mirror of
https://github.com/anotherhadi/nixy.git
synced 2026-10-05 11:18:24 +02:00
@@ -13,12 +13,9 @@
|
|||||||
../../nixos/hyprland.nix
|
../../nixos/hyprland.nix
|
||||||
../../nixos/kernel-hardening.nix
|
../../nixos/kernel-hardening.nix
|
||||||
../../nixos/vulnix.nix
|
../../nixos/vulnix.nix
|
||||||
../../home/programs/gui/helium/system.nix # I hate browser's configuration..
|
../../home/gui/helium/system.nix # I hate browser's configuration..
|
||||||
|
|
||||||
# CHANGEME: You should probably remove those things:
|
# CHANGEME: You should probably remove those things:
|
||||||
./persistence.nix # impermanence: what to keep once "/" is wiped on boot
|
|
||||||
./usbguard.nix
|
|
||||||
./disko.nix
|
|
||||||
./secrets
|
./secrets
|
||||||
./wireguard.nix
|
./wireguard.nix
|
||||||
|
|
||||||
@@ -31,6 +28,67 @@
|
|||||||
|
|
||||||
users.users.${config.var.username}.hashedPassword = "$y$j9T$quUlRuvuYJ18asD8SUrh11$0mHCP7ZRIOYjNHY0oT.aFfVho1V0M65eClLzVo0RARD"; # CHANGEME: This is my password
|
users.users.${config.var.username}.hashedPassword = "$y$j9T$quUlRuvuYJ18asD8SUrh11$0mHCP7ZRIOYjNHY0oT.aFfVho1V0M65eClLzVo0RARD"; # CHANGEME: This is my password
|
||||||
|
|
||||||
|
# Impermanence: declares what should survive a wipe of "/".
|
||||||
|
environment.persistence."/persist" = {
|
||||||
|
hideMounts = true;
|
||||||
|
|
||||||
|
directories = [
|
||||||
|
"/etc/NetworkManager/system-connections" # Wifi connections, VPN
|
||||||
|
"/var/lib/bluetooth" # Bluetooth connections
|
||||||
|
"/var/lib/nixos" # keeps uid/gid stable across boots
|
||||||
|
"/var/lib/systemd/coredump"
|
||||||
|
"/var/lib/upower" # battery calibration state
|
||||||
|
"/var/lib/systemd/backlight" # remembers screen brightness
|
||||||
|
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
|
||||||
|
"/var/log"
|
||||||
|
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
|
||||||
|
];
|
||||||
|
|
||||||
|
files = [
|
||||||
|
"/etc/machine-id"
|
||||||
|
"/etc/ssh/ssh_host_ed25519_key"
|
||||||
|
"/etc/ssh/ssh_host_ed25519_key.pub"
|
||||||
|
"/etc/ssh/ssh_host_rsa_key"
|
||||||
|
"/etc/ssh/ssh_host_rsa_key.pub"
|
||||||
|
"/var/lib/systemd/random-seed" # avoid a weak entropy pool on first boot
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
# USBGuard:
|
||||||
|
# The following line allow all USB devices until a proper policy is configured.
|
||||||
|
# Run `sudo usbguard generate-policy` with your devices plugged in,
|
||||||
|
# then set rules = "<output>" and switch implicitPolicyTarget to "block".
|
||||||
|
# services.usbguard.implicitPolicyTarget = lib.mkForce "allow";
|
||||||
|
services.usbguard = {
|
||||||
|
enable = true;
|
||||||
|
implicitPolicyTarget = "block";
|
||||||
|
IPCAllowedUsers = [
|
||||||
|
"root"
|
||||||
|
];
|
||||||
|
rules = ''
|
||||||
|
allow id 1d6b:0002 name "xHCI Host Controller"
|
||||||
|
allow id 0951:1666 name "DataTraveler 3.0"
|
||||||
|
allow id 1d6b:0003 name "xHCI Host Controller"
|
||||||
|
allow id 0461:574a name "HP 125 USB Optical Mouse"
|
||||||
|
allow id 0461:554a name "HP 125 Wired Keyboard"
|
||||||
|
allow id 1f75:0903 name "USB DISK"
|
||||||
|
allow id 17ef:30b7 name "USB2.0 Hub "
|
||||||
|
allow id 1d6b:0003 name "xHCI Host Controller"
|
||||||
|
allow id 17ef:30bb name "ThinkPad Thunderbolt 4 Dock USB Audio"
|
||||||
|
allow id 1d6b:0002 name "xHCI Host Controller"
|
||||||
|
allow id 17ef:30b4 name "ThinkPad Thunderbolt 4 Dock MCU Contoller"
|
||||||
|
allow id 17ef:30ba name "V1003"
|
||||||
|
allow id 8087:0b40 name "USB3.0 Hub"
|
||||||
|
allow id 17ef:30b5 name "40B1"
|
||||||
|
allow id 17ef:30b6 name "USB3.1 Hub "
|
||||||
|
allow id 0461:574a name "HP 125 USB Optical Mouse"
|
||||||
|
allow id 0461:554a name "HP 125 Wired Keyboard"
|
||||||
|
allow id 17ef:30b9 name "USB2.0 Hub "
|
||||||
|
allow id 0bda:8153 name "USB 10/100/1000 LAN"
|
||||||
|
allow id 17ef:30b8 name "USB3.1 Hub "
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
# Don't touch this
|
# Don't touch this
|
||||||
system.stateVersion = "26.05";
|
system.stateVersion = "26.05";
|
||||||
}
|
}
|
||||||
|
|||||||
+11
-42
@@ -3,48 +3,17 @@
|
|||||||
inputs,
|
inputs,
|
||||||
lib,
|
lib,
|
||||||
...
|
...
|
||||||
}: {
|
}: let
|
||||||
imports = [
|
utils = import ../../home/lib/utils.nix {inherit lib;};
|
||||||
# Programs
|
in {
|
||||||
|
imports =
|
||||||
## GUI
|
utils.importAll ../../home/tui
|
||||||
../../home/programs/gui/proton
|
++ utils.importAll ../../home/gui
|
||||||
../../home/programs/gui/helium
|
++ utils.importAll ../../home/system # System (Desktop environment like stuff)
|
||||||
../../home/programs/gui/pkgs.nix
|
++ [
|
||||||
|
inputs.nvf-config.homeManagerModules.default # My vim config
|
||||||
## TUI
|
./variables.nix # Mostly user-specific configuration
|
||||||
inputs.nvf-config.homeManagerModules.default
|
];
|
||||||
../../home/programs/tui/ghostty
|
|
||||||
../../home/programs/tui/ilovetui
|
|
||||||
../../home/programs/tui/shell
|
|
||||||
../../home/programs/tui/git
|
|
||||||
../../home/programs/tui/git/lazygit.nix
|
|
||||||
../../home/programs/tui/nixy
|
|
||||||
../../home/programs/tui/nix-utils
|
|
||||||
../../home/programs/tui/myx
|
|
||||||
../../home/programs/tui/elio
|
|
||||||
../../home/programs/tui/tealdeer
|
|
||||||
../../home/programs/tui/navi
|
|
||||||
../../home/programs/tui/pkgs.nix
|
|
||||||
|
|
||||||
## GROUPS
|
|
||||||
../../home/programs/group/cybersecurity.nix
|
|
||||||
../../home/programs/group/dev.nix
|
|
||||||
|
|
||||||
# System (Desktop environment like stuff)
|
|
||||||
../../home/system/hyprlock
|
|
||||||
../../home/system/hyprland
|
|
||||||
../../home/system/waybar
|
|
||||||
../../home/system/swaync
|
|
||||||
../../home/system/tofi
|
|
||||||
../../home/system/mime
|
|
||||||
../../home/system/udiskie
|
|
||||||
../../home/system/termfilechooser
|
|
||||||
../../home/system/clipboard
|
|
||||||
../../home/system/hypridle
|
|
||||||
|
|
||||||
./variables.nix # Mostly user-specific configuration
|
|
||||||
];
|
|
||||||
|
|
||||||
home = {
|
home = {
|
||||||
inherit (config.var) username;
|
inherit (config.var) username;
|
||||||
|
|||||||
@@ -1,29 +0,0 @@
|
|||||||
# Impermanence: declares what should survive a wipe of "/".
|
|
||||||
{
|
|
||||||
environment.persistence."/persist" = {
|
|
||||||
hideMounts = true;
|
|
||||||
|
|
||||||
directories = [
|
|
||||||
"/etc/NetworkManager/system-connections" # Wifi connections, VPN
|
|
||||||
"/var/lib/bluetooth" # Bluetooth connections
|
|
||||||
"/var/lib/nixos" # keeps uid/gid stable across boots
|
|
||||||
"/var/lib/systemd/coredump"
|
|
||||||
"/var/lib/upower" # battery calibration state
|
|
||||||
"/var/lib/systemd/backlight" # remembers screen brightness
|
|
||||||
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
|
|
||||||
"/var/log"
|
|
||||||
"/var/cache/tuigreet"
|
|
||||||
"/var/cache/vulnix"
|
|
||||||
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
|
|
||||||
];
|
|
||||||
|
|
||||||
files = [
|
|
||||||
"/etc/machine-id"
|
|
||||||
"/etc/ssh/ssh_host_ed25519_key"
|
|
||||||
"/etc/ssh/ssh_host_ed25519_key.pub"
|
|
||||||
"/etc/ssh/ssh_host_rsa_key"
|
|
||||||
"/etc/ssh/ssh_host_rsa_key.pub"
|
|
||||||
"/var/lib/systemd/random-seed" # avoid a weak entropy pool on first boot
|
|
||||||
];
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,22 +0,0 @@
|
|||||||
# USBGuard:
|
|
||||||
# The following line allow all USB devices until a proper policy is configured.
|
|
||||||
# Run `sudo usbguard generate-policy` with your devices plugged in,
|
|
||||||
# then set rules = "<output>" and switch implicitPolicyTarget to "block".
|
|
||||||
# services.usbguard.implicitPolicyTarget = lib.mkForce "allow";
|
|
||||||
{
|
|
||||||
services.usbguard = {
|
|
||||||
enable = true;
|
|
||||||
implicitPolicyTarget = "block";
|
|
||||||
IPCAllowedUsers = [
|
|
||||||
"root"
|
|
||||||
];
|
|
||||||
rules = ''
|
|
||||||
allow id 1d6b:0002 name "xHCI Host Controller"
|
|
||||||
allow id 0951:1666 name "DataTraveler 3.0"
|
|
||||||
allow id 1d6b:0003 name "xHCI Host Controller"
|
|
||||||
allow id 0461:574a name "HP 125 USB Optical Mouse"
|
|
||||||
allow id 0461:554a name "HP 125 Wired Keyboard"
|
|
||||||
allow id 1f75:0903 name "USB DISK"
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
}
|
|
||||||
Reference in New Issue
Block a user