aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/gopass/gopass-ssh-load.sh
diff options
context:
space:
mode:
Diffstat (limited to 'modules/security/gopass/gopass-ssh-load.sh')
-rw-r--r--modules/security/gopass/gopass-ssh-load.sh23
1 files changed, 22 insertions, 1 deletions
diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh
index e974713..b9a06e9 100644
--- a/modules/security/gopass/gopass-ssh-load.sh
+++ b/modules/security/gopass/gopass-ssh-load.sh
@@ -1,9 +1,30 @@
#!/usr/bin/env bash
+
+# gopass-ssh-load
+#
+# Load SSH keys into the SSH agent from the gopass password store.
+#
+# This script reads private keys and (optionally) their passphrases from gopass
+# entries under the `ssh/` directory and adds them to the SSH agent served by
+# gpg-agent. It is meant to be run manually whenever a key is imported into or
+# rotated within the gopass store, so the SSH agent picks up the change.
+#
+# Behaviour:
+# * It first verifies that a usable SSH agent socket exists and bails out if
+# not.
+# * It exits early (without doing anything) when the agent already has at
+# least one Ed25519/RSA/ECDSA identity loaded, to avoid useless work and
+# unnecessary gpg passphrase prompts.
+# * For each key listed in GOPASS_SSH_KEYS it writes the corresponding
+# `ssh/<key>` entry to a temporary file, strips the passphrase using the
+# `ssh/<key>/passphrase` entry, and registers the key with `ssh-add`.
+#
+# Temporary key files are written with mode 600 and removed afterwards.
+
set -o errexit
set -o nounset
set -o pipefail
-# Load SSH keys from gopass password store
export GNUPGHOME="@@GNUPGHOME@@"
export GOPASS_SSH_KEYS="@@GOPASS_SSH_KEYS@@"