move sops to config file
This commit is contained in:
+26
-1
@@ -32,6 +32,23 @@
|
|||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
# SOPS config
|
||||||
|
sops = {
|
||||||
|
age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
|
||||||
|
age.keyFile = "/var/lib/sops-nix/key.txt";
|
||||||
|
age.generateKey = true;
|
||||||
|
defaultSopsFormat = "json";
|
||||||
|
defaultSopsFile = ./secrets/roy.json;
|
||||||
|
|
||||||
|
# test secrets
|
||||||
|
secrets = {
|
||||||
|
"testKey" = {
|
||||||
|
sopsFile = ./secrets/roy.json;
|
||||||
|
key = "testKey";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
# needed to allowOther in home.nix
|
# needed to allowOther in home.nix
|
||||||
programs.fuse.userAllowOther = true;
|
programs.fuse.userAllowOther = true;
|
||||||
|
|
||||||
@@ -151,7 +168,15 @@
|
|||||||
};
|
};
|
||||||
|
|
||||||
# Enable the OpenSSH daemon.
|
# Enable the OpenSSH daemon.
|
||||||
services.openssh.enable = true;
|
services.openssh = {
|
||||||
|
enable = true;
|
||||||
|
hostKeys = [
|
||||||
|
{
|
||||||
|
type = "ed25519";
|
||||||
|
path = "/persist/etc/ssh/ssh_host_ed25519_key";
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
# Open ports in the firewall.
|
# Open ports in the firewall.
|
||||||
# networking.firewall.allowedTCPPorts = [ ... ];
|
# networking.firewall.allowedTCPPorts = [ ... ];
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{ pkgs, inputs, ... }:
|
{ config, pkgs, inputs, ... }:
|
||||||
|
|
||||||
{
|
{
|
||||||
|
|
||||||
@@ -43,7 +43,6 @@
|
|||||||
"rp"
|
"rp"
|
||||||
".mozilla/firefox/roy/storage/default"
|
".mozilla/firefox/roy/storage/default"
|
||||||
".cache/mozilla/firefox/roy"
|
".cache/mozilla/firefox/roy"
|
||||||
"age"
|
|
||||||
];
|
];
|
||||||
files = [
|
files = [
|
||||||
".bash_history"
|
".bash_history"
|
||||||
@@ -54,16 +53,6 @@
|
|||||||
allowOther = true;
|
allowOther = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
# SOPS config
|
|
||||||
sops = {
|
|
||||||
age.keyFile = "/persist/home/roy/age/.age-key.txt";
|
|
||||||
defaultSopsFormat = "json";
|
|
||||||
defaultSopsFile = ./secrets/roy.json;
|
|
||||||
# secrets.test = {
|
|
||||||
# path = "%r/test.txt";
|
|
||||||
#};
|
|
||||||
};
|
|
||||||
|
|
||||||
# User services must come after sops secrets
|
# User services must come after sops secrets
|
||||||
systemd.user.services.mbsync.unitConfig.After = [ "sops-nix.service" ];
|
systemd.user.services.mbsync.unitConfig.After = [ "sops-nix.service" ];
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user