Group service modules by category (media, network, vpn, identity, dev, desktop) to make the growing services/ dir easier to navigate. containers.nix stays at the top level since it's a shared backend, not a single-category service. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
48 lines
2.0 KiB
Nix
48 lines
2.0 KiB
Nix
{ config, ... }:
|
|
|
|
# sops-nix wiring for neptun (netcup VPS). Encrypted values in ../../secrets/neptun.yaml,
|
|
# decrypted with the VPS's own SSH host key (recipient in ../../.sops.yaml).
|
|
# The host key is pre-generated on the laptop and shipped at install
|
|
# (nixos-anywhere --extra-files -> /etc/ssh/ssh_host_ed25519_key).
|
|
{
|
|
sops.defaultSopsFile = ../../secrets/neptun.yaml;
|
|
sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
|
|
|
|
sops.secrets.tailscale_authkey = { };
|
|
|
|
# darman's console password (own hash = distinct from jupiter/mercury).
|
|
sops.secrets.darman_password.neededForUsers = true;
|
|
users.users.darman.hashedPasswordFile = config.sops.secrets.darman_password.path;
|
|
|
|
# Zitadel: masterKeyFile takes a path natively (no store leak). The admin
|
|
# bootstrap password is different — services.zitadel.steps would render it
|
|
# into a world-readable store path, so render a FirstInstance steps file
|
|
# from the secret instead and point extraStepsPaths at it (see
|
|
# services/identity/zitadel.nix and the pihole.env template on mercury for the same
|
|
# pattern).
|
|
sops.secrets.zitadel_master_key = { };
|
|
sops.secrets.zitadel_admin_password = { };
|
|
sops.templates."zitadel-first-instance.yaml".content = ''
|
|
FirstInstance:
|
|
Org:
|
|
Name: mgaction
|
|
Human:
|
|
UserName: admin
|
|
FirstName: Admin
|
|
LastName: Admin
|
|
Email:
|
|
Address: erik.simon.me@gmail.com
|
|
Verified: true
|
|
Password: ${config.sops.placeholder.zitadel_admin_password}
|
|
PasswordChangeRequired: false
|
|
'';
|
|
|
|
# Headplane: cookie_secret_path takes a path natively (no store leak).
|
|
# oidc.client_secret + the headscale API key are still REPLACE_ME
|
|
# placeholders (see services/vpn/headplane.nix) until Zitadel/headscale are
|
|
# actually deployed and those get created for real.
|
|
sops.secrets.headplane_cookie_secret = { };
|
|
sops.secrets.headplane_oidc_client_secret = { };
|
|
sops.secrets.headplane_headscale_api_key = { };
|
|
}
|