add endlessh-go autometic setup (#32)
This commit is contained in:
parent
a05be0f2d3
commit
d7f026b05b
@ -2,8 +2,8 @@
|
|||||||
{ config, lib, ... }:
|
{ config, lib, ... }:
|
||||||
{
|
{
|
||||||
config = {
|
config = {
|
||||||
services = lib.mkIf config.services.gitea.enable {
|
services = {
|
||||||
openssh = {
|
openssh = lib.mkIf config.services.gitea.enable {
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
Match User gitea
|
Match User gitea
|
||||||
AllowAgentForwarding no
|
AllowAgentForwarding no
|
||||||
@ -13,14 +13,19 @@
|
|||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|
||||||
gitea.settings."ssh.minimum_key_sizes" = {
|
gitea.settings."ssh.minimum_key_sizes" = lib.mkIf config.services.gitea.enable {
|
||||||
ECDSA = -1;
|
ECDSA = -1;
|
||||||
RSA = 4095;
|
RSA = 4095;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
endlessh-go = lib.mkIf (!builtins.elem 22 config.services.openssh.ports) {
|
||||||
|
enable = true;
|
||||||
|
port = 22;
|
||||||
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
networking.firewall = lib.mkIf config.services.openssh.enable {
|
networking.firewall = lib.mkIf config.services.openssh.enable {
|
||||||
allowedTCPPorts = config.services.openssh.ports;
|
allowedTCPPorts = config.services.openssh.ports ++ [ 22 ];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
Loading…
x
Reference in New Issue
Block a user