1password

This commit is contained in:
2026-06-26 17:50:34 +09:00
parent 4f59060cce
commit bb827d9ace
9 changed files with 83 additions and 53 deletions
-4
View File
@@ -7,8 +7,4 @@
boot.initrd.luks.devices.cryptroot.device = boot.initrd.luks.devices.cryptroot.device =
"/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e"; "/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e";
my.applications.git.homeManager = {
signingKey = "~/.ssh/id_ed25519_sk_rk.pub";
};
} }
+5
View File
@@ -17,5 +17,10 @@ in
enable = true; enable = true;
polkitPolicyOwners = [ "moons" ]; polkitPolicyOwners = [ "moons" ];
}; };
programs.ssh.startAgent = lib.mkForce false;
programs.gnupg.agent.enableSSHSupport = lib.mkForce false;
services.gnome.gcr-ssh-agent.enable = lib.mkForce false;
}; };
} }
+7 -5
View File
@@ -14,15 +14,17 @@ in
options.my.applications.git = { options.my.applications.git = {
enable = lib.mkEnableOption "git version control"; enable = lib.mkEnableOption "git version control";
userName = lib.mkOption { userName = lib.mkOption {
type = lib.types.str; type = lib.types.singleLineStr;
default = "moons-14"; default = "moons";
description = "Git user name"; description = "Default Git user.name.";
}; };
userEmail = lib.mkOption { userEmail = lib.mkOption {
type = lib.types.str; type = lib.types.singleLineStr;
default = "moons@moons14.com"; default = "moons@moons14.com";
description = "Git user email"; description = "Default Git user.email.";
}; };
}; };
+44 -6
View File
@@ -1,4 +1,5 @@
{ {
pkgs,
lib, lib,
config, config,
... ...
@@ -6,15 +7,48 @@
let let
cfg = config.my.applications.git; cfg = config.my.applications.git;
hmCfg = config.my.applications.git.homeManager; hmCfg = config.my.applications.git.homeManager;
signingKeyPath = ".ssh/1password-git-signing.pub";
signingKeyFile = "~/${signingKeyPath}";
gitSshSign = pkgs.writeShellScript "git-ssh-sign" ''
one_password_sock="$HOME/.1password/agent.sock"
if { [ -n "''${SSH_CONNECTION:-}" ] || [ -n "''${SSH_CLIENT:-}" ]; } \
&& [ -n "''${SSH_AUTH_SOCK:-}" ] \
&& [ -S "$SSH_AUTH_SOCK" ]; then
exec ${pkgs.openssh}/bin/ssh-keygen "$@"
fi
if [ -S "$one_password_sock" ]; then
export SSH_AUTH_SOCK="$one_password_sock"
exec ${pkgs.openssh}/bin/ssh-keygen "$@"
fi
if [ -n "''${SSH_AUTH_SOCK:-}" ] && [ -S "$SSH_AUTH_SOCK" ]; then
exec ${pkgs.openssh}/bin/ssh-keygen "$@"
fi
echo "git ssh signing failed: no forwarded SSH agent or 1Password agent socket found" >&2
echo "expected: forwarded SSH_AUTH_SOCK or $one_password_sock" >&2
exit 1
'';
in in
{ {
options.my.applications.git.homeManager = { options.my.applications.git.homeManager = {
enable = lib.mkEnableOption "git home-manager configuration"; enable = lib.mkEnableOption "git home-manager configuration";
signingPublicKey = lib.mkOption {
type = lib.types.nullOr lib.types.singleLineStr;
default = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPLwReAiwhXoO34S2+MrvqUhi8IWp4IzUq4OSp3niJdq 1password-git-signing";
example = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPLwReAiwhXoO34S2+MrvqUhi8IWp4IzUq4OSp3niJdq 1password-git-signing";
description = "SSH public key copied from the 1Password SSH key item used for Git signing.";
};
signingKey = lib.mkOption { signingKey = lib.mkOption {
type = lib.types.nullOr lib.types.str; type = lib.types.str;
default = "~/.ssh/id_ed25519_sk_rk.pub"; default = signingKeyFile;
example = "~/.ssh/id_ed25519.pub"; readOnly = true;
description = "SSH public key path used for Git commit and tag signing."; description = "SSH public key path used for Git commit and tag signing.";
}; };
}; };
@@ -22,13 +56,15 @@ in
config = lib.mkIf hmCfg.enable { config = lib.mkIf hmCfg.enable {
assertions = [ assertions = [
{ {
assertion = hmCfg.signingKey != null; assertion = hmCfg.signingPublicKey != null && hmCfg.signingPublicKey != "";
message = "my.applications.git.homeManager.signingKey must be set per host."; message = "my.applications.git.homeManager.signingPublicKey must be set to the public key copied from 1Password.";
} }
]; ];
home-manager.sharedModules = [ home-manager.sharedModules = [
{ {
home.file.${signingKeyPath}.text = hmCfg.signingPublicKey + "\n";
programs.git = { programs.git = {
enable = true; enable = true;
@@ -44,7 +80,7 @@ in
signByDefault = true; signByDefault = true;
}; };
settings = { extraConfig = {
user.name = cfg.userName; user.name = cfg.userName;
user.email = cfg.userEmail; user.email = cfg.userEmail;
@@ -55,6 +91,8 @@ in
log.date = "iso"; log.date = "iso";
merge.conflictStyle = "diff3"; merge.conflictStyle = "diff3";
gpg.ssh.program = "${gitSshSign}";
alias = { alias = {
br = "branch --sort=-committerdate"; br = "branch --sort=-committerdate";
co = "checkout"; co = "checkout";
+5
View File
@@ -48,6 +48,11 @@ in
spawn-at-startup = [ spawn-at-startup = [
{ command = [ "noctalia-shell" ]; } { command = [ "noctalia-shell" ]; }
{
command = [
"${pkgs.polkit_gnome}/libexec/polkit-gnome-authentication-agent-1"
];
}
]; ];
cursor.size = 16; cursor.size = 16;
+1
View File
@@ -18,6 +18,7 @@ in
environment.systemPackages = with pkgs; [ environment.systemPackages = with pkgs; [
wdisplays # Wayland display configuration GUI wdisplays # Wayland display configuration GUI
wlr-randr # Wayland output management CLI wlr-randr # Wayland output management CLI
polkit_gnome # Polkit authentication agent for GNOME
]; ];
}; };
} }
-27
View File
@@ -14,33 +14,6 @@ in
options.my.applications.ssh = { options.my.applications.ssh = {
enable = lib.mkEnableOption "OpenSSH client"; enable = lib.mkEnableOption "OpenSSH client";
defaultIdentityFile = lib.mkOption {
type = lib.types.str;
default = "~/.ssh/id_ed25519";
description = "Default SSH identity file";
};
addKeysToAgent = lib.mkOption {
type = lib.types.str;
default = "no";
description = "Add keys to SSH agent";
};
matchBlocks = lib.mkOption {
type = lib.types.attrs;
default = { };
description = "SSH match blocks";
};
githubIdentityFiles = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [
"~/.ssh/id_ed25519_sk_rk"
"~/.ssh/id_ed25519"
];
description = "SSH identity files for GitHub (tried in order)";
};
}; };
config = lib.mkIf cfg.enable { config = lib.mkIf cfg.enable {
+17 -11
View File
@@ -5,12 +5,17 @@
... ...
}: }:
let let
cfg = config.my.applications.ssh;
hmCfg = config.my.applications.ssh.homeManager; hmCfg = config.my.applications.ssh.homeManager;
in in
{ {
options.my.applications.ssh.homeManager = { options.my.applications.ssh.homeManager = {
enable = lib.mkEnableOption "SSH home-manager configuration"; enable = lib.mkEnableOption "SSH home-manager configuration";
matchBlocks = lib.mkOption {
type = lib.types.attrs;
default = { };
description = "SSH match blocks";
};
}; };
config.home-manager.sharedModules = [ config.home-manager.sharedModules = [
@@ -22,30 +27,31 @@ in
systemd.user.sockets.gcr-ssh-agent.Install.WantedBy = lib.mkForce [ ]; systemd.user.sockets.gcr-ssh-agent.Install.WantedBy = lib.mkForce [ ];
services.ssh-agent.enable = true; services.ssh-agent.enable = lib.mkForce false;
home.sessionVariables = {
SSH_AUTH_SOCK = "\${XDG_RUNTIME_DIR}/ssh-agent";
};
programs.ssh = { programs.ssh = {
enable = true; enable = true;
enableDefaultConfig = false; enableDefaultConfig = false;
settings = cfg.matchBlocks // { settings = hmCfg.matchBlocks // {
"github.com" = { "github.com" = {
IdentityFile = cfg.githubIdentityFiles; HostName = "github.com";
AddKeysToAgent = cfg.addKeysToAgent; User = "git";
AddKeysToAgent = "no";
}; };
"*" = { "*" = {
IdentityFile = cfg.defaultIdentityFile; AddKeysToAgent = "no";
AddKeysToAgent = cfg.addKeysToAgent;
SetEnv = { SetEnv = {
TERM = "xterm-256color"; TERM = "xterm-256color";
}; };
}; };
}; };
extraConfig = ''
Match exec "test -S %d/.1password/agent.sock"
IdentityAgent %d/.1password/agent.sock
'';
}; };
}; };
} }
+4
View File
@@ -14,6 +14,10 @@ in
config = lib.mkIf cfg.enable { config = lib.mkIf cfg.enable {
services.fprintd.enable = true; services.fprintd.enable = true;
security.polkit.enable = true;
security.pam.services.polkit-1.fprintAuth = true;
security.pam.services = { security.pam.services = {
login.fprintAuth = true; login.fprintAuth = true;
sudo.fprintAuth = true; sudo.fprintAuth = true;