From d129e0950bdaf55c7d752933e77790e9d5b151a3 Mon Sep 17 00:00:00 2001 From: Dmitry Ilvokhin Date: Sat, 1 Jun 2024 19:15:26 +0100 Subject: Remove .sh extention from bin tools --- ansible.cfg | 2 +- bin/decrypt-vault-password | 3 +++ bin/decrypt-vault-password.sh | 3 --- bin/rotate-vault-password | 15 +++++++++++++++ bin/rotate-vault-password.sh | 15 --------------- 5 files changed, 19 insertions(+), 19 deletions(-) create mode 100755 bin/decrypt-vault-password delete mode 100755 bin/decrypt-vault-password.sh create mode 100755 bin/rotate-vault-password delete mode 100755 bin/rotate-vault-password.sh diff --git a/ansible.cfg b/ansible.cfg index 6141e48..d268572 100644 --- a/ansible.cfg +++ b/ansible.cfg @@ -2,7 +2,7 @@ inventory = hosts.yml roles_path = roles remote_user = root -vault_password_file = bin/decrypt-vault-password.sh +vault_password_file = bin/decrypt-vault-password # Don't want to see warning about Python. On everything I run, proper Python 3 # should be discoverable. interpreter_python = auto_silent diff --git a/bin/decrypt-vault-password b/bin/decrypt-vault-password new file mode 100755 index 0000000..e82de62 --- /dev/null +++ b/bin/decrypt-vault-password @@ -0,0 +1,3 @@ +#! /usr/bin/env sh + +gpg --decrypt --batch --quiet --use-agent misc/vault-password.asc diff --git a/bin/decrypt-vault-password.sh b/bin/decrypt-vault-password.sh deleted file mode 100755 index e82de62..0000000 --- a/bin/decrypt-vault-password.sh +++ /dev/null @@ -1,3 +0,0 @@ -#! /usr/bin/env sh - -gpg --decrypt --batch --quiet --use-agent misc/vault-password.asc diff --git a/bin/rotate-vault-password b/bin/rotate-vault-password new file mode 100755 index 0000000..1762786 --- /dev/null +++ b/bin/rotate-vault-password @@ -0,0 +1,15 @@ +#! /usr/bin/env sh + +head -c 128 /dev/urandom | base64 > password.txt + +ansible-vault rekey + --new-vault-password-file password.txt \ + `git grep -l 'ANSIBLE_VAULT;1.1;AES256$'` + +gpg \ + -r d@ilvokhin.com \ + --armor \ + --output misc/vault-password.asc \ + --encrypt password.txt + +ansible-vault view misc/vaults/example.yml && rm password.txt diff --git a/bin/rotate-vault-password.sh b/bin/rotate-vault-password.sh deleted file mode 100755 index 1762786..0000000 --- a/bin/rotate-vault-password.sh +++ /dev/null @@ -1,15 +0,0 @@ -#! /usr/bin/env sh - -head -c 128 /dev/urandom | base64 > password.txt - -ansible-vault rekey - --new-vault-password-file password.txt \ - `git grep -l 'ANSIBLE_VAULT;1.1;AES256$'` - -gpg \ - -r d@ilvokhin.com \ - --armor \ - --output misc/vault-password.asc \ - --encrypt password.txt - -ansible-vault view misc/vaults/example.yml && rm password.txt -- cgit v1.2.3-70-g09d2