diff options
| author | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-08-17 15:25:55 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-08-29 03:50:27 +0530 |
| commit | 2ac22a72455341a3efced289782fe5daf5d788ee (patch) | |
| tree | dad5f0cb7ea6c2dce9426462e35cc518d73ad91f /modules/security/ssh | |
| parent | f001094478a394b70f32425c7fcc0d715950b851 (diff) | |
| download | home-manager-config-2ac22a72455341a3efced289782fe5daf5d788ee.tar.gz home-manager-config-2ac22a72455341a3efced289782fe5daf5d788ee.zip | |
refactor: rewrote how ssh keys are handled in gopass-ssh-load
- all ssh keys that are used under ssh/ have to be explicitely added via
security.ssh.gopassKeys = [ ... ]
Diffstat (limited to 'modules/security/ssh')
| -rw-r--r-- | modules/security/ssh/default.nix | 20 | ||||
| -rw-r--r-- | modules/security/ssh/git.nix | 23 |
2 files changed, 3 insertions, 40 deletions
diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix index 97b5808..8d1f881 100644 --- a/modules/security/ssh/default.nix +++ b/modules/security/ssh/default.nix @@ -6,8 +6,6 @@ ... }: { - imports = [ ./git.nix ]; - options.security.ssh = { enable = lib.mkEnableOption "Enables ssh."; package = lib.mkOption { @@ -17,10 +15,10 @@ description = "The ssh package to use."; }; - extraGopassKeys = lib.mkOption { + gopassKeys = lib.mkOption { type = lib.types.listOf lib.types.str; default = [ ]; - description = "Additional SSH keys to load from the gopass store (entries under ssh/), in addition to the git platform keys."; + description = "SSH keys to load from the gopass store (entries under ssh/)."; }; }; @@ -28,19 +26,7 @@ programs.ssh = { enable = true; - package = - if (config.security.gopass.enable or false && config.security.gopass.ssh-agent.enable or false) then - pkgs.symlinkJoin { - name = "openssh-gopass-wrapper"; - paths = [ pkgs.openssh ]; - buildInputs = [ pkgs.makeWrapper ]; - postBuild = '' - wrapProgram $out/bin/ssh \ - --run "${lib.getExe config.scripts.gopass-ssh-load.package}" - ''; - } - else - pkgs.openssh; + package = pkgs.openssh; enableDefaultConfig = false; extraOptionOverrides = { diff --git a/modules/security/ssh/git.nix b/modules/security/ssh/git.nix deleted file mode 100644 index 146bfb9..0000000 --- a/modules/security/ssh/git.nix +++ /dev/null @@ -1,23 +0,0 @@ -# SSH host configurations for git platforms -{ config, lib, ... }: -let - hosts = [ - "github.com" - "gitlab.com" - "bitbucket.org" - "codeberg.org" - "git.sr.ht" - ]; - - mkGitHost = - domain: - lib.nameValuePair domain { - hostname = domain; - user = "git"; - }; -in -{ - config = lib.mkIf (config.security.ssh.enable && config.development.git.useSSH) { - programs.ssh.settings = builtins.listToAttrs (map mkGitHost hosts); - }; -} |
