Skip to content

Commit

Permalink
fix(agenix-rekey)!: wrong generator syntax
Browse files Browse the repository at this point in the history
  • Loading branch information
reo101 committed Dec 25, 2023
1 parent 66ae98e commit 3243e61
Show file tree
Hide file tree
Showing 2 changed files with 17 additions and 8 deletions.
13 changes: 10 additions & 3 deletions machines/nixos/x86_64-linux/jeeves/configuration.nix
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,11 @@
config.nix.registry;

settings = {
trusted-users = [
"root"
"jeeves"
];

experimental-features = "nix-command flakes";
auto-optimise-store = true;
};
Expand All @@ -72,9 +77,11 @@
# NOTE: made with `mkpasswd -m sha-516`
age.secrets."jeeves.user.password" = {
rekeyFile = "${inputs.self}/secrets/home/jeeves/user/password.age";
generator = {pkgs, ...}: ''
${pkgs.mkpasswd}/bin/mkpasswd -m sha-516
'';
generator = {
script = {pkgs, ...}: ''
${pkgs.mkpasswd}/bin/mkpasswd -m sha-516
'';
};
};

users = {
Expand Down
12 changes: 7 additions & 5 deletions machines/nixos/x86_64-linux/jeeves/wireguard.nix
Original file line number Diff line number Diff line change
Expand Up @@ -13,11 +13,13 @@
age.secrets."wireguard.private" = {
mode = "077";
rekeyFile = "${inputs.self}/secrets/home/jeeves/wireguard/private.age";
generator = {lib, pkgs, file, ...}: ''
priv=$(${pkgs.wireguard-tools}/bin/wg genkey)
${pkgs.wireguard-tools}/bin/wg pubkey <<< "$priv" > ${lib.escapeShellArg (lib.removeSuffix ".age" file + ".pub")}
echo "$priv"
'';
generator = {
script = {lib, pkgs, file, ...}: ''
priv=$(${pkgs.wireguard-tools}/bin/wg genkey)
${pkgs.wireguard-tools}/bin/wg pubkey <<< "$priv" > ${lib.escapeShellArg (lib.removeSuffix ".age" file + ".pub")}
echo "$priv"
'';
};
};

networking.firewall.allowedUDPPorts = [51820];
Expand Down

0 comments on commit 3243e61

Please sign in to comment.