diff options
| author | Arpit Chakladar <arpitchakladar@gmail.com> | 2026-09-24 03:42:34 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar@gmail.com> | 2026-09-24 03:42:34 +0530 |
| commit | 44b8624d201e70c8418ada5db3c46e9ba130ea30 (patch) | |
| tree | ab960997bf8831d294dd84838523b358b7012ac5 | |
| parent | 30f8fea050f3242f0e6a2072779e706b5c8ceaf1 (diff) | |
| download | home-manager-config-44b8624d201e70c8418ada5db3c46e9ba130ea30.tar.gz home-manager-config-44b8624d201e70c8418ada5db3c46e9ba130ea30.zip | |
refactor(naming): use kebab-case option names and consistent gopass secret naming
| -rw-r--r-- | modules/communication/neomutt/account/assertions.nix | 4 | ||||
| -rw-r--r-- | modules/communication/neomutt/account/default.nix | 26 | ||||
| -rw-r--r-- | modules/communication/neomutt/account/flavors/gmail/default.nix | 2 | ||||
| -rw-r--r-- | modules/communication/neomutt/account/options.nix | 20 | ||||
| -rw-r--r-- | modules/communication/senpai/assertions.nix | 5 | ||||
| -rw-r--r-- | modules/communication/senpai/default.nix | 57 | ||||
| -rw-r--r-- | modules/desktop/eww/default.nix | 15 | ||||
| -rw-r--r-- | modules/desktop/rofi/default.nix | 3 | ||||
| -rw-r--r-- | modules/desktop/xdg/default.nix | 5 | ||||
| -rw-r--r-- | modules/development/git/assertions.nix | 12 | ||||
| -rw-r--r-- | modules/development/git/default.nix | 34 | ||||
| -rw-r--r-- | modules/fonts/default.nix | 12 | ||||
| -rw-r--r-- | modules/office/calcurse/default.nix | 76 | ||||
| -rw-r--r-- | modules/security/gopass/default.nix | 97 | ||||
| -rw-r--r-- | modules/security/ssh/default.nix | 14 | ||||
| -rw-r--r-- | modules/web/chawan/default.nix | 14 | ||||
| -rw-r--r-- | modules/web/chromium/assertions.nix | 4 | ||||
| -rw-r--r-- | modules/web/chromium/default.nix | 44 | ||||
| -rw-r--r-- | users/arpit/default.nix | 4 | ||||
| -rw-r--r-- | users/arpit/private.example.nix | 18 |
20 files changed, 264 insertions, 202 deletions
diff --git a/modules/communication/neomutt/account/assertions.nix b/modules/communication/neomutt/account/assertions.nix index c19ab72..5c30311 100644 --- a/modules/communication/neomutt/account/assertions.nix +++ b/modules/communication/neomutt/account/assertions.nix @@ -5,12 +5,12 @@ { assertion = !config.communication.neomutt.enable - || !lib.any (account: account.enable && account.passwordGopassSecret != null) ( + || !lib.any (account: account.enable && account.password-gopass-secret != null) ( lib.attrValues config.communication.neomutt.accounts ) || config.security.gopass.enable; message = '' - An enabled communication.neomutt account uses passwordGopassSecret but security.gopass.enable is not set. + An enabled communication.neomutt account uses password-gopass-secret but security.gopass.enable is not set. Enable security.gopass to provide the account password command. ''; } diff --git a/modules/communication/neomutt/account/default.nix b/modules/communication/neomutt/account/default.nix index e2d92eb..61256e1 100644 --- a/modules/communication/neomutt/account/default.nix +++ b/modules/communication/neomutt/account/default.nix @@ -21,17 +21,19 @@ config = lib.mkIf config.communication.neomutt.enable { accounts.email.accounts = lib.mapAttrs (accountName: accountInformation: { - inherit (accountInformation) realName address primary; + inherit (accountInformation) address primary; + + realName = accountInformation.real-name; userName = - if accountInformation.userName != null then - accountInformation.userName + if accountInformation.username != null then + accountInformation.username else accountInformation.address; passwordCommand = - if accountInformation.passwordGopassSecret != null then - "${lib.getExe config.security.gopass.package} -o ${accountInformation.passwordGopassSecret}" + if accountInformation.password-gopass-secret != null then + "${lib.getExe config.security.gopass.package} -o ${accountInformation.password-gopass-secret}" else null; @@ -50,7 +52,7 @@ neomutt = { enable = true; - mailboxType = accountInformation.neomutt.mailboxType; + mailboxType = accountInformation.neomutt.mailbox-type; extraConfig = accountInformation.neomutt.extraConfig; }; @@ -71,7 +73,7 @@ enable = true; neomutt = { enable = true; - virtualMailboxes = accountInformation.notmuch.neomutt.virtualMailboxes; + virtualMailboxes = accountInformation.notmuch.neomutt.virtual-mailboxes; }; }; @@ -80,7 +82,7 @@ port = accountInformation.imap.port; tls = { enable = accountInformation.imap.tls.enable; - useStartTls = accountInformation.imap.tls.useStartTls; + useStartTls = accountInformation.imap.tls.use-start-tls; }; }; @@ -89,14 +91,14 @@ port = accountInformation.smtp.port; tls = { enable = accountInformation.smtp.tls.enable; - useStartTls = accountInformation.smtp.tls.useStartTls; + useStartTls = accountInformation.smtp.tls.use-start-tls; }; }; gpg = lib.optionalAttrs (accountInformation.gpg.key != null) { key = accountInformation.gpg.key; - signByDefault = accountInformation.gpg.signByDefault; - encryptByDefault = accountInformation.gpg.encryptByDefault; + signByDefault = accountInformation.gpg.sign-by-default; + encryptByDefault = accountInformation.gpg.encrypt-by-default; }; signature = @@ -105,7 +107,7 @@ { text = accountInformation.signature.text; command = accountInformation.signature.command; - showSignature = accountInformation.signature.showSignature; + showSignature = accountInformation.signature.show-signature; }; }) (lib.filterAttrs (n: a: a.enable) config.communication.neomutt.accounts); }; diff --git a/modules/communication/neomutt/account/flavors/gmail/default.nix b/modules/communication/neomutt/account/flavors/gmail/default.nix index 66d7db3..5b3c098 100644 --- a/modules/communication/neomutt/account/flavors/gmail/default.nix +++ b/modules/communication/neomutt/account/flavors/gmail/default.nix @@ -32,7 +32,7 @@ neomutt.extraConfig = lib.mkBefore (builtins.readFile ./.muttrc); - notmuch.neomutt.virtualMailboxes = lib.mkDefault [ + notmuch.neomutt.virtual-mailboxes = lib.mkDefault [ { name = "All Mail"; query = "folder:${name}/Inbox or folder:\"${name}/[Gmail]/Sent Mail\""; diff --git a/modules/communication/neomutt/account/options.nix b/modules/communication/neomutt/account/options.nix index 45e6744..676f8b0 100644 --- a/modules/communication/neomutt/account/options.nix +++ b/modules/communication/neomutt/account/options.nix @@ -6,7 +6,7 @@ default = true; }; - realName = lib.mkOption { + real-name = lib.mkOption { type = lib.types.str; description = "Name displayed when sending mails."; }; @@ -16,13 +16,13 @@ description = "Email address of this account."; }; - userName = lib.mkOption { + username = lib.mkOption { type = lib.types.nullOr lib.types.str; default = null; description = "Server username. Defaults to address if null."; }; - passwordGopassSecret = lib.mkOption { + password-gopass-secret = lib.mkOption { type = lib.types.nullOr lib.types.str; default = null; description = "Gopass secret path (e.g. mail/user@gmail.com). Constructs passwordCommand automatically."; @@ -81,7 +81,7 @@ }; neomutt = { - mailboxType = lib.mkOption { + mailbox-type = lib.mkOption { type = lib.types.enum [ "maildir" "imap" @@ -178,7 +178,7 @@ notmuch = { neomutt = { - virtualMailboxes = lib.mkOption { + virtual-mailboxes = lib.mkOption { type = lib.types.listOf ( lib.types.submodule { options = { @@ -237,7 +237,7 @@ description = "Enable TLS."; }; - useStartTls = lib.mkOption { + use-start-tls = lib.mkOption { type = lib.types.bool; default = false; description = "Use STARTTLS."; @@ -265,7 +265,7 @@ description = "Enable TLS."; }; - useStartTls = lib.mkOption { + use-start-tls = lib.mkOption { type = lib.types.bool; default = false; description = "Use STARTTLS."; @@ -280,13 +280,13 @@ description = "GPG key to use."; }; - signByDefault = lib.mkOption { + sign-by-default = lib.mkOption { type = lib.types.bool; default = false; description = "Sign messages by default."; }; - encryptByDefault = lib.mkOption { + encrypt-by-default = lib.mkOption { type = lib.types.bool; default = false; description = "Encrypt messages by default."; @@ -306,7 +306,7 @@ description = "Command that generates a signature."; }; - showSignature = lib.mkOption { + show-signature = lib.mkOption { type = lib.types.nullOr ( lib.types.enum [ "append" diff --git a/modules/communication/senpai/assertions.nix b/modules/communication/senpai/assertions.nix index ed2cce8..8e74367 100644 --- a/modules/communication/senpai/assertions.nix +++ b/modules/communication/senpai/assertions.nix @@ -13,8 +13,9 @@ } { assertion = - config.communication.senpai.identity.passwordGopassSecret == null || config.security.gopass.enable; - message = "communication.senpai.identity.passwordGopassSecret requires security.gopass.enable."; + config.communication.senpai.identity.password-gopass-secret == null + || config.security.gopass.enable; + message = "communication.senpai.identity.password-gopass-secret requires security.gopass.enable."; } ]; } diff --git a/modules/communication/senpai/default.nix b/modules/communication/senpai/default.nix index 56bb7ab..49f82d9 100644 --- a/modules/communication/senpai/default.nix +++ b/modules/communication/senpai/default.nix @@ -5,6 +5,9 @@ pkgs, ... }: +let + cfg = config.communication.senpai; +in { imports = [ ./assertions.nix ]; @@ -17,48 +20,60 @@ description = "The senpai package to use."; }; - server = { - address = lib.mkOption { - type = lib.types.str; - description = "IRC server address (host[:port]). Supports irc://, ircs://, irc+insecure:// URLs."; + server = lib.mkOption { + type = lib.types.submodule { + options = { + address = lib.mkOption { + type = lib.types.str; + description = "IRC server address (host[:port]). Supports irc://, ircs://, irc+insecure:// URLs."; + }; + }; }; + default = { }; + description = "IRC server configuration."; }; - identity = { - nickname = lib.mkOption { - type = lib.types.str; - description = "Your IRC nickname (no spaces or colons)."; - }; + identity = lib.mkOption { + type = lib.types.submodule { + options = { + nickname = lib.mkOption { + type = lib.types.str; + description = "Your IRC nickname (no spaces or colons)."; + }; - passwordGopassSecret = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "Gopass secret path for SASL password (e.g. irc/user@server). Constructs password-cmd automatically."; + password-gopass-secret = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Gopass secret path for SASL password (e.g. irc/user@server). Constructs password-cmd automatically."; + }; + }; }; + default = { }; + description = "Identity configuration."; }; }; config = lib.mkMerge [ - (lib.mkIf config.communication.senpai.enable { + (lib.mkIf cfg.enable { programs.senpai = { enable = true; - package = config.communication.senpai.package; + package = cfg.package; config = { - address = config.communication.senpai.server.address; - nickname = config.communication.senpai.identity.nickname; - password-cmd = lib.mkIf (config.communication.senpai.identity.passwordGopassSecret != null) [ + address = cfg.server.address; + nickname = cfg.identity.nickname; + password-cmd = lib.mkIf (cfg.identity.password-gopass-secret != null) [ (lib.getExe config.security.gopass.package) "show" "-o" - config.communication.senpai.identity.passwordGopassSecret + cfg.identity.password-gopass-secret ]; }; }; }) - (lib.mkIf (config.communication.senpai.enable && config.terminal.kitty.enable) { + (lib.mkIf (cfg.enable && config.terminal.kitty.enable) { xdg.desktopEntries."senpai" = { name = "Senpai"; - exec = "${lib.getExe config.terminal.kitty.package} --class senpai -e ${lib.getExe config.communication.senpai.package}"; + exec = "${lib.getExe config.terminal.kitty.package} --class senpai -e ${lib.getExe cfg.package}"; icon = "senpai"; categories = [ "Network" diff --git a/modules/desktop/eww/default.nix b/modules/desktop/eww/default.nix index be6236f..a0727cd 100644 --- a/modules/desktop/eww/default.nix +++ b/modules/desktop/eww/default.nix @@ -6,6 +6,7 @@ ... }: let + cfg = config.desktop.eww; base16Colors = import ../../colors/base16 { inherit config lib pkgs; }; in { @@ -46,10 +47,10 @@ in [ config.fonts.normal (toString config.fonts.size) - (toString config.fonts.iconSize) - (toString config.fonts.labelSize) - (toString config.fonts.smallSize) - (toString config.fonts.idxSize) + (toString config.fonts.icon-size) + (toString config.fonts.label-size) + (toString config.fonts.small-size) + (toString config.fonts.idx-size) ] (builtins.readFile ./eww.scss); in @@ -67,9 +68,9 @@ in Service = { Type = "oneshot"; RemainAfterExit = true; - ExecStart = "${lib.getExe config.desktop.eww.package} open bar"; - ExecReload = "${lib.getExe config.desktop.eww.package} reload && ${lib.getExe config.desktop.eww.package} open bar"; - ExecStop = "${lib.getExe config.desktop.eww.package} kill"; + ExecStart = "${lib.getExe cfg.package} open bar"; + ExecReload = "${lib.getExe cfg.package} reload && ${lib.getExe cfg.package} open bar"; + ExecStop = "${lib.getExe cfg.package} kill"; Restart = "on-failure"; }; Install.WantedBy = [ "graphical-session.target" ]; diff --git a/modules/desktop/rofi/default.nix b/modules/desktop/rofi/default.nix index a15ce0a..ed1cf05 100644 --- a/modules/desktop/rofi/default.nix +++ b/modules/desktop/rofi/default.nix @@ -6,6 +6,7 @@ ... }: let + cfg = config.desktop.rofi; base16Colors = import ../../colors/base16 { inherit config lib pkgs; }; in { @@ -31,7 +32,7 @@ in ] [ ''"${config.fonts.normal} Bold ${toString config.fonts.size}"'' - ''"${config.fonts.normal} Bold ${toString config.fonts.idxSize}"'' + ''"${config.fonts.normal} Bold ${toString config.fonts.idx-size}"'' ] (builtins.readFile ./theme.rasi); in diff --git a/modules/desktop/xdg/default.nix b/modules/desktop/xdg/default.nix index 7f46d37..72b0290 100644 --- a/modules/desktop/xdg/default.nix +++ b/modules/desktop/xdg/default.nix @@ -6,10 +6,11 @@ ... }: let + cfg = config.desktop; base16Colors = import ../../colors/base16 { inherit config lib pkgs; }; in { - config = lib.mkIf config.desktop.enable { + config = lib.mkIf cfg.enable { dconf.enable = true; xdg.portal = { @@ -37,7 +38,7 @@ in enable = true; font = { name = config.fonts.normal; - size = config.fonts.uiSize; + size = config.fonts.ui-size; }; theme = { name = "Adwaita-dark"; diff --git a/modules/development/git/assertions.nix b/modules/development/git/assertions.nix index c66714a..2baeced 100644 --- a/modules/development/git/assertions.nix +++ b/modules/development/git/assertions.nix @@ -3,24 +3,24 @@ { assertions = [ { - assertion = !config.development.git.signing.signByDefault || config.development.git.enable; + assertion = !config.development.git.signing.sign-by-default || config.development.git.enable; message = '' - development.git.signing.signByDefault is enabled but development.git.enable is not. + development.git.signing.sign-by-default is enabled but development.git.enable is not. Enable development.git before enabling commit signing. ''; } { assertion = - !config.development.git.signing.signByDefault || config.development.git.signing.key != null; + !config.development.git.signing.sign-by-default || config.development.git.signing.key != null; message = '' - development.git.signing.signByDefault is enabled but development.git.signing.key is not set. + development.git.signing.sign-by-default is enabled but development.git.signing.key is not set. Set a GPG key ID before enabling commit signing by default. ''; } { - assertion = !config.development.git.signing.signByDefault || config.security.gpg.enable; + assertion = !config.development.git.signing.sign-by-default || config.security.gpg.enable; message = '' - development.git.signing.signByDefault is enabled but security.gpg.enable is not. + development.git.signing.sign-by-default is enabled but security.gpg.enable is not. Commit signing requires the managed GPG configuration. Please enable security.gpg. ''; } diff --git a/modules/development/git/default.nix b/modules/development/git/default.nix index 15dcc80..593c8a3 100644 --- a/modules/development/git/default.nix +++ b/modules/development/git/default.nix @@ -2,8 +2,12 @@ { config, lib, + pkgs, ... }: +let + cfg = config.development.git; +in { imports = [ ./assertions.nix @@ -30,29 +34,35 @@ description = "Git email."; }; - signing = { - key = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "GPG key ID used for signing commits."; - }; + signing = lib.mkOption { + type = lib.types.submodule { + options = { + key = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "GPG key ID used for signing commits."; + }; - signByDefault = lib.mkEnableOption "Sign commits by default."; + sign-by-default = lib.mkEnableOption "Sign commits by default."; + }; + }; + default = { }; + description = "Git commit signing configuration."; }; }; - config = lib.mkIf config.development.git.enable { + config = lib.mkIf cfg.enable { programs.git = { enable = true; signing = { - key = config.development.git.signing.key; - signByDefault = config.development.git.signing.signByDefault; + key = cfg.signing.key; + sign-by-default = cfg.signing.sign-by-default; }; settings = lib.mkMerge [ { user = { - name = config.development.git.username; - email = config.development.git.email; + name = cfg.username; + email = cfg.email; }; core = { askPass = ""; diff --git a/modules/fonts/default.nix b/modules/fonts/default.nix index 2df7b88..b7d78df 100644 --- a/modules/fonts/default.nix +++ b/modules/fonts/default.nix @@ -1,7 +1,7 @@ # Font configuration { - lib, config, + lib, pkgs, ... }: @@ -30,31 +30,31 @@ default = 18; }; - uiSize = lib.mkOption { + ui-size = lib.mkOption { type = lib.types.int; description = "Default desktop UI (GTK) font size."; default = 11; }; - iconSize = lib.mkOption { + icon-size = lib.mkOption { type = lib.types.int; description = "Font size for icons (base size + 6)."; default = 24; }; - labelSize = lib.mkOption { + label-size = lib.mkOption { type = lib.types.int; description = "Font size for labels (base size - 2)."; default = 16; }; - smallSize = lib.mkOption { + small-size = lib.mkOption { type = lib.types.int; description = "Font size for small text (base size - 6)."; default = 12; }; - idxSize = lib.mkOption { + idx-size = lib.mkOption { type = lib.types.int; description = "Font size for index numbers (base size - 4)."; default = 14; diff --git a/modules/office/calcurse/default.nix b/modules/office/calcurse/default.nix index 6e3e855..7c1df5e 100644 --- a/modules/office/calcurse/default.nix +++ b/modules/office/calcurse/default.nix @@ -6,6 +6,8 @@ ... }: let + cfg = config.office.calcurse; + calcurseSync = pkgs.writeShellScriptBin "calcurse-sync" (builtins.readFile ./calcurse-sync.sh); calcurse = pkgs.symlinkJoin { @@ -16,13 +18,13 @@ let pkgs.libnotify ] ++ lib.optionals config.development.nixvim.enable [ config.development.nixvim.package ] - ++ lib.optionals config.office.calcurse.sync.enable [ calcurseSync ]; + ++ lib.optionals cfg.sync.enable [ calcurseSync ]; nativeBuildInputs = [ pkgs.makeWrapper ]; postBuild = '' ${lib.optionalString config.development.nixvim.enable '' wrapProgram $out/bin/calcurse --set PAGER "nvim" ''} - ${lib.optionalString config.office.calcurse.sync.enable '' + ${lib.optionalString cfg.sync.enable '' wrapProgram $out/bin/calcurse-sync \ --prefix PATH : ${ lib.makeBinPath [ @@ -31,8 +33,8 @@ let pkgs.gnused ] } \ - ${lib.optionalString (config.office.calcurse.sync.remote != null) '' - --set CALCURSE_SYNC_REMOTE ${lib.escapeShellArg config.office.calcurse.sync.remote} + ${lib.optionalString (cfg.sync.remote != null) '' + --set CALCURSE_SYNC_REMOTE ${lib.escapeShellArg cfg.sync.remote} ''} ''} ''; @@ -52,35 +54,47 @@ in default = calcurse; description = "The calcurse package to use."; }; - sync = { - enable = lib.mkEnableOption "Enables git-backed syncing of the calcurse data directory (builds calcurse-sync, installs the sync hooks, and runs an initial 'calcurse-sync init' on activation)."; - remote = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "Git remote URL for the calcurse data directory. Use an https:// URL if 'credential' is configured. When set, calcurse-sync uses it automatically on first init instead of prompting."; - }; - credential = { - username = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "Username for HTTPS git authentication against the calcurse remote."; - }; - passwordGopassPath = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "gopass entry path holding the password or token used for HTTPS git authentication against the calcurse remote. E.g. 'git/calcurse-sync'."; + sync = lib.mkOption { + type = lib.types.submodule { + options = { + enable = lib.mkEnableOption "Enables git-backed syncing of the calcurse data directory (builds calcurse-sync, installs the sync hooks, and runs an initial 'calcurse-sync init' on activation)."; + remote = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Git remote URL for the calcurse data directory. Use an https:// URL if 'credential' is configured. When set, calcurse-sync uses it automatically on first init instead of prompting."; + }; + credential = lib.mkOption { + type = lib.types.submodule { + options = { + username = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Username for HTTPS git authentication against the calcurse remote."; + }; + password-gopass-secret = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "gopass entry path holding the password or token used for HTTPS git authentication against the calcurse remote. E.g. 'git/calcurse-sync'."; + }; + }; + }; + default = { }; + description = "Credentials for HTTPS git authentication."; + }; }; }; + default = { }; + description = "Git-backed syncing configuration."; }; }; config = lib.mkMerge [ - (lib.mkIf config.office.calcurse.enable { + (lib.mkIf cfg.enable { home.file.".local/share/icons/hicolor/scalable/apps/calcurse.svg" = { source = ../../../assets/icons/apps/calcurse.svg; }; - home.packages = [ config.office.calcurse.package ]; + home.packages = [ cfg.package ]; xdg.configFile."calcurse/conf" = { text = builtins.replaceStrings [ "@@CALCURSE_ICON@@" ] [ "${../../../assets/icons/apps/calcurse.svg}" ] @@ -92,10 +106,10 @@ in force = true; }; }) - (lib.mkIf (config.office.calcurse.enable && config.terminal.kitty.enable) { + (lib.mkIf (cfg.enable && config.terminal.kitty.enable) { xdg.desktopEntries."calcurse" = { name = "calcurse"; - exec = "${lib.getExe config.terminal.kitty.package} --class calcurse -e ${lib.getExe config.office.calcurse.package}"; + exec = "${lib.getExe config.terminal.kitty.package} --class calcurse -e ${lib.getExe cfg.package}"; icon = "calcurse"; categories = [ "Office" @@ -106,7 +120,7 @@ in type = "Application"; }; }) - (lib.mkIf config.office.calcurse.sync.enable { + (lib.mkIf cfg.sync.enable { xdg.configFile."calcurse/hooks/pre-load" = { source = ./hooks/pre-load; executable = true; @@ -129,15 +143,15 @@ in commit.gpgSign = false; tag.gpgSign = false; } - // lib.optionalAttrs (config.office.calcurse.sync.credential.passwordGopassPath != null) { - credential.helper = "!f() { echo username=${lib.escapeShellArg config.office.calcurse.sync.credential.username}; echo password=\"$(${lib.getExe config.security.gopass.package} show -o ${lib.escapeShellArg config.office.calcurse.sync.credential.passwordGopassPath})\"; }; f"; + // lib.optionalAttrs (cfg.sync.credential.password-gopass-secret != null) { + credential.helper = "!f() { echo username=${lib.escapeShellArg cfg.sync.credential.username}; echo password=\"$(${lib.getExe config.security.gopass.package} show -o ${lib.escapeShellArg cfg.sync.credential.password-gopass-secret})\"; }; f"; }; } ]; - home.activation.calcurseSyncInit = lib.hm.dag.entryAfter [ "writeBoundary" ] '' - run ${config.office.calcurse.package}/bin/calcurse-sync init || true - ''; + home.activation.calcurseSyncInit = lib.hm.dag.entryAfter [ "writeBoundary" ] ( + pkgs.writeText "calcurse-sync-init.sh" ("run " + cfg.package + "/bin/calcurse-sync init || true") + ); }) ]; } diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index 616baeb..17624ef 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -5,6 +5,9 @@ pkgs, ... }: +let + cfg = config.security.gopass; +in { imports = [ ./assertions.nix ]; @@ -16,33 +19,51 @@ default = config.programs.password-store.package; description = "The gopass package to use."; }; - sync = { - enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory."; - remote = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured."; - }; - credential = { - username = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "Username for HTTPS git authentication against the gopass remote."; - }; - passwordGopassPath = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "gopass entry path holding the password or token used."; + sync = lib.mkOption { + type = lib.types.submodule { + options = { + enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory."; + remote = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured."; + }; + credential = lib.mkOption { + type = lib.types.submodule { + options = { + username = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Username for HTTPS git authentication against the gopass remote."; + }; + password-gopass-secret = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "gopass entry path holding the password or token used."; + }; + }; + }; + default = { }; + description = "Credentials for HTTPS git authentication."; + }; }; }; + default = { }; + description = "Git-backed syncing configuration."; }; - creation-templates = { - enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands."; + creation-templates = lib.mkOption { + type = lib.types.submodule { + options = { + enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands."; + }; + }; + default = { }; + description = "Creation templates configuration."; }; }; config = lib.mkMerge [ - (lib.mkIf config.security.gopass.enable { + (lib.mkIf cfg.enable { programs.password-store = { enable = true; package = pkgs.gopass.override { passAlias = true; }; @@ -68,15 +89,9 @@ gpgSign = false; }; } - // - lib.optionalAttrs - ( - config.security.gopass.sync.enable - && config.security.gopass.sync.credential.passwordGopassPath != null - ) - { - credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f"; - }; + // lib.optionalAttrs (cfg.sync.enable && cfg.sync.credential.password-gopass-secret != null) { + credential.helper = "!f() { echo username=${lib.escapeShellArg cfg.sync.credential.username}; echo password=\"$(${cfg.package}/bin/gopass show -o ${lib.escapeShellArg cfg.sync.credential.password-gopass-secret})\"; }; f"; + }; } ]; @@ -88,20 +103,18 @@ source = ../../../assets/icons/apps/gopass.svg; }; - home.activation.copyCreationTemplatesForGopass = - lib.mkIf config.security.gopass.creation-templates.enable - ( - lib.hm.dag.entryAfter [ "writeBoundary" ] '' - $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" - $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create - $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" - '' - ); + home.activation.copyCreationTemplatesForGopass = lib.mkIf cfg.creation-templates.enable ( + lib.hm.dag.entryAfter [ "writeBoundary" ] '' + $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" + $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create + $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" + '' + ); }) - (lib.mkIf (config.security.gopass.enable && config.terminal.kitty.enable) { + (lib.mkIf (cfg.enable && config.terminal.kitty.enable) { xdg.desktopEntries."gopass" = { name = "gopass"; - exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe config.security.gopass.package}"; + exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe cfg.package}"; icon = "gopass"; comment = "Standard Unix password manager (Go implementation)"; categories = [ "Utility" ]; @@ -109,7 +122,7 @@ type = "Application"; }; }) - (lib.mkIf config.security.gopass.sync.enable { + (lib.mkIf cfg.sync.enable { home.activation.gopassSyncInit = let gopassSyncInit = pkgs.writeShellApplication { @@ -121,7 +134,7 @@ text = builtins.replaceStrings [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ] - [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ] + [ config.programs.password-store.settings.PASSWORD_STORE_DIR cfg.sync.remote ] (builtins.readFile ./gopass-sync-init.sh); }; in diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix index e18b933..ed93e27 100644 --- a/modules/security/ssh/default.nix +++ b/modules/security/ssh/default.nix @@ -6,13 +6,15 @@ ... }: let + cfg = config.security.ssh; + gpgSshKeyLoad = pkgs.writeShellApplication { name = "gpg-ssh-key-load"; runtimeInputs = [ config.terminal.bash.package config.security.gopass.package config.security.gpg.package - config.security.ssh.package + cfg.package pkgs.coreutils ]; text = @@ -22,7 +24,7 @@ let "@@GNUPGHOME@@" ] [ - config.security.ssh.sshKeyGopassPath + cfg.ssh-key-gopass-secret config.home.sessionVariables.GNUPGHOME ] (builtins.readFile ./gpg-ssh-key-load.sh); @@ -38,7 +40,7 @@ in description = "The ssh package to use."; }; - sshKeyGopassPath = lib.mkOption { + ssh-key-gopass-secret = lib.mkOption { type = lib.types.nullOr lib.types.str; default = null; description = '' @@ -50,8 +52,8 @@ in }; config = lib.mkMerge [ - (lib.mkIf config.security.ssh.enable { - home.packages = [ config.security.ssh.package ]; + (lib.mkIf cfg.enable { + home.packages = [ cfg.package ]; assertions = [ { @@ -64,7 +66,7 @@ in ]; }) - (lib.mkIf (config.security.ssh.enable && config.security.ssh.sshKeyGopassPath != null) { + (lib.mkIf (cfg.enable && cfg.ssh-key-gopass-secret != null) { home.activation.gpgSshKeyLoad = lib.hm.dag.entryAfter [ "writeBoundary" ] '' run ${lib.getExe gpgSshKeyLoad} || true ''; diff --git a/modules/web/chawan/default.nix b/modules/web/chawan/default.nix index f3f0a30..0f1256d 100644 --- a/modules/web/chawan/default.nix +++ b/modules/web/chawan/default.nix @@ -2,8 +2,12 @@ { config, lib, + pkgs, ... }: +let + cfg = config.web.chawan; +in { imports = [ ./assertions.nix @@ -17,7 +21,7 @@ default = config.programs.chawan.package; description = "Package to use for chawan."; }; - homeUrl = lib.mkOption { + home-url = lib.mkOption { type = lib.types.str; default = "https://searx.space"; description = "The first page to open when chawan is launched."; @@ -25,7 +29,7 @@ }; config = lib.mkMerge [ - (lib.mkIf config.web.chawan.enable { + (lib.mkIf cfg.enable { home.file.".local/share/icons/hicolor/scalable/apps/internet-web-browser.svg" = { source = ../../../assets/icons/apps/internet-web-browser.svg; }; @@ -50,13 +54,13 @@ }; }; home.packages = [ - config.web.chawan.package + cfg.package ]; }) - (lib.mkIf (config.web.chawan.enable && config.terminal.kitty.enable) { + (lib.mkIf (cfg.enable && config.terminal.kitty.enable) { xdg.desktopEntries."chawan" = { name = "Chawan"; - exec = "${lib.getExe config.terminal.kitty.package} --class chawan -e ${lib.getExe config.web.chawan.package} ${config.web.chawan.homeUrl}"; + exec = "${lib.getExe config.terminal.kitty.package} --class chawan -e ${lib.getExe cfg.package} ${cfg.home-url}"; icon = "internet-web-browser"; categories = [ "Network" ]; comment = "Text-based web browser"; diff --git a/modules/web/chromium/assertions.nix b/modules/web/chromium/assertions.nix index 465ebbd..79a9ba1 100644 --- a/modules/web/chromium/assertions.nix +++ b/modules/web/chromium/assertions.nix @@ -3,8 +3,8 @@ { assertions = [ { - assertion = !config.web.chromium.useOpenGL || config.web.chromium.enable; - message = "web.chromium.useOpenGL requires web.chromium.enable."; + assertion = !config.web.chromium.use-opengl || config.web.chromium.enable; + message = "web.chromium.use-opengl requires web.chromium.enable."; } ]; } diff --git a/modules/web/chromium/default.nix b/modules/web/chromium/default.nix index 1e3608c..ae9e97e 100644 --- a/modules/web/chromium/default.nix +++ b/modules/web/chromium/default.nix @@ -4,6 +4,10 @@ pkgs, ... }: +let + cfg = config.web.chromium; + extensionDirs = lib.concatStringsSep "," (lib.mapAttrsToList (_: ext: ext.drv) cfg.extensions); +in { imports = [ ./assertions.nix @@ -20,32 +24,26 @@ defaultText = lib.literalExpression "config.programs.chromium.finalPackage"; description = "Package to use for chromium. Defaults to the wrapped finalPackage from programs.chromium."; }; - useOpenGL = lib.mkEnableOption '' + use-opengl = lib.mkEnableOption '' Use OpenGL APIs for graphics acceleration ''; }; - config = lib.mkIf config.web.chromium.enable { + config = lib.mkIf cfg.enable { programs.chromium = { enable = true; package = pkgs.ungoogled-chromium; - commandLineArgs = - let - extensionDirs = lib.concatStringsSep "," ( - lib.mapAttrsToList (_: ext: ext.drv) config.web.chromium.extensions - ); - in - [ - "--force-dark-mode" - "--force-device-scale-factor=1.15" - # Don't use the gnome password store - "--password-store=basic" - "--load-extension=${extensionDirs}" - ] - ++ lib.optionals config.web.chromium.useOpenGL [ - "--use-angle=opengl" - "--use-cmd-decoder=passthrough" - ]; + commandLineArgs = [ + "--force-dark-mode" + "--force-device-scale-factor=1.15" + # Don't use the gnome password store + "--password-store=basic" + "--load-extension=${extensionDirs}" + ] + ++ lib.optionals cfg.use-opengl [ + "--use-angle=opengl" + "--use-cmd-decoder=passthrough" + ]; }; xdg.mimeApps.defaultApplications = { @@ -94,10 +92,10 @@ credentials_enable_autosignin = false; extensions = { pinned_extensions = [ - config.web.chromium.extensions.browserpass.id - config.web.chromium.extensions.darkreader.id - config.web.chromium.extensions.ublockOrigin.id - config.web.chromium.extensions.vimium.id + cfg.extensions.browserpass.id + cfg.extensions.darkreader.id + cfg.extensions.ublockOrigin.id + cfg.extensions.vimium.id ]; theme = { id = ""; diff --git a/users/arpit/default.nix b/users/arpit/default.nix index c2dec0e..7b02d30 100644 --- a/users/arpit/default.nix +++ b/users/arpit/default.nix @@ -36,7 +36,7 @@ development.delta.enable = true; development.direnv.enable = true; development.git.enable = true; - development.git.signing.signByDefault = true; + development.git.signing.sign-by-default = true; development.lazygit.enable = true; development.nixvim.enable = true; development.opencode.enable = true; @@ -101,7 +101,7 @@ web.aria2.enable = true; web.chawan.enable = true; web.chromium.enable = true; - web.chromium.useOpenGL = false; + web.chromium.use-opengl = false; programs.home-manager.enable = true; } diff --git a/users/arpit/private.example.nix b/users/arpit/private.example.nix index 3752f68..54fd972 100644 --- a/users/arpit/private.example.nix +++ b/users/arpit/private.example.nix @@ -5,16 +5,16 @@ remote = "YOUR_REPOSITORY_URL"; credential = { username = "example"; - passwordGopassPath = "websites/github.com/example/tokens/calendar"; + password-gopass-secret = "websites/github.com/example/tokens/calendar"; }; }; # Email - Template for configuring neomutt email accounts config.communication.neomutt.accounts = { "example@gmail.com" = { - realName = "Example User"; + real-name = "Example User"; address = "user@gmail.com"; - passwordGopassSecret = "mail/user@gmail.com"; + password-gopass-secret = "mail/user@gmail.com"; flavor = "gmail.com"; primary = true; neomutt.extraConfig = '' @@ -22,8 +22,8 @@ ''; gpg = { key = "YOUR_GPG_KEY_ID"; - signByDefault = true; - encryptByDefault = false; # set true only if you also want auto-encrypt + sign-by-default = true; + encrypt-by-default = false; # set true only if you also want auto-encrypt }; }; }; @@ -35,7 +35,7 @@ }; identity = { nickname = "example"; - passwordGopassSecret = "irc/user@irc.example.com"; + password-gopass-secret = "irc/user@irc.example.com"; }; }; @@ -45,19 +45,19 @@ email = "you@example.com"; signing = { key = "EXAMPLE_GPG_KEY_ID"; - signByDefault = true; + sign-by-default = true; }; }; # SSH key to load into the gpg-agent from gopass (entry in the gopass store) - config.security.ssh.sshKeyGopassPath = "ssh/hostname/username"; + config.security.ssh.ssh-key-gopass-secret = "ssh/hostname/username"; # Gopass - Template for configuring gopass, specially syncing config.security.gopass.sync = { remote = "YOUR_REPOSITORY_URL"; credential = { username = "example"; - passwordGopassPath = "websites/github.com/example/tokens/calendar"; + password-gopass-secret = "websites/github.com/example/tokens/calendar"; }; }; } |
