From 031b8a7f09b59055959284e5d6317400884ad15e Mon Sep 17 00:00:00 2001 From: Devin Finlinson Date: Fri, 4 Sep 2026 03:59:02 -0600 Subject: trying out sops-nix for secrets management documented here: https://github.com/Mic92/sops-nix?tab=readme-ov-file --- modules/nixos/sops.nix | 15 +++++++++++++++ 1 file changed, 15 insertions(+) create mode 100644 modules/nixos/sops.nix (limited to 'modules/nixos/sops.nix') diff --git a/modules/nixos/sops.nix b/modules/nixos/sops.nix new file mode 100644 index 0000000..41e828e --- /dev/null +++ b/modules/nixos/sops.nix @@ -0,0 +1,15 @@ +{config, ... }: { + # This will add secrets.yml to the nix store + # You can avoid this by adding a string to the full path instead, i.e. + # sops.defaultSopsFile = "/root/.sops/secrets/example.yaml"; + sops.defaultSopsFile = ../../secrets/example.yaml; + # This will automatically import SSH keys as age keys + sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; + # This is using an age key that is expected to already be in the filesystem + sops.age.keyFile = "/var/lib/sops-nix/key.txt"; + # This will generate a new key if the key specified above does not exist + sops.age.generateKey = true; + # This is the actual specification of the secrets. + # sops.secrets.example-key = {}; + # sops.secrets.example_array = {}; +} -- cgit v1.3.1