NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

sops.nix (1546B)


      1 # modules/hosts/laptop/sops.nix — sops-nix: secrets encrypted in this repo, decrypted
      2 # at activation into /run/secrets (root-only tmpfs; per-secret owner/mode).
      3 #
      4 # One age identity does everything (.sops.yaml): the user edits with the sops
      5 # CLI (reads ~/.config/sops/age/keys.txt), the system decrypts at boot with a
      6 # root-only copy at /var/lib/sops-nix/key.txt. Put it there once:
      7 #
      8 #   sudo install -D -m 600 -o root -g root ~/.config/sops/age/keys.txt /var/lib/sops-nix/key.txt
      9 #
     10 # No SSH host key is used: sshd is not enabled on this machine, so there is
     11 # none to derive an age key from (sshKeyPaths is emptied below for that reason).
     12 #
     13 # Declaring a secret:
     14 #   sops.secrets.my-token = { };                        # → /run/secrets/my-token, root:root 0400
     15 #   sops.secrets."ssd.key" = { path = "/etc/secrets/ssd.key"; };   # the LUKS key, once it is
     16 #                                                       # added to secrets/secrets.yaml (sops set …)
     17 #   sops.secrets.wifi-psk = { owner = user; };          # readable by the user
     18 # then `sops secrets/secrets.yaml` to add the value, and `nh os switch`.
     19 { ... }:
     20 {
     21   flake.nixosModules.laptop-sops =
     22   { inputs, user, ... }:
     23   {
     24     imports = [ inputs.sops-nix.nixosModules.sops ];
     25 
     26     sops = {
     27       defaultSopsFile = ../../../secrets/secrets.yaml;
     28       age = {
     29         keyFile = "/var/lib/sops-nix/key.txt";
     30         sshKeyPaths = [ ];
     31         generateKey = false; # the key is the user's (see header), never a fresh one
     32       };
     33       gnupg.sshKeyPaths = [ ];
     34     };
     35   }
     36   ;
     37 }