diff --git a/default-home.nix b/default-home.nix index 0a949af..3e0fa65 100644 --- a/default-home.nix +++ b/default-home.nix @@ -7,6 +7,9 @@ }: let system = pkgs.stdenv.hostPlatform.system; + pushoverEnvPath = + builtins.replaceStrings [ "\${XDG_RUNTIME_DIR}" ] [ "$XDG_RUNTIME_DIR" ] + config.age.secrets.pushover-env.path; in { imports = [ @@ -265,6 +268,10 @@ in xdg.configFile."fish/completions/zellij.fish".source = "${unstable.zellij}/share/fish/vendor_completions.d/zellij.fish"; + xdg.configFile."fish/env-files.fish".text = '' + set -a env_files ${pushoverEnvPath} + ''; + xdg.configFile.aerc = { source = ./aerc; recursive = true; @@ -300,6 +307,10 @@ in symlink = true; }; + age.secrets.pushover-env = { + file = ./secrets/pushover-env.age; + }; + manual.manpages.enable = true; home.stateVersion = "23.11"; diff --git a/fish/conf.d/env-files.fish b/fish/conf.d/env-files.fish new file mode 100644 index 0000000..63c7956 --- /dev/null +++ b/fish/conf.d/env-files.fish @@ -0,0 +1,21 @@ +if status is-interactive + set -l env_files + + if test -r $__fish_config_dir/env-files.fish + source $__fish_config_dir/env-files.fish + end + + for env_file in $env_files + test -r $env_file; or continue + + while read -l line + set -l assignment (string replace -r '^\s*export\s+' "" -- $line) + + string match -qr '^\s*(#|$)' -- $assignment; and continue + string match -qr '^[A-Za-z_][A-Za-z0-9_]*=' -- $assignment; or continue + + set -l pair (string split -m1 = -- $assignment) + set -gx $pair[1] $pair[2] + end < $env_file + end +end diff --git a/host-specific/aleister-noah.nix b/host-specific/aleister-noah.nix index 6cb5be7..8c58c8e 100644 --- a/host-specific/aleister-noah.nix +++ b/host-specific/aleister-noah.nix @@ -6,6 +6,11 @@ config, ... }: +let + pushoverEnvPath = + builtins.replaceStrings [ "\${XDG_RUNTIME_DIR}" ] [ "$XDG_RUNTIME_DIR" ] + config.age.secrets.pushover-env.path; +in { # Home Manager needs a bit of information about you and the paths it should # manage. @@ -348,6 +353,9 @@ "${pkgs.nix}/share/fish/vendor_completions.d/nix.fish"; xdg.configFile."fish/completions/zellij.fish".source = "${unstable.zellij}/share/fish/vendor_completions.d/zellij.fish"; + xdg.configFile."fish/env-files.fish".text = '' + set -a env_files ${pushoverEnvPath} + ''; xdg.configFile.aerc = { source = ../aerc; @@ -379,6 +387,10 @@ ''; }; + age.secrets.pushover-env = { + file = ../secrets/pushover-env.age; + }; + home.stateVersion = "24.11"; } diff --git a/scripts/pushover.rcsh b/scripts/pushover.rcsh new file mode 100755 index 0000000..d517ad6 --- /dev/null +++ b/scripts/pushover.rcsh @@ -0,0 +1,150 @@ +#!/usr/bin/env rc + +flag e + + +API=https://api.pushover.net/1/messages.json + +fn usage { + echo 'usage: pushover.rcsh [send] [-t title] [-p priority] [-s sound] [-d device] [-u url] [-U url_title] [--retry seconds] [--expire seconds] message...' >[1=2] + echo ' pushover.rcsh validate [-d device]' >[1=2] + echo ' pushover.rcsh receipt RECEIPT' >[1=2] + echo ' pushover.rcsh cancel-receipt RECEIPT' >[1=2] + echo >[1=2] + echo environment: >[1=2] + echo ' PUSHOVER_TOKEN application API token' >[1=2] + echo ' PUSHOVER_USER user or group key' >[1=2] + echo >[1=2] + echo examples: >[1=2] + echo ' pushover.rcsh -t "Traefik alert" "Traefik is not 3/3 ready"' >[1=2] + echo ' pushover.rcsh -p 1 -s siren "High-priority ingress alert"' >[1=2] + exit 1 +} + +fn post { + curl -sS $* +} + +if (~ $PUSHOVER_TOKEN ()) { + echo PUSHOVER_TOKEN is required >[1=2] + exit 1 +} +if (~ $PUSHOVER_USER ()) { + echo PUSHOVER_USER is required >[1=2] + exit 1 +} + +cmd=send +if (~ $1 send validate receipt cancel-receipt) { + cmd=$1 + shift +} + +switch($cmd) { +case validate + device=() + while(! ~ $1 ()) { + switch($1) { + case -d --device + shift + device=$1 + case -h --help + usage + case * + echo Unknown argument: $1 >[1=2] + exit 1 + } + shift + } + form=(--form-string token=^$PUSHOVER_TOKEN --form-string user=^$PUSHOVER_USER) + if (! ~ $device ()) { + form=($form --form-string device=^$device) + } + post $form https://api.pushover.net/1/users/validate.json + exit $status + +case receipt + if (! ~ $#* 1) { + usage + } + post --form-string token=^$PUSHOVER_TOKEN https://api.pushover.net/1/receipts/$1.json + exit $status + +case cancel-receipt + if (! ~ $#* 1) { + usage + } + post --form-string token=^$PUSHOVER_TOKEN https://api.pushover.net/1/receipts/$1/cancel.json + exit $status +} + +title='Infrastructure alert' +priority=1 +sound=() +device=() +url=() +url_title=() +retry=60 +expire=3600 + +while(! ~ $1 ()) { + switch($1) { + case -t --title + shift + title=$1 + case -p --priority + shift + priority=$1 + case -s --sound + shift + sound=$1 + case -d --device + shift + device=$1 + case -u --url + shift + url=$1 + case -U --url-title + shift + url_title=$1 + case --retry + shift + retry=$1 + case --expire + shift + expire=$1 + case -h --help + usage + case * + break + } + shift +} + +if (~ $#* 0) { + usage +} + +message=$"* +form=(--form-string token=^$PUSHOVER_TOKEN \ + --form-string user=^$PUSHOVER_USER \ + --form-string title=^$"title \ + --form-string message=^$"message \ + --form-string priority=^$priority) + +if (! ~ $sound ()) { + form=($form --form-string sound=^$sound) +} +if (! ~ $device ()) { + form=($form --form-string device=^$device) +} +if (! ~ $url ()) { + form=($form --form-string url=^$url) +} +if (! ~ $url_title ()) { + form=($form --form-string url_title=^$"url_title) +} +if (~ $priority 2) { + form=($form --form-string retry=^$retry --form-string expire=^$expire) +} + +post $form $API diff --git a/secrets/pushover-env.age b/secrets/pushover-env.age new file mode 100644 index 0000000..eb20bb2 --- /dev/null +++ b/secrets/pushover-env.age @@ -0,0 +1,18 @@ +age-encryption.org/v1 +-> ssh-ed25519 e6zq8g R5DhGeKDKHjSB1gCl/dFtMAItWuOchDMlRdCtrbKN0w +I4gSv78fU6EzS9UjjjtBMt40Qa/+QRy7unpTT9g8XhI +-> ssh-ed25519 OV+2QQ XbtDeGp7nlTBE3MQrfdYGih545G9FmyN/k0UBDIYcTQ +Q8MKlGCFQoz68QD+0iAVDaw6VGX9ntpkg+qDadRsfI4 +-> ssh-ed25519 h/Fm0A c5yngZjtPjrbeD6jE1V+r3xOBUAMflXyEqO630053lk +N10OOjivEUptdor3EfHINlldG7PJ8/Rj9zNtnotfh0E +-> ssh-ed25519 Aoo1Gg zNZw7VZvvRfcu9gRqYwfXVOJ9QSAj15tXKxc4k07zmM +rq2pixpc7a0MzpVEfKgBunUYEzwFAx7UyXxGQLJlPMs +-> ssh-ed25519 QBbeMw E+f8eRpYqlgWvODmjeAZJFuVq0HXvXPqJmNtjRtyuCY +ws0iffN7OYeEzsBA3k/J+s3gyaHJt+9YgkdWnWVsn3Y +-> ssh-ed25519 Wv0Urw Fbir6DFcXrtgD7v+c7D54yuGp6RLspFBOUbwhU15nD8 +07ptDr97yn8NH2QssZmpIw/nGVg0Jt5Vaib4/fAzaiY +-> ssh-ed25519 WVNCXA wnAjIIMzt0yz3gkNtowh286Z3U86gW8uMfZzm4U7xlA +TME1Z4gOiuVDAddR1YDxDQ4Xe/OQ7s3HKwTLmQh1f5A +--- J3RkpyynVhSfuG+GzIs4Qz8wzvnYn2WAiUHra2lJF7M +YH|�xf�6�b;P6U�r���\}И�W���_g�d�XQʡ q�z�y��Es��x`*��Y�%��<�x�{+U/�� +��F5"����� J*� -��N��NLQ g1����$L^�r7` \ No newline at end of file diff --git a/secrets/secrets.nix b/secrets/secrets.nix index 261d8ad..58a2655 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -39,4 +39,5 @@ in "influxdb-user-password.age".publicKeys = [ misaki ] ++ noah; "influxdb-admin-password.age".publicKeys = [ misaki ] ++ noah; "influxdb-admin-token.age".publicKeys = [ misaki ] ++ noah; + "pushover-env.age".publicKeys = hosts ++ noah; }