aboutsummaryrefslogtreecommitdiffstats
path: root/modules
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-08-17 15:25:55 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-08-29 03:50:27 +0530
commit2ac22a72455341a3efced289782fe5daf5d788ee (patch)
treedad5f0cb7ea6c2dce9426462e35cc518d73ad91f /modules
parentf001094478a394b70f32425c7fcc0d715950b851 (diff)
downloadhome-manager-config-2ac22a72455341a3efced289782fe5daf5d788ee.tar.gz
home-manager-config-2ac22a72455341a3efced289782fe5daf5d788ee.zip
refactor: rewrote how ssh keys are handled in gopass-ssh-load
- all ssh keys that are used under ssh/ have to be explicitely added via security.ssh.gopassKeys = [ ... ]
Diffstat (limited to 'modules')
-rw-r--r--modules/development/lazygit/default.nix10
-rw-r--r--modules/private/email.example.nix30
-rw-r--r--modules/private/git.example.nix17
-rw-r--r--modules/scripts/gopass-ssh-load/default.nix11
-rw-r--r--modules/security/ssh/default.nix20
-rw-r--r--modules/security/ssh/git.nix23
6 files changed, 36 insertions, 75 deletions
diff --git a/modules/development/lazygit/default.nix b/modules/development/lazygit/default.nix
index 1806fa5..a39a8b6 100644
--- a/modules/development/lazygit/default.nix
+++ b/modules/development/lazygit/default.nix
@@ -21,8 +21,8 @@
enableNushellIntegration = config.programs.nushell.enable;
enableZshIntegration = config.terminal.zsh.enable;
settings = {
- gui = {
- theme = with config.scheme.withHashtag; {
+ gui = with config.scheme.withHashtag; {
+ theme = {
lightTheme = false;
activeBorderColor = [
base0D
@@ -44,11 +44,11 @@
];
};
authorColors = {
- "*" = (with config.scheme.withHashtag; base0E);
+ "*" = base0E;
};
branchColors = {
- "master" = (with config.scheme.withHashtag; base08);
- "main" = (with config.scheme.withHashtag; base08);
+ "master" = base08;
+ "main" = base08;
};
showIcons = true;
scrollHeight = 2;
diff --git a/modules/private/email.example.nix b/modules/private/email.example.nix
index 16d8402..e6b4c2f 100644
--- a/modules/private/email.example.nix
+++ b/modules/private/email.example.nix
@@ -1,20 +1,22 @@
# Email example - Template for configuring neomutt email accounts
{ ... }:
{
- config.communication.neomutt.accounts = {
- "example@gmail.com" = {
- realName = "Example User";
- address = "user@gmail.com";
- passwordGopassSecret = "mail/user@gmail.com";
- flavor = "gmail.com";
- primary = true;
- neomutt.extraConfig = ''
- set pgp_default_key = YOUR_GPG_KEY_FINGERPRINT
- '';
- gpg = {
- key = "YOUR_GPG_KEY_ID";
- signByDefault = true;
- encryptByDefault = false; # set true only if you also want auto-encrypt
+ config = {
+ communication.neomutt.accounts = {
+ "example@gmail.com" = {
+ realName = "Example User";
+ address = "user@gmail.com";
+ passwordGopassSecret = "mail/user@gmail.com";
+ flavor = "gmail.com";
+ primary = true;
+ neomutt.extraConfig = ''
+ set pgp_default_key = YOUR_GPG_KEY_FINGERPRINT
+ '';
+ gpg = {
+ key = "YOUR_GPG_KEY_ID";
+ signByDefault = true;
+ encryptByDefault = false; # set true only if you also want auto-encrypt
+ };
};
};
};
diff --git a/modules/private/git.example.nix b/modules/private/git.example.nix
index 236687e..da4d77e 100644
--- a/modules/private/git.example.nix
+++ b/modules/private/git.example.nix
@@ -1,12 +1,17 @@
# Git example - Template for configuring git identity and signing
{ ... }:
{
- config.development.git = {
- username = "Arpit Chakladar";
- email = "arpitchakladar+git@gmail.com";
- signing = {
- key = "EXAMPLE_GPG_KEY_ID";
- signByDefault = true;
+ config = {
+ development.git = {
+ username = "Your Name";
+ email = "you@example.com";
+ signing = {
+ key = "EXAMPLE_GPG_KEY_ID";
+ signByDefault = true;
+ };
};
+
+ # SSH keys to load from gopass (entries under ssh/ in the gopass store)
+ security.ssh.gopassKeys = [ "github" ];
};
}
diff --git a/modules/scripts/gopass-ssh-load/default.nix b/modules/scripts/gopass-ssh-load/default.nix
index 7b39085..764f704 100644
--- a/modules/scripts/gopass-ssh-load/default.nix
+++ b/modules/scripts/gopass-ssh-load/default.nix
@@ -7,16 +7,7 @@
let
inherit ((import ../lib.nix { inherit lib pkgs; })) mkScriptModule;
- gitPlatformKeys = [
- "github"
- "gitlab"
- "bitbucket"
- "codeberg"
- "srht"
- ];
-
- gopassKeys =
- lib.optionals config.development.git.useSSH gitPlatformKeys ++ config.security.ssh.extraGopassKeys;
+ gopassKeys = config.security.ssh.gopassKeys;
base = mkScriptModule {
name = "gopass-ssh-load";
diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix
index 97b5808..8d1f881 100644
--- a/modules/security/ssh/default.nix
+++ b/modules/security/ssh/default.nix
@@ -6,8 +6,6 @@
...
}:
{
- imports = [ ./git.nix ];
-
options.security.ssh = {
enable = lib.mkEnableOption "Enables ssh.";
package = lib.mkOption {
@@ -17,10 +15,10 @@
description = "The ssh package to use.";
};
- extraGopassKeys = lib.mkOption {
+ gopassKeys = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [ ];
- description = "Additional SSH keys to load from the gopass store (entries under ssh/), in addition to the git platform keys.";
+ description = "SSH keys to load from the gopass store (entries under ssh/).";
};
};
@@ -28,19 +26,7 @@
programs.ssh = {
enable = true;
- package =
- if (config.security.gopass.enable or false && config.security.gopass.ssh-agent.enable or false) then
- pkgs.symlinkJoin {
- name = "openssh-gopass-wrapper";
- paths = [ pkgs.openssh ];
- buildInputs = [ pkgs.makeWrapper ];
- postBuild = ''
- wrapProgram $out/bin/ssh \
- --run "${lib.getExe config.scripts.gopass-ssh-load.package}"
- '';
- }
- else
- pkgs.openssh;
+ package = pkgs.openssh;
enableDefaultConfig = false;
extraOptionOverrides = {
diff --git a/modules/security/ssh/git.nix b/modules/security/ssh/git.nix
deleted file mode 100644
index 146bfb9..0000000
--- a/modules/security/ssh/git.nix
+++ /dev/null
@@ -1,23 +0,0 @@
-# SSH host configurations for git platforms
-{ config, lib, ... }:
-let
- hosts = [
- "github.com"
- "gitlab.com"
- "bitbucket.org"
- "codeberg.org"
- "git.sr.ht"
- ];
-
- mkGitHost =
- domain:
- lib.nameValuePair domain {
- hostname = domain;
- user = "git";
- };
-in
-{
- config = lib.mkIf (config.security.ssh.enable && config.development.git.useSSH) {
- programs.ssh.settings = builtins.listToAttrs (map mkGitHost hosts);
- };
-}