NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

commit db27a1eaf172a49a1acf0ea516003860c4cf2518
parent 8537077063f8dfdc03705b8cacfe9852e3d75d9e
Author: DAEMON-404 <zer0sec.xp@icloud.com>
Date:   Wed,  7 Oct 2026 22:43:33 +0100

nh (Nix helper) with weekly clean, nvd, nix-output-monitor; README workflow

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

Diffstat:
MREADME.md | 15++++++++++++++-
Mhosts/laptop/nix-settings.nix | 28++++++++++++++++++++++++++--
2 files changed, 40 insertions(+), 3 deletions(-)

diff --git a/README.md b/README.md @@ -17,7 +17,7 @@ hosts/laptop/ the machine uniwill-laptop.nix the `uniwill` hwmon the guard reads, built from Linux 6.19 sources (see below) nvidia.nix open kernel module, panel on the dGPU, device order for Hyprland ssd.nix Samsung 980 crypttab + /mnt/ssd (key restored by hand, see below) - nix-settings.nix flakes, hyprland.cachix.org + nix-settings.nix flakes, hyprland.cachix.org, nh (Nix helper) + weekly clean, nvd, nom toolbox.nix envfs (foreign shebangs), ~/.local/bin first on PATH, padx udev rule fan-reference/ the Arch-era captures (fan-ctl, fan-state, units, confs) and their README hosts/bootstrap/ stage A: today's GNOME install + fan fix + toolbox prerequisites @@ -36,6 +36,19 @@ modules/workstation.nix Claude Code, Claude desktop, Obsidian, gh, glab ( Everything below needs `sudo`, so it is left to the owner. +`nh` (Nix helper) is installed by both configurations; once Stage A is live it +is the nicer way to run the same steps. It shows a diff of what a generation +changes before asking for sudo, and the weekly `nh clean all` keeps the store +tidy (last 5 generations, 14 days). `NH_FLAKE` already points at this repo. + +```sh +nh os switch -H bootstrap # same as the Stage A command below +nh os boot # Stage B (picks nixosConfigurations.nixos by hostname) +nh os build; nvd diff /run/current-system result # dry look at what would change +nh search <package> # nixpkgs search +nh clean all --keep 5 --keep-since 14d +``` + **Stage A: fan fix now, on the GNOME install.** Small switch (fan module, driver, toolbox prerequisites, Hyprland cache). The new kernel modules only load from the booted system, hence the reboot. diff --git a/hosts/laptop/nix-settings.nix b/hosts/laptop/nix-settings.nix @@ -1,5 +1,6 @@ -# hosts/laptop/nix-settings.nix -{ ... }: +# hosts/laptop/nix-settings.nix — nix daemon settings and the nh helper. +# Imported by both the `nixos` target and the `bootstrap` stage. +{ pkgs, ... }: { nix.settings = { experimental-features = [ "nix-command" "flakes" ]; @@ -14,4 +15,27 @@ "hyprland.cachix.org-1:a7pgxzMz7+chwVL3/pzj6jIBMioiJM7ypFP8PwtkuGc=" ]; }; + + # nh, the Nix helper: `nh os switch|boot|test`, `nh clean all`, `nh search`. + # Wraps nixos-rebuild with nix-output-monitor progress and an nvd diff of + # what a generation changes, and asks for sudo only for the switch itself. + # NH_FLAKE points at this repo, so `nh os boot` works from any directory; + # the configuration is picked by hostname (`nixos`), or with -H <name>. + programs.nh = { + enable = true; + flake = "/home/daemonsec/NixDaemon"; + clean = { + enable = true; # weekly `nh clean all`: drops old generations and runs the GC, + dates = "weekly"; # keeping the last 5 and anything newer than 14 days + extraArgs = "--keep 5 --keep-since 14d"; + }; + }; + + # The two tools nh builds on, also useful by hand: + # nvd diff /run/current-system result what a build would change + # nom build .#… nix build with a live tree view + environment.systemPackages = with pkgs; [ + nvd + nix-output-monitor + ]; }