Getting started
Requirements
- An existing NixOS install (the installer creates the host config for you).
- A user with
sudoaccess. - Network access to fetch the flake inputs the first time.
Install
From the flake directory:
bash
./install.sh switchThe installer:
- Detects your user, host name, time zone and hardware.
- Creates
hosts/<host>/from thenixostemplate if it does not exist. - Collects garbage (skippable) and runs
nixos-rebuildwith the flake.
Installer actions
| Action | What it does |
|---|---|
switch | Build and activate, persistent (default) |
test | Build and activate for this boot only |
boot | Build and set as the default for the next boot |
build | Build only, do not activate |
dry-activate | Build and show what would change, do not activate |
Installer options
| Option | Meaning |
|---|---|
-H, --host HOST | Flake host to build (default: short hostname) |
-n, --no-gc | Skip garbage collection before rebuilding |
-v, --verbose | Stream all output (default is quiet) |
-- EXTRA... | Extra arguments passed to nixos-rebuild |
Examples:
bash
./install.sh build
./install.sh test -H myhost
./install.sh switch --verbose
./install.sh switch -- --show-traceAfter install
Useful shell aliases (defined in modules/home/shell.nix):
| Command | Does |
|---|---|
upd | Rebuild and activate |
update | Update all flake inputs, then rebuild |
rebuild | Not defined by default use upd |
Host configuration
The generated hosts/<host>/default.nix is the single place to tune the machine. Common options:
nix
pwnbox = {
hostName = "myhost";
timeZone = "Europe/Berlin";
username = "pwnbox";
desktop = {
enable = true;
resolution = "2560x1440@144"; # or "preferred"
accessibility = false; # at-spi bus off unless you need it
};
vpn.mullvad = false; # do not run the daemon
virtualisation = {
docker = true;
dockerOnBoot = false; # start the daemon on first use
libvirtd = true;
wireshark = true;
};
packages = {
hacking = true; # the full pentest toolset
gaming = false; # optional
creative = false; # optional
};
};Every option is documented in modules/nixos/options.nix.
Wallpapers
Wallpapers live in the flake at dotfiles/gnome/wallpapers/ and are linked read-only to ~/.local/share/pwnbox/wallpapers. Add an image there and rebuild, then pick it from ALT + S → Pywal.
Recovery
If a build breaks the system, boot an older generation from the boot menu and rebuild. You can also activate a previous configuration with:
bash
sudo /nix/var/nix/profiles/system-<n>-link/bin/switch-to-configuration switchThe installer writes its full log to /tmp/pwnbox-install.log.