This commit is contained in:
2025-10-31 22:32:48 +09:00
parent c341059747
commit 75bbb51e1e
3 changed files with 31 additions and 18 deletions
+3
View File
@@ -35,6 +35,9 @@ NixOS + Home Manager
## Declarative Defeat ## Declarative Defeat
Necessary configurations not achievable with dotfiles Necessary configurations not achievable with dotfiles
### Profile: cli-minimal
- SSH key registration
Please register the value of ~/.ssh/id_ed25519.pub on GitHub.
### Profile: laptop ### Profile: laptop
- Fingerprint registration - Fingerprint registration
Please register the user's fingerprints by running fprintd-enroll. Please register the user's fingerprints by running fprintd-enroll.
+7 -9
View File
@@ -1,24 +1,22 @@
{ inputs, pkgs, ... }: { inputs, pkgs, ... }:
{ {
imports = [ inputs.auth-keys-hub.nixosModules.auth-keys-hub ]; imports = [
inputs.auth-keys-hub.nixosModules.auth-keys-hub
programs.ssh.startAgent = true; ];
services.openssh = { services.openssh = {
enable = true; enable = true;
openFirewall = true; openFirewall = true;
settings = { settings = {
PermitRootLogin = "no"; # Prevent root from SSH login PermitRootLogin = "no";
PasswordAuthentication = false; PasswordAuthentication = false;
KbdInteractiveAuthentication = true; KbdInteractiveAuthentication = false;
PubkeyAuthentication = "yes";
}; };
ports = [ 22 ];
}; };
programs.auth-keys-hub = { programs.auth-keys-hub = {
enable = true; enable = true;
github = { github.users = [ "moons-14:${username}" ];
users = [ "moons-14:moons" ];
};
}; };
} }
+21 -9
View File
@@ -3,25 +3,37 @@
home.packages = [ pkgs.openssh ]; home.packages = [ pkgs.openssh ];
programs.ssh.startAgent = true;
home.activation.generateSshKey = lib.hm.dag.entryAfter [ "writeBoundary" ] '' home.activation.generateSshKey = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
key="$HOME/.ssh/id_ed25519" key="$HOME/.ssh/id_ed25519"
if [ ! -f "$key" ]; then if [ ! -f "$key" ]; then
umask 077 umask 077
mkdir -p "$HOME/.ssh" mkdir -p "$HOME/.ssh"
ssh-keygen -t ed25519 -N "" -f "$key" \ ssh-keygen -t ed25519 -N "" -f "$key" -C "${config.home.username}@$(hostnamectl --static 2>/dev/null || echo host)"
-C "${config.home.username}@$(hostnamectl --static)"
echo "Generated SSH key at $key" echo "Generated SSH key at $key"
echo "Public key:"
cat "$key.pub"
fi fi
''; '';
services.ssh-agent.enable = true; home.file.".ssh/config".text = ''
programs.gpg.enable = true; Host *
AddKeysToAgent yes
IdentityFile ~/.ssh/id_ed25519
'';
programs.git = {
services.gpg-agent = {
enable = true; enable = true;
enableSshSupport = true;
signing = {
gpgFormat = "ssh";
key = "~/.ssh/id_ed25519.pub";
signByDefault = true;
};
extraConfig = {
gpg.format = "ssh";
commit.gpgsign = true;
tag.gpgSign = true;
};
}; };
} }