about summary refs log tree commit diff
path: root/secrets/keys.nix
diff options
context:
space:
mode:
authorMel <einebeere@gmail.com>2024-12-29 22:42:23 +0100
committerMel <einebeere@gmail.com>2024-12-29 22:42:23 +0100
commitd86ce8ee66dce54c8eb36385149b0f9acfe244f6 (patch)
tree981b529a921fa1570e4c154499f81fc9286d6c6a /secrets/keys.nix
parent17b9ac8e3f73c787fb4a39677ccb59bbbf5860fa (diff)
downloadspecimen-d86ce8ee66dce54c8eb36385149b0f9acfe244f6.tar.zst
specimen-d86ce8ee66dce54c8eb36385149b0f9acfe244f6.zip
Add secrets directory and list all keys
Signed-off-by: Mel <einebeere@gmail.com>
Diffstat (limited to 'secrets/keys.nix')
-rw-r--r--secrets/keys.nix22
1 files changed, 22 insertions, 0 deletions
diff --git a/secrets/keys.nix b/secrets/keys.nix
new file mode 100644
index 0000000..6f3a57d
--- /dev/null
+++ b/secrets/keys.nix
@@ -0,0 +1,22 @@
+let
+  # machines and their host key that are included in this configuration,
+  # in this case, just one.
+  machines = {
+    specimen = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMuIJFXse7iSMaOoBdr/WGqbNBwWLQTpFw6R8ram89gB";
+  };
+
+  # users that can sign secrets, with all of their keys.
+  admins = {
+    mel = [
+      "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEDujTul5wWyGnidLnNuJDRze0Up29l2cDpyKdmvW2Ls"
+      "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEK96G1n31aJsZOrux3BKM0ztzi/SFAVHn0MsGkPDdqY"
+    ];
+    philip = [ ];
+  };
+in
+{
+  inherit machines admins;
+
+  allAdminKeys = with builtins; concatLists (attrValues admins);
+  allMachineKeys = builtins.attrValues machines;
+}