From a4acc43150d3315d21578e3bfb7290fa2c34f1ac Mon Sep 17 00:00:00 2001 From: Gregor Kleen Date: Mon, 28 Sep 2026 10:56:55 +0200 Subject: ... --- accounts/gkleen@skadhi/default.nix | 5 ++-- accounts/gkleen@skadhi/rzm/default.nix | 54 ++++++++++++++++------------------ accounts/gkleen@skadhi/ssh/default.nix | 35 +++++++++++++--------- flake.lock | 12 ++++---- flake.nix | 7 ++--- home-modules/autossh-proxy.nix | 10 +++++-- system-profiles/core/default.nix | 2 +- users/gkleen/default.nix | 24 +++++++-------- users/root.nix | 24 +++++++-------- 9 files changed, 89 insertions(+), 84 deletions(-) diff --git a/accounts/gkleen@skadhi/default.nix b/accounts/gkleen@skadhi/default.nix index 1d6381a5..6d8195aa 100644 --- a/accounts/gkleen@skadhi/default.nix +++ b/accounts/gkleen@skadhi/default.nix @@ -176,6 +176,7 @@ in { services.blueman-applet.enable = true; home.pointerCursor = { + enable = true; package = pkgs.vanilla-dmz; name = "Vanilla-DMZ-AA"; size = 16; @@ -204,7 +205,7 @@ in { }; }; qt.enable = true; - qt.platformTheme.name = "gtk"; + qt.platformTheme.name = "gtk3"; qt.kde.settings.kwalletrc = { KSecretD.Enabled = false; @@ -288,8 +289,6 @@ in { }; programs.chromium.enable = true; - - services.autosshProxy.vidhar.port = 8121; }; }; } diff --git a/accounts/gkleen@skadhi/rzm/default.nix b/accounts/gkleen@skadhi/rzm/default.nix index e2a47362..cea4a58a 100644 --- a/accounts/gkleen@skadhi/rzm/default.nix +++ b/accounts/gkleen@skadhi/rzm/default.nix @@ -176,51 +176,47 @@ in { pro = "$HOME/projects/pro"; }; - programs.ssh.matchBlocks = let - autosshProxy = host: "${lib.getExe pkgs.socat} - SOCKS4A:127.0.0.1:%h:%p,socksport=${toString config.services.autosshProxy.${host}.port}"; - in { + programs.ssh.settings = { "repo-apt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { - user = "root"; - hostname = "repo-apt01.mathinst.loc"; - proxyCommand = autosshProxy "mgmt01"; + User = "root"; + Hostname = "repo-apt01.mathinst.loc"; + inherit (config.programs.ssh.autosshProxies."mgmt01") ProxyCommand; }; "mgmt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { - user = "root"; - hostname = "mgmt01.mathinst.loc"; - proxyCommand = autosshProxy "mathw0h"; + User = "root"; + Hostname = "mgmt01.mathinst.loc"; + inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; }; "mathw0e" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { - hostname = "mathw0e.mathinst.loc"; - proxyCommand = autosshProxy "mathw0h"; + Hostname = "mathw0e.mathinst.loc"; + inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; }; "cip04" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { - hostname = "cip04.cipmath.loc"; - proxyCommand = autosshProxy "mathw0h"; + Hostname = "cip04.cipmath.loc"; + inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; }; "mathw0h" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { - hostname = "mathw0h.mathinst.loc"; - proxyCommand = autosshProxy "ssh.math.lmu.de"; + Hostname = "mathw0h.mathinst.loc"; + inherit (config.programs.ssh.autosshProxies."ssh.math.lmu.de") ProxyCommand; }; "math05" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { - hostname = "math05.mathinst.loc"; - proxyCommand = autosshProxy "mathw0h"; - extraOptions.KexAlgorithms = "+diffie-hellman-group1-sha1"; + Hostname = "math05.mathinst.loc"; + inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; + KexAlgorithms = "+diffie-hellman-group1-sha1"; }; "*.mathinst.loc" = { - match = "host *.mathinst.loc,*.cipmath.loc,*.math.lmu.de"; - identityFile = "~/.ssh/gkleen@mathinst.loc"; - extraOptions = { - HostKeyAlgorithms = "+ssh-rsa"; - PubkeyAcceptedAlgorithms = "+ssh-rsa"; - PasswordAuthentication = "yes"; - GlobalKnownHostsFile = toString (pkgs.writeText "ssh_known_hosts" '' - @cert-authority *.mathinst.loc,*.math.lmu.de,*.cipmath.loc ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBUTFpVCdETCXiDSDl7YGbR1J4BLTsoBzjDtflHJGO/z ssh-pki@mgmt01 - ''); - }; + header = "Host *.mathinst.loc,*.cipmath.loc,*.math.lmu.de"; + IdentityFile = "~/.ssh/gkleen@mathinst.loc"; + HostKeyAlgorithms = "+ssh-rsa"; + PubkeyAcceptedAlgorithms = "+ssh-rsa"; + PasswordAuthentication = "yes"; + GlobalKnownHostsFile = toString (pkgs.writeText "ssh_known_hosts" '' + @cert-authority *.mathinst.loc,*.math.lmu.de,*.cipmath.loc ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBUTFpVCdETCXiDSDl7YGbR1J4BLTsoBzjDtflHJGO/z ssh-pki@mgmt01 + ''); }; }; - services.autosshProxy = { + programs.ssh.autosshProxies = { "mgmt01" = { port = 8129; sshpassSecret = "root@mgmt01.mathinst.loc"; }; "mathw0e" = { port = 8125; sshpassSecret = "gkleen@mathw0e.mathinst.loc"; }; "mathw0h" = { port = 8123; sshpassSecret = "gkleen@mathw0h.mathinst.loc"; }; diff --git a/accounts/gkleen@skadhi/ssh/default.nix b/accounts/gkleen@skadhi/ssh/default.nix index f0fd93a8..ab0e8990 100644 --- a/accounts/gkleen@skadhi/ssh/default.nix +++ b/accounts/gkleen@skadhi/ssh/default.nix @@ -5,33 +5,40 @@ ".ssh" ]; - programs.ssh.matchBlocks = { + programs.ssh.settings = { "surtr" = { - hostname = "surtr.yggdrasil"; - identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; + Hostname = "surtr.yggdrasil"; + IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; }; "surtr.yggdrasil.li" = { - identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; + IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; }; "sif" = { - hostname = "sif.yggdrasil"; - identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; + Hostname = "sif.yggdrasil"; + IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; }; "vidhar" = { - hostname = "vidhar.yggdrasil"; - identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; + Hostname = "vidhar.yggdrasil"; + IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; }; "ymir" = { - hostname = "ymir.yggdrasil.li"; - identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; + Hostname = "ymir.yggdrasil.li"; + IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; }; - ${lib.concatStringsSep " " [".host" "skadhi" "skadhi.yggdrasil" "localhost" "::1" "127.0.0.0/8"]} = { - identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; + "localhost" = { + header = "Host " + lib.concatStringsSep " " [".host" "skadhi" "skadhi.yggdrasil" "localhost" "::1" "127.0.0.0/8"]; + IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; }; "git.yggdrasil.li" = { - user = "gitolite"; - identityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; + User = "gitolite"; + IdentityFile = "~/.ssh/gkleen@skadhi.yggdrasil"; + }; + "github.com" = { + User = "git"; + IdentityFile = "~/.ssh/gkleen@github.com"; }; }; + + programs.ssh.autosshProxies.vidhar.port = 8121; }; } diff --git a/flake.lock b/flake.lock index 1d8d3afe..5f41295e 100644 --- a/flake.lock +++ b/flake.lock @@ -502,16 +502,16 @@ ] }, "locked": { - "lastModified": 1765177068, - "narHash": "sha256-sY0Se9MMC+94kQYJysp036+M6dHV/Rv8t4rOGJrFy5I=", - "owner": "gkleen", + "lastModified": 1790365885, + "narHash": "sha256-iQ0ebhiVo64NktTnwft9hNxlFu4j5cvljVxyJaEVIP4=", + "owner": "nix-community", "repo": "home-manager", - "rev": "40a8c69f8502bf546e429efa18857b8b14fd467b", + "rev": "7b4c5ec4bedaf1e062bbc1bcaeddbc6bd242aa1b", "type": "github" }, "original": { - "owner": "gkleen", - "ref": "nixos-late-start", + "owner": "nix-community", + "ref": "master", "repo": "home-manager", "type": "github" } diff --git a/flake.nix b/flake.nix index cf029809..9f573db8 100644 --- a/flake.nix +++ b/flake.nix @@ -39,12 +39,9 @@ }; home-manager = { type = "github"; - # owner = "nix-community"; - # repo = "home-manager"; - # ref = "master"; - owner = "gkleen"; + owner = "nix-community"; repo = "home-manager"; - ref = "nixos-late-start"; + ref = "master"; inputs = { nixpkgs.follows = "nixpkgs"; }; diff --git a/home-modules/autossh-proxy.nix b/home-modules/autossh-proxy.nix index e3179096..46cf1838 100644 --- a/home-modules/autossh-proxy.nix +++ b/home-modules/autossh-proxy.nix @@ -1,10 +1,10 @@ { lib, sysConfig, config, pkgs, ... }: let - cfg = config.services.autosshProxy; + cfg = config.programs.ssh.autosshProxies; in { options = { - services.autosshProxy = lib.mkOption { + programs.ssh.autosshProxies = lib.mkOption { type = lib.types.attrsOf (lib.types.submodule ({ name, config, ... }: { options = { port = lib.mkOption { @@ -24,6 +24,12 @@ in { sshpassSecret = lib.mkOption { type = lib.types.nullOr lib.types.str; }; + + ProxyCommand = lib.mkOption { + type = lib.types.str; + readOnly = true; + default = "${lib.getExe pkgs.socat} - SOCKS4A:127.0.0.1:%h:%p,socksport=${toString config.port}"; + }; }; })); }; diff --git a/system-profiles/core/default.nix b/system-profiles/core/default.nix index 43369f50..710b57e0 100644 --- a/system-profiles/core/default.nix +++ b/system-profiles/core/default.nix @@ -154,7 +154,7 @@ in { home-manager = { useGlobalPkgs = true; # Otherwise home-manager would only work impurely useUserPackages = false; - useUserService = true; + startAsUserService = true; backupFileExtension = "bak"; sharedModules = lib.attrValues flake.homeModules ++ [ { diff --git a/users/gkleen/default.nix b/users/gkleen/default.nix index 9aa3b632..66930d4e 100644 --- a/users/gkleen/default.nix +++ b/users/gkleen/default.nix @@ -80,20 +80,20 @@ in { }; ssh = { enableDefaultConfig = false; - matchBlocks."*" = { - forwardAgent = false; - addKeysToAgent = "no"; - compression = false; - userKnownHostsFile = "~/.ssh/known_hosts"; + settings."*" = { + ForwardAgent = false; + AddKeysToAgent = "no"; + Compression = false; + UserKnownHostsFile = "~/.ssh/known_hosts"; - # controlMaster = "auto"; - # controlPersist = "30m"; - # controlPath = "~/.ssh/master-%r@%n:%p"; + # ControlMaster = "auto"; + # ControlPersist = "30m"; + # ControlPath = "~/.ssh/master-%r@%n:%p"; - serverAliveInterval = 6; - serverAliveCountMax = 10; - hashKnownHosts = true; - identitiesOnly = true; + ServerAliveInterval = 6; + ServerAliveCountMax = 10; + HashKnownHosts = true; + IdentitiesOnly = true; }; }; }; diff --git a/users/root.nix b/users/root.nix index a56c3c51..15dcd687 100644 --- a/users/root.nix +++ b/users/root.nix @@ -80,20 +80,20 @@ in { }; ssh = { enableDefaultConfig = false; - matchBlocks."*" = { - forwardAgent = false; - addKeysToAgent = "no"; - compression = false; - userKnownHostsFile = "~/.ssh/known_hosts"; + settings."*" = { + ForwardAgent = false; + AddKeysToAgent = "no"; + Compression = false; + UserKnownHostsFile = "~/.ssh/known_hosts"; - # controlMaster = "auto"; - # controlPersist = "30m"; - # controlPath = "~/.ssh/master-%r@%n:%p"; + # ControlMaster = "auto"; + # ControlPersist = "30m"; + # ControlPath = "~/.ssh/master-%r@%n:%p"; - serverAliveInterval = 6; - serverAliveCountMax = 10; - hashKnownHosts = true; - identitiesOnly = true; + ServerAliveInterval = 6; + ServerAliveCountMax = 10; + HashKnownHosts = true; + IdentitiesOnly = true; }; }; }; -- cgit v1.2.3