check if reference exists in key group before adding, skip if it does

This commit is contained in:
2025-05-05 09:38:43 -05:00
parent cf085c4eec
commit b3aedc5ead
2 changed files with 8 additions and 6 deletions
-2
View File
@@ -1,10 +1,8 @@
keys:
hosts:
- &laptop age1ldgnl53dmvl4fjz6hgdj0cvensagddn3ltpmxfm72m8q273w75fsk42p8v
- &nixos-homelab-00 age1kc49egwnslqjjy7yknlv9spxa2xvrq4l6alxumu54ez8vwvf3e2q5ff63k
creation_rules:
- path_regex: secrets/[^/]+\.(yaml|json|env|ini)$
key_groups:
- age:
- *laptop
- *nixos-homelab-00
+8 -4
View File
@@ -14,7 +14,7 @@ function sops_update_age_key() {
keyname="$1"
key="$2"
if [[ -n $(yq ".keys.hosts[] | select(anchor == \"$keyname\")" "${SOPS_FILE}") ]]; then
if [[ -n $(yq ".keys.hosts[] | select(anchor == \"$keyname\")" "${SOPS_FILE}") ]]; then
echo "Updating existing ${keyname} key"
yq -i "(.keys.hosts[] | select(anchor == \"$keyname\")) = \"$key\"" "$SOPS_FILE"
else
@@ -27,9 +27,13 @@ function sops_update_age_key() {
function sops_add_host_to_key_groups() {
h="\"$1\"" # quoted hostname for yaml
echo "Adding key to key group"
yq -i ".creation_rules[].key_groups[].age += [ $h ]" "$SOPS_FILE"
yq -i ".creation_rules[].key_groups[].age[-1] alias = $h" "$SOPS_FILE"
if [[ -z $(yq "select(.creation_rules[].key_groups[].age[] == $h)" "$SOPS_FILE") ]]; then
echo "Adding key to key group"
yq -i ".creation_rules[].key_groups[].age += [ $h ]" "$SOPS_FILE"
yq -i ".creation_rules[].key_groups[].age[-1] alias = $h" "$SOPS_FILE"
else
echo "Reference already exists in key group"
fi
}
# Use generated ssh key generate age key, and update sops