diff options
| author | Gregor Kleen <gkleen@yggdrasil.li> | 2026-09-28 10:56:55 +0200 |
|---|---|---|
| committer | Gregor Kleen <gkleen@yggdrasil.li> | 2026-09-28 10:56:55 +0200 |
| commit | a4acc43150d3315d21578e3bfb7290fa2c34f1ac (patch) | |
| tree | abba670a5f81109a6bd1fd717de04dd58380da9a | |
| parent | 0fbdb0cd87a55ac26df54694386953281850d0a9 (diff) | |
| download | nixos-a4acc43150d3315d21578e3bfb7290fa2c34f1ac.tar nixos-a4acc43150d3315d21578e3bfb7290fa2c34f1ac.tar.gz nixos-a4acc43150d3315d21578e3bfb7290fa2c34f1ac.tar.bz2 nixos-a4acc43150d3315d21578e3bfb7290fa2c34f1ac.tar.xz nixos-a4acc43150d3315d21578e3bfb7290fa2c34f1ac.zip | |
...flakes
| -rw-r--r-- | accounts/gkleen@skadhi/default.nix | 5 | ||||
| -rw-r--r-- | accounts/gkleen@skadhi/rzm/default.nix | 54 | ||||
| -rw-r--r-- | accounts/gkleen@skadhi/ssh/default.nix | 35 | ||||
| -rw-r--r-- | flake.lock | 12 | ||||
| -rw-r--r-- | flake.nix | 7 | ||||
| -rw-r--r-- | home-modules/autossh-proxy.nix | 10 | ||||
| -rw-r--r-- | system-profiles/core/default.nix | 2 | ||||
| -rw-r--r-- | users/gkleen/default.nix | 24 | ||||
| -rw-r--r-- | users/root.nix | 24 |
9 files changed, 89 insertions, 84 deletions
diff --git a/accounts/gkleen@skadhi/default.nix b/accounts/gkleen@skadhi/default.nix index 1d6381a5..6d8195aa 100644 --- a/accounts/gkleen@skadhi/default.nix +++ b/accounts/gkleen@skadhi/default.nix | |||
| @@ -176,6 +176,7 @@ in { | |||
| 176 | services.blueman-applet.enable = true; | 176 | services.blueman-applet.enable = true; |
| 177 | 177 | ||
| 178 | home.pointerCursor = { | 178 | home.pointerCursor = { |
| 179 | enable = true; | ||
| 179 | package = pkgs.vanilla-dmz; | 180 | package = pkgs.vanilla-dmz; |
| 180 | name = "Vanilla-DMZ-AA"; | 181 | name = "Vanilla-DMZ-AA"; |
| 181 | size = 16; | 182 | size = 16; |
| @@ -204,7 +205,7 @@ in { | |||
| 204 | }; | 205 | }; |
| 205 | }; | 206 | }; |
| 206 | qt.enable = true; | 207 | qt.enable = true; |
| 207 | qt.platformTheme.name = "gtk"; | 208 | qt.platformTheme.name = "gtk3"; |
| 208 | 209 | ||
| 209 | qt.kde.settings.kwalletrc = { | 210 | qt.kde.settings.kwalletrc = { |
| 210 | KSecretD.Enabled = false; | 211 | KSecretD.Enabled = false; |
| @@ -288,8 +289,6 @@ in { | |||
| 288 | }; | 289 | }; |
| 289 | 290 | ||
| 290 | programs.chromium.enable = true; | 291 | programs.chromium.enable = true; |
| 291 | |||
| 292 | services.autosshProxy.vidhar.port = 8121; | ||
| 293 | }; | 292 | }; |
| 294 | }; | 293 | }; |
| 295 | } | 294 | } |
diff --git a/accounts/gkleen@skadhi/rzm/default.nix b/accounts/gkleen@skadhi/rzm/default.nix index e2a47362..cea4a58a 100644 --- a/accounts/gkleen@skadhi/rzm/default.nix +++ b/accounts/gkleen@skadhi/rzm/default.nix | |||
| @@ -176,51 +176,47 @@ in { | |||
| 176 | pro = "$HOME/projects/pro"; | 176 | pro = "$HOME/projects/pro"; |
| 177 | }; | 177 | }; |
| 178 | 178 | ||
| 179 | programs.ssh.matchBlocks = let | 179 | programs.ssh.settings = { |
| 180 | autosshProxy = host: "${lib.getExe pkgs.socat} - SOCKS4A:127.0.0.1:%h:%p,socksport=${toString config.services.autosshProxy.${host}.port}"; | ||
| 181 | in { | ||
| 182 | "repo-apt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | 180 | "repo-apt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { |
| 183 | user = "root"; | 181 | User = "root"; |
| 184 | hostname = "repo-apt01.mathinst.loc"; | 182 | Hostname = "repo-apt01.mathinst.loc"; |
| 185 | proxyCommand = autosshProxy "mgmt01"; | 183 | inherit (config.programs.ssh.autosshProxies."mgmt01") ProxyCommand; |
| 186 | }; | 184 | }; |
| 187 | "mgmt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | 185 | "mgmt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { |
| 188 | user = "root"; | 186 | User = "root"; |
| 189 | hostname = "mgmt01.mathinst.loc"; | 187 | Hostname = "mgmt01.mathinst.loc"; |
| 190 | proxyCommand = autosshProxy "mathw0h"; | 188 | inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; |
| 191 | }; | 189 | }; |
| 192 | "mathw0e" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | 190 | "mathw0e" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { |
| 193 | hostname = "mathw0e.mathinst.loc"; | 191 | Hostname = "mathw0e.mathinst.loc"; |
| 194 | proxyCommand = autosshProxy "mathw0h"; | 192 | inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; |
| 195 | }; | 193 | }; |
| 196 | "cip04" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | 194 | "cip04" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { |
| 197 | hostname = "cip04.cipmath.loc"; | 195 | Hostname = "cip04.cipmath.loc"; |
| 198 | proxyCommand = autosshProxy "mathw0h"; | 196 | inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; |
| 199 | }; | 197 | }; |
| 200 | "mathw0h" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | 198 | "mathw0h" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { |
| 201 | hostname = "mathw0h.mathinst.loc"; | 199 | Hostname = "mathw0h.mathinst.loc"; |
| 202 | proxyCommand = autosshProxy "ssh.math.lmu.de"; | 200 | inherit (config.programs.ssh.autosshProxies."ssh.math.lmu.de") ProxyCommand; |
| 203 | }; | 201 | }; |
| 204 | "math05" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | 202 | "math05" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { |
| 205 | hostname = "math05.mathinst.loc"; | 203 | Hostname = "math05.mathinst.loc"; |
| 206 | proxyCommand = autosshProxy "mathw0h"; | 204 | inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; |
| 207 | extraOptions.KexAlgorithms = "+diffie-hellman-group1-sha1"; | 205 | KexAlgorithms = "+diffie-hellman-group1-sha1"; |
| 208 | }; | 206 | }; |
| 209 | "*.mathinst.loc" = { | 207 | "*.mathinst.loc" = { |
| 210 | match = "host *.mathinst.loc,*.cipmath.loc,*.math.lmu.de"; | 208 | header = "Host *.mathinst.loc,*.cipmath.loc,*.math.lmu.de"; |
| 211 | identityFile = "~/.ssh/gkleen@mathinst.loc"; | 209 | IdentityFile = "~/.ssh/gkleen@mathinst.loc"; |
| 212 | extraOptions = { | 210 | HostKeyAlgorithms = "+ssh-rsa"; |
| 213 | HostKeyAlgorithms = "+ssh-rsa"; | 211 | PubkeyAcceptedAlgorithms = "+ssh-rsa"; |
| 214 | PubkeyAcceptedAlgorithms = "+ssh-rsa"; | 212 | PasswordAuthentication = "yes"; |
| 215 | PasswordAuthentication = "yes"; | 213 | GlobalKnownHostsFile = toString (pkgs.writeText "ssh_known_hosts" '' |
| 216 | GlobalKnownHostsFile = toString (pkgs.writeText "ssh_known_hosts" '' | 214 | @cert-authority *.mathinst.loc,*.math.lmu.de,*.cipmath.loc ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBUTFpVCdETCXiDSDl7YGbR1J4BLTsoBzjDtflHJGO/z ssh-pki@mgmt01 |
| 217 | @cert-authority *.mathinst.loc,*.math.lmu.de,*.cipmath.loc ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBUTFpVCdETCXiDSDl7YGbR1J4BLTsoBzjDtflHJGO/z ssh-pki@mgmt01 | 215 | ''); |
| 218 | ''); | ||
| 219 | }; | ||
| 220 | }; | 216 | }; |
| 221 | }; | 217 | }; |
| 222 | 218 | ||
| 223 | services.autosshProxy = { | 219 | programs.ssh.autosshProxies = { |
| 224 | "mgmt01" = { port = 8129; sshpassSecret = "root@mgmt01.mathinst.loc"; }; | 220 | "mgmt01" = { port = 8129; sshpassSecret = "root@mgmt01.mathinst.loc"; }; |
| 225 | "mathw0e" = { port = 8125; sshpassSecret = "gkleen@mathw0e.mathinst.loc"; }; | 221 | "mathw0e" = { port = 8125; sshpassSecret = "gkleen@mathw0e.mathinst.loc"; }; |
| 226 | "mathw0h" = { port = 8123; sshpassSecret = "gkleen@mathw0h.mathinst.loc"; }; | 222 | "mathw0h" = { port = 8123; sshpassSecret = "gkleen@mathw0h.mathinst.loc"; }; |
diff --git a/accounts/gkleen@skadhi/ssh/default.nix b/accounts/gkleen@skadhi/ssh/default.nix index f0fd93a8..ab0e8990 100644 --- a/accounts/gkleen@skadhi/ssh/default.nix +++ b/accounts/gkleen@skadhi/ssh/default.nix | |||
| @@ -5,33 +5,40 @@ | |||
| 5 | ".ssh" | 5 | ".ssh" |
| 6 | ]; | 6 | ]; |
| 7 | 7 | ||
| 8 | programs.ssh.matchBlocks = { | 8 | programs.ssh.settings = { |
| 9 | "surtr" = { | 9 | "surtr" = { |
| 10 | hostname = "surtr.yggdrasil"; | 10 | Hostname = "surtr.yggdrasil"; |
| 11 | identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; | 11 | IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; |
| 12 | }; | 12 | }; |
| 13 | "surtr.yggdrasil.li" = { | 13 | "surtr.yggdrasil.li" = { |
| 14 | identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; | 14 | IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; |
| 15 | }; | 15 | }; |
| 16 | "sif" = { | 16 | "sif" = { |
| 17 | hostname = "sif.yggdrasil"; | 17 | Hostname = "sif.yggdrasil"; |
| 18 | identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; | 18 | IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; |
| 19 | }; | 19 | }; |
| 20 | "vidhar" = { | 20 | "vidhar" = { |
| 21 | hostname = "vidhar.yggdrasil"; | 21 | Hostname = "vidhar.yggdrasil"; |
| 22 | identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; | 22 | IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; |
| 23 | }; | 23 | }; |
| 24 | "ymir" = { | 24 | "ymir" = { |
| 25 | hostname = "ymir.yggdrasil.li"; | 25 | Hostname = "ymir.yggdrasil.li"; |
| 26 | identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; | 26 | IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; |
| 27 | }; | 27 | }; |
| 28 | ${lib.concatStringsSep " " [".host" "skadhi" "skadhi.yggdrasil" "localhost" "::1" "127.0.0.0/8"]} = { | 28 | "localhost" = { |
| 29 | identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; | 29 | header = "Host " + lib.concatStringsSep " " [".host" "skadhi" "skadhi.yggdrasil" "localhost" "::1" "127.0.0.0/8"]; |
| 30 | IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; | ||
| 30 | }; | 31 | }; |
| 31 | "git.yggdrasil.li" = { | 32 | "git.yggdrasil.li" = { |
| 32 | user = "gitolite"; | 33 | User = "gitolite"; |
| 33 | identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; | 34 | IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; |
| 35 | }; | ||
| 36 | "github.com" = { | ||
| 37 | User = "git"; | ||
| 38 | IdentityFile = "~/.ssh/gkleen@github.com"; | ||
| 34 | }; | 39 | }; |
| 35 | }; | 40 | }; |
| 41 | |||
| 42 | programs.ssh.autosshProxies.vidhar.port = 8121; | ||
| 36 | }; | 43 | }; |
| 37 | } | 44 | } |
| @@ -502,16 +502,16 @@ | |||
| 502 | ] | 502 | ] |
| 503 | }, | 503 | }, |
| 504 | "locked": { | 504 | "locked": { |
| 505 | "lastModified": 1765177068, | 505 | "lastModified": 1790365885, |
| 506 | "narHash": "sha256-sY0Se9MMC+94kQYJysp036+M6dHV/Rv8t4rOGJrFy5I=", | 506 | "narHash": "sha256-iQ0ebhiVo64NktTnwft9hNxlFu4j5cvljVxyJaEVIP4=", |
| 507 | "owner": "gkleen", | 507 | "owner": "nix-community", |
| 508 | "repo": "home-manager", | 508 | "repo": "home-manager", |
| 509 | "rev": "40a8c69f8502bf546e429efa18857b8b14fd467b", | 509 | "rev": "7b4c5ec4bedaf1e062bbc1bcaeddbc6bd242aa1b", |
| 510 | "type": "github" | 510 | "type": "github" |
| 511 | }, | 511 | }, |
| 512 | "original": { | 512 | "original": { |
| 513 | "owner": "gkleen", | 513 | "owner": "nix-community", |
| 514 | "ref": "nixos-late-start", | 514 | "ref": "master", |
| 515 | "repo": "home-manager", | 515 | "repo": "home-manager", |
| 516 | "type": "github" | 516 | "type": "github" |
| 517 | } | 517 | } |
| @@ -39,12 +39,9 @@ | |||
| 39 | }; | 39 | }; |
| 40 | home-manager = { | 40 | home-manager = { |
| 41 | type = "github"; | 41 | type = "github"; |
| 42 | # owner = "nix-community"; | 42 | owner = "nix-community"; |
| 43 | # repo = "home-manager"; | ||
| 44 | # ref = "master"; | ||
| 45 | owner = "gkleen"; | ||
| 46 | repo = "home-manager"; | 43 | repo = "home-manager"; |
| 47 | ref = "nixos-late-start"; | 44 | ref = "master"; |
| 48 | inputs = { | 45 | inputs = { |
| 49 | nixpkgs.follows = "nixpkgs"; | 46 | nixpkgs.follows = "nixpkgs"; |
| 50 | }; | 47 | }; |
diff --git a/home-modules/autossh-proxy.nix b/home-modules/autossh-proxy.nix index e3179096..46cf1838 100644 --- a/home-modules/autossh-proxy.nix +++ b/home-modules/autossh-proxy.nix | |||
| @@ -1,10 +1,10 @@ | |||
| 1 | { lib, sysConfig, config, pkgs, ... }: | 1 | { lib, sysConfig, config, pkgs, ... }: |
| 2 | 2 | ||
| 3 | let | 3 | let |
| 4 | cfg = config.services.autosshProxy; | 4 | cfg = config.programs.ssh.autosshProxies; |
| 5 | in { | 5 | in { |
| 6 | options = { | 6 | options = { |
| 7 | services.autosshProxy = lib.mkOption { | 7 | programs.ssh.autosshProxies = lib.mkOption { |
| 8 | type = lib.types.attrsOf (lib.types.submodule ({ name, config, ... }: { | 8 | type = lib.types.attrsOf (lib.types.submodule ({ name, config, ... }: { |
| 9 | options = { | 9 | options = { |
| 10 | port = lib.mkOption { | 10 | port = lib.mkOption { |
| @@ -24,6 +24,12 @@ in { | |||
| 24 | sshpassSecret = lib.mkOption { | 24 | sshpassSecret = lib.mkOption { |
| 25 | type = lib.types.nullOr lib.types.str; | 25 | type = lib.types.nullOr lib.types.str; |
| 26 | }; | 26 | }; |
| 27 | |||
| 28 | ProxyCommand = lib.mkOption { | ||
| 29 | type = lib.types.str; | ||
| 30 | readOnly = true; | ||
| 31 | default = "${lib.getExe pkgs.socat} - SOCKS4A:127.0.0.1:%h:%p,socksport=${toString config.port}"; | ||
| 32 | }; | ||
| 27 | }; | 33 | }; |
| 28 | })); | 34 | })); |
| 29 | }; | 35 | }; |
diff --git a/system-profiles/core/default.nix b/system-profiles/core/default.nix index 43369f50..710b57e0 100644 --- a/system-profiles/core/default.nix +++ b/system-profiles/core/default.nix | |||
| @@ -154,7 +154,7 @@ in { | |||
| 154 | home-manager = { | 154 | home-manager = { |
| 155 | useGlobalPkgs = true; # Otherwise home-manager would only work impurely | 155 | useGlobalPkgs = true; # Otherwise home-manager would only work impurely |
| 156 | useUserPackages = false; | 156 | useUserPackages = false; |
| 157 | useUserService = true; | 157 | startAsUserService = true; |
| 158 | backupFileExtension = "bak"; | 158 | backupFileExtension = "bak"; |
| 159 | sharedModules = lib.attrValues flake.homeModules ++ [ | 159 | sharedModules = lib.attrValues flake.homeModules ++ [ |
| 160 | { | 160 | { |
diff --git a/users/gkleen/default.nix b/users/gkleen/default.nix index 9aa3b632..66930d4e 100644 --- a/users/gkleen/default.nix +++ b/users/gkleen/default.nix | |||
| @@ -80,20 +80,20 @@ in { | |||
| 80 | }; | 80 | }; |
| 81 | ssh = { | 81 | ssh = { |
| 82 | enableDefaultConfig = false; | 82 | enableDefaultConfig = false; |
| 83 | matchBlocks."*" = { | 83 | settings."*" = { |
| 84 | forwardAgent = false; | 84 | ForwardAgent = false; |
| 85 | addKeysToAgent = "no"; | 85 | AddKeysToAgent = "no"; |
| 86 | compression = false; | 86 | Compression = false; |
| 87 | userKnownHostsFile = "~/.ssh/known_hosts"; | 87 | UserKnownHostsFile = "~/.ssh/known_hosts"; |
| 88 | 88 | ||
| 89 | # controlMaster = "auto"; | 89 | # ControlMaster = "auto"; |
| 90 | # controlPersist = "30m"; | 90 | # ControlPersist = "30m"; |
| 91 | # controlPath = "~/.ssh/master-%r@%n:%p"; | 91 | # ControlPath = "~/.ssh/master-%r@%n:%p"; |
| 92 | 92 | ||
| 93 | serverAliveInterval = 6; | 93 | ServerAliveInterval = 6; |
| 94 | serverAliveCountMax = 10; | 94 | ServerAliveCountMax = 10; |
| 95 | hashKnownHosts = true; | 95 | HashKnownHosts = true; |
| 96 | identitiesOnly = true; | 96 | IdentitiesOnly = true; |
| 97 | }; | 97 | }; |
| 98 | }; | 98 | }; |
| 99 | }; | 99 | }; |
diff --git a/users/root.nix b/users/root.nix index a56c3c51..15dcd687 100644 --- a/users/root.nix +++ b/users/root.nix | |||
| @@ -80,20 +80,20 @@ in { | |||
| 80 | }; | 80 | }; |
| 81 | ssh = { | 81 | ssh = { |
| 82 | enableDefaultConfig = false; | 82 | enableDefaultConfig = false; |
| 83 | matchBlocks."*" = { | 83 | settings."*" = { |
| 84 | forwardAgent = false; | 84 | ForwardAgent = false; |
| 85 | addKeysToAgent = "no"; | 85 | AddKeysToAgent = "no"; |
| 86 | compression = false; | 86 | Compression = false; |
| 87 | userKnownHostsFile = "~/.ssh/known_hosts"; | 87 | UserKnownHostsFile = "~/.ssh/known_hosts"; |
| 88 | 88 | ||
| 89 | # controlMaster = "auto"; | 89 | # ControlMaster = "auto"; |
| 90 | # controlPersist = "30m"; | 90 | # ControlPersist = "30m"; |
| 91 | # controlPath = "~/.ssh/master-%r@%n:%p"; | 91 | # ControlPath = "~/.ssh/master-%r@%n:%p"; |
| 92 | 92 | ||
| 93 | serverAliveInterval = 6; | 93 | ServerAliveInterval = 6; |
| 94 | serverAliveCountMax = 10; | 94 | ServerAliveCountMax = 10; |
| 95 | hashKnownHosts = true; | 95 | HashKnownHosts = true; |
| 96 | identitiesOnly = true; | 96 | IdentitiesOnly = true; |
| 97 | }; | 97 | }; |
| 98 | }; | 98 | }; |
| 99 | }; | 99 | }; |
