summaryrefslogtreecommitdiff
path: root/os/srv/ssh.nix
blob: 63b2034372cbc076dfff5b08fba8d70aadc4106d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
{
  config,
  lib,
  username,
  ...
}:
let
  cfg = config.os.srv.ssh;
  keys.main = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC610CJfgc3yII7MpLVqzEzQGa8Tsm+dih+CTXHXTnv4";
in
{
  options.os.srv.ssh = {
    server.enable = lib.mkEnableOption "enables the ssh server module";
    client = {
      enable = lib.mkEnableOption "enables the ssh client module";
      createAliases = lib.mkEnableOption "enables system-wide SSH shortcuts";
    };
    enableSigning = lib.mkEnableOption "enables signing git commits with ssh keys";
  };

  config = lib.mkMerge [
    (lib.mkIf cfg.server.enable {
      services.openssh = {
        enable = true;

        listenAddresses = [
          {
            addr = "127.0.0.1";
            port = 22;
          }
        ]
        ++ lib.optional (config.os.core.network ? lan.ip) {
          addr = config.os.core.network.lan.ip;
          port = 22;
        }
        ++ lib.optional (config.os.core.network ? wg.ip) {
          addr = config.os.core.network.wg.ip;
          port = 22;
        }
        ++ lib.optional (config.os.core.network ? hs.ip) {
          addr = config.os.core.network.hs.ip;
          port = 22;
        };
        hostKeys = [
          {
            path = "/etc/ssh/ssh_host_ed25519_key";
            type = "ed25519";
          }
        ];
        settings = {
          PasswordAuthentication = false;
          KbdInteractiveAuthentication = false;
          PermitRootLogin = "no";

          PubkeyAcceptedAlgorithms = "ssh-ed25519";
        };
      };

      users.users = (
        lib.optionalAttrs (username != "" && username != null) {
          ${username}.openssh.authorizedKeys.keys = [
            "${keys.main} adikro@disroot.org"
          ];
        }
      );
    })

    (lib.mkIf cfg.client.enable {
      programs.ssh.startAgent = true;
      services.gnome.gcr-ssh-agent.enable = false;
    })

    (lib.mkIf (cfg.client.enable && cfg.client.createAliases) {
      # TODO use hjem
      programs.ssh.extraConfig = ''
        Host github.com codeberg.org
          IdentityFile /home/${username}/.ssh/main_id_ed25519.pub
          IdentitiesOnly yes
          User git

        Host oci
          HostName 130.162.223.123
          User opc
      '';
      systemd.tmpfiles.rules = [
        "d /home/${username}/.ssh 0700 ${username} users - -"
        "f /home/${username}/.ssh/main_id_ed25519.pub 0644 ${username} users - ${keys.main}"
      ];
    })

    (lib.mkIf cfg.enableSigning {
      environment.etc."ssh/allowed_signers".text = "adikro@disroot.org ${keys.main}";
    })
  ];
}