From 01aaa7ad39c1fe8af6ffbca31abbab27dbfefc95 Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Wed, 15 Jul 2026 20:02:29 +0530 Subject: refactor: organized the modules into better categories Instead of lumping everything in modules/programs we are separating them into separate directories in modules/ --- modules/security/default.nix | 11 +++++++ modules/security/enteauth/default.nix | 61 +++++++++++++++++++++++++++++++++++ modules/security/gopass/default.nix | 30 +++++++++++++++++ modules/security/gpg/default.nix | 20 ++++++++++++ modules/security/openvpn/default.nix | 18 +++++++++++ modules/security/ssh/default.nix | 26 +++++++++++++++ modules/security/ssh/git.nix | 49 ++++++++++++++++++++++++++++ 7 files changed, 215 insertions(+) create mode 100644 modules/security/default.nix create mode 100644 modules/security/enteauth/default.nix create mode 100644 modules/security/gopass/default.nix create mode 100644 modules/security/gpg/default.nix create mode 100644 modules/security/openvpn/default.nix create mode 100644 modules/security/ssh/default.nix create mode 100644 modules/security/ssh/git.nix (limited to 'modules/security') diff --git a/modules/security/default.nix b/modules/security/default.nix new file mode 100644 index 0000000..e9d7208 --- /dev/null +++ b/modules/security/default.nix @@ -0,0 +1,11 @@ +{ ... }: + +{ + imports = [ + ./enteauth + ./gopass + ./gpg + ./openvpn + ./ssh + ]; +} diff --git a/modules/security/enteauth/default.nix b/modules/security/enteauth/default.nix new file mode 100644 index 0000000..a332bf3 --- /dev/null +++ b/modules/security/enteauth/default.nix @@ -0,0 +1,61 @@ +{ + config, + lib, + pkgs, + ... +}: + +# Ente Auth - end-to-end encrypted authentication (2FA) +let + enteAuthWithKeyring = pkgs.symlinkJoin { + name = "ente-auth-wrapped"; + paths = [ pkgs.ente-auth ]; + buildInputs = [ pkgs.makeWrapper ]; + postBuild = '' + wrapProgram $out/bin/enteauth \ + --prefix PATH : ${ + lib.makeBinPath [ + pkgs.gnome-keyring + pkgs.dbus + ] + } \ + --run "echo 'password' | ${pkgs.gnome-keyring}/bin/gnome-keyring-daemon --unlock --components=secrets" + + rm -rf $out/share/applications/* + + ln -s ${customDesktopItem}/share/applications/* $out/share/applications/ + ''; + }; + + customDesktopItem = pkgs.makeDesktopItem { + name = "enteauth"; + exec = "enteauth"; + icon = "io.ente.auth"; + comment = "End-to-end encrypted 2FA authenticator"; + desktopName = "Ente Auth"; + genericName = "2FA Authenticator"; + categories = [ + "Utility" + "Security" + ]; + terminal = false; + }; +in +{ + options.programs.enteauth = { + enable = lib.mkEnableOption "Enables wrapped ente-auth with automated keyring unlocks and a desktop entry."; + package = lib.mkOption { + type = lib.types.package; + default = enteAuthWithKeyring; + description = "The customized version of ente-auth with a self-unlocking daemon backend."; + }; + }; + + config = lib.mkIf config.programs.enteauth.enable { + home.packages = [ config.programs.enteauth.package ]; + + xdg.mimeApps.defaultApplications = { + "x-scheme-handler/enteauth" = "enteauth.desktop"; + }; + }; +} diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix new file mode 100644 index 0000000..3990f7f --- /dev/null +++ b/modules/security/gopass/default.nix @@ -0,0 +1,30 @@ +# gopass - Standard Unix password manager (Go implementation) +{ + config, + lib, + pkgs, + ... +}: + +{ + options.programs.gopass = { + enable = lib.mkEnableOption "Enables gopass."; + + package = lib.mkOption { + type = lib.types.package; + default = pkgs.gopass.override { passAlias = true; }; + defaultText = lib.literalExpression "pkgs.gopass.override { passAlias = true; }"; + description = "The gopass package to use."; + }; + }; + + config = lib.mkIf config.programs.gopass.enable { + programs.password-store = { + enable = true; + package = config.programs.gopass.package; + settings = { + PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass"; + }; + }; + }; +} diff --git a/modules/security/gpg/default.nix b/modules/security/gpg/default.nix new file mode 100644 index 0000000..858f79f --- /dev/null +++ b/modules/security/gpg/default.nix @@ -0,0 +1,20 @@ +{ + config, + lib, + pkgs, + ... +}: + +# gpg - GNU Privacy Guard +{ + config = lib.mkIf config.programs.gpg.enable { + services.gpg-agent = { + enable = true; + enableZshIntegration = true; + defaultCacheTtl = 3600; + maxCacheTtl = 86400; + enableSshSupport = config.programs.ssh.enable; + pinentry.package = pkgs.pinentry-gtk2; + }; + }; +} diff --git a/modules/security/openvpn/default.nix b/modules/security/openvpn/default.nix new file mode 100644 index 0000000..d0edef3 --- /dev/null +++ b/modules/security/openvpn/default.nix @@ -0,0 +1,18 @@ +{ + config, + lib, + pkgs, + ... +}: + +# OpenVPN - Open-source VPN client for secure remote access +{ + options.programs.openvpn = { + enable = lib.mkEnableOption "Enables openvpn."; + package = lib.mkPackageOption pkgs "openvpn" { }; + }; + + config = lib.mkIf config.programs.openvpn.enable { + home.packages = [ config.programs.openvpn.package ]; + }; +} diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix new file mode 100644 index 0000000..7e8752a --- /dev/null +++ b/modules/security/ssh/default.nix @@ -0,0 +1,26 @@ +{ + config, + lib, + pkgs, + ... +}: + +# OpenSSH - Secure shell (SSH) client for encrypted remote connections +{ + imports = [ ./git.nix ]; + + config = lib.mkIf config.programs.ssh.enable { + programs.ssh = { + package = pkgs.openssh; + enableDefaultConfig = false; + extraOptionOverrides = { + AddKeysToAgent = "yes"; + ForwardAgent = "yes"; + ServerAliveInterval = "60"; + ServerAliveCountMax = "3"; + VisualHostKey = "yes"; + HashKnownHosts = "yes"; + }; + }; + }; +} diff --git a/modules/security/ssh/git.nix b/modules/security/ssh/git.nix new file mode 100644 index 0000000..9683629 --- /dev/null +++ b/modules/security/ssh/git.nix @@ -0,0 +1,49 @@ +{ config, lib, ... }: + +let + hosts = [ + { + domain = "github.com"; + identityName = "github"; + } + { + domain = "gitlab.com"; + identityName = "gitlab"; + } + { + domain = "bitbucket.org"; + identityName = "bitbucket"; + } + { + domain = "codeberg.org"; + identityName = "codeberg"; + } + { + domain = "git.sr.ht"; + identityName = "sourcehut"; + } + ]; + + mkGitHost = + { domain, identityName }: + lib.nameValuePair domain { + hostname = domain; + user = "git"; + identityFile = "${config.home.homeDirectory}/.local/share/ssh/git/${identityName}"; + }; + + mkKeyFile = + { identityName, ... }: + lib.nameValuePair identityName { + enable = true; + text = ""; + force = false; + }; +in +{ + config = lib.mkIf (config.programs.ssh.enable && config.programs.git.useSSH) { + home.file = builtins.listToAttrs (map mkKeyFile hosts); + + programs.ssh.settings = builtins.listToAttrs (map mkGitHost hosts); + }; +} -- cgit v1.2.3