pwnbox The manual. Every option, every key, every file.

docs / getting-started

Getting started

Requirements

  • An existing NixOS install (the installer creates the host config for you).
  • A user with sudo access.
  • Network access to fetch the flake inputs the first time.

Install

From the flake directory:

bash
./install.sh switch

The installer:

  1. Detects your user, host name, time zone and hardware.
  2. Creates hosts/<host>/ from the nixos template if it does not exist.
  3. Collects garbage (skippable) and runs nixos-rebuild with the flake.

Installer actions

ActionWhat it does
switchBuild and activate, persistent (default)
testBuild and activate for this boot only
bootBuild and set as the default for the next boot
buildBuild only, do not activate
dry-activateBuild and show what would change, do not activate

Installer options

OptionMeaning
-H, --host HOSTFlake host to build (default: short hostname)
-n, --no-gcSkip garbage collection before rebuilding
-v, --verboseStream all output (default is quiet)
-- EXTRA...Extra arguments passed to nixos-rebuild

Examples:

bash
./install.sh build
./install.sh test -H myhost
./install.sh switch --verbose
./install.sh switch -- --show-trace

After install

Useful shell aliases (defined in modules/home/shell.nix):

CommandDoes
updRebuild and activate
updateUpdate all flake inputs, then rebuild
rebuildNot defined by default use upd

Host configuration

The generated hosts/<host>/default.nix is the single place to tune the machine. Common options:

nix
pwnbox = {
  hostName = "myhost";
  timeZone = "Europe/Berlin";
  username = "pwnbox";

  desktop = {
    enable = true;
    resolution = "2560x1440@144"; # or "preferred"
    accessibility = false;         # at-spi bus off unless you need it
  };

  vpn.mullvad = false;             # do not run the daemon

  virtualisation = {
    docker = true;
    dockerOnBoot = false;          # start the daemon on first use
    libvirtd = true;
    wireshark = true;
  };

  packages = {
    hacking = true;                # the full pentest toolset
    gaming = false;                # optional
    creative = false;              # optional
  };
};

Every option is documented in modules/nixos/options.nix.

Wallpapers

Wallpapers live in the flake at dotfiles/gnome/wallpapers/ and are linked read-only to ~/.local/share/pwnbox/wallpapers. Add an image there and rebuild, then pick it from ALT + S → Pywal.

Recovery

If a build breaks the system, boot an older generation from the boot menu and rebuild. You can also activate a previous configuration with:

bash
sudo /nix/var/nix/profiles/system-<n>-link/bin/switch-to-configuration switch

The installer writes its full log to /tmp/pwnbox-install.log.