diff options
Diffstat (limited to 'modules/security/ssh')
| -rw-r--r-- | modules/security/ssh/default.nix | 26 | ||||
| -rw-r--r-- | modules/security/ssh/git.nix | 49 |
2 files changed, 75 insertions, 0 deletions
diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix new file mode 100644 index 0000000..7e8752a --- /dev/null +++ b/modules/security/ssh/default.nix @@ -0,0 +1,26 @@ +{ + config, + lib, + pkgs, + ... +}: + +# OpenSSH - Secure shell (SSH) client for encrypted remote connections +{ + imports = [ ./git.nix ]; + + config = lib.mkIf config.programs.ssh.enable { + programs.ssh = { + package = pkgs.openssh; + enableDefaultConfig = false; + extraOptionOverrides = { + AddKeysToAgent = "yes"; + ForwardAgent = "yes"; + ServerAliveInterval = "60"; + ServerAliveCountMax = "3"; + VisualHostKey = "yes"; + HashKnownHosts = "yes"; + }; + }; + }; +} diff --git a/modules/security/ssh/git.nix b/modules/security/ssh/git.nix new file mode 100644 index 0000000..9683629 --- /dev/null +++ b/modules/security/ssh/git.nix @@ -0,0 +1,49 @@ +{ config, lib, ... }: + +let + hosts = [ + { + domain = "github.com"; + identityName = "github"; + } + { + domain = "gitlab.com"; + identityName = "gitlab"; + } + { + domain = "bitbucket.org"; + identityName = "bitbucket"; + } + { + domain = "codeberg.org"; + identityName = "codeberg"; + } + { + domain = "git.sr.ht"; + identityName = "sourcehut"; + } + ]; + + mkGitHost = + { domain, identityName }: + lib.nameValuePair domain { + hostname = domain; + user = "git"; + identityFile = "${config.home.homeDirectory}/.local/share/ssh/git/${identityName}"; + }; + + mkKeyFile = + { identityName, ... }: + lib.nameValuePair identityName { + enable = true; + text = ""; + force = false; + }; +in +{ + config = lib.mkIf (config.programs.ssh.enable && config.programs.git.useSSH) { + home.file = builtins.listToAttrs (map mkKeyFile hosts); + + programs.ssh.settings = builtins.listToAttrs (map mkGitHost hosts); + }; +} |
