summaryrefslogtreecommitdiff
path: root/home/ssh.nix
diff options
context:
space:
mode:
Diffstat (limited to 'home/ssh.nix')
-rw-r--r--home/ssh.nix20
1 files changed, 17 insertions, 3 deletions
diff --git a/home/ssh.nix b/home/ssh.nix
index f0e75c7..ddcce96 100644
--- a/home/ssh.nix
+++ b/home/ssh.nix
@@ -8,10 +8,24 @@
...
}:
-{
- home.file.".ssh/authorized_keys".text = ''
- cert-authority,principals="${lib.concatStringsSep "," principals}" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuc4HCdyEMu4uiYhlokSXmu+68hkm7j6CqVwjDkCeSj grace.pink
+let
+ authorizedKeys = ''
+ cert-authority,principals="t:rebuild,${lib.concatStringsSep "," principals}" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuc4HCdyEMu4uiYhlokSXmu+68hkm7j6CqVwjDkCeSj grace.pink
sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIA6Eq2yVsZrCH8so7f3ygH0UWp6WkOxbhLNFC9QewKwoAAAABHNzaDo= grace.pink
${lib.concatStringsSep "\n" extraKeys}
'';
+in
+{
+ home.activation.authorizedKeys = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
+ run mkdir -p "$HOME/.ssh"
+ run chmod 700 "$HOME/.ssh"
+
+ if [[ -z "''${DRY_RUN:-}" ]]; then
+ cat > "$HOME/.ssh/authorized_keys" <<'EOF'
+ ${authorizedKeys}
+ EOF
+
+ chmod 600 "$HOME/.ssh/authorized_keys"
+ fi
+ '';
}