nix/docs/setup.sh

63 lines
1.7 KiB
Bash
Raw Normal View History

2023-09-22 14:23:12 +02:00
#!/usr/bin/env bash
2023-09-23 15:32:23 +02:00
pushd /etc/nixos/git
2023-09-23 15:13:49 +02:00
# Home-Manager Setup
echo "Setting up Home Manager..... "
2023-09-22 14:09:37 +02:00
sudo mkdir /nix/var/nix/profiles/per-user/albert
2023-09-23 14:33:27 +02:00
home-manager switch -b backup --flake /etc/nixos/git
2023-09-18 09:16:55 +02:00
source ~/.bashrc
# Import and trust the GPG key
2023-09-23 14:31:46 +02:00
echo "Setting up user GPG key..... "
2023-09-23 15:13:49 +02:00
drive=$(lsblk -o serial,name | grep 012345679518 | awk {'print $2'})
2023-09-23 14:31:46 +02:00
sudo mkdir /tmp/drive
sudo cryptsetup luksOpen /dev/${drive}3 usb-luks
sudo mount /dev/mapper/usb-luks /tmp/drive
gpg --import /tmp/drive/gpg/albert@sysctl.io/privkey.asc
2023-09-23 15:05:27 +02:00
sudo umount /tmp/drive
2023-09-23 14:31:46 +02:00
sudo rmdir /tmp/drive
2023-09-23 15:05:27 +02:00
sudo cryptsetup luksClose /dev/mapper/usb-luks
2023-09-23 14:31:46 +02:00
echo -e "5\ny\n" | gpg --command-fd 0 --expert --edit-key albert@sysctl.io trust
2023-09-18 09:16:55 +02:00
# Setup SOPS
2023-09-23 15:13:49 +02:00
echo "Setting up SOPS keys..... "
2023-09-23 15:05:27 +02:00
echo "!!!!!"
echo "!!!!!"
echo "!!!!!"
2023-09-23 15:13:49 +02:00
echo "!!!!! Copy this signature to .sops.yaml: "
2023-09-23 15:05:27 +02:00
echo "!!!!!"
echo "!!!!!"
echo "!!!!!"
2023-09-23 02:05:32 +02:00
sudo ssh-to-pgp \
2023-09-23 15:05:27 +02:00
-comment "Generated `date +%Y.%m.%d`" \
2023-09-23 02:05:32 +02:00
-email "root@`hostname`" \
-i /etc/ssh/ssh_host_rsa_key \
-o /etc/nixos/git/keys/hosts/$(hostname).asc
2023-09-18 09:16:55 +02:00
# Set up ssh keys
2023-09-23 15:13:49 +02:00
echo "Setting up SSH Keys..... "
2023-09-18 09:16:55 +02:00
ssh-keygen -t rsa -b 8192 -f ~/.ssh/id_rsa -N ""
2023-09-22 14:09:37 +02:00
echo "" >> ./keys/ssh/keys.txt
echo "# `whoami`@`hostname`" >> ./keys/ssh/keys.txt
cat /home/albert/.ssh/id_rsa.pub >> ./keys/ssh/keys.txt
2023-09-18 09:16:55 +02:00
# Add all changes to git and and push
2023-09-23 15:13:49 +02:00
echo "Pushing to git..... "
2023-09-19 10:01:58 +02:00
git add keys/hosts/`hostname`.asc
2023-09-22 14:09:37 +02:00
git commit -am "Setup: `whoami`@`hostname`"
2023-09-18 09:16:55 +02:00
git push
2023-09-23 05:10:12 +02:00
# Fix gnupg permissions:
2023-09-23 15:13:49 +02:00
echo "Fixing ~/.gnupg permissions..... "
2023-09-23 05:10:12 +02:00
find ~/.gnupg -type f -exec chmod 600 {} \;
find ~/.gnupg -type d -exec chmod 700 {} \;
2023-09-22 14:09:37 +02:00
echo
echo
2023-09-23 02:05:32 +02:00
echo "Complete. Once '.sops.yaml' is updated, "
2023-09-23 02:19:07 +02:00
echo "you may run 'update-secrets'"
2023-09-23 02:05:32 +02:00
echo "and reboot."
2023-09-23 15:13:49 +02:00
echo
echo "Reminder: Upload these changes to git"
2023-09-23 02:05:32 +02:00
2023-09-23 02:19:07 +02:00
popd