{ config, lib, pkgs, inputs, username, ... }: let cfg = config.os.srv.sops; in { imports = [ inputs.sops-nix.nixosModules.sops ]; options.os.srv.sops.enable = lib.mkEnableOption "enables sops-nix"; config = lib.mkIf cfg.enable { sops = { defaultSopsFile = ../../secrets/common.yaml; defaultSopsFormat = "yaml"; age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; secrets = { # "syncthing/gui_password".owner = username; "syncthing/encryption/keepass".owner = username; "syncthing/encryption/sync".owner = username; "obs/websocket_password".owner = username; }; }; environment.systemPackages = with pkgs; [ sops age ssh-to-age ]; }; }