Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
41 lines
1.6 KiB
Nix
41 lines
1.6 KiB
Nix
# User identity registry -- pure data, no machinery. Keyed by username.
|
|
#
|
|
# Each entry describes WHO a user is (display name, email, authorized/signing
|
|
# keys, supplementary groups). The reusable modules read this indirectly:
|
|
# - system: modules/users.nix builds users.users.* from `userRegistry`
|
|
# (specialArg) restricted to the host's `hostUsers` set.
|
|
# - home: home/git.nix and home/desktop.nix read the per-user `identity`
|
|
# module arg, which mkHost derives from the matching registry entry.
|
|
#
|
|
# The login name is injected by mkHost as `identity.username`, so it is not
|
|
# repeated inside each entry here.
|
|
{
|
|
lyrathorpe = {
|
|
fullName = "Lyra Thorpe";
|
|
email = "iam@emmathe.dev";
|
|
extraGroups = [
|
|
"wheel"
|
|
"docker"
|
|
];
|
|
sshAuthorizedKeys = [
|
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA"
|
|
];
|
|
signingKey = "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDxHvdMTOzpFWUFMtCP7C/4tIOUO3GIO2QPvaifSnWH lyrathorpe@Lyra-MBA";
|
|
};
|
|
|
|
emmathorpe = {
|
|
fullName = "Emma Thorpe";
|
|
email = "emma.thorpe@citrix.com";
|
|
extraGroups = [
|
|
"wheel"
|
|
"docker"
|
|
];
|
|
# No personal authorized key on file yet. The previous shared user module
|
|
# applied Lyra's key to every account, including this one -- a defect. Leave
|
|
# this empty until a real key is provisioned; SSH login is moot on the WSL
|
|
# host (entered via wsl.exe, not sshd).
|
|
sshAuthorizedKeys = [ ];
|
|
signingKey = "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAJMVgeRKnfX1G8coU3nAobI485aeUpGTMqH7+zbKI8o emma.thorpe@cloud.com";
|
|
};
|
|
}
|