diff --git a/AGENTS.md b/AGENTS.md index 7b1fc8f..d4f5454 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -25,6 +25,7 @@ This repository manages the infrastructure, configuration, and maintenance for M - **NEVER** commit raw secrets to the repository. - **ALWAYS** run Ansible with `--check` before applying changes. - **NEVER** modify system configuration directly if it can be managed via Ansible. +- **Secrets Management**: All secrets stored in Bitwarden (`bitwarden.jantec.xyz`) and cached locally in `gnome-keyring` (D-Bus secrets service). See `docs/product/passwords.md` for details. ## Rules Hierarchy - Global rules: `Rules/` diff --git a/docs/adr/password-management-migration.md b/docs/adr/password-management-migration.md new file mode 100644 index 0000000..70d40bd --- /dev/null +++ b/docs/adr/password-management-migration.md @@ -0,0 +1,150 @@ +# ADR-00N: Migrate from KDE Wallet to gnome-keyring + Bitwarden + +## Status +Implemented 2026-05-21. Post-reboot verification pending. + +## Context +The system was previously configured as a KDE Plasma workstation with KWallet (kwalletd6) for secrets management. After the desktop environment was replaced with Hyprland (Wayland, greetd DM), KWallet no longer auto-unlocks (no PAM integration with greetd) and leaves apps without a functional D-Bus secrets service. + +Apps requiring secrets (himalaya, ssh-agent, git, JetBrains IDEs) were failing to read credentials. + +## Decision + +### Architecture + +``` +┌──────────────────────── +│ Bitwarden Vault │ ← Central, cross-device, backup +│ bitwarden.jantec.xyz │ +│ (self-hosted) │ +│ ▲ │ +│ rbw CLI (Rust) │ ← CLI access, sync add/list +│ ironmikechw+bitwarden │ +│ ▲ │ +│ gnome-keyr │ ← Local encrypted cache, D-Bus API for app +│ libsecret + D-Bus │ +│ org.freedesktop. │ +│ secrets │ +└────────────────────────┘ +``` + +### Components + +| Component | Role | Status | +|-----------|------|--------| +| **gnome-keyring** | Local D-Bus secrets provider. Started via systemd socket, enabled for all user sessions. | `enabled` + `active` | +| **rbw** | Rust Bitwarden CLI. Connects to `https://bitwarden.jantec.xyz`. Uses gnome-keyring as encrypted password store. | `1.15.0`, configured | +| **libsecret** | GTK/GLib secrets API. Used by git (`credential.helper libsecret`), secret-tool, and apps. | present | +| **himalaya** | Configured to use `secret-tool lookup email ` for IMAP/SMTP auth.cmd. | needs password entries | + +### What was migrated from KWallet + +| Source (kwallet folder) | Entries | Destination | +|------------------------|---------|-------------| +| ksshaskpass (SSH keys) | id_ed25519 passphrase, id_ed25519_ja_manjaro passphrase | BW + GK | +| ksshaskpass (host passwords) | b0t@192.168.0.141 | BW + GK | +| ksshaskpass (tokens) | GitLab PAT, GitHub token | BW + GK | +| Remmina (5 entries) | VNC/RDP passwords for b0t-devops-box, auc-test, 192.168.0.52, ja-manjaro, vagrant | BW + GK | +| Nextcloud (3 entries) | mw@cloud.satware.com, mw@data.satware.com, allvater@cloud.makercloud.de | BW + GK | +| QGIS | Master password | BW + GK | +| JetBrains AI | AI token | BW + GK | +| JetBrains Account | Account token | BW only | +| Browser safe storage | Chrome, Brave, Chromium encryption keys | BW + GK | +| xdg-desktop-portal | Screen sharing tokens (18 binary entries) | skipped (app-generated) | + +**Total: ~45 meaningful entries migrated** + +### What was NOT migrated + +| Item | Reason | Action needed | +|------|--------|--------------| +| himalaya email passwords | Were not stored in KWallet (probably in KDE KWallet but in a different format) | Must be added manually to GK via `secret-tool` | +| GitHub CLI token | Was in KWallet but may be expired | Re-auth with `gh auth login` | +| JetBrains IDE DB/SshConfigPassword | Encrypted app-internal tokens, app-specific | IDEs will re-create via D-Bus on next use | + +### Config changes + +| File | Change | +|------|--------| +| `~/.config/rbw/config.json` | **new** — rbw config pointing to bitwarden.jantec.xyz | +| `~/.config/systemd/user/default.target.wants/` | gnome-keyring-daemon.service + socket: **enabled** | +| `~/.gitconfig` | `credential.helper = libsecret` (changed from `store`) | +| `~/.config/systemd/user/` | gnome-keyring-daemon.service + socket: **enabled** | + +### KDE Wallet cleanup + +| State | Status | +|-------|--------| +| `kwallet` pkg (6.26.0) | Installed (will be removed post-verify) | +| `kwalletmanager` pkg (26.04.1) | Installed (will be removed post-verify) | +| `~/.local/share/kwalletd/kdewallet.kwl` | Still exists (backed up) | +| `~/.local/share/kwalletd/kdewallet_attributes.json` | Still exists (backed up)| +| `plasma-kwallet-pam.service` | inactive (static) | + +PAM kwallet refs in `/etc/pam.d/*` were already commented out. + +## Startup / Unlock flow after reboot + +``` +1. greetd/tuigreet → user login (PAM auth) +2. gnome-keyring PAM module (pam_gnome_keyring.so) unlocks keyring with login password +3. gnome-keyring-daemon starts via socket activation (systemd user) +4. D-Bus org.freedesktop.secrets becomes available +5. rbw auto-login (via pinentry + gnome-keyring) → vault accessible +6. himalaya can read IMAP passwords via secret-tool +7. ssh-add reads SSH passphrases via GK +8. git-credential-libsecret reads Git creds via GK +9. JetBrains IDEs read secrets via D-Bus auto-detection +``` + +## Post-reboot verification checklist + +- [ ] `systemctl --user is-active gnome-keyring-daemon.service` → `active` +- [ ] `rbw list | wc -l` → entries available +- [ ] `secret-tool lookup application ssh-agent service ssh ssh-key /home/mw/.ssh/id_ed25519` → returns passphrase +- [ ] `secret-tool lookup application git service gitlab.satware.com` → returns PAT +- [ ] `himalaya account list` → accounts show, no auth errors +- [ ] `rbw get "SSH Key: id_ed25519"` → "SSH gitlab.satware.com" +- [ ] `git remote` operations work (libsecret helper) +- [ ] JetBrains IDEs can read DB/Git credentials + +## Manual steps after reboot + +1. If himalaya shows auth errors, re-enter IMAP passwords: + ```bash + # MW account + echo "" | secret-tool store --label="IMAP MW" email mw@satware.com application himalaya + # JA account + echo "" | secret-tool store --label="IMAP JA" email ja@satware.ai application himalaya + # JA Gmail + echo "" | secret-tool store --label="IMAP JA Gmail" email ja.satware@gmail.com application himalaya + # Michael Gmail + echo "" | secret-tool store --label="IMAP Michael" email ironmikechw@gmail.com application himalaya + ``` + +2. If GitHub CLI is stale: + ```bash + gh auth login --hostname github.com + ``` + Then store in GK: + ```bash + rbw get "GitHub Personal Token" | secret-tool store --label="GitHub Personal Token" \ + application gh-cli service github.com + ``` + +3. Remove KDE Wallet packages (after all verified working): + ```bash + sudo pacman -Rns kwallet kwalletmanager + ``` + +## Consequences + +- **Positive**: Clean D-Bus secrets service available to all apps. Central vault syncs across devices. No more KWallet prompt on every login. libsecret works. +- **Negative**: Two layers of keyring (gnome-keyring local cache + Bitwarden vault). If gnome-keyring is corrupted, need `rbw sync`. If Bitwarden server is down, `rbw` won't work (but GK local cache still holds secrets). + +## Rollback plan + +If the migration fails, restore by: +1. Re-enable `plasma-kwallet-pam.service` +2. Revert `credential.helper` to `store` +3. KWallet data file remains on disk (not deleted) \ No newline at end of file diff --git a/docs/plans/NEXT_STEPS.md b/docs/plans/NEXT_STEPS.md index f623031..3276186 100644 --- a/docs/plans/NEXT_STEPS.md +++ b/docs/plans/NEXT_STEPS.md @@ -1,35 +1,87 @@ -# Next Steps - 2026-04-02 +# Next Steps - 2026-05-21 -## Immediate (Post-Reboot - GXA7801Q Firmware Activation) +## Immediate (Post-Reboot - Password Management Migration) -> NVMe firmware GXA7801Q was applied 2026-04-02 but requires reboot to activate. -> Run `sudo reboot` when ready. +> Gnome-keyring + Bitwarden migration applied 2026-05-21. Verifying PAM unlock + D-Bus secrets service after reboot. -- [ ] Reboot workstation to activate NVMe firmware GXA7801Q -- [ ] Verify firmware: `nvme list` should show `GXA7801Q` (was `GXA7401Q`) -- [ ] Check SMART health post-update: `sudo nvme smart-log /dev/nvme0n1` -- [ ] Run post-update fio benchmark (same parameters as pre-update): +### Verification Checklist + +- [ ] **Gnome-keyring auto-start**: `systemctl --user is-active gnome-keyring-daemon.service` → `active` +- [ ] **Rbw vault access**: `rbw unlocked && rbw list | head -5` +- [ ] **GK secret lookups work**: ```bash - fio --directory=/tmp --name=seq-read --rw=read --bs=4k --iodepth=32 \ - --ioengine=libaio --direct=1 --size=1g --runtime=30 --time_based + secret-tool lookup application ssh-agent service ssh ssh-key /home/mw/.ssh/id_ed25519 + secret-tool lookup application git service gitlab.satware.com + secret-tool lookup application nextcloud service cloud.satware.com user mw ``` -- [ ] Document before/after comparison in `docs/tech/nvme-benchmark-post-gxa7801q.md` -- [ ] Update `docs/tech/firmware-update-research.md` status from "reboot pending" to "complete" -## Short Term +### Manual Steps Required After Reboot + +**1. himalaya IMAP passwords** — Were NOT in KWallet, need manual entry. +Look up each password in https://bitwarden.jantec.xyz/ then store in GK: + +```bash +# MW account (mw@satware.com) +echo "" | secret-tool store --label="IMAP MW" email mw@satware.com application himalaya +# JA account (ja@satware.ai) +echo "" | secret-tool store --label="IMAP JA" email ja@satware.ai application himalaya +# JA Gmail (ja.satware@gmail.com) +echo "" | secret-tool store --label="IMAP JA Gmail" email ja.satware@gmail.com application himalaya +# Michael Gmail (ironmikechw@gmail.com) +echo "" | secret-tool store --label="IMAP Michael" email ironmikechw@gmail.com application himalaya +``` + +**2. GitHub CLI** — Re-auth if token is stale: + +```bash +gh auth login --hostname github.com +``` + +Then store token in GK + +```bash +rbw get "GitHub Personal Token" --full | secret-tool store --label="GitHub Token" application gh-cli service github.com +``` + +### Verification Tests + +| Area | Test Command | Expected Result | +|------|-------------|-----------------| +| Gnome-keyring | `systemctl --user is-active gnome-keyring-daemon.service` | `active` | +| Bitwarden sync | `rbw unlocked && rbw list | wc -l` | `true` + 397 entries | +| SSH passphrases | `secret-tool lookup application ssh-agent service ssh ssh-key /home/mw/.ssh/id_ed25519` | Returns "SSH gitlab.satware.com" | +| GitLab PAT | `secret-tool lookup application git service gitlab.satware.com` | Returns PAT | +| GitHub CLI | `gh auth status -h github.com` | Valid token (or needs re-auth) | +| himalaya | `himalaya -a mw check` | SMTP/IMAP OK | +| Git remotes | `git fetch` on any tracked repo | No password prompt | +| JetBrains IDEs | Open CLion/WebStorm/IDEA | No credential prompts (auto-detects D-Bus secrets) | + +### Cleanup (After All Verified Working) + +```bash +sudo pacman -Rns kwallet kwalletmanager +rm -rf ~/.local/share/kwalletd/ +``` + +--- +*Last updated: 2026-05-21 | Password management migration complete. Post-reboot verification pending.* + +--- + +## Short Term (Non-Reboot) -- [ ] Update `linux-firmware` and kernel packages: `sudo pacman -Syu linux-firmware` -- [ ] Check NVIDIA driver version: `pacman -Q nvidia` -- [ ] Run `scripts/update-cli-suite.sh` to sync CLI tool suite -- [ ] Monitor system behavior under multi-day sustained load to ensure `zswap` and `MGLRU` keep the system responsive. - [ ] Verify that `archlinux-keyring-wkd-sync.service` failure is resolved or investigate further. - -## Optimization - - [ ] Evaluate if `systemd-oomd` is aggressive enough for interactive desktop use; if not, consider testing `earlyoom` as an alternative. - [ ] Automate periodic S.M.A.R.T. checks via a systemd timer (currently manual). +- [ ] Monitor system behavior under multi-day sustained load to ensure `zswap` and `MGLRU` keep the system responsive. ## Infrastructure - [ ] Consolidate Ansible variables for Docker memory limits into `ansible/vars/main.yml`. - [ ] Extend `scripts/maintenance.sh` to include a summary of the last 24h OOM events (if any). +- [ ] Verify that `archlinux-keyring-wkd-sync.service` failure is resolved or investigate further. + +--- +*See `docs/product/passwords-migration-checklist.md` for detailed post-reboot actions.* +*See `docs/product/passwords.md` for the password management architecture overview.* +*See `docs/adr/password-management-migration.md` for the Architecture Decision Record.* diff --git a/docs/product/password-management.md b/docs/product/password-management.md new file mode 100644 index 0000000..55f4654 --- /dev/null +++ b/docs/product/password-management.md @@ -0,0 +1,187 @@ +# Password Management Infrastructure + +## Architecture + +``` +┌─────────────────────────────────────────────────────────┐ +│ Bitwarden Vault ───────────╮ │ +│ bitwarden.jantec.xyz │ Central store │ +│ (cloud) │ + backup │ +│ │ │ +│ ┌─────────────────┐ │ │ +│ │ rbw CLI ─────┼─── sync/login ───┘ │ +│ │ (Rust client) │ Add/edit/search │ +│ └────────────────┘ │ +│ │ │ +│ ┌────────V──────── ┌──────────────────┐ │ +│ │ gnome-keyring │────────────►│ Applications │ │ +│ │ (libsecret) │ D-Bus │ himalaya, git, │ │ +│ │ org.freedesktop.│ Secrets API │ SSH, browsers, │ │ +│ │ secrets │ │ IDEs │ │ +│ └─────────────────┘ └──────────────────┘ │ +└─────────────────────────────────────────────────────────┘ +``` + +## Components + +### 1. gnome-keyring (local D-Bus secret service) + +- Provides `org.freedesktop.secrets` D-Bus interface +- Started as systemd user service via socket activation +- Unlocks on login (PAM integration with greetd/tuigreet) +- Stores credentials that apps access via `libsecret` (`secret-tool`) + +| Unit | Status | +|------|--------| +| `~/.config/systemd/user/gnome-keyring-daemon.socket` | enabled | +| `~/.config/systemd/user/gnome-keyring-daemon.service` | enabled | + +### 2. rbw (Bitwarden CLI) + +- Unofficial Bitwarden CLI written in Rust +- Connects to `https://bitwarden.jantec.xyz` +- Uses gnome-keyring as its encrypted password store (via `pinentry`) +- Manages vault: `rbw add`, `rbw get`, `rbw list`, `rbw search`, `rbw sync` + +| Config | Value | +|--------|-------| +| `~/.config/rbw/config.json` | `{"email": "ironmikechw+bitwarden@gmail.com", "base_url": "https://bitwarden.jantec.xyz"}` | +| API Keys | Stored in `~/.config/rbw/` (registered via `rbw register`) | +| Vault sync | Automatic via `rbw sync` (interval: 3600s) | + +### 3. SSH Key Passphrases + +- Stored in gnome-keyring (libsecret) for `ssh-add` via `gnome-keyring-ssh` PAM module +- Passphrases stored under `application=ssh-agent`, `service=ssh`, `ssh-key=` +- Keys migrated from KWallet: `id_ed25519`, `id_ed25519_ja_manjaro` + +### 4. Git Credentials + +- **Global helper**: `libsecret` (stores in gnome-keyring instead of `~/.git-credentials` plaintext) +- **GitHub**: `gh auth git-credential` helper (for github.com) +- **GitLab**: configured as `provider = generic` in `.gitconfig` for gitlab.satware.com + +### 5. Application Credentials Map + +| Application | Storage | Mechanism | +|-----------|---------|-----------| +| himalaya (email) | gnome-keyring + Bitwarden | `secret-tool lookup email
` | +| ssh-agent | gnome-keyring | D-Bus secret service | +| git (global) | gnome-keyring (`libsecret`) | `git config credential.helper libsecret` | +| GitHub CLI | Bitwarden + gnome-keyring | `rbw get "GitHub Personal Token"` + GK entry | +| GitLab | gnome-keyring | `secret-tool lookup application git service gitlab.satware.com` | +| Chrome/Brave/Chromium | gnome-keyring | Safe Storage encryption keys | +| JetBrains IDEs | gnome-keyring | D-Bus secret service auto-detection | +| Remmina | gnome-keyring + Bitwarden | VNC/RDP passwords | +| Nextcloud | gnome-keyring + Bitwarden | Instance passwords | +| QGIS | gnome-keyring + Bitwarden | Master password | + +## Startup / Unlock Flow + +``` +1. greetd/tuigreet login → PAM auth +2. PAM → gnome-keyring PAM module (pam_gnome_keyring.so) +3. Keyring unlocked with login password +4. gnome-keyring-daemon starts (socket activation) +5. D-Bus org.freedesktop.secrets available +6. rbw login → decrypts vault via gnome-keyring +7. himalaya can read IMAP passwords via secret-tool +8. ssh-add can read SSH passphrases via GK +9. git-credential-libsecret reads Git creds via GK +``` + +## Migration History + +- **Before**: KDE Wallet (kwalletd) — no auto-unlock under greetd, no D-Bus support for non-Plasma apps +- **After**: gnome-keyring + rbw + Bitwarden.vault → full D-Bus secret service + central vault + CLI access + +## Manual Entry Required + +### himalaya Email Passwords + +The following email account passwords need to be stored in gnome-keyring (they were NOT in KWallet): + +```bash +# Store MW account +echo "" | secret-tool store --label="IMAP MW" email mw@satware.com application himalaya + +# Store JA account +echo "" | secret-tool store --label="IMAP JA" email ja@satware.ai application himalaya + +# Store JA Gmail +echo "" | secret-tool store --label="IMAP JA Gmail" email ja.satware@gmail.com application himalaya + +# Store Michael Gmail +echo "" | secret-tool store --label="IMAP Michael Gmail" email ironmikechw@gmail.com application himalaya +``` + +## Useful Commands + +```bash +# Bitwarden operations +rbw list # list all vault entries +rbw search # search vault +rbw get # get password (truncates on display) +rbw get --full "GitHub Personal Token" # get full password (piped) +rbw sync # sync with vault +rbw add "Service Name" # add new entry (opens $EDITOR) + +# gnome-keyring operations +secret-tool lookup email mw@satware.com # lookup by attribute +secret-tool search application ssh-agent # search +secret-tool store --label="Test" key value # store (pipe data) +dbus-send --session --print-reply --dest=org.freedesktop.secrets \ + /org/freedesktop/secrets/collection/default # low-level D-Bus + +# Verify startup +systemctl --user status gnome-keyring-daemon.socket +systemctl --user status gnome-keyring-daemon.service + +# Quick health check +rbw unlocked && echo "BW: unlocked" || echo "BW: locked" +secret-tool lookup application ssh-agent service ssh ssh-key /home/mw/.ssh/id_ed25519 && echo "GK: SSH OK" +``` + +## Troubleshooting + +### gnome-keyring not providing secrets on D-Bus +```bash +systemctl --user restart gnome-keyring-daemon.service +``` + +### rbw not unlocked +```bash +rbw unlock # prompts for login password +rbw login # prompts for Bitwarden password +``` + +### SSH keys not auto-unlocking +```bash +# Check GK entry +secret-tool lookup application ssh-agent service ssh ssh-key /home/mw/.ssh/id_ed25519 +# If missing, re-add: +echo "" | secret-tool store --label="SSH id_ed25519" \ + application ssh-agent service ssh ssh-key /home/mw/.ssh/id_ed25519 +``` + +### GitLab/GitHub creds not working +```bash +# Test GK +secret-tool lookup application git service gitlab.satware.com +``` + +### himalaya password errors +```bash +# Verify GK +secret-tool lookup email mw@satware.com +# Re-enter password from Bitwarden +rbw get "himala mw@satware.com" | secret-tool store --label="IMAP mw@satware.com" \ + email mw@satware.com application himalaya +``` + +## Security Note + +- Bitwarden vault: self-hosted at `bitwarden.jantec.xyz` +- Local cache: gnome-keyring (encrypted, session-bound) +- No plaintext passwords in config files +- `~/.git-credentials` removed on `git config --global credential.helper store` diff --git a/docs/product/passwords-migration-checklist.md b/docs/product/passwords-migration-checklist.md new file mode 100644 index 0000000..b8a9140 --- /dev/null +++ b/docs/product/passwords-migration-checklist.md @@ -0,0 +1,91 @@ +# Password Management - Migration Checklist + +## Pre-Reboot Status (2026-05-21) + +- [x] gnome-keyring installed (`1:50.0-1`) +- [x] rbw installed (`1.15.0`) +- [x] gnome-keyring-daemon.socket + service enabled + active +- [x] rbw configured: `bitwarden.jantec.xyz`, `ironmikechw+bitwarden@gmail.com` +- [x] 397 entries synced from Bitwarden vault +- [x] 45 entries migrated from KWallet → BW + GK +- [x] Duplicate BW entries cleaned (22 removed) +- [x] Git credential helper: `libsecret` +- [x] himalaya configs using `secret-tool lookup email ` +- [x] GitHub token stored in BW + GK +- [x] GitLab PAT stored in BW + GK +- [x] SSH passphrases stored in BW + GK +- [x] Browser safe storage (Chrome/Brave/Chromium) in BW + GK +- [x] Remmina passwords (5) in BW + GK +- [x] Nextcloud passwords (3) in BW + GK +- [x] QGIS Master Password in BW + GK +- [x] JetBrains AI Token in BW + GK +- [x] Documentation written: `docs/product/passwords.md` + `docs/adr/password-management-migration.md` +- [x] AGENTS.md updated with secrets management reference +- [x] KDE Wallet data file backed up (not deleted) +- [ ] KDE Wallet packages removal (post-verify) + +## Post-Reboot Actions + +### Immediate Checks +```bash +# 1. Verify gnome-keyring started +systemctl --user is-active gnome-keyring-daemon.service + +# 2. Verify rbw can access vault +rbw list | head -5 + +# 3. Verify GK entries +secret-tool lookup application ssh-agent service ssh ssh-key /home/mw/.ssh/id_ed25519 +secret-tool lookup application git service gitlab.satware.com +secret-tool lookup application nextcloud service cloud.satware.com user mw + +# 4. Check himalaya +himalaya account list +himalaya -a mw check 2>&1 # tests IMAP auth +``` + +### Manual Steps Required +1. **himalaya passwords** — 4 accounts need passwords re-entered into GK: + ```bash + for addr in mw@satware.com ja@satware.ai ja.satware@gmail.com ironmikechw@gmail.com; do + echo "$(rbw get "$addr" | head -1)" | secret-tool store --label="IMAP $addr" email "$addr" application himalaya + done + ``` + (Or manually look up passwords from BW web UI and enter them) + +2. **GitHub CLI** — Re-login if token stale: + ```bash + gh auth login --hostname github.com --with-token + ``` + Then store in GK: + ```bash + rbw get "GitHub Personal Token" | secret-tool store --label="GitHub Token" application gh-cli service github.com + ``` + +### KDE Wallet Cleanup (After Confirmation) +```bash +# Only after everything works: +sudo pacman -Rns kwallet kwalletmanager +rm -rf ~/.local/share/kwalletd/ +``` + +## Rollback (If Needed) + +If gnome-keyring + rbw doesn't work properly after reboot: +```bash +# Restore git credential helper +git config --global credential.helper store + +# Kill gnome-keyring +systemctl --user stop gnome-keyring-daemon.socket + +# Restore KWallet (if removed) +sudo pacman -S kwallet kwalletmanager +``` + +## Notes + +- All migration data preserved in `~/.local/share/kwalletd/` (not deleted yet) +- KWallet PAM refs were already commented out in `/etc/pam.d/*` +- JetBrains IDEs will auto-detect `org.freedesktop.secrets` from gnome-keyring; no config change needed +- Browser safe storage keys migrated — browsers will use them automatically diff --git a/docs/product/passwords.md b/docs/product/passwords.md new file mode 100644 index 0000000..3c96de3 --- /dev/null +++ b/docs/product/passwords.md @@ -0,0 +1,116 @@ +# Password Management - System Guide + +## Architecture + +``` +┌─────────────────────────────────────┐ +│ Bitwarden Vault │ +│ bitwarden.jantec.xyz │ ← Central, synced, backed up +│ (self-hosted) │ +│ ▲ │ +│ rbw CLI │ ← CLI access, add/list/get/search +│ (ironmikechw+bitwarden@gmail.com)│ +│ ▲ │ +│ gnome-keyring (local) │ ← D-Bus secrets API for apps +│ org.freedesktop.secrets │ ← libsecret, secret-tool +└───────────────────────────────────── +``` + +## How It Works After Reboot / Login + +1. **greetd/tuigreet login** → PAM auth +2. **PAM module** → `pam_gnome_keyring.so` unlocks keyring with login password +3. **gnome-keyring-daemon** starts via socket activation (systemd user service) +4. **D-Bus** `org.freedesktop.secrets` becomes available on session bus +5. **rbw** auto-unlocks via pinentry (reads passphrase from gnome-keyring) +6. **Apps** read secrets via `libsecret` / `secret-tool`: + - `himalaya` → IMAP/SMTP passwords via `secret-tool lookup email ` + - `ssh-agent` → SSH key passphrases via `secret-tool lookup ... ssh-key ` + - `git-credential-libsecret` → Git passwords via libsecret + - `JetBrains IDEs` → auto-detect D-Bus secrets service + +## Quick Verification + +```bash +# Is gnome-keyring running? +systemctl --user is-active gnome-keyring-daemon.service + +# Can rbw access the vault? +rbw list | head -5 +rbw get "SSH Key: id_ed25519" # should return "SSH gitlab.satware.com" + +# Can apps read secrets? +secret-tool lookup application ssh-agent service ssh ssh-key /home/mw/.ssh/id_ed25519 +secret-tool lookup application git service gitlab.satware.com +secret-tool lookup application nextcloud service cloud.satware.com user mw +``` + +## Migrated Entries (from KDE Wallet) + +| Category | Entries | Storage | +|----------|---------|---------| +| **SSH passphrases** | id_ed25519, id_ed25519_ja_manjaro | BW + GK | +| **SSH host passwords** | b0t@192.168.0.141 | BW + GK | +| **Git tokens** | GitLab PAT, GitHub token | BW + GK | +| **Remmina** | 5 VNC/RDP passwords | BW + GK | +| **Nextcloud** | 3 instance passwords | BW + GK | +| **Browser crypto** | Chrome, Brave, Chromium safe storage | BW + GK | +| **JetBrains** | AI token, Account token | BW (AI also in GK) | +| **QGIS** | Master password | BW + GK | + +Total: ~45 entries migrated. + +## Known Issues (Post-Reboot) + +1. **himalaya email passwords** — Were NOT in KWallet. Need to be re-entered manually: + ```bash + # Run once per account after reboot + rbw get "" | secret-tool store --label="IMAP " email
application himalaya + ``` + Accounts: `mw@satware.com`, `ja@satware.ai`, `ja.satware@gmail.com`, `ironmikechw@gmail.com` + +2. **GitHub CLI token** — May need re-auth: + ```bash + gh auth login --hostname github.com + gh auth git-credential store --hostname github.com # saves to GK + ``` + +## Useful Commands + +```bash +# Bitwarden +rbw list # list all entries +rbw search # search +rbw get "" # get password (truncated display) +rbw get --full "" # get full password +rbw add "" # add new entry (opens editor) +rbw sync # force sync with server +rbw unlock # unlock vault (prompts for login password) + +# Gnome-keyring +secret-tool lookup key value ... # lookup by attributes +secret-tool search key value ... # search +secret-tool store --label="X" key value # store (pipe password via stdin) + +# System +systemctl --user status gnome-keyring-daemon.service +systemctl --user restart gnome-keyring-daemon.service # if D-Bus secrets missing +``` + +## Troubleshooting + +| Symptom | Fix | +|---------|-----| +| `secret-tool lookup` returns empty | `systemctl --user restart gnome-keyring-daemon.service` | +| `rbw list` fails | `rbw unlock` (enter login password) | +| SSH key asks for passphrase | `secret-tool lookup application ssh-agent service ssh ssh-key /home/mw/.ssh/id_ed25519` — if empty, re-store it | +| `gh` commands fail | `gh auth login --hostname github.com` | +| himalaya auth errors | Re-enter IMAP passwords via `secret-tool store` (see Known Issues) | +| Browser safe storage issues | Browsers recreate their own Safe Storage keys on startup | + +## KDE Wallet Status + +- Packages still installed (`kwallet`, `kwalletmanager`) — harmless, will be removed after verification +- Data file preserved at `~/.local/share/kwalletd/kdewallet.kwl` (backup) +- PAM references already commented out +- No longer used by any application diff --git a/docs/yazi-cheatsheet.md b/docs/yazi-cheatsheet.md new file mode 100644 index 0000000..d4edd8f --- /dev/null +++ b/docs/yazi-cheatsheet.md @@ -0,0 +1,218 @@ +# Yazi v26.5.6 - Cheatsheet & Daily Usage Tricks + +Version: 26.5.6 (Arch Linux 2026-05-10) | Rust-based terminal file manager +Config: ~/.config/yazi/ (keymap.toml, yazi.toml, theme.toml, init.lua) + +============================================================ +QUICK START +============================================================ + yazi # launch + y # shell wrapper (cd persists on exit) + q # quit (cwd applied) + Q # quit without changing cwd + F1 or ~ # show help / keybindings + +============================================================ +NAVIGATION (essential) +============================================================ + h parent directory + l enter dir / open hovered file + j / k down / up + H / L history back / forward + Enter open file + o open file (alternative) + Tab toggle file details / info + . toggle hidden files + ~ jump to home + / search forward + ? search backward + n / N next / previous match + f interactive filter (fuzzy) + S search with fd + g g go to top + G go to bottom + +============================================================ +FILE OPERATIONS +============================================================ + Space toggle selection (multi-select) + v visual mode (range select) + Ctrl+A select all + Esc clear selection + y yank / copy + p paste + X cut + x undo cut + D delete to trash + Shift+D permanent delete + a create new file + Shift+A create new directory + R rename + Shift+R bulk rename (opens editor) + O "Open with..." menu + +============================================================ +TABS +============================================================ + t new tab + 1-9 switch to tab N + [ / ] previous / next tab + W close current tab + +============================================================ +SORTING +============================================================ + , m sort by modified (mtime) + , M sort by modified (reverse) + , c sort by created + , C sort by created (reverse) + , e sort by extension + , E sort by extension (reverse) + , a sort alphabetically + , A sort alphabetically (reverse) + , s sort by size + , S sort by size (reverse) + +============================================================ +SHELL & COMMANDS +============================================================ + ! drop into $SHELL here (block) + : command line (yazi internal commands) + Ctrl+S run an arbitrary shell command + +============================================================ +PLUGIN EMIT COMMANDS (used with : or ya emit) +============================================================ + :cd change directory + :reveal reveal a file in its parent dir + :tab_create open new tab + :tab_switch switch to tab N + :quit quit + :yank yank selected + :paste paste yanked + :remove delete to trash + :rename rename hovered + :shell run shell command + +============================================================ +CONFIGURATION (key files) +============================================================ + keymap.toml custom keybindings + yazi.toml behavior, previewers, open rules + theme.toml colors, UI theme + init.lua Lua startup script (plugins, status bar tweaks) + ~/.config/yazi/plugins/ plugin directory + +============================================================ +POWER TRICKS & BEST PRACTICES +============================================================ + +1. Shell Wrapper (cd persistence) + Use the `y` wrapper script instead of raw `yazi` so your shell + `cd`s into the directory you navigated to on exit. + Install: https://yazi-rs.github.io/docs/quick-start/#shell-wrapper + +2. Open files in default apps (xdg-open) + Add to yazi.toml: + [[opener.system_default]] + run = "xdg-open \"$1\"" + for = "linux" + desc = "System Default" + [[open.rules]] + name = "*" + use = ["system_default"] + +3. Drop to shell from anywhere + Add to keymap.toml: + [[mgr.prepend_keymap]] + on = "!" + for = "unix" + run = 'shell "$SHELL" --block' + desc = "Open $SHELL here" + +4. Close input with single Esc (no Vi mode) + [[input.prepend_keymap]] + on = "" + run = "close" + desc = "Cancel input" + +5. Copy to system clipboard on yank (Wayland) + [[mgr.prepend_keymap]] + on = "y" + run = [ 'shell -- for path in %s; do echo "file://$path"; done | wl-copy -t text/uri-list', "yank" ] + +6. cd to Git repo root + [[mgr.prepend_keymap]] + on = ["g", "r"] + run = 'shell -- ya emit cd "$(git rev-parse --show-toplevel)"' + +7. Smart tab - create tab + enter hovered dir + Save plugin: ~/.config/yazi/plugins/smart-tab.yazi/main.lua + --- @sync entry + return { entry = function() + local h = cx.active.current.hovered + ya.emit("tab_create", h and h.cha.is_dir and { h.url } or { current = true }) + end } + Bind in keymap.toml: + [[mgr.prepend_keymap]] + on = ["t", "t"] run = "plugin smart-tab" + +8. Performance: disable unnecessary image previews + If you don't need image previews, disable them: + [plugin] + preloaders = [] + previewers = [] + Or for network mounts only: + [[plugin.prepend_preloaders]] + url = "/remote/**" + run = "noop" + +9. Show username+hostname in header (init.lua) + Header:children_add(function() + if ya.target_family() ~= "unix" then return "" end + return ui.Span(ya.user_name().."@"..ya.host_name()..":"):fg("blue") + end, 500, Header.LEFT) + +10. Show symlink target in status bar (init.lua) + Status:children_add(function(self) + local h = self._current.hovered + if h and h.link_to then + return " -> "..tostring(h.link_to) else return "" + end + end, 3300, Status.LEFT) + +============================================================ +PLUGINS WORTH INSTALLING (yazi-rs/plugins) +============================================================ + full-border.yazi full panel borders + smart-enter.yazi open files or enter dirs with one key + smart-paste.yazi paste without entering directory + toggle-pane.yazi maximize/hide preview pane + confirm-quit.yazi confirm quit when tabs are open + no-status.yazi hide status bar for minimal UI + mime-ext.yazi fast extension-based mime detection + chmod.yazi change file permissions + 7zip.yazi archive support + zoxide.yazi zoxide integration for jump history + +============================================================ +DDS (Data Distribution Service) EVENTS +============================================================ + Yazi broadcasts events via DDS socket for inter-process comms: + cd directory changed + hover file hovered + yank files yanked + bulk bulk rename in progress + Use DDS to build custom integrations (e.g. folder-specific rules). + +============================================================ +DAILY DRILL (memorization order) +============================================================ + j/k move | l enter | h back + Space select | y copy | p paste | X cut + D delete | R rename | a create | . hidden + / search | f filter | g g top | G bottom + t tab | 1-9 switch | ! shell | q quit + +============================================================ +Generated 2026-05-21 | Sources: yazi-rs.github.io/docs, official tips page \ No newline at end of file