aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/gopass
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 22:07:14 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 22:07:14 +0530
commit5ac48b36e56d652d55272b77a6752558e630b3c7 (patch)
tree1442be6c6e475258248332cb35bbd7866551c7f0 /modules/security/gopass
parent171c30e79fe34ce2dcf411b9db0f9cf64616a0c7 (diff)
downloadhome-manager-config-5ac48b36e56d652d55272b77a6752558e630b3c7.tar.gz
home-manager-config-5ac48b36e56d652d55272b77a6752558e630b3c7.zip
feat(security/gopass): manage SSH keys from the gopass store
Diffstat (limited to 'modules/security/gopass')
-rw-r--r--modules/security/gopass/default.nix8
-rw-r--r--modules/security/gopass/gopass-ssh-load.sh23
-rw-r--r--modules/security/gopass/gopass-sync-init.sh9
3 files changed, 35 insertions, 5 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index 341c901..e543c03 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -10,11 +10,11 @@ let
gopassSshLoadScript = pkgs.writeShellApplication {
name = "gopass-ssh-load";
- runtimeInputs = with pkgs; [
+ runtimeInputs = [
config.security.gopass.package
- gnupg
- openssh
- bash
+ config.security.gpg.package
+ config.security.ssh.package
+ pkgs.bash
];
text =
builtins.replaceStrings
diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh
index e974713..b9a06e9 100644
--- a/modules/security/gopass/gopass-ssh-load.sh
+++ b/modules/security/gopass/gopass-ssh-load.sh
@@ -1,9 +1,30 @@
#!/usr/bin/env bash
+
+# gopass-ssh-load
+#
+# Load SSH keys into the SSH agent from the gopass password store.
+#
+# This script reads private keys and (optionally) their passphrases from gopass
+# entries under the `ssh/` directory and adds them to the SSH agent served by
+# gpg-agent. It is meant to be run manually whenever a key is imported into or
+# rotated within the gopass store, so the SSH agent picks up the change.
+#
+# Behaviour:
+# * It first verifies that a usable SSH agent socket exists and bails out if
+# not.
+# * It exits early (without doing anything) when the agent already has at
+# least one Ed25519/RSA/ECDSA identity loaded, to avoid useless work and
+# unnecessary gpg passphrase prompts.
+# * For each key listed in GOPASS_SSH_KEYS it writes the corresponding
+# `ssh/<key>` entry to a temporary file, strips the passphrase using the
+# `ssh/<key>/passphrase` entry, and registers the key with `ssh-add`.
+#
+# Temporary key files are written with mode 600 and removed afterwards.
+
set -o errexit
set -o nounset
set -o pipefail
-# Load SSH keys from gopass password store
export GNUPGHOME="@@GNUPGHOME@@"
export GOPASS_SSH_KEYS="@@GOPASS_SSH_KEYS@@"
diff --git a/modules/security/gopass/gopass-sync-init.sh b/modules/security/gopass/gopass-sync-init.sh
index 6fe4f8a..c7767f9 100644
--- a/modules/security/gopass/gopass-sync-init.sh
+++ b/modules/security/gopass/gopass-sync-init.sh
@@ -1,5 +1,14 @@
#!/usr/bin/env bash
+# gopass-sync-init
+#
+# Prepare the gopass password store directory for git-backed syncing.
+#
+# This runs during home-manager activation. It ensures the store directory
+# exists, initializes it as a git repository if it is not already one, and adds
+# the configured git remote as `origin` if no remote is set yet. It is a no-op
+# (and thus safe to rerun) when the store is already set up.
+
STORE_DIR="@@PASSWORD_STORE_DIR@@"
mkdir -p "$STORE_DIR"