fix(secrets): fix more permission issues
This commit is contained in:
parent
557d744846
commit
867bd7d3de
8
rpi4.nix
8
rpi4.nix
|
@ -32,11 +32,7 @@ in with builtins; {
|
||||||
./services/nextcloud.nix
|
./services/nextcloud.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
age.secrets.cfdyndns = {
|
age.secrets.cloudflare.file = ./secrets/cloudflare.age;
|
||||||
file = ./secrets/cfdyndns.age;
|
|
||||||
owner = "cfdyndns";
|
|
||||||
group = "cfdyndns";
|
|
||||||
};
|
|
||||||
age.secrets.hostKey.file = ./secrets/home-server/hostKey.age;
|
age.secrets.hostKey.file = ./secrets/home-server/hostKey.age;
|
||||||
|
|
||||||
nixpkgs.config.allowUnfree = true;
|
nixpkgs.config.allowUnfree = true;
|
||||||
|
@ -70,7 +66,7 @@ in with builtins; {
|
||||||
use = "web";
|
use = "web";
|
||||||
zone = "felschr.com";
|
zone = "felschr.com";
|
||||||
username = "felschr@pm.me";
|
username = "felschr@pm.me";
|
||||||
passwordFile = config.age.secrets.cfdyndns.path;
|
passwordFile = config.age.secrets.cloudflare.path;
|
||||||
domains = [
|
domains = [
|
||||||
"home.felschr.com"
|
"home.felschr.com"
|
||||||
"cloud.felschr.com"
|
"cloud.felschr.com"
|
||||||
|
|
|
@ -21,7 +21,7 @@ in {
|
||||||
"mqtt/tasmota.age".publicKeys = [ felschr home-pc home-server ];
|
"mqtt/tasmota.age".publicKeys = [ felschr home-pc home-server ];
|
||||||
"mqtt/owntracks.age".publicKeys = [ felschr home-pc home-server ];
|
"mqtt/owntracks.age".publicKeys = [ felschr home-pc home-server ];
|
||||||
"mqtt/owntracks-plain.age".publicKeys = [ felschr home-pc home-server ];
|
"mqtt/owntracks-plain.age".publicKeys = [ felschr home-pc home-server ];
|
||||||
"cfdyndns.age".publicKeys = [ felschr home-pc home-server ];
|
"cloudflare.age".publicKeys = [ felschr home-pc home-server ];
|
||||||
"owntracks/htpasswd.age".publicKeys = [ felschr home-pc home-server ];
|
"owntracks/htpasswd.age".publicKeys = [ felschr home-pc home-server ];
|
||||||
"etebase-server.age".publicKeys = [ felschr home-pc home-server ];
|
"etebase-server.age".publicKeys = [ felschr home-pc home-server ];
|
||||||
"miniflux.age".publicKeys = [ felschr home-pc home-server ];
|
"miniflux.age".publicKeys = [ felschr home-pc home-server ];
|
||||||
|
|
|
@ -120,5 +120,7 @@ in {
|
||||||
age.secrets.hass-secrets = {
|
age.secrets.hass-secrets = {
|
||||||
file = ../secrets/hass/secrets.age;
|
file = ../secrets/hass/secrets.age;
|
||||||
path = "/var/lib/hass/secrets.yaml";
|
path = "/var/lib/hass/secrets.yaml";
|
||||||
|
owner = "hass";
|
||||||
|
group = "hass";
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
|
@ -9,7 +9,6 @@ let
|
||||||
mkSecret = file: {
|
mkSecret = file: {
|
||||||
inherit file;
|
inherit file;
|
||||||
owner = "mosquitto";
|
owner = "mosquitto";
|
||||||
group = "mosquitto";
|
|
||||||
};
|
};
|
||||||
in {
|
in {
|
||||||
age.secrets = {
|
age.secrets = {
|
||||||
|
|
Loading…
Reference in a new issue