From 11518113bedd51b3e16004338c20df637eba0416 Mon Sep 17 00:00:00 2001 From: schererleander Date: Tue, 3 Feb 2026 19:13:05 +0100 Subject: feat(sops): fix sops-nix --- modules/flake/home.nix | 1 + modules/secrets/default.nix | 91 +++++++++++++++++++-------------------------- 2 files changed, 40 insertions(+), 52 deletions(-) (limited to 'modules') diff --git a/modules/flake/home.nix b/modules/flake/home.nix index 288b558..2ac2b45 100644 --- a/modules/flake/home.nix +++ b/modules/flake/home.nix @@ -14,6 +14,7 @@ in flake.homeModules = { default = { imports = homeModuleFiles ++ [ + inputs.sops-nix.homeManagerModules.sops inputs.nixcord.homeModules.nixcord inputs.spicetify-nix.homeManagerModules.spicetify ]; diff --git a/modules/secrets/default.nix b/modules/secrets/default.nix index 81f7a40..0543563 100644 --- a/modules/secrets/default.nix +++ b/modules/secrets/default.nix @@ -1,56 +1,43 @@ { inputs, ... }: { - flake.modules.nixos.secrets = { config, ... }: { - imports = [ inputs.sops-nix.nixosModules.sops ]; - sops.defaultSopsFile = ../../../secrets/secrets.yaml; - sops.age.keyFile = "/etc/sops/age_key"; - sops.secrets."borgbase_ssh_key" = { - owner = "root"; - mode = "0600"; - }; - sops.secrets."nextcloud-admin-pass" = { - owner = "root"; - mode = "0600"; - }; - sops.secrets."ssh_github_key" = { - owner = "schererleander"; - mode = "0600"; - }; - sops.secrets."ssh_jonsbo_key" = { - owner = "schererleander"; - mode = "0600"; - }; - sops.secrets."ssh_sachiel_key" = { - owner = "schererleander"; - mode = "0600"; - }; - sops.secrets."ssh_borgbase_unraid_key" = { - owner = "root"; - mode = "0600"; - }; - sops.secrets."ssh_config" = { - owner = "schererleander"; - mode = "0600"; - }; - sops.secrets."borg_repo" = { - owner = "root"; - mode = "0600"; - }; - }; - - flake.modules.darwin.secrets = { config, ... }: { - imports = [ inputs.sops-nix.darwinModules.sops ]; - sops.defaultSopsFile = ../../../secrets/secrets.yaml; - sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; - }; - - flake.modules.homeManager.secrets = { config, ... }: { - imports = [ inputs.sops-nix.homeManagerModules.sops ]; - sops.age.sshKeyPaths = [ "${config.home.homeDirectory}/.ssh/id_ed25519" ]; - - programs.ssh = { - enable = true; - includes = [ config.sops.secrets."ssh_config".path ]; + imports = [ inputs.sops-nix.nixosModules.sops ]; + sops = { + defaultSopsFile = inputs.self + /secrets/secrets.yaml; + age.keyFile = "/etc/sops/age_key"; + secrets = { + "borgbase_ssh_key" = { + owner = "root"; + mode = "0600"; + }; + "nextcloud-admin-pass" = { + owner = "root"; + mode = "0600"; + }; + "ssh_github_key" = { + owner = "administrator"; + mode = "0600"; + }; + "ssh_jonsbo_key" = { + owner = "administrator"; + mode = "0600"; + }; + "ssh_sachiel_key" = { + owner = "administrator"; + mode = "0600"; + }; + "ssh_config" = { + owner = "administrator"; + mode = "0600"; + }; + "ssh_borgbase_unraid_key" = { + owner = "root"; + mode = "0600"; + }; + "borg_repo" = { + owner = "root"; + mode = "0600"; + }; }; }; -} \ No newline at end of file +} + -- cgit v1.3.1