From 39a2b09c27bb74c9e59d1772764f901e3c8fb9e4 Mon Sep 17 00:00:00 2001 From: adi Date: Wed, 29 Jul 2026 17:09:58 +0200 Subject: revamped flake.nix, removed homelab specific modules --- modules/sops.nix | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 modules/sops.nix (limited to 'modules/sops.nix') diff --git a/modules/sops.nix b/modules/sops.nix new file mode 100644 index 0000000..3ca2d16 --- /dev/null +++ b/modules/sops.nix @@ -0,0 +1,36 @@ +{ + config, + lib, + pkgs, + inputs, + username, + ... +}: +let + cfg = config.os.srv.sops; +in +{ + imports = [ inputs.sops-nix.nixosModules.sops ]; + + options.os.srv.sops.enable = lib.mkEnableOption "enables sops-nix"; + config = lib.mkIf cfg.enable { + sops = { + defaultSopsFile = ../../secrets/common.yaml; + defaultSopsFormat = "yaml"; + age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; + + secrets = { + # "syncthing/gui_password".owner = username; + "syncthing/encryption/keepass".owner = username; + "syncthing/encryption/sync".owner = username; + "obs/websocket_password".owner = username; + }; + }; + + environment.systemPackages = with pkgs; [ + sops + age + ssh-to-age + ]; + }; +} -- cgit v1.3