blob: 20e18911ebb11c907fc032774b7b6101e0851df1 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
|
{
config,
lib,
pkgs,
inputs,
username,
...
}:
let
cfg = config.os.srv.sops;
in
{
imports = [ inputs.sops-nix.nixosModules.sops ];
options.os.srv.sops = {
enable = lib.mkEnableOption "enables sops-nix";
diskEncryption = lib.mkEnableOption "enables initrd decryption key (LUKS)";
};
config = lib.mkIf cfg.enable {
sops = {
defaultSopsFile = ../../secrets.yaml;
defaultSopsFormat = "yaml";
age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
secrets = {
"syncthing/gui_password".owner = username;
"syncthing/encryption/openmw-config".owner = username;
"syncthing/encryption/openmw-mods".owner = username;
"syncthing/encryption/game-saves".owner = username;
"syncthing/encryption/keepass".owner = username;
"syncthing/encryption/sync".owner = username;
"vpn/warp_private_key".owner = "root";
"obs/websocket_password".owner = username;
"yggdrasil-private-key" = {
owner = "root";
group = "wheel";
mode = "0440";
};
root_password.neededForUsers = true;
user_password.neededForUsers = true;
};
};
environment.systemPackages = with pkgs; [
sops
age
ssh-to-age
];
};
}
|