diff --git a/home/apps/espanso.nix b/home/apps/espanso.nix new file mode 100644 index 0000000..f14f6e0 --- /dev/null +++ b/home/apps/espanso.nix @@ -0,0 +1,100 @@ +{ + config, + lib, + pkgs, + ... +}: let + # ═══════════════════════════════════════════════════════════ + # PRIVATE MATCHES + # Add a key name here to expose it as an espanso trigger ":name". + # All keys are pulled from `sopsFile` below + # ═══════════════════════════════════════════════════════════ + sopsFile = ../../secrets/user.yaml; + privateMatchKeys = [ + "name" + "rname" + "fname" + "mail" + "gmail" + "bmail" + "tel" + "website" + "esky" + ]; + + secretName = key: "espanso-${key}"; +in { + options.modules.apps.espanso.enable = lib.mkOption { + default = config.modules.apps.enable; + description = "espanso text expander, with sops-managed private matches"; + type = lib.types.bool; + }; + + config = lib.mkIf config.modules.apps.espanso.enable { + services.espanso = { + enable = false; + package = pkgs.espanso-wayland; + configs.default = { + keyboard_layout.layout = "de"; + show_notifications = false; + }; + matches.default.matches = [ + { + replace = "{{mydate}}"; + trigger = ":today"; + vars = [ + { + name = "mydate"; + params.format = "%Y-%m-%d"; + type = "date"; + } + ]; + } + { + replace = "{{myweekday}}"; + trigger = ":day"; + vars = [ + { + name = "myweekday"; + params.format = "%A"; + type = "date"; + } + ]; + } + { + replace = "{{mytomorrow}}"; + trigger = ":tomorrow"; + vars = [ + { + name = "mytomorrow"; + params = { + format = "%Y-%m-%d"; + offset = 86400; + }; + type = "date"; + } + ]; + } + ]; + waylandSupport = true; + }; + sops = { + secrets = lib.listToAttrs (map (key: { + name = secretName key; + value = {inherit sopsFile key;}; + }) + privateMatchKeys); + templates."espanso-secrets.yml" = { + content = '' + matches: + ${lib.concatStrings (map (key: '' + - trigger: ":${key}" + replace: "${config.sops.placeholder.${secretName key}}" + '') + privateMatchKeys)} + ''; + path = "${config.home.homeDirectory}/.config/espanso/match/secrets.yml"; + }; + }; + }; +} diff --git a/modules/user.nix b/modules/user.nix index 9740a87..ad8ea60 100644 --- a/modules/user.nix +++ b/modules/user.nix @@ -49,6 +49,7 @@ description = "Main User Account"; extraGroups = [ "wheel" + "input" "networkmanager" "video" "audio" diff --git a/secrets/user.yaml b/secrets/user.yaml index 37c2458..353b070 100644 --- a/secrets/user.yaml +++ b/secrets/user.yaml @@ -6,6 +6,7 @@ gmail: ENC[AES256_GCM,data:orCnKCKupKg8JFj96N4Mw4sKnEQUbfRbvA==,iv:DcEuaKbmxEG3T bmail: ENC[AES256_GCM,data:qZY+oEYeZQC8L0pnseeApX8BW4ld+juW/LhQxdQM,iv:hz46N5uhFN92ataFM41art0fTh7XUPT7dN1RelZsuA4=,tag:E8ymyAWLQmMBW5YIiK34Qw==,type:str] tel: ENC[AES256_GCM,data:t6BIwawrcjHzytWNf+k=,iv:m3SRGBsZtgPBerLXolvjUoMOY7HszWsHokF8XPgH/OA=,tag:HY61SyipZMHpKVuXLAVcVg==,type:str] website: ENC[AES256_GCM,data:ROtaG5KP3TXdH7koN+BO6qJ7dHoBx57rci88tve+,iv:YbxpJQ23hf+yGw617JGvKVtlAaPGJsmn5qS46CrkZrk=,tag:U3R0wiiCXDXT4+Ax0CJY+g==,type:str] +esky: ENC[AES256_GCM,data:hZKutbBenyEIhsi3ZYKexGclqnEaJ0jHWN5xt82Psg==,iv:1D4loBnIZkNMuuEShzvXVtW3cwsVN0mXsQInD8WlgTE=,tag:8Vi9OslouOQ7z+xCGicSTQ==,type:str] sops: age: - enc: | @@ -26,7 +27,7 @@ sops: tyuuT+IZhjbiCbWeo+ql+jC/GZ9Jft0vBmDo+OIq/76DhH4SRYMHvg== -----END AGE ENCRYPTED FILE----- recipient: age1jc94u0ee9s8h605p82wr4e6hu53ph4y8um2uehmstfx7waup85ss2y30d5 - lastmodified: "2026-07-14T23:17:09Z" - mac: ENC[AES256_GCM,data:GMhK1UEw7gKdaOt7oW0F2e/bG6K92qhcOIsj/cni7c8BatCNpI3eoACzVitedEULfJJE21BbcLNQxwDDFYCAL3qTOaokftrvQZwAHOe36n2+NfVpa2VIRznnDRM15WQK+hVIFKf/cHcJuB5+Vddj/Q6+F08BGPE8WNNZ2nW69fw=,iv:vyNwFlM1W+udN+7DzQJkYb0hK4eNU36FBcNUo3xB9Vs=,tag:ht3GukNp9qtlfCLBz3QriA==,type:str] + lastmodified: "2026-07-26T17:00:23Z" + mac: ENC[AES256_GCM,data:n4kpTN84ZSCYZtlM5lQVwREkl9S9Fn1nTUbPXIDRik6pM09d8P1HeWl10HU8P8NFgvxg7ux+tZbvdrCpiUrCQX1G1KY1099tCBzcelnnPDW+E45egwAAHJ7fZ7Lg4ZK63HbG/iL1QczbdzrK4l8Pj3jQIK+L5FuyXN7tpQZb0rI=,iv:I+KUfIzkmtqcvU/8Z/XEGcXwdSrlBdkfz38vxE5j6sw=,tag:RNqnLq7FGD0GMLS0O2mhpg==,type:str] unencrypted_suffix: _unencrypted - version: 3.13.1 + version: 3.13.2