diff options
Diffstat (limited to 'modules/security')
| -rw-r--r-- | modules/security/gopass/default.nix | 97 | ||||
| -rw-r--r-- | modules/security/gpg-tui/default.nix | 11 | ||||
| -rw-r--r-- | modules/security/gpg/default.nix | 28 | ||||
| -rw-r--r-- | modules/security/ssh/default.nix | 14 |
4 files changed, 88 insertions, 62 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index 616baeb..173318b 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -5,6 +5,9 @@ pkgs, ... }: +let + cfg = config.security.gopass; +in { imports = [ ./assertions.nix ]; @@ -16,33 +19,51 @@ default = config.programs.password-store.package; description = "The gopass package to use."; }; - sync = { - enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory."; - remote = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured."; - }; - credential = { - username = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "Username for HTTPS git authentication against the gopass remote."; - }; - passwordGopassPath = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = null; - description = "gopass entry path holding the password or token used."; + sync = lib.mkOption { + type = lib.types.submodule { + options = { + enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory."; + remote = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured."; + }; + credential = lib.mkOption { + type = lib.types.submodule { + options = { + username = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Username for HTTPS git authentication against the gopass remote."; + }; + password-gopass-secret = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "gopass entry path holding the password or token used."; + }; + }; + }; + default = { }; + description = "Credentials for HTTPS git authentication."; + }; }; }; + default = { }; + description = "Git-backed syncing configuration."; }; - creation-templates = { - enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands."; + creation-templates = lib.mkOption { + type = lib.types.submodule { + options = { + enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands."; + }; + }; + default = { }; + description = "Creation templates configuration."; }; }; config = lib.mkMerge [ - (lib.mkIf config.security.gopass.enable { + (lib.mkIf cfg.enable { programs.password-store = { enable = true; package = pkgs.gopass.override { passAlias = true; }; @@ -68,15 +89,9 @@ gpgSign = false; }; } - // - lib.optionalAttrs - ( - config.security.gopass.sync.enable - && config.security.gopass.sync.credential.passwordGopassPath != null - ) - { - credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f"; - }; + // lib.optionalAttrs (cfg.sync.enable && cfg.sync.credential.password-gopass-secret != null) { + credential.helper = "!f() { echo username=${lib.escapeShellArg cfg.sync.credential.username}; echo password=\"$(${lib.getExe cfg.package} show -o ${lib.escapeShellArg cfg.sync.credential.password-gopass-secret})\"; }; f"; + }; } ]; @@ -88,20 +103,18 @@ source = ../../../assets/icons/apps/gopass.svg; }; - home.activation.copyCreationTemplatesForGopass = - lib.mkIf config.security.gopass.creation-templates.enable - ( - lib.hm.dag.entryAfter [ "writeBoundary" ] '' - $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" - $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create - $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" - '' - ); + home.activation.copyCreationTemplatesForGopass = lib.mkIf cfg.creation-templates.enable ( + lib.hm.dag.entryAfter [ "writeBoundary" ] '' + $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" + $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create + $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" + '' + ); }) - (lib.mkIf (config.security.gopass.enable && config.terminal.kitty.enable) { + (lib.mkIf (cfg.enable && config.terminal.kitty.enable) { xdg.desktopEntries."gopass" = { name = "gopass"; - exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe config.security.gopass.package}"; + exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe cfg.package}"; icon = "gopass"; comment = "Standard Unix password manager (Go implementation)"; categories = [ "Utility" ]; @@ -109,7 +122,7 @@ type = "Application"; }; }) - (lib.mkIf config.security.gopass.sync.enable { + (lib.mkIf cfg.sync.enable { home.activation.gopassSyncInit = let gopassSyncInit = pkgs.writeShellApplication { @@ -121,7 +134,7 @@ text = builtins.replaceStrings [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ] - [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ] + [ config.programs.password-store.settings.PASSWORD_STORE_DIR cfg.sync.remote ] (builtins.readFile ./gopass-sync-init.sh); }; in diff --git a/modules/security/gpg-tui/default.nix b/modules/security/gpg-tui/default.nix index bc4ac4f..2a5e61f 100644 --- a/modules/security/gpg-tui/default.nix +++ b/modules/security/gpg-tui/default.nix @@ -5,6 +5,9 @@ pkgs, ... }: +let + cfg = config.security.gpg-tui; +in { options.security.gpg-tui = { enable = lib.mkEnableOption "Enables gpg-tui."; @@ -17,17 +20,17 @@ }; config = lib.mkMerge [ - (lib.mkIf config.security.gpg-tui.enable { + (lib.mkIf cfg.enable { home.file.".local/share/icons/hicolor/scalable/apps/gpg.svg" = { source = ../../../assets/icons/apps/gpg.svg; }; - home.packages = [ config.security.gpg-tui.package ]; + home.packages = [ cfg.package ]; }) - (lib.mkIf (config.security.gpg-tui.enable && config.terminal.kitty.enable) { + (lib.mkIf (cfg.enable && config.terminal.kitty.enable) { xdg.desktopEntries."gpg-tui" = { name = "gpg-tui"; - exec = "${lib.getExe config.terminal.kitty.package} --class gpg-tui -e ${lib.getExe config.security.gpg-tui.package}"; + exec = "${lib.getExe config.terminal.kitty.package} --class gpg-tui -e ${lib.getExe cfg.package}"; icon = "gpg"; categories = [ "Security" ]; comment = "Terminal UI for GnuPG"; diff --git a/modules/security/gpg/default.nix b/modules/security/gpg/default.nix index 3047f59..8fa7348 100644 --- a/modules/security/gpg/default.nix +++ b/modules/security/gpg/default.nix @@ -6,6 +6,8 @@ ... }: let + cfg = config.security.gpg; + gpgBackupScript = pkgs.writeShellApplication { name = "gpg-backup"; runtimeInputs = [ @@ -51,19 +53,25 @@ in description = "The gpg package to use."; }; - backup = { - enable = lib.mkEnableOption "Enable the gpg-backup script"; - package = lib.mkOption { - type = lib.types.package; - readOnly = true; - default = gpgBackupScriptPkg; - description = "The package for the gpg-backup script"; + backup = lib.mkOption { + type = lib.types.submodule { + options = { + enable = lib.mkEnableOption "Enable the gpg-backup script"; + package = lib.mkOption { + type = lib.types.package; + readOnly = true; + default = gpgBackupScriptPkg; + description = "The package for the gpg-backup script"; + }; + }; }; + default = { }; + description = "GPG backup script configuration."; }; }; config = lib.mkMerge [ - (lib.mkIf config.security.gpg.enable { + (lib.mkIf cfg.enable { programs.gpg = { enable = true; homedir = "${config.xdg.dataHome}/gnupg"; @@ -82,8 +90,8 @@ in pinentry.package = pkgs.pinentry-rofi; }; }) - (lib.mkIf config.security.gpg.backup.enable { - home.packages = [ config.security.gpg.backup.package ]; + (lib.mkIf cfg.backup.enable { + home.packages = [ cfg.backup.package ]; }) ]; } diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix index e18b933..ed93e27 100644 --- a/modules/security/ssh/default.nix +++ b/modules/security/ssh/default.nix @@ -6,13 +6,15 @@ ... }: let + cfg = config.security.ssh; + gpgSshKeyLoad = pkgs.writeShellApplication { name = "gpg-ssh-key-load"; runtimeInputs = [ config.terminal.bash.package config.security.gopass.package config.security.gpg.package - config.security.ssh.package + cfg.package pkgs.coreutils ]; text = @@ -22,7 +24,7 @@ let "@@GNUPGHOME@@" ] [ - config.security.ssh.sshKeyGopassPath + cfg.ssh-key-gopass-secret config.home.sessionVariables.GNUPGHOME ] (builtins.readFile ./gpg-ssh-key-load.sh); @@ -38,7 +40,7 @@ in description = "The ssh package to use."; }; - sshKeyGopassPath = lib.mkOption { + ssh-key-gopass-secret = lib.mkOption { type = lib.types.nullOr lib.types.str; default = null; description = '' @@ -50,8 +52,8 @@ in }; config = lib.mkMerge [ - (lib.mkIf config.security.ssh.enable { - home.packages = [ config.security.ssh.package ]; + (lib.mkIf cfg.enable { + home.packages = [ cfg.package ]; assertions = [ { @@ -64,7 +66,7 @@ in ]; }) - (lib.mkIf (config.security.ssh.enable && config.security.ssh.sshKeyGopassPath != null) { + (lib.mkIf (cfg.enable && cfg.ssh-key-gopass-secret != null) { home.activation.gpgSshKeyLoad = lib.hm.dag.entryAfter [ "writeBoundary" ] '' run ${lib.getExe gpgSshKeyLoad} || true ''; |
