users.nix

 1# hosts/common/users.nix
 2# Shared user accounts across all hosts
 3{ config, lib, pkgs, ... }@args:
 4let
 5  flakeRoot = args.flakeRoot or ./../..;
 6in
 7{
 8  users.users = {
 9    # Root account with SSH keys: the fleet's admin keys (keys/admins.pub,
10    # what Colmena deploys with) plus the original scooter key.
11    root = {
12      openssh.authorizedKeys.keyFiles = [ ../../keys/admins.pub ];
13      openssh.authorizedKeys.keys = [
14        "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJBc3G95VyLjrA2cnUjRnWRV3Uf3x08hxKkPw6ufY9YD scooter@rtw.run"
15      ];
16    };
17
18    # btburke user with SSH key, sudo access, and a password hash from the
19    # secrets store
20    btburke = {
21      isNormalUser = true;
22      home = "/home/btburke";
23      description = "btburke";
24      extraGroups = [ "wheel" ];
25
26      # With mutableUsers (the default here) NixOS keeps an existing user's
27      # password; this file sets it only when the user is created.
28      hashedPasswordFile = config.servers.secrets."btburke-password-hash".path;
29
30      # SSH public key for login
31      openssh.authorizedKeys.keys = [
32        "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJBc3G95VyLjrA2cnUjRnWRV3Uf3x08hxKkPw6ufY9YD scooter@rtw.run"
33      ];
34    };
35  };
36
37  # Sudo configuration
38  security.sudo = {
39    enable = true;
40    wheelNeedsPassword = true;
41  };
42}