aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar@gmail.com>2026-09-24 04:02:19 +0530
committerArpit Chakladar <arpitchakladar@gmail.com>2026-09-24 04:02:19 +0530
commit5ea8c30b7b82d4c1e7164541892066b1f24f7d22 (patch)
treead9b994cc5415f63bae1f2342f520756d43c67ce /modules/security
parentad96214c9ab94bce925000a6059e3c68e2ff6a22 (diff)
parent748669e19daa3afc8f0cfe10eedc19ae9766ed2c (diff)
downloadhome-manager-config-5ea8c30b7b82d4c1e7164541892066b1f24f7d22.tar.gz
home-manager-config-5ea8c30b7b82d4c1e7164541892066b1f24f7d22.zip
Merge branch 'massive-refactoring'
Diffstat (limited to 'modules/security')
-rw-r--r--modules/security/gopass/default.nix97
-rw-r--r--modules/security/gpg-tui/default.nix11
-rw-r--r--modules/security/gpg/default.nix28
-rw-r--r--modules/security/ssh/default.nix14
4 files changed, 88 insertions, 62 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index 616baeb..173318b 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -5,6 +5,9 @@
pkgs,
...
}:
+let
+ cfg = config.security.gopass;
+in
{
imports = [ ./assertions.nix ];
@@ -16,33 +19,51 @@
default = config.programs.password-store.package;
description = "The gopass package to use.";
};
- sync = {
- enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
- remote = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
- };
- credential = {
- username = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "Username for HTTPS git authentication against the gopass remote.";
- };
- passwordGopassPath = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "gopass entry path holding the password or token used.";
+ sync = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
+ remote = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
+ };
+ credential = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ username = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Username for HTTPS git authentication against the gopass remote.";
+ };
+ password-gopass-secret = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "gopass entry path holding the password or token used.";
+ };
+ };
+ };
+ default = { };
+ description = "Credentials for HTTPS git authentication.";
+ };
};
};
+ default = { };
+ description = "Git-backed syncing configuration.";
};
- creation-templates = {
- enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands.";
+ creation-templates = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands.";
+ };
+ };
+ default = { };
+ description = "Creation templates configuration.";
};
};
config = lib.mkMerge [
- (lib.mkIf config.security.gopass.enable {
+ (lib.mkIf cfg.enable {
programs.password-store = {
enable = true;
package = pkgs.gopass.override { passAlias = true; };
@@ -68,15 +89,9 @@
gpgSign = false;
};
}
- //
- lib.optionalAttrs
- (
- config.security.gopass.sync.enable
- && config.security.gopass.sync.credential.passwordGopassPath != null
- )
- {
- credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f";
- };
+ // lib.optionalAttrs (cfg.sync.enable && cfg.sync.credential.password-gopass-secret != null) {
+ credential.helper = "!f() { echo username=${lib.escapeShellArg cfg.sync.credential.username}; echo password=\"$(${lib.getExe cfg.package} show -o ${lib.escapeShellArg cfg.sync.credential.password-gopass-secret})\"; }; f";
+ };
}
];
@@ -88,20 +103,18 @@
source = ../../../assets/icons/apps/gopass.svg;
};
- home.activation.copyCreationTemplatesForGopass =
- lib.mkIf config.security.gopass.creation-templates.enable
- (
- lib.hm.dag.entryAfter [ "writeBoundary" ] ''
- $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
- $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create
- $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
- ''
- );
+ home.activation.copyCreationTemplatesForGopass = lib.mkIf cfg.creation-templates.enable (
+ lib.hm.dag.entryAfter [ "writeBoundary" ] ''
+ $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
+ $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create
+ $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create"
+ ''
+ );
})
- (lib.mkIf (config.security.gopass.enable && config.terminal.kitty.enable) {
+ (lib.mkIf (cfg.enable && config.terminal.kitty.enable) {
xdg.desktopEntries."gopass" = {
name = "gopass";
- exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe config.security.gopass.package}";
+ exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe cfg.package}";
icon = "gopass";
comment = "Standard Unix password manager (Go implementation)";
categories = [ "Utility" ];
@@ -109,7 +122,7 @@
type = "Application";
};
})
- (lib.mkIf config.security.gopass.sync.enable {
+ (lib.mkIf cfg.sync.enable {
home.activation.gopassSyncInit =
let
gopassSyncInit = pkgs.writeShellApplication {
@@ -121,7 +134,7 @@
text =
builtins.replaceStrings
[ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ]
- [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ]
+ [ config.programs.password-store.settings.PASSWORD_STORE_DIR cfg.sync.remote ]
(builtins.readFile ./gopass-sync-init.sh);
};
in
diff --git a/modules/security/gpg-tui/default.nix b/modules/security/gpg-tui/default.nix
index bc4ac4f..2a5e61f 100644
--- a/modules/security/gpg-tui/default.nix
+++ b/modules/security/gpg-tui/default.nix
@@ -5,6 +5,9 @@
pkgs,
...
}:
+let
+ cfg = config.security.gpg-tui;
+in
{
options.security.gpg-tui = {
enable = lib.mkEnableOption "Enables gpg-tui.";
@@ -17,17 +20,17 @@
};
config = lib.mkMerge [
- (lib.mkIf config.security.gpg-tui.enable {
+ (lib.mkIf cfg.enable {
home.file.".local/share/icons/hicolor/scalable/apps/gpg.svg" = {
source = ../../../assets/icons/apps/gpg.svg;
};
- home.packages = [ config.security.gpg-tui.package ];
+ home.packages = [ cfg.package ];
})
- (lib.mkIf (config.security.gpg-tui.enable && config.terminal.kitty.enable) {
+ (lib.mkIf (cfg.enable && config.terminal.kitty.enable) {
xdg.desktopEntries."gpg-tui" = {
name = "gpg-tui";
- exec = "${lib.getExe config.terminal.kitty.package} --class gpg-tui -e ${lib.getExe config.security.gpg-tui.package}";
+ exec = "${lib.getExe config.terminal.kitty.package} --class gpg-tui -e ${lib.getExe cfg.package}";
icon = "gpg";
categories = [ "Security" ];
comment = "Terminal UI for GnuPG";
diff --git a/modules/security/gpg/default.nix b/modules/security/gpg/default.nix
index 3047f59..8fa7348 100644
--- a/modules/security/gpg/default.nix
+++ b/modules/security/gpg/default.nix
@@ -6,6 +6,8 @@
...
}:
let
+ cfg = config.security.gpg;
+
gpgBackupScript = pkgs.writeShellApplication {
name = "gpg-backup";
runtimeInputs = [
@@ -51,19 +53,25 @@ in
description = "The gpg package to use.";
};
- backup = {
- enable = lib.mkEnableOption "Enable the gpg-backup script";
- package = lib.mkOption {
- type = lib.types.package;
- readOnly = true;
- default = gpgBackupScriptPkg;
- description = "The package for the gpg-backup script";
+ backup = lib.mkOption {
+ type = lib.types.submodule {
+ options = {
+ enable = lib.mkEnableOption "Enable the gpg-backup script";
+ package = lib.mkOption {
+ type = lib.types.package;
+ readOnly = true;
+ default = gpgBackupScriptPkg;
+ description = "The package for the gpg-backup script";
+ };
+ };
};
+ default = { };
+ description = "GPG backup script configuration.";
};
};
config = lib.mkMerge [
- (lib.mkIf config.security.gpg.enable {
+ (lib.mkIf cfg.enable {
programs.gpg = {
enable = true;
homedir = "${config.xdg.dataHome}/gnupg";
@@ -82,8 +90,8 @@ in
pinentry.package = pkgs.pinentry-rofi;
};
})
- (lib.mkIf config.security.gpg.backup.enable {
- home.packages = [ config.security.gpg.backup.package ];
+ (lib.mkIf cfg.backup.enable {
+ home.packages = [ cfg.backup.package ];
})
];
}
diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix
index e18b933..ed93e27 100644
--- a/modules/security/ssh/default.nix
+++ b/modules/security/ssh/default.nix
@@ -6,13 +6,15 @@
...
}:
let
+ cfg = config.security.ssh;
+
gpgSshKeyLoad = pkgs.writeShellApplication {
name = "gpg-ssh-key-load";
runtimeInputs = [
config.terminal.bash.package
config.security.gopass.package
config.security.gpg.package
- config.security.ssh.package
+ cfg.package
pkgs.coreutils
];
text =
@@ -22,7 +24,7 @@ let
"@@GNUPGHOME@@"
]
[
- config.security.ssh.sshKeyGopassPath
+ cfg.ssh-key-gopass-secret
config.home.sessionVariables.GNUPGHOME
]
(builtins.readFile ./gpg-ssh-key-load.sh);
@@ -38,7 +40,7 @@ in
description = "The ssh package to use.";
};
- sshKeyGopassPath = lib.mkOption {
+ ssh-key-gopass-secret = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = ''
@@ -50,8 +52,8 @@ in
};
config = lib.mkMerge [
- (lib.mkIf config.security.ssh.enable {
- home.packages = [ config.security.ssh.package ];
+ (lib.mkIf cfg.enable {
+ home.packages = [ cfg.package ];
assertions = [
{
@@ -64,7 +66,7 @@ in
];
})
- (lib.mkIf (config.security.ssh.enable && config.security.ssh.sshKeyGopassPath != null) {
+ (lib.mkIf (cfg.enable && cfg.ssh-key-gopass-secret != null) {
home.activation.gpgSshKeyLoad = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
run ${lib.getExe gpgSshKeyLoad} || true
'';