diff --git a/README.md b/README.md index 50b1bdb..859ef3a 100644 --- a/README.md +++ b/README.md @@ -36,7 +36,10 @@ Create a `config.yaml` file with the following contents: ```yaml interval: "10m" -ageKeyPath: "keys/key.txt" +age: + identity: "keys/key.txt" + recipients: # optional, when used to encrypt secrets + - "age1xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" statePath: ".nox-state.json" defaultRepo: git@github.com:ShorkBytes/nox-secrets.git @@ -54,6 +57,14 @@ apps: nox --help ``` +### How to + +#### Decrypt secret into custom file + +```bash +nox decrypt --app debug --dry-run > secrets.env +``` + ### Contributing Contributions are welcome! diff --git a/cmd/nox/main.go b/cmd/nox/main.go index dda29fd..fd5adc1 100644 --- a/cmd/nox/main.go +++ b/cmd/nox/main.go @@ -17,7 +17,7 @@ func main() { var configPath string var statePath string var identityPaths []string - var appName string + var dryRun bool var force bool var verbose bool @@ -100,21 +100,20 @@ func main() { }, }, { - Name: "export", - Aliases: []string{"e"}, - Usage: "Export all secrets to a single file", + Name: "decrypt", + Aliases: []string{"d"}, + Usage: "Decrypts all secrets of one or all apps", Flags: []cli.Flag{ &cli.StringFlag{ - Name: "app", - Aliases: []string{"a"}, - Usage: "app to export secrets for", - Destination: &appName, + Name: "app", + Aliases: []string{"a"}, + Usage: "app to decrypt secrets for", }, &cli.BoolFlag{ Name: "dry-run", Aliases: []string{"d"}, Value: false, - Usage: "only print what would be exported", + Usage: "only print what would be decrypted", Destination: &dryRun, }, &cli.BoolFlag{ @@ -132,13 +131,13 @@ func main() { IdentityPaths: identityPaths, DryRun: dryRun, Force: force, - AppName: appName, + AppName: cmd.String("app"), Verbose: verbose, }) if err != nil { log.Fatalf("failed to build runtime context: %v", err) } - if appName != "" { + if cmd.String("app") != "" { return processor.SyncApp(rtx) } return processor.SyncApps(rtx) diff --git a/internal/gitrepo/utils.go b/internal/gitrepo/utils.go index a244a33..c85f739 100644 --- a/internal/gitrepo/utils.go +++ b/internal/gitrepo/utils.go @@ -7,4 +7,4 @@ import ( func FileExistsInTree(tree *object.Tree, path string) bool { _, err := tree.File(path) return err == nil -} \ No newline at end of file +} diff --git a/internal/processor/gitsync.go b/internal/processor/gitsync.go index ac7050f..ba13137 100644 --- a/internal/processor/gitsync.go +++ b/internal/processor/gitsync.go @@ -2,6 +2,7 @@ package processor import ( "fmt" + "os" "github.com/aottr/nox/internal/cache" "github.com/aottr/nox/internal/config" @@ -45,7 +46,7 @@ func SyncApp(ctx *config.RuntimeContext) error { cacheKey := state.GenerateKey(*appName, file.Path) // skip if file is up to date and force is not set - if !ctx.Force { + if !ctx.Force && !ctx.DryRun { if prevHash, ok := st.Data[cacheKey]; ok && prevHash == hash { ctx.Logger.Printf("file %s is up to date", file.Path) continue @@ -62,7 +63,7 @@ func SyncApp(ctx *config.RuntimeContext) error { // skip writing file if dry run is set if ctx.DryRun { ctx.Logger.Printf("❌ dry run, not writing file %s", file.Output) - fmt.Println(string(plaintext)) + os.Stdout.Write(plaintext) continue } WriteToFile(plaintext, file, &FileProcessorOptions{CreateDir: true}) diff --git a/internal/state/utils.go b/internal/state/utils.go index 265d323..49351a6 100644 --- a/internal/state/utils.go +++ b/internal/state/utils.go @@ -1,9 +1,9 @@ package state import ( - "fmt" "crypto/sha256" "encoding/hex" + "fmt" ) // HashContent returns the SHA256 hash of the given data. @@ -14,4 +14,4 @@ func HashContent(data []byte) string { func GenerateKey(appName, file string) string { return fmt.Sprintf("%s:%s", appName, file) -} \ No newline at end of file +}