From 41bdeb88009dd232808edee9fc0e4ae94358d8d6 Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Sat, 29 Aug 2026 02:02:23 +0530 Subject: refactor: moving script into modules that makes sense - instead of collecting all scripts into modules/scripts we are moving them to modules that makes sense (yazi-file-chooser.sh into yazi) --- modules/security/gopass/default.nix | 78 +++++++++++++++++++++--------- modules/security/gopass/gopass-ssh-load.sh | 46 ++++++++++++++++++ 2 files changed, 100 insertions(+), 24 deletions(-) create mode 100644 modules/security/gopass/gopass-ssh-load.sh (limited to 'modules/security/gopass') diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index d154226..4fefdd2 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -5,6 +5,32 @@ pkgs, ... }: +let + inherit ((import ../../lib/script.nix { inherit lib pkgs; })) mkScriptModule; + + gopassKeys = config.security.ssh.gopassKeys; + + gopassSshLoad = mkScriptModule { + scope = [ + "security" + "gopass" + ]; + name = "gopass-ssh-load"; + path = ./gopass-ssh-load.sh; + description = "Load SSH keys from gopass password store"; + env = { + GNUPGHOME = config.home.sessionVariables.GNUPGHOME; + GOPASS_SSH_KEYS = lib.concatStringsSep " " gopassKeys; + }; + deps = with pkgs; [ + config.security.gopass.package + gnupg + openssh + bash + ]; + inherit config; + }; +in { options.security.gopass = { enable = lib.mkEnableOption "Enables gopass."; @@ -15,33 +41,37 @@ description = "The gopass package to use."; }; ssh-agent.enable = lib.mkEnableOption "gopass-backed SSH keys for git"; - }; + } + // gopassSshLoad.options.security.gopass; - config = lib.mkIf config.security.gopass.enable { - programs.password-store = { - enable = true; - package = pkgs.gopass.override { passAlias = true; }; - settings = { - PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass"; + config = lib.mkMerge [ + (lib.mkIf config.security.gopass.enable { + programs.password-store = { + enable = true; + package = pkgs.gopass.override { passAlias = true; }; + settings = { + PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass"; + }; }; - }; - home.sessionVariables = { - PASSWORD_STORE_DIR = config.programs.password-store.settings.PASSWORD_STORE_DIR; - }; + home.sessionVariables = { + PASSWORD_STORE_DIR = config.programs.password-store.settings.PASSWORD_STORE_DIR; + }; - home.file.".local/share/icons/hicolor/scalable/apps/gopass.svg" = { - source = ../../../assets/icons/gopass.svg; - }; + home.file.".local/share/icons/hicolor/scalable/apps/gopass.svg" = { + source = ../../../assets/icons/gopass.svg; + }; - xdg.desktopEntries."gopass" = { - name = "gopass"; - exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe config.security.gopass.package}"; - icon = "gopass"; - comment = "Standard Unix password manager (Go implementation)"; - categories = [ "Utility" ]; - terminal = false; - type = "Application"; - }; - }; + xdg.desktopEntries."gopass" = { + name = "gopass"; + exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe config.security.gopass.package}"; + icon = "gopass"; + comment = "Standard Unix password manager (Go implementation)"; + categories = [ "Utility" ]; + terminal = false; + type = "Application"; + }; + }) + gopassSshLoad.config + ]; } diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh new file mode 100644 index 0000000..c6b9a29 --- /dev/null +++ b/modules/security/gopass/gopass-ssh-load.sh @@ -0,0 +1,46 @@ +#!/usr/bin/env bash +set -o errexit +set -o nounset +set -o pipefail + +# Load SSH keys from gopass password store +export GNUPGHOME="${GNUPGHOME:-$HOME/.local/share/gnupg}" + +SSH_AUTH_SOCK="$(gpgconf --list-dirs agent-ssh-socket)" +export SSH_AUTH_SOCK +if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then + echo "Error: SSH_AUTH_SOCK is not set or valid." >&2 + exit 1 +fi + +if ssh-add -l 2>/dev/null | grep -qE "(ED25519|RSA|ECDSA)"; then + exit 0 +fi + +# GOPASS_SSH_KEYS holds a space-separated list of gopass entry names under ssh +if [ -z "${GOPASS_SSH_KEYS:-}" ]; then + echo "Error: GOPASS_SSH_KEYS is not set. Example: GOPASS_SSH_KEYS=\"github gitlab\"" >&2 + exit 1 +fi + +# shellcheck disable=SC2086 +read -r -a keys <<< "$GOPASS_SSH_KEYS" + +for key in "${keys[@]}"; do + if gopass cat "ssh/$key" > /dev/null 2>&1; then + tmpdir=$(mktemp -d) + keyfile="$tmpdir/key" + gopass cat "ssh/$key" > "$keyfile" 2>/dev/null + chmod 600 "$keyfile" + + passphrase=$(gopass cat "ssh/$key/passphrase" 2>/dev/null || true) + if [ -n "$passphrase" ]; then + ssh-keygen -p -P "$passphrase" -N "" -f "$keyfile" 2>/dev/null + fi + + ssh-add "$keyfile" 2>/dev/null + rm -rf "$tmpdir" + else + echo "Warning: no gopass entry ssh/$key" >&2 + fi +done -- cgit v1.2.3