aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/gpg/default.nix
blob: ccab0dc400ab04058df884c7700a6143cc5c11ad (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
# GNU Privacy Guard
{
  config,
  lib,
  pkgs,
  ...
}:
let
  gpgBackupScript = pkgs.writeShellApplication {
    name = "gpg-backup";
    runtimeInputs = [
      pkgs.bash
      pkgs.gnupg
      pkgs.gnutar
      pkgs.coreutils
      pkgs.findutils
    ];
    text = builtins.readFile ./gpg-backup.sh;
  };

  gpgBackupCompletion =
    pkgs.runCommand "gpg-backup-completion"
      {
        nativeBuildInputs = [ pkgs.installShellFiles ];
      }
      ''
        mkdir -p $out/share/zsh/site-functions
        installShellCompletion --zsh --name _gpg-backup ${pkgs.writeText "gpg-backup.zsh" (builtins.readFile ./gpg-backup.zsh)}
      '';

  gpgBackupScriptPkg = pkgs.symlinkJoin {
    name = "gpg-backup";
    paths = [
      gpgBackupScript
      gpgBackupCompletion
    ];
    meta = gpgBackupScript.meta or { };
  };
in
{
  options.security.gpg = {
    enable = lib.mkEnableOption "Enables gpg.";

    package = lib.mkOption {
      type = lib.types.package;
      default = config.programs.gpg.package;
      readOnly = true;
      defaultText = lib.literalExpression "config.programs.gpg.package";
      description = "The gpg package to use.";
    };

    backup = {
      enable = lib.mkEnableOption "Enable the gpg-backup script";
      package = lib.mkOption {
        type = lib.types.package;
        readOnly = true;
        default = gpgBackupScriptPkg;
        description = "The package for the gpg-backup script";
      };
    };
  };

  config = lib.mkMerge [
    (lib.mkIf config.security.gpg.enable {
      programs.gpg = {
        enable = true;
        homedir = "${config.xdg.dataHome}/gnupg";
      };

      home.sessionVariables = {
        GNUPGHOME = config.programs.gpg.homedir;
      };

      services.gpg-agent = {
        enable = true;
        enableZshIntegration = true;
        defaultCacheTtl = 3600;
        maxCacheTtl = 86400;
        enableSshSupport = config.security.ssh.enable;
        pinentry.package = pkgs.pinentry-rofi;
      };
    })
    (lib.mkIf config.security.gpg.backup.enable {
      home.packages = [ config.security.gpg.backup.package ];
    })
  ];
}