This commit is contained in:
2025-10-31 22:32:48 +09:00
parent c341059747
commit 75bbb51e1e
3 changed files with 31 additions and 18 deletions
+7 -9
View File
@@ -1,24 +1,22 @@
{ inputs, pkgs, ... }:
{
imports = [ inputs.auth-keys-hub.nixosModules.auth-keys-hub ];
programs.ssh.startAgent = true;
imports = [
inputs.auth-keys-hub.nixosModules.auth-keys-hub
];
services.openssh = {
enable = true;
openFirewall = true;
settings = {
PermitRootLogin = "no"; # Prevent root from SSH login
PermitRootLogin = "no";
PasswordAuthentication = false;
KbdInteractiveAuthentication = true;
KbdInteractiveAuthentication = false;
PubkeyAuthentication = "yes";
};
ports = [ 22 ];
};
programs.auth-keys-hub = {
enable = true;
github = {
users = [ "moons-14:moons" ];
};
github.users = [ "moons-14:${username}" ];
};
}
+21 -9
View File
@@ -3,25 +3,37 @@
home.packages = [ pkgs.openssh ];
programs.ssh.startAgent = true;
home.activation.generateSshKey = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
key="$HOME/.ssh/id_ed25519"
if [ ! -f "$key" ]; then
umask 077
mkdir -p "$HOME/.ssh"
ssh-keygen -t ed25519 -N "" -f "$key" \
-C "${config.home.username}@$(hostnamectl --static)"
ssh-keygen -t ed25519 -N "" -f "$key" -C "${config.home.username}@$(hostnamectl --static 2>/dev/null || echo host)"
echo "Generated SSH key at $key"
echo "Public key:"
cat "$key.pub"
fi
'';
services.ssh-agent.enable = true;
programs.gpg.enable = true;
home.file.".ssh/config".text = ''
Host *
AddKeysToAgent yes
IdentityFile ~/.ssh/id_ed25519
'';
services.gpg-agent = {
programs.git = {
enable = true;
enableSshSupport = true;
signing = {
gpgFormat = "ssh";
key = "~/.ssh/id_ed25519.pub";
signByDefault = true;
};
extraConfig = {
gpg.format = "ssh";
commit.gpgsign = true;
tag.gpgSign = true;
};
};
}