diff options
| author | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-09-02 18:09:34 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-09-02 18:09:34 +0530 |
| commit | 4a1a196c4c08bd34226bc25bfefd0227ce53b092 (patch) | |
| tree | 334b47964b275ab54084c2eaaf9170fa1651143b | |
| parent | 1d7e16552cb230b0d35dcad01fb023990186c636 (diff) | |
| download | home-manager-config-4a1a196c4c08bd34226bc25bfefd0227ce53b092.tar.gz home-manager-config-4a1a196c4c08bd34226bc25bfefd0227ce53b092.zip | |
feat(security/gopass): options to add username and password for git remote
| -rw-r--r-- | modules/private/gopass.example.nix | 13 | ||||
| -rw-r--r-- | modules/security/gopass/default.nix | 23 | ||||
| -rw-r--r-- | users/arpit.nix | 1 |
3 files changed, 37 insertions, 0 deletions
diff --git a/modules/private/gopass.example.nix b/modules/private/gopass.example.nix new file mode 100644 index 0000000..2d783c9 --- /dev/null +++ b/modules/private/gopass.example.nix @@ -0,0 +1,13 @@ +# Gopass - Template for configuring gopass, specially syncing +{ ... }: +{ + config = { + security.gopass.sync = { + remote = "YOUR_REPOSITORY_URL"; + credential = { + username = "example"; + passwordGopassPath = "websites/github.com/example/tokens/calendar"; + }; + }; + }; +} diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index 4d223e9..5650c4b 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -47,6 +47,26 @@ in description = "The gopass-ssh-load script package."; }; }; + sync = { + enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory."; + remote = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured."; + }; + credential = { + username = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Username for HTTPS git authentication against the gopass remote."; + }; + passwordGopassPath = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "gopass entry path holding the password or token used."; + }; + }; + }; }; config = lib.mkMerge [ @@ -75,6 +95,9 @@ in tag = { gpgSign = false; }; + } + // lib.optionalAttrs (config.security.gopass.sync.credential.passwordGopassPath != null) { + credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f"; }; } ]; diff --git a/users/arpit.nix b/users/arpit.nix index 465d6e1..e03906f 100644 --- a/users/arpit.nix +++ b/users/arpit.nix @@ -5,6 +5,7 @@ ../modules/private/calcurse.nix ../modules/private/email.nix ../modules/private/git.nix + ../modules/private/gopass.nix ]; nixpkgs.config.allowUnfree = true; |
