{ config, lib, pkgs, inputs, ... }: let email = "aaron@0x29a.ch"; # public half of every machine's ~/.ssh/id_ed25519, each one verified as a # signing key in gitea. the key a host signs with is picked up from the key # file itself, this list only tells the local git which machines to trust signingKeys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHRhwzo1oxaT3fEySSmILKNnu9v30cfjx5G7FKpmfqeX aaron@argon" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGDkhvvTUcBSQdtXjX+Mw2Bp8HHhtiBm8aJi4ZxiBgZR aaron@neon" ]; in { # gitea verifies signatures against the account keys, this teaches the local # git the same trust so `git log --show-signature` resolves as well xdg.configFile."git/allowed_signers".text = lib.concatMapStrings (key: "${email} ${key}\n") signingKeys; programs.git = { enable = true; settings = { push = { autoSetupRemote = true; }; user = { name = "aaron"; email = email; }; gpg.ssh.allowedSignersFile = "${config.xdg.configHome}/git/allowed_signers"; }; signing = { format = "ssh"; # point at the *public* key so ssh-keygen signs through the ssh agent # instead of reading the passphrase protected private key from disk key = "${config.home.homeDirectory}/.ssh/id_ed25519.pub"; signer = "${pkgs.openssh}/bin/ssh-keygen"; signByDefault = true; }; }; }