aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-08-04 20:01:06 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-08-04 20:01:06 +0530
commit0a7afa2d1e576f05253b62c6b17e5e4873fbdebc (patch)
tree4aec8cee7c4db281510bc42ff4e214252428afa4 /modules/security
parent2e0f6163f61cb1e4195f1a08ad1148e57a4f5843 (diff)
downloadhome-manager-config-0a7afa2d1e576f05253b62c6b17e5e4873fbdebc.tar.gz
home-manager-config-0a7afa2d1e576f05253b62c6b17e5e4873fbdebc.zip
feat: moved gpg data directory, other gopass ssh keys, script builder
- Using ~/.local/share/gnupg/ for storing the data for gnupg, and made the necessary changes in all places to that effect - Additional ssh keys can be added to gopass under ssh/, which is on top of the git servers that already existed - Using pkgs.writeShellApplication for creating the scripts, stopped setting path for each dependency (creating a long PATH variable and thus finding binaries may take longer), instead using the inbuild dependency (runtimeInputs) for the scripts
Diffstat (limited to 'modules/security')
-rw-r--r--modules/security/gpg/default.nix5
-rw-r--r--modules/security/ssh/default.nix6
2 files changed, 11 insertions, 0 deletions
diff --git a/modules/security/gpg/default.nix b/modules/security/gpg/default.nix
index cd77549..88c57d1 100644
--- a/modules/security/gpg/default.nix
+++ b/modules/security/gpg/default.nix
@@ -21,6 +21,11 @@
config = lib.mkIf config.security.gpg.enable {
programs.gpg = {
enable = true;
+ homedir = "${config.xdg.dataHome}/gnupg";
+ };
+
+ home.sessionVariables = {
+ GNUPGHOME = config.programs.gpg.homedir;
};
services.gpg-agent = {
diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix
index c616677..9b89deb 100644
--- a/modules/security/ssh/default.nix
+++ b/modules/security/ssh/default.nix
@@ -16,6 +16,12 @@
default = config.programs.ssh.package;
description = "The ssh package to use.";
};
+
+ extraGopassKeys = lib.mkOption {
+ type = lib.types.listOf lib.types.str;
+ default = [ ];
+ description = "Additional SSH keys to load from the gopass store (entries under ssh/), in addition to the git platform keys.";
+ };
};
config = lib.mkIf config.security.ssh.enable {