1password

This commit is contained in:
2026-06-26 17:50:34 +09:00
parent 4f59060cce
commit bb827d9ace
9 changed files with 83 additions and 53 deletions
-27
View File
@@ -14,33 +14,6 @@ in
options.my.applications.ssh = {
enable = lib.mkEnableOption "OpenSSH client";
defaultIdentityFile = lib.mkOption {
type = lib.types.str;
default = "~/.ssh/id_ed25519";
description = "Default SSH identity file";
};
addKeysToAgent = lib.mkOption {
type = lib.types.str;
default = "no";
description = "Add keys to SSH agent";
};
matchBlocks = lib.mkOption {
type = lib.types.attrs;
default = { };
description = "SSH match blocks";
};
githubIdentityFiles = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [
"~/.ssh/id_ed25519_sk_rk"
"~/.ssh/id_ed25519"
];
description = "SSH identity files for GitHub (tried in order)";
};
};
config = lib.mkIf cfg.enable {
+17 -11
View File
@@ -5,12 +5,17 @@
...
}:
let
cfg = config.my.applications.ssh;
hmCfg = config.my.applications.ssh.homeManager;
in
{
options.my.applications.ssh.homeManager = {
enable = lib.mkEnableOption "SSH home-manager configuration";
matchBlocks = lib.mkOption {
type = lib.types.attrs;
default = { };
description = "SSH match blocks";
};
};
config.home-manager.sharedModules = [
@@ -22,30 +27,31 @@ in
systemd.user.sockets.gcr-ssh-agent.Install.WantedBy = lib.mkForce [ ];
services.ssh-agent.enable = true;
home.sessionVariables = {
SSH_AUTH_SOCK = "\${XDG_RUNTIME_DIR}/ssh-agent";
};
services.ssh-agent.enable = lib.mkForce false;
programs.ssh = {
enable = true;
enableDefaultConfig = false;
settings = cfg.matchBlocks // {
settings = hmCfg.matchBlocks // {
"github.com" = {
IdentityFile = cfg.githubIdentityFiles;
AddKeysToAgent = cfg.addKeysToAgent;
HostName = "github.com";
User = "git";
AddKeysToAgent = "no";
};
"*" = {
IdentityFile = cfg.defaultIdentityFile;
AddKeysToAgent = cfg.addKeysToAgent;
AddKeysToAgent = "no";
SetEnv = {
TERM = "xterm-256color";
};
};
};
extraConfig = ''
Match exec "test -S %d/.1password/agent.sock"
IdentityAgent %d/.1password/agent.sock
'';
};
};
}