Adds Rust/Go replacements for the day-to-day utilities and shadows four of them with aliases. Only read-only commands are shadowed (cat, du, df, ps), so a wrong flag costs a retype rather than data; rm, grep, find and sed keep their originals and the replacements are reached by their own names. The aliases land in .zshrc, so they apply to interactive zsh only -- scripts, `sudo <cmd>` and anything exec'd by another program still get the real binary. New on every host: dust, dysk, procs, trash-cli, doggo, xh, ouch, jnv, hexyl, fq and tealdeer. dysk is used rather than duf, which is unmaintained upstream. git gains difftastic behind a `git dft` alias. diff.external is deliberately left unset so delta remains the renderer for git diff/show and for anything parsing them. The work box gains kubecolor, aliased over kubectl; it wraps the real kubectl and drops colour when stdout is not a terminal, so pipes are unchanged. home/README.md documents the alias map, the flag incompatibilities (including the two that fail silently: dust -s is --apparent-size, and procs reads a bare `aux` as a search keyword) and the rationale for what was left alone.
106 lines
3.9 KiB
Nix
106 lines
3.9 KiB
Nix
# Work (EDaaS/WSL) home profile: corporate toolchain + tmux tweaks. Git identity
|
|
# comes from the registry (users/registry.nix), not here.
|
|
{
|
|
pkgs,
|
|
lib,
|
|
inputs,
|
|
...
|
|
}:
|
|
|
|
{
|
|
# Host-scoped extras for this machine only (the EDaaS/WSL host).
|
|
imports = [
|
|
./renovate-review.nix # daily headless Renovate PR review (systemd user timer)
|
|
];
|
|
|
|
# The work box keeps its own (corporate) ~/.ssh/config; don't let the personal
|
|
# programs.ssh (shell.nix) take it over. The ssh-agent below still runs.
|
|
programs.ssh.enable = lib.mkForce false;
|
|
|
|
home.packages = [
|
|
pkgs.kubectl
|
|
pkgs.argo-rollouts
|
|
pkgs.tenv
|
|
pkgs.kubernetes-helm
|
|
pkgs.azure-cli
|
|
pkgs.kubelogin
|
|
pkgs.curl
|
|
pkgs.notation
|
|
pkgs.powershell
|
|
pkgs.nuget
|
|
pkgs.gedit
|
|
pkgs.python3
|
|
pkgs.gnumake
|
|
pkgs.gcc
|
|
pkgs.libiconv
|
|
pkgs.autoconf
|
|
pkgs.automake
|
|
pkgs.pkg-config
|
|
pkgs.wget
|
|
pkgs.google-cloud-sdk
|
|
# Day-to-day Kubernetes / Helm / Terraform accelerators for this box.
|
|
pkgs.k9s # cluster TUI
|
|
pkgs.kubectx # kubectx + kubens (context/namespace switch)
|
|
pkgs.stern # multi-pod log tail
|
|
pkgs.dyff # semantic YAML/manifest diffs (Helm release drift)
|
|
pkgs.tflint # Terraform linter (catches what terraformls won't)
|
|
pkgs.terraform-docs # generate Terraform module docs
|
|
pkgs.yq-go # jq for YAML
|
|
pkgs.gcx # Grafana Cloud CLI (dashboards, SLOs, synthetics, alerts)
|
|
];
|
|
services.ssh-agent.enable = true;
|
|
|
|
# Colourised kubectl. enableAlias points `kubectl` at kubecolor, which parses
|
|
# the output of the real kubectl underneath and passes anything it does not
|
|
# recognise straight through, so every flag and subcommand still works. It
|
|
# drops colour automatically when stdout is not a terminal, leaving pipes into
|
|
# grep/jq/yq byte-identical. zsh integration reuses kubectl's own completions.
|
|
# Note the alias does apply to `KUBECONFIG=... kubectl ...`: zsh expands
|
|
# aliases after a variable-assignment prefix.
|
|
programs.kubecolor = {
|
|
enable = true;
|
|
enableAlias = true;
|
|
enableZshIntegration = true;
|
|
};
|
|
|
|
# gcx (above) keeps its OAuth tokens in the system keychain and has no
|
|
# plaintext fallback, so this WSL box needs something owning
|
|
# org.freedesktop.secrets. See home/secret-service.nix for why
|
|
# home-manager's services.gnome-keyring cannot be used on a headless host,
|
|
# and for the security trade-off of an auto-unlocked keyring.
|
|
services.headlessSecretService.enable = true;
|
|
home.shellAliases = {
|
|
docker = "/run/current-system/sw/bin/docker";
|
|
};
|
|
|
|
# Source the (nix-unmanaged) Jenkins credentials file into every zsh, so the
|
|
# JENKINS_UCE_/JENKINS_STF_ tokens are exported for all shells and anything they
|
|
# launch -- the Jenkins MCP servers read them via ${JENKINS_*} expansion.
|
|
# envExtra lands in ~/.zshenv, which zsh sources for login, interactive, and
|
|
# non-interactive shells alike. Guarded so a missing file never breaks a shell;
|
|
# the file holds secrets, so it is kept out of the world-readable nix store.
|
|
programs.zsh.envExtra = ''
|
|
[ -f "$HOME/.jenkinsenv" ] && . "$HOME/.jenkinsenv"
|
|
[ -f "$HOME/.splunkenv" ] && . "$HOME/.splunkenv"
|
|
'';
|
|
programs.tmux = {
|
|
# kube context/namespace in the status line. kube-tmux is pinned as a flake
|
|
# input (it is not in nixpkgs), so the script is always present in the store.
|
|
extraConfig = ''
|
|
set -g status-right "#(${pkgs.bash}/bin/bash ${inputs.kube-tmux}/kube.tmux 250 red black)"
|
|
'';
|
|
};
|
|
programs.go = {
|
|
enable = true;
|
|
};
|
|
|
|
# LSP servers only relevant to work: C# (omnisharp) and Helm charts (helm_ls).
|
|
# The shared editor (home/editor.nix) carries the universal ones;
|
|
# these are gated to this host so the heavy omnisharp closure stays off the
|
|
# personal machines. Tree-sitter grammars (highlighting) remain global there.
|
|
programs.nixvim.plugins.lsp.servers = {
|
|
omnisharp.enable = true;
|
|
helm_ls.enable = true;
|
|
};
|
|
}
|