diff --git a/.github/instructions/janus-host.instructions.md b/.github/instructions/janus-host.instructions.md index 7e6e6f2..567b281 100644 --- a/.github/instructions/janus-host.instructions.md +++ b/.github/instructions/janus-host.instructions.md @@ -24,7 +24,7 @@ When editing `modules/hosts/janus/default.nix`, preserve this composition unless - `nixos.mysops` with `sops.defaultSopsFile = ./secrets.yaml` for host-local encrypted CA runtime material. - `nixos.step-ca` to run the CA daemon and render `/etc/smallstep/ca.json` from Nix plus SOPS paths. - `nixos.step-client` to install Step trust bootstrap defaults and root CA material. -- `nixos.step-ssh-host` so Janus itself participates in SSH host certificate flow. +- `nixos.ssh-certs` so Janus itself participates in SSH host certificate flow. - `nixos.mtls` so Janus can issue and renew its own mTLS certificate bundle. ## Step CA Deployment Pattern @@ -83,7 +83,7 @@ Start with the smallest check that matches the change: 4. Rendered config: on the host, inspect `/etc/smallstep/ca.json` or `/etc/step-ca` paths without copying secret content into logs. 5. Service health: check `systemctl status step-ca.service`, `journalctl -u step-ca.service`, and `step ca health --ca-url https://janus.john-stream.com` after trust is bootstrapped. 6. Provisioners: use `step ca provisioner list` to confirm ACME, SSHPOP, and admin JWK availability. -7. SSH cert flow: use `ssh-host-cert-check`, `systemctl status step-ssh-host-renew.service`, and `systemctl status step-ssh-host-renew.timer`. +7. SSH cert flow: use `ssh-host-cert-check`, `systemctl status ssh-certs-renew.service`, and `systemctl status ssh-certs-renew.timer`. 8. mTLS flow: use `mtls-check`, `mtls-generate`, and `systemctl status mtls-renew.timer` for host certificate renewal issues. ## Change Safety Rules diff --git a/.github/instructions/soteria-host.instructions.md b/.github/instructions/soteria-host.instructions.md index 8628e65..091680f 100644 --- a/.github/instructions/soteria-host.instructions.md +++ b/.github/instructions/soteria-host.instructions.md @@ -19,31 +19,31 @@ Use this instruction when changing Soteria host wiring in `modules/hosts/soteria When editing `modules/hosts/soteria/default.nix`, preserve this composition unless the task explicitly changes architecture: -- Import `nixos.step-ssh-host` to enable host SSH cert integration. +- Import `nixos.ssh-certs` to enable host SSH cert integration. - Import `nixos.janus-ca` so Step client trust material and defaults remain available. - Import `nixos.restic-server` so the RESTic REST server implementation lives in the shared module rather than inline host wiring. -- Keep `step-ssh-host.hostname = hostname;` so cert principals match host naming. +- Keep `ssh-certs.hostname = hostname;` so cert principals match host naming. ## SSH Cert Mechanics On Soteria Soteria SSH certificate behavior is the result of multiple modules. Keep this flow intact: -1. `soteria/default.nix` imports `nixos.step-ssh-host` and sets `step-ssh-host.hostname = "soteria"` (via `hostname`). +1. `soteria/default.nix` imports `nixos.ssh-certs` and sets `ssh-certs.hostname = "soteria"` (via `hostname`). 2. `modules/services/step-ca/ssh-host.nix`: - Enables `ssh.certificates.enable = true`. - Requires `sops.secrets."janus/admin_jwk"` (provisioner credential) from Soteria's `secrets.yaml`. - Defines cert paths at `/etc/ssh/ssh_host_ed25519_key` and `/etc/ssh/ssh_host_ed25519_key-cert.pub`. - Exposes `ssh-host-cert-renew` and `ssh-host-cert-check` helper binaries. - - Schedules `step-ssh-host-renew.timer` every 4h with jitter. + - Schedules `ssh-certs-renew.timer` every 4h with jitter. 3. `modules/services/ssh.nix` consumes `ssh.certificates.enable` and configures OpenSSH to: - - Set `TrustedUserCAKeys = /etc/ssh/ssh_user_ca.pub`. + - Set `TrustedUserCAKeys = /etc/ssh/ssh_user_ca_key.pub`. - Set `HostCertificate = /etc/ssh/ssh_host_ed25519_key-cert.pub`. - - Install the trusted user CA file into `/etc/ssh/ssh_user_ca.pub`. + - Install the trusted user CA file into `/etc/ssh/ssh_user_ca_key.pub`. 4. `nixos.janus-ca` provides Step CA trust bootstrapping (`/etc/step-ca/defaults.json` and linked root CA material), allowing Step CLI operations to trust and reach the CA endpoint. Current implementation note: -- `step-ssh-host-renew.service` currently checks renewal state via `step ssh needs-renewal` and logs status. It does not directly invoke `ssh-host-cert-renew` in the service script. Preserve this behavior unless the task explicitly asks to change renewal execution semantics. +- `ssh-certs-renew.service` currently checks renewal state via `step ssh needs-renewal` and logs status. It does not directly invoke `ssh-host-cert-renew` in the service script. Preserve this behavior unless the task explicitly asks to change renewal execution semantics. ## SOPS/Secrets Mechanics On Soteria @@ -135,5 +135,5 @@ Current implementation note: - Do not rename the secret key `janus/admin_jwk` without updating all consumers. - Do not change SSH host key/cert filenames unless OpenSSH `HostKey`/`HostCertificate` paths are updated together. -- If changing hostnames or domains, update cert principals in `step-ssh-host` and corresponding SSH client targets together. -- If adding or removing `nixos.step-ssh-host`, explain impact on SSH cert issuance, renewal, and trust in the change summary. \ No newline at end of file +- If changing hostnames or domains, update cert principals in `ssh-certs` and corresponding SSH client targets together. +- If adding or removing `nixos.ssh-certs`, explain impact on SSH cert issuance, renewal, and trust in the change summary. \ No newline at end of file diff --git a/.github/instructions/step-ssh-host.instructions.md b/.github/instructions/step-ssh-host.instructions.md index b4e6b0b..20de2fb 100644 --- a/.github/instructions/step-ssh-host.instructions.md +++ b/.github/instructions/step-ssh-host.instructions.md @@ -12,8 +12,8 @@ Use this instruction when changing the shared NixOS module in modules/services/s - Keep this module reusable across hosts; do not hard-code host-local file paths beyond SSH system paths under /etc/ssh. - Preserve the option interface unless the task explicitly changes it: - - step-ssh-host.hostname (required host identity used for cert principals) - - step-ssh-host.provisioner (default: "admin") + - ssh-certs.hostname (required host identity used for cert principals) + - ssh-certs.provisioner (default: "admin") - Keep imports = [ inputs.self.modules.nixos.ssh ] so OpenSSH host certificate settings stay composed through the shared SSH module. ## Secret Key Contract @@ -29,7 +29,7 @@ When this module is enabled by a host, the host is expected to provide: - A working Step trust/bootstrap path (for example via janus-ca or equivalent trust material). - `sops.defaultSopsFile` containing `janus.admin_jwk` (or equivalent if contract is intentionally changed everywhere). -- `step-ssh-host.hostname` matching deployed host identity and DNS naming expectations. +- `ssh-certs.hostname` matching deployed host identity and DNS naming expectations. ## SSH Certificate Paths And Principals diff --git a/modules/hosts/janus/README.md b/modules/hosts/janus/README.md index d7dd0e5..598e595 100644 --- a/modules/hosts/janus/README.md +++ b/modules/hosts/janus/README.md @@ -34,7 +34,7 @@ If rotating provisioner password, also set: Secret source-of-truth after this split: - `modules/hosts/janus/secrets.yaml`: Janus runtime CA secrets (`ca_password`, `intermediate_ca_key`, `ssh_host_ca_key`, `ssh_user_ca_key`, `admin_provisioner_encrypted_key`) -- `keys/secrets.yaml`: shared Janus provisioner secret (`janus.admin_jwk`) consumed by `step-ssh-host` across hosts +- `keys/secrets.yaml`: shared Janus provisioner secret (`janus.admin_jwk`) consumed by `ssh-certs` across hosts Then update public artifacts in repo from generated output: @@ -54,14 +54,14 @@ ad hoc issuance commands first: ```shell systemctl status step-ca.service -systemctl status step-ssh-host-renew.service -systemctl status step-ssh-host-renew.timer +systemctl status ssh-certs-renew.service +systemctl status ssh-certs-renew.timer systemctl status mtls-bootstrap.service ssh-host-cert-check mtls-check ``` -`step-ssh-host-renew.service` issues the SSH host certificate when it is missing +`ssh-certs-renew.service` issues the SSH host certificate when it is missing or expiring. `mtls-bootstrap.service` issues the first Janus mTLS bundle only when the configured certificate files are absent or invalid; recurring mTLS renewal remains handled by `mtls-renew.timer`. diff --git a/modules/hosts/janus/default.nix b/modules/hosts/janus/default.nix index d147d29..ef0c178 100644 --- a/modules/hosts/janus/default.nix +++ b/modules/hosts/janus/default.nix @@ -10,7 +10,7 @@ in modules = with inputs.self.modules; [ nixos.lxc nixos.mysops - nixos.step-ssh-host + nixos.ssh-certs nixos.step-client nixos.step-ca inputs.home-manager.nixosModules.home-manager @@ -24,7 +24,7 @@ in "Step-CA" = "step-ca"; }; sops.defaultSopsFile = ./secrets.yaml; - step-ssh-host = { + ssh-certs = { hostname = hostname; extraPrincipals = [ ipv4 ipv6 ]; }; diff --git a/modules/hosts/john-pc/default.nix b/modules/hosts/john-pc/default.nix index 31dcaa9..b01d7ed 100644 --- a/modules/hosts/john-pc/default.nix +++ b/modules/hosts/john-pc/default.nix @@ -59,7 +59,7 @@ in ssh = { certificates.enable = true; knownHosts = [ - "@cert-authority fded:fb16:653e:25da:be24:11ff:fea0:753f ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBNug18oLH0vZxnibXJzMJvTWFPZTnSlhCDDVi+rHhgnIum6ZXQ4SF+VHOOAM5BbzZmMKitNJ5lcrGP15Eur7DzQ=" + "@cert-authority fded:fb16:653e:25da:be24:11ff:* ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBNug18oLH0vZxnibXJzMJvTWFPZTnSlhCDDVi+rHhgnIum6ZXQ4SF+VHOOAM5BbzZmMKitNJ5lcrGP15Eur7DzQ=" ]; matchSets = { certs = true; diff --git a/modules/hosts/soteria/default.nix b/modules/hosts/soteria/default.nix index a7b4e47..c2a7351 100644 --- a/modules/hosts/soteria/default.nix +++ b/modules/hosts/soteria/default.nix @@ -10,7 +10,7 @@ in nixos.lxc nixos.mysops nixos."${username}" - nixos.step-ssh-host + nixos.ssh-certs nixos.login-text nixos.docker nixos.mtls @@ -75,7 +75,7 @@ in "Restic REST Server" = "restic-rest-server.service"; }; - step-ssh-host.hostname = hostname; + ssh-certs.hostname = hostname; # This provides the secrets at install time sops.defaultSopsFile = ./secrets.yaml; diff --git a/modules/nixos/login-text.nix b/modules/nixos/login-text.nix index 8ead9dd..6bd3c2c 100644 --- a/modules/nixos/login-text.nix +++ b/modules/nixos/login-text.nix @@ -3,7 +3,7 @@ let defaultServiceStatus = { SSH = "sshd.socket"; - "SSH Cert Renewal" = "step-ssh-host-renew.timer"; + "SSH Cert Renewal" = "ssh-certs-renew.timer"; }; in { options.loginText.extraServiceStatus = lib.mkOption { diff --git a/modules/services/ssh.nix b/modules/services/ssh.nix index 94b7f96..686590a 100644 --- a/modules/services/ssh.nix +++ b/modules/services/ssh.nix @@ -48,7 +48,7 @@ in userCA = lib.mkOption { description = "Content for the SSH user CA file (public key)"; type = lib.types.path; - default = ../hosts/janus/ssh_user_ca_key.pub; + default = sshHostCAPubKeyPath; }; userCAFile = lib.mkOption { description = "String path to the SSh user CA"; @@ -139,10 +139,7 @@ in }; }; - # All this stuff has to be wrapped in a config attribute because of the presence of the options here? - config = let - provisionerPasswordPath = config.sops.secrets."janus/admin_jwk".path; - in { + config = { home.file.".ssh/known_hosts" = { text = lib.concatStringsSep "\n" ( cfg.knownHosts ++ lib.optionals cfg.certificates.enable [ @@ -198,7 +195,7 @@ in }) (lib.mkIf cfg.matchSets.certs { "janus" = { - HostName = "janus.john-stream.com"; + HostName = "fded:fb16:653e:25da:be24:11ff:fe6b:4d57"; User = "root"; }; "soteria" = { diff --git a/modules/services/step-ca/ssh-host.nix b/modules/services/step-ca/ssh-host.nix index e5c9e10..f26a5ff 100644 --- a/modules/services/step-ca/ssh-host.nix +++ b/modules/services/step-ca/ssh-host.nix @@ -1,7 +1,7 @@ { inputs, ... }: { - flake.modules.nixos.step-ssh-host = { config, pkgs, lib, ... }: + flake.modules.nixos.ssh-certs = { config, pkgs, lib, ... }: let - cfg = config.step-ssh-host; + cfg = config.ssh-certs; provisionerPasswordPath = config.sops.secrets."janus/admin_jwk".path; sshKeyPath = "/etc/ssh/ssh_host_ed25519_key"; sshCertPath = "${sshKeyPath}-cert.pub"; @@ -32,7 +32,7 @@ in { # NixOS Options - options.step-ssh-host = { + options.ssh-certs = { hostname = lib.mkOption { description = "Networking host name to register with the CA"; type = lib.types.str; @@ -68,9 +68,10 @@ sshHostCertCheck ]; - systemd.services.step-ssh-host-renew = { + systemd.services.ssh-certs-renew = { description = "Renew Step SSH host certificate if needed"; - wantedBy = [ ]; + wantedBy = [ "multi-user.target" ]; + before = [ "sshd.service" ]; after = [ "network-online.target" ]; wants = [ "network-online.target" ]; path = with pkgs; [ coreutils systemd step-cli openssh ]; @@ -112,7 +113,7 @@ ''; }; - systemd.timers.step-ssh-host-renew = { + systemd.timers.ssh-certs-renew = { description = "Periodic Step SSH host certificate renewal"; wantedBy = [ "timers.target" ]; @@ -121,9 +122,13 @@ OnUnitActiveSec = "4h"; RandomizedDelaySec = "15m"; Persistent = true; - Unit = "step-ssh-host-renew.service"; + Unit = "ssh-certs-renew.service"; }; }; + + # Ensure sshd waits for a cert reconciliation attempt at boot. + systemd.services.sshd.wants = [ "ssh-certs-renew.service" ]; + systemd.services.sshd.after = [ "ssh-certs-renew.service" ]; }; }; } \ No newline at end of file