#!/usr/bin/env bash if [ -z "$NIXOPS_ENV_LOADED" ]; then echo "Please load the environment with direnv" exit 1; fi umask 0077 TEMP=$(mktemp -d /tmp/XXXXXX-nixops-files) chmod go-rwx $TEMP finish() { rm -rf "$TEMP" } trap finish EXIT sops -d secrets/vars.yml | yq -r .ssl_keys.nix_repository > $TEMP/id_ed25519 export SSH_IDENTITY_FILE="$TEMP/id_ed25519" "$@"