Removed ssh password login

This commit is contained in:
Qubasa
2024-05-12 12:39:19 +02:00
parent 182b6f51f7
commit 9ccf712ce8
3 changed files with 12 additions and 20 deletions

View File

@@ -25,8 +25,7 @@ let
qrcode=$(gum style --border-foreground 240 --border normal "$(< /var/shared/qrcode.utf8)") qrcode=$(gum style --border-foreground 240 --border normal "$(< /var/shared/qrcode.utf8)")
msgs+=("$qrcode") msgs+=("$qrcode")
fi fi
network_status="Root password: $(cat /var/shared/root-password) network_status="Local network addresses:
Local network addresses:
$(ip -brief -color addr | grep -v 127.0.0.1) $(ip -brief -color addr | grep -v 127.0.0.1)
$([[ -e /var/shared/onion-hostname ]] && echo "Onion address: $(cat /var/shared/onion-hostname)" || echo "Onion address: Waiting for tor network to be ready...") $([[ -e /var/shared/onion-hostname ]] && echo "Onion address: $(cat /var/shared/onion-hostname)" || echo "Onion address: Waiting for tor network to be ready...")
Multicast DNS: $(hostname).local" Multicast DNS: $(hostname).local"
@@ -56,13 +55,8 @@ in
# https://github.com/nix-community/nixos-images/blob/main/nix/image-installer/module.nix#L46C3-L117C6 # # https://github.com/nix-community/nixos-images/blob/main/nix/image-installer/module.nix#L46C3-L117C6 #
# # # #
######################################################################################################## ########################################################################################################
systemd.tmpfiles.rules = [ "d /var/shared 0777 root root - -" ]; services.openssh.settings.PermitRootLogin = lib.mkForce "prohibit-password";
services.openssh.settings.PermitRootLogin = "yes";
system.activationScripts.root-password = ''
mkdir -p /var/shared
${pkgs.xkcdpass}/bin/xkcdpass --numwords 3 --delimiter - --count 1 > /var/shared/root-password
echo "root:$(cat /var/shared/root-password)" | chpasswd
'';
hidden-ssh-announce = { hidden-ssh-announce = {
enable = true; enable = true;
script = pkgs.writeShellScript "write-hostname" '' script = pkgs.writeShellScript "write-hostname" ''
@@ -83,10 +77,9 @@ in
echo "$1" > /var/shared/onion-hostname echo "$1" > /var/shared/onion-hostname
local_addrs=$(ip -json addr | jq '[map(.addr_info) | flatten | .[] | select(.scope == "global") | .local]') local_addrs=$(ip -json addr | jq '[map(.addr_info) | flatten | .[] | select(.scope == "global") | .local]')
jq -nc \ jq -nc \
--arg password "$(cat /var/shared/root-password)" \
--arg onion_address "$(cat /var/shared/onion-hostname)" \ --arg onion_address "$(cat /var/shared/onion-hostname)" \
--argjson local_addrs "$local_addrs" \ --argjson local_addrs "$local_addrs" \
'{ pass: $password, tor: $onion_address, addrs: $local_addrs }' \ '{ pass: null, tor: $onion_address, addrs: $local_addrs }' \
> /var/shared/login.json > /var/shared/login.json
cat /var/shared/login.json | qrencode -s 2 -m 2 -t utf8 -o /var/shared/qrcode.utf8 cat /var/shared/login.json | qrencode -s 2 -m 2 -t utf8 -o /var/shared/qrcode.utf8
''; '';

View File

@@ -191,6 +191,10 @@ def flash_command(args: argparse.Namespace) -> None:
if ask == "y": if ask == "y":
pubkeys = list_available_ssh_keys() pubkeys = list_available_ssh_keys()
root_keys.extend(read_public_key_contents(pubkeys)) root_keys.extend(read_public_key_contents(pubkeys))
else:
raise ClanError(
"No SSH public keys provided. Use --ssh-pubkey to add keys."
)
elif not opts.confirm and not root_keys: elif not opts.confirm and not root_keys:
pubkeys = list_available_ssh_keys() pubkeys = list_available_ssh_keys()
root_keys.extend(read_public_key_contents(pubkeys)) root_keys.extend(read_public_key_contents(pubkeys))

View File

@@ -20,12 +20,7 @@ let
}; };
}; };
installerModule = installerModule =
{ { config, modulesPath, ... }:
config,
pkgs,
modulesPath,
...
}:
{ {
imports = [ imports = [
wifiModule wifiModule
@@ -50,12 +45,12 @@ let
}; };
flashInstallerModule = flashInstallerModule =
{ config, pkgs, ... }: { config, ... }:
{ {
imports = [ imports = [
wifiModule wifiModule
self.nixosModules.installer self.nixosModules.installer
self.clanModules.diskLayouts self.clanModules.disk-layouts
]; ];
system.stateVersion = config.system.nixos.version; system.stateVersion = config.system.nixos.version;
nixpkgs.pkgs = self.inputs.nixpkgs.legacyPackages.x86_64-linux; nixpkgs.pkgs = self.inputs.nixpkgs.legacyPackages.x86_64-linux;
@@ -79,7 +74,7 @@ in
# This will include your ssh public keys in the installer. # This will include your ssh public keys in the installer.
machines.flash-installer = { machines.flash-installer = {
imports = [ flashInstallerModule ]; imports = [ flashInstallerModule ];
clan.diskLayouts.singleDiskExt4.device = lib.mkDefault "/dev/null"; clan.disk-layouts.singleDiskExt4.device = lib.mkDefault "/dev/null";
boot.loader.grub.enable = lib.mkDefault true; boot.loader.grub.enable = lib.mkDefault true;
}; };
}; };