Merge branch 'worktree-ipa-client-module'

This commit is contained in:
2026-07-28 09:48:55 +10:00
3 changed files with 25 additions and 2 deletions
+10
View File
@@ -127,6 +127,16 @@ creation_rules:
# scripts/secrets/sync-host-keys.sh yet, so whichever variant is actually # scripts/secrets/sync-host-keys.sh yet, so whichever variant is actually
# deployed next needs its recipient added here (and `sops updatekeys` rerun) # deployed next needs its recipient added here (and `sops updatekeys` rerun)
# before it can decrypt this. # before it can decrypt this.
# Host keytab for tailscale-router FreeIPA enrollment (binary sops file).
# Generated by scripts/ipa/create-nixos-ipa-host-account.sh.
- path_regex: secrets/tailscale-router\.keytab$
key_groups:
- age:
- *admin
- *lxc-tailscale-router
- *proxmox-tailscale-router
- *linode-tailscale-router
- path_regex: secrets/gui\.yaml$ - path_regex: secrets/gui\.yaml$
key_groups: key_groups:
- age: - age:
+2 -2
View File
@@ -8,13 +8,13 @@
}) })
(import ../../modules/ipa/client.nix { (import ../../modules/ipa/client.nix {
keytabSopsFile = ../../secrets/tailscale-router.keytab; keytabSopsFile = ../../secrets/tailscale-router.keytab;
caCertFile = ../../certs/ipa-ca.crt; caCertFile = ../../certs/ipa-ca.crt;
}) })
]; ];
networking = { networking = {
hostName = "tailscale-router"; hostName = "tailscale-router";
domain = vars.homeDomain;
useDHCP = false; useDHCP = false;
interfaces.${vars.lxcLanInterface}.ipv4.addresses = [{ interfaces.${vars.lxcLanInterface}.ipv4.addresses = [{
address = vars.tailscaleRouterIp; address = vars.tailscaleRouterIp;
+13
View File
@@ -60,6 +60,19 @@ in
cacheCredentials = true; cacheCredentials = true;
}; };
# Fetch SSH public keys from IPA so users can log in with the key stored
# in their IPA profile rather than needing ~/.ssh/authorized_keys on every
# host. sss_ssh_authorizedkeys queries SSSD (which queries IPA LDAP).
services.openssh.extraConfig = ''
AuthorizedKeysCommand ${pkgs.sssd}/bin/sss_ssh_authorizedkeys %u
AuthorizedKeysCommandUser nobody
'';
# Create the home directory on first login if it doesn't exist yet.
# IPA users have no pre-created home on the host; without this sshd
# opens a session to a non-existent directory and resets the connection.
security.pam.services.sshd.makeHomeDir = true;
# Host keytab: pre-provisioned on the IPA server, sops-encrypted binary. # Host keytab: pre-provisioned on the IPA server, sops-encrypted binary.
# Placed at /etc/krb5.keytab before SSSD starts so the host authenticates # Placed at /etc/krb5.keytab before SSSD starts so the host authenticates
# to IPA without running ipa-client-install. # to IPA without running ipa-client-install.