aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/gopass/default.nix
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 22:08:57 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 22:08:57 +0530
commitf6ef02e1a420b0bc79c05a04e572eb47ec7e0203 (patch)
tree1442be6c6e475258248332cb35bbd7866551c7f0 /modules/security/gopass/default.nix
parent627c1f723302f949e28d9df5a3acb380186b4c44 (diff)
parent5ac48b36e56d652d55272b77a6752558e630b3c7 (diff)
downloadhome-manager-config-f6ef02e1a420b0bc79c05a04e572eb47ec7e0203.tar.gz
home-manager-config-f6ef02e1a420b0bc79c05a04e572eb47ec7e0203.zip
Merge branch 'some-changes-to-git-usage'
Diffstat (limited to 'modules/security/gopass/default.nix')
-rw-r--r--modules/security/gopass/default.nix61
1 files changed, 56 insertions, 5 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index 4d223e9..e543c03 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -10,11 +10,11 @@ let
gopassSshLoadScript = pkgs.writeShellApplication {
name = "gopass-ssh-load";
- runtimeInputs = with pkgs; [
+ runtimeInputs = [
config.security.gopass.package
- gnupg
- openssh
- bash
+ config.security.gpg.package
+ config.security.ssh.package
+ pkgs.bash
];
text =
builtins.replaceStrings
@@ -47,6 +47,26 @@ in
description = "The gopass-ssh-load script package.";
};
};
+ sync = {
+ enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
+ remote = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
+ };
+ credential = {
+ username = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Username for HTTPS git authentication against the gopass remote.";
+ };
+ passwordGopassPath = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "gopass entry path holding the password or token used.";
+ };
+ };
+ };
};
config = lib.mkMerge [
@@ -75,7 +95,16 @@ in
tag = {
gpgSign = false;
};
- };
+ }
+ //
+ lib.optionalAttrs
+ (
+ config.security.gopass.sync.enable
+ && config.security.gopass.sync.credential.passwordGopassPath != null
+ )
+ {
+ credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f";
+ };
}
];
@@ -97,8 +126,30 @@ in
type = "Application";
};
})
+
(lib.mkIf config.security.gopass.ssh-agent.enable {
home.packages = [ config.security.gopass.ssh-agent.package ];
})
+
+ (lib.mkIf config.security.gopass.sync.enable {
+ home.activation.gopassSyncInit =
+ let
+ gopassSyncInit = pkgs.writeShellApplication {
+ name = "gopass-sync-init";
+ runtimeInputs = [
+ pkgs.bash
+ config.development.git.package
+ ];
+ text =
+ builtins.replaceStrings
+ [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ]
+ [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ]
+ (builtins.readFile ./gopass-sync-init.sh);
+ };
+ in
+ lib.hm.dag.entryAfter [ "writeBoundary" ] ''
+ run ${lib.getExe gopassSyncInit} || true
+ '';
+ })
];
}