[Services/GnuPG] Move all configuration in dedicated file

This commit is contained in:
Antoine Viallon 2023-04-05 09:41:53 +02:00
parent 3fa8298db2
commit 9977f0c62d
Signed by: aviallon
GPG key ID: 186FC35EDEB25716
4 changed files with 35 additions and 32 deletions

View file

@ -2,5 +2,6 @@
{
imports = [
./jupyterhub.nix
./gnupg.nix
];
}

34
services/gnupg.nix Normal file
View file

@ -0,0 +1,34 @@
{ config, pkgs, lib, ... }:
with lib;
{
config = {
programs.gnupg = {
agent.enable = true;
dirmngr.enable = true;
agent.pinentryFlavor = "curses"; # overriden anyway
agent.enableSSHSupport = true;
agent.enableExtraSocket = true;
agent.enableBrowserSocket = true;
};
environment.shellInit = ''
export GPG_TTY="$(tty)"
gpg-connect-agent /bye
export SSH_AUTH_SOCK="/run/user/$UID/gnupg/S.gpg-agent.ssh"
'';
systemd.user.services.gpg-agent = let
pinentrySwitcher = pkgs.callPackage ../packages/pinentry.nix {};
cfg = config.programs.gnupg;
in {
restartTriggers = [ pinentrySwitcher ];
restartIfChanged = true;
serviceConfig.ExecStart = [ "" ''
${cfg.package}/bin/gpg-agent --supervised \
--pinentry-program ${pinentrySwitcher}/bin/pinentry
'' ];
};
};
}