{ config, ... }: # sops-nix secret wiring (real host only; not imported by vm.nix). # Encrypted values live in ../../secrets/jupiter.yaml, decrypted at activation to # /run/secrets/. # # The host decrypts with its OWN SSH host key (age identity derived via # ssh-to-age, recipient listed in ../../.sops.yaml). The key is pre-generated on # the laptop and shipped once at install as /etc/ssh/ssh_host_ed25519_key # (nixos-anywhere --extra-files) — so decryption works on boot #1 and there is # no separate sops-only key to manage. { sops.defaultSopsFile = ../../secrets/jupiter.yaml; sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; # Decrypts to /run/secrets/samba_password (root-only by default). sops.secrets.samba_password = { }; # darman's login password (a sha-512 hash, not plaintext — generate with # `mkpasswd -m sha-512`, edit via ./edit_secrets). neededForUsers makes it # available before user setup, at /run/secrets-for-users/darman_password. sops.secrets.darman_password.neededForUsers = true; users.users.darman.hashedPasswordFile = config.sops.secrets.darman_password.path; # Headscale pre-auth key for tailscale auto-registration (see configuration.nix). sops.secrets.tailscale_authkey = { }; # Immich's OIDC client secret, from its Authentik application (a SEPARATE # app from headscale's and headplane's — see hosts/neptun/secrets.nix). # Referenced as settings.oauth.clientSecret._secret in # services/media/immich.nix; the module resolves it through systemd # LoadCredential, which reads as root before dropping privileges, so the # sops default of root:root 0400 is correct — do NOT set `owner`. sops.secrets.immich_oauth_client_secret = { }; # Gitea Actions runner registration token (services/dev/gitea.nix). Gitea # generates this itself once Actions is enabled — it is not a password # chosen up front. Rendered into a `TOKEN=...` env file because # gitea-actions-runner takes an EnvironmentFile, not a raw secret path. sops.secrets.gitea_runner_token = { }; sops.templates."gitea-runner.env".content = "TOKEN=${config.sops.placeholder.gitea_runner_token}"; # provisioning access token for gitea used to setup ci-bot account + repo access sops.secrets.gitea_provisioning_token.owner = "gitea"; # ci-bot access token to allow the ci-bot user to push to repos sops.secrets.gitea_ci_bot_token.owner = "gitea"; # Add the same value to secrets/jupiter.yaml before deploying Jupiter. sops.secrets.gitea_hermes_webhook_secret = { owner = "gitea"; }; # SABnzbd credentials (web UI login, API keys, eweka.nl usenet server) — # migrated off the reused ini in services/media/sabnzbd.nix into # services.sabnzbd.settings + secretValues. sabnzbd_api_key predates this # migration (provisioned for mediamanager's future use, services/experimental/ # mediamanager.nix — not currently imported by any host); reused here as the # same single source of truth rather than duplicating it. # owner = sabnzbd: the module's preStart (replace-secret) runs as the # service's own User=/Group=, and sops secrets default to root:root 0400 — # without this, replace-secret gets Permission denied reading /run/secrets. sops.secrets.sabnzbd_web_username.owner = "sabnzbd"; sops.secrets.sabnzbd_web_password.owner = "sabnzbd"; sops.secrets.sabnzbd_api_key.owner = "sabnzbd"; sops.secrets.sabnzbd_nzb_key.owner = "sabnzbd"; sops.secrets.sabnzbd_eweka_username.owner = "sabnzbd"; sops.secrets.sabnzbd_eweka_password.owner = "sabnzbd"; # CouchDB admin account for Obsidian LiveSync # (services/dev/obsidian-livesync.nix). Rendered into an [admins] ini # fragment rather than passed as services.couchdb.adminPass, which would put # the plaintext in the world-readable store. # # owner = couchdb on BOTH: couchdb re-reads its ini chain as its own # User=/Group= after systemd drops privileges, and sops defaults to # root:root 0400 — without this it comes up with no admin configured, which # under require_valid_user means every request 401s. sops.secrets.couchdb_admin_password.owner = "couchdb"; sops.templates."couchdb-admins.ini" = { owner = "couchdb"; content = '' [admins] obsidian = ${config.sops.placeholder.couchdb_admin_password} ''; }; }