aboutsummaryrefslogtreecommitdiffstats
path: root/modules/security/gopass/default.nix
blob: 23692bfb1abb34133afb2f9fed3b47ba21d9f44d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
# gopass - Standard Unix password manager (Go implementation)
{
  config,
  lib,
  pkgs,
  ...
}:
{
  options.security.gopass = {
    enable = lib.mkEnableOption "Enables gopass.";
    package = lib.mkOption {
      type = lib.types.package;
      default = pkgs.gopass.override { passAlias = true; };
      defaultText = lib.literalExpression "pkgs.gopass.override { passAlias = true; }";
      description = "The gopass package to use.";
    };
    ssh-agent = {
      enable = lib.mkEnableOption "gopass-backed SSH keys for git";
    };
  };
  config = lib.mkIf config.security.gopass.enable {
    programs.password-store = {
      enable = true;
      package = config.security.gopass.package;
      settings = {
        PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass";
      };
    };
    home.sessionVariables = {
      PASSWORD_STORE_DIR = config.programs.password-store.settings.PASSWORD_STORE_DIR;
    };
    systemd.user.services.gopass-ssh-load = lib.mkIf config.security.gopass.ssh-agent.enable {
      Unit = {
        Description = "Load SSH keys from gopass into SSH agent for git";
        After = [
          "gpg-agent.socket"
          "graphical-session.target"
        ];
        Requires = [
          "gpg-agent.socket"
        ];
        PartOf = [
          "graphical-session.target"
        ];
      };
      Service = {
        Type = "oneshot";
        ExecStart = "${pkgs.writeShellScript "gopass-ssh-load" ''
          export SSH_AUTH_SOCK="$(${pkgs.gnupg}/bin/gpgconf --list-dirs agent-ssh-socket)"

          if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then
            exit 1
          fi

          for key in github gitlab bitbucket codeberg sourcehut; do
            if ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > /dev/null 2>&1; then
              tmpdir=$(mktemp -d)
              keyfile="$tmpdir/key"
              ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > "$keyfile" 2>/dev/null
              chmod 600 "$keyfile"
              if ! ${pkgs.openssh}/bin/ssh-add "$keyfile" 2>/dev/null; then
                passphrase=$(${config.security.gopass.package}/bin/gopass cat "ssh/$key/passphrase" 2>/dev/null)
                if [ -n "$passphrase" ]; then
                  tmpcopy=$(mktemp)
                  cp "$keyfile" "$tmpcopy"
                  chmod 600 "$tmpcopy"
                  if ${pkgs.openssh}/bin/ssh-keygen -p -P "$passphrase" -N "" -f "$tmpcopy" 2>/dev/null; then
                    ${pkgs.openssh}/bin/ssh-add "$tmpcopy" 2>/dev/null
                  fi
                  rm -f "$tmpcopy"
                fi
              fi
              rm -rf "$tmpdir"
            fi
          done
        ''}";
      };
      Install = {
        WantedBy = [ "graphical-session.target" ];
      };
    };
  };
}