feat: base git/gnupg install + auto SSH/GPG key setup for external git
Provision Coder Templates / provision (push) Successful in 2m11s

- Every template's coder_agent startup script now unconditionally
  installs git and gnupg as base packages (guarded on `command -v`, so
  it's a fast no-op where already present, e.g. templates/web's baked
  image). Not every base image ships gnupg by default.

- cli-setup-wizard.sh (all 6 templates) now tracks whether the user
  actually ended up authenticated against GitHub and/or Gitea via the
  existing gh/tea install-and-login prompts. If at least one succeeded,
  it asks once more whether to auto-generate an SSH key (ed25519) and a
  GPG signing key (ed25519, quick-gen) and register them with whichever
  host(s) are in play - stays completely silent for "local git only"
  (neither gh nor tea set up).

  - GitHub: `gh ssh-key add` / `gh gpg-key add` (official gh CLI
    subcommands).
  - Gitea: direct calls against `/api/v1/user/keys` and
    `/api/v1/user/gpg_keys`, reusing the token `tea login add` already
    stored in tea's config.yml (parsed with a small awk extractor).
  - Either upload failing (already added, API shape mismatch, etc.)
    just prints the manual command/URL and moves on - never blocks the
    rest of the wizard, consistent with every other step's style.
  - git is configured to sign commits with the new key
    (user.signingkey + commit.gpgsign) once a GPG key exists, whether
    freshly generated or already present from a prior run.

README updated to document both additions.
This commit is contained in:
2026-08-26 23:16:25 +02:00
parent e8a8f93f9d
commit 013567f02a
13 changed files with 673 additions and 0 deletions
+13
View File
@@ -117,6 +117,19 @@ finishes it - and offers to install + log into:
- **GitHub CLI** (`gh`, via the official apt repo, then `gh auth login`)
- **Gitea CLI** (`tea`, official binary release downloaded to `~/.local/bin`, then `tea login add`)
`git` and `gnupg` themselves aren't part of this opt-in flow - every
template's `coder_agent` startup script installs them unconditionally as
base packages (a no-op where they're already present, e.g. baked into
`templates/web`'s image). If the wizard just authenticated GitHub and/or
Gitea above (skipped entirely for "local git only" - neither set up), it
asks once more whether to auto-generate an ed25519 SSH key and an ed25519
GPG signing key and register them with whichever host(s) got set up: `gh
ssh-key add` / `gh gpg-key add` for GitHub, a direct call against Gitea's
`/api/v1/user/keys` and `/api/v1/user/gpg_keys` (using the token `tea
login add` already stored) for Gitea. Either upload failing just prints
the manual command/URL to finish it yourself - never blocks the rest of
the wizard.
It does **not** ask about VS Code extensions, since those are handled by
Terraform (see above). Once the user confirms completion it writes a
sentinel file (`~/.cache/coder-cli-wizard/done`) and stops prompting. It can