NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

sops.nix (2110B)


      1 # modules/home/sops.nix — sops-nix for the user: the same encrypted file,
      2 # decrypted into $XDG_RUNTIME_DIR/secrets.d (symlinked at ~/.config/sops-nix/secrets)
      3 # by a user service at login, readable only by daemonsec.
      4 #
      5 # Use this for secrets that belong to the user's programs (API tokens an app
      6 # reads from a file, an rclone config, …); use modules/hosts/laptop/sops.nix for
      7 # anything a system service needs.
      8 #
      9 #   sops.secrets.example = { };                               # → ~/.config/sops-nix/secrets/example
     10 #   sops.secrets.rclone = { path = "${config.xdg.configHome}/rclone/rclone.conf"; };
     11 #
     12 # secretspec (modules/home/shell.nix) is the complement: per-project runtime
     13 # secrets pulled from the keyring at `secretspec run`, declared next to the
     14 # project in secretspec.toml, not in this repo.
     15 { ... }:
     16 {
     17   flake.homeModules.sops =
     18   { config, inputs, pkgs, lib, ... }:
     19   {
     20     imports = [ inputs.sops-nix.homeManagerModules.sops ];
     21 
     22     sops = {
     23       defaultSopsFile = ../../secrets/secrets.yaml;
     24       age.keyFile = "${config.home.homeDirectory}/.config/sops/age/keys.txt";
     25       age.sshKeyPaths = [ ];
     26       gnupg.sshKeyPaths = [ ];
     27     };
     28 
     29     home.packages = with pkgs; [
     30       sops
     31       age
     32       ssh-to-age # turn an ssh-ed25519 key into an age recipient when adding another machine
     33     ];
     34 
     35     # sops-nix's activation step restarts the sops-nix user unit. That unit is a
     36     # home-manager file (~/.config/systemd/user/sops-nix.service), linked by the
     37     # linkGeneration step, and the user systemd manager only sees new unit
     38     # files after a daemon-reload, which home-manager runs at the very end. With
     39     # the extra steps this config adds, the DAG happened to order sops-nix
     40     # before linkGeneration, so the first switch died with "Unit
     41     # sops-nix.service not found". This entry pins the order: linkGeneration →
     42     # daemon-reload → sops-nix.
     43     home.activation.reloadUserUnitsForSops = lib.hm.dag.entryBetween [ "sops-nix" ] [ "linkGeneration" "installPackages" ] ''
     44       ${pkgs.systemd}/bin/systemctl --user daemon-reload 2>/dev/null || true
     45     '';
     46   }
     47   ;
     48 }