OpenSSH
Configures opinionated SSH server and client defaults.
Purpose
Provide a hardened, consistent SSH experience across hosts: ed25519-only host keys, no password authentication, automatically generated known-host entries, PAM ssh-agent authentication, and GatewayPorts = "clientspecified" so clients may request non-loopback forwarding binds when needed. That forwarding flexibility can expose tunnels beyond localhost if the client explicitly asks for it.
Entry Point
- Main file: openssh.nix
Options
core.openssh.enable
| Type | boolean |
| Default | true |
| Example | true |
Whether to enable OpenSSH server and client opinionated configuration.
core.openssh.hostPrivateKeyPath
| Type | string |
| Default | "/var/lib/provisioning/ssh/ssh_host_ed25519_key" |
Canonical path of the provisioned ed25519 host private key used by OpenSSH, SOPS age decryption, and server-to-server SSH.
Architecture / Services / Scope
When enabled, the module:
- enables
services.opensshwith socket activation disabled so SSH runs as a traditional always-on service (avoiding disconnects duringnixos-rebuild switchover SSH), - disables password authentication and sets
PermitRootLogin = "prohibit-password", - configures the ed25519 host key from
core.openssh.hostPrivateKeyPath, persists that file viahost.persistence.files, and publishes the matching public key at/etc/ssh/ssh_host_ed25519_key.pub, - enables
security.pam.sshAgentAuth, - adds the current host’s public host key to root’s authorized keys, and
- generates
programs.ssh.knownHostsentries for every host inoutputs.nixosConfigurations.
Client configuration restricts host key algorithms and accepted public key types to ssh-ed25519.
Operational Notes / Assumptions
- Module expects a matching host public key file to exist in the flake for each host.
- The current host gets
localhostas an extra known-host alias in the generated SSH client config. - Root authorization uses host key material from the flake, not per-user login keys.
- Socket activation is disabled (
startWhenNeeded = false): the default NixOS setup spawns per-connectionsshd@...serviceinstances, and restarting them during a configuration switch disconnects active SSH sessions. An always-on service prevents remote disconnection duringnixos-rebuild switch.