{ config, ... }: # sops-nix wiring for mercury. Encrypted values in ../../secrets/mercury.yaml. # # SD images have no `--extra-files` step, so mercury uses a DEDICATED age key # placed on the ROOT filesystem (the Pi's vfat partition isn't mounted at # runtime — u-boot reads it pre-boot). `./deploy flash mercury ` drops # ~/.config/homelab/mercury/age.txt there automatically. # The key never enters the repo, the nix store, or the image itself. { sops.defaultSopsFile = ../../secrets/mercury.yaml; sops.age.keyFile = "/var/lib/sops-nix/age.txt"; # darman's console password (SSH is key-only regardless). Different hash per # host = different password per host. sops.secrets.darman_password.neededForUsers = true; users.users.darman.hashedPasswordFile = config.sops.secrets.darman_password.path; # Pre-auth key for services/vpn/tailscale.nix. Root-owned 0400 is right: # tailscaled runs as root and reads authKeyFile itself. sops.secrets.tailscale_authkey = { }; }