mirror of
https://github.com/RGBCube/agenix
synced 2025-07-31 02:37:45 +00:00
use unstable verison of rage in place of age
* age limits the number of recipients to 20 * the latest release of rage (0.4.0) doesn't work with ssh-rsa keys
This commit is contained in:
parent
d2dc883f3a
commit
07ce686870
5 changed files with 74 additions and 19 deletions
|
@ -1,4 +1,8 @@
|
|||
{writeShellScriptBin, runtimeShell, age} :
|
||||
{writeShellScriptBin, runtimeShell, pkgs} :
|
||||
let
|
||||
rage = pkgs.callPackage ./rage.nix {};
|
||||
ageBin = "${rage}/bin/rage";
|
||||
in
|
||||
writeShellScriptBin "agenix" ''
|
||||
set -Eeuo pipefail
|
||||
|
||||
|
@ -103,7 +107,7 @@ function edit {
|
|||
DECRYPT+=(--identity "$key")
|
||||
done <<<"$((find ~/.ssh -maxdepth 1 -type f -not -name "*pub" -not -name "config" -not -name "authorized_keys" -not -name "known_hosts") || exit 1)"
|
||||
DECRYPT+=(-o "$CLEARTEXT_FILE" "$FILE")
|
||||
${age}/bin/age "''${DECRYPT[@]}" || exit 1
|
||||
${ageBin} "''${DECRYPT[@]}" || exit 1
|
||||
cp "$CLEARTEXT_FILE" "$CLEARTEXT_FILE.before"
|
||||
fi
|
||||
|
||||
|
@ -127,7 +131,7 @@ function edit {
|
|||
|
||||
ENCRYPT+=(-o "$REENCRYPTED_FILE")
|
||||
|
||||
${age}/bin/age "''${ENCRYPT[@]}" <"$CLEARTEXT_FILE" || exit 1
|
||||
${ageBin} "''${ENCRYPT[@]}" <"$CLEARTEXT_FILE" || exit 1
|
||||
|
||||
mv -f "$REENCRYPTED_FILE" "$1"
|
||||
}
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue