diff options
| author | schererleander <leander@schererleander.de> | 2026-02-05 12:03:07 +0100 |
|---|---|---|
| committer | schererleander <leander@schererleander.de> | 2026-02-05 15:19:41 +0100 |
| commit | 3b13d9a2a367db84d48940460532c17a374bb488 (patch) | |
| tree | 599110a39c4baecf3991fe9a58d0103a43c38896 /modules/system/secrets.nix | |
| parent | 46aa4842b98d9215baca00060c233f386a0c2188 (diff) | |
feat(modules): use dendritic pattern
Diffstat (limited to 'modules/system/secrets.nix')
| -rw-r--r-- | modules/system/secrets.nix | 50 |
1 files changed, 50 insertions, 0 deletions
diff --git a/modules/system/secrets.nix b/modules/system/secrets.nix new file mode 100644 index 0000000..e59c7da --- /dev/null +++ b/modules/system/secrets.nix @@ -0,0 +1,50 @@ +{ + flake.modules.nixos.secrets = + { inputs, ... }: + { + imports = [ inputs.sops-nix.nixosModules.sops ]; + sops = { + defaultSopsFile = inputs.self + /secrets/secrets.yaml; + age.keyFile = "/etc/sops/age_key"; + secrets = { + "borgbase_ssh_key" = { + owner = "root"; + mode = "0600"; + }; + "nextcloud-secret" = { + owner = "nextcloud"; + group = "nextcloud"; + mode = "0400"; + }; + "nextcloud-admin-pass" = { + owner = "root"; + mode = "0600"; + }; + "ssh_github_key" = { + owner = "administrator"; + mode = "0600"; + }; + "ssh_jonsbo_key" = { + owner = "administrator"; + mode = "0600"; + }; + "ssh_sachiel_key" = { + owner = "administrator"; + mode = "0600"; + }; + "borg_repo" = { + owner = "root"; + mode = "0600"; + }; + "cert_fullchain" = { + owner = "nginx"; + group = "nginx"; + }; + "cert_private" = { + owner = "nginx"; + group = "nginx"; + }; + }; + }; + }; +} |
