aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar@gmail.com>2026-09-24 03:42:34 +0530
committerArpit Chakladar <arpitchakladar@gmail.com>2026-09-24 03:42:34 +0530
commit44b8624d201e70c8418ada5db3c46e9ba130ea30 (patch)
treeab960997bf8831d294dd84838523b358b7012ac5
parent30f8fea050f3242f0e6a2072779e706b5c8ceaf1 (diff)
downloadhome-manager-config-44b8624d201e70c8418ada5db3c46e9ba130ea30.tar.gz
home-manager-config-44b8624d201e70c8418ada5db3c46e9ba130ea30.zip
refactor(naming): use kebab-case option names and consistent gopass secret naming
-rw-r--r--modules/communication/neomutt/account/assertions.nix4
-rw-r--r--modules/communication/neomutt/account/default.nix26
-rw-r--r--modules/communication/neomutt/account/flavors/gmail/default.nix2
-rw-r--r--modules/communication/neomutt/account/options.nix20
-rw-r--r--modules/communication/senpai/assertions.nix5
-rw-r--r--modules/communication/senpai/default.nix57
-rw-r--r--modules/desktop/eww/default.nix15
-rw-r--r--modules/desktop/rofi/default.nix3
-rw-r--r--modules/desktop/xdg/default.nix5
-rw-r--r--modules/development/git/assertions.nix12
-rw-r--r--modules/development/git/default.nix34
-rw-r--r--modules/fonts/default.nix12
-rw-r--r--modules/office/calcurse/default.nix76
-rw-r--r--modules/security/gopass/default.nix97
-rw-r--r--modules/security/ssh/default.nix14
-rw-r--r--modules/web/chawan/default.nix14
-rw-r--r--modules/web/chromium/assertions.nix4
-rw-r--r--modules/web/chromium/default.nix44
-rw-r--r--users/arpit/default.nix4
-rw-r--r--users/arpit/private.example.nix18
20 files changed, 264 insertions, 202 deletions
diff --git a/modules/communication/neomutt/account/assertions.nix b/modules/communication/neomutt/account/assertions.nix
index c19ab72..5c30311 100644
--- a/modules/communication/neomutt/account/assertions.nix
+++ b/modules/communication/neomutt/account/assertions.nix
@@ -5,12 +5,12 @@
{
assertion =
!config.communication.neomutt.enable
- || !lib.any (account: account.enable && account.passwordGopassSecret != null) (
+ || !lib.any (account: account.enable && account.password-gopass-secret != null) (
lib.attrValues config.communication.neomutt.accounts
)
|| config.security.gopass.enable;
message = ''
- An enabled communication.neomutt account uses passwordGopassSecret but security.gopass.enable is not set.
+ An enabled communication.neomutt account uses password-gopass-secret but security.gopass.enable is not set.
Enable security.gopass to provide the account password command.
'';
}
diff --git a/modules/communication/neomutt/account/default.nix b/modules/communication/neomutt/account/default.nix
index e2d92eb..61256e1 100644
--- a/modules/communication/neomutt/account/default.nix
+++ b/modules/communication/neomutt/account/default.nix
@@ -21,17 +21,19 @@
config = lib.mkIf config.communication.neomutt.enable {
accounts.email.accounts = lib.mapAttrs (accountName: accountInformation: {
- inherit (accountInformation) realName address primary;
+ inherit (accountInformation) address primary;
+
+ realName = accountInformation.real-name;
userName =
- if accountInformation.userName != null then
- accountInformation.userName
+ if accountInformation.username != null then
+ accountInformation.username
else
accountInformation.address;
passwordCommand =
- if accountInformation.passwordGopassSecret != null then
- "${lib.getExe config.security.gopass.package} -o ${accountInformation.passwordGopassSecret}"
+ if accountInformation.password-gopass-secret != null then
+ "${lib.getExe config.security.gopass.package} -o ${accountInformation.password-gopass-secret}"
else
null;
@@ -50,7 +52,7 @@
neomutt = {
enable = true;
- mailboxType = accountInformation.neomutt.mailboxType;
+ mailboxType = accountInformation.neomutt.mailbox-type;
extraConfig = accountInformation.neomutt.extraConfig;
};
@@ -71,7 +73,7 @@
enable = true;
neomutt = {
enable = true;
- virtualMailboxes = accountInformation.notmuch.neomutt.virtualMailboxes;
+ virtualMailboxes = accountInformation.notmuch.neomutt.virtual-mailboxes;
};
};
@@ -80,7 +82,7 @@
port = accountInformation.imap.port;
tls = {
enable = accountInformation.imap.tls.enable;
- useStartTls = accountInformation.imap.tls.useStartTls;
+ useStartTls = accountInformation.imap.tls.use-start-tls;
};
};
@@ -89,14 +91,14 @@
port = accountInformation.smtp.port;
tls = {
enable = accountInformation.smtp.tls.enable;
- useStartTls = accountInformation.smtp.tls.useStartTls;
+ useStartTls = accountInformation.smtp.tls.use-start-tls;
};
};
gpg = lib.optionalAttrs (accountInformation.gpg.key != null) {
key = accountInformation.gpg.key;
- signByDefault = accountInformation.gpg.signByDefault;
- encryptByDefault = accountInformation.gpg.encryptByDefault;
+ signByDefault = accountInformation.gpg.sign-by-default;
+ encryptByDefault = accountInformation.gpg.encrypt-by-default;
};
signature =
@@ -105,7 +107,7 @@
{
text = accountInformation.signature.text;
command = accountInformation.signature.command;
- showSignature = accountInformation.signature.showSignature;
+ showSignature = accountInformation.signature.show-signature;
};
}) (lib.filterAttrs (n: a: a.enable) config.communication.neomutt.accounts);
};
diff --git a/modules/communication/neomutt/account/flavors/gmail/default.nix b/modules/communication/neomutt/account/flavors/gmail/default.nix
index 66d7db3..5b3c098 100644
--- a/modules/communication/neomutt/account/flavors/gmail/default.nix
+++ b/modules/communication/neomutt/account/flavors/gmail/default.nix
@@ -32,7 +32,7 @@
neomutt.extraConfig = lib.mkBefore (builtins.readFile ./.muttrc);
- notmuch.neomutt.virtualMailboxes = lib.mkDefault [
+ notmuch.neomutt.virtual-mailboxes = lib.mkDefault [
{
name = "All Mail";
query = "folder:${name}/Inbox or folder:\"${name}/[Gmail]/Sent Mail\"";
diff --git a/modules/communication/neomutt/account/options.nix b/modules/communication/neomutt/account/options.nix
index 45e6744..676f8b0 100644
--- a/modules/communication/neomutt/account/options.nix
+++ b/modules/communication/neomutt/account/options.nix
@@ -6,7 +6,7 @@
default = true;
};
- realName = lib.mkOption {
+ real-name = lib.mkOption {
type = lib.types.str;
description = "Name displayed when sending mails.";
};
@@ -16,13 +16,13 @@
description = "Email address of this account.";
};
- userName = lib.mkOption {
+ username = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = "Server username. Defaults to address if null.";
};
- passwordGopassSecret = lib.mkOption {
+ password-gopass-secret = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = "Gopass secret path (e.g. mail/user@gmail.com). Constructs passwordCommand automatically.";
@@ -81,7 +81,7 @@
};
neomutt = {
- mailboxType = lib.mkOption {
+ mailbox-type = lib.mkOption {
type = lib.types.enum [
"maildir"
"imap"
@@ -178,7 +178,7 @@
notmuch = {
neomutt = {
- virtualMailboxes = lib.mkOption {
+ virtual-mailboxes = lib.mkOption {
type = lib.types.listOf (
lib.types.submodule {
options = {
@@ -237,7 +237,7 @@
description = "Enable TLS.";
};
- useStartTls = lib.mkOption {
+ use-start-tls = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Use STARTTLS.";
@@ -265,7 +265,7 @@
description = "Enable TLS.";
};
- useStartTls = lib.mkOption {
+ use-start-tls = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Use STARTTLS.";
@@ -280,13 +280,13 @@
description = "GPG key to use.";
};
- signByDefault = lib.mkOption {
+ sign-by-default = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Sign messages by default.";
};
- encryptByDefault = lib.mkOption {
+ encrypt-by-default = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Encrypt messages by default.";
@@ -306,7 +306,7 @@
description = "Command that generates a signature.";
};
- showSignature = lib.mkOption {
+ show-signature = lib.mkOption {
type = lib.types.nullOr (
lib.types.enum [
"append"
diff --git a/modules/communication/senpai/assertions.nix b/modules/communication/senpai/assertions.nix
index ed2cce8..8e74367 100644
--- a/modules/communication/senpai/assertions.nix
+++ b/modules/communication/senpai/assertions.nix
@@ -13,8 +13,9 @@
}
{
assertion =
- config.communication.senpai.identity.passwordGopassSecret == null || config.security.gopass.enable;
- message = "communication.senpai.identity.passwordGopassSecret requires security.gopass.enable.";
+ config.communication.senpai.identity.password-gopass-secret == null
+ || config.security.gopass.enable;
+ message = "communication.senpai.identity.password-gopass-secret requires security.gopass.enable.";
}
];
}
diff --git a/modules/communication/senpai/default.nix b/modules/communication/senpai/default.nix
index 56bb7ab..49f82d9 100644
--- a/modules/communication/senpai/default.nix
+++ b/modules/communication/senpai/default.nix
@@ -5,6 +5,9 @@
pkgs,
...
}:
+let
+ cfg = config.communication.senpai;
+in
{
imports = [ ./assertions.nix ];
@@ -17,48 +20,60 @@
description = "The senpai package to use.";
};
- server = {
- address = lib.mkOption {
- type = lib.types.str;
- description = "IRC server address (host[:port]). Supports irc://, ircs://, irc+insecure:// URLs.";
+ server = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ address = lib.mkOption {
+ type = lib.types.str;
+ description = "IRC server address (host[:port]). Supports irc://, ircs://, irc+insecure:// URLs.";
+ };
+ };
};
+ default = { };
+ description = "IRC server configuration.";
};
- identity = {
- nickname = lib.mkOption {
- type = lib.types.str;
- description = "Your IRC nickname (no spaces or colons).";
- };
+ identity = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ nickname = lib.mkOption {
+ type = lib.types.str;
+ description = "Your IRC nickname (no spaces or colons).";
+ };
- passwordGopassSecret = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "Gopass secret path for SASL password (e.g. irc/user@server). Constructs password-cmd automatically.";
+ password-gopass-secret = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Gopass secret path for SASL password (e.g. irc/user@server). Constructs password-cmd automatically.";
+ };
+ };
};
+ default = { };
+ description = "Identity configuration.";
};
};
config = lib.mkMerge [
- (lib.mkIf config.communication.senpai.enable {
+ (lib.mkIf cfg.enable {
programs.senpai = {
enable = true;
- package = config.communication.senpai.package;
+ package = cfg.package;
config = {
- address = config.communication.senpai.server.address;
- nickname = config.communication.senpai.identity.nickname;
- password-cmd = lib.mkIf (config.communication.senpai.identity.passwordGopassSecret != null) [
+ address = cfg.server.address;
+ nickname = cfg.identity.nickname;
+ password-cmd = lib.mkIf (cfg.identity.password-gopass-secret != null) [
(lib.getExe config.security.gopass.package)
"show"
"-o"
- config.communication.senpai.identity.passwordGopassSecret
+ cfg.identity.password-gopass-secret
];
};
};
})
- (lib.mkIf (config.communication.senpai.enable && config.terminal.kitty.enable) {
+ (lib.mkIf (cfg.enable && config.terminal.kitty.enable) {
xdg.desktopEntries."senpai" = {
name = "Senpai";
- exec = "${lib.getExe config.terminal.kitty.package} --class senpai -e ${lib.getExe config.communication.senpai.package}";
+ exec = "${lib.getExe config.terminal.kitty.package} --class senpai -e ${lib.getExe cfg.package}";
icon = "senpai";
categories = [
"Network"
diff --git a/modules/desktop/eww/default.nix b/modules/desktop/eww/default.nix
index be6236f..a0727cd 100644
--- a/modules/desktop/eww/default.nix
+++ b/modules/desktop/eww/default.nix
@@ -6,6 +6,7 @@
...
}:
let
+ cfg = config.desktop.eww;
base16Colors = import ../../colors/base16 { inherit config lib pkgs; };
in
{
@@ -46,10 +47,10 @@ in
[
config.fonts.normal
(toString config.fonts.size)
- (toString config.fonts.iconSize)
- (toString config.fonts.labelSize)
- (toString config.fonts.smallSize)
- (toString config.fonts.idxSize)
+ (toString config.fonts.icon-size)
+ (toString config.fonts.label-size)
+ (toString config.fonts.small-size)
+ (toString config.fonts.idx-size)
]
(builtins.readFile ./eww.scss);
in
@@ -67,9 +68,9 @@ in
Service = {
Type = "oneshot";
RemainAfterExit = true;
- ExecStart = "${lib.getExe config.desktop.eww.package} open bar";
- ExecReload = "${lib.getExe config.desktop.eww.package} reload && ${lib.getExe config.desktop.eww.package} open bar";
- ExecStop = "${lib.getExe config.desktop.eww.package} kill";
+ ExecStart = "${lib.getExe cfg.package} open bar";
+ ExecReload = "${lib.getExe cfg.package} reload && ${lib.getExe cfg.package} open bar";
+ ExecStop = "${lib.getExe cfg.package} kill";
Restart = "on-failure";
};
Install.WantedBy = [ "graphical-session.target" ];
diff --git a/modules/desktop/rofi/default.nix b/modules/desktop/rofi/default.nix
index a15ce0a..ed1cf05 100644
--- a/modules/desktop/rofi/default.nix
+++ b/modules/desktop/rofi/default.nix
@@ -6,6 +6,7 @@
...
}:
let
+ cfg = config.desktop.rofi;
base16Colors = import ../../colors/base16 { inherit config lib pkgs; };
in
{
@@ -31,7 +32,7 @@ in
]
[
''"${config.fonts.normal} Bold ${toString config.fonts.size}"''
- ''"${config.fonts.normal} Bold ${toString config.fonts.idxSize}"''
+ ''"${config.fonts.normal} Bold ${toString config.fonts.idx-size}"''
]
(builtins.readFile ./theme.rasi);
in
diff --git a/modules/desktop/xdg/default.nix b/modules/desktop/xdg/default.nix
index 7f46d37..72b0290 100644
--- a/modules/desktop/xdg/default.nix
+++ b/modules/desktop/xdg/default.nix
@@ -6,10 +6,11 @@
...
}:
let
+ cfg = config.desktop;
base16Colors = import ../../colors/base16 { inherit config lib pkgs; };
in
{
- config = lib.mkIf config.desktop.enable {
+ config = lib.mkIf cfg.enable {
dconf.enable = true;
xdg.portal = {
@@ -37,7 +38,7 @@ in
enable = true;
font = {
name = config.fonts.normal;
- size = config.fonts.uiSize;
+ size = config.fonts.ui-size;
};
theme = {
name = "Adwaita-dark";
diff --git a/modules/development/git/assertions.nix b/modules/development/git/assertions.nix
index c66714a..2baeced 100644
--- a/modules/development/git/assertions.nix
+++ b/modules/development/git/assertions.nix
@@ -3,24 +3,24 @@
{
assertions = [
{
- assertion = !config.development.git.signing.signByDefault || config.development.git.enable;
+ assertion = !config.development.git.signing.sign-by-default || config.development.git.enable;
message = ''
- development.git.signing.signByDefault is enabled but development.git.enable is not.
+ development.git.signing.sign-by-default is enabled but development.git.enable is not.
Enable development.git before enabling commit signing.
'';
}
{
assertion =
- !config.development.git.signing.signByDefault || config.development.git.signing.key != null;
+ !config.development.git.signing.sign-by-default || config.development.git.signing.key != null;
message = ''
- development.git.signing.signByDefault is enabled but development.git.signing.key is not set.
+ development.git.signing.sign-by-default is enabled but development.git.signing.key is not set.
Set a GPG key ID before enabling commit signing by default.
'';
}
{
- assertion = !config.development.git.signing.signByDefault || config.security.gpg.enable;
+ assertion = !config.development.git.signing.sign-by-default || config.security.gpg.enable;
message = ''
- development.git.signing.signByDefault is enabled but security.gpg.enable is not.
+ development.git.signing.sign-by-default is enabled but security.gpg.enable is not.
Commit signing requires the managed GPG configuration. Please enable security.gpg.
'';
}
diff --git a/modules/development/git/default.nix b/modules/development/git/default.nix
index 15dcc80..593c8a3 100644
--- a/modules/development/git/default.nix
+++ b/modules/development/git/default.nix
@@ -2,8 +2,12 @@
{
config,
lib,
+ pkgs,
...
}:
+let
+ cfg = config.development.git;
+in
{
imports = [
./assertions.nix
@@ -30,29 +34,35 @@
description = "Git email.";
};
- signing = {
- key = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "GPG key ID used for signing commits.";
- };
+ signing = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ key = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "GPG key ID used for signing commits.";
+ };
- signByDefault = lib.mkEnableOption "Sign commits by default.";
+ sign-by-default = lib.mkEnableOption "Sign commits by default.";
+ };
+ };
+ default = { };
+ description = "Git commit signing configuration.";
};
};
- config = lib.mkIf config.development.git.enable {
+ config = lib.mkIf cfg.enable {
programs.git = {
enable = true;
signing = {
- key = config.development.git.signing.key;
- signByDefault = config.development.git.signing.signByDefault;
+ key = cfg.signing.key;
+ sign-by-default = cfg.signing.sign-by-default;
};
settings = lib.mkMerge [
{
user = {
- name = config.development.git.username;
- email = config.development.git.email;
+ name = cfg.username;
+ email = cfg.email;
};
core = {
askPass = "";
diff --git a/modules/fonts/default.nix b/modules/fonts/default.nix
index 2df7b88..b7d78df 100644
--- a/modules/fonts/default.nix
+++ b/modules/fonts/default.nix
@@ -1,7 +1,7 @@
# Font configuration
{
- lib,
config,
+ lib,
pkgs,
...
}:
@@ -30,31 +30,31 @@
default = 18;
};
- uiSize = lib.mkOption {
+ ui-size = lib.mkOption {
type = lib.types.int;
description = "Default desktop UI (GTK) font size.";
default = 11;
};
- iconSize = lib.mkOption {
+ icon-size = lib.mkOption {
type = lib.types.int;
description = "Font size for icons (base size + 6).";
default = 24;
};
- labelSize = lib.mkOption {
+ label-size = lib.mkOption {
type = lib.types.int;
description = "Font size for labels (base size - 2).";
default = 16;
};
- smallSize = lib.mkOption {
+ small-size = lib.mkOption {
type = lib.types.int;
description = "Font size for small text (base size - 6).";
default = 12;
};
- idxSize = lib.mkOption {
+ idx-size = lib.mkOption {
type = lib.types.int;
description = "Font size for index numbers (base size - 4).";
default = 14;
diff --git a/modules/office/calcurse/default.nix b/modules/office/calcurse/default.nix
index 6e3e855..7c1df5e 100644
--- a/modules/office/calcurse/default.nix
+++ b/modules/office/calcurse/default.nix
@@ -6,6 +6,8 @@
...
}:
let
+ cfg = config.office.calcurse;
+
calcurseSync = pkgs.writeShellScriptBin "calcurse-sync" (builtins.readFile ./calcurse-sync.sh);
calcurse = pkgs.symlinkJoin {
@@ -16,13 +18,13 @@ let
pkgs.libnotify
]
++ lib.optionals config.development.nixvim.enable [ config.development.nixvim.package ]
- ++ lib.optionals config.office.calcurse.sync.enable [ calcurseSync ];
+ ++ lib.optionals cfg.sync.enable [ calcurseSync ];
nativeBuildInputs = [ pkgs.makeWrapper ];
postBuild = ''
${lib.optionalString config.development.nixvim.enable ''
wrapProgram $out/bin/calcurse --set PAGER "nvim"
''}
- ${lib.optionalString config.office.calcurse.sync.enable ''
+ ${lib.optionalString cfg.sync.enable ''
wrapProgram $out/bin/calcurse-sync \
--prefix PATH : ${
lib.makeBinPath [
@@ -31,8 +33,8 @@ let
pkgs.gnused
]
} \
- ${lib.optionalString (config.office.calcurse.sync.remote != null) ''
- --set CALCURSE_SYNC_REMOTE ${lib.escapeShellArg config.office.calcurse.sync.remote}
+ ${lib.optionalString (cfg.sync.remote != null) ''
+ --set CALCURSE_SYNC_REMOTE ${lib.escapeShellArg cfg.sync.remote}
''}
''}
'';
@@ -52,35 +54,47 @@ in
default = calcurse;
description = "The calcurse package to use.";
};
- sync = {
- enable = lib.mkEnableOption "Enables git-backed syncing of the calcurse data directory (builds calcurse-sync, installs the sync hooks, and runs an initial 'calcurse-sync init' on activation).";
- remote = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "Git remote URL for the calcurse data directory. Use an https:// URL if 'credential' is configured. When set, calcurse-sync uses it automatically on first init instead of prompting.";
- };
- credential = {
- username = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "Username for HTTPS git authentication against the calcurse remote.";
- };
- passwordGopassPath = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "gopass entry path holding the password or token used for HTTPS git authentication against the calcurse remote. E.g. 'git/calcurse-sync'.";
+ sync = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ enable = lib.mkEnableOption "Enables git-backed syncing of the calcurse data directory (builds calcurse-sync, installs the sync hooks, and runs an initial 'calcurse-sync init' on activation).";
+ remote = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Git remote URL for the calcurse data directory. Use an https:// URL if 'credential' is configured. When set, calcurse-sync uses it automatically on first init instead of prompting.";
+ };
+ credential = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ username = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Username for HTTPS git authentication against the calcurse remote.";
+ };
+ password-gopass-secret = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "gopass entry path holding the password or token used for HTTPS git authentication against the calcurse remote. E.g. 'git/calcurse-sync'.";
+ };
+ };
+ };
+ default = { };
+ description = "Credentials for HTTPS git authentication.";
+ };
};
};
+ default = { };
+ description = "Git-backed syncing configuration.";
};
};
config = lib.mkMerge [
- (lib.mkIf config.office.calcurse.enable {
+ (lib.mkIf cfg.enable {
home.file.".local/share/icons/hicolor/scalable/apps/calcurse.svg" = {
source = ../../../assets/icons/apps/calcurse.svg;
};
- home.packages = [ config.office.calcurse.package ];
+ home.packages = [ cfg.package ];
xdg.configFile."calcurse/conf" = {
text =
builtins.replaceStrings [ "@@CALCURSE_ICON@@" ] [ "${../../../assets/icons/apps/calcurse.svg}" ]
@@ -92,10 +106,10 @@ in
force = true;
};
})
- (lib.mkIf (config.office.calcurse.enable && config.terminal.kitty.enable) {
+ (lib.mkIf (cfg.enable && config.terminal.kitty.enable) {
xdg.desktopEntries."calcurse" = {
name = "calcurse";
- exec = "${lib.getExe config.terminal.kitty.package} --class calcurse -e ${lib.getExe config.office.calcurse.package}";
+ exec = "${lib.getExe config.terminal.kitty.package} --class calcurse -e ${lib.getExe cfg.package}";
icon = "calcurse";
categories = [
"Office"
@@ -106,7 +120,7 @@ in
type = "Application";
};
})
- (lib.mkIf config.office.calcurse.sync.enable {
+ (lib.mkIf cfg.sync.enable {
xdg.configFile."calcurse/hooks/pre-load" = {
source = ./hooks/pre-load;
executable = true;
@@ -129,15 +143,15 @@ in
commit.gpgSign = false;
tag.gpgSign = false;
}
- // lib.optionalAttrs (config.office.calcurse.sync.credential.passwordGopassPath != null) {
- credential.helper = "!f() { echo username=${lib.escapeShellArg config.office.calcurse.sync.credential.username}; echo password=\"$(${lib.getExe config.security.gopass.package} show -o ${lib.escapeShellArg config.office.calcurse.sync.credential.passwordGopassPath})\"; }; f";
+ // lib.optionalAttrs (cfg.sync.credential.password-gopass-secret != null) {
+ credential.helper = "!f() { echo username=${lib.escapeShellArg cfg.sync.credential.username}; echo password=\"$(${lib.getExe config.security.gopass.package} show -o ${lib.escapeShellArg cfg.sync.credential.password-gopass-secret})\"; }; f";
};
}
];
- home.activation.calcurseSyncInit = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
- run ${config.office.calcurse.package}/bin/calcurse-sync init || true
- '';
+ home.activation.calcurseSyncInit = lib.hm.dag.entryAfter [ "writeBoundary" ] (
+ pkgs.writeText "calcurse-sync-init.sh" ("run " + cfg.package + "/bin/calcurse-sync init || true")
+ );
})
];
}
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index 616baeb..17624ef 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -5,6 +5,9 @@
pkgs,
...
}:
+let
+ cfg = config.security.gopass;
+in
{
imports = [ ./assertions.nix ];
@@ -16,33 +19,51 @@
default = config.programs.password-store.package;
description = "The gopass package to use.";
};
- sync = {
- enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
- remote = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
- };
- credential = {
- username = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "Username for HTTPS git authentication against the gopass remote.";
- };
- passwordGopassPath = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "gopass entry path holding the password or token used.";
+ sync = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
+ remote = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
+ };
+ credential = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ username = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Username for HTTPS git authentication against the gopass remote.";
+ };
+ password-gopass-secret = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "gopass entry path holding the password or token used.";
+ };
+ };
+ };
+ default = { };
+ description = "Credentials for HTTPS git authentication.";
+ };
};
};
+ default = { };
+ description = "Git-backed syncing configuration.";
};
- creation-templates = {
- enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands.";
+ creation-templates = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands.";
+ };
+ };
+ default = { };
+ description = "Creation templates configuration.";
};
};
config = lib.mkMerge [
- (lib.mkIf config.security.gopass.enable {
+ (lib.mkIf cfg.enable {
programs.password-store = {
enable = true;
package = pkgs.gopass.override { passAlias = true; };
@@ -68,15 +89,9 @@
gpgSign = false;
};
}
- //
- lib.optionalAttrs
- (
- config.security.gopass.sync.enable
- && config.security.gopass.sync.credential.passwordGopassPath != null
- )
- {
- credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f";
- };
+ // lib.optionalAttrs (cfg.sync.enable && cfg.sync.credential.password-gopass-secret != null) {
+ credential.helper = "!f() { echo username=${lib.escapeShellArg cfg.sync.credential.username}; echo password=\"$(${cfg.package}/bin/gopass show -o ${lib.escapeShellArg cfg.sync.credential.password-gopass-secret})\"; }; f";
+ };
}
];
@@ -88,20 +103,18 @@
source = ../../../assets/icons/apps/gopass.svg;
};
- home.activation.copyCreationTemplatesForGopass =
- lib.mkIf config.security.gopass.creation-templates.enable
- (
- lib.hm.dag.entryAfter [ "writeBoundary" ] ''
- $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
- $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create
- $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
- ''
- );
+ home.activation.copyCreationTemplatesForGopass = lib.mkIf cfg.creation-templates.enable (
+ lib.hm.dag.entryAfter [ "writeBoundary" ] ''
+ $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
+ $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create
+ $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
+ ''
+ );
})
- (lib.mkIf (config.security.gopass.enable && config.terminal.kitty.enable) {
+ (lib.mkIf (cfg.enable && config.terminal.kitty.enable) {
xdg.desktopEntries."gopass" = {
name = "gopass";
- exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe config.security.gopass.package}";
+ exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe cfg.package}";
icon = "gopass";
comment = "Standard Unix password manager (Go implementation)";
categories = [ "Utility" ];
@@ -109,7 +122,7 @@
type = "Application";
};
})
- (lib.mkIf config.security.gopass.sync.enable {
+ (lib.mkIf cfg.sync.enable {
home.activation.gopassSyncInit =
let
gopassSyncInit = pkgs.writeShellApplication {
@@ -121,7 +134,7 @@
text =
builtins.replaceStrings
[ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ]
- [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ]
+ [ config.programs.password-store.settings.PASSWORD_STORE_DIR cfg.sync.remote ]
(builtins.readFile ./gopass-sync-init.sh);
};
in
diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix
index e18b933..ed93e27 100644
--- a/modules/security/ssh/default.nix
+++ b/modules/security/ssh/default.nix
@@ -6,13 +6,15 @@
...
}:
let
+ cfg = config.security.ssh;
+
gpgSshKeyLoad = pkgs.writeShellApplication {
name = "gpg-ssh-key-load";
runtimeInputs = [
config.terminal.bash.package
config.security.gopass.package
config.security.gpg.package
- config.security.ssh.package
+ cfg.package
pkgs.coreutils
];
text =
@@ -22,7 +24,7 @@ let
"@@GNUPGHOME@@"
]
[
- config.security.ssh.sshKeyGopassPath
+ cfg.ssh-key-gopass-secret
config.home.sessionVariables.GNUPGHOME
]
(builtins.readFile ./gpg-ssh-key-load.sh);
@@ -38,7 +40,7 @@ in
description = "The ssh package to use.";
};
- sshKeyGopassPath = lib.mkOption {
+ ssh-key-gopass-secret = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = ''
@@ -50,8 +52,8 @@ in
};
config = lib.mkMerge [
- (lib.mkIf config.security.ssh.enable {
- home.packages = [ config.security.ssh.package ];
+ (lib.mkIf cfg.enable {
+ home.packages = [ cfg.package ];
assertions = [
{
@@ -64,7 +66,7 @@ in
];
})
- (lib.mkIf (config.security.ssh.enable && config.security.ssh.sshKeyGopassPath != null) {
+ (lib.mkIf (cfg.enable && cfg.ssh-key-gopass-secret != null) {
home.activation.gpgSshKeyLoad = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
run ${lib.getExe gpgSshKeyLoad} || true
'';
diff --git a/modules/web/chawan/default.nix b/modules/web/chawan/default.nix
index f3f0a30..0f1256d 100644
--- a/modules/web/chawan/default.nix
+++ b/modules/web/chawan/default.nix
@@ -2,8 +2,12 @@
{
config,
lib,
+ pkgs,
...
}:
+let
+ cfg = config.web.chawan;
+in
{
imports = [
./assertions.nix
@@ -17,7 +21,7 @@
default = config.programs.chawan.package;
description = "Package to use for chawan.";
};
- homeUrl = lib.mkOption {
+ home-url = lib.mkOption {
type = lib.types.str;
default = "https://searx.space";
description = "The first page to open when chawan is launched.";
@@ -25,7 +29,7 @@
};
config = lib.mkMerge [
- (lib.mkIf config.web.chawan.enable {
+ (lib.mkIf cfg.enable {
home.file.".local/share/icons/hicolor/scalable/apps/internet-web-browser.svg" = {
source = ../../../assets/icons/apps/internet-web-browser.svg;
};
@@ -50,13 +54,13 @@
};
};
home.packages = [
- config.web.chawan.package
+ cfg.package
];
})
- (lib.mkIf (config.web.chawan.enable && config.terminal.kitty.enable) {
+ (lib.mkIf (cfg.enable && config.terminal.kitty.enable) {
xdg.desktopEntries."chawan" = {
name = "Chawan";
- exec = "${lib.getExe config.terminal.kitty.package} --class chawan -e ${lib.getExe config.web.chawan.package} ${config.web.chawan.homeUrl}";
+ exec = "${lib.getExe config.terminal.kitty.package} --class chawan -e ${lib.getExe cfg.package} ${cfg.home-url}";
icon = "internet-web-browser";
categories = [ "Network" ];
comment = "Text-based web browser";
diff --git a/modules/web/chromium/assertions.nix b/modules/web/chromium/assertions.nix
index 465ebbd..79a9ba1 100644
--- a/modules/web/chromium/assertions.nix
+++ b/modules/web/chromium/assertions.nix
@@ -3,8 +3,8 @@
{
assertions = [
{
- assertion = !config.web.chromium.useOpenGL || config.web.chromium.enable;
- message = "web.chromium.useOpenGL requires web.chromium.enable.";
+ assertion = !config.web.chromium.use-opengl || config.web.chromium.enable;
+ message = "web.chromium.use-opengl requires web.chromium.enable.";
}
];
}
diff --git a/modules/web/chromium/default.nix b/modules/web/chromium/default.nix
index 1e3608c..ae9e97e 100644
--- a/modules/web/chromium/default.nix
+++ b/modules/web/chromium/default.nix
@@ -4,6 +4,10 @@
pkgs,
...
}:
+let
+ cfg = config.web.chromium;
+ extensionDirs = lib.concatStringsSep "," (lib.mapAttrsToList (_: ext: ext.drv) cfg.extensions);
+in
{
imports = [
./assertions.nix
@@ -20,32 +24,26 @@
defaultText = lib.literalExpression "config.programs.chromium.finalPackage";
description = "Package to use for chromium. Defaults to the wrapped finalPackage from programs.chromium.";
};
- useOpenGL = lib.mkEnableOption ''
+ use-opengl = lib.mkEnableOption ''
Use OpenGL APIs for graphics acceleration
'';
};
- config = lib.mkIf config.web.chromium.enable {
+ config = lib.mkIf cfg.enable {
programs.chromium = {
enable = true;
package = pkgs.ungoogled-chromium;
- commandLineArgs =
- let
- extensionDirs = lib.concatStringsSep "," (
- lib.mapAttrsToList (_: ext: ext.drv) config.web.chromium.extensions
- );
- in
- [
- "--force-dark-mode"
- "--force-device-scale-factor=1.15"
- # Don't use the gnome password store
- "--password-store=basic"
- "--load-extension=${extensionDirs}"
- ]
- ++ lib.optionals config.web.chromium.useOpenGL [
- "--use-angle=opengl"
- "--use-cmd-decoder=passthrough"
- ];
+ commandLineArgs = [
+ "--force-dark-mode"
+ "--force-device-scale-factor=1.15"
+ # Don't use the gnome password store
+ "--password-store=basic"
+ "--load-extension=${extensionDirs}"
+ ]
+ ++ lib.optionals cfg.use-opengl [
+ "--use-angle=opengl"
+ "--use-cmd-decoder=passthrough"
+ ];
};
xdg.mimeApps.defaultApplications = {
@@ -94,10 +92,10 @@
credentials_enable_autosignin = false;
extensions = {
pinned_extensions = [
- config.web.chromium.extensions.browserpass.id
- config.web.chromium.extensions.darkreader.id
- config.web.chromium.extensions.ublockOrigin.id
- config.web.chromium.extensions.vimium.id
+ cfg.extensions.browserpass.id
+ cfg.extensions.darkreader.id
+ cfg.extensions.ublockOrigin.id
+ cfg.extensions.vimium.id
];
theme = {
id = "";
diff --git a/users/arpit/default.nix b/users/arpit/default.nix
index c2dec0e..7b02d30 100644
--- a/users/arpit/default.nix
+++ b/users/arpit/default.nix
@@ -36,7 +36,7 @@
development.delta.enable = true;
development.direnv.enable = true;
development.git.enable = true;
- development.git.signing.signByDefault = true;
+ development.git.signing.sign-by-default = true;
development.lazygit.enable = true;
development.nixvim.enable = true;
development.opencode.enable = true;
@@ -101,7 +101,7 @@
web.aria2.enable = true;
web.chawan.enable = true;
web.chromium.enable = true;
- web.chromium.useOpenGL = false;
+ web.chromium.use-opengl = false;
programs.home-manager.enable = true;
}
diff --git a/users/arpit/private.example.nix b/users/arpit/private.example.nix
index 3752f68..54fd972 100644
--- a/users/arpit/private.example.nix
+++ b/users/arpit/private.example.nix
@@ -5,16 +5,16 @@
remote = "YOUR_REPOSITORY_URL";
credential = {
username = "example";
- passwordGopassPath = "websites/github.com/example/tokens/calendar";
+ password-gopass-secret = "websites/github.com/example/tokens/calendar";
};
};
# Email - Template for configuring neomutt email accounts
config.communication.neomutt.accounts = {
"example@gmail.com" = {
- realName = "Example User";
+ real-name = "Example User";
address = "user@gmail.com";
- passwordGopassSecret = "mail/user@gmail.com";
+ password-gopass-secret = "mail/user@gmail.com";
flavor = "gmail.com";
primary = true;
neomutt.extraConfig = ''
@@ -22,8 +22,8 @@
'';
gpg = {
key = "YOUR_GPG_KEY_ID";
- signByDefault = true;
- encryptByDefault = false; # set true only if you also want auto-encrypt
+ sign-by-default = true;
+ encrypt-by-default = false; # set true only if you also want auto-encrypt
};
};
};
@@ -35,7 +35,7 @@
};
identity = {
nickname = "example";
- passwordGopassSecret = "irc/user@irc.example.com";
+ password-gopass-secret = "irc/user@irc.example.com";
};
};
@@ -45,19 +45,19 @@
email = "you@example.com";
signing = {
key = "EXAMPLE_GPG_KEY_ID";
- signByDefault = true;
+ sign-by-default = true;
};
};
# SSH key to load into the gpg-agent from gopass (entry in the gopass store)
- config.security.ssh.sshKeyGopassPath = "ssh/hostname/username";
+ config.security.ssh.ssh-key-gopass-secret = "ssh/hostname/username";
# Gopass - Template for configuring gopass, specially syncing
config.security.gopass.sync = {
remote = "YOUR_REPOSITORY_URL";
credential = {
username = "example";
- passwordGopassPath = "websites/github.com/example/tokens/calendar";
+ password-gopass-secret = "websites/github.com/example/tokens/calendar";
};
};
}