disable auto-secrets for vault

This commit is contained in:
chaos 2023-09-20 18:08:00 +01:00
parent 8aa000a506
commit c3575e0d27
No known key found for this signature in database

View file

@ -1,10 +1,4 @@
{...}: {
# Since this is the machine that hosts vault
systemd.services.vault = {
before = ["auto-secrets.service"];
serviceConfig.PartOf = ["auto-secrets.service"];
};
services.secrets = {
enable = true;
@ -16,7 +10,8 @@
};
autoSecrets = {
enable = true;
# won't work when sealed
enable = false;
};
requiredVaultPaths = [