Fix agenix-rekey: add real uConsole host key, re-encrypt secrets
- Update uConsole hostPubkey from dummy to real SSH host key - Add uConsole host key to keys.nix - Add age.rekey config to lazyworkhorse - Add SSH host key to identityPaths on both hosts - Re-encrypt builder_key.age and gortium_password.age for both hosts
This commit is contained in:
@@ -251,7 +251,9 @@
|
|||||||
|
|
||||||
# Private host ssh key managed by agenix
|
# Private host ssh key managed by agenix
|
||||||
age = {
|
age = {
|
||||||
identityPaths = paths.identities;
|
identityPaths = paths.identities ++ [
|
||||||
|
"/etc/ssh/ssh_host_ed25519_key"
|
||||||
|
];
|
||||||
secrets = {
|
secrets = {
|
||||||
containers_env = {
|
containers_env = {
|
||||||
file = ../../secrets/containers.env.age;
|
file = ../../secrets/containers.env.age;
|
||||||
@@ -585,4 +587,12 @@
|
|||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|
||||||
|
# agenix-rekey configuration (for builder_key re-encryption at build time)
|
||||||
|
age.rekey = {
|
||||||
|
masterIdentities = [
|
||||||
|
"/home/gortium/.ssh/gortium_ssh_key"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
}
|
}
|
||||||
@@ -214,6 +214,10 @@
|
|||||||
};
|
};
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
|
age.identityPaths = [
|
||||||
|
"/etc/ssh/ssh_host_ed25519_key"
|
||||||
|
];
|
||||||
|
|
||||||
# agenix-rekey — automatic secret re-encryption at deploy time
|
# agenix-rekey — automatic secret re-encryption at deploy time
|
||||||
# ============================================================
|
# ============================================================
|
||||||
age.rekey = {
|
age.rekey = {
|
||||||
@@ -224,7 +228,7 @@
|
|||||||
# uConsole SSH host pubkey — for automatic rekey at build time
|
# uConsole SSH host pubkey — for automatic rekey at build time
|
||||||
# Once uConsole is deployed, replace with actual pubkey from:
|
# Once uConsole is deployed, replace with actual pubkey from:
|
||||||
# ssh-keyscan uConsole.local | ssh-to-age
|
# ssh-keyscan uConsole.local | ssh-to-age
|
||||||
hostPubkey = "age1qyqszqgpqyqszqgpqyqszqgpqyqszqgpqyqszqgpqyqszqgpqyqs3290gq"; # dummy — replace after bootstrap
|
hostPubkey = "age1un8td4jzkhg5fm4jja7z3aznskc8hlcm8ky0j2f70tv74rulwgaqtpemn2"; # uConsole CM5 SSH host key
|
||||||
};
|
};
|
||||||
|
|
||||||
# Pipewire overlay: drop libcamera (fixes aarch64 cross-compile — rpi-pisp blocks)
|
# Pipewire overlay: drop libcamera (fixes aarch64 cross-compile — rpi-pisp blocks)
|
||||||
|
|||||||
@@ -25,5 +25,9 @@
|
|||||||
gitea = "";
|
gitea = "";
|
||||||
bootstrap = "age1r796v2uldtspawyh863pks74sd2pwcan8j4e4pjzsvkmr3vjja9qpz5ste";
|
bootstrap = "age1r796v2uldtspawyh863pks74sd2pwcan8j4e4pjzsvkmr3vjja9qpz5ste";
|
||||||
};
|
};
|
||||||
|
uConsole = {
|
||||||
|
main = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICasvsmaHuNVaWnjwuBfoMXyY/6PIqGL8yxstPBb46u4";
|
||||||
|
bootstrap = "age1un8td4jzkhg5fm4jja7z3aznskc8hlcm8ky0j2f70tv74rulwgaqtpemn2";
|
||||||
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
Binary file not shown.
@@ -1,10 +1,8 @@
|
|||||||
-----BEGIN AGE ENCRYPTED FILE-----
|
age-encryption.org/v1
|
||||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IEdoTUQ4QSA4MlFz
|
-> X25519 7xL84BK2tC3CqgHpETooVNzVTpV/CcLWqyrydQhenzM
|
||||||
SHFjYjJMVHRlTWNGVGI2bHQxc0xRd2tlaExlM0NFMWhlbkR2bVg0CkxxenVTaXkr
|
idcoRTzHMOExLmwZUyrWKLYNxVYwKu4wrnK10vqFYzE
|
||||||
eWxybDdCeUM0ejRvZWI4cFZCWm5VczRvZkNnT0d5Y1oyYmsKLT4gK1NmRzVtLWdy
|
-> X25519 4XY4yLwWjdLAG1As22OK1BfLi+xbXxxYkex2bq3yWVs
|
||||||
ZWFzZSB3UDI6TyNaCnF4Ylk0QWduaXZxRFBFbDBOZ0dxeGxiWTVCYjRtZTJBRkFC
|
QVSZjLUA060toELjD5SXbh1HSUPv1Xwt7P8bjVrgjQA
|
||||||
YU5qaytYWWI4OWl1K1FSdXNlY2JXZjkzak9tTHkKVFlCRlRqY1FVSzFmNS9yZmxF
|
--- +19En3AkdJjEkeKmVSV0cm9z7zYVVtrOSQNexY9Yrbg
|
||||||
aEUxelUwNEpKN3VXYi9KUWN4bXFscm5oUEFOajhRZDlERWVYcFgvQQotLS0gK1JI
|
<EFBFBD>#c1<63><31>Yy /<2F><>X!<21><><0C>a,g<><67>c<19><><EFBFBD><EFBFBD><<3C>,<04><>ɫ% Lhړ<DA93><7F>(/
|
||||||
VERTQjB6d1k3NDQwbjNveXBqcFk1WE96cHlaTTVkTWRMZENPamFJZwpcT1CP/KvU
|
Tf<EFBFBD>7<EFBFBD>%<25><><EFBFBD><l
|
||||||
CsunvfX9RBlSSKuw4eem9N9s3JqJNj4FRQizNx6QzlE1vSME
|
|
||||||
-----END AGE ENCRYPTED FILE-----
|
|
||||||
Reference in New Issue
Block a user