{ config, ... }: { sops.defaultSopsFile = ./secrets/services.yaml; sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; # Vaultwarden sops.secrets."services/vaultwarden/.env" = { mode = "0400"; owner = config.users.users.vaultwarden.name; group = config.users.users.vaultwarden.group; sopsFile = ./secrets/vaultwarden.env; format = "dotenv"; }; }