diff options
| author | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-09-02 22:07:14 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-09-02 22:07:14 +0530 |
| commit | 5ac48b36e56d652d55272b77a6752558e630b3c7 (patch) | |
| tree | 1442be6c6e475258248332cb35bbd7866551c7f0 /modules/security | |
| parent | 171c30e79fe34ce2dcf411b9db0f9cf64616a0c7 (diff) | |
| download | home-manager-config-5ac48b36e56d652d55272b77a6752558e630b3c7.tar.gz home-manager-config-5ac48b36e56d652d55272b77a6752558e630b3c7.zip | |
feat(security/gopass): manage SSH keys from the gopass store
Diffstat (limited to 'modules/security')
| -rw-r--r-- | modules/security/gopass/default.nix | 8 | ||||
| -rw-r--r-- | modules/security/gopass/gopass-ssh-load.sh | 23 | ||||
| -rw-r--r-- | modules/security/gopass/gopass-sync-init.sh | 9 |
3 files changed, 35 insertions, 5 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index 341c901..e543c03 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -10,11 +10,11 @@ let gopassSshLoadScript = pkgs.writeShellApplication { name = "gopass-ssh-load"; - runtimeInputs = with pkgs; [ + runtimeInputs = [ config.security.gopass.package - gnupg - openssh - bash + config.security.gpg.package + config.security.ssh.package + pkgs.bash ]; text = builtins.replaceStrings diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh index e974713..b9a06e9 100644 --- a/modules/security/gopass/gopass-ssh-load.sh +++ b/modules/security/gopass/gopass-ssh-load.sh @@ -1,9 +1,30 @@ #!/usr/bin/env bash + +# gopass-ssh-load +# +# Load SSH keys into the SSH agent from the gopass password store. +# +# This script reads private keys and (optionally) their passphrases from gopass +# entries under the `ssh/` directory and adds them to the SSH agent served by +# gpg-agent. It is meant to be run manually whenever a key is imported into or +# rotated within the gopass store, so the SSH agent picks up the change. +# +# Behaviour: +# * It first verifies that a usable SSH agent socket exists and bails out if +# not. +# * It exits early (without doing anything) when the agent already has at +# least one Ed25519/RSA/ECDSA identity loaded, to avoid useless work and +# unnecessary gpg passphrase prompts. +# * For each key listed in GOPASS_SSH_KEYS it writes the corresponding +# `ssh/<key>` entry to a temporary file, strips the passphrase using the +# `ssh/<key>/passphrase` entry, and registers the key with `ssh-add`. +# +# Temporary key files are written with mode 600 and removed afterwards. + set -o errexit set -o nounset set -o pipefail -# Load SSH keys from gopass password store export GNUPGHOME="@@GNUPGHOME@@" export GOPASS_SSH_KEYS="@@GOPASS_SSH_KEYS@@" diff --git a/modules/security/gopass/gopass-sync-init.sh b/modules/security/gopass/gopass-sync-init.sh index 6fe4f8a..c7767f9 100644 --- a/modules/security/gopass/gopass-sync-init.sh +++ b/modules/security/gopass/gopass-sync-init.sh @@ -1,5 +1,14 @@ #!/usr/bin/env bash +# gopass-sync-init +# +# Prepare the gopass password store directory for git-backed syncing. +# +# This runs during home-manager activation. It ensures the store directory +# exists, initializes it as a git repository if it is not already one, and adds +# the configured git remote as `origin` if no remote is set yet. It is a no-op +# (and thus safe to rerun) when the store is already set up. + STORE_DIR="@@PASSWORD_STORE_DIR@@" mkdir -p "$STORE_DIR" |
