aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/gopass
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-07-29 23:45:01 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-07-29 23:45:01 +0530
commit175c923556d7e9d2ed83b4b281e1bdf54bba51bf (patch)
tree5cdf22ecb77bb9fc63808ad5efdab9aa14a20385 /modules/security/gopass
parent357d69f4ce7da70e746c465c8fa32c8d6dbe815e (diff)
downloadhome-manager-config-175c923556d7e9d2ed83b4b281e1bdf54bba51bf.tar.gz
home-manager-config-175c923556d7e9d2ed83b4b281e1bdf54bba51bf.zip
feat(gopass-ssh-load): moved the gopass-ssh-load into modules/scripts
- Maintaining the format of the rest of the codebase moving gopass-ssh-load into its own script in modules/scripts instead of writing it directly in modules/security/gopass/default.nix
Diffstat (limited to 'modules/security/gopass')
-rw-r--r--modules/security/gopass/default.nix51
1 files changed, 1 insertions, 50 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index d6848d8..f9bdf14 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -5,43 +5,6 @@
pkgs,
...
}:
-let
- gopass-ssh-load = pkgs.writeShellScriptBin "gopass-ssh-load" ''
- export SSH_AUTH_SOCK="$(${pkgs.gnupg}/bin/gpgconf --list-dirs agent-ssh-socket)"
-
- if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then
- echo "Error: SSH_AUTH_SOCK is not set or valid." >&2
- exit 1
- fi
-
- if ${pkgs.openssh}/bin/ssh-add -l 2>/dev/null | grep -qE "(ED25519|RSA|ECDSA)"; then
- exit 0
- fi
-
- for key in github gitlab bitbucket codeberg sourcehut; do
- if ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > /dev/null 2>&1; then
- tmpdir=$(mktemp -d)
- keyfile="$tmpdir/key"
- ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > "$keyfile" 2>/dev/null
- chmod 600 "$keyfile"
-
- if ! ${pkgs.openssh}/bin/ssh-add "$keyfile" 2>/dev/null; then
- passphrase=$(${config.security.gopass.package}/bin/gopass cat "ssh/$key/passphrase" 2>/dev/null)
- if [ -n "$passphrase" ]; then
- tmpcopy=$(mktemp)
- cp "$keyfile" "$tmpcopy"
- chmod 600 "$tmpcopy"
- if ${pkgs.openssh}/bin/ssh-keygen -p -P "$passphrase" -N "" -f "$tmpcopy" 2>/dev/null; then
- ${pkgs.openssh}/bin/ssh-add "$tmpcopy" 2>/dev/null
- fi
- rm -f "$tmpcopy"
- fi
- fi
- rm -rf "$tmpdir"
- fi
- done
- '';
-in
{
options.security.gopass = {
enable = lib.mkEnableOption "Enables gopass.";
@@ -51,18 +14,10 @@ in
defaultText = lib.literalExpression "pkgs.gopass.override { passAlias = true; }";
description = "The gopass package to use.";
};
- ssh-agent = {
- enable = lib.mkEnableOption "gopass-backed SSH keys for git";
- script = lib.mkOption {
- type = lib.types.package;
- description = "The package containing the gopass-ssh-load script.";
- };
- };
+ ssh-agent.enable = lib.mkEnableOption "gopass-backed SSH keys for git";
};
config = lib.mkIf config.security.gopass.enable {
- security.gopass.ssh-agent.script = gopass-ssh-load;
-
programs.password-store = {
enable = true;
package = config.security.gopass.package;
@@ -74,9 +29,5 @@ in
home.sessionVariables = {
PASSWORD_STORE_DIR = config.programs.password-store.settings.PASSWORD_STORE_DIR;
};
-
- home.packages = lib.mkIf config.security.gopass.ssh-agent.enable [
- config.security.gopass.ssh-agent.script
- ];
};
}