aboutsummaryrefslogtreecommitdiffstats
path: root/sys/secrets
diff options
context:
space:
mode:
authorSoispha <soispha@vhack.eu>2023-10-08 11:37:58 +0200
committerSoispha <soispha@vhack.eu>2023-10-08 11:37:58 +0200
commit0cb2eabde45f0f2644b96f2f93362278449629b3 (patch)
treea23a46f2e0eb2f391a964bb171556575397403cf /sys/secrets
parentfix(hm/conf/nvim/autocmds): Use 'desc' instead of 'description' (diff)
downloadnixos-config-0cb2eabde45f0f2644b96f2f93362278449629b3.zip
fix(sys/secrets): Rename 'name' to 'hostName'
Diffstat (limited to 'sys/secrets')
-rw-r--r--sys/secrets/default.nix92
1 files changed, 52 insertions, 40 deletions
diff --git a/sys/secrets/default.nix b/sys/secrets/default.nix
index 754d901f..b7387b8b 100644
--- a/sys/secrets/default.nix
+++ b/sys/secrets/default.nix
@@ -3,49 +3,61 @@
lib,
...
}: let
- name = config.networking.hostName;
+ inherit (config.networking) hostName;
+
+ # mkFakeSecret = secretName: {
+ # name = secretName;
+ # value = {
+ # path = "/dev/null";
+ # };
+ # };
+ # fakeSecrets =
+ # builtins.listToAttrs (lib.debug.traceValSeqN 2 (builtins.map mkFakeSecret
+ # (lib.debug.traceValSeqN 2 (builtins.attrNames secrets))));
in {
- config = lib.mkIf config.soispha.secrets.enable {
- age = {
- secrets = {
- nheko = {
- file = ./nheko/conf. + name;
- mode = "700";
- owner = "soispha";
- group = "users";
- };
- serverphoneCa = {
- file = ./serverphone/ca.key;
- mode = "700";
- owner = "serverphone";
- group = "serverphone";
- };
- serverphoneServer = {
- file = ./serverphone/server.key;
- mode = "700";
- owner = "serverphone";
- group = "serverphone";
- };
+ config =
+ lib.mkIf config.soispha.secrets.enable
+ {
+ age = {
+ secrets = {
+ nheko = {
+ file = ./nheko/conf. + hostName;
+ mode = "700";
+ owner = "soispha";
+ group = "users";
+ };
+ serverphoneCa = {
+ file = ./serverphone/ca.key;
+ mode = "700";
+ owner = "serverphone";
+ group = "serverphone";
+ };
+ serverphoneServer = {
+ file = ./serverphone/server.key;
+ mode = "700";
+ owner = "serverphone";
+ group = "serverphone";
+ };
- taskserverPrivate = {
- file = ./taskserver/private.key;
- mode = "700";
- owner = "soispha";
- group = "users";
- };
- taskserverPublic = {
- file = ./taskserver/public.cert;
- mode = "700";
- owner = "soispha";
- group = "users";
- };
- taskserverCA = {
- file = ./taskserver/ca.cert;
- mode = "700";
- owner = "soispha";
- group = "users";
+ taskserverPrivate = {
+ file = ./taskserver/private.key;
+ mode = "700";
+ owner = "soispha";
+ group = "users";
+ };
+ taskserverPublic = {
+ file = ./taskserver/public.cert;
+ mode = "700";
+ owner = "soispha";
+ group = "users";
+ };
+ taskserverCA = {
+ file = ./taskserver/ca.cert;
+ mode = "700";
+ owner = "soispha";
+ group = "users";
+ };
};
};
};
- };
}