nixos-config/modules/base/sshd/default.nix
Charlotte Van Petegem becf1495e5
Update dependencies
2023-01-21 10:03:26 +01:00

31 lines
892 B
Nix

{ config, lib, ... }:
{
chvp.base.zfs = {
ensureSystemExists = [ "${config.chvp.dataPrefix}/etc/ssh" ];
ensureHomeExists = [ ".ssh" ];
};
services.openssh = {
enable = true;
hostKeys = [
{ bits = 4096; path = "${config.chvp.dataPrefix}/etc/ssh/ssh_host_rsa_key"; type = "rsa"; }
{ path = "${config.chvp.dataPrefix}/etc/ssh/ssh_host_ed25519_key"; type = "ed25519"; }
];
settings = {
PasswordAuthentication = false;
PermitRootLogin = "prohibit-password";
};
};
age.secrets."authorized_keys/root" = {
file = ../../../secrets/authorized_keys/root.age;
path = "/root/.ssh/authorized_keys";
symlink = false;
};
age.secrets."authorized_keys/charlotte" = {
file = ../../../secrets/authorized_keys/charlotte.age;
owner = "charlotte";
path = "/home/charlotte/.ssh/authorized_keys";
symlink = false;
};
}