Skip to content

Commit

Permalink
chore(agenix): remove comments, add generators
Browse files Browse the repository at this point in the history
  • Loading branch information
reo101 committed Dec 25, 2023
1 parent 4d804f0 commit 66ae98e
Show file tree
Hide file tree
Showing 3 changed files with 8 additions and 17 deletions.
9 changes: 3 additions & 6 deletions machines/nixos/x86_64-linux/jeeves/configuration.nix
Original file line number Diff line number Diff line change
Expand Up @@ -71,13 +71,10 @@

# NOTE: made with `mkpasswd -m sha-516`
age.secrets."jeeves.user.password" = {
# file = ../../../../secrets/home/jeeves/user/password.age;
# file = "${inputs.self}/secrets/home/jeeves/user/password.age";
# FIXME: agenix-rekey
rekeyFile = "${inputs.self}/secrets/home/jeeves/user/password.age";
# generator = {pkgs, ...}: ''
# ${pkgs.mkpasswd}/bin/mkpasswd -m sha-516
# '';
generator = {pkgs, ...}: ''
${pkgs.mkpasswd}/bin/mkpasswd -m sha-516
'';
};

users = {
Expand Down
3 changes: 0 additions & 3 deletions machines/nixos/x86_64-linux/jeeves/network.nix
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@
];

age.secrets."home.wifi.env" = {
# file = ../../../../secrets/home/wifi/env.age;
# file = "${inputs.self}/secrets/home/wifi/env.age";
# FIXME: agenix-rekey
rekeyFile = "${inputs.self}/secrets/home/wifi/env.age";
};
networking.wireless = {
Expand Down
13 changes: 5 additions & 8 deletions machines/nixos/x86_64-linux/jeeves/wireguard.nix
Original file line number Diff line number Diff line change
Expand Up @@ -11,16 +11,13 @@

# Server
age.secrets."wireguard.private" = {
# file = ../../../../secrets/home/jeeves/wireguard/private.age;
# file = "${inputs.self}/secrets/home/jeeves/wireguard/private.age";
mode = "077";
# FIXME: agenix-rekey
rekeyFile = "${inputs.self}/secrets/home/jeeves/wireguard/private.age";
# generator = {lib, pkgs, file, ...}: ''
# priv=$(${pkgs.wireguard-tools}/bin/wg genkey)
# ${pkgs.wireguard-tools}/bin/wg pubkey <<< "$priv" > ${lib.escapeShellArg (lib.removeSuffix ".age" file + ".pub")}
# echo "$priv"
# '';
generator = {lib, pkgs, file, ...}: ''
priv=$(${pkgs.wireguard-tools}/bin/wg genkey)
${pkgs.wireguard-tools}/bin/wg pubkey <<< "$priv" > ${lib.escapeShellArg (lib.removeSuffix ".age" file + ".pub")}
echo "$priv"
'';
};

networking.firewall.allowedUDPPorts = [51820];
Expand Down

0 comments on commit 66ae98e

Please sign in to comment.