From 1e53f46930b7aa410858c3bc228caaf1726547e7 Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Sat, 6 Apr 2024 13:11:56 -0600 Subject: man colors should work with this bat theme --- modules/home-manager/bat.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/home-manager/bat.nix b/modules/home-manager/bat.nix index 13e8e6d..b54677f 100644 --- a/modules/home-manager/bat.nix +++ b/modules/home-manager/bat.nix @@ -4,6 +4,7 @@ enable = true; config = { pager = "less -FR"; + theme = "Solarized (dark)"; # theme = "catppuccin-mocha"; }; # themes = { -- cgit v1.2.3 From aa3f255a408ae189ec88b76e7c7313d5d8718cef Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Sat, 6 Apr 2024 13:13:22 -0600 Subject: cleaning declarations --- modules/nixos/headscale.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/nixos/headscale.nix b/modules/nixos/headscale.nix index 261dd52..d56785f 100644 --- a/modules/nixos/headscale.nix +++ b/modules/nixos/headscale.nix @@ -1,4 +1,4 @@ -{config, pkgs, ...}: +{config, ...}: let domain = "myrmexia.xyz"; subDomain = "bosco.${domain}"; -- cgit v1.2.3 From a60472b7b010295843a6c0b91305a25624f2edee Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Sat, 6 Apr 2024 13:38:30 -0600 Subject: add key for remote build --- modules/users/defin.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/modules/users/defin.nix b/modules/users/defin.nix index 139845f..eab36bb 100644 --- a/modules/users/defin.nix +++ b/modules/users/defin.nix @@ -22,6 +22,8 @@ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHXrt3+N4+ahtXZCUn11evQsVGsGgAohGwafC29/a4fk defin@Radahn" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICkGcmYIYCe6GHsZZvnXqsedF0wn+AhGSr+RPJtUO/kl defin@khad" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEaMYXO9ghATyUPzyE7aD/XVVmK9UAexueoGEYAqPT4L defin@kebab" + #unlocked keys for remote build + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHslJRD5+7rytlVDzeZh6B/4XW8QWQ5dsWWDBbOXKTrJ defin@zenbook" ]; }; }; -- cgit v1.2.3 From 04275d7faa164d960801548e74d648f89b62ac3c Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Sat, 6 Apr 2024 13:57:24 -0600 Subject: trying another key --- modules/users/defin.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/users/defin.nix b/modules/users/defin.nix index eab36bb..393a718 100644 --- a/modules/users/defin.nix +++ b/modules/users/defin.nix @@ -24,6 +24,7 @@ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEaMYXO9ghATyUPzyE7aD/XVVmK9UAexueoGEYAqPT4L defin@kebab" #unlocked keys for remote build "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHslJRD5+7rytlVDzeZh6B/4XW8QWQ5dsWWDBbOXKTrJ defin@zenbook" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFstzru5ItF3ZhAAR4B8+iTZfGztbbMsKh01Y/K8lg+Q defin@zenbook" ]; }; }; -- cgit v1.2.3 From c34b0520c2cf21f476bbf4a7702648b71561f184 Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Sat, 6 Apr 2024 14:00:23 -0600 Subject: made a root key --- modules/users/defin.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/users/defin.nix b/modules/users/defin.nix index 393a718..6f22dcd 100644 --- a/modules/users/defin.nix +++ b/modules/users/defin.nix @@ -23,6 +23,7 @@ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICkGcmYIYCe6GHsZZvnXqsedF0wn+AhGSr+RPJtUO/kl defin@khad" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEaMYXO9ghATyUPzyE7aD/XVVmK9UAexueoGEYAqPT4L defin@kebab" #unlocked keys for remote build + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINUdE8ETBYb9Is4BVekdgC5wStzcnWilSRhDmwp0vSX9 root@zenbook" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHslJRD5+7rytlVDzeZh6B/4XW8QWQ5dsWWDBbOXKTrJ defin@zenbook" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFstzru5ItF3ZhAAR4B8+iTZfGztbbMsKh01Y/K8lg+Q defin@zenbook" ]; -- cgit v1.2.3 From 40b26850c3cbafaba54e025be24667dfe20a8288 Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Sat, 6 Apr 2024 14:06:07 -0600 Subject: testing no root keys --- modules/users/defin.nix | 1 - 1 file changed, 1 deletion(-) diff --git a/modules/users/defin.nix b/modules/users/defin.nix index 6f22dcd..393a718 100644 --- a/modules/users/defin.nix +++ b/modules/users/defin.nix @@ -23,7 +23,6 @@ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICkGcmYIYCe6GHsZZvnXqsedF0wn+AhGSr+RPJtUO/kl defin@khad" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEaMYXO9ghATyUPzyE7aD/XVVmK9UAexueoGEYAqPT4L defin@kebab" #unlocked keys for remote build - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINUdE8ETBYb9Is4BVekdgC5wStzcnWilSRhDmwp0vSX9 root@zenbook" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHslJRD5+7rytlVDzeZh6B/4XW8QWQ5dsWWDBbOXKTrJ defin@zenbook" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFstzru5ItF3ZhAAR4B8+iTZfGztbbMsKh01Y/K8lg+Q defin@zenbook" ]; -- cgit v1.2.3 From 1fa49f495753b6fa90be67633b9f1ceff121ebad Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Sat, 6 Apr 2024 14:07:46 -0600 Subject: root can't user user keys even with no passphrase --- modules/users/defin.nix | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/modules/users/defin.nix b/modules/users/defin.nix index 393a718..b88fe2e 100644 --- a/modules/users/defin.nix +++ b/modules/users/defin.nix @@ -23,8 +23,7 @@ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICkGcmYIYCe6GHsZZvnXqsedF0wn+AhGSr+RPJtUO/kl defin@khad" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEaMYXO9ghATyUPzyE7aD/XVVmK9UAexueoGEYAqPT4L defin@kebab" #unlocked keys for remote build - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHslJRD5+7rytlVDzeZh6B/4XW8QWQ5dsWWDBbOXKTrJ defin@zenbook" - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFstzru5ItF3ZhAAR4B8+iTZfGztbbMsKh01Y/K8lg+Q defin@zenbook" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINUdE8ETBYb9Is4BVekdgC5wStzcnWilSRhDmwp0vSX9 root@zenbook" ]; }; }; -- cgit v1.2.3 From 1d378703dae7171ea97e8b981adffc4b64f02ed5 Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Sat, 6 Apr 2024 15:12:23 -0600 Subject: add builders group to nix truster users --- modules/users/defin.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/users/defin.nix b/modules/users/defin.nix index b88fe2e..b52ebe6 100644 --- a/modules/users/defin.nix +++ b/modules/users/defin.nix @@ -28,6 +28,7 @@ }; }; + nix.settings.trusted-users = [ "@builders" ]; # I can't think of a better spot to put this rn. services.openssh = { ports = [ 22 2200 ]; # needed because isp blocks ssh over 22 -- cgit v1.2.3 From 2d703cf9809eb1e008e1c3af37651cab90696ab0 Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Sat, 6 Apr 2024 15:19:29 -0600 Subject: enable doretta ssh auth for build server --- machines/doretta/configuration.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/machines/doretta/configuration.nix b/machines/doretta/configuration.nix index cee39ed..b29289e 100644 --- a/machines/doretta/configuration.nix +++ b/machines/doretta/configuration.nix @@ -16,6 +16,8 @@ networking.hostName = "doretta"; # Define your hostname. + security.pam.enableSSHAgentAuth = true; + virtualisation.libvirtd = { enable = true; }; -- cgit v1.2.3 From e458ce87743db6a3d4ae69112deb864542b8edda Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Sat, 6 Apr 2024 15:21:56 -0600 Subject: ssh agent auth for all systems test --- modules/users/defin.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/users/defin.nix b/modules/users/defin.nix index b52ebe6..af7e0cb 100644 --- a/modules/users/defin.nix +++ b/modules/users/defin.nix @@ -29,6 +29,7 @@ }; nix.settings.trusted-users = [ "@builders" ]; + security.pam.enableSSHAgentAuth = true; # I can't think of a better spot to put this rn. services.openssh = { ports = [ 22 2200 ]; # needed because isp blocks ssh over 22 -- cgit v1.2.3 From c40e52fffc7202ba86e6c1ab478989d9dd10eabc Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Sat, 6 Apr 2024 15:34:30 -0600 Subject: switch to locked key --- modules/users/defin.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/modules/users/defin.nix b/modules/users/defin.nix index af7e0cb..9d38f7b 100644 --- a/modules/users/defin.nix +++ b/modules/users/defin.nix @@ -22,8 +22,8 @@ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHXrt3+N4+ahtXZCUn11evQsVGsGgAohGwafC29/a4fk defin@Radahn" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICkGcmYIYCe6GHsZZvnXqsedF0wn+AhGSr+RPJtUO/kl defin@khad" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEaMYXO9ghATyUPzyE7aD/XVVmK9UAexueoGEYAqPT4L defin@kebab" - #unlocked keys for remote build - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINUdE8ETBYb9Is4BVekdgC5wStzcnWilSRhDmwp0vSX9 root@zenbook" + # keys for remote build + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPLx3RgUgbE7THS7hRZypyudEKffj0ppwQfQuxIpPf8H root@zenbook" ]; }; }; -- cgit v1.2.3