infrastructure/hosts/phoenix.lewd.wtf/secrets.nix

25 lines
665 B
Nix

{ config, ... }:
{
sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
# MSMTP
sops.secrets."services/msmtp/password" = {
mode = "0777";
sopsFile = ./secrets/msmtp.yaml;
};
# Wireguard
sops.secrets."services/wireguard/airvpn.private" = {
mode = "0400";
owner = config.users.users.systemd-network.name;
group = config.users.users.systemd-network.group;
sopsFile = ./secrets/wireguard.yaml;
};
sops.secrets."services/wireguard/airvpn.psk" = {
mode = "0400";
owner = config.users.users.systemd-network.name;
group = config.users.users.systemd-network.group;
sopsFile = ./secrets/wireguard.yaml;
};
}