# Work (EDaaS/WSL) home profile: corporate toolchain + tmux tweaks. Git identity # comes from the registry (users/registry.nix), not here. { pkgs, lib, inputs, ... }: { # Host-scoped extras for this machine only (the EDaaS/WSL host). imports = [ ./renovate-review.nix # daily headless Renovate PR review (systemd user timer) ]; # The work box keeps its own (corporate) ~/.ssh/config; don't let the personal # programs.ssh (shell.nix) take it over. The ssh-agent below still runs. programs.ssh.enable = lib.mkForce false; home.packages = [ pkgs.kubectl pkgs.argo-rollouts pkgs.tenv pkgs.kubernetes-helm pkgs.azure-cli pkgs.kubelogin pkgs.curl pkgs.notation pkgs.powershell pkgs.nuget pkgs.gedit pkgs.python3 pkgs.gnumake pkgs.gcc pkgs.libiconv pkgs.autoconf pkgs.automake pkgs.pkg-config pkgs.wget pkgs.google-cloud-sdk # Day-to-day Kubernetes / Helm / Terraform accelerators for this box. pkgs.k9s # cluster TUI pkgs.kubectx # kubectx + kubens (context/namespace switch) pkgs.stern # multi-pod log tail pkgs.dyff # semantic YAML/manifest diffs (Helm release drift) pkgs.tflint # Terraform linter (catches what terraformls won't) pkgs.terraform-docs # generate Terraform module docs pkgs.yq-go # jq for YAML pkgs.gcx # Grafana Cloud CLI (dashboards, SLOs, synthetics, alerts) ]; services.ssh-agent.enable = true; home.shellAliases = { docker = "/run/current-system/sw/bin/docker"; }; # Source the (nix-unmanaged) Jenkins credentials file into every zsh, so the # JENKINS_UCE_/JENKINS_STF_ tokens are exported for all shells and anything they # launch -- the Jenkins MCP servers read them via ${JENKINS_*} expansion. # envExtra lands in ~/.zshenv, which zsh sources for login, interactive, and # non-interactive shells alike. Guarded so a missing file never breaks a shell; # the file holds secrets, so it is kept out of the world-readable nix store. programs.zsh.envExtra = '' [ -f "$HOME/.jenkinsenv" ] && . "$HOME/.jenkinsenv" [ -f "$HOME/.splunkenv" ] && . "$HOME/.splunkenv" ''; programs.tmux = { # kube context/namespace in the status line. kube-tmux is pinned as a flake # input (it is not in nixpkgs), so the script is always present in the store. extraConfig = '' set -g status-right "#(${pkgs.bash}/bin/bash ${inputs.kube-tmux}/kube.tmux 250 red black)" ''; }; programs.go = { enable = true; }; # LSP servers only relevant to work: C# (omnisharp) and Helm charts (helm_ls). # The shared editor (home/editor.nix) carries the universal ones; # these are gated to this host so the heavy omnisharp closure stays off the # personal machines. Tree-sitter grammars (highlighting) remain global there. programs.nixvim.plugins.lsp.servers = { omnisharp.enable = true; helm_ls.enable = true; }; }