ssh generation/conversion working
This commit is contained in:
+6
-5
@@ -38,7 +38,7 @@ function sops_generate_host_age_key() {
|
|||||||
|
|
||||||
# Get the SSH key
|
# Get the SSH key
|
||||||
target_key="$1"
|
target_key="$1"
|
||||||
|
echo "$target_key"
|
||||||
host_age_key=$(echo "$target_key" | ssh-to-age)
|
host_age_key=$(echo "$target_key" | ssh-to-age)
|
||||||
|
|
||||||
if grep -qv '^age1' <<<"$host_age_key"; then
|
if grep -qv '^age1' <<<"$host_age_key"; then
|
||||||
@@ -55,9 +55,6 @@ function sops_generate_host_age_key() {
|
|||||||
|
|
||||||
# ---HELPER FUNCTIONS END---
|
# ---HELPER FUNCTIONS END---
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
# Create a temporary directory
|
# Create a temporary directory
|
||||||
temp=$(mktemp -d)
|
temp=$(mktemp -d)
|
||||||
|
|
||||||
@@ -123,6 +120,9 @@ if [ -z "$target_hostname" ] || [ -z "$target_destination" ]; then
|
|||||||
help_and_exit
|
help_and_exit
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# delete known hosts
|
||||||
|
sed -i "/$target_hostname/d; /$target_destination/d" ~/.ssh/known_hosts
|
||||||
|
|
||||||
# Create the directory where sshd expects to find the host keys
|
# Create the directory where sshd expects to find the host keys
|
||||||
install -d -m755 "$temp/persist/etc/ssh"
|
install -d -m755 "$temp/persist/etc/ssh"
|
||||||
|
|
||||||
@@ -133,7 +133,8 @@ ssh-keygen -t ed25519 -f "$temp/persist/etc/ssh/ssh_host_ed25519_key" -C "$targe
|
|||||||
chmod 600 "$temp/persist/etc/ssh/ssh_host_ed25519_key"
|
chmod 600 "$temp/persist/etc/ssh/ssh_host_ed25519_key"
|
||||||
|
|
||||||
# update sops with new host ssh key | age key
|
# update sops with new host ssh key | age key
|
||||||
target_key=$(cut -d' ' -f2 "$temp/persist/etc/ssh/ssh_host_ed25519_key.pub")
|
target_key=$(cut -f1- -d" " "$temp/persist/etc/ssh/ssh_host_ed25519_key.pub")
|
||||||
|
echo "$target_key"
|
||||||
sops_generate_host_age_key "$target_key"
|
sops_generate_host_age_key "$target_key"
|
||||||
|
|
||||||
# Install NixOS to the host system with our secrets
|
# Install NixOS to the host system with our secrets
|
||||||
|
|||||||
Reference in New Issue
Block a user