Mirror the NixOS openssh config on system-manager: no password auth, no
root login, ed25519 host key only, and gabriel's authorized keys. Its
module runs Ubuntu's /usr/sbin/sshd, so PAM keeps working.
Also enable programs.ssh for system-wide known hosts, and teach the NixOS
side about system-manager hosts so they know electra.