NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

configuration.nix (8237B)


      1 # modules/hosts/laptop/configuration.nix — the laptop as a NixOS module
      2 # (self.nixosModules.laptop), assembled from the named modules it imports.
      3 #
      4 # PCSpecialist Valeon II 17 (TongFang GM7RGxM): Ryzen 9 6900HX, Radeon 680M at
      5 # 06:00.0, RTX 3070 Ti Laptop at 01:00.0, 2560x1440@240 panel. Hyprland under
      6 # uwsm, Caelestia Shell from home-manager (modules/home/), or Niri with
      7 # Noctalia Shell (modules/features/desktop/), greetd + tuigreet to log in.
      8 { self, ... }:
      9 {
     10   flake.nixosModules.laptop =
     11   { config, pkgs, lib, user, identity, ... }:
     12   {
     13     imports = with self.nixosModules; [
     14       laptop-hardware
     15       laptop-fan-throttle-guard # dead-GPU-fan workaround (vault gpu-fan-fix/, imported unchanged)
     16       laptop-fan-extras # the one imperative step fanfix install did: the performance profile
     17       laptop-uniwill # the `uniwill` hwmon the guard reads: kernel 6.19 driver built for this kernel
     18       laptop-nvidia
     19       laptop-ssd
     20       laptop-nix-settings # nix daemon settings, caches, nh
     21       laptop-toolbox # envfs, ~/.local/bin on PATH, the touchpad udev rule
     22       laptop-sops # sops-nix: secrets/secrets.yaml → /run/secrets
     23       laptop-fan-cli # fan-ec: root side of the `fan` command (modules/home/fan.nix), passwordless for wheel
     24       workstation # Claude Code / desktop, Obsidian, git, gh, glab
     25       home-manager # the user's home, built with the system (modules/home/)
     26       desktop-options # daemon.desktop.* switches
     27       desktop-hyprland # Hyprland + Caelestia (NixOS side)
     28       desktop-niri # Niri + Noctalia: the wrapped package as the login session
     29       theme # Stylix: Rosé Pine Dawn GRUB and console (tuigreet)
     30       pentest # the offensive toolkit (modules/features/pentest/default.nix)
     31     ];
     32 
     33     # The desktops. Both are installed and chosen at login; set one to false to
     34     # drop it (modules/features/desktop/options.nix).
     35     daemon.desktop = {
     36       hyprland.enable = true;
     37       niri.enable = true;
     38     };
     39 
     40     # The offensive toolkit (modules/features/pentest/). Every switchable
     41     # category is listed here, so the whole toolkit is toggled from one place:
     42     # flip a `false` to `true` and `nh os switch`.
     43     #
     44     # 23 categories carry their own switch. The 12 not named below are on by
     45     # default: core, wordlists, python, recon, ad, web, pivot, crack, shells,
     46     # bloodhound, payloads, gui. The vpn/time/htb/update machinery has no
     47     # switch of its own — it follows `enable` below. See pentest-cheat.
     48     daemon.pentest = {
     49       enable = true;
     50 
     51       # Off by default: each adds a large closure, or needs hardware you may
     52       # not have plugged in. Nothing here is needed for CPTS.
     53       dfir.enable = false; # memory/disk/log forensics (volatility, sleuthkit)
     54       reversing.enable = false; # radare2, rizin, gdb+gef, pwntools
     55       wireless.enable = false; # wifi: aircrack, wifite, kismet, hostapd
     56       radio.enable = false; # SDR/bluetooth/RFID: hackrf, ubertooth, proxmark3
     57       hardware.enable = false; # flashrom, openocd, sigrok, can-utils
     58       c2.enable = false; # havoc, villain
     59       database.enable = false; # mysql/mssql/redis/mongo clients
     60       cloud.enable = false; # aws, az, gcloud, kubectl, pacu
     61       osint.enable = false; # theharvester, recon-ng, sn0int, dnstwist
     62       social.enable = false; # phishing: gophish, setoolkit — scoped work only
     63       mobile.enable = false; # apktool, jadx, frida, adb
     64     };
     65 
     66     # GRUB (themed Rosé Pine Dawn by modules/features/theme.nix) on the EFI
     67     # partition at /boot; kernels are copied there since / is a separate btrfs.
     68     boot.loader.grub = {
     69       enable = true;
     70       efiSupport = true;
     71       device = "nodev";
     72       configurationLimit = 20;
     73     };
     74     boot.loader.efi.canTouchEfiVariables = true;
     75 
     76     networking.hostName = "nixos";
     77     networking.networkmanager.enable = true;
     78     # LocalSend (modules/home/tools.nix) discovers peers and receives on 53317.
     79     networking.firewall.allowedTCPPorts = [ 53317 ];
     80     networking.firewall.allowedUDPPorts = [ 53317 ];
     81 
     82     time.timeZone = identity.timeZone;
     83     i18n.defaultLocale = "en_US.UTF-8";
     84     services.xserver.xkb = {
     85       layout = "us";
     86       options = "compose:caps,shift:both_capslock_cancel";
     87     };
     88 
     89     nixpkgs.config.allowUnfree = true; # nvidia, obsidian, claude-desktop
     90 
     91     users.users.${user} = {
     92       isNormalUser = true;
     93       description = identity.description;
     94       extraGroups = [ "networkmanager" "wheel" ];
     95       shell = pkgs.zsh;
     96     };
     97 
     98     ##### Shell ##################################################################
     99     # zsh is the login shell. Its configuration is the dotfiles' ZDOTDIR tree
    100     # (modules/home/shell.nix): core.zsh runs a cached compinit and theme.zsh
    101     # starts starship, so the global compinit and the default prompt stay off.
    102     # /etc/zshrc still puts every profile's share/zsh/site-functions on fpath.
    103     programs.zsh = {
    104       enable = true;
    105       enableGlobalCompInit = false;
    106       promptInit = "";
    107     };
    108 
    109     # Binaries that are not built by Nix (uv-managed Pythons and their wheels,
    110     # anything mise or npm downloads) expect /lib64/ld-linux-x86-64.so.2.
    111     programs.nix-ld.enable = true;
    112 
    113     ##### Desktop ################################################################
    114     # The compositors themselves are features (modules/features/desktop/): this
    115     # section is what every desktop shares — the greeter, portals, polkit, audio.
    116 
    117     # Display manager: greetd with the tuigreet text greeter. Remembers the last
    118     # user and session, so a boot is: password, Enter. No theme engine, no X.
    119     # Colours are names from the console palette, which Stylix sets to Rosé Pine
    120     # Dawn (modules/features/theme.nix has the name → colour table).
    121     services.greetd = {
    122       enable = true;
    123       useTextGreeter = true;
    124       settings.default_session.command = lib.concatStringsSep " " [
    125         "${pkgs.tuigreet}/bin/tuigreet"
    126         "--time"
    127         "--remember"
    128         "--remember-session"
    129         "--asterisks"
    130         "--theme 'container=black;text=gray;border=blue;title=blue;greet=yellow;time=cyan;prompt=green;input=gray;action=cyan;button=red'"
    131         "--sessions ${config.services.displayManager.sessionData.desktops}/share/wayland-sessions"
    132       ];
    133     };
    134     security.pam.services.greetd.enableGnomeKeyring = true; # unlock the keyring at login (Claude desktop uses it)
    135 
    136     security.polkit.enable = true; # agent: hyprpolkitagent user service (modules/home/hyprland.nix)
    137     services.udisks2.enable = true; # udiskie
    138     services.power-profiles-daemon.enable = true; # the fan fix depends on it
    139     services.gnome.gnome-keyring.enable = true;
    140     programs.dconf.enable = true;
    141 
    142     services.pulseaudio.enable = false;
    143     security.rtkit.enable = true;
    144     services.pipewire = {
    145       enable = true;
    146       alsa.enable = true;
    147       alsa.support32Bit = true;
    148       pulse.enable = true;
    149       wireplumber.enable = true;
    150     };
    151 
    152     programs.firefox.enable = true;
    153     services.printing.enable = true;
    154 
    155     programs.gnupg.agent = {
    156       enable = true;
    157       pinentryPackage = pkgs.pinentry-gnome3;
    158     };
    159 
    160     ##### Fonts ##################################################################
    161     # DMMono Nerd Font is not in nixpkgs; modules/home/tools.nix links it from
    162     # ~/git/daemon-sec-dotfiles into ~/.local/share/fonts.
    163     fonts.packages = with pkgs; [
    164       noto-fonts
    165       noto-fonts-color-emoji
    166       noto-fonts-cjk-sans
    167       rubik # Caelestia clock font
    168       material-symbols # Caelestia icons
    169     ];
    170     fonts.fontconfig.defaultFonts = {
    171       monospace = [ "DMMono Nerd Font" "Noto Sans Mono" ];
    172       sansSerif = [ "Noto Sans" ];
    173       serif = [ "Noto Serif" ];
    174       emoji = [ "Noto Color Emoji" ];
    175     };
    176 
    177     ##### Session environment ####################################################
    178     # uwsm imports these through the login shell. GPU-specific ones are in nvidia.nix.
    179     environment.sessionVariables = {
    180       ELECTRON_OZONE_PLATFORM_HINT = "auto";
    181       GDK_BACKEND = "wayland,x11";
    182       QT_QPA_PLATFORM = "wayland;xcb";
    183       QT_WAYLAND_DISABLE_WINDOWDECORATION = "1";
    184     };
    185 
    186     environment.systemPackages = with pkgs; [
    187       pciutils # lspci
    188       usbutils
    189     ];
    190 
    191     system.stateVersion = "26.05";
    192   }
    193   ;
    194 }