* Add SSH Agent as an optional service install Enables gcr-ssh-agent (already shipped via the gnome-keyring dependency) so passphrase-protected SSH keys work from any context: the agent prompts graphically on first use, with opt-in passphrase storage in the keyring. Adds install/remove commands and Install > Service / Remove > Service menu entries. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BReZWvvLsDRUaqgjiRzvZ5 * Clear the agent's SSH_AUTH_SOCK when removing the SSH agent service The socket's ExecStartPost exports SSH_AUTH_SOCK into the user manager with set-environment, which disabling the socket does not undo, so apps launched after removal still pointed at a stopped agent. The environment.d file also has to be deleted before disable reloads the manager, or the generator re-exports it. Only an SSH_AUTH_SOCK pointing at gcr is cleared, so another agent's stays. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Move SSH Agent setup to Setup > Security Turning on an SSH agent is security configuration of the machine rather than installing software, so it sits with SSHD and the other Setup > Security entries. It hides once enabled, as Sudoless Docker does, and Remove > Service > SSH Agent turns it back off. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: David Heinemeier Hansson <david@hey.com>
17 lines
720 B
Bash
Executable File
17 lines
720 B
Bash
Executable File
#!/bin/bash
|
|
|
|
# omarchy:summary=Disable the gcr-ssh-agent SSH agent and its environment override.
|
|
|
|
# The file goes before disable reloads the manager, or the environment generator keeps exporting it.
|
|
rm -f "$HOME/.config/environment.d/90-gcr-ssh-agent.conf"
|
|
systemctl --user disable --now gcr-ssh-agent.socket 2>/dev/null || true
|
|
systemctl --user stop gcr-ssh-agent.service 2>/dev/null || true
|
|
|
|
# The socket exported SSH_AUTH_SOCK to the user manager, which outlives the agent.
|
|
if systemctl --user show-environment | grep -Fqx "SSH_AUTH_SOCK=$XDG_RUNTIME_DIR/gcr/ssh"; then
|
|
systemctl --user unset-environment SSH_AUTH_SOCK
|
|
fi
|
|
|
|
echo ""
|
|
echo "SSH agent has been disabled. Log out and back in for it to take full effect."
|