summary refs log tree commit diff
path: root/secrets/keys.nix
diff options
context:
space:
mode:
authorMel <einebeere@gmail.com>2024-12-07 03:24:15 +0100
committerMel <einebeere@gmail.com>2024-12-07 03:41:20 +0100
commit44a4f7c6bac97a3381a2b7de8707cd9389f5460f (patch)
treef31f04984119dbdb6adba41ed8a1ff1303558d27 /secrets/keys.nix
parent8930b867a5bc863cf1362d3d27579e784a4bbe97 (diff)
downloadnetwork-44a4f7c6bac97a3381a2b7de8707cd9389f5460f.tar.zst
network-44a4f7c6bac97a3381a2b7de8707cd9389f5460f.zip
Move secrets and keys into agenix
Signed-off-by: Mel <einebeere@gmail.com>
Diffstat (limited to 'secrets/keys.nix')
-rw-r--r--secrets/keys.nix59
1 files changed, 59 insertions, 0 deletions
diff --git a/secrets/keys.nix b/secrets/keys.nix
new file mode 100644
index 0000000..6f6aa8e
--- /dev/null
+++ b/secrets/keys.nix
@@ -0,0 +1,59 @@
+let
+  machines = {
+    renard = {
+      user = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINs2TTjnQvDNr/S3lPLWYOnZi00YIMrRUDH8cpBz1k1m";
+      system = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ/qDL7+86+0H6NkPs/w4GYiWQwT/4YAx9O2J7sLkKmf";
+    };
+
+    lapin = {
+      user = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIzDyaafULcgTuFca51NNgYAzZ28RFDQwVWavRpnY5c+";
+      system = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGMD/EN9v8YgHOu4YG74Q+xvwjCdxbMIZjnQcUXi0QhZ";
+    };
+
+    corsac = {
+      user = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDlqytVSNMFAfbB+rdiNktv3WYViVBMeK7zUO2Pjfii+";
+      system = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHxghVX0Oq+eHklg/e7s/qhC8CK8PLUgvpLk2G53xEjK";
+    };
+  };
+
+  desktops = {
+    bismuth = {
+      user = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEK96G1n31aJsZOrux3BKM0ztzi/SFAVHn0MsGkPDdqY";
+      system = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEP1Q8/07PD5AXghM7cd9Uf54YY8rkuBHfllr1Kzxh10";
+    };
+
+    graphite = {
+      user = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEDujTul5wWyGnidLnNuJDRze0Up29l2cDpyKdmvW2Ls";
+      system = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHd+EvfxJC1rZbeI6hUq5tPpy8b3Xio02orgMBLwPU2l";
+    };
+
+    # this one is just a phone :3
+    anise = {
+      user = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMkdZb6fmfj8fHQUCigTz1x503nRqyokhxYC4RrgA3dZ";
+      system = "";
+    };
+  };
+
+  keysOfType = type: from: with builtins; catAttrs type (attrValues from);
+
+  machinesWithKey = type: from: builtins.mapAttrs (m: k: k.${type}) from;
+in
+rec {
+  inherit machines;
+
+  # keys of admin accounts on network machines
+  allAdmins = keysOfType "user" machines;
+  # keys of user accounts on desktop machines
+  allDesktopUsers = keysOfType "user" desktops;
+  # keys of all users, both on desktop and server
+  allUsers = allAdmins ++ allDesktopUsers;
+  # system host keys of all network machines
+  allSystems = keysOfType "system" machines;
+  # all keys, whether system or user
+  all = allUsers ++ allSystems;
+
+  # user keys per machine
+  user = machinesWithKey "user" (machines // desktops);
+  # system keys per machine
+  system = machinesWithKey "system" (machines // desktops);
+}