gpg.nix (2179B)
1 # modules/home/gpg.nix — the GPG main key and gpg.conf, from the flake. 2 # 3 # public key modules/home/gpg/daemon-main.pub.asc → imported with ultimate trust (programs.gpg.publicKeys) 4 # secret key sops secret gpg_main_secret (the armored export, still under its own passphrase): 5 # imported into the keyring on activation if the keyring lacks it 6 # gpg.conf programs.gpg.settings (the gpg-cheat `setup` defaults) 7 # 8 # The agent itself is NixOS's (programs.gnupg.agent, pinentry-gnome3), so 9 # services.gpg-agent is deliberately not enabled here. 10 # Key: RSA 4096, 2025-12-30, the one on GitLab; fingerprint in modules/hosts/laptop/_identity.nix. 11 { ... }: 12 { 13 flake.homeModules.gpg = 14 { config, pkgs, lib, identity, ... }: 15 let 16 fpr = identity.gpgFingerprint; 17 in 18 { 19 sops.secrets.gpg_main_secret = { }; 20 21 programs.gpg = { 22 enable = true; 23 mutableKeys = true; # other people's keys and new subkeys stay editable 24 mutableTrust = true; 25 publicKeys = [ 26 { source = ./gpg/daemon-main.pub.asc; trust = 5; } 27 ]; 28 settings = { 29 default-key = fpr; 30 default-recipient-self = true; 31 keyid-format = "0xlong"; 32 with-fingerprint = true; 33 with-subkey-fingerprints = true; 34 personal-cipher-preferences = "AES256 AES192 AES"; 35 personal-digest-preferences = "SHA512 SHA384 SHA256"; 36 cert-digest-algo = "SHA512"; 37 no-emit-version = true; 38 no-comments = true; 39 keyserver = "hkps://keys.openpgp.org"; 40 auto-key-locate = "local,wkd"; 41 trust-model = "tofu+pgp"; 42 }; 43 }; 44 45 # Import the secret key once (idempotent: skipped when the keyring has it). 46 # Runs after sops-nix has decrypted the secrets. 47 home.activation.gpgMainKey = lib.hm.dag.entryAfter [ "sops-nix" ] '' 48 if [ -r "${config.sops.secrets.gpg_main_secret.path}" ] \ 49 && ! ${pkgs.gnupg}/bin/gpg --batch --list-secret-keys ${fpr} >/dev/null 2>&1; then 50 run ${pkgs.gnupg}/bin/gpg --batch --quiet --import "${config.sops.secrets.gpg_main_secret.path}" \ 51 && echo "gpg: imported the main secret key ${fpr}" 52 fi 53 ''; 54 } 55 ; 56 }