From 75bbb51e1e2711ec8cbd0920cc6c9cae5d6f6521 Mon Sep 17 00:00:00 2001 From: moons14 Date: Fri, 31 Oct 2025 22:32:48 +0900 Subject: [PATCH] fix --- README.md | 3 +++ modules/core/ssh.nix | 16 +++++++--------- modules/home/ssh.nix | 30 +++++++++++++++++++++--------- 3 files changed, 31 insertions(+), 18 deletions(-) diff --git a/README.md b/README.md index 735e88f..5eb3e65 100644 --- a/README.md +++ b/README.md @@ -35,6 +35,9 @@ NixOS + Home Manager ## Declarative Defeat Necessary configurations not achievable with dotfiles +### Profile: cli-minimal +- SSH key registration + Please register the value of ~/.ssh/id_ed25519.pub on GitHub. ### Profile: laptop - Fingerprint registration Please register the user's fingerprints by running fprintd-enroll. diff --git a/modules/core/ssh.nix b/modules/core/ssh.nix index 11e4f1b..fa4ec5f 100644 --- a/modules/core/ssh.nix +++ b/modules/core/ssh.nix @@ -1,24 +1,22 @@ { inputs, pkgs, ... }: { - imports = [ inputs.auth-keys-hub.nixosModules.auth-keys-hub ]; - - programs.ssh.startAgent = true; + imports = [ + inputs.auth-keys-hub.nixosModules.auth-keys-hub + ]; services.openssh = { enable = true; openFirewall = true; settings = { - PermitRootLogin = "no"; # Prevent root from SSH login + PermitRootLogin = "no"; PasswordAuthentication = false; - KbdInteractiveAuthentication = true; + KbdInteractiveAuthentication = false; + PubkeyAuthentication = "yes"; }; - ports = [ 22 ]; }; programs.auth-keys-hub = { enable = true; - github = { - users = [ "moons-14:moons" ]; - }; + github.users = [ "moons-14:${username}" ]; }; } diff --git a/modules/home/ssh.nix b/modules/home/ssh.nix index 257ee12..01887df 100644 --- a/modules/home/ssh.nix +++ b/modules/home/ssh.nix @@ -3,25 +3,37 @@ home.packages = [ pkgs.openssh ]; + programs.ssh.startAgent = true; + home.activation.generateSshKey = lib.hm.dag.entryAfter [ "writeBoundary" ] '' key="$HOME/.ssh/id_ed25519" if [ ! -f "$key" ]; then umask 077 mkdir -p "$HOME/.ssh" - ssh-keygen -t ed25519 -N "" -f "$key" \ - -C "${config.home.username}@$(hostnamectl --static)" + ssh-keygen -t ed25519 -N "" -f "$key" -C "${config.home.username}@$(hostnamectl --static 2>/dev/null || echo host)" echo "Generated SSH key at $key" - echo "Public key:" - cat "$key.pub" fi ''; - services.ssh-agent.enable = true; - programs.gpg.enable = true; + home.file.".ssh/config".text = '' + Host * + AddKeysToAgent yes + IdentityFile ~/.ssh/id_ed25519 + ''; - - services.gpg-agent = { + programs.git = { enable = true; - enableSshSupport = true; + + signing = { + gpgFormat = "ssh"; + key = "~/.ssh/id_ed25519.pub"; + signByDefault = true; + }; + + extraConfig = { + gpg.format = "ssh"; + commit.gpgsign = true; + tag.gpgSign = true; + }; }; }