Initial commit: Hermes Agent Skills collection
This commit is contained in:
@@ -0,0 +1,57 @@
|
||||
# SSH Key Storage in 1Password — Reference
|
||||
|
||||
## Session: 2026-06-26 (Hermes Agent)
|
||||
|
||||
### Problem
|
||||
1Password's native "SSH Key" item category (`category: SSH_KEY`, field type `SSHKEY`) does **not** correctly persist the `private_key` field when created via `op item create`. The field is silently dropped from the created item.
|
||||
|
||||
### Workaround
|
||||
Use `SECURE_NOTE` with a `CONCEALED` field labeled `private key`. This stores the key securely, hides it from casual view, and makes it retrievable via `op read` or `op item get --reveal`.
|
||||
|
||||
### Pattern
|
||||
|
||||
1. **Generate key locally** (Ed25519 preferred):
|
||||
```bash
|
||||
ssh-keygen -t ed25519 -C "hermes-agent@proxmox" -f ~/.ssh/id_ed25519_proxmox -N ""
|
||||
```
|
||||
|
||||
2. **Build JSON template from file** (never pass private key on CLI):
|
||||
```bash
|
||||
python3 -c "
|
||||
import json
|
||||
pk = open('~/.ssh/id_ed25519_proxmox').read().strip()
|
||||
puk = open('~/.ssh/id_ed25519_proxmox.pub').read().strip()
|
||||
template = {
|
||||
'title': 'hermes-agent Proxmox SSH Key',
|
||||
'category': 'SECURE_NOTE',
|
||||
'fields': [
|
||||
{'id': 'notesPlain', 'type': 'STRING', 'purpose': 'NOTES',
|
||||
'label': 'notesPlain', 'value': f'Public key:\\n{puk}'},
|
||||
{'id': 'private_key', 'type': 'CONCEALED',
|
||||
'label': 'private key', 'value': pk}
|
||||
]
|
||||
}
|
||||
json.dump(template, open('/tmp/op_template.json', 'w'))
|
||||
"
|
||||
```
|
||||
|
||||
3. **Create and verify**:
|
||||
```bash
|
||||
cat /tmp/op_template.json | op item create - --vault Hermes
|
||||
# Verify
|
||||
op item get "hermes-agent Proxmox SSH Key" --vault Hermes --reveal
|
||||
```
|
||||
|
||||
### Retrieval in Scripts
|
||||
|
||||
```bash
|
||||
pk=$(op read 'op://Hermes/hermes-agent Proxmox SSH Key/private key')
|
||||
tmpkey=$(mktemp)
|
||||
echo "$pk" > "$tmpkey"
|
||||
chmod 600 "$tmpkey"
|
||||
ssh -i "$tmpkey" root@10.0.20.91 "hostname"
|
||||
rm -f "$tmpkey"
|
||||
```
|
||||
|
||||
### Note on Service Accounts
|
||||
Hermes' `OP_SERVICE_ACCOUNT_TOKEN` is scoped to specific vaults. If `op vault list` shows only "Hermes", that's the only vault accessible. To add access to other vaults, update the 1Password integration's vault grants in the 1Password admin console.
|
||||
Reference in New Issue
Block a user