From 75bbb51e1e2711ec8cbd0920cc6c9cae5d6f6521 Mon Sep 17 00:00:00 2001 From: moons14 Date: Fri, 31 Oct 2025 22:32:48 +0900 Subject: [PATCH 1/5] fix --- README.md | 3 +++ modules/core/ssh.nix | 16 +++++++--------- modules/home/ssh.nix | 30 +++++++++++++++++++++--------- 3 files changed, 31 insertions(+), 18 deletions(-) diff --git a/README.md b/README.md index 735e88f..5eb3e65 100644 --- a/README.md +++ b/README.md @@ -35,6 +35,9 @@ NixOS + Home Manager ## Declarative Defeat Necessary configurations not achievable with dotfiles +### Profile: cli-minimal +- SSH key registration + Please register the value of ~/.ssh/id_ed25519.pub on GitHub. ### Profile: laptop - Fingerprint registration Please register the user's fingerprints by running fprintd-enroll. diff --git a/modules/core/ssh.nix b/modules/core/ssh.nix index 11e4f1b..fa4ec5f 100644 --- a/modules/core/ssh.nix +++ b/modules/core/ssh.nix @@ -1,24 +1,22 @@ { inputs, pkgs, ... }: { - imports = [ inputs.auth-keys-hub.nixosModules.auth-keys-hub ]; - - programs.ssh.startAgent = true; + imports = [ + inputs.auth-keys-hub.nixosModules.auth-keys-hub + ]; services.openssh = { enable = true; openFirewall = true; settings = { - PermitRootLogin = "no"; # Prevent root from SSH login + PermitRootLogin = "no"; PasswordAuthentication = false; - KbdInteractiveAuthentication = true; + KbdInteractiveAuthentication = false; + PubkeyAuthentication = "yes"; }; - ports = [ 22 ]; }; programs.auth-keys-hub = { enable = true; - github = { - users = [ "moons-14:moons" ]; - }; + github.users = [ "moons-14:${username}" ]; }; } diff --git a/modules/home/ssh.nix b/modules/home/ssh.nix index 257ee12..01887df 100644 --- a/modules/home/ssh.nix +++ b/modules/home/ssh.nix @@ -3,25 +3,37 @@ home.packages = [ pkgs.openssh ]; + programs.ssh.startAgent = true; + home.activation.generateSshKey = lib.hm.dag.entryAfter [ "writeBoundary" ] '' key="$HOME/.ssh/id_ed25519" if [ ! -f "$key" ]; then umask 077 mkdir -p "$HOME/.ssh" - ssh-keygen -t ed25519 -N "" -f "$key" \ - -C "${config.home.username}@$(hostnamectl --static)" + ssh-keygen -t ed25519 -N "" -f "$key" -C "${config.home.username}@$(hostnamectl --static 2>/dev/null || echo host)" echo "Generated SSH key at $key" - echo "Public key:" - cat "$key.pub" fi ''; - services.ssh-agent.enable = true; - programs.gpg.enable = true; + home.file.".ssh/config".text = '' + Host * + AddKeysToAgent yes + IdentityFile ~/.ssh/id_ed25519 + ''; - - services.gpg-agent = { + programs.git = { enable = true; - enableSshSupport = true; + + signing = { + gpgFormat = "ssh"; + key = "~/.ssh/id_ed25519.pub"; + signByDefault = true; + }; + + extraConfig = { + gpg.format = "ssh"; + commit.gpgsign = true; + tag.gpgSign = true; + }; }; } From 2e404b4655dc33b28d1dc51f8db2b300e893d178 Mon Sep 17 00:00:00 2001 From: moons14 Date: Fri, 31 Oct 2025 22:35:09 +0900 Subject: [PATCH 2/5] fix --- modules/core/ssh.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/core/ssh.nix b/modules/core/ssh.nix index fa4ec5f..7204a5d 100644 --- a/modules/core/ssh.nix +++ b/modules/core/ssh.nix @@ -17,6 +17,6 @@ programs.auth-keys-hub = { enable = true; - github.users = [ "moons-14:${username}" ]; + github.users = [ "moons-14:moons" ]; }; } From df2c56a4a345cc0b9a6ff12e036f9edb747d2ead Mon Sep 17 00:00:00 2001 From: moons14 Date: Fri, 31 Oct 2025 22:47:41 +0900 Subject: [PATCH 3/5] fix --- modules/home/ssh.nix | 2 -- 1 file changed, 2 deletions(-) diff --git a/modules/home/ssh.nix b/modules/home/ssh.nix index 01887df..4f4067f 100644 --- a/modules/home/ssh.nix +++ b/modules/home/ssh.nix @@ -25,14 +25,12 @@ enable = true; signing = { - gpgFormat = "ssh"; key = "~/.ssh/id_ed25519.pub"; signByDefault = true; }; extraConfig = { gpg.format = "ssh"; - commit.gpgsign = true; tag.gpgSign = true; }; }; From a457670d25ffe1f54850ed79628717013b833ab2 Mon Sep 17 00:00:00 2001 From: moons14 Date: Fri, 31 Oct 2025 22:48:49 +0900 Subject: [PATCH 4/5] fix --- modules/home/ssh.nix | 2 -- 1 file changed, 2 deletions(-) diff --git a/modules/home/ssh.nix b/modules/home/ssh.nix index 4f4067f..6c89093 100644 --- a/modules/home/ssh.nix +++ b/modules/home/ssh.nix @@ -3,8 +3,6 @@ home.packages = [ pkgs.openssh ]; - programs.ssh.startAgent = true; - home.activation.generateSshKey = lib.hm.dag.entryAfter [ "writeBoundary" ] '' key="$HOME/.ssh/id_ed25519" if [ ! -f "$key" ]; then From 5cfacfb168e4742a68570ef0bafd8fdd54dde478 Mon Sep 17 00:00:00 2001 From: moons14 Date: Fri, 31 Oct 2025 22:56:27 +0900 Subject: [PATCH 5/5] fix --- flake.nix | 1 - modules/core/ssh.nix | 9 +-------- modules/home/ssh.nix | 2 +- 3 files changed, 2 insertions(+), 10 deletions(-) diff --git a/flake.nix b/flake.nix index 243a94a..a99b0d2 100644 --- a/flake.nix +++ b/flake.nix @@ -13,7 +13,6 @@ vicinae.url = "github:vicinaehq/vicinae"; ghostty.url = "github:ghostty-org/ghostty"; - auth-keys-hub.url = "github:input-output-hk/auth-keys-hub"; quickshell = { url = "github:outfoxxed/quickshell"; diff --git a/modules/core/ssh.nix b/modules/core/ssh.nix index 7204a5d..8a2a383 100644 --- a/modules/core/ssh.nix +++ b/modules/core/ssh.nix @@ -1,8 +1,5 @@ -{ inputs, pkgs, ... }: +{ pkgs, ... }: { - imports = [ - inputs.auth-keys-hub.nixosModules.auth-keys-hub - ]; services.openssh = { enable = true; @@ -15,8 +12,4 @@ }; }; - programs.auth-keys-hub = { - enable = true; - github.users = [ "moons-14:moons" ]; - }; } diff --git a/modules/home/ssh.nix b/modules/home/ssh.nix index 6c89093..6cfaf48 100644 --- a/modules/home/ssh.nix +++ b/modules/home/ssh.nix @@ -8,7 +8,7 @@ if [ ! -f "$key" ]; then umask 077 mkdir -p "$HOME/.ssh" - ssh-keygen -t ed25519 -N "" -f "$key" -C "${config.home.username}@$(hostnamectl --static 2>/dev/null || echo host)" + ssh-keygen -t ed25519 -N "" -f "$key" -C "moons@$(hostnamectl --static 2>/dev/null || echo host)" echo "Generated SSH key at $key" fi '';