blob: d36df00323f527c73ca082417fe8a5ccc6d2b71b (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
|
{
config,
lib,
username,
...
}:
let
cfg = config.os.srv.ssh;
keys.main = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC610CJfgc3yII7MpLVqzEzQGa8Tsm+dih+CTXHXTnv4";
in
{
options.os.srv.ssh = {
server = {
enable = lib.mkEnableOption "enables the ssh server module";
enableInitrd = lib.mkEnableOption "enables ssh access during initrd";
microvm.enable = lib.mkEnableOption "enables ssh for microvms";
};
client = {
enable = lib.mkEnableOption "enables the ssh client module";
createAliases = lib.mkEnableOption "enables system-wide SSH shortcuts";
};
enableSigning = lib.mkEnableOption "enables signing git commits with ssh keys";
};
config = lib.mkMerge [
(lib.mkIf cfg.server.enable {
services.openssh = {
enable = true;
listenAddresses = [
{
addr = "127.0.0.1";
port = 22;
}
{
addr = config.os.core.network.lan.ip;
port = 22;
}
{
addr = config.os.core.network.wg.ip;
port = 22;
}
{
addr = config.os.core.network.hs.ip;
port = 22;
}
];
hostKeys = [
{
path = "/etc/ssh/ssh_host_ed25519_key";
type = "ed25519";
}
];
settings = {
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;
PermitRootLogin = if cfg.server.microvm.enable then "prohibit-password" else "no";
PubkeyAcceptedAlgorithms = "ssh-ed25519";
};
};
users.users = (
lib.optionalAttrs (username != "" && username != null) {
${username}.openssh.authorizedKeys.keys = [
"${keys.main} adikro@disroot.org"
];
}
);
})
(lib.mkIf (cfg.server.enable && cfg.server.microvm.enable) {
users.users.root.openssh.authorizedKeys.keys = [
"${keys.main} adikro@disroot.org"
];
})
(lib.mkIf (cfg.server.enable && cfg.server.enableInitrd) {
assertions = [
{
assertion = config.os.srv.sops.enable;
message = "required for storing the ssh key";
}
];
sops.secrets."initrd_ssh_key" = {
path = "/etc/secrets/initrd/ssh_host_ed25519_key";
};
boot = {
initrd = {
secrets = {
"/etc/secrets/initrd/ssh_host_ed25519_key" = config.sops.secrets.initrd_ssh_key.path;
};
network = {
enable = true;
ssh = {
enable = true;
port = 2222;
authorizedKeys = [ "${keys.main}" ];
hostKeys = [ "/etc/secrets/initrd/ssh_host_ed25519_key" ];
};
};
};
kernelParams = [ "ip=dhcp" ];
};
})
(lib.mkIf cfg.client.enable {
programs.ssh.startAgent = true;
services.gnome.gcr-ssh-agent.enable = false;
})
(lib.mkIf (cfg.client.enable && cfg.client.createAliases) {
# TODO use hjem
programs.ssh.extraConfig = ''
Host github.com codeberg.org
IdentityFile /home/${username}/.ssh/main_id_ed25519.pub
IdentitiesOnly yes
User git
Host oci
HostName 130.162.223.123
User opc
'';
systemd.tmpfiles.rules = [
"d /home/${username}/.ssh 0700 ${username} users - -"
"f /home/${username}/.ssh/main_id_ed25519.pub 0644 ${username} users - ${keys.main}"
];
})
(lib.mkIf cfg.enableSigning {
environment.etc."ssh/allowed_signers".text = "adikro@disroot.org ${keys.main}";
})
];
}
|