diff options
| author | Arpit Chakladar <arpitchakladar@gmail.com> | 2026-09-10 04:32:33 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar@gmail.com> | 2026-09-10 04:32:38 +0530 |
| commit | 96ec0f89101ea414e764565e022b9bc83a96071c (patch) | |
| tree | 008b0d9dd79cc19afa65df40c79563dc67cf897b /modules/security/ssh/default.nix | |
| parent | f1787032594f7ca1a6521f5665a48bb70605d222 (diff) | |
| download | home-manager-config-96ec0f89101ea414e764565e022b9bc83a96071c.tar.gz home-manager-config-96ec0f89101ea414e764565e022b9bc83a96071c.zip | |
fix(security/ssh): fixed the loading ssh key from gopass
Now on every home-manager switch we run a script that loads the key form
gopass to gpg-agent, then the gpg-agent is responsible for storing it.
Anytime gopass changes the ssh key we must run home-manager switch to
load the ssh key into gpg agent.
Diffstat (limited to 'modules/security/ssh/default.nix')
| -rw-r--r-- | modules/security/ssh/default.nix | 75 |
1 files changed, 52 insertions, 23 deletions
diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix index 8d1f881..e18b933 100644 --- a/modules/security/ssh/default.nix +++ b/modules/security/ssh/default.nix @@ -5,40 +5,69 @@ pkgs, ... }: +let + gpgSshKeyLoad = pkgs.writeShellApplication { + name = "gpg-ssh-key-load"; + runtimeInputs = [ + config.terminal.bash.package + config.security.gopass.package + config.security.gpg.package + config.security.ssh.package + pkgs.coreutils + ]; + text = + builtins.replaceStrings + [ + "@@GOPASS_SSH_KEY@@" + "@@GNUPGHOME@@" + ] + [ + config.security.ssh.sshKeyGopassPath + config.home.sessionVariables.GNUPGHOME + ] + (builtins.readFile ./gpg-ssh-key-load.sh); + }; +in { options.security.ssh = { - enable = lib.mkEnableOption "Enables ssh."; + enable = lib.mkEnableOption "Enables ssh via the gpg-agent."; package = lib.mkOption { type = lib.types.package; readOnly = true; - default = config.programs.ssh.package; + default = pkgs.openssh; description = "The ssh package to use."; }; - gopassKeys = lib.mkOption { - type = lib.types.listOf lib.types.str; - default = [ ]; - description = "SSH keys to load from the gopass store (entries under ssh/)."; + sshKeyGopassPath = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = '' + gopass entry holding the private SSH key. The key is loaded into the + gpg-agent during home-manager switch so ssh works without a ~/.ssh + directory. + ''; }; }; - config = lib.mkIf config.security.ssh.enable { - programs.ssh = { - enable = true; - - package = pkgs.openssh; + config = lib.mkMerge [ + (lib.mkIf config.security.ssh.enable { + home.packages = [ config.security.ssh.package ]; - enableDefaultConfig = false; - extraOptionOverrides = { - AddKeysToAgent = "yes"; - ForwardAgent = "yes"; - ServerAliveInterval = "60"; - ServerAliveCountMax = "3"; - VisualHostKey = "yes"; - HashKnownHosts = "yes"; - }; - }; + assertions = [ + { + assertion = config.security.gpg.enable; + message = '' + Enabling `security.ssh` requires `security.gpg` so that + gpg-agent can be used as the ssh-agent. + ''; + } + ]; + }) - services.ssh-agent.enable = lib.mkIf config.security.gpg.enable false; - }; + (lib.mkIf (config.security.ssh.enable && config.security.ssh.sshKeyGopassPath != null) { + home.activation.gpgSshKeyLoad = lib.hm.dag.entryAfter [ "writeBoundary" ] '' + run ${lib.getExe gpgSshKeyLoad} || true + ''; + }) + ]; } |
