sops: new way of decrypting secrets

This commit is contained in:
Christoph Hollizeck 2024-11-12 16:12:32 +01:00
parent cfbdeed038
commit cc9c283e12
Signed by: Daholli
GPG key ID: 249300664F2AF2C7
8 changed files with 56 additions and 38 deletions

View file

@ -23,7 +23,7 @@ in
sops = {
secrets = {
forgejo_db_password = {
"forgejo/db/password" = {
inherit sopsFile;
};
};
@ -71,7 +71,7 @@ in
database.type = "postgres";
lfs.enable = true;
database = {
passwordFile = config.sops.secrets.forgejo_db_password.path;
passwordFile = config.sops.secrets."forgejo/db/password".path;
};
settings = {
@ -111,8 +111,8 @@ in
};
user.trustedPublicKeys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHFrDiO5+vMfD5MimkzN32iw3MnSMLZ0mHvOrHVVmLD0"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAII4Pr7p0jizrvIl0UhcvrmL5SHRQQQWIcHLAnRFyUZS6"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHFrDiO5+vMfD5MimkzN32iw3MnSMLZ0mHvOrHVVmLD0" # yggdrasil
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAII4Pr7p0jizrvIl0UhcvrmL5SHRQQQWIcHLAnRFyUZS6" # Phone
];
};