From 01aaa7ad39c1fe8af6ffbca31abbab27dbfefc95 Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Wed, 15 Jul 2026 20:02:29 +0530 Subject: refactor: organized the modules into better categories Instead of lumping everything in modules/programs we are separating them into separate directories in modules/ --- modules/security/ssh/default.nix | 26 +++++++++++++++++++++ modules/security/ssh/git.nix | 49 ++++++++++++++++++++++++++++++++++++++++ 2 files changed, 75 insertions(+) create mode 100644 modules/security/ssh/default.nix create mode 100644 modules/security/ssh/git.nix (limited to 'modules/security/ssh') diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix new file mode 100644 index 0000000..7e8752a --- /dev/null +++ b/modules/security/ssh/default.nix @@ -0,0 +1,26 @@ +{ + config, + lib, + pkgs, + ... +}: + +# OpenSSH - Secure shell (SSH) client for encrypted remote connections +{ + imports = [ ./git.nix ]; + + config = lib.mkIf config.programs.ssh.enable { + programs.ssh = { + package = pkgs.openssh; + enableDefaultConfig = false; + extraOptionOverrides = { + AddKeysToAgent = "yes"; + ForwardAgent = "yes"; + ServerAliveInterval = "60"; + ServerAliveCountMax = "3"; + VisualHostKey = "yes"; + HashKnownHosts = "yes"; + }; + }; + }; +} diff --git a/modules/security/ssh/git.nix b/modules/security/ssh/git.nix new file mode 100644 index 0000000..9683629 --- /dev/null +++ b/modules/security/ssh/git.nix @@ -0,0 +1,49 @@ +{ config, lib, ... }: + +let + hosts = [ + { + domain = "github.com"; + identityName = "github"; + } + { + domain = "gitlab.com"; + identityName = "gitlab"; + } + { + domain = "bitbucket.org"; + identityName = "bitbucket"; + } + { + domain = "codeberg.org"; + identityName = "codeberg"; + } + { + domain = "git.sr.ht"; + identityName = "sourcehut"; + } + ]; + + mkGitHost = + { domain, identityName }: + lib.nameValuePair domain { + hostname = domain; + user = "git"; + identityFile = "${config.home.homeDirectory}/.local/share/ssh/git/${identityName}"; + }; + + mkKeyFile = + { identityName, ... }: + lib.nameValuePair identityName { + enable = true; + text = ""; + force = false; + }; +in +{ + config = lib.mkIf (config.programs.ssh.enable && config.programs.git.useSSH) { + home.file = builtins.listToAttrs (map mkKeyFile hosts); + + programs.ssh.settings = builtins.listToAttrs (map mkGitHost hosts); + }; +} -- cgit v1.2.3