NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

nix-settings.nix (2122B)


      1 # modules/hosts/laptop/nix-settings.nix — nix daemon settings and the nh helper.
      2 # Imported by both the `nixos` target and the `bootstrap` stage.
      3 { ... }:
      4 {
      5   flake.nixosModules.laptop-nix-settings =
      6   { pkgs, ... }:
      7   {
      8     # The newest *released* Nix, rather than the conservative default nixpkgs
      9     # pins (2.34.x at the time of writing). `nixVersions.git` is a prerelease
     10     # build of master and is deliberately not used: a regression there would
     11     # break the daemon that rebuilds this system.
     12     nix.package = pkgs.nixVersions.latest;
     13 
     14     nix.settings = {
     15       experimental-features = [ "nix-command" "flakes" ];
     16       # Hyprland is built from its own flake pins, which cache.nixos.org does
     17       # not have. Without the Hyprland cache every update compiles it locally.
     18       substituters = [
     19         "https://cache.nixos.org"
     20         "https://hyprland.cachix.org"
     21       ];
     22       trusted-public-keys = [
     23         "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
     24         "hyprland.cachix.org-1:a7pgxzMz7+chwVL3/pzj6jIBMioiJM7ypFP8PwtkuGc="
     25       ];
     26     };
     27 
     28     # nh, the Nix helper: `nh os switch|boot|test`, `nh clean all`, `nh search`.
     29     # Wraps nixos-rebuild with nix-output-monitor progress and an nvd diff of
     30     # what a generation changes, and asks for sudo only for the switch itself.
     31     # NH_FLAKE points at this repo, so `nh os boot` works from any directory;
     32     # the configuration is picked by hostname (`nixos`), or with -H <name>.
     33     programs.nh = {
     34       enable = true;
     35       flake = "/home/daemonsec/NixDaemon";
     36       clean = {
     37         enable = true; # weekly `nh clean all`: drops old generations and runs the GC,
     38         dates = "weekly"; # keeping the last 5 and anything newer than 14 days
     39         extraArgs = "--keep 5 --keep-since 14d";
     40       };
     41     };
     42 
     43     # The two tools nh builds on, also useful by hand:
     44     #   nvd diff /run/current-system result      what a build would change
     45     #   nom build .#…                            nix build with a live tree view
     46     environment.systemPackages = with pkgs; [
     47       nvd
     48       nix-output-monitor
     49     ];
     50   }
     51   ;
     52 }