From 57dc86b062d73446de2f26875ee7b950f1db8ea3 Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Fri, 24 Jul 2026 21:53:14 +0530 Subject: feat(gopass): load SSH keys from gopass for git platforms - Add security.gopass.ssh-agent.enable option - Create gopass-ssh-load systemd oneshot service - Remove identityFile and placeholder files from SSH git host configs - Enable ssh-agent for the user --- modules/security/ssh/git.nix | 38 ++++++-------------------------------- 1 file changed, 6 insertions(+), 32 deletions(-) (limited to 'modules/security/ssh') diff --git a/modules/security/ssh/git.nix b/modules/security/ssh/git.nix index 88bd713..23b52ab 100644 --- a/modules/security/ssh/git.nix +++ b/modules/security/ssh/git.nix @@ -2,48 +2,22 @@ { config, lib, ... }: let hosts = [ - { - domain = "github.com"; - identityName = "github"; - } - { - domain = "gitlab.com"; - identityName = "gitlab"; - } - { - domain = "bitbucket.org"; - identityName = "bitbucket"; - } - { - domain = "codeberg.org"; - identityName = "codeberg"; - } - { - domain = "git.sr.ht"; - identityName = "sourcehut"; - } + "github.com" + "gitlab.com" + "bitbucket.org" + "codeberg.org" + "git.sr.ht" ]; mkGitHost = - { domain, identityName }: + domain: lib.nameValuePair domain { hostname = domain; user = "git"; - identityFile = "${config.home.homeDirectory}/.local/share/ssh/git/${identityName}"; - }; - - mkKeyFile = - { identityName, ... }: - lib.nameValuePair identityName { - enable = true; - text = ""; - force = false; }; in { config = lib.mkIf (config.security.ssh.enable && config.development.git.useSSH) { - home.file = builtins.listToAttrs (map mkKeyFile hosts); - programs.ssh.settings = builtins.listToAttrs (map mkGitHost hosts); }; } -- cgit v1.2.3