NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

nixpkgs.nix (914B)


      1 # modules/features/pentest/nixpkgs.nix — one package set for the system and for
      2 # the flake's own outputs.
      3 #
      4 # The checks in _sets.nix run against perSystem's `pkgs`, which by default is
      5 # plain nixpkgs: no overlays, no allowUnfree. The system, meanwhile, has both.
      6 # A check that passes against a different package set from the one the system
      7 # builds is not a check, so this module points them at the same thing:
      8 #
      9 #   _overlay.nix     the fixes (see that file for why each exists)
     10 #   allowUnfree      burpsuite, and the host already allows it
     11 { inputs, ... }:
     12 let
     13   overlay = import ./_overlay.nix;
     14 in
     15 {
     16   perSystem =
     17     { system, ... }:
     18     {
     19       _module.args.pkgs = import inputs.nixpkgs {
     20         inherit system;
     21         overlays = [ overlay ];
     22         config.allowUnfree = true;
     23       };
     24     };
     25 
     26   flake.nixosModules.pentest-nixpkgs =
     27     { ... }:
     28     {
     29       nixpkgs.overlays = [ overlay ];
     30     };
     31 }