From 76e043171c9a6cd7957ddee5d792740ada93b8ce Mon Sep 17 00:00:00 2001 From: Grisha Shipunov Date: Sun, 19 Jan 2025 20:46:38 +0100 Subject: reorganize secrets --- hosts/toaster/default.nix | 21 +++++++++++++++++++-- 1 file changed, 19 insertions(+), 2 deletions(-) (limited to 'hosts/toaster/default.nix') diff --git a/hosts/toaster/default.nix b/hosts/toaster/default.nix index c3b087d..f3afe11 100644 --- a/hosts/toaster/default.nix +++ b/hosts/toaster/default.nix @@ -1,15 +1,32 @@ -{ pkgs, ... }: +{ pkgs, config, ... }: { imports = [ ./amd.nix ./hardware-configuration.nix # ./irc.nix ./network - ./secrets.nix ./secure-boot.nix ./zfs.nix ]; + sops.defaultSopsFile = ./secrets.yaml; + sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; + + sops.secrets = { + "wg/zw" = { + owner = config.users.users.systemd-network.name; + }; + "wg/dvb" = { + owner = config.users.users.systemd-network.name; + }; + "wg/mullvad" = { + owner = config.users.users.systemd-network.name; + }; + "wg/0xa-mgmt" = { + owner = config.users.users.systemd-network.name; + }; + }; + nixpkgs.config.allowUnfree = true; # Use the systemd-boot EFI boot loader. -- cgit v1.3.1