diff --git a/homes/encode42/common/ssh.nix b/homes/encode42/common/ssh.nix new file mode 100644 index 0000000..8f4b2b8 --- /dev/null +++ b/homes/encode42/common/ssh.nix @@ -0,0 +1,27 @@ +let + host = "index"; + address = "192.168.1.2"; +in +{ + programs.ssh = { + enable = true; + enableDefaultConfig = false; + + matchBlocks = { + "index-local" = { + match = "host ${host} exec 'ping -c1 -W0.5 ${address} >/dev/null 2>&1'"; + hostname = address; + + forwardAgent = true; + }; + + "index-remote" = { + inherit host; + + hostname = "encrypted.group"; + + forwardAgent = true; + }; + }; + }; +} diff --git a/hosts/decryption/homes/encode42.nix b/hosts/decryption/homes/encode42.nix index 209c76c..5d53dd0 100644 --- a/hosts/decryption/homes/encode42.nix +++ b/hosts/decryption/homes/encode42.nix @@ -8,8 +8,9 @@ imports = [ (flakeRoot + /homes/encode42/common) - (flakeRoot + /homes/encode42/common/github.nix) (flakeRoot + /homes/encode42/common/direnv.nix) + (flakeRoot + /homes/encode42/common/github.nix) + (flakeRoot + /homes/encode42/common/ssh.nix) (flakeRoot + /homes/encode42/desktop/environments/gnome.nix) diff --git a/hosts/encryption/homes/encode42.nix b/hosts/encryption/homes/encode42.nix index b99e6d9..cb83b38 100644 --- a/hosts/encryption/homes/encode42.nix +++ b/hosts/encryption/homes/encode42.nix @@ -38,8 +38,9 @@ in imports = [ (flakeRoot + /homes/encode42/common) - (flakeRoot + /homes/encode42/common/github.nix) (flakeRoot + /homes/encode42/common/direnv.nix) + (flakeRoot + /homes/encode42/common/github.nix) + (flakeRoot + /homes/encode42/common/ssh.nix) (flakeRoot + /homes/encode42/common/imagemagik.nix) diff --git a/hosts/index/config/ssh.nix b/hosts/index/config/ssh.nix index 5a746e9..47213aa 100644 --- a/hosts/index/config/ssh.nix +++ b/hosts/index/config/ssh.nix @@ -1,5 +1,9 @@ { services.openssh = { + settings = { + AllowAgentForwarding = true; + }; + extraConfig = '' Match Address 192.168.1.0/24 AllowUsers *