aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--modules/development/git/assertions.nix8
-rw-r--r--modules/development/git/default.nix11
-rw-r--r--modules/office/calcurse/default.nix17
-rw-r--r--modules/private/calcurse.example.nix8
-rw-r--r--modules/private/gopass.example.nix13
-rw-r--r--modules/security/gopass/default.nix61
-rw-r--r--modules/security/gopass/gopass-ssh-load.sh23
-rw-r--r--modules/security/gopass/gopass-sync-init.sh29
-rw-r--r--users/arpit.nix5
9 files changed, 147 insertions, 28 deletions
diff --git a/modules/development/git/assertions.nix b/modules/development/git/assertions.nix
index 02acd92..c66714a 100644
--- a/modules/development/git/assertions.nix
+++ b/modules/development/git/assertions.nix
@@ -3,14 +3,6 @@
{
assertions = [
{
- assertion =
- !config.development.git.useSSH || (config.development.git.enable && config.security.ssh.enable);
- message = ''
- development.git.useSSH is enabled but security.ssh.enable is not.
- SSH must be enabled (security.ssh.enable = true) to use SSH for git.
- '';
- }
- {
assertion = !config.development.git.signing.signByDefault || config.development.git.enable;
message = ''
development.git.signing.signByDefault is enabled but development.git.enable is not.
diff --git a/modules/development/git/default.nix b/modules/development/git/default.nix
index a62f866..ce92674 100644
--- a/modules/development/git/default.nix
+++ b/modules/development/git/default.nix
@@ -30,8 +30,6 @@
description = "Git email.";
};
- useSSH = lib.mkEnableOption "Use SSH instead of HTTPS for common git platforms.";
-
signing = {
key = lib.mkOption {
type = lib.types.nullOr lib.types.str;
@@ -62,16 +60,9 @@
};
log.showSignature = true;
pull.rebase = true;
+ init.defaultBranch = "master";
}
- (lib.optionalAttrs config.development.git.useSSH {
- url."git@github.com:".insteadOf = "https://github.com/";
- url."git@gitlab.com:".insteadOf = "https://gitlab.com/";
- url."git@bitbucket.org:".insteadOf = "https://bitbucket.org/";
- url."git@codeberg.org:".insteadOf = "https://codeberg.org/";
- url."git@git.sr.ht:".insteadOf = "https://git.sr.ht/";
- })
-
(lib.optionalAttrs config.development.delta.enable {
core.pager = "delta";
interactive.diffFilter = "delta --color-only";
diff --git a/modules/office/calcurse/default.nix b/modules/office/calcurse/default.nix
index c72896e..3296f95 100644
--- a/modules/office/calcurse/default.nix
+++ b/modules/office/calcurse/default.nix
@@ -54,7 +54,19 @@ in
remote = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
- description = "Git remote URL for the calcurse data directory. When set, calcurse-sync uses it automatically on first init instead of prompting.";
+ description = "Git remote URL for the calcurse data directory. Use an https:// URL if 'credential' is configured. When set, calcurse-sync uses it automatically on first init instead of prompting.";
+ };
+ credential = {
+ username = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Username for HTTPS git authentication against the calcurse remote.";
+ };
+ passwordGopassPath = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "gopass entry path holding the password or token used for HTTPS git authentication against the calcurse remote. E.g. 'git/calcurse-sync'.";
+ };
};
};
};
@@ -94,6 +106,9 @@ in
};
commit.gpgSign = false;
tag.gpgSign = false;
+ }
+ // lib.optionalAttrs (config.office.calcurse.sync.credential.passwordGopassPath != null) {
+ credential.helper = "!f() { echo username=${lib.escapeShellArg config.office.calcurse.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.office.calcurse.sync.credential.passwordGopassPath})\"; }; f";
};
}
];
diff --git a/modules/private/calcurse.example.nix b/modules/private/calcurse.example.nix
index 16ee9e8..681d343 100644
--- a/modules/private/calcurse.example.nix
+++ b/modules/private/calcurse.example.nix
@@ -2,6 +2,12 @@
{ ... }:
{
config = {
- office.calcurse.sync.remote = "YOUR_REPOSITORY_URL";
+ office.calcurse.sync = {
+ remote = "YOUR_REPOSITORY_URL";
+ credential = {
+ username = "example";
+ passwordGopassPath = "websites/github.com/example/tokens/calendar";
+ };
+ };
};
}
diff --git a/modules/private/gopass.example.nix b/modules/private/gopass.example.nix
new file mode 100644
index 0000000..2d783c9
--- /dev/null
+++ b/modules/private/gopass.example.nix
@@ -0,0 +1,13 @@
+# Gopass - Template for configuring gopass, specially syncing
+{ ... }:
+{
+ config = {
+ security.gopass.sync = {
+ remote = "YOUR_REPOSITORY_URL";
+ credential = {
+ username = "example";
+ passwordGopassPath = "websites/github.com/example/tokens/calendar";
+ };
+ };
+ };
+}
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index 4d223e9..e543c03 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -10,11 +10,11 @@ let
gopassSshLoadScript = pkgs.writeShellApplication {
name = "gopass-ssh-load";
- runtimeInputs = with pkgs; [
+ runtimeInputs = [
config.security.gopass.package
- gnupg
- openssh
- bash
+ config.security.gpg.package
+ config.security.ssh.package
+ pkgs.bash
];
text =
builtins.replaceStrings
@@ -47,6 +47,26 @@ in
description = "The gopass-ssh-load script package.";
};
};
+ sync = {
+ enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
+ remote = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
+ };
+ credential = {
+ username = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Username for HTTPS git authentication against the gopass remote.";
+ };
+ passwordGopassPath = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "gopass entry path holding the password or token used.";
+ };
+ };
+ };
};
config = lib.mkMerge [
@@ -75,7 +95,16 @@ in
tag = {
gpgSign = false;
};
- };
+ }
+ //
+ lib.optionalAttrs
+ (
+ config.security.gopass.sync.enable
+ && config.security.gopass.sync.credential.passwordGopassPath != null
+ )
+ {
+ credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f";
+ };
}
];
@@ -97,8 +126,30 @@ in
type = "Application";
};
})
+
(lib.mkIf config.security.gopass.ssh-agent.enable {
home.packages = [ config.security.gopass.ssh-agent.package ];
})
+
+ (lib.mkIf config.security.gopass.sync.enable {
+ home.activation.gopassSyncInit =
+ let
+ gopassSyncInit = pkgs.writeShellApplication {
+ name = "gopass-sync-init";
+ runtimeInputs = [
+ pkgs.bash
+ config.development.git.package
+ ];
+ text =
+ builtins.replaceStrings
+ [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ]
+ [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ]
+ (builtins.readFile ./gopass-sync-init.sh);
+ };
+ in
+ lib.hm.dag.entryAfter [ "writeBoundary" ] ''
+ run ${lib.getExe gopassSyncInit} || true
+ '';
+ })
];
}
diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh
index e974713..b9a06e9 100644
--- a/modules/security/gopass/gopass-ssh-load.sh
+++ b/modules/security/gopass/gopass-ssh-load.sh
@@ -1,9 +1,30 @@
#!/usr/bin/env bash
+
+# gopass-ssh-load
+#
+# Load SSH keys into the SSH agent from the gopass password store.
+#
+# This script reads private keys and (optionally) their passphrases from gopass
+# entries under the `ssh/` directory and adds them to the SSH agent served by
+# gpg-agent. It is meant to be run manually whenever a key is imported into or
+# rotated within the gopass store, so the SSH agent picks up the change.
+#
+# Behaviour:
+# * It first verifies that a usable SSH agent socket exists and bails out if
+# not.
+# * It exits early (without doing anything) when the agent already has at
+# least one Ed25519/RSA/ECDSA identity loaded, to avoid useless work and
+# unnecessary gpg passphrase prompts.
+# * For each key listed in GOPASS_SSH_KEYS it writes the corresponding
+# `ssh/<key>` entry to a temporary file, strips the passphrase using the
+# `ssh/<key>/passphrase` entry, and registers the key with `ssh-add`.
+#
+# Temporary key files are written with mode 600 and removed afterwards.
+
set -o errexit
set -o nounset
set -o pipefail
-# Load SSH keys from gopass password store
export GNUPGHOME="@@GNUPGHOME@@"
export GOPASS_SSH_KEYS="@@GOPASS_SSH_KEYS@@"
diff --git a/modules/security/gopass/gopass-sync-init.sh b/modules/security/gopass/gopass-sync-init.sh
new file mode 100644
index 0000000..c7767f9
--- /dev/null
+++ b/modules/security/gopass/gopass-sync-init.sh
@@ -0,0 +1,29 @@
+#!/usr/bin/env bash
+
+# gopass-sync-init
+#
+# Prepare the gopass password store directory for git-backed syncing.
+#
+# This runs during home-manager activation. It ensures the store directory
+# exists, initializes it as a git repository if it is not already one, and adds
+# the configured git remote as `origin` if no remote is set yet. It is a no-op
+# (and thus safe to rerun) when the store is already set up.
+
+STORE_DIR="@@PASSWORD_STORE_DIR@@"
+
+mkdir -p "$STORE_DIR"
+cd "$STORE_DIR" || { echo "Failed to enter $STORE_DIR"; exit 1; }
+
+# Check if the directory is already a git repository; initialize if not
+if ! git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
+ echo "Initializing git repository in $STORE_DIR..."
+ git init
+fi
+
+# Check if the remote 'origin' is set; add it if not
+if ! git remote | grep -q "^origin$"; then
+ echo "Adding remote origin..."
+ git remote add origin "@@REMOTE_REPO_URL@@"
+fi
+
+echo "Password store git setup complete."
diff --git a/users/arpit.nix b/users/arpit.nix
index 989245e..837d2bf 100644
--- a/users/arpit.nix
+++ b/users/arpit.nix
@@ -5,6 +5,7 @@
../modules/private/calcurse.nix
../modules/private/email.nix
../modules/private/git.nix
+ ../modules/private/gopass.nix
];
nixpkgs.config.allowUnfree = true;
@@ -31,7 +32,6 @@
development.bruno.enable = true;
development.delta.enable = true;
development.git.enable = true;
- development.git.useSSH = true;
development.git.signing.signByDefault = true;
development.lazygit.enable = true;
development.nixvim.enable = true;
@@ -68,7 +68,8 @@
# Security
security.gopass.enable = true;
- security.gopass.ssh-agent.enable = false;
+ security.gopass.ssh-agent.enable = true;
+ security.gopass.sync.enable = true;
security.gpg.enable = true;
security.gpg.backup.enable = true;
security.gpg-tui.enable = true;