aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/gopass
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 19:08:01 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 19:08:01 +0530
commit171c30e79fe34ce2dcf411b9db0f9cf64616a0c7 (patch)
treecf64572f61d59cc4c6a3a9c4f187ec4be57899a8 /modules/security/gopass
parent4a1a196c4c08bd34226bc25bfefd0227ce53b092 (diff)
downloadhome-manager-config-171c30e79fe34ce2dcf411b9db0f9cf64616a0c7.tar.gz
home-manager-config-171c30e79fe34ce2dcf411b9db0f9cf64616a0c7.zip
feat(security/gopass): auto initialize git sync repo for gopass on build
Diffstat (limited to 'modules/security/gopass')
-rw-r--r--modules/security/gopass/default.nix34
-rw-r--r--modules/security/gopass/gopass-sync-init.sh20
2 files changed, 51 insertions, 3 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index 5650c4b..341c901 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -96,9 +96,15 @@ in
gpgSign = false;
};
}
- // lib.optionalAttrs (config.security.gopass.sync.credential.passwordGopassPath != null) {
- credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f";
- };
+ //
+ lib.optionalAttrs
+ (
+ config.security.gopass.sync.enable
+ && config.security.gopass.sync.credential.passwordGopassPath != null
+ )
+ {
+ credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f";
+ };
}
];
@@ -120,8 +126,30 @@ in
type = "Application";
};
})
+
(lib.mkIf config.security.gopass.ssh-agent.enable {
home.packages = [ config.security.gopass.ssh-agent.package ];
})
+
+ (lib.mkIf config.security.gopass.sync.enable {
+ home.activation.gopassSyncInit =
+ let
+ gopassSyncInit = pkgs.writeShellApplication {
+ name = "gopass-sync-init";
+ runtimeInputs = [
+ pkgs.bash
+ config.development.git.package
+ ];
+ text =
+ builtins.replaceStrings
+ [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ]
+ [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ]
+ (builtins.readFile ./gopass-sync-init.sh);
+ };
+ in
+ lib.hm.dag.entryAfter [ "writeBoundary" ] ''
+ run ${lib.getExe gopassSyncInit} || true
+ '';
+ })
];
}
diff --git a/modules/security/gopass/gopass-sync-init.sh b/modules/security/gopass/gopass-sync-init.sh
new file mode 100644
index 0000000..6fe4f8a
--- /dev/null
+++ b/modules/security/gopass/gopass-sync-init.sh
@@ -0,0 +1,20 @@
+#!/usr/bin/env bash
+
+STORE_DIR="@@PASSWORD_STORE_DIR@@"
+
+mkdir -p "$STORE_DIR"
+cd "$STORE_DIR" || { echo "Failed to enter $STORE_DIR"; exit 1; }
+
+# Check if the directory is already a git repository; initialize if not
+if ! git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
+ echo "Initializing git repository in $STORE_DIR..."
+ git init
+fi
+
+# Check if the remote 'origin' is set; add it if not
+if ! git remote | grep -q "^origin$"; then
+ echo "Adding remote origin..."
+ git remote add origin "@@REMOTE_REPO_URL@@"
+fi
+
+echo "Password store git setup complete."