NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

default.nix (2241B)


      1 # modules/home/default.nix — the user's home-manager configuration: every
      2 # home module in this directory, by name. Imported by the NixOS side in
      3 # modules/features/home-manager.nix (home-manager runs as a NixOS module;
      4 # `nh os switch` applies it, there is no standalone profile).
      5 { self, ... }:
      6 {
      7   flake.homeModules.daemonsec =
      8   { user, ... }:
      9   {
     10     imports = with self.homeModules; [
     11       hyprland # compositor config (Lua) and the carried shortcuts — only with daemon.desktop.hyprland
     12       caelestia # programs.caelestia, shell.json, the Rosé Pine scheme — only with daemon.desktop.hyprland
     13       session # polkit agent, cliphist, udiskie, screenshot and clipboard tools — for both desktops
     14       terminal # kitty, fonts
     15       tools # toolbox runtime closure, python env, dotfiles links
     16       shell # zsh via the dotfiles ZDOTDIR tree, tmux plugins, secretspec
     17       dotfiles # every dotfile from ~/git/daemon-sec-dotfiles, as out-of-store symlinks
     18       cheats # nix-cheat: the rebuild / nh / flake card
     19       sops # sops-nix for the user (same secrets file, age key in ~/.config/sops/age)
     20       passage # `passage`: an age-keyed password store for the logins you type
     21       neovim # nvf: Neovim with a small, Nix-built plugin set
     22       prompt # starship prompt and fastfetch card, Rosé Pine, NixOS logo
     23       fan # `fan`: status/watch without root, max/auto with a clamp watchdog
     24       htb-shell # $TARGET/$BOX in every terminal, and in the prompt
     25       git-site # git-site-sync: keep git.daemon-sec.xyz in step with GitLab (15-min timer)
     26       ssh # the ssh key (sops) and ~/.ssh/config
     27       gpg # the GPG main key (public in-repo, secret via sops) and gpg.conf
     28       git # git identity, signing with the main key, delta
     29       media # mpd + rmpc, mpv
     30       yazi # yazi with previews, Rosé Pine, plugins
     31       gtk # Yaru-purple icons, cursor, prefer-dark
     32       floorp # Floorp as the main browser: ShyFox (Rosé Pine), the Dia bookmarks
     33       zen # Zen Browser alongside Floorp, sharing the one encrypted bookmarks export
     34     ];
     35 
     36     home = {
     37       username = user;
     38       homeDirectory = "/home/${user}";
     39       stateVersion = "26.05";
     40     };
     41 
     42     programs.home-manager.enable = true;
     43     xdg.enable = true;
     44   }
     45   ;
     46 }