Archived
Check NixOS configurations / eval-hosts (pull_request) Failing after 30m6s
scripts/ had grown to 10 top-level scripts covering three distinct concerns (sops/age + SSH host-key management, Proxmox deployment, and repo-wide bootstrap/CI) with no grouping. Move the key-management scripts (backup-admin-key.sh, rotate-admin-key.sh, prepare-host-key.sh, sync-host-keys.sh) into scripts/secrets/, and the Proxmox scripts (create-proxmox-resource.sh, configure-nix-cache-client.sh) into scripts/proxmox/; leave env.sh, codex-setup.sh, codex-maintenance.sh, and bump-nixpkgs-release.sh at the top level (frequently hand-typed or pure shared config) and scripts/lib/ as-is. Updates every cross-reference: each moved script's repo_root computation (now one directory deeper), shellcheck source= directives, inter-script paths (create-proxmox-resource.sh's call into sync-host-keys.sh and its remote bootstrap of configure-nix-cache-client.sh on the Proxmox node), and every doc/module mention (CLAUDE.md's Scripts section reorganized to match, README.md, docs/auto-installer.md, docs/proxmox-images.md, modules/installer/common.nix, modules/platforms/lxc.nix). CI workflows need no change -- they only invoke codex-maintenance.sh, which didn't move. Verified via bash -n, shellcheck (no new warnings beyond the pre-existing SC1091/SC2029/SC2095 baseline), and live dry-runs of sync-host-keys.sh --all and create-proxmox-resource.sh --list from their new paths. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
31 lines
1.3 KiB
Bash
31 lines
1.3 KiB
Bash
#!/usr/bin/env bash
|
|
# Shared SSH-host-key / age-conversion helpers for scripts/secrets/sync-host-keys.sh
|
|
# and scripts/secrets/prepare-host-key.sh -- both generate the same kind of key
|
|
# (ed25519, no passphrase, the sops-nix age-derivation input) and convert it
|
|
# to an age recipient the same way; kept in one place so the two can't
|
|
# drift apart.
|
|
#
|
|
# Uses NIX_OPTS (an array of extra `nix-shell` options -- see env.sh's
|
|
# nix_extra_opts) if the caller has already set it, so a decision to avoid
|
|
# an unreachable nix-cache is reused here instead of probed again. Falls
|
|
# back to no extra options if the caller never sourced env.sh.
|
|
if ! declare -p NIX_OPTS >/dev/null 2>&1; then
|
|
declare -a NIX_OPTS=()
|
|
fi
|
|
|
|
# generate_host_ed25519_key <hostname> <keyfile>
|
|
# Writes <keyfile> and <keyfile>.pub. Caller is responsible for refusing to
|
|
# overwrite an existing keyfile -- this always runs ssh-keygen fresh.
|
|
generate_host_ed25519_key() {
|
|
local hostname="$1" keyfile="$2"
|
|
nix-shell "${NIX_OPTS[@]}" -p openssh --run \
|
|
"ssh-keygen -t ed25519 -N '' -C '${hostname}' -f '${keyfile}'" >/dev/null
|
|
}
|
|
|
|
# ssh_pubkey_to_age <pubkeyfile>
|
|
# Prints the age public key derived from an ed25519 SSH public key file.
|
|
ssh_pubkey_to_age() {
|
|
local pubkeyfile="$1"
|
|
nix-shell "${NIX_OPTS[@]}" -p ssh-to-age --run "ssh-to-age -i '${pubkeyfile}'"
|
|
}
|