61 lines
2.8 KiB
Nix
61 lines
2.8 KiB
Nix
{ config, ... }:
|
|
|
|
# sops-nix wiring for mars. Encrypted values in ../../secrets/mars.yaml,
|
|
# decrypted with mars's own SSH host key (recipient in ../../.sops.yaml).
|
|
# The host key is pre-generated on the laptop and shipped at install
|
|
# (nixos-anywhere --extra-files -> /etc/ssh/ssh_host_ed25519_key).
|
|
{
|
|
sops.defaultSopsFile = ../../secrets/mars.yaml;
|
|
sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
|
|
|
|
sops.secrets.darman_password.neededForUsers = true;
|
|
users.users.darman.hashedPasswordFile = config.sops.secrets.darman_password.path;
|
|
|
|
sops.secrets.tailscale_authkey = { };
|
|
|
|
# Credentials file for the //jupiter/data cifs mount (see configuration.nix).
|
|
# Same value as jupiter's own samba_password (services/network/samba.nix) —
|
|
# mars authenticates as the same smb user, mirroring terra's setup.
|
|
sops.secrets.samba_password = { };
|
|
sops.templates."jupiter-smb.credentials".content = ''
|
|
username=darman
|
|
password=${config.sops.placeholder.samba_password}
|
|
'';
|
|
|
|
# Hermes Agent (hermes-agent.nix) — moved here from jupiter (see that
|
|
# host's git history); same Telegram bot token, opencode key, and
|
|
# Authentik OIDC client secret, so no new bot/app to provision.
|
|
sops.secrets.opencode_go_api_key = { };
|
|
sops.secrets.telegram_bot_token = { };
|
|
sops.secrets.hermes_dashboard_oidc_client_secret = { };
|
|
sops.secrets.gitea_hermes_webhook_secret = {
|
|
# Add the same value to secrets/mars.yaml before deploying Mars.
|
|
restartUnits = [
|
|
"gitea-hermes-webhook-relay.service"
|
|
"hermes-agent-webhook-route.service"
|
|
];
|
|
};
|
|
sops.templates."hermes-agent.env".content = ''
|
|
OPENCODE_GO_API_KEY=${config.sops.placeholder.opencode_go_api_key}
|
|
TELEGRAM_BOT_TOKEN=${config.sops.placeholder.telegram_bot_token}
|
|
TELEGRAM_HOME_CHANNEL=15151223
|
|
TELEGRAM_ALLOWED_USERS=15151223
|
|
WEBHOOK_ENABLED=true
|
|
WEBHOOK_PORT=8644
|
|
GITEA_HERMES_WEBHOOK_SECRET=${config.sops.placeholder.gitea_hermes_webhook_secret}
|
|
HERMES_DASHBOARD_OIDC_CLIENT_SECRET=${config.sops.placeholder.hermes_dashboard_oidc_client_secret}
|
|
'';
|
|
|
|
# luna's own gitea push token (services/dev/gitea.nix provisions the
|
|
# account + PR-tier repo access on jupiter; this is the per-user token
|
|
# generated once via `gitea admin user generate-access-token --username
|
|
# luna --scopes write:repository,read:user` on jupiter — read:user is
|
|
# required, `tea logins add` fails without it). Read directly by
|
|
# hermes-agent.nix's prepare-dirs oneshot (default root:root owner is
|
|
# fine — that oneshot already runs as root) to set up a git
|
|
# credential-store file and a `tea` login, both written into hermesHome
|
|
# so they're visible inside the container at /opt/data/....
|
|
# restartUnits re-provisions both on rotation, without a full mars deploy.
|
|
sops.secrets.gitea_luna_token.restartUnits = [ "hermes-agent-prepare-dirs.service" ];
|
|
}
|