{ config, lib, pkgs, inputs, username, ... }: let cfg = config.os.srv.sops; in { imports = [ inputs.sops-nix.nixosModules.sops ]; options.os.srv.sops = { enable = lib.mkEnableOption "enables sops-nix"; diskEncryption = lib.mkEnableOption "enables initrd decryption key (LUKS)"; }; config = lib.mkIf cfg.enable { sops = { defaultSopsFile = ../../secrets.yaml; defaultSopsFormat = "yaml"; age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; secrets = { "syncthing/gui_password".owner = username; "syncthing/encryption/game-saves".owner = username; "syncthing/encryption/keepass".owner = username; "syncthing/encryption/sync".owner = username; "vpn/warp_private_key".owner = "root"; "obs/websocket_password".owner = username; "yggdrasil-private-key" = { owner = "root"; group = "wheel"; mode = "0440"; }; root_password.neededForUsers = true; user_password.neededForUsers = true; }; }; environment.systemPackages = with pkgs; [ sops age ssh-to-age ]; }; }