From cf24662a9d8cfc8542f356425d29b687f3a2bfc0 Mon Sep 17 00:00:00 2001 From: AmrikSD Date: Mon, 5 Oct 2026 19:06:40 +0100 Subject: [PATCH] feat(onboard): use the existing SSH key instead of generating one per machine --- projects/onboard/README.md | 6 +++--- projects/onboard/cmd/onboard/main.go | 6 +++--- projects/onboard/internal/machine/machine.go | 7 +++++-- 3 files changed, 11 insertions(+), 8 deletions(-) diff --git a/projects/onboard/README.md b/projects/onboard/README.md index b3196c7e..6b30a206 100644 --- a/projects/onboard/README.md +++ b/projects/onboard/README.md @@ -11,15 +11,15 @@ git clone https://github.com/AmrikSD/code ~/code/AmrikSD/code `setup.sh` installs Nix if it is missing, then builds and starts the onboarding flow: -1. GitHub: signs in with `gh` if needed. Pick SSH and let it upload a key. -2. Tools and config: clones the dotfiles repo into `~/.dotfiles`, or updates it, and runs its `bootstrap.sh`. That installs every tool and app, links the config, adds the Claude Code hooks and imports the GPG signing key. Tick "Work setup" on a work machine to fetch the work-only config too. +1. GitHub: signs in with `gh` in the browser if needed. No SSH key is created. +2. Tools and config: clones the dotfiles repo into `~/.dotfiles`, or updates it, and runs its `bootstrap.sh`. That installs every tool and app, links the config (including SSH through the 1Password agent), adds the Claude Code hooks and imports the GPG signing key. Tick "Work setup" on a work machine to fetch the work-only config too. 3. Repositories: lists your account and organisations with a tick box each. Ticking an owner ticks every repo under it, opening one lets you pick repos individually. Whatever is ticked is cloned into `~/code//`. Then open a new terminal. On a network that intercepts TLS and sets `SSL_CERT_FILE`, as some company laptops do, `setup.sh` first builds a certificate store from that file and points Bazel at it in `~/.bazelrc`. Bazel cannot download anything there otherwise. -Before you start, on a Mac: install the 1Password app, sign in, and turn on "Integrate with 1Password CLI" in its Developer settings. The GPG key and the work secrets are read from it. Without it the setup still finishes, and re-running it later picks them up. +Before you start: install the 1Password app, sign in, and in its Developer settings turn on "Use the SSH agent" and "Integrate with 1Password CLI". Your SSH key, GPG key and the work secrets all come from it, so every machine uses the same keys. Without the SSH agent the repositories step cannot clone anything. ## Enjoy diff --git a/projects/onboard/cmd/onboard/main.go b/projects/onboard/cmd/onboard/main.go index 13e92c14..86dc815f 100644 --- a/projects/onboard/cmd/onboard/main.go +++ b/projects/onboard/cmd/onboard/main.go @@ -60,13 +60,13 @@ func run() int { } // signedIn makes sure gh is signed in, walking through gh's own login when it -// is not. SSH is asked for because repos are cloned over SSH, and gh offers to -// create and upload a key for a machine that has none. +// is not. Repos are cloned over SSH with the key the dotfiles set up, so gh is +// told not to generate one for this machine. func signedIn() bool { if _, err := github.GH("auth", "status"); err == nil { return true } - login := exec.Command("gh", "auth", "login", "--git-protocol", "ssh", "--web") + login := exec.Command("gh", "auth", "login", "--git-protocol", "ssh", "--skip-ssh-key", "--web") login.Stdin, login.Stdout, login.Stderr = os.Stdin, os.Stdout, os.Stderr if err := login.Run(); err != nil { fmt.Fprintln(os.Stderr, "Could not sign in to GitHub:", err) diff --git a/projects/onboard/internal/machine/machine.go b/projects/onboard/internal/machine/machine.go index c0cdfe86..0a19008a 100644 --- a/projects/onboard/internal/machine/machine.go +++ b/projects/onboard/internal/machine/machine.go @@ -8,14 +8,17 @@ import ( "path/filepath" ) +// The first clone goes over HTTPS with gh's sign-in, because SSH is only set up +// by the dotfiles themselves. const script = `set -euo pipefail repo=$1 dir=$2 work=$3 +https=(-c credential.helper= -c 'credential.helper=!gh auth git-credential' -c url.https://github.com/.insteadOf=git@github.com:) if [ -d "$dir/.git" ]; then git -C "$dir" pull --ff-only || echo "Could not update $dir, carrying on with what is there." else - gh repo clone "$repo" "$dir" + git "${https[@]}" clone "https://github.com/$repo" "$dir" fi -if [ "$work" = work ]; then git -C "$dir" submodule update --init; fi +if [ "$work" = work ]; then git "${https[@]}" -C "$dir" submodule update --init; fi "$dir/bootstrap.sh" printf '\nPress enter to continue. ' read -r _