7 Commits

Author SHA1 Message Date
Hadi bb78dd67a5 fix waybar OSD calls
Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
2026-08-13 23:21:04 +02:00
Hadi b241f6bbd1 change the password
Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
2026-08-13 23:20:58 +02:00
Your Name 8e093d75ef Add disko with LUKS encryption and impermanence setup 2026-08-13 20:03:18 +00:00
Hadi ac0a706f1c Init impermanence
Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
2026-08-13 20:03:07 +02:00
Hadi b0a3843bcc Minimise the steam's games
Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
2026-08-13 17:33:41 +02:00
Hadi 6c5210cf66 add steam
Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
2026-08-13 14:57:34 +02:00
Hadi f704a5e9c4 Change pinned folders
Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
2026-08-13 14:42:07 +02:00
38 changed files with 400 additions and 514 deletions
-1
View File
@@ -1,4 +1,3 @@
.sops.yaml
.claude/ .claude/
old/ old/
docs/superpowers/ docs/superpowers/
+12
View File
@@ -0,0 +1,12 @@
keys:
- &primary age12yvtj49pfh3fqzqflscm0ek4yzrjhr6cqhn7x89gdxnlykq0xudq5c7334
- &work age1c8pawdsxptfslgrz2c56s39mrtnjzc5mm3hfzgr2wdwu2v6vfsdsupjsq6
creation_rules:
- path_regex: hosts/laptop/secrets/secrets.yaml$
key_groups:
- age:
- *primary
- path_regex: hosts/server/secrets/secrets.yaml$
key_groups:
- age:
- *primary
Generated
+85 -7
View File
@@ -214,6 +214,26 @@
"type": "github" "type": "github"
} }
}, },
"disko": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1781152676,
"narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=",
"owner": "nix-community",
"repo": "disko",
"rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "disko",
"type": "github"
}
},
"firefox-gnome-theme": { "firefox-gnome-theme": {
"flake": false, "flake": false,
"locked": { "locked": {
@@ -474,6 +494,27 @@
"type": "github" "type": "github"
} }
}, },
"home-manager_2": {
"inputs": {
"nixpkgs": [
"impermanence",
"nixpkgs"
]
},
"locked": {
"lastModified": 1768598210,
"narHash": "sha256-kkgA32s/f4jaa4UG+2f8C225Qvclxnqs76mf8zvTVPg=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "c47b2cc64a629f8e075de52e4742de688f930dc6",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "home-manager",
"type": "github"
}
},
"iknowyou": { "iknowyou": {
"inputs": { "inputs": {
"bun2nix": "bun2nix_3", "bun2nix": "bun2nix_3",
@@ -494,6 +535,25 @@
"type": "github" "type": "github"
} }
}, },
"impermanence": {
"inputs": {
"home-manager": "home-manager_2",
"nixpkgs": "nixpkgs_5"
},
"locked": {
"lastModified": 1769548169,
"narHash": "sha256-03+JxvzmfwRu+5JafM0DLbxgHttOQZkUtDWBmeUkN8Y=",
"owner": "nix-community",
"repo": "impermanence",
"rev": "7b1d382faf603b6d264f58627330f9faa5cba149",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "impermanence",
"type": "github"
}
},
"import-tree": { "import-tree": {
"locked": { "locked": {
"lastModified": 1763762820, "lastModified": 1763762820,
@@ -576,7 +636,7 @@
}, },
"nixarr": { "nixarr": {
"inputs": { "inputs": {
"nixpkgs": "nixpkgs_5", "nixpkgs": "nixpkgs_6",
"treefmt-nix": "treefmt-nix_4", "treefmt-nix": "treefmt-nix_4",
"vpnconfinement": "vpnconfinement", "vpnconfinement": "vpnconfinement",
"website-builder": "website-builder" "website-builder": "website-builder"
@@ -597,7 +657,7 @@
}, },
"nixos-hardware": { "nixos-hardware": {
"inputs": { "inputs": {
"nixpkgs": "nixpkgs_6" "nixpkgs": "nixpkgs_7"
}, },
"locked": { "locked": {
"lastModified": 1782166108, "lastModified": 1782166108,
@@ -739,6 +799,22 @@
} }
}, },
"nixpkgs_5": { "nixpkgs_5": {
"locked": {
"lastModified": 1768564909,
"narHash": "sha256-Kell/SpJYVkHWMvnhqJz/8DqQg2b6PguxVWOuadbHCc=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "e4bae1bd10c9c57b2cf517953ab70060a828ee6f",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_6": {
"locked": { "locked": {
"lastModified": 1775595990, "lastModified": 1775595990,
"narHash": "sha256-OEf7YqhF9IjJFYZJyuhAypgU+VsRB5lD4DuiMws5Ltc=", "narHash": "sha256-OEf7YqhF9IjJFYZJyuhAypgU+VsRB5lD4DuiMws5Ltc=",
@@ -754,7 +830,7 @@
"type": "github" "type": "github"
} }
}, },
"nixpkgs_6": { "nixpkgs_7": {
"locked": { "locked": {
"lastModified": 1767892417, "lastModified": 1767892417,
"narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=", "narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=",
@@ -767,7 +843,7 @@
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz" "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
} }
}, },
"nixpkgs_7": { "nixpkgs_8": {
"locked": { "locked": {
"lastModified": 1786430034, "lastModified": 1786430034,
"narHash": "sha256-Vux08kA5PICwS2sViCMfwVLAHNoH8TkKAeBo25LjpMI=", "narHash": "sha256-Vux08kA5PICwS2sViCMfwVLAHNoH8TkKAeBo25LjpMI=",
@@ -783,7 +859,7 @@
"type": "github" "type": "github"
} }
}, },
"nixpkgs_8": { "nixpkgs_9": {
"locked": { "locked": {
"lastModified": 1781216227, "lastModified": 1781216227,
"narHash": "sha256-9mUW6gNwoN2SWc/l0fW4svPNOulXLl8ijqKyeSOGgJE=", "narHash": "sha256-9mUW6gNwoN2SWc/l0fW4svPNOulXLl8ijqKyeSOGgJE=",
@@ -893,7 +969,7 @@
"flake-compat": "flake-compat_2", "flake-compat": "flake-compat_2",
"flake-parts": "flake-parts_5", "flake-parts": "flake-parts_5",
"mnw": "mnw", "mnw": "mnw",
"nixpkgs": "nixpkgs_8", "nixpkgs": "nixpkgs_9",
"systems": "systems_4" "systems": "systems_4"
}, },
"locked": { "locked": {
@@ -934,14 +1010,16 @@
"awesome-wallpapers": "awesome-wallpapers", "awesome-wallpapers": "awesome-wallpapers",
"blog": "blog", "blog": "blog",
"default-creds": "default-creds", "default-creds": "default-creds",
"disko": "disko",
"git-hooks": "git-hooks", "git-hooks": "git-hooks",
"helium-browser": "helium-browser", "helium-browser": "helium-browser",
"home-manager": "home-manager", "home-manager": "home-manager",
"iknowyou": "iknowyou", "iknowyou": "iknowyou",
"impermanence": "impermanence",
"nix-index-database": "nix-index-database", "nix-index-database": "nix-index-database",
"nixarr": "nixarr", "nixarr": "nixarr",
"nixos-hardware": "nixos-hardware", "nixos-hardware": "nixos-hardware",
"nixpkgs": "nixpkgs_7", "nixpkgs": "nixpkgs_8",
"nixpkgs-unstable": "nixpkgs-unstable", "nixpkgs-unstable": "nixpkgs-unstable",
"notashelf-tuigreet": "notashelf-tuigreet", "notashelf-tuigreet": "notashelf-tuigreet",
"nur": "nur", "nur": "nur",
+5 -1
View File
@@ -35,6 +35,11 @@
url = "github:Mic92/sops-nix"; url = "github:Mic92/sops-nix";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
impermanence.url = "github:nix-community/impermanence";
disko = {
url = "github:nix-community/disko";
inputs.nixpkgs.follows = "nixpkgs";
};
notashelf-tuigreet = { notashelf-tuigreet = {
url = "github:NotAShelf/tuigreet"; url = "github:NotAShelf/tuigreet";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
@@ -92,7 +97,6 @@
apps.${system}.nvim = inputs.nvf-config.apps.${system}.nvim; apps.${system}.nvim = inputs.nvf-config.apps.${system}.nvim;
nixosConfigurations = { nixosConfigurations = {
h-laptop = import ./hosts/laptop/flake.nix args; h-laptop = import ./hosts/laptop/flake.nix args;
h-work = import ./hosts/work/flake.nix args;
jack = import ./hosts/server/flake.nix args; jack = import ./hosts/server/flake.nix args;
}; };
devShells = forAllSystems (system: pkgs: { devShells = forAllSystems (system: pkgs: {
+4
View File
@@ -37,4 +37,8 @@
hash = "sha256-T0XkMHJZQiy63/j25nGTkaiDFjc+blmgEVGTAFgVylU="; hash = "sha256-T0XkMHJZQiy63/j25nGTkaiDFjc+blmgEVGTAFgVylU=";
}; };
}; };
home.persistence."/persist".directories = [
"Cyber"
];
} }
+13 -1
View File
@@ -3,7 +3,8 @@
pkgs-unstable, pkgs-unstable,
... ...
}: { }: {
home.packages = with pkgs-unstable; home = {
packages = with pkgs-unstable;
[ [
go go
claude-code claude-code
@@ -17,4 +18,15 @@
nix-prefetch-github nix-prefetch-github
rsync rsync
]); ]);
persistence."/persist" = {
directories = [
".claude"
];
files = [".claude.json"];
};
sessionPath = ["$HOME/.local/share/go/bin"];
sessionVariables.GOPATH = "$HOME/.local/share/go";
};
} }
@@ -1,7 +1,7 @@
{ {
config, config,
lib, lib,
pkgs-unstable, pkgs,
... ...
}: let }: let
bookmarkList = bookmarkList =
@@ -451,7 +451,7 @@ in {
}; };
Service = { Service = {
Type = "simple"; Type = "simple";
ExecStart = "${pkgs-unstable.darkhttpd}/bin/darkhttpd %h/.local/share/helium-startpage --port 8888 --addr 127.0.0.1 --no-listing"; ExecStart = "${pkgs.darkhttpd}/bin/darkhttpd %h/.local/share/helium-startpage --port 8888 --addr 127.0.0.1 --no-listing";
Restart = "on-failure"; Restart = "on-failure";
}; };
Install.WantedBy = ["default.target"]; Install.WantedBy = ["default.target"];
+4
View File
@@ -136,4 +136,8 @@ in {
categories = ["Network" "WebBrowser"]; categories = ["Network" "WebBrowser"];
mimeType = ["text/html" "text/xml" "application/xhtml+xml"]; mimeType = ["text/html" "text/xml" "application/xhtml+xml"];
}; };
home.persistence."/persist".directories = [
".config/net.imput.helium"
];
} }
+8 -2
View File
@@ -6,12 +6,18 @@
resources # Resource monitor resources # Resource monitor
gnome-clocks # Clocks app gnome-clocks # Clocks app
gnome-text-editor # Basic graphic text editor gnome-text-editor # Basic graphic text editor
ticktick # Todo app
pinta # Image editor pinta # Image editor
switcheroo # Convert images between different formats switcheroo # Convert images between different formats
onlyoffice-desktopeditors # Office suite onlyoffice-desktopeditors # Office suite
blanket # Listen to different sounds blanket # Listen to different sounds
signal-desktop # Messaging app
thunar # File explorer thunar # File explorer
signal-desktop # Messaging app
ticktick # Todo app
];
home.persistence."/persist".directories = [
".config/ticktick"
".config/Signal"
]; ];
} }
+5 -9
View File
@@ -6,19 +6,10 @@
home.packages = with pkgs; [ home.packages = with pkgs; [
proton-vpn proton-vpn
proton-pass proton-pass
proton-authenticator
]; ];
# Fix Proton Authenticator desktop entry # Fix Proton Authenticator desktop entry
xdg.desktopEntries = { xdg.desktopEntries = {
"Proton Authenticator" = {
name = "Proton Authenticator";
exec = "env WEBKIT_DISABLE_COMPOSITING_MODE=1 ${pkgs.proton-authenticator}/bin/proton-authenticator";
icon = "proton-authenticator";
type = "Application";
categories = ["Utility"];
terminal = false;
};
"Proton Calendar" = { "Proton Calendar" = {
name = "Proton Calendar"; name = "Proton Calendar";
exec = ''${config.programs.helium.package}/bin/helium "https://calendar.proton.me"''; exec = ''${config.programs.helium.package}/bin/helium "https://calendar.proton.me"'';
@@ -36,4 +27,9 @@
terminal = false; terminal = false;
}; };
}; };
home.persistence."/persist".directories = [
".config/protonvpn"
".config/Proton Pass"
];
} }
+15
View File
@@ -66,6 +66,21 @@ in {
categories = ["System" "FileManager" "FileTools" "ConsoleOnly"]; categories = ["System" "FileManager" "FileTools" "ConsoleOnly"];
}; };
xdg.configFile."elio/config.toml".text = ''
[places]
entries = [
"home",
"documents",
"downloads",
"pictures",
{ title = "Notes", path = "~/Notes" },
{ title = "Cyber", path = "~/Cyber" },
{ title = "Projects", path = "~/Projects" },
{ title = "NixOS Config", path = "~/.config/nixos" },
"trash",
]
'';
xdg.configFile."elio/theme.toml".text = '' xdg.configFile."elio/theme.toml".text = ''
[palette] [palette]
bg = "#${c.base00}" bg = "#${c.base00}"
+2
View File
@@ -36,4 +36,6 @@
cmatrix cmatrix
fastfetch fastfetch
]; ];
home.persistence."/persist".directories = [".config/gh" ".config/gh-dash"];
} }
+2 -2
View File
@@ -11,11 +11,11 @@
]; ];
home = { home = {
sessionPath = ["$HOME/go/bin"];
sessionVariables = { sessionVariables = {
COLORTERM = "truecolor"; COLORTERM = "truecolor";
MANPAGER = "bat -l man -p"; MANPAGER = "bat -l man -p";
}; };
persistence."/persist".files = [".zsh_history"];
}; };
programs.zsh = { programs.zsh = {
@@ -72,7 +72,7 @@
spt = "spotatui"; spt = "spotatui";
open = "${pkgs.xdg-utils}/bin/xdg-open"; open = "${pkgs.xdg-utils}/bin/xdg-open";
notes = "nvim ~/notes/index.md --cmd 'cd ~/notes' -c ':lua Snacks.picker.smart()'"; notes = "nvim ~/Notes/index.md --cmd 'cd ~/notes' -c ':lua Snacks.picker.smart()'";
# git # git
g = "lazygit"; g = "lazygit";
+2
View File
@@ -11,6 +11,8 @@ in {
spotatui spotatui
]; ];
home.persistence."/persist".directories = [".config/spotatui" ".config/spotify"];
home.file.".config/spotatui/config.yml".text = '' home.file.".config/spotatui/config.yml".text = ''
keybindings: keybindings:
back: q back: q
+3
View File
@@ -133,6 +133,9 @@ in {
"match:class helium, suppress_event fullscreen" "match:class helium, suppress_event fullscreen"
"match:class helium, sync_fullscreen false" "match:class helium, sync_fullscreen false"
"match:class ^(steam_app_.*)$, suppress_event fullscreen"
"match:class ^(steam_app_.*)$, sync_fullscreen false"
"match:class proton-authenticator, float on" "match:class proton-authenticator, float on"
"match:class proton-authenticator, center on" "match:class proton-authenticator, center on"
"match:class proton-authenticator, size 500 400" "match:class proton-authenticator, size 500 400"
+5
View File
@@ -1,4 +1,5 @@
{ {
config,
lib, lib,
pkgs, pkgs,
... ...
@@ -147,6 +148,10 @@ in {
music = null; music = null;
publicShare = null; publicShare = null;
templates = null; templates = null;
extraConfig = {
NOTES = "${config.home.homeDirectory}/Notes";
CYBER = "${config.home.homeDirectory}/Cyber";
};
}; };
}; };
} }
+1 -1
View File
@@ -7,7 +7,7 @@
runtimeInputs = with pkgs; [procps coreutils]; runtimeInputs = with pkgs; [procps coreutils];
text = '' text = ''
printf '%s' "$1" > /tmp/waybar-osd printf '%s' "$1" > /tmp/waybar-osd
pkill -x -RTMIN+8 waybar 2>/dev/null || true pkill -f -RTMIN+8 '^waybar$' 2>/dev/null || true
''; '';
}; };
+9 -34
View File
@@ -12,50 +12,25 @@
../../nixos/users.nix ../../nixos/users.nix
../../nixos/utils.nix ../../nixos/utils.nix
../../nixos/hyprland.nix ../../nixos/hyprland.nix
../../nixos/usbguard.nix ../../nixos/steam.nix
../../home/programs/gui/helium/system.nix # I hate browser's configuration.. ../../home/programs/gui/helium/system.nix # I hate browser's configuration..
../../nixos/omen.nix # CHANGEME: For my laptop only, remove this (OMEN 16) # CHANGEME: You should probably remove those things:
./wireguard.nix
./wireguard.nix # CHANGEME: For my laptop only ./persistence.nix # impermanence: what to keep once "/" is wiped on boot
./usbguard.nix
./disko.nix
./secrets
# You should let those lines as is # You should let those lines as is
./hardware-configuration.nix ./hardware-configuration.nix
./variables.nix ./variables.nix
]; ];
# USBGuard:
# Allow all USB devices until a proper policy is configured.
# Run `sudo usbguard generate-policy` with your devices plugged in,
# then set rules = "<output>" and switch implicitPolicyTarget to "block".
# services.usbguard.implicitPolicyTarget = lib.mkForce "allow";
services.usbguard.rules = ''
allow id 1d6b:0002 serial "0000:05:00.3" name "xHCI Host Controller" hash "4a4NgfdUaJO43rkCzmWRSeHHR/uUh5+SNsXnhosm9qs=" parent-hash "ldMchY4Tt4GPUYo30eNGvai+Fs/EdnVY3vMyxJUq4Nk=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0003 serial "0000:05:00.3" name "xHCI Host Controller" hash "d+DNGWARDtv9nEK2ZvnNOCtFernuMu5/e/oZ7kCppqQ=" parent-hash "ldMchY4Tt4GPUYo30eNGvai+Fs/EdnVY3vMyxJUq4Nk=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0002 serial "0000:05:00.4" name "xHCI Host Controller" hash "icotY3rI59mWiKsGxc59BGZZeBjfbuH0b4NUByj3cbQ=" parent-hash "tHvBfznK5rpQn+oa0PEEjHa29EAEvGyCcZixsfwA6W0=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0003 serial "0000:05:00.4" name "xHCI Host Controller" hash "UbEoCZW8HT2ldc3qDeiK+IiQlGeaBC7F63681OwmKhI=" parent-hash "tHvBfznK5rpQn+oa0PEEjHa29EAEvGyCcZixsfwA6W0=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0002 serial "0000:07:00.3" name "xHCI Host Controller" hash "pz29Oo0RhQ+5+7LgOZR4v3OlcsVv3m9kCgGsGUnoUjI=" parent-hash "DRyV2/31MYHdzkIEfbPQeb/1w4/PjOW6GqWrXkftf2I=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0003 serial "0000:07:00.3" name "xHCI Host Controller" hash "O6iOpcl9StImWT62SrbeXacqbG6N/mTIipTRc0ipCGM=" parent-hash "DRyV2/31MYHdzkIEfbPQeb/1w4/PjOW6GqWrXkftf2I=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0002 serial "0000:07:00.4" name "xHCI Host Controller" hash "Hp8B0Enf+ACRT2tyy0EqXj7eNsFDAnTRZadzuh/Iqd4=" parent-hash "l2vhvC+VGVKlkBUUK/usFu8jHJ/5bWOnJG6WzRexpt4=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0003 serial "0000:07:00.4" name "xHCI Host Controller" hash "rJ3LKdvkCK3SUrCU3lV8qVbmPjA+r9Fe5106x2HlgK4=" parent-hash "l2vhvC+VGVKlkBUUK/usFu8jHJ/5bWOnJG6WzRexpt4=" with-interface 09:00:00 with-connect-type ""
allow id 0bda:c85c serial "00e04c000001" name "Bluetooth Radio" hash "Q/wlToV8WQgEYHBW/UIhnSwCCusCGqAR2D5gspSCImQ=" parent-hash "4a4NgfdUaJO43rkCzmWRSeHHR/uUh5+SNsXnhosm9qs=" with-interface { e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 } with-connect-type "hardwired"
allow id 30c9:009f serial "01.00.00" name "HP True Vision FHD Camera" hash "eYW5fqReJd29tfHXkEktKC63dGfDpmlRMo5uMGUWwME=" parent-hash "icotY3rI59mWiKsGxc59BGZZeBjfbuH0b4NUByj3cbQ=" with-interface { 0e:01:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 fe:01:01 } with-connect-type "hardwired"
allow id 03f0:036b serial "" name "HP USB-C Dock G5" hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" parent-hash "Hp8B0Enf+ACRT2tyy0EqXj7eNsFDAnTRZadzuh/Iqd4=" via-port "7-1" with-interface { 09:00:01 09:00:02 } with-connect-type "hotplug"
allow id 03f0:066b serial "" name "HP USB-C Dock G5" hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" parent-hash "rJ3LKdvkCK3SUrCU3lV8qVbmPjA+r9Fe5106x2HlgK4=" via-port "8-1" with-interface 09:00:00 with-connect-type "hotplug"
allow id 03f0:056b serial "201604140001" name "USB Audio" hash "OxQ8HQenW3/4HSGEBOSYFS15rXDTOaNDnjMbICweHgw=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" with-interface { 01:01:00 01:02:00 01:02:00 01:02:00 01:02:00 03:00:00 } with-connect-type "unknown"
allow id 03f0:086b serial "" name "USB2734" hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" via-port "7-1.3" with-interface { 09:00:01 09:00:02 } with-connect-type "unknown"
allow id 03f0:046b serial "11AD1D0A89EA2D08310E0B00" name "HP USB-C Dock G5" hash "DEGeuj1u4lwqrzp0UksFX7mSEY9JnGLxg7yxGbglAKE=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" with-interface { 11:00:00 ff:03:00 03:00:00 } with-connect-type "unknown"
allow id 03f0:076b serial "" name "USB5734" hash "BshoqybYo0IKgoDORYPRtbhhlmQrYAxPQb2EAm1JsWA=" parent-hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" via-port "8-1.3" with-interface 09:00:00 with-connect-type "unknown"
allow id 0bda:8153 serial "000001000000" name "USB 10/100/1000 LAN" hash "utEnXKJ57kRUbPcGUaNWhEyoOEbLOYAFxvlsyC0PZkk=" parent-hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" with-interface { ff:ff:00 02:06:00 0a:00:00 0a:00:00 } with-connect-type "unknown"
allow id 046d:0ab7 serial "2046BAB04T68" name "Blue Microphones" hash "cC6AQ2e1Q/BeFeostpbf1mH2WpoUmt6bhau4NlA3niU=" parent-hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" with-interface { 01:01:00 01:02:00 01:02:00 01:02:00 01:02:00 01:02:00 01:02:00 03:00:00 } with-connect-type "unknown"
allow id 13fd:5900 serial "50026B76861EE752 " name "External" hash "l/QvVV5hzZj1z6OUwB/kWl+WnH/7awrdMBoiNVx660M=" parent-hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" with-interface { 08:06:50 08:06:62 } with-connect-type "unknown"
allow id 1532:02a1 name "Razer Ornata V3"
allow id 03f0:066b name "HP USB-C Dock G5"
'';
home-manager.users."${config.var.username}" = import ./home.nix; home-manager.users."${config.var.username}" = import ./home.nix;
users.users.${config.var.username}.hashedPasswordFile = config.sops.secrets.hashedPassword.path;
# Don't touch this # Don't touch this
system.stateVersion = "26.05"; system.stateVersion = "26.05";
} }
+56
View File
@@ -0,0 +1,56 @@
{
disko.devices = {
nodev = {
"/" = {
fsType = "tmpfs";
mountOptions = [
"defaults"
"size=12G"
"mode=755"
];
};
};
disk = {
boot = {
type = "disk";
device = "/dev/disk/by-uuid/5251-9B85";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = ["fmask=0077" "dmask=0077"];
};
};
nixos = {
type = "disk";
device = "/dev/disk/by-uuid/e3110976-78ee-4868-94c4-a3c052aee359";
content = {
type = "luks";
name = "crypted";
settings = {
allowDiscards = true;
bypassWorkqueues = true;
};
content = {
type = "btrfs";
extraArgs = ["-f"];
subvolumes = {
"/nix" = {
mountpoint = "/nix";
mountOptions = ["compress=zstd" "noatime"];
};
"/persist" = {
mountpoint = "/persist";
mountOptions = ["compress=zstd" "noatime"];
};
};
};
};
};
};
};
fileSystems."/persist".neededForBoot = true;
}
+3
View File
@@ -18,6 +18,9 @@ nixpkgs.lib.nixosSystem {
inputs.sops-nix.nixosModules.sops inputs.sops-nix.nixosModules.sops
inputs.nix-index-database.nixosModules.default inputs.nix-index-database.nixosModules.default
inputs.helium-browser.nixosModules.default inputs.helium-browser.nixosModules.default
inputs.impermanence.nixosModules.impermanence
inputs.disko.nixosModules.disko
./disko.nix
./configuration.nix ./configuration.nix
]; ];
} }
+2 -33
View File
@@ -1,6 +1,4 @@
# Do not modify this file! It was generated by nixos-generate-config # Hardware detection - filesystems are managed by disko.nix
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ {
config, config,
lib, lib,
@@ -11,42 +9,13 @@
(modulesPath + "/installer/scan/not-detected.nix") (modulesPath + "/installer/scan/not-detected.nix")
]; ];
boot.initrd.availableKernelModules = [ boot.initrd.availableKernelModules = ["nvme" "xhci_pci" "usb_storage" "usbhid" "uas" "sd_mod"];
"nvme"
"xhci_pci"
"uas"
"usbhid"
"sd_mod"
];
boot.initrd.kernelModules = []; boot.initrd.kernelModules = [];
boot.kernelModules = ["kvm-amd"]; boot.kernelModules = ["kvm-amd"];
boot.extraModulePackages = []; boot.extraModulePackages = [];
fileSystems."/" = {
device = "/dev/disk/by-uuid/6320d3c6-0231-45ec-817a-c6f0e39aab73";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/5251-9B85";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = []; swapDevices = [];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.eno1.useDHCP = lib.mkDefault true;
# networking.interfaces.enp7s0f4u1u4.useDHCP = lib.mkDefault true;
# networking.interfaces.wlo1.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
} }
+19 -3
View File
@@ -42,14 +42,30 @@
../../home/system/hypridle ../../home/system/hypridle
./variables.nix # Mostly user-specific configuration ./variables.nix # Mostly user-specific configuration
./secrets # CHANGEME: You should probably remove this line, this is where I store my secrets
]; ];
home = { home = {
inherit (config.var) username; inherit (config.var) username;
homeDirectory = "/home/" + config.var.username; homeDirectory = "/home/" + config.var.username;
file.".face" = {
source = ./profile_picture.png; persistence."/persist" = {
directories = [
".config/nixos" # this repo itself (nixy manages it here)
".local/share"
".local/state"
".cache"
"Notes"
"Projects"
"Documents"
"Downloads"
"Pictures"
"Videos"
];
files = [
".ssh/known_hosts"
".config/sops/age/keys.txt"
];
}; };
sessionVariables = { sessionVariables = {
+37
View File
@@ -0,0 +1,37 @@
# Impermanence: declares what should survive a wipe of "/".
{config, ...}: {
environment.persistence."/persist" = {
hideMounts = true;
directories = [
"/etc/NetworkManager/system-connections" # Wifi connections, VPN
"/var/lib/bluetooth" # Bluetooth connections
"/var/lib/nixos" # keeps uid/gid stable across boots
"/var/lib/systemd/coredump"
"/var/lib/upower" # battery calibration state
"/var/lib/systemd/backlight" # remembers screen brightness
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
"/var/log"
"/var/cache/tuigreet"
];
files = [
"/etc/machine-id"
"/etc/ssh/ssh_host_ed25519_key"
"/etc/ssh/ssh_host_ed25519_key.pub"
"/etc/ssh/ssh_host_rsa_key"
"/etc/ssh/ssh_host_rsa_key.pub"
"/var/lib/systemd/random-seed" # avoid a weak entropy pool on first boot
];
};
# -- How to find what's missing --
# Use the system normally for a week or two, then look for files that
# changed recently outside of what's already declared above:
# find "/home/${config.var.username}" -xdev -type f -mtime -14 \
# -not -path '*/.cache/*' -not -path '*/Cache/*' | less
# Anything that keeps showing up there (app state, history files,
# game saves, browser profile, spotify/lazygit config, GPG state, etc.)
# is a candidate to add above. Do this *before* switching root to a
# wipeable filesystem, not after.
}
Binary file not shown.

Before

Width:  |  Height:  |  Size: 12 KiB

+16 -30
View File
@@ -1,62 +1,48 @@
# Those are my secrets, encrypted with sops # Those are my secrets, encrypted with sops
# You shouldn't import this file, unless you edit it # You shouldn't import this file, unless you edit it
{ {
inputs,
pkgs, pkgs,
config, config,
... ...
}: let }: let
home = config.home.homeDirectory; username = config.var.username;
home = "/home/${username}";
in { in {
imports = [inputs.sops-nix.homeManagerModules.sops];
sops = { sops = {
age.keyFile = "${home}/.config/sops/age/keys.txt"; age.keyFile = "${home}/.config/sops/age/keys.txt";
defaultSopsFile = ./secrets.yaml; defaultSopsFile = ./secrets.yaml;
secrets = { secrets = {
hashedPassword.neededForUsers = true;
ssh-config = { ssh-config = {
owner = username;
path = "${home}/.ssh/config"; path = "${home}/.ssh/config";
}; };
github-key = { ssh-github-key = {
owner = username;
path = "${home}/.ssh/github"; path = "${home}/.ssh/github";
}; };
jack-key = { anotherhadi-pgp-key = {
owner = username;
path = "${home}/.ssh/anotherhadi-priv.asc";
};
ssh-jack-key = {
owner = username;
path = "${home}/.ssh/jack"; path = "${home}/.ssh/jack";
}; };
signing-key = { signing-key = {
owner = username;
path = "${home}/.ssh/key"; path = "${home}/.ssh/key";
}; };
signing-pub-key = { signing-pub-key = {
owner = username;
path = "${home}/.ssh/key.pub"; path = "${home}/.ssh/key.pub";
}; };
}; };
}; };
home.file.".config/nixos/.sops.yaml".text = '' environment.systemPackages = with pkgs; [
keys:
- &primary age12yvtj49pfh3fqzqflscm0ek4yzrjhr6cqhn7x89gdxnlykq0xudq5c7334
- &work age1c8pawdsxptfslgrz2c56s39mrtnjzc5mm3hfzgr2wdwu2v6vfsdsupjsq6
creation_rules:
- path_regex: hosts/laptop/secrets/secrets.yaml$
key_groups:
- age:
- *primary
- path_regex: hosts/server/secrets/secrets.yaml$
key_groups:
- age:
- *primary
- path_regex: hosts/work/secrets/secrets.yaml$
key_groups:
- age:
- *work
'';
home.packages = with pkgs; [
sops sops
age age
]; ];
wayland.windowManager.hyprland.settings.exec-once = [
"systemctl --user start sops-nix"
];
} }
File diff suppressed because one or more lines are too long
+37
View File
@@ -0,0 +1,37 @@
# USBGuard:
# The following line allow all USB devices until a proper policy is configured.
# Run `sudo usbguard generate-policy` with your devices plugged in,
# then set rules = "<output>" and switch implicitPolicyTarget to "block".
# services.usbguard.implicitPolicyTarget = lib.mkForce "allow";
{
services.usbguard = {
enable = true;
implicitPolicyTarget = "block";
IPCAllowedUsers = [
"root"
];
rules = ''
allow id 1d6b:0002 serial "0000:05:00.3" name "xHCI Host Controller" hash "4a4NgfdUaJO43rkCzmWRSeHHR/uUh5+SNsXnhosm9qs=" parent-hash "ldMchY4Tt4GPUYo30eNGvai+Fs/EdnVY3vMyxJUq4Nk=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0003 serial "0000:05:00.3" name "xHCI Host Controller" hash "d+DNGWARDtv9nEK2ZvnNOCtFernuMu5/e/oZ7kCppqQ=" parent-hash "ldMchY4Tt4GPUYo30eNGvai+Fs/EdnVY3vMyxJUq4Nk=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0002 serial "0000:05:00.4" name "xHCI Host Controller" hash "icotY3rI59mWiKsGxc59BGZZeBjfbuH0b4NUByj3cbQ=" parent-hash "tHvBfznK5rpQn+oa0PEEjHa29EAEvGyCcZixsfwA6W0=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0003 serial "0000:05:00.4" name "xHCI Host Controller" hash "UbEoCZW8HT2ldc3qDeiK+IiQlGeaBC7F63681OwmKhI=" parent-hash "tHvBfznK5rpQn+oa0PEEjHa29EAEvGyCcZixsfwA6W0=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0002 serial "0000:07:00.3" name "xHCI Host Controller" hash "pz29Oo0RhQ+5+7LgOZR4v3OlcsVv3m9kCgGsGUnoUjI=" parent-hash "DRyV2/31MYHdzkIEfbPQeb/1w4/PjOW6GqWrXkftf2I=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0003 serial "0000:07:00.3" name "xHCI Host Controller" hash "O6iOpcl9StImWT62SrbeXacqbG6N/mTIipTRc0ipCGM=" parent-hash "DRyV2/31MYHdzkIEfbPQeb/1w4/PjOW6GqWrXkftf2I=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0002 serial "0000:07:00.4" name "xHCI Host Controller" hash "Hp8B0Enf+ACRT2tyy0EqXj7eNsFDAnTRZadzuh/Iqd4=" parent-hash "l2vhvC+VGVKlkBUUK/usFu8jHJ/5bWOnJG6WzRexpt4=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0003 serial "0000:07:00.4" name "xHCI Host Controller" hash "rJ3LKdvkCK3SUrCU3lV8qVbmPjA+r9Fe5106x2HlgK4=" parent-hash "l2vhvC+VGVKlkBUUK/usFu8jHJ/5bWOnJG6WzRexpt4=" with-interface 09:00:00 with-connect-type ""
allow id 0bda:c85c serial "00e04c000001" name "Bluetooth Radio" hash "Q/wlToV8WQgEYHBW/UIhnSwCCusCGqAR2D5gspSCImQ=" parent-hash "4a4NgfdUaJO43rkCzmWRSeHHR/uUh5+SNsXnhosm9qs=" with-interface { e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 } with-connect-type "hardwired"
allow id 30c9:009f serial "01.00.00" name "HP True Vision FHD Camera" hash "eYW5fqReJd29tfHXkEktKC63dGfDpmlRMo5uMGUWwME=" parent-hash "icotY3rI59mWiKsGxc59BGZZeBjfbuH0b4NUByj3cbQ=" with-interface { 0e:01:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 fe:01:01 } with-connect-type "hardwired"
allow id 03f0:036b serial "" name "HP USB-C Dock G5" hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" parent-hash "Hp8B0Enf+ACRT2tyy0EqXj7eNsFDAnTRZadzuh/Iqd4=" via-port "7-1" with-interface { 09:00:01 09:00:02 } with-connect-type "hotplug"
allow id 03f0:066b serial "" name "HP USB-C Dock G5" hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" parent-hash "rJ3LKdvkCK3SUrCU3lV8qVbmPjA+r9Fe5106x2HlgK4=" via-port "8-1" with-interface 09:00:00 with-connect-type "hotplug"
allow id 03f0:056b serial "201604140001" name "USB Audio" hash "OxQ8HQenW3/4HSGEBOSYFS15rXDTOaNDnjMbICweHgw=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" with-interface { 01:01:00 01:02:00 01:02:00 01:02:00 01:02:00 03:00:00 } with-connect-type "unknown"
allow id 03f0:086b serial "" name "USB2734" hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" via-port "7-1.3" with-interface { 09:00:01 09:00:02 } with-connect-type "unknown"
allow id 03f0:046b serial "11AD1D0A89EA2D08310E0B00" name "HP USB-C Dock G5" hash "DEGeuj1u4lwqrzp0UksFX7mSEY9JnGLxg7yxGbglAKE=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" with-interface { 11:00:00 ff:03:00 03:00:00 } with-connect-type "unknown"
allow id 03f0:076b serial "" name "USB5734" hash "BshoqybYo0IKgoDORYPRtbhhlmQrYAxPQb2EAm1JsWA=" parent-hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" via-port "8-1.3" with-interface 09:00:00 with-connect-type "unknown"
allow id 0bda:8153 serial "000001000000" name "USB 10/100/1000 LAN" hash "utEnXKJ57kRUbPcGUaNWhEyoOEbLOYAFxvlsyC0PZkk=" parent-hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" with-interface { ff:ff:00 02:06:00 0a:00:00 0a:00:00 } with-connect-type "unknown"
allow id 046d:0ab7 serial "2046BAB04T68" name "Blue Microphones" hash "cC6AQ2e1Q/BeFeostpbf1mH2WpoUmt6bhau4NlA3niU=" parent-hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" with-interface { 01:01:00 01:02:00 01:02:00 01:02:00 01:02:00 01:02:00 01:02:00 03:00:00 } with-connect-type "unknown"
allow id 13fd:5900 serial "50026B76861EE752 " name "External" hash "l/QvVV5hzZj1z6OUwB/kWl+WnH/7awrdMBoiNVx660M=" parent-hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" with-interface { 08:06:50 08:06:62 } with-connect-type "unknown"
allow id 1532:02a1 name "Razer Ornata V3"
allow id 03f0:066b name "HP USB-C Dock G5"
'';
};
}
-3
View File
@@ -36,10 +36,7 @@ in {
]; ];
sops = { sops = {
age.keyFile = "/home/hadi/.config/sops/age/keys.txt";
defaultSopsFile = ./secrets/secrets.yaml;
secrets.wireguard-private-key = {}; secrets.wireguard-private-key = {};
templates."wg-vpn.nmconnection" = { templates."wg-vpn.nmconnection" = {
path = "/etc/NetworkManager/system-connections/wg-vpn.nmconnection"; path = "/etc/NetworkManager/system-connections/wg-vpn.nmconnection";
mode = "0600"; mode = "0600";
-41
View File
@@ -1,41 +0,0 @@
{config, ...}: {
imports = [
# Mostly system related configuration
../../nixos/audio.nix
../../nixos/fonts.nix
../../nixos/home-manager.nix
../../nixos/nix.nix
../../nixos/systemd-boot.nix
../../nixos/tuigreet.nix
../../nixos/usbguard.nix
../../nixos/users.nix
../../nixos/utils.nix
../../nixos/hyprland.nix
../../nixos/docker.nix
../../home/programs/gui/helium/system.nix # I hate browser's configuration..
# You should let those lines as is
./hardware-configuration.nix
./variables.nix
];
home-manager.users."${config.var.username}" = import ./home.nix;
# USBGuard:
# Allow all USB devices until a proper policy is configured.
# Run `sudo usbguard generate-policy` with your devices plugged in,
# then set rules = "<output>" and switch implicitPolicyTarget to "block".
# services.usbguard.implicitPolicyTarget = lib.mkForce "allow";
services.usbguard.rules = ''
allow id 1d6b:0002 serial "0000:00:14.0" name "xHCI Host Controller" hash "jEP/6WzviqdJ5VSeTUY8PatCNBKeaREvo2OqdplND/o=" parent-hash "rV9bfLq7c2eA4tYjVjwO4bxhm+y6GgZpl9J60L0fBkY=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0003 serial "0000:00:14.0" name "xHCI Host Controller" hash "prM+Jby/bFHCn2lNjQdAMbgc6tse3xVx+hZwjOPHSdQ=" parent-hash "rV9bfLq7c2eA4tYjVjwO4bxhm+y6GgZpl9J60L0fBkY=" with-interface 09:00:00 with-connect-type ""
allow id 17ef:6190 serial "" name "Lenovo Calliope USB Keyboard G2" hash "CfZ9R/aoXGm7BN/ojVEzKQwVoxCUtRWMuACrE7BL/5Y=" parent-hash "jEP/6WzviqdJ5VSeTUY8PatCNBKeaREvo2OqdplND/o=" via-port "1-10" with-interface { 03:01:01 03:00:00 } with-connect-type "hotplug"
allow id 0781:5581 name " SanDisk 3.2Gen1"
allow id 17ef:608d name "Lenovo USB Optical Mouse"
'';
networking.firewall.allowedTCPPorts = [9001];
# Don't touch this
system.stateVersion = "26.05";
}
-21
View File
@@ -1,21 +0,0 @@
{
inputs,
nixpkgs,
pkgs-unstable,
...
}:
nixpkgs.lib.nixosSystem {
modules = [
{
nixpkgs.overlays = [
inputs.nur.overlays.default
];
_module.args = {inherit inputs pkgs-unstable;};
}
inputs.home-manager.nixosModules.home-manager
inputs.stylix.nixosModules.stylix
inputs.nix-index-database.nixosModules.default
inputs.helium-browser.nixosModules.default
./configuration.nix
];
}
-44
View File
@@ -1,44 +0,0 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{
config,
lib,
modulesPath,
...
}: {
imports = [
(modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [
"xhci_pci"
"ahci"
"nvme"
"usb_storage"
"usbhid"
"sd_mod"
];
boot.initrd.kernelModules = [];
boot.kernelModules = ["kvm-intel"];
boot.extraModulePackages = [];
fileSystems."/" = {
device = "/dev/disk/by-uuid/5dbf85d3-d236-4af8-b489-d6066bfe1eb7";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/043E-1755";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
-64
View File
@@ -1,64 +0,0 @@
{
config,
inputs,
...
}: {
imports = [
# Programs
## GUI
../../home/programs/gui/proton
../../home/programs/gui/helium
../../home/programs/gui/pkgs.nix
## TUI
inputs.nvf-config.homeManagerModules.default
../../home/programs/tui/ghostty
../../home/programs/tui/shell
../../home/programs/tui/git
../../home/programs/tui/git/lazygit.nix
../../home/programs/tui/nixy
../../home/programs/tui/nix-utils
../../home/programs/tui/spotatui
../../home/programs/tui/pkgs.nix
## GROUPS
../../home/programs/group/cybersecurity.nix
../../home/programs/group/dev.nix
# System (Desktop environment like stuff)
../../home/system/hyprlock
../../home/system/hyprland
../../home/system/waybar
../../home/system/swaync
../../home/system/tofi
../../home/system/mime
../../home/system/termfilechooser
../../home/system/udiskie
../../home/system/clipboard
../../home/system/hypridle
./variables.nix # Mostly user-specific configuration
./secrets # CHANGEME: You should probably remove this line, this is where I store my secrets
];
home = {
inherit (config.var) username;
homeDirectory = "/home/" + config.var.username;
# Don't touch this
stateVersion = "26.05";
};
wayland.windowManager.hyprland.settings.monitor = [
"desc:Philips Consumer Electronics Company PHL 221B8L ZV02144013987,highres,0x0,1"
];
programs = {
home-manager.enable = true;
nixy = {
enable = true;
configDirectory = config.var.configDirectory;
};
};
}
-59
View File
@@ -1,59 +0,0 @@
# Those are my secrets, encrypted with sops
# You shouldn't import this file, unless you edit it
{
inputs,
pkgs,
config,
...
}: let
home = config.home.homeDirectory;
in {
imports = [inputs.sops-nix.homeManagerModules.sops];
sops = {
age.keyFile = "${home}/.config/sops/age/keys.txt";
defaultSopsFile = ./secrets.yaml;
secrets = {
ssh-config = {
path = "${home}/.ssh/config";
};
netrc = {
path = "${home}/.netrc";
};
github-key = {
path = "${home}/.ssh/github";
};
gitlab-key = {
path = "${home}/.ssh/gitlab";
};
};
};
home.file.".config/nixos/.sops.yaml".text = ''
keys:
- &primary age12yvtj49pfh3fqzqflscm0ek4yzrjhr6cqhn7x89gdxnlykq0xudq5c7334
- &work age1c8pawdsxptfslgrz2c56s39mrtnjzc5mm3hfzgr2wdwu2v6vfsdsupjsq6
creation_rules:
- path_regex: hosts/laptop/secrets/secrets.yaml$
key_groups:
- age:
- *primary
- path_regex: hosts/server/secrets/secrets.yaml$
key_groups:
- age:
- *primary
- path_regex: hosts/work/secrets/secrets.yaml$
key_groups:
- age:
- *work
'';
home.packages = with pkgs; [
sops
age
];
wayland.windowManager.hyprland.settings.exec-once = [
"systemctl --user start sops-nix"
];
}
-19
View File
@@ -1,19 +0,0 @@
ssh-config: ENC[AES256_GCM,data:npBcAOSwHpApUASlZmRo4stwMrOjdrdmhfYwumjbTpcq8aQ2ybV8le7cjNdVqIyxgwxUFV4/tGfmsq4nlrWIO/85spwfC5DyPGaZ848NI3UZJj8k2GKuw5qk/xGsTveNhq+vNZQcHeL4aeXF2TRmFLDHYGTku9anFL7FWkQ75MmGW78XfPUEyZJ52ylXq3gkYeVSrl6cXuwJw/QBlu+XTgFk4MM+E5BTXBFFNJOYkIt4GwWX7wdI+QqPEof8J0ENYdxUAMKMueL4pLNclWP0fu7QC7gwwRJWjauCNElJiDhpVFa6WukJV/Ut+I30FH9cJtj0rSodeu0hq2fWaiQ0wVbQudxi0JcnxJQs+B9nb6kpF+TN0MiD,iv:c7DMZSmlgMMnNlR0/kNRKPYjCzvNQJ46mZzojHppSg8=,tag:ausjsFk0H9nOiiMebHXSUg==,type:str]
netrc: ENC[AES256_GCM,data:EOpuZhDVXe7Q4P/98C3gtEvkdawI26d4oX/wRNytyp/mAdkHytXiLpFdsuO/3DADOG8h1CCo1UTs9ex+bqoD/LdChdp7INfNDSQ+aDxTiG0rLBgjvy8TIj8=,iv:tc/RbN1Upbjv+3rU5zUR3P//a1Hj1xODInLMShg4i1Y=,tag:7E9G2g4g+eMeJrwI20R/1g==,type:str]
github-key: ENC[AES256_GCM,data:LRgJxUcKvLiqVJ3acz88oGp5qmvbo7QiyTbcft3YwZr+84CLbty9GCMrryJ8DFnP8GCGh+cCQxyvk/n/hA71qz7WZ6vIWbTN2byP0LHwDtQpugYOQi9z1Q04hQU3DYnsqKS8hu6bnUV/SzrDpAOXugyMGZL5dITitidgEsVG5PxB+bzTZGhg7EOcZISz955AEtD+bGedvxaryEcMYPTZwRHYPl2+wvKKIbeZMiup6i0BCCYktUUIb3qSBawbknZ9nfbQFODkZbNuEEhyU2MITz2ajQEx8AjE4eUutjBBQpJsesIhiAyq5H1AmJDzesC4iccFUpTVHFWf20clPX9QTH5njqbJ+aw1hIzU2ljK3vou1eZfoZ5HCdV3+tuQTJGYcfFY29/PaN4sENPhgbYm0p9Ui4UlMbte3FfmhSqdMzIc8jIB8dPMtoUM/NTjxof/dVu/TPMBTqnJplzNgvH1r2UcPToiAVfWj96tXsr2ESZfE9q9oQh9EGMcyGpXxq06Gni4tOnXDaF3oHyWAiJ6jP/wrYag5/67m4DwpFEymg+/ROKcy2ou3MYA+748ocKYFRoOVfY+SwcM4bxl6smstsRZW8SoDo6O9ikZII51LIN7X/6sQ0L+dgsBTT75zm8DOAFx2tnVgSPN8HYsd2tyHA3L6pYxAAGmY6lSGJfgmYP8hForSuZgCSxWhlwPHLLrU14A2wOFw+X5b4Zgy2ZdsTv3pHDn35a8lNwANKiWhXSc/irie0enmNjKyKTQDcVxq65mho2D+q7XANjDYtqQ8VX93HD2mLNljuA5GjJxtlTrw6V80AI9OiKjMlbEIG5BHIwOcDj5z53kZ2hPHIlSMCXVBXgBwZgPzw2GXDnIgsLFtGirVj/H+N8IWUioUgyimLjygPJwk8lcIrRCA279O7PnFAQKW3gchs4BN76vF41dR5AVJrDeWmSRonMHZEmGaHONEy+8pxFYf+u7hI6dC6YwrhNYHFgKymtKoYCGS1VTi3MXVPxzL4KxnS+StgfDqzf/FypqGD+c9Qkz3THw01J5SyQO4r7Y7cJFhpRvF09uDvT55BtUVuxexOUxANsmbzJCSKG0GLEWa6e+8owLHRbUh5fQQHN4WVMOCb2XLJkHM6YkZv+Sl3sjwUOtZS1+hRAz4I5BsxxNYK3OySwlzb5yBF2axC6z0DTpXNhyMUSEm2yI4gGroW+x0q8AK4dYelhcBC2QYYp8a2QkQu7vphg05QusuebZpjhRsFVphkjNmpEmAxAGRK/AaRr6YZtfVe/IsZgXso9xr75TBl/wee3jl5kLfBxs0q4lUCmfAcdfkT9EUWp6IOX6E+l7rgObuPLU5q64QtPzu5WDG2zM8cQWMbGt34EnKqSqwUPP3cmEVNuPSWh4bubLFKh+wcREMaMQ5j9GA9AXHDQnFsp3M9L3+0CBJIdBGnZetkjpg3l8INkqXzI35rNmJ6DkfmAE1a/SLLu9qkYK8HWi+1hsqKpNqv6bAp9iKSCb/tFc88wgNVh2n9UVZXBuWXCmtwc2BUfaN9/rw6L/+iqrTu9vrq0LTDSy8A1RuKr3aY+EyCN9gd+BVjEjpszFD8Jnrgj4qz5jihEgo8/AdGAS5/8QiMhdr18LQ5JaNC2EAsSswHx4MpOtFyyt84qJV0Ip4zegDJ0wMukjBJuRsZ6yR6ThgB0357pdmJsSXvj4XgevTwewWMmyX18kleac/i7oifv1xvp1gQrgigdp7s3tY91zH2o1LG/DqTbife7lgt9P6kR/LsHevJaVOytLv8DTO1ggTZjHDMT+A9DiUVot/gmhPcf5JwMnhV6PII5XtR4dy+lIs876JQFDm2YUgWNTPO+EJS/G63TgHxyJxBhumPCODzbYY58x+RFzykPvBuf+d6MpP2A2Pc2KPgW/SWc4XqTUVj6FIgwS58NJm06uLdh3vrEEUqO+fL6KOzmLYAa5TabqOv9oFGXYpOJ8sJtfGXIj6i+/aG4LrNZGeTzBzvz+W2jOcAH27qciC4YopLcP4NR6aXA3jYLVOLCnh54IfPVgMFFg0ZoqeaHEZN9jJIMsXNGbGsfT+f9FxN8JxAOM/iqqAVeCguXxNiKGJuCl+uQU2QdqyJVSgyq1xtXibRqGfJCDc+oGnXy5/jxjb0uDzhdYH94kfR4cj01MTDqt3kfFNjJtjl0KBR0oXj/E//PJwRgKJ3i0o5jYjRyLSqUfUJvEyiPrOmzAZrXQT8aYeOyB5MO4t0pdcMGBwcrWPkmxRiu3dERJHJttpFD03Iv5qFRZdNAsrfzu0dW59nO9x//Czxs3mcJfRyj2moAjMiyYC6vg5hPZso3lyDyJgvEySZ70GhJAfkb6peossSco7cdEw6lVisXDk9BuPArDn/kua94eUiajB1v3dwwvWNc535HQIQIbTd5478JESiFmB7mt5EXFXWVZWDhPRxkK8Px3KErl+4WBZec+glBSnrY1VqXDdBRG63etA/Ev2P4ih0MTEiv7/Bcbw9uzVsIIwhyopY3JtkJP/YqZpS9HSDzSTnkCcetO9YC6K1aqRjdxzDwfOqadu98gzXxZZOsGMFaBgptFqBwfrP5Z8+CWWebMIL2HzZCEhMZhHRFcfi5dI7t6R2AS6cqRFXQlaB75lYhOvFLmeuMtspjTUL2SQa1J17bZn9JYVNvBfL4twfZdp4zjo5DgFF5LiHC6uQa4LW3aWN8ujQ2CGRP67iRsIgedfrNZG6vdkwDMpzhyFFZXXrs507RTimTJGngX1kBWNb+j+b/RmjLsdONPPgCgE1o9fxJCfHM53zDHSlVcO8rsLideXY6HIUKgZC0khgpif5YBG+iHeqfT3ZBLwhLjK0GH6oP3TKw0xmHWq4Nb6C6OqdEIGQ7Rxt+rWOOPKhUMyzdhwz1YpeZA0zobRdR7isvmWGTMwxS56r+NuI6dOQL6xs+MlVFOPtyYNJAF2qWDHt0XOa/7Kv4XDRF7zDA19ZhqG8xDU9NtDwUDFrPBV5kO0TDSHuh7WShkzyXJYfc62WEIxIfbdMVX1m+mG20/f6Tk2r9wRxtAdxU4WqhK+YaZf8ZE6LfsNwJVyWI+o0VeK2v/2GkdUVeuDvq9aju+BipuUUHs9K09a4EyZOMNJtYUPj53W76rVP3rwAXr2jj+sWeDFCibsNTkv2KuyOzOM1cJCbONXNfqPAo5yx3cAwXp/ikz9kPMwmVqgIHGAd6QsTmaBXe4ex5C+GA1OBCMvk6ZAoSwRsAmoOZdharD+6dEEFL4HeqQx3XT+ddTRcGiQxgxuwPDAxcuCBkvqZSuVt1jb2c4WpL9id1S0TEsfzRtDj6VGM318jV3pj3pZvLXwVMJc7J4o6f0MNhjtgOZdcc302sh6HrusTn/zrRPpQVUPHkmmvmB4eP6IVT6aeKQS8Vt10PNtXbJKLYqFGnlTrrlHxBrGDMfz/j5ycai16VKeaKS1SnR1TQAReOaOksMc17xDVo9hnocOMs89tzCkDQ3e14lKngxWzmcxZAS6NGA5u/Y6x48b8OCiVbsbOxoeI5ouKd37TVPJEHo1VRPOhruVU50xv+eZtCbSkpTWPMq3r4AXZJjTKXn3aYTMQNMisR0yhto4dkdoNQw93ngm+MSduv+Sxt3VG108G6UDVEjE21ylMDueP5rDQ4G2sBPgIT/uSyFWan3tcP2eTFjps4BB0yzx4evjdUqu+Uqkvts7DOPY4MT8/g8YO41PvAW5sFItcwr6gLALyVSK8I3dzePeNELXK6daHLhkcI4EN4Yh3OO+kkT00X29A/V7wqIoV7T06FneC6Hg8rWyPHTFbAO0zqXK58Tp4E0kp0LkZHS+nLbmvuZOKSyQOMNWTvMYcagfRc+VgbAPjnZ9yRCXvWHY6N2z2CTKEioYoqt3Sgs8dgRHVZK/qGoO5lAWfdb6cTUFOZU0FnXYTS2ccQdOf8bJHOmldhavi0Oswe6wWpg3/Rp5Rvm0Y0g3r5CEF6lybkjM4K6eXc3DsFWcV43VPw/1w0sV3ErtuJHVyYxZzyS+iO0FC0Vpvru2emHoylbn0Tw3Cy31onjbnRlJfd9hzEZYiCUDj9l2P5b8Lrmw127NL25pzA+tdnRi55QS+ceUZ6omPqf7YsIO5AygG5+ZDCwFfjBX3tW5dpEFXzsdx1GWLopxT8RkPxjRjm8Z5EJpQtIYmptc3C6nBvPPCx0qVXJKo0LNbm9pZ1QPF0Vi/qS+V8PsL6dwPFH4t5jcKXJUdPNuiVLcqogKVicPSP+NviDn38UjWXixPHhkYk5Rv/2setqUXkKM+vePnOv7fNE3Px8QqJembwYkaj+T5do8st2KbJy08B2/l3gYvKoMZ5A3B3ypz3gghnEYPXb9uK1QyQIUsfV8tPFyFFWLVDQbSBSbqsWDfV1FThAJSi/FhcI4Al2JuqPvESQmjKW3qP6kk2GXQQco+R0lPszTEum1M9YQxq6YnRRy/wAPnHZgSgwNliNzx9d/FQbgo1kNg5LgdFjZh41ooPAubRyxfkHxzsVrnhjEV22wA/7dsAdllnnWRARQjBfn3tzENiG8YV/pWZF78aL8XZwapiPrWI=,iv:2Mvmz1CFO1112RxjIl6sxyNIDqa/cg00um6RcQaHNY8=,tag:+zygdwQdCBeBXVLvAj/jJQ==,type:str]
gitlab-key: ENC[AES256_GCM,data:3vFa2NQIR0PVOJj8CTrGDRzFeo+G5P4e4LGYBAhjwnfm1q8D3pLHDcLP/Y5Rth5MpRtfYpomCV+8V7ia/zSqUh2N2toUEJyfkLEZOaIzcjli/EIKrnZriaqvQTPdfPzAskraYjpySbJimhkCM7xA9YjTdPIsz227M9GZbpXPHO2BkuqQf3zLGT0FnCR6gd+yE0NPgPw8ncmLnHfDET3lXbeVquxGqzndXaGAZU88sTwgBj4G6lM5aGJpzyGu+Wpx2ZeJQnUxxtBS9IaZXGUAR3ENdEPh4NsprxuEHsWFKj4uMYU0yGncPcsshdTL0OEfS0S9+E0EUIUwMdPmnEZDJBHAFo3tA/sMvY0sz7N17o5wg5PUEHwQIX2Xsxn6XBkfiM1DemV36KmaKQvJTc+Xv96XT1q6QY8ln5gPIqxb+5MJ1/DUR05vf6rzonso6XAPS18TTk6pnpI+0zfTcSE9K13xMiKSdHcciiaKzb6eYV3D+Grnw2YQVNBU58Of2ET6ljmHrcqmT+PPutbgXZ/+PtJmRN7vnjt3puDcrgcRxMvd93d4Xa4NH+Ex1oP8Dp0ihjO16uk2O2tMd0p4E8kOIPq6GqQKY1wlMX80NpFXnZmiN80UWUkbjulu+TU/MTp3dqs2K4Jct2edZhGgTPONraBcl1U1tr+iHtEPqOFRyriFIPHmkjVsJMUTvjGXCcgW2/w81RK6HWf1Ojqu7ruK5zMKgOBi3UpAEyUGNM4P4OKt9zfQbDcsOWMBJ/Q3+kzSK15XIocinTkfGVIZg5gRb6tiIox1YMnxwEn9j046Q9kWy8mCy0iAZVaTsComZYW9eV5lovl42QvWPTLM1GCU0W40jCc1Wtw9IVjgSDEO+TYRy1H8XMjlwADWw/U5N2o8BxYKkBCTiJ8lkxrLAbMCdLxjprbt0OgXqFO+BD1QTp+JP5zjg+Yrm+lyEXrG/8MCV81U+mYZLcTR1VRXhNGmbJ7JpJQfxvFNdYz0Q5cbqYE2/+metDgolKzv6RQaOFcyEgXSTJ85Pj6U2xrWvLrgnixtsLvQ1OULVd3aTEJk6v0USljKqvHyUrq56eIQqg4CtpHw2+AIicXF5L2YfnkIEvCp8Aj3z9YzGK31kVx0xcUO44eEY5g+tw2puMBY8h4vNbWQuZG2FZj6H8+iqfGEPXwNM87FHkk5fLxH8b9LjsIY69kY/oWBVeqwT7IDXgkyhnj4cHqVL+VJ1Xpx7nlMQAv31Jr92ZdxXVlacDe4VkVK2cDSQJmciM3rQKtechKJqiAWvyvftCQLmdHknjEusE1VLvTG72BAftQwxZgDFvLPPBJU8V/92CqNcJz8YFyrSB/zbI/+jkwa+xF0xGWpT2iTPYS5kdHJNclCnM9FvtYRV7LYCM3m4IWYK0GxMc9PlgYVlUzTnZtu6XLkt3qprYBkXcv0N2zj4vr1eGNuE89FnGr9RBj/MC7bMX3tEh1vzzeIYL8x/CVK2k6nJr0PXNvb8tzaYPI4ZKuTTDMOTLdcSBczY0846fSIbfTzPUENoQh2GHQGxlrMkhYcaDFwi5WBB+VUCZwjdYZ6Qie20DHZYg3GakxRBv62t3vaCLHtBLsGnY3U0TvDOMUmpbciO+yXHyhpw/maIRlHfh9g0ifXhSS14SJ5rqT8S+NDFiu7I++XlwKyyodFxPI36diPHGjZv5AoeG9Zf8Z3FhXuQcCMKQ7ZYOqlpOpXix3syee9v+Zys5ChOtb5JAO/sDIqVdJOIrsrBUv0sbQ+lpxxzwsKKUJQa5RotDp6zbMDaeoQaUiurgaRWDeKrvDc7HoYdu5HJVEwUCzBrugQi+agqsgv9eXfz8k91dDJ85DQAcIw4gJ3UMXmDu0lEhyfmL4zhQ4iH14TR5EnsBZ7aHkLbdGo8HVR3clyUV1pz4BmiQy3Ry7mpalPzggHSdDpRegqZ/v57U0n4koipaRpWx9+SzHrc5Htyv6BksY7P10jkPBND1V7v/SfKhybkqdxW6R8Y57n53SzD/D/qI71+usijxJ1dZFxzKAiOvGrm0bkWLKovNXAH7M9SQN5iE/CxjsRvCZg5vRSzzWWV2ugE03os6UKB4EVpe/1GhzITFx5nKTOMwIChCWZ+fMJSqjDW09kVigIzNYAkBLL/n0bVJmJFEed+kxO35+TNodE+L0w/1u3knoZ9Y/9J5ru5lZnFpa8Nl+J5pWoB02rVtFfDEsA00HuHxkY0cHLfS71IPiExsvvTlUUK8bhYXq4OIO3DaIUtI1kXZEc3+6/RXR/03QUEWFaOuZ7ZjuyyjlaZawcyBp32LRjBIC3Sj3HLyUyiCtSOCuLDuMQbD5P7iGJDGJupQfQOjQ73zaHsTjR3fi+vjRBii5zjEYYYEcGB3w+OxTnvc1gIsAGbJQ7XCp31is0RVnVpVPQmlRsZTswrVwUXx3ggpS6xIM4nWAi2e5lskxBono7ED0OWzBok76OTv0DwYKihdJUaGtcuUMdJ8WxJR1PE6Oe1wjrGoE7zXS9uQe2TFTMnpSxqsPyIJy30R1O5vSK/daZDCXCKs8924wKgmC5Z7gxU3/YTLv8wuJiZaYA85f16r0cuEj0z/a+wndf8x0vR+FybcCH6OvcYfVB5f0oGitY+M0F+dVkFNBGON/c7jv5v6bb/NhAPco3FmH0nify4a4oKqHdwBnV66Kq27DM1xfO7MRJRLRxoA/AcLuz308uPLxsQY6YoieAIFTI3clupk+OvorNDyIy8i9uSyYA7Y68HWzqwlbbNgd40EorIQBdVeBKBc6HFQiU0VzCj9IPIVy/E2KRrOFcfNYF5ABn+/sZ7rs6FR4V1fN02rHX2pT99h+wItyVO7urMoX4HigK415Fi3Cf2aFFZlUP6Cj4Xjm/bzWi3e6kqwwUY3tcILAiFXUthZz3RBw9KTwOL8cfPp+3cagNyO3mI9azyfuuk458vKSbgxpqIRFubTUDG59d5MiF1LF5Xuzjrmx1ZyJgMjLFl9tK3sZrcgzCvsCNZmYCjBb8dhfafeQ5bmw4aVlVJFEszPDYGJKs3ejXOZRiRwFrXPW4UyFNajiHYJKBpO5L9l6Pin90SJ+1fHXB3w8HOkJr3B/jYNXRiWS786YUn+zL4YDyecFtOFWgfWR6gA59nd4qI9dk01DS78P4dcEqPyhAFn+NL6YQ0wX6uoAhzHWaSXYtKqwE7huX10RxblUKxYjjNIsMdiSuz1qtivfGeRSY6hQx/pRSXTUbXsEUPGugoLXJacKUytq5PA9zfzideQw4M4uMAfs9+gxPRZbwvdFHDYbXWOBb+N0Ejv/dmK+7d/tFVP8wvQ4MMs1/7av4sCBYHx6XMbJq1VWKr+oi4jWDX7ayT7Me4kX6d+e9cw7gvxpp26687R1M0cEVWGnyql5w7nqNsBSm6EJASgu3PWtfMs61Z6uk+HvqrJsQLrvkfYhhdv0Q6Yn+OA0OjDEJtkdZrB9/x0mZhQdSbvto16yHPTmythygYh20DHPdfhA1Hj8PuOxqzOzRRjUvcUzt1zFMwP7xoh9OScF1gweVvioFzpQ+Wnwn3pej+z8meR1Pyb9AzSO3tyz4EWYaQG9U0tu0pTBsGIVLqhDgTh8coMVlEQLpWupADllM661pvSfDfZlbJt4rxlTAlruoFY+TF2sPZxragaQvWoTBqQEJWNuK1pakozf9R48MhmI3RV+y3XVJHV/s/jZrcId6C1CF3qQOiOn8hhGRVsvYiRVAqpth04dMfiZCpjGSBblTwI5zD8RjYPwwnRG+gDqko8zsR67A85P3JLnVT8V+0N2+7QxkfHcMWmCRauO70s5tc4RMNoCQk2gM1KYU6Ssul5mSsJ/F+2k1ACypyH/sY7NZV1jMtkoahlIt7nOjS4LN8nrzyBUj/wvpHvIT8Tx4wc8/3I57CL5ggNvikTu7xl0ta0kGuAP/hJThRxvBvyGkcHU5FDJhp3G7U4Vr4i5EB/MjPOtEd0a0cC4vnz1Xke6YTJl2j7NXMjt0TI/y25phsFN4OlLtbH1CrSNnw2vJlo+YmybCuUwuv+ortw+Zp8jjZXWkuuPT+pBRUvoTV9O40jUt3mKyFMjqCXo50xzNkxlGpFUl+EfAgqlveih4H6NJsGmHh6z/hVR5pPmMXyfZU+J2hwuDrbBjHTp/882pNdmaJA1fcX9VRti7bPKoNyY7f3fiucCmtiwg6jrRjABfZHdwj/xHxKwoL4YsA0VGZKbhk58+G61CM5iMqiWaEN4rC0WZnmPMAHc3272u8ue1hBoAbMnZnl2H9HdWQuLsFmqjWDW197bfEgsYKALY3fGGi/Rrt5WAoG73EjAmgK17WTKZhlJZCasZ/Hul9ax/2S/UhilJp41oXa/QsMtQGwau5jzXsGolfWhLBhTYMkCme2JD1sLoalKIkdPbmmtJx4VKlJq4Rc4WOKDXGhyfkUMhEutz8BHCjonJ8MTEyvopiqWPYepd1cqW+X2uXhLYLudLvvEGdMq0,iv:pbe2MtYmFmY/kS+gM9xyI6cXViVmzPB3H7XL1ZH47h0=,tag:NmSKMlAIEOWE8Jw/iy3+Xw==,type:str]
sops:
age:
- enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBVby9Wa1NUUkpyeDMwU3dM
R0EyeFVtT0tJU0pKaWtXQzRkTDBPY3JjcTFrClNIQnl2WVorS0FZZjhicTQ5V2kx
MUZTZWZtaUk2a1ZhUTBCUnhkWHFIMFUKLS0tIElLcjJLZWNLOUJYN0NNVGFNUEFN
RkMrdTYwNkY1Tlc3M3dxTFdkRXJJZUEKUlYU45jXpS9hJO9Z/uAQ6XMj9QWgMMRI
LbJxvt48+yC+Y0XKOtDE0lHAuGNzUG8R/7FB1tTD8NCamBe46KGCIg==
-----END AGE ENCRYPTED FILE-----
recipient: age1c8pawdsxptfslgrz2c56s39mrtnjzc5mm3hfzgr2wdwu2v6vfsdsupjsq6
lastmodified: "2026-07-01T12:18:22Z"
mac: ENC[AES256_GCM,data:rX8MoqaMAbfuMdcQMw8eDGXos3VgbA3VfNJJcGGk2xQPuTC7FW5S0BVuh68ajzVv0oaYtT8pBRktv9Lo2VDY6Mm4neVuF/9IgV0cTKwvx5ACjN40Zt7OU+QtlQK44kDXsJQFyV+BYHVNiW8jej1h9d7vSAgG0hD3GOpvtK6ZY6E=,iv:3B3COjvazDVRkUsuIiLlOCFqlE9ooFR8dC5PTXe/q28=,tag:QEqcRTks4zSX02qc9KDsrA==,type:str]
unencrypted_suffix: _unencrypted
version: 3.13.1
-38
View File
@@ -1,38 +0,0 @@
{
config,
lib,
...
}: {
imports = [
# Choose your theme here:
../../themes/nixy.nix
];
config.var = {
hostname = "h-work";
username = "hadrien";
configDirectory = "/home/" + config.var.username + "/.config/nixos"; # The path of the nixos configuration directory
keyboardLayout = "fr";
timeZone = "Europe/Paris";
defaultLocale = "en_US.UTF-8";
extraLocale = "fr_FR.UTF-8";
git = {
username = "Hadi";
email = "hadi@example.com";
};
autoUpgrade = false;
autoGarbageCollector = true;
};
# DON'T TOUCH THIS
options = {
var = lib.mkOption {
type = lib.types.attrs;
default = {};
};
};
}
-68
View File
@@ -1,68 +0,0 @@
# Omen laptop configuration for NixOS
# Import this only if you have an HP Omen laptop
{
config,
pkgs,
...
}: let
hp-omen-linux-module = pkgs.callPackage (
{
kernel ? config.boot.kernelPackages.kernel,
stdenv,
fetchFromGitHub,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "hp-omen-linux-module";
version = "rebase-6.15";
# Upstream only rebases per kernel branch and currently tops out at
# rebase-6.15, while linuxPackages_latest is already on 7.x. If the
# module ever fails to build against a newer kernel, either bump this
# to a fresh upstream branch or fall back to a stable kernel.
src = fetchFromGitHub {
owner = "ranisalt";
repo = "hp-omen-linux-module";
rev = "d4b9b5adb84581c3874ca3985dc749c40c3ece67"; # rebase-6.15
sha256 = "sha256-IOXHzcCB0n1InMjeIu3XYEJ4bhbHS3NIlS8/+4XIwkQ=";
};
setSourceRoot = ''
export sourceRoot=$(pwd)/${finalAttrs.src.name}/src
'';
nativeBuildInputs = kernel.moduleBuildDependencies;
makeFlags = [
"KERNELDIR=${kernel.dev}/lib/modules/${kernel.modDirVersion}/build"
];
installPhase = ''
runHook preInstall
install hp-wmi.ko -Dm444 -t $out/lib/modules/${kernel.modDirVersion}/kernel/drivers/platform/x86/hp/
runHook postInstall
'';
})
) {kernel = config.boot.kernelPackages.kernel;};
in {
boot.extraModulePackages = [hp-omen-linux-module];
boot.kernelModules = ["hp-wmi"];
boot.kernelParams = ["hp_wmi.force_slow_fan_control=1"];
users.groups.omen-rgb = {};
users.users.${config.var.username}.extraGroups = ["omen-rgb"];
systemd.tmpfiles.rules = [
"w /sys/devices/platform/hp-wmi/rgb_zones/zone00 0660 root omen-rgb -"
"w /sys/devices/platform/hp-wmi/rgb_zones/zone01 0660 root omen-rgb -"
"w /sys/devices/platform/hp-wmi/rgb_zones/zone02 0660 root omen-rgb -"
"w /sys/devices/platform/hp-wmi/rgb_zones/zone03 0660 root omen-rgb -"
];
services.udev.extraRules = ''
SUBSYSTEM=="platform", KERNEL=="hp-wmi", ACTION=="add", \
RUN+="${pkgs.coreutils-full}/bin/sleep 2", \
RUN+="${pkgs.coreutils}/bin/chgrp omen-rgb /sys/devices/platform/hp-wmi/rgb_zones/zone00", \
RUN+="${pkgs.coreutils}/bin/chmod 0660 /sys/devices/platform/hp-wmi/rgb_zones/zone00", \
RUN+="${pkgs.coreutils}/bin/chgrp omen-rgb /sys/devices/platform/hp-wmi/rgb_zones/zone01", \
RUN+="${pkgs.coreutils}/bin/chmod 0660 /sys/devices/platform/hp-wmi/rgb_zones/zone01", \
RUN+="${pkgs.coreutils}/bin/chgrp omen-rgb /sys/devices/platform/hp-wmi/rgb_zones/zone02", \
RUN+="${pkgs.coreutils}/bin/chmod 0660 /sys/devices/platform/hp-wmi/rgb_zones/zone02", \
RUN+="${pkgs.coreutils}/bin/chgrp omen-rgb /sys/devices/platform/hp-wmi/rgb_zones/zone03", \
RUN+="${pkgs.coreutils}/bin/chmod 0660 /sys/devices/platform/hp-wmi/rgb_zones/zone03"
'';
}
+34
View File
@@ -0,0 +1,34 @@
# Source: https://github.com/Dylouwu/MyNixy/blob/main/nixos/steam.nix
{
config,
pkgs,
...
}: {
programs.steam = {
enable = true;
gamescopeSession.enable = true;
};
environment.systemPackages = with pkgs; [
mangohud
protonup-ng
];
environment.sessionVariables = {
STEAM_EXTRA_COMPAT_TOOLS_PATHS = "/home/${config.var.username}/.steam/root/compatibilitytools.d";
};
environment.persistence."/persist".directories = [
"/home/${config.var.username}/.steam"
];
programs.gamemode.enable = true;
}
# Example of recommanded launch options for your games in Steam :
# Regular gaming :
# LD_PRELOAD="" gamescope -W 2560 -H 1440 -r 360 -f -- %command%
# LD_PRELOAD="" gamescope -W 3440 -H 1440 -r 140 -f -- %command%
# HDR gaming :
# LD_PRELOAD="" ENABLE_HDR_WSI=1 gamescope -w 2560 -h 1440 -r 360 -f --hdr-enabled --hdr-debug-force-output --hdr-sdr-content-nits 600 -- env ENABLE_GAMESCOPE_WSI=1 DXVK_HDR=1 DISABLE_HDR_WSI=1 VKD3D_DISABLE_EXTENSIONS=VK_KHR_present_wait %command%
# LD_PRELOAD="" removes a glitch causing games to slow down after roughly 24 minutes
# For the rest of the command, you can change the values to match your screen resolution and refresh rate
-14
View File
@@ -1,14 +0,0 @@
# USBGuard:
# The following line allow all USB devices until a proper policy is configured.
# Run `sudo usbguard generate-policy` with your devices plugged in,
# then set rules = "<output>" and switch implicitPolicyTarget to "block".
# services.usbguard.implicitPolicyTarget = lib.mkForce "allow";
{
services.usbguard = {
enable = true;
implicitPolicyTarget = "block";
IPCAllowedUsers = [
"root"
];
};
}