diff options
| author | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-08-04 20:01:06 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-08-04 20:01:06 +0530 |
| commit | 0a7afa2d1e576f05253b62c6b17e5e4873fbdebc (patch) | |
| tree | 4aec8cee7c4db281510bc42ff4e214252428afa4 /modules/scripts/gopass-ssh-load | |
| parent | 2e0f6163f61cb1e4195f1a08ad1148e57a4f5843 (diff) | |
| download | home-manager-config-0a7afa2d1e576f05253b62c6b17e5e4873fbdebc.tar.gz home-manager-config-0a7afa2d1e576f05253b62c6b17e5e4873fbdebc.zip | |
feat: moved gpg data directory, other gopass ssh keys, script builder
- Using ~/.local/share/gnupg/ for storing the data for gnupg, and made
the necessary changes in all places to that effect
- Additional ssh keys can be added to gopass under ssh/, which is on top
of the git servers that already existed
- Using pkgs.writeShellApplication for creating the scripts, stopped
setting path for each dependency (creating a long PATH variable and
thus finding binaries may take longer), instead using the inbuild dependency (runtimeInputs) for the scripts
Diffstat (limited to 'modules/scripts/gopass-ssh-load')
| -rw-r--r-- | modules/scripts/gopass-ssh-load/default.nix | 16 | ||||
| -rw-r--r-- | modules/scripts/gopass-ssh-load/script.sh | 39 |
2 files changed, 42 insertions, 13 deletions
diff --git a/modules/scripts/gopass-ssh-load/default.nix b/modules/scripts/gopass-ssh-load/default.nix index 002a4ac..e0a4615 100644 --- a/modules/scripts/gopass-ssh-load/default.nix +++ b/modules/scripts/gopass-ssh-load/default.nix @@ -6,10 +6,26 @@ }: let inherit ((import ../lib.nix { inherit lib pkgs; })) mkScriptModule; + + gitPlatformKeys = [ + "github" + "gitlab" + "bitbucket" + "codeberg" + "srht" + ]; + + gopassKeys = + lib.optionals config.development.git.useSSH gitPlatformKeys ++ config.security.ssh.extraGopassKeys; + base = mkScriptModule { name = "gopass-ssh-load"; path = ./script.sh; description = "Load SSH keys from gopass password store"; + env = { + GNUPGHOME = config.home.sessionVariables.GNUPGHOME; + GOPASS_SSH_KEYS = lib.concatStringsSep " " gopassKeys; + }; deps = with pkgs; [ config.security.gopass.package gnupg diff --git a/modules/scripts/gopass-ssh-load/script.sh b/modules/scripts/gopass-ssh-load/script.sh index e8bc0ee..43c83b0 100644 --- a/modules/scripts/gopass-ssh-load/script.sh +++ b/modules/scripts/gopass-ssh-load/script.sh @@ -1,5 +1,12 @@ -export SSH_AUTH_SOCK="$(gpgconf --list-dirs agent-ssh-socket)" +set -o errexit +set -o nounset +set -o pipefail +# Load SSH keys from gopass password store +export GNUPGHOME="${GNUPGHOME:-$HOME/.local/share/gnupg}" + +SSH_AUTH_SOCK="$(gpgconf --list-dirs agent-ssh-socket)" +export SSH_AUTH_SOCK if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then echo "Error: SSH_AUTH_SOCK is not set or valid." >&2 exit 1 @@ -9,25 +16,31 @@ if ssh-add -l 2>/dev/null | grep -qE "(ED25519|RSA|ECDSA)"; then exit 0 fi -for key in github gitlab bitbucket codeberg sourcehut; do +# GOPASS_SSH_KEYS: space-separated list of gopass entry names under ssh/ +# e.g. GOPASS_SSH_KEYS="github gitlab work-server" +if [ -z "${GOPASS_SSH_KEYS:-}" ]; then + echo "Error: GOPASS_SSH_KEYS is not set. Example: GOPASS_SSH_KEYS=\"github gitlab\"" >&2 + exit 1 +fi + +# shellcheck disable=SC2086 +read -r -a keys <<< "$GOPASS_SSH_KEYS" + +for key in "${keys[@]}"; do if gopass cat "ssh/$key" > /dev/null 2>&1; then tmpdir=$(mktemp -d) keyfile="$tmpdir/key" gopass cat "ssh/$key" > "$keyfile" 2>/dev/null chmod 600 "$keyfile" - if ! ssh-add "$keyfile" 2>/dev/null; then - passphrase=$(gopass cat "ssh/$key/passphrase" 2>/dev/null) - if [ -n "$passphrase" ]; then - tmpcopy=$(mktemp) - cp "$keyfile" "$tmpcopy" - chmod 600 "$tmpcopy" - if ssh-keygen -p -P "$passphrase" -N "" -f "$tmpcopy" 2>/dev/null; then - ssh-add "$tmpcopy" 2>/dev/null - fi - rm -f "$tmpcopy" - fi + passphrase=$(gopass cat "ssh/$key/passphrase" 2>/dev/null || true) + if [ -n "$passphrase" ]; then + ssh-keygen -p -P "$passphrase" -N "" -f "$keyfile" 2>/dev/null fi + + ssh-add "$keyfile" 2>/dev/null rm -rf "$tmpdir" + else + echo "Warning: no gopass entry ssh/$key" >&2 fi done |
