Files
nixy/hosts/server/secrets/default.nix
Hadi 26b08ec009 add signing key to sops
Former-commit-id: 1a771e97ac
2025-05-06 11:27:32 +02:00

40 lines
971 B
Nix

{ pkgs, ... }: {
sops = {
age.keyFile = "/home/hadi/.config/sops/age/keys.txt";
defaultSopsFile = ./secrets.yaml;
secrets = {
sshconfig = {
owner = "hadi";
path = "/home/hadi/.ssh/config";
mode = "0600";
};
github-key = {
owner = "hadi";
path = "/home/hadi/.ssh/github";
mode = "0600";
};
signing-key = {
owner = "hadi";
path = "/home/hadi/.ssh/key";
mode = "0600";
};
signing-pub-key = {
owner = "hadi";
path = "/home/hadi/.ssh/key.pub";
mode = "0600";
};
cloudflare-dns-token = { path = "/etc/cloudflare/dnskey.txt"; };
nextcloud-pwd = { path = "/etc/nextcloud/pwd.txt"; };
adguard-pwd = { };
hoarder = { };
recyclarr = {
owner = "recyclarr";
mode = "0777";
};
wireguard-pia = { };
};
};
environment.systemPackages = with pkgs; [ sops age ];
}