diff options
| author | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-07-24 21:53:14 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-07-24 21:53:14 +0530 |
| commit | 57dc86b062d73446de2f26875ee7b950f1db8ea3 (patch) | |
| tree | fb341d50baeed327862c90aa1ccca123397c3867 /modules/security/gopass/default.nix | |
| parent | 5032239a236595451f22ea948c42281f8aa04645 (diff) | |
| download | home-manager-config-57dc86b062d73446de2f26875ee7b950f1db8ea3.tar.gz home-manager-config-57dc86b062d73446de2f26875ee7b950f1db8ea3.zip | |
feat(gopass): load SSH keys from gopass for git platforms
- Add security.gopass.ssh-agent.enable option
- Create gopass-ssh-load systemd oneshot service
- Remove identityFile and placeholder files from SSH git host configs
- Enable ssh-agent for the user
Diffstat (limited to 'modules/security/gopass/default.nix')
| -rw-r--r-- | modules/security/gopass/default.nix | 55 |
1 files changed, 53 insertions, 2 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index 19191ff..a121022 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -8,15 +8,16 @@ { options.security.gopass = { enable = lib.mkEnableOption "Enables gopass."; - package = lib.mkOption { type = lib.types.package; default = pkgs.gopass.override { passAlias = true; }; defaultText = lib.literalExpression "pkgs.gopass.override { passAlias = true; }"; description = "The gopass package to use."; }; + ssh-agent = { + enable = lib.mkEnableOption "gopass-backed SSH keys for git"; + }; }; - config = lib.mkIf config.security.gopass.enable { programs.password-store = { enable = true; @@ -25,5 +26,55 @@ PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass"; }; }; + systemd.user.services.gopass-ssh-load = lib.mkIf config.security.gopass.ssh-agent.enable { + Unit = { + Description = "Load SSH keys from gopass into SSH agent for git"; + After = [ + "gpg-agent.socket" + "graphical-session.target" + ]; + Requires = [ + "gpg-agent.socket" + ]; + PartOf = [ + "graphical-session.target" + ]; + }; + Service = { + Type = "oneshot"; + ExecStart = "${pkgs.writeShellScript "gopass-ssh-load" '' + export SSH_AUTH_SOCK="$(${pkgs.gnupg}/bin/gpgconf --list-dirs agent-ssh-socket)" + + if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then + exit 1 + fi + + for key in github gitlab bitbucket codeberg sourcehut; do + if ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > /dev/null 2>&1; then + tmpdir=$(mktemp -d) + keyfile="$tmpdir/key" + ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > "$keyfile" 2>/dev/null + chmod 600 "$keyfile" + if ! ${pkgs.openssh}/bin/ssh-add "$keyfile" 2>/dev/null; then + passphrase=$(${config.security.gopass.package}/bin/gopass cat "ssh/$key/passphrase" 2>/dev/null) + if [ -n "$passphrase" ]; then + tmpcopy=$(mktemp) + cp "$keyfile" "$tmpcopy" + chmod 600 "$tmpcopy" + if ${pkgs.openssh}/bin/ssh-keygen -p -P "$passphrase" -N "" -f "$tmpcopy" 2>/dev/null; then + ${pkgs.openssh}/bin/ssh-add "$tmpcopy" 2>/dev/null + fi + rm -f "$tmpcopy" + fi + fi + rm -rf "$tmpdir" + fi + done + ''}"; + }; + Install = { + WantedBy = [ "graphical-session.target" ]; + }; + }; }; } |
