This is equivalent to setting users.extraUsers.nix-cache.openssh.authorizedKeys.keys.
ForceCommand ensures that we always run nix-store --serve, so there is no need to check SSH_ORIGINAL_COMMAND.