{ config, lib, pkgs, inputs, username, ... }: let cfg = config.os.srv.sops; in { imports = [ inputs.sops-nix.nixosModules.sops ]; options.os.srv.sops.enable = lib.mkEnableOption "enables sops-nix secret storing"; config = lib.mkIf cfg.enable { sops = { defaultSopsFile = ../../secrets/secrets.yaml; defaultSopsFormat = "yaml"; age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; secrets = { "syncthing/gui_password".owner = username; "obs/websocket_password".owner = username; root_password.neededForUsers = true; user_password.neededForUsers = true; crypt_key = { }; }; }; boot.initrd.secrets = { "/tmp/crypt.key" = config.sops.secrets.crypt_key.path; }; environment.systemPackages = with pkgs; [ sops age ssh-to-age gnupg ]; }; }