diff options
| author | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-07-24 21:53:14 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-07-24 21:53:14 +0530 |
| commit | 57dc86b062d73446de2f26875ee7b950f1db8ea3 (patch) | |
| tree | fb341d50baeed327862c90aa1ccca123397c3867 | |
| parent | 5032239a236595451f22ea948c42281f8aa04645 (diff) | |
| download | home-manager-config-57dc86b062d73446de2f26875ee7b950f1db8ea3.tar.gz home-manager-config-57dc86b062d73446de2f26875ee7b950f1db8ea3.zip | |
feat(gopass): load SSH keys from gopass for git platforms
- Add security.gopass.ssh-agent.enable option
- Create gopass-ssh-load systemd oneshot service
- Remove identityFile and placeholder files from SSH git host configs
- Enable ssh-agent for the user
| -rw-r--r-- | modules/security/gopass/default.nix | 55 | ||||
| -rw-r--r-- | modules/security/ssh/git.nix | 38 | ||||
| -rw-r--r-- | users/arpit.nix | 1 |
3 files changed, 60 insertions, 34 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index 19191ff..a121022 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -8,15 +8,16 @@ { options.security.gopass = { enable = lib.mkEnableOption "Enables gopass."; - package = lib.mkOption { type = lib.types.package; default = pkgs.gopass.override { passAlias = true; }; defaultText = lib.literalExpression "pkgs.gopass.override { passAlias = true; }"; description = "The gopass package to use."; }; + ssh-agent = { + enable = lib.mkEnableOption "gopass-backed SSH keys for git"; + }; }; - config = lib.mkIf config.security.gopass.enable { programs.password-store = { enable = true; @@ -25,5 +26,55 @@ PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass"; }; }; + systemd.user.services.gopass-ssh-load = lib.mkIf config.security.gopass.ssh-agent.enable { + Unit = { + Description = "Load SSH keys from gopass into SSH agent for git"; + After = [ + "gpg-agent.socket" + "graphical-session.target" + ]; + Requires = [ + "gpg-agent.socket" + ]; + PartOf = [ + "graphical-session.target" + ]; + }; + Service = { + Type = "oneshot"; + ExecStart = "${pkgs.writeShellScript "gopass-ssh-load" '' + export SSH_AUTH_SOCK="$(${pkgs.gnupg}/bin/gpgconf --list-dirs agent-ssh-socket)" + + if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then + exit 1 + fi + + for key in github gitlab bitbucket codeberg sourcehut; do + if ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > /dev/null 2>&1; then + tmpdir=$(mktemp -d) + keyfile="$tmpdir/key" + ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > "$keyfile" 2>/dev/null + chmod 600 "$keyfile" + if ! ${pkgs.openssh}/bin/ssh-add "$keyfile" 2>/dev/null; then + passphrase=$(${config.security.gopass.package}/bin/gopass cat "ssh/$key/passphrase" 2>/dev/null) + if [ -n "$passphrase" ]; then + tmpcopy=$(mktemp) + cp "$keyfile" "$tmpcopy" + chmod 600 "$tmpcopy" + if ${pkgs.openssh}/bin/ssh-keygen -p -P "$passphrase" -N "" -f "$tmpcopy" 2>/dev/null; then + ${pkgs.openssh}/bin/ssh-add "$tmpcopy" 2>/dev/null + fi + rm -f "$tmpcopy" + fi + fi + rm -rf "$tmpdir" + fi + done + ''}"; + }; + Install = { + WantedBy = [ "graphical-session.target" ]; + }; + }; }; } diff --git a/modules/security/ssh/git.nix b/modules/security/ssh/git.nix index 88bd713..23b52ab 100644 --- a/modules/security/ssh/git.nix +++ b/modules/security/ssh/git.nix @@ -2,48 +2,22 @@ { config, lib, ... }: let hosts = [ - { - domain = "github.com"; - identityName = "github"; - } - { - domain = "gitlab.com"; - identityName = "gitlab"; - } - { - domain = "bitbucket.org"; - identityName = "bitbucket"; - } - { - domain = "codeberg.org"; - identityName = "codeberg"; - } - { - domain = "git.sr.ht"; - identityName = "sourcehut"; - } + "github.com" + "gitlab.com" + "bitbucket.org" + "codeberg.org" + "git.sr.ht" ]; mkGitHost = - { domain, identityName }: + domain: lib.nameValuePair domain { hostname = domain; user = "git"; - identityFile = "${config.home.homeDirectory}/.local/share/ssh/git/${identityName}"; - }; - - mkKeyFile = - { identityName, ... }: - lib.nameValuePair identityName { - enable = true; - text = ""; - force = false; }; in { config = lib.mkIf (config.security.ssh.enable && config.development.git.useSSH) { - home.file = builtins.listToAttrs (map mkKeyFile hosts); - programs.ssh.settings = builtins.listToAttrs (map mkGitHost hosts); }; } diff --git a/users/arpit.nix b/users/arpit.nix index ab89546..d2803d6 100644 --- a/users/arpit.nix +++ b/users/arpit.nix @@ -57,6 +57,7 @@ # Security security.enteauth.enable = true; security.gopass.enable = true; + security.gopass.ssh-agent.enable = true; security.gpg.enable = true; security.openvpn.enable = true; security.ssh.enable = true; |
