From 22bc3e753aad927f43696e25229bbd317aceb310 Mon Sep 17 00:00:00 2001 From: materus Date: Sat, 30 Mar 2024 19:22:46 +0100 Subject: [PATCH] Old-materusPC: init secrets --- .../host/Old-materusPC/secrets/default.nix | 25 +++++++++++++ .../Old-materusPC/secrets/private/default.nix | Bin 0 -> 79 bytes .../host/Old-materusPC/secrets/secrets.yaml | 33 ++++++++++++++++++ 3 files changed, 58 insertions(+) create mode 100644 configurations/host/Old-materusPC/secrets/default.nix create mode 100644 configurations/host/Old-materusPC/secrets/private/default.nix create mode 100644 configurations/host/Old-materusPC/secrets/secrets.yaml diff --git a/configurations/host/Old-materusPC/secrets/default.nix b/configurations/host/Old-materusPC/secrets/default.nix new file mode 100644 index 0000000..6820d84 --- /dev/null +++ b/configurations/host/Old-materusPC/secrets/default.nix @@ -0,0 +1,25 @@ +{ config, pkgs, lib, materusCfg, ... }: +{ + imports = + [ + + ] ++ (if (materusCfg.materusFlake.decrypted) then [ ./private ] else [ ]); + + sops.age.generateKey = false; + sops.gnupg.home = null; + sops.gnupg.sshKeyPaths = [ ]; + sops.defaultSopsFile = materusCfg.hostPath + "/secrets/secrets.yaml"; + + services.openssh.hostKeys = [ + { + bits = 4096; + path = "/materus/root/ssh_host_rsa_key"; + type = "rsa"; + } + { + path = "/materus/root/ssh_host_ed25519_key"; + type = "ed25519"; + } + ]; + +} diff --git a/configurations/host/Old-materusPC/secrets/private/default.nix b/configurations/host/Old-materusPC/secrets/private/default.nix new file mode 100644 index 0000000000000000000000000000000000000000..19144af8d695f618e26fe46259415d2db85a2ca3 GIT binary patch literal 79 zcmV-V0I>f6M@dveQdv+`0HRxLm!-w#=8*s