aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/ssh
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-08-17 15:25:55 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-08-29 03:50:27 +0530
commit2ac22a72455341a3efced289782fe5daf5d788ee (patch)
treedad5f0cb7ea6c2dce9426462e35cc518d73ad91f /modules/security/ssh
parentf001094478a394b70f32425c7fcc0d715950b851 (diff)
downloadhome-manager-config-2ac22a72455341a3efced289782fe5daf5d788ee.tar.gz
home-manager-config-2ac22a72455341a3efced289782fe5daf5d788ee.zip
refactor: rewrote how ssh keys are handled in gopass-ssh-load
- all ssh keys that are used under ssh/ have to be explicitely added via security.ssh.gopassKeys = [ ... ]
Diffstat (limited to 'modules/security/ssh')
-rw-r--r--modules/security/ssh/default.nix20
-rw-r--r--modules/security/ssh/git.nix23
2 files changed, 3 insertions, 40 deletions
diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix
index 97b5808..8d1f881 100644
--- a/modules/security/ssh/default.nix
+++ b/modules/security/ssh/default.nix
@@ -6,8 +6,6 @@
...
}:
{
- imports = [ ./git.nix ];
-
options.security.ssh = {
enable = lib.mkEnableOption "Enables ssh.";
package = lib.mkOption {
@@ -17,10 +15,10 @@
description = "The ssh package to use.";
};
- extraGopassKeys = lib.mkOption {
+ gopassKeys = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [ ];
- description = "Additional SSH keys to load from the gopass store (entries under ssh/), in addition to the git platform keys.";
+ description = "SSH keys to load from the gopass store (entries under ssh/).";
};
};
@@ -28,19 +26,7 @@
programs.ssh = {
enable = true;
- package =
- if (config.security.gopass.enable or false && config.security.gopass.ssh-agent.enable or false) then
- pkgs.symlinkJoin {
- name = "openssh-gopass-wrapper";
- paths = [ pkgs.openssh ];
- buildInputs = [ pkgs.makeWrapper ];
- postBuild = ''
- wrapProgram $out/bin/ssh \
- --run "${lib.getExe config.scripts.gopass-ssh-load.package}"
- '';
- }
- else
- pkgs.openssh;
+ package = pkgs.openssh;
enableDefaultConfig = false;
extraOptionOverrides = {
diff --git a/modules/security/ssh/git.nix b/modules/security/ssh/git.nix
deleted file mode 100644
index 146bfb9..0000000
--- a/modules/security/ssh/git.nix
+++ /dev/null
@@ -1,23 +0,0 @@
-# SSH host configurations for git platforms
-{ config, lib, ... }:
-let
- hosts = [
- "github.com"
- "gitlab.com"
- "bitbucket.org"
- "codeberg.org"
- "git.sr.ht"
- ];
-
- mkGitHost =
- domain:
- lib.nameValuePair domain {
- hostname = domain;
- user = "git";
- };
-in
-{
- config = lib.mkIf (config.security.ssh.enable && config.development.git.useSSH) {
- programs.ssh.settings = builtins.listToAttrs (map mkGitHost hosts);
- };
-}