Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

SSH

Home Manager writes SSH host entries for GitHub, Codeberg, Tangled, Forgejo, and the Tangled Knot. On NixOS, identities come from SOPS-Nix paths under /run/secrets.

Host aliases

HostUserIdentityPurpose
github.comgitkeys_ghGitHub remotes
codeberg.orggitkeys_codebergCodeberg remotes
tangled.shgitkeys_tangledTangled hosted remotes
knot.desertthunder.devgitkeys_tangledKnot host
nix-baxcalibur-knotgitkeys_tangledTailnet Tangled Knot remotes

The shared config sets IdentitiesOnly yes and AddKeysToAgent no.

Secret paths

EnvironmentPath style
NixOS/run/secrets/keys_*
Non-NixOS~/.local/share/sops/keys_*

See Secrets for extraction and permissions. This page should not duplicate the SOPS workflow.

Validate

CheckCommand
GitHub authssh -T git@github.com
Codeberg authssh -T git@codeberg.org
Tangled authssh -T git@tangled.sh
Knot over tailnetssh -T nix-baxcalibur-knot
Debug identity choicessh -vT git@github.com

When debugging, look for Offering public key and confirm the path matches the configured identity.