blob: ed93e27539d9aaedc82aa80cfab58c84b65caf09 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
|
# Secure shell client for encrypted remote connections
{
config,
lib,
pkgs,
...
}:
let
cfg = config.security.ssh;
gpgSshKeyLoad = pkgs.writeShellApplication {
name = "gpg-ssh-key-load";
runtimeInputs = [
config.terminal.bash.package
config.security.gopass.package
config.security.gpg.package
cfg.package
pkgs.coreutils
];
text =
builtins.replaceStrings
[
"@@GOPASS_SSH_KEY@@"
"@@GNUPGHOME@@"
]
[
cfg.ssh-key-gopass-secret
config.home.sessionVariables.GNUPGHOME
]
(builtins.readFile ./gpg-ssh-key-load.sh);
};
in
{
options.security.ssh = {
enable = lib.mkEnableOption "Enables ssh via the gpg-agent.";
package = lib.mkOption {
type = lib.types.package;
readOnly = true;
default = pkgs.openssh;
description = "The ssh package to use.";
};
ssh-key-gopass-secret = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = ''
gopass entry holding the private SSH key. The key is loaded into the
gpg-agent during home-manager switch so ssh works without a ~/.ssh
directory.
'';
};
};
config = lib.mkMerge [
(lib.mkIf cfg.enable {
home.packages = [ cfg.package ];
assertions = [
{
assertion = config.security.gpg.enable;
message = ''
Enabling `security.ssh` requires `security.gpg` so that
gpg-agent can be used as the ssh-agent.
'';
}
];
})
(lib.mkIf (cfg.enable && cfg.ssh-key-gopass-secret != null) {
home.activation.gpgSshKeyLoad = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
run ${lib.getExe gpgSshKeyLoad} || true
'';
})
];
}
|