aboutsummaryrefslogtreecommitdiffstats
path: root/modules/vhack/op
diff options
context:
space:
mode:
authorBenedikt Peetz <benedikt.peetz@b-peetz.de>2026-07-30 14:05:39 +0200
committerBenedikt Peetz <benedikt.peetz@b-peetz.de>2026-07-30 14:05:39 +0200
commitc153a351659e4596acfc31f00bf594343cbfcd68 (patch)
treea9ed83de07711d6424fbea09aad28891bae5bfe4 /modules/vhack/op
parenthosts/server3: Setup prometheus server in agent mode (diff)
downloadnixos-server-c153a351659e4596acfc31f00bf594343cbfcd68.zip
modules: Use namespaces
That might make it easier in the future to merge different server configs together (and thusly facilitate code-reuse.).
Diffstat (limited to 'modules/vhack/op')
-rw-r--r--modules/vhack/op/openssh/module.nix60
1 files changed, 60 insertions, 0 deletions
diff --git a/modules/vhack/op/openssh/module.nix b/modules/vhack/op/openssh/module.nix
new file mode 100644
index 0000000..83aeadf
--- /dev/null
+++ b/modules/vhack/op/openssh/module.nix
@@ -0,0 +1,60 @@
+{
+ config,
+ lib,
+ ...
+}: let
+ cfg = config.vhack.openssh;
+in {
+ options.vhack.openssh = {
+ enable = lib.mkEnableOption ''
+ a sane openssh implementation.
+ '';
+ };
+
+ config = lib.mkIf cfg.enable {
+ /*
+ FIXME(@bpeetz):
+ This results in a boot error, as the `/var/lib/sshd` directory
+ is only mounted _after_ the stage 2 init and with it the system
+ activation. `agenix` needs the sshd hostkey however to decrypt the
+ secrets and thus we have to ensure that this directory is mounted
+ _before_ the system activation. Alas the only way I see to achieve
+ that is to store the ssh hostkey directly on /srv, which is mounted
+ before (it's marked as 'neededForBoot' after all).
+
+ It should be possible to achieve this with impermanence however,
+ as `/var/log` is mounted in the stage 1 init; The problem is that
+ I have no idea _why_ only this is mounted and nothing else.
+
+
+ vhack.persist.directories = [
+ {
+ directory = "/var/lib/sshd";
+ user = "root";
+ group = "root";
+ mode = "0755";
+ }
+ ];
+ */
+
+ users = {
+ users.sshd.uid = config.vhack.constants.ids.uids.sshd;
+ groups.sshd.gid = config.vhack.constants.ids.gids.sshd;
+ };
+
+ services.openssh = {
+ enable = true;
+ settings.PasswordAuthentication = false;
+ hostKeys = [
+ {
+ # FIXME: Remove the dependency on `/srv` this workaround.
+ # See the explanation for using `/srv` above.
+ path = "/srv/var/lib/sshd/ssh_host_ed25519_key";
+
+ rounds = 1000;
+ type = "ed25519";
+ }
+ ];
+ };
+ };
+}