diff options
Diffstat (limited to 'modules/ssh.nix')
| -rw-r--r-- | modules/ssh.nix | 95 |
1 files changed, 95 insertions, 0 deletions
diff --git a/modules/ssh.nix b/modules/ssh.nix new file mode 100644 index 0000000..63b2034 --- /dev/null +++ b/modules/ssh.nix @@ -0,0 +1,95 @@ +{ + config, + lib, + username, + ... +}: +let + cfg = config.os.srv.ssh; + keys.main = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC610CJfgc3yII7MpLVqzEzQGa8Tsm+dih+CTXHXTnv4"; +in +{ + options.os.srv.ssh = { + server.enable = lib.mkEnableOption "enables the ssh server module"; + client = { + enable = lib.mkEnableOption "enables the ssh client module"; + createAliases = lib.mkEnableOption "enables system-wide SSH shortcuts"; + }; + enableSigning = lib.mkEnableOption "enables signing git commits with ssh keys"; + }; + + config = lib.mkMerge [ + (lib.mkIf cfg.server.enable { + services.openssh = { + enable = true; + + listenAddresses = [ + { + addr = "127.0.0.1"; + port = 22; + } + ] + ++ lib.optional (config.os.core.network ? lan.ip) { + addr = config.os.core.network.lan.ip; + port = 22; + } + ++ lib.optional (config.os.core.network ? wg.ip) { + addr = config.os.core.network.wg.ip; + port = 22; + } + ++ lib.optional (config.os.core.network ? hs.ip) { + addr = config.os.core.network.hs.ip; + port = 22; + }; + hostKeys = [ + { + path = "/etc/ssh/ssh_host_ed25519_key"; + type = "ed25519"; + } + ]; + settings = { + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + PermitRootLogin = "no"; + + PubkeyAcceptedAlgorithms = "ssh-ed25519"; + }; + }; + + users.users = ( + lib.optionalAttrs (username != "" && username != null) { + ${username}.openssh.authorizedKeys.keys = [ + "${keys.main} adikro@disroot.org" + ]; + } + ); + }) + + (lib.mkIf cfg.client.enable { + programs.ssh.startAgent = true; + services.gnome.gcr-ssh-agent.enable = false; + }) + + (lib.mkIf (cfg.client.enable && cfg.client.createAliases) { + # TODO use hjem + programs.ssh.extraConfig = '' + Host github.com codeberg.org + IdentityFile /home/${username}/.ssh/main_id_ed25519.pub + IdentitiesOnly yes + User git + + Host oci + HostName 130.162.223.123 + User opc + ''; + systemd.tmpfiles.rules = [ + "d /home/${username}/.ssh 0700 ${username} users - -" + "f /home/${username}/.ssh/main_id_ed25519.pub 0644 ${username} users - ${keys.main}" + ]; + }) + + (lib.mkIf cfg.enableSigning { + environment.etc."ssh/allowed_signers".text = "adikro@disroot.org ${keys.main}"; + }) + ]; +} |
