change secret path?
This commit is contained in:
parent
1223d1b98b
commit
c0da687901
|
@ -12,7 +12,7 @@
|
||||||
};
|
};
|
||||||
|
|
||||||
requiredVaultPaths = [
|
requiredVaultPaths = [
|
||||||
"/private-public-keys/ssh/root@vault-decrypt"
|
"/private-public-keys/data/ssh/root@vault-decrypt"
|
||||||
|
|
||||||
"private-public-keys/data/restic/Vault"
|
"private-public-keys/data/restic/Vault"
|
||||||
|
|
||||||
|
@ -28,10 +28,9 @@
|
||||||
# but it makes it easier to install.
|
# but it makes it easier to install.
|
||||||
# it's stored in /nix store anyway
|
# it's stored in /nix store anyway
|
||||||
ssh_host_ed25519_key = {
|
ssh_host_ed25519_key = {
|
||||||
path = "/initrd_secrets/ssh_host_ed25519_key";
|
path = "/ssh_host_ed25519_key";
|
||||||
permissions = "600";
|
permissions = "600";
|
||||||
fetchScript = ''
|
fetchScript = ''
|
||||||
[ ! -d "$SYSROOT/initrd_secrets" ] && mkdir -p "$SYSROOT/initrd_secrets"
|
|
||||||
simple_get "/private-public-keys/ssh/root@vault-decrypt" .private | base64 > "$secretFile"
|
simple_get "/private-public-keys/ssh/root@vault-decrypt" .private | base64 > "$secretFile"
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|
|
@ -40,7 +40,7 @@ in {
|
||||||
secrets = {
|
secrets = {
|
||||||
# This will need to be generated before install or installed with secrets-init
|
# This will need to be generated before install or installed with secrets-init
|
||||||
# To keep it same across reinstalls add the ssh key and pubkey to secrets module
|
# To keep it same across reinstalls add the ssh key and pubkey to secrets module
|
||||||
"/ssh_host_ed25519_key" = mkForce "/initrd_secrets/ssh_host_ed25519_key";
|
"/ssh_host_ed25519_key" = "/ssh_host_ed25519_key";
|
||||||
};
|
};
|
||||||
|
|
||||||
luks = {
|
luks = {
|
||||||
|
|
Loading…
Reference in a new issue