NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

tools.nix (3889B)


      1 # modules/home/tools.nix — runtime closure for the hand-written toolbox in
      2 # ~/.local/bin, plus the general command-line tools.
      3 #
      4 # ~/.local/bin itself is not managed here on purpose: it is a flat git repo
      5 # (vault README: "git init there afterwards so editing a file edits the live
      6 # command"). NixOS puts it first on PATH (modules/hosts/laptop/toolbox.nix).
      7 { ... }:
      8 {
      9   flake.homeModules.tools =
     10   { config, pkgs, lib, ... }:
     11   let
     12     # ns [query]: fuzzy search of nixpkgs (+ NixOS and home-manager options) in
     13     # the terminal, with the package description as the preview. nix-search-tv
     14     # indexes search.nixos.org data locally on first run and refreshes it itself.
     15     #   Enter   print the attribute name (e.g. to paste into tools.nix)
     16     #   ctrl-o  open the homepage      ctrl-s  open the nixpkgs source
     17     #   ctrl-y  copy the attribute name
     18     ns = pkgs.writeShellScriptBin "ns" ''
     19       nst=${pkgs.nix-search-tv}/bin/nix-search-tv
     20       exec $nst print | ${pkgs.fzf}/bin/fzf \
     21         --query="$*" --scheme=history --prompt='nix › ' \
     22         --preview="$nst preview {}" --preview-window='right,60%,border-left,wrap' \
     23         --bind="ctrl-o:execute-silent(${pkgs.xdg-utils}/bin/xdg-open \$($nst homepage {}))" \
     24         --bind="ctrl-s:execute-silent(${pkgs.xdg-utils}/bin/xdg-open \$($nst source {}))" \
     25         --bind="ctrl-y:execute-silent(printf %s {} | ${pkgs.wl-clipboard}/bin/wl-copy)" \
     26         --header='enter: print · ctrl-y: copy · ctrl-o: homepage · ctrl-s: source'
     27     '';
     28 
     29     pythonEnv = pkgs.python3.withPackages (ps: with ps; [
     30       cryptography
     31       argon2-cffi
     32       rich
     33       questionary
     34       pikepdf
     35       mutagen
     36       pillow
     37       numpy
     38       pyqt6
     39       youtube-transcript-api
     40     ]);
     41   in
     42   {
     43     home.packages = with pkgs; [
     44       pythonEnv
     45       ns
     46       nix-search-tv # `ns`, and `nix-search-tv print|preview` by hand
     47       perl
     48       git
     49       jujutsu
     50       # `vaultx` syncs NetrunnerVault to GitLab with file contents
     51       # encrypted. git-crypt does that through git's clean/smudge filters,
     52       # which is only safe because the vault is plain git now -- jj does not
     53       # run those filters and would commit plaintext (Vault-Encryption.md).
     54       # git-remote-gcrypt stays for the older whole-repo scheme the vault
     55       # notes still describe; it cannot carry this vault to gitlab.com
     56       # because it packs each push into one blob and the cap is 100 MiB.
     57       # glab is how vaultx creates and purges the project.
     58       git-crypt
     59       git-remote-gcrypt
     60       glab
     61       gnutar
     62       zstd
     63       pigz
     64       xz
     65       rsync
     66       rclone
     67       aria2
     68       p7zip
     69       libarchive
     70       gnupg
     71       openssl
     72       pinentry-gnome3
     73       ffmpeg
     74       yt-dlp
     75       atomicparsley
     76       gallery-dl
     77       imagemagick
     78       img2pdf
     79       resvg
     80       zathura
     81       calibre
     82       poppler-utils
     83       starship
     84       bat
     85       eza
     86       fd
     87       ripgrep
     88       fzf
     89       zoxide
     90       atuin
     91       jq
     92       curl
     93       wget
     94       gh
     95       fastfetch
     96       wl-clipboard
     97       libnotify
     98 
     99       # General tools (2026-10-08): what the dotfiles' zsh modules look for
    100       # (modern.zsh, core.zsh) and what the stock Omarchy keys expect.
    101       uv # PEP-723 scripts in ~/.local/bin (dcx, dorkforge); managed Pythons work via nix-ld
    102       nodejs
    103       btop
    104       lazygit
    105       lazydocker
    106       tealdeer # `tldr`
    107       dust
    108       duf
    109       procs
    110       difftastic
    111       hyperfine
    112       glow
    113       onefetch
    114       tokei
    115       xh
    116       ncdu
    117       parallel
    118       unzip
    119       zip
    120       tree
    121       file
    122       cbonsai
    123       cmatrix
    124       localsend # phone ↔ laptop file drops on the LAN; port 53317 is open in modules/hosts/laptop/configuration.nix
    125       vesktop # Discord client; its config is linked from the dotfiles (dotfiles.nix)
    126     ];
    127 
    128     programs.codex.enable = true;
    129 
    130     # The browser has a module of its own: modules/home/floorp.nix.
    131   }
    132   ;
    133 }