summaryrefslogtreecommitdiff
path: root/os/srv/sops.nix
blob: 3c9f0a90d485b8fa64603ee502ac068a1de07941 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
{
  config,
  lib,
  pkgs,
  inputs,
  username,
  ...
}:
let
  cfg = config.os.srv.sops;
in
{
  imports = [ inputs.sops-nix.nixosModules.sops ];

  options.os.srv.sops.enable = lib.mkEnableOption "enables sops-nix secret storing";
  config = lib.mkIf cfg.enable {
    sops = {
      defaultSopsFile = ../../secrets/secrets.yaml;
      defaultSopsFormat = "yaml";
      age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];

      secrets = {
        "syncthing/gui_password".owner = username;
        "obs/websocket_password".owner = username;
        root_password.neededForUsers = true;
        user_password.neededForUsers = true;
#        crypt_key = { };
      };
    };

#    boot.initrd.secrets = {
#      "/tmp/crypt.key" = config.sops.secrets.crypt_key.path;
#    };

    environment.systemPackages = with pkgs; [
      sops
      age
      ssh-to-age
      gnupg
    ];
  };
}