mirror of
https://github.com/Stunkymonkey/nixos.git
synced 2025-05-24 01:44:40 +02:00
service/initrd-ssh: init from legacy
This commit is contained in:
parent
07da2f1b58
commit
460f9b2aa8
5 changed files with 36 additions and 26 deletions
|
@ -1,22 +0,0 @@
|
|||
{ pkgs, config, ... }:
|
||||
|
||||
{
|
||||
boot.initrd.network = {
|
||||
enable = true;
|
||||
|
||||
ssh = {
|
||||
enable = true;
|
||||
port = 2222;
|
||||
hostKeys = [
|
||||
"/etc/secrets/initrd/ssh_host_ed25519_key"
|
||||
];
|
||||
authorizedKeys = [
|
||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOFx6OLwL9MbkD3mnMsv+xrzZHN/rwCTgVs758SCLG0h felix@thinkman"
|
||||
];
|
||||
};
|
||||
|
||||
postCommands = ''
|
||||
echo 'cryptsetup-askpass' >> /root/.profile
|
||||
'';
|
||||
};
|
||||
}
|
|
@ -8,7 +8,6 @@
|
|||
./services.nix
|
||||
./syncthing.nix
|
||||
./system.nix
|
||||
../../legacy/modules/networkdecrypt.nix
|
||||
];
|
||||
|
||||
networking.hostName = "newton";
|
||||
|
@ -18,9 +17,6 @@
|
|||
gnupg.sshKeyPaths = [ ];
|
||||
};
|
||||
|
||||
networking.firewall.allowedTCPPorts = [
|
||||
];
|
||||
|
||||
system = {
|
||||
stateVersion = "22.11";
|
||||
autoUpgrade.enable = true;
|
||||
|
|
|
@ -95,6 +95,9 @@ in
|
|||
ssh-server = {
|
||||
enable = true;
|
||||
};
|
||||
initrd-ssh = {
|
||||
enable = true;
|
||||
};
|
||||
# self-hosted recipe manager
|
||||
tandoor-recipes = {
|
||||
enable = true;
|
||||
|
|
|
@ -7,6 +7,7 @@
|
|||
./hedgedoc
|
||||
./homepage
|
||||
./homer
|
||||
./initrd-ssh
|
||||
./jellyfin
|
||||
./minecraft-server
|
||||
./mumble-server
|
||||
|
|
32
modules/services/initrd-ssh/default.nix
Normal file
32
modules/services/initrd-ssh/default.nix
Normal file
|
@ -0,0 +1,32 @@
|
|||
# The Free Software Media System
|
||||
{ config, lib, pkgs, ... }:
|
||||
let
|
||||
cfg = config.my.services.initrd-ssh;
|
||||
domain = config.networking.domain;
|
||||
in
|
||||
{
|
||||
options.my.services.initrd-ssh = with lib; {
|
||||
enable = mkEnableOption "Enable initrd-ssh service";
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
boot.initrd.network = {
|
||||
enable = true;
|
||||
|
||||
ssh = {
|
||||
enable = true;
|
||||
port = 2222;
|
||||
hostKeys = [
|
||||
"/etc/secrets/initrd/ssh_host_ed25519_key"
|
||||
];
|
||||
authorizedKeys = [
|
||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOFx6OLwL9MbkD3mnMsv+xrzZHN/rwCTgVs758SCLG0h felix@thinkman"
|
||||
];
|
||||
};
|
||||
|
||||
postCommands = ''
|
||||
echo 'cryptsetup-askpass' >> /root/.profile
|
||||
'';
|
||||
};
|
||||
};
|
||||
}
|
Loading…
Add table
Add a link
Reference in a new issue