From 97d3e1ed92ee6c45f5573930e14a2d50f1d804bb Mon Sep 17 00:00:00 2001 From: Yuto Nishida Date: Mon, 22 Jun 2026 19:17:41 -0700 Subject: [PATCH] Centralize ssh public keys --- magic/CLAUDE.md | 92 +++++++++++++++++++ magic/common/constants.nix | 3 + magic/common/public_keys.json | 8 ++ milky-way/CLAUDE.md | 9 +- .../stage00/orion-system/main.jsonnet | 11 ++- milky-way/vendor/magic | 1 + .../modules/nixos-darwin/aluminum-nitride.nix | 7 +- venus/modules/nixos-darwin/ethane.nix | 5 +- .../modules/nixos-darwin/hydrogen-sulfide.nix | 5 +- venus/modules/nixos-darwin/methane.nix | 5 +- venus/modules/nixos-darwin/methanol.nix | 13 ++- venus/modules/nixos-darwin/sodium.nix | 5 +- venus/modules/nixos-darwin/tilderef.nix | 5 +- 13 files changed, 148 insertions(+), 21 deletions(-) create mode 100644 magic/CLAUDE.md create mode 100644 magic/common/public_keys.json create mode 120000 milky-way/vendor/magic diff --git a/magic/CLAUDE.md b/magic/CLAUDE.md new file mode 100644 index 0000000..8400dfb --- /dev/null +++ b/magic/CLAUDE.md @@ -0,0 +1,92 @@ +# magic — shared constants & public keys + +`magic/` holds small, cross-cutting values that several projects in this monorepo need to +agree on, so they live in one place instead of being copy-pasted. Today that's: + +- `magic/common/constants.nix` — home-relative path strings and other Nix constants. +- `magic/common/public_keys.json` — the single source of truth for reusable **public keys**. +- `magic/home-manager/` — a home-manager wrapper around `common/constants.nix`. + +## Public keys: `magic/common/public_keys.json` + +All reusable public keys live here, keyed by category then by a descriptive camelCase name: + +```json +{ + "ssh": { + "yutoSodium": "ssh-rsa AAAA… yuto@Yutos-MacBook-Pro.local", + "onePasswordMain": "ssh-ed25519 AAAA…", + "magnesiumHydroxideForGrandCentral": "ssh-ed25519 AAAA… grand-central yuto.nishida@magnesium-hydroxide", + "sodiumForGrandCentral": "ssh-ed25519 AAAA… grand-central-tunnel-sodium" + } +} +``` + +Each value is the **full** key line exactly as it belongs in an `authorized_keys` file +(including any trailing comment field). Never paste a public key literal into another file — +add it here once and reference it. + +### Consume from Nix + +`constants.nix` re-exports the parsed JSON as `publicKeys`: + +```nix +# constants.nix: +publicKeys = builtins.fromJSON (builtins.readFile ./public_keys.json); +``` + +In a module that already receives `lib` (any NixOS / nix-darwin module does), import it and +reference a key — e.g. the venus host modules under `venus/modules/nixos-darwin/*.nix`: + +```nix +let + publicKeys = (import ../../../magic/common/constants.nix { inherit lib; }).publicKeys; +in { + users.users.yuto.openssh.authorizedKeys.keys = [ + publicKeys.ssh.yutoSodium + publicKeys.ssh.onePasswordMain + ]; +} +``` + +If a module doesn't take `lib`, pass `{ lib = pkgs.lib; }` instead (e.g. `sodium.nix`, +`aluminum-nitride.nix`). Access is lazy: only `publicKeys` is forced, not the rest of +`constants.nix`. + +### Consume from jsonnet (milky-way / Tanka) + +`magic/` is symlinked into milky-way's jsonnet library path as +`milky-way/vendor/magic -> ../../magic` (the same mechanism as the existing +`vendor/exports -> ../../exports`). That makes the repo-root `magic/…` importable by path: + +```jsonnet +local pubkeys = import 'magic/common/public_keys.json'; +// … +authorizedKeys = [ + pubkeys.ssh.yutoSodium, + pubkeys.ssh.onePasswordMain, +], +``` + +`import` parses JSON natively. If a fresh checkout is missing the symlink, recreate it with +`ln -s ../../magic milky-way/vendor/magic` (it is committed, and `jb` only manages +`vendor/github.com/`, so it won't be disturbed). + +### Adding a key + +1. Add the full key line under the right category in `public_keys.json` with a descriptive name. +2. Reference it via `publicKeys.ssh.` (Nix) or `pubkeys.ssh.` (jsonnet). + +### Scope & deliberate exceptions + +This registry currently holds **SSH keys only**. Two key kinds are intentionally *not* sourced +from here because their consuming tools cannot import JSON: + +- **Cachix / nix binary-cache keys** in flakes' `nixConfig` — a flake's `nixConfig` is + evaluated per-flake and can't `readFile` outside its own directory. They stay as literals + in each `flake.nix`. +- **age / sops recipients** in `.sops.yaml` — the `sops` CLI reads `.sops.yaml` directly; the + per-file headers are auto-generated mirrors of it. They stay in `.sops.yaml` (already the + single place they're authored). + +Keys under `tilderef/keys/` are also out of scope and are managed there. diff --git a/magic/common/constants.nix b/magic/common/constants.nix index b77940a..64e8875 100644 --- a/magic/common/constants.nix +++ b/magic/common/constants.nix @@ -30,4 +30,7 @@ in { # MUT: Add any constants here jupiter-env-path-rel-to-everythingRepo = ".env.jupiter"; + + # Reusable public keys (SSH). Single source of truth: ./public_keys.json. + publicKeys = builtins.fromJSON (builtins.readFile ./public_keys.json); }) \ No newline at end of file diff --git a/magic/common/public_keys.json b/magic/common/public_keys.json new file mode 100644 index 0000000..6b25f5f --- /dev/null +++ b/magic/common/public_keys.json @@ -0,0 +1,8 @@ +{ + "ssh": { + "yutoSodium": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local", + "onePasswordMain": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPtVvX9uhSWD1DPBIRqgkNzFXqjdqvWB/WtDy4seaiJl", + "magnesiumHydroxideForGrandCentral": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJKRpVN+BI0l+wj28mUVq3ldRBZUgbsa9CymdCtXF7Vs grand-central yuto.nishida@magnesium-hydroxide", + "sodiumForGrandCentral": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBWjndergDSUeNxqTByOVeon92N6X52NaNydd4XUXR2A grand-central-tunnel-sodium" + } +} diff --git a/milky-way/CLAUDE.md b/milky-way/CLAUDE.md index 8d20a09..6bc6e58 100644 --- a/milky-way/CLAUDE.md +++ b/milky-way/CLAUDE.md @@ -89,9 +89,16 @@ milky-way/ ├── charts.jsonnet # Helm chart definitions with values ├── lib/ # Reusable Jsonnet libraries ├── secrets/ # sops-nix symlinks (READ-ONLY) -└── vendor/ # Jsonnet dependencies (tanka-util, etc.) +└── vendor/ # Jsonnet library path (tanka-util, etc.) + ├── exports -> ../../exports # repo-root exports/, importable as `exports/...` + └── magic -> ../../magic # repo-root magic/, importable as `magic/...` ``` +The `vendor/` symlinks put repo-root dirs on the jsonnet library path. In particular, +`import 'magic/common/public_keys.json'` resolves through `vendor/magic` — that JSON is the +single source of truth for reusable public keys (SSH); see `magic/CLAUDE.md`. Don't paste a +public-key literal into a `.jsonnet`/`.libsonnet` file; reference `pubkeys.ssh.` instead. + ## Secrets Management Secrets in `milky-way/secrets/` are **read-only symlinks** generated by sops-nix. To update secrets, modify the source in the sops-nix configuration and rebuild. diff --git a/milky-way/environments/stage00/orion-system/main.jsonnet b/milky-way/environments/stage00/orion-system/main.jsonnet index d458e59..79d19b4 100644 --- a/milky-way/environments/stage00/orion-system/main.jsonnet +++ b/milky-way/environments/stage00/orion-system/main.jsonnet @@ -28,6 +28,9 @@ local grandCentral = import 'milky-way/lib/grand-central.libsonnet'; local gluetunLeakTest = import 'milky-way/lib/gluetun-leak-test.libsonnet'; local testExampleWhaleImageDigest = import 'milky-way/lib/test-example-whale-image-digest.libsonnet'; local secrets = import 'milky-way/secrets/k8s-secret-values.jsonnet'; +// Reusable public keys (SSH). Source of truth: magic/common/public_keys.json, reached via the +// milky-way/vendor/magic -> ../../magic symlink (same mechanism as vendor/exports). See magic/CLAUDE.md. +local pubkeys = import 'magic/common/public_keys.json'; { local this = self, democraticCsiNamespace: { @@ -405,8 +408,8 @@ local secrets = import 'milky-way/secrets/k8s-secret-values.jsonnet'; sftpUser = "mdata", nodePort = 30022, authorizedKeys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local", // Yuto's Sodium - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPtVvX9uhSWD1DPBIRqgkNzFXqjdqvWB/WtDy4seaiJl", // 1Password "ssh key - main" + pubkeys.ssh.yutoSodium, // Yuto's Sodium + pubkeys.ssh.onePasswordMain, // 1Password "ssh key - main" ], ), @@ -425,7 +428,7 @@ local secrets = import 'milky-way/secrets/k8s-secret-values.jsonnet'; authorizedKeys = [ // Sodium -- a target pinned to its reverse-listener port 2222 (launchd agent in venus // sodium.nix; tunnel priv key in sops secrets/personal/grand-central-tunnel.json). - { key: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBWjndergDSUeNxqTByOVeon92N6X52NaNydd4XUXR2A grand-central-tunnel-sodium", listenPorts: [2222] }, + { key: pubkeys.ssh.sodiumForGrandCentral, listenPorts: [2222] }, // magnesium-hydroxide -- a client (also in Sodium's inbound authorized_keys for the final // hop). Bare string: may reach any target, no edits here when targets are added. // @@ -436,7 +439,7 @@ local secrets = import 'milky-way/secrets/k8s-secret-values.jsonnet'; // open vnc://localhost:5901 // (If this client has a `Host sodium` ssh_config block, just: ssh -L 5901:127.0.0.1:5900 sodium) // High Performance screen sharing can't traverse grand-central -- it needs native UDP 5900-5902. - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJKRpVN+BI0l+wj28mUVq3ldRBZUgbsa9CymdCtXF7Vs grand-central yuto.nishida@magnesium-hydroxide", + pubkeys.ssh.magnesiumHydroxideForGrandCentral, ], ), diff --git a/milky-way/vendor/magic b/milky-way/vendor/magic new file mode 120000 index 0000000..844024b --- /dev/null +++ b/milky-way/vendor/magic @@ -0,0 +1 @@ +../../magic \ No newline at end of file diff --git a/venus/modules/nixos-darwin/aluminum-nitride.nix b/venus/modules/nixos-darwin/aluminum-nitride.nix index 5c95881..28f5e7a 100644 --- a/venus/modules/nixos-darwin/aluminum-nitride.nix +++ b/venus/modules/nixos-darwin/aluminum-nitride.nix @@ -4,6 +4,9 @@ { config, pkgs, ... }: +let + publicKeys = (import ../../../magic/common/constants.nix { lib = pkgs.lib; }).publicKeys; +in { imports = [ # Include the results of the hardware scan. @@ -98,7 +101,7 @@ # thunderbird ]; openssh.authorizedKeys.keys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local" + publicKeys.ssh.yutoSodium ]; }; # Necessary for deploy-rs to be able to 1. push the config and 2. confirm activation. @@ -107,7 +110,7 @@ # having to type in the password for root. root = { openssh.authorizedKeys.keys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local" + publicKeys.ssh.yutoSodium ]; }; }; diff --git a/venus/modules/nixos-darwin/ethane.nix b/venus/modules/nixos-darwin/ethane.nix index 512f2ce..cc5d021 100644 --- a/venus/modules/nixos-darwin/ethane.nix +++ b/venus/modules/nixos-darwin/ethane.nix @@ -1,4 +1,5 @@ { modulesPath, lib, pkgs, config, ... }: let + publicKeys = (import ../../../magic/common/constants.nix { inherit lib; }).publicKeys; # Assigned IP from the Tailscale dashboard # TODO: create a centralized `magic.nix` for magic values like this # We can set this statically, since @@ -47,8 +48,8 @@ in { homeMode = "755"; # Let other users read/search (eg. Komga) (The x bit for directories is actually for searching) extraGroups = [ "wheel" ]; openssh.authorizedKeys.keys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local" # Yuto's Sodium - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPtVvX9uhSWD1DPBIRqgkNzFXqjdqvWB/WtDy4seaiJl" # 1Password "ssh key - main" + publicKeys.ssh.yutoSodium # Yuto's Sodium + publicKeys.ssh.onePasswordMain # 1Password "ssh key - main" ]; }; diff --git a/venus/modules/nixos-darwin/hydrogen-sulfide.nix b/venus/modules/nixos-darwin/hydrogen-sulfide.nix index 7d4db64..83f9ae6 100644 --- a/venus/modules/nixos-darwin/hydrogen-sulfide.nix +++ b/venus/modules/nixos-darwin/hydrogen-sulfide.nix @@ -1,6 +1,7 @@ { config, pkgs, lib, ... }: let + publicKeys = (import ../../../magic/common/constants.nix { inherit lib; }).publicKeys; # Assigned IP from the Tailscale dashboard # TODO: create a centralized `magic.nix` for magic values like this # We can set this statically, since @@ -113,12 +114,12 @@ in "nixos" = { shell = pkgs.fish; openssh.authorizedKeys.keys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local" + publicKeys.ssh.yutoSodium ]; }; "root" = { openssh.authorizedKeys.keys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local" + publicKeys.ssh.yutoSodium ]; }; }; diff --git a/venus/modules/nixos-darwin/methane.nix b/venus/modules/nixos-darwin/methane.nix index b7f05ca..d6a020f 100644 --- a/venus/modules/nixos-darwin/methane.nix +++ b/venus/modules/nixos-darwin/methane.nix @@ -1,4 +1,5 @@ { modulesPath, lib, pkgs, config, ... }: let + publicKeys = (import ../../../magic/common/constants.nix { inherit lib; }).publicKeys; # Assigned IP from the Tailscale dashboard # TODO: create a centralized `magic.nix` for magic values like this # We can set this statically, since @@ -45,8 +46,8 @@ in { homeMode = "755"; # Let other users read/search (eg. Komga) (The x bit for directories is actually for searching) extraGroups = [ "wheel" ]; openssh.authorizedKeys.keys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local" # Yuto's Sodium - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPtVvX9uhSWD1DPBIRqgkNzFXqjdqvWB/WtDy4seaiJl" # 1Password "ssh key - main" + publicKeys.ssh.yutoSodium # Yuto's Sodium + publicKeys.ssh.onePasswordMain # 1Password "ssh key - main" ]; }; diff --git a/venus/modules/nixos-darwin/methanol.nix b/venus/modules/nixos-darwin/methanol.nix index 7226947..f2aa83b 100644 --- a/venus/modules/nixos-darwin/methanol.nix +++ b/venus/modules/nixos-darwin/methanol.nix @@ -4,6 +4,9 @@ { config, lib, pkgs, ... }: +let + publicKeys = (import ../../../magic/common/constants.nix { inherit lib; }).publicKeys; +in { imports = [ # Include the results of the hardware scan. @@ -347,13 +350,13 @@ tree ]; openssh.authorizedKeys.keys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local" # Yuto's Sodium - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPtVvX9uhSWD1DPBIRqgkNzFXqjdqvWB/WtDy4seaiJl" # 1Password "ssh key - main" + publicKeys.ssh.yutoSodium # Yuto's Sodium + publicKeys.ssh.onePasswordMain # 1Password "ssh key - main" ]; }; users.users.root.openssh.authorizedKeys.keys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local" # Yuto's Sodium - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPtVvX9uhSWD1DPBIRqgkNzFXqjdqvWB/WtDy4seaiJl" # 1Password "ssh key - main" + publicKeys.ssh.yutoSodium # Yuto's Sodium + publicKeys.ssh.onePasswordMain # 1Password "ssh key - main" ]; users.users.democratic-csi = { @@ -363,7 +366,7 @@ group = "democratic-csi"; extraGroups = [ "wheel" ]; # Required for zfs manipulation openssh.authorizedKeys.keys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local" # Yuto's Sodium + publicKeys.ssh.yutoSodium # Yuto's Sodium ]; }; users.groups.democratic-csi = { }; diff --git a/venus/modules/nixos-darwin/sodium.nix b/venus/modules/nixos-darwin/sodium.nix index af5f83f..742e85b 100644 --- a/venus/modules/nixos-darwin/sodium.nix +++ b/venus/modules/nixos-darwin/sodium.nix @@ -1,6 +1,9 @@ { config, pkgs, ... }: # This file is the equivalent of /etc/nixos/configuration.nix on darwin +let + publicKeys = (import ../../../magic/common/constants.nix { lib = pkgs.lib; }).publicKeys; +in { # List packages installed in system profile. To search by name, run: # $ nix-env -qaP | grep wget @@ -120,7 +123,7 @@ # Add the SAME dedicated public key you put in grand-central's clientKeys (main.jsonnet): openssh.authorizedKeys.keys = [ # "ssh-ed25519 AAAA... grand-central @" # generated per client; see plan - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJKRpVN+BI0l+wj28mUVq3ldRBZUgbsa9CymdCtXF7Vs grand-central yuto.nishida@magnesium-hydroxide" + publicKeys.ssh.magnesiumHydroxideForGrandCentral ]; }; diff --git a/venus/modules/nixos-darwin/tilderef.nix b/venus/modules/nixos-darwin/tilderef.nix index 0565e83..e1fd869 100644 --- a/venus/modules/nixos-darwin/tilderef.nix +++ b/venus/modules/nixos-darwin/tilderef.nix @@ -1,6 +1,7 @@ { config, modulesPath, lib, pkgs, ... }: let generated = builtins.fromJSON (builtins.readFile ./../../../exports/jupiter/generated.json); + publicKeys = (import ./../../../magic/common/constants.nix { inherit lib; }).publicKeys; generated-serverref-data-from-pulumi = generated.serverref; hostKeys-by-name = { # INFO: deploy-rs cannot confirm activation if the first two attrsets are not in the following order by key! @@ -71,8 +72,8 @@ homeMode = "755"; extraGroups = [ "wheel" ]; openssh.authorizedKeys.keys = [ - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLrT2/gQXhOz4E4xSphB8EXouild5qNOnZ6ZVXuTnf167z8xxSB10mxNey2gKDaIVig6I/tRFeYy6/N/QutbBlKI/+GNPjGCcVJI0hf7fTZGL4caTW8ggcXRz4LAsFp3JBf6Li0FVrGz5ojD0Etbl54BDn033q/tlVRhme5bXJ6s73yRg04kqdQsWVBRJwyzbUUmCQPrZd9i5Nh4QFVuhZljEyUWIStajE+c9v8OOiY1svv+XjKBjyWphP16HqgzvnEDf5+MQ5AUxE05IvJx43UY43CKTe3evzt4F/IqSdYwYGIQ55DaseRmf5zmHLU8MTTkksmOPQEzJL0nBzAmxyGV3PsMYPoIN+1/gJmxCO6ZaaCxYr9SFK/yoRW5e0PFX433xPhNsITBq7jUrVg6BQ/lr0ntRfvd7pRhFq8v02R3jWokL/99skxp1kjVF42bXEJXYPpHF3XAUhYscjOwmWj8dJgsIsSIKIjh7gRVYxQGrZQXOcJQjMytFgXy7fWHM= yuto@Yutos-MacBook-Pro.local" # Yuto's Sodium - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPtVvX9uhSWD1DPBIRqgkNzFXqjdqvWB/WtDy4seaiJl" # 1Password "ssh key - main" + publicKeys.ssh.yutoSodium # Yuto's Sodium + publicKeys.ssh.onePasswordMain # 1Password "ssh key - main" ]; }; awang = { isNormalUser = true; homeMode = "755"; }; -- 2.51.2