summary refs log tree commit diff
path: root/configuration
diff options
context:
space:
mode:
authorMel <einebeere@gmail.com>2024-12-30 16:31:02 +0100
committerMel <einebeere@gmail.com>2024-12-30 16:31:02 +0100
commita416a9fb83def3bc00c04d57ef9d2284c2c1df4e (patch)
tree8365aa813bbe59c074514b41e29fa93bd3f3ba2a /configuration
parentc69a5189925637910c1e5ceb9ce8b45992390521 (diff)
downloadspecimen-a416a9fb83def3bc00c04d57ef9d2284c2c1df4e.tar.zst
specimen-a416a9fb83def3bc00c04d57ef9d2284c2c1df4e.zip
Move secrets folder into configuration
Signed-off-by: Mel <einebeere@gmail.com>
Diffstat (limited to 'configuration')
-rw-r--r--configuration/secrets/keys.nix22
-rw-r--r--configuration/secrets/name.age9
-rw-r--r--configuration/secrets/secrets.nix13
-rw-r--r--configuration/specimen.nix2
4 files changed, 45 insertions, 1 deletions
diff --git a/configuration/secrets/keys.nix b/configuration/secrets/keys.nix
new file mode 100644
index 0000000..6f3a57d
--- /dev/null
+++ b/configuration/secrets/keys.nix
@@ -0,0 +1,22 @@
+let
+  # machines and their host key that are included in this configuration,
+  # in this case, just one.
+  machines = {
+    specimen = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMuIJFXse7iSMaOoBdr/WGqbNBwWLQTpFw6R8ram89gB";
+  };
+
+  # users that can sign secrets, with all of their keys.
+  admins = {
+    mel = [
+      "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEDujTul5wWyGnidLnNuJDRze0Up29l2cDpyKdmvW2Ls"
+      "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEK96G1n31aJsZOrux3BKM0ztzi/SFAVHn0MsGkPDdqY"
+    ];
+    philip = [ ];
+  };
+in
+{
+  inherit machines admins;
+
+  allAdminKeys = with builtins; concatLists (attrValues admins);
+  allMachineKeys = builtins.attrValues machines;
+}
diff --git a/configuration/secrets/name.age b/configuration/secrets/name.age
new file mode 100644
index 0000000..fb89666
--- /dev/null
+++ b/configuration/secrets/name.age
@@ -0,0 +1,9 @@
+age-encryption.org/v1
+-> ssh-ed25519 3ri8RA 37aWnYSkaK31gtnFvqJUJ3iMdv3EYrUPXjrMzAmvOiI
+Xxw9Qpjs/FHAzAe6RtFQlDAvN+bVCQByo+wJK0vxfqg
+-> ssh-ed25519 bykYHg N5cM6Qk3gUfXsOLS4qPmCqntWPxR9YyOLu4U7e1SGH4
+WJej54hr1S4tUhG3HSsIUqb3fzaIQp84Q3ppEbJ/MCU
+-> ssh-ed25519 Ke+vKw Kdypreok2UzZshzuJVIfpIX+yVDq/GMH2gDVG84tcxA
+iunEfk3Vbg/Y9TIG8qNxIH/0BNsHWbRi9l2+OcYl1iY
+--- mYsf5UMHGgU02prC56f9WlKnR/I6EeVzWXvDEAXh47A
+šQ±O`@÷È’tGP•-£Ü‹ÔZ[ÄŸC½†6v*€OY…Ë–ÐܓUX]
\ No newline at end of file
diff --git a/configuration/secrets/secrets.nix b/configuration/secrets/secrets.nix
new file mode 100644
index 0000000..2dab9d1
--- /dev/null
+++ b/configuration/secrets/secrets.nix
@@ -0,0 +1,13 @@
+let
+  keys = import ./keys.nix;
+
+  inherit (keys) machines allAdminKeys;
+in
+{
+  "name.age".publicKeys =
+    with machines;
+    [
+      specimen
+    ]
+    ++ allAdminKeys;
+}
diff --git a/configuration/specimen.nix b/configuration/specimen.nix
index 4620e47..9e994ef 100644
--- a/configuration/specimen.nix
+++ b/configuration/specimen.nix
@@ -2,7 +2,7 @@
 
 {
   age.secrets.name = {
-    file = ../secrets/name.age;
+    file = ./secrets/name.age;
     owner = "specimen";
     group = "specimen";
     mode = "440";