summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--accounts/gkleen@skadhi/default.nix5
-rw-r--r--accounts/gkleen@skadhi/rzm/default.nix54
-rw-r--r--accounts/gkleen@skadhi/ssh/default.nix35
-rw-r--r--flake.lock12
-rw-r--r--flake.nix7
-rw-r--r--home-modules/autossh-proxy.nix10
-rw-r--r--system-profiles/core/default.nix2
-rw-r--r--users/gkleen/default.nix24
-rw-r--r--users/root.nix24
9 files changed, 89 insertions, 84 deletions
diff --git a/accounts/gkleen@skadhi/default.nix b/accounts/gkleen@skadhi/default.nix
index 1d6381a5..6d8195aa 100644
--- a/accounts/gkleen@skadhi/default.nix
+++ b/accounts/gkleen@skadhi/default.nix
@@ -176,6 +176,7 @@ in {
176 services.blueman-applet.enable = true; 176 services.blueman-applet.enable = true;
177 177
178 home.pointerCursor = { 178 home.pointerCursor = {
179 enable = true;
179 package = pkgs.vanilla-dmz; 180 package = pkgs.vanilla-dmz;
180 name = "Vanilla-DMZ-AA"; 181 name = "Vanilla-DMZ-AA";
181 size = 16; 182 size = 16;
@@ -204,7 +205,7 @@ in {
204 }; 205 };
205 }; 206 };
206 qt.enable = true; 207 qt.enable = true;
207 qt.platformTheme.name = "gtk"; 208 qt.platformTheme.name = "gtk3";
208 209
209 qt.kde.settings.kwalletrc = { 210 qt.kde.settings.kwalletrc = {
210 KSecretD.Enabled = false; 211 KSecretD.Enabled = false;
@@ -288,8 +289,6 @@ in {
288 }; 289 };
289 290
290 programs.chromium.enable = true; 291 programs.chromium.enable = true;
291
292 services.autosshProxy.vidhar.port = 8121;
293 }; 292 };
294 }; 293 };
295} 294}
diff --git a/accounts/gkleen@skadhi/rzm/default.nix b/accounts/gkleen@skadhi/rzm/default.nix
index e2a47362..cea4a58a 100644
--- a/accounts/gkleen@skadhi/rzm/default.nix
+++ b/accounts/gkleen@skadhi/rzm/default.nix
@@ -176,51 +176,47 @@ in {
176 pro = "$HOME/projects/pro"; 176 pro = "$HOME/projects/pro";
177 }; 177 };
178 178
179 programs.ssh.matchBlocks = let 179 programs.ssh.settings = {
180 autosshProxy = host: "${lib.getExe pkgs.socat} - SOCKS4A:127.0.0.1:%h:%p,socksport=${toString config.services.autosshProxy.${host}.port}";
181 in {
182 "repo-apt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { 180 "repo-apt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
183 user = "root"; 181 User = "root";
184 hostname = "repo-apt01.mathinst.loc"; 182 Hostname = "repo-apt01.mathinst.loc";
185 proxyCommand = autosshProxy "mgmt01"; 183 inherit (config.programs.ssh.autosshProxies."mgmt01") ProxyCommand;
186 }; 184 };
187 "mgmt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { 185 "mgmt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
188 user = "root"; 186 User = "root";
189 hostname = "mgmt01.mathinst.loc"; 187 Hostname = "mgmt01.mathinst.loc";
190 proxyCommand = autosshProxy "mathw0h"; 188 inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand;
191 }; 189 };
192 "mathw0e" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { 190 "mathw0e" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
193 hostname = "mathw0e.mathinst.loc"; 191 Hostname = "mathw0e.mathinst.loc";
194 proxyCommand = autosshProxy "mathw0h"; 192 inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand;
195 }; 193 };
196 "cip04" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { 194 "cip04" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
197 hostname = "cip04.cipmath.loc"; 195 Hostname = "cip04.cipmath.loc";
198 proxyCommand = autosshProxy "mathw0h"; 196 inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand;
199 }; 197 };
200 "mathw0h" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { 198 "mathw0h" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
201 hostname = "mathw0h.mathinst.loc"; 199 Hostname = "mathw0h.mathinst.loc";
202 proxyCommand = autosshProxy "ssh.math.lmu.de"; 200 inherit (config.programs.ssh.autosshProxies."ssh.math.lmu.de") ProxyCommand;
203 }; 201 };
204 "math05" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { 202 "math05" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
205 hostname = "math05.mathinst.loc"; 203 Hostname = "math05.mathinst.loc";
206 proxyCommand = autosshProxy "mathw0h"; 204 inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand;
207 extraOptions.KexAlgorithms = "+diffie-hellman-group1-sha1"; 205 KexAlgorithms = "+diffie-hellman-group1-sha1";
208 }; 206 };
209 "*.mathinst.loc" = { 207 "*.mathinst.loc" = {
210 match = "host *.mathinst.loc,*.cipmath.loc,*.math.lmu.de"; 208 header = "Host *.mathinst.loc,*.cipmath.loc,*.math.lmu.de";
211 identityFile = "~/.ssh/gkleen@mathinst.loc"; 209 IdentityFile = "~/.ssh/gkleen@mathinst.loc";
212 extraOptions = { 210 HostKeyAlgorithms = "+ssh-rsa";
213 HostKeyAlgorithms = "+ssh-rsa"; 211 PubkeyAcceptedAlgorithms = "+ssh-rsa";
214 PubkeyAcceptedAlgorithms = "+ssh-rsa"; 212 PasswordAuthentication = "yes";
215 PasswordAuthentication = "yes"; 213 GlobalKnownHostsFile = toString (pkgs.writeText "ssh_known_hosts" ''
216 GlobalKnownHostsFile = toString (pkgs.writeText "ssh_known_hosts" '' 214 @cert-authority *.mathinst.loc,*.math.lmu.de,*.cipmath.loc ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBUTFpVCdETCXiDSDl7YGbR1J4BLTsoBzjDtflHJGO/z ssh-pki@mgmt01
217 @cert-authority *.mathinst.loc,*.math.lmu.de,*.cipmath.loc ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBUTFpVCdETCXiDSDl7YGbR1J4BLTsoBzjDtflHJGO/z ssh-pki@mgmt01 215 '');
218 '');
219 };
220 }; 216 };
221 }; 217 };
222 218
223 services.autosshProxy = { 219 programs.ssh.autosshProxies = {
224 "mgmt01" = { port = 8129; sshpassSecret = "root@mgmt01.mathinst.loc"; }; 220 "mgmt01" = { port = 8129; sshpassSecret = "root@mgmt01.mathinst.loc"; };
225 "mathw0e" = { port = 8125; sshpassSecret = "gkleen@mathw0e.mathinst.loc"; }; 221 "mathw0e" = { port = 8125; sshpassSecret = "gkleen@mathw0e.mathinst.loc"; };
226 "mathw0h" = { port = 8123; sshpassSecret = "gkleen@mathw0h.mathinst.loc"; }; 222 "mathw0h" = { port = 8123; sshpassSecret = "gkleen@mathw0h.mathinst.loc"; };
diff --git a/accounts/gkleen@skadhi/ssh/default.nix b/accounts/gkleen@skadhi/ssh/default.nix
index f0fd93a8..ab0e8990 100644
--- a/accounts/gkleen@skadhi/ssh/default.nix
+++ b/accounts/gkleen@skadhi/ssh/default.nix
@@ -5,33 +5,40 @@
5 ".ssh" 5 ".ssh"
6 ]; 6 ];
7 7
8 programs.ssh.matchBlocks = { 8 programs.ssh.settings = {
9 "surtr" = { 9 "surtr" = {
10 hostname = "surtr.yggdrasil"; 10 Hostname = "surtr.yggdrasil";
11 identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; 11 IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil";
12 }; 12 };
13 "surtr.yggdrasil.li" = { 13 "surtr.yggdrasil.li" = {
14 identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; 14 IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil";
15 }; 15 };
16 "sif" = { 16 "sif" = {
17 hostname = "sif.yggdrasil"; 17 Hostname = "sif.yggdrasil";
18 identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; 18 IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil";
19 }; 19 };
20 "vidhar" = { 20 "vidhar" = {
21 hostname = "vidhar.yggdrasil"; 21 Hostname = "vidhar.yggdrasil";
22 identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; 22 IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil";
23 }; 23 };
24 "ymir" = { 24 "ymir" = {
25 hostname = "ymir.yggdrasil.li"; 25 Hostname = "ymir.yggdrasil.li";
26 identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; 26 IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil";
27 }; 27 };
28 ${lib.concatStringsSep " " [".host" "skadhi" "skadhi.yggdrasil" "localhost" "::1" "127.0.0.0/8"]} = { 28 "localhost" = {
29 identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; 29 header = "Host " + lib.concatStringsSep " " [".host" "skadhi" "skadhi.yggdrasil" "localhost" "::1" "127.0.0.0/8"];
30 IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil";
30 }; 31 };
31 "git.yggdrasil.li" = { 32 "git.yggdrasil.li" = {
32 user = "gitolite"; 33 User = "gitolite";
33 identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; 34 IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil";
35 };
36 "github.com" = {
37 User = "git";
38 IdentityFile = "~/.ssh/gkleen@github.com";
34 }; 39 };
35 }; 40 };
41
42 programs.ssh.autosshProxies.vidhar.port = 8121;
36 }; 43 };
37} 44}
diff --git a/flake.lock b/flake.lock
index 1d8d3afe..5f41295e 100644
--- a/flake.lock
+++ b/flake.lock
@@ -502,16 +502,16 @@
502 ] 502 ]
503 }, 503 },
504 "locked": { 504 "locked": {
505 "lastModified": 1765177068, 505 "lastModified": 1790365885,
506 "narHash": "sha256-sY0Se9MMC+94kQYJysp036+M6dHV/Rv8t4rOGJrFy5I=", 506 "narHash": "sha256-iQ0ebhiVo64NktTnwft9hNxlFu4j5cvljVxyJaEVIP4=",
507 "owner": "gkleen", 507 "owner": "nix-community",
508 "repo": "home-manager", 508 "repo": "home-manager",
509 "rev": "40a8c69f8502bf546e429efa18857b8b14fd467b", 509 "rev": "7b4c5ec4bedaf1e062bbc1bcaeddbc6bd242aa1b",
510 "type": "github" 510 "type": "github"
511 }, 511 },
512 "original": { 512 "original": {
513 "owner": "gkleen", 513 "owner": "nix-community",
514 "ref": "nixos-late-start", 514 "ref": "master",
515 "repo": "home-manager", 515 "repo": "home-manager",
516 "type": "github" 516 "type": "github"
517 } 517 }
diff --git a/flake.nix b/flake.nix
index cf029809..9f573db8 100644
--- a/flake.nix
+++ b/flake.nix
@@ -39,12 +39,9 @@
39 }; 39 };
40 home-manager = { 40 home-manager = {
41 type = "github"; 41 type = "github";
42 # owner = "nix-community"; 42 owner = "nix-community";
43 # repo = "home-manager";
44 # ref = "master";
45 owner = "gkleen";
46 repo = "home-manager"; 43 repo = "home-manager";
47 ref = "nixos-late-start"; 44 ref = "master";
48 inputs = { 45 inputs = {
49 nixpkgs.follows = "nixpkgs"; 46 nixpkgs.follows = "nixpkgs";
50 }; 47 };
diff --git a/home-modules/autossh-proxy.nix b/home-modules/autossh-proxy.nix
index e3179096..46cf1838 100644
--- a/home-modules/autossh-proxy.nix
+++ b/home-modules/autossh-proxy.nix
@@ -1,10 +1,10 @@
1{ lib, sysConfig, config, pkgs, ... }: 1{ lib, sysConfig, config, pkgs, ... }:
2 2
3let 3let
4 cfg = config.services.autosshProxy; 4 cfg = config.programs.ssh.autosshProxies;
5in { 5in {
6 options = { 6 options = {
7 services.autosshProxy = lib.mkOption { 7 programs.ssh.autosshProxies = lib.mkOption {
8 type = lib.types.attrsOf (lib.types.submodule ({ name, config, ... }: { 8 type = lib.types.attrsOf (lib.types.submodule ({ name, config, ... }: {
9 options = { 9 options = {
10 port = lib.mkOption { 10 port = lib.mkOption {
@@ -24,6 +24,12 @@ in {
24 sshpassSecret = lib.mkOption { 24 sshpassSecret = lib.mkOption {
25 type = lib.types.nullOr lib.types.str; 25 type = lib.types.nullOr lib.types.str;
26 }; 26 };
27
28 ProxyCommand = lib.mkOption {
29 type = lib.types.str;
30 readOnly = true;
31 default = "${lib.getExe pkgs.socat} - SOCKS4A:127.0.0.1:%h:%p,socksport=${toString config.port}";
32 };
27 }; 33 };
28 })); 34 }));
29 }; 35 };
diff --git a/system-profiles/core/default.nix b/system-profiles/core/default.nix
index 43369f50..710b57e0 100644
--- a/system-profiles/core/default.nix
+++ b/system-profiles/core/default.nix
@@ -154,7 +154,7 @@ in {
154 home-manager = { 154 home-manager = {
155 useGlobalPkgs = true; # Otherwise home-manager would only work impurely 155 useGlobalPkgs = true; # Otherwise home-manager would only work impurely
156 useUserPackages = false; 156 useUserPackages = false;
157 useUserService = true; 157 startAsUserService = true;
158 backupFileExtension = "bak"; 158 backupFileExtension = "bak";
159 sharedModules = lib.attrValues flake.homeModules ++ [ 159 sharedModules = lib.attrValues flake.homeModules ++ [
160 { 160 {
diff --git a/users/gkleen/default.nix b/users/gkleen/default.nix
index 9aa3b632..66930d4e 100644
--- a/users/gkleen/default.nix
+++ b/users/gkleen/default.nix
@@ -80,20 +80,20 @@ in {
80 }; 80 };
81 ssh = { 81 ssh = {
82 enableDefaultConfig = false; 82 enableDefaultConfig = false;
83 matchBlocks."*" = { 83 settings."*" = {
84 forwardAgent = false; 84 ForwardAgent = false;
85 addKeysToAgent = "no"; 85 AddKeysToAgent = "no";
86 compression = false; 86 Compression = false;
87 userKnownHostsFile = "~/.ssh/known_hosts"; 87 UserKnownHostsFile = "~/.ssh/known_hosts";
88 88
89 # controlMaster = "auto"; 89 # ControlMaster = "auto";
90 # controlPersist = "30m"; 90 # ControlPersist = "30m";
91 # controlPath = "~/.ssh/master-%r@%n:%p"; 91 # ControlPath = "~/.ssh/master-%r@%n:%p";
92 92
93 serverAliveInterval = 6; 93 ServerAliveInterval = 6;
94 serverAliveCountMax = 10; 94 ServerAliveCountMax = 10;
95 hashKnownHosts = true; 95 HashKnownHosts = true;
96 identitiesOnly = true; 96 IdentitiesOnly = true;
97 }; 97 };
98 }; 98 };
99 }; 99 };
diff --git a/users/root.nix b/users/root.nix
index a56c3c51..15dcd687 100644
--- a/users/root.nix
+++ b/users/root.nix
@@ -80,20 +80,20 @@ in {
80 }; 80 };
81 ssh = { 81 ssh = {
82 enableDefaultConfig = false; 82 enableDefaultConfig = false;
83 matchBlocks."*" = { 83 settings."*" = {
84 forwardAgent = false; 84 ForwardAgent = false;
85 addKeysToAgent = "no"; 85 AddKeysToAgent = "no";
86 compression = false; 86 Compression = false;
87 userKnownHostsFile = "~/.ssh/known_hosts"; 87 UserKnownHostsFile = "~/.ssh/known_hosts";
88 88
89 # controlMaster = "auto"; 89 # ControlMaster = "auto";
90 # controlPersist = "30m"; 90 # ControlPersist = "30m";
91 # controlPath = "~/.ssh/master-%r@%n:%p"; 91 # ControlPath = "~/.ssh/master-%r@%n:%p";
92 92
93 serverAliveInterval = 6; 93 ServerAliveInterval = 6;
94 serverAliveCountMax = 10; 94 ServerAliveCountMax = 10;
95 hashKnownHosts = true; 95 HashKnownHosts = true;
96 identitiesOnly = true; 96 IdentitiesOnly = true;
97 }; 97 };
98 }; 98 };
99 }; 99 };