From 80571337a8a21822449d1ca222677b3a6242ece4 Mon Sep 17 00:00:00 2001 From: Collin Williams <96917990+bluedragon1221@users.noreply.github.com> Date: Thu, 19 Mar 2026 12:09:12 -0500 Subject: just deploy as root (we're using safe ssh keys anyway) --- hosts/ganymede/config.nix | 1 + hosts/ganymede/nixos.nix | 26 -------------------------- pkgs/yo/default.nix | 4 ++-- 3 files changed, 3 insertions(+), 28 deletions(-) diff --git a/hosts/ganymede/config.nix b/hosts/ganymede/config.nix index bd990e8..6fe1e3e 100644 --- a/hosts/ganymede/config.nix +++ b/hosts/ganymede/config.nix @@ -64,6 +64,7 @@ { port = 22; listenAddr = "0.0.0.0"; + rootLogin = true; } ]; }; diff --git a/hosts/ganymede/nixos.nix b/hosts/ganymede/nixos.nix index 043f67a..a2314ee 100644 --- a/hosts/ganymede/nixos.nix +++ b/hosts/ganymede/nixos.nix @@ -59,32 +59,6 @@ }; }; - # deploy user - nix.settings.trusted-users = ["deploy"]; - users.groups."deploy" = {}; - users.users."deploy" = { - isSystemUser = true; - group = "deploy"; - shell = pkgs.bash; - - openssh.authorizedKeys.keys = config.users.users."collin".openssh.authorizedKeys.keys; - }; - security.sudo.extraRules = [ - { - users = ["deploy"]; - commands = [ - { - command = "/nix/store/*/bin/switch-to-configuration"; - options = ["NOPASSWD"]; - } - { - command = "/run/current-system/sw/bin/shutdown"; - options = ["NOPASSWD"]; - } - ]; - } - ]; - services.fail2ban.enable = true; programs.ssh.extraConfig = '' diff --git a/pkgs/yo/default.nix b/pkgs/yo/default.nix index 30a90f0..1423fdb 100644 --- a/pkgs/yo/default.nix +++ b/pkgs/yo/default.nix @@ -6,8 +6,8 @@ case ARGV[0] when "deploy", "dep" - hostname = ARGV[1] or abort "must specify hostname to build" - ssh_host = ARGV[2] or abort "must specify ssh host to target" + ssh_host = ARGV[1] or abort "must specify ssh target (host or user@host)" + hostname = ssh_host.include?("@") ? ssh_host.split("@", 2).last : ssh_host store_path = Nix.build_configuration( flake_path: FLAKE_PATH, -- cgit v1.3.1