Files
nixos-config/home/terminal/software/ssh.nix
T
jory ff31b21a74
CI / Flake check (aarch64-linux) (push) Successful in 32s
CI / Flake check (x86_64-linux) (push) Successful in 32s
CI / Pre-commit checks (x86_64-linux) (push) Successful in 10s
Harden server and add Nix-native CI + self-hosted Gitea Actions
- Add self-hosted Gitea Actions runner module (servers/hetzner/modules/services/gitea.nix)
- Add CI workflow (.gitea/workflows/ci.yml):
  - Flake check (x86_64-linux + aarch64-linux, eval-only)
  - Pre-commit checks (x86_64-linux only)
  - Gitea-native runner (no Docker); Nix from host PATH
  - NIX_CONFIG enables flakes + extra-platforms
- Remove redundant .github/workflows/ci.yml (shadows .gitea)
- Enable deadnix in pre-commit hooks (flake.nix), fix 38 files
- Add statix.toml disabling empty_pattern lint (nixpkgs standard)
- Format whole repo with alejandra (27 files)
- Fix CI nix-not-found: export /run/current-system/sw/bin in PATH
- Remove aarch64 from pre-commit matrix (no QEMU binfmt deployed yet)
2026-07-12 08:24:14 +02:00

34 lines
760 B
Nix

{
config,
pkgs,
...
}: {
users.users.someone.packages = with pkgs; [
openssh
];
xdg.configFile."ssh/config" = {
source = config.age.secrets.ssh_config.path;
};
home.file.".ssh/config" = {
source = config.xdg.configHome + "/ssh/config";
mutable = false;
};
environment.sessionVariables = {
SSH_AUTH_SOCK = "${config.xdg.runtimeDir}/gnupg/S.gpg-agent.ssh";
SSH_CONFIG = "${config.xdg.configHome}/ssh/config";
};
systemd.user.services.ssh-agent = {
description = "SSH agent service";
wantedBy = ["default.target"];
serviceConfig = {
Type = "simple";
ExecStart = "${pkgs.openssh}/bin/ssh-agent -D -a ${config.xdg.runtimeDir}/ssh-agent.socket";
Restart = "on-failure";
};
};
}