From c153a351659e4596acfc31f00bf594343cbfcd68 Mon Sep 17 00:00:00 2001 From: Benedikt Peetz Date: Thu, 30 Jul 2026 14:05:39 +0200 Subject: modules: Use namespaces That might make it easier in the future to merge different server configs together (and thusly facilitate code-reuse.). --- modules/vhack/op/openssh/module.nix | 60 +++++++++++++++++++++++++++++++++++++ 1 file changed, 60 insertions(+) create mode 100644 modules/vhack/op/openssh/module.nix (limited to 'modules/vhack/op/openssh') diff --git a/modules/vhack/op/openssh/module.nix b/modules/vhack/op/openssh/module.nix new file mode 100644 index 0000000..83aeadf --- /dev/null +++ b/modules/vhack/op/openssh/module.nix @@ -0,0 +1,60 @@ +{ + config, + lib, + ... +}: let + cfg = config.vhack.openssh; +in { + options.vhack.openssh = { + enable = lib.mkEnableOption '' + a sane openssh implementation. + ''; + }; + + config = lib.mkIf cfg.enable { + /* + FIXME(@bpeetz): + This results in a boot error, as the `/var/lib/sshd` directory + is only mounted _after_ the stage 2 init and with it the system + activation. `agenix` needs the sshd hostkey however to decrypt the + secrets and thus we have to ensure that this directory is mounted + _before_ the system activation. Alas the only way I see to achieve + that is to store the ssh hostkey directly on /srv, which is mounted + before (it's marked as 'neededForBoot' after all). + + It should be possible to achieve this with impermanence however, + as `/var/log` is mounted in the stage 1 init; The problem is that + I have no idea _why_ only this is mounted and nothing else. + + + vhack.persist.directories = [ + { + directory = "/var/lib/sshd"; + user = "root"; + group = "root"; + mode = "0755"; + } + ]; + */ + + users = { + users.sshd.uid = config.vhack.constants.ids.uids.sshd; + groups.sshd.gid = config.vhack.constants.ids.gids.sshd; + }; + + services.openssh = { + enable = true; + settings.PasswordAuthentication = false; + hostKeys = [ + { + # FIXME: Remove the dependency on `/srv` this workaround. + # See the explanation for using `/srv` above. + path = "/srv/var/lib/sshd/ssh_host_ed25519_key"; + + rounds = 1000; + type = "ed25519"; + } + ]; + }; + }; +} -- cgit v1.3.1