summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--flake.lock60
-rw-r--r--hm/conf/git.nix2
-rw-r--r--hm/soft/email.nix38
-rw-r--r--hm/soft/nixcord.nix13
-rw-r--r--hosts/desktop/disko.nix208
-rw-r--r--hosts/desktop/home.nix2
-rw-r--r--hosts/pendrive/disko.nix14
-rw-r--r--os/core/bootloader.nix44
-rw-r--r--os/core/networking.nix4
-rw-r--r--os/core/users.nix36
-rw-r--r--os/srv/sops.nix26
-rw-r--r--secrets.yaml9
12 files changed, 304 insertions, 152 deletions
diff --git a/flake.lock b/flake.lock
index 3653450..50e56e5 100644
--- a/flake.lock
+++ b/flake.lock
@@ -136,11 +136,11 @@
]
},
"locked": {
- "lastModified": 1770642890,
- "narHash": "sha256-XWWHZEy5ZYMOx5hVuz+oeKtKDfv7syl7dwKCBx0LqzA=",
+ "lastModified": 1770654520,
+ "narHash": "sha256-mg5WZMIPGsFu9MxSrUcuJUPMbfMsF77el5yb/7rc10k=",
"owner": "nix-community",
"repo": "home-manager",
- "rev": "13a1beb7c9962e0d2ba35a4d5c87546509b89b7d",
+ "rev": "6c4fdbe1ad198fac36c320fd45c5957324a80b8e",
"type": "github"
},
"original": {
@@ -175,11 +175,11 @@
]
},
"locked": {
- "lastModified": 1770595508,
- "narHash": "sha256-d81J55C/ctzfofd10e4k8Bldm1eXKuVaQAewbZPjHN4=",
+ "lastModified": 1770681890,
+ "narHash": "sha256-ommto8XEvGMYGuvrIjj2VM1tFZkRoLLmSuie+fvTTOk=",
"owner": "nix-community",
"repo": "neovim-nightly-overlay",
- "rev": "58b19445f29efe3b94db874fc64407099de0f0f7",
+ "rev": "3560c52c15aad8fccd4f62ae794b622969050202",
"type": "github"
},
"original": {
@@ -191,11 +191,11 @@
"neovim-src": {
"flake": false,
"locked": {
- "lastModified": 1770587030,
- "narHash": "sha256-2CaAx32akEOjUwkKnkvMWsHLhMvoIZ/SsV4ByiEIxfg=",
+ "lastModified": 1770678367,
+ "narHash": "sha256-suvGeMX6UQdyGuSNRLH4zJ25b72XfQBDva7Fxm+PNiA=",
"owner": "neovim",
"repo": "neovim",
- "rev": "19379d1255554041eb6d67423cfa83ca23e5be42",
+ "rev": "57fc77ed29ad9005d893a9dc2f37b3ad53aec4e6",
"type": "github"
},
"original": {
@@ -216,11 +216,11 @@
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
},
"locked": {
- "lastModified": 1770620836,
- "narHash": "sha256-HPoMvo/EqIr6xDDRlk6DGZYdu1Hte7lGLZaGZ5017Uc=",
+ "lastModified": 1770739738,
+ "narHash": "sha256-sLpvik461SjSY1b23gHhNbM9aMJF9iU4h2vPepi9JoM=",
"owner": "sodiboo",
"repo": "niri-flake",
- "rev": "ff1edce403a67cfac7bf1038d348f2ef457ac691",
+ "rev": "9e23010320cfe4012adc2d8810495bad0fe2d4a6",
"type": "github"
},
"original": {
@@ -249,11 +249,11 @@
"niri-unstable": {
"flake": false,
"locked": {
- "lastModified": 1770394959,
- "narHash": "sha256-if7bIsomdceIufOhkFwN74rFY/pLCWPynRxGyol2viQ=",
+ "lastModified": 1770735554,
+ "narHash": "sha256-8GzUa8bCyQ688jYW2waXrOqetTr7oV8UPTO2He+5Hsg=",
"owner": "YaLTeR",
"repo": "niri",
- "rev": "ab47f5cec4c1c5758afeb91c0c98554ffd3433db",
+ "rev": "41b5de87692b8262fbdbff7faab93f04ff0be453",
"type": "github"
},
"original": {
@@ -271,11 +271,11 @@
]
},
"locked": {
- "lastModified": 1770425102,
- "narHash": "sha256-36XIjxE4YA+dg/ylzC6IfdxTtRizkysXsAh433EaPns=",
+ "lastModified": 1770711111,
+ "narHash": "sha256-fwqwewKc+TGDz593PzfA3YCzZRYdmYDWk6pRTaRNPWg=",
"owner": "KaylorBen",
"repo": "nixcord",
- "rev": "d1880604a496708083964693d4ddc3783f81645b",
+ "rev": "b3f36f48d83a78653b86b4fe997ff1fccae38c6d",
"type": "github"
},
"original": {
@@ -317,11 +317,11 @@
},
"nixpkgs-stable": {
"locked": {
- "lastModified": 1770464364,
- "narHash": "sha256-z5NJPSBwsLf/OfD8WTmh79tlSU8XgIbwmk6qB1/TFzY=",
+ "lastModified": 1770617025,
+ "narHash": "sha256-1jZvgZoAagZZB6NwGRv2T2ezPy+X6EFDsJm+YSlsvEs=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "23d72dabcb3b12469f57b37170fcbc1789bd7457",
+ "rev": "2db38e08fdadcc0ce3232f7279bab59a15b94482",
"type": "github"
},
"original": {
@@ -453,11 +453,11 @@
]
},
"locked": {
- "lastModified": 1770526836,
- "narHash": "sha256-xbvX5Ik+0inJcLJtJ/AajAt7xCk6FOCrm5ogpwwvVDg=",
+ "lastModified": 1770683991,
+ "narHash": "sha256-xVfPvXDf9QN3Eh9dV+Lw6IkWG42KSuQ1u2260HKvpnc=",
"owner": "Mic92",
"repo": "sops-nix",
- "rev": "d6e0e666048a5395d6ea4283143b7c9ac704720d",
+ "rev": "8b89f44c2cc4581e402111d928869fe7ba9f7033",
"type": "github"
},
"original": {
@@ -540,11 +540,11 @@
]
},
"locked": {
- "lastModified": 1770581246,
- "narHash": "sha256-ywcaEOxk8trJNES7gKx6bWXgACp1iz7FY1Pnsdmt1fE=",
+ "lastModified": 1770731745,
+ "narHash": "sha256-GDl0P8Gc/uvDnT/0yGOalpWa4MGuSmBiGpiQNPlznFA=",
"owner": "Alexays",
"repo": "Waybar",
- "rev": "306f9706844d2e25c89b1338d12983600f416447",
+ "rev": "d527ccd4c1f53f4bb161677b451aabb89556f2d5",
"type": "github"
},
"original": {
@@ -595,11 +595,11 @@
"rust-overlay": "rust-overlay_2"
},
"locked": {
- "lastModified": 1770598201,
- "narHash": "sha256-7E8l+muffPFzlKzRR7YYFlVEjgfgV/d7EfMfeDuXeh0=",
+ "lastModified": 1770694186,
+ "narHash": "sha256-z4kRmmOkCMTF6dk9Id5tnuBEZ+cI7wcGfAGThMShSIc=",
"owner": "sxyazi",
"repo": "yazi",
- "rev": "1a121bbfb0fa024741c07535d23303415f459944",
+ "rev": "30ec603441733a19510a0d7d9ab8698fe6ff0844",
"type": "github"
},
"original": {
diff --git a/hm/conf/git.nix b/hm/conf/git.nix
index 09bd9e1..b297153 100644
--- a/hm/conf/git.nix
+++ b/hm/conf/git.nix
@@ -10,7 +10,7 @@ in
lfs.enable = true;
settings = {
user.name = "adikro";
- user.email = "/run/secrets/git/email";
+ user.email = "adikro@disroot.org";
init.defaultBranch = "main";
};
};
diff --git a/hm/soft/email.nix b/hm/soft/email.nix
index d60f802..869c4ed 100644
--- a/hm/soft/email.nix
+++ b/hm/soft/email.nix
@@ -1,4 +1,9 @@
-{ config, lib, pkgs, ... }:
+{
+ config,
+ lib,
+ pkgs,
+ ...
+}:
let
cfg = config.hm.soft.email;
in
@@ -8,8 +13,37 @@ in
evolution.enable = lib.mkEnableOption "evolution config";
};
config = lib.mkMerge [
+ {
+ accounts.email.accounts.disroot = {
+ primary = true;
+ address = "adikro@disroot.org";
+ userName = "adikro@disroot.org";
+ realName = "adi";
+
+ imap = {
+ host = "disroot.org";
+ port = 993;
+ tls.enable = true;
+ };
+ smtp = {
+ host = "disroot.org";
+ port = 465;
+ tls.enable = true;
+ };
+
+ thunderbird.enable = cfg.thunderbird.enable;
+ };
+ }
(lib.mkIf cfg.thunderbird.enable {
- programs.thunderbird.enable = true;
+ programs.thunderbird = {
+ enable = true;
+ profiles.main = {
+ isDefault = true;
+ settings = {
+ "network.proxy.type" = 0;
+ };
+ };
+ };
})
(lib.mkIf cfg.evolution.enable {
diff --git a/hm/soft/nixcord.nix b/hm/soft/nixcord.nix
index e1345b2..52f6cd3 100644
--- a/hm/soft/nixcord.nix
+++ b/hm/soft/nixcord.nix
@@ -2,7 +2,6 @@
inputs,
config,
lib,
- pkgs,
...
}:
let
@@ -13,9 +12,6 @@ in
options.hm.soft.nixcord.enable = lib.mkEnableOption "nixcord configuration";
config = lib.mkIf cfg.enable {
- home.packages = with pkgs; [
- equibop
- ];
programs.nixcord = {
enable = true;
discord = {
@@ -25,11 +21,12 @@ in
vencord.enable = false;
equicord.enable = true;
};
- # equibop = {
- # enable = true;
- # autoscroll.enable = true;
- # };
+ equibop = {
+ enable = true;
+ autoscroll.enable = true;
+ };
config = {
+ themeLinks = [ "https://raw.codeberg.page/AllPurposeMat/Disblock-Origin/DisblockOrigin.theme.css" ];
frameless = true;
plugins = {
ClearURLs.enable = true;
diff --git a/hosts/desktop/disko.nix b/hosts/desktop/disko.nix
index edc4008..78eb6a0 100644
--- a/hosts/desktop/disko.nix
+++ b/hosts/desktop/disko.nix
@@ -17,43 +17,92 @@
mountOptions = [ "umask=0077" ];
};
};
- root = {
+ luks = {
size = "100%";
content = {
- type = "btrfs";
- extraArgs = [ "-f" ];
- subvolumes = {
- "@" = {
- mountpoint = "/";
- mountOptions = [ "compress=zstd:1" "noatime" ];
- };
- "@home" = {
- mountpoint = "/home";
- mountOptions = [ "compress=zstd:1" "noatime" ];
- };
- "@nix" = {
- mountpoint = "/nix";
- mountOptions = [ "compress=zstd:1" "noatime" ];
- };
- "@log" = {
- mountpoint = "/var/log";
- mountOptions = [ "compress=zstd:1" "noatime" ];
- };
- "@games" = {
- mountpoint = "/games";
- mountOptions = [ "compress=zstd:1" "noatime" ];
- };
- "@llms" = {
- mountpoint = "/llms";
- mountOptions = [ "nodatacow" "noatime"];
- };
- "@vms" = {
- mountpoint = "/vms";
- mountOptions = [ "nodatacow" "noatime" ];
- };
- "@swap" = {
- mountpoint = "/.swapvol";
- mountOptions = [ "nodatacow" "noatime" ];
+ type = "luks";
+ name = "crypted_main";
+ settings.allowDiscards = true;
+ content = {
+ type = "btrfs";
+ extraArgs = [ "-f" ];
+ subvolumes = {
+ "root" = {
+ mountpoint = "/";
+ mountOptions = [
+ "compress=zstd:1"
+ "noatime"
+ "discard=async"
+ ];
+ };
+ "nix" = {
+ mountpoint = "/nix";
+ mountOptions = [
+ "compress=zstd:1"
+ "noatime"
+ "discard=async"
+ ];
+ };
+ "home" = {
+ mountpoint = "/home";
+ mountOptions = [
+ "compress=zstd:1"
+ "noatime"
+ "nosuid"
+ "nodev"
+ "discard=async"
+ ];
+ };
+ "log" = {
+ mountpoint = "/var/log";
+ mountOptions = [
+ "compress=zstd:1"
+ "noatime"
+ "nosuid"
+ "nodev"
+ "discard=async"
+ ];
+ };
+ "games" = {
+ mountpoint = "/games";
+ mountOptions = [
+ "compress=zstd:1"
+ "noatime"
+ "nosuid"
+ "nodev"
+ "discard=async"
+ ];
+ };
+ "llms" = {
+ mountpoint = "/llms";
+ mountOptions = [
+ "nodatacow"
+ "compress=none"
+ "noatime"
+ "nosuid"
+ "nodev"
+ "discard=async"
+ ];
+ };
+ "vms" = {
+ mountpoint = "/vms";
+ mountOptions = [
+ "nodatacow"
+ "compress=none"
+ "noatime"
+ "nosuid"
+ "nodev"
+ "discard=async"
+ ];
+ };
+ "swap" = {
+ mountpoint = "/.swapvol";
+ mountOptions = [
+ "nodatacow"
+ "noatime"
+ "discard=async"
+ ];
+ };
};
};
};
@@ -61,37 +110,78 @@
};
};
};
- media = {
+ storage = {
type = "disk";
device = "/dev/sda";
content = {
type = "gpt";
partitions = {
- media = {
+ luks = {
size = "100%";
content = {
- type = "btrfs";
- extraArgs = [ "-f" ];
- subvolumes = {
- "@archive" = {
- mountpoint = "/media/archive";
- mountOptions = [ "compress=zstd:1" "autodefrag" "noatime" ];
- };
- "@movies" = {
- mountpoint = "/media/movies";
- mountOptions = [ "autodefrag" "noatime" ];
- };
- "@anime" = {
- mountpoint = "/media/anime";
- mountOptions = [ "autodefrag" "noatime" ];
- };
- "@pictures" = {
- mountpoint = "/media/pics";
- mountOptions = [ "autodefrag" "noatime" ];
- };
- "@videos" = {
- mountpoint = "/media/vids";
- mountOptions = [ "autodefrag" "noatime" ];
+ type = "luks";
+ name = "crypted_storage";
+ keyFile = "/tmp/storage.key";
+ content = {
+ type = "btrfs";
+ extraArgs = [ "-f" ];
+ subvolumes = {
+ "archive" = {
+ mountpoint = "/storage/archive";
+ mountOptions = [
+ "compress=zstd:1"
+ "autodefrag"
+ "noatime"
+ "nofail"
+ "nosuid"
+ "nodev"
+ "x-systemd.device-timeout=5s"
+ ];
+ };
+ "movies" = {
+ mountpoint = "/storage/movies";
+ mountOptions = [
+ "autodefrag"
+ "noatime"
+ "nofail"
+ "nosuid"
+ "nodev"
+ "x-systemd.device-timeout=5s"
+ ];
+ };
+ "anime" = {
+ mountpoint = "/storage/anime";
+ mountOptions = [
+ "autodefrag"
+ "noatime"
+ "nofail"
+ "nosuid"
+ "nodev"
+ "x-systemd.device-timeout=5s"
+ ];
+ };
+ "pictures" = {
+ mountpoint = "/storage/pics";
+ mountOptions = [
+ "autodefrag"
+ "noatime"
+ "nofail"
+ "nosuid"
+ "nodev"
+ "x-systemd.device-timeout=5s"
+ ];
+ };
+ "videos" = {
+ mountpoint = "/storage/vids";
+ mountOptions = [
+ "autodefrag"
+ "noatime"
+ "nofail"
+ "nosuid"
+ "nodev"
+ "x-systemd.device-timeout=5s"
+ ];
+ };
};
};
};
diff --git a/hosts/desktop/home.nix b/hosts/desktop/home.nix
index 5eb1635..ba5777a 100644
--- a/hosts/desktop/home.nix
+++ b/hosts/desktop/home.nix
@@ -51,7 +51,7 @@
librewolf.enable = true;
brave.enable = true;
};
- email.evolution.enable = true;
+ email.thunderbird.enable = true;
media.enable = true;
mpv.enable = true;
nixcord.enable = true;
diff --git a/hosts/pendrive/disko.nix b/hosts/pendrive/disko.nix
index 24674b7..cc9dede 100644
--- a/hosts/pendrive/disko.nix
+++ b/hosts/pendrive/disko.nix
@@ -22,42 +22,40 @@
content = {
type = "luks";
name = "crypted";
- settings = {
- allowDiscards = true;
- };
+ settings.allowDiscards = true;
content = {
type = "btrfs";
extraArgs = [ "-f" ];
subvolumes = {
- "@" = {
+ "root" = {
mountpoint = "/";
mountOptions = [
"compress=zstd:1"
"noatime"
];
};
- "@home" = {
+ "home" = {
mountpoint = "/home";
mountOptions = [
"compress=zstd:1"
"noatime"
];
};
- "@nix" = {
+ "nix" = {
mountpoint = "/nix";
mountOptions = [
"compress=zstd:1"
"noatime"
];
};
- "@log" = {
+ "log" = {
mountpoint = "/var/log";
mountOptions = [
"compress=zstd:1"
"noatime"
];
};
- "@swap" = {
+ "swap" = {
mountpoint = "/.swapvol";
mountOptions = [
"nodatacow"
diff --git a/os/core/bootloader.nix b/os/core/bootloader.nix
index f0aacc0..52761f1 100644
--- a/os/core/bootloader.nix
+++ b/os/core/bootloader.nix
@@ -2,12 +2,18 @@
config,
lib,
...
-}: let
+}:
+let
cfg = config.os.core.bootloader;
-in {
+in
+{
options.os.core.bootloader = {
type = lib.mkOption {
- type = lib.types.enum ["systemd-boot" "grub" "none"];
+ type = lib.types.enum [
+ "systemd-boot"
+ "grub"
+ "none"
+ ];
default = "systemd-boot";
description = "which bootloader to use";
};
@@ -35,13 +41,25 @@ in {
config = lib.mkMerge [
{
boot = {
- supportedFilesystems = ["ntfs" "btrfs"];
- kernelParams = ["quiet" "splash"];
- initrd.luks.devices = lib.mkIf (cfg.enableEncryption && cfg.luksDevice != null) {
- "crypted" = {
- device = cfg.luksDevice;
- preLVM = true;
- allowDiscards = true;
+ supportedFilesystems = [
+ "ntfs"
+ "btrfs"
+ ];
+ kernelParams = [
+ "quiet"
+ "splash"
+ ];
+ initrd = {
+ availableKernelModules = [
+ "aesni_intel"
+ "cryptd"
+ ];
+ luks.devices = lib.mkIf (cfg.enableEncryption && cfg.luksDevice != null) {
+ "crypted" = {
+ device = cfg.luksDevice;
+ preLVM = true;
+ allowDiscards = true;
+ };
};
};
};
@@ -57,6 +75,7 @@ in {
systemd-boot = {
enable = true;
editor = false;
+ consoleMode = "max";
};
};
};
@@ -72,10 +91,7 @@ in {
useOSProber = cfg.useOSProber;
enableCryptodisk = cfg.enableEncryption;
- default =
- if cfg.useOSProber
- then 2
- else 0;
+ default = if cfg.useOSProber then 2 else 0;
efiSupport = lib.mkDefault (cfg.grubDevice == "nodev");
copyKernels = lib.mkIf cfg.enableEncryption true;
diff --git a/os/core/networking.nix b/os/core/networking.nix
index bf611a3..830f475 100644
--- a/os/core/networking.nix
+++ b/os/core/networking.nix
@@ -13,8 +13,8 @@ in
};
firewall = {
enable = true;
- allowedTCPPorts = [ 7960 ];
- allowedUDPPorts = [ 7960 ];
+ allowedTCPPorts = [ ];
+ allowedUDPPorts = [ ];
};
};
systemd.services."NetworkManager-wait-online".enable = false;
diff --git a/os/core/users.nix b/os/core/users.nix
index 74a8fc4..03eff8a 100644
--- a/os/core/users.nix
+++ b/os/core/users.nix
@@ -12,21 +12,29 @@ in
options.os.core.users.enable = lib.mkEnableOption "enables user accounts";
config = lib.mkIf cfg.enable {
programs.fish.enable = true;
- users.users.${username} = {
- isNormalUser = true;
- shell = pkgs.fish;
- extraGroups = lib.mkMerge [
- [ "wheel" ]
+ users = {
+ mutableUsers = false;
- (lib.mkIf (config.os.core.drivers.amd.enable or false) [
- "video"
- "render"
- ])
- (lib.mkIf (config.os.core.network.enable or false) [ "networkmanager" ])
- (lib.mkIf (config.os.srv.virtualization.enable or false) [ "libvirtd" ])
- (lib.mkIf (config.os.srv.docker.enable or false) [ "docker" ])
- (lib.mkIf (config.os.srv.autoclicker.enable or false) [ "input" ])
- ];
+ users = {
+ "${username}" = {
+ isNormalUser = true;
+ hashedPasswordFile = config.sops.secrets.user_password.path;
+ shell = pkgs.fish;
+ extraGroups = lib.mkMerge [
+ [ "wheel" ]
+
+ (lib.mkIf (config.os.core.drivers.amd.enable or false) [
+ "video"
+ "render"
+ ])
+ (lib.mkIf (config.os.core.network.enable or false) [ "networkmanager" ])
+ (lib.mkIf (config.os.srv.virtualization.enable or false) [ "libvirtd" ])
+ (lib.mkIf (config.os.srv.docker.enable or false) [ "docker" ])
+ (lib.mkIf (config.os.srv.autoclicker.enable or false) [ "input" ])
+ ];
+ };
+ root.hashedPasswordFile = config.sops.secrets.root_password.path;
+ };
};
};
}
diff --git a/os/srv/sops.nix b/os/srv/sops.nix
index 0d0c7bf..67cf8f7 100644
--- a/os/srv/sops.nix
+++ b/os/srv/sops.nix
@@ -1,6 +1,7 @@
{
config,
lib,
+ pkgs,
username,
...
}:
@@ -16,16 +17,23 @@ in
age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
secrets = {
- "syncthing/gui_password" = {
- owner = username;
- };
- "obs/websocket_password" = {
- owner = username;
- };
- "git/email" = {
- owner = username;
- };
+ "syncthing/gui_password".owner = username;
+ "obs/websocket_password".owner = username;
+ root_password.neededForUsers = true;
+ user_password.neededForUsers = true;
+ storage_key = { };
};
};
+
+ boot.initrd.secrets = {
+ "/tmp/storage.key" = config.sops.secrets.storage_key.path;
+ };
+
+ environment.systemPackages = with pkgs; [
+ sops
+ age
+ ssh-to-age
+ gnupg
+ ];
};
}
diff --git a/secrets.yaml b/secrets.yaml
index 913a731..5b2db9c 100644
--- a/secrets.yaml
+++ b/secrets.yaml
@@ -1,9 +1,10 @@
+user_password: ENC[AES256_GCM,data:lPSKNpHWQYQZvLFmK1NIqvcDTsXWe8lMnBuqATtkyQjjswFrBjreM5hp1l360VByGOupzG5c2Fz9W1ZCC/eYRrmbldJcSiMdYw==,iv:A6If6CSWoRNGR/CV/QBt8UH1N9BKp9xEnOOMcrSAET4=,tag:Ommq47gaEm86/ByCV1dlBA==,type:str]
+root_password: ENC[AES256_GCM,data:F2M3P5JTpP9bnO494jnLA/Hs2ndQRYhgN9Z9LiEgTYYQPvMdi0DGI5dN6rh+5Dhm0a9eqGSOpU+4rWYX6cXOp+Um2exKr0O8YQ==,iv:WZtTsAMhg+qzE66/v2DUsG50Voc3vJF+1X19LNNsG3Q=,tag:cpQu7W/SMfilYxnbsgi/RQ==,type:str]
+storage_key: ENC[AES256_GCM,data:GuprvpeHvlcEHtTzt0vrUfCApMQU/DOHSkdNB7nvFm6tFGatCRZdeT5aEJ00mMDhCZidm2SF3hRpv4P9ErLhLEIDCyQPQsA417ojgCvObTXXftWxLalCo/ZwME0rUG1/Amco04dL8sT8mvxE3TIImvFVJRuK3DwMWUG7Y27rGX8QglHKbumSkQtzjs6G2fDkUSebV7kPvvvLtvKlDYswZEnuQ3bBIFN0ZJvewAhOh/GoSq9RKmvNVgGj7VPqG2oFQ0t7pxlb9HLutC+PNQnw3u8iKDtOazCHiVEX4Q5RoxYsUCqrQtEWSNOKgpdRhNMWpe4SNk6KCcZ9KE4Sx6V26EXCTqnZbxQ/XGMTYkTbEWJPgqi8Oc6hluuelN36qd3D6zrARmMoyMTdvr9Ig8Kzxtlq1KAA8H+BEvvNvCXFIumB2FX7qAywNurV68UAH5+uSJBsgPBFEisi7cVHCJtMAUuRc3KnFjEbXC5HgNZd4fKynk4dSdAzuZRcB3+xKpHEDFEy2RMfG7GShKmXyRV7VwSz5Suu9c9UKmgyZ2lQqLaAufdwneIMROAYx603h/Tfx8aO7gjGrUqvFB1ACLiS+1f6QRxGRNxLD7x92xheXZnIbKWjKUC6y6vQI5S36NN6720zcQZFBmDlLPG7WNhI6idcqrTn473zaYOdm6zlCWbmOqzmoz/0EVmwnsVifKjrWHne02l41ywnP99OoPCy3X0dL4HOXkkxJnxAQljmnqm/DAv3Fg9ZglEBKzEBNUPfy42Wf0cLQCb4SZt+5ztrzFq8o+AkAiH5tSXFN/LPUz4GZN2cc12Gad4LDrVwGSvcntP79hAudnohQeqAG49HCE5cCBd1L4CNDCnp6Skpi9eUczjt6JHBrwME2nQIBgZaUqXHvh6hTc3/Y7lx,iv:Ng9EN8ykjB9ew4v9slmVe02MZOkvuoLonbgqU6RdI60=,tag:a/nGLG1NmooeI1yKBiOZrg==,type:str]
syncthing:
gui_password: ENC[AES256_GCM,data:9sivtxELQRCD+q1OFMmL9OwMnem22VxFRN9twVdnMlTMmtxplO/KmezuLt+SUpfhDne0i9cTliiqCm16bQb3fFQWplJIyQDRgIGr1Y7r4boGtvJ95oSIW3bmwJW+IkYyYysKbcNrTGfdWVS6lJWYfenhonNfWESxqo1CW81BxBY=,iv:tYxoE/pxBBFrbiuc3ZVJe9rZfnVo9QSJOtl1NlPHyNg=,tag:eUwgow5ZkkuMoXrUAZughg==,type:str]
obs:
websocket_password: ENC[AES256_GCM,data:eska/qJsOAiQpq3uHNIIHKobsdN2rnkfLznOMkVHWEmOiynBM5tl,iv:y6cwkZUPiBU671QFq/xEKQATWI9BYAvNRbgiGTF/550=,tag:b5G4PNFl1bmVmHjC7cwvHw==,type:str]
-git:
- email: ENC[AES256_GCM,data:yvu1D9hNQHzQrTVmZmzZ500i,iv:6DbURT2HW5CT+fmsxZU0NWHRnqdOogHNL8ewD0UtfPA=,tag:VTi/8YyC+3zefI8UnRFoAw==,type:str]
sops:
age:
- recipient: age1s39d4mdrjhkf8cy8eea02p836r7s875fj8f7w3z4ld2stmaac49qd075ww
@@ -24,8 +25,8 @@ sops:
b3E5bmZpN0tUclZjck4wUjFBUklOelkKf3v/9uVOgDp7olWyV50PMISVq8Ixf4+S
vLuXJ0kMeTuiW5CweAW9HiD01nwC+aRZaPn5JCLMoxWy/VVgMNNx1g==
-----END AGE ENCRYPTED FILE-----
- lastmodified: "2026-02-08T17:12:36Z"
- mac: ENC[AES256_GCM,data:h/XWYq9wZeaFbulD1y/SUTqSSu8RnOJ0vrlXMq4d0FzdEElsddZGF4+tL2ZDWMh1u69vUU/yKbVOf02NqA5zhbWwuMB4IJfP7x42iakuvG1o5yQAXJYSI/hhwGHIw00U7ek6UcxY+j5U/52PANMA499zGJjU5u+HP89q71bL7NQ=,iv:LtRc1zIu+5iZhXvjLuuOpoE0seEGaPe1n+hYpxeZfyg=,tag:V3Chh4howYQ6FSPWlPVLsQ==,type:str]
+ lastmodified: "2026-02-10T21:12:45Z"
+ mac: ENC[AES256_GCM,data:BqKVfu9u/tjELHkoWs2d/FKRgHp0trWJq/nZdunasotsMyxHO0AI5EtIMnRGnkBB+HTHnnIASYo+0ZymyG7z6satKnz1jKNA3vHLweWASSPOWzN3mgtkGKOJPDgYIHbes4Rb/GXpcUgVtmBRHFbIwF1FNYo7EK1YN2EKgTKkXxI=,iv:IGcWyftYTYKrgqf3LOGfBnoPLuOWgJK4q6/0aAvE3Dg=,tag:OdWdG/VrKCH9cCBkpiAe2w==,type:str]
pgp:
- created_at: "2026-02-09T13:58:02Z"
enc: |-