switch to keys
Some checks failed
/ lint (push) Waiting to run
/ build (push) Has been cancelled

This commit is contained in:
Jana Dönszelmann 2026-01-03 02:26:03 +01:00
parent c40e6e3255
commit 115a711a5f
No known key found for this signature in database
29 changed files with 122 additions and 221 deletions

View file

@ -1,7 +1,12 @@
{ pkgs, config, ... }:
{
pkgs,
config,
secrets,
...
}:
{
sops.secrets.oauth2-proxy = {
sopsFile = ../../../secrets/oauth2-proxy.env;
sopsFile = "${secrets}/oauth2-proxy.env";
};
services.oauth2-proxy =

View file

@ -1,8 +1,8 @@
{ config, ... }:
{ config, secrets, ... }:
{
sops.secrets.pocketid = {
owner = config.services.pocket-id.user;
sopsFile = ../../../secrets/pocketid.env;
sopsFile = "${secrets}/pocketid.env";
};
services.nginx.virtualHosts."auth.donsz.nl" = {

View file

@ -2,6 +2,7 @@
lib,
pkgs,
config,
secrets,
...
}:
let
@ -100,7 +101,7 @@ in
};
sops.secrets.factorio = {
sopsFile = ../../secrets/factorio.json;
sopsFile = "${secrets}/factorio.json";
format = "json";
key = "";
owner = "factorio";

View file

@ -3,6 +3,7 @@
pkgs,
config,
flakes,
secrets,
...
}:
let
@ -11,7 +12,7 @@ let
in
{
sops.secrets.forgejo = {
sopsFile = ../../secrets/forgejo.yaml;
sopsFile = "${secrets}/forgejo.yaml";
key = "email_password";
format = "yaml";
};
@ -97,7 +98,7 @@ in
};
sops.secrets.forgejo-runner = {
sopsFile = ../../secrets/forgejo-runner.env;
sopsFile = "${secrets}/forgejo-runner.env";
};
nix = {

View file

@ -1,11 +1,12 @@
{
config,
pkgs,
secrets,
...
}:
{
sops.secrets.mullvad = {
sopsFile = ../../../secrets/mullvad.yaml;
sopsFile = "${secrets}/mullvad.yaml";
owner = "root";
format = "yaml";
};

View file

@ -1,4 +1,9 @@
{ pkgs, config, ... }:
{
pkgs,
config,
secrets,
...
}:
let
lib = pkgs.lib;
in
@ -285,7 +290,7 @@ in
};
sops.secrets.geoip = {
sopsFile = ../../secrets/geoip.yaml;
sopsFile = "${secrets}/geoip.yaml";
key = "key";
format = "yaml";
};

View file

@ -1,10 +1,15 @@
{ pkgs, config, ... }:
{
pkgs,
config,
secrets,
...
}:
let
port = 5984;
in
{
sops.secrets.obsidian-sync = {
sopsFile = ../../secrets/obsidian-sync.ini;
sopsFile = "${secrets}/obsidian-sync.ini";
format = "ini";
owner = "couchdb";
};

View file

@ -2,11 +2,12 @@
config,
flakes,
pkgs,
secrets,
...
}:
{
sops.secrets.mapf = {
sopsFile = ../../../secrets/mapf-prod.env;
sopsFile = "${secrets}/mapf-prod.env";
};
services.nginx = {

View file

@ -1,7 +1,12 @@
{ pkgs, flakes, ... }:
{
pkgs,
flakes,
secrets,
...
}:
{
sops.secrets.reviewqueue = {
sopsFile = ../../../secrets/reviewqueue.env;
sopsFile = "${secrets}/reviewqueue.env";
};
services.nginx = {