aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/gopass
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-07-24 21:53:14 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-07-24 21:53:14 +0530
commit57dc86b062d73446de2f26875ee7b950f1db8ea3 (patch)
treefb341d50baeed327862c90aa1ccca123397c3867 /modules/security/gopass
parent5032239a236595451f22ea948c42281f8aa04645 (diff)
downloadhome-manager-config-57dc86b062d73446de2f26875ee7b950f1db8ea3.tar.gz
home-manager-config-57dc86b062d73446de2f26875ee7b950f1db8ea3.zip
feat(gopass): load SSH keys from gopass for git platforms
- Add security.gopass.ssh-agent.enable option - Create gopass-ssh-load systemd oneshot service - Remove identityFile and placeholder files from SSH git host configs - Enable ssh-agent for the user
Diffstat (limited to 'modules/security/gopass')
-rw-r--r--modules/security/gopass/default.nix55
1 files changed, 53 insertions, 2 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index 19191ff..a121022 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -8,15 +8,16 @@
{
options.security.gopass = {
enable = lib.mkEnableOption "Enables gopass.";
-
package = lib.mkOption {
type = lib.types.package;
default = pkgs.gopass.override { passAlias = true; };
defaultText = lib.literalExpression "pkgs.gopass.override { passAlias = true; }";
description = "The gopass package to use.";
};
+ ssh-agent = {
+ enable = lib.mkEnableOption "gopass-backed SSH keys for git";
+ };
};
-
config = lib.mkIf config.security.gopass.enable {
programs.password-store = {
enable = true;
@@ -25,5 +26,55 @@
PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass";
};
};
+ systemd.user.services.gopass-ssh-load = lib.mkIf config.security.gopass.ssh-agent.enable {
+ Unit = {
+ Description = "Load SSH keys from gopass into SSH agent for git";
+ After = [
+ "gpg-agent.socket"
+ "graphical-session.target"
+ ];
+ Requires = [
+ "gpg-agent.socket"
+ ];
+ PartOf = [
+ "graphical-session.target"
+ ];
+ };
+ Service = {
+ Type = "oneshot";
+ ExecStart = "${pkgs.writeShellScript "gopass-ssh-load" ''
+ export SSH_AUTH_SOCK="$(${pkgs.gnupg}/bin/gpgconf --list-dirs agent-ssh-socket)"
+
+ if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then
+ exit 1
+ fi
+
+ for key in github gitlab bitbucket codeberg sourcehut; do
+ if ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > /dev/null 2>&1; then
+ tmpdir=$(mktemp -d)
+ keyfile="$tmpdir/key"
+ ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > "$keyfile" 2>/dev/null
+ chmod 600 "$keyfile"
+ if ! ${pkgs.openssh}/bin/ssh-add "$keyfile" 2>/dev/null; then
+ passphrase=$(${config.security.gopass.package}/bin/gopass cat "ssh/$key/passphrase" 2>/dev/null)
+ if [ -n "$passphrase" ]; then
+ tmpcopy=$(mktemp)
+ cp "$keyfile" "$tmpcopy"
+ chmod 600 "$tmpcopy"
+ if ${pkgs.openssh}/bin/ssh-keygen -p -P "$passphrase" -N "" -f "$tmpcopy" 2>/dev/null; then
+ ${pkgs.openssh}/bin/ssh-add "$tmpcopy" 2>/dev/null
+ fi
+ rm -f "$tmpcopy"
+ fi
+ fi
+ rm -rf "$tmpdir"
+ fi
+ done
+ ''}";
+ };
+ Install = {
+ WantedBy = [ "graphical-session.target" ];
+ };
+ };
};
}