From 96ec0f89101ea414e764565e022b9bc83a96071c Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Thu, 10 Sep 2026 04:32:33 +0530 Subject: fix(security/ssh): fixed the loading ssh key from gopass Now on every home-manager switch we run a script that loads the key form gopass to gpg-agent, then the gpg-agent is responsible for storing it. Anytime gopass changes the ssh key we must run home-manager switch to load the ssh key into gpg agent. --- users/arpit/default.nix | 1 - users/arpit/private.example.nix | 7 ++----- 2 files changed, 2 insertions(+), 6 deletions(-) (limited to 'users') diff --git a/users/arpit/default.nix b/users/arpit/default.nix index 9348884..e21b280 100644 --- a/users/arpit/default.nix +++ b/users/arpit/default.nix @@ -65,7 +65,6 @@ # Security security.gopass.enable = true; - security.gopass.ssh-agent.enable = true; security.gopass.sync.enable = true; security.gpg.enable = true; security.gpg.backup.enable = true; diff --git a/users/arpit/private.example.nix b/users/arpit/private.example.nix index 77e5f54..2f169d9 100644 --- a/users/arpit/private.example.nix +++ b/users/arpit/private.example.nix @@ -38,11 +38,8 @@ }; }; - # SSH keys to load from gopass (entries under ssh/ in the gopass store) - config.security.ssh.gopassKeys = [ - "github" - "gitlab" - ]; + # SSH key to load into the gpg-agent from gopass (entry in the gopass store) + config.security.ssh.sshKeyGopassPath = "ssh/hostname/username"; # Gopass - Template for configuring gopass, specially syncing config.security.gopass.sync = { -- cgit v1.2.3 From bdee6f183cd38ff7539618336c5448a10f432aae Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Thu, 10 Sep 2026 19:43:49 +0530 Subject: feat(security/gopass): added templates for gopass creation wizard --- .../gopass/creation-templates/0-website.yml | 27 ++++++++++++++++ .../security/gopass/creation-templates/1-wifi.yml | 34 ++++++++++++++++++++ .../gopass/creation-templates/2-access-token.yml | 35 +++++++++++++++++++++ .../gopass/creation-templates/3-ssh-key.yml | 36 ++++++++++++++++++++++ modules/security/gopass/default.nix | 13 ++++++++ users/arpit/default.nix | 1 + 6 files changed, 146 insertions(+) create mode 100644 modules/security/gopass/creation-templates/0-website.yml create mode 100644 modules/security/gopass/creation-templates/1-wifi.yml create mode 100644 modules/security/gopass/creation-templates/2-access-token.yml create mode 100644 modules/security/gopass/creation-templates/3-ssh-key.yml (limited to 'users') diff --git a/modules/security/gopass/creation-templates/0-website.yml b/modules/security/gopass/creation-templates/0-website.yml new file mode 100644 index 0000000..0b80a12 --- /dev/null +++ b/modules/security/gopass/creation-templates/0-website.yml @@ -0,0 +1,27 @@ +--- +priority: 0 +name: "Website login" +prefix: "websites" +name_from: + - "url" + - "username" +welcome: "🌐 Creating Website login" +attributes: + - name: "url" + type: "hostname" + prompt: "Website URL" + min: 1 + max: 255 + - name: "username" + type: "string" + prompt: "Username" + min: 1 + - name: "password" + type: "password" + prompt: "Password for the Website" + - name: "totp" + type: "otp" + prompt: "TOTP secret / otpauth:// URI (leave blank if no 2FA)" + - name: "recovery_codes" + type: "string" + prompt: "Recovery/backup codes, space-separated (optional)" diff --git a/modules/security/gopass/creation-templates/1-wifi.yml b/modules/security/gopass/creation-templates/1-wifi.yml new file mode 100644 index 0000000..416a621 --- /dev/null +++ b/modules/security/gopass/creation-templates/1-wifi.yml @@ -0,0 +1,34 @@ +--- +priority: 1 +name: "WiFi network" +prefix: "wifi" +name_from: + - "location" + - "ssid" +welcome: "Creating WiFi network entry" +attributes: + - name: "location" + type: "string" + prompt: "Location (e.g. home, work, office, cafe)" + min: 1 + max: 64 + - name: "ssid" + type: "string" + prompt: "SSID" + min: 1 + max: 32 + - name: "username" + type: "string" + prompt: "Username (leave blank if not Enterprise/802.1X)" + - name: "security" + type: "string" + prompt: "Security (WPA2-Personal, WPA2-Enterprise, WPA3-Personal, WEP, Open)" + - name: "eap_method" + type: "string" + prompt: "EAP-Method (PEAP, TLS, TTLS, PWD) - leave blank unless Enterprise" + - name: "phase2_auth" + type: "string" + prompt: "Phase2-Auth (MSCHAPV2, GTC, etc.) - leave blank unless Enterprise" + - name: "password" + type: "password" + prompt: "Password / PSK for the network" diff --git a/modules/security/gopass/creation-templates/2-access-token.yml b/modules/security/gopass/creation-templates/2-access-token.yml new file mode 100644 index 0000000..1671e79 --- /dev/null +++ b/modules/security/gopass/creation-templates/2-access-token.yml @@ -0,0 +1,35 @@ +--- +priority: 2 +name: "Website access token" +prefix: "websites" +name_from: + - "url" + - "username" + - "token_name" +welcome: "Creating Website access token" +attributes: + - name: "url" + type: "hostname" + prompt: "Website URL" + min: 1 + max: 255 + - name: "username" + type: "string" + prompt: "Username / account this token belongs to" + min: 1 + - name: "token_name" + type: "string" + prompt: "Token name (e.g. api-readonly, ci-deploy, personal-access-token)" + min: 1 + - name: "token" + type: "password" + prompt: "Token value" + - name: "scopes" + type: "string" + prompt: "Scopes/permissions granted (optional)" + - name: "expires" + type: "string" + prompt: "Expiry date, e.g. 2027-01-15 (optional, leave blank if none)" + - name: "comment" + type: "string" + prompt: "Notes (optional)" diff --git a/modules/security/gopass/creation-templates/3-ssh-key.yml b/modules/security/gopass/creation-templates/3-ssh-key.yml new file mode 100644 index 0000000..136a22b --- /dev/null +++ b/modules/security/gopass/creation-templates/3-ssh-key.yml @@ -0,0 +1,36 @@ +--- +priority: 3 +name: "SSH login" +prefix: "ssh" +name_from: + - "host" + - "username" +welcome: "🔐 Creating SSH login" +attributes: + - name: "host" + type: "hostname" + prompt: "Host machine name (hostname, IP, or alias)" + min: 1 + max: 255 + - name: "username" + type: "string" + prompt: "Username" + min: 1 + - name: "password" + type: "password" + prompt: "Password (leave blank if using key-only auth)" + - name: "port" + type: "string" + prompt: "SSH port (optional, default 22)" + - name: "private_key" + type: "password" + prompt: "Private key (paste full contents, e.g. -----BEGIN OPENSSH PRIVATE KEY-----...)" + - name: "public_key" + type: "string" + prompt: "Public key (paste full contents, e.g. ssh-ed25519 AAAA...)" + - name: "key_passphrase" + type: "password" + prompt: "Private key passphrase (optional)" + - name: "comment" + type: "string" + prompt: "Notes (optional)" diff --git a/modules/security/gopass/default.nix b/modules/security/gopass/default.nix index e78e595..123b33f 100644 --- a/modules/security/gopass/default.nix +++ b/modules/security/gopass/default.nix @@ -34,6 +34,9 @@ }; }; }; + creation-templates = { + enable = lib.mkEnableOption "Enables gopass entry creation templates. New entry creation templates for gopass new or gopass create commands."; + }; }; config = lib.mkMerge [ @@ -83,6 +86,16 @@ source = ../../../assets/icons/apps/gopass.svg; }; + home.activation.copyCreationTemplatesForGopass = + lib.mkIf config.security.gopass.creation-templates.enable + ( + lib.hm.dag.entryAfter [ "writeBoundary" ] '' + $DRY_RUN_CMD mkdir -p $VERBOSE_ARG "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" + $DRY_RUN_CMD rm -rf ${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create + $DRY_RUN_CMD cp -r $VERBOSE_ARG --no-preserve=mode ${./creation-templates} "${config.programs.password-store.settings.PASSWORD_STORE_DIR}/.gopass/create" + '' + ); + xdg.desktopEntries."gopass" = { name = "gopass"; exec = "${lib.getExe config.terminal.kitty.package} --class gopass -e ${lib.getExe config.security.gopass.package}"; diff --git a/users/arpit/default.nix b/users/arpit/default.nix index e21b280..a76a893 100644 --- a/users/arpit/default.nix +++ b/users/arpit/default.nix @@ -66,6 +66,7 @@ # Security security.gopass.enable = true; security.gopass.sync.enable = true; + security.gopass.creation-templates.enable = true; security.gpg.enable = true; security.gpg.backup.enable = true; security.gpg-tui.enable = true; -- cgit v1.2.3