Archived
fix(sync-host-keys): extend --remove/--regenerate to cover clan vars
Check NixOS configurations / eval-hosts (pull_request) Successful in 10m26s
Check NixOS configurations / eval-hosts (pull_request) Successful in 10m26s
locally_managed_hosts() only scanned host-keys/ (now empty for all current targets), so --remove and --regenerate-all-keys silently did nothing. Fix: - locally_managed_hosts(): also yields targets from vars/per-machine/*/openssh/ssh_host_ed25519_key/secret, deduped - cmd_remove: shows [clan-vars] or [host-keys/] label per entry; deletes vars/per-machine/<target>/openssh/ in addition to host-keys/ - cmd_regenerate_all: same -- removes clan vars dirs before regenerating Also update CLAUDE.md and README.md to reflect that all flake targets now use clan vars (not just lxc-*); host-keys/ is only for the auto-installer's own pre-seeding path. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01B2EJ4qTsM5KUqhS5c3GAwx
This commit is contained in:
@@ -135,10 +135,17 @@ discover_targets() {
|
||||
}
|
||||
|
||||
locally_managed_hosts() {
|
||||
for f in "$keydir"/*_ssh_host_ed25519_key.pub; do
|
||||
[[ -e "$f" ]] || continue
|
||||
basename "$f" _ssh_host_ed25519_key.pub
|
||||
done
|
||||
{
|
||||
for f in "$keydir"/*_ssh_host_ed25519_key.pub; do
|
||||
[[ -e "$f" ]] || continue
|
||||
basename "$f" _ssh_host_ed25519_key.pub
|
||||
done
|
||||
local d
|
||||
for d in "${repo_root}/vars/per-machine"/*/openssh/ssh_host_ed25519_key/secret; do
|
||||
[[ -f "$d" ]] || continue
|
||||
basename "$(dirname "$(dirname "$(dirname "$d")")")"
|
||||
done
|
||||
} | sort -u
|
||||
}
|
||||
|
||||
add_keys_json="[]"
|
||||
@@ -317,7 +324,9 @@ cmd_remove() {
|
||||
for host in "${hosts[@]}"; do
|
||||
local registered="not registered in .sops.yaml"
|
||||
grep -qE "^ - &${host} age1" "$sops_yaml" && registered="registered in .sops.yaml"
|
||||
printf ' %d) %s (%s)\n' "$i" "$host" "$registered"
|
||||
local where="host-keys/"
|
||||
clan_ssh_key_exists "$host" "$repo_root" && where="clan-vars"
|
||||
printf ' %d) %s [%s, %s]\n' "$i" "$host" "$where" "$registered"
|
||||
i=$((i + 1))
|
||||
done
|
||||
|
||||
@@ -334,7 +343,7 @@ cmd_remove() {
|
||||
local target="${hosts[$((choice - 1))]}"
|
||||
|
||||
if [[ "$dry_run" -ne 1 ]]; then
|
||||
read -rp "Really remove '${target}'? Its host-keys/ files will be deleted and it will lose access to every secrets file it can currently decrypt. (y/N): " confirm
|
||||
read -rp "Really remove '${target}'? Its key files will be deleted and it will lose access to every secrets file it can currently decrypt. (y/N): " confirm
|
||||
if [[ ! "$confirm" =~ ^[Yy]$ ]]; then
|
||||
echo "Cancelled."
|
||||
return
|
||||
@@ -347,11 +356,13 @@ cmd_remove() {
|
||||
apply_edit_plan "$plan"
|
||||
|
||||
if [[ "$dry_run" -eq 1 ]]; then
|
||||
echo "[dry-run] would delete host-keys/${target}_ssh_host_ed25519_key(.pub)."
|
||||
echo "[dry-run] would delete host-keys/${target}_ssh_host_ed25519_key(.pub) if present."
|
||||
echo "[dry-run] would delete vars/per-machine/${target}/openssh/ if present."
|
||||
echo "[dry-run] Nothing was changed. Re-run without --dry-run to apply this."
|
||||
else
|
||||
rm -f "${keydir}/${target}_ssh_host_ed25519_key" "${keydir}/${target}_ssh_host_ed25519_key.pub"
|
||||
echo "Removed host-keys/${target}_ssh_host_ed25519_key(.pub)."
|
||||
rm -rf "${repo_root}/vars/per-machine/${target}/openssh"
|
||||
echo "Removed key for ${target} (host-keys/ and/or vars/per-machine/ as applicable)."
|
||||
echo
|
||||
echo "Review the diff, then commit and push."
|
||||
fi
|
||||
@@ -390,8 +401,8 @@ cmd_regenerate_all() {
|
||||
apply_edit_plan "$plan"
|
||||
|
||||
if [[ "$dry_run" -eq 1 ]]; then
|
||||
echo "[dry-run] would delete ${#hosts[@]} host-keys/ file pair(s)."
|
||||
echo "[dry-run] would then generate fresh replacements for the same hosts"
|
||||
echo "[dry-run] would delete ${#hosts[@]} key pair(s) from host-keys/ and/or vars/per-machine/."
|
||||
echo "[dry-run] would then generate fresh clan vars replacements for the same hosts"
|
||||
echo "[dry-run] (not simulated further here -- run without --dry-run, or"
|
||||
echo "[dry-run] preview a specific target with: $0 <target> --dry-run)."
|
||||
echo
|
||||
@@ -403,8 +414,9 @@ cmd_regenerate_all() {
|
||||
local host
|
||||
for host in "${hosts[@]}"; do
|
||||
rm -f "${keydir}/${host}_ssh_host_ed25519_key" "${keydir}/${host}_ssh_host_ed25519_key.pub"
|
||||
rm -rf "${repo_root}/vars/per-machine/${host}/openssh"
|
||||
done
|
||||
echo "Removed ${#hosts[@]} host-keys/ file pair(s)."
|
||||
echo "Removed ${#hosts[@]} key pair(s)."
|
||||
|
||||
echo
|
||||
echo "Regenerating fresh keys for every current flake target..."
|
||||
|
||||
Reference in New Issue
Block a user