#!/usr/bin/env bash
-if [ -z "$NIXOPS" ]; then
- echo "Please set NIXOPS to the nixops command"
+if [ -z "$NIXOPS_ENV_LOADED" ]; then
+ echo "Please load the environment with direnv"
exit 1;
fi
+umask 0077
TEMP=$(mktemp -d /tmp/XXXXXX-nixops-files)
chmod go-rwx $TEMP
finish() {
rm -rf "$TEMP"
- $NIXOPS set-args --unset privateFiles
}
trap finish EXIT
-# pass cannot "just" list files in a directory without showing a tree :(
-files=$(pass ls Nixops/files | sed -e '1d' -e 's/^.* //')
+sops -d secrets/vars.yml | yq -r .ssl_keys.nix_repository > $TEMP/id_ed25519
-for file in $files; do
- pass show "Nixops/files/$file" > $TEMP/$file
-done
-$NIXOPS set-args --argstr privateFiles "$TEMP"
+export SSH_IDENTITY_FILE="$TEMP/id_ed25519"
"$@"