aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/gopass/gopass-ssh-load.sh
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 22:08:57 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 22:08:57 +0530
commitf6ef02e1a420b0bc79c05a04e572eb47ec7e0203 (patch)
tree1442be6c6e475258248332cb35bbd7866551c7f0 /modules/security/gopass/gopass-ssh-load.sh
parent627c1f723302f949e28d9df5a3acb380186b4c44 (diff)
parent5ac48b36e56d652d55272b77a6752558e630b3c7 (diff)
downloadhome-manager-config-f6ef02e1a420b0bc79c05a04e572eb47ec7e0203.tar.gz
home-manager-config-f6ef02e1a420b0bc79c05a04e572eb47ec7e0203.zip
Merge branch 'some-changes-to-git-usage'
Diffstat (limited to 'modules/security/gopass/gopass-ssh-load.sh')
-rw-r--r--modules/security/gopass/gopass-ssh-load.sh23
1 files changed, 22 insertions, 1 deletions
diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh
index e974713..b9a06e9 100644
--- a/modules/security/gopass/gopass-ssh-load.sh
+++ b/modules/security/gopass/gopass-ssh-load.sh
@@ -1,9 +1,30 @@
#!/usr/bin/env bash
+
+# gopass-ssh-load
+#
+# Load SSH keys into the SSH agent from the gopass password store.
+#
+# This script reads private keys and (optionally) their passphrases from gopass
+# entries under the `ssh/` directory and adds them to the SSH agent served by
+# gpg-agent. It is meant to be run manually whenever a key is imported into or
+# rotated within the gopass store, so the SSH agent picks up the change.
+#
+# Behaviour:
+# * It first verifies that a usable SSH agent socket exists and bails out if
+# not.
+# * It exits early (without doing anything) when the agent already has at
+# least one Ed25519/RSA/ECDSA identity loaded, to avoid useless work and
+# unnecessary gpg passphrase prompts.
+# * For each key listed in GOPASS_SSH_KEYS it writes the corresponding
+# `ssh/<key>` entry to a temporary file, strips the passphrase using the
+# `ssh/<key>/passphrase` entry, and registers the key with `ssh-add`.
+#
+# Temporary key files are written with mode 600 and removed afterwards.
+
set -o errexit
set -o nounset
set -o pipefail
-# Load SSH keys from gopass password store
export GNUPGHOME="@@GNUPGHOME@@"
export GOPASS_SSH_KEYS="@@GOPASS_SSH_KEYS@@"