Signed-off-by: Hadi <[email protected]>
This commit is contained in:
Hadi
2026-09-29 11:13:17 +02:00
parent 3843a5dbde
commit 230121b8f3
4 changed files with 73 additions and 97 deletions
+62 -4
View File
@@ -13,12 +13,9 @@
../../nixos/hyprland.nix ../../nixos/hyprland.nix
../../nixos/kernel-hardening.nix ../../nixos/kernel-hardening.nix
../../nixos/vulnix.nix ../../nixos/vulnix.nix
../../home/programs/gui/helium/system.nix # I hate browser's configuration.. ../../home/gui/helium/system.nix # I hate browser's configuration..
# CHANGEME: You should probably remove those things: # CHANGEME: You should probably remove those things:
./persistence.nix # impermanence: what to keep once "/" is wiped on boot
./usbguard.nix
./disko.nix
./secrets ./secrets
./wireguard.nix ./wireguard.nix
@@ -31,6 +28,67 @@
users.users.${config.var.username}.hashedPassword = "$y$j9T$quUlRuvuYJ18asD8SUrh11$0mHCP7ZRIOYjNHY0oT.aFfVho1V0M65eClLzVo0RARD"; # CHANGEME: This is my password users.users.${config.var.username}.hashedPassword = "$y$j9T$quUlRuvuYJ18asD8SUrh11$0mHCP7ZRIOYjNHY0oT.aFfVho1V0M65eClLzVo0RARD"; # CHANGEME: This is my password
# Impermanence: declares what should survive a wipe of "/".
environment.persistence."/persist" = {
hideMounts = true;
directories = [
"/etc/NetworkManager/system-connections" # Wifi connections, VPN
"/var/lib/bluetooth" # Bluetooth connections
"/var/lib/nixos" # keeps uid/gid stable across boots
"/var/lib/systemd/coredump"
"/var/lib/upower" # battery calibration state
"/var/lib/systemd/backlight" # remembers screen brightness
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
"/var/log"
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
];
files = [
"/etc/machine-id"
"/etc/ssh/ssh_host_ed25519_key"
"/etc/ssh/ssh_host_ed25519_key.pub"
"/etc/ssh/ssh_host_rsa_key"
"/etc/ssh/ssh_host_rsa_key.pub"
"/var/lib/systemd/random-seed" # avoid a weak entropy pool on first boot
];
};
# USBGuard:
# The following line allow all USB devices until a proper policy is configured.
# Run `sudo usbguard generate-policy` with your devices plugged in,
# then set rules = "<output>" and switch implicitPolicyTarget to "block".
# services.usbguard.implicitPolicyTarget = lib.mkForce "allow";
services.usbguard = {
enable = true;
implicitPolicyTarget = "block";
IPCAllowedUsers = [
"root"
];
rules = ''
allow id 1d6b:0002 name "xHCI Host Controller"
allow id 0951:1666 name "DataTraveler 3.0"
allow id 1d6b:0003 name "xHCI Host Controller"
allow id 0461:574a name "HP 125 USB Optical Mouse"
allow id 0461:554a name "HP 125 Wired Keyboard"
allow id 1f75:0903 name "USB DISK"
allow id 17ef:30b7 name "USB2.0 Hub "
allow id 1d6b:0003 name "xHCI Host Controller"
allow id 17ef:30bb name "ThinkPad Thunderbolt 4 Dock USB Audio"
allow id 1d6b:0002 name "xHCI Host Controller"
allow id 17ef:30b4 name "ThinkPad Thunderbolt 4 Dock MCU Contoller"
allow id 17ef:30ba name "V1003"
allow id 8087:0b40 name "USB3.0 Hub"
allow id 17ef:30b5 name "40B1"
allow id 17ef:30b6 name "USB3.1 Hub "
allow id 0461:574a name "HP 125 USB Optical Mouse"
allow id 0461:554a name "HP 125 Wired Keyboard"
allow id 17ef:30b9 name "USB2.0 Hub "
allow id 0bda:8153 name "USB 10/100/1000 LAN"
allow id 17ef:30b8 name "USB3.1 Hub "
'';
};
# Don't touch this # Don't touch this
system.stateVersion = "26.05"; system.stateVersion = "26.05";
} }
+9 -40
View File
@@ -3,46 +3,15 @@
inputs, inputs,
lib, lib,
... ...
}: { }: let
imports = [ utils = import ../../home/lib/utils.nix {inherit lib;};
# Programs in {
imports =
## GUI utils.importAll ../../home/tui
../../home/programs/gui/proton ++ utils.importAll ../../home/gui
../../home/programs/gui/helium ++ utils.importAll ../../home/system # System (Desktop environment like stuff)
../../home/programs/gui/pkgs.nix ++ [
inputs.nvf-config.homeManagerModules.default # My vim config
## TUI
inputs.nvf-config.homeManagerModules.default
../../home/programs/tui/ghostty
../../home/programs/tui/ilovetui
../../home/programs/tui/shell
../../home/programs/tui/git
../../home/programs/tui/git/lazygit.nix
../../home/programs/tui/nixy
../../home/programs/tui/nix-utils
../../home/programs/tui/myx
../../home/programs/tui/elio
../../home/programs/tui/tealdeer
../../home/programs/tui/navi
../../home/programs/tui/pkgs.nix
## GROUPS
../../home/programs/group/cybersecurity.nix
../../home/programs/group/dev.nix
# System (Desktop environment like stuff)
../../home/system/hyprlock
../../home/system/hyprland
../../home/system/waybar
../../home/system/swaync
../../home/system/tofi
../../home/system/mime
../../home/system/udiskie
../../home/system/termfilechooser
../../home/system/clipboard
../../home/system/hypridle
./variables.nix # Mostly user-specific configuration ./variables.nix # Mostly user-specific configuration
]; ];
-29
View File
@@ -1,29 +0,0 @@
# Impermanence: declares what should survive a wipe of "/".
{
environment.persistence."/persist" = {
hideMounts = true;
directories = [
"/etc/NetworkManager/system-connections" # Wifi connections, VPN
"/var/lib/bluetooth" # Bluetooth connections
"/var/lib/nixos" # keeps uid/gid stable across boots
"/var/lib/systemd/coredump"
"/var/lib/upower" # battery calibration state
"/var/lib/systemd/backlight" # remembers screen brightness
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
"/var/log"
"/var/cache/tuigreet"
"/var/cache/vulnix"
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
];
files = [
"/etc/machine-id"
"/etc/ssh/ssh_host_ed25519_key"
"/etc/ssh/ssh_host_ed25519_key.pub"
"/etc/ssh/ssh_host_rsa_key"
"/etc/ssh/ssh_host_rsa_key.pub"
"/var/lib/systemd/random-seed" # avoid a weak entropy pool on first boot
];
};
}
-22
View File
@@ -1,22 +0,0 @@
# USBGuard:
# The following line allow all USB devices until a proper policy is configured.
# Run `sudo usbguard generate-policy` with your devices plugged in,
# then set rules = "<output>" and switch implicitPolicyTarget to "block".
# services.usbguard.implicitPolicyTarget = lib.mkForce "allow";
{
services.usbguard = {
enable = true;
implicitPolicyTarget = "block";
IPCAllowedUsers = [
"root"
];
rules = ''
allow id 1d6b:0002 name "xHCI Host Controller"
allow id 0951:1666 name "DataTraveler 3.0"
allow id 1d6b:0003 name "xHCI Host Controller"
allow id 0461:574a name "HP 125 USB Optical Mouse"
allow id 0461:554a name "HP 125 Wired Keyboard"
allow id 1f75:0903 name "USB DISK"
'';
};
}