rework: more TUIs! (#62)

Signed-off-by: Hadi <[email protected]>
This commit is contained in:
Hadi
2026-09-28 20:18:12 +02:00
committed by GitHub
parent 1a3f23f248
commit 07a60e91d2
98 changed files with 1280 additions and 1093 deletions
+65 -7
View File
@@ -1,13 +1,17 @@
{config, ...}: {
{
config,
lib,
...
}: {
imports = [
# Mostly system related configuration
../../nixos/nvidia.nix # CHANGEME: Remove this line if you don't have an Nvidia GPU
../../nixos/audio.nix
../../nixos/bluetooth.nix
../../nixos/fonts.nix
../../nixos/home-manager.nix
../../nixos/nix.nix
../../nixos/systemd-boot.nix
../../nixos/lanzaboot.nix # CHANGEME: Remove this line and uncomment the next one if you don't want to setup secure boot
# ../../nixos/systemd-boot.nix
../../nixos/tuigreet.nix
../../nixos/autologin.nix # Skip first TUIGreet login, use LUKS password to unlock the keyring
../../nixos/users.nix
@@ -15,13 +19,10 @@
../../nixos/hyprland.nix
../../nixos/steam.nix
../../nixos/kernel-hardening.nix
../../home/programs/gui/helium/system.nix # I hate browser's configuration..
../../home/gui/helium/system.nix # I hate browser's configuration..
# CHANGEME: You should probably remove those things:
./wireguard.nix
./persistence.nix # impermanence: what to keep once "/" is wiped on boot
./usbguard.nix
./disko.nix
./secrets
# You should let those lines as is
@@ -31,8 +32,65 @@
home-manager.users."${config.var.username}" = import ./home.nix;
# User password
users.users.${config.var.username}.hashedPassword = "$y$j9T$A7gH534UczuBxulj9IfEu1$ImRy3lpYpemRWNVIkA7efKPWXneFiqhZnEF1aMkWcD8"; # CHANGEME: This is my password
# Impermanence: declares what should survive a wipe of "/".
environment.persistence."/persist" = {
hideMounts = true;
directories = [
"/etc/NetworkManager/system-connections" # Wifi connections, VPN
"/var/lib/bluetooth" # Bluetooth connections
"/var/lib/nixos" # keeps uid/gid stable across boots
"/var/lib/systemd/coredump"
"/var/lib/upower" # battery calibration state
"/var/lib/systemd/backlight" # remembers screen brightness
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
"/var/log"
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
];
files = [
"/etc/machine-id"
"/etc/ssh/ssh_host_ed25519_key"
"/etc/ssh/ssh_host_ed25519_key.pub"
"/etc/ssh/ssh_host_rsa_key"
"/etc/ssh/ssh_host_rsa_key.pub"
"/var/lib/systemd/random-seed" # avoid a weak entropy pool on first boot
];
};
# USBGuard:
# The following line allow all USB devices until a proper policy is configured.
# Run `sudo usbguard generate-policy` with your devices plugged in,
# then set rules = "<output>" and switch implicitPolicyTarget to "block".
# services.usbguard.implicitPolicyTarget = lib.mkForce "allow";
services.usbguard = {
enable = true;
implicitPolicyTarget = "block";
IPCAllowedUsers = [
"root"
];
rules = ''
allow id 13fd:5900 name "External"
allow id 1d6b:0003 name "xHCI Host Controller"
allow id 1d6b:0002 name "xHCI Host Controller"
allow id 0bda:c85c name "Bluetooth Radio"
allow id 30c9:009f name "HP True Vision FHD Camera"
allow id 03f0:036b name "HP USB-C Dock G5"
allow id 03f0:066b name "HP USB-C Dock G5"
allow id 03f0:056b name "USB Audio"
allow id 0bda:8153 name "USB 10/100/1000 LAN"
allow id 046d:0ab7 name "Blue Microphones"
allow id 03f0:076b name "USB5734"
allow id 1532:02a1 name "Razer Ornata V3"
allow id 03f0:046b name "HP USB-C Dock G5"
allow id 03f0:086b name "USB2734"
allow id 1b1c:1b75 name "CORSAIR HARPOON RGB PRO Gaming Mouse"
'';
};
# Don't touch this
system.stateVersion = "26.05";
}
+1
View File
@@ -20,6 +20,7 @@ nixpkgs.lib.nixosSystem {
inputs.helium-browser.nixosModules.default
inputs.impermanence.nixosModules.impermanence
inputs.disko.nixosModules.disko
inputs.lanzaboote.nixosModules.lanzaboote
./disko.nix
./configuration.nix
];
+13 -43
View File
@@ -3,49 +3,18 @@
inputs,
lib,
...
}: {
imports = [
# Programs
## GUI
../../home/programs/gui/proton
../../home/programs/gui/helium
../../home/programs/gui/pkgs.nix
## TUI
inputs.nvf-config.homeManagerModules.default
../../home/programs/tui/ghostty
../../home/programs/tui/ilovetui
../../home/programs/tui/shell
../../home/programs/tui/git
../../home/programs/tui/git/lazygit.nix
../../home/programs/tui/git/signing.nix # CHANGEME: Change the key or remove this file
../../home/programs/tui/nixy
../../home/programs/tui/nix-utils
../../home/programs/tui/myx
../../home/programs/tui/elio
../../home/programs/tui/wikiman
../../home/programs/tui/navi
../../home/programs/tui/pkgs.nix
## GROUPS
../../home/programs/group/cybersecurity.nix
../../home/programs/group/dev.nix
# System (Desktop environment like stuff)
../../home/system/hyprlock
../../home/system/hyprland
../../home/system/waybar
../../home/system/swaync
../../home/system/tofi
../../home/system/mime
../../home/system/udiskie
../../home/system/termfilechooser
../../home/system/clipboard
../../home/system/hypridle
./variables.nix # Mostly user-specific configuration
];
}: let
utils = import ../../home/lib/utils.nix {inherit lib;};
in {
imports =
utils.importAll ../../home/tui
++ utils.importAll ../../home/gui
++ utils.importAll ../../home/system # System (Desktop environment like stuff)
++ [
inputs.nvf-config.homeManagerModules.default # My vim config
../../home/tui/git/signing.nix # CHANGEME: Change the key or remove this file
./variables.nix # Mostly user-specific configuration
];
home = {
inherit (config.var) username;
@@ -59,6 +28,7 @@
".cache"
".steam"
"Notes"
"Music"
"Projects"
"Documents"
"Downloads"
-29
View File
@@ -1,29 +0,0 @@
# Impermanence: declares what should survive a wipe of "/".
{
environment.persistence."/persist" = {
hideMounts = true;
directories = [
"/etc/NetworkManager/system-connections" # Wifi connections, VPN
"/var/lib/bluetooth" # Bluetooth connections
"/var/lib/nixos" # keeps uid/gid stable across boots
"/var/lib/systemd/coredump"
"/var/lib/upower" # battery calibration state
"/var/lib/systemd/backlight" # remembers screen brightness
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
"/var/log"
"/var/cache/tuigreet"
"/var/cache/vulnix"
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
];
files = [
"/etc/machine-id"
"/etc/ssh/ssh_host_ed25519_key"
"/etc/ssh/ssh_host_ed25519_key.pub"
"/etc/ssh/ssh_host_rsa_key"
"/etc/ssh/ssh_host_rsa_key.pub"
"/var/lib/systemd/random-seed" # avoid a weak entropy pool on first boot
];
};
}
File diff suppressed because one or more lines are too long
-31
View File
@@ -1,31 +0,0 @@
# USBGuard:
# The following line allow all USB devices until a proper policy is configured.
# Run `sudo usbguard generate-policy` with your devices plugged in,
# then set rules = "<output>" and switch implicitPolicyTarget to "block".
# services.usbguard.implicitPolicyTarget = lib.mkForce "allow";
{
services.usbguard = {
enable = true;
implicitPolicyTarget = "block";
IPCAllowedUsers = [
"root"
];
rules = ''
allow id 13fd:5900 name "External"
allow id 1d6b:0003 name "xHCI Host Controller"
allow id 1d6b:0002 name "xHCI Host Controller"
allow id 0bda:c85c name "Bluetooth Radio"
allow id 30c9:009f name "HP True Vision FHD Camera"
allow id 03f0:036b name "HP USB-C Dock G5"
allow id 03f0:066b name "HP USB-C Dock G5"
allow id 03f0:056b name "USB Audio"
allow id 0bda:8153 name "USB 10/100/1000 LAN"
allow id 046d:0ab7 name "Blue Microphones"
allow id 03f0:076b name "USB5734"
allow id 1532:02a1 name "Razer Ornata V3"
allow id 03f0:046b name "HP USB-C Dock G5"
allow id 03f0:086b name "USB2734"
allow id 1b1c:1b75 name "CORSAIR HARPOON RGB PRO Gaming Mouse"
'';
};
}