drkai-lab/BeOniomarchy

Make your Omarchy be OniOmarchy!!

Shell

1

8 commits

updated Sep 30, 2026

See the code

See what people are saying

SourceMessageScoreDate

Make Omarchy to be Oniomarchy(Kali Linux Like Omarchy) !! (r/SideProject)

I found the nice project that is named "[Oniomarchy](https://oniomarchy.com/)", but I am not in the mood to install it to my ThinkPad P14s... So I come up with a great idea to make shells to install same apps of Oniomarchy. The name is "[BeOniomarchy](https://github.com/drkai-lab/BeOniomarchy)". It…

2

Sep 30, 2026

README

BeOniomarchy

BeOniomarchy v1.0

English | 日本語 | 한국어 | 简体中文 | 繁體中文

BeOniomarchy turns a stock Omarchy install into an "Oniomarchy": the same machine, with a security and development workstation on top of it.

On the name: Oniomarchy is an existing project by SalimRK that does this same job with a far bigger toolkit and its own signed package repository. This repo is a different attempt at the same idea, with its own much smaller set of tools, and it is not Oniomarchy itself.

Everything here is nine numbered scripts. They put in the scanners and auditors I actually reach for, the container and Kubernetes bits, a couple of AI extras, two small API helpers for Qualys and Checkmarx, my own web and API audit scripts with a report generator, and they fork one of Omarchy's stock themes into an "Oniomarchy" theme.

Nothing in here is clever. Every file written, backup taken and package installed gets one line in a state file, and that file is the only thing ./uninstall.sh reads when you want your machine back.

Requirements

  • Omarchy, meaning Arch Linux with the omarchy CLI available
  • sudo, because packages go through pacman

Installing

./install.sh --dry-run   # print the plan, change nothing
./install.sh             # install, asks for a yes first
./install.sh --yes       # install without asking, needed when stdin is not a tty

Run the dry run at least once before you let it loose. If you only want part of the job done:

./install.sh --list            # show the modules
./install.sh --only 01,theme   # run those two only

Modules run in order:

ModuleWhat it does
00-systemdirectories, baseline packages, beoni-* links in ~/.local/bin
01-securitynmap, lynis, clamav, yara, beoni-audit
02-devtoolslazygit, ripgrep, fzf, bat, eza, docker
03-ai-toolsuv, ollama
04-cloudkubectl, helm, k9s, terraform, kustomize
05-qualysbeoni-qualys
06-checkmarxbeoni-checkmarx
07-reportwrites a markdown status report
08-themeforks a stock theme into Oniomarchy and switches to it

Uninstalling

./uninstall.sh --dry-run   # show what would go
./uninstall.sh --yes       # remove it

That restores every backup it took, deletes what it created, puts you back on your previous theme, drops the theme fork and removes the packages it added. It only acts on what is in the state file, so anything you installed by hand is left alone.

--keep-packages and --keep-theme hold those parts back, --purge also wipes the reports under ~/.local/share/beoniomarchy/, and --list prints the state file. If a step fails halfway the state file stays, so you can run it again and it picks up where it stopped.

Tools

Six commands end up in ~/.local/bin:

beoni-webaudit https://example.com        # response security headers
beoni-apiaudit https://api.example.com    # auth, CORS, leaks
beoni-reportgen -o report.md              # machine + installer status
beoni-audit                               # listening ports and services
beoni-qualys hosts                        # Qualys API
beoni-checkmarx GET /projects             # Checkmarx API

The last two are the only ones that need credentials. The installer drops qualys.env.example and checkmarx.env.example into ~/.config/beoniomarchy/. Copy each one to qualys.env and checkmarx.env and fill them in.

Where things are kept

  • state and backups: ~/.local/state/beoniomarchy/
  • reports: ~/.local/share/beoniomarchy/reports/

The state file is plain tab separated text with the types pkg, create, backup, dir, theme and themefork. You can just cat it. There is no database to dig through.

drkai-lab/BeOniomarchy

Make your Omarchy be OniOmarchy!!

Shell

1

8 commits

updated Sep 30, 2026

See the code

See what people are saying

SourceMessageScoreDate

Make Omarchy to be Oniomarchy(Kali Linux Like Omarchy) !! (r/SideProject)

I found the nice project that is named "[Oniomarchy](https://oniomarchy.com/)", but I am not in the mood to install it to my ThinkPad P14s... So I come up with a great idea to make shells to install same apps of Oniomarchy. The name is "[BeOniomarchy](https://github.com/drkai-lab/BeOniomarchy)". It…

2

Sep 30, 2026

README

BeOniomarchy

BeOniomarchy v1.0

English | 日本語 | 한국어 | 简体中文 | 繁體中文

BeOniomarchy turns a stock Omarchy install into an "Oniomarchy": the same machine, with a security and development workstation on top of it.

On the name: Oniomarchy is an existing project by SalimRK that does this same job with a far bigger toolkit and its own signed package repository. This repo is a different attempt at the same idea, with its own much smaller set of tools, and it is not Oniomarchy itself.

Everything here is nine numbered scripts. They put in the scanners and auditors I actually reach for, the container and Kubernetes bits, a couple of AI extras, two small API helpers for Qualys and Checkmarx, my own web and API audit scripts with a report generator, and they fork one of Omarchy's stock themes into an "Oniomarchy" theme.

Nothing in here is clever. Every file written, backup taken and package installed gets one line in a state file, and that file is the only thing ./uninstall.sh reads when you want your machine back.

Requirements

  • Omarchy, meaning Arch Linux with the omarchy CLI available
  • sudo, because packages go through pacman

Installing

./install.sh --dry-run   # print the plan, change nothing
./install.sh             # install, asks for a yes first
./install.sh --yes       # install without asking, needed when stdin is not a tty

Run the dry run at least once before you let it loose. If you only want part of the job done:

./install.sh --list            # show the modules
./install.sh --only 01,theme   # run those two only

Modules run in order:

ModuleWhat it does
00-systemdirectories, baseline packages, beoni-* links in ~/.local/bin
01-securitynmap, lynis, clamav, yara, beoni-audit
02-devtoolslazygit, ripgrep, fzf, bat, eza, docker
03-ai-toolsuv, ollama
04-cloudkubectl, helm, k9s, terraform, kustomize
05-qualysbeoni-qualys
06-checkmarxbeoni-checkmarx
07-reportwrites a markdown status report
08-themeforks a stock theme into Oniomarchy and switches to it

Uninstalling

./uninstall.sh --dry-run   # show what would go
./uninstall.sh --yes       # remove it

That restores every backup it took, deletes what it created, puts you back on your previous theme, drops the theme fork and removes the packages it added. It only acts on what is in the state file, so anything you installed by hand is left alone.

--keep-packages and --keep-theme hold those parts back, --purge also wipes the reports under ~/.local/share/beoniomarchy/, and --list prints the state file. If a step fails halfway the state file stays, so you can run it again and it picks up where it stopped.

Tools

Six commands end up in ~/.local/bin:

beoni-webaudit https://example.com        # response security headers
beoni-apiaudit https://api.example.com    # auth, CORS, leaks
beoni-reportgen -o report.md              # machine + installer status
beoni-audit                               # listening ports and services
beoni-qualys hosts                        # Qualys API
beoni-checkmarx GET /projects             # Checkmarx API

The last two are the only ones that need credentials. The installer drops qualys.env.example and checkmarx.env.example into ~/.config/beoniomarchy/. Copy each one to qualys.env and checkmarx.env and fill them in.

Where things are kept

  • state and backups: ~/.local/state/beoniomarchy/
  • reports: ~/.local/share/beoniomarchy/reports/

The state file is plain tab separated text with the types pkg, create, backup, dir, theme and themefork. You can just cat it. There is no database to dig through.

Languages

Shell

100.0%