aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/ssh/default.nix
blob: e18b933c51ecafb855d98fd3e42c158ca7e7a43f (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
# Secure shell client for encrypted remote connections
{
  config,
  lib,
  pkgs,
  ...
}:
let
  gpgSshKeyLoad = pkgs.writeShellApplication {
    name = "gpg-ssh-key-load";
    runtimeInputs = [
      config.terminal.bash.package
      config.security.gopass.package
      config.security.gpg.package
      config.security.ssh.package
      pkgs.coreutils
    ];
    text =
      builtins.replaceStrings
        [
          "@@GOPASS_SSH_KEY@@"
          "@@GNUPGHOME@@"
        ]
        [
          config.security.ssh.sshKeyGopassPath
          config.home.sessionVariables.GNUPGHOME
        ]
        (builtins.readFile ./gpg-ssh-key-load.sh);
  };
in
{
  options.security.ssh = {
    enable = lib.mkEnableOption "Enables ssh via the gpg-agent.";
    package = lib.mkOption {
      type = lib.types.package;
      readOnly = true;
      default = pkgs.openssh;
      description = "The ssh package to use.";
    };

    sshKeyGopassPath = lib.mkOption {
      type = lib.types.nullOr lib.types.str;
      default = null;
      description = ''
        gopass entry holding the private SSH key. The key is loaded into the
        gpg-agent during home-manager switch so ssh works without a ~/.ssh
        directory.
      '';
    };
  };

  config = lib.mkMerge [
    (lib.mkIf config.security.ssh.enable {
      home.packages = [ config.security.ssh.package ];

      assertions = [
        {
          assertion = config.security.gpg.enable;
          message = ''
            Enabling `security.ssh` requires `security.gpg` so that
            gpg-agent can be used as the ssh-agent.
          '';
        }
      ];
    })

    (lib.mkIf (config.security.ssh.enable && config.security.ssh.sshKeyGopassPath != null) {
      home.activation.gpgSshKeyLoad = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
        run ${lib.getExe gpgSshKeyLoad} || true
      '';
    })
  ];
}