{pkgs, ...}: { # The encrypted USB is NOT part of boot anymore # We do NOT use crypttab or systemd-cryptsetup units at all environment.systemPackages = with pkgs; [ cryptsetup # 🔓 Mount + unlock + load SSH key (writeShellScriptBin "keys-mount" '' set -e DEVICE="/dev/disk/by-uuid/da31e270-80d4-4a89-9633-87dd4d736ca2" NAME="ssh-keys" MNT="/mnt/ssh-keys" echo "🔐 Unlocking encrypted USB..." sudo cryptsetup open "$DEVICE" "$NAME" echo "📂 Mounting..." sudo mount "/dev/mapper/$NAME" "$MNT" echo "🔑 Adding SSH key..." ssh-add "$MNT/poseidon" ssh-add "$MNT/apollo" echo "✅ Done" '') # 🔒 Clean unmount + lock (writeShellScriptBin "keys-umount" '' set -e MNT="/mnt/ssh-keys" NAME="ssh-keys" echo "🔑 Removing SSH key..." ssh-add -d "$MNT/poseidon" 2>/dev/null || true ssh-add -d "$MNT/apollo" 2>/dev/null || true echo "📤 Unmounting..." sudo umount "$MNT" || true echo "🔒 Closing encrypted device..." sudo cryptsetup close "$NAME" || true echo "✅ Done" '') ]; }