aboutsummaryrefslogtreecommitdiff
path: root/modules/secrets
diff options
context:
space:
mode:
Diffstat (limited to 'modules/secrets')
-rw-r--r--modules/secrets/default.nix91
1 files changed, 39 insertions, 52 deletions
diff --git a/modules/secrets/default.nix b/modules/secrets/default.nix
index 81f7a40..0543563 100644
--- a/modules/secrets/default.nix
+++ b/modules/secrets/default.nix
@@ -1,56 +1,43 @@
{ inputs, ... }:
{
- flake.modules.nixos.secrets = { config, ... }: {
- imports = [ inputs.sops-nix.nixosModules.sops ];
- sops.defaultSopsFile = ../../../secrets/secrets.yaml;
- sops.age.keyFile = "/etc/sops/age_key";
- sops.secrets."borgbase_ssh_key" = {
- owner = "root";
- mode = "0600";
- };
- sops.secrets."nextcloud-admin-pass" = {
- owner = "root";
- mode = "0600";
- };
- sops.secrets."ssh_github_key" = {
- owner = "schererleander";
- mode = "0600";
- };
- sops.secrets."ssh_jonsbo_key" = {
- owner = "schererleander";
- mode = "0600";
- };
- sops.secrets."ssh_sachiel_key" = {
- owner = "schererleander";
- mode = "0600";
- };
- sops.secrets."ssh_borgbase_unraid_key" = {
- owner = "root";
- mode = "0600";
- };
- sops.secrets."ssh_config" = {
- owner = "schererleander";
- mode = "0600";
- };
- sops.secrets."borg_repo" = {
- owner = "root";
- mode = "0600";
- };
- };
-
- flake.modules.darwin.secrets = { config, ... }: {
- imports = [ inputs.sops-nix.darwinModules.sops ];
- sops.defaultSopsFile = ../../../secrets/secrets.yaml;
- sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
- };
-
- flake.modules.homeManager.secrets = { config, ... }: {
- imports = [ inputs.sops-nix.homeManagerModules.sops ];
- sops.age.sshKeyPaths = [ "${config.home.homeDirectory}/.ssh/id_ed25519" ];
-
- programs.ssh = {
- enable = true;
- includes = [ config.sops.secrets."ssh_config".path ];
+ imports = [ inputs.sops-nix.nixosModules.sops ];
+ sops = {
+ defaultSopsFile = inputs.self + /secrets/secrets.yaml;
+ age.keyFile = "/etc/sops/age_key";
+ secrets = {
+ "borgbase_ssh_key" = {
+ owner = "root";
+ mode = "0600";
+ };
+ "nextcloud-admin-pass" = {
+ owner = "root";
+ mode = "0600";
+ };
+ "ssh_github_key" = {
+ owner = "administrator";
+ mode = "0600";
+ };
+ "ssh_jonsbo_key" = {
+ owner = "administrator";
+ mode = "0600";
+ };
+ "ssh_sachiel_key" = {
+ owner = "administrator";
+ mode = "0600";
+ };
+ "ssh_config" = {
+ owner = "administrator";
+ mode = "0600";
+ };
+ "ssh_borgbase_unraid_key" = {
+ owner = "root";
+ mode = "0600";
+ };
+ "borg_repo" = {
+ owner = "root";
+ mode = "0600";
+ };
};
};
-} \ No newline at end of file
+}
+