{"id":14967952,"url":"https://github.com/sukhmancs/nixos-configs","last_synced_at":"2025-04-09T22:17:49.486Z","repository":{"id":247162451,"uuid":"825165744","full_name":"sukhmancs/nixos-configs","owner":"sukhmancs","description":"yoink, tweak, and make it your own! 🌟","archived":false,"fork":false,"pushed_at":"2025-04-06T17:18:36.000Z","size":52296,"stargazers_count":67,"open_issues_count":2,"forks_count":2,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-04-09T22:17:41.745Z","etag":null,"topics":["agenix","flake-parts","home-manager","nix","nix-flakes","nixos"],"latest_commit_sha":null,"homepage":"","language":"CSS","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/sukhmancs.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null},"funding":{"github":"sukhmancs","ko_fi":"xilain"}},"created_at":"2024-07-07T01:38:51.000Z","updated_at":"2025-03-28T17:53:58.000Z","dependencies_parsed_at":"2025-01-09T19:53:40.696Z","dependency_job_id":null,"html_url":"https://github.com/sukhmancs/nixos-configs","commit_stats":{"total_commits":1119,"total_committers":4,"mean_commits":279.75,"dds":"0.020554066130473614","last_synced_commit":"63f7b4e109b874536578d5820b0a059f787f3eb2"},"previous_names":["sukhmancs/nixos-configs"],"tags_count":28,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sukhmancs%2Fnixos-configs","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sukhmancs%2Fnixos-configs/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sukhmancs%2Fnixos-configs/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/sukhmancs%2Fnixos-configs/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/sukhmancs","download_url":"https://codeload.github.com/sukhmancs/nixos-configs/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248119286,"owners_count":21050755,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["agenix","flake-parts","home-manager","nix","nix-flakes","nixos"],"created_at":"2024-09-24T13:38:59.461Z","updated_at":"2025-04-09T22:17:49.463Z","avatar_url":"https://github.com/sukhmancs.png","language":"CSS","funding_links":["https://github.com/sponsors/sukhmancs","https://ko-fi.com/xilain"],"categories":[],"sub_categories":[],"readme":"[![built with nix](https://img.shields.io/static/v1?logo=nixos\u0026logoColor=white\u0026label=\u0026message=Built%20with%20Nix\u0026color=41439a)](https://builtwithnix.org)\n[![Linux](https://img.shields.io/badge/Linux-%23.svg?logo=linux\u0026color=FCC624\u0026logoColor=black)](https://www.linux.org/)\n[![Top Language](https://img.shields.io/github/languages/top/sukhmancs/nixos-configs)]()\n[![NeoVim](https://img.shields.io/badge/Neovim-0.10.1-blueviolet.svg?logo=Neovim\u0026logoColor=green)](https://neovim.io/)\n[![Commit Activity](https://img.shields.io/github/commit-activity/m/sukhmancs/nixos-configs?label=Commits)](https://github.com/sukhmancs/nixos-configs/graphs/commit-activity)\n[![Commit Since](https://img.shields.io/github/commits-since/sukhmancs/nixos-configs/iso-2024-07-29-211510?label=Commits%20Since%20Last%20Release)](https://github.com/sukhmancs/nixos-configs/releases/tag/iso-2024-07-29-211510)\n[![Repo Size](https://img.shields.io/github/repo-size/sukhmancs/nixos-configs?label=Repo%20Size)]()\n\n\u003cbr /\u003e\n\n\u003cp id=\"preview\" align=\"center\"\u003e\n  \u003cimg src=\".github/assets/firefox_vim_pfetch_yazi.png\" alt=\"Firefox, Neovim, pfetch, yazi\" /\u003e\n  \u003cimg src=\".github/assets/iso_preview.png\" alt=\"ISO Preview\" /\u003e\n\u003c/p\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003eMore Catppuccin Previews\u003c/summary\u003e\n\u003cimg src=\".github/assets/rofi.png\" alt=\"Rofi Preview\" /\u003e\n\u003cimg src=\".github/assets/anyrun.png\" alt=\"Anyrun Preview\" /\u003e\n\u003cimg src=\".github/assets/neovim.png\" alt=\"Neovim Preview\" /\u003e\n\u003cimg src=\".github/assets/vscode.png\" alt=\"VSCode Preview\" /\u003e\n\u003cimg src=\".github/assets/discord.png\" alt=\"Discord Preview\" /\u003e\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003eGruvbox-light-hard\u003c/summary\u003e\n\u003cimg src=\".github/assets/gruvbox-light-hard.png\" alt=\"gruvbox-light-hard Theme\" /\u003e\n\u003cimg src=\".github/assets/gruvbox-light-hard-common.png\" alt=\"gruvbox-light-hard-common Theme\" /\u003e\n\u003cimg src=\".github/assets/gruvbox-light-hard-discord.png\" alt=\"gruvbox-light-hard-discord Theme\" /\u003e\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003eAlph\u003c/summary\u003e\n\u003cimg src=\".github/assets/alph.png\" alt=\"Alph Theme\" /\u003e\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003eAshes\u003c/summary\u003e\n\u003cimg src=\".github/assets/ashes.png\" alt=\"Ashes Theme\" /\u003e\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003eGruvbox-dark-hard\u003c/summary\u003e\n\u003cimg src=\".github/assets/gruvbox-dark-hard.png\" alt=\"gruvbox-dark-hard Theme\" /\u003e\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003eCatppuccin-frappe\u003c/summary\u003e\n\u003cimg src=\".github/assets/catppuccin-frappe.png\" alt=\"Catppuccin-frappe Theme\" /\u003e\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003eember\u003c/summary\u003e\n\u003cimg src=\".github/assets/ember.png\" alt=\"ember Theme\" /\u003e\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003eemil\u003c/summary\u003e\n\u003cimg src=\".github/assets/emil1.png\" alt=\"emil Theme\" /\u003e\n\u003cimg src=\".github/assets/emil2.png\" alt=\"emil Theme\" /\u003e\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003efairy-floss\u003c/summary\u003e\n\u003cimg src=\".github/assets/fairy-floss1.png\" alt=\"fairy-floss Theme\" /\u003e\n\u003cimg src=\".github/assets/fairy-floss2.png\" alt=\"fairy-floss Theme\" /\u003e\n\u003c/details\u003e\n\n\u003cbr/\u003e\n\n## Todo\n\n- [ ] **Tailnet** - TailScale, WireGuard, ...\n- [ ] **Icons** - Icon fonts (gtk/qt) are not dynamic. Try to use base16 colors.\n- [ ] **Qemu** - Virtualization with GPU passthrough (_Done but not tested_)\n- [ ] **Hardened Systemd**\n- [ ] **Modularize** - Anyrun, qt.nix, ...\n- [ ] **Refactor** - Remove dead code, unused files, ...\n\n### AppArmor\n\n\u003e One profile a day keeps the hacker away\n\n- [x] **Chrome** - `google-chrome`, `chromium`\n\n## Structure\n\n```plaintext\n.\n├── homes 🏠          # Common home-manager configuration for all hosts.\n├── hosts 💻          # Host-specific configurations.\n├── modules 🔧        # Contains the common modules used across all hosts.\n│   ├── exclusive 🚪  # Modules that need to be enabled exclusively.\n│   ├── roles 🎭      # Roles that can be assigned to a host.\n│   └── shared 🤝     # Modules that are shared across multiple hosts.\n├── flake-parts ❄️    # flake.parts.\n│   ├── default 📦    # Custom packages that are available to all hosts.\n│   ├── git-hooks 🔗  # Git hooks.\n│   ├── lib 📚        # Common functions and variables.\n│   ├── npins 📌      # Nix packages that are pinned.\n│   ├── shell 🐚      # Direnv shell for this project.\n│   ├── templates 📑  # Flake templates for different languages.\n│   ├── keys 🔑       # Public keys for the hosts.\n│   ├── live-media 📀 # Live media available for build.\n│   └── treefmt 🌳    # Treefmt configuration.\n├── options ⚙️        # Custom options for the hosts.\n├── secrets 🔒        # Agenix secrets.\n└── themes 🎨         # Custom base16 themes.\n```\n\n## Privacy and Security\n\n\u003cdetails\u003e\n\n\u003csummary\u003e🛡️ Measures\u003c/summary\u003e\n\n\u003c/br\u003e\n\n- **Firewall** - `nftables`\n- **DNS** - `adguard`\n- **VPN** - `wireguard`\n- **Secrets** - `agenix`\n- **Encryption** - `LUKS`\n- **Sandboxing** - `firejail`\n- **Security Profiles** - `apparmor`, `selinux`\n- **Physical Security** - `yubikey`\n- **Ban IPs** - `fail2ban`\n- **Malware scanner** - `clamav`\n- **USB Device Control** - `usbguard`\n- **Software auditing** - `lynis` `vulnix` `auditd`\n- **Hardened Firefox** - `Schizofox`\n- **Stateless System** - `Impermanence`\n- **Kernel Hardening**\n\n\u003c/details\u003e\n\n## Host\n\nFollowing hosts are available:\n\n| Host         | Type    |\n| ------------ | ------- |\n| `milkyway`   | Laptop  |\n| `triangulum` | Server  |\n| `andromeda`  | Desktop |\n| `messier`    | ISO     |\n\n## Tools\n\nHere are the tools I am using:\n\n| Tool               | Milkyway/Andromeda | Messier       |\n| ------------------ | ------------------ | ------------- |\n| 🪟 Window Manager  | Hyprland           | River         |\n| 🖥️ Display Manager | swaylock           | swaylock      |\n| 📊 Bar             | AGS                | Waybar        |\n| 🚀 Launcher        | Anyrun, Rofi       | Rofi          |\n| 🎨 GTK Theme       | adw-gtk3-dark      | adw-gtk3-dark |\n| 🖥️ Terminal        | Foot               | Foot          |\n| 🔔 Notifications   | Dunst, AGS         | Mako          |\n\n\u003e [!NOTE]\n\u003e\n\u003e **Triangulum** is a headless server, so no graphical stuff there.\n\n## Color Scheme\n\n### Default Color Scheme: `cappuccino-mocha`\n\n| Element                                                    | Color Name | Hex Code  |\n| ---------------------------------------------------------- | ---------- | --------- |\n| Background Color                                           | base00     | `#1e1e1e` |\n| Secondary Background Color                                 | base02     | `#313244` |\n| Text Color                                                 | base05     | `#cdd6f4` |\n| Secondary Text Color                                       | base00     | `#1e1e1e` |\n| Accent Color (Button focused, Border color, Button active) | base0E     | `#cba6f7` |\n| Overlay Color (Button hover, Button disabled)              | base03     | `#45475a` |\n\n### Available Color Schemes\n\n| Scheme             | Variants                                                                                            |\n| ------------------ | --------------------------------------------------------------------------------------------------- |\n| `cappuccino`       | mocha, frappe                                                                                       |\n| `dracula`          | -                                                                                                   |\n| `gruvbox`          | light, dark, medium, hard                                                                           |\n| `henna`            | -                                                                                                   |\n| `helios`           | -                                                                                                   |\n| `horizon`          | dark                                                                                                |\n| `nord`             | -                                                                                                   |\n| `monokai`          | -                                                                                                   |\n| `selenized`        | dark, light                                                                                         |\n| `solarized`        | dark, light                                                                                         |\n| `tomorrow-night`   | -                                                                                                   |\n| `twilight`         | -                                                                                                   |\n| `ubuntu`           | -                                                                                                   |\n| `uwunicorn`        | -                                                                                                   |\n| `windows-95`       | -                                                                                                   |\n| `doom-one`         | -                                                                                                   |\n| `alph`             | -                                                                                                   |\n| `ashes`            | -                                                                                                   |\n| `atelier`          | cave, dune, estuary, forest, heath, lakeside, meadow, plateu, savanna, seaside, studio, sulphurpool |\n| `ayu-dark`         | -                                                                                                   |\n| `bespin`           | -                                                                                                   |\n| `caret`            | -                                                                                                   |\n| `darkmoss`         | -                                                                                                   |\n| `ember`            | -                                                                                                   |\n| `emil`             | -                                                                                                   |\n| `eris`             | -                                                                                                   |\n| `eva`              | -                                                                                                   |\n| `everforest`       | -                                                                                                   |\n| `fairy-floss`      | -                                                                                                   |\n| `gigavolt`         | -                                                                                                   |\n| `io`               | -                                                                                                   |\n| `isotope`          | -                                                                                                   |\n| `manegarm`         | -                                                                                                   |\n| `material-vivid`   | -                                                                                                   |\n| `miramare`         | -                                                                                                   |\n| `monokai`          | -                                                                                                   |\n| `oceanic-next`     | -                                                                                                   |\n| `old-hope`         | -                                                                                                   |\n| `outrun-dark`      | -                                                                                                   |\n| `spaceduck`        | -                                                                                                   |\n| `stella`           | -                                                                                                   |\n| `summerfruit-dark` | -                                                                                                   |\n| `woodland`         | -                                                                                                   |\n| `xcode-dusk`       | -                                                                                                   |\n\n## Installation\n\n### Disk Partitioning\n\nHere is what our disk partitioning will look like:\n\n```plaintext\n+-----------------------+------------------------+-----------------------+\n| Boot partition        | Swap partition         | LUKS encrypted root   |\n|                       |                        | partition             |\n|                       |                        |                       |\n| /boot                 | [SWAP]                 | /                     |\n|                       |                        |                       |\n|                       |                        | /dev/mapper/crypted   |\n|                       |                        |                       |\n| /dev/sda1             | /dev/sda2              | /dev/sda3             |\n|                       |                        |                       |\n| 1GB                   | 8GB                    | Remaining space       |\n+-----------------------+------------------------+-----------------------+\n```\n\n\u003cdetails\u003e\n\n\u003csummary\u003eOption 1 - Partition and mount the drives using disko\u003c/summary\u003e\n\n\u003c/br\u003e\n\n```bash\n# Change the disk id according to your system\nDISK='/dev/disk/by-id/ata-Samsung_SSD_870_EVO_250GB_S6PENL0T902873K'\n\ncurl https://raw.githubusercontent.com/sukhmancs/nixos-configs/main/disko/luks-btrfs-subvolumes/default.nix \\\n-o /tmp/disko.nix\nsed -i \"s|to-be-filled-during-installation|$DISK|\" /tmp/disko.nix\nnix --experimental-features \"nix-command flakes\" run github:nix-community/disko\\\n-- --mode disko /tmp/disko.nix\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\n\u003csummary\u003eOption 2 - Manual Partitioning\u003c/summary\u003e\n\n\u003c/br\u003e\n\n**Create Partitions**\n\n```bash\n# Create boot, swap, and root partitions\nDISK=/dev/sda\n\nparted \"$DISK\" -- mklabel gpt\nparted \"$DISK\" -- mkpart ESP fat32 1MiB 1GiB\nparted \"$DISK\" -- set 1 boot on\n\nparted \"$DISK\" -- mkpart Swap linux-swap 1GiB 9GiB\n\nparted \"$DISK\" -- mkpart primary 9GiB 100%\n```\n\n**Setup Swap Partition**\n\n```bash\nmkswap -L SWAP \"$DISK\"2\nswapon \"$DISK\"2\n```\n\n**Btrfs with LUKS (Root Partition)**\n\n```bash\ncryptsetup --verify-passphrase -v luksFormat \"$DISK\"3 # /dev/sda3\ncryptsetup open \"$DISK\"3 crypted\n\nmkfs.btrfs -L NIXOS /dev/mapper/crypted\n\nmount -t btrfs /dev/mapper/crypted /mnt\n\n# Setups subvolumes\nbtrfs subvolume create /mnt/root\nbtrfs subvolume create /mnt/home\nbtrfs subvolume create /mnt/nix\nbtrfs subvolume create /mnt/persist\nbtrfs subvolume create /mnt/log\nbtrfs subvolume create /mnt/snapshots\n\n# Blank snapshot of the root subvolume\nbtrfs subvolume snapshot -r /mnt/root /mnt/root-blank\n\n# Unmount the root partition\numount /mnt\n\n# Create mount points\nmkdir /mnt/home\nmkdir /mnt/nix\nmkdir /mnt/persist\nmkdir -p /mnt/var/log\nmkdir /mnt/snapshots\n\n# Mount the subvolumes\nmount -o subvol=root,compress=zstd,noatime /dev/mapper/crypted /mnt\nmount -o subvol=home,compress=zstd,noatime /dev/mapper/crypted /mnt/home\nmount -o subvol=nix,compress=zstd,noatime /dev/mapper/crypted /mnt/nix\nmount -o subvol=persist,compress=zstd,noatime /dev/mapper/crypted /mnt/persist\nmount -o subvol=log,compress=zstd,noatime /dev/mapper/crypted /mnt/var/log\nmount -o subvol=snapshots,compress=zstd,noatime /dev/mapper/crypted /mnt/snapshots\n```\n\n**Setup Boot Partition**\n\n```bash\nmkfs.vfat -n BOOT \"$DISK\"1\nmount --mkdir \"$DISK\"1 /mnt/boot\n```\n\n\u003c/details\u003e\n\n### Install NixOS\n\n```bash\n# Generate the configuration\nnixos-generate-config --root /mnt\n\n```\n\nRun `nixos-install` to install NixOS.\n\n### Install the dotfiles\n\n```bash\ngit clone https://github.com/sukhmancs/nixos-configs/ ~/.config/nixos-configs\ncd ~/.config/nixos-configs\n```\n\n\u003e [!CAUTION]\n\u003e If \u003cstrong\u003eImpermanence is enabled\u003c/strong\u003e, we need to add the `neededForBoot = true` to some\n\u003e mounted subvolumes in hardware-configuration.nix. It will look something like this:\n\u003e\n\u003e ```nix\n\u003e fileSystems.\"/persist\" = {\n\u003e    device = \"/dev/disk/by-uuid/b79d3c8b-d511-4d66-a5e0-641a75440ada\";\n\u003e    fsType = \"btrfs\";\n\u003e    options = [\"subvol=persist\"];\n\u003e    neededForBoot = true; # \u003c- add this\n\u003e  };\n\u003e\n\u003e  fileSystems.\"/var/log\" = {\n\u003e    device = \"/dev/disk/by-uuid/b79d3c8b-d511-4d66-a5e0-641a75440ada\";\n\u003e    fsType = \"btrfs\";\n\u003e    options = [\"subvol=log\"];\n\u003e    neededForBoot = true; # \u003c- add this\n\u003e  };\n\u003e\n\u003e  fileSystems.\"/snapshots\" = {\n\u003e    device = \"/dev/disk/by-uuid/b79d3c8b-d511-4d66-a5e0-641a75440ada\";\n\u003e    fsType = \"btrfs\";\n\u003e    options = [\"subvol=snapshots\"];\n\u003e    neededForBoot = true; # \u003c- add this\n\u003e  };\n\u003e ```\n\u003e\n\u003e Also, ensure that the password files are located in a volume marked with\n\u003e `neededForBoot = true` otherwise the user will not be able to login.\n\u003e\n\u003e ```bash\n\u003e mkdir -p /persist/passwords/root /persist/passwords/\u003cuser\u003e\n\u003e mkpasswd -m sha-512 \u003e /persist/passwords/\u003cuser\u003e\n\u003e mkpasswd -m sha-512 \u003e /persist/passwords/root\n\u003e ```\n\n```bash\nnixos-rebuild switch --flake .#\u003chost\u003e\n```\n\n## Thanks to these amazing people\n\n- [MatthiasBenaets](https://github.com/MatthiasBenaets/nix-config/)\n- [raf](https://github.com/notashelf/nyx)\n- [end-4](https://github.com/end-4/dots-hyprland)\n- [aylur](https://github.com/Aylur/dotfiles/)\n- will add more\n\n## Credit and Attribution\n\nI’m totally cool with you borrowing my code—no need to give me a shout-out. Just make sure to tip your hat to the original authors whose code I’ve borrowed for this project. They deserve the applause!\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsukhmancs%2Fnixos-configs","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsukhmancs%2Fnixos-configs","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsukhmancs%2Fnixos-configs/lists"}