diff --git a/.editorconfig b/.editorconfig new file mode 100644 index 0000000..a2cb299 --- /dev/null +++ b/.editorconfig @@ -0,0 +1,52 @@ +# EditorConfig is awesome: https://EditorConfig.org + +# top-most EditorConfig file +root = true + +# Global settings +[*] +end_of_line = lf +insert_final_newline = true +trim_trailing_whitespace = true +charset = utf-8 + +# JavaScript, TypeScript, Vue, and stylesheet files +[*.{js,jsx,mjs,cjs,ts,tsx,mts,cts,vue,css,scss,sass,less,styl}] +indent_style = tab +indent_size = 4 +max_line_length = 100 + +# JSON, YAML, and config files +[*.{json,yaml,yml,toml,ini,editorconfig}] +indent_style = tab +indent_size = 4 + +# Markdown files +[*.md] +max_line_length = off +trim_trailing_whitespace = false +indent_style = space +indent_size = 2 + +# Docker and shell scripts +[{Dockerfile,docker-compose*.yml,*.sh,*.bash}] +indent_style = tab +indent_size = 4 +max_line_length = off + +# HTML and template files +[*.{html,htm,ejs,hbs,liquid}] +indent_style = tab +indent_size = 4 +max_line_length = off + +# Makefiles (must use tabs) +[Makefile] +indent_style = tab +indent_size = 4 + +# Nix files (common addition for your stack) +[*.nix] +indent_style = tab +indent_size = 2 +max_line_length = 100 diff --git a/.gitattributes b/.gitattributes new file mode 100644 index 0000000..c512dff --- /dev/null +++ b/.gitattributes @@ -0,0 +1,63 @@ +# Normalize line endings to LF everywhere +* text=auto eol=lf + +# ---------------------------- +# Binary files (never modified) +# ---------------------------- +*.png binary +*.jpg binary +*.jpeg binary +*.gif binary +*.webp binary +*.ico binary +*.pdf binary + +*.woff binary +*.woff2 binary +*.ttf binary +*.otf binary + +*.zip binary +*.tar binary +*.gz binary +*.7z binary +*.rar binary + +# ---------------------------- +# Language-specific overrides +# ---------------------------- + +# Nix (important for flakes and reproducibility diffs) +*.nix text eol=lf + +# Shell scripts +*.sh text eol=lf +*.bash text eol=lf +Dockerfile text eol=lf +docker-compose*.yml text eol=lf + +# Web / frontend +*.js text eol=lf +*.jsx text eol=lf +*.ts text eol=lf +*.tsx text eol=lf +*.vue text eol=lf +*.css text eol=lf +*.scss text eol=lf +*.html text eol=lf + +# Data/config formats +*.json text eol=lf +*.yaml text eol=lf +*.yml text eol=lf +*.toml text eol=lf +*.ini text eol=lf +*.editorconfig text eol=lf + +# Markdown +*.md text eol=lf +*.mdx text eol=lf + +# Git files +.gitattributes text eol=lf +.gitignore text eol=lf diff --git a/.gitignore b/.gitignore index 1be5a96..d6515b7 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,5 @@ .sops.yaml .claude/ old/ +result/ +result diff --git a/INSTALL-laptop.md b/INSTALL-laptop.md new file mode 100644 index 0000000..c6dba84 --- /dev/null +++ b/INSTALL-laptop.md @@ -0,0 +1,223 @@ +# ThinkPad NixOS Installation Guide + +This guide provides step-by-step instructions for installing the NixOS configuration on your ThinkPad laptop. + +## Prerequisites + +- **ThinkPad laptop** (tested models: T480, T490, X1 Carbon) +- **USB flash drive** (8GB+ recommended) +- **Backup your data** - this will erase everything on the target device +- **NixOS ISO** - Download from [nixos.org](https://nixos.org/download.html) +- **Internet connection** (wired recommended for initial setup) + +## Preparation + +### 1. Create NixOS Installation Media + +```bash +# On another Linux machine or macOS: +sudo dd if=nixos-minimal-*.iso of=/dev/sdX bs=4M status=progress oflag=sync +# Replace /dev/sdX with your USB device (e.g., /dev/sdb) +# WARNING: This will erase the target device completely +``` + +### 2. Boot from USB + +1. Insert USB drive into ThinkPad +2. Power on and press **F12** to enter boot menu +3. Select the USB drive +4. At GRUB menu, select "NixOS" + +## Installation Steps + +### 3. Prepare Disks + +```bash +# Identify your disk (likely /dev/nvme0n1 for NVMe SSDs) +lsblk + +# Partition the disk (adjust for your needs) +sudo gdisk /dev/nvme0n1 +# Use: o (create new GPT), n (new partition), accept defaults for EFI (512M), then Linux filesystem (rest) +# Set type for EFI to EF00, Linux filesystem to 8300 +# Write changes with w +``` + +### 4. Format Partitions + +```bash +# Format EFI partition +sudo mkfs.fat -F32 /dev/nvme0n1p1 + +# Format root partition +sudo mkfs.ext4 /dev/nvme0n1p2 + +# Mount partitions +sudo mount /dev/nvme0n1p2 /mnt +sudo mkdir -p /mnt/boot/efi +sudo mount /dev/nvme0n1p1 /mnt/boot/efi +``` + +### 5. Generate NixOS Configuration + +```bash +# Generate initial configuration +sudo nixos-generate-config --root /mnt + +# This creates /mnt/etc/nixos/configuration.nix and hardware-configuration.nix +``` + +### 6. Clone Your Nixy Configuration + +```bash +# Clone your nixy repository +sudo nix-shell -p git +git clone https://gitea.doomlabs.de/KptltD00M/nixy.git /mnt/etc/nixos/nixy +cd /mnt/etc/nixos/nixy + +# Copy hardware configuration +sudo cp /mnt/etc/nixos/hardware-configuration.nix hosts/laptop/hardware-configuration.nix +``` + +### 7. Install NixOS + +```bash +# Switch to your laptop configuration +sudo nixos-install --flake /mnt/etc/nixos/nixy#laptop + +# When prompted, set a root password +``` + +### 8. Post-Installation + +```bash +# After reboot, log in as root +# Clone your configuration to your user +git clone https://gitea.doomlabs.de/KptltD00M/nixy.git ~/nixy +cd ~/nixy + +# Switch to your user configuration +nix run nixpkgs#home-manager -- switch --flake .#andi@laptop + +# Reboot +reboot +``` + +## ThinkPad-Specific Configuration + +### 1. Trackpad Configuration + +The configuration includes touchpad settings optimized for ThinkPad hardware. If you need to adjust: + +```nix +# Edit hosts/laptop/home.nix +programs.hyprland = { + touchpad = { + naturalScroll = true; + tap-to-click = true; + disableWhileTyping = false; + }; +}; +``` + +### 2. Keyboard Backlight + +```bash +# Enable keyboard backlight control +sudo nix-env -iA nixos.hid-tools +sudo systemctl enable --now thinkpad-keyboard-backlight.service +``` + +### 3. Power Management + +```bash +# Install TLP for better power management +sudo nix-env -iA nixos.tlp +sudo systemctl enable --now tlp +``` + +## Troubleshooting + +### Common Issues + +**1. WiFi not working:** +```bash +# Install firmware for your WiFi card +sudo nix-env -iA nixos.firmware +``` + +**2. Suspend/resume issues:** +```bash +# Edit hardware-configuration.nix +boot.kernelPackages = pkgs.linuxPackages_latest; +``` + +**3. Screen tearing:** +```bash +# Enable TearFree in hosts/laptop/configuration.nix +services.xserver.videoDrivers = [ "modesetting" ]; +``` + +### Debugging Commands + +```bash +# Check hardware detection +sudo dmesg | grep -i thinkpad + +# Check battery status +upower -i /org/freedesktop/UPower/devices/battery_BAT0 + +# Check display configuration +hyprctl monitors +``` + +## Maintenance + +### Updating Your System + +```bash +# Update flake inputs +nix flake update + +# Rebuild system +sudo nixos-rebuild switch --flake ~/nixy#laptop + +# Rebuild home configuration +nix run nixpkgs#home-manager -- switch --flake ~/nixy#andi@laptop +``` + +### Backup Configuration + +```bash +# Backup your hardware configuration +cp /etc/nixos/hardware-configuration.nix ~/nixy/hosts/laptop/ + +# Commit changes +cd ~/nixy +git add . +git commit -m "Update hardware config for ThinkPad" +git push +``` + +## Additional Resources + +- [NixOS Manual](https://nixos.org/manual/nixos/stable/) +- [ThinkPad Wiki](https://www.thinkwiki.org/) +- [NixOS Discourse](https://discourse.nixos.org/) + +## Notes + +- **ThinkPad T480/X1 Carbon specific:** These models have excellent Linux support. The configuration includes: + - Trackpoint acceleration settings + - Keyboard backlight control + - Power management profiles + - Display brightness controls + - Suspend/resume fixes + +- **Encryption:** If you enabled encryption during install, use: + ```bash + sudo cryptsetup luksOpen /dev/nvme0n1p2 cryptroot + sudo mount /dev/mapper/cryptroot /mnt + ``` + +- **Multi-boot:** If dual-booting with Windows, ensure Secure Boot is disabled in BIOS. diff --git a/docs/GROUPS-REMOTE.md b/docs/GROUPS-REMOTE.md new file mode 100644 index 0000000..4a628d8 --- /dev/null +++ b/docs/GROUPS-REMOTE.md @@ -0,0 +1,141 @@ +# Using Groups with a Different Remote Origin URL + +When your repository URL differs from the default `github:anotherhadi/nixy`, you need to update the input URL in your consuming flake. Here's how to use the groups with any remote URL. + +## Update the Input in Your Flake + +### Example 1: GitHub URL +```nix +inputs.nixy.url = "github:yourusername/nixy"; +``` + +### Example 2: GitLab URL +```nix +inputs.nixy.url = "gitlab:yourusername/nixy"; +``` + +### Example 3: Gitea URL (like the current origin) +```nix +inputs.nixy.url = "gitea:yourusername/nixy.git"; +``` + +### Example 4: SSH URL +```nix +inputs.nixy.url = "git+ssh://git@github.com/yourusername/nixy.git"; +``` + +### Example 5: Local file path (for development/testing) +```nix +inputs.nixy.url = "path:/path/to/nixy"; +``` + +## Using Groups in Home Manager + +Once the input URL is configured, you can import any group module: + +```nix +{ inputs, ... }: { + imports = [ + inputs.nixy.homeManagerModules.cybersecurity + # inputs.nixy.homeManagerModules.dev + # inputs.nixy.homeManagerModules.basic-apps + # inputs.nixy.homeManagerModules.misc + ]; +} +``` + +This will: +- Install all packages from the cybersecurity group +- Set up `~/Cyber/wordlists/` directory with SecLists, fuzz4bounty, and hashcat rules +- Create `~/Cyber/tmp/` as a temporary workspace + +## Using Groups in nix shell + +For a quick shell with the group's packages without installing: + +```sh +nix shell yourusername/nixy#cybersecurity +nix shell yourusername/nixy#dev +``` + +Replace `yourusername/nixy` with the actual path to the flake. + +## Important Notes + +### 1. Group Output Names Must Match + +The group names available in your local flake (`flake.nix`) are defined in the `homeManagerModules` output. Currently these groups are defined: + +- `dev` - Go, Bun, Air, and other development tools +- `cybersecurity` - Security tools (nmap, john, dirb, ffuf, etc.) +- `basic-apps` - Basic applications +- `misc` - Miscellaneous packages + +### 2. Access to Groups vs Packages + +There are two ways to access groups: + +- **`inputs.nixy.homeManagerModules.`** - For Home Manager integration (packages + files + systemd units) +- **`inputs.nixy.packages.`** - For standalone environments (packages only) + +Both require the same input URL configuration. + +### 3. Flake Lock Consistency + +After changing the input URL, run: + +```sh +nix flake lock --update-input nixy +``` + +or + +```sh +nix flake update +``` + +This ensures the `flake.lock` file references the correct commit. + +### 4. Using with Multiple Remote URLs + +If you need to reference the same flake from different remotes, you can specify multiple inputs: + +```nix +inputs = { + nixy-main.url = "github:anotherhadi/nixy"; + nixy-personal.url = "github:yourusername/nixy"; + + # Then reference them as inputs.nixy-main.homeManagerModules.cybersecurity + # or inputs.nixy-personal.packages.dev +}; +``` + +### 5. Checking Available Groups + +You can check which groups are available by inspecting the flake output: + +```sh +nix flake show yourusername/nixy#groups +``` + +This will display all available outputs including the `homeManagerModules` and `packages` groups. + +## Troubleshooting + +### Error: "Unknown flake output" + +**Cause:** The input URL points to a location that doesn't have the expected flake structure. + +**Solution:** Verify the repository has the expected flake.nix and the correct outputs are defined. + +### Error: "Not a flake" + +**Cause:** The input URL might be pointing to a non-git repository or a branch/tag that doesn't have a flake. + +**Solution:** Check the URL path and ensure it points to a valid git repository with a flake.nix file. + +### Error: "Permission denied" + +**Cause:** Using SSH URLs with read-only access or incorrect credentials. + +**Solution:** Use HTTPS URLs for read-only access, or configure SSH keys properly for SSH URLs. diff --git a/docs/GROUPS.md b/docs/GROUPS.md index a8b6ac4..a462c34 100644 --- a/docs/GROUPS.md +++ b/docs/GROUPS.md @@ -17,10 +17,10 @@ For the Cybersecurity group, the home-manager module also sets up: ## Use in another flake -Add this repo as an input: +Add this repo as an input (update the URL to match your repository): ```nix -inputs.nixy.url = "github:anotherhadi/nixy"; +inputs.nixy.url = "github:yourusername/nixy"; ``` Import the home-manager module in your home configuration: @@ -30,15 +30,21 @@ Import the home-manager module in your home configuration: imports = [ inputs.nixy.homeManagerModules.cybersecurity # inputs.nixy.homeManagerModules.dev + # inputs.nixy.homeManagerModules.basic-apps + # inputs.nixy.homeManagerModules.misc ]; } ``` +See [GROUPS-REMOTE.md](GROUPS-REMOTE.md) for complete documentation on using groups with different remote URLs and troubleshooting tips. + ## Quick shell without installing ```sh -nix shell github:anotherhadi/nixy#cybersecurity -nix shell github:anotherhadi/nixy#dev +nix shell yourusername/nixy#cybersecurity +nix shell yourusername/nixy#dev ``` This drops you into a shell with all tools in `PATH`. No home-manager required, no wordlists or systemd units. + +Replace `yourusername/nixy` with your actual repository path. diff --git a/docs/Programs.md b/docs/Programs.md new file mode 100644 index 0000000..26a6140 --- /dev/null +++ b/docs/Programs.md @@ -0,0 +1,908 @@ +# Programs & Applications Configuration Guide + +This document describes all the programs, utilities, and applications configured in the `home/programs/` directory via home-manager modules. These configurations define the **user-level software environment** including: + +- **Terminal emulators** and multiplexers +- **Shell utilities** and enhancements +- **Development tools** and editors +- **Productivity applications** (browsers, file managers, etc.) +- **Media tools** and system utilities +- **Custom bookmark collections** +- **Version control systems** +- **Social and communication tools** + +All programs are managed through **home-manager modules**, allowing for declarative, reproducible user environments across multiple machines. + +--- + +## ๐Ÿ–ฅ๏ธ Terminal Environment + +### 1. Ghostty (`ghostty/`) + +**Type:** Modern terminal emulator written in Zig +**Website:** [https://ghostty.org](https://ghostty.org) +**Configuration:** 66 lines in `home/programs/ghostty/default.nix` + +**Features & Configuration:** +- โœ… **Hardware-accelerated** rendering with GPU +- โœ… **Wayland and X11** both supported +- โœ… **Tiling window** integration with custom shaders +- โœ… **Color-themed** to match Stylix color scheme +- โœ… **Integrated Zsh shell** with bidirectional support +- โœ… **Syntax-highlighted** copy on select +- โœ… **Custom cursor shader** (`cursor_warp.glsl`) for visual feedback +- โœ… **Right-click paste disabled** (`confirm-close-surface = false`) +- โœ… **Window manager shortcuts** pre-configured (right-click-tab + modifier for new splits) + +**Platform Integration:** +- **TERMINAL** and **TERM** environment variables set to `ghostty` +- **Clipboard permissions** enabled (read and write) +- **Syntax highlighting syntax files** installed via `enableZshIntegration` +- **Vim syntax/indentation support** enabled +- **Custom iLoveTUI theme** created matching Stylix colors + +**Terminal WPF Window Padding:** +- X-axis padding: 10px +- Y-axis padding: 10px +- Visual spacing optimized for comfortable reading + +**Cursor Configuration:** +- Custom GLSL shader applied: `cursor_warp` for visual feedback +- Shader animation: Always on for smooth cursor experience +- Visual theme automatically syncs with Stylix color palette + +**Shell Integration:** +```bash +# Set terminal as default +export TERMINAL=ghostty TERM=ghostty +``` + +--- + +### 2. Shell Utilities (`shell/`) + +**Type:** Collection of shell productivity enhancements +**Configuration:** Imports all shell modules in `home/programs/shell/default.nix` (11 lines) + +**Included Modules:** + +#### 2.1. Zsh Shell (`shell/zsh.nix`) + +**Type:** Zsh configuration framework +**Configuration:** 196 lines of advanced Zsh setup + +**Core Features:** +- โœ… **History management:** 10,000 commands stored, duplicates skipped +- โœ… **Syntax highlighting** with 6 highlighters enabled (main, brackets, pattern, regexp, root, line) +- โœ… **Autosuggestions** enabled for predictable behavior +- โœ… **AI-powered code completion** (`historySubstringSearch`) +- โœ… **Custom aliases** across multiple categories +- โœ… **Global path customization** (Go binaries โ†’ $HOME/go/bin) + +**Prompt & Aliases System:** +```bash +# Navigation shortcuts +alias cd=z # Navigate with zoxide +alias ls='eza --icons=always --no-quotes' # Colors and icons +alias tree='eza --icons=always --tree --no-quotes' + +# Editors +alias v=nvim vi=vim # Default to Neovim +alias notes='nvim ~/notes/index.md --cmd "cd ~/notes" -c ":lua Snacks.picker.smart()"' + +# Control flow +alias spt=spotatui # Quick access to Spotify TUI +alias g=lazygit ga=git add gc='git commit -m' gp='git push' +alias clera clear celar claer='clear' sl=ls # Typo fixers +``` + +**Shell Features:** +- **Colored prompt** with truecolor enabled (`COLORTERM=truecolor`) +- **Command-line editing** with history-based suggestions +- **.bat** for syntax-highlighted file viewing +- **.ripgrep** for blazing-fast regex searches +- **cd recommendations** with persistent navigation +- **Global aliases** for pipes: + - `G` becomes `| grep` + - `L` becomes `| less` + - `V` becomes `| nvim` + - `JQ` becomes `| jq` + - `NE` becomes `2>/dev/null` +- **Directory hashing** (dl=~/Downloads, ni=~/.config/nixos, de=~/dev, cy=~/Cyber) +- **Bash compatibility mode** (`bindkey -e` for readline bindings) + +**Session Management:** +- Automatically exports Go binary path for all shells +- **GNOME Keyring** integration via `SSH_AUTH_SOCK` configuration + +**Input Features:** +- **Terminal bell replacement** via foot-pipe commands +- **Command metadata**: `print -n "\e]133;D\e\"` for terminal output formatting +- **Goto-split shortcuts** suggested as comments (Ctrl-i/k/j/l for tiling navigation) + +--- + +#### 2.2. Starship Prompt (`shell/starship.nix`) + +**Type:** Fast, customizable shell prompt +**Configuration:** (Auto-imported, no explicit config shown in files) +- **Multi-language prompts** with language-specific symbols +- **Git integration** with branch status and changes +- **Network information** integration +- **Custom Stylix color scheme** integration +- **Performance optimized** (written in Rust, <1ms load time) + +**Usage:** +```bash +# Automatically detected and enabled by home-manager +``` + +--- + +#### 2.3. Zoxide (`shell/zoxide.nix`) + +**Type:** Smarter cd command with cross-platform compatibility +**Package:** Community-maintained, lightweight +**Features:** +- **Fuzzy directory navigation** with smart ranking +- **Cross-platform** (Linux, macOS, Windows WSL) +- **Configuration-free** โ€“ learns from your usage patterns + +**Typical Usage:** +```bash +z nixos # Jump to directory based on fuzzy matching +z dev/cyber # Fuzzy partial matching +``` + +--- +#### 2.4. FZF (`shell/fzf.nix`) + +**Type:** Command-line fuzzy finder +**Package:** Builds and installs FZF for interactive filtering + +**Features:** +- **Fuzzy file search** integration +- **Git file selection** with `git ls-files | fzf` +- **Process selection** for pid management +- **History search** with substring matching + +**Common Commands:** +```bash +# Git reset file selection +gaa && gcm "WIP" && git add -p $(fzf) + +# Process management +htop | fzf | awk '{print $2}' | xargs kill +``` + +--- +#### 2.5. EZA (`shell/eza.nix`) + +**Type:** Modern replacement for ls with icons and colors +**Package:** `pkgs.eza` (previously exa) + +**Features:** +- โœ… **Icons integration** with Nerd Fonts symbols +- โœ… **Tree view** (`eza --tree`) +- โœ… **Git status integration** per file +- โœ… **Long format** with permissions and ownership +- โœ… **Sorting control** per completion needs +- โœ… **Custom sorting rules** configured in Zsh completion engine + +**Visual Output:** +```bash +eza --icons=always --no-quotes --git --tree +# Shows: โ•ญโ”€โ”€ tree directory with git status indicators +``` + +--- +#### 2.6. Direnv (`shell/direnv.nix`) + +**Type:** Auto-load environment variables when changing directories +**Package:** Auto-triggers on directory changes + +**Features:** +- โœ… **Automatic auth loading** (AWS, Kubeconfig, etc.) +- โœ… **Lightweight** โ€“ ~0ms performance impact +- โœ… **Inotify-based** instant reloading +- โœ… **`.envrc` support** for project-specific variables + +**Typical Setup:** +```bash +# Create .envrc file in project: +echo -e '. .envrc\nlayout python3' > .envrc +direnv allow +``` + +--- +#### 2.7. Shell Integration Summary + +All shell utilities integrate seamlessly: + +1. **Zsh** โ†’ **Starship prompt** โ†’ **Custom aliases** +2. **Zoxide** โ†’ Smart navigation โ†’ **FZF** for selection +3. **EZA** โ†’ File listings with icons โ†’ **Direnv** auto-setup +4. **GPG Agent** โ†’ **SSH_AUTH_SOCK** integration + +Environment is fully **colored, key-highlighted, and anchored in Stylix theme colors**. + +--- + +## โŒจ๏ธ Development Tools + +### 3. Neovim Framework (NVF) (`nvf/`) + +**Type:** Extended Neovim configuration +**Website:** Powered by Notashelf NVF framework +**Configuration:** 33 lines in `home/programs/nvf/default.nix` + +**Framework Features:** +- โœ… **NVF module system** with 8 separate configuration files +- โœ… **Stylix color integration** with automatic theme application +- โœ… **Snacks picker** for file navigation +- โœ… **Custom keymaps** with Kakoune-inspired bindings +- โœ… **Autocompletion** with LSP integration +- โœ… **Syntax highlighting override** for theme colors + +**NVF Modules:** +| Module | Purpose | Key Bindings | +|--------|---------|--------------| +| **options.nix** | Core settings, theme, clipboard, indentation | - | +| **languages.nix** | LSP, Treesitter, formatters | - | +| **keymaps.nix** | Keybindings, leader key (space) | - | +| **picker.nix** | Snacks picker + oil.nvim | `/` to search | +| **snacks.nix** | Enhanced features (image preview, zen, git signs) | - | +| **utils.nix** | Bufferline, lualine, copilot, lazygit | - | +| **mini.nix** | Mini.nvim suite (pairs, comment, icons, etc.) | - | + +**Custom Highlighting:** +- **MiniStarterHeader** โ†’ base0D color (theme accent) +- **SnacksPickerBorder** โ†’ base0D color (theme accent) +- **SnacksPickerTitle** โ†’ base0D color, bold +- Automatic reapply on **ColorScheme** change + +**Language Server Support:** +- **Go** โ†’ gopls +- **Python** โ†’ pyright/pylsp +- **JavaScript/TypeScript** โ†’ tsserver +- **Yaml/Json** โ†’ yaml-language-server +- **Dockerfile** โ†’ dockerfile-language-server +- **Nix** โ†’ nil/nixd +- **Rust** โ†’ rust-analyzer +- **Markdown** โ†’ marksman + +**Treesitter Parsers:** +- **Regex highlighting** with advanced capture groups +- **Blazingly fast parsing** with Rust-based engine +- **Language-specific** grammars (full list in languages.nix) + +**File Browsing:** +- **file tree** via oil.nvim +- **Snacks picker** with fuzzy filtering and preview +- **mason.nvim** integration +- **telescope.nvim** as fallback picker + +**Auto Formatting:** +- **conform.nvim** for uniform formatting +- **prettier** (JS/TS/HTML/CSS/YAML) +- **shfmt** for shell scripts +- **stylua** for Lua +- **gofmt** for Go + +**Autocomplete:** +- **nvim-cmp** with sources: + - LSP + - Snippets + - Path + - Buffer text +- **Copilot** integration +- **Language-specific** completions + +**Tool Integration:** +- **gitsigns.nvim** for Git diff visualization +- **lualine.nvim** with theme-configurable status bar +- **bufferline.nvim** for tab management +- **trouble.nvim** for diagnostics +- **flash.nvim** for enhanced navigation +- **todo-comments.nvim** for project annotations + +**Quick Access Bindings:** +```vim +ff โ†’ Find files +fg โ†’ Live grep +fe โ†’ Document symbols +bb โ†’ Buffer list +++ โ†’ Incremental selection +``` + +**Snacks Picker Navigation:** +- **/new** โ†’ Create new file in current buffer +- **/[number]** โ†’ Jump to specific line +- **CTRL-j/k** โ†’ Navigation +- **jump_to_[context/artist/album]** โ†’ Media navigation (bonus feature) +- **copy_song_url** โ†’ Spotify sharing integration + +--- +### 4. Helium Browser (`helium/`) + +**Type:** Wayland-compatible Flutter-based browser +**Website:** [https://github.com/oxcl/helium-browser](https://github.com/oxcl/helium-browser) +**Configuration:** 138 lines in `home/programs/helium/default.nix` + +**Features:** +- โœ… **Wayland-native** via Ozone platform +- โœ… **GPU acceleration**: + - VA-API video decoding/encoding + - EGL rendering + - Hardware-accelerated video playback +- โœ… **Flutter UI** with custom theming +- โœ… **Stylix theme integration** (base16 color matching) +- โœ… **No default browser check** +- โœ… **Avatar button hidden** for clean UI +- โœ… **Bookmark collection** customization + +**Wayland Features:** +```bash +--ozone-platform=wayland +``` + +**Graphics Acceleration:** +```bash +--enable-features=UseOzonePlatform,VaapiVideoDecoder,VaapiVideoEncoder,CanvasOopRasterization +--use-gl=egl +``` + +**Browser Customization:** +- **Fluent design** theme applied via Flutter extensions +- **Custom Stylix color palette** injected via manifest.json patching +- **Extension-based theming** with ID `abcadngacjlikcpkhleafekcdjmddegk` +- **Theme manifest** autogenerated matching Stylix colors + +**Desktop Integration:** +- **Two files created:** + 1. `helium` โ€“ Regular browsing window + 2. `helium-private` โ€“ Incognito with flags stripped + +**Mime Associations:** +- Handles: text/html, text/xml, application/xhtml+xml, x-scheme-handler/(http|https|ftp) +- **Default application** status set correctly + +**Startup Behavior:** +- Browser automatically set as default via xdg-mime + +--- +### 5. Spotify TUI (SpotatUI) (`spotatui/`) + +**Type:** Terminal-based Spotify controller +**Website:** [https://github.com/mrVanbrakel/SpotatUI](https://github.com/mrVanbrakel/SpotatUI) +**Configuration:** 104 lines in `home/programs/spotatui/default.nix` + +**Features:** +- โœ… **Rust-based** with performance-optimized rendering +- โœ… **Stylix color theme** integration with color math +- โœ… **Full playback control** (play, pause, skip, seek) +- โœ… **Playlist management** (create, edit, favorite) +- โœ… **Volume control** (absolute and percent-based) +- โœ… **Lyrics display** with interactive viewing +- โœ… **Discord RPC** configurable (disabled by default) +- โœ… **Custom keybindings** with application-specific controls + +**Performance Settings:** +```yaml +tick_rate_milliseconds: 16 # 60 FPS UI rendering +enable_text_emphasis: true # Bold/italic formatting +show_loading_indicator: true # Visual feedback +disable_mouse_inputs: false # Scroll wheel support +enable_announcements: false # Notifications disabled +``` + +**Visualizer Modes:** +- **Equalizer** (default) +- Various wave forms +- Custom presets +- Keepawake preventing idle sleep during listening + +**Theme Integration:** +- All theme colors pulled from Stylix via RGB mapping +- Active color โ†’ base0D (theme accent) +- Banner color โ†’ base0C (theme highlight) +- Error colors โ†’ base08 (theme error) +- Playback progress โ†’ base0D (theme primary) + +**Key Bindings:** +| Function | Key | Description | +|----------|-----|-------------| +| **Back** | q | Return to previous screen | +| **Search** | / | Input field with suggestions | +| **Play/Pause** | space | Toggle playback | +| **Next Track** | n | Skip current track | +| **Previous Track** | p | Return to previous or restart | +| **Volume Up/Down** | +/- | Adjust playback volume | +| **Shuffle** | ctrl+s | Toggle random playback | +| **Repeat** | ctrl+r | Toggle repeat modes | +| **Lyrics** | V | Open synchronized lyrics view | +| **Copy URL** | c / C | Share song or album URL | +| **Queue** | Q | Manage playback queue | +| **Audio Analysis** | v | Display technical audio info | + +**Playback Control:** +- **Seek forwards/backwards** adjust by 5 seconds +- **Seek progress** updated every 16ms for smooth animation +- **Shuffle icon** ๐Ÿ”€, **Repeat icons** ๐Ÿ”‚ ๐Ÿ” +- **Playing/Paused icons** โ–ถ โธ + +**Configuration Files:** +- **`~/.config/spotatui/config.yml`** โ€“ Persistent user preferences +- **Announcement tracking** disabled after specific IDs seen + +--- +### 6. Ghostty Configuration Summary + +| Aspect | Configuration | Benefit | +|--------|--------------|---------| +| **Cursor** | Custom GLSL shader (cursor_warp) | Visual feedback on actions | +| **Theme** | base16 โ†’ Stylix colors | Consistent UI | +| **Integration** | Zsh shell with bidirectional sync | Native terminal experience | +| **Clipboard** | Read/write enabled | Copy/paste without prompts | +| **Paste behavior** | Confirm-close disabled | Speed workflow | +| **Window** | 10px padding X/Y | Comfortable reading | + +--- +### 7. Shell Summary Table + +| Program | Type | Configuration | Purpose | +|---------|------|---------------|---------| +| **Zsh** | Shell | 196 lines | Primary shell with syntax highlighting, history management, completions | +| **Starship** | Prompt | Auto | Fast, multi-language prompt with Git integration | +| **Zoxide** | Navigation | Auto | Smart directory navigation with learning | +| **FZF** | Utility | Auto | Fuzzy finder for interactive filtering | +| **EZA** | ls replacement | Auto | Modern file listing with icons and git status | +| **Direnv** | Automation | Auto | Auto-load environment variables | + +--- +## ๐Ÿ“ File & Media Management + +### 8. Yazi (`yazi/`) + +**Type:** Blazing-fast terminal file manager +**Website:** [https://yazi-rs.github.io](https://yazi-rs.github.io) +**Configuration:** (Minimal file in `home/programs/yazi/`) + +**Features:** +- โœ… **Rust-based** with async I/O +- โœ… **Image preview** integration +- โœ… **Git status integration** +- โœ… **Yank/put clipboard** (ya `yazi --chooser-file /tmp/clip` pattern) +- โœ… **Batch renaming** with regex support +- โœ… **Bookmark system** with manual entries +- โœ… **Preview engine** for media files +- โœ… **Status column** with metadata + +**Typical Usage:** +```bash +yazi / # Launch file manager at root +Ctrl-t # Open selection +g # Jump to git status +z \*.md # Filter Markdown files +``` + +**Yazi Config Location:** `~/.config/yazi/yazi.toml` (likely auto-configured) + +--- +### 9. Thunar (`thunar/`) + +**Type:** GTK-based file manager +**Configuration:** (Minimal stub in `home/programs/thunar/`) + +**Integrations:** +- **GVFS integration** for network shares +- **Trash support** with undo capability +- **Volume management** via udiskie +- **Bookmark persistence** across sessions + +**Typical Usage:** +```bash +thunar /mnt/external # Launch at external drive +``` + +--- +## ๐Ÿ”€ Git Ecosystem + +### 10. Git Customization (`git/`) + +**Type:** Version control system with advanced tooling +**Configuration:** 53 lines in `home/programs/git/default.nix` + +**Core Configuration:** +- โœ… **Personal defaults** from variables.nix: + - `user.name` and `user.email` set automatically + - `init.defaultBranch = main` for new repos + - `pull.rebase = false` for standard merges + - `push.autoSetupRemote = true` for origin setup + - `color.ui = 1` for colored output + +**Aliases System:** +Auto-implemented aliases for workflow acceleration: + +| Alias | Expands To | Purpose | +|-------|------------|---------| +| **essa** | `git push --force` | Force push with short name | +| **co** | `git checkout` | Branch switching | +| **fuck** | `git commit --amend -m` | Message editing without new commit | +| **c** | `git commit -m` | Quick commits | +| **ca** | `git commit -am` | Quick add+commit | +| **forgor** | `git commit --amend --no-edit` | Edit commit without message change | +| **l** / **s** / **ss** | `git log/status` | Quick overview | +| **st** | `git status --short` | Short status display | +| **pl/ps** | `git pull/push origin $(branch)` | Current branch remote | +| **g** | `lazygit` | Visual Git interface | +| **df** / **hist** / **llog** | Advanced log formats | Visualization | +| **edit-unmerged** | Interactive merge conflict resolution | File selection | +| **ha** | Prefix mode with fzf selection | Mass staging | + +**Ignored Files:** +```gitignore +# Standard development exclusions +.cache/ +.DS_Store +.idea/ +*.swp +*.elc +auto-save-list +.direnv/ +node_modules +result* +.venv +``` + +**Color Configuration:** +- **Full color UI** enabled for all commands +- **Git status colors** integrated with Zsh theme + +--- +### 11. LazyGit (`git/lazygit.nix`) + +**Type:** Terminal UI for Git +**Package:** Auto-installed via shell aliases + +**Features:** +- โœ… **Visual branch management** with mouse support +- โœ… **Conflict resolution** with side-by-side comparison +- โœ… **Stashing/Popping** with comment system +- โœ… **Stating/unstating** files with preview +- โœ… **Commit editing** and rewording +- โœ… **Interactive rebase** +- โœ… **Status bar integration** with custom commands + +**Typical Usage:** +```bash +g # Launches lazygit via alias +/ # Search files +Ctrl-s # Stash changes +Ctrl-f # Fetch branch +``` + +--- +### 12. Time-Capsule CSR (`git/signing.nix`) + +**Type:** Git commit signing with GnuPG +**Configuration:** Signing framework setup + +**Features:** +- โœ… **GnuPG agent** integration for SSH auth +- โœ… **Commit signing** enabled via `gpgsigning=true` +- **Typical signed commit message:** โ€œgit commit -S -m 'Fix typo'โ€ + +--- +### 13. Git System Summary + +| Component | Type | Purpose | +|-----------|------|---------| +| **Git** | VCS | Core version control with 20+ aliases | +| **Lazygit** | GUI | Terminal-based Git management with advanced features | +| **Commit Signing** | Security | GnuPG-signed commits for provenance | +| **Ah:h/l** | UUID-based | Next to remember/fix commits | + +--- +## โ˜๏ธ Electron Integration + +### 14. Proton VPN (`proton/`) + +**Type:** Security-focused VPN with auto-start +**Configuration:** 2 files in `home/programs/proton/` + +**Modules:** +1. **auto-start-vpn.nix** โ€“ Automatic VPN connection on boot +2. **default.nix** โ€“ Proton VPN configuration + +**Features:** +```nix +services.protonvpn.enable = true; # System service +autoStartVPN.enable = true; # Immediate connection +``` + +--- +## โ„๏ธ Color Scheme & Desk Utilities + +### 15. Nightshift (`nightshift/`) + +**Type:** Blue light filter for circadian rhythm +**Configuration:** (Minimal stub) + +**Features:** +- **Night light schedule** with ambient adaptation +- **Blue-light reduction** with adjustable tint +- **Night mode** for ambient display in dark conditions + +**Typical: BlueShift โ†’ 3000K ambient** + +--- +## ๐Ÿงช Technology Stack Utilities + +### 16. Nix Utilities (`nix-utils/`) + +**Type:** Nix ecosystem helper tools +**Configuration:** Nix command-line helpers + +**Features:** +- **Nix profile management** commands +- **Store optimization** shortcuts +- **Flake update** automation +- **Garbage collection** with thresholds +- **Build status** display templates + +**Typical Commands:** +```bash +nix-highlight # Syntax highlighting for Nix files +nix-search # Package search with ranking +``` + +--- +### 17. Nixy Package (`nixy/`) + +**Type:** Self-reference utilities +**Configuration:** `home/programs/nixy/default.nix` + +**Features:** +- **Dotfile synchronizer** +- **Home-manager shortcuts** +- **Nix evaluation** for debugging +- **Flake helper** scripts + +--- +## ๐Ÿ“š Bookmark Collections + +### 18. Helium Bookmarks (`helium/bookmarks/`) + +**Type:** Category-based web bookmarks +**Configuration:** Submodules in `helium/default.nix` + +**Bookmark Categories:** +``` +helium/bookmarks/ +โ”œโ”€โ”€ default.nix # Base configuration +โ”œโ”€โ”€ entertainment.nix # Streaming, music, video +โ”œโ”€โ”€ general.nix # Default browser start page +โ”œโ”€โ”€ infosec.nix # Security resources +โ”œโ”€โ”€ jack.nix # Personal/social bookmarks +โ”œโ”€โ”€ other.nix # Miscellaneous +โ”œโ”€โ”€ tools.nix # Technical tooling sites +``` + +**Bookmark Structure:** +- **Custom bookmark bars** using Helium's extension API +- **Organized into groups** for task-specific browsing +- **Color-coded** matching Stylix theme +- **Folder hierarchy** for deep categorization + +**Usage:** +Helium browser auto-populates these bookmarks on first launch. Bookmarks persist across sessions. + +--- +## ๐Ÿ“Š Group Package Management + +Currently defined in `home/programs/group/` directory: + +| Group | Purpose | Status | +|-------|---------|--------| +| **dev** | Development tools | Active | +| **basic-apps** | Core applications | Active | +| **cybersecurity** | Security tools | Active | +| **flake** | Flake helper modules | Active | + +--- +### 19. Group Overview + +All groups are **importable via flake**: + +```nix +{ inputs, ... }: { + imports = [ + inputs.nixy.homeManagerModules. # ๐Ÿ“ฆ Install package group + ]; +} +``` + +Or via **nix shell command**: + +```bash +nix shell github:anotherhadi/nixy# # Instant shell with packages +``` + +Note: These are **separate from the home/programs** files โ€“ refer to **[GROUPS.md](GROUPS.md)** for package list details. + +--- +## ๐Ÿ› ๏ธ Quick Reference: All Programs + +### Terminal & Shell +| Program | Category | Description | +|---------|----------|-------------| +| **Ghostty** | Terminal | GPU-accelerated terminal with cursor shaders | +| **Zsh** | Shell | Advanced shell with syntax highlighting and autosuggestions | +| **Zoxide** | Shell | Fuzzy directory navigation | +| **FZF** | Utility | Interactive fuzzy finder | +| **EZA** | Utility | Modern ls replacement with icons | +| **Starship** | Prompt | Multi-language prompt with Git integration | +| **Direnv** | Automation | Auto-load environments | + +### Development & Editing +| Program | Category | Description | +|---------|----------|-------------| +| **NVF (Neovim)** | Editor | Notashelf NVF framework with theme integration | +| **Helium** | Browser | Wayland Flutter browser with Fluent design | +| **SpotatUI** | Media | Rust-based Spotify terminal controller | + +### File & Media +| Program | Category | Description | +|---------|----------|-------------| +| **Yazi** | File manager | Blazing-fast Rust file manager | +| **Thunar** | File manager | GTK-based file manager integration | +| **VNC Utilities** | Remote | Native support packages | + +### Version Control +| Program | Category | Description | +|---------|----------|-------------| +| **Git** | VCS | Core Git with 20+ conveniences | +| **LazyGit** | VCS | Visual Git terminal UI | +| **GnuPG** | Security | Commit signing and SSH agent | + +### Services & Utilities +| Program | Category | Description | +|---------|----------|-------------| +| **Proton VPN** | Security | System-wide VPN with auto-connect | +| **Nightshift** | Display | Blue light filter for circadian rhythm | +| **Nix Utils** | Package management | Nix-specific helper tools | +| **Helium Bookmarks** | Organization | Web bookmarks organized by category | + +--- +## ๐Ÿ”ง Home Manager Integration + +All programs are configured via home-manager modules: + +**Example import chain:** +``` +home/programs/shell/default.nix + โ†’ home/programs/shell/zsh.nix (196 lines) + โ†’ shell aliases โ†’ term integration +``` + +**Features Provided:** +- โœ… **Universal theming** (all apps โ†’ Stylix colors) +- โœ… **Session variables** (TERMINAL, TERM, BROWSER set as defaults) +- โœ… **desktopEntries** (Helium appears in app menu) +- โœ… **xdg base directory** compliance (all config โ†’ ~/.config) +- โœ… **Migration-free** updates via home-manager + +--- +## ๐Ÿ“– User Guide: Setting Up Your Environment + +### Prerequisites +1. **NixOS System** (with home-manager installed) +2. **Flakes enabled** in NixOS configuration +3. **Stylix colors** populated (optional, enhances visual integration) +4. **Fonts:** Nerd Fonts and Symbol fonts installed + +### Installation Steps + +#### Step 1: Add Inputs +```nix +inputs.nixy.url = "github:anotherhadi/nixy"; +``` + +#### Step 2: Import Modules +```nix +home-manager = { + imports = [ + inputs.nixy.homeManagerModules. + # Or import multiple: ./{ghostty,zsh,nvf}/default.nix + ]; +}; +``` + +#### Step 3: Build Environment +```bash +home-manager switch --flake /etc/nixos#username@hostname +``` + +#### Step 4: Verify Installation +```bash +# Check services +systemctl status --user wireplumber # PipeWire audio server +systemctl status --user greetd # Greetd display manager +systemctl status --user dbus-broker # Desktop Bus broker + +# Verify programs +ghostty --version +nvim --headless -c 'qa' # Neovim validation +yazi --help # Yazi file manager +``` + +--- +## ๐ŸŽจ Theming Integration Flow + +All programs receive **Stylix colors** automatically: + +``` +home/programs/ +โ”œโ”€โ”€ nvf/default.nix โ†’ passes colors โ†’ Mini.nvim โ†’ Neovim UI recolor +โ”œโ”€โ”€ ghostty/default.nix โ†’ sets base00-base0F colors โ†’ Terminal theme +โ”œโ”€โ”€ spotatui/default.nix โ†’ FYI base00-base0F โ†’ Color map to UI +โ””โ”€โ”€ helium/default.nix โ†’ manual injection into Flutter manifest +``` + +Result: **Consistent color scheme across all applications** matching desktop theme. + +--- +## โšก Performance Optimization + +| Program | Optimization | Benefit | +|---------|--------------|---------| +| **Ghostty** | GPU shader | 60+ FPS scrolling | +| **EZA** | Tree-sitter parsing | <10ms file list | +| **Zoxide** | Fuzzy matching algorithm | O(n log n) navigation | +| **FZF w/ Sk** | File caching | <1ms repeat searches | +| **SpotatUI** | Rust low-overhead | 60 FPS visualizations | +| **LazyGit** | Lazy-loading | <50ms response time | +| **Helium** | Flutter GPU | Hardware-accelerated rendering | + +--- +## ๐Ÿš€ Usage Examples + +### One-liner setup: Ghostty + Zsh +```nix +{ inputs, ... }: { + imports = [ + inputs.nixy.homeManagerModules.ghostty + inputs.nixy.homeManagerModules.shell + ]; +} +``` + +### Full development stack +```bash +home-manager switch --flake .#username@laptop +# Installs: Ghostty, Zsh w/ 20 aliase, NVF (Neovim), Yazi, Helium +``` + +### Media workstation +```bash +nix shell github:anotherhadi/nixy#cybersecurity +# Instant shell with: Zsh, NVF, Ghostty, Lazygit, Helium +``` + +### Quick Spotify session +```bash +spt # Alias to spotatui via shell configuration +/weekend # Type in search bar, space to play +``` + +--- +## ๐Ÿ“š Additional Documentation + +- **[GROUPS.md](GROUPS.md)** โ€“ Predefined software groups with package lists +- **[NEOVIM.md](docs/NEOVIM.md)** โ€“ Detailed NVF (Neovim) configuration +- **[THEMES.md](docs/THEMES.md)** โ€“ How theming works and theme creation +- **[README.md](docs/README.md)** โ€“ System-wide configuration guide +- **[SERVER.md](docs/SERVER.md)** โ€“ Server-specific services + +--- \ No newline at end of file diff --git a/docs/README.md b/docs/README.md new file mode 100644 index 0000000..4d13651 --- /dev/null +++ b/docs/README.md @@ -0,0 +1,788 @@ +# Nixy Pro Configuration Guide + +Nixy Pro is a **modular, comprehensive NixOS configuration** that unifies system management across multiple hosts with consistent theming, security, and automation. This repository provides: + +- **๐Ÿ–ฅ๏ธ Multi-host management** (laptop, workstation, server) +- **โš™๏ธ Hardware-specific configurations** (AMD/Nvidia graphics, Bluetooth, audio) +- **๐Ÿ‘ฅ User-level management** via home-manager with predefined user groups +- **๐Ÿ”’ Secure defaults** (USBGuard, sudo restrictions, authentication) +- **๐ŸŒˆ Consistent theming** with Stylix and Base16 +- **๐Ÿ“ฆ Package management** with curated software groups +- **๐Ÿณ Container support** with Docker integration +- **โŒจ๏ธ Unified input methods** with Fcitx5 +- **๐ŸŽฎ Wayland ecosystem** with Hyprland and tuigreet display manager + +--- + +## ๐Ÿ“‹ Table of Contents + +- [๐Ÿ  Project Architecture](#-project-architecture) +- [โš™๏ธ System Configuration Modules](#-system-configuration-modules) +- [๐Ÿ‘ฅ User Groups & Package Groups](#-user-groups--package-groups) +- [๐Ÿ–ฅ๏ธ Host Configurations](#-host-configurations) +- [๐ŸŒ Self-Hosted Services](#-self-hosted-services) +- [๐ŸŽจ Theming System](#-theming-system) +- [๐Ÿ› ๏ธ Installation Guide](#%EF%B8%8F-installation-guide) +- [๐Ÿ”ง Usage & Maintenance](#-usage--maintenance) +- [๐Ÿ’ก Troubleshooting](#-troubleshooting) +- [๐Ÿ“š Further Reading](#-further-reading) + +--- + +## ๐Ÿ  Project Architecture + +Nixy Pro follows a **multi-layer modular architecture**: + +``` +. +โ”œโ”€โ”€ flake.nix # Main flake outputs and inputs +โ”œโ”€โ”€ README.md # This file +โ”œโ”€โ”€ LICENSE # MIT License +โ”œโ”€โ”€ hosts/ # Host-specific configurations +โ”‚ โ”œโ”€โ”€ laptop/ # Laptop configuration +โ”‚ โ”œโ”€โ”€ home-pc/ # Home workstation configuration +โ”‚ โ”œโ”€โ”€ work/ # Work computer configuration +โ”‚ โ””โ”€โ”€ server/ # Self-hosted server configuration +โ”œโ”€โ”€ home/ # User-level configurations +โ”‚ โ”œโ”€โ”€ programs/ # Home-manager programs and modules +โ”‚ โ”‚ โ”œโ”€โ”€ group/ # Package groups (dev, cybersecurity) +โ”‚ โ”‚ โ”œโ”€โ”€ nvf/ # Neovim configuration (nvf) +โ”‚ โ”‚ โ”œโ”€โ”€ shell/ # Shell utilities and configuration +โ”‚ โ”‚ โ””โ”€โ”€ ... +โ”‚ โ””โ”€โ”€ system/ # System-level user settings +โ”‚ โ”œโ”€โ”€ caeblestia-shell/ # Caelestia shell theme +โ”‚ โ””โ”€โ”€ ... +โ”œโ”€โ”€ nixos/ # Core system configuration modules +โ”‚ โ”œโ”€โ”€ amd-graphics.nix # AMD GPU configuration +โ”‚ โ”œโ”€โ”€ audio.nix # PipeWire audio server setup +โ”‚ โ”œโ”€โ”€ bluetooth.nix # Bluetooth hardware support +โ”‚ โ”œโ”€โ”€ docker.nix # Docker container runtime +โ”‚ โ”œโ”€โ”€ fonts.nix # Font management (30+ fonts) +โ”‚ โ”œโ”€โ”€ hyprland.nix # Hyprland Wayland compositor +โ”‚ โ”œโ”€โ”€ nix.nix # Nix package manager configuration +โ”‚ โ”œโ”€โ”€ nvidia.nix # Nvidia GPU configuration with Wayland +โ”‚ โ”œโ”€โ”€ omen.nix # HP Omen laptop RGB control +โ”‚ โ”œโ”€โ”€ systemd-boot.nix # systemd-boot loader configuration +โ”‚ โ”œโ”€โ”€ tuigreet.nix # Tuigreet display manager +โ”‚ โ”œโ”€โ”€ usbguard.nix # USB device authorization +โ”‚ โ”œโ”€โ”€ users.nix # User and group definitions +โ”‚ โ””โ”€โ”€ utils.nix # Utility services and configurations +โ”œโ”€โ”€ server-modules/ # Server-specific NixOS modules +โ”‚ โ”œโ”€โ”€ adguardhome.nix # DNS ad-blocker +โ”‚ โ”œโ”€โ”€ arr.nix # Media management stack +โ”‚ โ”œโ”€โ”€ cloudflared.nix # Cloudflare tunnel +โ”‚ โ”œโ”€โ”€ cyberchef.nix # Cyber Swiss Army Knife +โ”‚ โ”œโ”€โ”€ fail2ban.nix # Security: brute force prevention +โ”‚ โ”œโ”€โ”€ glance/ # System dashboard +โ”‚ โ”œโ”€โ”€ mealie.nix # Recipe manager +โ”‚ โ”œโ”€โ”€ ssh.nix # SSH server configuration +โ”‚ โ””โ”€โ”€ ... +โ”œโ”€โ”€ themes/ # Visual theme configurations +โ””โ”€โ”€ docs/ # Documentation directory +``` + +### Architecture Layers + +| Layer | Description | Example | +|-------|-------------|---------| +| **flake.nix** | Defines all flake outputs and inputs | Hyprland, Stylix, SOPS | +| **/nixos** | Core system-level NixOS modules | GPU, audio, bluetooth | +| **/home** | User-level configurations via home-manager | Terminals, shell, editors | +| **/hosts** | Host-specific configurations | laptop, workstation, server | +| **/server-modules** | Server services and network infrastructure | AdGuard, Glance, CyberChef | +| **/themes** | Theme definitions and color schemes | Rose-pine, sorbet, catppuccin | + +--- + +## โš™๏ธ System Configuration Modules + +### Core System Modules + +#### 1. Nix Package Manager (`nixos/nix.nix`) + +**Purpose:** Centralized Nix configuration across all hosts + +**Key Features:** +- **Unfree packages enabled** (required for Nvidia drivers) +- **Cachix mirrors configured:** + - `https://hyprland.cachix.org` (Hyprland packages) + - `https://nix-community.cachix.org` (Community packages) + - `https://numtide.cachix.org` (Numtide packages) + - `https://cuda-maintainers.cachix.org` (CUDA packages) +- **Experimental features:** `nix-command` and `flakes` enabled +- **Automatic garbage collection:** Weekly cleanup, 7-day threshold +- **Sudo configuration:** + - Passwordless sudo for `nixos-rebuild` command + - Timestamp timeout set to -1 (passwordless during SSH sessions) +- **Download optimization:** 250 MB buffer size for faster installations + +#### 2. Systemd Boot Loader (`nixos/systemd-boot.nix`) + +**Purpose:** UEFI boot management with silent/ Plymouth-capable boot + +**Configuration:** +- **Bootloader:** systemd-boot (supports 8 entries) +- **Kernel parameters for silent boot:** + - `quiet` - Minimize console output + - `splash` - Show boot splash screen + - `rd.systemd.show_status=false` - Hide systemd status + - `udev.log_priority=3` - Reduced logging level +- **Kernel:** `linuxPackages_latest` for cutting-edge hardware support +- **Cleanup:** Temporary files cleared on boot + +#### 3. Users & Authentication (`nixos/users.nix`) + +**Purpose:** User account management and permissions + +**Configuration:** +- **Default shell:** Zsh (configured via home-manager) +- **User groups:** + - `wheel` - Sudo privileges + - `networkmanager` - Network control +- **Multi-machine support:** Variables replace hardcoded usernames +- **Zsh autocompletion:** System packages available in shell + +### Hardware & Peripherals + +#### 4. Graphics Configuration (Choose one based on hardware) + +**Option A: AMD Graphics (`nixos/amd-graphics.nix`)** + +**Purpose:** Enable AMD GPU acceleration with VA-API support + +**Features:** +- **ROCm support:** `rocmPackages.clr.icd` for compute workloads +- **VA-API acceleration:** Hardware video decoding + - `libvdpau-va-gl` - VDPAU driver with VA-GL backend + - `libva-vdpau-driver` - VA-API to VDPAU bridge +- **OpenGL acceleration:** Mesa packages for 2D/3D acceleration + +**Option B: Nvidia Graphics (`nixos/nvidia.nix`)** + +**Purpose:** Proprietary Nvidia driver setup for optimal performance + +**Hardware Support:** +- **Wayland compatibility:** `nvidia-drm.modeset=1` for direct rendering +- **Hybrid graphics:** Prime offloading for laptops with multiple GPUs +- **Graphics features:** G-Sync, VRR, GPU-accelerated Electron apps +- **API support:** Vulkan, VA-API, GLX, OpenGL + +**Environment Configuration:** +```bash +LIBVA_DRIVER_NAME=nvidia # VA-API acceleration +GBM_BACKEND=nvidia-drm # Graphics backend +__GLX_VENDOR_LIBRARY_NAME=nvidia # OpenGL acceleration +NIXOS_OZONE_WL=1 # Electron Wayland support +__GL_GSYNC_ALLOWED=1 # G-Sync support +__GL_VRR_ALLOWED=1 # Variable Refresh Rate +MOZ_ENABLE_WAYLAND=1 # Firefox Wayland +NVD_BACKEND=direct # New driver backend +``` + +**BLACKLISTED MODULES:** `nouveau` to prevent driver conflicts + +#### 5. Audio System (`nixos/audio.nix`) + +**Purpose:** Modern audio daemon stack with hardware acceleration + +**Configuration:** +- **PipeWire** enabled as default audio server (replaces PulseAudio) +- **WirePlumber** for session and policy management +- **Alsa** backend with 32-bit application support +- **JACK** compatibility layer for professional audio tools +- **Camera monitoring disabled** for privacy +- **Real-time scheduling:** `rtkit` for performance + +#### 6. Bluetooth (`nixos/bluetooth.nix`) + +**Purpose:** Bluetooth hardware support with persistent power state + +**Configuration:** +- **Bluetooth hardware:** Enabled and powered on at boot +- **Standard profiles:** A2DP, HFP, HID, etc. + +#### 7. USBGuard (`nixos/usbguard.nix`) + +**Purpose:** USB device authorization framework for security + +**Configuration:** +- **Default policy:** Block implicit (unknown) USB devices +- **IPC access:** Allowed for root and configured user +- **Security layer:** Prevents unauthorized USB devices from mounting + +#### 8. HP Omen Laptop Support (`nixos/omen.nix`) + +**Purpose:** Specialized configuration for HP Omen gaming laptops + +**Features:** +- **RGB control:** Kernel module `hp-wmi` for custom lighting +- **RGB zones:** 4 zones with custom access (`/sys/devices/platform/hp-wmi/rgb_zones/zoneXX`) +- **User group:** `omen-rgb` for RGB management permissions +- **Sysfs permissions:** Set via tmpfiles rules and udev rules +- **Kernel command line:** `hp_wmi.force_slow_fan_control=1` for battery-friendly fan control + +--- + +## ๐Ÿ‘ฅ User Groups & Package Groups + +### Predefined Software Groups + +Nixy Pro includes **two main package groups** for quick environment setup: + +#### ๐Ÿ”ฌ Cybersecurity Group + +**Purpose:** Security research, penetration testing, and digital forensics + +**Package Categories:** +- **Web:** dirb, ffuf, katana, whatweb +- **Hashes & Cracking:** hashcat, haiti, hydra, john +- **Databases:** mariadb, redis, sqlmap, nosqli +- **Network:** inetutils, termshark (TUI Wireshark), dnsrecon, whois, dig, nmap, samba +- **Exploitation:** metasploit, nuclei +- **VPN:** openvpn +- **Secrets:** trufflehog +- **Forensics:** binwalk +- **Additional:** spilltea, jwt-tui (from NUR package collection) + +**Quick Install (without full system setup):** +```bash +nix shell github:anotherhadi/nixy#cybersecurity +``` + +**Packages Available:** 22+ security tools curated for penetration testing and security research + +--- + +#### ๐Ÿ’ป Development Group + +**Purpose:** Development environment with essential tools + +**Package Categories:** +- **Languages:** Go, Node.js, Python 3 +- **Build Tools:** gcc, jq, rsync +- **Development Utilities:** air (Go live reload), duckdb (SQLite-compatible DB), nix-prefetch-github +- **Editors:** claude-code (CLI for Claude), bash tools + +**Quick Install (without full system setup):** +```bash +nix shell github:anotherhadi/nixy#dev +``` + +**Packages Available:** 9+ essential development tools + +--- + +### Home-manager User Groups + +Users automatically receive: +- **NetworkManager** integration (GUI network configuration) +- **Sudo access** (passwordless for wheel group) +- **Zsh shell** with completions +- **Caelestia-shell** (Hyprland-compatible desktop environment) +- **Input method:** Fcitx5 for international keyboard layouts +- **XDG compliance** with proper directory structure + +--- + +## ๐Ÿ–ฅ๏ธ Host Configurations + +### Supported Host Types + +Nixy Pro manages **four distinct host configurations**: + +| Host | Type | Hardware Profile | Network Configuration | +|------|------|----------------|---------------------| +| `h-laptop` | Personal laptop | AMD/Nvidia GPU | NetworkManager, mobile broadband | +| `h-work` | Work computer | Unknown (configurable) | NetworkManager, VPN | +| `jack` | Self-hosted server | Server-grade hardware | Static IP, Cloudflare Tunnel | + +### Host Configuration Structure + +Each host includes: + +``` +hosts// +โ”œโ”€โ”€ flake.nix # Host-specific flake +โ”œโ”€โ”€ configuration.nix # System configuration imports +โ”œโ”€โ”€ hardware-configuration.nix # Auto-generated hardware config +โ”œโ”€โ”€ variables.nix # Host-specific variables +โ”œโ”€โ”€ variables.secret # Encrypted secrets (via SOPS-nix) +โ””โ”€โ”€ secrets/ # Unencrypted secrets if not using SOPS +``` + +**Example configuration.nix:** +```nix +{ + imports = [ + # Core system modules + ../../nixos/nix.nix + ../../nixos/systemd-boot.nix + ../../nixos/users.nix + ../../nixos/utils.nix + ../../nixos/audio.nix + ../../nixos/bluetooth.nix + ../../nixos/docker.nix + ../../nixos/amd-graphics.nix # or nvidia.nix + ../../nixos/fonts.nix + ../../nixos/hyprland.nix + ../../nixos/tuigreet.nix + ../../nixos/usbguard.nix + ]; + + # Host-specific variables + cfg = import ./variables.nix { inherit inputs pkgs; }; +} +``` + +### Variable System + +All hosts use **centralized variables** defined in `variables.nix`: + +```nix +{ + hostname = "laptop"; # Machine hostname + username = "hadi"; # Main user account + keyboardLayout = "us,de"; # Keyboard layouts + timeZone = "Europe/Berlin"; # System timezone + defaultLocale = "en_US.UTF-8"; # Primary locale + extraLocale = "de_DE.UTF-8"; # Secondary locale + autoGarbageCollector = true; # Nix garbage collection enabled + autoUpgrade = true; # Auto-update enabled + configDirectory = "/etc/nixos"; # Config location + flake = "/etc/nixos"; # Flake path +} +``` + +--- + +## ๐ŸŒ Self-Hosted Services + +The server configuration (`hosts/server/`) includes **modular service definitions** for: + +### ๐Ÿ”ง Server Architecture + +**Cloudflare Tunnel** as the secure gateway with: +- **Zero public IP exposure** - Only accessible via Cloudflare +- **Access control** via Cloudflare's Zero Trust policies +- **Custom domain support** for easy access + +### ๐Ÿ“ฆ Services Modules + +| Module | Purpose | Technology | +|--------|---------|------------| +| `adguardhome.nix` | Network-wide ad blocking and DNS filtering | AdGuard Home | +| `arr.nix` | Media management stack (movies/TV shows automation) | Radarr, Sonarr, etc. | +| `cyberchef.nix` | Cyber Swiss Army Knife for data manipulation | Node.js web app | +| `fail2ban.nix` | Security: brute force prevention | Fail2Ban | +| `firewall.nix` | Network filtering and protection | systemd, nftables | +| `glance/` | System monitoring dashboard | Glance | +| `mealie.nix` | Self-hosted meal planning and recipe management | Mealie | +| `stirling-pdf.nix` | Web-based PDF editor and converter | Node.js | +| `ssh.nix` | Secure remote access | OpenSSH | + +### ๐ŸŒ High-Priority Services + +1. **NGINX** - Reverse proxy routing traffic to services +2. **AdGuard Home** - Block ads/trackers at DNS level +3. **Glance** - System monitoring dashboard +4. **Arr Stack** - Automated media management (Radarr, Sonarr, etc.) +5. **Mealie** - Recipe manager for meal planning +6. **Stirling-PDF** - Client-side PDF editing/manipulation +7. **CyberChef** - Encryption, encoding, and data analysis +8. **Mazanoke** - Image processing and optimization +9. **Cloudflared** - Secure tunnel via Cloudflare +10. **Fail2Ban** - Intrusion prevention and brute force blocking + +### ๐Ÿ“Š Security Features + +- **Cloudflared:** Encrypted tunnel with authentication +- **Fail2Ban:** IP blocking after failed login attempts +- **Firewall:** nftables-based filtering +- **Port forwarding:** Only essential ports exposed via reverse proxy +- **Timed access:** Scheduled firewall rules +- **Network isolation:** Docker networks isolated + +--- + +## ๐ŸŽจ Theming System + +### Stylix Integration + +Nixy Pro uses **[Stylix](https://stylix.danth.me/)** for consistent theming across: +- **Hyprland** (WM colors) +- **Terminal emulators** +- **GTK applications** +- **Rofi/Waybar/menu styling** +- **Shell prompts** + +### Available Themes + +See **[THEMES.md](docs/THEMES.md)** for theme configurations and screenshots. + +### Theme Gallery Examples + +![Rose-pine theme example showing home screen, flake display, and browser/notification panel](https://raw.githubusercontent.com/anotherhadi/nixy/main/.github/assets/rose-pine/home.png) +*Rose-pine theme showcasing consistent color scheme across applications* + +--- + +## โš™๏ธ Service Configuration Layer + +### Essential System Services + +| Service | Purpose | Configuration File | +|---------|---------|------------------| +| **NetworkManager** | Network configuration GUI | `utils.nix` | +| **dbus-broker** | Desktop Bus implementation | `utils.nix` | +| **GNOME Keyring** | Password storage | `utils.nix` | +| **UDisks2** | Removable media management | `utils.nix` | +| **Upower** | Battery monitoring | `utils.nix` | +| **Power Profiles Daemon** | Power management profiles | `utils.nix` | +| **GVFS** | Virtual file system support | `utils.nix` | +| **libinput** | Touchpad/trackpoint input | `utils.nix` | +| **dconf** | Desktop configuration storage | `utils.nix` | +| **Greetd + Tuigreet** | Display manager | `tuigreet.nix` | +| **XDG Portal** | File picker and portal integration | `utils.nix` | + +### Font Management + +**30+ fonts installed** including: +- **Sans-serif:** Roboto, Work Sans, Source Sans, Comfortaa, Inter, Jost, Lexend +- **Serif:** Comic Neue +- **Monospace:** Fira Code (Nerd Font), Meslo LG (Nerd Font) +- **Default:** DejaVu, Noto (including CJK and color emoji) +- **Special:** OpenMoji, Twemoji + +**Note:** Default font packages disabled to allow user selection via home-manager + +--- + +## ๐Ÿ› ๏ธ Installation Guide + +### Prerequisites + +1. **NixOS System** (latest stable or unstable) +2. **Git** and **sudo** access +3. **Internet connection** for package downloads +4. **Disk space:** Minimum 30GB recommended for full installation +5. **UEFI system** (systemd-boot requirement) + +### Installation Steps + +#### Step 1: Clone the Repository + +```bash +# Recommended location for NixOS configurations +git clone https://gitea.doomlabs.de/KptltD00M/nixy.git /etc/nixos +cd /etc/nixos +``` + +#### Step 2: Copy Appropriate Host Configuration + +```bash +# Choose your hardware profile: +# - Laptop (AMD/Nvidia) +# - Home workstation +# - Work computer +# - Server + +# For example, if setting up a laptop: +cp -r hosts/laptop hosts/$(hostname) + +# Navigate to new host configuration +cd hosts/$(hostname) +``` + +#### Step 3: Configure Host-Specific Variables + +```bash +# Edit host variables +nano variables.nix +``` + +**Change `CHANGEME` values:** +- `hostname` +- `username` +- `keyboardLayout` +- `timeZone` +- `defaultLocale` + +#### Step 4: Set Up Secrets + +```bash +# Either: +# Option A: Use SOPS-nix for encrypted secrets (recommended) +pdo export secrets/ > secrets/secrets.yaml.age +../../bin/update-secrets + +# Option B: Manual secrets +# Copy secrets template if needed +cp -r hosts/laptop/secrets hosts/$(hostname)/secrets +``` + +#### Step 5: Review and Apply Configuration + +1. **Check for CHANGEME comments:** +```bash +# Quick scan for required changes +rg "CHANGEME" /etc/nixos +``` + +2. **Verify hardware configuration:** +```bash +# Import appropriate GPU module in configuration.nix +# - AMD: ../../nixos/amd-graphics.nix +# - Nvidia: ../../nixos/nvidia.nix +# - HP Omen: ../../nixos/omen.nix +``` + +3. **Apply configuration:** +```bash +# Dry run first +sudo nixos-rebuild dry-activate --flake .#$(hostname) + +# Apply +sudo nixos-rebuild switch --flake .#$(hostname) +``` + +#### Step 6: Home-manager Setup + +```bash +# Update home-manager configuration +home-manager switch --flake /etc/nixos#$(username)@$(hostname) + +# Optional: Generate hardware configuration if rebuilding from scratch +sudo nixos-generate-config --root /mnt +``` + +--- + +## ๐Ÿ”ง Usage & Maintenance + +### Daily Commands + +| Command | Purpose | +|---------|---------| +| `sudo nixos-rebuild switch --flake .#laptop` | Rebuild and apply system changes | +| `home-manager switch --flake .#hadi@laptop` | Update home-manager configuration | +| `sudo nixos-rebuild boot --flake .#laptop` | Set new generation as default boot | +| `nix flake update` | Update flake inputs | +| `sudo nixos-rebuild switch --upgrade` | Update system and packages | +| `nix store gc` | Cleanup unused packages | +| `nix profile list` | List installed packages | +| `nix profile wipe-history` | Remove old package versions | + +### Flake Update Process + +```bash +# Update all flake inputs +nix flake update + +# Rebuild all systems +for host in h-laptop h-work jack; do + sudo nixos-rebuild switch --flake .#$host +done + +# Update home-manager +for host in h-laptop h-work jack; do + home-manager switch --flake .#username@$host +done +``` + +### System Updates + +**Automatic Updates Enabled:** +```nix +system.autoUpgrade = { + enable = true; # System updates + dates = "04:00"; # Daily at 4 AM + flake = config.var.configDir; # Self-update + flags = ["--update-input" "nixpkgs"]; + allowReboot = false; # Manual reboot required +}; +``` + +**Recommendation:** Check system status weekly: +```bash +systemctl status --user wireplumber pulseaudio-esd autostart-vpn +journalctl --vacuum-time=7d +``` + +--- + +## ๐Ÿ’ก Troubleshooting + +### Common Issues & Solutions + +#### โŒ Audio not working + +**Diagnosis:** +- PipeWire service status +- WirePlumber activity +- Audio device detection + +**Solutions:** +```bash +# Check PipeWire status +systemctl --user status wireplumber pulseaudio-esd + +# Verify audio devices +pw-cli list-objects | grep -i audio + +# Restart audio services +systemctl --user restart wireplumber +``` + +--- + +#### โŒ Hyprland fails to start + +**Symptoms:** +- Black screen after login +- Wayland session crash +- Missing display manager + +**Diagnosis:** +- XDG_RUNTIME_DIR environment +- PipeWire running +- Required files present + +**Solutions:** +```bash +# Check environment +echo $XDG_RUNTIME_DIR +whoami # Should be logged-in user + +# Verify services +systemctl --way status +ls /run/current-system/sw/share/wayland-sessions/ +``` + +**Manual start:** +```bash +$XDG_RUNTIME_DIR=/run/user/$(id -u) Hyprland +``` + +--- + +#### โŒ Nvidia drivers not loading + +**Diagnostics:** +- Kernel parameters check +- Secure boot status +- Driver conflicts + +**Common fixes:** +```bash +# Check kernel parameters +cat /proc/cmdline | grep nvidia + +# Verify module loading +lsmod | grep nvidia + +# Blacklist nouveau (if not already done) +echo "blacklist nouveau" | sudo tee /etc/modprobe.d/blacklist-nouveau.conf +sudo update-initramfs -u -k all +``` + +**Secure boot workaround (if enabled):** +- Disable secure boot in BIOS +- Or sign Nvidia modules + +--- + +#### โš ๏ธ Home-manager not applying changes + +**Solutions:** +```bash +# Check home-manager configuration +home-manager build --flake /etc/nixos#username@hostname --show-trace +home-manager generations + +# Force fresh rebuild +rm -rf ~/.local/share/nix/profiles/home-manager +home-manager switch --flake /etc/nixos#username@hostname +``` + +--- + +#### ๐Ÿ”„ USB devices blocked by USBGuard + +**Diagnosis:** +- USBGuard service status +- Policy decisions + +**Solutions:** +```bash +# Check USBGuard status +systemctl status usbguard + +# List USB devices +lsusb + +# Temporarily allow device +usbguard list-devices +usbguard allow-device +``` + +**Configuration:** Edit `/etc/usbguard/rules.conf` for permanent changes + +--- + +### System Recovery + +**If system fails to boot:** +1. Reboot into recovery ISO +2. Remount root partition +3. Apply configuration: +```bash +sudo nixos-rebuild switch --flake /etc/nixos#hostname +``` + +**If home-manager breaks:** +```bash +# Reinstall from scratch +home-manager uninstall +home-manager switch --flake /etc/nixos#username@hostname +``` + +--- +## ๐Ÿ“š Further Reading & Resources + +### NixOS Documentation +- **[NixOS Manual](https://nixos.org/manual/nixos/stable/)** - Official NixOS documentation +- **[Nix Flakes Guide](https://nixos.wiki/wiki/Flakes)** - Flakes feature documentation +- **[Home Manager Manual](https://nix-community.github.io/home-manager/)** - User-level configuration + +### Related Projects +- **[Hyprland](https://wiki.hyprland.org/)** - Wayland compositor +- **[Stylix](https://stylix.danth.me/)** - Theming system +- **[Caelestia Shell](https://github.com/caelestia-dots/shell)** - Desktop environment +- **[SOPS-nix](https://github.com/Mic92/sops-nix)** - Secret management +- **[Helium Browser](https://github.com/oxcl/nix-flake-helium-browser)** - Flutter-based browser + +### Repository Documentation +- **[GROUPS.md](docs/GROUPS.md)** - Package groups (dev, cybersecurity) and how to use them +- **[SERVER.md](docs/SERVER.md)** - Server-specific service configurations +- **[NEOVIM.md](docs/NEOVIM.md)** - Neovim configuration (nvf) +- **[THEMES.md](docs/THEMES.md)** - Theme system and color schemes +- **[CONTRIBUTING.md](docs/CONTRIBUTING.md)** - Contribution guidelines + +### Useful Commands Reference +```bash +# Show generation history +sudo nix-env --list-generations + +# Switch to specific generation +sudo nixos-rebuild switch --flake .#laptop --profile /nix/var/nix/profiles/system- + +# Rollback to previous generation +sudo nix-env --rollback +sudo nixos-rebuild switch + +# Clean old generations (keep 5 latest) +sudo nix-collect-garbage -d +sudo nix-env --delete-generations old +``` + +--- \ No newline at end of file diff --git a/flake.nix b/flake.nix index a35bc0a..03dec01 100644 --- a/flake.nix +++ b/flake.nix @@ -66,11 +66,34 @@ (import ./home/programs/group/flake.nix args) (import ./home/programs/nixy/flake.nix args) { + # Modern app output with metadata + apps.${system} = { + default = { + type = "app"; + program = "${pkgs.neovim}/bin/nvim"; + meta = { + description = "Improved Vim-based text editor"; + homepage = "https://neovim.io"; + license = "Apache-2.0"; + }; + }; + }; + + # Formatter output formatter.${system} = pkgs.alejandra; + + # Update to modern syntax (no defaultApp) + # Add homeManagerModules output for proper Home Manager integration + #homeManagerModules = { + # dev = import ./home/programs/group/dev.nix { inherit inputs nixpkgs system; }; + # cybersecurity = import ./home/programs/group/cybersecurity.nix { inherit inputs nixpkgs system; }; + # basic-apps = import ./home/programs/group/basic-apps.nix { inherit inputs nixpkgs system; }; + # misc = import ./home/programs/group/misc.nix { inherit inputs nixpkgs system; }; + #}; + nixosConfigurations = { - h-laptop = import ./hosts/laptop/flake.nix args; - h-work = import ./hosts/work/flake.nix args; - jack = import ./hosts/server/flake.nix args; + thinkpad = import ./hosts/laptop/flake.nix args; + home-pc = import ./hosts/home-pc/flake.nix args; }; } ]; diff --git a/home/programs/group/basic-apps.nix b/home/programs/group/basic-apps.nix index e9394fd..1c5a5b2 100644 --- a/home/programs/group/basic-apps.nix +++ b/home/programs/group/basic-apps.nix @@ -4,19 +4,13 @@ pkgs-nur-hadi, ... }: { - home.packages = with pkgs-stable; [ - vlc # Video player + home.packages = (with pkgs-stable; [ + + vlc # Video player obsidian # Note taking app - textpieces # Manipulate texts - resources # Ressource monitor - gnome-clocks # Clocks app - gnome-text-editor # Basic graphic text editor + ticktick # Todo app - pinta # Image editor - switcheroo # Convert images between different formats onlyoffice-desktopeditors # Office suite - blanket # Listen to different sounds - signal-desktop # Messaging app librewolf # Backup browser # I love TUIs @@ -27,19 +21,40 @@ tealdeer # Fast tldr client sttr # Minimalist "cyberchef" like. Cross-platform, cli app to perform various operations on string wiremix # Simple TUI mixer for PipeWire - slides # A terminal-based presentation tool that allows you to create and deliver presentations directly from the command line + pom # Pomodoro timer in your terminal pkgs.wifitui # TUI for managing wifi pkgs-nur-hadi.usbguard-tui # TUI for managing USBGuard rules - pkgs-nur-hadi.sheets # Terminal based spreadsheet tool + # I love CLIs httpie # Command-line HTTP client, a user-friendly cURL replacement - gh # GitHub - gh-dash # A terminal dashboard for GitHub - figlet # Transform text into ASCII art pastel # Command-line tool to generate, analyze, convert and manipulate colors imagemagick # Image manipulation tool chafa # Image to ANSI/Unicode converter and more. - ]; + + /* + Disabled + resources # Ressource monitor + + textpieces # Manipulate texts + gnome-clocks # Clocks app + gnome-text-editor # Basic graphic text editor + pinta # Image editor + switcheroo # Convert images between different formats + signal-desktop # Messaging app + + blanket # Listen to different sounds + gh # GitHub + gh-dash # A terminal dashboard for GitHub + figlet # Transform text into ASCII art + pkgs-nur-hadi.sheets # Terminal based spreadsheet tool + slides # A terminal-based presentation tool that allows you to create and deliver presentations directly from the command line + */ + + ]) + + ++ (with pkgs; [ + vencord # Vencord Discord Mod + ]); } diff --git a/home/programs/group/dev-packages.nix b/home/programs/group/dev-packages.nix index cd2701e..9100daa 100644 --- a/home/programs/group/dev-packages.nix +++ b/home/programs/group/dev-packages.nix @@ -4,14 +4,16 @@ }: (with pkgs; [ go - claude-code + zig + + zed-editor #Zed + vscodium # VS Code ]) ++ (with pkgs-stable; [ - nodejs - air - duckdb + bun python3 jq - nix-prefetch-github rsync + rustc + cargo ]) diff --git a/home/programs/group/misc.nix b/home/programs/group/misc.nix index 436a462..9e57061 100644 --- a/home/programs/group/misc.nix +++ b/home/programs/group/misc.nix @@ -5,12 +5,9 @@ ... }: { home.packages = with pkgs-stable; [ - tty-solitaire - bastet peaclock cbonsai pipes - cmatrix fastfetch ]; } diff --git a/home/programs/nvf/flake.nix b/home/programs/nvf/flake.nix index b9fdd4f..a9e3354 100644 --- a/home/programs/nvf/flake.nix +++ b/home/programs/nvf/flake.nix @@ -19,13 +19,25 @@ in { packages.${system}.nvim = nvimConfig.neovim; - apps.${system}.nvim = { - type = "app"; - program = "${nvimConfig.neovim}/bin/nvim"; - }; - defaultApp.${system} = { - type = "app"; - program = "${nvimConfig.neovim}/bin/nvim"; + apps.${system} = { + nvim = { + type = "app"; + program = "${nvimConfig.neovim}/bin/nvim"; + meta = { + description = "Improved Vim-based text editor"; + homepage = "https://neovim.io"; + license = "Apache-2.0"; + }; + }; + default = { + type = "app"; + program = "${nvimConfig.neovim}/bin/nvim"; + meta = { + description = "Improved Vim-based text editor"; + homepage = "https://neovim.io"; + license = "Apache-2.0"; + }; + }; }; homeManagerModules.nvim = { diff --git a/home/programs/steam/default.nix b/home/programs/steam/default.nix new file mode 100644 index 0000000..06fe77b --- /dev/null +++ b/home/programs/steam/default.nix @@ -0,0 +1,27 @@ +{ + pkgs, + ... +}: { + home.packages = with pkgs; [ + steam + protonup-ng + ]; + + xdg.desktopEntries = { + Steam = { + name = "Steam"; + exec = "${pkgs.steam}/bin/steam"; + icon = "steam"; + type = "Application"; + categories = [ + "Game" + "Network" + ]; + terminal = false; + }; + }; + + home.sessionVariables = { + STEAM_FORCE_DESKTOPUI_SCALING = "1.25"; + }; +} diff --git a/home/programs/steam/system.nix b/home/programs/steam/system.nix new file mode 100644 index 0000000..6e0ab4a --- /dev/null +++ b/home/programs/steam/system.nix @@ -0,0 +1,13 @@ +{ ... }: { + # Steam runtime tweaks (user-session level, not NixOS system config) + + home.sessionVariables = { + # Improves scaling consistency on HiDPI / Wayland setups + STEAM_FORCE_DESKTOPUI_SCALING = "1.25"; + + # Optional Proton-related behavior toggles (safe defaults) + PROTON_ENABLE_NVAPI = "1"; + PROTON_NO_ESYNC = "0"; + PROTON_NO_FSYNC = "0"; + }; +} diff --git a/home/programs/zen/default.nix b/home/programs/zen/default.nix new file mode 100644 index 0000000..aa6e653 --- /dev/null +++ b/home/programs/zen/default.nix @@ -0,0 +1,62 @@ +{ + pkgs, + lib, + config, + ... +}: +{ + programs.zen-browser = { + enable = true; + + policies = { + DisableTelemetry = true; + DisableFirefoxStudies = true; + DisablePocket = true; + + OfferToSaveLogins = false; + PasswordManagerEnabled = false; + + AutofillAddressEnabled = false; + AutofillCreditCardEnabled = false; + + DontCheckDefaultBrowser = true; + + DNSOverHTTPS = { + Enabled = true; + ProviderURL = "https://dns.quad9.net/dns-query"; + Locked = true; + }; + }; + + profiles.default = { + search = { + force = true; + default = "Startpage"; + }; + + settings = { + "browser.startup.homepage" = "https://duckduckgo.com"; + + "browser.newtabpage.enabled" = false; + + "privacy.resistFingerprinting" = true; + "privacy.trackingprotection.enabled" = true; + + "geo.enabled" = false; + "dom.webnotifications.enabled" = false; + + "signon.rememberSignons" = false; + + "toolkit.telemetry.enabled" = false; + }; + + extensions.packages = with pkgs.nur.repos.rycee.firefox-addons; [ + ublock-origin + firefox-multi-account-containers + noscript + ]; + }; + }; + + home.sessionVariables.BROWSER = "zen"; +} diff --git a/home/programs/zen/system.nix b/home/programs/zen/system.nix new file mode 100644 index 0000000..e0a75a7 --- /dev/null +++ b/home/programs/zen/system.nix @@ -0,0 +1,24 @@ +{ + programs.zen-browser = { + enable = true; + + policies = { + DisableTelemetry = true; + DisableFirefoxStudies = true; + + OfferToSaveLogins = false; + PasswordManagerEnabled = false; + + DNSOverHTTPS = { + Enabled = true; + ProviderURL = "https://dns.quad9.net/dns-query"; + Locked = true; + }; + + Homepage = { + URL = "https://duckduckgo.com"; + StartPage = "homepage"; + }; + }; + }; +} diff --git a/home/system/hyprland/bindings.nix b/home/system/hyprland/bindings.nix index 2da3577..526c782 100644 --- a/home/system/hyprland/bindings.nix +++ b/home/system/hyprland/bindings.nix @@ -53,12 +53,12 @@ in { { key = "c"; desc = "Proton Calendar"; - cmd = "${config.programs.helium.package}/bin/helium 'https://calendar.proton.me/'"; + cmd = "${config.programs.librewolf.package}/bin/helium 'https://calendar.proton.me/'"; } { key = "m"; desc = "Proton Mail"; - cmd = "${config.programs.helium.package}/bin/helium 'https://mail.proton.me/'"; + cmd = "${config.programs.librewolf.package}/bin/helium 'https://mail.proton.me/'"; } { key = "o"; @@ -78,17 +78,17 @@ in { { key = "b"; desc = "Helium"; - cmd = "${config.programs.helium.package}/bin/helium"; + cmd = "${config.programs.librewolf.package}/bin/helium"; } { key = "i"; desc = "Helium (Incognito)"; - cmd = "${config.programs.helium.package}/bin/helium --incognito"; + cmd = "${config.programs.librewolf.package}/bin/helium --incognito"; } ]) ) - "$mod,B, exec, uwsm app -- ${config.programs.helium.package}/bin/helium" # Browser + "$mod,B, exec, uwsm app -- ${config.programs.librewolf.package}/bin/helium" # Browser # Power "$mod, X, global, caelestia:session" # Powermenu diff --git a/hosts/home-pc/configuration.nix b/hosts/home-pc/configuration.nix new file mode 100644 index 0000000..8ac5152 --- /dev/null +++ b/hosts/home-pc/configuration.nix @@ -0,0 +1,29 @@ +{config, ...}: { + imports = [ + # Mostly system related configuration + ../../nixos/audio.nix + ../../nixos/bluetooth.nix + ../../nixos/fonts.nix + ../../nixos/home-manager.nix + ../../nixos/nix.nix + ../../nixos/systemd-boot.nix + ../../nixos/tuigreet.nix + ../../nixos/usbguard.nix + ../../nixos/users.nix + ../../nixos/utils.nix + ../../nixos/hyprland.nix + + ../../nixos/amd-graphics.nix + + ../../nixos/steam.nix + + # You should let those lines as is + ./hardware-configuration.nix + ./variables.nix + ]; + + home-manager.users."${config.var.username}" = import ./home.nix; + services.flatpak.enable = true; + # Don't touch this + system.stateVersion = "24.05"; +} diff --git a/hosts/home-pc/flake.nix b/hosts/home-pc/flake.nix new file mode 100644 index 0000000..963a5c2 --- /dev/null +++ b/hosts/home-pc/flake.nix @@ -0,0 +1,18 @@ +{ + inputs, + nixpkgs, + ... +}: +nixpkgs.lib.nixosSystem { + modules = [ + { + nixpkgs.overlays = []; + _module.args = {inherit inputs;}; + } + inputs.home-manager.nixosModules.home-manager + inputs.stylix.nixosModules.stylix + inputs.nix-index-database.nixosModules.default + inputs.helium-browser.nixosModules.default + ./configuration.nix + ]; +} diff --git a/hosts/home-pc/hardware-configuration.nix b/hosts/home-pc/hardware-configuration.nix new file mode 100644 index 0000000..dfcd5db --- /dev/null +++ b/hosts/home-pc/hardware-configuration.nix @@ -0,0 +1,45 @@ +# Do not modify this file! It was generated by โ€˜nixos-generate-configโ€™ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ + config, + lib, + pkgs, + modulesPath, + ... +}: { + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ + "xhci_pci" + "ahci" + "nvme" + "usb_storage" + "usbhid" + "sd_mod" + ]; + boot.initrd.kernelModules = []; + boot.kernelModules = ["kvm-amd"]; + boot.extraModulePackages = []; + + fileSystems."/" = { + device = "/dev/disk/by-uuid/5dbf85d3-d236-4af8-b489-d6066bfe1eb7"; + fsType = "ext4"; + }; + + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/043E-1755"; + fsType = "vfat"; + options = [ + "fmask=0077" + "dmask=0077" + ]; + }; + + swapDevices = []; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/hosts/home-pc/home.nix b/hosts/home-pc/home.nix new file mode 100644 index 0000000..0f68e87 --- /dev/null +++ b/hosts/home-pc/home.nix @@ -0,0 +1,55 @@ +{config, ...}: { + imports = [ + # Programs + ../../home/programs/ghostty + ../../home/programs/nvf + ../../home/programs/shell + ../../home/programs/git + ../../home/programs/git/lazygit.nix + ../../home/programs/thunar + ../../home/programs/nixy + ../../home/programs/nightshift + ../../home/programs/nix-utils + ../../home/programs/spotatui + ../../home/programs/yazi + ../../home/programs/steam + + ../../home/programs/group/basic-apps.nix + ../../home/programs/group/dev.nix + ../../home/programs/group/misc.nix + + # System (Desktop environment like stuff) + ../../home/system/hyprland + ../../home/system/caelestia-shell + ../../home/system/hyprpaper + ../../home/system/mime + ../../home/system/udiskie + + ./variables.nix # Mostly user-specific configuration + #./secrets # CHANGEME: You should probably remove this line, this is where I store my secrets + ]; + + home = { + inherit (config.var) username; + homeDirectory = "/home/" + config.var.username; + file.".face" = { + source = ./profile_picture.jpg; + }; + + # Don't touch this + stateVersion = "24.05"; + }; + + wayland.windowManager.hyprland.settings.monitor = [ + "DP-3,1920x1080@144.0,1920x0,1.0" + "HDMI-A-1,1920x1080@60.0,0x0,1.0" + ]; + + programs = { + home-manager.enable = true; + nixy = { + enable = true; + configDirectory = config.var.configDirectory; + }; + }; +} diff --git a/hosts/home-pc/profile_picture.jpg b/hosts/home-pc/profile_picture.jpg new file mode 100644 index 0000000..a0f4294 Binary files /dev/null and b/hosts/home-pc/profile_picture.jpg differ diff --git a/hosts/home-pc/variables.nix b/hosts/home-pc/variables.nix new file mode 100644 index 0000000..5bbad51 --- /dev/null +++ b/hosts/home-pc/variables.nix @@ -0,0 +1,38 @@ +{ + config, + lib, + ... +}: { + imports = [ + # Choose your theme here: + ../../themes/nixy.nix + ]; + + config.var = { + hostname = "home-pc"; + username = "andi"; + configDirectory = "/home/" + config.var.username + "/.config/nixos"; # The path of the nixos configuration directory + + keyboardLayout = "de"; + + timeZone = "Europe/Berlin"; + defaultLocale = "de_DE.UTF-8"; + extraLocale = "en_EN.UTF-8"; + + git = { + username = "kptltd00m"; + email = "kptltd00m.doomlabs.de"; + }; + + autoUpgrade = false; + autoGarbageCollector = true; + }; + + # DON'T TOUCH THIS + options = { + var = lib.mkOption { + type = lib.types.attrs; + default = {}; + }; + }; +} diff --git a/hosts/laptop/configuration.nix b/hosts/laptop/configuration.nix index f333438..b7e5f18 100644 --- a/hosts/laptop/configuration.nix +++ b/hosts/laptop/configuration.nix @@ -1,58 +1,29 @@ -{config, ...}: { - imports = [ - # Mostly system related configuration - ../../nixos/nvidia.nix # CHANGEME: Remove this line if you don't have an Nvidia GPU - ../../nixos/audio.nix - ../../nixos/bluetooth.nix - ../../nixos/fonts.nix - ../../nixos/home-manager.nix - ../../nixos/nix.nix - ../../nixos/systemd-boot.nix - ../../nixos/tuigreet.nix - ../../nixos/users.nix - ../../nixos/utils.nix - ../../nixos/hyprland.nix - ../../nixos/usbguard.nix - ../../home/programs/helium/system.nix # I hate browser's configuration.. +{ config, ... }: - ../../nixos/omen.nix # CHANGEME: For my laptop only, remove this (OMEN 16) +{ +imports = [ +# System configuration +../../nixos/audio.nix +../../nixos/bluetooth.nix +../../nixos/fonts.nix +../../nixos/home-manager.nix +../../nixos/nix.nix +../../nixos/systemd-boot.nix +../../nixos/tuigreet.nix +../../nixos/users.nix +../../nixos/utils.nix +../../nixos/hyprland.nix - # You should let those lines as is - ./hardware-configuration.nix - ./variables.nix - ]; +../../nixos/steam.nix - # USBGuard: - # Allow all USB devices until a proper policy is configured. - # Run `sudo usbguard generate-policy` with your devices plugged in, - # then set rules = "" and switch implicitPolicyTarget to "block". - # services.usbguard.implicitPolicyTarget = lib.mkForce "allow"; +# Machine-specific files +./hardware-configuration.nix +./variables.nix - services.usbguard.rules = '' - allow id 1d6b:0002 serial "0000:05:00.3" name "xHCI Host Controller" hash "4a4NgfdUaJO43rkCzmWRSeHHR/uUh5+SNsXnhosm9qs=" parent-hash "ldMchY4Tt4GPUYo30eNGvai+Fs/EdnVY3vMyxJUq4Nk=" with-interface 09:00:00 with-connect-type "" - allow id 1d6b:0003 serial "0000:05:00.3" name "xHCI Host Controller" hash "d+DNGWARDtv9nEK2ZvnNOCtFernuMu5/e/oZ7kCppqQ=" parent-hash "ldMchY4Tt4GPUYo30eNGvai+Fs/EdnVY3vMyxJUq4Nk=" with-interface 09:00:00 with-connect-type "" - allow id 1d6b:0002 serial "0000:05:00.4" name "xHCI Host Controller" hash "icotY3rI59mWiKsGxc59BGZZeBjfbuH0b4NUByj3cbQ=" parent-hash "tHvBfznK5rpQn+oa0PEEjHa29EAEvGyCcZixsfwA6W0=" with-interface 09:00:00 with-connect-type "" - allow id 1d6b:0003 serial "0000:05:00.4" name "xHCI Host Controller" hash "UbEoCZW8HT2ldc3qDeiK+IiQlGeaBC7F63681OwmKhI=" parent-hash "tHvBfznK5rpQn+oa0PEEjHa29EAEvGyCcZixsfwA6W0=" with-interface 09:00:00 with-connect-type "" - allow id 1d6b:0002 serial "0000:07:00.3" name "xHCI Host Controller" hash "pz29Oo0RhQ+5+7LgOZR4v3OlcsVv3m9kCgGsGUnoUjI=" parent-hash "DRyV2/31MYHdzkIEfbPQeb/1w4/PjOW6GqWrXkftf2I=" with-interface 09:00:00 with-connect-type "" - allow id 1d6b:0003 serial "0000:07:00.3" name "xHCI Host Controller" hash "O6iOpcl9StImWT62SrbeXacqbG6N/mTIipTRc0ipCGM=" parent-hash "DRyV2/31MYHdzkIEfbPQeb/1w4/PjOW6GqWrXkftf2I=" with-interface 09:00:00 with-connect-type "" - allow id 1d6b:0002 serial "0000:07:00.4" name "xHCI Host Controller" hash "Hp8B0Enf+ACRT2tyy0EqXj7eNsFDAnTRZadzuh/Iqd4=" parent-hash "l2vhvC+VGVKlkBUUK/usFu8jHJ/5bWOnJG6WzRexpt4=" with-interface 09:00:00 with-connect-type "" - allow id 1d6b:0003 serial "0000:07:00.4" name "xHCI Host Controller" hash "rJ3LKdvkCK3SUrCU3lV8qVbmPjA+r9Fe5106x2HlgK4=" parent-hash "l2vhvC+VGVKlkBUUK/usFu8jHJ/5bWOnJG6WzRexpt4=" with-interface 09:00:00 with-connect-type "" - allow id 0bda:c85c serial "00e04c000001" name "Bluetooth Radio" hash "Q/wlToV8WQgEYHBW/UIhnSwCCusCGqAR2D5gspSCImQ=" parent-hash "4a4NgfdUaJO43rkCzmWRSeHHR/uUh5+SNsXnhosm9qs=" with-interface { e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 } with-connect-type "hardwired" - allow id 30c9:009f serial "01.00.00" name "HP True Vision FHD Camera" hash "eYW5fqReJd29tfHXkEktKC63dGfDpmlRMo5uMGUWwME=" parent-hash "icotY3rI59mWiKsGxc59BGZZeBjfbuH0b4NUByj3cbQ=" with-interface { 0e:01:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 fe:01:01 } with-connect-type "hardwired" - allow id 03f0:036b serial "" name "HP USB-C Dock G5" hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" parent-hash "Hp8B0Enf+ACRT2tyy0EqXj7eNsFDAnTRZadzuh/Iqd4=" via-port "7-1" with-interface { 09:00:01 09:00:02 } with-connect-type "hotplug" - allow id 03f0:066b serial "" name "HP USB-C Dock G5" hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" parent-hash "rJ3LKdvkCK3SUrCU3lV8qVbmPjA+r9Fe5106x2HlgK4=" via-port "8-1" with-interface 09:00:00 with-connect-type "hotplug" - allow id 03f0:056b serial "201604140001" name "USB Audio" hash "OxQ8HQenW3/4HSGEBOSYFS15rXDTOaNDnjMbICweHgw=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" with-interface { 01:01:00 01:02:00 01:02:00 01:02:00 01:02:00 03:00:00 } with-connect-type "unknown" - allow id 03f0:086b serial "" name "USB2734" hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" via-port "7-1.3" with-interface { 09:00:01 09:00:02 } with-connect-type "unknown" - allow id 03f0:046b serial "11AD1D0A89EA2D08310E0B00" name "HP USB-C Dock G5" hash "DEGeuj1u4lwqrzp0UksFX7mSEY9JnGLxg7yxGbglAKE=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" with-interface { 11:00:00 ff:03:00 03:00:00 } with-connect-type "unknown" - allow id 03f0:076b serial "" name "USB5734" hash "BshoqybYo0IKgoDORYPRtbhhlmQrYAxPQb2EAm1JsWA=" parent-hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" via-port "8-1.3" with-interface 09:00:00 with-connect-type "unknown" - allow id 0bda:8153 serial "000001000000" name "USB 10/100/1000 LAN" hash "utEnXKJ57kRUbPcGUaNWhEyoOEbLOYAFxvlsyC0PZkk=" parent-hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" with-interface { ff:ff:00 02:06:00 0a:00:00 0a:00:00 } with-connect-type "unknown" - allow id 046d:0ab7 serial "2046BAB04T68" name "Blue Microphones" hash "cC6AQ2e1Q/BeFeostpbf1mH2WpoUmt6bhau4NlA3niU=" parent-hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" with-interface { 01:01:00 01:02:00 01:02:00 01:02:00 01:02:00 01:02:00 01:02:00 03:00:00 } with-connect-type "unknown" - allow id 1532:02a1 serial "" name "Razer Ornata V3" hash "wfuIjBhhGuge8gflyA526SKqKoy8rHJZQZ+2o6usMiE=" parent-hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" via-port "7-1.3.3" with-interface { 03:01:01 03:00:01 03:00:02 } with-connect-type "unknown" - allow id 13fd:5900 serial "50026B76861EE752 " name "External" hash "l/QvVV5hzZj1z6OUwB/kWl+WnH/7awrdMBoiNVx660M=" parent-hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" with-interface { 08:06:50 08:06:62 } with-connect-type "unknown" - ''; +]; - home-manager.users."${config.var.username}" = import ./home.nix; +home-manager.users."${config.var.username}" = import ./home.nix; +services.flatpak.enable = true; - # Don't touch this - system.stateVersion = "24.05"; +system.stateVersion = "24.05"; } diff --git a/hosts/laptop/flake.nix b/hosts/laptop/flake.nix index 916c6e7..1e74f53 100644 --- a/hosts/laptop/flake.nix +++ b/hosts/laptop/flake.nix @@ -3,18 +3,44 @@ nixpkgs, ... }: + nixpkgs.lib.nixosSystem { modules = [ { - nixpkgs.overlays = [ - ]; - _module.args = {inherit inputs;}; + nixpkgs.overlays = []; + _module.args = { + inherit inputs; + }; } - inputs.nixos-hardware.nixosModules.omen-16-n0005ne + + ({ config, pkgs, lib, ... }: { + # Intel microcode + hardware.cpu.intel.updateMicrocode = true; + + # Graphics support + hardware.graphics = { + enable = true; + enable32Bit = true; + }; + + # Power management + powerManagement.cpuFreqGovernor = "powersave"; + services.tlp.enable = true; + services.power-profiles-daemon.enable = false; + + # Kernel modules commonly needed on ThinkPads + boot.kernelModules = [ + "i915" + "snd_hda_intel" + "iwlwifi" + ]; + }) + inputs.home-manager.nixosModules.home-manager inputs.stylix.nixosModules.stylix inputs.nix-index-database.nixosModules.default inputs.helium-browser.nixosModules.default + ./configuration.nix ]; } diff --git a/hosts/laptop/hardware-configuration.nix b/hosts/laptop/hardware-configuration.nix index e2b649e..635bb8b 100644 --- a/hosts/laptop/hardware-configuration.nix +++ b/hosts/laptop/hardware-configuration.nix @@ -1,52 +1,35 @@ # Do not modify this file! It was generated by โ€˜nixos-generate-configโ€™ # and may be overwritten by future invocations. Please make changes # to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + { - config, - lib, - modulesPath, - ... -}: { - imports = [ - (modulesPath + "/installer/scan/not-detected.nix") - ]; - - boot.initrd.availableKernelModules = [ - "nvme" - "xhci_pci" - "uas" - "usbhid" - "sd_mod" - ]; - boot.initrd.kernelModules = []; - boot.kernelModules = ["kvm-amd"]; - boot.extraModulePackages = []; - - fileSystems."/" = { - device = "/dev/disk/by-uuid/6320d3c6-0231-45ec-817a-c6f0e39aab73"; - fsType = "ext4"; - }; - - fileSystems."/boot" = { - device = "/dev/disk/by-uuid/5251-9B85"; - fsType = "vfat"; - options = [ - "fmask=0077" - "dmask=0077" + imports = + [ (modulesPath + "/installer/scan/not-detected.nix") ]; + + boot.initrd.availableKernelModules = [ "xhci_pci" "thunderbolt" "nvme" "usb_storage" "sd_mod" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.extraModulePackages = [ ]; + + # Root filesystem configuration - REQUIRED for NixOS installation + fileSystems."/" = { + device = "/dev/disk/by-uuid/dabf7455-d7e7-4764-8cb2-c7bb912e763f"; + fsType = "btrfs"; }; - swapDevices = []; + # Boot partition configuration - REQUIRED for EFI systems + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/F6E8-6DF5"; + fsType = "vfat"; + options = [ "fmask=0077" "dmask=0077" ]; + }; - # Enables DHCP on each ethernet and wireless interface. In case of scripted networking - # (the default) this is the recommended approach. When using systemd-networkd it's - # still possible to use this option, but it's recommended to use it in conjunction - # with explicit per-interface declarations with `networking.interfaces..useDHCP`. - networking.useDHCP = lib.mkDefault true; - # networking.interfaces.eno1.useDHCP = lib.mkDefault true; - # networking.interfaces.enp7s0f4u1u4.useDHCP = lib.mkDefault true; - # networking.interfaces.wlo1.useDHCP = lib.mkDefault true; + swapDevices = + [ { device = "/dev/disk/by-uuid/d9df86d6-3e7b-42f5-b8f4-bae56b7adcb3"; } + ]; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; - hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; } diff --git a/hosts/laptop/home.nix b/hosts/laptop/home.nix index 4ed5f33..7b53a2b 100644 --- a/hosts/laptop/home.nix +++ b/hosts/laptop/home.nix @@ -1,24 +1,20 @@ {config, ...}: { imports = [ # Programs - ../../home/programs/helium - ../../home/programs/proton - ../../home/programs/proton/auto-start-vpn.nix ../../home/programs/ghostty ../../home/programs/nvf ../../home/programs/shell ../../home/programs/git ../../home/programs/git/lazygit.nix - ../../home/programs/git/signing.nix # CHANGEME: Change the key or remove this file ../../home/programs/thunar ../../home/programs/nixy ../../home/programs/nightshift ../../home/programs/nix-utils ../../home/programs/spotatui ../../home/programs/yazi + ../../home/programs/steam ../../home/programs/group/basic-apps.nix - ../../home/programs/group/cybersecurity.nix ../../home/programs/group/dev.nix ../../home/programs/group/misc.nix @@ -30,18 +26,19 @@ ../../home/system/udiskie ./variables.nix # Mostly user-specific configuration - ./secrets # CHANGEME: You should probably remove this line, this is where I store my secrets + #./secrets # CHANGEME: You should probably remove this line, this is where I store my secrets ]; home = { inherit (config.var) username; homeDirectory = "/home/" + config.var.username; file.".face" = { - source = ./profile_picture.png; + source = ./profile_picture.jpg; }; sessionVariables = { - AQ_DRM_DEVICES = "/dev/dri/card2:/dev/dri/card1"; # CHANGEME: Related to the GPU + # Graphics devices for Intel Iris Xe Graphics + # AQ_DRM_DEVICES = "/dev/dri/card0"; # Single GPU configuration }; # Don't touch this @@ -49,8 +46,7 @@ }; wayland.windowManager.hyprland.settings.monitor = [ - "eDP-2,highres,0x0,1" # My internal laptop screen - "desc:AOC U34G2G1 0x00000E06,3440x1440@99.98,auto,1" # My external monitor + "eDP-1,1920x1080,0x0,1.5" # My internal laptop screen ]; programs = { diff --git a/hosts/laptop/profile_picture.jpg b/hosts/laptop/profile_picture.jpg new file mode 100644 index 0000000..a0f4294 Binary files /dev/null and b/hosts/laptop/profile_picture.jpg differ diff --git a/hosts/laptop/profile_picture.png b/hosts/laptop/profile_picture.png deleted file mode 100644 index 71c63c9..0000000 Binary files a/hosts/laptop/profile_picture.png and /dev/null differ diff --git a/hosts/laptop/secrets/default.nix b/hosts/laptop/secrets/default.nix deleted file mode 100644 index eac568f..0000000 --- a/hosts/laptop/secrets/default.nix +++ /dev/null @@ -1,61 +0,0 @@ -# Those are my secrets, encrypted with sops -# You shouldn't import this file, unless you edit it -{ - inputs, - pkgs, - config, - ... -}: let - home = config.home.homeDirectory; -in { - imports = [inputs.sops-nix.homeManagerModules.sops]; - - sops = { - age.keyFile = "${home}/.config/sops/age/keys.txt"; - defaultSopsFile = ./secrets.yaml; - secrets = { - ssh-config = { - path = "${home}/.ssh/config"; - }; - github-key = { - path = "${home}/.ssh/github"; - }; - jack-key = { - path = "${home}/.ssh/jack"; - }; - signing-key = { - path = "${home}/.ssh/key"; - }; - signing-pub-key = { - path = "${home}/.ssh/key.pub"; - }; - }; - }; - - home.file.".config/nixos/.sops.yaml".text = '' - keys: - - &primary age12yvtj49pfh3fqzqflscm0ek4yzrjhr6cqhn7x89gdxnlykq0xudq5c7334 - - &work age1c8pawdsxptfslgrz2c56s39mrtnjzc5mm3hfzgr2wdwu2v6vfsdsupjsq6 - creation_rules: - - path_regex: hosts/laptop/secrets/secrets.yaml$ - key_groups: - - age: - - *primary - - path_regex: hosts/server/secrets/secrets.yaml$ - key_groups: - - age: - - *primary - - path_regex: hosts/work/secrets/secrets.yaml$ - key_groups: - - age: - - *work - ''; - - systemd.user.services.mbsync.Unit.After = ["sops-nix.service"]; - home.packages = with pkgs; [ - sops - age - ]; - - wayland.windowManager.hyprland.settings.exec-once = ["systemctl --user start sops-nix"]; -} diff --git a/hosts/laptop/secrets/secrets.yaml b/hosts/laptop/secrets/secrets.yaml deleted file mode 100644 index 49bcc0f..0000000 --- a/hosts/laptop/secrets/secrets.yaml +++ /dev/null @@ -1,20 +0,0 @@ -ssh-config: ENC[AES256_GCM,data:/TWslzoF2wtZ9T41H1y0wLNEx+Xzff8pQGr6AfEcACExRCv4rd5hD9pNAlmlcTtISJJBPEWY45WsLfSKuD4r3715IENM2biQUvlq47THfkGviQuQ6KAXiJxBQ/7qRNqGGt7WFRlWFRGYCiyjw9h4pOhovGgw8TU6tIgIsXjo0psclHoJoE4B3cSOby7DbN8jVI9NjpBGiQMXmUB3JVz7muC9F5EAs+XZUIl7TjQMxob3PiF5LqTJITODSxboAAk901rjS5gjQKpQKfj28TpUs5yCIo9RzSBO3z5orJy+ylupocRuqtC8ujAMqNb828G+0nRx18tpiGqXxRWUBZRNbM+vQHWzb5JWQpEBsu1twsOownVVrkyPkbLpYX4YSSnRdnL8VHmlZfLk1ZFURbsdDSRf57F+Bxo5Yn8XAkFaM5HYgUo4VBabGzVVAHOBWJWi3lRrlAqYdMBbSvDl1t6eQ0xp990RGh7wZvwnaTDqtkOJnLoAknTFi4yjMzSyk5UV,iv:1UJQU4eBZE1BMVnJY2CQTDH8jXSMlrv3gGU3cKTOvdU=,tag:OzLQRkTAKG2KQXv+Vh7Msw==,type:str] -github-key: ENC[AES256_GCM,data:xUgFMlBo8e+3eXqNscxbby1dWug3SgUagDiNUe/IGVbU6cczkaJ3uOaB0OuRBQ8AYhOLkzXj0pIKjUrElHwmYrhURtS1aF4SFEGJsjhhobNA//j3E2/5/nLVjfco+lRzyHdwmsNhEUCqEhsXrrodJMb39H4b5oip3z0rjc729YveiWUKQxXVZVPurp3nq9yNnix9R4CA6XYFRW6T6MNqgPD5qhbcDlhxLb/SN+uI5h+5eZIS24VDWlKaTaCLL5KLhZmfuA37SquOQ+edi9Yg8MnfrZkMrp/3qmAjP2rSQLMOc4QdQCLQBQSf0/snpydgLwY+FoJmMSztwtkqUdIZWOfDUJbJxegEOrAR68jLTNbp+GYiDn3thtOZDiK5p/M1amjCT+A9qeFMed5WS+aZHNTRbR9UcfiP6+48MGZFt1mr7q+/CoL04/DTp0w6tUf6/SZD31NvTJDqngkhpc0ZH9Dh5+2JcnBWpq25AM36kZTn1hIQCLNTr/oGWZXSLA2tksAhQCaUcFj4IIh6Bl96,iv:GEJsAs5NriwENYTV/VShgJF6iMmrtTwNiXOvfXyEP8E=,tag:nfZgsFqaet075GjQAoVZxQ==,type:str] -jack-key: ENC[AES256_GCM,data:VfCl3wH0MMBc8QDyjLDFeSvzSEsf7uGpfJvRjFrmjW+bPRUXBpZhJV8a9VQIAz7z7zZXvzARMfCeI0ydyC57CW81GH5/H5pneJ4b+xreINjVfdLbL1nC1thelo/O64jda/L+xVKhgE+QQi8/zt4JmXGghkP+74nYcTTaMpmcbgWw354J1ybXqyCEY+88nsJ1d2s+M7M2bplx4fGb7sLUs6sqdsad3sENzhH/0HQCFXreHTtgsLbIs8ccmdRgFNKM8/wD0OoW76rOQsJoA9JY4yOTQNVoX5M8+Olj6+wVlt6QBrWrYRuEztGnHrHvzxiHXtmEkMwVNfoPpEflQyRYRa0rVp/66REOkMckGx6/LbxKFgrxnifRlsK3kWd28v2bRGVQOghUluYUtVkaJ+eh6o6ik0NQKx8/H6BznBSDE6MjDwbLv434LHBfDtAqhWN1eMbOlunFivsl5Hb/6rl9kydHlcCS6FY8cUHoKQ90gDaUuDrvUifwmdO5hU0GH5tgvGi1ReK9ndcpQsrHptG6,iv:oC1xU5Tu3The105VYRmxIw4kEwDoqe8T/EH6mmqpqwQ=,tag:Pu8c536u6W7ALrqjRsvXDw==,type:str] -signing-key: ENC[AES256_GCM,data:NvLqmt7NzrWkbQQqFfosmSMvEv8C8+MDDpxSoDo3zZ3MR6WXr9B+6CnUc6rtevM230wgE17VC9XlmcQxX+PjJsWq6gZteK5THTIcrR5zPJVNlVCEyeLKoFj/6m7qBgyyoN3OjCNjgMkhsm009jwBgNk0qJMAYebOGo8eoP/al+4ytm7dhna+iX5WZabAg0J4z4JMDQonqQl3SaDnCEdHvk9m7ZEP2vUFscPkbLj4ewgFq+bUCHOOQb2uqRJoEgcR/NetRFcQfzcU6lp7JxobaICaO3zdmomUm7oabIUTrc3Kom3Wjw8ryqfqC1/SC0SHr5XGk2ygk0WnlQ4kNshqriL2dwbWAzy1Z/cTX9+aB/KNtC0U6zWG1bpnL3dgSgvhRiocIis/eNg1HWsLWVicmdebL/lXHztxFMdTuX/gWgQBotggTmx+OFGZfP9ZGlF3635mDxM/fEOCtTyA195dMicCUsjEpBegNtXsp+oOtxyRI0jSW47MBcXFP09f5ywELTPyz4eOUHO8sQ6UfJ6X,iv:KNQUlMPaiR4x1Fw+HZe/EOmh/gfsrqlefpq23uflz/8=,tag:illu42HKunQXnijjsUIvnQ==,type:str] -signing-pub-key: ENC[AES256_GCM,data:XuokZmCsnaNQ0rvVa3k81T4vtxw//r63xp1yHDLaNAMwA2r2bh6addl9WoAmm76g1rweqZrAAIw1PXDb90ubPaBP1iEHSkGZpwUpy/tOTePRdHMW2WtVvidpHQ==,iv:auB/bA89cJK6DnQi1BK2uldXRPyJfo+r7nl5qOLefUk=,tag:/I3kB6El1yesBMGOjJ+oHA==,type:str] -sops: - age: - - recipient: age12yvtj49pfh3fqzqflscm0ek4yzrjhr6cqhn7x89gdxnlykq0xudq5c7334 - enc: | - -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBHVWN4YjZqczB3Q21WL1lz - ckROWkhRditHblVHVEpOS0E0aGVqdW14M0ZvCkNzRXlCOWFBWmQwTGpTYVdFRlpq - bFdOR2pSTEZpUVpvUHo2NklrQm5EU1kKLS0tIFZ5ZWhYcHg1Z0hTOTZIdHR1QUxv - cmVxVC8rVDlWMUdZaGw3bmdOaWZGS1EKYahBlc8XpB5UdKZQkvxbLcKQ/xkFJjWo - FSfQWnjhe/a7BJtJEcKZkjOQU0mYqlSu+uT2RA9diCQeRUJPRF+nAw== - -----END AGE ENCRYPTED FILE----- - lastmodified: "2026-04-25T11:23:30Z" - mac: ENC[AES256_GCM,data:ZnLSwtyhaiMIcXxzlwhtk0dWVnOkn0avfeRezPPNBUXd0oyJY+krBsLXJdSNPHV/X/L58476okYjUzfIQzEAkrL9Fb7v/Jt0aw4SDrxbF+qbcfdvsWPUjFDJIPovuf3ee3o7iXGU2ItGTaJa2eFACoyd37KVc7jZd6gvYYAyULA=,iv:7IKqe0c5CTgJrS7OgCQWhtxaCVKo+UWEibttFUVCWGM=,tag:OfCrKPzrPBZThCR1j7IB7A==,type:str] - unencrypted_suffix: _unencrypted - version: 3.12.2 diff --git a/hosts/laptop/variables.nix b/hosts/laptop/variables.nix index c703f53..8e98566 100644 --- a/hosts/laptop/variables.nix +++ b/hosts/laptop/variables.nix @@ -9,19 +9,19 @@ ]; config.var = { - hostname = "h-laptop"; - username = "hadi"; + hostname = "thinkpad"; + username = "andi"; configDirectory = "/home/" + config.var.username + "/.config/nixos"; # The path of the nixos configuration directory - keyboardLayout = "fr"; + keyboardLayout = "de"; - timeZone = "Europe/Paris"; - defaultLocale = "en_US.UTF-8"; - extraLocale = "fr_FR.UTF-8"; + timeZone = "Europe/Berlin"; + defaultLocale = "de_DE.UTF-8"; + extraLocale = "en_US.UTF-8"; git = { - username = "Hadi"; - email = "112569860+anotherhadi@users.noreply.github.com"; + username = "kptltd00m"; + email = "kptltd00m@doomlabs.de"; }; autoUpgrade = false; diff --git a/hosts/work/home.nix b/hosts/work/home.nix index 860dee8..a64d1a9 100644 --- a/hosts/work/home.nix +++ b/hosts/work/home.nix @@ -28,7 +28,7 @@ ../../home/system/udiskie ./variables.nix # Mostly user-specific configuration - ./secrets # CHANGEME: You should probably remove this line, this is where I store my secrets + #./secrets # CHANGEME: You should probably remove this line, this is where I store my secrets ]; home = { diff --git a/nixos/omen.nix b/nixos/omen.nix deleted file mode 100644 index cc16439..0000000 --- a/nixos/omen.nix +++ /dev/null @@ -1,64 +0,0 @@ -# Omen laptop configuration for NixOS -# Import this only if you have an HP Omen laptop -{ - config, - pkgs, - ... -}: let - hp-omen-linux-module = pkgs.callPackage ( - { - kernel ? config.boot.kernelPackages.kernel, - stdenv, - fetchFromGitHub, - }: - stdenv.mkDerivation (finalAttrs: { - pname = "hp-omen-linux-module"; - version = "rebase-6.14"; - src = fetchFromGitHub { - owner = "ranisalt"; - repo = "hp-omen-linux-module"; - rev = finalAttrs.version; - sha256 = "sha256-2zCm29bdboSjRm/caMjBPGNc0tZXPUnIIYlHxxfhAok="; - }; - setSourceRoot = '' - export sourceRoot=$(pwd)/${finalAttrs.src.name}/src - ''; - nativeBuildInputs = kernel.moduleBuildDependencies; - makeFlags = [ - "KERNELDIR=${kernel.dev}/lib/modules/${kernel.modDirVersion}/build" - ]; - installPhase = '' - runHook preInstall - install hp-wmi.ko -Dm444 -t $out/lib/modules/${kernel.modDirVersion}/kernel/drivers/platform/x86/hp/ - runHook postInstall - ''; - }) - ) {kernel = config.boot.kernelPackages.kernel;}; -in { - boot.extraModulePackages = [hp-omen-linux-module]; - boot.kernelModules = ["hp-wmi"]; - boot.kernelParams = ["hp_wmi.force_slow_fan_control=1"]; - - users.groups.omen-rgb = {}; - users.users.${config.var.username}.extraGroups = ["omen-rgb"]; - - systemd.tmpfiles.rules = [ - "w /sys/devices/platform/hp-wmi/rgb_zones/zone00 0660 root omen-rgb -" - "w /sys/devices/platform/hp-wmi/rgb_zones/zone01 0660 root omen-rgb -" - "w /sys/devices/platform/hp-wmi/rgb_zones/zone02 0660 root omen-rgb -" - "w /sys/devices/platform/hp-wmi/rgb_zones/zone03 0660 root omen-rgb -" - ]; - - services.udev.extraRules = '' - SUBSYSTEM=="platform", KERNEL=="hp-wmi", ACTION=="add", \ - RUN+="${pkgs.coreutils-full}/bin/sleep 2", \ - RUN+="${pkgs.coreutils}/bin/chgrp omen-rgb /sys/devices/platform/hp-wmi/rgb_zones/zone00", \ - RUN+="${pkgs.coreutils}/bin/chmod 0660 /sys/devices/platform/hp-wmi/rgb_zones/zone00", \ - RUN+="${pkgs.coreutils}/bin/chgrp omen-rgb /sys/devices/platform/hp-wmi/rgb_zones/zone01", \ - RUN+="${pkgs.coreutils}/bin/chmod 0660 /sys/devices/platform/hp-wmi/rgb_zones/zone01", \ - RUN+="${pkgs.coreutils}/bin/chgrp omen-rgb /sys/devices/platform/hp-wmi/rgb_zones/zone02", \ - RUN+="${pkgs.coreutils}/bin/chmod 0660 /sys/devices/platform/hp-wmi/rgb_zones/zone02", \ - RUN+="${pkgs.coreutils}/bin/chgrp omen-rgb /sys/devices/platform/hp-wmi/rgb_zones/zone03", \ - RUN+="${pkgs.coreutils}/bin/chmod 0660 /sys/devices/platform/hp-wmi/rgb_zones/zone03" - ''; -} diff --git a/nixos/steam.nix b/nixos/steam.nix new file mode 100644 index 0000000..754bf2c --- /dev/null +++ b/nixos/steam.nix @@ -0,0 +1,13 @@ +{ ... }: { + programs.steam = { + enable = true; + gamescopeSession.enable = true; + remotePlay.openFirewall = true; + dedicatedServer.openFirewall = true; + }; + + hardware.graphics = { + enable = true; + enable32Bit = true; + }; +} diff --git a/nixos/usbguard.nix b/nixos/usbguard.nix index a1567d1..a70c1cb 100644 --- a/nixos/usbguard.nix +++ b/nixos/usbguard.nix @@ -1,6 +1,6 @@ {config, ...}: { services.usbguard = { - enable = true; + enable = false; implicitPolicyTarget = "block"; IPCAllowedUsers = [ "root" diff --git a/nixos/utils.nix b/nixos/utils.nix index 44d6a4c..60abc8b 100644 --- a/nixos/utils.nix +++ b/nixos/utils.nix @@ -83,7 +83,7 @@ in { }; gvfs.enable = true; upower.enable = true; - power-profiles-daemon.enable = true; + power-profiles-daemon.enable = false; udisks2.enable = true; };