{ pkgs, lib, config, ... }: let enabled = config.mod.git.enable; # Wrapper around `ssh-keygen` used as git's SSH signing program. Before a # signing operation it ensures the passphrase-protected signing key is loaded # into the agent — `ssh-keygen -Y sign` reads the key from disk and re-prompts # every commit otherwise, since `AddKeysToAgent` only ever caches auth keys. # Loading it once (through the GUI askpass) lets later commits reuse the # cached key from the agent. Verification and every other op pass straight # through to the real ssh-keygen untouched. sshSignWrapper = pkgs.writeShellApplication { name = "git-ssh-sign"; runtimeInputs = [ pkgs.openssh pkgs.gawk pkgs.gnugrep ]; text = '' key="${config.age.secrets."alex.pinwheel-github.com-signing".path}" case " $* " in *" -Y sign "*) fp="" fp="$(ssh-keygen -lf "$key.pub" 2>/dev/null | awk '{print $2}')" || true if [ -n "$fp" ] && ! ssh-add -l 2>/dev/null | grep -qF "$fp"; then # ~/.ssh/config run chmod 600 ~/.ssh/config ''; home.packages = [ pkgs.tig ]; home.file.".tigrc".text = '' set main-view-line-number = yes set main-view-line-number-interval = 1 ''; }; age.secrets = { "alex.pinwheel-github.com-signing" = { file = ../../../../secrets/pinwheel/alex.pinwheel-github.com-signing.age; path = "/home/alex/.ssh/alex.pinwheel-github.com-signing"; owner = "alex"; group = "users"; }; "alex.pinwheel-github.com-signing.pub" = { file = ../../../../secrets/pinwheel/alex.pinwheel-github.com-signing.pub.age; path = "/home/alex/.ssh/alex.pinwheel-github.com-signing.pub"; owner = "alex"; group = "users"; }; }; }; }