aboutsummaryrefslogtreecommitdiffstats
path: root/modules
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 22:08:57 +0530
committerArpit Chakladar <arpitchakladar+git@gmail.com>2026-09-02 22:08:57 +0530
commitf6ef02e1a420b0bc79c05a04e572eb47ec7e0203 (patch)
tree1442be6c6e475258248332cb35bbd7866551c7f0 /modules
parent627c1f723302f949e28d9df5a3acb380186b4c44 (diff)
parent5ac48b36e56d652d55272b77a6752558e630b3c7 (diff)
downloadhome-manager-config-f6ef02e1a420b0bc79c05a04e572eb47ec7e0203.tar.gz
home-manager-config-f6ef02e1a420b0bc79c05a04e572eb47ec7e0203.zip
Merge branch 'some-changes-to-git-usage'
Diffstat (limited to 'modules')
-rw-r--r--modules/development/git/assertions.nix8
-rw-r--r--modules/development/git/default.nix11
-rw-r--r--modules/office/calcurse/default.nix17
-rw-r--r--modules/private/calcurse.example.nix8
-rw-r--r--modules/private/gopass.example.nix13
-rw-r--r--modules/security/gopass/default.nix61
-rw-r--r--modules/security/gopass/gopass-ssh-load.sh23
-rw-r--r--modules/security/gopass/gopass-sync-init.sh29
8 files changed, 144 insertions, 26 deletions
diff --git a/modules/development/git/assertions.nix b/modules/development/git/assertions.nix
index 02acd92..c66714a 100644
--- a/modules/development/git/assertions.nix
+++ b/modules/development/git/assertions.nix
@@ -3,14 +3,6 @@
{
assertions = [
{
- assertion =
- !config.development.git.useSSH || (config.development.git.enable && config.security.ssh.enable);
- message = ''
- development.git.useSSH is enabled but security.ssh.enable is not.
- SSH must be enabled (security.ssh.enable = true) to use SSH for git.
- '';
- }
- {
assertion = !config.development.git.signing.signByDefault || config.development.git.enable;
message = ''
development.git.signing.signByDefault is enabled but development.git.enable is not.
diff --git a/modules/development/git/default.nix b/modules/development/git/default.nix
index a62f866..ce92674 100644
--- a/modules/development/git/default.nix
+++ b/modules/development/git/default.nix
@@ -30,8 +30,6 @@
description = "Git email.";
};
- useSSH = lib.mkEnableOption "Use SSH instead of HTTPS for common git platforms.";
-
signing = {
key = lib.mkOption {
type = lib.types.nullOr lib.types.str;
@@ -62,16 +60,9 @@
};
log.showSignature = true;
pull.rebase = true;
+ init.defaultBranch = "master";
}
- (lib.optionalAttrs config.development.git.useSSH {
- url."git@github.com:".insteadOf = "https://github.com/";
- url."git@gitlab.com:".insteadOf = "https://gitlab.com/";
- url."git@bitbucket.org:".insteadOf = "https://bitbucket.org/";
- url."git@codeberg.org:".insteadOf = "https://codeberg.org/";
- url."git@git.sr.ht:".insteadOf = "https://git.sr.ht/";
- })
-
(lib.optionalAttrs config.development.delta.enable {
core.pager = "delta";
interactive.diffFilter = "delta --color-only";
diff --git a/modules/office/calcurse/default.nix b/modules/office/calcurse/default.nix
index c72896e..3296f95 100644
--- a/modules/office/calcurse/default.nix
+++ b/modules/office/calcurse/default.nix
@@ -54,7 +54,19 @@ in
remote = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
- description = "Git remote URL for the calcurse data directory. When set, calcurse-sync uses it automatically on first init instead of prompting.";
+ description = "Git remote URL for the calcurse data directory. Use an https:// URL if 'credential' is configured. When set, calcurse-sync uses it automatically on first init instead of prompting.";
+ };
+ credential = {
+ username = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Username for HTTPS git authentication against the calcurse remote.";
+ };
+ passwordGopassPath = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "gopass entry path holding the password or token used for HTTPS git authentication against the calcurse remote. E.g. 'git/calcurse-sync'.";
+ };
};
};
};
@@ -94,6 +106,9 @@ in
};
commit.gpgSign = false;
tag.gpgSign = false;
+ }
+ // lib.optionalAttrs (config.office.calcurse.sync.credential.passwordGopassPath != null) {
+ credential.helper = "!f() { echo username=${lib.escapeShellArg config.office.calcurse.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.office.calcurse.sync.credential.passwordGopassPath})\"; }; f";
};
}
];
diff --git a/modules/private/calcurse.example.nix b/modules/private/calcurse.example.nix
index 16ee9e8..681d343 100644
--- a/modules/private/calcurse.example.nix
+++ b/modules/private/calcurse.example.nix
@@ -2,6 +2,12 @@
{ ... }:
{
config = {
- office.calcurse.sync.remote = "YOUR_REPOSITORY_URL";
+ office.calcurse.sync = {
+ remote = "YOUR_REPOSITORY_URL";
+ credential = {
+ username = "example";
+ passwordGopassPath = "websites/github.com/example/tokens/calendar";
+ };
+ };
};
}
diff --git a/modules/private/gopass.example.nix b/modules/private/gopass.example.nix
new file mode 100644
index 0000000..2d783c9
--- /dev/null
+++ b/modules/private/gopass.example.nix
@@ -0,0 +1,13 @@
+# Gopass - Template for configuring gopass, specially syncing
+{ ... }:
+{
+ config = {
+ security.gopass.sync = {
+ remote = "YOUR_REPOSITORY_URL";
+ credential = {
+ username = "example";
+ passwordGopassPath = "websites/github.com/example/tokens/calendar";
+ };
+ };
+ };
+}
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index 4d223e9..e543c03 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -10,11 +10,11 @@ let
gopassSshLoadScript = pkgs.writeShellApplication {
name = "gopass-ssh-load";
- runtimeInputs = with pkgs; [
+ runtimeInputs = [
config.security.gopass.package
- gnupg
- openssh
- bash
+ config.security.gpg.package
+ config.security.ssh.package
+ pkgs.bash
];
text =
builtins.replaceStrings
@@ -47,6 +47,26 @@ in
description = "The gopass-ssh-load script package.";
};
};
+ sync = {
+ enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
+ remote = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
+ };
+ credential = {
+ username = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Username for HTTPS git authentication against the gopass remote.";
+ };
+ passwordGopassPath = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "gopass entry path holding the password or token used.";
+ };
+ };
+ };
};
config = lib.mkMerge [
@@ -75,7 +95,16 @@ in
tag = {
gpgSign = false;
};
- };
+ }
+ //
+ lib.optionalAttrs
+ (
+ config.security.gopass.sync.enable
+ && config.security.gopass.sync.credential.passwordGopassPath != null
+ )
+ {
+ credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f";
+ };
}
];
@@ -97,8 +126,30 @@ in
type = "Application";
};
})
+
(lib.mkIf config.security.gopass.ssh-agent.enable {
home.packages = [ config.security.gopass.ssh-agent.package ];
})
+
+ (lib.mkIf config.security.gopass.sync.enable {
+ home.activation.gopassSyncInit =
+ let
+ gopassSyncInit = pkgs.writeShellApplication {
+ name = "gopass-sync-init";
+ runtimeInputs = [
+ pkgs.bash
+ config.development.git.package
+ ];
+ text =
+ builtins.replaceStrings
+ [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ]
+ [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ]
+ (builtins.readFile ./gopass-sync-init.sh);
+ };
+ in
+ lib.hm.dag.entryAfter [ "writeBoundary" ] ''
+ run ${lib.getExe gopassSyncInit} || true
+ '';
+ })
];
}
diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh
index e974713..b9a06e9 100644
--- a/modules/security/gopass/gopass-ssh-load.sh
+++ b/modules/security/gopass/gopass-ssh-load.sh
@@ -1,9 +1,30 @@
#!/usr/bin/env bash
+
+# gopass-ssh-load
+#
+# Load SSH keys into the SSH agent from the gopass password store.
+#
+# This script reads private keys and (optionally) their passphrases from gopass
+# entries under the `ssh/` directory and adds them to the SSH agent served by
+# gpg-agent. It is meant to be run manually whenever a key is imported into or
+# rotated within the gopass store, so the SSH agent picks up the change.
+#
+# Behaviour:
+# * It first verifies that a usable SSH agent socket exists and bails out if
+# not.
+# * It exits early (without doing anything) when the agent already has at
+# least one Ed25519/RSA/ECDSA identity loaded, to avoid useless work and
+# unnecessary gpg passphrase prompts.
+# * For each key listed in GOPASS_SSH_KEYS it writes the corresponding
+# `ssh/<key>` entry to a temporary file, strips the passphrase using the
+# `ssh/<key>/passphrase` entry, and registers the key with `ssh-add`.
+#
+# Temporary key files are written with mode 600 and removed afterwards.
+
set -o errexit
set -o nounset
set -o pipefail
-# Load SSH keys from gopass password store
export GNUPGHOME="@@GNUPGHOME@@"
export GOPASS_SSH_KEYS="@@GOPASS_SSH_KEYS@@"
diff --git a/modules/security/gopass/gopass-sync-init.sh b/modules/security/gopass/gopass-sync-init.sh
new file mode 100644
index 0000000..c7767f9
--- /dev/null
+++ b/modules/security/gopass/gopass-sync-init.sh
@@ -0,0 +1,29 @@
+#!/usr/bin/env bash
+
+# gopass-sync-init
+#
+# Prepare the gopass password store directory for git-backed syncing.
+#
+# This runs during home-manager activation. It ensures the store directory
+# exists, initializes it as a git repository if it is not already one, and adds
+# the configured git remote as `origin` if no remote is set yet. It is a no-op
+# (and thus safe to rerun) when the store is already set up.
+
+STORE_DIR="@@PASSWORD_STORE_DIR@@"
+
+mkdir -p "$STORE_DIR"
+cd "$STORE_DIR" || { echo "Failed to enter $STORE_DIR"; exit 1; }
+
+# Check if the directory is already a git repository; initialize if not
+if ! git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
+ echo "Initializing git repository in $STORE_DIR..."
+ git init
+fi
+
+# Check if the remote 'origin' is set; add it if not
+if ! git remote | grep -q "^origin$"; then
+ echo "Adding remote origin..."
+ git remote add origin "@@REMOTE_REPO_URL@@"
+fi
+
+echo "Password store git setup complete."