From 357d69f4ce7da70e746c465c8fa32c8d6dbe815e Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Wed, 29 Jul 2026 23:36:51 +0530 Subject: feat(ssh): lazy-loading ssh keys from gopass - Loading ssh keys from gopass only when ssh command runs for the first time --- modules/security/ssh/default.nix | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) (limited to 'modules/security/ssh/default.nix') diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix index 4b4180f..62186c4 100644 --- a/modules/security/ssh/default.nix +++ b/modules/security/ssh/default.nix @@ -15,7 +15,21 @@ config = lib.mkIf config.security.ssh.enable { programs.ssh = { enable = true; - package = pkgs.openssh; + + package = + if (config.security.gopass.enable or false && config.security.gopass.ssh-agent.enable or false) then + pkgs.symlinkJoin { + name = "openssh-gopass-wrapper"; + paths = [ pkgs.openssh ]; + buildInputs = [ pkgs.makeWrapper ]; + postBuild = '' + wrapProgram $out/bin/ssh \ + --run "${config.security.gopass.ssh-agent.script}/bin/gopass-ssh-load" + ''; + } + else + pkgs.openssh; + enableDefaultConfig = false; extraOptionOverrides = { AddKeysToAgent = "yes"; -- cgit v1.2.3