NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

workstation.nix (1988B)


      1 # Claude Code, the Claude desktop app, Obsidian, and the git / GitHub / GitLab
      2 # command-line tools. Written by nixdaemon-bootstrap.sh; edit freely.
      3 { ... }:
      4 {
      5   flake.nixosModules.workstation =
      6   { lib, pkgs, inputs, ... }:
      7   let
      8     # Anthropic's own Linux builds, repackaged for Nix by numtide and refreshed
      9     # daily. (NixOS isn't a distro Anthropic supports directly: its desktop app
     10     # ships as a .deb for Debian/Ubuntu.)
     11     claude = inputs.llm-agents.packages.${pkgs.stdenv.hostPlatform.system};
     12   in
     13   {
     14     nix.settings.experimental-features = [ "nix-command" "flakes" ];
     15 
     16     # Unfree packages (Obsidian) are already allowed elsewhere in this config.
     17 
     18     environment.systemPackages = [
     19       claude.claude-code    # terminal: `claude`
     20       claude.claude-desktop # desktop app: "Claude" in your launcher, or `claude-desktop`
     21       pkgs.obsidian
     22       pkgs.git
     23       pkgs.gh               # GitHub CLI
     24       pkgs.glab             # GitLab CLI
     25       pkgs.qemu_kvm         # only for the desktop app's Cowork tab
     26     ];
     27 
     28     # The desktop app keeps its sign-in in the system keyring; without one it
     29     # asks you to log in on every launch.
     30     services.gnome.gnome-keyring.enable = lib.mkDefault true;
     31 
     32     # The desktop app's Cowork tab runs its tasks in a local VM, which needs KVM.
     33     # If you don't use Cowork, delete these two lines and qemu_kvm above.
     34     boot.kernelModules = [ "vhost_vsock" ];
     35     users.groups.kvm.members = [ "daemonsec" ];
     36 
     37     # Run Electron apps (Claude, Obsidian) natively on Wayland, e.g. on Hyprland.
     38     environment.sessionVariables.NIXOS_OZONE_WL = lib.mkDefault "1";
     39 
     40     # Optional: numtide's binary cache, so the Claude packages download instead
     41     # of building a couple of small helper tools locally on each update.
     42     # nix.settings.extra-substituters = [ "https://cache.numtide.com" ];
     43     # nix.settings.extra-trusted-public-keys = [
     44     #   "niks3.numtide.com-1:DTx8wZduET09hRmMtKdQDxNNthLQETkc/yaX7M4qK0g="
     45     # ];
     46   }
     47   ;
     48 }