aboutsummaryrefslogtreecommitdiff
path: root/modules/hosts/lilith/secrets.nix
diff options
context:
space:
mode:
authorLeander Scherer <leander@schererleander.de>2026-02-05 20:09:08 +0100
committerLeander Scherer <leander@schererleander.de>2026-02-05 20:09:08 +0100
commitd2c7fb0bfe44fe37833e5c50329839d33e42c7b1 (patch)
tree7455d74cee2a880190699b7a388a7d01cc9ba223 /modules/hosts/lilith/secrets.nix
parent264239e195928d59d4eb4b060b7446a95358aeb0 (diff)
feat(sops): host specific secrets config
Diffstat (limited to 'modules/hosts/lilith/secrets.nix')
-rw-r--r--modules/hosts/lilith/secrets.nix25
1 files changed, 25 insertions, 0 deletions
diff --git a/modules/hosts/lilith/secrets.nix b/modules/hosts/lilith/secrets.nix
new file mode 100644
index 0000000..b02dacc
--- /dev/null
+++ b/modules/hosts/lilith/secrets.nix
@@ -0,0 +1,25 @@
+{
+ flake.modules.darwin.lilith =
+ { inputs, ... }:
+ {
+ imports = [ inputs.sops-nix.darwinModules.sops ];
+ sops = {
+ defaultSopsFile = inputs.self + /secrets/secrets.yaml;
+ age.keyFile = "/etc/sops/age_key";
+ secrets = {
+ "ssh_github_key" = {
+ owner = "schererleander";
+ mode = "0600";
+ };
+ "ssh_jonsbo_key" = {
+ owner = "schererleander";
+ mode = "0600";
+ };
+ "ssh_sachiel_key" = {
+ owner = "schererleander";
+ mode = "0600";
+ };
+ };
+ };
+ };
+}