diff --git a/modules/home-manager/git.nix b/modules/home-manager/git.nix index 2cb61b6..e6f5b74 100644 --- a/modules/home-manager/git.nix +++ b/modules/home-manager/git.nix @@ -1,16 +1,21 @@ -{ config, pkgs, inputs, ... }: +{ config, lib, pkgs, inputs, ... }: let - # public half of ~/.ssh/id_ed25519, registered and verified as a signing key - # in gitea - signingKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHRhwzo1oxaT3fEySSmILKNnu9v30cfjx5G7FKpmfqeX aaron@argon"; + email = "aaron@0x29a.ch"; + + # public half of every machine's ~/.ssh/id_ed25519, each one verified as a + # signing key in gitea. the key a host signs with is picked up from the key + # file itself, this list only tells the local git which machines to trust + signingKeys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHRhwzo1oxaT3fEySSmILKNnu9v30cfjx5G7FKpmfqeX aaron@argon" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGDkhvvTUcBSQdtXjX+Mw2Bp8HHhtiBm8aJi4ZxiBgZR aaron@neon" + ]; in { - # gitea verifies signatures against the account key, this teaches the local + # gitea verifies signatures against the account keys, this teaches the local # git the same trust so `git log --show-signature` resolves as well - xdg.configFile."git/allowed_signers".text = '' - aaron@0x29a.ch ${signingKey} - ''; + xdg.configFile."git/allowed_signers".text = + lib.concatMapStrings (key: "${email} ${key}\n") signingKeys; programs.git = { enable = true; @@ -18,7 +23,7 @@ in push = { autoSetupRemote = true; }; user = { name = "aaron"; - email = "aaron@0x29a.ch"; + email = email; }; gpg.ssh.allowedSignersFile = "${config.xdg.configHome}/git/allowed_signers"; };