Files
omarchy/bin/omarchy-setup-security-ssh-agent
T
324f0ba5e6 Add SSH Agent (gcr-ssh-agent) as an optional service install (#9399)
* Add SSH Agent as an optional service install

Enables gcr-ssh-agent (already shipped via the gnome-keyring dependency)
so passphrase-protected SSH keys work from any context: the agent prompts
graphically on first use, with opt-in passphrase storage in the keyring.
Adds install/remove commands and Install > Service / Remove > Service
menu entries.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BReZWvvLsDRUaqgjiRzvZ5

* Clear the agent's SSH_AUTH_SOCK when removing the SSH agent service

The socket's ExecStartPost exports SSH_AUTH_SOCK into the user manager with set-environment, which disabling the socket does not undo, so apps launched after removal still pointed at a stopped agent. The environment.d file also has to be deleted before disable reloads the manager, or the generator re-exports it. Only an SSH_AUTH_SOCK pointing at gcr is cleared, so another agent's stays.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Move SSH Agent setup to Setup > Security

Turning on an SSH agent is security configuration of the machine rather than installing software, so it sits with SSHD and the other Setup > Security entries. It hides once enabled, as Sudoless Docker does, and Remove > Service > SSH Agent turns it back off.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: David Heinemeier Hansson <david@hey.com>
2026-09-28 08:46:30 +02:00

18 lines
559 B
Bash
Executable File

#!/bin/bash
# omarchy:summary=Enable an SSH agent (gcr-ssh-agent) that prompts for key passphrases graphically.
set -e
ENV_FILE="$HOME/.config/environment.d/90-gcr-ssh-agent.conf"
systemctl --user enable --now gcr-ssh-agent.socket
mkdir -p "$(dirname "$ENV_FILE")"
echo 'SSH_AUTH_SOCK=$XDG_RUNTIME_DIR/gcr/ssh' >"$ENV_FILE"
echo ""
echo "SSH agent has been enabled. Log out and back in to make it available everywhere."
echo "The first use of a passphrase-protected key opens a dialog, with the option to"
echo "remember the passphrase in the keyring."