diff options
| author | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-09-02 19:08:01 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-09-02 19:08:01 +0530 |
| commit | 171c30e79fe34ce2dcf411b9db0f9cf64616a0c7 (patch) | |
| tree | cf64572f61d59cc4c6a3a9c4f187ec4be57899a8 /modules/security | |
| parent | 4a1a196c4c08bd34226bc25bfefd0227ce53b092 (diff) | |
| download | home-manager-config-171c30e79fe34ce2dcf411b9db0f9cf64616a0c7.tar.gz home-manager-config-171c30e79fe34ce2dcf411b9db0f9cf64616a0c7.zip | |
feat(security/gopass): auto initialize git sync repo for gopass on build
Diffstat (limited to 'modules/security')
| -rw-r--r-- | modules/security/gopass/default.nix | 34 | ||||
| -rw-r--r-- | modules/security/gopass/gopass-sync-init.sh | 20 |
2 files changed, 51 insertions, 3 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index 5650c4b..341c901 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -96,9 +96,15 @@ in gpgSign = false; }; } - // lib.optionalAttrs (config.security.gopass.sync.credential.passwordGopassPath != null) { - credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f"; - }; + // + lib.optionalAttrs + ( + config.security.gopass.sync.enable + && config.security.gopass.sync.credential.passwordGopassPath != null + ) + { + credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f"; + }; } ]; @@ -120,8 +126,30 @@ in type = "Application"; }; }) + (lib.mkIf config.security.gopass.ssh-agent.enable { home.packages = [ config.security.gopass.ssh-agent.package ]; }) + + (lib.mkIf config.security.gopass.sync.enable { + home.activation.gopassSyncInit = + let + gopassSyncInit = pkgs.writeShellApplication { + name = "gopass-sync-init"; + runtimeInputs = [ + pkgs.bash + config.development.git.package + ]; + text = + builtins.replaceStrings + [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ] + [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ] + (builtins.readFile ./gopass-sync-init.sh); + }; + in + lib.hm.dag.entryAfter [ "writeBoundary" ] '' + run ${lib.getExe gopassSyncInit} || true + ''; + }) ]; } diff --git a/modules/security/gopass/gopass-sync-init.sh b/modules/security/gopass/gopass-sync-init.sh new file mode 100644 index 0000000..6fe4f8a --- /dev/null +++ b/modules/security/gopass/gopass-sync-init.sh @@ -0,0 +1,20 @@ +#!/usr/bin/env bash + +STORE_DIR="@@PASSWORD_STORE_DIR@@" + +mkdir -p "$STORE_DIR" +cd "$STORE_DIR" || { echo "Failed to enter $STORE_DIR"; exit 1; } + +# Check if the directory is already a git repository; initialize if not +if ! git rev-parse --is-inside-work-tree >/dev/null 2>&1; then + echo "Initializing git repository in $STORE_DIR..." + git init +fi + +# Check if the remote 'origin' is set; add it if not +if ! git remote | grep -q "^origin$"; then + echo "Adding remote origin..." + git remote add origin "@@REMOTE_REPO_URL@@" +fi + +echo "Password store git setup complete." |
