aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/gopass
diff options
context:
space:
mode:
Diffstat (limited to 'modules/security/gopass')
-rw-r--r--modules/security/gopass/default.nix61
-rw-r--r--modules/security/gopass/gopass-ssh-load.sh23
-rw-r--r--modules/security/gopass/gopass-sync-init.sh29
3 files changed, 107 insertions, 6 deletions
diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix
index 4d223e9..e543c03 100644
--- a/modules/security/gopass/default.nix
+++ b/modules/security/gopass/default.nix
@@ -10,11 +10,11 @@ let
gopassSshLoadScript = pkgs.writeShellApplication {
name = "gopass-ssh-load";
- runtimeInputs = with pkgs; [
+ runtimeInputs = [
config.security.gopass.package
- gnupg
- openssh
- bash
+ config.security.gpg.package
+ config.security.ssh.package
+ pkgs.bash
];
text =
builtins.replaceStrings
@@ -47,6 +47,26 @@ in
description = "The gopass-ssh-load script package.";
};
};
+ sync = {
+ enable = lib.mkEnableOption "Enables git-backed syncing of the gopass data directory.";
+ remote = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Git remote URL for the gopass data directory. Use an https:// URL if 'credential' is configured.";
+ };
+ credential = {
+ username = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "Username for HTTPS git authentication against the gopass remote.";
+ };
+ passwordGopassPath = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ description = "gopass entry path holding the password or token used.";
+ };
+ };
+ };
};
config = lib.mkMerge [
@@ -75,7 +95,16 @@ in
tag = {
gpgSign = false;
};
- };
+ }
+ //
+ lib.optionalAttrs
+ (
+ config.security.gopass.sync.enable
+ && config.security.gopass.sync.credential.passwordGopassPath != null
+ )
+ {
+ credential.helper = "!f() { echo username=${lib.escapeShellArg config.security.gopass.sync.credential.username}; echo password=\"$(${config.security.gopass.package}/bin/gopass show -o ${lib.escapeShellArg config.security.gopass.sync.credential.passwordGopassPath})\"; }; f";
+ };
}
];
@@ -97,8 +126,30 @@ in
type = "Application";
};
})
+
(lib.mkIf config.security.gopass.ssh-agent.enable {
home.packages = [ config.security.gopass.ssh-agent.package ];
})
+
+ (lib.mkIf config.security.gopass.sync.enable {
+ home.activation.gopassSyncInit =
+ let
+ gopassSyncInit = pkgs.writeShellApplication {
+ name = "gopass-sync-init";
+ runtimeInputs = [
+ pkgs.bash
+ config.development.git.package
+ ];
+ text =
+ builtins.replaceStrings
+ [ "@@PASSWORD_STORE_DIR@@" "@@REMOTE_REPO_URL@@" ]
+ [ config.programs.password-store.settings.PASSWORD_STORE_DIR config.security.gopass.sync.remote ]
+ (builtins.readFile ./gopass-sync-init.sh);
+ };
+ in
+ lib.hm.dag.entryAfter [ "writeBoundary" ] ''
+ run ${lib.getExe gopassSyncInit} || true
+ '';
+ })
];
}
diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh
index e974713..b9a06e9 100644
--- a/modules/security/gopass/gopass-ssh-load.sh
+++ b/modules/security/gopass/gopass-ssh-load.sh
@@ -1,9 +1,30 @@
#!/usr/bin/env bash
+
+# gopass-ssh-load
+#
+# Load SSH keys into the SSH agent from the gopass password store.
+#
+# This script reads private keys and (optionally) their passphrases from gopass
+# entries under the `ssh/` directory and adds them to the SSH agent served by
+# gpg-agent. It is meant to be run manually whenever a key is imported into or
+# rotated within the gopass store, so the SSH agent picks up the change.
+#
+# Behaviour:
+# * It first verifies that a usable SSH agent socket exists and bails out if
+# not.
+# * It exits early (without doing anything) when the agent already has at
+# least one Ed25519/RSA/ECDSA identity loaded, to avoid useless work and
+# unnecessary gpg passphrase prompts.
+# * For each key listed in GOPASS_SSH_KEYS it writes the corresponding
+# `ssh/<key>` entry to a temporary file, strips the passphrase using the
+# `ssh/<key>/passphrase` entry, and registers the key with `ssh-add`.
+#
+# Temporary key files are written with mode 600 and removed afterwards.
+
set -o errexit
set -o nounset
set -o pipefail
-# Load SSH keys from gopass password store
export GNUPGHOME="@@GNUPGHOME@@"
export GOPASS_SSH_KEYS="@@GOPASS_SSH_KEYS@@"
diff --git a/modules/security/gopass/gopass-sync-init.sh b/modules/security/gopass/gopass-sync-init.sh
new file mode 100644
index 0000000..c7767f9
--- /dev/null
+++ b/modules/security/gopass/gopass-sync-init.sh
@@ -0,0 +1,29 @@
+#!/usr/bin/env bash
+
+# gopass-sync-init
+#
+# Prepare the gopass password store directory for git-backed syncing.
+#
+# This runs during home-manager activation. It ensures the store directory
+# exists, initializes it as a git repository if it is not already one, and adds
+# the configured git remote as `origin` if no remote is set yet. It is a no-op
+# (and thus safe to rerun) when the store is already set up.
+
+STORE_DIR="@@PASSWORD_STORE_DIR@@"
+
+mkdir -p "$STORE_DIR"
+cd "$STORE_DIR" || { echo "Failed to enter $STORE_DIR"; exit 1; }
+
+# Check if the directory is already a git repository; initialize if not
+if ! git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
+ echo "Initializing git repository in $STORE_DIR..."
+ git init
+fi
+
+# Check if the remote 'origin' is set; add it if not
+if ! git remote | grep -q "^origin$"; then
+ echo "Adding remote origin..."
+ git remote add origin "@@REMOTE_REPO_URL@@"
+fi
+
+echo "Password store git setup complete."