{ config, lib, username, ... }: let cfg = config.os.srv.ssh; keys.main = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC610CJfgc3yII7MpLVqzEzQGa8Tsm+dih+CTXHXTnv4"; in { options.os.srv.ssh = { server = { enable = lib.mkEnableOption "enables the ssh server module"; enableInitrd = lib.mkEnableOption "enables ssh access during initrd"; microvm.enable = lib.mkEnableOption "enables ssh for microvms"; }; client = { enable = lib.mkEnableOption "enables the ssh client module"; createAliases = lib.mkEnableOption "enables system-wide SSH shortcuts"; }; enableSigning = lib.mkEnableOption "enables signing git commits with ssh keys"; }; config = lib.mkMerge [ (lib.mkIf cfg.server.enable { services.openssh = { enable = true; listenAddresses = [ { addr = "127.0.0.1"; port = 22; } { addr = config.os.core.network.lan.ip; port = 22; } { addr = config.os.core.network.wg.ip; port = 22; } { addr = config.os.core.network.hs.ip; port = 22; } ]; hostKeys = [ { path = "/etc/ssh/ssh_host_ed25519_key"; type = "ed25519"; } ]; settings = { PasswordAuthentication = false; KbdInteractiveAuthentication = false; PermitRootLogin = if cfg.server.microvm.enable then "prohibit-password" else "no"; PubkeyAcceptedAlgorithms = "ssh-ed25519"; }; }; users.users = ( lib.optionalAttrs (username != "" && username != null) { ${username}.openssh.authorizedKeys.keys = [ "${keys.main} adikro@disroot.org" ]; } ); }) (lib.mkIf (cfg.server.enable && cfg.server.microvm.enable) { users.users.root.openssh.authorizedKeys.keys = [ "${keys.main} adikro@disroot.org" ]; }) (lib.mkIf (cfg.server.enable && cfg.server.enableInitrd) { assertions = [ { assertion = config.os.srv.sops.enable; message = "required for storing the ssh key"; } ]; sops.secrets."initrd_ssh_key" = { path = "/etc/secrets/initrd/ssh_host_ed25519_key"; }; boot = { initrd = { secrets = { "/etc/secrets/initrd/ssh_host_ed25519_key" = config.sops.secrets.initrd_ssh_key.path; }; network = { enable = true; ssh = { enable = true; port = 2222; authorizedKeys = [ "${keys.main}" ]; hostKeys = [ "/etc/secrets/initrd/ssh_host_ed25519_key" ]; }; }; }; kernelParams = [ "ip=dhcp" ]; }; }) (lib.mkIf cfg.client.enable { programs.ssh.startAgent = true; services.gnome.gcr-ssh-agent.enable = false; }) (lib.mkIf (cfg.client.enable && cfg.client.createAliases) { # TODO use hjem programs.ssh.extraConfig = '' Host github.com codeberg.org IdentityFile /home/${username}/.ssh/main_id_ed25519.pub IdentitiesOnly yes User git Host oci HostName 130.162.223.123 User opc ''; systemd.tmpfiles.rules = [ "d /home/${username}/.ssh 0700 ${username} users - -" "f /home/${username}/.ssh/main_id_ed25519.pub 0644 ${username} users - ${keys.main}" ]; }) (lib.mkIf cfg.enableSigning { environment.etc."ssh/allowed_signers".text = "adikro@disroot.org ${keys.main}"; }) ]; }