add host assert sshd
This commit is contained in:
@@ -1,12 +1,11 @@
|
|||||||
{ hyper, secrets, ... }:
|
{ ... }@all: with all; {
|
||||||
|
|
||||||
{
|
|
||||||
environment.etc."ssh/ssh_host_ed25519_key.pub".text = if (hyper.host == "NxNORTH") then
|
environment.etc."ssh/ssh_host_ed25519_key.pub".text = if (hyper.host == "NxNORTH") then
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF1r5gUQPPS/dGB0SsvWtP6WdNWoxMwhhHRrqlO19cJt root@NxNORTH"
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF1r5gUQPPS/dGB0SsvWtP6WdNWoxMwhhHRrqlO19cJt root@NxNORTH"
|
||||||
else if ( hyper.host == "NxXPS" ) then
|
else if ( hyper.host == "NxXPS" ) then
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPf+08+t8a0lY2+nR1mhIU3vuksStiJOlojJjzCwFk7r root@NxXPS"
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPf+08+t8a0lY2+nR1mhIU3vuksStiJOlojJjzCwFk7r root@NxXPS"
|
||||||
else
|
else if ( hyper.host == "NxACE" ) then
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBFfZpWVPlujsz3FklSVAM+tuYn4pzDSijhp5CeYNOZk root@NxACE";
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBFfZpWVPlujsz3FklSVAM+tuYn4pzDSijhp5CeYNOZk root@NxACE"
|
||||||
|
else (assert 1==2; "");
|
||||||
sops.secrets."ssh/${hyper.host}-ssh_host_ed25519_key" = {
|
sops.secrets."ssh/${hyper.host}-ssh_host_ed25519_key" = {
|
||||||
mode = "0600";
|
mode = "0600";
|
||||||
path = "/etc/ssh/ssh_host_ed25519_key.shadow";
|
path = "/etc/ssh/ssh_host_ed25519_key.shadow";
|
||||||
@@ -19,5 +18,6 @@
|
|||||||
PrintLastLog = false;
|
PrintLastLog = false;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
# users authorized keys are set in users.nix
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user