diff options
| author | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-09-02 22:08:57 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-09-02 22:08:57 +0530 |
| commit | f6ef02e1a420b0bc79c05a04e572eb47ec7e0203 (patch) | |
| tree | 1442be6c6e475258248332cb35bbd7866551c7f0 | |
| parent | 627c1f723302f949e28d9df5a3acb380186b4c44 (diff) | |
| parent | 5ac48b36e56d652d55272b77a6752558e630b3c7 (diff) | |
| download | home-manager-config-f6ef02e1a420b0bc79c05a04e572eb47ec7e0203.tar.gz home-manager-config-f6ef02e1a420b0bc79c05a04e572eb47ec7e0203.zip | |
Merge branch 'some-changes-to-git-usage'
| -rw-r--r-- | modules/development/git/assertions.nix | 8 | ||||
| -rw-r--r-- | modules/development/git/default.nix | 11 | ||||
| -rw-r--r-- | modules/office/calcurse/default.nix | 17 | ||||
| -rw-r--r-- | modules/private/calcurse.example.nix | 8 | ||||
| -rw-r--r-- | modules/private/gopass.example.nix | 13 | ||||
| -rw-r--r-- | modules/security/gopass/default.nix | 61 | ||||
| -rw-r--r-- | modules/security/gopass/gopass-ssh-load.sh | 23 | ||||
| -rw-r--r-- | modules/security/gopass/gopass-sync-init.sh | 29 | ||||
| -rw-r--r-- | users/arpit.nix | 5 |
9 files changed, 147 insertions, 28 deletions
diff --git a/modules/development/git/assertions.nix b/modules/development/git/assertions.nix index 02acd92..c66714a 100644 --- a/modules/development/git/assertions.nix +++ b/modules/development/git/assertions.nix @@ -3,14 +3,6 @@ { assertions = [ { - assertion = - !config.development.git.useSSH || (config.development.git.enable && config.security.ssh.enable); - message = '' - development.git.useSSH is enabled but security.ssh.enable is not. - SSH must be enabled (security.ssh.enable = true) to use SSH for git. - ''; - } - { assertion = !config.development.git.signing.signByDefault || config.development.git.enable; message = '' development.git.signing.signByDefault is enabled but development.git.enable is not. diff --git a/modules/development/git/default.nix b/modules/development/git/default.nix index a62f866..ce92674 100644 --- a/modules/development/git/default.nix +++ b/modules/development/git/default.nix @@ -30,8 +30,6 @@ description = "Git email."; }; - useSSH = lib.mkEnableOption "Use SSH instead of HTTPS for common git platforms."; - signing = { key = lib.mkOption { type = lib.types.nullOr lib.types.str; @@ -62,16 +60,9 @@ }; log.showSignature = true; pull.rebase = true; + init.defaultBranch = "master"; } - (lib.optionalAttrs config.development.git.useSSH { - url."git@github.com:".insteadOf = "https://github.com/"; - url."git@gitlab.com:".insteadOf = "https://gitlab.com/"; - url."git@bitbucket.org:".insteadOf = "https://bitbucket.org/"; - url."git@codeberg.org:".insteadOf = "https://codeberg.org/"; - url."git@git.sr.ht:".insteadOf = "https://git.sr.ht/"; - }) - (lib.optionalAttrs config.development.delta.enable { core.pager = "delta"; interactive.diffFilter = "delta --color-only"; diff --git a/modules/office/calcurse/default.nix b/modules/office/calcurse/default.nix index c72896e..3296f95 100644 --- a/modules/office/calcurse/default.nix +++ b/modules/office/calcurse/default.nix @@ -54,7 +54,19 @@ in remote = lib.mkOption { type = lib.types.nullOr lib.types.str; default = null; - description = "Git remote URL for the calcurse data directory. When set, calcurse-sync uses it automatically on first init instead of prompting."; + description = "Git remote URL for the calcurse data directory. Use an https:// URL if 'credential' is configured. When set, calcurse-sync uses it automatically on first init instead of prompting."; + }; + credential = { + username = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Username for HTTPS git authentication against the calcurse remote."; + }; + passwordGopassPath = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "gopass entry path holding the password or token used for HTTPS git authentication against the calcurse remote. E.g. 'git/calcurse-sync'."; + }; }; }; }; @@ -94,6 +106,9 @@ in }; commit.gpgSign = false; tag.gpgSign = false; + } + // lib.optionalAttrs (config.office.calcurse.sync.credential.passwordGopassPath != null) { + credential.helper = "!f() { echo username=${lib.escapeShellArg config.office.calcurse.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.office.calcurse.sync.credential.passwordGopassPath})\"; }; f"; }; } ]; diff --git a/modules/private/calcurse.example.nix b/modules/private/calcurse.example.nix index 16ee9e8..681d343 100644 --- a/modules/private/calcurse.example.nix +++ b/modules/private/calcurse.example.nix @@ -2,6 +2,12 @@ { ... }: { config = { - office.calcurse.sync.remote = "YOUR_REPOSITORY_URL"; + office.calcurse.sync = { + remote = "YOUR_REPOSITORY_URL"; + credential = { + username = "example"; + passwordGopassPath = "websites/github.com/example/tokens/calendar"; + }; + }; }; } diff --git a/modules/private/gopass.example.nix b/modules/private/gopass.example.nix new file mode 100644 index 0000000..2d783c9 --- /dev/null +++ b/modules/private/gopass.example.nix @@ -0,0 +1,13 @@ +# Gopass - Template for configuring gopass, specially syncing +{ ... }: +{ + config = { + security.gopass.sync = { + remote = "YOUR_REPOSITORY_URL"; + credential = { + username = "example"; + passwordGopassPath = "websites/github.com/example/tokens/calendar"; + }; + }; + }; +} diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index 4d223e9..e543c03 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -10,11 +10,11 @@ let gopassSshLoadScript = pkgs.writeShellApplication { name = "gopass-ssh-load"; - runtimeInputs = with pkgs; [ + runtimeInputs = [ config.security.gopass.package - gnupg - openssh - bash + config.security.gpg.package + config.security.ssh.package + pkgs.bash ]; text = builtins.replaceStrings @@ -47,6 +47,26 @@ in description = "The gopass-ssh-load script package."; }; }; + sync = { + enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory."; + remote = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured."; + }; + credential = { + username = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Username for HTTPS git authentication against the gopass remote."; + }; + passwordGopassPath = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "gopass entry path holding the password or token used."; + }; + }; + }; }; config = lib.mkMerge [ @@ -75,7 +95,16 @@ in tag = { gpgSign = false; }; - }; + } + // + lib.optionalAttrs + ( + config.security.gopass.sync.enable + && config.security.gopass.sync.credential.passwordGopassPath != null + ) + { + credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f"; + }; } ]; @@ -97,8 +126,30 @@ in type = "Application"; }; }) + (lib.mkIf config.security.gopass.ssh-agent.enable { home.packages = [ config.security.gopass.ssh-agent.package ]; }) + + (lib.mkIf config.security.gopass.sync.enable { + home.activation.gopassSyncInit = + let + gopassSyncInit = pkgs.writeShellApplication { + name = "gopass-sync-init"; + runtimeInputs = [ + pkgs.bash + config.development.git.package + ]; + text = + builtins.replaceStrings + [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ] + [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ] + (builtins.readFile ./gopass-sync-init.sh); + }; + in + lib.hm.dag.entryAfter [ "writeBoundary" ] '' + run ${lib.getExe gopassSyncInit} || true + ''; + }) ]; } diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh index e974713..b9a06e9 100644 --- a/modules/security/gopass/gopass-ssh-load.sh +++ b/modules/security/gopass/gopass-ssh-load.sh @@ -1,9 +1,30 @@ #!/usr/bin/env bash + +# gopass-ssh-load +# +# Load SSH keys into the SSH agent from the gopass password store. +# +# This script reads private keys and (optionally) their passphrases from gopass +# entries under the `ssh/` directory and adds them to the SSH agent served by +# gpg-agent. It is meant to be run manually whenever a key is imported into or +# rotated within the gopass store, so the SSH agent picks up the change. +# +# Behaviour: +# * It first verifies that a usable SSH agent socket exists and bails out if +# not. +# * It exits early (without doing anything) when the agent already has at +# least one Ed25519/RSA/ECDSA identity loaded, to avoid useless work and +# unnecessary gpg passphrase prompts. +# * For each key listed in GOPASS_SSH_KEYS it writes the corresponding +# `ssh/<key>` entry to a temporary file, strips the passphrase using the +# `ssh/<key>/passphrase` entry, and registers the key with `ssh-add`. +# +# Temporary key files are written with mode 600 and removed afterwards. + set -o errexit set -o nounset set -o pipefail -# Load SSH keys from gopass password store export GNUPGHOME="@@GNUPGHOME@@" export GOPASS_SSH_KEYS="@@GOPASS_SSH_KEYS@@" diff --git a/modules/security/gopass/gopass-sync-init.sh b/modules/security/gopass/gopass-sync-init.sh new file mode 100644 index 0000000..c7767f9 --- /dev/null +++ b/modules/security/gopass/gopass-sync-init.sh @@ -0,0 +1,29 @@ +#!/usr/bin/env bash + +# gopass-sync-init +# +# Prepare the gopass password store directory for git-backed syncing. +# +# This runs during home-manager activation. It ensures the store directory +# exists, initializes it as a git repository if it is not already one, and adds +# the configured git remote as `origin` if no remote is set yet. It is a no-op +# (and thus safe to rerun) when the store is already set up. + +STORE_DIR="@@PASSWORD_STORE_DIR@@" + +mkdir -p "$STORE_DIR" +cd "$STORE_DIR" || { echo "Failed to enter $STORE_DIR"; exit 1; } + +# Check if the directory is already a git repository; initialize if not +if ! git rev-parse --is-inside-work-tree >/dev/null 2>&1; then + echo "Initializing git repository in $STORE_DIR..." + git init +fi + +# Check if the remote 'origin' is set; add it if not +if ! git remote | grep -q "^origin$"; then + echo "Adding remote origin..." + git remote add origin "@@REMOTE_REPO_URL@@" +fi + +echo "Password store git setup complete." diff --git a/users/arpit.nix b/users/arpit.nix index 989245e..837d2bf 100644 --- a/users/arpit.nix +++ b/users/arpit.nix @@ -5,6 +5,7 @@ ../modules/private/calcurse.nix ../modules/private/email.nix ../modules/private/git.nix + ../modules/private/gopass.nix ]; nixpkgs.config.allowUnfree = true; @@ -31,7 +32,6 @@ development.bruno.enable = true; development.delta.enable = true; development.git.enable = true; - development.git.useSSH = true; development.git.signing.signByDefault = true; development.lazygit.enable = true; development.nixvim.enable = true; @@ -68,7 +68,8 @@ # Security security.gopass.enable = true; - security.gopass.ssh-agent.enable = false; + security.gopass.ssh-agent.enable = true; + security.gopass.sync.enable = true; security.gpg.enable = true; security.gpg.backup.enable = true; security.gpg-tui.enable = true; |
