{ config, lib, pkgs, inputs, username, ... }: let cfg = config.os.srv.sops; in { imports = [ inputs.sops-nix.nixosModules.sops ]; options.os.srv.sops = { enable = lib.mkEnableOption "enables sops-nix"; diskEncryption = lib.mkEnableOption "enables initrd decryption key (LUKS)"; }; config = lib.mkIf cfg.enable { sops = { defaultSopsFile = ../../secrets/common.yaml; defaultSopsFormat = "yaml"; age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; secrets = { "syncthing/gui_password" = { owner = username; sopsFile = ../../secrets/oci.yaml; }; "obs/websocket_password".owner = username; root_password.neededForUsers = true; user_password.neededForUsers = true; oracler_password = { neededForUsers = true; sopsFile = ../../secrets/oci.yaml; }; }; }; environment.systemPackages = with pkgs; [ sops age ssh-to-age gnupg ]; }; }