Compare commits

..
11 Commits
Author SHA1 Message Date
aaron 7ceef4775c Merge pull request 'feature: move from gpg-git-commit-signing to ssh-signing' (#74) from feature/ssh-git-sign into main
Reviewed-on: #74
2026-09-05 15:46:55 +02:00
aaron 1b9b584729 feature(gpg): add more signing-keys to the config to enable my laptop as well 2026-09-05 15:44:42 +02:00
aaron d9d6877714 feature(gpg): move git from gpg-signing to ssh-signing 2026-09-05 15:33:05 +02:00
aaron 6704ec389c Merge pull request 'chore(update): update flake file' (#73) from chore/update into main
Reviewed-on: #73
2026-08-31 13:52:26 +02:00
aaron aca9e5d7cc chore(update): update flake file 2026-08-30 18:46:17 +02:00
aaron 2c8fbf008d Merge pull request 'chore(update): update flake file' (#72) from chore/update into main
Reviewed-on: #72
2026-08-20 20:53:12 +02:00
aaron c4f1be8a38 chore(update): update flake file 2026-08-20 20:52:22 +02:00
aaron 6df7fcacbb Merge pull request 'fix: ship a numbered udev rule file for vial since otherwise it gets overwritten by systemd's udev file' (#71) from feature/vial into main
Reviewed-on: #71
2026-08-09 14:45:34 +02:00
aaron bc11b464a8 fix: ship a numbered udev rule file for vial since otherwise it gets overwritten by systemd's udev file 2026-08-09 14:45:08 +02:00
aaron 0ac9b45286 Merge pull request 'feature(udev): add support for vial.rocks configurable devices and add the native app as well' (#69) from feature/lily58 into main
Reviewed-on: #69
2026-08-09 14:27:03 +02:00
aaron 62954a67b5 feature(udev): add support for vial.rocks configurable devices and add the native app as well 2026-08-09 13:49:46 +02:00
7 changed files with 88 additions and 21 deletions
Generated
+16 -15
View File
@@ -8,11 +8,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1782949081, "lastModified": 1787559586,
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=", "narHash": "sha256-onL0VLf9vPllmT0H/OlURIU5r5t5WIEl7t4tVNKT0Nw=",
"owner": "hercules-ci", "owner": "hercules-ci",
"repo": "flake-parts", "repo": "flake-parts",
"rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e", "rev": "9d0d87172c374f89da73c1cfe6d81ae62feac1f1",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -28,11 +28,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1785958398, "lastModified": 1787797243,
"narHash": "sha256-5r/JgsoNMTx+qIh83WkxpujEKBR7PF5ssnh5vYCuSAw=", "narHash": "sha256-8+Q7NOB7RPajRjA4pbCDLzqH+MTjnG9x6LUPLfL2joA=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "a7c70cc290290f373f50cd820403833d250459ac", "rev": "99c9ec63390f1d8c14d95d9e8b17cc29cfbd4e11",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -43,11 +43,11 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1785967620, "lastModified": 1787900134,
"narHash": "sha256-IItrdb7Puk05RqOBWZYFC5X6Wl1sJmCfh5MWVHw5iMM=", "narHash": "sha256-VYXO0XZlgj06dxJZRhrD3WoSsvq/c7+/Akyoa22pefw=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "b7c2ada94fe99c15b0dbcf4d11fd7850b957a436", "rev": "83199d0d373dd3ac2b9a1996b1d0263f76ab7a4c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -66,11 +66,11 @@
"systems": "systems" "systems": "systems"
}, },
"locked": { "locked": {
"lastModified": 1785763201, "lastModified": 1787862710,
"narHash": "sha256-wA373y/B9orM3HatLu9oS+Ke5lmdZyBl/bdjd2gLMq4=", "narHash": "sha256-dL1Tv7LekaTWUJxHRckjbupWczDdc3QOgRuVCM+WAvQ=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nixvim", "repo": "nixvim",
"rev": "c7be49306b23a952c0151cf4bbeacd944ed82f2a", "rev": "8c096abcf376137527c134da4ee210332b08ccc0",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -86,11 +86,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786013897, "lastModified": 1788099672,
"narHash": "sha256-u14Iaus6ROW6IWQUNGZ/IZJ3TcIUs1ngxn5sUMNnwMM=", "narHash": "sha256-t4Rw5OeULK/WA2Jh9ja615sCs2AmvahkAUx/ymdf2YQ=",
"owner": "noctalia-dev", "owner": "noctalia-dev",
"repo": "noctalia-shell", "repo": "noctalia-shell",
"rev": "0247e4c5e5268f8c2a5658b60b97cb5f2eca7766", "rev": "d891007c022a3a1d4484495fe8b350a00deafae9",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -108,6 +108,7 @@
} }
}, },
"systems": { "systems": {
"flake": false,
"locked": { "locked": {
"lastModified": 1774449309, "lastModified": 1774449309,
"narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=", "narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=",
+1
View File
@@ -26,6 +26,7 @@
../../modules/nixos/steam.nix ../../modules/nixos/steam.nix
../../modules/nixos/thunar.nix ../../modules/nixos/thunar.nix
../../modules/nixos/users.nix ../../modules/nixos/users.nix
../../modules/nixos/vial.nix
]; ];
# set hostname # set hostname
+1
View File
@@ -22,6 +22,7 @@
../../modules/nixos/settings.nix ../../modules/nixos/settings.nix
../../modules/nixos/steam.nix ../../modules/nixos/steam.nix
../../modules/nixos/users.nix ../../modules/nixos/users.nix
../../modules/nixos/vial.nix
]; ];
# set hostname # set hostname
+24 -3
View File
@@ -1,17 +1,38 @@
{ config, pkgs, inputs, ... }: { config, lib, pkgs, inputs, ... }:
let
email = "aaron@0x29a.ch";
# public half of every machine's ~/.ssh/id_ed25519, each one verified as a
# signing key in gitea. the key a host signs with is picked up from the key
# file itself, this list only tells the local git which machines to trust
signingKeys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHRhwzo1oxaT3fEySSmILKNnu9v30cfjx5G7FKpmfqeX aaron@argon"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGDkhvvTUcBSQdtXjX+Mw2Bp8HHhtiBm8aJi4ZxiBgZR aaron@neon"
];
in
{ {
# gitea verifies signatures against the account keys, this teaches the local
# git the same trust so `git log --show-signature` resolves as well
xdg.configFile."git/allowed_signers".text =
lib.concatMapStrings (key: "${email} ${key}\n") signingKeys;
programs.git = { programs.git = {
enable = true; enable = true;
settings = { settings = {
push = { autoSetupRemote = true; }; push = { autoSetupRemote = true; };
user = { user = {
name = "aaron"; name = "aaron";
email = "aaron@0x29a.ch"; email = email;
}; };
gpg.ssh.allowedSignersFile = "${config.xdg.configHome}/git/allowed_signers";
}; };
signing = { signing = {
key = "7A830180A05DAC59CDE43B0677D2F5DB48184456"; format = "ssh";
# point at the *public* key so ssh-keygen signs through the ssh agent
# instead of reading the passphrase protected private key from disk
key = "${config.home.homeDirectory}/.ssh/id_ed25519.pub";
signer = "${pkgs.openssh}/bin/ssh-keygen";
signByDefault = true; signByDefault = true;
}; };
}; };
+18 -2
View File
@@ -4,12 +4,28 @@
# enable gnupg agent # enable gnupg agent
programs.gnupg.agent = { programs.gnupg.agent = {
enable = true; enable = true;
enableSSHSupport = true; # a graphical pinentry never grabs the tty, so a passphrase prompt can no
pinentryPackage = pkgs.pinentry-curses; # longer take over a terminal that a coding agent is driving
pinentryPackage = pkgs.pinentry-qt;
settings = {
# keep the key unlocked for a full working day instead of 10 minutes,
# so signing commits asks at most once per session
default-cache-ttl = 86400;
max-cache-ttl = 86400;
# fail an unattended signature instead of blocking on a prompt forever
pinentry-timeout = 120;
};
}; };
environment.systemPackages = with pkgs; [ environment.systemPackages = with pkgs; [
gnupg gnupg
pinentry-qt
# fallback for sessions without a display, switch pinentryPackage to use it
pinentry-curses pinentry-curses
# prime the passphrase cache on demand, e.g. before an agent session
(writeShellScriptBin "gpg-unlock" ''
echo | ${config.programs.gnupg.package}/bin/gpg --clearsign --output /dev/null
echo "gpg key unlocked"
'')
]; ];
} }
+1
View File
@@ -35,6 +35,7 @@
tree tree
unzip unzip
usbutils usbutils
vial
vim vim
wget wget
which which
+26
View File
@@ -0,0 +1,26 @@
{ config, lib, pkgs, ... }:
{
# Vial-capable keyboards (lily58 pro r2g) expose a second, non-keyboard raw
# HID interface that vial.rocks drives over WebHID. Its /dev/hidraw* node is
# root-only by default, so neither chromium nor the native app can open it.
#
# This has to ship as a numbered rules file rather than via
# services.udev.extraRules: extraRules lands in 99-local.rules, but the
# builtin that turns TAG+="uaccess" into an actual ACL is invoked from
# systemd's 73-seat-late.rules. A tag set at 99 is set too late to be seen,
# so the device ends up correctly tagged and still unreadable. 60- sorts
# safely ahead of 73.
services.udev.packages = [
(pkgs.writeTextFile {
name = "vial-udev-rules";
destination = "/lib/udev/rules.d/60-vial.rules";
# Vial firmware advertises itself through a magic USB serial, so this
# matches any vial board rather than just the lily58. uaccess hands the
# device to whoever owns the active seat, no group membership needed.
text = ''
KERNEL=="hidraw*", SUBSYSTEM=="hidraw", ATTRS{serial}=="*vial:f64c2b3c*", TAG+="uaccess"
'';
})
];
}