Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

OpenSSH

Configures opinionated SSH server and client defaults.

Purpose

Provide a hardened, consistent SSH experience across hosts: ed25519-only host keys, no password authentication, automatically generated known-host entries, PAM ssh-agent authentication, and GatewayPorts = "clientspecified" so clients may request non-loopback forwarding binds when needed. That forwarding flexibility can expose tunnels beyond localhost if the client explicitly asks for it.

Entry Point

Options

core.openssh.enable

Typeboolean
Defaulttrue
Exampletrue

Whether to enable OpenSSH server and client opinionated configuration.


core.openssh.hostPrivateKeyPath

Typestring
Default"/var/lib/provisioning/ssh/ssh_host_ed25519_key"

Canonical path of the provisioned ed25519 host private key used by OpenSSH, SOPS age decryption, and server-to-server SSH.


Architecture / Services / Scope

When enabled, the module:

  • enables services.openssh with socket activation disabled so SSH runs as a traditional always-on service (avoiding disconnects during nixos-rebuild switch over SSH),
  • disables password authentication and sets PermitRootLogin = "prohibit-password",
  • configures the ed25519 host key from core.openssh.hostPrivateKeyPath, persists that file via host.persistence.files, and publishes the matching public key at /etc/ssh/ssh_host_ed25519_key.pub,
  • enables security.pam.sshAgentAuth,
  • adds the current host’s public host key to root’s authorized keys, and
  • generates programs.ssh.knownHosts entries for every host in outputs.nixosConfigurations.

Client configuration restricts host key algorithms and accepted public key types to ssh-ed25519.

Operational Notes / Assumptions

  • Module expects a matching host public key file to exist in the flake for each host.
  • The current host gets localhost as an extra known-host alias in the generated SSH client config.
  • Root authorization uses host key material from the flake, not per-user login keys.
  • Socket activation is disabled (startWhenNeeded = false): the default NixOS setup spawns per-connection sshd@...service instances, and restarting them during a configuration switch disconnects active SSH sessions. An always-on service prevents remote disconnection during nixos-rebuild switch.