users.nix
1# hosts/common/users.nix
2# Shared user accounts across all hosts
3{ config, lib, pkgs, ... }@args:
4let
5 flakeRoot = args.flakeRoot or ./../..;
6in
7{
8 users.users = {
9 # Root account with SSH keys: the fleet's admin keys (keys/admins.pub,
10 # what Colmena deploys with) plus the original scooter key.
11 root = {
12 openssh.authorizedKeys.keyFiles = [ ../../keys/admins.pub ];
13 openssh.authorizedKeys.keys = [
14 "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJBc3G95VyLjrA2cnUjRnWRV3Uf3x08hxKkPw6ufY9YD scooter@rtw.run"
15 ];
16 };
17
18 # btburke user with SSH key, sudo access, and a password hash from the
19 # secrets store
20 btburke = {
21 isNormalUser = true;
22 home = "/home/btburke";
23 description = "btburke";
24 extraGroups = [ "wheel" ];
25
26 # With mutableUsers (the default here) NixOS keeps an existing user's
27 # password; this file sets it only when the user is created.
28 hashedPasswordFile = config.servers.secrets."btburke-password-hash".path;
29
30 # SSH public key for login
31 openssh.authorizedKeys.keys = [
32 "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJBc3G95VyLjrA2cnUjRnWRV3Uf3x08hxKkPw6ufY9YD scooter@rtw.run"
33 ];
34 };
35 };
36
37 # Sudo configuration
38 security.sudo = {
39 enable = true;
40 wheelNeedsPassword = true;
41 };
42}