Files
nixfiles/users/emmathorpe/work.nix
T
Emma ThorpeandClaude Opus 5 10f713103c
CI / flake (push) Skipped
CI / flake (pull_request) Successful in 3m57s
feat(work): headless Secret Service for gcx keychain tokens
gcx stores its OAuth access and refresh tokens in the system keychain
unconditionally -- its config file keeps only opaque `keychain:gcx:v2:...`
handles -- and exposes no plaintext fallback. With nothing owning
org.freedesktop.secrets on this headless WSL box, `gcx login` authenticates
against Grafana and then dies writing its config: "The name is not activatable".

Add services.headlessSecretService: gnome-keyring as a systemd --user service,
unlocking the login keyring at start. home-manager's own services.gnome-keyring
does not fit here on two counts -- it is WantedBy graphical-session-pre.target,
which never activates without a desktop session, and it passes no --unlock, so
writes would block on a GUI prompter that does not exist.

Only the secrets component is started. The ssh component is deliberately off: it
would claim SSH_AUTH_SOCK and displace services.ssh-agent, breaking SSH auth and
signed commits.

The unlock password defaults to a random one generated on first activation under
$XDG_DATA_HOME. The passwordFile option is the seam for supplying it from an
agenix secret instead, once that lands.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-11 15:03:18 +01:00

93 lines
3.2 KiB
Nix

# Work (EDaaS/WSL) home profile: corporate toolchain + tmux tweaks. Git identity
# comes from the registry (users/registry.nix), not here.
{
pkgs,
lib,
inputs,
...
}:
{
# Host-scoped extras for this machine only (the EDaaS/WSL host).
imports = [
./renovate-review.nix # daily headless Renovate PR review (systemd user timer)
];
# The work box keeps its own (corporate) ~/.ssh/config; don't let the personal
# programs.ssh (shell.nix) take it over. The ssh-agent below still runs.
programs.ssh.enable = lib.mkForce false;
home.packages = [
pkgs.kubectl
pkgs.argo-rollouts
pkgs.tenv
pkgs.kubernetes-helm
pkgs.azure-cli
pkgs.kubelogin
pkgs.curl
pkgs.notation
pkgs.powershell
pkgs.nuget
pkgs.gedit
pkgs.python3
pkgs.gnumake
pkgs.gcc
pkgs.libiconv
pkgs.autoconf
pkgs.automake
pkgs.pkg-config
pkgs.wget
pkgs.google-cloud-sdk
# Day-to-day Kubernetes / Helm / Terraform accelerators for this box.
pkgs.k9s # cluster TUI
pkgs.kubectx # kubectx + kubens (context/namespace switch)
pkgs.stern # multi-pod log tail
pkgs.dyff # semantic YAML/manifest diffs (Helm release drift)
pkgs.tflint # Terraform linter (catches what terraformls won't)
pkgs.terraform-docs # generate Terraform module docs
pkgs.yq-go # jq for YAML
pkgs.gcx # Grafana Cloud CLI (dashboards, SLOs, synthetics, alerts)
];
services.ssh-agent.enable = true;
# gcx (above) keeps its OAuth tokens in the system keychain and has no
# plaintext fallback, so this WSL box needs something owning
# org.freedesktop.secrets. See home/secret-service.nix for why
# home-manager's services.gnome-keyring cannot be used on a headless host,
# and for the security trade-off of an auto-unlocked keyring.
services.headlessSecretService.enable = true;
home.shellAliases = {
docker = "/run/current-system/sw/bin/docker";
};
# Source the (nix-unmanaged) Jenkins credentials file into every zsh, so the
# JENKINS_UCE_/JENKINS_STF_ tokens are exported for all shells and anything they
# launch -- the Jenkins MCP servers read them via ${JENKINS_*} expansion.
# envExtra lands in ~/.zshenv, which zsh sources for login, interactive, and
# non-interactive shells alike. Guarded so a missing file never breaks a shell;
# the file holds secrets, so it is kept out of the world-readable nix store.
programs.zsh.envExtra = ''
[ -f "$HOME/.jenkinsenv" ] && . "$HOME/.jenkinsenv"
[ -f "$HOME/.splunkenv" ] && . "$HOME/.splunkenv"
'';
programs.tmux = {
# kube context/namespace in the status line. kube-tmux is pinned as a flake
# input (it is not in nixpkgs), so the script is always present in the store.
extraConfig = ''
set -g status-right "#(${pkgs.bash}/bin/bash ${inputs.kube-tmux}/kube.tmux 250 red black)"
'';
};
programs.go = {
enable = true;
};
# LSP servers only relevant to work: C# (omnisharp) and Helm charts (helm_ls).
# The shared editor (home/editor.nix) carries the universal ones;
# these are gated to this host so the heavy omnisharp closure stays off the
# personal machines. Tree-sitter grammars (highlighting) remain global there.
programs.nixvim.plugins.lsp.servers = {
omnisharp.enable = true;
helm_ls.enable = true;
};
}