Add agenix-rekey module + rekey config back to lazyworkhorse
agenix-rekey auto-re-encrypts secrets per host at build time: - Encrypted once in git with master identity - Re-encrypted for each host using their SSH host key - No manual multi-recipient encryption needed
This commit is contained in:
@@ -262,6 +262,7 @@
|
|||||||
}
|
}
|
||||||
inputs.home-manager.nixosModules.home-manager
|
inputs.home-manager.nixosModules.home-manager
|
||||||
agenix.nixosModules.default
|
agenix.nixosModules.default
|
||||||
|
agenix-rekey.nixosModules.default
|
||||||
./hosts/lazyworkhorse/configuration.nix
|
./hosts/lazyworkhorse/configuration.nix
|
||||||
./hosts/lazyworkhorse/hardware-configuration.nix
|
./hosts/lazyworkhorse/hardware-configuration.nix
|
||||||
./modules/nixos/filesystem/hoardingcow-mount.nix
|
./modules/nixos/filesystem/hoardingcow-mount.nix
|
||||||
|
|||||||
@@ -588,4 +588,10 @@
|
|||||||
};
|
};
|
||||||
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
# agenix-rekey — automatic re-encryption for each target host
|
||||||
|
age.rekey = {
|
||||||
|
masterIdentities = [
|
||||||
|
"/home/gortium/.ssh/gortium_ssh_key"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|||||||
@@ -12,5 +12,7 @@ in
|
|||||||
"home_wifi.age".publicKeys = authorizedKeys;
|
"home_wifi.age".publicKeys = authorizedKeys;
|
||||||
"lazyworkhorse_host_ssh_key.age".publicKeys = authorizedKeys;
|
"lazyworkhorse_host_ssh_key.age".publicKeys = authorizedKeys;
|
||||||
"n8n_ssh_key.age".publicKeys = authorizedKeys;
|
"n8n_ssh_key.age".publicKeys = authorizedKeys;
|
||||||
"builder_key.age".publicKeys = authorizedKeys;
|
"builder_key.age".publicKeys = authorizedKeys ++ [
|
||||||
|
keys.hosts.uConsole.bootstrap
|
||||||
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user