aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/ssh/default.nix
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar@gmail.com>2026-09-10 04:32:33 +0530
committerArpit Chakladar <arpitchakladar@gmail.com>2026-09-10 04:32:38 +0530
commit96ec0f89101ea414e764565e022b9bc83a96071c (patch)
tree008b0d9dd79cc19afa65df40c79563dc67cf897b /modules/security/ssh/default.nix
parentf1787032594f7ca1a6521f5665a48bb70605d222 (diff)
downloadhome-manager-config-96ec0f89101ea414e764565e022b9bc83a96071c.tar.gz
home-manager-config-96ec0f89101ea414e764565e022b9bc83a96071c.zip
fix(security/ssh): fixed the loading ssh key from gopass
Now on every home-manager switch we run a script that loads the key form gopass to gpg-agent, then the gpg-agent is responsible for storing it. Anytime gopass changes the ssh key we must run home-manager switch to load the ssh key into gpg agent.
Diffstat (limited to 'modules/security/ssh/default.nix')
-rw-r--r--modules/security/ssh/default.nix75
1 files changed, 52 insertions, 23 deletions
diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix
index 8d1f881..e18b933 100644
--- a/modules/security/ssh/default.nix
+++ b/modules/security/ssh/default.nix
@@ -5,40 +5,69 @@
pkgs,
...
}:
+let
+ gpgSshKeyLoad = pkgs.writeShellApplication {
+ name = "gpg-ssh-key-load";
+ runtimeInputs = [
+ config.terminal.bash.package
+ config.security.gopass.package
+ config.security.gpg.package
+ config.security.ssh.package
+ pkgs.coreutils
+ ];
+ text =
+ builtins.replaceStrings
+ [
+ "@@GOPASS_SSH_KEY@@"
+ "@@GNUPGHOME@@"
+ ]
+ [
+ config.security.ssh.sshKeyGopassPath
+ config.home.sessionVariables.GNUPGHOME
+ ]
+ (builtins.readFile ./gpg-ssh-key-load.sh);
+ };
+in
{
options.security.ssh = {
- enable = lib.mkEnableOption "Enables ssh.";
+ enable = lib.mkEnableOption "Enables ssh via the gpg-agent.";
package = lib.mkOption {
type = lib.types.package;
readOnly = true;
- default = config.programs.ssh.package;
+ default = pkgs.openssh;
description = "The ssh package to use.";
};
- gopassKeys = lib.mkOption {
- type = lib.types.listOf lib.types.str;
- default = [ ];
- description = "SSH keys to load from the gopass store (entries under ssh/).";
+ sshKeyGopassPath = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = ''
+ gopass entry holding the private SSH key. The key is loaded into the
+ gpg-agent during home-manager switch so ssh works without a ~/.ssh
+ directory.
+ '';
};
};
- config = lib.mkIf config.security.ssh.enable {
- programs.ssh = {
- enable = true;
-
- package = pkgs.openssh;
+ config = lib.mkMerge [
+ (lib.mkIf config.security.ssh.enable {
+ home.packages = [ config.security.ssh.package ];
- enableDefaultConfig = false;
- extraOptionOverrides = {
- AddKeysToAgent = "yes";
- ForwardAgent = "yes";
- ServerAliveInterval = "60";
- ServerAliveCountMax = "3";
- VisualHostKey = "yes";
- HashKnownHosts = "yes";
- };
- };
+ assertions = [
+ {
+ assertion = config.security.gpg.enable;
+ message = ''
+ Enabling `security.ssh` requires `security.gpg` so that
+ gpg-agent can be used as the ssh-agent.
+ '';
+ }
+ ];
+ })
- services.ssh-agent.enable = lib.mkIf config.security.gpg.enable false;
- };
+ (lib.mkIf (config.security.ssh.enable && config.security.ssh.sshKeyGopassPath != null) {
+ home.activation.gpgSshKeyLoad = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
+ run ${lib.getExe gpgSshKeyLoad} || true
+ '';
+ })
+ ];
}