "tinted-theming", + "repo": "base16-zed", + "type": "github" + } + }, "treefmt-nix": { "inputs": { "nixpkgs": [ diff --git a/flake.nix b/flake.nix @@ -60,6 +60,12 @@ url = "github:notashelf/nvf"; inputs.nixpkgs.follows = "nixpkgs"; }; + + # Rosé Pine Dawn for GRUB and the console tuigreet runs on (modules/features/theme.nix). + stylix = { + url = "github:nix-community/stylix"; + inputs.nixpkgs.follows = "nixpkgs"; + }; }; outputs = inputs: inputs.flake-parts.lib.mkFlake { inherit inputs; } (inputs.import-tree ./modules); diff --git a/modules/features/desktop/niri.nix b/modules/features/desktop/niri.nix @@ -32,6 +32,11 @@ props.allow-when-locked = true; content.spawn-sh = cmd; }; + # a bind listed in the Mod+Shift+/ hotkey overlay under its own title + titled = title: action: _: { + props.hotkey-overlay-title = title; + content = action; + }; workspaceBinds = lib.foldl' (acc: n: acc // { "Mod+${toString n}".focus-workspace = n; "Mod+Shift+${toString n}".move-column-to-workspace = n; @@ -128,6 +133,19 @@ "Mod+Ctrl+L".set-column-width = "+5%"; "Mod+Ctrl+J".set-window-height = "-5%"; "Mod+Ctrl+K".set-window-height = "+5%"; + # stacking: pull the focused window into the column beside it + # (under the window there), or push it back out into its own column + "Mod+BracketLeft" = titled "Stack window under the column on the left" { consume-or-expel-window-left = _: { }; }; + "Mod+BracketRight" = titled "Stack window under the column on the right" { consume-or-expel-window-right = _: { }; }; + "Mod+Period" = titled "Pop bottom window out of the column" { expel-window-from-column = _: { }; }; + "Mod+W" = titled "Toggle column as tabs" { toggle-column-tabbed-display = _: { }; }; + # evening out: preset widths/heights, back to an equal split + "Mod+R" = titled "Cycle column width ⅓ ½ ⅔" { switch-preset-column-width = _: { }; }; + "Mod+Shift+R" = titled "Cycle window height ⅓ ½ ⅔" { switch-preset-window-height = _: { }; }; + "Mod+Ctrl+R" = titled "Reset window height (even split)" { reset-window-height = _: { }; }; + "Mod+Equal" = titled "Column width ½ (even columns)" { set-column-width = "50%"; }; + "Mod+Ctrl+F" = titled "Expand column into free space" { expand-column-to-available-width = _: { }; }; + "Mod+C" = titled "Centre column" { center-column = _: { }; }; "Mod+WheelScrollDown" = _: { props.cooldown-ms = 150; content.focus-workspace-down = _: { }; diff --git a/modules/features/theme.nix b/modules/features/theme.nix @@ -0,0 +1,40 @@ +# modules/features/theme.nix — Rosé Pine Dawn for the boot path, by Stylix: +# the GRUB menu and the Linux console (which is what tuigreet draws on). +# +# Stylix only themes the targets enabled here (autoEnable = false), so the +# hand-tuned Rosé Pine (main) setups for the desktop, neovim, bat, starship, +# yazi and friends stay as they are; its home-manager module is not imported. +# +# The console target maps the scheme onto the 16 VT colours, so tuigreet's +# --theme names in configuration.nix resolve to Dawn: +# black base00 #faf4ed (bg) · red love · green pine · yellow rose · blue iris +# magenta gold · cyan foam · gray base05 #575279 (text) · darkgray muted +{ inputs, ... }: +{ + flake.nixosModules.theme = + { pkgs, ... }: + { + imports = [ inputs.stylix.nixosModules.stylix ]; + + stylix = { + enable = true; + autoEnable = false; + homeManagerIntegration.autoImport = false; + + base16Scheme = "${pkgs.base16-schemes}/share/themes/rose-pine-dawn.yaml"; + polarity = "light"; + + # GRUB renders these (converted to .pf2); applications is its font size, + # sized up for the 2560x1440 panel GRUB draws at natively. + fonts = { + sansSerif = { package = pkgs.noto-fonts; name = "Noto Sans"; }; + monospace = { package = pkgs.noto-fonts; name = "Noto Sans Mono"; }; + sizes.applications = 24; + }; + + targets.grub.enable = true; # cream background, pine selection bar + targets.console.enable = true; # the VT palette tuigreet uses + }; + } + ; +} diff --git a/modules/home/cheats/niri.md b/modules/home/cheats/niri.md @@ -67,8 +67,16 @@ Mod+Shift+L / Shift+Right move column right Mod+Shift+J / Shift+Down move window down (within / out of the column) Mod+Shift+K / Shift+Up move window up Mod+Shift+1..9 move column to workspace N +Mod+[ stack window into the column on the left (under it) +Mod+] stack window into the column on the right (under it) + (pressed on a stacked window: pops it back out to its own column) +Mod+. pop the bottom window out of the column +Mod+W column as tabs (toggle) ``` +Stacking two windows: focus the right one, `Mod+[` — it slides under the left one. +Inside a column, `Mod+Shift+J/K` reorders them. + ## resize — width and height ```text @@ -76,7 +84,14 @@ Mod+Ctrl+H column width −5% Mod+Ctrl+L column width +5% Mod+Ctrl+J window height −5% Mod+Ctrl+K window height +5% ``` -Not bound (yet): cycling the ⅓/½/⅔ presets. `niri msg action switch-preset-column-width` does it from a shell. +```text +Mod+R cycle column width ⅓ → ½ → ⅔ +Mod+Shift+R cycle window height ⅓ → ½ → ⅔ +Mod+= column width ½ (do it on two columns → even side by side) +Mod+Ctrl+R reset window height (do it on each stacked window → even split) +Mod+Ctrl+F stretch column into the free space on screen +Mod+C centre column +``` ## workspaces diff --git a/modules/hosts/laptop/configuration.nix b/modules/hosts/laptop/configuration.nix @@ -26,6 +26,7 @@ desktop-options # daemon.desktop.* switches desktop-hyprland # Hyprland + Caelestia (NixOS side) desktop-niri # Niri + Noctalia: the wrapped package as the login session + theme # Stylix: Rosé Pine Dawn GRUB and console (tuigreet) ]; # The desktops. Both are installed and chosen at login; set one to false to @@ -35,7 +36,14 @@ niri.enable = true; }; - boot.loader.systemd-boot.enable = true; + # GRUB (themed Rosé Pine Dawn by modules/features/theme.nix) on the EFI + # partition at /boot; kernels are copied there since / is a separate btrfs. + boot.loader.grub = { + enable = true; + efiSupport = true; + device = "nodev"; + configurationLimit = 20; + }; boot.loader.efi.canTouchEfiVariables = true; networking.hostName = "nixos"; @@ -81,6 +89,8 @@ # Display manager: greetd with the tuigreet text greeter. Remembers the last # user and session, so a boot is: password, Enter. No theme engine, no X. + # Colours are names from the console palette, which Stylix sets to Rosé Pine + # Dawn (modules/features/theme.nix has the name → colour table). services.greetd = { enable = true; useTextGreeter = true; @@ -90,6 +100,7 @@ "--remember" "--remember-session" "--asterisks" + "--theme 'container=black;text=gray;border=blue;title=blue;greet=yellow;time=cyan;prompt=green;input=gray;action=cyan;button=red'" "--sessions ${config.services.displayManager.sessionData.desktops}/share/wayland-sessions" ]; };