diff options
| author | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-08-29 02:02:23 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-08-29 03:50:32 +0530 |
| commit | 41bdeb88009dd232808edee9fc0e4ae94358d8d6 (patch) | |
| tree | c1a41f54e086064dac178ebed24d36ab34087c32 /modules/scripts/gopass-ssh-load | |
| parent | 530299d97926d45939f831dc3ea5e444d2839d08 (diff) | |
| download | home-manager-config-41bdeb88009dd232808edee9fc0e4ae94358d8d6.tar.gz home-manager-config-41bdeb88009dd232808edee9fc0e4ae94358d8d6.zip | |
refactor: moving script into modules that makes sense
- instead of collecting all scripts into modules/scripts we are moving
them to modules that makes sense (yazi-file-chooser.sh into yazi)
Diffstat (limited to 'modules/scripts/gopass-ssh-load')
| -rw-r--r-- | modules/scripts/gopass-ssh-load/default.nix | 32 | ||||
| -rw-r--r-- | modules/scripts/gopass-ssh-load/script.sh | 46 |
2 files changed, 0 insertions, 78 deletions
diff --git a/modules/scripts/gopass-ssh-load/default.nix b/modules/scripts/gopass-ssh-load/default.nix deleted file mode 100644 index 764f704..0000000 --- a/modules/scripts/gopass-ssh-load/default.nix +++ /dev/null @@ -1,32 +0,0 @@ -{ - config, - lib, - pkgs, - ... -}: -let - inherit ((import ../lib.nix { inherit lib pkgs; })) mkScriptModule; - - gopassKeys = config.security.ssh.gopassKeys; - - base = mkScriptModule { - name = "gopass-ssh-load"; - path = ./script.sh; - description = "Load SSH keys from gopass password store"; - env = { - GNUPGHOME = config.home.sessionVariables.GNUPGHOME; - GOPASS_SSH_KEYS = lib.concatStringsSep " " gopassKeys; - }; - deps = with pkgs; [ - config.security.gopass.package - gnupg - openssh - bash - ]; - inherit config; - }; -in -{ - options = base.options; - config = base.moduleConfig; -} diff --git a/modules/scripts/gopass-ssh-load/script.sh b/modules/scripts/gopass-ssh-load/script.sh deleted file mode 100644 index c6b9a29..0000000 --- a/modules/scripts/gopass-ssh-load/script.sh +++ /dev/null @@ -1,46 +0,0 @@ -#!/usr/bin/env bash -set -o errexit -set -o nounset -set -o pipefail - -# Load SSH keys from gopass password store -export GNUPGHOME="${GNUPGHOME:-$HOME/.local/share/gnupg}" - -SSH_AUTH_SOCK="$(gpgconf --list-dirs agent-ssh-socket)" -export SSH_AUTH_SOCK -if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then - echo "Error: SSH_AUTH_SOCK is not set or valid." >&2 - exit 1 -fi - -if ssh-add -l 2>/dev/null | grep -qE "(ED25519|RSA|ECDSA)"; then - exit 0 -fi - -# GOPASS_SSH_KEYS holds a space-separated list of gopass entry names under ssh -if [ -z "${GOPASS_SSH_KEYS:-}" ]; then - echo "Error: GOPASS_SSH_KEYS is not set. Example: GOPASS_SSH_KEYS=\"github gitlab\"" >&2 - exit 1 -fi - -# shellcheck disable=SC2086 -read -r -a keys <<< "$GOPASS_SSH_KEYS" - -for key in "${keys[@]}"; do - if gopass cat "ssh/$key" > /dev/null 2>&1; then - tmpdir=$(mktemp -d) - keyfile="$tmpdir/key" - gopass cat "ssh/$key" > "$keyfile" 2>/dev/null - chmod 600 "$keyfile" - - passphrase=$(gopass cat "ssh/$key/passphrase" 2>/dev/null || true) - if [ -n "$passphrase" ]; then - ssh-keygen -p -P "$passphrase" -N "" -f "$keyfile" 2>/dev/null - fi - - ssh-add "$keyfile" 2>/dev/null - rm -rf "$tmpdir" - else - echo "Warning: no gopass entry ssh/$key" >&2 - fi -done |
