Commit Diff


commit - b614376fa8156d2ebee9daeda7069ace5c890043
commit + 4af61d4412a45612c07e0915bcae9f78a32e9c65
blob - /dev/null
blob + 295ce4da959fdad1d56c9f880bee60a753ca3688 (mode 644)
--- /dev/null
+++ system/home.scm
@@ -0,0 +1,107 @@
+;; system/home.scm
+;;
+;; Guix Home — usuario richard (Nitro 5)
+;; Gestiona .bashrc, gpg-agent.conf y paquetes de usuario.
+;;
+;; Aplicar después de instalar el sistema:
+;;   guix home reconfigure system/home.scm
+;;
+;; Primera vez (en la instalación):
+;;   guix home init system/home.scm
+
+(use-modules
+  (gnu home)
+  (gnu home services)
+  (gnu home services shells)
+  (gnu packages)
+  (guix gexp))
+
+;; ══════════════════════════════════════════════════════════════════
+;; Contenido de ~/.bashrc — bloque YubiKey / gpg-agent
+;; ══════════════════════════════════════════════════════════════════
+
+(define %yubikey-bashrc
+  (plain-file "yubikey-gpg-agent"
+    "\
+# ── YubiKey: gpg-agent como agente SSH ──────────────────────────────
+# Necesario para firmar commits y autenticar SSH con la llave del YubiKey.
+export GPG_TTY=$(tty)
+export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)
+export DISPLAY=${DISPLAY:-:0}
+export WAYLAND_DISPLAY=${WAYLAND_DISPLAY:-wayland-0}
+gpgconf --launch gpg-agent
+
+# Resetea gpg-agent y refresca el contexto de pinentry.
+# Correr si GPG o SSH falla tras desconectar/reconectar el YubiKey.
+yubico() {
+    echo \"Reiniciando gpg-agent...\"
+    gpgconf --kill gpg-agent
+    export GPG_TTY=$(tty)
+    export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)
+    export DISPLAY=${DISPLAY:-:0}
+    export WAYLAND_DISPLAY=${WAYLAND_DISPLAY:-wayland-0}
+    gpgconf --launch gpg-agent
+    # Notifica al nuevo agente el TTY/display para que pinentry funcione en SSH
+    gpg-connect-agent updatestartuptty /bye &>/dev/null
+    if ssh-add -L &>/dev/null; then
+        echo \"OK — YubiKey lista\"
+    else
+        echo \"Error: no se detecta la clave. ¿Está conectada la YubiKey?\"
+    fi
+}
+"))
+
+;; ══════════════════════════════════════════════════════════════════
+;; ~/.gnupg/gpg-agent.conf
+;; ══════════════════════════════════════════════════════════════════
+
+(define %gpg-agent-conf
+  (plain-file "gpg-agent.conf"
+    "\
+# Habilita soporte SSH — SSH_AUTH_SOCK apunta al socket de gpg-agent
+enable-ssh-support
+
+# Tiempo de caché del PIN en segundos (10 min / 2 h máximo)
+default-cache-ttl 600
+max-cache-ttl     7200
+
+# pinentry-qt: diálogo gráfico para KDE Plasma
+# gpg-agent lo localiza via PATH del perfil de usuario
+pinentry-program pinentry-qt
+"))
+
+;; ══════════════════════════════════════════════════════════════════
+;; Home environment
+;; ══════════════════════════════════════════════════════════════════
+
+(home-environment
+
+  ;; ── Paquetes de usuario ────────────────────────────────────────
+  (packages
+    (map specification->package
+         '(;; GPG / YubiKey
+           "gnupg"
+           "pinentry-qt"          ; diálogo PIN para KDE Plasma
+           "openssh"              ; ssh, ssh-add, ssh-keygen
+
+           ;; Herramientas de desarrollo
+           "git"
+           "neovim"
+           "python"
+
+           ;; Diagnóstico GPU
+           "mesa-utils"           ; glxinfo, glxgears
+           "vulkan-tools")))      ; vulkaninfo
+
+  ;; ── Servicios ─────────────────────────────────────────────────
+  (services
+    (list
+
+      ;; ── bash: YubiKey/gpg-agent ─────────────────────────────
+      (service home-bash-service-type
+               (home-bash-configuration
+                 (bashrc (list %yubikey-bashrc))))
+
+      ;; ── gpg-agent.conf ──────────────────────────────────────
+      (service home-files-service-type
+               `((".gnupg/gpg-agent.conf" ,%gpg-agent-conf))))))