{ config, secrets, ... }: { sops.secrets.mullvad = { sopsFile = "${secrets}/mullvad.yaml"; owner = "root"; format = "yaml"; }; vpnNamespaces.mullvad = { enable = true; wireguardConfigFile = config.sops.secrets.mullvad.path; accessibleFrom = [ "192.168.0.0/16" ]; }; }