From 2ac22a72455341a3efced289782fe5daf5d788ee Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Mon, 17 Aug 2026 15:25:55 +0530 Subject: refactor: rewrote how ssh keys are handled in gopass-ssh-load - all ssh keys that are used under ssh/ have to be explicitely added via security.ssh.gopassKeys = [ ... ] --- modules/security/ssh/default.nix | 20 +++----------------- 1 file changed, 3 insertions(+), 17 deletions(-) (limited to 'modules/security/ssh/default.nix') diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix index 97b5808..8d1f881 100644 --- a/modules/security/ssh/default.nix +++ b/modules/security/ssh/default.nix @@ -6,8 +6,6 @@ ... }: { - imports = [ ./git.nix ]; - options.security.ssh = { enable = lib.mkEnableOption "Enables ssh."; package = lib.mkOption { @@ -17,10 +15,10 @@ description = "The ssh package to use."; }; - extraGopassKeys = lib.mkOption { + gopassKeys = lib.mkOption { type = lib.types.listOf lib.types.str; default = [ ]; - description = "Additional SSH keys to load from the gopass store (entries under ssh/), in addition to the git platform keys."; + description = "SSH keys to load from the gopass store (entries under ssh/)."; }; }; @@ -28,19 +26,7 @@ programs.ssh = { enable = true; - package = - if (config.security.gopass.enable or false && config.security.gopass.ssh-agent.enable or false) then - pkgs.symlinkJoin { - name = "openssh-gopass-wrapper"; - paths = [ pkgs.openssh ]; - buildInputs = [ pkgs.makeWrapper ]; - postBuild = '' - wrapProgram $out/bin/ssh \ - --run "${lib.getExe config.scripts.gopass-ssh-load.package}" - ''; - } - else - pkgs.openssh; + package = pkgs.openssh; enableDefaultConfig = false; extraOptionOverrides = { -- cgit v1.2.3