diff options
| author | Arpit Chakladar <arpitchakladar@gmail.com> | 2026-09-10 04:32:33 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar@gmail.com> | 2026-09-10 04:32:38 +0530 |
| commit | 96ec0f89101ea414e764565e022b9bc83a96071c (patch) | |
| tree | 008b0d9dd79cc19afa65df40c79563dc67cf897b /users | |
| parent | f1787032594f7ca1a6521f5665a48bb70605d222 (diff) | |
| download | home-manager-config-96ec0f89101ea414e764565e022b9bc83a96071c.tar.gz home-manager-config-96ec0f89101ea414e764565e022b9bc83a96071c.zip | |
fix(security/ssh): fixed the loading ssh key from gopass
Now on every home-manager switch we run a script that loads the key form
gopass to gpg-agent, then the gpg-agent is responsible for storing it.
Anytime gopass changes the ssh key we must run home-manager switch to
load the ssh key into gpg agent.
Diffstat (limited to 'users')
| -rw-r--r-- | users/arpit/default.nix | 1 | ||||
| -rw-r--r-- | users/arpit/private.example.nix | 7 |
2 files changed, 2 insertions, 6 deletions
diff --git a/users/arpit/default.nix b/users/arpit/default.nix index 9348884..e21b280 100644 --- a/users/arpit/default.nix +++ b/users/arpit/default.nix @@ -65,7 +65,6 @@ # Security security.gopass.enable = true; - security.gopass.ssh-agent.enable = true; security.gopass.sync.enable = true; security.gpg.enable = true; security.gpg.backup.enable = true; diff --git a/users/arpit/private.example.nix b/users/arpit/private.example.nix index 77e5f54..2f169d9 100644 --- a/users/arpit/private.example.nix +++ b/users/arpit/private.example.nix @@ -38,11 +38,8 @@ }; }; - # SSH keys to load from gopass (entries under ssh/ in the gopass store) - config.security.ssh.gopassKeys = [ - "github" - "gitlab" - ]; + # SSH key to load into the gpg-agent from gopass (entry in the gopass store) + config.security.ssh.sshKeyGopassPath = "ssh/hostname/username"; # Gopass - Template for configuring gopass, specially syncing config.security.gopass.sync = { |
