From 7a97abeb25d056907121a42da2a7518f4971b229 Mon Sep 17 00:00:00 2001 From: erik Date: Sun, 12 Jul 2026 21:10:56 +0200 Subject: [PATCH] chore: add edit_secrets helper for sops --- edit_secrets | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100755 edit_secrets diff --git a/edit_secrets b/edit_secrets new file mode 100755 index 0000000..ff4af0f --- /dev/null +++ b/edit_secrets @@ -0,0 +1,36 @@ +#!/usr/bin/env bash +# Edit (or view) a sops-encrypted secrets file with the admin age key. +# +# Usage: +# ./edit_secrets # edit secrets/jupiter.yaml +# ./edit_secrets secrets/other.yaml # edit another file +# ./edit_secrets --show # decrypt to stdout, no edit +# +# The admin age PRIVATE key must be at $SOPS_AGE_KEY_FILE +# (default ~/.config/sops/age/keys.txt). Never commit that key. +set -euo pipefail + +REPO="$(cd "$(dirname "$0")" && pwd)" +cd "$REPO" + +export SOPS_AGE_KEY_FILE="${SOPS_AGE_KEY_FILE:-$HOME/.config/sops/age/keys.txt}" +if [ ! -f "$SOPS_AGE_KEY_FILE" ]; then + echo "error: admin age key not found at $SOPS_AGE_KEY_FILE" >&2 + echo "set SOPS_AGE_KEY_FILE or generate one with age-keygen." >&2 + exit 1 +fi + +show=0 +file="secrets/jupiter.yaml" +for arg in "$@"; do + case "$arg" in + --show) show=1 ;; + *) file="$arg" ;; + esac +done + +if [ "$show" -eq 1 ]; then + exec nix shell nixpkgs#sops -c sops --decrypt "$file" +else + exec nix shell nixpkgs#sops -c sops "$file" +fi