configuration.nix (8237B)
1 # modules/hosts/laptop/configuration.nix — the laptop as a NixOS module 2 # (self.nixosModules.laptop), assembled from the named modules it imports. 3 # 4 # PCSpecialist Valeon II 17 (TongFang GM7RGxM): Ryzen 9 6900HX, Radeon 680M at 5 # 06:00.0, RTX 3070 Ti Laptop at 01:00.0, 2560x1440@240 panel. Hyprland under 6 # uwsm, Caelestia Shell from home-manager (modules/home/), or Niri with 7 # Noctalia Shell (modules/features/desktop/), greetd + tuigreet to log in. 8 { self, ... }: 9 { 10 flake.nixosModules.laptop = 11 { config, pkgs, lib, user, identity, ... }: 12 { 13 imports = with self.nixosModules; [ 14 laptop-hardware 15 laptop-fan-throttle-guard # dead-GPU-fan workaround (vault gpu-fan-fix/, imported unchanged) 16 laptop-fan-extras # the one imperative step fanfix install did: the performance profile 17 laptop-uniwill # the `uniwill` hwmon the guard reads: kernel 6.19 driver built for this kernel 18 laptop-nvidia 19 laptop-ssd 20 laptop-nix-settings # nix daemon settings, caches, nh 21 laptop-toolbox # envfs, ~/.local/bin on PATH, the touchpad udev rule 22 laptop-sops # sops-nix: secrets/secrets.yaml → /run/secrets 23 laptop-fan-cli # fan-ec: root side of the `fan` command (modules/home/fan.nix), passwordless for wheel 24 workstation # Claude Code / desktop, Obsidian, git, gh, glab 25 home-manager # the user's home, built with the system (modules/home/) 26 desktop-options # daemon.desktop.* switches 27 desktop-hyprland # Hyprland + Caelestia (NixOS side) 28 desktop-niri # Niri + Noctalia: the wrapped package as the login session 29 theme # Stylix: Rosé Pine Dawn GRUB and console (tuigreet) 30 pentest # the offensive toolkit (modules/features/pentest/default.nix) 31 ]; 32 33 # The desktops. Both are installed and chosen at login; set one to false to 34 # drop it (modules/features/desktop/options.nix). 35 daemon.desktop = { 36 hyprland.enable = true; 37 niri.enable = true; 38 }; 39 40 # The offensive toolkit (modules/features/pentest/). Every switchable 41 # category is listed here, so the whole toolkit is toggled from one place: 42 # flip a `false` to `true` and `nh os switch`. 43 # 44 # 23 categories carry their own switch. The 12 not named below are on by 45 # default: core, wordlists, python, recon, ad, web, pivot, crack, shells, 46 # bloodhound, payloads, gui. The vpn/time/htb/update machinery has no 47 # switch of its own — it follows `enable` below. See pentest-cheat. 48 daemon.pentest = { 49 enable = true; 50 51 # Off by default: each adds a large closure, or needs hardware you may 52 # not have plugged in. Nothing here is needed for CPTS. 53 dfir.enable = false; # memory/disk/log forensics (volatility, sleuthkit) 54 reversing.enable = false; # radare2, rizin, gdb+gef, pwntools 55 wireless.enable = false; # wifi: aircrack, wifite, kismet, hostapd 56 radio.enable = false; # SDR/bluetooth/RFID: hackrf, ubertooth, proxmark3 57 hardware.enable = false; # flashrom, openocd, sigrok, can-utils 58 c2.enable = false; # havoc, villain 59 database.enable = false; # mysql/mssql/redis/mongo clients 60 cloud.enable = false; # aws, az, gcloud, kubectl, pacu 61 osint.enable = false; # theharvester, recon-ng, sn0int, dnstwist 62 social.enable = false; # phishing: gophish, setoolkit — scoped work only 63 mobile.enable = false; # apktool, jadx, frida, adb 64 }; 65 66 # GRUB (themed Rosé Pine Dawn by modules/features/theme.nix) on the EFI 67 # partition at /boot; kernels are copied there since / is a separate btrfs. 68 boot.loader.grub = { 69 enable = true; 70 efiSupport = true; 71 device = "nodev"; 72 configurationLimit = 20; 73 }; 74 boot.loader.efi.canTouchEfiVariables = true; 75 76 networking.hostName = "nixos"; 77 networking.networkmanager.enable = true; 78 # LocalSend (modules/home/tools.nix) discovers peers and receives on 53317. 79 networking.firewall.allowedTCPPorts = [ 53317 ]; 80 networking.firewall.allowedUDPPorts = [ 53317 ]; 81 82 time.timeZone = identity.timeZone; 83 i18n.defaultLocale = "en_US.UTF-8"; 84 services.xserver.xkb = { 85 layout = "us"; 86 options = "compose:caps,shift:both_capslock_cancel"; 87 }; 88 89 nixpkgs.config.allowUnfree = true; # nvidia, obsidian, claude-desktop 90 91 users.users.${user} = { 92 isNormalUser = true; 93 description = identity.description; 94 extraGroups = [ "networkmanager" "wheel" ]; 95 shell = pkgs.zsh; 96 }; 97 98 ##### Shell ################################################################## 99 # zsh is the login shell. Its configuration is the dotfiles' ZDOTDIR tree 100 # (modules/home/shell.nix): core.zsh runs a cached compinit and theme.zsh 101 # starts starship, so the global compinit and the default prompt stay off. 102 # /etc/zshrc still puts every profile's share/zsh/site-functions on fpath. 103 programs.zsh = { 104 enable = true; 105 enableGlobalCompInit = false; 106 promptInit = ""; 107 }; 108 109 # Binaries that are not built by Nix (uv-managed Pythons and their wheels, 110 # anything mise or npm downloads) expect /lib64/ld-linux-x86-64.so.2. 111 programs.nix-ld.enable = true; 112 113 ##### Desktop ################################################################ 114 # The compositors themselves are features (modules/features/desktop/): this 115 # section is what every desktop shares — the greeter, portals, polkit, audio. 116 117 # Display manager: greetd with the tuigreet text greeter. Remembers the last 118 # user and session, so a boot is: password, Enter. No theme engine, no X. 119 # Colours are names from the console palette, which Stylix sets to Rosé Pine 120 # Dawn (modules/features/theme.nix has the name → colour table). 121 services.greetd = { 122 enable = true; 123 useTextGreeter = true; 124 settings.default_session.command = lib.concatStringsSep " " [ 125 "${pkgs.tuigreet}/bin/tuigreet" 126 "--time" 127 "--remember" 128 "--remember-session" 129 "--asterisks" 130 "--theme 'container=black;text=gray;border=blue;title=blue;greet=yellow;time=cyan;prompt=green;input=gray;action=cyan;button=red'" 131 "--sessions ${config.services.displayManager.sessionData.desktops}/share/wayland-sessions" 132 ]; 133 }; 134 security.pam.services.greetd.enableGnomeKeyring = true; # unlock the keyring at login (Claude desktop uses it) 135 136 security.polkit.enable = true; # agent: hyprpolkitagent user service (modules/home/hyprland.nix) 137 services.udisks2.enable = true; # udiskie 138 services.power-profiles-daemon.enable = true; # the fan fix depends on it 139 services.gnome.gnome-keyring.enable = true; 140 programs.dconf.enable = true; 141 142 services.pulseaudio.enable = false; 143 security.rtkit.enable = true; 144 services.pipewire = { 145 enable = true; 146 alsa.enable = true; 147 alsa.support32Bit = true; 148 pulse.enable = true; 149 wireplumber.enable = true; 150 }; 151 152 programs.firefox.enable = true; 153 services.printing.enable = true; 154 155 programs.gnupg.agent = { 156 enable = true; 157 pinentryPackage = pkgs.pinentry-gnome3; 158 }; 159 160 ##### Fonts ################################################################## 161 # DMMono Nerd Font is not in nixpkgs; modules/home/tools.nix links it from 162 # ~/git/daemon-sec-dotfiles into ~/.local/share/fonts. 163 fonts.packages = with pkgs; [ 164 noto-fonts 165 noto-fonts-color-emoji 166 noto-fonts-cjk-sans 167 rubik # Caelestia clock font 168 material-symbols # Caelestia icons 169 ]; 170 fonts.fontconfig.defaultFonts = { 171 monospace = [ "DMMono Nerd Font" "Noto Sans Mono" ]; 172 sansSerif = [ "Noto Sans" ]; 173 serif = [ "Noto Serif" ]; 174 emoji = [ "Noto Color Emoji" ]; 175 }; 176 177 ##### Session environment #################################################### 178 # uwsm imports these through the login shell. GPU-specific ones are in nvidia.nix. 179 environment.sessionVariables = { 180 ELECTRON_OZONE_PLATFORM_HINT = "auto"; 181 GDK_BACKEND = "wayland,x11"; 182 QT_QPA_PLATFORM = "wayland;xcb"; 183 QT_WAYLAND_DISABLE_WINDOWDECORATION = "1"; 184 }; 185 186 environment.systemPackages = with pkgs; [ 187 pciutils # lspci 188 usbutils 189 ]; 190 191 system.stateVersion = "26.05"; 192 } 193 ; 194 }