From ee32d0d0813f9870d89fb7d821633fd8b4a9987a Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Thu, 9 Jul 2026 20:34:00 +0530 Subject: feat: added email configuration with mbsync + notmuch added a private module which will be gitignored and serves to include options that are not meant to be shared --- modules/programs/git/default.nix | 23 ++++++++++++++++++++--- 1 file changed, 20 insertions(+), 3 deletions(-) (limited to 'modules/programs/git') diff --git a/modules/programs/git/default.nix b/modules/programs/git/default.nix index 133c063..91498b0 100644 --- a/modules/programs/git/default.nix +++ b/modules/programs/git/default.nix @@ -20,14 +20,24 @@ }; useSSH = lib.mkEnableOption "Use SSH instead of HTTPS for common git platforms."; + + signing = { + key = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "GPG signing key ID."; + }; + signByDefault = lib.mkEnableOption "Sign commits by default"; + }; }; config = lib.mkIf config.programs.git.enable { programs.git = { includes = [ - # An additional config file for global git settings but for more - # private/non-portable configuration options like GPG keys - { path = "${config.xdg.configHome}/git/personal"; } + { + path = "${config.xdg.configHome}/git/personal"; + condition = "hasconfig:remote.*.url:git@*"; + } ]; settings = lib.recursiveUpdate @@ -47,6 +57,13 @@ url."git@git.sr.ht:".insteadOf = "https://git.sr.ht/"; } ); + extraConfig = { + user.signingKey = lib.mkIf ( + config.programs.git.signing.key != null + ) config.programs.git.signing.key; + commit.gpgSign = config.programs.git.signing.signByDefault; + tag.forceSignAnnotated = config.programs.git.signing.signByDefault; + }; }; }; } -- cgit v1.2.3