aboutsummaryrefslogtreecommitdiffstats
path: root/users
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar@gmail.com>2026-09-10 04:32:33 +0530
committerArpit Chakladar <arpitchakladar@gmail.com>2026-09-10 04:32:38 +0530
commit96ec0f89101ea414e764565e022b9bc83a96071c (patch)
tree008b0d9dd79cc19afa65df40c79563dc67cf897b /users
parentf1787032594f7ca1a6521f5665a48bb70605d222 (diff)
downloadhome-manager-config-96ec0f89101ea414e764565e022b9bc83a96071c.tar.gz
home-manager-config-96ec0f89101ea414e764565e022b9bc83a96071c.zip
fix(security/ssh): fixed the loading ssh key from gopass
Now on every home-manager switch we run a script that loads the key form gopass to gpg-agent, then the gpg-agent is responsible for storing it. Anytime gopass changes the ssh key we must run home-manager switch to load the ssh key into gpg agent.
Diffstat (limited to 'users')
-rw-r--r--users/arpit/default.nix1
-rw-r--r--users/arpit/private.example.nix7
2 files changed, 2 insertions, 6 deletions
diff --git a/users/arpit/default.nix b/users/arpit/default.nix
index 9348884..e21b280 100644
--- a/users/arpit/default.nix
+++ b/users/arpit/default.nix
@@ -65,7 +65,6 @@
# Security
security.gopass.enable = true;
- security.gopass.ssh-agent.enable = true;
security.gopass.sync.enable = true;
security.gpg.enable = true;
security.gpg.backup.enable = true;
diff --git a/users/arpit/private.example.nix b/users/arpit/private.example.nix
index 77e5f54..2f169d9 100644
--- a/users/arpit/private.example.nix
+++ b/users/arpit/private.example.nix
@@ -38,11 +38,8 @@
};
};
- # SSH keys to load from gopass (entries under ssh/ in the gopass store)
- config.security.ssh.gopassKeys = [
- "github"
- "gitlab"
- ];
+ # SSH key to load into the gpg-agent from gopass (entry in the gopass store)
+ config.security.ssh.sshKeyGopassPath = "ssh/hostname/username";
# Gopass - Template for configuring gopass, specially syncing
config.security.gopass.sync = {