NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

flake.nix (3070B)


      1 {
      2   description = "NixDaemon: NixOS + home-manager for the PCSpecialist Valeon II 17 (Hyprland + Caelestia, Niri + Noctalia, dead-GPU-fan workaround)";
      3 
      4   # The flake is dendritic: flake-parts evaluates every *.nix under ./modules
      5   # (import-tree) as a flake-parts module, and each file declares the outputs
      6   # it owns (flake.nixosModules.<name>, flake.homeModules.<name>,
      7   # flake.nixosConfigurations.<host>, perSystem.packages.<name>). Files and
      8   # directories whose path contains `/_` are skipped. Modules refer to each
      9   # other by name through `self`, never by path.
     10   inputs = {
     11     nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
     12 
     13     flake-parts = {
     14       url = "github:hercules-ci/flake-parts";
     15       inputs.nixpkgs-lib.follows = "nixpkgs";
     16     };
     17     import-tree.url = "github:vic/import-tree";
     18 
     19     # Wrapped, portable programs (modules/features/desktop/{niri,noctalia}.nix):
     20     # `nix run ~/NixDaemon#niri` works anywhere the flake can be fetched.
     21     wrapper-modules = {
     22       url = "github:BirdeeHub/nix-wrapper-modules";
     23       inputs.nixpkgs.follows = "nixpkgs";
     24     };
     25 
     26     home-manager = {
     27       url = "github:nix-community/home-manager";
     28       inputs.nixpkgs.follows = "nixpkgs";
     29     };
     30 
     31     # Deliberately not following nixpkgs: Hyprland pins its own, and the
     32     # hyprland.cachix.org cache (modules/hosts/laptop/nix-settings.nix) only
     33     # serves builds made against those pins.
     34     hyprland.url = "github:hyprwm/Hyprland";
     35 
     36     # Shell and CLI pin each other, so one revision of each is used everywhere.
     37     caelestia-shell = {
     38       url = "github:caelestia-dots/shell";
     39       inputs.nixpkgs.follows = "nixpkgs";
     40       inputs.caelestia-cli.follows = "caelestia-cli";
     41     };
     42     caelestia-cli = {
     43       url = "github:caelestia-dots/cli";
     44       inputs.nixpkgs.follows = "nixpkgs";
     45       inputs.caelestia-shell.follows = "caelestia-shell";
     46     };
     47 
     48     # Claude Code and the Claude desktop app (modules/features/workstation.nix).
     49     llm-agents.url = "github:numtide/llm-agents.nix";
     50 
     51     # Secrets: encrypted in secrets/ with age, decrypted at activation
     52     # (modules/hosts/laptop/sops.nix for the system, modules/home/sops.nix for the user).
     53     sops-nix = {
     54       url = "github:Mic92/sops-nix";
     55       inputs.nixpkgs.follows = "nixpkgs";
     56     };
     57 
     58     # Zen Browser, which is not in nixpkgs (modules/home/zen.nix).
     59     # `packages.default` is the general release channel; `twilight` is nightly.
     60     zen-browser = {
     61       url = "github:0xc000022070/zen-browser-flake";
     62       inputs.nixpkgs.follows = "nixpkgs";
     63       inputs.home-manager.follows = "home-manager";
     64     };
     65 
     66     # Neovim, configured in Nix (modules/home/neovim.nix).
     67     nvf = {
     68       url = "github:notashelf/nvf";
     69       inputs.nixpkgs.follows = "nixpkgs";
     70     };
     71 
     72     # Rosé Pine Dawn for GRUB and the console tuigreet runs on (modules/features/theme.nix).
     73     stylix = {
     74       url = "github:nix-community/stylix";
     75       inputs.nixpkgs.follows = "nixpkgs";
     76     };
     77   };
     78 
     79   outputs = inputs: inputs.flake-parts.lib.mkFlake { inherit inputs; } (inputs.import-tree ./modules);
     80 }