aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--modules/security/gopass/default.nix55
-rw-r--r--modules/security/ssh/git.nix38
-rw-r--r--users/arpit.nix1
3 files changed, 60 insertions, 34 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index 19191ff..a121022 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -8,15 +8,16 @@
{
options.security.gopass = {
enable = lib.mkEnableOption "Enables gopass.";
-
package = lib.mkOption {
type = lib.types.package;
default = pkgs.gopass.override { passAlias = true; };
defaultText = lib.literalExpression "pkgs.gopass.override { passAlias = true; }";
description = "The gopass package to use.";
};
+ ssh-agent = {
+ enable = lib.mkEnableOption "gopass-backed SSH keys for git";
+ };
};
-
config = lib.mkIf config.security.gopass.enable {
programs.password-store = {
enable = true;
@@ -25,5 +26,55 @@
PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass";
};
};
+ systemd.user.services.gopass-ssh-load = lib.mkIf config.security.gopass.ssh-agent.enable {
+ Unit = {
+ Description = "Load SSH keys from gopass into SSH agent for git";
+ After = [
+ "gpg-agent.socket"
+ "graphical-session.target"
+ ];
+ Requires = [
+ "gpg-agent.socket"
+ ];
+ PartOf = [
+ "graphical-session.target"
+ ];
+ };
+ Service = {
+ Type = "oneshot";
+ ExecStart = "${pkgs.writeShellScript "gopass-ssh-load" ''
+ export SSH_AUTH_SOCK="$(${pkgs.gnupg}/bin/gpgconf --list-dirs agent-ssh-socket)"
+
+ if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then
+ exit 1
+ fi
+
+ for key in github gitlab bitbucket codeberg sourcehut; do
+ if ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > /dev/null 2>&1; then
+ tmpdir=$(mktemp -d)
+ keyfile="$tmpdir/key"
+ ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > "$keyfile" 2>/dev/null
+ chmod 600 "$keyfile"
+ if ! ${pkgs.openssh}/bin/ssh-add "$keyfile" 2>/dev/null; then
+ passphrase=$(${config.security.gopass.package}/bin/gopass cat "ssh/$key/passphrase" 2>/dev/null)
+ if [ -n "$passphrase" ]; then
+ tmpcopy=$(mktemp)
+ cp "$keyfile" "$tmpcopy"
+ chmod 600 "$tmpcopy"
+ if ${pkgs.openssh}/bin/ssh-keygen -p -P "$passphrase" -N "" -f "$tmpcopy" 2>/dev/null; then
+ ${pkgs.openssh}/bin/ssh-add "$tmpcopy" 2>/dev/null
+ fi
+ rm -f "$tmpcopy"
+ fi
+ fi
+ rm -rf "$tmpdir"
+ fi
+ done
+ ''}";
+ };
+ Install = {
+ WantedBy = [ "graphical-session.target" ];
+ };
+ };
};
}
diff --git a/modules/security/ssh/git.nix b/modules/security/ssh/git.nix
index 88bd713..23b52ab 100644
--- a/modules/security/ssh/git.nix
+++ b/modules/security/ssh/git.nix
@@ -2,48 +2,22 @@
{ config, lib, ... }:
let
hosts = [
- {
- domain = "github.com";
- identityName = "github";
- }
- {
- domain = "gitlab.com";
- identityName = "gitlab";
- }
- {
- domain = "bitbucket.org";
- identityName = "bitbucket";
- }
- {
- domain = "codeberg.org";
- identityName = "codeberg";
- }
- {
- domain = "git.sr.ht";
- identityName = "sourcehut";
- }
+ "github.com"
+ "gitlab.com"
+ "bitbucket.org"
+ "codeberg.org"
+ "git.sr.ht"
];
mkGitHost =
- { domain, identityName }:
+ domain:
lib.nameValuePair domain {
hostname = domain;
user = "git";
- identityFile = "${config.home.homeDirectory}/.local/share/ssh/git/${identityName}";
- };
-
- mkKeyFile =
- { identityName, ... }:
- lib.nameValuePair identityName {
- enable = true;
- text = "";
- force = false;
};
in
{
config = lib.mkIf (config.security.ssh.enable && config.development.git.useSSH) {
- home.file = builtins.listToAttrs (map mkKeyFile hosts);
-
programs.ssh.settings = builtins.listToAttrs (map mkGitHost hosts);
};
}
diff --git a/users/arpit.nix b/users/arpit.nix
index ab89546..d2803d6 100644
--- a/users/arpit.nix
+++ b/users/arpit.nix
@@ -57,6 +57,7 @@
# Security
security.enteauth.enable = true;
security.gopass.enable = true;
+ security.gopass.ssh-agent.enable = true;
security.gpg.enable = true;
security.openvpn.enable = true;
security.ssh.enable = true;