feat: add ssh.nix with matchBlocks, pass origins (forgejo+github+solmoe)

This commit is contained in:
mikl 2026-07-01 18:43:33 +03:00
parent e9ddbc5d0e
commit eec7efabd1
4 changed files with 82 additions and 6 deletions

View file

@ -3,8 +3,10 @@
imports = [
./cli.nix
./git.nix
./ssh.nix
./zsh.nix
./duti.nix
./pass.nix
];
home.stateVersion = "24.11";

View file

@ -6,22 +6,60 @@
package = pkgs.pass.withExtensions (exts: [ exts.pass-otp ]);
settings = {
PASSWORD_STORE_DIR = "$HOME/.password-store";
PASSWORD_STORE_GIT = "git+https://git.iscg.dev/mikl/password-store.git";
PASSWORD_STORE_GIT = "ssh://git@git.iscg.dev:2222/mikl/password-store.git";
PASSWORD_STORE_X_SELECTION_TIMEOUT = "5";
PASSWORD_STORE_CLIP_TIME = "45";
PASSWORD_STORE_GENERATED_LENGTH = "25";
};
};
# Activation: ensure GPG key is available
# TODO: figure out why home.activation.data fails with multi-line strings
# For now, run pass setup manually after first activation
# GPG agent settings
services.gpg-agent = {
enable = true;
defaultCacheTtl = 3600;
enableSshSupport = true;
};
# Activation: setup pass git origins (forgejo + github + sol.moe)
# Uses pkgs.writeShellScript to avoid home.activation.data string issues
home.activation.passOrigins = {
data = let
setupScript = pkgs.writeShellScript "pass-origins-setup" ''
set -e
# Initialize pass if not yet
if [ ! -d "$HOME/.password-store" ]; then
echo "Initializing pass store..."
mkdir -p "$HOME/.password-store"
fi
# Initialize git if not yet
if [ ! -d "$HOME/.password-store/.git" ]; then
cd "$HOME/.password-store"
${pkgs.git}/bin/git init -q
fi
cd "$HOME/.password-store"
# Add origin (forgejo) if not present
if ! ${pkgs.git}/bin/git remote get-url origin >/dev/null 2>&1; then
${pkgs.git}/bin/git remote add origin "ssh://git@git.iscg.dev:2222/mikl/password-store.git"
fi
# Add github remote if not present
if ! ${pkgs.git}/bin/git remote get-url github >/dev/null 2>&1; then
${pkgs.git}/bin/git remote add github "git@github.com:isogonalconjugate/password-store.git"
fi
# Add git.sol.moe remote if not present
if ! ${pkgs.git}/bin/git remote get-url git.sol.moe >/dev/null 2>&1; then
${pkgs.git}/bin/git remote add "git.sol.moe" "git@git.sol.moe:mikl/password-store.git"
fi
cd - >/dev/null
'';
in builtins.toFile "pass-origins.sh" ''
${setupScript}
'';
};
}

32
home/ssh.nix Normal file
View file

@ -0,0 +1,32 @@
{ ... }:
{
# SSH client configuration with host-specific keys
programs.ssh = {
enable = true;
matchBlocks = {
# Forgejo (personal) — port 2222
"git.iscg.dev" = {
identityFile = "~/.ssh/id_ed25519_forgejo";
port = 2222;
identitiesOnly = true;
addKeysToAgent = "yes";
};
# GitHub
"github.com" = {
identityFile = "~/.ssh/id_ed25519";
identitiesOnly = true;
addKeysToAgent = "yes";
};
# git.sol.moe
"git.sol.moe" = {
identityFile = "~/.ssh/poppy";
user = "mikl";
identitiesOnly = true;
addKeysToAgent = "yes";
};
};
};
}

View file

@ -49,6 +49,10 @@
pass-sync = "pass git push";
pass-pull = "pass git pull";
pass-status = "pass git status";
pass-sync-forgejo = "pass git push origin";
pass-sync-github = "pass git push github";
pass-sync-solmoe = "pass git push git.sol.moe";
pass-pull-all = "pass git pull --all";
};
# Environment setup (zshenv)