mirror of
https://github.com/dnlbauer/dotfiles.git
synced 2026-09-10 13:35:30 +00:00
feat: add machineClass and ssh config
This commit is contained in:
@@ -1,7 +1,14 @@
|
|||||||
{{- $github_email := promptStringOnce . "github_email" "Github Email address" -}}
|
{{- $github_email := promptStringOnce . "github_email" "Github Email address" -}}
|
||||||
|
{{- $machineClass := promptChoiceOnce . "machineClass" "Machine class (private/server/public)" (list "private" "server" "public") -}}
|
||||||
|
|
||||||
|
encryption = "age"
|
||||||
|
[age]
|
||||||
|
identity = "~/.config/chezmoi/key.txt"
|
||||||
|
recipient = "age1q8r0dfsjadzq8fy6453acvurhzt7ndptyur0xrkwfh76tx7fwyks3lxp42"
|
||||||
|
|
||||||
[data]
|
[data]
|
||||||
github_email = {{ $github_email | quote }}
|
github_email = {{ $github_email | quote }}
|
||||||
|
machineClass = {{ $machineClass | quote }}
|
||||||
[git]
|
[git]
|
||||||
autoPush = true
|
autoPush = true
|
||||||
autoCommit = true
|
autoCommit = true
|
||||||
|
|||||||
@@ -4,3 +4,9 @@ README.md
|
|||||||
.agents
|
.agents
|
||||||
CLAUDE.md
|
CLAUDE.md
|
||||||
CLAUDE.local.md
|
CLAUDE.local.md
|
||||||
|
key.txt.age
|
||||||
|
|
||||||
|
{{- if ne .machineClass "private" }}
|
||||||
|
.ssh/config.d/home
|
||||||
|
.ssh/config.d/web
|
||||||
|
{{- end }}
|
||||||
|
|||||||
@@ -40,4 +40,5 @@ There is no build, lint, or test suite — this is a config repo. "Testing" a ch
|
|||||||
- **`dot_gitconfig.tmpl`** — templated on `.github_email`; wires up diff-so-fancy/difftastic as pagers and nbdime for Jupyter notebook diffing. `~/.gitconfig.local` (untracked) is included for machine-specific overrides.
|
- **`dot_gitconfig.tmpl`** — templated on `.github_email`; wires up diff-so-fancy/difftastic as pagers and nbdime for Jupyter notebook diffing. `~/.gitconfig.local` (untracked) is included for machine-specific overrides.
|
||||||
- **`private_dot_config/`** → installs to `~/.config/` with restrictive permissions (nvim, matplotlib styles, fontconfig).
|
- **`private_dot_config/`** → installs to `~/.config/` with restrictive permissions (nvim, matplotlib styles, fontconfig).
|
||||||
- **`bin/`** → installs to `~/bin/`; `executable_term-background` detects terminal light/dark background via OSC 11 for theme-matching in nvim etc.
|
- **`bin/`** → installs to `~/bin/`; `executable_term-background` detects terminal light/dark background via OSC 11 for theme-matching in nvim etc.
|
||||||
- **`.chezmoiignore`** lists source-repo-only paths (`README.md`, `.claude`, `.codex`, `.agents`) that chezmoi should never install to `$HOME`.
|
- **`.chezmoiignore`** lists source-repo-only paths (`README.md`, `.claude`, `.codex`, `.agents`) that chezmoi should never install to `$HOME`, plus a `machineClass`-gated conditional excluding `.ssh/config.d/home` and `.ssh/config.d/web` on any machine that isn't `machineClass = "private"`.
|
||||||
|
- **Age encryption**: `key.txt.age` (repo root) is an age private key encrypted with a passphrase.`run_onchange_before_02_decrypt-age-key.sh.tmpl` decrypts it into `~/.config/chezmoi/key.txt`.
|
||||||
|
|||||||
10
key.txt.age
Normal file
10
key.txt.age
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNjcnlwdCBQZUNHSE1VaUUrcHNrZS9n
|
||||||
|
aEd3QTNRIDE4CmUxQkVTanJ1aUpEMFY5ZmVzWlA4dDRjUXB5MlRva01NRU94YTY1
|
||||||
|
a2trVEEKLS0tIHI0RFJqVkNOVVVVV1ZkbEtIRGprMkNnRzFsaHJlQWI4clZGUE1p
|
||||||
|
V0hPUUEKyI/d5w+oADNHOhN5/JRBvlAhIdnja8VTnQwNGkowq7Pw4VhajpRGjkAO
|
||||||
|
3aEyc3WLaJIq16IyKGW6OmLP37mR7ZixL2xOm9i7jqbze8v4UxJWbtNA5pVvgMAA
|
||||||
|
fa1nneE/NSGdnBExNeSXp3mxnFEUgYVLMCEOMLe/be98xqSLXXxJ05o53RVqX7YF
|
||||||
|
uvUQrvcHDVE0fujTuwofKnXpKqk5BVvgciiaSb9yKR6mLrNkj8Hq1828WNq6Diec
|
||||||
|
qc/4CDSRMa8nVxYLKtVSLvKriD4nDGhSN5zPGYO5AqgOkIg=
|
||||||
|
-----END AGE ENCRYPTED FILE-----
|
||||||
14
private_dot_ssh/config.d/encrypted_home.age
Normal file
14
private_dot_ssh/config.d/encrypted_home.age
Normal file
@@ -0,0 +1,14 @@
|
|||||||
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBTN1ppYjdMNHpZMWw1Qkll
|
||||||
|
MjBYSWtVRSttYWQ1czRJTU1hTHAyS0R1TjBjCnQ4WlMrdXljeHdiZ0g2VHFIeXhS
|
||||||
|
YWw3OHVJWk5JcGppZk1kekROWjdjbE0KLS0tIEltU0pqKzRFeWdVOUVnWHdDTnZW
|
||||||
|
cHIyY25wZ1EvL1Z1aVJYbFVlSHcrdnMKf9IUp+5PkkSnmmslWchqss3UJbLTkYOh
|
||||||
|
ACl/3NtI5ROgMyMqRucoVCeagTKVfkURWjMcUmCDQBMrwKMF96f7Xvm3xR0/cDbU
|
||||||
|
BBnvDC01ZhSXpjK5BzHloxhWSeGJPHMovj1kGsGNDk8mXoH1D0qnSU1StSoCQKvD
|
||||||
|
b8JREL3MtUr7YuGLmwOZCjilrAfL1y5YLV7NkDiuBJN1Mm+3pTtOUQt1qQcB4Chr
|
||||||
|
Pi/8HSqUtULrL5Kxa9XP1yYfdvRkLXEcOD9aNHp9VxH/emI7hKYjzYGdeGl6On6x
|
||||||
|
tBInuCFsORlhVVi9m7k66PEabv0Aw+7+CC0ezfPprRMZJEp8m6k8o+dimF+4JvnE
|
||||||
|
AedI6GwOBHnfrfjPp9p5MuNnXyFMav0/uf+xElb9Cw1RFPnP50FzbX9dHLtqgKf7
|
||||||
|
asCEAlGfxg2ix9dnJz42f2dHI4ZPacfLpRAGKSCyBqQskmU3uNtKSOy7uwBkU6C+
|
||||||
|
uFIkPyKgDlSlGap4KGTqLQzE9fSmuv98JQiN0Z4nss/e51t1DKXLULPy
|
||||||
|
-----END AGE ENCRYPTED FILE-----
|
||||||
10
private_dot_ssh/config.d/encrypted_web.age
Normal file
10
private_dot_ssh/config.d/encrypted_web.age
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBpL1FleXg3WDR3K3pkcEpB
|
||||||
|
QVdwQU1UV3h5Uitaamw3OTBaUXUreHFPbFJjCndZOUJ2ZlRyc0RGWFlXUGMzYkpY
|
||||||
|
VWtKMDhQVTJlQ2cxK1kwU0VITGowcGsKLS0tIDY0ZFFNZ3JMdElVcmNkeElZYVJE
|
||||||
|
bWE1bU92UEFGYmkzSmRZTmZQcEs3S0EKe2vkmr30RGDw33AvL3FlxojmUzx8eslB
|
||||||
|
GQgU0lVxAm73B5kAexV2bSCLMhXLhPGZrnID7ZiV7ZHJMKjHnoSM0vjOwL1EylAn
|
||||||
|
3YBytrGmKd1FWgdzY8F/yF+dSIBZ6+cxttPW4lW9IBGiZL4fFX1fxt2DNR3MSzj/
|
||||||
|
OWwJ5yW1MkVYJOwfB9MflylsW4KDxkcVuBiUpGwuJ9HlkN2QKIso56YQWm5UH0L5
|
||||||
|
fl7gKQMkgmPnBzQG1uv9RdllTOAQcw==
|
||||||
|
-----END AGE ENCRYPTED FILE-----
|
||||||
5
private_dot_ssh/private_executable_config
Normal file
5
private_dot_ssh/private_executable_config
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
Include config.d/*
|
||||||
|
|
||||||
|
Host *:
|
||||||
|
PermitLocalCommand yes
|
||||||
|
|
||||||
@@ -6,7 +6,7 @@ echo "Installing packages"
|
|||||||
echo "Updating sources..."
|
echo "Updating sources..."
|
||||||
sudo apt update -qq
|
sudo apt update -qq
|
||||||
|
|
||||||
for package in zsh xsel unzip git git-extras neovim git ripgrep pipx; do
|
for package in zsh xsel unzip git git-extras neovim git ripgrep pipx age; do
|
||||||
if dpkg -s "$package" >/dev/null 2>&1; then
|
if dpkg -s "$package" >/dev/null 2>&1; then
|
||||||
echo $package is already installed.
|
echo $package is already installed.
|
||||||
else
|
else
|
||||||
16
run_onchange_before_02_decrypt_age_key.sh.tmpl
Normal file
16
run_onchange_before_02_decrypt_age_key.sh.tmpl
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
{{- if ne .machineClass "private" }}
|
||||||
|
exit 0
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
echo "Decrypting age key ..."
|
||||||
|
if [ ! -f "$HOME/.config/chezmoi/key.txt" ]; then
|
||||||
|
mkdir -p "$HOME/.config/chezmoi"
|
||||||
|
chezmoi age decrypt --output "$HOME/.config/chezmoi/key.txt" --passphrase "{{ .chezmoi.sourceDir }}/key.txt.age"
|
||||||
|
chmod 600 "$HOME/.config/chezmoi/key.txt"
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Done decrypting age key"
|
||||||
Reference in New Issue
Block a user