Files
spacestation/secrets.nix

77 lines
1.5 KiB
Nix
Raw Normal View History

{
config,
inputs,
lib,
pkgs,
...
2025-09-13 11:29:15 -03:00
}:
with lib; {
imports = [
inputs.sops-nix.nixosModules.sops
];
2025-09-13 11:29:15 -03:00
environment.systemPackages = with pkgs; [
sops
];
2025-09-13 11:29:15 -03:00
sops.defaultSopsFile = ./secrets.yaml;
sops.defaultSopsFormat = "yaml";
sops.secrets =
concatMapAttrs (owner: secrets:
listToAttrs (map (s: {
name = s;
value = optionalAttrs (owner != "") {inherit owner;};
})
secrets))
{
"" = [
# Cloudflared
"cloudflared/tunnel_env"
];
2025-04-01 10:07:35 -03:00
# Anubis
${config.services.anubis.defaultOptions.user} = [
"anubis/forgejo/hex_file"
"anubis/medama/hex_file"
];
2025-04-05 17:22:44 -03:00
# Forgejo
${config.services.forgejo.user} = [
"forgejo/actions/token"
"forgejo/git_password"
"forgejo/s3/key"
"forgejo/s3/secret"
];
# Garage
"garage" = [
"garage/admin_key"
"garage/admin_secret"
"garage/admin_token"
"garage/metrics_token"
"garage/rpc_secret"
];
# keikos.work
${config.services.keikos.web.user} = [
"keiko/env_file"
];
2025-09-16 16:18:06 -03:00
# Nextcloud
${config.services.phpfpm.pools.nextcloud.user} = [
"nextcloud/adminpass"
"nextcloud/s3/secret"
"nextcloud/s3/sseC"
];
2025-09-16 16:18:06 -03:00
# Users
${config.users.users."guz".name} = [
"guz/password"
];
2025-09-13 11:29:15 -03:00
};
sops.age.keyFile = "/home/guz/.config/sops/age/keys.txt";
}