Skip to content

Commit

Permalink
add additionalKeyFiles option to luks
Browse files Browse the repository at this point in the history
  • Loading branch information
arch authored and mergify[bot] committed Jul 14, 2023
1 parent 68eb09b commit 7eb0940
Show file tree
Hide file tree
Showing 4 changed files with 10 additions and 0 deletions.
1 change: 1 addition & 0 deletions example/complex.nix
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,7 @@
type = "luks";
name = "crypted1";
settings.keyFile = "/tmp/secret.key";
additionalKeyFiles = ["/tmp/additionalSecret.key"];
extraFormatArgs = [
"--iter-time 1" # unsecure but fast for tests
];
Expand Down
1 change: 1 addition & 0 deletions example/luks-lvm.nix
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@
# if you want to use the key for interactive login be sure there is no trailing newline
# for example use `echo -n "password" > /tmp/secret.key`
settings.keyFile = "/tmp/secret.key";
additionalKeyFiles = ["/tmp/additionalSecret.key"];
content = {
type = "lvm_pv";
vg = "pool";
Expand Down
7 changes: 7 additions & 0 deletions lib/types/luks.nix
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,12 @@ in
};
'';
};
additionalKeyFiles = lib.mkOption {
type = lib.types.listOf diskoLib.optionTypes.absolute-pathname;
default = [];
description = "Path to additional key files for encryption";
example = ["/tmp/disk2.key"];
};
initrdUnlock = lib.mkOption {
type = lib.types.bool;
default = true;
Expand Down Expand Up @@ -82,6 +88,7 @@ in
cryptsetup luksOpen ${config.device} ${config.name} \
${toString config.extraOpenArgs} \
${keyFileArgs}
${toString (lib.lists.forEach config.additionalKeyFiles (x: "cryptsetup luksAddKey ${config.device} ${x} ${keyFileArgs}"))}
${lib.optionalString (config.content != null) config.content._create}
'';
};
Expand Down
1 change: 1 addition & 0 deletions tests/lib.nix
Original file line number Diff line number Diff line change
Expand Up @@ -135,6 +135,7 @@
machine.start()
machine.succeed("echo -n 'secretsecret' > /tmp/secret.key")
machine.succeed("echo -n 'additionalSecret' > /tmp/additionalSecret.key")
${lib.optionalString (testMode == "direct") ''
machine.succeed("${tsp-create}")
machine.succeed("${tsp-mount}")
Expand Down

0 comments on commit 7eb0940

Please sign in to comment.