install.md (15156B)
1 <div align="center"> 2 <img src="images/headers/03-installation.png" width="800" alt="[02] INSTALLATION — ANY MACHINE"/> 3 </div> 4 5 # Installing NixDaemon 6 7 NixDaemon installs as the **generic host** (`nixosConfigurations.nixdaemon`, 8 `modules/hosts/generic/`). It works on a PC, a laptop or a virtual machine, 9 Intel/AMD or ARM, UEFI or legacy BIOS. You change **two files** and nothing 10 else: 11 12 | File | What goes in it | 13 |---|---| 14 | `modules/hosts/generic/_settings.nix` | user name, hostname, CPU architecture, boot mode, hypervisor, desktop, which toolkit categories | 15 | `modules/hosts/generic/_hardware-configuration.nix` | your disks and kernel modules, generated by `nixos-generate-config` | 16 17 > `modules/hosts/laptop/` is the author's own machine. It needs his secrets 18 > and private dotfiles and **will not build for you** — ignore it. 19 20 **Contents** 21 22 1. [Requirements](#1-requirements) 23 2. [Pick your path](#2-pick-your-path) 24 3. [Path A — fresh install (bare metal or VM)](#3-path-a--fresh-install-bare-metal-or-vm) 25 4. [Path B — you already run NixOS](#4-path-b--you-already-run-nixos) 26 5. [Path C — just the tools (any Linux, WSL)](#5-path-c--just-the-tools-any-linux-wsl) 27 6. [Hypervisor notes](#6-hypervisor-notes) 28 7. [First boot](#7-first-boot) 29 8. [Updating, rolling back, more machines](#8-updating-rolling-back-more-machines) 30 9. [When something goes wrong](#9-when-something-goes-wrong) 31 32 --- 33 34 ## 1. Requirements 35 36 | | Minimum | Comfortable | 37 |---|---|---| 38 | CPU | x86_64 or aarch64, 2 cores | 4+ cores | 39 | RAM | 4 GB (install with `--max-jobs 1`) | 8–16 GB (BloodHound wants 4 GB on its own) | 40 | Disk | 60 GB | 100 GB+ (old generations, wordlists, VMs) | 41 | Network | needed for the whole install | wired or a stable Wi-Fi | 42 43 The installed system is about **23 GB**, of which ~10 GB is downloaded 44 pre-built from cache.nixos.org. Some things are compiled on your machine: 45 the Python 3.12 AD tooling (impacket, certipy, lsassy …), the 46 ligolo-ng/chisel/fscan/pspy agents cross-built for every OS and CPU, and a 47 few editor plugins. Expect a first install to take **30–90 minutes** 48 depending on CPU and bandwidth. 49 50 **Architecture support.** Everything works on x86_64. On aarch64 (Apple 51 Silicon VMs, ARM servers) BloodHound CE is switched off automatically (its 52 pinned neo4j is x86_64-only) and the `mobile` category cannot be enabled. 53 54 --- 55 56 ## 2. Pick your path 57 58 ```text 59 Do you already run NixOS on this machine? 60 ├── yes ─────────────────────────────────────────────▶ Path B 61 └── no 62 ├── want a full NixDaemon machine (PC or VM) ────▶ Path A 63 └── want only the tools on your current Linux ───▶ Path C 64 ``` 65 66 --- 67 68 ## 3. Path A — fresh install (bare metal or VM) 69 70 ### 3.1 Get the installer 71 72 Download the **minimal ISO** from <https://nixos.org/download/#nixos-iso>: 73 `x86_64` for Intel/AMD, `aarch64` for ARM (Apple Silicon with UTM/Parallels/ 74 VMware Fusion, ARM servers). Write it to a USB stick (`dd`, Ventoy, Rufus, 75 balenaEtcher) or attach it to your VM — see [Hypervisor notes](#6-hypervisor-notes) 76 first if you are in one. 77 78 Boot it. On real hardware, **turn Secure Boot off** in the firmware setup; 79 NixOS does not sign its bootloader by default. 80 81 ### 3.2 Get online 82 83 ```sh 84 sudo -i # everything below runs as root 85 ping -c1 nixos.org # wired / VM networking: usually already up 86 nmtui # Wi-Fi: pick the network, enter the password 87 ``` 88 89 ### 3.3 Check how the machine booted 90 91 ```sh 92 [ -d /sys/firmware/efi ] && echo UEFI || echo BIOS 93 lsblk # find your disk: /dev/nvme0n1, /dev/sda, /dev/vda … 94 DISK=/dev/sda # ← set this to YOUR disk. Everything on it is erased. 95 ``` 96 97 ### 3.4 Partition, format, mount 98 99 The labels (`nixos`, `boot`) matter: the placeholder hardware file finds the 100 partitions by them. 101 102 **UEFI** (most PCs since 2012, VMware, Hyper-V Gen 2, UTM, QEMU with OVMF): 103 104 ```sh 105 parted "$DISK" -- mklabel gpt 106 parted "$DISK" -- mkpart ESP fat32 1MiB 1GiB 107 parted "$DISK" -- set 1 esp on 108 parted "$DISK" -- mkpart root ext4 1GiB 100% 109 110 # partition names: /dev/sda1 /dev/sda2, but /dev/nvme0n1p1 /dev/nvme0n1p2 111 P1=${DISK}1; P2=${DISK}2; case "$DISK" in *nvme*|*mmcblk*) P1=${DISK}p1; P2=${DISK}p2;; esac 112 113 mkfs.fat -F 32 -n boot "$P1" 114 mkfs.ext4 -L nixos "$P2" 115 mount /dev/disk/by-label/nixos /mnt 116 mkdir -p /mnt/boot 117 mount -o umask=077 /dev/disk/by-label/boot /mnt/boot 118 ``` 119 120 **BIOS** (old PCs; VirtualBox unless *Enable EFI* is ticked): 121 122 ```sh 123 parted "$DISK" -- mklabel msdos 124 parted "$DISK" -- mkpart primary ext4 1MiB 100% 125 mkfs.ext4 -L nixos "${DISK}1" 126 mount /dev/disk/by-label/nixos /mnt 127 ``` 128 129 Want swap? After install, a swap file is one line in `_hardware-configuration.nix`: 130 `swapDevices = [ { device = "/var/lib/swapfile"; size = 8192; } ];`. 131 Want full-disk encryption, btrfs or ZFS? Partition your way (the 132 [NixOS manual](https://nixos.org/manual/nixos/stable/#sec-installation-manual-partitioning) 133 has the recipes); just make sure to generate the hardware file in step 3.6. 134 135 ### 3.5 Get NixDaemon 136 137 Pick your user name now — it must match `user` in `_settings.nix` (step 3.6). 138 139 ```sh 140 U=operator # ← your user name 141 nix-shell -p git # git is not on the ISO 142 git clone https://gitlab.com/DAEMON-404/NixDaemon.git /mnt/home/$U/NixDaemon 143 cd /mnt/home/$U/NixDaemon 144 ``` 145 146 ### 3.6 Configure 147 148 ```sh 149 nano modules/hosts/generic/_settings.nix 150 ``` 151 152 Set at least `user` (same as `$U`), `system`, `boot` (and `biosDevice` for 153 BIOS), `vm`, `desktop` and `timeZone`. Every option is explained in the file. 154 155 Then generate the hardware file **into the repo**: 156 157 ```sh 158 nixos-generate-config --root /mnt --show-hardware-configuration \ 159 > modules/hosts/generic/_hardware-configuration.nix 160 ``` 161 162 (Skipping this works only if you partitioned exactly as in 3.4 — the 163 placeholder assumes those labels. Generating it is always the safer choice.) 164 165 > **Flakes only see files git knows about.** Editing the two files above is 166 > fine (they are already tracked). If you ever *add* a file, `git add` it 167 > before building, or Nix will say it does not exist. 168 169 ### 3.7 Install 170 171 ```sh 172 nixos-install --flake .#nixdaemon 173 # low RAM (≤ 4 GB)? nixos-install --flake .#nixdaemon --max-jobs 1 --cores 2 174 ``` 175 176 It asks for a **root password** at the end. Then: 177 178 ```sh 179 reboot # remove the ISO / USB when the machine powers off 180 ``` 181 182 Continue with [First boot](#7-first-boot). 183 184 --- 185 186 ## 4. Path B — you already run NixOS 187 188 ```sh 189 git clone https://gitlab.com/DAEMON-404/NixDaemon.git ~/NixDaemon 190 cd ~/NixDaemon 191 cp /etc/nixos/hardware-configuration.nix modules/hosts/generic/_hardware-configuration.nix 192 nano modules/hosts/generic/_settings.nix 193 ``` 194 195 In `_settings.nix`, make these **match your current system** or it may not 196 boot: 197 198 - `user` — your existing user name (your files are kept; the account is 199 re-declared by NixDaemon, so groups and shell follow `_settings.nix`). 200 - `boot` — `"efi"` if `/sys/firmware/efi` exists (this switches you to 201 systemd-boot), else `"bios"` with `biosDevice` set to the disk GRUB is on now. 202 - `hostName`, `timeZone`, `keyboard`. 203 204 Build first, switch on the next boot (safest): 205 206 ```sh 207 sudo nixos-rebuild boot --flake .#nixdaemon 208 sudo reboot 209 ``` 210 211 Your old configuration stays in the boot menu as an earlier generation, so 212 you can always go back. `/etc/nixos` is no longer used. 213 214 --- 215 216 ## 5. Path C — just the tools (any Linux, WSL) 217 218 No NixOS needed: install Nix, then open a shell with the whole toolkit on 219 `PATH`. Nothing is installed system-wide, and leaving the shell leaves no 220 trace. 221 222 ```sh 223 # 1. Nix (Linux, WSL2). Determinate's installer enables flakes for you: 224 curl -fsSL https://install.determinate.systems/nix | sh -s -- install 225 226 # 2. the toolkit (x86_64-linux): 227 nix develop gitlab:DAEMON-404/NixDaemon#pentest # everything 228 nix develop gitlab:DAEMON-404/NixDaemon#pentest-recon # one category: -ad -web -crack -pivot … 229 ``` 230 231 Limits: the dev shell has the **tools**, not the machine. `htbvpn`, `htbtarget` 232 (`/etc/hosts`), the `~/pentesting` arsenal and `sudo nmap` need the NixOS 233 install. The dev shells are x86_64-linux only (several tools exist only 234 for x86_64); on ARM, install the generic host instead (Path A). macOS is not 235 supported — use a VM ([UTM](https://mac.getutm.app/) + Path A). 236 237 **WSL**: Path C works in WSL2. A full NixDaemon *inside* WSL is not supported 238 (no systemd units for the VPN, no desktop); use Hyper-V or VMware instead. 239 240 --- 241 242 ## 6. Hypervisor notes 243 244 Set `vm` in `_settings.nix` to install the matching guest tools (shared 245 clipboard, automatic resolution, time sync). Give the VM **8 GB RAM, 4 CPUs, 246 100 GB disk** if you can. 247 248 > **The X11 desktops are off until you pick one.** `desktop` defaults to 249 > `"niri"`. For a VM without working 3D set it to `"xfce"` (a full desktop, 250 > Rosé Pine) or `"i3"` (a lightweight tiling window manager, Rosé Pine — the 251 > whole VM idles around 0.9 GB). Both are newer than the Niri desktop and less 252 > tested: expect the odd rough edge. 253 254 | Hypervisor | `vm =` | Firmware → `boot =` | Graphics → `desktop =` | 255 |---|---|---|---| 256 | **VMware** Workstation / Fusion (x86) | `"vmware"` | set *UEFI* in VM options → `"efi"` | enable *Accelerate 3D graphics* → `"niri"` | 257 | **VMware Fusion** on Apple Silicon | `"vmware"` | UEFI → `"efi"`, `system = "aarch64-linux"` | 3D on → `"niri"`, else `"xfce"` | 258 | **VirtualBox** | `"virtualbox"` | default is BIOS → `"bios"` (`biosDevice = "/dev/sda"`); or tick *Enable EFI* → `"efi"` | VirtualBox's 3D is unreliable → `"xfce"` or `"i3"` | 259 | **QEMU / KVM / virt-manager** | `"qemu"` | OVMF (UEFI) → `"efi"`, SeaBIOS → `"bios"` | *Virtio* video with *3D acceleration* + Spice *OpenGL* → `"niri"`; otherwise `"xfce"` | 260 | **Proxmox** | `"qemu"` | OVMF → `"efi"` | no host GPU → `"xfce"` / `"i3"`, or `"none"` + SSH | 261 | **UTM** (Apple Silicon) | `"qemu"` | UEFI → `"efi"`, `system = "aarch64-linux"` | *virtio-gpu-gl-pci* → `"niri"`, else `"xfce"` | 262 | **Parallels** (Apple Silicon) | `"none"` | UEFI → `"efi"`, `system = "aarch64-linux"` | `"xfce"` | 263 | **Hyper-V** | `"hyperv"` | Generation 2, **Secure Boot off** → `"efi"` | no 3D → `"xfce"` / `"i3"` | 264 | **Cloud / headless server** | `"qemu"` or `"none"` | provider's default | `"none"`, `ssh = true` + your key | 265 266 **Niri needs working 3D.** If you log in and get a black screen or are 267 thrown back to the greeter, the VM has no usable OpenGL: switch to 268 `desktop = "xfce"` or `"i3"` (see [§9](#9-when-something-goes-wrong)). 269 270 **Shared folders**: set `sharedFolders = true;` and enable sharing in the 271 hypervisor too. VMware mounts them at `/mnt/hgfs/<name>` (on first access); 272 VirtualBox puts them at `/media/sf_<name>` and adds your user to `vboxsf`. 273 Under XFCE and i3, VMware's clipboard and auto-resize come from 274 open-vm-tools; on Niri (Wayland) the clipboard is not shared. 275 276 **Disk device names differ**: VirtIO disks are `/dev/vda`, SATA/SCSI are 277 `/dev/sda`, NVMe is `/dev/nvme0n1`. Check with `lsblk` before partitioning, 278 and use the right one for `biosDevice`. 279 280 --- 281 282 ## 7. First boot 283 284 1. Log in as your `user` with the `initialPassword` from `_settings.nix` 285 (default `nixdaemon`), then **change it at once**: 286 287 ```sh 288 passwd 289 ``` 290 291 2. Fix ownership of the checkout (it was cloned as root in Path A): 292 293 ```sh 294 sudo chown -R "$USER":users ~/NixDaemon 295 ``` 296 297 3. Find your way around: 298 299 ```sh 300 pentest-cheat # the toolkit card: htb workflow, recon, AD, pivot, crack, web … 301 niri-cheat # the desktop's keys (Super+Return terminal, Super+Space launcher) 302 htbpaths # the ~/pentesting arsenal and its $variables 303 ``` 304 305 4. HTB / lab VPN: put your `.ovpn` file(s) in `~/.config/htb/vpn/`, then 306 `htbup` (or `htbvpn up <name>`). `htbip` prints your tunnel address. 307 308 5. Start a box: 309 310 ```sh 311 htbbox new Sauna 10.10.10.175 windows easy # directory, box.json, $TARGET, /etc/hosts 312 htbscan full # nmap → recon/, ports into box.json 313 revshell bash # a reverse shell for your tunnel IP 314 ``` 315 316 --- 317 318 ## 8. Updating, rolling back, more machines 319 320 ```sh 321 cd ~/NixDaemon 322 nh os switch -H nixdaemon # rebuild after editing _settings.nix (shows a diff, asks for sudo) 323 nix flake update && nh os switch -H nixdaemon # update every input (nixpkgs etc.) 324 git pull && nh os switch -H nixdaemon # take upstream NixDaemon changes 325 ``` 326 327 If you kept `hostName = "nixdaemon"`, plain `nh os switch` works without `-H`. 328 The plain-Nix equivalent of all of these is 329 `sudo nixos-rebuild switch --flake ~/NixDaemon#nixdaemon`. 330 331 **Rolling back**: every rebuild is a new generation. Pick an older one in the 332 boot menu, or `sudo nixos-rebuild switch --rollback`. 333 334 **More than one machine** from one checkout: in your fork, add a file such as 335 `modules/hosts/mine.nix`: 336 337 ```nix 338 { self, ... }: 339 { 340 flake.nixosConfigurations.vm = self.lib.mkHost ( 341 import ./generic/_settings.nix // { 342 hostName = "vm"; 343 vm = "qemu"; 344 hardware = ./_vm-hardware.nix; # that machine's nixos-generate-config output 345 } 346 ); 347 } 348 ``` 349 350 then `git add` both files and install it with `--flake .#vm`. 351 352 --- 353 354 ## 9. When something goes wrong 355 356 | Symptom | Fix | 357 |---|---| 358 | `error: … does not provide attribute … nixdaemon` or "path does not exist" | A new file is not tracked: `git add -A`, build again. | 359 | `Failed assertions: _settings.nix: …` | A value in `_settings.nix` is misspelled; the message names it. | 360 | Black screen / back at the greeter after choosing Niri | No 3D in the VM. Set `desktop = "xfce"` (or `"i3"`), then from a text console (Ctrl+Alt+F2) run `sudo nixos-rebuild switch --flake ~/NixDaemon#nixdaemon`. | 361 | Machine does not boot after install | Wrong `boot` mode, or BIOS `biosDevice` pointing at the wrong disk. Boot the ISO, mount (3.4), fix `_settings.nix`, run `nixos-install` again. | 362 | `No space left on device` during install | The disk is too small (60 GB minimum), or the target is not mounted at `/mnt`. | 363 | Install killed / machine freezes while building | Out of RAM: `--max-jobs 1 --cores 2`, or give the VM more memory. | 364 | `hash mismatch` fetching a payload | Upstream replaced a release file. Run `pentest-update` (re-pins), or turn that category off for now. | 365 | Clock-skew errors from Kerberos tools | `htbtime` syncs your clock to the target's DC (and restores it after). | 366 | You want the previous system back | Choose an older generation in the boot menu, or `sudo nixos-rebuild switch --rollback`. | 367 368 **Ask Claude.** NixDaemon installs a Claude Code skill at 369 `~/.claude/skills/nixdaemon` (source: [skills/nixdaemon/SKILL.md](../skills/nixdaemon/SKILL.md)): 370 run `claude` and describe the problem — it knows which file to edit, the 371 traps above and where the logs are. It shows changes before making them and 372 leaves `sudo` to you. 373 374 Still stuck? `nix flake check` runs every category's smoke test and the VM 375 tests, and usually names the broken piece.