diff options
| author | adi <adikro@disroot.org> | 2026-07-29 17:09:58 +0200 |
|---|---|---|
| committer | adi <adikro@disroot.org> | 2026-07-29 17:09:58 +0200 |
| commit | 39a2b09c27bb74c9e59d1772764f901e3c8fb9e4 (patch) | |
| tree | 0ba58e6fbf086a85d875df1c10f6d23bc3bbc7da /modules/sops.nix | |
| parent | 8a820cacee1ff07ae7397d053b26e66f7086a4a4 (diff) | |
revamped flake.nix, removed homelab specific modulesstaging
Diffstat (limited to 'modules/sops.nix')
| -rw-r--r-- | modules/sops.nix | 36 |
1 files changed, 36 insertions, 0 deletions
diff --git a/modules/sops.nix b/modules/sops.nix new file mode 100644 index 0000000..3ca2d16 --- /dev/null +++ b/modules/sops.nix @@ -0,0 +1,36 @@ +{ + config, + lib, + pkgs, + inputs, + username, + ... +}: +let + cfg = config.os.srv.sops; +in +{ + imports = [ inputs.sops-nix.nixosModules.sops ]; + + options.os.srv.sops.enable = lib.mkEnableOption "enables sops-nix"; + config = lib.mkIf cfg.enable { + sops = { + defaultSopsFile = ../../secrets/common.yaml; + defaultSopsFormat = "yaml"; + age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; + + secrets = { + # "syncthing/gui_password".owner = username; + "syncthing/encryption/keepass".owner = username; + "syncthing/encryption/sync".owner = username; + "obs/websocket_password".owner = username; + }; + }; + + environment.systemPackages = with pkgs; [ + sops + age + ssh-to-age + ]; + }; +} |
