From fdde154c63eeb8e6aac5129f9226f38c4b0b8bf0 Mon Sep 17 00:00:00 2001 From: Grace Yoder Date: Sat, 3 Oct 2026 14:54:12 -0400 Subject: hamano again --- home/ssh.nix | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-) (limited to 'home/ssh.nix') diff --git a/home/ssh.nix b/home/ssh.nix index f0e75c7..ddcce96 100644 --- a/home/ssh.nix +++ b/home/ssh.nix @@ -8,10 +8,24 @@ ... }: -{ - home.file.".ssh/authorized_keys".text = '' - cert-authority,principals="${lib.concatStringsSep "," principals}" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuc4HCdyEMu4uiYhlokSXmu+68hkm7j6CqVwjDkCeSj grace.pink +let + authorizedKeys = '' + cert-authority,principals="t:rebuild,${lib.concatStringsSep "," principals}" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuc4HCdyEMu4uiYhlokSXmu+68hkm7j6CqVwjDkCeSj grace.pink sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIA6Eq2yVsZrCH8so7f3ygH0UWp6WkOxbhLNFC9QewKwoAAAABHNzaDo= grace.pink ${lib.concatStringsSep "\n" extraKeys} ''; +in +{ + home.activation.authorizedKeys = lib.hm.dag.entryAfter [ "writeBoundary" ] '' + run mkdir -p "$HOME/.ssh" + run chmod 700 "$HOME/.ssh" + + if [[ -z "''${DRY_RUN:-}" ]]; then + cat > "$HOME/.ssh/authorized_keys" <<'EOF' + ${authorizedKeys} + EOF + + chmod 600 "$HOME/.ssh/authorized_keys" + fi + ''; } -- cgit v1.3.1