sops.nix (2110B)
1 # modules/home/sops.nix — sops-nix for the user: the same encrypted file, 2 # decrypted into $XDG_RUNTIME_DIR/secrets.d (symlinked at ~/.config/sops-nix/secrets) 3 # by a user service at login, readable only by daemonsec. 4 # 5 # Use this for secrets that belong to the user's programs (API tokens an app 6 # reads from a file, an rclone config, …); use modules/hosts/laptop/sops.nix for 7 # anything a system service needs. 8 # 9 # sops.secrets.example = { }; # → ~/.config/sops-nix/secrets/example 10 # sops.secrets.rclone = { path = "${config.xdg.configHome}/rclone/rclone.conf"; }; 11 # 12 # secretspec (modules/home/shell.nix) is the complement: per-project runtime 13 # secrets pulled from the keyring at `secretspec run`, declared next to the 14 # project in secretspec.toml, not in this repo. 15 { ... }: 16 { 17 flake.homeModules.sops = 18 { config, inputs, pkgs, lib, ... }: 19 { 20 imports = [ inputs.sops-nix.homeManagerModules.sops ]; 21 22 sops = { 23 defaultSopsFile = ../../secrets/secrets.yaml; 24 age.keyFile = "${config.home.homeDirectory}/.config/sops/age/keys.txt"; 25 age.sshKeyPaths = [ ]; 26 gnupg.sshKeyPaths = [ ]; 27 }; 28 29 home.packages = with pkgs; [ 30 sops 31 age 32 ssh-to-age # turn an ssh-ed25519 key into an age recipient when adding another machine 33 ]; 34 35 # sops-nix's activation step restarts the sops-nix user unit. That unit is a 36 # home-manager file (~/.config/systemd/user/sops-nix.service), linked by the 37 # linkGeneration step, and the user systemd manager only sees new unit 38 # files after a daemon-reload, which home-manager runs at the very end. With 39 # the extra steps this config adds, the DAG happened to order sops-nix 40 # before linkGeneration, so the first switch died with "Unit 41 # sops-nix.service not found". This entry pins the order: linkGeneration → 42 # daemon-reload → sops-nix. 43 home.activation.reloadUserUnitsForSops = lib.hm.dag.entryBetween [ "sops-nix" ] [ "linkGeneration" "installPackages" ] '' 44 ${pkgs.systemd}/bin/systemctl --user daemon-reload 2>/dev/null || true 45 ''; 46 } 47 ; 48 }