I've been very pleasantly surprised by how easy it was to get everything set up on NixOS:
``` programs.gnupg.agent = { enable = true; enableSSHSupport = true; };
services.udev.packages = [ pkgs.yubikey-personalization pkgs.libu2f-host ]; services.pcscd.enable = true;
environment.shellInit = '' export GPG_TTY="$(tty)" gpg-connect-agent /bye export SSH_AUTH_SOCK="/run/user/$UID/gnupg/S.gpg-agent.ssh" ''; ```
The only surprise I had was that I forgot to tell gpg to trust the imported key after I imported it.
Combine this with GoPass... its the start of something good :)