From 24761b58b2c950a0a3cace7969d8eec1d20e70a5 Mon Sep 17 00:00:00 2001 From: Hermes Date: Mon, 22 Jun 2026 00:05:22 -0400 Subject: [PATCH] Add agenix-rekey module + rekey config back to lazyworkhorse agenix-rekey auto-re-encrypts secrets per host at build time: - Encrypted once in git with master identity - Re-encrypted for each host using their SSH host key - No manual multi-recipient encryption needed --- flake.nix | 1 + hosts/lazyworkhorse/configuration.nix | 8 +++++++- secrets/secrets.nix | 4 +++- 3 files changed, 11 insertions(+), 2 deletions(-) diff --git a/flake.nix b/flake.nix index ef628c8..8a8b302 100644 --- a/flake.nix +++ b/flake.nix @@ -262,6 +262,7 @@ } inputs.home-manager.nixosModules.home-manager agenix.nixosModules.default + agenix-rekey.nixosModules.default ./hosts/lazyworkhorse/configuration.nix ./hosts/lazyworkhorse/hardware-configuration.nix ./modules/nixos/filesystem/hoardingcow-mount.nix diff --git a/hosts/lazyworkhorse/configuration.nix b/hosts/lazyworkhorse/configuration.nix index 41de1e7..bf92d4b 100644 --- a/hosts/lazyworkhorse/configuration.nix +++ b/hosts/lazyworkhorse/configuration.nix @@ -588,4 +588,10 @@ }; -} \ No newline at end of file +} + # agenix-rekey — automatic re-encryption for each target host + age.rekey = { + masterIdentities = [ + "/home/gortium/.ssh/gortium_ssh_key" + ]; + }; diff --git a/secrets/secrets.nix b/secrets/secrets.nix index d7fcec7..d94174d 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -12,5 +12,7 @@ in "home_wifi.age".publicKeys = authorizedKeys; "lazyworkhorse_host_ssh_key.age".publicKeys = authorizedKeys; "n8n_ssh_key.age".publicKeys = authorizedKeys; - "builder_key.age".publicKeys = authorizedKeys; +"builder_key.age".publicKeys = authorizedKeys ++ [ + keys.hosts.uConsole.bootstrap + ]; }