aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-07-15 20:02:29 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-07-15 20:03:04 +0530
commit01aaa7ad39c1fe8af6ffbca31abbab27dbfefc95 (patch)
tree88560b79fa71e3b83d9d9aca6d1bb40673a1a170 /modules/security
parent2c573bb0c437b83fe629a9a5b818c976d2dfd796 (diff)
downloadhome-manager-config-01aaa7ad39c1fe8af6ffbca31abbab27dbfefc95.tar.gz
home-manager-config-01aaa7ad39c1fe8af6ffbca31abbab27dbfefc95.zip
refactor: organized the modules into better categories
Instead of lumping everything in modules/programs we are separating them into separate directories in modules/
Diffstat (limited to 'modules/security')
-rw-r--r--modules/security/default.nix11
-rw-r--r--modules/security/enteauth/default.nix61
-rw-r--r--modules/security/gopass/default.nix30
-rw-r--r--modules/security/gpg/default.nix20
-rw-r--r--modules/security/openvpn/default.nix18
-rw-r--r--modules/security/ssh/default.nix26
-rw-r--r--modules/security/ssh/git.nix49
7 files changed, 215 insertions, 0 deletions
diff --git a/modules/security/default.nix b/modules/security/default.nix
new file mode 100644
index 0000000..e9d7208
--- /dev/null
+++ b/modules/security/default.nix
@@ -0,0 +1,11 @@
+{ ... }:
+
+{
+ imports = [
+ ./enteauth
+ ./gopass
+ ./gpg
+ ./openvpn
+ ./ssh
+ ];
+}
diff --git a/modules/security/enteauth/default.nix b/modules/security/enteauth/default.nix
new file mode 100644
index 0000000..a332bf3
--- /dev/null
+++ b/modules/security/enteauth/default.nix
@@ -0,0 +1,61 @@
+{
+ config,
+ lib,
+ pkgs,
+ ...
+}:
+
+# Ente Auth - end-to-end encrypted authentication (2FA)
+let
+ enteAuthWithKeyring = pkgs.symlinkJoin {
+ name = "ente-auth-wrapped";
+ paths = [ pkgs.ente-auth ];
+ buildInputs = [ pkgs.makeWrapper ];
+ postBuild = ''
+ wrapProgram $out/bin/enteauth \
+ --prefix PATH : ${
+ lib.makeBinPath [
+ pkgs.gnome-keyring
+ pkgs.dbus
+ ]
+ } \
+ --run "echo 'password' | ${pkgs.gnome-keyring}/bin/gnome-keyring-daemon --unlock --components=secrets"
+
+ rm -rf $out/share/applications/*
+
+ ln -s ${customDesktopItem}/share/applications/* $out/share/applications/
+ '';
+ };
+
+ customDesktopItem = pkgs.makeDesktopItem {
+ name = "enteauth";
+ exec = "enteauth";
+ icon = "io.ente.auth";
+ comment = "End-to-end encrypted 2FA authenticator";
+ desktopName = "Ente Auth";
+ genericName = "2FA Authenticator";
+ categories = [
+ "Utility"
+ "Security"
+ ];
+ terminal = false;
+ };
+in
+{
+ options.programs.enteauth = {
+ enable = lib.mkEnableOption "Enables wrapped ente-auth with automated keyring unlocks and a desktop entry.";
+ package = lib.mkOption {
+ type = lib.types.package;
+ default = enteAuthWithKeyring;
+ description = "The customized version of ente-auth with a self-unlocking daemon backend.";
+ };
+ };
+
+ config = lib.mkIf config.programs.enteauth.enable {
+ home.packages = [ config.programs.enteauth.package ];
+
+ xdg.mimeApps.defaultApplications = {
+ "x-scheme-handler/enteauth" = "enteauth.desktop";
+ };
+ };
+}
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
new file mode 100644
index 0000000..3990f7f
--- /dev/null
+++ b/modules/security/gopass/default.nix
@@ -0,0 +1,30 @@
+# gopass - Standard Unix password manager (Go implementation)
+{
+ config,
+ lib,
+ pkgs,
+ ...
+}:
+
+{
+ options.programs.gopass = {
+ enable = lib.mkEnableOption "Enables gopass.";
+
+ package = lib.mkOption {
+ type = lib.types.package;
+ default = pkgs.gopass.override { passAlias = true; };
+ defaultText = lib.literalExpression "pkgs.gopass.override { passAlias = true; }";
+ description = "The gopass package to use.";
+ };
+ };
+
+ config = lib.mkIf config.programs.gopass.enable {
+ programs.password-store = {
+ enable = true;
+ package = config.programs.gopass.package;
+ settings = {
+ PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass";
+ };
+ };
+ };
+}
diff --git a/modules/security/gpg/default.nix b/modules/security/gpg/default.nix
new file mode 100644
index 0000000..858f79f
--- /dev/null
+++ b/modules/security/gpg/default.nix
@@ -0,0 +1,20 @@
+{
+ config,
+ lib,
+ pkgs,
+ ...
+}:
+
+# gpg - GNU Privacy Guard
+{
+ config = lib.mkIf config.programs.gpg.enable {
+ services.gpg-agent = {
+ enable = true;
+ enableZshIntegration = true;
+ defaultCacheTtl = 3600;
+ maxCacheTtl = 86400;
+ enableSshSupport = config.programs.ssh.enable;
+ pinentry.package = pkgs.pinentry-gtk2;
+ };
+ };
+}
diff --git a/modules/security/openvpn/default.nix b/modules/security/openvpn/default.nix
new file mode 100644
index 0000000..d0edef3
--- /dev/null
+++ b/modules/security/openvpn/default.nix
@@ -0,0 +1,18 @@
+{
+ config,
+ lib,
+ pkgs,
+ ...
+}:
+
+# OpenVPN - Open-source VPN client for secure remote access
+{
+ options.programs.openvpn = {
+ enable = lib.mkEnableOption "Enables openvpn.";
+ package = lib.mkPackageOption pkgs "openvpn" { };
+ };
+
+ config = lib.mkIf config.programs.openvpn.enable {
+ home.packages = [ config.programs.openvpn.package ];
+ };
+}
diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix
new file mode 100644
index 0000000..7e8752a
--- /dev/null
+++ b/modules/security/ssh/default.nix
@@ -0,0 +1,26 @@
+{
+ config,
+ lib,
+ pkgs,
+ ...
+}:
+
+# OpenSSH - Secure shell (SSH) client for encrypted remote connections
+{
+ imports = [ ./git.nix ];
+
+ config = lib.mkIf config.programs.ssh.enable {
+ programs.ssh = {
+ package = pkgs.openssh;
+ enableDefaultConfig = false;
+ extraOptionOverrides = {
+ AddKeysToAgent = "yes";
+ ForwardAgent = "yes";
+ ServerAliveInterval = "60";
+ ServerAliveCountMax = "3";
+ VisualHostKey = "yes";
+ HashKnownHosts = "yes";
+ };
+ };
+ };
+}
diff --git a/modules/security/ssh/git.nix b/modules/security/ssh/git.nix
new file mode 100644
index 0000000..9683629
--- /dev/null
+++ b/modules/security/ssh/git.nix
@@ -0,0 +1,49 @@
+{ config, lib, ... }:
+
+let
+ hosts = [
+ {
+ domain = "github.com";
+ identityName = "github";
+ }
+ {
+ domain = "gitlab.com";
+ identityName = "gitlab";
+ }
+ {
+ domain = "bitbucket.org";
+ identityName = "bitbucket";
+ }
+ {
+ domain = "codeberg.org";
+ identityName = "codeberg";
+ }
+ {
+ domain = "git.sr.ht";
+ identityName = "sourcehut";
+ }
+ ];
+
+ mkGitHost =
+ { domain, identityName }:
+ lib.nameValuePair domain {
+ hostname = domain;
+ user = "git";
+ identityFile = "${config.home.homeDirectory}/.local/share/ssh/git/${identityName}";
+ };
+
+ mkKeyFile =
+ { identityName, ... }:
+ lib.nameValuePair identityName {
+ enable = true;
+ text = "";
+ force = false;
+ };
+in
+{
+ config = lib.mkIf (config.programs.ssh.enable && config.programs.git.useSSH) {
+ home.file = builtins.listToAttrs (map mkKeyFile hosts);
+
+ programs.ssh.settings = builtins.listToAttrs (map mkGitHost hosts);
+ };
+}