2024-07-11 14:49:11 -07:00
|
|
|
{ lib, config, inputs, pkgs, ... }:
|
2024-07-08 20:35:25 -07:00
|
|
|
|
|
|
|
let
|
|
|
|
cfg = config.snowhawk.sops;
|
|
|
|
home = config.home.homeDirectory;
|
|
|
|
in
|
|
|
|
{
|
|
|
|
imports = [
|
|
|
|
inputs.sops-nix.homeManagerModules.sops
|
|
|
|
];
|
|
|
|
|
|
|
|
options.snowhawk.sops = {
|
|
|
|
enable = lib.mkEnableOption "sops";
|
|
|
|
};
|
|
|
|
|
|
|
|
config = lib.mkIf cfg.enable {
|
2024-07-11 14:49:11 -07:00
|
|
|
home.packages = [
|
|
|
|
pkgs.sops
|
|
|
|
];
|
|
|
|
|
2024-07-08 20:35:25 -07:00
|
|
|
sops = {
|
|
|
|
age.keyFile = "${home}/.config/sops/age/keys.txt";
|
|
|
|
|
|
|
|
defaultSopsFile = ../../secrets.yaml;
|
|
|
|
validateSopsFiles = false;
|
|
|
|
|
|
|
|
secrets = {
|
|
|
|
"private_keys/personal_git" = {
|
|
|
|
path = "${home}/.ssh/personal_git";
|
|
|
|
};
|
2024-07-09 01:47:23 -07:00
|
|
|
"private_keys/msiserver" = {
|
|
|
|
path = "${home}/.ssh/msiserver";
|
|
|
|
};
|
2024-07-11 05:58:16 -07:00
|
|
|
"private_keys/caveserver" = {
|
|
|
|
path = "${home}/.ssh/caveserver";
|
|
|
|
};
|
2024-07-11 05:22:08 -07:00
|
|
|
"ssh_hosts/caveserver" = {
|
|
|
|
path = "${home}/.ssh/conf.d/caveserver_config";
|
|
|
|
};
|
2024-07-08 20:35:25 -07:00
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
}
|