aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 18:09:34 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 18:09:34 +0530
commit4a1a196c4c08bd34226bc25bfefd0227ce53b092 (patch)
tree334b47964b275ab54084c2eaaf9170fa1651143b /modules/security
parent1d7e16552cb230b0d35dcad01fb023990186c636 (diff)
downloadhome-manager-config-4a1a196c4c08bd34226bc25bfefd0227ce53b092.tar.gz
home-manager-config-4a1a196c4c08bd34226bc25bfefd0227ce53b092.zip
feat(security/gopass): options to add username and password for git remote
Diffstat (limited to 'modules/security')
-rw-r--r--modules/security/gopass/default.nix23
1 files changed, 23 insertions, 0 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index 4d223e9..5650c4b 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -47,6 +47,26 @@ in
description = "The gopass-ssh-load script package.";
};
};
+ sync = {
+ enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
+ remote = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
+ };
+ credential = {
+ username = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Username for HTTPS git authentication against the gopass remote.";
+ };
+ passwordGopassPath = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "gopass entry path holding the password or token used.";
+ };
+ };
+ };
};
config = lib.mkMerge [
@@ -75,6 +95,9 @@ in
tag = {
gpgSign = false;
};
+ }
+ // lib.optionalAttrs (config.security.gopass.sync.credential.passwordGopassPath != null) {
+ credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f";
};
}
];