diff --git a/hosts/work/configuration.nix b/hosts/work/configuration.nix index b8d47950..87233bb9 100644 --- a/hosts/work/configuration.nix +++ b/hosts/work/configuration.nix @@ -13,12 +13,9 @@ ../../nixos/hyprland.nix ../../nixos/kernel-hardening.nix ../../nixos/vulnix.nix - ../../home/programs/gui/helium/system.nix # I hate browser's configuration.. + ../../home/gui/helium/system.nix # I hate browser's configuration.. # CHANGEME: You should probably remove those things: - ./persistence.nix # impermanence: what to keep once "/" is wiped on boot - ./usbguard.nix - ./disko.nix ./secrets ./wireguard.nix @@ -31,6 +28,67 @@ users.users.${config.var.username}.hashedPassword = "$y$j9T$quUlRuvuYJ18asD8SUrh11$0mHCP7ZRIOYjNHY0oT.aFfVho1V0M65eClLzVo0RARD"; # CHANGEME: This is my password + # Impermanence: declares what should survive a wipe of "/". + environment.persistence."/persist" = { + hideMounts = true; + + directories = [ + "/etc/NetworkManager/system-connections" # Wifi connections, VPN + "/var/lib/bluetooth" # Bluetooth connections + "/var/lib/nixos" # keeps uid/gid stable across boots + "/var/lib/systemd/coredump" + "/var/lib/upower" # battery calibration state + "/var/lib/systemd/backlight" # remembers screen brightness + "/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly) + "/var/log" + "/var/db/sudo/lectured" # remembers that the sudo lecture was already shown + ]; + + files = [ + "/etc/machine-id" + "/etc/ssh/ssh_host_ed25519_key" + "/etc/ssh/ssh_host_ed25519_key.pub" + "/etc/ssh/ssh_host_rsa_key" + "/etc/ssh/ssh_host_rsa_key.pub" + "/var/lib/systemd/random-seed" # avoid a weak entropy pool on first boot + ]; + }; + + # USBGuard: + # The following line allow all USB devices until a proper policy is configured. + # Run `sudo usbguard generate-policy` with your devices plugged in, + # then set rules = "" and switch implicitPolicyTarget to "block". + # services.usbguard.implicitPolicyTarget = lib.mkForce "allow"; + services.usbguard = { + enable = true; + implicitPolicyTarget = "block"; + IPCAllowedUsers = [ + "root" + ]; + rules = '' + allow id 1d6b:0002 name "xHCI Host Controller" + allow id 0951:1666 name "DataTraveler 3.0" + allow id 1d6b:0003 name "xHCI Host Controller" + allow id 0461:574a name "HP 125 USB Optical Mouse" + allow id 0461:554a name "HP 125 Wired Keyboard" + allow id 1f75:0903 name "USB DISK" + allow id 17ef:30b7 name "USB2.0 Hub " + allow id 1d6b:0003 name "xHCI Host Controller" + allow id 17ef:30bb name "ThinkPad Thunderbolt 4 Dock USB Audio" + allow id 1d6b:0002 name "xHCI Host Controller" + allow id 17ef:30b4 name "ThinkPad Thunderbolt 4 Dock MCU Contoller" + allow id 17ef:30ba name "V1003" + allow id 8087:0b40 name "USB3.0 Hub" + allow id 17ef:30b5 name "40B1" + allow id 17ef:30b6 name "USB3.1 Hub " + allow id 0461:574a name "HP 125 USB Optical Mouse" + allow id 0461:554a name "HP 125 Wired Keyboard" + allow id 17ef:30b9 name "USB2.0 Hub " + allow id 0bda:8153 name "USB 10/100/1000 LAN" + allow id 17ef:30b8 name "USB3.1 Hub " + ''; + }; + # Don't touch this system.stateVersion = "26.05"; } diff --git a/hosts/work/home.nix b/hosts/work/home.nix index ea03f124..82146edf 100644 --- a/hosts/work/home.nix +++ b/hosts/work/home.nix @@ -3,48 +3,17 @@ inputs, lib, ... -}: { - imports = [ - # Programs - - ## GUI - ../../home/programs/gui/proton - ../../home/programs/gui/helium - ../../home/programs/gui/pkgs.nix - - ## TUI - inputs.nvf-config.homeManagerModules.default - ../../home/programs/tui/ghostty - ../../home/programs/tui/ilovetui - ../../home/programs/tui/shell - ../../home/programs/tui/git - ../../home/programs/tui/git/lazygit.nix - ../../home/programs/tui/nixy - ../../home/programs/tui/nix-utils - ../../home/programs/tui/myx - ../../home/programs/tui/elio - ../../home/programs/tui/tealdeer - ../../home/programs/tui/navi - ../../home/programs/tui/pkgs.nix - - ## GROUPS - ../../home/programs/group/cybersecurity.nix - ../../home/programs/group/dev.nix - - # System (Desktop environment like stuff) - ../../home/system/hyprlock - ../../home/system/hyprland - ../../home/system/waybar - ../../home/system/swaync - ../../home/system/tofi - ../../home/system/mime - ../../home/system/udiskie - ../../home/system/termfilechooser - ../../home/system/clipboard - ../../home/system/hypridle - - ./variables.nix # Mostly user-specific configuration - ]; +}: let + utils = import ../../home/lib/utils.nix {inherit lib;}; +in { + imports = + utils.importAll ../../home/tui + ++ utils.importAll ../../home/gui + ++ utils.importAll ../../home/system # System (Desktop environment like stuff) + ++ [ + inputs.nvf-config.homeManagerModules.default # My vim config + ./variables.nix # Mostly user-specific configuration + ]; home = { inherit (config.var) username; diff --git a/hosts/work/persistence.nix b/hosts/work/persistence.nix deleted file mode 100644 index 3a0b648f..00000000 --- a/hosts/work/persistence.nix +++ /dev/null @@ -1,29 +0,0 @@ -# Impermanence: declares what should survive a wipe of "/". -{ - environment.persistence."/persist" = { - hideMounts = true; - - directories = [ - "/etc/NetworkManager/system-connections" # Wifi connections, VPN - "/var/lib/bluetooth" # Bluetooth connections - "/var/lib/nixos" # keeps uid/gid stable across boots - "/var/lib/systemd/coredump" - "/var/lib/upower" # battery calibration state - "/var/lib/systemd/backlight" # remembers screen brightness - "/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly) - "/var/log" - "/var/cache/tuigreet" - "/var/cache/vulnix" - "/var/db/sudo/lectured" # remembers that the sudo lecture was already shown - ]; - - files = [ - "/etc/machine-id" - "/etc/ssh/ssh_host_ed25519_key" - "/etc/ssh/ssh_host_ed25519_key.pub" - "/etc/ssh/ssh_host_rsa_key" - "/etc/ssh/ssh_host_rsa_key.pub" - "/var/lib/systemd/random-seed" # avoid a weak entropy pool on first boot - ]; - }; -} diff --git a/hosts/work/usbguard.nix b/hosts/work/usbguard.nix deleted file mode 100644 index 27e83211..00000000 --- a/hosts/work/usbguard.nix +++ /dev/null @@ -1,22 +0,0 @@ -# USBGuard: -# The following line allow all USB devices until a proper policy is configured. -# Run `sudo usbguard generate-policy` with your devices plugged in, -# then set rules = "" and switch implicitPolicyTarget to "block". -# services.usbguard.implicitPolicyTarget = lib.mkForce "allow"; -{ - services.usbguard = { - enable = true; - implicitPolicyTarget = "block"; - IPCAllowedUsers = [ - "root" - ]; - rules = '' - allow id 1d6b:0002 name "xHCI Host Controller" - allow id 0951:1666 name "DataTraveler 3.0" - allow id 1d6b:0003 name "xHCI Host Controller" - allow id 0461:574a name "HP 125 USB Optical Mouse" - allow id 0461:554a name "HP 125 Wired Keyboard" - allow id 1f75:0903 name "USB DISK" - ''; - }; -}