summaryrefslogtreecommitdiff
path: root/modules/sops.nix
diff options
context:
space:
mode:
authoradi <adikro@disroot.org>2026-07-29 17:09:58 +0200
committeradi <adikro@disroot.org>2026-07-29 17:09:58 +0200
commit39a2b09c27bb74c9e59d1772764f901e3c8fb9e4 (patch)
tree0ba58e6fbf086a85d875df1c10f6d23bc3bbc7da /modules/sops.nix
parent8a820cacee1ff07ae7397d053b26e66f7086a4a4 (diff)
revamped flake.nix, removed homelab specific modulesstaging
Diffstat (limited to 'modules/sops.nix')
-rw-r--r--modules/sops.nix36
1 files changed, 36 insertions, 0 deletions
diff --git a/modules/sops.nix b/modules/sops.nix
new file mode 100644
index 0000000..3ca2d16
--- /dev/null
+++ b/modules/sops.nix
@@ -0,0 +1,36 @@
+{
+ config,
+ lib,
+ pkgs,
+ inputs,
+ username,
+ ...
+}:
+let
+ cfg = config.os.srv.sops;
+in
+{
+ imports = [ inputs.sops-nix.nixosModules.sops ];
+
+ options.os.srv.sops.enable = lib.mkEnableOption "enables sops-nix";
+ config = lib.mkIf cfg.enable {
+ sops = {
+ defaultSopsFile = ../../secrets/common.yaml;
+ defaultSopsFormat = "yaml";
+ age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
+
+ secrets = {
+ # "syncthing/gui_password".owner = username;
+ "syncthing/encryption/keepass".owner = username;
+ "syncthing/encryption/sync".owner = username;
+ "obs/websocket_password".owner = username;
+ };
+ };
+
+ environment.systemPackages = with pkgs; [
+ sops
+ age
+ ssh-to-age
+ ];
+ };
+}