home · contact · privacy
Better passphrase management.
[config] / buster / setup_scripts / setup_home_eeepc.sh
index be52afbc2656d4a268d5cb77182941acbb2e0f5e..7678bf356b507f1d1c60901d773210446af502ad 100755 (executable)
@@ -2,13 +2,14 @@
 set -e
 
 public_repos_dir="${HOME}/public_repos"
-config_tree_prefix="${public_repos_dir}/config/buster"
-setup_scripts_dir="${config_tree_prefix}/setup_scripts"
+config_tree_prefix="${public_repos_dir}/config"
+path_borgscript="${config_tree_prefix}/all_new_2018/borg.sh"
+config_tree_buster="${config_tree_prefix}/buster"
+setup_scripts_dir="${config_tree_buster}/setup_scripts"
 repos_list_file="${public_repos_dir}/repos"
-secrets_dev="sdb"
-source_dir="/media/${secrets_dev}/to_usb"
-target_dir="${HOME}/tmp_to_usb"
+dir_secrets="${HOME}/tmp_secrets"
 borgkeys_dir=~/.config/borg/keys
+borgrepos_file=~/.borgrepos
 ssh_dir=~/.ssh
 
 ensure_repo() {
@@ -19,31 +20,49 @@ ensure_repo() {
     fi
 }
 
+# Clone config to copy dotfiles etc. from it.
 cd
 mkdir -p "${public_repos_dir}"
 ensure_repo config
 cd "${setup_scripts_dir}"
-./copy_dirtree.sh "${config_tree_prefix}/home_files" "${HOME}" minimal user_eeepc
-cat "${repos_list_file}" | while read line; do
-    ensure_repo "${line}"
-done
+./copy_dirtree.sh "${config_tree_buster}/home_files" "${HOME}" minimal user_eeepc
+
+# Set up native messenger for tridactyl.
 curl -fsSl https://raw.githubusercontent.com/tridactyl/tridactyl/78e662efefd1f4af2bdb2a53edecf03b535b997b/native/install.sh | bash
-while [ ! -e /dev/"${secrets_dev}" ]; do
-    echo "Put secrets drive into slot for /dev/${secrets_dev}, then hit Return."
-    read ignore
-done
-sudo pmount /dev/"${secrets_dev}"
-cp -a "${source_dir}" "${target_dir}"
-sudo pumount "${secrets_dev}"
-echo "You can remove /dev/${secrets_dev} now."
-cd "${target_dir}"
+
+# Set up non-public parts of infrastructure.
+cd "${dir_secrets}"
 mkdir -p "${ssh_dir}"
 echo "Setting up .ssh"
 cp id_rsa ~/.ssh
+stty -echo
 ssh-keygen -y -f ~/.ssh/id_rsa > ~/.ssh/id_rsa.pub
+stty echo
 tar xf borg_keyfiles.tar
 mkdir -p "${borgkeys_dir}"
 mv borg_keyfiles/* "${borgkeys_dir}"
 cd
-rm -rf "${target_dir}"
+rm -rf "${dir_secrets}"
+
+# Sync org dir via borgbackup. For this we need the borgbackup servers
+# in our .ssh/known_hosts file.
+cat "${borgrepos_file}" | while read line; do
+    first_char=$(echo "${line}" | cut -c1)
+    if [ "${first_char}" = "#" ]; then
+        continue
+    fi
+    ssh-keyscan "${line}" >> "${ssh_dir}"/known_hosts
+done
+BORG_PASSPHRASE="${SECRETS_PASS}" "${path_borgscript}" orgpull
+
+# Fill ~/public_repos.
+cat "${repos_list_file}" | while read line; do
+    first_char=$(echo "${line}" | cut -c1)
+    if [ "${first_char}" = "#" ]; then
+        continue
+    fi
+    ensure_repo "${line}"
+done
+
+# Final note on how to integrate tridactyl.
 echo "TODO: As tridactyl user, don't forget to do :source on the first Firefox run and then re-start."