NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

cheats.nix (2634B)


      1 # modules/home/cheats.nix — the cheat cards this repo ships, in the house
      2 # style (~/.local/bin/*-cheat, rendered with the toolbox's cheat-render).
      3 # Every modules/home/cheats/<name>.md becomes a `<name>-cheat` command:
      4 #
      5 #   nix-cheat               rebuilding this machine: layout, nixos-rebuild, nh, add, desktop (Hyprland or Niri), secrets, repo
      6 #   gpg-cheat               GnuPG from the key hierarchy to signing, encryption, SSH, git, offline primary, fixes
      7 #   niri-cheat              Niri + Noctalia: every bind, Noctalia ipc, niri msg, wallpaper, settings, fixes
      8 #   pentest-cheat           the offensive toolkit: htb workflow, recon, AD, pivoting, transfer, cracking, web, DFIR
      9 #
     10 #   <name>-cheat            the whole card           <name>-cheat --list   the section names
     11 #   <name>-cheat SECTION    one section              <name>-cheat --raw    the markdown itself
     12 #
     13 # Rendered with cheat-render when that is on PATH, else glow, else printed
     14 # plain. These cards live here (not in the dotfiles) because they document
     15 # this repo and this machine; xcheats only lists ~/.local/bin cards, so call
     16 # these by name.
     17 { ... }:
     18 {
     19   flake.homeModules.cheats =
     20   { pkgs, lib, ... }:
     21   let
     22     cards = [ "nix" "gpg" "niri" "pentest" ];
     23 
     24     mkCheat = name: pkgs.writeShellScriptBin "${name}-cheat" ''
     25       set -uo pipefail
     26       card=${./cheats + "/${name}.md"}
     27 
     28       usage() {
     29         echo "usage: ${name}-cheat [SECTION] [--list] [--raw] [--help]"
     30         echo "       sections: $(sections | tr '\n' ' ')"
     31       }
     32       sections() {  # first word of each '## ' heading
     33         ${pkgs.gnused}/bin/sed -n 's/^## \([a-z-]*\).*/\1/p' "$card"
     34       }
     35       section() {   # the heading whose first word matches $1, up to the next heading
     36         ${pkgs.gawk}/bin/awk -v want="$1" '
     37           /^## / { on = (tolower($2) == want) }
     38           /^# /  { next }
     39           on
     40         ' "$card"
     41       }
     42       render() {
     43         if [ ! -t 1 ]; then cat
     44         elif command -v cheat-render >/dev/null 2>&1; then cheat-render - | ''${PAGER:-less -R}
     45         else ${pkgs.glow}/bin/glow -p -
     46         fi
     47       }
     48 
     49       case "''${1:-}" in
     50         -h|--help) usage; exit 0 ;;
     51         --list) sections; exit 0 ;;
     52         --raw) cat "$card"; exit 0 ;;
     53         "") render < "$card" ;;
     54         *)
     55           key=$(echo "$1" | tr '[:upper:]' '[:lower:]')
     56           out=$(section "$key")
     57           if [ -z "$out" ]; then
     58             echo "${name}-cheat: no section '$1'" >&2; usage >&2; exit 1
     59           fi
     60           { head -1 "$card"; echo; printf '%s\n' "$out"; } | render ;;
     61       esac
     62     '';
     63   in
     64   {
     65     home.packages = map mkCheat cards;
     66   }
     67   ;
     68 }