2023-10-13 21:04:24 +02:00
|
|
|
{
|
|
|
|
config,
|
|
|
|
lib,
|
|
|
|
pkgs,
|
|
|
|
...
|
|
|
|
}: with lib; let
|
|
|
|
cfg = config.myOptions.services.ssh;
|
|
|
|
in {
|
|
|
|
options.myOptions.services.ssh = {
|
|
|
|
daemon = mkOption {
|
|
|
|
description = "sshd options";
|
|
|
|
type = with types; submodule {
|
|
|
|
options = {
|
2024-04-05 22:59:32 +02:00
|
|
|
enable = mkEnableOption "sshd";
|
2023-10-13 21:04:24 +02:00
|
|
|
passwordAuth = mkOption {
|
|
|
|
description = "allow password auth";
|
|
|
|
default = false;
|
|
|
|
type = bool;
|
|
|
|
};
|
|
|
|
allowRoot = mkOption {
|
|
|
|
description = "allow root login";
|
|
|
|
default = false;
|
|
|
|
type = bool;
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
agent = mkOption {
|
|
|
|
description = "ssh agent options";
|
|
|
|
type = with types; submodule {
|
|
|
|
options = {
|
2024-04-05 22:59:32 +02:00
|
|
|
enable = mkEnableOption "ssh-agent";
|
2023-10-13 21:04:24 +02:00
|
|
|
hostAliases = mkOption {
|
|
|
|
description = "host aliases";
|
|
|
|
type = with types; attrsOf (submodule {
|
|
|
|
options = {
|
|
|
|
hostName = mkOption {
|
|
|
|
description = "hostname to ssh into";
|
|
|
|
type = types.str;
|
|
|
|
};
|
2024-02-05 22:24:04 +01:00
|
|
|
port = mkOption {
|
|
|
|
description = "port to ssh into";
|
|
|
|
type = with types; nullOr number;
|
|
|
|
default = null;
|
|
|
|
};
|
2023-10-13 21:04:24 +02:00
|
|
|
user = mkOption {
|
|
|
|
description = "ssh user";
|
|
|
|
type = types.str;
|
|
|
|
default = "git";
|
|
|
|
};
|
2024-03-06 12:11:58 +01:00
|
|
|
publicKey = mkOption {
|
|
|
|
description = "public key used for picking the correct key from the ssh-agent";
|
2024-03-06 12:13:21 +01:00
|
|
|
type = with types; nullOr str;
|
2024-03-05 17:36:26 +01:00
|
|
|
default = null;
|
2023-10-13 21:04:24 +02:00
|
|
|
};
|
|
|
|
};
|
|
|
|
});
|
2024-03-06 12:03:08 +01:00
|
|
|
default = {};
|
2023-10-13 21:04:24 +02:00
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
config = mkMerge [
|
|
|
|
(mkIf cfg.daemon.enable {
|
|
|
|
services.openssh = {
|
|
|
|
enable = true;
|
|
|
|
settings = {
|
|
|
|
PasswordAuthentication = false;
|
|
|
|
PermitRootLogin = "no";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
})
|
|
|
|
(mkIf cfg.agent.enable {
|
2024-03-03 02:25:43 +01:00
|
|
|
programs.ssh = {
|
|
|
|
enableAskPassword = true;
|
|
|
|
askPassword = "${pkgs.libsForQt5.ksshaskpass}/bin/ksshaskpass";
|
|
|
|
extraConfig = ''
|
|
|
|
AddKeysToAgent yes
|
2023-10-13 21:04:24 +02:00
|
|
|
|
2024-03-03 02:25:43 +01:00
|
|
|
${concatStrings (mapAttrsToList (name: value: ''
|
|
|
|
Host ${name}
|
|
|
|
HostName ${value.hostName}
|
|
|
|
User ${value.user}
|
2024-03-06 12:11:58 +01:00
|
|
|
${
|
|
|
|
if value.port != null then
|
|
|
|
"Port ${toString value.port}"
|
|
|
|
else ""
|
|
|
|
}
|
|
|
|
${
|
|
|
|
if value.publicKey != null then
|
2024-03-06 12:21:02 +01:00
|
|
|
"IdentityFile ${pkgs.writeText "${name}.pub" value.publicKey}"
|
2024-03-06 12:11:58 +01:00
|
|
|
else ""
|
|
|
|
}
|
2024-03-03 02:25:43 +01:00
|
|
|
'') cfg.agent.hostAliases)}
|
|
|
|
'';
|
|
|
|
};
|
2023-10-13 21:04:24 +02:00
|
|
|
|
|
|
|
systemd.user.services.ssh-agent = {
|
|
|
|
enable = true;
|
|
|
|
description = "SSH key agent";
|
|
|
|
serviceConfig = {
|
|
|
|
Type = "simple";
|
|
|
|
ExecStart = "${pkgs.openssh}/bin/ssh-agent -D -a $SSH_AUTH_SOCK";
|
|
|
|
};
|
|
|
|
environment = {
|
|
|
|
SSH_AUTH_SOCK = "%t/ssh-agent.socket";
|
|
|
|
DISPLAY = ":0";
|
|
|
|
};
|
|
|
|
wantedBy = [ "default.target" ];
|
|
|
|
};
|
|
|
|
|
2023-10-13 23:18:35 +02:00
|
|
|
environment.sessionVariables = {
|
|
|
|
SSH_AUTH_SOCK = "\$XDG_RUNTIME_DIR/ssh-agent.socket";
|
|
|
|
};
|
2023-10-13 21:04:24 +02:00
|
|
|
})
|
|
|
|
];
|
|
|
|
}
|