# Work (EDaaS/WSL) home profile: corporate toolchain + tmux tweaks. Git identity # comes from the registry (users/registry.nix), not here. { pkgs, lib, ... }: { # Host-scoped extras for this machine only (the EDaaS/WSL host). imports = [ ./renovate-review.nix # daily headless Renovate PR review (systemd user timer) ]; # The work box keeps its own (corporate) ~/.ssh/config; don't let the personal # programs.ssh (shell.nix) take it over. The ssh-agent below still runs. programs.ssh.enable = lib.mkForce false; home.packages = [ pkgs.kubectl pkgs.argo-rollouts pkgs.tenv pkgs.kubernetes-helm pkgs.azure-cli pkgs.kubelogin pkgs.curl pkgs.notation pkgs.powershell pkgs.nuget pkgs.gedit pkgs.lens pkgs.python3 pkgs.gnumake pkgs.gcc pkgs.libiconv pkgs.autoconf pkgs.automake pkgs.pkg-config pkgs.wget pkgs.google-cloud-sdk # Day-to-day Kubernetes / Helm / Terraform accelerators for this box. pkgs.k9s # cluster TUI pkgs.kubectx # kubectx + kubens (context/namespace switch) pkgs.stern # multi-pod log tail pkgs.dyff # semantic YAML/manifest diffs (Helm release drift) pkgs.tflint # Terraform linter (catches what terraformls won't) pkgs.terraform-docs # generate Terraform module docs pkgs.yq-go # jq for YAML ]; services.ssh-agent.enable = true; home.shellAliases = { docker = "/run/current-system/sw/bin/docker"; }; programs.tmux = { # kube-tmux is an external checkout; guard on its presence so the status # line degrades gracefully (no per-refresh error) when it isn't cloned. extraConfig = '' set -g status-right "#(if [ -f $HOME/code/kube-tmux/kube.tmux ]; then /run/current-system/sw/bin/bash $HOME/code/kube-tmux/kube.tmux 250 red black; fi)" ''; }; programs.go = { enable = true; }; # LSP servers only relevant to work: C# (omnisharp) and Helm charts (helm_ls). # The shared editor (home/editor.nix) carries the universal ones; # these are gated to this host so the heavy omnisharp closure stays off the # personal machines. Tree-sitter grammars (highlighting) remain global there. programs.nixvim.plugins.lsp.servers = { omnisharp.enable = true; helm_ls.enable = true; }; }