#!/usr/bin/env sh set -eu dir=${0%/*} key=$1 name=${key##*/} name=${name%.secret} sudo unshare --mount sh -xc " mount --bind '$dir'/credential.secret /var/lib/systemd/credential.secret && systemd-creds decrypt --with-key=host --name '$name' '$key' - "