Files
nixfiles/users/emmathorpe/work.nix
T

122 lines
4.6 KiB
Nix
Raw Normal View History

# Work (EDaaS/WSL) home profile: corporate toolchain + tmux tweaks. Git identity
# comes from the registry (users/registry.nix), not here.
{
pkgs,
lib,
inputs,
...
}:
2025-06-17 15:14:06 +01:00
{
# Host-scoped extras for this machine only (the EDaaS/WSL host).
imports = [
./renovate-review.nix # daily headless Renovate PR review (systemd user timer)
];
# The work box keeps its own (corporate) ~/.ssh/config; don't let the personal
# programs.ssh (shell.nix) take it over. The ssh-agent below still runs.
programs.ssh.enable = lib.mkForce false;
2025-06-17 15:14:06 +01:00
home.packages = [
pkgs.kubectl
pkgs.argo-rollouts
2026-06-02 07:40:25 -07:00
pkgs.tenv
pkgs.kubernetes-helm
pkgs.azure-cli
pkgs.kubelogin
pkgs.curl
pkgs.notation
pkgs.powershell
pkgs.nuget
pkgs.gedit
pkgs.python3
pkgs.gnumake
pkgs.gcc
pkgs.libiconv
pkgs.autoconf
pkgs.automake
pkgs.pkg-config
pkgs.wget
pkgs.google-cloud-sdk
# Day-to-day Kubernetes / Helm / Terraform accelerators for this box.
pkgs.k9s # cluster TUI
pkgs.kubectx # kubectx + kubens (context/namespace switch)
pkgs.stern # multi-pod log tail
pkgs.dyff # semantic YAML/manifest diffs (Helm release drift)
pkgs.tflint # Terraform linter (catches what terraformls won't)
pkgs.terraform-docs # generate Terraform module docs
pkgs.yq-go # jq for YAML
2026-08-11 14:24:52 +01:00
pkgs.gcx # Grafana Cloud CLI (dashboards, SLOs, synthetics, alerts)
# WSL ships no xdg-open, so anything that shells out to a browser dies with
# `exec: "xdg-open,x-www-browser,www-browser": executable file not found`.
# kubelogin's interactive login is the one that bites: it is the login mode
# the shared cluster kubeconfig uses. Hand the URL to Windows instead.
# (wslu, the usual answer, is gone from nixpkgs -- upstream archived it.)
(pkgs.writeShellScriptBin "xdg-open" ''
url="$1"
if command -v powershell.exe >/dev/null 2>&1; then
exec powershell.exe -NoProfile -Command "Start-Process '$url'"
fi
exec explorer.exe "$url"
'')
2025-06-17 15:14:06 +01:00
];
# Honoured by tools that read $BROWSER rather than calling xdg-open.
home.sessionVariables.BROWSER = "xdg-open";
2026-06-02 15:22:58 +00:00
services.ssh-agent.enable = true;
# Colourised kubectl. enableAlias points `kubectl` at kubecolor, which parses
# the output of the real kubectl underneath and passes anything it does not
# recognise straight through, so every flag and subcommand still works. It
# drops colour automatically when stdout is not a terminal, leaving pipes into
# grep/jq/yq byte-identical. zsh integration reuses kubectl's own completions.
# Note the alias does apply to `KUBECONFIG=... kubectl ...`: zsh expands
# aliases after a variable-assignment prefix.
programs.kubecolor = {
enable = true;
enableAlias = true;
enableZshIntegration = true;
};
# gcx (above) keeps its OAuth tokens in the system keychain and has no
# plaintext fallback, so this WSL box needs something owning
# org.freedesktop.secrets. See home/secret-service.nix for why
# home-manager's services.gnome-keyring cannot be used on a headless host,
# and for the security trade-off of an auto-unlocked keyring.
services.headlessSecretService.enable = true;
home.shellAliases = {
docker = "/run/current-system/sw/bin/docker";
};
# Source the (nix-unmanaged) Jenkins credentials file into every zsh, so the
# JENKINS_UCE_/JENKINS_STF_ tokens are exported for all shells and anything they
# launch -- the Jenkins MCP servers read them via ${JENKINS_*} expansion.
# envExtra lands in ~/.zshenv, which zsh sources for login, interactive, and
# non-interactive shells alike. Guarded so a missing file never breaks a shell;
# the file holds secrets, so it is kept out of the world-readable nix store.
programs.zsh.envExtra = ''
[ -f "$HOME/.jenkinsenv" ] && . "$HOME/.jenkinsenv"
2026-07-14 15:58:00 +01:00
[ -f "$HOME/.splunkenv" ] && . "$HOME/.splunkenv"
'';
2026-06-02 07:40:25 -07:00
programs.tmux = {
# kube context/namespace in the status line. kube-tmux is pinned as a flake
# input (it is not in nixpkgs), so the script is always present in the store.
2026-06-02 07:40:25 -07:00
extraConfig = ''
set -g status-right "#(${pkgs.bash}/bin/bash ${inputs.kube-tmux}/kube.tmux 250 red black)"
2026-06-02 07:40:25 -07:00
'';
};
programs.go = {
enable = true;
};
# LSP servers only relevant to work: C# (omnisharp) and Helm charts (helm_ls).
# The shared editor (home/editor.nix) carries the universal ones;
# these are gated to this host so the heavy omnisharp closure stays off the
# personal machines. Tree-sitter grammars (highlighting) remain global there.
programs.nixvim.plugins.lsp.servers = {
omnisharp.enable = true;
helm_ls.enable = true;
};
2025-06-17 15:14:06 +01:00
}