# roles/thin-client/identity/local-users.nix # # Local break-glass users for Thin Clients. These exist independently of # AD/DNS/NetBird availability. Used for disaster recovery via NetBird SSH. # # NOTE: This intentionally does NOT import the m3ta-home profile system # from hosts/common/users/. Thin Clients are not dev machines and don't # need home-manager profiles — just a lean account with password, SSH key, # and wheel membership. { config, lib, ... }: let inherit (lib) mkIf; cfg = config.az.tc; in { config = mkIf cfg.enable { users.users."sascha.koenig" = { # Re-uses the existing hashedPassword from hosts/common/users/sascha.koenig.nix hashedPassword = "$y$j9T$ORX4btVZgs9Xjq2oIvzJm0$lXiPwaa0D6t.eMDIx1UBesEAMOkWXBoGwpeI7X0aS8D"; isNormalUser = true; shell = config.users.defaultUserShell; extraGroups = ["wheel" "networkmanager" "plugdev" "input"]; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEZbg/Z9mnflXuLahGY8WOSBMqbgeqVIkIwRkquys1Ml sascha.koenig@azintec.com" ]; }; users.users."jannik.mueller" = { # Re-uses the existing hashedPassword from hosts/common/users/jannik.mueller.nix hashedPassword = "$y$j9T$09RgD3AU3PK9Oi6JGLe0V1$i8J2ZOD1h1b6Zpw28ub.kExujoDKHzokeXzkM23Tfd/"; isNormalUser = true; shell = config.users.defaultUserShell; extraGroups = ["wheel" "networkmanager" "plugdev" "input"]; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPvZazSuIoWoRWhkAqQDMLeurxVUyy1MTllp1wfw1tzq" ]; }; }; }