- new nixosConfigurations.vps: UEFI systemd-boot, disko on /dev/vda - static IPv4 159.195.64.117/22 gw .1 (+ IPv6), eth0 pinned, public DNS - tailscale via headscale + sops authkey (secrets/vps.yaml, own host key) - caddy public reverse proxy: audiobookshelf.mgaction.town -> jupiter tailnet:8000 - shared common.nix (user/ssh/nix) ; .sops.yaml per-host rules
13 lines
458 B
Nix
13 lines
458 B
Nix
{ config, ... }:
|
|
|
|
# sops-nix wiring for the VPS. Encrypted values live in ../secrets/vps.yaml,
|
|
# decrypted with the VPS's own SSH host key (recipient in ../.sops.yaml).
|
|
# The host key is pre-generated on the laptop and shipped at install
|
|
# (nixos-anywhere --extra-files -> /etc/ssh/ssh_host_ed25519_key).
|
|
{
|
|
sops.defaultSopsFile = ../secrets/vps.yaml;
|
|
sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
|
|
|
|
sops.secrets.tailscale_authkey = { };
|
|
}
|