NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

gpg.nix (2179B)


      1 # modules/home/gpg.nix — the GPG main key and gpg.conf, from the flake.
      2 #
      3 #   public key   modules/home/gpg/daemon-main.pub.asc → imported with ultimate trust (programs.gpg.publicKeys)
      4 #   secret key   sops secret gpg_main_secret (the armored export, still under its own passphrase):
      5 #                imported into the keyring on activation if the keyring lacks it
      6 #   gpg.conf     programs.gpg.settings (the gpg-cheat `setup` defaults)
      7 #
      8 # The agent itself is NixOS's (programs.gnupg.agent, pinentry-gnome3), so
      9 # services.gpg-agent is deliberately not enabled here.
     10 # Key: RSA 4096, 2025-12-30, the one on GitLab; fingerprint in modules/hosts/laptop/_identity.nix.
     11 { ... }:
     12 {
     13   flake.homeModules.gpg =
     14   { config, pkgs, lib, identity, ... }:
     15   let
     16     fpr = identity.gpgFingerprint;
     17   in
     18   {
     19     sops.secrets.gpg_main_secret = { };
     20 
     21     programs.gpg = {
     22       enable = true;
     23       mutableKeys = true; # other people's keys and new subkeys stay editable
     24       mutableTrust = true;
     25       publicKeys = [
     26         { source = ./gpg/daemon-main.pub.asc; trust = 5; }
     27       ];
     28       settings = {
     29         default-key = fpr;
     30         default-recipient-self = true;
     31         keyid-format = "0xlong";
     32         with-fingerprint = true;
     33         with-subkey-fingerprints = true;
     34         personal-cipher-preferences = "AES256 AES192 AES";
     35         personal-digest-preferences = "SHA512 SHA384 SHA256";
     36         cert-digest-algo = "SHA512";
     37         no-emit-version = true;
     38         no-comments = true;
     39         keyserver = "hkps://keys.openpgp.org";
     40         auto-key-locate = "local,wkd";
     41         trust-model = "tofu+pgp";
     42       };
     43     };
     44 
     45     # Import the secret key once (idempotent: skipped when the keyring has it).
     46     # Runs after sops-nix has decrypted the secrets.
     47     home.activation.gpgMainKey = lib.hm.dag.entryAfter [ "sops-nix" ] ''
     48       if [ -r "${config.sops.secrets.gpg_main_secret.path}" ] \
     49          && ! ${pkgs.gnupg}/bin/gpg --batch --list-secret-keys ${fpr} >/dev/null 2>&1; then
     50         run ${pkgs.gnupg}/bin/gpg --batch --quiet --import "${config.sops.secrets.gpg_main_secret.path}" \
     51           && echo "gpg: imported the main secret key ${fpr}"
     52       fi
     53     '';
     54   }
     55   ;
     56 }