sops.nix (1546B)
1 # modules/hosts/laptop/sops.nix — sops-nix: secrets encrypted in this repo, decrypted 2 # at activation into /run/secrets (root-only tmpfs; per-secret owner/mode). 3 # 4 # One age identity does everything (.sops.yaml): the user edits with the sops 5 # CLI (reads ~/.config/sops/age/keys.txt), the system decrypts at boot with a 6 # root-only copy at /var/lib/sops-nix/key.txt. Put it there once: 7 # 8 # sudo install -D -m 600 -o root -g root ~/.config/sops/age/keys.txt /var/lib/sops-nix/key.txt 9 # 10 # No SSH host key is used: sshd is not enabled on this machine, so there is 11 # none to derive an age key from (sshKeyPaths is emptied below for that reason). 12 # 13 # Declaring a secret: 14 # sops.secrets.my-token = { }; # → /run/secrets/my-token, root:root 0400 15 # sops.secrets."ssd.key" = { path = "/etc/secrets/ssd.key"; }; # the LUKS key, once it is 16 # # added to secrets/secrets.yaml (sops set …) 17 # sops.secrets.wifi-psk = { owner = user; }; # readable by the user 18 # then `sops secrets/secrets.yaml` to add the value, and `nh os switch`. 19 { ... }: 20 { 21 flake.nixosModules.laptop-sops = 22 { inputs, user, ... }: 23 { 24 imports = [ inputs.sops-nix.nixosModules.sops ]; 25 26 sops = { 27 defaultSopsFile = ../../../secrets/secrets.yaml; 28 age = { 29 keyFile = "/var/lib/sops-nix/key.txt"; 30 sshKeyPaths = [ ]; 31 generateKey = false; # the key is the user's (see header), never a fresh one 32 }; 33 gnupg.sshKeyPaths = [ ]; 34 }; 35 } 36 ; 37 }