Sistema de sync boot/shutdown con chezmoi (systemd --user)

Añade chezmoi-boot-sync.service (aplica la config respaldada al
arrancar, vía chezmoi update) y chezmoi-shutdown-sync.service (re-add +
commit + push al cerrar sesión/apagar, usando el truco de ExecStop en
un servicio oneshot con RemainAfterExit). Ambos a nivel de usuario, sin
depender de sudo.

run_once_after_enable-chezmoi-sync-linger.sh habilita 'loginctl
enable-linger' automáticamente en cualquier máquina nueva donde se
aplique este repo, para que la instancia systemd --user (y por tanto
ambos servicios) sobreviva al logout y arranque con el sistema.

El remoto origin pasó de SSH a HTTPS: el push automático desde un
servicio systemd no tiene acceso al agente SSH (Bitwarden) de la
sesión interactiva, así que usa el token cacheado por
credential.helper=store en su lugar.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Josevi
2026-07-31 20:24:20 +02:00
co-authored by Claude Sonnet 5
parent 274f4f0e58
commit ca8997663b
7 changed files with 91 additions and 0 deletions
@@ -0,0 +1,12 @@
[Unit]
Description=Chezmoi: aplica config respaldada al iniciar sesión
After=network-online.target
Wants=network-online.target
[Service]
Type=oneshot
ExecStart=%h/.local/bin/chezmoi-boot-sync.sh
TimeoutStartSec=60
[Install]
WantedBy=default.target
@@ -0,0 +1,14 @@
[Unit]
Description=Chezmoi: respalda config al cerrar sesión/apagar
After=network-online.target
Wants=network-online.target
[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/bin/true
ExecStop=%h/.local/bin/chezmoi-shutdown-sync.sh
TimeoutStopSec=30
[Install]
WantedBy=default.target
@@ -0,0 +1 @@
/home/VampireJSV/.config/systemd/user/chezmoi-boot-sync.service
@@ -0,0 +1 @@
/home/VampireJSV/.config/systemd/user/chezmoi-shutdown-sync.service
@@ -0,0 +1,22 @@
#!/usr/bin/env bash
# Aplica al arrancar la sesión la config respaldada en chezmoi.
# No debe bloquear nunca el arranque: cualquier fallo (sin red, conflicto)
# se registra y se continúa con el estado local tal cual está.
set -uo pipefail
LOG="$HOME/.local/share/chezmoi-sync.log"
mkdir -p "$(dirname "$LOG")"
exec >>"$LOG" 2>&1
echo "=== boot-sync $(date -Iseconds) ==="
if ! timeout 15 git -C "$HOME/.local/share/chezmoi" ls-remote --exit-code origin >/dev/null 2>&1; then
echo "sin conexión con el remoto, me quedo con el estado local"
exit 0
fi
if timeout 30 chezmoi update --force; then
echo "chezmoi update OK"
else
echo "chezmoi update falló (ver arriba), me quedo con el estado local"
fi
@@ -0,0 +1,30 @@
#!/usr/bin/env bash
# Respalda al cerrar sesión/apagar todo lo que chezmoi ya tiene rastreado.
# Solo re-sincroniza rutas YA gestionadas (chezmoi re-add), nunca añade
# rutas nuevas por su cuenta -- eso evita que algo sensible se cuele solo.
set -uo pipefail
LOG="$HOME/.local/share/chezmoi-sync.log"
mkdir -p "$(dirname "$LOG")"
exec >>"$LOG" 2>&1
echo "=== shutdown-sync $(date -Iseconds) ==="
SRC="$HOME/.local/share/chezmoi"
cd "$SRC" || exit 0
chezmoi re-add
git add -A
if git diff --cached --quiet; then
echo "sin cambios que respaldar"
exit 0
fi
git commit -m "Auto-backup $(date '+%Y-%m-%d %H:%M')"
if timeout 20 git push origin main; then
echo "push OK"
else
echo "push falló (¿sin red?), el commit queda en local para el próximo intento"
fi
+11
View File
@@ -0,0 +1,11 @@
#!/usr/bin/env bash
# Se ejecuta una sola vez tras `chezmoi apply`/`chezmoi init --apply` en una
# máquina nueva. Habilita "linger" para que la instancia systemd --user
# arranque con el sistema (no solo al hacer login) y sobreviva al logout,
# necesario para que chezmoi-boot-sync/chezmoi-shutdown-sync se disparen
# en el arranque/apagado reales y no solo en la sesión gráfica.
set -euo pipefail
if command -v loginctl >/dev/null 2>&1; then
loginctl enable-linger "$USER" || true
fi