diff options
| author | Devin Finlinson <devin.finlinson@pm.me> | 2026-09-04 03:59:02 -0600 |
|---|---|---|
| committer | Devin Finlinson <devin.finlinson@pm.me> | 2026-09-04 03:59:02 -0600 |
| commit | 031b8a7f09b59055959284e5d6317400884ad15e (patch) | |
| tree | 4111341ea5c52639d61808f1beb842a19218943b /modules | |
| parent | 32d4405ee1e75ae1e2b84e191981cedbdfa9a683 (diff) | |
trying out sops-nix for secrets management
documented here: https://github.com/Mic92/sops-nix?tab=readme-ov-file
Diffstat (limited to 'modules')
| -rw-r--r-- | modules/nixos/sops.nix | 15 | ||||
| -rw-r--r-- | modules/nixos/system-packages.nix | 2 |
2 files changed, 17 insertions, 0 deletions
diff --git a/modules/nixos/sops.nix b/modules/nixos/sops.nix new file mode 100644 index 0000000..41e828e --- /dev/null +++ b/modules/nixos/sops.nix @@ -0,0 +1,15 @@ +{config, ... }: { + # This will add secrets.yml to the nix store + # You can avoid this by adding a string to the full path instead, i.e. + # sops.defaultSopsFile = "/root/.sops/secrets/example.yaml"; + sops.defaultSopsFile = ../../secrets/example.yaml; + # This will automatically import SSH keys as age keys + sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; + # This is using an age key that is expected to already be in the filesystem + sops.age.keyFile = "/var/lib/sops-nix/key.txt"; + # This will generate a new key if the key specified above does not exist + sops.age.generateKey = true; + # This is the actual specification of the secrets. + # sops.secrets.example-key = {}; + # sops.secrets.example_array = {}; +} diff --git a/modules/nixos/system-packages.nix b/modules/nixos/system-packages.nix index 6430915..b29388b 100644 --- a/modules/nixos/system-packages.nix +++ b/modules/nixos/system-packages.nix @@ -3,7 +3,9 @@ environment.systemPackages = with pkgs; [ #For root age + sops nix-tree + ssh-to-age nushell bat # helix |
